Repository navigation
Managed-host cut O1c-2: PriorLifeBoundary archive, effect-leg deadlines, incomplete vs refused (dry) - #13419
Conversation
…ms (pre-existing O1b proxy) test.claim.machine_intake_bmc_secure_state_witness observer_at was admitted to gunbc.clock_read observer_clock_modeled and returned a sealed ObserverClockInstant, so any function of that module could mint a modeled instant through it: a sanctioned-constructor proxy. The helpers now take instants, each Bool claim mints its own into an open ScheduleInstants record, and only those claims are admitted. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es, incomplete vs refused (dry) The convergence fold's first effectful consumer. gunbc.fleet.convergence_fold gains StepIncomplete / InstanceIncomplete / RunIncomplete, distinct from refused and stopped and never converged, with the domain's incompleteness type as a third parameter; and sealed effect-leg carriers: LegBudget (a positive duration, minted only for the domain's declaring function), LegDeadline and LegCompletedWithinDeadline, judged on the observer clock. gunbc.machine_intake_prior_life_boundary archives the eight prior-life carriers of machine-intake-design §5 as content-addressed evidence, derives the baseline cursor from that archive, writes it to the (dry) staging store and reads it back by digest. Observe/assess/decide go through HostEffectDomainProjection; the write and readback are the domain's (C8 stays awaiting). Only LogsArchivedWithBaselineCursor has a constructor. Mt. Collins and Mt. Jade policy rows require all eight carriers and admit only the uncleared arm. gunbc.bmc_model BmcWorld gains record_surfaces (Manager DateTime, Redfish LogService, account-event log entries, VirtualMedia, Sensor), all unmodeled by default; extdeps.bmc.redfish_telemetry gains RedfishLogService. The arrival prefix now runs through PriorLifeBoundary with its census row. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (real-path control) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…caught Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… plus a Bool (review 76614) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 76614 (stopped_incomplete as an undeclared sum): fixed in 3d7b1f3. — sent from deep-lynx-731 |
|
Hermetic on BuildBuddy at the exact head
— sent from deep-lynx-731 |
# Conflicts: # dag/gunbc/bmc_model.dag # dag/test/claim/machine_intake/machine_intake_bmc_secure_state_witness_test.dag
|
Merged main, including #13242, at 31ef3db. There were two conflicts:
Local hermetic re-run on the merged tree: bmc_secure_state_witness and its forged probe are 24/24. Full roster: 340 witnesses, 327 PASS, plus the same 13 route gaps that fail at base.
— sent from deep-lynx-731 |
|
Review 76675, the growing admit list on — sent from deep-lynx-731 |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact requested head 31ef3dbe8c6270bb7fe8599a95c4fa937607e0b0, against DESIGN.md §§3, 4b, 5 and 6b and docs/plans/managed-host-untangle.md O1c-2. Two archive-boundary blockers; neither requires BmcSecure apply/cutover, a live controller write, or restoration of a CI lane.
Accepted scope and composition
Keeping BmcSecure apply/readback, authorization, principals and lanes for O1c-3 is correct. The archive is explicitly a dry realization, not evidence of a live prior-life capture. The platform rows require all eight carriers and do not infer a controller family. Unmodeled record surfaces stay distinct from modeled empty populations.
The incomplete propagation is coherent: StepIncomplete becomes InstanceIncomplete, satisfies no converged precondition, preserves LineIncompleteAt, and produces RunIncomplete rather than RunStopped or ConvergedRun. The duration budget and deadline use their own carriers; completion distinguishes elapsed, reversed and unobserved time. This is a dry elapsed-time judgment, not evidence that a future live I/O operation is cancellable. The ordinary archive path independently looks up and hashes the stored body before establishment. Those improvements are not the findings below.
[P1] The actual archive/receipt minters remain callable around the checked entry
In gunbc.machine_intake_prior_life_boundary, dry_archive_prior_life has an admit list, but established does not. It directly constructs PriorLifeBoundaryEstablished from independently supplied key, consumed identity, subject, policy, archive, application and readback. A caller holding a genuine receipt can reuse its archive/readback, supply another subject/run's keys, choose ArchiveAlreadyHeld, and obtain a new sealed receipt without executing the identity join, policy assessment or a store read. Supplying sealed members does not establish the relationships between those members.
There is also a route that does not need a previously established phase receipt. archive_of is unrestricted and takes a world and captures independently; it can return a sealed archive with empty/gapped or unrelated captures. write_then_read_back is unrestricted too: it constructs the sealed plan, writes, reads back and calls established without running classify_prior_life_policy. Calling this helper on an incomplete archive therefore bypasses the very required-carrier refusal the guarded entry tests.
The enrolled forged probe covers carrier literals and outside calls to dry_archive_prior_life, dry_prior_life_instant and leg_budget. It does not cover these actual minter/helper calls. Its greens do not establish the claimed entry confinement.
Confine the receipt/plan/archive-producing helper chain to its checked production callers, or change those functions to consume sufficient joined evidence rather than independent authorable facts. In particular, close established, write_then_read_back and the independent world/captures construction boundary in archive_of; audit intermediary carrier-returning helpers rather than sealing only the advertised entry. Add callee-specific outside-call REDs and an accepted real-entry control. A receipt for A must not be re-keyed to B, and an incomplete capture population must not become established through a helper. No carrier-returning witness facade is needed.
[P1] The stored archive is lossy, so a valid digest readback can certify the wrong baseline
The earliest faulty boundary is the capture encoding, before hashing or storage. virtual_media_line serializes only locator, inserted and image. The input RedfishVirtualMediaObservation also carries media_types and connected_via, which are discarded. This is not merely omitting an unmodeled upstream property: these fields are present in this exact tree, and redfish_virtual_media_is_detached explicitly consumes connected_via. Varying that observed state can leave the archive body and digest unchanged.
The delimiter encoding is also non-injective. log_entry_line joins id/severity/message with |, and log_service_lines joins records with newlines without escaping or lengths. These two valid two-entry populations of one service produce identical capture bytes:
A: (1, "OK", "a\n2|OK|b"), (3, "OK", "c")
B: (1, "OK", "a"), (2, "OK", "b\n3|OK|c")
Both emit:
1|OK|a
2|OK|b
3|OK|c
The service id and declared entry count are the same. Every other carrier and the subject can remain identical, so the complete archive body and its digest are identical too. But archive_of obtains the cursor separately from world.record_surfaces.log_services: A gets final entry 3 and B gets final entry 2. Thus the alleged archive-derived cursor is not a function of the stored archive. Re-observing B over A's store can take ArchiveAlreadyHeld while producing a different baseline cursor. This is a serialization collision, not a cryptographic-hash collision.
Preserve the complete modeled capture payload through an existing lossless encoding authority, with unambiguous framing. Derive the bytes and baseline cursor from that one archived payload (or derive the cursor from its verified readback), not independent world/capture inputs. Unsupported fidelity must be a typed gap, not a CarrierCaptured that silently discards it. Add controls for the two log populations above, differing connected_via/media_types with other fields held fixed, and a real write/readback positive. Hashing and re-reading a lossy summary cannot satisfy the archive contract.
The 13 KVM Hermetic route gaps: no new declared drop merely for this rerun
These are no-verdict realization gaps, not 13 semantic assertion failures and not newly demonstrated regressions. At this head v2.workflow.floor_route_gap already records this KVM witness family in floor_route_gap_expectation_chunk_29, naming Dir/DirWithTemplate and NoMockResponse; its receipt also names their local-repo-wet route and historical execution. Preserve/reconcile the measured identities with those existing records and cite that standing in this PR's terminal receipt.
Do not invent a previous working Hermetic rung and then declare it lost. DESIGN §4b(3) needs a real loss of a previously held route or guarantee; the reported identical base/head gaps establish no such loss. Do not enroll these as expected semantic reds, or add unconditional success mocks to manufacture a verdict. No duplicate RFM is required merely to repeat an already tracked gap. A genuinely uncovered error class gets an RFM filing/update under §4b; evidence that a formerly executing wet route or gate has been removed would instead require updating/declaring the corresponding bounded drop. Neither is established solely by this Hermetic result.
Evidence
Verified exact-head workflow 37345767503: floor, generated, emit-build and aggregate witnesses all succeeded. The 310/13 BuildBuddy batch belongs to 3d7b1f303b; the later PR comment reports 327 passes and the same 13 route gaps at the requested merged head, including 24/24 for the merged BmcSecure state/probe population. Those batches and ten mutation results remain author-run evidence. I inspected the source and controls; I did not execute the project's claims/mutations or touch hardware. The encoding counterexample above is derived directly from the implemented joins.
The requested SHA was unchanged and mergeable immediately before submission. The two blockers are new archive-authority/fidelity defects, independent of the acknowledged, separately routed dry_bmc_account_instant repair and of the pre-existing KVM route gaps.
…rchive bytes, digest and cursor (review 5419442560) established, write_then_read_back, archive_of, observe_prior_life, dry_write_archive, read_back_archive, effect_leg_deadline and complete_effect_leg are admit_callers-sealed to the checked path, each with an outside-call RED. Captures carry their typed payloads; the archive bytes are RFC 8259 JSON over every modeled field (tagged enum arms, framed lists), the cursor positions are read from those payloads and encoded too, and the digest is of those bytes. Controls: the review's two-log counterexample and connected_via / media_types variation. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… position (floor cost) The two arrival route claims went over the 72,300 new-witness budget (83,264 / 82,829 marginal eval steps) after the archive moved to an injective JSON encoding. The encoder is linear (about 720 steps per SEL record at 1, 20 and 80), so the route claims archive the smallest world that still captures all eight carriers with one real SEL record, and assert the cursor's SEL position as well as its archive digest. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact requested head 061696d5b28d44393261d9934758b35a6642ce5d, against DESIGN.md §§3, 4b, 5 and 6b. The previously demonstrated receipt-rekeying and unchecked-write bypasses are closed. The one-SEL real-route pairing is accepted. One archive-fidelity blocker remains: a nested record is still flattened through a non-injective renderer before JSON receives it.
[P1] virtual_media_json still loses the locator's field boundaries
In gunbc.machine_intake_prior_life_boundary::virtual_media_json, v.locator is archived only as:
json_kv(key: "resource", value: json_string(s: redfish_virtual_media_resource_path(locator: v.locator) as String))
But extdeps.bmc.redfish_virtual_media::RedfishVirtualMediaLocator contains a tagged parent and a separate media_id. The manager/system ID and media ID are NonEmptyStr, not sealed path segments. Its resource-path renderer concatenates them around /VirtualMedia/ without escaping or refusing embedded separators.
These two distinct modeled locators therefore produce the same resource string:
// A
RedfishVirtualMediaLocator {
parent: UnderManager { manager_id: "bmc" },
media_id: "slot/VirtualMedia/CD1",
}
// B
RedfishVirtualMediaLocator {
parent: UnderManager { manager_id: "bmc/VirtualMedia/slot" },
media_id: "CD1",
}
Both render:
/redfish/v1/Managers/bmc/VirtualMedia/slot/VirtualMedia/CD1
Hold the subject, times, other carriers and all other virtual-media fields constant. capture_from_world retains those distinct locator values in memory, but virtual_media_json gives them identical JSON values. Their cursor positions also agree, so the entire stored archive body and its digest agree. B observed over A's store is consequently accepted as ArchiveAlreadyHeld; the independent digest re-read cannot recover the lost parent-ID/media-ID distinction. This is identical input bytes to the hash, not a cryptographic-collision argument.
I am not asserting that a live controller has emitted these IDs. The issue is the currently admitted modeled payload: the IDs have only non-emptiness constraints, and neither capture nor policy assessment establishes a stricter segment domain. The archive's stated contract is preservation of every modeled field. JSON quoting repairs delimiter collisions inside values supplied to JSON; it cannot repair field boundaries already discarded by the upstream path renderer.
The current virtual-media discriminators keep the locator constant while varying connected_via and media_types, so they do not discriminate this remaining loss.
Bounded repair: serialize the locator structurally too: its parent arm, the raw manager/system ID in that arm, and the separate media ID. Reuse the existing JSON constructors; no new identity model or JSON serializer is needed. Alternatively, an established admission boundary could restrict the renderer's domain and prove the crossing injective, but that boundary is absent here and is unnecessary merely to preserve this record. Keep the resource path as a derived display only if a consumer actually needs it.
Add this locator A/B at the encoding boundary, preserving the unchanged-locator positive. The existing production archive/virtual-media pairing may carry the integration obligation; another large arrival-route fixture is not required. A phase-level version can follow the existing two-log control: different stored bytes/digests, and B over A's store must be written rather than held. Replacing the structural locator encoding with the old path-only projection must redden the discriminator.
Accepted repairs and scope
established and write_then_read_back now admit only the checked phase's callers. The archive constructor captures the supplied world itself rather than accepting an independently supplied captures list. The direct observation, store-write, readback and effect-leg mint restrictions are present, and the compiler probe requires blocking ConstructorCallAdmissionRefused separately at all eight named callees; an unrelated refusal or CensusNotRunnable cannot satisfy it. The public arrival step still joins the consumed identity's run and subject before entering the dry phase. I am not retaining the old unchecked receipt/write finding.
The original two-log counterexample is now a meaningful control: it asserts distinct bodies/digests, B written over A's store, and final log cursors 3 versus 2. connected_via and media_types are preserved and discriminated. Tagged choices, framed lists and payload-derived cursor positions are the right repair; the locator is the remaining nested flattening identified here.
The smaller route claim is non-vacuous
Yes: w_mtjade1_converges_the_prefix_through_its_dry_prior_life_archive still invokes converge_mtjade1_arrival_prefix, consumes the real Manager/FRU/SMBIOS-backed access and identity results, reaches the PriorLifeBoundary instance, requires ArchiveWritten, checks the consumed identity's run/subject, and checks both the archive-digest join and Present { value: "1" } from the one SEL record. It is not an empty-cursor equality. The losing-store sibling goes through the same route and requires incomplete rather than converged. The reported route-removal and cursor-ignores-payload mutations are appropriate discriminators. Richer field-fidelity populations belong to the archive's boundary witnesses; shrinking the integration input does not itself erase that obligation or require a budget increase.
KVM gaps and evidence
I checked the current floor_route_gap_expectation_chunk_29: its KVM subset matches the 13 identities and operations in the PR table, including the one DirWithTemplate case; each carries NoMockResponse. The adjacent SOL row is a separate identity. These are already tracked no-verdict gaps, not 13 semantic failures needing new expected-red admissions. No additional drop or duplicate RFM is required for encountering the same population.
Verified requested-SHA workflow 37409003854: floor, generated, emit-build, rust-unit-tests and aggregate witnesses all succeeded. The Hermetic batches, encoder-cost measurements and mutation executions remain author-run evidence; I inspected source and controls but did not run gunbc claims, compiler mutants or hardware actions. The locator counterexample is source-derived. The head remained unchanged and mergeable before submission. No live read/write, O1c-3 implementation, CI-lane restoration or larger route specimen is requested.
…not as rendered strings (review 5424040879) redfish_virtual_media_resource_path joins a manager/system ID and a media ID around separators the IDs may contain, so two distinct locators archived to one path. The locator is now its parent arm with that arm's ID plus the media ID; the image URI is its scheme plus locator. Swept every *_json encoder: no other field is joined into a string. Control: the review's two locators that render one path archive to distinct bytes and digests, and B over A's store is written, not held. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact requested head f073ddfb81b89b5a71f7afad2e4fc2cfe54f02a2, against DESIGN.md §§3, 4b, 5 and 6b. The remaining archive-fidelity finding in review 5424040879 is resolved. No remaining semantic blocker in this re-review.
The locator's structure reaches the stored bytes
gunbc.machine_intake_prior_life_boundary::virtual_media_json now calls locator_json rather than flattening the locator through redfish_virtual_media_resource_path. The encoded object preserves the parent arm (UnderManager or UnderSystem), that arm's raw manager/system ID, and the separate media_id. An embedded /VirtualMedia/ therefore remains inside its original JSON string; it cannot move the boundary between the two IDs. The previously demonstrated pair can no longer produce identical archive bodies through this projection.
The image URI also retains its two modeled components: uri_json records the scheme using the existing scheme-spelling authority and records the locator separately, inside an explicit Present/Absent choice. No new path-segment restriction or alternate JSON serializer has been introduced. The other payload encoders retain their record fields, tagged alternatives and framed populations; the cursor remains derived from the captured payload and encoded with it. This is a field-preservation argument at the encoding boundary, not a claim that a finite cryptographic digest is mathematically injective.
The new control exercises the archive's actual reuse decision
w_two_locators_that_render_one_resource_path_archive_distinctly holds the subject, other fields and timing constant and calls the checked dry_archive_prior_life entry for A, B over A's resulting store, and A again over its own store. It asserts that the old resource renderer conflates the locators, requires both different archive bytes and different digests, requires B to be written rather than held, and requires the unchanged A to remain ArchiveAlreadyHeld. Its helper requires established outcomes on both sides, so a refusal cannot satisfy the distinctness assertion.
That is the requested RED and positive at the product boundary, not merely a comparison of two designed JSON values. Restoring the path-only projection removes the distinction this claim asserts; the reported M14 failure is the appropriate single-mutation discriminator. The additional admitted caller is this Bool claim, not a carrier-returning helper.
Earlier accepted boundaries remain intact
The comparison with reviewed head 061696d5b28d44393261d9934758b35a6642ce5d limits this repair to the encoder changes and new witness/admission entry; the main merge also brings the separate guarantee-probe ordering change. The previously accepted receipt/write confinement, independent store readback, policy refusals, incomplete propagation and effect-leg checks are not loosened.
The one-SEL arrival pairing and its losing-store sibling are unchanged. The earlier ruling therefore stands: the integration is non-vacuous because it traverses the real arrival prefix, requires the archive write/receipt, and checks the payload-derived nonempty SEL cursor and archive join. Richer field-fidelity cases belong at the archive boundary; no larger arrival specimen or budget increase is required.
The previously reconciled 13 chunk_29 KVM outcomes remain tracked no-verdict route gaps, not newly introduced semantic reds. This correction neither supplies their missing routes nor requires a duplicate RFM or declared drop. BmcSecure apply/cutover, C8 and live archive realization remain outside this dry cut's completed scope.
Evidence
Verified requested-SHA workflow 37419410952: floor, generated, emit-build, rust-unit-tests and aggregate witnesses all completed successfully. The local Hermetic 10/10 archive result, 331-pass consumer roster with the same 13 gaps, and M14 execution remain author-run evidence; I inspected the source, exact-head comparison, control and CI results but did not execute gunbc claims, mutants or hardware actions. The branch still named the requested SHA immediately before submission. This approval does not authorize a live controller write or claim a live prior-life capture.
Managed-host cut O1c-2: the convergence fold's effectful half (dry)
Plan of record:
docs/plans/managed-host-untangle.md, Cut O, the fold capability table, row O1c-2. The first effectful consumer ofgunbc.fleet.convergence_foldis the PriorLifeBoundary archive. This PR brings an applied step with its own domain receipt, per-leg deadlines, and incomplete-versus-refused.Brief corrected against the plan. The brief placed "apply plus independent readback" on
BmcSecurein this cut. The plan givesBmcSecure, the authorization gate, the principal and the mutation lane to O1c-3. Putting BmcSecure's Apply into the fold here would have admitted an ungated credential-write arm. warm-crane-577 ruled (A): BmcSecure is untouched here, and no ungated write arm enters the fold.What lands
gunbc.fleet.convergence_fold: incomplete as its own armStepOutcome<R, C, I>gainsStepIncomplete { key, cause: I }. The domain's incompleteness type is a third parameter, so a cause meaning "nothing was done" cannot stand for "something was done and not read back".InstanceIncompletenever satisfies a precondition.RunIncomplete { ledger, at }is distinct fromRunStopped.ConvergedRunstays mintable only when every instance converged.gunbc.fleet.convergence_fold: effect legs and their deadlinesLegBudgetis sealed, holds aPositiveMillisecondduration, and is minted only for each domain's declaring function.LegDeadlineandLegCompletedWithinDeadlineare sealed.complete_effect_legjudges a leg on the observer clock. Its result is within the deadline, elapsed, finished-before-start, or unobserved.gunbc.machine_intake_prior_life_boundary(new): the carriersBaselineCursoris derived from the archive: the SEL final id, each log service's final entry, the account-event final entry, and the archive digest.ContentAddressedArtifactStore, then read back from the store by digest, independently of what the write returned.HostEffectDomainProjection. The write and readback are the domain's own, so C8 stays awaiting: the write is not reconciled throughhost_effect_apply.LogsArchivedWithBaselineCursorhas a constructor.LogsArchivedAndClearedhas none.gunbc.machine_intake_prior_life_boundary: policy rows (warm-crane-577's decision, reported upward for veto)extdeps.ampere.mt_collins_product_brief.subject,extdeps.ocp.mt_jade.subject), so neither row claims a controller family.std.artifact_storeArtifactStore, because that is an LRU cache provider that evicts, and an evidence archive must never evict.gunbc.bmc_modelBmcWorld:record_surfacesDateTime, RedfishLogService(newextdeps.bmc.redfish_telemetryRedfishLogService, citing LogService.v1_0_0), account-eventLogEntrys,VirtualMedia, andSensor.gunbc.machine_intake_arrival_converge:PriorLifeBoundary, which has its own census row.observer_clock_modeledadmittedtest.claim.machine_intake_bmc_secure_state_witnessobserver_at, which returned a sealedObserverClockInstant. That was a lesson-1 proxy.ScheduleInstantsrecord.gunbc.machine_intake_bmc_securedry_bmc_account_instantis an unsealed fn that takesEpochMsand returns a sealedObserverClockInstant. It is routed, not left open: Managed-host cut O1a-2: IPMI Set User Access as a second route request shape #13242 has landed, and bright-wolf-485 is sealing it in a separate PR.No hardware was touched, no live write was made, and no workflow mode or job changed. The
fleet-converge.ymlgenerator output equals the committed file body (details below).Side-chat review 5419442560: both blockers fixed
established,write_then_read_back,archive_of,observe_prior_life,dry_write_archive,read_back_archive,effect_leg_deadlineandcomplete_effect_legeach admit only their checked-path callers.test.claim.machine_intake_prior_life_boundary_forged_probe_witnessevery_minter_behind_the_checked_entry_refuses_an_outside_caller.archive_ofnow captures the world itself, so it no longer takes captures from the caller.extdeps.languages.json.emitserialize_json) over every modeled field: tagged enum arms, framed lists, andmedia_types/connected_viakept.w_two_log_populations_that_a_delimiter_join_conflated_archive_distinctlyis the review's counterexample. The bytes and digests are distinct, B is written rather than held over A's store, and the cursors are 3 and 2.w_virtual_media_connected_via_and_media_types_are_archivedconnected_via: FAIL.The 13 KVM Hermetic route gaps, reconciled by identity
These are no-verdict route gaps, not semantic reds. Each measured (claim, operation) pair joins exactly one row of
v2.workflow.floor_route_gapfloor_route_gap_expectation_chunk_29(groundNoMockResponse), 13 of 13 both ways. No rung drop, failure-mode row or expected-red enrolment is added.test.claim.machine_intake.mtcollins1_kvm_observer_protocol_wet_witness.…a_busy_viewer_slot_refuses_the_observer_and_the_handoffa_connection_lost_mid_boot_is_reported_and_no_still_is_claimed_after_ita_held_observer_is_admitted_and_its_triggered_still_is_hash_bounda_launch_that_cannot_publish_its_pid_stops_its_childan_owned_process_is_released_and_observed_gonean_unreadable_canvas_is_acquisition_failed_with_the_browsers_wordsan_unreadable_process_state_never_skips_the_kill_of_an_unpublished_childa_record_naming_another_process_is_foreign_and_not_releaseda_relative_observer_directory_is_resolved_oncea_root_page_that_navigates_cannot_destroy_the_logina_term_ignoring_child_with_an_unpublished_record_is_observed_stoppeda_transport_that_exits_at_once_is_not_servinga_viewer_without_its_feature_list_never_opens_kvmHermetic results (
claim_batch --hermetic,--functionsregenerated from each file)Run locally with the release
claim_batchbuilt from this branch's base compiler sources. The merge of main since then touched nosrc/v1orCargo.lock. One process ran all 22 entry groups, 322 witnesses:b8497f0b85)8d39b30a73, so they are not caused by this PRBuildBuddy run at the exact head: see the comment below.
Terminal receipt
1. Consumer witnesses, run by name. The roster is every test module that directly imports a module this PR changes (
bmc_model,bmc_dry_realization,bmc_megarac_web_adapter,bmc_rotation_route,bmc_secure,mtcollins1_boot_dry_realization,clock_read,host_convergence_census,convergence_fold,arrival_converge,redfish_telemetry,prior_life_boundary). It was run withclaim_batch --hermetic, with--functionsregenerated from each file. Results are in the table below.2. Same-path REDs. Each mutation was applied alone to the measured head, and only the claims named here were run:
arrival_step_of_phasePriorLifeBoundary => none)w_mtjade1_converges_the_prefix_through_its_dry_prior_life_archiveFAILw_only_the_sel_final_record_with_the_other_carriers_absent_is_not_established,w_one_unmodeled_carrier_is_a_typed_gap_that_refusesFAILRunIncompletew_a_lost_archive_write_leaves_the_run_incomplete_at_prior_life_boundary,w_an_incomplete_instance_satisfies_no_dependent_and_the_run_is_incompleteFAILw_a_lost_corrupted_or_late_write_is_incomplete_not_refused,w_a_lost_archive_write_leaves_the_run_incomplete_at_prior_life_boundaryFAILw_a_budget_that_differs_only_in_its_duration_flips_completed_to_elapsed,w_a_lost_corrupted_or_late_write_is_incomplete_not_refusedFAILw_a_policy_refusal_writes_nothingFAILw_prior_life_boundary_refuses_an_identity_receipt_from_another_runFAILw_an_archive_already_held_is_a_noop_and_is_not_written_twiceFAILw_the_baseline_cursor_is_derived_from_the_archive_it_was_read_fromFAILobserver_atproxy is restoredconstructor call admission refused: 'gunbc.clock_read.observer_clock_modeled' refuses call from '…observer_at'The seals' outside-call and literal REDs are enrolled in
test.claim.machine_intake_prior_life_boundary_forged_probe_witness, covering:LegBudget,leg_budget,LegDeadline,LegCompletedWithinDeadlineBaselineCursor,PriorLifeArchive,PriorLifeArchivePlan,ArchiveWriteReceipt,ArchiveReadBack,PriorLifeBoundaryEstablisheddry_archive_prior_life,dry_prior_life_instantIt also has a class-scoped clean control. All 4 pass.
3. Corpus sweep.
git grepat head across.dag,.rs,.yml,docs/andartifacts/for the deleted and renamed symbols returns 0 hits for each:observer_at,w_mtjade1_converges_both_read_only_phases_from_its_committed_captures,w_the_roster_is_the_two_phase_prefix_of_the_authority,w_the_real_two_step_plan_is_admitted. No module was deleted.4. No aliases. Nothing re-exports, wraps or renames through a removed root.
Lesson 3 (trial merge): main was merged at
bc6efca7f7. None of the.dagfiles main changed since base constructsBmcWorld, namesStepOutcome</ConvergenceRunVerdict<, or callsconverge_arrival_prefix/converge_mtjade1_arrival_prefix.fleet-converge.yml:gunbc.fleet_converge_workflowexpected_fleet_converge_ymlat head was diffed against the committed file. The body is identical. The only differences are the two# Generated byheader lines that the artifact layer prepends.🤖 Generated with Claude Code