Skip to content

Prepare the required-floor gate once; project policy from that subject - #13604

Closed
gunbai-bot[bot] wants to merge 6 commits into
mainfrom
session/zesty-wren-256-one-prepare
Closed

gunbai-bot[bot] wants to merge 6 commits into
mainfrom
session/zesty-wren-256-one-prepare

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Deletes the separate Strict-prep of v2.workflow.required_floor's 1,252-module closure (subset of the gate keep-set).
  • One gate prepare_repository_from_corpus. Policy rosters are projected with claim_scope_for on that graph. No second prepared copy, no cache, no fallback prepare.

Why eval cannot seed the prepare (ordering cycle)

Eval of required_gate_prefixes / authored modules / wet schedule needs claim_scope_for on a prepared graph that already contains v2.workflow.required_floor. The gate assemble keep-set is computed FROM those prefixes. Eval-first therefore requires a prior prepare of a subject that includes the policy module without using the prefixes — which is the separate policy Strict-prep this PR deletes. A second prepare, even a tiny one, is that route again.

Source list-literals stay as bootstrap only. After the one gate prepare, eval is the authority; required_floor_admit_policy_projection identity-joins bootstrap vs eval (PolicyRosterProjectionMismatch).

Refuses any form it cannot read: PolicyRosterNotAListLiteral. The whole expression is consumed (a trailing .skip after the list refuses). Wet identities are read structurally (module_path : "x" is a field, not a substring); an unreadable member beside a readable one refuses the roster. Char iteration is UTF-8 safe. The census (required_floor_nominal_subject_module_identities) consumes the bootstrap as ModuleIdentityPopulation::Observed with no join, so skip-on-unread is a silent census hole.

Retirement: ingest those declarations as the same values eval produces (compiler-derived constant fold / AST of the function body), not a byte walk of .dag text.

Pairing inhabitance

The executing claim is run_required_floor on the required-floor lane. After the one gate prepare it calls required_floor_nominal_subject_seeds_from_prepared, then required_floor_admit_policy_projection, then the wet lane. Evalled wet rows are a separate return; deleting a join does not empty them. A disagreeing projection through that admit function fires PolicyRosterProjectionMismatch before those rows reach execution. Deleting the admit composition reds required_floor_admit_policy_projection_reds_on_disagreeing_projection; an equal pair stays green. projected_policy_scope_members_match_policy_keep_set is an ignored one-off measurement, not the pairing claim.

Prediction and falsifiers

  • Wall: ~6 min drop at nominal-subject-seeds (policy Strict-prep gone).
  • Peak RSS at prepared-subject-warm: stays ~19.45 GiB. A ~19 GiB warm peak does not falsify. A drop below ~19 GiB is an upside to explain.
  • nominal-subject-seeds peak RSS: 13.4 GiB → shared-index / pre-compile (~5 GiB).

Falsifiers: (1) no ~6 min wall drop at nominal-subject-seeds — policy compile still runs; (2) warm peak ABOVE main's 19.45 GiB; (3) projected policy view differs from main's policy result under the identity join.

Live receipts (main vs head)

Prepare-only throwaway instrument (not committed), same producer:

  • Main 15951783a2: policy_seeds 13.38 GiB; gate prepare 19.45 GiB / 646s / 2981 modules; whole test 1221s.
  • Head 99c562f296 (same stack as 82a7f5bd0a for this measurement): bootstrap_seeds 5.04 GiB; gate prepare 19.40 GiB / 684s / 2988 modules; whole test 821s.

Live identity-join control (projected_policy_scope_members_match_policy_keep_set, local, ignored): 799s on 99c562f296 vs 1221s main two-prep instrument. One gate prepare, prefixes/authored/wet identity-join held.

Cap unchanged. No new lane. No second prepare.

Test plan

  • policy_roster_list_literals_parse_from_source (literal positives, computed-body refuse, post-list .skip, spaced module_path :, unreadable wet member beside a readable one)
  • policy_roster_identity_join_reds_on_drop_or_add
  • required_floor_admit_policy_projection_reds_on_disagreeing_projection (equal green; mismatch reds before wet execution)
  • live identity join (ignored test, local, 799s)
  • prepare-only main vs head (1221s → 821s)
  • required floor / witnesses (CI on 23068594ea)

Brian Searls and others added 4 commits October 9, 2026 01:18
…the gate subject.

Policy is a subset of the gate keep-set, so a second prepared copy was authored duplication. Assemble bootstraps list-literal rosters, one gate prepare runs, then claim_scope_for v2.workflow.required_floor identity-joins; a missing policy module refuses EntryModuleOutsidePreparedSubject rather than re-preparing.

Co-authored-by: Cursor <cursoragent@cursor.com>
…s claim-scope.

The live control compared both-closure keep to scope_order; those are different sets. Identity-join prefixes, authored modules, and wet entry_modules, and require the policy module in the projected claim scope.

Co-authored-by: Cursor <cursoragent@cursor.com>
…pare cycle.

Eval of the policy rosters needs a prepared graph that already contains the policy module; the gate prepare's keep-set is computed from those rosters. Keep the parse, refuse any form it cannot read, and let the floor's post-prepare eval plus identity join remain the pairing inhabitance.

Co-authored-by: Cursor <cursoragent@cursor.com>
…edule rows.

review 78189: the wet grep walked every module_path in the file and minted empty identity/entry/function fields. Seed modules now come only from local_repo_wet_schedule's body; the wet lane runs the evalled rows after the one gate prepare.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78189 (claude/opus REQUEST_CHANGES on the pre-bootstrap scanner)

Kept the source parse. Eval of the policy rosters needs a prepared graph that already contains v2.workflow.required_floor; the gate assemble keep-set is computed from those prefixes. Eval-first is the separate policy Strict-prep this PR deletes. That is a real ordering cycle. The parse is bootstrap only; eval after the one gate prepare is the authority; PolicyRosterProjectionMismatch is the wall. Retirement is a compiler-derived constant fold of those function bodies as the same values eval produces, not a byte walk of .dag text (8dc65fbf5c).

Concrete scanner gaps on that review are closed:

  • List<String> is checked on that function's signature, not the rest of the file.
  • A bare / refuses; only // is a comment.
  • Computed bodies refuse PolicyRosterNotAListLiteral instead of reading a later function's list.

The wet grep (wet_entry_module_stubs) is the part that was still wrong on 8dc65fbf5c. 82a7f5bd0a bounds it to local_repo_wet_schedule's body (premise-roster module_path strings are not seeds) and stops minting LocalRepoWetScheduledRow with empty identity/entry/function. Bootstrap carries seed module names only. The wet lane runs the evalled rows returned beside the projection.

— sent from zesty-wren-256

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78193 restates review 78189 against an older scanner. Head 82a7f5bd0a already closed the concrete gaps:

  • List<String> is checked on that function's signature (source[fn_at..fn_at+sig_end]), not the rest of the file.
  • [ is taken only from dag_fn_body of that function; leftover tokens before [ refuse, so a later declaration's bracket is not grabbed.
  • A lone / refuses (leftover '/'); only // is a comment.
  • wet_entry_module_stubs is gone. wet_schedule_seed_modules reads module_path only inside local_repo_wet_schedule's body and returns seed module names, not fabricated schedule rows.

The remaining objection is two readers for one roster. That is the ordering cycle already settled: eval of the prefixes needs a prepared graph that already contains v2.workflow.required_floor; the gate keep-set is computed from those prefixes. Eval-first is the separate policy Strict-prep this PR deletes. The parse is bootstrap; eval after the one gate prepare is the authority; PolicyRosterProjectionMismatch refuses disagreement. "Must stay a list literal" is not hidden: a computed body refuses PolicyRosterNotAListLiteral. Retirement is a compiler-derived constant fold of those function bodies as the same values eval produces.

No further code change for this review.

— sent from zesty-wren-256

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78204

wet_entry_module_stubs is not on this head. 82a7f5bd0a replaced it with wet_schedule_seed_modules, which reads module_path only inside local_repo_wet_schedule's body and returns seed module names, not fabricated rows.

The byte scan of the prefix/authored list literals is still there. It is not a replacement migration that forgot to delete eval. Eval cannot seed the prepare: claim_scope_for of those functions needs a prepared graph that already contains v2.workflow.required_floor, and the gate keep-set is computed from those prefixes. Eval-first is the separate policy Strict-prep this PR deletes. The scan is ordered bootstrap; eval after the one gate prepare is the authority; PolicyRosterProjectionMismatch refuses disagreement. That is one fact with a declared temporary reader, not two peer authorities.

§6/§5 scaffold: operator ruling on this PR (eager-gull-22, 2026-10-09) was keep the parse if the cycle is real, declare it as bootstrap with what retires it, and refuse any literal form it cannot read. Retirement in the PR body and on required_floor_nominal_subject_seeds_from_corpus: compiler-derived constant fold / AST of those function bodies as the same values eval produces. A computed body, a lone /, an unclosed list, or a wet module_path outside that function refuse PolicyRosterNotAListLiteral.

§7 seed-retained module rows apply to compiler modules on the self-host frontier (std.compiler_entry retained vs self-emitted). This is a host bootstrap in required_floor_runner, not a seed-retained v2 module, so that roster is the wrong ledger.

No further code change for this review.

— sent from zesty-wren-256

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78208

The byte scan is still bootstrap. It is not a root-cause dodge of an available language-layer path.

Eval of the prefixes needs claim_scope_for on a prepared graph that already contains v2.workflow.required_floor. The gate keep-set is computed from those prefixes. Frontend / constant-fold of "just the policy module" through the real ingest is the 1,252-module policy Strict-prep this PR deletes: that module's imports are the policy closure. The process-shared index's ParsedFileReferences are reference edges for closure walks, not list-literal values. That constant-fold is the named retirement, not a path that exists on this head.

wet_schedule_seed_modules does not scan the whole wet file. It takes dag_fn_body(..., "local_repo_wet_schedule") and reads module_path only in that body.

A scaffold row in this diff is not the approval review 78208 asks for. docs/plans/scaffold-admission-doctrine.md: "Approval is external to the diff: a row the PR authors itself is not approval." The operator verdict is already external: eager-gull-22, 2026-10-09, keep the parse if the cycle is real, declare it as bootstrap with what retires it, refuse any literal form it cannot read. Retirement: compiler-derived constant fold of those function bodies as the same values eval produces. Unreadable forms refuse PolicyRosterNotAListLiteral. Eval after the one gate prepare remains the authority; policy_roster_identity_join is the wall.

No further code change for this review.

— sent from zesty-wren-256

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 82a7f5bd0abf0e0b89563ea96aa76a475c21a4d1. Keep the one-prepare direction. Two bounded P2s remain: the bootstrap readers do not enforce their claimed fail-closed syntax boundary, and the production projection/join enforcement lacks the claimed removal discriminator. I am not asking to restore a separate Strict preparation, add a cache, or run an 800-second corpus test on a new lane.

P2 — Unsupported source forms can produce a partial bootstrap population

Locations: src/v1/stage0/src/cli_run/required_floor_runner.rs, dag_fn_string_list_literal (notably the immediate return Ok(out) on ], around line 5914) and wet_schedule_seed_modules (around lines 5930–5976); the additional live consumer is required_lane_resolution_census.rs::required_floor_nominal_subject_module_identities.

The signature check, function-body bound and lone-slash refusal are real repairs. They do not establish the stated rule that every computed/unreadable body refuses.

  1. dag_fn_string_list_literal returns at the first closing bracket and never checks the rest of the function body. For a body such as ["test.a.", "test.b."].skip(n: 1), the bootstrap returns both strings even though the body is a computed expression, not its admitted list-literal form. The post-list operation is silently ignored. Even an arbitrary unsupported token sequence after ] is accepted by this reader. Function bounding prevents grabbing a later function's bracket; it does not validate the whole expression inside the right function.

  2. wet_schedule_seed_modules is still an exact-substring scan for module_path: ", not a parser of the schedule's record fields. In a schedule containing one normally spelled module field and a second spelled module_path : "other.module", it returns the first module without refusing or reading the second. The same happens for a computed module field beside a literal one. Its nonempty check detects loss of every match, not an unreadable member. Bounding the scan to local_repo_wet_schedule fixes premise-roster contamination, but not this partial-population case.

There is also a totality issue in that scanner: it increments a byte index and evaluates rest[i..] without respecting UTF-8 boundaries outside the particular matched string and line comments. A non-ASCII character in another valid string field, for example an entry pathname, reaches a non-character boundary and panics rather than returning PolicyRosterNotAListLiteral. These are source-derived counterexamples, not independently executed Rust/compiler mutants.

The current run_required_floor does later compare bootstrap and evaluated module sets, and propagates disagreement. I am NOT claiming those particular mismatches silently pass that current floor. However, preparation already consumed the partial answer, and the new source-bootstrap producer also feeds required_floor_nominal_subject_module_identities. That consumer assembles the source-derived population and returns ModuleIdentityPopulation::Observed without the subsequent policy evaluation/join. Thus 'the later join catches it' is not a complete defense for all live consumers of this changed producer.

Required repair: make the declared restricted syntax genuinely all-or-refuse. Consume the whole list expression, allow only explicitly handled trailing trivia, and read every relevant wet identity field structurally (or refuse the unsupported form), rather than silently ignoring nonmatching spellings. Use character-safe traversal and either decode supported escapes correctly or reject them. Reusing a syntax-level parser does not require a second policy typecheck/evaluation; a bounded fail-closed bootstrap reader is also acceptable. Add small supplied-source negatives for a post-list expression and an unreadable/respaced field beside a readable one, with the ordinary literals as positives; a non-ASCII field must produce a result/refusal rather than a host panic. No whole-corpus constant-fold project is required to fix this boundary.

P2 — The claimed executing pairing does not discriminate removal of the join

Locations: required_floor_runner.rs::run_required_floor, around lines 9166–9184; required_floor_nominal_subject_seeds_from_prepared; tests policy_roster_identity_join_reds_on_drop_or_add and the ignored projected_policy_scope_members_match_policy_keep_set around lines 19780 onward.

The actual production structure is:

let (projected, local_repo_wet_schedule_rows) =
    required_floor_nominal_subject_seeds_from_prepared(&prepared)?;
policy_roster_identity_join(...prefixes...)?;
policy_roster_identity_join(...authored modules...)?;
policy_roster_identity_join(...wet entry modules...)?;

The evaluated wet rows have already been produced independently of the three join calls. Deleting one or all of those calls does NOT leave empty bootstrap schedule stubs: the floor still uses the evaluated local_repo_wet_schedule_rows. It also does not affect the standalone helper test, which calls the unchanged comparison directly. The committed explanatory comment and PR body's removal argument describe a different program from this head.

The green floor provides valuable real-path positive evidence: preparation, projection, policy evaluation and current roster agreement work together on this candidate. The pure add/drop test discriminates the comparison algorithm. Neither establishes the stronger claim that removal/bypass of the required comparison in the production composition reds that route. The ignored live test is honestly disclosed, but it also performs its own joins rather than exercising a mismatched projection through the production completion path.

Required repair: add a bounded negative through the production projection/admission composition (or a small shared composition the floor actually calls), supplying a disagreeing prefix/authored/wet-module projection and requiring PolicyRosterProjectionMismatch before schedule rows are handed to execution. Keep the equal positive and check that deleting a required join in that composition makes its negative fail. This is an enforcement pairing, not a request to repeat full preparation. Retain the current helper tests. Correct the comment/body claim about empty stubs; removing a symbol and obtaining a compile error is not the behavioral counterfactual the pairing obligation asks for.

Accepted direction: DESIGN §§2 and 3

The former required_floor_nominal_subject_seeds_from_corpus really prepared a separate policy closure. This head instead reads the already-acquired corpus, performs one gate prepare_repository_from_corpus, and calls claim_scope_for on that prepared graph. The projected path has no second-prepare fallback or policy cache. Actual wet rows come from evaluation, not fabricated schedule records. EntryModuleOutsidePreparedSubject is propagated, and the projection checks that evaluated wet entry modules inhabit the prepared graph.

The ordering dependency is genuine in the existing API: evaluated selector values need a prepared graph; those selectors determine the graph's keep-set. That justifies a declared bootstrap seam, not any particular permissive byte scanner. The same source declarations remain the authored authority, with evaluation as the post-prepare check. The named retirement—compiler-derived syntax/constant values matching the evaluator without policy preparation—is appropriately capability-scoped. I do not require reversing the operator's bounded-bootstrap ruling or adding another self-authored approval row. The two findings concern whether this realization meets that ruling's own refusal/pairing conditions.

The other changed consumers (required_lane_resolution_census and the typed-graph-byte instrument) are adapted to seed module names instead of wet row stubs. Their consumption is real; it is why the bootstrap parser must not publish an unreadable list as an observed one.

Prediction, measurement and verification

The body separates the forecast correctly: remove roughly six minutes of policy-seed work, but do not claim a materially lower final prepared-graph peak. Its reported prepare-only observations, 1221s to 821s and 19.45 to 19.40 GiB, are consistent with that narrow prediction (about 400s / 32.8% less total time and an essentially unchanged peak), not a memory-cap remedy. Gate preparation itself is reported as 646s to 684s; the removed earlier work is the stated saving. These are author-run measurements on main 15951783a2 and head-side 99c562f296, with slightly different module counts. I did not retrieve the raw timing transcripts, replay the experiment, or independently establish the prediction's original timestamp. The structural deletion supports the explanation; one measurement is not a universal performance bound.

Exact-head workflow 37875370116 succeeded in seed, generated, floor, emit-build and witnesses. Generated passed all-target lint and the one-emission mirror check. Rust unit tests were skipped, not passed. I downloaded floor artifact 11594756501, checked SHA256 13ad445eb86550fe1519809968025cb739949e20f9dec19b26a5016088a285f4 against GitHub metadata, and parsed its 836 claim rows. The two new Rust test names and ignored projection test are not executed claims in that receipt. Their reported local runs remain author-run evidence, distinct from the live floor execution.

Local execution in this review was artifact hashing/parsing only; no compiler, injected source, production-floor mutant or new remote run was executed. Current CI is not reported as failing, and I found no second-prepare fallback in the inspected code. No merge or enqueue. Preserve the one-prepare improvement and close the small source-reader and enforcement-pairing boundaries.

…ion as one composition.

The census consumes the source parse with no join, so a trailing list operation or a computed wet member beside a literal one must refuse rather than skip. Pairing goes through required_floor_admit_policy_projection so a disagreeing eval fires PolicyRosterProjectionMismatch before wet rows run.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78240 (claude/opus REQUEST_CHANGES: second .dag reader / scaffold)

Not changing the bootstrap reader to a compiler constant-fold in this PR.

The ordering cycle the finding names is the reason the reader exists: eval of required_gate_prefixes needs claim_scope_for on a prepared graph that already contains v2.workflow.required_floor, and the gate keep-set is computed from those prefixes. The construction it asks for — ingest those declarations as the values eval produces — is the named retirement, not a path that is available without restoring the deleted policy Strict-prep (or a second prepare of the same 1,252-module closure). That is why the comment calls it bootstrap.

Operator ruling (eager-gull-22, and review 5465737586): the one-prepare design and the ordering-cycle bootstrap are accepted. Review 5465737586 explicitly did not require reversing that ruling or adding a self-authored approval row. DESIGN §5: scaffold approval is external to the diff; a row in the same change is not that approval.

Eval after the one gate prepare remains the authority (required_floor_admit_policy_projection). A form the bootstrap cannot read refuses (PolicyRosterNotAListLiteral); it does not skip or fall back. That is a bounded fail-closed seam, not a second meaning of the roster. The attractor concern is why retirement is named as compiler-derived constant fold of those function bodies, not more scanner investment.

Head 23068594ea already closed the two P2s review 5465737586 asked for on that seam (whole-expression refuse, structural wet fields, admit composition pairing). No new lane, no second prepare.

— sent from zesty-wren-256

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 23068594ea.

The two findings from review 5465737586 are otherwise repaired. The bootstrap now consumes the complete list expression, refuses a trailing operation, structurally parses the wet schedule (including spaced module_path :), refuses a computed/unreadable member beside a readable one, and walks source text by char. The production pairing is also now real: run_required_floor performs the one gate prepare, projects with required_floor_nominal_subject_seeds_from_prepared, then calls required_floor_admit_policy_projection(&bootstrap_seeds, &projected)? before subsequent floor execution. The bounded negative exercises that composition helper and gets PolicyRosterProjectionMismatch; the equal case is green.

One P2 remains in the all-or-refuse reader: DagSrc::parse_string does not implement Daglang string escape semantics and does not refuse escapes it cannot decode. On seeing \, it sets escaped=true; on the next character it simply buf.push(c). Thus, e.g. a Daglang "\\n" escape becomes the two-character identity "n" rather than a newline, while the language supports string escapes including \n (and the grammar plans also enumerate \u{...} / \x..). More generally the bootstrap silently removes the escape introducer and publishes a different string.

That is not only a future projection mismatch issue. required_floor_nominal_subject_module_identities calls the source bootstrap, assembles the subject, and returns ModuleIdentityPopulation::Observed with no evaluated-policy join. Therefore an escaped module/prefix literal can silently change the census population before any PolicyRosterProjectionMismatch exists to protect it. This is the exact consumer that made the earlier reader boundary blocking.

Required repair is small and remains within the accepted one-prepare design: either decode every Daglang string escape this restricted reader admits with the same semantics as the language, or reject any escape form you do not explicitly support. Add at least one supplied-source control whose escaped literal would be misidentified by the current parse_string (for example \n), proving decode-or-refuse rather than backslash dropping. No second prepare, cache, or whole-corpus parser is requested.

Exact-head workflow 37888260658 is the requested head 23068594eac244fddd67dd3087bcb25df0b1e845; seed, emit-build, floor, generated, and witnesses all succeeded, and rust-unit-tests was skipped. CI therefore confirms the live current corpus route, but it does not cover this escaped-literal counterexample.

Once the escape handling is decode-or-refuse, I have no remaining objection to the one-prepare/pairing structure.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST_CHANGES at exact head 23068594ea.

The structural and pairing findings from review 5465737586 are fixed: the bootstrap consumes the whole list expression, structurally reads every wet identity, refuses the supplied computed/trailing forms, walks UTF-8 by char, and run_required_floor now projects after the single prepare and calls required_floor_admit_policy_projection before wet execution; the bounded disagreeing projection discriminates that admission.

One P2 remains: DagSrc::parse_string is neither semantics-correct nor fail-closed for Daglang escapes. When it sees \\, it sets escaped; the next character is then pushed verbatim, dropping the escape introducer. Daglang's tokenizer has real escape semantics (\n, unicode/hex handling and refusal of unknown escapes), so a source literal containing an escape can be published by this bootstrap under a different string identity. This matters independently of the later floor join because required_floor_nominal_subject_module_identities consumes the bootstrap directly as Observed with no evaluated-policy join.

Repair by decoding the restricted reader's admitted escapes with Daglang semantics, or refuse every escape form it does not explicitly implement. Add a supplied-source control such as \n that proves decode-or-refuse rather than backslash dropping. No second prepare/cache is needed.

Exact-head run 37888260658: seed, emit-build, generated, floor, and witnesses succeeded; rust-unit-tests was skipped. CI does not cover the escaped-literal counterexample.

The census consumes those identities with no join, so dropping the backslash introducer could silently rename a module. Decode exactly dag_string_escapes / numeric forms and refuse any other escape.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

review 78326 (claude/opus REQUEST_CHANGES: second .dag parser / scaffold / seed-growth row)

Not replacing the bootstrap reader with frontend ingest of two modules, and not adding a gunbc.seed_growth row, in this PR.

Ingest-to-Node without prepare is not the missing construction. The cycle is eval of the roster functions vs the gate keep-set: claim_scope_for / eval of required_gate_prefixes needs a prepared graph that already contains v2.workflow.required_floor, and that keep-set is computed from those prefixes. Tokenizing two files into Node does not yield those values. Getting the same values eval produces through the real ingest/constant-fold is the named retirement — and running that fold over the policy module is the 1,252-module policy Strict-prep this PR deletes. A second prepare, even of “just those two modules,” is that route again if it has to close the policy closure to eval.

Operator ruling (eager-gull-22; review 5465737586): the one-prepare design and the ordering-cycle source bootstrap are accepted. Review 5465737586: “I do not require reversing the operator's bounded-bootstrap ruling or adding another self-authored approval row.” DESIGN §5: scaffold approval is external to the diff; a SeedGrowthJustification written by the same change is not that approval.

Eval after the one gate prepare remains the authority (required_floor_admit_policy_projection). A form the bootstrap cannot read refuses (PolicyRosterNotAListLiteral). Escape decode follows extdeps.languages.dag dag_string_escapes / dag_string_decode_step and refuses the rest (review 5470795778, head 90ba3b5b01). No new lane, no second prepare.

This is the same finding as review 78240. Head still 90ba3b5b01.

— sent from zesty-wren-256

@gunbai-bot
gunbai-bot Bot marked this pull request as draft October 9, 2026 17:15
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Wind-down disposition (operator, 2026-10-09): #13604 is left out of integration/eager-gull-22 and parked as a draft. It has an open REQUEST_CHANGES, its CI was unfinished at 90ba3b5, and the side chat never approved this head. review 78326's finding stands unaddressed: the seed gains a hand-written .dag text walker (dag_fn_body / DagSrc / wet_schedule_seed_modules), described as bootstrap with no seed-growth row. Whoever picks this up next must remove that walker or declare and approve it as a scaffold. Its measurements (prepare-only wall time 1221 s to 821 s; policy_seeds peak RSS 13.38 GiB to 5.04 GiB) remain the receipt for the one-prepare direction.

— sent from eager-gull-22

@briansrls
briansrls marked this pull request as ready for review October 9, 2026 20:11
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T20:20:13.047503Z 90ba3b5 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Closed without folding in the v1 closeout bankruptcy (#13641). Reverted from the fold: a second hand-written .dag parser in the seed (review 78326), serving the retiring floor. The branch is kept for archaeology; no follow-up obligation is created. — sent from neat-wolf-604

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
briansrls added a commit that referenced this pull request Oct 10, 2026
* dispatch-actuator witness: import the lineage, alignment and ticket names #13622's specimen uses

Review 78285 on #13622: the supplied-specimen claims call lineage_walk, lineage_is_rooted and alignment_chain and build TicketLine/TicketFields/NodeParent/AdmittedRoot/RoadmapNodeIdentity without importing them. They resolved only through the flat bare-name tier DESIGN schedules for removal, so they would go red when it is cut. Import each from its declaring module.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Merge #13548 (session/sharp-deer-755-unimported-type-import-migrate) into integration/sharp-raven-357"

This reverts commit 1a22abd, reversing
changes made to a04255a.

* native_emission_controls: repair integration union (close variant_literal_application_cases, one roster, one composition over all 17 case groups)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclude #13604 from integration/eager-gull-22: WIP, open REQUEST_CHANGES (review 78326)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* docs/design-rung-drops.md: regenerate through tools.docs_projection_gate regen after the #13569 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* grammar: import int_to_decimal_string from std.integer (#13436 moved it; #13379's binding-power row still named v2.std.integer integer_int_to_decimal_string)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: mtcollins1 runner: boot leg, runner image medium + runner-host-up termin

* Realize reviewed kernel dependencies through guarded host maintenance

* Rewrite the cross-module record-field pin to the refusal it named as its trigger.

Infer now refuses `n: true` against `RcfFar` declared in another module; keeping the counted-Undecidable pin would be a meaning fork of the same claim name.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Close the post-main census: drop the Map interpolation hole, concat the spatial cast.

Merging main reintroduced one implicit stringify (Map Display in the canonical-order witness) and left the spatial_dimension `{o as String}` template as a v1 span mismatch. Named Int/Nat/Symbol routes stay; the Map hole is deleted rather than given a fourth renderer.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Regenerate fleet-converge.yml via generated_artifact_gate main_wet

Replaces the provisional #13359 copy taken at merge, which dropped main's printer mode, WIF provider rename and r2_cache options. Diff vs main is now only the two new custody credential options (cursor_worker_turn_api_key, codex_worker_turn_auth). Regenerated remotely (BuildBuddy invocation 3107c1bf-7c17-4bd4-92ec-53bb6b0be1fe) under a cgroup memory.max, regen exit 0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Remove scratch witness scripts committed by the close-out flush (review 78354)

The wind-down flush committed untracked local files (.runwit*.sh, .probe2.sh, .wit/)
as 32dcf74. They are local receipt scaffolding, not part of the boot leg.
This restores the tree to 80c24b3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* cax onboard: enumerate the closed-coproduct arms the floor's non-fold residue check refused

approved_grant_policy, plan_against_policy and provider_controlled_host matched closed coproducts
with a wildcard arm; each arm is now explicit, so a new variant refuses at compile rather than being
absorbed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* v1 closeout: open PR accounting

Every open PR, with its owning lane and its disposition in the mega branch.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: add the side-chat dispositions and wave 2

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 emit_rust mirror for the integrated authorities (first_generation_equal=true, 0 installs on pass 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: bold-bee and qwen dispositions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: outstanding work, closed PRs, and a re-sweep of all 162 open PRs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: #13607, swift-bat-828 branches

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration/silent-lark-156: regenerate generated artifacts after merging #13472 and #13610

Produced by main_wet + claim_executor --required-regen on BuildBuddy at fd4421d;
second regen round installed nothing (fixed point).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: silent-lark, gentle-dove, royal-moth, neat-boar, nimble-heron, valiant-crab handoffs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Second-type OpenRouter Retry-After and quota term (review 78356)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: lively-ram and silent-lark handoffs, #13460 folded, #13108 and #13330 dispositions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md and the v1_compiler_emit_rust stage0 mirror for the integrated tree

Generated through docs_projection_gate regen and claim_executor --required-regen
on srv1; round 2 reports first_generation_equal=true (a fixed point).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: #13488, #13574, #13475, #13634 reviews; #13648 closed; archive-flush residue

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* provisional: gentle-dove-36 mirrors for conflicted generated files (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Revert "Merge #13574 into integration/gentle-dove-36"

This reverts commit 32720e2, reversing
changes made to eee50a4.

* provisional: v1_rt.rs from silent-lark-156 (carries host_budget_darwin_physical; seed bootstrap, regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* provisional: v1_rt.rs = v1-closeout + silent-lark-156 delta (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: sharp-raven report, #13265, #13574 revert decision

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* provisional: append rt_host_budget (HostBudgetJoin*) to v1_rt.rs (seed bootstrap; regen replaces)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclude #13595/#13574 from integration/eager-gull-22 (operator decision msg_c695ffcc)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix stderr-capture tests so they hit real routes, not decoys.

Delete the rustc program that returned Err before spawn without compiling
emit_shell_stderr_policy_binding; absent policy is already refused at the
emit diagnostic wall. Drive Complete limits from the live host-budget join
and keep drain specimens on the emit_rust authority strings.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fabric_quota: re-attach the window-start comment to quota_window_start (review 78371)

checked_second had been inserted between the comment and the function it documents.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Required CI: withdraw the four v1-judged lanes; the gate is emit-build alone (operator ruling 2026-10-09)

The operator's v1 withdrawal: v1 is no longer a validation authority, and
the one use left to the seed is emitting v2. gunbc.compiler_gate_workflow
drops `floor`, `generated`, `rust-unit-tests` and `seed`; the `witnesses`
aggregate reads the one remaining lane, `emit-build`, through the same
folded roster (one row). The GateArmSkippedOnPullRequest arm leaves with
its only inhabitant.

The loss is one declared drop, gunbc.rung_drop v1_required_lanes_withdrawn,
stated member by member (witnesses, stage0 mirrors and every generated
artifact, lint, v1 unit tests, module resolution outside the two emitted
closures, the downstream consumers), with a trigger that names the
capability: a binary built from an emission of v2 judging that population
on the required path. rust_unit_tests_off_pull_requests is Superseded (its
lane runs nowhere; trigger did not fire; the new row holds the loss).

gunbc.required_ci_contract_epoch moves to 2026-10-09.1: the name `witnesses`
now carries a materially different contract.

Consumers repaired rather than left dangling: the lane-resolution census
roster (the census now does not hold by design and is the instrument that
re-derives the drop's module population), DESIGN section 3's typed
required-gate reference (gunbc.documentary_refs, now
emitted_subject_build_rows), the Building & checks rows, the onboarding
path's run-witnesses step, five recurring_failure_mode evidence rows that
cited deleted declarations, and the two gate witness files (the blocking
set is asserted as exactly emit-build; a new RED asserts the four
withdrawn variables reach neither gate surface).

Projections regenerated by tools.generated_artifact_gate main_wet (the run
peaked at 15.8 GB RSS, against the 7.55 GiB that module's own note cites
for 2026-08-31): witnesses.yml, DESIGN.md, docs/design-rung-drops.md,
docs/onboarding.md; every other rostered artifact came out byte-identical.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Drop process-global budget env from stderr-capture tests.

review 78373: planting Complete limits through GUNBC_MEMORY_BUDGET_BYTES
leaked into parallel tests and did not inhabit the emit bind. Claim the
drain strings only; leave the host-budget join uncovered.

Co-authored-by: Cursor <cursoragent@cursor.com>

* regen round 0: stage0 mirrors from claim_executor --required-regen (supersedes provisional splices)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* provisional: re-append rt_host_budget to v1_rt.rs (round-0 regen emitted v1_rt.rs without it; seed bootstrap)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* regen round 2: stage0 mirrors (v1_rt.rs now emitted with rt_host_budget; hand-appended lines gone)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate generated artifacts for integration/eager-gull-22

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* required_ci_phase_roster: import std.optional (v2.std.optional moved by #13388; stale import from #13225)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v1 closeout accounting: all lanes reported; remaining merge plan; closed auto-opened PRs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert #13123 (admit_callers enforcement: mega's AdmitCallersEdge is the one enforcer)

* v1 closeout accounting: #13516 folded, #13212 dispositioned; every lane reported

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop #13545 transcribed-count red chunk (counts derive from ci_runner_sudo_binaries); retarget caller-admission real-route evidence to exact counts

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* v1 closeout accounting: eager-gull review outcomes, #13608 newer head, updated plan

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop the seed-growth citation of the deleted absent-policy decoy.

review 78381: hand_authored_declarations still named
emitted_absent_policy_refuses_before_spawn after that test was removed.
Absent policy stays cited as
capture_channels_without_stderr_capture_input_refuse_the_union.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert #13586 (receipt-only, excluded by operator review)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Revert #13453 (base-compiler/floor protocol; excluded by operator review): seed Rust, workflow steps and the script-row refusal API go with it

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* WIP: one required job, fresh products, memory envelope, heal-publish deletion (pre-merge, projections not yet regenerated)

* stage0 mirrors: restore generated mirrors to the mega branch's coherent set pending one regen round

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* floor_route_gap: give the belt exit-drain expectations their own chunk_43

Two folded PRs (#13442's seeded_filler rows and #13125's belt exit-drain rows) each
added floor_route_gap_expectation_chunk_42. The second silently replaced the first and
the native emitter refused (duplicate declaration). The exit-drain chunk becomes
chunk_43 and joins the roster, so both expectation sets are read.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* live_deploy: reconcile #13599 with #13583's directory authority

#13583 made owned directories the single directory authority (directory demands; host_directories)
and removed the directory kinds from the ensured steps and the instance parameter from
deployment_ensured_steps. #13599, folded alongside it, still called deployment_ensured_steps(instance:, target:)
and its witness matched on the deleted step kinds. The call passes target only, and the
lab-vs-production fabric-store claim now counts fabric_storage_store_directories demands in
deployment_directory_demands. Same claim, read through the surviving authority.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap_task_record: JSON codec for a runtime RoadmapNode (piece 1, uncompiled draft)

* roadmap_task_record witness

* roadmap_task_store: chain-partition roster over the fabric state binding, with wet witness (draft)

* roadmap_task_record: parent and centering required on the wire; drop nested optionals

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* managed_host: a superseded rung drop is not a standing citation

drop_is_standing_citation matched RungDropStanding with Retired and Standing only. Superseded has
existed since the 2026-10-06 supersession, and the closeout's seed refuses the non-exhaustive match,
which reaches every closure through managed_host (generated_artifact_gate included). A superseded
drop no longer stands, so it is not a citation, the same as Retired. (Found by smart-gull-336.)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: federation retired-path row below imports; floor_demand pinned envelope rows; managed_host Superseded arm (pre-regen)

* Headless Claude dispatch: print argv, systemd unit, stream-json projection.

When the harness has no spark, ExecutorDefault can admit Claude if custody is present; events stay in the belt's Codex envelope. Credential converge on srv1 remains an operator decision.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API

6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: complete the #13453 revert -- gunbc.fleet_desired_admission_workflow no longer imports the deleted script-row refusal API

6ee1d21 (integration/v1-closeout) removed fleet_desired_candidate_fetch_script_row and candidate_scripts_refusal from gunbc.fleet_desired_candidate but left their consumer, so every entry whose closure reaches the generated-artifact registry refused to resolve (regen, verify, five gate witnesses). This is origin/main's shape of the file: the admission workflow emits its YAML directly again.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 94464b1)

* roadmap_task_record: balance ticket decode braces

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Address review 78387: one Claude event mapping, explicit executor, transmit effort.

parse_codex_jsonl now classifies bounded Claude stream-json via claude_code_line_codex_kind; jq only bounds those lines. ExecutorDefault stays a harness refusal. Print argv carries --effort.

Co-authored-by: Cursor <cursoragent@cursor.com>

* v2 compiler: reconcile #13438's precedence climbing with #13582 and #12942

Two merge-born references to deleted code, found by emit-build on #13641:
- 02_parse: #13438's infix stamp still wrote ParseProvenanceState.frame / FrameMinted, which
  #13582 deleted with the packrat memo. The write goes; the sibling stamps already carry none.
- body_lowering_fold: #12942's sealed body_lower_fold_raw kept the pre-#13438 pipe-tower test
  (body_lower_is_pipe_tower_root / body_lower_tower_pipes_into_fold), which #13438 deleted. It now
  uses #13438's replacement predicate, body_lower_application_pipes_into_fold, and keeps
  #12942's sealed outcome.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fleet_converge_workflow: drop MtCollins1UiBundleObserve from the mode list

#13503 removed the UI-bundle-observe mode (AMI-bundle-derived MegaRAC content) from
FleetConvergeWorkflowMode but left it in fleet_converge_workflow_modes. Every name in the list
now resolves to a declared variant. (Found by smart-gull-336.)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: trip is a ByteSize derived from the slot envelope (review 78388 item 3); witness claim the_trip_sits_inside_the_slot_envelope

* Address review 78389: emit tmux event pipe only for tmux containers.

Claude and harness systemd spawn no longer derive readiness from tee/pipe emission or refuse as tmux-event-pipe-emit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: two stale references from folded deletions

- first_element_of_a_list_has_three_spellings cited v2.std.optional Optional; the module is
  std.optional (#13388's move).
- authorization_pattern_selection_witness imported PastedOperatorToken, which #13568 removed
  with the pasted-token refusal; the import was unused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerated projections for the one-job gate, on the merged closeout tree

One main_wet of tools.generated_artifact_gate over this branch merged with
integration/v1-closeout a925452 (regen 632 s, verify 693 s, both exit 0,
on srv1 under capped MemorySwapMax=0 scopes), nine artifacts:

- witnesses.yml: both subject steps carry GUNBC_BIND_MEMORY_CGROUP_BYTES
  (the derived trip, 20 GiB) and the failure notice carries the envelope
  lines (what 137 means, no larger runner and no retry, the MEMORY RECEIPT).
- DESIGN.md, docs/design-rung-drops.md: the CI row and the drop roster.
- .gitattributes: the deleted heal-publish.yml leaves the generated-artifact
  merge list.
- fleet-converge.yml: the closeout's authority fix projected.
- tools/fabric_ci_fci1_bounded_execution_context.env: the fci1 context
  follows the slot (22/21 GiB).
- provisioning/srv{1,3,4}/gunbc-ghrunner.sudoers: a 22 GiB slot fits more
  slots per host than a 26 GiB one, so the derived rosters grow (srv1 gains
  srv1-10 and srv1-11). Desired state; applying it is the converge effect.

The witness batch on the same tree: 16 files, green except the two latent
reds already recorded in the PR (fci1_bounded_execution_context: a stale
envelope-basis expectation; heal_publication_boundary: 23/34).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Enrol roadmap_task_store wet witness on the local-repo wet lane, as the allocation seam witness is

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Land the v2 cutover program as designed roadmap entries: 11 nodes, native_obligation_population plan, edges, RED acceptance witnesses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md belt_liveness_publication_answers_unconsumed
Ledger-Rows-Repaired: docs/design-rung-drops.md bmc_secure_apply_converge_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci
Ledger-Rows-Repaired: docs/design-rung-drops.md fixture_closure_union_unmodeled_stderr_capture
Ledger-Rows-Repaired: docs/design-rung-drops.md handoff_observer_is_sol_not_kvm_viewer
Ledger-Rows-Repaired: docs/design-rung-drops.md kvm_observer_protocol_wet_witnesses_deleted_with_the_observer
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Heal-Candidate-Run: 38000315997

* closeout: regenerate stage0 mirrors and workflows from the folded tree

One emission round (operator ruling 2026-10-04) on srv1 at a925452:
claim_executor --required-regen, then generated_artifact_gate main_wet. Then on the
regenerated tree: seed build OK, gunbc test //gunbc/instruments:v2-native-cli exit 0,
//gunbc/instruments:self-host exit 0. Settles the files the folds left provisional
(fleet-converge.yml, the std_* and v1_compiler_* mirrors). docs/design-rung-drops.md was
already regenerated by CI auto-heal (17a309c).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: option B -- subject steps require the slot envelope; per-step trip withheld by the declared drop native_step_trip_awaits_fleet_job_cgroup; slot-grain receipt in gunbc test; seed-growth receipt (pre-regen)

* Enrol roadmap_task_store wet witness in floor_route_gap and the local-repo wet terminal, as the allocation seam witness is

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate ROADMAP.md, docs/plans and .gitattributes for the cutover rows; repair updated(...) wrapping

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Describe the envelope as slot-grain (option B) in witnesses-one-required-job; regenerate projections on the merged head

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Type the cutover receipt readings (closed kinds, ByteSize) and make the peak-above-trip control compare against the slot trip

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Subject steps require the slot envelope; the per-step trip waits on a fleet fact; the envelope decision is a .dag fold the seed mirrors

The first required run that passed GUNBC_BIND_MEMORY_CGROUP_BYTES
(38002497388 on a4b8f78) refused in four seconds: MemoryCgroupBindRefused,
the cgroup2 tree is not writable. memory_governor apply_memory_cgroup_bind
creates its leaf at the cgroup ROOT (a container-root design; the bind had
never been requested on the fleet) and a fleet job runs as the setpriv'd
job user under a root unit, so no job process can create the bound. The
operator approved the slot-grain arm (escalation 2026-10-09).

gunbc.memory_envelope (new) owns the decision and the verdict as folds over
supplied inputs -- the sibling of gunbc.memory_cgroup_binding -- and
test.claim.memory_envelope_witness_test reaches every arm by supplied value,
including the RED an inline decision could not: a slot requirement over a
process no numeric memory.max binds REFUSES (MemoryEnvelopeAbsent) rather
than running as bounded. The seed mirrors it arm for arm with unit tests;
the shells resolve the bounding cgroup through binding_cap_cgroup_dir (never
the peak locator), read memory.swap.max/.current/.peak (modeled in
extdeps.linux.cgroup_v2_memory) before and after the producer, print a
slot-grain MEMORY RECEIPT with event deltas and the peak labelled by whether
it rose, and refuse the run on any OOM kill or swap.

gunbc.emitted_subject_build_gate carries two envelope inputs and ONE
decision over them, native_step_memory_inputs(ownership): every subject step
REQUIRES the slot envelope (GUNBC_MEMORY_ENVELOPE_REQUIRED=slot, the
projection of EnvelopeSlotRequired) and the bind input at the derived trip
is withheld while gunbc.runner_slot_desired gunbc_runner_slot_job_cgroup_ownership
is JobOwnsNoBoundedCgroup. That is a fleet fact, not a rung drop -- nothing
on the required path ever held the trip -- so the climb is rostered as
gunbc.guarantee_stall native_step_trip_awaits_fleet_job_cgroup_stall
(grounding: unit delegation with DelegateSubgroup=, a per-job cgroup staged
by the root JIT wrapper, the governor's already-bound arm). The workflow and
the failure notice consume the fact; the witness exercises both arms by
supplied value, reads the live row, and asserts the bind KEY is absent.

The slot wall follows the ruling too: gunbc.runner_slot_allocation
gunbc_runner_slot_allocation_wall_holds drops its three floor conjuncts (a
slot sized to a tenant that no longer runs in it) and requires
MemorySwapMax == 0 instead of a swap above the maximum; the floor-fit drop
slot_row_pinned_below_demonstrated_demand_unrefused is Superseded with
v1_required_lanes_withdrawn as its loss holder; the slot witness re-pins the
row to 22/21/0 and its width alarms to the smaller slot's derivation
(srv1 12, srv3/srv4 21). The slot's demand oracle from here is the first
cold required run's MEMORY RECEIPT, a declared frontier.

The trip stays a ByteSize derived from the slot (review 78388 item 3). The
seed growth is receipted as gunbc.memory_envelope_receipt_seed_growth
(review 78391). The design document's CI row and the slot row's note say
the same.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* emit_rust: locate module via ModuleIndex.by_name; is_known_variant reads carried variant_to_enum (port of #13608 23f2d08, 8ff94ca; mirrors pending regen)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* decimal_digit_of_units: construct the units digit via the successor table; no D9 default for out-of-range Int

* closeout: bind variant_to_enum correctly at three #13665 call sites

import_variant_parent_for_name has no emit_info parameter; emit_specific_import_use_lines has no variant_to_enum binding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate ROADMAP.md on the merged head; re-cite the envelope fact and stall

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Take sold Group B (srv9-srv12) out of everything that reaches hardware; declare fixture residue as a rung drop

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Supply sold Group B (srv9-srv12) as in-witness fixture population; production rosters stay empty

Chain: the scoped cut emptied dgx_spark_reserved_identities and the router bindings, so witnesses that
discriminated on the Group B population (commitment standings, admissibility, rail rows, topology
membership, reach labels) read nothing. spark_host_commitment_witness now folds the production
placement, claim and reservation rows over a local four-host fixture, with one inhabitance claim that
the production roster is empty; the topology, reach and site-locale witnesses are re-derived to the
emptied rosters. Under rung drop serving_fixtures_name_sold_group_b_hosts.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Regenerate std_integer stage0 mirror (remote required-regen candidate)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* closeout: revert #13662's fold (operator decision 2026-10-10)

#13662 (headless Claude worker) stays outside the closeout. A child re-lands it into main after #13641, with its review findings resolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Recut to five durable outcomes: cold-run envelope receipt rename, acceptance-receipt framing, derived-universe denominator, stable frontier subject; six chores moved to runtime tasks; no red witnesses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* roadmap: split the event carrier's directory demand into a leaf module

gunbc.roadmap.dashboard_instance_directories imported gunbc.roadmap.roadmap_event_carrier for one
directory function, and through it the dispatch actuator. With #13625's host_standup -> host_effect
import (c390a49), that closed a 13-module cycle (materialized_secret -> host_phase_status ->
host_standup -> host_effect -> live_deploy.spec -> dashboard_instance_directories ->
roadmap_event_carrier -> roadmap_dispatch_actuator -> cursor_harness_credential -> ...), and main_wet
refused to resolve. The demand moves unchanged to gunbc.roadmap.roadmap_event_carrier_directory;
the carrier, the directory list and the owned-directory witness import it from there.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Address review 78405: delete the never-red frontier-count decoration; eligibility and disjointness controls run over supplied members

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* closeout: five merge-born refusals that main_wet found

- managed_host: HostnameAllocation no longer carries canonical_hostname; read it through
  allocated_canonical_hostname (hostname_allocation's name scheme, #13625).
- host_control_route: handle ManagedHostFoundUnderDeclaredDrop the way managed_host's own
  account lookup does: the standing still decides the BMC route.
- mtjade1_arrival_federation_provision: DedicatedFederation's principal_set became
  impersonation: FederationImpersonation; the arrival pool is a standing-pool impersonation.
- fleet_workflow_steps: ci_fleet_wif_auth_step_when passed if_condition twice (a merge of
  #13607 and #13625).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Make fleet-converge branch-agnostic and parseable.

GitHub refused the workflow on every push after the mode input description crossed ~10k characters. Shorten that description to an authority citation, pin WIF to the workflow file on any heads ref plus workflow_dispatch (not pull_request), and admit a deploy from the current branch when --candidate-branch is empty. expected_revision stays a check when supplied and otherwise is the dispatched sha.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Name the branch-dispatch ruling; type malformed expected_revision.

Comments no longer claim reviewed-main file trust. Absent vs malformed expected_revision are separate arms so admit_optional cannot parse prose.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Declare the named-revision and deploy-branch drop.

Those two refusals are a different subject from the WIF main pin; §4b(3) needs its own population and trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Recut #13660: restore privileged WIF to reviewed-main equality.

A rung drop does not substitute for the trust boundary. Privileged fleet-converge federations pin workflow_ref and ref at main again; session-branch admission lives only on the development pin list, which is not bound to fleet-cloud-convergence.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop leftover census conflict markers and project the named-revision drop.

The recut commit had kept rebase markers in gcp_iam_approval_enforced_in_reviewed_code; the projection now carries fleet_converge_named_revision_and_branch against closeout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix OidcClaimPin inhabitance and the privileged-pin wording fork.

branch_dispatch_claim_pins now constructs event_name via oidc_equals. Privileged jobs are described as reviewed-main equality; the development pin list is named as a frontier, not a live federation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Split presented OIDC claims from pins; printer session-branch is a red.

Privileged printer pins equal reviewed main, so a concatenated session-branch workflow_ref must refuse. Admission now takes OidcPresentedClaim (name and value only); relation lives only on the pin.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Regenerate fleet-converge.yml (21 inputs) and pin dashboard-deploy to main.

GitHub refused the hand-edited 30-input file; emission from fleet_converge_dispatch_inputs is the repair. dashboard-deploy now requires refs/heads/main and environment srv1-production so a branch dispatch cannot wet-deploy production.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: revert #13663's fold (operator ruling: #13662 and #13663 stay outside the closeout)

deep-cat-540 recuts it onto main after #13641.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Omit Spark dispatch when the administrator roster is empty.

Review 78408: regeneration had folded a sold-out Spark roster into target options: [] while spark_* modes stayed selectable. Restoring srv5-srv12 would invent enrolled hosts. Emission now drops the target input and spark_* mode options, and refuses any remaining empty InputChoice.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Treat srv1-production environment protection as the root-mutation boundary.

A branch dispatch runs that branch's YAML, so a github.ref if is not a trust boundary. dashboard-deploy, approval-broker-dark-install and microvm-controller-install now name srv1-production; the required GitHub setting (main-only deployment branches, required reviewers) is modeled with an unobserved readback. Checkout is the event sha.

Co-authored-by: Cursor <cursoragent@cursor.com>

* closeout: stage0 mirrors and projections regenerated at a fixed point on 5c0d9d5

The composed closeout tip (the #13663 revert and #13664's fixed head folded) could not regenerate itself: claim_executor --required-regen refused with Stage0EmittedEdgesNotCovered (62 emitted edge endpoints with no stage0 crate) and the committed mirrors did not build a seed. Two generation-1 facts explain both, and both are repaired in this set rather than worked around.

First, the regen's coverage check reads the host-shell roster from the TREE's src/v1/stage0/src/lib.rs (required_regen_host: closure_modules(lib.rs)), not from the seed. The integration-side regen from the d9368e8 seed, an emitter predating the crate planner (#13597), rewrote lib.rs without the three pub mod lines #13597's head 3674580 carried for gunbc_crate_partition, gunbc_emitted_crate_workspace and v1_compiler_emitted_workspace, while their mirrors and .dag sources stayed. Restoring the three declarations lets the regen run; the regenerated lib.rs then lists them canonically, which is the only change this set makes to lib.rs.

Second, --required-regen renders v1_rt.rs from the SEED's compiled-in runtime rows, so a boot seed older than the tree's runtime_rust.dag emits a candidate without the host-budget join that the tree's memory_governor mirror consumes, and generation 1 does not build (the closeout history records the same provisional step at 42954d2). The committed v1_rt.rs is kept for generation 1; generation 2, whose seed carries the tip's rows, emits it identically, so v1_rt.rs is unchanged here.

Recipe, on a shallow clone of 5c0d9d5 on srv1, each step under systemd-run --user --scope -p MemoryMax=80G -p MemorySwapMax=0: boot seed built from 3674580; main_wet; lib.rs roster repair; required-regen with the boot seed (first_generation_equal=false, 244-file candidate); install; v1_rt.rs restored; then the tip's own seed: build, main_wet, required-regen (generation 1: divergent, candidate installed; generation 2: first_generation_equal=true). No .dag file changes. The projections are main_wet's output over the composed tree: fleet-converge.yml regenerated from its 21-row authority (the committed 30-input file was drift), ROADMAP.md and docs/plans/native-obligation-population.md for #13664's recut, docs/design-rung-drops.md for the supersession, .gitattributes for the plan projection's merge driver.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* fleet-converge: omit the Spark target input and spark_* modes while the administrator roster is empty; refuse an empty choice at emission (port of ffe8a90)

The fixed-point regeneration on 5c0d9d5 faithfully emitted .github/workflows/fleet-converge.yml with `target: type: choice, options: []`, because gunbc.spark.credential_workflow spark_administrator_credential_roster has been empty since 2026-10-10 (every Spark sold) and gunbc.fleet_converge_workflow had no wall for an empty closed choice. GitHub rejects a choice input without options, so the regenerated workflow would have been undispatchable in every mode, not only the seven spark_* modes that read inputs.target; the previously committed file was drift the other way (hand-kept srv5..srv12 options for hosts no longer enrolled). Review 78408 on gunbc#13660 found this, and snappy-stag-26 fixed the authority there at ffe8a90; that PR is ruled outside the closeout at its WIF scope, so this commit ports exactly the empty-roster hunk and nothing of the WIF or environment changes.

What changes in the authority: fleet_converge_spark_target_modes names the seven modes that consume the target; fleet_converge_dispatchable_modes() drops them while fleet_converge_spark_target_options is empty, and fleet_converge_mode_options is derived from it; the dispatch inputs are now fleet_converge_dispatch_input_rows filtered by fleet_converge_dispatch_inputs, which omits `target` while the roster is empty; fleet_converge_empty_choice_input_names() enumerates every InputChoice with no options over the four DispatchInputType variants, and expected_fleet_converge_yml() refuses emission with those names before the input-count check (DESIGN section 5: refuse, do not emit options: []). The witness every_dispatch_option_is_a_wire_value_of_the_vocabulary joins the options to the dispatchable modes, and empty_spark_roster_does_not_emit_an_empty_choice_or_spark_dispatch_modes pins the current roster state. The fleet_workflow_steps.dag hunk of ffe8a90 is not needed here: the closeout's ci_fleet_wif_auth_step_when already passes if_condition by name.

The regenerated fleet-converge.yml is main_wet's output over this authority with the fixed-point seed; the stage0 mirrors are unchanged (the module is not in the emitted population) and required-regen stays at first_generation_equal=true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: delete the accounting doc; the terminal ledger lives in #13641's body (review 5474794145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* closeout: revert the #13664 fold (5c0d9d5) per the operator's review 5477471759: close #13664 without folding, branch preserved; projections regenerated next

* deployment environments: model the branch policy as GitHub returns it (name + branch-or-tag rules), so the srv1-production standing can be discharged by a faithful GET (review 78420)

Review 78420 on gunbc#13660 (folded here at 60c9457) found that extdeps.github.deployment_environments modeled the deployment-branch policy as SelectedRefs { refs: ["refs/heads/main"] }, while the API carries no refs: the environment object's deployment_branch_policy is null or { protected_branches, custom_branch_policies }, and the custom rules live at GET /repos/{owner}/{repo}/environments/{name}/deployment-branch-policies as branch_policies rows { name, type } with type "branch" or "tag". A reading of the real API can therefore never match the modeled refs, so gunbc.auth.github_deployment_environment's standing could never move from Unobserved to Holds (DESIGN section 3: model what the API actually returns; section 5: a check that cannot be discharged is not a boundary).

The model now carries DeploymentBranchPolicyRule { name, ref_type: PolicyRefBranch | PolicyRefTag } under SelectedBranchesAndTags { rules }, the srv1-production requirement is the single branch rule named main with required reviewers, the restriction predicate requires exactly one rule that is a branch named main, and the read obligation names both GETs and the shapes they return. The witness gains a supplied-value control: a tag rule named main and a two-rule policy are not the main-branch boundary, the single branch rule is. Standing stays Unobserved until the operator applies the setting and its readback lands; that flip is the first follow-up on main.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* closeout: regenerate at the fixed point on composition A (revert of #13664, fold of #13660)

Same recipe as f8c3fa4, on a shallow clone of dbdc9d2 with the previous fixed-point seed as the boot seed (srv1, logs8): main_wet exit 0; required-regen generation 0 drifted gunbc_cli_dispatch_surface.rs (gunbc.cli_dispatch_surface is touched by #13660), generation 1 drifted gunbc_cli_dispatch_generated.rs, generation 2 first_generation_equal=true planned=169 executed=169 adjudicated=169 declared_divergent=1 [main.rs]; verify (dry main) exit 0; rebuild; gunbc test //gunbc/instruments:v2-native-cli exit 0 (emit and build exit_status=0 warning_count=0 wall_s=611, discriminating red on v2_cli_compile_cli) and //gunbc/instruments:self-host exit 0 (wall_s=716, red on v2_compiler_compile). The projections resolved toward #13660's side in the merge (ROADMAP.md, fleet-converge.yml, docs/design-rung-drops.md) were byte-identical to main_wet's output, so only .gitattributes and the two cli_dispatch mirrors change here.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <briansrls@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: x <x@x>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant