Skip to content

ShellProgram -> DAG - #6467

Merged
briansrls merged 35 commits into
mainfrom
session/witty-ibex-317
Jul 11, 2026
Merged

briansrls merged 35 commits into
mainfrom
session/witty-ibex-317

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session witty-ibex-317.
Pushing to session/witty-ibex-317 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

briansrls and others added 30 commits July 10, 2026 20:20
…wall on the whole-tree emit path

Fold-family productions extended so the fold no longer refuses word
Concat/CmdSubst or stmt WithRedir (all four Redir variants): new
concat_parts/word-compound/with_redir production families, lex tokens,
kind-tag emit transforms, and recursive bundle arms. Byte-identity vs
serialize_bash proven by execution: five depth-2 oracle tests plus the
depth-4 assign_root_stmt manual probe (ROOT=$('git' 'rev-parse'
'--show-toplevel' 2>/dev/null || 'pwd') byte-exact). The delegated
fail-closed RED control repoints from WithRedir (now native) to Heredoc
(still delegated) so the boundary guard stays discriminating.

Measured cost wall, declared on-carrier (bash_program_emit_cost_wall_note):
whole-tree backward row-selection is ~alternatives^depth (1s flat stmt,
64s for the single depth-4 stmt, DNF >8min for the full witness_bin
program) because formal_production_unique_lhs_exact_match deep-validates
every candidate per level and the descent re-validates each level again.
Real-program oracles therefore stay MANUAL probes, not test fns (a
discovery-run test would hang the local floor); the probe note on the
test carrier names the dissolution triggers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t runtime)

Phase-3 shape for the shared witness invocation, per the shell-emission-model
rule that runtime-present sites are argv invocations wearing bash syntax.
run_witness_bin_program and run_gunbc_claims no longer build a ShellProgram,
serialize it, and shell out - they realize the same intent as typed service
operations:

- git.Core.Toplevel (new op beside CurrentBranch/HeadCommit) resolves the
  repo root the bash path derived with a cd/rev-parse dance
- shell.Test.IsExecutable (new, POSIX test -x) replaces the test-not-
  executable guard and the post-build artifact verification
- cargo.Build.BuildInheritEnv (new) is the build-if-absent arm; it inherits
  process env exactly as the old sh -c cargo build did (cargo.Build.Build's
  env Map default is both a behavior change and unrecordable by the claim-
  run fixture writer, which fail-closes on Map values)
- gunbc.WitnessBin.Run (new) invokes the witness binary by absolute path
  with a spliced args list

Proven by execution: six op probes incl. argv[0] interpolation, list splice,
and negative RED controls (typed_witness_invocation_test); pattern A
end-to-end (v1_dag_parse witness, 0.43s wall vs bash round-trip); the
run_gunbc_claims rider (extdeps_external_authority uri witnesses); and the
flip-level RED control (unbuildable bin -> false, refused not fabricated).
The ShellProgram builders stay as the canonical fixtures for the bash
row-emit byte-identity oracles; importer ratchet unchanged at 27.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rs 27 -> 20

Second typed-argv tranche, riding the host_prelude flip:

- dag_compile_clean_transport: the four perturb receipts and the gate are
  one shared typed composition (Mktemp.Dir, Filesystem.Write for the
  perturb module - the heredoc dissolves, WitnessBin.Run on gunbc,
  Remove.RecursiveForce), parameterized by expected compile outcome. The
  ShellProgram builders, their serialize-shape witnesses, the marker rows,
  and both RealizationDispatch scaffold rows dissolve: with typed args the
  invocation facts are the construction, so the spelling-drift class those
  witnesses validated is unwritable (DESIGN 5) - the witness test file and
  the duplicate_computation compile-clean subject go with them (noted on
  the carrier; the lens keeps its emit_determinism subjects).
- dag_compile_clean_seam: the RawLine pile (cp -r, sed, $VAR-captured
  compiles, grep -c, echo SEAM_RESULT) becomes typed ops end to end - the
  sed is Filesystem.Read + replace + Write, the three compiles return
  typed results, and the SEAM_RESULT string protocol plus its parser
  dissolve; the receipt is a typed record and the synthetic RED controls
  construct it directly.
- dag_compile_clean_shard / shard_totality: typed staging compile and a
  Find.Files op (the '| sort' was cosmetic - the totality algebra is
  set-membership both ways).
- source_root_ingest_transport, compiler_closure_ingest_transport,
  self_host_realized_comparison_gate: typed compositions over the shared
  helpers (run_witness_bin_program / run_gunbc_claims).
- New extdeps ops: shell.Mktemp.Dir/DirWithTemplate, shell.Mkdir.Parents,
  shell.Remove.RecursiveForce, shell.Copy.File/Recursive, shell.Find.Files,
  shell.Test.IsNonEmpty (review fix: restores the test -s zero-byte guard
  the bash emit_verifications carried).
- Importer ratchet re-frozen 27 -> 20; seven stale exception-roster rows
  removed; ratchet + planted RED controls + clean-tree + roster-soundness
  all green.

Verified by execution: seam algebra + seam live probe, totality live,
shard exemplar compile, cross-tree green + optional-skew red receipts,
ingest gate (incl. a live cold-build refusal: remote-routed cargo produced
no local artifact and the non-empty/executable verification failed closed),
closure ingest gate, pattern A, full co-rooted corpus compile x2 clean.

Deferred with in-tree notes: floor_diff_observe (affected-set CI's diff
observer - avoid colliding with that lane), emit_determinism_transport
(last duplicate_computation ShellProgram subject), emit_host_transport
(go/node arms are genuine toolchain-bootstrap windows; rust arm needs an
env-pinning build op), bmc/ubuntu/srv3 provisioning tails.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… regression)

The dissolved bash prelude carried cd "$ROOT" - the construction that made
relative --source-root values and cargo build unambiguous. The typed flip
dropped it: WitnessBin.Run, BuildInheritEnv, and Find.Files ran in inherited
process cwd. Fix: each op now takes a required workdir input spelled as GNU
env -C (coreutils env(1)), so a call that does not say where it runs is a
type error, not a latent host-state dependency. All call sites thread
git.Core.Toplevel(). New discriminating probes: pwd under workdir=/tmp and
workdir=toplevel; ingest gate re-run green from a repo subdirectory (the
exact failure class flagged).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls and others added 5 commits July 11, 2026 00:17
…, Bash); on_exhausted wired

Precondition first (plan-doc FLAG): Retry.on_exhausted was a declared-but-unread
field - the emitter matched it as _ and the row baked exhaustion as fixed
tokens. Wired end to end: seg_h split into four fixed segments with three
shared-binding occurrences of an exhausted spelling, the emitter emits the
on_exhausted Pipeline and threads it through realize_retry (arity 8), and a
new teeth test reds the bytes when on_exhausted changes.

Cutover: gunbc.ci_spec.ci_cargo_eagain_retry_core no longer concatenates bash -
it builds the Retry intent (body run, two LogMatches escalation levels,
exhausted pipeline: the policy facts ci_spec owns) and renders through
orch_emit_step over the bash grammar rows. First dag-tree module importing
v2.* (gunbc ci loads both roots; workflow->compiler is the allowed layering
direction). The String seam's refusal arm emits a loud poison marker that reds
both the drift gate and the yaml parse gate - refuse, never widen; noted on
the carrier. The hand-authored blob moved verbatim to the test module as an
emitter-independent golden; the intent fixture module now delegates to the
production intent so tests exercise the value production emits.

Receipts: 5 retry emit tests green (byte-identity vs golden, production seam
vs golden, env/exhausted teeth); ci_yaml_parse_witness (the CI drift+parse
gate) ExitSuccess - committed ci.yml byte-identical through the new path;
full corpus compile 0 diagnostics. Attribution: the local 'gunbc ci' top-level
failure (dash rejecting set -o pipefail) reproduces on clean origin/main -
pre-existing, not this change.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 11, 2026 01:14
@briansrls
briansrls merged commit c97439d into main Jul 11, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/witty-ibex-317 branch July 11, 2026 01:25
gunbai-bot Bot pushed a commit that referenced this pull request Jul 11, 2026
Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 11, 2026
Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 11, 2026
Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 11, 2026
Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 11, 2026
Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 11, 2026
…f gate) (#6474)

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* docs: cross-link provisioning-window design from emission-ingestion-inverse gap B

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs: parent review fixes for provisioning-window design (Lane D)

Bake in parent-endorsed FLAG resolutions (v2.std.execution_surface,
per-site window, roster freeze at 58); mark slice 0 LANDED (#6467);
cross-link lane E fleet-converge ruling for slice 2 sequencing.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): skip floor receipt gates when docs-only floor is skipped

Documentation-only PRs stamp merge-admission as skipped without running
claim_executor, so target/floor-resolve-receipt.txt was never written and
the resolve/materialization receipt gates failed closed. Write a
ci-floor-disposition marker on the shortcut path and teach both gates to
skip loudly when CI_FLOOR_DISPOSITION=documentation_only_skipped.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Expand docs-only floor shortcut allowlist for receipt-gate companions.

Docs-only PRs that fix the floor-skip/receipt-gate mismatch must be able
to touch the minimal CI substrate rows without triggering the full floor,
which was timing out at 60 minutes on this lane.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): repair docs-only floor script parse errors and stamp receipt in shell.

Fix missing concat comma in ci_documentation_only_floor_shortcut_script,
avoid bash ${VAR:-} syntax that breaks DAG parse, replace gunbc
merge_admission_stamp in the docs-only path with a shell scaffold (v1 import
closure fails with one resolved source on CI), and sync ci.yml + witnesses.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): allow merge_admission producer witness in docs-only companion bundle.

The prior fix commit touched merge_admission_producer_witness_test.dag,
which forced the full floor because it was outside the closed allowlist.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): revert companion allowlist, dag-only stamp, checkout root witness

Docs-only shortcut is docs/* again (no CI substrate self-shortcut). Remove
shell merge-admission stamp; invoke merge_admission_stamp with --source-root
dag only. Fix floor_skip_discovery_witness to resolve checkout root at
runtime for cross-job artifacts. Sync ci.yml skip prefixes for selection
control and merge-admission gate.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): single merge-base authority + gate-skip dissolve-on entry

Add gunbc.ci_diff_defaults.ci_merge_base_ref as the sole authority for
origin/main (ci_spec diff_policy.base and merge_admission gate/stamp).
Name ci_documentation_only_gate_skip_prefix with Scaffold + dissolve-on
trigger; witness both follow-ups in ci_spec_witness_test.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): emit gate-skip dissolve-on in shell runners + witness tests

Prepend # dissolve-on comment into ci_documentation_only_gate_skip_prefix
emitted bash (matching floor-shortcut and cgroup-peak scaffolds). Sync all
four receipt-gate runners in ci.yml. Witness emitted scripts in
ci_spec_witness_test; extract ci_selection_control_script for coverage.

Pairs with 9281460: workspace_root discovery unit tests (git-toplevel +
cwd-ascent) in cli_run.rs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): add HAND-RUST receipt for workspace_root discovery scaffold

Model seed-retained disposition + dissolve-on in
cli_run_workspace_root_scaffold.dag; floor witness + planning anchor in
cli-run-reconcile-defork.md; mirror scaffold marker in cli_run.rs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): parse fix in workspace_root hand-rust witness

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): stamp floor_running before docs-only disposition branch

Persistent self-hosted target/ could retain documentation_only_skipped from a
prior docs-only job and fail-open the four receipt gates on a full floor run.
Initialize the marker to floor_running at the start of every floor step.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): bump floor step cap to 180m for legit s1_closure RUN

Run 29148664744 hit the 120m floor timeout after ~32m discovery corpus
SKIPs and an ~88m legitimate s1_closure_receipt RUN (this PR touches the
receipt files). Raise floor/regen to 180m and ci job backstop to 420m.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* WIP: Lane D — provisioning window/executor-capability model draft (sign-off g

* fix(ci): repair post-rebase ci_spec parse + drop stale shell stamp scaffold

Rebase onto main (#6473) left a broken concat nest in
ci_documentation_only_floor_shortcut_script and resurrected the removed
ci_documentation_only_merge_admission_stamp_script — both blocked
dag_compile_clean_gate batch-1 resolve.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): scaffold floor_running init shell with dissolve-on marker

Review 37154: ci_floor_disposition_marker_init_script lacked the HAND-SHELL
scaffold row and on-carrier dissolve-on comment that sibling receipt-gate
runners carry. Add Disposition = Scaffold bind, shell_emit_dissolution_trigger,
witness receipts, and sync ci.yml floor step opener.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
…ve LANDED

The .dag carrier is the authority (§6), and its status lines had gone stale
against the tree. Verified by reading the live tree on 2026-07-16, not by grep:

- Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a
  real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations,
  on_exhausted}; :235 routes it through orch_emit_step, with
  ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift
  gate and the yaml parse gate rather than masking with a hand-spelled fallback).
  Its stated precondition is also resolved: Retry.on_exhausted is no longer
  emitter-ignored (05_emit_orchestration.dag:503 -> :627).
- Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and
  every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03
  pre-runtime census found zero justified sites) — a decision, not a gap.
- Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via
  gunbc converge --host + the sanctioned fresh-standup bootstrap arm);
  EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST
/ the For-While scope ruling / the bash-minimization rule all stand as signed.
Only status facts changed.

Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto
finished work today. Added an explicit warning that status lines here are
load-bearing and the tree is the ground truth.

docs/plans/shell-emission-model.md regenerated via the generated-artifact gate
(PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
… 2 receipts recorded pending operator sign-off (#6734)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* plans: refresh shell_emission_model status — Slices 0/1(If band)/2 have LANDED

The .dag carrier is the authority (§6), and its status lines had gone stale
against the tree. Verified by reading the live tree on 2026-07-16, not by grep:

- Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a
  real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations,
  on_exhausted}; :235 routes it through orch_emit_step, with
  ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift
  gate and the yaml parse gate rather than masking with a hand-spelled fallback).
  Its stated precondition is also resolved: Retry.on_exhausted is no longer
  emitter-ignored (05_emit_orchestration.dag:503 -> :627).
- Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and
  every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03
  pre-runtime census found zero justified sites) — a decision, not a gap.
- Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via
  gunbc converge --host + the sanctioned fresh-standup bootstrap arm);
  EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST
/ the For-While scope ruling / the bash-minimization rule all stand as signed.
Only status facts changed.

Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto
finished work today. Added an explicit warning that status lines here are
load-bearing and the tree is the ground truth.

docs/plans/shell-emission-model.md regenerated via the generated-artifact gate
(PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

* plans: address review 38787 — Slice 1 marker + stop contradicting the roadmap authority

Both findings from cursor/composer-2.5 verified against the tree and valid.

Finding 1 (Slice 1 §5 row had no LANDED marker while §1 said it landed):
FIXED. The §5 Slice 1 row now records LANDED with its receipts (#6475, tier-2
band #6566, operator-signed as 6-shell-slice1) and states that For/While refuse
BY DESIGN rather than reading as unfinished work. That inconsistency was exactly
the failure mode this PR exists to fix.

Finding 2 (roadmap_authority.dag 6-shell-slice2 is done:false while this PR
claimed Slice 2 LANDED — two carriers disagreeing, §3):
VALID, fixed in the other direction from what the review suggested, for a reason
the review did not have: every done:true row in roadmap_authority.dag is wrapped
in sign(s: signed(by: "operator", works: true, scope_equivalent: true,
as_expected: true)). That is an OPERATOR ATTESTATION. There is no precedent in
that carrier for done:true + Unsigned. So "follow the same pattern for Slice 2"
would mean forging an operator signature, which I will not do.

Instead this doc stops asserting a verdict it has no authority to give:
- roadmap_authority.dag is named as THE status authority; this doc must not
  contradict it.
- The Slice 2 row now reports only what tree receipts prove (.github/
  fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and
  emits one artifact; EmitArtifactThenThinRun is a live transport arm) and marks
  the slice WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING.
- FLAGs 2a(i)/2b/2c named in the roadmap row are not resolvable from tree
  receipts, so the verdict is explicitly left to the operator.
- §1 is reworded to match, so the two sections no longer disagree either.

Also noted: the "~275 lines / 12+ fn defs" fleet_converge_emit row in the
residual census is stale against the current emitter (same class of staleness
this PR fixes).

docs/plans/shell-emission-model.md regenerated (PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
ci_floor_disposition_marker_init_emit_matches_concat_golden_holds failed
on CI because the concat-reconstructed golden carried a trailing newline
after the echo redirect that orch_emit_pipeline does not emit. Switch to
the #6467 hand-authored golden pattern (matches committed ci.yml).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
ci_floor_disposition_marker_init_emit_matches_concat_golden_holds failed
on CI because the concat-reconstructed golden carried a trailing newline
after the echo redirect that orch_emit_pipeline does not emit. Switch to
the #6467 hand-authored golden pattern (matches committed ci.yml).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Jul 26, 2026
…ker (#7265)

* WIP: shell→dag bucket D — foreign-executor emit cluster (gate #7216 now MERGE

* WIP: shell→dag bucket D — foreign-executor emit cluster (gate #7216 now MERGE

* Fix sccache emit if-branch semantics and commit regenerated ci.yml.

Multi-statement if/then bodies must be semicolon-joined in a single Run
(the if-else grammar inserts then_body verbatim without braces). The heal
job failed because ci.yml drifted and the bot lacks workflows permission to
push workflow files — commit the regenerated ci.yml and falsifier.yml here.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fold bucket-D census into arc census; delete orphan doc.

The standalone bucket-d-foreign-executor-emit-census.md had zero inbound
refs and would red the falsifier after merge. True-up §4.E/4.I and add
§4.J punch-list to the existing shell-to-dag-residual census (reachable
via design_document.dag) — single authority, no bind row needed.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Repoint ci_sccache_opportunistic_detect scaffold to emit module.

ci_sccache_provider_shell_injection moved to v2.workflow.ci_materialization_emit
in this PR; host_build_cache_provision's scaffold bind still pointed at the
deleted gunbc.ci_materialization declaration (review 43048).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix merge-admission emit golden: hand-authored bytes, no trailing NL.

ci_floor_disposition_marker_init_emit_matches_concat_golden_holds failed
on CI because the concat-reconstructed golden carried a trailing newline
after the echo redirect that orch_emit_pipeline does not emit. Switch to
the #6467 hand-authored golden pattern (matches committed ci.yml).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Mark ci_sccache_bound_branch semijoin as declared Scaffold.

Three bound-branch Runs are semicolon-folded because multi-Do then_
inside realize_if_else inline binding is unguarded by the if-band
corpus and byte-diverged on first ci.yml regen — not a carriage bug.
Dissolution: emit-lane construction refusal for multi-step then_ at
inline if_else bind, or block-bodied if_else row (emit lane, not D).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add missing Present import to ci_materialization_emit.

Present is used for redirect and else_ arms but was not in the import
list; golden tests executed green via compilation (review 43241).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Roster ct_render_rust_applied_type_qualified_base_test for scaffold index.

#7269 added the hand assertion blob after #7272 landed the inventory witness;
merge main exposed compiler_tests_rust_blobs_are_all_rostered red (27 declared, 26 rostered).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: shell→dag bucket D — foreign-executor emit cluster (gate #7216 now MERGE

* Rework bucket D PR1: dissolve semijoin, extract shared emit plumbing.

Replace semicolon-folded sccache bound branch with three Do steps so
block-bodied if_else (#7277) emits multi-line workflow text; re-golden
and regen ci.yml/falsifier.yml. Route both new emit modules through
orchestration_bash_emit_support (run/do/emit_pipeline); pre-existing
ci_*_emit forks migrate in PR2.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: shell→dag bucket D — foreign-executor emit cluster (gate #7216 now MERGE

* Fix CI drift gate: regen ci.yml from emit authority; drop duplicate roster.

Remove duplicate ct_render_rust_applied_type_qualified_base_test row (main
already carries it after #7272/#7288); revert language_source_scaffold_index
to main placement. Regenerate ci.yml/falsifier.yml via main_wet — block if
then/else body lines use emit indentation (10-space), not hand-indented
12-space; matches heal job 89806546636 output the bot could not push.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: shell→dag bucket D — foreign-executor emit cluster (gate #7216 now MERGE

* Remove duplicate ct_render_rust roster row from #7265 merge.

Main already owns this entry via #7288; the branch copy made rostered exceed declared (27/28).

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant