Skip to content

Split the retiree-roster claim from #11800 into two authorable reds, and repair the file's resolve after #11762 - #11842

Merged
briansrls merged 10 commits into
mainfrom
session/nimble-swift-273
Sep 21, 2026
Merged

briansrls merged 10 commits into
mainfrom
session/nimble-swift-273

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Repairs a decoration that landed on main in #11800 (efe292a), found by review 69106, and — discovered while doing so — a live main breakage in the same file. Work item node://adhoc-aa9e0221-13a, parent sunny-ant-606.

1. The decoration (review 69106)

the_real_srv1_retiree_roster_reaches_one_admitted_read in test.claim.runner.runner_host_file_converge_witness_test carried two conjuncts with no authorable red:

  • retired == required_retirees_for_host(host: operator_host_srv1) — f(x) == f(x): runner_host_file_subject sets retired_units to that very call.
  • a test-side disjointness fold over retired and desired — both derive from the width authority on opposite sides of it, so disjoint by derivation.

Both are deleted; no count literal is restored; no assertion whose two sides come from one production call is added (exact manifest correctness stays runner_slot_retirement_witness_test's proposition).

2. Two claims, one interface each

  • the_real_srv1_retiree_roster_reaches_one_admitted_read — narrowly: length(retired) > 0, the argv literal, portable_remote_words admits it. Its red lives in the cgroup read batching / argv transport.
  • every_desired_srv1_unit_is_outside_the_retirement_manifest (new sibling) — plants the whole desired roster beside the real retirees as an observed surplus and requires gunbc.runner_width_transition transition_population_agreement to answer Disagrees { unexpected } with unexpected equal to exactly the desired roster (length(desired) > 0 as a conjunct; Agrees and Undecidable are false). It proves one cross-authority exclusion relation — every identity the deploy currently desires is outside the transition obligation — not that the manifest is exact.

Why its red is authorable in production. The two sides are independent producers: desired_units comes from the deploy row's runner_count via desired_runner_slot_members; the obligation from the transition row via transition_required_retirees_at. Changing production alone — slot: target + 1 → slot: target in transition_required_retirees_at (the off-by-one that counts the top desired-live slot as a retiree, the stale-38 class) — absorbs a desired unit into the manifest, it vanishes from unexpected, and the exact-list equality fails. Planting the whole roster (not one unit) means a later non-contiguous widening that absorbed any other desired unit fails it the same way. An always-Disagrees fold fails it too, since the list must name the desired roster alone.

3. The width migration — and what it is and is not load-bearing for

gunbc.runner_slot_allocation gunbc_runner_slots_per_host was deleted by #11762 in the same window that #11800 added it as an import of this file, so for a while every claim in this file refused to resolve on main and no required lane noticed (v2.workflow.required_floor required_gate_prefixes carries no dag/test/claim/runner/ row, so the file is never resolved unless a diff touches it — DESIGN §3 "the deletion is the census — but only over the population a run compiles", caught in the wild).

That import break is already cleared on main by #11871, not by this PR. This PR is therefore not load-bearing for the floor/parse chain. What it replaces is #11871's repair itself: that one returns 0 - 1 from srv1_width() on the unresolved arm — a fabricated sentinel (DESIGN §5), and one that would start srv1_retiring_names at slot 0. Here srv1_width() is Int?; the unresolved arm yields an empty listing from the four width-derived helpers, and every consumer was audited so that cannot become an absorbing fallback: five carry a positive conjunct no unit can satisfy on an empty listing (every_unit_holds, population_holds, an effective population); the two pure-refusal claims (a_declared_live_slot_missing_from_the_host_refuses, an_unread_omitted_retiree_refuses) gained a length(...) > 0 conjunct. The TransitionPopulationUndecidable arm from #11762 closes to false.

So the PR's value rests on two things: the claim-quality repair (§1–2) and replacing the 0 - 1 sentinel with the typed arm.

Evidence

claim_batch built from this exact head into a private CARGO_TARGET_DIR:

  • path /tmp/nimble-swift-273-target/release/claim_batch, sha256 9c0882411376f303a92a3a8deb984eaa15598da42f301a77a79290f91b7db7a5
  • build head 20a471d8de5 (main merged through 87c6658641e; zero commits behind main at build time), worktree clean, built 2026-09-20 19:56:42–19:58:58 UTC
  • three earlier takes (12:10Z cba30e3b…; 15:52Z c5cea50c… at 9f7d5893f82; 17:51Z 295d7697… at 3d52ee3487d) are superseded; every re-take reproduced the same verdicts and eval-step counts exactly.

One targeted invocation per arm, GUNBC_MEMORY_BUDGET_BYTES=16GiB, the same four claims:

claim head production-only mutation (slot: target + 1 → slot: target in transition_required_retirees_at, test untouched)
the_real_srv1_retiree_roster_reaches_one_admitted_read PASS (59,457 steps) PASS (62,183)
every_desired_srv1_unit_is_outside_the_retirement_manifest PASS (9,785) FAIL (9,893)
a_declared_live_slot_missing_from_the_host_refuses PASS (20,055) PASS (20,233)
an_unread_omitted_retiree_refuses PASS (61,508) PASS (61,933)

The argv claim stays green under the mutation that reds the transition claim — the two controls are independent. Mutation reverted; worktree clean after.

🤖 Generated with Claude Code

…production refusal

review 69106: `retired == required_retirees_for_host(host: srv1)` was f(x) == f(x)
(the subject's retired_units IS that call), and the test-side disjointness fold
compared two sets derived on opposite sides of gunbc_runner_slots_per_host.
Neither had an authorable red. Both are deleted; the argv equality and the
portable_remote_words admission stay. The relation the stale 38 stood in for is
now asserted through transition_population_agreement: the real roster plus the
subject's top desired unit (from the deploy row, an independent producer) must
be refused naming exactly that unit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Repair the tautological retiree-roster claim from #11800 Replace the tautological retiree-roster conjuncts from #11800 with a production refusal (review 69106) Sep 20, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 20, 2026 12:38
gunbc-ci-auto-heal and others added 4 commits September 20, 2026 14:36
…le's resolve after #11762

Side-chat changes on #11842: the argv claim keeps only its own subject
(length(retired) > 0, the argv literal, portable_remote_words admission);
every_desired_srv1_unit_is_outside_the_retirement_manifest plants the whole
desired roster beside the real retirees and requires
transition_population_agreement to name exactly the desired roster.

Also repairs main: #11762 deleted gunbc_runner_slots_per_host while #11800
added it as an import here, so every claim in this file refused to resolve.
srv1_width() now reads gunbc_runner_committed_width (Int?; the unresolved
arm yields an empty listing, and the two pure-refusal consumers gain a
length > 0 conjunct so an empty listing cannot pass vacuously). The new
TransitionPopulationUndecidable arm closes to false.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Replace the tautological retiree-roster conjuncts from #11800 with a production refusal (review 69106) Split the retiree-roster claim from #11800 into two authorable reds, and repair the file's resolve after #11762 Sep 20, 2026
The authorability sentence cited gunbc_runner_slots_per_host and
transition_required_retirees, both superseded by #11762; it now names
transition_required_retirees_at and the slot: target + 1 range start the
evidence run actually mutated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

review 69250 addressed in 7d5d27d: the authorability annotation now names the live mutation — slot: target + 1 → slot: target in transition_required_retirees_at, over gunbc_runner_committed_width's RunnerWidthDerived { slots } arm — which is the mutation the evidence run actually performed. The remaining gunbc_runner_slots_per_host mention (the historical one) is unchanged. The commit touches only // annotation lines, so the annotation-erased program the four verdicts were taken on at 9f7d589 is byte-identical (DESIGN §4c).

— sent from nimble-swift-273

gunbc-ci-auto-heal and others added 3 commits September 20, 2026 17:47
# Conflicts:
#	dag/test/claim/runner/runner_host_file_converge_witness_test.dag
Ledger-Repair-Judged: docs/design-rung-drops.md
Heal-Candidate-Run: 35533936549
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 20, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 20, 2026
@briansrls
briansrls added this pull request to the merge queue Sep 21, 2026
Merged via the queue into main with commit 267e6a7 Sep 21, 2026
4 checks passed
@briansrls
briansrls deleted the session/nimble-swift-273 branch September 21, 2026 02:43
@briansrls
briansrls restored the session/nimble-swift-273 branch September 21, 2026 02:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant