Repository navigation
The eval driver's verb surface becomes a plan, the way the CLI driver's already is - #11952
Conversation
…'s already is The rendered main decided the verb itself: it read argv, compared the first word against three literals, and refused inline at three points with its own message and its own status. Each of those is a DECISION taken in emitted Rust, where no .dag consumer can read it, no witness can exercise it, and no refusal vocabulary owns it. gunbc.source_root_eval_driver_seed_growth names the capability that retires its row -- the rendered main becomes one call into a fold -- and this is the first part of that: the verb surface. The shape is not invented. v2.cli.compile_cli already renders a thin main for the other driver as five calls: parse, plan_source_roots, run, outcome_text, exit. This mirrors it, with one addition the eval driver needs -- adjudicate reads a host-facts file whose path comes from argv, so the plan names that too. The split exists for the same reason there: the host cannot know which roots to walk or which file to read until argv is parsed, and this module cannot read a directory. BEHAVIOUR IS PRESERVED EXACTLY, including where that looks like an omission. `census` with no roots is PLANNED rather than refused, because the rendered main collected an empty vector and let the run fold answer; a parse-time refusal would be a new wall wearing a refactor's clothes. The three refusal messages are carried verbatim. Exit 2 is the cited misuse code the rendered main used for all three. Evidence: ten arms in v2.test.claim.native_driver_plan -- every verb, every refusal, both accessors, and the preserved empty-roots case. 10 PASS. Mutation-verified: making adjudicate treat its facts path as a root reds the facts-path arm; letting a later word repair a refused parse reds the two unknown-verb arms. What this does NOT do: the rendered main still dispatches on the verb and still carries run_census, run_census_resolve and run_adjudication, which hold the cost accounting, the timing and the JSON rows. Those are the next parts, and each is separable from this one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
#11959) dcd1552 introduced 7 blocking parse errors, and they blocked the floor for every lane: a parse FAIL lends no declaration index, so the floor refuses at ArmSetConsumerPlanningUnavailable and never prepares a subject. mtcollins1_boot_authorization.dag:188-191 annotation names no subject (trailing block at EOF with no declaration after it) -- moved onto MtCollins1BootSubject, the declaration it is about, since the block's subject IS that type's gate. deepseek_v4_1_flash_authority_witness_test.dag:239,250-251 in-body annotations -- hoisted onto the enclosing test fn, after the block already attached there, in source order. Prose byte-identical in both; no semantic line touched. This is the fourth landing of this class today, which is what a required gate that cannot refuse buys: the class is only mechanically preventable once #11829 binds the floor's adjudicator. Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ispatch is deleted Review 69524: the plan had no production consumer and the emitted main kept the same three literals and messages. emit_source_root_eval_driver_main_rs now renders main as native_driver_parse + plan-derived roots/facts path + plan exit, dispatching on the plan's verb. The usage line stops naming a crate (the fold had hardcoded v1_compiled, the pipeline-free crate's name). Stage0 mirror regen follows. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Now owned by wise-raven-686. This addresses review 69524 at One fact, two sources: fixed by cutting over at the root.
The three literal mode comparisons and the three inline refusals are deleted. The only remaining arm the shim writes is an impossible "refused plan with a success exit", which exits 70 loudly. The stage0 mirror No production consumer: fixed. The rendered driver main is now the consumer of Refusal texts pinned a copy: resolved by the cutover. The strings the witnesses assert are now the only ones the program prints. One bug surfaced along the way: the fold's usage line hardcoded Evidence and limits: — sent from wise-raven-686 |
Held: this PR's contract is now subject to a deliberate amendment (Pkg 9)Operator ruling, 2026-09-21: This PR's stated scope is behaviour-preserving — it moves the verb surface out of the rendered main into a modeled plan while preserving the old verbs. That is no longer the destination, so merging it as-is would land a modeled spine around a verb set that is about to change shape. What specifically moves:
What should be kept from
And one trap worth recording before the amendment is written: native-lane admission does not mean "every requested test passed." It admits an observation carrying classified exclusions provided its other conditions hold. That is useful for observing an incomplete migration and is not the success contract for ordinary I am not taking this further; flagging it so whoever owns Pkg 9 amends from here rather than rediscovering it. The witnesses in this PR (10 arms, 2 discriminating mutations) remain valid for the parse/plan layer regardless of which verbs survive. |
|
Owner's response to the hold above. These are the terms Pkg 9 is written against:
— sent from wise-raven-686 |
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
This answers the hold comment above. Manager ruling: the spine lands now and Pkg 9 amends it.
The four controls you named (the false/true pair, malformed, old-route, closure + executable identity) are untouched by this diff. Merge readiness waits for them to be green in the required-v2-native receipt on this exact head. — sent from wise-raven-686 |
…hority Review 69567: native_driver_plan_facts_path had no production consumer (the rendered main reads facts_path from the Adjudicate verb). Deleted, both prose blocks corrected, and the misuse arm compares against exit_code_misuse. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69567 is fixed at
Control: — sent from wise-raven-686 |
Review 69580: the cutover removed main's closing brace with the old tail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69580 is fixed at
Honest limit, as the review says: the rendered main still has no executing consumer that has run. The executing consumer is — sent from wise-raven-686 |
|
Native lane run on exact head
So the four controls still cannot be observed on this PR's own head until #11971 lands. They are being run on the integration branch (main + #11971 + #11919 + this PR + the argv wiring) meanwhile. That run is labelled as composed evidence and will not be credited to this head. — sent from wise-raven-686 |
…an-spine # Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…an-spine # Conflicts: # src/v2/compiler/00_compile.dag
…iverse The driver plan's adjudicate is now: adjudicate <host-facts.tsv> <target-pattern> <source-root>... The pattern is parsed by extdeps.bazel.target_pattern parse_target_pattern; an unparseable or missing pattern is a plan refusal with the misuse status (2). The rendered run_adjudication calls native_lane_universe_selected(ingest, pattern). The seed lane runner passes the default //v2/test/... (mirror of native_route_default_pattern). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> (cherry picked from commit 0d10ab3)
…nd over merged main Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Head
— sent from wise-raven-686 |
|
Side-chat review approved merging this head (b52c7b5) under the operator's delegation, as the consumed plan/target-pattern increment. It does not qualify native Boolean-test execution or complete Pkg9. I read the floor log: planned=423, executed=423, claims_failed=0, verdict=FloorClean. Still open: the live true/false pair is an execution obligation, retried and requalified once the Pkg12 resolver work lands (a changed refusal gets investigated, not auto-accepted); the identity-level no-regression comparison; and facts_path. |
What was in the rendered main
It decided the verb itself — read argv, compared the first word against three literals, dispatched, and refused inline at three points with its own message and its own status:
Every one of those is a decision taken in emitted Rust, where no
.dagconsumer can read it, no witness can exercise it, and no refusal vocabulary owns it.gunbc.source_root_eval_driver_seed_growthnames the capability that retires its row — the rendered main becomes one call into that fold. This is the first part of that: the verb surface.The shape is not invented
v2.cli.compile_clialready renders a thin main for the other driver, as five calls:This mirrors it, with the one addition the eval driver needs:
adjudicatereads a host-facts file whose path comes from argv, so the plan names that too vianative_driver_plan_facts_path. The split exists for the same reason it does there — the host cannot know which roots to walk or which file to read until argv is parsed, and this module cannot read a directory.Behaviour is preserved exactly, including where that looks like an omission
censuswith no roots is planned, not refused. The rendered main collected an empty vector and let the run fold answer. A parse-time refusal here would be a new wall wearing a refactor's clothes — so there's an arm asserting it stays planned.exit_code_misuse, the cited code the rendered main used for all three.Evidence
Ten arms in
v2.test.claim.native_driver_plan— every verb, every refusal, both accessors, and the preserved empty-roots case. 10 PASS.Mutation-verified, both in the direction that matters:
adjudicatetreats its facts path as a source rootadjudicate_takes_its_facts_path_before_the_rootsan_unknown_verb_refuses_and_names_the_word,a_later_word_cannot_repair_an_unknown_verbThe refusal arms assert the exact message. That's deliberate and it isn't a change detector: these strings are the program's command-line contract, this change is a move rather than a redesign, and an arm accepting any refusal text would pass while the contract silently changed.
What this does NOT do
The rendered main still dispatches on the verb and still carries
run_census,run_census_resolveandrun_adjudication— 628 lines holding the cost accounting, theInstanttiming, the/procreads and the JSON rows. Those are the next parts and each is separable.Worth stating for whoever takes the next one: timing and
/procreads are genuine host observations and cannot become pure folds. They belong in the same category as reading argv and walking a directory — supplied back as values, with the decisions they feed living here.Not verified natively: no native binary can currently be built at
main(#11915). This is interpreted evidence, which is the honest level for a pure fold over argv.🤖 Generated with Claude Code