Repository navigation
map_get fork: the declared projection renames to map_get_checked - #13460
gunbai-bot[bot] wants to merge 20 commits into
Conversation
…red on main, 2026-10-05 19:11Z)
…hecked The spelling map_get named two contracts: the v2.std.collection declared projection (Outcome<Optional<V>>) and the interpreter primitive (Optional<V>). One spelling, two meanings - RFM one_spelling_names_a_primitive_and_a_declaration_with_different_contracts. The authoritative meaning is the primitive's (interpreter:14297 registry, outcome_accepted(map_lookup(...))). The declared projection is renamed to map_get_checked at its owner (src/v2/std/collection.dag) and every consumer follows: imports, qualified calls, the primitive-projection row (decl_name only; the primitive slug primitive.map_get keeps its spelling), the emitted probe strings, and the synthesized declaration_index.rs test fixture. The v1 mechanism never keyed on the declared spelling. Reds: w_projection_census_declares_no_divergent_shared_spelling (fails while any row's decl_name equals its primitive's runtime name at DivergentProjection fidelity); positive control keeps the outcome-lookup projection under its own name. RFM receipt updated, row kept.
required-regen on the merged tree (origin/main@39d1e2e6db + d540486): self-compile clean, adjudicated 163, declared_divergent=1 - the projection row's decl_name follows the map_get_checked rename. compiler_tests.rs and all other mirrors already equal.
…d_target's comment states the truth declaration_index.rs: the authored-membership control still asserted FuncSigAmbiguous over builtin:map_get + declared:map_get_checked -- a collision the rename made unrepresentable (the registry keys the primitive as map_get; the lookup string no longer mints a builtin candidate). The omitted arm is rewritten as a dissolution control checked by its exact identity shape: the bare map_get spelling must have no declared candidate and never go ambiguous; a re-widening of the fork flips it red again (DESIGN 4b: the probe does not retire, it becomes a regression control). build_target.dag: the mechanically renamed comment claimed two declarations answer to map_get_checked in the present tense -- false after the repair. Rewritten: the historical account of the map_get fork (why lookup exists) with the dissolution recorded.
briansrls
left a comment
There was a problem hiding this comment.
Approved at a1d0d22.
I audited the rename at contract grain rather than treating it as a textual sweep.
-
Every executable call renamed to
map_get_checkedwas already a consumer of the declaredOutcome<Optional<V>>projection. The sites either matchAccepted/Rejecteddirectly or feed the value through an Outcome combinator before matching the innerPresent/Absent. None of the renamed calls used the primitive's directOptional<V>contract. The declaration body itself is unchanged apart from the name: it still projects totalmap_lookupthroughoutcome_accepted. -
Primitive consumers were correctly left on
map_get. Representative production and witness sites use the direct Optional shape (Present/Absent, or return the bare lookup asOptional) and remain untouched. The original transitive incident source is deliberately unchanged: after the declared projection vacates the spelling, its baremap_getresolves without ambiguity to the primitive route whose contract its arms already expect. -
Probe strings moved only when they assert the declared call target. Their expected target is now
crate::v2_std_collection::map_get_checked, while they explicitly rejectv1_rt::map_get; primitive-route specimens retainmap_get. -
The hand-written v1 change is fixture-only.
declaration_index.rschanges only inside#[cfg(test)] mod import_binding_authority_tests: the synthetic declared candidate is renamed, and the permanent regression arm requires baremap_getnever to become ambiguous again. No production declaration-index mechanism changes. The only other v1 file is the generatedstd_primitive_projection.rsmirror, whose sole change is the declared projection name; the primitive identity and divergent-contract record remain intact. -
The repair controls are discriminating: the projection roster refuses any divergent projection that reuses its primitive's runtime name, a positive control retains the
primitive.map_get -> v2.std.collection::map_get_checkedprojection fact, and the original incident source now requires zero ambiguous references.
All five exact-head jobs passed. No blockers.
…get_checked rename and take std.optional's re-homing; the emitted_crate_workspace import now reads std.optional and names map_get_checked
…get_checked rename and take std.optional's re-homing; 03_name_resolve and emitted_crate_workspace read std.optional and name map_get_checked
required-regen re-adjudicated clean on the merged tree: lib.rs declares pub mod std_optional and its mirror arrives with the merge; no other surface changed.
#13388 re-homed v2.std.optional to std.optional; the synthesized probe module in the emission-identity witness still imported the defunct path, so the witness resolved against a probe that could not load. The probe now reads std.optional and the pinned emitted target crate::v2_std_collection::map_get_checked( is unchanged.
…et_checked The same synthesized-probe pattern as the emission-identity witness: the qualified-call probe still imported the defunct v2.std.optional and the pre-rename bare declaration, so it could not load and pinned nothing. Now it reads std.optional and names map_get_checked; the asserted emitted target crate::v2_std_collection::map_get_checked( follows.
The stash carrying the self_host probe fix also held #13412's in-flight confinement patches for version/semver.dag and git/versioning.dag; those belong on the semver-precedence branch, not this PR. This restores both files to their merged-tree state; only the self_host probe re-point remains.
An earlier stash pop left <<<<<<< Updated upstream / >>>>>>> Stashed changes inside the compile_dag_rust_emit_check arguments (RFM class a_verification_reads_its_own_label_not_its_output, committed this time). The block now reads std.optional and names map_get_checked; the asserted emitted target crate::v2_std_collection::map_get_checked( is unchanged.
|
Both findings addressed in 61849f0:
The class's enrolled executing evidence therefore lives in the .dag tree, against real data: — sent from vivid-lynx-377 |
…l after #13388 The probes at :60, :699, :754 still imported v2.std.optional (defunct since the Optional de-fork); their compile.frontend refused, so three witnesses red. Same class as the :281 probe re-point review 77124 asked for. Verified attribution for the one remaining red in this entry (w_depth_one_shared_field_refutation_stays_shape_guarded): it fails on origin/main's own tree identically (exit=1 FAIL=1 at main), so it is main-carried latent debt, untouched here.
…13388) Fresh emission at this head no longer contains a v2.std.optional module (re-homed to std.optional by #13388), so the registration is stale and required-regen refuses. Main's own lib.rs carries the same stale registration; main's pushes never re-run required-regen, so it surfaces only at a PR head. Byte-exact inverse of the drift line CI reported at 51aefcc.
…/vivid-lynx-377-map-get-fork
… state the seam arm's reach honestly The seam arm's comment claimed a future re-widening would flip it red from inside the synthetic fixture — false: parent_closure_callable_candidates takes the declared identity's decl_name from the LOOKUP KEY (v1_compiler_infer_sigs.rs:339), the compiled roster's only DivergentProjection row answers to (v2.std.collection, map_get_checked) (std_primitive_projection.rs:423-425), and the registry keys the primitive as map_get (v1_compiler_infer_method.rs:719), so no lookup name can carry both a rival declaration and a builtin co-candidate. That absence is the repair landing, not a hole. The comment now says so. The mechanism's executing evidence stays enrolled (DESIGN 4b(4)): declared_candidate_rivals_the_builtin_discriminates_by_row_fidelity checks the predicate against the compiled roster's actual rows — the divergent declaration must rival, a modeled projection must not, an unprojected declaration must not, a builtin is never a rival to itself. cargo test -p v1-compiler --lib declaration_index: 8 passed 0 failed (both this and the seam arm).
|
Review 77428, finding 1 — addressed at d3b5791. You are right that the comment was false and that the rival-join composition had lost its executing red; the fix splits along the seam the code actually draws. Why the suggested fixture cannot mint the rival (verified against this head's code): parent_closure_callable_candidates takes the declared identity's decl_name from the LOOKUP KEY, not from sig.name (v1_compiler_infer_sigs.rs:339), so a fixture that declares What is now enrolled (d3b5791):
The composition red (builtin joins rival → FuncSigAmbiguous) is unrepresentable at this seam without manufacturing a shared production spelling, which is exactly what this PR exists to remove; the predicate-level control plus the census wall are the honest enrolled evidence. If you read the composition as still requiring a seam-level red, the mechanism that would carry it is a fixture-local roster injection, which the stage0 crate does not have — flag it and I'll take that up as its own change rather than widen this one. |
briansrls
left a comment
There was a problem hiding this comment.
Approved at d3b5791c65eba1852b5bff68d54f12a067cece31.
The delta is coherent and remains fixture-only on the v1 side.
- The seam comment now states the actual reach.
parent_closure_callable_candidatesderives a declared identity'sdecl_namefrom the lookup key. The compiled projection roster's divergent declaration is(v2.std.collection, map_get_checked), while the builtin registry key ismap_get. Therefore no current lookup spelling can mint both that divergent declared candidate and the builtin candidate. Recreating the old composition red inside this seam would require either a false shared production spelling or injectable/fabricated roster state; the absence is the rename's result, not missing coverage. - The new
declared_candidate_rivals_the_builtin_discriminates_by_row_fidelitytest invokes the production predicate, whose implementation consults the generatedprimitive_projection_row_for_declaration. It pins the current divergent row true, the current modeledempty_maprow false, an unprojected declaration false, and a builtin candidate false. Dropping the divergent specimen or changing its fidelity makes the positive arm fail. - Commit
d3b5791c65changes onlysrc/v1/stage0/src/declaration_index.rs. The other post-approval movement is main integration, including thestd.optionalre-home/re-point; the current PR file set contains no unrelated generated-registration residue. - All five exact-head jobs in run
37574044032passed.
Nonblocking precision: the comment's phrase that any predicate that stops consulting the roster must fail is stronger than this finite black-box control—a future implementation hard-coded to the current divergent identity could satisfy it. The test does establish the current real-row/fidelity behavior and the roster specimen's continued presence, which is sufficient for this delta; a future genericity proof could fold the compiled roster itself.
…d; repair dual-dispatch optional equality
Merge brings in main's new consumer of the declared map_get:
src/v2/workflow/floor_pure_producer_share.dag imports map_get from
v2.std.collection and consumes the Outcome contract (five call sites
match Accepted { value: .. } / Rejected), so it renames to
map_get_checked with the declaration. Consumer census on the merged
tree finds no other importer of the declared spelling.
dag/test/claim/map_lookup_dual_dispatch_witness_test.dag (new on main)
compared the dual-dispatch lookups' Optional results against required
values — the #13179 T? == T refusal, same silent class as
os_install_actuator_selection_witness_test. Its own lookup test already
documents the discriminating form: 'Matching Present is still the
discriminating form'. The method and index tests now match on
Present/Absent instead of comparing raw.
Local parse-check of the merged tree at the floor_pure_producer_share
entry: 0 blocking diagnostics, 109 files emitted.
briansrls
left a comment
There was a problem hiding this comment.
Approved at 0edf0e5. Delta from approved d3b5791 is confined to the origin/main merge plus the two-file repair commit. floor_pure_producer_share's five new declared-route calls all move with the Outcome<Optional> authority to map_get_checked; outer Rejected/Accepted handling remains explicit through share_map_lookup_causes and the value readers still distinguish Accepted Present, Accepted Absent, and Rejected. map_lookup_dual_dispatch_witness rewrites only the two optional-vs-required comparisons to the already-authoritative Present/Absent match form; it avoids the constructed-Present equality realization defect and preserves the exact hit assertions. No other post-approval PR-owned change found. Exact-head run 37740552960 is green.
* dispatch-actuator witness: import the lineage, alignment and ticket names #13622's specimen uses Review 78285 on #13622: the supplied-specimen claims call lineage_walk, lineage_is_rooted and alignment_chain and build TicketLine/TicketFields/NodeParent/AdmittedRoot/RoadmapNodeIdentity without importing them. They resolved only through the flat bare-name tier DESIGN schedules for removal, so they would go red when it is cut. Import each from its declaring module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert "Merge #13548 (session/sharp-deer-755-unimported-type-import-migrate) into integration/sharp-raven-357" This reverts commit 1a22abd, reversing changes made to a04255a. * native_emission_controls: repair integration union (close variant_literal_application_cases, one roster, one composition over all 17 case groups) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Exclude #13604 from integration/eager-gull-22: WIP, open REQUEST_CHANGES (review 78326) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * docs/design-rung-drops.md: regenerate through tools.docs_projection_gate regen after the #13569 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * grammar: import int_to_decimal_string from std.integer (#13436 moved it; #13379's binding-power row still named v2.std.integer integer_int_to_decimal_string) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: mtcollins1 runner: boot leg, runner image medium + runner-host-up termin * Realize reviewed kernel dependencies through guarded host maintenance * Rewrite the cross-module record-field pin to the refusal it named as its trigger. Infer now refuses `n: true` against `RcfFar` declared in another module; keeping the counted-Undecidable pin would be a meaning fork of the same claim name. Co-authored-by: Cursor <cursoragent@cursor.com> * Close the post-main census: drop the Map interpolation hole, concat the spatial cast. Merging main reintroduced one implicit stringify (Map Display in the canonical-order witness) and left the spatial_dimension `{o as String}` template as a v1 span mismatch. Named Int/Nat/Symbol routes stay; the Map hole is deleted rather than given a fourth renderer. Co-authored-by: Cursor <cursoragent@cursor.com> * Regenerate fleet-converge.yml via generated_artifact_gate main_wet Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Remove scratch witness scripts committed by the close-out flush (review 78354) The wind-down flush committed untracked local files (.runwit*.sh, .probe2.sh, .wit/) as 32dcf74. They are local receipt scaffolding, not part of the boot leg. This restores the tree to 80c24b3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * cax onboard: enumerate the closed-coproduct arms the floor's non-fold residue check refused approved_grant_policy, plan_against_policy and provider_controlled_host matched closed coproducts with a wildcard arm; each arm is now explicit, so a new variant refuses at compile rather than being absorbed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * v1 closeout: open PR accounting Every open PR, with its owning lane and its disposition in the mega branch. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: add the side-chat dispositions and wave 2 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 emit_rust mirror for the integrated authorities (first_generation_equal=true, 0 installs on pass 2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: bold-bee and qwen dispositions Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: outstanding work, closed PRs, and a re-sweep of all 162 open PRs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: #13607, swift-bat-828 branches Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration/silent-lark-156: regenerate generated artifacts after merging #13472 and #13610 Produced by main_wet + claim_executor --required-regen on BuildBuddy at fd4421d; second regen round installed nothing (fixed point). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: silent-lark, gentle-dove, royal-moth, neat-boar, nimble-heron, valiant-crab handoffs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Second-type OpenRouter Retry-After and quota term (review 78356) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: lively-ram and silent-lark handoffs, #13460 folded, #13108 and #13330 dispositions Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md and the v1_compiler_emit_rust stage0 mirror for the integrated tree Generated through docs_projection_gate regen and claim_executor --required-regen on srv1; round 2 reports first_generation_equal=true (a fixed point). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: #13488, #13574, #13475, #13634 reviews; #13648 closed; archive-flush residue Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * provisional: gentle-dove-36 mirrors for conflicted generated files (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Revert "Merge #13574 into integration/gentle-dove-36" This reverts commit 32720e2, reversing changes made to eee50a4. * provisional: v1_rt.rs from silent-lark-156 (carries host_budget_darwin_physical; seed bootstrap, regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * provisional: v1_rt.rs = v1-closeout + silent-lark-156 delta (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: sharp-raven report, #13265, #13574 revert decision Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * provisional: append rt_host_budget (HostBudgetJoin*) to v1_rt.rs (seed bootstrap; regen replaces) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Fix stderr-capture tests so they hit real routes, not decoys. Delete the rustc program that returned Err before spawn without compiling emit_shell_stderr_policy_binding; absent policy is already refused at the emit diagnostic wall. Drive Complete limits from the live host-budget join and keep drain specimens on the emit_rust authority strings. Co-authored-by: Cursor <cursoragent@cursor.com> * fabric_quota: re-attach the window-start comment to quota_window_start (review 78371) checked_second had been inserted between the comment and the function it documents. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Required CI: withdraw the four v1-judged lanes; the gate is emit-build alone (operator ruling 2026-10-09) The operator's v1 withdrawal: v1 is no longer a validation authority, and the one use left to the seed is emitting v2. gunbc.compiler_gate_workflow drops `floor`, `generated`, `rust-unit-tests` and `seed`; the `witnesses` aggregate reads the one remaining lane, `emit-build`, through the same folded roster (one row). The GateArmSkippedOnPullRequest arm leaves with its only inhabitant. The loss is one declared drop, gunbc.rung_drop v1_required_lanes_withdrawn, stated member by member (witnesses, stage0 mirrors and every generated artifact, lint, v1 unit tests, module resolution outside the two emitted closures, the downstream consumers), with a trigger that names the capability: a binary built from an emission of v2 judging that population on the required path. rust_unit_tests_off_pull_requests is Superseded (its lane runs nowhere; trigger did not fire; the new row holds the loss). gunbc.required_ci_contract_epoch moves to 2026-10-09.1: the name `witnesses` now carries a materially different contract. Consumers repaired rather than left dangling: the lane-resolution census roster (the census now does not hold by design and is the instrument that re-derives the drop's module population), DESIGN section 3's typed required-gate reference (gunbc.documentary_refs, now emitted_subject_build_rows), the Building & checks rows, the onboarding path's run-witnesses step, five recurring_failure_mode evidence rows that cited deleted declarations, and the two gate witness files (the blocking set is asserted as exactly emit-build; a new RED asserts the four withdrawn variables reach neither gate surface). Projections regenerated by tools.generated_artifact_gate main_wet (the run peaked at 15.8 GB RSS, against the 7.55 GiB that module's own note cites for 2026-08-31): witnesses.yml, DESIGN.md, docs/design-rung-drops.md, docs/onboarding.md; every other rostered artifact came out byte-identical. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Drop process-global budget env from stderr-capture tests. review 78373: planting Complete limits through GUNBC_MEMORY_BUDGET_BYTES leaked into parallel tests and did not inhabit the emit bind. Claim the drain strings only; leave the host-budget join uncovered. Co-authored-by: Cursor <cursoragent@cursor.com> * regen round 0: stage0 mirrors from claim_executor --required-regen (supersedes provisional splices) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * provisional: re-append rt_host_budget to v1_rt.rs (round-0 regen emitted v1_rt.rs without it; seed bootstrap) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * regen round 2: stage0 mirrors (v1_rt.rs now emitted with rt_host_budget; hand-appended lines gone) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate generated artifacts for integration/eager-gull-22 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * required_ci_phase_roster: import std.optional (v2.std.optional moved by #13388; stale import from #13225) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v1 closeout accounting: all lanes reported; remaining merge plan; closed auto-opened PRs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert #13123 (admit_callers enforcement: mega's AdmitCallersEdge is the one enforcer) * v1 closeout accounting: #13516 folded, #13212 dispositioned; every lane reported Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop #13545 transcribed-count red chunk (counts derive from ci_runner_sudo_binaries); retarget caller-admission real-route evidence to exact counts Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * v1 closeout accounting: eager-gull review outcomes, #13608 newer head, updated plan Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop the seed-growth citation of the deleted absent-policy decoy. review 78381: hand_authored_declarations still named emitted_absent_policy_refuses_before_spawn after that test was removed. Absent policy stays cited as capture_channels_without_stderr_capture_input_refuse_the_union. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert #13586 (receipt-only, excluded by operator review) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Revert #13453 (base-compiler/floor protocol; excluded by operator review): seed Rust, workflow steps and the script-row refusal API go with it Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * WIP: one required job, fresh products, memory envelope, heal-publish deletion (pre-merge, projections not yet regenerated) * stage0 mirrors: restore generated mirrors to the mega branch's coherent set pending one regen round Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * floor_route_gap: give the belt exit-drain expectations their own chunk_43 Two folded PRs (#13442's seeded_filler rows and #13125's belt exit-drain rows) each added floor_route_gap_expectation_chunk_42. The second silently replaced the first and the native emitter refused (duplicate declaration). The exit-drain chunk becomes chunk_43 and joins the roster, so both expectation sets are read. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * live_deploy: reconcile #13599 with #13583's directory authority #13583 made owned directories the single directory authority (directory demands; host_directories) and removed the directory kinds from the ensured steps and the instance parameter from deployment_ensured_steps. #13599, folded alongside it, still called deployment_ensured_steps(instance:, target:) and its witness matched on the deleted step kinds. The call passes target only, and the lab-vs-production fabric-store claim now counts fabric_storage_store_directories demands in deployment_directory_demands. Same claim, read through the surviving authority. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * roadmap_task_record: JSON codec for a runtime RoadmapNode (piece 1, uncompiled draft) * roadmap_task_record witness * roadmap_task_store: chain-partition roster over the fabric state binding, with wet witness (draft) * roadmap_task_record: parent and centering required on the wire; drop nested optionals Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * managed_host: a superseded rung drop is not a standing citation drop_is_standing_citation matched RungDropStanding with Retired and Standing only. Superseded has existed since the 2026-10-06 supersession, and the closeout's seed refuses the non-exhaustive match, which reaches every closure through managed_host (generated_artifact_gate included). A superseded drop no longer stands, so it is not a citation, the same as Retired. (Found by smart-gull-336.) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: federation retired-path row below imports; floor_demand pinned envelope rows; managed_host Superseded arm (pre-regen) * Headless Claude dispatch: print argv, systemd unit, stream-json projection. When the harness has no spark, ExecutorDefault can admit Claude if custody is present; events stay in the belt's Codex envelope. Credential converge on srv1 remains an operator decision. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API 6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API 6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> (cherry picked from commit 94464b1) * roadmap_task_record: balance ticket decode braces Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Address review 78387: one Claude event mapping, explicit executor, transmit effort. parse_codex_jsonl now classifies bounded Claude stream-json via claude_code_line_codex_kind; jq only bounds those lines. ExecutorDefault stays a harness refusal. Print argv carries --effort. Co-authored-by: Cursor <cursoragent@cursor.com> * v2 compiler: reconcile #13438's precedence climbing with #13582 and #12942 Two merge-born references to deleted code, found by emit-build on #13641: - 02_parse: #13438's infix stamp still wrote ParseProvenanceState.frame / FrameMinted, which #13582 deleted with the packrat memo. The write goes; the sibling stamps already carry none. - body_lowering_fold: #12942's sealed body_lower_fold_raw kept the pre-#13438 pipe-tower test (body_lower_is_pipe_tower_root / body_lower_tower_pipes_into_fold), which #13438 deleted. It now uses #13438's replacement predicate, body_lower_application_pipes_into_fold, and keeps #12942's sealed outcome. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fleet_converge_workflow: drop MtCollins1UiBundleObserve from the mode list #13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list now resolves to a declared variant. (Found by smart-gull-336.) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: trip is a ByteSize derived from the slot envelope (review 78388 item 3); witness claim the_trip_sits_inside_the_slot_envelope * Address review 78389: emit tmux event pipe only for tmux containers. Claude and harness systemd spawn no longer derive readiness from tee/pipe emission or refuse as tmux-event-pipe-emit. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: two stale references from folded deletions - first_element_of_a_list_has_three_spellings cited v2.std.optional Optional; the module is std.optional (#13388's move). - authorization_pattern_selection_witness imported PastedOperatorToken, which #13568 removed with the pasted-token refusal; the import was unused. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerated projections for the one-job gate, on the merged closeout tree One main_wet of tools.generated_artifact_gate over this branch merged with integration/v1-closeout a925452 (regen 632 s, verify 693 s, both exit 0, on srv1 under capped MemorySwapMax=0 scopes), nine artifacts: - witnesses.yml: both subject steps carry GUNBC_BIND_MEMORY_CGROUP_BYTES (the derived trip, 20 GiB) and the failure notice carries the envelope lines (what 137 means, no larger runner and no retry, the MEMORY RECEIPT). - DESIGN.md, docs/design-rung-drops.md: the CI row and the drop roster. - .gitattributes: the deleted heal-publish.yml leaves the generated-artifact merge list. - fleet-converge.yml: the closeout's authority fix projected. - tools/fabric_ci_fci1_bounded_execution_context.env: the fci1 context follows the slot (22/21 GiB). - provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: a 22 GiB slot fits more slots per host than a 26 GiB one, so the derived rosters grow (srv1 gains srv1-10 and srv1-11). Desired state; applying it is the converge effect. The witness batch on the same tree: 16 files, green except the two latent reds already recorded in the PR (fci1_bounded_execution_context: a stale envelope-basis expectation; heal_publication_boundary: 23/34). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Enrol roadmap_task_store wet witness on the local-repo wet lane, as the allocation seam witness is Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Land the v2 cutover program as designed roadmap entries: 11 nodes, native_obligation_population plan, edges, RED acceptance witnesses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md belt_liveness_publication_answers_unconsumed Ledger-Rows-Repaired: docs/design-rung-drops.md bmc_secure_apply_converge_new_witness_eval_step_cost Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci Ledger-Rows-Repaired: docs/design-rung-drops.md fixture_closure_union_unmodeled_stderr_capture Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer Ledger-Rows-Repaired: docs/design-rung-drops.md kvm_observer_protocol_wet_witnesses_deleted_with_the_observer Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost Heal-Candidate-Run: 38000315997 * closeout: regenerate stage0 mirrors and workflows from the folded tree One emission round (operator ruling 2026-10-04) on srv1 at a925452: claim_executor --required-regen, then generated_artifact_gate main_wet. Then on the regenerated tree: seed build OK, gunbc test //gunbc/instruments:v2-native-cli exit 0, //gunbc/instruments:self-host exit 0. Settles the files the folds left provisional (fleet-converge.yml, the std_* and v1_compiler_* mirrors). docs/design-rung-drops.md was already regenerated by CI auto-heal (17a309c). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: option B -- subject steps require the slot envelope; per-step trip withheld by the declared drop native_step_trip_awaits_fleet_job_cgroup; slot-grain receipt in gunbc test; seed-growth receipt (pre-regen) * Enrol roadmap_task_store wet witness in floor_route_gap and the local-repo wet terminal, as the allocation seam witness is Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate ROADMAP.md, docs/plans and .gitattributes for the cutover rows; repair updated(...) wrapping Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Describe the envelope as slot-grain (option B) in witnesses-one-required-job; regenerate projections on the merged head Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Type the cutover receipt readings (closed kinds, ByteSize) and make the peak-above-trip control compare against the slot trip Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Subject steps require the slot envelope; the per-step trip waits on a fleet fact; the envelope decision is a .dag fold the seed mirrors The first required run that passed GUNBC_BIND_MEMORY_CGROUP_BYTES (38002497388 on a4b8f78) refused in four seconds: MemoryCgroupBindRefused, the cgroup2 tree is not writable. memory_governor apply_memory_cgroup_bind creates its leaf at the cgroup ROOT (a container-root design; the bind had never been requested on the fleet) and a fleet job runs as the setpriv'd job user under a root unit, so no job process can create the bound. The operator approved the slot-grain arm (escalation 2026-10-09). gunbc.memory_envelope (new) owns the decision and the verdict as folds over supplied inputs -- the sibling of gunbc.memory_cgroup_binding -- and test.claim.memory_envelope_witness_test reaches every arm by supplied value, including the RED an inline decision could not: a slot requirement over a process no numeric memory.max binds REFUSES (MemoryEnvelopeAbsent) rather than running as bounded. The seed mirrors it arm for arm with unit tests; the shells resolve the bounding cgroup through binding_cap_cgroup_dir (never the peak locator), read memory.swap.max/.current/.peak (modeled in extdeps.linux.cgroup_v2_memory) before and after the producer, print a slot-grain MEMORY RECEIPT with event deltas and the peak labelled by whether it rose, and refuse the run on any OOM kill or swap. gunbc.emitted_subject_build_gate carries two envelope inputs and ONE decision over them, native_step_memory_inputs(ownership): every subject step REQUIRES the slot envelope (GUNBC_MEMORY_ENVELOPE_REQUIRED=slot, the projection of EnvelopeSlotRequired) and the bind input at the derived trip is withheld while gunbc.runner_slot_desired gunbc_runner_slot_job_cgroup_ownership is JobOwnsNoBoundedCgroup. That is a fleet fact, not a rung drop -- nothing on the required path ever held the trip -- so the climb is rostered as gunbc.guarantee_stall native_step_trip_awaits_fleet_job_cgroup_stall (grounding: unit delegation with DelegateSubgroup=, a per-job cgroup staged by the root JIT wrapper, the governor's already-bound arm). The workflow and the failure notice consume the fact; the witness exercises both arms by supplied value, reads the live row, and asserts the bind KEY is absent. The slot wall follows the ruling too: gunbc.runner_slot_allocation gunbc_runner_slot_allocation_wall_holds drops its three floor conjuncts (a slot sized to a tenant that no longer runs in it) and requires MemorySwapMax == 0 instead of a swap above the maximum; the floor-fit drop slot_row_pinned_below_demonstrated_demand_unrefused is Superseded with v1_required_lanes_withdrawn as its loss holder; the slot witness re-pins the row to 22/21/0 and its width alarms to the smaller slot's derivation (srv1 12, srv3/srv4 21). The slot's demand oracle from here is the first cold required run's MEMORY RECEIPT, a declared frontier. The trip stays a ByteSize derived from the slot (review 78388 item 3). The seed growth is receipted as gunbc.memory_envelope_receipt_seed_growth (review 78391). The design document's CI row and the slot row's note say the same. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * emit_rust: locate module via ModuleIndex.by_name; is_known_variant reads carried variant_to_enum (port of #13608 23f2d08, 8ff94ca; mirrors pending regen) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * decimal_digit_of_units: construct the units digit via the successor table; no D9 default for out-of-range Int * closeout: bind variant_to_enum correctly at three #13665 call sites import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate ROADMAP.md on the merged head; re-cite the envelope fact and stall Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Take sold Group B (srv9-srv12) out of everything that reaches hardware; declare fixture residue as a rung drop Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Supply sold Group B (srv9-srv12) as in-witness fixture population; production rosters stay empty Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that discriminated on the Group B population (commitment standings, admissibility, rail rows, topology membership, reach labels) read nothing. spark_host_commitment_witness now folds the production placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Regenerate std_integer stage0 mirror (remote required-regen candidate) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * closeout: revert #13662's fold (operator decision 2026-10-10) #13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Recut to five durable outcomes: cold-run envelope receipt rename, acceptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * roadmap: split the event carrier's directory demand into a leaf module gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status -> host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories -> roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory; the carrier, the directory list and the owned-directory witness import it from there. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Address review 78405: delete the never-red frontier-count decoration; eligibility and disjointness controls run over supplied members Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * closeout: five merge-born refusals that main_wet found - managed_host: HostnameAllocation no longer carries canonical_hostname; read it through allocated_canonical_hostname (hostname_allocation's name scheme, #13625). - host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own account lookup does: the standing still decides the BMC route. - mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation. - fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of #13607 and #13625). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Make fleet-converge branch-agnostic and parseable. GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha. Co-authored-by: Cursor <cursoragent@cursor.com> * Name the branch-dispatch ruling; type malformed expected_revision. Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose. Co-authored-by: Cursor <cursoragent@cursor.com> * Declare the named-revision and deploy-branch drop. Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger. Co-authored-by: Cursor <cursoragent@cursor.com> * Recut #13660: restore privileged WIF to reviewed-main equality. A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop leftover census conflict markers and project the named-revision drop. The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix OidcClaimPin inhabitance and the privileged-pin wording fork. branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation. Co-authored-by: Cursor <cursoragent@cursor.com> * Split presented OIDC claims from pins; printer session-branch is a red. Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin. Co-authored-by: Cursor <cursoragent@cursor.com> * Regenerate fleet-converge.yml (21 inputs) and pin dashboard-deploy to main. GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: revert #13663's fold (operator ruling: #13662 and #13663 stay outside the closeout) deep-cat-540 recuts it onto main after #13641. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Omit Spark dispatch when the administrator roster is empty. Review 78408: regeneration had folded a sold-out Spark roster into target options: [] while spark_* modes stayed selectable. Restoring srv5-srv12 would invent enrolled hosts. Emission now drops the target input and spark_* mode options, and refuses any remaining empty InputChoice. Co-authored-by: Cursor <cursoragent@cursor.com> * Treat srv1-production environment protection as the root-mutation boundary. A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha. Co-authored-by: Cursor <cursoragent@cursor.com> * closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5 The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around. First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs. Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here. Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * fleet-converge: omit the Spark target input and spark_* modes while the administrator roster is empty; refuse an empty choice at emission (port of ffe8a90) The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes. What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name. The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: delete the accounting doc; the terminal ledger lives in #13641's body (review 5474794145) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * closeout: revert the #13664 fold (5c0d9d5) per the operator's review 5477471759: close #13664 without folding, branch preserved; projections regenerated next * deployment environments: model the branch policy as GitHub returns it (name + branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET (review 78420) Review 78420 on gunbc#13660 (folded here at 60c9457) found that extdeps.github.deployment_environments modeled the deployment-branch policy as SelectedRefs { refs: ["refs/heads/main"] }, while the API carries no refs: the environment object's deployment_branch_policy is null or { protected_branches, custom_branch_policies }, and the custom rules live at GET /repos/{owner}/{repo}/environments/{name}/deployment-branch-policies as branch_policies rows { name, type } with type "branch" or "tag". A reading of the real API can therefore never match the modeled refs, so gunbc.auth.github_deployment_environment's standing could never move from Unobserved to Holds (DESIGN section 3: model what the API actually returns; section 5: a check that cannot be discharged is not a boundary). The model now carries DeploymentBranchPolicyRule { name, ref_type: PolicyRefBranch | PolicyRefTag } under SelectedBranchesAndTags { rules }, the srv1-production requirement is the single branch rule named main with required reviewers, the restriction predicate requires exactly one rule that is a branch named main, and the read obligation names both GETs and the shapes they return. The witness gains a supplied-value control: a tag rule named main and a two-rule policy are not the main-branch boundary, the single branch rule is. Standing stays Unobserved until the operator applies the setting and its readback lands; that flip is the first follow-up on main. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * closeout: regenerate at the fixed point on composition A (revert of #13664, fold of #13660) Same recipe as f8c3fa4, on a shallow clone of dbdc9d2 with the previous fixed-point seed as the boot seed (srv1, logs8): main_wet exit 0; required-regen generation 0 drifted gunbc_cli_dispatch_surface.rs (gunbc.cli_dispatch_surface is touched by #13660), generation 1 drifted gunbc_cli_dispatch_generated.rs, generation 2 first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; verify (dry main) exit 0; rebuild; gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0 warning_count=0 wall_s=611, discriminating red on v2_cli_compile_cli) and //gunbc/instruments:self-host exit 0 (wall_s=716, red on v2_compiler_compile). The projections resolved toward #13660's side in the merge (ROADMAP.md, fleet-converge.yml, docs/design-rung-drops.md) were byte-identical to main_wet's output, so only .gitattributes and the two cli_dispatch mirrors change here. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: gunbc-ci-auto-heal <briansrls@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: x <x@x> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Defect (RFM one_spelling_names_a_primitive_and_a_declaration_with_different_contracts)
The spelling map_get named two contracts:
The authoritative meaning is the primitive's: it is the runtime the floor roster already treats as the bare-provider path, and the declared body was the divergent second meaning. The declared projection is renamed to map_get_checked at its owner (src/v2/std/collection.dag) and every consumer follows.
What changed
Reds and positive control
Witness evidence (remote claim_batch, 2026-10-06)
Consumer census
Found by identity across src/v2, dag, src/v1: all declared-form call sites renamed (incl. the compiler passes 02_parse/03_ingest/03_name_resolve/03_resolve/emit_, lens/, std/, workflow/); floor_unimported_bare_provider_debt_roster rows stay (primitive-route sites); calm-koi-257's #13376 floor_route_gap.dag calls only map_contains_key/empty_map/map_insert (unrenamed) — coordinated, no interaction.