Skip to content

Floor: derive cross-claim pure-share from planned claims' call-site demand; delete the hand roster - #13043

Merged
gunbai-bot[bot] merged 59 commits into
mainfrom
session/royal-deer-478
Oct 5, 2026
Merged

gunbai-bot[bot] merged 59 commits into
mainfrom
session/royal-deer-478

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Floor repair C3 part 2 (plan #13030): cross-claim pure-share admission is derived from the planned claims' call-site demand, and the hand roster is deleted in the same change (DESIGN §3, replacement migration). Mechanism ruled by sharp-raven-357 (option A, then (i)): the observation row type and the decision live in .dag, and the seed only observes and realizes.

What changes

  • .dag authority v2.workflow.floor_pure_producer_share:
    • CallSiteDemandObservation is keyed by std.computation_identity (NormalizedIdentical, normalizer named on the row).
    • CallSiteDemandCause is a closed coproduct of why a site has no closed identity.
    • derive_cross_claim_share decides: it admits a closed identity demanded by at least 2 planned claims. It declines DemandedByOneClaim, IdentityGradeNotShareable, RefusedByMeasurement and CarriedInputProducer. Unadmissible sites are counted under their cause, never widened.
    • Deleted: the warm roster (575 rows), the claim-forced roster (5), the pending candidates, floor_cross_claim_admitted_producers, and both collision walls. The walls are now unconstructible by the fold.
  • Seed observer cli_run::claim_call_site_demand is one realization of the row type. It walks each planned claim's reach and reads every call site. It counts distinct claims per identity and decides nothing. It is seed-retained under the new receipt gunbc.floor_call_site_demand_seed_growth, whose trigger is per-claim call-site demand identity available to .dag (demand-engine M1.b).
  • Realization: derive_and_install_cross_claim_share runs after planning.
    • It refuses if the fold's partition does not reconcile with the observed closed rows.
    • It admits each decided producer at its call sites only, through the interpreter's site gate.
    • It warms each admitted row once, in its site module's frame. The warms are adjudicated against the existing preparation limits.
    • Stores stay keyed on evaluated argument values, with preimage verification before any serve. A misjudged site can cost a missed share or a wasted store, never a wrong value.
  • Unchanged: refused candidates (including the correctness arm KeyOmitsAnInputTheValueDependsOn) and the carried-input rows. Both stay as identity gates.
  • C3 part 1 is subsumed: nothing outside the planned claims' reach is filled.

Structural prediction, stated before the confirming run

  • Collapses: for every closed identity reached by k ≥ 2 planned claims, the producer's evaluation multiplicity goes from k (one per claim frame) to 1 warm plus k hits.
  • Stays equal: the planned claim set and every verdict. The share changes which frame pays for a value, never the value.
  • Disappears: warms of producers no planned claim reaches. The prepared-subject-warm consumer_claims=0 fills go to zero.
  • May remain:
    • Shares the old roster held that the derivation does not reproduce. These are producers reached by a single planned claim, or reached through argument rows that are not closed constants. Each one is listed below from the run's own [cross-claim-share-admitted] / [cross-claim-share-declined] lines.
    • Per-claim recompute of non-constant-argument producers. It is counted, as ArgumentNotClosedConstant, rather than hidden.

Roster dispositions

All 647 rows of main's roster (at 6386677) are dispositioned by identity in this comment, per-row lists in the next:

disposition rows
reproduced: shared by declared demand 159
one claim demands it; that claim is a fill-debt member 416
one claim demands it; fits its budget unshared 58
shared by declared demand, no probed claim planned it 3
frozen runtime-identity residual 5
no observation row (3 dead, 3 with an unobserved single consumer) 6

Evidence

Final pair, all fixes in: PR-side 37210396855 (e46846f) vs main-side 37210398646 (main 44ed81c), 134 modules / 1290 claims force-planned on both.

The price of deleting the hand roster is the derivation seam, and it is stated plainly: observing the declared claims' call sites and running the fold costs about 25 s of thread CPU on an ordinary PR subject and 92 s on this full probe subject. That is new work this change adds to every floor run.

  • This change does not make the floor faster. Share-related thread CPU: main 1260.6 s roster warm + 291.3 s fold = 1551.9 s; PR 5.1 s warm + 92.0 s derivation + 1545.0 s fold = 1642.1 s. That is +5.8% raw; the PR side's host read 1.046x on the pre-claim seams, so about +1% net.
  • Per-claim CPU is within a few percent of main, not shown equal. On the 14 over-budget claims common to both sides (same steps), the median CPU-per-step ratio is 1.079 against the 1.046 host factor. One sample per side on different hosts cannot separate the remainder from runner variance.

What the comparison caught along the way, each fixed in this PR with a control:

  • A steps-only cost floor declined dag_prepared_grammar (few steps, 466-1140 ms of native keying), so every claim re-paid it. The floor now has a CPU arm, typed as a Millisecond and set to the new-witness envelope.
  • The site-gate check allocated a file-path string on every call of a gated producer. The site sets are now indexed by byte span.
  • A site whose fill is below the floor stayed admitted and was re-keyed and declined on every call (446k declines on one probe; 5.6k now). It is retired on its first below-floor fill.
  • The tier lookup reified the caller's whole argument row on every call. An argument that is a served instance is now verified by its content digest from a registry filled at publication; other arguments are reified as before.

Part (b), the TSV uploads, is #13031.

🤖 Generated with Claude Code

Brian Searls and others added 6 commits October 3, 2026 00:53
…all-site demand

Deletes the hand-authored share roster (575 warm + 5 claim-forced rows, the
pending-candidate shape, two collision walls, the seed's plain warm loop) and
replaces it with a derivation:

- .dag (v2.workflow.floor_pure_producer_share): the observation row type
  CallSiteDemandObservation keyed by std.computation_identity, the closed cause
  coproduct CallSiteDemandCause, and the decision fold derive_cross_claim_share
  (admit a closed identity demanded by >=2 planned claims; decline single-claim,
  unknown-grade, measured-refused and carried-input producers; count every
  unadmissible site under its cause, never widen).
- seed: claim_call_site_demand observes each planned claim's reach and reads its
  call sites (one realization of the .dag row type; seed-retained under
  gunbc.floor_call_site_demand_seed_growth until demand-engine M1.b supplies
  per-claim call-site demand identity to .dag). derive_and_install_cross_claim_share
  calls the fold after planning, admits the decided producers at their call
  sites only, and warms each once in its site module's frame, adjudicated
  against the preparation limits.
- interpreter: site-gated admission (install_cross_claim_derived_share,
  cross_claim_site_admitted) and warm_cross_claim_call_site; stores stay keyed
  on evaluated argument values with preimage verification.

Refused candidates and carried-input rows stay as identity gates.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttributed hits by key

The observer called CallSemantics::target() on a FunctionValueCallSemantics call,
which has no static target and panics (floor run 37083945879). Such a site is
CalleeUnresolved.

Per sharp-raven-357: the shared-fill ledger now renders each unattributed hit as
one [floor-shared-fill-unattributed] line per (frame, phase, cache, key) via
gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed
mirror, so preparation's own reads are answerable by identity.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
call_target matches CallSemantics exhaustively (no target() panic path) and
returns a typed cause: CalleeIsAValue for function-value and locally bound
calls, CalleeUnresolved otherwise. A panic while reading any site is caught and
counted as CallShapeUnread, never a crash and never a skip. Both arms are added
to the .dag CallSiteDemandCause coproduct. Control:
a_function_value_call_is_counted_as_a_value_callee_never_a_panic.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37087208959 refused CrossClaimShareDerivationUndecodable: the fold's
lists come from v2.std.algebra list_flat_map / list_map, i.e. FreeMonoid
Cons/Empty chains, and the decoder accepted only kernel lists. Decode through
v1_interpreter::list_value_items (free_monoid_to_vec under the frame).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ws only

Run 37089182924 (first derived run) admitted 2919 identities; 2807 warmed under
5ms, and their stores plus nested stores exhausted the tier's 4096-entry cap,
so every identity claims actually needed was refused (EntryCapReached=1460)
and 16+ claims crossed the new-witness budget.

- v2.workflow.floor_pure_producer_share floor_cross_claim_share_cost_floor_eval_steps
  (declared policy, DESIGN section 2's recompute-below-the-cost-floor): a warm
  measured under it is declined BelowCostFloor and counted.
- warm_cross_claim_call_site stores only the producer it warms
  (CROSS_CLAIM_WARM_ONLY); nested admitted calls recompute, so the measured
  steps are the warm's own and no entry is spent on an unjudged identity.
- After the warm the derived share is re-installed with the retained rows only;
  install replaces the previous derivation, removing dropped producers from the
  roster so none stays admitted without its site gate.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Agreed with royal-moth-86 (cache program): each closed identity becomes one
FrameDemand per demanding planned claim at its claim frame under preparation,
judged by std.materialization_ladder group_verdict against the existing
cross-claim CacheProvider (MemoTier ContentKeyed, preparation scope). Two or
more claims are AuthoredDuplication (the carry is owed; the warm is the carry);
one claim is AcceptedSingleRecompute (DemandedByOneClaim); any other verdict is
carried on the decline (LadderOwesNoCarry). Observation rows now carry the
demanding claim identities instead of a count.

The frame path, the tier retention and the provider (cross_claim_share_provider)
move into v2.workflow.floor_pure_producer_share as their single authority;
v2.workflow.floor_prepared_effect_input_ladder now covers the carried
identities with the same provider. The cost floor is documented as DESIGN s2's
economic realization after the ladder, not the ladder's below-floor exemption
(which the ladder applies only below an isolated LCA).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sharp-raven-357 ruling A: recurrence is a fact about the declared subject, so
the observer walks every claim declared in a prepared module and each row
carries its declared claims plus how many are planned. The ladder judges the
declared demand (deterministic per claim: the same on main and on a PR that
plans a narrower set); the fold declines ReachedByNoPlannedClaim so nothing is
warmed that no planned claim in this run can consume. Reason stated beside the
observation row type. Controls: two_declared_claims_with_one_planned_is_admitted,
declared_demand_no_planned_claim_reaches_is_declined_and_named, and the seed's
declared_unplanned_claims_count_as_demand_and_are_not_counted_planned.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eclared cost debt

Run 37096345499 (f64b8f9): with recurrence counted over declared claims, the
class-1 claim (btar) passes; 20 claims remain over the new-witness budget, each
the ONLY declared claim reaching its front-end fixture producer, which the
deleted roster warmed in preparation (DESIGN s5 externalization). Per
sharp-raven-357's ruling each is dispositioned individually: supplying normalized
front-end subjects as literals is not practicable in this change, so each is a
declared cost-debt row (v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22,
measured eval steps beside each) with the per-claim trigger being the s3 witness
rule. The coverage loss is a declared s4b(3) drop:
gunbc.rung_drop.derived_share_single_claim_fixtures_withheld (rostered;
docs/design-rung-drops.md regenerated).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 5 commits October 3, 2026 05:33
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13029) appended the
warm row v2.test.claim.body_lowering.if_arm_position.iap_verdicts to the hand
roster this PR deletes. Resolved to this PR's side: iap_verdicts is a nullary
producer demanded by its four declared claims, so the derived share admits it
by recurrence (no row needed); its disposition is read from the next floor run.
docs/design-rung-drops.md regenerated against the merged tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Unadmissible sites with a known callee (open argument row, effectful callee) are
also aggregated per (producer, cause) and printed as
[cross-claim-share-unadmissible] lines, so each deleted roster row's disposition
is readable by identity: admitted, declined, open/effectful, or outside the run's
subject. The .dag rows stay aggregated by cause.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main added 53 hand warm rows
(#12506's 44 and #13050's) to the roster this PR deletes. Resolved to this PR's
side; each row is dispositioned from this head's floor run (derived, or a
single-declared-claim fill reported to its owning lane, calm-boar-904, for the
s3 supply-the-inputs restructure). Two comments in main's new test modules
that cited the deleted roster are rewritten. docs/design-rung-drops.md
regenerated against the merged tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion, wall-excused in flight

Same-revision A/B (PR run 37104970794 vs baseline dispatch 37105064700, both at
main 3a22bc2) showed the warm pass costing more than it saves: the derived
warm seam took 133.5s thread CPU against the old roster warm's 53.0s, with the
claim-evaluation fold unchanged (735.7s vs 731.9s). Most of it was 169
evaluation frames built only to warm 2523 identities, 2404 of which were then
discarded below the cost floor.

- No warm: an admitted site fills on the first planned claim that evaluates it.
  Its eval steps are netted from that claim by the existing fill guard
  (deterministic budgets).
- Its wall is excused from the claim's wall deadline while in flight
  (in_flight_cross_claim_fill_wall_nanos), capped at the preparation wall safety
  limit so a runaway fill still interrupts: the wall sibling of the existing
  CPU-deadline FillBudgetExceeded netting.
- The declared cost floor is applied to the fill's own steps at retention
  (CrossClaimStoreOutcome::RefusedBelowCostFloor, counted).
- Deleted: warm_cross_claim_call_site, CallSiteWarmRefusal,
  CROSS_CLAIM_WARM_ONLY, and the observer's site-node bookkeeping.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Same-revision floor comparison

Method. merry-koi-266's #13037 recipe:

  • PR run: 37109381438, head 97f1921. Its CI merge ref sits on main 2d8bfeb.
  • Baseline: dispatch 37109482629 of that bare main sha, on branch session/royal-deer-478-baseline-2d8b.
  • Read from: [floor-seam-cpu] deltas, [floor-shared-fill] claim= rows, [over-cost] rows and the required-floor: summary.
  • Planned sets differ (660 vs 664). Planning follows the diff and this PR touches .dag. So per-claim figures are compared over the claims both runs carry, and the counts are stated.

Verdicts. The two runs agree on everything below:

baseline PR
claims planned / executed 664 / 664 660 / 660
passed 654 650
failed 0 0
interrupted 0 0
over cost 0 0
known reds held 5 5

Share-related thread CPU:

seam baseline (hand roster) PR (derived)
prepared-subject-warm 50.5s 5.9s
cross-claim-share-derivation (observe + fold + install) none 19.6s
claim-evaluation-fold 629.0s 656.8s
total 679.5s 682.3s (+0.4%, on a 2529- vs 2400-module subject)

Structural prediction, checked over the 195 fill-paying claims common to both runs:

  • Shared work moves out of individual claims into netted fills. Per-claim marginal eval steps fall from 236,508 to 92,232; fill eval steps rise from 8,871 to 136,633.
  • Measured CPU on those claims is unchanged: 584.7s vs 588.2s.
  • On the 19 common [over-cost] rows, eval steps go from 1,220,210 to 1,205,562.
  • Verdicts are unchanged.

What the comparison caught along the way. The first derived head warmed every admitted identity during preparation. Its same-revision pair (37104970794 vs 37105064700, at main 3a22bc2) showed that seam costing 133.5s against the roster warm's 53.0s:

  • 169 evaluation frames were built to warm 2,523 identities.
  • 2,404 of those were then discarded below the cost floor.

97f1921 removes the warm pass:

  • Fill on first use: fills are lazy, on the first planned claim that evaluates an admitted site.
  • Wall excused only while in flight: the fill's wall is excused from the claim's wall deadline, capped at the preparation wall safety limit.
  • Cost floor at retention: the floor is applied to the fill's own steps when the value would be retained.
  • Netted, not lost: steps stay netted from the paying claim.

Preparation-read concern. The per-key [floor-shared-fill-unattributed] lines are in the PR log. Unattributed hits fall from 40 in the baseline to 6 in the PR, and every remaining one is named by key and frame.

Roster dispositions. These are pending a planning probe. Dispatch 37112519045 runs on a measurement-only branch that touches the 111 test modules behind deleted or main-added roster rows, so the floor plans their claims. Until then, from 37109381438:

  • Deleted roster, 578 rows: 18 admitted, 55 shared but not reached by a planned claim, 5 with an open argument row, and 500 in modules outside this run's subject.
  • Main-added, 53 rows: 14 shared but not planned, 1 single-claim, and 38 outside the subject.

The probe settles the 538 outside-subject rows by identity, and it lists any single-claim claim that goes over budget once its row is gone.

— sent from royal-deer-478

Brian Searls and others added 8 commits October 3, 2026 10:59
Conflict in v2.workflow.floor_pure_producer_share: main (#13010) added one more
hand warm row to the roster this PR deletes; resolved to this PR's side and
recorded for disposition. docs/design-rung-drops.md regenerated against the
merged tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Planning probe 37114012751 (all 111 roster-row test modules planned) showed 59
claims each re-preparing the grammar (prepare_grammar, ~1.8M steps / ~4.9s per
claim): the derivation also admitted v2.compiler.parse.prepare_grammar at its
closed-argument sites, which put its node in the site-gated set and withdrew the
built-in arm's admission at every other site. install_cross_claim_derived_share
now gates only producers the derivation alone admits; the built-in
prepare_grammar arm and roster (carried-input) producers keep every site.
Control: a_derived_admission_never_gates_a_producer_already_admitted_ungated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13053) added four hand
warm rows to the roster this PR deletes; resolved to this PR's side and recorded
for disposition. The new value_base_projection test's comment citing the deleted
roster is rewritten. docs/design-rung-drops.md regenerated against the merged
tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lared cost debt

The planning probe (dispatch 37121610250: every test module behind a deleted or
main-added roster row planned, on the site-gate-fixed head; control 37117342059
at main 2d8bfeb with the same touches) finds 25 claims over the new-witness
budget only with the roster deleted (two materially worse), each the sole
declared claim of its fixture producer. Per sharp-raven-357's class-2 ruling
they are declared cost debt (floor_cost_debt_proven_chunk_23, measured steps
beside each, trigger the s3 witness rule) and join the population of
gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. The probe's four
failures fail identically at main (pre-existing reds that only run when their
modules are touched) and are not this change's.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37125103721 refused: floor_cost_debt_roster duplicate withheld
identity reference_conservation.a_string_literal_is_conserved_by_its_value_holds,
already in chunk_22 and re-added to chunk_23 from the planning probe. Removed
from chunk_23 and from the second mention in the rung drop population;
docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Only docs/design-rung-drops.md conflicted (generated); regenerated against the
merged tree.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13051) added one hand
warm row (if_arm_reader_differential.iard_fixture_censuses) to the roster this
PR deletes; resolved to this PR's side and recorded for disposition.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
review 74858: the population spans floor_cost_debt_proven_chunk_22 and
chunk_23 but the trigger named only chunk_22, so the 24 chunk_23 rows could
never retire it (DESIGN s4b(3): a plural loss with a singular trigger). The
trigger now names both chunks and states that the row retires when every claim
in the population has left its chunk. docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 4 commits October 3, 2026 16:33
…per claim

sharp-raven-357 ruling A. The full planning probe (PR 37131459602 vs main
37131472056, every test declaration in the roster-row modules planned at one
revision) found 344 claims over the new-witness budget only with the hand
roster deleted, each the sole declared demander of its fixture producer: most of
the deleted roster billed a claim's own fixture to preparation rather than
sharing anything.

- v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt: a
  monotone debt set, 345 claims in 69 modules, generated once from the probe
  and marked so. Standing is ActiveFillDebt or RetiredFillDebt with a typed
  disposition (RestructuredPerWitnessRule, BecameSharedByDemand, ClaimDeleted).
- derive_cross_claim_share admits a one-claim identity only when its sole claim
  is an active member, with basis SingleClaimFillDebt naming the claim; a shared
  identity keeps basis SharedByDeclaredDemand. The claim's own fill is then
  netted from its budget by the existing fill guard, so the claim keeps running.
- The seed realizes the identity join: a planned active member with no admitted
  fixture identity refuses SingleClaimFillDebtStale.
- One mechanism: the 45 claims first withheld as cost debt
  (floor_cost_debt_proven_chunk_22/23) and their rung drop are removed, so
  their verdicts return.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13099, #12992) added
three hand warm rows to the roster this PR deletes; resolved to this PR's side
and recorded for disposition.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merge: main added four hand warm rows (infer_fold_member_instance fmi_*) to the
roster this PR deletes; resolved to this PR's side, recorded for disposition,
and the new test's comment citing the deleted roster rewritten.

Probe 37137409052 showed 345/345 debt members planned and billed, yet 106 of
them still over budget with no fill row: an admitted fill whose store the tier
declines stays on the paying claim, and nothing printed it. The floor now prints
one [cross-claim-share-store-declined] line per (producer, cause) -- including
the recompute-ledger branch that returns without offering the fill to the tier
(RecomputeKeyUnavailable) -- and a [cross-claim-share-tier] totals line.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13113, #13056) added
three hand warm rows (elif_verdicts, bhr_verdicts, trt_verdicts) to the roster
this PR deletes; resolved to this PR's side and recorded for disposition.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Roster file keeps this change's side. Main added sixteen roster rows (#13187: gfi_*_reason in
v2.test.claim.compiler.generic_formal_instantiation); their module is probed next.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Brian Searls and others added 2 commits October 4, 2026 22:43
…, from probe 37238532455

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Re-read by sharp-raven-357 at d0a206d (both current-head reviews timed out with no verdict). Since my APPROVE read at 2fa5771, the PR's own diff against its merge base is unchanged in every file except floor_pure_producer_share.dag, where the only addition is the generic_formal_instantiation fill-debt module (12 ActiveFillDebt claims for #13187's rows, cited to probe 37238532455). The interpreter delta is identical to what I read. APPROVE.

— sent from sharp-raven-357

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 5, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Correction to my earlier read (sharp-raven-357): codex review 76009 is right and I missed it. Digest-only matching of served arguments relies on a 64-bit FNV digest, which isn't collision-safe, so it drops the preimage verification the old structural comparison gave. Dequeued for an instance-identity fast path with structural fallback.

— sent from sharp-raven-357

…ever by digest alone

Review 76009: cross_claim_entry_matches accepted a served composite argument on
equality of portable_value_digest, a 64-bit FNV hash that is not injective, so a
key-plus-digest collision served another call's value (a section 4b(3) regression
from the structural check it replaced). Each entry now records the
ServedInstanceKey each argument was stored as; a served probe matches only the
same instance, and otherwise falls back to portable_value_eq over the argument
reified at most once per lookup. The digest stays as a pre-filter that can only
rule a candidate out.

Control: two_values_sharing_a_digest_are_not_served_as_one_another forges an
entry with the probe's digest over a different value (refused), plus the
same-instance (hit, no reify) and equal-value fallback (hit, one reify) arms.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 5, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Read of the collision fix at 628b258 by sharp-raven-357 (review 76111 approved but didn't discuss it). APPROVE. cross_claim_entry_matches for a served probe: a digest mismatch rejects (sound, since equal values have equal digests, so the digest only rules OUT); the same recorded ServedInstanceKey accepts (exact, since registered instances are retained for the tier's lifetime); otherwise it falls back to portable_value_eq on the caller's argument, reified at most once per lookup. A digest match alone never accepts. Codex 76009's finding is resolved, and the forged-digest control covers it.

— sent from sharp-raven-357

Merged via the queue into main with commit 1634157 Oct 5, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/royal-deer-478 branch October 5, 2026 05:17
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
…path claim as single-claim fill debt (sharp-raven-357)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
…-path claim as single-claim fill debt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
…im as single-claim fill debt

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
Applied this branch's net diff over d0a206d onto main; xl2 nested claim
taken from main (renamed, inverted), pointed at xl2_nesting_run, debt row renamed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
… hand warm row

#13043 deleted the hand-maintained floor_cross_claim_pure_producers_warm roster: cross-claim sharing
is now derived from planned claims' call-site demand. dag_prepared_lex is a nullary producer of a
portable value demanded by many claims, so the derivation shares it; the row and its comment go.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
The 24 #12506 witnesses are restructured per the DESIGN section 3 witness rule,
so their single-claim fill debt retires by typed disposition:
RestructuredPerWitnessRule for cref (6), fps (10) and dre (4);
BecameSharedByDemand for mbt underived_arm_body and sevens_call; ClaimDeleted for
fps_a_root_bound_data_value_is_not_yet_projectable_holds (replaced on main by
the projects positive control after #13216). mbt hiding and dre imported stay
ActiveFillDebt.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 5, 2026
…in's #13043)

#13043 added floor_seam("cross-claim-share-derivation") to the floor runner
without a FloorSeam arm or a FloorSeamToken row; main never runs the unit
lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the
restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation,
its token row, and its arm in receipt_peak_seam.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Oct 5, 2026
…#12951)

* Regenerate docs/design-rung-drops.md after merging main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: the base arm runs only the reached claims whose head can block

reach_head_cannot_block is derived from claim_differential_blocks over every base arm.
A passing head never blocks, and a head where the claim is no longer declared is a
removal under every base, so neither is run at base. The base arm then runs only the
claims that FAIL at head: 60 of 1481 for a one-line v2.std.node edit and 18 of 240
for #12582's change (srv1, 2026-10-01), about 25x less base work. An all-passing reach
spawns no base process.

Controls: a_head_passed_claim_is_never_run_at_base_and_never_blocks (Rust, real
model: the partition sends only the failing head to base, and a passing head blocks
under no base) and only_a_failing_head_needs_the_base_arm (.dag).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitted-package join also matches canonicalized paths, so a symlinked crate dir cannot undercount (review 73526)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: the base-arm budget is born typed Milliseconds (review 73528)

ReachDifferentialStanding's DifferentialBlocking carries base_arm_wall_budget:
Milliseconds (std.types) instead of base_arm_wall_budget_ms: Int, and the host wire
reach_differential_blocking_budget returns Milliseconds, so the unit is the type's
and not the name's. The branded value reaches the host as Value::Int, which the
existing non-negative match unwraps; any other shape still refuses. The sibling
required_floor_claim_wall_safety_limit_ms stays as existing debt, not widened here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: per-identity base verdicts; an unmeasured base blocks only when no roster declares the claim red

A non-verdict base outcome (budget, panic, host tool or effect, not attempted) is now
not_measured for that identity alone; the other reached claims keep their verdicts
(srv1 replay 4d79fc6: one BudgetInterrupted claim voided all 60). Only instrument
failures refuse the whole arm.

reach_claim_verdict takes the claim identity. An unmeasured base on the declared
main-red roster (floor_expected_red_roster, joined by identity) is a counted
base_not_measured_rostered finding that does not block. On no roster it BLOCKS as
base_not_measured_unrostered (deep-ferret-305 ruling, 2026-10-01). A base verdict
decides as before.

Control: an_unmeasured_base_blocks_only_when_no_roster_declares_the_claim_red (.dag:
rostered reports, unrostered blocks, a base verdict still decides).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: planned on the merge group only (operator ruling 2026-10-01), modeled, announced when deferred, naming what newly failed

- v2.workflow.floor_subject_seed reach_planned_for_event decides, over the event the
  runner reads through the authority that chose its diff window, whether reach
  consumers are planned: ReachOnMergeGroupOnly, compared against
  extdeps.github.actions github_event_name_merge_group. This is the phase scoping
  DESIGN puts in the binary, not the workflow YAML. An unreadable event refuses on CI
  (ReachEventUnreadable) rather than silently deferring.
- On any other event no reach consumer is planned or executed (PRs +0), and the floor
  prints phase=reach-differential state=deferred_to_merge_group with the count it
  would have reached.
- A blocking regression or failing new claim prints
  [floor-reach-finding] NewlyFailedAtHead identity=..., so a dequeued author sees
  what broke without rerunning.

Controls: only_a_merge_group_plans_the_reach_differential (.dag, both directions) and
a_pull_request_defers_the_reach_differential_and_a_merge_group_plans_it (Rust, real
rule plus the deferral line).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR: enumerate the three qemu-host-observe readiness arms main added since (census PR1/3)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: blocking verdicts are a typed outcome field the adjudication names, not free text in failures

neat-boar-16's srv1 control (2026-10-01) showed blocking=8 but no per-identity
adjudication line for them. RequiredFloorOutcome gains reach_differential_blocking:
Vec<(identity, differential)>. required_floor_outcome_is_clean requires it empty, and
required_floor_measurement_blockers adds one blocker per identity with cause
reach_differential_<differential> (regressed, new_claim, base_not_measured_unrostered,
refused). A refused base arm records every claim it left unjudged as base_arm_refused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: both main-red rosters; a non-verdict at head is not_measured, never failed; one shared test pool

- claim_on_declared_main_red_roster joins floor_expected_red by identity AND
  gunbc.explicit_witness_admission's known-red rows by (entry, function), through that
  roster's own explicit_witness_admission_is_known_red. On the srv1 control rerun three
  known_red_probe map_literal claims had blocked as unrostered; they now report.
- The head standing uses the base arm's classifier (base_standing_of): a wall
  interruption at head under load is not_measured, verdict head_not_measured, never
  sent to base and never read as a regression. It was matches!(Pass), which made a
  passing base plus a loaded head a false regression. The floor's own
  interrupted_before_verdict rule still refuses such a run.
- The base-only residual is named beside the rule: an unrostered claim whose base lands
  within load noise of the 8 s hang guard dequeues load-dependently (loud, named). Its
  trigger: the hang guard gets its own typed refusal and a much larger declared value
  through one plumbing for both arms.
- reach_base_standings tests share one pool (test_roots): the process-global shared
  index holds a single resident pool, and the fixture test's extra root made test order
  decide a SharedIndexSecondResidentPool panic.

Controls: an_unmeasured_head_is_not_a_regression (.dag); the roster control extended
with the explicit-admission arm; the partition test with a not_measured head. Rust 5/5,
.dag controls true, clippy clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: locate floor runtime-error rows; typed host IO refusal

* Floor runtime-error rows carry message + raising declaration; host write failures are a typed IO refusal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM: portable value map order is process-random (RandomState HAMT iteration; Symbol hashed by address)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Portable map entries in canonical content order; value_hash hashes variant names by spelling; RFM row scoped by the iteration and value_hash censuses, with the DefaultHasher residual

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* emit-host transport read failures are HostIoFailed too (Cargo config read, tool canonicalize/read, cold receipt read, cache evict); probe spawn via host_tool_spawn_failure

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73653: seed-growth justification for the canonical-order Rust; the row states its controls are off the merge path

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Canonical order: floats by IEEE 754-2019 totalOrder (f64::total_cmp), not raw bits, which invert negatives; control floats_order_by_ieee_total_order

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Six ungated main reds re-derived; three entries admitted by importing LiveTreeDisposition

(1)(2) live_deploy.emit sudoers claims: the needle is now the install's own node
(gunbc.ci_deploy_sudoers deploy_sudoers_elevated over the fleet visudo row) rendered by the same
serializer. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). The
two probe negatives are deleted: unmatchable under quoting, and since #12168 those probes are
emitted on purpose after the install.
(3) twin claim: count equality replaced by an identity join on artifact kind, host singletons
(fabric storage + #12747's approval broker front door) subtracted by the functions that decide them.
(4) CPUQuota grant: sudoers side read through sudoers_argument_word (escape since #12563).
(5) tasks verdict: bare `Absent ==` never named the ConvergeVerdict arm; typed match + a Drifted
discriminating conjunct.
(6) runner_lifecycle: fabric rows from srv3/srv4_fabric_first_slot, each controlled by the
slot below it on its own host (srv4-06 is fabric since 2026-09-18).
Admission: build_cache_endpoint_observe, ci_budget_tree_witness, host_allocation_conservation
import v2.std.live_tree (the #12540 class #12819 fixed once); variant rows retired ImportsFixed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci_budget_tree_witness: three live-tree reds were stale premises; re-derived from the producers

witness_live_is_fail_closed asserted the Unestablished arm while srv1 now resolves ReservationBytes;
it asserts each arm's relation over session_reservation_bytes(srv1). witness_srv2_symmetric_to_srv1
assumed equal RAM (srv1 is 512 GiB since 2026-08-22; usable RAM per host since #11625); it asserts
the pools differ by exactly the RAM gap. witness_srv3_outbudgets_srv1_by_exactly_the_overhead_gap
missed the 1,392,640-byte usable-RAM difference; gap = overhead gap + RAM gap, both read from the
producers. Removed from floor_expected_red_chunk_live_tree_admission (they now pass).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: unimported-bare-provider standing judged over the whole pool, not the diff; census fixed

The diff-scoped standing check let #12540's new pairs in untouched files through while
claim_batch's entry route refused them. The floor now judges every pool file (13.6 s over
7,175 files on the warm index, measured). Census at this base: 172 Unrostered + 16 RosterStale.
Fixes: 167 pairs import their declared provider (138 files; no new import cycle), 5 bare
`ends_with` calls that bound to gunbc.rust_item_scan's private helper use the builtin
.ends_with(suffix:) method instead; 16 + 344 rows whose pairs the imports dissolved retire as
ImportsFixed. Re-census: zero refusals.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.algebra: TotalOrder<T> is the one compare law; OrderedRing and Field compose it (WIP)

* Interpreter: one canonical content order (ContentView over Value and PortableValue); map Display/Debug canonical; sort_by admits only emitted-agreeing keys; cmp_values deleted (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Canonical render order: emitter refuses map rendering typed; to_string classified CanonicalOrder; two-process, kind-rank, totalOrder and carrier-differential controls (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rows: RFM rendering receipt and per-path rung; spelling stand-in on variant_owner_identity_stall; seed-growth row extended (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witness: emitted map rendering refused typed; to_string classified CanonicalOrder by the gate route (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Gate comment names the phase line instead of transcribing its measurement; phase line carries standing_ms (review 73712)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: production list order from map_keys -> sorted_map_keys (target_model supplemental-bound and representation-choice nodes, rust_crate_partition first-unknown module, legacy_binding_observation expected ids)

The #12890 warm-row specimen: rust_classical_not_ingested_target_model_staging varied per process because
target_derive_supplemental_generic_bound_requirement_nodes_for_contract built its child list by folding
map_keys (HostUnspecifiedOrder). Keys are Symbol/ModuleId/Int, all admitted by sorted_map_keys, whose order
is identical in both realizations.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop determinism_transitive_reachability: population names the unjudged production corpus; receipt for the six map_keys folds found by the #12890 specimen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitter: a single-field anonymous record literal matching 2+ structs refuses instead of emitting the bare value; VersionScheme literals name their type; revert stage0 files swept in by an interrupted regen

std.algebra TotalOrder gained the same single 'compare' field as extdeps.version VersionScheme, so
find_unique_struct_name_by_fields stopped being unique and '{ compare: f }' emitted 'f' -- a fail-open
arm (DESIGN section 5). It now refuses exactly as the multi-field arm does; the three VersionScheme
literals carry the nominal type that remedy names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Split the two cost-debt-rostered sudoers claims out of this PR

The floor's changed cost-debt edit judgment lexes the whole 125 KB emit_test.dag at base and at
head per identity in the interpreter; with these two identities changed, site projection ran past
the 90-minute cap (run 36856989404). Their fix moves to its own PR, held on that floor defect.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* live_deploy.emit sudoers claims: needle is the install's own node; unmatchable probe negatives deleted

Split from #12905. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitter annotation moved to module-item grain

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire the one row main's merge made stale (ownership_movable_test#Read); re-census over 7,193 files: 0 refusals after this

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 (std_algebra, std_primitive_projection, v1_compiler_emit_rust); control: supplemental-bound requirement nodes emit in canonical parameter order (the #12890 specimen at its cause)

regen-round-cost converged in one stage, changed_paths=3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor cost-debt edit judgment: one lex per changed file, shared by every identity in it

v2.workflow.floor_cost_debt_edit judged each changed cost-debt witness in its own call, and each
call lexed the whole base and head file, so a file with k changed witnesses paid 2k lexes. With two
changed witnesses in the 125 KB emit_test.dag, site projection ran past the floor's 90-minute cap
(run 36856989404). The wet entry is now cost_debt_changed_witness_ceilings_at_base, called once
per file with every changed cost-debt function in it. It lexes base and head once, reads the base
resolution once, and selects each declaration from those streams. The host prints
`[floor-cost-debt-edit] judgments= changed_identities=` as the control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Pin PlannedAsReachConsumer as not a changed-witness selection in the sublane join

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* clippy: redundant closure in the per-file ceiling call

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2.std.integer: int_ordered_ring composes order: TotalOrder (OrderedRing no longer restates compare/lt/le/gt/ge)

Control supplemental_bound_requirement_order: requirement_nodes_are_emitted_in_canonical_parameter_order
returns true, and false with map_keys restored at the outer fold (discriminating).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md (docs_projection_gate regen)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a raw string literal opened in a body is tracked; an unattributed refusal names its cause

The census could not judge gunbc#12886 because the scanner tracked raw string
literals only when opened on an item header. A `let src = r#"...` fixture in a
body let its own column-zero `}` close the fn early, and its `"#;` then refused
the file (interp_recorded_fixture_witness.rs:458). The same shape put 5 of the
9 hand files on main out of reach. An item ends at its own closing brace, and a
brace inside a literal is not one: every item line is now read for an unclosed
raw literal (token-start `r`/`br`, terminator from its own hash count). Only a
header-opened literal's end may end the item.

v1_interpreter.rs was never unscanned: the scanner reads it whole (1040 items,
36 macro regions) and attributes #12814 completely. #12886's v1_interpreter
refusal is a line inside `thread_local!`, the declared macro-item ceiling, but
it was reported with the out-of-range sentence. The refusal now names which
cause fired.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md after merging main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM: anonymous_record_resolved_by_field_names_guesses_on_ambiguity (the emitter one-field fail-open TotalOrder exposed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: DifferentialBlocking per the operator's 2026-10-01 option-B ruling

Base-arm budget 625200 ms: the largest srv1 base arm measured (312.6 s for 22
identities, loaded host) times 2 for load variance; an arm over it still refuses
with BaseArmOverBudget. PRs still defer to the merge group.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: an expression-bodied item ends at its own semicolon; a backslash-continued line is string text

A `static NAME: T =` header that rustfmt continues before its initializer puts
the declaration's `;` one indent deeper, so the item stayed open and swallowed
the following items until a column-0 `}`. That was a SILENT mis-attribution:
cli_run.rs `static PROVIDER_BOOTSTRAP_STORE_SKIPS` absorbed
`fn record_provider_bootstrap_store_skip`. Across 22 hand files, about 125
items were never recorded, 7 of them in v1_interpreter.rs
(record_builtin_time_inclusive, canonical_symbol_spelling, ...). An item whose
header ends at `=` now ends at the continuation-indent line that ends the
statement.

A line after a trailing backslash is string-literal text at whatever indent
its author chose, never structure. The line that ends such a literal with `;`
ends an expression-bodied item; ExprBody is read from rust_item_forms, not
listed here. No item key is lost in any hand file, and the refusal count is
unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_host_observation: carry the refusal from the one attribution; RawLiteral replaces terminator+flag

Review 73783 found that change_lines_unattributed reduced each attribution to a
line number, and unattributed_line_detail recomputed it. That was the same fact
derived twice (DESIGN §2), and the recompute needed two arms that wrote a
fabricated sentence (DESIGN §5). change_lines_unattributed now matches once
into RustLineRefusal, which has only the two refusing arms
(LineInsideUnnamedMacroBlock, LineBeyondTheFile). The detail is read off that
value, so the record and its sentence cannot disagree.

Also from the review: ItemScope's raw_terminator + raw_opened_on_header could
represent "opened on the header with no terminator". They are now one variant,
RawLiteral = NoRawLiteral | OpenRawLiteral { terminator, opened_on_header }.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.algebra: the TotalOrder comment names the real (seed-retained) realization instead of a symbol that does not exist (review 73794)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitted ordering keys fail closed: v1_rt CanonicalOrdKey (String, i64, bool only) bounds sorted_map_keys and sort_by; sort_by drops partial_cmp(..).unwrap_or(Equal); enrolled one-order claims; seed-growth trigger names the capability and first consumer

neat-boar-16 conditions for executed agreement on #12925: (1) enrolled claims
test.claim.canonical_order_enrolled_witness; (2)+(4) trigger at capability grain naming the first
real consumer; (3) the emitted frontier refuses non-admitted keys typed (on_unimplemented message).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a static inside thread_local! is a named item, by upstream citation

extdeps.rust.std_thread_local records std's thread_local! as the pinned 1.93.0
docs state it: the macro "wraps any number of static declarations", and
"Publicity and attributes for each static are allowed". The scanner reads a
thread_local! block as a scope that admits exactly those lines. Each static is
an item of the enclosing module, so a change inside one is attributed to it by
name. Anything else in the body refuses, and so does a one-line
thread_local!(...), which this reader cannot split. Every other macro stays at
the declared macro-item ceiling (macro_rules! controls).

On #12886's tree the census now observes the change completely:
JSON_ENCODE_NESTING is an added static, and the only unreadable hand file left
is phase_profile.rs (extern "C").

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a header at the open item's own indent refuses; a trailing comment does not hold a declaration open

The swallow class becomes structural. Whatever leaves an item open past its
end -- a continued initializer, a trailing comment, an ordinary multi-line
string, or a construct not yet met -- next meets a sibling item header at the
open item's own indent, and no item body puts one there. scan_step now refuses
at that header instead of reading it as body. Under the prior reader that
refusal fires at the original swallow sites in cli_run.rs and v1_interpreter.rs.

A second instance surfaced by the same measurement is fixed. A one-line
declaration followed by `// comment` did not end in `;`, so it stayed open and
swallowed the next const (resolved_graph_cache.rs PART_DESCRIPTOR_LEN over
V3_HEADER_LEN). A `//` with an even quote count before it now starts a comment.

Files the recurring failure mode as its general class,
gunbc.recurring_failure_mode census_instrument_silently_drops_items: a census
instrument whose parser silently drops items reports a smaller population, and
a short count reads as success. Its distinguishing fact is that a swallowed
item's lines ARE attributed (to the swallower), so a line-coverage join passes.
The violated join is header coverage.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 (whole-compiler rebuild: runtime CanonicalOrdKey reaches v1_compiler_stage0_crates)

--regen-round-cost refused with WholeCompilerRebuildRequired (partition generation authority
changed), so candidates were emitted with --required-regen, installed, the whole compiler rebuilt,
and --required-regen re-run: first_generation_equal=true over 161 planned.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enrolled one-order claims import empty_map/map_insert from v2.std.collection (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Name the instrument instead of transcribing the probed RAM gap (review 73848)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge group: the floor window's base is the group's own parent (merge_group.base_sha), never origin/main

#12514's first live merge_group run (group head 529d438) compared against main
8a249e7 and charged the four PRs queued ahead (#12921 #12735 #12770 #12905) to
this landing: three order-edge claims from #12770 read as regressed.

- extdeps.github.merge_group_event: cited payload reader for merge_group.base_sha
  and the merge queue's group-composition guarantee (cited), consumed by the resolver.
- gunbc.diff_baseline: MergeGroupBase arm; merge_group resolves through
  resolve_merge_group_base, which REFUSES on an absent/empty/unreadable/malformed
  base_sha and never falls back to origin/main. Two-dot comparison.
- Witnesses: payload parsing (nested member, absent, empty, not an oid, not json)
  and resolution (own parent, no parent refuses, cause carried).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: derive gunbc.rung_drop.roster from its directory by declared type (shared fold with RFM)

Unverified by CI; main_wet regen of stage0 mirrors not completed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* #12514: cover PlannedAsReachConsumer in main's newer disposition matches; hoist in-body annotations

Merging main brought six matches over RequiredFloorDisposition written after the
reach-consumer arm existed on this branch (E0004 in emit-build). Each new arm follows
the .dag authority: v2.workflow.floor_changed_witness and v2.workflow.required_floor
treat PlannedAsReachConsumer exactly as Planned (planned standing, gate runs, not a
cost-debt withhold, CostDebtDeclaredButNotWithheld, never suppresses a changed-witness
enrollment).

merge_group_event.dag carried '//' annotations inside a type body, which DESIGN §4c
refuses; they move to the leading block above the declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: cover variants that landed on main after the NFR enumerations were written

Composing the burn-downs with main exposed two non-exhaustive matches, the
exact class enumeration exists to surface:
- floor_unimported_bare_provider_debt_roster: three standing matches lacked
  Retired { cause: RelocatedOutOfSourceRoots } (floor refusal, CI run 36931173776).
- target_model realized-closure body classification lacked ParameterReferenceBody,
  added by #12766 (emit-build refusal); it projects like DeclarationReferenceBody.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate stage0 mirrors to a fixed point; cover more variants that landed after enumeration

- stage0 mirrors regenerated locally (claim_executor --required-regen, whole-compiler
  rebuild between rounds) until first_generation_equal=true (161/161 adjudicated).
- DESIGN.md and docs/design-rung-drops.md from tools.docs_projection_gate regen and
  generated_artifact_gate main_wet_verified.
- More matches the NFR burn-downs enumerated before main added variants; each new arm
  keeps what main's removed wildcard returned:
  live_deploy emit identity_member_of_step and member_observe root_members_of_step
  gain ApprovalBrokerFrontDoor (none / []); mtcollins1_kvm_still kvm_pending_step,
  kvm_established_step and kvm_gap_mark gain KvmJournalNavigated/PageConsole/PageError
  (acc / []).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: retire 31 bare-provider rows the composed tree no longer carries

The pool-wide standing check (#12908) judged the composed head and found 31 ActiveDebt
pairs whose files no longer carry them (imports added by the other merged burn-downs).
Each is retired as ImportsFixed, exactly as the refusal names (CI run 36939427278).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate after merging main; name runner_microvm_boot_probe's Filesystem authority

- stage0 mirrors regenerated to a fixed point after the main merge (first_generation_equal=true),
  docs/design-rung-drops.md regenerated; main_wet_verified green.
- runner_microvm_boot_probe read Filesystem bare while three modules declare it
  (AmbiguousBareNameRead, floor run 36941252236); it uses Filesystem.Write, so it imports the
  service from extdeps.filesystem.filesystem_io, as its sibling runner modules do.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate the rung-drops projection after the main merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: back out #12610 (typed NFR check D)

Its typed check judges every module the diff touches, and this branch's diff touches
hundreds, so the floor refused with 65 unrostered closed-coproduct wildcard sites
(NonFoldResidueRosterDiverged, run 36948688303). That is exactly the joint landing
#12610 was waiting on (census roster, old-scan deletion, srv1 typed census at 0/0),
which is not built. #12610 is reopened to carry it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: iterative Drop for PortableValue

value_depth_walker_tests::a_deep_value_round_trips_through_the_portable_form aborted the
test process (stack overflow, SIGABRT, rust-unit-tests run 36951304061) when the deep
portable chain was dropped: PortableValue is a plain owned tree, as deep as its value, and had
the recursive default drop. It now drops through a heap worklist exactly as impl Drop for
Value does (class recursion_over_value_depth_uncounted_by_the_call_limit). The test passes
locally, and the other deep-value tests still pass.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: green the --lib population #12753 makes blocking

#12753 turns rust-unit-tests into a blocking lane, so this branch must carry a green --lib
population. Main's own reds, which nothing ran:
- closure_edge_demand_tests::required_phase_..._catches_a_bypass judged a second root set on
  the same thread, which #12831's SharedIndexSecondResidentPool now refuses; the twin pool's
  judgment runs on its own thread, as a separate floor run would.
- compile_clean_via_index_verdict_equivalence::regen_subject_admits_a_provider_reached_only_by_
  reference wrote a bare cross-tree reference, which #12741 refuses (CrossTreeBareReference);
  the fixture now writes it qualified, still reference-only with no import.
- nfr_roster_receipt: 13 parameter-scrutinee wildcard sites landed on main after the
  2026-10-01 census; rostered with a stated reason and the owning-fold dissolution.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: live-pool tests start from no held pool

live_pool_thread_tests::two_claims_on_the_live_pool_thread_share_one_index failed whenever
an earlier test had left the live-pool thread holding its own fixture pool: #12831 refuses a
second resident pool on one thread (SharedIndexSecondResidentPool). Each live-pool test now
releases the live pool first (yield_live_pool_before_building_another), so its result no longer
depends on test order. The serial suite's live-pool and content-key tests pass (7/7).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate stage0 after the main merge; roster 2 more post-census NFR sites

- v1_compiler_emit{,_rust}.rs regenerated from main's base to a fixed point
  (first_generation_equal=true); docs projection unchanged.
- dag/gunbc/action_use_admission.dag checkout_context_names_a_commit and
  checkout_ref_value_refusals landed on main after the census; rostered like the earlier 13.
- Full serial --lib suite (RUST_TEST_THREADS=1, as CI runs it): 1116 passed, with the only
  failure being these two sites, now green.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: keep a deleted file's roster row FileDeleted; stop a test helper from providing 'github' pool-wide

- import_closure_live_test.dag#ReadsLiveTree: the file is deleted on main, so its row stays
  Retired FileDeleted (my conflict resolution had taken ImportsFixed).
- #12835's fleet_converge_checkout_pin_witness_test.dag declares a top-level helper
  'fn github(path:)'. With #12908's pool-wide standing check, that made it a candidate bare
  provider for every module that reads 'github' bare (115 Unrostered refusals, run
  36964372555). The helper is test-local, so it is renamed github_context_access; it no
  longer collides with the 'github' those modules mean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "integration: merge #12912 (session/deep-deer-663-sudoers)"

This reverts commit 9502c4c, reversing
changes made to c276c43.

* Regenerate stage0 mirrors and rung-drop docs after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* github_app_registry witness: import its live-tree disposition instead of reading it bare

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs and stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: rows for parse_sequence_capture and grammar_emit_sequence (landed on main after the census)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors and docs after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Cover main's new LexicalReferenceKind / LexicalReferenceBody in two enumerated matches; docs regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider debt roster: the three body_lowering tests' rows are ImportsFixed on this branch (floor: RosterStale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: delete the 757 rows whose wildcards this branch's burn-down PRs enumerated (floor: stale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* semantic_decl_emission: the four edge-label matches name Authored and StructuralLabel (Named is gone after #12799)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* target_model: name StructuralLabel in the wire-child declared-type match; docs regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* match_pattern_binds_erased: carry the pattern's parent_identity (main's VariantPattern field)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* program_partition, realization_attempt: name StructuralLabel in three edge-label matches (#12799)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate DESIGN.md from the merged design_document (generated_artifact_gate main_wet)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: restore main's rows for the five wildcard bodies taken from main in the #12799 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap_belt_actuate: delete belt_spawn_tally_not_admitted, left without a caller once main's arms were taken

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Delete two branch helpers left without a caller once main's arms were taken in the #12787 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the #12787 merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider debt roster: retire three pairs the merged files no longer carry (floor: RosterStale -> ImportsFixed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* unit_standing, runner_microvm_slot_unit: name RuntimeMaxSec in four directive matches taken from main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider roster unit test: ImportsFixed -> FileDeleted now admits (#12787's rule); the reverse still refuses

#12787 made FileDeleted terminal in v2.workflow.floor_unimported_bare_provider_debt without updating this Rust test, which main does not run as a blocking lane.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the #12512 merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_unit_live_read: the enumerated converge-verdict arms name VerdictAbsent (#12721)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: drop two rows main added for d0 sites this branch enumerates (floor: stale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: floor fixes after the main merge; #12753 retirement text claims only what was observed

- debt roster: fabric_witness_run_test HardRequirements/Shape/current_runner_slot_profile keep
  main's Retired ResolvesInClosure (the floor refuses a changed retirement, RosterRetirementChanged).
- unit_standing_witness_test: import extdeps.systemd { systemd_duration_usec } (Unrostered on the
  floor; the file declares imports so its bare channel is off).
- rust_unit_tests_off_the_merge_path: the merge_group pass had not happened; the text now says the
  merge_group revision is proven by the queue's own required run at landing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Heal-Candidate-Run: 37180751525

* Regenerate docs projections (docs_projection_gate regen)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 1)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* integration: follow main's #13186 (HeadGrain deleted) in the ownership join; LoadCredential arm in the microvm slot unit

- gunbc.refusal_reason_ownership_join: main keyed cause ownership by cause alone and deleted the grain
  field, so a row owns its cause; reason_is_fatal_owned is the cause match. The witness drops the
  HeadGrain control (head_row / head_grain_row_does_not_own_a_fatal_reason): the state it planted is
  no longer constructible.
- runner_microvm_slot_unit: main added SystemdServiceDirective LoadCredential; the enumerated
  directive match was non-exhaustive (floor declarations finding).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: delete the 2 NFR rows whose sites no longer carry a wildcard (floor NonFoldResidueRosterDiverged stale=2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Heal-Candidate-Run: 37235281080

* Regenerate docs projections and witnesses.yml after stage0 regen

* integration: the four rust-unit-tests reds the restored lane surfaced (all stale against main, which runs no unit lane)

- nfr_observation_roster_test: gunbc#13277 enumerated ci_hold_cause_text and drained its NFR row;
  the test now asserts the row stays drained (renamed observation_hold_cause_row_stays_drained).
- process_cwd_mutation_reachability_gate: a_stale_binary_is_refused_before_any_instrument_runs
  reached test_verb's producers, several of which set the process cwd. The freshness refusal is
  split out as stale_binary_refusal and the witness calls it, so the route is asserted without
  reaching any producer; test_verb_after keeps the same behaviour.
- changed_selections_outside_discovery_mirror_tests: since gunbc#13138 the .dag decider returns
  its list as a free-monoid Cons/Empty chain (list_reverse); the test reads either realization.
- renderer_hop_decides_realization_from_declaration_identity_without_an_env: the structural-Bool
  half retires as dissolution of the Bool de-fork (gunbc#12583), mirroring the .dag witness's
  retired row; the prelude control stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: list_items matches the Value by reference (E0509: Value implements Drop)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: pin run_native_serve_program in the cwd gate's undecided set; carry the renderer-hop retirement into its .dag source

- process_cwd_mutation_reachability_gate: main's #13135 declared run_native_serve_program in two
  files, the exact shape of the pinned run_native_claim_program (producer called only from its own
  TargetProducer match; the native_lane_runner twin reached by the qualified cli_run:: spelling).
- compiler_tests.rs is generated from v1.compiler.compiler_tests_rust; the structural-Bool
  retirement is now authored there, rendering the same lines the mirror carries.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: the compiler_tests_rust mirror carries the renderer-hop retirement its .dag source now authors

v1_compiler_compiler_tests_rust.rs is the emitted form of v1.compiler.compiler_tests_rust; its
ct_renderer_hop_identity_keying_test is re-rendered in the emitter's own concat shape (the old body
round-trips byte-identically through the same rendering), so the regen's first generation agrees.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* Reach differential: an unmeasured head and a claim declared at neither side refuse, never pass (review 76405)

reach_claim_verdict returned a non-blocking 'head_not_measured' for a head
with no verdict; it now refuses typed and located (DESIGN 5). claim_differential
mapped NotDeclared at both sides to DifferentialRemoved (never blocks); it is
now DifferentialUndeclaredAtBothSides, which blocks, so a removal runs the
base arm to prove it was one. Tests: an_unmeasured_head_is_refused_not_reported,
a_claim_declared_at_neither_side_blocks_and_a_removal_reports, and
only_a_passing_head_skips_the_base_arm.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Reach differential: not_measured is a declared parsed arm; one constructor builds the verdict (review 76416)

ParsedClaimStanding gains StandingNotMeasured, parsed once in
claim_standing_named; reach_claim_verdict and reach_head_cannot_block match the
arm instead of each comparing the string. reach_verdict_of builds ReachVerdict's
name and blocks from ONE ClaimDifferential value, so they cannot disagree; the
two flat fields stay because they are the wire the seed floor runner reads.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* floor_demand: typed arm for the cross-claim-share-derivation seam (main's #13043)

#13043 added floor_seam("cross-claim-share-derivation") to the floor runner
without a FloorSeam arm or a FloorSeamToken row; main never runs the unit
lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the
restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation,
its token row, and its arm in receipt_peak_seam.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung drop rust_unit_tests_off_the_merge_path: retired on its own trigger, runner supply, with the receipt (review 76493)

The trigger_fired text cited the population being green and the job being
re-added, which the row itself says does not retire it. It now cites the
supply receipt from this PR's required runs: the unit job starts with the
other lanes (no queueing) and finishes before floor, so the required wall
did not rise. It also cites the operator's sign-off for the roster addition.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung drop rust_unit_tests_off_the_merge_path: restore the declaration the last edit dropped (review 76497)

163ef99 replaced the trigger_fired text but cut through to the end of
the declaration's AuthoredProse, deleting the drop's record of what it
declared (and leaving the record without a required field). Restored from
its parent; only the trigger_fired string differs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs projections (rung-drop retirement text)

* Regenerate DESIGN.md (generated_artifact_gate main_wet_one): the unit-test lane is no longer described as off every CI path

* rung drop retirement: name the instrument for the supply receipt, not the transcribed wall times (review 76511)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs projections and DESIGN.md (retirement receipt names its instrument)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate stage0 mirrors after the eighth main merge (round 1)

* Regenerate docs projections after the tenth main merge

* required_floor_runner test: cost_debt_clean_outcome carries reach_differential_blocking

Main's test constructor (added with the moved required_floor_outcome_is_clean)
predates this branch's field; the unit lane failed to compile (E0063).
cargo check --lib --tests is clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate DESIGN.md and docs projections after the eleventh main merge

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants