Skip to content

Strip .dag comments (flush — no grammar change, no ctrl dependency) - #5567

Merged
briansrls merged 1 commit into
mainfrom
session/loyal-raven-204-flush
Jun 22, 2026
Merged

briansrls merged 1 commit into
mainfrom
session/loyal-raven-204-flush

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Deletion-only comment strip across 165 .dag files: dsl/{ctrl,extdeps,gunbc,std,test,tools}, src/v1/*.dag, src/v2/{lens,test,workflow,program.dag}, scripts/fixtures/
  • Complements c810babf89 (Ban source comments — .rs seed (~6000 LOC, deletion-only) + rust-aware stripper #5544) which already stripped the .rs seed and src/v2/compiler pipeline stages
  • Excludes three WALL files (dag.dag, 01_tokenize.dag, dag_comment_wall_test.dag) held for the companion PR that gates on ctrl#1793 (cool-heron-518 strip) — that PR will remove skip_spaces_and_comments trivia rules from the lexer and fail-close the fidelity model

Verification

Every removed line is a // or /* */ comment, or a blank line collapsed by blank-line deduplication. No logic, type, import, or structural changes. Verified by: grep of diff ^- lines shows no non-comment content.

Test plan

  • CI floor passes (batch 1: compile-clean, batch 2: witnesses, batch 3: source-root-ingest gate)
  • No resolved symbols affected (comment-only deletions change no declarations)

🤖 Generated with Claude Code

… flush)

Deletion-only comment strip across 165 .dag files: dsl/{ctrl,extdeps,gunbc,std,test,tools}, src/v1/*.dag, src/v2/{lens,test,workflow,program.dag}, scripts/fixtures. Excludes the three WALL files (dag.dag, 01_tokenize.dag, dag_comment_wall_test.dag) held for the companion PR that gates on ctrl#1793.

Verified comment-only: every removed line is a // or /* */ comment, or a blank line eliminated by blank-line collapsing. No logic, type, or import changes.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@briansrls
briansrls force-pushed the session/loyal-raven-204-flush branch from f77b9fd to 78e6044 Compare June 22, 2026 22:13
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review June 22, 2026 22:13
@gunbai-bot gunbai-bot Bot changed the title Parser-wall: make .dag comments unwritable by construction (delete comment-skip, fail-closed) Strip .dag comments (flush — no grammar change, no ctrl dependency) Jun 22, 2026
@briansrls
briansrls merged commit 85a1e8b into main Jun 22, 2026
2 checks passed
@briansrls
briansrls deleted the session/loyal-raven-204-flush branch June 22, 2026 22:41
briansrls added a commit that referenced this pull request Jun 23, 2026
…Appropriation/LineItem/zero-based; recursive conservation + admission construction) (#5582)

* budget-tree carrier: hierarchical memory budget, two-verdict (static conservation WALL + runtime reconcile HANDLER)

Foundational §1 carrier for ROADMAP 1-budget-tree (operator: "model the whole
machine as a memory budget tree; each level inherits a budget from its parent as
a transaction"). Zero consumers yet — routed for review before any consumer edit.

product.budget_tree models a node's allocated budget (capacity_intent) and its
children's claims, with TWO DISTINCT regimes (never conflated — else a runtime
ratchet masquerades as a compile wall):

  REGIME 1  node_conserves : Bool  — STATIC conservation over AUTHORED budgets.
    Sum(children claims) <= parent budget. Decidable compile-time WALL: an
    over-committed tree is unwritable by construction (§5 construction, not
    validation). This is the stern-otter co-residence OOM made unwritable.

  REGIME 2  reconcile : Reconciliation  — RUNTIME intent x MEASURED-actual.
    A fail-closed HANDLER (Realization), NOT a wall. Admit in QoS order
    (Guaranteed > Burstable > BestEffort); classify:
      AllSatisfied        actual covers all claims
      Evicted             best-effort/burstable shed to fit actual
      GuaranteedShortfall typed LOUD error — guaranteed set exceeds actual
                          (genuinely under-provisioned; never a silent OOM,
                          which matters most on the UNCAPPED fleet where the
                          physical OOM-killer would otherwise pick random victims)

Levels (L0 host / L1 concurrent runs / L2 within-run rustc+spawn-width) are
BudgetNode INSTANCES; spawn-width #5444, placement R #5559, compile-jobs N #5546
become consumer leaves that IMPORT their parent allocation (divide-once), not
parallel facts that re-divide host_ram.

Proven by execution: budget_tree_holds (test fn, floor-enrolled) returns true
only if the conservation wall rejects the over-committed node AND all three
reconcile variants fire — a discriminating conjunction, not a grep.

Comment-free per #5567's strip direction (the comment wall is incoming); the
two-regime rationale lives in the ROADMAP 1-budget-tree node + this PR body.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* review fixes (opus-4-7 #5582): dissolve priority_eq to canonical ==, add ByteSize algebra to std.measure

Finding 1 (predicate dissolution / §4 ops-from-inhabitance): deleted priority_eq
(Bool helper minted per-coproduct with a `_ => false` wildcard) — claims_of_priority
now routes through canonical `==` (Value::eq, the single CanonKey authority; same
form as extdeps oci linux.dag namespace equality). Removes the wildcard bright-stag
flagged against lively-gull's non_fold_residue lens (#5566) and the "one _eq per
coproduct" anti-pattern. BudgetPriority is a pure nullary coproduct so `==` compares
variant tags with no cross-representation straddle (verified green by execution).

Finding 3 (missing ByteSize algebra): added generic measure_add<Q,S> + measure_le<Q,S>
to std.measure (the canonical home all reviewers named). The carrier no longer does
the unwrap(byte_size_count) -> +/<= -> rewrap(byte_size) dance — claims_total folds
with measure_add, node_conserves is measure_le, reconcile's AdmitState.used is ByteSize.
Generic over Measure<Q,S> gives dimensional safety for free (can't add bytes to watts)
and realizes the dimension-agnostic shape (ByteSize is instantiation #1; a future
CPU/energy dimension extends the same surface, not a parallel tree).

Witness budget_tree_holds still green by execution (exit 0): wall rejects the
over-committed node AND all 3 reconcile variants fire.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* ground budget tree in real accounting (extdeps); add tree recursion + admission-as-construction (opus-4-7 round 2)

Operator: ground budget_tree in the real budgeting/accounting framework (start from
en.wikipedia.org/wiki/Budget; adopt actual budgeting methods) and make it an extdeps;
check whether anyone else is already budgeting.

NEW extdeps/accounting/budget.dag — the single §3 authority for the budgeting framework,
anchored to en.wikipedia.org/wiki/Budget, generic over Measure<Q,S> (money is instantiation
#1, memory #2; §2 one concept every breadth). Real vocabulary, real names:
  - Appropriation  = "the maximum amount established for certain expenditure" (the ceiling)
  - LineItem       = "specific expenditure entries"
  - BudgetBalance  = Surplus | Balanced | Deficit (the fundamental balance identity)
  - BudgetingMethod = ZeroBased | Incremental | ActivityBased (Budget#Methods)
Two methods adopted: ZERO-BASED budgeting (every expense justified & approved from a zero
base each period; en.wikipedia.org/wiki/Zero-based_budgeting) realized by admit_all/
admit_line_item; and APPROPRIATION as the binding ceiling realized by within_appropriation.

budget_tree.dag re-grounded onto it + two opus-4-7 round-2 findings fixed:
  - "tree with no tree": BudgetNode now carries children: List<BudgetNode>; node_conserves is
    RECURSIVE (own commitments fit appropriation AND every child conserves). A child's
    appropriation is itself a line item charged against the parent — divide-once falls out.
  - "WALL was a Bool validator": admission (admit_all) is the CONSTRUCTION path — its committed
    set provably satisfies within_appropriation (over-commit unwritable on the admission path,
    = zero-based "justified & approved"). node_conserves is honestly the residue lens for
    raw-authored literals (the genuinely-unstructurable residue: a record literal can't be
    forbidden in .dag), NOT relabeled a wall.

Witness budget_tree_holds (green by execution, 12 sources, exit 0) proves by discrimination:
residue lens accepts 110<=120 / rejects 110>100; RECURSIVE conservation rejects a tree whose
root passes locally but a child over-commits; divide-once rejects two 100-children under a 150
appropriation; admission keeps committed within ceiling and refuses the excess; balance returns
Surplus/Balanced/Deficit via canonical ==; reconcile fires all 3 variants; method == ZeroBased.

Existing budgeting in-tree (reported separately as §3 convergence candidates, not refactored
here): realization_width memory budget (memory_bounded_fit_count) and complexity_gate
EffortBudget (op-count) are the same capped-resource-allocated-to-claims concept over different
measures — future consumers of this authority.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…)-ruled hardening)

Parent ruling (neat-boar-71, signed by bright-stag-194): keep the host-seam
shape (A) — NO PrimitiveContract/registry conversion, no inference touch — but
satisfy a hard §5 condition: a decoy body is only acceptable if PROVABLY
UNREACHABLE; a body that returns a plausible value ([] / "") on a path that can
execute is a fail-OPEN fabrication, worse than the §3 fork.

Fail-close every seam body (loud, never a fabricated value):
  - bytes_octets:      [] -> [pure_dag_seam_unreachable()] (1/0 -> DivisionByZero)
  - utf8_decode_bytes: "" -> from_code_point(pure_dag_seam_unreachable())
  - octets_bytes / utf8_encode_bytes: already fail-closed ( raises an
    unsupported-cast at runtime; eval_cast has no Bytes arm).

Verified by execution (parent's probe): with the bodies fail-closed, the FULL
witness suite (11) stays green => the v1 host builtins shadow the bodies => they
are dead. And when reached (non-shadowed), they raise 'division by zero' instead
of fabricating — confirmed on a throwaway non-shadowed fn.

Open-thread marker (comments are walled tree-wide by #5567, so markers are
in-code  rows): bytes_seam_host_realization_marker +
utf8_decode_bytes_host_realization_marker tie all four bodies to the DESIGN.md
open thread 'ground each primitive into its realization' (operator-owned);
dissolve-on = that systemic grounding lands, converting all to
PrimitiveContract + builtin_function_registry together.

dsl compile 437/0; all 11 witnesses green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jun 23, 2026
Resolve conflicts in the two lens files by keeping the #5599 anti_unify refactor
(simulated_relationship now derives chain_is_simulated from the produced whole-chain
generalization; intent_linearity uses algebra any/for_all) over main's prior congruent
logic. Strip // comments from the 5 touched .dag files to satisfy the post-#5567
parser-wall (line comments are FailClosed on ingest); no in-string // present.
All 17 lens_unit witnesses (11 simulated_relationship + 6 intent_linearity) green by
execution on the merged tree.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jun 23, 2026
…YamlValue (#5566 floor unblock)

The non_fold_residue gate (#5566) was RED on main: block_sequence_element_doc
and project_yaml_to_doc each carried a `_ =>` wildcard over the closed YamlValue
coproduct (a fail-open escape a fold would not have), landed unrostered; and the
roster carried a stale `emit_yaml_value` entry for a fn that no longer exists.

Per operator directive ("I would just dissolve"): migrate both matches to total
form rather than roster them. Each wildcard is replaced with explicit arms for the
variants it caught (YamlNull/Bool/Int/Float[/Sequence]), each delegating to the
exact same emit_scalar expression — behavior-preserving by construction. The stale
roster entry is removed so the roster shrinks (live_tree_residue_roster_has_no_stale_entries).

Verified by execution: all 11 non_fold_residue gate tests green (was 2 RED);
all 38 yaml serializer/quoting/multiline witnesses green (behavior unchanged).
No comments added to .dag (post-#5567 comment-wall).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
 floor unblock (#5612)

* WIP: roadmap discussion

* Dissolve yaml.dag non-fold residue: 2 wildcards → total matches over YamlValue (#5566 floor unblock)

The non_fold_residue gate (#5566) was RED on main: block_sequence_element_doc
and project_yaml_to_doc each carried a `_ =>` wildcard over the closed YamlValue
coproduct (a fail-open escape a fold would not have), landed unrostered; and the
roster carried a stale `emit_yaml_value` entry for a fn that no longer exists.

Per operator directive ("I would just dissolve"): migrate both matches to total
form rather than roster them. Each wildcard is replaced with explicit arms for the
variants it caught (YamlNull/Bool/Int/Float[/Sequence]), each delegating to the
exact same emit_scalar expression — behavior-preserving by construction. The stale
roster entry is removed so the roster shrinks (live_tree_residue_roster_has_no_stale_entries).

Verified by execution: all 11 non_fold_residue gate tests green (was 2 RED);
all 38 yaml serializer/quoting/multiline witnesses green (behavior unchanged).
No comments added to .dag (post-#5567 comment-wall).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jun 23, 2026
…unded (review §3 (b))

Per parent's §6-scaffold conditions: route_observation's OutOfBand StorageInventory/
NetworkInventory arms now go through out_of_band_inventory_blind_pending_firmware_visibility_derivation,
so the carrier itself states this outcome is FIRMWARE-GROUNDED (derives from host
storage/network visibility at the 2nd firmware) rather than reading as a channel-universal
claim. Comments are comment-walled (#5567/#5579 — verified: a // line is a compile error),
so the dissolution trigger lives in the carrier name (DESIGN §6 'the mark on the carrier is
the authority'). No behavior change: the cell still returns ChannelCannotObserve; witnesses
green; flip-openbmc perturb still reds the grounding witness by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…Int8> host seam — parent-greenlit shape; done = iso round-trip + base64 round-trip + RFC §10 golden vectors all green by execution in a *_test.dag (#5585)

* WIP: base64/base64url in std.encoding (pure .dag, RFC 4648) + Bytes≅List<UInt

* base64/base64url in std.encoding (RFC 4648) + Bytes≅List<UInt8> seam

Pure-.dag base64/base64url (RFC 4648 §4/§5) over std.integer.UInt8, plus the
Bytes ≅ List<UInt8> host seam (bytes_octets / octets_bytes / utf8_encode_bytes
interpreter realization handlers mirroring utf8_decode_bytes).

6-bit regrouping by Int arithmetic only (*256, /64, %64) — no bit-op/shift
primitive (deferred to a 2nd consumer, §6 purity-trap guard). Encode/decode are
fold-with-state over the octet/sextet stream; decode inverts the alphabet by
code_point arithmetic (no indexOf).

Witnesses green by execution in base64_rfc4648_witness_test.dag (floor auto-
enrolled):
  - bytes_octets ISO round-trip (total)
  - utf8 total direction (decode∘encode, non-ASCII 'naïve')
  - base64 octet round-trip (total over octets)
  - RFC 4648 §10 golden vectors ('' f fo foo foob fooba foobar)
  - base64url alphabet golden (+/ vs -_) + UrlSafe round-trip

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: base64/base64url in std.encoding (pure .dag, RFC 4648) + Bytes≅List<UInt

* base64_decode: fail-closed on invalid input (§5)

Review finding (claude-opus-4-7): base64_char_value silently returned 63 for
any non-alphabet char — a fail-open decoder fabricating plausible octets from
garbage, against §5 'loud error, never a warning'.

Fix by construction: base64_decode is a PARTIAL function (List<UInt8>?), mirroring
the utf8_decode partiality. base64_char_value -> Int? (Present for the exact
RFC 4648 alphabet incl. the per-variant +/ vs -_ specials, none otherwise);
base64_collect_values short-circuits to Absent on the first invalid char, so the
whole decode is Absent (typed absence), never silent garbage.

New fail-closed witnesses (green by execution):
  - base64_decode_rejects_invalid_char_holds   ('Zm9*' -> Absent)
  - base64_decode_rejects_cross_variant_char_holds ('Zm9-' under Standard -> Absent)
Round-trip witnesses updated to unwrap Present. All 8 green; dsl compile 437/0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* base64_decode: reject interior '=' and lone trailing sextet (RFC 4648 §3.5)

Review finding (claude-opus-4-7, non-blocking): the decoder accepted
arbitrarily-placed '=' and silently dropped a lone trailing sextet
(flush ignored count==1). Both are fail-open residuals — RFC 4648 §3.5 says
decoders SHOULD reject. Completing the fail-closed wall started for invalid chars:

- base64_collect_values carries seen_pad: once '=' is seen, any later non-'='
  char -> Absent (interior/misplaced padding rejected).
- base64_decode_flush -> List<Int>?; count==1 (lone sextet, structurally
  impossible in valid base64) -> Absent instead of silent drop.

New witnesses green by execution:
  - base64_decode_rejects_interior_pad_holds   ('Zg==Zg==' -> Absent)
  - base64_decode_rejects_lone_sextet_holds     ('Zm9vY' (5 sextets) -> Absent)
  - base64_decode_accepts_unpadded_holds        ('Zm9vYg' -> 'foob') CONTROL:
    proves unpadded-but-valid still decodes (not over-rejecting; base64url
    legitimately omits padding, so length%4 is NOT required).
All 11 witnesses green; dsl compile 437/0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: base64/base64url in std.encoding (pure .dag, RFC 4648) + Bytes≅List<UInt

* Bytes seam: fail-close the decoy .dag bodies + open-thread marker ((A)-ruled hardening)

Parent ruling (neat-boar-71, signed by bright-stag-194): keep the host-seam
shape (A) — NO PrimitiveContract/registry conversion, no inference touch — but
satisfy a hard §5 condition: a decoy body is only acceptable if PROVABLY
UNREACHABLE; a body that returns a plausible value ([] / "") on a path that can
execute is a fail-OPEN fabrication, worse than the §3 fork.

Fail-close every seam body (loud, never a fabricated value):
  - bytes_octets:      [] -> [pure_dag_seam_unreachable()] (1/0 -> DivisionByZero)
  - utf8_decode_bytes: "" -> from_code_point(pure_dag_seam_unreachable())
  - octets_bytes / utf8_encode_bytes: already fail-closed ( raises an
    unsupported-cast at runtime; eval_cast has no Bytes arm).

Verified by execution (parent's probe): with the bodies fail-closed, the FULL
witness suite (11) stays green => the v1 host builtins shadow the bodies => they
are dead. And when reached (non-shadowed), they raise 'division by zero' instead
of fabricating — confirmed on a throwaway non-shadowed fn.

Open-thread marker (comments are walled tree-wide by #5567, so markers are
in-code  rows): bytes_seam_host_realization_marker +
utf8_decode_bytes_host_realization_marker tie all four bodies to the DESIGN.md
open thread 'ground each primitive into its realization' (operator-owned);
dissolve-on = that systemic grounding lands, converting all to
PrimitiveContract + builtin_function_registry together.

dsl compile 437/0; all 11 witnesses green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Remove stray probe file zzfc_test.dag (auto-committer captured a throwaway)

A throwaway typecheck-probe file was swept into a WIP auto-commit; it is not part
of the base64 work. Removing it.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* WIP: base64/base64url in std.encoding (pure .dag, RFC 4648) + Bytes≅List<UInt

* Revert ROADMAP hand-edit: wrong artifact (ROADMAP is a generated projection)

The orphan-doc pointer I added to ROADMAP.md drifted the generated artifact
(RoadmapArtifact in gunbc.generated_artifact, emitted from PR data), reddening
generated_artifact_drift_gate. Proven by differential: reverting the line ->
drift gate returns true. The intent-linearity-design-draft orphan is a main-side
defect (unreferenced on origin/main itself); not fixed by hand-editing a
generated artifact on this branch.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* std/{bytes,encoding}.dag: remove host-realization / debt marker data rows (operator-directed)

Operator asked to delete the verbose marker data rows from the PR. Removes
bytes_seam_host_realization_marker, utf8_decode_bytes_host_realization_marker,
and base64_group_fill_carrier_debt_marker. They were inert (no consumers, no
census gate); compile 446/0 and all 11 base64 witnesses stay green by execution.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* std.encoding: ground base64 count carriers as closed sums (§5 construction)

Per review 31963 (RC) + parent greenlight: the Base64EncodeState.count /
Base64DecodeState.count Int tags were hand-rolled closed sums over {0,1,2} /
{0,1,2,3} with dead-but-representable else arms — an illegal state writable in
std/ substrate (count=2 with only one octet buffered). Fuse counter+octets into
one sound carrier:
  Base64EncodeBuf = EncEmpty | EncOne{b0} | EncTwo{b0,b1}
  Base64DecodeBuf = DecEmpty | DecOne{v0} | DecTwo{v0,v1} | DecThree{v0,v1,v2}
The 4 step/flush fns now match exhaustively over the coproduct (§4 ops-from-
inhabitance) — NO else arm exists, so the illegal combos cease to be
representable (state-space de-conflation, not the widening trap: variants CARRY
the octet data). You cannot construct an EncOne without its Int.

Verified by execution on the post-#5579 binary: compile 450/0, 11/11 base64
witnesses green; discriminating perturb (swap octets in the EncOne->EncTwo arm)
reds golden-vectors + roundtrip, restore -> green.

UInt8<->Int seam (base64_octet_int b+0 / base64_octet_of_int n) left as free
coercion: std.integer has no widen/narrow surface, so a typed Bounded<Int>
conversion belongs to the operator-owned 'ground each primitive into its
realization' open thread, not this PR.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jun 23, 2026
…g 970 EVO Plus) + the in-band/out-of-band observability boundary (BMC can't see drives — route queries by channel) + update operator_fleet.dag with per-host drives (srv1/srv2 in-band, srv3 known); multiple-drives-per-host (#5586)

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* Rename operator_fleet{,_network} -> fleet_intent{,_network} (operator-directed)

Module + symbol + file rename (gunbc.operator_fleet -> gunbc.fleet_intent,
gunbc.operator_fleet_network -> gunbc.fleet_intent_network) plus the test
witnesses and the consuming importers (ci_runner_placement, runner_placement
witness, roadmap_authority prose). Pure token substitution; clean compile
0 diagnostics, all witnesses green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* Finalize fleet storage: srv3 Samsung 970 EVO Plus 2TB, per-drive serial typed-absent

Operator confirmed (via neat-boar-71): srv1/srv2 = WD_BLACK SN850X 2TB final,
srv3 = Samsung 970 EVO Plus 2TB final (MZ-V7S2T0BW), serials pending in-band
enumeration. StorageDevice gains serial: NonEmptyStr? (typed-absent/pending,
not fabricated) closing the per-drive-identity review finding structurally.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* docs: link intent-linearity draft from self-applying-lenses (heal inherited doc-orphan)

The intent-linearity-design-draft.md (added by #5584 'roadmap discussion') was
unlinked tree-wide — orphan on main HEAD too, reding doc_graph_has_no_orphan_docs
(main CI confirmed red). It is the candidate DESIGN.md articulation of the same
fractal-intent-linearity crux self-applying-lenses.md opens with, so the cross-link
is topically exact (the regime2 <- emission-ingestion-inverse pattern).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Revert orphan cross-link in self-applying-lenses.md (defer to #5604 central fix)

Per parent ruling: #5604 (warm-lark) is the designated CENTRAL orphan fix and
edits this exact file; a per-branch link to the same orphan from the same file
would collide on merge and duplicates the heal (DESIGN §2). Drop my line; #5586
stays orphan-red until #5604 lands, then merges origin/main CLEAN and inherits
the central heal. Keeps the ROADMAP.md regen (my genuine drift fix).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* observability: dissolve channel_observes Bool predicate into route_observation (review §3)

Reviewer (claude-opus-4-7, non-blocking APPROVE) flagged channel_observes(channel,
class) -> Bool as a predicate over coproducts that brushes predicate-dissolution: it
was a second public surface answering the same question route_observation answers with
the typed ObservationRoutingOutcome. Inlined its match into route_observation so the
only public answer is the structured outcome (RoutedTo/ChannelCannotObserve), and the
witness now asserts that typed surface directly (no Bool projection). Compile clean
(0 diagnostics); all 5 observability witnesses green by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: Model storage devices (grounded NVMe StorageDevice in extdeps, Samsung 9

* observability: name the OOB host-inventory blind cell as firmware-grounded (review §3 (b))

Per parent's §6-scaffold conditions: route_observation's OutOfBand StorageInventory/
NetworkInventory arms now go through out_of_band_inventory_blind_pending_firmware_visibility_derivation,
so the carrier itself states this outcome is FIRMWARE-GROUNDED (derives from host
storage/network visibility at the 2nd firmware) rather than reading as a channel-universal
claim. Comments are comment-walled (#5567/#5579 — verified: a // line is a compile error),
so the dissolution trigger lives in the carrier name (DESIGN §6 'the mark on the carrier is
the authority'). No behavior change: the cell still returns ChannelCannotObserve; witnesses
green; flip-openbmc perturb still reds the grounding witness by execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fleet_intent: repoint ci_budget_tree.dag import after rename (merge-collision fix)

Main's new ci_budget_tree.dag (#5590/#5595 budget-tree work) imports gunbc.operator_fleet
{ srv1_host }; my rename operator_fleet -> fleet_intent makes that unresolved in the merge
commit. Repointed to gunbc.fleet_intent (srv1_host unchanged). Whole-tree compile: 0
diagnostics. Same class as the earlier rust_gates_ci.dag repoint.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant