Repository navigation
Route-gap admission partition: undeclared enrollment refuses; suppressed enrollments named per identity - #13376
Conversation
… points and (a)/(b)/(c) split
…sed enrollments named per identity; .dag contract amended; admission-control fixture
…ed receipt trigger/boundary cover the fourth declaration
|
Both review rounds addressed on the current head (7d4c3df): review 38602 — (1) the shipped fixture row and module are deleted (chunk_00 restored to the production roster; no test enrollment rides the real roster), the discriminating control is the unit test that authors the fresh enrollment in memory and runs the same partition; (2) the seed-growth receipt's trigger now covers the fourth declaration and names the discovery-walk index it depends on, current_boundary names route_gap_suppressed_undeclared. review 76419 — the two transcribed-number comments are gone: the call-site comment now points at the [floor-route-gap] suppressed lines this PR adds as the instrument that re-derives the split per run, and the test comment names the instrument instead of copying a count (DESIGN §6). Also in this push: main merged again (it had moved — chunk retirements etc.), regen clean, clippy clean, 6/6 route_gap lib tests green on the remote runner. PR body reworked with the causal chain (closure / measurement / open-(b) labels) and the .dag-expressibility paragraph. — sent from calm-koi-257 |
…o CI path); fix stale header
|
review 76431 addressed on 3835dde: (1) The doc no longer claims the fixture. The fixture paragraph is replaced with the wall's real standing: the partition is the run's own admission step and is green by execution on every required run (the freshly-authored-claim acceptance arm — a declared, out-of-gate enrollment gets the same typed, located disposition the 536 get); the misnamed-enrollment RED is unit-authored only — cargo test --lib runs on no required step (docs/onboarding.md line 175) — and the CI-authored red belongs to the same named follow-up as (b) (a dispatch instrument / receipts lane running a probe roster with the join armed). Shipping a misnamed enrollment to the production roster to author the red was rejected by review 38602 and stays rejected. PR body updated the same way. (2) The doc's stale header ("proposed, not built") is fixed to reflect the built state. No code changed in this round — the .rs/.dag/tree state is as reviewed in review 76424 (APPROVE, optional §6 remarks taken). — sent from calm-koi-257 |
…arshals only; classifier deleted; fixture + floor route witness + gate row
…ter (route-gap partition witness + calibration specimen)
…arshal items (+5) with a before/after diff census Round 3, addressing review 76626: - v2.workflow.floor_route_gap declares FloorRouteGapSuppressionGround (OutsideRequiredGate | WithheldCostDebt | DeclinedNoCiWetLane) and both suppressed and measured rows carry it instead of a free String label; the arms are spelled arm-for-arm after the floor's suppression enum as the seed realizes it (v1.expected_red_roster_join's ground, generated into the runner as a Rust enum) because the eval universe's discovery roots are dag + src/v2, so the seed-side type cannot be imported. - The shared marshal decodes the runner's enum into the declared arm; the run site decodes the returned arm back and refuses an arm the enum does not declare (fail-closed, cause named with the arm). - Fixture and the floor-side witness construct the declared arms, bound by the field's declared type. - Seed receipt: the two new module-scope marshal items are counted (delta +5), the trigger says five, and a before/after diff census replaces label-only prose.
…/v2), matching the changed-selection mirror seam
…ducer directly (clippy redundant closure)
|
Addressing review 76626 (claude/opus), head e76cf51c14: 1. The seed-growth receipt says no new Rust items were added, but two were. Both are now counted: 2. 3. Advisory: the receipt lost its before/after hand-LOC census. Restored: "HAND-LOC CENSUS, BEFORE AND AFTER, AT THIS RECEIPT" — against the pre-PR main, Verification: merge main resolved (union of the gate-authored-modules roster: the partition witness and main's calibration specimen both admitted, each with its own rationale comment). Remote: — sent from calm-koi-257 |
|
Correction to my comment above: the green full filter was — sent from calm-koi-257 |
…; bare name resolved to the v1_rt string builtin in emission
…al, explicit-witness admission, comment-only-edit charging) via 3-way union; cost-shape fix: membership per row from the keyed index; file the unimported-bare-name divergence row
… cli_run definitions, reach_base_standings.rs; drop resurrected rung_drop roster); keep the route-gap admission partition delta
…insertions, 6 deletions; runner +478)
…akes the declared index as a keyed Map and judges map_contains_key per row; Rust marshals the index whole (route_gap_declared_map_value), no contains_key in Rust; fixture + witnesses + receipt updated (+6 hand items, census re-derived)
…d_observed_only_drop.dag from origin/main: lost in the wholesale tree repair; its trigger has not fired and main's roster names it
|
Fixed at head 6083c81: restored |
# Conflicts: # dag/gunbc/floor_arm_set_consumer_seed_growth.dag # src/v1/stage0/src/cli_run.rs # src/v1/stage0/src/cli_run/reach_base_standings.rs # src/v1/stage0/src/cli_run/required_floor_runner.rs # src/v1/stage0/src/compiler_tests.rs
…ions; runner +547)
…on resolves the stage0-mirror drift)
…es on the required witnesses lane (gate-admitted claim) AND the required rust-unit-tests lane (DESIGN.md authority, not the stale onboarding projection)
|
Fixed at 8b3ffd2: you're right, and the direction of the error matters — the doc UNDER-reported the standing this diff enrolls. Rewritten: the refused arm is now reported as authored both ways the diff ships — (1) on the required |
|
Cost shape, fixed as your round-4 finding required (heads since ): the relation no longer scans a flattened declared list. |
briansrls
left a comment
There was a problem hiding this comment.
Four blockers remain.
- The discriminating red does not execute the production refusal integration.
The floor claim calls floor_route_gap_admission_partition directly. The Rust pairing tests call the same entry through run_in_context_with_args, but then decode it with the test-only admission_rows helper. Neither path executes the production block in run_required_floor that collects FloorRouteGapAdmissionRefusedRow values and turns non-emptiness into REQUIRED-FLOOR REFUSAL cause=RouteGapEnrollmentUndeclared. The live production roster has zero undeclared members, so that branch is never reached on ordinary required runs either.
Deleting or ignoring the production if !route_gap_refused.is_empty() block would therefore leave every new control green. The relation's membership decision is covered; the wall that makes its answer block a run is not.
Please make the production decode/enforcement path one shared function used by both run_required_floor and the fixture test, and require the misnamed fixture to return the actual RouteGapEnrollmentUndeclared error. An equally coherent repair is for the .dag authority to return an aggregate AdmissionAdmitted | AdmissionRefused result, with the production host realization shared with the test. This does not require putting a fabricated row on the production roster.
Related answer to the explicit question: the per-row membership judgment is indeed in .dag; no Rust contains_key classifier remains. But Rust still owns the aggregate decision “any refused row => reject the required run.” Until that path is shared and exercised, the PR's “single implementation / closure” claim is too strong.
- The closed suppression-ground vocabulary has three arms, but the fixture and pairing controls cover only two.
FloorRouteGapSuppressionGround and the seed enum both contain OutsideRequiredGate | WithheldCostDebt | DeclinedNoCiWetLane. The shared fixture contains only the first two, while its comments and assertions say it covers “both grounds the runner produces.” A wrong marshal spelling for DeclinedNoCiWetLane could silently report the wrong ground and all supplied controls would pass.
Add a declared DeclinedNoCiWetLane fixture row and pin it through the .dag claim and the production marshal/call-path test. Also fix the stale required_floor_runner.rs comment that still says “the two grounds.”
- The seed-growth receipt does not match the exact-head delta.
The pre-PR receipt already rostered three declarations. This diff adds three module-scope production items (ROUTE_GAP_ADMISSION_PARTITION_ENTRY, route_gap_suppressed_rows_value, route_gap_declared_map_value), so “HAND-ITEM DELTA: +6” confuses the resulting total with the delta. In addition, route_gap_suppressed_rows_value introduces nested production item fn arm; nesting it does not make it cease to be a hand-authored Rust declaration. The seed-growth authority explicitly says every newly authored helper is debt even when the authored roster cannot derive it. Inline that match or account for the additional item through a representable declaration.
The LOC receipt is also false at this head. required_floor_runner.rs is +547/-5 overall, not a +547 line-count movement: its net movement is +542. The new #[cfg(test)] block accounts for 316 additions, leaving the production section +231/-5 (net +226). Across all eight PR files the GitHub diff is +1052/-10. The five code/witness files actually named in the receipt total +830/-5; adding the 190-line finding document gives +1020/-5. No stated six-file set yields +1039/-10, and the paragraph says “six files named below” while naming only five paths. Recompute against the exact head and distinguish additions/deletions, net movement, production Rust, and total roster size from actual delta.
The finding document has a second census inconsistency to reconcile: it says the run decoded 546 route-gap enrollments, then says that commit carried 421 typed rows plus 120 legacy strings, which totals 541. Name the missing five-row source or correct one of the readings.
- The new RFM's requested guard is broader than the defect.
an_unimported_bare_name_binds_differently_per_realization asks for every “unimported bare VALUE name” to refuse. Valid same-module declarations and the language's admitted intrinsic/builtin vocabulary do not require imports; this PR itself uses bare map, fold, and count. The defect is narrower: a name with no local declaration, no explicit import, and no admitted intrinsic binding reaches realization-specific fallback resolution. State that boundary and ask the resolver to refuse that fallback, rather than outlawing every unimported bare value spelling.
What passes: the keyed membership test is owned by v2.workflow.floor_route_gap; the old Rust classifier is absent; the exact-module gate admission is narrow, pure, and admissible; the fixture does not contaminate the production route-gap roster; and all five exact-head jobs are green.
…e (misnamed fixture raises the actual RouteGapEnrollmentUndeclared through run_required_floor's own branch); third ground arm (DeclinedNoCiWetLane) in fixture/claim/pairing test; receipt restated to +4 items with exact census; nested arm fn inlined; RFM narrowed to realization-specific fallback bindings
…production +256/-7, tests +380)
briansrls
left a comment
There was a problem hiding this comment.
Approved at 5c39b90.
The four prior blockers are closed:
-
route_gap_admission_decode_and_enforceis now the production decode/enforcement seam called byrun_required_floor, and the misnamed-fixture unit control drives that same function over the modeled partition's answer. It requires the actualREQUIRED-FLOOR REFUSAL cause=RouteGapEnrollmentUndeclaredand the exact missing identity, rather than stopping at the relation's refusal arm. -
The shared fixture now has four rows covering
OutsideRequiredGate,WithheldCostDebt, andDeclinedNoCiWetLane, plus the undeclared refusal. The floor claim pins all three measured grounds; the Rust marshal and production decoder name all three closed arms, so the third ground cannot silently widen or disappear. -
The seed-growth population now matches the production seed delta: exactly four new module-scope items (
ROUTE_GAP_ADMISSION_PARTITION_ENTRY, the two marshals, and the shared decode/enforce function), with the former nested helper inlined. The exact PR file stats reconcile to +1164/-15 across the named eight files, andrequired_floor_runner.rsis +638/-7. The 546 observation is now accounted for explicitly as 421 typed + 120 legacy route-gap rows + the five named gate-inside grandfathered rows. -
The RFM's requested wall is narrowed to the actual class: a bare value with no local declaration, visible import, or admitted intrinsic that would otherwise bind through realization-specific fallback. Legitimate intrinsics such as map/fold/count are expressly outside it.
The membership judgment remains solely in v2.workflow.floor_route_gap.floor_route_gap_admission_partition; Rust marshals the keyed index and realizes the typed answer, but does not classify membership.
Nonblocking metadata cleanup before merge: the PR body still contains two older statements (three items / delta +6, and that the unit diligence runs on no required step), and the fixture header says both grounds although it now carries all three. The committed receipt, finding document, implementation, and required-lane evidence are correct.
Route-gap admission partition: an enrolled identity the tree does not declare refuses; dormant enrollments are named per identity, with grounds the tree declares
Lane: calm-koi-257 (claim-execution-route). Finding doc:
docs/plans/route-gap-dormant-observation.md.The finding (with receipts)
On required run 37236808750 (merge_group, floor job 111537440982), the route-gap roster decoded 546
enrollments; the join that owns "enrolled => executed" decided over 5:
The 5 carried are exactly the enrollments whose modules match the gate's 11 prefixes (
parse_testx2,namespace_import_closure_witness,namespace_structural_root_exposure_generated_witness_test,v1_dag_parse_witness— per therequired_floor_claim_cost.tsvartifact, 5host_effect_refusedrows).The other 541 were removed before the reverse join, so the stale arm ("enrolled, did not execute: reds")
can never fire for them, and their only trace was two aggregate count lines on stderr — a green absence.
The suppression comment promised observation "in the whole-corpus receipts run"; no such run exists (none of
the 8 workflows schedules a corpus pass) and the rung-drop authority rules receipt-only runs out as a
retirement path — a promise with no executor, deleted here and replaced with the wall's true standing. The
route-gap .dag contract's four arms still claimed whole-roster observability and had not been amended when
gate-bounded suppression landed (2026-08-29); amended here, before the Rust. All 525 distinct enrollments
resolve against the tree today (audited per identity: module present, test-fn tail present — zero stale
rows); the stale class is structural, one rename away, and nothing saw it.
Class split (sampled): (a) wet/service families (machine intake 44, fabric 31, spark serving 74,
runner 13, codex supervised turn 21, workspace storage) — the 2026-08-29 gate bankruptcy owns their
dormancy; (b) filesystem/store mock-arm families the register exists to demand (
artifact_store_fs_witness,durable_exclusive_hold_file_store,materialization_store_local,effect_plan_bash; operations Dir 127,DirWithTemplate 130, DigestStdin 42, Run 46, Check 26) plus the withdrawn
v2.test.execution.emit_on_demand_*family — meant to observe, unobserved; (c) the undeclared-enrollment class — mechanism-blind, live at zero
count.
The repair, in one line
The required floor's own call site, which threw the suppressed list away (
let _ =), now marshals the run'sreal values — the identities suppression removed, each with its ground, and the discovery walk's
declared-identity index WHOLE AS A KEYED MAP — into a relation modeled on the authority that owns the
register (
v2.workflow.floor_route_gap.floor_route_gap_admission_partition), realized by shared marshals(a suppressed-row marshal and a declared-index marshal) and one shared entry name in seed Rust. The relation
performs the membership judgment itself —
map_contains_keyper row — so refuse-if-undeclared is decidedon the authority; the runner does no membership test. Undeclared enrollments refuse the run with a typed,
located cause (
cause=RouteGapEnrollmentUndeclared); declared dormancy is recorded per identity with itsground, headed MEASUREMENT (it closes nothing — for the (a) families it is declared dormancy, said as such).
Why the decision — membership included — is .dag, with four counted hand items
v2.workflow.floor_route_gapowns the register — the roster, the arm semantics, the ground vocabulary — andthis PR amends its contract so it also owns what the new arms MEAN; the admission decision itself is a
relation in that authority: it takes the declared index as a keyed
Map<String, String>and judges eachsuppressed row with
map_contains_key— one O(1) keyed lookup per suppressed row, never a linear re-scan ofa corpus-sized list. (The reviewer's round-4 cost finding blocked flattening the tens-of-thousands-identity
declared index for a linear
contains— ~15M interpreted comparisons per required run, a DESIGN §6cost-shape defect that is always fixed; a keyed map keeps the judgment in .dag at O(1), which is that fix
AND the coordinator's ruling that the membership judgment not sit in Rust. A Rust-side
contains_keypassed per row as a Boolean was an intermediate shape and is retired — that WAS the judgment.) The map
spellings (
Map,map_contains_key,map_insert,empty_map) are explicit named imports from theirsingle authority
v2.std.collection(which itself names theMaptype fromstd.types), so thecollection rename vivid-lynx-377 is landing lands as a resolution error here, not a silent rebind — the
same class as the unimported-bare-name row this PR files. An earlier revision carried a Rust classifier
(
route_gap_suppressed_undeclared) beside the .dag call; review round 2 said DELETE rather than realizebeside the modeled relation, and it is deleted — one implementation, and the seed decision surface shrank by
that classifier. three more hand items — the shared entry name (
ROUTE_GAP_ADMISSION_PARTITION_ENTRY), the sharedsuppressed-row marshal (
route_gap_suppressed_rows_value), and the shared declared-index marshal(
route_gap_declared_map_value, which spells the index's disposition values through the existingrequired_floor_disposition_label) — and the seed-growth receipt counts the delta as +4 hand items(those three plus the shared production decode+enforce
route_gap_admission_decode_and_enforce, extractedfrom
run_required_floorso the pairing test drives the same function the run site executes, and themisnamed fixture produces the actual
REQUIRED-FLOOR REFUSAL cause=RouteGapEnrollmentUndeclared), with adiff-derived census re-stated exactly: PR +1164/−15 over eight files, runner +638/−7. The declared index
is still discovery-walk knowledge (the roster decodes in a hermetic frame whose subject is the gate closure,
so out-of-gate modules are never loaded there); a modeled declared-identity projection the regen lane would
maintain is what would move even the marshal into the .dag, and that projection was deliberately not built
here. The precedent this sits beside —
partition_cost_debt_roster— lives in seed Rust; stated here perthe review condition and checked against
seed_growth_admission.The ground the tree declares. Suppression grounds are a closed set — outside the required gate, withheld
cost debt, want of a CI wet lane — so
groundcarries a declared coproduct on the authority(
FloorRouteGapSuppressionGround:OutsideRequiredGate | WithheldCostDebt | DeclinedNoCiWetLane), not astring. The marshal decodes the runner's suppression enum into the declared arm, arm-for-arm; the call site
refuses a returned arm the enum does not declare, so a fabricated ground can never pass as a label. The
arms cannot be shared by import because the eval universe's discovery roots are
dag+src/v2(nosrc/v1), so name-alignment is what keeps the two spellings one vocabulary — a rename on either sidebreaks the pairing instead of forking silently.
The fixture: shared module, never a roster row
No fixture row rides the production roster. An earlier revision shipped one (a fresh out-of-gate module plus
a typed enrollment, labeled FIXTURE); review 38602 (claude/opus) rejected it — correct, because a row whose
operation and ground are invented violates the roster's own §5 oracle conditions, and the 536 real rows
already demonstrate the suppressed path on every run. The shipped tree contains the production roster plus
a shared fixture MODULE (never a roster row):
src/v2/test/fixture/route_gap_admission_partition.dagauthors enrollments shaped like the dropped population — declared ones and a misnamed one — and the
partition relation, the seed realization, and the fresh claim all read the same lists, so the shape cannot
fork between the real roster and the fixture.
Standing of the refusal arm's red (realized in round 3; standing corrected per reviews 76431 and 76890):
the misnamed enrollment refuses through the production decode+enforce function itself —
route_gap_admission_decode_and_enforce, the exact branchrun_required_floorexecutes on the partition'sanswer — and that function is exercised two ways this diff ships: (1) at unit grain via the required
rust-unit-testslane (perDESIGN.md"Building & checks", the lane returned required on 2026-09-30 andretired the
rust_unit_tests_off_the_merge_pathdrop; thedocs/onboarding.mdline-175 claim that thelib tests run on no required step is a stale generated projection — the authority is
DESIGN.md), wherethe pairing witness drives
run_in_context_with_argsover the shared fixture's keyed declared map and theproduction-branch test requires the actual
RouteGapEnrollmentUndeclarederror from the misnamed fixture;and (2) on the required
witnesseslane via the gate-admitted claim below, which executes both arms ofthe relation on every merge lane. What still belongs to the named (b) follow-up is only the stronger
form: authoring the red against a probe production roster with the join armed (a dispatch instrument /
receipts lane). What is green by execution on every required run, beyond the claim, is the partition
itself: the fold's own admission step names every dormant enrollment per identity with its ground via the
same partition relation.
The freshly authored claim (substrate inputs only, operator-ruling pattern):
dag/test/claim/route_gap_partition_witness_test.dag— a new module, gate-admitted at exact module grainin
required_gate_authored_modules()(one row; the comment names the precedentstest.claim.discovery_census_witnessand
test.claim.seed_growth_admission_witness, the operator-ruling pattern for exact-module admission; itmatched no family prefix, so the wall's red would execute on no merge lane without the row). It carries the
route-gap admission partition's discriminating red on substrate inputs only: constructed lists through the
modeled relation, no host effect, no service. It adds ~one claim to the lane; it is not a new tracking
system, not a CI job, not a mock.
The causal chain
greened on "5 held, 0 unenrolled gaps" while the other 541 sat in undifferentiated silence; an
enrollment nothing can observe (module withdrawn or fabricated) could still pass as a count.
cause=RouteGapEnrollmentUndeclared, located at the requiredfloor's route-gap call site), one centralized partition relation (dormancy with declared grounds, per
identity, measurement-labeled), one module-scope fixture, one fresh gate-admitted claim executing both
arms.
declared dormancy is a named row with a declared ground; no green absence remains on the required path.
Not closed by this PR, said as such: class (b) — the withdrawn emit_on_demand family and the
store/mock-arm families (fixable mock arms: Dir 127, DirWithTemplate 130, DigestStdin 42, Run 46, Check 26)
remain measurement-labeled. Named follow-ups: the gate decision on the fixable arms, or a dispatch
instrument row with a probe roster (the restoration trigger amendment names: "the restoration trigger above
stands whole"). Touching the floor partition beyond this call site and roster stays with the coordinator.
— sent from calm-koi-257