Skip to content

chore: delete internal-only content for public repo visibility flip - #4192

Merged
briansrls merged 2 commits into
mainfrom
session/wise-ant-469
Jun 1, 2026
Merged

briansrls merged 2 commits into
mainfrom
session/wise-ant-469

Conversation

@briansrls

@briansrls briansrls commented Jun 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Operator decision 2026-06-01: pivot to gunb-ai/gunbc as the public repo. This mechanical PR removes all internal-only content ahead of the visibility flip:

  • docs/ — entire directory (~818 files: briefs, planning, audit, history, debt, etc.)
  • _internal/, .cursor/, wip/ — internal ops and agent metadata
  • scripts/session-dashboard/, scripts/_internal/ — dashboard and release tooling
  • RELEASE_TODO.md, WISHLIST.md — maintainer scratchpads
  • src/v4/{TASKS,BRIEF_TEMPLATE,CULTURE,DECISIONS}.md — agent process docs
  • src/v2/{CM,CM-inventory,cx-violation-triage}.md — internal design notes
  • dsl/examples/interp_test/{rest_test,shell_test}.dag — internal fixtures

CI wiring updated to drop references to deleted planning docs (ci.yml, Wave 1/3 smoke tests, check-ci-no-new-shell.sh). closure_ledger_gate.rs inlines the L6 key snapshot formerly read from docs/r2-closure-ledger.md.

Test plan

  • bash scripts/check-ci-no-new-shell.sh --self-test — pass
  • bash scripts/check-ci-no-new-shell.sh — pass
  • CI floor on PR (fmt + M1 + bootstrap + ci.dag binding + no-new-shell)

@briansrls briansrls changed the title Release Jun1 one-shot public-repo cleanup (operator decision 2026-06-01: pivot to gunb-ai/gunbc as the public repo, delete docs/ entirely, prepare for visibility flip). Single mechanical PR deleting all internal-only content. DELETE (wholesale, git rm -r): - docs/ (818 files — entire directory; ope chore: delete internal-only content for public repo visibility flip Jun 1, 2026
@briansrls
briansrls marked this pull request as ready for review June 1, 2026 13:38
@briansrls
briansrls merged commit eceeed7 into main Jun 1, 2026
6 of 7 checks passed
briansrls added a commit that referenced this pull request Jun 1, 2026
…p sg0 census TS grammar-inverse receipts)

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls briansrls mentioned this pull request Jun 1, 2026
4 tasks done
briansrls added a commit that referenced this pull request Jun 1, 2026
…or the right-way sccache projection (#4197)

* WIP: CI floor

* ci.dag: cite durable in-repo cache authority (worksheets deleted in #4192 public flip)
briansrls added a commit that referenced this pull request Jun 1, 2026
Retarget P5 checkable receipts from deleted docs/briefs/ to INVARIANTS.md
(post-#4192). Apply cargo fmt multiline formatting CI required.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jun 1, 2026
* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* chore: remove stale public cleanup test anchors

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: remove stale CI carrier regeneration wording

* docs: drop orphaned workflow brief receipt claim

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: align cleanup receipts with static CI carrier

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: clarify P5 dissolution receipts

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* ci: refresh pinned workflow carrier
briansrls added a commit that referenced this pull request Jun 1, 2026
…oc policy

Worksheet content delivered as a dashboard receipt to the RCA manager for
PM aggregation in ctrl gunbc-planning instead. No planning markdown lands
under gunb-ai/gunbc.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 1, 2026
…shells (#4162)

* docs: add v4 modeling DFS ratification log

Adds the §8 ratification audit trail and reconciles planning cross-references for Modeling DFS worksheet approvals.

* Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via SG-RC plus SG-2 residual constraints (#4153)

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* fix SG-RC Outcome claim projection argument

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via SG-RC

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via SG-RC

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* Remove temporary stage0 emitter debug

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* Remove stage0 emitter diagnostic

* Document Outcome smoke P5 receipt

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* WIP: Outcome ownership implementation — Outcome/Rc<Outcome> E0308 route via S

* Wave 3 Phase 1: CiSelectionReceipt extension + fixture shadow receipt (live CI deferred) (#4174)

* fix: rebase #4174 on main — receipt extension only (consume #4178)

Rebase onto origin/main after #4178 merged wave3_shadow_roster.dag and the
runtime selection API. Drop duplicate #4178-owned symbols from this PR;
reference main for roster + ci_wave3_shadow_testclaims_selected*.

Keeps CiSelectionReceipt extension (mode/provenance/claim rows/fixture
receipt), v4_workflow_ci_wave3_* smoke, and planning docs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Wave 3: affected-set + testgen shadow integration (coordinate neat-hawk-

* fix: restore M1 ledger honesty + smoke parity after rebase (#4174)

- Revert ci-required-surface-cut gate-3 row to match modeled authority
  (V4_M1_RUST_EMIT_PROBE_STRICT=0 in ci.dag/ci.yml; preconditions fail-closed).
- Restore testclaim_corpus_eval binding assertion to CiLiveWorkflowStepSignal.
- Restore M1 smoke: nested M1CiLiveWorkflowSignal.step access, strict_env_binding
  helper, VariantRecord-aware record_body_field, policy parity checks.

Addresses codex REQUEST_CHANGES on ef0f438.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>

* Python L1 pyright/mypy static structural checks implementation (#4158)

* WIP: Python L1 pyright/mypy static structural checks implementation

* WIP: Python L1 pyright/mypy static structural checks implementation

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix: address python static CI failures

* fix: clean up python static smoke test

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix(v4): address review #23594/#23595 on PY-L1 static slice

- mypy.dag: import Bool from v4.std.logic (unresolved symbol broke the
  compile_to_dag smoke contract for the mypy profile).
- v4-leaf-model-python-l1-static-verify.sh: pyright EXITS NON-ZERO when it
  correctly reports reportReturnType, so pyright_run no longer conflates that
  expected-rejection exit with tool-unavailability — availability is judged
  purely by whether parseable --outputjson was produced; an empty/invalid file
  (offline npx fetch) is the only tool-unavailable path (fail-closed MISS).
- Add scripts/ci-merge/sg0-pr-body-append.4158.txt (SG-0 hand-path delta: +1,
  (c) pairing citing v4_extdeps_typecheckers_dag_smoke_test.rs + T-PB-B + #4158).
- Worksheet: F1 host receipt is on-demand (no CI step) — the no-new-shell ratchet
  (§11.7.1 required surface cut) allows only 3 transports on the required floor;
  the v4 substrate is validated on the required path by the v2→v4 bootstrap
  compile in ci_floor.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix(v4): de-conflate profile/tool identity + make BlockingForRung structural

Addresses codex scheduled review (sha 871b898) — 2 BLOCKING:

1. tool_profile_ref conflated profile identity with tool identity (filled with
   pyright_tool_id), so pyright_profile_l1's version/mode facts never flowed into
   the fixture (Facts-Flow-Forward / single-authority). Add distinct profile-identity
   Symbols pyright_profile_l1_id / mypy_profile_l1_id; the invocation's tool_profile_ref
   now references the PROFILE row, while the verdict's tool_id stays the tool identity.

2. LeafModelPythonStatic{Happy,Falsification}Case stored a free TargetStaticAnalysisInvocation,
   so a blocking fixture could be built with analysis_role: Advisory. Cases now carry only
   artifact + tool_profile_ref (+ tool_id/diagnostic_code for falsification); the invocation
   is CONSTRUCTED with analysis_role: BlockingForRung by accessor fns
   (leaf_model_python_static_{happy,falsification}_invocation). The blocking role and the
   profile/tool distinction are guaranteed by construction, not accepted as free fields.

Lens + claim updated to the new case shape; claim now also asserts tool_profile_ref ==
pyright_profile_l1_id flows. Verify script unchanged (fixture sources identical) — re-ran
PROVEN. NOTE: .dag changes not locally compile-validated (host load ~50, fork EAGAIN);
relying on CI ci_floor bootstrap compile.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(v4): clarify static tool identity comments

* fix(v4): F1 runner consumes the modeled pyright profile (single authority)

Addresses codex REQUEST_CHANGES #23685: the runner used any pyright on PATH
without pinning the modeled version/config, so the F1 receipt could pass under a
different tool profile than pyright_profile_l1_id references.

Now the runner reads pyright_profile_l1 facts from pyright.dag (single authority):
- pyright_version → pins exactly that version (PATH pyright used only if its
  --version matches; otherwise npx pins it; else fail-closed unavailable),
- python_version + type_checking_mode → written to a generated pyrightconfig.json
  that pyright auto-discovers for the fixtures.
The receipt records the consumed version/python_version/mode. Re-ran: PROVEN
(pyright 1.1.410, python 3.11, standard; falsification reportReturnType).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix(v4): address openai-pro REQUEST_CHANGES (single-authority + no-prose)

1. P2 single-authority: the F1 host receipt no longer hardcodes the pyright rule
   string. It reads the fixture's modeled expected diagnostic_code from the lens and
   resolves the rule_name from the pyright_diagnostic_rules row in pyright.dag, so the
   receipt can't drift from the modeled diagnostic namespace. Re-ran: PROVEN.
2. CODING.md no-prose / Practice 9: reduced the verbose "tried X, rejected Y"
   dissolution analysis embedded in TargetStaticAnalysisRole / TargetStaticAnalysisVerdict
   (leaf_model_verification.dag) and PyrightTypeCheckingMode (pyright.dag) to one-line
   🟢-terminal carrier tags; the full dissolution analysis is recorded in PR #4158 review.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix(v4): model pyright typeCheckingMode keyword spelling (single authority)

Addresses codex REQUEST_CHANGES #23765: the host receipt's mode_map re-authored
the PyrightTypeCheckingMode → config-keyword mapping (off/basic/standard/strict),
a second authority for a modeled profile fact (P2 / Practices 3,5).

pyright.dag now carries the modeled projection pyright_type_checking_mode_spellings
(variant_name → keyword). The runner resolves the typeCheckingMode keyword from that
row keyed by the profile's variant — no parallel mode map. Combined with the earlier
version/python-version/rule-string sourcing, the script now owns ZERO pyright
semantics; every pyright fact flows from pyright.dag. Re-ran: PROVEN.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(v4): key pyright mode-spelling projection by the enum variant (M4/P2)

Addresses codex REQUEST_CHANGES (sha f0ab617): PyrightTypeCheckingModeSpelling
modeled the enum member as a string proxy (variant_name: String), splitting the
closed PyrightTypeCheckingMode enum from its config spelling into two authorities.

The row is now keyed by a PyrightTypeCheckingMode value
(`PyrightTypeCheckingModeSpelling { mode: PyrightTypeCheckingMode, keyword: String }`,
rows use PyrightModeOff/Basic/Standard/Strict), so the enum and its spelling are one
authority. The host runner consumes that typed row (matches `mode: <variant>`) keyed by
the profile's modeled variant. Re-ran: PROVEN.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(v4): bind pyright to the generated profile config (--project)

Addresses openai-pro REQUEST_CHANGES (sha fad72bd): the F1 runner wrote the
modeled profile into ${scratch}/pyrightconfig.json but invoked pyright from the
repo root without --project, so pyright's config discovery was not structurally
bound to the generated config — the same-profile proof was not mechanically
guaranteed (P2 single authority / facts-flow-forward).

Both pyright command paths now pass `--project "$scratch"`, binding pyright to the
pyrightconfig.json carrying the modeled pythonVersion + typeCheckingMode. The run
provably consumes pyright_profile_l1 rather than ambient/default config. Re-ran:
PROVEN (happy clean, falsification reportReturnType).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Python L1 pyright/mypy static structural checks implementation

* fix(v4): drop broken v3 smoke; validate profiles via whole-tree v2 gate

Addresses codex REQUEST_CHANGES (sha 8f5432e): the bespoke v3 hand-Rust smoke
`v4_extdeps_typecheckers_dag_smoke_test.rs` was mechanically failing. Its flat
`compile_to_dag_modules_in_order` chain transitively pulls in src/v4/std/logic.dag,
which the isolated v3 compile path cannot parse (`BoolWidthFact {}` → "expected field
label, got LBrace"). The profiles need text → logic, so a compatible flat chain isn't
available on the v3 path.

Per codex's whole-tree/generated-gate alternative: drop the v3 smoke and rely on the
`v2 → v4 bootstrap compile (fail-closed full)` step in ci_floor, which compiles all of
src/v4 (pyright.dag + mypy.dag + the std static-analysis carriers) — the v2 path parses
logic.dag fine. Removes the failing test plus its SG-0 census entry, INVARIANTS_OPS row,
and sg0-pr-body-append.4158.txt (net hand-Rust census delta is now 0). Worksheet updated.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(v4): remove unconsumed mypy profile (E-6); track as bounded follow-up

Addresses openai-pro REQUEST_CHANGES (sha 4910860): mypy.dag added a
mypy_profile_l1 + diagnostic namespace with NO same-PR consumer — the fixture,
.dag claim, and host runner are pyright-only. Per INVARIANTS E-6 / Boundary
Discipline a new target-spec extdeps fact is real only when a same-PR consumer
lands; an unconsumed mypy profile is dormant scaffold.

Per the offered remove-or-track option (and since mypy is not installable in the
current env, so a mypy F1 receipt can't be proven here): remove
src/v4/extdeps/typecheckers/mypy.dag from this slice and record mypy as bounded
tracked debt in the worksheet (owner = Python RCA Manager; trigger = land mypy.dag
together with a mypy fixture/claim/fail-closed receipt). The shared
TargetStaticAnalysis* carriers already accept a mypy profile by Symbol, so the
follow-up is additive — no carrier change. pyright remains fully consumed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(merge): resolve conflict markers left in the main merge commit

The auto-committed merge ab3c1fc landed with conflict markers still present in
src/v4/std/leaf_model_verification.dag, src/v4/lens/leaf_model_verification.dag, and
the worksheet. This commit applies the resolved content: keep BOTH the Python
PY-L1 static-analysis carriers/fixtures (this PR) and main's TypeScript
leaf-model carriers/fixtures (additive, distinct types); merge the import lists and
claim-id lists; take main's worksheet status line updated to note Worksheet A is
implemented in #4158.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* TS L0 impl (1/5): algebra inhabitance widening — ts_*_facts_* data lines per v4-ts-algebra-inhabitance-widening-worksheet-2026-06-01.md §10.0 (#4155)

* WIP: TS L0 impl (1/5): algebra inhabitance widening — ts_*_facts_* data lines

* WIP: TS L0 impl (1/5): algebra inhabitance widening — ts_*_facts_* data lines

* Merge origin/main into session/fierce-deer-550

Resolve typescript.dag conflict: main landed the number/bigint
algebra-inhabitance fact rows (+ SG-1 atom-realization block) via a
sibling PR. Dedupe — keep main's number/bigint rows once and the
atom-realization block; this PR's net-new content is the boolean row
(ts_bool_algebra_inhabitance_ts_facts_boolean, with E-6 staging marker)
and the string row (ts_string_algebra_inhabitance_ts_facts_string,
clean-merged).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore: delete internal-only content for public repo visibility flip (#4192)

* WIP: Release Jun1 one-shot public-repo cleanup (operator decision 2026-06-01:

* WIP: Release Jun1 one-shot public-repo cleanup (operator decision 2026-06-01:

* Add TypeScript TargetAtomRealization rows (#4189)

* WIP: TS L0 impl (3/5): TargetAtomRealization rows (Symbol/boolean/string) per

* Add TypeScript target atom realization rows

* Dissolve duplicate TypeScript symbol atom row

* Use structural String carrier for TypeScript atom row

* WIP: TS L0 impl (3/5): TargetAtomRealization rows (Symbol/boolean/string) per

* Fail closed for string value templates

* Use projections for string value templates

* Add FreeMonoid node projection receipt

* Declare SourceAtomValue as coproduct

* Document SourceAtomString raw node bridge

* TS L0 impl (5/5): grammar-inverse TestClaims G1+G2 — mvp1 add-fn + wave2a type_alias per v4-ts-grammar-inverse-testclaims-worksheet (#4156)

* WIP: TS L0 impl (5/5): grammar-inverse TestClaims G1+G2 — mvp1 add-fn + wave2

* WIP: TS L0 impl (5/5): grammar-inverse TestClaims G1+G2 — mvp1 add-fn + wave2

* WIP: TS L0 impl (5/5): grammar-inverse TestClaims G1+G2 — mvp1 add-fn + wave2

* docs: add P5 receipt for TS grammar inverse ratchet

* WIP: TS L0 impl (5/5): grammar-inverse TestClaims G1+G2 — mvp1 add-fn + wave2

* test: assert TS grammar inverse anchor bindings

* style: rustfmt TS grammar inverse test

---------

Co-authored-by: Cursor <cursoragent@cursor.com>

* T-38: restore corpus receipt smoke coverage (#4191)

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* fix(t38): require generated corpus tally conjunction

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* fix(t38): match modeled manual corpus gate

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* Tighten generated corpus eval receipt probes

* Merge origin/main into T-38 receipt follow-up

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* Test inverted corpus tally receipt rejection

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* Tighten T-38 receipt smoke needle

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* Anchor T-38 tally receipt to body tail

* WIP: Runtime/TestClaim Manager — authority over T-22 eval execution, T-38 str

* Pin T-38 inverted tally receipt subject

* Fix shared applied type Rc authority (#4190)

* ci_floor: de-churn cargo cache key (stop-the-bleeding) + model note for the right-way sccache projection (#4197)

* WIP: CI floor

* ci.dag: cite durable in-repo cache authority (worksheets deleted in #4192 public flip)

* ci_floor: route M1 emit-probe through host compute governor (memory-denominated dynamic jobs + jobserver + sccache) (#4210)

* WIP: CI floor

* WIP: CI floor

* WIP: CI floor

* chore: close Jun1 public cleanup gaps (#4200)

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* chore: remove stale public cleanup test anchors

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: remove stale CI carrier regeneration wording

* docs: drop orphaned workflow brief receipt claim

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: align cleanup receipts with static CI carrier

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* docs: clarify P5 dissolution receipts

* WIP: Release Jun1 public-repo cleanup gap-fix (follow-on to merged PR #4192):

* ci: refresh pinned workflow carrier

* ci_floor: M1 emit-probe fail-closed on host governor (remove static --jobs fallback) (#4212)

* WIP: CI floor

* WIP: CI floor

* WIP: CI floor

* WIP: CI floor

* ci_floor: M1 emit-probe fail-closed (no static fallback) + sync regen artifact SHA/env

* ci_floor: M1 emit-probe couples to host jobserver (MAKEFLAGS on GHA / ctrl-build in session), fail-closed on neither

ctrl-build is not installed on GHA runners — #4210's ctrl-build routing was a silent no-op
(always hit the --jobs 4 fallback). GHA couples to the jobserver via the actions-runner@.service
MAKEFLAGS instead, so raw cargo joins the pool directly (jobserver bounds rustc processes
host-wide: fill when idle, pare under load). Probe now runs jobserver-coupled with no fallback,
capped per-invocation at the ceiling; echoes MAKEFLAGS for verification.

* ci_floor: reframe M1 parallelism comments as jobserver-coupled (not ctrl-build-centric); sync ci.yml Source-SHA256

Addresses cursor review nit on #4212: ci.yml + smoke-test comments framed governance as
ctrl-build, but GHA is MAKEFLAGS-coupled without ctrl-build. Comments now match the authoritative
ci.dag/probe logic. ci.yml comment change → recomputed Source-SHA256 pin in the regen artifact.

* Go leaf-model: R1/R2a/R2b/R3-external claims, lens fixtures, verify scripts

Admin-merge onto main post-#4164/#4168 (orphan #4162 path-b).
Leaf-only diff: scripts, go_r*.dag, lens/std leaf_model_verification carriers.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the session/wise-ant-469 branch June 1, 2026 18:43
briansrls added a commit that referenced this pull request Jun 3, 2026
Point live M1 gate at .github/ci-floor/v4-m1-rust-emit-probe.sh (v2 emit
receipt only). Recover SG-8 F1–F4 and #4140 rustc histogram via git show
after #4192 removed planning/audit paths.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jun 6, 2026
Remove lens-register markdown ratchets and E-M doc prose checks that
read docs/v3-lens-capability-register.md (deleted #4192). Keep the
structural gate #83 ratchet over std.verification lens_capability_register_rows.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Jun 7, 2026
…delink

The prior pass delinked dead Markdown links to bare backtick paths, which sidesteps
check_doc_refs.py (it only checks [text](path) links) and leaves dead prose pointers.
Fixing properly:

- src/v3/DOWNSTREAM_REQUIREMENTS.md: removed the self-contradiction left by the strip
  ("was pruned from this file" ... "Retained there for audit traceability") and the two
  remaining prose references to the nonexistent docs/history enumeration file.
- dsl/std/runtime/bin_shims/README.md: replaced the dead-ref scaffolding (frozen-v3
  PB-runtime program; all referenced briefs/design docs were deleted in #4192) with a
  concise stub keeping only the live anchors (bin_shim.dag, process.dag, INVARIANTS).
- .github/PULL_REQUEST_TEMPLATE.md: reverted to main (un-touched). Its dead _internal/*
  + briefs/debt references are pre-existing main debt for a wholesale-deleted internal
  apparatus; a proper trim of the v3-census-gate sections is a separate process-template
  decision, not a delink in this PR. Touch-driven gate leaves untouched-file debt alone.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 7, 2026
…ence-resolver gate (#4519)

* WIP: mgmt

* docs: consolidate doc authority — one rule, fold-DELETE duplicate maps, add reference-resolver gate

Establishes the single-authority rule for docs (one fact, one canonical home;
every other mention links, never restates) — P2/M2 applied to prose.

- Refreshes docs/thesis/doc-authority.md from a stale docs/thesis-only contract
  (its prior version cited a ROADMAP structure — "Release R1 Program", lane table,
  tracked-debt ledger at fixed line numbers — that no longer exists) into the
  whole-tree doc map + rule, with the sound mode-tagging discipline kept.
- Fold-DELETEs the two duplicate maps (THESIS "How the docs connect", ROADMAP
  "How to read the tree") to one-line links to doc-authority.md.
- Adds scripts/check_doc_refs.py — the construction-tier detection: every Markdown
  reference must resolve. Census: 99 dangling refs across 87 files; per the
  touch-driven discipline those clear on touch, not by sweep. Fixes ROADMAP's own
  2 dead links (the doc touched here). CI wiring (--changed origin/main) pending
  operator OK per the CI single-authority rule.

Scoped to the ratified W1 core. Tracked follow-ups in the same sub-lane:
coercion-mismatch taxonomy re-home (ROADMAP -> docs/design), planning/ -> ctrl
per-doc, DIRECTION-CHECKLIST inline authority refs (after #4518 merges), ci.yml wiring.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: mgmt

* docs+ci: combine direction-checklist into the consolidation PR; wire the reference gate into CI

Combines PR #4518 (DIRECTION-CHECKLIST.md) into this PR so the doc-direction work
is one change (operator: "put 4518 and 4519 together so we don't miss it").

- DIRECTION-CHECKLIST.md added with a per-item authority ref ("-> home") on every
  item, proving it is a deferring view, not a 9th authority (operator ask). Refs are
  plain-text section pointers, not links -- terse, and they don't create 40 new
  link-maintenance points the reference gate would police.
- docs/thesis/doc-authority.md: DIRECTION-CHECKLIST promoted from in-flight [target]
  to a live link (it's now in this PR).
- .github/workflows/ci.yml: new doc_refs job runs scripts/check_doc_refs.py
  --changed origin/main on every non-draft PR and rolls into the `ci` aggregator
  (fail-closed). Touch-driven: a touched doc with an unresolved reference fails the
  gate -- no repo-wide sweep, no ratchet baseline. Promoting doc_refs to a
  branch-protection required check is the operator's step.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs+ci: generate the actual doc-chain diagram into doc-authority.md

check_doc_refs.py gains a graph mode: it renders the doc *chain* (which doc
references which) as a Mermaid diagram computed from the real Markdown links —
not hand-drawn — so the "actual chain" can be checked against the declared
authority DAG instead of trusted.

- --graph        prints the Mermaid block (36 nodes / 93 edges over root + docs/**)
- --write-graph  regenerates the block embedded in docs/thesis/doc-authority.md
- --check-graph  fails if the embedded block is stale (drift gate)

doc-authority.md gains a "The doc chain as it actually is (generated)" section
holding the diagram between do-not-hand-edit markers. The doc_refs CI job now also
runs --check-graph, so the diagram cannot silently drift from the link structure.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: mgmt

* WIP: mgmt

* docs: strip dangling subdoc citations from INVARIANTS.md + MODELING.md

The two biggest rule docs cited ~61 subdocs (docs/invariants/*, docs/modeling/*,
docs/design-*, docs/debt/*, _internal/*) that don't exist -- the rationale they
pointed at was either inline or never authored. Per the operator's err-toward-deletion
call:

- INVARIANTS.md: removed 6 inline dead citations, dropped the entirely-dead "Subdoc"
  column from the appendix ID table (kept ID / principle / short-form + the #id
  anchors used by "violates C-8"-style refs), and trimmed the Pointers section to the
  one live target (docs/thesis/).
- MODELING.md: rewritten to the genuine slim rule surface -- M1-M10 and every
  principle statement verbatim; removed all dead "See docs/modeling/X" pointers and
  the empty Exemplary-models / Per-file-findings / Deleted-files / Known-future-work /
  Appendix scaffolding sections (which existed only to point at nonexistent subdocs).

No rule text changed; only dead pointers and empty scaffolding removed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs: DIRECTION-CHECKLIST v1.1 — THESIS/INVARIANTS gap audit

Add scannable items for dependency-graph default parallelism, ownership,
two groundings, CX/structural-termination checker, grounding completeness,
model-before-implement gate, map-vs-territory discipline, and single doc
authority. Fast scan grows to 8 questions (grounding + load-bearing gate).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* docs(ci): address #4519 manager review — split doc_refs CI gate

- Revert ci.yml doc_refs job + aggregator wiring (hold for operator GO follow-up)
- doc-authority: script [live], CI wiring [target]; remove stale [proposed] drift

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(authority): flip CI-wiring status [proposed] -> [live]

Review (still-raven-546): doc-authority.md Enforcement still read the CI wiring as
[proposed] / "pending operator OK", but this PR wires doc_refs into the ci aggregator
(fail-closed) and the operator authorized it in-session. The doc now matches what it
ships. (check_doc_refs.py resolves references, not status tags, so this drift slipped
its own net -- caught in review.)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* docs: strip remaining dangling citations (7 component/template/historical files)

Completes the dangling-reference cleanup so the whole tree resolves (0 across 88
docs) and the doc_refs gate is green repo-wide -- no pre-existing-violation surprises
for future PRs that touch these files.

- README.md: dropped dead docs/v3-spec.md + docs/v4-compilation-milestones.md citations.
- src/v2/tests/testing-strategy.md: fixed wrong-depth INVARIANTS.md path (../ -> ../../../),
  dropped stale "§Verifiability Invariant" anchor (folded into P4).
- src/v3/compiler/benches/tier3_fixtures/README.md: dropped dead r3-pb brief link.
- dsl/ctrl/README.md: dropped dead r4-ctrl audit/plan/brief links (planning lives in ctrl).
- src/v3/DOWNSTREAM_REQUIREMENTS.md: dropped dead docs/history + docs/design-m2 links
  (kept the live ROADMAP.md ref).
- .github/PULL_REQUEST_TEMPLATE.md: delinked the dead _internal/{INVARIANTS,ROADMAP}_OPS.md
  citations (internal-repo docs absent here) to backtick text.
- dsl/std/runtime/bin_shims/README.md: delinked the dead r3-pb briefs +
  design-pb-runtime-interpreter.md citations (frozen-v3 framework placeholder).

Delete-by-default per operator; live links preserved.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* WIP: mgmt

* WIP: Emit-generalization SCOPING phase (DESIGN-ONLY, no-GO; operator 'get wor

* WIP: mgmt

* WIP: mgmt

* docs: address review (cursor/composer-2.5) — delete dead refs, don't delink

The prior pass delinked dead Markdown links to bare backtick paths, which sidesteps
check_doc_refs.py (it only checks [text](path) links) and leaves dead prose pointers.
Fixing properly:

- src/v3/DOWNSTREAM_REQUIREMENTS.md: removed the self-contradiction left by the strip
  ("was pruned from this file" ... "Retained there for audit traceability") and the two
  remaining prose references to the nonexistent docs/history enumeration file.
- dsl/std/runtime/bin_shims/README.md: replaced the dead-ref scaffolding (frozen-v3
  PB-runtime program; all referenced briefs/design docs were deleted in #4192) with a
  concise stub keeping only the live anchors (bin_shim.dag, process.dag, INVARIANTS).
- .github/PULL_REQUEST_TEMPLATE.md: reverted to main (un-touched). Its dead _internal/*
  + briefs/debt references are pre-existing main debt for a wholesale-deleted internal
  apparatus; a proper trim of the v3-census-gate sections is a separate process-template
  decision, not a delink in this PR. Touch-driven gate leaves untouched-file debt alone.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Jun 11, 2026
…dary wording

Restores docs/modeling-discipline.md and docs/modeling/grounding-worked-examples.md
(deleted in the #4192 visibility flip while still cited as enforcement
authority by INVARIANTS.md and live .dag marks — the gap that let PR #4627's
dissolution findings through review), with retired-ledger refs re-pointed
to PR review / dashboard work items and a #4627 worked example added to
Practice 10.

Tightens the marking discipline so 🟡 records debt and never authorizes it:
PRs enumerate new 🟡s, each needs a bound dissolution plan, and the default
review posture is debt-negative (INVARIANTS hand-rolled-derived-operation
shape + modeling-discipline Calibration).

Adds the references-not-imports P2 problem shape (target atoms compared
literally in compiler/ code are boundary violations; a new file under
src/v4/compiler/ is a default-block finding), the M8 predicate-dissolution
mechanical trigger, and the M9 operations extension (a hand-rolled fold
whose accumulator coincides with an existing carrier IS that carrier).

Fixes drift: THESIS facet-4 / DIRECTION-CHECKLIST H3 / SELF_HOSTING.md
still named the deleted ci.dag as live scope; annotates remaining
references to deleted subdocs as historical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 11, 2026
…ary references, and stale-scope drift (#4650)

* docs: restore deleted modeling rubric + tighten debt-marking and boundary wording

Restores docs/modeling-discipline.md and docs/modeling/grounding-worked-examples.md
(deleted in the #4192 visibility flip while still cited as enforcement
authority by INVARIANTS.md and live .dag marks — the gap that let PR #4627's
dissolution findings through review), with retired-ledger refs re-pointed
to PR review / dashboard work items and a #4627 worked example added to
Practice 10.

Tightens the marking discipline so 🟡 records debt and never authorizes it:
PRs enumerate new 🟡s, each needs a bound dissolution plan, and the default
review posture is debt-negative (INVARIANTS hand-rolled-derived-operation
shape + modeling-discipline Calibration).

Adds the references-not-imports P2 problem shape (target atoms compared
literally in compiler/ code are boundary violations; a new file under
src/v4/compiler/ is a default-block finding), the M8 predicate-dissolution
mechanical trigger, and the M9 operations extension (a hand-rolled fold
whose accumulator coincides with an existing carrier IS that carrier).

Fixes drift: THESIS facet-4 / DIRECTION-CHECKLIST H3 / SELF_HOSTING.md
still named the deleted ci.dag as live scope; annotates remaining
references to deleted subdocs as historical.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: fix relative link to docs/thesis/ from docs/modeling/ (doc_refs gate)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: record live P2 corroboration (#4627 boundary-leak recurrence caught post-restore) in Practice 10 worked example

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: address composer review — fix stale 'dissolved in this PR' claim, annotate retired DECISIONS.md cites, ground the Shape-B beachhead description

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs: regenerate doc-authority embedded doc-chain (check_doc_refs --write-graph)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This was referenced Jun 12, 2026
briansrls pushed a commit that referenced this pull request Jun 12, 2026
… concept issues (comment-only)

src/v4/TASKS.md was deleted 2026-06-01 (#4192); 🟡 marks in std/, compiler/,
and lens/ still bound its rows. Repoint each to its dissolve-on concept
tracking issue (#4757-#4766), created per the F1a plan in
docs/planning/label-hygiene-census-2026-06-12.md (PR #4749). No code changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 12, 2026
…, codenames, dead bind anchors (census only, NO renames) (#4749)

* docs(planning): label-hygiene census 2026-06-12 — deprecated task-ID jargon, codename identifiers, dead bind anchors (census only, no renames)

Inventory dispatched by operator directive 2026-06-12 (work item adhoc-ea6ea9da-88c):
- 151 src/v4/TASKS.md cites across 68 files (ledger deleted 2026-06-01 in #4192), 119 inside 🟡 marks
- 650 distinct mvp1_* + 241 distinct comprep_* identifiers, 23 jargon-named files, ^dag_mvp1_* atoms
- dead bind anchors: gunbc#4674 closed 2026-06-12 with dissolve-on NOT landed, still bound by 4 marks
- rename couplings (ci-floor witness pins, ci_affected_components path prefix) and in-flight PR collision map (#4741/#4747 still adding new comprep_*/mvp1_* files)
- 4-wave cleanup sequence; renames deferred until §2/§4 lanes settle

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* census: record Wave-0 execution (#4752 → issues #4750/#4751) + fifth #4674 cite site found (sg0_census_test.rs:347)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Label-hygiene SWEEP (census-first, NO renames yet): inventory deprecated

* census round 2 (operator): complete pattern catalogue + ASAP cleanup plan

Operator follow-up: catalogue ALL known codename patterns, not just the
mvp1/comprep/task-ID families from the original brief, and plan to
rename/delete them all ASAP. Adds: pilot (356 hits + the grounding_pilot
probe crate, delete-candidate), wave[0-9] (1429), sg[0-9] (1250), rung
(711), phase1 (675 incl. V4_PHASE1_* env vars + 3 gate scripts), mvp2
(338), W1-W3/Tranche/Lane/Theme comment families, m0/m1 probe scripts.
Supersedes the parked-waves framing with parallel F1 lanes dispatched
now; only open-PR-touched files and naming-decision families (wave/sg/
rung) wait.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* census: F1e appendix — SG = Self-Generation (defining cites, per-lane table, v4 catalog family deferred)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* census: Wave-0 status lines say 'in flight (PR #4752)' not DONE — inline marks still cite #4674/#3971 until that PR merges (cursor review on #4749)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* census: record operator ruling — no historical parentheticals in repointed marks; genealogy lives in tracking issues

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 12, 2026
… concept issues (comment-only) (#4767)

* F1a: repoint deleted-TASKS.md bind cites in std/compiler/lens to live concept issues (comment-only)

src/v4/TASKS.md was deleted 2026-06-01 (#4192); 🟡 marks in std/, compiler/,
and lens/ still bound its rows. Repoint each to its dissolve-on concept
tracking issue (#4757-#4766), created per the F1a plan in
docs/planning/label-hygiene-census-2026-06-12.md (PR #4749). No code changes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* F1a: update coupled assert literal in closeout test to match repointed verification.dag mark

v4_test_bootstrap_infra_closeout_test.rs:584 asserts the verbatim mark text
this PR rewrites in std/verification.dag; the literal moves in the same PR
so the (dormant-in-CI) test stays true.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* F1a: drop historical '(re-anchor of deleted TASKS.md …)' parentheticals per operator; fixes §T-6.1 lexing.dag mangle by deletion; coupled closeout literal (line 584) updated in step

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Sep 8, 2026
…ese numbers expire with the profile

Two corrections found while checking this branch against the disposition on the
other lane's PR.

PREFILL-FINDINGS.md SHOULD NOT BE IN THIS REPOSITORY. It is an internal RCA
worksheet at the repository root, and the standing operator ruling after #4192 and
#4200 is that planning and RCA documents do not land here -- worksheets are
delivered as receipts. The findings themselves are not lost: they are in the typed
carriers, which is where DESIGN section 4c says they belong, and the readable
summary is the pull request body. The raw measurement receipts stay under
docs/receipts, because the carriers CITE them as the producer of their fitted
coefficients and a citation that does not resolve is worse than none.

AND THE MEASUREMENT ROWS NOW SAY WHOSE PROFILE THEY DESCRIBE. Every number in
prefill_batch_sweep and tensor_parallel_comparison was taken against one artifact --
DeepSeek-V4-Flash at snapshot 60d8d707 on one vLLM revision -- and that artifact is
being replaced. The rows carry an explicit statement that every coefficient expires
with it: per-token and per-step terms, the depth law, the KV pools, the decode and
stall figures, the per-step FLOPs divisor. What survives is the MECHANISM each number
established, which is already stated in prose beside it.

THE STRUCTURAL VERSION OF THAT IS NAMED AS AN OBLIGATION AND DELIBERATELY NOT BUILT.
A measurement should carry its model artifact, tokenizer, runtime, KV policy,
topology and speculative policy in a TYPE, so a row from one profile cannot be joined
to a decision about another -- the defect gunbc.spark.vllm_serving_launch prevents
for process incarnations, one level up. That type belongs with the serving-observation
substrate. Coining it here would be a second profile authority, which is exactly the
fork this lane already made once and reverted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW
briansrls added a commit that referenced this pull request Sep 8, 2026
…unter that refuted it was never a step counter (#10813)

* The prefill budget is 2048, an exception handler chose it, and the counter that refuted it was never a step counter

Investigation receipts for the evidence/numerical lane, reconstructed on current
main rather than on the serving-prefill-scaling branch, whose commit descriptions
still assert the conclusions this work overturns.

WHAT WAS MEASURED. Four launches on the group A head, same harness, idle engine,
unique nonce per prompt. Group A was restored to its authored unit afterwards and
group B was never touched.

  budget  steps  16.4k prefill   co-tenant stall     KV pool
    2048      9        17759 ms      2168 ms meas  11,767,856
    8192      3        16652 ms      8225 ms meas   8,704,293
   16384      2        16327 ms     15930 ms meas   5,836,755

Three-term fit over 20 clean probes, wall = 105.8 + 189.9*steps + 0.9661*tokens
(rms 82 ms). The stall law S + b*budget predicts every measured arm within 1%.

THE PER-TOKEN COST IS INVARIANT over a 32x range of batch size, so the ~1 ms/token
is not a batching, scheduling or MoE-granularity artifact. Going from 48 to 384
tokens per routed expert per step moved it ~2%.

WHY THE BUDGET IS 2048. nvmlDeviceGetMemoryInfo returns NotSupported on a GB10's
unified memory; vLLM catches it with a bare `except Exception: device_memory = 0`,
so 0 >= 70 GiB fails and a 121 GB machine takes the small-device default. Torch
reads the memory correctly; only the NVML path fails. DESIGN §5 absorbing fallback.

WHY THE REFUTATION WAS WRONG. iteration_tokens_total_count advances once per
EngineCoreOutputs batch carrying an output, not once per engine step, so a
prefill-only request advances it exactly once regardless of chunk count. Measured
directly: iter_delta == 1 on requests the per-step counter measured at 10 steps.
The honest step counter is estimated_flops_per_gpu_total under --enable-mfu-metrics.

AND THE 83-ITERATION NUMBER WAS NEVER FABRICATED. A co-tenant decoder beside a
chunked prefill receives one token per chunk, so the quotient approximates the chunk
size by construction. 1,913 ~ 2048 was not a coincidence; the original inference was
right by a route it misdescribed, and was then withdrawn as wrong. The specimen is
that a wrong-grain quotient can land near the true answer, which is what makes it
unfalsifiable by inspection -- first as apparent confirmation, then as refutation.

No carrier is changed here. This commit preserves the findings and the raw sweep
receipts so the corrected carriers can be built from them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* The metric that refuted the 2048 budget was never a step counter, and an exception handler picked the budget

The corrected evidence carriers for the prefill work, authored on current main from
the receipts in the previous commit rather than on serving-prefill-scaling, whose
commit descriptions still assert what this overturns.

WHAT WAS WRONG. gunbc.spark.serving_critical_path carried
BehaviouralPerIterationCapacityAtLeast{20082}, established by polling
vllm:iteration_tokens_total_count on an idle engine and seeing every window from
512 to 20,082 computed tokens complete in "one iteration". That counter is not a
step counter on any engine: async_llm.py builds its stats object as
`IterationStats() if (log_stats and num_outputs) else None` and the recorder
returns early on None, so it advances once per output batch. A chunked-prefill
step emits no output for the request it is advancing, so a prefill-only request
advances it EXACTLY ONCE however many chunks it ran -- measured at 1 for requests
a true per-step counter measured at 3, 4, 7, 9 and 10 steps. The reading was
invariant across the whole sweep and carried no information about the budget.

Exclusivity is what made the withdrawal look safe, and exclusivity was never the
defect. It answers WHOSE events are counted; it says nothing about WHICH.

WHAT IS TRUE. The effective budget is 2048, established by three instruments that
do not share the defect: estimated_flops_per_gpu_total under --enable-mfu-metrics
advances once per engine step and its counts came out as exactly ceil(tokens/2048)
at seven sizes; the engine's own banner logs compile_ranges_endpoints [2048], which
_set_compile_ranges sets FROM scheduler_config.max_num_batched_tokens; and
inter_token_latency_seconds held 1,454,342 samples over 45 hours with none above
7.5s, which alone refutes a 20,082-token step.

WHY IT IS 2048. Not because anyone chose it. nvmlDeviceGetMemoryInfo returns
NotSupported on a GB10's unified memory, vLLM catches it with a bare
`except Exception: device_memory = 0`, and a 121.7 GiB machine takes the
small-device branch. An absorbing fallback, filed as a receipt on that class.

AND 1,913 WAS NEVER FABRICATED. A co-tenant decoder beside a chunked prefill gets
one token per chunk, each token one output batch, so the engine-wide quotient
approximates the chunk size by construction. The original inference was right by a
mechanism nobody identified, then discarded for a worse reason. The specimen is
that a wrong-grain quotient can land NEAR the true answer, which is what makes it
unfalsifiable by inspection -- first as confirmation, then as refutation.

CARRIERS. extdeps.nvidia.management_library models the device-memory query so that
its refusal arm carries NO byte count, making `device_memory = 0` unwritable rather
than discouraged. extdeps.vllm.batch_defaults models upstream's resolution and
keeps the SELECTION CAUSE beside the value, because 2048-because-small and
2048-because-absorbed behave identically and have different fixes.
extdeps.vllm.metrics pairs each metric with a QUESTION and refuses the pairings the
installed source does not support, including this one.
gunbc.spark.prefill_batch_sweep carries the four-launch sweep with MeasuredBatchArm
and PredictedBatchArm as INCOMPATIBLE types -- the 1024 and 512 arms were never run
and must not be readable as observations.

The extdeps do-not-set row is withdrawn as a layer inversion, not only as a wrong
claim: whether to set the flag trades interactive latency against throughput
against KV pool, which is product policy. Its "reduces the KV pool" half was true
and measured (11.77M -> 5.84M tokens); its ground for the other half was inferred
from average link utilisation. The optional prefill_scheduling field lands WITH its
consumer in the argv renderer rather than dangling.

Group A was restored to its authored unit; group B was never touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* TP=4 over-shards this prefill by 25%, and the two topologies are not numerically interchangeable

The batch axis could not move the per-token term at all. Collective topology moves
it, which makes this the first mechanism found that reaches the ~1 microsecond per
computed token, and the largest single lever measured on this fleet.

HELD CONSTANT: same head, image, container, model snapshot, tokenizer, executor,
backend selections and cache standing; batch budget PINNED EXPLICITLY at 2048 in
both arms; MFU metrics on in both; one context ceiling of 131,072 for both, lowered
from the production 1,048,576 because a TP=2 rank holds roughly half of a ~168.7 GB
model against a ~99.8 GiB budget. Only the tensor-parallel degree differs.

    quantity                  TP=4         TP=2      TP=2 against TP=4
    marginal per token      1.053 us     0.786 us     25.4% cheaper
    prefill throughput       949 tok/s   1272 tok/s     34% higher
    decode alone             30.2 ms      40.5 ms       34% WORSE
    co-tenant stall         2146 ms      1629 ms        24% shorter
    KV pool at 131,072    6,175,555    2,310,685        63% LESS

The gain holds at every probe above 2,048 tokens across a 40x range and is 7% at
510, where the fixed per-request term still dominates. Step counts from the per-step
FLOPs counter matched ceil(tokens/2048) in both arms, so the budget really was
pinned and the comparison really is topology.

THE TWO WORKLOADS WANT OPPOSITE TOPOLOGIES. Decode is 34% worse at TP=2 -- decode is
memory-bound per token and fewer ranks means less bandwidth to stream weights, while
prefill pays for every extra collective participant. An adoption is therefore a
decision about what a replica is FOR, not a tuning change.

AND THEY ARE NOT NUMERICALLY INTERCHANGEABLE. A greedy text comparison would have
been worthless: the arms diverge at the first token from a near-tie. The measurement
is prompt logprobs over one fixed 22-token input -- one deterministic forward pass,
no sampling. Same token sequence, but per-token logprobs differ by up to 1.517 nats
(a 4.56x ratio on one token's probability) with a mean of 0.330. That is orders of
magnitude above reduction-order noise: the sharding changes the computation, not its
rounding. Causes are UNSEPARATED -- per-shard fp8 accumulation, routed-expert
selection under a different partition of 256 experts, or a shape-dependent kernel.

So the carrier gates on it. `topology_substitutable` REFUSES on divergence rather
than warning, because a 25% speed win may not silently carry a numerical change into
production. The speed result and the equivalence result are different subjects and
only the second decides substitutability.

MISSING CONTROL, NAMED RATHER THAN GLOSSED: no arm was repeated, so within-topology
run-to-run variation is unmeasured and the 25.4% carries no interval. Whether TP=2
fits the production ceiling at all is likewise untested.

Group A was restored to its authored unit and verified: no drop-in, tensor_parallel
4, max_seq_len 1048576, enable_mfu_metrics False, KV 12,739,744 tokens. Group B was
never touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* Correct a thousandfold units error I introduced, and stop claiming topology caused the numerical divergence

Two defects in the carriers landed by the previous two commits, both found in review.

THE UNITS ERROR IS THE SERIOUS ONE, and it is the same class the branch had already
repaired once. FittedExecutionLaw.micros_per_thousand_tokens carried 966 for a rate
of 0.9661 MILLIseconds per token. 966 micros per thousand tokens is 0.966
microseconds per token, which is a million tokens per second. The field was wrong by
exactly 1000, and both predicted_wall_micros and predicted_step_micros returned
values three orders of magnitude too small.

It survived authoring because 966 and 966100 are both plausible small integers
beside a field name that does not say which. It is caught now by a derivation rather
than by care: at the corrected 966100, predicted_step_micros(budget 2048) is
2,168,472 micros against an INDEPENDENTLY MEASURED co-tenant stall of 2,168,200 --
agreement to 0.013%, where the wrong value misses by 1000x.

The topology carrier had the same error (1053 and 786 for 1.053 and 0.786 ms/token)
AND a second representation of the same rate stored beside it as
prefill_tokens_per_second. That is the §3 fork that let the error hide: two stored
spellings of one quantity, neither checking the other. Throughput is now DERIVED
from the rate, so a wrong-by-1000 value announces itself immediately.

THE SECOND DEFECT IS AN OVERCLAIM. The module said the logprob divergence showed
"the sharding changes the computation, not merely its rounding". That is a causal
claim the population cannot carry: WITHIN-topology variation was never measured, so
there is no envelope to compare the cross-topology distance against. The variant is
renamed CrossTopologyDifferenceObservedWithinTopologyUnmeasured and carries the
minimum design that would earn attribution -- three same-launch repeats plus one
relaunch per degree, over identical token ids, comparing within and across before
across-topology. The refusal arm now also fires on the unmeasured control, because
an unexplained difference and an unmeasured baseline are both reasons not to
substitute.

ALSO CORRECTED, all from the same review:
- "measured, not adopted" read as a verdict on TP=2's fitness. What the evidence
  refuses is FUNGIBILITY -- serving one alias from either topology as though a
  request could not tell them apart. A separately named profile is a different
  proposition and nothing here rules it out. The standing is renamed accordingly.
- The per-replica view is not the fleet decision. At a fixed four-Spark footprint
  the alternative to one TP=4 replica is TWO TP=2 replicas, and the capacity story
  changes magnitude: 63% less KV per replica becomes about 25% less across the same
  four Sparks. Both views are carried; each is misleading alone. The aggregate
  decode figure is throughput, not latency -- a user on one stream still feels
  40.5 ms.
- The topologies do not force a global choice. TP=2 saves 267 micros per computed
  prompt token and pays 10,300 per generated token, so it wins whole-request time
  above about 38 prompt tokens per generated token. A live 60-second window on this
  head measured about 280 to 1, an order of magnitude above the crossover.
- A printed pool size is not an admission pool, and summing two of them does not
  make one. Carried as a caveat on the aggregate.
- replicas_in refuses on a zero rank population rather than answering 0, which would
  have flowed into the aggregates as a real zero.

No new measurement was taken; the fleet was not touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* The 25.4% was one unrepeated launch: TP=2 is 8%, the numerical divergence IS the topology, and prefill is quadratic in prompt length

Three results from the repeat design and the production-ceiling gate, one of which
withdraws this lane's own headline.

THE MAGNITUDE WAS WRONG. Four alternated launches, two per degree, three cold 16k
probes each:

    TP=4 across launches:  0.9398 .. 0.9835 ms/token   spread 4.6%
    TP=2 across launches:  0.8344 .. 0.8414 ms/token   spread 0.8%

Effective at 16k that is 938 against 1016 tok/s -- TP=2 is 7.7% cheaper per token,
NOT the 25.4% this lane reported. The first TP=2 launch measured 0.786 and was never
repeated; both repeats land at 0.98 on two DIFFERENT Spark pairs, so that reading is
an unexplained outlier. TP=4 was stable across every launch, which is why the error
was one-sided. 8% is outside the 4.6% envelope but not hugely so.

THE NUMERICAL ATTRIBUTION IS NOW EARNED, and it is the strong direction. Prefix-cache
hit delta was zero on every numerical probe, so each reading is a real recomputation:

    within-launch, all four launches      0.0000 nats
    across-launch, same topology          0.0000 nats
    cross-topology, all four pairings     2.2387 nats

The within-topology envelope is BIT-IDENTICAL across a fresh relaunch and across
different hardware -- Ray placed the two TP=2 launches on different Spark pairs and
they agreed to the last bit. All four cross pairings give the same 2.2387. That is a
deterministic function of the degree, not noise. The refusal is now HARDER than an
unexplained one: the difference is reproducible and will not average out. Which
degree is closer to the intended semantics remains unanswered and needs a reference.

TP=2 CLEARS THE PRODUCTION CEILING. At max_model_len 1,048,576 it started, reported
4,823,795 KV tokens at 4.6x concurrency, correctly refused a 1,048,576-token prompt
because prompt plus output must fit, and admitted 1,048,575 tokens in 1598.1s at
1.5241 ms/token mean, in EXACTLY 512 steps with zero preemptions. 1,048,575 / 2048 =
512.0 -- the batch budget confirming itself at the largest scale the model admits.

AND THE AFFINE LAW ONLY DESCRIBES SHALLOW CONTEXT. Sampling KV allocation through
that 26-minute prefill gives a per-token cost AFFINE IN DEPTH, residuals <= 0.05 ms
over a 123x range:

    ms/token = 0.9236 + 1.4159 microseconds per million tokens of depth

so total prefill is QUADRATIC in prompt length, and the fleet's ~149k average sits an
order of magnitude outside the range every earlier law was fitted on. The consequence
for the batch budget is structural: chunking does not change which token pairs are
scored, only how they are grouped, so the quadratic term is INDEPENDENT of the budget
and the budget only ever moves ceil(tokens/budget) * per_step. That is why the
measured gain from 2048 to 16384 was at most 7.5% and could not have been more. It
also means the co-tenant stall GROWS with the offending prefill's depth -- about 2.1s
at 16k against 5.1s near 1M at budget 2048.

Which subsystem carries the depth term is NOT established; a cost linear in prior
context is what a key-selection scan looks like, which is a hypothesis for the
operation ladder and not a finding.

WITHDRAWN WITHOUT REPLACEMENT: a per-step cost broken out by topology. All four
repeat launches held the budget at 2048, so steps ~ tokens/2048 and the per-step and
per-token terms are collinear; only the batch sweep, where the budget varied at fixed
token count, separates them. The decode and co-tenant-stall rows also remain single
measurements and carry no envelope.

Group A restored to its authored unit and verified: no drop-in, tensor_parallel 4,
max_seq_len 1048576, enable_mfu_metrics False, KV 12,761,995. Group B never touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* Scope three findings to what they were established against, before a model swap carries them as law

Corrections from review. Each is a claim of mine that was true for the profile it
was measured on and would be wrong the moment it is carried past it.

THE CO-TENANT LAW WAS THE ONE-ACCEPTED-TOKEN SPECIAL CASE. This module derived
"a co-tenant decoder receives exactly one token per chunk, so its inter-token
latency IS the step duration" from a profile serving no speculative decoding. Under
speculative decoding a single step can accept a BURST, so the general relation is

    victim progress per step = accepted decode tokens from that step

and a profile with a draft model can suffer the same step duration with a materially
better felt cadence. The mechanism survives a model change; the equation does not.
The batch-policy trade measured beside it inherits the same caveat and it is now
stated: draft tokens consume the same budget, so a budget measurement taken with
speculation OFF does not describe a product served with it ON.

THE NVML FINDING IS PLATFORM TIMES RUNTIME REVISION, NOT THE HARDWARE ALONE. What
was established is that THIS vLLM revision, on a GB10, resolves the batch default
through a device-memory probe it catches and zeroes. The path does not consult the
model, so it should reproduce for any checkpoint served by the same build -- and a
different image must REACQUIRE it rather than inherit it. That is the rule the
cumulative_metric_read_as_per_event row already states for metric semantics, and my
own summary broke it. The durable remedy was never knowing the default; it is
pinning the budget explicitly so no default is consulted.

THE PER-STEP FLOPS QUANTUM IS NOT A CONSTANT TO CARRY. The counter advances by a
fixed amount per step for a GIVEN model and topology because it estimates that
model's work per rank -- it was observed to DOUBLE when the rank count halved. A
divisor carried across a model or topology change silently reports the wrong step
population, which is the same wrong-grain reading this corpus already has a failure
mode for.

WHAT IS NOT HERE, AND WHY. I had also written a context-window decision carrier with
its own serving-profile identity and candidate selector. It is deleted rather than
landed. The seams it reached for are already owned: pair_serving_capacity_floor
declares maximum_sequence_tokens 500000 beside an imported seat count, which IS a
context and concurrency policy expressed as a literal, so a second selector would
have been a second answer to one question -- the §3 fork, authored by me, one turn
after I wrote a scope note in that very module warning about it. The context
decision belongs downstream of a reconstructed observation substrate and consuming
its profile type, not beside it.

No measurement changed and the fleet was not touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* Drop the RCA worksheet from the repo, and say in the carriers that these numbers expire with the profile

Two corrections found while checking this branch against the disposition on the
other lane's PR.

PREFILL-FINDINGS.md SHOULD NOT BE IN THIS REPOSITORY. It is an internal RCA
worksheet at the repository root, and the standing operator ruling after #4192 and
#4200 is that planning and RCA documents do not land here -- worksheets are
delivered as receipts. The findings themselves are not lost: they are in the typed
carriers, which is where DESIGN section 4c says they belong, and the readable
summary is the pull request body. The raw measurement receipts stay under
docs/receipts, because the carriers CITE them as the producer of their fitted
coefficients and a citation that does not resolve is worse than none.

AND THE MEASUREMENT ROWS NOW SAY WHOSE PROFILE THEY DESCRIBE. Every number in
prefill_batch_sweep and tensor_parallel_comparison was taken against one artifact --
DeepSeek-V4-Flash at snapshot 60d8d707 on one vLLM revision -- and that artifact is
being replaced. The rows carry an explicit statement that every coefficient expires
with it: per-token and per-step terms, the depth law, the KV pools, the decode and
stall figures, the per-step FLOPs divisor. What survives is the MECHANISM each number
established, which is already stated in prose beside it.

THE STRUCTURAL VERSION OF THAT IS NAMED AS AN OBLIGATION AND DELIBERATELY NOT BUILT.
A measurement should carry its model artifact, tokenizer, runtime, KV policy,
topology and speculative policy in a TYPE, so a row from one profile cannot be joined
to a decision about another -- the defect gunbc.spark.vllm_serving_launch prevents
for process incarnations, one level up. That type belongs with the serving-observation
substrate. Coining it here would be a second profile authority, which is exactly the
fork this lane already made once and reverted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md absorbing_fallback
Ledger-Rows-Repaired: docs/design-failure-modes.md cumulative_metric_read_as_per_event
Ledger-Repair-Judged: docs/design-rung-drops.md

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Rows-Repaired: docs/design-failure-modes.md absorbing_fallback
Ledger-Rows-Repaired: docs/design-failure-modes.md decision_surface_truncation
Ledger-Rows-Repaired: docs/design-failure-modes.md cumulative_metric_read_as_per_event
Ledger-Repair-Judged: docs/design-rung-drops.md

* Pin the prefill batch budget at 2048 instead of inheriting it from a failed device probe

Operator decision, 2026-09-08. The value does not change; its PROVENANCE does.

WHAT WAS HAPPENING. On a GB10 the NVML device-memory probe returns NotSupported,
vLLM's `except Exception` writes device_memory = 0, and a 121.7 GiB machine takes the
small-device branch to max_num_batched_tokens 2048. Nobody chose that number, and it
moves the moment the probe, the driver or the image changes. Requesting 2048
explicitly was MEASURED to be a no-op -- an explicit-2048 launch rendered
compile_ranges_endpoints [2048], identical to the implicit one -- so this is
provenance, not behaviour.

WHY 2048 AND NOT THE 8192 UPSTREAM WOULD HAVE PICKED, measured on this fleet at a
16.4k cold prefill:

    budget   prefill wall   vs 2048   co-tenant stall   KV pool
      2048       17,759 ms         -        2,168 ms   11,767,856
      8192       16,652 ms     -6.5%        8,225 ms    8,704,293
     16384       16,327 ms     -7.5%       15,930 ms    5,836,755

The gain is pure per-step amortisation and cannot exceed ~7.5%, because per-token
cost is FLAT from 512 to 16,384 tokens per step -- bigger batches do not make the
routed-expert GEMMs more efficient here. The sharper cost is not the stall but the KV
pool: -26% at 8192 is roughly 85 -> 63 warm conversations per replica at this fleet's
average context, and a conversation that falls out of the warm set recomputes its
whole prompt.

CHUNKED PREFILL IS PINNED ALONGSIDE IT because the budget is only meaningful under
chunking. Pinning the budget while inheriting the chunking mode pins half a policy,
and a future default change would silently make the pinned number mean something
else. Also a no-op today: the engine already resolves enable_chunked_prefill=True.

THE OPTIONAL FIELD HAD NO PRODUCER UNTIL NOW, which was a gap in the change that
introduced it. Both construction sites passed `none`, so the renderer's Present arm
was unreachable: it typechecked, it was imported, and nothing could ever emit the
flag. Consumption is not "a consumer exists" but "a consumer is reached".

THE WITNESS IS DISCRIMINATING, and its RED was executed rather than assumed. The
positive asserts the rendered argv carries --max-num-batched-tokens 2048; the
negative asserts an unrequested policy emits NO batch flag at all, so a renderer that
hard-coded it would fail. Planting the desired row back to `none` and re-running the
rendered-argv check exits 1 and prints the argv without the flag; restoring it exits
0. Rendered tail as pinned:

    ... --gpu-memory-utilization 0.82 --enable-prefix-caching
        --max-num-batched-tokens 2048 --enable-chunked-prefill

SCOPE. These measurements are DeepSeek-V4-Flash on one vLLM revision. A different
model or image must re-measure rather than inherit the number, and must re-establish
that the NVML path still resolves the same way -- and with speculative decoding
enabled, since draft tokens consume this same budget.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* Derive the execution law from the samples, and stop a single-budget population producing two confident coefficients

Closing the transcription gap this lane declared and then widened. The coefficients
were literals copied out of a Python script, beside an annotation admitting that
"editing them here would not be caught by anything" -- and that is exactly what
happened. Asked how the reported ratios were calculated, the answer could not be read
off the carrier: it needed reopening the script, where the percentages sitting beside
measured wall times turned out to be MODEL PREDICTIONS at a normalised token count.

THE SAMPLES ARE NOW THE AUTHORITY. Twenty clean probes are carried and every
coefficient, prediction and ratio is a fold over them. Adding a probe moves the law;
editing a coefficient is impossible because there is no coefficient to edit. The one
contaminated probe -- 81,697 computed tokens booked against a 20,262-token request --
is excluded and named in the carrier rather than in the tool.

THE INTEGER SOLVE REPRODUCES AN INDEPENDENT LEAST-SQUARES: 189 ms/step and 966
microseconds/token, against 189.9 and 966.1 from an ordinary floating-point fit over
the same receipts. Scaling is declared rather than hidden -- wall in milliseconds, the
per-token rate emitted in microseconds because a ~1 ms/token rate rounds to the
useless integer 1 -- and the cross-products use the no-division form n*Sxy - Sx*Sy so
no mean is rounded before the solve. Largest intermediate is ~3.1e16 against a 9.2e18
ceiling.

AND THE REFUSAL I FIRST WROTE WAS WRONG, WHICH ONLY EXECUTING IT SHOWED. It tested
`determinant == 0`, on the belief that a single-budget population makes step count
exactly collinear with tokens. Running it against a planted single-budget population
refuted that: ceil is NOT linear, the determinant came out at 236,236,900 rather than
zero -- against 32,424,810,042,480 for the real population -- and the fit cheerfully
returned S = 305 ms/step and b = 906 us/token from noise. A det == 0 guard catches
nothing.

So the wall now tests the structural property that makes the split possible at all:
the population must span at least two budgets, because that is what gives step count
information the token count does not already carry. Decidable, no tolerance, and not
a smuggled heuristic about how small a determinant is too small. It is not
hypothetical either -- the tensor-parallel repeat launches all held the budget at
2048, and their per-step/per-token split had to be withdrawn.

EVERY READING NOW SAYS WHICH KIND IT IS. DirectMeasurement, DerivedAtCommonWorkload
and PredictedOutsideMeasuredArm are incompatible by construction, because the defect
they exist to prevent was a table rendering a measured wall and a model-normalised
percentage in adjacent columns with nothing between them.

THE CO-TENANT AXIS IS REPAIRED FOR ONE ARM AND HONESTLY INCOMPLETE FOR TWO. The 2048
arm was re-run under an attribution guard that polls the running count and books the
engine-wide prompt-token delta against the window's own two requests: 16,451 booked
against 16,449 own, max_running 2.0, giving 30.0 ms alone against 2,171.6 ms beside
the prefill. That supersedes the itl_* fields in arm-2048.json, which came from the
first co-tenant test whose victim finished before the prefill was submitted.

The guard also refused three attempts at 8192 -- 311,543 foreign prompt tokens
against 16,448 own -- and revealed that NEITHER sibling arm ever had an attribution
boundary, because the instrument did not exist when they ran. One attributed reading
of three. The refused attempt is committed beside the clean one, because a refusal
that leaves no receipt is indistinguishable from never having tried.

Notable: one refused window reported 2,172.6 ms, agreeing with the figure this lane
had been quoting, and the guard rejected it anyway. Agreement with a prior belief is
not attribution.

Group A restored to its authored unit and verified.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TLj9vB2KVcTUA9wvuLa8fW

* Admit the wave delta the new failure-mode class produces, and retire the two rows it came due on

The required run refused with `1 unadjudicated delta`. The delta is the roster's
existing `recurring_failure_mode_roster` declaration resolving the spelling
`cumulative_metric_read_as_per_event` into the class module this change adds --
NewPoolCoincidenceResolution, which does not auto-admit. That is the shape EVERY
new failure-mode class produces: the ledger is a directory of one file per class
precisely so two lanes never rewrite one file, so a class arrives as a name newly
resolving in the roster's pool rather than as an authored rebind. Needing a row
for it is the honest cost of the pool being adjudicated instead of assumed.

The same run reported the two gunbc#10688 call-target rows as `already satisfied
at the base -- consumed by its own merge`, and their entry said they came due on
this roster's next touch. This is that touch, so they are deleted, together with
the label constant they shared. Adjudicated by the join they demanded rather than
by their own trigger sentence: the run's CONSUMED line IS that tuple join executed
against main.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant