Skip to content

affected set processing - #6453

Merged
briansrls merged 9 commits into
mainfrom
session/loyal-wren-398-selection-fix
Jul 10, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/loyal-wren-398-selection-fix

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Selection-grain fix: the entry_file_touched widen becomes a counted refusal, control green and wired (operator fork (c), ASAP)

The falsifier control predict_only_red_predicted_unaffected_is_divergence was red on main because the CI floor's entry_file_touched channel carried a silent widen: cli_run.rs entry_file_touched_via_dependency_view answered Ok(true) for every row whenever the substrate was not whole-tree, while its comment called itself fail-closed — the §5 absorbing fallback wearing §5's own name. Probe receipt (pristine main, empty real diff): substrate_is_whole_tree=FALSE -> touched=true, would_skip=false with empty frontier and no fn edits.

What this PR does

1. Reground entry_file_touched on the module-graph dependency closure (declared #6335 partial unwind).

  • The widen fn is deleted (tombstone in place). The channel now decides via entry_file_touched_via_import_closure (cli_run.rs): empty touched set → false; entry not in the module-graph facts → typed refusal AFFECTED-SET REFUSAL cause=EntryOutsideModuleGraphFacts (refuses the batch, never widens to run-all, never narrows to skip); else closure walk + path match — the same relation the .dag authority v2.lens.module_graph.entry_affected_by_touched_paths reads.
  • Unwind receipts (both carried in entry_selection.dag entry_file_touched_grain_interim_note): (a) the widen above; (b) the Lever a slice 2: reground selection on DependencyView #6335 grain defect — edit loci are decl.output nodes, so a touched file's test fns put the shared Bool node in the locus set and file_paths_for_frontier_nodes marks every Bool-returning module affected (decl identity conflated with output type). The fn-arrow DependencyView machinery stays (compile-clean scoping consumer, gated P3+P5: infer whole-corpus scans to per-module maps #6239; decl-level candidate for this channel).
  • Namespace-only constraint honored: the closure query is edge-source-agnostic; the import-derived edge producer is isolated behind dependency_edge_source_migration_note in module_graph.dag ("the swap replaces it; do not add a second producer"). Scaffold marker entry_file_touched_grain_interim dissolves at the namespace-only terminal step, where the file-grain-vs-decl-grain choice re-decides.
  • Certification: the module-grain equivalence harness (re-promoted from orphan scaffold to production certification) — module_grain_affected_equivalence_dag_only_real_diff, module_grain_affected_equivalence_v2_only_real_diff, module_grain_affected_decision_discriminates_under_wiring_perturbation — 3/3 green explicit (158s), receipts require discriminating rows (at least one affected and one unaffected) on real merged diffs.

2. Two-channel hermetic injection actually executable (completes aeba290).
merry-owl's name-status injection was refuted by execution: a POSIX env value is a C string and can never carry the NUL-separated --name-status -z wire format (std::env::set_var panics). Fix at both ends, one wire-format authority: the injection arm decodes an env-safe escaped form at the template boundary (printf %b, octal \000 → NUL; floor_diff_observe.dag floor_name_status_injection_encoding_note), the injector emits M\000path\000. Verified under sh (dash) byte-exact including multi-record rename streams; both channels traced hermetic in the suite run.

3. Cross-file classifier hole: closure-scan fix REFUTED by execution, landed as declared deficit instead.
eager-ram's finding (a live read behind an import is invisible to the entry-file scan) is real, but the closure-wide text scan I first landed classified essentially the whole corpus host-scaffold — dag/std/primitives.dag (in virtually every closure) declares the live intrinsics, plan-doc prose mentions them — zeroing every predict-skip: the corpus-denominated absorbing fallback this PR removes, and it broke the pinned empty-diff-skips ruling (2026-07-05). Reverted; the deficit is now a declared comment on witness_test_fn_uses_live_host_scan with its bounded exposure (nightly falsifier counts wrong skips as divergences within one cadence window; floor:host_scaffold marker for explicit classification) and dissolve-on = decl-grain call reachability (the fn-arrow machinery). The filesystem_read signal addition to the entry-file scan stays.

4. Control wired into per-PR CI (the "wired" half of acceptance).
floor_skip_discovery_witness joins the ci job as its own step — named 15m budget (80s measured local), backstop stays the exact step-sum (135→150), bin added to the release-build line + artifact verify (stale-binary wall #6352). Run-step nature pin consciously bumped 19→20 per ci_run_step_nature_claim_note. A PR that reintroduces a widen now reds before merge, not at the nightly cadence.

Acceptance mapping (operator fork (c), relayed by merry-owl-649)

  1. ✅ The Ok(Bool(false)) => return Ok(true) widen is deleted; the failure arm is a counted typed refusal and the fail-closed label sits on the actual refusal.
  2. ✅ predict_only_red_predicted_unaffected_is_divergence green (full suite RUN_EXIT=0, 80s) and wired into per-PR CI.
  3. ✅ Two-channel-coherent injection (name-status + unified), hermetic by execution.

Receipts

  • Witness bin full suite: exit 0, all ~14 tests including the control and the empty-diff pin (SKIP [assumed-green node-frontier] on unaffected rows).
  • cargo test -p v1-compiler --lib -- cli_run: 135 passed / 0 failed.
  • Touched claim witnesses via claim_batch: 17/17 PASS (incl. nature pin at 20 against the live workflow, falsifier backstop formula, 8 floor-plan witnesses).
  • entry_selection.dag compiles clean (0 diagnostics); regen via main_wet, ci.yml/falsifier.yml drift-free by construction.
  • Width-1 pre==post closure-consistency oracle live in both bin runs (190/226 nodes).

briansrls and others added 9 commits July 10, 2026 22:11
…l hermeticity)

The control bin injected only the unified-diff channel (GUNBC_CI_DIFF_UNIFIED); the
name-status channel fell through to the REAL checkout diff, so the divergence control
read a mix of fixture (unified) and working-tree (name-status) state — non-hermetic.

Inject GUNBC_CI_DIFF_NAME_STATUS at both run_injected_diff_roster helpers, coherent
with each unified hunk: a single-file modify, "M" NUL path NUL. Format verified against
the git.dag parser (git_diff_name_status_advance splits on from_code_point(0), reads
status-token then path-token, skips empties). The .dag override already exists
(floor_diff_observe.dag printf injection); this only makes the bin SET the var. The
BASE/HEAD real-git failure-path sites are left untouched deliberately.

Part of the :5426 absorbing-fallback fix (loyal-wren-398 lane): the divergence control
must be hermetic to be a clean standing regression guard. Greens with the widen-arm
rewire on this branch. Compiles clean (cargo check, this commit).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 10, 2026 23:16
@gunbai-bot

gunbai-bot Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor Author

CI receipt for run 29129931005 @ b2bfb16: rust_tests PASS (5m19s), ci_regen PASS (4m58s — the new build line incl. floor_skip_discovery_witness works on CI), ci job RED with the pre-existing post-flip class, not this PR's changes. Anatomy from the job log: the affected-set selection is live and delivering (long runs of SKIP [assumed-green node-frontier] on unaffected rows — the fix working in production), then claim_executor was cgroup-OOM-killed (exit 137) mid-corpus at the 24 GiB cap. Labeled calibration pair produced exactly per contract: roster_import_closure_nodes=1395 rows=1958 + floor_peak_post=25769803776 floor_outcome=failure (peak == memory.max to the byte → CENSORED lower bound; matches the 29123623007 anchor). Root cause is the known one: rows skip execution but still resolve — resolve residency + cross-witness eval retention is the S2a lane (gentle-hawk #6444, node-keyed store) plus the frame-exit eviction fix (merry-moth #6456). The selection-control step never executed this run (job aborts at the floor step), but the identical suite is green locally (exit 0, 80s) and its step wiring is proven by ci_regen's green build. Implication: this PR's ci job cannot green before S2a/#6456 land — the same condition under which #6438 was merged red by the operator. Review bar is otherwise progressing (1 approval, zero findings, no R-C). — sent from loyal-wren-398

@briansrls
briansrls merged commit 07fe0eb into main Jul 10, 2026
2 of 6 checks passed
@briansrls
briansrls deleted the session/loyal-wren-398-selection-fix branch July 10, 2026 23:28
briansrls added a commit that referenced this pull request Jul 11, 2026
…den (#6453 added floor_skip_discovery_witness)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…b) (#6466)

* WIP: ci floor measurement

* WIP: ci floor measurement

* WIP: ci floor measurement

* Remove scratch probe test auto-committed into the branch

A temporary red probe (union_resolve_receipts_test.rs) used to characterize the
width==1 typecheck-compute-counter semantics was captured by the auto-committer
in 533e473 while it sat in the working tree. It asserts a deliberate RED, so it
fails rust_tests. It was never intended to land.

Restores the file to its state at 674381f.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ci floor measurement

* WIP: ci floor measurement

* roster_closure_nodes: derive from resolved graphs, not the thread typecheck counter

`typecheck_compute_count()` counts typecheck cache MISSES on the current thread and
is never reset in production (only tests reset it), so it equals a closure size only
from a cold start. The measurement window cannot assume that:

  - width == 1 returns `run_discovery_rows` on the discovery thread, which has already
    resolved every changed file via `floor_diff_edits_from_line_ranges` plus both prefix
    entries. The reported count was therefore |closure(changed files) u closure(prefix)
    u closure(rows)| -- a function of the diff under test, not of the roster.
  - `floor_skip_discovery_witness` calls run_discovery_corpus three times on one thread,
    so the 2nd and 3rd calls read a counter warmed by the 1st.

Count the union of authored module names across the graphs the shard actually resolves
(prefix contexts + each roster entry) instead. That is a property of the source closure:
independent of cache warmth, resolve order, and the diff. Prefix modules stay counted --
they are resident for the shard's lifetime, so they belong in the memory pairing.

Note the parallel path was never the problem: run_walk dispatches DiscoveryBatch via
thread::spawn, so shards do start cold. The defect was the pre-row work on the discovery
thread, which shards never repeat.

Adds a discriminating control: a prior same-thread resolve moves the compute counter
(asserted, so the control stays discriminating) but must not move the closure count.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ci floor measurement

* space-lens plan: fold in loyal-wren's systematic-kill correction (two knobs)

The host OOM is systematic, not intermittent: a width==1 shard is killed by
host-level oversubscription under its own slot cap, so narrowing width cannot
help. The per-shard prediction therefore feeds TWO knobs — within-job width and
cross-job packing/admission — and the systematic case is served by admission-
refusal, not width. Records RSS-at-kill as a lower-bound calibration point.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ci floor measurement

* WIP: ci floor measurement

* Remove rust_tests job from CI + RustMonolithGate/GithubActionsRustTestsJob coproduct variants

Frees a runner slot and drops CI's largest memory job (~37 GiB). The v1 rust
fmt+nextest gate was non-required and red on main (v1 seed being deleted, §7);
formatting stays covered by the pre-push hook. Removes the job, its roster
enrollment, the now-orphan Gate/surface coproduct variants and all their match
arms, the dead gate-runner wrappers, and updates the placement-grain duplicate
-computation flagship to the surviving 2 sibling jobs (still >1, still discharged).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: ci floor measurement

* rust_tests removal: fix binding count (3->2) + stale build-verify golden (#6453 added floor_skip_discovery_witness)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* Document rust-suite removal: declared Terminal rationale + no-return trigger at commit_gate_roster

Addresses PR review (cursor/composer-2.5): records the v1 fmt+nextest removal as
intentional with rationale (non-required + red on main, v1 seed being deleted §7,
fmt stays on pre-push) and its no-return trigger, rather than a silent coverage drop.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…flushed raw markers)

All six conflicted files take origin/main verbatim: HEAD side was stale
pre-#6453/#6463/#6466 session WIP; main carries the merged truth.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 11, 2026
…nchor scaffold receipt (#6500)

* Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin

Three content reds every completed floor now hits, all proven on clean
main (the 60m-timeout and batch-2-panic masks are gone, so the content
layer behind them is finally visible):

1. anchor_source_root panicked mid-floor on "dag/compiler" (run for
   PR #6497, cli_run.rs:365) - a DECLARED root from the
   medium-structure roster that does not exist on disk yet
   (modeled-before-implemented). The layer walk's own is_dir guard
   proves absence is a legitimate skip state there, but the anchorer
   panicked before the guard could run. New non-panicking
   try_anchor_source_root for declared-root walks: absence skips with
   a counted [layer-import] line (loud, never silent); CLI-provided
   roots keep the strict panicking contract.

2. affected_set_universe_gate_processes_match_declared_gates compared
   the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's
   slice (7) since the #6472 job split. The witness now unions
   floor+regen+emit_determinism (the same union its sibling
   witness_gate_roster_matches_coproduct_arms already used); probe
   receipt: the three slices partition the 10 arms exactly.

3. witness_floor_disposition_marker_initialized_before_docs_only_branch
   (landed in today's wave) pinned the stamp DIRECTLY adjacent to the
   docs-only branch, but the emitted script has a blank line between
   them - red on clean main from its first run. The pin now matches
   the emitted adjacency (stamp, blank, _ci_changed) and still proves
   the ordering it exists for.

Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses,
and the layering clean-tree witness green by execution with the fixed
binary. Remaining known main reds (predate today, tracked separately):
s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm),
ci_deploy_witnesses.

* ci_deploy witness: repin deploy invoke to the rooted source-root spelling

witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted
'--source-root dag' while gunbc_ci_deploy_invoke emits the rooted
'--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453)
- red on clean main, the third masked layer of the rooted-argv family
(#6493 repinned the scheduler-argv pair). Proven by execution: suite
false -> true on the repin, conjunct-bisected first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch)

Hand-Rust expansion now carries the DESIGN §7 shape the same file
requires: authority rows (cli_run_source_root_anchor_scaffold sibling of
the workspace-root scaffold, bind to the declaration), named dissolve-on
(roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a
typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt
anchor + counted loc delta, scaffold witnesses green by execution, and a
discriminating unit pair (declared-present -> Some, declared-absent ->
None).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 11, 2026
… Diagnostics coproduct (#6501)

* Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin

Three content reds every completed floor now hits, all proven on clean
main (the 60m-timeout and batch-2-panic masks are gone, so the content
layer behind them is finally visible):

1. anchor_source_root panicked mid-floor on "dag/compiler" (run for
   PR #6497, cli_run.rs:365) - a DECLARED root from the
   medium-structure roster that does not exist on disk yet
   (modeled-before-implemented). The layer walk's own is_dir guard
   proves absence is a legitimate skip state there, but the anchorer
   panicked before the guard could run. New non-panicking
   try_anchor_source_root for declared-root walks: absence skips with
   a counted [layer-import] line (loud, never silent); CLI-provided
   roots keep the strict panicking contract.

2. affected_set_universe_gate_processes_match_declared_gates compared
   the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's
   slice (7) since the #6472 job split. The witness now unions
   floor+regen+emit_determinism (the same union its sibling
   witness_gate_roster_matches_coproduct_arms already used); probe
   receipt: the three slices partition the 10 arms exactly.

3. witness_floor_disposition_marker_initialized_before_docs_only_branch
   (landed in today's wave) pinned the stamp DIRECTLY adjacent to the
   docs-only branch, but the emitted script has a blank line between
   them - red on clean main from its first run. The pin now matches
   the emitted adjacency (stamp, blank, _ci_changed) and still proves
   the ordering it exists for.

Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses,
and the layering clean-tree witness green by execution with the fixed
binary. Remaining known main reds (predate today, tracked separately):
s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm),
ci_deploy_witnesses.

* ci_deploy witness: repin deploy invoke to the rooted source-root spelling

witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted
'--source-root dag' while gunbc_ci_deploy_invoke emits the rooted
'--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453)
- red on clean main, the third masked layer of the rooted-argv family
(#6493 repinned the scheduler-argv pair). Proven by execution: suite
false -> true on the repin, conjunct-bisected first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch)

Hand-Rust expansion now carries the DESIGN §7 shape the same file
requires: authority rows (cli_run_source_root_anchor_scaffold sibling of
the workspace-root scaffold, bind to the declaration), named dissolve-on
(roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a
typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt
anchor + counted loc delta, scaffold witnesses green by execution, and a
discriminating unit pair (declared-present -> Some, declared-absent ->
None).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* s1_closure floor panic: wrapper-retained diagnostics must inhabit the Diagnostics coproduct

body_lower_wrapper_retained_shell constructed Accepted with a RAW
NonEmptyDiagnostics in the diagnostics field where the Diagnostics
coproduct (None | Some) is declared - the first downstream match over
Diagnostics (diagnostics_merge in the normalize child fold) panicked
non-exhaustive on every file with a wrapper-retained fn body, killing
the s1_closure witness whenever the affected set selected it. Fix wraps
the singleton in Some. Reproduced red (exact CI panic) and green by
execution via s1_file_parses on dag/std/error_primitives.dag; new
witness pins the shape and returns false (no panic) on the raw form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Jul 12, 2026
… cost/routing work (#6489)

* witness-cost-locality lens v0: one typed verdict for the two ambient-coupling axes (receipt-only)

One law: witness cost must be denominated in its subject (the DESIGN 5
denomination law). Two detectable projections at module grain:
DataBreadth (closure reaches an ambient-read carrier: filesystem_read
callers + the decl_facts reflection home) and LayerDepth (closure spans
>=2 compiler pipeline stages - the round-trip shape). Verdict algebra +
census receipt + precision-frontier disclosures as data; six fixture
witnesses incl. the single-stage boundary and a red control (law
perturbed to >=1 flips single_stage_closure_stays_local red - receipted).

Census 2026-07-11 over the 732-entry roster: Local 483 / LayerDepth 229 /
DataBreadth 9 / both 11; derives the operator-ruled-offline enforcement
rows and the execution/ exclusions; falsified two naive laws (decl_facts
reflection invisible to filesystem_read grep; hermetic fixture rows
over-flagged - the declared InputEnvelope is the override authority).
LayerDepth is receipt-only until fn-grain call-graph reachability lands
(ci_yaml counter-receipt: stage-type imports are not stage execution).

Dissolve-on: fn-grain reachability + InputEnvelope declarations wired
into floor admission; the witness_exclusion hand-rows and this v0
roster retire together.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Add the required construction_justification row (cursor review)

WallAfterGrounding dissolving to SingleAuthority: the verdict is
validation-tier until fn-grain reachability + InputEnvelope declarations
let floor admission consume it, at which point non-Local rows are
structurally absent from the per-PR plan (the single authority) and the
lens dissolves per its precision-frontier note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* [ITERATION-ONLY - REVERT BEFORE MERGE] Route CI to ubicloud runners

Self-hosted fleet has no free slots (operator, 2026-07-11); route this
PR's iteration to ubicloud-standard-16-arm so the lens work is not
gated on fleet capacity. Same move as the #6107 -> #6111 precedent.

gunbc_ci_runner_spec() returns the ubicloud label; the fleet
derivation is preserved untouched as gunbc_ci_runner_spec_fleet_derived()
and ubicloud_iteration_routing_note carries the revert obligation.
Workflows regenerated from the authority via main_wet (drift gate
stays coherent): runs-on [ubicloud-standard-16-arm] at ci.yml
build_release/floor/emit-determinism and falsifier.yml.

Revert = git revert this single commit + regen (or just revert; the
regenerated ci.yml/falsifier.yml are included here).

* Closure facts + per-PR admission law: the transitive-carrier case becomes provable, and verdict x envelope decides the lane

Extends the v0 lens with the fact half its census note promised:

- ModuleImportFact + import_closure: module-grain closure over declared
  import facts, the |E|-sweeps fixpoint shape sanctioned by
  v2.lens.affected_set (pass + frontier-stability + doubled-facts fuel,
  early-stable). Terminates on cyclic FACT rows - the substrate refuses
  cyclic imports, but the fold must not trust its input.
- witness_cost_locality_from_facts: closes over the facts so the
  transitive carrier (the enforcement_live falsification - the corpus
  read two hops away) is provable in fixtures, not just prose.
- WitnessInputEnvelope + per_pr_admission: the admission matrix
  (verdict x declared envelope), fail-closed with
  declaration-wins-when-stricter. DeclaredCorpusInput always routes to
  the scheduled lane; DeclaredBoundedFixture is the hermetic override
  (reachability over-approximates; the scheduled falsifier lane is its
  audit); EnvelopeUndeclared admits only Local - the
  refused_undeclared_when_envelope_unknown shape from InputEnvelope P0.
  RouteScheduledLane is a typed routing verdict, never a silent drop.

Witnesses (7 new, 13 total, all green by execution; the suite itself
stays Local-class: 393ms resolve, 0ms eval, fixture-only):
- two-hop transitive carrier couples on DataBreadth; severing the mid
  hop flips it Local (the discriminating pair)
- cyclic facts terminate and still reach the carrier
- admission matrix cells incl. the RED control: undeclared + coupled
  never rides the continuous floor

* Resolve the cargo binary at toolchain-pin time; stop baking the fleet's shim path into the build line

The build line invoked "$CARGO_HOME/bin/cargo" - a fleet fact fused
into the job model. On a runner image whose rustup pre-exists (ubicloud,
GitHub-hosted), setup-rust-toolchain never runs rustup-init, so no shim
lands under the isolated $CARGO_HOME and the build dies with "No such
file or directory" (run 29161556017). The isolated RUSTUP_HOME/CARGO_HOME
env still governs whichever shim exists - only the shim's LOCATION is
realization-specific.

Fix: the pin step (already the "make the isolated toolchain invocable"
step, name unchanged so the cost-floor roster keeps resolving; no new
run-step so the raw-script count pin holds) resolves CARGO_BIN once -
isolated shim if present, else PATH - and refuses loudly when neither
exists (fail-closed, DESIGN 5). ci_release_build_line invokes
"$CARGO_BIN"; the retry escalations' env-prefix composition is
unchanged since it stays one word. Falsifier inherits via the shared
prelude. Workflows regenerated via main_wet.

witness_rustup_run_plain_not_quoted repinned as
witness_rustup_run_block_scalar_not_quoted: the pin step is now
multi-line so its run correctly serializes as a block scalar; the
property the witness guards (quote-laden content never YAML-escaped,
negative control kept) is unchanged. ci_yaml_serializer_keystone_holds
green by execution; 18-entry consumer sweep green except 3 witnesses
red on unedited baseline too (pre-existing/environmental).

* [ITERATION-ONLY - REVERT BEFORE MERGE] Reconcile the runner seam witness with the ubicloud override

Cursor catch (review on the folded #6490, restated on #6489): the
routing override left ci_runner_seam_holds red - it pinned
gunbc_ci_runner_spec() to the fleet derivation and the yaml to
[self-hosted, linux, arm64].

Reconciliation, discriminating in both directions during the window:
the fleet-derivation witnesses repoint to
gunbc_ci_runner_spec_fleet_derived() (the derivation authority stays
proven and un-drifted), the live-spec witnesses pin the override label
exactly (drift of the override itself is caught), and the
workflow==live-spec seam witness is unchanged. ci_runner_seam_iteration_note
carries the revert obligation; this commit reverts together with the
routing commit (3f203d8). ci_runner_seam_holds green by execution.

* Revert the iteration-only ubicloud routing (operator go 2026-07-11: iteration window closed, focus on merge)

Restores gunbc_ci_runner_spec() to the fleet derivation as the single
runner authority and the seam witnesses to pinning it (reverts
3f203d8 + 36e4cd3 as one motion); workflows regenerated via
main_wet back to [self-hosted, linux, arm64]. The CARGO_BIN
resolution (a03142d) stays - fleet-neutral portability fix, proven
by execution on both runner classes (fleet floors unchanged; ubicloud
build green run 29162064482). ci_runner_seam_holds and the serializer
keystone green by execution on the reverted head.

What the iteration window bought, for the record: the CARGO_BIN
portability bug (fixed), the 12.5-min full floor + 13.5GiB-uncapped
counterfactual receipt that pinned the fleet wedge on the memory.high
throttle (now fixed at the budget edge in #6495), and the surfacing of
the #6459 batch-2 panic (fixed in #6493).

* Runner offers modeled + one selection authority: labels, memory regime, and budgets project from the selected target

Operator asks 2026-07-11: model the runner rows (github, ubicloud;
fleet existed) and make the mappings clear - then "stay on ubicloud
for this change; self host runners are still contended."

extdeps (cited, zero fabrication):
- extdeps.cloud.ubicloud: the 10 documented runner shapes
  (runner-types.md anchor; arm 3GB/vCPU, x64 4GB/vCPU kept as vendor
  facts; the standard-16-arm observed MemTotal receipt recorded
  SEPARATELY from the catalog claim, discrepancy noted not reconciled)
- extdeps.github.hosted_runners: the Ubuntu family with repository
  VISIBILITY as a first-class axis (public 4vCPU/16GB vs private
  2vCPU/8GB for the same label - folding it away would be a
  state-space conflation); version-pinned labels, ubuntu-latest alias
  deliberately not a row

gunbc.ci_runner_target (the missing edge the iteration window proved):
- CiRunnerTarget = FleetSelfHosted | UbicloudRunner{row} |
  GithubHostedRunner{row}; selected_ci_runner_target() is THE switch
- projections: runs-on spec (fleet stays DERIVED from the fleet offer;
  cloud rows carry the provider's cited token), memory regime
  (SlotCarved{desired} with the 15GiB throttle line vs
  WholeMachine{ram}), RAM-speed budget (fleet -> slot ceiling;
  cloud -> catalog ram)
- ci_workflow, falsifier_workflow, floor budget, falsifier width all
  read the projections: flipping the selection row moved runs-on AND
  CARGO_BUILD_JOBS (4 -> 11, from the 48GB row) AND floor width in one
  regen - the propagation the label-only model could not do
- selection = ubicloud-standard-16-arm (operator routing, fleet
  contended); flip back = FleetSelfHosted + regen, nothing else moves
- falsifier now rides the selected shape too: its pinned fleet-slot
  capacity deficit witness stays parameterized on the FLEET ceiling
  (the deficit is a slot fact), while on 48GB its envelope fits with
  3x headroom - the nightly's dissolve-on path

Witnesses: ci_runner_target_witnesses (fleet-derivation identity,
ubicloud/github label projections, both regimes, cited arm ratio held
across the family, visibility-axis discrimination) + seam witnesses
repinned to the selection authority with the fleet derivation kept
live for the flip back.

* Width-fit witness measures against the machine the plan runs on (the selected target budget), not the fleet slot unconditionally

* Regen after folding the runner-offer selection into this branch (ubicloud labels + JOBS=11 + CARGO_BIN compose)

* Resolve the cargo binary at toolchain-pin time; stop baking the fleet's shim path into the build line

The build line invoked "$CARGO_HOME/bin/cargo" - a fleet fact fused
into the job model. On a runner image whose rustup pre-exists (ubicloud,
GitHub-hosted), setup-rust-toolchain never runs rustup-init, so no shim
lands under the isolated $CARGO_HOME and the build dies with "No such
file or directory" (run 29161556017). The isolated RUSTUP_HOME/CARGO_HOME
env still governs whichever shim exists - only the shim's LOCATION is
realization-specific.

Fix: the pin step (already the "make the isolated toolchain invocable"
step, name unchanged so the cost-floor roster keeps resolving; no new
run-step so the raw-script count pin holds) resolves CARGO_BIN once -
isolated shim if present, else PATH - and refuses loudly when neither
exists (fail-closed, DESIGN 5). ci_release_build_line invokes
"$CARGO_BIN"; the retry escalations' env-prefix composition is
unchanged since it stays one word. Falsifier inherits via the shared
prelude. Workflows regenerated via main_wet.

witness_rustup_run_plain_not_quoted repinned as
witness_rustup_run_block_scalar_not_quoted: the pin step is now
multi-line so its run correctly serializes as a block scalar; the
property the witness guards (quote-laden content never YAML-escaped,
negative control kept) is unchanged. ci_yaml_serializer_keystone_holds
green by execution; 18-entry consumer sweep green except 3 witnesses
red on unedited baseline too (pre-existing/environmental).

* Unbreak the post-merge-wave floor: absent declared roots skip loudly, the split-spanning gate universe, and the disposition-marker adjacency pin

Three content reds every completed floor now hits, all proven on clean
main (the 60m-timeout and batch-2-panic masks are gone, so the content
layer behind them is finally visible):

1. anchor_source_root panicked mid-floor on "dag/compiler" (run for
   PR #6497, cli_run.rs:365) - a DECLARED root from the
   medium-structure roster that does not exist on disk yet
   (modeled-before-implemented). The layer walk's own is_dir guard
   proves absence is a legitimate skip state there, but the anchorer
   panicked before the guard could run. New non-panicking
   try_anchor_source_root for declared-root walks: absence skips with
   a counted [layer-import] line (loud, never silent); CLI-provided
   roots keep the strict panicking contract.

2. affected_set_universe_gate_processes_match_declared_gates compared
   the Gate coproduct's 10 arms against gunbc_ci_gates - the ci JOB's
   slice (7) since the #6472 job split. The witness now unions
   floor+regen+emit_determinism (the same union its sibling
   witness_gate_roster_matches_coproduct_arms already used); probe
   receipt: the three slices partition the 10 arms exactly.

3. witness_floor_disposition_marker_initialized_before_docs_only_branch
   (landed in today's wave) pinned the stamp DIRECTLY adjacent to the
   docs-only branch, but the emitted script has a blank line between
   them - red on clean main from its first run. The pin now matches
   the emitted adjacency (stamp, blank, _ci_changed) and still proves
   the ordering it exists for.

Receipts: ci_spec_witnesses, all 4 affected_set_universe witnesses,
and the layering clean-tree witness green by execution with the fixed
binary. Remaining known main reds (predate today, tracked separately):
s1_closure_parses_holds (#6459 wrapper-retained diagnostic arm),
ci_deploy_witnesses.

* GithubHostedRunner projects the hosted scalar form (cursor catch)

Ground GithubHostedRunnerCatalogRow.runs_on_label in the actions grammar's
RunnerLabel closed vocabulary (extended with the cited ubuntu-24.04-arm /
ubuntu-slim spellings; runner_label_string stays the single spelling
authority) and route the GithubHostedRunner target through HostedRunner,
whose serialization is the scalar runs-on form GitHub uses for hosted
labels. A labels-list projection would have emitted the self-hosted
label-matching form. Witness repinned to the HostedRunner variant plus a
by-execution runner_yaml discrimination (scalar hosted vs flow-list
label-routed). Ubicloud stays SelfHosted label routing (provider tokens,
proven live 2026-07-11).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* ci_deploy witness: repin deploy invoke to the rooted source-root spelling

witness_deploy_run_script_invokes_gunbc_wet pinned the unrooted
'--source-root dag' while gunbc_ci_deploy_invoke emits the rooted
'--source-root "$ROOT/dag"' (witness_layer_source_flags_rooted, #6453)
- red on clean main, the third masked layer of the rooted-argv family
(#6493 repinned the scheduler-argv pair). Proven by execution: suite
false -> true on the repin, conjunct-bisected first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* try_anchor_source_root: seed-retained scaffold receipt (cursor #6489 catch)

Hand-Rust expansion now carries the DESIGN §7 shape the same file
requires: authority rows (cli_run_source_root_anchor_scaffold sibling of
the workspace-root scaffold, bind to the declaration), named dissolve-on
(roots walk GENERATED via cli-run-reconcile-defork Chunk F, absence a
typed roster-layer diagnostic; or 5-dissolve-patches), checkable receipt
anchor + counted loc delta, scaffold witnesses green by execution, and a
discriminating unit pair (declared-present -> Some, declared-absent ->
None).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* s1_closure floor panic: wrapper-retained diagnostics must inhabit the Diagnostics coproduct

body_lower_wrapper_retained_shell constructed Accepted with a RAW
NonEmptyDiagnostics in the diagnostics field where the Diagnostics
coproduct (None | Some) is declared - the first downstream match over
Diagnostics (diagnostics_merge in the normalize child fold) panicked
non-exhaustive on every file with a wrapper-retained fn body, killing
the s1_closure witness whenever the affected set selected it. Fix wraps
the singleton in Some. Reproduced red (exact CI panic) and green by
execution via s1_file_parses on dag/std/error_primitives.dag; new
witness pins the shape and returns false (no panic) on the raw form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Post-merge regen: plan docs re-derive the Lane D links from the merged authorities

This branch's earlier regen ran while the .dag plan authorities lacked
the link rows (pre-#6503), so it had written the docs linkless; the
merge kept that side while main brought the link rows. main_wet now
re-derives the linked docs - pair consistent, drift gate green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Two latent fleet-lane witness reds, first executed by this head's wider selection

Both red on clean main by direct execution, latent behind affected-set
skips and the batch-2 red era:

host_standup_spine: the spine gained the P0:host-identity-converge step
in #6253 (11 steps) while spine_step_tag matched exactly 10 phases with
no catchall - non-exhaustive panic on Assimilation{HostIdentityConverge}
whenever executed. Witness now describes the 11-step spine (tag arm +
ordinal shift + length/ledger pins 10->11, gap count 4 unchanged,
fn renamed ten->eleven to keep the name truthful).

fleet_show_effective_read: declared_runner_count() derives from
pool_budget / slot cap, so the #6495 re-carve (24->16GiB) moved it
10->5 and the 2026-07-03 width fixtures went stale. The parse-typing
witness now pins the literal it parses (a parse fixture must not depend
on a live-derived count - that fusion is how this went latent-red); the
srv1 convergence witness flips to assert the REAL fact, drift (the hosts
still run pre-carve width - the same oversubscription the falsifier
exit-137 receipts located), with a dissolve-on for a post-re-carve
readback.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant