Repository navigation
Dogfood G4: return a typed attempt result to the requester on the issue event log - #13075
Conversation
…ute) gunbc.roadmap_dogfood_route folds one attempt's durable records into a closed DogfoodRouteReceipt over the eleven route stages (request, immutable subject, shared computation, placement grant, isolated execution, durable result, metering, cleanup, result returned, candidate published, independent review). Completeness is an identity join: a stage missing or read twice is malformed and named; one owed or refused stage withholds the receipt and is named. Stages with a producer today are read off the attempt's own workflow segments (no second reader); the six without one are typed Owed by the change that will produce them (G1 shared computation, G3 metering, G4 result returned, G5 placement/isolation/cleanup). dogfood_route_acceptance_holds reads every srv2 attempt and holds when one folds Complete -- the first such attempt is the dogfood start receipt (operator ruling 2026-10-03). It is a plain function, not a floor witness: its subject is a deployment's attempt records, which a CI runner lacks. The roadmap row factory-dogfood-route binds it under the factory project. Witness (supplied values at the two interfaces): positive control; owed, refused, missing and duplicated stages; segment-to-reading mapping. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressed review 74515 in c4345b7: the reader's annotation no longer cites |
…e belt's selectors Review 74522: - Request and immutable subject no longer read records that belong to other stages (the environment admission; the verification verdict). Each is owed by the change that writes its own record: request by G4 (the Claimed event joined to the attempt), immutable subject by the G1 cutover (the exact tree the shared computation was keyed on). Durable result stays on the verification receipt, which is that record. - DogfoodStageReadings is a product with one field per stage, so a stage missing or read twice has no constructor; the Malformed arm, the identity join and the stage-equality helper are deleted. - Segments are selected by the belt's own exhaustive selectors (belt_verification_segment, belt_review_segment, and the new belt_publication_segment beside them) instead of a hand-numbered ordinal. - The yes/no completeness predicate is inlined as a match at its one use. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Review 74549: - gunbc.roadmap_workflow_stage workflow_segment_of_kind (with workflow_segment_kind_eq read once through the kind's own key) replaces the hand-written per-kind folds: belt_verification_segment, belt_review_segment, belt_goal_audit_segment and the belt_publication_segment this PR had added are deleted and their callers rewritten; roadmap_attempt_continuation's verification_segment_of (no callers) is deleted with its now-unused kind imports. A new segment kind is one edit, not one per copy. - The dogfood route's durable-result stage reads the SUBMISSION segment (the worker's candidate captured and committed at the head), not verification's verdict, so no stage rests on another stage's record. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… durable start receipt Side-chat ruling on #13077 (NO-LAND at c55dd72), four findings: 1. The start receipt is selected and retained. dogfood_start_record_for_instance runs in the belt tick right after its passes and writes the first complete attempt ONCE, create-only, through the durable CAS store (file_compare_and_set, ExpectSlotAbsent) under <instance_root>/dogfood-start. The candidate-published stage is written by that same tick's publish pass, so the completing attempt is necessarily current when observed; once recorded, a newer attempt cannot move it. A refused write fails the tick loudly. The acceptance function now READS that receipt. 2. One record per stage is enforced by types: SubmissionEvidence, ReviewEvidence and PublicationEvidence are sole_constructor and built only from the producer's decoded record; each stage has its own reading type; stages with no producer have no Established arm (ProducerPending), so the route cannot complete until their producers land. 3. The route is declared in production order (review before publication: the belt publishes only a head whose review approved). The binding is the head: publication evidence requires its receipt's expected head to be the captured submission's head. 4. Witnesses exercise the real seams: the submission/review/publication readers over producer records (the publication receipt rendered by roadmap_publish's own encoder), cross-head publication refuses, the fold names the eight owed stages in route order, first-complete selection, and the start receipt round-trips through the acceptance read. Single reader: gunbc.roadmap_belt_actuate exposes belt_workflow_attempt_evidence_for_ref (the typed evidence the progress projection reduces) and belt_workflow_attempt_evidences_observe_for_instance; belt_workflow_progress_for_attempt_ref is its reduction. ROADMAP.md regenerated for the factory-dogfood-route row. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dence Side-chat re-ruling on #13077 (NO-LAND at 6c9082a), three blockers: 1. The acceptance read decodes the whole receipt. DogfoodStartReceipt carries node, attempt, head, submission digest, review subject/plan/digest, PR number/url and an Rfc3339Timestamp; one join validation (dogfood_start_receipt_defect: review_subject == node@head, 40-hex head, positive PR, canonical RFC 3339 UTC instant, no empty identity) is run by the mint, the encoder and the total decoder. A refused clock refuses the record before the CAS; it is never written as the time. 2. The recorder scans durable attempt HISTORY: belt_workflow_attempt_evidence _for_key reads a named attempt (the current-pointer builder now delegates to it) and belt_workflow_attempt_history_evidences_observe_for_instance reads every dispatch ref by its own key. The scan stops once a valid receipt is in the slot. "First" is stated as the first complete attempt observed by a successful recorder; ties within a scan go by refname order (deterministic, not temporal). 3. One mint from evidence: dogfood_start_candidate builds the receipt from a single WorkflowAttemptEvidence and checks the joins; the encoder re-checks them, so correctness does not rest on sole_constructor (not enforced on the native route); review evidence carries an exact digest of the review report. Witnesses: decoder accepts a complete receipt; rejects a same-schema fragment, cross-field disagreement (subject node/head, bad head, PR 0, empty node), refused/empty/non-canonical times; decoded receipt round-trips. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Reworked to the side-chat NO-LAND ruling on 3c70d77 in e75f127; the PR description is rewritten for this head. In short: (1) the attempt records its |
|
Re review 74752: verified. Not changing the code here, and why: those declarations are not this PR's. They are bold-bee-114's refactor from #13077, carried as a patch that its owner asked to be kept byte-identical so the two PRs do not fork one builder. Their consumer is If #13077 is not going to land, the right fix is to drop the unused observer and the citation from this PR, and I will. — sent from tidy-pike-588 |
…ep while unproducible Side-chat ruling on #13077 at 49f9cdd (NO-LAND), two blockers + hardening: 1. belt_workflow_attempt_evidence_for_key reads EVERY attempt-varying fact by the supplied key: admission, provider events and spawn failure now use dispatch_attempt_admission/events/spawn_failure_path_for_instance instead of the node's current projection. The provider-event projection is one argv over a path (dispatch_events_projection_argv_at, belt_provider_event_projection_observe_at); the current-pointer versions delegate. The validation summary stays node-level (the node's contract). Wet witness test.claim.roadmap_attempt_history_evidence_wet_witness_test plants K1 (historical) and K2 (current) with distinct sentinels: reading K1 by key returns only K1's, the current wrapper only K2's. 2. The recorder finds a candidate before reading the clock (dogfood_first_complete_evidence, then dogfood_start_step), and reads the clock only when a candidate exists. Producer-less stages live in one constant record (dogfood_unproduced) read by both the fold and the recorder; while it is non-empty the recorder answers NoCompleteAttempt without a history sweep. Pure controls: no candidate -> NoCandidate whatever the clock; candidate + absent/refused clock -> refused; canonical instant -> timestamp. 3. CasPreconditionFailed decodes the observed receipt before reporting AlreadyRecorded. Row text states the exact semantics (first complete attempt in refname order, by the first successful recorder). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ue's event log Stacked on roadmap/dogfood-route (#13077) at b542857; this commit is the whole G4 change on top of that branch. - gunbc.roadmap.roadmap_attempt_request_binding: at launch the attempt records the Claimed event its issue is held under. - gunbc.roadmap.roadmap_event_log: ResultReturned { attempt, claim, return_to, outcome } replaces the writer-less PublicationObserved; strict per-arm decoder; a second result for an attempt is not admitted. - gunbc.roadmap.roadmap_event_carrier: the append asks that admission. - gunbc.roadmap.roadmap_result_returned: final-state classification over CandidateHandoffState, the claim join, the pure write decision, the reconciliation over durable attempt history, and result_returned_observe_for_attempt. - gunbc.roadmap_belt_tick_cli: the reconciliation runs on every tick; the tail exit keeps every failure cause. - gunbc.roadmap_workflow_progress: the attempt row carries its handoff state. - gunbc.roadmap_page: the issue stream renders every outcome. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
c58d519 to
9e52e23
Compare
|
Re review 74752: resolved by stacking, at 9e52e23. This PR is now based on |
…terface The floor runs witnesses hermetically and shell.Mktemp.DirWithTemplate has no hermetic arm, so the wet two-attempt witness never reached its subject (route_gap). Rather than enrol it as route-gap debt, the keyed addressing the side chat's finding is about is extracted into one pure function, belt_attempt_record_paths (admission, provider events, spawn failure for one named attempt), which the evidence builder reads through, and witnessed at that interface with supplied values: K1's paths name K1's directory, two attempts never share a record path, and a historical attempt never resolves through the node's current-attempt projection. The builder's real route runs in production via the belt's history scan. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # ROADMAP.md # dag/gunbc/roadmap/roadmap_belt_actuate.dag
…ion/tidy-pike-588
… the event
Review 74788: the event carried return_to beside the claim it names; the
standing fold trusted the copy while only the reader checked it against
the claim, so one fact had two homes that could disagree.
ResultReturned is now { attempt, claim, outcome }. The fold, the reader and
the page read the recipient from the claim via roadmap_claim_return_to.
The carrier's append admission also refuses a result whose claim is not a
Claimed on the same history, so a result with no readable recipient cannot
be written.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 74788: fixed in 66d2938 by the first option. |
Review 74930: belt_run_once_cli_note was a data String no program reads, and this change had added an exit rule to it. The text is now the leading annotation on belt_run_once_cli and the row is gone; the one citation of the row's name now names the entry. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 74930: fixed in 529766c. CI note for reviewers: this PR is stacked on |
…onsumed Side-chat NO-LAND at e7e9ca9, two blockers: 1. The start-receipt CAS root was never provisioned. The slot now lives in the instance's attempt-state root, which the deployment's AttemptStateRoot member converges (gunbc.live_deploy.spec deployment_owned_steps). The tick tail (belt_tick_tail_exit) writes the served observation before a refused start record fails the tick. Wet controls run on a fresh instance layout, enrolled on the local-repo wet lane (exclusion row, wet schedule, route-gap chunk 33): - an unconverged root refuses; - a converged root reads absent and the tick tail succeeds; - the first create commits and a competing create decodes the winner; - an invalid winner refuses. 2. The landed G5 reader is consumed. WorkflowAttemptEvidence carries one SessionPlacementObservation, read by the supplied attempt key in belt_workflow_attempt_evidence_for_key. - placement-grant is established from a recorded grant: host, unit, grant identity and fence. - cleanup is established from a settled release bound to that grant. - isolated-execution stays owed to a named producer, because the slot and record do not establish that the capped unit ran. - dogfood_unproduced now has six stages, and the route witness asserts the same six. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in roadmap_belt_tick_cli.dag: that branch added its own belt_tick_tail_exit(served, start). It is kept unchanged; the result-return exit is renamed belt_tick_result_tail_exit and wraps it, so the result return still runs first on every tick and the exit names every cause. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rved-before-recorder dependency Side-chat NO-LAND at 845ed0e: 1. DogfoodRouteComplete carries placement and cleanup evidence; dogfood_route_complete_of refuses cleanup of another grant/fence; the start receipt (schema v2) carries grant identity, fence and cleanup outcome through wire, decoder and defect check. 2. The raw-wire writer is gone: the create-only write is inline in the evidence-derived recorder. Wet claims plant through the generic CAS primitive and ask what the recorder and acceptance read make of a valid or invalid occupied slot. 3. The tick's tail matches on the served observation's exit before the recorder runs; belt_start_record_exit maps only the recorder's outcome; the exit contract names it. 4. The roadmap authority row states six owed stages, G5 placement and cleanup produced. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # src/v2/workflow/floor_route_gap.dag
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
RulingNO-LAND #13075 at This ruling is independent of #13077’s outstanding repairs. Do not queue a future retargeted head without fixing the G4 issues below. The exact stacked head is mergeable against The prior three findings are much closer:
Three request/result-binding blockers remain. 1. The attempt does not carry the claim that caused its dispatchThe request claim is not an input to launch admission or the spawn plan. During attempt-state initialization, the code rereads the issue log and binds whichever claim is current at that later moment: This leaves the following race: K’s result is now addressed to C2 even though C1 caused K. The stored binding is also not immutable. This must be a fact carried from the exact dispatch decision that admitted K, not a second read of current issue state. The attempt initialization should receive a typed request binding containing the claim event ID from that decision and persist it create-only: Required controls:
2. An unreadable request log still launches work that can never return a resultWhen the issue history is unreadable, forked, or incomplete, initialization writes: That is still At completion, that same record becomes This is a permanent loss of the exact obligation G4 exists to discharge: For a request-bound worker attempt, inability to establish the exact claim must refuse launch. It cannot be recorded as a permanent “unobserved” fact and then treated as successful initialization. A genuinely autonomous attempt with no requester can have a separate typed launch class and remain outside G4. Do not collapse that case with a request whose identity could not be observed. 3. A result event is not checked against the attempt’s bindingThe shared event carrier admits a
It never reads the attempt’s The reader is weaker still: It receives no expected node and reads no request binding. It searches all issue logs by attempt key, selects the sole issue containing such a result, and accepts the result’s own claim. fileciteturn303file0 fileciteturn293file0 Therefore this bad history remains constructible: Both pass the carrier’s current admission if the named claim is a Worse, the anti-entropy population considers K answered when any result event with key K exists anywhere: So the misaddressed event removes K from the open population and permanently prevents the correct C1 result from being written. fileciteturn293file0 This disproves the PR description’s assertion that a misaddressed result is no longer writable. Required repairThe authoritative identity is the full tuple: Both writing and reading must establish it.
Required reds:
Stack integration requirementThe current merged tail executes, by data dependencies:
That inherits the outstanding #13077 issue: a long-running or aborting start recorder can still prevent the served observation from running. After #13077 is repaired, the integrated ordering should be explicit: That gives the dashboard the newly returned result while ensuring the start recorder cannot freeze the page. The retargeted head must preserve this as an actual dependency, not as eager argument evaluation plus comments. What should remainKeep:
The missing srv2 wet receipt is not the current code-review blocker. After the three binding repairs and the corrected stack ordering, require the production receipt already identified in the PR: Reapproval bar: immutable dispatch-carried claim binding; launch refusal when that binding is unobservable; exact |
Conflict in roadmap_belt_tick_cli.dag. The tick tail is now result return, then served observation, then start record, as dependencies: the observation is taken inside a match on the result-return pass (every arm proceeds, so an undelivered result cannot freeze the page), and the start record runs only after a persisted observation, through that branch's belt_start_record_exit. belt_tick_result_tail_exit remains the one pure join that names both causes. The exit annotation carries the new start-record sentence. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nly binding, exact identity Side-chat NO-LAND ruling on d74ed55. 1. The attempt carries the claim from the dispatch decision. The assign route passes LaunchForClaim { node, claim } into the dispatch it triggers; the request is an explicit parameter down the spawn chain to attempt-state initialization, which no longer reads the issue's current claim. The binding is written with Filesystem.WriteCreateNew: identical is idempotent, different refuses. 2. A request-bound launch whose claim cannot be established refuses the launch. The unobserved binding state is gone. A bound claim the log no longer carries at result time is a failed outcome. 3. Exact (node, attempt, claim). The generic append refuses every ResultReturned; roadmap_bound_result_append builds the event from the binding inside one snapshot and refuses a result elsewhere, a second result, a foreign claim, or a forked history. Anti-entropy treats an attempt as answered only by a result on its issue naming its bound claim. The reader takes the issue and the key and reads the binding. Continuations: a dispatch no claim caused that continues an attempt is LaunchContinuing and copies the predecessor's recorded binding; a predecessor without a readable binding refuses the launch. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Reworked to the second NO-LAND ruling (on d74ed55) in bca612b; the PR description is rewritten for this head.
One point for the side chat to rule on, set out in the PR description under "continuations": a dispatch no claim caused that continues an attempt is CI: stacked PRs get no PR-triggered run; dispatch 37160413666 is running on this head. Not done: the srv2 deployment receipt. — sent from tidy-pike-588 |
RulingNO-LAND #13075 at The exact stacked head is mergeable against The continuation design is correct. One binding-authority blocker remains. Continuation ruling: approve
|
…t's own record Side-chat NO-LAND ruling on bca612b: roadmap_bound_result_append still accepted a caller-authored binding, so a result for attempt K naming a later valid claim C2 could be written and would permanently occupy K's result slot. roadmap_bound_result_append(instance, node, attempt, outcome, author, recorded_at) takes no claim, binding or event. Inside its snapshot it reads the attempt's create-only request record and derives the claim (roadmap_result_authority_of_record); an absent, autonomous or unreadable record refuses. No effectful carrier function accepts a claim. The record's type, codec, path, read and create-only write move to gunbc.roadmap.roadmap_attempt_request_record, below the carrier, so the launch admission and the bound append both read it without a cycle. The new append closes its snapshot through a consumed match. LaunchContinuing is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Reworked to the third NO-LAND ruling (on bca612b) in 2e2eea8; the PR description is updated.
A dispatched CI run is in progress on this head. After #13077 lands: retarget to main and rerun all four jobs. — sent from tidy-pike-588 |
Review 75190: the launch admission (and the result reader and admission) asked whether a history can be ordered by comparing roadmap_node_standing_key to two strings. roadmap_history_unordered_reason matches RoadmapNodeStanding exhaustively, and all three callers use it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 75190: fixed in 98c39ff. Verified the finding: Not changed: the same string comparison in code this PR does not touch ( |
#13077 was squash-merged, so the two files both sides carried conflicted textually. ROADMAP.md is generated and untouched by this PR: main's copy. roadmap_belt_tick_cli.dag on main is identical to the old base branch's, so this branch's copy (base plus the result-return tail) stands unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
What this does
Dogfood vertical, stage G4 (result returned). The requester who assigned an issue to
principal:gunbc/workflows/fabriconly learned the outcome by reading the dashboard. The belt now appends ONE durable roadmap event per request-bound attempt when the attempt reaches a final outcome, so the issue's event history carries the answer and the issue page renders it.This head answers the third side-chat NO-LAND ruling (on
bca612b6), which approvedLaunchContinuingas implemented and left one blocker: the result writer must derive the claim from the attempt's own durable binding. It builds on the second ruling's rework (three request/result-binding blockers and the stack ordering), described below. What both rulings said to keep is kept:ResultReturned { attempt, claim, outcome }with the recipient derived from the claim, the strict outcome decoder, anti-entropy over attempt history, pending classification for unreadable evidence / blocked integration or publication / yielded turns, one result per attempt at the append, causal ordering on the existingroadmap-eventscarrier, and combined reporting of result-return and later tail failures.gunbc.roadmap.roadmap_event_log):ResultReturned { attempt, claim, outcome },AttemptResultOutcome = ResultPublished { pr, head } | ResultVerificationFailed { head, cause } | ResultHandedBack { reason }. It replaces the writer-lessPublicationObserved.gunbc.roadmap.roadmap_attempt_request_record):request-binding.jsonin the attempt state directory, written create-only; its type, codec, path, read and create. Launch binding (gunbc.roadmap.roadmap_attempt_request_binding): the launch classes and the admission that decides what is committed.gunbc.roadmap.roadmap_result_returnedresult_return_attempts_for_instance, called fromgunbc.roadmap_belt_tick_clibelt_run_once_cli_in), throughgunbc.roadmap.roadmap_event_carrierroadmap_bound_result_append.result_returned_observe_for_attempt(instance: HostDashboardInstance, node_id: String, attempt_key: String) -> ResultReturnedObservationwith armsResultReturnedObserved { node, event, claim, return_to, outcome, recorded_at } | ResultNotReturned | ResultNotOwed | ResultReturnedUnobserved. Pure coreresult_returned_observation_of(read, binding, node_id, attempt_key).events/<node>/<event id>.jsonon theroadmap-eventsbranch. No second result store.Third ruling: the result writer derives the claim itself
roadmap_bound_result_append(instance, node, attempt, outcome, author, recorded_at)takes no claim, no binding and no event. Inside its private snapshot it reads the attempt's create-only request record, requiresRequestClaimBound { claim }, and builds theRoadmapResultBindingitself (roadmap_result_authority_of_record). An absent, autonomous or unreadable record refuses (result-binding), as does a keyless attempt.roadmap_attempt_request_record(type, codec, path, read, create-only write; no event-carrier dependency) sits below the carrier;roadmap_attempt_request_binding(launch admission) androadmap_event_carrier(bound append) both import it.the_result_writer_derives_the_claim_from_the_attempts_record_so_a_later_claim_cannot_poison_it: K is bound to C1 and C2 is a later valid claim on the same issue. The authority established for K is C1; a raw K/C2 result offered to the generic append is refused and the log is unchanged; K/C1 is then admitted on the head.letpattern in the carrier's older appends and reads is unchanged here; that carrier-wide cleanup is a follow-up, as the ruling says.LaunchContinuingis unchanged from the ruled head.Second ruling: the three blockers
1. The attempt carries the claim from the dispatch decision that admitted it
Claimedevent id the moment it appends the claim. Its follow-through now passesLaunchForClaim { node, claim }intobelt_dispatch_node_for_instance_over, and that request is an explicit parameter down the spawn chain tobelt_attempt_state_initialize_for_instance. Initialization no longer reads "the current claim".Claimedon that issue's history), never to choose one. A later claim C2 on the log changes nothing.Filesystem.WriteCreateNew: absent commits; present and identical is an idempotent success; present and different, or unreadable, refuses.a_launch_binds_the_claim_its_dispatch_decision_carried,a_committed_binding_is_created_once_and_cannot_be_replaced.2. A request-bound launch whose claim cannot be read refuses the launch
RequestBindingNotAdmitted, which fails attempt-state initialization and so the spawn./dispatch) that starts a lineage is its own class,LaunchAutonomous, recorded asRequestAutonomous.a_request_bound_launch_refuses_when_its_claim_cannot_be_read.3. Exact
(node, attempt, claim)at append, anti-entropy and readroadmap_event_appendrefuses everyResultReturned(stepresult-requires-binding). The only writer isroadmap_bound_result_append(see the third ruling above): it derives the identity from the attempt's record inside one private snapshot and decides withroadmap_bound_result_admissionover every issue's events in that snapshot. It refuses a result for the attempt on another issue (result-elsewhere), a different result on this issue (result-duplicate), a claim that is not aClaimedon this issue (result-claim), and a history with no single head (result-history).result_attempt_answer); a result under its key on another issue, or naming another claim, does not take it out of the population.a_superseded_attempt_stays_owed_and_a_misaddressed_result_does_not_answer_it,a_misaddressed_unreadable_forked_or_duplicated_result_is_not_the_attempts_answer); a second result on a different issue is refused at the append (a_bound_result_is_refused_for_a_second_answer_a_foreign_claim_or_another_issue).Stack ordering
The tick tail is result return, then served observation, then dogfood start record, as dependencies: the observation is taken inside a match on the result-return pass (every arm proceeds, so an undelivered result cannot freeze the page), and the start record runs only after a persisted observation.
belt_tick_result_tail_exitis the one pure join and names both causes.Continuations (ruled: approved as implemented)
LaunchContinuing { predecessor_attempt_key }, chosen byattempt_launch_request_for_originwhen a dispatch nobody's claim caused turns out to continue an attempt. A dispatch FOR a claim that continues a lineage stays for that claim.Control:
a_continuation_copies_its_predecessors_recorded_binding_or_refuses.Things a reviewer should know
ResultNotOwed.request: AttemptLaunchRequestis an explicit parameter onbelt_dispatch_node_for_instance_over,belt_dispatch_node_staged_over,belt_actuate_spawn_for_instance,belt_actuate_spawn_exec_for_instance,belt_actuate_spawn_exec_modeled,belt_actuate_spawn_with_origin,belt_spawn_admittedandbelt_attempt_state_initialize_for_instance.2dcaefadand the PR targets main, so its checks are PR-triggered. Earlier heads were stacked onroadmap/dogfood-routeand were verified by manual dispatches of the workflow on the branch. The side chat ruled LAND at2e2eea84; the one commit since that is not a merge is98c39ff9(review 75190: history ordering decided by an exhaustive match on the standing instead of its key string).Not verified
ResultReturned, same claim/requester/outcome through the production reader.roadmap-eventson srv2 is inferred from the belt and serve units sharing a service user.Filesystem.WriteCreateNewat launch, and the serve route's hand-off of the claim id are not reachable from the hermetic floor. The claims cover the pure admission, commit, join, decision and read functions, both codecs, the carrier's decode, and the pass's observe-only gate.Evidence (local
claim_batch)roadmap_result_returned_witness_test: 21/21.roadmap_event_log_witness_test: 24/24.roadmap_page_witness_test: 93/93.roadmap_event_carrier_witness_test: 3/3.roadmap_dogfood_route_witness_test: 21/21.🤖 Generated with Claude Code