Repository navigation
recurring_failure_mode: a roster edit judged against the base tip, not the merge base - #13344
gunbai-bot[bot] wants to merge 2 commits into
Conversation
…t the merge base Two PRs (#13333, #13341) went red with RosterRetirementChanged on rows their diffs never touched, and cleared after merging main. The cause is read from the code: interface_consumer_planning resolves the merge base on the MergeBase arm, while unimported_bare_provider_gate and the cost-debt edit-budget arm read the roster at floor_diff_comparison_readout().base(), the tip. #13332's admission reading inherits the same accessor. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head de0ab803071e211a0cdbf7e1a70f1dc1285a3a1c, against DESIGN.md §§3, 4b/4d, 5 and 6b. One receipt-accuracy correction only; no implementation fix or new execution is required in this RFM-only PR.
The central diagnosis is accepted. required_floor_runner::interface_consumer_planning branches on FreezeBaselineComparison: Direct keeps the selected base, while MergeBase runs git merge-base base head, then resolves the selected commits. The unimported-provider gate and changed-cost-witness budget branch instead take .base() without applying that relation. The unimported roster edit correctly refuses a supplied Retired -> ActiveDebt transition; the unjustified link is supplying the target tip as its base. The reported incidents are therefore loud false refusals, not evidence that those retirements were silently reasserted.
The historical #13332 admission call site at 103a8ea847 also supplies .base() to cost_debt_admitted_identities when the cost roster is changed. Its head-minus-base membership can consequently attribute main-side retirements to the behind branch as admissions. Keeping that code-derived attribution error distinct from the reported false-red incidents is appropriate; neither establishes an observed silent merge of a retirement reversal.
Correction: the cost-edit reader reads witness source, not the unimported roster
The MECHANISM receipt currently groups both existing tip readers as reading “the roster ... through ... unimported_bare_provider_roster_at_base.” That is not the cost-edit path.
unimported_bare_provider_gatereads the unimported-provider roster throughunimported_bare_provider_roster_source_at_base/unimported_bare_provider_roster_at_base.- The cost-debt edit-budget branch passes the affected witness's
rel_path, functions and head source tocost_debt_changed_witness_ceilings. Its model,v2.workflow.floor_cost_debt_edit::cost_debt_changed_witness_ceilings_at_base, performsgit.Core.Show(base, path)for that WITNESS FILE, then classifies its declaration-token edits to select the budget. It does not read either debt roster through the unimported-provider reader. - #13332's cost-debt admission is a third path:
v2.workflow.floor_cost_debt_verdict::cost_debt_admitted_identities_at_basereads the COST roster's membership.
Separate those source objects and owning readers in the receipt and the matching PR-body sentence. They share the same wrong base selection, but they do not share the same roster reader or judgment. This matters to the stated fix population: a roster-only correction would leave the witness-source budget comparison on the wrong tree.
The proposed one-resolution trigger is otherwise accepted in scope: all deciding base-tree readers consume the same resolved commit for the selected relation, rather than independently adding merge-base calls. Preserve Direct comparisons for exact replay/push windows; the existing floor_diff_comparison_readout_law records why applying merge-base to every arm is itself a fail-open. This row records an unbuilt repair, not an attained rung or permission to change a ceiling.
Reviewed the complete one-file diff, exact-head DESIGN, the cited host call sites and model readers, and the historical #13332 admission call site. Incident and post-merge outcomes remain author-reported; I did not rerun a floor, reproduce the incidents, or mutate any code. Exact-head witnesses run 37259379438 is in progress. The head was unchanged immediately before submission.
…vs witness source) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…integration control Review on #13332: base membership is the base roster's evaluated result, in an isolated pool under a scratch module name (an unselected chunk is not membership; an unevaluable base refuses CostDebtBaseRosterUnevaluable). The base is read at the merge base on a MergeBase comparison, not the base tip (#13344). The admission merge and the wall are the production handoffs the integration control drives; a roster ADDED by the change now admits every row, as documented. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…inputs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Rows only. Files one recurring_failure_mode row, at eager-gull-22's request, after the same red hit two PRs in one lane.
Class. A required-floor judgment of a roster edit reads the base roster at the base ref's TIP, while the floor's declared comparison is merge-base. A roster-editing branch that falls behind main is charged with reversing every roster change main made after the branch point.
Occurrences. #13333 and #13341 both refused with
RosterRetirementChanged (Retired -> ActiveDebt)onroadmap_launch_deployment_receiptrows neither diff touched. Both cleared after mergingorigin/main, with the fix unchanged.Mechanism (read from the code, not inferred).
required_floor_runner::interface_consumer_planningresolvesgit merge-baseon theFreezeBaselineComparison::MergeBasearm.unimported_bare_provider_gateand the cost-debt edit-budget arm of the claim planner callfloor_diff_comparison_readout()?.base()and read the roster at the tip. So one readout yields two base trees in one run. #13332'scost_debt_admitted_identitiesread (at 103a8ea) uses the same accessor, which is the silent-arm variant: a behind branch is charged with admitting rows main retired.Correction to the request's framing. The occurrences observed are a LOUD false red, not a silent reassertion. The silent arm is reachable through the admission reading, and the row records both.
Ceiling 3, trigger (capability): every base-tree reader obtains the base commit from one resolution of the readout that applies the MergeBase arm. A per-site merge-base call does not discharge it.
No code change here. The fix belongs in its own PR; #13332 is being asked to read its admission base through the merge-base resolution.
🤖 Generated with Claude Code