From 05e1f98bc3ed6890adfe94a82a1e2fdd7e86fe93 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 22:27:19 +0000 Subject: [PATCH 01/50] Delete the unused served pages: sandbox, instrument labs, repo atlas, project suite Owner ruling: unused frontend pages are deleted, with everything that exists only to serve them, and no legacy accommodation (the site has no users). The allocations page is KEPT: it works (live client over the real workspace contract, #13272), so its page, client, style, routes, nav link, witnesses and handoff note are exactly as upstream. Routes removed from gunbc.roadmap_serve: /sandbox, /sandbox/echo, /sandbox/instrument, /sandbox/instrument/tuner, /sandbox/instrument/motion, /sandbox/repo-atlas and their JS assets; /project/{node_id} (no redirect). The issue breadcrumb now links ancestors to /issue/. Page modules, their client programs in gunbc.roadmap_component, the project suite functions and the sandbox-only forest renderer in gunbc.roadmap_page, and the witness modules that existed only for those pages are deleted. Rosters updated with the deletions: v2.workflow.floor_cost_debt (two rows left with their witness), v2.workflow.floor_unimported_bare_provider_debt_roster (two rows retired as FileDeleted), gunbc.ci_layer_roots (long-lane exclusion and substrate long-lane rows), gunbc.deleted_cadence_reference_census and the deleted_cadence_reference rung drop population (one row, recorded as a gunbc.rung_drop_amendment; docs/design-rung-drops.md regenerated). /roadmap and /ROADMAP.md are NOT cut: the surface-observation bundle, healthz digests and the deploy readback consume both surfaces. Co-Authored-By: Claude Fable 5.1 --- dag/gunbc/ci/ci_layer_roots.dag | 11 - dag/gunbc/ci/ci_runner_placement.dag | 3 +- .../deleted_cadence_reference_census.dag | 12 - dag/gunbc/roadmap/roadmap_component.dag | 1516 ++--------------- .../roadmap/roadmap_instrument_motion.dag | 320 ---- .../roadmap/roadmap_instrument_sandbox.dag | 647 ------- .../roadmap/roadmap_instrument_tuner.dag | 289 ---- dag/gunbc/roadmap/roadmap_page.dag | 200 +-- .../roadmap/roadmap_repo_atlas_sandbox.dag | 634 ------- dag/gunbc/roadmap/roadmap_sandbox.dag | 628 ------- dag/gunbc/roadmap/roadmap_serve.dag | 123 +- .../deleted_cadence_reference_drop.dag | 1 - ...andbox_reference_left_with_its_witness.dag | 14 + dag/gunbc/rung_drop_amendment/roster.dag | 2 + .../instrument_motion_page_witness_test.dag | 230 --- .../claim/instrument_sandbox_witness_test.dag | 256 --- .../claim/instrument_tuner_witness_test.dag | 123 -- .../instrument_sandbox_live_witness_test.dag | 168 -- .../roadmap_presentation_witness_test.dag | 67 +- ...oadmap_repo_atlas_sandbox_witness_test.dag | 334 ---- .../roadmap_sandbox_render_witness_test.dag | 41 - .../roadmap/roadmap_sandbox_witness_test.dag | 185 -- .../roadmap/roadmap_serve_witness_test.dag | 36 +- docs/design-rung-drops.md | 4 +- src/v2/workflow/floor_cost_debt.dag | 9 +- ...r_unimported_bare_provider_debt_roster.dag | 4 +- 26 files changed, 154 insertions(+), 5703 deletions(-) delete mode 100644 dag/gunbc/roadmap/roadmap_instrument_motion.dag delete mode 100644 dag/gunbc/roadmap/roadmap_instrument_sandbox.dag delete mode 100644 dag/gunbc/roadmap/roadmap_instrument_tuner.dag delete mode 100644 dag/gunbc/roadmap/roadmap_repo_atlas_sandbox.dag delete mode 100644 dag/gunbc/roadmap/roadmap_sandbox.dag create mode 100644 dag/gunbc/rung_drop_amendment/instrument_sandbox_reference_left_with_its_witness.dag delete mode 100644 dag/test/claim/instrument_motion_page_witness_test.dag delete mode 100644 dag/test/claim/instrument_sandbox_witness_test.dag delete mode 100644 dag/test/claim/instrument_tuner_witness_test.dag delete mode 100644 dag/test/claim/long/instrument_sandbox_live_witness_test.dag delete mode 100644 dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag delete mode 100644 dag/test/claim/roadmap/roadmap_sandbox_render_witness_test.dag delete mode 100644 dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag diff --git a/dag/gunbc/ci/ci_layer_roots.dag b/dag/gunbc/ci/ci_layer_roots.dag index 40ca0b403d4..71a7228a5cb 100644 --- a/dag/gunbc/ci/ci_layer_roots.dag +++ b/dag/gunbc/ci/ci_layer_roots.dag @@ -801,11 +801,6 @@ data witness_exclusion_frontier: List = [ classification: FalsifierSubstrateLongLane, reason: excl_substrate_long_lane_reason, dissolution: excl_substrate_long_lane_dissolve}, - WitnessExclusionRow { - pattern: "long/instrument_sandbox_live_witness_test.dag", - classification: FalsifierSubstrateLongLane, - reason: excl_substrate_long_lane_reason, - dissolution: excl_substrate_long_lane_dissolve}, WitnessExclusionRow { pattern: "synthetic_orphan_admission_witness_test.dag", classification: NoConsumer, @@ -2220,12 +2215,6 @@ data falsifier_substrate_long_lane_rows: List = [ reason: "C0(b2) bare-name join precondition, read against the REAL derived population: classification_matches_fact keys on DeclFact.name, which is sound only while the population's top-level names are distinct, and nothing in the carrier makes that true — it is a property of the subject module. Enrolled here rather than per-PR because it reads the same decl_facts population as the five totality rows above and shares their witness-layer scan over a pool including src/v1. The MECHANISM that would catch a broken fold — a planted-duplicate RED plus a distinct positive control over synthetic two-element fixtures — is NOT enrolled here: it runs per-PR in test.claim.v1_complexity_decl_classification_witness_test, so a regression in the fold reds on every PR and only the live-population reading waits for the cadence.", dissolution: unbound_dissolution(description: "the classification roster carries exact DeclFact identity (qualified_name, or name plus kind) so the join is exact by construction and no precondition remains to read; or per-witness declared cost envelopes subsume the long-lane cadence (long_lane_exclusion_note trigger).") }, - SubstrateLongLaneRow { - entry: "dag/test/claim/long/instrument_sandbox_live_witness_test.dag", - function: "instrument_sandbox_live_keystone_holds", - reason: "Re-homed off per-PR discovery after 5074ms thread-CPU in falsifier discovery batch 3 (run 30986055960, BudgetExceeded against the 5000ms fast-lane budget). WHY THE SPLIT, which is structural and does not move with the measurements: every claim on this entry renders the served page or reads the live program view and pays that cost once, while the cheap register-gate claims — derived salience role, emission/admission join, refused-role controls, theme-block position — do not, so those stay per-PR in dag/test/claim/instrument_sandbox_witness_test.dag at 0-2ms each, per the 2026-08-04 admission ruling that a live-population subject decomposes into mechanism fixtures per PR plus the irreducible live half on a cadence. NOT declared irreducible corpus breadth: the cost is measured and its gating term named. WHERE THAT COST IS: dag/test/claim/long/instrument_sandbox_live_witness_test.dag post_7822_attribution_note, which is its single home. This field used to carry an attribution of its own — the served-page render and live_program_view_result named as the dominant term, a 263ms-inputs / 5132ms-derivation split, n=25 declared nodes — and all of it is retracted: the cost location was wrong and the node count was never right. Deleted rather than disclaimed, because reason is read before dissolve_on and a superseded attribution here steers a worker scanning this roster before any correction below it can land (review 48997; the same fix the witness file's header got)", - dissolution: unbound_dissolution(description: "PARTIALLY MET AND RE-MEASURED TWICE, 2026-08-05. #7822 landed the keyed-lookup restructure this row originally named, and this witness fell roughly tenfold on the same host and binary, so that condition — eval under gunbc_ci_fast_lane_witness_eval_budget — now HOLDS. The row does not dissolve: the bar moved to a 500ms per-witness warning threshold (operator, 2026-08-05) and this witness is still several times over it. THE SECOND CONDITION THIS ROW NAMED IS ALSO WITHDRAWN. It said the residue was the served-page render and asked for a measured run under the warning line, which pointed the work at the witness file; attribution by execution says the dominant term is constructing declared_roadmap_nodes, several times the warning line on its own and before the page renders anything, so no change confined to dag/test/claim/long/instrument_sandbox_live_witness_test.dag can close the gap. CORRECTED CONDITION: the cost of reading the live roadmap authority — declared_roadmap_nodes construction specifically — drops under the per-witness warning line. That cost is shared with every other witness reading that authority, so it is owned by that authority's lane and tracked with the materialization/native-witness-execution work, not here; when it lands, this witness's own render residue is inside the line, these claims re-merge into dag/test/claim/instrument_sandbox_witness_test.dag per-PR, and this row, the exclusion row, and the long-lane file delete together. Every figure behind this — the per-component thread-CPU breakdown, the clock basis, and both retractions — is carried once in the witness file's post_7822_attribution_note and deferral_floor_note, deliberately not copied here, because two numeric copies of one measurement drift") - }, SubstrateLongLaneRow { entry: "dag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag", function: "dag_compile_clean_scope_all_disposition_rows_hold", diff --git a/dag/gunbc/ci/ci_runner_placement.dag b/dag/gunbc/ci/ci_runner_placement.dag index 7b5706022f3..76c59ef82aa 100644 --- a/dag/gunbc/ci/ci_runner_placement.dag +++ b/dag/gunbc/ci/ci_runner_placement.dag @@ -508,7 +508,8 @@ fn host_usable_ram_or_refusal(host: HostIdentity, r: HostUsableRam) -> HostUsabl // THE CAUSE RENDERS FROM ITS OWN MODULE so the manifest, the witnesses and any later consumer all // read one projection rather than each spelling the variants again. // NAMED FOR ITS SUBJECT BECAUSE A BARE `refusal_cause_text` IS AMBIGUOUS CORPUS-WIDE. -// gunbc.roadmap_instrument_sandbox already declares one over ProgramViewRefusalCause. Modules that +// gunbc.roadmap_instrument_sandbox (since deleted with its page) declared one over +// ProgramViewRefusalCause when this was named. Modules that // resolve by bare reference -- the witness tests do -- then see two candidates and refuse, and the // refusal surfaces only in a whole-corpus resolve, never in a per-entry run whose closure happens // to contain one of them. The two functions are genuinely different facts, not a nickname pair, so diff --git a/dag/gunbc/deleted_cadence_reference_census.dag b/dag/gunbc/deleted_cadence_reference_census.dag index 7ecfc66e45a..e2814b4d7c1 100644 --- a/dag/gunbc/deleted_cadence_reference_census.dag +++ b/dag/gunbc/deleted_cadence_reference_census.dag @@ -185,11 +185,6 @@ data self_host_wet_roster_coverage: CoverageNotEstablished = CoverageNotEstablis restoration_trigger: "witness_cadence_has_scheduled_route(FalsifierSelfHostWet) returns true, which is the separate operator agreement std.witness_admission witness_cadence_has_scheduled_route_note reserves" as NonEmptyStr, } -data substrate_long_lane_coverage: CoverageNotEstablished = CoverageNotEstablished { - lost_with: FalsifierSubstrateLongLane, - restoration_trigger: "witness_cadence_has_scheduled_route(FalsifierSubstrateLongLane) returns true" as NonEmptyStr, -} - // A COVERAGE OF ITS OWN RATHER THAN THE SHARED `bin_wet_template_coverage`, because the shared // row's trigger is a ROUTE FLAG and this row needs a stronger thing than a flag. DESIGN section // 4b(3): a drop retires by its trigger and nothing else, so a trigger naming less than the @@ -393,13 +388,6 @@ fn deleted_cadence_references() -> List { current_coverage: self_host_wet_roster_coverage, }, }, - DeletedCadenceReference { - site: decl_ref(module_path: "test.claim.instrument_sandbox_witness", decl_name: "fixture_line_remaining"), - standing: PremiseInvalidated { - affected_decision: decl_ref(module_path: "gunbc.ci_layer_roots", decl_name: "falsifier_substrate_long_lane_rows"), - current_coverage: substrate_long_lane_coverage, - }, - }, DeletedCadenceReference { site: decl_ref(module_path: "test.claim.self_host_use_site_verdict_behavioral_witness", decl_name: "self_host_use_site_verdict_behavioral_receipt_holds"), standing: PremiseInvalidated { diff --git a/dag/gunbc/roadmap/roadmap_component.dag b/dag/gunbc/roadmap/roadmap_component.dag index 74eb96ab15c..44ef823392c 100644 --- a/dag/gunbc/roadmap/roadmap_component.dag +++ b/dag/gunbc/roadmap/roadmap_component.dag @@ -27,7 +27,7 @@ import gunbc.roadmap_presentation { import gunbc.roadmap_belt_actuate { belt_dispatch_all_status_labels, belt_dispatch_label_is_ok, belt_dispatch_ok_status_labels, belt_dispatch_path_prefix, - belt_dispatch_label_band_rows, belt_dispatch_label_band_key, + belt_dispatch_label_band_rows, belt_dispatch_provider_label, belt_dispatch_disabled_status_label, } @@ -35,7 +35,7 @@ import extdeps.languages.typescript.program { TsProgram, TsExpr, TsStmt, serialize_typescript_program, ts_ident, ts_lit_str, ts_lit_num, ts_member, ts_call, ts_binop, ts_arrow, ts_block, ts_const, ts_let, ts_return, ts_new, ts_expr_stmt, ts_if, ts_cond, ts_prefix, ts_object, ts_field, - ts_array, ts_index, ts_try, ts_for_of, + ts_array, ts_try, } import extdeps.w3c.device_orientation_and_motion { devicemotion_event_type, device_motion_event_interface, @@ -55,14 +55,9 @@ import gunbc.design.sound { sound_mute_storage_key, } import gunbc.design.instrument_camera { - camera_storage_key, camera_wire_sep, camera_initial, - program_depth_key, DepthProgram, DepthOutcome, DepthFront, DepthNode, DepthEvidence, - program_mode_key, ModeStatus, ModeRemaining, ModeWhy, - focus_subject_key, NoSubjectSelected, - wheel_detent_threshold_px, wheel_gesture_reset_interval, - instrument_depth_keys, instrument_user_depth_keys, instrument_mode_keys, + DepthProgram, DepthOutcome, DepthFront, DepthNode, DepthEvidence, + ModeStatus, ModeRemaining, ModeWhy, } -import gunbc.v1_deletion_plan { v1_exit_finish_lines, v1_finish_line_key } import extdeps.web_audio { web_audio_context_interface, web_audio_create_oscillator_method, web_audio_create_gain_method, @@ -141,12 +136,6 @@ fn dispatch_button_terminal_count() -> Int { // phrases + dispatch-receipt and observed-session morphs) plus a fixed gutter. A caption or // ok-label change moves the reservation by derivation; there is no pixel to re-tune. - - - - - - fn dispatch_caption_set() -> List { concat([ dispatch_caption_idle, @@ -188,8 +177,7 @@ data dashboard_instance_label_class: String = "dashboard-instance-label" // instance banner. Observe-only is also projected onto every real dispatch control before // interaction: the control reads `dispatch · disabled`, carries the located posture reason, and is // physically disabled, while the server independently returns typed HTTP 403 if a stale or scripted -// client still POSTs. The /sandbox program deliberately omits this projection so its harmless -// wire-state gallery remains pressable. +// client still POSTs. fn dashboard_instance_fetch_statements() -> List { [ @@ -414,7 +402,6 @@ data roadmap_row_archetype_note: String = "The RoadmapRow archetype (composition data roadmap_row_height: ScaleToken = height_row data roadmap_row_gutter: ScaleToken = space_4 - // The operator-facing captions (remodel W1d, operator ruling 2026-07-24; lifecycle correction // 2026-07-27): ok keeps the exact belt status under the dispatch-receipt prefix, while fail and // loud collapse to one operator phrase each with the wire label and located fields in the @@ -448,55 +435,12 @@ data disclosure_mark_class: String = "disclosure-mark" data disclosure_open_class: String = "disclosure-open" data disclosure_mark_glyph: String = "›" - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - // The toggle paints itself from the same predicate the tick reads, then repaints after each flip, // so the label is a projection of the stored state rather than a second copy of it — a toggle whose // label and behaviour can disagree is worse than no toggle. paint() runs once at bind time because // the stored preference outlives the page: on load the label must already say what this browser // will actually do. - - // The single authority for a state's CSS modifier class, consumed by the client script (which flips // classes on the live button), the stylesheet (which paints each class through the state's role // material), and the P4 gallery (which renders each state statically) — three consumers, one class @@ -504,36 +448,8 @@ data disclosure_mark_glyph: String = "›" // the terminals collapse to their ok/refusal MATERIAL group (figure vs boundary), the per-label // distinction living in the text, not the color. -fn dispatch_state_class(state: ComponentState) -> String { - match state.kind { - IdleState => "" - RequestedState => dispatch_class_requested - TerminalState { wire_label: wl, ok: ok } => - if ok { - dispatch_class_ok - } else if belt_dispatch_label_band_key(wire_label: wl) == "loud" { - join([dispatch_class_refused, " ", dispatch_class_loud], "") - } else { - dispatch_class_refused - } - } -} - -// The dispatch button's client behavior, modeled in native .dag as ONE TsProgram -// (extdeps.languages.typescript.program) — never a hand-concatenated JS string (the dispatch-button -// incident's root class, §5). It is EMITTED as an external served asset -// (gunbc.roadmap_dispatch_asset_path, served by belt B) and referenced by