From 2a88e9350737b7a490d02e8918902a1db36fc73a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 27 Sep 2026 22:29:55 +0000 Subject: [PATCH 1/4] Census the fabric store's protected-head writers: run the authorization selection per writer MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Operator ruling A (2026-09-27): the fabric DB door verifies a per-operation grant on every protected advance. Which grant is a DESIGN §3b selection, so each writer is a gunbc.auth.privileged_effect_census row and the selection decides: D0 selects and realizes operator approval (conforms); the recurring host-effect lanes select workload identity; the operator's establish, finalize, abort and recover entries select one approval each. Adds RealizedUnauthorized for sites that write under host access alone, and one stated reason (fabric_store_write_unverified) whose dissolution is the store door d0_store_operation_wall names. Co-Authored-By: Claude Opus 5.5 (1M context) --- dag/gunbc/auth/privileged_effect_census.dag | 125 +++++++++++++++++- ...ization_pattern_selection_witness_test.dag | 34 +++++ 2 files changed, 158 insertions(+), 1 deletion(-) diff --git a/dag/gunbc/auth/privileged_effect_census.dag b/dag/gunbc/auth/privileged_effect_census.dag index 23783399c78..3ef40e98644 100644 --- a/dag/gunbc/auth/privileged_effect_census.dag +++ b/dag/gunbc/auth/privileged_effect_census.dag @@ -6,7 +6,7 @@ import std.dissolution { DissolutionCondition, DissolutionStatus, DissolutionFired, DissolutionPending, DissolutionUnbound, dissolution_status, unbound_dissolution, retires_dissolution, } -import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision } +import std.human_intervention { FleetOnce, DeviceOnce, EveryProvision, BreakGlassOnly } import std.roster_frontier { FrontierRow, frontier_row_decl } import gunbc.spark.bootstrap_provision { fleet_cloud_principal_standing, @@ -56,6 +56,9 @@ import gunbc.auth.authorization_pattern_selection { // resolve_access_token: the federated arm in a dispatched run, the operator's file in a session. // Classified as the federated pattern, because that is the arm that executes unattended and the // file arm is the operator's own workstation realization of the same entry. +// RealizedUnauthorized -- the site performs the effect under no credential that names it: the +// write reaches its store on the executor's host access alone. It matches no pattern, so a row +// realizing it is red unless it states why and what retires the reason. type OperatorSessionArm = GcloudInteractive | OperatorTokenFile @@ -66,6 +69,7 @@ type RealizedAuthorization | RealizedApprovalCapability | RealizedHumanStep | RealizedOperatorSession { arm: OperatorSessionArm } + | RealizedUnauthorized // A REASON IS A STATEMENT PLUS THE CONDITION UNDER WHICH IT STOPS BEING ONE. A bare string moved a // site out of the debt roster for as long as anyone left it there (review 68720): no bound, no @@ -109,6 +113,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedApprovalCapability => false RealizedHumanStep => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } OperatorApprovedCapability => match realized { @@ -117,6 +122,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedHumanStep => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } HumanOnlyStep { step: _ } => match realized { @@ -125,6 +131,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedApprovalCapability => false RealizedOperatorSession { arm: _ } => false + RealizedUnauthorized => false } OperatorOwnSession => match realized { @@ -133,6 +140,7 @@ fn realized_matches(selected: AuthorizationPattern, realized: RealizedAuthorizat RealizedRunSelected => false RealizedApprovalCapability => false RealizedHumanStep => false + RealizedUnauthorized => false } PastedOperatorToken => false } @@ -419,6 +427,17 @@ data eager_bootstrap_fork_declared: DivergenceReason = DivergenceReason { dissolution: retires_dissolution(ref: decl_ref(module_path: "gunbc.auth.access_token_source", decl_name: "ensure_access_token_eager_bootstrap_fork_dissolve_on")), } +// THE FABRIC STORE'S PROTECTED HEADS ARE WRITTEN UNDER HOST ACCESS ALONE (operator ruling A, +// 2026-09-27, relayed by proud-deer-538). The pair-serving authority partitions, the host-placement +// partition and the D0 consent slots are advanced by whoever reaches the fabric DB -- the placed +// host in process, every other host through the served door -- and the store verifies no grant for +// the operation. The rows below carry what each writer's selection asks for, so the door that +// verifies it has a derived answer per writer rather than one grant vocabulary for all of them. +data fabric_store_write_unverified: DivergenceReason = DivergenceReason { + statement: "the fabric DB admits an advance of a pair-serving authority partition, the host-placement partition or a D0 consent slot on the writer's host access alone: the placed host writes in process (FabricStorageLocalFiles) and the served door carries no grant, so the pattern selected for this writer is not the one the store enforces" as NonEmptyStr, + dissolution: unbound_dissolution(description: "one fabric store door every writer passes, the placed host included, that admits an advance of a protected head only under the credential this writer's selected pattern names, verified by the store for that operation -- the capability gunbc.spark.pair_serving_d0 d0_store_operation_wall names" as NonEmptyStr), +} + // THE DECLARATIONS THE BOUND TRIGGERS NAME, PRESENT BY CITATION. Each decl_ref here is checked by // the required floor against the corpus, so a trigger whose subject was deleted cannot stay in this // list. dissolution_status over it therefore answers Pending for every bound reason while its @@ -801,6 +820,110 @@ data privileged_effect_census: List = [ }, realized: RealizedFederatedGrant, divergence_reason: Present { value: gcp_iam_approval_enforced_in_reviewed_code }, + }, PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_d0_door", decl_name: "pair_serving_d0_ci_wet"), + effect: PrivilegedEffect { + subject: "D0: suspend a group's pair-serving authority for a keyed successor -- claim the consent slot, move the authority partition twice and finalize the host-placement preparation on the fabric DB" as NonEmptyStr, + frequency: FleetOnce, + reversibility: IrreversibleEffect { what_is_lost: "the incumbent pair's serving authority: a suspended authority is not restored by re-applying, only by a further authority transition" as NonEmptyStr }, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedApprovalCapability, + divergence_reason: none, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "claim_host_effect_live"), + effect: PrivilegedEffect { + subject: "admit a bounded host effect on the host-placement partition of the fabric DB for a v41 lane" as NonEmptyStr, + frequency: EveryProvision, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "settle_host_effect_live_over"), + effect: PrivilegedEffect { + subject: "release a bounded host effect on the host-placement partition of the fabric DB when its lane settles" as NonEmptyStr, + frequency: EveryProvision, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityBindable { member: "ghrunner on srv1, the dispatched fleet-converge run's host principal on the placed fabric DB host" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.host_commitment", decl_name: "host_effect_recover_wet"), + effect: PrivilegedEffect { + subject: "release a host effect whose lane died, on the host-placement partition of the fabric DB, under an operator-stated receipt" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "pair_serving_authority_establish_wet"), + effect: PrivilegedEffect { + subject: "establish a group's pair-serving authority on its fabric DB partition from the source row, once per group" as NonEmptyStr, + frequency: FleetOnce, + reversibility: IrreversibleEffect { what_is_lost: "the group's establishment: an established authority is never re-established, only transitioned" as NonEmptyStr }, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_finalize_wet"), + effect: PrivilegedEffect { + subject: "finalize a host-placement preparation whose saga died after its authority event landed" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, + }, + PrivilegedEffectSite { + site: site(module_path: "gunbc.spark.pair_serving_authority_log", decl_name: "host_placement_abort_wet"), + effect: PrivilegedEffect { + subject: "abort a host-placement preparation whose saga died before its authority event landed" as NonEmptyStr, + frequency: BreakGlassOnly, + reversibility: ReversibleByReapply, + surface: ApiSurface, + workload_identity: WorkloadIdentityUnbindable { cause: "an operator-run gunbc run entry; no dispatched run carries it, so no workload identity is bound to it" as NonEmptyStr }, + minted_reach: MintsNoCredential, + billing: NoBillingConsequence, + witness_discharge: NoWitnessDischarge, + }, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, }, ] diff --git a/dag/test/claim/authorization_pattern_selection_witness_test.dag b/dag/test/claim/authorization_pattern_selection_witness_test.dag index 7e1699b0ff1..e3a6c77124b 100644 --- a/dag/test/claim/authorization_pattern_selection_witness_test.dag +++ b/dag/test/claim/authorization_pattern_selection_witness_test.dag @@ -201,6 +201,40 @@ test fn each_witness_ground_fires_alone() -> Bool { && witness_required(e: break_glass) } +// THE FABRIC STORE'S PROTECTED-HEAD WRITERS (operator ruling A, 2026-09-27). Each writer's +// selection is the credential the store door will verify for it; asserting it here is what makes +// the tap count the operator was told a derived fact. D0 already realizes the approval it selects. +// The recurring host-effect lanes select the workload's own identity -- no human per run -- and the +// operator's recovery and establishment entries select one approval each; both groups diverge today +// under the one stated reason, because the store verifies nothing for any of them. +fn fabric_writer_verdict(key: String, want_approval: Bool, want_conforms: Bool) -> Bool { + any(census_verdicts(), v => + declaration_ref_display_key(ref: v.site) == key + && (if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) }) + && match v.conformance { + Conforms => want_conforms + DivergesWithReason { reason: _ } => !want_conforms + Diverges => false + SiteNotDecidable { standing: _ } => false + }) +} + +test fn the_d0_door_selects_and_realizes_operator_approval() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.pair_serving_d0_door::pair_serving_d0_ci_wet", want_approval: true, want_conforms: true) +} + +test fn the_host_effect_lanes_select_workload_identity_and_state_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.host_commitment::claim_host_effect_live", want_approval: false, want_conforms: false) + && fabric_writer_verdict(key: "gunbc.spark.host_commitment::settle_host_effect_live_over", want_approval: false, want_conforms: false) +} + +test fn the_fabric_operator_entries_select_one_approval_each_and_state_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.host_commitment::host_effect_recover_wet", want_approval: true, want_conforms: false) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::pair_serving_authority_establish_wet", want_approval: true, want_conforms: false) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_finalize_wet", want_approval: true, want_conforms: false) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_abort_wet", want_approval: true, want_conforms: false) +} + // ── The census, run through the real fold ──────────────────────────────────────────────────── test fn every_census_site_is_decidable() -> Bool { (undecidable_sites() |> count) == 0 From 3cb234c8f1bf69cb9b75c868527866ff45c7df15 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 27 Sep 2026 23:02:12 +0000 Subject: [PATCH 2/4] Census: D0's store write realizes no store-verified authorization (review 71933) Co-Authored-By: Claude Opus 5.5 (1M context) --- dag/gunbc/auth/privileged_effect_census.dag | 10 +++++-- ...ization_pattern_selection_witness_test.dag | 30 +++++++++---------- 2 files changed, 23 insertions(+), 17 deletions(-) diff --git a/dag/gunbc/auth/privileged_effect_census.dag b/dag/gunbc/auth/privileged_effect_census.dag index 3ef40e98644..379070d657f 100644 --- a/dag/gunbc/auth/privileged_effect_census.dag +++ b/dag/gunbc/auth/privileged_effect_census.dag @@ -433,6 +433,12 @@ data eager_bootstrap_fork_declared: DivergenceReason = DivergenceReason { // host in process, every other host through the served door -- and the store verifies no grant for // the operation. The rows below carry what each writer's selection asks for, so the door that // verifies it has a derived answer per writer rather than one grant vocabulary for all of them. +// D0's door does gate on an approval before it writes, but the effect a row counts is the STORE +// write, and the store does not see that approval: any writer reaching the DB performs the same +// advance without it, so D0's row realizes RealizedUnauthorized like the rest (review 71933). +// THE DISSOLUTION IS UNBOUND ON PURPOSE. d0_store_operation_wall is not retired when the capability +// lands -- it is flipped to StoreOperationWallRestored -- so retires_dissolution over it would fire +// on the row's deletion, an artifact, while the capability stayed dead (§4b(3)). data fabric_store_write_unverified: DivergenceReason = DivergenceReason { statement: "the fabric DB admits an advance of a pair-serving authority partition, the host-placement partition or a D0 consent slot on the writer's host access alone: the placed host writes in process (FabricStorageLocalFiles) and the served door carries no grant, so the pattern selected for this writer is not the one the store enforces" as NonEmptyStr, dissolution: unbound_dissolution(description: "one fabric store door every writer passes, the placed host included, that admits an advance of a protected head only under the credential this writer's selected pattern names, verified by the store for that operation -- the capability gunbc.spark.pair_serving_d0 d0_store_operation_wall names" as NonEmptyStr), @@ -832,8 +838,8 @@ data privileged_effect_census: List = [ billing: NoBillingConsequence, witness_discharge: NoWitnessDischarge, }, - realized: RealizedApprovalCapability, - divergence_reason: none, + realized: RealizedUnauthorized, + divergence_reason: Present { value: fabric_store_write_unverified }, }, PrivilegedEffectSite { site: site(module_path: "gunbc.spark.host_commitment", decl_name: "claim_host_effect_live"), diff --git a/dag/test/claim/authorization_pattern_selection_witness_test.dag b/dag/test/claim/authorization_pattern_selection_witness_test.dag index e3a6c77124b..2f83de9ed35 100644 --- a/dag/test/claim/authorization_pattern_selection_witness_test.dag +++ b/dag/test/claim/authorization_pattern_selection_witness_test.dag @@ -203,36 +203,36 @@ test fn each_witness_ground_fires_alone() -> Bool { // THE FABRIC STORE'S PROTECTED-HEAD WRITERS (operator ruling A, 2026-09-27). Each writer's // selection is the credential the store door will verify for it; asserting it here is what makes -// the tap count the operator was told a derived fact. D0 already realizes the approval it selects. -// The recurring host-effect lanes select the workload's own identity -- no human per run -- and the -// operator's recovery and establishment entries select one approval each; both groups diverge today -// under the one stated reason, because the store verifies nothing for any of them. -fn fabric_writer_verdict(key: String, want_approval: Bool, want_conforms: Bool) -> Bool { +// the tap count the operator was told a derived fact. D0's door gates on the approval it selects, +// but the store does not verify it, so its store write diverges like every other writer's. The recurring host-effect lanes select the workload's own identity -- no human per run -- and the +// operator's recovery and establishment entries select one approval each; all diverge today under +// the one stated reason, because the store verifies nothing for any of them. +fn fabric_writer_verdict(key: String, want_approval: Bool) -> Bool { any(census_verdicts(), v => declaration_ref_display_key(ref: v.site) == key && (if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) }) && match v.conformance { - Conforms => want_conforms - DivergesWithReason { reason: _ } => !want_conforms + Conforms => false + DivergesWithReason { reason: _ } => true Diverges => false SiteNotDecidable { standing: _ } => false }) } -test fn the_d0_door_selects_and_realizes_operator_approval() -> Bool { - fabric_writer_verdict(key: "gunbc.spark.pair_serving_d0_door::pair_serving_d0_ci_wet", want_approval: true, want_conforms: true) +test fn the_d0_door_selects_operator_approval_and_states_the_unverified_store() -> Bool { + fabric_writer_verdict(key: "gunbc.spark.pair_serving_d0_door::pair_serving_d0_ci_wet", want_approval: true) } test fn the_host_effect_lanes_select_workload_identity_and_state_the_unverified_store() -> Bool { - fabric_writer_verdict(key: "gunbc.spark.host_commitment::claim_host_effect_live", want_approval: false, want_conforms: false) - && fabric_writer_verdict(key: "gunbc.spark.host_commitment::settle_host_effect_live_over", want_approval: false, want_conforms: false) + fabric_writer_verdict(key: "gunbc.spark.host_commitment::claim_host_effect_live", want_approval: false) + && fabric_writer_verdict(key: "gunbc.spark.host_commitment::settle_host_effect_live_over", want_approval: false) } test fn the_fabric_operator_entries_select_one_approval_each_and_state_the_unverified_store() -> Bool { - fabric_writer_verdict(key: "gunbc.spark.host_commitment::host_effect_recover_wet", want_approval: true, want_conforms: false) - && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::pair_serving_authority_establish_wet", want_approval: true, want_conforms: false) - && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_finalize_wet", want_approval: true, want_conforms: false) - && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_abort_wet", want_approval: true, want_conforms: false) + fabric_writer_verdict(key: "gunbc.spark.host_commitment::host_effect_recover_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::pair_serving_authority_establish_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_finalize_wet", want_approval: true) + && fabric_writer_verdict(key: "gunbc.spark.pair_serving_authority_log::host_placement_abort_wet", want_approval: true) } // ── The census, run through the real fold ──────────────────────────────────────────────────── From 528bbb7c21215302b60739a8197df0d5346bc805 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 27 Sep 2026 23:36:47 +0000 Subject: [PATCH 3/4] Census: newline between rows (review 71946) Co-Authored-By: Claude Opus 5.5 (1M context) --- dag/gunbc/auth/privileged_effect_census.dag | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/dag/gunbc/auth/privileged_effect_census.dag b/dag/gunbc/auth/privileged_effect_census.dag index 379070d657f..c0cc7f34fde 100644 --- a/dag/gunbc/auth/privileged_effect_census.dag +++ b/dag/gunbc/auth/privileged_effect_census.dag @@ -826,7 +826,8 @@ data privileged_effect_census: List = [ }, realized: RealizedFederatedGrant, divergence_reason: Present { value: gcp_iam_approval_enforced_in_reviewed_code }, - }, PrivilegedEffectSite { + }, + PrivilegedEffectSite { site: site(module_path: "gunbc.spark.pair_serving_d0_door", decl_name: "pair_serving_d0_ci_wet"), effect: PrivilegedEffect { subject: "D0: suspend a group's pair-serving authority for a keyed successor -- claim the consent slot, move the authority partition twice and finalize the host-placement preparation on the fabric DB" as NonEmptyStr, From a2766a4681cb52af25075293d2f65e77903643ce Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Mon, 28 Sep 2026 01:11:19 +0000 Subject: [PATCH 4/4] Census witnesses: one row's verdict, not the whole census filtered (floor over-cost 111ms/100ms) Co-Authored-By: Claude Opus 5.5 (1M context) --- .../authorization_pattern_selection_witness_test.dag | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/dag/test/claim/authorization_pattern_selection_witness_test.dag b/dag/test/claim/authorization_pattern_selection_witness_test.dag index 2f83de9ed35..4132fcb84a6 100644 --- a/dag/test/claim/authorization_pattern_selection_witness_test.dag +++ b/dag/test/claim/authorization_pattern_selection_witness_test.dag @@ -207,10 +207,12 @@ test fn each_witness_ground_fires_alone() -> Bool { // but the store does not verify it, so its store write diverges like every other writer's. The recurring host-effect lanes select the workload's own identity -- no human per run -- and the // operator's recovery and establishment entries select one approval each; all diverge today under // the one stated reason, because the store verifies nothing for any of them. +// THE ROW'S OWN VERDICT through the real per-row fold (site_verdict), not the whole census folded +// and then filtered: each claim is about one site, and the census fold is already run by the +// roster claims above (§3: a witness discriminates at one interface). fn fabric_writer_verdict(key: String, want_approval: Bool) -> Bool { - any(census_verdicts(), v => - declaration_ref_display_key(ref: v.site) == key - && (if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) }) + any(map(filter(privileged_effect_census, row => declaration_ref_display_key(ref: row.site) == key), row => site_verdict(row: row)), v => + (if want_approval { selected_approved(s: v.selection) } else { selected_federated(s: v.selection) }) && match v.conformance { Conforms => false DivergesWithReason { reason: _ } => true