Skip to content

T-WAD Slice 7 canvas: affected-set selection via BinaryShim (row 103) - #2760

Merged
briansrls merged 5 commits into
mainfrom
session/cool-crab-565
May 12, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/cool-crab-565

Conversation

@briansrls

@briansrls briansrls commented May 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md — the Verification-lane design canvas for T-WAD Slice 7 / docs/r3-program-plan.md row 103 (ci_uses_affected_set_selection). The doc specifies: how BinaryShim consumes PR #2713 affected-set lens output; staged first landing (in-runner selection, no required GitHub dynamic matrix) vs end-state (optional matrix fan-out); fail-closed superset rules; dimension ∪ TestClaim / job metadata mapping; YAML path-regex selection non-authoritative; PM sequencing (Slice 4 first; Slices 5 ∥ 8); hard dependency on warm-wolf-698 Slice 5; §9 skeleton for future hermetic tests (feedback_lenses_not_passes, TESTING.md). Canvas only — no emitter, no gunbc-ci binary, no workflow edits.

Scope

In scope Out of scope
Single markdown canvas + citations to existing design docs project_github_actions implementation, Rust CI binary, .github/workflows/ci.yml

Test plan

  • Doc-only PR: no compiler/unit tests are required for correctness of prose.
  • Review: cross-check canvas against docs/design-ci-workflow-emitter-dispatch.md §5.2–§6, docs/design-affected-set-lens.md §2 / §5, docs/r3-structure.md gate ci_uses_affected_set_selection.
  • CI: optional while PR stays draft; mark ready for review (gh pr ready 2760 --repo gunb-ai/gunbc) when intentionally opting into default GitHub auto-coverage.

Worker attestation

  • Title describes the change (not the session id alone).
  • PR body states what / why / scope / test plan (this file).
  • Tests: N/A — documentation only; no Rust or workflow paths changed.
  • Closes # / Fixes #: N/A — work item is internal (dashboard); this PR does not close a GitHub issue by design.
  • Commits on this branch are session-authored canvas + review fixups only.
  • No secrets, credentials, or large binaries.

briansrls and others added 2 commits May 12, 2026 11:24
 draft note

- Spell assumed project_github_actions(BinaryShim) interface (waits on Slice 5).
- Add §9 skeleton for hermetic dispatch-planner tests (feedback_lenses_not_passes).
- Document draft PR workflow and gh pr ready opt-in for CI coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls marked this pull request as ready for review May 12, 2026 15:25
@briansrls
briansrls marked this pull request as draft May 12, 2026 15:26
briansrls and others added 2 commits May 12, 2026 15:26
Co-authored-by: Cursor <cursoragent@cursor.com>
- Header: draft is default; point reviewers at gh pr view for canonical state.
- §1.2 vs §2: separate PM end-state from staged first landing; matrix optional.
- Table clarifies in-runner selection satisfies row 103 without dynamic matrix.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls marked this pull request as ready for review May 12, 2026 15:36
@briansrls

Copy link
Copy Markdown
Contributor Author

Verification (cool-crab-565) — re: dashboard review artifact for review 10202 (claude-opus-4-7, APPROVE).

Checked current branch vs origin/main: one file, docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md (+196 lines). No Rust/YAML/workflow edits. The review’s characterization (docs-only canvas, §3/§4 fail-closed, §5 if: split, Slice 5 deferral, authority alignment) matches the file on HEAD.

Action: No fix commit — there are no actionable findings in that approval.

Merge readiness (re-evaluated): dashboard-ops reviews on this PR reports 1/2 distinct dashboard approval providers (claude only), REQUEST_CHANGES: none, mergeable: MERGEABLE, checks: passing. Per program rule (≥2 distinct approving providers), squash-merge is not executed yet — waiting on a second dashboard-tracked approval (e.g. openai-pro weighted review when scheduled).

— sent from cool-crab-565

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: 76a14b3a · Trigger: manual
  • Comparison: main @ 821b5769 ... session/cool-crab-565 @ 76a14b3a
  • Conversation: View conversation

1. Story of the diff

This PR adds a single design canvas for T-WAD Slice 7: how BinaryShim should use the affected-set lens to decide which CI checks run, without implementing the runner yet. The document makes the dependency chain explicit: Slice 7’s implementation waits on Slice 5’s BinaryShim projection/runtime, and this PR only records the contract, fail-closed behavior, selection rules, path-regex dissolution rule, and future test harness (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:3, :10, :117-129, :190-192). The load-bearing design choice is that initial row-103 satisfaction does not require GitHub dynamic matrix emission; the first implementation can compute the affected set inside the compiled runner and invoke selected checks from there (:56-65). The safety shape is conservative: typed affected-set receipts and modeled metadata are the authority, and any unknown/missing proof path expands to the superset rather than silently skipping checks (:20-24, :71-84, :92-99).

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation). Compliant — this diff is a documentation-only implementation plan, not a substrate change: it states “implementation not in this PR” and adds no Dag-resident types, pass-crossing fields, or dag.rs shapes (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:3, :190-192). It also preserves layer placement by making Slice 5 own the exact runner/lens API while Slice 7 documents the required contract (:34-41).
  2. INVARIANTS.md + modeling-discipline.md. Compliant — fail-closed and single-authority are handled directly. The canvas says affectedness is not re-derived from path globs, consumes typed lens output, and treats the authoritative serialized PR docs(r3): add affected-set Introspect-lens prototype canvas #2713 output as the single source of truth (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:20-24). It also explicitly sends unavailable DAGs, unknown deltas, missing exclusion receipts, incomplete diagnostic-bearing output, absent dimensions, and unmapped workflow nodes to the superset path (:71-80), matching the invariant rule that failures either succeed fully or fail/propagate typed diagnostics rather than fabricating plausible output. chatgpt-review-d72e819e-4699-47…
  3. CODING.md. Compliant — although no Rust is added, the planned implementation shape follows the CODING direction that lenses are pure functions over data and should stay external to Dag: the harness names a pure plan_dispatch(receipt, obligation_metadata) -> RunPlan seam and keeps selection based on structured lens receipts plus declared metadata, not a stateful workflow object or YAML scraping (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:175, :180-186). That lines up with the project’s data + free-functions / “lenses not passes” guidance. chatgpt-review-48c2ca11-cde1-43…
  4. TESTING.md. Compliant — no executable test is expected in this PR because the PR is a canvas and explicitly does not ship runtime code (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:150-165, :190-192). The future test shape is specific and appropriate: unit tests over a dispatch planner with synthetic receipts for unknowns/missing proofs/narrow paths, an optional small integration test for real lens + planner, and a static ratchet over emitted workflow artifacts (:178-188). That matches the uploaded testing discipline: hermetic, behavior-driven, one claim per test, and unit-first. chatgpt-review-bdad0996-b4c3-46…
  5. LOCKED DESIGN DECISIONS. N/A — the diff references parent authorities but does not alter a locked design document or change an existing locked decision. It explicitly says this canvas specializes Slice 7 and “does not reopen” parent emitter placement or WorkflowRuntime shape (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:6).
  6. TRACKED vs UNTRACKED DEBT. Compliant — the only scaffold is declared as a documentation/design canvas and future implementation dependency, with bounds and dissolution triggers: Slice 7 implementation is blocked until Slice 5 provides the thin shim, compiled runner artifact path, hook point, and local reproduction command (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:115-129). The implementation checklist then names the concrete closure work, including deleting path-regex bridges and proving ci_uses_affected_set_selection (:133-146). This is tracked bridge text, not an unbounded TODO.

2.5. Top-down PM intent review

Compliant — the PR preserves the top-level intent rather than diluting it. The PM-level direction for this slice is affected-set selection via BinaryShim; the diff keeps selection authority in the binary/lens path, not in YAML path filters (docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md:20-24, :103-111). It also avoids overstating progress: it says the PR is a verification-lane design canvas, that runtime code is not implemented here, and that integration queues behind Slice 5 (:3, :28-32, :117-129, :190-192). The staging decision is semantically faithful: dynamic GitHub matrix fan-out remains an optional end-state escalation, while row 103 can initially be satisfied by in-runner affected-set selection (:52-65), so the worker following this document would not accidentally build a second YAML selection engine or claim implementation before the BinaryShim hand-off exists.

3. Verdict

APPROVE

This is a documentation-only canvas, and it cleanly names the implementation boundary, fail-closed semantics, single-authority selection source, and future test obligations. I did not find any diff-cited mismatch against the invariant rubric or PM intent.

@briansrls

Copy link
Copy Markdown
Contributor Author

Verification (cool-crab-565) — openai-pro / gpt-5-5-thinking review (comment), HEAD = 76a14b3a.

  • Diff: origin/main...origin/session/cool-crab-565 is still one file — docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md (+196 lines). No Rust/YAML.
  • Substance: Re-read the canvas at 76a14b3a; the review’s claims match the text: docs-only boundary (L3–L4), typed lens receipts + superset table (§3), dimension/TestClaim selection (§4), path-regex vs orthogonal if: (§5), Slice 5 hard dependency + checklist (§6–§7), staged in-runner vs optional matrix (§2), future harness (§9). No diff-cited mismatch and no actionable review items → no fix commit.

Merge readiness (dashboard-ops reviews gunb-ai/gunbc#2760 just now): mergeable = MERGEABLE, checks passing, no REQUEST_CHANGES, not draft. However the dashboard still counts 1/2 distinct approving providers: claude parses as approve (review 10202), while openai-pro (review 10204) is recorded as verdict: "unknown" from the stdout artifact even though the GitHub thread is an explicit APPROVE. Until the dashboard ingests that run as approve (or a second dashboard-counted approval lands), merge_criteria.ready stays false — I am not running gh pr merge yet to stay aligned with the program’s dashboard gate.

If an operator can re-post / re-ingest review 10204 so openai-pro resolves to approve, I can re-run dashboard-ops reviews and squash-merge immediately after it flips to 2/2.

— sent from cool-crab-565

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 76a14b3a · Trigger: schedule
  • Thinking: 262s wall

✅ This design canvas is docs-only and preserves the affected-set, fail-closed, and BinaryShim authority boundaries; I found no blocking concerns.

@briansrls

Copy link
Copy Markdown
Contributor Author

Verification (cool-crab-565) — codex api-review (sha:76a14b3a, schedule): “docs-only … no blocking concerns.”

  • Tree: origin/main...origin/session/cool-crab-565 is unchanged — still only docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md (+196 lines). Matches the review (no new Rust/YAML, boundaries unchanged).
  • Action: No fix commit — there are no substantive findings to implement.

Merge readiness (dashboard-ops reviews gunb-ai/gunbc#2760): mergeable MERGEABLE, checks passing, no REQUEST_CHANGES, not draft — but ready: false, approval_count: 1/2 (claude only). Review 10204 (openai-pro) remains verdict: unknown in the dashboard despite the GitHub APPROVE thread; the codex comment you just posted is not yet present in the dashboard review list (ingestion lag). Per Verification Mgr direction: holding gh pr merge until ready: true or an explicit operator bypass.

— sent from cool-crab-565

@briansrls

Copy link
Copy Markdown
Contributor Author

Operator/parser-lag note for PR #2760.

Dashboard source of truth re-polled immediately before this comment:

Item State
HEAD 76a14b3a5db1329abc6cdf2107fc590969eeff25
Checks passing
Mergeable MERGEABLE
Draft/open ready PR, open
Active reviews 0
REQUEST_CHANGES 0
Dashboard readiness ready=false
Dashboard approvals 1/2, counted provider: claude

Substantive review evidence at this HEAD:

Provider Review/artifact Dashboard verdict Substantive state
claude #10202 dashboard artifact approve APPROVE, counted
openai-pro #10204 / GitHub comment 4432281453 unknown GitHub comment verdict is APPROVE

This appears to be parser lag rather than a code/doc blocker: the openai-pro review text says APPROVE, while dashboard verdict ingestion keeps it as unknown, leaving the PR at 1/2 counted providers. As Verification Mgr I am holding merge while dashboard-ops reviews reports ready=false. Requesting either dashboard verdict backfill for openai-pro #10204 on 76a14b3a5, or explicit operator authorization/merge if this should use the same parser-lag bypass class as prior operator-tier cases.

@briansrls

Copy link
Copy Markdown
Contributor Author

Verification (cool-crab-565) — operator/parser-lag note (this thread).

Re-polled dashboard-ops reviews https://github.com/gunb-ai/gunbc/pull/2760 and gh pr view 2760 just now: head_sha = 76a14b3a5db1329abc6cdf2107fc590969eeff25, checks passing, mergeable = MERGEABLE, PR open and not draft, ready: false, approval_count = 1/2 with counted provider claude only; openai-pro review 10204 still verdict: unknown while the linked GitHub thread is substantive APPROVE. git diff --stat origin/main...origin/session/cool-crab-565 is still the single canvas file (+196 lines) — no doc/code delta needed for this ingestion gap.

Action: No commit. Continuing to hold gh pr merge until ready: true or explicit operator bypass/merge (per Verification Mgr).

— sent from cool-crab-565

@briansrls
briansrls merged commit 598a463 into main May 12, 2026
3 checks passed
briansrls added a commit that referenced this pull request May 12, 2026
…x inventory ratchet (#2766)

* docs(r3): T-WAD Slice 7 pre-impl prequeue — harness contract + Layer 2 path-regex inventory ratchet

Verification-lane scaffolding queued behind warm-wolf-698 Slice 5 (BinaryShim
emitter + runner + project_github_actions hook). This PR does NOT satisfy gate
`ci_uses_affected_set_selection` (program-plan row 103) and does NOT modify
workflow behavior — parent directive (clever-tern-670 msg_1e664a12) explicitly
scopes this work item to (1) §9 hermetic harness contract pre-authored without
fabricating Slice 5 substrate, and (2) observational fail-closed inventory of
current authoritative path-regex selection in .github/workflows/ci.yml.

Deliverables:

- docs/design-t-wad-slice-7-implementation-prequeue.md — companion to the
  canvas in PR #2760; pins §3 inventory of the `changes:` docs-only allowlist
  + the `v3:` job `if:` that consumes it; specifies §5 hermetic planner test
  contract (no Rust types declared — those are Slice 5 / lens-substrate
  authorities per INVARIANTS P2 + feedback_import_not_redeclare_carriers).

- scripts/check-workflow-path-regex-inventory.sh — fail-closed both directions:
  fails if a new path-regex authoritative selection appears OR if an inventoried
  site is removed before BinaryShim replacement is wired. Not invoked from
  ci.yml (would itself be a CI behavior change); reviewers + Slice 7
  implementation PR invoke it manually as part of the dissolution receipt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): ratchet scans ci.yml itself for new path-regex bridges (codex BLOCKING)

Codex review on #2766 BLOCKING: scripts/check-workflow-path-regex-inventory.sh
v1 skipped .github/workflows/ci.yml in the drift loop, so the inventoried file
could grow a second un-inventoried path-regex selector without tripping the
ratchet — fail-open against INVARIANTS P3 / Practice 1.

Tighten: count `git diff --name-only` invocations across ALL workflow files
(including ci.yml), compare against expected baseline (1 — the §3 row #1
invocation anchored at `origin/main...HEAD`). Any occurrence beyond the
inventoried anchor fails with a pointer to the prequeue doc.

Verified both directions:
 - baseline still passes ('ok 2/2 inventoried sites present, no new bridges')
 - injecting a second `git diff --name-only HEAD~1 HEAD` into ci.yml fails
   with line + remediation pointer

Doc §4 first bullet tightened to match the broader scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): broaden ratchet to non-diff path-regex bridges (codex BLOCKING)

Codex review 10240 on #2766 BLOCKING: prior ratchet only detected
`git diff --name-only` bridges; a new authority introduced via `paths:`/
`paths-ignore:`, `dorny/paths-filter`, or `tj-actions/changed-files` would
have passed silently — overclaim against INVARIANTS P2/P3 + Practice 5.

Broadened the detector to a second class spanning all workflow files:
trigger-level `paths:`/`paths-ignore:`, `dorny/paths-filter` use, `tj-actions/
changed-files` use, and `paths-filter@` uses-clause substring. Current
baseline across all .github/workflows/*.yml is zero occurrences for the
non-diff class, so the default stance is fail-closed (any introduction
fails). Future event-orthogonal use must be documented in §3 + allowlisted
in the script.

Doc §4 first bullet rewritten to spell out both detector classes explicitly,
matching what the script enforces.

Verified all 4 mechanisms fail-closed on injected fixtures (paths,
paths-ignore, dorny/paths-filter, tj-actions/changed-files); baseline still
passes after restore.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): close duplicate-anchor count-overflow gap in ratchet (cursor APPROVE_WITH_COMMENTS)

Cursor review 10250 NON-BLOCKING but accurate: when actual_diff_count >
expected_diff_count but every overflow line still matches the inventoried
anchor verbatim (e.g. a copy-paste of the §3 row #1 invocation), the prior
loop iterated zero times and no failure fired — fail-open against the §4 /
INVARIANTS P3 contract.

Now: when count exceeds baseline and extra_locations is empty (all overflow
lines are duplicates of the anchor), emit a dedicated duplicate-anchor
diagnostic with same remediation pointer.

Verified: baseline still passes; injecting a second verbatim
`git diff --name-only origin/main...HEAD` line into ci.yml now fails with
the duplicate-anchor message.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): scan both .yml and .yaml workflow files (briansrls BLOCKING)

Operator BLOCKING review on #2766: prior ratchet narrowed the workflow-file
universe to `*.yml`, so a new path-regex bridge introduced via a `*.yaml`
file would have passed silently — fail-open extension gap.

Factor the workflow-file glob into a single `workflow_files_nul` helper used
by BOTH detector pipelines (diff-bridge count + non-diff mechanisms). The
helper covers `.github/workflows/{*.yml,*.yaml}` — both extensions are
honored by GitHub Actions. New extensions cannot create another fail-open
gap because every detector consumes the same source-of-truth helper.

Doc §1 / §2 / §4 references to `*.yml` widened to `{*.yml,*.yaml}` with an
explicit note that the helper is the single source of truth.

Verified: baseline still passes; injecting a new `*.yaml` workflow with a
fresh `git diff --name-only HEAD~1 HEAD` line is detected with file:line
and remediation pointer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): add raw-literal authoritative-text block to §3 (cursor 10260)

Cursor review 10260 NON-BLOCKING (APPROVE_WITH_COMMENTS) — accurate: §3
table cell quoted the docs-only allowlist regex with markdown table-escape
`\|` so the raw markdown source string did not match the live ci.yml literal
nor the ratchet's PATH_REGEX_FILTER pin. Reviewers told to "treat as
inventory truth" could not grep the doc and hit the same string.

Add a non-table fenced code block above the table holding the three
authoritative literals verbatim (docs-only allowlist filter, the inventoried
`git diff --name-only` anchor, the if-gate substring fingerprint). Table
cells now reference "literal above" instead of duplicating the escaped form.

Three-way grep verifies:
 - docs/design-t-wad-slice-7-implementation-prequeue.md L69
 - .github/workflows/ci.yml L238
 - scripts/check-workflow-path-regex-inventory.sh L64 (PATH_REGEX_FILTER)
all carry the same literal `grep -vE '^(docs/.*|[^/]+\.md)$'`.

INVARIANTS P1 ("Documentation Describes Live State") preserved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): close anchor-host + underflow gaps in ratchet (cursor 10271)

Cursor review 10271 NON-BLOCKING but accurate: §4 promised fail-closed in
both directions, but the count branch silently passed in two cases:

  (a) actual_diff_count == 1 with the sole match OUTSIDE ci.yml — neither
      `>` nor `<` branch fired and the earlier PATH_REGEX_FILTER pin
      (different literal) did not catch a refactor that kept the docs-only
      allowlist regex but moved the diff anchor elsewhere.

  (b) actual_diff_count < expected_diff_count and inventoried_present == 0
      — the branch ran `:` and exited success.

Tightened:

 - Anchor-host invariant: independently fail if the §3 row #1 anchor
   `git diff --name-only origin/main...HEAD` is not present in ci.yml,
   regardless of count or extra_locations. This closes case (a).

 - Count underflow: fail if actual_diff_count < expected_diff_count
   (anchor removed before BinaryShim replacement is wired). This closes
   case (b).

Verified:
 - Baseline still passes.
 - Case (a) (anchor moved to sibling .yml): fails with anchor-host message.
 - Case (b) (anchor deleted entirely): fails with BOTH anchor-host AND
   count-underflow messages (defense-in-depth).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(t-wad-slice-7): narrow paths:/paths-ignore: detector to trigger-level only (codex 10280)

Codex review 10280 NON-BLOCKING (APPROVE_WITH_COMMENTS) — accurate doc-vs-impl
mismatch (INVARIANTS P2 / Practice 5 single-authority):

Prior detector greped `^[[:space:]]*paths(-ignore)?:` anywhere in a workflow
file. The prequeue doc §4 scopes this to trigger-level `paths:` /
`paths-ignore:` under on.push/on.pull_request. Step-input `paths:` keys
(e.g., under a `with:` block of `dorny/paths-filter` itself, or other
step inputs) would have triggered the ratchet despite not being
authoritative path-regex selection.

Replaced the regex with an awk state-machine that only flags
`paths:` / `paths-ignore:` keys appearing under `on:` →
`push:` / `pull_request:` / `pull_request_target:`. Step inputs and
unrelated YAML blocks are no longer flagged.

Split the action-name detection (dorny/paths-filter, tj-actions/changed-files,
`paths-filter@`) into its own clearly-scoped loop with a distinct message,
since those are step uses-clauses with no false-positive risk.

Verified scoping:
 - trigger-level `paths:` under on.pull_request → fails (correct)
 - trigger-level `paths-ignore:` under on.push → fails (correct)
 - `paths:` inside a step `with:` block → passes (correct, no false positive)
 - dorny/paths-filter step use → fails via action-name detector (correct)
 - baseline still passes

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant