Skip to content

Classify POSIX 126/127 as environmental CI failure, not subject red - #10985

Merged
briansrls merged 24 commits into
mainfrom
session/still-bear-335
Sep 11, 2026
Merged

briansrls merged 24 commits into
mainfrom
session/still-bear-335

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • POSIX shell statuses 126/127 (extdeps.process.posix_exit) classify as Infra (CommandInvokedCannotExecute / CommandNotFound) rather than as a subject/structural defect. The required aggregator now has a third rendered standing, stands-environment, with ::error title=environment:: telling the reader this is not a verdict about the diff.
  • Each required lane (build, floor, v2-native) wraps the executing command, writes gunbc-floor-outcome.txt, publishes floor_class as a job output, and uploads gunbc-floor-outcome-${{github.run_id}}-${{github.run_attempt}}-${{github.job}} under always() so a re-run cannot erase the failed attempt. Fetch that artifact before re-running; gh run view --log on the same run id loses the failed attempt.
  • Filesystem probe dissolution (toolchain_filesystem_probe_dissolution_condition) is AND, not OR: (1) every required public job selects a per-attempt microVM via selected_ci_runner_target / gunbc_ci_selected_runner_spec, and every required private job selects one via witnesses_job() SelfHosted custom labels — not the empty-custom fleet slot; (2) that selection makes the shared-FS eviction class impossible, so this row may bind. Cure plan: gunbc#10971 (no runs-on flip in this PR). Identifying a deleter on the shared slot is not a substitute. Process-count (Cursor/dsl roadmap worker plan 965b #46) does not retire the probe.
  • Typed env-vs-code does not dissolve on isolation. Wrap, receipts, and stands-environment remain for BMC/host/JIT vs code after microVMs. Job roster is unchanged (v2-native was already on main).
  • Private CI is a follow-on: strategy.private_witness_workflow step list is warm-badger-62's surface (Cursor/dsl roadmap worker plan 965b #46). This PR does not edit that authority. Attachment there is new STEPS plus a run-script arm that consumes a run outcome, not a fourth WitnessDisposition. One aggregate process for whatever strategy.private_witness_workflow enforced_witnesses() currently is (do not hardcode the count; it moved 29→30 when Cursor/session roadmap todos 4a27 #49 enrolled node_rental_witness_test). Classify that process by exit status (cli_run classify_cli_wire → cli_wire_outcome); stdout is a roll call of PASS lines, not a single PASS, and the return type is CliWireResponse / CliWirePrintable as of d338a15. Per-process classification remains for the non-enforced known-red / refusal-probe entries.
  • Specimen (gunbc-private PR Well-specified TODO tasks #50, ~2026-09-10T20:04Z, exit 126 in ~15s): this session could not recover the failed-attempt log or a filesystem join that names a deleter; do not reconstruct a deleter from the exit code alone. Private main's last completed witnesses run was 2026-09-08; later runs 34506604778 and 34420214922 cancelled at the 60-minute job timeout — the same collapse of environment into “no result.”

Test plan

  • gunbc run witness_posix_shell_reserved_exits_are_infra_not_subject (ProcessExit) green on remote
  • generated-artifact regen of .github/workflows/witnesses.yml from expected_witness_floor_yml (full workflow typecheck OOM'd this session's 8GiB runner; CI is the execution proof)
  • required aggregator: infra receipt → stands-environment + environment annotation; structural compile error still stands-red
  • receipt artifact present after a failed attempt; re-run does not delete the prior attempt's artifact name (attempt is in the name)
  • w_RED_a_failed_lane_carries_no_established_mechanism stays green on the words-only composition

gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
Identifying a deleter on the shared slot is not a substitute; typed env-vs-code stays after isolation.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63311 — verified against the tree and fixed on this head (c770154a44e).

  1. required_lane_is_infra_class_test was missing. Confirmed: two call sites, no fn. Defined it as required_lane_var_equals_lit_test on floor_outcome_wire_infra, which is why that import existed. That is the emitted stands-environment arm.

  2. lane_subject_receipt_from_wire had no production caller, and floor_rendered_verdict_with_receipts was test-only. The real acceptance path is still the aggregator bash. That is now honest in floor_subject_receipt_acquisition_trigger: production split is required_lanes_any_class_test / required_lane_is_infra_class_test; class_wire_is_environment is the modeled decode of the same wire; w_RED_an_infra_receipt_is_environment_not_subject_red exercises both the composition and the decode. The words-only floor_rendered_verdict still cannot split red; w_RED_a_failed_lane_carries_no_established_mechanism stays that control.

  3. class=infra minted CommandInvokedCannotExecute. Confirmed, and that would lie for 127 and MemoryStall. Decode now uses ClassWireOnly: the job output carries class, not signature. Signature stays on the attempt-receipt file.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63326 — verified against the tree and fixed on this head (fd3d9a8931d).

  1. Unmarked medium-as-string wrap. Confirmed. Typed classification must not ride the microVM dissolve-on (that was the earlier correction). The shell carrier now has floor_attempt_receipt_shell_emit_dissolution_condition: dissolve when this wrap is Nodes through bash_build / bash_fold_serialize_program, the capability required_lanes_gate already uses. Echoed on the wrap itself.

  2. Shell was a second classifier. Confirmed: production if-ladder only did 126/127/0/MemoryStall while classify_failure_reason folds verdict_infra_signatures. Log elif grep lines are now that same roster, last-wins order matching the fold. POSIX 126/127 still precede reason greps, as classify_failure_exit does.

  3. Any-infra OR absorbed a concurrent subject red. Confirmed in both the aggregator and floor_rendered_verdict_with_receipts. Environment now requires infra class and no structural class on any lane. Mixed infra+structural stays stands-red. Witness added.

gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63333 — both findings were real against the wrap at fd3d9a8, and both are fixed on e6d0779.

  1. The wrap/write/finalize programs are now bash_build Nodes serialized by bash_fold_serialize_program (the same route required_lanes_gate already uses). floor_attempt_receipt_shell_emit_dissolution_condition is deleted rather than kept as a trigger that was already true at authoring time. Combined stdout+stderr capture to the attempt log is a Node (bash_build_with_redir_stdout_and_stderr_to_file) rather than a join/concat script. Emission refuses if serialize rejects (wrap_command_is_renderable / floor_attempt_receipt_finalize_is_renderable on expected_witness_floor_yml).

  2. posix_exit_status_decimal is integer_int_to_decimal_string, so a structural 101 is exit=101 in floor_attempt_receipt_body as well as in the shell receipt ($GUNBC_FLOOR_EXIT). The witness asserts 101, not unknown.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63343 — both findings were real against e6d0779, fixed on d3f737e.

  1. sh -e -c was handed a free bash_build_word_lit, so a multi-line cargo build … serialized as unquoted words and ran cargo with the rest as $1…. There is now bash_build_word_single_quoted, serialized with bash_single_quote (the same IEEE 1003.1-2017 encoding v2.extdeps.languages.bash already cites from extdeps.posix.shell_command_language). The wrap argument is one quoted word, including newlines and embedded quotes. The witness asserts 'cargo build' and that sh -e -c cargo is not emitted.

  2. Absent => "" is gone. Serialize rejection is floor_attempt_shell_serialize_refused (::error + exit 1), not an empty passing step. wrap_command_is_renderable takes the actual command and requires the POSIX-quoted payload in the serialized script. expected_witness_floor_yml conjoins floor_attempt_production_wraps_are_renderable over every production wrap input (floor/build/v2-native/heal builds, the three lane run scripts, clippy), not "true".

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63351 — both findings were real against the wrap/upload and the MemoryStall match text, fixed on 984dc55.

  1. The wrap no longer buffers then cat after return. It tees with set -o pipefail and 2>&1 | tee $GUNBC_FLOOR_LOG, so the step log streams while the command runs. always() now uploads gunbc-floor-cmd.log beside gunbc-floor-outcome.txt (if-no-files-found: warn, because a timeout-cancel may have the log and not the receipt). Fetch that artifact before re-running.

  2. infra_signature_match_substring for MemoryStallRefusedPageThrash no longer hand-copies the class name. It reads gunbc.memory_stall_refusal memory_stall_refusal_page_thrash_class_name, which is the same row memory_stall_refusal_pressure_text concatenates.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63442 — verified on the wrap path and fixed on d649fa54b5.

bash_build_word_lit is already POSIX-single-quoted at emit: bash_production_fold_lit_word binds bash_token_lit, and that class maps to bash_posix_single_quote_transform. bash_build_word_single_quoted ran bash_single_quote first, so command = "cargo build" became a lit whose value already contained quotes, then emit wrapped it again (''\''cargo build'\'''). sh -e -c would treat 'cargo build' as the command name → 127, which this PR's own classifier would call infra and hide as stands-environment.

The wrap now uses bash_build_word_lit(text: command). The helper is deleted. The posix witness requires 'cargo build' and refuses the ''\' double-quote residue.

— sent from still-bear-335

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63493 — verified and fixed on fdc3d73107.

The String row was unclassified prose: invalid state, specimen, and next-rung trigger with five string_contains greps as the only consumer. Deleted it. The class is now gunbc.recurring_failure_mode.command_not_found_exit_cannot_distinguish_eviction_from_misnaming (review 63442 specimen, three-state harm, serialized-wrap-argument join). infra_signature_origin consumes the typed identity; the posix witness joins that origin and the evidence refs (classify_failure_exit, wrap_command_with_floor_attempt_receipt_stmts, bash_build_word_lit). The wrap RED remains 'cargo build' vs the ''\' residue, not a grep of the ledger sentence. The // above classify_failure_exit only points at that row.

— sent from still-bear-335

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63533 — verified against the tree and fixed on this head.

  1. Parallel POSIX 127. Confirmed: rustc_missing_exit_code = 127 beside exit_code_command_not_found. Deleted the local mint; rustc_target_compile_observation consumes extdeps.process.posix_exit exit_code_command_not_found.

  2. Dangling floor_attempt_receipt_bound_steps. Confirmed: factory unused, same two WitnessFloorBoundSteps inlined on floor and build. Both lanes now concat that factory.

  3. Dangling bash_single_quote. Confirmed: only the definition after the wrap moved to bash_build_word_lit. Deleted. bash_single_quote_spaced stays; directive emit still uses it.

— sent from still-bear-335

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63559 — verified against the wrap and GitHub RunStep shell: none, fixed on 358dc30d3b.

The wrap is serialized with set_e: false, but Actions still runs bash -e {0}. With set -o pipefail, a failing pipeline aborted the step before GUNBC_FLOOR_EXIT=$? and floor_attempt_receipt_write_stmts, so finalize's ! -f arm published class=unobserved on the failure path this PR exists to classify.

wrap_disable_github_errexit_stmt (set +e) now runs before pipefail. Inner sh -e -c still fails the subject; pipefail still puts the pipeline status in $?; then the receipt writes and exit "$GUNBC_FLOOR_EXIT". Timeout-cancel before the wrap finishes can still be unobserved. floor_subject_receipt_acquisition_trigger now names that constraint. The posix witness requires 'set' '+e' on a wrap of false. The executing consumer is the wrapped required-lane run: under Actions, not a substring grep.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

review 63582 — verified: .github/workflows/witnesses.yml was byte-identical to main and had no floor_class / wrap / stands-environment. Regenerated via tools.generated_artifact_gate main_wet and committed on 905d8288ec.

The file now carries 'set' '+e', the tee wrap, floor_class job outputs, and aggregator stands-environment. That is the Actions consumer, not expected_witness_floor_yml() in-memory.

— sent from still-bear-335

gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
…placed-during.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor

review 63635 is a real defect: POSIX &&/|| are equal-precedence and left-associative, so the ungrouped environment arm parsed as ((A||B) && !C) || D and overwrote stands-red when FLOOR_CLASS=structural.

Fix is at the serialize layer, not a one-off in the gate: mixed &&/||/! now emit grouped commands. Regenerated aggregator line is (A||B) && (! (C||D)) — modeled (any infra) && !(any structural). Direct shell check: structural/structural stays subject-red; infra-only still takes stands-environment. Head bfd7e8483f.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

review 63660: both findings hold on the previous head.

  1. Shared gunbc-floor-outcome.txt last-wins: wrap now replaces the receipt only when the new class outranks or ties (none < infra < structural). Seal class=none after a MemoryStall infra write keeps the infra receipt and signature.

  2. Aggregator environment rewrite is conjunct on VERDICT=stands-red, matching floor_rendered_verdict_with_receipts. Timeout/cancel stays unestablished even if a leftover class is infra. Mixed infra+structural still stays subject-red.

Head bc2bb080b1.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

review 63682: agreed — dangling. Removed bash_build_with_redir_stdout_and_stderr_to_file and its serialize arm. Live wrap is still 2>&1 | tee. Head follows in the next line after push.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

Head for the review 63682 deletion is 53e1bb253e.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

review 63697: both hold.

Receipt replace: one policy. Rank stays; the wrap predicate is now a fold over floor_attempt_receipt_class_wire_roster and strictly-higher wires, same construction as required_lanes_any_class_test. Witnesses on floor_attempt_receipt_class_may_replace now name the authority the shell consumes.

lane_subject_receipt_from_wire: unobserved / empty / else were the same fail-closed arm; one else remains.

Head — see push SHA.

— sent from still-bear-335

@briansrls

Copy link
Copy Markdown
Contributor

Head for review 63697 is 75891a7376.

— sent from still-bear-335

briansrls pushed a commit that referenced this pull request Sep 11, 2026
)

* Plan CI onto per-job microVMs without taking the cutover.

Public dogfood is M1; private is the first workflow because it is already red on the shared-filesystem deleter class. host_boot_cutover_frontier stays unbound.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Correct the adjacent-lane map: process count is not the filesystem mitigation.

After private #46 the public-seed gunbc build dominates the job; a per-attempt guest is cold by construction, so name the cache arm and require a cold-build measurement before flipping runs-on.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Reframe microVM cost: cache location, not VM lifetime.

Local-compile-cold seed build was 3m 58s on amd64 BuildBuddy with an empty target dir and no rustc wrapper; guest sccache reachability is still the open constraint.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Retire seed-build cache as a cutover gate: accepted-cold clears the job bar.

3m 58s is a twice-over lower bound; even 2x still leaves a ~12 minute private job versus 53 and under the 60-minute timeout. Guest egress stays blocked on its own frontier and is off this path.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Cite the private job-wall producers the accepted-cold subtraction uses.

The 3341 s and 759 s walls are GitHub job timestamps on runs 34462653642 and 34512318040; the ~61-minute cancel class is run 34523487941. Bare 53/8 minute prose is no longer the bar.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Point the probe dissolution at #10985's two conjuncts.

Identifying a deleter on the shared slot is not a substitute; typed env-vs-code stays after isolation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore the #10985 probe-home sentence the merge dropped.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Record the in-flight runner re-registration specimen as the shared-FS class this plan makes unwritable.

Identification still does not dissolve the filesystem probe; thrash remains unjoined.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Cite #10985: double-occupancy is eviction 127, wrap trigger is not-replaced-during.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Brian Searls and others added 10 commits September 11, 2026 12:17
GitHub still publishes one witnesses FAILURE for a missing toolchain and a compile error. Lane jobs now wrap the executing command, publish a per-attempt receipt (run_id + attempt + job), and the aggregator renders stands-environment with an annotation telling the reader to fetch that artifact before re-running. Dissolve the wrap and probes when per-job microVMs (or an identified deleter fix) make shared-FS eviction impossible.

Co-authored-by: Cursor <cursoragent@cursor.com>
…class.

Isolation makes shared-FS eviction impossible; it does not retire POSIX 126/127, attempt receipts, or stands-environment. Those remain BMC/host/JIT vs code. The probe binds when both public selected_ci_runner_target and private witnesses_job custom labels select a per-attempt guest (gunbc#10971), not on process-count.

Co-authored-by: Cursor <cursoragent@cursor.com>
Exit 126 stays environment. MemoryStallRefusedPageThrash is already a typed floor refusal — classify it as Infra so GitHub cannot paint it as a subject defect, and do not put it on the build-retry grep. Timeout-cancel stays stands-unestablished (no verdict, still blocks) and the aggregator tells the reader to fetch the attempt receipt before re-running.

Co-authored-by: Cursor <cursoragent@cursor.com>
CommandNotFound stays Infra because the exit code is ambiguous, not because it is an unambiguous environmental signal. A typo-induced 127 currently renders as stands-environment. Narrow when a 127 can be joined to a start-probe or closed-argv inhabitance; 126 is outside this limitation.

Co-authored-by: Cursor <cursoragent@cursor.com>
…nfra.

required_lane_is_infra_class_test is the shell realization of class_wire_is_environment on floor_outcome_wire_infra. Decoding the CLASS job output no longer fabricates CommandInvokedCannotExecute; class-only is ClassWireOnly. The words-only floor_rendered_verdict still cannot split red; production split is the aggregator class test.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ell debt.

Environment standing requires infra class and no structural class on any lane. The wrap still emits join/concat shell; that carrier now carries a dissolve-on for bash_build serialization, while typed classification stays. Log greps are the same verdict_infra_signatures roster classify_failure_reason folds, last-wins order.

Co-authored-by: Cursor <cursoragent@cursor.com>
…eal exit decimal.

The dissolution trigger named a capability this PR already consumed, so the hand-shell wrap was not admissible. posix_exit_status_decimal now uses integer_int_to_decimal_string instead of fabricating unknown.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ialize.

sh -c was receiving a free unquoted lit, so a multi-line cargo build became `sh -c cargo`. The wrap now uses bash_build_word_single_quoted (IEEE 1003.1-2017 single-quote encoding already cited from bash). Serialize rejection is exit 1, not an empty step, and the yaml gate checks every production wrap input rather than `true`.

Co-authored-by: Cursor <cursoragent@cursor.com>
…nhabits.

Heal and the build lane refused witnesses.yml because bash_build_word_single_quoted was a new word kind command serialize cannot inhabit, so expected_witness_floor_yml refused. The constructor now quotes with bash_single_quote and emits a lit. Serialize rejection stays exit 1, not an empty step.

Co-authored-by: Cursor <cursoragent@cursor.com>
…om its home.

Timeout-cancel was emptying the step log because the wrap redirected then cat after return. The wrap now tees with pipefail, and always() uploads gunbc-floor-cmd.log beside the receipt. The page-thrash grep prefix is gunbc.memory_stall_refusal memory_stall_refusal_page_thrash_class_name, the same row pressure_text concatenates.

Co-authored-by: Cursor <cursoragent@cursor.com>
Brian Searls and others added 13 commits September 11, 2026 12:18
bash_build_word_single_quoted ran POSIX quoting and then bash_token_lit quoted again, so sh -c received a quoted command name and exited 127, which this PR classifies as infra.

Co-authored-by: Cursor <cursoragent@cursor.com>
The wrap-start identity join would not have caught a well-formed command mangled in transit; the row now names that third state and the serialized-argument join.

Co-authored-by: Cursor <cursoragent@cursor.com>
The limitation was a commentary String whose only consumer was substring greps. The class, review 63442 specimen, and next-rung join live on gunbc.recurring_failure_mode; classify origin and wrap evidence consume the typed identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
rustc_missing_exit_code was a second literal for the same reserved status; bash_single_quote had no caller after the wrap used lit emit; floor_attempt_receipt_bound_steps was defined and then re-inlined on both lanes.

Co-authored-by: Cursor <cursoragent@cursor.com>
…writes.

Actions runs RunStep with bash -e; pipefail then aborted before GUNBC_FLOOR_EXIT and the class file, so finalize published unobserved on the failure path this wrap exists to classify.

Co-authored-by: Cursor <cursoragent@cursor.com>
…cimen.

The same step name was FloorRefused on main (cpu_deadline) and 127 here after claim_executor vanished mid-job; without a class receipt those causes were indistinguishable.

Co-authored-by: Cursor <cursoragent@cursor.com>
Present-at-wrap-start would have been green: claim_executor existed at 06:03 and 06:06 and was destroyed mid-job by a second process on the same _work. That is still eviction, not a fourth POSIX meaning.

Co-authored-by: Cursor <cursoragent@cursor.com>
…cimen.

Taxonomy stays here: three POSIX 127 states, trigger is present at wrap start and not replaced during.

Co-authored-by: Cursor <cursoragent@cursor.com>
…a structural red.

POSIX left-associative equal-precedence flattened `A || B && ! C || D` into `((A||B) && !C) || D`. Serialize now parenthesizes the modeled `(any infra) && !(any structural)` tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
…nly over stands-red.

A later class=none wrap was last-wins over MemoryStall infra; timeout/cancel sat in unestablished then the aggregator promoted leftover infra to stands-environment. Both contradict floor_rendered_verdict_with_receipts.

Co-authored-by: Cursor <cursoragent@cursor.com>
Nothing constructed that tag after the wrap moved to 2>&1 | tee; the serialize arm was the same dangling pair.

Co-authored-by: Cursor <cursoragent@cursor.com>
The bash tree is a fold over the same wires the ordinal ranks, so the witness on may_replace is asserting the policy that executes. Collapse identical unobserved wire arms to one else.

Co-authored-by: Cursor <cursoragent@cursor.com>
…wrap conjuncts.

Main deleted the v2-native required job; the wrap-renderable closure still named its scripts. Projection is from the merged authorities, not a side of the generated-file conflict.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/still-bear-335 branch from 75891a7 to 2a71cca Compare September 11, 2026 12:26
…ecute annotation.

Class-only infra does not establish ToolchainIdentityLost; production already printed unestablished. The aggregator arm covers every Infra class, so the annotation names an environmental cause rather than a missing toolchain.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls

Copy link
Copy Markdown
Contributor

review 63805: both hold.

floor_rendered_verdict_with_receipts keeps the red arm's interruption (mechanism/attribution unestablished). Deleted the ToolchainIdentityLost mint on class-only infra. Aggregator environment annotation is now generic ('environmental cause'), not 'could not execute the toolchain'.

— sent from still-bear-335

@briansrls
briansrls merged commit 7086eb4 into main Sep 11, 2026
4 checks passed
@briansrls
briansrls deleted the session/still-bear-335 branch September 11, 2026 15:49
gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
…an_its_declared_claim

#10985 appended to the same row this PR appends to, so the one file this PR
touches was the one content conflict. Resolved by keeping BOTH sides: main's
two receipts (the direction case at analytic grain, royal-wolf-747/gunbc#10997,
and the general promote-evidence rule from bright-boar-435) and this PR's
witness-population form. They are appends to one receipts list and neither
supersedes the other -- taking either side alone would have deleted a landed
receipt, which is the class this very row exists to catch.

Verified the merged row parses rather than assuming an append cannot break it:
gunbc compile --entry <the row> --target dag, 0 blocking errors, and no
conflict markers or body-grain annotations survive. No projection to
regenerate: the combined markdown view is not a committed merge surface and
roster.dag is generated and gitignored, so a row CONTENT edit drives nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RPVTQBSK9E8j3UDQGPZN1f
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant