Skip to content

Delete the fixture mint: an admitted wrapper was an unrestricted constructor, so #10934's rung-4 claim was inflated - #10972

Merged
briansrls merged 25 commits into
mainfrom
session/lively-ibex-812
Sep 11, 2026
Merged

briansrls merged 25 commits into
mainfrom
session/lively-ibex-812

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

This is a correctness repair, not cleanup. Until it lands, #10934's rung-4 claim stands inflated on main: gunbc.fabric_m0_origin_readback and the subject_and_its_digest_as_independent_parameters receipt both assert a guarantee that was never held, because the fixture mint's admitted wrapper was a public unrestricted constructor. Nothing should cite that claim as evidence while this is open — not a climb, not a dissolution trigger, not a "this class is already at rung 4". DESIGN §4b(1): an inflated class never ranks for climbing, which makes it worse than sitting low honestly.

Follow-up to #10934, which merged with three review findings still open against its head. All three are probe-confirmed, not taken on faith. A fourth was found while repairing them.

The retraction, first

#10934 merged the claim that the sub-class was structurally impossible "outside the enumerated admission". That claim was not established at the head that merged it, so an inflated guarantee has been standing on main since. It is withdrawn — in the corpus row and in the module prose — and this PR re-earns it. "The rung is unchanged" would be the wrong sentence: the rung was never held. DESIGN §4b(1) is why this is written out rather than quietly corrected — an inflated class never ranks for climbing.

Finding 2 — why the claim was false

.dag has no module-private, so witness_origin_reading's admitted caller — a plain exported fn witness_reading(d) -> OriginReading — was itself an unrestricted constructor proxy:

resolved 66 sources … 0 blocking error(s), 431 advisory diagnostic(s)
compiled: 73 files emitted

admit_callers on the wrapper only moves the proxy one hop: every helper returning a value that carries a reading is the same escape (object_reads, confirmed, reads_with_* all were), and the cascade terminates only at functions carrying nothing outward. So the fixture route is deleted, not fenced. Mismatch arms moved to the recorded axis — an authority cannot choose what it reads back.

Egress answered mechanically, not assumed: every function in either witness module returning a reading-carrying value requires an OriginReading parameter, so it propagates and never mints. The only zero-argument egress is the sanctioned read, whose result a caller cannot aim.

The prerequisite — a finding of its own

crypto.Sha256Sum.File's mock_response interpolated the input path into its canned line. It was the only interpolation of its kind in any extdeps mock, refused NoSuchVariable on every hermetic call, and had therefore never once replayed — a mock that cannot execute, reading as hermetic coverage. Repaired to a literal, verified --dry-run before/after.

Correction: that mock, not a parameter rename, caused the earlier undefined variable: path. Two changes went in together and the rename got the credit. Isolated with a consumer containing no identifier path at all. Corrected in place rather than quietly edited.

The rung, as three propositions

proposition rung
i the digest was computed over the file the reading names re-earned structural impossibility, source→dag
ii the named file was the origin operation's own output mitigatable, unchanged
iii a caller-supplied /var/cache/… path remains possible must never be described as an origin read

Only (i) climbed.

Evidence standing, separated by instrument

  • Required hermetic witnesses — establish the modeled effect route and the verdict algebra using the mock. They do not establish that real bytes were hashed; the repaired mock makes that route executable, not wet.
  • The hand-run instrument tools.fabric_m0_origin_readback_probe — the only thing that shows the live handler computing over real bytes. No required lane runs it.
  • The compile-refusal battery — shows what the acceptance path refuses, and touches neither of the above.

Finding 3 — attribution

The battery counted by diagnostic class alone and accepted >= 1, while gunbc.compile_diagnostic_census states that CensusObserved carries every diagnostic the compile produced, the imported closure included. Counts are now keyed (class, subject_name, blocking) — subjects measured, not guessed — with a one-axis differential replacing the bare zero. CensusObserved is never treated as "compiled clean".

The foreign-wrapper control is evidence that the known escape remains deleted — not that every imaginable proxy is absent, which no probe over one source can show.

Finding 1 — prose stronger than the implementation

"A cache read has no route to a confirmation" was false. cache_manifest_read is a safe helper, not a total classifier, and the prose now says so.

New class filed

gunbc.recurring_failure_mode.admitted_call_edge_with_unrestricted_value_egress — an admission list confines the call edge and says nothing about where the value goes next. Recognition rule: do not ask who may call it, ask what may leave. Filed as its own class rather than folded into the digest row.

🤖 Generated with Claude Code

https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt

gunbc-ci-auto-heal and others added 5 commits September 10, 2026 05:37
… stamp

gunbc.fabric_m0_commit carried ManifestRead { observed_digest, source: ReadSource }
-- a digest and a provenance stamp as two peer values -- and refused the
DisposableCacheRead arm in a fold. That check was satisfied by editing the
DECLARATION while the realization still digested a local copy, which is the
review tell for validation standing where construction was available.

gunbc.fabric_m0_origin_readback now owns a sole_constructor RECORD, OriginReading,
pairing a staged path with the digest computed over it by one operation. ManifestRead
and ReadbackConfirmed carry that reading; ReadSource / DurableOriginRead /
DisposableCacheRead are deleted with the fold arm that refused them, and a cache read
reaches cache_manifest_read, whose only product is a located refusal.

The seal is on a RECORD because sole_constructor on a COPRODUCT does not refuse
cross-module variant construction (the hole f13_variant_construction_refuses measures);
sealing the coproduct would have been a permanently green wall.

Executed evidence: test.claim.fabric_m0_origin_readback_seal (three forged-literal REDs,
an unadmitted-mint RED, a green control on the sanctioned route, and a calibration that
the control compiled) and test.claim.fabric_m0_origin_readback_real_execution_witness
(real bytes: two fixture files digest to their own values, an absent path refuses, and
the whole gate publishes only when the readback digests the recorded manifest).

Rung, as the minimum: the sub-class "a confirming readback whose digest was not computed
over the file it names" is structurally impossible on source->dag outside an enumerated
admission. The enclosing class stays mitigatable -- staged_path is still caller-chosen --
with the capability trigger declared once in fabric_m0_origin_readback.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PbBMgVvnAq1DtmfKB51wDq
…ned regardless of the exclusion frontier

CI floor red on the landing run: five identities in
test.claim.fabric_m0_origin_readback_real_execution_witness errored
`undefined variable: path` and blocked as
changed_witness_planned_without_terminal_verdict.

TWO DEFECTS, and the second is the one worth writing down.

1. The parameter spelled `path` did not bind under whole-corpus preparation, while
   the same source ran green under a scoped entry compile. Renamed to `staged`.

2. The witness_exclusion_frontier row did NOT keep the wet file off the floor, and
   could not have: v2.workflow.required_floor
   required_floor_disposition_with_changed_selection REPLACES the ordinary
   disposition — DeclinedDiscoveryExcluded included — with PlannedAsChangedWitness
   for any identity the change touches. That is deliberate; the rule's own words are
   that the change is the moment its author is present to route it, rename it, or
   remove it. Under the hermetic envelope crypto.Sha256Sum.File replays one constant
   digest for every path, so the discriminating arm is false there by construction.

So the file is routed the third way: it becomes the instrument
tools.fabric_m0_origin_readback_probe with a `probe` entry and its recipe, per DESIGN
§6 (name the producer that re-derives the measurement), and the inert exclusion row is
deleted rather than left standing as coverage. Its standing is stated in the module: no
required lane executes it; the compile-refusal half in
test.claim.fabric_m0_origin_readback_seal is what runs per PR, and that one passed on
the failing run.

`gunbc run --claim-run ... --function probe` PASSes on the real tree.

The remaining floor phases (parse, namespace-wave-admission) are red on main at
0d6b665 with verdict=FloorClean and phases_failed=2 — inherited, not from this branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PbBMgVvnAq1DtmfKB51wDq
…tructor, so the rung-4 claim was inflated

Three findings from review, all probe-confirmed rather than taken on faith, plus one
found while repairing them.

FINDING 2 (the one that had to be fixed). The seal claimed the invalid state was
unwritable "outside an enumerated admission". It was not. .dag has no module-private,
so witness_origin_reading's admitted caller -- a plain exported
`fn witness_reading(d) -> OriginReading` -- was itself an unrestricted constructor
proxy. A foreign module importing it and passing any digest reached ManifestRead with
0 blocking errors. DESIGN 4b(1): an inflated class never ranks for climbing.

admit_callers on the wrapper would only move the proxy one hop, because every helper
returning a value CARRYING a reading is the same escape (object_reads, confirmed,
reads_with_* were all proxies) and the cascade terminates only at functions that carry
nothing outward. So the fixture route is DELETED, not fenced: both witness files now
obtain readings the only way anything can, by digesting a committed fixture file
through read_origin_staged_file. Mismatch arms move to the RECORDED axis -- an
authority cannot choose what it reads back. The escape's exact source is kept as a
permanent regression control (4b(4)).

PREREQUISITE, and a finding of its own: extdeps.crypto.hash crypto.Sha256Sum.File's
mock_response interpolated the input path into its canned line. It was the only such
interpolation in any extdeps mock, refused NoSuchVariable on every hermetic call, and
had therefore never once replayed -- a mock that cannot execute, reading as hermetic
coverage. Repaired to a literal; verified by running a consumer under --dry-run before
and after.

CORRECTION: that mock, not a parameter name, is what caused the `undefined variable:
path` on run 34441858589. Two changes went in together and the rename got the credit.
Isolated by running a consumer with no identifier `path` in it at all. The false
attribution is corrected in place rather than quietly edited.

FINDING 3. The seal battery counted by diagnostic CLASS alone and accepted >= 1, while
gunbc.compile_diagnostic_census states that CensusObserved carries every diagnostic the
compile produced, the imported closure included. Every count is now keyed
(class, subject_name, blocking) -- subjects measured, not guessed -- and the bare-zero
calibration is replaced by a one-axis differential where the shared closure cancels.

FINDING 1. "A CACHE READ HAS NO ROUTE TO A CONFIRMATION" was stronger than the
implementation: a caller can hand a /var/cache path to read_origin_staged_file and get
an honest confirming reading. cache_manifest_read is a safe helper, not a total
classifier, and the prose now says so. Path provenance stays the mitigatable enclosing
class with its capability trigger; the rung is unchanged.

Executed: six seal arms PASS with exact keys; commit witnesses PASS wet and hermetic,
including the mismatch arm; the wet instrument PASSes end to end.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
# Conflicts:
#	dag/gunbc/fabric/fabric_m0_commit.dag
#	dag/gunbc/fabric/fabric_m0_origin_readback.dag
#	dag/gunbc/instruments/fabric_m0_origin_readback_probe.dag
#	dag/gunbc/recurring_failure_mode/subject_and_its_digest_as_independent_parameters.dag
#	dag/test/claim/fabric_m0_commit_witness_test.dag
#	dag/test/claim/fabric_m0_completion_witness_test.dag
#	dag/test/claim/fabric_m0_origin_readback_seal_test.dag
@gunbai-bot gunbai-bot Bot changed the title fabric-M0 B2: origin-readback discipline as a construction Delete the fixture mint: an admitted wrapper was an unrestricted constructor, so #10934's rung-4 claim was inflated Sep 10, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 10, 2026 21:35
gunbc-ci-auto-heal and others added 2 commits September 10, 2026 21:48
…cape belongs to

The wording repairs the previous commit's code changes earn but its text did not say.

RETRACTION, NOT ADJUSTMENT. #10934 merged the claim that the sub-class was
structurally impossible "outside the enumerated admission". That claim was NOT
established at the head that merged it -- the public wrapper route was open -- so an
inflated guarantee stood on main between that merge and this PR. "The rung is
unchanged" was the wrong sentence: the rung was never held. It is withdrawn in the
corpus row and in the module prose, and this PR re-earns it.

THREE PROPOSITIONS, UNBLURRED. (i) the digest was computed over the file the reading
names -- re-earned structural impossibility on the source-to-dag path; (ii) the named
file was the origin operation's own output -- still mitigatable; (iii) a
caller-supplied /var/cache path remains possible and must never be described as an
origin read. Only (i) climbed.

EVIDENCE STANDING, SEPARATED BY INSTRUMENT. The required hermetic witnesses establish
the modeled effect route and the verdict algebra USING THE MOCK; they do not establish
that real bytes were hashed. The repaired mock makes that route executable, not wet.
Only the hand-run instrument shows the live handler computing over real bytes, and no
required lane runs it. The compile-refusal battery shows a third thing and touches
neither.

NARROWER REGRESSION CLAIM. The foreign-wrapper control is evidence that the KNOWN
escape remains deleted, not that every imaginable proxy is absent.

EGRESS ANSWERED, NOT ASSUMED. Enumerated mechanically: every function in either witness
module returning a value that carries an OriginReading requires one as a parameter, so
it propagates and never mints. The only zero-argument egress is the sanctioned read,
whose result a caller cannot aim.

NEW CLASS FILED SEPARATELY: gunbc.recurring_failure_mode
admitted_call_edge_with_unrestricted_value_egress -- an admission list confines the CALL
EDGE and says nothing about where the value goes next, so a sealed constructor with an
admitted caller is sealed only if that caller's egress is closed. Recognition rule: do
not ask who may call it, ask what may leave. It is its own class rather than folded into
the digest row, which is about a value and a summary standing side by side.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
…iants #10934 deleted

main's required floor fails the declarations phase with IMPORT-MEMBER-ABSENT at
dag/test/claim/fabric_m0_publication_witness_test.dag:39-40, which blocks the floor for
every open PR in the repo. Two individually-green PRs from one lane, incompatible only
once both were on main: #10933 landed this witness against the old shape while #10934
replaced ManifestRead's digest-plus-provenance-stamp pair with a sealed OriginReading
and deleted ReadSource / DurableOriginRead / DisposableCacheRead with it. The file also
still built ReadbackConfirmed { observed_digest }, so the two imports were the visible
half of a wider skew.

The repair INHABITS the new construction rather than reaching around it: the reading
comes from read_origin_staged_file over a committed fixture file, the recorded digest is
DERIVED from that reading so a success arm cannot drift from what was read, and the
cache arm goes through cache_manifest_read. Restoring the deleted variants, or adding
this module to witness_origin_reading's admit_callers, would both have been smaller and
both would have re-opened what #10934 closed.

CARRIES ONE LINE OF extdeps.crypto.hash, and it is a prerequisite rather than scope
creep: crypto.Sha256Sum.File's mock_response interpolated the input path into its canned
line -- the only interpolation of its kind in any extdeps mock -- so it refused
NoSuchVariable on every hermetic call and had never once replayed. Without that repair
these witnesses cannot execute hermetically at all, which is exactly what they did here
before it was applied. The same one-line change is also in #10972; whichever lands
second sees no conflict.

Executed hermetically (--dry-run, the envelope CI uses): all five publication witnesses
PASS, including the cache-read refusal and the two pending arms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
gunbc-ci-auto-heal and others added 3 commits September 10, 2026 23:07
This witness declared SubstrateInputsOnly and was correct to: it was a pure fold over
authored fixtures. The repair in this PR makes it call read_origin_staged_file over a
committed repository path, which reaches a live-checkout sink, so the stamp became a
declaration asserting something its own body contradicts -- and nothing in the toolchain
compares the two.

Found by review on the sibling PR (#10972, review 63276), which caught the same class in
all three fabric-M0 witness files. It is the stale-evidence class this lane has been
repairing all along, one scale down: a carrier-grain declaration that outlives the body
it describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
…al real, and stop three stamps from lying

Review 63276 (REQUEST_CHANGES) on #10972, both findings verified at source before fixing.

RED 4 WAS UNKEYED, and it was the worst place for that defect to be: it is the permanent
4b(4) regression control for the escape this PR exists to close. It read "any blocking
diagnostic anywhere >= 1", and its own comment claimed the assertion was on the
unresolved-reference class while the code asserted no class and no subject.

MEASURED RATHER THAN GUESSED: dumping the blocking key set of that probe's closure
returns FORTY-FIVE rows -- UnresolvedType on Time, Memory, Frequency and thirty more,
plus an InternalError cascade -- so the control was satisfied by closure noise. If the
wrapper proxy came back AND any unrelated blocking row existed, it would stay green and
report the escape as still closed. The proposition is "the wrapper symbol is gone", the
row that says so is MissingExport on witness_reading, and there is exactly one of it.

THE DIFFERENTIAL IS NOW REAL. Both arms come from one probe_source producer, so module
header, import block and signature are byte-identical and only the constructing
expression differs. The comparison is over the COMPLETE blocking key set of each
compile, not a chosen target key: everything present on both sides cancels, exactly one
key survives on the RED side (SoleConstructorViolation|OriginReading), and nothing
survives on the GREEN side. The previous form compared two hand-written sources whose
imports differed, so the shared closure was ASSUMED to cancel rather than shown to. A
calibration arm carries the CensusNotRunnable sentinel into the key set so a
both-sides-failed census cannot cancel and read as agreement.

EXACT COUNTS where exactly one refusal is the proposition, replacing >= 1, so a second
unintended refusal is visible instead of absorbed.

THE LIVE-TREE STAMPS WERE LYING. All three fabric-M0 witness files declared
SubstrateInputsOnly and were correct to before this PR; deleting the fixture mint makes
them call read_origin_staged_file over a committed repository path, which reaches a
live-checkout sink. Nothing in the toolchain compares a stamp to the body beneath it, so
this is the stale-evidence class this lane keeps finding, one scale down: a
carrier-grain declaration that outlived the body it describes. The publication witness's
stamp is fixed on #10977 as well, since that PR introduces the same call.

Executed: all seven seal arms PASS, including the complete-key differential and its
calibration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Both findings from review 63276 verified at source and fixed in a05f601.

RED 4 was unkeyed, and that was the worst place for the defect to be — it is the permanent §4b(4) regression control for the escape this PR exists to close. Its comment claimed the assertion was on the unresolved-reference class; the code asserted no class and no subject.

I measured the closure rather than guessing at a key. That probe's blocking key set is 45 rows — UnresolvedType on Time, Memory, Frequency and thirty more, plus an InternalError cascade. So >= 1 on "any blocking" was satisfied by closure noise: reintroduce the wrapper and have any unrelated blocking row present, and the control stays green while reporting the escape closed. Now keyed on the row that actually states the proposition — MissingExport × witness_reading, == 1.

The differential is now real. Both arms come from one probe_source producer, so module header, import block and signature are byte-identical and only the constructing expression differs. The comparison is over the complete blocking key set of each compile, not a chosen target key: everything on both sides cancels, exactly one key survives on RED (SoleConstructorViolation|OriginReading), nothing survives on GREEN. The previous form compared two hand-written sources whose imports differed — the shared closure was assumed to cancel, and your reviewer was right that it had not been shown to. A calibration arm carries the CensusNotRunnable sentinel into the key set so a both-sides-failed census cannot cancel into apparent agreement.

>= 1 is replaced by == 1 wherever exactly one refusal is the proposition.

The live-tree stamps were lying, and this one I would not have caught. All three fabric-M0 witness files declared SubstrateInputsOnly — correct before this PR, false after it, because deleting the fixture mint makes them call read_origin_staged_file over a committed repository path and reach a live-checkout sink. Nothing in the toolchain compares a stamp to the body beneath it. That is the same stale-evidence class this lane keeps finding, one scale down: a carrier-grain declaration outliving the body it describes. Fixed in all three, including on #10977, which introduces the same call and would otherwise have landed the same lie.

Executed: all seven seal arms PASS, including the complete-key differential and its calibration.

— sent from lively-ibex-812

briansrls pushed a commit that referenced this pull request Sep 10, 2026
…iants #10934 deleted (#10977)

* Repair main: the publication witness still imports the ReadSource variants #10934 deleted

main's required floor fails the declarations phase with IMPORT-MEMBER-ABSENT at
dag/test/claim/fabric_m0_publication_witness_test.dag:39-40, which blocks the floor for
every open PR in the repo. Two individually-green PRs from one lane, incompatible only
once both were on main: #10933 landed this witness against the old shape while #10934
replaced ManifestRead's digest-plus-provenance-stamp pair with a sealed OriginReading
and deleted ReadSource / DurableOriginRead / DisposableCacheRead with it. The file also
still built ReadbackConfirmed { observed_digest }, so the two imports were the visible
half of a wider skew.

The repair INHABITS the new construction rather than reaching around it: the reading
comes from read_origin_staged_file over a committed fixture file, the recorded digest is
DERIVED from that reading so a success arm cannot drift from what was read, and the
cache arm goes through cache_manifest_read. Restoring the deleted variants, or adding
this module to witness_origin_reading's admit_callers, would both have been smaller and
both would have re-opened what #10934 closed.

CARRIES ONE LINE OF extdeps.crypto.hash, and it is a prerequisite rather than scope
creep: crypto.Sha256Sum.File's mock_response interpolated the input path into its canned
line -- the only interpolation of its kind in any extdeps mock -- so it refused
NoSuchVariable on every hermetic call and had never once replayed. Without that repair
these witnesses cannot execute hermetically at all, which is exactly what they did here
before it was applied. The same one-line change is also in #10972; whichever lands
second sees no conflict.

Executed hermetically (--dry-run, the envelope CI uses): all five publication witnesses
PASS, including the cache-read refusal and the two pending arms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt

* The live-tree stamp had to change with the body

This witness declared SubstrateInputsOnly and was correct to: it was a pure fold over
authored fixtures. The repair in this PR makes it call read_origin_staged_file over a
committed repository path, which reaches a live-checkout sink, so the stamp became a
declaration asserting something its own body contradicts -- and nothing in the toolchain
compares the two.

Found by review on the sibling PR (#10972, review 63276), which caught the same class in
all three fabric-M0 witness files. It is the stale-evidence class this lane has been
repairing all along, one scale down: a carrier-grain declaration that outlives the body
it describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ag entries' consumer

Review 63291 (REQUEST_CHANGES), verified at source: `digest_a_unused_marker` had exactly
one occurrence in the tree -- its own definition -- with a stray blank line as its first
body line. It is the authored "aaaa..." digest left over from the deleted fixture-mint
route, surviving as an artifact of the scripted rename that replaced it, under a name
that admits it is unused. DESIGN 3c makes an unconsumed declaration with no declared
frontier the red state and 6 names it experimental residue, doubly so in a PR whose
whole point is that success arms DERIVE their digest from the reading instead of
authoring one. Deleted rather than given a frontier, because there is no later consumer
to name.

SWEPT FOR THE SAME CLASS rather than fixing only the reported instance, since these files
were edited by transform and that is exactly how such residue appears. The first sweep
was useless and worth saying so: counting textual references flagged all 58 `test fn`s,
which the harness consumes without any reference -- a candidate list, not a detector.
Filtered to non-harness declarations, the only survivors are the three `diag_*` printed
diagnostics, which are a real consumption route rather than residue: they are entry
points a person runs when an arm reds, the same shape as the f10_diag_* / f13_diag_*
entries in test.claim.sole_constructor_completeness_audit_probe. Their consumer and the
exact invocation are now stated in the file instead of left to be inferred.

Executed after the deletion: completion witnesses still PASS hermetically, seal battery
compiles clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Verified and fixed in 7cf9f57. Review 63291 was right: digest_a_unused_marker had exactly one occurrence in the tree — its own definition — with a stray blank line as its first body line. It is the authored "aaaa…" digest left over from the deleted fixture-mint route, surviving as an artifact of the scripted rename that replaced it. Deleted, not given a frontier: there is no later consumer to name, and §3c only admits a frontier when the trigger can be stated.

I swept for the class rather than fixing the one instance, since these files were edited by transform and that is precisely how such residue appears. Worth reporting that my first sweep was useless: counting textual references flagged all 58 test fns, because the harness consumes them without any reference — a candidate list, not a detector. Filtered to non-harness declarations, the only survivors are the three diag_* printed diagnostics.

Those are not residue — they are entry points a person runs when an arm reds, the same shape as the f10_diag_* / f13_diag_* entries in test.claim.sole_constructor_completeness_audit_probe. But you were right that inhabitance should be legible rather than inferred, so their consumer and the exact invocation are now stated in the file.

Executed after the deletion: completion witnesses still PASS hermetically; the seal battery compiles clean.

— sent from lively-ibex-812

gunbc-ci-auto-heal and others added 2 commits September 10, 2026 23:40
Both findings verified at source before fixing.

TWO AXES CALLED ONE. The pair shared imports and signature prefix but the bodies differed
in RETURN TYPE as well as expression -- OriginReading vs OriginReadingOutcome -- so a
delta attributable to the type change alone was not excluded. That is the same overclaim
class this PR exists to repair, and the second one I have had to correct in this file.

A SAME-RETURN-TYPE PAIR TURNED OUT TO BE AUTHORABLE, so it is built rather than
disclosed: both arms now return OriginReadingOutcome, which works because that is an
ordinary coproduct whose OriginReadingTaken variant CARRIES the sealed record. The forged
arm must still write the forbidden literal and still refuses on it, while the shapes on
either side match exactly.

And the reason a bare-OriginReading pair is NOT authorable is worth stating, because it
is the wall itself: a green arm returning a bare reading would have to unwrap the
Outcome, and the unavailable branch would then need to produce an OriginReading from
nothing -- which is exactly what has no constructor.

SET DIFFERENCE IGNORED MULTIPLICITY. keys_only_in filtered "keys of a absent from b", so
a key occurring twice on the red side and once on green cancelled completely and a second
unintended refusal on an already-shared key was invisible -- the precise failure the == 1
assertions elsewhere in this file exist to close, left open in the comparison meant to be
the strictest thing here. Replaced by a per-key multiset comparison over the distinct key
union: the target key must be exactly one higher on the red side, and EVERY other key must
match in count.

The calibration arm drops its inverted key_only_in trick for a direct count of the
CENSUS-NOT-RUNNABLE sentinel on each side.

Unaffected and unchanged: the three == 1 refusal assertions and MissingExport x
witness_reading == 1.

Executed: all seven arms PASS. The delta check passing is itself the stronger result --
it says the two closures are identical count-for-count on every key except the wall.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Both verified at source and fixed in 95cc0ac.

The pair varied two axes and I called it one — imports and signature prefix were shared, but the bodies differed in return type as well as expression (OriginReading vs OriginReadingOutcome), so a delta attributable to the type change alone was not excluded. That is the same overclaim class this PR exists to repair, and the second one I have had to correct in this file.

A same-return-type pair turned out to be authorable, so it is built rather than disclosed. Both arms now return OriginReadingOutcome. That works because OriginReadingOutcome is an ordinary coproduct whose OriginReadingTaken variant carries the sealed record — so the forged arm must still write the forbidden literal and still refuses on it, while the shapes on either side match exactly.

And the reason a bare-OriginReading pair is not authorable is worth stating, because it is the wall itself: a green arm returning a bare reading would have to unwrap the Outcome, and the unavailable branch would then need to produce an OriginReading from nothing — which is exactly what has no constructor.

The set difference ignored multiplicity, and this one was unambiguous. keys_only_in filtered "keys of a absent from b", so a key occurring twice on RED and once on GREEN cancelled completely — a second unintended refusal on an already-shared key was invisible. That is the precise failure the == 1 assertions elsewhere in this file exist to close, left open in the comparison meant to be the strictest thing here. Replaced by a per-key multiset comparison over the distinct key union: the target key must be exactly one higher on RED, and every other key must match in count.

The calibration arm drops its inverted keys_only_in trick for a direct count of the CENSUS-NOT-RUNNABLE sentinel on each side.

Unaffected, as you noted: the three == 1 refusal assertions and MissingExport × witness_reading == 1.

Executed: all seven arms PASS. The delta check passing is itself the stronger result — it now says the two closures are identical count-for-count on every key except the wall.

— sent from lively-ibex-812

…d it was the weaker one

Review 63308, both findings verified at source.

A SECOND IMPLEMENTATION OF ONE FACT. My seal battery hand-rolled blocking_keys /
key_count / distinct_keys / key_delta_is_exactly over "class|subject" strings. That
comparator already existed, general and row-typed, in
test.claim.machine_intake.no_fallback_plan_ineligibility_wall_test -- and
gunbc.compile_diagnostic_census names THAT RECEIPT by name as the authority for exactly
these two exact forms. Two sources that can drift for one fact is the DESIGN 3 fork.

AND THE COPY DROPPED count, which is the defect the previous commit claimed to close.
The census module states in its own words that census_total_count sums counts rather than
rows, so a class occurring twice is two occurrences. My key_count tallied ROW ENTRIES, so
a red row with count 2 and a green row with count 1 at one key still cancelled -- the
multiplicity blindness I had just replaced set-difference to remove, reintroduced one
layer down. It also made "one" mean two things in the same file: keyed_count summed
r.count, key_count did not.

THE REPAIR IS THE HOME, NOT A THIRD COPY. census_key_count, census_key_delta and
censuses_differ_by_exactly_the_target_key now live in gunbc.compile_diagnostic_census --
the module that owns the rule -- parameterised by the target key. Naming a receipt as the
authority for a form does not make the form reusable; the function does, and the proof is
that the next battery to need it re-implemented it and got it wrong.

BOTH CONSUMERS MIGRATED, so there is one implementation rather than three: the
machine_intake receipt keeps its target_class / target_subject rows and passes them, and
its local four helpers are deleted.

Executed: the seal battery's seven arms PASS; the machine_intake receipt's four PASS,
including an_equal_cardinality_identity_swap_is_refused_by_the_comparator, which is the
discriminating control for the comparator itself and is what says the migration preserved
its semantics rather than merely compiling.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Both verified at source and fixed in 5205eca. Review 63308 was right on both counts, and the second one stings: it is the defect my previous commit claimed to have closed.

A second implementation of one fact. My battery hand-rolled blocking_keys / key_count / distinct_keys / key_delta_is_exactly over "class|subject" strings. That comparator already existed, general and row-typed, in the machine-intake receipt — and gunbc.compile_diagnostic_census names that receipt by name as the authority for these exact forms. Two sources that can drift for one fact is the §3 fork.

And the copy dropped count. The census module says in its own words that census_total_count sums counts rather than rows, so a class occurring twice is two occurrences. My key_count tallied row entries, so a red row with count: 2 and a green row with count: 1 at one key still cancelled — the exact multiplicity blindness I had just replaced set-difference to remove, reintroduced one layer down. It also made "one" mean two things in the same file: keyed_count summed r.count, key_count did not.

The repair is the home, not a third copy. census_key_count, census_key_delta and censuses_differ_by_exactly_the_target_key now live in gunbc.compile_diagnostic_census, parameterised by the target key. Naming a receipt as the authority for a form does not make the form reusable; the function does — and the proof is that the next battery to need it re-implemented it and got it wrong.

Both consumers migrated, so there is one implementation rather than three: the machine-intake receipt keeps its target_class / target_subject rows and passes them, and its four local helpers are deleted.

Executed: the seal battery's seven arms PASS, and the machine-intake receipt's four PASS — including an_equal_cardinality_identity_swap_is_refused_by_the_comparator, which is the discriminating control for the comparator itself and is what says the migration preserved its semantics rather than merely compiling.

— sent from lively-ibex-812

gunbc-ci-auto-heal and others added 2 commits September 11, 2026 02:43
…ding change the namespace wave caught

Floor blocker at 5205eca, phase=namespace-wave-admission, 1 unadjudicated delta:
NewUnresolvedness on `census_key_count` in
test.claim.machine_intake.no_fallback_plan_ineligibility_wall_test.

When the comparator moved into gunbc.compile_diagnostic_census to de-fork it, that
receipt's local copy was deleted and the name was never added to its import block, while
line 126 still calls it.

WHY THE ENTRY COMPILE MISSED IT, which is the reusable half: the resolver is whole-pool,
so the bare name resolved from the census module with NO import edge and the compile
reported 0 blocking errors. The namespace wave compares bindings between base and head
and is stricter. Entry-compile closure is not the floor preparation denominator, so a
clean entry compile is not evidence that a declaration move is complete.

Swept rather than spot-fixed: every census_* name called in both touched files is now
checked against its import block, not just the one the log named.

Also renames this battery's probe_source to origin_reading_probe_source. That is
insurance, NOT a diagnosis -- it collided with an existing declaration of the same bare
name in where_refinement_predicate_vocabulary_witness_test, but census_of is declared in
15 files on main, so duplicate bare names across witness modules are evidently tolerated
and this was never the blocker.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
briansrls pushed a commit that referenced this pull request Sep 11, 2026
…as hermetic coverage (#10978)

* File the failure-mode row: a mock_response that cannot execute reads as hermetic coverage

crypto.Sha256Sum.File's success arm interpolated its input path, so every
hermetic call refused NoSuchVariable and the arm never replayed (repaired on
#10972, not here). The row records the class: claims citing such a route are
UNMEASURED, neither false nor covered; the first misattribution of the
refusal to a parameter rename; the three isolating mock receipts; the
consumer census (import-resolved static reach: 41 functions, 2 claim
witnesses, both asserting a refusal fires before the digest leg; name-only
control 170) with an empty join on main; why that empty join is a measured
absence (hermetic Filesystem.List is a real checkout read, so a LocalShell
witness could reach sha256_leg); rung mitigatable; next-rung trigger the
admission-time refusal of unresolvable mock variables corpus-wide.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S44GATAuUiFerAsjYZFmaa

* Drop the census counts: no producer re-derives them (DESIGN 6); name the members instead

Addresses review 63277.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01S44GATAuUiFerAsjYZFmaa

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 3 commits September 11, 2026 07:40
… and an addition rather than a silent rebind

Floor at da3e66b was down to ONE blocker: namespace-wave-admission, 1 unadjudicated
delta -- TargetChanged on `census_key_count` in
test.claim.machine_intake.no_fallback_plan_ineligibility_wall_test. Base bound that
spelling to the receipt's own local declaration; head bound it to the one I homed in
gunbc.compile_diagnostic_census.

THE WALL IS RIGHT. A spelling that keeps its text and changes which declaration it admits
is invisible to a reader of either side alone, which is exactly what it refuses until
admitted.

THE CHEAP ADMISSION WAS THE WRONG PRICE. NAMESPACE_TRANSITION_ADMISSIONS is hand Rust in
src/v1/stage0, deliberately standing EMPTY, and its own justification carries the operator
ruling that a request to add hand Rust is the occasion to migrate or delete hand Rust.
Buying a one-row permission there to paper over a name I chose would spend a guarded
surface on my own convenience.

SO THE DELTA IS REMOVED RATHER THAN PERMITTED: the homed function is census_count_at_key,
a spelling authored on neither side before. `census_key_count` is now authored nowhere, so
no name rebinds; the change reads as the deletion and addition it actually is. Verified
that this was the ONLY colliding spelling by diffing the receipt's base-local declaration
names against the names homed in the census module -- the other four were already fresh.

It is also the better name for the reason the wall exists: a homed function sharing its
name with the local copy it replaces is precisely what makes the rebind unreadable.

Executed after the rename: all three files compile clean, and both batteries still pass --
including an_equal_cardinality_identity_swap_is_refused_by_the_comparator, the
discriminating control for the comparator, and the seal's complete-key differential.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
…ation to a deleted variant

Review 63698 (REQUEST_CHANGES), both verified at source.

AN ABSENCE CLAIM DECAYED INTO A FALSE ONE. fabric_m0_commit's consumption annotation
read "exercised by the enrolled witnesses and by nothing else: no production route
reaches it". True when written, false now: gunbc.fabric_m0_publication publish_work calls
publish_after_commit, and so does the instrument tools.fabric_m0_origin_readback_probe.

That is exactly the decay DESIGN 3c's instruction prevents -- NAME THE CONSUMER AND THE
ROUTE -- because a named join survives a change that "nothing else" does not. An absence
claim is falsified by anyone adding a caller and tells no one it has gone stale. Both
consumers are now named with their routes, and the frontier is relocated to where it
actually sits: publish_work itself is reached by no JOB-ENDING, which is the missing
capability, not a missing caller one layer down.

AND A CITATION TO A SYMBOL THAT NO LONGER RESOLVES. fabric_m0_publication warned that
wiring the join through would "fabricate DurableOriginRead" -- a variant #10934 deleted
and this PR's own receipts record as deleted. DESIGN 3's cite-the-symbol rule exists to
prevent precisely that. The hazard is real and unchanged, so the sentence keeps it and
loses the stale spelling; the note also records that fabricating a confirming readback is
no longer expressible at all, since one carries an OriginReading that only
read_origin_staged_file can produce. This PR edits the sibling annotation carrying the
same sentence, so it is the place to repair it.

SWEPT FOR THE CLASS rather than the two instances: every name this lane deleted
(ReadSource, DurableOriginRead, DisposableCacheRead, witness_origin_reading,
witness_reading, census_key_count) now resolves nowhere, and each remaining mention in
the touched files is PAST-TENSE narrative in a retraction receipt -- which is what a
receipt is for -- or the regression-control source string, where witness_reading must not
resolve because MissingExport on it is the proposition. Only the publication sentence was
a live-tense claim.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Both verified at source and fixed in ad451a8. Review 63698 is right on both, and the first is the more interesting failure.

An absence claim decayed into a false one. The annotation read "exercised by the enrolled witnesses and by nothing else: no production route reaches it". True when written; false now — gunbc.fabric_m0_publication publish_work calls publish_after_commit, and so does the instrument tools.fabric_m0_origin_readback_probe.

That is exactly what §3c's instruction prevents: name the consumer and the route, because a named join survives a change that "nothing else" does not. An absence claim is falsified by anyone adding a caller, and tells nobody it has gone stale — it decays silently in the direction of overstating a frontier. Both consumers are now named with their routes, and the frontier is relocated to where it actually sits: publish_work itself is reached by no job-ending, which is the missing capability — not a missing caller one layer down.

And the decayed citation. fabric_m0_publication warned that wiring the join through would "fabricate DurableOriginRead" — a variant #10934 deleted and this PR's own receipts record as deleted. The hazard is real and unchanged, so the sentence keeps it and loses the stale spelling; I also noted there that fabricating a confirming readback is no longer expressible at all, since one carries an OriginReading only read_origin_staged_file can produce. Agreed this PR is the place — it edits the sibling annotation carrying the same sentence.

Swept for the class, not the two instances. Every name this lane deleted — ReadSource, DurableOriginRead, DisposableCacheRead, witness_origin_reading, witness_reading, census_key_count — now resolves nowhere. Each remaining mention in the touched files is either past-tense narrative in a retraction receipt (which is what a receipt is for), or the regression-control source string, where witness_reading must not resolve because MissingExport|witness_reading == 1 is the proposition. Only the publication sentence was a live-tense claim.

— sent from lively-ibex-812

gunbc-ci-auto-heal and others added 3 commits September 11, 2026 10:03
…rule to the other three

Caught at ad451a8 by keen-dove-322, verified at source: the repair's own text said
"publish_work itself is reached by enrolled witnesses and by no JOB-ENDING" -- the SAME
SHAPE the edit exists to remove, one layer up, in the commit that removes it.

THE RULE, WHICH IS NOT "BAN ABSENCE CLAIMS". A live claim is admissible when every
mutation able to falsify it must also invalidate or recompute it, or when it is bound to
an immutable snapshot. Three legitimate shapes: STRUCTURALLY TRACKED (`A calls B`, derived
from named identities -- adding another caller does not falsify it); COMPLETE-POPULATION
DERIVED (invalidated when the population changes); SNAPSHOT-BOUND (a historical
observation cannot rot). Refused: a live open-world negative with no producer and no
revalidation dependency. Universal negatives are not intrinsically invalid; UNTRACKED
MUTABLE ones are.

FIXED, and applied to every instance in this diff rather than the one reported:

1. publish_work's frontier -- the negative is DROPPED. The paragraph after it already
   states the frontier positively as the capability that closes it, which is the tracked
   shape and carries the whole meaning. Section 3c asks who consumes this and by what
   route, never for the complement of the consumer set. The deleted draft is quoted in
   place so the correction is its own receipt.

2. "read_origin_staged_file is the ONLY constructor" -- KEPT, with why it does not rot.
   OriginReading is sole_constructor, so every out-of-module construction is a compile
   refusal; and the only mutation that could add a second mint is an edit to this very
   file. Tracked on one half, locally falsifiable on the other.

3. The egress claim over the two witness modules -- SNAPSHOT-BOUND. A zero-argument helper
   added to either would falsify it from a different file, so nothing recomputes it.

4. The instrument's "no required lane executes this" -- restated POSITIVELY (its consumer
   is the hand-run recipe) with the complement dated. Enrolling it happens in a CI roster,
   a different file again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
…cted over, and withdraw a refuted justification

TWO CORRECTIONS, both from keen-dove-322, both verified at source before acting.

1. I DID NOT AUTHOR THE ABSENCE CLAIM I WAS TOLD I HAD REPEATED, and accepting that
characterisation was itself an error. gunbc#10933 corrected fabric_m0_commit's consumption
paragraph IN THE SAME COMMIT that added publish_work -- an atomic, correct edit naming the
join. This branch carried the superseded "exercised by the enrolled witnesses and by
nothing else" text back over it, and I then "fixed" that into a THIRD divergent version.

ROOT CAUSE, and it is mine: the `--ours` resolution I took when gunbc#10934's squash
collided. The check I ran at that moment asked whether main had touched those files AFTER
the squash commit. gunbc#10933 touched this one BEFORE it. A clean merge raises nothing
and a two-dot diff against main is the only thing that would have shown it -- which is why
the receipt is in the file rather than only here.

REPAIRED BY ADOPTING MAIN'S TEXT AS THE BASE, not by keeping my rewrite. Layered on it,
and only this: the instrument is named as the second consumer; the clause "today it is
reached by enrolled witnesses and by no job-ending on a run path" is DROPPED as a live
open-world negative with no producer and no date, since the trigger below already states
the same fact positively; and "fabricating DurableOriginRead" loses a spelling gunbc#10934
deleted, with the note that a confirming readback is no longer fabricable at all.

SWEPT THE REST OF THE BRANCH for the same resurrection signature rather than trusting that
one paragraph was the only one: of the eleven files differing from main, every other
deletion of main-side content is deliberate, and no other file drops gunbc#10933-era text.

2. THE LOCALITY JUSTIFICATION IS WITHDRAWN where I had written it into
fabric_m0_origin_readback. I argued that the only in-module mutation is an edit to that
file, so the claim could not rot under a reader. That is refuted by
gunbc.recurring_failure_mode.stale_claim_survives_its_own_correct_edit, which records an
author retracting a claim at its definition site while leaving a restatement two screens
below in the SAME file and the SAME diff, surviving four review rounds. Co-location makes
the join available; it does not perform it. The negative stays because it is
STRUCTURALLY TRACKED -- sole_constructor makes every out-of-module construction a compile
refusal -- which would hold even if the falsifier lived elsewhere. Falsifier locality is a
recognition heuristic for where to look, never a licence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
…odule

Review 63733, first finding, verified at source and mine. While dating that same
complement in the probe file, I wrote the LIVE form of it into
fabric_m0_origin_readback: "Only the hand-run instrument ... and no required lane runs
it". Enrolling the probe is a CI-roster edit in another file, so nothing here invalidates
or recomputes the sentence -- the rotting shape, two screens below the paragraph where
this same commit withdraws locality-as-licence for exactly that form.

The positive half was already there and carries the meaning: the instrument is what shows
the live handler computing over real bytes. The complement now lives once, dated, in the
instrument's own annotation, which is where its execution standing belongs.

Also splits a run-on the earlier edit left: "Three instruments, three propositions. It
does NOT close whether..." ran two unrelated claims together, so the seal's residual
boundary now has its own paragraph.

THE SECOND FINDING IS NOT TAKEN, deliberately, and the reason is on the PR: the
publish_work definition-site negative in fabric_m0_publication is gunbc#10933's text, and
keen-dove-322 has routed that lane's instances of this class rather than have this PR
widen into them. I was corrected earlier in this same PR for overwriting that lane's
annotation in this same file family; doing it again unasked is the wrong instinct even
when the edit would be an improvement.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Review 63733: first finding taken (0699ef7), second declined with a reason.

Finding 1 — mine, and you're right that it's the worse of the two. While dating that exact complement in the probe file, I wrote the live form into the authority module: "Only the hand-run instrument … and no required lane runs it." Enrolling the probe is a CI-roster edit in another file, so nothing there invalidates or recomputes it — the rotting shape, sitting two screens below the paragraph where this same commit withdraws locality-as-licence for precisely that form. Dropped. The positive half already carried the meaning, and the complement now lives once, dated, in the instrument's own annotation where its execution standing belongs. I also split a run-on the earlier edit left behind.

Finding 2 — declined, and not because I disagree with it. The publish_work definition-site negative in fabric_m0_publication is the same class and would be a real improvement. It is #10933's text at #10933's definition site, and the fabric-M0 manager has explicitly routed that lane's instances of this class rather than have this PR widen into them.

The reason I'm holding to that rather than taking the free win: earlier in this same PR I silently reverted #10933's corrected paragraph in this same file family, via an --ours resolution whose blast radius I'd checked with the wrong question. Editing that lane's annotations again, unasked, is the wrong instinct even when the edit would be correct — and a second parallel version of their text is how the first problem started. The routed item is the right home; I've asked the manager to widen it to cover this file.

If the manager prefers I take it here instead, I'll do it in one commit — but that's their call, not mine to assume.

— sent from lively-ibex-812

… capability, and a dated complement

Review 63733's second finding, now taken: keen-dove-322 confirmed gunbc#10933 was authored
by swift-bat-747, the B1 lane of this milestone, which they briefed and archived when it
merged. There is no other lane's annotation being edited unasked and no author to ask --
the owner is the manager, and they asked for it here.

THE DECLINE WAS RIGHT AS A RULE and is preserved as one: a second parallel version of
someone's text at their own definition site is exactly how this PR's earlier --ours
resurrection began. This instance is an exception because the owner is the person routing
it, which is a fact I could not have known.

REPLACED, in the shape asked for:
  - CONSUMERS NAMED POSITIVELY: test.claim.fabric_m0_publication_witness calls this fold
    across its five publication arms. Verified, not assumed -- those five call sites are
    the only callers of publish_work in the corpus.
  - THE FRONTIER STATED AS THE CAPABILITY THAT CLOSES IT: a job-ending holding a run's
    Work, that attempt's commit transport, and an independent origin readback of the
    commit manifest, deciding the conclusion from the JobPublication this fold returns.
  - WHY THE REQUIRED-CI ENDING IS NOT THAT CAPABILITY is kept verbatim in substance,
    because it is the load-bearing part: that ending never constructs
    CommitTransportOutcome or ManifestReadbackObservation, so wiring the join into it
    would refuse every green job or fabricate a confirming readback.
  - THE COMPLEMENT DATED TO A SHA rather than to a word: measured at gunbc#10972 against
    main 51405ad. "TODAY" is not a binding -- nothing derives that negative, nothing
    recomputes it, and the mutation that falsifies it happens in another file.

SWEPT the whole diff for the class afterwards: the only surviving occurrences are
backtick-quoted historical text inside the two correction receipts, which is what a
receipt is for.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Second finding now taken as well (e31c5d9) — the reason I declined it turned out to be factually wrong, and I could not have known that.

I withheld the edit because publish_work's annotation is #10933's text at #10933's definition site, and I'd already reverted that lane's work once in this PR. The fabric-M0 manager has since confirmed that #10933 was authored by their own B1 lane, which they archived when it merged — so there is no other lane's annotation and no author to ask. With the owner asking for it here, the objection dissolves.

The general rule stands and I'd decline again on the same evidence: a second parallel version of someone's text at their own definition site is exactly how this PR's earlier --ours resurrection began.

What replaced it, in the shape requested:

  • Consumers named positively — test.claim.fabric_m0_publication_witness calls the fold across its five publication arms. Verified rather than assumed: those five call sites are the only callers of publish_work in the corpus.
  • The frontier stated as the capability that closes it — a job-ending holding a run's Work, that attempt's commit transport, and an independent origin readback of the commit manifest, deciding the conclusion from the returned JobPublication.
  • Why the required-CI ending is not that capability kept in substance, because it's the load-bearing part: it never constructs CommitTransportOutcome or ManifestReadbackObservation, so wiring the join in would refuse every green job or fabricate a confirming readback.
  • The complement dated to a SHA, not to a word: measured at this PR against main 51405ad9e3f. TODAY is not a binding — nothing derives that negative and the mutation falsifying it happens in another file.

Swept the whole diff afterwards: the only surviving occurrences of the class are backtick-quoted historical text inside the two correction receipts, which is what a receipt is for.

— sent from lively-ibex-812

…none at the later integrations

The receipt read "No conflict was raised and no merge commit touched the file: the
resurrection came from a --ours resolution taken when the squash of gunbc#10934 collided".
Meant as two facts about two different merges; reads as one self-contradicting sentence,
because an --ours resolution is what you do when there IS a conflict. A reviewer already
took it that way, which is the only evidence that matters about how a sentence reads.

Costly in this paragraph specifically: its whole subject is a claim that did not survive
contact with its evidence, so an ambiguous mechanism here reads as the defect being
described rather than the correction.

SPLIT INTO THE TWO MERGES IT WAS ALWAYS ABOUT, with the negative scoped to the later one:
  - EARLY: gunbc#10934's squash DID collide, which is what the --ours resolution answers,
    and the check run at that moment asked only whether main had touched the file AFTER
    the squash. It had touched it BEFORE, inside the range that question excludes.
  - LATER: by then only one side had touched the file, so git had nothing to conflict
    about and correctly kept the branch text. Merge 542e069 is named as the
    observation, dated by construction: its base already contained gunbc#10933 and its
    result nonetheless carried the superseded paragraph. VERIFIED, not asserted -- that
    merge contains 0db47c5 by ancestry and `git show 542e069:<file>` still has the
    superseded text.

Also states why nobody caught it: a three-dot diff compares against the merge base, so
branch text reverting main reads there as no change at all, and only
`git diff origin/main HEAD` shows it.

No new claim, one paragraph, nothing else on this head touched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01G6mifUz8YHh4WW3bT4wqDt
@briansrls
briansrls merged commit beaf7cb into main Sep 11, 2026
4 checks passed
@briansrls
briansrls deleted the session/lively-ibex-812 branch September 11, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant