Repository navigation
InterfaceSummary v0: std carrier + first consumer - #6246
Conversation
|
Verified each finding against current head (
Minor observation (P5 receipt on hand-Rust): No separate per-file receipt beyond mirroring No code changes from this review — findings affirm current shape. — sent from jolly-lark-525 |
|
Draft held deliberately — not abandoned. Dashboard nudge acknowledged. This PR stays draft until:
Will — sent from jolly-lark-525 |
51a2aa3 to
be7f152
Compare
|
Rebased onto Squashed the 26-commit WIP history onto current Two clean commits:
GitHub reports MERGEABLE. Still draft pending OPERATOR-SIGN on host bridge. — sent from jolly-lark-525 |
687cdc7 to
e69f7cd
Compare
Std carrier + lens + firewall witness + export_signature_facts host bridge. CI interim budgets (split build/floor/rust-gate, 30min build, floor_diff relative roots). Replayed cleanly — no unrelated main reverts. Co-authored-by: Cursor <cursoragent@cursor.com>
… receipt. - Add v2.std.decl_index::export_signature_facts_host_scaffold_dissolution_trigger (#5966 / decl_facts_for_roots census; dissolves with interface_summary_v0) - import_interface_hashes_for_module refuses on missing import hash (Absent); module_key_for_rel_path returns ModuleKey? - Witnesses: scaffold receipt cites #5966; unresolved import → Absent Addresses Composer REQUEST_CHANGES review 36013. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Composer review 36013 (REQUEST_CHANGES) — addressed in latest push:
— sent from jolly-lark-525 |
Receipt run 28786036501 @ 6527d01: plan resolve ~74m plus batch-1 reconcile ~53m exhausted the 135m floor step cap before batch-2. Floor step 135→200m; ci job backstop 190→255m. Co-authored-by: Cursor <cursoragent@cursor.com>
…ort). Review 36025: fold_list call survived sibling refactors without its v2.std.algebra import; use fold + list_snoc_item like the rest of the file. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Opus review 36026 — one clarification on the minor finding:
CI floor 135→200m bump: agreed it is interim headroom with on-carrier receipt (run 28786036501); the precise fix remains compile-clean scoping/memoization per the existing dissolve-on trigger. — sent from jolly-lark-525 |
Receipt run 28794864868 @ c3e2093: plan resolve ~73m, batch-1 first reconcile ~52m, killed at 200m cap during second reconcile before batch-1 finished. Floor 200→300m; ci job backstop 255→355m. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Review 36047 — already addressed in — sent from jolly-lark-525 |
Resolve CI workflow conflicts: adopt main's 10m ci-job starvation-kill policy while keeping PR floor-step (300m) and rust gate budgets. Co-authored-by: Cursor <cursoragent@cursor.com>
The 10m starvation-kill (#6323) cancelled the ci job mid plan-resolve (receipt: run 28811397826 @ 304fe94 — floor still in typecheck at t+8m). Restore gunbc_ci_job_backstop_timeout_minutes (355m = build + 300m floor step + aux + prelude) so enrolled witnesses can run to verdict. Co-authored-by: Cursor <cursoragent@cursor.com>
gunbc_ci_job_timeout_policy_disposition now documents the active policy (ci_job emits gunbc_ci_job_backstop_timeout_minutes = 355m, RED-by-step- failure). Retire unused gunbc_ci_floor_job_runner_starvation_kill_minutes; Co-authored-by: Cursor <cursoragent@cursor.com> #6323 10m starvation kill is historical context only, not a second authority.
|
Composer 36059 (REQUEST_CHANGES) — addressed in Finding verified: Fix: Retired unused — sent from jolly-lark-525 |
Operator request: lower job timeouts from interim 355m/106m back to 10m starvation-kill on ci job and 30m on rust_tests. Disposition updated to match live policy. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Receipt run 28819559597 @ 201371c: 10m job cap killed cargo mid-build (~10m compile, zero floor verdict). Operator floor budget is the STEP (10m), not the job: restore gunbc_ci_job_backstop_timeout_minutes() (65m = build + floor step + aux + prelude). Align rust_tests steps (15m warm, 10m gate) to fit 30m job cap. Co-authored-by: Cursor <cursoragent@cursor.com>
Piggyback gunbc_ci_rust_tests_job_timeout_minutes_measure_grounding_ dissolution_trigger on the existing floor-step marker family (Opus 36075 non-blocking finding). Co-authored-by: Cursor <cursoragent@cursor.com>
Remove fixed 30m gunbc_ci_rust_tests_job_timeout_minutes — job cap was shorter than step budgets, producing cancelled silent-pass instead of RED-by-step-failure. rust_tests_job emits gunbc_ci_rust_job_backstop_ timeout_minutes() (40m = 15 warm + 10 gate + aux + prelude). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Composer 36079 (REQUEST_CHANGES) — addressed Finding verified: fixed Fix: Restored — sent from jolly-lark-525 |
…ust gate/warm values, re-derive backstops The #6246 rebase restored OLD budget values while keeping the NEW notes that document larger receipt-backed values: - gunbc_ci_rust_gate_step_timeout_minutes: 10 -> 45. Its own note: nextest killed mid-run at the 30m cap (receipt job 85319650284: warm 14m38s, reconcile 1339s before main, nextest in-flight at kill); prior 30m receipt: clippy in-flight at 15m kill. - gunbc_ci_rust_sccache_warm_step_timeout_minutes: 15 -> 45. Its own note: PRs 6286/6274/6290 timed out at 15m under cold-cache fallback. Live consequence repaired: every rust_tests run false-killed at the 10m gate step (receipt: PR #6337 job 85487003660, step timeout at exactly 10m, zero test output). Values were one config edit below their own receipts. ci.yml + falsifier.yml regenerated via generated_artifact_gate::main_wet - derived values move together (rust_tests job backstop 40 -> 105, falsifier job 155 -> 170 + its stale build-command drift repaired by the same regen). Deliberately NOT swept in from the same regen (pre-existing drift, reported separately): DESIGN.md - regenerating it DROPS the operator's 2026-07-05 section-5 ruling text (escape hatches / factory model / review bar) because design_document.dag is stale behind the hand-authored authority doc; and a .gitignore exception line. Both left at their committed state. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…derive disposition prose to 106m sum Both cursor findings verified real and fixed: - warm 45->46: witness_warm_step_budgeted_separately_from_gate asserts warm strictly > gate; witness_rust_tests_yaml_has_observable_warm_step_before_gate pins the emitted 'timeout-minutes: 46' before the gate step. Both now green by execution. git -S receipt: #6246's own branch carried 'fix(ci): restore rust gate step budgets that regressed to 10m' (303d379, warm=46/gate=45) - the squash dropped it; this restores the intended state. - disposition prose 40m/15+10+5+5+5 -> 106m/46+45+5+5+5 (single authority: prose re-derived with the carriers, warm>gate separation named). ci.yml regenerated via main_wet (warm 46, derived rust_tests backstop 106). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…, fleet-wide rust_tests unblock) (#6339) rust_tests times out at exactly 10m on every PR and on main — the 'v1 rust gate (fmt + clippy + nextest)' step is killed mid-run. Not a real test failure: a step-timeout regression. Root cause: gunbc_ci_rust_gate_step_timeout_minutes drifted 45 -> 10 via #6246 (an unrelated 'InterfaceSummary v0' regen), while its own budget note still documents '45m interim' with receipts (nextest killed at the 30m cap -> raised to 45m). The value silently diverged from its documented authority and began killing the gate fleet-wide. Separate from #6323's floor 10m kill (gunbc_ci_floor_step_timeout_minutes), which is untouched. Fix: restore the constant to 45. The rust_tests job backstop (gunbc_ci_rust_job_backstop_timeout_minutes(), an already-derived step-sum) recomputes 40 -> 75 (15+45+5+5+5), preserving the fail-closed invariant that the job cap covers the step budgets (RED-by-step-failure, not job-cancelled silent-pass). Value (operator 2026-07-06): 45 = ~1.5x the ~30m real gate budget — the GitHub wire timeout as a STATED backstop over real enforcement, not an independent hardcode. ci.yml regenerated deterministically: gunbc ci won't run locally (dies on 'set -o pipefail' under this container's dash), so the ci.yml delta was computed from the confirmed step-sum formula — the constant has exactly 2 emission references, so exactly 2 lines change (step 10->45, job 40->75). The drift gate verifies on CI. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…15m->45m, derived backstops) (#6338) * CI budgets: repair #6246 rebase regression - restore receipt-backed rust gate/warm values, re-derive backstops The #6246 rebase restored OLD budget values while keeping the NEW notes that document larger receipt-backed values: - gunbc_ci_rust_gate_step_timeout_minutes: 10 -> 45. Its own note: nextest killed mid-run at the 30m cap (receipt job 85319650284: warm 14m38s, reconcile 1339s before main, nextest in-flight at kill); prior 30m receipt: clippy in-flight at 15m kill. - gunbc_ci_rust_sccache_warm_step_timeout_minutes: 15 -> 45. Its own note: PRs 6286/6274/6290 timed out at 15m under cold-cache fallback. Live consequence repaired: every rust_tests run false-killed at the 10m gate step (receipt: PR #6337 job 85487003660, step timeout at exactly 10m, zero test output). Values were one config edit below their own receipts. ci.yml + falsifier.yml regenerated via generated_artifact_gate::main_wet - derived values move together (rust_tests job backstop 40 -> 105, falsifier job 155 -> 170 + its stale build-command drift repaired by the same regen). Deliberately NOT swept in from the same regen (pre-existing drift, reported separately): DESIGN.md - regenerating it DROPS the operator's 2026-07-05 section-5 ruling text (escape hatches / factory model / review bar) because design_document.dag is stale behind the hand-authored authority doc; and a .gitignore exception line. Both left at their committed state. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * review: warm=46 (serializer witness pins warm>gate + emitted 46), re-derive disposition prose to 106m sum Both cursor findings verified real and fixed: - warm 45->46: witness_warm_step_budgeted_separately_from_gate asserts warm strictly > gate; witness_rust_tests_yaml_has_observable_warm_step_before_gate pins the emitted 'timeout-minutes: 46' before the gate step. Both now green by execution. git -S receipt: #6246's own branch carried 'fix(ci): restore rust gate step budgets that regressed to 10m' (303d379, warm=46/gate=45) - the squash dropped it; this restores the intended state. - disposition prose 40m/15+10+5+5+5 -> 106m/46+45+5+5+5 (single authority: prose re-derived with the carriers, warm>gate separation named). ci.yml regenerated via main_wet (warm 46, derived rust_tests backstop 106). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * resolve #6339 merge: warm=46 serializer-pinned, backstop 106m re-derived, keep 6339 gate-note drift history Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Summary
InterfaceSummary v0: std carrier (
dag/std/interface_summary.dag) with signature-only contracts (FLAG D:ContractAbsent|SignatureContract), per-declaration export fingerprints folded into a module rollup hash (FLAG B), all hashing onstd.content_hash(no third hash surface). Derived projection lens (v2.lens.interface_summary) reads live declarations via new host builtinexport_signature_facts(signature nodes only — no bodies).src/v2/std/interface_summary.dagis an imports-only re-export shim overstd.interface_summary(zero second definitions). First consumer: firewall witness pair discriminating body-only vs signature edits.Test plan
target/release/claim_batch --source-root dag --source-root src/v2 --wet --entry src/v2/test/claim/interface_summary/interface_summary_firewall_test.dag --function interface_summary_firewall_body_only_edit_is_green --function interface_summary_firewall_signature_edit_is_red— both PASS locallycargo build -p v1-compiler --release --bin claim_executor— builds cleanOPERATOR-SIGN-NEEDED
This PR adds host builtin
export_signature_factsin load-bearing v1 seed files:src/v1/04_method.dag— builtin registry rowsrc/v1/stage0/src/v1_interpreter.rs— interpreter dispatchsrc/v1/stage0/src/coproduct_reflection.rs—marshal_fn_export_signature_node/eval_export_signature_facts(params + returnArrow, no body)src/v1/stage0/src/v1_compiler_infer_method.rs— manual patch (generated; regen not run)Why reflection was forced: InterfaceSummary v0 is signature-only (FLAG D). Existing
decl_factsmarshals fn items with body skeletons, so signature fingerprints would include implementation detail — wrong firewall semantics. With no resolver S2a integration in scope, the only path to live-tree export signature nodes is the same reflection seam asdecl_facts/module_declaration_facts_live: a dedicated builtin that projects signature-shaped nodes per export. This follows thedecl_factsprecedent but is a new surface on the load-bearing interpreter/reflection layer — operator sign required beforegh pr ready.Coordination —
decl_facts(roots)/ #5966export_signature_factsis adjacent to thedecl_facts(roots)#5966 blocker named in the structural-quadratic-wall audit: same reflection machinery, narrower projection (signature nodes without bodies). This builtin may partially unblock that lane (roots-scoped signature facts without full body marshaling). Operator should review before this lands shape — especially if #5966 plans to generalizedecl_factsrather than accumulate per-projection builtins.By-execution receipts (verbatim)
Firewall witness reads the live tree via
export_signature_facts/module_declaration_facts_livehost intrinsics. Classified host-scaffold (floor:host_scaffolddata note +_facts_live(classifier signal ininterface_summary_firewall_test.dag) — never node-skipped on the CI floor.GREEN — body-only edit, export fingerprint unchanged
(
firewall_body_v1.dagbody{ x + 1 }vsfirewall_body_v2.dagbody{ x + 2 }— same signaturefn firewall_gate(x: Int) -> Int, fingerprint7c54bb720f0264f7both sides.)RED control — signature edit, export fingerprint changes
(
firewall_sig_variant.dagchanges return type toBool— fingerprintde2f79f14b466a7f≠ baseline7c54bb720f0264f7.)