Skip to content

Model Google Sheets and converge review sheets by readback - #10986

Merged
gunbai-bot[bot] merged 56 commits into
mainfrom
session/still-crab-505
Sep 12, 2026
Merged

gunbai-bot[bot] merged 56 commits into
mainfrom
session/still-crab-505

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Model Google Workspace and the Sheets API v4 as their own extdeps authorities (not GCP rows): values.get / values.batchUpdate, published quotas, and the spreadsheets OAuth scope. Auth reuses ADC + SecretRef / gunbc.secret_provision; no second credential type and no invented idempotency key.
  • Review-sheet convergence is std.upsert_decision (via ensure assembly) over an independent readback of the derived region, keyed by listing identity. Operator columns are never written; a hand-edited derived cell refuses with a located cell; gone listings that still carry judgement are retained and marked StandingGone.
  • Listing standing is a closed sum (StandingObserved | StandingGone). Cell text is listing_standing_label at emit; ingest is read_listing_standing. Foreign cell text refuses.
  • Operator path is now modeled in gunbc.review_sheet_operator, and review_sheet_live_access refuses before any write: Sheets API enablement on the existing gunbai-secrets project (serviceusage GetService, sheets.googleapis.com), fleet-automation SA + secret_provision (WIF binding is NoDischargeSiteModeled — unverified, not assumed live), a declared spreadsheet identity with an owner (FleetOnce create), and Editor sharing with that SA (DeviceOnce per sheet, not FleetOnce). A Sheets HTTP refusal is not this decision.

Sheets works against a plain Google account as well as a paid Workspace domain. Where Workspace specifically bites is domain sharing policy (forbidding shares outside the org can block sharing with a service-account principal). That policy is an unobserved operator fact (DomainSharingPolicyUnobserved); we do not assume either way.

One public PR: the projection still imports only std.types and std.upsert_decision. Gmail is out of scope.

Renderer coupling (#11047)

This PR does not add recurring-failure-mode rows, design-ledger receipts, or docs-projection prose. The RFM render authored (join(r.receipts, " ")) therefore has no new inputs from this diff. Added strings are path identities on extdeps_scope_frontier, Service Usage / OAuth / quota facts consumed by folds and witnesses, and sheet A1/ensure plans — not receipt lists joined for a markdown emit. Looked because "nothing I import changed" is not a clearance after #11100.

Discriminating REDs (executed)

Instrument: gunbc run --source-root dag --source-root src/v2 --entry dag/test/claim/review_sheet_converge_witness_test.dag --function <name>. Each test fn returns Bool; the CLI then refuses because it wants ProcessExit — the value printed is the verdict.

Mutation Function Expected
Derived title alpha replaced with hand-edited converge_over_hand_edited_derived_cell_refuses_and_names_the_cell Refuse naming listing=L1 column=title cell=B2
Standing cell Observed replaced with Obsered foreign_standing_cell_refuses_and_names_the_cell Refuse naming column=standing cell=C2
Same projection and sheet, run twice converge_twice_unchanged_is_noop Noop then Noop
Title empty, judgement buy converge_preserves_populated_human_column Apply that does not touch judgement; readback still buy
Rows swapped resorted_sheet_does_not_move_a_judgement Noop; L1 still buy, L2 still skip
Projection empty, sheet still has L1+buy listing_gone_with_judgement_is_retained_and_marked Apply standing label ListingGone; no append; judgement still buy
Unobserved Sheets enablement on gunbai-secrets committed_operator_path_refuses_unobserved_sheets_enablement ReviewSheetOperatorRefused; live access stays closed
WIF still NoDischargeSiteModeled unverified_wif_is_awaiting_human_not_assumed_live ReviewSheetAwaitingHuman on gcp-fleet-secrets-wif-binding
Spreadsheet not identified undeclared_spreadsheet_is_fleet_once_create_not_a_caller_string create intervention FleetOnce
Identified sheet, share undischarged sharing_is_device_once_editor_with_the_fleet_sa share intervention DeviceOnce naming the fleet SA as Editor

Test plan

  • Functions above returned true on this tree
  • CI required witnesses on this PR

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63314:

  1. Fixed. a1_column_letter is now String? with Absent past Z. A write or conflict at column index 26 returns ReviewSheetUnreadable (unrepresentable A1 column index 26) rather than Apply with ?2. RED: a_twenty_seventh_column_refuses_rather_than_writing_a_fake_a1.

  2. Deleted the unused SpreadsheetId, A1Range, and BatchUpdateValuesRequest brands/types. Remaining cited rows (rate-limit roster, quota FactCitation, major-dimension wire, both OAuth scopes, mock corpus, SecretRef access, RAW input) are read by sheets_cited_facts_have_executing_readers. The live GetValues/BatchUpdateValues adapter is a declared frontier (live_sheets_transport_frontier) for sunny-carp-475; this PR's executing consumer of the decision is test.claim.review_sheet_converge_witness, which is the brief's RED surface.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63331:

  1. Fixed. derived_value_for now returns String?. A schema-derived column with no DerivedCell is ReviewSheetUnreadable (projection omitted derived column title listing=L1), not CellSkip/CellConflict over "". Present empty string remains a real desired value. REDs: omitted_derived_column_on_blank_sheet_refuses_rather_than_noop, omitted_derived_column_on_populated_sheet_is_not_a_conflict.

  2. Fixed. live_sheets_transport_frontier is Scaffold { dissolves_to: RealizationDispatch, bind: review_sheet_from_readback }, not Terminal. The witness asserts the Scaffold arm.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63349:

  1. Fixed. Deleted the identity wrappers (sheets_projection_oauth_scope, sheets_value_input_raw, sheets_api_edition, sheets_workspace_suite, sheets_api_enablement_from_service_state) and the sheets_cited_facts_have_executing_readers count-equality witness. The operator-module re-exports the review cited at those line numbers (review_sheet_uses_fleet_secrets_project / review_sheet_writer_service_account) were already gone.

  2. Fixed as a declared frontier, not a fake caller. GetValues/BatchUpdateValues bind through live_sheets_transport_frontier (Scaffold → review_sheet_from_readback). GetService/EnableService bind through live_serviceusage_get_frontier / live_serviceusage_enable_frontier (Scaffold → service_enablement_from_state_wire / decide_service_enablement). RED: live_transport_frontiers_are_scaffold_not_terminal.

  3. Already fixed before this review landed: live_sheets_transport_frontier is Scaffold { RealizationDispatch }, not Terminal. The witness now fails on the Terminal arm.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63357:

  1. Fixed. judgement_for_listing returns JudgementRead (JudgementBlank | JudgementEntered | JudgementUnreadable). Missing identity column, missing judgement column, and listing-not-present are located Unreadable, not "". RED: judgement_failures_are_unreadable_not_blank.

  2. Fixed. admit_review_sheet_operator now takes the share intervention. Identified spreadsheet + discharged share produces ReviewSheetOperatorAdmitted; undischarged share stays ReviewSheetAwaitingHuman. RED: discharged_share_admits_the_identified_spreadsheet.

The dashboard payload named four findings and then cut off after (2). If (3) and (4) are still open, they are not in the text I received.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63372 — both findings were real; they are now inhabited rather than deleted.

  1. ReviewSheetOperatorAdmitted / ReviewSheetLiveOpen unreachable. Share was already an admission input (admit_review_sheet_operator(..., share, ...)); discharged share + identified sheet constructs Admitted (discharged_share_admits_the_identified_spreadsheet). review_sheet_live_access_from now takes that admission so ReviewSheetLiveOpen is fixture-reachable (admitted_admission_opens_live_access). Fleet review_sheet_live_access stays NotAdmitted while project/writer await identification.

  2. WorkspaceDomainSharingPolicy unused. Admission now takes sharing_policy and tenancy. Workspace + DomainSharingPolicyUnobserved refuses (operator is admin; the policy is readable). DomainSharingForbidsExternalPrincipals refuses. DomainSharingAllowsServiceAccountShare (or a plain Google account) proceeds to share discharge. Witnesses: unread_workspace_sharing_policy_refuses, domain_policy_forbidding_sa_share_refuses.

Head: 7b25e3c0c2e.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63428 — all three findings were real; head 5c58a99cca3.

  1. GetValues omitted cells. Output is now value_range: ValueRange plus outcome, matching how GetAuthenticatedUser projects user: GitHubUser. The 200 body is the ValueRange that already carries values; observed_sheet_from_value_range can consume that payload instead of a range-only projection.

  2. extdeps.google.workspace unimported. gunbc.review_sheet_operator now imports google_workspace_product. Unread and SA-forbidding domain-policy refusals are worded from that product name, so the module is on the admission edge rather than only on scope_carrier_paths.

  3. Fabricated "unidentified" share id. share_intervention_for_spreadsheet derives share from buyer_review_spreadsheet: create while awaiting, share of the declared id once identified. Fleet admission uses that fold. Witnesses: identified_spreadsheet_share_uses_that_id_not_a_placeholder, awaiting_creation_does_not_mint_an_unidentified_share_id.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63460 — both listed findings were real; head 20ccf54a39.

  1. BatchUpdateValues.data: Json. Input is now data: List<ValueRange>. value_ranges_from_write_plan maps ReviewSheetWritePlan patches onto that list (A1 + cell), so the write plan does not have to become an opaque blob at the wire seam.

  2. value_input_option: String beside an unused SheetsValueInputOption. The operation takes SheetsValueInputOption; the body sends sheets_value_input_option_wire. Review-sheet writes use InputUserEntered. Round-trip from_wire is in live_transport_frontiers_are_scaffold_not_terminal.

The artifact text cut off after “prefer a single authority from which the realizat…”. If there was a further duplicated-predicate site, it was not in the delivered list.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63471 — both findings were real; head 20f5164838.

  1. Permanently-green fleet_secrets_wif_is_not_assumed_live. Deleted. Witnesses now call intervention_is_discharged on gcp_fleet_secrets_wif_binding_intervention() (GREEN: undischarged) and on w_discharged_iam() (RED: DischargedAt). fleet_secrets_wif_binding_is_still_undischarged holds both arms.

  2. Copied accumulators / quadratic joins in review_sheet_projection. Header and listing indexes are maps built once. Duplicate and missing-row checks look up instead of count_id over the whole list. Cell/A1 access is skip, not enumerate-filter. Write-plan patches/appends prepend and reverse once at emit.

The artifact text cut off after the §6 cost-shape quote; this is the projection file that quote named.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63522 — both facets were real; head $(git rev-parse --short HEAD).

GetValues returns the actual range in ValueRange.range; observed_sheet_from_value_range discarded it and sheet_row_number assumed A1. A Review!B2:E200 read would still emit B2 patches, and an unqualified B2 would write the first tab.

a1_readback_standing now requires a sheet title and an A1 origin (readback_not_a1_anchored_refuses, unqualified_readback_range_refuses). review_sheet_from_readback / ensure qualify Apply patches as Review!B2 (value_ranges_from_write_plan takes the tab). Projection data_index + 2 remains valid only behind that A1 wall.

The artifact cut off after the first-tab write; that is the qualification facet.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63567 — both findings were real; head 6b25bd4581 plus the citation attachment on that enum.

  1. Unrecognized state widened to Unobserved. service_enablement_from_state_wire now maps only ENABLED/DISABLED to observed enabled/disabled. STATE_UNSPECIFIED and any other spelling are ServiceEnablementStateForeign { raw }; decide_service_enablement Refuses with that raw. Unobserved stays “GetService was not called.” Witness: unspecified_or_unknown_serviceusage_state_is_foreign_not_unobserved.

  2. Closed State enum reminted in gunbc. GcpServiceUsageState plus gcp_service_usage_state_wire / from_wire live in extdeps.cloud.gcp.serviceusage, same pattern as SheetsMajorDimension. GetService still projects the JSON string; the product fold consumes from_wire.

The artifact cut off at “The correct shape is already demo…”; that demo is the Sheets major-dimension wire pair.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63604 (claude/opus): both findings held on 4846ab0; fixed in b72fcbaf28.

  • value_ranges_from_write_plan now concatenates patch ranges with one located ValueRange per append (Tab!A{row}:{last}{row}, cells in identity+schema order, empty operator cells). Classify assigns sheet_row as len(observed.rows)+2 and refuses an unrepresentable A1 instead of planning a row that cannot be written. Discriminating coverage: absent_listing_appends_a_located_row (header-only sheet, listing L2 → Review!A2:D2).

  • review_sheet_estate_unresolved_gcp_project / review_sheet_estate_unresolved_writer are the single constructors; admit_review_sheet_operator and fleet_review_sheet_operator_admission both call them.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63645 finding 1 held on the previous head; fixed in this push.

Sheet qualification had two homes: review_sheet_from_readback / review_sheet_ensure prefixed the tab onto DerivedCellWrite.a1, then value_ranges_from_write_plan prefixed again (Review!Review!B2). Appends were already qualified only on the ValueRange fold. The plan is now tab-free (B2); sheet_qualified_a1 runs only when emitting ValueRanges. Discriminating coverage: readback_apply_qualifies_once_on_the_value_range_fold — readback Apply then value_ranges_from_write_plan must be Review!B2, not Review!Review!B2.

Findings 2 and 3 were truncated in the dashboard copy (the artifact cut off mid-sentence of finding 1). They were not in the tree I was given; please re-post them if they still apply.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63667 held: appends were schema-positional while every other path is header-keyed. Fixed in this push.

missing_schema_header only requires presence, so ["listing_id","standing","title","judgement"] is readable. append_row_for used concat([listing_id], map(schema.columns, …)) from column A, which would write alpha into standing and then the next converge would StandingForeign / conflict. Append cells are now map(observed.headers, …) — identity, derived, standing, and blank operator cells under the header that names them. Discriminating coverage: append_follows_observed_header_order_not_schema_order.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63677 held: appends were a quadratic fold. Fixed in this push.

append_row_for no longer filters schema.columns or rebuilds derived_by_column per header. columns_by_name is folded once per classify; each listing builds derived_by_column once; headers and derived cells look those maps up.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63702 held: duplicate headers last-won in indexes_by_header and classify treated that map as the sheet. Fixed in this push.

first_duplicate_name runs before the header map is used. Two title columns are ReviewSheetUnreadable (duplicate header title), not a silent bind to the last column. judgement_for_listing uses the same refuse. Discriminating coverage: duplicate_header_refuses_rather_than_last_wins.

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63716 held on both counts. Fixed in this push.

AppendListingRow now carries the a1 classify already computed. value_range_from_append consumes it; there is no second append_row_a1 that can Absent and drop the row from the batch. value_ranges_from_write_plan is concat(map(patches), map(appends)) — no concat(acc, [vr]). absent_listing_appends_a_located_row asserts a.a1 == "A2:D2".

— sent from still-crab-505

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63724: both findings held on the previous head. Fixed in this push, with one boundary noted.

  1. Deleted review_sheet_from_readback. live_sheets_transport_frontier binds review_sheet_ensure. Policy is the caller's EnsurePolicy, not a literal may-apply. Discriminating: observe_only_does_not_emit_a_write_plan (mismatch refuses, does not Apply).

  2. sheets_major_dimension_from_wire is consumed on GetValues ingest. Absent majorDimension is row-major (Sheets default); COLUMNS and any foreign string are ReadbackUnreadable. Witnesses: column_major_readback_refuses, foreign_major_dimension_refuses.

sheets_value_input_option_from_wire is still only the closed inverse next to *_wire in extdeps.google.sheets. GetValues / BatchUpdate do not return valueInputOption; the request carries the SheetsValueInputOption enum (review_sheet_batch_value_input_option = InputUserEntered). Parsing a string there would invent a field the API does not send. If a later adapter takes a stringly option from config, that is the consumer — not a second converge fold.

— sent from still-crab-505

@gunbai-bot
gunbai-bot Bot force-pushed the session/still-crab-505 branch from d7bdee4 to 170762a Compare September 11, 2026 10:31
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63743: the conflict markers were real on the pre-rebase tree. They are gone on 170762aed9.

scope_carrier_paths now lists all four additive rows, no markers:

  • dag/extdeps/deepseek/deepseek_v4_1_flash.dag
  • dag/extdeps/vllm/recipe_deepseek_v4_1_flash.dag
  • dag/extdeps/google/workspace.dag
  • dag/extdeps/google/sheets.dag

That was the rebase onto main that landed after the DIRTY merge. The quoted <<<<<< in commit_writer_admission_witness_test.dag is still a fixture, not this file.

— sent from still-crab-505

@gunbai-bot
gunbai-bot Bot force-pushed the session/still-crab-505 branch from 514fa0a to 13bfa46 Compare September 11, 2026 11:23
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63769 — agreed. review_sheet_batch_value_input_option is now InputRaw so derived strings ("1/2", leading =/+/-) are stored as strings, not parsed into dates/formulas. GetValues now takes an explicit valueRenderOption; this lane pins FORMATTED_VALUE so ValueRange.values stays List<List<String>> (UNFORMATTED can be JSON numbers; that gap is already structural_coverage_gap_value_range_cell_types). Witness live_transport_frontiers_are_scaffold_not_terminal pins both.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63787 — both findings hold on the prior head; both are in e9059db.

  • Mock corpus: sheets_published_mock_corpus is now imported by v2.test.lens_mock_totality.sheets_mock_totality (sheets_mock_consumer_is_total_holds / sheets_mock_omitted_member_is_red_holds) and by sheets_published_mock_corpus_covers_get_and_batch_update. Scope-exempt still names the file as citation/mock machinery; it is no longer the only reader.
  • BatchUpdateValues output total_updated_cells is Int? from "totalUpdatedCells", matching BatchUpdateValuesResponse.totalUpdatedCells. Omitted key on a zero-cell update is Absent, not a fabricated 0.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63806 — agreed. review_sheet_ensure was discarding the tab that a1_readback_standing had already validated, then value_ranges_from_write_plan took a second tab argument. The compared cells and the BatchUpdate range could be different tabs.

review_sheet_ensure now returns TabBoundWritePlan { tab, plan }, with tab from the readback. value_ranges_from_write_plan takes only that bound value. ensure_write_ranges_use_the_readback_tab uses OtherTab!A1:D4 and asserts OtherTab!B2 with no "Review" literal on the write path.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63819 — both items hold on the prior head; addressed in 236695b.

  • Bounded readback: a1_readback_standing only required start A1, so Review!A1:D4 was admitted while start_row came from the returned row count. A 50-row tab with a 4-row GetValues would BatchUpdate at row 5 over unobserved operator cells. Standing now requires an open-ended end (A1:D, no row digits). bounded_readback_range_refuses is the RED; fixtures use Review!A1:D.
  • Dual append payload: AppendListingRow.derived was a second copy of cells used only by write_plan_touches_column. Removed. Emit is cells. Preserve-operator checks patches on existing rows. Blank operator slots on an append initialize a new row after an open-ended readback; they are not a second write plan.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63832 — agreed that the previous wall was on the wrong artifact. Cited ValueRange.range (sheets_value_range_resource_citation): for output it is the entire requested range; values omit trailing empties. An open-ended request Review!A1:D may therefore come back as Review!A1:D{gridRowCount}. Grading that response string as "bounded" would refuse every live GetValues.

review_sheet_ensure now takes requested_range (the GetValues path this lane owns). Open-endedness is required there (bounded_get_values_request_refuses). Response standing is tab-qualified and A1-anchored only; grid_resolved_response_range_is_not_a_truncated_request admits Review!A1:D1000 against request Review!A1:D. The live adapter consumes review_sheet_get_values_request.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63844 — agreed. The three duplicate-key scans (NameDupScan / first_duplicate / ObservedIdIndex) were a second fold+map_insert authority beside std.keyed_roster. They are gone. classify_review_sheet and judgement_for_listing now keyed_roster_build header rows, projection listing ids, and observed identity cells; KeyedRosterBuildDuplicateKey is the refusal, with the same reason strings. Membership maps for the rest of classify are folded only from a KeyedRosterBuilt roster.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63854 — those rows were dangling; they are consumed on 37a6cbe.

  • sheets_rate_limits is concatenated into capacity_quota_witness w_all_limits (13 scopes). The three published windows are identity-keyed members of that roster, not a second count of the tree.
  • sheets_api_base is concat of the host and sheets_api_version, so the version row is the path the service endpoint reads.
  • Writer vs readonly oauth scopes and sheets_read_quota_citation are folded by sheets_quota_scope_and_version_rows_are_consumed.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 63864 — hoisted intervention_is_discharged into std.human_intervention on 3ebbe0f. Advisory only; the rest of that review did not need a follow-up.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 63876 (stdout: /api/reviews/63876/artifacts/stdout.log).

  • Deleted std.human_intervention intervention_is_discharged. admit_review_sheet_operator (IAM + share) and the converge witnesses now match completion_evidence (DischargedAt / NoDischargeSiteModeled) instead of a Bool wrapper over the closed sum.
  • every_upstream_scope_is_one_pool_with_the_published_ceiling_and_period no longer pins length(limits) == 13. It identity-joins the named enrolled sources (github_rate_limits, gcp_rate_limits, ebay_rate_limits, sheets_rate_limits, anthropic, openai) into w_all_limits() by upstream_rate_limit_key, and keeps uniqueness plus the grounded GitHub / eBay / Sheets ceiling pins.

Witnesses fleet_secrets_wif_binding_is_still_undischarged, discharged_share_admits_the_identified_spreadsheet, and the capacity quota function returned true on 5df94456bc.

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 63889 (stdout: /api/reviews/63889/artifacts/stdout.log).

The request path no longer splits a string this module concatenated. review_sheet_get_values_request returns SheetA1Range (tab × origin cell × A1EndOpen / A1EndClosed). review_sheet_ensure matches that end coproduct: a closed end is the bounded-GetValues refuse; an open end proceeds. a1_request_standing, a1_start_cell, and a1_contains_digit are gone.

Write-plan cells are A1Cell / A1RowSpan (column letter from the A–Z roster × row). The A1 string is rendered at ValueRange.range (sheet_qualified_cell / sheet_qualified_span / sheet_a1_range_wire) and in conflict text.

a1_readback_standing still ingests the response ValueRange.range string and now returns a typed SheetA1Range (open or closed end) rather than a tab-only verdict. Column letters join the enrolled A–Z roster; row numbers use parse_int on the remainder.

Witnesses including bounded_get_values_request_refuses, grid_resolved_response_range_is_not_a_truncated_request, readback_apply_qualifies_once_on_the_value_range_fold, and absent_listing_appends_a_located_row returned true on 0bc750a138.

Those rows are not exercised by a transport yet; the live adapter frontier already names that later consumer. A test that greps a concat for its own operand is not coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

review 64111 — the decoration was real; deleted in 3e4bbb5.

sheets_quota_scope_and_version_rows_are_consumed is gone. string_contains(sheets_api_base, sheets_api_version) could not go red, and the citation/scope comparisons were existence greps. sheets_api_base is already the sheets.Spreadsheets endpoint. Quota numbers are enrolled through sheets_rate_limits. OAuth scopes stay as upstream rows; live_sheets_transport_frontier (sunny-carp-475) is the named later consumer of those scopes on the live adapter. No fake never, no substitute test.

The dashboard payload truncated after that finding. If the cut-off second item was another decoration in the same function, it went with it.

— sent from still-crab-505

Keep both additive extdeps_scope_frontier paths: eBay marketplace-account-deletion and Google Workspace/Sheets.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Merged current origin/main (9d25609300). git merge-base --is-ancestor origin/main HEAD holds on HEAD 3601b596db.

Renderer coupling after #11047: this PR adds no RFM rows and no design-ledger receipts, so authored (join(r.receipts, " ")) has no new inputs. No docs-projection prose. Added strings are scope-frontier path identities, Service Usage / OAuth / quota facts, and A1/ensure plans. Looked because the import graph is not a clearance.

— sent from still-crab-505

Quota numbers are already enrolled through sheets_rate_limits. The citation had no reader after the decoration witness was dropped.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64278 — dangling citation was real; deleted in 23d3ccd.

sheets_read_quota_citation had no reader after the decoration witness was dropped. Quota numbers stay enrolled through sheets_rate_limits. sheets_quota_citation remains as the ExternalAuthority on extdeps_model_scope.

— sent from still-crab-505

Brian Searls and others added 2 commits September 12, 2026 03:46
Review-sheet fleet admission now matches the estate calling-home fact, so a later Identified home cannot stay AwaitingIdentification in this module.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 64312: deleted ReviewSheetGcpProjectStanding / ReviewSheetWriterStanding and the committed review_sheet_gcp_project / review_sheet_writer rows. Fleet admission now matches sheets_calling_home() (gunbc.gcp_estate_observation) and refuses as ReviewSheetEstateUnresolved { subject: sheets_calling_home } with the refused API-surface project and writer from that fact. admit_review_sheet_operator takes caller-supplied project/writer for fixture paths only; it is not a second committed home. When SheetsCallingHome later grows an Identified arm, the exhaustive match here fails to compile until admission consumes it.

— sent from still-crab-505

Brian Searls and others added 2 commits September 12, 2026 04:54
Keep #10986 an ancestor of current main so the PR is not behind.
…mpty A1 end.

GetValues is whole-tab only; a computed last column had no executing consumer. Bounded ends are now spelled in sheet_a1_range_wire, so WholeTab cannot emit Review!A1: by fabricating an empty token.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 64342:

Deleted review_sheet_get_values_last_column. GetValues is A1EndWholeTab and ensure refuses Open/Closed, so a last-column letter had no executing route; the witness that asserted "D" was not a consumer. Did not add a Scaffold frontier because there is no later consumer to name.

Deleted sheet_a1_end_wire. WholeTab stays only in sheet_a1_range_wire (bare tab). Open/Closed spell their end tokens there, so "" cannot produce Review!A1:.

— sent from still-crab-505

Brian Searls and others added 2 commits September 12, 2026 06:06
Observe-only can refuse a disabled API instead of always producing EnableApiPlan. Policy is a workflow fact, as it already is on review_sheet_ensure.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep #10986 an ancestor of current main.
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 64365: decide_service_enablement takes policy: EnsurePolicy and passes it to ensure_decide. sheets_api_enablement_decision and admit_review_sheet_operator (enablement_policy) thread the caller. Observe-only on observed-disabled is Refuse (desired enabled, observed disabled), not Apply. Witnesses: enablement_observe_only_refuses_disabled_instead_of_applying, admit_observe_only_refuses_disabled_api_instead_of_needing_enable.

— sent from still-crab-505

Brian Searls and others added 2 commits September 12, 2026 06:30
The sheets_api_service_id replacement pasted the census name onto a line that already imported it.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep #10986 an ancestor of current main.
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Fixed review 64403: deleted the duplicate named_projects_are_observed_in_census import left when sheets_api_service_id was replaced. One binding remains.

— sent from still-crab-505

Brian Searls and others added 4 commits September 12, 2026 09:16
…nt first.

Append writes only non-operator runs, so a populated judgement in the target row is Unreadable rather than a blanking write. Admission consults the enablement decision before the serviceusage IAM grant, so an already-enabled API does not demand a human grant.

Co-authored-by: Cursor <cursoragent@cursor.com>
The predicate now sees append run column names, and the append witness asserts judgement is absent from emitted A1 ranges rather than written as blank.

Co-authored-by: Cursor <cursoragent@cursor.com>
…duplicate judgements.

Admission treated any DischargedAt share as proof for the requested spreadsheet. Identity now names spreadsheet and writer, and admit compares that identity before admitting. judgement_for_listing reads through the duplicate-refusing keyed roster instead of first-match.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 64497 on 32bb4c7199.

  1. Share admission now compares share.identity to spreadsheet_share_intervention for this spreadsheet id and writer. Identity includes both. A discharged share for sheet A (or another writer) refuses instead of admitting sheet B. Witnesses: discharged_share_for_another_spreadsheet_does_not_admit, discharged_share_for_another_writer_does_not_admit.

  2. judgement_for_listing builds the same duplicate-refusing keyed roster classify uses. Two L1 rows with buy/reject is duplicate sheet listing L1, not first-match. Witness: judgement_for_duplicate_listing_rows_is_unreadable.

— sent from still-crab-505

Brian Searls and others added 2 commits September 12, 2026 11:37
The required floor refused on a stale #11137 namespace-wave admission; main already retired that row in #11165.
Apply treated any DischargedAt intervention as the enable grant. Identity now names project and writer, admit joins that identity, pending returns the expected intervention, and a foreign discharge refuses.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 64546 on 2d2e9a0d53.

Apply now identity-joins serviceusage_enable_iam to serviceusage_enable_iam_grant_intervention for this project and writer (identity includes both). Mismatch refuses. Pending returns that expected intervention, not the caller’s foreign one. Matching discharge still yields ReviewSheetNeedsApiEnable. Discriminating RED: discharged_iam_for_another_project_does_not_need_enable.

— sent from still-crab-505

@gunbai-bot
gunbai-bot Bot merged commit 3461823 into main Sep 12, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/still-crab-505 branch September 12, 2026 13:57
@briansrls
briansrls restored the session/still-crab-505 branch September 12, 2026 13:59
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
…re its row

MERGE of origin/main dfac90c (#11121, #11142, #11154, #10986). Three
conflicts. namespace_wave_admission.rs: main's THIRTY-SIXTH DISSOLUTION record
kept, this branch's 181 still-required rows kept with their 181
expected_candidates. accepted_source_emits_uncompilable_target.dag: took MAIN's
side -- their rung claim is mechanically preventable backed by executing
evidence, this branch's said still-mitigatable and is superseded, and their four
added receipts are preserved. v1_compiler_emit_rust.rs: resolved BY REGEN, never
text-merged; main's bytes stood as a placeholder and the regenerated mirror
overwrote them from the merged .dag authority.

THE WALK IS REPAIRED RATHER THAN DEFERRED, because the primitive it was waiting
for is now in the tree. #11121 landed as dfac90c (v2.std.collection
primitive-backed map_insert/map_lookup delegates), which is the capability the
declared drop named. DESIGN section 6: a proven cost-shape defect is always
fixed, and a trigger amended after the capability arrives is a deferral with
better wording.

SHAPE. native_lane_facts_index builds module -> imports ONCE, before the
recursion. native_lane_module_reachable looks up only what the frontier names and
carries seen_set through the recursion. Neither is rebuilt per round: rebuilding
either would reintroduce the cost under a keyed spelling.

A MODULE DECLARED TWICE APPENDS, AND THIS IS THE CASE A REVIEW WOULD HAVE
PLANTED. The fold this replaces visited every fact whose module the frontier
named, so two facts declaring one module contributed BOTH import lists. A naive
map_insert keeps the last and SHRINKS the closure -- a behaviour change wearing a
performance change's clothes, and the same silent narrowing this PR has already
repaired twice. The index appends on a duplicate key.

PRESERVED: declared membership; the refusal arms (fuel exhaustion still refuses
the whole derivation by identity with budget and frontier); last-round
completion.

DIVERGED, DELIBERATELY AND STATED ON THE CARRIER: discovery order is FRONTIER
order, not FACT order. Preserving fact order needs a per-round pass over all
modules to re-derive it -- the repeated scan this repair removes. It is
unobservable, checked rather than assumed: native_lane_closure_ingest filters by
membership (the ingest supplies its own order), both halves of
native_lane_ingest_matches_closure are membership tests, and the emitted receipt
carries `closure.len()`, a count, never the sequence. If a consumer that reads
the sequence ever appears, THAT change owns this order fact; it cannot be
inherited silently from here.

NOT CLAIMED: that the route is now O(closure). One walk changed. The instrument
is the universe_derivation span -- 192.4 s at 36e6ad9 -- and the successor run
on this head is the before/after. No cost witness is added: no corpus home can
hold a planted-quadratic control for this walk inside the 500 ms line without a
synthetic population that exceeds it, and a witness that cannot discriminate is
worse than none.

ROW RETIRED BY ITS TRIGGER, with the repair as the discharge, in this same
commit -- never in an intermediate state with the original scan still standing.
Retiring on the capability alone would have been the 4b(3) inflation: a row
marked discharged with the quadratic walk intact.

CITATIONS (review 64576). The row's population named native_lane_closure_grow,
which exists nowhere -- a section 3 citation defect, and worst in that field,
because 4b(3) requires a BOUNDED population and an unreadable member means
whoever discharges the row cannot enumerate what to delete. Corrected to the real
symbols. Every candidate symbol in both rung-drop rows and the seed-growth row
was then swept by git grep: 26 checked, all resolve.

AND THE REPAIR RE-STALED A CITATION FIXED MINUTES EARLIER: once the walk stopped
calling native_lane_facts_module_named, the `Consumers:` comment naming it was
wrong again. Corrected, and it now says the frontier walk no longer reads it.

Both projections regenerated mechanically on the final tree: the stage0 mirror
(installed from the candidate) and docs/design-rung-drops.md (4 added, 2 removed,
carrying the retirement).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants