Skip to content

Floor: typed exclusion of unmodeled rust stderr-capture in fixture-closure union - #13466

Merged
gunbai-bot[bot] merged 11 commits into
mainfrom
session/fierce-badger-476
Oct 7, 2026
Merged

gunbai-bot[bot] merged 11 commits into
mainfrom
session/fierce-badger-476

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

§4b(3) / §5 interim (reviewer checklist)

(a) Rostered as gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture (projected in docs/design-rung-drops.md):

  • previous: MechanicallyPreventable → temporary: Mitigatable
  • population: exactly gunbc.WitnessBin.Run in extdeps.gunbc (stderr_truncated / stderr_total_bytes / stderr_retained_bytes). The same capture-gap fact on any other operation is not a member and still refuses the union.
  • restoration trigger names the capability: rust emitted shell realization implements the declared WitnessStderrCapturePolicy (sufficient for shell_channel_realized_by_target to admit those three channels).

(b) Counted and printed every required floor: [floor-phase] phase=fixture-closure-union-emit … excluded=N excluded_rows=\module=extdeps.gunbc service=WitnessBin cause=ShellChannelNotRealizedByTarget … drop=gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture``. Never a silent skip.

Control: same gunbc-reaching closure plus a non-tail effectful self-call still FixtureClosureUnionEmitRefused at module=efr_member (a_real_emit_error_beside_the_excluded_service_still_refuses, also enrolled in fixture_closure_union_controls on every floor).

Exclusion keys on equality to shell_emission_refusal_fact(ShellChannelNotRealizedByTarget) plus (module, service, operation) = (extdeps.gunbc, WitnessBin, Run), not an English substring.

Test plan

  • ctrl-build --remote -- cargo test --release -p v1-compiler --lib fixture_closure_union — 8/8 including fact-equality, gunbc typed exclusion, other-module not excluded, real emit error still refuses
  • Full required floor is CI's job

Do not merge this PR from the worker; parent sleek-koi-528 should land it. #13420 is blocked on this.

Brian Searls and others added 3 commits October 6, 2026 11:32
…ixture-closure union.

The emit wall on WitnessBin.Run's capture-accounting channels is justified; treating it as a union-wide floor refusal after #13437 aborted every other member's render. Exclude those services by diagnostic fact, keep a real emit error refusing, and declare the drop until rust realizes WitnessStderrCapturePolicy.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…yTarget facts.

Match emit's rendered ShellChannelNotRealizedByTarget facts by equality, not an English substring of missing_realization_fact, so an unmodeled key cannot ride the exclusion.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 77014 on 579c4e7 (head now 1205494).

The exclusion no longer keys on an English substring of missing_realization_fact. It matches by equality against the facts v1.compiler.emit shell_emission_refusal_fact renders for ShellChannelNotRealizedByTarget on every ShellResultChannel that shell_channel_realized_by_target returns false for on rust. ShellOutputKeyNotModeled (and a fact that merely contains the capture-policy sentence) stay in the render set. Enrolled unit: capture_gap_keys_on_shell_channel_not_realized_fact_equality.

On the seed vs .dag point: this is the existing seed floor instrument (fixture_closure_union_emit_receipt on RetainedHostCliKernel). The drop gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture is the §4b(3) declaration. The discriminator consumes emit's typed refusal constructor rather than restating it. Adding the same predicate as a new .dag wrapper would be a second name for that constructor's facts.

Brian Searls and others added 2 commits October 6, 2026 13:13
The §4b(3) population is exactly extdeps.gunbc WitnessBin.Run stderr-channel refusals; the same fact on any other operation still refuses the union.

Co-authored-by: Cursor <cursoragent@cursor.com>
…xclusion.

Emit's TransportEmissionNotModeled names the service gunbc.WitnessBin and the operation gunbc.WitnessBin.Run; WitnessBin/Run alone never excluded the live union.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 77014 (artifact /api/reviews/77014/artifacts/stdout.log) against current head f4168ad4bb.

Finding 1 (substring of missing_realization_fact): already changed. STDERR_CAPTURE_POLICY_GAP_FACT and .contains(...) are gone. The discriminator is equality to the strings v1.compiler.emit shell_emission_refusal_fact renders for ShellChannelNotRealizedByTarget on every ShellResultChannel that shell_channel_realized_by_target returns false for on rust, and (declaring_module, service, operation) is exactly extdeps.gunbc / gunbc.WitnessBin / Run (or gunbc.WitnessBin.Run). A fact that merely contains the capture-policy sentence does not match (capture_gap_keys_on_shell_channel_not_realized_fact_equality). Sibling unmodeled keys stay in the render set.

Carrying a new typed cause field on TransportEmissionNotModeled in 00_core is not done: that diagnostic is the shared unmodeled-transport wall. Adding a floor-union cause there would put union policy on the emit diagnostic, a second meaning on one constructor. The union already consumes the emit constructor that owns the fact (ShellChannelNotRealizedByTarget via shell_emission_refusal_fact).

Finding 2 (policy only in seed Rust): the exclusion is realized in fixture_closure_union_emit_receipt, which is already the seed floor instrument (RetainedHostCliKernel) that #13195 enrolled. A new .dag function that lists the same service to skip would be a second name for gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture plus the emit refusal constructor. The drop row is the §4b(3) declaration (previous/temporary/bounded population/capability trigger); the seed fold is the existing realization of the union, not a new scaffold beside it. Modeling the strip inside 05_emit would put union membership policy on the wall this repair deliberately left in place.

Floor print remains excluded= / excluded_rows=; a real emit error beside the excluded service still refuses.

— sent from fierce-badger-476

…nels.

A later unrealized stdout-side ShellChannelNotRealizedByTarget must still refuse the union rather than inherit this drop (review 77034).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 77034 (artifact /api/reviews/77034/artifacts/stdout.log) on head a3d8baef16.

Finding 1: the fact set no longer walks every ShellResultChannel and keeps whatever rust currently fails to realize. It lists only ShellChanStderrTruncated, ShellChanStderrTotalBytes, and ShellChanStderrRetainedBytes — the drop population. A ShellChannelNotRealizedByTarget fact for stdout does not match (capture_gap_keys_on_shell_channel_not_realized_fact_equality). That refusal stays on the union.

Advisory (seed census): not adding a census row. This is the existing seed floor instrument (fixture_closure_union_emit_receipt) plus the declared drop, not a new seed feature lane.

— sent from fierce-badger-476

@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Review 77042 (artifact /api/reviews/77042/artifacts/stdout.log): no code change.

extdeps.gunbc gunbc.WitnessBin has one operation, Run. Stripping the service is the same population as stripping that operation. A second operation would still refuse the union unless every unmodeled-transport refusal on the service is the three stderr-accounting facts and that new operation is added to the drop — the drop is not widened in this PR.

Seed-census advisory: not adding a named lane. This is the existing fixture_closure_union_emit_receipt seed floor instrument plus gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture.

— sent from fierce-badger-476

A later operation on gunbc.WitnessBin that emits cleanly must stay in the union; the drop population is exactly Run (review 77051).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 77051 (artifact /api/reviews/77051/artifacts/stdout.log) on head 993633e944.

Finding 1: exclusion is now operation grain. strip_excluded_run_operations removes only children named Run / gunbc.WitnessBin.Run from gunbc.WitnessBin. Other operations stay. The guard looks only at Run's unmodeled-transport diagnostics. Today WitnessBin has only Run, so the empty-service item is dropped; a later sibling operation would remain in the render set. Printed row includes operation=gunbc.WitnessBin.Run.

Advisory (seed census): not adding a named lane. Existing fixture_closure_union_emit_receipt plus the declared drop.

— sent from fierce-badger-476

The emit graph Node children carrier is im::Vector, not std::Vec.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Head is now 2ef8d0cf8c: remaining service children after stripping Run are kept as im::Vector (the emit graph's Node children carrier).

— sent from fierce-badger-476

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 2ef8d0cf8cac3b3b430e256619fe54e63cf69e4c, against DESIGN.md §§2, 3 and 4b. The operation-level exclusion and its declared population are accepted on inspection. Two bounded testing corrections remain; no capture-policy implementation, new test lane, widened drop or second closure authority is requested.

Accepted: the current predicate is bounded, and compilation still covers the original union

fixture_closure_union_emit_receipt compiles every recorded source and refuses blocking compilation diagnostics before applying the emit-only exclusion. stderr_capture_policy_gap_service matches the TransportEmissionNotModeled arm, shell transport, Rust target, exact declaring module extdeps.gunbc, service gunbc.WitnessBin, and Run's two established spellings. Its fact set is derived from shell_emission_refusal_fact for exactly the three declared stderr-accounting channels, not every channel Rust might fail to realize and not a substring of an English diagnostic.

run_operations_excluded_for_stderr_capture_gap combines the file, shell and REST diagnostic streams. A matching capture row proposes a candidate, and every unmodeled-transport row for that same Run must then satisfy the capture predicate. An additional ShellOutputKeyNotModeled on Run therefore vetoes the exclusion in the current code. The shell producer flat-maps the individual output fields; it does not stop at the first offending field, so the consumer is not basing its all-rows judgment on a first-error-only observation. Refusals belonging to another operation remain on that operation, which stays rendered.

strip_excluded_run_operations currently filters only Run from the matching service's children, preserving other children and other items, and drops the service container only when no operations remain. The population is therefore narrower than the initial request's service wording: exactly extdeps.gunbc / gunbc.WitnessBin.Run. The rung-drop row names that singleton and the three channel facts, records the downgrade, and requires a real Rust implementation of WitnessStderrCapturePolicy rather than fabricated accounting or deleting interface fields. The named exclusion remains observable. This is a partial emission judgment with an explicitly excluded operation, not proof of clean Rust emission for the excluded Run itself.

[P2] Retain discriminators for the mixed-refusal veto and the strip's exact scope

The existing floor pair is meaningful and accepted: the gunbc-reaching fixture must succeed with a named exclusion, while the same closure plus the real efr_member emit error must still refuse. Removing the exclusion would break the former. However, neither case establishes that the exclusion cannot grow beyond its declared boundary.

There are two specific missing distinctions:

  1. capture_gap_keys_on_shell_channel_not_realized_fact_equality tests single diagnostic rows individually. It does not drive the candidate-selection fold with BOTH an allowed capture row and a different unmodeled-transport row on the SAME Run. Loosening the aggregate .all(...) veto to .any(...) is not distinguished by that test or by the current live fixture, whose Run has only the allowed capture diagnostics. Add a small supplied-row control through the production selection fold: allowed-only selects Run; allowed plus ShellOutputKeyNotModeled on that same Run selects nothing. Keep wrong-module/nonmember controls. A narrow projection used by run_operations_excluded_for_stderr_capture_gap is sufficient; do not duplicate the selection algorithm in the test.

  2. No control invokes strip_excluded_run_operations with a matching service that has Run AND a sibling operation, then checks the retained graph. The live service currently has only Run, so deleting the whole service instead produces the same answer on that specimen. The positive libtest checks membership in the original source union and the emitted exclusion string; neither checks the graph after stripping. The unrelated efr_member error also survives a too-broad removal of WitnessBin and therefore cannot discriminate it. Add a supplied resolved-graph control through the real strip: Run disappears, a sibling operation remains, and unrelated items/modules remain. Also retain an empty-exclusion unchanged control. This requires no additional operations or fake fields in the production extdeps interface.

Execute the corresponding small mutants: ignoring the mixed-refusal veto must fail the first control; deleting the whole matching service instead of only Run must fail the second. I have not executed these mutants myself. These are coverage findings about the newly introduced safety boundary, not a claim that the current inspected .all or operation filter is already wrong.

[P2] Remove the two duplicate live-corpus Rust integration tests; keep their floor executions

The new libtests a_fixture_whose_closure_reaches_extdeps_gunbc_is_excluded_by_typed_cause and a_real_emit_error_beside_the_excluded_service_still_refuses each acquire the live module closure, compile it and emit it. They duplicate the corresponding cases already executed by fixture_closure_union_controls. This recreates the expensive corpus-integration placement #13452 removed from the under-100ms unit lane, and adds no boundary distinction beyond the mandatory floor cases.

Delete these two duplicate libtests, not the floor controls or their fixtures. Keep the cheap fact-equality test and implement the bounded supplied-input selection/strip controls above. The existing floor pair remains the real-path pairing for those supplied boundaries; no new lane or expensive replacement is needed.

Evidence

Requested-SHA witnesses workflow 37474583447 is successful. The floor job 112314282589 checks out this exact head and records receipt=fixture-closure-union-controls state=held; this independently establishes that the retained floor pair executes, not merely that its functions compile. The Rust-unit log for 112314282723 checks out merge f9e7e07d010850075b29e2a09aaf53e09695ff4d, explicitly including this head, and records the three new tests as passing. I am not treating the intervals between log lines as individual test-time certificates. The current green workflow does not supply the two missing discrimination cases above or justify duplicate live-corpus executions in libtest. Remote counts and uncommitted experiments remain author-run evidence; I did not build, time tests, run clippy, mutate the tree or touch hardware.

The exact requested head remained unchanged and mergeable when checked. The current exclusion mechanism, bounded declaration and restoration capability are not being reopened; the requested changes are the narrow controls and removal of redundant heavy unit executions.

…corpus libtests.

The mixed-refusal veto and operation-grain strip are exercised through the production folds on supplied rows and a supplied graph. Floor gunbc fixtures stay enrolled.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Addressing GitHub review 5430969101 at prior head 2ef8d0cf8c; current head 7212cd1573.

(1) Supplied-input controls go through the production folds only: select_run_operations_excluded_for_stderr_capture_gap (the selection used by run_operations_excluded_for_stderr_capture_gap) and strip_excluded_run_operations. Allowed Run capture rows select Run; the same Run plus ShellOutputKeyNotModeled selects nothing; wrong-module and Sibling nonmember stay out. Strip: Run gone, Sibling and unrelated items/modules remain; empty exclusion is unchanged.

Uncommitted remote mutants on 7212cd1573: .all → .any fails selection_fold_allows_only_run_capture_rows_and_vetoes_mixed_refusal (exit 101). Keeping no operations (whole matching service dropped) fails strip_removes_only_run_and_keeps_sibling_and_unrelated_items (exit 101).

(2) Deleted libtests a_fixture_whose_closure_reaches_extdeps_gunbc_is_excluded_by_typed_cause and a_real_emit_error_beside_the_excluded_service_still_refuses. Floor fixture_closure_union_controls and the gunbc fixtures remain. capture_gap_keys_on_shell_channel_not_realized_fact_equality remains.

Clippy -D warnings on 7212cd1573 (cargo clippy -p v1-compiler --lib) held. Baseline fixture_closure_union 8 passed.

— sent from fierce-badger-476

Deleting the rung-drop file now fails the seed compile, and the union reads
module/service/operation from those fields instead of a second hardcoded
population (review 77110).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

review 77110: the exclusion no longer carries a second authored population.

gunbc.rung_drop.fixture_closure_union_unmodeled_stderr_capture now declares typed data fields (exclusion_drop_identity, exclusion_declaring_module, exclusion_service, exclusion_operation_qualified, exclusion_operation_bare). The union includes that module source and reads those fields; deleting the file fails the seed compile. RungDrop.population stays List<String> for the rest of the ledger — widening that type would be a corpus-wide migration, not this drop's repair.

Head: abd25b5

— sent from fierce-badger-476

…urce.

The union now reads gunbc.stderr_capture_gap_exclusion.exclusion through
compile_to_resolved; a missing or misshapen field is a typed cause, not a
panic. The drop row consumes that carrier. RungDrop.population stays
List<String> for the rest of the ledger (review 77125).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

review 77125: the include_str + find("data {name}: String") scan is gone.

The excluded (module, service, operation) now lives on a typed record gunbc.stderr_capture_gap_exclusion.exclusion. The union compiles that module with compile_to_resolved and evaluates the data item. A missing or wrong-shaped field is cause=CaptureGapExclusion…, not a panic. The drop row consumes the carrier via capture_gap_exclusion_population; deleting either file fails the seed compile.

RungDrop.population stays List<String> for every other drop. Putting an ItemRef on that field is a ledger-wide migration, not this exclusion's repair. The record fields are the compiler's authored names for extdeps.gunbc / WitnessBin / Run.

Head: 7e3f030

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE / LAND at exact head 7e3f030a316f13cc4c9f2332a2e82a172f45da40. Both P2 requests from review 5430969101 are resolved. No new blocking findings.

The supplied-input controls exercise the production boundaries

run_operations_excluded_for_stderr_capture_gap still acquires all three unmodeled-transport diagnostic streams and now delegates its decision to select_run_operations_excluded_for_stderr_capture_gap. The new selection control calls that same function: an allowed capture row selects the singleton; an allowed capture row plus ShellOutputKeyNotModeled on the SAME Run selects nothing. Wrong-module and sibling-operation cases remain outside the population. This distinguishes the requested .all -> .any mutation; it is not a separate test implementation of the selection algorithm.

strip_removes_only_run_and_keeps_sibling_and_unrelated_items supplies a small resolved graph directly to the actual strip_excluded_run_operations. It requires Sibling to survive while Run disappears, checks the unrelated function remains, retains the second module, and checks the empty-exclusion case keeps both operation names. Deleting the whole matching service therefore fails the sibling assertion. No live-corpus acquisition was introduced to establish these distinctions.

The reported uncommitted mutant runs are consistent with those assertions: the mixed-refusal mutation fails the selection control, and whole-service deletion fails the strip control. I did not independently execute the mutants.

The duplicate heavy executions are removed, not the real-path pairing

The two live-corpus libtests named in my prior request are absent. Their gunbc-reaching success-with-named-exclusion case and gunbc-plus-real-member-emit-error case remain in fixture_closure_union_controls, through the real closure acquisition, compile, exclusion, and emit path. This retains the integration pairing required for the supplied boundaries; removing the strip still breaks that mandatory success case. No new lane or widened drop is needed.

Additional change checked

The exclusion identity is now the evaluated nominal record gunbc.stderr_capture_gap_exclusion.exclusion, also consumed by the rung-drop module. Its committed module/service/operation values remain the same singleton, and the Rust fact set still explicitly names only the three stderr-accounting channels. The loader compiles the small embedded carrier and checks its nominal record/field shapes rather than scraping source text. A load failure does not authorize an exclusion: the graph is left intact, and the mandatory gunbc control cannot hold without the exclusion. This is not a claim that the full rung-drop declaration is evaluated or that every loader cause is propagated by the outer union function.

Execution verified

Workflow 37499886076 has all five required jobs successful, including generated's Lint every target step. Floor job 112397649753 checks out the exact requested SHA and records receipt=fixture-closure-union-controls state=held. Rust-unit job 112397649204 checks out synthetic merge 9001fafd27e9ffcc3ba5b637f23189259cbc086a, explicitly including this head; its log names both new controls as executed and passing, alongside the fact-equality and typed-carrier tests. Thus the evidence is execution, not merely compilation or test enrollment.

This approval preserves the previously accepted bounded emit exclusion and its restoration obligation. It does not claim that Rust implements WitnessStderrCapturePolicy or renders the excluded Run. No further changes requested.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 027839e Oct 7, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/fierce-badger-476 branch October 7, 2026 08:57
@briansrls
briansrls restored the session/fierce-badger-476 branch October 7, 2026 09:00
gunbai-bot Bot pushed a commit that referenced this pull request Oct 7, 2026
…d rust stderr-capture; fleet-converge.yml regenerated = main + D2 host-neutral step names)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 7, 2026
…ure.

After the main merge the floor still required a capture-gap exclusion that this branch closed.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 8, 2026
… channels.

The constructed ShellChannelNotRealizedByTarget fact is unchanged; rust_stderr_capture_channel_not_realized_facts is empty because shell_channel_realized_by_target is now true for those channels. Install the required-regen emit_rust mirror after merging main.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant