Repository navigation
The v2-native route producer sets -D warnings itself, records the emitted build on its receipt, and separates receipt from telemetry - #11011
Conversation
…admitted memory bound, build receipt
…ry bound, and separates receipt from telemetry RUSTFLAGS is SET at the emitted-crate cargo spawn from the one repository row (gunbc.repo_self_build repo_self_warning_denial; extdeps.rust.cargo RustflagsEnv), never inherited from a CI action's default. NativeRouteReceipt carries the build (argv, flags, rustc identity, status, warning count), the enforced memory bound (gunbc.host_budget_source carrier; memory.max only), and per-identity provenance (VerdictExecuted | VerdictMaterialized, a declared frontier on the closure digest) with derived hit/miss counts; native_route_admission gains seven named clauses. rss/trim/wall move to a telemetry line off the receipt. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
…ovenance leaves this PR review 63410: v2_native_lane_memory_envelope / _reserve were a second spelling of gunbc.runner_slot_allocation's memory_high and memory_max-memory_high; they now read gunbc_runner_slot_desired(), so the requirement is the slot's memory.max by construction (witnessed). Ruling D (2026-09-11): the provenance arms and hit/miss counts land with the provider-spine lane where their consumer exists; removed here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
|
review 63410 (slot-budget fork): fixed in 5a3dd54. v2_native_lane_memory_envelope() now reads gunbc.runner_slot_allocation gunbc_runner_slot_desired().memory_high and v2_native_lane_memory_reserve() is that slot's memory_max minus memory_high, so the requirement equals the slot's memory.max by construction; the witness a_bound_below_the_requirement_is_refused_and_an_exact_fit_is_admitted now also asserts envelope == slot.memory_high and requirement == slot.memory_max. The two literals are gone. Same push removes the i-a provenance arms per the side-chat ruling D (they land with the provider-spine lane). |
… std.realization cost vocabulary C7 correction (side-chat, 2026-09-11): resource preflight (predicted critical path, memory envelope) is owned by route integration under std.realization and reads gunbc.runner_slot_allocation; an admission arm on NativeRouteReceipt re-homed it. Removed with its rows, clauses, witnesses and producer minting. The telemetry line stays, on no receipt field. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
Producer-regenerated (claim_executor --required-regen on BuildBuddy); the candidate's sha256 9f3e9f4275aa043e1eba09bfc1d4a1c3285dbe00cc0322b025d06458d00eeeb4 is the committed file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
…ty; the target-dir rationale states the fingerprint cost review 63536: RustflagsEnv was minted with only a spelling witness as consumer while the spawn hard-spelled "RUSTFLAGS" (DESIGN 3c dangling row, 3 second spelling). The spawn now reads both env names through extdeps_cargo::cargo_environment_variable_name, and the unit test asserts the row's spelling. The run_cargo rationale no longer claims the seed build's fingerprint is shared off-CI: RUSTFLAGS is in the fingerprint, so a workstation pays one dependency-graph rebuild under the denial. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
|
review 63536: both findings fixed in d732881. (1) The probe spawn now reads its env-var names through the stage0 mirror of extdeps.rust.cargo — cargo_environment_variable_name(CargoEnvironmentVariable::RustflagsEnv) (and CargoTargetDirEnv likewise) — so RustflagsEnv has an executing consumer and the spawn no longer spells the name; the unit test the_probe_cargo_spawn_sets_the_warning_denial_and_the_receipt_names_that_spawn asserts the row's spelling. The denial VALUE stays a documented mirror of repo_self_warning_denial (no repo_self_build mirror exists in stage0), closed mechanically by the receipt clause emitted_build_warnings_not_denied. (2) The run_cargo rationale now states the fingerprint fact: RUSTFLAGS is part of cargo's fingerprint, CI's seed build shares it, a workstation pays one dependency-graph rebuild under the denial on the first probe build and is incremental after. |
…he extdeps_cargo use line
srv2 closure receipt at 34bd1b7 (post-D4, post-#10988 baseline)Instrument: Compared with the main baseline taken the same way at 199aee7 (
So this head changes nothing in the emitted compiler's provenance; its receipt is the baseline's. Regressed files: none. Population: unchanged. srv2 artifacts: — sent from eager-raven-113 |
…s, one bound compiler, wrappers disabled Landing-review finding on 34bd1b7: the receipt recorded RUSTFLAGS=-D warnings and a compiler probed via RUSTC/PATH while cargo reads CARGO_ENCODED_RUSTFLAGS first and may select build.rustc or front the compiler with a wrapper, so the receipt could disagree with the build. The construction now resolves one executable (RUSTC, else rustc on PATH; typed refusal otherwise), takes its identity from the crate's own directory, binds cargo to it via RUSTC, sets RUSTC_WRAPPER and RUSTC_WORKSPACE_WRAPPER present-and-empty (which also disables config wrappers), and carries the denial on CARGO_ENCODED_RUSTFLAGS and RUSTFLAGS alike. The receipt records the bound compiler path (clause emitted_build_compiler_unbound). RED controls plant conflicting ambient values on every channel and prove the spawn overrides each. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx
Keep native ancestry acquire/genesis and OldRouteAbsentByConstruction; take #11011's bound cargo invocation, emitted-build receipt, and warning-denial rustflags. Remap stays an extra spawn suffix plus the ancestry store, not a second denial string. Co-authored-by: Cursor <cursoragent@cursor.com>
…-facts boundary as rows #11011 put NativeRouteEmittedBuild on NativeRouteReceipt (argv, RUSTFLAGS, bound compiler, rustc identity, exit status, warning count) and four admission clauses over it, minted in the seed's receipt_value. This branch had already deleted receipt_value: the receipt is minted INSIDE the emitted binary from the host-facts TSV, so the two sides conflict on native_lane_runner.rs and both must survive semantically. Resolution: the build is a host observation by the same rule as the identities (the cargo spawn this binary is the product of cannot be observed from inside it), so it crosses as host facts. write_host_facts writes cargo_argv_len plus one cargo_argv_<i> row per word (a word is opaque bytes; no separator is smuggled into a value), rustflags, compiler_path, rustc_identity, exit_status and warning_count, and refuses a value carrying a tab or newline rather than letting the decoder read back a different row set. NativeLaneHostFacts (v2.compiler.compile) gains emitted_build and native_lane_receipt threads it into the receipt; the rendered main (v1.compiler.emit_rust emit_source_root_eval_driver_main_rs) decodes the rows with host_fact_int refusing a non-integer, and the section-7 frontier bullet names the decoder's grown surface. Main's telemetry line (process RSS, slot cgroup memory, wall -- on no receipt field) is kept at the lane's end. The stage0 emitter mirror (v1_compiler_emit_rust.rs) and the compile mirror are left to drift for the srv2 regeneration, as before: the required-v2-native job is expected red at this head (the seed-emitted main lacks the field the .dag record now carries) until the mirror commit. Verified: v1_src_dag_parse 5533 file(s) parse-clean; cargo clippy -p v1-compiler --all-targets -- -D warnings clean (BuildBuddy). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01K5undHKUrfMXhB8tcmphja
interpret_acquisition takes the workspace so it can load the stored build observation, and finish_cargo_command takes a mutable Command for output(). Co-authored-by: Cursor <cursoragent@cursor.com>
…tag two stale required-ci prefixes (a) src/v2/test/v2_native_route_test.dag: green_receipt_with_old_route_control copies every field of green_receipt() and swaps only the old-route arm, and it did not get emitted_build when #11011 added the field -- the floor refused the corpus on it (structural, adjudication REFUSED, no receipt TSVs written). One line, exactly what the comment above the literal already promises. Re-checked by joining every NativeRouteReceipt literal against the field rather than counting mentions: 19 literals, 0 missing. The count I used first (21 ctors vs 40 mentions) could not have found this, because 40 > 21 hid a literal with none. (b) native_lane_runner.rs carried two `required-ci:` prefixes inherited from #11011, which was authored while this WAS a required lane. #11003 deleted that job and the route survives as an operator-invoked instrument; the file header says "IT IS NOT A REQUIRED LANE, and the prefixes below say so" four lines above them. Retagged to `v2-native-route:` so the prefix stops claiming a required lane emitted the line. (c) review 64075, finding 1 (DESIGN sections 4d and 5). OldRouteNotPresentAtWindow asserts a property of an INTERVAL -- nothing was there for the whole spawn window -- on evidence about an INSTANT: one is_file() before either spawn. A binary materializing mid-run (concurrent build, cache landing) greened the one control whose whole job is proving the native route could not have fallen back. The window is now read at BOTH ENDS, the second read taken before the guard drops (dropping it restores the withdrawn file), and a path that became occupied REFUSES with OldRouteAppearedDuringWindow rather than widening the arm to "absent at some point". The withdrawn arm still closes its window by construction, so the two arms stay distinct. The witness annotation now states the mechanism rather than only the claim. (d) review 64075, finding 2 (sections 4c and 3). The cost annotation still described the deleted per-phase cost_partition_line: it called four names "exact" (universe_derivation, module_preparation, identity_evaluation, receipt_admission), named three more that do not exist (source_load, test_context, module_bundle), and cited identity_evaluation.wall_nanos, which names no field at all. The emitted receipt prints the row set NativeDriverExclusiveRows carries. The annotation now names that set once and states only what belongs to this main -- that the eval row is the sum of native_lane_identity_row and nothing else. Three stale comments inside the emitted code are corrected to the row names that exist. This PR removed the same defect in dag/std/compiler_entry.dag and then left it one file over; the reviewer was right to say so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
…mpty-map generics, argv word-list splice, append concat form (#11154) * Three v2->Rust emitter arms the widened 00_compile closure exposed #11011 widened the emitted closure to carry extdeps.rust.cargo_build and extdeps.exec.command; the first srv2 execution of that route emitted a crate rustc refused with 28 errors, all of them in those two newly-emitted modules. Reproduced locally and repaired at the emitter, so any closure carrying the shapes emits correctly. None of #10940's layer-inversion fix is here. (1) EMPTY-MAP TURBOFISH, E0425. A module-scope `data ...: Map<String, String> = empty_map()` emitted `v1_rt::rc_empty_map::<K, V>()`: the call resolved to the v2.std.collection DECLARATION and the emitter wrote that declaration's own formals into a module with no generic scope. The fold-init arm had already learned to defer such a turbofish to the target's inference; the plain-call arm had not. Both now read one authority, rust_empty_map_init_expr -- two sites asking one question was the second representation DESIGN section 2 forbids. (2) WORD LIST SPLICED INTO AN ARGV LITERAL, E0277, 17 sites. `Command::arg(list)` handed one argument a run of words. emit_shell_call now asks the operation's own input declaration -- the same authority optional_params beside it reads -- and emits `.args(..)` for a List-typed element. argv[0] is deliberately untouched: a word list there is already refused loudly on the same bound, and an emitted refusal in its place is a red this route cannot adjudicate, since an emitted panic compiles. (3) THE CONCAT FORM OF append SPELLED AS THE SNOC BRIDGE, E0308, 9 sites. The defect report named the `items:` keyword as the discriminator; measured against the interpreter it is not. `append(xs, items: ys)` and `append(xs, ys)` BOTH answer concat and `append(xs, items: x)` answers snoc -- method_call.concat asks value_to_list_carrier of the argument and never reads the keyword. The discriminator is the APPENDED ARGUMENT'S TYPE, so keying on the keyword would have left the positional concat form still emitting snoc. All nine sites emit through emit_rust_generic_method_call, not the plain-call seam, because nothing in the corpus imports append and infer rewrites the bare form into a method call; the plain-call seam therefore gets no reader, because its red is not authorable anywhere a check could run it (section 4b). EVIDENCE. Three fixtures under fixtures/fixture_closure_rustc/, each measured RED against the pre-repair seed -- E0425 x4, E0277 x4, E0308 x5 -- and green after, consumed by fixture_closure_rustc_verdict through three discrimination pairs whose red arm is the route's own FIXTURE_RED_PATH. A pair per arm so a regression is attributed to one emitter decision. Positive control: both real modules emitted and cargo-built, 28 errors before and 0 after. The argv fixture carries a note about a SEPARATE gap found while authoring it: a single-output shell operation with no exit block emits an unwrapped value where its own declared Result is expected. It is recorded, not repaired here -- a fixture carrying two defects adjudicates neither. gunbc.recurring_failure_mode.accepted_source_emits_uncompilable_target gains one occurrence carrying all three, the keyword-discriminator correction, and an honest rung: still mitigatable. The three pairs are #[ignore]d --lib tests and repo_self_test_command is off the merge path, so nothing blocks a regression and reporting rung 2 would be inflation. The trigger names the capability: a required phase that emits a closure and compiles it over a population that includes fixture-authored sources. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012xQnkeiJ1pnEpMgqh3dE1e * File the shell projection arity class, and walk the mirror generation chain to its fixed point TWO THINGS, and the second is the repair of my own error on the first push. FIRST, THE ROW eager-raven-113 ASKED FOR. The separate finding the previous commit recorded only as a note in the argv fixture is a newly discovered error class, so under DESIGN 4b it gets its own row: gunbc.recurring_failure_mode.shell_projection_return_convention_selected_by_arity. THE MECHANISM WAS ISOLATED BEFORE IT WAS NAMED, because the fixture that exposed it changed two things at once. Measured, each ruling out a plausible co-cause: one field with NO exit block emits `output.status.success()` and is refused E0308; one field WITH an exit block emits `0 => { output.status.success() }` and is refused at the same grain, so the exit block is not load-bearing -- the exit arm reaches the same projection; a lone `stdout` is refused exactly as a lone `exit_success`, so the channel is not load-bearing; and TWO fields already emit `Ok((output.status.success(), stdout.clone()))` and compile, so the boundary is at one rather than at some larger shape. The arity is the whole mechanism. SO IT IS A FORK, NOT A MISSING ARM: the Result convention is present and correct at two fields and up, and an arity test chooses between two conventions where one declaration should derive one. The trigger therefore names the capability -- the return convention derived once, at the authority that also renders the signature -- because "wrap the one-field case in Ok" would be satisfied by a second arity branch, leaving the fork one arm wider. THE SPECIMEN IS COMMITTED AS A RUNNABLE KNOWN-HOLE PAIR, which is the lesson its sibling class records having learned twice: widening the argv fixture to the output shape extdeps.rust.cargo_build actually declares had removed the only instance from the tree. shell_single_field_projection_probe.dag (red, 1 x E0308) and shell_multi_field_projection_probe.dag (control, compiles) differ in ONE authored thing, so a green against a red locates the refusal at the arity. Measured both directions. Per 4b(4) the red flips and is KEPT when the class climbs. No repair here -- it was found by a different fixture being wrong, and repairing it inside that subject would make one fixture carry two defects. SECOND, THE CI FAILURE, WHICH WAS MINE. required-witnesses-build failed at `generated-artifact stage0-mirrors FAIL generated surface drift: compiler_tests.rs`. The stage0 mirrors are a GENERATION CHAIN: compiler_tests_rust.dag generates v1_compiler_compiler_tests_rust.rs, and the binary built from THAT generates compiler_tests.rs. Installing the first generation and stopping leaves the second un-derived, so the drift appears only on the pass after the one I acted on. Local regen said `first_generation_equal=false` twice and I read the named file list instead of the flag -- a regen is a fixed-point iteration, and I stopped at one pass. WALKED TO THE FIXED POINT THIS TIME, one install and rebuild per generation: pass 3 drifted v1_compiler_compiler_tests_rust.rs, pass 4 drifted compiler_tests.rs (the file CI named), pass 5 reports `first_generation_equal=true` with no FAIL line. All four generated discrimination tests are present in compiler_tests.rs, and the three generated mirrors are byte-identical to the candidate after cargo fmt, which touched only the hand-authored host file. cargo fmt --all --check clean; cargo clippy --all-targets -- -D warnings clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012xQnkeiJ1pnEpMgqh3dE1e * Name the argv seam coupling and its trigger Review 64440 on gunbc#11154 verified that the one-word argv arm's emit_rust_dag_string_to_host_via_seam is the identity today and concluded the word-list arm skipping it introduces no divergence. That is correct, and the more useful half is what it implies: the two arms are now coupled through a function only one of them calls. They agree only while that seam is identity. If it becomes a real dag-String-to-host-String conversion, every word spliced through the list arm skips the conversion every word through the one-word arm receives -- silently, because both arms still compile and the splice still yields the right NUMBER of words. The coupling is invisible at the site that would break it: a lane changing the seam has no reason to read the splice, and the splice never named the seam. It does now, with the trigger stated beside it. I said on the PR I would fold this in if another push became necessary rather than spend a CI cycle on prose alone. It did, so this rides along. MEASURED RATHER THAN ASSUMED, because DESIGN 4c's disjointness of annotation capture from semantic emission is itself a claim and gunbc.recurring_failure_mode.content_digest_makes_annotations_semantically_load_bearing is a rostered class: required-regen over this annotation-only edit reports first_generation_equal=true, so the emitted bytes are byte-identical with the new block in place and no mirror needed reinstalling. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012xQnkeiJ1pnEpMgqh3dE1e * Collapse the two word-list predicates onto one authority (review 64464) review 64464 found this diff committing the defect its own headline arm exists to repair: `is_list_typed_expr` and `shell_argv_param_is_word_list` were two spellings of one question -- is this type an ordered run of elements -- authored in the same change as `rust_empty_map_init_expr`, which exists because two sites asking one question is the second representation DESIGN section 2 forbids. The finding is correct and is fixed in code rather than argued with. THE DIVERGENCE WAS A LATENT MISCLASSIFICATION, NOT A STYLE MATTER, which is why consolidating repairs rather than tidies. The two conjunctions had ALREADY diverged: `is_list_typed_expr` excluded a string carrier and the argv-parameter reader did not. In this substrate `String` IS `FreeMonoid<Char>`, so a string carrier spelled structurally satisfies node_is_element_collection -- and the argv reader would then classify a shell input declared that way as a run of words and splice it, when a string is ONE argv word. THE EXCLUSION IS RIGHT FOR BOTH CONSUMERS, SO IT IS NOW DECIDED ONCE. For `append`, a string second argument must be snoc and not concat, which is the interpreter's own rule -- its concat arm tests Value::Str before asking value_to_list_carrier. For an argv element, a string must be one word and never a splice. Two consumers, one reason: a string is an atom to both even though its carrier is a sequence. `type_node_is_ordered_element_run` carries the whole conjunction and both readers project onto it. NO EMISSION CHANGED, AND THAT IS MEASURED RATHER THAN ASSERTED, because it is the evidence for WHY the divergence was latent rather than live: the ordinary spelling `word: String` is a zero-child leaf excluded by ARITY alone, not by the string test. Emitted extdeps_cargo_build.rs and extdeps_exec_command.rs are BYTE-IDENTICAL before and after the consolidation. Had they differed, the explanation above would have been wrong. The argv fixture still emits its four `.args(..)` splices and its one `.arg(word)`, and its crate still builds. Regen at fixed point (first_generation_equal=true). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012xQnkeiJ1pnEpMgqh3dE1e * Thirty-sixth dissolution: delete gunbc#11137's consumed admission row OPERATOR RULING A (eager-raven-113). required-witnesses-floor refused this branch twice -- a0486fd and f991009 -- on `namespace-wave-admission 1 stale admission(s)`, with the floor itself clean both times (verdict=FloorClean, unexpected_failures=0) and this branch's own delta adjudicated clean (ExplicitlyEvaluatedZeroDelta on the new recurring_failure_mode row). The single blocker was gunbc#11137's row, whose own recorded trigger was "this row goes when #11137 merges". #11137 merged as 34d2a8d, so the trigger fired; a consumed row's deletion comes due on this roster's OWN next touch, and this change is that touch. The roster returns to its resting state, empty, and nothing else in the file changes. MERGING MAIN DOES NOT CLEAR IT, WHICH I ASSERTED EARLIER AND WAS WRONG ABOUT. gunbc.rung_drop namespace_admission_consumed_row_deletion says so in terms: the row is RESIDENT on main "from that merge until a human deletes it", an interval that "can never match a delta and is therefore pure liability". Human deletion is the declared remedy and no push to this branch's own files could substitute. THE EVIDENCE IS GIT IDENTITY, NOT A `CONSUMED ADMISSION` RECEIPT, and the difference is recorded in the dissolution rather than glossed. Every dissolution above this one cites the wall printing `CONSUMED ADMISSION ... already satisfied at the base`. This one cannot: on this branch the wall printed `STALE ADMISSION ... matches no delta in this run` and failed the phase. So the fired trigger is established by ancestry -- 34d2a8d is an ancestor of this run's base -- which is exactly what the trigger sentence names. THAT DISCREPANCY IS NOTED AS UNVERIFIED AND DELIBERATELY NOT CHASED HERE, per the ruling. gunbc#9824 split ConsumedByMerge from UnmatchedAdmission precisely so a row whose relocation the base already satisfies stops refusing unrelated pull requests, and this row took the second arm where the first looks applicable. Whether admission_consumed_at_base fails to recognise a TargetChanged binding whose module and target are the same module, or whether the arm is right and my reading is wrong, is UNVERIFIED: I read no code in that path, and nothing here may be cited as a finding about it. It belongs to that mechanism's owner, because if the hole is real then deleting one row treats a symptom while the mechanism keeps producing them. ONE MEASURED FACT WORTH CARRYING, recorded in the dissolution: main's own run of this phase prints `NO SUBJECT -- the merge base against origin/main IS <tip>, so this run has no diff to adjudicate`. main is therefore green on this phase VACUOUSLY, and a resident row bills pull requests from a position where no push run can observe it. cargo fmt --all --check clean; cargo clippy --all-targets -- -D warnings clean with the roster empty. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012xQnkeiJ1pnEpMgqh3dE1e --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
P0b of the route-operability program (parent: eager-raven-113), scoped to the ROUTE PRODUCER
claim_executor --v2-native-route(gunbc.witness_v2_native_route,v1_compiler.cli_run.native_lane_runner). No workflow edits; the CI job was deleted by #11003 and this lands after D4 per the side-chat ruling (the receipt's validity binds the producer's provenance, so the producer must not change mid-train).What changes
-D warningsis set by the producer at the emitted-crate cargo invocation.emitted_closure_compile_host::run_cargonow SETSRUSTFLAGSon the spawn (never inherits it). The value is one row,gunbc.repo_self_build repo_self_warning_denial(["-D","warnings"]), which the all-targets clippy command already consumed and which now also renders asrepo_self_warning_denial_rustflags(); the env-var name is cargo's own,extdeps.rust.cargo RustflagsEnv(new arm, spelling witnessed). Before this the flag came from the setup-rust-toolchain action's DEFAULT input, so the same crate compiled clean on a workstation and refused 101 in CI. The build lane's emit-compile phase sharesrun_cargo, so it now runs under the same explicit flag it already ran under in CI (behaviour-preserving there; local runs now match CI).NativeRouteReceiptgainsemitted_build: NativeRouteEmittedBuild { cargo_argv, rustflags, rustc_identity, exit_status, warning_count }and three admission clauses with named refusal causes:emitted_build_rustc_unrecorded,emitted_build_warnings_not_denied(equality against the denial row — an inherited empty value and a widened-D warnings -C …both refuse),emitted_build_not_clean(status 0 and zerowarningheaders).required-ci: v2-native telemetry …line (process peak RSS viagetrusage, current RSS, slot cgroup current/peak — labelled slot-lifetime — and wall) and are on no receipt field.Not in this PR (C7 correction, 2026-09-11): resource preflight — the predicted critical path and the memory envelope/reserve — is
std.realizationcost vocabulary and lands with route integration; what it will read is the slot authoritygunbc.runner_slot_allocation(gunbc_runner_slot_desired().memory_highas the envelope,memory_max − memory_highas the reserve, by construction). No memory admission arm lives on this receipt.Not in this PR (ruling D, 2026-09-11): per-identity provenance / hit-miss counts land with the provider-spine lane, where their consumer exists (§3c).
Held from merge
Per the side-chat ruling (producer-provenance rule): this lands AFTER D4. Reviews welcome now.
Baseline receipt (run 34521851736 on 1eb184f, srv1-17 aarch64, before this change)
812d6addfae6f2f25295d63bbf29b2f70e9b1cfdd6aafaa11074658ecea8ec91(172 files); emitted binary sha25646175db15d7d209617bfc6f5f520955d83e0ed81fbc6beb64e45e9cd3c5beb81RUSTFLAGS=-D warnings(toolchain-action default), 0warninglines in the job logrss_kb_before=14124724trim→9272220; slot cgroupmemory.max=17179869184memory.high=16106127360Evidence
RUSTFLAGSis SET and the receipt argv equals the spawned argv;warningheader counting.cargo clippy -D warningsclean.dag/test/claim/devboot_host_tool_spelling_witness_test.dag:RUSTFLAGSspelling (PASS on BuildBuddy).src/v1/stage0/src/extdeps_cargo.rsis the producer-regenerated mirror ofextdeps.rust.cargo(regen run on BuildBuddy; candidate sha2569f3e9f42…equals the committed file).src/v2/test/v2_native_route_test.dag: 3 new witnesses (one RED per new clause, positive controls). Their closure cannot be resolved on BuildBuddy (MemoryStallRefusedPageThrash), so their executing evidence is the CI floor: ate6ac6ac9916all 16 changedv2.test.v2_native_routewitnesses wereplanned-and-passed; that run's floor wasFloorRefusedonly on 14v2.test.parse.*/body_loweringcpu-deadline interruptions that main's own latest floor (run 34560949186) shares by identity.Landing-review repair (head
d71e98bb5c7): the spawn owns every channel cargo readsFinding: the receipt recorded
RUSTFLAGS=-D warningsand a compiler probed viaRUSTC/PATH, while cargo readsCARGO_ENCODED_RUSTFLAGSfirst and may selectbuild.rustcor front the compiler withRUSTC_WRAPPER/RUSTC_WORKSPACE_WRAPPER— so the receipt could disagree with the build. Repair (probe_cargo_command/probe_cargo_command_bound): one compiler executable is resolved (RUSTCif set, else the firstrustcon PATH; a non-file is a typedProbeCompilerUnresolvedrefusal), its--version --verboseidentity is taken from the crate's own directory (a rustup proxy selects per cwd), cargo is bound to it viaRUSTC(which wins overbuild.rustc), both wrapper channels are set present-and-empty (cargo's env read short-circuits the config wrappers), and the denial is set onCARGO_ENCODED_RUSTFLAGS(-D\x1fwarnings) andRUSTFLAGSalike. The receipt now carriescompiler_pathwith clauseemitted_build_compiler_unbound(RED witness + positive control). RED controls in Rust plant conflicting ambientCARGO_ENCODED_RUSTFLAGS,RUSTFLAGS,RUSTC,CARGO_BUILD_RUSTC,RUSTC_WRAPPER,CARGO_BUILD_RUSTC_WRAPPER,RUSTC_WORKSPACE_WRAPPERand prove the spawn's own env table overrides each (planted_ambient_flags_compiler_and_wrappers_cannot_reach_the_probe_build). Local cost, stated: the emitted-crate build runs without a wrapper (no sccache) — the price of the verdict being about the crate. BuildBuddy at this head: clippy-D warningsrc=0, 20/20 + 2/2 unit tests, 5471 parse-clean, regenfirst_generation_equal=true, spelling witness PASS. This touches stage0, so the srv2 closure receipt is re-taken at this head by the coordinator.Seed-growth receipt (review 63809)
Hand-written v1 seed grows in two existing seed-retained modules, both maintained under
gunbc.v1_maintenance_standingv1_seed_standing's PURPOSE test (the v2 self-host route producer):src/v1/stage0/src/emitted_closure_compile_host.rs2509 → 2652 lines (its row:gunbc.emitted_closure_compile_seed_growthemitted_closure_compile_seed_growth_justification),src/v1/stage0/src/cli_run/native_lane_runner.rs1140 → 1271 (rostered as consumernative_lane_runner_refingunbc.v1_consumer_census; producer ofgunbc.witness_v2_native_route's receipt, dissolving with that route's v2 emission). No scaffold path was added; the one deliberate seed mirror (WARNING_DENIAL_RUSTFLAGS) is guarded byemitted_build_warnings_not_denied.Pre-push evidence for the remerge head
34bd1b77117(=d73288125de+ main199aee77ab0, one conflict hunk: theextdeps_cargouseline, resolved to importcargo_environment_variable_name, CargoDependency, CargoEnvironmentVariable)BuildBuddy, tree materialised as base
199aee77ab0+ this PR's diff (content-identical to the merge): build rc=0;cargo clippy -D warningsrc=0; unit tests 19/19 (emitted_closure_compile_host) + 2/2 (native_lane_runner);v1_src_dag_parse5471 files parse-clean;claim_executor --required-regenfirst_generation_equal=trueplanned=155 executed=155 adjudicated=155 (declared_divergent=1 [main.rs], the standing divergence);cargo_environment_variable_names_are_the_cited_upstream_spellingsPASS. The srv2--v2-native-routeclosure receipt at this head is run by the coordinator against the main baseline at199aee77and posted on this PR.Obligations bound to the EVENTUAL post-D4 head
This PR is held until after D4 and will remerge main then; the obligations below bind whatever head results, not any sha named above, and are executed once there:
v2.test.v2_native_routewitnessplanned-and-passed, and the build lane's generated-artifact phase is green;claim_executor --v2-native-route --source-root dag --source-root src/v2at that head, whose log showsrequired-ci: v2-native emitted crate built — … RUSTFLAGS="-D warnings" …with rustc's identity andwarning_count=0, therequired-ci: v2-native telemetry …line, and a terminalrequired-ci: v2-native admission admittedline.Baseline receipt (run 34521851736 on 1eb184f, srv1-17 aarch64, before this change)
812d6addfae6f2f25295d63bbf29b2f70e9b1cfdd6aafaa11074658ecea8ec91(172 files); emitted binary sha25646175db15d7d209617bfc6f5f520955d83e0ed81fbc6beb64e45e9cd3c5beb81RUSTFLAGS=-D warnings(toolchain-action default), 0warninglines in the job logrss_kb_before=14124724trim→9272220🤖 Generated with Claude Code
https://claude.ai/code/session_01TeSjTvn6wik6dGnnGgK5vx