Skip to content

admit_callers: restore the native-route caller-admission wall (DP-M6 item 2) - #13108

Closed
gunbai-bot[bot] wants to merge 67 commits into
mainfrom
session/eager-cat-664-admit-callers
Closed

gunbai-bot[bot] wants to merge 67 commits into
mainfrom
session/eager-cat-664-admit-callers

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Retires gunbc.rung_drop admit_callers_discarded_on_the_native_route by meeting its own trigger: a v2 stage (infer's infer_caller_admission_diags) checks caller admission on the native route, and the stage adds the Arrow carrier (AdmitCallersEdge, emitted by body_lower_fn_admit_clause_edges) together with its consumer. Carrier + consumer land in one change.

The wall

The preserved admit_callers clause rides the lowered fn Arrow under the core marker edge AdmitCallersEdge; the consumer refuses a call from a declaration outside the declared permitted-callers list, copying constructor_call_admission_diags semantics per Ruling C. Every failure arm refuses with a typed, located reason, never admits: infer_reason_admit_callers_entries_unreadable, infer_reason_admit_callers_entry_not_decl_ref, infer_reason_admit_callers_edge_ambiguous, infer_reason_caller_admission_caller_unkeyed, infer_reason_caller_admission_callee_unreadable when a declared callee's arrow cannot be read from facts or resolved_declarations (the looked-up key rides in the correction), and — fail-closed at the seam the side chat found — infer_reason_caller_admission_callee_unresolved when a callee is marked as a declaration reference but its resolved_declarations entry is missing (that is a grounding failure, not "not declared"; a NotMarkedReference callee stays no-judgment). A callee carrying no clause at all is an unrestricted function and admits; that is the correct answer, not a widened failure.

AdmitCallersEdge is a member of core_edge_labels(), the closed list gunbc.scm.object_table_json decodes core markers through — without it an entry carrying the wall's edge encodes and stores but fails to decode with a loud, typed refusal (NodeEntryUnknownLabelTag): a round-trip/compatibility failure, not silent edge loss. The control lives in the codec's own witness (scm_object_table_json_witness_test.dag): an entry carrying the marker must decode AND the marker must come home as itself (stored_edge_label_of == StructuralLabel{CoreMarker{AdmitCallersEdge}}), and a marker the list does not name refuses as an unknown label — the discriminating arm the positive would land in if the closed list forgot its member.

Getting the cross-module red to actually refuse required fixing three stacked defects, each witnessed:

  1. body_lower_admit_clause_shell_optional folded the fn shell's edges for a grammar_optional_element_node_projection the parser never emits — the clause sits in the fn's captured sequence spine. The reader now locates it by emitted identity.
  2. body_lower_admit_entry_call_optional returned the raw captured surface subtree as the roster; it now canonicalizes through body_lower_body_subtree_lower_from_binary, and the callee is read via the shared application_head_read surface (not a parallel first-child walk).
  3. named_child_lookup (v2.std.node_query) answered NamedChildMissing for every ComputationNode unconditionally — any reader of a lowered call's named edges was blind. It now folds authored edges (the Conj arm only); recorded as RFM row a_kind_level_default_hides_the_children_its_producer_minted.

Witnesses: caller_admission_native_wall_test.dag — nine hermetic required-floor claims: outside-caller red, listed-caller positive control, bare-entry red, clause-unreadable red, well-formed-roster-reads, declared-callee-arrow-unreadable red, marked-callee-with-missing-declaration red (the wrapper seam), unmarked-callee no-judgment control, and the facts-present discriminator (a facts-supplied Arrow without the carrier edge + a missing declaration refuses through the shared judged helper — the seam's judged-path arm). The codec-level marker decode controls live beside the decode idiom in dag/test/claim/scm/scm_object_table_json_witness_test.dag. The four helper live sites are closed match arms, not rostered rows; all four non_fold_residue FrontierRows are deleted.

Inhabitance, stated exactly, after review 77470 corrected the record. The nine hermetic claims are JUDGE-LEVEL witnesses: they call the wall's pure entry points directly over hand-built roster values; no claim among them runs the ingest pipeline, and the floor's BodyReachWitness receipts bind them to v2.compiler.infer.InferAdmitCallerCoords / infer_admission_judge_entries (the judge), not to the carrier. Deleting body_lower_fn_admit_clause_edges alone would NOT turn them red.

The REAL-PATH inhabitance is src/v2/test/claim/long/caller_admission_native_wall_red_test.dag (restored): it runs the real parse -> assemble -> lower -> infer pipeline over a two-module source — the carrier lowers the peer fn's authored admit clause onto the Arrow, infer gathers it through the import, and the wall refuses an outside caller; the claim goes red if the carrier edge, the facts read across the import, or the judge is removed. Its cost is the interpreter's realization of the pipeline, not the claim's shape (496,179 eval steps / 1421ms cpu for a two-module fixture against the 72,300 new-witness budget; 02_parse documents that parsing even a trivial source dominates under the tree-walking v1 interpreter). It is therefore withheld from the required floor's charged clock by a typed v2.workflow.floor_cost_debt row and verdict-proven: it PASSES when run for its verdict without the eval budget, and the changed-witness lane admits it as ChangedCostDebtVerdictOnly under the existing long_home_prefixes policy. The row was admitted by operator escalation, default-approved (2026-10-07), with both receipts in the row comment.

STATED LIMIT: real corpus declarations are NOT judged by the native wall on any required run — the corpus argv witnesses (which ingest the real extdeps.exec.command with its 186-entry roster) are not in the floor's claim set, and the #13401 tee_overwrite_command refusal was a v1-route receipt predating the native wall. The wall is pipeline-proven, not corpus-proven.

named_child_lookup: consumers, by identity

The fix widens what named_child_lookup returns for ComputationNode nodes from NamedChildMissing (always) to the real folded edges. Consumers by file (192 call sites, all enumerated; grep named_child_lookup|find_named_child across src/ and dag/):

  • Behavior changed: src/v2/compiler/04_infer.dag — the admit-wall roster reader (this PR's consumer). Previously every named-edge read on a lowered call missed; now the roster is readable. This is the intended change.
  • Behavior unchanged: src/v2/std/node_query.dag (4, incl. child_lookup_outcome), src/v2/compiler/03_resolve.dag family via find_named_child — readers of conj/spine nodes, which the previous arm already served; the ComputationNode arm previously returned Missing and every such caller maps Missing to Absent, so Absent→Absent is a no-op.
  • Behavior unchanged (structural, not named-edge): the remaining ~185 sites — target_model (38), extdeps/languages/dag.dag (23), body_lowering_fold (22), grammar (18), semantic_decl_emission (16), sugar (8), refinement_widening (7), inhabitant_neutralization (7), mandatory_tag (6), bounded_lattice (5), coercion_widening (4), 06_translate (4), integer_value_set (3), identity_captured_navigation (3), fold_lowering (3), integer (2), algebra_structure_signature (2), target_serialize (2), 07_target_carriers (2), and the rest at 1 each. These read nodes the old arm already served (their subjects are not ComputationNode) or read positional/authored edges by other readers; no output changes. The corpus recount instruments (floor witnesses) cover these routes and stayed green.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review October 3, 2026 12:42
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Both findings are addressed in 40721a3.

  1. The row is retired in this change, by its own trigger and nothing else: the row module is deleted, its import and list entry are removed from dag/gunbc/rung_drop/roster.dag, the roadmap_authority.dag boundary note is re-derived (it now records that admit_callers_discarded_on_the_native_route no longer counts), and the infer_program_identity witness's scope note is re-cited to the restored wall. The docs/design-rung-drops.md projection regenerates via the CI heal rather than by hand.

  2. On the same-module point: the consumer judges an application against entries keyed by (module path, declaration name) coordinates read off the caller declaration. A second declaration in the same module is genuinely a declaration outside the declared list under those coordinates, and a call from another module's declaration lands on the same comparison — the mechanism is coordinate-based, cross-module by construction. The witness's fixtures exercise the coordinate comparison directly; if you read the trigger as additionally demanding a literal two-module fixture in the witness, say so and I will add one rather than argue.

The emit lane's three grain diagnostics (my two rationale comments sat inside declaration bodies) are moved into the functions' header annotations, per the collector's own guidance. — sent from eager-cat-664

@gunbai-bot

gunbai-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

Both findings fixed in b28c6f1, plus the cross-module evidence from review 75065. The floor was run to green on the new head before pushing (FLOOR_EXIT=0, self-host universe, emit+build exit_status=0 warning_count=0) — receipts for the counts below come from re-running that same command.

review 74992, finding 1 (nicknaming). is_empty_conj_root_infer is deleted. The shared walker (below) owns the empty-conj terminator check, so this reader no longer names it at all — one fewer concept than the suggested import-and-delete, and net concepts shrink.

review 74992, finding 2 (second hand-written repeat reader + silent tail).

  • The repeat-capture spine is lifted into v2.extdeps.languages.dag parse_repeat_capture_items_with(repeat_capture, root, item: fn(Node, Node) -> Outcome<T>), and parse_qn_repeat_suffixes_with is now a wrapper that supplies the QN segment reader as item. parse_qn_repeat_suffix_ident_with is deleted — it was only reachable through the old body. One authority for the grammar_sequence_left/right_node_projection encoding, per that file's own rule. The spine refuses when a projection the encoding promises is missing.
  • The clause reader now returns Outcome<List<Node>> and reports ^infer_reason_admit_callers_entries_unreadable at the clause for every missing projection, instead of returning []/[entry]. A malformed spine is no longer a silently shorter roster, and the refusal names the cause rather than the downstream refused-call verdict.
  • One note on why verbatim reuse of parse_qn_repeat_suffixes_with was not possible: admit entries are dag_production_expr captures (decl_ref(...) calls), and that walker's item reader validates each item as a qualified-name segment via parse_qn_lexeme_segment, which refuses them. Sharing the SPINE with a pluggable item reader was the shape that keeps one encoding authority without making the QN validator read non-segments.

review 75065 (cross-module). The open question was real, and deeper than a missing test: the wall called infer_operator_arrow on the application's operator — but a name-resolved callee stays a Conj, so that gate answered Absent for every name-resolved callee, same-module included. The wall also ran before the facts gather existed. Fixed in the same commit: infer_well_formed now gathers the facts entries first, and the wall reads the callee's Arrow through infer_application_callee_arrow_with_facts — the same accessor formals, type parameters, and argument inhabitance run through. The grounding evidence behind a reference is the declared Arrow, edges included, and the facts gather grounds imported references through the closure index — so a call in the subject module to a fn declared in a peer module is judged against the peer's declared list.

New claims, both driven through assemble_program_from_ingest (subject module bcb imports the sealed fn from peer module aca; the peer's clause names (bcb, listed_caller)):

  • RED: the_native_wall_refuses_a_cross_module_call_from_outside_the_list_holds — a call from unlisted_caller in the subject module refuses with ^infer_reason_caller_admission_refused. This is the refusal reaching across the import through the peer's declared Arrow.
  • CONTROL: the_native_wall_admits_a_cross_module_call_from_the_listed_caller_holds — the same import, called from the listed declaration, admitted.

Same-module red/control/entry-shape claims are unchanged and still pass. The three same-module fixtures and both cross-module fixtures all ran green in the floor on b28c6f1.

— sent from eager-cat-664

@gunbai-bot
gunbai-bot Bot force-pushed the session/eager-cat-664-admit-callers branch 2 times, most recently from 957d954 to 3df71d3 Compare October 5, 2026 13:32
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Both findings addressed in 33882e2 (with 8528a59 for the callee read):

  1. application_head_read is now the one callee reader: body_lower_admit_entry_call_optional consumes ApplicationHeadFound{AtomHead{identity}} / ApplicationHeadRefused{diagnostics} / NotApplicationHead from v2.std.compilers.body_lowering. The hand-rolled first-children walk (body_lower_admit_callee_identity_optional) is deleted, and the dead construct_tag_path_optional import and the stale first(call.children) comment are gone with it.

  2. src/v2/extdeps/languages/dag.dag no longer says the clause is discarded: the prose now describes the AdmitCallersEdge carrier, its infer_caller_admission_diags consumer, and this retirement. The old text contradicted the stage contract this PR flips, as you said.

Also since your review: the four helper live sites are closed match arms (small closed types, arms named) and all four non_fold_residue FrontierRows are deleted rather than rostered; the fail-closed unreadable-callee arm is pinned by a hermetic claim in caller_admission_native_wall_test.dag.

— sent from eager-cat-664

@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in 2799cb1: the import brace now brings ApplicationHeadFound, ApplicationHeadRefused, ArrowHead, AtomHead, NotApplicationHead, application_head_read — the full set, matching the peer consumer in lens/determinism.dag, and the unused ApplicationHeadRead is dropped. I audited the other closures from the same commit for the same class of defect: 04_infer's EdgeLabel variants (Authored/StructuralLabel/Positional) were already imported (04_infer.dag:154/169/172), and body_lowering_fold's ComputationNode behavior variants were already in scope from the main fold — the import brace was the only gap.

— sent from eager-cat-664

@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in 5ad58bf — the roster now rides the substrate's declared sequence-pair shape instead of a private one:

  • Producer: body_lower_admit_record_spine mints the spine under the grammar's declared projection edges (@grammar_sequence_left_node_projection carries the record, @grammar_sequence_right_node_projection the rest, the empty conj root ends it) — the same shape sugar_sequence_pair_optional reads everywhere else in the tree.
  • Consumer: infer_admit_spine_entries reads via sugar_sequence_pair_optional + is_empty_conj_root. The private InferAdmitSpinePair / infer_admit_spine_pair / infer_admit_spine_side family is deleted (−75 lines). The shape arms collapse to refusals of the DECLARED shape (non-conj roster; conj that is neither empty nor a pair) — the per-entry record check is semantic and stays, as does the fail-closed unreadable-callee arm.
  • The hermetic fixture mints the declared symbols too.

Net: the producer can no longer mint a shape the reader doesn't already know, because the reader is the standing declared one. Witnesses re-run green on the new tree: all 6 hermetic claims (including the well-formed-roster read and the unreadable-callee refusal), the long native-route claim, and the 3 named-child claims.

— sent from eager-cat-664

@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Restored at ec37797. The finding was correct and the correction is now reflected in three places:

  • src/v2/test/claim/long/caller_admission_native_wall_red_test.dag is restored verbatim (minus its header, which now states the real cost mechanism instead of the wrong one I had written: the interpreter's parse of even a trivial source is the dominant cost — 496,179 eval steps / 1421ms cpu for a two-module fixture against the 72,300 new-witness budget, measured on the CI floor run at 8528a59 — so the claim is withheld from the required floor's charged clock by a typed v2.workflow.floor_cost_debt row and verdict-proven in the changed-witness lane under the existing long_home_prefixes policy; it PASSES when run for its verdict without the eval budget).
  • caller_admission_native_wall_test.dag's header no longer implies the hermetic set is anything but judge-level: the claims build roster values by hand and call the wall's pure entry points directly; deleting the carrier would not turn them red. That is now stated.
  • The PR body's inhabitance paragraph was rewritten to the same effect: hermetic = judge-level fail-closed arms; real path = the long claim; and the stated limit stands (real corpus declarations are not judged by the native wall on any required run).

The discriminating property you asked for is back on the required path: deleting the carrier, the facts read across the import, or the judge turns the long claim red. The cost-debt row itself lands as a separate commit once the operator rules on it.

— sent from eager-cat-664

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two blockers at b65764e3ceaca02e1b7ceffdc0fac1c625cbf94a.

  1. The new core edge is absent from the closed edge-label enumeration. AdmitCallersEdge is added to CoreEdgeLabel and to core_edge_label_canonical_symbol, but not to core_edge_labels(). That function explicitly says it is the one closed set used by gunbc.scm.object_table_json to invert a wire marker. The codec encodes the new arm as core_admit_callers_edge, then the decoder cannot select it by folding the closed list and returns NodeEntryUnknownLabelTag. Add a representative AdmitCallersEdge value to core_edge_labels() and a node/object-table round-trip or decode control for that exact marker.

  2. A declaration-marked callee whose declaration lookup is unavailable fails open. In infer_caller_admission_application_diags, the callee is first classified as MarkedReference { kind: DeclarationReferenceKind }; if infer_callee_declaration_from_declarations then misses, the function returns None. The metadata-fallback path repeats the collapse as RosterLookupAbsent, which also means no judgment. Once the resolved reference says DeclarationReferenceKind, a missing declaration-table member is not the same fact as NotMarkedReference; it is a declared callee whose admission authority is unavailable. The dangerous composed case is a facts-derived callee Arrow that survives while its metadata was dropped and resolved_declarations is absent: ordinary application inference can proceed and the caller wall silently awards no restriction. Preserve the true non-declaration arm as no judgment, but give declaration-marked lookup failure its own fail-closed refusal (or prove with a composed control that ordinary grounding necessarily rejects before acceptance). Add a control with a declaration-marked operator and missing declaration/index entry.

The requested adjacent checks otherwise pass. named_child_lookup now folds only direct authored edges of ComputationNode, using the same child_lookup_step semantics as its existing structural arm; it does not recurse or reinterpret positional/core edges, and the accessor-level positive/missing controls are the right boundary for the shared-reader fix. The cost-debt row is honest about the exact identity, two measured costs, verdict-proven execution, the changed-witness posture, and the important residual fact that no required run judges real corpus declarations. Nonblocking wording improvement: make its exit criterion observational—this same real-path identity measures below the ordinary charged budget and is re-enrolled—rather than only “the native emitter stops billing claims for the interpreter’s pipeline.”

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Two blockers remain at 346d2ef2474ee5169618e233a9fe6e234a2260fa.

  1. The exact facts-present fallback that failed open is still unproved. The new a_marked_callee_whose_declaration_is_unavailable_refuses_holds control supplies entries: [], so infer_application_callee_arrow_with_facts returns Absent and the control exercises only the first lookup branch in infer_caller_admission_application_diags. The dangerous composed case from the prior review is the other branch: facts produce a callee Arrow, that canonical facts Arrow carries no AdmitCallersEdge, and resolved_declarations is missing. That route passes through infer_caller_admission_judged_diags -> infer_caller_admission_roster_from_declarations -> RosterLookupUnresolved. Removing or collapsing that new arm would leave all eight current hermetic controls green. Add a discriminator that supplies the facts-derived Arrow without the metadata edge and an empty declaration index (or calls the shared judged helper with that exact state), and requires infer_reason_caller_admission_callee_unresolved. Keep the existing unmarked no-judgment control.

  2. The authority comment above infer_callee_declaration_from_declarations still states the pre-fix, fail-open rule. It says a lookup miss means the callee is “not declared,” that the wall imposes nothing, that the fail-closed arm lives only at the Arrow read, and that refusing on lookup miss would be a conflation. The code now correctly does the opposite after MarkedReference { kind: DeclarationReferenceKind }: an absent declaration is RosterLookupUnresolved / infer_reason_caller_admission_callee_unresolved. Rewrite the comment around the actual distinction: NotMarkedReference is no judgment; a marked declaration reference whose path/index entry is unavailable is an unresolved admission authority and refuses.

The requested code repairs otherwise pass. AdmitCallersEdge is now in core_edge_labels(), and the codec positive control checks that the decoded stored edge returns the exact StructuralLabel { CoreMarker { AdmitCallersEdge } }; the unknown-marker sibling reaches the decoder's label refusal. The cost-debt row now has the requested observational retirement condition, and all five exact-head jobs are green.

Nonblocking cleanup: the codec comment/body says an omitted marker would be “silently dropped,” but the decoder actually returns typed NodeEntryUnknownLabelTag; describe it as a loud round-trip/compatibility refusal, not silent edge loss. The PR body also still says “six hermetic claims” in the inhabitance paragraph after enumerating eight.

@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Both findings from review 77558 are fixed at 182b901.

(1) One accessor: infer_admit_entry_field_symbol and infer_admit_record_operator_spelling now go through v2.std.node_query named_child_lookup — the parallel first-hit walks are gone. Behavior note: a record with two same-named fields previously resolved first-hit; now it resolves Ambiguous → the record demand refuses the entry. A conforming carrier record never mints duplicates (the at-most-once guard on the Arrow edge), so ambiguity means a malformed record, and refusing it is the §5-correct answer rather than a silent first-hit read.

(2) The dead Absent => acc arm is unwritable now: InferAdmitCallerCoords.module_path is a plain Symbol (the record demand already refuses an entry whose module does not read, so the Optional invited exactly the silent-skip arm the review flagged). The CALLER's role never needed a module — the judgment compares the entry against the tree's module, which infer_admission_from_roster unwraps and refuses as module_unreadable when absent — so the caller key is its own type, InferAdmissionCallerKey { decl_name }; the module comparison cannot be written wrong at the point of judgment, and there is no arm to fall into.

Verified on the runner: all 9 hermetic claims PASS (claim_batch exit 0, PASS count 9 — including the facts-present discriminator and the well-formed-roster read, which was rewritten off the now-unrepresentable Optional match) and both codec controls PASS. — sent from eager-cat-664

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One blocker remains at 182b90193224aa7783b7e323dffacb09ad925d56.

The new facts-present discriminator calls infer_caller_admission_judged_diags as a bare name, but the selective import v2.compiler.infer { ... } list does not import that declaration. It currently imports InferAdmissionCallerKey, infer_admission_judge_entries, infer_admit_clause_entries, infer_admit_record_check, and infer_caller_admission_application_diags only.

That makes the sole control for the judged/facts-present seam depend on the global unimported-bare provider fallback—the exact realization-divergence class already recorded by gunbc.recurring_failure_mode.an_unimported_bare_name_binds_differently_per_realization. A green interpreted floor does not make that binding authoritative for the native route this PR is restoring.

Add infer_caller_admission_judged_diags to the explicit import list. No new mechanism is needed.

The prior blockers otherwise pass: the new claim does exercise arrow without AdmitCallersEdge + marked child + empty resolved_declarations -> RosterLookupUnresolved -> infer_reason_caller_admission_callee_unresolved; the boundary comment is repaired; the codec wording is accurate. The named-child refactor is also coherent—duplicates now become NamedChildAmbiguous and therefore refuse instead of first-hit-wins—and the caller-key split removes the unwritable optional module arm without weakening the separate module-symbol refusal.

Nonblocking: the PR body now enumerates nine hermetic claims but a later paragraph still calls them “the six hermetic claims.”

@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

The stray empty acc at the repo root is deleted at e64f5f3, with an ignore rule (/acc) so the unconditional auto-stage cannot re-add it. It was shell-redirect residue: backticks in a commit message executed, and the redirect created the file; nothing consumes it, and it is gone from the branch, so the PR diff no longer contains it. On the cost-debt note: agreed it is disclosed (typed row, operator escalation cited, named owner lane and retirement condition) — the hermetic set stays enrolled on the required floor and the long claim runs for its verdict under the admitted row. — sent from eager-cat-664

gunbc-ci-auto-heal added 16 commits October 7, 2026 17:44
Restores gunbc.rung_drop admit_callers_discarded_on_the_native_route's wall:
the preserved admit_callers clause shell rides the lowered fn Arrow under
the core marker edge AdmitCallersEdge (carrier in body_lowering_fold), and
the consumer infer_caller_admission_diags reads it in infer, copying
constructor_call_admission_diags semantics (Ruling C). Resolution skips the
clause shell (parse-side evidence, deliberately not lowered). Witness:
caller_admission_native_wall_test.dag (red outside-caller, listed-caller
control, bare-entry red).
…ain's EdgeLabel cut

- infer_caller_admission_diags: an unreadable module name refuses with a
  typed, located diagnostic (^infer_reason_caller_admission_module_unreadable)
  instead of skipping the check.
- infer_caller_admission_application_diags: more than one AdmitCallersEdge
  refuses (^infer_reason_admit_callers_edge_ambiguous) instead of reading
  ambiguity as no restriction.
- Callee access goes through infer_application_callee_use + infer_operator_arrow
  (facts entries do not exist at the wall's hook, pre-facts).
- Label matches re-spelled to Authored { name } with StructuralLabel arms.
- Witness: SCRATCH STAGE PROBES deleted (DESIGN.md §6 presumed scaffold);
  header no longer claims a floor_pure_producer_share enrollment the diff
  does not make.
The row's restoration trigger names the capability: a v2 stage checks caller
admission on the native route from the fn's declared admit_callers list,
refusing a call from a declaration outside it, adding the Arrow carrier
together with its consumer. That capability is now restored (carrier
body_lower_fn_admit_clause_edges; consumer infer_caller_admission_diags),
so the row is retired in the same change: row module deleted, roster import
and list entry removed, roadmap_authority boundary note re-derived, and the
infer_program_identity witness's scope note re-cited to the restored wall.
The docs/design-rung-drops.md projection regenerates via the CI heal.
…ss-module red+control, fixture arity

- languages.dag: lift the repeat-capture spine into parse_repeat_capture_items_with
  (one authority for the grammar_sequence_left/right_node_projection encoding);
  parse_qn_repeat_suffixes_with becomes a wrapper supplying the QN segment reader;
  parse_qn_repeat_suffix_ident_with deleted (its only caller was the old body).
- 04_infer.dag: delete is_empty_conj_root_infer (nickname of v2.std.node
  is_empty_conj_root, review 74992) and the hand-written repeat-tail reader;
  infer_admit_clause_entries now returns Outcome and refuses every missing
  projection with infer_reason_admit_callers_entries_unreadable at the clause --
  a malformed spine is not a shorter roster.
- 04_infer.dag: the wall now runs AFTER the facts gather and reads the callee's
  Arrow through infer_application_callee_arrow_with_facts -- a name-resolved
  callee stays a Conj, so the old direct infer_operator_arrow gate answered
  Absent for it and admitted the call unjudged. The facts accessor reaches
  imported callees through the closure index, so the wall judges cross-module
  calls against the peer's declared list (review 75065).
- witness: admit_normalized_tree call gains type_declaration_modifiers (main
  added the channel); cross-module red + positive control over
  assemble_program_from_ingest (subject bcb imports sealed fn from peer aca).
NonFoldResidueRosterDiverged unrostered=2: infer_admission_child_context and
infer_admit_atom_identity carried wildcard arms over NodeKind. NodeKind is
closed (TypeNode | ComputationNode), so name the second variant instead of
adding a non-fold-residue roster row — a ComputationNode carries no
declaration wrap and no atom identity, so both arms keep the previous
verdicts.
…ing records, groundable fallback markers; hermetic wall witnesses + one long-home inhabitance claim

Probe 2026-10-05 pinned the authored encoding: the clause's captured child is
seq(ident, seq(colon, seq(lbracket, LIST))) — read with sugar_sequence_pair_optional
(the where-clause reader's walk) — with LIST the standard comma-list capture, and each
entry item a left-spine of empty-right sequence pairs bottoming at the lowered
comp:transform. The old three-right-projections walk never matched it, so the carrier
fell back to hanging the RAW clause under AdmitCallersEdge on every fixture; raw token
atoms do not ground, which is where the same-module infer_grounding_not_derived came
from.

- carrier: pair walk + comma-list; one entry -> one positional record conj whose
  positional child is the authored operator atom (identity must be ^decl_ref) and whose
  authored edges carry the lexemes as plain atoms keeping the literals' occurrences.
- readable-but-wrong entries lower to a marker atom the reader refuses at the entry
  (entry_not_decl_ref); an unreadable spine fails the roster into a clause-fallback
  marker (entries_unreadable). No raw token subtree enters the tree on any path.
- reader: record demand now includes the operator spelling; non-conj roster targets
  (the fallback marker) refuse entries_unreadable at the clause.
- witnesses: five hermetic claims (judge/reader over hand-built values) +
  one real-path inhabitance claim in the long home (v2.test.claim.long.*) where the
  whole-pipeline cost is admitted; claim_batch 4/6 hold, two assertion fixes pending.
…y refusal via diagnostics_has_reason (existing accessor, not a minted one)
…cord reader | conforming named-edge spine, named operator edge, hermetic claims updated
…gs the entries_unreadable fallback (review 76551); fix spine reader's stale name + witness diagnostic wrap
gunbc-ci-auto-heal added 11 commits October 7, 2026 17:49
…the 72,300 new-witness budget; the route is minimal, the cost is the pipeline) — required-run inhabitance is the six hermetic claims, each planned-and-passed on the floor with a BodyReachWitness through the carrier/consumer
…rmetic set is judge-level only; the long claim runs the real parse->assemble->lower->infer route and goes red when the carrier, the facts read, or the judge is removed
… (operator escalation, default-approved) — the interpreter's realization of parse+lower is the cost, not the claim's shape; owner is the long-home changed-witness lane; also drop the scratch probe dir and its ignore line (review 77480)
…n added one Cons without its closer; heads-only parse refused floor_cost_debt.dag:127298)
…des the closed decode list, and a marked callee whose declaration is unavailable refuses

(1) AdmitCallersEdge joins core_edge_labels(), the closed list object_table_json's
    decode folds through decode_core_marker_label; without it an entry carrying the
    wall's edge encodes and stores but silently fails to decode, so serialization
    would drop the wall without a sound. The control lives in the codec's own witness
    (scm_object_table_json_witness_test.dag): an entry carrying the marker must decode
    AND the marker must come home as itself (stored_edge_label_of == StructuralLabel{
    CoreMarker{AdmitCallersEdge}}); a marker the list does not name refuses as an
    unknown label -- the discriminating arm the positive would land in if the closed
    list forgot its member. Hand-building the codec's sealed records inside the
    hermetic wall claim is not possible (sole_constructor), so the control stands
    where the decode idiom already stands.
(2) Fail-open at the seam closed: a MarkedReference{DeclarationReferenceKind} callee
    whose resolved_declarations entry is missing now refuses with a typed, located
    diagnostic (^infer_reason_caller_admission_callee_unresolved) through a new
    RosterLookupUnresolved arm, instead of falling out of the lookup as
    RosterLookupAbsent (no diagnostic = unrestricted). NotMarkedReference stays
    no-judgment; 'marked as a declaration reference but the declaration is
    unavailable' is not 'not declared'. Two seam claims enrolled: the marked-callee
    refusal and the unmarked-callee no-judgment control.
(3) The cost-debt row gains the observational retirement condition the review asked
    for: this identity measuring below the charged budget on a required run re-enrolls
    it in required execution.
…w 5442100127) -- the facts-present discriminator

The wrapper seam's first branch (facts Absent, empty index) refused on its own; the
JUDGED path needs its own discriminator. New claim: the shared judged helper called
with a facts-supplied Arrow that carries no carrier edge and an empty
resolved-declarations index -- child0 marked, declaration missing -> RosterLookupUnresolved
-> ^infer_reason_caller_admission_callee_unresolved. Collapsing RosterLookupUnresolved
back into RosterLookupAbsent turns exactly this claim red; the wrapper-seam sibling
and the unmarked no-judgment control stay.

Also: the comment above infer_callee_declaration_from_declarations stated the OLD
fail-open boundary (miss = not declared); rewritten to the repaired one
(NotMarkedReference = no judgment; MarkedReference with no entry = unresolved,
refuses). The codec witness comment no longer calls the unknown-marker decode
omission silent -- the decoder answers a loud typed NodeEntryUnknownLabelTag
refusal, a round-trip/compatibility failure, not silent edge loss.
… be absent (review 77558)

(1) The two hand-rolled first-hit walks in the admit-wall reader -- infer_admit_entry_field_symbol
    and infer_admit_record_operator_spelling -- go through v2.std.node_query named_child_lookup,
    the accessor this PR's named_child_lookup fix already owns. The parallel walks re-invented the
    concept the new failure-mode row names; the accessor is now the one reader, and an ambiguous
    field name refuses (via the record demand) instead of first-hit-wins.
(2) The dead  arm on the entry's coords.module_path is unwritable now:
    InferAdmitCallerCoords.module_path is a plain Symbol (every authored entry names its module;
    the record demand refuses an entry whose module does not read). The CALLER's role never needed
    a module -- the judgment compares the entry against the tree's module, which
    infer_admission_from_roster unwraps and refuses as module_unreadable when absent -- so the
    caller key becomes its own type, InferAdmissionCallerKey { decl_name }: the module comparison
    cannot be written wrong at the point of judgment, and no silent-skip arm exists to fall into.
    Claims and the descent keying site updated to the key type; all 9 hermetic claims and both
    codec controls re-verified on the runner (PASS 9, WALL_EXIT=0, CODEC_EXIT=0).
… 5444526887) -- no unimported-bare-provider fallback
…) -- shell-redirect residue from a commit message, nothing consumes it; ignore rule so the auto-stage cannot re-add it
@gunbai-bot
gunbai-bot Bot force-pushed the session/eager-cat-664-admit-callers branch from e64f5f3 to 6441557 Compare October 7, 2026 18:05
…retired admit_callers section (review 77645) -- the six Standing rows and one Superseded keep their declaration surface; the projection matches the Standing .dag roster (118 sections / 118 retired-or-standing row files)
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Fixed at HEAD (see the docs commit): docs/design-rung-drops.md is now main's projection minus exactly the retired admit_callers section — the six Standing rows (accumulator_copy_priced_out_file_gate_ratchets, fixture_closure_union_unmodeled_stderr_capture, identity_cast_route_new_witness_eval_step_cost, native_fault_experiment_off_pull_requests, rust_unit_tests_off_pull_requests, v1_integration_tests_deleted_from_the_unit_lane) and the Superseded rust_unit_tests_over_their_cap keep their declaration surface. The projection now matches the Standing .dag roster: 118 sections against 118 row files (main's 119 minus the one .dag retirement this PR makes). The mid-rebase regeneration had replayed the pre-rebase projection over main's newer rows; the restored file is the regen from the current roster, hand-removed only for the one retired row. — sent from eager-cat-664

…already deleted from the branch, so the rule has no consumer
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

The /acc ignore line is dropped at 5b2c3a0. The rule existed only to keep the unconditional auto-stage from re-committing the stray empty file review 77619 flagged; the file is deleted from the branch, nothing produces the path anymore, and the rule had no remaining consumer — agreed it does not belong. — sent from eager-cat-664

Ledger-Repair-Judged: docs/design-rung-drops.md
Heal-Candidate-Run: 37669169524
@gunbai-bot

gunbai-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

All three findings from review 77706 are fixed in the docs/census commit now on HEAD:

(1) The reference-conservation census's pin for dag/gunbc/rung_drop/admit_callers_discarded_on_the_native_route.dag is removed with the file it pinned — the census's own SamplePathMissing arm documents that a pin naming a deleted file is stale, and the variant_fields retirement set the same precedent (that row's pin was removed with its file).

(2) Every new comment that cited the drop as a live symbol now cites it as the former drop, matching dag.dag's wording: the arrow_named_edge_is_contract header in v2/std/node.dag, the infer_caller_admission_diags preamble in 04_infer.dag, the hermetic wall header, the long red claim's header, and the cost-debt row.

(3) floor_cost_debt_proven_chunk_22 no longer copies 496,179 eval steps / 1421ms cpu into prose; the comment now states that the figures live in the runs the row cites (floor of record 8528a59, re-measured at run 37499673683 / floor job 112393139664, head d4ec92f) and leaves the numbers there.

Re-verified on the runner: PASS 9 / WALL_EXIT=0 / CODEC_EXIT=0 on the new head. — sent from eager-cat-664

…ed as former, the cost-debt row cites its runs instead of copying their figures

(1) reference_consensus_census: the sample pin for the retired rung-drop row is removed
    with the file it pinned -- the census's own SamplePathMissing arm documents that a pin
    naming a deleted file is stale; the variant_fields retirement set the precedent.
(2) The new comment sites that cited gunbc.rung_drop.admit_callers_discarded_on_the_native_route
    as a live symbol now cite it as the former drop (matching the dag.dag wording): the
    arrow_named_edge_is_contract header, the infer_caller_admission_diags preamble, the
    hermetic wall header, the long red claim's header, and the cost-debt row.
(3) floor_cost_debt_proven_chunk_22 no longer copies 496,179 / 1421ms into prose; the
    figures live in the runs the row cites (8528a59 / run 37499673683 / floor job
    112393139664).

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head 458063a6f3021aaaec6c3f9694b4cbda718581e0.

The prior blocker is closed: infer_caller_admission_judged_diags is explicitly present in the claim module's selective v2.compiler.infer import, so the facts-present discriminator no longer depends on the unimported-bare-provider fallback.

I also checked the rebase-sensitive delta:

  • the branch follows main's removal of dag/gunbc/rung_drop/roster.dag; no replayed roster edit remains;
  • the affected imports use std.optional, with no stale v2.std.optional route in the PR diff;
  • docs/design-rung-drops.md differs from current main by exactly the retired admit_callers section; the six Standing and one Superseded sections restored after the bad replay remain present;
  • the /acc ignore residue has zero net diff;
  • reference_conservation_census.dag only drops the pin for the deleted row file;
  • floor_cost_debt_proven_chunk_22 retains its identity and retirement condition while citing the measurement runs instead of copying their figures;
  • the other carrier, consumer, fail-closed arms, codec controls, and nine hermetic claims retain the previously reviewed behavior. The only additional wording edits correctly refer to the now-retired row as the former drop.

Exact-head run 37685305629 completed with the required aggregate green: emit-build, generated, and floor succeeded; the pull-request rust-unit-tests job was skipped under the current workflow policy.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 7, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 8, 2026
gunbc-ci-auto-heal added 2 commits October 9, 2026 15:19
# Conflicts:
#	ROADMAP.md
#	docs/design-rung-drops.md
gunbai-bot Bot pushed a commit that referenced this pull request Oct 9, 2026
…olded, #13108 and #13330 dispositions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #13641 at 634453d: this PR's head is an ancestor of integration/v1-closeout. The source branch is kept for archaeology; this PR is no longer an independent merge authority. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
briansrls added a commit that referenced this pull request Oct 10, 2026
* dispatch-actuator witness: import the lineage, alignment and ticket names #13622's specimen uses

Review 78285 on #13622: the supplied-specimen claims call lineage_walk, lineage_is_rooted and alignment_chain and build TicketLine/TicketFields/NodeParent/AdmittedRoot/RoadmapNodeIdentity without importing them. They resolved only through the flat bare-name tier DESIGN schedules for removal, so they would go red when it is cut. Import each from its declaring module.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Merge #13548 (session/sharp-deer-755-unimported-type-import-migrate) into integration/sharp-raven-357"

This reverts commit 1a22abd, reversing
changes made to a04255a.

* native_emission_controls: repair integration union (close variant_literal_application_cases, one roster, one composition over all 17 case groups)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclude #13604 from integration/eager-gull-22: WIP, open REQUEST_CHANGES (review 78326)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs/design-rung-drops.md: regenerate through tools.docs_projection_gate regen after the #13569 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* grammar: import int_to_decimal_string from std.integer (#13436 moved it; #13379's binding-power row still named v2.std.integer integer_int_to_decimal_string)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: mtcollins1 runner: boot leg, runner image medium + runner-host-up termin

* Realize reviewed kernel dependencies through guarded host maintenance

* Rewrite the cross-module record-field pin to the refusal it named as its trigger.

Infer now refuses `n: true` against `RcfFar` declared in another module; keeping the counted-Undecidable pin would be a meaning fork of the same claim name.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Close the post-main census: drop the Map interpolation hole, concat the spatial cast.

Merging main reintroduced one implicit stringify (Map Display in the canonical-order witness) and left the spatial_dimension `{o as String}` template as a v1 span mismatch. Named Int/Nat/Symbol routes stay; the Map hole is deleted rather than given a fourth renderer.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Regenerate fleet-converge.yml via generated_artifact_gate main_wet

Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Remove scratch witness scripts committed by the close-out flush (review 78354)

The wind-down flush committed untracked local files (.runwit*.sh, .probe2.sh, .wit/)
as 32dcf74. They are local receipt scaffolding, not part of the boot leg.
This restores the tree to 80c24b3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* cax onboard: enumerate the closed-coproduct arms the floor's non-fold residue check refused

approved_grant_policy, plan_against_policy and provider_controlled_host matched closed coproducts
with a wildcard arm; each arm is now explicit, so a new variant refuses at compile rather than being
absorbed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* v1 closeout: open PR accounting

Every open PR, with its owning lane and its disposition in the mega branch.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: add the side-chat dispositions and wave 2

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 emit_rust mirror for the integrated authorities (first_generation_equal=true, 0 installs on pass 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: bold-bee and qwen dispositions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: outstanding work, closed PRs, and a re-sweep of all 162 open PRs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: #13607, swift-bat-828 branches

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration/silent-lark-156: regenerate generated artifacts after merging #13472 and #13610

Produced by main_wet + claim_executor --required-regen on BuildBuddy at fd4421d;
second regen round installed nothing (fixed point).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: silent-lark, gentle-dove, royal-moth, neat-boar, nimble-heron, valiant-crab handoffs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Second-type OpenRouter Retry-After and quota term (review 78356)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: lively-ram and silent-lark handoffs, #13460 folded, #13108 and #13330 dispositions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md and the v1_compiler_emit_rust stage0 mirror for the integrated tree

Generated through docs_projection_gate regen and claim_executor --required-regen
on srv1; round 2 reports first_generation_equal=true (a fixed point).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: #13488, #13574, #13475, #13634 reviews; #13648 closed; archive-flush residue

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* provisional: gentle-dove-36 mirrors for conflicted generated files (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Revert "Merge #13574 into integration/gentle-dove-36"

This reverts commit 32720e2, reversing
changes made to eee50a4.

* provisional: v1_rt.rs from silent-lark-156 (carries host_budget_darwin_physical; seed bootstrap, regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* provisional: v1_rt.rs = v1-closeout + silent-lark-156 delta (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: sharp-raven report, #13265, #13574 revert decision

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* provisional: append rt_host_budget (HostBudgetJoin*) to v1_rt.rs (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix stderr-capture tests so they hit real routes, not decoys.

Delete the rustc program that returned Err before spawn without compiling
emit_shell_stderr_policy_binding; absent policy is already refused at the
emit diagnostic wall. Drive Complete limits from the live host-budget join
and keep drain specimens on the emit_rust authority strings.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fabric_quota: re-attach the window-start comment to quota_window_start (review 78371)

checked_second had been inserted between the comment and the function it documents.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Required CI: withdraw the four v1-judged lanes; the gate is emit-build alone (operator ruling 2026-10-09)

The operator's v1 withdrawal: v1 is no longer a validation authority, and
the one use left to the seed is emitting v2. gunbc.compiler_gate_workflow
drops `floor`, `generated`, `rust-unit-tests` and `seed`; the `witnesses`
aggregate reads the one remaining lane, `emit-build`, through the same
folded roster (one row). The GateArmSkippedOnPullRequest arm leaves with
its only inhabitant.

The loss is one declared drop, gunbc.rung_drop v1_required_lanes_withdrawn,
stated member by member (witnesses, stage0 mirrors and every generated
artifact, lint, v1 unit tests, module resolution outside the two emitted
closures, the downstream consumers), with a trigger that names the
capability: a binary built from an emission of v2 judging that population
on the required path. rust_unit_tests_off_pull_requests is Superseded (its
lane runs nowhere; trigger did not fire; the new row holds the loss).

gunbc.required_ci_contract_epoch moves to 2026-10-09.1: the name `witnesses`
now carries a materially different contract.

Consumers repaired rather than left dangling: the lane-resolution census
roster (the census now does not hold by design and is the instrument that
re-derives the drop's module population), DESIGN section 3's typed
required-gate reference (gunbc.documentary_refs, now
emitted_subject_build_rows), the Building & checks rows, the onboarding
path's run-witnesses step, five recurring_failure_mode evidence rows that
cited deleted declarations, and the two gate witness files (the blocking
set is asserted as exactly emit-build; a new RED asserts the four
withdrawn variables reach neither gate surface).

Projections regenerated by tools.generated_artifact_gate main_wet (the run
peaked at 15.8 GB RSS, against the 7.55 GiB that module's own note cites
for 2026-08-31): witnesses.yml, DESIGN.md, docs/design-rung-drops.md,
docs/onboarding.md; every other rostered artifact came out byte-identical.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Drop process-global budget env from stderr-capture tests.

review 78373: planting Complete limits through GUNBC_MEMORY_BUDGET_BYTES
leaked into parallel tests and did not inhabit the emit bind. Claim the
drain strings only; leave the host-budget join uncovered.

Co-authored-by: Cursor <cursoragent@cursor.com>

* regen round 0: stage0 mirrors from claim_executor --required-regen (supersedes provisional splices)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* provisional: re-append rt_host_budget to v1_rt.rs (round-0 regen emitted v1_rt.rs without it; seed bootstrap)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* regen round 2: stage0 mirrors (v1_rt.rs now emitted with rt_host_budget; hand-appended lines gone)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate generated artifacts for integration/eager-gull-22

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* required_ci_phase_roster: import std.optional (v2.std.optional moved by #13388; stale import from #13225)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: all lanes reported; remaining merge plan; closed auto-opened PRs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert #13123 (admit_callers enforcement: mega's AdmitCallersEdge is the one enforcer)

* v1 closeout accounting: #13516 folded, #13212 dispositioned; every lane reported

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop #13545 transcribed-count red chunk (counts derive from ci_runner_sudo_binaries); retarget caller-admission real-route evidence to exact counts

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: eager-gull review outcomes, #13608 newer head, updated plan

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop the seed-growth citation of the deleted absent-policy decoy.

review 78381: hand_authored_declarations still named
emitted_absent_policy_refuses_before_spawn after that test was removed.
Absent policy stays cited as
capture_channels_without_stderr_capture_input_refuse_the_union.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert #13586 (receipt-only, excluded by operator review)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Revert #13453 (base-compiler/floor protocol; excluded by operator review): seed Rust, workflow steps and the script-row refusal API go with it

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* WIP: one required job, fresh products, memory envelope, heal-publish deletion (pre-merge, projections not yet regenerated)

* stage0 mirrors: restore generated mirrors to the mega branch's coherent set pending one regen round

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* floor_route_gap: give the belt exit-drain expectations their own chunk_43

Two folded PRs (#13442's seeded_filler rows and #13125's belt exit-drain rows) each
added floor_route_gap_expectation_chunk_42. The second silently replaced the first and
the native emitter refused (duplicate declaration). The exit-drain chunk becomes
chunk_43 and joins the roster, so both expectation sets are read.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* live_deploy: reconcile #13599 with #13583's directory authority

#13583 made owned directories the single directory authority (directory demands; host_directories)
and removed the directory kinds from the ensured steps and the instance parameter from
deployment_ensured_steps. #13599, folded alongside it, still called deployment_ensured_steps(instance:, target:)
and its witness matched on the deleted step kinds. The call passes target only, and the
lab-vs-production fabric-store claim now counts fabric_storage_store_directories demands in
deployment_directory_demands. Same claim, read through the surviving authority.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap_task_record: JSON codec for a runtime RoadmapNode (piece 1, uncompiled draft)

* roadmap_task_record witness

* roadmap_task_store: chain-partition roster over the fabric state binding, with wet witness (draft)

* roadmap_task_record: parent and centering required on the wire; drop nested optionals

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* managed_host: a superseded rung drop is not a standing citation

drop_is_standing_citation matched RungDropStanding with Retired and Standing only. Superseded has
existed since the 2026-10-06 supersession, and the closeout's seed refuses the non-exhaustive match,
which reaches every closure through managed_host (generated_artifact_gate included). A superseded
drop no longer stands, so it is not a citation, the same as Retired. (Found by smart-gull-336.)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: federation retired-path row below imports; floor_demand pinned envelope rows; managed_host Superseded arm (pre-regen)

* Headless Claude dispatch: print argv, systemd unit, stream-json projection.

When the harness has no spark, ExecutorDefault can admit Claude if custody is present; events stay in the belt's Codex envelope. Credential converge on srv1 remains an operator decision.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API

6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API

6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 94464b1)

* roadmap_task_record: balance ticket decode braces

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address review 78387: one Claude event mapping, explicit executor, transmit effort.

parse_codex_jsonl now classifies bounded Claude stream-json via claude_code_line_codex_kind; jq only bounds those lines. ExecutorDefault stays a harness refusal. Print argv carries --effort.

Co-authored-by: Cursor <cursoragent@cursor.com>

* v2 compiler: reconcile #13438's precedence climbing with #13582 and #12942

Two merge-born references to deleted code, found by emit-build on #13641:
- 02_parse: #13438's infix stamp still wrote ParseProvenanceState.frame / FrameMinted, which
  #13582 deleted with the packrat memo. The write goes; the sibling stamps already carry none.
- body_lowering_fold: #12942's sealed body_lower_fold_raw kept the pre-#13438 pipe-tower test
  (body_lower_is_pipe_tower_root / body_lower_tower_pipes_into_fold), which #13438 deleted. It now
  uses #13438's replacement predicate, body_lower_application_pipes_into_fold, and keeps
  #12942's sealed outcome.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fleet_converge_workflow: drop MtCollins1UiBundleObserve from the mode list

#13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from
FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list
now resolves to a declared variant. (Found by smart-gull-336.)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: trip is a ByteSize derived from the slot envelope (review 78388 item 3); witness claim the_trip_sits_inside_the_slot_envelope

* Address review 78389: emit tmux event pipe only for tmux containers.

Claude and harness systemd spawn no longer derive readiness from tee/pipe emission or refuse as tmux-event-pipe-emit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: two stale references from folded deletions

- first_element_of_a_list_has_three_spellings cited v2.std.optional Optional; the module is
  std.optional (#13388's move).
- authorization_pattern_selection_witness imported PastedOperatorToken, which #13568 removed
  with the pasted-token refusal; the import was unused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerated projections for the one-job gate, on the merged closeout tree

One main_wet of tools.generated_artifact_gate over this branch merged with
integration/v1-closeout a925452 (regen 632 s, verify 693 s, both exit 0,
on srv1 under capped MemorySwapMax=0 scopes), nine artifacts:

- witnesses.yml: both subject steps carry GUNBC_BIND_MEMORY_CGROUP_BYTES
  (the derived trip, 20 GiB) and the failure notice carries the envelope
  lines (what 137 means, no larger runner and no retry, the MEMORY RECEIPT).
- DESIGN.md, docs/design-rung-drops.md: the CI row and the drop roster.
- .gitattributes: the deleted heal-publish.yml leaves the generated-artifact
  merge list.
- fleet-converge.yml: the closeout's authority fix projected.
- tools/fabric_ci_fci1_bounded_execution_context.env: the fci1 context
  follows the slot (22/21 GiB).
- provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: a 22 GiB slot fits more
  slots per host than a 26 GiB one, so the derived rosters grow (srv1 gains
  srv1-10 and srv1-11). Desired state; applying it is the converge effect.

The witness batch on the same tree: 16 files, green except the two latent
reds already recorded in the PR (fci1_bounded_execution_context: a stale
envelope-basis expectation; heal_publication_boundary: 23/34).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Enrol roadmap_task_store wet witness on the local-repo wet lane, as the allocation seam witness is

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Land the v2 cutover program as designed roadmap entries: 11 nodes, native_obligation_population plan, edges, RED acceptance witnesses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md belt_liveness_publication_answers_unconsumed
Ledger-Rows-Repaired: docs/design-rung-drops.md bmc_secure_apply_converge_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci
Ledger-Rows-Repaired: docs/design-rung-drops.md fixture_closure_union_unmodeled_stderr_capture
Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer
Ledger-Rows-Repaired: docs/design-rung-drops.md kvm_observer_protocol_wet_witnesses_deleted_with_the_observer
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Heal-Candidate-Run: 38000315997

* closeout: regenerate stage0 mirrors and workflows from the folded tree

One emission round (operator ruling 2026-10-04) on srv1 at a925452:
claim_executor --required-regen, then generated_artifact_gate main_wet. Then on the
regenerated tree: seed build OK, gunbc test //gunbc/instruments:v2-native-cli exit 0,
//gunbc/instruments:self-host exit 0. Settles the files the folds left provisional
(fleet-converge.yml, the std_* and v1_compiler_* mirrors). docs/design-rung-drops.md was
already regenerated by CI auto-heal (17a309c).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: option B -- subject steps require the slot envelope; per-step trip withheld by the declared drop native_step_trip_awaits_fleet_job_cgroup; slot-grain receipt in gunbc test; seed-growth receipt (pre-regen)

* Enrol roadmap_task_store wet witness in floor_route_gap and the local-repo wet terminal, as the allocation seam witness is

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate ROADMAP.md, docs/plans and .gitattributes for the cutover rows; repair updated(...) wrapping

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Describe the envelope as slot-grain (option B) in witnesses-one-required-job; regenerate projections on the merged head

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Type the cutover receipt readings (closed kinds, ByteSize) and make the peak-above-trip control compare against the slot trip

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Subject steps require the slot envelope; the per-step trip waits on a fleet fact; the envelope decision is a .dag fold the seed mirrors

The first required run that passed GUNBC_BIND_MEMORY_CGROUP_BYTES
(38002497388 on a4b8f78) refused in four seconds: MemoryCgroupBindRefused,
the cgroup2 tree is not writable. memory_governor apply_memory_cgroup_bind
creates its leaf at the cgroup ROOT (a container-root design; the bind had
never been requested on the fleet) and a fleet job runs as the setpriv'd
job user under a root unit, so no job process can create the bound. The
operator approved the slot-grain arm (escalation 2026-10-09).

gunbc.memory_envelope (new) owns the decision and the verdict as folds over
supplied inputs -- the sibling of gunbc.memory_cgroup_binding -- and
test.claim.memory_envelope_witness_test reaches every arm by supplied value,
including the RED an inline decision could not: a slot requirement over a
process no numeric memory.max binds REFUSES (MemoryEnvelopeAbsent) rather
than running as bounded. The seed mirrors it arm for arm with unit tests;
the shells resolve the bounding cgroup through binding_cap_cgroup_dir (never
the peak locator), read memory.swap.max/.current/.peak (modeled in
extdeps.linux.cgroup_v2_memory) before and after the producer, print a
slot-grain MEMORY RECEIPT with event deltas and the peak labelled by whether
it rose, and refuse the run on any OOM kill or swap.

gunbc.emitted_subject_build_gate carries two envelope inputs and ONE
decision over them, native_step_memory_inputs(ownership): every subject step
REQUIRES the slot envelope (GUNBC_MEMORY_ENVELOPE_REQUIRED=slot, the
projection of EnvelopeSlotRequired) and the bind input at the derived trip
is withheld while gunbc.runner_slot_desired gunbc_runner_slot_job_cgroup_ownership
is JobOwnsNoBoundedCgroup. That is a fleet fact, not a rung drop -- nothing
on the required path ever held the trip -- so the climb is rostered as
gunbc.guarantee_stall native_step_trip_awaits_fleet_job_cgroup_stall
(grounding: unit delegation with DelegateSubgroup=, a per-job cgroup staged
by the root JIT wrapper, the governor's already-bound arm). The workflow and
the failure notice consume the fact; the witness exercises both arms by
supplied value, reads the live row, and asserts the bind KEY is absent.

The slot wall follows the ruling too: gunbc.runner_slot_allocation
gunbc_runner_slot_allocation_wall_holds drops its three floor conjuncts (a
slot sized to a tenant that no longer runs in it) and requires
MemorySwapMax == 0 instead of a swap above the maximum; the floor-fit drop
slot_row_pinned_below_demonstrated_demand_unrefused is Superseded with
v1_required_lanes_withdrawn as its loss holder; the slot witness re-pins the
row to 22/21/0 and its width alarms to the smaller slot's derivation
(srv1 12, srv3/srv4 21). The slot's demand oracle from here is the first
cold required run's MEMORY RECEIPT, a declared frontier.

The trip stays a ByteSize derived from the slot (review 78388 item 3). The
seed growth is receipted as gunbc.memory_envelope_receipt_seed_growth
(review 78391). The design document's CI row and the slot row's note say
the same.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* emit_rust: locate module via ModuleIndex.by_name; is_known_variant reads carried variant_to_enum (port of #13608 23f2d08, 8ff94ca; mirrors pending regen)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* decimal_digit_of_units: construct the units digit via the successor table; no D9 default for out-of-range Int

* closeout: bind variant_to_enum correctly at three #13665 call sites

import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate ROADMAP.md on the merged head; re-cite the envelope fact and stall

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Take sold Group B (srv9-srv12) out of everything that reaches hardware; declare fixture residue as a rung drop

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Supply sold Group B (srv9-srv12) as in-witness fixture population; production rosters stay empty

Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that
discriminated on the Group B population (commitment standings, admissibility, rail rows, topology
membership, reach labels) read nothing. spark_host_commitment_witness now folds the production
placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that
the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the
emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate std_integer stage0 mirror (remote required-regen candidate)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* closeout: revert #13662's fold (operator decision 2026-10-10)

#13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Recut to five durable outcomes: cold-run envelope receipt rename, acceptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* roadmap: split the event carrier's directory demand into a leaf module

gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one
directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect
import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status ->
host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories ->
roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet
refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory;
the carrier, the directory list and the owned-directory witness import it from there.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Address review 78405: delete the never-red frontier-count decoration; eligibility and disjointness controls run over supplied members

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* closeout: five merge-born refusals that main_wet found

- managed_host: HostnameAllocation no longer carries canonical_hostname; read it through
  allocated_canonical_hostname (hostname_allocation's name scheme, #13625).
- host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own
  account lookup does: the standing still decides the BMC route.
- mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became
  impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation.
- fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of
  #13607 and #13625).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Make fleet-converge branch-agnostic and parseable.

GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Name the branch-dispatch ruling; type malformed expected_revision.

Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Declare the named-revision and deploy-branch drop.

Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Recut #13660: restore privileged WIF to reviewed-main equality.

A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop leftover census conflict markers and project the named-revision drop.

The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OidcClaimPin inhabitance and the privileged-pin wording fork.

branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Split presented OIDC claims from pins; printer session-branch is a red.

Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Regenerate fleet-converge.yml (21 inputs) and pin dashboard-deploy to main.

GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: revert #13663's fold (operator ruling: #13662 and #13663 stay outside the closeout)

deep-cat-540 recuts it onto main after #13641.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Omit Spark dispatch when the administrator roster is empty.

Review 78408: regeneration had folded a sold-out Spark roster into target options: [] while spark_* modes stayed selectable. Restoring srv5-srv12 would invent enrolled hosts. Emission now drops the target input and spark_* mode options, and refuses any remaining empty InputChoice.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Treat srv1-production environment protection as the root-mutation boundary.

A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5

The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around.

First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs.

Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here.

Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fleet-converge: omit the Spark target input and spark_* modes while the administrator roster is empty; refuse an empty choice at emission (port of ffe8a90)

The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes.

What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name.

The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: delete the accounting doc; the terminal ledger lives in #13641's body (review 5474794145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* closeout: revert the #13664 fold (5c0d9d5) per the operator's review 5477471759: close #13664 without folding, branch preserved; projections regenerated next

* deployment environments: model the branch policy as GitHub returns it (name + branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET (review 78420)

Review 78420 on gunbc#13660 (folded here at 60c9457) found that extdeps.github.deployment_environments modeled the deployment-branch policy as SelectedRefs { refs: ["refs/heads/main"] }, while the API carries no refs: the environment object's deployment_branch_policy is null or { protected_branches, custom_branch_policies }, and the custom rules live at GET /repos/{owner}/{repo}/environments/{name}/deployment-branch-policies as branch_policies rows { name, type } with type "branch" or "tag". A reading of the real API can therefore never match the modeled refs, so gunbc.auth.github_deployment_environment's standing could never move from Unobserved to Holds (DESIGN section 3: model what the API actually returns; section 5: a check that cannot be discharged is not a boundary).

The model now carries DeploymentBranchPolicyRule { name, ref_type: PolicyRefBranch | PolicyRefTag } under SelectedBranchesAndTags { rules }, the srv1-production requirement is the single branch rule named main with required reviewers, the restriction predicate requires exactly one rule that is a branch named main, and the read obligation names both GETs and the shapes they return. The witness gains a supplied-value control: a tag rule named main and a two-rule policy are not the main-branch boundary, the single branch rule is. Standing stays Unobserved until the operator applies the setting and its readback lands; that flip is the first follow-up on main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: regenerate at the fixed point on composition A (revert of #13664, fold of #13660)

Same recipe as f8c3fa4, on a shallow clone of dbdc9d2 with the previous fixed-point seed as the boot seed (srv1, logs8): main_wet exit 0; required-regen generation 0 drifted gunbc_cli_dispatch_surface.rs (gunbc.cli_dispatch_surface is touched by #13660), generation 1 drifted gunbc_cli_dispatch_generated.rs, generation 2 first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; verify (dry main) exit 0; rebuild; gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0 warning_count=0 wall_s=611, discriminating red on v2_cli_compile_cli) and //gunbc/instruments:self-host exit 0 (wall_s=716, red on v2_compiler_compile). The projections resolved toward #13660's side in the merge (ROADMAP.md, fleet-converge.yml, docs/design-rung-drops.md) were byte-identical to main_wet's output, so only .gitattributes and the two cli_dispatch mirrors change here.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <briansrls@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: x <x@x>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant