From 708113d40327aabe5915a9d6f3989b67f6362bfd Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sat, 19 Sep 2026 10:43:57 +0000 Subject: [PATCH 1/2] Live-condition the enrolment Roster ground; retire the stored cost-debt reading. A typed cost-debt admission now carries identity and reason only. The enrolment-margin gate decides the Roster ground from THIS run's live reading against the per-subject CPU line: over the line admits, at or under it is stale and blocks (the row must delete), a planned identity with no cost row is NotMeasured exactly as an undeclared one is, and a lower bound admits only if the bound itself clears the line. Long-home is unchanged (declared drop long_home_enrolment_margin_observed_only). Replacement migration at the root (gunbc#11622 review 68363): the stored reading and the live one answered the same question and could disagree, and the stored one decided nothing once the gate went live. The constructor, reading and verdict axis are removed with it; their behaviours are re-homed onto the live arms in floor_enrolment_margin_test, and a Rust unit test covers the seed realization in required_floor_runner. Co-Authored-By: Claude Opus 5 (1M context) --- ...ng_home_enrolment_margin_observed_only.dag | 7 +- .../src/cli_run/required_floor_runner.rs | 239 ++++++++++++++-- .../test/floor_cost_debt_admission_test.dag | 255 ------------------ src/v2/test/floor_enrolment_margin_test.dag | 90 +++++-- src/v2/workflow/floor_cost_debt.dag | 15 +- src/v2/workflow/floor_cost_debt_admission.dag | 206 ++------------ src/v2/workflow/floor_enrolment_margin.dag | 98 +++++-- 7 files changed, 406 insertions(+), 504 deletions(-) delete mode 100644 src/v2/test/floor_cost_debt_admission_test.dag diff --git a/dag/gunbc/rung_drop/long_home_enrolment_margin_observed_only.dag b/dag/gunbc/rung_drop/long_home_enrolment_margin_observed_only.dag index c2b019787ae..d126ceb106b 100644 --- a/dag/gunbc/rung_drop/long_home_enrolment_margin_observed_only.dag +++ b/dag/gunbc/rung_drop/long_home_enrolment_margin_observed_only.dag @@ -22,9 +22,10 @@ import gunbc.guarantee_rung { Mitigatable, MechanicallyPreventable } // refuses that reading at either gate. That removes a standing mechanically-preventable wall, // so it is declared here rather than landed silently. // -// WHAT THIS DROP IS NOT. It is not the typed cost-debt constructor. Half two of the same -// change (`v2.workflow.floor_cost_debt_admission` `floor_cost_debt_row`) still refuses a 325ms -// observed reading into the roster, so Roster ground cannot be minted from a margin crossing. +// WHAT THIS DROP IS NOT. It does not cover the Roster ground. A typed admission is +// live-conditioned (`v2.workflow.floor_enrolment_margin` `enrolment_declared_measured_standing`): +// a 325ms reading under the per-subject line leaves it stale and blocking, and a planned Roster +// identity with no reading is NotMeasured, so Roster ground cannot hold on a margin crossing. // Undeclared new witnesses at 325ms still refuse over the margin. Wall deadline and semantic // red stay armed. Censored and absent-with-verdict readings still stop the run on // changed-witness; those walls were not lowered. diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 800a1e35651..e779e22b2e3 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -1487,6 +1487,14 @@ pub(crate) enum EnrolmentMarginStanding { ground: EnrolmentExpensivenessGround, reading: EnrolmentDeclaredCostReading, }, + /// Mirror of `EnrolmentRosterGroundStale`. A Roster (typed cost-debt) declaration admits only + /// while THIS RUN's live reading is strictly above the per-subject CPU line. A reading at or + /// under the line means the identity is no longer expensive, so its row is stale and must + /// delete: the declaration cannot outlive the cost that justified it. + RosterGroundStale { + observed_cpu_ms: u64, + line_ms: u64, + }, } /// Host rendering of `EnrolmentCostReading` beside a declared-expensiveness standing. @@ -1528,6 +1536,7 @@ impl EnrolmentMarginStanding { EnrolmentMarginStanding::NotMeasured { .. } => true, EnrolmentMarginStanding::OutsideThisRunsExecution { .. } => false, EnrolmentMarginStanding::ExpensivenessDeclared { .. } => false, + EnrolmentMarginStanding::RosterGroundStale { .. } => true, } } @@ -1540,7 +1549,8 @@ impl EnrolmentMarginStanding { | EnrolmentMarginStanding::OverMargin { .. } | EnrolmentMarginStanding::CeilingCensored { .. } | EnrolmentMarginStanding::BoundWithoutCeiling { .. } - | EnrolmentMarginStanding::NotMeasured { .. } => EnrolmentPairingHole::None, + | EnrolmentMarginStanding::NotMeasured { .. } + | EnrolmentMarginStanding::RosterGroundStale { .. } => EnrolmentPairingHole::None, EnrolmentMarginStanding::OutsideThisRunsExecution { .. } => { EnrolmentPairingHole::OutsideExecution } @@ -1562,6 +1572,7 @@ impl EnrolmentMarginStanding { EnrolmentMarginStanding::NotMeasured { .. } => "enrolment_not_measured", EnrolmentMarginStanding::OutsideThisRunsExecution { .. } => "", EnrolmentMarginStanding::ExpensivenessDeclared { .. } => "", + EnrolmentMarginStanding::RosterGroundStale { .. } => "enrolment_roster_ground_stale", } } @@ -1580,6 +1591,7 @@ impl EnrolmentMarginStanding { "outside_this_runs_execution" } EnrolmentMarginStanding::ExpensivenessDeclared { .. } => "expensiveness_declared", + EnrolmentMarginStanding::RosterGroundStale { .. } => "roster_ground_stale", } } @@ -1620,28 +1632,68 @@ impl EnrolmentMarginStanding { EnrolmentExpensivenessGround::Roster => "roster", EnrolmentExpensivenessGround::LongHome => "long_home", }; + // The Roster ground IS decided here, from the live reading; LongHome is reported + // and not decided (the declared drop long_home_enrolment_margin_observed_only). + let decision = match ground { + EnrolmentExpensivenessGround::Roster => { + "admitted: live reading over the per-subject line" + } + EnrolmentExpensivenessGround::LongHome => "reported; does not decide this gate", + }; match reading { EnrolmentDeclaredCostReading::Observed { observed_cpu_ms } => format!( "expensiveness_declared ground={ground_name} observed_cpu_ms={observed_cpu_ms} \ - (reported; does not decide this gate)" + ({decision})" ), EnrolmentDeclaredCostReading::BoundWithoutCeiling { cpu_lower_bound_ms } => { format!( "expensiveness_declared ground={ground_name} cost=BOUND_WITHOUT_CEILING \ cpu_at_least_ms={cpu_lower_bound_ms} \ - (reported; does not decide this gate)" + ({decision})" ) } EnrolmentDeclaredCostReading::Absent => format!( "expensiveness_declared ground={ground_name} cost=UNMEASURED \ - (reported; does not decide this gate)" + ({decision})" ), } } + EnrolmentMarginStanding::RosterGroundStale { + observed_cpu_ms, + line_ms, + } => format!( + "roster ground stale: observed_cpu_ms={observed_cpu_ms} is not above the \ + per-subject line line_ms={line_ms}; the typed cost-debt row for this identity \ + must delete" + ), } } } +/// The per-subject CPU line (`required_floor_per_subject_cpu_line_ms`), read out of the policy +/// model. One read shared by the enrolment-margin budget, which must sit strictly below it, and by +/// the Roster expensiveness ground, which admits only a live reading strictly above it. +pub(crate) fn floor_per_subject_cpu_line_ms( + prepared: &crate::cli_run::PreparedRepository, +) -> Result { + let policy_scope = claim_scope_for(prepared, REQUIRED_FLOOR_POLICY_MODULE)?; + let policy_ctx = evaluation_frame( + &policy_scope, + v1_interpreter::ExecutionMode::Hermetic, + None, + None, + ); + // THE CPU LINE, NOT THE WORK ENVELOPE (review 66007). This budget is compared against + // an observed CPU reading, so the ceiling it must sit strictly below has to be + // denominated on the same clock. `required_floor_claim_work_envelope_ms` is policy in + // milliseconds of WORK, consumed only after conversion into eval steps; reading it here + // judged a CPU figure against a line from another quantity because both are spelled in + // milliseconds, which is the fusion `std.measure` `measure_clock_basis_note` forbids. + // The two share the magnitude 500 and that coincidence is exactly how the fork got + // written. + floor_required_measure_count(&policy_ctx, "required_floor_per_subject_cpu_line_ms") +} + /// THE MARGIN BUDGET, READ OUT OF THE MODEL. Not a Rust literal and not arithmetic repeated here: /// `v2.workflow.floor_enrolment_margin` `floor_enrolment_margin_budget_ms` derives it from the /// ceiling authority and the measured p90 runner envelope, and this reads that derivation's own @@ -1660,24 +1712,7 @@ pub(crate) fn floor_enrolment_margin_budget_ms( // witness before it evaluates one; a budget at or above the ceiling is the decoration the // model's own `the_enrolment_budget_is_strictly_below_the_ceiling` witness exists to forbid, // permanently green by construction while still being reported as coverage. - let ceiling_ms = { - let policy_scope = claim_scope_for(prepared, REQUIRED_FLOOR_POLICY_MODULE)?; - let policy_ctx = evaluation_frame( - &policy_scope, - v1_interpreter::ExecutionMode::Hermetic, - None, - None, - ); - // THE CPU LINE, NOT THE WORK ENVELOPE (review 66007). This budget is compared against - // an observed CPU reading, so the ceiling it must sit strictly below has to be - // denominated on the same clock. `required_floor_claim_work_envelope_ms` is policy in - // milliseconds of WORK, consumed only after conversion into eval steps; reading it here - // judged a CPU figure against a line from another quantity because both are spelled in - // milliseconds, which is the fusion `std.measure` `measure_clock_basis_note` forbids. - // The two share the magnitude 500 and that coincidence is exactly how the fork got - // written. - floor_required_measure_count(&policy_ctx, "required_floor_per_subject_cpu_line_ms")? - }; + let ceiling_ms = floor_per_subject_cpu_line_ms(prepared)?; match v1_interpreter::run_in_context(&ctx, &qualified, false) { Ok(v1_interpreter::Value::Int(n)) if n > 0 && (n as u64) < ceiling_ms => Ok(n as u64), Ok(v1_interpreter::Value::Int(n)) => Err(format!( @@ -1695,7 +1730,7 @@ pub(crate) fn floor_enrolment_margin_budget_ms( /// `v2.workflow.floor_enrolment_margin` `enrolment_typed_cost_debt_identities`, decoded /// from the frame the same way `floor_cost_debt_roster` is. Never a Rust-empty HashSet: -/// authoring `floor_cost_debt_typed_admission_attempts` must reach this gate (review 65692). +/// authoring a `floor_cost_debt_typed_admissions` row must reach this gate (review 65692). pub(crate) fn floor_enrolment_typed_cost_debt_identities( prepared: &crate::cli_run::PreparedRepository, ) -> Result, String> { @@ -1788,6 +1823,7 @@ pub(crate) fn enrolment_margin_standing_for( claim_cost: &HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence>, dispositions: &HashMap<&str, &crate::cli_run::RequiredFloorDisposition>, budget_ms: u64, + per_subject_line_ms: u64, declared_expensiveness: Option, ) -> EnrolmentMarginStanding { // THE EXECUTION JOIN COMES FIRST, AND SKIPPING IT IS THE DEFECT review 64022 FOUND. @@ -1815,7 +1851,18 @@ pub(crate) fn enrolment_margin_standing_for( // THE DECLARATION COMES NEXT, AND IT IS NOT THE COST POPULATION. Consulting `claim_cost` // before this point would rebuild review 64022. The caller supplies // `enrolment_expensiveness_declaration` (long home, never an ungated string-roster - // append). This match decides nothing from the CPU — `ChangedCostDebtVerdictOnly`. + // append). For LongHome ground this match decides nothing from the CPU — + // `ChangedCostDebtVerdictOnly`, the declared drop `long_home_enrolment_margin_observed_only`. + // + // THE ROSTER GROUND IS LIVE-CONDITIONED (gunbc#11622 review 68363). A typed cost-debt row + // carries an identity and a reason, never a reading, so the only cost that can justify it is + // THIS run's: it admits only while the live reading is strictly above the per-subject line. + // At or under the line it is stale and refuses. With NO cost row it refuses as NotMeasured, + // exactly as an undeclared planned identity does — otherwise the declaration would buy an + // exemption from being measured at all, which is the absorbing fallback DESIGN 5 forbids. + // A lower bound establishes expensiveness only if the bound itself is over the line; at or + // under it the bound proves nothing and blocks as BoundWithoutCeiling, the arm an undeclared + // identity with the same reading gets. if let Some(ground) = declared_expensiveness { let reading = match claim_cost.get(identity) { Some(row) => match &row.reading { @@ -1832,6 +1879,29 @@ pub(crate) fn enrolment_margin_standing_for( }, None => EnrolmentDeclaredCostReading::Absent, }; + if ground == EnrolmentExpensivenessGround::Roster { + match reading { + EnrolmentDeclaredCostReading::Observed { observed_cpu_ms } + if observed_cpu_ms <= per_subject_line_ms => + { + return EnrolmentMarginStanding::RosterGroundStale { + observed_cpu_ms, + line_ms: per_subject_line_ms, + }; + } + EnrolmentDeclaredCostReading::BoundWithoutCeiling { cpu_lower_bound_ms } + if cpu_lower_bound_ms <= per_subject_line_ms => + { + return EnrolmentMarginStanding::BoundWithoutCeiling { cpu_lower_bound_ms }; + } + EnrolmentDeclaredCostReading::Absent => { + return EnrolmentMarginStanding::NotMeasured { + cause: "no_claim_cost_row_for_a_planned_identity".to_string(), + }; + } + _ => {} + } + } return EnrolmentMarginStanding::ExpensivenessDeclared { ground, reading }; } let Some(row) = claim_cost.get(identity) else { @@ -9776,6 +9846,7 @@ pub fn run_required_floor( let mut enrolment_budget_ms: Option = None; if let Some(newly_enrolled) = newly_enrolled_witnesses.as_ref() { let budget_ms = floor_enrolment_margin_budget_ms(&prepared)?; + let per_subject_line_ms = floor_per_subject_cpu_line_ms(&prepared)?; enrolment_budget_ms = Some(budget_ms); let cost_by_identity = claim_cost_by_identity(&outcome.claim_cost); let dispositions: HashMap<&str, &RequiredFloorDisposition> = outcome @@ -9795,6 +9866,7 @@ pub fn run_required_floor( &cost_by_identity, &dispositions, budget_ms, + per_subject_line_ms, declared_expensiveness, ); eprintln!( @@ -12156,6 +12228,7 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ &cost_owned, &dispositions, 302, + 500, Some(declared), ); let terminals: Vec = terminal_row.into_iter().collect(); @@ -12389,6 +12462,119 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ ); } + /// THE ROSTER GROUND IS LIVE-CONDITIONED (gunbc#11622 review 68363). A typed cost-debt row + /// carries no reading, so it admits only on THIS run's reading strictly above the per-subject + /// line: over the line admits, at or under it is stale and blocks, and no cost row blocks as + /// NotMeasured exactly as an undeclared planned identity does. LongHome is the control that + /// the same absent reading is still only reported there (the declared drop). + #[test] + fn the_roster_ground_admits_only_on_a_live_reading_over_the_line() { + let identity = "m.roster"; + let planned = RequiredFloorDisposition::Planned; + let mut dispositions = HashMap::new(); + dispositions.insert(identity, &planned); + let occurrence_at = |cpu: u64| crate::cli_run::WitnessExecutionOccurrence { + identity: identity.to_string(), + module_path: "m".to_string(), + outcome: "passed".to_string(), + reading: crate::cli_run::ClaimCostReading::Observed { + observed_cpu_ms: cpu, + observed_wall_ms: cpu, + }, + eval_steps: 1, + verdict_reached: true, + cost_line_ms: 500, + preemption_reachability: "cooperatively_pollable".to_string(), + }; + let roster = Some(EnrolmentExpensivenessGround::Roster); + + let over = occurrence_at(681); + let mut over_cost: HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence> = + HashMap::new(); + over_cost.insert(identity, &over); + let admitted = + enrolment_margin_standing_for(identity, &over_cost, &dispositions, 302, 500, roster); + assert_eq!(admitted.name(), "expensiveness_declared"); + assert!(!admitted.blocks()); + + let at_line = occurrence_at(500); + let mut at_cost: HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence> = + HashMap::new(); + at_cost.insert(identity, &at_line); + let stale = + enrolment_margin_standing_for(identity, &at_cost, &dispositions, 302, 500, roster); + assert_eq!(stale.name(), "roster_ground_stale"); + assert_eq!(stale.cause(), "enrolment_roster_ground_stale"); + assert!(stale.blocks()); + + let absent = enrolment_margin_standing_for( + identity, + &HashMap::new(), + &dispositions, + 302, + 500, + roster, + ); + assert_eq!(absent.name(), "not_measured"); + assert!(absent.blocks()); + + let bound_at = |bound: u64| crate::cli_run::WitnessExecutionOccurrence { + identity: identity.to_string(), + module_path: "m".to_string(), + outcome: "interrupted".to_string(), + reading: crate::cli_run::ClaimCostReading::RightCensored( + crate::cli_run::SafetyInterruptReading { + raised_by: crate::cli_run::SafetyInterruptTrigger::WallDeadlineRaised, + elapsed_cpu_at_least_ms: bound, + elapsed_wall_at_least_ms: 8000, + wall_safety_limit_ms: 8000, + }, + ), + eval_steps: 1, + verdict_reached: false, + cost_line_ms: 500, + preemption_reachability: "cooperatively_pollable".to_string(), + }; + let bound_over = bound_at(514); + let mut bound_over_cost: HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence> = + HashMap::new(); + bound_over_cost.insert(identity, &bound_over); + let bound_admitted = enrolment_margin_standing_for( + identity, + &bound_over_cost, + &dispositions, + 302, + 500, + roster, + ); + assert_eq!(bound_admitted.name(), "expensiveness_declared"); + let bound_under = bound_at(1); + let mut bound_under_cost: HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence> = + HashMap::new(); + bound_under_cost.insert(identity, &bound_under); + let bound_refused = enrolment_margin_standing_for( + identity, + &bound_under_cost, + &dispositions, + 302, + 500, + roster, + ); + assert_eq!(bound_refused.name(), "bound_without_ceiling"); + assert!(bound_refused.blocks()); + + let long_home_absent = enrolment_margin_standing_for( + identity, + &HashMap::new(), + &dispositions, + 302, + 500, + Some(EnrolmentExpensivenessGround::LongHome), + ); + assert_eq!(long_home_absent.name(), "expensiveness_declared"); + assert!(!long_home_absent.blocks()); + } + /// THE PAIRING INVARIANT MADE EXECUTABLE. newly_enrolled contains a declared identity /// and the changed projection does not. Enrolment does not block; without a changed row /// the identity would admit silently. This call is the unpaired production arm @@ -12406,6 +12592,7 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ &cost_owned, &dispositions, 302, + 500, Some(EnrolmentExpensivenessGround::LongHome), ); assert_eq!(standing.name(), "expensiveness_declared"); @@ -12432,7 +12619,7 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ dispositions.insert(identity, &declined); let cost_owned: HashMap<&str, &crate::cli_run::WitnessExecutionOccurrence> = HashMap::new(); let standing = - enrolment_margin_standing_for(identity, &cost_owned, &dispositions, 302, None); + enrolment_margin_standing_for(identity, &cost_owned, &dispositions, 302, 500, None); assert_eq!(standing.name(), "outside_this_runs_execution"); assert!(!standing.blocks()); let blockers = required_floor_blockers_for(identity, Some(&standing), None); @@ -12529,6 +12716,7 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ &cost_owned, &dispositions, 302, + 500, Some(EnrolmentExpensivenessGround::LongHome), ); let absent = enrolment_margin_standing_for( @@ -12536,6 +12724,7 @@ fn lit(l: Light) -> Bool {\n match l {\n Red => true\n Off => false\n }\ &HashMap::new(), &dispositions, 302, + 500, Some(EnrolmentExpensivenessGround::LongHome), ); assert!( diff --git a/src/v2/test/floor_cost_debt_admission_test.dag b/src/v2/test/floor_cost_debt_admission_test.dag deleted file mode 100644 index 9528fdccfa3..00000000000 --- a/src/v2/test/floor_cost_debt_admission_test.dag +++ /dev/null @@ -1,255 +0,0 @@ -module v2.test.floor_cost_debt_admission - -import v2.workflow.floor_cost_debt_admission { - FloorCostDebtRow, FloorCostDebtRowStanding, - FloorCostDebtRowAdmitted, FloorCostDebtRowRefusedUnderCeiling, - FloorCostDebtRowRefusedCensoredNotEstablished, - FloorCostDebtRowRefusedBoundWithoutCeiling, - FloorCostDebtReadingAttempt, - FloorCostDebtVerdictAxis, FloorCostDebtReachedAVerdict, FloorCostDebtNeverReachedAVerdict, - floor_cost_debt_row, floor_cost_debt_row_is_admitted, floor_cost_debt_admit_attempts, -} -import gunbc.floor_cost_distribution { - ClaimCostReading, ObservedCpuReading, RightCensoredCpuReading, CpuLowerBoundWithoutCeiling, -} -import v2.std.logic { Bool } -import v2.std.integer { Int } -import std.measure { Millisecond, millisecond, millisecond_count, EvalStepCount, eval_step_count } -import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } - -data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly - -// Ceiling is a constructor parameter. The live authority is -// `required_floor_claim_work_envelope_ms`; the enrolment-margin suite joins that name to this -// constructor so this file need not import required_floor (and with it the floor's whole roster). -fn ceiling() -> Millisecond { - millisecond(count: 500) -} - -// THE STEP COUNT THESE FIXTURES CARRY IS INCIDENTAL AND IS DECLARED AS SUCH (gunbc#11366 Phase 1). -// Every witness in this file exercises the CPU half -- the margin, the ceiling, the censoring -// discriminator -- so the count is present because the arm requires one and not because any -// assertion here reads it. When Phase 2 denominates this gate in eval steps these fixtures gain a -// step parameter and the value stops being incidental; saying so now is what keeps a later reader -// from mistaking an arbitrary figure for a measured one. -fn observed(cpu_ms: Int) -> ClaimCostReading { - ObservedCpuReading { cpu_ms: millisecond(count: cpu_ms), eval_steps: fixture_incidental_steps() } -} - -fn fixture_incidental_steps() -> EvalStepCount { - eval_step_count(count: 1000) -} - -fn censored(cpu_lower_bound_ms: Millisecond, censoring_ceiling_ms: Millisecond) -> ClaimCostReading { - RightCensoredCpuReading { - cpu_lower_bound_ms: cpu_lower_bound_ms, - censoring_ceiling_ms: censoring_ceiling_ms, - eval_steps_before_censor: fixture_incidental_steps(), - } -} - -fn observed_attempt(identity: String, cpu_ms: Int) -> FloorCostDebtReadingAttempt { - FloorCostDebtReadingAttempt { - identity: identity, - reading: observed(cpu_ms: cpu_ms), - verdict: FloorCostDebtReachedAVerdict, - } -} - -fn censored_no_verdict( - identity: String, - cpu_lower_bound_ms: Millisecond, - censoring_ceiling_ms: Millisecond, -) -> FloorCostDebtReadingAttempt { - FloorCostDebtReadingAttempt { - identity: identity, - reading: censored( - cpu_lower_bound_ms: cpu_lower_bound_ms, - censoring_ceiling_ms: censoring_ceiling_ms, - ), - verdict: FloorCostDebtNeverReachedAVerdict, - } -} - -fn standing_observed(identity: String, cpu_ms: Int) -> FloorCostDebtRowStanding { - floor_cost_debt_row( - identity: identity, - reading: observed(cpu_ms: cpu_ms), - ceiling_ms: ceiling(), - verdict: FloorCostDebtReachedAVerdict, - ) -} - -fn standing_censored( - identity: String, - cpu_lower_bound_ms: Millisecond, - censoring_ceiling_ms: Millisecond, - verdict: FloorCostDebtVerdictAxis, -) -> FloorCostDebtRowStanding { - floor_cost_debt_row( - identity: identity, - reading: censored( - cpu_lower_bound_ms: cpu_lower_bound_ms, - censoring_ceiling_ms: censoring_ceiling_ms, - ), - ceiling_ms: ceiling(), - verdict: verdict, - ) -} - -// A BOUND WITH NO CEILING REFUSES ON ITS OWN ARM AND MINTS NOTHING. Since no CPU deadline is -// armed, a preempted row's CPU is a bound with no ceiling beside it, so the "establishes the -// supplied ceiling" test has nothing to compare. The refusal must be its OWN arm: reusing -// `RefusedCensoredNotEstablished` would need a `censoring_ceiling_ms` filled from the supplied -// ceiling, a figure the reading never carried. This drives the real classification and asserts -// both halves -- that it refuses, and that it refuses under the arm that does not fabricate. -test fn a_bound_with_no_ceiling_is_refused_and_does_not_fabricate_a_ceiling() -> Bool { - let standing = floor_cost_debt_row( - identity: "fixture.bound_no_ceiling", - reading: CpuLowerBoundWithoutCeiling { cpu_lower_bound_ms: millisecond(count: 514), eval_steps_before_censor: fixture_incidental_steps() }, - ceiling_ms: ceiling(), - verdict: FloorCostDebtNeverReachedAVerdict, - ) - match standing { - FloorCostDebtRowRefusedBoundWithoutCeiling { identity: i, cpu_lower_bound_ms: b } => - i == "fixture.bound_no_ceiling" - && millisecond_count(m: b) == 514 - && !floor_cost_debt_row_is_admitted(standing: standing) - FloorCostDebtRowAdmitted { row: _ } => false - FloorCostDebtRowRefusedUnderCeiling { identity: _, observed_cpu_ms: _ } => false - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: _, - cpu_lower_bound_ms: _, - censoring_ceiling_ms: _, - } => false - } -} - -// HALF TWO RED: a fixture row at 325ms OBSERVED refuses to enter the roster. That is the -// gunbc#10994 specimen cost — over the enrolment margin, under the 500ms ceiling — and -// rostering it would mint "declared too expensive" from a margin crossing. -test fn an_observed_row_at_325ms_cannot_enter_the_cost_debt_roster() -> Bool { - let standing = standing_observed(identity: "fixture.tripwire_325", cpu_ms: 325) - !floor_cost_debt_row_is_admitted(standing: standing) - && match standing { - FloorCostDebtRowAdmitted { row: _ } => false - FloorCostDebtRowRefusedUnderCeiling { identity: _, observed_cpu_ms: c } => - millisecond_count(m: c) == 325 - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: _, - cpu_lower_bound_ms: _, - censoring_ceiling_ms: _, - } => false - FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: _, - cpu_lower_bound_ms: _, - } => false - } -} - -test fn an_observed_row_above_the_ceiling_is_admitted() -> Bool { - floor_cost_debt_row_is_admitted( - standing: standing_observed(identity: "fixture.proven_501", cpu_ms: 501) - ) - && fold( - floor_cost_debt_admit_attempts( - attempts: [observed_attempt(identity: "fixture.proven_501", cpu_ms: 501)], - ceiling_ms: ceiling(), - ), - init: "", - f: fn(acc, row) { concat(acc, row.identity) } - ) == "fixture.proven_501" -} - -test fn a_censored_row_is_admitted() -> Bool { - floor_cost_debt_row_is_admitted( - standing: standing_censored( - identity: "fixture.censored", - cpu_lower_bound_ms: millisecond(count: 500), - censoring_ceiling_ms: millisecond(count: 500), - verdict: FloorCostDebtNeverReachedAVerdict, - ) - ) - && fold( - floor_cost_debt_admit_attempts( - attempts: [censored_no_verdict( - identity: "fixture.censored", - cpu_lower_bound_ms: millisecond(count: 500), - censoring_ceiling_ms: millisecond(count: 500), - )], - ceiling_ms: ceiling(), - ), - init: "", - f: fn(acc, row) { concat(acc, row.identity) } - ) == "fixture.censored" -} - -// THE GATEKEEPER COUNTEREXAMPLE: a 1ms censored reading against the real 500ms ceiling must -// refuse. Censoring at 1ms does not establish the required-floor CPU ceiling. -test fn a_1ms_censored_reading_against_the_500ms_ceiling_is_refused() -> Bool { - let standing = standing_censored( - identity: "fixture.censored_1ms", - cpu_lower_bound_ms: millisecond(count: 1), - censoring_ceiling_ms: millisecond(count: 1), - verdict: FloorCostDebtNeverReachedAVerdict, - ) - !floor_cost_debt_row_is_admitted(standing: standing) - && match standing { - FloorCostDebtRowAdmitted { row: _ } => false - FloorCostDebtRowRefusedUnderCeiling { identity: _, observed_cpu_ms: _ } => false - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: _, - cpu_lower_bound_ms: b, - censoring_ceiling_ms: c, - } => millisecond_count(m: b) == 1 && millisecond_count(m: c) == 1 - FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: _, - cpu_lower_bound_ms: _, - } => false - } -} - -test fn a_censored_row_whose_ceiling_mismatches_the_supplied_ceiling_is_refused() -> Bool { - !floor_cost_debt_row_is_admitted( - standing: standing_censored( - identity: "fixture.censored_wrong_ceiling", - cpu_lower_bound_ms: millisecond(count: 500), - censoring_ceiling_ms: millisecond(count: 1), - verdict: FloorCostDebtNeverReachedAVerdict, - ) - ) -} - -test fn a_censored_row_that_reached_a_verdict_is_refused() -> Bool { - !floor_cost_debt_row_is_admitted( - standing: standing_censored( - identity: "fixture.censored_with_verdict", - cpu_lower_bound_ms: millisecond(count: 500), - censoring_ceiling_ms: millisecond(count: 500), - verdict: FloorCostDebtReachedAVerdict, - ) - ) -} - -test fn the_admission_fold_drops_a_325ms_observed_row() -> Bool { - let admitted = floor_cost_debt_admit_attempts( - attempts: [ - observed_attempt(identity: "fixture.tripwire_325", cpu_ms: 325), - observed_attempt(identity: "fixture.proven_501", cpu_ms: 501), - censored_no_verdict( - identity: "fixture.censored", - cpu_lower_bound_ms: millisecond(count: 514), - censoring_ceiling_ms: millisecond(count: 500), - ), - censored_no_verdict( - identity: "fixture.censored_1ms", - cpu_lower_bound_ms: millisecond(count: 1), - censoring_ceiling_ms: millisecond(count: 1), - ), - ], - ceiling_ms: ceiling(), - ) - fold(admitted, init: "", f: fn(acc, row) { - concat(acc, concat(row.identity, ";")) - }) == "fixture.proven_501;fixture.censored;" -} diff --git a/src/v2/test/floor_enrolment_margin_test.dag b/src/v2/test/floor_enrolment_margin_test.dag index eddadbca49e..c3b92b6f0ad 100644 --- a/src/v2/test/floor_enrolment_margin_test.dag +++ b/src/v2/test/floor_enrolment_margin_test.dag @@ -7,7 +7,7 @@ import v2.workflow.floor_enrolment_margin { EnrolmentMarginStanding, EnrolmentWithinMargin, EnrolmentOverMargin, EnrolmentCeilingCensored, EnrolmentBoundWithoutCeiling, EnrolmentNotMeasured, - EnrolmentOutsideThisRunsExecution, EnrolmentExpensivenessDeclared, + EnrolmentOutsideThisRunsExecution, EnrolmentExpensivenessDeclared, EnrolmentRosterGroundStale, EnrolmentExpensivenessNotDeclared, EnrolmentExpensivenessIsDeclared, EnrolmentExpensivenessGround, EnrolmentExpensivenessRoster, EnrolmentExpensivenessLongHome, enrolment_expensiveness_declaration, @@ -21,10 +21,6 @@ import v2.workflow.floor_enrolment_margin { enrolment_margin_blockers, } import v2.workflow.required_floor { required_floor_per_subject_cpu_line_ms } -import v2.workflow.floor_cost_debt_admission { - floor_cost_debt_row, floor_cost_debt_row_is_admitted, - FloorCostDebtReachedAVerdict, -} import gunbc.floor_cost_distribution { ClaimCostReading, ObservedCpuReading, RightCensoredCpuReading, CpuLowerBoundWithoutCeiling, implied_clean_run_budget, @@ -90,6 +86,7 @@ fn standing_of(reading: EnrolmentCostReading) -> EnrolmentMarginStanding { enrolment_margin_standing( reading: reading, budget_ms: floor_enrolment_margin_budget_ms(), + per_subject_line_ms: required_floor_per_subject_cpu_line_ms(), declaration: EnrolmentExpensivenessNotDeclared, ) } @@ -102,6 +99,7 @@ fn standing_declared( enrolment_margin_standing( reading: reading, budget_ms: floor_enrolment_margin_budget_ms(), + per_subject_line_ms: required_floor_per_subject_cpu_line_ms(), declaration: EnrolmentExpensivenessIsDeclared { witness_identity: identity, ground: ground, @@ -118,6 +116,7 @@ fn standing_kind(s: EnrolmentMarginStanding) -> String { EnrolmentNotMeasured { witness_identity: _, cause: _ } => "not-measured" EnrolmentOutsideThisRunsExecution { witness_identity: _, disposition: _ } => "outside-this-run" EnrolmentExpensivenessDeclared { witness_identity: _, ground: _, reading: _ } => "expensiveness-declared" + EnrolmentRosterGroundStale { witness_identity: _, observed_cpu_ms: _, line_ms: _ } => "roster-ground-stale" } } @@ -478,16 +477,75 @@ test fn the_pairing_hole_is_exhaustive_over_standing() -> Bool { } } -// HALF TWO RED JOINED TO THE CEILING AUTHORITY: 325ms observed against -// `required_floor_per_subject_cpu_line_ms` cannot mint a cost-debt row. gunbc#10994 is not -// waiting on a cost-debt line; this is the constructor that would have refused that classification. -test fn an_observed_row_at_325ms_is_refused_against_the_required_floor_ceiling() -> Bool { - !floor_cost_debt_row_is_admitted( - standing: floor_cost_debt_row( - identity: "fixture.tripwire_325", - reading: ObservedCpuReading { cpu_ms: millisecond(count: 325), eval_steps: fixture_incidental_steps() }, - ceiling_ms: required_floor_per_subject_cpu_line_ms(), - verdict: FloorCostDebtReachedAVerdict, - ) +// THE ROSTER GROUND IS LIVE-CONDITIONED (gunbc#11622 review 68363). A typed admission carries an +// identity and a reason, never a reading, so every row below is decided by the reading THIS run +// supplies, against `required_floor_per_subject_cpu_line_ms`. These rows re-home the behaviours +// the retired stored-reading constructor used to establish onto the live arms that now own them. + +fn roster_standing(reading: EnrolmentCostReading) -> EnrolmentMarginStanding { + standing_declared( + reading: reading, + identity: "fixture.roster", + ground: EnrolmentExpensivenessRoster, ) } + +// Re-homed from the constructor's "above the ceiling is admitted": a live reading strictly over +// the line keeps the admission. +test fn a_roster_admission_over_the_line_stays_declared() -> Bool { + let s = roster_standing(reading: observed(cpu_ms: 501)) + standing_kind(s: s) == "expensiveness-declared" + && !enrolment_margin_standing_blocks(standing: s) +} + +// Re-homed from the gunbc#10994 325ms tripwire: a margin crossing under the line cannot hold a +// Roster admission. It is stale, blocks, and says the row must delete. +test fn a_roster_admission_at_325ms_is_stale_and_blocks() -> Bool { + let s = roster_standing(reading: observed(cpu_ms: 325)) + standing_kind(s: s) == "roster-ground-stale" + && enrolment_margin_standing_blocks(standing: s) + && enrolment_margin_blocking_cause(standing: s) == "enrolment_roster_ground_stale" +} + +// The boundary: the line itself is not over the line. +test fn a_roster_admission_exactly_at_the_line_is_stale() -> Bool { + standing_kind(s: roster_standing(reading: observed(cpu_ms: 500))) == "roster-ground-stale" + && standing_kind(s: roster_standing(reading: observed(cpu_ms: 501))) == "expensiveness-declared" +} + +// THE HOLE THIS CHANGE CLOSES. A planned Roster identity with no cost row is NotMeasured, exactly +// as an undeclared one is -- the declaration buys no exemption from being measured. LongHome is +// the control: the same absent reading is still only reported there (the declared drop +// `long_home_enrolment_margin_observed_only`), so this row is the Roster arm and not a global +// change. +test fn a_roster_admission_with_no_reading_is_not_measured() -> Bool { + let absent = EnrolmentCostAbsent { + witness_identity: "fixture.roster", + cause: "no_claim_cost_row_for_a_planned_identity", + } + standing_kind(s: roster_standing(reading: absent)) == "not-measured" + && enrolment_margin_standing_blocks(standing: roster_standing(reading: absent)) + && standing_kind(s: standing_declared( + reading: absent, + identity: "fixture.long_home", + ground: EnrolmentExpensivenessLongHome, + )) == "expensiveness-declared" +} + +// Re-homed from "a bound with no ceiling mints nothing" and "a censored row at the ceiling is +// admitted": a lower bound establishes expensiveness only if the bound itself clears the line. +test fn a_roster_admission_with_a_bound_over_the_line_stays_declared() -> Bool { + standing_kind(s: roster_standing(reading: bound_without_ceiling(lower_bound_ms: 514))) == "expensiveness-declared" + && standing_kind(s: roster_standing(reading: censored(lower_bound_ms: 514, ceiling_ms: 500))) == "expensiveness-declared" +} + +// Re-homed from "a 1ms censored reading against the 500ms ceiling is refused": a bound at or under +// the line proves nothing, so it blocks under the same arm an undeclared identity would get. +test fn a_roster_admission_with_a_bound_under_the_line_blocks_on_its_own_arm() -> Bool { + let b = roster_standing(reading: bound_without_ceiling(lower_bound_ms: 1)) + let c = roster_standing(reading: censored(lower_bound_ms: 1, ceiling_ms: 1)) + standing_kind(s: b) == "bound-without-ceiling" + && enrolment_margin_standing_blocks(standing: b) + && standing_kind(s: c) == "ceiling-censored" + && enrolment_margin_standing_blocks(standing: c) +} diff --git a/src/v2/workflow/floor_cost_debt.dag b/src/v2/workflow/floor_cost_debt.dag index 760bbc3f3f7..0ad80642e92 100644 --- a/src/v2/workflow/floor_cost_debt.dag +++ b/src/v2/workflow/floor_cost_debt.dag @@ -111,13 +111,14 @@ import v2.std.collection { List } // - the direction is justified: a row leaves by being made cheap, and the forward hole is // already shut -- a NEW or REGRESSED row over 500ms simply refuses, because 500 is the // ceiling and nothing here admits an identity the floor did not already discover. -// THE TYPED CONSTRUCTOR `v2.workflow.floor_cost_debt_admission` `floor_cost_debt_row` is -// NOT this roster's mint path today. Membership is still the hand-authored identity-string -// chunks `floor_cost_debt_roster` folds. Claiming those strings are minted only through -// the constructor was a §3c dangling assertion (review 65585). The constructor is the -// gate for `floor_cost_debt_typed_admission_attempts`, whose first live consumer is named -// at that function: the required-floor runner unioning typed-admitted identities into -// the withhold set, with these string chunks frozen against growth. Until that lands, +// THE TYPED ADMISSIONS `v2.workflow.floor_cost_debt_admission` +// `floor_cost_debt_typed_admissions` ARE NOT this roster's mint path today. Membership is +// still the hand-authored identity-string chunks `floor_cost_debt_roster` folds. Claiming +// those strings are minted through the typed rows was a §3c dangling assertion (review +// 65585). A typed row carries identity and reason and is live-conditioned at the enrolment +// gate (`v2.workflow.floor_enrolment_margin` `enrolment_declared_measured_standing`); its +// later consumer is the required-floor runner unioning typed-admitted identities into the +// withhold set, with these string chunks frozen against growth. Until that lands, // a margin-crossing identity can still be string-appended here; that hole is the existing // monotone contract (identity-grain stale, shrink-only review), not construction. // - a rostered identity the tree no longer carries REFUSES as a stale row, so the roster diff --git a/src/v2/workflow/floor_cost_debt_admission.dag b/src/v2/workflow/floor_cost_debt_admission.dag index 3633319425c..5b98c71ea6f 100644 --- a/src/v2/workflow/floor_cost_debt_admission.dag +++ b/src/v2/workflow/floor_cost_debt_admission.dag @@ -1,195 +1,43 @@ module v2.workflow.floor_cost_debt_admission import v2.std.collection { List } -import v2.std.logic { Bool } -import gunbc.floor_cost_distribution { - ClaimCostReading, ObservedCpuReading, RightCensoredCpuReading, CpuLowerBoundWithoutCeiling, -} -import std.measure { Millisecond, millisecond_count } +import std.types { NonEmptyStr } -// ROSTER ADMISSION BY CONSTRUCTION FOR `v2.workflow.floor_cost_debt`. -// -// WHY THIS IS NOT INSIDE THAT MODULE. `required_floor` already imports `floor_cost_debt` for -// membership. Importing `ClaimCostReading` there would pull `gunbc.floor_cost_distribution` -// into every required-floor compile — a second copy of a large analysis module on the floor's -// hot path. The identity census stays there; the READING FIELD of a new row lives here. -// -// THE PROVEN CLASS, STATED SO THE PR DOES NOT RE-DERIVE THE POLICY: witnesses whose observed -// CPU exceeds `required_floor_per_subject_cpu_line_ms` (the 500ms CPU line -- CPU milliseconds, NOT the -// work envelope: they share a magnitude and are different quantities) plus censored -// witnesses that never reached a verdict. A censored reading must ESTABLISH that supplied -// ceiling (censoring_ceiling equals it, lower bound at least it) and the attempt must CARRY -// `FloorCostDebtNeverReachedAVerdict` — censoring is not that discriminator. -// required_floor treats the roster and the long home as ONE declaration class. This constructor -// is what makes "one declaration class" true IN EVIDENCE: a margin crossing (over 302, under -// 500) cannot mint a row, and a 1ms censored reading against the 500ms ceiling cannot either. +// TYPED ROSTER ADMISSION FOR THE ENROLMENT MARGIN: AN IDENTITY AND A REASON, NEVER A READING. // -// THE CEILING IS A PARAMETER. This module must not import `required_floor` (cycle through -// floor_cost_debt) and must not restate 500. Callers pass -// `required_floor_per_subject_cpu_line_ms()`. +// WHAT THIS REPLACED, AND WHY AT THE ROOT (DESIGN §3, replacement migration; gunbc#11622 review +// 68363). A typed admission used to carry an authored `ClaimCostReading` that a constructor +// compared against the per-subject CPU line. Once the enrolment gate decides the Roster ground +// from THIS run's live reading (`v2.workflow.floor_enrolment_margin` +// `enrolment_declared_measured_standing`), a stored reading answers the same question a second +// time -- is this identity expensive enough to admit -- and the two can disagree: a stored 681 +// says admit while a live 200 says stale. Nothing would say which wins. The stored figure also +// decided nothing any more while still being a number transcribed into source. So it is gone, +// with the constructor that judged it: the only cost that can justify an admission is the one the +// floor measures on the run it is judging, and an admission whose identity has become cheap goes +// stale and refuses, which forces its deletion. // -// DECLARED FRONTIER (DESIGN §3c), not a live mint. `floor_cost_debt_row` is consumed by -// `floor_cost_debt_admit_attempts` and by executing tests; it is NOT consumed by -// `floor_cost_debt_roster`. The live withhold set is still those identity strings. Wiring -// this module into every required-floor compile would import `gunbc.floor_cost_distribution` -// onto that hot path (the reason the constructor is not inside `floor_cost_debt`). +// WHAT A ROW STILL CARRIES. The identity, and a reason that is the whole surviving justification: +// the diagnosis of why the witness is honestly expensive, and who owns it. The measurement that +// established it is cited by naming the run that produced it in the change that authors the row, +// never by copying its figures here. // -// NAMED CONSUMER: `v2.workflow.floor_enrolment_margin` `enrolment_typed_cost_debt_identities` -// decodes this list onto enrolment Roster ground. The withhold HashSet union into -// `floor_cost_debt_roster` remains a later consumer: the first identity that would otherwise -// be appended as a string after this PR is authored here as a `FloorCostDebtReadingAttempt` -// and nowhere else. Until then this list is Empty, which is the honest population. +// NAMED CONSUMER: `v2.workflow.floor_enrolment_margin` `enrolment_typed_cost_debt_identities`, +// decoded by the host `required_floor_runner` `floor_enrolment_typed_cost_debt_identities`. + +type FloorCostDebtTypedAdmission { + identity: String + reason: NonEmptyStr +} -fn floor_cost_debt_typed_admission_attempts() -> List { +fn floor_cost_debt_typed_admissions() -> List { [] } -fn floor_cost_debt_typed_admitted_identities(ceiling_ms: Millisecond) -> List { +fn floor_cost_debt_typed_admitted_identities() -> List { reverse(fold( - floor_cost_debt_admit_attempts( - attempts: floor_cost_debt_typed_admission_attempts(), - ceiling_ms: ceiling_ms, - ), + floor_cost_debt_typed_admissions(), init: [], f: fn(acc, row) { concat([row.identity], acc) }, )) } - -type FloorCostDebtRow { - identity: String - reading: ClaimCostReading -} - -// VERDICT REACHABILITY IS A SEPARATE AXIS from ClaimCostReading (gunbc.floor_cost_distribution -// / v2.workflow.claim_cost_observation). Censoring does not prove "never reached a verdict". -// The attempt carries the discriminator; the constructor consumes it. -type FloorCostDebtVerdictAxis = - FloorCostDebtReachedAVerdict - | FloorCostDebtNeverReachedAVerdict - -type FloorCostDebtRowStanding = - FloorCostDebtRowAdmitted { row: FloorCostDebtRow } - | FloorCostDebtRowRefusedUnderCeiling { identity: String, observed_cpu_ms: Millisecond } - | FloorCostDebtRowRefusedCensoredNotEstablished { - identity: String - cpu_lower_bound_ms: Millisecond - censoring_ceiling_ms: Millisecond - } - | FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: String - cpu_lower_bound_ms: Millisecond - } - -type FloorCostDebtReadingAttempt { - identity: String - reading: ClaimCostReading - verdict: FloorCostDebtVerdictAxis -} - -// A BOUND WITH NO CEILING CAN NEVER ESTABLISH THE SUPPLIED ONE, SO IT REFUSES ON ITS OWN ARM. -// The admission test for a censored row is that its reading ESTABLISHES the ceiling it was -// stopped at -- `censoring_ceiling` equals the supplied ceiling and the bound reaches it. A -// `CpuLowerBoundWithoutCeiling` carries no ceiling at all, so that test has nothing to compare -// and the row cannot be minted. It does NOT reuse `RefusedCensoredNotEstablished`, whose -// `censoring_ceiling_ms` field would have to be filled from the SUPPLIED ceiling -- writing a -// figure the reading never carried into a field named for one it did, which is the fabricated -// diagnostic DESIGN §5 forbids. The refusal is typed, located, and names the bound it did read. -fn floor_cost_debt_row( - identity: String, - reading: ClaimCostReading, - ceiling_ms: Millisecond, - verdict: FloorCostDebtVerdictAxis, -) -> FloorCostDebtRowStanding { - match reading { - RightCensoredCpuReading { cpu_lower_bound_ms: b, censoring_ceiling_ms: c, eval_steps_before_censor: steps } => - match verdict { - FloorCostDebtNeverReachedAVerdict => - if millisecond_count(m: c) == millisecond_count(m: ceiling_ms) - && millisecond_count(m: b) >= millisecond_count(m: ceiling_ms) { - FloorCostDebtRowAdmitted { - row: FloorCostDebtRow { - identity: identity, - reading: RightCensoredCpuReading { - cpu_lower_bound_ms: b, - censoring_ceiling_ms: c, - eval_steps_before_censor: steps, - }, - }, - } - } else { - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: identity, - cpu_lower_bound_ms: b, - censoring_ceiling_ms: c, - } - } - FloorCostDebtReachedAVerdict => - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: identity, - cpu_lower_bound_ms: b, - censoring_ceiling_ms: c, - } - } - CpuLowerBoundWithoutCeiling { cpu_lower_bound_ms: b, eval_steps_before_censor: _ } => - FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: identity, - cpu_lower_bound_ms: b, - } - ObservedCpuReading { cpu_ms: c, eval_steps: steps } => - if millisecond_count(m: c) > millisecond_count(m: ceiling_ms) { - FloorCostDebtRowAdmitted { - row: FloorCostDebtRow { - identity: identity, - reading: ObservedCpuReading { cpu_ms: c, eval_steps: steps }, - }, - } - } else { - FloorCostDebtRowRefusedUnderCeiling { identity: identity, observed_cpu_ms: c } - } - } -} - -fn floor_cost_debt_row_is_admitted(standing: FloorCostDebtRowStanding) -> Bool { - match standing { - FloorCostDebtRowAdmitted { row: _ } => true - FloorCostDebtRowRefusedUnderCeiling { identity: _, observed_cpu_ms: _ } => false - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: _, - cpu_lower_bound_ms: _, - censoring_ceiling_ms: _, - } => false - FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: _, - cpu_lower_bound_ms: _, - } => false - } -} - -// THE ROSTER WITNESS FOLD. Identity-grain over every attempt: a 325ms observed row cannot -// survive into the admitted set; a censored row that does not establish the supplied ceiling -// cannot either. -fn floor_cost_debt_admit_attempts( - attempts: List, - ceiling_ms: Millisecond, -) -> List { - reverse(fold(attempts, init: [], f: fn(acc, attempt) { - match floor_cost_debt_row( - identity: attempt.identity, - reading: attempt.reading, - ceiling_ms: ceiling_ms, - verdict: attempt.verdict, - ) { - FloorCostDebtRowAdmitted { row: row } => concat([row], acc) - FloorCostDebtRowRefusedUnderCeiling { identity: _, observed_cpu_ms: _ } => acc - FloorCostDebtRowRefusedCensoredNotEstablished { - identity: _, - cpu_lower_bound_ms: _, - censoring_ceiling_ms: _, - } => acc - FloorCostDebtRowRefusedBoundWithoutCeiling { - identity: _, - cpu_lower_bound_ms: _, - } => acc - } - })) -} diff --git a/src/v2/workflow/floor_enrolment_margin.dag b/src/v2/workflow/floor_enrolment_margin.dag index 53ed3e23e7a..8add68e2d00 100644 --- a/src/v2/workflow/floor_enrolment_margin.dag +++ b/src/v2/workflow/floor_enrolment_margin.dag @@ -190,15 +190,11 @@ fn floor_enrolment_margin_budget_ms_count() -> Int { // TYPED COST-DEBT IDENTITIES THIS GATE MAY HONOUR AS ROSTER GROUND. Decoded by the host // the same way `floor_cost_debt_roster` is decoded -- never a Rust-empty HashSet. // -// REACHABLE, UNEXERCISED UNTIL THE FIRST AUTHORED ATTEMPT; THAT FIRST ATTEMPT IS THE RED. -// The Roster arm is reachable by construction (`enrolment_expensiveness_declaration` given -// typed_admission_holds). End-to-end execution of this nullary list waits on the first -// `FloorCostDebtReadingAttempt` in `floor_cost_debt_typed_admission_attempts`. That -// authoring is the discriminating evidence; emptiness of today's list is not coverage. +// A typed admission carries an identity and a reason, never a reading: whether the identity is +// still expensive is decided by THIS run's live reading in `enrolment_declared_measured_standing`, +// so an admission cannot outlive the cost that justified it. fn enrolment_typed_cost_debt_identities() -> List { - floor_cost_debt_typed_admitted_identities( - ceiling_ms: required_floor_per_subject_cpu_line_ms(), - ) + floor_cost_debt_typed_admitted_identities() } type EnrolmentExpensivenessGround = @@ -211,13 +207,13 @@ type EnrolmentExpensivenessDeclaration = // STATED DIVERGENCE FROM `v2.workflow.required_floor` // `changed_witness_expensiveness_is_declared`. That function is string-roster OR long home -// and still decides changed-witness CPU policy. This function is typed `floor_cost_debt_row` -// admission OR long home. String roster ALONE never declares here (review 65637). Long +// and still decides changed-witness CPU policy. This function is typed +// `floor_cost_debt_typed_admissions` membership (live-conditioned) OR long home. String roster ALONE never declares here (review 65637). Long // home declares regardless of a string-roster line: the home is the file's location, and an // append cannot subtract a structural declaration. // -// RE-CONVERGENCE TRIGGER: when half two's typed attempts replace the string roster -- -// `floor_cost_debt_typed_admission_attempts` is non-empty and the string chunks are deleted -- +// RE-CONVERGENCE TRIGGER: when the typed admissions replace the string roster -- +// `floor_cost_debt_typed_admissions` carries every row and the string chunks are deleted -- // the two predicates collapse into one. Until then this is a narrower fork with a named // dissolution. fn enrolment_expensiveness_declaration( @@ -268,6 +264,59 @@ type EnrolmentMarginStanding = ground: EnrolmentExpensivenessGround reading: EnrolmentCostReading } + | EnrolmentRosterGroundStale { witness_identity: String, observed_cpu_ms: Millisecond, line_ms: Millisecond } + +// THE ROSTER GROUND IS LIVE-CONDITIONED (gunbc#11622 review 68363). A typed cost-debt row carries +// an identity and a reason, never a reading, so the only cost that can justify it is THIS run's: +// it stays declared only while the live observed CPU is strictly above the per-subject line, and +// at or under the line it is stale and blocks, naming that the row must delete. Absence is handled +// in `enrolment_margin_standing`: a Roster identity with no cost row is EnrolmentNotMeasured, +// exactly as an undeclared planned identity is, or the declaration would buy an exemption from +// being measured at all. LongHome is unchanged -- reported, never decided -- which is the declared +// drop `gunbc.rung_drop` `long_home_enrolment_margin_observed_only`. A lower bound (with or +// without a ceiling) establishes expensiveness only if the bound ITSELF is above the line; a bound +// at or under it proves nothing, so on the Roster ground it blocks under the same bound or censored +// arm an undeclared identity would get, whose remedy is to produce a reading that decides. +fn enrolment_declared_measured_standing( + witness_identity: String, + ground: EnrolmentExpensivenessGround, + reading: ClaimCostReading, + per_subject_line_ms: Millisecond, +) -> EnrolmentMarginStanding { + let declared = EnrolmentExpensivenessDeclared { + witness_identity: witness_identity, + ground: ground, + reading: EnrolmentCostMeasured { reading: reading }, + } + match ground { + EnrolmentExpensivenessLongHome => declared + EnrolmentExpensivenessRoster => + match reading { + ObservedCpuReading { cpu_ms: c, eval_steps: _ } => + if millisecond_count(m: c) > millisecond_count(m: per_subject_line_ms) { + declared + } else { + EnrolmentRosterGroundStale { + witness_identity: witness_identity, + observed_cpu_ms: c, + line_ms: per_subject_line_ms, + } + } + CpuLowerBoundWithoutCeiling { cpu_lower_bound_ms: b, eval_steps_before_censor: _ } => + if millisecond_count(m: b) > millisecond_count(m: per_subject_line_ms) { + declared + } else { + EnrolmentBoundWithoutCeiling { cpu_lower_bound_ms: b } + } + RightCensoredCpuReading { cpu_lower_bound_ms: b, censoring_ceiling_ms: ceiling, eval_steps_before_censor: _ } => + if millisecond_count(m: b) > millisecond_count(m: per_subject_line_ms) { + declared + } else { + EnrolmentCeilingCensored { cpu_lower_bound_ms: b, censoring_ceiling_ms: ceiling } + } + } + } +} // A BOUND WITH NO CEILING IS NOT MEASURED, AND IS NOT A CENSORED READING EITHER. Since gunbc#11195 // the floor arms no CPU deadline, so a preempted row's CPU is a lower bound that nothing on this @@ -299,6 +348,7 @@ type EnrolmentMarginStanding = fn enrolment_margin_standing( reading: EnrolmentCostReading, budget_ms: Millisecond, + per_subject_line_ms: Millisecond, declaration: EnrolmentExpensivenessDeclaration, ) -> EnrolmentMarginStanding { match reading { @@ -307,10 +357,14 @@ fn enrolment_margin_standing( EnrolmentCostAbsent { witness_identity: i, cause: k } => match declaration { EnrolmentExpensivenessIsDeclared { witness_identity: id, ground: g } => - EnrolmentExpensivenessDeclared { - witness_identity: id, - ground: g, - reading: EnrolmentCostAbsent { witness_identity: i, cause: k }, + match g { + EnrolmentExpensivenessRoster => EnrolmentNotMeasured { witness_identity: i, cause: k } + EnrolmentExpensivenessLongHome => + EnrolmentExpensivenessDeclared { + witness_identity: id, + ground: g, + reading: EnrolmentCostAbsent { witness_identity: i, cause: k }, + } } EnrolmentExpensivenessNotDeclared => EnrolmentNotMeasured { witness_identity: i, cause: k } @@ -318,11 +372,12 @@ fn enrolment_margin_standing( EnrolmentCostMeasured { reading: r } => match declaration { EnrolmentExpensivenessIsDeclared { witness_identity: id, ground: g } => - EnrolmentExpensivenessDeclared { + enrolment_declared_measured_standing( witness_identity: id, ground: g, - reading: EnrolmentCostMeasured { reading: r }, - } + reading: r, + per_subject_line_ms: per_subject_line_ms, + ) EnrolmentExpensivenessNotDeclared => match r { ObservedCpuReading { cpu_ms: c, eval_steps: _ } => @@ -364,6 +419,7 @@ fn enrolment_margin_standing_blocks(standing: EnrolmentMarginStanding) -> Bool { EnrolmentNotMeasured { witness_identity: _, cause: _ } => true EnrolmentOutsideThisRunsExecution { witness_identity: _, disposition: _ } => false EnrolmentExpensivenessDeclared { witness_identity: _, ground: _, reading: _ } => false + EnrolmentRosterGroundStale { witness_identity: _, observed_cpu_ms: _, line_ms: _ } => true } } @@ -391,6 +447,7 @@ fn enrolment_margin_blocking_cause(standing: EnrolmentMarginStanding) -> String EnrolmentNotMeasured { witness_identity: _, cause: _ } => "enrolment_not_measured" EnrolmentOutsideThisRunsExecution { witness_identity: _, disposition: _ } => "" EnrolmentExpensivenessDeclared { witness_identity: _, ground: _, reading: _ } => "" + EnrolmentRosterGroundStale { witness_identity: _, observed_cpu_ms: _, line_ms: _ } => "enrolment_roster_ground_stale" } } @@ -406,6 +463,7 @@ fn enrolment_margin_standing_name(standing: EnrolmentMarginStanding) -> String { EnrolmentNotMeasured { witness_identity: _, cause: _ } => "not_measured" EnrolmentOutsideThisRunsExecution { witness_identity: _, disposition: _ } => "outside_this_runs_execution" EnrolmentExpensivenessDeclared { witness_identity: _, ground: _, reading: _ } => "expensiveness_declared" + EnrolmentRosterGroundStale { witness_identity: _, observed_cpu_ms: _, line_ms: _ } => "roster_ground_stale" } } @@ -429,6 +487,8 @@ fn enrolment_unpaired_pairing_hole(standing: EnrolmentMarginStanding) -> Enrolme EnrolmentPairingHoleOutsideExecution EnrolmentExpensivenessDeclared { witness_identity: _, ground: _, reading: _ } => EnrolmentPairingHoleDeclared + EnrolmentRosterGroundStale { witness_identity: _, observed_cpu_ms: _, line_ms: _ } => + EnrolmentPairingHoleNone } } From 454c4d77fce34a59c2d8e729360b974c97142e51 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sat, 19 Sep 2026 11:28:51 +0000 Subject: [PATCH 2/2] Spell the admitting Roster arms; cut the drop and plan prose over to the live ground. Review 68380: the seed's Roster match ended in a wildcard that defaulted any new reading shape to admit; the admitting arms are now spelled, matching the exhaustive .dag mirror. floor_cost_claim_qualification_unavailable (and its docs projection) and the eval-step denomination plan still named cost-debt admission as a CPU-line consumer; that comparison is gone, and they now name the live Roster ground in floor_enrolment_margin. Co-Authored-By: Claude Opus 5 (1M context) --- .../floor_cost_claim_qualification_unavailable.dag | 2 +- docs/design-rung-drops.md | 2 +- .../enrolment-margin-eval-step-denomination.md | 14 +++++++++----- src/v1/stage0/src/cli_run/required_floor_runner.rs | 5 ++++- 4 files changed, 15 insertions(+), 8 deletions(-) diff --git a/dag/gunbc/rung_drop/floor_cost_claim_qualification_unavailable.dag b/dag/gunbc/rung_drop/floor_cost_claim_qualification_unavailable.dag index 205868477a4..39da0b7e2b6 100644 --- a/dag/gunbc/rung_drop/floor_cost_claim_qualification_unavailable.dag +++ b/dag/gunbc/rung_drop/floor_cost_claim_qualification_unavailable.dag @@ -12,5 +12,5 @@ data floor_cost_claim_qualification_unavailable: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: FloorCostClaimQualificationUnavailable, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. the 500ms CPU line this row was declared over (now `required_floor_per_subject_cpu_line_ms`, which is still CPU milliseconds and still compared to a CPU reading by the enrolment margin and by cost-debt admission; the claim ceiling's own 500 moved to `required_floor_claim_work_envelope_ms`, a policy in milliseconds of work that no clock is compared to) was a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 219ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR, and a floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. RE-DERIVED 2026-09-03, BY THAT CONDITION AND BY NOTHING ELSE. The floor was 1.777 from a single identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed -- which is ONE PAIR, and one pair is one sample of a between-run quantity and therefore has no spread at all. A LARGER FLOOR IS NOW MEASURED OVER A SAMPLE THAT INDEXES OVER RUNS: 2.280, the worst per-identity max-over-min across TWELVE green `main` runs of `witnesses.yml` on twelve distinct runner registrations across three hosts, restricted to identities present in every run with a verdict, a baseline at or above 50 cpu-ms, and equal `eval_steps` in all twelve. THAT LAST RESTRICTION IS A FILTER AND NOT A FINDING, and the distinction matters here more than anywhere because MISSING ITEM (b) BELOW MEASURED THE SAME COLUMN AND REFUTED ITS INVARIANCE: selecting rows whose steps agree removes tree movement from the sample so the residual is inflation, and it establishes nothing about whether steps are invariant in general -- they are not. 500 over 2.280 floors to the constant above. THE PRODUCER IS NAMED AND THE DIGITS ARE NOT THE AUTHORITY: `gunbc.floor_cost_distribution` `worst_envelope_permille` over `work_invariant_envelopes` of `complete_envelopes`, driven by `tools.floor_cost_distribution_instrument` `floor_cost_envelope_report`, whose sampled runs and their runners are data in `floor_cost_envelope_sampled_runs`. This is the modeled producer the paragraph below says does not exist for the SUBSET; it exists for the CONSTANT'S INPUT and not for the subset, and those are different gaps. ROBUST IN DIRECTION AND NOT ONLY IN VALUE: restricting the same derivation to rows at or above 200 cpu-ms, where whole-millisecond quantisation cannot dominate, gives 1.874 and a constant of 266ms -- still below the superseded 280, so the re-derivation does not rest on the small-baseline tail. STILL A FLOOR: twelve runs on three hosts are a SUBSET of the admitted execution envelopes, so 2.280 can only rise and this constant can only fall. AND THE EXTREMES ARE CONCENTRATED ON PARTICULAR MACHINES, which a median run factor cannot see because a median is robust exactly where the envelope is driven: `run_extreme_census` over the same population reports one run holding the MINIMUM for 367 of 398 rows and one host holding the MAXIMUM for 279 of 398 from three of twelve runs, while per-run median factors span only 0.878 to 1.118. That is this row's own subject measured at host grain. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN, AT THE SUPERSEDED 280ms CONSTANT AND NOT AT THE ONE ABOVE -- the enumeration is kept as the receipt of what was measured and must not be read as today's subset, which is larger at a lower constant (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. That histogram is that run's, at the superseded constant; on the twelve-run sample above, taking each identity's MAX over the twelve, 88 identities reach 280 and 158 reach the constant now standing, and the same doubling holds within a single run rather than only in the union (run 33754393519: 61 then 115; run 33775106554: 73 then 128; run 33766436293: 20 then 72). Lowering the constant roughly doubles the subset, which is the cost of the re-derivation stated rather than left for a reader to discover. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED BY CONSTRUCTION across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE PER-CLAIM MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. THE QUALIFIER IS LOAD-BEARING AND WAS ADDED BY RULING (fierce-lark-661, 2026-09-13, on gunbc#11195) BECAUSE THE UNQUALIFIED SENTENCE FORBADE MORE THAN ITS EVIDENCE SUPPORTS -- DESIGN section 4d's over-prohibition arm, whose cost is the thing nobody does. WHAT IS FORBIDDEN is deriving a claim's budget from the population's own CPU readings: that is the run-varying, position-sensitive quantity, and a budget consuming it inherits the defect AND makes a verdict vary between runs. WHAT IS ADMITTED is a SINGLE CONTROLLED READING pinned as a POLICY CONSTANT -- `v2.workflow.floor_eval_step_calibration` -- taken on a fixture whose work is fixed by source rather than by the corpus. The discriminator is not the unit but the DEPENDENCE: an error in a pinned constant mis-scales BOTH tiers ONCE and UNIFORMLY and cannot make one claim's verdict differ between two runs of the same tree, which is precisely the property the denominator change buys and precisely what the per-claim distribution cannot offer. A RE-PIN RESCALES EVERY BUDGET UNIFORMLY AND NEVER ONE CLAIM, so it is a policy act taken deliberately and never maintenance. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. RECEIPT, 2026-09-03, gunbc#10192: ONE EPISODE BY RUN ID -- ADMITTED IN PART AND NOT END TO END, WHICH THE ENUMERATION BELOW ADJUDICATES RATHER THAN SMOOTHS -- AND THE FIRST CORPUS-GRAIN MEASUREMENT OF MISSING ITEM (b) -- WHICH IT REFUTES RATHER THAN DISCHARGES. THE EPISODE, run 33716314510 on head b65a0eb5b32, ENUMERATED IN FULL INCLUDING THE ATTEMPTS THAT DO NOT QUALIFY, because the sequence contains a transition this row does NOT authorize and an enumeration that showed only the eligible attempts would present an unadmitted retry as part of an admitted mitigation. ATTEMPT 1 EXECUTED ZERO JOBS -- no required-witnesses-floor job exists for it; the run was created awaiting workflow approval -- so it is not an attempt of this class and counting it as one would inflate the denominator. ATTEMPT 2, job 100543957851: claims_failed=33 with BOTH cost arms at zero. OUTSIDE this row's domain: zero dispositions in either cost arm. THE CAUSE OF THOSE 33 IS NOT ESTABLISHED HERE AND AN EARLIER DRAFT CALLED THEM SEMANTIC, WHICH THE COUNTERS DO NOT SUPPORT -- claims_failed enumerates ordinary claim-failure dispositions and does not say why they failed, and a missing host capability surfacing as a runtime error would land in the same counter as a genuine false assertion. The honest reading is an ORDINARY CLAIM-FAILURE FLOOR REFUSAL, CAUSE UNESTABLISHED. ITS ROLE HERE IS A NEGATIVE ELIGIBILITY CONTROL AND NOT A DENOMINATOR MEMBER, which corrects the reason an earlier draft gave for including it: a mitigation's eligible population is the attempts satisfying its admission predicate, so an attempt outside the class can no more count as a failed use of the mitigation than an ordinary compile error can. It is kept because it PROVES THE PREDICATE EXCLUDES SOMETHING REAL. AND THE TRANSITION OUT OF IT IS UNADJUDICATED, WHICH THIS ROW RECORDS RATHER THAN LAUNDERS: outside this row's budget means attempt 2 SPENT no reroll; it does not mean attempt 2 EARNED one. The re-run that produced attempt 3 was NOT admitted by this row -- attempt 2's refusal was carried by neither cost arm -- and no other authority is named for it. So this sequence is not one admitted mitigation end to end: it is an unadmitted retry of an ordinary red on byte-identical executed input, followed by a cost-only refusal that this row does admit, followed by its one reroll. A clean attempt 4 does not retroactively discharge attempt 2, and with attempt 2's identity artifact absent it cannot even be shown that all 33 failures were offered again. ATTEMPT 3, job 100573179841: presents as the two-arm shape this row admits, AND THE ADJUDICATING SURFACE IS ENROLLED HERE RATHER THAN ASSUMED: the run reports phases_run=3 with phases_failed=1, the ONLY FAILED PHASE being the floor, and unexpected_failures=0 -- the external phase verdict this row names as the current eligibility surface, and what establishes that no other phase failed. Beneath it the cost arms are completed_over_cost_requirement=1 and interrupted_before_verdict=1 all cpu_deadline, one row each. An earlier revision removed the internal proof without putting the external one in its place, leaving a correct qualification unsupported by the very surface this row says must adjudicate it. THE `failed=0` SPELLING IS NOT THE ELIGIBILITY KEY AND IS NOT RESTATED AS ONE HERE, because this row already ruled that test defective: it is read off the floor's own COST disposition counters, which do not range over other phases and so could only ever confirm themselves. The current surface is the RUN'S PHASE VERDICT -- phases_run, failed, and FAILED PHASE lines -- and the counters below are receipt, not the test. The completed-past-limit row is v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order at cpu_ms=515, an EXACT measurement against the 500 line; the interrupted row is its SIBLING IN THE SAME MODULE, produced_decl_two_targets_render_own_order, whose printed 509 is the BUDGET and not a measurement. ATTEMPT 4, job 100606296727: the consumed reroll, clean, failed=0 and both arms zero. A LATER AND DIFFERENT TREE, head 2b9e59206af (run 33746447180, job 100619903740), ran clean with MORE claims (executed 3519 rising to 3539) and spent no reroll -- consistent with this row's redraw reading and NOT evidence for it, since one clean draw discriminates nothing. MISSING ITEM (b) IS NOW MEASURED AND IS REFUTED. (b) asked for an identity join of eval_steps across two attempts of ONE IDENTICAL TREE where the cpu column moves and this one must not. Attempts 3 and 4 are exactly that pair, and the artifacts are required-floor-claim-cost 9885042655 and 9889079822, both executed=3519, the identity join TOTAL at 3519 with zero rows on either side alone. cpu_ms disagrees on 1394 of 3519 rows, max absolute delta 128ms. eval_steps disagrees on 18 of 3519. So the step measure reproduces exactly on 99.49 percent of the corpus against cpu's 60.4 percent -- FAR more stable, AND NOT INVARIANT, and (b) asked for invariance. THE JOB LOG SAYS THE OPPOSITE, AND THAT IS THE TRAP THIS PARAGRAPH EXISTS TO CLOSE: in the printed over-cost list every identity carries an identical eval_steps across all four runs while cpu swings by a third, so (b) reads as satisfied from the log alone. It is not. That list is ranked BY COST and truncated at 25, and 17 of the 18 disagreeing rows are too cheap to appear in it. A SUBSET SELECTED BY THE VARIABLE YOU ARE NOT TESTING CANNOT TEST THE ONE YOU ARE -- the same defect this row already records for the attention subset, reappearing on the new column, and the reason (b) must be joined on the uploaded artifact and never on the run's printed summary. WHAT THE 18 ARE, AND THEY ARE TWO DIFFERENT CLASSES RATHER THAN ONE POPULATION. SEVENTEEN ARE PASS/PASS with tiny deltas -- 3 to 161 steps, absolute relative difference at most 0.43 percent -- and they are CLUSTERED, NOT UNIFORM: sixteen of the seventeen sit in three modules, v2.test.claim.rust_crate_partition_witness (6), v2.test.claim.c_compilation_unit_witness (5) and v2.test.claim.compilation_unit_witness (5), one partition-and-unit witness family, with a single stray in v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract -- out of 3519 claims spanning the corpus. So MODULE-CLUSTERED VARIANCE EXISTS IN THIS A/B. That is the measurement; it does NOT establish the source, and an earlier revision called it a nondeterminism SOURCE, asserting as fact the conjecture the paragraph below correctly labels as one. IT IS EVIDENCE ABOUT THE STEP COUNT AND NOT ABOUT THE REFUSAL POPULATION, and conflating those is the error this row has already had to retract once: it establishes that module-clustered variance EXISTS in the corpus, which is the mechanism a module-clustered redraw would require, and it does not establish that the refused set redraws by module. THE EIGHTEENTH IS A DIFFERENT CLASS AND BEARS DIRECTLY ON MISSING ITEM (a). produced_decl_two_targets_render_own_order carries 196608 steps in the attempt where it was budget_interrupted and 197227 where it passed, so AN INTERRUPTED CLAIM'S eval_steps IS A PARTIAL COUNT AT THE STOP, not the claim's work -- the exact twin, in the step domain, of the already-recorded fact that an interrupted row's printed ms is the budget rather than a measurement. 196608 is 3 times 2 to the 16th exactly, which is suggestive of a step-interval deadline check; that is n=1 and the mechanism is NOT asserted here. THE CONSEQUENCE FOR (a) IS CONCRETE AND IS WHY THIS IS RECORDED BESIDE IT: a step-denominated line would compare against this partial for precisely the rows it exists to judge, so (a) needs a rule for the non-terminal row BEFORE it needs a number. NET EFFECT ON THE TRIGGER, STATED PER ARM BECAUSE (ii) IS A DISJUNCTION: the conjunct reads INVARIANT OR BOUNDED BY CONSTRUCTION and only the first arm has been tested. EXACT-INVARIANCE ARM: measured and REFUTED. BOUNDEDNESS ARM: UNESTABLISHED -- the 556-identity distribution below calls itself a spread and not a bound, reinforcing the distinction rather than resolving it. WHOLE CONJUNCT: REMAINS UNSATISFIED. An earlier revision wrote that (ii) moves to MEASURED AND FAILING, which is too broad for a disjunction whose second arm is untested: unsatisfied and both-alternatives-measured-and-failing are different findings. The trigger is a conjunction of three and (i) and (iii) are untouched, so nothing here retires this row and nothing here proposes raising the ceiling. RE-DERIVE with gh run download rather than by piping the artifact zip through a shell: gh api .../artifacts/ID/zip redirected to a file, and curl -o on the redirect target, BOTH corrupt the bytes in this environment -- a malformed local header and roughly 380 bytes short -- so an auditor who reaches for the obvious command gets an unreadable archive and may conclude the artifacts are gone. Taking the Location header and fetching it UNAUTHENTICATED also works; forwarding the Authorization header to blob storage returns 401. ONE FURTHER MEASUREMENT FROM THE SAME EPISODE, AND IT BEARS ON THIS ROW'S OWN REROLL SIGNATURE RATHER THAN ON ITS COST ARMS: THE PLANNED POPULATION IS NOT A FUNCTION OF THE TREE. On the single head b65a0eb5b32, the three attempts carrying a floor job report planned=executed=3534 (attempt 2, 33 claims failed), 3519 (attempt 3) and 3519 (attempt 4) -- fifteen claims of difference across attempts of ONE head with no change to the source. NO CAUSE IS ASSERTED HERE AND THE OBVIOUS ONE IS NOT VERIFIED: if the plan is computed relative to a moving main rather than to the head under test, this is expected rather than anomalous, and that is the first thing to check before treating it as a defect. WHAT IT DOES ESTABLISH REGARDLESS OF CAUSE is that EXACT HEAD DOES NOT BY ITSELF FIX THE POPULATION A REROLL IS DRAWN FROM, so a changed planned COUNT is RECEIPT AND COMPARABILITY DETAIL, and a potential planning or coverage defect, and NEVER a fresh reroll allowance. An earlier draft left that open as though it were undecided; it was already decided earlier in this same row, and leaving it open invited the budget reading it forbids. IT DOES NOT CONTAMINATE THE (b) JOIN ABOVE: attempts 3 and 4 both planned 3519 and their identity join is total at 3519 with zero rows on either side alone, which is why that measurement stands independently of this one. AND IT CORRECTS A CHARACTERISATION THAT WAS OFFERED FOR ATTEMPT 2 AND IS FALSE: that attempt was not a toolchain or host-tool incident -- its own summary reports host_tool_unresolved=0 beside claims_failed=33, so it is an ordinary red floor and belongs to no runner-incident population. The disposition is unchanged either way, since both cost arms are zero, so THE COST-ARM ADMISSION PREDICATE DOES NOT HOLD -- stated that way because there is no failed=0 precondition to fail, that key having been retired earlier in this same row, and an earlier revision resurrected it here after removing it one paragraph away, but the ground for excluding it from the mitigation is the cost-arm test and NOT a tooling attribution. THE CAUSE NAMED AS LIKELY IN THE PARAGRAPH ABOVE IS NOW CHECKED AND REFUTED, WHICH IS WHY THAT PARAGRAPH SAID TO CHECK IT FIRST. The suggestion was that the plan might be computed relative to a moving main rather than to the head under test, which would make the differing planned counts expected. IT IS NOT THAT. GitHub Actions evaluates a SYNTHETIC MERGE rather than the branch head, and all three attempts checked out THE SAME SYNTHETIC MERGE COMMIT -- each job log carries the identical line naming the merge of b65a0eb5b32 into 3547b3f9028 at one merge SHA -- so the three attempts ran a BYTE-IDENTICAL TREE and the main they were merged against did not move between them. The planned population therefore varies across attempts of a genuinely fixed tree. THE COUNTERS THAT DO NOT VARY NARROW IT FURTHER, and they are the ones a reader would reach for first: known_red_held, route_gap_held and stale_quarantine are IDENTICAL across all three attempts, so this is not a roster, quarantine or route-gap difference selecting a different population. Only planned, executed and terminal move, together, by fifteen. WHAT CANNOT BE SAID, AND THE REASON IS an artifact gap rather than a judgement: WHICH fifteen identities differ is NOT recoverable, because the attempt that planned 3534 uploaded no per-claim cost artifact -- only the two 3519-attempts did -- so the finding is available at COUNT grain and not at IDENTITY grain, which is precisely the weaker form this row elsewhere refuses to accept as a population. It is recorded as a count because that is what was measured. ONE CONJECTURE, LABELLED AS ONE AND CARRYING ITS OWN TEST RATHER THAN A CONCLUSION: the same unpinned iteration order that would explain the module-clustered eval_steps variance recorded above -- sixteen of seventeen disagreements inside one partition-and-unit witness family, which is exactly the shape of a fold over a set with no declared order -- could also change how many claims a generator emits, giving both observations ONE root. NOTHING HERE ESTABLISHES THAT, and the discriminating test is named so the next lane does not have to invent it: recover the fifteen identities by having the planner emit its plan as an artifact on every attempt including a failing one, then join two attempts of one synthetic merge at IDENTITY grain and ask whether the differing rows are generated claims from the same witness families that carry the step variance. Until that artifact exists the two observations are adjacent and unjoined. THE CONSEQUENCE FOR THIS ROW'S REROLL RULE IS UNCHANGED BY THE REFUTATION AND IS STRENGTHENED BY IT: exact head does not fix the drawn population, and it is now known that no appeal to a moving base explains it away. AND IT DOES NOT EXPAND THE REROLL ALLOWANCE, WHICH IS THE READING IT MOST INVITES AND THE ONE THIS SENTENCE EXISTS TO REFUSE: a differing planned cardinality WEAKENS COMPARABILITY between two attempts and lowers confidence that they covered the same claims; it does not license a second draw. The allowance stays at ONE PER EXACT HEAD, consumed on actuation. IT IS NOT PER SIGNATURE, AND SAYING SO WOULD REINTRODUCE A SPELLING THIS ROW ALREADY REFUTED: the signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget key. This finding makes exact head insufficient as a COMPARABILITY IDENTITY; it leaves exact head intact as the deliberately coarse BUDGET KEY, and letting a changed population mint a fresh signature would recreate retry-until-green exactly when the roster becomes unstable. An attempt that falls outside this row's domain spends nothing AND EARNS NOTHING -- it is not a free retry, and treating an ineligible red as though it restored the budget would be retry-until-green reached by a different route than the one this row already forbids. RECEIPT, 2026-09-03, gunbc#10231 -- THE SHARPEST INSTANCE THIS ROW CARRIES, BECAUSE THE VERDICT FLIPPED WHILE THE WORK MEASURE DID NOT MOVE BY ONE STEP. THE SUBJECT MAKES THE POINT BEFORE THE NUMBERS DO: it is a LEDGER-ONLY PROSE PR -- the filing of this row's sibling mechanism class -- touching one authority row and its generated projection, with no code, no types and no gates. A DIFF CATEGORY DOES NOT GRANT COST INNOCENCE BY CONSTRUCTION, and an earlier revision claimed it did: the ledger is ACCEPTED .dag SOURCE here, so altering a large literal can move parsing, resolution, allocation, generated structure or closure work, and shape is not an argument about cost. THE NARROWER CONTROL IS SUFFICIENT AND IS WHAT IS CLAIMED: the diff was IDENTICAL ACROSS BOTH ATTEMPTS, so whatever it costs relative to its base, it cannot explain the attempt-to-attempt flip. Run 33756177727 attempt 1, floor job 100651027559: REFUSED with completed_over_cost_requirement=1 beside claims_failed=0, interrupted_before_verdict=0 and host_tool_unresolved=0 -- one row, wholly inside this row's admitted domain on the two-arm test, with the run's phase verdict carrying no other failed phase. One reroll was actuated and thereby CONSUMED, against a budget of ONE PER EXACT HEAD. Attempt 2, job 100663093895: PASS. THE DISCRIMINATING PAIR, and it is one identity rather than an aggregate: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates measured cpu_ms=523 on the refusing attempt and cpu_ms=404 on the passing one -- a ratio of 1.294 across the 500 line -- WHILE ITS eval_steps IS IDENTICAL AT 169297 ON BOTH. Same head, same tree, same identity, same count of evaluator steps, opposite verdicts. WHAT THAT SUPPORTS, AT THE INSTRUMENT'S REACH AND NOT BEYOND IT: for one fixed identity on one fixed head the cpu-line verdict flipped while the recorded net evaluator-step count stayed exactly identical, so THE CPU VERDICT IS NOT DETERMINED BY eval_steps ALONE -- stronger than showing cpu varies more often than steps, because it exhibits the mismatch at the very identity whose verdict changed. WHAT IT DOES NOT SUPPORT, and an earlier revision asserted it: that the deciding component lies OUTSIDE THE CLAIM'S WORK. Identical eval_steps establishes identical COUNTED EVALUATOR ENTRIES AFTER THIS INSTRUMENT'S NETTING RULE, not identical claim work -- host work, closure work, attribution and cache behaviour are uncounted and remain possible. This row keeps CHARGE-SUBJECT ALIGNMENT open as conjunct (i), so it cannot use this pair to place the varying component outside the claim; that would discharge (i) by assertion. THIS DOES NOT CONTRADICT THE (b) REFUTATION RECORDED ABOVE, and the reconciliation matters because the two readings look opposed: (b) failed because 18 identities of 3519 disagree on eval_steps, NOT because the measure is generally unstable -- 3501 reproduce exactly, and this identity is one of them. A measure can be exact on a given row and still fail an invariance claim asserted over a corpus. A THIRD SAMPLE OF THE SAME IDENTITY EXISTS ON GREEN MAIN, CITED BY RUN AND JOB SO IT IS RE-DERIVABLE RATHER THAN RELAYED: run 33754393519, floor job 100645180812, event push on main head 75873c28978, reports this identity at cpu_ms=406 with eval_steps=169297 -- the SAME step count as both attempts of the episode above, at a third distinct cpu. AND THE ORDERING IS WEAKER THAN AN EARLIER REVISION OF THIS PARAGRAPH CLAIMED, WHICH IS WHY THE CARRIER WAS WORTH DEMANDING. That revision said the identity had been NAMED IN ADVANCE and that a lane had PUBLISHED the crossing arithmetic before the refusal, which made it a prediction. The job timestamps refute that framing: the green-main job ran 12:17:45Z to 12:45:05Z and the refusing attempt ran 12:40:20Z to 13:10:22Z, so THE TWO RUNS OVERLAPPED. The green-main value was therefore observable 25 minutes before the refusal was observed, and it is CORROBORATION AT A THIRD SAMPLE rather than a prediction made before the event. The advance-prediction claim is withdrawn; it was received by relay and no carrier for the publication event was ever produced, which is exactly the transcribed-number failure DESIGN section 6 forbids -- name the producer, never copy its output. A prediction that names the row before it refuses a PR is worth more than a fresh observation of the same event. INDEPENDENT REPLICATION OF THE SPREAD, derived from the per-claim cost artifacts of THIS row's other episode rather than from the reporting lane's run, and it is an INDEPENDENT RUN AND ARTIFACT SAMPLE rather than an independent instrument -- an earlier revision said the two share NO instrument, which is false: they share the required-floor cpu producer, its accounting semantics, the evaluator-step counter and the artifact schema. What they do not share is a run or an artifact, and that is the whole of the independence claimed: over the 556 identities measuring at least 50 cpu-ms in BOTH attempts of one identical tree, the attempt-to-attempt cpu ratio -- DEFINED PER JOINED IDENTITY AS max(cpu_A, cpu_B) / min(cpu_A, cpu_B), so it is direction-free and never below 1.0, stated because an earlier revision published percentiles without the formula and B/A would give materially different numbers -- has median 1.045, p10 1.005, p90 1.219 and MAXIMUM 1.721. THE MEDIAN IS THE UNINTERESTING NUMBER AND THE TAIL IS THE ONE THAT DECIDES VERDICTS -- a corpus whose typical row moves by 4 percent still puts four identities at 94 to 103 percent of budget on a tree that PASSED. WHAT NONE OF THIS ESTABLISHES, stated because this row's trigger asks for exactly the thing it falls short of: A BOUND. Two attempts give a SPREAD, and (ii) requires the basis to be invariant OR BOUNDED BY CONSTRUCTION across the admitted envelopes; a maximum of 1.721 observed over one pair of attempts on one host pair is a FLOOR on the spread, not a bound on it, and the admitted envelope set is wider than the hosts these pairs sampled. THE CONSEQUENCE ON MAIN, MEASURED AT VERDICT GRAIN RATHER THAN AT ROW GRAIN (2026-09-03), because everything above measures ROWS and the thing that costs the fleet its afternoon is the VERDICT. Of the twenty-five most recent `witnesses.yml` runs on `main`, five reported `verdict=FloorRefused` with `claims_failed=0` and `unexpected_failures=0` -- the whole refusal carried by `interrupted_cpu_deadline` and `completed_over_cost_requirement`, so the required floor refused main five times without a single claim disagreeing with the tree. A GATE THAT REFUSES FOR REASONS UNRELATED TO THE CHANGE TEACHES ITS READERS THAT A RED REQUIRED FLOOR IS NOISE, and that is the cost this row had not priced: the sections above price the mis-attribution of a NUMBER to a row, and this one prices the mis-attribution of a VERDICT to a tree. AND THE HOST CORRELATION, STATED AT THE WIDTH THE SAMPLE SUPPORTS AND NOT WIDER. THE DECISIVE MEASUREMENT IS NOT THE HOST TABLE, IT IS A SAME-HEAD CONTROL, and it is stated first because it is established BY CONSTRUCTION rather than by correlation. Run 33806159353 was re-run at the same head: attempt 1 recorded `required-witnesses-floor` FAILURE on runner srv4-14 and attempt 2 recorded SUCCESS on runner srv4-19, both at head 07f81df887a, unchanged between them. ONE TREE, TWO ATTEMPTS, OPPOSITE VERDICTS. Nothing about the subject differed, so the required floor's verdict is demonstrably NOT A PROPERTY OF THE TREE -- which is this row's whole subject, now shown rather than inferred, and shown without needing any closure argument because nothing changed. THE HOST TABLE IS THE WEAKER EVIDENCE AND ITS FAMILY-SHAPED READINGS ARE REFUTED, twice, in the same direction. Eleven `required-witnesses-floor` jobs by runner registration: seven failed (srv1-02, srv1-07, srv1-10, srv1-16, srv1-17, srv4-11, srv4-14) and four passed (srv3-02, srv3-04, srv3-10, srv4-19). A first reading said srv1 is the bad host and srv4-11 refuted it; a second said srv3 is the only host observed clearing the ceiling and srv4-19 refuted that too, since srv4 now does BOTH. BOTH READINGS GENERALISED A HOST FAMILY FROM MACHINE-LEVEL SAMPLES AND THE NEXT SAMPLE CROSSED THE LINE EACH TIME, which is why the surviving statement names no family at all. WHAT THE MEASUREMENTS SUPPORT, AND NOTHING WIDER: the verdict is not a property of the tree; it is not cleanly a property of the host family; THE ACTUAL VARIABLE IS UNIDENTIFIED, with machine-level load or moment and a per-machine difference both consistent with the data, and eleven samples cannot separate them. Naming a cause here would be the looks-principled-and-is-not move this row already refuses on the calibration arm. MISSING ITEM (b) IS NOW DISCHARGED OVER THE MEASURABLE POPULATION AND THE ROW STILL STANDS, and the reason it still stands is the more useful half. THE JOIN (warm-seal-35, over the two attempts above): 338 shared-fill per-claim rows on each side, joined ON IDENTITY with ZERO unmatched rows in either direction, `marginal_eval_steps` and `measured_eval_steps` IDENTICAL for all 338, while measured cpu-ms moved by more than ten percent on 124 of them and spanned 0.627 to 1.217 as an attempt-2-over-attempt-1 ratio. That is (b) as worded -- an exact identity join of the step column across two attempts of ONE IDENTICAL TREE, with the cpu column moving and this one not -- and it is a population rather than a subject, which is what separates it from the single-claim reading above. ITS DENOMINATOR IS NOT THE FLOOR, AND QUOTING IT AS WHOLE-FLOOR COVERAGE WOULD BE THE ERROR THIS ROW EXISTS TO REFUSE: both attempts executed 3585 claims and the shared-fill instrument reports per-claim cost for 338 of them, so the join covers 9.4 percent and is silent about the rest. THE EXCLUSION IS THE FINDING, NOT A CAVEAT ON IT, AND IT IS SHARPER THAN THE CONSTRAINT PREDICTED ABOVE. An interrupted row is unmeasured in steps by construction, so the join can only cover completed rows -- and the rows it therefore excludes are EXACTLY THE ROWS THAT DECIDED THE VERDICT. Attempt 1 recorded passed=3507 with interrupted_before_verdict=2 and completed_over_cost_requirement=1 and refused; attempt 2 recorded passed=3510 with both counters at zero and was clean. 3507 plus 2 plus 1 is 3510: the three rows are precisely the difference between the two attempts, and they are precisely the rows no step measurement can speak about. THE MORE A CLAIM IS AFFECTED, THE LESS MEASURABLE IT BECOMES. So the join establishes that 338 OTHER claims did identical work under a moving envelope -- strong evidence about the envelope, and NO evidence about the three. WHICH IS A CONSTRAINT ON MISSING ITEM (a) AND NOT ONLY ON (b), and it is the first thing this row has been able to say about (a) at all: A STEP-DENOMINATED LINE BUILT ON THIS INSTRUMENT WOULD BE BLIND IN EXACTLY ITS OWN SUBJECT DIRECTION, because the rows that would cross such a line are the rows that carry no step count. Sizing one from the measurable population would produce a threshold that looks principled and is derived from the rows that were never at issue. EVIDENCE GRADES, KEPT SEPARATE AS EVERYWHERE ELSE IN THIS ROW. The two attempt summaries and their arithmetic were read FIRST-HAND from the run at two different times, attempt 1 while it was the only attempt and attempt 2 after the re-run; the 338-row join is taken from its builder with its own disclosed method corrections and was not re-derived here, because the attempt-1 log archive returns a truncated response that will not open. A CITATION TRAP WAS OBSERVED WHILE CHECKING THIS AND IS RECORDED SO THE NEXT READER DOES NOT LOSE AN HOUR TO IT: a bare job id serves the LATEST attempt, so job 100817014187 -- whose own conclusion is failure -- now serves attempt 2 FloorClean summary. An attempt-level citation is the only stable one. AND THE DISPOSITION GETS MORE DEFENSIBLE RATHER THAN LESS: a ceiling whose verdict flips on ONE UNCHANGED TREE between two attempts thirty-six minutes apart is not something a fifth shave of the claim would fix, which is the measured form of the argument that four prior lanes closed on the claim and it fired again. WHAT IS ESTABLISHED PER SAMPLE DIFFERS AND IS NOT FLATTENED: the `claims_failed=0` / `unexpected_failures=0` signature was read from the run logs for six of the seven failures, srv4-11 being the one taken on report rather than read. The distinction is kept because this carrier's own subject is a verdict being attributed to the wrong thing, and a floor job can redden on a phase that is not the floor -- so FAILED and FAILED-WITH-THIS-SIGNATURE are different facts and the row says which it has. A ONE-SUBJECT CROSS-ENVELOPE READING, WHICH BEARS ON MISSING ITEM (b) AND DOES NOT DISCHARGE IT (calm-deer-33, 2026-09-03, verified here rather than relayed). `v2.test.emit.rust_produced_decl_emit.produced_decl_unwired_target_still_refuses` measured 165802 eval_steps at 346 cpu-ms on run 33802603168 and 165802 eval_steps at 514 cpu-ms on run 33806159353 -- the step count IDENTICAL to the digit while cpu moved 1.49x, and the second reading is the one that crossed into completed-over-budget. Log-line controls of 3472 and 3465 rule out an empty capture on either side, which is this repository's standing guard against a zero that reads as a clean sweep. WHY IT IS NOT (b), ON THREE COUNTS, AND THE THIRD IS THE ONE A LATER READER WILL MISS. (i) GRAIN: (b) asks for a join AT CORPUS GRAIN and this is one subject. (ii) SUBJECT: (b) asks for TWO ATTEMPTS OF ONE IDENTICAL TREE, and these are two different trees -- 8b2323f is an ANCESTOR of 07f81df, so the pull request adds commits on top of the main commit it is compared against. (iii) THE WARRANT FOR THE-WORK-DID-NOT-CHANGE CANNOT COME FROM THE STEP COUNT ITSELF: constant steps are read as envelope-independence only if the work is identical on INDEPENDENT grounds, since a measure insensitive to the change produces the same reading. TWO ATTEMPTS OF ONE IDENTICAL TREE supplies that warrant BY CONSTRUCTION, which is why (b) is written that way. ACROSS TWO TREES IT WAS SUPPLIED SEPARATELY AND (iii) IS ANSWERED, by two arguments that do not depend on each other, both re-derived here rather than relayed. FIRST, A SYMBOL-GRAIN JOIN: the whole diff between the compared trees touches three files and adds or removes six declarations -- `absence_classifier_default_bucket`, `green_reported_over_a_population_the_instrument_does_not_own`, `live_03_normalize_data_inits`, `live_03_normalize_facts`, `live_argument_threaded_past_the_arm_that_decides` and `effect_reach_live_03_normalize_witness_derived_host_reading_holds` -- and the module declaring the measured claim, `v2.test.claim.emit.produced_decl_two_target_test`, references none of the six, with a positive control on the same grep finding `tt_emit`, `tt_emits` and `tt_refuses` there. SYMBOL GRAIN RATHER THAN IMPORT CLOSURE IS LOAD-BEARING IN THIS SUBSTRATE: names resolve by global uniqueness rather than by import lists, so a name absent from every import list still resolves and an import-closure argument would exclude modules that can still supply a binding. SECOND, AND INDEPENDENT OF WHETHER THAT JOIN IS EXHAUSTIVE: the diff is NET NEGATIVE, 32 insertions against 60 deletions, and the only witness change DELETES a row, so any corpus-scale work effect would push this claim CHEAPER while the observation is 1.49x MORE EXPENSIVE. The move is in the wrong direction for every work-based explanation. A CONSTRAINT ON HOW (b) CAN EVER BE DISCHARGED, WHICH IS A PROPERTY OF THE COLUMN AND NOT OF TONIGHT. An INTERRUPTED row is unmeasured in `eval_steps` BY CONSTRUCTION -- the poll fires before a count exists -- so a corpus-grain identity join over this column has a STRUCTURALLY EXCLUDED SUBPOPULATION, and the excluded rows are precisely the expensive ones the join most needs to cover. (b) as worded may therefore not be buildable at full coverage at all. A LATER LANE THAT BUILDS IT OVER COMPLETED ROWS AND REPORTS COVERAGE WILL BE REPORTING OVER A POPULATION IT DOES NOT OWN, which is `gunbc.recurring_failure_mode` `green_reported_over_a_population_the_instrument_does_not_own` -- so the honest discharge of (b) must either state the exclusion as part of its result or reach the interrupted rows by a different measure, and a coverage figure over completed rows alone does not retire this row. WHAT IT DOES ESTABLISH is still an advance on what this row had: the invariance reading was previously grounded at FIXTURE grain and nowhere wider, and this extends it to a live corpus subject under real floor pressure. Recorded as that and not as more. IT WAS MEASURED FORWARD, WHICH IS THE ONLY REASON IT IS RECORDED AT ALL: a prediction that srv1-10 would fail and srv3-10 would pass was registered before either returned, and runs 33794985110 and 33796487867 held it. WHAT IT IS NOT IS AN EXPLANATION. A SLOWER HOST is a hypothesis with no mechanism attached, three passes on one host is a thin denominator, and neither this correlation nor a wider one discharges (i), (ii) or (iii) of the trigger below -- a basis that varies with the machine is exactly what (ii) asks to be rid of, so measuring WHICH machines it varies with sharpens the subject and closes none of it. NOT PROPOSED HERE, AND THE DISTINCTION IS THE SAME ONE THIS ROW HAS MADE THROUGHOUT: raising the 500 line would change which rows cross and would not make the crossing a property of the claim, so it does not retire this row and is not requested." } + declaration: AuthoredProse { legacy: FloorCostClaimQualificationUnavailable, authored: "Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. the 500ms CPU line this row was declared over (now `required_floor_per_subject_cpu_line_ms`, which is still CPU milliseconds and still compared to a CPU reading by the enrolment margin, both as the ceiling its budget must sit below and as the line a live Roster (typed cost-debt) ground must clear, `v2.workflow.floor_enrolment_margin` `enrolment_declared_measured_standing`; the claim ceiling's own 500 moved to `required_floor_claim_work_envelope_ms`, a policy in milliseconds of work that no clock is compared to) was a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 219ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR, and a floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. RE-DERIVED 2026-09-03, BY THAT CONDITION AND BY NOTHING ELSE. The floor was 1.777 from a single identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed -- which is ONE PAIR, and one pair is one sample of a between-run quantity and therefore has no spread at all. A LARGER FLOOR IS NOW MEASURED OVER A SAMPLE THAT INDEXES OVER RUNS: 2.280, the worst per-identity max-over-min across TWELVE green `main` runs of `witnesses.yml` on twelve distinct runner registrations across three hosts, restricted to identities present in every run with a verdict, a baseline at or above 50 cpu-ms, and equal `eval_steps` in all twelve. THAT LAST RESTRICTION IS A FILTER AND NOT A FINDING, and the distinction matters here more than anywhere because MISSING ITEM (b) BELOW MEASURED THE SAME COLUMN AND REFUTED ITS INVARIANCE: selecting rows whose steps agree removes tree movement from the sample so the residual is inflation, and it establishes nothing about whether steps are invariant in general -- they are not. 500 over 2.280 floors to the constant above. THE PRODUCER IS NAMED AND THE DIGITS ARE NOT THE AUTHORITY: `gunbc.floor_cost_distribution` `worst_envelope_permille` over `work_invariant_envelopes` of `complete_envelopes`, driven by `tools.floor_cost_distribution_instrument` `floor_cost_envelope_report`, whose sampled runs and their runners are data in `floor_cost_envelope_sampled_runs`. This is the modeled producer the paragraph below says does not exist for the SUBSET; it exists for the CONSTANT'S INPUT and not for the subset, and those are different gaps. ROBUST IN DIRECTION AND NOT ONLY IN VALUE: restricting the same derivation to rows at or above 200 cpu-ms, where whole-millisecond quantisation cannot dominate, gives 1.874 and a constant of 266ms -- still below the superseded 280, so the re-derivation does not rest on the small-baseline tail. STILL A FLOOR: twelve runs on three hosts are a SUBSET of the admitted execution envelopes, so 2.280 can only rise and this constant can only fall. AND THE EXTREMES ARE CONCENTRATED ON PARTICULAR MACHINES, which a median run factor cannot see because a median is robust exactly where the envelope is driven: `run_extreme_census` over the same population reports one run holding the MINIMUM for 367 of 398 rows and one host holding the MAXIMUM for 279 of 398 from three of twelve runs, while per-run median factors span only 0.878 to 1.118. That is this row's own subject measured at host grain. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN, AT THE SUPERSEDED 280ms CONSTANT AND NOT AT THE ONE ABOVE -- the enumeration is kept as the receipt of what was measured and must not be read as today's subset, which is larger at a lower constant (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. That histogram is that run's, at the superseded constant; on the twelve-run sample above, taking each identity's MAX over the twelve, 88 identities reach 280 and 158 reach the constant now standing, and the same doubling holds within a single run rather than only in the union (run 33754393519: 61 then 115; run 33775106554: 73 then 128; run 33766436293: 20 then 72). Lowering the constant roughly doubles the subset, which is the cost of the re-derivation stated rather than left for a reader to discover. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED BY CONSTRUCTION across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE PER-CLAIM MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. THE QUALIFIER IS LOAD-BEARING AND WAS ADDED BY RULING (fierce-lark-661, 2026-09-13, on gunbc#11195) BECAUSE THE UNQUALIFIED SENTENCE FORBADE MORE THAN ITS EVIDENCE SUPPORTS -- DESIGN section 4d's over-prohibition arm, whose cost is the thing nobody does. WHAT IS FORBIDDEN is deriving a claim's budget from the population's own CPU readings: that is the run-varying, position-sensitive quantity, and a budget consuming it inherits the defect AND makes a verdict vary between runs. WHAT IS ADMITTED is a SINGLE CONTROLLED READING pinned as a POLICY CONSTANT -- `v2.workflow.floor_eval_step_calibration` -- taken on a fixture whose work is fixed by source rather than by the corpus. The discriminator is not the unit but the DEPENDENCE: an error in a pinned constant mis-scales BOTH tiers ONCE and UNIFORMLY and cannot make one claim's verdict differ between two runs of the same tree, which is precisely the property the denominator change buys and precisely what the per-claim distribution cannot offer. A RE-PIN RESCALES EVERY BUDGET UNIFORMLY AND NEVER ONE CLAIM, so it is a policy act taken deliberately and never maintenance. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. RECEIPT, 2026-09-03, gunbc#10192: ONE EPISODE BY RUN ID -- ADMITTED IN PART AND NOT END TO END, WHICH THE ENUMERATION BELOW ADJUDICATES RATHER THAN SMOOTHS -- AND THE FIRST CORPUS-GRAIN MEASUREMENT OF MISSING ITEM (b) -- WHICH IT REFUTES RATHER THAN DISCHARGES. THE EPISODE, run 33716314510 on head b65a0eb5b32, ENUMERATED IN FULL INCLUDING THE ATTEMPTS THAT DO NOT QUALIFY, because the sequence contains a transition this row does NOT authorize and an enumeration that showed only the eligible attempts would present an unadmitted retry as part of an admitted mitigation. ATTEMPT 1 EXECUTED ZERO JOBS -- no required-witnesses-floor job exists for it; the run was created awaiting workflow approval -- so it is not an attempt of this class and counting it as one would inflate the denominator. ATTEMPT 2, job 100543957851: claims_failed=33 with BOTH cost arms at zero. OUTSIDE this row's domain: zero dispositions in either cost arm. THE CAUSE OF THOSE 33 IS NOT ESTABLISHED HERE AND AN EARLIER DRAFT CALLED THEM SEMANTIC, WHICH THE COUNTERS DO NOT SUPPORT -- claims_failed enumerates ordinary claim-failure dispositions and does not say why they failed, and a missing host capability surfacing as a runtime error would land in the same counter as a genuine false assertion. The honest reading is an ORDINARY CLAIM-FAILURE FLOOR REFUSAL, CAUSE UNESTABLISHED. ITS ROLE HERE IS A NEGATIVE ELIGIBILITY CONTROL AND NOT A DENOMINATOR MEMBER, which corrects the reason an earlier draft gave for including it: a mitigation's eligible population is the attempts satisfying its admission predicate, so an attempt outside the class can no more count as a failed use of the mitigation than an ordinary compile error can. It is kept because it PROVES THE PREDICATE EXCLUDES SOMETHING REAL. AND THE TRANSITION OUT OF IT IS UNADJUDICATED, WHICH THIS ROW RECORDS RATHER THAN LAUNDERS: outside this row's budget means attempt 2 SPENT no reroll; it does not mean attempt 2 EARNED one. The re-run that produced attempt 3 was NOT admitted by this row -- attempt 2's refusal was carried by neither cost arm -- and no other authority is named for it. So this sequence is not one admitted mitigation end to end: it is an unadmitted retry of an ordinary red on byte-identical executed input, followed by a cost-only refusal that this row does admit, followed by its one reroll. A clean attempt 4 does not retroactively discharge attempt 2, and with attempt 2's identity artifact absent it cannot even be shown that all 33 failures were offered again. ATTEMPT 3, job 100573179841: presents as the two-arm shape this row admits, AND THE ADJUDICATING SURFACE IS ENROLLED HERE RATHER THAN ASSUMED: the run reports phases_run=3 with phases_failed=1, the ONLY FAILED PHASE being the floor, and unexpected_failures=0 -- the external phase verdict this row names as the current eligibility surface, and what establishes that no other phase failed. Beneath it the cost arms are completed_over_cost_requirement=1 and interrupted_before_verdict=1 all cpu_deadline, one row each. An earlier revision removed the internal proof without putting the external one in its place, leaving a correct qualification unsupported by the very surface this row says must adjudicate it. THE `failed=0` SPELLING IS NOT THE ELIGIBILITY KEY AND IS NOT RESTATED AS ONE HERE, because this row already ruled that test defective: it is read off the floor's own COST disposition counters, which do not range over other phases and so could only ever confirm themselves. The current surface is the RUN'S PHASE VERDICT -- phases_run, failed, and FAILED PHASE lines -- and the counters below are receipt, not the test. The completed-past-limit row is v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order at cpu_ms=515, an EXACT measurement against the 500 line; the interrupted row is its SIBLING IN THE SAME MODULE, produced_decl_two_targets_render_own_order, whose printed 509 is the BUDGET and not a measurement. ATTEMPT 4, job 100606296727: the consumed reroll, clean, failed=0 and both arms zero. A LATER AND DIFFERENT TREE, head 2b9e59206af (run 33746447180, job 100619903740), ran clean with MORE claims (executed 3519 rising to 3539) and spent no reroll -- consistent with this row's redraw reading and NOT evidence for it, since one clean draw discriminates nothing. MISSING ITEM (b) IS NOW MEASURED AND IS REFUTED. (b) asked for an identity join of eval_steps across two attempts of ONE IDENTICAL TREE where the cpu column moves and this one must not. Attempts 3 and 4 are exactly that pair, and the artifacts are required-floor-claim-cost 9885042655 and 9889079822, both executed=3519, the identity join TOTAL at 3519 with zero rows on either side alone. cpu_ms disagrees on 1394 of 3519 rows, max absolute delta 128ms. eval_steps disagrees on 18 of 3519. So the step measure reproduces exactly on 99.49 percent of the corpus against cpu's 60.4 percent -- FAR more stable, AND NOT INVARIANT, and (b) asked for invariance. THE JOB LOG SAYS THE OPPOSITE, AND THAT IS THE TRAP THIS PARAGRAPH EXISTS TO CLOSE: in the printed over-cost list every identity carries an identical eval_steps across all four runs while cpu swings by a third, so (b) reads as satisfied from the log alone. It is not. That list is ranked BY COST and truncated at 25, and 17 of the 18 disagreeing rows are too cheap to appear in it. A SUBSET SELECTED BY THE VARIABLE YOU ARE NOT TESTING CANNOT TEST THE ONE YOU ARE -- the same defect this row already records for the attention subset, reappearing on the new column, and the reason (b) must be joined on the uploaded artifact and never on the run's printed summary. WHAT THE 18 ARE, AND THEY ARE TWO DIFFERENT CLASSES RATHER THAN ONE POPULATION. SEVENTEEN ARE PASS/PASS with tiny deltas -- 3 to 161 steps, absolute relative difference at most 0.43 percent -- and they are CLUSTERED, NOT UNIFORM: sixteen of the seventeen sit in three modules, v2.test.claim.rust_crate_partition_witness (6), v2.test.claim.c_compilation_unit_witness (5) and v2.test.claim.compilation_unit_witness (5), one partition-and-unit witness family, with a single stray in v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract -- out of 3519 claims spanning the corpus. So MODULE-CLUSTERED VARIANCE EXISTS IN THIS A/B. That is the measurement; it does NOT establish the source, and an earlier revision called it a nondeterminism SOURCE, asserting as fact the conjecture the paragraph below correctly labels as one. IT IS EVIDENCE ABOUT THE STEP COUNT AND NOT ABOUT THE REFUSAL POPULATION, and conflating those is the error this row has already had to retract once: it establishes that module-clustered variance EXISTS in the corpus, which is the mechanism a module-clustered redraw would require, and it does not establish that the refused set redraws by module. THE EIGHTEENTH IS A DIFFERENT CLASS AND BEARS DIRECTLY ON MISSING ITEM (a). produced_decl_two_targets_render_own_order carries 196608 steps in the attempt where it was budget_interrupted and 197227 where it passed, so AN INTERRUPTED CLAIM'S eval_steps IS A PARTIAL COUNT AT THE STOP, not the claim's work -- the exact twin, in the step domain, of the already-recorded fact that an interrupted row's printed ms is the budget rather than a measurement. 196608 is 3 times 2 to the 16th exactly, which is suggestive of a step-interval deadline check; that is n=1 and the mechanism is NOT asserted here. THE CONSEQUENCE FOR (a) IS CONCRETE AND IS WHY THIS IS RECORDED BESIDE IT: a step-denominated line would compare against this partial for precisely the rows it exists to judge, so (a) needs a rule for the non-terminal row BEFORE it needs a number. NET EFFECT ON THE TRIGGER, STATED PER ARM BECAUSE (ii) IS A DISJUNCTION: the conjunct reads INVARIANT OR BOUNDED BY CONSTRUCTION and only the first arm has been tested. EXACT-INVARIANCE ARM: measured and REFUTED. BOUNDEDNESS ARM: UNESTABLISHED -- the 556-identity distribution below calls itself a spread and not a bound, reinforcing the distinction rather than resolving it. WHOLE CONJUNCT: REMAINS UNSATISFIED. An earlier revision wrote that (ii) moves to MEASURED AND FAILING, which is too broad for a disjunction whose second arm is untested: unsatisfied and both-alternatives-measured-and-failing are different findings. The trigger is a conjunction of three and (i) and (iii) are untouched, so nothing here retires this row and nothing here proposes raising the ceiling. RE-DERIVE with gh run download rather than by piping the artifact zip through a shell: gh api .../artifacts/ID/zip redirected to a file, and curl -o on the redirect target, BOTH corrupt the bytes in this environment -- a malformed local header and roughly 380 bytes short -- so an auditor who reaches for the obvious command gets an unreadable archive and may conclude the artifacts are gone. Taking the Location header and fetching it UNAUTHENTICATED also works; forwarding the Authorization header to blob storage returns 401. ONE FURTHER MEASUREMENT FROM THE SAME EPISODE, AND IT BEARS ON THIS ROW'S OWN REROLL SIGNATURE RATHER THAN ON ITS COST ARMS: THE PLANNED POPULATION IS NOT A FUNCTION OF THE TREE. On the single head b65a0eb5b32, the three attempts carrying a floor job report planned=executed=3534 (attempt 2, 33 claims failed), 3519 (attempt 3) and 3519 (attempt 4) -- fifteen claims of difference across attempts of ONE head with no change to the source. NO CAUSE IS ASSERTED HERE AND THE OBVIOUS ONE IS NOT VERIFIED: if the plan is computed relative to a moving main rather than to the head under test, this is expected rather than anomalous, and that is the first thing to check before treating it as a defect. WHAT IT DOES ESTABLISH REGARDLESS OF CAUSE is that EXACT HEAD DOES NOT BY ITSELF FIX THE POPULATION A REROLL IS DRAWN FROM, so a changed planned COUNT is RECEIPT AND COMPARABILITY DETAIL, and a potential planning or coverage defect, and NEVER a fresh reroll allowance. An earlier draft left that open as though it were undecided; it was already decided earlier in this same row, and leaving it open invited the budget reading it forbids. IT DOES NOT CONTAMINATE THE (b) JOIN ABOVE: attempts 3 and 4 both planned 3519 and their identity join is total at 3519 with zero rows on either side alone, which is why that measurement stands independently of this one. AND IT CORRECTS A CHARACTERISATION THAT WAS OFFERED FOR ATTEMPT 2 AND IS FALSE: that attempt was not a toolchain or host-tool incident -- its own summary reports host_tool_unresolved=0 beside claims_failed=33, so it is an ordinary red floor and belongs to no runner-incident population. The disposition is unchanged either way, since both cost arms are zero, so THE COST-ARM ADMISSION PREDICATE DOES NOT HOLD -- stated that way because there is no failed=0 precondition to fail, that key having been retired earlier in this same row, and an earlier revision resurrected it here after removing it one paragraph away, but the ground for excluding it from the mitigation is the cost-arm test and NOT a tooling attribution. THE CAUSE NAMED AS LIKELY IN THE PARAGRAPH ABOVE IS NOW CHECKED AND REFUTED, WHICH IS WHY THAT PARAGRAPH SAID TO CHECK IT FIRST. The suggestion was that the plan might be computed relative to a moving main rather than to the head under test, which would make the differing planned counts expected. IT IS NOT THAT. GitHub Actions evaluates a SYNTHETIC MERGE rather than the branch head, and all three attempts checked out THE SAME SYNTHETIC MERGE COMMIT -- each job log carries the identical line naming the merge of b65a0eb5b32 into 3547b3f9028 at one merge SHA -- so the three attempts ran a BYTE-IDENTICAL TREE and the main they were merged against did not move between them. The planned population therefore varies across attempts of a genuinely fixed tree. THE COUNTERS THAT DO NOT VARY NARROW IT FURTHER, and they are the ones a reader would reach for first: known_red_held, route_gap_held and stale_quarantine are IDENTICAL across all three attempts, so this is not a roster, quarantine or route-gap difference selecting a different population. Only planned, executed and terminal move, together, by fifteen. WHAT CANNOT BE SAID, AND THE REASON IS an artifact gap rather than a judgement: WHICH fifteen identities differ is NOT recoverable, because the attempt that planned 3534 uploaded no per-claim cost artifact -- only the two 3519-attempts did -- so the finding is available at COUNT grain and not at IDENTITY grain, which is precisely the weaker form this row elsewhere refuses to accept as a population. It is recorded as a count because that is what was measured. ONE CONJECTURE, LABELLED AS ONE AND CARRYING ITS OWN TEST RATHER THAN A CONCLUSION: the same unpinned iteration order that would explain the module-clustered eval_steps variance recorded above -- sixteen of seventeen disagreements inside one partition-and-unit witness family, which is exactly the shape of a fold over a set with no declared order -- could also change how many claims a generator emits, giving both observations ONE root. NOTHING HERE ESTABLISHES THAT, and the discriminating test is named so the next lane does not have to invent it: recover the fifteen identities by having the planner emit its plan as an artifact on every attempt including a failing one, then join two attempts of one synthetic merge at IDENTITY grain and ask whether the differing rows are generated claims from the same witness families that carry the step variance. Until that artifact exists the two observations are adjacent and unjoined. THE CONSEQUENCE FOR THIS ROW'S REROLL RULE IS UNCHANGED BY THE REFUTATION AND IS STRENGTHENED BY IT: exact head does not fix the drawn population, and it is now known that no appeal to a moving base explains it away. AND IT DOES NOT EXPAND THE REROLL ALLOWANCE, WHICH IS THE READING IT MOST INVITES AND THE ONE THIS SENTENCE EXISTS TO REFUSE: a differing planned cardinality WEAKENS COMPARABILITY between two attempts and lowers confidence that they covered the same claims; it does not license a second draw. The allowance stays at ONE PER EXACT HEAD, consumed on actuation. IT IS NOT PER SIGNATURE, AND SAYING SO WOULD REINTRODUCE A SPELLING THIS ROW ALREADY REFUTED: the signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget key. This finding makes exact head insufficient as a COMPARABILITY IDENTITY; it leaves exact head intact as the deliberately coarse BUDGET KEY, and letting a changed population mint a fresh signature would recreate retry-until-green exactly when the roster becomes unstable. An attempt that falls outside this row's domain spends nothing AND EARNS NOTHING -- it is not a free retry, and treating an ineligible red as though it restored the budget would be retry-until-green reached by a different route than the one this row already forbids. RECEIPT, 2026-09-03, gunbc#10231 -- THE SHARPEST INSTANCE THIS ROW CARRIES, BECAUSE THE VERDICT FLIPPED WHILE THE WORK MEASURE DID NOT MOVE BY ONE STEP. THE SUBJECT MAKES THE POINT BEFORE THE NUMBERS DO: it is a LEDGER-ONLY PROSE PR -- the filing of this row's sibling mechanism class -- touching one authority row and its generated projection, with no code, no types and no gates. A DIFF CATEGORY DOES NOT GRANT COST INNOCENCE BY CONSTRUCTION, and an earlier revision claimed it did: the ledger is ACCEPTED .dag SOURCE here, so altering a large literal can move parsing, resolution, allocation, generated structure or closure work, and shape is not an argument about cost. THE NARROWER CONTROL IS SUFFICIENT AND IS WHAT IS CLAIMED: the diff was IDENTICAL ACROSS BOTH ATTEMPTS, so whatever it costs relative to its base, it cannot explain the attempt-to-attempt flip. Run 33756177727 attempt 1, floor job 100651027559: REFUSED with completed_over_cost_requirement=1 beside claims_failed=0, interrupted_before_verdict=0 and host_tool_unresolved=0 -- one row, wholly inside this row's admitted domain on the two-arm test, with the run's phase verdict carrying no other failed phase. One reroll was actuated and thereby CONSUMED, against a budget of ONE PER EXACT HEAD. Attempt 2, job 100663093895: PASS. THE DISCRIMINATING PAIR, and it is one identity rather than an aggregate: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates measured cpu_ms=523 on the refusing attempt and cpu_ms=404 on the passing one -- a ratio of 1.294 across the 500 line -- WHILE ITS eval_steps IS IDENTICAL AT 169297 ON BOTH. Same head, same tree, same identity, same count of evaluator steps, opposite verdicts. WHAT THAT SUPPORTS, AT THE INSTRUMENT'S REACH AND NOT BEYOND IT: for one fixed identity on one fixed head the cpu-line verdict flipped while the recorded net evaluator-step count stayed exactly identical, so THE CPU VERDICT IS NOT DETERMINED BY eval_steps ALONE -- stronger than showing cpu varies more often than steps, because it exhibits the mismatch at the very identity whose verdict changed. WHAT IT DOES NOT SUPPORT, and an earlier revision asserted it: that the deciding component lies OUTSIDE THE CLAIM'S WORK. Identical eval_steps establishes identical COUNTED EVALUATOR ENTRIES AFTER THIS INSTRUMENT'S NETTING RULE, not identical claim work -- host work, closure work, attribution and cache behaviour are uncounted and remain possible. This row keeps CHARGE-SUBJECT ALIGNMENT open as conjunct (i), so it cannot use this pair to place the varying component outside the claim; that would discharge (i) by assertion. THIS DOES NOT CONTRADICT THE (b) REFUTATION RECORDED ABOVE, and the reconciliation matters because the two readings look opposed: (b) failed because 18 identities of 3519 disagree on eval_steps, NOT because the measure is generally unstable -- 3501 reproduce exactly, and this identity is one of them. A measure can be exact on a given row and still fail an invariance claim asserted over a corpus. A THIRD SAMPLE OF THE SAME IDENTITY EXISTS ON GREEN MAIN, CITED BY RUN AND JOB SO IT IS RE-DERIVABLE RATHER THAN RELAYED: run 33754393519, floor job 100645180812, event push on main head 75873c28978, reports this identity at cpu_ms=406 with eval_steps=169297 -- the SAME step count as both attempts of the episode above, at a third distinct cpu. AND THE ORDERING IS WEAKER THAN AN EARLIER REVISION OF THIS PARAGRAPH CLAIMED, WHICH IS WHY THE CARRIER WAS WORTH DEMANDING. That revision said the identity had been NAMED IN ADVANCE and that a lane had PUBLISHED the crossing arithmetic before the refusal, which made it a prediction. The job timestamps refute that framing: the green-main job ran 12:17:45Z to 12:45:05Z and the refusing attempt ran 12:40:20Z to 13:10:22Z, so THE TWO RUNS OVERLAPPED. The green-main value was therefore observable 25 minutes before the refusal was observed, and it is CORROBORATION AT A THIRD SAMPLE rather than a prediction made before the event. The advance-prediction claim is withdrawn; it was received by relay and no carrier for the publication event was ever produced, which is exactly the transcribed-number failure DESIGN section 6 forbids -- name the producer, never copy its output. A prediction that names the row before it refuses a PR is worth more than a fresh observation of the same event. INDEPENDENT REPLICATION OF THE SPREAD, derived from the per-claim cost artifacts of THIS row's other episode rather than from the reporting lane's run, and it is an INDEPENDENT RUN AND ARTIFACT SAMPLE rather than an independent instrument -- an earlier revision said the two share NO instrument, which is false: they share the required-floor cpu producer, its accounting semantics, the evaluator-step counter and the artifact schema. What they do not share is a run or an artifact, and that is the whole of the independence claimed: over the 556 identities measuring at least 50 cpu-ms in BOTH attempts of one identical tree, the attempt-to-attempt cpu ratio -- DEFINED PER JOINED IDENTITY AS max(cpu_A, cpu_B) / min(cpu_A, cpu_B), so it is direction-free and never below 1.0, stated because an earlier revision published percentiles without the formula and B/A would give materially different numbers -- has median 1.045, p10 1.005, p90 1.219 and MAXIMUM 1.721. THE MEDIAN IS THE UNINTERESTING NUMBER AND THE TAIL IS THE ONE THAT DECIDES VERDICTS -- a corpus whose typical row moves by 4 percent still puts four identities at 94 to 103 percent of budget on a tree that PASSED. WHAT NONE OF THIS ESTABLISHES, stated because this row's trigger asks for exactly the thing it falls short of: A BOUND. Two attempts give a SPREAD, and (ii) requires the basis to be invariant OR BOUNDED BY CONSTRUCTION across the admitted envelopes; a maximum of 1.721 observed over one pair of attempts on one host pair is a FLOOR on the spread, not a bound on it, and the admitted envelope set is wider than the hosts these pairs sampled. THE CONSEQUENCE ON MAIN, MEASURED AT VERDICT GRAIN RATHER THAN AT ROW GRAIN (2026-09-03), because everything above measures ROWS and the thing that costs the fleet its afternoon is the VERDICT. Of the twenty-five most recent `witnesses.yml` runs on `main`, five reported `verdict=FloorRefused` with `claims_failed=0` and `unexpected_failures=0` -- the whole refusal carried by `interrupted_cpu_deadline` and `completed_over_cost_requirement`, so the required floor refused main five times without a single claim disagreeing with the tree. A GATE THAT REFUSES FOR REASONS UNRELATED TO THE CHANGE TEACHES ITS READERS THAT A RED REQUIRED FLOOR IS NOISE, and that is the cost this row had not priced: the sections above price the mis-attribution of a NUMBER to a row, and this one prices the mis-attribution of a VERDICT to a tree. AND THE HOST CORRELATION, STATED AT THE WIDTH THE SAMPLE SUPPORTS AND NOT WIDER. THE DECISIVE MEASUREMENT IS NOT THE HOST TABLE, IT IS A SAME-HEAD CONTROL, and it is stated first because it is established BY CONSTRUCTION rather than by correlation. Run 33806159353 was re-run at the same head: attempt 1 recorded `required-witnesses-floor` FAILURE on runner srv4-14 and attempt 2 recorded SUCCESS on runner srv4-19, both at head 07f81df887a, unchanged between them. ONE TREE, TWO ATTEMPTS, OPPOSITE VERDICTS. Nothing about the subject differed, so the required floor's verdict is demonstrably NOT A PROPERTY OF THE TREE -- which is this row's whole subject, now shown rather than inferred, and shown without needing any closure argument because nothing changed. THE HOST TABLE IS THE WEAKER EVIDENCE AND ITS FAMILY-SHAPED READINGS ARE REFUTED, twice, in the same direction. Eleven `required-witnesses-floor` jobs by runner registration: seven failed (srv1-02, srv1-07, srv1-10, srv1-16, srv1-17, srv4-11, srv4-14) and four passed (srv3-02, srv3-04, srv3-10, srv4-19). A first reading said srv1 is the bad host and srv4-11 refuted it; a second said srv3 is the only host observed clearing the ceiling and srv4-19 refuted that too, since srv4 now does BOTH. BOTH READINGS GENERALISED A HOST FAMILY FROM MACHINE-LEVEL SAMPLES AND THE NEXT SAMPLE CROSSED THE LINE EACH TIME, which is why the surviving statement names no family at all. WHAT THE MEASUREMENTS SUPPORT, AND NOTHING WIDER: the verdict is not a property of the tree; it is not cleanly a property of the host family; THE ACTUAL VARIABLE IS UNIDENTIFIED, with machine-level load or moment and a per-machine difference both consistent with the data, and eleven samples cannot separate them. Naming a cause here would be the looks-principled-and-is-not move this row already refuses on the calibration arm. MISSING ITEM (b) IS NOW DISCHARGED OVER THE MEASURABLE POPULATION AND THE ROW STILL STANDS, and the reason it still stands is the more useful half. THE JOIN (warm-seal-35, over the two attempts above): 338 shared-fill per-claim rows on each side, joined ON IDENTITY with ZERO unmatched rows in either direction, `marginal_eval_steps` and `measured_eval_steps` IDENTICAL for all 338, while measured cpu-ms moved by more than ten percent on 124 of them and spanned 0.627 to 1.217 as an attempt-2-over-attempt-1 ratio. That is (b) as worded -- an exact identity join of the step column across two attempts of ONE IDENTICAL TREE, with the cpu column moving and this one not -- and it is a population rather than a subject, which is what separates it from the single-claim reading above. ITS DENOMINATOR IS NOT THE FLOOR, AND QUOTING IT AS WHOLE-FLOOR COVERAGE WOULD BE THE ERROR THIS ROW EXISTS TO REFUSE: both attempts executed 3585 claims and the shared-fill instrument reports per-claim cost for 338 of them, so the join covers 9.4 percent and is silent about the rest. THE EXCLUSION IS THE FINDING, NOT A CAVEAT ON IT, AND IT IS SHARPER THAN THE CONSTRAINT PREDICTED ABOVE. An interrupted row is unmeasured in steps by construction, so the join can only cover completed rows -- and the rows it therefore excludes are EXACTLY THE ROWS THAT DECIDED THE VERDICT. Attempt 1 recorded passed=3507 with interrupted_before_verdict=2 and completed_over_cost_requirement=1 and refused; attempt 2 recorded passed=3510 with both counters at zero and was clean. 3507 plus 2 plus 1 is 3510: the three rows are precisely the difference between the two attempts, and they are precisely the rows no step measurement can speak about. THE MORE A CLAIM IS AFFECTED, THE LESS MEASURABLE IT BECOMES. So the join establishes that 338 OTHER claims did identical work under a moving envelope -- strong evidence about the envelope, and NO evidence about the three. WHICH IS A CONSTRAINT ON MISSING ITEM (a) AND NOT ONLY ON (b), and it is the first thing this row has been able to say about (a) at all: A STEP-DENOMINATED LINE BUILT ON THIS INSTRUMENT WOULD BE BLIND IN EXACTLY ITS OWN SUBJECT DIRECTION, because the rows that would cross such a line are the rows that carry no step count. Sizing one from the measurable population would produce a threshold that looks principled and is derived from the rows that were never at issue. EVIDENCE GRADES, KEPT SEPARATE AS EVERYWHERE ELSE IN THIS ROW. The two attempt summaries and their arithmetic were read FIRST-HAND from the run at two different times, attempt 1 while it was the only attempt and attempt 2 after the re-run; the 338-row join is taken from its builder with its own disclosed method corrections and was not re-derived here, because the attempt-1 log archive returns a truncated response that will not open. A CITATION TRAP WAS OBSERVED WHILE CHECKING THIS AND IS RECORDED SO THE NEXT READER DOES NOT LOSE AN HOUR TO IT: a bare job id serves the LATEST attempt, so job 100817014187 -- whose own conclusion is failure -- now serves attempt 2 FloorClean summary. An attempt-level citation is the only stable one. AND THE DISPOSITION GETS MORE DEFENSIBLE RATHER THAN LESS: a ceiling whose verdict flips on ONE UNCHANGED TREE between two attempts thirty-six minutes apart is not something a fifth shave of the claim would fix, which is the measured form of the argument that four prior lanes closed on the claim and it fired again. WHAT IS ESTABLISHED PER SAMPLE DIFFERS AND IS NOT FLATTENED: the `claims_failed=0` / `unexpected_failures=0` signature was read from the run logs for six of the seven failures, srv4-11 being the one taken on report rather than read. The distinction is kept because this carrier's own subject is a verdict being attributed to the wrong thing, and a floor job can redden on a phase that is not the floor -- so FAILED and FAILED-WITH-THIS-SIGNATURE are different facts and the row says which it has. A ONE-SUBJECT CROSS-ENVELOPE READING, WHICH BEARS ON MISSING ITEM (b) AND DOES NOT DISCHARGE IT (calm-deer-33, 2026-09-03, verified here rather than relayed). `v2.test.emit.rust_produced_decl_emit.produced_decl_unwired_target_still_refuses` measured 165802 eval_steps at 346 cpu-ms on run 33802603168 and 165802 eval_steps at 514 cpu-ms on run 33806159353 -- the step count IDENTICAL to the digit while cpu moved 1.49x, and the second reading is the one that crossed into completed-over-budget. Log-line controls of 3472 and 3465 rule out an empty capture on either side, which is this repository's standing guard against a zero that reads as a clean sweep. WHY IT IS NOT (b), ON THREE COUNTS, AND THE THIRD IS THE ONE A LATER READER WILL MISS. (i) GRAIN: (b) asks for a join AT CORPUS GRAIN and this is one subject. (ii) SUBJECT: (b) asks for TWO ATTEMPTS OF ONE IDENTICAL TREE, and these are two different trees -- 8b2323f is an ANCESTOR of 07f81df, so the pull request adds commits on top of the main commit it is compared against. (iii) THE WARRANT FOR THE-WORK-DID-NOT-CHANGE CANNOT COME FROM THE STEP COUNT ITSELF: constant steps are read as envelope-independence only if the work is identical on INDEPENDENT grounds, since a measure insensitive to the change produces the same reading. TWO ATTEMPTS OF ONE IDENTICAL TREE supplies that warrant BY CONSTRUCTION, which is why (b) is written that way. ACROSS TWO TREES IT WAS SUPPLIED SEPARATELY AND (iii) IS ANSWERED, by two arguments that do not depend on each other, both re-derived here rather than relayed. FIRST, A SYMBOL-GRAIN JOIN: the whole diff between the compared trees touches three files and adds or removes six declarations -- `absence_classifier_default_bucket`, `green_reported_over_a_population_the_instrument_does_not_own`, `live_03_normalize_data_inits`, `live_03_normalize_facts`, `live_argument_threaded_past_the_arm_that_decides` and `effect_reach_live_03_normalize_witness_derived_host_reading_holds` -- and the module declaring the measured claim, `v2.test.claim.emit.produced_decl_two_target_test`, references none of the six, with a positive control on the same grep finding `tt_emit`, `tt_emits` and `tt_refuses` there. SYMBOL GRAIN RATHER THAN IMPORT CLOSURE IS LOAD-BEARING IN THIS SUBSTRATE: names resolve by global uniqueness rather than by import lists, so a name absent from every import list still resolves and an import-closure argument would exclude modules that can still supply a binding. SECOND, AND INDEPENDENT OF WHETHER THAT JOIN IS EXHAUSTIVE: the diff is NET NEGATIVE, 32 insertions against 60 deletions, and the only witness change DELETES a row, so any corpus-scale work effect would push this claim CHEAPER while the observation is 1.49x MORE EXPENSIVE. The move is in the wrong direction for every work-based explanation. A CONSTRAINT ON HOW (b) CAN EVER BE DISCHARGED, WHICH IS A PROPERTY OF THE COLUMN AND NOT OF TONIGHT. An INTERRUPTED row is unmeasured in `eval_steps` BY CONSTRUCTION -- the poll fires before a count exists -- so a corpus-grain identity join over this column has a STRUCTURALLY EXCLUDED SUBPOPULATION, and the excluded rows are precisely the expensive ones the join most needs to cover. (b) as worded may therefore not be buildable at full coverage at all. A LATER LANE THAT BUILDS IT OVER COMPLETED ROWS AND REPORTS COVERAGE WILL BE REPORTING OVER A POPULATION IT DOES NOT OWN, which is `gunbc.recurring_failure_mode` `green_reported_over_a_population_the_instrument_does_not_own` -- so the honest discharge of (b) must either state the exclusion as part of its result or reach the interrupted rows by a different measure, and a coverage figure over completed rows alone does not retire this row. WHAT IT DOES ESTABLISH is still an advance on what this row had: the invariance reading was previously grounded at FIXTURE grain and nowhere wider, and this extends it to a live corpus subject under real floor pressure. Recorded as that and not as more. IT WAS MEASURED FORWARD, WHICH IS THE ONLY REASON IT IS RECORDED AT ALL: a prediction that srv1-10 would fail and srv3-10 would pass was registered before either returned, and runs 33794985110 and 33796487867 held it. WHAT IT IS NOT IS AN EXPLANATION. A SLOWER HOST is a hypothesis with no mechanism attached, three passes on one host is a thin denominator, and neither this correlation nor a wider one discharges (i), (ii) or (iii) of the trigger below -- a basis that varies with the machine is exactly what (ii) asks to be rid of, so measuring WHICH machines it varies with sharpens the subject and closes none of it. NOT PROPOSED HERE, AND THE DISTINCTION IS THE SAME ONE THIS ROW HAS MADE THROUGHOUT: raising the 500 line would change which rows cross and would not make the crossing a property of the claim, so it does not retire this row and is not requested." } } diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 6ae47cb00b1..e12b9d11b54 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -44,7 +44,7 @@ Each row declares a safety guarantee that was lowered: what stood before, what s ### Per-claim cost qualification is unavailable at the subject grain the gate consumes — declared 2026-09-01 -Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. the 500ms CPU line this row was declared over (now `required_floor_per_subject_cpu_line_ms`, which is still CPU milliseconds and still compared to a CPU reading by the enrolment margin and by cost-debt admission; the claim ceiling's own 500 moved to `required_floor_claim_work_envelope_ms`, a policy in milliseconds of work that no clock is compared to) was a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 219ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR, and a floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. RE-DERIVED 2026-09-03, BY THAT CONDITION AND BY NOTHING ELSE. The floor was 1.777 from a single identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed -- which is ONE PAIR, and one pair is one sample of a between-run quantity and therefore has no spread at all. A LARGER FLOOR IS NOW MEASURED OVER A SAMPLE THAT INDEXES OVER RUNS: 2.280, the worst per-identity max-over-min across TWELVE green `main` runs of `witnesses.yml` on twelve distinct runner registrations across three hosts, restricted to identities present in every run with a verdict, a baseline at or above 50 cpu-ms, and equal `eval_steps` in all twelve. THAT LAST RESTRICTION IS A FILTER AND NOT A FINDING, and the distinction matters here more than anywhere because MISSING ITEM (b) BELOW MEASURED THE SAME COLUMN AND REFUTED ITS INVARIANCE: selecting rows whose steps agree removes tree movement from the sample so the residual is inflation, and it establishes nothing about whether steps are invariant in general -- they are not. 500 over 2.280 floors to the constant above. THE PRODUCER IS NAMED AND THE DIGITS ARE NOT THE AUTHORITY: `gunbc.floor_cost_distribution` `worst_envelope_permille` over `work_invariant_envelopes` of `complete_envelopes`, driven by `tools.floor_cost_distribution_instrument` `floor_cost_envelope_report`, whose sampled runs and their runners are data in `floor_cost_envelope_sampled_runs`. This is the modeled producer the paragraph below says does not exist for the SUBSET; it exists for the CONSTANT'S INPUT and not for the subset, and those are different gaps. ROBUST IN DIRECTION AND NOT ONLY IN VALUE: restricting the same derivation to rows at or above 200 cpu-ms, where whole-millisecond quantisation cannot dominate, gives 1.874 and a constant of 266ms -- still below the superseded 280, so the re-derivation does not rest on the small-baseline tail. STILL A FLOOR: twelve runs on three hosts are a SUBSET of the admitted execution envelopes, so 2.280 can only rise and this constant can only fall. AND THE EXTREMES ARE CONCENTRATED ON PARTICULAR MACHINES, which a median run factor cannot see because a median is robust exactly where the envelope is driven: `run_extreme_census` over the same population reports one run holding the MINIMUM for 367 of 398 rows and one host holding the MAXIMUM for 279 of 398 from three of twelve runs, while per-run median factors span only 0.878 to 1.118. That is this row's own subject measured at host grain. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN, AT THE SUPERSEDED 280ms CONSTANT AND NOT AT THE ONE ABOVE -- the enumeration is kept as the receipt of what was measured and must not be read as today's subset, which is larger at a lower constant (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. That histogram is that run's, at the superseded constant; on the twelve-run sample above, taking each identity's MAX over the twelve, 88 identities reach 280 and 158 reach the constant now standing, and the same doubling holds within a single run rather than only in the union (run 33754393519: 61 then 115; run 33775106554: 73 then 128; run 33766436293: 20 then 72). Lowering the constant roughly doubles the subset, which is the cost of the re-derivation stated rather than left for a reader to discover. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED BY CONSTRUCTION across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE PER-CLAIM MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. THE QUALIFIER IS LOAD-BEARING AND WAS ADDED BY RULING (fierce-lark-661, 2026-09-13, on gunbc#11195) BECAUSE THE UNQUALIFIED SENTENCE FORBADE MORE THAN ITS EVIDENCE SUPPORTS -- DESIGN section 4d's over-prohibition arm, whose cost is the thing nobody does. WHAT IS FORBIDDEN is deriving a claim's budget from the population's own CPU readings: that is the run-varying, position-sensitive quantity, and a budget consuming it inherits the defect AND makes a verdict vary between runs. WHAT IS ADMITTED is a SINGLE CONTROLLED READING pinned as a POLICY CONSTANT -- `v2.workflow.floor_eval_step_calibration` -- taken on a fixture whose work is fixed by source rather than by the corpus. The discriminator is not the unit but the DEPENDENCE: an error in a pinned constant mis-scales BOTH tiers ONCE and UNIFORMLY and cannot make one claim's verdict differ between two runs of the same tree, which is precisely the property the denominator change buys and precisely what the per-claim distribution cannot offer. A RE-PIN RESCALES EVERY BUDGET UNIFORMLY AND NEVER ONE CLAIM, so it is a policy act taken deliberately and never maintenance. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. RECEIPT, 2026-09-03, gunbc#10192: ONE EPISODE BY RUN ID -- ADMITTED IN PART AND NOT END TO END, WHICH THE ENUMERATION BELOW ADJUDICATES RATHER THAN SMOOTHS -- AND THE FIRST CORPUS-GRAIN MEASUREMENT OF MISSING ITEM (b) -- WHICH IT REFUTES RATHER THAN DISCHARGES. THE EPISODE, run 33716314510 on head b65a0eb5b32, ENUMERATED IN FULL INCLUDING THE ATTEMPTS THAT DO NOT QUALIFY, because the sequence contains a transition this row does NOT authorize and an enumeration that showed only the eligible attempts would present an unadmitted retry as part of an admitted mitigation. ATTEMPT 1 EXECUTED ZERO JOBS -- no required-witnesses-floor job exists for it; the run was created awaiting workflow approval -- so it is not an attempt of this class and counting it as one would inflate the denominator. ATTEMPT 2, job 100543957851: claims_failed=33 with BOTH cost arms at zero. OUTSIDE this row's domain: zero dispositions in either cost arm. THE CAUSE OF THOSE 33 IS NOT ESTABLISHED HERE AND AN EARLIER DRAFT CALLED THEM SEMANTIC, WHICH THE COUNTERS DO NOT SUPPORT -- claims_failed enumerates ordinary claim-failure dispositions and does not say why they failed, and a missing host capability surfacing as a runtime error would land in the same counter as a genuine false assertion. The honest reading is an ORDINARY CLAIM-FAILURE FLOOR REFUSAL, CAUSE UNESTABLISHED. ITS ROLE HERE IS A NEGATIVE ELIGIBILITY CONTROL AND NOT A DENOMINATOR MEMBER, which corrects the reason an earlier draft gave for including it: a mitigation's eligible population is the attempts satisfying its admission predicate, so an attempt outside the class can no more count as a failed use of the mitigation than an ordinary compile error can. It is kept because it PROVES THE PREDICATE EXCLUDES SOMETHING REAL. AND THE TRANSITION OUT OF IT IS UNADJUDICATED, WHICH THIS ROW RECORDS RATHER THAN LAUNDERS: outside this row's budget means attempt 2 SPENT no reroll; it does not mean attempt 2 EARNED one. The re-run that produced attempt 3 was NOT admitted by this row -- attempt 2's refusal was carried by neither cost arm -- and no other authority is named for it. So this sequence is not one admitted mitigation end to end: it is an unadmitted retry of an ordinary red on byte-identical executed input, followed by a cost-only refusal that this row does admit, followed by its one reroll. A clean attempt 4 does not retroactively discharge attempt 2, and with attempt 2's identity artifact absent it cannot even be shown that all 33 failures were offered again. ATTEMPT 3, job 100573179841: presents as the two-arm shape this row admits, AND THE ADJUDICATING SURFACE IS ENROLLED HERE RATHER THAN ASSUMED: the run reports phases_run=3 with phases_failed=1, the ONLY FAILED PHASE being the floor, and unexpected_failures=0 -- the external phase verdict this row names as the current eligibility surface, and what establishes that no other phase failed. Beneath it the cost arms are completed_over_cost_requirement=1 and interrupted_before_verdict=1 all cpu_deadline, one row each. An earlier revision removed the internal proof without putting the external one in its place, leaving a correct qualification unsupported by the very surface this row says must adjudicate it. THE `failed=0` SPELLING IS NOT THE ELIGIBILITY KEY AND IS NOT RESTATED AS ONE HERE, because this row already ruled that test defective: it is read off the floor's own COST disposition counters, which do not range over other phases and so could only ever confirm themselves. The current surface is the RUN'S PHASE VERDICT -- phases_run, failed, and FAILED PHASE lines -- and the counters below are receipt, not the test. The completed-past-limit row is v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order at cpu_ms=515, an EXACT measurement against the 500 line; the interrupted row is its SIBLING IN THE SAME MODULE, produced_decl_two_targets_render_own_order, whose printed 509 is the BUDGET and not a measurement. ATTEMPT 4, job 100606296727: the consumed reroll, clean, failed=0 and both arms zero. A LATER AND DIFFERENT TREE, head 2b9e59206af (run 33746447180, job 100619903740), ran clean with MORE claims (executed 3519 rising to 3539) and spent no reroll -- consistent with this row's redraw reading and NOT evidence for it, since one clean draw discriminates nothing. MISSING ITEM (b) IS NOW MEASURED AND IS REFUTED. (b) asked for an identity join of eval_steps across two attempts of ONE IDENTICAL TREE where the cpu column moves and this one must not. Attempts 3 and 4 are exactly that pair, and the artifacts are required-floor-claim-cost 9885042655 and 9889079822, both executed=3519, the identity join TOTAL at 3519 with zero rows on either side alone. cpu_ms disagrees on 1394 of 3519 rows, max absolute delta 128ms. eval_steps disagrees on 18 of 3519. So the step measure reproduces exactly on 99.49 percent of the corpus against cpu's 60.4 percent -- FAR more stable, AND NOT INVARIANT, and (b) asked for invariance. THE JOB LOG SAYS THE OPPOSITE, AND THAT IS THE TRAP THIS PARAGRAPH EXISTS TO CLOSE: in the printed over-cost list every identity carries an identical eval_steps across all four runs while cpu swings by a third, so (b) reads as satisfied from the log alone. It is not. That list is ranked BY COST and truncated at 25, and 17 of the 18 disagreeing rows are too cheap to appear in it. A SUBSET SELECTED BY THE VARIABLE YOU ARE NOT TESTING CANNOT TEST THE ONE YOU ARE -- the same defect this row already records for the attention subset, reappearing on the new column, and the reason (b) must be joined on the uploaded artifact and never on the run's printed summary. WHAT THE 18 ARE, AND THEY ARE TWO DIFFERENT CLASSES RATHER THAN ONE POPULATION. SEVENTEEN ARE PASS/PASS with tiny deltas -- 3 to 161 steps, absolute relative difference at most 0.43 percent -- and they are CLUSTERED, NOT UNIFORM: sixteen of the seventeen sit in three modules, v2.test.claim.rust_crate_partition_witness (6), v2.test.claim.c_compilation_unit_witness (5) and v2.test.claim.compilation_unit_witness (5), one partition-and-unit witness family, with a single stray in v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract -- out of 3519 claims spanning the corpus. So MODULE-CLUSTERED VARIANCE EXISTS IN THIS A/B. That is the measurement; it does NOT establish the source, and an earlier revision called it a nondeterminism SOURCE, asserting as fact the conjecture the paragraph below correctly labels as one. IT IS EVIDENCE ABOUT THE STEP COUNT AND NOT ABOUT THE REFUSAL POPULATION, and conflating those is the error this row has already had to retract once: it establishes that module-clustered variance EXISTS in the corpus, which is the mechanism a module-clustered redraw would require, and it does not establish that the refused set redraws by module. THE EIGHTEENTH IS A DIFFERENT CLASS AND BEARS DIRECTLY ON MISSING ITEM (a). produced_decl_two_targets_render_own_order carries 196608 steps in the attempt where it was budget_interrupted and 197227 where it passed, so AN INTERRUPTED CLAIM'S eval_steps IS A PARTIAL COUNT AT THE STOP, not the claim's work -- the exact twin, in the step domain, of the already-recorded fact that an interrupted row's printed ms is the budget rather than a measurement. 196608 is 3 times 2 to the 16th exactly, which is suggestive of a step-interval deadline check; that is n=1 and the mechanism is NOT asserted here. THE CONSEQUENCE FOR (a) IS CONCRETE AND IS WHY THIS IS RECORDED BESIDE IT: a step-denominated line would compare against this partial for precisely the rows it exists to judge, so (a) needs a rule for the non-terminal row BEFORE it needs a number. NET EFFECT ON THE TRIGGER, STATED PER ARM BECAUSE (ii) IS A DISJUNCTION: the conjunct reads INVARIANT OR BOUNDED BY CONSTRUCTION and only the first arm has been tested. EXACT-INVARIANCE ARM: measured and REFUTED. BOUNDEDNESS ARM: UNESTABLISHED -- the 556-identity distribution below calls itself a spread and not a bound, reinforcing the distinction rather than resolving it. WHOLE CONJUNCT: REMAINS UNSATISFIED. An earlier revision wrote that (ii) moves to MEASURED AND FAILING, which is too broad for a disjunction whose second arm is untested: unsatisfied and both-alternatives-measured-and-failing are different findings. The trigger is a conjunction of three and (i) and (iii) are untouched, so nothing here retires this row and nothing here proposes raising the ceiling. RE-DERIVE with gh run download rather than by piping the artifact zip through a shell: gh api .../artifacts/ID/zip redirected to a file, and curl -o on the redirect target, BOTH corrupt the bytes in this environment -- a malformed local header and roughly 380 bytes short -- so an auditor who reaches for the obvious command gets an unreadable archive and may conclude the artifacts are gone. Taking the Location header and fetching it UNAUTHENTICATED also works; forwarding the Authorization header to blob storage returns 401. ONE FURTHER MEASUREMENT FROM THE SAME EPISODE, AND IT BEARS ON THIS ROW'S OWN REROLL SIGNATURE RATHER THAN ON ITS COST ARMS: THE PLANNED POPULATION IS NOT A FUNCTION OF THE TREE. On the single head b65a0eb5b32, the three attempts carrying a floor job report planned=executed=3534 (attempt 2, 33 claims failed), 3519 (attempt 3) and 3519 (attempt 4) -- fifteen claims of difference across attempts of ONE head with no change to the source. NO CAUSE IS ASSERTED HERE AND THE OBVIOUS ONE IS NOT VERIFIED: if the plan is computed relative to a moving main rather than to the head under test, this is expected rather than anomalous, and that is the first thing to check before treating it as a defect. WHAT IT DOES ESTABLISH REGARDLESS OF CAUSE is that EXACT HEAD DOES NOT BY ITSELF FIX THE POPULATION A REROLL IS DRAWN FROM, so a changed planned COUNT is RECEIPT AND COMPARABILITY DETAIL, and a potential planning or coverage defect, and NEVER a fresh reroll allowance. An earlier draft left that open as though it were undecided; it was already decided earlier in this same row, and leaving it open invited the budget reading it forbids. IT DOES NOT CONTAMINATE THE (b) JOIN ABOVE: attempts 3 and 4 both planned 3519 and their identity join is total at 3519 with zero rows on either side alone, which is why that measurement stands independently of this one. AND IT CORRECTS A CHARACTERISATION THAT WAS OFFERED FOR ATTEMPT 2 AND IS FALSE: that attempt was not a toolchain or host-tool incident -- its own summary reports host_tool_unresolved=0 beside claims_failed=33, so it is an ordinary red floor and belongs to no runner-incident population. The disposition is unchanged either way, since both cost arms are zero, so THE COST-ARM ADMISSION PREDICATE DOES NOT HOLD -- stated that way because there is no failed=0 precondition to fail, that key having been retired earlier in this same row, and an earlier revision resurrected it here after removing it one paragraph away, but the ground for excluding it from the mitigation is the cost-arm test and NOT a tooling attribution. THE CAUSE NAMED AS LIKELY IN THE PARAGRAPH ABOVE IS NOW CHECKED AND REFUTED, WHICH IS WHY THAT PARAGRAPH SAID TO CHECK IT FIRST. The suggestion was that the plan might be computed relative to a moving main rather than to the head under test, which would make the differing planned counts expected. IT IS NOT THAT. GitHub Actions evaluates a SYNTHETIC MERGE rather than the branch head, and all three attempts checked out THE SAME SYNTHETIC MERGE COMMIT -- each job log carries the identical line naming the merge of b65a0eb5b32 into 3547b3f9028 at one merge SHA -- so the three attempts ran a BYTE-IDENTICAL TREE and the main they were merged against did not move between them. The planned population therefore varies across attempts of a genuinely fixed tree. THE COUNTERS THAT DO NOT VARY NARROW IT FURTHER, and they are the ones a reader would reach for first: known_red_held, route_gap_held and stale_quarantine are IDENTICAL across all three attempts, so this is not a roster, quarantine or route-gap difference selecting a different population. Only planned, executed and terminal move, together, by fifteen. WHAT CANNOT BE SAID, AND THE REASON IS an artifact gap rather than a judgement: WHICH fifteen identities differ is NOT recoverable, because the attempt that planned 3534 uploaded no per-claim cost artifact -- only the two 3519-attempts did -- so the finding is available at COUNT grain and not at IDENTITY grain, which is precisely the weaker form this row elsewhere refuses to accept as a population. It is recorded as a count because that is what was measured. ONE CONJECTURE, LABELLED AS ONE AND CARRYING ITS OWN TEST RATHER THAN A CONCLUSION: the same unpinned iteration order that would explain the module-clustered eval_steps variance recorded above -- sixteen of seventeen disagreements inside one partition-and-unit witness family, which is exactly the shape of a fold over a set with no declared order -- could also change how many claims a generator emits, giving both observations ONE root. NOTHING HERE ESTABLISHES THAT, and the discriminating test is named so the next lane does not have to invent it: recover the fifteen identities by having the planner emit its plan as an artifact on every attempt including a failing one, then join two attempts of one synthetic merge at IDENTITY grain and ask whether the differing rows are generated claims from the same witness families that carry the step variance. Until that artifact exists the two observations are adjacent and unjoined. THE CONSEQUENCE FOR THIS ROW'S REROLL RULE IS UNCHANGED BY THE REFUTATION AND IS STRENGTHENED BY IT: exact head does not fix the drawn population, and it is now known that no appeal to a moving base explains it away. AND IT DOES NOT EXPAND THE REROLL ALLOWANCE, WHICH IS THE READING IT MOST INVITES AND THE ONE THIS SENTENCE EXISTS TO REFUSE: a differing planned cardinality WEAKENS COMPARABILITY between two attempts and lowers confidence that they covered the same claims; it does not license a second draw. The allowance stays at ONE PER EXACT HEAD, consumed on actuation. IT IS NOT PER SIGNATURE, AND SAYING SO WOULD REINTRODUCE A SPELLING THIS ROW ALREADY REFUTED: the signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget key. This finding makes exact head insufficient as a COMPARABILITY IDENTITY; it leaves exact head intact as the deliberately coarse BUDGET KEY, and letting a changed population mint a fresh signature would recreate retry-until-green exactly when the roster becomes unstable. An attempt that falls outside this row's domain spends nothing AND EARNS NOTHING -- it is not a free retry, and treating an ineligible red as though it restored the budget would be retry-until-green reached by a different route than the one this row already forbids. RECEIPT, 2026-09-03, gunbc#10231 -- THE SHARPEST INSTANCE THIS ROW CARRIES, BECAUSE THE VERDICT FLIPPED WHILE THE WORK MEASURE DID NOT MOVE BY ONE STEP. THE SUBJECT MAKES THE POINT BEFORE THE NUMBERS DO: it is a LEDGER-ONLY PROSE PR -- the filing of this row's sibling mechanism class -- touching one authority row and its generated projection, with no code, no types and no gates. A DIFF CATEGORY DOES NOT GRANT COST INNOCENCE BY CONSTRUCTION, and an earlier revision claimed it did: the ledger is ACCEPTED .dag SOURCE here, so altering a large literal can move parsing, resolution, allocation, generated structure or closure work, and shape is not an argument about cost. THE NARROWER CONTROL IS SUFFICIENT AND IS WHAT IS CLAIMED: the diff was IDENTICAL ACROSS BOTH ATTEMPTS, so whatever it costs relative to its base, it cannot explain the attempt-to-attempt flip. Run 33756177727 attempt 1, floor job 100651027559: REFUSED with completed_over_cost_requirement=1 beside claims_failed=0, interrupted_before_verdict=0 and host_tool_unresolved=0 -- one row, wholly inside this row's admitted domain on the two-arm test, with the run's phase verdict carrying no other failed phase. One reroll was actuated and thereby CONSUMED, against a budget of ONE PER EXACT HEAD. Attempt 2, job 100663093895: PASS. THE DISCRIMINATING PAIR, and it is one identity rather than an aggregate: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates measured cpu_ms=523 on the refusing attempt and cpu_ms=404 on the passing one -- a ratio of 1.294 across the 500 line -- WHILE ITS eval_steps IS IDENTICAL AT 169297 ON BOTH. Same head, same tree, same identity, same count of evaluator steps, opposite verdicts. WHAT THAT SUPPORTS, AT THE INSTRUMENT'S REACH AND NOT BEYOND IT: for one fixed identity on one fixed head the cpu-line verdict flipped while the recorded net evaluator-step count stayed exactly identical, so THE CPU VERDICT IS NOT DETERMINED BY eval_steps ALONE -- stronger than showing cpu varies more often than steps, because it exhibits the mismatch at the very identity whose verdict changed. WHAT IT DOES NOT SUPPORT, and an earlier revision asserted it: that the deciding component lies OUTSIDE THE CLAIM'S WORK. Identical eval_steps establishes identical COUNTED EVALUATOR ENTRIES AFTER THIS INSTRUMENT'S NETTING RULE, not identical claim work -- host work, closure work, attribution and cache behaviour are uncounted and remain possible. This row keeps CHARGE-SUBJECT ALIGNMENT open as conjunct (i), so it cannot use this pair to place the varying component outside the claim; that would discharge (i) by assertion. THIS DOES NOT CONTRADICT THE (b) REFUTATION RECORDED ABOVE, and the reconciliation matters because the two readings look opposed: (b) failed because 18 identities of 3519 disagree on eval_steps, NOT because the measure is generally unstable -- 3501 reproduce exactly, and this identity is one of them. A measure can be exact on a given row and still fail an invariance claim asserted over a corpus. A THIRD SAMPLE OF THE SAME IDENTITY EXISTS ON GREEN MAIN, CITED BY RUN AND JOB SO IT IS RE-DERIVABLE RATHER THAN RELAYED: run 33754393519, floor job 100645180812, event push on main head 75873c28978, reports this identity at cpu_ms=406 with eval_steps=169297 -- the SAME step count as both attempts of the episode above, at a third distinct cpu. AND THE ORDERING IS WEAKER THAN AN EARLIER REVISION OF THIS PARAGRAPH CLAIMED, WHICH IS WHY THE CARRIER WAS WORTH DEMANDING. That revision said the identity had been NAMED IN ADVANCE and that a lane had PUBLISHED the crossing arithmetic before the refusal, which made it a prediction. The job timestamps refute that framing: the green-main job ran 12:17:45Z to 12:45:05Z and the refusing attempt ran 12:40:20Z to 13:10:22Z, so THE TWO RUNS OVERLAPPED. The green-main value was therefore observable 25 minutes before the refusal was observed, and it is CORROBORATION AT A THIRD SAMPLE rather than a prediction made before the event. The advance-prediction claim is withdrawn; it was received by relay and no carrier for the publication event was ever produced, which is exactly the transcribed-number failure DESIGN section 6 forbids -- name the producer, never copy its output. A prediction that names the row before it refuses a PR is worth more than a fresh observation of the same event. INDEPENDENT REPLICATION OF THE SPREAD, derived from the per-claim cost artifacts of THIS row's other episode rather than from the reporting lane's run, and it is an INDEPENDENT RUN AND ARTIFACT SAMPLE rather than an independent instrument -- an earlier revision said the two share NO instrument, which is false: they share the required-floor cpu producer, its accounting semantics, the evaluator-step counter and the artifact schema. What they do not share is a run or an artifact, and that is the whole of the independence claimed: over the 556 identities measuring at least 50 cpu-ms in BOTH attempts of one identical tree, the attempt-to-attempt cpu ratio -- DEFINED PER JOINED IDENTITY AS max(cpu_A, cpu_B) / min(cpu_A, cpu_B), so it is direction-free and never below 1.0, stated because an earlier revision published percentiles without the formula and B/A would give materially different numbers -- has median 1.045, p10 1.005, p90 1.219 and MAXIMUM 1.721. THE MEDIAN IS THE UNINTERESTING NUMBER AND THE TAIL IS THE ONE THAT DECIDES VERDICTS -- a corpus whose typical row moves by 4 percent still puts four identities at 94 to 103 percent of budget on a tree that PASSED. WHAT NONE OF THIS ESTABLISHES, stated because this row's trigger asks for exactly the thing it falls short of: A BOUND. Two attempts give a SPREAD, and (ii) requires the basis to be invariant OR BOUNDED BY CONSTRUCTION across the admitted envelopes; a maximum of 1.721 observed over one pair of attempts on one host pair is a FLOOR on the spread, not a bound on it, and the admitted envelope set is wider than the hosts these pairs sampled. THE CONSEQUENCE ON MAIN, MEASURED AT VERDICT GRAIN RATHER THAN AT ROW GRAIN (2026-09-03), because everything above measures ROWS and the thing that costs the fleet its afternoon is the VERDICT. Of the twenty-five most recent `witnesses.yml` runs on `main`, five reported `verdict=FloorRefused` with `claims_failed=0` and `unexpected_failures=0` -- the whole refusal carried by `interrupted_cpu_deadline` and `completed_over_cost_requirement`, so the required floor refused main five times without a single claim disagreeing with the tree. A GATE THAT REFUSES FOR REASONS UNRELATED TO THE CHANGE TEACHES ITS READERS THAT A RED REQUIRED FLOOR IS NOISE, and that is the cost this row had not priced: the sections above price the mis-attribution of a NUMBER to a row, and this one prices the mis-attribution of a VERDICT to a tree. AND THE HOST CORRELATION, STATED AT THE WIDTH THE SAMPLE SUPPORTS AND NOT WIDER. THE DECISIVE MEASUREMENT IS NOT THE HOST TABLE, IT IS A SAME-HEAD CONTROL, and it is stated first because it is established BY CONSTRUCTION rather than by correlation. Run 33806159353 was re-run at the same head: attempt 1 recorded `required-witnesses-floor` FAILURE on runner srv4-14 and attempt 2 recorded SUCCESS on runner srv4-19, both at head 07f81df887a, unchanged between them. ONE TREE, TWO ATTEMPTS, OPPOSITE VERDICTS. Nothing about the subject differed, so the required floor's verdict is demonstrably NOT A PROPERTY OF THE TREE -- which is this row's whole subject, now shown rather than inferred, and shown without needing any closure argument because nothing changed. THE HOST TABLE IS THE WEAKER EVIDENCE AND ITS FAMILY-SHAPED READINGS ARE REFUTED, twice, in the same direction. Eleven `required-witnesses-floor` jobs by runner registration: seven failed (srv1-02, srv1-07, srv1-10, srv1-16, srv1-17, srv4-11, srv4-14) and four passed (srv3-02, srv3-04, srv3-10, srv4-19). A first reading said srv1 is the bad host and srv4-11 refuted it; a second said srv3 is the only host observed clearing the ceiling and srv4-19 refuted that too, since srv4 now does BOTH. BOTH READINGS GENERALISED A HOST FAMILY FROM MACHINE-LEVEL SAMPLES AND THE NEXT SAMPLE CROSSED THE LINE EACH TIME, which is why the surviving statement names no family at all. WHAT THE MEASUREMENTS SUPPORT, AND NOTHING WIDER: the verdict is not a property of the tree; it is not cleanly a property of the host family; THE ACTUAL VARIABLE IS UNIDENTIFIED, with machine-level load or moment and a per-machine difference both consistent with the data, and eleven samples cannot separate them. Naming a cause here would be the looks-principled-and-is-not move this row already refuses on the calibration arm. MISSING ITEM (b) IS NOW DISCHARGED OVER THE MEASURABLE POPULATION AND THE ROW STILL STANDS, and the reason it still stands is the more useful half. THE JOIN (warm-seal-35, over the two attempts above): 338 shared-fill per-claim rows on each side, joined ON IDENTITY with ZERO unmatched rows in either direction, `marginal_eval_steps` and `measured_eval_steps` IDENTICAL for all 338, while measured cpu-ms moved by more than ten percent on 124 of them and spanned 0.627 to 1.217 as an attempt-2-over-attempt-1 ratio. That is (b) as worded -- an exact identity join of the step column across two attempts of ONE IDENTICAL TREE, with the cpu column moving and this one not -- and it is a population rather than a subject, which is what separates it from the single-claim reading above. ITS DENOMINATOR IS NOT THE FLOOR, AND QUOTING IT AS WHOLE-FLOOR COVERAGE WOULD BE THE ERROR THIS ROW EXISTS TO REFUSE: both attempts executed 3585 claims and the shared-fill instrument reports per-claim cost for 338 of them, so the join covers 9.4 percent and is silent about the rest. THE EXCLUSION IS THE FINDING, NOT A CAVEAT ON IT, AND IT IS SHARPER THAN THE CONSTRAINT PREDICTED ABOVE. An interrupted row is unmeasured in steps by construction, so the join can only cover completed rows -- and the rows it therefore excludes are EXACTLY THE ROWS THAT DECIDED THE VERDICT. Attempt 1 recorded passed=3507 with interrupted_before_verdict=2 and completed_over_cost_requirement=1 and refused; attempt 2 recorded passed=3510 with both counters at zero and was clean. 3507 plus 2 plus 1 is 3510: the three rows are precisely the difference between the two attempts, and they are precisely the rows no step measurement can speak about. THE MORE A CLAIM IS AFFECTED, THE LESS MEASURABLE IT BECOMES. So the join establishes that 338 OTHER claims did identical work under a moving envelope -- strong evidence about the envelope, and NO evidence about the three. WHICH IS A CONSTRAINT ON MISSING ITEM (a) AND NOT ONLY ON (b), and it is the first thing this row has been able to say about (a) at all: A STEP-DENOMINATED LINE BUILT ON THIS INSTRUMENT WOULD BE BLIND IN EXACTLY ITS OWN SUBJECT DIRECTION, because the rows that would cross such a line are the rows that carry no step count. Sizing one from the measurable population would produce a threshold that looks principled and is derived from the rows that were never at issue. EVIDENCE GRADES, KEPT SEPARATE AS EVERYWHERE ELSE IN THIS ROW. The two attempt summaries and their arithmetic were read FIRST-HAND from the run at two different times, attempt 1 while it was the only attempt and attempt 2 after the re-run; the 338-row join is taken from its builder with its own disclosed method corrections and was not re-derived here, because the attempt-1 log archive returns a truncated response that will not open. A CITATION TRAP WAS OBSERVED WHILE CHECKING THIS AND IS RECORDED SO THE NEXT READER DOES NOT LOSE AN HOUR TO IT: a bare job id serves the LATEST attempt, so job 100817014187 -- whose own conclusion is failure -- now serves attempt 2 FloorClean summary. An attempt-level citation is the only stable one. AND THE DISPOSITION GETS MORE DEFENSIBLE RATHER THAN LESS: a ceiling whose verdict flips on ONE UNCHANGED TREE between two attempts thirty-six minutes apart is not something a fifth shave of the claim would fix, which is the measured form of the argument that four prior lanes closed on the claim and it fired again. WHAT IS ESTABLISHED PER SAMPLE DIFFERS AND IS NOT FLATTENED: the `claims_failed=0` / `unexpected_failures=0` signature was read from the run logs for six of the seven failures, srv4-11 being the one taken on report rather than read. The distinction is kept because this carrier's own subject is a verdict being attributed to the wrong thing, and a floor job can redden on a phase that is not the floor -- so FAILED and FAILED-WITH-THIS-SIGNATURE are different facts and the row says which it has. A ONE-SUBJECT CROSS-ENVELOPE READING, WHICH BEARS ON MISSING ITEM (b) AND DOES NOT DISCHARGE IT (calm-deer-33, 2026-09-03, verified here rather than relayed). `v2.test.emit.rust_produced_decl_emit.produced_decl_unwired_target_still_refuses` measured 165802 eval_steps at 346 cpu-ms on run 33802603168 and 165802 eval_steps at 514 cpu-ms on run 33806159353 -- the step count IDENTICAL to the digit while cpu moved 1.49x, and the second reading is the one that crossed into completed-over-budget. Log-line controls of 3472 and 3465 rule out an empty capture on either side, which is this repository's standing guard against a zero that reads as a clean sweep. WHY IT IS NOT (b), ON THREE COUNTS, AND THE THIRD IS THE ONE A LATER READER WILL MISS. (i) GRAIN: (b) asks for a join AT CORPUS GRAIN and this is one subject. (ii) SUBJECT: (b) asks for TWO ATTEMPTS OF ONE IDENTICAL TREE, and these are two different trees -- 8b2323f is an ANCESTOR of 07f81df, so the pull request adds commits on top of the main commit it is compared against. (iii) THE WARRANT FOR THE-WORK-DID-NOT-CHANGE CANNOT COME FROM THE STEP COUNT ITSELF: constant steps are read as envelope-independence only if the work is identical on INDEPENDENT grounds, since a measure insensitive to the change produces the same reading. TWO ATTEMPTS OF ONE IDENTICAL TREE supplies that warrant BY CONSTRUCTION, which is why (b) is written that way. ACROSS TWO TREES IT WAS SUPPLIED SEPARATELY AND (iii) IS ANSWERED, by two arguments that do not depend on each other, both re-derived here rather than relayed. FIRST, A SYMBOL-GRAIN JOIN: the whole diff between the compared trees touches three files and adds or removes six declarations -- `absence_classifier_default_bucket`, `green_reported_over_a_population_the_instrument_does_not_own`, `live_03_normalize_data_inits`, `live_03_normalize_facts`, `live_argument_threaded_past_the_arm_that_decides` and `effect_reach_live_03_normalize_witness_derived_host_reading_holds` -- and the module declaring the measured claim, `v2.test.claim.emit.produced_decl_two_target_test`, references none of the six, with a positive control on the same grep finding `tt_emit`, `tt_emits` and `tt_refuses` there. SYMBOL GRAIN RATHER THAN IMPORT CLOSURE IS LOAD-BEARING IN THIS SUBSTRATE: names resolve by global uniqueness rather than by import lists, so a name absent from every import list still resolves and an import-closure argument would exclude modules that can still supply a binding. SECOND, AND INDEPENDENT OF WHETHER THAT JOIN IS EXHAUSTIVE: the diff is NET NEGATIVE, 32 insertions against 60 deletions, and the only witness change DELETES a row, so any corpus-scale work effect would push this claim CHEAPER while the observation is 1.49x MORE EXPENSIVE. The move is in the wrong direction for every work-based explanation. A CONSTRAINT ON HOW (b) CAN EVER BE DISCHARGED, WHICH IS A PROPERTY OF THE COLUMN AND NOT OF TONIGHT. An INTERRUPTED row is unmeasured in `eval_steps` BY CONSTRUCTION -- the poll fires before a count exists -- so a corpus-grain identity join over this column has a STRUCTURALLY EXCLUDED SUBPOPULATION, and the excluded rows are precisely the expensive ones the join most needs to cover. (b) as worded may therefore not be buildable at full coverage at all. A LATER LANE THAT BUILDS IT OVER COMPLETED ROWS AND REPORTS COVERAGE WILL BE REPORTING OVER A POPULATION IT DOES NOT OWN, which is `gunbc.recurring_failure_mode` `green_reported_over_a_population_the_instrument_does_not_own` -- so the honest discharge of (b) must either state the exclusion as part of its result or reach the interrupted rows by a different measure, and a coverage figure over completed rows alone does not retire this row. WHAT IT DOES ESTABLISH is still an advance on what this row had: the invariance reading was previously grounded at FIXTURE grain and nowhere wider, and this extends it to a live corpus subject under real floor pressure. Recorded as that and not as more. IT WAS MEASURED FORWARD, WHICH IS THE ONLY REASON IT IS RECORDED AT ALL: a prediction that srv1-10 would fail and srv3-10 would pass was registered before either returned, and runs 33794985110 and 33796487867 held it. WHAT IT IS NOT IS AN EXPLANATION. A SLOWER HOST is a hypothesis with no mechanism attached, three passes on one host is a thin denominator, and neither this correlation nor a wider one discharges (i), (ii) or (iii) of the trigger below -- a basis that varies with the machine is exactly what (ii) asks to be rid of, so measuring WHICH machines it varies with sharpens the subject and closes none of it. NOT PROPOSED HERE, AND THE DISTINCTION IS THE SAME ONE THIS ROW HAS MADE THROUGHOUT: raising the 500 line would change which rows cross and would not make the crossing a property of the claim, so it does not retire this row and is not requested. +Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim cost qualification at the subject grain the gate consumes. THIS ROW NAMES NO CAUSE, AND ITS EARLIER NAME DID -- it was `floor_cost_contention_verdict`, which asserted contention as the mechanism when the evidence establishes only that the charge is not a stable property of the claim. Renamed rather than reworded, because a row identity that carries a refuted attribution is cited onward as if the attribution were the finding. WHAT IS LOST: an attempt's CPU duration cannot be read as an invariant property of the witness, nor as proof of a witness-owned regression. the 500ms CPU line this row was declared over (now `required_floor_per_subject_cpu_line_ms`, which is still CPU milliseconds and still compared to a CPU reading by the enrolment margin, both as the ceiling its budget must sit below and as the line a live Roster (typed cost-debt) ground must clear, `v2.workflow.floor_enrolment_margin` `enrolment_declared_measured_standing`; the claim ceiling's own 500 moved to `required_floor_claim_work_envelope_ms`, a policy in milliseconds of work that no clock is compared to) was a cpu-ms literal compared against a measurement that is not a stable property of the claim. WHAT THE CHARGE IS MADE OF, MEASURED RATHER THAN ATTRIBUTED, and this is the whole of what this row asserts about mechanism: it contains a CLOSURE-LEVEL COMPONENT insensitive to the claim's own assertion work, and an EXECUTION-POSITION-SENSITIVE COMPONENT whose cause and bound are NOT established. Neither component is named as contention, memory pressure or warm-up here, because no evidence in hand separates those, and NO BOUND HAS BEEN ESTABLISHED -- which is a different statement from an unbounded cause and must not be read as one. THE MEASUREMENT IS NOT WRONG AND THIS ROW DOES NOT SAY SO: it is a VALID observation of THIS EXECUTION ATTEMPT. What it is not is a stable observation of the claim as an isolated subject, and only the second reading is what a cost verdict needs. WHAT REMAINS, AND STAYS REQUIRED: the 500ms attempt-safety stop, and fail-closed treatment of a required claim that produced no verdict. The position-sensitive component disqualifies the deadline as an INTRINSIC CLAIM-COST VERDICT; it does not disqualify it as a REQUIRED ATTEMPT-SAFETY AND VERDICT-AVAILABILITY criterion. Both terminal arms stay required reds and are distinct: an interrupted attempt means the required claim never produced a semantic verdict, and a completed-past-limit attempt means it crossed the declared safety envelope. Neither proves the witness intrinsically costs more than the limit, that it regressed, that it owns the observed excess, or that it belongs in permanent cost debt. False refusals are an AVAILABILITY loss that fails closed, and removing the deadline would let genuinely runaway evaluation consume the executor without bound. PREVIOUS RUNG: none for environment-independent claim-cost qualification -- that guarantee was never held, and saying it was would be inventing a rung to drop from. Mechanically preventable remains TRUE and undropped for attempt safety. TEMPORARY RUNG: claim-cost qualification UNAVAILABLE; verdict availability environment-sensitive; acceptance still fail-closed. REASON, and the three negative results that make this a capability claim rather than a shrug. (1) THE BASIS IS ALREADY CPU BY DECLARATION: `required_floor_cost_basis` returns `CpuCost` because these claims execute Hermetic, so 'judge cpu rather than wall' is DONE and what remains is cpu-time variance itself. (2) THE OBVIOUS CALIBRATOR IS REFUTED BY MEASUREMENT, and this is the sentence that stops the trigger being discharged by pointing at what we already measure: THE PREPARATION WARM PHASES ARE NOT A CALIBRATOR. Across main and two attempts of one identical tree, `pool-root-index-warm` measured 693 / 727 / 596 cpu-ms and `languages-consumer-census-warm` measured 858 / 606 / 531, so on the attempt whose CLAIMS ran hottest the census phase ran COLDER than main's. They do not track claim inflation. (3) NO CALIBRATION CONCEPT EXISTS IN THE REPOSITORY AT ALL. Normalizing by a quantity that does not track the machine would produce a threshold that LOOKS principled and is not, which is strictly worse than the honest literal. POPULATION -- THE CLOSED SUBJECT UNIVERSE IS NOT A THRESHOLD-SELECTED SET, AND THIS ROW SAID OTHERWISE FOR TWO REVISIONS. The universe is EVERY REQUIRED IDENTITY FOR WHICH THE CPU DEADLINE IS ARMED. That is closed, decidable from the run's own plan, and it does not move with anyone's measurement. WHY THE THRESHOLD SET IS NOT THAT UNIVERSE: the position-sensitive term has no established bound, so NO lower threshold can prove the rows beneath it unaffected. A set selected by 'measured cpu at or above N' is a VIEW whose membership is a property of the MEASUREMENT rather than of the subject, and letting a decidable admission predicate's output stand in for the class's population joins two different objects by an assumption. The predicate was the right answer to a censored-parameter refusal and the wrong answer to 'what is the population'. THE THRESHOLD SET SURVIVES AS AN EXPOSED ATTENTION SUBSET, which is what it is good for: prioritising optimisation and isolation work. Admission is measured cpu at or above the attention constant -- 219ms against the 500ms ceiling, the ceiling over the largest inflation floor observed to date -- and the constant is spelled ONCE here, with every later reference in this row naming it rather than repeating the digits, because a constant that has already moved twice in one day reforks the row on its next revision if it is spelled in three places. THAT SINGLE-SPELLING DISCIPLINE IS PROSE AND NOT STRUCTURE: `RungDrop` carries no numeric field, so nothing refuses a future revision that updates one mention and not another. That missing field is this discipline's next rung. THE ATTENTION CONSTANT'S OWN DERIVATION AND REVISION CONDITION: it is the ceiling over an inflation FLOOR, and a floor is not the inflation, so the constant MUST BE RE-DERIVED THE MOMENT A LARGER FLOOR IS MEASURED. RE-DERIVED 2026-09-03, BY THAT CONDITION AND BY NOTHING ELSE. The floor was 1.777 from a single identity join -- `v2.test.execution.emit_host_meet_join_equals_eval.emit_host_meet_wrong_fixture_refuses_holds` measured 501 cpu-ms on one attempt and 282 on a re-run of THE SAME TREE with nothing changed -- which is ONE PAIR, and one pair is one sample of a between-run quantity and therefore has no spread at all. A LARGER FLOOR IS NOW MEASURED OVER A SAMPLE THAT INDEXES OVER RUNS: 2.280, the worst per-identity max-over-min across TWELVE green `main` runs of `witnesses.yml` on twelve distinct runner registrations across three hosts, restricted to identities present in every run with a verdict, a baseline at or above 50 cpu-ms, and equal `eval_steps` in all twelve. THAT LAST RESTRICTION IS A FILTER AND NOT A FINDING, and the distinction matters here more than anywhere because MISSING ITEM (b) BELOW MEASURED THE SAME COLUMN AND REFUTED ITS INVARIANCE: selecting rows whose steps agree removes tree movement from the sample so the residual is inflation, and it establishes nothing about whether steps are invariant in general -- they are not. 500 over 2.280 floors to the constant above. THE PRODUCER IS NAMED AND THE DIGITS ARE NOT THE AUTHORITY: `gunbc.floor_cost_distribution` `worst_envelope_permille` over `work_invariant_envelopes` of `complete_envelopes`, driven by `tools.floor_cost_distribution_instrument` `floor_cost_envelope_report`, whose sampled runs and their runners are data in `floor_cost_envelope_sampled_runs`. This is the modeled producer the paragraph below says does not exist for the SUBSET; it exists for the CONSTANT'S INPUT and not for the subset, and those are different gaps. ROBUST IN DIRECTION AND NOT ONLY IN VALUE: restricting the same derivation to rows at or above 200 cpu-ms, where whole-millisecond quantisation cannot dominate, gives 1.874 and a constant of 266ms -- still below the superseded 280, so the re-derivation does not rest on the small-baseline tail. STILL A FLOOR: twelve runs on three hosts are a SUBSET of the admitted execution envelopes, so 2.280 can only rise and this constant can only fall. AND THE EXTREMES ARE CONCENTRATED ON PARTICULAR MACHINES, which a median run factor cannot see because a median is robust exactly where the envelope is driven: `run_extreme_census` over the same population reports one run holding the MINIMUM for 367 of 398 rows and one host holding the MAXIMUM for 279 of 398 from three of twelve runs, while per-run median factors span only 0.878 to 1.118. That is this row's own subject measured at host grain. Its predecessor was falsified within the hour for exactly this reason: sized at 400 against a floor of 1.196, it EXCLUDED the one row this class has been observed to trip on the completed-past-limit arm, and an admission rule that omits a known member is wrong at its own grain. TWO OBJECTS, ONE MONOTONE AND ONE NOT, AND THIS ROW PREVIOUSLY CONFLATED THEM: the EVIDENCE FLOOR is monotone -- the largest observed inflation floor can only rise, so the constant derived from it can only fall. THE MEMBERSHIP SET IS NOT MONOTONE: individual identities enter and leave the attention subset as their measured attempt costs vary, which is exactly what makes it a view rather than a population. Monotonicity of the first gives nothing about the second. ON THE NAMED RUN, AT THE SUPERSEDED 280ms CONSTANT AND NOT AT THE ONE ABOVE -- the enumeration is kept as the receipt of what was measured and must not be read as today's subset, which is larger at a lower constant (gunbc#9840 head 85c4a307, required-witnesses-floor, second attempt, 3381 executed rows) the attention subset holds 53 identities across 21 modules, the largest groups being `test.claim.compiler_frontend_program_status_witness` (9), `v2.test.execution.emit_host_meet_join_equals_eval` (4), `v2.test.emit.rust_body_add_emit` (4) and `v2.test.emit.rust_binop_emit` (4). THE SUBSET IS A MANUAL DERIVATION AND NOT AN EXPOSED RUN PRODUCT, AND AN EARLIER REVISION OF THIS ROW OVERCLAIMED IT. The enumeration above was computed BY HAND by reading a run's uploaded `required_floor_claim_cost.tsv` and filtering on the attention constant. NO MODELED FIELD, FUNCTION OR REPORT PRODUCES IT: the constant lives only in this prose, `RungDrop` carries no numeric field to hold it, and nothing consumes it -- so saying the artifact 'reports the subset' asserted an executable relationship that does not exist. WHAT WOULD MAKE IT A PRODUCER, and it is a carrier gap rather than a missing script: the constant modeled as a declaration, and the per-claim cost artifact modeled as data a function can read, at which point the subset is a fold and this paragraph becomes its projection. Neither exists today, and a hand-run filter described as a run product is the specification-without-execution DESIGN section 5 names -- which is why this row now says which of the two it is. THE CONSTANT SITS ON THE STEEPEST PART OF THE COST CURVE and must not be read as a measured threshold: 12 rows reach 400, 16 reach 350, 43 reach 300, 50 reach 290 and 53 reach 280 -- seven rows arrive in a 10ms interval, and 1388 rows measure zero. That histogram is that run's, at the superseded constant; on the twelve-run sample above, taking each identity's MAX over the twelve, 88 identities reach 280 and 158 reach the constant now standing, and the same doubling holds within a single run rather than only in the union (run 33754393519: 61 then 115; run 33775106554: 73 then 128; run 33766436293: 20 then 72). Lowering the constant roughly doubles the subset, which is the cost of the re-derivation stated rather than left for a reader to discover. WHAT LANDED TOWARD THE TRIGGER, AND WHY THIS ROW IS STILL STANDING. The deterministic-work-measure arm now EXISTS AS AN INSTRUMENT and does NOT yet exist AS A BASIS, and those are different things. `v1.interpreter` counts one evaluator step per `eval_expr` entry, UNCONDITIONALLY -- not under the profiling flag, because a measure available only in an instrumented envelope is not available in the envelopes this row is about -- and `run_claim_measured` takes the per-claim delta and nets stored shared-artifact fills out of it by exactly the rule the CPU clock is netted by. WHAT THAT NETTING BUYS, STATED AT THE WIDTH THE EVIDENCE SUPPORTS AND NOT WIDER: the net count is not determined by WHICH TESTED CLAIM PAYS THE MODELED SHARED-ARTIFACT FILL. That is ONE modeled path. It is NOT independence from arbitrary corpus execution order, which is unmeasured and which this row's own missing-item (b) below still names as owed; an earlier revision of this sentence claimed the broad property and contradicted that boundary paragraph two sentences later. It reaches `PerformanceReceipt.eval_steps`, the `[over-cost]` line, and an `eval_steps` column in the per-claim cost artifact. ITS EVIDENCE IS EXECUTED AND DISCRIMINATING, and it is enrolled rather than described: `evaluator_step_work_measure_tests` asserts EXACT equality of the count across two genuinely different envelopes -- one arm with the CPU deadline ARMED, which takes a different path through `eval_expr`, under a co-tenant thread spinning for the whole evaluation -- beside a work control at a different fixture size, so a counter frozen at any constant including zero fails; and a netting arm in which the claim that PAYS a shared fill and the claim that reads it warm are asserted to carry the SAME marginal count while their RAW counts are asserted to differ by more than a factor of ten, so the netted equality is not two identical numbers compared. NOTHING COMPARES THE COLUMN AGAINST A LINE, AND THAT IS DELIBERATE RATHER THAN UNFINISHED. The trigger asks for a claim-owned cost BASIS; a column no verdict reads is a measurement and not a basis, and calling this row retired on the strength of a published column would be exactly the rung inflation 4b(1) forbids. TWO THINGS ARE STILL MISSING and neither is bought by more prose. (a) A STEP-DENOMINATED LINE, which cannot be sized from this tree today because no run has yet published the distribution that the column now makes publishable -- and inventing one would be the same looks-principled-and-is-not threshold this row already refuses on the calibration arm. (b) THE CROSS-ENVELOPE A/B ON THE SHARED RUNNER AT CORPUS GRAIN: an identity join of `eval_steps` across two attempts of one identical tree, where the cpu column moves and this one must not. Until (b) is measured the invariance claim is grounded at FIXTURE grain and nowhere wider, which is the honest reading of what landed. THE CPU DEADLINE IS UNCHANGED BY ALL OF THIS: it is still the armed enforcement clock, still denominated in cpu-ms, and the new column changes no threshold and no verdict. RESTORATION TRIGGER, A CONJUNCTION AND NOT A MENU. An earlier revision offered three ALTERNATIVE arms -- isolation, a deterministic work measure, or a calibrated relative basis -- and that disjunction is refuted by the composition measured above: isolation can stabilise the WRONG SUBJECT, a deterministic measure can count the wrong subject EXACTLY, and calibration can normalise a WRONGLY ALLOCATED charge. Each arm answers a different one of three independent questions, so any one alone leaves the other two open. ALL THREE MUST HOLD. (i) CHARGE SUBJECT ALIGNED: the marginal claim work is separated from the closure-level component, OR the gate is honestly rehomed to closure identity and stops claiming to judge claims. (ii) BASIS INVARIANT OR BOUNDED BY CONSTRUCTION across execution POSITION and envelope, demonstrated by EXACT IDENTITY JOINS rather than by aggregates -- a median over a corpus cannot see a windowed effect, which is the specific error that produced this row's revision. (iii) POLICY LINE GROUNDED over the independently defined FULL population and CONSUMED AT THE SAME SUBJECT GRAIN it was derived at. A basis satisfying (ii) while the gate consumes it at a grain it was not derived for is the same defect wearing better numbers. TWO CONTROLS THAT WOULD DISCHARGE (i) AND (ii), named so the next lane does not have to re-derive them. POSITION CONTROL: the same exact tree and population, a deterministic ORDER ROTATION carrying the same identities through both the early inflated region and the flat tail, cpu allowed to move, and net eval_steps required to remain IDENTICAL by identity join. CHARGE-SUBJECT CONTROL: two claims in ONE closure with materially different assertion work -- do marginal eval_steps discriminate them? The ordinary larger-fixture-takes-more-steps control proves the counter is ALIVE and does NOT prove the steps belong to the claim rather than to its closure, and this row previously leaned on the first as if it answered the second. IF THE SAME-CLOSURE DIFFERENTIAL IS CONSTANT, THE ANSWER IS NOT A STEP THRESHOLD AT CLAIM GRAIN: rehome the policy to closure identity or subtract the closure component explicitly. AND DO NOT TRANSLATE THE 500 CPU-MS LINE INTO STEPS USING THE PER-CLAIM MEASURED CPU DISTRIBUTION, which carries the position-sensitive component this row exists to declare. THE QUALIFIER IS LOAD-BEARING AND WAS ADDED BY RULING (fierce-lark-661, 2026-09-13, on gunbc#11195) BECAUSE THE UNQUALIFIED SENTENCE FORBADE MORE THAN ITS EVIDENCE SUPPORTS -- DESIGN section 4d's over-prohibition arm, whose cost is the thing nobody does. WHAT IS FORBIDDEN is deriving a claim's budget from the population's own CPU readings: that is the run-varying, position-sensitive quantity, and a budget consuming it inherits the defect AND makes a verdict vary between runs. WHAT IS ADMITTED is a SINGLE CONTROLLED READING pinned as a POLICY CONSTANT -- `v2.workflow.floor_eval_step_calibration` -- taken on a fixture whose work is fixed by source rather than by the corpus. The discriminator is not the unit but the DEPENDENCE: an error in a pinned constant mis-scales BOTH tiers ONCE and UNIFORMLY and cannot make one claim's verdict differ between two runs of the same tree, which is precisely the property the denominator change buys and precisely what the per-claim distribution cannot offer. A RE-PIN RESCALES EVERY BUDGET UNIFORMLY AND NEVER ONE CLAIM, so it is a policy act taken deliberately and never maintenance. A SEPARATE CAPABILITY BOUND, RECORDED HERE AND EXPLICITLY NOT THIS ROW'S CAUSE: a shared artifact fill paid inside a claim's measured window before preemption bounds what any deadline mechanism can promise about attribution. PAYER TRANSFER IS REFUTED FOR THIS INCIDENT -- the red run's own `[floor-shared-fill]` ledger carries no `paid_by` line naming the module that tripped, the whole module shifted uniformly by 8 to 11 percent rather than one row taking a lump, and the rows that crossed sat mid-pack on the green attempt. It is a bound on the mechanism, not an explanation of these observations, and it is not this row's population producer. RAISING THE CEILING DOES NOT RETIRE THIS ROW AND IS NOT PROPOSED: 'the comparison does not qualify the claim' and 'the threshold is too low' are different claims, and only the first is recorded here. NOT PROPOSED EITHER: re-running an undecided row until it answers is retry-until-green -- fail-open wearing a fail-closed label -- admissible only as a counted, visible mitigation carrying this row's trigger as its dissolution condition. RECEIPT, 2026-09-02, AND THE MITIGATION THE SENTENCE ABOVE ADMITS CONDITIONALLY IS HEREBY MADE VISIBLE RATHER THAN LEFT IMPLICIT. Rerolling a refused required floor job has been in continuous informal use across this board today under a bounded rule -- at most one reroll per head, and only where the refusal is carried entirely by this row's two arms. THAT RULE WAS MIS-SPELLED AND MIS-EVIDENCED WHEN FIRST WRITTEN, AND BOTH DEFECTS ARE CORRECTED HERE RATHER THAN QUIETLY RESPELLED. It read `one reroll per head per signature`, which parses as a COUNTER KEY -- so many rerolls per distinct signature -- and that reading is self-defeating on this row's own claim: these arms vary across attempts of one unchanged tree, so A CHANGED SIGNATURE IS THE EXPECTED OUTCOME OF A REROLL rather than new information, and every reroll would license the next one for exactly the reason this row exists. The signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget. The budget is ONE, PER HEAD. AND THE ELIGIBILITY TEST MUST NOT BE EVALUATED AGAINST THIS CLASS'S OWN COUNTERS. It said `the run reported failed=0`, which was read off the floor's disposition counters; those enumerate COST dispositions and do not range over other phases, so they cannot report that anything else failed and the test could only ever confirm itself. THE RULE STATED SO IT SURVIVES THE SPELLING: ELIGIBILITY IS A PROPERTY OF THE RUN'S PHASE VERDICT AND IS NEVER READ OFF A CLASS'S OWN DISPOSITION COUNTERS, whatever either is called. The quotation `failed=0` above is preserved as a RECEIPT of what a run actually printed on 2026-09-02 and must not be restated as the current key: at the time, one word `failed` carried FOUR SUBJECTS across four emitters of one binary -- lane phases, required-floor claims, DISCOVERY ROWS, and a package LIST -- which is why an inside-the-subject reading looked like an outside-the-subject one. THE DISCOVERY SUBJECT IS THE ONE THAT MATTERS AND IT IS NOT A NARROWER OR WIDER SPELLING OF THE CLAIM POPULATION: it is a DIFFERENT population that additionally absorbs NotBool, RuntimeError, HostToolUnresolved, timeout, panic and NotAttempted, so a reader treating the two as the same word silently unions failure classes the other excludes. That fork is being repaired at the producer by a separate lane, into `phases_failed`, `claims_failed`, `discovery_rows_failed` and `packages_failed`, with `FAILED PHASE` unchanged; this row therefore names the phase verdict as the adjudicating SURFACE rather than any counter key. Eligibility is decided by the RUN'S PHASE VERDICT -- `phases_run`, `failed`, and the `FAILED PHASE` lines -- which is evidence from outside the predicate's own subject. The class is `admission_predicate_evidenced_from_inside_its_own_subject`. Bounded is better than retry-until-green, and it was still NOT the admitted arm, because nothing enumerated the instances and nothing carried this row's trigger as their dissolution condition. This paragraph is that enumeration. DISSOLUTION CONDITION: this row's own RESTORATION TRIGGER and nothing short of it -- a claim-owned cost basis whose value is invariant, or bounded by construction, across the admitted execution envelopes. When that lands, the reroll has no subject and this paragraph goes with it. INSTANCES, CITED BY RUN ID SO EACH IS REACHABLE AND FALSIFIABLE RATHER THAN TALLIED: gunbc#9984 run 33604337589 attempts 1 and 2 on head 9b00e24f592 (refuse then pass; `interrupted_before_verdict` 4 then 0, `completed_over_cost_requirement` 3 then 0, `planned=executed=3486` and `failed=0` on both); gunbc#10022 run 33615900632 attempts 1 and 2 on head c2c1db141a (refuse then pass, two undecided rows in `test.claim.self_host_compile_phase_live_gate_witness`); gunbc#9954 commit 53088562e30 (`interrupted_before_verdict=15`, `completed_over_cost_requirement=0`, `failed=0` -- the largest single observation, and purely the non-verdict arm); gunbc#10044 run 33618811753 attempts 1 and 2 on head 2d42cca4b94 by session eager-ferret-714's lane (refuse THEN REFUSE on one tree with different accounting -- `interrupted` 2 then 4, `over_cost` 0 then 2); and gunbc#10044 run 33619277245 attempts 1 and 2 on head 0e9b1518b7b (refuse then refuse; `interrupted` 5 then 2, `over_cost` 4 then 0, `planned=executed=3477` and `failed=0` on both); gunbc#10047 run 33622971872 attempt 2 on head 1aa6d8f41dc (attempt 1 refused at 502ms on `v2.test.emit.rust_binop_emit.rust_binop_producer_emit_sub_holds`, a module carrying four identities in this row's own attention subset -- so the roster PREDICTED the row that blocked that PR, which is a stronger receipt than a fresh observation); gunbc#9986 at f5fca17678f (`planned=executed=3503`, `failed=0`, `interrupted_before_verdict=2` in `test.claim.compiler_frontend_program_status_witness` and `test.claim.self_host_compile_phase_frontier_witness` -- NEITHER in the live-gate family, on a head that had ALREADY taken 2d76d9ccb33, which is what establishes the arm is not confined to a repairable family); and gunbc#10044 run 33628404336 attempts 1 and 2 on head 03780b8c76c, floor jobs 100219422472 and 100256793010 (REFUSE THEN REFUSE at ONE ROW EACH, `failed=0` and `planned=executed=3486` on both, `interrupted_cpu_deadline=1` -- but attempt 1's row was `v2.test.emit.produced_decl_two_target` and attempt 2's was `v2.test.execution.emit_host_module_equals_eval`, a DIFFERENT identity at the same count). AND ONE FURTHER PAIR, ENTERED MARKED BECAUSE ITS ADMISSION WAS INVALID AND THAT IS PRECISELY WHY IT IS KEPT: gunbc#10077 run 33647114048, floor job 100317014535, head 74719e46dd, both attempts `planned=executed=3487` with no unexpected claim failures -- attempt 1 `interrupted_before_verdict=12` (all `interrupted_cpu_deadline`), `completed_over_cost_requirement=0`; attempt 2 `interrupted_before_verdict=1`, `completed_over_cost_requirement=2`. Refuse then refuse. All twelve of attempt 1's rows sit in `test.claim.self_host_compile_phase_frontier_witness` and `test.claim.self_host_compile_phase_live_gate_witness`, EACH MEASURED 501 TO 506 CPU-MS AGAINST THE 500MS LIMIT -- a one-to-six millisecond miss, which is the sharpest evidence this row has for its own claim: a witness failing at 900ms would be consistent with genuinely costing that much, and one failing at 501 is not. THE ADMISSION WAS FALSE WHEN IT WAS MADE. The run was `phases_run=3 failed=2`, refusing on the floor AND on `namespace-wave-admission` with 57 unadjudicated deltas, so the refusal was never carried entirely by this row's two arms; the eligibility test had been evaluated against the floor's own disposition counters, which cannot report that another phase failed. IT IS ENTERED RATHER THAN REPLACED BY A CLEANER RUN, and the reason is structural: a clean run cannot evidence a defective admission predicate, so this is the only receipt that the rule was broken, and dropping it for being untidy would filter the mitigation's record by how the mitigation turned out. WHAT IT DOES NOT ESTABLISH, stated because the counts invite it: attempt 2's single interrupted row was ALSO IN attempt 1's twelve, so the pair is a SUBSET and not a disjoint redraw, and a stable population straddling the threshold explains both attempts without any redraw at all -- one module in this run carries members at 481, 490, 499, 500 and 501 ms. The counts moved; the membership did not leave the prior set. An earlier reading of this pair asserted that a fixed marginal set could not produce those counts; that assertion was withdrawn by its own author on the membership measurement before it was entered here. THAT LAST PAIR IS SUGGESTIVE AND DOES NOT SETTLE IT ALONE, WHICH IS WORTH SAYING BECAUSE THE OVERSTATED VERSION WAS WRITTEN HERE FIRST: two draws showing DIFFERENT identities at n=1 per side are equally consistent with a FIXED set of marginal rows sitting so close to the deadline that ordering decides which one crosses. Identity change alone does not discriminate those two explanations. WHAT DISCRIMINATES IS THAT THE COUNT MOVES AS WELL AS THE MEMBERSHIP, across the instances above taken jointly: 4 then 0, 5 then 2, 1 then 1, 2 then 4, and 15. A fixed marginal set would have to explain a count ranging over 0, 1, 2, 4, 5 and 15 AND the membership changing; a population redrawn per attempt explains both, and near-threshold ordering explains only the second. So the redraw reading is CORROBORATED BY THE INSTANCES JOINTLY rather than established by any one pair -- and the load-bearing consequence survives either way, because on both readings no enumeration of the expensive claims can be the population, family-by-family cost repair lowers incidence without bounding the class, and a green reroll is not evidence the refused row was wrong. ; and gunbc#9986 run 33655367446 attempts 1 and 2 on head 2ee252f3339 (REFUSE THEN CLEAN, the mitigation's only successful roll recorded here: attempt 1 `interrupted_before_verdict=15` all `cpu_deadline`, attempt 2 `interrupted_before_verdict=0`, with `planned=executed=terminal=3504` and `failed=0` on BOTH -- and every one of the 15 sat in `test.claim.self_host_compile_phase_frontier_witness` or `test.claim.self_host_compile_phase_live_gate_witness`, neither of which that change touched. 15 equals the largest prior observation (gunbc#9954) on an unrelated tree, and the previous head of this same PR showed 2, so the amplitude moved by an order of magnitude across a main merge alone). THIS INSTANCE WAS ENUMERATED BY THE LANDING MANAGER RATHER THAN THE AUTHORING LANE, deliberately: this row is one very long line, so each lane appending its own instance produces a diff the review surface sizes as a one-line wording tweak -- the class filed as `gunbc.recurring_failure_mode` `salience_instrument_blind_to_the_record_it_sizes`, whose specimen is an earlier edit to THIS row. Batching the appends does not reduce the bytes a reviewer must read; it reduces the number of times that misreading is invited. RE-DERIVE ANY OF THESE WITH `gh api repos/OWNER/REPO/actions/jobs/JOB/logs --allow-escape-sequences` AND WITH NOTHING ELSE. Measured on the first pair above: `gh run view --job --log` answers an ATTEMPT-1 job id with ATTEMPT 2's CONTENT -- banner timestamp and counters both attempt 2's -- so an auditor re-deriving a two-attempt specimen with it obtains IDENTICAL content on both sides, observes no disagreement, and reports these enumerated instances as fabricated. The instrument defect is WIDER THAN WRONG-ATTEMPT, measured 2026-09-02 on gunbc#10077 by diffing both fetches of ONE job: the `gh run view` copy was MISSING THE `FAILED PHASE` LINES ENTIRELY. It does not merely serve the wrong attempt; it can DROP THE LINES CARRYING THE VERDICT, turning a two-phase failure into an apparent one-phase failure -- which is precisely how the admission predicate above was evaluated as true while it was false. An instrument whose omission is invisible is worse than one that is merely stale. The instrument fails in the direction that discredits a true finding, and without the escape-sequences flag the same endpoint writes zero bytes instead. Anyone checking these numbers must be holding the right instrument before disagreeing with them. NO MODELED PRODUCER COUNTS THESE, AND THAT MISSING COUNTER IS THIS PARAGRAPH'S OWN GAP: `RungDrop` carries no field for a mitigation instance, nothing folds the run ids, and a hand-kept TALLY is deliberately absent here because this row has already had to retract one hand-derivation described as a run product. A count with no producer is stale at the next roll and re-derivable by nobody; a run id is reachable by anyone. Whoever wants the number counts the citations. WHAT THE INSTANCES ESTABLISH BEYOND THE MITIGATION ITSELF: the two arms vary INDEPENDENTLY and in both directions on fixed bytes, and a refusal can repeat while disagreeing with itself about which rows were undecided -- so a reroll is not a coin flip against a fixed population but a fresh draw of the population. ONE FINER OBSERVATION THAN THIS ROW PREVIOUSLY SUPPORTED, from the last instance: after the live-gate cost repairs in 2d76d9ccb33 (gunbc#10038), `test.claim.self_host_compile_phase_live_gate_witness` was ABSENT from attempt 1 and BACK in attempt 2 of ONE head. A cost repair lowering a family's incidence is the expected reading; that the family is intermittent WITHIN a single head's attempts is stronger, and it is the sharpest available statement that a cost repair moves incidence without touching the mechanism at the boundary. The conflation of a computed non-verdict with a refusal at the AGGREGATE boundary is a separate class and is filed as `gunbc.recurring_failure_mode` `non_verdict_disposition_surfaces_as_refusal`, which cites this row for the cost half rather than re-deriving it. RECEIPT, 2026-09-03, gunbc#10192: ONE EPISODE BY RUN ID -- ADMITTED IN PART AND NOT END TO END, WHICH THE ENUMERATION BELOW ADJUDICATES RATHER THAN SMOOTHS -- AND THE FIRST CORPUS-GRAIN MEASUREMENT OF MISSING ITEM (b) -- WHICH IT REFUTES RATHER THAN DISCHARGES. THE EPISODE, run 33716314510 on head b65a0eb5b32, ENUMERATED IN FULL INCLUDING THE ATTEMPTS THAT DO NOT QUALIFY, because the sequence contains a transition this row does NOT authorize and an enumeration that showed only the eligible attempts would present an unadmitted retry as part of an admitted mitigation. ATTEMPT 1 EXECUTED ZERO JOBS -- no required-witnesses-floor job exists for it; the run was created awaiting workflow approval -- so it is not an attempt of this class and counting it as one would inflate the denominator. ATTEMPT 2, job 100543957851: claims_failed=33 with BOTH cost arms at zero. OUTSIDE this row's domain: zero dispositions in either cost arm. THE CAUSE OF THOSE 33 IS NOT ESTABLISHED HERE AND AN EARLIER DRAFT CALLED THEM SEMANTIC, WHICH THE COUNTERS DO NOT SUPPORT -- claims_failed enumerates ordinary claim-failure dispositions and does not say why they failed, and a missing host capability surfacing as a runtime error would land in the same counter as a genuine false assertion. The honest reading is an ORDINARY CLAIM-FAILURE FLOOR REFUSAL, CAUSE UNESTABLISHED. ITS ROLE HERE IS A NEGATIVE ELIGIBILITY CONTROL AND NOT A DENOMINATOR MEMBER, which corrects the reason an earlier draft gave for including it: a mitigation's eligible population is the attempts satisfying its admission predicate, so an attempt outside the class can no more count as a failed use of the mitigation than an ordinary compile error can. It is kept because it PROVES THE PREDICATE EXCLUDES SOMETHING REAL. AND THE TRANSITION OUT OF IT IS UNADJUDICATED, WHICH THIS ROW RECORDS RATHER THAN LAUNDERS: outside this row's budget means attempt 2 SPENT no reroll; it does not mean attempt 2 EARNED one. The re-run that produced attempt 3 was NOT admitted by this row -- attempt 2's refusal was carried by neither cost arm -- and no other authority is named for it. So this sequence is not one admitted mitigation end to end: it is an unadmitted retry of an ordinary red on byte-identical executed input, followed by a cost-only refusal that this row does admit, followed by its one reroll. A clean attempt 4 does not retroactively discharge attempt 2, and with attempt 2's identity artifact absent it cannot even be shown that all 33 failures were offered again. ATTEMPT 3, job 100573179841: presents as the two-arm shape this row admits, AND THE ADJUDICATING SURFACE IS ENROLLED HERE RATHER THAN ASSUMED: the run reports phases_run=3 with phases_failed=1, the ONLY FAILED PHASE being the floor, and unexpected_failures=0 -- the external phase verdict this row names as the current eligibility surface, and what establishes that no other phase failed. Beneath it the cost arms are completed_over_cost_requirement=1 and interrupted_before_verdict=1 all cpu_deadline, one row each. An earlier revision removed the internal proof without putting the external one in its place, leaving a correct qualification unsupported by the very surface this row says must adjudicate it. THE `failed=0` SPELLING IS NOT THE ELIGIBILITY KEY AND IS NOT RESTATED AS ONE HERE, because this row already ruled that test defective: it is read off the floor's own COST disposition counters, which do not range over other phases and so could only ever confirm themselves. The current surface is the RUN'S PHASE VERDICT -- phases_run, failed, and FAILED PHASE lines -- and the counters below are receipt, not the test. The completed-past-limit row is v2.test.emit.produced_decl_two_target.produced_decl_module_folds_declarations_in_order at cpu_ms=515, an EXACT measurement against the 500 line; the interrupted row is its SIBLING IN THE SAME MODULE, produced_decl_two_targets_render_own_order, whose printed 509 is the BUDGET and not a measurement. ATTEMPT 4, job 100606296727: the consumed reroll, clean, failed=0 and both arms zero. A LATER AND DIFFERENT TREE, head 2b9e59206af (run 33746447180, job 100619903740), ran clean with MORE claims (executed 3519 rising to 3539) and spent no reroll -- consistent with this row's redraw reading and NOT evidence for it, since one clean draw discriminates nothing. MISSING ITEM (b) IS NOW MEASURED AND IS REFUTED. (b) asked for an identity join of eval_steps across two attempts of ONE IDENTICAL TREE where the cpu column moves and this one must not. Attempts 3 and 4 are exactly that pair, and the artifacts are required-floor-claim-cost 9885042655 and 9889079822, both executed=3519, the identity join TOTAL at 3519 with zero rows on either side alone. cpu_ms disagrees on 1394 of 3519 rows, max absolute delta 128ms. eval_steps disagrees on 18 of 3519. So the step measure reproduces exactly on 99.49 percent of the corpus against cpu's 60.4 percent -- FAR more stable, AND NOT INVARIANT, and (b) asked for invariance. THE JOB LOG SAYS THE OPPOSITE, AND THAT IS THE TRAP THIS PARAGRAPH EXISTS TO CLOSE: in the printed over-cost list every identity carries an identical eval_steps across all four runs while cpu swings by a third, so (b) reads as satisfied from the log alone. It is not. That list is ranked BY COST and truncated at 25, and 17 of the 18 disagreeing rows are too cheap to appear in it. A SUBSET SELECTED BY THE VARIABLE YOU ARE NOT TESTING CANNOT TEST THE ONE YOU ARE -- the same defect this row already records for the attention subset, reappearing on the new column, and the reason (b) must be joined on the uploaded artifact and never on the run's printed summary. WHAT THE 18 ARE, AND THEY ARE TWO DIFFERENT CLASSES RATHER THAN ONE POPULATION. SEVENTEEN ARE PASS/PASS with tiny deltas -- 3 to 161 steps, absolute relative difference at most 0.43 percent -- and they are CLUSTERED, NOT UNIFORM: sixteen of the seventeen sit in three modules, v2.test.claim.rust_crate_partition_witness (6), v2.test.claim.c_compilation_unit_witness (5) and v2.test.claim.compilation_unit_witness (5), one partition-and-unit witness family, with a single stray in v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract -- out of 3519 claims spanning the corpus. So MODULE-CLUSTERED VARIANCE EXISTS IN THIS A/B. That is the measurement; it does NOT establish the source, and an earlier revision called it a nondeterminism SOURCE, asserting as fact the conjecture the paragraph below correctly labels as one. IT IS EVIDENCE ABOUT THE STEP COUNT AND NOT ABOUT THE REFUSAL POPULATION, and conflating those is the error this row has already had to retract once: it establishes that module-clustered variance EXISTS in the corpus, which is the mechanism a module-clustered redraw would require, and it does not establish that the refused set redraws by module. THE EIGHTEENTH IS A DIFFERENT CLASS AND BEARS DIRECTLY ON MISSING ITEM (a). produced_decl_two_targets_render_own_order carries 196608 steps in the attempt where it was budget_interrupted and 197227 where it passed, so AN INTERRUPTED CLAIM'S eval_steps IS A PARTIAL COUNT AT THE STOP, not the claim's work -- the exact twin, in the step domain, of the already-recorded fact that an interrupted row's printed ms is the budget rather than a measurement. 196608 is 3 times 2 to the 16th exactly, which is suggestive of a step-interval deadline check; that is n=1 and the mechanism is NOT asserted here. THE CONSEQUENCE FOR (a) IS CONCRETE AND IS WHY THIS IS RECORDED BESIDE IT: a step-denominated line would compare against this partial for precisely the rows it exists to judge, so (a) needs a rule for the non-terminal row BEFORE it needs a number. NET EFFECT ON THE TRIGGER, STATED PER ARM BECAUSE (ii) IS A DISJUNCTION: the conjunct reads INVARIANT OR BOUNDED BY CONSTRUCTION and only the first arm has been tested. EXACT-INVARIANCE ARM: measured and REFUTED. BOUNDEDNESS ARM: UNESTABLISHED -- the 556-identity distribution below calls itself a spread and not a bound, reinforcing the distinction rather than resolving it. WHOLE CONJUNCT: REMAINS UNSATISFIED. An earlier revision wrote that (ii) moves to MEASURED AND FAILING, which is too broad for a disjunction whose second arm is untested: unsatisfied and both-alternatives-measured-and-failing are different findings. The trigger is a conjunction of three and (i) and (iii) are untouched, so nothing here retires this row and nothing here proposes raising the ceiling. RE-DERIVE with gh run download rather than by piping the artifact zip through a shell: gh api .../artifacts/ID/zip redirected to a file, and curl -o on the redirect target, BOTH corrupt the bytes in this environment -- a malformed local header and roughly 380 bytes short -- so an auditor who reaches for the obvious command gets an unreadable archive and may conclude the artifacts are gone. Taking the Location header and fetching it UNAUTHENTICATED also works; forwarding the Authorization header to blob storage returns 401. ONE FURTHER MEASUREMENT FROM THE SAME EPISODE, AND IT BEARS ON THIS ROW'S OWN REROLL SIGNATURE RATHER THAN ON ITS COST ARMS: THE PLANNED POPULATION IS NOT A FUNCTION OF THE TREE. On the single head b65a0eb5b32, the three attempts carrying a floor job report planned=executed=3534 (attempt 2, 33 claims failed), 3519 (attempt 3) and 3519 (attempt 4) -- fifteen claims of difference across attempts of ONE head with no change to the source. NO CAUSE IS ASSERTED HERE AND THE OBVIOUS ONE IS NOT VERIFIED: if the plan is computed relative to a moving main rather than to the head under test, this is expected rather than anomalous, and that is the first thing to check before treating it as a defect. WHAT IT DOES ESTABLISH REGARDLESS OF CAUSE is that EXACT HEAD DOES NOT BY ITSELF FIX THE POPULATION A REROLL IS DRAWN FROM, so a changed planned COUNT is RECEIPT AND COMPARABILITY DETAIL, and a potential planning or coverage defect, and NEVER a fresh reroll allowance. An earlier draft left that open as though it were undecided; it was already decided earlier in this same row, and leaving it open invited the budget reading it forbids. IT DOES NOT CONTAMINATE THE (b) JOIN ABOVE: attempts 3 and 4 both planned 3519 and their identity join is total at 3519 with zero rows on either side alone, which is why that measurement stands independently of this one. AND IT CORRECTS A CHARACTERISATION THAT WAS OFFERED FOR ATTEMPT 2 AND IS FALSE: that attempt was not a toolchain or host-tool incident -- its own summary reports host_tool_unresolved=0 beside claims_failed=33, so it is an ordinary red floor and belongs to no runner-incident population. The disposition is unchanged either way, since both cost arms are zero, so THE COST-ARM ADMISSION PREDICATE DOES NOT HOLD -- stated that way because there is no failed=0 precondition to fail, that key having been retired earlier in this same row, and an earlier revision resurrected it here after removing it one paragraph away, but the ground for excluding it from the mitigation is the cost-arm test and NOT a tooling attribution. THE CAUSE NAMED AS LIKELY IN THE PARAGRAPH ABOVE IS NOW CHECKED AND REFUTED, WHICH IS WHY THAT PARAGRAPH SAID TO CHECK IT FIRST. The suggestion was that the plan might be computed relative to a moving main rather than to the head under test, which would make the differing planned counts expected. IT IS NOT THAT. GitHub Actions evaluates a SYNTHETIC MERGE rather than the branch head, and all three attempts checked out THE SAME SYNTHETIC MERGE COMMIT -- each job log carries the identical line naming the merge of b65a0eb5b32 into 3547b3f9028 at one merge SHA -- so the three attempts ran a BYTE-IDENTICAL TREE and the main they were merged against did not move between them. The planned population therefore varies across attempts of a genuinely fixed tree. THE COUNTERS THAT DO NOT VARY NARROW IT FURTHER, and they are the ones a reader would reach for first: known_red_held, route_gap_held and stale_quarantine are IDENTICAL across all three attempts, so this is not a roster, quarantine or route-gap difference selecting a different population. Only planned, executed and terminal move, together, by fifteen. WHAT CANNOT BE SAID, AND THE REASON IS an artifact gap rather than a judgement: WHICH fifteen identities differ is NOT recoverable, because the attempt that planned 3534 uploaded no per-claim cost artifact -- only the two 3519-attempts did -- so the finding is available at COUNT grain and not at IDENTITY grain, which is precisely the weaker form this row elsewhere refuses to accept as a population. It is recorded as a count because that is what was measured. ONE CONJECTURE, LABELLED AS ONE AND CARRYING ITS OWN TEST RATHER THAN A CONCLUSION: the same unpinned iteration order that would explain the module-clustered eval_steps variance recorded above -- sixteen of seventeen disagreements inside one partition-and-unit witness family, which is exactly the shape of a fold over a set with no declared order -- could also change how many claims a generator emits, giving both observations ONE root. NOTHING HERE ESTABLISHES THAT, and the discriminating test is named so the next lane does not have to invent it: recover the fifteen identities by having the planner emit its plan as an artifact on every attempt including a failing one, then join two attempts of one synthetic merge at IDENTITY grain and ask whether the differing rows are generated claims from the same witness families that carry the step variance. Until that artifact exists the two observations are adjacent and unjoined. THE CONSEQUENCE FOR THIS ROW'S REROLL RULE IS UNCHANGED BY THE REFUTATION AND IS STRENGTHENED BY IT: exact head does not fix the drawn population, and it is now known that no appeal to a moving base explains it away. AND IT DOES NOT EXPAND THE REROLL ALLOWANCE, WHICH IS THE READING IT MOST INVITES AND THE ONE THIS SENTENCE EXISTS TO REFUSE: a differing planned cardinality WEAKENS COMPARABILITY between two attempts and lowers confidence that they covered the same claims; it does not license a second draw. The allowance stays at ONE PER EXACT HEAD, consumed on actuation. IT IS NOT PER SIGNATURE, AND SAYING SO WOULD REINTRODUCE A SPELLING THIS ROW ALREADY REFUTED: the signature was only ever an ADMISSION PREDICATE -- which refusals are eligible at all -- and never a budget key. This finding makes exact head insufficient as a COMPARABILITY IDENTITY; it leaves exact head intact as the deliberately coarse BUDGET KEY, and letting a changed population mint a fresh signature would recreate retry-until-green exactly when the roster becomes unstable. An attempt that falls outside this row's domain spends nothing AND EARNS NOTHING -- it is not a free retry, and treating an ineligible red as though it restored the budget would be retry-until-green reached by a different route than the one this row already forbids. RECEIPT, 2026-09-03, gunbc#10231 -- THE SHARPEST INSTANCE THIS ROW CARRIES, BECAUSE THE VERDICT FLIPPED WHILE THE WORK MEASURE DID NOT MOVE BY ONE STEP. THE SUBJECT MAKES THE POINT BEFORE THE NUMBERS DO: it is a LEDGER-ONLY PROSE PR -- the filing of this row's sibling mechanism class -- touching one authority row and its generated projection, with no code, no types and no gates. A DIFF CATEGORY DOES NOT GRANT COST INNOCENCE BY CONSTRUCTION, and an earlier revision claimed it did: the ledger is ACCEPTED .dag SOURCE here, so altering a large literal can move parsing, resolution, allocation, generated structure or closure work, and shape is not an argument about cost. THE NARROWER CONTROL IS SUFFICIENT AND IS WHAT IS CLAIMED: the diff was IDENTICAL ACROSS BOTH ATTEMPTS, so whatever it costs relative to its base, it cannot explain the attempt-to-attempt flip. Run 33756177727 attempt 1, floor job 100651027559: REFUSED with completed_over_cost_requirement=1 beside claims_failed=0, interrupted_before_verdict=0 and host_tool_unresolved=0 -- one row, wholly inside this row's admitted domain on the two-arm test, with the run's phase verdict carrying no other failed phase. One reroll was actuated and thereby CONSUMED, against a budget of ONE PER EXACT HEAD. Attempt 2, job 100663093895: PASS. THE DISCRIMINATING PAIR, and it is one identity rather than an aggregate: v2.test.emit.rust_produced_decl_emit.rust_produced_decl_name_discriminates measured cpu_ms=523 on the refusing attempt and cpu_ms=404 on the passing one -- a ratio of 1.294 across the 500 line -- WHILE ITS eval_steps IS IDENTICAL AT 169297 ON BOTH. Same head, same tree, same identity, same count of evaluator steps, opposite verdicts. WHAT THAT SUPPORTS, AT THE INSTRUMENT'S REACH AND NOT BEYOND IT: for one fixed identity on one fixed head the cpu-line verdict flipped while the recorded net evaluator-step count stayed exactly identical, so THE CPU VERDICT IS NOT DETERMINED BY eval_steps ALONE -- stronger than showing cpu varies more often than steps, because it exhibits the mismatch at the very identity whose verdict changed. WHAT IT DOES NOT SUPPORT, and an earlier revision asserted it: that the deciding component lies OUTSIDE THE CLAIM'S WORK. Identical eval_steps establishes identical COUNTED EVALUATOR ENTRIES AFTER THIS INSTRUMENT'S NETTING RULE, not identical claim work -- host work, closure work, attribution and cache behaviour are uncounted and remain possible. This row keeps CHARGE-SUBJECT ALIGNMENT open as conjunct (i), so it cannot use this pair to place the varying component outside the claim; that would discharge (i) by assertion. THIS DOES NOT CONTRADICT THE (b) REFUTATION RECORDED ABOVE, and the reconciliation matters because the two readings look opposed: (b) failed because 18 identities of 3519 disagree on eval_steps, NOT because the measure is generally unstable -- 3501 reproduce exactly, and this identity is one of them. A measure can be exact on a given row and still fail an invariance claim asserted over a corpus. A THIRD SAMPLE OF THE SAME IDENTITY EXISTS ON GREEN MAIN, CITED BY RUN AND JOB SO IT IS RE-DERIVABLE RATHER THAN RELAYED: run 33754393519, floor job 100645180812, event push on main head 75873c28978, reports this identity at cpu_ms=406 with eval_steps=169297 -- the SAME step count as both attempts of the episode above, at a third distinct cpu. AND THE ORDERING IS WEAKER THAN AN EARLIER REVISION OF THIS PARAGRAPH CLAIMED, WHICH IS WHY THE CARRIER WAS WORTH DEMANDING. That revision said the identity had been NAMED IN ADVANCE and that a lane had PUBLISHED the crossing arithmetic before the refusal, which made it a prediction. The job timestamps refute that framing: the green-main job ran 12:17:45Z to 12:45:05Z and the refusing attempt ran 12:40:20Z to 13:10:22Z, so THE TWO RUNS OVERLAPPED. The green-main value was therefore observable 25 minutes before the refusal was observed, and it is CORROBORATION AT A THIRD SAMPLE rather than a prediction made before the event. The advance-prediction claim is withdrawn; it was received by relay and no carrier for the publication event was ever produced, which is exactly the transcribed-number failure DESIGN section 6 forbids -- name the producer, never copy its output. A prediction that names the row before it refuses a PR is worth more than a fresh observation of the same event. INDEPENDENT REPLICATION OF THE SPREAD, derived from the per-claim cost artifacts of THIS row's other episode rather than from the reporting lane's run, and it is an INDEPENDENT RUN AND ARTIFACT SAMPLE rather than an independent instrument -- an earlier revision said the two share NO instrument, which is false: they share the required-floor cpu producer, its accounting semantics, the evaluator-step counter and the artifact schema. What they do not share is a run or an artifact, and that is the whole of the independence claimed: over the 556 identities measuring at least 50 cpu-ms in BOTH attempts of one identical tree, the attempt-to-attempt cpu ratio -- DEFINED PER JOINED IDENTITY AS max(cpu_A, cpu_B) / min(cpu_A, cpu_B), so it is direction-free and never below 1.0, stated because an earlier revision published percentiles without the formula and B/A would give materially different numbers -- has median 1.045, p10 1.005, p90 1.219 and MAXIMUM 1.721. THE MEDIAN IS THE UNINTERESTING NUMBER AND THE TAIL IS THE ONE THAT DECIDES VERDICTS -- a corpus whose typical row moves by 4 percent still puts four identities at 94 to 103 percent of budget on a tree that PASSED. WHAT NONE OF THIS ESTABLISHES, stated because this row's trigger asks for exactly the thing it falls short of: A BOUND. Two attempts give a SPREAD, and (ii) requires the basis to be invariant OR BOUNDED BY CONSTRUCTION across the admitted envelopes; a maximum of 1.721 observed over one pair of attempts on one host pair is a FLOOR on the spread, not a bound on it, and the admitted envelope set is wider than the hosts these pairs sampled. THE CONSEQUENCE ON MAIN, MEASURED AT VERDICT GRAIN RATHER THAN AT ROW GRAIN (2026-09-03), because everything above measures ROWS and the thing that costs the fleet its afternoon is the VERDICT. Of the twenty-five most recent `witnesses.yml` runs on `main`, five reported `verdict=FloorRefused` with `claims_failed=0` and `unexpected_failures=0` -- the whole refusal carried by `interrupted_cpu_deadline` and `completed_over_cost_requirement`, so the required floor refused main five times without a single claim disagreeing with the tree. A GATE THAT REFUSES FOR REASONS UNRELATED TO THE CHANGE TEACHES ITS READERS THAT A RED REQUIRED FLOOR IS NOISE, and that is the cost this row had not priced: the sections above price the mis-attribution of a NUMBER to a row, and this one prices the mis-attribution of a VERDICT to a tree. AND THE HOST CORRELATION, STATED AT THE WIDTH THE SAMPLE SUPPORTS AND NOT WIDER. THE DECISIVE MEASUREMENT IS NOT THE HOST TABLE, IT IS A SAME-HEAD CONTROL, and it is stated first because it is established BY CONSTRUCTION rather than by correlation. Run 33806159353 was re-run at the same head: attempt 1 recorded `required-witnesses-floor` FAILURE on runner srv4-14 and attempt 2 recorded SUCCESS on runner srv4-19, both at head 07f81df887a, unchanged between them. ONE TREE, TWO ATTEMPTS, OPPOSITE VERDICTS. Nothing about the subject differed, so the required floor's verdict is demonstrably NOT A PROPERTY OF THE TREE -- which is this row's whole subject, now shown rather than inferred, and shown without needing any closure argument because nothing changed. THE HOST TABLE IS THE WEAKER EVIDENCE AND ITS FAMILY-SHAPED READINGS ARE REFUTED, twice, in the same direction. Eleven `required-witnesses-floor` jobs by runner registration: seven failed (srv1-02, srv1-07, srv1-10, srv1-16, srv1-17, srv4-11, srv4-14) and four passed (srv3-02, srv3-04, srv3-10, srv4-19). A first reading said srv1 is the bad host and srv4-11 refuted it; a second said srv3 is the only host observed clearing the ceiling and srv4-19 refuted that too, since srv4 now does BOTH. BOTH READINGS GENERALISED A HOST FAMILY FROM MACHINE-LEVEL SAMPLES AND THE NEXT SAMPLE CROSSED THE LINE EACH TIME, which is why the surviving statement names no family at all. WHAT THE MEASUREMENTS SUPPORT, AND NOTHING WIDER: the verdict is not a property of the tree; it is not cleanly a property of the host family; THE ACTUAL VARIABLE IS UNIDENTIFIED, with machine-level load or moment and a per-machine difference both consistent with the data, and eleven samples cannot separate them. Naming a cause here would be the looks-principled-and-is-not move this row already refuses on the calibration arm. MISSING ITEM (b) IS NOW DISCHARGED OVER THE MEASURABLE POPULATION AND THE ROW STILL STANDS, and the reason it still stands is the more useful half. THE JOIN (warm-seal-35, over the two attempts above): 338 shared-fill per-claim rows on each side, joined ON IDENTITY with ZERO unmatched rows in either direction, `marginal_eval_steps` and `measured_eval_steps` IDENTICAL for all 338, while measured cpu-ms moved by more than ten percent on 124 of them and spanned 0.627 to 1.217 as an attempt-2-over-attempt-1 ratio. That is (b) as worded -- an exact identity join of the step column across two attempts of ONE IDENTICAL TREE, with the cpu column moving and this one not -- and it is a population rather than a subject, which is what separates it from the single-claim reading above. ITS DENOMINATOR IS NOT THE FLOOR, AND QUOTING IT AS WHOLE-FLOOR COVERAGE WOULD BE THE ERROR THIS ROW EXISTS TO REFUSE: both attempts executed 3585 claims and the shared-fill instrument reports per-claim cost for 338 of them, so the join covers 9.4 percent and is silent about the rest. THE EXCLUSION IS THE FINDING, NOT A CAVEAT ON IT, AND IT IS SHARPER THAN THE CONSTRAINT PREDICTED ABOVE. An interrupted row is unmeasured in steps by construction, so the join can only cover completed rows -- and the rows it therefore excludes are EXACTLY THE ROWS THAT DECIDED THE VERDICT. Attempt 1 recorded passed=3507 with interrupted_before_verdict=2 and completed_over_cost_requirement=1 and refused; attempt 2 recorded passed=3510 with both counters at zero and was clean. 3507 plus 2 plus 1 is 3510: the three rows are precisely the difference between the two attempts, and they are precisely the rows no step measurement can speak about. THE MORE A CLAIM IS AFFECTED, THE LESS MEASURABLE IT BECOMES. So the join establishes that 338 OTHER claims did identical work under a moving envelope -- strong evidence about the envelope, and NO evidence about the three. WHICH IS A CONSTRAINT ON MISSING ITEM (a) AND NOT ONLY ON (b), and it is the first thing this row has been able to say about (a) at all: A STEP-DENOMINATED LINE BUILT ON THIS INSTRUMENT WOULD BE BLIND IN EXACTLY ITS OWN SUBJECT DIRECTION, because the rows that would cross such a line are the rows that carry no step count. Sizing one from the measurable population would produce a threshold that looks principled and is derived from the rows that were never at issue. EVIDENCE GRADES, KEPT SEPARATE AS EVERYWHERE ELSE IN THIS ROW. The two attempt summaries and their arithmetic were read FIRST-HAND from the run at two different times, attempt 1 while it was the only attempt and attempt 2 after the re-run; the 338-row join is taken from its builder with its own disclosed method corrections and was not re-derived here, because the attempt-1 log archive returns a truncated response that will not open. A CITATION TRAP WAS OBSERVED WHILE CHECKING THIS AND IS RECORDED SO THE NEXT READER DOES NOT LOSE AN HOUR TO IT: a bare job id serves the LATEST attempt, so job 100817014187 -- whose own conclusion is failure -- now serves attempt 2 FloorClean summary. An attempt-level citation is the only stable one. AND THE DISPOSITION GETS MORE DEFENSIBLE RATHER THAN LESS: a ceiling whose verdict flips on ONE UNCHANGED TREE between two attempts thirty-six minutes apart is not something a fifth shave of the claim would fix, which is the measured form of the argument that four prior lanes closed on the claim and it fired again. WHAT IS ESTABLISHED PER SAMPLE DIFFERS AND IS NOT FLATTENED: the `claims_failed=0` / `unexpected_failures=0` signature was read from the run logs for six of the seven failures, srv4-11 being the one taken on report rather than read. The distinction is kept because this carrier's own subject is a verdict being attributed to the wrong thing, and a floor job can redden on a phase that is not the floor -- so FAILED and FAILED-WITH-THIS-SIGNATURE are different facts and the row says which it has. A ONE-SUBJECT CROSS-ENVELOPE READING, WHICH BEARS ON MISSING ITEM (b) AND DOES NOT DISCHARGE IT (calm-deer-33, 2026-09-03, verified here rather than relayed). `v2.test.emit.rust_produced_decl_emit.produced_decl_unwired_target_still_refuses` measured 165802 eval_steps at 346 cpu-ms on run 33802603168 and 165802 eval_steps at 514 cpu-ms on run 33806159353 -- the step count IDENTICAL to the digit while cpu moved 1.49x, and the second reading is the one that crossed into completed-over-budget. Log-line controls of 3472 and 3465 rule out an empty capture on either side, which is this repository's standing guard against a zero that reads as a clean sweep. WHY IT IS NOT (b), ON THREE COUNTS, AND THE THIRD IS THE ONE A LATER READER WILL MISS. (i) GRAIN: (b) asks for a join AT CORPUS GRAIN and this is one subject. (ii) SUBJECT: (b) asks for TWO ATTEMPTS OF ONE IDENTICAL TREE, and these are two different trees -- 8b2323f is an ANCESTOR of 07f81df, so the pull request adds commits on top of the main commit it is compared against. (iii) THE WARRANT FOR THE-WORK-DID-NOT-CHANGE CANNOT COME FROM THE STEP COUNT ITSELF: constant steps are read as envelope-independence only if the work is identical on INDEPENDENT grounds, since a measure insensitive to the change produces the same reading. TWO ATTEMPTS OF ONE IDENTICAL TREE supplies that warrant BY CONSTRUCTION, which is why (b) is written that way. ACROSS TWO TREES IT WAS SUPPLIED SEPARATELY AND (iii) IS ANSWERED, by two arguments that do not depend on each other, both re-derived here rather than relayed. FIRST, A SYMBOL-GRAIN JOIN: the whole diff between the compared trees touches three files and adds or removes six declarations -- `absence_classifier_default_bucket`, `green_reported_over_a_population_the_instrument_does_not_own`, `live_03_normalize_data_inits`, `live_03_normalize_facts`, `live_argument_threaded_past_the_arm_that_decides` and `effect_reach_live_03_normalize_witness_derived_host_reading_holds` -- and the module declaring the measured claim, `v2.test.claim.emit.produced_decl_two_target_test`, references none of the six, with a positive control on the same grep finding `tt_emit`, `tt_emits` and `tt_refuses` there. SYMBOL GRAIN RATHER THAN IMPORT CLOSURE IS LOAD-BEARING IN THIS SUBSTRATE: names resolve by global uniqueness rather than by import lists, so a name absent from every import list still resolves and an import-closure argument would exclude modules that can still supply a binding. SECOND, AND INDEPENDENT OF WHETHER THAT JOIN IS EXHAUSTIVE: the diff is NET NEGATIVE, 32 insertions against 60 deletions, and the only witness change DELETES a row, so any corpus-scale work effect would push this claim CHEAPER while the observation is 1.49x MORE EXPENSIVE. The move is in the wrong direction for every work-based explanation. A CONSTRAINT ON HOW (b) CAN EVER BE DISCHARGED, WHICH IS A PROPERTY OF THE COLUMN AND NOT OF TONIGHT. An INTERRUPTED row is unmeasured in `eval_steps` BY CONSTRUCTION -- the poll fires before a count exists -- so a corpus-grain identity join over this column has a STRUCTURALLY EXCLUDED SUBPOPULATION, and the excluded rows are precisely the expensive ones the join most needs to cover. (b) as worded may therefore not be buildable at full coverage at all. A LATER LANE THAT BUILDS IT OVER COMPLETED ROWS AND REPORTS COVERAGE WILL BE REPORTING OVER A POPULATION IT DOES NOT OWN, which is `gunbc.recurring_failure_mode` `green_reported_over_a_population_the_instrument_does_not_own` -- so the honest discharge of (b) must either state the exclusion as part of its result or reach the interrupted rows by a different measure, and a coverage figure over completed rows alone does not retire this row. WHAT IT DOES ESTABLISH is still an advance on what this row had: the invariance reading was previously grounded at FIXTURE grain and nowhere wider, and this extends it to a live corpus subject under real floor pressure. Recorded as that and not as more. IT WAS MEASURED FORWARD, WHICH IS THE ONLY REASON IT IS RECORDED AT ALL: a prediction that srv1-10 would fail and srv3-10 would pass was registered before either returned, and runs 33794985110 and 33796487867 held it. WHAT IT IS NOT IS AN EXPLANATION. A SLOWER HOST is a hypothesis with no mechanism attached, three passes on one host is a thin denominator, and neither this correlation nor a wider one discharges (i), (ii) or (iii) of the trigger below -- a basis that varies with the machine is exactly what (ii) asks to be rid of, so measuring WHICH machines it varies with sharpens the subject and closes none of it. NOT PROPOSED HERE, AND THE DISTINCTION IS THE SAME ONE THIS ROW HAS MADE THROUGHOUT: raising the 500 line would change which rows cross and would not make the crossing a property of the claim, so it does not retire this row and is not requested. ### Emitted-bytes fixture witnesses in a required lane — declared 2026-09-01 diff --git a/docs/plans/enrolment-margin-eval-step-denomination.md b/docs/plans/enrolment-margin-eval-step-denomination.md index 6950420b314..bf0dbaa5d2d 100644 --- a/docs/plans/enrolment-margin-eval-step-denomination.md +++ b/docs/plans/enrolment-margin-eval-step-denomination.md @@ -171,11 +171,15 @@ are a lower bound with no ceiling, exactly as its CPU is. ## Phase 3 — retire the CPU line, or say why it stays -`required_floor_per_subject_cpu_line_ms` exists only because two per-subject gates still -read a CPU clock. When Phase 2 lands, the enrolment margin is not one of them, and the -remaining consumer is `v2.workflow.floor_cost_debt_admission`. Phase 3 decides that one: -either it is denominated too and the symbol is deleted with its own dissolution -condition discharged, or the symbol survives with a population of exactly one, stated. +`required_floor_per_subject_cpu_line_ms` exists only because per-subject decisions still +read a CPU clock. Since gunbc#11700 `v2.workflow.floor_cost_debt_admission` compares nothing +(a typed admission is identity and reason); the consumers are both in +`v2.workflow.floor_enrolment_margin`: the margin budget, which must sit below the line, and +the live Roster ground (`enrolment_declared_measured_standing`), which admits only a reading +over it. When Phase 2 denominates the margin, the Roster ground is the remaining consumer, and +Phase 3 decides that one: either it is denominated too and the symbol is deleted with its own +dissolution condition discharged, or the symbol survives with a population of exactly one, +stated. **Only when no per-subject budget reads a run-level figure does the drop's clause (iv) retire**, and the drop is retired by its trigger and by nothing else. diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index e779e22b2e3..50b875826f8 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -1899,7 +1899,10 @@ pub(crate) fn enrolment_margin_standing_for( cause: "no_claim_cost_row_for_a_planned_identity".to_string(), }; } - _ => {} + // The admitting arms are spelled, never a wildcard: a new reading shape must be + // given a disposition here rather than default to admit (review 68380). + EnrolmentDeclaredCostReading::Observed { .. } + | EnrolmentDeclaredCostReading::BoundWithoutCeiling { .. } => {} } } return EnrolmentMarginStanding::ExpensivenessDeclared { ground, reading };