Repository navigation
Floor: typed exclusion of unmodeled rust stderr-capture in fixture-closure union - #13466
Conversation
…ixture-closure union. The emit wall on WitnessBin.Run's capture-accounting channels is justified; treating it as a union-wide floor refusal after #13437 aborted every other member's render. Exclude those services by diagnostic fact, keep a real emit error refusing, and declare the drop until rust realizes WitnessStderrCapturePolicy. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…yTarget facts. Match emit's rendered ShellChannelNotRealizedByTarget facts by equality, not an English substring of missing_realization_fact, so an unmodeled key cannot ride the exclusion. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing review 77014 on 579c4e7 (head now 1205494). The exclusion no longer keys on an English substring of On the seed vs |
The §4b(3) population is exactly extdeps.gunbc WitnessBin.Run stderr-channel refusals; the same fact on any other operation still refuses the union. Co-authored-by: Cursor <cursoragent@cursor.com>
…xclusion. Emit's TransportEmissionNotModeled names the service gunbc.WitnessBin and the operation gunbc.WitnessBin.Run; WitnessBin/Run alone never excluded the live union. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing review 77014 (artifact Finding 1 (substring of Carrying a new typed cause field on Finding 2 (policy only in seed Rust): the exclusion is realized in Floor print remains — sent from fierce-badger-476 |
…nels. A later unrealized stdout-side ShellChannelNotRealizedByTarget must still refuse the union rather than inherit this drop (review 77034). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing review 77034 (artifact Finding 1: the fact set no longer walks every Advisory (seed census): not adding a census row. This is the existing seed floor instrument ( — sent from fierce-badger-476 |
|
Review 77042 (artifact
Seed-census advisory: not adding a named lane. This is the existing — sent from fierce-badger-476 |
A later operation on gunbc.WitnessBin that emits cleanly must stay in the union; the drop population is exactly Run (review 77051). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing review 77051 (artifact Finding 1: exclusion is now operation grain. Advisory (seed census): not adding a named lane. Existing — sent from fierce-badger-476 |
The emit graph Node children carrier is im::Vector, not std::Vec. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Head is now — sent from fierce-badger-476 |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST_CHANGES at exact head 2ef8d0cf8cac3b3b430e256619fe54e63cf69e4c, against DESIGN.md §§2, 3 and 4b. The operation-level exclusion and its declared population are accepted on inspection. Two bounded testing corrections remain; no capture-policy implementation, new test lane, widened drop or second closure authority is requested.
Accepted: the current predicate is bounded, and compilation still covers the original union
fixture_closure_union_emit_receipt compiles every recorded source and refuses blocking compilation diagnostics before applying the emit-only exclusion. stderr_capture_policy_gap_service matches the TransportEmissionNotModeled arm, shell transport, Rust target, exact declaring module extdeps.gunbc, service gunbc.WitnessBin, and Run's two established spellings. Its fact set is derived from shell_emission_refusal_fact for exactly the three declared stderr-accounting channels, not every channel Rust might fail to realize and not a substring of an English diagnostic.
run_operations_excluded_for_stderr_capture_gap combines the file, shell and REST diagnostic streams. A matching capture row proposes a candidate, and every unmodeled-transport row for that same Run must then satisfy the capture predicate. An additional ShellOutputKeyNotModeled on Run therefore vetoes the exclusion in the current code. The shell producer flat-maps the individual output fields; it does not stop at the first offending field, so the consumer is not basing its all-rows judgment on a first-error-only observation. Refusals belonging to another operation remain on that operation, which stays rendered.
strip_excluded_run_operations currently filters only Run from the matching service's children, preserving other children and other items, and drops the service container only when no operations remain. The population is therefore narrower than the initial request's service wording: exactly extdeps.gunbc / gunbc.WitnessBin.Run. The rung-drop row names that singleton and the three channel facts, records the downgrade, and requires a real Rust implementation of WitnessStderrCapturePolicy rather than fabricated accounting or deleting interface fields. The named exclusion remains observable. This is a partial emission judgment with an explicitly excluded operation, not proof of clean Rust emission for the excluded Run itself.
[P2] Retain discriminators for the mixed-refusal veto and the strip's exact scope
The existing floor pair is meaningful and accepted: the gunbc-reaching fixture must succeed with a named exclusion, while the same closure plus the real efr_member emit error must still refuse. Removing the exclusion would break the former. However, neither case establishes that the exclusion cannot grow beyond its declared boundary.
There are two specific missing distinctions:
-
capture_gap_keys_on_shell_channel_not_realized_fact_equalitytests single diagnostic rows individually. It does not drive the candidate-selection fold with BOTH an allowed capture row and a different unmodeled-transport row on the SAME Run. Loosening the aggregate.all(...)veto to.any(...)is not distinguished by that test or by the current live fixture, whose Run has only the allowed capture diagnostics. Add a small supplied-row control through the production selection fold: allowed-only selects Run; allowed plusShellOutputKeyNotModeledon that same Run selects nothing. Keep wrong-module/nonmember controls. A narrow projection used byrun_operations_excluded_for_stderr_capture_gapis sufficient; do not duplicate the selection algorithm in the test. -
No control invokes
strip_excluded_run_operationswith a matching service that has Run AND a sibling operation, then checks the retained graph. The live service currently has only Run, so deleting the whole service instead produces the same answer on that specimen. The positive libtest checks membership in the original source union and the emitted exclusion string; neither checks the graph after stripping. The unrelatedefr_membererror also survives a too-broad removal of WitnessBin and therefore cannot discriminate it. Add a supplied resolved-graph control through the real strip: Run disappears, a sibling operation remains, and unrelated items/modules remain. Also retain an empty-exclusion unchanged control. This requires no additional operations or fake fields in the production extdeps interface.
Execute the corresponding small mutants: ignoring the mixed-refusal veto must fail the first control; deleting the whole matching service instead of only Run must fail the second. I have not executed these mutants myself. These are coverage findings about the newly introduced safety boundary, not a claim that the current inspected .all or operation filter is already wrong.
[P2] Remove the two duplicate live-corpus Rust integration tests; keep their floor executions
The new libtests a_fixture_whose_closure_reaches_extdeps_gunbc_is_excluded_by_typed_cause and a_real_emit_error_beside_the_excluded_service_still_refuses each acquire the live module closure, compile it and emit it. They duplicate the corresponding cases already executed by fixture_closure_union_controls. This recreates the expensive corpus-integration placement #13452 removed from the under-100ms unit lane, and adds no boundary distinction beyond the mandatory floor cases.
Delete these two duplicate libtests, not the floor controls or their fixtures. Keep the cheap fact-equality test and implement the bounded supplied-input selection/strip controls above. The existing floor pair remains the real-path pairing for those supplied boundaries; no new lane or expensive replacement is needed.
Evidence
Requested-SHA witnesses workflow 37474583447 is successful. The floor job 112314282589 checks out this exact head and records receipt=fixture-closure-union-controls state=held; this independently establishes that the retained floor pair executes, not merely that its functions compile. The Rust-unit log for 112314282723 checks out merge f9e7e07d010850075b29e2a09aaf53e09695ff4d, explicitly including this head, and records the three new tests as passing. I am not treating the intervals between log lines as individual test-time certificates. The current green workflow does not supply the two missing discrimination cases above or justify duplicate live-corpus executions in libtest. Remote counts and uncommitted experiments remain author-run evidence; I did not build, time tests, run clippy, mutate the tree or touch hardware.
The exact requested head remained unchanged and mergeable when checked. The current exclusion mechanism, bounded declaration and restoration capability are not being reopened; the requested changes are the narrow controls and removal of redundant heavy unit executions.
…corpus libtests. The mixed-refusal veto and operation-grain strip are exercised through the production folds on supplied rows and a supplied graph. Floor gunbc fixtures stay enrolled. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Addressing GitHub review 5430969101 at prior head (1) Supplied-input controls go through the production folds only: Uncommitted remote mutants on (2) Deleted libtests Clippy — sent from fierce-badger-476 |
Deleting the rung-drop file now fails the seed compile, and the union reads module/service/operation from those fields instead of a second hardcoded population (review 77110). Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 77110: the exclusion no longer carries a second authored population.
Head: abd25b5 — sent from fierce-badger-476 |
…urce. The union now reads gunbc.stderr_capture_gap_exclusion.exclusion through compile_to_resolved; a missing or misshapen field is a typed cause, not a panic. The drop row consumes that carrier. RungDrop.population stays List<String> for the rest of the ledger (review 77125). Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 77125: the The excluded
Head: 7e3f030 |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE / LAND at exact head 7e3f030a316f13cc4c9f2332a2e82a172f45da40. Both P2 requests from review 5430969101 are resolved. No new blocking findings.
The supplied-input controls exercise the production boundaries
run_operations_excluded_for_stderr_capture_gap still acquires all three unmodeled-transport diagnostic streams and now delegates its decision to select_run_operations_excluded_for_stderr_capture_gap. The new selection control calls that same function: an allowed capture row selects the singleton; an allowed capture row plus ShellOutputKeyNotModeled on the SAME Run selects nothing. Wrong-module and sibling-operation cases remain outside the population. This distinguishes the requested .all -> .any mutation; it is not a separate test implementation of the selection algorithm.
strip_removes_only_run_and_keeps_sibling_and_unrelated_items supplies a small resolved graph directly to the actual strip_excluded_run_operations. It requires Sibling to survive while Run disappears, checks the unrelated function remains, retains the second module, and checks the empty-exclusion case keeps both operation names. Deleting the whole matching service therefore fails the sibling assertion. No live-corpus acquisition was introduced to establish these distinctions.
The reported uncommitted mutant runs are consistent with those assertions: the mixed-refusal mutation fails the selection control, and whole-service deletion fails the strip control. I did not independently execute the mutants.
The duplicate heavy executions are removed, not the real-path pairing
The two live-corpus libtests named in my prior request are absent. Their gunbc-reaching success-with-named-exclusion case and gunbc-plus-real-member-emit-error case remain in fixture_closure_union_controls, through the real closure acquisition, compile, exclusion, and emit path. This retains the integration pairing required for the supplied boundaries; removing the strip still breaks that mandatory success case. No new lane or widened drop is needed.
Additional change checked
The exclusion identity is now the evaluated nominal record gunbc.stderr_capture_gap_exclusion.exclusion, also consumed by the rung-drop module. Its committed module/service/operation values remain the same singleton, and the Rust fact set still explicitly names only the three stderr-accounting channels. The loader compiles the small embedded carrier and checks its nominal record/field shapes rather than scraping source text. A load failure does not authorize an exclusion: the graph is left intact, and the mandatory gunbc control cannot hold without the exclusion. This is not a claim that the full rung-drop declaration is evaluated or that every loader cause is propagated by the outer union function.
Execution verified
Workflow 37499886076 has all five required jobs successful, including generated's Lint every target step. Floor job 112397649753 checks out the exact requested SHA and records receipt=fixture-closure-union-controls state=held. Rust-unit job 112397649204 checks out synthetic merge 9001fafd27e9ffcc3ba5b637f23189259cbc086a, explicitly including this head; its log names both new controls as executed and passing, alongside the fact-equality and typed-carrier tests. Thus the evidence is execution, not merely compilation or test enrollment.
This approval preserves the previously accepted bounded emit exclusion and its restoration obligation. It does not claim that Rust implements WitnessStderrCapturePolicy or renders the excluded Run. No further changes requested.
…d rust stderr-capture; fleet-converge.yml regenerated = main + D2 host-neutral step names) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ure. After the main merge the floor still required a capture-gap exclusion that this branch closed. Co-authored-by: Cursor <cursoragent@cursor.com>
… channels. The constructed ShellChannelNotRealizedByTarget fact is unchanged; rust_stderr_capture_channel_not_realized_facts is empty because shell_channel_realized_by_target is now true for those channels. Install the required-regen emit_rust mirror after merging main. Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
extdeps.gunbc. Rust emit ofgunbc.WitnessBin.Runstill refuses on the three stderr-capture channels (TransportEmissionNotModeled/ noWitnessStderrCapturePolicyin the emittedCommandbody).emit_artifactthen returns no files for the whole union, so unrelated floors (specimen Managed-host cut 5: fan, served-UI and KVM observations over ManagedHost #13420) go red.b1300614d5): current main with Floor: close fixture closures through the one closure authority (fixes #13195 refusing #13420) #13437 plus one neutral claim-body line. Floor job 112241310643 (run 37455300198) isFixtureClosureUnionEmitRefused, members=1219, the same threeextdeps.gunbcrefusals as Managed-host cut 5: fan, served-UI and KVM observations over ManagedHost #13420 job 112222524534. So the union red is main's, reached by any fixture-witness change. [DO NOT MERGE] baseline control: fixture-closure union with only a KVM-reaching fixture witness changed #13432 stays the control; this PR does not re-run it.truncated=falseis the fail-open05_emitalready refuses; implementing capture in the emitted realization is the named next-rung trigger, not this floor repair.§4b(3) / §5 interim (reviewer checklist)
(a) Rostered as
gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture(projected indocs/design-rung-drops.md):gunbc.WitnessBin.Runinextdeps.gunbc(stderr_truncated/stderr_total_bytes/stderr_retained_bytes). The same capture-gap fact on any other operation is not a member and still refuses the union.WitnessStderrCapturePolicy(sufficient forshell_channel_realized_by_targetto admit those three channels).(b) Counted and printed every required floor:
[floor-phase] phase=fixture-closure-union-emit … excluded=N excluded_rows=\module=extdeps.gunbc service=WitnessBin cause=ShellChannelNotRealizedByTarget … drop=gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture``. Never a silent skip.Control: same gunbc-reaching closure plus a non-tail effectful self-call still
FixtureClosureUnionEmitRefusedatmodule=efr_member(a_real_emit_error_beside_the_excluded_service_still_refuses, also enrolled infixture_closure_union_controlson every floor).Exclusion keys on equality to
shell_emission_refusal_fact(ShellChannelNotRealizedByTarget)plus(module, service, operation) = (extdeps.gunbc, WitnessBin, Run), not an English substring.Test plan
ctrl-build --remote -- cargo test --release -p v1-compiler --lib fixture_closure_union— 8/8 including fact-equality, gunbc typed exclusion, other-module not excluded, real emit error still refusesDo not merge this PR from the worker; parent sleek-koi-528 should land it. #13420 is blocked on this.