Skip to content

Journal initial commissioning and gate workspace supply on committed readback - #12691

Closed
briansrls wants to merge 279 commits into
codex/allocation-verticalfrom
codex/workspace-commissioning-production
Closed

briansrls wants to merge 279 commits into
codex/allocation-verticalfrom
codex/workspace-commissioning-production

Conversation

@briansrls

@briansrls briansrls commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Initial commissioning runs through the existing fleet plan/apply and slot controller. A host-owned executor retains the reviewed subject through exact controller completion, protected provenance/readiness readback, credential removal, and durable fleet-generation publication. Supply remains unavailable until that transaction commits. Executor lock and helper waits are bounded.

The branch is reconciled with main at a5e08e4dff9 and includes the stable-source lexer cursor for changed-witness classification. Merge resolution preserves all 62 workflow modes. The latest source repairs resolve qualified service prefixes without pulling unrelated bare helpers, preserve genuine missing-import checks, and explicitly import the live-tree authority in the three affected lexer/pipeline witnesses.

Current head: e7c4426229c. Required CI: run 37027879359. This run completed red: generated and emit-build passed, while floor/witnesses refused NonFoldResidueRosterDiverged unrostered=290. It is not a green qualification verdict.

Qualification evidence, scoped to its actual source:

  • At 1296fb5f713, the release compiler built, 17 closure-admission controls passed, and the separate live-corpus comparison passed over 621 sources. The ten native indexed-read cases passed with that compiler.
  • The full serve entry at 1296fb5f713 reached loopback readiness in 236 seconds under 12 GiB/no swap, with about 11.2 GiB peak and no OOM. The temporary server was stopped. This is startup evidence, not deployment or VM acceptance.
  • At 01a43aa013a, the three repaired lexer/pipeline files passed the full-repository batch import-admission gate and all four assertions (exit 0). Its OverAttributed cost diagnostic supports no cost conclusion. The current head adds only its receipt. See receipts.
  • The earlier reconciled workflow at 305283996bf passed all 38 workflow controls. Its generated 324,285-byte YAML matched the committed workflow exactly. Build and workflow evidence. This is not relabeled as latest-head evidence.
  • The local whole-floor runs for main, the cursor branch, and the earlier allocation head completed with the same seven browser-host prerequisite refusals: srv2 is outside the declared browser-test pool. None is a green full-floor verdict. Full CI uses its existing modeled 26 GiB envelope; server and VM limits remain 12 GiB and 28 GiB. No runner configuration was changed.

The PR remains draft. No release installation, initial readiness, reservation, guest boot, SSH, release, or reuse is claimed.

After qualification: install and read back the exact release, review the commissioning plan, exercise cancellation/reattachment, commission and replan to a no-op, then boot, verify SSH, release, reuse the same slot, and exercise expiry. Automatic website preparation, selected-host dispatch, and recurring readiness/expiry reconciliation remain subsequent integration work.

Landing update (2026-10-02): #13000 now extracts the compiler prerequisite directly onto main (20 files, one source commit). This PR still targets codex/allocation-vertical; no retarget, history rewrite, or merge has occurred. Of its 279 commits beyond that parent, 229 are already ancestors of main and 50 are child-specific. The full net diff to main still includes the unlanded parent work and needs separation.

Recorded landing path: compiler prerequisite → authentication/protected state → workspace request/lifecycle → commissioning, with broad task-history migration and unrelated presentation work separate. The isolated allocation-main-landing branch preserves the integration reconciled with main; it is not a replacement mega-PR or a commissioned artifact.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD at exact head 59a8744b5c91e60a769db3fe0ea571a405e57b1c, with the architecture accepted.

The source now closes the important internal commissioning gap: protected prepared/committed provenance, generation-CAS publication, restartable readiness publication, a sole-constructor committed-supply readback, fresh hold/sanitation checks before every phase, installed runtime/image/boundary checks, and offer/preparation consumers that can no longer accept fixture admission or a bare generation-zero readiness row. Preserve this shape.

P1 remains, and the PR already names it: there is still no reviewed fleet plan/apply subject that proves and retains the commissioning exclusion. The current controller can reach journal/readiness writes from a canonical credential whose plan_hash is supplied by that credential. The ordinary launch operation installs a credential and issues SystemdStartUnit; because the slot unit is Type=exec, that start completes before the controller's commissioning transaction completes. That is not yet an apply transaction.

The bounded next cut should add one commissioning-only fleet scope/request. Its plan should bind the exact host/slot, source and installed tree/controller/image identities, cell/controller budgets, hold/journal/readiness heads, prior-purpose withdrawal and sanitation identity. Apply must reobserve that subject under the host-generation and slot-start exclusion, stage the canonical credential, start and capture the exact unit invocation, wait for that invocation's terminal, verify its receipt plus committed journal and coherent readiness readback, and remove/read back the commissioning credential. Only then may the fleet terminal be FullyApplied and the generation commit. Timeout, cancellation and an already-running/prepared incarnation must remain nonterminal and recover through the same subject rather than starting another commissioning.

P2: cpu_budget is still authored by the directive. Runtime proves the installed cell boundary separately, but no join requires the provenance CPU figure to equal that observed/desired boundary; admission accepts any value >= the large profile, and offer production later reads the provenance value. Derive the CPU budget from the commissioned slot authority, or require exact equality before the journal can commit.

Separate live blocker discovered after this head: follow-up storage plan run 36637771191 completed red because the unprivileged planner could not list the correctly installed root:root 0700 /var/lib/gunbc/fabric namespace. Keep 0700; move that observation through the administrator/read-only privileged edge. Until that is repaired, convergence cannot establish the intended no-op prestate.

No VM launch is claimed or established. After the observer and guarded apply are connected, the next useful operation is the wet commissioning plan/apply, then one manually prepared selected-host allocation, SSH, release, and same-slot reuse. No memory ceiling increase is indicated.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head follow-up at 52b532e0ec896b82187556f369beaa572921e69f: HOLD remains, narrowed to the guarded fleet commissioning apply and integrated qualification.

Accepted repairs:

  • the storage no-op is now genuine: the administrator observer can read the root:root 0700 substrate and the reviewed no-op emits zero ensure operations;
  • commissioning CPU provenance is derived from, and required to equal, the installed slot boundary rather than being an independent credential assertion;
  • installed-tree identity is now bound by both release revision and installed-tree digest;
  • the start/wait helper binds completion and receipt readback to the exact new systemd InvocationID and refuses unread or changed invocations.

The source-critical blocker is still the enclosing fleet transaction. microvm_slot_start_admitted deliberately means only “this exact invocation terminated and its receipt was readable”; it admits a readable refusal receipt as a successful observation. The commissioning apply must add the stronger terminal: retain shared start/acquisition exclusion, install the exact commissioning credential, start and wait for the exact invocation, require the receipt text to be the commissioning-success arm, reread Committed provenance plus generation-zero CellReady and unchanged artifact/budget/hold facts, remove and read back credential absence, and only then publish FullyApplied/advance fleet generation. Timeout, cancellation, an unread receipt, or any refused: receipt must leave the operation unsettled/recoverable, never expose supply.

Exact-head CI is red, but the published floor receipt points to stale-base failures outside this commissioning delta: Optional unwrapping in the BMC/PID/host-hygiene witnesses and a stale WorkRowView literal. This stack is 34 commits behind current main, and current main already contains at least the BMC total-match repair. Reconcile current main into the allocation stack rather than repairing those predecessor files again here, then rerun the exact integrated floor.

After a clean rebase, the next useful artifact is a read-only commissioning plan—not another fixture pass—showing the complete subject, exclusion, exact credential, invocation wait, terminal receipt, protected readbacks, credential cleanup, and recovery behavior. No VM boot or memory-ceiling increase is justified yet.

gunbai-bot Bot and others added 28 commits September 30, 2026 04:41
…producer no longer pulls parent modules (#12719)

collect_node_refs recorded a chain at every field-access node, so `a.b.c.d` also arrived as
`a.b.c` and `a.b`. #12655 filtered receiver prefixes in its own reader
(module_paths_of_references); the other chain consumers -- the reference-edge producer
(reference_edges_for_file_on_demand) and reference_targets_of -- resolve every recorded chain by
longest_declared_module_prefix with no filter, so a receiver prefix named the parent module.

The prefix is now withheld at the producer, on the receiver spine it already tracks, and the
reader-side filter is deleted: one place decides it.

v1 admission (gunbc.v1_maintenance_standing): serves the v2 floor's closure edges.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…le-path re-scan) (#12722)

load_sources_for_entry_with_pool ran load_sources_for_entry_with_index, whose
extend_with_reference_closure fully parses every closure file (no reuse; timed as
load_reference_scan) -- once per entry -- and then extend_sources_to_both_closure_fixpoint,
whose reference half (extend_with_reference_closure_for_pool) answers the same question from the
index's one parse per file. Since #12655 made that scan a full parse, it is a second parse of
the whole closure on every entry.

The pool route now loads the import closure only (load_import_closure_for_entry) and leaves the
reference half to the fixpoint. Callers without a pool index keep
load_sources_for_entry_with_index unchanged.

v1 admission (gunbc.v1_maintenance_standing): serves the v2 floor's preparation cost.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t as Absent (#12725)

* XL-2: the reify route carries an operand refusal instead of reading it as Absent

body_lower_reify_operand_node and body_lower_reify_branch_target mapped
OperandRefRefused to Absent, so a refused operand fell to the shell reader and
surfaced as unsupported_form (or, for a branch target, was kept as if read).
Both now carry the refusal with its own cause and locus. One of the two routes
#12615 named for RFM lowering_accessor_collapses_a_sequence_operand.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* XL-2 reify route: witness (red on main) and RFM receipt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…gin is its own typed standing (#12752)

A dead-band row asserts its claim can land above the enrolment margin on a runner the measured
envelope admits. The self-staling rule compared every reading against the margin itself, which is
the bound derived for a p90-slow runner, so a fast runner's reading of a genuine band member staled
the row the slow run needed: gunbc#12533's matrix cases read 332/339 ms, then 294/294 ms, at
identical eval_steps.

v2.workflow.floor_enrolment_margin floor_enrolment_dead_band_envelope_floor applies the same measured
p90 envelope once more (margin 302 ms -> floor 182 ms); no literal is added. With a dead-band row:
- (margin, line]: declared, unchanged;
- (floor, margin]: EnrolmentDeadBandWithinRunnerEnvelope, reported with both bounds, not blocking;
- at or under the floor: EnrolmentDeadBandStale (now carrying the floor), blocks;
- over the line: wrong ground, blocks.
Without a row nothing changes: an undeclared reading over the margin still refuses (the
discriminating red, pinned in v2.test.floor_enrolment_margin).

The seed mirror gains the arm, reads the floor out of the model beside the margin, and its unit
test pins 303/420/500 declared, 302/250/183 within the envelope, 182 stale, 501 wrong ground.
Seed growth rostered in gunbc.enrolment_dead_band_seed_growth; the straddle is filed as the second
form of gunbc.recurring_failure_mode enrolment_dead_band_has_no_representable_standing.

Local: required_floor_runner 109/109; v2.test.floor_enrolment_margin and the seed-mirror witness
43/43.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…own; 52-warning report not reproduced) (#12733)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ound screen stills as boot evidence (#12492)

* mtcollins1 SOL collector: open silent stdin instead of /dev/zero; watch yields ObservationChannelLost on collector loss

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* sol hold: record srv1 ipmitool identity + patch-set check; model keepalive-loss exit line

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 SOL collector: silent non-EOF stdin instead of /dev/zero; stop the child when its pid cannot be published; executed stdin control

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* extdeps.bmc.megarac: record 0.32 screen-capture surfaces (no server-side on-demand still)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enrol the SOL stdin wet witnesses in the local-repo wet lane (route-gap expectation, schedule rows, exclusion row)

Floor run 36345313509 refused both identities: their first effect is
shell.Mktemp.DirWithTemplate with no mock_response, so the hermetic route
never reached a verdict. The wet lane runs them for real.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL watch: timestamped collector exit, pre-teardown snapshot, our own deactivate recorded as an attributed workflow event

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enrol the watch/teardown wet witnesses in the local-repo wet lane

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* extdeps.bmc.ipmi: import filter (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL watch: exit notices independent of the .dag watch; per-identity delivery markers set only after a successful write; unreadable /proc is its own arm; establishment by the operational banner

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: KVM still capture (per-still sessions); rework to held observer pending

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Entry-bound modeled operation realization (dry arm of HandlerBinding) + first BMC model slice

A witness frame may now carry a modeled operation realization
(v2.std.operation_realization): per-grant HandlerBinding gains ModeledRealization,
and while one is active every operation the subject issues is answered EXCLUSIVELY
by the model at its transport observation -- before the checkout-input carve-out,
the recorded fixture store, published mocks and wet dispatch, none of which is
reached. The observation feeds the SAME declared-output projection a spawned
process reaches (shell_result_projection), so production decoders run unchanged.
Bindings key on resolved OperationRef identity and are admitted before the subject
runs (Hermetic only; duplicate and unresolvable identities refuse). The dispatcher
writes the DispatchRecord route; frames return it with the final state on every
arm, plus WitnessInterrupted for a worker killed between effect and reply.

gunbc.bmc_model is the one BMC model (state + pure step/advance, time as input);
gunbc.bmc_dry_realization adapts diagnostic.ipmi.Tool ChassisStatus /
ChassisPowerControl and sleep.Delay to it using extdeps renderers beside the
production decoder.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM screen: held observer (journal, boundary events, gaps, timestamped teardown)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* bmc_model: MegaRAC web session and KVM stream rows; protocol adapter over the model

World rows (sessions, account, other KVM viewers, the KVM stream, the browser-side
canvas_readable flag), pure transitions (login, viewer count, /kvm connect, logout) and a
BmcKvmStreamClosed event fired by bmc_advance. Wire shapes in extdeps.bmc.megarac, cited to the
0.32 bundles. gunbc.bmc_megarac_web_adapter renders the model's answers for an HTTP+WS transport.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* bmc_megarac_web_adapter: transport launch and stop

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer: executing protocol controls over gunbc.bmc_model; real-still claim; exclusion rows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer: drop boot-step toolchain install (separate modeled route); real route is the boot's receipt line

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL notices as a .dag watcher process; establishment waits through pid publication; instance-bound activation receipt for adopted collectors; exit ordered against requests by instant

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Time as std.measure Second; declare the seed growth; repair the floor refusals

- Review 72007 (1): every virtual-time quantity is now a std.measure Second
  (Nat-counted, so a negative elapsed time or a backward clock has no
  constructor): OperationObserved.elapsed, OperationCall.now, advance, the
  DispatchRecord instants, BmcScheduledEvent.at and bmc_advance. The clock's
  origin and addition are .dag (virtual_clock_origin / virtual_clock_after);
  the interpreter carries the Second opaquely.
- Review 72007 (2): the seed growth is admitted by a row in
  gunbc.v1_maintenance_standing citing #12423 decision 5858742863, classified
  against all five refused classes (SeedFeatureCompletion and
  PublicSurfaceGrowth stated, not argued away), with its lane and
  execution-checkable deletion condition; the witness-frame seed receipt and a
  hand-Rust gate on the new interpreter code point at it.
- Floor: fleet_desired_merge_queue_admission_witness_test gains the
  WitnessInterrupted arm; std.effect_axes' three grant folds no longer read
  List.first() as a Grant (the Optional mismatch main already carried in that
  file, which this PR's edit brought into the judged set) -- rewritten as
  all/any folds with the same meaning.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wet protocol controls: Second-typed event time

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fleet runners: declared Playwright/Chromium toolchain, RunnerBrowserToolchainConverge mode, typed consumer seam

extdeps: Playwright 1.62.1 npm tarballs (registry SRI), Chromium/headless-shell
revision 1234 downloads and layout, install-deps chromium package set and
soname->package rows for ubuntu24.04-arm64; Node v24.21.0 linux-arm64 release
(SHASUMS256); unzip and ldd tool modules.

gunbc.runner_browser_toolchain: CDN zip digests as dated receipts, pool derived
from the floor job's runs-on labels, absolute typed location (replaces
GUNBC_KVM_STILL_TOOLCHAIN), converge (apt over the admin edge, archives as the
job user), readback (digests, versions, ldd with location, headless render).

Shared folds (operator condition: no copied realization):
gunbc.verified_archive_install now serves the Firecracker converge too;
srv3_ensure_apt generalizes the apt ensure over a binary or dpkg package subject.

Mode wired through every exhaustive fold; fleet-converge.yml regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* adapter: unique transport operation names; import filter

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* megarac: login reply variants renamed (MegaRacSessionRefused already names an attach outcome)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM journal: instants and gap lengths on std.measure Millisecond (review 72042); regenerate fleet-converge.yml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Close the three held defects; type the seed-growth admission; fix the floor import

Held review (eager-owl-205 relay; #12423 comment 5862131474):
- P1 frame composition: no witness frame opens while a modeled realization
  is active, whatever it carries (none, another realization, the same one) --
  refused before its subject runs, so a nested frame can never sit above the
  active slot and let dispatch fall through.
- P2 callback failure: a handler or advance that fails still finalizes its
  DispatchRecord as DispatchCallbackFailed { stage, cause } with the last
  established state and the unadvanced clock; the original cause propagates.
- P2 resume clock: OperationRealization carries an epoch; admission applies
  advance at it; WitnessInterrupted reports the clock at interruption, so a
  resume continues from it (modeled time does not advance while the worker is
  absent unless the supervisor declares it).
- Mode admission is the .dag decision modeled_realization_admitted_in,
  executed on Hermetic, Wet and Record by a witness.
New controls: nested none/other/same frames refused with the escaping
SensorList / checkout read never dispatched; independence after the outer
scope; throwing handler, forbidden handler effect and failing advance each
keep ordinal/identity/failure record; uninterrupted vs interrupted-at-3 with
power loss at 5. Each wall's red executed locally.

Review 72035: the prose admission row is replaced by a typed
SeedGrowthJustification (gunbc.modeled_operation_realization_seed_growth),
enrolled in seed_growth_justification_roster, naming every added hand item.

Floor: effect_axes no longer calls the unimported bare `any`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: create the probe directory before writing the page (run 36372647500 refused ENOENT); archive receipt byte_count is std.measure ByteSize (review 72047)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: installed-state probe via dpkg-query Status-Abbrev; Playwright resolved only from the install root, with a planted decoy control

- srv3_dpkg_package_installed reads dpkg-query ${db:Status-Abbrev} through a new
  Srv3DpkgStatusAbbrev token subject; only `ii` holds, so a removed-with-config
  (`rc`) package no longer reads present. Control: dpkg_installed_state_of.
- NODE_PATH dropped (it loses to a workspace node_modules). Playwright is
  required by absolute path; the readback runs node from a directory holding a
  planted decoy node_modules/playwright that throws, and the launch reports
  require.resolve, refused unless it lies under the install root.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* adapter: name the transport's consumer (gunbc#12492 wet controls) as a declared frontier

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL notice watcher publishes readiness and the boot waits for it; scaffold triggers name the whole hold/release lifecycle and the trap's watcher coordination; avoid the shadowed ends_with; boot checkout-ref claim asserts the boot arm, not other modes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dpkg installed-state probe: dpkg-query -s read by its Status: line (the ${db:Status-Abbrev} format word is refused by the fleet SSH portability guard, run 36375956111); rc/unpacked controls kept

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: launch readback matches its three lines structurally instead of the unimported bare get (floor UnimportedBareProvider, CI run 36377603306)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1_sol_notice: move a body comment above its declaration (module-item grain only)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* regenerate fleet-converge.yml after the #12434/main merge; boot_run, kvm_still, bundle witnesses pass locally

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transport scaffold: admission recorded (operator escalation msg_d5eebfff, default-approved on recommendation A); trigger names the replacing capability

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* observer: #12500 seam (working directory, playwright by absolute path); scaffold admission recorded (operator escalation msg_d5eebfff, default-approved on recommendation A); trigger names the replacing capability

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transport runs under the caller-named node binary

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transport binds ephemeral loopback ports and logs the one it got

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wet protocol controls: transport under the toolchain's node

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* enrol the KVM observer protocol controls on the local-repo wet lane (toolchain converged on the floor pool); transport on ephemeral ports under the toolchain's node

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: admit the installed tree by content before executing anything; strict readers (side-chat review 5333729136 findings 2 and 4)

Finding 2:
- the tree is admitted by a pinned sha256 of its content (every file's sha256,
  owner-executable bits, symlink targets; relative, LC_ALL=C sorted), not by
  retained archives plus a marker file
- placement stages into <tree>.staging, admits the staged tree, publishes by
  mv -T; an unadmitted stage never touches the published tree; an admitted
  tree is a no-op repeat
- the tree is named by the structural hash of the whole recipe (every
  archive's pin, url, destination, extraction, and the tree pin), so a
  digest-only pin change builds beside
- readback computes admission first and executes nothing unless admitted;
  the converge runs readback only when apt and placement held
Finding 4:
- launch: exactly three lines, the declared title, the declared 137px width,
  and require.resolve equal to the converged entry file
- ldd: every line recognized or the reading is unreadable; empty is unreadable
- versions: the whole trimmed output, exactly (chromium: chromium_version_line)

Controls: 19 pure, 8 real-execution (altered/deleted extracted code, no
candidate executed without admission with a positive control, no-op repeat
and intact tree on a refused stage).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* move the observer-start timing note out of the actuate body

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL notice watcher as a supervised sibling: token-bound readiness, a recorded (pid, starttime) the boot requires before each further BMC effect, and its exit status collected apart from the boot's; watcher terms in the step timeout; typed source reads; completion judged on the delivering pass; every exit record kept with an ordinal identity; pin a filter's element type for the new optional-arm check

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Import String from its declaring module (std.string_type) in the new/edited modules; floor AmbiguousBareNameRead on extdeps.dpkg (CI run 36381665773)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* bmc_model web: occupied-seat decision; adapter derives a transition table the transport enforces per request; transport and its lifecycle leave this change (gunbc#12492)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer: waits as Second, gap bound and operands through std.measure second_to_millisecond (review 72112); regenerate the std_measure stage0 mirror

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: cleared node environment, per-invocation scratch and staging, safe publication, decisive dpkg query, strict ldd shapes; probe scripts declared as a scaffold (side-chat review 5334435195, review 72115)

- node runs under /usr/bin/env -i -C <dir> with exactly PLAYWRIGHT_BROWSERS_PATH
  and HOME: an inherited NODE_OPTIONS preload can no longer answer the probe
- readback and placement each own a mktemp scratch; staging is a mktemp dir
  under the base (same file system, one-rename publication); an admitted tree
  is never replaced; a mismatched one is renamed aside then removed; an
  unobservable tree is refused, never rebuilt; manifest coverage stated
- dpkg-query -s keeps exit/stdout/stderr through the typed exec; installed only
  on one decodable Status line; unknown-to-dpkg distinct; anything else is
  Unobserved and the apt fold refuses rather than installing
- ldd lines accepted only in their complete declared shapes with hex addresses
- the node -e probe scripts carry a Scaffold disposition with a capability
  trigger; admission recorded exactly: msg_87357a75, DEFAULT-approved on A
- producers for both digest receipts (archive and tree) write a receipt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: the converge retires superseded trees after the current one is published and ready (rename aside, remove, record); refuses and removes nothing if the base is unlistable or the current tree is missing or named

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* megarac: state only the captured login and services fields, as typed JSON; the refusal wire is the adapter's declared choice; the transition table is emitted as JSON (review 72138)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer rework (hold on #12492): held observer waits for a /kvm frame, generations, failure-independent teardown; handoff consumes the observer's admission; typed journal reads, write-checked boundary reports, terminal-still outcome, clock step-backs and unclosed final gaps; model-derived table transport under the owned-process lifecycle, with lifecycle controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: decoy package.json emitted by extdeps.languages.json; the probe scaffold's scope names every JavaScript string it covers, including the decoy module (review 72145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* bmc_model: the web account is optional by construction, not an empty-string sentinel (review 72157); table depth is a parameter so the transition witness explores only depth 3 (floor enrolment margin)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wet controls read the JSON table fixture

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 boot step on v2.workflow.bash_emit: credential fetch, capture wiring, watcher record and EXIT trap as bash_build nodes; the readiness wait moves into the boot's .dag entry; only the [C5 background-hold] watcher start stays hand-spelled, under the SOL hold's single trigger

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wet controls on the optional-account model and the served table depth; regenerate fleet-converge.yml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* trap note above the function body

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* extdeps.dpkg: import Unit from std.types (floor AmbiguousBareNameRead, CI run 36393217274)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: retain other recipes' trees and refuse contested replacement; one declared environment for every candidate subprocess (side-chat review 5336109370)

- the converge no longer retires other recipes' trees: they are reported as
  superseded-retained (retirement outstanding) and never removed
- a mismatched tree at the recipe path is refused as ContestedTreeNotReplaced;
  publication is only `mv -T stage root` into an absent path
- node --version, package versions, chromium --version, ldd and the launch
  all run under env -i with exactly PLAYWRIGHT_BROWSERS_PATH, HOME and a fixed
  declared PATH
- the environment control appends one record per invocation and checks each

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* restore #12500's ci_spec rows dropped by the #12434 merge; regenerate fleet-converge.yml

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* adapter statuses typed as std.types HttpStatus (review 72176)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor_route_gap: typed rows for the browser toolchain real-execution controls (local-repo wet lane; hermetic Dir / RunArgv gap measured on floor run 36401239618)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* String from std.string_type, not std.types (floor AmbiguousBareNameRead)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* String from std.string_type in the new modules (floor AmbiguousBareNameRead)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* adapter: a request is encoded with its field boundaries (op + argument list) in the table, never a space-joined key (hold review 5337039757)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* hold review 5337052083: owned launch drives an unpublished child to an observed end; readback keeps gone/unreadable/unparseable apart and an unobservable release unresolved; transport readiness bound to pid and start time; one absolute observer directory; handoff and the watch consume the live standing (journal + owned process); controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* adapter: world key is the complete canonical JSON encoding of the world; exploration accumulates by Cons and tracks seen worlds in a Map (review 72199)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: rename the local capture variants (ToolchainCapturedText/ToolchainCaptureRefused); main's gunbc.spark.serving_load_probe CapturedText is a sole_constructor type and the bare name resolved to it (floor run 36415872954)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM a_local_variant_resolves_to_another_modules_homonym_type: gunbc.runner_browser_toolchain's CapturedText variant resolved to gunbc.spark.serving_load_probe's sole_constructor type (floor run 36415872954 at 6edf620); the #12500 rename is avoidance, not a repair

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor route-gap: duplicate chunk_27 renamed chunk_28

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor route-gap: drop duplicated #12500 toolchain chunk (already enrolled as chunk_27)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: the probe page is a std.markup tree serialized by extdeps.languages.html, not concatenated markup (review 72231)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: SOL release ends observed and retired for our instance (SolReleaseOutcome); foreign record distinct

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL release observed and retired for our instance; supervision at the handoff boundary after the presentation recheck; the capture watch checks its observer; the trap judges the watcher by its recorded identity, stops a survivor through the identity-checked release, and reports cleanup beside the boot and watcher results

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* owned launch: unpublished-pid cleanup keeps running/gone/unobservable apart (an unreadable stat never ends the wait or skips KILL); wet assertions read the structured request log

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate fleet-converge.yml with a binary built from the merged tree

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL release and owned check as bash_build nodes rendered by bash_emit (review 72304): no loop, function, input redirect or pattern expansion needed; [C5 background-hold] now covers only ActivateHeld and the watcher's background start; executed identity control for the release

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: exclude Playwright's in-tree DEPENDENCIES_VALIDATED write; re-admit the tree after every candidate execution (fleet-converge run 36469030109)

- run 36469030109 found srv1's tree at 89e3b24d..., not the pinned 829fefb8...;
  adding one empty DEPENDENCIES_VALIDATED to a locally extracted tree reproduces
  89e3b24d... exactly, so Playwright's host-requirements marker is the only writer
- the declared environment now sets PLAYWRIGHT_SKIP_VALIDATE_HOST_REQUIREMENTS=1
  (Playwright's own skip for that check and write); the check is covered by the
  module's ldd library readback
- the launch policy is part of the recipe, so the repaired recipe gets a new
  name and srv1's contested e4ad7f3f559ad5a8 tree stays superseded-retained
- the readback admits the tree again after every candidate has run (`after`);
  ready requires both admissions
- controls: a candidate writing inside the tree fails the post-execution
  admission; one writing only outside is admitted before and after

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_browser_toolchain: move the post-execution admission note above the function (CI parse phase refused an annotation inside a declaration body; floor run 36472004202)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* sol_hold: pass the record-absent exit code into the node builder instead of substituting it into emitted text (review 72330)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer wet controls: retained unreadable-stat discriminator at the production launch script (enrolled), and the toolchain's typed NotReady/Unresolved reason is carried into the rig instead of a generic string

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL lifecycle (review 5344336416): the trap releases the collector only when the activation receipt names it and retires its record only on a confirmed end; the owned check has three outcomes and the watcher is waited on only once it is not a running job; a publication failure escalates to KILL and records only the observed result; test values compared through quoted variables; establishment fixture lives until released

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* sol_hold stdin wet witness: pass the screen arguments mtcollins1_boot_await_capture_terminal now takes (the #12434 merge left two calls without them)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: ActivateHeld publication failure ends bounded (residue recorded, no unbounded wait); establishment claim split per case

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL release exits 2 on an unobservable identity (unreadable record or unreadable stat), like the owned check; drop the scalar settle helper for the sleep carrier inline (review 72605 on #12492)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate fleet-converge.yml for the release script's unobservable exit

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* merge #12434 at 03e197c (release exits 2 when the identity is unobservable); the trap keeps the KVM release's exit code (1 survived KILL, 2 unobservable) instead of reading non-zero as one cause; the channel-loss SOL control sleeps on a typed Second

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor: hermetic route-gap expectations for the KVM observer wet controls and the SOL channel-loss control (all held wet on run 36583319535); the relative-directory control makes its scratch directory before resolving the toolchain, so its hermetic route stops at the same no-mock effect

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL supervisor: a child that exited before its start time could be read is not a publication failure (bash reaps it asynchronously), so the ordinary wait records its exit and the client's refusal decides the cause; an unobservable collector is pending inside the establishment allowance

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* restore main's red5 wet schedule row an earlier merge dropped; regenerate fleet-converge.yml over the #12434 squash

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM observer journal vocabulary has one authority: typed KvmJournalWord rows render the script's EV/CA constants and are what the parser reads (trigger-scan-failed now parses to its own variant); witness asserts every word reaches the script and parses back (review 72962)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* retire dag/std/measure.dag#Time from the unimported-bare-provider debt roster as NotAReference: Time is a Dimension variant this file declares, not a bare reference; the parsed reader (#12609) no longer derives it, and this PR touching the file made the stale row visible

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One parser for the owned-process record: boot_run reads the SOL collector record through gunbc.owned_process owned_process_record and sol_holder_record is deleted (review 73053); owned_process_launch_script no longer cites msg_d5eebfff, which never covered it — its admission is pending the operator

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Owned-process journal lines have one source: the launch script receives owned_process_exit_prefix and the three unpublished lines as positional arguments instead of repeating their text, and the wet controls supply and assert those rows (review 73076)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* owned_process_launch_script admission: operator escalation msg_4bbcf810, default-approved on recommendation A, 2026-09-30

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…machine_intake (#12670)

* NFR burn-down: enumerate closed-coproduct wildcard arms in dag/gunbc/machine_intake

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR: delegate kept wildcard bodies to named fns (machine_intake)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR: megarac_await_enumeration delegates the decision to a step coproduct; tail call stays in the loop

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* machine_intake: bind each repeated arm result once (review 72788)

Three enumerated matches repeated one long result per variant: detach_verdict's
still-presenting DetachNotEstablished (6x), readiness_wait_outcome's
MegaRacReadinessRefused / MegaRacMediaStateUnestablished records (8x / 2x), and
presentation_still_served's PresentationNoLongerReady (5x). Each is now bound once
with a let beside its match and named by the arms, so the reason text and record
fields have one spelling. Pure data, same values, no behavior change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…puts (Outcome<Node>); tpb_accepts/tpb_refuses_with are generic over the value (#12756)

#12432 retyped tpb_type_decl_emit_twin/_generic to Outcome<ResolvedTree>, but they return
translate_type_expression_project's Outcome<Node>, so the module has not resolved on main since then.
The two readers inspect only Accepted/Rejected and the fatal reason, so they take Outcome<T>.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…efusal) (#12420)

* MQ-1 PR-2 WIP: caret symbol lowers to a symbol literal

* MQ-1 PR-2: RFMs, conservation control, symbol-literal frontier control

* symbol literal payload read without a nested Edge pattern (emitted Rust holds the label in an Rc)

* caret lowering claims: list_snoc_item from v2.std.algebra; declare the generic-ident-class flip

* parse probe: caret-site claims read one warm-shared parse (caret_tree_atom_identities) instead of re-parsing each

* caret lowering witness: plain recursion instead of fn-lambda call arguments (the witness is about carets, not the lambda frontier)

* caret lowering witness: build lists with list literals/concat (seed types a bare Cons as FreeMonoid)

* Dissolve dag_node_is_symbol_literal_atom: callers match dag_symbol_literal_name_optional directly (review 72280 on #12549)

* identity_captured_navigation: read a caret literal's name from the lexeme-stamped terminal; delete the span/source-text route and its prose note row (review 72294 on #12549)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Delete the octet-to-scalar index and its lens-slice claims with the lens span route: nothing else consumed them

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM reference_conservation_population_omits_class_stamped_terminals: the caret WHY is past tense and names its helper as deleted (review 72492)

* Merge origin/main; bla_symbol_literal_as_int returns Outcome<ResolvedTree> (the #12432 assemble type)

* roster_gate imports Finding (bare channel is off in a file that declares imports)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…solved_declarations (base for #12407) (#12629)

* v2 resolve: ResolvedTree carries the SymbolIndex resolution consulted; cut every consumer root-first

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* pick_ingested: the arrow extractor returns the arrow Node (my retype over-reached)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main (#12379 landed); #12379's new hand-built infer inputs use the named no-declarations constructor

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* plain_type_decl_lowering (new from main): its assembly helpers carry ResolvedTree and walk .root

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main; body_let_annotation (#12540's new rows) carries ResolvedTree

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: lower the where-refined head as a type so resolve binds it; ResolvedTree.resolved_declarations (neat-boar-16 ruling)

The head reached resolve as an unlowered dag_surface_qualified_name shell,
which resolve preserves unchanged as module metadata, so a declaration's
carrier was never resolved. It is now lowered through the one type-expression
lowering; resolve binds it; an undeclared carrier refuses unbound.
ResolvedTree gains resolved_declarations, the same module fold over the
resolved root, alongside symbol_index (the index resolution consulted). The
other declaration-body type positions are a declared frontier
(gunbc.recurring_failure_mode declaration_body_type_shell_preserved_unresolved).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* resolve: ResolvedTree comment states symbol_index's consumers once (no later stage reads it; #12407 reads resolved_declarations) (review 72652)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ng (#12742)

* Seed emitter: tail-call match lowering shares the #8570 Rc arm grouping

emit_rust_tco_match rendered every nested variant under an Rc field as a
match guard, so an enumerated nested arm set in a tail-recursive fold was
E0004 (gunbc.recurring_failure_mode
tail_call_match_lowering_skips_rc_arm_grouping). The grouping fold is now
one function, rc_grouped_match_arm_strs, parameterized by the arm-body
emitter; the ordinary and tail-call lowerings both call it.

Fixture tco_rc_grouped_match_emitted_rust: red (E0004) on the prior seed,
green (compiles and runs) after. Stage0 regenerated via
claim_executor --regen-round-cost until rebuild_packages=0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* File RFM tail_call_match_lowering_skips_rc_arm_grouping with its climb receipt (rung stays 1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es the floor never plans; english_emit_add and file_hold leave quarantine (they pass) (#12651)

* Quarantine: NeverRunDeclinedOutsideGate holds the ten probes the required floor never plans, per row, joined on module identity; english_emit_add leaves the quarantine

Operator-manager ruling (option B): the fold gains a fifth holder, WitnessNeverRuns, for a probe
with a gunbc.quarantine_outside_gate_decline row whose module required_gate_admits refuses. Each
row carries its own module and next-rung trigger. A row whose module the gate admits derives no
holder. english_emit_add_ingest_round_trip_holds PASSES (measured), so its admission row and its
transitional-exception entry delete and the witness stays as a regression control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Quarantine: file_hold probe leaves the quarantine; it passes on main (its dissolution, #12132, landed)

The #filter bare-provider refusal that hid its verdict was already retired by #12609. On main
785934a the probe PASSES, which its own dissolution names as the row's deletion condition.
The nine algebra_receiver probes remain red (re-measured on the same main).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* quarantine witness: load-bearing claim reads every population's holder off one live evaluation (was five live folds, 808,294 eval steps)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* quarantine witness: key both joins (788k -> 43.6k eval steps per live claim); regenerate the rung-drop projection

Chain re-derived from the budget refusal (808,294 steps, CI run 36656467027), measured with
claim_batch: the corpus census host read is 10 steps; live subject derivation was 677,277
because module_for_entry folded the whole census once per admission row, and the disposition
fold scanned each roster once per probe. Now: admission entries keyed once, the census read
over the entries' own directories (derived, never authored) in one pass; the two rosters
keyed once per population in quarantine_probe_dispositions. Both live claims 43.6k steps; all
nine claims PASS; emptying the outside-gate roster reds both live claims.

docs/design-rung-drops.md regenerated via tools.docs_projection_gate regen: english_emit_add
leaves the transitional_admission_exception population.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… paths (#12467)

* Wet witnesses assert the host relation, not a fixed runner arm (off_fleet on srv1; manager_unaskable)

fabric_capacity_standing and spark_pair_serving_apply wet claims now read the
host's layout resolution and assert: store undeclared => every group refused
naming the undeclared store; store declared => no such refusal. manager_unaskable's
manager-present arm asserts the termination and lifecycle routes agree (a live
manager answers not-found for the all-f unit, which frees and ends; the old arm
asserted nothing frees and was red on every manager host). Files rfm row
wet_witness_keyed_to_the_runner_not_its_subject with the census.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor_route_gap: enrol the two renamed fleet-relation wet witnesses (RunArgv, no mock_response)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 census wet witness: per-run Mktemp dir replaces host-global /tmp counter and dd marker

The disagreeing stub kept its counter at /tmp/gunbc-wl-counter. srv1 runs several
runner instances on one host sharing /tmp, and the pre-clear (an unused let) never
ran, so a counter left by another runner's user was readable but not writable:
both passes printed the same digest, the disagreeing case agreed, and the stage
emitted the token (red on srv1 by runner assignment). Both claims now own a
DirWithTemplate directory and remove it; floor_route_gap first-operation updated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rfm wet_witness_keyed_to_the_runner_not_its_subject: sibling cause (shared host-global paths), repaired by #12467

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…12734)

* MQ PR1: model map-literal introduction (graph of a finitely supported function)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Map introduction model: site moved to resolve_construct_walk (#12711 revision)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Map introduction model: fold of insert over empty in v2.std.map_introduction; pre-fold duplicate check by declared key equality; resolve placement; consumers and controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Map introduction: honest equality coverage; add algebra_profile_equality_extensional to the keys/hashing conformance row (DESIGN projection updated)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* design_argument: import its std.syllogism names (unimported-bare-provider gate)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire design_argument's three unimported-provider debt rows as ImportsFixed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the '=' with a typed reason (#12686)

* v2 parse: grammar Expect label; fn '=' with no expression refuses with a located typed reason

std.grammar gains Expect { element, reason }: a label, never a cut. It matches and captures
exactly what its element does in every direction; when the element fails at the furthest
position the parse reached, the refusal names the reason at the token the element was to
follow. Ties at one position go to the expectation recorded first in parse order. Reasons
come from a declared GrammarRoot.expectations roster; preparation refuses undeclared and
unconsumed reasons.

The dag fn_decl row wraps the expression after '=' with
^parse_fn_expression_body_missing_after_eq, and empty_eq_fn_decl_refuses now asserts that
exact fatal reason at the '=' span (43..44).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Import LiveTreeDisposition in the two touched claim files (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* parse_token_before: typed step so both arms are Optional<Token>

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire the two SubstrateInputsOnly bare-provider debt rows as ImportsFixed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor resolve fixes: explicit imports in grammar_expect_test; drop a mis-added arg; declared text unfold in dag_arrow_lambda witness

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Expect reason: typed by a closed parse-stage vocabulary; drop the hand-kept roster

Review 72912: GrammarRoot.expectations was a hand copy of the reasons the Expect nodes already
carry, checked against them after the fact (DESIGN §5). It is deleted with both comparison
checks, and every grammar root is back to its main shape. The reason field is now typed by
v2.std.parse_refusal_reason ParseRefusalReason, the parse stage's closed refusal-reason
coproduct, so a misspelled reason fails to typecheck. Members: FnExpressionBodyMissingAfterEq
and DataValueMissingAfterEq; the data_decl '= expr' row carries the second, and its own claim
asserts the reason and the '=' span.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… cost, step 4 / option C) (#12716)

* Closure front end reads its lexical artifact from pool_acquire

The via-index parse and the parse-cache miss arm re-lexed every closure file the pool
census had already lexed under the same spelling. Both now ask pool_acquire. Adds the
per-term attribution probe and a live identity differential (pooled vs fresh artifact
over the whole pool).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One heads reading per file: the pool census projects it instead of re-parsing

pool_acquire holds one file-local heads reading (empty intern table, occurrence
ordinals from zero). module_path_index reads it as-is; the pool census maps it into
its threaded intern/occurrence space by a total projection (occurrence ids offset by
the entry base, idents relabeled through the file's string list) instead of parsing
the file a second time. Anything the parser does not produce refuses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Heads projection: exhaustive destructuring, no catch-all arms

Every Node field and every ExprData / MatchPattern / InferredNode arm is named with
no '..' or wildcard, so a field or variant added later fails to compile at the walker
instead of passing through with file-local ids (review 72735).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Tree census upgrades the memoized raw census instead of rebuilding it

build_symbol_index_census_nodes is census_with_resolved_fn_sigs over the raw census;
closure_name_census(index, Some(root)) already builds and memoizes exactly that raw
census over the same nodes and source indices. tree_bare_census_for_root now upgrades
the memoized value. Adds a live whole-SymbolIndex differential per root.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Heads projection: name Node.declaration (#12612); the parser never writes it, so Some refuses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: tree census upgrades only the bare fill (seed regen pending)

* Regenerate v1_compiler_infer.rs from 04_infer.dag (bare-fill split)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, conserved by value) (#12759)

* MQ: a string literal carries its decoded value (parse decode by class, conserved by value)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Expose the string decode as dag_string_literal_decoded_text (one reader for the escape table)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emit fixes: no annotation inside a body; string payload read through an edge-target reader (int/caret shape)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Conservation: a string literal the parse left without its value is a typed unmeasured row; lowering reads a string literal through one route

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Move the variant's annotation above its declaration

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Decode the dag language's full escape vocabulary (\0 \r \xHH \u{..}), as the v1 tokenizer does; census found three modules the six-row decode refused

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Test sources: escape the braces of \u{..} (an unescaped brace in a .dag string opens interpolation)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ut over to E1 declared signatures (#12625)

* Program P: one Arrow encoding -- E2 positional-types Arrow producers cut over to E1 declared signatures

Every producer of the positional-types Arrow [T1..Tn, U] now builds the
one encoding (named-binder domain + declared-order edge) through
v2.std.arrow_signature declared_signature, with type-only signatures
going through the new anonymous_signature_arrow (minted anonymous
binders). The v1 host seam export_signature_facts marshals a named
domain and v2.std.decl_index export_signature_declared_facts lifts it
through declared_signature. The algebra's structure signatures move out
of v2.std.algebra into v2.std.algebra_structure_signature (above
arrow_signature; no re-export). translate reads Arrow inputs through
arrow_declared_parameter_order; the produced-decl and realized-closure
'domain binding no names' arms are deleted.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* translate: build the Arrow split outside the Present match arm (CI: field 'output' not found in type 'Present')

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* firewall test: optional_present in the lookup fold so both if branches are Optional<DeclFact>

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* export_signature_declared_arrow: fail-closed decoder -- Arrow connective, exactly two Positional outer edges; refusal controls for wrong connective and extra Named outer edge

Addresses GitHub review 5356388749 on #12625.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM arrow_domain_meaning_is_not_carried_on_the_node: re-cite algebra_binary_fn_node at v2.std.algebra_structure_signature; record Program P as holding the trigger (rung stays 1 until A4's wall)

The declarations phase dequeued #12625 with CITED-DECLARATION-ABSENT: the row cited
v2.std.algebra algebra_binary_fn_node, which P moved. The row is not discharged --
P satisfies its trigger, but the climb (well-formedness refusing a Named-binder domain
with no order edge) is A4's -- so it is re-cited, not retired.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One assembler for signature Arrows: declared_signature_arrow in v2.std.arrow_signature; decl_index uses it and v2.std.node all_edges_named / all_edges_positional (review 73121)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…refuses instead of binding as a catch-all (#12755)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…f_expr (#12754)

body_lower_if_else_capture_optional deep-searched the else part for any
if_expr, so `else { match k { .. B => if c {..} else {..} } }` lowered to the
nested if alone, dropping the scrutinee, the other arms and the patterns.
It now reads the else part's first production shell. RFM
else_arm_lowered_as_an_if_nested_inside_it; found by #12713's census.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the last NameRoleNotYetRead row (#12757)

* Transport kind is a closed choice of literal terminals; delete occurrence_role's last NameRoleNotYetRead row

dag_grammar_transport_expr takes rest | shell | file | local as literal terminals (the
dag_grammar_op_modifier_expr precedent), so the production holds no name terminal and needs no role
row; an unknown kind refuses at its own token instead of being accepted as an identifier.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transport kind test: one claim per kind (the four-parse conjunction exceeded the new-witness eval-step budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…th directions) (#12767)

* KVM observer journal: the renderer beside its parser (one grammar, both directions)

gunbc.machine_intake_mtcollins1_kvm_still kvm_journal_line renders the line kvm_journal_event parses,
over the same KvmJournalWord rows, in the observer script's layout and key order; values are written as
the parser returns them, and keys the parser does not read (url, started_ms, bytes) are not written.
Its consumer is the boot matrix's dry observer in gunbc#12533, which must write the journal the boot
now gates its handoff on without a second spelling of the line.

Controls: every event arm and every refusal and acquisition cause round-trips to a structurally equal
event (a renderer that dropped gen was measured to fail it; a text-only comparison stayed green);
observer-format lines re-render byte for byte (a key-order swap fails it); a malformed line is
Unparsed and renders verbatim.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM journal: one layout row per event for both directions; the renderer refuses what no line can carry (review 73156)

Each event word's key names and order are now one KvmJournalLayout row (and one KvmRefusalLayout per
refusal cause); kvm_journal_event reads its fields through those rows and kvm_journal_line writes
through the same rows, so no key is spelled twice. The renderer returns KvmJournalRendered only when
its own line parses back to a structurally equal event, and KvmJournalRenderRefused otherwise: a
login detail that is not http <status>, an empty no-frame detail, an other cause spelled like a
declared one, a word field holding a space or " gen=" are refused, never written as a line that
reads as another event. Free text the grammar can carry (a final detail holding " gen=") still
renders, pinned so the refusal is not over-broad. The consumer frontier (gunbc#12533's dry observer)
is stated on the declaration. Witness module 19/19.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ip, broker unit carries its release, slice from stage 3 (#12747)

* Approval broker cutover stage 4: front door as a deploy member, posture flip, broker unit carries its release, slice sized from stage 3

The approvals app's enrolment 404 re-derived (DESIGN 6b): the broker's
public route was already modeled (approval_broker_endpoint's /approve and
/approvals front door, which covers /approve/device/*), but the cutover
posture kept it uninstalled, the stage-4 argv had no live_deploy consumer,
and under RoadmapServesAndWrites the broker refuses every write (a bare
mapping would have turned 404 into 503). Operator ruled: advance the cutover.

- live_deploy.spec: owned member ApprovalBrokerFrontDoor, present exactly when
  approval_front_door_mounts_installed(); emit installs/removes the cutover's
  own two endpoints (enable/off from one value).
- approval_cutover_posture -> BrokerServesAndWrites.
- live_deploy.emit: the broker unit write now carries its release install; the
  2026-09-29 dashboard_deploy rollback wrote a unit naming a release only the
  dark install populates (status=203/EXEC since 16:57).
- slice_bounds: broker slice 16 GiB max / 14 GiB high from the stage-3
  readings (max memory.peak 11,332,878,336 B), superseding the 2026-09-21
  10/9 GiB ruling under which the broker could not finish booting.
- serve witness derives writer/non-writer from the live authority.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Broker ownership: one comparison, read by the spec predicate and the front-door member (review 73068)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witnesses: match privileged argv words (quoted per word), read the decision writer half at the gate the route consults (floor run 36669289190)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witnesses compare derived tailscale command bytes; production may scope exactly the broker's front-door mounts (floor run 36672903361)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rescope the production root-mount claim to its own tailscale member; regenerate gunbc-ghrunner.sudoers (floor/generated run 36683351599)

production_apply_serves_its_own_endpoint_and_scopes_no_path read the whole
apply; with the broker's front-door mounts in it the claim cost 98,345 eval
steps against the 72,300 budget. It now reads the dashboard's own
TailscaleServeMapping member; the broker mounts are pinned by
approval_broker_front_door_member_witness.

provisioning/srv1/gunbc-ghrunner.sudoers is the generator's own projection
(heal candidate blob 2e734ef from run 36683351599): main's #12689 dropped the
srv1-10 runner slot from the model and the committed projection still granted
it. Not a change of this PR's; the CI merge ref surfaced it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…escalation d0-group-a-ds41-2026-09-30) while the store walls are unfinished (#12744)

Operator-ruled 2026-09-30 (option A, relayed by proud-deer-538).
gunbc.rung_drop.d0_store_walls_single_lifecycle declares the drop (previous
MechanicallyPreventable, temporary Mitigatable, replacement staged, one
lifecycle including its reruns, restoration: both walls live on srv1).
d0_store_write_wall_standing now takes the group and escalation id: both
walls finished admits every lifecycle; otherwise only the declared one is
admitted and everything else refuses as before. Witnesses: the declared
lifecycle is admitted on the real row; a second consent id, group-b and a
retired drop refuse; the walls' own refusal still answers for group-b.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… — census + proposal, no cut (#12473)

* EdgeLabel coproduct: model proposal + mechanical census (step 1, no cut)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: drop transcribed census counts; the step-2 deletion is the census (DESIGN §3, §6)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: remove remaining transcribed counts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: remove residual scan counts; cite symbols (review 71986)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: record neat-boar-16 ruling (A); name consumer of each new declaration (§3c)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: headline the ruling as settled; note namespace-spine question

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: loop domain + Loop head-reference edges are Core markers; roster consistency with #12548 / MQ-5 S3

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: name loop_edge_role as the Loop-label reader the cut converts

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* EdgeLabel model: name ^loop_realized_declaration_edge (LoopRealizedDeclaration)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t the tools' own walls (#12751)

* nbd-proxy serve: raw argv builders dissolve into typed ArgvCommands at the tools' own walls

The serve half of the BMC virtual-media estate, adjacent to #12579 (the
attach half). The hand-authored List<String> builders in
extdeps.bmc.webui.nbd_proxy_serve (bmcweb_session_login_curl_args/_argv,
nbd_proxy_serve_nbdkit_argv, nbd_proxy_serve_websocat_argv) and their
joined-surface readers retire; the legs are described commands minted at
their tools' own extdeps modules and admitted at the argv_command wall:

- extdeps.tools.nbdkit: nbdkit_program() (the CliTool row's name derives
  from it, the curl pattern) + nbdkit_readonly_file_serve_command
- extdeps.tools.websocat: websocat_program() (identity derives from the
  CliTool row's own install_path) + websocat_nbd_proxy_bridge_command,
  with websocat_header_argv_word_dissolution_trigger carrying the
  credential_argv_exposure instance-3 obligation (the BMCWEB session
  token in the --header= word; measured latent, repair operator-ruled)
- extdeps.tools.curl: curl_bmcweb_session_login_command

Realization sites read the commands back through argv_words; the word
lists are byte-identical, so no realization bytes change. The retired
scaffold dissolves-to (#8582) and retires to a Terminal disposition
naming both halves of its own condition; the joined-string supervision
oracle retires because the transient-unit realization offers no
shell-statement surface at all -- the 2026-07-14 no-trap/&/$! ruling
holds by construction, not by search. Witnesses assert at field grain
(program against the cited identity row, words by membership), with the
token-placement witness pinned word-for-word so the repair cannot land
silently. Deliberately unchanged: no --fail on the login curl (fail-open
shape now visible at the tool, behavior change out of scope) and the
quoting inside the --header= word.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witness notes: move body-interior // blocks above their declarations

CI floor (run 36669524121, job 109741313320) refused the tree in the parse
phase: "source annotation sits inside a declaration body. Only module-item
grain is modeled; move it above the declaration it describes." DESIGN.md 4c
is the law: the initial .dag realization admits only standalone leading //
blocks attached to module-scope declarations; trailing, body, unattached,
and block-comment forms refuse until separately modeled.

Five prose blocks I had authored inside witness/fn bodies move to sit above
the declarations they describe; the text is kept (two "this test/control"
self-references reworded to "this witness") and the virtual-media block is
merged into its fn's existing module-grain note. No semantic change: the
substrate models annotations at module-item grain only, so moving them
cannot alter any semantic occurrence, resolution result, or graph hash.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* srv3_os_install_actuate: pin Filesystem to filesystem_io's service

CI floor (run 36673340996) got past parse and through witness planning, then
refused at claim scope: AmbiguousBareNameRead, sites=1 — `Filesystem` is read
bare by gunbc.srv3_os_install_actuate while two transitively-reached modules
declare the name (extdeps.filesystem.filesystem_io as a service, std.resources
as a capability resource). The module has no imports; its login-body write is
`Filesystem.Write(path:, content:)` consumed via `.success`/`.error`, which is
filesystem_io's service Write shape exactly (std.resources' capability write
returns {written} and has no Write constructor). Import naming the declaring
module settles the ambiguity the same way five other modules already do.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* srv3_os_install_actuate: import every provider name it reads bare

Round 3 (run 36679499372) taught the other half of the rule: declaring any
import turns a module's bare-name channel off entirely, so the single
Filesystem pin left 22 provider names unrostered (110 refusal lines = 22
names x 5 folds), including type and constructor reads. The gate derives
pairs with the loader's own provider selection and refuses a pair iff the
declarer lies outside the file's import closure (cli_run.rs
unimported_bare_providers), so importing each refused name's declaring
module is exactly the repair: std.process, filesystem_io (the Filesystem
pin, kept), gunbc.auth.access_token_source, gunbc.nbd_proxy_virtual_media_install,
gunbc.seeded_media_publish... spelled from the refusal rows themselves.
Reads whose declarers were already inside the previous closure (ExitSuccess,
ActuatorMechanismRefused, the std type annotations) stay bare by the same
rule and are not refused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Placement pin: carry the token word-by-word, not word-equality

Round 4 (run 36686558922) cleared every gate and reached witness execution;
one rewritten witness returned false:
witness_srv3_nbd_proxy_websocat_argv_materializes_token_not_shell_env_ref.
The surface law this helper translates (origin/main) is two SUBSTRING facts
over the joined argv: the materialized token appears (it rides inside the
--header word, never as a standalone word), and the $BMCWEB_SESSION_TOKEN
spelling appears nowhere. My word-grain rewrite had strengthened the first
to word equality -- false for an embedded token -- and weakened the second
to word equality, which a word merely containing the env ref would slip
past. Both conjuncts now carry the original law word-by-word via
string_contains, which is a language builtin, so the import gate is
untouched. Inversion direction unchanged: when the token leaves argv, the
first conjunct flips false and this witness refuses, as the census requires.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…renceProjected (#12604)

* Model: a lowering closes its image; derived nodes mint OccurrenceProjected (PR1 of 2)

Revises the v2.std.node lowering rule: an occurrence names one node, so a
lowering's image keeps OccurrenceMinted on the root the builder names and
projects every other member. Adds the id source (derive_projected_occurrence,
N + cantor(source, k) over one OccurrenceAllocatorSnapshot, bound as a typed
refusal) and the idempotent image pass project_image_occurrences. Producers
migrate, and the duplicate-minted-id admission wall lands, in the cut (PR2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 72543: one Projected arm, two producers told apart by cause scope; seal the allocator

- std.occurrence_identity documents the arm's contract ("a real occurrence of
  the containing graph with a cause and no author"). A projector insertion
  and a same-graph lowering member are told apart by
  scoped_occurrence_ref_in_scope on the cause.
- legacy_binding_delta insertion_provenance_entry returns NotAnInsertion for
  a same-scope cause.
- occurrence_allocator_seal returns the snapshot plus a continuation
  allocator advanced past the derived range (rung stated as mitigatable).
- New controls; each is paired with a mutation that went red locally.
- Regenerated stage0 mirror std_occurrence_identity.rs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Move the same-scope note above insertion_provenance_entry (DESIGN 4c: module-item grain only)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* Delete the hosted rust-unit-tests lane from the compiler gate

Operator ruling 2026-09-29: stop relying on GitHub-hosted runners. The
rust-unit-tests job ran `cargo test --release -p v1-compiler --lib` on every
pull request and merge_group as a non-blocking measurement on ubuntu-24.04-arm.
Its continue_on_error step reported success on every run while two tests are
red on main (cli_run::nfr_tests::nfr_roster_receipt and
cli_run::node_frontier_plumbing_controls::frozen_path_deferral_roster_carries_no_stale_rows),
so it bought an unreadable verdict with about a third of the hosted pool, which
the Free plan caps at 20 concurrent jobs and which the heal publisher shares.

The job, its lane row and its capability-closure clause leave
gunbc.compiler_gate_workflow; witnesses.yml and DESIGN.md are regenerated.
gunbc.rung_drop rust_unit_tests_off_the_merge_path stays Standing: the deletion
returns CI to exactly the state it declares, and its restoration trigger is
unchanged. The tests come back as a blocking fleet lane once the population is
green.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md from the amended rung drop

The drop row's authored text gained the 2026-09-29 deletion note; its
projection was not regenerated, which the generated lane caught.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot and others added 6 commits October 2, 2026 05:58
* rung_drop infer_facts first-wins: route back is site keying (B); population adds the childless-Conj codomain claims

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs: regenerate design-rung-drops projection

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung_drop infer facts: drop product_introduction (calm-hawk-793: roster-membership cause, not the key); codomain row stated as attributed, not confirmed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung_drop infer facts: drop the codomain row too (calm-hawk-793: its tree has one childless Conj, roster cause); trigger names the kc two-site specimen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…l rsync source, image distribution off the executor relay (#12941)

* Fabric peer blob transfer: one sha256-keyed Spark file handler, a rail rsync source, and image distribution off the executor relay

The runtime image distribution relayed a ~30 GB docker-save tar source -> srv1 -> target by scp,
both legs on the Sparks' wireless management link. On 2026-10-01 a band-steering roam on srv5
broke the upload mid-transfer (fleet-converge run 36867302511, "client_loop: send disconnect:
Broken pipe") and every re-run restarted from zero, while the 50 Gb/s fabric rail between the two
Sparks sat idle.

- gunbc.spark.spark_file_blob: the gunbc.artifact_acquisition handler for one sha256-keyed file on
  a Spark (probe, detached supervised unit, reattach, staged digest, publish by rename), extracted
  from gunbc.spark.v41_checkpoint_materialize, which now calls it. A staged partial is kept for a
  resuming source; exit statuses are classified by the program that produced them.
- gunbc.spark.fabric_blob_peer: a blob root per Spark named by digest, a read-only rsync daemon on
  the holder bound to its rail address only, and the rsync pull as an acquisition source.
- extdeps.tools.rsync (new) and extdeps.tools.curl: daemon config, argv shapes, network exit codes.
- gunbc.spark.vllm_runtime_image_build: the scp relay is deleted. The source saves into its blob
  root, reads the tar's sha256, publishes and serves it; each target pulls over the rail through the
  generic handler, loads, and is held to the configuration digest.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Create the fabric blob root before reading its free space (first wet run refused at df on an absent root)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Place the any import above the multi-line import block

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire the stale v41_checkpoint_materialize get debt row (handler moved to gunbc.spark.spark_file_blob)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the persistent carrier (lexer quadratic, part i) (#12944)

* WIP list_at: list_at_optional as the total projection of the get primitive (seed arm, emitter row, roster rows); stage0 mirrors not yet regenerated

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* list_at: stage0 mirrors (projection, emitter, runtime, dispatch, v1_rt), seed equivalence witness, egress get row qualified

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Projection authority witness: list_nth is the no-surface specimen; list_at_optional projects get

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1_rt.rs: regenerated bytes for list_get_optional

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Generated seed files: three-way merge of the list_at branch and main (rt registry keeps both get and observed_thread_cpu_nanos)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Surface membership reads each surface's symbols, not the full census rows

primitive_surface_carries_symbol built the whole five-surface census, resolving every
row's primitive identity and authority reference, only to ask whether a name appears.
Each surface now has one symbols list; the census rows map over it and the membership
check reads it directly, so a name has one derivation and the question costs names only.
The no-surface claim w_a_declaration_on_no_surface_answers_classified_no_primitive goes
from 182,972 to 7,791 eval steps (claim_batch --wet, same runner, same head).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(D) (#12610)

* NFR: typed, diff-scoped non-fold-residue check on the required floor (D)

The non-fold-residue census keyed on a PARAMETER's written type, so a wildcard over a
closed coproduct reached through a local binding, a field or a call was invisible.
This adds a typed walk that reads each match's INFERRED scrutinee type through the
checker's existing constructor_roster_for (no new v1 04_* analysis), and runs it on the
required floor, diff-scoped, over the graph strict preparation already typed: the
touched modules plus the planned interface consumers. No second compile, no new job.
A divergence refuses as cause=NonFoldResidueRosterDiverged.

- cli_run/non_fold_residue.rs: typed_fallback_arm_walk, non_fold_residue_diff_verdict,
  fixture controls (param/local/field red; open-domain/open-local/total-fold green;
  diff scope), and the ignored whole-corpus census the widened roster is derived from.
- required_floor_runner.rs: phase non-fold-residue-diff after strict-preparation.
- recurring_failure_mode non_fold_residue_diff_scope_misses_an_untouched_flip: the
  declared residual (untouched module whose scrutinee flips), trigger = the v2 lens
  (#5364) reads typed scrutinees corpus-wide.

The parameter-keyed text scan and its --lib nfr_roster_receipt stay until this check
covers the merge path together with the census-derived roster.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR census: state the measured cost (srv1, 36.5 min, 39.9 GB peak), not the 32 GB estimate

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR D: undetermined scrutinees refuse unless rostered; census tags sites in blocked modules

An in-scope wildcard whose scrutinee carries no resolved inferred type no longer
passes as open: the floor refuses it unless the site has its own roster row.
The whole-corpus census tags a site in a module with a blocking diagnostic
(unrostered-in-blocked-module, blocked-module-typed-partially) instead of
listing it as ordinary, so no row is minted from partial typing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR D: a roster-row edit brings its subject into the typed scope (REQUEST_CHANGES on #12610)

D scoped the roster comparison to touched modules plus planned interface consumers, so an
edit to the roster alone never reached the subjects its rows name. Three holes followed:
a row added for a stale or nonexistent site, a row deleted for a live site, and a deleted
subject module whose row stayed -- each passing unexamined, and the joint landing is exactly
D plus roster edits.

- When the diff touches gunbc.non_fold_residue, the roster is read at the floor's own diff
  base (new v2.workflow.floor_diff_observe floor_run_base_file_read: listing + show effects,
  absent-at-base its own arm, a failed read refuses) and compared with head. Every added or
  deleted row's subject module becomes a preparation seed and joins D's scope, so it is typed
  and judged. An unreadable base roster refuses the floor (NonFoldResidueRosterBaseUnreadable).
- A roster row whose subject file does not exist is stale on every run.
- A changed row's subject module that the prepared graph did not type REFUSES
  (row_subjects_untyped), rather than being reported.
- Red controls: row-only addition of a stale site, row-only deletion of a live site, deleted
  subject with its row retained (with a positive control), untyped row subject.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR D: judge each changed roster row by its exact subject path (REQUEST_CHANGES on #12610)

The row-subject join dropped a subject whose existing path was unreadable or declared no
module, and an existing path outside the walk's coverage (a non-module file, an excluded
`_test.dag`, a same-named module at another path) was never judged. Each changed row's
subject is now carried by its EXACT path with a typed disposition
(NonFoldResidueRowSubject): Missing -> stale via the roster diff's existence arm;
Unreadable / NoModuleDeclaration -> refuse; Module -> seeded, then required to appear by
that same path, with that module, among the walk's covered paths, or refuse.

Controls drive the real classify-then-judge route: existing non-module path (Cargo.toml),
unreadable path and excluded test path refuse; a covered path is judged, and a missing
path is left to the stale arm.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor_base_file_read: pass the path without an owned copy (clippy unnecessary_to_owned)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed where an Optional call argument is refused (#12633)

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
list_at_optional's emitted realization (v1_rt::list_get_optional) has no executing
emit-build-run claim. #12944 merged before the operator decided on extending the
identity-cast scaffold to carry that fixture (msg_7bdba37a), so the gap is declared here
with its dissolution trigger instead of being left silent.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 2, 2026
…machine intake)

These 22 sites landed after the last roster-maintenance commit and were
never rostered, so the corpus-read ratchet (nfr_roster_receipt, which
runs on no CI path) never saw them. Totalling them here rather than
rostering them.

Skipped (mid-flight in open PRs, listed for follow-up):
- src/v2/extdeps/languages/swift/rows.dag: swl_decl_has_body, swl_decl_is_import, swl_stmt_has_block (PRs #12942, #12799)
- src/v2/extdeps/languages/dag.dag::dag_emit_text_step (PRs #12961, #12942, #12799)
- src/v2/compiler/00_compile.dag: native_demand_collect_rows, native_demand_settled_label (PRs #12942, #12799)
- dag/gunbc/approve_ios_swift_wire.dag::aw_sum (PR #12951)
- dag/gunbc/bmc_megarac_web_transport.dag::megarac_web_transport_readiness (PRs #12951, #12691)
- dag/gunbc/bmc_model.dag::bmc_event_eq (PR #12951)
briansrls and others added 14 commits October 2, 2026 13:13
…icates as declarations) (#12969)

* v2: ground where-refinement predicates as declarations; resolve binds them

Each decidable where predicate is a total Bool declaration (std.types string_non_empty,
gt_zero, range; std.content_hash lower_hex_16/40/64/128) and brand a declared marker fn.
Lowering carries every predicate of a clause, with its arguments, at its own occurrence;
v2 resolve binds each by ordinary name lookup and refuses an unbound one as
resolve_reason_where_predicate_unbound. non_empty is respelled string_non_empty corpus-wide
(v1 parse/infer tables + stage0 regen) and the gate's non_empty_string consolidates onto it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: home the Char classifier in std.unicode.char_class; fix stale predicate homes; import filter

std.string_type pulled into the compiler closure broke self-host emission (string_lex_compare
E0308); the classifier moves to its own Unicode module instead. Comments naming std.integer as
the home of gt_zero/range now name std.types (review 71649). filesystem_io imports the bare
filter the floor refused once the file was touched.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor roster: retire filter rows discharged by filesystem_io's filter import

filesystem_io now imports v2.std.algebra filter, so every file importing filesystem_io
no longer carries its bare filter pair; the floor refused the touched one as RosterStale.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor roster: retire v2.std.algebra rows reached through filesystem_io

The import closure is module-grained: importing filesystem_io now reaches every
v2.std.algebra declaration, so skip/any/length rows on its importers are discharged too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* where predicates: execute each declaration against the seed's probe values; stop overclaiming one authority

Until v1's tables can consult a declaration (feature:where-refinement-predicate-declaration-authority),
the declaration and the table are two representations. The vocabulary witness now executes each
grounded declaration on the probe value the compiler is observed to refuse, with boundary controls,
one claim per predicate; the comments state the fork instead of claiming one authority (review 71681).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* stage0: restore main's v1_rt.rs (a stale-binary regen had reverted it)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* filesystem_io: drop the duplicate filter import (main added the same one; review 71725)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* MQ-1 PR-2 WIP: caret symbol lowers to a symbol literal

* MQ-1 PR-2: RFMs, conservation control, symbol-literal frontier control

* symbol literal payload read without a nested Edge pattern (emitted Rust holds the label in an Rc)

* caret lowering claims: list_snoc_item from v2.std.algebra; declare the generic-ident-class flip

* parse probe: caret-site claims read one warm-shared parse (caret_tree_atom_identities) instead of re-parsing each

* caret lowering witness: plain recursion instead of fn-lambda call arguments (the witness is about carets, not the lambda frontier)

* caret lowering witness: build lists with list literals/concat (seed types a bare Cons as FreeMonoid)

* reference_conservation_admission: drop the braces my merge resolution orphaned (floor/generated: unparseable at byte 6129)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* namecheap witnesses: rename the test helper response -> namecheap_api_response

#12421 declared a top-level fn response. The bare-reference scanner reads each
service operation's response { ... } block (42 files) as a reference to it, so
every PR touching one of those files is refused UnimportedBareProvider. The
scanner's missing keyword awareness is reported as its own finding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: a module's own `type Int` / `type Bool` shadows the kernel spelling instead of being captured

Body lowering rewrote every type atom spelled Int or Bool to the kernel binding before any scope
existed. A module that declared its own `type Int = | Mine` and wrote `let y: Int = 1` therefore
had its annotation replaced by the kernel Int, and infer judged the let matched.

The spelling table moves to its language authority (v2.extdeps.languages.dag
dag_kernel_type_binding_optional), and resolve_atom consults it only after the scope walk and the
symbol index. A hit declared in the referencing module binds that declaration. Imported, foreign,
ambiguous and unbound kernel spellings keep the kernel binding, unchanged.

Claims (v2.test.claim.body_let_annotation, 5c): the module-declared Int and Bool lets refuse at the
annotation, and the annotation is asserted not to be the kernel binding. An undeclared Int/Bool
still binds the kernel type. Both shadow rows are red on main 9ce0394 and green here.
The rfm row records the residual and its trigger.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: an imported user Int refuses instead of binding the kernel Int

Resolve now reads a kernel spelling by the declaration a door selected.
v2.extdeps.languages.dag dag_kernel_type_declaration_binding_optional lists the declarations a
kernel spelling denotes. A hit on one of them takes the canonical binding, and the module's own
declaration shadows it. Any other declaration, reached through an import or another module,
refuses with resolve_reason_kernel_type_spelling_names_a_foreign_declaration. Unbound and
ambiguous names keep the spelling fallback.

Third RED: bla_imported_user_int_refuses_rather_than_binding_the_kernel_int (a two-module
fixture, p imports q's `type Int = | Mine`). All three REDs are F on main and T here, and the
controls are T on both. The new specimens are enrolled in floor_pure_producer_share. The rfm row now
states rung = refused, with the trigger at capability grain: declaration-keyed binding across every
door.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: an ambiguous kernel spelling refuses unless every candidate is a kernel declaration

An ambiguous kernel spelling now binds the kernel type only when every candidate is a kernel
declaration of it: v2.std.integer Int beside std.integer Int is one kernel type. Otherwise it
refuses with the ordinary resolve_reason_ambiguous_symbol instead of defaulting to the kernel. An
unbound name keeps the kernel binding, which is the correct answer when no declaration is in scope.

New claims:
- RED bla_ambiguous_imported_int_refuses_rather_than_defaulting_to_the_kernel (p imports Int from
  q and r). F on main, T here.
- Control bla_ambiguous_kernel_declarations_bind_the_kernel_type. T on both.

The multi-module specimens now share one helper, bla_assemble_with_peers. The rfm residual is now
only the kernel-declaration path list. Its trigger is a mark on the kernel declarations themselves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wip: infer symbol-literal arm (DagCanonicalSymbolLiteral typed as v2.std.node Symbol)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* test.claim.parse_test_fn_decl_return_clause: lowering carries the authored return-type spelling

Three floor blockers on fa8c596. These claims read the positional return clause from body lowering
and expected the kernel binding (dag_binding_type_int, bool_node_symbol). Lowering used to produce
that binding by rewriting the spelling. That rewrite now happens in v2.compiler.resolve, after the
scope walk, so lowering carries `Int` and `Bool` as written, as the generic row already reads `T`.
Arm 1 still discriminates: the return type is Bool, not the parameter's Int.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag_canonical_literal_from_node: match the symbol-literal optional once

review 72280: the symbol arm tested dag_node_is_symbol_literal_atom and then recomputed
dag_symbol_literal_name_optional. That was the same optional twice, and the recomputation needed an
arm the predicate had already ruled out. The decision now matches the optional once. The remaining
Absent arm is a name payload with no atom identity, which is reachable.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Dissolve dag_node_is_symbol_literal_atom: callers match dag_symbol_literal_name_optional directly (review 72280 on #12549)

* identity_captured_navigation: read a caret literal's name from the lexeme-stamped terminal; delete the span/source-text route and its prose note row (review 72294 on #12549)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Delete the octet-to-scalar index and its lens-slice claims with the lens span route: nothing else consumed them

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* caret_symbol_has_no_lowered_form: the receipt states the literal's type as this PR derives it

review 72301: the receipt still said the symbol literal's type stays on the GroundingNotDerived
frontier. The arm in this PR makes that false. It now names the derivation route
(DagCanonicalSymbolLiteral, infer_literal_type_binding, v2.std.node symbol_type_node) and the two
body_let_annotation claims that execute it. Census trigger (a) stays open and the receipt says why:
it names the source checker v1.compiler.types, which still types LitSymbol as string_type.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: the single-tree namespace binds the module's own declarations; ownership reads declared_in

GitHub review 5342739525 on #12540. The same-module test compared a declaration's path to
ctx.namespace.module_qn, but build_program_namespace (the plain normalize -> resolve route)
leaves module_qn Empty and records its owner in declared_in. namespace_owns_declaration now reads
declared_in, which is the owner on both namespace routes and the field root_binding_origin reads.

Measuring that route found the earlier boundary. build_program_namespace harvested only the root's
named edges, and a normalized module keeps its declarations under captured -> <module path>, so
none of them were bound. `type Myint` refused as unbound, and a module's own `type Int` fell
through to the kernel spelling and was silently bound to the kernel Int. The namespace now also
harvests the module body, which it finds by declared_in.

Controls on that route (v2.test.claim.body_let_annotation, enrolled share points):
- bla_single_tree_module_declared_int_and_bool_bind_the_local_declaration: F before, T now.
- bla_single_tree_undeclared_int_binds_the_kernel_type: T on both.
The foreign-import refusal and both ambiguity dispositions are unchanged and still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: select a grafted module body by the graft's mark, never by walking names

Review 5343957887 (P2 on b55b8a7). namespace_tree_module_body walked the module path's names and
restarted at the root on a missing step. Two leaks followed:
- `module m.t` with a root-level record `t` missed `m`, restarted, found `t`, and bound the record's
  field as a module binding.
- `module t` with a record `t` selected it at once.

The body is now selected by the producer's own mark. v2.compiler.namespace_graft
namespace_graft_module_body_optional descends the containment spine
(namespace_graft_spine_segment_edge_optional) until a step is not a segment, never restarts, and
answers only when that stop is the marked body (namespace_graft_node_is_module_body).
Header and flat representations have no grafted body, so they keep root-only harvesting.

The admission reader in v2.compiler.name_resolve already descended the same spine with its own
copy (admit_named_exports_body_root and _descend_spine). It now calls the one function in
namespace_graft (namespace_graft_module_body_root), so the spine has one reader.

Controls (v2.test.claim.resolve.single_tree_module_body): supplied emit-shaped roots, because
normalize always emits a well-formed graft and source text cannot author these shapes.
- a_record_matching_the_path_suffix_is_not_a_module_body_holds: F on b55b8a7, T here.
- a_record_named_like_a_flat_module_is_not_its_body_holds: F on b55b8a7, T here.
Each asserts `leaked` is not bound and `t` still is.

The local Int/Bool and undeclared-kernel controls still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: move build_program_namespace's rationale above the declaration

The parse phase refused a // annotation inside the fn body (DESIGN section 4c: only module-item
grain is modeled). This is the same text, placed above the declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM reference_conservation_population_omits_class_stamped_terminals: the caret WHY is past tense and names its helper as deleted (review 72492)

* v2 infer: a literal payload's facts derive for its own family

Review 5348050288. infer_literal_edge_diagnostics_derived decided which literal family owned a
payload edge, then dropped the family. infer_literal_payload_entries typed every payload atom as a
DecimalDigit, so a Symbol literal's name terminal was recorded as a digit.

The edge decision is now typed: infer_literal_edge_payload returns InferIntMagnitudePayload,
InferSymbolNamePayload or InferNotALiteralPayload, and the payload fold takes that family.
- Int magnitude members keep DecimalDigit / FreeMonoid<DecimalDigit>.
- A Symbol name payload is one childless atom and derives as v2.std.node Symbol (symbol_type_node).
- Any other shape stays on the frontier.

Controls read each payload node's recorded resolved_type (v2.test.claim.body_let_annotation 5e):
- bla_symbol_literal_payload_is_typed_symbol_not_digit: F at 87a29e4, T here.
- bla_int_literal_payload_digits_stay_decimal_digits: T on both (the integer family is unchanged).
Both require at least one payload to be seen, so neither can pass vacuously.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* body_let_annotation: share the payload verdicts, not the inferred trees

The floor refused at 92389ff: PureProducerShareWarmNotStored for bla_symbol_literal_as_symbol_tree,
because the cross-claim store cannot hold a closure (ServeCacheValueNotPortable, path
.value.facts.lookup). The shared producers now return the portable projection the claims inspect:
bla_symbol_literal_payload_verdict (the symbol-typed and digit-typed Bools) and
bla_int_literal_payload_digit_verdict. The trees are built inside those producers and never stored.
The claims and their discrimination are unchanged: the Symbol payload control is F without the
family-aware fold and T with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 04_infer: the payload comment cites infer_literal_edge_payload, not the deleted predicate

Review 72579: the comment above infer_literal_payload_member_type still named
infer_literal_edge_diagnostics_derived, which this PR replaced. No definition or reference to it remains.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main; bla_symbol_literal_as_int returns Outcome<ResolvedTree> (the #12432 assemble type)

* Import the std.disposition / v2.std.live_tree names two touched files use bare; retire their now-imported roster rows

Main newly declared Disposition and LiveTreeDisposition, so the gate refused
both files on this touch as UnimportedBareProvider. Importing the declaring
modules also covers SingleAuthority, RealizationDispatch and
SubstrateInputsOnly, whose ActiveDebt rows retire as ImportsFixed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roster_gate imports Finding (bare channel is off in a file that declares imports)

* reference_conservation_admission: KnownDropShape as a one-variant coproduct (leading |), not an alias to StatementLetBinder

With one arm left, '= StatementLetBinder' parsed as an alias, so the variant
did not exist and two importers refused IMPORT-MEMBER-ABSENT. The corpus form
for a one-variant coproduct is '= | Variant' (e.g. SdramSignalingFamily).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: the kernel host-text String, bound only where no String declaration is visible

neat-boar-16's ruling after #12549. It mirrors #12549's Symbol pair through the same mechanism.

- Declaration: v2.std.node declares the opaque kernel `String` beside Symbol (the kernel-types home),
  and owns its type node, host_text_type_node.
- Binding: v2.extdeps.languages.dag binds the spelling `String` to it, and the declaration table maps
  v2.std.node.String to it.
- Foreign declarations (decision A): String is the one kernel spelling the corpus already declares
  with another meaning (v2.std.text and std.string_type are FreeMonoid<Char>, imported by 470+
  modules), so dag_kernel_type_foreign_declaration types its foreign-declaration disposition as
  ForeignDeclarationBinds. v2.compiler.resolve then binds the declaration the author reached, and
  the kernel host text applies only in the unbound arm. Int, Bool and Symbol keep
  ForeignDeclarationRefuses.
- Literal: DagCanonicalStringLiteral is a fourth arm of the one literal decision, typed as host
  text. Every consumer that matches the literal decision handles it (infer's type binding, branch
  operand, match-arm body, Bool pattern classify, payload edge, and the undecidable-verdict lens).
- No implicit coercion: a host-text literal at a FreeMonoid<Char> position REFUSES. The declared
  unfold (literal_homomorphism_rows, UnicodeScalarSequenceUnfold) is not reachable yet, because the
  literal carries no value. That is filed as gunbc.recurring_failure_mode
  string_literal_lowers_to_one_class_stamped_atom (fix routed to gentle-koi-724's lane).

Claims (v2.test.claim.body_let_annotation 5f). The REDs are F with the behavior reverted and T here:
- bla_unimported_string_binds_kernel_host_text
- bla_string_literal_is_typed_host_text
- bla_string_literal_ascribed_int_refuses
- bla_host_text_literal_at_structural_string_refuses
Controls, T on both:
- bla_imported_structural_string_binds_its_declaration
- bla_host_text_value_at_structural_string_is_never_matched (no non-literal expression derives host
  text in v2 yet, so it pins "never a clean admit")
- bla_unknown_unimported_type_name_still_refuses

The Symbol and #12540 claims are unchanged and still hold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: record the v1/v2 String fork and where it resolves (at the importers)

royal-newt-820 flagged it and neat-boar-16 ruled. Under decision A, v2 binds `import v2.std.text { String }`
to the structural carrier, while v1 keeps the kernel. The fork resolves at the importers:
- host-using importers drop String from their imports, in a separate PR ahead of #12760;
- structural-using importers are a declared divergence, recorded here, with #12760's census as the
  instrument.
The rung stays at the v1 minimum. Evidence: bla_imported_structural_string_binds_its_declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag_canonical_literal_from_node: the string arm matches the atom inline; the is_* predicate is gone

Review 73119. dag_node_is_string_literal_atom was a sibling Bool predicate over Node storage, which
the literal coproduct exists to replace. That is the same dissolution as dag_node_is_symbol_literal_atom
(3fb5d6a, review 72280). The decision matches the atom identity inline. The claim reads
DagCanonicalStringLiteral from the decision, and the RFM row cites the decision.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* defork census: the String row names the kernel host-text String as a distinct concept

The generated check failed at d9cc153: docs/plans/dag-v2-defork-audit.md drifted, because the census
now finds v2.std.node String (#12760) among the String declarations. The derived file list was
right, but the authored reading still called every String '= FreeMonoid<Char>, one concept, two
declarations'. That is false for the opaque host text. The reading now separates the structural pair
from the host-text String, and the projection is regenerated with generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* kernel String: read #12759's string value; realize v2.std.node String as the host string

#12759 landed, so a string literal now carries its decoded value as one named payload.
- DagCanonicalStringLiteral { value } reads it through dag_string_literal_value_symbol_optional. A
  payload-less string atom is now a malformed literal.
- The value edge is its own payload family (InferStringValuePayload), typed host text and never a
  digit, as #12549 did for the Symbol name. bla_string_literal_is_typed_host_text now also
  requires that.
- string_literal_lowers_to_one_class_stamped_atom records the climb by #12759. The remaining
  literal-at-FreeMonoid<Char> refusal is now blocked only by v2 infer not peeling an alias to its
  body.

emit-build failed at 9b7c07f: the opaque v2.std.node String was emitted as its own struct, so the
bare String in v2_std_node.rs (symbol_lexeme's return) stopped meaning the host string (E0308).
gunbc.rust_source_type_bindings gains the exact row v2.std.node String -> RustStdString beside
Symbol's, and the String checkpoint proof records that the kernel spelling now has one declaration
rendering the same carrier. The stage0 mirror is updated to match: claim_executor --required-regen
reports first_generation_equal=true over 161 files.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: the importer census is a named frontier, not an instrument this PR cites

Review 73214. The receipt called the importer census '#12760's census' and its instrument, but no
classification exists in the tree yet. It now says the population is described, not bounded; names
the census and deletion lane that will bound it; and states that #12760 is held as a draft until both
land, so the flip cannot precede the cutover. When the census lands, the receipt will cite it by
symbol.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* where_predicate_binding: assemble_program_from_ingest now returns Outcome<ResolvedTree> (#12629)

The binding claims inspect only accept/refuse, so they retype to
Outcome<ResolvedTree>; Node is no longer used.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 emit_rust: an opaque declaration with an exact realization row emits an alias to that row

Ruled by deep-bee-18 for gunbc#12760. The emitter emitted every zero-parameter opaque declaration
as `pub struct X(PhantomData)` and ignored the declaration-keyed rows in
gunbc.rust_source_type_bindings. On #12760, v2.std.node String therefore became a struct, and the
kernel's bare `String` render inside v2_std_node.rs meant that struct (E0308 at symbol_lexeme).

The rule is general and declaration-keyed: rust_opaque_declaration_has_exact_row joins the existing
name-keyed kernel-alias route at all three sites that decide it. An exact row emits
`pub type X = <row spelling>`. An ambiguous row, or a row with no realization, renders the located
compile_error! that rust_exact_binding_spelling already produces, so there is no silent choice. The
phantom struct stays only where no row exists.

Stage0: v1_compiler_emit_rust.rs is regenerated. std_types.rs gains `pub type Unit = ();`, because
std.types Unit is a bare opaque declaration with an exact row (RustUnit) that the old emitter
emitted nothing for. claim_executor --required-regen reports first_generation_equal=true.

Controls (test.claim.opaque_exact_row_alias_witness_test, each read from the emitted text):
- std.types Unit, reached only by its row, emits `pub type Unit = ();` (absent before this rule);
- a row-less opaque declaration keeps its phantom struct;
- Symbol keeps its row alias.

v1 admission (gunbc.v1_maintenance_standing v1_seed_standing): this serves the v2 self-host
program, because the emitted compiler closure must build with the v2.std.node host-text String.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 04_infer: bind the literal payload family once in the gather

Review 73303 on #12809 (finding 2) flagged the pattern this PR introduced: each family arm matched a
variant only to rebuild it for infer_gather_literal_payload_step. The gather now binds the family
once, with one arm for InferNotALiteralPayload and one for every family (DESIGN section 2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: cite the importer census by symbol, and its structural-using population

The census is gunbc#12840 (royal-lark-857). Instrument: v2.lens.text_string_importer_census
verdict_with_crossings, whose identity join closes (407 = 391 String importers + 16 non-members). The
structural-using population, the declared v1/v2 divergence, is 7 modules, named here. It is a lower
bound: 120 unclassified and 2 unmeasured importers stay open. #12760 stays a draft until #12840 and the
import-deletion PR land. The symbol is cited in prose only, and joins the evidence list once #12840
lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_by_spelling: the structural-using population is 15 (census revision 7b87f99)

After neat-boar-16's fixpoint ruling, #12840 classifies 15 structural-using modules. Eight of them
are structural only because they pass host text into a module that keeps its import. v2.compiler.tokenize
and v2.std.integer are named divergence sites (ruling 1), 10 parse-refused modules keep the import
(ruling 4), and 24 remain undecided. The second instrument, text_string_importer_fixpoint, is added.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor: the live-tree closure reads the process-shared index (one index for the environment and kernel-types closures)

closure_paths_of built a fresh MultiEntryIndex over the live dag root per
call. A diff touching std/types.dag asks for both the parse-environment and
kernel-types closures, so the same name set was indexed twice and #12765's
guard refused the floor (MultiEntryIndexBuiltTwiceForOneNameSet, both sites
namespace_baseline.rs closure_paths_of). The revision-tree index in
evaluate_owned_item_in is a distinct source set and is left as is.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Carry one live-tree index to both closures instead of using the thread's shared slot

The shared slot holds the floor's own dag+src/v2 index; a dag-only demand
there evicted it and the floor refused SharedIndexRebuiltAfterEviction
(#12848's own floor). LiveDagIndex is built on first demand by the floor's
baseline reconstruction and passed to environment_agreement and
kernel_set_serves_both (-> kernel_names_at), so the two closures share one
build and the shared slot is untouched. The roundtrip test shares one too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* string_literal RFM: the literal-at-structural refusal is a stopgap; #12809 is its trigger

neat-boar-16's ruling on #12760: since #12759 carries the literal's value, the lawful route is the
unfold. The row now cites gunbc#12809 (parked on #12726 PR2 and #12506) as the trigger that flips
bla_host_text_literal_at_structural_string_refuses to an unfold control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: import unicode_char_code_point from std.unicode.char_class

This branch moved it out of std.unicode.types (to break the std.types cycle);
main's new v2.std.compilers.lexing imported it from the old module, so the
v2-native emit of 00_compile refused (emit-build).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP v2 resolve: lexical references keyed by occurrence; infer/eval/translate/emit read them

* legacy_repair_tap witness: import Present/Absent from v2.std.optional

The witness matched git_sha1_object_id's Optional result with bare Present/Absent.
v2.std.execution_surface also declares Absent | Present (a9388e4, the same
commit), so once a closure holds both, the four reads are ambiguous and the floor
refuses PureProducerShareRowModuleUnframeable (AmbiguousBareNameRead, sites=4).
The value variant Present { value } is v2.std.optional's; execution_surface's
carries no field.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: lift unscoped atom arm; flatten infer pattern

* WIP: argument may not begin after a newline

* WIP: walk-population fixture mints its bound references, as the parser does

* Restore main's text in the gap-analysis plan: its non_empty spellings record measurements taken on the old name (review 73826)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: a loop carrier is a binder, kept as the atom it names, never a lexical reference

* Debt roster: retire (std/content_hash.dag, get) as NotAReference

The floor refused RosterStale: content_hash's get is the builtin get(xs:, index:),
whose pair came from the whole-pool fallback resolving it to an unrelated pool
fn get. be51d1f (bare loader asks per name) removed that, and retired the same
builtin-get pairs elsewhere (e.g. extdeps/bootloader/grub.dag) as NotAReference.
This branch touches content_hash.dag, so its row is the one this floor judges.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73872: drop the unused Char classifier; the gate checks its structural strings with v2.std.algebra non_empty

- std.unicode.char_class keeps only unicode_char_code_point (consumed by tokenize
  and lexing). CharClass and char_in_class had no consumer anywhere and are deleted
  rather than rehomed.
- gate's displaced_cost / mechanism_class are v2.std.text String = FreeMonoid<Char>.
  Passing them to std.types string_non_empty (host text) crossed representations
  with no declared unfold (DESIGN section 4). The gate now calls v2.std.algebra
  non_empty, the structural carrier's own check; main's private non_empty_string
  stays deleted.
- The vocabulary comment no longer claims String inhabits no FreeMonoid carrier.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Arrow-body-form mutation mirrors place the lexical-reference arm, as production does

* Integration: real three-way merges of the generated stage0 files; name Filesystem's declaring module at its five bare readers

The five bare Filesystem reads (harness_cli, harness_turn, runner_microvm_boot_probe,
scm.repository_load, scm.repository_save) call Filesystem.Read/Write/List, the
extdeps.filesystem.filesystem_io service that v1.compiler.emit_rust emit_file_call binds,
so that module is the import. They were refused AmbiguousBareNameRead once #12381's
std.types edit brought them into the floor's prepared closure.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: thread #12947's lexical field through #12381's where-predicate walk

resolve_where_predicate_operator converts resolve_atom's Outcome through the existing
resolve_walk_of_outcome (a type's where clause has no lexical binders in scope, and
resolve_atom carries no lexical answer), and the unwalked where-set edge carries an
empty lexical list. With this, v2.test.claim.parameter_reference's five assembled-program
rows (the four the floor failed on #12947 plus pr_named_fn_parameter_is_a_parameter_reference_holds,
red on main) return true: #12381's where-predicate binding is what cures main's
resolve_unbound_name_is_declared_in_several_modules at the where clause.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Merge #12760 (neat-ibex-696/kernel-string) into the integration branch (generated conflicts taken from ours; regenerated below)"

This reverts commit 2688462, reversing
changes made to d5446f3.

* Integration: take #12760 back out (operator option A); regenerate

#12760's own carrier_by_spelling row orders it after the String import-deletion
PR, which has not started. Its merge is reverted, the source-type binding row it
added is re-derived away by claim_executor --regen-round-cost (fixed point,
rebuild_packages=0), and the defork audit's String row returns to main's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: #12947's occurrence matches take main's OccurrencePending (#12790)

A pending occurrence has no id yet, so it is read like a synthetic one:
resolved_tree_lexical_binding finds no binding (Absent), and resolve_lexical_reference
refuses it as unkeyed (resolve_reason_lexical_reference_unkeyed). emit-build and the
generated lane refused both matches as non-exhaustive on bc718d2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: main's resolve_arrow_resource_requirements atom arm carries #12947's lexical field

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: name the declaring module at three bare reads the combined closure made ambiguous

extdeps.cloud.gcp.sts and extdeps.tailscale.acl_api read String bare, declared by both
std.string_type and v2.std.text; they import it from std.string_type, the dag/extdeps
convention (acl_api's std.types import of String bound nothing). gunbc.systemd_property_directive_overlap
reads Unit bare, declared by std.types and v2.std.cardinality; it imports std.types Unit.
The floor refused these as AmbiguousBareNameRead (CLAIM-SCOPE) on 430d11d.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: revert #12381's annotation-only edit in an excluded wet receipt; file the floor class it trips

The floor selects an annotation-only hunk as a changed witness, contrary to DESIGN section 4c,
and refused the head with ChangedWitnessOutsidePreparedSubject for
test.manual.command_runner_local_argv_receipt (on the hermetic exclusion list). The
annotation correction (non_empty -> string_non_empty) is reverted so the honest edit is not
what blocks the integration; the stale annotation and the capability that lets it be
restored are rostered as gunbc.recurring_failure_mode annotation_only_edit_selects_a_changed_witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integration: the two spark get rows keep main's Retired ImportsFixed standing

Main (#12954) retired them after fixing those imports; a merge here had carried the older
ActiveDebt rows forward, which the floor refuses as RosterRetirementChanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…OperationInputName> (#12987)

* v2.std.template: one literal-or-hole Template<H>; ArgvTemplate = Template<String> (XL-2 PR1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* operation_argv: one OperationInputName identity for bindings, refusal causes, declared-input rows and template holes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* host_occupancy: enumerate the two UnitActivity wildcard arms the diff-scoped NFR check reaches through operation_argv

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* operation_argv: state OperationInputName's mint points accurately (review 74147)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 4, 2026
…them

NonFoldResidue named 99 wildcard sites over closed coproducts in the
#12691 commissioning code. None are enrolled: every arm is now explicit,
one per missing variant with the original body. The generation-zero
readiness check that three sites matched three levels deep is one
exhaustive helper, runner_microvm_cell_readiness record_ready_cell_at.
The two stale rows named fleet_converge_plan hash sites whose hashing
moved into fleet_plan_bundle (closed here); they are deleted.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Closed without folding in the v1 closeout bankruptcy (#13641). A stale draft on codex/allocation-vertical (2026-09-29), not targeting main. Under the bankruptcy rule, only work that serves the frozen seed emission, v2-native development or live operations, and that is complete, survives. The branch is kept for archaeology; no follow-up obligation is created. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant