Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,8 @@ data admitted_module_without_judged_standing: RecurringFailureMode = RecurringFa
"The next rung requires four capabilities together: (1) one typed standing registry exhaustively binds every first-party ingest identity to required judgment, a verified executing consumer, typed fixture/generated/exclusion, retirement, or orphan standing; (2) each executing-consumer binding is checked against the named consumer's actual roster and execution receipt, so a hollow alias cannot admit it; (3) a changed retained identity resolves only through its named consumer from materialized facts within the required floor's 8-second wall and 500-millisecond CPU envelopes, never by whole-corpus compilation; and (4) the two-direction matched undeclared-field control remains executable.",

"At that rung admission makes the invalid state unwritable; until then this remains measurement and an Undecided population, not a defect backlog.)",

"**A THIRD CONFIRMED MEMBER, RED FOR ALMOST FOUR WEEKS AND SEEN BY NO LANE** (2026-10-01). test.claim.srv3_websocat_sequence_witness has been red on main since 2026-09-04: its first bad commit is gunbc#10146 (ccc874c840), bisected by execution by clever-lynx-801 in quiet-gull-780's v1 checker lane. A seed infer change stopped resolving a bare kernel `join` on a lambda parameter typed by a literal list of call results, and the test file itself did not change. Every required lane stayed green from 2026-09-04 to 2026-09-30, because no lane's closure contained the module. It surfaced only when gunbc#12761's widened subject Strict-prepared every admitted module (fleet run 36751831054). It is in the census of gunbc#12855, and its repair is the infer owner's, not a rewrite of the test. This is the class's harm in its plainest form: a refusal that is real, located and reproducible sat silent for almost four weeks.",
],

evidence: [],
Expand Down
2 changes: 1 addition & 1 deletion dag/test/claim/build_cache_endpoint_path_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ test fn witness_a_tcp_endpoint_has_no_stale_socket_state() -> Bool {

test fn witness_the_unconditional_sketch_differs_where_it_is_destructive() -> Bool {
let states = [
EndpointListening { owner: live_owner() },
gunbc.build_cache_endpoint_path.EndpointListening { owner: live_owner() },
EndpointPathConflict { detail: "regular file" as NonEmptyStr },
]
states |> all(s => unconditional_unlink_sketch(observed: s) && (unlinks(observed: s, currency: current()) == false))
Expand Down
2 changes: 1 addition & 1 deletion dag/test/claim/build_cache_placement_observation_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ test fn witness_both_runner_lifecycles_refuse_at_the_verdict() -> Bool {
}

fn refuses(placement: BuildCacheServerPlacement) -> Bool {
match placement_verdict(catalog_id: sccache_local_id, stats_line: "stats", placement: placement) {
match gunbc.build_cache_provision_verdict.placement_verdict(catalog_id: sccache_local_id, stats_line: "stats", placement: placement) {
BuildCacheProvisionRefused { cause: _, reason: _ } => true
BuildCacheProvisionConverged { catalog_id: _, stats_line: _ } => false
}
Expand Down
10 changes: 7 additions & 3 deletions dag/test/claim/citation_cit0_witness_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -247,9 +247,13 @@ test fn citation_target_carries_pin_and_selector_not_observation() -> Bool {
right: witness_citation_pin.subject,
)
&& match witness_citation_target.selector {
TextQuoteSelectorVariant(_) => true
FragmentSelectorVariant(_) => false
TextPositionSelectorVariant(_) => false
Present { value: s } =>
match s {
TextQuoteSelectorVariant(_) => true
FragmentSelectorVariant(_) => false
TextPositionSelectorVariant(_) => false
}
none => false
}
}

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
module test.claim.fleet.health_read_only_fixture_refusal_witness

import std.types { String, Bool, Int, List }
import extdeps.filesystem.filesystem_io
import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree }
import gunbc.compile_diagnostic_census {
CompileDiagnosticCensus, CompileDiagnosticCensusRow, CensusObserved, CensusNotRunnable,
}

data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree

// THE DESIGNED REFUSAL OF test.fixture.health_read_only.mutation_probe, ASSERTED BY CLASS AND
// SUBJECT. The fixture is the forbidden program the fleet health no-mutation witness derives its
// findings from (test.claim.fleet_health_read_only_witness), and it is consumed PARSE-ONLY: its
// callees are undeclared spellings by design, so it must never resolve. It is therefore excluded
// from the required floor's Strict preparation (floor_prepared_subject_exclusions row
// "test/fixture/health_read_only/"), the same disposition as dag/test/probe/, and this witness is
// what keeps that exclusion honest. It is red if the fixture starts resolving, and red if it
// refuses only for a reason other than its undeclared callees.
//
// FOUND BY the gunbc#12761 widened subject (every admitted module Strict-prepared), which refused
// on this file at 0207c666 with the rest of the 14-file census: no exclusion row covered it, and it
// stayed out of preparation only because nothing imported it.

data fixture_path: String = "dag/test/fixture/health_read_only/mutation_probe.dag"

fn fixture_census() -> CompileDiagnosticCensus {
compile_dag_diagnostic_census(filesystem_read(path: fixture_path).content)
}

fn blocking_count(c: CompileDiagnosticCensus, wanted: String, subject: String) -> Int {
match c {
CensusNotRunnable { cause: _ } => -1
CensusObserved { rows: rows } =>
rows
|> filter(r => (r.diagnostic_class as String) == wanted && r.subject_name == subject && r.blocking)
|> fold(init: 0, f: (acc, r) => acc + r.count)
}
}

// The undeclared Redfish account callee, the forbidden mutation's own spelling.
test fn the_fixture_still_refuses_on_its_undeclared_account_callee() -> Bool {
blocking_count(c: fixture_census(), wanted: "InternalError", subject: "function:CreateAccount") >= 1
}

// The undeclared host-shell provider, the fixture's second forbidden leg.
test fn the_fixture_still_refuses_on_its_undeclared_shell_provider() -> Bool {
blocking_count(c: fixture_census(), wanted: "UnresolvedType", subject: "SshShell") >= 1
}
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,7 @@ test fn w_refusal_carries_its_phase() -> Bool {
SharedModuleIndexBuild => false
BareReferenceEdgeIndexBuild => true
LanguagesConsumerCensusBuild => false
CrossClaimPureProducerWarm => false
}
}
}
Expand Down
7 changes: 6 additions & 1 deletion dag/test/claim/llm_attempt_receipt_witness_test.dag
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
module test.claim.llm_attempt_receipt_witness

import gunbc.econ.llm_attempt_receipt {
TokenThroughput,
AcceptedGoodputDerived,
AcceptedGoodputRefused,
ArchitectureJudgment,
Expand Down Expand Up @@ -194,8 +195,12 @@ test fn zero_decode_duration_refuses_rather_than_fabricating() -> Bool {
}
}

// The fraction is declared at TokenThroughput (FieldOfFractions<Nat>), the type the projection
// reads; a bare construct at the call argument infers its own instantiation from the literals.
data zero_denominator_throughput: TokenThroughput = FieldOfFractions { num: 1000, denom: 0 }

test fn zero_denominator_floor_projection_returns_none() -> Bool {
match throughput_per_second_floor(t: FieldOfFractions { num: 1000, denom: 0 }) {
match throughput_per_second_floor(t: zero_denominator_throughput) {
none => true
Present { value: _ } => false
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ fn witness_unreachable_grant() -> OperatorGrant<Srv3BootOverrideSubject> {
},
],
purpose: "unreachable" as NonEmptyStr,
attempt: "no-attempt" as AttemptIdentity,
attempt: "no-attempt" as std.scoped_authorization.AttemptIdentity,
intent_hash: content_hash_of_value(value: "no-intent" as NonEmptyStr),
granted_by: "nobody" as NonEmptyStr,
granted_at: "1970-01-01T00:00:00Z",
Expand Down Expand Up @@ -190,7 +190,7 @@ test fn srv3_grant_refuses_a_different_attempt() -> Bool {
scopes: srv3_boot_once_cd_authorization_request.scopes,
subject: srv3_boot_once_cd_subject,
purpose: srv3_boot_once_cd_authorization_request.purpose,
attempt: "srv3-os-install-actuate-2" as AttemptIdentity,
attempt: "srv3-os-install-actuate-2" as std.scoped_authorization.AttemptIdentity,
intent_hash: srv3_boot_once_cd_authorization_request.intent_hash,
destructive: true,
}
Expand All @@ -200,7 +200,7 @@ test fn srv3_grant_refuses_a_different_attempt() -> Bool {
observed_at: witness_before_expiry,
) {
AuthorizationRefused { cause: AuthorizationAttemptMismatch { requested: req, granted: got } } =>
req == "srv3-os-install-actuate-2" as AttemptIdentity && got == srv3_boot_once_cd_attempt
req == "srv3-os-install-actuate-2" as std.scoped_authorization.AttemptIdentity && got == srv3_boot_once_cd_attempt
_ => false
}
}
Expand Down Expand Up @@ -285,7 +285,7 @@ test fn srv3_grant_is_single_use() -> Bool {
test fn srv3_grant_excludes_a_concurrent_attempt() -> Bool {
let held_by_other = witness_grant_claimed(
claim: claim_transition_claimed(
attempt: "srv3-os-install-actuate-99" as AttemptIdentity,
attempt: "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity,
at: witness_before_expiry,
),
)
Expand All @@ -301,7 +301,7 @@ test fn srv3_grant_excludes_a_concurrent_attempt() -> Bool {
observed_at: witness_before_expiry,
) {
AuthorizationRefused { cause: AuthorizationClaimedByOtherAttempt { requested: r, holder: h } } =>
r == srv3_boot_once_cd_attempt && h == "srv3-os-install-actuate-99" as AttemptIdentity
r == srv3_boot_once_cd_attempt && h == "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity
_ => false
}
&& srv3_boot_once_cd_is_runnable_with_approval(
Expand All @@ -319,7 +319,7 @@ test fn srv3_claim_loser_learns_who_holds_it() -> Bool {
at: witness_before_expiry,
)
let winner = claim_transition_claimed(
attempt: "srv3-os-install-actuate-99" as AttemptIdentity,
attempt: "srv3-os-install-actuate-99" as std.scoped_authorization.AttemptIdentity,
at: witness_before_expiry,
)
let attempt = claim_authorization(
Expand Down
10 changes: 5 additions & 5 deletions dag/test/claim/std_list_keyed_scan_witness_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -11,18 +11,18 @@ data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly
// from the other rows sharing its key. A scan returning the right KEYS but the wrong ELEMENT would
// pass any claim that read keys only, which is how duplicated_by_key once shipped emitting the second
// occurrence while its note promised the first (review 68028).
type KeyedRow {
type KeyedScanRow {
key: String
payload: String
}

fn row(key: String, payload: String) -> KeyedRow { KeyedRow { key: key, payload: payload } }
fn row(key: String, payload: String) -> KeyedScanRow { KeyedScanRow { key: key, payload: payload } }

fn key_of(r: KeyedRow) -> String { r.key }
fn key_of(r: KeyedScanRow) -> String { r.key }

fn payloads(rs: List<KeyedRow>) -> List<String> { map(rs, r => r.payload) }
fn payloads(rs: List<KeyedScanRow>) -> List<String> { map(rs, r => r.payload) }

fn rows() -> List<KeyedRow> {
fn rows() -> List<KeyedScanRow> {
[row(key: "a", payload: "a1"), row(key: "b", payload: "b1"), row(key: "a", payload: "a2"),
row(key: "c", payload: "c1"), row(key: "b", payload: "b2"), row(key: "a", payload: "a3")]
}
Expand Down
7 changes: 7 additions & 0 deletions src/v1/stage0/src/cli_run/required_floor_runner.rs
Original file line number Diff line number Diff line change
Expand Up @@ -4982,6 +4982,13 @@ pub fn floor_prepared_subject_exclusions() -> Vec<String> {
// vanished seed), and `ExclusionOrphansImporter` refuses the day anything imports one.
"test/probe/".to_string(),
"test/fixture/meta_exec_confinement_scan/".to_string(),
// THE FLEET HEALTH FORBIDDEN PROGRAM. test.fixture.health_read_only.mutation_probe is the
// program the no-mutation witness derives its findings from, consumed PARSE-ONLY: its
// callees are undeclared spellings by design, so it must never resolve. Nothing imports it,
// so it stayed out of preparation by that accident alone until gunbc#12761's widened
// subject prepared it and it refused. Its designed refusal is asserted by class and subject
// in test.claim.fleet.health_read_only_fixture_refusal_witness.
"test/fixture/health_read_only/".to_string(),
"test/manual/ownership_movable_test.dag".to_string(),
// WET RECEIPT, AND IT HAS NO CI CONSUMER TODAY — stated plainly rather than dressed up
// as an enrollment. case4_expansion_carrier_splices dispatches a real jq through
Expand Down