Skip to content

ta.txt - #13594

Closed
briansrls wants to merge 80 commits into
mainfrom
session/witty-tern-54
Closed

ta.txt#13594
briansrls wants to merge 80 commits into
mainfrom
session/witty-tern-54

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session witty-tern-54.
Pushing to session/witty-tern-54 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

Brian Searls added 30 commits October 3, 2026 20:05
…nd everywhere

The seven string-glued builders (systemd_run_property_argv,
systemd_run_user_transient_arguments, systemd_run_user_wait_arguments,
systemd_run_system_scope_argv, systemd_run_property, systemd_run_transient_unit_argv,
systemd_run_transient_wait_unit_argv) are deleted. In their place:

- SystemdRunOption, a sealed sum whose arms carry systemd-run(1)'s own spellings at
  systemd 255 (the major the summary ground reads): RunUnit, RunUserManager, RunScope,
  PropertyShort, PropertyLong, SetEnv, Wait, Quiet, Pipe, Collect, EndOfOptions.
- systemd_run_option_words, ONE projection from options to words, with refusals at the
  wall: a unit name carrying / or a newline, a property value carrying a newline, a
  setenv name carrying = (the wire cannot carry them; they are refused, not trimmed or
  split). An unknown flag has no arm to ride: the sum is closed and the projection's fold
  walks every variant.
- Every builder returns ArgvCommand through SystemdRunCommandReading
  (Ready | Refused); extdeps.exec.command's admit list now admits
  systemd_run_command_of.
- The service operations take the projected words and the transport template leads with
  the declaration literal, per the materializer's executable-position contract.
- Callers migrated: roadmap_dispatch_actuator (the four unit mints return readings; the
  belt layer composes the resolved program head with the projected words, refusals land
  in ExecRefused/ExecStepFailed), runner_microvm_lifecycle_realize,
  runner_throughput_qualification_route, compute.work_provider_local,
  compute.unit_bounds (the grant fold now yields typed properties), auth
  approval_device_enrolment_code_issue, gunbc.systemd_run_transient (the bridge carries
  the typed command end to end; the authority check joins the materialized words against
  the one projection's words), host_effect_nbd_proxy_serve.

Evidence: positive controls pin the projected words byte-identical to the words the
string-built forms rendered for existing callers (wait witness, user-wait witness,
review-unit option words, nbd wire-name witness); reds witness a newline in a property
value, a slash in a unit name and an = in a setenv name refused at the projection.
SystemdUnitProperty is widened with the seven real settings the dispatch units bind
(StandardOutput, StandardError, ProtectSystem, ProtectHome, PrivateTmp, ReadWritePaths,
RemainAfterExit) so no property travels as a free-form string.

Debt paydown trial, session witty-tern-54. The census instrument
(gunbc.instruments.argv_word_construction_census) counts this population; this module was
its specimen row set. CI-lane claim batch over the eight affected witness files: 20 pass,
0 fail.
…-systemd-run

# Conflicts:
#	dag/gunbc/roadmap/roadmap_belt_actuate.dag
…o the reading; the property-overlap fold walks the widened enum
…-systemd-run

# Conflicts:
#	dag/gunbc/runner/runner_microvm_lifecycle_realize.dag
#	dag/test/claim/runner/runner_microvm_slot_controller_witness_test.dag
…ed builder; the property-overlap fold walks the widened enum

- dag/test/claim/approval_device_enrolment_code_witness_test.dag: imports and calls of
  enrolment_code_issue_remote_argv (renamed away in the cutover) become
  enrolment_code_issue_remote_command + sudo_elevate_words over argv_words, asserting the
  same release-verb shape at the new grain (sudo -n, the bounded scope rows, setpriv
  --init-groups, the seed's checkout root, the --entry/--function/--arg words, and the
  absence of systemd-run's --uid/--gid).
- dag/gunbc/systemd_property_directive_overlap.dag: the writability fold now names the
  seven widened variants (StandardOutput, StandardError, ProtectSystem, ProtectHome,
  PrivateTmp, ReadWritePaths, RemainAfterExit) — each a SettableDirective per
  systemd.exec(5)/systemd-run(1) at v255.
- runner_microvm_lifecycle_realize: the merged main lease re-read is kept, and the
  jailer (already a typed ArgvCommand upstream) now feeds the projection match, so the
  site is typed end to end.

Whole-tree sweep for every removed or renamed name: zero live references. Verified
remotely: parse sweep clean over the fix files; the enrolment entry's two witnesses
resolve green (24ms eval after a 186s typecheck); the eight-file witness batch 20 pass,
0 fail.
…-systemd-run

# Conflicts:
#	dag/gunbc/runner/runner_throughput_qualification_route.dag
…ion (bare -N never reaches a terminal verdict)
…inition site (expected-red enrolment deliberately refused)
… refusal widened with the carried reason (main gained a consumer of the renamed builder)
…gative controls folded into assertions of absence (refusal sentinels + degenerate counts), one-hot designed-false claims deleted
…ained transient builder without --collect; FleetSsh wait refusal restored; ComputeExecRefused arm (type + run arm + UnitLaunchRefused cause); non-wait builder order restored
…-systemd-run

# Conflicts:
#	dag/extdeps/systemd/systemd.dag
…l arm; compute tail fix; retained builder migrated into realize + wet receipt; --user restored on the scope builder; per-builder byte-identity controls; token-equal carries the length check
… stays observable (loaded) vs collected twin (not-found) vs waited exact exit 86, through real systemd-run
…roperty union with main renamed the field's type)
…he value as two words (blob 71a9a1c~1 list_push(list_push(acc, -p), p)); the 11-word cardinality control confirms the shape
…; compute_spawn_and_collect's outcome match arms ComputeExecRefused as WorkCancelled (nothing was spawned)
…tes/list_string_params); fix data_decl_reaches_argv kw name
…ped builders: roster wrappers around the three typed launch matches, length-prefixed attempt identities + head_sha events path, wet receipt to test/manual (out of hermetic discovery), scope builder --scope-only and transient order --unit,properties,--collect per main's nbd witness (landed authority over retired blob order), controls flipped
Brian Searls added 25 commits October 5, 2026 20:57
…ort the filesystem outcome type with the variants, and turn the fact-name if into match arms (constructor-valued if branches do not parse)
…/ read.content), the shape the tsic pin claim uses in a test module -- variant matching on the effect outcome does not resolve there
…al wildcard sites the new diff-scoped residue scan requires rostered (they predate the typed-argv cutover; the cutover's diff touched the module, which is what arms the scan) -- four FrontierRows with reason + dissolution, the population the ratchet may only shrink
…tside the modeled roots by design, so the per-root emitters never see it; this runs the same lens over the fixture directory alone so the fixture claims' expectations are checked against the lens's own rendering
…s_dump writes one TSV row per fact with every pinned field, so the fixture claims' expectations are aligned to the lens's output rather than a hand-maintained parallel list
…ule) — the wet lane's entry loader refuses entries bearing test functions, so the dump needs a non-test entry; the claims import the reading from there
…only loads dag/ entries) and reads at the FACT level — read/parse/facts_of, the same route the fixture claims use, since for_paths refuses any module outside the modeled roots; the test file is restored to its reviewed shape
…tch arms are an unproven shape; function-body lets are the shape for_paths proves
…std.node (the lens does not re-export it), the module already imported Bool (duplicate import dropped), and bool_word keeps a single definition
…l list — the hand-counted nested concat had an extra close-paren (27 open, 28 close), which is the grammar error the entry validation kept refusing
… identity as the instrument, and the loader refuses the collision (DESIGN §3, one module one authority)
… observed through the instrument's fixture_facts_dump — data decls render unnamed (fact_name fallback) and are not members; the candidate class is now the fn that spells flags (fixture_waits_quietly: 2 candidates, not counted); the reach to commit_args shows on the reaching fn (transient: counted, 2 flag words). Members = 4, data decls = 3, facts = 7
…lti-let match arm is an unproven shape (the same one the instrument dump already had to shed)
…ilter lambdas use their own parameter, and the transient match binds member (a bare f resolves to declaring_identity_spelling/shorter.dag, whose bare channel is off)
… dissolution (the matches spelled exhaustively in a change that edits work_provider_local.dag) is already met by the queued #13257, which spells all four matches exhaustively over their closed coproducts and deletes these rows; a trigger the same diff already meets is not a trigger
# Conflicts:
#	dag/extdeps/systemd/systemd_run.dag
#	dag/gunbc/compute/unit_bounds.dag
#	dag/gunbc/compute/work_provider_local.dag
#	dag/gunbc/roadmap/roadmap_dispatch_actuator.dag
#	dag/gunbc/runner/runner_host_unit_slot.dag
#	dag/test/claim/github_app_registry_witness_test.dag
#	dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag
… drop (the four wildcard rows left with #13257); the auto-merge left stray closers — take main's file whole
…omed the module after this branch was cut
…cus + grammar validation) ONCE per walk and thread it — measured ~120s fixed per module_sites call x 158 extdeps modules was hours; the per-file callers keep raw_tree_of_text as a wrapper
@briansrls
briansrls marked this pull request as ready for review October 8, 2026 20:25
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T20:33:18.727671Z c03581a Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Closing: this PR was opened automatically from witty-tern-54's work-in-progress branch when that lane was archived during the operator-directed wind-down. It is not ready, and review 78130 is right on both counts: (1) src/v1/stage0/tests/argv_parse_probe.rs is a throwaway probe that must not land; (2) the census roster and baseline are empty because the recount never ran (the per-root emitters don't fit the runner; the next step is a partitioned recount emitter). The branch session/witty-tern-54 is kept as-is for whoever resumes the argv census; the remaining steps are in the lane's hand-off. No merge intended. — sent from lively-ram-153

@gunbai-bot gunbai-bot Bot closed this Oct 8, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c03581af90

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"src/v2/lens/argv_word_construction.dag",
"dag/gunbc/instruments/argv_word_construction_census.dag",
"src/v2/test/claim/argv_word_construction/census_test.dag",
"test/fixture_roots/argv_word_construction/host_words.dag",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Point the parse probe at the committed fixture

Every run of this Rust test panics in parse_path before parsing anything because this path does not exist; the committed fixture is at src/v2/test/fixture_roots/argv_word_construction/host_words.dag. Any CI lane running the workspace tests will therefore fail unconditionally.

Useful? React with 👍 / 👎.

// THE ROSTER: one row per live census member. `note` names what the site is and what pays it.
// Kept at zero rows until the first committed recount fills it from the instrument (never by
// hand from a text search).
data argv_word_construction_census_roster: List<ArgvWordsRosterRow> = []

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Populate the census roster before enabling the gate

With this roster empty and the baseline set to zero, argv_word_construction_census_roster_modules() returns no paths, so committed_census_holds_its_own_contract calls check_paths([]) and succeeds without inspecting either modeled root. The corpus already contains many matching List<String> builders (for example the argv functions in dag/extdeps/tools/id.dag), so new or existing string-built argv cannot be rejected until the initial recount is committed here.

Useful? React with 👍 / 👎.

Comment on lines +425 to +427
let name_node = match find_named_child(root: decl, name: ^dag_surface_data_decl_name) {
Accepted { value: n, diagnostics: _ } => Present { value: n }
Rejected { diagnostics: _ } => Absent

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Decode data declarations from the raw parse shape

When this lens is entered through raw_tree_of_text, data declarations are parse-shaped grammar sequences, not the emit-shaped nodes carrying dag_surface_data_decl_* named edges. The existing dual-shape decoder documents and handles this distinction in src/v2/lens/mandatory_tag.dag:76-85; without the equivalent spine fallback here and for the type/expression lookups below, every fixture data declaration becomes <unnamed data> with empty type and expression atoms, so the census silently misses its entire advertised data-declaration population.

Useful? React with 👍 / 👎.

@@ -0,0 +1,316 @@
module v2.test.claim.argv_word_construction.census_test

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enroll the census claims in witness discovery

This test is outside all configured discovery roots: witness_discovery_scan_dirs in dag/gunbc/ci/ci_layer_roots.dag:311 scans only dag/test/claim, src/v2/test/claim/manual, and src/v2/test/claim/emit. Consequently none of the new census claims, including the purported committed-contract check, execute in the required claim lane; move or explicitly enroll the file so regressions produce a CI verdict.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant