Repository navigation
RFM amendment: witness_module_absent_from_the_executed_set gains the standing-main-red specimen - #13523
Conversation
A silent main red: dag/test/claim/self_host_emitted_call_target_realization_witness_test.dag w_depth_one_shared_field_refutation_stays_shape_guarded fails against origin/main's own tree (claim_batch claim-run exit=1, FAIL=1, measured 2026-10-07 on the remote runner). No gate executes that entry on main pushes -- the required floor selects witnesses by an integration head's diff -- so the red stays silent until an unrelated PR touches the entry and inherits it. Row records the specimen, the attribution discipline (run the entry on main's own tree before blaming a PR), and the next rung (a main-push/scheduled full-corpus mode). Discovered while verifying PR #13460's floor; recorded here, out of that PR's scope, per coordinator ruling.
…er meetable A red witness on main stays writable; a full-corpus gate would only expose and block it (rung 2, mechanically preventable) — rung 3 was inflation. The gate needs operator sign-off: the push-on-main trigger was CUT 2026-09-15 and adding a job needs sign-off, so the next-rung trigger is the operator signing off a scheduled, not push-triggered, full-corpus claim lane on the existing runner.
…s count into prose (§6)
briansrls
left a comment
There was a problem hiding this comment.
Reviewing exact head 4f0717ca956ff4d8c816b6fc8015ed1d3bb7634f: the specimen is real, but this must not land as a new RFM row yet.
-
This is already an existing failure class, so the new file forks its authority.
gunbc.recurring_failure_mode.witness_module_absent_from_the_executed_setexplicitly records the same consequence: a claim module outside the executed set is free to break and stay red indefinitely, with no required verdict reporting it. Its receipts already include silently red witness entries whose defect survived because of schedule membership. The narrower neighbourwitness_outside_gate_closure_falsified_by_other_fileowns the outside-gate + changed-witness-only shape and already carries population-scale red-on-main receipts. This specimen should update the existing row. If a bisect later proves a different file falsified this witness, it belongs as another receipt on the narrower row; the current evidence proves onlyred on pristine main + outside standing execution, which the first row already owns. -
The current rung is not mitigatable. The invalid state named here is a required system reporting green while a committed witness is red. No total operation, typed outcome, bound, rollback, or isolation contains that harm. A chance manual corpus run, the next PR that edits the entry, and attribution diligence after discovery are not mitigation. This is the silent-wrongness state below the ladder, exactly as the existing
witness_module_absent_from_the_executed_setrow explains. Rung 2 is a plausible ceiling, but only once a mechanism reliably executes the population and gives a red/non-verdict a declared blocking or remedy consequence. -
The trigger names approval, not the capability. DESIGN 4b requires the trigger to name the capability and retire only when that capability exists. Operator sign-off for a scheduled lane is one prerequisite; it does not execute a claim, publish a verdict, or block anything. No push-on-main revival is required, but the trigger must be the implemented and enrolled scheduled full-corpus lane, its exact population, its red/non-verdict consequence, and an observation that a planted or standing red makes that lane fail. A scheduled report with no consequence is an instrument, not rung-2 prevention.
-
Tighten the evidence grain and mechanism statement. Cite the specimen as the qualified symbol
test.claim.self_host_emitted_call_target_realization_witness_test::w_depth_one_shared_field_refutation_stays_shape_guarded, with the path only as convenience. Bind the historical receipt to an immutable main SHA and run/job or retained receipt;origin/mainis mutable. Also replaceno gate ever sees itandonly on main: the ordinary floor declines the module outside the gate closure, while changed-witness selection can execute it when its own test declaration is edited, and every unrepaired descendant of the measured main SHA inherits the red.
The ceiling correctly stops at rung 2 rather than claiming structural prevention, and all five exact-head lanes are green. The blockers are single-authority placement, rung honesty, trigger sufficiency, and immutable evidence.
…ess_module_absent_from_the_executed_set instead of filing a new row The class already owns 'red on main + no standing required execution'; my new row duplicated it. The specimen moves in as a receipt, cited by qualified symbol (test.claim.self_host_emitted_call_target_realization_witness_test::w_depth_one_shared_field_refutation_stays_shape_guarded), with the honest fields: the class is found at silent wrongness BELOW the ladder, the ceiling is rung 2, and the next-rung trigger is a scheduled full-corpus lane implemented and enrolled -- defined claim-root population, refusing or invoking a declared remedy on every red or non-verdict, demonstrated failing on a planted or standing red -- not an operator sign-off. If a later bisect names the falsifying change, witness_outside_gate_closure_falsified_by_other_file gets a receipt too. SCOPE CHANGE: the PR is now an amendment of an existing row (the new file is deleted), not a new row.
…n immutable sha and state the exclusion mechanism precisely (a) The specimen is now measured at main's immutable sha 1728bcc (census phase 3, #13415) -- claim_batch claim-run at that sha, exit=1, FAIL=1, BuildBuddy dispatch completed 2026-10-07T08:27:47.537Z, discovering session job j36fc601a, command and output retained in the session transcript -- and every unrepaired descendant of that sha inherits the red. (b) 'no gate ever saw it' and the main-only framing are replaced with the precise mechanism: the ordinary prepared subject excludes modules outside the required-gate closure, and changed-witness selection replaces that disposition only when a diff selects the identity -- which is exactly how the red surfaced.
briansrls
left a comment
There was a problem hiding this comment.
Approved at ef063c3f29b83e9483be26c13d8e69018da4c59f.
All four prior blockers are closed:
- The duplicate RFM row is gone. The exact diff is one new receipt on the existing single authority,
gunbc.recurring_failure_mode.witness_module_absent_from_the_executed_set. - The row's existing standing remains honest: rung 2 only “on paper,” below the ladder in fact because no executing/enrolled mechanism holds it. The new receipt expressly keeps manual attribution as diligence, not a rung, and caps the class at rung 2 because a scheduled lane would expose/block the writable bad state rather than make it structurally inadmissible.
- The trigger now names the capability, not operator approval: an implemented and enrolled scheduled full-corpus claim run over a defined claim-root population, with a declared refusal/remedy for every red or non-verdict, observed failing on a planted or standing red.
- The specimen is cited by qualified symbol and bound to immutable main SHA
1728bcc0ab4e7d8285359f161612d4c1226812f2, theclaim_batch claim-runproducer, and BuildBuddy jobj36fc601a. The mechanism wording is also narrowed correctly: no standing gate executed it; changed-witness selection only replaces the ordinary outside-closure disposition when the diff selects an identity. “Every unrepaired descendant” avoids the earlier false “only on main” claim.
The raw output living only in the worker transcript is acceptable for this historical receipt because the subject and re-executable producer are immutable and named; the row is not using the transcript as a standing measurement authority.
Nonblocking: the PR title still says “RFM row” although the final change amends an existing row. The body makes the scope change clear.
AMENDED per side chat review 5439001746: the class is EXISTING -- gunbc.recurring_failure_mode.witness_module_absent_from_the_executed_set already owns 'red on main + no standing required execution' -- so this PR no longer files a new row. SCOPE CHANGE: it now (1) amends that row with the measured specimen as a receipt, cited by qualified symbol (test.claim.self_host_emitted_call_target_realization_witness_test::w_depth_one_shared_field_refutation_stays_shape_guarded; claim_batch claim-run at origin/main, exit=1 FAIL=1, 2026-10-07), and (2) deletes the previously-added new row. The receipt keeps the fields honest: found at silent wrongness BELOW the ladder (manual attribution is a discipline, not a rung), ceiling rung 2, next-rung trigger a scheduled full-corpus lane implemented and enrolled -- defined claim-root population, refusing or invoking a declared remedy on every red or non-verdict, demonstrated failing on a planted or standing red -- not an operator sign-off. If a later bisect names the falsifying change, witness_outside_gate_closure_falsified_by_other_file receives a receipt too. Parse-check: 0 blocking on main's tree.