From 3ecbf8e85f193ec03cc8a9c017679759399fc8fb Mon Sep 17 00:00:00 2001 From: gunbc-ci-auto-heal Date: Sat, 3 Oct 2026 09:51:07 +0000 Subject: [PATCH 1/7] read-outcome adoption, gunbc/auth batch: a refused read is a typed outcome, never a defaulted none filesystem sibling of DP-M5; converts all 8 unconverted Filesystem.Read consumption sites in dag/gunbc/auth to the modeled fold filesystem_read_outcome (extdeps.filesystem.filesystem_io), per the row filesystem_read_outcome_adoption_standing: - ci_app_key_rotation: THE RED -- an unreadable observation record collapsed into the absent arm (silent none, same as env-unset). Now observe_app_key_mint_record returns AppKeyMintRecordRead? via app_key_mint_record_from_read; a refused read is a new typed refusal AppKeyMintObservationUnreadable, distinct from Absent (which now means only 'env unset'). Red witness + positive controls appended to dag/test/claim/ci_app_key_rotation_witness_test.dag. - credentials, approval_gate, approval_keyring_converge, access_token_source, profile_projection (new on main): manual if/else and match-on-success routed through the fold; refusal texts preserved verbatim; classify_supplied_token now takes FilesystemReadOutcome. Instrument (named re-runnable, per the row's RE-DERIVATION): tools/read_outcome_recount.sh, identity grain; calibrated -- at b21b710d5378387ae0c841f07323292c5d72faba it reproduces the row's recorded baseline exactly (92 sites / 48 files, 0 converted), and at DP-M5's head 6471587dbaa it agrees with the final-semantics recount (207 raw unconverted / 43 dag/test/claim fixtures / 98 files). Sites whose projections all feed filesystem_exact_read are reported as their own class (exact_read_typed): already typed outcomes, not this debt. After this batch: 219 unconverted (44 dag/test/claim fixtures, 175 non-fixture) across 100 files; was 227/183/106 at fresh main 0456f1cfb2b. --- dag/extdeps/filesystem/filesystem_io.dag | 2 +- dag/gunbc/auth/access_token_source.dag | 34 ++-- dag/gunbc/auth/approval_gate.dag | 19 +- dag/gunbc/auth/approval_keyring_converge.dag | 34 +++- dag/gunbc/auth/ci_app_key_rotation.dag | 42 ++++- dag/gunbc/auth/credentials.dag | 18 +- dag/gunbc/auth/profile_projection.dag | 26 +-- .../ci_app_key_rotation_witness_test.dag | 55 ++++++ tools/read_outcome_recount.sh | 178 ++++++++++++++++++ 9 files changed, 352 insertions(+), 56 deletions(-) create mode 100755 tools/read_outcome_recount.sh diff --git a/dag/extdeps/filesystem/filesystem_io.dag b/dag/extdeps/filesystem/filesystem_io.dag index eeee7e62d67..13e3ca113f6 100644 --- a/dag/extdeps/filesystem/filesystem_io.dag +++ b/dag/extdeps/filesystem/filesystem_io.dag @@ -157,7 +157,7 @@ fn filesystem_create_new( } } -data filesystem_read_outcome_adoption_standing: String ="RUNG: mitigatable. filesystem_read_outcome provides the single modeled fold from Filesystem.Read's scalar transport observation into FilesystemReadSucceeded | FilesystemReadRefused, but nothing forces callers through it. gunbc.ci_yaml_validate is the first converted consumer and preserves read refusal separately from YAML parse refusal. The raw operation remains directly consumed elsewhere, so content+success+error nonsense combinations remain writable at those sites. SUBJECT: an unconverted consumption site is a Filesystem Read call whose bound result has any success, error, or content projection outside the three arguments of filesystem_read_outcome. The call and those three projections remain after conversion because they supply the fold; adoption changes where they are consumed, not whether they exist. BASELINE measured on origin/main b21b710d5378387ae0c841f07323292c5d72faba: 92 unconverted consumption sites across 48 .dag files. REMAINDER after the first conversion: 91 unconverted consumption sites across 47 files. RE-DERIVATION: enumerate Filesystem Read assignment calls in tracked .dag source, excluding this adoption-standing data declaration so the instrument cannot count its own prose; for each bound result, classify it converted only when every success, error, and content projection is an argument of filesystem_read_outcome, otherwise classify it unconverted; count unconverted rows and distinct paths. NEXT-RUNG TRIGGER: the unconverted population reaches zero -- every Filesystem Read result projection occurs only as an argument to filesystem_read_outcome. The compiler-only filesystem_read intrinsic is a separate replacement migration and is not part of this population or this fold." +data filesystem_read_outcome_adoption_standing: String ="RUNG: mitigatable. filesystem_read_outcome provides the single modeled fold from Filesystem.Read's scalar transport observation into FilesystemReadSucceeded | FilesystemReadRefused, but nothing forces callers through it. gunbc.ci_yaml_validate is the first converted consumer and preserves read refusal separately from YAML parse refusal. The raw operation remains directly consumed elsewhere, so content+success+error nonsense combinations remain writable at those sites. SUBJECT: an unconverted consumption site is a Filesystem Read call whose bound result has any success, error, or content projection outside the three arguments of filesystem_read_outcome. The call and those three projections remain after conversion because they supply the fold; adoption changes where they are consumed, not whether they exist. BASELINE measured on origin/main b21b710d5378387ae0c841f07323292c5d72faba: 92 unconverted consumption sites across 48 .dag files. REMAINDER after the first conversion: 91 unconverted consumption sites across 47 files. RE-DERIVATION: enumerate Filesystem Read assignment calls in tracked .dag source, excluding this adoption-standing data declaration so the instrument cannot count its own prose; for each bound result, classify it converted only when every success, error, and content projection is an argument of filesystem_read_outcome, otherwise classify it unconverted; count unconverted rows and distinct paths. The named re-runnable instrument is tools/read_outcome_recount.sh (