Repository navigation
Scope the jointly-incompatible-open-PR mitigation, and land checkpoint 1: joint_claim_join, the instrument behind its figures - #11044
Conversation
…surface join over the declaration index, advisory-first Three 2026-09-10 reds on main were pairs of individually-green, textually disjoint PRs whose union does not compile. This records the scope of a mitigation and builds nothing, answering the four questions the brief asked before any shape: THE CUT. All three public instances are one finding kind, ImportMemberAbsent, and only one was a deletion: #10865 was a rename, and #10923 dropped a RE-EXPORT with no declaration deleted anywhere. The cut is therefore the surface predicate the declarations rider already applies, import_surface_has (declared | variants | reexported) as a base-minus-head DELTA, not the kind of edit. The general case is every claim channel the index carries -- imports, citations, rostered rows (#10769, #10718 are the same shape through the other two) -- and the residuals the index cannot see are named: field rename, arity/signature, and pure freshness (private #49 x #50). THE COST. namespace_wave_admission already reconstructs a base index beside the head index from only the diff-touched files, per run, in the witnesses lane; the join is A(I) & R(D) minus the claims D itself retires, a set intersection, not a pairwise compile. Measured retrospectively over 374 first-parent commits since 2026-08-28: the raw join is a 207-hit candidate list (the superset trap); with the one exclusion it is 5 hits, 4 of them the three brief instances, the fifth an ordering artefact an open-PR-set join excludes by construction. Recall 3/3 on the window's ImportMemberAbsent reds. THE PLACEMENT. No new job (roster closed): a rider on the parse phase, like rostered_row_join, advisory, reporting and annotating without pushing a phase failure; the one emitted-workflow change is a pull-requests: read permission row. The freshness caveat of a push-time verdict is stated as the reason this sits beneath the ceiling. THE REFUSAL. One finding per removed entry x claiming site: the (module, name) and which surface it left, the sibling PR and head, the claiming module, in_declaration and SourceLocation; NotEvaluated when the open-PR set is unobservable, never an empty hit set. gunbc-private: no parse phase, the overlay is outside DAG_PARSE_SWEEP_ROOTS, so the join is public-only today; 113/114 private modules import from public, a cross-repo exposure no public PR is ever compiled against, named and left to warm-badger-62's lane. Ceiling stays with gunbc.plans.ci_merge_freshness and the landed, deferred receipt_is_admissible; this record retires with it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QzQcQRu3WKxJuWV2zaiHSW
Ledger-Repair-Judged: docs/design-rung-drops.md
…ures; the private gap as a typed stall; the within-tree half re-homed Answers review 63772 / 63786 (a transcribed measurement with no producer) and the manager's 2026-09-11 rulings, by landing the producer rather than softening the claim. THE INSTRUMENT. v1_compiler.bin.joint_claim_join computes, per change, the export-surface entries removed (declared | variants | reexported, base minus head) and the import claims added and retired, from only the diff-touched files on both sides through namespace_wave_admission base_records and diff_sides, and joins every admitted pair. A claim is joined only while LIVE when the entry leaves: not retired by the removing change itself, and in retrospective mode not retired by any change that landed between the pair. raw_candidates is reported beside findings so the width the exclusion removes stays a number. Seven fixture-boundary controls, real parser, real join: one positive control per instance shape (variant deleted, name renamed, re-export dropped), one RED per exclusion, one for the pair predicate, one for a claim already at the base. WHAT IT ANSWERS, cited by invocation in the plan and not transcribed: `joint_claim_join 6a54695^..f078c59` (first-parent main since 2026-08-28, default 3-day window) reports subjects=373 raw_candidates=236 findings=4 -- exactly the three 2026-09-10 instances (instance 1 is two names). The two candidates the first-exclusion-only run reported as findings were both a third commit retiring the claim between the pair (#10617 for the harness one; the DensityMarketedMax one likewise); two artefacts with one cause was a defect in the retrospective's pair predicate, built in as the second exclusion with its own control rather than described. TWO CORRECTIONS THE INSTRUMENT MADE TO THE SCOPE. Instance 2 (#10923 x #10925) was a MOVE, not a dropped re-export: the base declared mutation_status_is_commit_ambiguous in secret_provision_actuator and #10923 re-homed it; the instrument reports `(declared)` and the plan's table now says so. The dropped re-export stays covered by the surface and keeps its control. THE RULINGS. Checkpoint 2 stops at the pull-requests:read permission row on a required job (the operator's trade); the dashboard reader is costed in section 4.1 and preferred on every axis but authority. The private gap is a typed GuaranteeStall row (joint_claim_join_private_corpus_unindexed_stall) with the overlay's extra-source-root trigger as its grounding, not prose. The within-tree field-set case is NOT a checkpoint here: its home is witness_that_fails_to_compile_is_absent_rather_than_red, and this change appends a receipt there widening the trigger from claim-root files to the ruled capability -- every construction site of a type whose field set changed, regardless of gate closure -- per section 4b(3), rather than minting a second authority. Hand Rust is enumerated in gunbc.joint_claim_join_seed_growth (33 items, no impl block, every one citable) and rostered in seed_growth_admission. Verified remotely: clippy -D warnings clean on the bin, 7/7 tests, the retrospective above, and v1_src_dag_parse over the corpus with every new .dag present: 5461 files parse-clean, no findings. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QzQcQRu3WKxJuWV2zaiHSW
…sion/lively-bat-864
|
Re review 63772 and review 63786 (the §3.1 figures were transcribed with no producer): addressed in 1ea557f by landing the producer rather than dropping the counts. |
|
CI red on 6eaf349 is infra, not the change: |
…the claim-root population, not evaluation of it A file that compiles and whose test fns are declared but never reached from the entry passes that wall untouched (cool-badger-34's four fns, 2026-09-11). That hole is discriminating_arm_built_but_never_enrolled's, named as the neighbour so the word POPULATION is not later cited for a scope the trigger never claimed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QzQcQRu3WKxJuWV2zaiHSW
Scope record
gunbc.plans.joint_incompatibility_claim_join(registered inplan_registry_batch_g, authority-only like its siblings) plus checkpoint 1, the instrument, per the manager's 2026-09-11 ruling. Nothing gates on anything here.Q1 — the cut. All three 2026-09-10 public instances are one finding kind,
ImportMemberAbsent, and only one was a deletion: #10865 was a rename; #10923 was a move (its base declaredmutation_status_is_commit_ambiguousinsecret_provision_actuatorand re-homed it — the instrument's(declared)corrected my first draft, which called it a dropped re-export). So the cut isimport_surface_has(declared ∪ variants ∪ reexported) as a base-minus-head delta, not the kind of edit. The general case is every claim channel the index carries (imports, citations, rostered rows). Residuals the index cannot see are named (arity, pure freshness). The within-tree field-set case is not subsumed and is not a checkpoint here: its home iswitness_that_fails_to_compile_is_absent_rather_than_red, and this PR appends a receipt there widening the trigger from claim-root files to the ruled capability (every construction site of a type whose field set changed, regardless of gate closure), per §4b(3), instead of minting a second authority.Q2 — the cost, now instrumented.
v1_compiler.bin.joint_claim_joincomputes per-change deltas from only diff-touched files vianamespace_wave_admissionbase_records/diff_sides(the wave wall's own reconstruction) and joins pairs; a claim is joined only while live when the entry leaves (not retired by the remover, nor — in retrospective mode — by any change landing between the pair).raw_candidatesis reported besidefindings.joint_claim_join 6a54695f6c7^..f078c59b0b4(first-parentmainsince 2026-08-28, 3-day window): subjects=373 raw_candidates=236 findings=4 — exactly the three instances. The two candidates the single-exclusion run reported as findings were both a third commit retiring the claim between the pair; that was built in as the second exclusion with its own control. Seven fixture-boundary tests: one positive control per instance shape, one RED per exclusion, one for the pair predicate, one for a claim already at the base.Q3 — placement. No new job. The CI rider stops at a
pull-requests: readrow on a required job — the operator's trade, not a lane's (manager ruling). §4.1 costs the dashboard-side reader against it: it wins on compute, freshness and surface and never touches the merge path; checkpoint 2 is that reader, dispatched from outside this repo.Q4 — refusal. One finding per removed
(module, name)× claiming site: which surface it left, remover, claimer, claiming module,rel_path:offset;NotEvaluatedwhen a subject's delta is unobservable, never an empty hit set.gunbc-private: no parse phase, overlay outside
DAG_PARSE_SWEEP_ROOTS→ the join is public-only, and that is a typedGuaranteeStallrow (joint_claim_join_private_corpus_unindexed_stall) grounded on the overlay's own extra-source-root trigger, not prose. 113/114 private modules import public.Boundary of the widened trigger. The population compile establishes compilability of the claim-root population, not evaluation of it: a file that compiles but whose
test fns are absent from the entry's conjunction passes that wall untouched (cool-badger-34's four never-evaluated fns, 2026-09-11). That hole belongs todiscriminating_arm_built_but_never_enrolled, named on the row as the neighbour; this trigger does not close it.What the instrument is NOT about. Its subject is claim support silently lost — A removes what B's claim depends on, both green alone, nothing red until a third party inherits it. A text conflict (two PRs appending to one data row — this PR and #11050 both append to
witness_that_fails_to_compile_is_absent_rather_than_red) is the opposite case: git raises it loudly at merge time, no surface entry leaves, no claim loses support. A conflict on a shared row is not a miss of this join; it was never in its scope.Hand Rust enumerated in
gunbc.joint_claim_join_seed_growth(noimplblock; every item citable). Verified remotely: clippy-D warningsclean, 7/7 tests, the retrospective above,v1_src_dag_parseover the corpus: 5461 files parse-clean, no findings.🤖 Generated with Claude Code
https://claude.ai/code/session_01QzQcQRu3WKxJuWV2zaiHSW