Skip to content

Host-scaffold classifier defork: substrate-declared LiveTreeDisposition; delete the Rust text classifier - #6479

Merged
briansrls merged 18 commits into
mainfrom
session/valiant-ant-115
Jul 12, 2026
Merged

briansrls merged 18 commits into
mainfrom
session/valiant-ant-115

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 11, 2026 •

Copy link
Copy Markdown
Contributor

Host-scaffold classifier de-fork (ROADMAP 2-host-scaffold-classifier-defork)

Dissolves the claim_executor Rust text classifier (witness_test_fn_uses_live_host_scan in cli_run.rs) and the interim floor:host_scaffold marker into a substrate-declared live-tree disposition, then deletes both (tombstone at the old cli_run.rs site).

The model

  • New leaf module src/v2/std/live_tree.dag: LiveTreeDisposition = ReadsLiveTree | SubstrateInputsOnly.
  • Single authority = the witness ENTRY FILE's own row: data live_tree_disposition: LiveTreeDisposition = .... Entry grain — the entry's own row asserts the fact for the whole evaluation, no matter where the read hides behind imports. This closes the declared cross-file deficit (former cli_run.rs:5874 comment block) at declaration grade.
  • Fail-closed default: undeclared = ReadsLiveTree = never predict-skip. A row must DECLARE SubstrateInputsOnly to become selection-eligible.
  • Placement deviation from the roadmap row's original wording (updated in roadmap_authority.dag, same PR): the disposition does NOT live on TestClaim/BoolWitness claim rows — a claim row asserting a foreign entry's liveness would be a second carrier of the same fact (§3 dual representation). Parent (loyal-wren-398) approved this placement 2026-07-11.
  • The floor runner's forked skip fns (floor_host_scaffold_would_skip / floor_host_scaffold_precompute_would_skip) are replaced by disposition-parameterized kernels (floor_row_would_skip, floor_row_precompute_would_skip): the policy match lives in the substrate; the executor passes each row's declared disposition (a typed variant) across the seam. FloorWitnessRow carries the typed field.

Migration stamp (machine-stamped, provenance on the carrier)

638 entry files stamped: 610 SubstrateInputsOnly + 28 ReadsLiveTree, frozen from the deleted classifier's verdict at migration time — selection behavior is preserved exactly (no skip-set pin moves by the stamp itself). The stamp is entry-text grain and machine-vouched, not author-vouched: live_tree_disposition_stamp_provenance in live_tree.dag records this once on the carrier, with the dissolve-at (call-reachability grade re-derivation).

Coverage math: the ~1,721 corpus rows are test FNs; dispositions are entry-grain, so every row inherits its entry file's declaration. 638 entries ≈ 636 *_test.dag files + 2 claim-referenced non-_test entries (sg2_type_expression_projection.dag, find_witness_project_to_core_controls.dag).

Soundness argument

A row that declares SubstrateInputsOnly while actually reading live state is NOT re-checked by any text scan (the closure text-scan was refuted by execution 2026-07-10 — primitives.dag declares the live intrinsics in virtually every closure). The nightly affected-set falsifier (.github/workflows/falsifier.yml, predict-only cold run) is the enforcement: a lying row surfaces as a counted divergence within one cadence window.

Controls (green by execution)

  • Collision spike (parent FLAG 1): src/v2/test/fixture/live_tree/live_tree_collision_test.dag — entry and imported peer BOTH declare live_tree_disposition; resolves cleanly, entry binds its own row. Run green before the bulk stamp.
  • Never-skip control: live_tree_declared_test.dag (declares ReadsLiveTree) — floor_skip_discovery_witness proves an unrelated diff still RUNS it (Applied) and never records it predicted-unaffected (PredictOnly).
  • Lying-row RED path: falsifier_divergence_control_test.dag now DECLARES SubstrateInputsOnly; predict_only_red_predicted_unaffected_is_divergence proves a declared-not-live red row = exactly one counted divergence. No second text scan added — the falsifier IS the enforcement.
  • Rust: 6 new disposition-parse unit tests (declared/undeclared/malformed/duplicate) + live_tree_declared_row_not_skipped_on_unrelated_diff with a discriminating SubstrateInputsOnly control. 8/8 green; floor tests 28/28 green; floor_skip_discovery_witness 16/16 green.

Consciously-moved pins / flags for reviewers

  1. test/fixture/floor_skip/ excluded from tree-wide discovery at DIR grain (gunbc.ci_layer_roots.witness_exclusion_substrings + note; parent-approved 2026-07-11, corpus enrollment was never intended). falsifier_divergence_control_test.dag carries a BY-DESIGN red row (falsifier_red_control_holds returns false); as a corpus row it reds any completed full-corpus run and makes the falsifier's 8-clean-window retirement criterion unsatisfiable — the leading hypothesis for the first completed nightly falsifier run's red (29135185172, failed ~2h20m; falsifier-side verdict owned by loyal-wren-398). Its intended execution path — the explicit rosters in floor_skip_discovery_witness, run per-PR since affected set processing #6453 — is unaffected, so the exclusion inerts nothing. Genuine corpus witnesses that were mis-homed under fixture/ are re-homed to test/claim/ (provenance_fail_closed_contract_test, live_tree_collision_test) and stay enrolled.
  2. This PR's CI floor red, if it comes, is the residency cap-kill class, not logic: the stamp adds an import line (a pre-declaration touch) to every entry, so entry_file_touched fires for all 638 entries — the honest attribution, not gamed — making this the first full flipped-corpus run in per-PR CI. That is the runner-slot residency cap-kill class, override-eligible with precedent (Turn on affected-set CI: re-land witness enrollment flip (discovery shrunk by affected set) + falsifier host-OOM receipt #6438, affected set processing #6453, Runner-slot caps: operator per-axis targets (16GiB x 5 guaranteed, swap 32GiB applied); de-fork swap knob onto the authority #6463 operator-merged red under it). Note the srv1 slots read 16GiB live as of 2026-07-11 (nightly falsifier receipt), so expect the censored peak at ~17179869184, not the earlier 24GiB shape. Read the classification off the calibration triple in the job log (closure_nodes / floor_peak_post / floor_outcome): cap-kill = censored peak at the slot cap with floor_outcome != success. Local acceptance is green (receipts above).
  3. Dashboard modeling-coherence check reports too_large (fail-closed) — gh pr diff caps at 300 files. Mechanism-first splitting is unsound (an undeclared=live window collapses selection to ~0 skips until the stamps land). A sound split DOES exist — stamps-first tranches (~3 PRs of ~250 entry files, inert under the still-live classifier), mechanism PR last and small — at the cost of ~3 extra heavy floor runs and 4× review overhead. Operator's call: coherence override on this atomic PR (default) vs the tranche re-cut.

🤖 Generated with Claude Code

@gunbai-bot gunbai-bot Bot changed the title W1-A host-scaffold defork (reads_live_tree on TestClaim rows, delete the Rust classifier) Host-scaffold classifier defork: substrate-declared LiveTreeDisposition; delete the Rust text classifier Jul 11, 2026
… roadmap/plan-doc updates

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 11, 2026 04:25
@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

Review finding 1 (prefix over-fire) fixed in efe5a63877: parse_entry_live_tree_disposition now requires a non-identifier char after live_tree_disposition, so a sibling row like data live_tree_disposition_note: String neither classifies the entry nor trips the malformed-row refusal. Regression test live_tree_disposition_sibling_named_row_is_not_the_declaration covers both the co-declared and note-only shapes (7/7 disposition tests green). Finding 2 (hand-rolled text parser = small §3 parallel rep) is acknowledged as-is: the dissolution trigger is already named at the parse site (call-reachability-grade re-derivation via fn-arrow DependencyView).

On the CI red @ 64a1c3e (32s, pre-floor): not a logic failure and not the expected residency cap-kill — claim_executor panicked reading dag/gunbc/ci_layer_roots.dag at an absolute path under /opt/actions-runner/srv2-01/_work/... while the job ran on srv1-04. workspace_root() is compile-time baked from CARGO_MANIFEST_DIR, and the shared cargo/sccache cache served an object built on a different runner instance, so the baked root doesn't exist on this host. This commit changes cli_run.rs, forcing a fresh compile hash, which should clear it for this head; the underlying cross-runner env!-baked-path poisoning is a fleet/infra class (same family as the #6352 stale-binary fix) that deserves its own lane — flagged to the affected-set manager. — sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

Correction to flag 3 in the PR body (the coherence too_large block): my claim that no under-300-file cut exists was too strong. A sound split DOES exist, in the reverse order I originally considered: land the stamps first in ~3 tranche PRs (~250 entry files each — inert under the still-live text classifier, which ignores the new rows, so there is no undeclared=live fail-open window at any point), then land the mechanism PR last (small: the Rust classifier deletion, the floor-runner kernels, v2.std.live_tree, controls). Each tranche passes the coherence check's file cap.

Trade-off for the operator: the split costs ~3 additional heavy CI floor runs (each tranche touches its 250 entries' import lines → corpus-scale selection) plus 4× review overhead, versus one override of the coherence check on this atomic PR (which already carries one APPROVE). Both paths are fail-closed; this PR stays as-is unless the operator prefers the tranche route, in which case I'll re-cut. — sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

CI red @ efe5a63 is the same cross-runner baked-path class, confirmed FLEET-WIDE, not this PR's defect: this run panicked in build_module_path_index — binary baked to srv2-02's tree, job ran on srv2-04 — and the runs list shows simultaneous failures across unrelated session branches (jolly-swift-105, lively-pike-140, lively-ant-589, eager-heron-120) in the same window. The ci job executes bins built by the separate build job (artifact download), so whenever the two jobs land on different runner instances, every workspace_root()-anchored read points at the builder's tree. A fix branch claude/workspace-root-runtime-derivation is already in flight on the infra side; this PR should be re-run once that lands. No fix commit is applicable here — the failure reproduces on any branch. — sent from valiant-ant-115

briansrls and others added 2 commits July 11, 2026 04:52
…collision test matches the coproduct inline

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

cursor REQUEST_CHANGES addressed in 34645b470c: live_tree_disposition_is_live is deleted from v2.std.live_tree (the module is now a pure leaf — type + note rows only, no imports), and its sole consumer live_tree_collision_test.dag matches the coproduct inline, consistent with how floor_row_would_skip consumes it. Both witnesses re-run green by execution. — sent from valiant-ant-115

… not resolvable in the floor's dag+src/v2 attribution index (its own note declares this)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

CI red @ 34645b4 (batch-2 discovery refusal) fixed in 6daf9ae0cd: the floor's diff-to-declaration attribution resolves every CHANGED .dag file, and the bulk stamp had touched src/v2/test/manual/ownership_movable_test.dag — a file whose own dissolution note declares it NOT RESOLVABLE on clean main under the floor's dag+src/v2 index (it imports v1.compiler.ownership from src/v1, off the witness layer roots). It is discovery-excluded (test/manual/) and in no explicit roster, so its disposition row was unread dead weight; the fix reverts the file byte-identical to main, removing it from the diff so attribution never touches it. Every other stamped file in an excluded path was resolve-probed locally (35/35 ok); the remaining corpus files are discovery rows the floor resolves as a matter of course. Note this attribution behavior is a general landmine independent of this PR: ANY future edit to that file (or any unresolvable-by-design retired test) reds the floor's attribution — the file's dissolve-on (v2-side use_site_verdict witness) is the durable fix. — sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

CI red @ 6daf9ae decomposed — three causes, none fixable by a commit on this branch:

  1. 60-min job timeout mid-corpus (claim_executor terminated as an orphan at cleanup): the corpus-wide floor was still executing when the window expired, with floor_peak_post=16140107776 / floor_outcome=failure — the censored-peak residency signature right at the 16GiB live slot cap, exactly the override-precedented class documented in the body. Note batch-1 compile went clean in ~21.5min this run; the wall is the corpus batch + window, not a logic red.
  2. interp_recorded_fixture_witness exit=1 is PRE-EXISTING on main, proven by execution: a clean origin/main worktree + main-built binaries reproduce the identical 6 check failures (out-of-tree /tmp fixture entries fail resolve on their first import, e.g. extdeps.filesystem.filesystem_io not found). Not introduced by this PR.
  3. Main itself is red: the 5 most recent main CI runs all failed (the 2026-07-10/11 incident, Evidence doc: why CI performance is tanking (2026-07-10/11 main-red incident, argued serially with receipts) #6469 evidence doc); the 04:15 main run died on the same cross-runner baked-workspace_root panic this PR hit earlier (fix in flight: regen_stage0: runtime workspace_root() instead of baked CARGO_MANIFEST_DIR (defer to #6484 authority) #6482).

Net: this PR's local acceptance remains fully green (unit tests, floor-runner witnesses, floor_skip bin 16/16, compile-clean, collision + re-homed witnesses); its CI outcome is bounded by main-red + fleet infra + the corpus-window class already flagged for operator override. — sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 11, 2026

Copy link
Copy Markdown
Contributor Author

CI red @ 72eaae6 decomposed: it is the #6482 cross-slot baked-path bug, made deterministic by #6472's job split. Not a defect in this diff.

Head 72eaae6 is the dashboard's merge of origin/main (now containing #6472's build/floor/emit-determinism job split) into this branch — no content change from 6daf9ae.

Receipt from run 29143290543, job ci (fails in 31s):

  • The build job passes and ships release-bins.tgz as an artifact; the ci job (on srv1-04) unpacks it and artifact verification passes (15 bins present + non-empty — presence-grain, so it cannot see path skew).
  • claim_executor then panics immediately at src/v1/stage0/src/cli_run.rs:499:
    ci_layer_roots authority: failed to read /opt/actions-runner/srv2-03/_work/gunbc/gunbc/dag/gunbc/ci_layer_roots.dag — a srv2-03 path while running on srv1-04. That is the compile-time-baked CARGO_MANIFEST_DIR in workspace_root() (cli_run.rs:170), the exact class PR regen_stage0: runtime workspace_root() instead of baked CARGO_MANIFEST_DIR (defer to #6484 authority) #6482 fixes with runtime derivation.
  • The merge_admission_stamp unresolved-import cascade after the panic is the same skewed binary resolving against the wrong baked root, not a modeling error (dag/tools/merge_admission_stamp.dag is untouched by this PR and resolves clean locally).

Note the interaction: #6472's artifact hand-off makes this bug fire deterministically whenever the ci job lands on a different runner slot than the one whose paths are baked into the cached objects — previously it needed a cross-slot cache hit. #6482's merge is the unblocking event; after it merges I'll rerun this CI.

The other queued item (modeling-coherence too_large) is the known 300-file gh pr diff cap, unchanged — decomposition and split analysis are already in the PR body; default disposition is atomic + operator override.

— sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

Re: claude's non-blocking observation that parse_entry_live_tree_disposition's dissolution should be named on the Rust helper the way live_tree_disposition_stamp_provenance names it for the stamps —

That trigger is already stated directly on the helper: the TOMBSTONE comment immediately above the fn (cli_run.rs:6541-6554) closes with "Call-reachability-grade classification (fn-arrow DependencyView over lowered bodies) remains the later lane that re-derives these declarations" — the same call-reachability grounding cited for the stamps. So the helper and the stamps name one shared dissolution lane, no second trigger.

The only delta from the review is cosmetic: framing the parser explicitly as an INTERIM hand-Rust scaffold with a *_SCAFFOLD_MARKER const like the file's other §7 scaffolds (e.g. CLI_RUN_RUNTIME_WORKSPACE_ROOT_SCAFFOLD_MARKER). Given this is explicitly non-blocking, the PR is merge-past-ready (2/2 approvals accruing, lane-owner signed off, fold proven green-by-execution), and every push resets approvals + cancels the in-flight CI under active hourly main-merges, I'm not pushing a comment-only change now — the marker-const framing can land as a trivial follow-up in the 2-host-scaffold-classifier-defork lane without churning this head. — sent from valiant-ant-115

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

CI red @ 7e275f8 — INHERITED whole-corpus floor timeout, not this diff

Decomposition of run 29178731365 (job ci, 4h31m → fail):

  • build job: PASS (2m25s) — artifact verification green (15 bins present + non-empty). The cross-slot baked-path panic that killed the 31s runs is gone (workspace_root: derive at runtime from cwd (fix cross-runner shared-binary panic, main red) #6484 in-tree): the job ran 4.5 hours, well past the early-panic point.
  • batch 1 dag_compile_clean_gate_passes: ✓ PASS (03:55) — the full fold compiles clean under CI's -D warnings.
  • batch 2 (witness corpus): preempted by the 270-minute action timeout — ##[error]The action 'gunbc ci (.dag witnesses + gates)' has timed out after 270 minutes, floor_outcome=failure floor_peak_post=47411183616 (censored lower bound — the process was killed while running, not a peak read at completion).
  • Zero witness reds: no DIVERGENCE, no witness fail, no REFUS, no panic anywhere in the batch-2 log before the wall-clock kill. The only failure is the window running out on the full corpus.

Why inherited, not a regression here: this PR touches cli_run.rs + 638 test-entry stamps, so the affected set is the whole tree — it runs the full witness corpus, which is the exact scenario the 270-min floor budget already cannot complete on main (the window was escalated 60→270 and rows were offlined in #6488 for precisely this reason). The git diff does not touch the floor transport or add per-witness cost. Proven green-by-execution locally: floor_skip_discovery_witness exit 0, 13/13 targeted unit tests incl. the discriminating never-skip RED tooth.

Per the lane owner's merge-past posture (loyal-wren-398, sign-off above; same as #6482/#6485/#6494): functionality is green-by-execution, the CI-red is the inherited whole-corpus floor-window insufficiency, not a defect in this change. Stays merge-past-ready for the operator. — sent from valiant-ant-115

@briansrls
briansrls merged commit 5b2f412 into main Jul 12, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/valiant-ant-115 branch July 12, 2026 16:56
gunbai-bot Bot pushed a commit that referenced this pull request Jul 12, 2026
ci_layer_roots: union — wet-exclusion entries + main's test/fixture/floor_skip/
dir-grain row. runnable_resource_profile_witness_test: union — execution_mode_eq
import + main's #6479 live-tree disposition decl. ci_floor_measurement_per_shard_test:
deletion stands — its witness subjects (pinned-width measurement rows) were
retired by the governor; main's edit there was the mechanical disposition decl.
Proven: profile/ci_floor umbrellas + drift gate PASS on the resolved tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 13, 2026
… 5s rule, whole-corpus red burn-down (#6506)

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Hermetic floor: pre-commit fmt hook (generated), execution-mode envelope on runnable profiles, checkout-read carve-out, bin-witness wet lane

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Adaptive AIMD memory governor replaces the pinned spawn-width constants (operator ruling 2026-07-12)

The hand-edited width machinery — per-shard peak samples, executor base
overhead, usable-fraction, memory-derived width folds, spawn_width_cap pins,
and the per-plan *_plan_spawn_width fns the executor evaluated by name — is
DELETED. Run-time concurrency is now governed adaptively (TCP-shaped):

- v1_compiler::memory_governor: AIMD admission against the slot's OWN cgroup
  budget (memory.high > memory.max > MemTotal; GUNBC_MEMORY_BUDGET_BYTES
  override). Graceful hold on creep (memory.current past 4/5 high-water, PSI
  some avg10 > 10, swap growth per sample) — swap/reclaim buffer the overshoot
  so creep is not loss; multiplicative back-off (halve, floor 1) only on hard
  events (memory.events high/oom_kill deltas); additive re-growth on calm
  completions; active==0 always admits (progress floor, counted forced_serial).
  Every degradation is typed, counted, and surfaced in the [governor] receipt
  line (DESIGN §5: loud bounded degradation, never an absorbing widen). Pure
  decision core unit-tested without cgroups (12 tests).
- cli_run: DiscoveryWidthPolicy { Serial, Adaptive } replaces parallel_width;
  adaptive pool drains entry-groups through lazily admitted workers (one
  whole-tree index per worker, amortized across pulled groups); workers retire
  between groups when the window halves; undrained-queue-without-error refuses.
  Serial keeps the width-1 closure-drift oracle.
- claim_executor: plan-evaluated spawn width deleted (with the absent-width-fn
  FATAL wiring-gap class); gate resolve-groups draw AdmittedSlots from the same
  governor; cgroup sensor fns single-authority in the governor module; walk
  memo key becomes a typed (entry, ExecutionMode) tuple (review follow-up).
- .dag: RunnableDiscoveryBatch loses spawn_width_cap; RunnableMemoryClass
  degrades to payload-less Negligible|Substantial markers (the predicted-peak
  bytes were the hack); gunbc.ci_floor_measurement keeps only INTER-run rows;
  width witness cluster deleted; gunbc_ci_adaptive_width_note carries the model
  story and the dissolve-on (graph-derived per-node demand).
- regen: std_execution_mode.rs twin registered (latent gap from the
  ExecutionMode re-home — fresh self-compile emitted it unregistered, so the
  regen gate would have refused on first execution); stage0 + stage0_core
  rosters updated; regen_stage0 --verify green (divergence 0).

Proofs by execution (release): adaptive smoke ramps 1→2 workers and passes 3/3;
RED control (1MB budget) pins width 1 with forced_serial=1 counted and still
completes; whole-tree compile-clean green through the new plan schema; witness
files green (profile, measurement, width, floor plan, disposition lens);
generated-artifact regen gate green with zero drift; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor slow-start overshoot fix: admission pacing on first-cost digestion + MemAvailable budget fallback

CI run 29180195694 (first governor run): the uncapped runner cgroup fell the
budget through to MemTotal, and additive increase ran at unit-completion speed
(instant skip decisions) while each worker's real demand (whole-tree index
build, 3-5GiB) lands 30-60s after admission — width blasted 1→16 before any
build allocated, current hit physical RAM at pool+2min, swap filled, PSI 68,
the runner agent starved and GitHub killed the job.

Fix 1 — admission pacing: at most one admitted-but-undigested worker at a
time; the digest point is the front-loaded cost landing (index build + runner
resolve returned), not first unit completion, so a slow first eval cannot
freeze the pump, and a worker that dies before digesting clears its debt on
release. Ramp rate becomes the index-build rate — the demand-relevant clock —
and overshoot is bounded to one worker's build. Typed hold reason
(AwaitFirstCost), episode-counted in the receipt as pacing_holds.

Fix 2 — budget fallback order gains /proc/meminfo MemAvailable before
MemTotal: on uncapped hosts the kernel's availability estimate excludes the
co-tenant baseline (the runner agent) instead of handing the floor the whole
box.

Proofs: 15/15 governor unit tests (pacing hold/unblock, dead-worker debt
clear, meminfo exact-key parse); calm smoke 3/3 PASS ramping to width 2 with
receipt; RED control (1MB budget) pins width 1, forced_serial=1, completes.
The 4 cli_run lib test failures are pre-existing environmental (tmp-fixture
vs workspace-root pin), identical at the pre-fix head.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: budget-exceeded is a hard event (reachable multiplicative decrease on uncapped runners)

Run 29181858455 (paced governor): admission pacing and the high-water hold
worked — [governor] holding admissions at 43.5GiB — but in-flight workers'
own growth (request-major re-resolves of heavy closures, multi-GB each)
blew through the 20% buffer to 52.6GiB in seventy seconds with zero new
admissions, and on a runner whose cgroup sets no memory.high/max the
memory.events counters never move, so the multiplicative-decrease arm was
unreachable: hold was the governor's strongest response, and hold cannot
shed demand.

The budget is the declaration, so crossing it IS a hard event: halve the
window (episode-counted with hysteresis — one halving per crossing,
re-armed only below high-water so oscillation at the line cannot halve per
poll), and should_retire drains workers between units, freeing their
indexes. Three declared zones: below high-water admit+grow; high-water to
budget hold (the buffer absorbs); above budget halve+drain. No new
constant: the zone edges are the declared budget and the existing policy
fraction.

Receipt gains budget_exceeded=N. Proofs: 16/16 governor unit tests (exceed
halves once per episode, hysteresis re-arm below high-water, drain
reachable); RED smoke (1MB budget) fires the arm live — hard_backoffs=1
budget_exceeded=1 forced_serial=1, run still completes 3/3; calm smoke
unchanged (ramp to 2, budget_exceeded=0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: creep-episode edge is multiplicative decrease (ECN semantics, not stop-and-hope)

Run 29182481051 proved hold-only creep handling cannot save the box: the
pacing ramp was correct, the hold fired at 47.9GiB, the budget-exceed halve
fired at 51.7GiB — and the box still died at 52.7GiB eighty seconds later,
because already-admitted workers' residency grows ~1GiB/min each
(request-major closure accumulation) and the exceed line sits one gigabyte
from physical death: no margin for drain latency plus the allocator's
freed-page plateau.

Creep IS the early congestion signal — TCP's ECN mark, not its loss. The
first hold of a creep episode (high-water, PSI, or swap growth) now halves
the window too, so workers drain while the high-water→budget buffer still
has ~10GiB of margin. One halving per episode, re-armed on the next
admission; the budget-exceed halve stays as the backstop; the creep arm
moves ahead of window-full so a full window cannot mask the edge, and
completions observe the same edge (the only polls at a full window).
graceful_holds renamed creep_backoffs — the receipt now says what the
episode does.

Proofs: 16/16 governor unit tests (edge halves once per episode, drain
reachable, re-arm on admission); RED smoke fires creep back-off, budget
exceed, and progress floor live and still completes 3/3; calm smoke
unchanged (ramp to 2, creep_backoffs=0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: measured-share headroom gate (predictive admission) + budget-exceed collapses to width 1

Run 29183064852 was the decisive datapoint on reactive-only control: the
creep back-off caught the high-water crossing within one poll (41.287 vs
41.286 GiB) and halved 16->7, the budget-exceed halve fired at 51.7 —
and the box still died at 52.7 GiB, because ~14 admitted workers'
residency was maturing at ~18GiB/min, drain latency is a group boundary
away, and exited workers' pages never return within a run (allocator
plateau). Reactive arms observe demand minutes after the admission that
committed it; at that lag they are structurally too late.

The predictive complement, with no authored constant: the run measures
its own per-worker share — memory.current at the first poll is the pool
baseline, and the first slot's digest fixes share = current - baseline —
and admission then requires current + share <= high-water. The old
2h26m run that sat stable at width 7 / 38.5GiB is the existence proof
that an equilibrium exists; this gate finds it from the run's own
measurements instead of the deleted calibration constants. Typed
episode-counted hold (InsufficientHeadroom, headroom_holds), window
untouched (prediction is not a creep event).

Budget-exceed escalates from halve to collapse-to-1: it is TCP's
timeout, not its duplicate-ACK — when the crossing is discovered a
gigabyte from death, every growing worker beyond the first must stop at
its next group boundary.

Proofs: 17/17 governor unit tests (gate predicts below high-water,
episode edges, resume on settle; exceed collapse + hysteresis re-arm);
calm smoke arms the gate ('measured worker share ... headroom gate
armed') and still ramps to 2, 3/3 PASS; RED smoke fires creep back-off,
exceed collapse, and progress floor, still completes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: admission ceiling at half the budget (the maturation reserve) + budget-chain doc sync

Run 29183727188 exposed the last measurement lie: the headroom gate armed
with a 0.48GiB share measured at the first worker's index-build digest,
but the mature per-worker footprint is ~3.5GiB — admitted demand matures
MINUTES after admission at ~7x its digest-time footprint, so any share
measured at digest under-prices the future and the gate admitted the same
fatal ramp (creep 16->7 at 41.2GiB, exceed collapse 7->1, dead at 52.5GiB,
SIGTERM).

The honest arm this yields is TCP's own ssthresh: admissions stop once
memory.current crosses HALF the budget — the other half is the maturation
reserve for in-flight growth the signals cannot see yet. Dimensionless
policy fraction like the high-water line; no workload constant. On run
29183727188's curve this stops admission at ~25.7GiB / width ~8, and the
2h26m run that sat stable at width 7 / 38.5GiB is the existence proof
that the resulting equilibrium fits. Typed episode-counted hold
(AdmissionCeiling / ceiling_holds).

Also syncs the budget-chain documentation cursor's review caught drifting
(single-authority): gunbc_ci_adaptive_width_note and the module header now
describe the implemented chain (memory.high > memory.max > MemAvailable >
MemTotal) and the full controller (pacing, measured-share gate, ceiling,
creep-edge halve, exceed collapse).

Proofs: 18/18 governor unit tests (ceiling holds past budget/2 while calm,
episode-counted, resumes below; window untouched); calm smoke ramps to 2
with ceiling_holds=0; RED smoke completes with every arm counted;
whole-tree compile-clean green on the .dag note edit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* githooks_pre_commit_emit: explicit dissolve-on for the concat-built shell (review follow-up)

The pre-commit hook's shell-via-concat carried its medium-as-string debt
implicitly through the pre-push sibling's roster; the note now cites its
own dissolution trigger (grammar-path shell emission superseding the
concat-built literals, one trigger for the hook-emit family).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Dissolve single-variant ExecutionMode predicates (review follow-up)

execution_mode_is_record was dead on both surfaces (zero callers);
execution_mode_is_hermetic was a single-variant Bool nickname over the
coproduct. Effect-io host dispatch sites now read directionally through
execution_mode_is_wet_dispatch (the semantically-real fact: Wet|Record
dispatch to live transports, Hermetic replays fixtures); witness-test
assertions go through execution_mode_eq against the expected variant.
Seed regenerated via regen_stage0 (16-line drop mirrors the .dag).

Proof: crate builds clean with the fns deleted (no Rust callers);
effect_io_host_mode_test 4/4 PASS by execution (wet_does_not_replay +
hermetic_write_fail_closed discriminate the arm-flip); profile and
ci_floor_plan witness umbrellas PASS; zero residual references.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Resolve main merge conflicts (auto-WIP-commit swept the conflicted tree)

ci_layer_roots: union — wet-exclusion entries + main's test/fixture/floor_skip/
dir-grain row. runnable_resource_profile_witness_test: union — execution_mode_eq
import + main's #6479 live-tree disposition decl. ci_floor_measurement_per_shard_test:
deletion stands — its witness subjects (pinned-width measurement rows) were
retired by the governor; main's edit there was the mechanical disposition decl.
Proven: profile/ci_floor umbrellas + drift gate PASS on the resolved tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* Fast-lane 5-second rule: cooperative eval deadline + long/ test home (operator ruling 2026-07-12)

A witness whose own eval reaches 5s does not run in per-PR discovery.
Three layers, one authority:

- Authority: gunbc_ci_fast_lane_witness_eval_budget (Second, =5) +
  gunbc_ci_fast_lane_eval_budget_ms projection in v2.workflow.ci_floor_plan,
  with the rule note. claim_executor reads it fail-closed when a plan
  schedules a discovery batch (missing/mistyped row refuses the run;
  discovery-free plans never read it).
- Enforcement: cooperative per-witness eval deadline in v1_interpreter
  (checked every 4096 eval dispatches; typed EvalBudgetExceeded unwinds
  from inside eval — in-process worker threads have no kill authority,
  the Phase A lesson). Armed in run_claim_measured from the ctx-level
  budget; resolve/index cost is infra and never counted (operator
  carve-out). claim_batch gains --eval-budget-ms for local audits.
- Home: test/claim/long/ excluded from discovery at dir grain
  (ci_layer_roots + note). First receipted residents: s1_closure_receipt
  (90+min whole-closure re-parse, the run-29183446733 wedge) and
  self_host_module_emit_derisk (~31s/witness), modules renamed
  v2.test.manual.* -> v2.test.long.*.

Proof by execution: RED control fires (1ms budget on a 19ms-eval witness
-> typed FAIL naming it); calm control passes unbudgeted; the wedge
witness dies in 10s total instead of 90+min (4s resolve uncounted,
refusal at 5.002s eval); moved files resolve at their new home; drift
gate PASS. This is the wedge tourniquet: the class that burned 243 of
270 billed minutes in silence now fails red in seconds, by name.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Home #6512's classical_not equals_eval witness in the execution corpus

The merge from main brought emit_host_classical_not_ingested_equals_eval_test.dag
into test/claim/manual/ — the emit_host wet transport class (hermetic discovery
refuses it: emit_host_run_transport, no mock arm). Moved to the execution corpus
home (src/v2/test/claim/execution/, Wet-profiled explicit batch) beside its 12
siblings; proven wet at the new home incl. the swapped-refuses RED control.
Other #6512 witness files pass hermetically in place (rust_test,
match_infer_fail_open_audit; body_lowering_match carries no test fns).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* CI retrigger: supersede wedged queued run 29206348113 (cancel would not propagate)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Burn down run-29208529942's 11 floor failures (first full-floor receipt: 12min, typed per-witness list)

Three classes, all addressed:

Budget class (6 witnesses / 5 files at 5.0-6.4s on the runner): moved to long/
homes — the two dag-side files the first sweep missed (module_graph
import_closure_live, reference_closure_equivalence; dag/test/claim/long/ now
exists), dag_import_block_lexeme_stamp, syntactic_audit_witness,
string_head_linear. Plus proactive moves of the audit's remaining >5s
native-heavy witnesses that the stride blind spot had silently greened and this
run's node-frontier selection happened to skip (derived_machinery_exempt_live
21.7s, inert_lens_hygiene 19.3s, shadow_mask_red / live_anchored_modules_clean
9.9s): latent reds under the completion-side check, moved before they fire.
The local timing distribution is bimodal (>=5s or <3s; empty 3-5s band), so
runner slowdown cannot create new stragglers from the passing set.

IsExecutable class (3 witnesses / 2 files): double enrollment — parse_test
floor/perf and dag_compile_clean_perturb_receipts were declared BOTH in
bin_witness_wet_entries (the Wet bin lane) and as commit_workflow
CorpusWitnessKind rows, so the corpus projection ran them a second time inside
the hermetic discovery batch where run_witness_bin refuses. Deleted the
commit_workflow rows (§3 one-fact-one-roster; the bin lane keeps per-PR
coverage), recorded beside the deletion.

Bare-false class (2): medium_structure exception-roster growth ratchet bumped
58 -> 59 for the justified pre-commit-emitter row (the ratchet doing its job);
floor_diff_observe_witness moved to the execution corpus — it shells real git
diff, which hermetic mode folds into its Fail arm, so its home is the Wet
per-PR lane (green there incl. fail-closed arms). Named follow-on: a git
read-only observation carve-out (diff between SHAs is commit-deterministic,
same argument as the repo-tree read carve-out).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Resolve #6516 merge: governor pool keeps main's floor observability (ShardStyle threading, categorization, fmt)

The auto-WIP commits 081c00a/4cdaca3e captured the merge mid-resolution;
this completes it: run_discovery_rows takes both fast_lane_eval_budget_ms
(mine) and ShardStyle (main's #6516); Serial arm passes shard_id 0/count 1;
adaptive workers get spawn-ordinal shard ids with spawn-time target width.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Repoint 4 stale entry paths left by the long/ move round (caught: module_grain equivalence tests red)

The dag-side/second-round long/ moves postdated the 12-min floor receipt
and the 212/0 lib-suite run, so nothing had re-executed these references:
- cli_run.rs module_grain sample entries (x2) -> dag/test/claim/long/
  (both equivalence tests + wiring-perturbation control green locally, 162s)
- extdeps_external_authority_transport ClaimRun rows (x2) -> src/v2/test/claim/long/
  (both claims PASS by execution at new homes, 10.0s / 21.8s)
- complexity_linearity_audit.rs diagnostic pointer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Fast-lane eval budget: denominate in thread CPU time, not wall (fix realization_vocab_clean_tree contention flake)

Run 29215148169 red on realization_vocab_clean_tree_holds at 5004ms > 5000ms
in the hermetic discovery batch. Its genuine eval is ~3.4s (measured local
eval_self); the extra ~1.6s is cold-I/O (a ReadsLiveTree whole-corpus scan)
plus governor time-slicing under the concurrent worker pool. By the operator
5s rule's own 'assuming the infra isn't the problem' clause, a 3.4s-compute
witness must not be misclassified as a long/ resident because CI contention
inflated its WALL time.

Root fix: the fast-lane budget (both the cooperative stride-poll deadline and
the completion-side check) now measures THREAD CPU TIME (CLOCK_THREAD_CPUTIME_ID),
which advances only while the thread runs on a core. A genuine non-terminating
eval burns CPU and is still caught; a bounded scan whose wall time was inflated
by I/O waits or scheduler contention is not. Switching wall->CPU can only make
witnesses pass more easily (CPU <= wall), so it introduces no new failures.

Proven by execution: clean_tree --eval-budget-ms 5000 -> PASS (CPU < 5s);
--eval-budget-ms 500 -> REFUSE at 503ms (deadline still fires accurately).
budget_completion unit tests green; all-targets compile clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 15, 2026
…e-tree stamp

Two fixes from the docs-enforcement audit (operator-directed):

1. bind: provenance row in accelerator_demo_plan.dag makes
   docs/plans/machine-shape-orthogonal-scheduling.md doc-graph-reachable
   (the established hand-authored-design-md convention: accelerator_demo_plan
   :51, live_read_classification.dag:66). Registration as a gunbc.plan.Plan
   row stays the md's declared Phase-1 dissolution — registering now would
   flip the actively-evolving doc into a generated artifact prematurely.
   Verified by build_doc_graph_report replication: doc_count=107,
   orphan_count 1->0, dangling 0.

2. doc_reachability_witness_test live_tree_disposition: SubstrateInputsOnly
   -> ReadsLiveTree. The 2026-07-12 machine stamp (#6479 entry-text batch)
   was false: every test fn reads the live docs/ tree via doc_graph_* host
   builtins — the exact classifier blind spot live_tree.dag:5 declares.
   The false stamp made the orphan wall predict-skippable, which composed
   with the docs-only floor shortcut into a pre-merge false-green (this PR
   minted an orphan with green CI). ReadsLiveTree restores the never-skip
   tooth: the wall now runs on every full floor, including this PR's.

This diff leaves the docs-only shortcut class, so this PR runs the full
floor with the corrected stamp — the wall itself verifies the de-orphan
by execution, pre-merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 15, 2026
…6659)

* WIP: Sweep the 2026-07-12 machine-stamped SubstrateInputsOnly batch (#6479) f

* WIP: Sweep the 2026-07-12 machine-stamped SubstrateInputsOnly batch (#6479) f

* WIP: Sweep the 2026-07-12 machine-stamped SubstrateInputsOnly batch (#6479) f

* WIP: Sweep the 2026-07-12 machine-stamped SubstrateInputsOnly batch (#6479) f

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
briansrls added a commit that referenced this pull request Jul 15, 2026
…rule, convergence map (#6654)

* WIP: map reduce

* WIP: map reduce

* WIP: map reduce

* WIP: map reduce

* machine-shape plan: end shape agreed, no-kind rule, convergence map to existing carriers

- §2 terminal model pinned (operator rulings 2026-07-15): one locality lattice
  (lifted to std, converging BOTH existing latency enums), divergence/idle-lane/
  crossing laws, Placement dissolution trigger, kind-erasure at the
  ComputeHost→MachineShape derivation boundary
- convergence map: every end-shape element bound to its existing carrier
  (HardwareThreadCount reused for lane_count; PlacementSupplyRow identified as
  the degenerate single-domain MachineShape; PTX ThreadHierarchyShape/PtxCost
  gain their consumer; MemoryKind.UnifiedShared flagged as topology-in-technology)
- MemoryLevel.sharing dropped: sharing derives from SharedLevelEdge graph
  structure (single authority)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: address operator request-changes (7 blocking findings)

- MachineShape is now a representable graph: DomainId/LevelId identities,
  explicit edge endpoints, SharedLevelEdge references the owner's level by id
  (embedding duplicated it), InterconnectLink coproduct holds NetworkAttach
  (LinkEdge was PcieLink-only while the map claimed NetworkInterface as a fill),
  terminal Placement = DomainId reference; dangling refs refuse
- Phase 3 batching vs signed scheduling authority: conflict acknowledged, now
  an EXPLICIT supersession proposal (topology = pure fn of declared shape;
  MeasuredBy banned from topology; schedule_eq generalized to equal-given-equal-
  declared-inputs) gated on operator sign-off, with a confined fallback
- both §5 fallback arms converted to refusals: Priced|PricingRefused{missing}
  (no term-incomplete Predicted accounts), Placed|PlacementRefused{missing}
  (no stay-at-current-domain answer)
- Quantified<T> restructured: Precision (Exact|Interval) x Evidence
  (Cited|MeasuredBy{ExecutionReceiptDigest}|DerivedFrom) — evidence-bearing
  constructors make the authored-literal RED enforceable
- locality/latency split into two axes: latency = per-level magnitude with one
  std class projection (converging ReadLatencyClass + network LatencyClass);
  locality = graph-derived, domain-relative (no universal total order)
- OperandFlow total derivation spelled out: operand_root (fail-closed), hash-
  authority convergence precondition (v2.std.node.Hash vs ContentHash — the
  fnv1a64 thread), edge->root mapping for node_keyed_graph_transitive_bytes,
  OperandFlowRefused rows
- AssociativityEvidence subject-bound: {combine, inhabitant, law, receipt},
  license requires structural identity with the scheduled combine; keyed-patch
  witness scoped to mechanism-precedent-only; within-fold expansion scoped
  kernel-internal (never central Schedule topology)
- corrections: PlacementSupplyRow has zero production callers (grep -l
  overcount); document-level dissolution trigger added (Plan-row registration
  = part of Phase 1 definition of done)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* de-orphan machine-shape plan doc + correct doc_reachability lying live-tree stamp

Two fixes from the docs-enforcement audit (operator-directed):

1. bind: provenance row in accelerator_demo_plan.dag makes
   docs/plans/machine-shape-orthogonal-scheduling.md doc-graph-reachable
   (the established hand-authored-design-md convention: accelerator_demo_plan
   :51, live_read_classification.dag:66). Registration as a gunbc.plan.Plan
   row stays the md's declared Phase-1 dissolution — registering now would
   flip the actively-evolving doc into a generated artifact prematurely.
   Verified by build_doc_graph_report replication: doc_count=107,
   orphan_count 1->0, dangling 0.

2. doc_reachability_witness_test live_tree_disposition: SubstrateInputsOnly
   -> ReadsLiveTree. The 2026-07-12 machine stamp (#6479 entry-text batch)
   was false: every test fn reads the live docs/ tree via doc_graph_* host
   builtins — the exact classifier blind spot live_tree.dag:5 declares.
   The false stamp made the orphan wall predict-skippable, which composed
   with the docs-only floor shortcut into a pre-merge false-green (this PR
   minted an orphan with green CI). ReadsLiveTree restores the never-skip
   tooth: the wall now runs on every full floor, including this PR's.

This diff leaves the docs-only shortcut class, so this PR runs the full
floor with the corrected stamp — the wall itself verifies the de-orphan
by execution, pre-merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* bind main's orphaned no-smuggled-programs-wall.md from its lens carrier

The doc merged to main orphaned (docs-only shortcut + then-lying
doc_reachability stamp — the same false-green class this PR fixes).
With the stamp corrected, the orphan wall's first live pre-merge run
(this PR's floor) caught it: 1 of 1880 witnesses red. Bound from
medium_structure_containment.dag, the wall the design doc signs —
same bind-from-carrier convention as accelerator_demo_plan.dag:51.

Verified by build_doc_graph_report replication on the merged tree:
doc_count=108, orphan_count 1->0, dangling 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: apply #6663 review amendments 1+2

- Amendment 1: the 'evidence carried by construction' claim is gated on the
  record-field wall (witness-realization P0 / #6663 audit F1) — the
  typechecker checks field NAMES only (refuted-by-execution: Known omitting
  evidence compiles at 0 diagnostics); P0 named a Phase-1 acceptance
  precondition. Asymmetry recorded: the no-kind wall rests on field-name
  checking, which DOES hard-error — it holds today; evidence-required does not.
- Amendment 2: Phase 2 claims the DerivedFrom fill of CostAccount.space only;
  the AIMD governor's dissolve-on additionally requires MeasuredBy per-runnable
  peaks (witness-realization P1) — derived operand footprint and measured peak
  are different space facts (receipt: 6.25GB VmSize vs KB operands — retention,
  not operands; the v1 run-stability axis).
- Cross-refs: P4 composition note in the supersession paragraph; P1 named
  third party to the Quantified/CostBasis convergence (one carrier, not three;
  realization_measurement.dag merge-order flagged); Energy/Watt divergence
  deduped with audit F3 (owner TBD).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* heal main's composed drift + re-anchor vacuity design docs (unblocks all full-floor PRs)

Main's tree (post #6638/#6664) fails generated_artifact_drift_gate_passes on
every full floor: the vacuity lane hand-added a 'Sibling family' paragraph to
the GENERATED docs/plans/inert-layer-lens.md without updating its generating
Plan row (dag/gunbc/plans/inert_layer_lens.dag) — committed != regenerated.
Their docs-only PRs merged through the docs-only shortcut, which skipped both
the drift gate and the doc-graph wall.

1. Regenerate inert-layer-lens.md (paragraph removed; byte-identical to
   warm-crab-65's independent main_wet regen on #6658 — same blob 2b36cf2).
2. That hand-edit was ALSO the only doc-graph anchor for the vacuity lane's
   two design docs; regen alone orphans vacuity-lens-design.md and (via its
   link chain) lens-consolidation-design.md. Re-anchored with a bind:
   provenance row in dag/std/materialization_ladder.dag — the file whose
   AuthoredDuplication verdict the vacuity doc's load-bearing correction is
   about — migrating to the vacuity lens .dag carrier when it lands.

Verified by build_doc_graph_report replication: doc_count=110,
orphan_count=0, dangling=0.

Follow-up for the vacuity lane: re-add the sibling-family paragraph via the
inert_layer_lens Plan row (the authority), not the generated md.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
… evidence carriers, Energy, scheduling-invariant refinement) (#6685)

* WIP: map reduce

* WIP: map reduce

* WIP: map reduce

* WIP: map reduce

* machine-shape plan: end shape agreed, no-kind rule, convergence map to existing carriers

- §2 terminal model pinned (operator rulings 2026-07-15): one locality lattice
  (lifted to std, converging BOTH existing latency enums), divergence/idle-lane/
  crossing laws, Placement dissolution trigger, kind-erasure at the
  ComputeHost→MachineShape derivation boundary
- convergence map: every end-shape element bound to its existing carrier
  (HardwareThreadCount reused for lane_count; PlacementSupplyRow identified as
  the degenerate single-domain MachineShape; PTX ThreadHierarchyShape/PtxCost
  gain their consumer; MemoryKind.UnifiedShared flagged as topology-in-technology)
- MemoryLevel.sharing dropped: sharing derives from SharedLevelEdge graph
  structure (single authority)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: address operator request-changes (7 blocking findings)

- MachineShape is now a representable graph: DomainId/LevelId identities,
  explicit edge endpoints, SharedLevelEdge references the owner's level by id
  (embedding duplicated it), InterconnectLink coproduct holds NetworkAttach
  (LinkEdge was PcieLink-only while the map claimed NetworkInterface as a fill),
  terminal Placement = DomainId reference; dangling refs refuse
- Phase 3 batching vs signed scheduling authority: conflict acknowledged, now
  an EXPLICIT supersession proposal (topology = pure fn of declared shape;
  MeasuredBy banned from topology; schedule_eq generalized to equal-given-equal-
  declared-inputs) gated on operator sign-off, with a confined fallback
- both §5 fallback arms converted to refusals: Priced|PricingRefused{missing}
  (no term-incomplete Predicted accounts), Placed|PlacementRefused{missing}
  (no stay-at-current-domain answer)
- Quantified<T> restructured: Precision (Exact|Interval) x Evidence
  (Cited|MeasuredBy{ExecutionReceiptDigest}|DerivedFrom) — evidence-bearing
  constructors make the authored-literal RED enforceable
- locality/latency split into two axes: latency = per-level magnitude with one
  std class projection (converging ReadLatencyClass + network LatencyClass);
  locality = graph-derived, domain-relative (no universal total order)
- OperandFlow total derivation spelled out: operand_root (fail-closed), hash-
  authority convergence precondition (v2.std.node.Hash vs ContentHash — the
  fnv1a64 thread), edge->root mapping for node_keyed_graph_transitive_bytes,
  OperandFlowRefused rows
- AssociativityEvidence subject-bound: {combine, inhabitant, law, receipt},
  license requires structural identity with the scheduled combine; keyed-patch
  witness scoped to mechanism-precedent-only; within-fold expansion scoped
  kernel-internal (never central Schedule topology)
- corrections: PlacementSupplyRow has zero production callers (grep -l
  overcount); document-level dissolution trigger added (Plan-row registration
  = part of Phase 1 definition of done)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* de-orphan machine-shape plan doc + correct doc_reachability lying live-tree stamp

Two fixes from the docs-enforcement audit (operator-directed):

1. bind: provenance row in accelerator_demo_plan.dag makes
   docs/plans/machine-shape-orthogonal-scheduling.md doc-graph-reachable
   (the established hand-authored-design-md convention: accelerator_demo_plan
   :51, live_read_classification.dag:66). Registration as a gunbc.plan.Plan
   row stays the md's declared Phase-1 dissolution — registering now would
   flip the actively-evolving doc into a generated artifact prematurely.
   Verified by build_doc_graph_report replication: doc_count=107,
   orphan_count 1->0, dangling 0.

2. doc_reachability_witness_test live_tree_disposition: SubstrateInputsOnly
   -> ReadsLiveTree. The 2026-07-12 machine stamp (#6479 entry-text batch)
   was false: every test fn reads the live docs/ tree via doc_graph_* host
   builtins — the exact classifier blind spot live_tree.dag:5 declares.
   The false stamp made the orphan wall predict-skippable, which composed
   with the docs-only floor shortcut into a pre-merge false-green (this PR
   minted an orphan with green CI). ReadsLiveTree restores the never-skip
   tooth: the wall now runs on every full floor, including this PR's.

This diff leaves the docs-only shortcut class, so this PR runs the full
floor with the corrected stamp — the wall itself verifies the de-orphan
by execution, pre-merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* bind main's orphaned no-smuggled-programs-wall.md from its lens carrier

The doc merged to main orphaned (docs-only shortcut + then-lying
doc_reachability stamp — the same false-green class this PR fixes).
With the stamp corrected, the orphan wall's first live pre-merge run
(this PR's floor) caught it: 1 of 1880 witnesses red. Bound from
medium_structure_containment.dag, the wall the design doc signs —
same bind-from-carrier convention as accelerator_demo_plan.dag:51.

Verified by build_doc_graph_report replication on the merged tree:
doc_count=108, orphan_count 1->0, dangling 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: apply #6663 review amendments 1+2

- Amendment 1: the 'evidence carried by construction' claim is gated on the
  record-field wall (witness-realization P0 / #6663 audit F1) — the
  typechecker checks field NAMES only (refuted-by-execution: Known omitting
  evidence compiles at 0 diagnostics); P0 named a Phase-1 acceptance
  precondition. Asymmetry recorded: the no-kind wall rests on field-name
  checking, which DOES hard-error — it holds today; evidence-required does not.
- Amendment 2: Phase 2 claims the DerivedFrom fill of CostAccount.space only;
  the AIMD governor's dissolve-on additionally requires MeasuredBy per-runnable
  peaks (witness-realization P1) — derived operand footprint and measured peak
  are different space facts (receipt: 6.25GB VmSize vs KB operands — retention,
  not operands; the v1 run-stability axis).
- Cross-refs: P4 composition note in the supersession paragraph; P1 named
  third party to the Quantified/CostBasis convergence (one carrier, not three;
  realization_measurement.dag merge-order flagged); Energy/Watt divergence
  deduped with audit F3 (owner TBD).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* heal main's composed drift + re-anchor vacuity design docs (unblocks all full-floor PRs)

Main's tree (post #6638/#6664) fails generated_artifact_drift_gate_passes on
every full floor: the vacuity lane hand-added a 'Sibling family' paragraph to
the GENERATED docs/plans/inert-layer-lens.md without updating its generating
Plan row (dag/gunbc/plans/inert_layer_lens.dag) — committed != regenerated.
Their docs-only PRs merged through the docs-only shortcut, which skipped both
the drift gate and the doc-graph wall.

1. Regenerate inert-layer-lens.md (paragraph removed; byte-identical to
   warm-crab-65's independent main_wet regen on #6658 — same blob 2b36cf2).
2. That hand-edit was ALSO the only doc-graph anchor for the vacuity lane's
   two design docs; regen alone orphans vacuity-lens-design.md and (via its
   link chain) lens-consolidation-design.md. Re-anchored with a bind:
   provenance row in dag/std/materialization_ladder.dag — the file whose
   AuthoredDuplication verdict the vacuity doc's load-bearing correction is
   about — migrating to the vacuity lens .dag carrier when it lands.

Verified by build_doc_graph_report replication: doc_count=110,
orphan_count=0, dangling=0.

Follow-up for the vacuity lane: re-add the sibling-family paragraph via the
inert_layer_lens Plan row (the authority), not the generated md.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: record operator rulings 5-8 (2026-07-15)

- R5 compute_fabric relationship: Shape IS the degenerate one-axis
  MachineShape; market stays thin (no #5904 rebuild); Fabric = outermost
  rung of the recursive supply tower. Convergence-map row added.
- R6 evidence carriers: staged convergence (Quantified for greenfield,
  P1 receipts reuse Evidence.MeasuredBy, CostBasis migrates on forced
  join); owner = #6663 lane.
- R7 Energy: derived quantity (Power x Time), lands Phase 1, is the
  F3 dedupe.
- R8 scheduling invariant REFINED not superseded (operator: determinism
  was being conflated with input-invariance — different machines are
  different inputs). Surviving wall: no UNSTABLE (MeasuredBy) inputs to
  topology; declared shape is a stable input; cross-host schedule_eq
  demoted to corollary under equal declared shapes. Phase 3 UNBLOCKED.

Open list rewritten: law-carrier home, SymbolIndex sequencing, hash
convergence (dispatched), P0 field wall (#6663) remain.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: map reduce

* machine-shape plan: reconcile §2/§3/§5/§8 with rulings 6-8 (cursor review on #6685)

Five stale spots aligned: Energy divergence now records ruling 7 (was
'flagging for operator'); the Quantified/CostBasis rows in §2 and the
convergence map record ruling 6's staged convergence (was 'open Q1');
§5's batching rule reads 'under the refinement' (was 'supersession');
§8's schedule_eq wall restated per ruling 8 (corollary under equal
declared shapes, not unconditional).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant