Repository navigation
affected set processing - #6453
Conversation
…l hermeticity) The control bin injected only the unified-diff channel (GUNBC_CI_DIFF_UNIFIED); the name-status channel fell through to the REAL checkout diff, so the divergence control read a mix of fixture (unified) and working-tree (name-status) state — non-hermetic. Inject GUNBC_CI_DIFF_NAME_STATUS at both run_injected_diff_roster helpers, coherent with each unified hunk: a single-file modify, "M" NUL path NUL. Format verified against the git.dag parser (git_diff_name_status_advance splits on from_code_point(0), reads status-token then path-token, skips empties). The .dag override already exists (floor_diff_observe.dag printf injection); this only makes the bin SET the var. The BASE/HEAD real-git failure-path sites are left untouched deliberately. Part of the :5426 absorbing-fallback fix (loyal-wren-398 lane): the divergence control must be hermetic to be a clean standing regression guard. Greens with the widen-arm rewire on this branch. Compiles clean (cargo check, this commit). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
CI receipt for run 29129931005 @ b2bfb16: rust_tests PASS (5m19s), ci_regen PASS (4m58s — the new build line incl. floor_skip_discovery_witness works on CI), ci job RED with the pre-existing post-flip class, not this PR's changes. Anatomy from the job log: the affected-set selection is live and delivering (long runs of |
…den (#6453 added floor_skip_discovery_witness) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…b) (#6466) * WIP: ci floor measurement * WIP: ci floor measurement * WIP: ci floor measurement * Remove scratch probe test auto-committed into the branch A temporary red probe (union_resolve_receipts_test.rs) used to characterize the width==1 typecheck-compute-counter semantics was captured by the auto-committer in 533e473 while it sat in the working tree. It asserts a deliberate RED, so it fails rust_tests. It was never intended to land. Restores the file to its state at 674381f. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci floor measurement * WIP: ci floor measurement * roster_closure_nodes: derive from resolved graphs, not the thread typecheck counter `typecheck_compute_count()` counts typecheck cache MISSES on the current thread and is never reset in production (only tests reset it), so it equals a closure size only from a cold start. The measurement window cannot assume that: - width == 1 returns `run_discovery_rows` on the discovery thread, which has already resolved every changed file via `floor_diff_edits_from_line_ranges` plus both prefix entries. The reported count was therefore |closure(changed files) u closure(prefix) u closure(rows)| -- a function of the diff under test, not of the roster. - `floor_skip_discovery_witness` calls run_discovery_corpus three times on one thread, so the 2nd and 3rd calls read a counter warmed by the 1st. Count the union of authored module names across the graphs the shard actually resolves (prefix contexts + each roster entry) instead. That is a property of the source closure: independent of cache warmth, resolve order, and the diff. Prefix modules stay counted -- they are resident for the shard's lifetime, so they belong in the memory pairing. Note the parallel path was never the problem: run_walk dispatches DiscoveryBatch via thread::spawn, so shards do start cold. The defect was the pre-row work on the discovery thread, which shards never repeat. Adds a discriminating control: a prior same-thread resolve moves the compute counter (asserted, so the control stays discriminating) but must not move the closure count. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci floor measurement * space-lens plan: fold in loyal-wren's systematic-kill correction (two knobs) The host OOM is systematic, not intermittent: a width==1 shard is killed by host-level oversubscription under its own slot cap, so narrowing width cannot help. The per-shard prediction therefore feeds TWO knobs — within-job width and cross-job packing/admission — and the systematic case is served by admission- refusal, not width. Records RSS-at-kill as a lower-bound calibration point. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci floor measurement * WIP: ci floor measurement * Remove rust_tests job from CI + RustMonolithGate/GithubActionsRustTestsJob coproduct variants Frees a runner slot and drops CI's largest memory job (~37 GiB). The v1 rust fmt+nextest gate was non-required and red on main (v1 seed being deleted, §7); formatting stays covered by the pre-push hook. Removes the job, its roster enrollment, the now-orphan Gate/surface coproduct variants and all their match arms, the dead gate-runner wrappers, and updates the placement-grain duplicate -computation flagship to the surviving 2 sibling jobs (still >1, still discharged). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci floor measurement * rust_tests removal: fix binding count (3->2) + stale build-verify golden (#6453 added floor_skip_discovery_witness) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Document rust-suite removal: declared Terminal rationale + no-return trigger at commit_gate_roster Addresses PR review (cursor/composer-2.5): records the v1 fmt+nextest removal as intentional with rationale (non-required + red on main, v1 seed being deleted §7, fmt stays on pre-push) and its no-return trigger, rather than a silent coverage drop. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…nchor scaffold receipt (#6500) * Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin Three content reds every completed floor now hits, all proven on clean main (the 60m-timeout and batch-2-panic masks are gone, so the content layer behind them is finally visible): 1. anchor_source_root panicked mid-floor on "dag/compiler" (run for PR #6497, cli_run.rs:365) - a DECLARED root from the medium-structure roster that does not exist on disk yet (modeled-before-implemented). The layer walk's own is_dir guard proves absence is a legitimate skip state there, but the anchorer panicked before the guard could run. New non-panicking try_anchor_source_root for declared-root walks: absence skips with a counted [layer-import] line (loud, never silent); CLI-provided roots keep the strict panicking contract. 2. affected_set_universe_gate_processes_match_declared_gates compared the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's slice (7) since the #6472 job split. The witness now unions floor+regen+emit_determinism (the same union its sibling witness_gate_roster_matches_coproduct_arms already used); probe receipt: the three slices partition the 10 arms exactly. 3. witness_floor_disposition_marker_initialized_before_docs_only_branch (landed in today's wave) pinned the stamp DIRECTLY adjacent to the docs-only branch, but the emitted script has a blank line between them - red on clean main from its first run. The pin now matches the emitted adjacency (stamp, blank, _ci_changed) and still proves the ordering it exists for. Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses, and the layering clean-tree witness green by execution with the fixed binary. Remaining known main reds (predate today, tracked separately): s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm), ci_deploy_witnesses. * ci_deploy witness: repin deploy invoke to the rooted source-root spelling witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted '--source-root dag' while gunbc_ci_deploy_invoke emits the rooted '--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453) - red on clean main, the third masked layer of the rooted-argv family (#6493 repinned the scheduler-argv pair). Proven by execution: suite false -> true on the repin, conjunct-bisected first. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch) Hand-Rust expansion now carries the DESIGN §7 shape the same file requires: authority rows (cli_run_source_root_anchor_scaffold sibling of the workspace-root scaffold, bind to the declaration), named dissolve-on (roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt anchor + counted loc delta, scaffold witnesses green by execution, and a discriminating unit pair (declared-present -> Some, declared-absent -> None). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
… Diagnostics coproduct (#6501) * Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin Three content reds every completed floor now hits, all proven on clean main (the 60m-timeout and batch-2-panic masks are gone, so the content layer behind them is finally visible): 1. anchor_source_root panicked mid-floor on "dag/compiler" (run for PR #6497, cli_run.rs:365) - a DECLARED root from the medium-structure roster that does not exist on disk yet (modeled-before-implemented). The layer walk's own is_dir guard proves absence is a legitimate skip state there, but the anchorer panicked before the guard could run. New non-panicking try_anchor_source_root for declared-root walks: absence skips with a counted [layer-import] line (loud, never silent); CLI-provided roots keep the strict panicking contract. 2. affected_set_universe_gate_processes_match_declared_gates compared the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's slice (7) since the #6472 job split. The witness now unions floor+regen+emit_determinism (the same union its sibling witness_gate_roster_matches_coproduct_arms already used); probe receipt: the three slices partition the 10 arms exactly. 3. witness_floor_disposition_marker_initialized_before_docs_only_branch (landed in today's wave) pinned the stamp DIRECTLY adjacent to the docs-only branch, but the emitted script has a blank line between them - red on clean main from its first run. The pin now matches the emitted adjacency (stamp, blank, _ci_changed) and still proves the ordering it exists for. Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses, and the layering clean-tree witness green by execution with the fixed binary. Remaining known main reds (predate today, tracked separately): s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm), ci_deploy_witnesses. * ci_deploy witness: repin deploy invoke to the rooted source-root spelling witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted '--source-root dag' while gunbc_ci_deploy_invoke emits the rooted '--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453) - red on clean main, the third masked layer of the rooted-argv family (#6493 repinned the scheduler-argv pair). Proven by execution: suite false -> true on the repin, conjunct-bisected first. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch) Hand-Rust expansion now carries the DESIGN §7 shape the same file requires: authority rows (cli_run_source_root_anchor_scaffold sibling of the workspace-root scaffold, bind to the declaration), named dissolve-on (roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt anchor + counted loc delta, scaffold witnesses green by execution, and a discriminating unit pair (declared-present -> Some, declared-absent -> None). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * s1_closure floor panic: wrapper-retained diagnostics must inhabit the Diagnostics coproduct body_lower_wrapper_retained_shell constructed Accepted with a RAW NonEmptyDiagnostics in the diagnostics field where the Diagnostics coproduct (None | Some) is declared - the first downstream match over Diagnostics (diagnostics_merge in the normalize child fold) panicked non-exhaustive on every file with a wrapper-retained fn body, killing the s1_closure witness whenever the affected set selected it. Fix wraps the singleton in Some. Reproduced red (exact CI panic) and green by execution via s1_file_parses on dag/std/error_primitives.dag; new witness pins the shape and returns false (no panic) on the raw form. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
… cost/routing work (#6489) * witness-cost-locality lens v0: one typed verdict for the two ambient-coupling axes (receipt-only) One law: witness cost must be denominated in its subject (the DESIGN 5 denomination law). Two detectable projections at module grain: DataBreadth (closure reaches an ambient-read carrier: filesystem_read callers + the decl_facts reflection home) and LayerDepth (closure spans >=2 compiler pipeline stages - the round-trip shape). Verdict algebra + census receipt + precision-frontier disclosures as data; six fixture witnesses incl. the single-stage boundary and a red control (law perturbed to >=1 flips single_stage_closure_stays_local red - receipted). Census 2026-07-11 over the 732-entry roster: Local 483 / LayerDepth 229 / DataBreadth 9 / both 11; derives the operator-ruled-offline enforcement rows and the execution/ exclusions; falsified two naive laws (decl_facts reflection invisible to filesystem_read grep; hermetic fixture rows over-flagged - the declared InputEnvelope is the override authority). LayerDepth is receipt-only until fn-grain call-graph reachability lands (ci_yaml counter-receipt: stage-type imports are not stage execution). Dissolve-on: fn-grain reachability + InputEnvelope declarations wired into floor admission; the witness_exclusion hand-rows and this v0 roster retire together. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Add the required construction_justification row (cursor review) WallAfterGrounding dissolving to SingleAuthority: the verdict is validation-tier until fn-grain reachability + InputEnvelope declarations let floor admission consume it, at which point non-Local rows are structurally absent from the per-PR plan (the single authority) and the lens dissolves per its precision-frontier note. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * [ITERATION-ONLY - REVERT BEFORE MERGE] Route CI to ubicloud runners Self-hosted fleet has no free slots (operator, 2026-07-11); route this PR's iteration to ubicloud-standard-16-arm so the lens work is not gated on fleet capacity. Same move as the #6107 -> #6111 precedent. gunbc_ci_runner_spec() returns the ubicloud label; the fleet derivation is preserved untouched as gunbc_ci_runner_spec_fleet_derived() and ubicloud_iteration_routing_note carries the revert obligation. Workflows regenerated from the authority via main_wet (drift gate stays coherent): runs-on [ubicloud-standard-16-arm] at ci.yml build_release/floor/emit-determinism and falsifier.yml. Revert = git revert this single commit + regen (or just revert; the regenerated ci.yml/falsifier.yml are included here). * Closure facts + per-PR admission law: the transitive-carrier case becomes provable, and verdict x envelope decides the lane Extends the v0 lens with the fact half its census note promised: - ModuleImportFact + import_closure: module-grain closure over declared import facts, the |E|-sweeps fixpoint shape sanctioned by v2.lens.affected_set (pass + frontier-stability + doubled-facts fuel, early-stable). Terminates on cyclic FACT rows - the substrate refuses cyclic imports, but the fold must not trust its input. - witness_cost_locality_from_facts: closes over the facts so the transitive carrier (the enforcement_live falsification - the corpus read two hops away) is provable in fixtures, not just prose. - WitnessInputEnvelope + per_pr_admission: the admission matrix (verdict x declared envelope), fail-closed with declaration-wins-when-stricter. DeclaredCorpusInput always routes to the scheduled lane; DeclaredBoundedFixture is the hermetic override (reachability over-approximates; the scheduled falsifier lane is its audit); EnvelopeUndeclared admits only Local - the refused_undeclared_when_envelope_unknown shape from InputEnvelope P0. RouteScheduledLane is a typed routing verdict, never a silent drop. Witnesses (7 new, 13 total, all green by execution; the suite itself stays Local-class: 393ms resolve, 0ms eval, fixture-only): - two-hop transitive carrier couples on DataBreadth; severing the mid hop flips it Local (the discriminating pair) - cyclic facts terminate and still reach the carrier - admission matrix cells incl. the RED control: undeclared + coupled never rides the continuous floor * Resolve the cargo binary at toolchain-pin time; stop baking the fleet's shim path into the build line The build line invoked "$CARGO_HOME/bin/cargo" - a fleet fact fused into the job model. On a runner image whose rustup pre-exists (ubicloud, GitHub-hosted), setup-rust-toolchain never runs rustup-init, so no shim lands under the isolated $CARGO_HOME and the build dies with "No such file or directory" (run 29161556017). The isolated RUSTUP_HOME/CARGO_HOME env still governs whichever shim exists - only the shim's LOCATION is realization-specific. Fix: the pin step (already the "make the isolated toolchain invocable" step, name unchanged so the cost-floor roster keeps resolving; no new run-step so the raw-script count pin holds) resolves CARGO_BIN once - isolated shim if present, else PATH - and refuses loudly when neither exists (fail-closed, DESIGN 5). ci_release_build_line invokes "$CARGO_BIN"; the retry escalations' env-prefix composition is unchanged since it stays one word. Falsifier inherits via the shared prelude. Workflows regenerated via main_wet. witness_rustup_run_plain_not_quoted repinned as witness_rustup_run_block_scalar_not_quoted: the pin step is now multi-line so its run correctly serializes as a block scalar; the property the witness guards (quote-laden content never YAML-escaped, negative control kept) is unchanged. ci_yaml_serializer_keystone_holds green by execution; 18-entry consumer sweep green except 3 witnesses red on unedited baseline too (pre-existing/environmental). * [ITERATION-ONLY - REVERT BEFORE MERGE] Reconcile the runner seam witness with the ubicloud override Cursor catch (review on the folded #6490, restated on #6489): the routing override left ci_runner_seam_holds red - it pinned gunbc_ci_runner_spec() to the fleet derivation and the yaml to [self-hosted, linux, arm64]. Reconciliation, discriminating in both directions during the window: the fleet-derivation witnesses repoint to gunbc_ci_runner_spec_fleet_derived() (the derivation authority stays proven and un-drifted), the live-spec witnesses pin the override label exactly (drift of the override itself is caught), and the workflow==live-spec seam witness is unchanged. ci_runner_seam_iteration_note carries the revert obligation; this commit reverts together with the routing commit (3f203d8). ci_runner_seam_holds green by execution. * Revert the iteration-only ubicloud routing (operator go 2026-07-11: iteration window closed, focus on merge) Restores gunbc_ci_runner_spec() to the fleet derivation as the single runner authority and the seam witnesses to pinning it (reverts 3f203d8 + 36e4cd3 as one motion); workflows regenerated via main_wet back to [self-hosted, linux, arm64]. The CARGO_BIN resolution (a03142d) stays - fleet-neutral portability fix, proven by execution on both runner classes (fleet floors unchanged; ubicloud build green run 29162064482). ci_runner_seam_holds and the serializer keystone green by execution on the reverted head. What the iteration window bought, for the record: the CARGO_BIN portability bug (fixed), the 12.5-min full floor + 13.5GiB-uncapped counterfactual receipt that pinned the fleet wedge on the memory.high throttle (now fixed at the budget edge in #6495), and the surfacing of the #6459 batch-2 panic (fixed in #6493). * Runner offers modeled + one selection authority: labels, memory regime, and budgets project from the selected target Operator asks 2026-07-11: model the runner rows (github, ubicloud; fleet existed) and make the mappings clear - then "stay on ubicloud for this change; self host runners are still contended." extdeps (cited, zero fabrication): - extdeps.cloud.ubicloud: the 10 documented runner shapes (runner-types.md anchor; arm 3GB/vCPU, x64 4GB/vCPU kept as vendor facts; the standard-16-arm observed MemTotal receipt recorded SEPARATELY from the catalog claim, discrepancy noted not reconciled) - extdeps.github.hosted_runners: the Ubuntu family with repository VISIBILITY as a first-class axis (public 4vCPU/16GB vs private 2vCPU/8GB for the same label - folding it away would be a state-space conflation); version-pinned labels, ubuntu-latest alias deliberately not a row gunbc.ci_runner_target (the missing edge the iteration window proved): - CiRunnerTarget = FleetSelfHosted | UbicloudRunner{row} | GithubHostedRunner{row}; selected_ci_runner_target() is THE switch - projections: runs-on spec (fleet stays DERIVED from the fleet offer; cloud rows carry the provider's cited token), memory regime (SlotCarved{desired} with the 15GiB throttle line vs WholeMachine{ram}), RAM-speed budget (fleet -> slot ceiling; cloud -> catalog ram) - ci_workflow, falsifier_workflow, floor budget, falsifier width all read the projections: flipping the selection row moved runs-on AND CARGO_BUILD_JOBS (4 -> 11, from the 48GB row) AND floor width in one regen - the propagation the label-only model could not do - selection = ubicloud-standard-16-arm (operator routing, fleet contended); flip back = FleetSelfHosted + regen, nothing else moves - falsifier now rides the selected shape too: its pinned fleet-slot capacity deficit witness stays parameterized on the FLEET ceiling (the deficit is a slot fact), while on 48GB its envelope fits with 3x headroom - the nightly's dissolve-on path Witnesses: ci_runner_target_witnesses (fleet-derivation identity, ubicloud/github label projections, both regimes, cited arm ratio held across the family, visibility-axis discrimination) + seam witnesses repinned to the selection authority with the fleet derivation kept live for the flip back. * Width-fit witness measures against the machine the plan runs on (the selected target budget), not the fleet slot unconditionally * Regen after folding the runner-offer selection into this branch (ubicloud labels + JOBS=11 + CARGO_BIN compose) * Resolve the cargo binary at toolchain-pin time; stop baking the fleet's shim path into the build line The build line invoked "$CARGO_HOME/bin/cargo" - a fleet fact fused into the job model. On a runner image whose rustup pre-exists (ubicloud, GitHub-hosted), setup-rust-toolchain never runs rustup-init, so no shim lands under the isolated $CARGO_HOME and the build dies with "No such file or directory" (run 29161556017). The isolated RUSTUP_HOME/CARGO_HOME env still governs whichever shim exists - only the shim's LOCATION is realization-specific. Fix: the pin step (already the "make the isolated toolchain invocable" step, name unchanged so the cost-floor roster keeps resolving; no new run-step so the raw-script count pin holds) resolves CARGO_BIN once - isolated shim if present, else PATH - and refuses loudly when neither exists (fail-closed, DESIGN 5). ci_release_build_line invokes "$CARGO_BIN"; the retry escalations' env-prefix composition is unchanged since it stays one word. Falsifier inherits via the shared prelude. Workflows regenerated via main_wet. witness_rustup_run_plain_not_quoted repinned as witness_rustup_run_block_scalar_not_quoted: the pin step is now multi-line so its run correctly serializes as a block scalar; the property the witness guards (quote-laden content never YAML-escaped, negative control kept) is unchanged. ci_yaml_serializer_keystone_holds green by execution; 18-entry consumer sweep green except 3 witnesses red on unedited baseline too (pre-existing/environmental). * Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin Three content reds every completed floor now hits, all proven on clean main (the 60m-timeout and batch-2-panic masks are gone, so the content layer behind them is finally visible): 1. anchor_source_root panicked mid-floor on "dag/compiler" (run for PR #6497, cli_run.rs:365) - a DECLARED root from the medium-structure roster that does not exist on disk yet (modeled-before-implemented). The layer walk's own is_dir guard proves absence is a legitimate skip state there, but the anchorer panicked before the guard could run. New non-panicking try_anchor_source_root for declared-root walks: absence skips with a counted [layer-import] line (loud, never silent); CLI-provided roots keep the strict panicking contract. 2. affected_set_universe_gate_processes_match_declared_gates compared the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's slice (7) since the #6472 job split. The witness now unions floor+regen+emit_determinism (the same union its sibling witness_gate_roster_matches_coproduct_arms already used); probe receipt: the three slices partition the 10 arms exactly. 3. witness_floor_disposition_marker_initialized_before_docs_only_branch (landed in today's wave) pinned the stamp DIRECTLY adjacent to the docs-only branch, but the emitted script has a blank line between them - red on clean main from its first run. The pin now matches the emitted adjacency (stamp, blank, _ci_changed) and still proves the ordering it exists for. Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses, and the layering clean-tree witness green by execution with the fixed binary. Remaining known main reds (predate today, tracked separately): s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm), ci_deploy_witnesses. * GithubHostedRunner projects the hosted scalar form (cursor catch) Ground GithubHostedRunnerCatalogRow.runs_on_label in the actions grammar's RunnerLabel closed vocabulary (extended with the cited ubuntu-24.04-arm / ubuntu-slim spellings; runner_label_string stays the single spelling authority) and route the GithubHostedRunner target through HostedRunner, whose serialization is the scalar runs-on form GitHub uses for hosted labels. A labels-list projection would have emitted the self-hosted label-matching form. Witness repinned to the HostedRunner variant plus a by-execution runner_yaml discrimination (scalar hosted vs flow-list label-routed). Ubicloud stays SelfHosted label routing (provider tokens, proven live 2026-07-11). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci_deploy witness: repin deploy invoke to the rooted source-root spelling witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted '--source-root dag' while gunbc_ci_deploy_invoke emits the rooted '--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453) - red on clean main, the third masked layer of the rooted-argv family (#6493 repinned the scheduler-argv pair). Proven by execution: suite false -> true on the repin, conjunct-bisected first. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch) Hand-Rust expansion now carries the DESIGN §7 shape the same file requires: authority rows (cli_run_source_root_anchor_scaffold sibling of the workspace-root scaffold, bind to the declaration), named dissolve-on (roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt anchor + counted loc delta, scaffold witnesses green by execution, and a discriminating unit pair (declared-present -> Some, declared-absent -> None). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * s1_closure floor panic: wrapper-retained diagnostics must inhabit the Diagnostics coproduct body_lower_wrapper_retained_shell constructed Accepted with a RAW NonEmptyDiagnostics in the diagnostics field where the Diagnostics coproduct (None | Some) is declared - the first downstream match over Diagnostics (diagnostics_merge in the normalize child fold) panicked non-exhaustive on every file with a wrapper-retained fn body, killing the s1_closure witness whenever the affected set selected it. Fix wraps the singleton in Some. Reproduced red (exact CI panic) and green by execution via s1_file_parses on dag/std/error_primitives.dag; new witness pins the shape and returns false (no panic) on the raw form. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Post-merge regen: plan docs re-derive the Lane D links from the merged authorities This branch's earlier regen ran while the .dag plan authorities lacked the link rows (pre-#6503), so it had written the docs linkless; the merge kept that side while main brought the link rows. main_wet now re-derives the linked docs - pair consistent, drift gate green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Two latent fleet-lane witness reds, first executed by this head's wider selection Both red on clean main by direct execution, latent behind affected-set skips and the batch-2 red era: host_standup_spine: the spine gained the P0:host-identity-converge step in #6253 (11 steps) while spine_step_tag matched exactly 10 phases with no catchall - non-exhaustive panic on Assimilation{HostIdentityConverge} whenever executed. Witness now describes the 11-step spine (tag arm + ordinal shift + length/ledger pins 10->11, gap count 4 unchanged, fn renamed ten->eleven to keep the name truthful). fleet_show_effective_read: declared_runner_count() derives from pool_budget / slot cap, so the #6495 re-carve (24->16GiB) moved it 10->5 and the 2026-07-03 width fixtures went stale. The parse-typing witness now pins the literal it parses (a parse fixture must not depend on a live-derived count - that fusion is how this went latent-red); the srv1 convergence witness flips to assert the REAL fact, drift (the hosts still run pre-carve width - the same oversubscription the falsifier exit-137 receipts located), with a dissolve-on for a post-re-carve readback. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Selection-grain fix: the
entry_file_touchedwiden becomes a counted refusal, control green and wired (operator fork (c), ASAP)The falsifier control
predict_only_red_predicted_unaffected_is_divergencewas red on main because the CI floor'sentry_file_touchedchannel carried a silent widen:cli_run.rsentry_file_touched_via_dependency_viewansweredOk(true)for every row whenever the substrate was not whole-tree, while its comment called itself fail-closed — the §5 absorbing fallback wearing §5's own name. Probe receipt (pristine main, empty real diff):substrate_is_whole_tree=FALSE -> touched=true,would_skip=falsewith empty frontier and no fn edits.What this PR does
1. Reground
entry_file_touchedon the module-graph dependency closure (declared #6335 partial unwind).entry_file_touched_via_import_closure(cli_run.rs): empty touched set →false; entry not in the module-graph facts → typed refusalAFFECTED-SET REFUSAL cause=EntryOutsideModuleGraphFacts(refuses the batch, never widens to run-all, never narrows to skip); else closure walk + path match — the same relation the .dag authorityv2.lens.module_graph.entry_affected_by_touched_pathsreads.entry_selection.dagentry_file_touched_grain_interim_note): (a) the widen above; (b) the Lever a slice 2: reground selection on DependencyView #6335 grain defect — edit loci aredecl.outputnodes, so a touched file's test fns put the sharedBoolnode in the locus set andfile_paths_for_frontier_nodesmarks every Bool-returning module affected (decl identity conflated with output type). The fn-arrow DependencyView machinery stays (compile-clean scoping consumer, gated P3+P5: infer whole-corpus scans to per-module maps #6239; decl-level candidate for this channel).dependency_edge_source_migration_noteinmodule_graph.dag("the swap replaces it; do not add a second producer"). Scaffold markerentry_file_touched_grain_interimdissolves at the namespace-only terminal step, where the file-grain-vs-decl-grain choice re-decides.module_grain_affected_equivalence_dag_only_real_diff,module_grain_affected_equivalence_v2_only_real_diff,module_grain_affected_decision_discriminates_under_wiring_perturbation— 3/3 green explicit (158s), receipts require discriminating rows (at least one affected and one unaffected) on real merged diffs.2. Two-channel hermetic injection actually executable (completes aeba290).
merry-owl's name-status injection was refuted by execution: a POSIX env value is a C string and can never carry the NUL-separated
--name-status -zwire format (std::env::set_varpanics). Fix at both ends, one wire-format authority: the injection arm decodes an env-safe escaped form at the template boundary (printf %b, octal\000→ NUL;floor_diff_observe.dagfloor_name_status_injection_encoding_note), the injector emitsM\000path\000. Verified undersh(dash) byte-exact including multi-record rename streams; both channels traced hermetic in the suite run.3. Cross-file classifier hole: closure-scan fix REFUTED by execution, landed as declared deficit instead.
eager-ram's finding (a live read behind an import is invisible to the entry-file scan) is real, but the closure-wide text scan I first landed classified essentially the whole corpus host-scaffold —
dag/std/primitives.dag(in virtually every closure) declares the live intrinsics, plan-doc prose mentions them — zeroing every predict-skip: the corpus-denominated absorbing fallback this PR removes, and it broke the pinned empty-diff-skips ruling (2026-07-05). Reverted; the deficit is now a declared comment onwitness_test_fn_uses_live_host_scanwith its bounded exposure (nightly falsifier counts wrong skips as divergences within one cadence window;floor:host_scaffoldmarker for explicit classification) and dissolve-on = decl-grain call reachability (the fn-arrow machinery). Thefilesystem_readsignal addition to the entry-file scan stays.4. Control wired into per-PR CI (the "wired" half of acceptance).
floor_skip_discovery_witnessjoins thecijob as its own step — named 15m budget (80s measured local), backstop stays the exact step-sum (135→150), bin added to the release-build line + artifact verify (stale-binary wall #6352). Run-step nature pin consciously bumped 19→20 perci_run_step_nature_claim_note. A PR that reintroduces a widen now reds before merge, not at the nightly cadence.Acceptance mapping (operator fork (c), relayed by merry-owl-649)
Ok(Bool(false)) => return Ok(true)widen is deleted; the failure arm is a counted typed refusal and the fail-closed label sits on the actual refusal.predict_only_red_predicted_unaffected_is_divergencegreen (full suiteRUN_EXIT=0, 80s) and wired into per-PR CI.Receipts
SKIP [assumed-green node-frontier]on unaffected rows).cargo test -p v1-compiler --lib -- cli_run: 135 passed / 0 failed.entry_selection.dagcompiles clean (0 diagnostics); regen viamain_wet, ci.yml/falsifier.yml drift-free by construction.