Skip to content

CONTROL (do not merge): #13211 head + union-emit begin line - #13620

Closed
gunbai-bot[bot] wants to merge 48 commits into
mainfrom
control/13211-plus-union-begin-line
Closed

gunbai-bot[bot] wants to merge 48 commits into
mainfrom
control/13211-plus-union-begin-line

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Measurement control: #13211 head 7fddcd2 plus only b99d9af (prints fixture-closure-union-emit state=begin with members/outside_prepared before the union compile). Purpose: read the identity join between union members and the prepared subject on #13211's large union. Close after the run.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits October 4, 2026 04:03
…inding (leg 2)

One JIT mint over a slot sum (microVM cell | transient systemd unit on a
gunbc.managed_host host); ensure-style deregistration with org-listing
readback and typed refusal on every exit; teardown inventory generalized to
a host-unit arm; census row for deregistration (pre-approved, ruling
2026-10-03); route legs registration/deregistration bound.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttempt label as input; collect the run back (leg 3)

Generalizes extdeps.github.workflows CreateDispatch from the heal-only
expected_healed_sha key to the upstream's own inputs object, and dissolves
create_dispatch_unconsumed_frontier_rows with a production caller.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ack's subject is the dispatched run

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e the carrier-returning helper (constructor proxy)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pt, token check, workflow compare; split RouteLegStanding

(1) post-delete listing consumes the delete receipts (readback_after_deletes)
(2) JitRegistration sole_constructor, minted only by jit_registration_of
(3) refuse a token or authority for another App/installation
(4) JitDeregistrationReceipt sealed, built only from a GitHub listing
    (OrganizationRunnerListRead sealed); pure classifier kept
(5) slots carry their workflow; mint refuses a group restricted to another
RouteLegStanding = LegWired | LegAuthorityImplemented | LegAwaitingAuthority;
route_is_executable requires LegWired; registration/deregistration are
LegAuthorityImplemented with the wiring they owe.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mplemented with the fleet-converge wiring owed

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… derived runner image until the untangle 4a runner medium

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ambiguous standing, App-token credential, runner-id floor join, attempt-1 binding, ruling+interpretation+interlock

- QualificationDispatchSubject (sole_constructor) minted only from the route's JIT registration and
  its delivered credential, the slot's workflow == the generated fleet-converge workflow, and a floor
  job whose runs-on is exactly the declared attempt input; REDs for other workflows and labels
- dispatch classified through RestMutationExchange: 4xx refused, transport/5xx/undecodable ambiguous
- CreateDispatch takes its bearer as an input; dispatch runs under the gunbai-ci installation token,
  credential checked against DispatchWorkflow; takes the host-generic UnitHoldProof (interlock)
- collection: attempt-scoped jobs, run_attempt == 1, revision pinned, workflow path, and the floor
  job's runner_id == the minted runner id; collected payload keeps the sealed dispatch + WorkflowRun
- WorkflowJobRun gains runner_id/runner_name (upstream job resource fields)
- census: IrreversibleEffect, discharged by the 2026-10-03 ruling (verbatim) through a separate
  scope interpretation (eager-gull-22, 2026-10-04); interlock rostered; narrowed-interpretation RED

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n_ref_in_list arity, no panic)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the minted JitRegistration name); drop runner_id; fix witness braces

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mplate expression (floor NonFoldResidueRosterDiverged)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uery subject (side-chat RC on #13206)

(1) JitMintDispatchAuthorized { dispatch: AuthorizedJitMintDispatch } sole_constructor,
    minted only by dispatch_jit_mint; dispatch_jit_mint, attempt_dispatch and the witness
    helper `dispatched` are admit_callers-sealed so no admitted caller returns it onward.
(2) OrganizationRunnerListRead carries organization, name, App and installation;
    readback_subject_refusal runs before the answer is read; conclude_from_readback,
    its inner step and readback_after_deletes admit only ensure_jit_runner_deregistered.
REDs: compile probe test.probe.jit_deregistration_forged_probe (victim-runner forgeries
of all four sealed records + unadmitted conclusion) enrolled by
test.claim.jit_deregistration_forged_probe_witness; pure readback-subject RED.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… subject consumes the sealed authorized dispatch; witness claims mint in place, admitted by name

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nt case (floor COMPLETED-OVER-COST-REQUIREMENT 604048 > 72300)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pure scope checks, run expectation, hold), ONE real-path claim through the mint

The scope checks and the run decision take values: qualification_slot_refusal,
qualification_floor_admission, QualificationRunExpectation, hold_covers_slot_host. The subject
mint composes them; collect derives the expectation from the sealed subject. Only
the_real_mint_admits_the_attempt_and_refuses_todays_workflow runs dispatch_jit_mint and the
subject mint (admit lists trimmed to it).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rop the fleet_converge_workflow evaluation (~600k eval steps, a fact about generated data)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ts own claim in the long tier, with its measured cost declared (~600k eval steps building the generated model)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…_slot_controller resolved as the union)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ep leg-2's added imports)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…t_converge_workflow (a shape fix: the ~600k-step jobs were built and never read); its refusal claim returns to the module witness

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…h authority bound to the token's installation; runner_id join with name corroboration and a unique floor display name

- JitCredentialBoundToAttempt gains dispatch: AuthorizedJitMintDispatch (set in receive_jit_mint; an
  edit to #13206's type made here per quiet-stag-623); the subject refuses a delivery from another
  dispatch (SubjectDeliveryForAnotherDispatch), RED with two authorized mints for one slot
- dispatch_authority_refusal: the authority must project to the registration's App/installation;
  an ActionsJobCredential refuses (REDs for other App, other installation, job token)
- WorkflowJobRun regains runner_id; the subject carries the delivered runner_id and collection joins
  on it, runner_name corroborating; the floor's display name must be unique at the subject mint

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lification/<attempt> at the revision, the dedicated group pinned to it, removal by readback on every exit

GitHub selects a dispatched (non-reusable) workflow in a runner group only at a branch (docs cited
in extdeps.github.org_actions), so the pin is a branch, not a SHA or tag. New:
- extdeps.github.git_database CreateRef/DeleteRef (+ auth_input beside GITHUB_TOKEN; heal unchanged)
- extdeps.github.org_actions UpdateOrganizationRunnerGroupWorkflows
- gunbc.runner.runner_qualification_ref_pin: QualificationBranchName (one segment under the prefix),
  QualificationGroupWriteTarget (dedicated group only), sealed QualificationRefPin, ensure + removal
- the dispatch subject carries the pin; dispatch ref = the pin branch; mint must be into the pinned
  group; collection refuses a run on another branch (RunOnAnotherBranch)
- census rows + interpretation extension (eager-gull-22, 2026-10-04)
- witnesses: out-of-prefix, pre-existing branch, another group, removal readback, no push workflow
  fires on qualification/**, run on another branch

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…not the sealed dispatch); fixtures build it as a value

The sealed fixture mint (test.claim.github_app_registry dispatched) admits named callers only, so
carrying the sealed dispatch on the open delivery variant would make every hand-built delivery a
proxy. The identity is what the subject's comparison needs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ranch' resolved to another module's declaration; floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s leg-2 content plus this branch's additions, resolved to keep the additions

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… NonFoldResidueRosterDiverged)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…orkflowRuns auth_input

1. JitCredentialBoundToAttempt { bound: BoundJitCredential } -- sole_constructor, built only by
   receive_jit_mint, carrying the complete AuthorizedJitMintDispatch with the credential and runner id
   (JitMintIdentity deleted). The subject requires bound.dispatch == its dispatch: the complete request
   (App, installation, organization, name, runner group, labels, work folder). REDs: same slot/App/
   installation/org/name with another runner group refuses; a rewrapped delivery refuses at
   BoundJitCredential (compiler probe, test.claim.runner_qualification_delivery_rewrap_witness).
   The two hand-built delivery fixtures now mint for their own attempt (admitted helpers).
3. github.WorkflowRuns declares auth_input: auth_token beside GITHUB_TOKEN (callers passing "" keep
   the fallback); collect_qualification_run refuses a token for another App/installation before either
   read (RunCollectedUnderAnotherInstallation), RED in the real-path claim.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 18 commits October 4, 2026 16:49
…git/info/exclude 'probe/' rule kept it out of the earlier commit)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ob checks out inputs.qualification_revision first and refuses on a mismatch; the residual declared

- qualification_revision_dispatch_input; the dispatch sends both the attempt label and the revision
- qualification_floor_revision_guard_step: fetch + checkout the revision, exit 1 unless HEAD equals it;
  the floor contract (qualification_floor_admission) requires it as the FIRST step and refuses any step
  or job that runs past a failure (if:, continue-on-error); emission is the dispatch leg's wiring_owed
- REDs: revision input undeclared, no guard, guard not first, later step with if: always(), later step
  with continue-on-error; the guard compares HEAD to the input and exits 1; post-run head_sha refusal
  remains RunRevisionNotPinned
- RFM qualification_floor_guard_skippable_by_a_workflow_file_edit: a rewritten workflow file on the
  qualification branch can drop the guard (needs repo push); rung, ceiling, next trigger

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…admit only the response-bound path and Bool claims; the delivery fixture hands back a plan, not a delivery; collection reads live inside the token join (no _under); three executed REDs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ollection over the dispatched subject and the token); collect performs only the planned reads; foreign-token RED inside the real-mint claim

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…9b76)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… conflict resolved keeping both sides' imports and claims

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s; covers is the single source of which rows take its discharge (branch-pin sites dropped: federated on their own parameters); claim pins the iff

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion msg_5756a200) recorded as its own row beside the verbatim 10-03 ruling, replacing the agent interpretation; dispatch and branch pins back in covers and every covered row derives its discharge from it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… row takes it only if covers names it); covered sites the selection federates on their own parameters -- registration, deregistration, the reversible branch pins -- do not consume it and owe no interlock

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ts own federated standing, not by the 10-03/10-05 rulings; covers lists ensure_qualification_ref_pin for its branch create only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…me field, no RestExchangePerformance)

Conflicts: github_effect_perform.dag (imports; the generate fold takes main's RestResult and keeps
this branch's admit_callers seal) and github_effect_perform_witness_test.dag (main's RestAnswered
call, this branch's sealed BoundJitCredential pattern). Beyond the conflicts, the port touches
logic: this branch's REST ops drop their outcome fields (CreateDispatch's body is now
result: WorkflowDispatchReceipt), the qualification performers carry RestResult<T>, and the
dispatch, run collection, ref pin and branch removal decisions match RestAnswered/RestRefused and
classify only the refusal (classify_rest_refusal, read or mutation).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dispatch fold

The collection-relabel probe is a fixture; its closure reached gunbc.fleet_converge_workflow through the dispatch module's production wrapper, and from there extdeps.gunbc (WitnessBin.Run), which the fixture-closure union emit refuses for target rust. The wrapper moves to gunbc.runner.runner_qualification_production_subject, the only importer of fleet_converge_workflow; the fold's closure no longer reaches extdeps.gunbc.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…STAYS DELETED prose (review 77507)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…llected (review 77511)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…s row and witness read InterlockedBy

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…' declarations

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
… outside_prepared) before the union compile

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Control reading delivered to deep-ram-343: union-emit begin members=768 outside_prepared=1 prepared_paths=3259 fixture_compiles=252.

@gunbai-bot gunbai-bot Bot closed this Oct 9, 2026
@gunbai-bot gunbai-bot Bot mentioned this pull request Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants