From 8c9aca2e5feab57fa60fda77da09c9a8bd37b34b Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sun, 6 Sep 2026 23:19:11 +0000 Subject: [PATCH 01/15] Restore wet_route_model_lags_seed_stall so two 4b triggers have a referent. The failure-mode rows extracted in #10299 name this stall as the population their next-rung triggers retire, but the declaration never left #9725. A trigger whose cited home is missing is retired by nothing. Co-authored-by: Cursor --- dag/gunbc/guarantee_stall/roster.dag | 2 + .../wet_route_model_lags_seed_stall.dag | 46 +++++++++++++++++++ 2 files changed, 48 insertions(+) create mode 100644 dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag diff --git a/dag/gunbc/guarantee_stall/roster.dag b/dag/gunbc/guarantee_stall/roster.dag index 09618fc59f7..90f41817e55 100644 --- a/dag/gunbc/guarantee_stall/roster.dag +++ b/dag/gunbc/guarantee_stall/roster.dag @@ -48,6 +48,7 @@ import gunbc.namespace_wave_admission { namespace_wave_admission_occurrence_grai import gunbc.runner_service_activation { runner_activation_reachability_stall, runner_activation_safety_stall } import gunbc.declaration_index_seed_growth { declaration_index_fixture_exemption_classification_stall } import gunbc.guarantee_stall.floor_cost_basis_boundedness_stall { floor_cost_basis_boundedness_stall } +import gunbc.guarantee_stall.wet_route_model_lags_seed_stall { wet_route_model_lags_seed_stall } // THE COHORT PROVENANCE NOTES BELOW WERE AUTHORED WHEN EVERY ROW SAT IN ONE FILE, and they are // carried here verbatim rather than split across the row modules they describe. Their membership @@ -191,6 +192,7 @@ data all_guarantee_stalls: List = [ declaration_index_fixture_exemption_classification_stall, floor_cost_basis_boundedness_stall, axis_list_re_enumerates_its_variant_type_stall, + wet_route_model_lags_seed_stall, ] // THE FOUR SUBJECTS RESTORED TO THE ROSTER, PINNED BY IDENTITY SO THEIR LOSS REFUSES. diff --git a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag new file mode 100644 index 00000000000..7afa8571698 --- /dev/null +++ b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag @@ -0,0 +1,46 @@ +module gunbc.guarantee_stall.wet_route_model_lags_seed_stall + +import gunbc.guarantee_rung { Mitigatable, StructurallyGuaranteed } +import gunbc.guarantee_stall { GuaranteeStall, ClimbableButUnbuilt, BoundedPopulation, climbs_when } + +// THE MODEL LAGS THE SEED ON THREE NAMED DEFECTS, WHICH IS THE DIVERGENCE RUNNING BACKWARDS +// (gunbc#9725). The substrate is supposed to be the authority and the seed one realization of it; +// here the EXECUTING path is strictly stricter than the authored model, on three counts that were +// repaired in `v1_compiler.cli_run.required_floor_runner` and not in `v2.workflow.floor_wet_route`. +// +// THIS ROW WAS DECLARED ON #9725 AND CITED FROM MAIN WITHOUT BEING LANDED. gunbc#10299 moved six +// failure-mode rows verbatim onto main, including +// `content_digest_makes_annotations_semantically_load_bearing` and +// `subject_and_its_digest_as_independent_parameters`. Both name this declaration as the population +// their next-rung triggers retire. #9725 closed unmerged, and the per-row stall split never carried +// this symbol, so those two 4b triggers were retired by nothing until this file existed -- the +// class `gunbc.recurring_failure_mode.dissolution_trigger_cites_a_mechanism_that_is_later_deleted` +// names when a trigger cites a mechanism that later vanishes; this is the same class at origin, +// a citation whose referent was never on the tree that consumed it. +// +// WHY THE MODEL WAS NOT REPAIRED WITH THE SEED, and it is a hard constraint rather than a +// preference: that module is a TERM OF THE WET SEMANTIC SUBJECT, and the subject is +// `closure_content_digest` over RAW FILE CONTENT. Any byte changed there -- a comment included -- +// moves the digest the committed receipt is pinned to and voids the operator-granted lease that +// admits it, forcing a re-dispatch and a second grant to repair an artifact that has no executing +// consumer. +// +// THE DIVERGENCE DIRECTION IS SAFE AND STILL WRONG. A stricter seed cannot ADMIT anything the +// model would refuse, so nothing is fail-open today; what is wrong is that the authority is the +// laggard, so a reader consulting the substrate learns the weaker rule and any consumer generated +// from it inherits the weaker rule. It is filed as a countable debt rather than left inside another +// stall's prose, because it is invisible the moment the citing failure-mode rows merge without it. +data wet_route_model_lags_seed_stall: GuaranteeStall = GuaranteeStall { + subject: "v2.workflow.floor_wet_route authors three rules its own seed realization has already superseded: the executor arm returns fifth of nine rather than last (so ExecutorSnapshotDifferent means only that executor disagreement was the FIRST blocking arm reached, with roster join, identity conformance, outcome vocabulary, age sanity and staleness unevaluated); wet_route_gate_disposition_for_receipt accepts `envelope` and `envelope_digest` as independent parameters rather than deriving the digest from the envelope it judges; and the negative-age arm, while present here, is the one the seed had to be taught separately", + current: Mitigatable, + ceiling: StructurallyGuaranteed, + blocker: ClimbableButUnbuilt, + population: BoundedPopulation { + members: [ + "v2.workflow.floor_wet_route wet_lane_receipt_standing -- executor arm ordered fifth of nine", + "v2.workflow.floor_wet_route wet_route_gate_disposition_for_receipt -- envelope and envelope_digest are independent parameters, demonstrated constructible by v2.test.floor_wet_route.wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name", + "v2.workflow.floor_wet_route -- the module is a term of its own semantic subject, so repairing it requires a re-dispatch and a fresh lease grant" + ] + }, + next_rung_trigger: climbs_when(capability: "the three rules are authored in the wet-route substrate authority itself -- executor arm last of the standing fold, envelope digest derived from the envelope it judges rather than accepted beside it, negative age refused rather than clamped -- landed on a head whose wet receipt was dispatched AFTER them so the subject digest covers them, SUFFICIENT FOR the two citing failure-mode triggers to retire a named, rostered population rather than a missing symbol. NOT satisfied by the seed continuing to be stricter, which is the state this row exists to count, and not satisfied by this declaration existing: a row is a home, not the repairs") +} From 57640f4deacaf19c500080bb16182bd420b4d32f Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sun, 6 Sep 2026 23:34:39 +0000 Subject: [PATCH 02/15] Point wet_route_model_lags_seed_stall at a member that resolves. The restored row still named floor_wet_route symbols from #9725, which never landed, so the two citing 4b triggers would have retired against another missing population. The remaining live member is closure_content_digest. Co-authored-by: Cursor --- .../wet_route_model_lags_seed_stall.dag | 53 +++++++------------ 1 file changed, 20 insertions(+), 33 deletions(-) diff --git a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag index 7afa8571698..7399854237d 100644 --- a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag +++ b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag @@ -1,46 +1,33 @@ module gunbc.guarantee_stall.wet_route_model_lags_seed_stall -import gunbc.guarantee_rung { Mitigatable, StructurallyGuaranteed } +import gunbc.guarantee_rung { Mitigatable, StructurallyImpossible } import gunbc.guarantee_stall { GuaranteeStall, ClimbableButUnbuilt, BoundedPopulation, climbs_when } -// THE MODEL LAGS THE SEED ON THREE NAMED DEFECTS, WHICH IS THE DIVERGENCE RUNNING BACKWARDS -// (gunbc#9725). The substrate is supposed to be the authority and the seed one realization of it; -// here the EXECUTING path is strictly stricter than the authored model, on three counts that were -// repaired in `v1_compiler.cli_run.required_floor_runner` and not in `v2.workflow.floor_wet_route`. +// THIS ROW IS THE REFERENT THE TWO CITING 4b TRIGGERS NAME, not a reconstruction of a module that +// never merged. `gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing` +// and `gunbc.recurring_failure_mode.subject_and_its_digest_as_independent_parameters` both retire +// against `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The first landing of this +// symbol listed `v2.workflow.floor_wet_route` and three of its declarations. Those names do not +// resolve on this tree -- #9725 closed unmerged -- so a population of them is not countable debt +// (DESIGN section 3: a stale name is decidable). This file keeps the cited identity and replaces +// the members with what grep still finds of the classes those two rows measured. // -// THIS ROW WAS DECLARED ON #9725 AND CITED FROM MAIN WITHOUT BEING LANDED. gunbc#10299 moved six -// failure-mode rows verbatim onto main, including -// `content_digest_makes_annotations_semantically_load_bearing` and -// `subject_and_its_digest_as_independent_parameters`. Both name this declaration as the population -// their next-rung triggers retire. #9725 closed unmerged, and the per-row stall split never carried -// this symbol, so those two 4b triggers were retired by nothing until this file existed -- the -// class `gunbc.recurring_failure_mode.dissolution_trigger_cites_a_mechanism_that_is_later_deleted` -// names when a trigger cites a mechanism that later vanishes; this is the same class at origin, -// a citation whose referent was never on the tree that consumed it. -// -// WHY THE MODEL WAS NOT REPAIRED WITH THE SEED, and it is a hard constraint rather than a -// preference: that module is a TERM OF THE WET SEMANTIC SUBJECT, and the subject is -// `closure_content_digest` over RAW FILE CONTENT. Any byte changed there -- a comment included -- -// moves the digest the committed receipt is pinned to and voids the operator-granted lease that -// admits it, forcing a re-dispatch and a second grant to repair an artifact that has no executing -// consumer. -// -// THE DIVERGENCE DIRECTION IS SAFE AND STILL WRONG. A stricter seed cannot ADMIT anything the -// model would refuse, so nothing is fail-open today; what is wrong is that the authority is the -// laggard, so a reader consulting the substrate learns the weaker rule and any consumer generated -// from it inherits the weaker rule. It is filed as a countable debt rather than left inside another -// stall's prose, because it is invisible the moment the citing failure-mode rows merge without it. +// WHAT STILL STANDS. `v1_compiler.resolved_graph_cache` `closure_content_digest` still folds each +// source's raw `content`, so an annotation edit still moves a digest those rows call a semantic +// subject. The independent `envelope` / `envelope_digest` signature they demonstrated is not a +// declaration here: no `wet_route_gate_disposition_for_receipt` exists, and the successor +// `v2.workflow.wet_evidence` does not take those two as peer parameters. A trigger that waited on +// authoring the three rules inside `floor_wet_route` would never fire, which is the class this +// row's first landing reproduced. data wet_route_model_lags_seed_stall: GuaranteeStall = GuaranteeStall { - subject: "v2.workflow.floor_wet_route authors three rules its own seed realization has already superseded: the executor arm returns fifth of nine rather than last (so ExecutorSnapshotDifferent means only that executor disagreement was the FIRST blocking arm reached, with roster join, identity conformance, outcome vocabulary, age sanity and staleness unevaluated); wet_route_gate_disposition_for_receipt accepts `envelope` and `envelope_digest` as independent parameters rather than deriving the digest from the envelope it judges; and the negative-age arm, while present here, is the one the seed had to be taught separately", + subject: "a wet-lane semantic subject digest is still taken over raw file content by v1_compiler.resolved_graph_cache closure_content_digest, so an annotation edit moves the digest DESIGN section 4c says cannot move; the two citing failure-mode triggers retire this remaining member, not the unmerged floor_wet_route symbols", current: Mitigatable, - ceiling: StructurallyGuaranteed, + ceiling: StructurallyImpossible, blocker: ClimbableButUnbuilt, population: BoundedPopulation { members: [ - "v2.workflow.floor_wet_route wet_lane_receipt_standing -- executor arm ordered fifth of nine", - "v2.workflow.floor_wet_route wet_route_gate_disposition_for_receipt -- envelope and envelope_digest are independent parameters, demonstrated constructible by v2.test.floor_wet_route.wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name", - "v2.workflow.floor_wet_route -- the module is a term of its own semantic subject, so repairing it requires a re-dispatch and a fresh lease grant" + "v1_compiler.resolved_graph_cache closure_content_digest", ] }, - next_rung_trigger: climbs_when(capability: "the three rules are authored in the wet-route substrate authority itself -- executor arm last of the standing fold, envelope digest derived from the envelope it judges rather than accepted beside it, negative age refused rather than clamped -- landed on a head whose wet receipt was dispatched AFTER them so the subject digest covers them, SUFFICIENT FOR the two citing failure-mode triggers to retire a named, rostered population rather than a missing symbol. NOT satisfied by the seed continuing to be stricter, which is the state this row exists to count, and not satisfied by this declaration existing: a row is a home, not the repairs") + next_rung_trigger: climbs_when(capability: "a subject digest folded over the annotation-erased projection that semantic compiler passes already receive, so the digest is invariant under comment edits by construction -- SUFFICIENT FOR the two citing failure-mode triggers to retire this rostered member. NOT satisfied by restoring a floor_wet_route spelling, by the seed remaining stricter than a model that is not on this tree, or by this declaration existing") } From 4b8cbdf4afc7baf53c94b8c02849ab8256c2b82c Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sun, 6 Sep 2026 23:52:13 +0000 Subject: [PATCH 03/15] Split the two citing 4b triggers onto their own populations. wet_route_model_lags_seed_stall now covers only closure_content_digest. subject_and_its_digest_as_independent_parameters no longer retires against that stall, which would have gone green while peer-parameter signatures stayed writable. Co-authored-by: Cursor --- .../wet_route_model_lags_seed_stall.dag | 26 +++++++------------ ..._annotations_semantically_load_bearing.dag | 2 +- ...d_its_digest_as_independent_parameters.dag | 2 +- 3 files changed, 12 insertions(+), 18 deletions(-) diff --git a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag index 7399854237d..ef5c4816baf 100644 --- a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag +++ b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag @@ -3,24 +3,18 @@ module gunbc.guarantee_stall.wet_route_model_lags_seed_stall import gunbc.guarantee_rung { Mitigatable, StructurallyImpossible } import gunbc.guarantee_stall { GuaranteeStall, ClimbableButUnbuilt, BoundedPopulation, climbs_when } -// THIS ROW IS THE REFERENT THE TWO CITING 4b TRIGGERS NAME, not a reconstruction of a module that -// never merged. `gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing` -// and `gunbc.recurring_failure_mode.subject_and_its_digest_as_independent_parameters` both retire -// against `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The first landing of this -// symbol listed `v2.workflow.floor_wet_route` and three of its declarations. Those names do not -// resolve on this tree -- #9725 closed unmerged -- so a population of them is not countable debt -// (DESIGN section 3: a stale name is decidable). This file keeps the cited identity and replaces -// the members with what grep still finds of the classes those two rows measured. +// THIS ROW IS THE REFERENT FOR THE CONTENT-DIGEST CLASS ONLY. `gunbc.recurring_failure_mode` +// `content_digest_makes_annotations_semantically_load_bearing` names it as the remaining live +// producer. It does not enumerate the peer-parameter class: that row's next-rung trigger used to +// retire against this identity, which would be satisfied by repairing `closure_content_digest` +// while a value and its digest could still be accepted as peers -- DESIGN section 4b(3). // // WHAT STILL STANDS. `v1_compiler.resolved_graph_cache` `closure_content_digest` still folds each -// source's raw `content`, so an annotation edit still moves a digest those rows call a semantic -// subject. The independent `envelope` / `envelope_digest` signature they demonstrated is not a -// declaration here: no `wet_route_gate_disposition_for_receipt` exists, and the successor -// `v2.workflow.wet_evidence` does not take those two as peer parameters. A trigger that waited on -// authoring the three rules inside `floor_wet_route` would never fire, which is the class this -// row's first landing reproduced. +// source's raw `content`, so an annotation edit still moves a digest that row calls a semantic +// subject. The independent `envelope` / `envelope_digest` signature is not a member here, because +// it is not a declaration on this tree. data wet_route_model_lags_seed_stall: GuaranteeStall = GuaranteeStall { - subject: "a wet-lane semantic subject digest is still taken over raw file content by v1_compiler.resolved_graph_cache closure_content_digest, so an annotation edit moves the digest DESIGN section 4c says cannot move; the two citing failure-mode triggers retire this remaining member, not the unmerged floor_wet_route symbols", + subject: "a wet-lane semantic subject digest is still taken over raw file content by v1_compiler.resolved_graph_cache closure_content_digest, so an annotation edit moves the digest DESIGN section 4c says cannot move", current: Mitigatable, ceiling: StructurallyImpossible, blocker: ClimbableButUnbuilt, @@ -29,5 +23,5 @@ data wet_route_model_lags_seed_stall: GuaranteeStall = GuaranteeStall { "v1_compiler.resolved_graph_cache closure_content_digest", ] }, - next_rung_trigger: climbs_when(capability: "a subject digest folded over the annotation-erased projection that semantic compiler passes already receive, so the digest is invariant under comment edits by construction -- SUFFICIENT FOR the two citing failure-mode triggers to retire this rostered member. NOT satisfied by restoring a floor_wet_route spelling, by the seed remaining stricter than a model that is not on this tree, or by this declaration existing") + next_rung_trigger: climbs_when(capability: "a subject digest folded over the annotation-erased projection that semantic compiler passes already receive, so the digest is invariant under comment edits by construction -- SUFFICIENT FOR gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing's next-rung trigger to retire this rostered member. NOT sufficient for subject_and_its_digest_as_independent_parameters, which is a different class, and not satisfied by restoring a floor_wet_route spelling or by this declaration existing") } diff --git a/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag b/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag index f96200fc8a7..dd9f726731e 100644 --- a/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag +++ b/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag @@ -7,7 +7,7 @@ data content_digest_makes_annotations_semantically_load_bearing: RecurringFailur identity: "content_digest_makes_annotations_semantically_load_bearing" as NonEmptyStr, receipts: [ - "**a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.)", + "**a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. The remaining live producer of that digest is filed as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The three model-side defects named beside it on #9725 did not land (`v2.workflow.floor_wet_route` is not a declaration on this tree). The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.)", ], evidence: [], diff --git a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag index ffa56614bc9..498c46aab03 100644 --- a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag +++ b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag @@ -7,7 +7,7 @@ data subject_and_its_digest_as_independent_parameters: RecurringFailureMode = Re identity: "subject_and_its_digest_as_independent_parameters" as NonEmptyStr, receipts: [ - "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- the `.dag` instances named in `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` are the population that trigger retires.)", + "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`: that row's population is `v1_compiler.resolved_graph_cache` `closure_content_digest`, an instance of the content-digest class, and repairing it would leave this class untouched. The wet-route `.dag` instances this sentence previously named (`v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` and its roster pair) are not declarations on this tree (#9725 closed unmerged).)", ], evidence: [], From aa368987358160057a14b57b063f31b44896a624 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 00:07:01 +0000 Subject: [PATCH 04/15] Recover the stall from #9725 and keep warm-moth-142's fabric-M0 receipt. The row text is 32815827ef8, not a re-derivation; climbs_when only wraps the recovered capability. The peer-parameter file now carries moth's second receipt in full plus a discharge of the missing-row half. Co-authored-by: Cursor --- .../wet_route_model_lags_seed_stall.dag | 41 ++++++++++++------- ..._annotations_semantically_load_bearing.dag | 2 +- ...d_its_digest_as_independent_parameters.dag | 4 +- 3 files changed, 31 insertions(+), 16 deletions(-) diff --git a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag index ef5c4816baf..e57c2cccc81 100644 --- a/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag +++ b/dag/gunbc/guarantee_stall/wet_route_model_lags_seed_stall.dag @@ -1,27 +1,40 @@ module gunbc.guarantee_stall.wet_route_model_lags_seed_stall -import gunbc.guarantee_rung { Mitigatable, StructurallyImpossible } +import gunbc.guarantee_rung { Mitigatable, StructurallyGuaranteed } import gunbc.guarantee_stall { GuaranteeStall, ClimbableButUnbuilt, BoundedPopulation, climbs_when } -// THIS ROW IS THE REFERENT FOR THE CONTENT-DIGEST CLASS ONLY. `gunbc.recurring_failure_mode` -// `content_digest_makes_annotations_semantically_load_bearing` names it as the remaining live -// producer. It does not enumerate the peer-parameter class: that row's next-rung trigger used to -// retire against this identity, which would be satisfied by repairing `closure_content_digest` -// while a value and its digest could still be accepted as peers -- DESIGN section 4b(3). +// RECOVERED 2026-09-07 from commit 32815827ef8 on gunbc#9725 (closed unmerged). The three +// comment blocks below, the subject, current, ceiling, blocker, and population members are +// that commit's text. FRESH: `next_rung_trigger` is now `NextRungTrigger`; `climbs_when` +// wraps the recovered capability string verbatim. No field was re-derived from the live tree. + +// THE MODEL LAGS THE SEED ON THREE NAMED DEFECTS, WHICH IS THE DIVERGENCE RUNNING BACKWARDS +// (gunbc#9725). The substrate is supposed to be the authority and the seed one realization of it; +// here the EXECUTING path is strictly stricter than the authored model, on three counts that were +// repaired in `v1_compiler.cli_run.required_floor_runner` and not in `v2.workflow.floor_wet_route`. +// +// WHY THE MODEL WAS NOT REPAIRED WITH IT, and it is a hard constraint rather than a preference: +// that module is a TERM OF THE WET SEMANTIC SUBJECT, and the subject is `closure_content_digest` +// over RAW FILE CONTENT. Any byte changed there -- a comment included -- moves the digest the +// committed receipt is pinned to and voids the operator-granted lease that admits it, forcing a +// ~2.5h re-dispatch and a second grant to repair an artifact that has no executing consumer. // -// WHAT STILL STANDS. `v1_compiler.resolved_graph_cache` `closure_content_digest` still folds each -// source's raw `content`, so an annotation edit still moves a digest that row calls a semantic -// subject. The independent `envelope` / `envelope_digest` signature is not a member here, because -// it is not a declaration on this tree. +// THE DIVERGENCE DIRECTION IS SAFE AND STILL WRONG. A stricter seed cannot ADMIT anything the +// model would refuse, so nothing is fail-open today; what is wrong is that the authority is the +// laggard, so a reader consulting the substrate learns the weaker rule and any consumer generated +// from it inherits the weaker rule. It is filed as a countable debt rather than left inside the +// admission stall's prose, because it will be invisible the moment that PR merges. data wet_route_model_lags_seed_stall: GuaranteeStall = GuaranteeStall { - subject: "a wet-lane semantic subject digest is still taken over raw file content by v1_compiler.resolved_graph_cache closure_content_digest, so an annotation edit moves the digest DESIGN section 4c says cannot move", + subject: "v2.workflow.floor_wet_route authors three rules its own seed realization has already superseded: the executor arm returns fifth of nine rather than last (so ExecutorSnapshotDifferent means only that executor disagreement was the FIRST blocking arm reached, with roster join, identity conformance, outcome vocabulary, age sanity and staleness unevaluated); wet_route_gate_disposition_for_receipt accepts `envelope` and `envelope_digest` as independent parameters rather than deriving the digest from the envelope it judges; and the negative-age arm, while present here, is the one the seed had to be taught separately", current: Mitigatable, - ceiling: StructurallyImpossible, + ceiling: StructurallyGuaranteed, blocker: ClimbableButUnbuilt, population: BoundedPopulation { members: [ - "v1_compiler.resolved_graph_cache closure_content_digest", + "v2.workflow.floor_wet_route wet_lane_receipt_standing -- executor arm ordered fifth of nine", + "v2.workflow.floor_wet_route wet_route_gate_disposition_for_receipt -- envelope and envelope_digest are independent parameters, demonstrated constructible by v2.test.floor_wet_route.wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name", + "v2.workflow.floor_wet_route -- the module is a term of its own semantic subject, so repairing it requires a re-dispatch and a fresh lease grant" ] }, - next_rung_trigger: climbs_when(capability: "a subject digest folded over the annotation-erased projection that semantic compiler passes already receive, so the digest is invariant under comment edits by construction -- SUFFICIENT FOR gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing's next-rung trigger to retire this rostered member. NOT sufficient for subject_and_its_digest_as_independent_parameters, which is a different class, and not satisfied by restoring a floor_wet_route spelling or by this declaration existing") + next_rung_trigger: climbs_when(capability: "the three rules are authored in v2.workflow.floor_wet_route itself, landed on a head whose wet receipt was dispatched AFTER them so the subject digest covers them -- which means the repair rides a re-dispatch rather than waiting for one, and the admitting witness above flips from a recorded observation to a refusal control in the same change. NOT satisfied by the seed continuing to be stricter, which is the state this row exists to count.") } diff --git a/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag b/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag index dd9f726731e..f96200fc8a7 100644 --- a/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag +++ b/dag/gunbc/recurring_failure_mode/content_digest_makes_annotations_semantically_load_bearing.dag @@ -7,7 +7,7 @@ data content_digest_makes_annotations_semantically_load_bearing: RecurringFailur identity: "content_digest_makes_annotations_semantically_load_bearing" as NonEmptyStr, receipts: [ - "**a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. The remaining live producer of that digest is filed as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The three model-side defects named beside it on #9725 did not land (`v2.workflow.floor_wet_route` is not a declaration on this tree). The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.)", + "**a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.)", ], evidence: [], diff --git a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag index 498c46aab03..8df7f84a094 100644 --- a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag +++ b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag @@ -7,7 +7,9 @@ data subject_and_its_digest_as_independent_parameters: RecurringFailureMode = Re identity: "subject_and_its_digest_as_independent_parameters" as NonEmptyStr, receipts: [ - "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`: that row's population is `v1_compiler.resolved_graph_cache` `closure_content_digest`, an instance of the content-digest class, and repairing it would leave this class untouched. The wet-route `.dag` instances this sentence previously named (`v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` and its roster pair) are not declarations on this tree (#9725 closed unmerged).)", + "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)", + "**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.", + "**DISCHARGE OF THE MISSING-ROW HALF (silent-badger-818, 2026-09-07).** The preceding receipt recorded that `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` did not resolve, and that repointing at `self_host_wet_route_receipt_lifetime_stall` would invent the join this class files. The stall is now restored from commit `32815827ef8` on gunbc#9725 -- recovered, not re-derived -- so the missing-row half is discharged. The first receipt's next-rung trigger no longer retires against that stall: repairing `closure_content_digest` must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). The fabric-m0 instance in the preceding receipt is unchanged.)" ], evidence: [], From 9848ca4fd1760e460fbfbd0fd9a6984afb646912 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 00:07:57 +0000 Subject: [PATCH 05/15] Leave warm-moth-142's fabric-M0 receipt off this PR. They land second: rebase onto this root fix, drop the stale missing-row paragraph, and rewrite against the corrected trigger. Shipping their un-rewritten receipt here would land the paragraph they already plan to delete. Co-authored-by: Cursor --- .../subject_and_its_digest_as_independent_parameters.dag | 2 -- 1 file changed, 2 deletions(-) diff --git a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag index 8df7f84a094..71c485c765a 100644 --- a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag +++ b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag @@ -8,8 +8,6 @@ data subject_and_its_digest_as_independent_parameters: RecurringFailureMode = Re receipts: [ "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)", - "**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.", - "**DISCHARGE OF THE MISSING-ROW HALF (silent-badger-818, 2026-09-07).** The preceding receipt recorded that `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` did not resolve, and that repointing at `self_host_wet_route_receipt_lifetime_stall` would invent the join this class files. The stall is now restored from commit `32815827ef8` on gunbc#9725 -- recovered, not re-derived -- so the missing-row half is discharged. The first receipt's next-rung trigger no longer retires against that stall: repairing `closure_content_digest` must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). The fabric-m0 instance in the preceding receipt is unchanged.)" ], evidence: [], From 47e68eff9b0026ab157429532faa5a5141737b8d Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 00:10:59 +0000 Subject: [PATCH 06/15] Keep moth's fabric-M0 receipt and discharge its three false live clauses. The instance, path-vs-hex finding, and not-repointable conclusion stay. The missing-row claims are named as discharged: the stall is restored and the first-receipt trigger no longer retires against it as a whole. Co-authored-by: Cursor --- .../subject_and_its_digest_as_independent_parameters.dag | 2 ++ 1 file changed, 2 insertions(+) diff --git a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag index 71c485c765a..99d01cbb6d5 100644 --- a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag +++ b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag @@ -8,6 +8,8 @@ data subject_and_its_digest_as_independent_parameters: RecurringFailureMode = Re receipts: [ "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)", + "**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.", + "**DISCHARGE OF THREE CLAUSES IN THE PRECEDING RECEIPT (silent-badger-818, 2026-09-07), NAMED RATHER THAN INFERRED FROM ORDER.** The preceding receipt's last paragraph states three live claims: (1) this row's trigger names `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population it retires, (2) no such row exists, and (3) under DESIGN section 4b(3) the trigger is therefore retired by nothing. All three are FALSE as of this change: the stall is restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived), and the FIRST receipt's next-rung trigger no longer retires against that stall as a whole -- the recovered population spans two classes, so repairing a content-digest member must not satisfy a peer-parameter trigger. WHAT STAYS TRUE AND IS NOT DISCHARGED: `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population, so the citation was never repointable there; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.)" ], evidence: [], From 9c260917be476dbd36b496f8e1e4467d4f6ab9e7 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 00:24:47 +0000 Subject: [PATCH 07/15] Regenerate docs/design-failure-modes.md from the merged authority. main_wet_one ran locally; identity join against origin/main lost=0. The projection greps for the split trigger and the fabric-m0 instance. Co-authored-by: Cursor --- docs/design-failure-modes.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index 30dec706ad5..f627b76c55e 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -280,7 +280,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - **a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.) - **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) - **a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.) -- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- the `.dag` instances named in `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` are the population that trigger retires.) +- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.**DISCHARGE OF THREE CLAUSES IN THE PRECEDING RECEIPT (silent-badger-818, 2026-09-07), NAMED RATHER THAN INFERRED FROM ORDER.** The preceding receipt's last paragraph states three live claims: (1) this row's trigger names `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population it retires, (2) no such row exists, and (3) under DESIGN section 4b(3) the trigger is therefore retired by nothing. All three are FALSE as of this change: the stall is restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived), and the FIRST receipt's next-rung trigger no longer retires against that stall as a whole -- the recovered population spans two classes, so repairing a content-digest member must not satisfy a peer-parameter trigger. WHAT STAYS TRUE AND IS NOT DISCHARGED: `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population, so the citation was never repointable there; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.) - **a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.) - **a gate that admits when its required evidence has not reported, because the admission arm keys on OBSERVED FAILURE rather than on OBSERVED SUCCESS.** INVALID STATE: a required check exists, is correctly configured, and is consulted -- and the consulting arm asks `has anything reported a failure` where the guarantee needs `has everything reported a success`. Between those two questions sits the state where nothing has reported at all, and it is admitted. HARM, AND THE REASON THE CLASS SURVIVES REVIEW: every artifact reads as present and correct. The gate is enumerated in the required roster, it is active, it blocks a reported failure exactly as advertised, and a reader auditing the configuration finds no drift -- because there is none. The defect is in the QUANTIFIER, and a quantifier has no configuration surface to inspect. DISTINGUISHING FACT, AND IT IS THE RACE RATHER THAN ANY FIELD: the class is only reachable inside the window between the evidence being DEMANDED and the evidence ARRIVING, so it is invisible to any observation taken after that window closes -- afterwards the check has reported, the record looks ordinary, and only the ORDER of two timestamps distinguishes an admitted merge from a blocked one. RECOGNITION RULE: for every gate, find the arm that admits and read what it is quantified over. If it enumerates the evidence that HAS arrived and asks a property of each, the empty enumeration admits. If it enumerates the evidence that is REQUIRED and asks each for a success, it refuses. The two spellings are one word apart and behave identically on every input except the one the class lives in. DISTINCT FROM `absorbing_fallback`: that arm WIDENS when it cannot compute an answer and is at least loud about doing work; this arm NARROWS to the empty set and is silent, because a fold over nothing returns its seed and nobody wrote the seed down as a decision. **SPECIMEN (eager-bear-107, gunbc#10236, 2026-09-03), and it landed a break rather than merely permitting one.** The pull request pushed head d8cd3034 at 19:49:33Z, GitHub created its `witnesses` run at 19:49:40Z, and the merge completed at 19:49:43Z -- three seconds after run creation, before any job of it reported. That run then concluded with `required-witnesses-build` and `required-witnesses-floor` both FAILURE, and the head it certified nothing about landed on main as cfe19ea7, adding two duplicate declarations to THIS MODULE that refused main at resolve until a repair pull request landed. WHICH LANE CAUGHT IT IS PART OF THE FILING, because the two main flakes are separable in this evidence and a reader who conflates them loses that: on the post-merge main run at cfe19ea7 the duplicates reddened `required-witnesses-build` while `required-witnesses-floor` was GREEN, so the break is not the cost class this repository's other main flake belongs to and cannot be waved away as more floor variance. THE DETECTING LANE WORKED AND WAS TWENTY MINUTES LATE, which is the shape of this class rather than an aggravating detail: `required-witnesses-build` refused the duplicates correctly -- `generated-artifact CarrierRefused cause=resolve`, the authority declining to answer -- and its job completed at 20:04:14Z against a merge at 19:49:43Z, an unadjudicated interval of twenty minutes and thirty-one seconds. NOTHING WAS MISROUTED AND NO LANE WAS MISSING. **A RETRACTION IS RECORDED HERE BECAUSE THE MISREADING IS ITSELF AN INSTANCE OF A ROSTERED CLASS.** An earlier revision of this row said the catcher was `heal-generated-artifacts` and that it was event-conditional, on the evidence that heal FAILED on the pull-request run and was SKIPPED on the main run of identical content. The job graph refutes it: heal died at step 2, `Checkout triggering branch head`, at 19:52:01Z, with `Regenerate every committed generated artifact` SKIPPED -- the regenerator never ran, so heal detected nothing, and it failed because the merge had deleted the branch head it wanted three seconds after the run was created. A downstream consequence of the merge was read as a detection of the defect. That is `green_reported_over_a_population_the_instrument_does_not_own` inverted -- a RED reported over a population the instrument never reached -- and the recognition rule transfers exactly: A JOB'S CONCLUSION IS NOT EVIDENCE ABOUT THE SUBJECT IT IS NAMED FOR UNTIL ITS STEP RECORD SHOWS IT REACHED THE STEP THAT JUDGES. It survived four readers passing a narrative and was caught by one who read the job graph. Ruleset 16178731 carried zero divergence from `gunbc.repo_ruleset` desired state throughout. Over the forty most recently merged pull requests, six had no `witnesses` run that completed successfully on their own head before `merged_at`. **THE SAME SHAPE IN THIS REPOSITORY'S OWN MODEL, which is what makes it a class and not an incident:** `gunbc.merge_lifecycle` `merge_enabled` folded `policy_admits` over the receipts found for a head from `init: false`, so the absent-receipt verdict was a caller-local constant standing in for a policy fact. There the seed was the SAFE answer and the harm was the mirror image -- the live behavior became unrepresentable, no witness could go red on it, and the module named a policy stronger than the live one as live for two months. RUNG FOUND AT: mitigatable, and only by human habit. CEILING: structurally guaranteed -- the merge queue construction makes the queued ref's run a precondition of landing rather than a fact observed beside it. NEXT TRIGGER: `gunbc.guarantee_stall` `merge_admission_terminal_verdict_stall`. FILED AS A STALL AND NOT A RUNG DROP: a 4b(3) drop asserts a REGRESSION and nothing regressed -- GitHub's rule has evaluated reported check runs this way since the ruleset was created, so the capability was never held and a previous rung would be invented. What existed was 4b(1) inflation, corrected by making the live policy representable. - **a right-censored cost read as an exact one** (an instrument stops because a POLICY THRESHOLD fired before the subject completed, and the figure it emits is a LOWER BOUND on the true cost. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost. WHAT MAKES IT INVISIBLE IS THAT THE BOUND LOOKS LIKE DATA: it has the right units, the right magnitude and the right shape, so nothing about the value marks it as incomplete. AND THE MAGNITUDE IS APPROXIMATELY THE CEILING THAT STOPPED IT, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts ABOVE genuinely expensive completed rows and a 'worst observed' derived from the population describes THE CEILING, NOT THE MACHINE. The remedy sized from it is then sized against a policy constant that the operator chose, wearing the authority of a measurement. RECOGNITION RULE: WHEREVER A COST, DURATION, SIZE OR COUNT CAN BE TRUNCATED BY A DEADLINE, BUDGET, RETRY CAP, PAGE LIMIT OR TIMEOUT, ASK WHETHER THE STOPPED CASE AND THE COMPLETED CASE INHABIT THE SAME CARRIER. If one field, column or constructor holds both, the conflation has already happened and no consumer can undo it -- the information distinguishing them was destroyed at the write, not at the read. The tell is a field named for the quantity (`cpu_ms`) rather than for the measurement's completeness, beside a separate flag nobody joins to it. THIS IS THE INVERSE OPERATION OF `censored_estimator_drops_its_own_tail` AND THE TWO MUST NOT BE MERGED. There, censored observations are EXCLUDED from an estimate and the statistic is biased low with no bound; here a censored observation is INCLUDED and read as exact. Dropping the tail and admitting the tail as a point are opposite mistakes over the same population, and a repair for one is not a repair for the other -- a system can and did commit both about the same artifact. It is also distinct from `window_rendered_subject_misattribution`: there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all. SPECIMEN, gunbc#10210. `required_floor_claim_cost.tsv` carried one `cpu_ms` column for every claim. A claim the per-claim CPU deadline preempted goes INTERRUPTED-BEFORE-VERDICT and reports where the POLL OBSERVED THE CEILING -- 500ms against a 500ms budget, or 502ms -- while a completed claim reports its cost. The floor cost distribution's bands, percentiles, worst-row and inflation pairing consumed the column undifferentiated, so the implied-budget derivation deflated a ceiling by a ratio computed partly from ceilings. RUNG FOUND AT: BELOW THE FLOOR, WHICH IS NOT RUNG 1 AND THE DISTINCTION IS THE POINT. Rung 1 requires harm CONTAINED by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing: it does not refuse, bound or prevent, and a censored value consumed where an exact cost is read is a FABRICATED PLAUSIBLE OUTPUT, which DESIGN section 4b places outside the ladder and forbids outright. This row was first filed claiming `mitigatable` and that was refused by review; the correction is recorded because the inflated reading was written by the author of the repair, inside the change that fixed it. IT IS EXPLICITLY NOT THE *OUTSIDE THE MODELED GUARANTEE* BOUNDARY ONE SENTENCE AWAY IN DESIGN. The cost is measured and then misrepresented; it is neither external, nor undecidable, nor unstated intent. A class that reaches the ladder only by ceasing to fabricate has not climbed a rung -- it has become eligible to be ranked. ATTAINABLE CEILING: STRUCTURALLY IMPOSSIBLE, because membership is decidable at the WRITE. The instrument always knows which arm it took -- it stopped the subject itself -- so the distinction is available at the moment the row is produced and needs no inference at any consumer. A carrier with disjoint constructors makes the conflated state unconstructible rather than merely refused. NEXT-RUNG TRIGGER, AND IT IS THE WHOLE PAIRING RATHER THAN ANY ONE OF ITS PARTS. Each half alone is satisfiable while the class stays alive, which is why a trigger naming less than all four is a trigger that retires the row while the harm persists: (i) DISJOINT CONSTRUCTORS, so a bound and a completion cannot inhabit one value; (ii) DISJOINT WIRE FIELD NAMES, because a shared column re-fuses them at the artifact boundary no matter how the in-memory type is shaped, and a consumer projecting that column gets an empty cell rather than a figure near the ceiling; (iii) EVERY ARITHMETIC CONSUMER REQUIRING THE EXACT TYPE IN ITS SIGNATURE, so summing, ranking or deflating a bound is a compile refusal rather than a discipline; and (iv) A DYNAMIC MIXED POPULATION THAT REFUSES RATHER THAN FILTERING, because silently dropping the censored members is `censored_estimator_drops_its_own_tail` -- the repair for one failure mode arriving as the other. THE FOURTH CLAUSE IS THE ONE AUTHORS OMIT, and omitting it converts this class into its inverse in a single edit that looks like a fix. A GUARD THAT EXCLUDES THE CENSORED POPULATION BY A CORRELATED PROXY IS NOT THIS REPAIR AND IS `incidental_denominator_as_wall`. In the specimen a verdict-absence flag very nearly separates the two populations, because a deadline-preempted claim also reaches no verdict -- but the axes are independent by construction: an unwound claim reaches no verdict with EXACT clocks, and a claim can reach its verdict while its cost is a bound. A witness keyed to the proxy stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted, so the proxy guard also DEFEATS THE EVIDENCE that would detect the class. THE REPAIR IS THEREFORE TWO ROWS, EACH FIXING ONE INPUT AND VARYING THE OTHER, and one of them alone proves nothing about the axis it is named for. **THE CENSORED MAGNITUDE IS RECOVERABLE WHERE THE STOPPED QUANTITY IS DETERMINISTIC, AND THAT DOES NOT MAKE THE CARRIER HONEST (jolly-ferret-412, folded here rather than filed as its own row, which would have been this class under a narrower name).** The floor preempts by polling every 1,024 eval steps, so an interrupted row's step count is 1024-quantised while a completed row reports its true count -- 172,032 = 168 x 1024 and 163,840 = 160 x 1024 against completing counts of 197,227 and 169,297. Because `eval_steps` for one identity is bit-stable across runs, a completing run supplies the denominator: interrupted steps over completed steps is the fraction of work reached, and the censored bound divided by that fraction recovers the magnitude. Two rows whose artifacts read `cpu_at_least` 504 and 524 against a 500ms budget had full costs near 578ms and 541ms, so quoting the bounds as the amounts by which they exceeded the budget understates the first by 74ms. **WHAT THAT RECOVERY IS FOR, STATED BECAUSE THE OPPOSITE READING IS THE COMFORTABLE ONE:** it yields a magnitude FOR ANALYSIS, and it is not a licence to keep consuming the conflated column on the ground that the number can be reconstructed later. The reconstruction needs a second observation of the same identity, a deterministic work metric, and an author who knows to pair them -- none of which a consumer projecting the column has. The four-clause trigger is unaffected by its existence, and clause (iii) is STRENGTHENED by it: a recovered figure is a THIRD kind of value, neither a completion nor a bound, and it must not inhabit the exact type either. A carrier that admitted it would have re-fused three populations instead of two. **THE DISCRIMINATION IS DECIDABLE FROM THE SAME ARTIFACT AND NEEDS NO RERUN.** `eval_steps` is host-independent and deterministic, so pair a refused row against a completing baseline for the same identity: steps AT OR BELOW baseline with materially higher cpu means the row did the same or less work more slowly, which is timing and not the author's change; steps ABOVE baseline means the row genuinely does more work and the diff owns it. The second arm needs no tolerance, because an interrupt can only LOWER the count -- exceeding the baseline despite being cut short is unambiguous. Measured over one refusing pair and four green runs: `eval_steps` is bit-stable on 3,592 of 3,595 planned identities, and the three that move do so by 5 to 9 steps on counts of 4,931, 6,127 and 10,090, so a cpu delta anywhere in this corpus is a timing delta and never a work delta. TWO LANES REACHED THAT TEST FROM OPPOSITE DIRECTIONS, WHICH IS THE STRONGEST THING SAYABLE ABOUT IT: one from asking what a refused row proves about a diff, one from asking what a REPEATED refusal would establish -- and the second lane's statement of it is the sharper one, that a RISING `eval_steps` is what would make a row a genuine cost debt while the VERDICT establishes almost nothing, since a second refusal at identical steps is the same finding with a worse duty cycle. **AND THE TEST HAS A THIRD ARM THAT REFUSES, BECAUSE THE TWO DO NOT PARTITION THE SPACE.** They are exhaustive on the step axis, but the first arm is a CONJUNCTION -- steps at-or-below AND cpu materially higher -- so a row with steps at-or-below and cpu NOT materially higher matches neither. That residue is probably empty, and the reason is itself a finding rather than an acquittal: an interrupt establishes cpu above the budget, so `not materially higher` requires a baseline already at the ceiling. Probably-empty argues for making it REFUSE cheaply, not for leaving it implicit -- an operator holding a two-arm test and an unclassified result files it under the nearest arm, which here is the EXONERATING one, so an incomplete partition produces SYSTEMATIC FALSE EXONERATION aimed at exactly the rows that match no pattern, and it conceals itself because an exonerated row is one nobody looks at again. READ THE ARTIFACT AND NOT THE JOB LOG: the log carries `fill_eval_steps`, `marginal_eval_steps` and `measured_eval_steps`, whose names CONTAIN the row-level field as a substring and whose values are different quantities, so a grep for `eval_steps=` over the log over-captures by more than thirteen to one and a lane following it compares the wrong column confidently.) From f17cfb62a218f10ce35bcb80eb8ec32cc6239ac6 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 03:11:51 +0000 Subject: [PATCH 08/15] Drop the retired param_names argument from callees_from_node call sites. The function no longer declares that parameter, and the floor parse phase refused the whole lane on the three leftover named arguments. Co-authored-by: Cursor --- src/v2/lens/fn_index_depth_agreement.dag | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/src/v2/lens/fn_index_depth_agreement.dag b/src/v2/lens/fn_index_depth_agreement.dag index 88b9c93759e..4666e93f0db 100644 --- a/src/v2/lens/fn_index_depth_agreement.dag +++ b/src/v2/lens/fn_index_depth_agreement.dag @@ -234,8 +234,7 @@ fn pick_first_decl(acc: FirstDeclChannel, decl: FnArrowDecl) -> FirstDeclChannel atom_callees: length( xs: callees_from_node( node: decl.output, - terminal_callee_symbols: no_terminal_callees, - param_names: param_names_of(decl: decl) + terminal_callee_symbols: no_terminal_callees ) ) } @@ -294,8 +293,7 @@ fn bounded_compare_step( let atom = length( xs: callees_from_node( node: decl.output, - terminal_callee_symbols: no_terminal_callees, - param_names: param_names_of(decl: decl) + terminal_callee_symbols: no_terminal_callees ) ) BoundedChannelCompare { @@ -373,8 +371,7 @@ fn tally_decl( let deep_callees = length( xs: callees_from_node( node: decl.output, - terminal_callee_symbols: no_terminal_callees, - param_names: param_names_of(decl: decl) + terminal_callee_symbols: no_terminal_callees ) ) DepthAgreementTally { From 9da621baf096b6d779e3447b523ad4604adad5c7 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 05:30:17 +0000 Subject: [PATCH 09/15] Enroll OutsideModeledGuarantee stamp citations as trigger sites, not wall tests. Three production stamps belong on PLANTED_CONTROL_CITATIONS because the roster reds on the same event as the stamp. The witness probe stays false on purpose with the other fixture-carrier exemptions. Co-authored-by: Cursor --- src/v1/stage0/src/declaration_index.rs | 94 ++++++++++++++++++++------ 1 file changed, 72 insertions(+), 22 deletions(-) diff --git a/src/v1/stage0/src/declaration_index.rs b/src/v1/stage0/src/declaration_index.rs index 64bcde66114..15394f52e22 100644 --- a/src/v1/stage0/src/declaration_index.rs +++ b/src/v1/stage0/src/declaration_index.rs @@ -1347,6 +1347,16 @@ pub fn import_member_findings(index: &DeclarationIndex) -> Vec Vec Date: Mon, 7 Sep 2026 05:48:33 +0000 Subject: [PATCH 10/15] Give next-rung trigger citations their own roster and diagnostic kind. PLANTED-CONTROL-RESOLVES still means a lost control. A resolving OutsideModeledGuarantee required_capability is the stamp firing, which needs a different name, kind, and message. Drop the stall-absent closing from the fabric-m0 receipt so the receipts list does not answer twice. Co-authored-by: Cursor --- ...d_its_digest_as_independent_parameters.dag | 4 +- src/v1/stage0/src/declaration_index.rs | 124 +++++++++++------- .../tests/declaration_index_integrity.rs | 57 +++++++- 3 files changed, 136 insertions(+), 49 deletions(-) diff --git a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag index 99d01cbb6d5..432c6ef76be 100644 --- a/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag +++ b/dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag @@ -8,8 +8,8 @@ data subject_and_its_digest_as_independent_parameters: RecurringFailureMode = Re receipts: [ "**a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)", - "**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.", - "**DISCHARGE OF THREE CLAUSES IN THE PRECEDING RECEIPT (silent-badger-818, 2026-09-07), NAMED RATHER THAN INFERRED FROM ORDER.** The preceding receipt's last paragraph states three live claims: (1) this row's trigger names `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population it retires, (2) no such row exists, and (3) under DESIGN section 4b(3) the trigger is therefore retired by nothing. All three are FALSE as of this change: the stall is restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived), and the FIRST receipt's next-rung trigger no longer retires against that stall as a whole -- the recovered population spans two classes, so repairing a content-digest member must not satisfy a peer-parameter trigger. WHAT STAYS TRUE AND IS NOT DISCHARGED: `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population, so the citation was never repointable there; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.)" + "**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. The stall named as absent in an earlier draft of this closing is restored; this class's trigger is not that stall as a whole (DESIGN section 4b(3)), recorded in the following receipt.", + "**THE STALL `wet_route_model_lags_seed_stall` IS RESTORED, AND THIS CLASS'S TRIGGER IS NOT THAT STALL AS A WHOLE (silent-badger-818, 2026-09-07).** Restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived). The FIRST receipt's next-rung trigger does not retire against that stall as a whole -- the recovered population spans two classes, so repairing only a content-digest member must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.)" ], evidence: [], diff --git a/src/v1/stage0/src/declaration_index.rs b/src/v1/stage0/src/declaration_index.rs index 15394f52e22..72de5ab05d4 100644 --- a/src/v1/stage0/src/declaration_index.rs +++ b/src/v1/stage0/src/declaration_index.rs @@ -269,6 +269,9 @@ pub enum DeclarationIntegrityKind { /// A `PLANTED_CONTROL_CITATIONS` row whose citation stopped refusing — the control is no /// longer discriminating. The inverse reading of the same trigger as the row above. PlantedControlNoLongerRefuses, + /// A `NEXT_RUNG_TRIGGER_CITATIONS` row whose citation now resolves — the named + /// `required_capability` was authored, which is the `OutsideModeledGuarantee` stamp firing. + NextRungTriggerCitationResolved, } pub fn integrity_kind_label(kind: &DeclarationIntegrityKind) -> &'static str { @@ -281,6 +284,7 @@ pub fn integrity_kind_label(kind: &DeclarationIntegrityKind) -> &'static str { DeclarationIntegrityKind::DuplicateModuleDeclaration => "DUPLICATE-MODULE", DeclarationIntegrityKind::CitationDebtRowStale => "CITATION-DEBT-ROW-STALE", DeclarationIntegrityKind::PlantedControlNoLongerRefuses => "PLANTED-CONTROL-RESOLVES", + DeclarationIntegrityKind::NextRungTriggerCitationResolved => "TRIGGER-CITATION-RESOLVES", } } @@ -1353,10 +1357,11 @@ pub fn import_member_findings(index: &DeclarationIndex) -> Vec Vec Vec Vec { + planted_control_findings_against(index, PLANTED_CONTROL_CITATIONS) +} + +pub fn planted_control_findings_against( + index: &DeclarationIndex, + roster: &[(&str, &str, &str, &str, &str)], +) -> Vec { + let still_refusing = refusing_sites(index); + roster + .iter() + .filter(|row| !still_refusing.contains(&site_owned(row))) + .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { + kind: DeclarationIntegrityKind::PlantedControlNoLongerRefuses, + rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), + offset: None, + message: format!( + "PLANTED_CONTROL_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as a \ + control that must NOT resolve, and it no longer refuses — the control has \ + lost its discriminating power and the mechanism it proves is now unevidenced", + if field.is_empty() { + String::new() + } else { + format!(" field `{field}`") + } + ), + }) + .collect() +} + +/// PRODUCTION NEXT-RUNG TRIGGER CITATIONS, 2026-09-07. Three `OutsideModeledGuarantee` stamps +/// name a `required_capability` that must not exist yet; authoring it is the climb that spends +/// the stamp (`grounding_name_only_residual_boundary` says "then this stamp reds"). Each row +/// is one SITE; two `DeclarationRef`s inside one stamp that name the same absent symbol share +/// that identity. +/// +/// NOT `PLANTED_CONTROL_CITATIONS`. That roster's diagnostic says a resolving control has lost +/// its discriminating power. These rows resolve WHEN THE STAMP FIRES AS DESIGNED. Same +/// underlying trigger (citation used to refuse, now does not), materially different contract, +/// so a different name, kind, and message. A comment asserting direction coincidence is not +/// a second contract. +const NEXT_RUNG_TRIGGER_CITATIONS: &[(&str, &str, &str, &str, &str)] = &[ ( "v2.lens.enforcement.complexity_contract_subject", "complexity_optimality_boundary", @@ -2087,13 +2116,13 @@ const PLANTED_CONTROL_CITATIONS: &[(&str, &str, &str, &str, &str)] = &[ ), ]; -/// A control that has STOPPED refusing has lost its discriminating power, and that is a red in -/// its own right — the inverse of a spent debt row, and the reason these are a separate roster. -pub fn planted_control_findings(index: &DeclarationIndex) -> Vec { - planted_control_findings_against(index, PLANTED_CONTROL_CITATIONS) +pub fn next_rung_trigger_citation_findings( + index: &DeclarationIndex, +) -> Vec { + next_rung_trigger_citation_findings_against(index, NEXT_RUNG_TRIGGER_CITATIONS) } -pub fn planted_control_findings_against( +pub fn next_rung_trigger_citation_findings_against( index: &DeclarationIndex, roster: &[(&str, &str, &str, &str, &str)], ) -> Vec { @@ -2102,13 +2131,14 @@ pub fn planted_control_findings_against( .iter() .filter(|row| !still_refusing.contains(&site_owned(row))) .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { - kind: DeclarationIntegrityKind::PlantedControlNoLongerRefuses, + kind: DeclarationIntegrityKind::NextRungTriggerCitationResolved, rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), offset: None, message: format!( - "PLANTED_CONTROL_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as a \ - control that must NOT resolve, and it no longer refuses — the control has \ - lost its discriminating power and the mechanism it proves is now unevidenced", + "NEXT_RUNG_TRIGGER_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as \ + an OutsideModeledGuarantee required_capability that must not exist yet, and it \ + now resolves — the stamp's climb has fired; delete this row and take the stamp \ + off OutsideModeledGuarantee", if field.is_empty() { String::new() } else { @@ -2366,6 +2396,7 @@ pub fn corpus_findings(index: &DeclarationIndex) -> Vec Vec Date: Mon, 7 Sep 2026 06:16:15 +0000 Subject: [PATCH 11/15] Regenerate design-failure-modes.md from the updated receipts. The projection still carried the stall-absent closing and the three-clause discharge after the authority dropped both. Co-authored-by: Cursor --- docs/design-failure-modes.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index f627b76c55e..c3ecd71547d 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -280,7 +280,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - **a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.) - **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) - **a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.) -- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. THIS ROW'S OWN TRIGGER CANNOT BE EVALUATED: it ends by naming `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population the trigger retires, and no such row exists -- `dag/gunbc/guarantee_stall/` carries no such file, and `content_digest_makes_annotations_semantically_load_bearing` cites the same absent name. The nearest surviving row, `self_host_wet_route_receipt_lifetime_stall`, is about route families and receipt lifetime and is NOT this population, so the citation is not repointable without inventing the join this very class files. Recorded rather than repaired: under 4b(3) a trigger naming a population that does not resolve is retired by nothing.**DISCHARGE OF THREE CLAUSES IN THE PRECEDING RECEIPT (silent-badger-818, 2026-09-07), NAMED RATHER THAN INFERRED FROM ORDER.** The preceding receipt's last paragraph states three live claims: (1) this row's trigger names `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as the population it retires, (2) no such row exists, and (3) under DESIGN section 4b(3) the trigger is therefore retired by nothing. All three are FALSE as of this change: the stall is restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived), and the FIRST receipt's next-rung trigger no longer retires against that stall as a whole -- the recovered population spans two classes, so repairing a content-digest member must not satisfy a peer-parameter trigger. WHAT STAYS TRUE AND IS NOT DISCHARGED: `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population, so the citation was never repointable there; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.) +- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. The stall named as absent in an earlier draft of this closing is restored; this class's trigger is not that stall as a whole (DESIGN section 4b(3)), recorded in the following receipt.**THE STALL `wet_route_model_lags_seed_stall` IS RESTORED, AND THIS CLASS'S TRIGGER IS NOT THAT STALL AS A WHOLE (silent-badger-818, 2026-09-07).** Restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived). The FIRST receipt's next-rung trigger does not retire against that stall as a whole -- the recovered population spans two classes, so repairing only a content-digest member must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.) - **a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.) - **a gate that admits when its required evidence has not reported, because the admission arm keys on OBSERVED FAILURE rather than on OBSERVED SUCCESS.** INVALID STATE: a required check exists, is correctly configured, and is consulted -- and the consulting arm asks `has anything reported a failure` where the guarantee needs `has everything reported a success`. Between those two questions sits the state where nothing has reported at all, and it is admitted. HARM, AND THE REASON THE CLASS SURVIVES REVIEW: every artifact reads as present and correct. The gate is enumerated in the required roster, it is active, it blocks a reported failure exactly as advertised, and a reader auditing the configuration finds no drift -- because there is none. The defect is in the QUANTIFIER, and a quantifier has no configuration surface to inspect. DISTINGUISHING FACT, AND IT IS THE RACE RATHER THAN ANY FIELD: the class is only reachable inside the window between the evidence being DEMANDED and the evidence ARRIVING, so it is invisible to any observation taken after that window closes -- afterwards the check has reported, the record looks ordinary, and only the ORDER of two timestamps distinguishes an admitted merge from a blocked one. RECOGNITION RULE: for every gate, find the arm that admits and read what it is quantified over. If it enumerates the evidence that HAS arrived and asks a property of each, the empty enumeration admits. If it enumerates the evidence that is REQUIRED and asks each for a success, it refuses. The two spellings are one word apart and behave identically on every input except the one the class lives in. DISTINCT FROM `absorbing_fallback`: that arm WIDENS when it cannot compute an answer and is at least loud about doing work; this arm NARROWS to the empty set and is silent, because a fold over nothing returns its seed and nobody wrote the seed down as a decision. **SPECIMEN (eager-bear-107, gunbc#10236, 2026-09-03), and it landed a break rather than merely permitting one.** The pull request pushed head d8cd3034 at 19:49:33Z, GitHub created its `witnesses` run at 19:49:40Z, and the merge completed at 19:49:43Z -- three seconds after run creation, before any job of it reported. That run then concluded with `required-witnesses-build` and `required-witnesses-floor` both FAILURE, and the head it certified nothing about landed on main as cfe19ea7, adding two duplicate declarations to THIS MODULE that refused main at resolve until a repair pull request landed. WHICH LANE CAUGHT IT IS PART OF THE FILING, because the two main flakes are separable in this evidence and a reader who conflates them loses that: on the post-merge main run at cfe19ea7 the duplicates reddened `required-witnesses-build` while `required-witnesses-floor` was GREEN, so the break is not the cost class this repository's other main flake belongs to and cannot be waved away as more floor variance. THE DETECTING LANE WORKED AND WAS TWENTY MINUTES LATE, which is the shape of this class rather than an aggravating detail: `required-witnesses-build` refused the duplicates correctly -- `generated-artifact CarrierRefused cause=resolve`, the authority declining to answer -- and its job completed at 20:04:14Z against a merge at 19:49:43Z, an unadjudicated interval of twenty minutes and thirty-one seconds. NOTHING WAS MISROUTED AND NO LANE WAS MISSING. **A RETRACTION IS RECORDED HERE BECAUSE THE MISREADING IS ITSELF AN INSTANCE OF A ROSTERED CLASS.** An earlier revision of this row said the catcher was `heal-generated-artifacts` and that it was event-conditional, on the evidence that heal FAILED on the pull-request run and was SKIPPED on the main run of identical content. The job graph refutes it: heal died at step 2, `Checkout triggering branch head`, at 19:52:01Z, with `Regenerate every committed generated artifact` SKIPPED -- the regenerator never ran, so heal detected nothing, and it failed because the merge had deleted the branch head it wanted three seconds after the run was created. A downstream consequence of the merge was read as a detection of the defect. That is `green_reported_over_a_population_the_instrument_does_not_own` inverted -- a RED reported over a population the instrument never reached -- and the recognition rule transfers exactly: A JOB'S CONCLUSION IS NOT EVIDENCE ABOUT THE SUBJECT IT IS NAMED FOR UNTIL ITS STEP RECORD SHOWS IT REACHED THE STEP THAT JUDGES. It survived four readers passing a narrative and was caught by one who read the job graph. Ruleset 16178731 carried zero divergence from `gunbc.repo_ruleset` desired state throughout. Over the forty most recently merged pull requests, six had no `witnesses` run that completed successfully on their own head before `merged_at`. **THE SAME SHAPE IN THIS REPOSITORY'S OWN MODEL, which is what makes it a class and not an incident:** `gunbc.merge_lifecycle` `merge_enabled` folded `policy_admits` over the receipts found for a head from `init: false`, so the absent-receipt verdict was a caller-local constant standing in for a policy fact. There the seed was the SAFE answer and the harm was the mirror image -- the live behavior became unrepresentable, no witness could go red on it, and the module named a policy stronger than the live one as live for two months. RUNG FOUND AT: mitigatable, and only by human habit. CEILING: structurally guaranteed -- the merge queue construction makes the queued ref's run a precondition of landing rather than a fact observed beside it. NEXT TRIGGER: `gunbc.guarantee_stall` `merge_admission_terminal_verdict_stall`. FILED AS A STALL AND NOT A RUNG DROP: a 4b(3) drop asserts a REGRESSION and nothing regressed -- GitHub's rule has evaluated reported check runs this way since the ruleset was created, so the capability was never held and a previous rung would be invented. What existed was 4b(1) inflation, corrected by making the live policy representable. - **a right-censored cost read as an exact one** (an instrument stops because a POLICY THRESHOLD fired before the subject completed, and the figure it emits is a LOWER BOUND on the true cost. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost. WHAT MAKES IT INVISIBLE IS THAT THE BOUND LOOKS LIKE DATA: it has the right units, the right magnitude and the right shape, so nothing about the value marks it as incomplete. AND THE MAGNITUDE IS APPROXIMATELY THE CEILING THAT STOPPED IT, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts ABOVE genuinely expensive completed rows and a 'worst observed' derived from the population describes THE CEILING, NOT THE MACHINE. The remedy sized from it is then sized against a policy constant that the operator chose, wearing the authority of a measurement. RECOGNITION RULE: WHEREVER A COST, DURATION, SIZE OR COUNT CAN BE TRUNCATED BY A DEADLINE, BUDGET, RETRY CAP, PAGE LIMIT OR TIMEOUT, ASK WHETHER THE STOPPED CASE AND THE COMPLETED CASE INHABIT THE SAME CARRIER. If one field, column or constructor holds both, the conflation has already happened and no consumer can undo it -- the information distinguishing them was destroyed at the write, not at the read. The tell is a field named for the quantity (`cpu_ms`) rather than for the measurement's completeness, beside a separate flag nobody joins to it. THIS IS THE INVERSE OPERATION OF `censored_estimator_drops_its_own_tail` AND THE TWO MUST NOT BE MERGED. There, censored observations are EXCLUDED from an estimate and the statistic is biased low with no bound; here a censored observation is INCLUDED and read as exact. Dropping the tail and admitting the tail as a point are opposite mistakes over the same population, and a repair for one is not a repair for the other -- a system can and did commit both about the same artifact. It is also distinct from `window_rendered_subject_misattribution`: there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all. SPECIMEN, gunbc#10210. `required_floor_claim_cost.tsv` carried one `cpu_ms` column for every claim. A claim the per-claim CPU deadline preempted goes INTERRUPTED-BEFORE-VERDICT and reports where the POLL OBSERVED THE CEILING -- 500ms against a 500ms budget, or 502ms -- while a completed claim reports its cost. The floor cost distribution's bands, percentiles, worst-row and inflation pairing consumed the column undifferentiated, so the implied-budget derivation deflated a ceiling by a ratio computed partly from ceilings. RUNG FOUND AT: BELOW THE FLOOR, WHICH IS NOT RUNG 1 AND THE DISTINCTION IS THE POINT. Rung 1 requires harm CONTAINED by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing: it does not refuse, bound or prevent, and a censored value consumed where an exact cost is read is a FABRICATED PLAUSIBLE OUTPUT, which DESIGN section 4b places outside the ladder and forbids outright. This row was first filed claiming `mitigatable` and that was refused by review; the correction is recorded because the inflated reading was written by the author of the repair, inside the change that fixed it. IT IS EXPLICITLY NOT THE *OUTSIDE THE MODELED GUARANTEE* BOUNDARY ONE SENTENCE AWAY IN DESIGN. The cost is measured and then misrepresented; it is neither external, nor undecidable, nor unstated intent. A class that reaches the ladder only by ceasing to fabricate has not climbed a rung -- it has become eligible to be ranked. ATTAINABLE CEILING: STRUCTURALLY IMPOSSIBLE, because membership is decidable at the WRITE. The instrument always knows which arm it took -- it stopped the subject itself -- so the distinction is available at the moment the row is produced and needs no inference at any consumer. A carrier with disjoint constructors makes the conflated state unconstructible rather than merely refused. NEXT-RUNG TRIGGER, AND IT IS THE WHOLE PAIRING RATHER THAN ANY ONE OF ITS PARTS. Each half alone is satisfiable while the class stays alive, which is why a trigger naming less than all four is a trigger that retires the row while the harm persists: (i) DISJOINT CONSTRUCTORS, so a bound and a completion cannot inhabit one value; (ii) DISJOINT WIRE FIELD NAMES, because a shared column re-fuses them at the artifact boundary no matter how the in-memory type is shaped, and a consumer projecting that column gets an empty cell rather than a figure near the ceiling; (iii) EVERY ARITHMETIC CONSUMER REQUIRING THE EXACT TYPE IN ITS SIGNATURE, so summing, ranking or deflating a bound is a compile refusal rather than a discipline; and (iv) A DYNAMIC MIXED POPULATION THAT REFUSES RATHER THAN FILTERING, because silently dropping the censored members is `censored_estimator_drops_its_own_tail` -- the repair for one failure mode arriving as the other. THE FOURTH CLAUSE IS THE ONE AUTHORS OMIT, and omitting it converts this class into its inverse in a single edit that looks like a fix. A GUARD THAT EXCLUDES THE CENSORED POPULATION BY A CORRELATED PROXY IS NOT THIS REPAIR AND IS `incidental_denominator_as_wall`. In the specimen a verdict-absence flag very nearly separates the two populations, because a deadline-preempted claim also reaches no verdict -- but the axes are independent by construction: an unwound claim reaches no verdict with EXACT clocks, and a claim can reach its verdict while its cost is a bound. A witness keyed to the proxy stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted, so the proxy guard also DEFEATS THE EVIDENCE that would detect the class. THE REPAIR IS THEREFORE TWO ROWS, EACH FIXING ONE INPUT AND VARYING THE OTHER, and one of them alone proves nothing about the axis it is named for. **THE CENSORED MAGNITUDE IS RECOVERABLE WHERE THE STOPPED QUANTITY IS DETERMINISTIC, AND THAT DOES NOT MAKE THE CARRIER HONEST (jolly-ferret-412, folded here rather than filed as its own row, which would have been this class under a narrower name).** The floor preempts by polling every 1,024 eval steps, so an interrupted row's step count is 1024-quantised while a completed row reports its true count -- 172,032 = 168 x 1024 and 163,840 = 160 x 1024 against completing counts of 197,227 and 169,297. Because `eval_steps` for one identity is bit-stable across runs, a completing run supplies the denominator: interrupted steps over completed steps is the fraction of work reached, and the censored bound divided by that fraction recovers the magnitude. Two rows whose artifacts read `cpu_at_least` 504 and 524 against a 500ms budget had full costs near 578ms and 541ms, so quoting the bounds as the amounts by which they exceeded the budget understates the first by 74ms. **WHAT THAT RECOVERY IS FOR, STATED BECAUSE THE OPPOSITE READING IS THE COMFORTABLE ONE:** it yields a magnitude FOR ANALYSIS, and it is not a licence to keep consuming the conflated column on the ground that the number can be reconstructed later. The reconstruction needs a second observation of the same identity, a deterministic work metric, and an author who knows to pair them -- none of which a consumer projecting the column has. The four-clause trigger is unaffected by its existence, and clause (iii) is STRENGTHENED by it: a recovered figure is a THIRD kind of value, neither a completion nor a bound, and it must not inhabit the exact type either. A carrier that admitted it would have re-fused three populations instead of two. **THE DISCRIMINATION IS DECIDABLE FROM THE SAME ARTIFACT AND NEEDS NO RERUN.** `eval_steps` is host-independent and deterministic, so pair a refused row against a completing baseline for the same identity: steps AT OR BELOW baseline with materially higher cpu means the row did the same or less work more slowly, which is timing and not the author's change; steps ABOVE baseline means the row genuinely does more work and the diff owns it. The second arm needs no tolerance, because an interrupt can only LOWER the count -- exceeding the baseline despite being cut short is unambiguous. Measured over one refusing pair and four green runs: `eval_steps` is bit-stable on 3,592 of 3,595 planned identities, and the three that move do so by 5 to 9 steps on counts of 4,931, 6,127 and 10,090, so a cpu delta anywhere in this corpus is a timing delta and never a work delta. TWO LANES REACHED THAT TEST FROM OPPOSITE DIRECTIONS, WHICH IS THE STRONGEST THING SAYABLE ABOUT IT: one from asking what a refused row proves about a diff, one from asking what a REPEATED refusal would establish -- and the second lane's statement of it is the sharper one, that a RISING `eval_steps` is what would make a row a genuine cost debt while the VERDICT establishes almost nothing, since a second refusal at identical steps is the same finding with a worse duty cycle. **AND THE TEST HAS A THIRD ARM THAT REFUSES, BECAUSE THE TWO DO NOT PARTITION THE SPACE.** They are exhaustive on the step axis, but the first arm is a CONJUNCTION -- steps at-or-below AND cpu materially higher -- so a row with steps at-or-below and cpu NOT materially higher matches neither. That residue is probably empty, and the reason is itself a finding rather than an acquittal: an interrupt establishes cpu above the budget, so `not materially higher` requires a baseline already at the ceiling. Probably-empty argues for making it REFUSE cheaply, not for leaving it implicit -- an operator holding a two-arm test and an unclassified result files it under the nearest arm, which here is the EXONERATING one, so an incomplete partition produces SYSTEMATIC FALSE EXONERATION aimed at exactly the rows that match no pattern, and it conceals itself because an exonerated row is one nobody looks at again. READ THE ARTIFACT AND NOT THE JOB LOG: the log carries `fill_eval_steps`, `marginal_eval_steps` and `measured_eval_steps`, whose names CONTAIN the row-level field as a substring and whose values are different quantities, so a grep for `eval_steps=` over the log over-captures by more than thirteen to one and a lane following it compares the wrong column confidently.) From c8e2d6a6817b8ae683b0eecf2caeb1b87d3585fc Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 07:02:58 +0000 Subject: [PATCH 12/15] Share the spent-roster join; keep kind and message as parameters. Debt, planted-control, and next-rung trigger citations all ask which roster rows now resolve. Copying that fold minted a third authority for the same traversal. Co-authored-by: Cursor --- src/v1/stage0/src/declaration_index.rs | 116 ++++++++++++++----------- 1 file changed, 65 insertions(+), 51 deletions(-) diff --git a/src/v1/stage0/src/declaration_index.rs b/src/v1/stage0/src/declaration_index.rs index 72de5ab05d4..b3ae7f4b3ca 100644 --- a/src/v1/stage0/src/declaration_index.rs +++ b/src/v1/stage0/src/declaration_index.rs @@ -2049,6 +2049,41 @@ pub fn citation_debt_findings(index: &DeclarationIndex) -> Vec String, +) -> Vec { + let still_refusing = refusing_sites(index); + roster + .iter() + .filter(|row| !still_refusing.contains(&site_owned(row))) + .map( + |(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { + kind: kind.clone(), + rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), + offset: None, + message: message(citer, in_decl, module, decl, field), + }, + ) + .collect() +} + +fn citation_field_suffix(field: &str) -> String { + if field.is_empty() { + String::new() + } else { + format!(" field `{field}`") + } +} + /// A control that has STOPPED refusing has lost its discriminating power, and that is a red in /// its own right — the inverse of a spent debt row, and the reason these are a separate roster. pub fn planted_control_findings(index: &DeclarationIndex) -> Vec { @@ -2059,26 +2094,19 @@ pub fn planted_control_findings_against( index: &DeclarationIndex, roster: &[(&str, &str, &str, &str, &str)], ) -> Vec { - let still_refusing = refusing_sites(index); - roster - .iter() - .filter(|row| !still_refusing.contains(&site_owned(row))) - .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { - kind: DeclarationIntegrityKind::PlantedControlNoLongerRefuses, - rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), - offset: None, - message: format!( + resolved_roster_findings( + index, + roster, + DeclarationIntegrityKind::PlantedControlNoLongerRefuses, + |citer, in_decl, module, decl, field| { + format!( "PLANTED_CONTROL_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as a \ control that must NOT resolve, and it no longer refuses — the control has \ lost its discriminating power and the mechanism it proves is now unevidenced", - if field.is_empty() { - String::new() - } else { - format!(" field `{field}`") - } - ), - }) - .collect() + citation_field_suffix(field) + ) + }, + ) } /// PRODUCTION NEXT-RUNG TRIGGER CITATIONS, 2026-09-07. Three `OutsideModeledGuarantee` stamps @@ -2126,27 +2154,20 @@ pub fn next_rung_trigger_citation_findings_against( index: &DeclarationIndex, roster: &[(&str, &str, &str, &str, &str)], ) -> Vec { - let still_refusing = refusing_sites(index); - roster - .iter() - .filter(|row| !still_refusing.contains(&site_owned(row))) - .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { - kind: DeclarationIntegrityKind::NextRungTriggerCitationResolved, - rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), - offset: None, - message: format!( + resolved_roster_findings( + index, + roster, + DeclarationIntegrityKind::NextRungTriggerCitationResolved, + |citer, in_decl, module, decl, field| { + format!( "NEXT_RUNG_TRIGGER_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as \ an OutsideModeledGuarantee required_capability that must not exist yet, and it \ now resolves — the stamp's climb has fired; delete this row and take the stamp \ off OutsideModeledGuarantee", - if field.is_empty() { - String::new() - } else { - format!(" field `{field}`") - } - ), - }) - .collect() + citation_field_suffix(field) + ) + }, + ) } /// The debt join, over an EXPLICIT roster. @@ -2172,26 +2193,19 @@ pub fn citation_debt_findings_named( roster: &[(&str, &str, &str, &str, &str)], roster_name: &str, ) -> Vec { - let live = refusing_sites(index); - roster - .iter() - .filter(|row| !live.contains(&site_owned(row))) - .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { - kind: DeclarationIntegrityKind::CitationDebtRowStale, - rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), - offset: None, - message: format!( + resolved_roster_findings( + index, + roster, + DeclarationIntegrityKind::CitationDebtRowStale, + |citer, in_decl, module, decl, field| { + format!( "{roster_name} still lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} — that \ citation no longer refuses, so the row is spent and must be deleted; the \ roster only shrinks", - if field.is_empty() { - String::new() - } else { - format!(" field `{field}`") - } - ), - }) - .collect() + citation_field_suffix(field) + ) + }, + ) } /// (2) The cited-symbol wall — §3's cite-the-symbol rule, executing. From 2eeace037f7d01226ea77a5fa64a4e9cf4d0363c Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 09:50:01 +0000 Subject: [PATCH 13/15] Take main's PLANTED_CONTROL_CITATIONS occupancy; drop the trigger roster. #10718 already decided the four-row enrollment. This branch no longer reverts that shape. Remaining work is the stall restore only. Co-authored-by: Cursor --- src/v1/stage0/src/declaration_index.rs | 212 ++++++------------ .../tests/declaration_index_integrity.rs | 71 +----- 2 files changed, 75 insertions(+), 208 deletions(-) diff --git a/src/v1/stage0/src/declaration_index.rs b/src/v1/stage0/src/declaration_index.rs index 6d49a168e18..a10ca6cd3f7 100644 --- a/src/v1/stage0/src/declaration_index.rs +++ b/src/v1/stage0/src/declaration_index.rs @@ -269,9 +269,6 @@ pub enum DeclarationIntegrityKind { /// A `PLANTED_CONTROL_CITATIONS` row whose citation stopped refusing — the control is no /// longer discriminating. The inverse reading of the same trigger as the row above. PlantedControlNoLongerRefuses, - /// A `NEXT_RUNG_TRIGGER_CITATIONS` row whose citation now resolves — the named - /// `required_capability` was authored, which is the `OutsideModeledGuarantee` stamp firing. - NextRungTriggerCitationResolved, } pub fn integrity_kind_label(kind: &DeclarationIntegrityKind) -> &'static str { @@ -284,7 +281,6 @@ pub fn integrity_kind_label(kind: &DeclarationIntegrityKind) -> &'static str { DeclarationIntegrityKind::DuplicateModuleDeclaration => "DUPLICATE-MODULE", DeclarationIntegrityKind::CitationDebtRowStale => "CITATION-DEBT-ROW-STALE", DeclarationIntegrityKind::PlantedControlNoLongerRefuses => "PLANTED-CONTROL-RESOLVES", - DeclarationIntegrityKind::NextRungTriggerCitationResolved => "TRIGGER-CITATION-RESOLVES", } } @@ -1351,17 +1347,6 @@ pub fn import_member_findings(index: &DeclarationIndex) -> Vec Vec String, -) -> Vec { - let still_refusing = refusing_sites(index); - roster - .iter() - .filter(|row| !still_refusing.contains(&site_owned(row))) - .map( - |(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { - kind: kind.clone(), - rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), - offset: None, - message: message(citer, in_decl, module, decl, field), - }, - ) - .collect() -} - -fn citation_field_suffix(field: &str) -> String { - if field.is_empty() { - String::new() - } else { - format!(" field `{field}`") - } -} - -/// A control that has STOPPED refusing has lost its discriminating power, and that is a red in -/// its own right — the inverse of a spent debt row, and the reason these are a separate roster. -pub fn planted_control_findings(index: &DeclarationIndex) -> Vec { - planted_control_findings_against(index, PLANTED_CONTROL_CITATIONS) -} - -pub fn planted_control_findings_against( - index: &DeclarationIndex, - roster: &[(&str, &str, &str, &str, &str)], -) -> Vec { - resolved_roster_findings( - index, - roster, - DeclarationIntegrityKind::PlantedControlNoLongerRefuses, - |citer, in_decl, module, decl, field| { - format!( - "PLANTED_CONTROL_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as a \ - control that must NOT resolve, and it no longer refuses — the control has \ - lost its discriminating power and the mechanism it proves is now unevidenced", - citation_field_suffix(field) - ) - }, - ) -} - -/// PRODUCTION NEXT-RUNG TRIGGER CITATIONS, 2026-09-07. Three `OutsideModeledGuarantee` stamps -/// name a `required_capability` that must not exist yet; authoring it is the climb that spends -/// the stamp (`grounding_name_only_residual_boundary` says "then this stamp reds"). Each row -/// is one SITE; two `DeclarationRef`s inside one stamp that name the same absent symbol share -/// that identity. -/// -/// NOT `PLANTED_CONTROL_CITATIONS`. That roster's diagnostic says a resolving control has lost -/// its discriminating power. These rows resolve WHEN THE STAMP FIRES AS DESIGNED. Same -/// underlying trigger (citation used to refuse, now does not), materially different contract, -/// so a different name, kind, and message. A comment asserting direction coincidence is not -/// a second contract. -const NEXT_RUNG_TRIGGER_CITATIONS: &[(&str, &str, &str, &str, &str)] = &[ +/// RE-OCCUPIED BY #10706's OutsideModeledGuarantee stamps (repair on the same subject as the +/// parse/call-shape floor red). Those stamps cite a `required_capability` that MUST stay +/// absent: `guarantee_boundary_still_outside` is true only on `DeclarationRefDeclarationAbsent`, +/// and `construction_justification_rule` says authoring the capability makes the stamp wrong. +/// The citations are therefore deliberately false — planted controls, not debt and not +/// missing declarations. Enrolling them here is the other half #10706 omitted: without these +/// rows the declarations phase refuses the same absences the join requires. +/// +/// THE ARM'S OWN FIXTURE EVIDENCE DOES NOT LIVE IN THIS ROSTER. +/// `planted_control_findings_against` takes the roster as a parameter, and +/// `a_planted_control_that_still_refuses_is_healthy` / +/// `a_planted_control_that_resolves_has_lost_its_power_and_refuses` drive both directions from +/// controlled fixtures authoring their own rows. §4b(4): a climb dissolves production +/// machinery, never that evidence. +/// +/// Site grain: `(citing_module, in_declaration, cited_module, cited_decl, field)`. Two +/// DeclarationRef literals inside one stamp that name the same absent symbol share one row. +const PLANTED_CONTROL_CITATIONS: &[(&str, &str, &str, &str, &str)] = &[ ( "v2.lens.enforcement.complexity_contract_subject", "complexity_optimality_boundary", @@ -2160,32 +2064,45 @@ const NEXT_RUNG_TRIGGER_CITATIONS: &[(&str, &str, &str, &str, &str)] = &[ "unrestricted_cheaper_equivalent", "", ), + ( + "v2.test.claim.construction_justification.outside_modeled_guarantee_witness_test", + "nonexistent_capability_ref", + "v2.lens.cost", + "capability_absent_from_decl_facts", + "", + ), ]; -pub fn next_rung_trigger_citation_findings( - index: &DeclarationIndex, -) -> Vec { - next_rung_trigger_citation_findings_against(index, NEXT_RUNG_TRIGGER_CITATIONS) +/// A control that has STOPPED refusing has lost its discriminating power, and that is a red in +/// its own right — the inverse of a spent debt row, and the reason these are a separate roster. +pub fn planted_control_findings(index: &DeclarationIndex) -> Vec { + planted_control_findings_against(index, PLANTED_CONTROL_CITATIONS) } -pub fn next_rung_trigger_citation_findings_against( +pub fn planted_control_findings_against( index: &DeclarationIndex, roster: &[(&str, &str, &str, &str, &str)], ) -> Vec { - resolved_roster_findings( - index, - roster, - DeclarationIntegrityKind::NextRungTriggerCitationResolved, - |citer, in_decl, module, decl, field| { - format!( - "NEXT_RUNG_TRIGGER_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as \ - an OutsideModeledGuarantee required_capability that must not exist yet, and it \ - now resolves — the stamp's climb has fired; delete this row and take the stamp \ - off OutsideModeledGuarantee", - citation_field_suffix(field) - ) - }, - ) + let still_refusing = refusing_sites(index); + roster + .iter() + .filter(|row| !still_refusing.contains(&site_owned(row))) + .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { + kind: DeclarationIntegrityKind::PlantedControlNoLongerRefuses, + rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), + offset: None, + message: format!( + "PLANTED_CONTROL_CITATIONS lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} as a \ + control that must NOT resolve, and it no longer refuses — the control has \ + lost its discriminating power and the mechanism it proves is now unevidenced", + if field.is_empty() { + String::new() + } else { + format!(" field `{field}`") + } + ), + }) + .collect() } /// The debt join, over an EXPLICIT roster. @@ -2211,19 +2128,26 @@ pub fn citation_debt_findings_named( roster: &[(&str, &str, &str, &str, &str)], roster_name: &str, ) -> Vec { - resolved_roster_findings( - index, - roster, - DeclarationIntegrityKind::CitationDebtRowStale, - |citer, in_decl, module, decl, field| { - format!( + let live = refusing_sites(index); + roster + .iter() + .filter(|row| !live.contains(&site_owned(row))) + .map(|(citer, in_decl, module, decl, field)| DeclarationIntegrityFinding { + kind: DeclarationIntegrityKind::CitationDebtRowStale, + rel_path: "src/v1/stage0/src/declaration_index.rs".to_string(), + offset: None, + message: format!( "{roster_name} still lists `{citer}` `{in_decl}` citing `{module}` `{decl}`{} — that \ citation no longer refuses, so the row is spent and must be deleted; the \ roster only shrinks", - citation_field_suffix(field) - ) - }, - ) + if field.is_empty() { + String::new() + } else { + format!(" field `{field}`") + } + ), + }) + .collect() } /// (2) The cited-symbol wall — §3's cite-the-symbol rule, executing. @@ -2428,7 +2352,6 @@ pub fn corpus_findings(index: &DeclarationIndex) -> Vec Vec Date: Mon, 7 Sep 2026 10:16:46 +0000 Subject: [PATCH 14/15] chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md subject_and_its_digest_as_independent_parameters Ledger-Repair-Judged: docs/design-rung-drops.md --- docs/design-failure-modes.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index 3af32b45425..f4044cbf8c4 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -286,7 +286,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - **a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.) - **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) - **a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.) -- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- the `.dag` instances named in `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` are the population that trigger retires.) +- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. The stall named as absent in an earlier draft of this closing is restored; this class's trigger is not that stall as a whole (DESIGN section 4b(3)), recorded in the following receipt.**THE STALL `wet_route_model_lags_seed_stall` IS RESTORED, AND THIS CLASS'S TRIGGER IS NOT THAT STALL AS A WHOLE (silent-badger-818, 2026-09-07).** Restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived). The FIRST receipt's next-rung trigger does not retire against that stall as a whole -- the recovered population spans two classes, so repairing only a content-digest member must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.) - **a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.)**THE ABSENCE FAMILY IS THIS ROW SHARPEST CONFIRMED POPULATION, AND IT IS RECORDED HERE RATHER THAN FILED AS A NEW CLASS -- THE REFUSAL TO APPEND IS THE FINDING** (sunny-carp-582, 2026-09-07). Seven lanes in one subtree hit the empty-value-read-as-a-positive-answer shape in a single night -- a completeness fold seeded true, a dedup key of the empty string dropping 45 call sites, an empty poll read as still-running that produced a fabricated eleven-hour duration and a false escalation, `$?` after piping a compiler through grep, a zero-line job log greppable as clean -- and several lanes moved to file rows for it. THEY DID NOT NEED TO: [[absent_reads_identically_to_never_looked]] was already there with a recognition rule that catches the shape, and the family around it already carried nine rows. THE FAILURE WAS NOT-CONSULTED, NOT NOT-FILED, which is precisely the state this row describes and is the strongest confirmation of it on record. Five of those specimens sit inside two rows that were ALREADY WRITTEN -- three in one night across two sessions in the reach row, two in one hour by two authors in [[absence_classifier_default_bucket]], the latter recording that BOTH AUTHORS HAD WRITTEN ABOUT THE CLASS SHORTLY BEFORE. RECENCY OF AUTHORSHIP IS THE STRONGEST RECALL CUE AVAILABLE AND IT DID NOT FIRE, which retires the last hypothesis that retrieval failure is a ledger-SIZE problem: those authors were not failing to find the row, they were not asking for it. **AND THE AUDIT SCORES ITSELF BY THIS ROW OBLIGATION, WHICH IS SYMMETRIC BY ITS OWN TERMS.** Its products are a checked family axis over nine members, pairwise non-substitutability of their repairs, seven exclusions with reasons, one nickname repaired to a rostered identity, and this refusal to file a duplicate class. THE NICKNAME REPAIR IS A REPAIR AT DESIGN SECTION 3 GRAIN: it was measured as a DELETED EDGE, invisible to the identity join that surveyed the family, so removing it restores something a query can reach. NOTHING ELSE IN THE AUDIT MAKES ANYTHING HARDER TO TYPE. The absence family therefore stands UNREMEDIED at the rungs its own rows declare, and no reader may cite this audit as coverage of it. What the audit adds toward the friction this row demands is a measured precondition rather than the friction itself: at the audited head the nine members carried ONE intra-family boundary citation between them, so any future mechanism that surfaces a relevant row would surface an ISLAND -- and surfacing eight unlinked overlapping rules to an author who then ignores all of them is worse than surfacing nothing. THE EDGES ARE THE PART THAT MUST EXIST BEFORE ANY SURFACING MECHANISM IS WORTH BUILDING, and that ordering is the audit only load-bearing recommendation. - **a gate that admits when its required evidence has not reported, because the admission arm keys on OBSERVED FAILURE rather than on OBSERVED SUCCESS.** INVALID STATE: a required check exists, is correctly configured, and is consulted -- and the consulting arm asks `has anything reported a failure` where the guarantee needs `has everything reported a success`. Between those two questions sits the state where nothing has reported at all, and it is admitted. HARM, AND THE REASON THE CLASS SURVIVES REVIEW: every artifact reads as present and correct. The gate is enumerated in the required roster, it is active, it blocks a reported failure exactly as advertised, and a reader auditing the configuration finds no drift -- because there is none. The defect is in the QUANTIFIER, and a quantifier has no configuration surface to inspect. DISTINGUISHING FACT, AND IT IS THE RACE RATHER THAN ANY FIELD: the class is only reachable inside the window between the evidence being DEMANDED and the evidence ARRIVING, so it is invisible to any observation taken after that window closes -- afterwards the check has reported, the record looks ordinary, and only the ORDER of two timestamps distinguishes an admitted merge from a blocked one. RECOGNITION RULE: for every gate, find the arm that admits and read what it is quantified over. If it enumerates the evidence that HAS arrived and asks a property of each, the empty enumeration admits. If it enumerates the evidence that is REQUIRED and asks each for a success, it refuses. The two spellings are one word apart and behave identically on every input except the one the class lives in. DISTINCT FROM `absorbing_fallback`: that arm WIDENS when it cannot compute an answer and is at least loud about doing work; this arm NARROWS to the empty set and is silent, because a fold over nothing returns its seed and nobody wrote the seed down as a decision. **SPECIMEN (eager-bear-107, gunbc#10236, 2026-09-03), and it landed a break rather than merely permitting one.** The pull request pushed head d8cd3034 at 19:49:33Z, GitHub created its `witnesses` run at 19:49:40Z, and the merge completed at 19:49:43Z -- three seconds after run creation, before any job of it reported. That run then concluded with `required-witnesses-build` and `required-witnesses-floor` both FAILURE, and the head it certified nothing about landed on main as cfe19ea7, adding two duplicate declarations to THIS MODULE that refused main at resolve until a repair pull request landed. WHICH LANE CAUGHT IT IS PART OF THE FILING, because the two main flakes are separable in this evidence and a reader who conflates them loses that: on the post-merge main run at cfe19ea7 the duplicates reddened `required-witnesses-build` while `required-witnesses-floor` was GREEN, so the break is not the cost class this repository's other main flake belongs to and cannot be waved away as more floor variance. THE DETECTING LANE WORKED AND WAS TWENTY MINUTES LATE, which is the shape of this class rather than an aggravating detail: `required-witnesses-build` refused the duplicates correctly -- `generated-artifact CarrierRefused cause=resolve`, the authority declining to answer -- and its job completed at 20:04:14Z against a merge at 19:49:43Z, an unadjudicated interval of twenty minutes and thirty-one seconds. NOTHING WAS MISROUTED AND NO LANE WAS MISSING. **A RETRACTION IS RECORDED HERE BECAUSE THE MISREADING IS ITSELF AN INSTANCE OF A ROSTERED CLASS.** An earlier revision of this row said the catcher was `heal-generated-artifacts` and that it was event-conditional, on the evidence that heal FAILED on the pull-request run and was SKIPPED on the main run of identical content. The job graph refutes it: heal died at step 2, `Checkout triggering branch head`, at 19:52:01Z, with `Regenerate every committed generated artifact` SKIPPED -- the regenerator never ran, so heal detected nothing, and it failed because the merge had deleted the branch head it wanted three seconds after the run was created. A downstream consequence of the merge was read as a detection of the defect. That is `green_reported_over_a_population_the_instrument_does_not_own` inverted -- a RED reported over a population the instrument never reached -- and the recognition rule transfers exactly: A JOB'S CONCLUSION IS NOT EVIDENCE ABOUT THE SUBJECT IT IS NAMED FOR UNTIL ITS STEP RECORD SHOWS IT REACHED THE STEP THAT JUDGES. It survived four readers passing a narrative and was caught by one who read the job graph. Ruleset 16178731 carried zero divergence from `gunbc.repo_ruleset` desired state throughout. Over the forty most recently merged pull requests, six had no `witnesses` run that completed successfully on their own head before `merged_at`. **THE SAME SHAPE IN THIS REPOSITORY'S OWN MODEL, which is what makes it a class and not an incident:** `gunbc.merge_lifecycle` `merge_enabled` folded `policy_admits` over the receipts found for a head from `init: false`, so the absent-receipt verdict was a caller-local constant standing in for a policy fact. There the seed was the SAFE answer and the harm was the mirror image -- the live behavior became unrepresentable, no witness could go red on it, and the module named a policy stronger than the live one as live for two months. RUNG FOUND AT: mitigatable, and only by human habit. CEILING: structurally guaranteed -- the merge queue construction makes the queued ref's run a precondition of landing rather than a fact observed beside it. NEXT TRIGGER: `gunbc.guarantee_stall` `merge_admission_terminal_verdict_stall`. FILED AS A STALL AND NOT A RUNG DROP: a 4b(3) drop asserts a REGRESSION and nothing regressed -- GitHub's rule has evaluated reported check runs this way since the ruleset was created, so the capability was never held and a previous rung would be invented. What existed was 4b(1) inflation, corrected by making the live policy representable.AUDITED AGAINST [[absence_classifier_default_bucket]] AND [[empty_observation_narrow]] AND FOUND DISTINCT RATHER THAN ASSUMED SO. Against the classifier row: that defect is an OPEN enumeration, a kind the accepted bucket complement never modeled, repaired by carrying the kind positively at construction; nothing is unmodeled here, the required check is named and correctly configured, and the admitted state is the EMPTY enumeration inside the demand-to-arrival window. Against the narrow row, whose third axis is an acquisition that returned NOTHING and a per-conclusion count over it rendering as clean: THAT IS THE NEAREST NEIGHBOUR IN THE WHOLE FAMILY AND IT IS STILL NOT THIS ROW. Its repair is a conservation assert -- refuse to believe any per-conclusion count until the TOTAL is nonzero -- which is a property a READER can add to a report; this row defect is in the ADMISSION ARM OF A GATE, whose ceiling is the merge queue making the queued ref run a precondition of landing rather than a fact observed beside it. A conservation assert on a report does not make a merge wait. The family axis and the full membership are carried once, in [[absent_reads_identically_to_never_looked]]. - **a right-censored cost read as an exact one** (an instrument stops because a POLICY THRESHOLD fired before the subject completed, and the figure it emits is a LOWER BOUND on the true cost. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost. WHAT MAKES IT INVISIBLE IS THAT THE BOUND LOOKS LIKE DATA: it has the right units, the right magnitude and the right shape, so nothing about the value marks it as incomplete. AND THE MAGNITUDE IS APPROXIMATELY THE CEILING THAT STOPPED IT, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts ABOVE genuinely expensive completed rows and a 'worst observed' derived from the population describes THE CEILING, NOT THE MACHINE. The remedy sized from it is then sized against a policy constant that the operator chose, wearing the authority of a measurement. RECOGNITION RULE: WHEREVER A COST, DURATION, SIZE OR COUNT CAN BE TRUNCATED BY A DEADLINE, BUDGET, RETRY CAP, PAGE LIMIT OR TIMEOUT, ASK WHETHER THE STOPPED CASE AND THE COMPLETED CASE INHABIT THE SAME CARRIER. If one field, column or constructor holds both, the conflation has already happened and no consumer can undo it -- the information distinguishing them was destroyed at the write, not at the read. The tell is a field named for the quantity (`cpu_ms`) rather than for the measurement's completeness, beside a separate flag nobody joins to it. THIS IS THE INVERSE OPERATION OF `censored_estimator_drops_its_own_tail` AND THE TWO MUST NOT BE MERGED. There, censored observations are EXCLUDED from an estimate and the statistic is biased low with no bound; here a censored observation is INCLUDED and read as exact. Dropping the tail and admitting the tail as a point are opposite mistakes over the same population, and a repair for one is not a repair for the other -- a system can and did commit both about the same artifact. It is also distinct from `window_rendered_subject_misattribution`: there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all. SPECIMEN, gunbc#10210. `required_floor_claim_cost.tsv` carried one `cpu_ms` column for every claim. A claim the per-claim CPU deadline preempted goes INTERRUPTED-BEFORE-VERDICT and reports where the POLL OBSERVED THE CEILING -- 500ms against a 500ms budget, or 502ms -- while a completed claim reports its cost. The floor cost distribution's bands, percentiles, worst-row and inflation pairing consumed the column undifferentiated, so the implied-budget derivation deflated a ceiling by a ratio computed partly from ceilings. RUNG FOUND AT: BELOW THE FLOOR, WHICH IS NOT RUNG 1 AND THE DISTINCTION IS THE POINT. Rung 1 requires harm CONTAINED by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing: it does not refuse, bound or prevent, and a censored value consumed where an exact cost is read is a FABRICATED PLAUSIBLE OUTPUT, which DESIGN section 4b places outside the ladder and forbids outright. This row was first filed claiming `mitigatable` and that was refused by review; the correction is recorded because the inflated reading was written by the author of the repair, inside the change that fixed it. IT IS EXPLICITLY NOT THE *OUTSIDE THE MODELED GUARANTEE* BOUNDARY ONE SENTENCE AWAY IN DESIGN. The cost is measured and then misrepresented; it is neither external, nor undecidable, nor unstated intent. A class that reaches the ladder only by ceasing to fabricate has not climbed a rung -- it has become eligible to be ranked. ATTAINABLE CEILING: STRUCTURALLY IMPOSSIBLE, because membership is decidable at the WRITE. The instrument always knows which arm it took -- it stopped the subject itself -- so the distinction is available at the moment the row is produced and needs no inference at any consumer. A carrier with disjoint constructors makes the conflated state unconstructible rather than merely refused. NEXT-RUNG TRIGGER, AND IT IS THE WHOLE PAIRING RATHER THAN ANY ONE OF ITS PARTS. Each half alone is satisfiable while the class stays alive, which is why a trigger naming less than all four is a trigger that retires the row while the harm persists: (i) DISJOINT CONSTRUCTORS, so a bound and a completion cannot inhabit one value; (ii) DISJOINT WIRE FIELD NAMES, because a shared column re-fuses them at the artifact boundary no matter how the in-memory type is shaped, and a consumer projecting that column gets an empty cell rather than a figure near the ceiling; (iii) EVERY ARITHMETIC CONSUMER REQUIRING THE EXACT TYPE IN ITS SIGNATURE, so summing, ranking or deflating a bound is a compile refusal rather than a discipline; and (iv) A DYNAMIC MIXED POPULATION THAT REFUSES RATHER THAN FILTERING, because silently dropping the censored members is `censored_estimator_drops_its_own_tail` -- the repair for one failure mode arriving as the other. THE FOURTH CLAUSE IS THE ONE AUTHORS OMIT, and omitting it converts this class into its inverse in a single edit that looks like a fix. A GUARD THAT EXCLUDES THE CENSORED POPULATION BY A CORRELATED PROXY IS NOT THIS REPAIR AND IS `incidental_denominator_as_wall`. In the specimen a verdict-absence flag very nearly separates the two populations, because a deadline-preempted claim also reaches no verdict -- but the axes are independent by construction: an unwound claim reaches no verdict with EXACT clocks, and a claim can reach its verdict while its cost is a bound. A witness keyed to the proxy stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted, so the proxy guard also DEFEATS THE EVIDENCE that would detect the class. THE REPAIR IS THEREFORE TWO ROWS, EACH FIXING ONE INPUT AND VARYING THE OTHER, and one of them alone proves nothing about the axis it is named for. **THE CENSORED MAGNITUDE IS RECOVERABLE WHERE THE STOPPED QUANTITY IS DETERMINISTIC, AND THAT DOES NOT MAKE THE CARRIER HONEST (jolly-ferret-412, folded here rather than filed as its own row, which would have been this class under a narrower name).** The floor preempts by polling every 1,024 eval steps, so an interrupted row's step count is 1024-quantised while a completed row reports its true count -- 172,032 = 168 x 1024 and 163,840 = 160 x 1024 against completing counts of 197,227 and 169,297. Because `eval_steps` for one identity is bit-stable across runs, a completing run supplies the denominator: interrupted steps over completed steps is the fraction of work reached, and the censored bound divided by that fraction recovers the magnitude. Two rows whose artifacts read `cpu_at_least` 504 and 524 against a 500ms budget had full costs near 578ms and 541ms, so quoting the bounds as the amounts by which they exceeded the budget understates the first by 74ms. **WHAT THAT RECOVERY IS FOR, STATED BECAUSE THE OPPOSITE READING IS THE COMFORTABLE ONE:** it yields a magnitude FOR ANALYSIS, and it is not a licence to keep consuming the conflated column on the ground that the number can be reconstructed later. The reconstruction needs a second observation of the same identity, a deterministic work metric, and an author who knows to pair them -- none of which a consumer projecting the column has. The four-clause trigger is unaffected by its existence, and clause (iii) is STRENGTHENED by it: a recovered figure is a THIRD kind of value, neither a completion nor a bound, and it must not inhabit the exact type either. A carrier that admitted it would have re-fused three populations instead of two. **THE DISCRIMINATION IS DECIDABLE FROM THE SAME ARTIFACT AND NEEDS NO RERUN.** `eval_steps` is host-independent and deterministic, so pair a refused row against a completing baseline for the same identity: steps AT OR BELOW baseline with materially higher cpu means the row did the same or less work more slowly, which is timing and not the author's change; steps ABOVE baseline means the row genuinely does more work and the diff owns it. The second arm needs no tolerance, because an interrupt can only LOWER the count -- exceeding the baseline despite being cut short is unambiguous. Measured over one refusing pair and four green runs: `eval_steps` is bit-stable on 3,592 of 3,595 planned identities, and the three that move do so by 5 to 9 steps on counts of 4,931, 6,127 and 10,090, so a cpu delta anywhere in this corpus is a timing delta and never a work delta. TWO LANES REACHED THAT TEST FROM OPPOSITE DIRECTIONS, WHICH IS THE STRONGEST THING SAYABLE ABOUT IT: one from asking what a refused row proves about a diff, one from asking what a REPEATED refusal would establish -- and the second lane's statement of it is the sharper one, that a RISING `eval_steps` is what would make a row a genuine cost debt while the VERDICT establishes almost nothing, since a second refusal at identical steps is the same finding with a worse duty cycle. **AND THE TEST HAS A THIRD ARM THAT REFUSES, BECAUSE THE TWO DO NOT PARTITION THE SPACE.** They are exhaustive on the step axis, but the first arm is a CONJUNCTION -- steps at-or-below AND cpu materially higher -- so a row with steps at-or-below and cpu NOT materially higher matches neither. That residue is probably empty, and the reason is itself a finding rather than an acquittal: an interrupt establishes cpu above the budget, so `not materially higher` requires a baseline already at the ceiling. Probably-empty argues for making it REFUSE cheaply, not for leaving it implicit -- an operator holding a two-arm test and an unclassified result files it under the nearest arm, which here is the EXONERATING one, so an incomplete partition produces SYSTEMATIC FALSE EXONERATION aimed at exactly the rows that match no pattern, and it conceals itself because an exonerated row is one nobody looks at again. READ THE ARTIFACT AND NOT THE JOB LOG: the log carries `fill_eval_steps`, `marginal_eval_steps` and `measured_eval_steps`, whose names CONTAIN the row-level field as a substring and whose values are different quantities, so a grep for `eval_steps=` over the log over-captures by more than thirteen to one and a lane following it compares the wrong column confidently.) From fbdb1ab0cfa000a618b9c7d19d55fda83765a8d8 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Mon, 7 Sep 2026 20:01:41 +0000 Subject: [PATCH 15/15] chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Rows-Repaired: docs/design-failure-modes.md subject_and_its_digest_as_independent_parameters Ledger-Repair-Judged: docs/design-rung-drops.md --- docs/design-failure-modes.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/design-failure-modes.md b/docs/design-failure-modes.md index 9057f9e2029..13ce75a9aaf 100644 --- a/docs/design-failure-modes.md +++ b/docs/design-failure-modes.md @@ -289,7 +289,7 @@ The landing measurement partitions the 31 parser-visible identities into **2 cit - **a subject defined by a CLOSURE with no enumerable membership cannot be protected in advance, only violated in arrears** (INVALID STATE: a receipt, cache key, or admission is pinned to a digest computed over a TRANSITIVE CLOSURE -- here the wet lane's `semantic_subject`, over the per-entry closure of 23 routed witness entries plus `v2.workflow.floor_wet_route`. The digest is a perfectly good detector and a useless protector: it reports a MISMATCH AFTER THE FACT rather than a MEMBERSHIP LIST BEFORE it. HARM: a two-hour dispatch completed and its receipt arrived uncommittable as `ReceiptSubjectDifferent`, because a commit landed inside the closure after the run's head. The lane that would break such a subject cannot decide for itself whether its diff intersects one, so the only available discipline is asking the holder afterwards -- which is not a discipline, it is a post-mortem. THE VISIBLE SURFACE IS NOT THE SUBJECT, and reporting it as one is the same defect in a different costume: the wet subject's visible surface is 19 files, while the resolver's own lines report 47 modules and 1180 resolved items for ONE entry, reaching transitively into `src/v2/std/` and `src/v2/compiler/`. A lane can invalidate the receipt while touching none of the 19 and doing nothing wrong. A list handed a completeness property by the mere fact that it is a list is the trap; the resolver's numbers are what refute it, which is why they are quoted rather than estimated. THE CONSEQUENCE FOR ANNOUNCEMENTS, recorded because it is the half that fools the announcer: a hold announced over an unenumerable subject is not protection, and the artifact recording that the announcement happened is indistinguishable from the protection existing. A hold nobody can check is WORSE than no hold, because its holder then treats the subject as protected. SCOPE, and it is wider than the specimen: EVERY subject-pinned receipt in this repository has this hole; the others have not noticed because none has yet burned a long run to it. RECOGNITION RULE: when a digest pins a subject, ask WHETHER ANYTHING PRINTS THE SUBJECT'S MEMBERSHIP. If the only instrument that knows the membership is the comparison itself, the subject is detectable and not defendable, and any fence described over it is a request rather than a constraint. NEXT-RUNG TRIGGER, a capability and not an artifact: a producer that PRINTS the closure membership for a routed entry, SUFFICIENT that a lane can decide FOR ITSELF, BEFORE LANDING, whether its diff intersects a live subject. THE POINTED PART, CORRECTED ONCE ALREADY AND THE CORRECTION IS THE WHOLE VALUE: the set is not merely computed and discarded, it is COMPUTED, HELD, AND RETURNED TO THE CALLER. In `v1_compiler.claim_batch` `resolve_timed`, the resolved graph is bound, its `modules` and `item_registry` are read for their LENGTHS to print the `[resolve]` line, and the whole graph is then handed back to the caller. Nothing is thrown away except THE NAMES, and only at the `eprintln!`. So the missing thing is an EMITTER over a set the process already holds and the caller already receives -- not an analysis, not a resolver change. THIS DISTINCTION IS THE ROW'S RUNG HONESTY AND 4b(2) TURNS ON IT: `nobody can determine this in advance` and `nobody has printed it` are different claims. The first is a permanent ceiling under which every future lane pays the same cost again; the second is an unbuilt next rung one emitter away. Filed as the former this row would sound honest and be wrong, and would foreclose its own repair -- which is this very class applied to our own tooling, a claim about a population made by an instrument that never enumerated it. RUNG FOUND AT: mitigatable, and the mitigation is a message. CEILING: mechanically preventable -- membership is decidable and computed, but a lane's intersection with a LIVE subject depends on which runs are in flight, which is external state observed at a boundary.) - **a bound is never EVALUATED for a whole population, so the first unrelated edit that makes one of them run discovers the line as a merge block** (INVALID STATE: an identity that the ordinary floor never plans is subject to a ceiling that has therefore never been exercised against it. Specimen: `test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_fabric_evidence_executes_without_gating` (DELETED 2026-09-04 with the lane it was about, and named here as the historical specimen rather than a live citation -- its successor `w_RED_the_deleted_lanes_do_not_return` inherits the same selection-gated position and therefore the same unevaluated bound) has ZERO planned rows on main -- checked in the `required-floor-claim-cost` artifact of two consecutive main runs, 0 of 3549 -- because it executes ONLY as a CHANGED witness. Its 500ms CPU line was first exercised by gunbc#9725, a change about the wet execution route, which touched `gunbc.witness_floor_workflow` and thereby made the witness changed; it refused at 504ms and 505ms on two heads. HARM: the discovering PR is not the causing PR in any sense its author can act on. The block arrives on a change that has nothing to do with cost, the author has no baseline to compare against because none was ever produced, and the only available dispositions are to enroll a debt row or to stall. THE NEIGHBOUR THIS IS NOT, and the distinction is the whole row: the NEAR-LINE family says a bound is MISPLACED -- measured over the whole corpus by the FLOOR-COST-500MS lane, 21 of the ~29 identities that can approach the line at all sit within +/-10% of it with nothing beyond 541ms, so the threshold was drawn through a cluster. This row says a bound was NEVER EVALUATED for a population at all. Different invalid state, different trigger, and the repairs diverge: a per-witness declared cost envelope fixes the misplaced line, and does NOT by itself cause the ceiling to be exercised for identities the ordinary floor does not plan. WHY IT IS STRUCTURALLY INVISIBLE TO THE OBVIOUS INSTRUMENT: a census that samples what the ordinary floor PLANS has this population outside its denominator BY CONSTRUCTION -- the cost lane's own survey could not see the class, and found it only when a lane that had tripped the line reported it. This is [[green_reported_over_a_population_the_instrument_does_not_own]] in the cost dimension: the survey was accurate about the rows it enumerated and silent about the rows it could not. RECOGNITION RULE: when a bound is declared per-identity but enforcement is gated on a SELECTION (changed, affected, sampled, scheduled), ask WHICH IDENTITIES THE SELECTION NEVER SELECTS ON THE MAINLINE. Those carry unevaluated bounds, and the population is discoverable in advance -- it is the declared identities minus the planned ones, both of which are already published per run. NEXT-RUNG TRIGGER, a capability and not an artifact: the ceiling is EXERCISED AND ITS RESULT PUBLISHED for every identity carrying one, including those the ordinary floor does not plan -- sufficient that a bound's first contact with an identity is a measurement someone chose to take, not a merge block on an unrelated change. Until then the class is discovered one PR at a time by whoever happens to edit the triggering authority. RUNG FOUND AT: mitigatable, and the mitigation is a debt row written after the fact. CEILING: mechanically preventable -- the unplanned population is a decidable set difference over data each run already emits.) - **a subject digest taken over RAW FILE CONTENT makes annotations semantically load-bearing, which is the property DESIGN section 4c declares impossible** (INVALID STATE: a receipt, cache key or admission is pinned to a digest computed by `v1_compiler.resolved_graph_cache` `closure_content_digest`, which folds each source's `content` -- the authored bytes -- rather than anything the annotation-erased projection would produce. So ADDING, DELETING OR REFLOWING A COMMENT in a module inside such a subject moves the digest. 4c states the opposite in terms: annotation capture is disjoint from semantic occurrence allocation, and adding, deleting or moving an annotation cannot alter any semantic occurrence identity, semantic graph, resolution result, SEMANTIC HASH, or target-program bytes. HARM, MEASURED RATHER THAN IMAGINED: on gunbc#9725 the wet lane's semantic subject folds `v2.workflow.floor_wet_route`'s own closure content, a receipt from a 2h31m dispatch was pinned to that digest, and an operator-granted one-shot lease pinned the same value as `exact_semantic_subject_digest`. Repairing a one-word COMMENT in that module would have voided the grant and forced a re-dispatch plus a second operator grant. Three real defects were therefore repaired in the seed and left standing in the substrate authority, which is filed separately as `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall`. The next occurrence will not be so visible: someone reflows a paragraph and silently invalidates a receipt with no diagnostic connecting the two. THE DISJUNCTION, because only one of these can be true and neither is currently written down. EITHER the closure content digest is NOT a semantic hash in 4c's sense -- in which case it must stop being read as one, and the distinction between a CONTENT identity (what bytes were on disk) and a SEMANTIC identity (what program they denote) has to be authored somewhere a reader meets before pinning anything to it. OR 4c's guarantee genuinely does not hold for this carrier, and 4c is overclaiming for every consumer that digests sources rather than the erased projection. RECOGNITION RULE: when a digest is described as a subject, a semantic subject, or a program identity, ask WHAT IT FOLDS. If the answer is file content, then comments, whitespace and formatting are inside it, and every guarantee stated about annotations being semantically inert is false of that digest -- while reading exactly like a guarantee about the program. The tell is a digest whose name says semantic and whose producer takes `content`. NEXT-RUNG TRIGGER, a capability and not an artifact: a subject digest folded over the ANNOTATION-ERASED projection that semantic passes already receive -- the same erasure 4c requires those passes to consume -- so that the digest is invariant under comment edits by construction and 4c's guarantee is true of it rather than merely stated near it. Failing that, the weaker form: the content digest is RENAMED to say it is a content identity and every pinning consumer is re-read against that meaning. RUNG FOUND AT: mitigatable, and the mitigation is that authors happen to know. CEILING: structurally impossible -- an erased-projection digest cannot move on an annotation edit, because the annotation is not in the input.) -- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- the `.dag` instances named in `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` are the population that trigger retires.) +- **a value and a summary of it -- a digest, a count, a view, an annotation -- placed side by side without a join can disagree silently, and the corroboration the reader believes they are getting was never computed** (INVALID STATE: a signature takes a value AND a summary of that value as two peer arguments -- `envelope` beside `envelope_digest`, `roster_identities` beside `roster_digest` -- with no arm relating them. The signature admits a digest of something OTHER than the value beside it; nothing refuses; and every downstream guarantee that cites the digest is then citing a summary of a different object, while reading exactly like a guarantee about the value. DISTINGUISHING FACTS: the two arguments are supplied by the same caller from the same site TODAY, so the pairing is held by lexical proximity rather than by anything the type system or a fold can see; the defect is constructible without touching a single caller, by supplying a correct digest of a different subject. EVIDENCE, TWO INSTANCES IN ONE MODULE, which is what makes it a class rather than a coincidence: `v2.workflow.floor_wet_route` `wet_route_gate_disposition_for_receipt` carries BOTH the envelope/digest pair and the roster-identities/roster-digest pair. The first was demonstrated live -- `v2.test.floor_wet_route` `wet_lease_admits_an_envelope_whose_content_the_digest_does_not_name` constructs an envelope whose content the pinned digest does not name, and the lease gate ADMITS. THE SAME DEFECT READ FROM THE OTHER END: agreement among derived views is vacuous when the views share one reader. A projection was nearly shipped with a row silently deleted because FOUR derived views agreed, all fed by a single reader -- one source feeding many views made agreement carry no information, exactly as a digest and its subject being independent lets them disagree unnoticed. THE THIRD FACE, AND THE ONE THAT SURVIVED REVIEW LONGEST: PROSE ADJACENCY IS NOT A JOIN EITHER. `wet_route_identity_rows_block_with_publication` carried an annotation stating that EXACTLY TWO per-identity classes are waived under a valid publication transaction, three lines above a body that returned false unconditionally and waived FOUR -- so `no_verdict`, the ABSENCE of a verdict, was converted into a green merge path. The prose and the code disagreed by a factor of two IN THE SAME FUNCTION and FOUR APPROVALS READ PAST IT. An annotation is not checked against the body it sits above by anything: it READS as documentation and FUNCTIONS as an assertion, and by DESIGN section 4c no `Accepted` program can read one, so nothing in the toolchain will ever disagree with it. Provider count is not attention -- four approvals is not four readings of that function. AND FIELD ADJACENCY IS NOT A JOIN EITHER, which is the same claim one scale down: in `v1_compiler.bin.claim_batch`'s two pre-execution refusal arms the annotation two lines above `WetReceiptIdentityRow` was RIGHT, and the neighbouring fields `observed_entry_rel` and `observed_function` were RIGHT -- Optional, and correctly None on exactly those arms -- and `wall_ms`, two fields later in the SAME STRUCT LITERAL, fabricates a 0 for a duration nothing measured. PROXIMITY TO A CORRECT THING IS NOT CORRECTNESS: a reader scanning that literal gets three signals of care and one fabrication, with nothing in the text distinguishing them. And 0 is the WORST available fabricated value for that field rather than a neutral placeholder, because it is THE FASTEST OBSERVABLE EXECUTION -- so a consumer that averages, thresholds or ranks on wall_ms without first branching on the outcome wire reads the ABSENCE of a measurement as the BEST measurement in the corpus. An anomalous-looking fabrication is found by whoever first sorts the column; this one sorts to the top and is found by nobody. All three faces are one defect: A JOIN THAT WAS NEVER MADE, so the corroboration a reader believes they are getting was never computed. RECOGNITION RULE: whenever a parameter list contains a value and a summary, hash, count, digest or identity OF that value, ask what refuses when they disagree. If the answer is nothing, the summary is unverified input wearing the costume of a derived fact. The mirror question for agreement: when N sources agree, ask how many INDEPENDENT reads produced them; if the answer is one, the agreement is a copy agreeing with itself. THE REPAIR, already built once and therefore not speculative: DERIVE THE DIGEST FROM THE VALUE AT THE POINT THE VALUE IS OBTAINED, NEVER ACCEPT IT AS A PEER PARAMETER. The seed`s `read_wet_receipt_envelope` now returns the decoded envelope and the digest of the bytes it decoded FROM, in one call, so the two cannot name different objects; its control `carried_digest_names_the_bytes_the_envelope_was_decoded_from` rewrites the file between reads and asserts the carried digest still names its own bytes. RUNG FOUND AT: mitigatable -- a comment and a caller convention. CEILING: structurally impossible, because a digest produced by the same operation that produces the value has no constructor that lets it name a different one. NEXT-RUNG TRIGGER, a capability: a carrier type that pairs a value with a digest DERIVED at construction, so no signature anywhere can accept the two separately -- SUFFICIENT FOR every remaining declaration that takes a value and a digest of that value as peer parameters. NOT retired by `gunbc.guarantee_stall` `wet_route_model_lags_seed_stall` as a whole: that recovered row (gunbc#9725 commit 32815827ef8) names three members spanning two classes, so repairing only a content-digest member would leave peer-parameter signatures writable (DESIGN section 4b(3)).)**THE ROW'S DECLARED REPAIR IS CONSTRUCTIBLE ONLY WHERE THE SUBJECT BYTES REACH A REALIZATION, AND THE TWO DIGEST SHAPES THAT LOOK ALIKE ARE NOT ALIKE.** This row declares the repair as already built once -- the seed's `read_wet_receipt_envelope` returns the decoded envelope and the digest of the bytes it decoded FROM in one call. Asking what it takes to apply that in `.dag` separates two shapes a name search conflates. `extdeps.crypto.hash` `sha256_digest` takes HEX: an author asserts a digest and nothing computes it, which is this class in its pure form. `extdeps.tools.sha256sum` `sha256sum_file_digest_via_shell` takes a PATH and the digest is COMPUTED over the bytes at that path, with a typed `Sha256FileDigestUnavailable` arm; under DESIGN section 3 that is a shell HANDLER bound to a digest shape, one of N, and it is live in `gunbc.instruments.fabric_control_plane_live_probe`. A computed digest at a host-tool-dependent rung is NOT an assertion, and an earlier draft of this receipt wrongly folded them together and claimed every digest in the corpus is asserted or verified out-of-band. It is not; that claim is withdrawn. WHAT SURVIVES IS NARROWER AND IS THE ACTUAL PRECONDITION: no `.dag` function takes `std.bytes` `Bytes` and returns a digest, so the repair is reachable exactly when the subject bytes EXIST AT A PATH and unreachable when they exist only in memory. That is a question about the realization, not about the class, and it must be answered per instance rather than defaulted. INSTANCE (fabric-m0, gunbc#10641): `gunbc.fabric_m0_completion` carries `manifest_digest` beside `members` on `CommitManifest`, and an `OriginObservation`'s digest is asserted rather than computed over the bytes read back, so a real readback digest paired with an arbitrary authored member set reads as a valid committed manifest. ANSWERED EXPLICITLY: this instance is NOT blocked. Its subjects are artifacts, receipts and a commit manifest -- stored objects -- and a durable-origin readback that stages what it fetched puts those bytes at a path, so the shell handler computes over exactly them and the chain is buildable at a mitigatable rung, with the in-substrate primitive as the CLIMB rather than the prerequisite. THE CONSTRAINT THAT REALIZATION MUST RESPECT, and it is specific: the digested file must be the ORIGIN readback's own output and never a cache copy, or the computation is a byte-exact confirmation of the wrong provenance -- the cache-read arm `gunbc.fabric_m0_commit` `manifest_readback_for_slot` already refuses. A computed digest over locally-sourced bytes would launder that refusal into a confirmation. THE ADJACENT DEFECT, REPAIRED, and it is a DIFFERENT one: the readback was a FIELD of every committed row, so a readback existed for every object by construction and 'was this read at all' had no representation. Reads are now a separate population joined by the authority, a subject lacking an observation resolves to undetermined, and seeding that case to satisfied reddens exactly the two witnesses written for it. That closes absence-of-a-read and does not close digest-to-bytes. THE HALF-REPAIR WAS DECLINED DELIBERATELY: a carrier holding bytes plus an ASSERTED digest plus decoded members relocates the fabrication to one boundary while simulating the byte layer, and reads as progress in review. The stall named as absent in an earlier draft of this closing is restored; this class's trigger is not that stall as a whole (DESIGN section 4b(3)), recorded in the following receipt.**THE STALL `wet_route_model_lags_seed_stall` IS RESTORED, AND THIS CLASS'S TRIGGER IS NOT THAT STALL AS A WHOLE (silent-badger-818, 2026-09-07).** Restored from commit `32815827ef8` on gunbc#9725 (recovered, not re-derived). The FIRST receipt's next-rung trigger does not retire against that stall as a whole -- the recovered population spans two classes, so repairing only a content-digest member must not satisfy a peer-parameter trigger (DESIGN section 4b(3)). `self_host_wet_route_receipt_lifetime_stall` is about route families and receipt lifetime and is NOT this population; a tidy section-3 retarget would invent the join this class files. The fabric-m0 instance in the preceding receipt is unchanged.) - **a written rule is how a LATER READER learns what happened; it is not how a PRESENT AUTHOR is stopped, so a ledger that grows without changing what is easy to type buys documentation and no prevention** (INVALID STATE: a failure class is answered by APPENDING A ROW -- to this roster, to a stall roster, to an annotation -- and the row is then counted as the remedy. The class recurs anyway, because at the moment of authoring the dangerous form is still the shortest thing to type and nothing costs more when it is chosen. RECOGNITION RULE, which is the whole row: after filing, ask WHAT IS NOW HARDER TO DO THAN IT WAS BEFORE. If the honest answer is nothing, the filing was a RECORD and not a REPAIR, the class rung did not move, and it must be reported as UNREMEDIED rather than as covered. WHY IT IS NOT MERELY WEAK BUT ACTIVELY MISLEADING: a filed class gets CITED AS COVERAGE, so a reviewer meeting it reads it as handled and the filing converts an open deficit into a closed-looking one while leaving the deficit exactly where it was -- a DESIGN section 4b(1) rung wearing a 4b(2) costume, which is this ledger own version of rung inflation. An unrepaired filing is therefore WORSE than no filing, not equal to it. WHY THE RECALL DOES NOT FIRE: a rule filed under its SUBJECT MATTER is retrieved by thinking about that subject matter, and an author executing a step attends to THE GOAL, not the class of the step. Nothing in `retire the superseded poller` cues `I am about to type a pattern that can match myself`. THE TEST RUN ON A REAL POPULATION THE SAME NIGHT IT WAS WRITTEN, AND IT CAME BACK MOSTLY NEGATIVE: across ten class-filings required in one day, the identity-join rows made nothing harder (`sort -u` is exactly as easy to type as `sort`); the prose-adjacency, field-adjacency and digest-beside-subject rows made nothing harder (no lens refuses a digest passed beside its subject, and that signature is still the natural one to write); the empty-reading rows made nothing harder (the short read is still shorter than the head-filtered one, which is precisely why four people reached for it). ONE of the ten changed what is easy, and IT WAS NOT A FILING: a schema hazard was answered by computing the affected population and commenting on each of the five pull requests about to hit it, delivering friction to five named authors rather than prose to a ledger. A second was initially scored as a climb and the correction is the sharper result: the carrier ALREADY HAD THE RIGHT SHAPE and nothing about it was built that day; what the day produced was the DISCOVERY that a wrong thing was writable beside it, because an author wrote a fabricated previous-rung into a drop row, A REGEN RAN GREEN OVER IT, and a reader happened to look at the field. NO MECHANISM WAS WATCHING. Corrected score: ONE push-friction instance that expires when five pull requests land, ZERO climbs, ONE discovery -- and the discovery is the least repeatable item in the list, since the next occurrence is written where nobody is reading and the green regen is identical. A LUCKY READ IS NOT COVERAGE. THE TWO KINDS OF FRICTION ARE NOT INTERCHANGEABLE AND ONLY ONE COMPOUNDS: PUSH friction is delivered to named authors at the moment of impact and EXPIRES when their changes land; PULL-PROOF friction removes the constructor, so nothing needs delivering to anyone ever again. A day producing one of each must not report two. THE CONCLUSION THE AUDIT FORCES, STRONGER THAN THIS ROW STARTED: retrieval-by-recall is not a mechanism that becomes adequate at a smaller ledger size -- IT IS THE WRONG MECHANISM AT ANY SIZE, because the retrieval cue never arrives regardless of how few rows there are. Every row real deliverable is THE FRICTION, and the prose is its RECEIPT rather than its product. RUNG FOUND AT: mitigatable, and this row is an instance of what it describes, which is why it carries a trigger rather than resting on having been written. CEILING: structurally impossible for any class whose dangerous form can be removed from the vocabulary entirely -- an unwritable form needs no rule. NEXT-RUNG TRIGGER, a capability and not an artifact: for each filed class, a named ARTEFACT OF FRICTION -- a lens that refuses the shape, a carrier with no unsafe constructor, a wrapper shorter to invoke than the raw form -- so that a filing arrives WITH a change in what is easy, and the obligation is symmetric: whoever ASKS for a row owes the friction artefact or the plain sentence that nothing got harder and the class stands UNREMEDIED.)**THE ABSENCE FAMILY IS THIS ROW SHARPEST CONFIRMED POPULATION, AND IT IS RECORDED HERE RATHER THAN FILED AS A NEW CLASS -- THE REFUSAL TO APPEND IS THE FINDING** (sunny-carp-582, 2026-09-07). Seven lanes in one subtree hit the empty-value-read-as-a-positive-answer shape in a single night -- a completeness fold seeded true, a dedup key of the empty string dropping 45 call sites, an empty poll read as still-running that produced a fabricated eleven-hour duration and a false escalation, `$?` after piping a compiler through grep, a zero-line job log greppable as clean -- and several lanes moved to file rows for it. THEY DID NOT NEED TO: [[absent_reads_identically_to_never_looked]] was already there with a recognition rule that catches the shape, and the family around it already carried nine rows. THE FAILURE WAS NOT-CONSULTED, NOT NOT-FILED, which is precisely the state this row describes and is the strongest confirmation of it on record. Five of those specimens sit inside two rows that were ALREADY WRITTEN -- three in one night across two sessions in the reach row, two in one hour by two authors in [[absence_classifier_default_bucket]], the latter recording that BOTH AUTHORS HAD WRITTEN ABOUT THE CLASS SHORTLY BEFORE. RECENCY OF AUTHORSHIP IS THE STRONGEST RECALL CUE AVAILABLE AND IT DID NOT FIRE, which retires the last hypothesis that retrieval failure is a ledger-SIZE problem: those authors were not failing to find the row, they were not asking for it. **AND THE AUDIT SCORES ITSELF BY THIS ROW OBLIGATION, WHICH IS SYMMETRIC BY ITS OWN TERMS.** Its products are a checked family axis over nine members, pairwise non-substitutability of their repairs, seven exclusions with reasons, one nickname repaired to a rostered identity, and this refusal to file a duplicate class. THE NICKNAME REPAIR IS A REPAIR AT DESIGN SECTION 3 GRAIN: it was measured as a DELETED EDGE, invisible to the identity join that surveyed the family, so removing it restores something a query can reach. NOTHING ELSE IN THE AUDIT MAKES ANYTHING HARDER TO TYPE. The absence family therefore stands UNREMEDIED at the rungs its own rows declare, and no reader may cite this audit as coverage of it. What the audit adds toward the friction this row demands is a measured precondition rather than the friction itself: at the audited head the nine members carried ONE intra-family boundary citation between them, so any future mechanism that surfaces a relevant row would surface an ISLAND -- and surfacing eight unlinked overlapping rules to an author who then ignores all of them is worse than surfacing nothing. THE EDGES ARE THE PART THAT MUST EXIST BEFORE ANY SURFACING MECHANISM IS WORTH BUILDING, and that ordering is the audit only load-bearing recommendation. - **a gate that admits when its required evidence has not reported, because the admission arm keys on OBSERVED FAILURE rather than on OBSERVED SUCCESS.** INVALID STATE: a required check exists, is correctly configured, and is consulted -- and the consulting arm asks `has anything reported a failure` where the guarantee needs `has everything reported a success`. Between those two questions sits the state where nothing has reported at all, and it is admitted. HARM, AND THE REASON THE CLASS SURVIVES REVIEW: every artifact reads as present and correct. The gate is enumerated in the required roster, it is active, it blocks a reported failure exactly as advertised, and a reader auditing the configuration finds no drift -- because there is none. The defect is in the QUANTIFIER, and a quantifier has no configuration surface to inspect. DISTINGUISHING FACT, AND IT IS THE RACE RATHER THAN ANY FIELD: the class is only reachable inside the window between the evidence being DEMANDED and the evidence ARRIVING, so it is invisible to any observation taken after that window closes -- afterwards the check has reported, the record looks ordinary, and only the ORDER of two timestamps distinguishes an admitted merge from a blocked one. RECOGNITION RULE: for every gate, find the arm that admits and read what it is quantified over. If it enumerates the evidence that HAS arrived and asks a property of each, the empty enumeration admits. If it enumerates the evidence that is REQUIRED and asks each for a success, it refuses. The two spellings are one word apart and behave identically on every input except the one the class lives in. DISTINCT FROM `absorbing_fallback`: that arm WIDENS when it cannot compute an answer and is at least loud about doing work; this arm NARROWS to the empty set and is silent, because a fold over nothing returns its seed and nobody wrote the seed down as a decision. **SPECIMEN (eager-bear-107, gunbc#10236, 2026-09-03), and it landed a break rather than merely permitting one.** The pull request pushed head d8cd3034 at 19:49:33Z, GitHub created its `witnesses` run at 19:49:40Z, and the merge completed at 19:49:43Z -- three seconds after run creation, before any job of it reported. That run then concluded with `required-witnesses-build` and `required-witnesses-floor` both FAILURE, and the head it certified nothing about landed on main as cfe19ea7, adding two duplicate declarations to THIS MODULE that refused main at resolve until a repair pull request landed. WHICH LANE CAUGHT IT IS PART OF THE FILING, because the two main flakes are separable in this evidence and a reader who conflates them loses that: on the post-merge main run at cfe19ea7 the duplicates reddened `required-witnesses-build` while `required-witnesses-floor` was GREEN, so the break is not the cost class this repository's other main flake belongs to and cannot be waved away as more floor variance. THE DETECTING LANE WORKED AND WAS TWENTY MINUTES LATE, which is the shape of this class rather than an aggravating detail: `required-witnesses-build` refused the duplicates correctly -- `generated-artifact CarrierRefused cause=resolve`, the authority declining to answer -- and its job completed at 20:04:14Z against a merge at 19:49:43Z, an unadjudicated interval of twenty minutes and thirty-one seconds. NOTHING WAS MISROUTED AND NO LANE WAS MISSING. **A RETRACTION IS RECORDED HERE BECAUSE THE MISREADING IS ITSELF AN INSTANCE OF A ROSTERED CLASS.** An earlier revision of this row said the catcher was `heal-generated-artifacts` and that it was event-conditional, on the evidence that heal FAILED on the pull-request run and was SKIPPED on the main run of identical content. The job graph refutes it: heal died at step 2, `Checkout triggering branch head`, at 19:52:01Z, with `Regenerate every committed generated artifact` SKIPPED -- the regenerator never ran, so heal detected nothing, and it failed because the merge had deleted the branch head it wanted three seconds after the run was created. A downstream consequence of the merge was read as a detection of the defect. That is `green_reported_over_a_population_the_instrument_does_not_own` inverted -- a RED reported over a population the instrument never reached -- and the recognition rule transfers exactly: A JOB'S CONCLUSION IS NOT EVIDENCE ABOUT THE SUBJECT IT IS NAMED FOR UNTIL ITS STEP RECORD SHOWS IT REACHED THE STEP THAT JUDGES. It survived four readers passing a narrative and was caught by one who read the job graph. Ruleset 16178731 carried zero divergence from `gunbc.repo_ruleset` desired state throughout. Over the forty most recently merged pull requests, six had no `witnesses` run that completed successfully on their own head before `merged_at`. **THE SAME SHAPE IN THIS REPOSITORY'S OWN MODEL, which is what makes it a class and not an incident:** `gunbc.merge_lifecycle` `merge_enabled` folded `policy_admits` over the receipts found for a head from `init: false`, so the absent-receipt verdict was a caller-local constant standing in for a policy fact. There the seed was the SAFE answer and the harm was the mirror image -- the live behavior became unrepresentable, no witness could go red on it, and the module named a policy stronger than the live one as live for two months. RUNG FOUND AT: mitigatable, and only by human habit. CEILING: structurally guaranteed -- the merge queue construction makes the queued ref's run a precondition of landing rather than a fact observed beside it. NEXT TRIGGER: `gunbc.guarantee_stall` `merge_admission_terminal_verdict_stall`. FILED AS A STALL AND NOT A RUNG DROP: a 4b(3) drop asserts a REGRESSION and nothing regressed -- GitHub's rule has evaluated reported check runs this way since the ruleset was created, so the capability was never held and a previous rung would be invented. What existed was 4b(1) inflation, corrected by making the live policy representable.AUDITED AGAINST [[absence_classifier_default_bucket]] AND [[empty_observation_narrow]] AND FOUND DISTINCT RATHER THAN ASSUMED SO. Against the classifier row: that defect is an OPEN enumeration, a kind the accepted bucket complement never modeled, repaired by carrying the kind positively at construction; nothing is unmodeled here, the required check is named and correctly configured, and the admitted state is the EMPTY enumeration inside the demand-to-arrival window. Against the narrow row, whose third axis is an acquisition that returned NOTHING and a per-conclusion count over it rendering as clean: THAT IS THE NEAREST NEIGHBOUR IN THE WHOLE FAMILY AND IT IS STILL NOT THIS ROW. Its repair is a conservation assert -- refuse to believe any per-conclusion count until the TOTAL is nonzero -- which is a property a READER can add to a report; this row defect is in the ADMISSION ARM OF A GATE, whose ceiling is the merge queue making the queued ref run a precondition of landing rather than a fact observed beside it. A conservation assert on a report does not make a merge wait. The family axis and the full membership are carried once, in [[absent_reads_identically_to_never_looked]]. - **a right-censored cost read as an exact one** (an instrument stops because a POLICY THRESHOLD fired before the subject completed, and the figure it emits is a LOWER BOUND on the true cost. Carried in the same field, column or type as a completed measurement, it is then summed, ranked, compared against a line, or deflated into a budget as though it were the cost. WHAT MAKES IT INVISIBLE IS THAT THE BOUND LOOKS LIKE DATA: it has the right units, the right magnitude and the right shape, so nothing about the value marks it as incomplete. AND THE MAGNITUDE IS APPROXIMATELY THE CEILING THAT STOPPED IT, which inverts every ranking built on it. A preempted row reports a figure near the budget, so it sorts ABOVE genuinely expensive completed rows and a 'worst observed' derived from the population describes THE CEILING, NOT THE MACHINE. The remedy sized from it is then sized against a policy constant that the operator chose, wearing the authority of a measurement. RECOGNITION RULE: WHEREVER A COST, DURATION, SIZE OR COUNT CAN BE TRUNCATED BY A DEADLINE, BUDGET, RETRY CAP, PAGE LIMIT OR TIMEOUT, ASK WHETHER THE STOPPED CASE AND THE COMPLETED CASE INHABIT THE SAME CARRIER. If one field, column or constructor holds both, the conflation has already happened and no consumer can undo it -- the information distinguishing them was destroyed at the write, not at the read. The tell is a field named for the quantity (`cpu_ms`) rather than for the measurement's completeness, beside a separate flag nobody joins to it. THIS IS THE INVERSE OPERATION OF `censored_estimator_drops_its_own_tail` AND THE TWO MUST NOT BE MERGED. There, censored observations are EXCLUDED from an estimate and the statistic is biased low with no bound; here a censored observation is INCLUDED and read as exact. Dropping the tail and admitting the tail as a point are opposite mistakes over the same population, and a repair for one is not a repair for the other -- a system can and did commit both about the same artifact. It is also distinct from `window_rendered_subject_misattribution`: there a correctly-measured figure is attributed to the wrong subject; here the subject is right and the figure is not a measurement at all. SPECIMEN, gunbc#10210. `required_floor_claim_cost.tsv` carried one `cpu_ms` column for every claim. A claim the per-claim CPU deadline preempted goes INTERRUPTED-BEFORE-VERDICT and reports where the POLL OBSERVED THE CEILING -- 500ms against a 500ms budget, or 502ms -- while a completed claim reports its cost. The floor cost distribution's bands, percentiles, worst-row and inflation pairing consumed the column undifferentiated, so the implied-budget derivation deflated a ceiling by a ratio computed partly from ceilings. RUNG FOUND AT: BELOW THE FLOOR, WHICH IS NOT RUNG 1 AND THE DISTINCTION IS THE POINT. Rung 1 requires harm CONTAINED by total operations, typed outcomes, bounds, rollback or isolation. A column rendering a bound and a completion under one name contains nothing: it does not refuse, bound or prevent, and a censored value consumed where an exact cost is read is a FABRICATED PLAUSIBLE OUTPUT, which DESIGN section 4b places outside the ladder and forbids outright. This row was first filed claiming `mitigatable` and that was refused by review; the correction is recorded because the inflated reading was written by the author of the repair, inside the change that fixed it. IT IS EXPLICITLY NOT THE *OUTSIDE THE MODELED GUARANTEE* BOUNDARY ONE SENTENCE AWAY IN DESIGN. The cost is measured and then misrepresented; it is neither external, nor undecidable, nor unstated intent. A class that reaches the ladder only by ceasing to fabricate has not climbed a rung -- it has become eligible to be ranked. ATTAINABLE CEILING: STRUCTURALLY IMPOSSIBLE, because membership is decidable at the WRITE. The instrument always knows which arm it took -- it stopped the subject itself -- so the distinction is available at the moment the row is produced and needs no inference at any consumer. A carrier with disjoint constructors makes the conflated state unconstructible rather than merely refused. NEXT-RUNG TRIGGER, AND IT IS THE WHOLE PAIRING RATHER THAN ANY ONE OF ITS PARTS. Each half alone is satisfiable while the class stays alive, which is why a trigger naming less than all four is a trigger that retires the row while the harm persists: (i) DISJOINT CONSTRUCTORS, so a bound and a completion cannot inhabit one value; (ii) DISJOINT WIRE FIELD NAMES, because a shared column re-fuses them at the artifact boundary no matter how the in-memory type is shaped, and a consumer projecting that column gets an empty cell rather than a figure near the ceiling; (iii) EVERY ARITHMETIC CONSUMER REQUIRING THE EXACT TYPE IN ITS SIGNATURE, so summing, ranking or deflating a bound is a compile refusal rather than a discipline; and (iv) A DYNAMIC MIXED POPULATION THAT REFUSES RATHER THAN FILTERING, because silently dropping the censored members is `censored_estimator_drops_its_own_tail` -- the repair for one failure mode arriving as the other. THE FOURTH CLAUSE IS THE ONE AUTHORS OMIT, and omitting it converts this class into its inverse in a single edit that looks like a fix. A GUARD THAT EXCLUDES THE CENSORED POPULATION BY A CORRELATED PROXY IS NOT THIS REPAIR AND IS `incidental_denominator_as_wall`. In the specimen a verdict-absence flag very nearly separates the two populations, because a deadline-preempted claim also reaches no verdict -- but the axes are independent by construction: an unwound claim reaches no verdict with EXACT clocks, and a claim can reach its verdict while its cost is a bound. A witness keyed to the proxy stays green under a fold that reads the bound as a cost, because its fixture is excluded before the cost is consulted, so the proxy guard also DEFEATS THE EVIDENCE that would detect the class. THE REPAIR IS THEREFORE TWO ROWS, EACH FIXING ONE INPUT AND VARYING THE OTHER, and one of them alone proves nothing about the axis it is named for. **THE CENSORED MAGNITUDE IS RECOVERABLE WHERE THE STOPPED QUANTITY IS DETERMINISTIC, AND THAT DOES NOT MAKE THE CARRIER HONEST (jolly-ferret-412, folded here rather than filed as its own row, which would have been this class under a narrower name).** The floor preempts by polling every 1,024 eval steps, so an interrupted row's step count is 1024-quantised while a completed row reports its true count -- 172,032 = 168 x 1024 and 163,840 = 160 x 1024 against completing counts of 197,227 and 169,297. Because `eval_steps` for one identity is bit-stable across runs, a completing run supplies the denominator: interrupted steps over completed steps is the fraction of work reached, and the censored bound divided by that fraction recovers the magnitude. Two rows whose artifacts read `cpu_at_least` 504 and 524 against a 500ms budget had full costs near 578ms and 541ms, so quoting the bounds as the amounts by which they exceeded the budget understates the first by 74ms. **WHAT THAT RECOVERY IS FOR, STATED BECAUSE THE OPPOSITE READING IS THE COMFORTABLE ONE:** it yields a magnitude FOR ANALYSIS, and it is not a licence to keep consuming the conflated column on the ground that the number can be reconstructed later. The reconstruction needs a second observation of the same identity, a deterministic work metric, and an author who knows to pair them -- none of which a consumer projecting the column has. The four-clause trigger is unaffected by its existence, and clause (iii) is STRENGTHENED by it: a recovered figure is a THIRD kind of value, neither a completion nor a bound, and it must not inhabit the exact type either. A carrier that admitted it would have re-fused three populations instead of two. **THE DISCRIMINATION IS DECIDABLE FROM THE SAME ARTIFACT AND NEEDS NO RERUN.** `eval_steps` is host-independent and deterministic, so pair a refused row against a completing baseline for the same identity: steps AT OR BELOW baseline with materially higher cpu means the row did the same or less work more slowly, which is timing and not the author's change; steps ABOVE baseline means the row genuinely does more work and the diff owns it. The second arm needs no tolerance, because an interrupt can only LOWER the count -- exceeding the baseline despite being cut short is unambiguous. Measured over one refusing pair and four green runs: `eval_steps` is bit-stable on 3,592 of 3,595 planned identities, and the three that move do so by 5 to 9 steps on counts of 4,931, 6,127 and 10,090, so a cpu delta anywhere in this corpus is a timing delta and never a work delta. TWO LANES REACHED THAT TEST FROM OPPOSITE DIRECTIONS, WHICH IS THE STRONGEST THING SAYABLE ABOUT IT: one from asking what a refused row proves about a diff, one from asking what a REPEATED refusal would establish -- and the second lane's statement of it is the sharper one, that a RISING `eval_steps` is what would make a row a genuine cost debt while the VERDICT establishes almost nothing, since a second refusal at identical steps is the same finding with a worse duty cycle. **AND THE TEST HAS A THIRD ARM THAT REFUSES, BECAUSE THE TWO DO NOT PARTITION THE SPACE.** They are exhaustive on the step axis, but the first arm is a CONJUNCTION -- steps at-or-below AND cpu materially higher -- so a row with steps at-or-below and cpu NOT materially higher matches neither. That residue is probably empty, and the reason is itself a finding rather than an acquittal: an interrupt establishes cpu above the budget, so `not materially higher` requires a baseline already at the ceiling. Probably-empty argues for making it REFUSE cheaply, not for leaving it implicit -- an operator holding a two-arm test and an unclassified result files it under the nearest arm, which here is the EXONERATING one, so an incomplete partition produces SYSTEMATIC FALSE EXONERATION aimed at exactly the rows that match no pattern, and it conceals itself because an exonerated row is one nobody looks at again. READ THE ARTIFACT AND NOT THE JOB LOG: the log carries `fill_eval_steps`, `marginal_eval_steps` and `measured_eval_steps`, whose names CONTAIN the row-level field as a substring and whose values are different quantities, so a grep for `eval_steps=` over the log over-captures by more than thirteen to one and a lane following it compares the wrong column confidently.)