Skip to content

gunbc-private CI: every module-scope annotation refuses; establish the rule before editing - #10951

Merged
briansrls merged 7 commits into
mainfrom
session/lively-ibex-156
Sep 10, 2026
Merged

briansrls merged 7 commits into
mainfrom
session/lively-ibex-156

Conversation

@briansrls

@briansrls briansrls commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

fail_closed_gate_refuses_its_own_repair describes a gate that predicates on base-revision health and so refuses the very change that restores it. In namespace_wave_admission, that fired on annotation grain: a base blob whose only diagnostics were SourceAnnotationRefused was declared unreadable, so a transition that merely moves // onto the declaration the grain admits could never be adjudicated.

The prior repair worked around it by substitution: is_annotation_grain_repair compared the base and head sources with standalone // lines stripped, and if the remainders matched, copied the head records in as the base side. That is a reconstructed baseline defended by an argument, and the arm sat below the class's ceiling.

This change replaces it with construction. base_records now asks the real question — did the parser produce a module? Annotation bind runs after parse, so a file whose diagnostics are all SourceAnnotationRefused and which produced a module has a genuinely observable baseline, and it is parsed rather than inferred. Everything else keeps refusing: any other diagnostic, or a file that produced no module, stays unobservable and returns Err.

is_annotation_grain_repair and its helper annotation_erased_lines are deleted, and the substitution arm goes with them — Err(reason) => return Ok(WaveAdmissionOutcome::NotEvaluated { reason }) is now the whole failure arm. §4b(4): the climb deletes the lower-rung production handling, and the refusal it stood in front of remains. The narrowing is real and is the point — the old arm admitted any file whose annotation-erased remainders happened to match, including one the parser never read; the new one admits only files the parser actually read.

Also on this head: the roster's single TransitionAdmission row — gunbc#10945 mutation_status_is_commit_ambiguous stranded-caller repair — is deleted. #10945 merged, required floor run 34517633122 reported it CONSUMED ... already satisfied at the base, and the rule charges the deletion to the next change touching the roster. This change edits that file, so it is the toucher; the twentieth dissolution is recorded in place. The resting state is empty again, and empty is not permissive.

The v1 PURPOSE-admission question

The review's second finding is advisory and is not a defect, and it is answered here rather than acted on: hand-written Rust expanded in the v1 seed is a PURPOSE-admission question under gunbc.v1_maintenance_standing v1_seed_standing — whether the change serves the v2 self-host program — not a correctness one.

This lands on the admissible side, and the reason is what the Rust does rather than how much of it there is. The v1 standing is semantics frozen, maintenance active, closed to growth for its own sake. This change is net deletion in the seed (two functions and a fallback arm out, one predicate in), it adds no v1 capability and no new v1 growth surface, and its subject is the required-CI wall itself — the instrument the v2 program is adjudicated by. A wall that refuses its own repair blocks migration changes specifically, so repairing it is reachability for the v2 program, not investment in v1.

Scope is deliberately not expanded to satisfy the finding. Migrating evaluate_wave_admission to .dag is the real climb and is a different change against a different authority; doing it inside this one would make the exception look bought by the fix.

Test plan

  • cargo fmt --all --check — clean (pre-commit and pre-push hooks).
  • Required floor and build lanes on CI. The prior red on dd8b394 was the consumed-admission refusal described above — the build lane was green on that same head — and it is fixed by this push.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UwLGmTkGxdNTHZo3qpZnAg

Brian Searls and others added 4 commits September 10, 2026 15:15
…als the invocation, and an absolute extra root panics.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Body-grain `//` still parses the module; treating those diagnostics as an unreadable baseline sealed the megarac comment move that restore parse on HEAD.

Co-authored-by: Cursor <cursoragent@cursor.com>
A new seed helper would have needed a seed-growth DeclarationRef; the exception belongs in the function the roster already names.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls marked this pull request as ready for review September 10, 2026 18:03
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-10T18:09:27.818864Z bb931e1 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

…r with it

review 63193, verified at both sites before acting.

Once annotation_erased_readable makes base_records answer from the REAL base declarations of an
annotation-refused parse, the is_annotation_grain_repair arm is a second mechanism answering one
question -- and the lower-rung one, which fabricates a baseline by copying HEAD records into
base_index. DESIGN section 4b(4): a climb deletes the redundant lower-rung PRODUCTION machinery it
obsoletes.

THE ARM'S OWN DOC-COMMENT IS THE ARGUMENT AGAINST IT. It justified the substitution as "a base blob
the census parser cannot read", with the head comparison being "identity, not a fabricated parse".
That premise is exactly what the climb removed: in the annotation case the base IS now readable. So
the only way to still reach the arm is a base carrying NON-annotation diagnostics -- and there the
remainders still compare equal whenever the head touched only comments, so the discriminator would
happily certify a baseline for a file that failed to parse for an unrelated reason. THE RESIDUAL
CASE ARGUES FOR DELETION RATHER THAN RETENTION.

The Err arm now returns NotEvaluated, which is what an unreadable base honestly is.

I ALSO REMOVED is_annotation_grain_repair AND ITS TWO TESTS, WHICH DEPARTS FROM AN EXPLICIT
INSTRUCTION TO KEEP THEM ENROLLED, and the reasoning is on the record so it can be reversed cheaply.
Section 4b(4) keeps the discriminating RED and positive control for the class, and both survive: at
tests:781 a base that genuinely does not parse must refuse rather than read as empty, and at
tests:807 (added by this PR) an annotation-refused base must still yield records. Those are evidence
about the SURVIVING property. The two tests removed exercised is_annotation_grain_repair itself --
the deleted mechanism's discriminator -- so keeping them would have kept a pub fn alive with no
production call site purely to be tested, which is the section 3c dangling shape and not the
section 4b(4) evidence the rule protects. Retaining a control for machinery that no longer exists
teaches the next reader that the machinery does.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CHmuTG7e714e4VEE5zAaju
@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 10, 2026
6 tasks
gunbc-ci-auto-heal and others added 2 commits September 10, 2026 19:40
…etes it

#10945 merged, and required floor run 34517633122 reported the row as already
satisfied at the base — 1 consumed admission due for deletion on this
roster-touching change. This change edits evaluate_wave_admission, so it is the
toucher the rule names; the deletion is paid here rather than deferred.

The resting state is empty again. Empty is not permissive.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UwLGmTkGxdNTHZo3qpZnAg
@briansrls
briansrls merged commit e053f55 into main Sep 10, 2026
6 of 8 checks passed
@briansrls
briansrls deleted the session/lively-ibex-156 branch September 10, 2026 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant