Repository navigation
§3b observability conformance row; the floor heartbeat renders through the observation model again - #11017
Conversation
…hard laws Adds the conformance-decision domain to gunbc.design_argument conformance_domains, homed on std.decision (DecisionSubject, RealizationSelectionResult, SelectionReceipt, select_realization) and std.pareto (SelectionAxis, ParetoEntry, DominanceVerdict). The row is narrow: inhabitance of the decision/Pareto models, or a stated departure. Consumer route for the home: gunbc.spark.serving_deployment_selection select_serving_deployment and product.fleet_operating_point fleet_operating_point_selection call select_realization; exercised by test.claim.spark.serving_deployment_selection_witness_test and test.claim.realization_selection_witness_test. The s3d.selection-precedes-convergence reviewer keeps only the hard laws (no answer outrunning field/constraints/evidence/policy; a front is not a winner; missing funded evidence is never a fabricated zero or settled fact; goal assessment/ensure never choose) and says a stated home departure excuses none of them. Home-inhabitance tells moved to the conformance row. Witness: a_stated_departure_from_the_decision_home_is_admitted_while_the_selection_law_still_fails folds one plan through the existing review machinery -- conformance-decision answers DivergesStated (approved with reason), selection-precedes-convergence requests changes on the same file, the report fails; the converse plan with the laws honoured approves. gunbc.design_document: "missing authority" -> "selection authority" in §3d; §3b no longer claims the overlap counter proves the partition (review_criterion_identities_are_unique proves unique keys only and disclaims semantic exclusivity); scope/ownership mismatch distinguished from a non-resolving citation; §3d records the admitted row and that the effectful convergence cycle (plan, admission, actuation, readback) still has no consumed home. DESIGN.md regenerated via generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
…h the observation model again Lane B of the process-observability brief. Row: conformance-observability on gunbc.design_argument conformance_domains, homed on std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting; repository populations stay with gunbc.repository_census_observation, delivery with effects. Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall, seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults, rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its own rate/share functions. seed_heartbeat_line is the oracle over that input space; cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no interpreter on that thread); floor_resource_sample and the stall window become typed producers (FloorResourceSample, floor_stall_window_observation) with None for unread sources -- nothing formats a number outside the mirror. Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat, the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing; cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror byte-equal to the interpreter on the same two specimens (off the merge path: rung drop rust_unit_tests_off_the_merge_path). Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep. seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory] lived only in required_floor_runner.rs, so the census could not find its own row and the declined hygiene suite reported nothing. New executing witness observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep) are repaired to the restored subject and their standing restated -- the lockstep no-fabrication row had gone false a second time on the same cli_run split. DESIGN.md regenerated via generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
|
Execution receipts for the Rust half (head
— sent from stern-heron-185 |
Review 63436: cpu_ms/cgroup_charge_bytes/stall_window_ms/stall_user_cpu_ms (and elapsed_ms, rss_bytes) were bare Nat with a unit suffix. They are now Millisecond / ByteSize, on the precedent of ci_batch_summary_text's `work: Nanosecond`; the seed test builds each carrier through the interpreter's millisecond / byte_size constructor, so a caller handing the wrong unit cannot typecheck. Dimensionless counts stay Nat. Oracle test green locally (3/3); floor witness 5/5. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
|
review 63436 (blocking, flat-scalar unit params on Noting for the record rather than as a counter: every pre-existing fn in — sent from stern-heron-185 |
…md regenerated via generated_artifact_gate main_wet) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
Lane B of the process-observability / decision-conformance brief (reviewed against main at b0a6d53). Stacked on #11010 (Lane A); the diff to read is this branch against
session/stern-heron-185.Row
conformance-observability("process observability / reporting") ongunbc.design_argumentconformance_domains. Homes (typeddecl_refliterals, resolved by the ingestion declaration index on this PR's required run):std.observation::ObservationEvent,::RecordedObservation,::ObservationPresentation;gunbc.observation_ci_render::ci_event_line,::ci_render_line. Scoped to process reporting — a repository population measured at a revision stays withgunbc.repository_census_observation, durable delivery with the effect authorities; the narrative keeps the four responsibilities (owning domain / observation model / renderer or codec / bound effect) explicit and says producing bytes is not delivery.First concrete repair: the heartbeat
gunbc.observation_emit_censusfloor_heartbeat_siterecorded that #9228 deleted the[floor-memory]projection and a raw[floor-heartbeat]key=value eprintln took its job. Restored:gunbc.observation_ci_renderHeartbeatSampleis replaced (§3 replacement migration, not extended) with the one-attempt floor's real sample: wall since floor start, the seam as aRunSegment+PhaseSegmentsubject, and every reading the raw line had grown under a measured justification as aMeasuredarm — cpu delta, major faults, rss, cgroup charge, high/max/local-high events, host swap-in and major faults — plus the stall window carried asgunbc.memory_stall_refusal's ownMemoryStallObservation, so the printed rate and share come from the two functions the refusal itself consumes. Unreadability is kept at the grain the seed reads (one/proc/self/statread feeds cpu and faults together; three cgroup files; one vmstat; both stall counters or none) and every arm names its cause; nothing prints 0.gunbc.observation_seed_renderseed_heartbeat_lineis the oracle over the seed's primitive input space. The liveness thread calls the Rust mirrorcli_run::render_heartbeat_line_mirror(no interpreter on that thread, per the brief);floor_resource_samplebecomes a typedFloorResourceSamplewithNonefor unread sources andfloor_stall_window_observationreturns the governor'sMemoryStallObservationorNone(half-read or zero-wall window). The rawwall_s= phase= cpu_ms=shape is gone from the seed;FLOOR_HEARTBEAT_CENSUS_MARKERkeeps the roster's presence check honest.test.claim.observation_seed_heartbeat_witness_test(SubstrateInputsOnly) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat, the treadmill specimen's178795 faults/min at 0.8% user cpu, no fabricated zero on any arm, and a zero-wall stall window refusing. Ran green under claim_batch on this tree (5/5), and it is discovered by the floor on this PR.rust_unit_tests_off_the_merge_path):cli_run::heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracleruns the.dagthrough the interpreter on the same two specimens and asserts byte-equality with the mirror and with the same literal strings, so oracle, mirror and floor witness agree over one input. Executed remotely (receipt in the PR comments).test.claim.observation_ci_render_witness_testandobservation_crawl_replay_test(executing) updated to the replaced sample; the captured crawl replays with its uncaptured vitals honestlyunreadable (not captured by run 30044816605).[floor-claim-memory]stays aCountedFrontierSite: a growth line is a delta between two readings on a named claim and the renderer has no measurement-delta projection; its dissolution now names that projection.Census extension (bounded)
CensusedEmitSitegainsproducer: EmitProducer(aDeclarationRefinto hand Rust — the ingestion wall counts these outside-index rather than resolving them; the declined hygiene suite holds each symbol present in the seed) andconsumption: EmitConsumption=MachineConsumed { reader, fields_read } | HumanPresentationOnly { evidence } | ConsumerUnresolved { searched }. Every row isConsumerUnresolvedwith its in-repo search stated — none is booked human-only on a prefix grep, per the brief. Producer is one declaration per family at function grain; the multi-site enumeration remains the unbuilt occurrence-grain discovery the module already names. Folds:observation_emit_unresolved_consumer_count,observation_emit_located_producer_count; new executing witnessobservation_emit_census_producer_witness_test(pure folds + planted controls).Finding recorded in the census:
seed_emit_sourceshad fallen behind thecli_run/split —[floor-claim-memory]lives only incli_run/required_floor_runner.rs, socensus_marker_presentanswered false for its own row and the declined suite reported nothing; four files added. The lockstep witness's no-fabrication row had likewise gone false a second time on the same split (needles intocli_run.rsfor code now inrequired_floor_runner.rs). Both suites are repaired to the restored subject; their declined standing is restated, not changed — they executed under claim_batch on this tree (7/7, 20/20) and nowhere on the merge path. This PR does not lift the live-tree decline.Not claimed
No corpus-wide migration (frontier count moves 8→7: this family only); no effectful convergence; no external-reader survey — if a reader outside the tree parsed the old key=value line, it now reads prose, which is exactly what the
ConsumerUnresolvedrow says.DESIGN.mdregenerated viagenerated_artifact_gatemain_wet.🤖 Generated with Claude Code
https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH