diff --git a/dag/gunbc/discovery_census.dag b/dag/gunbc/discovery_census.dag index 14917b32791..12b45290933 100644 --- a/dag/gunbc/discovery_census.dag +++ b/dag/gunbc/discovery_census.dag @@ -13,7 +13,7 @@ import gunbc.build_target { import v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedCostDebt, - DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, + DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, required_floor_site_disposition, } import v2.std.live_tree { LiveTreeDisposition } @@ -265,6 +265,8 @@ fn census_partition_step(acc: CensusPartition, row: CensusRow) -> CensusPartitio CensusPartition { planned: acc.planned, declined: concat([row], acc.declined) } DeclinedDiscoveryExcluded { matched_substring: _ } => CensusPartition { planned: acc.planned, declined: concat([row], acc.declined) } + DeclinedNoCiWetLane { pattern: _ } => + CensusPartition { planned: acc.planned, declined: concat([row], acc.declined) } } } @@ -338,6 +340,7 @@ type CensusCounts { declined_outside_required_gate: Int declined_outside_gate_closure: Int declined_discovery_excluded: Int + declined_no_ci_wet_lane: Int } fn census_counts_zero() -> CensusCounts { @@ -349,7 +352,8 @@ fn census_counts_zero() -> CensusCounts { declined_cost_debt: 0, declined_outside_required_gate: 0, declined_outside_gate_closure: 0, - declined_discovery_excluded: 0 + declined_discovery_excluded: 0, + declined_no_ci_wet_lane: 0 } } @@ -364,7 +368,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } PlannedAsChangedWitness => CensusCounts { @@ -375,7 +380,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedLongModule { matched_prefix: _ } => CensusCounts { @@ -386,7 +392,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedFixtureMember { matched_prefix: _ } => CensusCounts { @@ -397,7 +404,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedCostDebt => CensusCounts { @@ -408,7 +416,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt + 1, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedOutsideRequiredGate => CensusCounts { @@ -419,7 +428,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate + 1, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedOutsideGateClosure => CensusCounts { @@ -430,7 +440,8 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure + 1, - declined_discovery_excluded: counts.declined_discovery_excluded + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane } DeclinedDiscoveryExcluded { matched_substring: _ } => CensusCounts { @@ -441,7 +452,20 @@ fn census_counts_add(counts: CensusCounts, d: RequiredFloorDisposition) -> Censu declined_cost_debt: counts.declined_cost_debt, declined_outside_required_gate: counts.declined_outside_required_gate, declined_outside_gate_closure: counts.declined_outside_gate_closure, - declined_discovery_excluded: counts.declined_discovery_excluded + 1 + declined_discovery_excluded: counts.declined_discovery_excluded + 1, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane + } + DeclinedNoCiWetLane { pattern: _ } => + CensusCounts { + offered: counts.offered + 1, + planned: counts.planned, + declined_long_module: counts.declined_long_module, + declined_fixture_member: counts.declined_fixture_member, + declined_cost_debt: counts.declined_cost_debt, + declined_outside_required_gate: counts.declined_outside_required_gate, + declined_outside_gate_closure: counts.declined_outside_gate_closure, + declined_discovery_excluded: counts.declined_discovery_excluded, + declined_no_ci_wet_lane: counts.declined_no_ci_wet_lane + 1 } } } diff --git a/dag/gunbc/recurring_failure_mode/doctrine_safety_claim_stated_wider_than_the_census_that_delivers_it.dag b/dag/gunbc/recurring_failure_mode/doctrine_safety_claim_stated_wider_than_the_census_that_delivers_it.dag index 04e701a3be5..e074873bc34 100644 --- a/dag/gunbc/recurring_failure_mode/doctrine_safety_claim_stated_wider_than_the_census_that_delivers_it.dag +++ b/dag/gunbc/recurring_failure_mode/doctrine_safety_claim_stated_wider_than_the_census_that_delivers_it.dag @@ -47,7 +47,7 @@ data doctrine_safety_claim_stated_wider_than_the_census_that_delivers_it: Recurr "BOUNDARY AGAINST [[check_subject_narrower_than_its_declared_claim]], which is the same asymmetry one layer down. There a CHECK is cited for a population wider than the one its implementation ranges over, and the repair is to widen the check or narrow its citation. Here there is no defective check to widen: the substrate's refusal is total and correct at every site it reaches, and the floor's selection is a priced ruling rather than an accident of first implementation -- which is precisely the distinction that row makes load-bearing when it says the narrowing `is never a decision`. Here it WAS a decision. The narrowness lives only in the JOIN between a doctrine's stated subject and a mechanism's signed subject, which is why the population is prose in `gunbc.design_document` rather than any executing declaration.", - "THE POPULATION IS NAMED BY ITS PRODUCER AND NOT TRANSCRIBED, because a count of unqualified safety sentences copied here would rot beside the document it describes. The candidates are the sentences of `gunbc.design_document` that assert a guarantee in the present tense over a substrate-grain subject; the mechanisms they could rest on are the required lanes rostered at `gunbc.witness_floor_workflow` `required_lanes_roster` and the prefix roster at `v2.workflow.required_floor` `required_gate_prefixes`, read beside the standing drops at `gunbc.rung_drop`. `the deletion is the census` is the one adjudicated. No number is recorded here and none may be quoted from this row.", + "THE POPULATION IS NAMED BY ITS PRODUCER AND NOT TRANSCRIBED, because a count of unqualified safety sentences copied here would rot beside the document it describes. The candidates are the sentences of `gunbc.design_document` that assert a guarantee in the present tense over a substrate-grain subject; the mechanisms they could rest on are the required lanes rostered at `gunbc.witness_floor_lanes` `required_lanes_roster` and the prefix roster at `v2.workflow.required_floor` `required_gate_prefixes`, read beside the standing drops at `gunbc.rung_drop`. `the deletion is the census` is the one adjudicated. No number is recorded here and none may be quoted from this row.", "RUNG FOUND AT: 1, mitigatable, and the mitigation is that a reader happened to read a review. Nothing holds this class today: the doctrine is prose, no `Accepted` program can read it (DESIGN section 4c), and the one instrument that could have contradicted it -- the required floor -- reported SUCCESS on the named runs while the modules where the doctrine failed sat outside that run's prepared closure. CEILING: 2, mechanically preventable, and the ceiling is honestly 2 and not higher because the subject is an authored English sentence whose intended scope is not derivable from any modeled fact; what IS derivable is the gate's admitted subject, so a doctrine sentence can be REQUIRED to cite the mechanism it rests on and that citation can be joined against the mechanism's actual subject. Making the unqualified sentence unwritable would need the doctrine itself modeled as a claim with a declared subject, which is not a capability this repo has or has planned.", diff --git a/dag/gunbc/repo/repo_ruleset.dag b/dag/gunbc/repo/repo_ruleset.dag index ca57c4ce804..33f8f48e505 100644 --- a/dag/gunbc/repo/repo_ruleset.dag +++ b/dag/gunbc/repo/repo_ruleset.dag @@ -4,7 +4,8 @@ import std.process { ProcessExit, ExitSuccess, exit_failure } import std.types { HttpStatus, NonEmptyStr } import std.dissolution { DissolutionCondition, unbound_dissolution } import gunbc.repository { gunbc_repository } -import gunbc.witness_floor_workflow { witness_floor_workflow_job_id, witness_floor_lane_timeout, required_lanes_roster } +import gunbc.witness_floor_workflow { witness_floor_workflow_job_id, witness_floor_lane_timeout } +import gunbc.witness_floor_lanes { required_lanes_roster } import std.measure { Minute, minute, minute_count, measure_add, MergeQueueEntryCount, merge_queue_entry_count, merge_queue_entry_count_value } import gunbc.ensure { EnsurePolicy, diff --git a/dag/gunbc/required_lanes_gate.dag b/dag/gunbc/required_lanes_gate.dag index c368e6c0362..5c267090e6f 100644 --- a/dag/gunbc/required_lanes_gate.dag +++ b/dag/gunbc/required_lanes_gate.dag @@ -36,6 +36,7 @@ import gunbc.floor_attempt_standing { import gunbc.ci_failure_class { floor_outcome_wire_infra, floor_outcome_wire_structural } import v2.std.node { Node } import std.types { String, List } +import gunbc.witness_floor_lanes { RequiredLane } // THE REQUIRED AGGREGATOR'S REFUSAL, CONSTRUCTED AS NODES RATHER THAN SPELLED AS TEXT. // @@ -209,58 +210,6 @@ fn required_lanes_head_standing_stmts( ] } -// THE REQUIRED LANE, AS ONE CONCEPT WITH N INSTANCES RATHER THAN N NAMED PARAMETERS. -// -// This axis was a HARDCODED PAIR -- `build_var` beside `floor_var`, threaded through four -// functions and spelled 28 times -- which is one concept given one name per instance, the fork -// DESIGN section 2 horizontal exists to delete. The tell was mechanical: promoting a third job -// into the aggregate was described by `gunbc.witness_floor_workflow` as a one-row edit, and was -// in fact a signature change in four places plus a step-name rewrite, because the gate could not -// say "a lane" at all -- only "the build one" and "the floor one". -// -// A LANE IS THREE FACTS AND NOT ONE, and each is read by a different surface: the JOB ID is what -// the workflow's `needs..result` expression names, the VARIABLE is what the emitted shell -// reads, and the LABEL is what the receipt prints. They are genuinely distinct strings -- the job -// id is `required-witnesses-build`, the variable `BUILD`, the label `build` -- so collapsing any -// two would force one surface to derive its spelling from another's, which is a nickname for a -// fact the caller already holds. Carrying all three is what lets the gate AND the step's `env` -// block be projections of one roster instead of two hand-kept lists whose agreement nothing -// checks. -// -// NON-EMPTY BY CONSTRUCTION, and that is the whole safety argument for the shape. The verdict is -// an OR-fold over the lanes, and an or-fold over nothing is FALSE -- so an empty lane list would -// publish the required context GREEN over a gate that read no lane at all, which is section 5's -// fail-open in its purest form. `FreeSemigroup` has no empty representation, so that state is -// UNWRITABLE rather than validated: the structurally-impossible rung of section 4b rather than -// the mechanically-preventable one, and no refusal arm is owed because there is no arm to write. -// -// THE BOUNDARY THAT GUARANTEE HOLDS AT, stated because section 4b says unwritable in the ACCEPTED -// CORPUS and unwritable as SOURCE HANDED TO THE COMPILER are different claims and only the second -// decides whether a RED is authorable. MEASURED, not reasoned: a fixture module authoring -// `FreeSemigroup { tail: [] }` was handed to the compiler on 2026-09-02 and refused with -// `error: missing required field 'head' in literal of type 'FreeSemigroup'`, located at the -// literal -- one blocking error. So the empty roster is authorable as fixture source and is -// refused there, which is the stronger of the two boundaries. -// -// WHAT THAT DOES NOT ESTABLISH, AND THE TRIGGER IS OWNED ELSEWHERE. The refusal is the compiler's -// GENERAL record-completeness wall, not anything this roster authored, and the roadmap node -// `floor-record-construction-wall` (rn_ILWLG34LVL5SAS6QPN5GZDPMFY) records that wall's own -// evidence as NOT YET ENROLLED -- in its words, a construction wall "currently rests on -// record-completeness enforcement that is itself unmeasured" -- the refusal measured here is -// recorded as that node's executed RED specimen rather than restated. So this roster's rung is section -// 4b(4) CONDITIONAL ON that wall, and its next-rung trigger is that node's probe-pairing rather -// than anything in this file. A per-consumer fixture asserting the same refusal is deliberately -// NOT added here: it would be one more monomorphised copy of a corpus-wide property, the same -// duplication declining a sixth NonEmpty carrier avoids. -// It is deliberately not a fresh NonEmptyRequiredLanes carrier — that would re-invent -// std.algebra FreeSemigroup. -type RequiredLane { - job_id: String, - label: String, - var_name: String, - class_var_name: String -} - // THE OR-FOLD OVER THE LANES, left-associated so that the two-lane case is the exact node the // hardcoded pair built: `or_else(left: test(first), right: test(second))`. fn required_lanes_any_test(lanes: FreeSemigroup, mk: fn(String) -> Node) -> Node { diff --git a/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag index 81d4de6d7a2..b5ab04d0fe5 100644 --- a/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag +++ b/dag/gunbc/rung_drop/emit_copy_qualification_without_a_consumer.dag @@ -12,5 +12,5 @@ data emit_copy_qualification_without_a_consumer: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: EmitCopyQualificationWithoutAConsumer, authored: "**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: \"false\"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `\"false\"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair." } + declaration: AuthoredProse { legacy: EmitCopyQualificationWithoutAConsumer, authored: "**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: \"false\"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `\"false\"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair." } } diff --git a/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag b/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag index 163803f66a5..a4bbf24d699 100644 --- a/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag +++ b/dag/gunbc/rung_drop/emitted_bytes_witness_required_lane.dag @@ -13,5 +13,5 @@ data emitted_bytes_witness_required_lane: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: EmittedBytesWitnessRequiredLane, authored: "UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger." } + declaration: AuthoredProse { legacy: EmittedBytesWitnessRequiredLane, authored: "UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_lanes` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger." } } diff --git a/dag/gunbc/rung_drop/fabric_evidence_gating.dag b/dag/gunbc/rung_drop/fabric_evidence_gating.dag index bd228d9faf8..b66c1d1ac69 100644 --- a/dag/gunbc/rung_drop/fabric_evidence_gating.dag +++ b/dag/gunbc/rung_drop/fabric_evidence_gating.dag @@ -12,5 +12,5 @@ data fabric_evidence_gating: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: FabricEvidenceGating, authored: "**CORRECTED 2026-09-28: THE CALIBRATION SCRIPT WAS DELETED AND THEN RESTORED, AND THE LANE WAS NOT.** The amendment below said the 2026-09-04 ruling deleted `tools/fabric_ci_evidence_calibration.sh`. #10390 did delete it on 2026-09-04. #10270 (FCI-1) re-added it on 2026-09-05, and it is live: `tools/fabric_ci_fci1_live_instrument.sh` runs it against the exact binary before any srv3 observation. The original sentence is QUOTED, not deleted, because the record of what was claimed is the point: 'together with fabric_ci_evidence_calibration_step, its two derived bounds, and tools/fabric_ci_evidence_calibration.sh'. WHAT THE CORRECTION CHANGES: only the script clause. The script now runs only when an operator invokes the FCI-1 live instrument by hand, on no CI trigger. WHAT IT DOES NOT CHANGE: the `fabric-evidence` job, the calibration step and the FABRIC_EVIDENCE binding are still absent from every emitted workflow. `w_RED_the_deleted_lanes_do_not_return` still guards that absence. A red from a hand-invoked run is still not a merge wall, so the temporary rung (outside the modeled guarantee for merges), the population and the restoration trigger all stand unchanged. The script is its own scaffold with its own dissolution condition in its header; this row does not govern it. **AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows." } + declaration: AuthoredProse { legacy: FabricEvidenceGating, authored: "**CORRECTED 2026-09-28: THE CALIBRATION SCRIPT WAS DELETED AND THEN RESTORED, AND THE LANE WAS NOT.** The amendment below said the 2026-09-04 ruling deleted `tools/fabric_ci_evidence_calibration.sh`. #10390 did delete it on 2026-09-04. #10270 (FCI-1) re-added it on 2026-09-05, and it is live: `tools/fabric_ci_fci1_live_instrument.sh` runs it against the exact binary before any srv3 observation. The original sentence is QUOTED, not deleted, because the record of what was claimed is the point: 'together with fabric_ci_evidence_calibration_step, its two derived bounds, and tools/fabric_ci_evidence_calibration.sh'. WHAT THE CORRECTION CHANGES: only the script clause. The script now runs only when an operator invokes the FCI-1 live instrument by hand, on no CI trigger. WHAT IT DOES NOT CHANGE: the `fabric-evidence` job, the calibration step and the FABRIC_EVIDENCE binding are still absent from every emitted workflow. `w_RED_the_deleted_lanes_do_not_return` still guards that absence. A red from a hand-invoked run is still not a merge wall, so the temporary rung (outside the modeled guarantee for merges), the population and the restoration trigger all stand unchanged. The script is its own scaffold with its own dissolution condition in its header; this row does not govern it. **AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows." } } diff --git a/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag b/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag index 8977672e42a..2d073a23133 100644 --- a/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag +++ b/dag/gunbc/rung_drop/rust_unit_tests_off_the_merge_path.dag @@ -12,5 +12,5 @@ data rust_unit_tests_off_the_merge_path: RungDrop = RungDrop { standing: Standing, - declaration: AuthoredProse { legacy: RustUnitTestsOffTheMergePath, authored: "**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row. ENROLMENT 2026-09-08 (gunbc#10822): this change adds `v1_compiler.cli_run.rostered_row_join` `file_roster_join_tests` to that `--lib` population. The restoration trigger is unchanged and covers them: they are `--lib` tests, so runner supply sufficient to execute that population restores them with the rest. HOSTED MEASUREMENT LANE DELETED (operator ruling 2026-09-29): the `rust-unit-tests` job that ran this population non-blocking on `ubuntu-24.04-arm` (2026-09-27 to 2026-09-29) is removed from `gunbc.compiler_gate_workflow`. Its continue_on_error step reported success on every run while two tests were red on main, so it executed the population without exposing it and did not climb this row; its deletion returns CI to exactly the state this row declares. The restoration trigger is unchanged." } + declaration: AuthoredProse { legacy: RustUnitTestsOffTheMergePath, authored: "**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row. ENROLMENT 2026-09-08 (gunbc#10822): this change adds `v1_compiler.cli_run.rostered_row_join` `file_roster_join_tests` to that `--lib` population. The restoration trigger is unchanged and covers them: they are `--lib` tests, so runner supply sufficient to execute that population restores them with the rest. HOSTED MEASUREMENT LANE DELETED (operator ruling 2026-09-29): the `rust-unit-tests` job that ran this population non-blocking on `ubuntu-24.04-arm` (2026-09-27 to 2026-09-29) is removed from `gunbc.compiler_gate_workflow`. Its continue_on_error step reported success on every run while two tests were red on main, so it executed the population without exposing it and did not climb this row; its deletion returns CI to exactly the state this row declares. The restoration trigger is unchanged." } } diff --git a/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag b/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag index 7970dfd1842..282291aa361 100644 --- a/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag +++ b/dag/gunbc/rung_drop/v2_native_route_off_the_merge_path.dag @@ -63,6 +63,6 @@ data v2_native_route_off_the_merge_path: RungDrop = RungDrop { temporary: Mitigatable, reason: DeletedWithoutReplacement, population: v2_native_route_off_the_merge_path_population, - restoration_trigger: "THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return", + restoration_trigger: "THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.deleted_lanes_countable_witness_test w_RED_the_deleted_lanes_do_not_return", } } diff --git a/dag/gunbc/v1/v1_witness_census.dag b/dag/gunbc/v1/v1_witness_census.dag index 552b486205f..3faea642c77 100644 --- a/dag/gunbc/v1/v1_witness_census.dag +++ b/dag/gunbc/v1/v1_witness_census.dag @@ -6,7 +6,7 @@ import std.dissolution { DissolutionCondition, unbound_dissolution } import gunbc.replacement_cut { EvidenceDisposition, ReenrollAgainstY, ReplaceEvidence, RetireEvidence } import v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, - DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedCostDebt + DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, DeclinedCostDebt } // XL-5's SECOND DELIVERABLE: the wall that stops the bankruptcy transaction greening by LOSING @@ -123,6 +123,7 @@ fn floor_standing_is_fixture_member(s: RequiredFloorDisposition) -> Bool { DeclinedOutsideRequiredGate => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false DeclinedCostDebt => false } } diff --git a/dag/gunbc/witness/witness_floor_lanes.dag b/dag/gunbc/witness/witness_floor_lanes.dag new file mode 100644 index 00000000000..7dc7d4f24f4 --- /dev/null +++ b/dag/gunbc/witness/witness_floor_lanes.dag @@ -0,0 +1,202 @@ +module gunbc.witness_floor_lanes + +import std.types { String, List } +import v2.std.algebra { FreeSemigroup, list_map, non_empty_to_list } + +// THE REQUIRED LANE, AS ONE CONCEPT WITH N INSTANCES RATHER THAN N NAMED PARAMETERS. +// +// This axis was a HARDCODED PAIR -- `build_var` beside `floor_var`, threaded through four +// functions and spelled 28 times -- which is one concept given one name per instance, the fork +// DESIGN section 2 horizontal exists to delete. The tell was mechanical: promoting a third job +// into the aggregate was described by `gunbc.witness_floor_workflow` as a one-row edit, and was +// in fact a signature change in four places plus a step-name rewrite, because the gate could not +// say "a lane" at all -- only "the build one" and "the floor one". +// +// A LANE IS THREE FACTS AND NOT ONE, and each is read by a different surface: the JOB ID is what +// the workflow's `needs..result` expression names, the VARIABLE is what the emitted shell +// reads, and the LABEL is what the receipt prints. They are genuinely distinct strings -- the job +// id is `required-witnesses-build`, the variable `BUILD`, the label `build` -- so collapsing any +// two would force one surface to derive its spelling from another's, which is a nickname for a +// fact the caller already holds. Carrying all three is what lets the gate AND the step's `env` +// block be projections of one roster instead of two hand-kept lists whose agreement nothing +// checks. +// +// NON-EMPTY BY CONSTRUCTION, and that is the whole safety argument for the shape. The verdict is +// an OR-fold over the lanes, and an or-fold over nothing is FALSE -- so an empty lane list would +// publish the required context GREEN over a gate that read no lane at all, which is section 5's +// fail-open in its purest form. `FreeSemigroup` has no empty representation, so that state is +// UNWRITABLE rather than validated: the structurally-impossible rung of section 4b rather than +// the mechanically-preventable one, and no refusal arm is owed because there is no arm to write. +// +// THE BOUNDARY THAT GUARANTEE HOLDS AT, stated because section 4b says unwritable in the ACCEPTED +// CORPUS and unwritable as SOURCE HANDED TO THE COMPILER are different claims and only the second +// decides whether a RED is authorable. MEASURED, not reasoned: a fixture module authoring +// `FreeSemigroup { tail: [] }` was handed to the compiler on 2026-09-02 and refused with +// `error: missing required field 'head' in literal of type 'FreeSemigroup'`, located at the +// literal -- one blocking error. So the empty roster is authorable as fixture source and is +// refused there, which is the stronger of the two boundaries. +// +// WHAT THAT DOES NOT ESTABLISH, AND THE TRIGGER IS OWNED ELSEWHERE. The refusal is the compiler's +// GENERAL record-completeness wall, not anything this roster authored, and the roadmap node +// `floor-record-construction-wall` (rn_ILWLG34LVL5SAS6QPN5GZDPMFY) records that wall's own +// evidence as NOT YET ENROLLED -- in its words, a construction wall "currently rests on +// record-completeness enforcement that is itself unmeasured" -- the refusal measured here is +// recorded as that node's executed RED specimen rather than restated. So this roster's rung is section +// 4b(4) CONDITIONAL ON that wall, and its next-rung trigger is that node's probe-pairing rather +// than anything in this file. A per-consumer fixture asserting the same refusal is deliberately +// NOT added here: it would be one more monomorphised copy of a corpus-wide property, the same +// duplication declining a sixth NonEmpty carrier avoids. +// It is deliberately not a fresh NonEmptyRequiredLanes carrier — that would re-invent +// std.algebra FreeSemigroup. +type RequiredLane { + job_id: String, + label: String, + var_name: String, + class_var_name: String +} + +// THE LANE JOB IDS ARE THEIR OWN DECLARATIONS, AND UN-FUSING THEM FROM THE LANE WORDS IS THE WHOLE +// OF THIS CHANGE. +// +// WHY A UNIQUE NAME IS NEEDED AT ALL. A GitHub required status check names a CONTEXT, and a +// context is the job's name -- which workflow published it is not part of the name. So `build` is +// not a name this repository owns: `gunbc.fleet_converge_workflow` declares a job whose id is also +// exactly `build`, and a rule naming `build` names two jobs in two workflows, answered by +// whichever green arrives. Enforcement cannot move onto a lane job until that lane's context is +// unique across every workflow emitted here. +// +// WHY THE NAME IS NOT COMPUTED FROM THE LANE WORD -- the modeling content, not a spelling +// preference. `build_lane_job_id` was DEFINED AS `required_ci_lane_build`, which read as single +// authority because the two strings coincided. They are two facts with different authorities and +// consumers: the LANE WORD is a CLI argument this workflow passes to `claim_executor +// --required-lane`, owned by `gunbc.fabric_witness_run` and consumed by an exhaustive +// `RequiredCiPhase::lane` match inside the binary; the JOB ID is a GitHub required-context name, +// owned here and consumed by a repository ruleset that is not a `.dag` fact at all. Their +// coincidence was the accident, not the authority. Deriving the job id from the lane word -- +// including by concatenating a prefix -- re-fuses them through a different door and in the +// dangerous direction: a lane rename, an ordinary CLI-vocabulary edit, would silently move a +// REQUIRED CONTEXT NAME and a check would stop being required with nothing going red. The rows +// below are therefore spelled, and every reference to a job id in this file is taken FROM these +// declarations rather than typed, so a rename here moves the `needs` list and the `needs.*.result` +// expressions with it. +// +// WHAT THIS DOES NOT DO: move enforcement. `witnesses` remains the aggregation job and the one +// required context the ruleset names, produced exactly as before, so the gate is unchanged and no +// window opens. The lane contexts are published and ignored until an operator names them in the +// ruleset -- a repository setting no wall in this repository can constrain. Until that edit lands +// the aggregator is still what gates; after it, the aggregator's role is diagnosis rather than +// enforcement, because a same-run dependent job is SKIPPED when a lane fails or the run is +// cancelled at run level, and a SKIPPED required context does not block a merge (measured: +// `mergeable=MERGEABLE mergeStateStatus=UNSTABLE`), while root jobs carrying no `needs` edge take +// cancelled/success/failure and are never skipped. +data floor_lane_job_id: String = "required-witnesses-floor" + +data build_lane_job_id: String = "required-witnesses-build" + +data required_lanes_gate_build_var: String = "BUILD" + +data required_lanes_gate_floor_var: String = "FLOOR" + +data required_lanes_gate_build_class_var: String = "BUILD_CLASS" + +data required_lanes_gate_floor_class_var: String = "FLOOR_CLASS" + +// THE REQUIRED LANE ROSTER, AND IT IS ONE ROSTER READ TWICE RATHER THAN TWO LISTS THAT AGREE. +// +// The gate's verdict and the step's `env` block are the same fact asked in two directions -- which +// jobs decide the merge -- and they were previously two hand-kept lists whose agreement nothing +// checked. A lane present here but absent from `needs` reads an unset variable; a lane in `needs` +// but absent here is a job that runs and cannot block. Both are silent. Deriving both surfaces +// from this row makes the second state unwritable and leaves only the `needs` edge to keep in +// step, which is the one edge GitHub owns rather than us. +// +// NON-EMPTY BY CONSTRUCTION -- see `gunbc.witness_floor_lanes` `RequiredLane` for why an empty +// roster is a fail-open rather than a degenerate case. +fn required_lanes_roster() -> FreeSemigroup { + FreeSemigroup { + head: RequiredLane { + job_id: build_lane_job_id, + label: "build", + var_name: required_lanes_gate_build_var, + class_var_name: required_lanes_gate_build_class_var + }, + tail: [ + RequiredLane { + job_id: floor_lane_job_id, + label: "floor", + var_name: required_lanes_gate_floor_var, + class_var_name: required_lanes_gate_floor_class_var + } + ] + } +} + +// ═══════════════════════════════════════════════════════════════════════════════════════════ +// ADDING A JOB TO THIS LIST REQUIRES OPERATOR SIGN-OFF. IT IS NOT AN ORDINARY EDIT. +// ═══════════════════════════════════════════════════════════════════════════════════════════ +// A job here is not a line of configuration, it is a standing claim on a runner that someone pays +// for, on every push and every pull request, forever. This list was SEVEN on 2026-09-04 and the +// fleet could not serve seven: the required check's wall is the max over its lanes, so jobs that +// gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was +// what people waited on. The 2026-09-04 operator ruling cut `rust-unit-tests`, `fabric-evidence` +// and `emit-copy-qualification-battery` on that basis; the drop rows carry what each cut cost. +// +// SO THE ROSTER IS CLOSED TO GROWTH BY DEFAULT, and an author proposing a new lane owes the +// operator three things BEFORE the edit, not in review of it: the MEASURED wall of the job on a +// fleet runner (not an estimate, and not a timeout, which says nothing about what the aggregate +// waits for); what its RED DISCRIMINATES -- a lane that reds for host or shared reasons is worse +// added than absent, because it converts a known-uninformative signal into repository-wide noise; +// and why the check cannot be a STEP on a lane that already checks out and builds this tree, which +// is where every one of these jobs' preludes is otherwise paid a second time. +// +// THAT LAST QUESTION IS THE ONE THAT ACTUALLY SHRINKS THIS LIST. A separate job buys isolation and +// a separate verdict, and it costs a whole checkout, toolchain install and release build of the +// same tree. `rust_clippy_all_targets_step` is the worked example: it kept its step id, its +// verdict and its coverage, and stopped costing a job, by moving onto `required-witnesses-build`. +// +// THE SECOND WORKED EXAMPLE, AND ITS SIGN-OFF (operator decision msg_6e36a6a2, 2026-09-23, which +// supersedes msg_4a9045fc and the ~20 min pricing of msg_f1ade7cf-77e4-4896-a8b3-476747692c37). +// This file's build lane -- the stage0 mirrors' generated-artifact and regen-fixed-point phases, +// which no job had run since #11742 -- returns as ONE merge_group-only STEP on the emitted floor +// job (gunbc.compiler_gate_workflow compiler_gate_stage0_regen_step), not as a job: that job +// already checks out and builds claim_executor, and the lane measured 22.5 min on the fleet (run +// 35890770775), fitting after the floor process exits. The sign-off covers exactly that step on +// that event; it admits no per-PR run and no new job. SUPERSEDED TWICE since: operator ruling +// 2026-09-27 moved the step onto its own `generated` job beside the floor, and operator ruling +// 2026-09-28 runs it on every event, pull requests included (gunbc.compiler_gate_workflow +// compiler_gate_stage0_regen_condition), because a pull request that failed it still entered the +// queue and failed every group stacked on it. +// +// THIS COMMENT IS RATIONALE, NOT A GATE. No `Accepted` program reads it, so it stops nobody -- +// it records WHY the roster is small so the next author meets the reasoning rather than +// rediscovering the outage. The construction that would make an over-budget roster unwritable is +// a runner-wall budget refused at emit time, and it is not built; until it is, this is diligence. +// +// THE AGGREGATE IS DELIBERATELY NOT A MEMBER. It checks out nothing and runs no witness: it reads +// the other lanes' results. Every consumer of this list is asking about lanes that carry a subject, +// and the aggregate joined that population only as something to filter back out. +type WitnessFloorLane = WitnessFloorBuildLane | WitnessFloorFloorLane + +fn witness_floor_lane_roster() -> FreeSemigroup { + FreeSemigroup { + head: WitnessFloorBuildLane, + tail: [WitnessFloorFloorLane] + } +} + +// THE IDENTITY PROJECTION IS NARROW ON PURPOSE. A witness deciding which jobs exist must not +// materialize every job's steps (and therefore the compiler-floor command) merely to read ids. +// Both this projection and the materialized jobs derive from `witness_floor_lane_roster`, so an +// added lane cannot enter one without entering the other. +fn witness_floor_lane_job_id(lane: WitnessFloorLane) -> String { + match lane { + WitnessFloorBuildLane => build_lane_job_id + WitnessFloorFloorLane => floor_lane_job_id + } +} + +fn witness_floor_lane_job_ids() -> List { + list_map(xs: non_empty_to_list(xs: witness_floor_lane_roster()), f: fn(lane) { + witness_floor_lane_job_id(lane: lane) + }) +} diff --git a/dag/gunbc/witness/witness_floor_workflow.dag b/dag/gunbc/witness/witness_floor_workflow.dag index 4523d89951f..83ec9d79221 100644 --- a/dag/gunbc/witness/witness_floor_workflow.dag +++ b/dag/gunbc/witness/witness_floor_workflow.dag @@ -64,7 +64,16 @@ import gunbc.merge_admission_produce { ci_repo_root_shell } import gunbc.ci_layer_roots { witness_layer_roots } import gunbc.fabric_witness_run { witnesses_lane_run_command, witnesses_lane_measurement_command, build_lane_run_command } import extdeps.exec.command { ArgvCommand, shell_command_render } -import gunbc.required_lanes_gate { RequiredLane, required_lanes_gate_stmts } +import gunbc.required_lanes_gate { required_lanes_gate_stmts } +import gunbc.witness_floor_lanes { + floor_lane_job_id, + build_lane_job_id, + required_lanes_roster, + WitnessFloorLane, + WitnessFloorBuildLane, + WitnessFloorFloorLane, + witness_floor_lane_roster, +} import gunbc.ci_failure_class { wrap_command_with_floor_attempt_receipt, wrap_command_is_renderable, @@ -194,44 +203,6 @@ import std.types { Bool, List, String, Int } // names which lane to open. data witness_floor_workflow_job_id: String = "witnesses" -// THE LANE JOB IDS ARE THEIR OWN DECLARATIONS, AND UN-FUSING THEM FROM THE LANE WORDS IS THE WHOLE -// OF THIS CHANGE. -// -// WHY A UNIQUE NAME IS NEEDED AT ALL. A GitHub required status check names a CONTEXT, and a -// context is the job's name -- which workflow published it is not part of the name. So `build` is -// not a name this repository owns: `gunbc.fleet_converge_workflow` declares a job whose id is also -// exactly `build`, and a rule naming `build` names two jobs in two workflows, answered by -// whichever green arrives. Enforcement cannot move onto a lane job until that lane's context is -// unique across every workflow emitted here. -// -// WHY THE NAME IS NOT COMPUTED FROM THE LANE WORD -- the modeling content, not a spelling -// preference. `build_lane_job_id` was DEFINED AS `required_ci_lane_build`, which read as single -// authority because the two strings coincided. They are two facts with different authorities and -// consumers: the LANE WORD is a CLI argument this workflow passes to `claim_executor -// --required-lane`, owned by `gunbc.fabric_witness_run` and consumed by an exhaustive -// `RequiredCiPhase::lane` match inside the binary; the JOB ID is a GitHub required-context name, -// owned here and consumed by a repository ruleset that is not a `.dag` fact at all. Their -// coincidence was the accident, not the authority. Deriving the job id from the lane word -- -// including by concatenating a prefix -- re-fuses them through a different door and in the -// dangerous direction: a lane rename, an ordinary CLI-vocabulary edit, would silently move a -// REQUIRED CONTEXT NAME and a check would stop being required with nothing going red. The rows -// below are therefore spelled, and every reference to a job id in this file is taken FROM these -// declarations rather than typed, so a rename here moves the `needs` list and the `needs.*.result` -// expressions with it. -// -// WHAT THIS DOES NOT DO: move enforcement. `witnesses` remains the aggregation job and the one -// required context the ruleset names, produced exactly as before, so the gate is unchanged and no -// window opens. The lane contexts are published and ignored until an operator names them in the -// ruleset -- a repository setting no wall in this repository can constrain. Until that edit lands -// the aggregator is still what gates; after it, the aggregator's role is diagnosis rather than -// enforcement, because a same-run dependent job is SKIPPED when a lane fails or the run is -// cancelled at run level, and a SKIPPED required context does not block a merge (measured: -// `mergeable=MERGEABLE mergeStateStatus=UNSTABLE`), while root jobs carrying no `needs` edge take -// cancelled/success/failure and are never skipped. -data floor_lane_job_id: String = "required-witnesses-floor" - -data build_lane_job_id: String = "required-witnesses-build" - // The workflow's own name, hoisted to a declaration because a second consumer now joins on // it. gunbc.fleet_desired_admission refuses a workflow_run payload whose workflow_name is // not the required floor's; spelling "witnesses" a second time there would fork the name @@ -2317,40 +2288,6 @@ fn required_lanes_run_id_expression() -> String { // serializes -> the gate; gate rejects but the refusal serializes -> the refusal, which stops every // run loudly; both reject -> ABSENT, and `expected_witness_floor_yml` refuses to emit any yaml at // all. A `Rejected` fold can therefore never reach a published step. -data required_lanes_gate_build_var: String = "BUILD" -data required_lanes_gate_floor_var: String = "FLOOR" -data required_lanes_gate_build_class_var: String = "BUILD_CLASS" -data required_lanes_gate_floor_class_var: String = "FLOOR_CLASS" - -// THE REQUIRED LANE ROSTER, AND IT IS ONE ROSTER READ TWICE RATHER THAN TWO LISTS THAT AGREE. -// -// The gate's verdict and the step's `env` block are the same fact asked in two directions -- which -// jobs decide the merge -- and they were previously two hand-kept lists whose agreement nothing -// checked. A lane present here but absent from `needs` reads an unset variable; a lane in `needs` -// but absent here is a job that runs and cannot block. Both are silent. Deriving both surfaces -// from this row makes the second state unwritable and leaves only the `needs` edge to keep in -// step, which is the one edge GitHub owns rather than us. -// -// NON-EMPTY BY CONSTRUCTION -- see `RequiredLane` in `gunbc.required_lanes_gate` for why an empty -// roster is a fail-open rather than a degenerate case. -fn required_lanes_roster() -> FreeSemigroup { - FreeSemigroup { - head: RequiredLane { - job_id: build_lane_job_id, - label: "build", - var_name: required_lanes_gate_build_var, - class_var_name: required_lanes_gate_build_class_var - }, - tail: [ - RequiredLane { - job_id: floor_lane_job_id, - label: "floor", - var_name: required_lanes_gate_floor_var, - class_var_name: required_lanes_gate_floor_class_var - } - ] - } -} data required_lanes_gate_pull_request_var: String = "PULL_REQUEST" data required_lanes_gate_event_name_var: String = "EVENT_NAME" data required_lanes_gate_measured_head_var: String = "MEASURED_HEAD" @@ -2566,59 +2503,6 @@ fn witness_floor_triggers() -> List { ] } -// ═══════════════════════════════════════════════════════════════════════════════════════════ -// ADDING A JOB TO THIS LIST REQUIRES OPERATOR SIGN-OFF. IT IS NOT AN ORDINARY EDIT. -// ═══════════════════════════════════════════════════════════════════════════════════════════ -// A job here is not a line of configuration, it is a standing claim on a runner that someone pays -// for, on every push and every pull request, forever. This list was SEVEN on 2026-09-04 and the -// fleet could not serve seven: the required check's wall is the max over its lanes, so jobs that -// gated nothing were displacing the ones that do, and the queue -- not any lane's own cost -- was -// what people waited on. The 2026-09-04 operator ruling cut `rust-unit-tests`, `fabric-evidence` -// and `emit-copy-qualification-battery` on that basis; the drop rows carry what each cut cost. -// -// SO THE ROSTER IS CLOSED TO GROWTH BY DEFAULT, and an author proposing a new lane owes the -// operator three things BEFORE the edit, not in review of it: the MEASURED wall of the job on a -// fleet runner (not an estimate, and not a timeout, which says nothing about what the aggregate -// waits for); what its RED DISCRIMINATES -- a lane that reds for host or shared reasons is worse -// added than absent, because it converts a known-uninformative signal into repository-wide noise; -// and why the check cannot be a STEP on a lane that already checks out and builds this tree, which -// is where every one of these jobs' preludes is otherwise paid a second time. -// -// THAT LAST QUESTION IS THE ONE THAT ACTUALLY SHRINKS THIS LIST. A separate job buys isolation and -// a separate verdict, and it costs a whole checkout, toolchain install and release build of the -// same tree. `rust_clippy_all_targets_step` is the worked example: it kept its step id, its -// verdict and its coverage, and stopped costing a job, by moving onto `required-witnesses-build`. -// -// THE SECOND WORKED EXAMPLE, AND ITS SIGN-OFF (operator decision msg_6e36a6a2, 2026-09-23, which -// supersedes msg_4a9045fc and the ~20 min pricing of msg_f1ade7cf-77e4-4896-a8b3-476747692c37). -// This file's build lane -- the stage0 mirrors' generated-artifact and regen-fixed-point phases, -// which no job had run since #11742 -- returns as ONE merge_group-only STEP on the emitted floor -// job (gunbc.compiler_gate_workflow compiler_gate_stage0_regen_step), not as a job: that job -// already checks out and builds claim_executor, and the lane measured 22.5 min on the fleet (run -// 35890770775), fitting after the floor process exits. The sign-off covers exactly that step on -// that event; it admits no per-PR run and no new job. SUPERSEDED TWICE since: operator ruling -// 2026-09-27 moved the step onto its own `generated` job beside the floor, and operator ruling -// 2026-09-28 runs it on every event, pull requests included (gunbc.compiler_gate_workflow -// compiler_gate_stage0_regen_condition), because a pull request that failed it still entered the -// queue and failed every group stacked on it. -// -// THIS COMMENT IS RATIONALE, NOT A GATE. No `Accepted` program reads it, so it stops nobody -- -// it records WHY the roster is small so the next author meets the reasoning rather than -// rediscovering the outage. The construction that would make an over-budget roster unwritable is -// a runner-wall budget refused at emit time, and it is not built; until it is, this is diligence. -// -// THE AGGREGATE IS DELIBERATELY NOT A MEMBER. It checks out nothing and runs no witness: it reads -// the other lanes' results. Every consumer of this list is asking about lanes that carry a subject, -// and the aggregate joined that population only as something to filter back out. -type WitnessFloorLane = WitnessFloorBuildLane | WitnessFloorFloorLane - -fn witness_floor_lane_roster() -> FreeSemigroup { - FreeSemigroup { - head: WitnessFloorBuildLane, - tail: [WitnessFloorFloorLane] - } -} - fn witness_floor_lane_job(lane: WitnessFloorLane) -> Job { match lane { WitnessFloorBuildLane => build_lane_job() @@ -2632,23 +2516,6 @@ fn witness_floor_lane_jobs() -> List { }) } -// THE IDENTITY PROJECTION IS NARROW ON PURPOSE. A witness deciding which jobs exist must not -// materialize every job's steps (and therefore the compiler-floor command) merely to read ids. -// Both this projection and the materialized jobs derive from `witness_floor_lane_roster`, so an -// added lane cannot enter one without entering the other. -fn witness_floor_lane_job_id(lane: WitnessFloorLane) -> String { - match lane { - WitnessFloorBuildLane => build_lane_job_id - WitnessFloorFloorLane => floor_lane_job_id - } -} - -fn witness_floor_lane_job_ids() -> List { - list_map(xs: non_empty_to_list(xs: witness_floor_lane_roster()), f: fn(lane) { - witness_floor_lane_job_id(lane: lane) - }) -} - data witness_floor_workflow: Workflow = { name: witness_floor_workflow_name, run_name: none, diff --git a/dag/test/claim/deleted_lanes_countable_witness_test.dag b/dag/test/claim/deleted_lanes_countable_witness_test.dag new file mode 100644 index 00000000000..1b566ff1985 --- /dev/null +++ b/dag/test/claim/deleted_lanes_countable_witness_test.dag @@ -0,0 +1,46 @@ +module test.claim.deleted_lanes_countable_witness_test + +import std.types { Bool, List, String } +import v2.std.algebra { non_empty_to_list } +import gunbc.witness_floor_lanes { required_lanes_roster, witness_floor_lane_job_ids } + +// THE FABRIC LANE STILL RUNS AND NO LONGER GATES, AND THIS ROW ASSERTS BOTH HALVES. +// +// It replaces w_RED_fabric_evidence_executes_without_gating, whose subject was the lane still +// EXECUTING while `gunbc.rung_drop` `fabric_evidence_gating` withheld only its merge block. The +// 2026-09-04 runner-capacity ruling deleted the job itself, so that row asserted a fact that is +// deliberately no longer true. It is not retired as obsolete -- the lane's restoration is still +// the drop's trigger -- it is restated at the subject the drop now covers. +// +// SO THE CLAIM IS ABSENCE AT THE TYPED PRODUCERS rather than after whole-workflow serialization. +// A diff that re-adds any deleted job authors RED here; so does one that restores only the +// FABRIC_EVIDENCE roster binding, because a lane that gates without running is the fail-open a +// skipped required check produces. The row goes green again only together with the drop's +// retirement, which is a measured wall and not a pull request. +// +// PERMANENT AFTER OBSERVED RED (DESIGN 4b(4)). Run 33924210916 supplied `fabric-evidence` and +// observed this exact identity return Bool(false). This probe is therefore a regression control, +// not scaffolding: keep it enrolled for as long as any of the citing rung drops stands. +// `required-v2-native` joined the deleted set 2026-09-11 (gunbc.rung_drop +// v2_native_route_off_the_merge_path): its ~4h wall on every push, with no supersession, +// starved the two lanes that gate. Re-adding it into the same envelope authors RED here. +// POSITIVE-CONTROL SEAM: the countable must author RED when a deleted lane is supplied. Without +// this input boundary, a planned/pass receipt would not distinguish a live absence wall from a +// vacuous projection that always returned an empty list. +fn deleted_lane_job_ids_are_absent(job_ids: List) -> Bool { + !any(xs: job_ids, predicate: fn(job_id) { + job_id == "fabric-evidence" + || job_id == "rust-unit-tests" + || job_id == "emit-copy-qualification-battery" + || job_id == "required-v2-native" + }) +} + +test fn w_RED_the_deleted_lanes_do_not_return() -> Bool { + deleted_lane_job_ids_are_absent(job_ids: witness_floor_lane_job_ids()) + && !deleted_lane_job_ids_are_absent(job_ids: ["fabric-evidence"]) + && !deleted_lane_job_ids_are_absent(job_ids: ["required-v2-native"]) + && !any(xs: non_empty_to_list(xs: required_lanes_roster()), predicate: fn(lane) { + lane.var_name == "FABRIC_EVIDENCE" || lane.var_name == "V2_NATIVE" + }) +} diff --git a/dag/test/claim/discovery_census_witness_test.dag b/dag/test/claim/discovery_census_witness_test.dag index 01e0dc50f5d..68fa12bf065 100644 --- a/dag/test/claim/discovery_census_witness_test.dag +++ b/dag/test/claim/discovery_census_witness_test.dag @@ -36,7 +36,7 @@ import gunbc.discovery_census { import v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, DeclinedCostDebt, - DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, + DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, required_floor_site_disposition, } import v2.workflow.floor_terminal_ledger { ClaimDisposition, Passed } @@ -218,6 +218,7 @@ test fn w_fixture_home_declines_with_its_matched_prefix() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -234,6 +235,7 @@ test fn w_long_home_module_declines_with_its_matched_prefix() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -253,6 +255,7 @@ test fn w_long_home_is_a_prefix_not_a_substring() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -269,6 +272,7 @@ test fn w_site_is_planned_when_no_home_matched() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -279,8 +283,8 @@ test fn w_site_is_planned_when_no_home_matched() -> Bool { // row, rather than a synthetic neighbour, so removing its exact-module gate admission reds. test fn w_deleted_lane_countable_is_planned_by_the_required_gate() -> Bool { match required_floor_site_disposition( - module_path: "test.claim.witness_floor_workflow_consolidation_witness_test", - identity: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_deleted_lanes_do_not_return" + module_path: "test.claim.deleted_lanes_countable_witness_test", + identity: "test.claim.deleted_lanes_countable_witness_test.w_RED_the_deleted_lanes_do_not_return" ) { Planned => true DeclinedLongModule { matched_prefix: _ } => false @@ -289,6 +293,7 @@ test fn w_deleted_lane_countable_is_planned_by_the_required_gate() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -308,6 +313,7 @@ test fn w_site_outside_the_required_gate_is_declined() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } @@ -367,6 +373,7 @@ test fn w_rostered_identity_declines_for_cost_debt() -> Bool { DeclinedOutsideRequiredGate => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false Planned => false DeclinedLongModule { matched_prefix: _ } => false DeclinedFixtureMember { matched_prefix: _ } => false @@ -389,6 +396,7 @@ test fn w_unrostered_sibling_in_the_same_module_reaches_the_gate_decline() -> Bo DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false DeclinedLongModule { matched_prefix: _ } => false DeclinedFixtureMember { matched_prefix: _ } => false PlannedAsChangedWitness => false @@ -410,6 +418,7 @@ test fn w_home_decline_outranks_cost_debt() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false Planned => false DeclinedFixtureMember { matched_prefix: _ } => false PlannedAsChangedWitness => false @@ -459,6 +468,7 @@ test fn w_planned_and_outside_gate_rows_partition_once_each() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false }) && all(split.declined, r => match r.disposition { @@ -469,6 +479,7 @@ test fn w_planned_and_outside_gate_rows_partition_once_each() -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false }) } @@ -605,3 +616,23 @@ test fn w_derived_aggregate_is_satisfiable_against_standings() -> Bool { } } } + +// THE MODELED CENSUS CLASSIFIES A DeclinedNoCiWetLane ROW (gunbc#12794's arm, now in the .dag +// type): it is counted in its own bucket and partitioned as declined, never as planned. +test fn the_census_counts_a_declined_no_ci_wet_lane_row_in_its_own_bucket() -> Bool { + let real = census_rows_of(sites: [ + hermetic_site(module_path: "v2.test.claim.bootstrap", function: "bootstrap_witness_keystone_holds") + ]) + let rows = map(real, r => CensusRow { + label: r.label, + disposition: DeclinedNoCiWetLane { pattern: "bootstrap_test.dag" } + }) + let counts = census_counts(rows: rows) + let split = census_partition(rows: rows) + count(rows) == 1 + && counts.declined_no_ci_wet_lane == 1 + && counts.declined_discovery_excluded == 0 + && counts.offered == 1 + && count(split.declined) == 1 + && count(split.planned) == 0 +} diff --git a/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag b/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag index d0154ad4326..fd1a0a84101 100644 --- a/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag +++ b/dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag @@ -38,9 +38,9 @@ data missing_arm_coproduct_source: String = "module exhaust_missing\ntype Trio = // The negative omits exactly `DeclinedOutsideRequiredGate`; the positive differs only by // including it. Both name every later arm so growth in the imported authority makes these // controls fail closed instead of changing which omission the negative measures. -data imported_projected_missing_arm_source: String = "module exhaust_imported_projected_missing\nimport v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, DeclinedCostDebt, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded }\ntype Row { disposition: RequiredFloorDisposition }\nfn f(row: Row) -> Bool {\n match row.disposition {\n Planned => true\n PlannedAsChangedWitness => true\n DeclinedLongModule { matched_prefix: _ } => false\n DeclinedFixtureMember { matched_prefix: _ } => false\n DeclinedCostDebt => false\n DeclinedOutsideGateClosure => false\n DeclinedDiscoveryExcluded { matched_substring: _ } => false\n }\n}\n" +data imported_projected_missing_arm_source: String = "module exhaust_imported_projected_missing\nimport v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, DeclinedCostDebt, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane }\ntype Row { disposition: RequiredFloorDisposition }\nfn f(row: Row) -> Bool {\n match row.disposition {\n Planned => true\n PlannedAsChangedWitness => true\n DeclinedLongModule { matched_prefix: _ } => false\n DeclinedFixtureMember { matched_prefix: _ } => false\n DeclinedCostDebt => false\n DeclinedOutsideGateClosure => false\n DeclinedDiscoveryExcluded { matched_substring: _ } => false\n DeclinedNoCiWetLane { pattern: _ } => false\n }\n}\n" -data imported_projected_exhaustive_source: String = "module exhaust_imported_projected_complete\nimport v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, DeclinedCostDebt, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded }\ntype Row { disposition: RequiredFloorDisposition }\nfn f(row: Row) -> Bool {\n match row.disposition {\n Planned => true\n PlannedAsChangedWitness => true\n DeclinedLongModule { matched_prefix: _ } => false\n DeclinedFixtureMember { matched_prefix: _ } => false\n DeclinedOutsideRequiredGate => false\n DeclinedCostDebt => false\n DeclinedOutsideGateClosure => false\n DeclinedDiscoveryExcluded { matched_substring: _ } => false\n }\n}\n" +data imported_projected_exhaustive_source: String = "module exhaust_imported_projected_complete\nimport v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedOutsideRequiredGate, DeclinedCostDebt, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane }\ntype Row { disposition: RequiredFloorDisposition }\nfn f(row: Row) -> Bool {\n match row.disposition {\n Planned => true\n PlannedAsChangedWitness => true\n DeclinedLongModule { matched_prefix: _ } => false\n DeclinedFixtureMember { matched_prefix: _ } => false\n DeclinedOutsideRequiredGate => false\n DeclinedCostDebt => false\n DeclinedOutsideGateClosure => false\n DeclinedDiscoveryExcluded { matched_substring: _ } => false\n DeclinedNoCiWetLane { pattern: _ } => false\n }\n}\n" fn non_exhaustive_blocking_count(source: String) -> Int { match compile_dag_diagnostic_census(source) { diff --git a/dag/test/claim/required_lane_claim_agreement_witness_test.dag b/dag/test/claim/required_lane_claim_agreement_witness_test.dag index 7ce72358e14..d5529291a6c 100644 --- a/dag/test/claim/required_lane_claim_agreement_witness_test.dag +++ b/dag/test/claim/required_lane_claim_agreement_witness_test.dag @@ -14,7 +14,7 @@ import test.fixture.required_lane_claim.stale_claim_fixture { stale_claim_fixture_documents, stale_claim_fixture_rostered_job_ids, } -import gunbc.witness_floor_workflow { RequiredLane, required_lanes_roster } +import gunbc.witness_floor_lanes { RequiredLane, required_lanes_roster } import gunbc.design_document { expected_design_md } import gunbc.design_ledgers { expected_design_failure_modes_md, expected_design_rung_drops_md } diff --git a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag index e40d35b0b08..288b00fa8f9 100644 --- a/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag +++ b/dag/test/claim/witness_floor_workflow_consolidation_witness_test.dag @@ -3,7 +3,8 @@ module test.claim.witness_floor_workflow_consolidation_witness_test import std.types { Bool, List, String } import v2.std.algebra { count_where, length, non_empty_to_list } import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } -import gunbc.witness_floor_workflow { expected_witness_floor_yml, WitnessFloorGenerated, WitnessFloorGenerationRefused, build_lane_job_id, floor_lane_job_id, witness_floor_workflow_job_id, required_ci_measurement_publish_condition, required_ci_measurement_bound_steps, witness_floor_run_step, required_lanes_roster, witness_floor_lane_job_ids, build_lane_needs, witness_floor_lane_needs, ci_heal_expected_healed_sha_input_name, WitnessFloorGroupFixture, DispatchInputBinding, resolve_witness_floor_concurrency_group, WitnessFloorGroupResolved, WitnessFloorGroupRefused, evaluate_against_group_fixture, witness_floor_pull_request_activity_types, witness_floor_group_expression, witness_floor_triggers } +import gunbc.witness_floor_workflow { expected_witness_floor_yml, WitnessFloorGenerated, WitnessFloorGenerationRefused, witness_floor_workflow_job_id, required_ci_measurement_publish_condition, required_ci_measurement_bound_steps, witness_floor_run_step, build_lane_needs, witness_floor_lane_needs, ci_heal_expected_healed_sha_input_name, WitnessFloorGroupFixture, DispatchInputBinding, resolve_witness_floor_concurrency_group, WitnessFloorGroupResolved, WitnessFloorGroupRefused, evaluate_against_group_fixture, witness_floor_pull_request_activity_types, witness_floor_group_expression, witness_floor_triggers } +import gunbc.witness_floor_lanes { build_lane_job_id, floor_lane_job_id, required_lanes_roster } import gunbc.fabric_witness_run { required_ci_lane_build, required_ci_lane_witnesses } import gunbc.required_lanes_gate { required_lanes_gate_unrenderable_stmts } import gunbc.fleet_converge_workflow { fleet_converge_workflow } @@ -312,47 +313,6 @@ test fn w_RED_neither_lane_waits_on_the_other() -> Bool { ) == 1 } -// THE FABRIC LANE STILL RUNS AND NO LONGER GATES, AND THIS ROW ASSERTS BOTH HALVES. -// -// It replaces w_RED_fabric_evidence_executes_without_gating, whose subject was the lane still -// EXECUTING while `gunbc.rung_drop` `fabric_evidence_gating` withheld only its merge block. The -// 2026-09-04 runner-capacity ruling deleted the job itself, so that row asserted a fact that is -// deliberately no longer true. It is not retired as obsolete -- the lane's restoration is still -// the drop's trigger -- it is restated at the subject the drop now covers. -// -// SO THE CLAIM IS ABSENCE AT THE TYPED PRODUCERS rather than after whole-workflow serialization. -// A diff that re-adds any deleted job authors RED here; so does one that restores only the -// FABRIC_EVIDENCE roster binding, because a lane that gates without running is the fail-open a -// skipped required check produces. The row goes green again only together with the drop's -// retirement, which is a measured wall and not a pull request. -// -// PERMANENT AFTER OBSERVED RED (DESIGN 4b(4)). Run 33924210916 supplied `fabric-evidence` and -// observed this exact identity return Bool(false). This probe is therefore a regression control, -// not scaffolding: keep it enrolled for as long as any of the citing rung drops stands. -// `required-v2-native` joined the deleted set 2026-09-11 (gunbc.rung_drop -// v2_native_route_off_the_merge_path): its ~4h wall on every push, with no supersession, -// starved the two lanes that gate. Re-adding it into the same envelope authors RED here. -// POSITIVE-CONTROL SEAM: the countable must author RED when a deleted lane is supplied. Without -// this input boundary, a planned/pass receipt would not distinguish a live absence wall from a -// vacuous projection that always returned an empty list. -fn deleted_lane_job_ids_are_absent(job_ids: List) -> Bool { - !any(xs: job_ids, predicate: fn(job_id) { - job_id == "fabric-evidence" - || job_id == "rust-unit-tests" - || job_id == "emit-copy-qualification-battery" - || job_id == "required-v2-native" - }) -} - -test fn w_RED_the_deleted_lanes_do_not_return() -> Bool { - deleted_lane_job_ids_are_absent(job_ids: witness_floor_lane_job_ids()) - && !deleted_lane_job_ids_are_absent(job_ids: ["fabric-evidence"]) - && !deleted_lane_job_ids_are_absent(job_ids: ["required-v2-native"]) - && !any(xs: non_empty_to_list(xs: required_lanes_roster()), predicate: fn(lane) { - lane.var_name == "FABRIC_EVIDENCE" || lane.var_name == "V2_NATIVE" - }) -} - // THE GATE RUNS FOR EVERY ATTEMPT, INCLUDING A CANCELLED ONE, AND THEN REFUSES A NON-SUCCESS // LANE. // diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index c26c0f3a28e..cb117deb681 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -48,7 +48,7 @@ Required floor cost — **RUNG DROP, DECLARED (2026-09-01).** SUBJECT: per-claim ### Emitted-bytes fixture witnesses in a required lane — declared 2026-09-01 -UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_workflow` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger. +UN-RETIRED 2026-09-04. This row was retired on 2026-09-02 by gunbc#10078 because arm (i) of its trigger fired: `rust-unit-tests` was promoted into the required aggregate, so the witness executed on the real acceptance path. The 2026-09-04 runner-capacity ruling DELETED that job -- see `gunbc.rung_drop` `rust_unit_tests_off_the_merge_path` -- so arm (i) has un-fired and arm (ii), a substrate-visible emitted-bytes probe surface, was never built. The class is therefore back below its declared previous rung and the drop stands again. THE RETIREMENT ADJUDICATION IS KEPT VERBATIM BELOW rather than deleted, because it is the record of what was true when it was made and of exactly which fact stopped being true: everything it establishes about the witness being un-ignored and about the runner-fault class being retired by toolchain-home isolation REMAINS CORRECT. What changed is not the evidence quality, it is that no required lane executes the command any more. Retiring this row a second time needs arm (i) restored under a supply the fleet actually has, or arm (ii) built; re-reading the adjudication below is not sufficient. FORMER trigger_fired: 2026-09-02 by gunbc#10078, both conjuncts of arm (i) adjudicated rather than assumed. FIRST CONJUNCT -- PROMOTED: `gunbc.witness_floor_lanes` `required_lanes_roster` carries `rust_unit_tests_job_id` beside the build and floor lanes, so the emitted aggregate reads `needs: [required-witnesses-build, required-witnesses-floor, rust-unit-tests]` AND reads `$UNIT` in both verdict folds -- the second half is what grants blocking authority, a `needs` alone would only have added a wait. The repository ruleset makes `witnesses` the one required context, so this lane now gates every merge transitively. SECOND CONJUNCT -- THE RUNNER-FAULT CLASS IS RETIRED BY CONSTRUCTION, NOT PRICED. The 2026-09-01 measurement's two failures were the shared-runner `$HOME`/cargo-shim class: concurrent runner slots sharing one toolchain home. Every job of the emitted workflow now carries an `Isolate toolchain homes` prelude that wipes and repoints HOME/CARGO_HOME/RUSTUP_HOME under `$RUNNER_TEMP`, so the sharing the class needs does not occur. MEASURED AGAINST THAT CONSTRUCTION RATHER THAN ASSERTED FROM IT, 2026-09-03 over the witnesses workflow's most recent 100 runs: 55 `rust-unit-tests` jobs had concluded -- 52 success, 3 failure, 2 cancelled -- and EVERY ONE of the three failures is about the diff or is a designed refusal (two `clippy, all targets` reds on the same branch's `type_occurrence_binding_census.rs`, one heal-revalidation preflight refusing a run subject that does not name the expected healed SHA). ZERO runner-environment faults, against the ~8 percent this row declared. THE INSTRUMENT IS NAMED AND THE FIGURES ARE NOT THE CLAIM: re-derive with `gh api repos/OWNER/REPO/actions/workflows/witnesses.yml/runs` then `/actions/runs//jobs` selecting the `rust-unit-tests` job, and read each failure's FAILING STEP -- a conclusion count alone cannot separate a fault class from a defect, which is the whole question this conjunct asks. AND THE WITNESS ACTUALLY EXECUTES: `emit_import_lines_follow_resolved_binding_identity` is emitted into `compiler_tests.rs` as a plain `#[test]` with NO `#[ignore]`, so `cargo test --release -p v1-compiler --lib` runs it on the acceptance path. WHAT THIS DOES NOT RETIRE: the REASON clause stays true -- no substrate-visible surface exposes emitted bytes to a `dag/test/claim` witness -- so arm (ii) is unbuilt and the population is held at the required rung by a Rust-hosted test rather than by the floor. That is a standing modeling gap, not a rung drop, and it is not re-declared here. --- **DECLARED AGAIN 2026-09-04; the 2026-09-02 retirement is un-done and is recorded above.** The witness this row was declared about now executes on the real acceptance path, so the emission-follows-resolution class sits at its declared previous rung again and this drop is debt that no longer exists. The adjudication of both trigger conjuncts is carried in `trigger_fired` rather than restated here. The declaration below is kept verbatim because it is the record of what was true when it was made; `standing` carries what is true now. Witness enrollment — **RUNG DROP, DECLARED (2026-09-01, gunbc#9850 witness enrollment).** PREVIOUS RUNG: none to lower — this declares that the mechanically-preventable rung for the emission-follows-resolution class (the 139-row use-line shadow repaired in gunbc#9850) is held by a test OUTSIDE the required aggregate. TEMPORARY RUNG: the discriminating RED and positive controls are enrolled as `emit_import_lines_follow_resolved_binding_identity` in `v1.compiler.compiler_tests_rust`, emitted into `compiler_tests.rs` and executed by `repo_self_test_command` (`cargo test --release -p v1-compiler --lib`) in the `rust-unit-tests` job of `gunbc.witness_floor_workflow` — which runs on every push and pull request but is NOT a `needs` of the required aggregate, so a regression reddens a visible job without blocking the merge. REASON: no substrate-visible surface exposes EMITTED BYTES to a `dag/test/claim` witness (the host census builtin carries diagnostics only), so the assertion is inexpressible in the required floor today; promoting `rust-unit-tests` to required was measured 2026-09-01 at 23/25 recent completions green with both failures runner-environment faults (shared-runner `$HOME`/cargo-shim class) — an ~8% infra-noise rate ruled too high to make 612 tests merge-blocking fleet-wide tonight. POPULATION: the emission-follows-resolution witness matrix (String RED, structural-Bool and non-kernel controls) plus every other `compiler_tests` row asserting on emitted bytes. RESTORATION TRIGGER, named at capability grain: a required-lane capability SUFFICIENT to execute, on the real acceptance path, a fixture assertion that a named `pub use` line is ABSENT from emitted bytes for a sole-exporter structural type resolved to a host-realized kernel scalar, and PRESENT for a structural kernel carrying a connective (Bool = True | False) — via either (i) `rust-unit-tests` promoted into the required aggregate after its runner-fault class is retired or priced, or (ii) a substrate-visible emitted-bytes probe surface admitted under the scaffold doctrine. A surface that can read emitted bytes but cannot discriminate those two cases does NOT satisfy this trigger. ### Direct-call argument TYPE-COMPAT judgment inside v2.* modules (one of two arms; inhabitance still runs) — declared 2026-09-01 · RETIRED @@ -128,11 +128,11 @@ CORRECTION NOTICE, recorded because the wrong version travelled: an earlier revi ### Fabric CI evidence lane as a required merge block, and then as a lane at all — declared 2026-08-31 -**CORRECTED 2026-09-28: THE CALIBRATION SCRIPT WAS DELETED AND THEN RESTORED, AND THE LANE WAS NOT.** The amendment below said the 2026-09-04 ruling deleted `tools/fabric_ci_evidence_calibration.sh`. #10390 did delete it on 2026-09-04. #10270 (FCI-1) re-added it on 2026-09-05, and it is live: `tools/fabric_ci_fci1_live_instrument.sh` runs it against the exact binary before any srv3 observation. The original sentence is QUOTED, not deleted, because the record of what was claimed is the point: 'together with fabric_ci_evidence_calibration_step, its two derived bounds, and tools/fabric_ci_evidence_calibration.sh'. WHAT THE CORRECTION CHANGES: only the script clause. The script now runs only when an operator invokes the FCI-1 live instrument by hand, on no CI trigger. WHAT IT DOES NOT CHANGE: the `fabric-evidence` job, the calibration step and the FABRIC_EVIDENCE binding are still absent from every emitted workflow. `w_RED_the_deleted_lanes_do_not_return` still guards that absence. A red from a hand-invoked run is still not a merge wall, so the temporary rung (outside the modeled guarantee for merges), the population and the restoration trigger all stand unchanged. The script is its own scaffold with its own dissolution condition in its header; this row does not govern it. **AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows. +**CORRECTED 2026-09-28: THE CALIBRATION SCRIPT WAS DELETED AND THEN RESTORED, AND THE LANE WAS NOT.** The amendment below said the 2026-09-04 ruling deleted `tools/fabric_ci_evidence_calibration.sh`. #10390 did delete it on 2026-09-04. #10270 (FCI-1) re-added it on 2026-09-05, and it is live: `tools/fabric_ci_fci1_live_instrument.sh` runs it against the exact binary before any srv3 observation. The original sentence is QUOTED, not deleted, because the record of what was claimed is the point: 'together with fabric_ci_evidence_calibration_step, its two derived bounds, and tools/fabric_ci_evidence_calibration.sh'. WHAT THE CORRECTION CHANGES: only the script clause. The script now runs only when an operator invokes the FCI-1 live instrument by hand, on no CI trigger. WHAT IT DOES NOT CHANGE: the `fabric-evidence` job, the calibration step and the FABRIC_EVIDENCE binding are still absent from every emitted workflow. `w_RED_the_deleted_lanes_do_not_return` still guards that absence. A red from a hand-invoked run is still not a merge wall, so the temporary rung (outside the modeled guarantee for merges), the population and the restoration trigger all stand unchanged. The script is its own scaffold with its own dissolution condition in its header; this row does not govern it. **AMENDED 2026-09-04: THE LANE NO LONGER EXECUTES EITHER, AND THIS ROW NOW COVERS BOTH LOSSES.** The 2026-09-04 operator ruling on runner capacity deleted the `fabric-evidence` JOB, together with `fabric_ci_evidence_calibration_step`, its two derived bounds, and `tools/fabric_ci_evidence_calibration.sh`. The declaration below was written when only the merge block was withdrawn and the calibration still ran; read every present-tense claim in it about the lane EXECUTING in the past tense. WHAT CHANGES: the temporary rung falls from mitigatable to outside the modeled guarantee — there is no longer a red for a human to read, because there is no run. WHAT DOES NOT: the restoration trigger, which was already stated at capability grain and is unchanged, and the operational consequence, which now binds harder — the FABRIC-CI program (warm-seal-35) agreed to check `fabric-evidence` explicitly on every head rather than inferring it from `witnesses`, and there is now nothing to check, so any conclusion resting on that lane rests on nothing. THE ROW IS AMENDED RATHER THAN SUPERSEDED because the subject is the same lane and the same trigger retires both losses; a second row would have split one subject across two authorities. The countability moved: `w_RED_fabric_evidence_executes_without_gating` asserted the lane still ran and is replaced by `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return`, which reds if the job, the FABRIC_EVIDENCE binding or the calibration argv returns while this row stands. The original declaration follows. **THE FABRIC-CI EVIDENCE LANE STOPS BLOCKING MERGES AND KEEPS EXECUTING (2026-08-31).** #9704 added `fabric-evidence` as a fourth job and, in the same change, made it a `needs` of the aggregating `witnesses` job that the `passing CI` ruleset names as this repository's one required context. PREVIOUS RUNG: mechanically preventable — a defect in the FCI-EVIDENCE-0 run-boundary contract was exposed by an enrolled calibration and blocked the merge. TEMPORARY RUNG: mitigatable — the same calibration still runs on every push and pull request, still refuses loudly, and its log is still the record; what is gone is the block, so a red is now a signal a human must read rather than a wall. REASON, and it is wall clock rather than doubt about the evidence: the required context's wall is the MAX over its three lanes, and on run 33350499023 that max was `fabric-evidence` at 27 minutes against 20 for the floor lane and 10.5 for the build lane, having moved the required wall from ~13 minutes to ~28-40 within a day of #9704 landing. 1469 of those 1620 seconds are the calibration step, and its own logs put all ~18 of the plan's `gunbc run` host processes at 80-90 seconds each. That cost is not the evidence: the instrument's import closure is six modules, and per `cli_run.entry_resolve` an `--entry` run is scoped in what it EMITS but WHOLE-TREE in what it PARSES, so each process re-parses and re-censuses the entire 4414-module corpus to evaluate a handful of rows. The lane is paying eighteen whole-corpus censuses (DESIGN §2 duplicated work) for thirteen assertions. Batching them is NOT the repair and is not what this row defers: the calibration-timeout derivation recorded that distinct host processes ARE the process-edge subject (that row was deleted with the lane on 2026-09-04; its reasoning is preserved in this sentence), so fewer processes would remove the boundary rather than observe it more cheaply. BOUNDED POPULATION: exactly one job, `fabric-evidence`, and exactly one lost edge — its `needs.fabric-evidence.result` binding into the aggregate's closed-vocabulary verdict fold. No other lane, phase, witness or claim changes rung; the build and floor lanes keep every edge they had, and the calibration keeps every assertion it had. The drop is countable from the emitted workflow: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_fabric_evidence_executes_without_gating` reds if the job stops executing, and reds again if either gating spelling returns while this row still stands. ONE OPERATIONAL CONSEQUENCE, recorded here because it is the kind of practice that quietly stops once the person who agreed to it moves on. With the needs edge withdrawn, a `fabric-evidence` failure no longer reaches the aggregate verdict, so any lane that was reading the required context as a proxy for that lane's health is now reading a context that cannot see it. The FABRIC-CI program (warm-seal-35) accepted the drop on that basis and will check `fabric-evidence` EXPLICITLY on every head rather than inferring it from `witnesses`. Anyone else joining on the required context owes the same explicit check for as long as this row stands; that obligation ends when the trigger below is met and not before. RESTORATION TRIGGER: the CAPABILITY of a single fabric evidence process resolving its entry against the source roots at a cost that fits the required wall budget — concretely, the whole-tree parse and name census being paid once per tree state rather than once per host process, so that the 13-row plan executes its full process-edge roster inside the lane's share of a ~10-minute required wall. THIS IS NOT RETIRED BY THE MEMO PR MERGING. It is retired by a measured `fabric-evidence` job wall that leaves the required context at or under its budget with the needs edge and the FABRIC_EVIDENCE binding restored, which is the only thing that makes the block affordable again. Reducing the plan's process count, relaxing what a row asserts, or moving the calibration to a cadence does not satisfy this trigger — the first removes the subject, and the other two are different drops that would need their own rows. ### The v1 crate's Rust unit tests, and their job, on every CI path — declared 2026-09-04 -**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row. ENROLMENT 2026-09-08 (gunbc#10822): this change adds `v1_compiler.cli_run.rostered_row_join` `file_roster_join_tests` to that `--lib` population. The restoration trigger is unchanged and covers them: they are `--lib` tests, so runner supply sufficient to execute that population restores them with the rest. HOSTED MEASUREMENT LANE DELETED (operator ruling 2026-09-29): the `rust-unit-tests` job that ran this population non-blocking on `ubuntu-24.04-arm` (2026-09-27 to 2026-09-29) is removed from `gunbc.compiler_gate_workflow`. Its continue_on_error step reported success on every run while two tests were red on main, so it executed the population without exposing it and did not climb this row; its deletion returns CI to exactly the state this row declares. The restoration trigger is unchanged. +**THE RUST UNIT TESTS LEAVE CI ENTIRELY; THE ALL-TARGETS LINT DOES NOT (2026-09-04).** gunbc#10078 promoted `rust-unit-tests` into `required_lanes_roster`, making `cargo test --release -p v1-compiler --lib` and `cargo clippy --all-targets -- -D warnings` merge-blocking. The 2026-09-04 operator ruling on runner capacity deletes the JOB. The two commands are separated rather than dropped together, and that separation is the whole of this row. PREVIOUS RUNG: mechanically preventable — a regression in any of the 774 `#[test]`s under src/v1/stage0 was exposed by an enrolled test and blocked the merge through the aggregate's `$UNIT` verdict fold. TEMPORARY RUNG: mitigatable, and only barely — the tests still exist, still refuse loudly, and `cargo test --release -p v1-compiler --lib` still runs them, but NO CI STEP EXECUTES THEM, so they run when a human chooses to and not otherwise. This is the exact state gunbc#9663 was created to end, and #9886's two failing tests landing on main with every required check green is the measured harm of it; that harm is re-admitted knowingly here, not rediscovered. WHAT IS NOT DROPPED, and a reader must not infer it from the job's absence: `repo_self_clippy_command` moved to `required-witnesses-build` as `rust_clippy_all_targets_step`, keeping its step id, its verdict and its position on a REQUIRED lane. That command is the only one on any CI path that compiles the integration-test and example targets — twelve of them sat red on main (2026-08-30) behind a green required run — so dropping it would have been a below-baseline floor regression under DESIGN §4b rather than a declared drop, and the ruling did not ask for it. REASON, and it is runner supply rather than doubt about the tests: the witnesses workflow carried seven jobs against a fleet that could not serve seven, each paying its own checkout, toolchain install and release build of one tree. The required context's wall is the MAX over its lanes, so contention among jobs that could have been steps was displacing the lanes that gate. The unit tests were cut rather than folded into an existing lane because the ruling asked for the Rust test population to leave CI, not to be relocated; folding them would have preserved the cost this row exists to remove. BOUNDED POPULATION: every `#[test]` in the v1-compiler crate reached by `--lib`, and every witness whose enrollment routed through that command — including `emit_import_lines_follow_resolved_binding_identity`, whose own drop row `emitted_bytes_witness_required_lane` was RETIRED on the strength of this lane being required and is un-retired in the same motion. No other lane, phase or claim changes rung; the build and floor lanes keep every edge they had. COUNTABLE: `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns while this row stands, and `test.claim.required_lane_claim_agreement_witness_test` `w_the_live_roster_is_read_and_carries_both_lanes` asserts its absence from the roster at identity grain. RESTORATION TRIGGER, named at capability grain and not as an artifact: RUNNER SUPPLY SUFFICIENT to execute the v1-compiler `--lib` test population on the real acceptance path within the required context's wall budget, concurrently with the build and floor lanes and without displacing either — concretely, a fleet that admits a third required lane at the observed unit-test wall without raising the max over lanes. THIS IS NOT RETIRED BY SOMEONE RE-ADDING THE JOB, which the roster comment in `gunbc.witness_floor_workflow` now requires operator sign-off for; a job re-added into the same shortage reproduces the contention that caused the cut. Nor is it retired by running the tests somewhere unmeasured, or on a cadence — a cadence is a different drop and would need its own row. ENROLMENT 2026-09-08 (gunbc#10822): this change adds `v1_compiler.cli_run.rostered_row_join` `file_roster_join_tests` to that `--lib` population. The restoration trigger is unchanged and covers them: they are `--lib` tests, so runner supply sufficient to execute that population restores them with the rest. HOSTED MEASUREMENT LANE DELETED (operator ruling 2026-09-29): the `rust-unit-tests` job that ran this population non-blocking on `ubuntu-24.04-arm` (2026-09-27 to 2026-09-29) is removed from `gunbc.compiler_gate_workflow`. Its continue_on_error step reported success on every run while two tests were red on main, so it executed the population without exposing it and did not climb this row; its deletion returns CI to exactly the state this row declares. The restoration trigger is unchanged. ### The witness floor as a required merge gate — declared 2026-09-20 @@ -152,7 +152,7 @@ Required lanes do not resolve product-layer modules: a module outside the nomina ### The EMIT-COST-QUAL-0 wet battery's only sanctioned executing consumer — declared 2026-09-04 -**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: "false"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `"false"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.witness_floor_workflow_consolidation_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair. +**THE EMIT-COST-QUAL-0 BATTERY LOSES ITS ONLY SANCTIONED CONSUMER (2026-09-04).** `emit-copy-qualification-battery` shipped with `if_condition: "false"` under the ROOT-N division ruling of 2026-08-31, holding one activation token for the #9769 chain. The 2026-09-04 runner-capacity ruling spent that token on DELETION rather than activation: the job is removed from `gunbc.witness_floor_workflow` instead of having its `"false"` lifted. PREVIOUS RUNG: none was held — the job never executed, so the honest previous state is the declared standing that it WOULD execute on activation, with its `claim_batch --functions` line named as `gunbc.emit_copy_qualification_wet_battery`'s only sanctioned consumer. TEMPORARY RUNG: outside the modeled guarantee, which is deliberately not a rung — the battery's wet shards and its five instrument-falsifier mutants are now specification without execution in the sense DESIGN §5 names, and no row in `test.claim.emit_copy_qualification_witness_test` establishes anything about a running system. REASON: the job cost a roster slot and a permanently-skipped entry in the emitted workflow while establishing nothing, and under a runner shortage the cheapest honest disposition of a lane that has never run is to delete it rather than to keep holding a slot for it. Note what this did NOT save, because the opposite would be an inflated claim: the job was skipped, so it consumed no runner time and the deletion buys no capacity. What it buys is a roster that means what it says. BOUNDED POPULATION: `gunbc.emit_copy_qualification_wet_battery` — the six wet carrier shards and six calibration rows named in the deleted argv — plus the three workflow-subject rows removed from its witness file. `gunbc.emit_copy_qualification`, `gunbc.emit_copy_qualification_fixture_gen` and `tools.emit_copy_qualification_transport` keep whatever consumers they had; this row does not speak for them. COUNTABLE: `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return` reds if the job returns. RESTORATION TRIGGER, at capability grain: the battery's assertions EXECUTING on the real acceptance path as floor-enrolled `*_test.dag` witnesses — which is the same conversion the deleted job's own dissolution row demanded and never got, now with nothing else holding the module up. The blocker it named is real and unchanged: `v2.workflow.floor_changed_witness` refuses a changed witness identity with no terminal floor verdict, and these wet transactions route-gap hermetically (`IsExecutable`, `NoMockResponse`), so the trigger is the capability to give a hermetically route-gapped wet transaction a terminal floor verdict. RE-ADDING A JOB DOES NOT SATISFY IT and now requires operator sign-off besides; a battery that can only be executed by a lane nobody will fund is the state this row records, not the repair. ### Required-floor merge-blocking authority for witnesses at or above 219 cpu-ms — declared 2026-09-04 @@ -230,7 +230,7 @@ admission rows on falsifier-family cadences with no scheduled route, awaiting tr ### The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane — declared 2026-09-11 -The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane: RUNG DROP, mechanically preventable -> mitigatable (deleted without replacement). Population: gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate, the derived v2.test.* universe executed by the emitted-native compiler (positive population), v2.native_lane_fixture.control native_lane_false_control / native_lane_true_control (live-verdict controls), fixtures/native_lane_malformed/poison.dag.poisoned (malformed-specimen control), the old-route-withdrawn (no-fallback) control. Restored when: THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.witness_floor_workflow_consolidation_witness_test w_RED_the_deleted_lanes_do_not_return. +The v2 native route (emitted-native compiler over the derived v2.test.* universe) as a required CI lane: RUNG DROP, mechanically preventable -> mitigatable (deleted without replacement). Population: gunbc.witness_v2_native_route native_route_admission — every receipt clause, on every merge candidate, the derived v2.test.* universe executed by the emitted-native compiler (positive population), v2.native_lane_fixture.control native_lane_false_control / native_lane_true_control (live-verdict controls), fixtures/native_lane_malformed/poison.dag.poisoned (malformed-specimen control), the old-route-withdrawn (no-fallback) control. Restored when: THE FIRST GREEN merge_group RUN OF THE `emit-build` LANE (gunbc.compiler_gate_workflow compiler_gate_emit_build_job_id) AS A REQUIRED LANE -- its compiler_gate_lane_rows row LaneBlocks and the job on the fleet runner -- IN WHICH THAT LANE ALSO EXECUTES //gunbc/instruments:v2-native-frontier over the derived v2.test.* universe on the merge_group revision and publishes its [native-frontier-roster] proposal with tested_tree = that merge_group sha. Its receipt (run id, job id, tested tree, measured wall on the fleet runner class) becomes `trigger_fired`. Sufficient for: execution of the native route on every landing, inside the lane's declared timeout on the real runner class (a measured wall, not a cited one), with supersession so no head holds more than one native claimant, and a red that still discriminates every clause of gunbc.witness_v2_native_route native_route_admission -- universe join, a positive population held to a FLOOR rather than to non-emptiness (gunbc.witness_v2_native_route native_route_required_pass_identities enrols the identities that pass natively at that head -- it holds only the one smoke member at this writing, so a run whose population regressed to that member would still be admitted), classified refusals, per-identity agreement with the floor reference, and all four controls, with the live false/true pair OBSERVED at native_route_live_pair_standing = LivePairRequired (gunbc.rung_drop.native_lane_live_pair_expected_red retired first or in the same change). NOT sufficient, and named so it cannot be mistaken for the trigger: a green run of the lane with only //gunbc/instruments:self-host and //gunbc/instruments:v2-native-cli, required or not -- those emit and build the native compiler and CLI but execute none of the v2.test.* universe this row lists. Re-adding `required-v2-native` with its 2026-09-10 shape does not retire this row and is refused by test.claim.deleted_lanes_countable_witness_test w_RED_the_deleted_lanes_do_not_return. ### The v2 native frontier (the ratchet over the emitted-native route's refusals) runs on no merge candidate and on no schedule until the required native-route lane is live — declared 2026-09-23 diff --git a/src/v2/compiler/effect_demand_floor_join.dag b/src/v2/compiler/effect_demand_floor_join.dag index a5602d334eb..512efc0b1ea 100644 --- a/src/v2/compiler/effect_demand_floor_join.dag +++ b/src/v2/compiler/effect_demand_floor_join.dag @@ -26,6 +26,7 @@ import v2.workflow.floor_discovery_producer { discover_floor_corpus_rows_from_ho import v2.workflow.floor_discovery_source_authority { FloorDiscoveryAccepted, FloorDiscoveryProducerResult, FloorDiscoveryRefused } import v2.workflow.required_floor { DeclinedCostDebt, + DeclinedNoCiWetLane, DeclinedFixtureMember, DeclinedLongModule, DeclinedOutsideRequiredGate, @@ -75,6 +76,7 @@ type FloorStandingCounts { declined_outside_gate_closure: Int declined_discovery_excluded: Int declined_cost_debt: Int + declined_no_ci_wet_lane: Int } // EVERY WAY THE POPULATION CAN BE WRONG IS AN ARM, AND NONE OF THEM IS A SKIP. An entry the walk found @@ -156,20 +158,22 @@ fn floor_join_counts_zero() -> FloorStandingCounts { declined_outside_required_gate: 0, declined_outside_gate_closure: 0, declined_discovery_excluded: 0, - declined_cost_debt: 0 + declined_cost_debt: 0, + declined_no_ci_wet_lane: 0 } } fn floor_join_counts_add(c: FloorStandingCounts, d: RequiredFloorDisposition) -> FloorStandingCounts { match d { - Planned => FloorStandingCounts { offered: c.offered + 1, planned: c.planned + 1, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - PlannedAsChangedWitness => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness + 1, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - DeclinedLongModule { matched_prefix } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module + 1, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - DeclinedFixtureMember { matched_prefix } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member + 1, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - DeclinedOutsideRequiredGate => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate + 1, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - DeclinedOutsideGateClosure => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure + 1, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt }, - DeclinedDiscoveryExcluded { matched_substring } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded + 1, declined_cost_debt: c.declined_cost_debt }, - DeclinedCostDebt => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt + 1 } + Planned => FloorStandingCounts { offered: c.offered + 1, planned: c.planned + 1, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + PlannedAsChangedWitness => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness + 1, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedLongModule { matched_prefix } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module + 1, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedFixtureMember { matched_prefix } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member + 1, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedOutsideRequiredGate => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate + 1, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedOutsideGateClosure => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure + 1, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedDiscoveryExcluded { matched_substring } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded + 1, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedCostDebt => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt + 1, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane }, + DeclinedNoCiWetLane { pattern } => FloorStandingCounts { offered: c.offered + 1, planned: c.planned, planned_as_changed_witness: c.planned_as_changed_witness, declined_long_module: c.declined_long_module, declined_fixture_member: c.declined_fixture_member, declined_outside_required_gate: c.declined_outside_required_gate, declined_outside_gate_closure: c.declined_outside_gate_closure, declined_discovery_excluded: c.declined_discovery_excluded, declined_cost_debt: c.declined_cost_debt, declined_no_ci_wet_lane: c.declined_no_ci_wet_lane + 1 } } } diff --git a/src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag b/src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag index be0975aa550..e5773d27c3f 100644 --- a/src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag +++ b/src/v2/test/claim/effect_demand/effect_demand_floor_join_test.dag @@ -22,7 +22,7 @@ import v2.std.logic { Bool } import v2.std.text { String } import v2.workflow.floor_discovery_row { FloorDiscoveryRow } import v2.workflow.required_floor { - DeclinedCostDebt, + DeclinedCostDebt, DeclinedNoCiWetLane, DeclinedFixtureMember, DeclinedLongModule, DeclinedOutsideRequiredGate, @@ -122,9 +122,9 @@ test fn floor_join_witness_an_unreached_entry_is_excluded_not_refused() -> Bool test fn floor_join_witness_standing_is_the_floors_own_rule() -> Bool { let j = probe_join() - probe_disposition_of(join: j, identity: "test.claim.infer_probe_a.t_a", expected: fn(d) { match d { Planned => true, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false } }) - && probe_disposition_of(join: j, identity: "v2.test.long.probe_c.t_c", expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => matched_prefix == "v2.test.long.", DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false } }) - && probe_disposition_of(join: j, identity: "test.claim.probe_d.t_d", expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => true, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false } }) + probe_disposition_of(join: j, identity: "test.claim.infer_probe_a.t_a", expected: fn(d) { match d { Planned => true, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false, DeclinedNoCiWetLane { pattern } => false } }) + && probe_disposition_of(join: j, identity: "v2.test.long.probe_c.t_c", expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => matched_prefix == "v2.test.long.", DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false, DeclinedNoCiWetLane { pattern } => false } }) + && probe_disposition_of(join: j, identity: "test.claim.probe_d.t_d", expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => true, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => false, DeclinedNoCiWetLane { pattern } => false } }) } test fn floor_join_witness_cost_debt_arm_is_reached_from_the_policy_roster() -> Bool { @@ -134,7 +134,7 @@ test fn floor_join_witness_cost_debt_arm_is_reached_from_the_policy_roster() -> probe_disposition_of( join: effect_demand_floor_join(discovered: rows, nodes: nodes, edges: edges, seam_modules: probe_seam_modules, owned_data_records_supplied: 0), identity: "test.claim.belt_tick_receipt_home_witness.the_belt_member_bootstraps_its_own_receipts_directory", - expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => true } } + expected: fn(d) { match d { Planned => false, PlannedAsChangedWitness => false, DeclinedLongModule { matched_prefix } => false, DeclinedFixtureMember { matched_prefix } => false, DeclinedOutsideRequiredGate => false, DeclinedOutsideGateClosure => false, DeclinedDiscoveryExcluded { matched_substring } => false, DeclinedCostDebt => true, DeclinedNoCiWetLane { pattern } => false } } ) } diff --git a/src/v2/test/floor_changed_witness_test.dag b/src/v2/test/floor_changed_witness_test.dag index 24caa1f7245..d72286bc18d 100644 --- a/src/v2/test/floor_changed_witness_test.dag +++ b/src/v2/test/floor_changed_witness_test.dag @@ -5,6 +5,7 @@ import v2.workflow.wet_evidence { WetEvidenceBinding, CoResidentPreparedSubject, } +import v2.std.optional { Present, Absent } import v2.workflow.floor_changed_witness { ChangedWitnessExecutionStanding, HermeticRouteGapWetEvidence, HermeticRouteGapWetUnavailable, HermeticRouteGapWetAdmitted, @@ -19,6 +20,7 @@ import v2.workflow.floor_changed_witness { ChangedWitnessRow, changed_witness_execution_standing, changed_witness_standing_blocks, + changed_witness_decline_blocks, ChangedWitnessBlocker, changed_witness_blocking_cause, changed_witness_blockers, @@ -26,7 +28,7 @@ import v2.workflow.floor_changed_witness { import v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, - DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, + DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, DeclinedCostDebt, required_floor_disposition_with_changed_selection, ChangedWitnessCostPolicy, OrdinaryChangedWitnessCostPolicy, ChangedCostDebtVerdictOnly, @@ -183,6 +185,7 @@ test fn changed_selector_replaces_an_ordinary_decline_with_its_own_planned_arm() match required_floor_disposition_with_changed_selection( ordinary: DeclinedOutsideGateClosure {}, selected_as_changed_witness: true, + declared_wet_pattern: Absent {}, ) { PlannedAsChangedWitness => true Planned => false @@ -192,6 +195,7 @@ test fn changed_selector_replaces_an_ordinary_decline_with_its_own_planned_arm() DeclinedCostDebt => false DeclinedFixtureMember { matched_prefix: _ } => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false } } @@ -199,6 +203,7 @@ test fn unchanged_identity_keeps_its_ordinary_disposition() -> Bool { match required_floor_disposition_with_changed_selection( ordinary: DeclinedOutsideGateClosure {}, selected_as_changed_witness: false, + declared_wet_pattern: Absent {}, ) { DeclinedOutsideGateClosure => true Planned => false @@ -208,6 +213,7 @@ test fn unchanged_identity_keeps_its_ordinary_disposition() -> Bool { DeclinedCostDebt => false DeclinedFixtureMember { matched_prefix: _ } => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false } } @@ -966,3 +972,32 @@ test fn a_short_module_changed_pass_is_an_ordinary_pass() -> Bool { ) ) == "planned-and-passed" } + +// THE MODELED DECIDER CLASSIFIES A DECLARED BinWitnessWet SELECTION AS DeclinedNoCiWetLane, the +// arm the seed's required_floor_runner already decides (gunbc#12794); before this the .dag type had +// no such arm, so the modeled census could not say what the floor did. +test fn a_selected_declared_bin_wet_row_is_declined_no_ci_wet_lane() -> Bool { + match required_floor_disposition_with_changed_selection( + ordinary: Planned {}, + selected_as_changed_witness: true, + declared_wet_pattern: Present { value: "bootstrap_test.dag" }, + ) { + DeclinedNoCiWetLane { pattern: p } => p == "bootstrap_test.dag" + Planned => false + PlannedAsChangedWitness => false + DeclinedLongModule { matched_prefix: _ } => false + DeclinedFixtureMember { matched_prefix: _ } => false + DeclinedOutsideRequiredGate => false + DeclinedOutsideGateClosure => false + DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedCostDebt => false + } +} + +// THE DECLINE IS THE ONE THAT DOES NOT BLOCK, AND ONLY IT: the declared loss is the rung drop, and +// every other decline of a changed witness still blocks. +test fn the_no_ci_wet_lane_decline_does_not_block_and_other_declines_do() -> Bool { + !changed_witness_decline_blocks(disposition: DeclinedNoCiWetLane { pattern: "bootstrap_test.dag" }) + && changed_witness_decline_blocks(disposition: DeclinedDiscoveryExcluded { matched_substring: "x" }) + && changed_witness_decline_blocks(disposition: DeclinedOutsideGateClosure {}) +} diff --git a/src/v2/test/required_floor_gate_selector_test.dag b/src/v2/test/required_floor_gate_selector_test.dag index 7743ff7f970..725eb94a782 100644 --- a/src/v2/test/required_floor_gate_selector_test.dag +++ b/src/v2/test/required_floor_gate_selector_test.dag @@ -3,7 +3,7 @@ module v2.test.required_floor_gate_selector import v2.workflow.required_floor { RequiredFloorDisposition, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, - DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, + DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, DeclinedCostDebt, required_floor_site_disposition, RequiredGateSelector, GateModuleFamily, GateAuthoredModule, @@ -36,6 +36,7 @@ fn site_is_planned(module_path: String) -> Bool { DeclinedCostDebt => false DeclinedOutsideGateClosure => false DeclinedDiscoveryExcluded { matched_substring: _ } => false + DeclinedNoCiWetLane { pattern: _ } => false PlannedAsChangedWitness => false } } diff --git a/src/v2/workflow/floor_changed_witness.dag b/src/v2/workflow/floor_changed_witness.dag index 98109dc4c6e..11a888d9f24 100644 --- a/src/v2/workflow/floor_changed_witness.dag +++ b/src/v2/workflow/floor_changed_witness.dag @@ -4,7 +4,7 @@ import v2.workflow.required_floor { RequiredFloorDisposition, required_floor_disposition_name, Planned, PlannedAsChangedWitness, DeclinedLongModule, DeclinedFixtureMember, DeclinedCostDebt, - DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, + DeclinedOutsideRequiredGate, DeclinedOutsideGateClosure, DeclinedDiscoveryExcluded, DeclinedNoCiWetLane, ChangedWitnessCostPolicy, OrdinaryChangedWitnessCostPolicy, ChangedCostDebtVerdictOnly, } import v2.workflow.floor_terminal_ledger { @@ -313,6 +313,7 @@ fn changed_witness_execution_standing( DeclinedOutsideRequiredGate => Declined { disposition: d } DeclinedOutsideGateClosure => Declined { disposition: d } DeclinedDiscoveryExcluded { matched_substring: _ } => Declined { disposition: d } + DeclinedNoCiWetLane { pattern: _ } => Declined { disposition: d } DeclinedCostDebt => Declined { disposition: d } } } @@ -332,11 +333,28 @@ fn changed_witness_standing_blocks(standing: ChangedWitnessExecutionStanding) -> PlannedWithoutTerminalVerdict => true HermeticRouteGapHeldAndWetPassed { evidence: e, identity: i, candidate: c } => !hermetic_route_gap_wet_join_complete(evidence: e, identity: i, candidate: c) - Declined { disposition: _ } => true + Declined { disposition: d } => changed_witness_decline_blocks(disposition: d) MissingDisposition => true } } +// WHICH DECLINES BLOCK A CHANGED WITNESS: every one, except the declared BinWitnessWet decline, +// whose loss is `gunbc.rung_drop.edited_bin_witness_wet_rows_not_executed_by_ci` and which the PR +// discharges with a real bin_wet receipt. Exhaustive, so a new disposition states its polarity. +fn changed_witness_decline_blocks(disposition: RequiredFloorDisposition) -> Bool { + match disposition { + DeclinedNoCiWetLane { pattern: _ } => false + Planned => true + PlannedAsChangedWitness => true + DeclinedLongModule { matched_prefix: _ } => true + DeclinedFixtureMember { matched_prefix: _ } => true + DeclinedOutsideRequiredGate => true + DeclinedOutsideGateClosure => true + DeclinedDiscoveryExcluded { matched_substring: _ } => true + DeclinedCostDebt => true + } +} + type ChangedWitnessRow { identity: String standing: ChangedWitnessExecutionStanding diff --git a/src/v2/workflow/floor_grandfathered_roster.dag b/src/v2/workflow/floor_grandfathered_roster.dag index b838d600edf..1df1fe8b61d 100644 --- a/src/v2/workflow/floor_grandfathered_roster.dag +++ b/src/v2/workflow/floor_grandfathered_roster.dag @@ -463,7 +463,7 @@ fn floor_grandfathered_chunk_034() -> List { } fn floor_grandfathered_chunk_035() -> List { - Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_push_is_not_grouped_as_a_pr", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_bare_dispatch_to_run_id", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_empty_heal_input_to_run_id", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_heal_dispatch_to_heal_sha", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_merge_group_to_mg_sha", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_pull_request_to_pr_number", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_push_to_github_ref", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_emitted_group_expression_names_each_event_branch", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_floor_measurement_publishes_before_separate_adjudication", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_neither_lane_waits_on_the_other", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_deleted_lanes_do_not_return", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_pull_request_activity_set_excludes_closed", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_pull_request_activity_set_excludes_ready_for_review", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_unmodeled_format_arity_and_base_ref_refuse", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_associativity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_inherit_preserves", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_left_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_identity_preserves", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_left_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_right_bias", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_right_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_override_replaces", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_right_bias", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_right_identity", tail: Cons { head: "v2.test.claim.affected_set_universe.affected_set_universe_gate_processes_match_declared_gates", tail: Empty {} } } } } } } } } } } } } } } } } } } } } } } } } } + Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_push_is_not_grouped_as_a_pr", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_bare_dispatch_to_run_id", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_empty_heal_input_to_run_id", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_heal_dispatch_to_heal_sha", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_merge_group_to_mg_sha", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_pull_request_to_pr_number", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_concurrency_group_resolves_push_to_github_ref", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_emitted_group_expression_names_each_event_branch", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_floor_measurement_publishes_before_separate_adjudication", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_neither_lane_waits_on_the_other", tail: Cons { head: "test.claim.deleted_lanes_countable_witness_test.w_RED_the_deleted_lanes_do_not_return", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_pull_request_activity_set_excludes_closed", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_the_pull_request_activity_set_excludes_ready_for_review", tail: Cons { head: "test.claim.witness_floor_workflow_consolidation_witness_test.w_RED_unmodeled_format_arity_and_base_ref_refuse", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_associativity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_inherit_preserves", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_left_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_identity_preserves", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_left_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_right_bias", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_monoid_right_identity", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_override_replaces", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_right_bias", tail: Cons { head: "v2.test.algebra_laws.field_patch_monoid.witness_right_identity", tail: Cons { head: "v2.test.claim.affected_set_universe.affected_set_universe_gate_processes_match_declared_gates", tail: Empty {} } } } } } } } } } } } } } } } } } } } } } } } } } } fn floor_grandfathered_chunk_036() -> List { diff --git a/src/v2/workflow/required_floor.dag b/src/v2/workflow/required_floor.dag index 5faceaad360..d91bc0e93fb 100644 --- a/src/v2/workflow/required_floor.dag +++ b/src/v2/workflow/required_floor.dag @@ -2,6 +2,7 @@ module v2.workflow.required_floor import v2.std.algebra { Cons, Empty, contains } import v2.std.collection { List } +import v2.std.optional { Optional, Present, Absent } import v2.std.logic { Bool, True, False } import v2.std.integer { Int, int_gt, int_add, int_mul } import v2.workflow.floor_expected_red { floor_expected_red_roster } @@ -125,6 +126,7 @@ type RequiredFloorDisposition = | DeclinedOutsideGateClosure | DeclinedDiscoveryExcluded { matched_substring: String } | DeclinedCostDebt + | DeclinedNoCiWetLane { pattern: String } // THE WIRE NAME OF ONE ARM, HOMED WITH THE COPRODUCT IT NAMES. This spelling is what every // receipt, counter and blocking cause downstream prints, so it is a fact about the arm and not @@ -142,7 +144,8 @@ fn required_floor_disposition_name(d: RequiredFloorDisposition) -> String { DeclinedOutsideRequiredGate => "declined_outside_required_gate", DeclinedOutsideGateClosure => "declined_outside_gate_closure", DeclinedDiscoveryExcluded { matched_substring } => "declined_discovery_excluded", - DeclinedCostDebt => "declined_cost_debt" + DeclinedCostDebt => "declined_cost_debt", + DeclinedNoCiWetLane { pattern } => "declined_no_ci_wet_lane" } } @@ -151,12 +154,22 @@ fn required_floor_disposition_name(d: RequiredFloorDisposition) -> String { // therefore replaces the static gate's answer with one planned arm before execution; every // identity still has exactly one disposition and the ordinary answer is preserved unchanged for // the standing population. +// +// A SELECTED IDENTITY WHOSE FILE IS A DECLARED BinWitnessWet ROW IS DECLINED, NOT PLANNED. No CI +// lane executes that class, so planning it only mints a route gap; `declared_wet_pattern` is the +// BinWitnessWet exclusion pattern the file matched AND that `gunbc.rung_drop` +// `edited_bin_witness_wet_rows_not_executed_by_ci` names in its bounded population, or Absent. +// The seed's `required_floor_runner` decision is the host mirror of THIS function. fn required_floor_disposition_with_changed_selection( ordinary: RequiredFloorDisposition, selected_as_changed_witness: Bool, + declared_wet_pattern: Optional, ) -> RequiredFloorDisposition { if selected_as_changed_witness { - PlannedAsChangedWitness {} + match declared_wet_pattern { + Present { value: p } => DeclinedNoCiWetLane { pattern: p } + Absent => PlannedAsChangedWitness {} + } } else { ordinary } @@ -314,6 +327,7 @@ fn cost_debt_roster_standing(reading: CostDebtDispositionReading) -> CostDebtRos PlannedAsChangedWitness => CostDebtWithholdOverriddenForChangedVerdict {} DeclinedOutsideGateClosure => CostDebtOutsideThisRunsUniverse {} DeclinedDiscoveryExcluded { matched_substring: _ } => CostDebtOutsideThisRunsUniverse {} + DeclinedNoCiWetLane { pattern: _ } => CostDebtOutsideThisRunsUniverse {} Planned => CostDebtDeclaredButNotWithheld {} DeclinedLongModule { matched_prefix: _ } => CostDebtDeclaredButNotWithheld {} DeclinedFixtureMember { matched_prefix: _ } => CostDebtDeclaredButNotWithheld {} @@ -820,6 +834,7 @@ fn required_gate_authored_modules() -> List { "v2.test.claim.coercion.identity_cast_emission_route", "v2.test.execution.self_host_candidate_generation_stage_verdicts", "v2.test.manual.cross_language_add_python_to_typescript", + "test.claim.deleted_lanes_countable_witness_test", ] } @@ -898,7 +913,16 @@ fn required_gate_admits(module_path: String) -> Bool { // depend on which single row someone remembered to enroll. data required_gate_allocation_deploy_seam_note: String = "test.claim.runner_slot_provision is admitted to the required gate because no_deploy_row_out_commits_the_memory_budget is the executable statement of the positive-width law at the allocation-to-deploy seam; it was declined_outside_required_gate at 890c264be36 while srv2 carried a zero-width operational deploy row" -// THE WORKFLOW-CONSOLIDATION MODULE IS ADMITTED AT EXACT MODULE GRAIN. Three declared rung +// THE DELETED-LANES COUNTABLE IS ADMITTED AT EXACT MODULE GRAIN, AS ITS OWN MODULE. Four declared +// rung drops cite `test.claim.deleted_lanes_countable_witness_test` `w_RED_the_deleted_lanes_do_not_return` +// as the countable refusal if a cut CI lane returns. It lived in +// `test.claim.witness_floor_workflow_consolidation_witness_test`, whose import closure is the whole +// workflow emitter; the 2026-09-19 nominal roster withdrew that module for its preparation cost and +// the countable stopped running on any required path. The countable reads only the lane rosters, so +// those moved to `gunbc.witness_floor_lanes` and the claim to its own module: re-admitting it adds +// the rosters' closure, not the emitter's. The history below is the consolidation module's. +// +// (HISTORY) THE WORKFLOW-CONSOLIDATION MODULE WAS ADMITTED AT EXACT MODULE GRAIN. Three declared rung // drops cite its `w_RED_the_deleted_lanes_do_not_return` row as the countable refusal if a cut // CI lane returns. Before this row, the required floor discovered all 12 witnesses in that // module but dispositioned every one `DeclinedOutsideGateClosure`; eight happened also to be diff --git a/src/v2/workflow/required_lane_claim_agreement.dag b/src/v2/workflow/required_lane_claim_agreement.dag index 665d3e8ecb3..b60d740ce72 100644 --- a/src/v2/workflow/required_lane_claim_agreement.dag +++ b/src/v2/workflow/required_lane_claim_agreement.dag @@ -111,7 +111,7 @@ fn document_sites_for_lane(doc: ProjectedDocument, job_id: String) -> List