diff --git a/.github/workflows/witnesses.yml b/.github/workflows/witnesses.yml index 1d5ae79b78f..276391b5ee3 100644 --- a/.github/workflows/witnesses.yml +++ b/.github/workflows/witnesses.yml @@ -183,24 +183,7 @@ jobs: run: |- printf '%s\n' 'emit-build is a NON-REQUIRED detector lane. A red here does NOT block your merge:' printf '%s\n' 'the required context is `witnesses`, and this job is not an input to it.' - printf '%s\n' '' - printf '%s\n' 'A RED IS CURRENTLY EXPECTED: main cannot self-host, and the break has this signature --' - printf '%s\n' ' E0573 PointerWidth at src/std_integer.rs' - printf '%s\n' '' - printf '%s\n' 'This notice names no owning pull request ON PURPOSE. Ownership of a standing break moves,' - printf '%s\n' 'and a stale pointer here would be read as authoritative by someone who has no other source.' - printf '%s\n' 'The SIGNATURE is the durable handle: search it to find whoever currently holds it.' - printf '%s\n' '' - printf '%s\n' 'WHAT TO DO: if the failure above matches that signature, this is not your defect and' - printf '%s\n' 'there is nothing for you to fix. Do not patch around it in your branch.' - printf '%s\n' '' - printf '%s\n' 'WHAT IS A REAL FINDING: a DIFFERENT error code, or a different emitted file. That is a' - printf '%s\n' 'second defect this lane just caught, and it should be reported rather than assumed to be' - printf '%s\n' 'the known one -- every break at this step shares cause=EmittedCompilerBuildFailed, so the' - printf '%s\n' 'cause line does not discriminate and the ERROR CODE is what you compare.' - printf '%s\n' '' - printf '%s\n' 'THIS STANDING RETIRES WHEN: a head of main on which `gunbc test //gunbc/instruments:self-host` and `gunbc test //gunbc/instruments:v2-native-cli` all exit zero' - printf '%s\n' 'If that already holds on main, this notice is stale: flip gunbc.emitted_subject_build_gate emit_build_standing to EmitBuildExpectedGreen.' + printf '%s\n' 'No standing break is declared, so a red here is a REAL FINDING -- most likely yours.' if: failure() floor: runs-on: [self-hosted, linux, arm64] diff --git a/dag/gunbc/emitted_subject_build_gate.dag b/dag/gunbc/emitted_subject_build_gate.dag index 68d4282d50d..864f2d7be4d 100644 --- a/dag/gunbc/emitted_subject_build_gate.dag +++ b/dag/gunbc/emitted_subject_build_gate.dag @@ -181,13 +181,12 @@ fn emitted_subject_build_retirement_clause(row: EmittedSubjectBuildRow) -> Strin // THE ONE ROW TO EDIT WHEN MAIN SELF-HOSTS AGAIN. Flipping it to `EmitBuildExpectedGreen` deletes // the notice from every future run; leaving it stale keeps printing a reassurance for a red that // is no longer expected, which is why the type has only two arms and no "probably fine" middle. -data emit_build_standing: NativeEmitBuildStanding = EmitBuildExpectedRed { - known_signature: EmittedBuildSignature { - error_code: "E0573", - symbol: "PointerWidth", - emitted_path: "src/std_integer.rs", - } -} +// +// RETIRED 2026-09-27 (operator ruling): the retirement condition held on main 5bfe79be45c -- both +// instruments exited zero on srv1 (neat-boar-16, MemoryMax=45G), and the lane's own merge_group runs +// were green on the hosted runner (e.g. run 36344502292, job 108690877383, tested tree 12ab6d1439a). +// The E0573 PointerWidth at src/std_integer.rs signature is no longer expected. +data emit_build_standing: NativeEmitBuildStanding = EmitBuildExpectedGreen // THE LINES A LANE READS WHEN IT CLICKS THE RED X. Rendered from the standing row above AND from // whether the lane blocks -- a SUPPLIED Bool, because that fact's one home is the lane row in diff --git a/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag b/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag index 9dbd61e1737..7970dfd1842 100644 --- a/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag +++ b/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag @@ -34,6 +34,12 @@ import gunbc.guarantee_rung { Mitigatable, MechanicallyPreventable } // promoted under a separate work item. This row retires when that lane is OBSERVED to execute the // whole universe on a merge candidate; its receipt (run id, tested tree, the // `[native-cost-partition]` wall and peak) becomes `trigger_fired`. The emission alone does not. +// +// TRIGGER REBOUND 2026-09-27 (operator ruling, node adhoc-11684de4-07b): the native route becomes a +// REQUIRED LANE, and this trigger now names that lane's first green run carrying the frontier. The +// change that rewrote it retired only the E0573 standing: `emit-build` stays hosted and announced, +// because a blocking lane may not run hosted (operator ruling 2026-09-28) and its fleet claim awaits +// operator sign-off. The nightly above was deleted by #12439, which rebound its own row here. data v2_native_route_off_the_merge_path_population: List = [ "gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate", @@ -57,6 +63,6 @@ data v2_native_route_off_the_merge_path: RungDrop = RungDrop { temporary: Mitigatable, reason: DeletedWithoutReplacement, population: v2_native_route_off_the_merge_path_population, - restoration_trigger: "A REQUIRED NATIVE-ROUTE JOB WHOSE WALL FITS THE ACCEPTANCE PATH, designed from the ground up against an operator-agreed contract and not re-added into the same envelope: the job must conclude on every merge candidate inside its declared timeout on the real runner class (a measured wall, not a cited one), a newer head of the same subject must supersede the older run so no head holds more than one native claimant, and its red must still discriminate every clause of native_route_admission — universe join, positive population, classified refusals, per-identity agreement with the floor reference, and all four controls -- with the live false/true pair OBSERVED at gunbc.witness_v2_native_route native_route_live_pair_standing = LivePairRequired, not held by the expecting-red enrollment (gunbc.rung_drop.native_lane_live_pair_expected_red must be retired first, or retire in the same change). Whether that is reached by affected-set admission that runs only the universe a change touches, by a native run cheap enough to fit whole, or by a job that runs on a different cadence with its own row, is the design decision this drop waits on; the first two retire this row, the third replaces it with a differently-named drop. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return", + restoration_trigger: "THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return", } } diff --git a/dag/gunbc/witness/compiler_gate_workflow.dag b/dag/gunbc/witness/compiler_gate_workflow.dag index 66f79077f7e..e10e5adad53 100644 --- a/dag/gunbc/witness/compiler_gate_workflow.dag +++ b/dag/gunbc/witness/compiler_gate_workflow.dag @@ -1146,11 +1146,20 @@ fn compiler_gate_var_report(row: CompilerGateLaneRow) -> String { } fn compiler_gate_blocking_rows() -> List { - filter(xs: compiler_gate_lane_rows(), predicate: compiler_gate_lane_blocks) + compiler_gate_blocking_rows_of(rows: compiler_gate_lane_rows()) } -fn compiler_gate_strict_rows() -> List { - filter(xs: compiler_gate_blocking_rows(), predicate: fn(row) { +// THE AGGREGATE IS A FUNCTION OF A SUPPLIED ROSTER, and the live gate is that function applied to +// `compiler_gate_lane_rows`. The roster is the one input every surface below derives from, so +// taking it as a parameter lets a witness state a LAW over any roster -- an announced lane binds no +// variable, a blocking lane is read by every arm -- over a supplied row, while the live claims +// assert which lanes block today (DESIGN section 3: a witness discriminates at one interface). +fn compiler_gate_blocking_rows_of(rows: List) -> List { + filter(xs: rows, predicate: compiler_gate_lane_blocks) +} + +fn compiler_gate_strict_rows_of(rows: List) -> List { + filter(xs: compiler_gate_blocking_rows_of(rows: rows), predicate: fn(row) { match row.arm { GateArmStrict => true GateArmSkippableOnFork { notice: _, unobserved_error: _ } => false @@ -1158,8 +1167,8 @@ fn compiler_gate_strict_rows() -> List { }) } -fn compiler_gate_fork_rows() -> List { - filter(xs: compiler_gate_blocking_rows(), predicate: fn(row) { +fn compiler_gate_fork_rows_of(rows: List) -> List { + filter(xs: compiler_gate_blocking_rows_of(rows: rows), predicate: fn(row) { match row.arm { GateArmStrict => false GateArmSkippableOnFork { notice: _, unobserved_error: _ } => true @@ -1185,20 +1194,20 @@ fn compiler_gate_not_success_clause(row: CompilerGateLaneRow) -> String { join(["[ ", compiler_gate_var_read(row: row), " != success ]"], "") } -fn compiler_gate_echo_line() -> String { +fn compiler_gate_echo_line(rows: List) -> String { join([ "echo \"required lanes: ", - compiler_gate_report_text(rows: compiler_gate_blocking_rows()), + compiler_gate_report_text(rows: compiler_gate_blocking_rows_of(rows: rows)), " (same_repo=$SAME_REPO)\"" ], "") } -fn compiler_gate_failure_line() -> String { +fn compiler_gate_failure_line(rows: List) -> String { join([ "if ", - join(list_map(xs: compiler_gate_blocking_rows(), f: compiler_gate_is_failure_clause), " || "), + join(list_map(xs: compiler_gate_blocking_rows_of(rows: rows), f: compiler_gate_is_failure_clause), " || "), "; then echo \"::error::a required lane concluded failure (", - compiler_gate_report_text(rows: compiler_gate_blocking_rows()), + compiler_gate_report_text(rows: compiler_gate_blocking_rows_of(rows: rows)), ") - open that job's log\" >&2; exit 1; fi" ], "") } @@ -1207,12 +1216,12 @@ fn compiler_gate_failure_line() -> String { // there are two: a lane that FAILED is a verdict about the diff, and a lane that produced no // conclusion of its own leaves the head UNOBSERVED. Both block; they send a reader to different // places. -fn compiler_gate_unobserved_line() -> String { +fn compiler_gate_unobserved_line(rows: List) -> String { join([ "if ", - join(list_map(xs: compiler_gate_strict_rows(), f: compiler_gate_not_success_clause), " || "), + join(list_map(xs: compiler_gate_strict_rows_of(rows: rows), f: compiler_gate_not_success_clause), " || "), "; then echo \"::error::a required lane produced no conclusion of its own, so this head is unobserved rather than failed (", - compiler_gate_report_text(rows: compiler_gate_strict_rows()), + compiler_gate_report_text(rows: compiler_gate_strict_rows_of(rows: rows)), ")\" >&2; exit 1; fi" ], "") } @@ -1236,14 +1245,18 @@ fn compiler_gate_fork_line(row: CompilerGateLaneRow) -> String { // unobserved line over zero rows would render `if ; then` -- a shell syntax error that reds the // required context on every run, a gate whose only reachable state is red. The fork lines already // refuse `!= success` for every fleet lane, so omitting the empty line loses no refusal. -fn compiler_gate_unobserved_lines() -> List { - if length(xs: compiler_gate_strict_rows()) == 0 { [] } else { [compiler_gate_unobserved_line()] } +fn compiler_gate_unobserved_lines(rows: List) -> List { + if length(xs: compiler_gate_strict_rows_of(rows: rows)) == 0 { [] } else { [compiler_gate_unobserved_line(rows: rows)] } } fn compiler_gate_aggregate_script_lines() -> List { + compiler_gate_aggregate_script_lines_for(rows: compiler_gate_lane_rows()) +} + +fn compiler_gate_aggregate_script_lines_for(rows: List) -> List { list_append( - left: list_append(left: [compiler_gate_echo_line(), compiler_gate_failure_line()], right: compiler_gate_unobserved_lines()), - right: list_map(xs: compiler_gate_fork_rows(), f: compiler_gate_fork_line) + left: list_append(left: [compiler_gate_echo_line(rows: rows), compiler_gate_failure_line(rows: rows)], right: compiler_gate_unobserved_lines(rows: rows)), + right: list_map(xs: compiler_gate_fork_rows_of(rows: rows), f: compiler_gate_fork_line) ) } @@ -1273,8 +1286,12 @@ fn compiler_gate_same_repo_expression() -> String { } fn compiler_gate_aggregate_step_env() -> List { + compiler_gate_aggregate_step_env_for(rows: compiler_gate_lane_rows()) +} + +fn compiler_gate_aggregate_step_env_for(rows: List) -> List { list_append( - left: list_map(xs: compiler_gate_blocking_rows(), f: fn(row) { + left: list_map(xs: compiler_gate_blocking_rows_of(rows: rows), f: fn(row) { kv(key: row.var_name, value: yaml_string(s: compiler_gate_lane_result_expression(job_id: row.job_id))) }), right: [kv(key: "SAME_REPO", value: yaml_string(s: compiler_gate_same_repo_expression()))] @@ -1387,7 +1404,7 @@ fn compiler_gate_lane_rows() -> List { var_name: "EMIT_BUILD", arm: GateArmStrict, standing: LaneAnnouncedNotBlocking { - flip_trigger: "THE EMITTED SELF-HOST CLOSURE BUILDS ON MAIN. Measured red on run 35686128136: the emitted src/extdeps_numeric_base16.rs refuses with E0425 (UInt8 not found in scope at base16_decode_lower) and E0282, cargo status 101 -- gunbc#12004 pulling base16 into the closure while it still spelled the UNINHABITED UInt8 carrier where values are put -- NOT an emitter import gap, which is what the E0425 reads like and what this row first said; the repair (gunbc#12056) changes base16 to carry std.integer QualifiedOctets and leaves the emitter untouched. Sufficient for: a head of main on which `gunbc test //gunbc/instruments:self-host` and `gunbc test //gunbc/instruments:v2-native-cli` both exit zero, so that requiring this lane blocks merges only for defects the head in front of it introduced. At that point this row becomes LaneBlocks, the aggregate gains the needs edge and the variable, the job moves onto the fleet runner with the fleet lanes' fork guard and arm (operator ruling 2026-09-28: no blocking lane runs hosted, and compiler_gate_merge_path_runs_on_the_fleet refuses emission otherwise), and the measured GREEN wall is reported to the operator -- the 12m33s figure from the run above is a red run's wall and is a lower bound, not the number the decision turns on." + flip_trigger: "OPERATOR SIGN-OFF ON THE FLEET RUNNER CLAIM. The self-host closure builds on main -- the E0573 standing is retired (gunbc.emitted_subject_build_gate emit_build_standing = EmitBuildExpectedGreen; hosted emit-build green on main c39426540c, run 36580079634) -- so what now keeps this lane non-blocking is not a red but the runner: a blocking lane may not run hosted (operator ruling 2026-09-28, compiler_gate_merge_path_runs_on_the_fleet), and moving these two compilations onto the fleet is a standing claim on it for every pull request and merge_group that the job-roster rule gives to the operator. Sufficient for: the operator agreeing the fleet cost of this job, measured from a green wall of this lane. At that point this row becomes LaneBlocks, the aggregate gains the needs edge and the variable, and the job moves onto the fleet runner with the fleet lanes' fork guard and arm, in one change." } }, CompilerGateLaneRow { diff --git a/dag/test/claim/compiler_gate_emit_build_lane_witness_test.dag b/dag/test/claim/compiler_gate_emit_build_lane_witness_test.dag index 9f275812b84..7b9d24cee46 100644 --- a/dag/test/claim/compiler_gate_emit_build_lane_witness_test.dag +++ b/dag/test/claim/compiler_gate_emit_build_lane_witness_test.dag @@ -16,6 +16,8 @@ import gunbc.compiler_gate_workflow { compiler_gate_lane_result_expression, compiler_gate_aggregate_step_env, compiler_gate_aggregate_script_lines, + compiler_gate_aggregate_script_lines_for, compiler_gate_aggregate_step_env_for, + compiler_gate_blocking_rows_of, CompilerGateLaneStanding, GateArmStrict, compiler_gate_blocking_rows, compiler_gate_lane_rows, compiler_gate_same_repo_expression, compiler_gate_floor_job_condition, compiler_gate_emit_build_notice_step, @@ -126,11 +128,11 @@ test fn the_emit_build_lane_is_a_job_and_is_rostered() -> Bool { ) } -// AND IT IS DELIBERATELY NOT BLOCKING TODAY, which is the operator ruling this change implements. -// The claim is written so that FLIPPING the row to LaneBlocks reddens it: the follow-up that -// makes the lane required must come here and say so, rather than leaving a stale claim asserting -// a standing the workflow no longer has. -test fn the_emit_build_lane_is_announced_and_does_not_block_yet() -> Bool { +// AND IT DOES NOT BLOCK YET. The E0573 standing is retired, but a blocking lane may not run hosted +// (operator ruling 2026-09-28) and the fleet claim awaits operator sign-off, so the row stays +// announced. Reads the LIVE roster and aggregate, so a flip that forgets the fleet move is seen here +// as well as by compiler_gate_merge_path_runs_on_the_fleet. +test fn the_emit_build_lane_is_announced_and_not_read_by_the_gate() -> Bool { (any(compiler_gate_blocking_job_ids(), id => id == compiler_gate_emit_build_job_id) == false) && (any(compiler_gate_aggregate_job().needs, n => n == compiler_gate_emit_build_job_id) == false) } @@ -243,11 +245,33 @@ test fn every_blocking_lane_is_read_by_a_conditional() -> Bool { string_contains(s: script, pattern: join(["\"$", row.var_name, "\" = failure"], ""))) } +// AN ANNOUNCED LANE REACHES NO SURFACE OF THE GATE -- a LAW over any roster, so it is stated over a +// SUPPLIED LaneAnnouncedNotBlocking row rather than over a live lane, which today has none. Were an +// announced lane bound, its variable would render EMPTY, compare unequal to `success`, and refuse +// every run. The positive half renders the SAME row as LaneBlocks and requires it to reach every +// surface, so the claim cannot pass by the builders emitting nothing for that row. +fn announced_probe_row(standing: CompilerGateLaneStanding) -> CompilerGateLaneRow { + CompilerGateLaneRow { job_id: "probe-lane", var_name: "PROBE_LANE", standing: standing, arm: GateArmStrict } +} + +test fn w_RED_an_announced_lane_binds_no_variable_and_is_read_by_no_clause() -> Bool { + let announced = [announced_probe_row(standing: LaneAnnouncedNotBlocking { flip_trigger: "Sufficient for: probe" })] + let blocking = [announced_probe_row(standing: LaneBlocks)] + let announced_script = join(compiler_gate_aggregate_script_lines_for(rows: announced), "\n") + let blocking_script = join(compiler_gate_aggregate_script_lines_for(rows: blocking), "\n") + (any(compiler_gate_aggregate_step_env_for(rows: announced), e => e.key == "PROBE_LANE") == false) + && (string_contains(s: announced_script, pattern: "PROBE_LANE") == false) + && (length(xs: compiler_gate_blocking_rows_of(rows: announced)) == 0) + && any(compiler_gate_aggregate_step_env_for(rows: blocking), e => e.key == "PROBE_LANE") + && string_contains(s: blocking_script, pattern: "[ \"$PROBE_LANE\" = failure ]") + && string_contains(s: blocking_script, pattern: "[ \"$PROBE_LANE\" != success ]") +} + // AND THE ANNOUNCED LANES REACH NEITHER SURFACE. Without this the two claims above would be // satisfied by a gate that also read a lane it must not yet block on -- whose variable would // render EMPTY, compare unequal to `success`, and refuse every run. Both announced lanes are named: // emit-build, and since 2026-09-28 the unit-test lane. -test fn w_RED_an_announced_lane_binds_no_variable_and_is_read_by_no_clause() -> Bool { +test fn w_RED_the_live_announced_lanes_reach_neither_surface() -> Bool { let script = join(compiler_gate_aggregate_script_lines(), "\n") let env = compiler_gate_aggregate_step_env() (any(env, e => e.key == "EMIT_BUILD") == false) @@ -303,18 +327,37 @@ test fn the_fork_predicate_has_one_authority_across_both_transports() -> Bool { // ═══ THE STANDING NOTICE: WHAT A STRANGER READS WHEN THEY CLICK THE RED X ═══ // -// From the moment this lane landed, every PR in the repository runs it, and while main cannot -// self-host every one goes red for a defect its author did not introduce. The manager made -// exactly that mistake on this PR's own predecessor with ONE instance in front of him. +// THE LIVE STANDING IS GREEN (both instruments exit zero on main 5bfe79be45c; hosted emit-build +// green on main c39426540c, run 36580079634), so the red arm is +// reachable only over a SUPPLIED standing. These claims render it through this probe, so the +// discriminator, the no-owner rule and the retirement condition stay exercised while no red is +// declared; the live claim below asserts the green, non-blocking notice. +fn advisory_red_probe_notice() -> String { + join(emit_build_standing_notice_for(standing: EmitBuildExpectedRed { + known_signature: EmittedBuildSignature { error_code: "E9999", symbol: "Probe", emitted_path: "src/probe.rs" } + }, lane_blocks: false), "\n") +} + +test fn the_live_notice_is_green_and_not_blocking() -> Bool { + let text = join(compiler_gate_emit_build_notice_lines(), "\n") + string_contains(s: text, pattern: "does NOT block your merge") + && string_contains(s: text, pattern: "REAL FINDING") + && (string_contains(s: text, pattern: "E0573") == false) + && (string_contains(s: text, pattern: "CONTRADICTION") == false) +} // THE REASSURANCE ALONE WOULD BE WORSE THAN NOTHING: a standing red teaches every lane to ignore // this lane, which is how a detector dies without anyone deciding to kill it. So the notice must // carry the DISCRIMINATOR -- what would be a genuinely new finding -- and not only the comfort. test fn the_notice_carries_the_discriminator_and_not_only_the_reassurance() -> Bool { let text = join(compiler_gate_emit_build_notice_lines(), "\n") - string_contains(s: text, pattern: "does NOT block your merge") - && string_contains(s: text, pattern: "E0573 PointerWidth at src/std_integer.rs") - && string_contains(s: text, pattern: "DIFFERENT error code") + let probe = join(emit_build_standing_notice_for(standing: EmitBuildExpectedRed { + known_signature: EmittedBuildSignature { error_code: "E9999", symbol: "Probe", emitted_path: "src/probe.rs" } + }, lane_blocks: false), "\n") + string_contains(s: probe, pattern: "does NOT block your merge") + && string_contains(s: probe, pattern: "E9999 Probe at src/probe.rs") + && string_contains(s: probe, pattern: "DIFFERENT error code") + && string_contains(s: text, pattern: "REAL FINDING") } // THE NOTICE NAMES NO OWNING PULL REQUEST, and this claim exists because the first cut DID. @@ -331,14 +374,15 @@ test fn w_RED_the_notice_names_no_owning_pull_request() -> Bool { (string_contains(s: text, pattern: "#1") == false) && (string_contains(s: text, pattern: "#2") == false) && (string_contains(s: text, pattern: "PR #") == false) - && string_contains(s: text, pattern: "names no owning pull request") + && string_contains(s: advisory_red_probe_notice(), pattern: "names no owning pull request") + && (string_contains(s: advisory_red_probe_notice(), pattern: "#1") == false) } // AND IT TELLS A READER WHY THE CAUSE LINE CANNOT BE THE DISCRIMINATOR, because that is the trap: // every break at this step shares `cause=EmittedCompilerBuildFailed`, so a reader comparing cause // lines concludes "known break" for a defect that is new. test fn the_notice_says_the_cause_line_does_not_discriminate() -> Bool { - string_contains(s: join(compiler_gate_emit_build_notice_lines(), "\n"), pattern: "cause=EmittedCompilerBuildFailed") + string_contains(s: advisory_red_probe_notice(), pattern: "cause=EmittedCompilerBuildFailed") } // THE REASSURANCE IS UNPRINTABLE ONCE THE STANDING FLIPS. This renders the Green arm over a @@ -363,7 +407,7 @@ test fn w_RED_the_green_standing_cannot_print_the_expected_red_reassurance() -> // automatically when the condition holds -- that stays review diligence, and this claim does not // pretend otherwise; it establishes only that the condition reaches the surface a reader sees. test fn the_live_notice_prints_its_retirement_capability() -> Bool { - let text = join(compiler_gate_emit_build_notice_lines(), "\n") + let text = advisory_red_probe_notice() string_contains(s: text, pattern: "THIS STANDING RETIRES WHEN: ") && string_contains(s: text, pattern: "//gunbc/instruments:self-host") && string_contains(s: text, pattern: "//gunbc/instruments:v2-native-cli") diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 353f7accbad..22a709e6079 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -228,7 +228,7 @@ admission rows on falsifier-family cadences with no scheduled route, awaiting tr ### The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane — declared 2026-09-11 -The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane: RUNG DROP, mechanically preventable -> mitigatable (deleted without replacement). Population: gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate, the derived v2.test.* universe executed by the emitted-native compiler (positive population), v2.native_lane_fixture.control native_lane_false_control / native_lane_true_control (live-verdict controls), fixtures/native_lane_malformed/poison.dag.poisoned (malformed-specimen control), the old-route-withdrawn (no-fallback) control. Restored when: A REQUIRED NATIVE-ROUTE JOB WHOSE WALL FITS THE ACCEPTANCE PATH, designed from the ground up against an operator-agreed contract and not re-added into the same envelope: the job must conclude on every merge candidate inside its declared timeout on the real runner class (a measured wall, not a cited one), a newer head of the same subject must supersede the older run so no head holds more than one native claimant, and its red must still discriminate every clause of native_route_admission — universe join, positive population, classified refusals, per-identity agreement with the floor reference, and all four controls -- with the live false/true pair OBSERVED at gunbc.witness_v2_native_route native_route_live_pair_standing = LivePairRequired, not held by the expecting-red enrollment (gunbc.rung_drop.native_lane_live_pair_expected_red must be retired first, or retire in the same change). Whether that is reached by affected-set admission that runs only the universe a change touches, by a native run cheap enough to fit whole, or by a job that runs on a different cadence with its own row, is the design decision this drop waits on; the first two retire this row, the third replaces it with a differently-named drop. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return. +The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane: RUNG DROP, mechanically preventable -> mitigatable (deleted without replacement). Population: gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate, the derived v2.test.* universe executed by the emitted-native compiler (positive population), v2.native_lane_fixture.control native_lane_false_control / native_lane_true_control (live-verdict controls), fixtures/native_lane_malformed/poison.dag.poisoned (malformed-specimen control), the old-route-withdrawn (no-fallback) control. Restored when: THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return. ### The v2 native frontier (the ratchet over the emitted-native route's refusals) runs on no merge candidate and on no schedule until the required native-route lane is live — declared 2026-09-23