Repository navigation
Primitive-egress wind-down (split A): OpenBMC Optional repairs, roadmap authority, main repairs, EFFECTS-1 cut (c) - #11993
Conversation
… in .dag Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ise the fold accumulation Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…to.mac off the RustCrypto primitives Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ranscription The bitwise claim was false and the fold was correct. 0x0FF00FF0 was written as 267391984, which is 0x0FF013F0, while the expected and/or/xor beside it were computed from the pattern intended. .dag has no hex literal, so the conversion is done by hand and read by nobody; a comment stating the intent cannot catch it because no machine reads one. The transcription is now claimed against the octet packing, which has its own pinned vectors, so a future mistype reds a claim that names the constant rather than one that blames the fold. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…; padding witness matches on get Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…gunbc into session/royal-stag-544
…consumers The previous commit's edits to these three files never reached disk; the floor named them again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…itness from main Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The initial hash values and round constants are facts of FIPS 180-4, not of a message; sha256_octets re-derived all 72 words on every digest (DESIGN §2, §6 bare minimum cost). They are now data rows. Measured with claim_batch eval_steps, prediction recorded beforehand: the_published_abc_digest_holds 1063259 -> 1063261; mac_sign_produces_the_published_rfc4231_case1_tag 4123450 -> 4123448. The predicted ~-70k per HMAC did not appear: the interpreter's pure-call memo was already collapsing the repeated decode, so the cut removes the work from the source and from emitted code, not from the interpreter's step count. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…frontier as rows Review 68053 (REQUEST_CHANGES), both findings. (1) word_modulus walked int_pow_bounded on every operation to learn one of four numbers, so every op paid a linear recursion with a checked multiply per step just to read a constant off a closed coproduct. It now answers from the closed set, and word_modulus_agrees_with_the_power_authority_holds runs the table against std.induction int_pow_bounded for every member including Width64, where both must answer with nothing -- the value is derived and checked, not transcribed and trusted. word_shift_left also computed two powers where the second is the modulus divided by the first. (2) The operations landing ahead of their consumers said so in a // block, and DESIGN 4c rules an annotation is not evidence a machine claim holds. They now carry std.roster_frontier rows: DeclarationAppears bound to the exact symbols on gunbc#11647 where the consumer exists to cite, unbound with a stated description where it does not, because a forward citation to a name nobody has written can never resolve. word_zero and word_equal had no consumer anywhere and were deleted rather than described; word_rotate_left needs no row because word_rotate_right consumes it here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ited instance Verifying review 68053's first finding against the code surfaced two more instances of the same defect that the finding did not name: word_wrapping_multiply walked int_pow_bounded per call for its split point, and octet_radix did the same for a number this module already answers. Fixing only the cited site would be repairing the symptom rather than the boundary. word_half_radix is derived once over the closed set and checked against the power authority, as the modulus is; it refuses Width64 although 2^32 IS representable, because a split point for a word with no residue would be answering about a subject that does not exist, and that deliberate disagreement is claimed rather than left looking like an oversight. octet_radix now READS the Width8 modulus rather than deriving a second constant, so nothing new was introduced that could go stale. The three surviving int_pow_bounded call sites all take a genuine variable. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…l signature Review 68073. std.dissolution bound_dissolution takes ref: DeclarationRef and does the DeclarationAppears wrapping itself; the four bound rows passed a DissolutionTrigger under a keyword the signature does not declare. I wrote the call from the TYPE it constructs rather than from the helper's own signature, which is how a call can look right beside the type declaration and bind against nothing. The floor refuses this, so the frontier claim could not have been green -- neither of the two heads carrying it has a CI verdict yet, so this was caught by review rather than by a run. DeclarationAppears, DeclarationRef and DissolutionCondition were imported only for that mis-shaped call and are dropped. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s its expiry Review 68088. The roster asserted in prose that gunbc.dissolution_census reads it, while the census folds census_closure_frontier_row_groups, which it was not a member of. So every row's expiry was computed by nothing: when extdeps.crypto.sha2 sha256_add_all lands, a row outside the census is never reported fired-still-present and its trigger cannot fire. That is the inert-lens tier, and it is the same DESIGN 4c violation the roster exists to correct, committed in the sentence claiming to correct it -- declaring rows in a typed carrier is half of the discharge and being folded is the other half. Enrolled in gunbc.census_closure_frontier and renamed to the roster's _frontier_rows convention. The two existing claims assert the declarations exist, which is not enrolment, so a third joins the rows against the census closure itself by subject key; dropping the group entry reds it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68118. word_from_octets was the one exported operation that did arithmetic before guarding on its own width: it guarded on octet_radix, which asks about Width8 and always answers, so a Width64 call passed the count and per-octet checks and then accumulated eight octets to as much as 2^64 - 1 in the Int the seed realizes as i64, with word_of_int refusing only afterwards. The refusal was inspecting a number the realization had already wrapped or trapped on -- the post-check this file's own word_wrapping_multiply annotation forbids, and the thing that made the module's Width64 sentence false for one entry. Every other exported operation was checked and guards on word_modulus first. A Width64 call with the wrong octet count now reports WordWidthUnrealizable rather than OctetCountMismatch, which is the right order: a width with no residue the carrier can hold is the more fundamental fact. The arm was unwitnessed, which is why it stood -- nothing reds on a path no claim runs. Three claims now pin it, the from_octets one supplied the exact eight-octet input that overflowed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t from this tree The required declarations phase refused four CITED-MODULE-ABSENT: std.machine_word cites extdeps.crypto.sha2 sha256_add_all / sha256_sigma / sha256_xor3 / sha256_ch, and no module declares extdeps.crypto.sha2 here. It exists on gunbc#11647 and nowhere else. A DeclarationRef is a CITATION and the gate resolves it against the tree it runs in, not against any branch. I had written the rule correctly on the issue -- a forward reference to a name nobody has written can never resolve -- applied it to three rows, and then broke it for four because I had READ those symbols on CRYPTO-0's branch, which is what made citing them feel safe. Seeing a symbol somewhere is not this tree being able to check it. DeclarationAppears remains right for a forward reference into a module that already exists; it is the absent MODULE that cannot be cited. The four consuming symbols are now named in prose in each description, where they point a reader without asserting a reference this tree must honour. Floor was already clean on b290752: verdict=FloorClean, claims_failed=0, all 43 newly enrolled claims passed. This was the parse phase alone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t, order width before amount Three defects, each with a counterexample on a40faa2. (1) Word is an ordinary record and .dag has no module-private construction, so word_of_int being the 'sanctioned entry' was unfalsifiable -- nothing refused the other route. word_shift_right(Word{Width8,256},1) answered WordReady 128, and no arm fired because the OUTPUT was in range: the operations validated their results and trusted their premises. Every exported boundary now qualifies its Word arguments against their own declared width before any arithmetic reads them, via one shared seam, and word_from_octets qualifies every member -- it checked member width and trusted member value, so [1, 256] packed to 512 at Width16. This is mitigation and says so; sole construction remains the trigger that DELETES these checks rather than keeping them. (2) int_to_octets read every absent capacity as 'fits'. int_pow_bounded answers Absent both when the power exceeds the Int bound, where every representable value genuinely is below it, and when the exponent is NEGATIVE, which is not about capacity at all -- so count = -1 returned OctetsReady [], a successful empty rendering of a nonsense request. The neighbouring annotation had already named this exact conflation and the code committed its other half. The count is decided on its own terms before the capacity is asked. (3) word_rotate_right asked amount before width, alone among the four shift and rotate arms, so a Width64 rotate by 64 named the amount when the width is what cannot exist. Two operations disagreeing about which refusal one malformed call produces is a fork in the refusal vocabulary. Controls for all three, each red against the pre-fix code, including one per exported family so a partially applied premise check cannot pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # dag/test/claim/approval_device_redemption_witness_test.dag
…octet seam main's #11660 added std.encoding utf8_decode_octets, which reads each member through base64_octet_int -- the 'b + 0' identity whose entire content was a width claim it never checked, and which this branch deleted. The two changes are correct separately and refuse together: a SEMANTIC conflict, with nothing overlapping textually, so the merge is clean and the resolve is not. Fixed here rather than in #11647 because this branch removed the helper and lands first. The replacement is the seam base64's own octets already use: base64_octet_word admits through word_of_int at Width8, and Utf8Refused is the honest destination, which is the state this fold already uses for every other malformed input -- no new refusal vocabulary for a case the model had a word for. The discriminator is a NEGATIVE member, not an oversized one: 256 refused on both paths because utf8_step rejected it anyway, but -1 satisfied and was decoded as an ASCII scalar of -1. Three controls, one of them that exact input. gunbc.plans.blackjack_onboarding taught base64_octet_int in a code sample and in prose; deleting the symbol is what made that stale, so it is repointed here rather than left for its owner to discover. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…action that lands their consumer std.machine_word machine_word_consumer_frontier_rows named word_wrapping_add, word_rotate_right, word_xor and word_not as awaiting extdeps.crypto.sha2 (sha256_add_all, sha256_sigma, sha256_xor3, sha256_ch). That consumer lands here, so the rows are deleted rather than rebound: a DeclarationAppears trigger written in the same commit as its declaration fires on arrival and describes nothing. Consumption is evidenced by execution in sha256_fips180_witness_test. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…_int_value
Two boundaries the premise seam missed, which is the partial-coverage state my
own commit message named and then left one function short of complete.
(A) octet_int_values mapped o.value over its members with no qualification and no
refusal arm, so [Word{Width8,256}] projected to [256] -- and std.encoding consumed
that projection on the base64 decode production route. A projection is not exempt
from the premise rule: reading a field is where an uninhabitable word stops being
a record and becomes a number a consumer trusts. It now qualifies through the
same octets_first_unqualified fold word_from_octets uses, so width and value come
from one authority rather than two agreeing by accident, and returns a typed
result because a projection that can refuse must be able to say so. Threaded at
the base64 caller, which already had an Optional channel.
(B) word_int_value was unqualified AND had no consumer, witness or frontier row
anywhere. Deleted, the same remedy word_zero and word_equal got: a declaration
with no consumer at all is removed, not described. A caller with a matched
qualified word reads its field directly.
Three controls: an out-of-range member, a non-octet member, and a qualified
positive.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lper repeats Ruled repair shape. .dag has NO module-private, so every top-level helper is a callable boundary and there is no wall to put one behind. Qualifying each public operation and leaving the helpers taking raw Word left four raw entrances, and one of them was the defect the public wrapper exists to prevent: word_from_octets_realizable was callable directly with Width64 and would reconstruct up to 2^64 - 1 in the i64 before word_of_int refused. I had split that body out claiming the guard could not be bypassed. A name is not a proof. Re-validating inside every helper is validation multiplied by helper count, and it fails when helper N+1 forgets -- which is exactly how the projection survived the previous pass. So the proof moved into the type. QualifiedWord is produced only by word_qualified / word_pair_qualified; RealizableWidth only by word_realizable_width, the one function that refuses Width64. Helpers below the public boundary take those carriers, so reaching them unqualified does not typecheck. Public ops take Word, qualify once, pass carriers down. octet_int_values takes List<QualifiedWord> and LOSES its refusal arm: with every member arriving with its proof attached there is nothing left to refuse, so the typed result added last round is gone again -- the carrier subsumed it. word_int_value stays deleted. OctetsReady now carries List<QualifiedWord>, which is an interface change for consumers of word_to_octets; CRYPTO-0 told. Honest about the rung: a record with public fields is still constructible, so this is a sealed wrapper, not a private constructor. It changes the failure mode from "a helper forgot" to "someone forged the proof". Rung unchanged at mitigatable; sole construction remains the next-rung trigger. The wall is unwritable in the accepted corpus by construction, so the controls are fixture sources compiled through the real acceptance path, in their own module -- machine_word_witness_test is stamped SubstrateInputsOnly truthfully and compile_dag_diagnostic_census walks the checkout, so the claims could not live there without making that stamp a lie. Three REDs, one per former raw entrance, plus a green control that is load-bearing because three REDs alone are satisfied by a compiler that stopped judging argument types. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…GN §4c) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 68365, and the build lane had already caught its consequence: the generated-artifact gate reported dag/test/fixture/approval_device_redemption/ vectors.json DRIFTED, which is this defect rendered into bytes. path_segment joined base64_encode(...) directly into the segment. This PR changed that return to String?, and this call site arrived on main from gunbc#11660 while this PR was in review, so the two are correct separately and wrong together -- nothing overlaps textually, the merge was clean, and an Optional was being joined into a route identity. Every other caller in the tree was migrated; this one did not exist when I migrated them. The arm is unreachable here: the octets are the UTF-8 encoding of a String, so every member is a byte by construction. The declared contract is TOTALITY -- the annotation above the function says the segment is total, injective and never refused -- so threading an Optional out would be a weaker contract at a route-identity boundary rather than more honesty, and would ripple into decode_path_segment. std.bytes divergent seam is the declared idiom for an arm that cannot be reached; same treatment and same reason as encode_sm_access_version_payload_wire earlier in this PR. The vectors drift is expected to clear without regeneration: the committed file was generated when path_segment was correct, and this restores that. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
…ced a regen CI on 8d81d86 was structural, not infra: the carrier refactor changed word_to_octets to answer List<QualifiedWord> while word_from_octets takes List<Word>, and octet_packing_round_trips_holds fed one into the other -- "value does not inhabit its declared type at the generic type argument: declared Product(Word), produced Product(std.machine_word.QualifiedWord)". That round trip is an ordinary consumer pattern, not a witness artefact: SHA-2 block packing is exactly to_octets into from_octets. So the unwrap is exported as qualified_words_to_words rather than open-coded at the call site. It discards a proof, which is safe in this direction only -- word_from_octets re-qualifies every member, so the cost is paying the check twice, never skipping it. The asymmetry is deliberate and stays: a caller assembling octets by hand has raw Words, and making the entry demand carriers would push the qualification back onto callers. Separately, the plans-doc edit is REVERTED. It repointed prose that taught base64_octet_int, which this PR deletes, and doing so drifted the generated docs/plans/blackjack-onboarding.md. A remote regen of the generated-artifact gate produced no change to that projection, so I cannot verify the repair, and I will not carry an unverified edit to a generated artifact to close a drift I created. The file is now byte-identical to main and the drift clears. The staleness is real and is reported on the PR rather than silently dropped -- and the right replacement is a judgment for that doc owner, since the idiomatic form under the new model is not a one-for-one symbol swap. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…down-split-a # Conflicts: # dag/gunbc/instruments/github_app_acquire.dag # docs/design-rung-drops.md
…ses rows Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…s/temporary rung, reason, population and return trigger on gunbc.rung_drop, rostered Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…d the END marker; the claim binds the console device now), so the schedule withdrawal and its rung drop are retracted Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
extdeps.auth.jws: take main's side whole. Both sides removed the raw List<UInt8> reaching base64_encode; main's cut does it at the stronger rung -- the formal becomes QualifiedOctets and the octet range is observed once at the std.bytes boundary, with JwsEncodeOutcome and JwsSerializationOutcome carrying the refusal -- while this branch's cut folded base64_octets here with an unreachable-seam arm, which is exactly the reasoning main's annotation retracts. This branch touched no jws consumer, so nothing of ours is lost with it. docs/design-rung-drops.md: generated projection, concurrent divergence. Base side taken verbatim per the driver's declared repair route; set difference over row identities (failure-mode slugs and rung-drop headings) against origin/main is empty, so no base row went dark. Not regenerated locally -- heal derives it from the merged authorities. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…hree causes Review 70194 (non-blocking): openbmc_stepwise_scalars answered a bare Absent for both a row count other than five and a row missing at an index the count admits, and the caller then refused with one sentence that also covered negative duty -- three causes with different repairs behind one string. The fold now answers OpenBmcStepwiseScalarsResult, naming the cause and carrying the observed count or the absent index. The caller splits the composite guard into its three checks, each with its own reason. No arm widens: every arm still refuses. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review 70208 (cosmetic, non-blocking): deleting a `uses` clause left a
line of trailing spaces between the signature and its `{`. 27 lines
across four files. The remaining `) -> T` / `{` pair is the shape the
corpus already carries wherever a signature wraps.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The single failing check is not from this diff.
Evidence that it is the trunk and not this branch: the identical annotation is on the merge-queue runs of two unrelated PRs, #12059 (run 35775641816) and #12060 (run 35775942248), whose only commonality with this branch is main; branch runs before that landing were green. The repair is already in flight as #12070, which is exactly this class ( Both review nits are fixed: review 70194 (typed stepwise-scalar refusal cause) in c0d0eee, review 70208 (whitespace residue from the deleted — sent from fierce-seal-607 |
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md interpreter_purity_gate_reads_authored_uses_only Heal-Candidate-Run: 35780463577
…carry the five ENCODING defects as obligations EFFECTS-1 now names #11993 as the landing of cut (c) and leaves only E2 and the restatement refusal open. CRYPTO-0 and ENCODING-0 cite the immutable quarry head 8fc4448 (tag quarry/11895) instead of a mutable branch, and ENCODING-0 no longer describes the parser landing as landed: it records the five review defects in the reconciled tree, each with its refusal control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Correction: Also in 789e3bf: roadmap rows now name #11993 as the split-A landing, cite the #11895 quarry head 🤖 Generated with Claude Code |
Ledger-Repair-Judged: docs/design-rung-drops.md Heal-Candidate-Run: 35789591558
briansrls
left a comment
There was a problem hiding this comment.
HOLD at 885ad19c2a97d9cf2adb7f9cae1b79506e5f0aa4; the prior conditional source approval of the substantive Split-A tree still stands.
The shared E0573 blocker is now repaired on main by merged #12089, not by #12070 or the redundant first commit of #12091. Before this lands:
-
Update onto the actual final main and rerun cut (c)'s semantic census at that frozen base.
demand_restatement_follow_up_commit_rangestill says5ff323b6d29..87c6658641e, anddemand_restatement_follow_up_modulesstill carries that historical population while the surrounding authority says it was re-derived at the landing head. Enumerate every authoredusesrow at the final base, resolve each ordinary function, apply the sameItemInfo.service_namescriterion, delete the measured restatements, and carry only exact unresolved/out-of-range rows with their triggers. Then update both symbols. -
Remove the duplicate import of
fabric_purpose_handover_registration_unobserved_stallingunbc.guarantee_stall.roster; keep exactly one import and oneall_guarantee_stallsmember. -
Sharpen ENCODING defect (4)'s durable acceptance control to both DER directions. The original defect was that
der_expectignoredDerElement.constructed: a primitive encoding of a constructed tag (the concrete outer-CertificateSEQUENCEmutation0x30 -> 0x10) was admitted, and constructed encodings of primitive tags were admitted. The roadmap currently names only “a constructed encoding of a primitive tag refuses.” Require both: primitive SEQUENCE/SET/context-constructed encodings refuse, and constructed BOOLEAN/INTEGER/BIT STRING/OCTET STRING/OID encodings refuse, with discriminating controls.
After the color-attribution repair from #12091 is rewritten onto current main and lands, merge that final base here, regenerate all projections, and return exact-head compiler/clippy/emit-build/floor green. Then this is approvable; close #11895 unmerged only after #11993 lands, as planned.
Main's EFFECTS-1 cut (#11993) deleted the uses-net clauses in five files this branch also edits. Resolved to this branch's content with the same clauses removed, and the same cut applied to the new mtcollins1_boot_federation entry. fleet-converge.yml regenerated from the merged authority. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ses onto a hermetic route with no ReadInterfaceFile arm Floor on 3a746c4 and 81696b3: every executed claim passed, and route_gap_unenrolled=10. Deleting the uses rows in test.manual.runner_microvm_lifecycle_wet_receipt made its wet tests changed witnesses. The floor plans those onto the hermetic route, and extdeps.linux.cgroup_v2 ReadInterfaceFile declares no mock_response, so all ten stopped before a verdict. The floor says enrolling them in v2.workflow.floor_route_gap records debt, not acceptance. So the module returns to main's bytes. Its 17 identities are measured deletable but retained under a new trigger, EditedWitnessHasNoHermeticRoute: ReadInterfaceFile gains a mock_response. Counts: 220 identities; 191 deleted, 29 retained. Also per review: the census base is d759da1 (main's resolver after #12116; the row set is identical to 834148a). The EFFECTS-1 row names the range tip rather than the #11993 landing, and the header calls the lists retained exceptions rather than arrivals. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Operator ruling 2026-09-21 (option A on the cost-budget escalation): the wind-down consolidation #11895 is split. This PR is #11895's reconciled tree with CRYPTO-0 and ENCODING-0 restored to main's versions; those two re-draft from #11895's history once NUMERIC-BIT's kernel arms bring interpreted SHA-256 and the whole-object App Attest parses inside the floor's new-witness cost budget (their 22 witnesses ran at 0.8–4 M eval steps against the 100 ms-equivalent; every witness here is within it).
The fleet-lane seal is main's now. #11829 landed a different construction of the same fix (the receipt kept, its D0-ADJUDICATE consumer bound); one authority for one fix (§3), so the generation-refusal seal this PR carried from #11836 is withdrawn — predicate, witness and failure-mode row deleted. The honest-floor evidence below was gathered under that seal before it was withdrawn and is the same verdict main's seal now produces.
Lands here
extdeps.bmc.openbmc_fan_control: nineOptional.first()sites matched under #11720's wall;OpenBmcStepwiseScalarscarrier.primitive-egressrows + ten edges (the CRYPTO-0/ENCODING-0 rows name the cost budget as their trigger and #11895 as their reconciled tree); owner added to the page focus.usesrows deleted where derived service demand is nonempty, the same criterion applied to every row main added since; ten retained rows with per-row triggers; the interpreter purity gate's declared rung drop; follow-up roster re-derived at the landing head.GuaranteeStall#11625 declared but never rostered;mosquitto_options_bindingnaming whichFilesystemit reads;openbmc_*namingstd.string_typeforString;jws.dag's raw-List base64 call admitted through the sealed mint;fabric_storage_wirewitness body annotation hoisted; (the census-image wet claim that was red on every main queue run since #11731 is repaired at its root by main's #12024, which this PR takes.)Projections (
ROADMAP.md,docs/design-rung-drops.md,docs/plans/demand-engine-program.md) regenerated on this tree viagenerated_artifact_gate main_wet_one.Evidence: floor at 03d4f26 and ac43f1a —
planned=415 executed=415 passed=402 known_red_held=8 claims_failed=0 interrupted=0 completed_over_cost_requirement=0,verdict=FloorClean,phases_failed=0.🤖 Generated with Claude Code