Repository navigation
Document absorbing fallback trap and enforcement intent - #6236
Merged
Merged
Conversation
…sed fail-open) A failure arm that answers uncertainty by widening scope (rerun everything, scan all keys, always run) is not fail-closed: it conflates ⊤-as-answer with ⊤-as-ignorance, zeroes the deficit's observable frequency by construction, and denominates its cost in the corpus instead of the change — so the budget breaks later instead of the build failing loudly now. Rule for review: a failure arm must refuse, never widen; every degradation a typed, located, countable diagnostic. Fences the two legitimate neighbors (structural over-approximation computed as the answer; loud budget-bounded interim fallback with a dissolution trigger). Receipt: floor_witness_run_disposition's FailClosed→RunWitness arms and the 90-min CI timeout they produced. Also adds the failure-modes list entry and the enforcement-intent standing directive. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N8eqUhkbcosvSCUJNTm6pe
briansrls
added a commit
that referenced
this pull request
Jul 4, 2026
…uditOnly demotion, live meta-gate CI consumer (E0 / PR-0a) The complexity.repo-wide governance layer (#6167 A-C) consumed hand-authored CoverageReceipt data rows - receipts-by-declaration, the exact §5 edit-the-declaration trap the enforcement-intent design §12 forbids. This PR makes the receipts DERIVED IN-PASS by execution and gives the meta-gate its first live consumer: - receipts.dag (new): discovered_subjects from live decl_facts over the whole corpus; consumer_observed derived by READING commit_gate_roster projections (contract binds its witness via ConsumerWitnessBinding/ScheduleWitnessEntry; the roster stays the single enrollment authority); red_control_status by RUNNING the malformed-Loop probe through cost_lens in-pass; self_application derived from the discovered set; SubjectJudgment = BodyJudged | BodyUnavailable (typed, counted - #6236 discipline; totality judged + unavailable == fn_items asserted by execution). - hand rows receipt_cost/receipt_complexity/coverage_receipt_registry DELETED; probed_at/Timestamp deleted (derivation-in-pass makes staleness unwritable). - lens_contract_cost DEMOTED Blocking -> AuditOnly (anti-overcomplication rule: the gate now PROVES the Blocking claim false - derived consumer is WitnessOnly). Named re-promotion trigger on the row. - gate.dag: find_answering_contract matches by property only; mode-satisfaction becomes the claimed leg (demotion keeps per-leg diagnostics). - standing_intent.dag: whole_corpus_scope "dsl" -> "dag" - the dead root was SILENTLY dropping a third of the corpus through the tolerant walk (the exact silent-narrowing this gate exists to kill); per-root sentinels now guard it. required_subjects grounded to the real qualified name v1.compiler.infer.build_type_env. - enforcement_live.dag (new, workflow layer): the live join - one decl_facts walk per check, receipts derived per contract from the registry fold. - enforcement_live_witness_test.dag (new): 2 CI-ENROLLED fns (commit_gate_roster row added) - enforcement_consistency_gate_holds (Blocking: a Blocking claim without a live consumer reds) and complexity_repo_wide_verdict_matches_roadmap (the 6-leg verdict PINNED: claimed RED, scope RED w/ TRUE fn-body-reflection reason, subjects GREEN, consumer RED, red_control GREEN, self_application GREEN - any drift in either direction reds until the expectation is updated: roadmap-as-executable). Plus 8 local red controls/sentinels: roster-read both directions, empty-facts feed reds subjects, red-control-of-the-red-control, self-application liveness, skeleton->BodyUnavailable absorbing-fallback control, totality, per-root sentinels, and the all-body-unavailable pin. Receipts by execution (2026-07-04, this container): - step-0: decl_facts over [dag, src/v1, src/v2] finds all three sentinels incl. v1.compiler.infer.build_type_env; one walk ~9-10s; fn_item_count = 14283; body_unavailable == 14283 (the honest pin - skeletons only until the v2 front-end ingest lane lands bodies). - all 10 gate_test synthetic witnesses green; all 10 enforcement_live witnesses green; enrolled pair ~40s each interpreted. - live R1 evidence: the step-0 counts probe using decl_facts_fn_items (fold + list_snoc_item) burned 3m41s - the accumulator-in-copied-port quadratic the E2 object rule will wall; new derivations are linear. - KNOWN FORK BITE, worked around with a dissolve marker: importing any dag-tree module (std.realization_schedule via gunbc.commit_workflow) into a v2 entry closure breaks bare imported Empty/Cons at runtime (undefined variable: Empty - the dag<->v2 algebra fork, ROADMAP pillar-1, LIVE fail-open). List construction in the enforcement modules uses [] literals + list_append(left: [x], right: acc) until the algebra de-fork lands (freemonoid_constructor_avoidance_note carries the trigger). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 5, 2026
…uditOnly demotion, live meta-gate CI consumer (E0) (#6238) * WIP: complexity lens enforcement * WIP: complexity lens enforcement * WIP: complexity lens enforcement * Enforcement receipts by execution: derived CoverageReceipts, honest AuditOnly demotion, live meta-gate CI consumer (E0 / PR-0a) The complexity.repo-wide governance layer (#6167 A-C) consumed hand-authored CoverageReceipt data rows - receipts-by-declaration, the exact §5 edit-the-declaration trap the enforcement-intent design §12 forbids. This PR makes the receipts DERIVED IN-PASS by execution and gives the meta-gate its first live consumer: - receipts.dag (new): discovered_subjects from live decl_facts over the whole corpus; consumer_observed derived by READING commit_gate_roster projections (contract binds its witness via ConsumerWitnessBinding/ScheduleWitnessEntry; the roster stays the single enrollment authority); red_control_status by RUNNING the malformed-Loop probe through cost_lens in-pass; self_application derived from the discovered set; SubjectJudgment = BodyJudged | BodyUnavailable (typed, counted - #6236 discipline; totality judged + unavailable == fn_items asserted by execution). - hand rows receipt_cost/receipt_complexity/coverage_receipt_registry DELETED; probed_at/Timestamp deleted (derivation-in-pass makes staleness unwritable). - lens_contract_cost DEMOTED Blocking -> AuditOnly (anti-overcomplication rule: the gate now PROVES the Blocking claim false - derived consumer is WitnessOnly). Named re-promotion trigger on the row. - gate.dag: find_answering_contract matches by property only; mode-satisfaction becomes the claimed leg (demotion keeps per-leg diagnostics). - standing_intent.dag: whole_corpus_scope "dsl" -> "dag" - the dead root was SILENTLY dropping a third of the corpus through the tolerant walk (the exact silent-narrowing this gate exists to kill); per-root sentinels now guard it. required_subjects grounded to the real qualified name v1.compiler.infer.build_type_env. - enforcement_live.dag (new, workflow layer): the live join - one decl_facts walk per check, receipts derived per contract from the registry fold. - enforcement_live_witness_test.dag (new): 2 CI-ENROLLED fns (commit_gate_roster row added) - enforcement_consistency_gate_holds (Blocking: a Blocking claim without a live consumer reds) and complexity_repo_wide_verdict_matches_roadmap (the 6-leg verdict PINNED: claimed RED, scope RED w/ TRUE fn-body-reflection reason, subjects GREEN, consumer RED, red_control GREEN, self_application GREEN - any drift in either direction reds until the expectation is updated: roadmap-as-executable). Plus 8 local red controls/sentinels: roster-read both directions, empty-facts feed reds subjects, red-control-of-the-red-control, self-application liveness, skeleton->BodyUnavailable absorbing-fallback control, totality, per-root sentinels, and the all-body-unavailable pin. Receipts by execution (2026-07-04, this container): - step-0: decl_facts over [dag, src/v1, src/v2] finds all three sentinels incl. v1.compiler.infer.build_type_env; one walk ~9-10s; fn_item_count = 14283; body_unavailable == 14283 (the honest pin - skeletons only until the v2 front-end ingest lane lands bodies). - all 10 gate_test synthetic witnesses green; all 10 enforcement_live witnesses green; enrolled pair ~40s each interpreted. - live R1 evidence: the step-0 counts probe using decl_facts_fn_items (fold + list_snoc_item) burned 3m41s - the accumulator-in-copied-port quadratic the E2 object rule will wall; new derivations are linear. - KNOWN FORK BITE, worked around with a dissolve marker: importing any dag-tree module (std.realization_schedule via gunbc.commit_workflow) into a v2 entry closure breaks bare imported Empty/Cons at runtime (undefined variable: Empty - the dag<->v2 algebra fork, ROADMAP pillar-1, LIVE fail-open). List construction in the enforcement modules uses [] literals + list_append(left: [x], right: acc) until the algebra de-fork lands (freemonoid_constructor_avoidance_note carries the trigger). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Jul 5, 2026
…e model) #6236 landed the absorbing-fallback section by editing DESIGN.md directly; the generated-artifact model never learned it. Undetected because the drift gate produced no verdict since 2026-07-01 (the blackout this branch repairs). Oracle: wet regen must reproduce committed DESIGN.md byte-identically. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 5, 2026
…ng fallback) into design_document.dag + regen ROADMAP.md (#6264) The composed floor's batch-2 GeneratedArtifactDriftGate has been RED on main: generated_artifact_drift_gate_passes -> false (verified on pristine origin/main a44b3b4), stopping the floor before dependent batches for every lane. Root cause, with a direction control on each artifact (drift direction is NOT always authority->projection): - DESIGN.md: #6236 landed the operator-signed section-5 absorbing-fallback trap by editing DESIGN.md DIRECTLY - the generated projection - without its authority dag/gunbc/design_document.dag. A blind main_wet regen would have DELETED the signed content. Fix direction: back-port the three drifted spots verbatim into the authority (trap paragraph, extended e.g. bullet, recurring-failure-modes entry, enforcement-intent thread clause). Oracle: after the back-port, main_wet reproduces committed DESIGN.md byte-identically (it does not appear in the regen diff). - ROADMAP.md: the authority row gained "(#6105)" wording while the committed projection was stale. Fix direction: regen (one line). Receipt: generated_artifact_drift_gate_passes -> true by execution after this commit. The gate did its job; the ironic part - the document that says model-before-implement was hand-edited around its own model - is exactly the class the enforcement-intent lane exists to make unwritable. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 5, 2026
…port #6236 into the DESIGN model) (#6263) * CI budget breach is a step-level FAILURE, never job-cancellation silence (operator ruling 2026-07-05) Any timed-out gate is a failure, not a silent pass — no verdict == failure. The 10-min job-kill (2026-07-04) produced conclusion=cancelled, which every consumer treated as not-red: 29 of 30 main runs cancelled since the last green (2026-07-01T01:00Z), four days of merges with zero gate verdicts, two latent reds entering unseen. Budget moves to step-level timeout-minutes (step fails RED, logs + [t+Xs] phase marks intact), value 30 derived from last-green duration (27min) + margin — re-derive downward as resolver work lands. Job-level timeout becomes a +5 backstop whose firing means the failure mechanism itself wedged. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Port #6236's carrier-only DESIGN.md edit into design_document.dag (the model) #6236 landed the absorbing-fallback section by editing DESIGN.md directly; the generated-artifact model never learned it. Undetected because the drift gate produced no verdict since 2026-07-01 (the blackout this branch repairs). Oracle: wet regen must reproduce committed DESIGN.md byte-identically. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Backstop must exceed prelude + max step budget; budget every gate-bearing step cursor review finding (valid): step timeouts start at step start, so a policy+5 backstop measured from job start could job-cancel (silence) before the gate step fails red whenever prelude runs long - resurrecting the exact silent-pass defect. Backstop is now policy+30 (above worst-case honest prelude + the 30-min gate budget) and the merge-admission, nextest-install, and cgroup steps carry their own 10-min step budgets, so every post-prelude phase fails RED; the backstop fires only on a wedged prelude, which the disposition names a mechanism bug, never a gate verdict. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Budgets stay short per operator ruling: floor 10, rust gate 15, aux 5 Operator (2026-07-05): keep timeouts short - 10 minutes is long enough, 15 at most for rust_tests. The forcing function survives with honest semantics: breach = step-level FAILURE with [t+Xs] phase attribution. Per-job backstops = step-budget sum + prelude allowance (ci 20, rust_tests 30), reachable only via wedged prelude. Until resolver work fits the floor in 10 minutes, main runs red-by-failure: a countable deficit signal, not cancelled silence. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 5, 2026
…ap receipts refresh (1667-error fresh-emit receipt) (#6253) * WIP: continue work on v1 burn down * WIP: continue work on v1 burn down * WIP: continue work on v1 burn down * WIP: continue work on v1 burn down * Drop get-form revert per operator collision resolution (#6255 owns the get arm); regen ROADMAP projection Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: continue work on v1 burn down * WIP: continue work on v1 burn down * Fix roadmap_authority_test pins: track the 2026-07-05 ground-truth refresh (cursor RC) + repoint pre-existing-stale charter-adjacency pin witness_b_ordered_interleaving pinned the pre-refresh prose (Ground truth 2026-07-01 date + old walls sentence); updated to the refreshed authority. Also fixed a pin this PR did NOT stale: the charter->core-design-rule adjacency has been red on main since [host-converge inventory] was appended after [charter] — repointed to the real paragraph tail. Discriminator date kept in lockstep. All pins verified against the regenerated ROADMAP.md (byte-identical projection). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2 tasks
briansrls
added a commit
that referenced
this pull request
Jul 5, 2026
Exclude generated-artifact carriers (.gitignore, README/CLAUDE/ DESIGN symlinks) whose drift guard is floor-resident (#6236 class). Aligns with Ruling 1 path grain; 6277 audit paths under docs/ still shortcut once .gitignore hand-edit is moved to gitignore_authority. Co-authored-by: Cursor <cursoragent@cursor.com>
6 tasks
briansrls
added a commit
that referenced
this pull request
Jul 11, 2026
…6473) Review 37033: carry-path allowlisting of ci_spec.dag, ci.yml, and the ci_spec witness inverted the #6236 floor-resident guard — a PR editing the shortcut substrate could skip the witnesses that catch it. Allowlist is now docs/* + dag/gunbc/plans/* only; compile-clean pre-pass and $ROOT-absolute invoke retained. Revert cli_run workspace_root scaffold and ci_layer_roots rooted helper to follow-up PR. Co-authored-by: Cursor <cursoragent@cursor.com>
2 tasks done
briansrls
added a commit
that referenced
this pull request
Jul 11, 2026
Run 29151169700 @ 5b3eca1 hit the 60m step cap mid batch-2 discovery corpus (compile-clean green, no witness FAIL). CI-substrate PRs cannot use the plan-artifact shortcut (#6236); raise floor step + job backstop (180→240m) with receipt so this one-time merge can complete. Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
added a commit
that referenced
this pull request
Jul 11, 2026
Runs 29151169700 and 29153190481 hit 60m/90m floor step caps mid batch-2 discovery (compile-clean green, no witness FAIL; ~82m silent hang post- lens_verdict). CI-substrate files expand the affected set and cannot self- shortcut (#6236). Revert ci_spec/shortcut/cross-runner/timeout to main so this PR diff is plan authority + projections only; CI infra lands follow-up. Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Expands DESIGN.md §5 with a detailed analysis of the "absorbing fallback" anti-pattern — a subtle failure mode where mechanisms degrade to superset answers (rerun everything, scan all keys, always run) instead of refusing, masking deficits and deferring corpus-denominated costs until budget breaks. Adds this pattern to the recurring failure modes list and integrates it into the enforcement intent open thread.
Key Changes
New §5 subsection on absorbing fallbacks: Explains how ⊤-as-answer conflates with ⊤-as-ignorance on the answer lattice, destroying the signal that precise mechanisms have deficits. Shows how masked costs displace nothing and compound anemia, and how confidence thresholds that select such arms are smuggled heuristics in a closed system.
Live example from codebase: Documents
floor_witness_run_dispositioninsrc/v2/workflow/affected_set_floor_runner.dag:122-130as a concrete instance — arms returningRunWitnesswith "empty diff — run full corpus (fail-closed)" that are enshrined in tests, surfacing corpus-denominated cost as CI's 90-minute timeout rather than a diagnostic.Updated recurring failure modes list: Adds "absorbing fallback" as a named pattern with its key symptoms (widening failure arms, ⊤-conflation, zeroed deficit frequency, corpus-denominated cost breaking budget later).
Enforcement intent refinement: Adds "a failure arm must refuse, never widen — no absorbing fallbacks, §5" to the standing directives the operator repeatedly enforces by hand, positioning it for mechanization via
StandingIntentrows.Notable Details
Distinguishes absorbing fallbacks from two legitimate neighbors: structural over-approximations computed as the answer (precision frontier, not absorption), and deliberate interim fallbacks that are loud, budget-bounded, and land with dissolution triggers.
Connects the pattern to §6 complexity pricing: a masked cost displaces nothing and never ranks for fixing, compounding the anemia.
Frames the rule as a review tell: a failure arm must refuse, never widen — every degradation a typed, located, countable diagnostic.
https://claude.ai/code/session_01N8eqUhkbcosvSCUJNTm6pe