Skip to content

Integration 2026-09-30: #12718 #12732 #12712 #12775 #12784 #12789 #12727 #12748 #12729 #12738 - #12805

Merged
gunbai-bot[bot] merged 51 commits into
mainfrom
integration/2026-09-30
Sep 30, 2026
Merged

gunbai-bot[bot] merged 51 commits into
mainfrom
integration/2026-09-30

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Integration branch for ten PRs, one merge commit each, plus merges of current main (through d0fd2c6c71). An eleventh, #12523, was merged and then reverted; see below.

PRs and head shas

PR Head Merge
#12718 Host SHA-256 primitive sha256_hex_of_text 402742cd clean
#12732 self-host / v2-native-cli: a non-clean emitted build exits 1 with its typed cause b65617d2 clean
#12712 Borrow the cached module index in keyed reads 8c957d29 clean
#12523 Wall: the approval broker's import closure contains no v2 compiler module c8b6c81a excluded (merged clean, then reverted)
#12775 approve-ios: derive the app's server host from the broker endpoint authority fd2e8ad1 clean
#12784 Broker front door: the backend carries its mount path ace61c22 clean
#12789 Approval device enrolment as a handshake 37c83b6c clean
#12727 Release-bins lookup: a tag dispatch finds its own cache entry 9745e2e9 conflict, regenerated
#12748 Generic substitution keeps a slot's optional cardinality fdf1d075 conflict, regenerated
#12729 A service exit arm names a type 45358289 conflict, regenerated
#12738 Uniform program installation/access contract (orphaned WIP) f2ba8742 conflict, resolved by hand; part dropped

#12523 is excluded

Its one file, test.claim.auth.approval_broker_closure_witness, is over the floor budget, so the merge is reverted here (proud-deer-538's ruling). On this PR's run 36743189391, the_approval_broker_closure_contains_no_compiler_module measured 97547 eval steps against a 72300 budget and a_closure_that_reaches_the_compiler_is_seen_to measured 12108ms against the 8000ms wall deadline; both were also refused on the enrolment margin. #12523's own head failed the same five blockers (run 36634310768), so this is not an integration effect. Moving the witness to dag/test/claim/long/ was rejected because the required floor declines that lane and the wall would stop gating merges. Head c8b6c81a stays fetchable for whoever finishes it. The annotation #12712 adds in gunbc.keyed_dependency_edge_read_seed_growth still names that witness, as one already on main does.

How each conflict was resolved

#12727 — .github/workflows/fleet-converge.yml (generated). Not hand-merged. The merge commit carries the integration side's bytes as provisional; the next commit regenerates the file from the merged authorities with tools.generated_artifact_gate main_wet_one --arg path=.github/workflows/fleet-converge.yml. The regenerated file is the integration side plus #12727's own delta (+3/-2: the second cache lookup keys on RELEASE_BINS_DISPATCH_SCOPE_REF).

#12748 — compiler_tests.rs, v1_compiler_compiler_tests_rust.rs, v1_compiler_infer.rs, v1_compiler_infer_resolve.rs (stage0 mirrors). The src/v1/*.dag authorities (04_infer, 04_method, 04_patterns, 04_resolve, 05_emit_rust, compiler_tests_rust) merged with no conflict. The mirrors carry provisional integration-side bytes in the merge commit and are regenerated afterwards.

#12729 — v1_compiler_parse.rs (stage0 mirror). src/v1/02_parse.dag merged with no conflict; the mirror is regenerated the same way.

Mirror regeneration (both of the above). claim_executor --required-regen --source-root dag --source-root src/v2, run from a seed built at the pre-#12748 integration tree. Pass 1 rewrote v1_compiler_{infer,infer_resolve,parse,compiler_tests_rust}.rs; after rebuilding from those, pass 2 rewrote compiler_tests.rs, which the seed emits from its compiled-in function and so lags one pass.

#12738 — four dag/extdeps modules and four witnesses. This branch is orphaned WIP from session/tidy-crane-517. Its first three commits already landed on main as #12630, and #12751 has since dissolved the raw argv builders it still carries.

Checks run locally

  • claim_executor --required-regen and --required-regen-fixed-point at 087be8e835; the later commits (the Wall: the approval broker's import closure contains no v2 compiler module #12523 revert and a second main merge) touch no src/v1 file: first_generation_equal=true planned=161 executed=161 adjudicated=161, and fixed_point_equal=true referenced_first_generation_equal=true.
  • tools.docs_projection_gate regen: exit 0, no committed file changed.
  • cargo clippy --all-targets -- -D warnings: clean.
  • cargo fmt --all --check: clean.

Do not merge from here; proud-deer-538 lands it and closes the source PRs.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits September 28, 2026 11:04
…dule

A ReadsLiveTree floor witness over v2.lens.module_graph import_closure_live:
refuses any src/v2/compiler/ path in the closure of
gunbc.auth.approval_broker_serve, pins a leaf the broker really reaches so an
empty closure cannot pass by vacancy, and carries a real-entry red control
(gunbc.commit_workflow, which imports v2.compiler.source_authority).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ching entry

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Tool/ResolveResult

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…h stale .name / resolve citations

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…a pin subject's program through a CliTool-typed helper

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t per call

with_module_path_index lends MODULE_PATH_INDEX_CACHE's entry for one closure;
build_module_path_index (owned) now clones through it once. module_declaration_fact_at
and dependency_resolution_facts_at (and its import half, now taking an is_declared
predicate) read through the borrow, so a demand walk no longer pays a copy of the
whole index -- plus a full declared-set rebuild -- per visited module and per edge
target. Measured on gunbc#12523's floor at c8b6c81: the broker claim at 3,998ms.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The pool heads index is built once per pool per process and served to every
consumer -- the same class as module_path_index and reference_edges -- but it was
never reported to shared_fill, so its cost was invisible and read as the own CPU
of whichever claim first reached an import-less file. It now records hit and fill
under cache=reference_pool_names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the pure fold as its differential oracle

The fabric store door digests an approved intent on every protected write;
the pure extdeps.crypto.sha2 fold costs ~200k interpreted eval steps per
64-octet block (measured). sha256_hex_of_text is the RustCrypto sha2 digest of
the text's UTF-8 bytes, wired exactly like hmac_sha256_hex: 04_method builtin
signature (+ regenerated v1_compiler_infer_method.rs), interpreter arm
(+ regenerated dispatch), authored dispatch row, std.primitives contract and
rosters, primitive_egress evidence row. test.claim.sha256_host_differential_
witness: host == pure fold == known answer on empty, abc, 55/56/63/64/65,
130-octet and the NIST 448-bit text (all PASS locally).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…vely through sha256_fips_witness's KATs), and the host crypto seams' seed-growth receipt

Per proud-deer-538: the floor carries only host-vs-known-answer claims (7
eval steps at most) over the FIPS vectors sha256_fips_witness asserts of the
pure fold plus the padding boundaries; the direct pure-vs-host comparison is a
local receipt. gunbc.host_crypto_digest_seed_growth enumerates both host
digest seams (sha256_hex_of_text_digest, and hmac_sha256_hex_tag, which had
none), retired by an emitted #12389 bridge body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ns, which had captured them (review 72974)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…I's spelling (refs/heads/<ref>)

A workflow_dispatch on a tag saves its release-bins entry under a scope the cache API lists as
refs/heads/<GITHUB_REF>; the lookup matched .ref == GITHUB_REF, read absent, and refused
StoreTransportDisagreeAbsentHit over the dispatch's own entry (runs 36653382960, 36653490246 on tag
deploy/door-8e0c1fad16). The dispatch lookup now reads RELEASE_BINS_DISPATCH_SCOPE_REF, derived from
github.ref (tags respelled, branches verbatim). Same ref, one spelling; the disagreement check is
unchanged. Claims: tag entry present, another tag's entry absent. Files the failure mode.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…value ExprVar

The exit arm RHS was parsed as a type and then wrapped in a fresh ExprVar,
so the claim-scope wall counted a type read as a value read and refused
AmbiguousBareNameRead on kernel Unit/String whenever both declarers were
reachable (#12563). Nothing evaluates that node; the arm now carries the
parsed type node. Control row added to bare_name_ambiguity_wall_witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; mark the tool_invocation helpers as its workaround

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… typed cause and the warning lines

The instrument seam mapped a non-zero warning_count to ObservationDidNotHold (exit 1) and printed
only the counters line, so a run whose every step said "success" exited 1 with no stated cause
(DESIGN §5). The termination is now derived from `emitted_build_not_clean_cause`, which names
EmittedBuildNonZeroStatus / EmittedBuildWarnings and the warning header lines (with multiplicity)
that CargoVerdict now carries beside its count, by the one predicate that counts them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… placed under its own comment (review 73004)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…oute-gap roster

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ound located at the pattern

T? instantiated with a type application (Nat, Holder<Nat>, a generic record)
lost the '?' because substitute_generics_apply (infer) and
substitute_type_slots_scoped (resolve) replaced the bare slot with the
argument node wholesale; the same substituted node carried the alias
declaration's span into the diagnostic.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ty, not an operator-typed xcconfig value

ApproveServerHost in the generated project.yml is now the broker's public host
(gunbc.auth.approval_broker_endpoint approval_broker_public_host_from over
fleet_intent_network.tailnet_domain), the same composition approval_broker_base_url
is built from. APPROVE_SERVER_HOST leaves Config/Team.xcconfig; DEVELOPMENT_TEAM
stays operator-filled. A non-default public port refuses the projection because
ServerConfig carries no port.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(Int does not cast to Port)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t-path strips the prefix; stage-5 probe, srv1 2026-09-30)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… cut-over and app follow in this PR)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(review 73232)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s sole-constructed in redemption); roster the witness attestation fixture (floor run 36727002278)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 10 commits September 30, 2026 15:02
fleet-converge.yml is a generated projection both sides changed; the ours bytes are
provisional here and are regenerated from the merged authorities in a follow-up commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The src/v1/*.dag authorities merged without conflict. The four conflicted stage0 mirrors
carry provisional ours bytes here and are regenerated from the merged .dag in a follow-up commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
src/v1/02_parse.dag merged without conflict. The conflicted mirror v1_compiler_parse.rs carries
provisional ours bytes here and is regenerated from the merged .dag in a follow-up commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
#12738 is orphaned WIP whose first three commits already landed on main as #12630, and whose raw
argv builders were since dissolved by #12751. Resolution:
- dag/extdeps/{bmc/webui/nbd_proxy_serve,exec/program,tools/nbdkit,tools/websocat}.dag and the
  nbd_proxy_serve_transport / srv3_host_effect_apply witnesses: ours (main after #12751). The
  theirs side is the pre-#12751 shape of the same change.
- tool_pin / tool_readiness witnesses: theirs adds only the WORKAROUND annotation on the
  tool_invocation helper both sides already carry; kept, with the failure-mode row it cites.
- dag/zz_scratch_typecheck/{repro,evalrepro}.dag (the WIP commit): dropped. They are unenrolled
  scratch probes with no consumer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…flict)

tools.generated_artifact_gate main_wet_one --arg path=.github/workflows/fleet-converge.yml.
The result is the integration side plus #12727's dispatch-scope-ref delta (+3/-2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…12729 conflicts)

claim_executor --required-regen, two passes: v1_compiler_{infer,infer_resolve,parse,compiler_tests_rust}.rs
from the first, compiler_tests.rs (emitted by the seed's compiled-in fn) from the second.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

PR #12805 floor is red with 5 blockers, all on test.claim.auth.approval_broker_closure_witness, the witness #12523 adds. It is not an integration effect: #12523's own floor at c8b6c81 (run 36634310768) was red with the identical 5 blockers, so that head was never green. Measured on #12805 run 36743189391: the_approval_broker_closure_contains_no_compiler_module = 97547 eval steps against a new-witness budget of 72300; a_closure_that_reaches_the_compiler_is_seen_to = 12108ms against the 8000ms wall deadline; both also enrolment_measured_over_margin. Both claims pass their verdicts; the cost is the live import_closure_live walk itself, so I see no small edit that brings a 12s walk inside the margin. The other two import_closure_live witnesses live in dag/test/claim/long/, which the required floor declines, so moving it there makes CI green but the wall stops gating merges, which is the stated purpose of #12523. Its author wrote that an over-budget result would come to you as a cost finding rather than a debt row. Everything else on the floor passed (planned=621 passed=607, the rest held rosters); generated is green; emit-build still running. A = revert the #12523 merge on the integration branch (10 PRs land; #12523 returns separately once its cost is solved). B = keep it, move the witness to the long lane.

— sent from wise-bee-807

Brian Searls and others added 2 commits September 30, 2026 17:05
…own head

test.claim.auth.approval_broker_closure_witness measured 97547 eval steps against a 72300 budget
and 12108ms against the 8000ms wall deadline on PR #12805 (run 36743189391), and the same five
blockers on #12523's own head c8b6c81 (run 36634310768). Excluded from this integration by
proud-deer-538's ruling; the head stays fetchable for whoever finishes it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Integration 2026-09-30: #12718 #12732 #12712 #12523 #12775 #12784 #12789 #12727 #12748 #12729 #12738 Integration 2026-09-30: #12718 #12732 #12712 #12775 #12784 #12789 #12727 #12748 #12729 #12738 Sep 30, 2026
@gunbai-bot

gunbai-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

On review 73317's note that #12738 has no content left: it does have content, 25 lines, all in git diff origin/main...HEAD:

  • the new row gunbc.recurring_failure_mode nested_field_read_through_a_binder_of_an_inferred_generic_result (+17);
  • the WORKAROUND annotation on tool_invocation in tool_pin_witness_test.dag and tool_readiness_witness_test.dag (+4 each).

The rest of #12738 was already on main as #12630/#12751, and its scratch probes were dropped. The PR body describes both.

The enrolment-handshake files (gunbc.auth.approval_enrolment_handshake and its witness) come from #12789 (commit 3df5fe5), not #12738, and are merged as that PR's head 37c83b6c. No change pushed.

— sent from wise-bee-807

src/v1/04_infer.dag merged without conflict; v1_compiler_infer.rs carries provisional ours bytes
here and is regenerated from the merged .dag in the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 30, 2026
@briansrls
briansrls removed this pull request from the merge queue due to a manual request Sep 30, 2026
Brian Searls and others added 4 commits September 30, 2026 19:03
…main 68ad067 merge)

claim_executor --required-regen, then --required-regen-fixed-point: fixed_point_equal=true.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
src/v1/{04_infer,04_service,compiler_tests_rust}.dag merged without conflict; the three conflicted
mirrors carry provisional ours bytes and are regenerated in the next commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…3bda4 merge)

claim_executor --required-regen, three passes (infer + compiler_tests_rust, then compiler_tests.rs),
then --required-regen-fixed-point: fixed_point_equal=true.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 30, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 30, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 3150d9b Sep 30, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the integration/2026-09-30 branch September 30, 2026 22:57
gunbai-bot Bot pushed a commit that referenced this pull request Oct 2, 2026
…arrier or dropped with a located reason; kind_reflection row discharged

The stale-justification census went 97 -> 3 at identity grain against the
current tree. Three classes of edit:

REPAIRED (~44 DeclarationRefs): citations that named an enclosing module
while the subject had moved, re-pathed to the carrier that now produces it
- target_invocation: 15 compile_clean refs v1_compiler.cli_run ->
  v1_compiler.cli_run.compile_clean (the subjects live in the inline mod),
  plus the render ref dropped (impl method on QualificationRefusal,
  floor_memory_supervisor.rs:93 -- uncitable, not dead)
- namespace bridges: v1_interpreter -> v1_compiler.v1_interpreter (the
  module moved into the generated infer/resolve carrier)
- generated_artifact_boundary: 5 refs -> v1_compiler.generated_artifact_
  boundary_host.tests (subjects in the inline mod tests at :443)
- bare_reference_scanner module_self_declared_names ->
  v1_compiler.cli_run.bare_reference_scanner_tests
- floor_cost_debt: citation repaired to run_required_floor (the constant
  became fn-local inside it at required_floor_runner.rs:11968) -- repaired
  rather than deleted because that row's trigger has NOT fired and
  repair-to-live-carrier is the teardown precedent
- floor_teardown_attribution: citation re-inserted as
  v1_compiler.cli_run::release_process_caches_at_exit -- the old subject
  was RENAMED, not deleted (b1f4f11), and the live fn is called from
  claim_executor.rs:2435; current_boundary sentence corrected to what the
  one whole-run teardown figure still measures

DROPPED (~25 citations, each with a 2-line doctrinal comment): subjects
that are macro-declared extents (thread_local! stores in
floor_memory_instrumentation, modeled_operation_realization,
cross_claim_pure_share, cross_claim_demand_census -- gunbc.rust_item_scan
MacroScope cannot name them at item grain, so the citation can never be
anything but stale noise) or impl methods with no item-grain identity.

DELETED: kind_reflection_seed_growth.dag, file + roster entry + import.
Its regen trigger FIRED: both cited subjects now carry the four-param fn
with kind_inhabitant_matches_resolved x2 and the two-arm enum, regenerated
by 3150d9b #12805 -- the row was 'narrowed, not retired' per #12163
until that regen carried the second half, and deletion IS its discharge.

KEPT (3, per operator ruling): v1.compiler.emit_rust::
emit_source_root_eval_driver_main_rs, v1_compiler.main::RetainedCliHost,
v1_compiler.v1_interpreter::write_file_create_new -- each subject moved to
a generated mirror, neither row's trigger has fired, and the census's
stale join compares against the live hand-Rust population only, so it
cannot address a generated subject. Typed dispositions in the PR body.

Admission COMPLETE; well-formedness gate green; the 87-row roster folds
with no empty declaration list and no duplicate display key
(1210 declarations); duplicate-justifications 0; uncitable-items 1 (the
declared Display impl, uncitable by rule). Witnesses:
dag/test/claim/seed_growth_admission_witness_test.dag answers 7/7 PASS,
and the census instrument exits 0 with stale-justifications (3).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants