Repository navigation
runner_microvm_lifecycle witness constructs HelperSurfaceReading / ConvergeGeneration (latent main type error) - #12120
Conversation
…ConvergeGeneration, not Int literals Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head 12a3021.
The one-file repair preserves the witness's old meaning while constructing the migrated types honestly:
ConvergeGenerationis an identity (NonEmptyStrbrand), so"run-7"is the correct replacement for numeric generation 7 and matches the existing network witness.HelperSurfaceCounted { count: 0 }means the surface was read and contained zero helpers;HelperSurfaceUnreadwould change the claim because unread is deliberately not empty.- No production type is loosened and no refusal is bypassed.
The reported 30/30 local claim_batch --wet receipt is appropriate for this latent witness repair. Land after the required exact-head CI checks finish green.
The floor-planning discovery warrants a separate recurring_failure_mode row, but should not be added to this repair. The class is broader than this witness: a declaration-signature/type change can leave untouched reverse consumers outside the prepared subject, allowing main to carry a non-typechecking importer until an unrelated later change happens to seed it. The restoration trigger should be a mechanically derived changed-declaration-signature → direct-consumer seed relation, analogous to but broader than SeedArmSetChangedMatchConsumer, with a RED proving a product-field/type-alias change plans an untouched importer.
…ess fix); fleet-converge.yml takes main's side and is regenerated by generated_artifact_gate main_wet Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
What
dag/test/claim/runner/runner_microvm_lifecycle_witness_test.dagfails to typecheck on main. #12002 (ff2110b) changedgunbc.runner_microvm_networkHelperStanding's four surface fields toHelperSurfaceReadingand made the converge generationConvergeGeneration, a brandedNonEmptyStr. This witness still built them fromIntliterals. This PR changes the witness to build the real types through their declared constructors. No type is loosened.converged_generation: Int = 7→ConvergeGeneration = "run-7" as ConvergeGeneration. This is the same spellingrunner_microvm_network_witness_testuses.0→HelperSurfaceCounted { count: 0 }. In the old code,0meant "read, and found zero".HelperSurfaceUnreadwould have meant "not read", andhelper_surface_is_emptyanswersfalsefor it. SoCounted { 0 }is the arm that keepshelpers_excludedtrue, and the receipt still admits the subject.0… this witness's is 7". It now describes the generation as an identity instead of a number. What the claim asserts is unchanged.Evidence
claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/runner/runner_microvm_lifecycle_witness_test.dag --functions <all 30 test fns> --claim-run --wetgave 30 PASS, 0 FAIL, with the file typechecking. This includesthe_host_grain_readings_carry_the_receipts_generation_not_a_literalanda_slot_network_readback_for_another_slot_cannot_settle_this_attempt.This ran locally with a same-day arm64
claim_batchbuild. It could not run on BuildBuddy because the executor exposes no cgroup memory limit and its cgroup tree is not writable, soHostBudgetUnreadable/MemoryCgroupBindRefusedrefuse there.Why main's floor never compiled this file
I read #12002's own
floorjob (run 35668300140, job 106559215589):phase=touched-entry-compile-subject seeds=11. The seeds are exactly the files The microVM network's apply half gets an administrator, and the root grant the job user already holds gets rostered #12002 touched:gunbc.runner_microvm_network,_apply,_converge, the apply witness, and so on.gate-closure … closure=2044 … outside_closure=4476 corpus=6520.The planned subject is the touched modules plus what they import (downward). It never includes modules that import a changed module (reverse dependents).
runner_microvm_lifecycle_witness_testimportsgunbc.runner_microvm_networkdirectly. It was not touched and it is not in the required gate prefixes, so it was outside the subject and the type change went green. The file only compiles in a floor run when a PR's change set pulls it in; #12077 does, and that is where the error appeared.Follow-up (not fixed here): when a declaration's type changes, the floor plan does not re-plan the witnesses that import it. The planner already has
arm-set-changed-consumers(SeedArmSetChangedMatchConsumer), which covers coproduct arm-set changes only. A field-type change on a product (HelperStanding,ConvergedSlotNetwork) or a newly branded alias gets no consumer seeding. So a type change can break every importer outside the gate prefixes silently, the §3 "enumerate the consumers by name" hazard, in a place the floor could derive mechanically.🤖 Generated with Claude Code