Repository navigation
Ground the host-effect plan doc into its .dag Plan authority (close #5745's parallel-rep debt) - #5764
Merged
Merged
Conversation
….dag #5745 hand-edited ROADMAP.md (+the host-effect-orchestration `→` pointer) and added docs/plans/host-effect-orchestration.md as raw markdown, neither driven through the .dag model + regen. Both are GeneratedArtifacts (RoadmapArtifact, PlanArtifact), so the emitted form no longer matched the committed files → generated_artifact_drift_gate_passes returned Bool(false), reding main from #5745's merge onward. - model the doc as gunbc.plans.host_effect_orchestration (Plan authority, faithful body incl. the apply() code fence + layer-split table + dissolution trigger); register in plan_registry_batch_g. - back the ROADMAP `→` pointer with a section_prose in roadmap_authority (split the Host-operation band group: heading group + prose + list group). - regen all artifacts (claim_batch main_wet --wet) so committed == emitted. Green by execution: generated_artifact_drift gate ExitSuccess (no drift), every_registered_plan_has_dissolution_trigger + _is_titled PASS, whole tree resolves. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
# Conflicts: # dsl/gunbc/roadmap_authority.dag
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…p was BACKWARDS (shipped false status) My prior "drift fix" was the wrong direction and un-landed correct status (§5 ships-false-status trap). Ground truth (parent neat-boar-71 verified by reading both files on origin/main): - the committed .md said Phase A "[LANDED #5756]" = CORRECT - the .dag authority (host_effect_orchestration.dag) says "[now, parallel]" = STALE (the authority itself was regressed, likely by #5764 grounding a pre-landed draft). main_wet regenerated the .md FROM the stale .dag, propagating the regression INTO the .md and reverting the accurate "[LANDED #5756]" back to "[now, parallel]". My differential control (committed == origin/main) only proved the drift was not introduced by this PR's 4 model files — it did NOT establish which side was correct. I wrongly assumed authority==truth; here the authority was the stale side. Fix: restore docs/plans/host-effect-orchestration.md to origin/main (the LANDED version). KEEP ROADMAP.md + roadmap_authority.dag (the srv3 orphan-doc pointer — legit BMC scope). Do NOT touch the .dag or re-run main_wet — the drift ROOT (stale .dag) is the host-effect lane's to fix in a separate focused PR. EXPECTED: generated_artifact_drift_gate stays RED on #5773 until the host-effect lane's .dag fix lands on main; that is correct, not a regression to chase. Rebase on main after their fix merges. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
Without the `body_is_param_ref` guard, `emit_fn_def` added `M: Clone` to
every function whose return type was a bare generic param — breaking
`generic_fn_emits_type_params_without_synthesized_bounds` (identity/fold_stack).
Correct signal: `ExprVar` nodes carry the variable name as `.name` and have no
children; `ExprFieldAccess` nodes carry the field name (not the receiver).
So `body.name ∈ value_param_names` IFF the body is a direct parameter return.
Clone bound is now added only when `return_is_bare_generic && !body_is_param_ref`,
which fires for `measure_count<Q,S,M>(m) -> M { m.count }` (field access, M: Clone
needed to call `.clone()` through Rc) but not for `identity<T>(x) -> T { x }`
(direct param ref, no Rc access, no .clone() emitted).
Also regenerate docs/plans/host-effect-orchestration.md from its .dag authority
(pre-existing drift since #5764; the committed file matched an older Phase A/B state).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…rity (drift fix)
The committed .md carried a stale pre-grounding version ('LANDED #5756'
Phase A/B text) that predated #5764's grounding of the plan into its
gunbc.plans authority. Regenerated via main_wet so the projection matches
the single-authority output (identical to origin/main); fixes the
generated_artifact_drift_gate red. No 3-file scope content touched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jun 25, 2026
… truth (regressed by #5764) (#5790) The .dag authority had a stale pre-landed draft ([now, parallel]); the committed .md was correct ([LANDED #5756]). Restores the .dag li(text) to the landed prose so projection(.dag) == committed .md and the main-wide generated_artifact_drift_gate goes green. Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Jun 25, 2026
…egen ROADMAP.md #5795 added docs/plans/roadmap-spawner.md without an inbound edge, reding the tree-wide doc_graph_has_no_orphan_docs floor gate (folds ALL committed docs, so it blocked every open PR's floor). Fix is §3 single-authority: the roadmap-as-spawner work IS a roadmap node, so it belongs cited in the authority. Adds an authored_doc node `8-roadmap-spawner` under §8 (Session dashboard on .dag) — the slice it un-shelves (operator-directed) — with path: docs/plans/roadmap-spawner.md, giving the doc its inbound link. ROADMAP.md regenerated from the authority via main_wet (never hand-edited). Verified: first_failing_path no longer returns ROADMAP.md (the only residual is docs/plans/host-effect-orchestration.md — the entangled #5764/#5796 host-effect drift neat-fox-547 is fixing; both must land to green the wave's floor). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…repo requirements (DESIGN.md, extdeps conventions, no handwritten/embedded js or shell, Playwright modeled in extdeps), produce a design for review, THEN implement. Prior approaches (hand-written .mjs, embedded-JS-emit) were reject (#5773) * WIP: srv3 WebUI-KVM virtual-media install, FROM SCRATCH: FIRST understand rep * Ground srv3 WebUI-KVM virtual media as a distinct capability + install mechanism srv3's OpenBMC 2.07 exposes virtual media ONLY via the legacy WebUI KVM (OpenBMC web-UI NBD over wss), NOT over Redfish/DMTF InsertMedia (404). The on-main solve therefore resolved srv3 to PxeHttpInstall — wrong, since PXE cannot cross the Tailscale overlay (needs BIOS net-stack + same-L2). Per DESIGN §3 (single authority; the OpenBMC web-UI mechanism is a DIFFERENT mechanism than DMTF Redfish VirtualMedia, not a nickname for it): - extdeps/bmc/capability: add a DISTINCT CapabilityWebuiVirtualMedia variant (kept separate from CapabilityVirtualMedia, the Redfish surface) and ground openbmc_2_07_00_capabilities to include it (srv3 live-probe confirms the web-UI KVM media path works). - gunbc/os_install_mechanism: add the WebuiVirtualMediaInstall arm; solve prefers Redfish VirtualMediaInstall (automatable standard) first, then WebuiVirtualMediaInstall, then FirmwareUpdateThenVirtualMedia, then PXE. srv3 now falls out of the grounded solve to WebuiVirtualMediaInstall. Witness green-by-execution (8/8 PASS via claim_executor) + discriminating RED control (dropping the capability flips srv3's two grounding tests to FAIL): - redfish_vm_preferred_over_webui (both caps -> Redfish, proves ordering) - webui_vm_capable_row_solves_webui (WebUI-only -> WebuiVirtualMediaInstall) - vm_capable_firmware_row_flips_to_update_path uses an update-only current row (srv3's row now carries WebUI VM, so the old test premise moved). The install-WORKFLOW over browser ops is HELD pending the operator's runner-origin decision (see docs/plans/srv3-webui-kvm-virtual-media.md §5); this PR is pure modeling, zero JS. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv3 WebUI-KVM virtual-media install, FROM SCRATCH: FIRST understand rep * Rename Webui→NbdProxy virtual-media capability (§3: cite OpenBMC's real term, not a client nickname) CapabilityWebuiVirtualMedia / WebuiVirtualMediaInstall were named after one CLIENT (the WebUI browser). Per DESIGN §3 (single authority; cite the upstream's real name, not a coined nickname), the actual BMC capability is OpenBMC's nbd-proxy virtual media (upstream "proxy mode": browser/JS NBD server over a secure websocket carrying NBD) — distinct from DMTF Redfish InsertMedia (CapabilityVirtualMedia). The browser is just one client of that protocol; openbmc/jsnbd ships a non-browser reference (the nbd-proxy binary). Rename only — solve precedence (Redfish-VM > nbd-proxy-VM > firmware-update > PXE) and the 8/8 witness logic are unchanged: CapabilityWebuiVirtualMedia -> CapabilityNbdProxyVirtualMedia WebuiVirtualMediaInstall -> NbdProxyVirtualMediaInstall (+ matching test-fn / local-var names). srv3 still falls out to NbdProxyVirtualMediaInstall as a consequence of the grounded solve. This keeps the client-named nickname OFF main entirely (not cement-then-churn). The formal openbmc/jsnbd ExternalAuthority citation homes with the Layer-1 transport shape in the B design (extdeps/bmc/webui), not the capability taxonomy. Witness 8/8 green-by-execution via claim_executor. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Design doc → architecture B (direct wss+NBD seed client), fold in srv3 read-only probe Rewrite the srv3 virtual-media design from the rejected browser/Playwright path to architecture B: the WebUI KVM "attach media" is sugar over OpenBMC's documented nbd-proxy protocol (NBD carried in a secure WebSocket; BMC is the NBD client, we are the NBD server). The honest realization is a direct wss+NBD client in the Rust seed — a transport realization like ureq/sh, NOT UI automation. No browser, no JS. Adds: - §1 the protocol grounded from openbmc/jsnbd (nbd-proxy / nbd.js) + the NBD fixed-newstyle handshake + docs/designs/virtual-media.md. - §2 read-only srv3 probe findings: Redfish VirtualMedia 404 under BOTH Systems and Managers => InsertMedia AND legacy HTTPS/CIFS share-mount are OUT (answers parent's disambiguation; Tailscale-reachability for that path is moot). New doubt: nbd ws route 404s on non-upgrade GET + no static WebUI + KVM-video-only => nbd-proxy may not be compiled into this 2.07.00 build; settling it needs an operator-gated ws-upgrade dry-run. - §3 the §3 interface/transport/policy split for NbdProxyServe. - §6 two sign-off gates before any seed code: (1) operator ws-upgrade dry-run confirming nbd-proxy is present, (2) acceptance of a seed-resident wss+NBD client as the realization origin. Capability/dispatch modeling (8/8 witness) stays done in #5773; seed client deferred. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv3 WebUI-KVM virtual-media install, FROM SCRATCH: FIRST understand rep * Fix §5 fail-open: keep srv3's cited row at read-only-probe truth (drop ungrounded NbdProxy VM capability) Review (claude-opus-4-7, REQUEST_CHANGES) correctly caught a §5 fail-open: the openbmc_2_07_00_capabilities cited row asserted CapabilityNbdProxyVirtualMedia for srv3, but the design doc itself flags that surface as UNSETTLED — /nbd/0 404s on a non-upgrade GET (indistinguishable from absent), and settlement is gated on the §6 operator ws-upgrade dry-run. Asserting the capability before the dry-run dispatches srv3 to NbdProxyVirtualMediaInstall on an ungrounded fact. Fix — leave the cited row at exactly what the read-only probe grounded: - drop CapabilityNbdProxyVirtualMedia from openbmc_2_07_00_capabilities (back to PowerControl/BootSourceOverride/AccountManagement/FirmwareUpdate — the 200-confirmed Redfish surfaces; KVM video != virtual media). - srv3 now HONESTLY solves to PxeHttpInstall today (FirmwareUpdate present, catalog has no VM-capable firmware), not NbdProxyVirtualMediaInstall. - witness: srv3_capabilities_are_grounded now asserts NbdProxyVirtualMedia == false; srv3_install_mechanism_is_nbd_proxy_vm_today -> srv3_install_mechanism_is_pxe_until_dry_run. Kept (reviewer: "the dispatch arm and discriminating RED rows are fine to land now"): the NbdProxyVirtualMediaInstall enum arm + solve precedence, and the synthetic-row proofs nbd_proxy_vm_capable_row_solves / redfish_vm_preferred_over_nbd_proxy — the arm is proven on a GROUNDED synthetic row, not on srv3's ungrounded one. Flipping srv3's row to CapabilityNbdProxyVirtualMedia is deferred to the PR that lands the §6 dry-run confirmation receipt. Design doc §5 updated to match. Witness 8/8 green by execution via claim_executor. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv3 WebUI-KVM virtual-media install, FROM SCRATCH: FIRST understand rep * Revert host-effect-orchestration.md to origin/main — my main_wet sweep was BACKWARDS (shipped false status) My prior "drift fix" was the wrong direction and un-landed correct status (§5 ships-false-status trap). Ground truth (parent neat-boar-71 verified by reading both files on origin/main): - the committed .md said Phase A "[LANDED #5756]" = CORRECT - the .dag authority (host_effect_orchestration.dag) says "[now, parallel]" = STALE (the authority itself was regressed, likely by #5764 grounding a pre-landed draft). main_wet regenerated the .md FROM the stale .dag, propagating the regression INTO the .md and reverting the accurate "[LANDED #5756]" back to "[now, parallel]". My differential control (committed == origin/main) only proved the drift was not introduced by this PR's 4 model files — it did NOT establish which side was correct. I wrongly assumed authority==truth; here the authority was the stale side. Fix: restore docs/plans/host-effect-orchestration.md to origin/main (the LANDED version). KEEP ROADMAP.md + roadmap_authority.dag (the srv3 orphan-doc pointer — legit BMC scope). Do NOT touch the .dag or re-run main_wet — the drift ROOT (stale .dag) is the host-effect lane's to fix in a separate focused PR. EXPECTED: generated_artifact_drift_gate stays RED on #5773 until the host-effect lane's .dag fix lands on main; that is correct, not a regression to chase. Rebase on main after their fix merges. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…ore byte-equality proof (#5771) * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * gap B review: hoist scenario extraction out of std (§3) + fail-closed Optional accessors (§5) Addresses claude-opus-4-7 review on #5771: - §3: remove retry_eagain_command/retry_eagain_pattern (gunbc-scenario nicknames) from v2.std.orchestration; the retry intent->(command,pattern) extraction now lives in the witness (gunbc layer), restoring the std<-extdeps<-workflow arrow. bash retry target models take command/pattern strings directly (gap-A emit_directive precedent: construction-safe, no Step sum-match in the realization). - §5: replace ''-fabricating accessors (classifier_pattern, step_run_command_spelling) with fail-closed Optional ones (classifier_log_pattern, step_command_spelling) -> Present only for the meaningful arm, Absent otherwise; witness threads Optional and a missing shape goes red instead of emitting an empty slot. Both witnesses green by execution under claim_batch; RED twin still breaks byte-equality. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * Regenerate host-effect-orchestration plan doc to match its .dag authority (drift fix) The committed .md carried a stale pre-grounding version ('LANDED #5756' Phase A/B text) that predated #5764's grounding of the plan into its gunbc.plans authority. Regenerated via main_wet so the projection matches the single-authority output (identical to origin/main); fixes the generated_artifact_drift_gate red. No 3-file scope content touched. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * WIP: P3-impl gap B: orchestration-as-intent emit(intent,Bash) core + retry_co * gap B (round-4): canonical list_head/list_tail + inline Predicate match; fix payload-concretization cascade Findings 1+2: deleted std nicknames (escalations_head/escalations_rest/ pipeline_first_step) and one-arm projections (predicate_log_pattern/ step_command_spelling); witness now calls canonical list_head/list_tail (algebra.dag) in test-local re-wrap helpers and matches the closed Predicate/Step coproducts inline, exhaustive + fail-closed. Interp constraint found by execution: field access / variant-match on a value bound directly from a generic list_head payload cascades (the payload type stays deferred). Concretize by re-wrapping into a concretely-annotated Optional<T> (escalation field access) and routing the Step variant-match through a concrete-EscalationLevel/Step-param helper (command extraction). 3/3 witnesses green by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…599) + Optional receiver unwrap before method call (E0624) (#5777) * WIP: Lane A cargo-green re-census + Phase C1 fixed-point SCOPING (post measur * WIP: Lane A cargo-green re-census + Phase C1 fixed-point SCOPING (post measur * WIP: Lane A cargo-green re-census + Phase C1 fixed-point SCOPING (post measur * WIP: Lane A cargo-green re-census + Phase C1 fixed-point SCOPING (post measur * Fix E0599 over-broad Clone bound: narrow gate to body-is-not-param-ref Without the `body_is_param_ref` guard, `emit_fn_def` added `M: Clone` to every function whose return type was a bare generic param — breaking `generic_fn_emits_type_params_without_synthesized_bounds` (identity/fold_stack). Correct signal: `ExprVar` nodes carry the variable name as `.name` and have no children; `ExprFieldAccess` nodes carry the field name (not the receiver). So `body.name ∈ value_param_names` IFF the body is a direct parameter return. Clone bound is now added only when `return_is_bare_generic && !body_is_param_ref`, which fires for `measure_count<Q,S,M>(m) -> M { m.count }` (field access, M: Clone needed to call `.clone()` through Rc) but not for `identity<T>(x) -> T { x }` (direct param ref, no Rc access, no .clone() emitted). Also regenerate docs/plans/host-effect-orchestration.md from its .dag authority (pre-existing drift since #5764; the committed file matched an older Phase A/B state). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * Revert host-effect-orchestration.md: drift fix was wrong-direction My regeneration via main_wet reverted the plan doc from LANDED [#5756] to [now, parallel] — wrong direction. The .dag Plan authority needs to be updated (not the committed .md) to fix the drift, and that belongs to the host-effect lane (neat-boar/fierce-carp). Restoring the correct LANDED state. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * E0091: realize unused type-alias params as PhantomData (cargo-green 2→0) type Compose<Algebra, MachineConstraint> = Phantom emits a bare Phantom ZST with neither param referenced in the RHS → E0091 ×2. Fix mirrors the struct path (rust_phantom_marker_inner, line ~3229): detect params absent from the alias RHS via alias_unused_param_names (same type_node_mentions_name predicate as struct_unused_param_names), then substitute std::marker::PhantomData<(Algebra, MachineConstraint)> for the RHS. Guard: only fires when unused_params |> count > 0 — param-using aliases (List<T>, Map<K,V>) have their params present in the RHS and are left unchanged. Witness: unused_param_alias_gets_phantom_data (positive — Compose gains PhantomData carrying both params) + param_using_alias_has_no_phantom_data (negative control — Wrapper<T> = List<T> is unperturbed). Both axes of E0599+E0624 witnesses still green (no regression). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fmt: fix brace placement + module order (cargo fmt --all --check red) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix html_markup_smoke_test: add dsl/extdeps source root (smoke dag imports extdeps.languages.html after d3ed2a9) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jun 25, 2026
…egen ROADMAP.md (#5804) #5795 added docs/plans/roadmap-spawner.md without an inbound edge, reding the tree-wide doc_graph_has_no_orphan_docs floor gate (folds ALL committed docs, so it blocked every open PR's floor). Fix is §3 single-authority: the roadmap-as-spawner work IS a roadmap node, so it belongs cited in the authority. Adds an authored_doc node `8-roadmap-spawner` under §8 (Session dashboard on .dag) — the slice it un-shelves (operator-directed) — with path: docs/plans/roadmap-spawner.md, giving the doc its inbound link. ROADMAP.md regenerated from the authority via main_wet (never hand-edited). Verified: first_failing_path no longer returns ROADMAP.md (the only residual is docs/plans/host-effect-orchestration.md — the entangled #5764/#5796 host-effect drift neat-fox-547 is fixing; both must land to green the wave's floor). Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Context
mainwent red from #5745, which hand-edited two generated artifacts (ROADMAP.md+ a rawdocs/plans/host-effect-orchestration.md) without driving them through the.dagmodel. The ROADMAP-drift red is already fixed on main by #5762 — so this PR is narrowed to the one piece #5762 left undone: grounding the raw plan doc into its.dagPlanauthority (no-dual-representation, DESIGN §6).What this does
gunbc.plans.host_effect_orchestration(faithful body incl. theapply()code fence, layer-split table, dissolution trigger); register inplan_registry_batch_g.docs/plans/host-effect-orchestration.mdis now a regenerated projection of that Plan (was raw markdown).Verified green-by-execution (merged tree)
generated_artifactdrift gate →ExitSuccess(committed == emitted; regen leaves the tree clean)every_registered_plan_has_dissolution_trigger+_is_titled→ PASS🤖 Generated with Claude Code