Skip to content

Primitive-egress wind-down (split A): OpenBMC Optional repairs, roadmap authority, main repairs, EFFECTS-1 cut (c) - #11993

Merged
briansrls merged 173 commits into
mainfrom
fierce-seal-607/wind-down-split-a
Sep 23, 2026
Merged

briansrls merged 173 commits into
mainfrom
fierce-seal-607/wind-down-split-a

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Operator ruling 2026-09-21 (option A on the cost-budget escalation): the wind-down consolidation #11895 is split. This PR is #11895's reconciled tree with CRYPTO-0 and ENCODING-0 restored to main's versions; those two re-draft from #11895's history once NUMERIC-BIT's kernel arms bring interpreted SHA-256 and the whole-object App Attest parses inside the floor's new-witness cost budget (their 22 witnesses ran at 0.8–4 M eval steps against the 100 ms-equivalent; every witness here is within it).

The fleet-lane seal is main's now. #11829 landed a different construction of the same fix (the receipt kept, its D0-ADJUDICATE consumer bound); one authority for one fix (§3), so the generation-refusal seal this PR carried from #11836 is withdrawn — predicate, witness and failure-mode row deleted. The honest-floor evidence below was gathered under that seal before it was withdrawn and is the same verdict main's seal now produces.

Lands here

from content
#11834 extdeps.bmc.openbmc_fan_control: nine Optional .first() sites matched under #11720's wall; OpenBmcStepwiseScalars carrier.
#11872 Roadmap: twelve primitive-egress rows + ten edges (the CRYPTO-0/ENCODING-0 rows name the cost budget as their trigger and #11895 as their reconciled tree); owner added to the page focus.
#11744 EFFECTS-1 cut (c): 412 authored uses rows deleted where derived service demand is nonempty, the same criterion applied to every row main added since; ten retained rows with per-row triggers; the interpreter purity gate's declared rung drop; follow-up roster re-derived at the landing head.
main repairs the honest floor exposed the GuaranteeStall #11625 declared but never rostered; mosquitto_options_binding naming which Filesystem it reads; openbmc_* naming std.string_type for String; jws.dag's raw-List base64 call admitted through the sealed mint; fabric_storage_wire witness body annotation hoisted; (the census-image wet claim that was red on every main queue run since #11731 is repaired at its root by main's #12024, which this PR takes.)

Projections (ROADMAP.md, docs/design-rung-drops.md, docs/plans/demand-engine-program.md) regenerated on this tree via generated_artifact_gate main_wet_one.

Evidence: floor at 03d4f26 and ac43f1a — planned=415 executed=415 passed=402 known_red_held=8 claims_failed=0 interrupted=0 completed_over_cost_requirement=0, verdict=FloorClean, phases_failed=0.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits September 18, 2026 18:14
… in .dag

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ise the fold accumulation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…to.mac off the RustCrypto primitives

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ranscription

The bitwise claim was false and the fold was correct. 0x0FF00FF0 was written as
267391984, which is 0x0FF013F0, while the expected and/or/xor beside it were
computed from the pattern intended. .dag has no hex literal, so the conversion is
done by hand and read by nobody; a comment stating the intent cannot catch it
because no machine reads one. The transcription is now claimed against the octet
packing, which has its own pinned vectors, so a future mistype reds a claim that
names the constant rather than one that blames the fold.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…; padding witness matches on get

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…consumers

The previous commit's edits to these three files never reached disk; the floor named them again.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…itness from main

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The initial hash values and round constants are facts of FIPS 180-4, not of a message; sha256_octets
re-derived all 72 words on every digest (DESIGN §2, §6 bare minimum cost). They are now data rows.

Measured with claim_batch eval_steps, prediction recorded beforehand: the_published_abc_digest_holds
1063259 -> 1063261; mac_sign_produces_the_published_rfc4231_case1_tag 4123450 -> 4123448. The
predicted ~-70k per HMAC did not appear: the interpreter's pure-call memo was already collapsing the
repeated decode, so the cut removes the work from the source and from emitted code, not from the
interpreter's step count.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…frontier as rows

Review 68053 (REQUEST_CHANGES), both findings.

(1) word_modulus walked int_pow_bounded on every operation to learn one of
four numbers, so every op paid a linear recursion with a checked multiply per
step just to read a constant off a closed coproduct. It now answers from the
closed set, and word_modulus_agrees_with_the_power_authority_holds runs the
table against std.induction int_pow_bounded for every member including Width64,
where both must answer with nothing -- the value is derived and checked, not
transcribed and trusted. word_shift_left also computed two powers where the
second is the modulus divided by the first.

(2) The operations landing ahead of their consumers said so in a // block, and
DESIGN 4c rules an annotation is not evidence a machine claim holds. They now
carry std.roster_frontier rows: DeclarationAppears bound to the exact symbols on
gunbc#11647 where the consumer exists to cite, unbound with a stated description
where it does not, because a forward citation to a name nobody has written can
never resolve. word_zero and word_equal had no consumer anywhere and were
deleted rather than described; word_rotate_left needs no row because
word_rotate_right consumes it here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ited instance

Verifying review 68053's first finding against the code surfaced two more
instances of the same defect that the finding did not name: word_wrapping_multiply
walked int_pow_bounded per call for its split point, and octet_radix did the same
for a number this module already answers. Fixing only the cited site would be
repairing the symptom rather than the boundary.

word_half_radix is derived once over the closed set and checked against the power
authority, as the modulus is; it refuses Width64 although 2^32 IS representable,
because a split point for a word with no residue would be answering about a
subject that does not exist, and that deliberate disagreement is claimed rather
than left looking like an oversight. octet_radix now READS the Width8 modulus
rather than deriving a second constant, so nothing new was introduced that could
go stale. The three surviving int_pow_bounded call sites all take a genuine
variable.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…l signature

Review 68073. std.dissolution bound_dissolution takes ref: DeclarationRef and
does the DeclarationAppears wrapping itself; the four bound rows passed a
DissolutionTrigger under a keyword the signature does not declare. I wrote the
call from the TYPE it constructs rather than from the helper's own signature,
which is how a call can look right beside the type declaration and bind against
nothing. The floor refuses this, so the frontier claim could not have been green
-- neither of the two heads carrying it has a CI verdict yet, so this was caught
by review rather than by a run.

DeclarationAppears, DeclarationRef and DissolutionCondition were imported only
for that mis-shaped call and are dropped.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s its expiry

Review 68088. The roster asserted in prose that gunbc.dissolution_census reads
it, while the census folds census_closure_frontier_row_groups, which it was not
a member of. So every row's expiry was computed by nothing: when
extdeps.crypto.sha2 sha256_add_all lands, a row outside the census is never
reported fired-still-present and its trigger cannot fire. That is the inert-lens
tier, and it is the same DESIGN 4c violation the roster exists to correct,
committed in the sentence claiming to correct it -- declaring rows in a typed
carrier is half of the discharge and being folded is the other half.

Enrolled in gunbc.census_closure_frontier and renamed to the roster's
_frontier_rows convention. The two existing claims assert the declarations
exist, which is not enrolment, so a third joins the rows against the census
closure itself by subject key; dropping the group entry reds it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68118. word_from_octets was the one exported operation that did
arithmetic before guarding on its own width: it guarded on octet_radix, which
asks about Width8 and always answers, so a Width64 call passed the count and
per-octet checks and then accumulated eight octets to as much as 2^64 - 1 in the
Int the seed realizes as i64, with word_of_int refusing only afterwards. The
refusal was inspecting a number the realization had already wrapped or trapped
on -- the post-check this file's own word_wrapping_multiply annotation forbids,
and the thing that made the module's Width64 sentence false for one entry.

Every other exported operation was checked and guards on word_modulus first.

A Width64 call with the wrong octet count now reports WordWidthUnrealizable
rather than OctetCountMismatch, which is the right order: a width with no
residue the carrier can hold is the more fundamental fact.

The arm was unwitnessed, which is why it stood -- nothing reds on a path no
claim runs. Three claims now pin it, the from_octets one supplied the exact
eight-octet input that overflowed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t from this tree

The required declarations phase refused four CITED-MODULE-ABSENT: std.machine_word
cites extdeps.crypto.sha2 sha256_add_all / sha256_sigma / sha256_xor3 /
sha256_ch, and no module declares extdeps.crypto.sha2 here. It exists on
gunbc#11647 and nowhere else.

A DeclarationRef is a CITATION and the gate resolves it against the tree it runs
in, not against any branch. I had written the rule correctly on the issue -- a
forward reference to a name nobody has written can never resolve -- applied it to
three rows, and then broke it for four because I had READ those symbols on
CRYPTO-0's branch, which is what made citing them feel safe. Seeing a symbol
somewhere is not this tree being able to check it.

DeclarationAppears remains right for a forward reference into a module that
already exists; it is the absent MODULE that cannot be cited. The four consuming
symbols are now named in prose in each description, where they point a reader
without asserting a reference this tree must honour.

Floor was already clean on b290752: verdict=FloorClean, claims_failed=0, all 43
newly enrolled claims passed. This was the parse phase alone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t, order width before amount

Three defects, each with a counterexample on a40faa2.

(1) Word is an ordinary record and .dag has no module-private construction, so
word_of_int being the 'sanctioned entry' was unfalsifiable -- nothing refused the
other route. word_shift_right(Word{Width8,256},1) answered WordReady 128, and no
arm fired because the OUTPUT was in range: the operations validated their results
and trusted their premises. Every exported boundary now qualifies its Word
arguments against their own declared width before any arithmetic reads them, via
one shared seam, and word_from_octets qualifies every member -- it checked member
width and trusted member value, so [1, 256] packed to 512 at Width16. This is
mitigation and says so; sole construction remains the trigger that DELETES these
checks rather than keeping them.

(2) int_to_octets read every absent capacity as 'fits'. int_pow_bounded answers
Absent both when the power exceeds the Int bound, where every representable value
genuinely is below it, and when the exponent is NEGATIVE, which is not about
capacity at all -- so count = -1 returned OctetsReady [], a successful empty
rendering of a nonsense request. The neighbouring annotation had already named
this exact conflation and the code committed its other half. The count is decided
on its own terms before the capacity is asked.

(3) word_rotate_right asked amount before width, alone among the four shift and
rotate arms, so a Width64 rotate by 64 named the amount when the width is what
cannot exist. Two operations disagreeing about which refusal one malformed call
produces is a fork in the refusal vocabulary.

Controls for all three, each red against the pre-fix code, including one per
exported family so a partially applied premise check cannot pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/test/claim/approval_device_redemption_witness_test.dag
…octet seam

main's #11660 added std.encoding utf8_decode_octets, which reads each member
through base64_octet_int -- the 'b + 0' identity whose entire content was a width
claim it never checked, and which this branch deleted. The two changes are
correct separately and refuse together: a SEMANTIC conflict, with nothing
overlapping textually, so the merge is clean and the resolve is not.

Fixed here rather than in #11647 because this branch removed the helper and lands
first. The replacement is the seam base64's own octets already use:
base64_octet_word admits through word_of_int at Width8, and Utf8Refused is the
honest destination, which is the state this fold already uses for every other
malformed input -- no new refusal vocabulary for a case the model had a word for.

The discriminator is a NEGATIVE member, not an oversized one: 256 refused on both
paths because utf8_step rejected it anyway, but -1 satisfied  and was
decoded as an ASCII scalar of -1. Three controls, one of them that exact input.

gunbc.plans.blackjack_onboarding taught base64_octet_int in a code sample and in
prose; deleting the symbol is what made that stale, so it is repointed here
rather than left for its owner to discover.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…action that lands their consumer

std.machine_word machine_word_consumer_frontier_rows named word_wrapping_add, word_rotate_right,
word_xor and word_not as awaiting extdeps.crypto.sha2 (sha256_add_all, sha256_sigma, sha256_xor3,
sha256_ch). That consumer lands here, so the rows are deleted rather than rebound: a
DeclarationAppears trigger written in the same commit as its declaration fires on arrival and
describes nothing. Consumption is evidenced by execution in sha256_fips180_witness_test.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…_int_value

Two boundaries the premise seam missed, which is the partial-coverage state my
own commit message named and then left one function short of complete.

(A) octet_int_values mapped o.value over its members with no qualification and no
refusal arm, so [Word{Width8,256}] projected to [256] -- and std.encoding consumed
that projection on the base64 decode production route. A projection is not exempt
from the premise rule: reading a field is where an uninhabitable word stops being
a record and becomes a number a consumer trusts. It now qualifies through the
same octets_first_unqualified fold word_from_octets uses, so width and value come
from one authority rather than two agreeing by accident, and returns a typed
result because a projection that can refuse must be able to say so. Threaded at
the base64 caller, which already had an Optional channel.

(B) word_int_value was unqualified AND had no consumer, witness or frontier row
anywhere. Deleted, the same remedy word_zero and word_equal got: a declaration
with no consumer at all is removed, not described. A caller with a matched
qualified word reads its field directly.

Three controls: an out-of-range member, a non-octet member, and a qualified
positive.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lper repeats

Ruled repair shape. .dag has NO module-private, so every top-level helper is a
callable boundary and there is no wall to put one behind. Qualifying each public
operation and leaving the helpers taking raw Word left four raw entrances, and
one of them was the defect the public wrapper exists to prevent:
word_from_octets_realizable was callable directly with Width64 and would
reconstruct up to 2^64 - 1 in the i64 before word_of_int refused. I had split
that body out claiming the guard could not be bypassed. A name is not a proof.

Re-validating inside every helper is validation multiplied by helper count, and
it fails when helper N+1 forgets -- which is exactly how the projection survived
the previous pass. So the proof moved into the type. QualifiedWord is produced
only by word_qualified / word_pair_qualified; RealizableWidth only by
word_realizable_width, the one function that refuses Width64. Helpers below the
public boundary take those carriers, so reaching them unqualified does not
typecheck. Public ops take Word, qualify once, pass carriers down.

octet_int_values takes List<QualifiedWord> and LOSES its refusal arm: with every
member arriving with its proof attached there is nothing left to refuse, so the
typed result added last round is gone again -- the carrier subsumed it.
word_int_value stays deleted. OctetsReady now carries List<QualifiedWord>, which
is an interface change for consumers of word_to_octets; CRYPTO-0 told.

Honest about the rung: a record with public fields is still constructible, so
this is a sealed wrapper, not a private constructor. It changes the failure mode
from "a helper forgot" to "someone forged the proof". Rung unchanged at
mitigatable; sole construction remains the next-rung trigger.

The wall is unwritable in the accepted corpus by construction, so the controls
are fixture sources compiled through the real acceptance path, in their own
module -- machine_word_witness_test is stamped SubstrateInputsOnly truthfully and
compile_dag_diagnostic_census walks the checkout, so the claims could not live
there without making that stamp a lie. Three REDs, one per former raw entrance,
plus a green control that is load-bearing because three REDs alone are satisfied
by a compiler that stopped judging argument types.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…GN §4c)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68365, and the build lane had already caught its consequence: the
generated-artifact gate reported dag/test/fixture/approval_device_redemption/
vectors.json DRIFTED, which is this defect rendered into bytes.

path_segment joined base64_encode(...) directly into the segment. This PR changed
that return to String?, and this call site arrived on main from gunbc#11660 while
this PR was in review, so the two are correct separately and wrong together --
nothing overlaps textually, the merge was clean, and an Optional was being joined
into a route identity. Every other caller in the tree was migrated; this one did
not exist when I migrated them.

The arm is unreachable here: the octets are the UTF-8 encoding of a String, so
every member is a byte by construction. The declared contract is TOTALITY -- the
annotation above the function says the segment is total, injective and never
refused -- so threading an Optional out would be a weaker contract at a
route-identity boundary rather than more honesty, and would ripple into
decode_path_segment. std.bytes divergent seam is the declared idiom for an arm
that cannot be reached; same treatment and same reason as
encode_sm_access_version_payload_wire earlier in this PR.

The vectors drift is expected to clear without regeneration: the committed file
was generated when path_segment was correct, and this restores that.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
…ced a regen

CI on 8d81d86 was structural, not infra: the carrier refactor changed
word_to_octets to answer List<QualifiedWord> while word_from_octets takes
List<Word>, and octet_packing_round_trips_holds fed one into the other --
"value does not inhabit its declared type at the generic type argument:
declared Product(Word), produced Product(std.machine_word.QualifiedWord)".

That round trip is an ordinary consumer pattern, not a witness artefact: SHA-2
block packing is exactly to_octets into from_octets. So the unwrap is exported as
qualified_words_to_words rather than open-coded at the call site. It discards a
proof, which is safe in this direction only -- word_from_octets re-qualifies every
member, so the cost is paying the check twice, never skipping it. The asymmetry
is deliberate and stays: a caller assembling octets by hand has raw Words, and
making the entry demand carriers would push the qualification back onto callers.

Separately, the plans-doc edit is REVERTED. It repointed prose that taught
base64_octet_int, which this PR deletes, and doing so drifted the generated
docs/plans/blackjack-onboarding.md. A remote regen of the generated-artifact gate
produced no change to that projection, so I cannot verify the repair, and I will
not carry an unverified edit to a generated artifact to close a drift I created.
The file is now byte-identical to main and the drift clears. The staleness is
real and is reported on the PR rather than silently dropped -- and the right
replacement is a judgment for that doc owner, since the idiomatic form under the
new model is not a one-for-one symbol swap.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 12 commits September 22, 2026 02:44
…down-split-a

# Conflicts:
#	dag/gunbc/instruments/github_app_acquire.dag
#	docs/design-rung-drops.md
…ses rows

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s/temporary rung, reason, population and return trigger on gunbc.rung_drop, rostered

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d the END marker; the claim binds the console device now), so the schedule withdrawal and its rung drop are retracted

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
extdeps.auth.jws: take main's side whole. Both sides removed the raw
List<UInt8> reaching base64_encode; main's cut does it at the stronger
rung -- the formal becomes QualifiedOctets and the octet range is
observed once at the std.bytes boundary, with JwsEncodeOutcome and
JwsSerializationOutcome carrying the refusal -- while this branch's cut
folded base64_octets here with an unreachable-seam arm, which is exactly
the reasoning main's annotation retracts. This branch touched no jws
consumer, so nothing of ours is lost with it.

docs/design-rung-drops.md: generated projection, concurrent divergence.
Base side taken verbatim per the driver's declared repair route; set
difference over row identities (failure-mode slugs and rung-drop
headings) against origin/main is empty, so no base row went dark. Not
regenerated locally -- heal derives it from the merged authorities.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…hree causes

Review 70194 (non-blocking): openbmc_stepwise_scalars answered a bare
Absent for both a row count other than five and a row missing at an
index the count admits, and the caller then refused with one sentence
that also covered negative duty -- three causes with different repairs
behind one string.

The fold now answers OpenBmcStepwiseScalarsResult, naming the cause and
carrying the observed count or the absent index. The caller splits the
composite guard into its three checks, each with its own reason. No arm
widens: every arm still refuses.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 70208 (cosmetic, non-blocking): deleting a `uses` clause left a
line of trailing spaces between the signature and its `{`. 27 lines
across four files. The remaining `) -> T` / `{` pair is the shape the
corpus already carries wherever a signature wraps.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

The single failing check is not from this diff.

emit-build refuses at the //gunbc/instruments:self-host step with floor_class=structural exit=2, rustc E0573 expected type, found variant PointerWidth. The site is in the EMITTED crate: src/std_integer.rs:162 writes crate::std_machine_constraints::MachineWidth<PointerWidth> with PointerWidth unqualified, and that spelling now resolves to the WidthResolution variant rather than the bodyless type — rustc offers both candidate use lines. The emitter dropped the qualifying path for a spelling that has two declarations in the closure since 32fc2c87d1f (kind reflection) landed.

Evidence that it is the trunk and not this branch: the identical annotation is on the merge-queue runs of two unrelated PRs, #12059 (run 35775641816) and #12060 (run 35775942248), whose only commonality with this branch is main; branch runs before that landing were green. clippy and compiler are green here, and the seed builds — the gap is emission-side only.

The repair is already in flight as #12070, which is exactly this class (an_authored_import_emits_no_use_line_when_its_spelling_is_forked). Holding this PR until it lands rather than touching v2 emission from this lane.

Both review nits are fixed: review 70194 (typed stepwise-scalar refusal cause) in c0d0eee, review 70208 (whitespace residue from the deleted uses lines) in 43ee636.

— sent from fierce-seal-607

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md interpreter_purity_gate_reads_authored_uses_only
Heal-Candidate-Run: 35780463577
@gunbai-bot gunbai-bot Bot changed the title Primitive-egress wind-down (split A): fleet-lane seal, main repairs, openbmc Optional sites, roadmap rows, EFFECTS-1 cut (c) Primitive-egress wind-down (split A): OpenBMC Optional repairs, roadmap authority, main repairs, EFFECTS-1 cut (c) Sep 22, 2026
…carry the five ENCODING defects as obligations

EFFECTS-1 now names #11993 as the landing of cut (c) and leaves only E2 and
the restatement refusal open. CRYPTO-0 and ENCODING-0 cite the immutable
quarry head 8fc4448 (tag quarry/11895) instead of a mutable branch, and
ENCODING-0 no longer describes the parser landing as landed: it records the
five review defects in the reconciled tree, each with its refusal control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Correction: emit-build is red on E0573 expected type, found variant PointerWidth (std.integer UIntPlatform over std.machine_constraints WidthResolution, from #11996). Main's merge-queue runs fail identically, so it is not this diff. #12070 is not its fix — that PR's description says so. This PR holds until the actual MachineWidth emission repair lands on main; then it merges that base, reruns the semantic uses census at the frozen landing base, and returns an exact green head.

Also in 789e3bf: roadmap rows now name #11993 as the split-A landing, cite the #11895 quarry head 8fc4448575cd (tag quarry/11895), and record the five ENCODING defects as obligations on egress-encoding-0-cbor-der-landing. #11895 is marked draft / DO NOT MERGE and will be closed unmerged after this lands.

🤖 Generated with Claude Code

Ledger-Repair-Judged: docs/design-rung-drops.md
Heal-Candidate-Run: 35789591558

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD at 885ad19c2a97d9cf2adb7f9cae1b79506e5f0aa4; the prior conditional source approval of the substantive Split-A tree still stands.

The shared E0573 blocker is now repaired on main by merged #12089, not by #12070 or the redundant first commit of #12091. Before this lands:

  1. Update onto the actual final main and rerun cut (c)'s semantic census at that frozen base. demand_restatement_follow_up_commit_range still says 5ff323b6d29..87c6658641e, and demand_restatement_follow_up_modules still carries that historical population while the surrounding authority says it was re-derived at the landing head. Enumerate every authored uses row at the final base, resolve each ordinary function, apply the same ItemInfo.service_names criterion, delete the measured restatements, and carry only exact unresolved/out-of-range rows with their triggers. Then update both symbols.

  2. Remove the duplicate import of fabric_purpose_handover_registration_unobserved_stall in gunbc.guarantee_stall.roster; keep exactly one import and one all_guarantee_stalls member.

  3. Sharpen ENCODING defect (4)'s durable acceptance control to both DER directions. The original defect was that der_expect ignored DerElement.constructed: a primitive encoding of a constructed tag (the concrete outer-Certificate SEQUENCE mutation 0x30 -> 0x10) was admitted, and constructed encodings of primitive tags were admitted. The roadmap currently names only “a constructed encoding of a primitive tag refuses.” Require both: primitive SEQUENCE/SET/context-constructed encodings refuse, and constructed BOOLEAN/INTEGER/BIT STRING/OCTET STRING/OID encodings refuse, with discriminating controls.

After the color-attribution repair from #12091 is rewritten onto current main and lands, merge that final base here, regenerate all projections, and return exact-head compiler/clippy/emit-build/floor green. Then this is approvable; close #11895 unmerged only after #11993 lands, as planned.

@briansrls
briansrls added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit 4716b4c Sep 23, 2026
4 of 5 checks passed
@briansrls
briansrls deleted the fierce-seal-607/wind-down-split-a branch September 23, 2026 02:27
gunbai-bot Bot pushed a commit that referenced this pull request Sep 23, 2026
Main's EFFECTS-1 cut (#11993) deleted the uses-net clauses in five files this branch also edits. Resolved
to this branch's content with the same clauses removed, and the same cut applied to the new
mtcollins1_boot_federation entry. fleet-converge.yml regenerated from the merged authority.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 23, 2026
…ses onto a hermetic route with no ReadInterfaceFile arm

Floor on 3a746c4 and 81696b3: every executed claim passed, and
route_gap_unenrolled=10. Deleting the uses rows in
test.manual.runner_microvm_lifecycle_wet_receipt made its wet tests changed
witnesses. The floor plans those onto the hermetic route, and
extdeps.linux.cgroup_v2 ReadInterfaceFile declares no mock_response, so all ten
stopped before a verdict. The floor says enrolling them in
v2.workflow.floor_route_gap records debt, not acceptance.

So the module returns to main's bytes. Its 17 identities are measured
deletable but retained under a new trigger, EditedWitnessHasNoHermeticRoute:
ReadInterfaceFile gains a mock_response. Counts: 220 identities; 191 deleted,
29 retained.

Also per review: the census base is d759da1 (main's resolver after #12116;
the row set is identical to 834148a). The EFFECTS-1 row names the range tip
rather than the #11993 landing, and the header calls the lists retained
exceptions rather than arrivals.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant