Skip to content

Observe Namecheap DNS through fleet convergence and approval-gated WIF - #12421

Merged
briansrls merged 4 commits into
mainfrom
work/namecheap-secret-manager
Sep 28, 2026
Merged

briansrls merged 4 commits into
mainfrom
work/namecheap-secret-manager

Conversation

@briansrls

@briansrls briansrls commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

The owner has provisioned namecheap-api-key in the existing gunbai-secrets project and reported the Namecheap account and API allowlist. Fleet convergence needs an authenticated zone observation before it can plan stable tailnet-only dashboard ingress.

This adds the namecheap_observe dispatch mode with a dedicated, main-pinned WIF identity and enrolls that identity in the existing approval-gated IAM convergence target registry. The observer checks its public egress against the reported allowlist, resolves latest once through the checked Secret Manager reader, calls only getHosts, and records the exact resolved version and provider fields. Future reviewed mutations must select a numeric credential version; that selector is not a prerequisite for this discovery read.

The key travels to curl on stdin. Both the raw response and every retained decoded result/host attribute are checked for credential material before an observation can be returned. The bounded XML reader rejects malformed or ambiguous responses and unsupported syntax. Unknown attributes are preserved; detected credential material refuses the whole observation without printing the value. Mail mode remains unobserved and write authority withheld.

Review 5331195485 corrections:

  • One receipt-path declaration now feeds the writer, generated console read and artifact uploader. The nonexistent execution-text receipt is removed.
  • Post-decode exclusion covers known and unknown result/host attributes. Six behavioral controls cover raw, URI-encoded and XML-entity-encoded echoes, and ordinary entities. Removing the decoded guard in an isolated copy makes all three XML-echo controls fail.
  • A clean-root shell control executes the emitted success path with a successful observer stand-in producing only the declared JSON, checks the upload artifact, and confirms an unmatched receipt read fails. It reproduced the original defect against the previous YAML.
  • Native list-method calls and an explicit domain binder address the previous head's CI bare-provider failures. Uppercase Host is unchanged.

Local validation: 51 combined controls passed; the final parser/publication controls passed again after the CI-reference fixes. The regenerated shell passed the clean-root success control and rejected the planted unmatched receipt read. git diff --check passed.

Validation details and live prerequisites are recorded in docs/plans/namecheap-secret-manager.md. The workflow is regenerated through tools.generated_artifact_gate.main_wet_one. The loopback transport test uses a synthetic credential; these controls do not claim a live GCP or Namecheap observation.

Live boundary: after reviewed main landing, the controller's resource-local bootstrap reach must be verified, the exact IAM plan approved through the existing app, and the observer dispatched from an allowlisted runner. Full-zone DNS mutation, DNS-01 renewal coordination and dashboard fleet cutover are outside this bounded observation change.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T16:28:29.321434Z bf610a1 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bf610a13ef

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

&& all(e.children, c => nc_namespace_inherited(e: c))
}
fn nc_host_valid(e: XmlElement) -> Bool {
e.name == "Host" && xml_leaf(e: e) && trim(s: e.text) == ""

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Accept lowercase host elements from getHosts

The Namecheap getHosts response format emits DNS records as lowercase <host .../> elements, but this predicate only accepts Host. Consequently, any normal response containing records reaches NamecheapHostsRefused, so the new observation job cannot produce its receipt; the tests miss this because their fixtures also use the incorrect uppercase spelling.

Useful? React with 👍 / 👎.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD — exact-head review at bf610a1

The observation-only scope is appropriate, and the reuse is good: the Namecheap federation enters the existing IAM target registry; the trust condition derives from the shared fleet job claim pins; credential access consumes the existing checked Secret Manager reader; the dedicated job uses the event SHA and excludes the shared SSH-capable job. I am not asking this PR to finish DNS mutation, TLS, OAuth, or dashboard cutover.

Two corrections are needed before this head is a usable, safe observation route.

P1 — the generated success path cats a receipt that the observer never writes

Authorities: gunbc.ci_spec.gunbc_ci_namecheap_observe_invoke, gunbc.namecheap.observe.namecheap_observe_at, and v2.workflow.gunbc_invoke_step_emit.gunbc_invoke_receipt_steps.

The invocation supplies receipt_rel: "target/namecheap-observe-execution.txt". That argument is an OPTIONAL RECEIPT CAT, not an output path passed to gunbc: the generated workflow runs the observer, then executes:

cat "$ROOT/target/namecheap-observe-execution.txt"

The observer only writes target/namecheap-observation.json, and its CLI invocation has no argument that could produce the extra text file. On a clean runner, a successful authenticated getHosts read and successful JSON write are therefore followed by a failing cat. The step fails and the if: success() artifact upload is skipped. A leftover file could instead make the step accidentally depend on stale residue.

I executed the generated shell tail against a disposable directory containing the successful observer's declared JSON output and a success stub for the invocation: exit 1. Pointing the cat at the actual JSON output exits 0. This is a shell-boundary counterexample, not an execution of gunbc or the live observer.

Remove the unmatched cat (receipt_rel: none is sufficient if no console summary is needed), or bind it to an actually produced artifact. Derive the writer/upload/optional display locus from the same owned artifact declaration; do not add an otherwise unnecessary second receipt merely to satisfy the typo. Regenerate the YAML from its authority, never hand-edit it.

Acceptance: a clean-root success-path control executes the emitted step after producing only the observer's declared output, exits zero, and leaves the exact upload artifact available. Do not satisfy this by precreating the erroneous text file.

P2 — the credential-exclusion gate runs before XML decoding, so the persisted representation can reintroduce the key

Authorities: extdeps.namecheap.client.namecheap_get_hosts, extdeps.languages.xml.read.xml_entity, and gunbc.namecheap.observe.namecheap_host_json / namecheap_observe_at.

The client checks the RAW response for the credential and its URI-percent-encoded spelling, then decodes XML and returns all result/host fields for JSON persistence. Supported XML entity decoding can create the secret only after the check.

Concrete synthetic example, using the same fake-key spelling as the PR's transport test:

credential:       fixture-only-not-a-key&value
raw XML Address: fixture-only-not-a-key&amp;value

The raw XML contains neither the credential nor its %26 URI spelling. The supported &amp; decoding produces the credential in the returned Address. namecheap_host_json then serializes it into the uploaded JSON. An unknown retained attribute can do the same.

I reproduced these guard/decode/serialization expressions locally with synthetic data. This is not a report that a real key leaked, that today's real key has this shape, or that Namecheap currently echoes credentials. It is a counterexample to the claimed publication-safety contract over inputs the current model admits; the upstream global parameter table specifies ApiKey as String and this code does not constrain it to a narrower alphabet.

Keep the early raw-body check, but also check the decoded retained projection before returning/publishing it. Cover result attributes and every host's retained attributes, including unknown names/values. Refuse the observation without exposing the offending payload; do not silently delete a host field and still claim a complete snapshot. Put this at one publication boundary rather than maintaining unrelated redaction rules.

Acceptance: raw echo and URI-encoded echo refuse; XML-entity-encoded echo in a known field and in an unknown retained attribute also refuses; an ordinary unrelated value containing &amp; remains accepted and decoded normally. The successful credential-exclusion path needs a test through client response handling to receipt construction, not only the stdin-query transport test.

Existing bot finding: the cited documentation does NOT support changing Host to lowercase

I independently opened the Namecheap getHosts documentation during this review:
https://www.namecheap.com/support/api/methods/domains-dns/get-hosts/

Its published response example contains uppercase <Host HostId="12" ... /> and <Host HostId="14" ... />, matching nc_host_valid. The response table separately spells HostID, which is not evidence about element casing. I would not change the parser to lowercase-only based on the current automated comment. A real provider capture with a different spelling would warrant its own explicitly supported compatibility case; none is supplied in this PR.

Nonblocking modeling follow-ups

  • Preserve the narrow meaning of this receipt: authenticated getHosts observation at one run/version, not DNS convergence or write authorization. The existing mail_mode=unobserved and write_authority=withheld are good.
  • The numeric-version helper is not the production observation path: namecheap_observe_at intentionally reads latest once through the checked reader and records the numeric result. That is reasonable for discovery. Clarify the docs saying latest is for IAM only, and do not later cite the five selector tests as proof that this observation route is exact-version-selected.
  • For operational diagnosis, a future structured refusal should preserve safe provider error numbers and distinguish transport/egress/read-shape failures; it should not expose raw provider error messages or key-bearing bodies. This is not a demand to complete that redesign before the observation-only slice.

Evidence and scope

I inspected the changed source, generated job, shared claim pins, Secret Manager identity join, and inherited IAM request/re-admission/readback path. I did not independently rerun the 45 .dag controls or the supplied gunbc loopback harness: this environment has no gunbc executable. The local reproductions are deliberately narrower and use no real credentials or external calls. The witnesses run 36333250667 remained in progress at the final check. No IAM approval, secret access, Namecheap request, DNS mutation, deployment, or merge was performed.

After the two repairs and green exact-head CI, this can be reviewed for its declared observation scope without waiting for DNS/TLS/cutover. Live IAM bootstrap reach, exact approval/readback, and live zone observation remain separate acceptance evidence.

@briansrls
briansrls added this pull request to the merge queue Sep 27, 2026
@briansrls
briansrls removed this pull request from the merge queue due to a manual request Sep 27, 2026

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE — observation slice at 95e7af3

This re-review lifts my technical HOLD in review 5331195485, which was bound to bf610a1. Both findings are closed at the SHA above. I found no new blocking issue in the corrective delta. Proceed through the normal merge queue and its required checks; this is not permission to bypass them.

This is recorded as a COMMENT using the connected briansrls account, which is also the PR author's account. The technical merge disposition is explicit here; this is not an independent GitHub APPROVED vote.

P1 closed — one produced receipt, all consumers derived

gunbc.namecheap.observation_artifact.namecheap_observation_receipt_path now supplies the path to the observer's Filesystem.Write, the invocation's optional receipt cat, and the workflow artifact uploader. The generated job reads target/namecheap-observation.json; there is no extra execution-text receipt requirement and no unnecessary second producer added to satisfy the old mismatch.

I independently ran the repository's test/namecheap/workflow_success.py against the observer/upload steps extracted from the generated YAML at this head. The harness and artifact-declaration copies were checked against their Git blob hashes. The control passed: a clean temporary root with the successful observer stand-in produces only the declared JSON, the emitted step exits zero, and the exact upload path exists. The planted unmatched receipt read still fails. This verifies the shell/artifact boundary, not a live gunbc/Namecheap execution or an actual Actions upload.

P2 closed — the production client checks the decoded retained projection

namecheap_get_hosts now routes its successful HTTP response through namecheap_read_hosts_for_publication. That function retains the raw literal/URI-encoded exclusion, parses through the existing bounded Namecheap reader, then checks the observed domain and every retained result/host attribute name and value before returning NamecheapHostsObserved. The failure is a whole-observation refusal containing no offending payload; no field is silently dropped to make a partial snapshot appear complete.

The six new publication controls call this same production response-handling function. They distinguish raw and URI-encoded echoes, XML-entity-encoded echoes in Address, an unknown host attribute and an unknown result attribute, and an ordinary-entity positive control. The decoded cases require the decoded-refusal result, rather than passing merely because some earlier XML parse failed. I inspected these controls and the production-to-serialization wiring; I did not independently rerun the .dag suite or the author-reported mutation test in this environment.

Other delta and scope

  • The parser changes to list-method calls and the explicit observed_domain binder do not introduce a second provider format; uppercase Host is retained.
  • The documentation now correctly distinguishes discovery's one checked latest resolution from a future reviewed mutation's numeric-version selection.
  • The recurring-failure records state both the mitigation and the stronger future construction boundary; they do not claim that a path constant or substring guard is a general proof for every workflow or transformation.
  • No corrective-delta change widens IAM trust, adds DNS mutation, supplies SSH custody, or replaces the existing approval/readback authority.

Exact-head CI

GitHub run 36335450846 completed successfully at this SHA. All five check runs are successful: clippy, compiler, emit-build, floor, and witnesses. The floor job's registry-rostered generated-artifact check also succeeded. The merge-group-only stage0 check was skipped on this pull-request run, as named by the workflow; merge-queue qualification remains the normal landing boundary.

What this verdict does not discharge

This approves the bounded observation code, not live IAM standing or DNS convergence. After queue landing: verify the IAM controller's resource-local bootstrap reach for the new target; present the exact IAM diff through the existing approval app; apply and independently read it back; then run namecheap_observe on an allowlisted runner and verify the resulting receipt's run/attempt/revision, exact resolved credential version, domain and retained provider fields. Keep mail_mode=unobserved and write_authority=withheld.

DNS mutation convergence, coordinated DNS-01/TLS renewal, stable tailnet-only ingress and dashboard/approval-app cutover remain separate work. No IAM approval, secret retrieval, Namecheap request, DNS write, deployment, or merge was performed by this review.

@briansrls
briansrls added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit f55be8c Sep 28, 2026
5 checks passed
@briansrls
briansrls deleted the work/namecheap-secret-manager branch September 28, 2026 01:09
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…llows #12421's mode; regenerate fleet-converge.yml

kvm_still, boot_run and diagnostic_bundle witnesses pass locally (gunbc run --claim-run).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…_response

#12421 declared a top-level fn response. The bare-reference scanner reads each
service operation's response { ... } block (42 files) as a reference to it, so
every PR touching one of those files is refused UnimportedBareProvider. The
scanner's missing keyword awareness is reported as its own finding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…clause resolves to github.sha, not the exact mode list (#12421 added a mode and falsified the pinned prefix outside the gate)
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
A top-level fn named response (from #12421) made the unimported-bare-provider
gate read every service declaration's response block as a bare use of it in
the extdeps files this PR touches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…tsFixed); rename namecheap test helper off the `response` service keyword

Touching ebay/browse and github/app made the unimported-bare-provider gate
read their `response { }` service blocks as bare references to the test
helper fn `response` (#12421). Renaming the helper removes that collision.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
… namecheap test helper off the 'response' keyword

- provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: the set-property grants now carry the escaped '\\=' the
  sudoers renderer emits (generated job drift). The executor note is corrected: the bare '=' was
  accepted by the installed sudo (visudo-gated), so this is the documented spelling replacing a
  tolerated one, not a repair of mis-matching grants.
- test.claim.namecheap_hosts_witness_test fn response -> namecheap_api_response (and its one
  importer). Since #12421 that top-level name made the loader's bare-reference visitor read the
  'response { ... }' block of any importing service declaration as a use of it, so the floor's
  UnimportedBareProvider check refuses any PR that touches such a module (here
  approval_ntfy_deployment.dag). The visitor misreading a grammar keyword is the underlying
  defect and is reported separately.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Oct 2, 2026
…icates as declarations) (#12969)

* v2: ground where-refinement predicates as declarations; resolve binds them

Each decidable where predicate is a total Bool declaration (std.types string_non_empty,
gt_zero, range; std.content_hash lower_hex_16/40/64/128) and brand a declared marker fn.
Lowering carries every predicate of a clause, with its arguments, at its own occurrence;
v2 resolve binds each by ordinary name lookup and refuses an unbound one as
resolve_reason_where_predicate_unbound. non_empty is respelled string_non_empty corpus-wide
(v1 parse/infer tables + stage0 regen) and the gate's non_empty_string consolidates onto it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: home the Char classifier in std.unicode.char_class; fix stale predicate homes; import filter

std.string_type pulled into the compiler closure broke self-host emission (string_lex_compare
E0308); the classifier moves to its own Unicode module instead. Comments naming std.integer as
the home of gt_zero/range now name std.types (review 71649). filesystem_io imports the bare
filter the floor refused once the file was touched.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor roster: retire filter rows discharged by filesystem_io's filter import

filesystem_io now imports v2.std.algebra filter, so every file importing filesystem_io
no longer carries its bare filter pair; the floor refused the touched one as RosterStale.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor roster: retire v2.std.algebra rows reached through filesystem_io

The import closure is module-grained: importing filesystem_io now reaches every
v2.std.algebra declaration, so skip/any/length rows on its importers are discharged too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* where predicates: execute each declaration against the seed's probe values; stop overclaiming one authority

Until v1's tables can consult a declaration (feature:where-refinement-predicate-declaration-authority),
the declaration and the table are two representations. The vocabulary witness now executes each
grounded declaration on the probe value the compiler is observed to refuse, with boundary controls,
one claim per predicate; the comments state the fork instead of claiming one authority (review 71681).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* stage0: restore main's v1_rt.rs (a stale-binary regen had reverted it)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* filesystem_io: drop the duplicate filter import (main added the same one; review 71725)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* MQ-1 PR-2 WIP: caret symbol lowers to a symbol literal

* MQ-1 PR-2: RFMs, conservation control, symbol-literal frontier control

* symbol literal payload read without a nested Edge pattern (emitted Rust holds the label in an Rc)

* caret lowering claims: list_snoc_item from v2.std.algebra; declare the generic-ident-class flip

* parse probe: caret-site claims read one warm-shared parse (caret_tree_atom_identities) instead of re-parsing each

* caret lowering witness: plain recursion instead of fn-lambda call arguments (the witness is about carets, not the lambda frontier)

* caret lowering witness: build lists with list literals/concat (seed types a bare Cons as FreeMonoid)

* reference_conservation_admission: drop the braces my merge resolution orphaned (floor/generated: unparseable at byte 6129)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* namecheap witnesses: rename the test helper response -> namecheap_api_response

#12421 declared a top-level fn response. The bare-reference scanner reads each
service operation's response { ... } block (42 files) as a reference to it, so
every PR touching one of those files is refused UnimportedBareProvider. The
scanner's missing keyword awareness is reported as its own finding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: a module's own `type Int` / `type Bool` shadows the kernel spelling instead of being captured

Body lowering rewrote every type atom spelled Int or Bool to the kernel binding before any scope
existed. A module that declared its own `type Int = | Mine` and wrote `let y: Int = 1` therefore
had its annotation replaced by the kernel Int, and infer judged the let matched.

The spelling table moves to its language authority (v2.extdeps.languages.dag
dag_kernel_type_binding_optional), and resolve_atom consults it only after the scope walk and the
symbol index. A hit declared in the referencing module binds that declaration. Imported, foreign,
ambiguous and unbound kernel spellings keep the kernel binding, unchanged.

Claims (v2.test.claim.body_let_annotation, 5c): the module-declared Int and Bool lets refuse at the
annotation, and the annotation is asserted not to be the kernel binding. An undeclared Int/Bool
still binds the kernel type. Both shadow rows are red on main 9ce0394 and green here.
The rfm row records the residual and its trigger.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: an imported user Int refuses instead of binding the kernel Int

Resolve now reads a kernel spelling by the declaration a door selected.
v2.extdeps.languages.dag dag_kernel_type_declaration_binding_optional lists the declarations a
kernel spelling denotes. A hit on one of them takes the canonical binding, and the module's own
declaration shadows it. Any other declaration, reached through an import or another module,
refuses with resolve_reason_kernel_type_spelling_names_a_foreign_declaration. Unbound and
ambiguous names keep the spelling fallback.

Third RED: bla_imported_user_int_refuses_rather_than_binding_the_kernel_int (a two-module
fixture, p imports q's `type Int = | Mine`). All three REDs are F on main and T here, and the
controls are T on both. The new specimens are enrolled in floor_pure_producer_share. The rfm row now
states rung = refused, with the trigger at capability grain: declaration-keyed binding across every
door.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: an ambiguous kernel spelling refuses unless every candidate is a kernel declaration

An ambiguous kernel spelling now binds the kernel type only when every candidate is a kernel
declaration of it: v2.std.integer Int beside std.integer Int is one kernel type. Otherwise it
refuses with the ordinary resolve_reason_ambiguous_symbol instead of defaulting to the kernel. An
unbound name keeps the kernel binding, which is the correct answer when no declaration is in scope.

New claims:
- RED bla_ambiguous_imported_int_refuses_rather_than_defaulting_to_the_kernel (p imports Int from
  q and r). F on main, T here.
- Control bla_ambiguous_kernel_declarations_bind_the_kernel_type. T on both.

The multi-module specimens now share one helper, bla_assemble_with_peers. The rfm residual is now
only the kernel-declaration path list. Its trigger is a mark on the kernel declarations themselves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wip: infer symbol-literal arm (DagCanonicalSymbolLiteral typed as v2.std.node Symbol)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test.claim.parse_test_fn_decl_return_clause: lowering carries the authored return-type spelling

Three floor blockers on fa8c596. These claims read the positional return clause from body lowering
and expected the kernel binding (dag_binding_type_int, bool_node_symbol). Lowering used to produce
that binding by rewriting the spelling. That rewrite now happens in v2.compiler.resolve, after the
scope walk, so lowering carries `Int` and `Bool` as written, as the generic row already reads `T`.
Arm 1 still discriminates: the return type is Bool, not the parameter's Int.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag_canonical_literal_from_node: match the symbol-literal optional once

review 72280: the symbol arm tested dag_node_is_symbol_literal_atom and then recomputed
dag_symbol_literal_name_optional. That was the same optional twice, and the recomputation needed an
arm the predicate had already ruled out. The decision now matches the optional once. The remaining
Absent arm is a name payload with no atom identity, which is reachable.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Dissolve dag_node_is_symbol_literal_atom: callers match dag_symbol_literal_name_optional directly (review 72280 on #12549)

* identity_captured_navigation: read a caret literal's name from the lexeme-stamped terminal; delete the span/source-text route and its prose note row (review 72294 on #12549)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Delete the octet-to-scalar index and its lens-slice claims with the lens span route: nothing else consumed them

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* caret_symbol_has_no_lowered_form: the receipt states the literal's type as this PR derives it

review 72301: the receipt still said the symbol literal's type stays on the GroundingNotDerived
frontier. The arm in this PR makes that false. It now names the derivation route
(DagCanonicalSymbolLiteral, infer_literal_type_binding, v2.std.node symbol_type_node) and the two
body_let_annotation claims that execute it. Census trigger (a) stays open and the receipt says why:
it names the source checker v1.compiler.types, which still types LitSymbol as string_type.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: the single-tree namespace binds the module's own declarations; ownership reads declared_in

GitHub review 5342739525 on #12540. The same-module test compared a declaration's path to
ctx.namespace.module_qn, but build_program_namespace (the plain normalize -> resolve route)
leaves module_qn Empty and records its owner in declared_in. namespace_owns_declaration now reads
declared_in, which is the owner on both namespace routes and the field root_binding_origin reads.

Measuring that route found the earlier boundary. build_program_namespace harvested only the root's
named edges, and a normalized module keeps its declarations under captured -> <module path>, so
none of them were bound. `type Myint` refused as unbound, and a module's own `type Int` fell
through to the kernel spelling and was silently bound to the kernel Int. The namespace now also
harvests the module body, which it finds by declared_in.

Controls on that route (v2.test.claim.body_let_annotation, enrolled share points):
- bla_single_tree_module_declared_int_and_bool_bind_the_local_declaration: F before, T now.
- bla_single_tree_undeclared_int_binds_the_kernel_type: T on both.
The foreign-import refusal and both ambiguity dispositions are unchanged and still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: select a grafted module body by the graft's mark, never by walking names

Review 5343957887 (P2 on b55b8a7). namespace_tree_module_body walked the module path's names and
restarted at the root on a missing step. Two leaks followed:
- `module m.t` with a root-level record `t` missed `m`, restarted, found `t`, and bound the record's
  field as a module binding.
- `module t` with a record `t` selected it at once.

The body is now selected by the producer's own mark. v2.compiler.namespace_graft
namespace_graft_module_body_optional descends the containment spine
(namespace_graft_spine_segment_edge_optional) until a step is not a segment, never restarts, and
answers only when that stop is the marked body (namespace_graft_node_is_module_body).
Header and flat representations have no grafted body, so they keep root-only harvesting.

The admission reader in v2.compiler.name_resolve already descended the same spine with its own
copy (admit_named_exports_body_root and _descend_spine). It now calls the one function in
namespace_graft (namespace_graft_module_body_root), so the spine has one reader.

Controls (v2.test.claim.resolve.single_tree_module_body): supplied emit-shaped roots, because
normalize always emits a well-formed graft and source text cannot author these shapes.
- a_record_matching_the_path_suffix_is_not_a_module_body_holds: F on b55b8a7, T here.
- a_record_named_like_a_flat_module_is_not_its_body_holds: F on b55b8a7, T here.
Each asserts `leaked` is not bound and `t` still is.

The local Int/Bool and undeclared-kernel controls still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: move build_program_namespace's rationale above the declaration

The parse phase refused a // annotation inside the fn body (DESIGN section 4c: only module-item
grain is modeled). This is the same text, placed above the declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM reference_conservation_population_omits_class_stamped_terminals: the caret WHY is past tense and names its helper as deleted (review 72492)

* v2 infer: a literal payload's facts derive for its own family

Review 5348050288. infer_literal_edge_diagnostics_derived decided which literal family owned a
payload edge, then dropped the family. infer_literal_payload_entries typed every payload atom as a
DecimalDigit, so a Symbol literal's name terminal was recorded as a digit.

The edge decision is now typed: infer_literal_edge_payload returns InferIntMagnitudePayload,
InferSymbolNamePayload or InferNotALiteralPayload, and the payload fold takes that family.
- Int magnitude members keep DecimalDigit / FreeMonoid<DecimalDigit>.
- A Symbol name payload is one childless atom and derives as v2.std.node Symbol (symbol_type_node).
- Any other shape stays on the frontier.

Controls read each payload node's recorded resolved_type (v2.test.claim.body_let_annotation 5e):
- bla_symbol_literal_payload_is_typed_symbol_not_digit: F at 87a29e4, T here.
- bla_int_literal_payload_digits_stay_decimal_digits: T on both (the integer family is unchanged).
Both require at least one payload to be seen, so neither can pass vacuously.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* body_let_annotation: share the payload verdicts, not the inferred trees

The floor refused at 92389ff: PureProducerShareWarmNotStored for bla_symbol_literal_as_symbol_tree,
because the cross-claim store cannot hold a closure (ServeCacheValueNotPortable, path
.value.facts.lookup). The shared producers now return the portable projection the claims inspect:
bla_symbol_literal_payload_verdict (the symbol-typed and digit-typed Bools) and
bla_int_literal_payload_digit_verdict. The trees are built inside those producers and never stored.
The claims and their discrimination are unchanged: the Symbol payload control is F without the
family-aware fold and T with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 04_infer: the payload comment cites infer_literal_edge_payload, not the deleted predicate

Review 72579: the comment above infer_literal_payload_member_type still named
infer_literal_edge_diagnostics_derived, which this PR replaced. No definition or reference to it remains.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main; bla_symbol_literal_as_int returns Outcome<ResolvedTree> (the #12432 assemble type)

* Import the std.disposition / v2.std.live_tree names two touched files use bare; retire their now-imported roster rows

Main newly declared Disposition and LiveTreeDisposition, so the gate refused
both files on this touch as UnimportedBareProvider. Importing the declaring
modules also covers SingleAuthority, RealizationDispatch and
SubstrateInputsOnly, whose ActiveDebt rows retire as ImportsFixed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roster_gate imports Finding (bare channel is off in a file that declares imports)

* reference_conservation_admission: KnownDropShape as a one-variant coproduct (leading |), not an alias to StatementLetBinder

With one arm left, '= StatementLetBinder' parsed as an alias, so the variant
did not exist and two importers refused IMPORT-MEMBER-ABSENT. The corpus form
for a one-variant coproduct is '= | Variant' (e.g. SdramSignalingFamily).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: the kernel host-text String, bound only where no String declaration is visible

neat-boar-16's ruling after #12549. It mirrors #12549's Symbol pair through the same mechanism.

- Declaration: v2.std.node declares the opaque kernel `String` beside Symbol (the kernel-types home),
  and owns its type node, host_text_type_node.
- Binding: v2.extdeps.languages.dag binds the spelling `String` to it, and the declaration table maps
  v2.std.node.String to it.
- Foreign declarations (decision A): String is the one kernel spelling the corpus already declares
  with another meaning (v2.std.text and std.string_type are FreeMonoid<Char>, imported by 470+
  modules), so dag_kernel_type_foreign_declaration types its foreign-declaration disposition as
  ForeignDeclarationBinds. v2.compiler.resolve then binds the declaration the author reached, and
  the kernel host text applies only in the unbound arm. Int, Bool and Symbol keep
  ForeignDeclarationRefuses.
- Literal: DagCanonicalStringLiteral is a fourth arm of the one literal decision, typed as host
  text. Every consumer that matches the literal decision handles it (infer's type binding, branch
  operand, match-arm body, Bool pattern classify, payload edge, and the undecidable-verdict lens).
- No implicit coercion: a host-text literal at a FreeMonoid<Char> position REFUSES. The declared
  unfold (literal_homomorphism_rows, UnicodeScalarSequenceUnfold) is not reachable yet, because the
  literal carries no value. That is filed as gunbc.recurring_failure_mode
  string_literal_lowers_to_one_class_stamped_atom (fix routed to gentle-koi-724's lane).

Claims (v2.test.claim.body_let_annotation 5f). The REDs are F with the behavior reverted and T here:
- bla_unimported_string_binds_kernel_host_text
- bla_string_literal_is_typed_host_text
- bla_string_literal_ascribed_int_refuses
- bla_host_text_literal_at_structural_string_refuses
Controls, T on both:
- bla_imported_structural_string_binds_its_declaration
- bla_host_text_value_at_structural_string_is_never_matched (no non-literal expression derives host
  text in v2 yet, so it pins "never a clean admit")
- bla_unknown_unimported_type_name_still_refuses

The Symbol and #12540 claims are unchanged and still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: record the v1/v2 String fork and where it resolves (at the importers)

royal-newt-820 flagged it and neat-boar-16 ruled. Under decision A, v2 binds `import v2.std.text { String }`
to the structural carrier, while v1 keeps the kernel. The fork resolves at the importers:
- host-using importers drop String from their imports, in a separate PR ahead of #12760;
- structural-using importers are a declared divergence, recorded here, with #12760's census as the
  instrument.
The rung stays at the v1 minimum. Evidence: bla_imported_structural_string_binds_its_declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag_canonical_literal_from_node: the string arm matches the atom inline; the is_* predicate is gone

Review 73119. dag_node_is_string_literal_atom was a sibling Bool predicate over Node storage, which
the literal coproduct exists to replace. That is the same dissolution as dag_node_is_symbol_literal_atom
(3fb5d6a, review 72280). The decision matches the atom identity inline. The claim reads
DagCanonicalStringLiteral from the decision, and the RFM row cites the decision.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* defork census: the String row names the kernel host-text String as a distinct concept

The generated check failed at d9cc153: docs/plans/dag-v2-defork-audit.md drifted, because the census
now finds v2.std.node String (#12760) among the String declarations. The derived file list was
right, but the authored reading still called every String '= FreeMonoid<Char>, one concept, two
declarations'. That is false for the opaque host text. The reading now separates the structural pair
from the host-text String, and the projection is regenerated with generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* kernel String: read #12759's string value; realize v2.std.node String as the host string

#12759 landed, so a string literal now carries its decoded value as one named payload.
- DagCanonicalStringLiteral { value } reads it through dag_string_literal_value_symbol_optional. A
  payload-less string atom is now a malformed literal.
- The value edge is its own payload family (InferStringValuePayload), typed host text and never a
  digit, as #12549 did for the Symbol name. bla_string_literal_is_typed_host_text now also
  requires that.
- string_literal_lowers_to_one_class_stamped_atom records the climb by #12759. The remaining
  literal-at-FreeMonoid<Char> refusal is now blocked only by v2 infer not peeling an alias to its
  body.

emit-build failed at 9b7c07f: the opaque v2.std.node String was emitted as its own struct, so the
bare String in v2_std_node.rs (symbol_lexeme's return) stopped meaning the host string (E0308).
gunbc.rust_source_type_bindings gains the exact row v2.std.node String -> RustStdString beside
Symbol's, and the String checkpoint proof records that the kernel spelling now has one declaration
rendering the same carrier. The stage0 mirror is updated to match: claim_executor --required-regen
reports first_generation_equal=true over 161 files.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: the importer census is a named frontier, not an instrument this PR cites

Review 73214. The receipt called the importer census '#12760's census' and its instrument, but no
classification exists in the tree yet. It now says the population is described, not bounded; names
the census and deletion lane that will bound it; and states that #12760 is held as a draft until both
land, so the flip cannot precede the cutover. When the census lands, the receipt will cite it by
symbol.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* where_predicate_binding: assemble_program_from_ingest now returns Outcome<ResolvedTree> (#12629)

The binding claims inspect only accept/refuse, so they retype to
Outcome<ResolvedTree>; Node is no longer used.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 emit_rust: an opaque declaration with an exact realization row emits an alias to that row

Ruled by deep-bee-18 for gunbc#12760. The emitter emitted every zero-parameter opaque declaration
as `pub struct X(PhantomData)` and ignored the declaration-keyed rows in
gunbc.rust_source_type_bindings. On #12760, v2.std.node String therefore became a struct, and the
kernel's bare `String` render inside v2_std_node.rs meant that struct (E0308 at symbol_lexeme).

The rule is general and declaration-keyed: rust_opaque_declaration_has_exact_row joins the existing
name-keyed kernel-alias route at all three sites that decide it. An exact row emits
`pub type X = <row spelling>`. An ambiguous row, or a row with no realization, renders the located
compile_error! that rust_exact_binding_spelling already produces, so there is no silent choice. The
phantom struct stays only where no row exists.

Stage0: v1_compiler_emit_rust.rs is regenerated. std_types.rs gains `pub type Unit = ();`, because
std.types Unit is a bare opaque declaration with an exact row (RustUnit) that the old emitter
emitted nothing for. claim_executor --required-regen reports first_generation_equal=true.

Controls (test.claim.opaque_exact_row_alias_witness_test, each read from the emitted text):
- std.types Unit, reached only by its row, emits `pub type Unit = ();` (absent before this rule);
- a row-less opaque declaration keeps its phantom struct;
- Symbol keeps its row alias.

v1 admission (gunbc.v1_maintenance_standing v1_seed_standing): this serves the v2 self-host
program, because the emitted compiler closure must build with the v2.std.node host-text String.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 04_infer: bind the literal payload family once in the gather

Review 73303 on #12809 (finding 2) flagged the pattern this PR introduced: each family arm matched a
variant only to rebuild it for infer_gather_literal_payload_step. The gather now binds the family
once, with one arm for InferNotALiteralPayload and one for every family (DESIGN section 2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: cite the importer census by symbol, and its structural-using population

The census is gunbc#12840 (royal-lark-857). Instrument: v2.lens.text_string_importer_census
verdict_with_crossings, whose identity join closes (407 = 391 String importers + 16 non-members). The
structural-using population, the declared v1/v2 divergence, is 7 modules, named here. It is a lower
bound: 120 unclassified and 2 unmeasured importers stay open. #12760 stays a draft until #12840 and the
import-deletion PR land. The symbol is cited in prose only, and joins the evidence list once #12840
lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: the structural-using population is 15 (census revision 7b87f99)

After neat-boar-16's fixpoint ruling, #12840 classifies 15 structural-using modules. Eight of them
are structural only because they pass host text into a module that keeps its import. v2.compiler.tokenize
and v2.std.integer are named divergence sites (ruling 1), 10 parse-refused modules keep the import
(ruling 4), and 24 remain undecided. The second instrument, text_string_importer_fixpoint, is added.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor: the live-tree closure reads the process-shared index (one index for the environment and kernel-types closures)

closure_paths_of built a fresh MultiEntryIndex over the live dag root per
call. A diff touching std/types.dag asks for both the parse-environment and
kernel-types closures, so the same name set was indexed twice and #12765's
guard refused the floor (MultiEntryIndexBuiltTwiceForOneNameSet, both sites
namespace_baseline.rs closure_paths_of). The revision-tree index in
evaluate_owned_item_in is a distinct source set and is left as is.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Carry one live-tree index to both closures instead of using the thread's shared slot

The shared slot holds the floor's own dag+src/v2 index; a dag-only demand
there evicted it and the floor refused SharedIndexRebuiltAfterEviction
(#12848's own floor). LiveDagIndex is built on first demand by the floor's
baseline reconstruction and passed to environment_agreement and
kernel_set_serves_both (-> kernel_names_at), so the two closures share one
build and the shared slot is untouched. The roundtrip test shares one too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* string_literal RFM: the literal-at-structural refusal is a stopgap; #12809 is its trigger

neat-boar-16's ruling on #12760: since #12759 carries the literal's value, the lawful route is the
unfold. The row now cites gunbc#12809 (parked on #12726 PR2 and #12506) as the trigger that flips
bla_host_text_literal_at_structural_string_refuses to an unfold control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: import unicode_char_code_point from std.unicode.char_class

This branch moved it out of std.unicode.types (to break the std.types cycle);
main's new v2.std.compilers.lexing imported it from the old module, so the
v2-native emit of 00_compile refused (emit-build).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP v2 resolve: lexical references keyed by occurrence; infer/eval/translate/emit read them

* legacy_repair_tap witness: import Present/Absent from v2.std.optional

The witness matched git_sha1_object_id's Optional result with bare Present/Absent.
v2.std.execution_surface also declares Absent | Present (a9388e4, the same
commit), so once a closure holds both, the four reads are ambiguous and the floor
refuses PureProducerShareRowModuleUnframeable (AmbiguousBareNameRead, sites=4).
The value variant Present { value } is v2.std.optional's; execution_surface's
carries no field.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: lift unscoped atom arm; flatten infer pattern

* WIP: argument may not begin after a newline

* WIP: walk-population fixture mints its bound references, as the parser does

* Restore main's text in the gap-analysis plan: its non_empty spellings record measurements taken on the old name (review 73826)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: a loop carrier is a binder, kept as the atom it names, never a lexical reference

* Debt roster: retire (std/content_hash.dag, get) as NotAReference

The floor refused RosterStale: content_hash's get is the builtin get(xs:, index:),
whose pair came from the whole-pool fallback resolving it to an unrelated pool
fn get. be51d1f (bare loader asks per name) removed that, and retired the same
builtin-get pairs elsewhere (e.g. extdeps/bootloader/grub.dag) as NotAReference.
This branch touches content_hash.dag, so its row is the one this floor judges.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73872: drop the unused Char classifier; the gate checks its structural strings with v2.std.algebra non_empty

- std.unicode.char_class keeps only unicode_char_code_point (consumed by tokenize
  and lexing). CharClass and char_in_class had no consumer anywhere and are deleted
  rather than rehomed.
- gate's displaced_cost / mechanism_class are v2.std.text String = FreeMonoid<Char>.
  Passing them to std.types string_non_empty (host text) crossed representations
  with no declared unfold (DESIGN section 4). The gate now calls v2.std.algebra
  non_empty, the structural carrier's own check; main's private non_empty_string
  stays deleted.
- The vocabulary comment no longer claims String inhabits no FreeMonoid carrier.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Arrow-body-form mutation mirrors place the lexical-reference arm, as production does

* Integration: real three-way merges of the generated stage0 files; name Filesystem's declaring module at its five bare readers

The five bare Filesystem reads (harness_cli, harness_turn, runner_microvm_boot_probe,
scm.repository_load, scm.repository_save) call Filesystem.Read/Write/List, the
extdeps.filesystem.filesystem_io service that v1.compiler.emit_rust emit_file_call binds,
so that module is the import. They were refused AmbiguousBareNameRead once #12381's
std.types edit brought them into the floor's prepared closure.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: thread #12947's lexical field through #12381's where-predicate walk

resolve_where_predicate_operator converts resolve_atom's Outcome through the existing
resolve_walk_of_outcome (a type's where clause has no lexical binders in scope, and
resolve_atom carries no lexical answer), and the unwalked where-set edge carries an
empty lexical list. With this, v2.test.claim.parameter_reference's five assembled-program
rows (the four the floor failed on #12947 plus pr_named_fn_parameter_is_a_parameter_reference_holds,
red on main) return true: #12381's where-predicate binding is what cures main's
resolve_unbound_name_is_declared_in_several_modules at the where clause.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Merge #12760 (neat-ibex-696/kernel-string) into the integration branch (generated conflicts taken from ours; regenerated below)"

This reverts commit 2688462, reversing
changes made to d5446f3.

* Integration: take #12760 back out (operator option A); regenerate

#12760's own carrier_by_spelling row orders it after the String import-deletion
PR, which has not started. Its merge is reverted, the source-type binding row it
added is re-derived away by claim_executor --regen-round-cost (fixed point,
rebuild_packages=0), and the defork audit's String row returns to main's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: #12947's occurrence matches take main's OccurrencePending (#12790)

A pending occurrence has no id yet, so it is read like a synthetic one:
resolved_tree_lexical_binding finds no binding (Absent), and resolve_lexical_reference
refuses it as unkeyed (resolve_reason_lexical_reference_unkeyed). emit-build and the
generated lane refused both matches as non-exhaustive on bc718d2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: main's resolve_arrow_resource_requirements atom arm carries #12947's lexical field

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: name the declaring module at three bare reads the combined closure made ambiguous

extdeps.cloud.gcp.sts and extdeps.tailscale.acl_api read String bare, declared by both
std.string_type and v2.std.text; they import it from std.string_type, the dag/extdeps
convention (acl_api's std.types import of String bound nothing). gunbc.systemd_property_directive_overlap
reads Unit bare, declared by std.types and v2.std.cardinality; it imports std.types Unit.
The floor refused these as AmbiguousBareNameRead (CLAIM-SCOPE) on 430d11d.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: revert #12381's annotation-only edit in an excluded wet receipt; file the floor class it trips

The floor selects an annotation-only hunk as a changed witness, contrary to DESIGN section 4c,
and refused the head with ChangedWitnessOutsidePreparedSubject for
test.manual.command_runner_local_argv_receipt (on the hermetic exclusion list). The
annotation correction (non_empty -> string_non_empty) is reverted so the honest edit is not
what blocks the integration; the stale annotation and the capability that lets it be
restored are rostered as gunbc.recurring_failure_mode annotation_only_edit_selects_a_changed_witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: the two spark get rows keep main's Retired ImportsFixed standing

Main (#12954) retired them after fixing those imports; a merge here had carried the older
ActiveDebt rows forward, which the floor refuses as RosterRetirementChanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant