Repository navigation
docs: enforcement-intent governance model — ask once, compile forever - #6164
Merged
Merged
Conversation
- §2 posture: required CI back on the fleet (#6111 revert; Ubicloud detour bought no wall-clock — serial compile-clean wall dominates); milestones updated; fleet-return group becomes fleet-hardening (the return happened ungated, the gates are now owed). - New: 2-compile-clean-serial (the ~47min width-immune dominant cost + its three levers), 2-runner-shape (operator 1:3 core:GiB + swap slot contract), cap-deconflation corrected (width=9 was live by construction; the deferred item was only the concept rename), CD-transport reframed post-revert, G4 gains the dup-run + lingering in_progress evidence. - §3 audit: 3-audit-artifact-freshness (operator freshness-gate ask; the .gitignore landed-drift incident as the RED receipt, closes via the merge-admission freshness block) and 3-audit-gate-disagreement (compile-clean green while discovery red on the same tree — the extdeps.shell collision; one tree, one verdict). - §1 5-defork gains the live evidence line (the shell fork kept main red). Witnesses re-targeted in lockstep; verified by execution: main_wet regen, drift gate, roadmap_authority_witnesses, doc-graph orphans+dangling all PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…d MVP
Applies the operator's three directives in one lockstep batch:
1. Roadmap-review blockers:
- Ubicloud tone: detour was the diagnostic + emergency valve, not a
failure; stays the break-glass/burst option.
- CD transport reframed as target-host proof (LocalShell valid only
when runner identity proves host=srv1), not Ubicloud-specific.
- v1-collapse dependency edges now REAL: roadmap_spawner readiness is
all-parents (node_dep_done folds every edge, not the first), with a
RED/GREEN multi-parent witness; 5-collapse-v1 gains edges from
dissolve-patches, test-migration, seed-honesty, defork.
- workload-class admission model + cap/admission de-conflation (three
facts, one knob today) + sound host admission (Guaranteed vs Burst
with Σ-accounting receipts) + live host read seam as first-class
nodes; G1 stale "dormant on Ubicloud" conditional fixed (cursor
review finding on #6110).
- Floor group renamed: throughput — reduce work, then schedule it.
- Shelf: privacy/isolation model + structural correctness walls.
2. Fabric dispatch design (operator-signed): core design rule prose
(ProviderOffer adapter / RunShape→Allocation→Receipt / strict default /
oversubscription earned by receipts), StrictLease Policy 0, CI shape
labels (runs-on as a projection; runner availability is backpressure),
ProviderOffer rows + dormant-Ubicloud design-break probe, BurstLease
Policy 1; TERMINAL reworded to "required CI runs on the compute
fabric"; converge re-land gains the narrow srv2 first-acceptance case;
ordering prose ①–⑩.
3. Stateless frontend MVP on fabric: first non-CI product-shaped
consumer (SiteArtifact/WebServiceShape/DomainRoute/ServiceAllocation,
manual DNS, digest-proving receipt, milestones A/B), service
allocation receipt under control plane, fabric-hostable rule prose,
shelf HTML line scoped.
Verified by execution: main_wet regen, drift gate, roadmap_authority
witnesses (new fabric pins + updated interleaving neighbor), spawner
witnesses (incl. new all-parents RED control), doc-graph orphans +
dangling links — all PASS.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tion fix
Operator ask: a small utility returning the active/needed work items to
dispatch from the roadmap (frontend/visualization seam, useful now).
- gunbc.roadmap_spawner gains roadmap_dispatch_json (single authority
for spawn semantics): {ready (full node rows), upcoming (node +
unmet_parents), done}. node_json also emits parent_node_ids (all
parents — folds in claude's non-blocking #6110 finding; single
parent_node_id kept for bridge back-compat). json_escape now escapes
newlines (latent invalid-JSON bug, witnessed).
- dsl/tools/roadmap_dispatch.dag: `claim_batch --source-root dsl
--entry dsl/tools/roadmap_dispatch.dag --function main --wet` writes
target/roadmap-dispatch.json (schema roadmap-dispatch-file/v1, embeds
the M0-M3 worker-brief template).
- First-receipt splits per operator dispatch review:
1-resolver-pathology → -a (profile receipt only) / -b (fix one
confirmed pathology, edge b←a); 2-live-read-runner-memory as the
first slice of the read seam (seam gated on it); 2-privilege-model
sized with RED/green acceptance.
- Edge-direction fix (operator structural concern): 2-converge-reland
now DEPENDS ON 2-live-read-seam + 2-privilege-model (was inverted:
privilege as converge's child); umbrella g2-runner edge removed so it
cannot gate; periodic-actuation ← converge kept.
Verified by execution: spawner witnesses (new dispatch-partition +
newline-escape RED controls), authority witnesses, main_wet regen,
drift gate, doc-graph — PASS; utility run produces valid JSON with 11
ready / 4 gated, gates matching the signed ordering.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…owned Operator go-ahead post-merge of #6110/#6111/#6112. 2-compile-clean-shard-a (partition boundary + ONE shard + compose proof, no scheduler enrollment) dispatched as adhoc-3e95c046-279 and marked owned; 2-compile-clean-shard-b (floor-plan enrollment + before/after batch-1 wall receipt) gated on A. Verified: regen, drift gate, authority + spawner witnesses PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
#6116 (gate-inventory audit + pilot red-control) merged without flipping its node, unlike #6120 which self-marked. Set done: true to parity with the resolver node — both now render "⏳ awaiting sign-off" (the [x] checkbox is gated on operator sign-off by design, not merge alone). Verified: main_wet regen, drift gate, roadmap_authority_witnesses PASS; dispatch file moves 3-audit-gate-inventory to the done partition. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…phan Addresses cursor REQUEST_CHANGES on #6122: - Finding 3 (real): removed 1-resolver-pathology-receipt, a #6120-introduced near-verbatim duplicate of 1-resolver-pathology-a (§2 parallel representation). - Findings 1/2 (drift-heal, not regression): done:true renders "[ ] — ⏳ awaiting sign-off" by design (box = signoff_accepts, not merge); #6120 had committed ROADMAP.md with resolver-A as [x] with no sign-off — that was drift, and the regen heals it to the honest awaiting-sign-off state. - Also heals a pre-existing doc-graph orphan: mechanism-inventory-red-controls.md (#6116) was link-unreachable; attached it to the 3-audit-gate-inventory node via a new with_plan helper (keeps the node sized). Verified: main_wet, drift gate, roadmap_authority_witnesses, doc-graph orphans + dangling links all PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…branch Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…des done The three verification-target PRs merged without self-marking their nodes; central-marker flips 2-cd-transport, 2-live-read-runner-memory, and 2-compile-clean-shard-a to done: true (render 'awaiting sign-off' — operator sign-off stays separate). Drift gate, roadmap witnesses, doc-graph all green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…) done; flip 2-privilege-model (#6114); mark 2-emit-partition dispatched - authored_merged_prs += 6104, 6106 (operator merged both) - 2-privilege-model done: #6114 merged, live receipts on #6123/#6130 wet runs - 2-emit-partition now un-gated and dispatched (adhoc-2040cdfe-46b) - regen ROADMAP.md via generated_artifact_gate main_wet; drift gate + roadmap witnesses PASS Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ci_deploy_access to main) The manual-deploy investigation surfaced two real bugs (dash/pipefail + principal fiction) but the fix belongs in the modeled grounded-principal lane, not anemic stopgap strings. Restoring these two files to origin/main clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…lt stays modeled) Operator directive 2026-07-02: a healthy floor is ~9min solo — a job past 30min is pathological and must fail fast + release its runner slot instead of squatting toward the platform ceiling (observed: 6h-timeout jobs holding all 25 fleet slots in a self-sustaining queue deadlock, ~9h single-core claim_executor runs). - gunbc_ci_job_timeout_policy_minutes: Int = 30 (+ Terminal disposition carrying the rationale) - extdeps default_job_timeout_minutes = 360 deliberately unchanged (§3: it faithfully models GitHub's real platform default; policy lives in the workflow layer) - ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…egression) #6127 (merged 15:08 today) sharded compile-clean into ~1,605 per-module gunbc-compile subprocesses, each re-resolving its full import closure (sum-of-closures ~30.9x the monolith CPU), scheduled at WIDTH 1 because the width fold priced each single-module shard against a stale whole-corpus 4.24GiB RSS sample vs the 8GiB cap. Live regression: 8h57m wall / 8h07m CPU per job on an 87%-idle 128-core box. Pre-regression monolith green runs were 28-96min. Sets the modeled rollback valve GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1 on the ci job (env), restoring the whole-tree monolith compile-clean. Authority = the matching v2.workflow valve; rationale on ci_compile_clean_rollback_dissolution_trigger; Scaffold disposition bound, dissolves with the v2 authority once the in-process shard resolve pool lands. ci.yml regenerated via generated_artifact_gate main_wet; drift gate PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE valve does NOT cleanly restore a green monolith floor: under the valve, gunbc_ci_floor_schedule_lens_holds() FAILs and batch-0 carries neither shards nor the monolith gate label (verified by execution with claim_batch --wet under GUNBC_CI_COMPILE_CLEAN_WHOLE_TREE=1). The valve looks like a half-exercised scaffold from #6127. Flipping it and patching witnesses to match an unverified plan path would violate DESIGN §5 (ship only what runs green), so this PR keeps only the sound, approved part: - gunbc_ci_job_timeout_policy_minutes = 30 (workflow-layer; GitHub 360 default stays modeled) - disposition text reconciled: 30min is deliberately BELOW today's 28-96min floor — a fail-fast smoke alarm until the resolver single-thread fix lands (verification local meanwhile) The #6127 regression is better addressed by a clean revert of #6127 or a proper fix to the plan's rollback branch (load-bearing floor-plan work) — surfaced to the operator. ci.yml regenerated (timeout-only, no rollback env); drift gate PASS; both shard-b floor witnesses PASS at origin/main state. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…AP §3 node + sketch) Model the operator's recurring standing directives (complexity repo-wide, lenses-must-be-live, self-application, no dual-representation/anemia) as durable StandingIntent rows, gated fail-closed against LensContract + coverage receipts -- "ask once, compile forever". One new authority (StandingIntent); everything else extends existing machinery (LensRegistryEntryV0 -> LensContract; reuse ConstructionJustification / subject_roster; consume intent_linearity / self_applying_lenses for the fractal/self-application layer). Un-shelves the lens-meta-wall lane into ROADMAP §3 with displaced-cost justification (the operator's repeated manual what-is-enforced-by-what-lens-over-what-corpus join). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…emption types + roadmap A-E split) Operator design-review deltas before the model becomes load-bearing: - ConsumerKind / ConsumerRequirement replace the hardwired FloorGate — merge-admission, pre-push, periodic-actuator, deploy-readback are valid consumers (gate leg 4 = consumer_satisfies). - EnforcementMode order (Advisory < AuditOnly < Blocking) modeled with enforcement_mode_satisfies; no overloaded >=. - CoverageReceipt shape added; the gate reads receipts, never self-declared contract claims (a red_control:Present whose receipt is RedControlFailedToFlip still reds). - ScopeSatisfaction / NarrowingReason type the whole-corpus-narrowing path (BootstrapBlocked / TypeReflectionUnavailable / ExternalRuntimeOnly / ExplicitOperatorExemption) — not a stringly hatch. - StandingIntent admission rule (recurring + displaced cost + scoped + mechanism class + receiptable) keeps the carrier from becoming a preference dump. - ROADMAP node split into parent + children A-E with explicit A->B->C-before-object-rules dependency. DESIGN.md entry unchanged (its "mechanism claiming enforcement" wording was already the refinement). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…s; de-nickname PropertyClass Addresses cursor REQUEST_CHANGES (all three findings valid): - DESIGN.md / ROADMAP.md are EMITTED from gunbc.design_document / gunbc.roadmap_authority. My hand-edits to the generated artifacts were drift (a §3 parallel-representation of the authority, and would fail the generated-artifact drift gate). Moved the enforcement-intent content INTO the authorities (open_threads_blocks li + section_3 node + un-shelve prose) and regenerated (claim_batch main_wet). Drift gate now PASSES: committed == emitted. - Removed the PropertyClass nickname (git-grep empty; a fork of the existing LensIdV0 lens-property coproduct at src/v2/lens/registry.dag:10) — the exact §3 sin this PR argues against. StandingIntent.property now reuses LensIdV0. Fitting that a single-authority PR forked its own authority; caught by review, fixed at the source. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lands the governance-layer model the operator signed off on: the operator's recurring standing directives (enforce complexity repo-wide; lenses must be live; lenses must self-apply; scope must not silently narrow; model must not carry dual representations) become durable
StandingIntentrows, gated fail-closed againstLensContract+ coverage receipts. Ask once, compile forever — the repeated manual "what is enforced, by what lens, over what corpus" join stops being the operator's hand-run meta-lens.Docs only. No behavior change. The carrier + gate are a follow-on manager deliverable (silent-ferret-137), built against this declaration.
What changed
enforcement intent + model-quality wallsnode + ananemia/consolidationchild acceptance block.LensRegistryEntryV0→LensContract, reuseConstructionJustification/subject_roster, consumeintent_linearity/self_applying_lenses).Grounding (verified against the tree)
src/v2/lens/cost.dag,WallNow, detectsPoly(2)) but is roster-bound to[dsl, src/v2]— never walkssrc/v1.complexity.repo-widealready reds today on three contract legs (claimed_scope, consumer, self_application) with nodecl_factsdependency — the gate's first honest RED needs nothing new.One new authority (
StandingIntent); everything else is an extension. Default enforcement scope = whole corpus; under-scope is a failing receipt unless explicitly justified.🤖 Generated with Claude Code