Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 1 addition & 18 deletions .github/workflows/witnesses.yml
Original file line number Diff line number Diff line change
Expand Up @@ -183,24 +183,7 @@ jobs:
run: |-
printf '%s\n' 'emit-build is a NON-REQUIRED detector lane. A red here does NOT block your merge:'
printf '%s\n' 'the required context is `witnesses`, and this job is not an input to it.'
printf '%s\n' ''
printf '%s\n' 'A RED IS CURRENTLY EXPECTED: main cannot self-host, and the break has this signature --'
printf '%s\n' ' E0573 PointerWidth at src/std_integer.rs'
printf '%s\n' ''
printf '%s\n' 'This notice names no owning pull request ON PURPOSE. Ownership of a standing break moves,'
printf '%s\n' 'and a stale pointer here would be read as authoritative by someone who has no other source.'
printf '%s\n' 'The SIGNATURE is the durable handle: search it to find whoever currently holds it.'
printf '%s\n' ''
printf '%s\n' 'WHAT TO DO: if the failure above matches that signature, this is not your defect and'
printf '%s\n' 'there is nothing for you to fix. Do not patch around it in your branch.'
printf '%s\n' ''
printf '%s\n' 'WHAT IS A REAL FINDING: a DIFFERENT error code, or a different emitted file. That is a'
printf '%s\n' 'second defect this lane just caught, and it should be reported rather than assumed to be'
printf '%s\n' 'the known one -- every break at this step shares cause=EmittedCompilerBuildFailed, so the'
printf '%s\n' 'cause line does not discriminate and the ERROR CODE is what you compare.'
printf '%s\n' ''
printf '%s\n' 'THIS STANDING RETIRES WHEN: a head of main on which `gunbc test //gunbc/instruments:self-host` and `gunbc test //gunbc/instruments:v2-native-cli` all exit zero'
printf '%s\n' 'If that already holds on main, this notice is stale: flip gunbc.emitted_subject_build_gate emit_build_standing to EmitBuildExpectedGreen.'
printf '%s\n' 'No standing break is declared, so a red here is a REAL FINDING -- most likely yours.'
if: failure()
floor:
runs-on: [self-hosted, linux, arm64]
Expand Down
13 changes: 6 additions & 7 deletions dag/gunbc/emitted_subject_build_gate.dag
Original file line number Diff line number Diff line change
Expand Up @@ -181,13 +181,12 @@ fn emitted_subject_build_retirement_clause(row: EmittedSubjectBuildRow) -> Strin
// THE ONE ROW TO EDIT WHEN MAIN SELF-HOSTS AGAIN. Flipping it to `EmitBuildExpectedGreen` deletes
// the notice from every future run; leaving it stale keeps printing a reassurance for a red that
// is no longer expected, which is why the type has only two arms and no "probably fine" middle.
data emit_build_standing: NativeEmitBuildStanding = EmitBuildExpectedRed {
known_signature: EmittedBuildSignature {
error_code: "E0573",
symbol: "PointerWidth",
emitted_path: "src/std_integer.rs",
}
}
//
// RETIRED 2026-09-27 (operator ruling): the retirement condition held on main 5bfe79be45c -- both
// instruments exited zero on srv1 (neat-boar-16, MemoryMax=45G), and the lane's own merge_group runs
// were green on the hosted runner (e.g. run 36344502292, job 108690877383, tested tree 12ab6d1439a).
// The E0573 PointerWidth at src/std_integer.rs signature is no longer expected.
data emit_build_standing: NativeEmitBuildStanding = EmitBuildExpectedGreen

// THE LINES A LANE READS WHEN IT CLICKS THE RED X. Rendered from the standing row above AND from
// whether the lane blocks -- a SUPPLIED Bool, because that fact's one home is the lane row in
Expand Down
8 changes: 7 additions & 1 deletion dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,12 @@ import gunbc.guarantee_rung { Mitigatable, MechanicallyPreventable }
// promoted under a separate work item. This row retires when that lane is OBSERVED to execute the
// whole universe on a merge candidate; its receipt (run id, tested tree, the
// `[native-cost-partition]` wall and peak) becomes `trigger_fired`. The emission alone does not.
//
// TRIGGER REBOUND 2026-09-27 (operator ruling, node adhoc-11684de4-07b): the native route becomes a
// REQUIRED LANE, and this trigger now names that lane's first green run carrying the frontier. The
// change that rewrote it retired only the E0573 standing: `emit-build` stays hosted and announced,
// because a blocking lane may not run hosted (operator ruling 2026-09-28) and its fleet claim awaits
// operator sign-off. The nightly above was deleted by #12439, which rebound its own row here.

data v2_native_route_off_the_merge_path_population: List<String> = [
"gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate",
Expand All @@ -57,6 +63,6 @@ data v2_native_route_off_the_merge_path: RungDrop = RungDrop {
temporary: Mitigatable,
reason: DeletedWithoutReplacement,
population: v2_native_route_off_the_merge_path_population,
restoration_trigger: "A REQUIRED NATIVE-ROUTE JOB WHOSE WALL FITS THE ACCEPTANCE PATH, designed from the ground up against an operator-agreed contract and not re-added into the same envelope: the job must conclude on every merge candidate inside its declared timeout on the real runner class (a measured wall, not a cited one), a newer head of the same subject must supersede the older run so no head holds more than one native claimant, and its red must still discriminate every clause of native_route_admission — universe join, positive population, classified refusals, per-identity agreement with the floor reference, and all four controls -- with the live false/true pair OBSERVED at gunbc.witness_v2_native_route native_route_live_pair_standing = LivePairRequired, not held by the expecting-red enrollment (gunbc.rung_drop.native_lane_live_pair_expected_red must be retired first, or retire in the same change). Whether that is reached by affected-set admission that runs only the universe a change touches, by a native run cheap enough to fit whole, or by a job that runs on a different cadence with its own row, is the design decision this drop waits on; the first two retire this row, the third replaces it with a differently-named drop. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return",
restoration_trigger: "THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return",
}
}
55 changes: 36 additions & 19 deletions dag/gunbc/witness/compiler_gate_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -1146,20 +1146,29 @@ fn compiler_gate_var_report(row: CompilerGateLaneRow) -> String {
}

fn compiler_gate_blocking_rows() -> List<CompilerGateLaneRow> {
filter(xs: compiler_gate_lane_rows(), predicate: compiler_gate_lane_blocks)
compiler_gate_blocking_rows_of(rows: compiler_gate_lane_rows())
}

fn compiler_gate_strict_rows() -> List<CompilerGateLaneRow> {
filter(xs: compiler_gate_blocking_rows(), predicate: fn(row) {
// THE AGGREGATE IS A FUNCTION OF A SUPPLIED ROSTER, and the live gate is that function applied to
// `compiler_gate_lane_rows`. The roster is the one input every surface below derives from, so
// taking it as a parameter lets a witness state a LAW over any roster -- an announced lane binds no
// variable, a blocking lane is read by every arm -- over a supplied row, while the live claims
// assert which lanes block today (DESIGN section 3: a witness discriminates at one interface).
fn compiler_gate_blocking_rows_of(rows: List<CompilerGateLaneRow>) -> List<CompilerGateLaneRow> {
filter(xs: rows, predicate: compiler_gate_lane_blocks)
}

fn compiler_gate_strict_rows_of(rows: List<CompilerGateLaneRow>) -> List<CompilerGateLaneRow> {
filter(xs: compiler_gate_blocking_rows_of(rows: rows), predicate: fn(row) {
match row.arm {
GateArmStrict => true
GateArmSkippableOnFork { notice: _, unobserved_error: _ } => false
}
})
}

fn compiler_gate_fork_rows() -> List<CompilerGateLaneRow> {
filter(xs: compiler_gate_blocking_rows(), predicate: fn(row) {
fn compiler_gate_fork_rows_of(rows: List<CompilerGateLaneRow>) -> List<CompilerGateLaneRow> {
filter(xs: compiler_gate_blocking_rows_of(rows: rows), predicate: fn(row) {
match row.arm {
GateArmStrict => false
GateArmSkippableOnFork { notice: _, unobserved_error: _ } => true
Expand All @@ -1185,20 +1194,20 @@ fn compiler_gate_not_success_clause(row: CompilerGateLaneRow) -> String {
join(["[ ", compiler_gate_var_read(row: row), " != success ]"], "")
}

fn compiler_gate_echo_line() -> String {
fn compiler_gate_echo_line(rows: List<CompilerGateLaneRow>) -> String {
join([
"echo \"required lanes: ",
compiler_gate_report_text(rows: compiler_gate_blocking_rows()),
compiler_gate_report_text(rows: compiler_gate_blocking_rows_of(rows: rows)),
" (same_repo=$SAME_REPO)\""
], "")
}

fn compiler_gate_failure_line() -> String {
fn compiler_gate_failure_line(rows: List<CompilerGateLaneRow>) -> String {
join([
"if ",
join(list_map(xs: compiler_gate_blocking_rows(), f: compiler_gate_is_failure_clause), " || "),
join(list_map(xs: compiler_gate_blocking_rows_of(rows: rows), f: compiler_gate_is_failure_clause), " || "),
"; then echo \"::error::a required lane concluded failure (",
compiler_gate_report_text(rows: compiler_gate_blocking_rows()),
compiler_gate_report_text(rows: compiler_gate_blocking_rows_of(rows: rows)),
") - open that job's log\" >&2; exit 1; fi"
], "")
}
Expand All @@ -1207,12 +1216,12 @@ fn compiler_gate_failure_line() -> String {
// there are two: a lane that FAILED is a verdict about the diff, and a lane that produced no
// conclusion of its own leaves the head UNOBSERVED. Both block; they send a reader to different
// places.
fn compiler_gate_unobserved_line() -> String {
fn compiler_gate_unobserved_line(rows: List<CompilerGateLaneRow>) -> String {
join([
"if ",
join(list_map(xs: compiler_gate_strict_rows(), f: compiler_gate_not_success_clause), " || "),
join(list_map(xs: compiler_gate_strict_rows_of(rows: rows), f: compiler_gate_not_success_clause), " || "),
"; then echo \"::error::a required lane produced no conclusion of its own, so this head is unobserved rather than failed (",
compiler_gate_report_text(rows: compiler_gate_strict_rows()),
compiler_gate_report_text(rows: compiler_gate_strict_rows_of(rows: rows)),
")\" >&2; exit 1; fi"
], "")
}
Expand All @@ -1236,14 +1245,18 @@ fn compiler_gate_fork_line(row: CompilerGateLaneRow) -> String {
// unobserved line over zero rows would render `if ; then` -- a shell syntax error that reds the
// required context on every run, a gate whose only reachable state is red. The fork lines already
// refuse `!= success` for every fleet lane, so omitting the empty line loses no refusal.
fn compiler_gate_unobserved_lines() -> List<String> {
if length(xs: compiler_gate_strict_rows()) == 0 { [] } else { [compiler_gate_unobserved_line()] }
fn compiler_gate_unobserved_lines(rows: List<CompilerGateLaneRow>) -> List<String> {
if length(xs: compiler_gate_strict_rows_of(rows: rows)) == 0 { [] } else { [compiler_gate_unobserved_line(rows: rows)] }
}

fn compiler_gate_aggregate_script_lines() -> List<String> {
compiler_gate_aggregate_script_lines_for(rows: compiler_gate_lane_rows())
}

fn compiler_gate_aggregate_script_lines_for(rows: List<CompilerGateLaneRow>) -> List<String> {
list_append(
left: list_append(left: [compiler_gate_echo_line(), compiler_gate_failure_line()], right: compiler_gate_unobserved_lines()),
right: list_map(xs: compiler_gate_fork_rows(), f: compiler_gate_fork_line)
left: list_append(left: [compiler_gate_echo_line(rows: rows), compiler_gate_failure_line(rows: rows)], right: compiler_gate_unobserved_lines(rows: rows)),
right: list_map(xs: compiler_gate_fork_rows_of(rows: rows), f: compiler_gate_fork_line)
)
}

Expand Down Expand Up @@ -1273,8 +1286,12 @@ fn compiler_gate_same_repo_expression() -> String {
}

fn compiler_gate_aggregate_step_env() -> List<YamlKeyValue> {
compiler_gate_aggregate_step_env_for(rows: compiler_gate_lane_rows())
}

fn compiler_gate_aggregate_step_env_for(rows: List<CompilerGateLaneRow>) -> List<YamlKeyValue> {
list_append(
left: list_map(xs: compiler_gate_blocking_rows(), f: fn(row) {
left: list_map(xs: compiler_gate_blocking_rows_of(rows: rows), f: fn(row) {
kv(key: row.var_name, value: yaml_string(s: compiler_gate_lane_result_expression(job_id: row.job_id)))
}),
right: [kv(key: "SAME_REPO", value: yaml_string(s: compiler_gate_same_repo_expression()))]
Expand Down Expand Up @@ -1387,7 +1404,7 @@ fn compiler_gate_lane_rows() -> List<CompilerGateLaneRow> {
var_name: "EMIT_BUILD",
arm: GateArmStrict,
standing: LaneAnnouncedNotBlocking {
flip_trigger: "THE EMITTED SELF-HOST CLOSURE BUILDS ON MAIN. Measured red on run 35686128136: the emitted src/extdeps_numeric_base16.rs refuses with E0425 (UInt8 not found in scope at base16_decode_lower) and E0282, cargo status 101 -- gunbc#12004 pulling base16 into the closure while it still spelled the UNINHABITED UInt8 carrier where values are put -- NOT an emitter import gap, which is what the E0425 reads like and what this row first said; the repair (gunbc#12056) changes base16 to carry std.integer QualifiedOctets and leaves the emitter untouched. Sufficient for: a head of main on which `gunbc test //gunbc/instruments:self-host` and `gunbc test //gunbc/instruments:v2-native-cli` both exit zero, so that requiring this lane blocks merges only for defects the head in front of it introduced. At that point this row becomes LaneBlocks, the aggregate gains the needs edge and the variable, the job moves onto the fleet runner with the fleet lanes' fork guard and arm (operator ruling 2026-09-28: no blocking lane runs hosted, and compiler_gate_merge_path_runs_on_the_fleet refuses emission otherwise), and the measured GREEN wall is reported to the operator -- the 12m33s figure from the run above is a red run's wall and is a lower bound, not the number the decision turns on."
flip_trigger: "OPERATOR SIGN-OFF ON THE FLEET RUNNER CLAIM. The self-host closure builds on main -- the E0573 standing is retired (gunbc.emitted_subject_build_gate emit_build_standing = EmitBuildExpectedGreen; hosted emit-build green on main c39426540c, run 36580079634) -- so what now keeps this lane non-blocking is not a red but the runner: a blocking lane may not run hosted (operator ruling 2026-09-28, compiler_gate_merge_path_runs_on_the_fleet), and moving these two compilations onto the fleet is a standing claim on it for every pull request and merge_group that the job-roster rule gives to the operator. Sufficient for: the operator agreeing the fleet cost of this job, measured from a green wall of this lane. At that point this row becomes LaneBlocks, the aggregate gains the needs edge and the variable, and the job moves onto the fleet runner with the fleet lanes' fork guard and arm, in one change."
}
},
CompilerGateLaneRow {
Expand Down
Loading
Loading