From 2703794062dfbc19b50451696b2d7a8154703dd8 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 1 Oct 2026 01:35:12 +0000 Subject: [PATCH 1/3] Census of main-latent refusals (part 1): two fixes, one designed-refusal exclusion with its witness - floor_preparation_shared_build_witness_test: the exhaustive match over the preparation phases gains CrossClaimPureProducerWarm (added to the phase type without updating this consumer). - llm_attempt_receipt_witness_test: the zero-denominator fraction is declared at TokenThroughput (FieldOfFractions) rather than constructed bare at the call argument, where its instantiation was inferred from Int literals. - test.fixture.health_read_only.mutation_probe is a designed must-not-resolve fixture consumed parse-only; it gets a floor_prepared_subject_exclusions row and test.claim.fleet.health_read_only_fixture_refusal_witness asserts its refusal by class and subject. Co-Authored-By: Claude Opus 5.5 (1M context) --- ...read_only_fixture_refusal_witness_test.dag | 49 +++++++++++++++++++ ..._preparation_shared_build_witness_test.dag | 1 + .../llm_attempt_receipt_witness_test.dag | 7 ++- .../src/cli_run/required_floor_runner.rs | 7 +++ 4 files changed, 63 insertions(+), 1 deletion(-) create mode 100644 dag/test/claim/fleet/health_read_only_fixture_refusal_witness_test.dag diff --git a/dag/test/claim/fleet/health_read_only_fixture_refusal_witness_test.dag b/dag/test/claim/fleet/health_read_only_fixture_refusal_witness_test.dag new file mode 100644 index 00000000000..64272470889 --- /dev/null +++ b/dag/test/claim/fleet/health_read_only_fixture_refusal_witness_test.dag @@ -0,0 +1,49 @@ +module test.claim.fleet.health_read_only_fixture_refusal_witness + +import std.types { String, Bool, Int, List } +import extdeps.filesystem.filesystem_io +import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } +import gunbc.compile_diagnostic_census { + CompileDiagnosticCensus, CompileDiagnosticCensusRow, CensusObserved, CensusNotRunnable, +} + +data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree + +// THE DESIGNED REFUSAL OF test.fixture.health_read_only.mutation_probe, ASSERTED BY CLASS AND +// SUBJECT. The fixture is the forbidden program the fleet health no-mutation witness derives its +// findings from (test.claim.fleet_health_read_only_witness), and it is consumed PARSE-ONLY: its +// callees are undeclared spellings by design, so it must never resolve. It is therefore excluded +// from the required floor's Strict preparation (floor_prepared_subject_exclusions row +// "test/fixture/health_read_only/"), the same disposition as dag/test/probe/, and this witness is +// what keeps that exclusion honest. It is red if the fixture starts resolving, and red if it +// refuses only for a reason other than its undeclared callees. +// +// FOUND BY the gunbc#12761 widened subject (every admitted module Strict-prepared), which refused +// on this file at 0207c666 with the rest of the 14-file census: no exclusion row covered it, and it +// stayed out of preparation only because nothing imported it. + +data fixture_path: String = "dag/test/fixture/health_read_only/mutation_probe.dag" + +fn fixture_census() -> CompileDiagnosticCensus { + compile_dag_diagnostic_census(filesystem_read(path: fixture_path).content) +} + +fn blocking_count(c: CompileDiagnosticCensus, wanted: String, subject: String) -> Int { + match c { + CensusNotRunnable { cause: _ } => -1 + CensusObserved { rows: rows } => + rows + |> filter(r => (r.diagnostic_class as String) == wanted && r.subject_name == subject && r.blocking) + |> fold(init: 0, f: (acc, r) => acc + r.count) + } +} + +// The undeclared Redfish account callee, the forbidden mutation's own spelling. +test fn the_fixture_still_refuses_on_its_undeclared_account_callee() -> Bool { + blocking_count(c: fixture_census(), wanted: "InternalError", subject: "function:CreateAccount") >= 1 +} + +// The undeclared host-shell provider, the fixture's second forbidden leg. +test fn the_fixture_still_refuses_on_its_undeclared_shell_provider() -> Bool { + blocking_count(c: fixture_census(), wanted: "UnresolvedType", subject: "SshShell") >= 1 +} diff --git a/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag b/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag index d2171573c41..3eb823423f8 100644 --- a/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag +++ b/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag @@ -118,6 +118,7 @@ test fn w_refusal_carries_its_phase() -> Bool { SharedModuleIndexBuild => false BareReferenceEdgeIndexBuild => true LanguagesConsumerCensusBuild => false + CrossClaimPureProducerWarm => false } } } diff --git a/dag/test/claim/llm_attempt_receipt_witness_test.dag b/dag/test/claim/llm_attempt_receipt_witness_test.dag index 1da56efc8f9..2a1f70cb5cc 100644 --- a/dag/test/claim/llm_attempt_receipt_witness_test.dag +++ b/dag/test/claim/llm_attempt_receipt_witness_test.dag @@ -1,6 +1,7 @@ module test.claim.llm_attempt_receipt_witness import gunbc.econ.llm_attempt_receipt { + TokenThroughput, AcceptedGoodputDerived, AcceptedGoodputRefused, ArchitectureJudgment, @@ -194,8 +195,12 @@ test fn zero_decode_duration_refuses_rather_than_fabricating() -> Bool { } } +// The fraction is declared at TokenThroughput (FieldOfFractions), the type the projection +// reads; a bare construct at the call argument infers its own instantiation from the literals. +data zero_denominator_throughput: TokenThroughput = FieldOfFractions { num: 1000, denom: 0 } + test fn zero_denominator_floor_projection_returns_none() -> Bool { - match throughput_per_second_floor(t: FieldOfFractions { num: 1000, denom: 0 }) { + match throughput_per_second_floor(t: zero_denominator_throughput) { none => true Present { value: _ } => false } diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 5e1d13cf0c6..c52657262c5 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -4982,6 +4982,13 @@ pub fn floor_prepared_subject_exclusions() -> Vec { // vanished seed), and `ExclusionOrphansImporter` refuses the day anything imports one. "test/probe/".to_string(), "test/fixture/meta_exec_confinement_scan/".to_string(), + // THE FLEET HEALTH FORBIDDEN PROGRAM. test.fixture.health_read_only.mutation_probe is the + // program the no-mutation witness derives its findings from, consumed PARSE-ONLY: its + // callees are undeclared spellings by design, so it must never resolve. Nothing imports it, + // so it stayed out of preparation by that accident alone until gunbc#12761's widened + // subject prepared it and it refused. Its designed refusal is asserted by class and subject + // in test.claim.fleet.health_read_only_fixture_refusal_witness. + "test/fixture/health_read_only/".to_string(), "test/manual/ownership_movable_test.dag".to_string(), // WET RECEIPT, AND IT HAS NO CI CONSUMER TODAY — stated plainly rather than dressed up // as an enrollment. case4_expansion_carrier_splices dispatches a real jq through From a5dccf62f8c0934de28e8ac0a5e85d8a483789e7 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 1 Oct 2026 03:21:16 +0000 Subject: [PATCH 2/3] Census of main-latent refusals (part 2): the pool-dependent rows from the whole-root run at c95f906 Each refused only when its competing declaration shares the pool, so the per-file resolve was clean and the whole-root compile (neat-boar-16, srv1) was red. Fixed at the earliest boundary, keeping the importless files off the import channel: - std_list_keyed_scan_witness_test declared its own KeyedRow beside std.keyed_row's, a nickname fork; renamed KeyedScanRow, which clears both readers (gunbc.host_converge_delta, keyed_delta_fold_witness_test) without touching them. - build_cache_endpoint_path_test:122 constructs EndpointListening in a list literal, where no expected type selects between gunbc.build_cache_endpoint_path's arm and gunbc.spark.serving_incarnation_observe's; qualified. - srv3_os_install_actuate_workflow_witness_test casts to AttemptIdentity, declared by std.scoped_authorization (the brand meant) and gunbc.runner_microvm_lifecycle (a product); qualified at the six casts. - build_cache_placement_observation_test calls placement_verdict, declared by gunbc.runner.runner_cgroup_placement_receipt and gunbc.build_cache_provision_verdict; qualified to the one returning BuildCacheProvision*. - citation_cit0_witness_test matched CitationTarget.selector (declared Selector?) directly; #12791 made the optional refuse there, so it is unwrapped. Verified by a probe that pulls each competing declarer into one closure: the original files reproduce exactly the whole-root census's 11 errors; the fixed files resolve. Every claim in the touched files returns true. Co-Authored-By: Claude Opus 5.5 (1M context) --- dag/test/claim/build_cache_endpoint_path_test.dag | 2 +- .../claim/build_cache_placement_observation_test.dag | 2 +- dag/test/claim/citation_cit0_witness_test.dag | 10 +++++++--- ...srv3_os_install_actuate_workflow_witness_test.dag | 12 ++++++------ dag/test/claim/std_list_keyed_scan_witness_test.dag | 10 +++++----- 5 files changed, 20 insertions(+), 16 deletions(-) diff --git a/dag/test/claim/build_cache_endpoint_path_test.dag b/dag/test/claim/build_cache_endpoint_path_test.dag index 543c47fdfe4..b735acf354a 100644 --- a/dag/test/claim/build_cache_endpoint_path_test.dag +++ b/dag/test/claim/build_cache_endpoint_path_test.dag @@ -119,7 +119,7 @@ test fn witness_a_tcp_endpoint_has_no_stale_socket_state() -> Bool { test fn witness_the_unconditional_sketch_differs_where_it_is_destructive() -> Bool { let states = [ - EndpointListening { owner: live_owner() }, + gunbc.build_cache_endpoint_path.EndpointListening { owner: live_owner() }, EndpointPathConflict { detail: "regular file" as NonEmptyStr }, ] states |> all(s => unconditional_unlink_sketch(observed: s) && (unlinks(observed: s, currency: current()) == false)) diff --git a/dag/test/claim/build_cache_placement_observation_test.dag b/dag/test/claim/build_cache_placement_observation_test.dag index ddee93ac84a..5a43f0eed3c 100644 --- a/dag/test/claim/build_cache_placement_observation_test.dag +++ b/dag/test/claim/build_cache_placement_observation_test.dag @@ -86,7 +86,7 @@ test fn witness_both_runner_lifecycles_refuse_at_the_verdict() -> Bool { } fn refuses(placement: BuildCacheServerPlacement) -> Bool { - match placement_verdict(catalog_id: sccache_local_id, stats_line: "stats", placement: placement) { + match gunbc.build_cache_provision_verdict.placement_verdict(catalog_id: sccache_local_id, stats_line: "stats", placement: placement) { BuildCacheProvisionRefused { cause: _, reason: _ } => true BuildCacheProvisionConverged { catalog_id: _, stats_line: _ } => false } diff --git a/dag/test/claim/citation_cit0_witness_test.dag b/dag/test/claim/citation_cit0_witness_test.dag index 3495de82325..0a257b8b683 100644 --- a/dag/test/claim/citation_cit0_witness_test.dag +++ b/dag/test/claim/citation_cit0_witness_test.dag @@ -247,9 +247,13 @@ test fn citation_target_carries_pin_and_selector_not_observation() -> Bool { right: witness_citation_pin.subject, ) && match witness_citation_target.selector { - TextQuoteSelectorVariant(_) => true - FragmentSelectorVariant(_) => false - TextPositionSelectorVariant(_) => false + Present { value: s } => + match s { + TextQuoteSelectorVariant(_) => true + FragmentSelectorVariant(_) => false + TextPositionSelectorVariant(_) => false + } + none => false } } diff --git a/dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag index 6308f7546c7..e7d7f09e0da 100644 --- a/dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag +++ b/dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag @@ -39,7 +39,7 @@ fn witness_unreachable_grant() -> OperatorGrant { }, ], purpose: "unreachable" as NonEmptyStr, - attempt: "no-attempt" as AttemptIdentity, + attempt: "no-attempt" as std.scoped_authorization.AttemptIdentity, intent_hash: content_hash_of_value(value: "no-intent" as NonEmptyStr), granted_by: "nobody" as NonEmptyStr, granted_at: "1970-01-01T00:00:00Z", @@ -190,7 +190,7 @@ test fn srv3_grant_refuses_a_different_attempt() -> Bool { scopes: srv3_boot_once_cd_authorization_request.scopes, subject: srv3_boot_once_cd_subject, purpose: srv3_boot_once_cd_authorization_request.purpose, - attempt: "srv3-os-install-actuate-2" as AttemptIdentity, + attempt: "srv3-os-install-actuate-2" as std.scoped_authorization.AttemptIdentity, intent_hash: srv3_boot_once_cd_authorization_request.intent_hash, destructive: true, } @@ -200,7 +200,7 @@ test fn srv3_grant_refuses_a_different_attempt() -> Bool { observed_at: witness_before_expiry, ) { AuthorizationRefused { cause: AuthorizationAttemptMismatch { requested: req, granted: got } } => - req == "srv3-os-install-actuate-2" as AttemptIdentity && got == srv3_boot_once_cd_attempt + req == "srv3-os-install-actuate-2" as std.scoped_authorization.AttemptIdentity && got == srv3_boot_once_cd_attempt _ => false } } @@ -285,7 +285,7 @@ test fn srv3_grant_is_single_use() -> Bool { test fn srv3_grant_excludes_a_concurrent_attempt() -> Bool { let held_by_other = witness_grant_claimed( claim: claim_transition_claimed( - attempt: "srv3-os-install-actuate-99" as AttemptIdentity, + attempt: "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity, at: witness_before_expiry, ), ) @@ -301,7 +301,7 @@ test fn srv3_grant_excludes_a_concurrent_attempt() -> Bool { observed_at: witness_before_expiry, ) { AuthorizationRefused { cause: AuthorizationClaimedByOtherAttempt { requested: r, holder: h } } => - r == srv3_boot_once_cd_attempt && h == "srv3-os-install-actuate-99" as AttemptIdentity + r == srv3_boot_once_cd_attempt && h == "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity _ => false } && srv3_boot_once_cd_is_runnable_with_approval( @@ -319,7 +319,7 @@ test fn srv3_claim_loser_learns_who_holds_it() -> Bool { at: witness_before_expiry, ) let winner = claim_transition_claimed( - attempt: "srv3-os-install-actuate-99" as AttemptIdentity, + attempt: "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity, at: witness_before_expiry, ) let attempt = claim_authorization( diff --git a/dag/test/claim/std_list_keyed_scan_witness_test.dag b/dag/test/claim/std_list_keyed_scan_witness_test.dag index d07915f3d72..21a26b548c0 100644 --- a/dag/test/claim/std_list_keyed_scan_witness_test.dag +++ b/dag/test/claim/std_list_keyed_scan_witness_test.dag @@ -11,18 +11,18 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly // from the other rows sharing its key. A scan returning the right KEYS but the wrong ELEMENT would // pass any claim that read keys only, which is how duplicated_by_key once shipped emitting the second // occurrence while its note promised the first (review 68028). -type KeyedRow { +type KeyedScanRow { key: String payload: String } -fn row(key: String, payload: String) -> KeyedRow { KeyedRow { key: key, payload: payload } } +fn row(key: String, payload: String) -> KeyedScanRow { KeyedScanRow { key: key, payload: payload } } -fn key_of(r: KeyedRow) -> String { r.key } +fn key_of(r: KeyedScanRow) -> String { r.key } -fn payloads(rs: List) -> List { map(rs, r => r.payload) } +fn payloads(rs: List) -> List { map(rs, r => r.payload) } -fn rows() -> List { +fn rows() -> List { [row(key: "a", payload: "a1"), row(key: "b", payload: "b1"), row(key: "a", payload: "a2"), row(key: "c", payload: "c1"), row(key: "b", payload: "b2"), row(key: "a", payload: "a3")] } From c6c44a4e69419559418fbdb31d2b30f8c80b1946 Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Thu, 1 Oct 2026 03:37:48 +0000 Subject: [PATCH 3/3] admitted_module_without_judged_standing: srv3_websocat receipt, red on main 2026-09-04 to 2026-09-30 and seen by no lane First bad commit #10146 (ccc874c840), bisected by execution by clever-lynx-801. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../admitted_module_without_judged_standing.dag | 2 ++ 1 file changed, 2 insertions(+) diff --git a/dag/gunbc/recurring_failure_mode/admitted_module_without_judged_standing.dag b/dag/gunbc/recurring_failure_mode/admitted_module_without_judged_standing.dag index cc9c7084747..656819b5062 100644 --- a/dag/gunbc/recurring_failure_mode/admitted_module_without_judged_standing.dag +++ b/dag/gunbc/recurring_failure_mode/admitted_module_without_judged_standing.dag @@ -64,6 +64,8 @@ data admitted_module_without_judged_standing: RecurringFailureMode = RecurringFa "The next rung requires four capabilities together: (1) one typed standing registry exhaustively binds every first-party ingest identity to required judgment, a verified executing consumer, typed fixture/generated/exclusion, retirement, or orphan standing; (2) each executing-consumer binding is checked against the named consumer's actual roster and execution receipt, so a hollow alias cannot admit it; (3) a changed retained identity resolves only through its named consumer from materialized facts within the required floor's 8-second wall and 500-millisecond CPU envelopes, never by whole-corpus compilation; and (4) the two-direction matched undeclared-field control remains executable.", "At that rung admission makes the invalid state unwritable; until then this remains measurement and an Undecided population, not a defect backlog.)", + + "**A THIRD CONFIRMED MEMBER, RED FOR ALMOST FOUR WEEKS AND SEEN BY NO LANE** (2026-10-01). test.claim.srv3_websocat_sequence_witness has been red on main since 2026-09-04: its first bad commit is gunbc#10146 (ccc874c840), bisected by execution by clever-lynx-801 in quiet-gull-780's v1 checker lane. A seed infer change stopped resolving a bare kernel `join` on a lambda parameter typed by a literal list of call results, and the test file itself did not change. Every required lane stayed green from 2026-09-04 to 2026-09-30, because no lane's closure contained the module. It surfaced only when gunbc#12761's widened subject Strict-prepared every admitted module (fleet run 36751831054). It is in the census of gunbc#12855, and its repair is the infer owner's, not a rewrite of the test. This is the class's harm in its plainest form: a refusal that is real, located and reproducible sat silent for almost four weeks.", ], evidence: [],