Repository navigation
Classify POSIX 126/127 as environmental CI failure, not subject red - #10985
Conversation
Identifying a deleter on the shared slot is not a substitute; typed env-vs-code stays after isolation. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 63311 — verified against the tree and fixed on this head (
|
|
review 63326 — verified against the tree and fixed on this head (
|
Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 63333 — both findings were real against the wrap at fd3d9a8, and both are fixed on e6d0779.
|
|
review 63343 — both findings were real against e6d0779, fixed on d3f737e.
|
|
review 63351 — both findings were real against the wrap/upload and the MemoryStall match text, fixed on 984dc55.
|
|
review 63442 — verified on the wrap path and fixed on
The wrap now uses — sent from still-bear-335 |
|
review 63493 — verified and fixed on The — sent from still-bear-335 |
|
review 63533 — verified against the tree and fixed on this head.
— sent from still-bear-335 |
|
review 63559 — verified against the wrap and GitHub The wrap is serialized with
— sent from still-bear-335 |
|
review 63582 — verified: The file now carries — sent from still-bear-335 |
…placed-during. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 63635 is a real defect: POSIX Fix is at the serialize layer, not a one-off in the gate: mixed — sent from still-bear-335 |
|
review 63660: both findings hold on the previous head.
Head — sent from still-bear-335 |
|
review 63682: agreed — dangling. Removed — sent from still-bear-335 |
|
Head for the review 63682 deletion is — sent from still-bear-335 |
|
review 63697: both hold. Receipt replace: one policy. Rank stays; the wrap predicate is now a fold over
Head — sent from still-bear-335 |
|
Head for review 63697 is — sent from still-bear-335 |
) * Plan CI onto per-job microVMs without taking the cutover. Public dogfood is M1; private is the first workflow because it is already red on the shared-filesystem deleter class. host_boot_cutover_frontier stays unbound. Co-authored-by: Cursor <cursoragent@cursor.com> * Correct the adjacent-lane map: process count is not the filesystem mitigation. After private #46 the public-seed gunbc build dominates the job; a per-attempt guest is cold by construction, so name the cache arm and require a cold-build measurement before flipping runs-on. Co-authored-by: Cursor <cursoragent@cursor.com> * Reframe microVM cost: cache location, not VM lifetime. Local-compile-cold seed build was 3m 58s on amd64 BuildBuddy with an empty target dir and no rustc wrapper; guest sccache reachability is still the open constraint. Co-authored-by: Cursor <cursoragent@cursor.com> * Retire seed-build cache as a cutover gate: accepted-cold clears the job bar. 3m 58s is a twice-over lower bound; even 2x still leaves a ~12 minute private job versus 53 and under the 60-minute timeout. Guest egress stays blocked on its own frontier and is off this path. Co-authored-by: Cursor <cursoragent@cursor.com> * Cite the private job-wall producers the accepted-cold subtraction uses. The 3341 s and 759 s walls are GitHub job timestamps on runs 34462653642 and 34512318040; the ~61-minute cancel class is run 34523487941. Bare 53/8 minute prose is no longer the bar. Co-authored-by: Cursor <cursoragent@cursor.com> * Point the probe dissolution at #10985's two conjuncts. Identifying a deleter on the shared slot is not a substitute; typed env-vs-code stays after isolation. Co-authored-by: Cursor <cursoragent@cursor.com> * Restore the #10985 probe-home sentence the merge dropped. Co-authored-by: Cursor <cursoragent@cursor.com> * Record the in-flight runner re-registration specimen as the shared-FS class this plan makes unwritable. Identification still does not dissolve the filesystem probe; thrash remains unjoined. Co-authored-by: Cursor <cursoragent@cursor.com> * Cite #10985: double-occupancy is eviction 127, wrap trigger is not-replaced-during. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
GitHub still publishes one witnesses FAILURE for a missing toolchain and a compile error. Lane jobs now wrap the executing command, publish a per-attempt receipt (run_id + attempt + job), and the aggregator renders stands-environment with an annotation telling the reader to fetch that artifact before re-running. Dissolve the wrap and probes when per-job microVMs (or an identified deleter fix) make shared-FS eviction impossible. Co-authored-by: Cursor <cursoragent@cursor.com>
…class. Isolation makes shared-FS eviction impossible; it does not retire POSIX 126/127, attempt receipts, or stands-environment. Those remain BMC/host/JIT vs code. The probe binds when both public selected_ci_runner_target and private witnesses_job custom labels select a per-attempt guest (gunbc#10971), not on process-count. Co-authored-by: Cursor <cursoragent@cursor.com>
Exit 126 stays environment. MemoryStallRefusedPageThrash is already a typed floor refusal — classify it as Infra so GitHub cannot paint it as a subject defect, and do not put it on the build-retry grep. Timeout-cancel stays stands-unestablished (no verdict, still blocks) and the aggregator tells the reader to fetch the attempt receipt before re-running. Co-authored-by: Cursor <cursoragent@cursor.com>
CommandNotFound stays Infra because the exit code is ambiguous, not because it is an unambiguous environmental signal. A typo-induced 127 currently renders as stands-environment. Narrow when a 127 can be joined to a start-probe or closed-argv inhabitance; 126 is outside this limitation. Co-authored-by: Cursor <cursoragent@cursor.com>
…nfra. required_lane_is_infra_class_test is the shell realization of class_wire_is_environment on floor_outcome_wire_infra. Decoding the CLASS job output no longer fabricates CommandInvokedCannotExecute; class-only is ClassWireOnly. The words-only floor_rendered_verdict still cannot split red; production split is the aggregator class test. Co-authored-by: Cursor <cursoragent@cursor.com>
…ell debt. Environment standing requires infra class and no structural class on any lane. The wrap still emits join/concat shell; that carrier now carries a dissolve-on for bash_build serialization, while typed classification stays. Log greps are the same verdict_infra_signatures roster classify_failure_reason folds, last-wins order. Co-authored-by: Cursor <cursoragent@cursor.com>
…eal exit decimal. The dissolution trigger named a capability this PR already consumed, so the hand-shell wrap was not admissible. posix_exit_status_decimal now uses integer_int_to_decimal_string instead of fabricating unknown. Co-authored-by: Cursor <cursoragent@cursor.com>
…ialize. sh -c was receiving a free unquoted lit, so a multi-line cargo build became `sh -c cargo`. The wrap now uses bash_build_word_single_quoted (IEEE 1003.1-2017 single-quote encoding already cited from bash). Serialize rejection is exit 1, not an empty step, and the yaml gate checks every production wrap input rather than `true`. Co-authored-by: Cursor <cursoragent@cursor.com>
…nhabits. Heal and the build lane refused witnesses.yml because bash_build_word_single_quoted was a new word kind command serialize cannot inhabit, so expected_witness_floor_yml refused. The constructor now quotes with bash_single_quote and emits a lit. Serialize rejection stays exit 1, not an empty step. Co-authored-by: Cursor <cursoragent@cursor.com>
…om its home. Timeout-cancel was emptying the step log because the wrap redirected then cat after return. The wrap now tees with pipefail, and always() uploads gunbc-floor-cmd.log beside the receipt. The page-thrash grep prefix is gunbc.memory_stall_refusal memory_stall_refusal_page_thrash_class_name, the same row pressure_text concatenates. Co-authored-by: Cursor <cursoragent@cursor.com>
bash_build_word_single_quoted ran POSIX quoting and then bash_token_lit quoted again, so sh -c received a quoted command name and exited 127, which this PR classifies as infra. Co-authored-by: Cursor <cursoragent@cursor.com>
The wrap-start identity join would not have caught a well-formed command mangled in transit; the row now names that third state and the serialized-argument join. Co-authored-by: Cursor <cursoragent@cursor.com>
The limitation was a commentary String whose only consumer was substring greps. The class, review 63442 specimen, and next-rung join live on gunbc.recurring_failure_mode; classify origin and wrap evidence consume the typed identity. Co-authored-by: Cursor <cursoragent@cursor.com>
rustc_missing_exit_code was a second literal for the same reserved status; bash_single_quote had no caller after the wrap used lit emit; floor_attempt_receipt_bound_steps was defined and then re-inlined on both lanes. Co-authored-by: Cursor <cursoragent@cursor.com>
…writes. Actions runs RunStep with bash -e; pipefail then aborted before GUNBC_FLOOR_EXIT and the class file, so finalize published unobserved on the failure path this wrap exists to classify. Co-authored-by: Cursor <cursoragent@cursor.com>
…cimen. The same step name was FloorRefused on main (cpu_deadline) and 127 here after claim_executor vanished mid-job; without a class receipt those causes were indistinguishable. Co-authored-by: Cursor <cursoragent@cursor.com>
Present-at-wrap-start would have been green: claim_executor existed at 06:03 and 06:06 and was destroyed mid-job by a second process on the same _work. That is still eviction, not a fourth POSIX meaning. Co-authored-by: Cursor <cursoragent@cursor.com>
…cimen. Taxonomy stays here: three POSIX 127 states, trigger is present at wrap start and not replaced during. Co-authored-by: Cursor <cursoragent@cursor.com>
…a structural red. POSIX left-associative equal-precedence flattened `A || B && ! C || D` into `((A||B) && !C) || D`. Serialize now parenthesizes the modeled `(any infra) && !(any structural)` tree. Co-authored-by: Cursor <cursoragent@cursor.com>
…nly over stands-red. A later class=none wrap was last-wins over MemoryStall infra; timeout/cancel sat in unestablished then the aggregator promoted leftover infra to stands-environment. Both contradict floor_rendered_verdict_with_receipts. Co-authored-by: Cursor <cursoragent@cursor.com>
Nothing constructed that tag after the wrap moved to 2>&1 | tee; the serialize arm was the same dangling pair. Co-authored-by: Cursor <cursoragent@cursor.com>
The bash tree is a fold over the same wires the ordinal ranks, so the witness on may_replace is asserting the policy that executes. Collapse identical unobserved wire arms to one else. Co-authored-by: Cursor <cursoragent@cursor.com>
…wrap conjuncts. Main deleted the v2-native required job; the wrap-renderable closure still named its scripts. Projection is from the merged authorities, not a side of the generated-file conflict. Co-authored-by: Cursor <cursoragent@cursor.com>
75891a7 to
2a71cca
Compare
…ecute annotation. Class-only infra does not establish ToolchainIdentityLost; production already printed unestablished. The aggregator arm covers every Infra class, so the annotation names an environmental cause rather than a missing toolchain. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 63805: both hold.
— sent from still-bear-335 |
…an_its_declared_claim #10985 appended to the same row this PR appends to, so the one file this PR touches was the one content conflict. Resolved by keeping BOTH sides: main's two receipts (the direction case at analytic grain, royal-wolf-747/gunbc#10997, and the general promote-evidence rule from bright-boar-435) and this PR's witness-population form. They are appends to one receipts list and neither supersedes the other -- taking either side alone would have deleted a landed receipt, which is the class this very row exists to catch. Verified the merged row parses rather than assuming an append cannot break it: gunbc compile --entry <the row> --target dag, 0 blocking errors, and no conflict markers or body-grain annotations survive. No projection to regenerate: the combined markdown view is not a committed merge surface and roster.dag is generated and gitignored, so a row CONTENT edit drives nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RPVTQBSK9E8j3UDQGPZN1f
Summary
extdeps.process.posix_exit) classify asInfra(CommandInvokedCannotExecute/CommandNotFound) rather than as a subject/structural defect. The required aggregator now has a third rendered standing,stands-environment, with::error title=environment::telling the reader this is not a verdict about the diff.gunbc-floor-outcome.txt, publishesfloor_classas a job output, and uploadsgunbc-floor-outcome-${{github.run_id}}-${{github.run_attempt}}-${{github.job}}underalways()so a re-run cannot erase the failed attempt. Fetch that artifact before re-running;gh run view --logon the same run id loses the failed attempt.toolchain_filesystem_probe_dissolution_condition) is AND, not OR: (1) every required public job selects a per-attempt microVM viaselected_ci_runner_target/gunbc_ci_selected_runner_spec, and every required private job selects one viawitnesses_job()SelfHostedcustomlabels — not the empty-custom fleet slot; (2) that selection makes the shared-FS eviction class impossible, so this row may bind. Cure plan: gunbc#10971 (noruns-onflip in this PR). Identifying a deleter on the shared slot is not a substitute. Process-count (Cursor/dsl roadmap worker plan 965b #46) does not retire the probe.stands-environmentremain for BMC/host/JIT vs code after microVMs. Job roster is unchanged (v2-native was already on main).strategy.private_witness_workflowstep list is warm-badger-62's surface (Cursor/dsl roadmap worker plan 965b #46). This PR does not edit that authority. Attachment there is new STEPS plus a run-script arm that consumes a run outcome, not a fourthWitnessDisposition. One aggregate process for whateverstrategy.private_witness_workflowenforced_witnesses()currently is (do not hardcode the count; it moved 29→30 when Cursor/session roadmap todos 4a27 #49 enrollednode_rental_witness_test). Classify that process by exit status (cli_runclassify_cli_wire→cli_wire_outcome); stdout is a roll call of PASS lines, not a single PASS, and the return type isCliWireResponse/CliWirePrintableas of d338a15. Per-process classification remains for the non-enforced known-red / refusal-probe entries.Test plan
gunbc runwitness_posix_shell_reserved_exits_are_infra_not_subject(ProcessExit) green on remote.github/workflows/witnesses.ymlfromexpected_witness_floor_yml(full workflow typecheck OOM'd this session's 8GiB runner; CI is the execution proof)stands-environment+ environment annotation; structural compile error stillstands-redw_RED_a_failed_lane_carries_no_established_mechanismstays green on the words-only composition