Skip to content

Document absorbing fallback trap and enforcement intent - #6236

Merged
briansrls merged 2 commits into
mainfrom
claude/design-degradation-patterns-wph241
Jul 4, 2026
Merged

briansrls merged 2 commits into
mainfrom
claude/design-degradation-patterns-wph241

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Expands DESIGN.md §5 with a detailed analysis of the "absorbing fallback" anti-pattern — a subtle failure mode where mechanisms degrade to superset answers (rerun everything, scan all keys, always run) instead of refusing, masking deficits and deferring corpus-denominated costs until budget breaks. Adds this pattern to the recurring failure modes list and integrates it into the enforcement intent open thread.

Key Changes

  • New §5 subsection on absorbing fallbacks: Explains how ⊤-as-answer conflates with ⊤-as-ignorance on the answer lattice, destroying the signal that precise mechanisms have deficits. Shows how masked costs displace nothing and compound anemia, and how confidence thresholds that select such arms are smuggled heuristics in a closed system.

  • Live example from codebase: Documents floor_witness_run_disposition in src/v2/workflow/affected_set_floor_runner.dag:122-130 as a concrete instance — arms returning RunWitness with "empty diff — run full corpus (fail-closed)" that are enshrined in tests, surfacing corpus-denominated cost as CI's 90-minute timeout rather than a diagnostic.

  • Updated recurring failure modes list: Adds "absorbing fallback" as a named pattern with its key symptoms (widening failure arms, ⊤-conflation, zeroed deficit frequency, corpus-denominated cost breaking budget later).

  • Enforcement intent refinement: Adds "a failure arm must refuse, never widen — no absorbing fallbacks, §5" to the standing directives the operator repeatedly enforces by hand, positioning it for mechanization via StandingIntent rows.

Notable Details

  • Distinguishes absorbing fallbacks from two legitimate neighbors: structural over-approximations computed as the answer (precision frontier, not absorption), and deliberate interim fallbacks that are loud, budget-bounded, and land with dissolution triggers.

  • Connects the pattern to §6 complexity pricing: a masked cost displaces nothing and never ranks for fixing, compounding the anemia.

  • Frames the rule as a review tell: a failure arm must refuse, never widen — every degradation a typed, located, countable diagnostic.

https://claude.ai/code/session_01N8eqUhkbcosvSCUJNTm6pe

claude and others added 2 commits July 4, 2026 20:09
…sed fail-open)

A failure arm that answers uncertainty by widening scope (rerun everything,
scan all keys, always run) is not fail-closed: it conflates ⊤-as-answer with
⊤-as-ignorance, zeroes the deficit's observable frequency by construction,
and denominates its cost in the corpus instead of the change — so the budget
breaks later instead of the build failing loudly now. Rule for review: a
failure arm must refuse, never widen; every degradation a typed, located,
countable diagnostic. Fences the two legitimate neighbors (structural
over-approximation computed as the answer; loud budget-bounded interim
fallback with a dissolution trigger). Receipt: floor_witness_run_disposition's
FailClosed→RunWitness arms and the 90-min CI timeout they produced. Also adds
the failure-modes list entry and the enforcement-intent standing directive.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N8eqUhkbcosvSCUJNTm6pe
@briansrls
briansrls merged commit 9120555 into main Jul 4, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the claude/design-degradation-patterns-wph241 branch July 4, 2026 21:40
briansrls added a commit that referenced this pull request Jul 4, 2026
…uditOnly demotion, live meta-gate CI consumer (E0 / PR-0a)

The complexity.repo-wide governance layer (#6167 A-C) consumed hand-authored
CoverageReceipt data rows - receipts-by-declaration, the exact §5
edit-the-declaration trap the enforcement-intent design §12 forbids. This PR
makes the receipts DERIVED IN-PASS by execution and gives the meta-gate its
first live consumer:

- receipts.dag (new): discovered_subjects from live decl_facts over the whole
  corpus; consumer_observed derived by READING commit_gate_roster projections
  (contract binds its witness via ConsumerWitnessBinding/ScheduleWitnessEntry;
  the roster stays the single enrollment authority); red_control_status by
  RUNNING the malformed-Loop probe through cost_lens in-pass;
  self_application derived from the discovered set; SubjectJudgment =
  BodyJudged | BodyUnavailable (typed, counted - #6236 discipline; totality
  judged + unavailable == fn_items asserted by execution).
- hand rows receipt_cost/receipt_complexity/coverage_receipt_registry DELETED;
  probed_at/Timestamp deleted (derivation-in-pass makes staleness unwritable).
- lens_contract_cost DEMOTED Blocking -> AuditOnly (anti-overcomplication
  rule: the gate now PROVES the Blocking claim false - derived consumer is
  WitnessOnly). Named re-promotion trigger on the row.
- gate.dag: find_answering_contract matches by property only; mode-satisfaction
  becomes the claimed leg (demotion keeps per-leg diagnostics).
- standing_intent.dag: whole_corpus_scope "dsl" -> "dag" - the dead root was
  SILENTLY dropping a third of the corpus through the tolerant walk (the exact
  silent-narrowing this gate exists to kill); per-root sentinels now guard it.
  required_subjects grounded to the real qualified name
  v1.compiler.infer.build_type_env.
- enforcement_live.dag (new, workflow layer): the live join - one decl_facts
  walk per check, receipts derived per contract from the registry fold.
- enforcement_live_witness_test.dag (new): 2 CI-ENROLLED fns (commit_gate_roster
  row added) - enforcement_consistency_gate_holds (Blocking: a Blocking claim
  without a live consumer reds) and complexity_repo_wide_verdict_matches_roadmap
  (the 6-leg verdict PINNED: claimed RED, scope RED w/ TRUE fn-body-reflection
  reason, subjects GREEN, consumer RED, red_control GREEN, self_application
  GREEN - any drift in either direction reds until the expectation is updated:
  roadmap-as-executable). Plus 8 local red controls/sentinels: roster-read both
  directions, empty-facts feed reds subjects, red-control-of-the-red-control,
  self-application liveness, skeleton->BodyUnavailable absorbing-fallback
  control, totality, per-root sentinels, and the all-body-unavailable pin.

Receipts by execution (2026-07-04, this container):
- step-0: decl_facts over [dag, src/v1, src/v2] finds all three sentinels incl.
  v1.compiler.infer.build_type_env; one walk ~9-10s; fn_item_count = 14283;
  body_unavailable == 14283 (the honest pin - skeletons only until the v2
  front-end ingest lane lands bodies).
- all 10 gate_test synthetic witnesses green; all 10 enforcement_live witnesses
  green; enrolled pair ~40s each interpreted.
- live R1 evidence: the step-0 counts probe using decl_facts_fn_items
  (fold + list_snoc_item) burned 3m41s - the accumulator-in-copied-port
  quadratic the E2 object rule will wall; new derivations are linear.
- KNOWN FORK BITE, worked around with a dissolve marker: importing any
  dag-tree module (std.realization_schedule via gunbc.commit_workflow) into a
  v2 entry closure breaks bare imported Empty/Cons at runtime (undefined
  variable: Empty - the dag<->v2 algebra fork, ROADMAP pillar-1, LIVE
  fail-open). List construction in the enforcement modules uses [] literals +
  list_append(left: [x], right: acc) until the algebra de-fork lands
  (freemonoid_constructor_avoidance_note carries the trigger).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…uditOnly demotion, live meta-gate CI consumer (E0) (#6238)

* WIP: complexity lens enforcement

* WIP: complexity lens enforcement

* WIP: complexity lens enforcement

* Enforcement receipts by execution: derived CoverageReceipts, honest AuditOnly demotion, live meta-gate CI consumer (E0 / PR-0a)

The complexity.repo-wide governance layer (#6167 A-C) consumed hand-authored
CoverageReceipt data rows - receipts-by-declaration, the exact §5
edit-the-declaration trap the enforcement-intent design §12 forbids. This PR
makes the receipts DERIVED IN-PASS by execution and gives the meta-gate its
first live consumer:

- receipts.dag (new): discovered_subjects from live decl_facts over the whole
  corpus; consumer_observed derived by READING commit_gate_roster projections
  (contract binds its witness via ConsumerWitnessBinding/ScheduleWitnessEntry;
  the roster stays the single enrollment authority); red_control_status by
  RUNNING the malformed-Loop probe through cost_lens in-pass;
  self_application derived from the discovered set; SubjectJudgment =
  BodyJudged | BodyUnavailable (typed, counted - #6236 discipline; totality
  judged + unavailable == fn_items asserted by execution).
- hand rows receipt_cost/receipt_complexity/coverage_receipt_registry DELETED;
  probed_at/Timestamp deleted (derivation-in-pass makes staleness unwritable).
- lens_contract_cost DEMOTED Blocking -> AuditOnly (anti-overcomplication
  rule: the gate now PROVES the Blocking claim false - derived consumer is
  WitnessOnly). Named re-promotion trigger on the row.
- gate.dag: find_answering_contract matches by property only; mode-satisfaction
  becomes the claimed leg (demotion keeps per-leg diagnostics).
- standing_intent.dag: whole_corpus_scope "dsl" -> "dag" - the dead root was
  SILENTLY dropping a third of the corpus through the tolerant walk (the exact
  silent-narrowing this gate exists to kill); per-root sentinels now guard it.
  required_subjects grounded to the real qualified name
  v1.compiler.infer.build_type_env.
- enforcement_live.dag (new, workflow layer): the live join - one decl_facts
  walk per check, receipts derived per contract from the registry fold.
- enforcement_live_witness_test.dag (new): 2 CI-ENROLLED fns (commit_gate_roster
  row added) - enforcement_consistency_gate_holds (Blocking: a Blocking claim
  without a live consumer reds) and complexity_repo_wide_verdict_matches_roadmap
  (the 6-leg verdict PINNED: claimed RED, scope RED w/ TRUE fn-body-reflection
  reason, subjects GREEN, consumer RED, red_control GREEN, self_application
  GREEN - any drift in either direction reds until the expectation is updated:
  roadmap-as-executable). Plus 8 local red controls/sentinels: roster-read both
  directions, empty-facts feed reds subjects, red-control-of-the-red-control,
  self-application liveness, skeleton->BodyUnavailable absorbing-fallback
  control, totality, per-root sentinels, and the all-body-unavailable pin.

Receipts by execution (2026-07-04, this container):
- step-0: decl_facts over [dag, src/v1, src/v2] finds all three sentinels incl.
  v1.compiler.infer.build_type_env; one walk ~9-10s; fn_item_count = 14283;
  body_unavailable == 14283 (the honest pin - skeletons only until the v2
  front-end ingest lane lands bodies).
- all 10 gate_test synthetic witnesses green; all 10 enforcement_live witnesses
  green; enrolled pair ~40s each interpreted.
- live R1 evidence: the step-0 counts probe using decl_facts_fn_items
  (fold + list_snoc_item) burned 3m41s - the accumulator-in-copied-port
  quadratic the E2 object rule will wall; new derivations are linear.
- KNOWN FORK BITE, worked around with a dissolve marker: importing any
  dag-tree module (std.realization_schedule via gunbc.commit_workflow) into a
  v2 entry closure breaks bare imported Empty/Cons at runtime (undefined
  variable: Empty - the dag<->v2 algebra fork, ROADMAP pillar-1, LIVE
  fail-open). List construction in the enforcement modules uses [] literals +
  list_append(left: [x], right: acc) until the algebra de-fork lands
  (freemonoid_constructor_avoidance_note carries the trigger).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 5, 2026
…e model)

#6236 landed the absorbing-fallback section by editing DESIGN.md directly;
the generated-artifact model never learned it. Undetected because the drift
gate produced no verdict since 2026-07-01 (the blackout this branch repairs).
Oracle: wet regen must reproduce committed DESIGN.md byte-identically.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…ng fallback) into design_document.dag + regen ROADMAP.md (#6264)

The composed floor's batch-2 GeneratedArtifactDriftGate has been RED on main:
generated_artifact_drift_gate_passes -> false (verified on pristine
origin/main a44b3b4), stopping the floor before dependent batches for
every lane.

Root cause, with a direction control on each artifact (drift direction is
NOT always authority->projection):

- DESIGN.md: #6236 landed the operator-signed section-5 absorbing-fallback
  trap by editing DESIGN.md DIRECTLY - the generated projection - without
  its authority dag/gunbc/design_document.dag. A blind main_wet regen would
  have DELETED the signed content. Fix direction: back-port the three
  drifted spots verbatim into the authority (trap paragraph, extended e.g.
  bullet, recurring-failure-modes entry, enforcement-intent thread clause).
  Oracle: after the back-port, main_wet reproduces committed DESIGN.md
  byte-identically (it does not appear in the regen diff).
- ROADMAP.md: the authority row gained "(#6105)" wording while the committed
  projection was stale. Fix direction: regen (one line).

Receipt: generated_artifact_drift_gate_passes -> true by execution after
this commit. The gate did its job; the ironic part - the document that says
model-before-implement was hand-edited around its own model - is exactly the
class the enforcement-intent lane exists to make unwritable.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 5, 2026
…port #6236 into the DESIGN model) (#6263)

* CI budget breach is a step-level FAILURE, never job-cancellation silence (operator ruling 2026-07-05)

Any timed-out gate is a failure, not a silent pass — no verdict == failure.
The 10-min job-kill (2026-07-04) produced conclusion=cancelled, which every
consumer treated as not-red: 29 of 30 main runs cancelled since the last
green (2026-07-01T01:00Z), four days of merges with zero gate verdicts,
two latent reds entering unseen. Budget moves to step-level timeout-minutes
(step fails RED, logs + [t+Xs] phase marks intact), value 30 derived from
last-green duration (27min) + margin — re-derive downward as resolver work
lands. Job-level timeout becomes a +5 backstop whose firing means the
failure mechanism itself wedged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Port #6236's carrier-only DESIGN.md edit into design_document.dag (the model)

#6236 landed the absorbing-fallback section by editing DESIGN.md directly;
the generated-artifact model never learned it. Undetected because the drift
gate produced no verdict since 2026-07-01 (the blackout this branch repairs).
Oracle: wet regen must reproduce committed DESIGN.md byte-identically.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Backstop must exceed prelude + max step budget; budget every gate-bearing step

cursor review finding (valid): step timeouts start at step start, so a
policy+5 backstop measured from job start could job-cancel (silence)
before the gate step fails red whenever prelude runs long - resurrecting
the exact silent-pass defect. Backstop is now policy+30 (above worst-case
honest prelude + the 30-min gate budget) and the merge-admission,
nextest-install, and cgroup steps carry their own 10-min step budgets, so
every post-prelude phase fails RED; the backstop fires only on a wedged
prelude, which the disposition names a mechanism bug, never a gate verdict.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Budgets stay short per operator ruling: floor 10, rust gate 15, aux 5

Operator (2026-07-05): keep timeouts short - 10 minutes is long enough,
15 at most for rust_tests. The forcing function survives with honest
semantics: breach = step-level FAILURE with [t+Xs] phase attribution.
Per-job backstops = step-budget sum + prelude allowance (ci 20,
rust_tests 30), reachable only via wedged prelude. Until resolver work
fits the floor in 10 minutes, main runs red-by-failure: a countable
deficit signal, not cancelled silence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 5, 2026
…ap receipts refresh (1667-error fresh-emit receipt) (#6253)

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* Drop get-form revert per operator collision resolution (#6255 owns the get arm); regen ROADMAP projection

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: continue work on v1 burn down

* WIP: continue work on v1 burn down

* Fix roadmap_authority_test pins: track the 2026-07-05 ground-truth refresh (cursor RC) + repoint pre-existing-stale charter-adjacency pin

witness_b_ordered_interleaving pinned the pre-refresh prose (Ground truth 2026-07-01 date + old walls sentence); updated to the refreshed authority. Also fixed a pin this PR did NOT stale: the charter->core-design-rule adjacency has been red on main since [host-converge inventory] was appended after [charter] — repointed to the real paragraph tail. Discriminator date kept in lockstep. All pins verified against the regenerated ROADMAP.md (byte-identical projection).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot mentioned this pull request Jul 5, 2026
2 tasks
briansrls added a commit that referenced this pull request Jul 5, 2026
Exclude generated-artifact carriers (.gitignore, README/CLAUDE/
DESIGN symlinks) whose drift guard is floor-resident (#6236 class).
Aligns with Ruling 1 path grain; 6277 audit paths under docs/ still
shortcut once .gitignore hand-edit is moved to gitignore_authority.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…6473)

Review 37033: carry-path allowlisting of ci_spec.dag, ci.yml, and the
ci_spec witness inverted the #6236 floor-resident guard — a PR editing
the shortcut substrate could skip the witnesses that catch it. Allowlist
is now docs/* + dag/gunbc/plans/* only; compile-clean pre-pass and
$ROOT-absolute invoke retained. Revert cli_run workspace_root scaffold
and ci_layer_roots rooted helper to follow-up PR.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
Run 29151169700 @ 5b3eca1 hit the 60m step cap mid batch-2 discovery
corpus (compile-clean green, no witness FAIL). CI-substrate PRs cannot
use the plan-artifact shortcut (#6236); raise floor step + job backstop
(180→240m) with receipt so this one-time merge can complete.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
Runs 29151169700 and 29153190481 hit 60m/90m floor step caps mid batch-2
discovery (compile-clean green, no witness FAIL; ~82m silent hang post-
lens_verdict). CI-substrate files expand the affected set and cannot self-
shortcut (#6236). Revert ci_spec/shortcut/cross-runner/timeout to main so
this PR diff is plan authority + projections only; CI infra lands follow-up.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants