Skip to content

runner_microvm_lifecycle witness constructs HelperSurfaceReading / ConvergeGeneration (latent main type error) - #12120

Merged
gunbai-bot[bot] merged 1 commit into
mainfrom
session/gentle-eagle-814
Sep 23, 2026
Merged

gunbai-bot[bot] merged 1 commit into
mainfrom
session/gentle-eagle-814

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

What

dag/test/claim/runner/runner_microvm_lifecycle_witness_test.dag fails to typecheck on main. #12002 (ff2110b) changed gunbc.runner_microvm_network HelperStanding's four surface fields to HelperSurfaceReading and made the converge generation ConvergeGeneration, a branded NonEmptyStr. This witness still built them from Int literals. This PR changes the witness to build the real types through their declared constructors. No type is loosened.

  • converged_generation: Int = 7 → ConvergeGeneration = "run-7" as ConvergeGeneration. This is the same spelling runner_microvm_network_witness_test uses.
  • The four helper surfaces: 0 → HelperSurfaceCounted { count: 0 }. In the old code, 0 meant "read, and found zero". HelperSurfaceUnread would have meant "not read", and helper_surface_is_empty answers false for it. So Counted { 0 } is the arm that keeps helpers_excluded true, and the receipt still admits the subject.
  • One annotation said "literal 0 … this witness's is 7". It now describes the generation as an identity instead of a number. What the claim asserts is unchanged.

Evidence

claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/runner/runner_microvm_lifecycle_witness_test.dag --functions <all 30 test fns> --claim-run --wet gave 30 PASS, 0 FAIL, with the file typechecking. This includes the_host_grain_readings_carry_the_receipts_generation_not_a_literal and a_slot_network_readback_for_another_slot_cannot_settle_this_attempt.

This ran locally with a same-day arm64 claim_batch build. It could not run on BuildBuddy because the executor exposes no cgroup memory limit and its cgroup tree is not writable, so HostBudgetUnreadable / MemoryCgroupBindRefused refuse there.

Why main's floor never compiled this file

I read #12002's own floor job (run 35668300140, job 106559215589):

The planned subject is the touched modules plus what they import (downward). It never includes modules that import a changed module (reverse dependents). runner_microvm_lifecycle_witness_test imports gunbc.runner_microvm_network directly. It was not touched and it is not in the required gate prefixes, so it was outside the subject and the type change went green. The file only compiles in a floor run when a PR's change set pulls it in; #12077 does, and that is where the error appeared.

Follow-up (not fixed here): when a declaration's type changes, the floor plan does not re-plan the witnesses that import it. The planner already has arm-set-changed-consumers (SeedArmSetChangedMatchConsumer), which covers coproduct arm-set changes only. A field-type change on a product (HelperStanding, ConvergedSlotNetwork) or a newly branded alias gets no consumer seeding. So a type change can break every importer outside the gate prefixes silently, the §3 "enumerate the consumers by name" hazard, in a place the floor could derive mechanically.

🤖 Generated with Claude Code

…ConvergeGeneration, not Int literals

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE at exact head 12a3021.

The one-file repair preserves the witness's old meaning while constructing the migrated types honestly:

  • ConvergeGeneration is an identity (NonEmptyStr brand), so "run-7" is the correct replacement for numeric generation 7 and matches the existing network witness.
  • HelperSurfaceCounted { count: 0 } means the surface was read and contained zero helpers; HelperSurfaceUnread would change the claim because unread is deliberately not empty.
  • No production type is loosened and no refusal is bypassed.

The reported 30/30 local claim_batch --wet receipt is appropriate for this latent witness repair. Land after the required exact-head CI checks finish green.

The floor-planning discovery warrants a separate recurring_failure_mode row, but should not be added to this repair. The class is broader than this witness: a declaration-signature/type change can leave untouched reverse consumers outside the prepared subject, allowing main to carry a non-typechecking importer until an unrelated later change happens to seed it. The restoration trigger should be a mechanically derived changed-declaration-signature → direct-consumer seed relation, analogous to but broader than SeedArmSetChangedMatchConsumer, with a RED proving a product-field/type-alias change plans an untouched importer.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit 5bce6dd Sep 23, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/gentle-eagle-814 branch September 23, 2026 07:23
@briansrls
briansrls restored the session/gentle-eagle-814 branch September 23, 2026 07:27
gunbai-bot Bot pushed a commit that referenced this pull request Sep 23, 2026
…ess fix); fleet-converge.yml takes main's side and is regenerated by generated_artifact_gate main_wet

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant