Repository navigation
shell-to-dag: codex account trip to typed argv (retained_foreign site retired) - #12973
Merged
Merged
Conversation
added 2 commits
October 2, 2026 01:17
…ex account trip The account trip in gunbc.codex_app_server_press reaches the codex app-server as a retained heredoc: retained_foreign wrapping the bash body codex_press_account_trip_script assembles (export, mktemp, printf, sentinel echo, rm), run through shell.Exec.Run's bash -s, with its stdout a ---GUNBC_EXIT--- mux re-parsed by parse_gunbc_exit_marker. This lands the identity-stable claim codex_account_trip_transport_surface_carries_no_shell_control_word in dag/test/claim/codex_app_server_press_witness_test.dag: project the trip's transport surface as text, assert no shell control word. On this tree the surface IS the script body, so the claim FAILS and is enrolled in v2.workflow.floor_expected_red (floor_expected_red_chunk_shell_to_dag_typed_transport) under that roster's contract: enrolled-and-fails is agreement now; when the trip runs as a typed argv through shell.Exec.RunArgvStdin and the script, its sentinel parse and the retained_foreign site are deleted together, the claim passes and the row reports stale-quarantine naming itself for removal. Receipt (red on main, measured before enrollment): ./target/release/gunbc run --source-root dag --source-root src/v2 --entry dag/test/claim/codex_app_server_press_witness_test.dag --claim-run => FAIL codex_account_trip_transport_surface_carries_no_shell_control_word, the 24 pre-existing claims in the module all PASS.
…oreign retires with its site
The account trip in gunbc.codex_app_server_press spawned the codex app-server
through retained_foreign: a bash body assembled by
codex_press_account_trip_script (export, mktemp, printf, sentinel echo, rm)
run through shell.Exec.Run's bash -s, its stdout a ---GUNBC_EXIT--- mux that
parse_gunbc_exit_marker re-parsed, quoting the one thing a script must quote
-- a filesystem path.
This deletes that whole carrier with its site:
- shell.Exec.RunArgvStdin (dag/extdeps/shell/exec.dag) completes the
Run/RunArgv family along the one axis they vary on -- stdin. Minted after a
tree-wide survey: the argv+stdin shape existed only as tool-fixed rows
(jq.Process.RunWithStdin, ssh.Session.ExecPortableWordsWithStdin,
git.Plumbing.HashObjectWriteStdin), none admitting a caller-named program.
Same output triple and no-success-field discipline as RunArgv; the seed's
dispatch_shell already realizes argv+stdin generically, no seed-side change.
- observe_codex_account_preflight binds RunArgvStdin: env(1) carries CODEX_HOME
as an argv element (extdeps.tools.env), the four request lines ride stdin as
data, stdout/stderr/exit_code arrive as separate declared outputs. The script
builder, GunbcStdioCapture, parse_gunbc_exit_marker,
split_gunbc_stdio_capture, process_receipt_from_capture, the sentinel
dissolve note and the retained_foreign import are deleted together.
- cli_surface_of_literal_words admits the trip's invocation builder per that
mechanism's own extension rule (an edit to the declaring module's roster):
it holds the runtime words -- the projected executable path and the CODEX_HOME
binding.
- The expected-red probe
codex_account_trip_transport_surface_carries_no_shell_control_word now
projects the typed invocation, PASSES, and its roster chunk
floor_expected_red_chunk_shell_to_dag_typed_transport is removed -- the
stale-quarantine arm, done by hand the same commit that greens the row. A
positive control pins the semantics the script used to carry: CODEX_HOME as
an argv element, app-server --stdio, four newline-terminated request lines,
initialize first, rate-limits read last, no turn/start.
Receipts (measured, local cgroup-bounded run):
base: FAIL codex_account_trip_transport_surface_carries_no_shell_control_word,
24 pre-existing claims PASS
head: 26 PASS, 0 FAIL (the module above)
gunbc retained_foreign count on dag/: 1 live site left
(dag/gunbc/instruments/emit_host_transport.dag), deferred to its own vertical
per emit_host_node_serve_process_lifecycle_trigger.
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…ike its RunArgv siblings Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…pile-pool slice install The compile-pool slice install still reaches its host as retained shell text (compile_pool_slice_install_body over shell_exec_via_bash through retained_srvn), so its transport surface is exactly the shell programming words the probe forbids. The probe projects that surface -- the stage-directory assignment, the trap line, and the assembled body -- and asserts none of them appears; measured by execution at this commit: FAIL compile_pool_slice_install_surface_carries_no_shell_control_word, this module's 22 pre-existing hermetic claims PASS. Enrolled expected-red in v2.workflow.floor_expected_red (chunk shell_to_dag_pool_install_typed_argv) naming its own next-rung trigger: the install as a typed staging fold over run_argv_over_host_effect_transport, at which point the row passes and is removed by the same change (the codex account-trip row's shape, PR1 #12973).
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
- gunbc.spark.native_experiment_apply: main (#12952) split unreached legs out of SparkPairHostApplyFailed into SparkPairHostUnreached. Every match here now handles Unreached exactly as Failed, which preserves the pre-split behavior (an unreached leg refuses/halts with its cause). - shell_dag_codex_app_server_trip_script witness: main (#12973) deleted codex_press_account_trip_script. Re-pointed trip_surface at the typed invocation under the file's own sanctioned exception, using the projection codex_app_server_press_witness_test already uses. Claims are unchanged. The control-word and sentinel arms now pass and leave the expected-red chunk; the adversarial codex_home arm still fails and stays enrolled. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…pile-pool slice install The compile-pool slice install still reaches its host as retained shell text (compile_pool_slice_install_body over shell_exec_via_bash through retained_srvn), so its transport surface is exactly the shell programming words the probe forbids. The probe projects that surface -- the stage-directory assignment, the trap line, and the assembled body -- and asserts none of them appears; measured by execution at this commit: FAIL compile_pool_slice_install_surface_carries_no_shell_control_word, this module's 22 pre-existing hermetic claims PASS. Enrolled expected-red in v2.workflow.floor_expected_red (chunk shell_to_dag_pool_install_typed_argv) naming its own next-rung trigger: the install as a typed staging fold over run_argv_over_host_effect_transport, at which point the row passes and is removed by the same change (the codex account-trip row's shape, PR1 #12973).
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…pile-pool slice install The compile-pool slice install still reaches its host as retained shell text (compile_pool_slice_install_body over shell_exec_via_bash through retained_srvn), so its transport surface is exactly the shell programming words the probe forbids. The probe projects that surface -- the stage-directory assignment, the trap line, and the assembled body -- and asserts none of them appears; measured by execution at this commit: FAIL compile_pool_slice_install_surface_carries_no_shell_control_word, this module's 22 pre-existing hermetic claims PASS. Enrolled expected-red in v2.workflow.floor_expected_red (chunk shell_to_dag_pool_install_typed_argv) naming its own next-rung trigger: the install as a typed staging fold over run_argv_over_host_effect_transport, at which point the row passes and is removed by the same change (the codex account-trip row's shape, PR1 #12973).
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…pile-pool slice install The compile-pool slice install still reaches its host as retained shell text (compile_pool_slice_install_body over shell_exec_via_bash through retained_srvn), so its transport surface is exactly the shell programming words the probe forbids. The probe projects that surface -- the stage-directory assignment, the trap line, and the assembled body -- and asserts none of them appears; measured by execution at this commit: FAIL compile_pool_slice_install_surface_carries_no_shell_control_word, this module's 22 pre-existing hermetic claims PASS. Enrolled expected-red in v2.workflow.floor_expected_red (chunk shell_to_dag_pool_install_typed_argv) naming its own next-rung trigger: the install as a typed staging fold over run_argv_over_host_effect_transport, at which point the row passes and is removed by the same change (the codex account-trip row's shape, PR1 #12973).
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 2, 2026
…pile-pool slice install The compile-pool slice install still reaches its host as retained shell text (compile_pool_slice_install_body over shell_exec_via_bash through retained_srvn), so its transport surface is exactly the shell programming words the probe forbids. The probe projects that surface -- the stage-directory assignment, the trap line, and the assembled body -- and asserts none of them appears; measured by execution at this commit: FAIL compile_pool_slice_install_surface_carries_no_shell_control_word, this module's 22 pre-existing hermetic claims PASS. Enrolled expected-red in v2.workflow.floor_expected_red (chunk shell_to_dag_pool_install_typed_argv) naming its own next-rung trigger: the install as a typed staging fold over run_argv_over_host_effect_transport, at which point the row passes and is removed by the same change (the codex account-trip row's shape, PR1 #12973).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Debt paydown of the shell-to-dag residual (docs/plans/shell-to-dag-residual-census-and-arc-completion.md §4). Two commits, delete-first, one retained row retired with its whole carrier.
What this PR does
9aa98c9a946): lands the identity-stable probecodex_account_trip_transport_surface_carries_no_shell_control_wordindag/test/claim/codex_app_server_press_witness_test.dag— project the account trip's transport surface as text, assert no shell control word (export,$(,mktemp,printf,---GUNBC_,rm -f). On that tree the surface IS the retained heredoc body, so the claim FAILS and is enrolled expected-red inv2.workflow.floor_expected_red(floor_expected_red_chunk_shell_to_dag_typed_transport) under that roster's own contract.1862911dac1): the migration.shell.Exec.RunArgvStdin(dag/extdeps/shell/exec.dag) completes the Run/RunArgv family along the stdin axis — minted after a tree-wide survey (DESIGN §3 fork check): the argv+stdin shape existed only as tool-fixed rows (jq.RunWithStdin, ssh.ExecPortableWordsWithStdin, git.HashObjectWriteStdin), none admitting a caller-named program; the seed'sdispatch_shellalready realizes argv+stdin generically (no seed change).observe_codex_account_preflightnow binds it:env(1)carries CODEX_HOME as an argv element, four request lines ride stdin as data, stdout/stderr/exit_code are separate declared outputs. Deleted together with the site:codex_press_account_trip_script,GunbcStdioCapture,parse_gunbc_exit_marker,split_gunbc_stdio_capture,process_receipt_from_capture, the sentinel dissolve note, and theretained_foreignimport.cli_surface_of_literal_wordsadmits the trip's invocation builder per that mechanism's own extension rule (roster edit in the declaring module). The probe now projects the typed invocation, passes, and its roster chunk is removed; a new positive control pins the semantics the script carried (CODEX_HOME binding,app-server --stdio, four newline-terminated request lines, no turn/start).Receipts (measured with
gunbc run --claim-runon the single witness module, local cgroup-bounded run; the remote BuildBuddy executor exposes no cgroup memory limit soHostBudgetUnreadablerefuses there — the module's own 2026-08-30 receipt names this route gap):FAIL codex_account_trip_transport_surface_carries_no_shell_control_word, 24 pre-existing claims PASSRecount (named instruments, at this head vs synced base
0ec6e549625):grep -rn "retained_srvn\|retained_foreign" dag/ src/: 37 → 35. Identity-level delta: the two codex rows (import + call site ingunbc.codex_app_server_press) retired; the tworunner_browser_toolchain.dagrows (81, 1295) landed on main during the trial and remain, they are srvN admin-edge work (PR2 scope,compile_pool_slice_install_stepand friends).grep -rn "posix_sh_program_command(" dag/ src/: 23 → 23 (unchanged; PR2+ scope).Deliberately deferred:
dag/gunbc/instruments/emit_host_transport.dag:193— the lastretained_foreignlive site — is its own vertical per its own triggeremit_host_node_serve_process_lifecycle_trigger(typed process-lifecycle ops), per parent agreement in the trial.Not merged by me — operator decides.