Skip to content

File the class #10992 repaired: one shared precondition re-derived once per claim frame - #11015

Merged
briansrls merged 1 commit into
mainfrom
session/clever-dove-148
Sep 11, 2026
Merged

briansrls merged 1 commit into
mainfrom
session/clever-dove-148

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

What this is

gunbc#10992 repaired the four v2.test.native_decl_selection witnesses by sharing the fixture at the resolved seam. The repair is landed and this PR does not touch it, the floor budget, or the v2-native lane. It files the failure class that repair revealed, which #10992 did not file — one new row under dag/gunbc/recurring_failure_mode/, and nothing else.

The class

One pure precondition re-derived once per isolated claim frame, so a cost gate adjudicates the duplication and every disposition it offers is aimed at the wrong quantity.

The durable finding is not that four rows were expensive. It is that the gate measured N copies of one shared pure derivation and attributed them to N separate rows. The refusal was true and its subject was wrong, so it misdirected every reader who trusted it: trim the subject, re-home it to a lane that allows the cost, widen the line — all three price the duplication as though it were the claim's work, and the correct move is in none of them, because it is not a cost decision at all. DESIGN §2 already rules on the shape: several demands with a shared-state least common ancestor are authored duplication, to be carried or shared at that ancestor, never cached and never re-homed.

The measurement that locates it

Partitioning one claim into its precondition and its own act (claim_batch, one resolve, probe module deleted after):

rung CPU
bare native_test_context_from_ingest, one minimal 4-line source ~725ms
ingest of both sources 867ms
ingest + native_test_prepare_module 1106ms
same, fixture trimmed 874ms
ingest + prepare + native_test_eval_one 1130ms

The claim's own act is ~24ms against a ~725ms precondition — three percent. A row whose own work is three percent of its measured cost is not an expensive claim; it is a cheap claim behind a shared precondition, and that ratio is the recognition rule.

The second half, which is why it generalises

A per-claim line is derived from the corpus that was paying it. 3,592 planned identities pass the 500ms line precisely because none of them pays per-claim ingest, so the corpus the figure was calibrated against could not have exposed the gap. A newly arrived claim family paying a cost kind no incumbent pays is adjudicated by a constant that never saw it. #10992 fixed these four; it did not make the next such family safe.

Bounded against three neighbours

Each is close enough that merging them would lose the repair:

  • right_censored_cost_read_as_exact — a defect in the carrier (reading cpu_at_least as a cost). Fixable while the duplication stands; correcting it would have left all four rows refusing.
  • ceiling_never_exercised_for_a_population_the_census_cannot_plan — those identities are never planned, so their bound is unevaluated. These were planned, executed and interrupted: the bound was exercised.
  • the near-line misplaced-threshold family — those sit within ±10% of the line. These sat 2.2×–2.7× out, so no defensible placement admits them. That is the positive argument the cost was structural rather than marginal, and it is what rules out tuning.

Rung

Found at mitigatable — the gate refuses, typed and located, and shipped no wrong verdict; what it does not do is name the duplication, so the class is diagnosed by hand.

Attainable ceiling mechanically preventable, and deliberately not higher: whether one pure derivation is reached from several claim frames is decidable from the resolved graph, so a check can refuse and report the multiplicity rather than the total — but the shape stays perfectly authorable and is correct whenever the value is cheap, so it is refusable, not unconstructible.

Next-rung trigger is a capability, not an artifact: the floor reports, per refusing file, the shared pure preconditions its claims re-derive and the multiplicity.

Evidence by execution

  • Consumer: the row renders through gunbc.design_ledgers expected_design_failure_modes_md — identity and receipt text present in the evaluated projection (§3c: it has a consumer and a route, not just a well-shaped declaration).
  • Discriminating control: breaking the consumed receipts field reds the fold (module index refused: 1 unparseable .dag source) and the row's text leaves the projection. Restored byte-identical; positive control re-run green.
  • A weaker check was rejected as vacuous: a resolve-only run stayed green under a deliberately mistyped evidence: 42, because data declarations are not typechecked at resolve. That is why the evidence above evaluates the fold rather than resolving the closure.
  • The derived roster (roster.dag, generated and gitignored) picked the row up at lines 189/407.
  • required-regen reports first_generation_equal=true, planned=155 executed=155 adjudicated=155, no committed artifact drift.

Scope

One file, 32 lines added. No change to native_decl_selection, the floor's budget machinery, or the v2-native lane.

🤖 Generated with Claude Code

https://claude.ai/code/session_01V8Xv998kJjfXLcG34vwGuq

…ce per claim frame

#10882 landed four native_decl_selection witnesses into the required floor;
each called collision_prepared, so the seed tokenized and parsed the same ~230
characters of synthetic source once per claim. The floor refused on main with
claims_failed=0 and interrupted_cpu_deadline=4 -- nothing failing, the lane red.
#10992 repaired it by sharing the fixture at the resolved seam.

The repair is landed; the class is not filed. This files it.

The durable finding is not that four rows were expensive. It is that a cost gate
measured N copies of one shared pure derivation and attributed them to N rows, so
every disposition the refusal offered -- trim the subject, re-home it to a lane
that allows the cost, widen the line -- priced the duplication as though it were
the claim's work. Partitioned, the claim's own act (native_test_eval_one) is ~24ms
against a ~725ms precondition: three percent. A row whose own work is three
percent of its measured cost is a cheap claim behind a shared precondition, and
that ratio is what locates the class.

The second half is the ceiling: 3,592 planned identities pass the 500ms line
precisely because none of them pays per-claim ingest, so the corpus the figure was
calibrated against could not have exposed the gap. A newly arrived claim family
paying a cost kind no incumbent pays is adjudicated by a constant that never saw it.

Bounded against three neighbours it would otherwise be merged with:
right_censored_cost_read_as_exact (a carrier defect, fixable while the duplication
stands), ceiling_never_exercised_for_a_population_the_census_cannot_plan (those
identities are never planned; these were planned and interrupted), and the
near-line misplaced-threshold family (these sat 2.2x-2.7x out, so no defensible
placement admits them).

Rung found at mitigatable; attainable ceiling mechanically preventable, because
whether one pure derivation is reached from several claim frames is decidable from
the resolved graph -- and deliberately not higher, since the shape stays authorable
and is correct whenever the value is cheap.

Evidence by execution: the row renders through its consumer,
gunbc.design_ledgers expected_design_failure_modes_md, with its identity and
receipt text present in the projection. Discriminating control: breaking the
consumed receipts field reds the fold (module index refused, unparseable source)
and the row's text leaves the projection; restored byte-identical and re-run green.
The derived roster (gitignored) picked the row up at lines 189/407.
required-regen reports first_generation_equal=true with no committed artifact drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V8Xv998kJjfXLcG34vwGuq
@briansrls briansrls closed this Sep 11, 2026
@gunbai-bot gunbai-bot Bot reopened this Sep 11, 2026
@briansrls
briansrls merged commit ec1571e into main Sep 11, 2026
5 of 7 checks passed
@briansrls
briansrls deleted the session/clever-dove-148 branch September 11, 2026 06:43
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
…use rotted

review 64357 (claude/opus[1m], REQUEST_CHANGES) is correct and I verified it
rather than taking it: shared_precondition_re_derived_once_per_claim_frame is
on this tree. It landed via #11015 (ec1571e), was appended by #11037
(ce76f34), and this PR's own merge of main brought it in -- so the file is
present in the worktree and the identity resolves.

The BOUNDARIES receipt was therefore printing a justification that was TRUE WHEN
WRITTEN AND IS NOW FALSE, and a false one in the worst direction: it told a
reader the name does not exist when it does, which inverts
unlanded_citation_indistinguishable_at_the_citing_end rather than applying it.
Restored the direct citation and deleted the withholding clause entirely; the
boundary the receipt draws is unchanged, only the handle.

Every backticked ledger identity in the row now resolves against the directory:
absorbing_fallback and shared_precondition_re_derived_once_per_claim_frame.
(namespace_graft is the specimen's error name, not a ledger identity.)

Re-derived: regen EXIT=0, rendered paragraph 7096 chars with 0 double spaces,
second regen byte-identical to the first (cmp clean), and the receipt
trailing-space count stays 0 under the #11047 join convention.

Worth naming, since this row is about exactly this: the withheld citation was a
correct judgement about a tree that then moved underneath it, and nothing in the
row re-read its own premise. That is the same shape as the class being filed --
a conclusion whose condition was checked once and never again -- which is why a
reviewer reading the current tree caught it and the author who wrote it did not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NuEqKq5Jxcy4Wj3fYEwYFL
gunbai-bot Bot added a commit that referenced this pull request Sep 12, 2026
… adjudicate it (#11020)

* File the class: routing a subject to an adjudicator never observed to adjudicate it

One row under dag/gunbc/recurring_failure_mode/. The invalid state: a subject
whose adjudication is transferred to an authority never OBSERVED to adjudicate
it, with the transfer recorded as a routing rather than as a loss of coverage.
The origin gate goes green on a typed, honest decline; the destination's silence
is indistinguishable from coverage.

Specimen: the near-miss of 2026-09-09/10 on the four native_decl_selection
witnesses, the ruling that they be routed to required-v2-native, and
clever-dove-148's out-of-scope check of the DESTINATION, which found it refusing
at its own emit/resolve stage before adjudicating any witness. The row records
what actually caught it -- an acceptance condition demanding the destination
COMPLETE and NAME all four identities -- as the repair it points at.

Bounded explicitly against shared_precondition_re_derived_once_per_claim_frame
(cost, not destination), absorbing_fallback (widens, does not refuse), the inert
lens (never consulted; here the destination is consulted and loud), and the
escape hatch (proceeds as if no refusal; here the refusal fires and is located).

Rung found at mitigatable; ceiling argued at mechanically preventable -- a
decline arm required to cite a destination receipt naming the routed subject --
and explicitly NOT structural, since a receipt can be stale or name a run that
reached no verdict. Trigger names the capability: a cross-gate adjudication
receipt carrying destination lane, run, and the subject identities that run
actually reached a verdict on.

EVIDENCE, by execution against a release gunbc built from this tree, through
tools.docs_projection_gate regen (gunbc.design_ledgers
expected_design_failure_modes_md):

  - green: regen EXIT=0, writes docs/design-failure-modes.md 1563582 bytes, and
    the row's identity and prose render into it.
  - MUTATION, consumed field: one element of `receipts` replaced by `42`. regen
    EXIT=1, resolve refusal located at
    routing_a_subject_to_an_unverified_adjudicator.dag:10:5 "type mismatch:
    expected 'Primitive(String)', got 'Primitive(Int)'", and NO
    docs/design-failure-modes.md is written -- the fold reds and the text is gone.
  - CONTROL, unconsumed field: `evidence: 42` on the same row. regen EXIT=0 and
    the projection writes normally, reproducing exactly the green that #11015's
    author found and threw the resolve-only check out over. The pair is what
    makes the first result discriminating rather than incidental.
  - regen re-run after restore is byte-identical to the first generation (cmp
    clean), no drift; docs_projection_gate main EXIT=0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NuEqKq5Jxcy4Wj3fYEwYFL

* Describe the sibling class by shape, not by an identity that resolves nowhere

review 63417 (cursor/auto, REQUEST_CHANGES) is correct: the BOUNDARIES receipt
cited `shared_precondition_re_derived_once_per_claim_frame` as a peer ledger
identity, and that row is on neither tree -- empty on origin/main and empty in
git ls-files at this head, so the only mention of the name in the corpus was my
own citation of it. The named sibling is filed but unlanded.

Repaired the way `unlanded_citation_indistinguishable_at_the_citing_end`
prescribes: describe the sibling by SHAPE -- "the class filed by clever-dove-148
over the same specimen, whose subject is a shared precondition re-derived once
per claim frame" -- and say in the same breath why the identity is withheld, so
a later reader is not left to wonder whether the name rotted or never existed.
The boundary the receipt draws is unchanged; only the handle is. Landing the
sibling in this closure was the other admissible repair and is not mine to do:
it belongs to that row's author and to its own PR.

Every remaining backticked ledger identity in the row resolves against the
directory: `absorbing_fallback` and
`unlanded_citation_indistinguishable_at_the_citing_end`.

Re-verified by execution: tools.docs_projection_gate regen EXIT=0, the reworded
receipt renders into docs/design-failure-modes.md, and a second regen is
byte-identical to the first (cmp clean).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NuEqKq5Jxcy4Wj3fYEwYFL

* Migrate the row's receipts to the #11047 separator convention

gunbc#11047 moved the separator into the fold -- `authored` is now
`join(r.receipts, " ")` -- and deleted the per-receipt trailing-space
convention this row was authored under. All eight of my receipts ended in a
space, so after the merge every one of the seven boundaries would have rendered
double-spaced. Stripped the trailing space from all eight; the diff is 8/8 and
each changed line is a receipt terminator, not prose.

The coupling is the RENDERER, not the import graph. This row imports only
RecurringFailureMode and NonEmptyStr, neither touched by #11047, so an
import-graph reading clears it and is wrong -- which is how #11100 was judged
safe.

Re-derived against the merged tree, with a pre-existing row on the same page as
the control:
  - regen EXIT=0; my rendered paragraph 7426 chars, double-space count 0;
    control `absorbing_fallback` paragraph 3602 chars, double-space count 0.
  - all seven receipt boundaries render with exactly one space
    ("...by no one. WHY IT IS WORSE", "...a climb. THE SPECIMEN", and so on).
  - second regen byte-identical to the first (cmp clean).

The mutation evidence is RE-DERIVED under the new fold rather than carried over
from the old one: one `receipts` element replaced by 42 gives regen EXIT=1, a
located resolve refusal at :10:5 "type mismatch: expected 'Primitive(String)',
got 'Primitive(Int)'", and no projection written. Restoring the row reproduces
the projection byte-for-byte.

This merge also brings in #11093 (census heads modelled, non-closure bodies
dropped after parsing), which is the cause of the MemoryStallRefusedPageThrash
that refused the floor on the previous head. A rerun would have replayed the
merge ref pinned before it; only a push re-measures the current memory shape.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NuEqKq5Jxcy4Wj3fYEwYFL

* Cite the sibling class by identity: it landed, so the withholding clause rotted

review 64357 (claude/opus[1m], REQUEST_CHANGES) is correct and I verified it
rather than taking it: shared_precondition_re_derived_once_per_claim_frame is
on this tree. It landed via #11015 (ec1571e), was appended by #11037
(ce76f34), and this PR's own merge of main brought it in -- so the file is
present in the worktree and the identity resolves.

The BOUNDARIES receipt was therefore printing a justification that was TRUE WHEN
WRITTEN AND IS NOW FALSE, and a false one in the worst direction: it told a
reader the name does not exist when it does, which inverts
unlanded_citation_indistinguishable_at_the_citing_end rather than applying it.
Restored the direct citation and deleted the withholding clause entirely; the
boundary the receipt draws is unchanged, only the handle.

Every backticked ledger identity in the row now resolves against the directory:
absorbing_fallback and shared_precondition_re_derived_once_per_claim_frame.
(namespace_graft is the specimen's error name, not a ledger identity.)

Re-derived: regen EXIT=0, rendered paragraph 7096 chars with 0 double spaces,
second regen byte-identical to the first (cmp clean), and the receipt
trailing-space count stays 0 under the #11047 join convention.

Worth naming, since this row is about exactly this: the withheld citation was a
correct judgement about a tree that then moved underneath it, and nothing in the
row re-read its own premise. That is the same shape as the class being filed --
a conclusion whose condition was checked once and never again -- which is why a
reviewer reading the current tree caught it and the author who wrote it did not.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NuEqKq5Jxcy4Wj3fYEwYFL

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant