Repository navigation
Delete the required-v2-native CI job; the route stays as an operator-invoked instrument - #11003
Merged
Merged
Conversation
…invoked instrument Operator ruling 2026-09-11. The job landed with #10882 citing a ~70-minute native run inside a 180-minute envelope; the only full run on the real runner class took 4h06m at 14.8 GB, and the workflow's concurrency group (per PR number or run id, cancel-in-progress false) never supersedes a running job, so every push added another ~4h claimant. 31 native jobs were running concurrently this morning and the build and floor lanes were failing on main under memory stalls and budget interruptions. Cut at the root: WitnessFloorV2NativeLane leaves gunbc.witness_floor_workflow, the v2-native lane and phase leave gunbc.required_ci_phase_roster and the host binary, witnesses.yml and docs/design-rung-drops.md are regenerated. The route model, harness and admission authority are unchanged and reachable as claim_executor --v2-native-route. Declared as the 4b(3) drop gunbc.rung_drop v2_native_route_off_the_merge_path with a capability-shaped trigger; the consolidation witness reds if required-v2-native returns. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQyBe1FaYb3bFZmpTczetX
2 of 4 tasks
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 11, 2026
… deleted CI job
Three prose corrections to the same annotation, none changing a rendered byte.
THE OVERCLAIM. The doc comment called the parameter's removal "the
construction rather than the check", so that a repository path "cannot be
rendered into a manifest by a function that is not handed one". That is a
wall this change does not build. `CargoDependency` still admits
`CargoDepSource::LocalPathDep { path }`, so a local path remains authorable
here from a literal -- which is how this commit's own discriminating red was
established, with a hardcoded `/repo/src/v1/stage0`. Claiming otherwise is
rung inflation (DESIGN 4b(1)) in the compiler's self-description. What the
removal actually buys is stated instead: it eliminates the live producer
route that minted the seed path dependency, and the witness beside it
additionally refuses a rendered `src/v1` / `v1-compiler` row as a second,
independent reader of the same output. A type-level registry-only boundary
is explicitly NOT claimed; it belongs to the terminal shape, where the host
consumes the emission's own manifest rather than authoring a second one.
THE DEAD CITATION. The `[lib]`-name paragraph measured its E0433 on "the
required-v2-native lane's first preparation". #11003 deleted that job; the
route survives as the operator-invoked `--v2-native-route` instrument. The
paragraph now names the two consumers this manifest actually has -- that
instrument and the `emit-compile` phase -- rather than a job main no longer
declares.
Five further "native lane" references in this file name OTHER declarations
and are #11003's own unswept residue on main, not this change's subject;
they are left for that sweep rather than widened into here.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DHjB4qGMsejnXWhdejjmU8
briansrls
pushed a commit
that referenced
this pull request
Sep 11, 2026
…-scope onto --v2-native-route Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 11, 2026
The annotation added by this PR's first commit copied two figures into prose -- "emits 15 files" and "completes at status 0" for the `dag/std/node.dag` closure. DESIGN section 6 forbids exactly that: name the producer that re-derives a measurement, never copy its numbers, because a transcribed number is unreachable from the thing that owns it and rots without anyone touching either end. Section 4c adds that an annotation is never evidence a machine claim holds, since no Accepted program can read one. The point lands with unusual force here, and the reviewer said so: this PR's SECOND commit exists because a comparable transcribed citation in this same doc comment -- the required-v2-native CI job, deleted by #11003 -- had already rotted. So the counts go and the entry point stays. The replacement names `run_required_emit_compile` over `gunbc.ci_layer_roots` `required_emit_compile_entries` as the producer that re-derives the claim on every run, emitting each entry's closure through this writer and handing the result to `run_cargo`. A seed symbol the emission failed to cover refuses there, on the acceptance path, rather than in a sentence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DHjB4qGMsejnXWhdejjmU8
This was referenced Sep 11, 2026
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 11, 2026
Review 63636. The commit that followed the lane's deletion repaired native_standing and left lens_native_route_reach -- an authored NonEmptyStr naming "the required-v2-native lane" -- feeding reached_by_native_route. One published column reported reach through a lane the column beside it reported as deleted, and unlike the annotation form this ledger's own row describes, a FOLD read it. Fixed by deriving rather than rewording, which is the move this module has made everywhere else and the reason the other columns survived #11003 without anyone editing them. WHAT REACH MEANS NOW, AND THAT IT COLLAPSES. The axis asks which EXECUTING route names the door as a consumer. With the required lane deleted the answer is none: the route model and harness survive and still enter the door when invoked, but an operator-invoked instrument is not an executing route in the sense this axis was built to distinguish. So reach and native standing now give the same answer for every row and the axis carries no information it did not already carry. That is stated rather than hidden -- an axis that has gone constant is worth noticing -- and it separates again when gunbc.rung_drop v2_native_route_off_the_merge_path retires. reached_by_native_route 13 -> 0. The RouteReach field leaves V2CompileObligation entirely; no row authors it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz
briansrls
pushed a commit
that referenced
this pull request
Sep 11, 2026
…scape (#10942) * v2 obligation census: claimed vs executing-natively vs seed-side escape Every compile-time obligation v2 declares, as data, with the rung it EXECUTES on each route rather than the rung it claims. Twelve obligations: the compile door itself, the five always_required_root lenses, the three always_required subtree lenses, and the three declared primitive traversal facts whose order leaves determinism open (two HostUnspecifiedOrder, one TraversalOrderUnclassified). Executed by folding the roster, not transcribed: 12 claimed, 0 executing natively, 0 executing on the interpreted per-PR route, 12 with an open seed-side escape. Two independent reasons the executing columns are zero. No lens witness is in a directory gunbc.ci_layer_roots witness_discovery_scan_dirs walks -- several are additionally frozen path deferrals, which means declared never-executed -- and validate_then_compile has no production caller, so a roster that fires on every call of it fires never. The two machine_shape witnesses that ARE inside the scope import std.machine_shape, not v2.lens.machine_shape. mandatory_tag is the roster's only WallNow and all twelve of its gate witnesses are frozen, including the one whose job is the root-roster enrollment the claim rests on. Read-only measurement. Two findings are named and left to their owners: the compile door's own annotation asserts, present tense, that the de-enrolled lens_module_gate invariant executes per-PR via an entry that is both frozen and outside the scan dirs; and the only native behavioral receipt for v2.compiler.compile compares one prose string against a nine-line seed module containing that same string. A row-shape validator was written and deleted rather than shipped: every field is NonEmptyStr, so its RED is unauthorable in the corpus and at the fixture boundary alike, which makes it a decoration under DESIGN 4b. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Derive the census dispositions; retract "executing interpreted = 0" REVIEW 63152 ASKED FOR THE DERIVATION AND THE DERIVATION CAUGHT A FALSE HEADLINE. The first cut hand-authored each row's per-PR standing from a reading of gunbc.ci_layer_roots witness_discovery_scan_dirs. That reading was wrong: witness_discovery_scan_dirs has exactly one consumer in v1_compiler.cli_run and it is inside a cfg(test) module asserting the authority's own value. The walk that discovers witnesses takes every *_test.dag under witness_layer_roots (dag, src/v2) and subtracts gunbc.ci_layer_roots witness_exclusion_frontier by substring. So the corrected count is 9 of 14 executing on the interpreted per-PR route, not 0. Six obligations reported as unreachable are discovered and running. The error was invisible precisely because the disposition was a sentence rather than a question put to the authority that owns it -- DESIGN section 3, a fork is a correctness concern. Each row now authors only what no authority owns: which witnesses exercise the obligation (entry + function, the grain both rosters key on), what makes them red, and what the seed does outside reach. Whether those witnesses execute is ASKED on every fold, through gunbc.witness_deferral_freeze frozen_path_deferral_covers and a string_contains join against witness_exclusion_frontier that reproduces the host's rel.contains(pattern) rule rather than approximating it. The witness is no longer a fold over data the same file authored. It joins two live rosters it does not own, in both directions, and separates which authority decided -- a derivation that had lost the freeze lookup would still get the mandatory-tag answer right through the exclusion pattern alone. WHAT SURVIVES THE CORRECTION: executing natively is still 0 (no gate is reached on the native lane; every admitted subject refuses upstream at resolve). mandatory_tag is still the only WallNow with no executing evidence anywhere -- both its entries are frozen AND under the test/claim/long/ exclusion. The 00_compile annotation finding survives on a corrected ground: test/claim/enforcement/ is an exclusion pattern. Also per review 63152: the two discovered error classes are filed as rows under dag/gunbc/recurring_failure_mode/ rather than left in a comment, and the counts gained census_counts as the single named instrument. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Hoist the census annotations to module-item grain (DESIGN 4c) CI refused at the parse sweep with 62 errors: source annotations sitting inside declaration bodies, and a closing block with no module item after it. The hoist is not mechanical relocation. A field-by-field comment moved above its type reads as a disconnected list that has lost its referent, so the PathExecution arm notes and the V2CompileObligation field notes are rewritten as single annotations that NAME the arm or field they describe. The trailing findings block moves into the module header, where it has a subject. Verified with the local check rather than by inference: gunbc compile --output-dir --source-root dag --source-root src/v2 --entry <file> reports 0 blocking errors on all four files, including recurring_failure_mode/roster which pulls in both new rows. Witness-green is not parse-clean; they are different checkers. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Aim the next triggers at the real lever; withdraw the pub-use claim once Review 63166, both findings, both real. TRIGGERS. Eight next_trigger strings still required witnesses to be "homed inside witness_discovery_scan_dirs" -- the authority the same module's header had just discredited. The correction had shipped half: header and derivation fixed, repair targets not. That is worse than the original error, because a census whose job is to aim repair work was aiming it at a lever that does nothing. Each now names the capability that actually holds its rung down (DESIGN 4b(3)). For the six rows whose witnesses already execute per-PR, that is the NATIVE path alone -- the emitted lane's subjects must stop refusing at resolve so the door is entered -- stated with the reason no discovery, exclusion or freeze change can move them. For accumulator_copy and mandatory_tag the real walls are the exclusion patterns and the freeze rows, and the trigger names the cost that put them there rather than the pattern text, because editing a pattern around a witness that is still unaffordable swaps one silence for another. PUB-USE ATTRIBUTION. determinism_obligation's seed_escape still said the seed's pub-use walk is something this gate would classify NonDeterministic, while the same module withdrew exactly that diagnosis on primitive_map_keys_obligation and filed the measured unique_strings site as outside the gate's denominator. One measured incident, two answers, inside one module. The claim is withdrawn here too, on the same gunbc#10941 measurement, and the row now says which single row owns the incident. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Compute claimed-vs-executing; type the drop citations; share the trigger Review 63176, three findings, all real. The first is the one that mattered. THE CENSUS DID NOT COMPUTE THE COMPARISON IT IS NAMED FOR. claimed_rung was authored on all fourteen rows and read by no fold -- DESIGN 3c's red arm, and a title the diff did not make true. obligation_rung_is_inflated now compares the declared claim against the rung the path arms establish, as a STRICT inequality: under-claiming is honesty, not a defect, and only claimed > executed counts. Measured on the live roster: inflated_rung=13 of 14. That number is the census's whole point stated as data rather than as prose, and it is the first cut where the roster answers the operator's question by folding rather than by being read. A second checkable incoherence came with it: a row claiming above its own declared ceiling has asserted something its own record calls unreachable. Unlike the emptiness checks this module deleted for being unauthorable against NonEmptyStr, this RED is writable at the fixture boundary because the claim and the ceiling are independent fields. It is authored there and the live count is 0, with the fixture proving the check is not vacuous. THE WITNESS CAUGHT MY OWN ARM. The inflation test's third case reused the shared fixture, which hardcodes a StructurallyGuaranteed claim, and asserted it was not inflated while it executed at MechanicallyPreventable. It returned false rather than green. The arm is now four rows varying claim and paths independently, so the predicate cannot be reading only one axis, and the comment records the miss rather than hiding it. CITATIONS. related_drops was a List<NonEmptyStr> of bare identities while every other citation in the module was a DeclarationRef -- the exact shape this ledger files as unlanded_citation_indistinguishable_at_the_citing_end. Now List<DeclarationRef> through rung_drop_ref, which is mechanical because the row files are one declaration per module named for their identity. DUPLICATION. The same ~300-character next_trigger sentence was pasted on six rows; a correction would land in five and drift in the sixth. It is one shared data binding, the move this module already made for lens_native_execution. The report projection consumes the remaining authored fields -- kind, claimed rung, both path standings, ceiling, drop-citation count, trigger -- through census_report. discriminating_red and positive_control are deliberately not rendered: they are paragraphs, and a report that inlined them would be the source with worse formatting. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Consume guarantee_rung_index instead of re-minting the ladder order Review 63194. guarantee_rung_rank was a nickname: gunbc.guarantee_rung already declares guarantee_rung_index with byte-identical arms, the census already imports that module for guarantee_rung_label and the rung constructors, and gunbc.guarantee_stall already consumes the index. Minting a second name for the ladder's order is DESIGN 3's recurring violation, and it is the one this census exists to measure, committed inside the census. The order is a property of the closed vocabulary, so a second copy could disagree with the first the day a rung is added -- which is exactly the failure the index's own annotation says it exists to prevent. Deleted and repointed; census_counts is unchanged at inflated_rung=13 claiming_above_ceiling=0, which is the receipt that the swap preserved behavior rather than the assumption that it did. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Say route coverage, not executed; refuse the widen on an unverified entry Two corrections, one from plan review and one from review 63201, and both are about a name or an arm promising more than it computes. ROUTE COVERAGE IS NOT QUALIFICATION. obligation_executed_rung read whether each ROUTE executes the obligation's witnesses -- not whether the right lens ran, its red went red, its green stayed green, on the compiler closure, in the current generation. discriminating_red and positive_control are prose joined to nothing and the native standing is authored, because no per-lens native receipt authority exists to ask. Harmless today at native=0, but the moment a native standing flips the old name would report MechanicallyPreventable on the strength of a route running. Renamed to obligation_route_coverage_rung; the answer did not change, only the claim the name makes about it. Inflation findings stay sound under the weaker reading, and the module says why: route coverage is an UPPER BOUND on any qualified rung, so claimed > coverage implies claimed > qualified. What the weaker reading costs is false negatives, which is the gap the qualification authority closes -- named as the trigger: v2.compiler.self_host.compile_obligation_activation, a QualifiedOnPath arm carrying red-and-green receipts, required before MechanicallyPreventable is reportable. THE DERIVATION WIDENED WHERE IT COULD NOT DECIDE. "Not frozen and not excluded" reported plain ExecutedOnPath, so a moved or deleted entry -- covered by neither roster -- read as covered at exactly the moment the derivation lost the ability to answer. That is DESIGN 5's failure arm that widens instead of refusing. It is now the carve-out section 5 does allow: LOUD (ExecutedPendingEntryVerification, a distinct arm naming the premise, counted by obligations_executing_on_an_unverified_entry -- unverified_entry=9 beside executing_interpreted=9, two folds so they can diverge), BOUNDED (the fourteen rows' entries, it cannot grow with the corpus), and TRIGGERED by a typed bound DissolutionCondition rather than a sentence. AND THE SENTENCE IT REPLACES WAS THE CLASS THIS PR FILES. The annotation said the optimism's trigger was "named on the census's own next_trigger below" when no such declaration existed -- stale_present_tense_coverage_claim_in_the_ authority_consulted_first, committed inside the module that files it. The repair is the declaration, not a softer sentence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Ask the third subtraction; drop the forward citation to an unlanded module Review 63208 and the floor's own declarations phase, which caught the second half before I pushed it. THE DERIVATION ASKED TWO OF THREE SUBTRACTIONS. Per-PR standing is not discovery minus freeze minus exclusion: the required floor prepares the import closure of v2.workflow.required_floor required_gate_prefixes, not the corpus, and a discovered witness whose MODULE is outside that roster is dispositioned DeclinedOutsideGateClosure and does not run. The census reduced the question to two rosters and then reported discovery-reach as execution -- the same widen it had just argued against for entry existence, one subtraction larger. The arm now exists (DeclinedOutsideGateClosure), the roster is asked, and WitnessSubject carries module_path because that is the grain this third authority answers in -- read from each entry's own module line, not derived from its path, since several of these files drop the _test suffix. IT CHANGES NO ROW'S VALUE, AND THAT IS WHY IT HAD TO BE ASKED. Every witness the census names is under v2.test., which the roster admits. A subtraction that happens to be satisfied is not a subtraction that was checked. THE PREFIX TEST IS A CONTAINMENT TEST and the module says so: the floor matches a prefix, the substrate offers string_contains and no prefix primitive, and containment admits a superset -- so it can only ever say ADMITTED where the gate would decline. Same optimistic direction as the unverified entry, carried by the same declared debt rather than a second one. AND THIS WITNESS PROVES ITS OWN DORMANCY. test.claim.v2_compile_obligation_ census_witness_test matches no prefix in the roster, so it runs on changes touching its closure and is declined on ordinary floors. The new witness arm uses this file's own module as the negative control, and the consumer sentence that said the witness simply executes is narrowed to that grain -- it was the present-tense coverage claim this same change files in the ledger, for the third time in this PR. FORWARD CITATION REMOVED. entry_existence_verification_trigger was a bound_dissolution naming v2.compiler.self_host.compile_obligation_activation, which does not exist: the declarations phase refuses CITED-MODULE-ABSENT, and a forward reference to a DECLARATION inside an existing module is admitted while a reference to a missing module is not. Binding to some other module so the citation resolves would be a checkable trigger impersonating a decision. Unbound with the capability stated is the honest arm -- still a typed DissolutionCondition, and the citation direction stays right: the activation authority will cite the census, never the reverse. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Give the prefix approximation its own premise, trigger and number Review 63226. The census named the containment-for-prefix imprecision and then discharged it as "carried by the same declared debt" as the entry premise. That discharge was false: entry_existence_verification_trigger is scoped strictly to whether a witness FILE is still present at its path, so retiring it would leave the prefix approximation standing with nothing to retire it and no number beside the coverage number. That is the class this same change files in the ledger, asserted about a trigger this change authored -- the second time in one module, which is why the repair is a separate declaration rather than a longer sentence. The pending arm now carries a LIST of premises, because they co-occur and an arm carrying one would discharge the other by silence. Each premise has its own unbound trigger and its own fold, and each fold READS ITS OWN PREMISE through declaration_ref_eq -- the first cut of that pair folded the same predicate twice under two names, which would have made the second number track the first forever instead of the premise it is named for. Both read 9 today. A witness arm builds a standing carrying only the entry premise and shows the gate premise absent from it, which is the shape neither count can produce from the live roster and the only thing that makes "two numbers, two premises" a claim rather than a coincidence. Recorded while landing: the containment test is SOUND IN THE DECLINE DIRECTION -- containment matches a superset of prefixes, so a module the test says is outside really is outside -- and approximate only in the admit direction. The decline arm is therefore reported flatly and only the admit arm is pending. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Re-derive the native column against the landed lane; type the trigger THE NATIVE LANE LANDED AND THE ANSWER CHANGED. Every earlier cut reported RouteGapHeld on every row, on the true observation that the self-host behavioral receipt family publishes nothing spendable. That is still true of THAT family and it stopped being the whole native story when gunbc#10882 landed the required-v2-native lane, whose subject is the emitted compiler binary executing a derived v2.test.* population through its own SourceRootEvalDriver. A lens gate exercised by one of those tests runs inside the emitted binary, which is native execution in the only sense this census ever meant. So the native column is DERIVED too, by asking the lane's own universe predicate rather than re-deriving its prefix. Hand-authoring RouteGapHeld after the lane landed would have been the stale present-tense coverage claim in reverse -- a pessimistic one, which is not more honest, only wrong in the safer direction. MEMBERSHIP IS THE PREFIX INTERSECTED WITH FLOOR DISCOVERY, and the first fold got that wrong in the direction that flatters: asking the predicate alone reported 11 obligations executing natively, two of them exactly the rows carved out by the exclusion frontier. Corrected to 9. executing_natively moves 0 -> 9 and inflated_rung 13 -> 4. Those are the figures from the landed authority, and the pre-landing ones are superseded rather than annotated. STARTS_WITH EXISTS. Two cuts used string_contains for the gate-closure prefix test and declared the imprecision as debt -- first discharged onto the wrong trigger, then given its own. Both were answers to a question with a better answer: gunbc.witness_v2_native_route calls starts_with for exactly this one module over. A declared debt for a capability that already exists is not honesty, it is a permanent excuse with a receipt, so the premise, its trigger and its number are DELETED rather than kept as documentation. NEXT_TRIGGER IS NextRungTrigger. The prose field forked gunbc.guarantee_stall's typed carrier, which exists for exactly the DESIGN 4b(2) obligation these rows carry -- and the in-tree ledger row obligation_fields_as_prose_make_their_own_ grain_check_undecidable names GuaranteeStall as the existence proof that the fields are authorable. Consumed, with next_rung_trigger_render in the report. TRANSCRIBED NUMBERS REMOVED per DESIGN 6: the counts in the annotations are replaced by the names of the folds that re-derive them. COMPLETENESS IS NOW STATED, NOT IMPLIED. The roster was enumerated by hand and nothing joins it to the enrolled lens rosters at identity grain, so the census claims coverage of ITS OWN ROWS and not of v2's obligations as a whole. Every count is denominated in obligations_claimed. Reading them as "v2's obligations" would be completeness inflation in the headline of the module that measures it. The predecessor arm no_row_executes_natively retired by its own declared dissolution -- it went red when the lane landed, exactly as it said it would, and is deleted rather than repaired back to passing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Carry the fixtures to the typed trigger; my green was measured on stale bytes Review 63290, and it caught something worse than the defect it names. THE DEFECT. Typing next_trigger as NextRungTrigger changed the field and did not carry the five fixture rows over, which still built it as a NonEmptyStr. The witness could not typecheck, so every one of its arms was dead -- and this witness is the change's only executing consumer, which makes the whole census specification-without-execution for exactly as long as that stood. THE WORSE PART, RECORDED BECAUSE IT IS THE MORE USEFUL FINDING. I reported "all nine witness arms green by execution" on the PR and to the lane. That measurement was real and it was taken BEFORE the NextRungTrigger change; I carried the number across a revision that changed the thing it measured. A true reading of the wrong bytes is not a weaker claim than a false one, it is the same claim with better camouflage, and no reviewer reading my comment could have known which tree the nine referred to. So the fixtures now build climbs_when(capability: ...) with the import, and executing_arm -- dangling since the native field became a derived fold -- is deleted rather than left as a definition nothing calls. Re-measured on THESE bytes, named so the binding is checkable: all nine arms return true at this commit, not at its predecessor. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Repoint the ledger citation the native rework stranded required-ci declarations FAIL CITED-DECLARATION-ABSENT: gunbc.recurring_failure_mode.receipt_subject_is_the_prose_about_the_mechanism cited gunbc.v2_compile_obligation_census lens_native_execution, which the native-column rework deleted when that shared constant became a derived fold. The class is the one this PR already files twice over: a carrier swap strands the citations pointing at the old carrier, and a DeclarationRef into a declaration that no longer exists is exactly the state unlanded_citation_indistinguishable_at_the_citing_end describes. Committed in a ledger row about receipts being honest, in the change that authored it. Repointed to native_standing, which is the row's real subject anyway -- the finding is about the native receipt's subject, and the derived fold is what answers for it now. Audited rather than spot-fixed: every decl_ref in both new ledger rows and all 19 distinct refs in the census module were resolved against the tree, module and declaration. No other stale citation. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Narrow the witness's own run-grain claim to what selects it Review 63350. The consumption paragraph said the witness "runs on changes that touch its own closure". Changed-witness selection does not walk a closure: v1_compiler.cli_run changed_witness_identities_from_edited_test_fns folds the (file, function) pairs the run's DIFF edited, and nothing expands that to dependents. So the consequence is sharper than dormancy. A later change that edits interpreted_standing, native_standing or witness_subject_in_native_lane without touching the witness file selects nothing, and the derivation those folds implement goes unchecked on that run -- while the witness stays DeclinedOutsideGateClosure on every required run regardless. This is the third cut of this one sentence. The first said the witness simply executes; the second said it runs on changes touching its closure; each overstated by one grain, in the authority a reader consults first, which is the class this change files in the ledger. The annotation now records all three rather than quietly reading correctly, because a sentence that has been wrong twice is worth leaving its own history beside. Both files parse clean; no value changes, annotation only. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Count the native verdict premise; give the dormancy a typed trigger Review 63369, both findings, and the first is the widen this census exists to measure committed inside the census. THE NATIVE PREMISE WAS DECLARED AND COUNTED BY NOTHING. unread_native_verdict_premise was minted, attached to every native ExecutedPendingVerification, and then read only by witness fixtures -- obligation_is_pending_on folds the INTERPRETED standing alone, so the single debt fold tracked the entry premise and never the verdict. Meanwhile path_execution_is_executing scores a pending arm as executing, so obligations_executing_natively, obligation_route_coverage_rung and obligations_with_inflated_rung all CLEARED rows on a verdict nobody read: an identity whose native run reached NativeTestReturnedFalse or NativeTestRefused was reported route-covered at MechanicallyPreventable and dropped out of the inflation count. A premise with no fold is not a declared debt, it is a footnote, and the module's own sentence -- the debt's own number BESIDE the coverage number rather than inside it -- is exactly what it broke. Now obligations_on_an_unread_native_verdict reads native_standing and renders beside the others: unread_native_verdict=9. MY OWN ARM FOR IT WAS WRONG FIRST. It contrasted the native standing against the ENTRY premise, asserting the native arm does not carry it -- but the arm carries both, which is why the premises are a list. It went red, and the contrast moved to where the defect actually was: the same row asked through the interpreted fold answers false for the verdict premise, so a fold reading the wrong standing passes the first conjunct and fails the second. THE DORMANCY GETS A TYPED TRIGGER, because this module already ruled on the asymmetry one premise over: the repair is the declaration, not a softer sentence. witness_dormancy_trigger names both honest ways out and says plainly that growing required_gate_prefixes from inside the diff that benefits would be the move this census exists to object to. Ten witness arms, all true on these bytes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Delete the three sentences the native rework falsified Review 63446. Re-deriving the native column changed what the folds answer and left three annotations describing the old behaviour, in present tense, in the authority a reader consults first: - "Executing-natively is 0 because every admitted subject refuses upstream" - "THIS VALUE IS RouteGapHeld" said of every row, when it is now the arm for rows the lane does not reach - "the native standing is an authored field ... native execution is 0 everywhere, so the fold bottoms out at Mitigatable regardless" Each was true of the tree before gunbc#10882 and false after it, which makes them the meaning fork DESIGN section 3 names: executing-natively cannot mean both "no gate is ever asked, count is 0" and "lane membership pending a verdict, count is non-zero". It is the live specimen of the class this same change files, sitting on the fold that defines the headline comparison. They are DELETED rather than softened, and what replaces the third is the sentence I would have had to write anyway: the gap is NOT harmless any more. Before the lane, the native arm never executed, so the fold bottomed out whatever the name promised and the rename was the cheap half of a problem with no teeth. Now lane members report route coverage at MechanicallyPreventable on membership plus an unread verdict -- the reading the old name would have licensed, reached honestly through a named premise that obligations_on_an_unread_native_verdict counts. Swept both files rather than patching the three cited lines; what remains reads "THIS PARAGRAPH SAID" and "this file asserted", which is the history kept on purpose, not a live claim. No value changes: counts and all ten witness arms unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Follow the lane's deletion: native standing is off the merge path, not executing gunbc#11003 deleted the required-v2-native CI job on an operator ruling -- the only full run on the real runner class took over four hours at 14.8 GB and the workflow's concurrency group never supersedes a running job, so every push added another claimant. The route model, harness and admission authority are unchanged and still reachable when invoked; what left is the REQUIRED LANE. MERGING THAT MADE THE CENSUS WRONG IN THE FLATTERING DIRECTION. Lane membership no longer means execution on an acceptance path, so a native column that kept reporting ExecutedPendingVerification would have been this module's own headline defect for the second time in two days, in the same column, with the sign reversed: once when the lane landed and the module still said zero, once now when the lane is gone and the module would still say nine. Lane members now report RouteOffTheMergePath, citing gunbc.rung_drop v2_native_route_off_the_merge_path -- the authority for when the lane returns. This module does not restate its trigger. executing_natively 9 -> 0, inflated_rung 4 -> 13. Those numbers moved because the standing is DERIVED; an authored column would have sat still through both the landing and the deletion, which is the whole argument for deriving it. THE VERDICT PREMISE IS DELETED WITH THE LANE. With no required invocation there is no execution to be pending about, so unread_native_verdict_premise, its trigger and its fold described a state nobody can reach -- the dangling declaration DESIGN 3c calls red. They return with the lane. TWO LAWS SPLIT FROM THEIR ROWS, because both standings are now derived and no fixture obligation can reach a both-routes-executing state: route_coverage_rung_of and rung_is_inflated_of take their arguments, so their REDs stay authorable. An arm that could only ever observe one answer is the decoration 4b names, and that is what the row-based versions had become -- caught by both going red rather than by reading them. Nine arms, all true on these bytes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Derive route_reach; it was the last authored column and it went stale Review 63636. The commit that followed the lane's deletion repaired native_standing and left lens_native_route_reach -- an authored NonEmptyStr naming "the required-v2-native lane" -- feeding reached_by_native_route. One published column reported reach through a lane the column beside it reported as deleted, and unlike the annotation form this ledger's own row describes, a FOLD read it. Fixed by deriving rather than rewording, which is the move this module has made everywhere else and the reason the other columns survived #11003 without anyone editing them. WHAT REACH MEANS NOW, AND THAT IT COLLAPSES. The axis asks which EXECUTING route names the door as a consumer. With the required lane deleted the answer is none: the route model and harness survive and still enter the door when invoked, but an operator-invoked instrument is not an executing route in the sense this axis was built to distinguish. So reach and native standing now give the same answer for every row and the axis carries no information it did not already carry. That is stated rather than hidden -- an axis that has gone constant is worth noticing -- and it separates again when gunbc.rung_drop v2_native_route_off_the_merge_path retires. reached_by_native_route 13 -> 0. The RouteReach field leaves V2CompileObligation entirely; no row authors it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz * Delete the dead reached-by-route axis Review 63691, and it is this module's own deletion rule applied one column over. route_reach_of ignored its argument and returned NotNamedByAnyExecutingRoute constantly, ReachedByNativeRoute had no constructor anywhere in the tree, obligation_is_reached_by_the_native_route was constant-false, and census_counts published reached_by_native_route= as a permanently-zero column. That is DESIGN 4b's decoration -- permanently green by construction, carrying no information, worse than absent because it would be cited as coverage -- and 3c's dangling declaration. It is the exact ground on which this same change deletes the unread-verdict premise. WHAT THE PREVIOUS CUT DID WRONG IS THE PART WORTH RECORDING. It kept the axis and wrote an annotation CONCEDING it had gone constant. Stating the rule and then not applying it is worse than not noticing, because the concession reads as diligence while the decoration stays; the reviewer named it as the module applying its own deletion rule inconsistently, which is exactly right. The axis existed to separate two facts that really were different while the required-v2-native lane ran: a door a route names, and a door a route reaches. gunbc#11003 deleted the lane and with it the distinction. Its return is owned by gunbc.rung_drop v2_native_route_off_the_merge_path, which the module already cites; until then native_standing carries the whole of what this census can say about that route. RouteReach, route_reach_of, obligation_is_reached_by_the_native_route, obligations_reached_by_the_native_route and the published field are gone. The witness keeps its argument-grain exercise of route_coverage_rung_of and rung_is_inflated_of. Nine arms, all true on these bytes; both files parse clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPF5TTachtTAeAkYWQshXz --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Sep 11, 2026
* Cut the seed out of the emitted closure's dependency graph
`v1_compiler.emitted_closure_compile_host` `probe_manifest` minted
`v1-compiler = { path = <workspace>/src/v1/stage0 }` into the manifest of
every crate the emit-compile phase and the required-v2-native lane write.
So a fixed point measured on emitted BYTES said nothing about whether the
emitted compiler can BUILD: "v2 emits itself" could be true while the
emitted crate needed src/v1 present to link. It also meant building any
probe rebuilt the seed into the shared target directory the running
claim_executor was executing from.
MEASURED FIRST, and the denominator is zero. The emitter writes
`src/v1_rt.rs` into every emission (`v1.compiler.emit_rust`
`emit_v2_rt_module`, unconditional) and renders the NonEmptyVec /
NonEmptyBTreeSet wrappers into the emitted lib.rs; the emitted crate is
named `v1_compiled` for every entry that is not the retained-host
pipeline, so no emitted line paths into `v1_compiler`. The closure of
src/v2/compiler/00_compile.dag -- the native lane's own entry -- emits
172 files with zero `v1_compiler::` references and builds to a running
binary under RUSTFLAGS=-D warnings against a manifest naming no path
into the repository.
THE WORKSPACE ROOT IS NO LONGER A PARAMETER of `probe_manifest`, which
is the construction rather than the check (DESIGN section 5): a function
that is handed no repository path cannot render one into a manifest, and
`stage0_foundation_runtime_dependencies` carries registry rows only. The
unit test's seed assertion flips from requiring the path dependency to
refusing any `src/v1` substring, and was confirmed discriminating by
re-adding the dependency (red) and removing it again (green).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DHjB4qGMsejnXWhdejjmU8
* Say what removing the workspace root actually buys, and stop citing a deleted CI job
Three prose corrections to the same annotation, none changing a rendered byte.
THE OVERCLAIM. The doc comment called the parameter's removal "the
construction rather than the check", so that a repository path "cannot be
rendered into a manifest by a function that is not handed one". That is a
wall this change does not build. `CargoDependency` still admits
`CargoDepSource::LocalPathDep { path }`, so a local path remains authorable
here from a literal -- which is how this commit's own discriminating red was
established, with a hardcoded `/repo/src/v1/stage0`. Claiming otherwise is
rung inflation (DESIGN 4b(1)) in the compiler's self-description. What the
removal actually buys is stated instead: it eliminates the live producer
route that minted the seed path dependency, and the witness beside it
additionally refuses a rendered `src/v1` / `v1-compiler` row as a second,
independent reader of the same output. A type-level registry-only boundary
is explicitly NOT claimed; it belongs to the terminal shape, where the host
consumes the emission's own manifest rather than authoring a second one.
THE DEAD CITATION. The `[lib]`-name paragraph measured its E0433 on "the
required-v2-native lane's first preparation". #11003 deleted that job; the
route survives as the operator-invoked `--v2-native-route` instrument. The
paragraph now names the two consumers this manifest actually has -- that
instrument and the `emit-compile` phase -- rather than a job main no longer
declares.
Five further "native lane" references in this file name OTHER declarations
and are #11003's own unswept residue on main, not this change's subject;
they are left for that sweep rather than widened into here.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DHjB4qGMsejnXWhdejjmU8
* Name the instrument instead of transcribing its counts (review 63393)
The annotation added by this PR's first commit copied two figures into
prose -- "emits 15 files" and "completes at status 0" for the
`dag/std/node.dag` closure. DESIGN section 6 forbids exactly that: name the
producer that re-derives a measurement, never copy its numbers, because a
transcribed number is unreachable from the thing that owns it and rots
without anyone touching either end. Section 4c adds that an annotation is
never evidence a machine claim holds, since no Accepted program can read
one.
The point lands with unusual force here, and the reviewer said so: this
PR's SECOND commit exists because a comparable transcribed citation in this
same doc comment -- the required-v2-native CI job, deleted by #11003 --
had already rotted.
So the counts go and the entry point stays. The replacement names
`run_required_emit_compile` over `gunbc.ci_layer_roots`
`required_emit_compile_entries` as the producer that re-derives the claim on
every run, emitting each entry's closure through this writer and handing the
result to `run_cargo`. A seed symbol the emission failed to cover refuses
there, on the acceptance path, rather than in a sentence.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DHjB4qGMsejnXWhdejjmU8
---------
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
6 tasks
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 11, 2026
…tag two stale required-ci prefixes (a) src/v2/test/v2_native_route_test.dag: green_receipt_with_old_route_control copies every field of green_receipt() and swaps only the old-route arm, and it did not get emitted_build when #11011 added the field -- the floor refused the corpus on it (structural, adjudication REFUSED, no receipt TSVs written). One line, exactly what the comment above the literal already promises. Re-checked by joining every NativeRouteReceipt literal against the field rather than counting mentions: 19 literals, 0 missing. The count I used first (21 ctors vs 40 mentions) could not have found this, because 40 > 21 hid a literal with none. (b) native_lane_runner.rs carried two `required-ci:` prefixes inherited from #11011, which was authored while this WAS a required lane. #11003 deleted that job and the route survives as an operator-invoked instrument; the file header says "IT IS NOT A REQUIRED LANE, and the prefixes below say so" four lines above them. Retagged to `v2-native-route:` so the prefix stops claiming a required lane emitted the line. (c) review 64075, finding 1 (DESIGN sections 4d and 5). OldRouteNotPresentAtWindow asserts a property of an INTERVAL -- nothing was there for the whole spawn window -- on evidence about an INSTANT: one is_file() before either spawn. A binary materializing mid-run (concurrent build, cache landing) greened the one control whose whole job is proving the native route could not have fallen back. The window is now read at BOTH ENDS, the second read taken before the guard drops (dropping it restores the withdrawn file), and a path that became occupied REFUSES with OldRouteAppearedDuringWindow rather than widening the arm to "absent at some point". The withdrawn arm still closes its window by construction, so the two arms stay distinct. The witness annotation now states the mechanism rather than only the claim. (d) review 64075, finding 2 (sections 4c and 3). The cost annotation still described the deleted per-phase cost_partition_line: it called four names "exact" (universe_derivation, module_preparation, identity_evaluation, receipt_admission), named three more that do not exist (source_load, test_context, module_bundle), and cited identity_evaluation.wall_nanos, which names no field at all. The emitted receipt prints the row set NativeDriverExclusiveRows carries. The annotation now names that set once and states only what belongs to this main -- that the eval row is the sum of native_lane_identity_row and nothing else. Three stale comments inside the emitted code are corrected to the row names that exist. This PR removed the same defect in dag/std/compiler_entry.dag and then left it one file over; the reviewer was right to say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Operator ruling 2026-09-11: the
required-v2-nativeCI job is deleted now; a replacement is designed from the ground up with the operator before any native-route job returns to the merge path.Why delete rather than retune
witnesses.ymlconcurrency isgroup: witness-floor-${{ pull_request.number || run_id }}withcancel-in-progress: false— a running native job is never superseded, on PRs or on main. Every push added another ~4h claimant.required-v2-nativejobs;required-witnesses-floorfailing on main itself under memory stalls and changed-witness budget interruptions. A required check that never concludes was displacing the checks that do.What this change does
Root-first cut (§3 replacement migration), emission regenerated from the authority:
gunbc.witness_floor_workflow:WitnessFloorV2NativeLaneand thev2-nativeRequiredLanerow deleted; the native-lane job functions and its 180-minute timeout row deleted..github/workflows/witnesses.ymlregenerated — jobs are nowrequired-witnesses-build,required-witnesses-floor,heal-generated-artifacts,witnesses(aggregate).gunbc.required_ci_phase_roster:V2NativeLane/V2NativePhasedeleted from the lane and phase coproducts, the name/lane matches and the enrolled roster.claim_executor's host enum, lane match,REQUIRED_CI_PHASESandPHASE_ROSTER_VARIANT_LABELSfollow (the variant-set and (phase, lane) pair joins require both sides to move together).--required-lane v2-nativeis no longer a lane word.gunbc.fabric_witness_run:v2_native_lane_run_commanddeleted.gunbc.witness_v2_native_route(admission authority),cli_run::native_lane_runner(harness) and the controls. They are reachable asclaim_executor --v2-native-route --source-root dag --source-root src/v2— the same producer the lane ran, operator-invoked, so a hand-minted receipt and a lane receipt cannot be two facts. This keeps the srv2 closure measurements the D-lanes are accepted on.gunbc.rung_drop.v2_native_route_off_the_merge_path(new, typed): mechanically preventable → mitigatable, deleted without replacement, population = everynative_route_admissionclause on every merge candidate plus the four controls. Restoration trigger is the capability: a required native-route job that concludes inside its declared timeout on the real runner class, supersedes older runs of the same head, and whose red still discriminates every admission clause. Re-addingrequired-v2-nativein its 2026-09-10 shape does not retire it.docs/design-rung-drops.mdregenerated.test.claim.witness_floor_workflow_consolidation_witness_test:required-v2-nativejoins the deleted-lane set inw_RED_the_deleted_lanes_do_not_return(with its own positive control), the roster-size and needs assertions return to two lanes.Evidence
gunbc run … generated_artifact_gate.dag --function main_wet: onlywitnesses.ymlanddocs/design-rung-drops.mdmoved.w_RED_the_deleted_lanes_do_not_return,w_RED_neither_lane_waits_on_the_other,w_RED_lane_contexts_collide_with_no_other_emitted_workflowevaluatetrueon this head.cargo clippy --release -p v1-compiler --bin claim_executor -- -D warnings: clean.cargo test --release -p v1-compiler --bin claim_executor -- tests::: 15 passed, including the rewritten lane-roster pair-join tests.Follow-on
The replacement job's contract is being agreed with the operator separately (eager-raven-113's measured proposal: emit+build as a phase with its own receipt, closure-only or affected-set on PRs, whole universe on main with pending-collapse and a 300-minute commissioning bound, per-phase receipts bound to the head). #10981's job-scoped native grouping is moot after this; its whole-workflow grouping half rebases onto this.
🤖 Generated with Claude Code
https://claude.ai/code/session_01DQyBe1FaYb3bFZmpTczetX