Skip to content

infer: refuse a Present arm over an unresolved scrutinee (silent wrong answer from #12386) - #12398

Merged
briansrls merged 8 commits into
mainfrom
session/quiet-eagle-13
Sep 28, 2026
Merged

briansrls merged 8 commits into
mainfrom
session/quiet-eagle-13

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

What

A silent wrong answer in the v1 interpreter (DESIGN §5), found by valiant-bat-424 on #12386. observe_numa reported a malformed numactl CPU record as an ESTABLISHED topology. This PR refuses the shape at the checker with a located diagnostic, v1.compiler.infer PresentArmScrutineeTypeUnresolved.

Minimal repro (no map lambda needed; it reproduces on current main)

type Attempt<T, E> = Ok { observed: T } | No { cause: E }
let t0 = [No { cause: Bad { detail: "x" } }]
let m0 = flat_map(t0, a => match a { No { cause: c } => [c]  _ => [] })
match first(m0) { Present { value: c } => "P"  _ => "A" }   // "A", though count(m0) == 1

It needs a generic variant built with no expected type, and a payload that is itself a variant. That is why the Nat/String two-liner did not reproduce: the interpreter peels a raw non-variant payload without reading the type.

Chain (§6b, traced with temporary instrumentation)

  1. Earliest unjustified link. v1.compiler.infer types the record literal of a generic variant with no expected type as the uninstantiated declaration. Its fields are still typed T / E, and E stays free even though the field value fixes it.
  2. The lambda parameter over that element type collapses to the bare T.
  3. [c] is typed List<T>, and first(..) becomes a CompilerError "unresolved type" node. No diagnostic.
  4. annotate_pattern_parent_enums sees PatternLookupBlocked and stamps parent_enum: none. Silent.
  5. v1_compiler.interpreter match_pattern peels a raw present payload for Present only when parent_enum == Optional. A variant payload misses the arm, so _ wins.

Hoisting the two matches into typed fns (#12386's workaround) worked only because the declared types supplied the expected type at link 1.

The repair and its rung

  • The refusal lands at link 4, where the checker currently proceeds without the type it needs.
  • Only direct Present arms over a PatternLookupBlocked scrutinee are refused. The reviewed distinction is Present versus Absent: an Absent arm matches Null and Optional.Absent without the parent stamp, so it stays admitted. Nested field patterns were not audited, and nothing is claimed about other variant patterns (match_pattern also special-cases Holds on parent_enum == Witness).
  • The construction fix at link 1 is rostered as the next-rung trigger in the new row gunbc.recurring_failure_mode generic_variant_without_expected_type_leaves_a_present_arm_undecided. That fix instantiates type parameters from field values or the expected type, unifies arm types, and refuses a type argument nothing determines.
  • I did not build that fix here: it is type-inference work in 04_infer with unmeasured corpus reach. The unresolved type still flows silently into consumers that are not Present arms; the row says so.

Rust emitter (built and run):

  • I emitted the red shape with a compiler without the refusal. Emission succeeded and rendered the arm as Some(c): the emitter picks Present by variant name, so the missing parent type never reached it.
  • rustc then refused the crate with E0282, "type annotations needed": it could not infer T of the generic constructor, whose type parameters were never filled in (link 1).
  • So before this PR the interpreter answered silently wrong and the emitted route failed loudly. The refusal now closes both routes at the checker.

Evidence (local runs, CI floor pending)

test.claim.infer_present_arm_unresolved_scrutinee_witness, driven locally through gunbc run:

compiler without the wall with the wall
a_present_arm_over_an_unresolved_scrutinee_refuses false true
the_typed_producer_is_accepted (red−green difference control) false (difference is 0 with no wall) true
the_typed_producer_reads_its_variant_payload_as_present (executes the route) true true

Corpus reach (measured): the CI floor on 621f3c5 resolved 2237 modules with 0 excluded, and the refusal rejected exactly one site.

  • The site: gunbc.spark.native_serving_apply, in spark_native_arm_steps (now spark_native_arm_steps_of). A Present arm over the untyped result of a zip_map with a function-value argument.
  • Its payload is a record, so today's interpreter happened to answer it correctly. Its meaning still rested on a type the checker never established.
  • The rule was not widened. The site gets the remedy the refusal names: its zip_map result is declared as List<SparkNativeHostStep?>.
  • The census covers the required-gate population; the floor on the current head re-counts it, including modules added on main since.

Re-count after merging main (head 976ed45):

  • main brought in a second site, which the CI floor on 5563bad refused (run 36306265263): gunbc.durable_cas_file_store cas_key_of_slot_name. It matched first(skip(parts, ..)), where parts came from the method-form name.split(..) and its type was never established.
  • Same remedy, no widening: let parts: List<String> = name.split(delimiter: ".").
  • A local floor on the merged tree, after the fix, completed strict-preparation: 2236 modules resolved, 0 excluded, 0 sites remaining.

Re-count over every separately compiled entry (head d890e00):

The preparation census missed a third site. The floor compiles src/v2/workflow/floor_terminal_ledger_wire.dag as its own entry (CI floor on 976ed45: TERMINAL-LEDGER REFUSAL cause=WireAuthorityUnresolved). So the reach was re-measured over three populations.

  1. Every separately compiled entry. These are the .dag entry constants in the stage0 hosts: terminal ledger, generated-artifact boundary, regen, target invocation, native lane, and the workflow and emit-build entries generated_artifact_gate, heal_candidate, self-host → src/v2/compiler/00_compile.dag, and v2-native-cli → src/v2/cli/compile_cli.dag. Each was compiled with gunbc compile --entry <e> --target dag:
entry rc Present-arm refusals
dag/extdeps/languages/dag/syntax.dag 0 0
dag/gunbc/ci/ci_layer_roots.dag 0 0
dag/gunbc/class_b_import_closure_overlay.dag 0 0
dag/gunbc/commit_workflow.dag 0 0
dag/gunbc/compile_clean_diagnostic_policy.dag 0 0
dag/gunbc/declared_import_closure_binding.dag 0 0
dag/gunbc/evaluation_store_address_census.dag 0 0
dag/gunbc/explicit_witness_admission.dag 0 0
dag/gunbc/floor_memory_demand.dag 0 0
dag/gunbc/generated_artifact_emit.dag 0 0
dag/gunbc/githooks/githooks_pre_push_plan.dag 0 0
dag/gunbc/instruments/dag_compile_clean_scope.dag 0 0
dag/gunbc/instruments/docs_projection_gate.dag 0 0
dag/gunbc/instruments/generated_artifact_gate.dag 0 0
dag/gunbc/native_claim_program.dag 0 0
dag/gunbc/non_fold_residue.dag 0 0
dag/gunbc/witness/witness_deferral_freeze.dag 0 0
dag/gunbc/regen_affected_set.dag 0 0
dag/gunbc/regen_round_cost.dag 0 0
dag/gunbc/heal_candidate.dag 0 0
dag/gunbc/recurring_failure_mode/roster.dag 0 0
src/v2/cli/compile_cli.dag 0 0
src/v2/compiler/00_compile.dag 0 0
src/v2/lens/affected_set.dag 0 0
src/v2/lens/live_read_classification.dag 0 0
src/v2/lens/machine_shape.dag 0 0
src/v2/lens/module_graph.dag 0 0
src/v2/std/effect_reach.dag 0 0
src/v2/std/live_read.dag 0 0
src/v2/workflow/class_b_import_closure_transport.dag 0 0
src/v2/workflow/emitted_crate_workspace.dag 0 0
src/v2/workflow/floor_terminal_ledger_wire.dag 0 0

Control: the same instrument on the terminal-ledger wire with its fix reverted gives rc=1 and 1 site (printed on 2 lines). The zeros above are therefore readable.

  1. The regen population (the compiler's own src/v1 closure): --required-regen on this build, 161/161 modules, first_generation_equal=true, 0 sites.

  2. Whole-root dag compile (--repository gunbc, measured-demand admitted). It found two more sites, both outside the required gate:

    • dag/test/claim/fabric/data_class_admission_witness_test.dag:233 is a genuine site: a Present arm over the untyped parameter of a function value handed to classified_map. Fixed by moving the match into a typed fn. That module now compiles with rc=0 and 0 refusals.
    • dag/test/probe/bare_string_from_boundary_probe.dag:35 is left as is. Its scrutinee is unresolved because the same file already fails with no field 'email' on type 'Classified' (35:51) and a sole-constructor violation (42:3). The module is refused with or without this PR, and the new diagnostic there is a consequence of that existing error, not a new silent answer.

    Caveat: this whole-root compile reports 1243 indexed modules outside its compile-clean closure as "name census only (not compiled)". It is a strong cross-check, not a complete superset; the per-entry table and the required floor are what cover the populations CI builds.

Total reach: 4 genuine sites, all given declared types, and no widening. They are native_serving_apply, durable_cas_file_store, floor_terminal_ledger_wire and data_class_admission_witness_test. The probe is noted above.

Per-entry compile over the derived roster (head d890e00; no source change)

The roster is derived from four sources, 210 entries in total:

  • every entry: in gunbc.ci.ci_spec: 69 GunbcRunStepTarget and DeployStage rows, giving 49 distinct entries.
  • every .dag path literal in the stage0 host (src/v1/stage0/src) that resolves to a file, excluding test/fixture paths.
  • the data compiler_pipeline_entry modules plus src/v1/compile.dag.
  • the producer entries in gunbc.instrument_targets.

Method. Each entry is compiled individually with gunbc compile --entry <e> --target dag, under the roots its declaring target uses:

  • dag + src/v2, which is also the gunbc run configuration of the ci_spec workflow steps;
  • src/v1 first for compiler modules;
  • the fixture's own directory for fixtures/ entries.

Each compile has a 30-minute timeout, so a timeout (rc=124) is distinguishable from a failure. Compiles killed under memory pressure during 3-way parallel runs (rc 137/143) were re-run serially, and only the serial result is recorded; no timeouts, kills or skips remain. "Sites" counts PresentArmScrutineeTypeUnresolved refusals; each site prints as two lines (cause and located error). The log names refer to per-entry logs kept in the session's scratch storage (/tmp/claude-1000/qe-r/), not in the repo.

Result: 0 Present-arm sites in every entry. Classes: clean: 203; pre-existing failure, not this rule: 4; expected-invalid fixture: 1; non-standalone fragment (owned by src/v1/compile.dag, rc=0): 2.

The pre-existing failures are unrelated to this rule, and the checker ran in each. runner_microvm_slot_start is a live runner entry that does not compile today because of no field 'Journalctl' on type 'systemd' in runner_microvm_lifecycle_realize.dag; it is reported separately.

Per-entry table (210)
entry source rc Present-arm sites class log
dag/examples/weather/weather.dag host/pipeline/instrument 0 0 clean dag_examples_weather_weather.dag.log
dag/extdeps/cloud/cloud.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_cloud.dag.log
dag/extdeps/cloud/gcp/errors.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_gcp_errors.dag.log
dag/extdeps/cloud/gcp/gcp.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_gcp_gcp.dag.log
dag/extdeps/cloud/gcp/iam.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_gcp_iam.dag.log
dag/extdeps/cloud/gcp/secret_manager.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_gcp_secret_manager.dag.log
dag/extdeps/cloud/gcp/sts.dag host/pipeline/instrument 0 0 clean dag_extdeps_cloud_gcp_sts.dag.log
dag/extdeps/git/git.dag host/pipeline/instrument 0 0 clean dag_extdeps_git_git.dag.log
dag/extdeps/github/auth.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_auth.dag.log
dag/extdeps/github/errors.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_errors.dag.log
dag/extdeps/github/gists.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_gists.dag.log
dag/extdeps/github/github.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_github.dag.log
dag/extdeps/github/issues.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_issues.dag.log
dag/extdeps/github/pulls.dag host/pipeline/instrument 0 0 clean dag_extdeps_github_pulls.dag.log
dag/extdeps/languages/dag/syntax.dag host/pipeline/instrument 0 0 clean dag_extdeps_languages_dag_syntax.dag.log
dag/extdeps/languages/json/emit.dag host/pipeline/instrument 0 0 clean dag_extdeps_languages_json_emit.dag.log
dag/extdeps/llm/anthropic_rest.dag host/pipeline/instrument 0 0 clean dag_extdeps_llm_anthropic_rest.dag.log
dag/extdeps/llm/openai_rest.dag host/pipeline/instrument 0 0 clean dag_extdeps_llm_openai_rest.dag.log
dag/extdeps/render/surface.dag host/pipeline/instrument 0 0 clean dag_extdeps_render_surface.dag.log
dag/extdeps/rust/cargo_build.dag host/pipeline/instrument 0 0 clean dag_extdeps_rust_cargo_build.dag.log
dag/extdeps/shell.dag host/pipeline/instrument 0 0 clean dag_extdeps_shell.dag.log
dag/extdeps/systems/nvidia.dag host/pipeline/instrument 0 0 clean dag_extdeps_systems_nvidia.dag.log
dag/gunbc/auth/approval_device_enrolment_code_issue.dag ci_spec workflow 0 0 clean dag_gunbc_auth_approval_device_enrolment_code_issue.dag.log
dag/gunbc/auth/approval_keyring_converge.dag ci_spec workflow 0 0 clean dag_gunbc_auth_approval_keyring_converge.dag.log
dag/gunbc/auth/ci_app_key_rotation.dag ci_spec workflow 0 0 clean dag_gunbc_auth_ci_app_key_rotation.dag.log
dag/gunbc/auth/credentials.dag host/pipeline/instrument 0 0 clean dag_gunbc_auth_credentials.dag.log
dag/gunbc/auth/gcp_iam_converge_run.dag ci_spec workflow 0 0 clean dag_gunbc_auth_gcp_iam_converge_run.dag.log
dag/gunbc/auth/patterns.dag host/pipeline/instrument 1 0 pre-existing failure, not this rule: unresolved type 'GitHubActionsRuntime' dag_gunbc_auth_patterns.dag.log
dag/gunbc/ci/ci_layer_roots.dag host/pipeline/instrument 0 0 clean dag_gunbc_ci_ci_layer_roots.dag.log
dag/gunbc/ci/ci_materialization.dag host/pipeline/instrument 0 0 clean dag_gunbc_ci_ci_materialization.dag.log
dag/gunbc/ci/ci_spec.dag host/pipeline/instrument 0 0 clean dag_gunbc_ci_ci_spec.dag.log
dag/gunbc/class_b_import_closure_overlay.dag host/pipeline/instrument 0 0 clean dag_gunbc_class_b_import_closure_overlay.dag.log
dag/gunbc/cloudflare/r2_bucket_ensure.dag ci_spec workflow 0 0 clean dag_gunbc_cloudflare_r2_bucket_ensure.dag.log
dag/gunbc/cloudflare/r2_permission_group_observe.dag ci_spec workflow 0 0 clean dag_gunbc_cloudflare_r2_permission_group_observe.dag.log
dag/gunbc/cloudflare/r2_token_mint_run.dag ci_spec workflow 0 0 clean dag_gunbc_cloudflare_r2_token_mint_run.dag.log
dag/gunbc/commit_workflow.dag host/pipeline/instrument 0 0 clean dag_gunbc_commit_workflow.dag.log
dag/gunbc/compile_clean_diagnostic_policy.dag host/pipeline/instrument 0 0 clean dag_gunbc_compile_clean_diagnostic_policy.dag.log
dag/gunbc/declared_import_closure_binding.dag host/pipeline/instrument 0 0 clean dag_gunbc_declared_import_closure_binding.dag.log
dag/gunbc/devboot/build.dag host/pipeline/instrument 0 0 clean dag_gunbc_devboot_build.dag.log
dag/gunbc/evaluation_store_address_census.dag host/pipeline/instrument 0 0 clean dag_gunbc_evaluation_store_address_census.dag.log
dag/gunbc/executor_schedule_retention.dag host/pipeline/instrument 0 0 clean dag_gunbc_executor_schedule_retention.dag.log
dag/gunbc/explicit_witness_admission.dag host/pipeline/instrument 0 0 clean dag_gunbc_explicit_witness_admission.dag.log
dag/gunbc/fabric/fabric_writer_identity_observe.dag ci_spec workflow 0 0 clean dag_gunbc_fabric_fabric_writer_identity_observe.dag.log
dag/gunbc/fleet/app_control_plane_inspection.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_app_control_plane_inspection.dag.log
dag/gunbc/fleet/fleet_converge_plan_cli.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_fleet_converge_plan_cli.dag.log
dag/gunbc/fleet/fleet_host_key_enrollment.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_fleet_host_key_enrollment.dag.log
dag/gunbc/fleet/fleet_multi_principal_probe.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_fleet_multi_principal_probe.dag.log
dag/gunbc/fleet/fleet_probe_identity_observe.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_fleet_probe_identity_observe.dag.log
dag/gunbc/fleet/fleet_receipt_collector.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_fleet_receipt_collector.dag.log
dag/gunbc/fleet/host_credential_custody_converge.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_host_credential_custody_converge.dag.log
dag/gunbc/fleet/org_actions_inspection.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_org_actions_inspection.dag.log
dag/gunbc/fleet/organization_runner_roster_read.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_organization_runner_roster_read.dag.log
dag/gunbc/fleet/site_pxe_edge_converge.dag ci_spec workflow 0 0 clean dag_gunbc_fleet_site_pxe_edge_converge.dag.log
dag/gunbc/floor_memory_demand.dag host/pipeline/instrument 0 0 clean dag_gunbc_floor_memory_demand.dag.log
dag/gunbc/generated_artifact_emit.dag host/pipeline/instrument 0 0 clean dag_gunbc_generated_artifact_emit.dag.log
dag/gunbc/githooks/githooks_pre_push_plan.dag host/pipeline/instrument 0 0 clean dag_gunbc_githooks_githooks_pre_push_plan.dag.log
dag/gunbc/heal_candidate.dag ci_spec workflow 0 0 clean dag_gunbc_heal_candidate.dag.log
dag/gunbc/heal_publication.dag ci_spec workflow 0 0 clean dag_gunbc_heal_publication.dag.log
dag/gunbc/host/host_reach_identity_probe.dag ci_spec workflow 0 0 clean dag_gunbc_host_host_reach_identity_probe.dag.log
dag/gunbc/host/host_reset_return_run.dag ci_spec workflow 0 0 clean dag_gunbc_host_host_reset_return_run.dag.log
dag/gunbc/instruments/build_step.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_build_step.dag.log
dag/gunbc/instruments/dag_compile_clean_scope.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_dag_compile_clean_scope.dag.log
dag/gunbc/instruments/dag_compile_clean_transport.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_dag_compile_clean_transport.dag.log
dag/gunbc/instruments/docs_projection_gate.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_docs_projection_gate.dag.log
dag/gunbc/instruments/floor_effect_gate_witness.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_floor_effect_gate_witness.dag.log
dag/gunbc/instruments/generated_artifact_gate.dag ci_spec workflow 0 0 clean dag_gunbc_instruments_generated_artifact_gate.dag.log
dag/gunbc/instruments/host_prelude.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_host_prelude.dag.log
dag/gunbc/instruments/native_app_attest.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_native_app_attest.dag.log
dag/gunbc/instruments/native_crypto_vectors.dag host/pipeline/instrument 0 0 clean dag_gunbc_instruments_native_crypto_vectors.dag.log
dag/gunbc/live_deploy/apply.dag ci_spec workflow 0 0 clean dag_gunbc_live_deploy_apply.dag.log
dag/gunbc/machine_intake/mtcollins1_boot_admission.dag ci_spec workflow 0 0 clean dag_gunbc_machine_intake_mtcollins1_boot_admission.dag.log
dag/gunbc/machine_intake/mtcollins1_boot_run.dag ci_spec workflow 0 0 clean dag_gunbc_machine_intake_mtcollins1_boot_run.dag.log
dag/gunbc/machine_intake/mtcollins1_census_image.dag ci_spec workflow 0 0 clean dag_gunbc_machine_intake_mtcollins1_census_image.dag.log
dag/gunbc/machine_intake/mtcollins1_fan_observe.dag ci_spec workflow 0 0 clean dag_gunbc_machine_intake_mtcollins1_fan_observe.dag.log
dag/gunbc/native_claim_program.dag host/pipeline/instrument 0 0 clean dag_gunbc_native_claim_program.dag.log
dag/gunbc/non_fold_residue.dag host/pipeline/instrument 0 0 clean dag_gunbc_non_fold_residue.dag.log
dag/gunbc/observation_ci_render.dag host/pipeline/instrument 0 0 clean dag_gunbc_observation_ci_render.dag.log
dag/gunbc/observation_seed_render.dag host/pipeline/instrument 0 0 clean dag_gunbc_observation_seed_render.dag.log
dag/gunbc/output_policy.dag host/pipeline/instrument 0 0 clean dag_gunbc_output_policy.dag.log
dag/gunbc/primitive_egress/census_live.dag host/pipeline/instrument 0 0 clean dag_gunbc_primitive_egress_census_live.dag.log
dag/gunbc/recurring_failure_mode/roster.dag host/pipeline/instrument 0 0 clean dag_gunbc_recurring_failure_mode_roster.dag.log
dag/gunbc/regen_affected_set.dag host/pipeline/instrument 0 0 clean dag_gunbc_regen_affected_set.dag.log
dag/gunbc/regen_round_cost.dag host/pipeline/instrument 0 0 clean dag_gunbc_regen_round_cost.dag.log
dag/gunbc/required_ci_phase_roster.dag host/pipeline/instrument 0 0 clean dag_gunbc_required_ci_phase_roster.dag.log
dag/gunbc/required_lane_resolution_census_live.dag host/pipeline/instrument 0 0 clean dag_gunbc_required_lane_resolution_census_live.dag.log
dag/gunbc/roadmap/roadmap_authority.dag host/pipeline/instrument 0 0 clean dag_gunbc_roadmap_roadmap_authority.dag.log
dag/gunbc/roadmap/roadmap_launch_deployment_cli.dag ci_spec workflow 0 0 clean dag_gunbc_roadmap_roadmap_launch_deployment_cli.dag.log
dag/gunbc/runner/runner_group_restriction_ensure_run.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_group_restriction_ensure_run.dag.log
dag/gunbc/runner/runner_guest_image.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_guest_image.dag.log
dag/gunbc/runner/runner_host_file_converge.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_host_file_converge.dag.log
dag/gunbc/runner/runner_microvm_boot_probe.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_microvm_boot_probe.dag.log
dag/gunbc/runner/runner_microvm_host_ready.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_microvm_host_ready.dag.log
dag/gunbc/runner/runner_microvm_network_apply.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_microvm_network_apply.dag.log
dag/gunbc/runner/runner_microvm_network_observe.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_microvm_network_observe.dag.log
dag/gunbc/runner/runner_microvm_slot_start.dag ci_spec workflow 1 0 pre-existing failure, not this rule: no field 'Journalctl' on type 'systemd' dag_gunbc_runner_runner_microvm_slot_start.dag.log
dag/gunbc/runner/runner_password_session_tool_converge.dag ci_spec workflow 0 0 clean dag_gunbc_runner_runner_password_session_tool_converge.dag.log
dag/gunbc/spark/managed_access_apply.dag ci_spec workflow 0 0 clean dag_gunbc_spark_managed_access_apply.dag.log
dag/gunbc/spark/managed_grant_install.dag ci_spec workflow 0 0 clean dag_gunbc_spark_managed_grant_install.dag.log
dag/gunbc/spark/native_serving_apply.dag ci_spec workflow 0 0 clean dag_gunbc_spark_native_serving_apply.dag.log
dag/gunbc/spark/pair_serving_apply.dag ci_spec workflow 0 0 clean dag_gunbc_spark_pair_serving_apply.dag.log
dag/gunbc/spark/pair_serving_d0_door.dag ci_spec workflow 0 0 clean dag_gunbc_spark_pair_serving_d0_door.dag.log
dag/gunbc/spark/v41_checkpoint_materialize.dag ci_spec workflow 0 0 clean dag_gunbc_spark_v41_checkpoint_materialize.dag.log
dag/gunbc/spark/v41_row_store_encode_run.dag ci_spec workflow 0 0 clean dag_gunbc_spark_v41_row_store_encode_run.dag.log
dag/gunbc/spark/v41_row_store_readback_run.dag ci_spec workflow 0 0 clean dag_gunbc_spark_v41_row_store_readback_run.dag.log
dag/gunbc/spark/v41_runtime_image_converge.dag ci_spec workflow 0 0 clean dag_gunbc_spark_v41_runtime_image_converge.dag.log
dag/gunbc/spark/v41_runtime_image_probe.dag ci_spec workflow 0 0 clean dag_gunbc_spark_v41_runtime_image_probe.dag.log
dag/gunbc/srv1_tasks_preapply_observation.dag ci_spec workflow 0 0 clean dag_gunbc_srv1_tasks_preapply_observation.dag.log
dag/gunbc/stage0/stage0_emitted_edge_admission.dag host/pipeline/instrument 0 0 clean dag_gunbc_stage0_stage0_emitted_edge_admission.dag.log
dag/gunbc/test_module_hygiene.dag host/pipeline/instrument 0 0 clean dag_gunbc_test_module_hygiene.dag.log
dag/gunbc/tools/review_codex.dag host/pipeline/instrument 1 0 pre-existing failure, not this rule: undefined variable 'llm' dag_gunbc_tools_review_codex.dag.log
dag/gunbc/witness/witness_deferral_freeze.dag host/pipeline/instrument 0 0 clean dag_gunbc_witness_witness_deferral_freeze.dag.log
dag/gunbc/witness/witness_row_cost.dag host/pipeline/instrument 0 0 clean dag_gunbc_witness_witness_row_cost.dag.log
dag/std/algebra.dag host/pipeline/instrument 0 0 clean dag_std_algebra.dag.log
dag/std/behavioral.dag host/pipeline/instrument 0 0 clean dag_std_behavioral.dag.log
dag/std/decl_ref.dag host/pipeline/instrument 0 0 clean dag_std_decl_ref.dag.log
dag/std/effect_grant.dag host/pipeline/instrument 0 0 clean dag_std_effect_grant.dag.log
dag/std/encoding.dag host/pipeline/instrument 0 0 clean dag_std_encoding.dag.log
dag/std/error_primitives.dag host/pipeline/instrument 0 0 clean dag_std_error_primitives.dag.log
dag/std/evaluation_budget.dag host/pipeline/instrument 0 0 clean dag_std_evaluation_budget.dag.log
dag/std/integer.dag host/pipeline/instrument 0 0 clean dag_std_integer.dag.log
dag/std/languages.dag host/pipeline/instrument 0 0 clean dag_std_languages.dag.log
dag/std/logic.dag host/pipeline/instrument 0 0 clean dag_std_logic.dag.log
dag/std/materialization_provider.dag host/pipeline/instrument 0 0 clean dag_std_materialization_provider.dag.log
dag/std/measure.dag host/pipeline/instrument 0 0 clean dag_std_measure.dag.log
dag/std/nat.dag host/pipeline/instrument 0 0 clean dag_std_nat.dag.log
dag/std/primitives.dag host/pipeline/instrument 0 0 clean dag_std_primitives.dag.log
dag/std/realize_pack.dag host/pipeline/instrument 0 0 clean dag_std_realize_pack.dag.log
dag/std/resources.dag host/pipeline/instrument 0 0 clean dag_std_resources.dag.log
dag/std/stack.dag host/pipeline/instrument 0 0 clean dag_std_stack.dag.log
dag/std/string_type.dag host/pipeline/instrument 0 0 clean dag_std_string_type.dag.log
dag/std/types.dag host/pipeline/instrument 0 0 clean dag_std_types.dag.log
fixtures/atomic_materialization/subject.dag fixture 0 0 clean fixtures_atomic_materialization_subject.dag.log
fixtures/fixture_closure_rustc/append_concat_form_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_append_concat_form_probe.dag.log
fixtures/fixture_closure_rustc/argv_word_list_splice_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_argv_word_list_splice_probe.dag.log
fixtures/fixture_closure_rustc/empty_map_data_turbofish_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_empty_map_data_turbofish_probe.dag.log
fixtures/fixture_closure_rustc/function_value_adapter_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_function_value_adapter_probe.dag.log
fixtures/fixture_closure_rustc/function_value_let_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_function_value_let_probe.dag.log
fixtures/fixture_closure_rustc/green_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_green_probe.dag.log
fixtures/fixture_closure_rustc/nested_refinement_cast_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_nested_refinement_cast_probe.dag.log
fixtures/fixture_closure_rustc/phantom_marker_applied_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_phantom_marker_applied_probe.dag.log
fixtures/fixture_closure_rustc/phantom_marker_non_applied_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_phantom_marker_non_applied_probe.dag.log
fixtures/fixture_closure_rustc/shell_multi_field_projection_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_shell_multi_field_projection_probe.dag.log
fixtures/fixture_closure_rustc/shell_single_field_projection_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_shell_single_field_projection_probe.dag.log
fixtures/fixture_closure_rustc/text_nonliteral_probe.dag fixture 0 0 clean fixtures_fixture_closure_rustc_text_nonliteral_probe.dag.log
fixtures/v2_emission_gate/green/subject.dag fixture 0 0 clean fixtures_v2_emission_gate_green_subject.dag.log
fixtures/v2_emission_gate/red/subject.dag fixture 1 0 expected-invalid fixture fixtures_v2_emission_gate_red_subject.dag.log
src/v1/00_core.dag src/v1 0 0 clean src_v1_00_core.dag.log
src/v1/01_tokenize.dag src/v1 0 0 clean src_v1_01_tokenize.dag.log
src/v1/02_parse.dag src/v1 0 0 clean src_v1_02_parse.dag.log
src/v1/03_resolve.dag src/v1 0 0 clean src_v1_03_resolve.dag.log
src/v1/04_infer.dag src/v1 1 0 non-standalone fragment (owned by src/v1/compile.dag, rc=0) src_v1_04_infer.dag.log
src/v1/05_emit.dag src/v1 1 0 non-standalone fragment (owned by src/v1/compile.dag, rc=0) src_v1_05_emit.dag.log
src/v1/05_emit_rust.dag src/v1 0 0 clean src_v1_05_emit_rust.dag.log
src/v1/artifact.dag src/v1 0 0 clean src_v1_artifact.dag.log
src/v1/compile.dag src/v1 0 0 clean src_v1_compile.dag.log
src/v1/complexity.dag src/v1 0 0 clean src_v1_complexity.dag.log
src/v1/ownership.dag src/v1 0 0 clean src_v1_ownership.dag.log
src/v1/tests/fixtures/non_ascii_perf.dag src/v1 0 0 clean src_v1_tests_fixtures_non_ascii_perf.dag.log
src/v2/cli/compile_cli.dag host/pipeline/instrument 0 0 clean src_v2_cli_compile_cli.dag.log
src/v2/compiler/00_compile.dag host/pipeline/instrument 0 0 clean src_v2_compiler_00_compile.dag.log
src/v2/compiler/01_tokenize.dag host/pipeline/instrument 0 0 clean src_v2_compiler_01_tokenize.dag.log
src/v2/compiler/03_name_resolve.dag host/pipeline/instrument 0 0 clean src_v2_compiler_03_name_resolve.dag.log
src/v2/compiler/03_normalize.dag host/pipeline/instrument 0 0 clean src_v2_compiler_03_normalize.dag.log
src/v2/compiler/04_infer.dag host/pipeline/instrument 0 0 clean src_v2_compiler_04_infer.dag.log
src/v2/compiler/05_emit.dag host/pipeline/instrument 0 0 clean src_v2_compiler_05_emit.dag.log
src/v2/compiler/05_emit_orchestration.dag host/pipeline/instrument 0 0 clean src_v2_compiler_05_emit_orchestration.dag.log
src/v2/compiler/self_host.dag host/pipeline/instrument 0 0 clean src_v2_compiler_self_host.dag.log
src/v2/compiler/self_host/wet_receipt_enrollment.dag host/pipeline/instrument 0 0 clean src_v2_compiler_self_host_wet_receipt_enrollment.dag.log
src/v2/compiler/self_host/witness_entry_eligibility_census.dag host/pipeline/instrument 0 0 clean src_v2_compiler_self_host_witness_entry_eligibility_census.dag.log
src/v2/extdeps/languages/bash.dag host/pipeline/instrument 0 0 clean src_v2_extdeps_languages_bash.dag.log
src/v2/extdeps/languages/bash_orchestration_emit.dag host/pipeline/instrument 0 0 clean src_v2_extdeps_languages_bash_orchestration_emit.dag.log
src/v2/extdeps/languages/rust_test_fixtures.dag host/pipeline/instrument 0 0 clean src_v2_extdeps_languages_rust_test_fixtures.dag.log
src/v2/lens/affected_set.dag host/pipeline/instrument 0 0 clean src_v2_lens_affected_set.dag.log
src/v2/lens/cost.dag host/pipeline/instrument 0 0 clean src_v2_lens_cost.dag.log
src/v2/lens/enforcement/lens_module_gate.dag host/pipeline/instrument 0 0 clean src_v2_lens_enforcement_lens_module_gate.dag.log
src/v2/lens/languages_consumer_census.dag host/pipeline/instrument 1 0 pre-existing failure, not this rule: unresolved type 'ConstructionJustification' src_v2_lens_languages_consumer_census.dag.log
src/v2/lens/live_read_classification.dag host/pipeline/instrument 0 0 clean src_v2_lens_live_read_classification.dag.log
src/v2/lens/machine_shape.dag host/pipeline/instrument 0 0 clean src_v2_lens_machine_shape.dag.log
src/v2/lens/module_graph.dag host/pipeline/instrument 0 0 clean src_v2_lens_module_graph.dag.log
src/v2/std/algebra.dag host/pipeline/instrument 0 0 clean src_v2_std_algebra.dag.log
src/v2/std/effect_reach.dag host/pipeline/instrument 0 0 clean src_v2_std_effect_reach.dag.log
src/v2/std/grounding.dag host/pipeline/instrument 0 0 clean src_v2_std_grounding.dag.log
src/v2/std/integer.dag host/pipeline/instrument 0 0 clean src_v2_std_integer.dag.log
src/v2/std/live_read.dag host/pipeline/instrument 0 0 clean src_v2_std_live_read.dag.log
src/v2/std/logic.dag host/pipeline/instrument 0 0 clean src_v2_std_logic.dag.log
src/v2/std/nat.dag host/pipeline/instrument 0 0 clean src_v2_std_nat.dag.log
src/v2/std/node.dag host/pipeline/instrument 0 0 clean src_v2_std_node.dag.log
src/v2/std/optional.dag host/pipeline/instrument 0 0 clean src_v2_std_optional.dag.log
src/v2/std/text.dag host/pipeline/instrument 0 0 clean src_v2_std_text.dag.log
src/v2/std/witness_execution_routing.dag host/pipeline/instrument 0 0 clean src_v2_std_witness_execution_routing.dag.log
src/v2/workflow/class_b_import_closure_probe.dag host/pipeline/instrument 0 0 clean src_v2_workflow_class_b_import_closure_probe.dag.log
src/v2/workflow/class_b_import_closure_transport.dag host/pipeline/instrument 0 0 clean src_v2_workflow_class_b_import_closure_transport.dag.log
src/v2/workflow/emitted_crate_workspace.dag host/pipeline/instrument 0 0 clean src_v2_workflow_emitted_crate_workspace.dag.log
src/v2/workflow/floor_compile_clean_predicates.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_compile_clean_predicates.dag.log
src/v2/workflow/floor_cost_debt_edit.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_cost_debt_edit.dag.log
src/v2/workflow/floor_diff_observe.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_diff_observe.dag.log
src/v2/workflow/floor_discovery.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_discovery.dag.log
src/v2/workflow/floor_discovery_producer.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_discovery_producer.dag.log
src/v2/workflow/floor_discovery_row.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_discovery_row.dag.log
src/v2/workflow/floor_discovery_source_authority.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_discovery_source_authority.dag.log
src/v2/workflow/floor_naming_hygiene.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_naming_hygiene.dag.log
src/v2/workflow/floor_terminal_ledger_wire.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_terminal_ledger_wire.dag.log
src/v2/workflow/floor_unimported_bare_provider_debt.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_unimported_bare_provider_debt.dag.log
src/v2/workflow/floor_unimported_bare_provider_debt_roster.dag host/pipeline/instrument 0 0 clean src_v2_workflow_floor_unimported_bare_provider_debt_roster.dag.log
src/v2/workflow/orchestration_bash_test.dag host/pipeline/instrument 0 0 clean src_v2_workflow_orchestration_bash_test.dag.log
src/v2/workflow/orchestration_emit_test.dag host/pipeline/instrument 0 0 clean src_v2_workflow_orchestration_emit_test.dag.log
src/v2/workflow/orchestration_retry_emit_test.dag host/pipeline/instrument 0 0 clean src_v2_workflow_orchestration_retry_emit_test.dag.log
src/v2/workflow/orchestration_tier2_emit_test.dag host/pipeline/instrument 0 0 clean src_v2_workflow_orchestration_tier2_emit_test.dag.log
src/v2/workflow/regen_convergence_transaction.dag host/pipeline/instrument 0 0 clean src_v2_workflow_regen_convergence_transaction.dag.log
src/v2/workflow/required_regen.dag host/pipeline/instrument 0 0 clean src_v2_workflow_required_regen.dag.log

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 4 commits September 27, 2026 03:03
…ve (silent wrong answer from #12386)

A generic variant constructed with no expected type is typed as the uninstantiated declaration
(fields still T/E). Downstream, `first` of a list built from it is an "unresolved type" node, the
checker stamps a `Present { value: c }` arm parent_enum none with no diagnostic, and the
interpreter's raw-payload peel -- which requires parent_enum Optional -- misses a variant payload
and takes the next arm. #12386's observe_numa reported a malformed numactl section as an
ESTABLISHED topology this way.

v1.compiler.infer PresentArmScrutineeTypeUnresolved now refuses that arm, located at the match.
The constructor-instantiation gap (the earliest unjustified link) is rostered as the next-rung
trigger in gunbc.recurring_failure_mode
generic_variant_without_expected_type_leaves_a_present_arm_undecided.

Witness: test.claim.infer_present_arm_unresolved_scrutinee_witness. Measured locally: the red
reads false on a compiler without the wall and true with it; the executed route control reads
true on both.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The one corpus site PresentArmScrutineeTypeUnresolved refuses (CI floor, 2237 modules resolved,
0 excluded): a Present arm over the unresolved result of zip_map with a function-value argument.
Its payload is a record, so today's interpreter happened to answer it; its meaning still hung on
a type the checker never established. The remedy the refusal names: declare the producer's type.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/spark/native_serving_apply.dag
#	src/v1/stage0/src/v1_compiler_infer.rs
…0282), replaces the read

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — exact head ac000d435910d47c3a7975050982d328f53cea20, confirmed open, non-draft and mergeable. This approves the explicitly bounded checker refusal, not a claim that generic constructor inference or every annotation-dependent match has been repaired.

The actual new wall is precise: in v1.compiler.infer.infer_expr_expected's ExprMatch path, resolve_pattern_subject must return PatternLookupBlocked; present_arms_over_unresolved_scrutinee then inspects each direct typed arm and emits PresentArmScrutineeTypeUnresolved only when its variant's last segment is Present and its parent_enum is absent. The diagnostic retains the pattern spelling and the enclosing match's SourceSpan. It is concatenated into the ordinary InferResult diagnostics without removing scrutinee, arm, join, empty-arm or exhaustiveness diagnostics. v1.std.core.diagnostic_disposition makes it SeverityError/GateBlocking; span/message handling, compile-clean class specimen and histogram handling, and both stage0 mirrors include it. This is refusal before either executing route, not an interpreter branch-selection patch or an invented Optional parent.

Present versus Absent: inspected v1_interpreter.rs::match_pattern. For a raw variant payload, the Present peel requires parent_enum Optional; with no stamp the ordinary variant-name test can instead miss. The fieldless Absent handling admits Null, and matches the explicit absent variant without requiring a missing parent stamp. Leaving Absent out of THIS new refusal is therefore justified. The name-last-segment test also does not accidentally omit a qualified direct Present arm. Resolved and Dynamic subjects remain on their existing paths; the new predicate is not a blanket unresolved-type gate and does not recursively audit nested field patterns.

The Spark repair is at the producing value, not an exception: spark_native_arm_steps_of now binds per_rank: List<SparkNativeHostStep?> before the same flat_map and match. The zip_map inputs, computation and downstream completeness check are preserved. No module whitelist or diagnostic relaxation was added.

The three committed witnesses retain useful independent obligations: the minimized unannotated fixture requires one blocking diagnostic of the new class; the typed twin removes that class and the red-minus-green blocking count differs by one; and the inline typed route actually executes the generic-variant/flat_map/first chain and requires Present with the nested variant's detail. The last is the real-execution pairing, not merely a compiler-histogram assertion. I did not independently run these or the reported pre-fix Rust/rustc experiment.

DESIGN 4b / 6b: the recorded earliest unjustified link remains generic constructor instantiation. A link-4 refusal can establish rung 3 (structurally guaranteed) for this direct blocked-subject Present-arm population; it is not rung 4 and does not establish that the constructor is instantiated. The RFM explicitly retains unresolved-type propagation into other consumers and names the next capability: bind constructor parameters from field values/expected types, reconcile branches, and refuse genuinely undetermined arguments. That is a substantive capability trigger, not a date or a promise that the work is already done. When the upstream wall supersedes this one, retain the invalid-source regression obligation; the expected diagnostic may move to the earlier constructor boundary rather than freezing this exact downstream tag forever.

NON-BLOCKING documentary correction: the sentence in the source comment, RFM and PR body that all other variant patterns match solely by constructor name in every realization is too broad. The same interpreter function also has a raw-payload Holds peel conditioned on parent_enum Witness. This review establishes the Present/Absent distinction; it does not establish safety of every other special representation. Narrow that explanation to the reviewed direct Present population and explicitly leave other annotation-dependent representations outside its guarantee. Also make the row's rung wording explicitly direct-arm/PatternLookupBlocked so it is not read as recursive coverage. This does not require widening the current rule to every variant or delaying this protective fix for the full constructor-instantiation project.

Evidence scope: the exactly-one Spark site was author-measured over the stated required-gate census, not a proof over every repository consumer. The local fixture results, pre-fix silent answer, E0282 experiment and regeneration run remain author-run evidence. I reviewed the exact-head source, shared pattern-subject/annotation logic, runtime matching implementation, witnesses and generated deltas. At the latest exact-head check, clippy was successful; compiler, emit-build and floor were still running. Require all normal exact-head and merge-queue gates green before landing.

Copy link
Copy Markdown
Contributor

Symbol correction to approval review 5329439112: the new ExprMatch diagnostic is in v1.compiler.infer.infer_expr_body, reached through infer_expr; I wrote infer_expr_expected in the review, which is not this function's name. The inspected branch, exact head ac000d435910d47c3a7975050982d328f53cea20, approval and scope qualifications are unchanged.

- State only the reviewed Present-vs-Absent distinction. 'Every other variant pattern matches by
  constructor name' was too broad: match_pattern also special-cases Holds on parent_enum Witness.
- Scope the rung to direct arms over a PatternLookupBlocked scrutinee. Nested field patterns are
  not audited.
- When constructor instantiation (link 1) lands, the invalid-source control stays enrolled. Its
  expected refusal may move to the constructor boundary.
- Fix the RFM identity the 04_infer comment cited (a name that does not exist).

Review follow-up requested by eager-owl-205 on #12398 (review 5329439112).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

On review 71728 (dashboard artifact /api/reviews/71728/artifacts/stdout.log): the finding is correct. At ac000d4, the comment above present_arms_over_unresolved_scrutinee in src/v1/04_infer.dag cites generic_variant_constructed_without_expected_type_leaves_a_present_arm_undecided. The row is generic_variant_without_expected_type_leaves_a_present_arm_undecided.

It is fixed in #12402 (commit 5563bad), which is stacked on this branch. That commit renames the citation to the real identity, and also narrows the same comment's scope wording per review 5329439112.

It is not pushed to #12398 because this head is approved at ac000d4 and the approver asked that follow-ups go in a separate PR rather than move the approved SHA. The defect is in a comment only: annotations are erased before any semantic pass, and the text does not reach the generated mirror, so no behaviour or evidence on this head depends on it. #12402 retargets to main when this merges.

— sent from quiet-eagle-13

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — exact head 5563bad5159db307fafff3e42e13f72eb5fb0e76, reconfirmed as the current open, non-draft, mergeable head targeting main. Rebind of approval 5329439112 at ac000d435910d47c3a7975050982d328f53cea20.

Verified the complete approved-head-to-requested-head comparison and the successor commit. This is one fast-forward commit whose sole parent is the previously approved SHA. Only two paths change: the leading annotation on v1.compiler.infer.present_arms_over_unresolved_scrutinee in src/v1/04_infer.dag, and two descriptive receipt strings in gunbc.recurring_failure_mode.generic_variant_without_expected_type_leaves_a_present_arm_undecided. No executable inference expressions, diagnostic disposition/rendering, Spark remedy, witness assertions, runtime implementation, or generated mirrors change.

The documentary corrections are complete:

  • The inference annotation now cites the existing RFM identity generic_variant_without_expected_type_leaves_a_present_arm_undecided; verified the exact-head module declaration, data declaration and identity field. The previous non-existent name with constructed is removed from the annotation.
  • The source annotation, RFM and current PR description limit the explanation to the reviewed Present-versus-Absent distinction. The RFM/PR description explicitly acknowledge the separate Holds/Witness parent-stamp dependence instead of claiming that all other patterns are safe by constructor name.
  • The rung statement now names DIRECT Present arms over a PatternLookupBlocked scrutinee, and explicitly excludes nested field patterns. This matches the existing non-recursive checker refusal; it is not an expanded guarantee.
  • Link 1, generic constructor instantiation, remains the named upstream capability to build. The RFM names the existing invalid-source regression control and requires it to stay enrolled when that capability lands, allowing its expected refusal to move to the constructor boundary rather than preserving this downstream tag artificially.

The scope correction from my previous approval and the reported stale-RFM-citation issue are closed. No new source blocker; the previously approved bounded checker refusal and typed Spark producer repair remain unchanged. This is not approval of a completed constructor-inference repair or coverage of every annotation-dependent representation.

Evidence: source-delta and exact-head documentary review. I did not rerun tests, generation, or the interpreter/rustc experiments on this head. At the latest exact-head check, clippy, compiler, floor and emit-build were all in progress. Require the normal exact-head and merge-queue gates to complete green before landing.

gunbc-ci-auto-heal and others added 2 commits September 27, 2026 09:39
# Conflicts:
#	src/v1/stage0/src/v1_std_core.rs
The second corpus site PresentArmScrutineeTypeUnresolved refuses, which arrived on main after the
first census (run 36306265263): cas_key_of_slot_name matched first(skip(parts, ..)) where parts
came from the method-form split with no established type. Remedy the refusal names, same as the
native_serving_apply site: a typed let. Local floor on the merged tree after the fix: strict
preparation completed, 2236 modules resolved, 0 excluded, 0 PresentArmScrutineeTypeUnresolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — exact head 976ed457e8b419725c87ec8ac2f5d7b022b588c1, reconfirmed as the current open, non-draft, mergeable head targeting main. Rebind of approval 5329519427 at 5563bad5159db307fafff3e42e13f72eb5fb0e76.

No new source blocker. The second-site remedy establishes the producer's type without weakening or broadening the checker refusal.

History checked beyond the empty top commit: merge 6a6bd4d0efa77b523c05429cd40f384eb59a6d7b has first parent exactly the approved 5563bad5159db307fafff3e42e13f72eb5fb0e76 and second parent 2b2ee88bcefe8ef3815dc5198bbe64a9a24f60cb, matching the displayed main base. Requested head 976ed45 has that merge as its sole parent, has no changed files, and points to the same tree 4a276d303cc5ccaca66844a98b8add2c1d8fbce5. The CAS annotation is present in the merged tree, not merely asserted by the empty commit's message.

gunbc.durable_cas_file_store.cas_key_of_slot_name now declares let parts: List<String> = name.split(delimiter: "."). Inspected the complete function and its cas_slot_keys consumer: the count guard, final-component lookup, nonempty-decimal suffix requirement, dotted-key reconstruction, and refusal of an empty key remain unchanged. No alternate parse route, cast, authored Present result, module exemption, or diagnostic suppression is introduced. It is the same declared-producer remedy used by the existing typed Spark per_rank binding, not a special case in inference.

The approved-head comparison leaves src/v1/04_infer.dag, its generated inference mirror, the compile-clean diagnostic handling, the three refusal/typed-twin/executed-payload witnesses, the RFM, and the Spark producer repair unchanged. The main integration changes v1.std.core and its generated mirror only by incorporating main's separate EffectfulSelfRecursionUnrealized message update relative to the approved tree. The current PR delta retains PresentArmScrutineeTypeUnresolved's constructor, source-span and message rendering, and SeverityError/GateBlocking disposition; the generated diagnostic was not lost in the merge.

The refusal still applies only to direct Present arms with no parent stamp over a PatternLookupBlocked scrutinee. Absent remains outside this new refusal, nested field patterns remain unaudited, and the RFM still explicitly excludes a guarantee over other annotation-dependent representations such as Holds/Witness. Link 1 constructor instantiation remains the upstream capability to build, with the invalid-source regression obligation retained when the expected refusal moves upstream.

Evidence scope: I reviewed the merge ancestry, complete current PR delta, approved-head comparison, CAS function and consumer, and merged diagnostic handling. The reported first_generation_equal=true and local preparation result (2236 modules, 0 excluded, 0 PresentArmScrutineeTypeUnresolved) remain author-run evidence; I did not independently regenerate, rebuild, or execute the floor or witnesses. That zero is a result over the measured prepared population, not a proof that every repository consumer is resolved. The source shows two typed remedies: Spark and the CAS slot-name reader.

Non-blocking metadata: the PR body's corpus-reach section still ends with the first census and only the Spark remedy. Preserve that historical receipt and append the second site and new measured census, so it is not mistaken for the current reach. No source rebind is needed for a PR-description-only update.

At the latest exact-head check, clippy was successful; compiler, floor and emit-build were still in progress. Require all normal exact-head and merge-queue gates green before landing.

…edger wire and a data-class witness

- floor_terminal_ledger_wire: first() over filter(flat_map(admitted, ..)) with no established type.
  Now a typed let admitted_fields: List<String>. The floor compiles this as its own entry, which
  the preparation census could not see.
- data_class_admission_witness_test: a Present arm over the untyped parameter of the function value
  handed to classified_map. The match moves into a typed fn, email_length_of(claims:
  OidcStandardClaims) -> Nat.

Reach, re-counted per separately compiled entry (32 entries, each rc=0 with 0 refusals) and by a
whole-root compile of dag; the full table is in the PR body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — exact head d890e006de7c9e937f9a2d7bd2f9ad680243a0be, reconfirmed as the current open, non-draft, mergeable head targeting main. Rebind of approval 5329787555 at 976ed457e8b419725c87ec8ac2f5d7b022b588c1.

No new source blocker. Both additional consumer repairs supply declared types; the checker refusal is neither widened nor weakened.

Verified the complete approved-head-to-requested-head comparison. This is one successor commit whose sole parent is the previously approved SHA, not another merge. Only src/v2/workflow/floor_terminal_ledger_wire.dag and dag/test/claim/fabric/data_class_admission_witness_test.dag change. The inference rule, diagnostic disposition/rendering/census handling, generated mirrors, original refusal/typed-twin/executed-payload witnesses, RFM, and previously accepted Spark/CAS remedies are unchanged.

  1. Terminal-ledger wire: render_ledger_from_seed now binds admitted_fields: List<String> to the same flat_map(admitted, r => [r.qualified, r.terminal_detail]), then applies the same unclean-field filter and first-element match. The order and population of inspected fields are unchanged. The Present arm still returns LedgerUnrenderable with reason field-carries-separator, the actual offending value, and seed_diagnosis_of over the original rows. The Absent arm still renders the original admitted rows, row count and digest. No sanitization, fabricated clean result, shortened field population or omitted refusal is introduced. Snapshot and seed-row admission still precede this branch.

I checked the actual host consumer: cli_run/terminal_ledger_publish.rs::build_ledger_wire_ctx resolves workflow/floor_terminal_ledger_wire.dag as its own entry through resolve_entry_with_index_for_discovery_corpus, and publication invokes render_ledger_from_seed. The new census therefore addresses a real separately compiled boundary rather than relabeling the earlier preparation result as complete. Failure to resolve or render remains a terminal-ledger refusal; the host publication route has not been bypassed.

  1. Data-class witness: the email match moves into email_length_of(claims: OidcStandardClaims) -> Nat, using the same Present string count and Absent zero. a_projection_of_classified_data_keeps_its_category still obtains its classified input through fx_pii, executes classified_map, and compares the resulting category to personal_identity_ref. It is not replaced by a fabricated classified result or an unconditional success, and no data-class admission rule or caller seal changes.

  2. The existing invalid probe is correctly left invalid. bare_string_from_boundary_probe.email_in_the_clear attempts the nonexistent email field on Classified, and self_classified attempts an outside literal of the sealed carrier. I checked its consuming witness too: a_bare_string_cannot_be_walked_out_of_the_boundary_and_a_value_cannot_be_self_classified requires the original InternalError at subject no field 'email' on type 'Classified' AND SoleConstructorViolation at Classified, each by class and subject. A downstream PresentArmScrutineeTypeUnresolved cannot satisfy either assertion, and the test does not require an unchanged total diagnostic count. Leaving the new consequential diagnostic in this already-invalid source is not an exemption for an accepted program.

Reach/evidence: the PR description now preserves the earlier census receipts and separately reports the 32 named entry compiles, the reverted-wire control (rc=1, one site), regeneration (161/161, first_generation_equal=true), and the whole-root cross-check. It explicitly discloses 1243 name-census-only modules that were not compiled. Those results are author-run evidence; I did not independently execute or exhaustively re-enumerate the entry census, run regeneration, or rerun the witnesses. Compile rc=0 establishes compilation for the tested entry, not execution of every function/claim or a whole-repository zero. The source delta supports the two new typed remedies, bringing the documented repaired consumer population to four; the original deliberately invalid probe remains separately accounted for.

The approval's guarantee scope is unchanged: direct Present arms with no parent stamp over PatternLookupBlocked. Absent remains outside this refusal; nested field patterns and other annotation-dependent representations are not claimed repaired. Link-1 constructor instantiation remains the named upstream capability, with the invalid-source control retained when its expected refusal moves upstream.

At the latest exact-head check, clippy was successful; compiler, floor and emit-build were still in progress. Require normal exact-head and merge-queue gates to finish green, including completion of the floor's terminal-ledger publication. Source approval does not substitute for those results.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD / REQUEST_CHANGES — reach coverage incomplete at exact head d890e006de7c9e937f9a2d7bd2f9ad680243a0be, reconfirmed as the current open, non-draft head. This supersedes review 5330431710's APPROVE-MERGE recommendation pending the complete per-entry census. The previously reviewed checker and four declared-type consumer repairs remain accepted on source; this is an evidence/compatibility-coverage hold, not a newly found defect in those repairs.

The operator reports a second enumeration of 95 separately compiled entries versus the PR's 32, with the gap mainly in ci_spec GunbcRunStepTarget declarations for production workflows. I have not independently verified the 95 count or exhaustively enumerated the difference. I did verify a concrete omission against this exact tree: gunbc.ci_spec.gunbc_ci_mtcollins1_boot_target declares entry dag/gunbc/machine_intake/mtcollins1_boot_run.dag, function mtcollins1_boot_wet; that entry is absent from the PR's 32-row table. A declaration being present in an imported/name-census population is not evidence that it was typechecked as its own operational entry.

Accordingly, the existing 32 zero-result compiles remain valid author-reported observations for those entries only. They must not be described as EVERY separately compiled entry. The regeneration census and the whole-root cross-check (with its disclosed name-census-only population) do not fill this missing population. Required CI turning green alone cannot discharge this addendum: an uncompiled workflow entry could encounter the new refusal only when dispatched. No failure of mtcollins1_boot itself is asserted here; its independent entry result is presently unestablished by the submitted table.

To close this hold, as already requested by the operator:

  1. Derive and reconcile the entry roster from the exact reviewed tree's ci_spec GunbcRunStepTarget declarations and stage0 host entry constants, retaining the additional separately compiled workflow/CLI entries already identified. Show provenance from each entry to its declaring target/host consumer. Deduplicate actual equivalent compile configurations, not merely names; retain differing source roots/options as separate checks. Reconcile the 32 versus reported 95 by identities rather than treating either count as a fixed target. Any unresolved or unenumerated entry remains explicitly uncovered.
  2. Publish the complete per-entry table from a compiler built with this refusal against that source tree: entry, relevant compile configuration, return code, PresentArmScrutineeTypeUnresolved count, and evidence location. Every intended operational entry must compile successfully; timeouts, other compile failures and skipped checks are not zero-result passes. Preserve the reverted-wire control and account separately for intentionally invalid probes, whose original refusal assertions must remain intact.
  3. Repair any newly exposed accepted-program sites using established declared types, without a module exception, fallback or relaxation of the refusal. Rebind any changed source SHA. If only additional evidence is needed on the unchanged tree, no empty source commit is required; the evidence must still be reviewed before approval is restored.

Compile-only verification is the obligation here. Do not execute privileged production workflow functions merely to establish entry reach. Completing the permanent CI coverage mechanism is separate from supplying this missing census and is not an additional source demand in this hold.

My earlier caveat that I had not exhaustively re-enumerated the entry census did not justify the merge recommendation while this operational population was unaccounted for. The correct current status is source repairs accepted, coverage incomplete, HOLD for merge until the derived per-entry results are reviewed. No source, CI settings or live systems were modified by this review.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD / REQUEST_CHANGES — coverage evidence reviewed at unchanged head d890e006de7c9e937f9a2d7bd2f9ad680243a0be. This does not close coverage HOLD 5330451318. The checker and four declared-type repairs remain accepted on source; no additional source defect is asserted here.

The expanded inventory is useful progress: the table now includes ci_spec production targets, notably dag/gunbc/machine_intake/mtcollins1_boot_run.dag, as well as bootstrap/compiler and fixture populations. The distinction between the additional individually compiled rows and the union-closure rows is visible. However, the stated experiment is not the per-operational-entry verification requested by the hold.

Remaining blocker: source-closure containment has been substituted for equivalence of entry-specific compilation.

The method says that 183 dag/src/v2 entries were imported by ONE synthetic entry, and reasons that its 2352-source closure contains each entry's closure, so zero sites implies zero for every individual entry. That implication is not established by the submitted evidence. mtcollins1_boot_run.dag, mtcollins1_boot_admission.dag, the enrollment-code issuer, and the other ci_spec workflows are still recorded as union closure, not with their own compilation return code/configuration.

This rule is not a syntax-only predicate that necessarily distributes over a union of files. In the exact-head src/v1/04_infer.dag, resolve_pattern_subject resolves using scope.type_env; the new diagnostic is emitted from the inferred scrutinee/typed arms only when that resolution is PatternLookupBlocked. The operational host path in cli_run/entry_resolve.rs loads sources for the requested entry and passes that graph into resolution/reconciliation. A source file being present in a larger graph does not, by itself, establish identical bindings, inferred subjects, source-root precedence, or completion of the same item checks in the standalone entry's context. I am NOT asserting that the union actually masks a new failure here; the missing result is precisely what needs to be established.

The planted RED proves that the detector can report that specimen in the synthetic union. It does not prove that every operational entry's check is equivalent to its restriction from that union. Likewise, the admitted standalone rc=1 versus full-compiler rc=0 examples show why inclusion in a larger successful compilation is not itself an independent-success receipt; they do not establish a new Present-arm regression and I am not demanding unrelated repairs to those fragments.

The narrow way to close the existing hold:

  1. Keep the derived roster and run compile-only checks for the intended operational entry/configuration rows whose coverage is currently inferred only from the union. In particular retain the ci_spec target identity -> entry/function -> actual roots/options mapping for the boot, enrollment, IAM and other workflow steps. Reuse already obtained exact-head per-entry results where the configuration matches; there is no need to redo every prior successful check or force the inventory to a particular count.
  2. Report entry, actual compile configuration, return code, target diagnostic count, and a retained output/evidence reference. Each intended operational entry must complete the relevant checks; another error/timeout/skip is not a successful zero. A batch driver and existing sound parse/typecheck sharing are fine, provided each entry still resolves under its own configuration rather than being replaced by one synthetic import graph.
  3. Alternatively, justify the union substitution with an explicit equivalence argument against the actual compiler: identical relevant name/type environments and module-item checks for every represented operational configuration, and evidence of their completion. Mere subset-of-source-paths plus one planted RED is not that argument. Independent entry checks are the direct route; this review is not asking for a new compiler-equivalence project.

The 27 separate compiler/fixture observations and the additional 18 individual compiles remain useful author-run evidence for those configurations. Keep intentionally red fixtures and compiler fragments categorized separately. A .dag string literal is not automatically a supported standalone operational entry: when a fragment is actually compiled only through compile.dag or another pipeline root, show that consumer instead of requiring the fragment to become independently green. Conversely, an intended live entry with rc=1 cannot be marked covered solely because this diagnostic's count is zero.

Until the missing operational-context results or equivalence are provided, the supported conclusion is 'no new target diagnostic observed in the tested union and individually tested configurations; four repaired sites known,' not an established zero across every separately compiled entry. No evidence-only empty commit is needed, and no privileged workflow function should be executed for this census. The permanent CI coverage mechanism remains separate from this merge hold.

I read the expanded table and inspected the relevant exact-head entry-resolve and pattern-subject code. I did not independently run the compiler, validate the planted RED, or exhaustively rederive the 210-path roster. The exact-head floor now reports success; that does not discharge the separately identified production-entry coverage gap. Source and live systems were not modified by this review.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — coverage HOLD closed at the unchanged exact head

Reviewed d890e00. A comparison with refs/pull/12398/head returned identical (0 commits, 0 changed files). This supersedes my coverage REQUEST_CHANGES 5330790214. The current PR description now supplies the missing individual-entry compilation results; it is no longer substituting a synthetic union closure for those results.

What closes the condition

The table names the derived population (ci_spec workflow/deploy entries, stage0 host entry literals, compiler pipeline entries, instrument producers), states the root selection by entry family and command, and records per-entry return code, targeted diagnostic count, classification and log name. Its 210 rows are explicitly partitioned as 203 clean, 4 pre-existing non-rule failures, 1 deliberately invalid fixture, and 2 non-standalone fragments owned by src/v1/compile.dag. Re-run serial results replace the killed parallel attempts; no remaining timeout, kill or skip is represented as zero. The actual mtcollins1 boot/admission entries and the other operational ci_spec entries are included individually. The four pre-existing failures, including runner_microvm_slot_start, are not counted as successful compiles and do not require widening this rule. They still need their separately stated handling.

This is author-run evidence accepted for the scope of the earlier HOLD, not an assertion that I reran the 210 compiles or retrieved their scratch logs. The log references remain /tmp/claude-1000/qe-r/; retain them durably rather than treating a temporary path or the table itself as a permanent replayable artifact. I have not independently re-derived every roster member. The positive/negative detector controls and independently compiled configurations are materially different evidence from the earlier union experiment.

Source recheck

The direct Present-arm refusal remains conditional on PatternLookupBlocked and missing parent annotation; Absent is not broadened into the rule. I re-read the inference delta, the diagnostic histogram/specimen integration, the four declared-type repairs and the retained witness/RFM scope. The earliest constructor-instantiation defect remains named as the next rung, rather than claiming that this refusal repairs generic inference. No source change since the previously accepted d890e00 code was needed to supply this evidence.

Adjacent-class answer

Unresolved types flowing to other consumers or nested field patterns remain outside this deliberately bounded repair; Holds/Witness and other annotation-dependent behavior are not certified by Present coverage. The invalid-source control must remain when constructor inference is repaired, with its expected boundary adjusted if necessary. Separately compiled entry coverage is an exact-tree observation, not a standing guarantee against later entries or main drift.

Source: APPROVE-MERGE at this SHA through ordinary required checks and merge queue. The current metadata reports mergeable=false: resolve actual integration conflicts and request a delta rebind at any changed head, preserving these declared-type repairs and the rule. No bypass of merge gates. This review does not clear the unrelated integrated live-boot HOLD, merge, dispatch or perform hardware operations.

Merged via the queue into main with commit a5d8fbc Sep 28, 2026
5 checks passed
@briansrls
briansrls deleted the session/quiet-eagle-13 branch September 28, 2026 01:09
@briansrls
briansrls restored the session/quiet-eagle-13 branch September 28, 2026 01:18
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…hecker)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 29, 2026
… (bad process-substitution merge)

Content is the clean three-way text merge of the regenerated mirror (062a6c2) and
main's #12398 change; pending a regen byte check.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant