Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
eca351a
YAML ingest 2-3x cheaper at its owning links; mark the action-use pro…
Sep 19, 2026
50c7ef1
YAML ingest/emit: a bounded subset with a correct-meaning contract, a…
Sep 20, 2026
cad119d
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 20, 2026
d3e063a
The YAML writer's refusal travels to the seeded install media, and th…
Sep 20, 2026
4d46744
Record the census claim's margin on the carrier, and correct the two …
Sep 20, 2026
8bff40f
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 20, 2026
5e52616
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 20, 2026
dd4c161
Cut the reader's per-entry cost where the census actually spends it
Sep 20, 2026
73e5756
Point the cost standing's remedy at the path the measurement found
Sep 20, 2026
fa8c354
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 20, 2026
cb39f95
File the class the commit_sha workaround belongs to, and point the wo…
Sep 20, 2026
2e8e65c
Name the instrument instead of transcribing its figures, and commit t…
Sep 20, 2026
e78927a
Admit the shared predicate's respelling on its own cost shape, under …
Sep 20, 2026
fab65ea
Delete the probe that could not run, and state the method instead
Sep 20, 2026
d524716
Make the per-file census claim mean what its name says
Sep 20, 2026
93cf1ce
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 20, 2026
9963d1a
Merge origin/main into session/still-lynx-398: re-derive the writer's…
Sep 22, 2026
f2ea1ac
Merge remote-tracking branch 'origin/main' into session/still-lynx-398
Sep 22, 2026
f2e0504
A quote only opens a scalar where an entry opens, and a key with a li…
Sep 22, 2026
da18f39
Delete three declarations this change added and never consumed
Sep 22, 2026
536871d
Merge origin/main into session/still-lynx-398: regenerate the two wor…
Sep 22, 2026
0f06513
Merge origin/main into session/still-lynx-398: the compiler-gate guar…
Sep 22, 2026
39d1a4d
Merge origin/main into session/still-lynx-398: regenerate the two wor…
Sep 23, 2026
2872ad6
commit_sha_text_holds: the respelling buys a constant factor, not a c…
Sep 23, 2026
919b58a
Merge origin/main (with #12087) into session/still-lynx-398: regenera…
Sep 23, 2026
4875c6f
Move the seeded grub-cmdline witness to the executing local wet lane
Sep 23, 2026
9b3c243
YAML reader: rewrite the accepted-path block walk around decisions ke…
Sep 23, 2026
e689d77
Census traversal: one reading per use site, and no copied accumulator
Sep 23, 2026
5d9f3f9
Cost standing: the remedy names the census traversal's own repairs be…
Sep 23, 2026
a6800c4
Route test over a real workflow's uses line, and block-scalar chompin…
Sep 23, 2026
be77936
Merge origin/main (with #12134) into session/still-lynx-398: roster t…
Sep 23, 2026
676b743
Merge origin/main into session/still-lynx-398: regenerate fleet-conve…
Sep 23, 2026
983ac5a
Merge origin/main into session/still-lynx-398: regenerate fleet-conve…
Sep 23, 2026
d8994b4
YAML reader: a refusal is a typed arm, never a sentinel value (review…
Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
106 changes: 53 additions & 53 deletions .github/workflows/fleet-converge.yml

Large diffs are not rendered by default.

6 changes: 3 additions & 3 deletions .github/workflows/fleet-desired.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,9 +19,9 @@ jobs:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
with:
fetch-depth: 0
fetch-depth: "0"
- name: Isolate toolchain homes
run: |
run: |-
# dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not
rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo"
echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV"
Expand All @@ -34,7 +34,7 @@ jobs:
cache: false
rustflags: -D warnings
- name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain)
run: |
run: |-
# dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing
rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')"
if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi
Expand Down
13 changes: 7 additions & 6 deletions .github/workflows/heal-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
steps:
- name: Ask the triggering run whether it sealed a candidate
id: candidate_probe
run: |
run: |-
set -euo pipefail
NAMES=$(gh api --paginate "repos/$GITHUB_REPOSITORY/actions/runs/$TRIGGERING_RUN_ID/artifacts" --jq '.artifacts[].name')
if printf '%s\n' "$NAMES" | grep -qx "heal-repair-candidate"; then
Expand All @@ -52,7 +52,7 @@ jobs:
github-token: ${{ github.token }}
if: steps.candidate_probe.outputs.present == 'true'
- name: Isolate toolchain homes
run: |
run: |-
# dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not
rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo"
echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV"
Expand All @@ -65,15 +65,15 @@ jobs:
cache: false
rustflags: -D warnings
- name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain)
run: |
run: |-
# dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing
rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')"
if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi
if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi
echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV"
- name: Build the publisher this job runs from the default branch
id: build_witness_fold
run: |
run: |+
GUNBC_FLOOR_LOG='gunbc-floor-cmd.log'
'set' '+e'
'set' '-o' 'pipefail'
Expand All @@ -94,8 +94,9 @@ jobs:
if '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']' && '[' '-f' "$GUNBC_FLOOR_LOG" ']' && 'grep' '-q' 'Resource temporarily unavailable' "$GUNBC_FLOOR_LOG"; then GUNBC_FLOOR_CLASS='infra'; GUNBC_FLOOR_SIGNATURE='ResourceTemporarilyUnavailable'; fi
if (! '[' '-f' "$GUNBC_FLOOR_RECEIPT" ']') || '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']' || ('[' "$GUNBC_FLOOR_CLASS" '=' 'infra' ']' && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=structural' "$GUNBC_FLOOR_RECEIPT"))) || ('[' "$GUNBC_FLOOR_CLASS" '=' 'none' ']' && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=structural' "$GUNBC_FLOOR_RECEIPT")) && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=infra' "$GUNBC_FLOOR_RECEIPT"))); then 'printf' 'class=%s\nsignature=%s\nexit=%s\n' "$GUNBC_FLOOR_CLASS" "$GUNBC_FLOOR_SIGNATURE" "$GUNBC_FLOOR_EXIT" > "$GUNBC_FLOOR_RECEIPT"; if '[' "$GUNBC_FLOOR_CLASS" '=' 'infra' ']'; then 'echo' '::error title=environment::floor_class='"$GUNBC_FLOOR_CLASS"' signature='"$GUNBC_FLOOR_SIGNATURE"' exit='"$GUNBC_FLOOR_EXIT"'; this is not a verdict about the diff. Attempt receipt: '"$GUNBC_FLOOR_RECEIPT"; fi; if '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']'; then 'echo' '::error title=subject::floor_class='"$GUNBC_FLOOR_CLASS"' exit='"$GUNBC_FLOOR_EXIT"'; read the step log for the subject defect'; fi; fi
'exit' "$GUNBC_FLOOR_EXIT"

- name: Admit the candidate against this checkout's policy, with no publication credential
run: |
run: |-
set -euo pipefail
GUNBC_CG=/sys/fs/cgroup/gunbc-publish
echo "+memory" | sudo tee /sys/fs/cgroup/cgroup.subtree_control >/dev/null
Expand All @@ -121,7 +122,7 @@ jobs:
export_environment_variables: false
if: hashFiles('heal-candidate/heal-repair-candidate-blob-*') != ''
- name: Publish the admitted repair, fast-forward only, and read it back
run: |
run: |-
set -euo pipefail
GUNBC_CG=/sys/fs/cgroup/gunbc-publish
echo "+memory" | sudo tee /sys/fs/cgroup/cgroup.subtree_control >/dev/null
Expand Down
15 changes: 8 additions & 7 deletions .github/workflows/heal.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ concurrency:
cancel-in-progress: true
env:
CARGO_TERM_COLOR: always
MALLOC_ARENA_MAX: 2
MALLOC_ARENA_MAX: "2"
jobs:
heal-generated-artifacts:
runs-on: [self-hosted, linux, arm64]
Expand All @@ -43,7 +43,7 @@ jobs:
ref: ${{ inputs.head_sha }}
persist-credentials: false
- name: Isolate toolchain homes
run: |
run: |-
# dissolve-on: ci_toolchain_home_isolation_script -- orch-emitted foreign-executor prelude step wiping and setting HOME/CARGO_HOME/RUSTUP_HOME under RUNNER_TEMP so concurrent runner slots stop sharing one toolchain; leaf rm/echo strings remain until a typed per-job filesystem-and-environment effect lands on host_effect_apply (shell-to-intent Phase 2). This obligation covers THIS carrier and ci_isolate_toolchain_script, which share that terminal construction; ci_pin_rustup_default_script carries its own obligation because it does not
rm -rf "$RUNNER_TEMP/rustup" "$RUNNER_TEMP/cargo"
echo "HOME=$RUNNER_TEMP" >> "$GITHUB_ENV"
Expand All @@ -56,15 +56,15 @@ jobs:
cache: false
rustflags: -D warnings
- name: Pin rustup default (isolated RUSTUP_HOME has no default toolchain)
run: |
run: |-
# dissolve-on: ci_pin_rustup_default_script -- orch-emitted foreign-executor step selecting a rustup default toolchain inside an isolated RUSTUP_HOME, which starts with none, and resolving the cargo binary that selection implies. The leaf rustup/command/echo strings remain until a typed TOOLCHAIN-SELECTION effect lands on host_effect_apply -- NOT the filesystem-and-environment effect ci_toolchain_home_isolation_script waits on, which is why this is a separate obligation: that effect landing alone would leave this carrier standing
rustup default "$(rustup show active-toolchain | awk '{print $1; exit}')"
if [ -x "$CARGO_HOME/bin/cargo" ]; then CARGO_BIN="$CARGO_HOME/bin/cargo"; else CARGO_BIN="$(command -v cargo || true)"; fi
if [ -z "$CARGO_BIN" ]; then echo "::error::no cargo binary: neither the isolated $CARGO_HOME/bin/cargo shim nor PATH carries one"; exit 1; fi
echo "CARGO_BIN=$CARGO_BIN" >> "$GITHUB_ENV"
- name: Build the regenerator this job runs against its own checkout
id: build_witness_fold
run: |
run: |+
GUNBC_FLOOR_LOG='gunbc-floor-cmd.log'
'set' '+e'
'set' '-o' 'pipefail'
Expand All @@ -85,18 +85,19 @@ jobs:
if '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']' && '[' '-f' "$GUNBC_FLOOR_LOG" ']' && 'grep' '-q' 'Resource temporarily unavailable' "$GUNBC_FLOOR_LOG"; then GUNBC_FLOOR_CLASS='infra'; GUNBC_FLOOR_SIGNATURE='ResourceTemporarilyUnavailable'; fi
if (! '[' '-f' "$GUNBC_FLOOR_RECEIPT" ']') || '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']' || ('[' "$GUNBC_FLOOR_CLASS" '=' 'infra' ']' && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=structural' "$GUNBC_FLOOR_RECEIPT"))) || ('[' "$GUNBC_FLOOR_CLASS" '=' 'none' ']' && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=structural' "$GUNBC_FLOOR_RECEIPT")) && (! ('[' '-f' "$GUNBC_FLOOR_RECEIPT" ']' && 'grep' '-q' 'class=infra' "$GUNBC_FLOOR_RECEIPT"))); then 'printf' 'class=%s\nsignature=%s\nexit=%s\n' "$GUNBC_FLOOR_CLASS" "$GUNBC_FLOOR_SIGNATURE" "$GUNBC_FLOOR_EXIT" > "$GUNBC_FLOOR_RECEIPT"; if '[' "$GUNBC_FLOOR_CLASS" '=' 'infra' ']'; then 'echo' '::error title=environment::floor_class='"$GUNBC_FLOOR_CLASS"' signature='"$GUNBC_FLOOR_SIGNATURE"' exit='"$GUNBC_FLOOR_EXIT"'; this is not a verdict about the diff. Attempt receipt: '"$GUNBC_FLOOR_RECEIPT"; fi; if '[' "$GUNBC_FLOOR_CLASS" '=' 'structural' ']'; then 'echo' '::error title=subject::floor_class='"$GUNBC_FLOOR_CLASS"' exit='"$GUNBC_FLOOR_EXIT"'; read the step log for the subject defect'; fi; fi
'exit' "$GUNBC_FLOOR_EXIT"

- name: Declare which ledger rows this heal will repair
run: |
run: |-
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/instruments/generated_artifact_gate.dag --function heal_repair_declaration
- name: Regenerate every registry-rostered generated artifact (not the stage0 mirrors)
run: |
run: |-
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main
- name: Produce the sealed repair candidate
run: |
run: |-
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/heal_candidate.dag --function heal_candidate_produce_wet
env:
Expand Down
Loading