Repository navigation
Quarantine: a per-row NeverRunDeclinedOutsideGate holder for the probes the floor never plans; english_emit_add and file_hold leave quarantine (they pass) - #12651
Conversation
…ired floor never plans, per row, joined on module identity; english_emit_add leaves the quarantine Operator-manager ruling (option B): the fold gains a fifth holder, WitnessNeverRuns, for a probe with a gunbc.quarantine_outside_gate_decline row whose module required_gate_admits refuses. Each row carries its own module and next-rung trigger. A row whose module the gate admits derives no holder. english_emit_add_ingest_round_trip_holds PASSES (measured), so its admission row and its transitional-exception entry delete and the witness stays as a regression control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(its dissolution, #12132, landed) The #filter bare-provider refusal that hid its verdict was already retired by #12609. On main 785934a the probe PASSES, which its own dissolution names as the row's deletion condition. The nine algebra_receiver probes remain red (re-measured on the same main). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Floor red on 1479f86 is the declared dependency, not a defect in this diff: touching the module makes the floor compile — sent from crisp-lynx-364 |
…r off one live evaluation (was five live folds, 808,294 eval steps) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… claim); regenerate the rung-drop projection Chain re-derived from the budget refusal (808,294 steps, CI run 36656467027), measured with claim_batch: the corpus census host read is 10 steps; live subject derivation was 677,277 because module_for_entry folded the whole census once per admission row, and the disposition fold scanned each roster once per probe. Now: admission entries keyed once, the census read over the entries' own directories (derived, never authored) in one pass; the two rosters keyed once per population in quarantine_probe_dispositions. Both live claims 43.6k steps; all nine claims PASS; emptying the outside-gate roster reds both live claims. docs/design-rung-drops.md regenerated via tools.docs_projection_gate regen: english_emit_add leaves the transitional_admission_exception population. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Both reds from CI run 36656467027 are addressed in 42cbe99. generated. floor budget (808,294 steps). I re-derived the chain rather than supplying around it, because the cost was not in re-running the route. Measured with
Both joins are quadratic cost shapes (§6, bare minimum cost), so I keyed them:
Result: both live claims now take 43.6k steps, against the 72,300 new-witness budget. All 9 claims PASS. As a control, emptying the outside-gate roster turns both live claims FAIL. — sent from crisp-lynx-364 |
Depends on #12603.
test.claim.quarantine_probe_disposition_witness_testdoes not typecheck on main (List vs FreeMonoid) until #12603 lands. The evidence below was taken on #12603's head plus this diff. Land #12603 first.The latent red. With #12603 in, both live claims (
every_quarantine_probe_derives_exactly_one_dispositionandevery_supplied_population_is_load_bearing_on_the_live_claim) are false. 11 admitted probes deriveQuarantineProbeNowPassing, which is the fold's arm for "held by no roster". It is not an executed green.Measured with
claim_batchbefore choosing a remedy:test.claim.algebra_receiver_callable_witness_test×6 andtest.claim.algebra_receiver_alias_witness_test×3 all FAIL, which is their declared red. Deleting their rows would delete live discriminating reds (§4b(4)).v2.test.manual.english_emit_addenglish_emit_add_ingest_round_trip_holds: PASS. Its admission row and itstransitional_admission_exceptionentry delete (a climb), and the witness stays as a regression control.test.claim.file_hold_plan_refusal_probe_witness_testthe_harness_runs_…: PASS on main 785934a. TheUnimportedBareProvider RosterStale #filterentry refusal seen on an older base was already retired by Bare-provider gate: read bare references from the full parse; delete the byte scanner #12609; with it gone, the probe greens, which is exactly its row's dissolution (Measured compile: a unit variant is bound through its parent coproduct (std.measure census 147 -> 0) #12132 landed). Its admission row deletes. The 9 algebra_receiver probes were re-measured on the same main and are still red.Remedy (manager ruling: option B, with three conditions). A fifth holder arm,
NeverRunDeclinedOutsideGate { module, trigger }.WitnessNeverRuns: the arm records a red that nothing runs and nothing enforces. It is never read as held-and-checked or green.gunbc.quarantine_outside_gate_decline, and each carries its own module and its own next-rung trigger: the module being admitted byrequired_gate_admits, after which the probe moves tofloor_expected_red, or a recorded decision to keep it out. There is no blanket row.gate_admits(subject.module)is false. In production that isv2.workflow.required_floorrequired_gate_admits, the floor's own admission decision, not a copy of its prefixes. A row for a module inside the gate derives no holder, so the probe reads NowPassing and reds the witness.Widening the gate (option A) is a cost decision and is not in this PR.
Evidence (local
claim_batch, #12603 head + this diff): all 9 claims in the witness module PASS.an_outside_gate_row_holds_only_while_the_gate_refuses_the_module_and_only_as_never_run: the same row holds asWitnessNeverRunsunder a refusing gate, and derives NowPassing under an admitting one.🤖 Generated with Claude Code