Repository navigation
Model Google Sheets and converge review sheets by readback - #10986
Conversation
|
review 63314:
— sent from still-crab-505 |
|
review 63331:
— sent from still-crab-505 |
|
review 63349:
— sent from still-crab-505 |
|
review 63357:
The dashboard payload named four findings and then cut off after (2). If (3) and (4) are still open, they are not in the text I received. — sent from still-crab-505 |
|
review 63372 — both findings were real; they are now inhabited rather than deleted.
Head: |
|
review 63428 — all three findings were real; head
|
|
review 63460 — both listed findings were real; head
The artifact text cut off after “prefer a single authority from which the realizat…”. If there was a further duplicated-predicate site, it was not in the delivered list. |
|
review 63471 — both findings were real; head
The artifact text cut off after the §6 cost-shape quote; this is the projection file that quote named. |
|
review 63522 — both facets were real; head
The artifact cut off after the first-tab write; that is the qualification facet. |
|
review 63567 — both findings were real; head
The artifact cut off at “The correct shape is already demo…”; that demo is the Sheets major-dimension wire pair. |
|
review 63604 (claude/opus): both findings held on
— sent from still-crab-505 |
|
review 63645 finding 1 held on the previous head; fixed in this push. Sheet qualification had two homes: Findings 2 and 3 were truncated in the dashboard copy (the artifact cut off mid-sentence of finding 1). They were not in the tree I was given; please re-post them if they still apply. — sent from still-crab-505 |
|
review 63667 held: appends were schema-positional while every other path is header-keyed. Fixed in this push.
— sent from still-crab-505 |
|
review 63677 held: appends were a quadratic fold. Fixed in this push.
— sent from still-crab-505 |
|
review 63702 held: duplicate headers last-won in
— sent from still-crab-505 |
|
review 63716 held on both counts. Fixed in this push.
— sent from still-crab-505 |
|
review 63724: both findings held on the previous head. Fixed in this push, with one boundary noted.
— sent from still-crab-505 |
d7bdee4 to
170762a
Compare
|
review 63743: the conflict markers were real on the pre-rebase tree. They are gone on
That was the rebase onto main that landed after the DIRTY merge. The quoted — sent from still-crab-505 |
514fa0a to
13bfa46
Compare
|
review 63769 — agreed. |
|
review 63787 — both findings hold on the prior head; both are in e9059db.
|
|
review 63806 — agreed.
|
|
review 63819 — both items hold on the prior head; addressed in 236695b.
|
|
review 63832 — agreed that the previous wall was on the wrong artifact. Cited
|
|
review 63844 — agreed. The three duplicate-key scans ( |
|
review 63854 — those rows were dangling; they are consumed on 37a6cbe.
|
|
review 63864 — hoisted |
|
Fixed review 63876 (stdout: /api/reviews/63876/artifacts/stdout.log).
Witnesses |
|
Fixed review 63889 (stdout: /api/reviews/63889/artifacts/stdout.log). The request path no longer splits a string this module concatenated. Write-plan cells are
Witnesses including |
Those rows are not exercised by a transport yet; the live adapter frontier already names that later consumer. A test that greps a concat for its own operand is not coverage. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 64111 — the decoration was real; deleted in 3e4bbb5.
The dashboard payload truncated after that finding. If the cut-off second item was another decoration in the same function, it went with it. — sent from still-crab-505 |
Keep both additive extdeps_scope_frontier paths: eBay marketplace-account-deletion and Google Workspace/Sheets. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Merged current Renderer coupling after #11047: this PR adds no RFM rows and no design-ledger receipts, so — sent from still-crab-505 |
Quota numbers are already enrolled through sheets_rate_limits. The citation had no reader after the decoration witness was dropped. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 64278 — dangling citation was real; deleted in 23d3ccd.
— sent from still-crab-505 |
Review-sheet fleet admission now matches the estate calling-home fact, so a later Identified home cannot stay AwaitingIdentification in this module. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Fixed review 64312: deleted — sent from still-crab-505 |
Keep #10986 an ancestor of current main so the PR is not behind.
…mpty A1 end. GetValues is whole-tab only; a computed last column had no executing consumer. Bounded ends are now spelled in sheet_a1_range_wire, so WholeTab cannot emit Review!A1: by fabricating an empty token. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Fixed review 64342: Deleted Deleted — sent from still-crab-505 |
Observe-only can refuse a disabled API instead of always producing EnableApiPlan. Policy is a workflow fact, as it already is on review_sheet_ensure. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep #10986 an ancestor of current main.
|
Fixed review 64365: — sent from still-crab-505 |
The sheets_api_service_id replacement pasted the census name onto a line that already imported it. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep #10986 an ancestor of current main.
|
Fixed review 64403: deleted the duplicate — sent from still-crab-505 |
…nt first. Append writes only non-operator runs, so a populated judgement in the target row is Unreadable rather than a blanking write. Admission consults the enablement decision before the serviceusage IAM grant, so an already-enabled API does not demand a human grant. Co-authored-by: Cursor <cursoragent@cursor.com>
The predicate now sees append run column names, and the append witness asserts judgement is absent from emitted A1 ranges rather than written as blank. Co-authored-by: Cursor <cursoragent@cursor.com>
…duplicate judgements. Admission treated any DischargedAt share as proof for the requested spreadsheet. Identity now names spreadsheet and writer, and admit compares that identity before admitting. judgement_for_listing reads through the duplicate-refusing keyed roster instead of first-match. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 64497 on
— sent from still-crab-505 |
Apply treated any DischargedAt intervention as the enable grant. Identity now names project and writer, admit joins that identity, pending returns the expected intervention, and a foreign discharge refuses. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressed review 64546 on
— sent from still-crab-505 |
…re its row MERGE of origin/main dfac90c (#11121, #11142, #11154, #10986). Three conflicts. namespace_wave_admission.rs: main's THIRTY-SIXTH DISSOLUTION record kept, this branch's 181 still-required rows kept with their 181 expected_candidates. accepted_source_emits_uncompilable_target.dag: took MAIN's side -- their rung claim is mechanically preventable backed by executing evidence, this branch's said still-mitigatable and is superseded, and their four added receipts are preserved. v1_compiler_emit_rust.rs: resolved BY REGEN, never text-merged; main's bytes stood as a placeholder and the regenerated mirror overwrote them from the merged .dag authority. THE WALK IS REPAIRED RATHER THAN DEFERRED, because the primitive it was waiting for is now in the tree. #11121 landed as dfac90c (v2.std.collection primitive-backed map_insert/map_lookup delegates), which is the capability the declared drop named. DESIGN section 6: a proven cost-shape defect is always fixed, and a trigger amended after the capability arrives is a deferral with better wording. SHAPE. native_lane_facts_index builds module -> imports ONCE, before the recursion. native_lane_module_reachable looks up only what the frontier names and carries seen_set through the recursion. Neither is rebuilt per round: rebuilding either would reintroduce the cost under a keyed spelling. A MODULE DECLARED TWICE APPENDS, AND THIS IS THE CASE A REVIEW WOULD HAVE PLANTED. The fold this replaces visited every fact whose module the frontier named, so two facts declaring one module contributed BOTH import lists. A naive map_insert keeps the last and SHRINKS the closure -- a behaviour change wearing a performance change's clothes, and the same silent narrowing this PR has already repaired twice. The index appends on a duplicate key. PRESERVED: declared membership; the refusal arms (fuel exhaustion still refuses the whole derivation by identity with budget and frontier); last-round completion. DIVERGED, DELIBERATELY AND STATED ON THE CARRIER: discovery order is FRONTIER order, not FACT order. Preserving fact order needs a per-round pass over all modules to re-derive it -- the repeated scan this repair removes. It is unobservable, checked rather than assumed: native_lane_closure_ingest filters by membership (the ingest supplies its own order), both halves of native_lane_ingest_matches_closure are membership tests, and the emitted receipt carries `closure.len()`, a count, never the sequence. If a consumer that reads the sequence ever appears, THAT change owns this order fact; it cannot be inherited silently from here. NOT CLAIMED: that the route is now O(closure). One walk changed. The instrument is the universe_derivation span -- 192.4 s at 36e6ad9 -- and the successor run on this head is the before/after. No cost witness is added: no corpus home can hold a planted-quadratic control for this walk inside the 500 ms line without a synthetic population that exceeds it, and a witness that cannot discriminate is worse than none. ROW RETIRED BY ITS TRIGGER, with the repair as the discharge, in this same commit -- never in an intermediate state with the original scan still standing. Retiring on the capability alone would have been the 4b(3) inflation: a row marked discharged with the quadratic walk intact. CITATIONS (review 64576). The row's population named native_lane_closure_grow, which exists nowhere -- a section 3 citation defect, and worst in that field, because 4b(3) requires a BOUNDED population and an unreadable member means whoever discharges the row cannot enumerate what to delete. Corrected to the real symbols. Every candidate symbol in both rung-drop rows and the seed-growth row was then swept by git grep: 26 checked, all resolve. AND THE REPAIR RE-STALED A CITATION FIXED MINUTES EARLIER: once the walk stopped calling native_lane_facts_module_named, the `Consumers:` comment naming it was wrong again. Corrected, and it now says the frontier walk no longer reads it. Both projections regenerated mechanically on the final tree: the stage0 mirror (installed from the candidate) and docs/design-rung-drops.md (4 added, 2 removed, carrying the retirement). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
Summary
extdepsauthorities (not GCP rows):values.get/values.batchUpdate, published quotas, and the spreadsheets OAuth scope. Auth reuses ADC +SecretRef/gunbc.secret_provision; no second credential type and no invented idempotency key.std.upsert_decision(viaensureassembly) over an independent readback of the derived region, keyed by listing identity. Operator columns are never written; a hand-edited derived cell refuses with a located cell; gone listings that still carry judgement are retained and markedStandingGone.StandingObserved|StandingGone). Cell text islisting_standing_labelat emit; ingest isread_listing_standing. Foreign cell text refuses.gunbc.review_sheet_operator, andreview_sheet_live_accessrefuses before any write: Sheets API enablement on the existinggunbai-secretsproject (serviceusageGetService,sheets.googleapis.com), fleet-automation SA +secret_provision(WIF binding isNoDischargeSiteModeled— unverified, not assumed live), a declared spreadsheet identity with an owner (FleetOncecreate), and Editor sharing with that SA (DeviceOnceper sheet, not FleetOnce). A Sheets HTTP refusal is not this decision.Sheets works against a plain Google account as well as a paid Workspace domain. Where Workspace specifically bites is domain sharing policy (forbidding shares outside the org can block sharing with a service-account principal). That policy is an unobserved operator fact (
DomainSharingPolicyUnobserved); we do not assume either way.One public PR: the projection still imports only
std.typesandstd.upsert_decision. Gmail is out of scope.Renderer coupling (#11047)
This PR does not add recurring-failure-mode rows, design-ledger receipts, or docs-projection prose. The RFM render
authored(join(r.receipts, " ")) therefore has no new inputs from this diff. Added strings are path identities onextdeps_scope_frontier, Service Usage / OAuth / quota facts consumed by folds and witnesses, and sheet A1/ensure plans — not receipt lists joined for a markdown emit. Looked because "nothing I import changed" is not a clearance after #11100.Discriminating REDs (executed)
Instrument:
gunbc run --source-root dag --source-root src/v2 --entry dag/test/claim/review_sheet_converge_witness_test.dag --function <name>. Eachtest fnreturnsBool; the CLI then refuses because it wantsProcessExit— the value printed is the verdict.alphareplaced withhand-editedconverge_over_hand_edited_derived_cell_refuses_and_names_the_cellRefusenaminglisting=L1 column=title cell=B2Observedreplaced withObseredforeign_standing_cell_refuses_and_names_the_cellRefusenamingcolumn=standing cell=C2converge_twice_unchanged_is_noopNoopthenNoopbuyconverge_preserves_populated_human_columnApplythat does not touchjudgement; readback stillbuyresorted_sheet_does_not_move_a_judgementNoop; L1 stillbuy, L2 stillskipbuylisting_gone_with_judgement_is_retained_and_markedApplystanding labelListingGone; no append; judgement stillbuygunbai-secretscommitted_operator_path_refuses_unobserved_sheets_enablementReviewSheetOperatorRefused; live access stays closedNoDischargeSiteModeledunverified_wif_is_awaiting_human_not_assumed_liveReviewSheetAwaitingHumanongcp-fleet-secrets-wif-bindingundeclared_spreadsheet_is_fleet_once_create_not_a_caller_stringFleetOncesharing_is_device_once_editor_with_the_fleet_saDeviceOncenaming the fleet SA as EditorTest plan
trueon this tree