Skip to content

Wave 1 exit 1.6: ingested classical_not emit→compile→run equals_eval (PATH 1 int-bool octet bridge) - #6512

Merged
briansrls merged 83 commits into
mainfrom
consolidate-wise-koi-6510
Jul 12, 2026
Merged

briansrls merged 83 commits into
mainfrom
consolidate-wise-koi-6510

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Land Wave 1 exit witness emit_host_classical_not_ingested_equals_eval_holds: first real ingested fn body proven emit→compile→run→behaviorally-equal end-to-end for classical_not.

PATH 1 (emit bridge): At match sites where scrutinee is Int (octet wire) and patterns/bodies are bool-kw literals, emit lowers to scrutinee != 0 with octet 0/1 arm bodies — match domain stays boolean; Int at fn boundary is serialization only.

Infer: Restores int-channel arm typing (infer_match_bool_arm_body_type) required for ingested_classical_not_real_infer_holds and equals_eval green.

Audit fix: Reverts mistaken classical_not_int_match_arrow_real_infer_refuses_holds flip; complement witnesses renamed to *_refuses_unsupported_pattern_holds (fail-closed-correct for dag_complement_lit_* patterns).

Cleanup: Removes stray WIP body_lowering_match.dag from branch scope (kept locally under .git/info/exclude).

Test plan

Wet claim_batch on tip e1a39e55a4 — 9/9 PASS:

cargo run -q --bin claim_batch -- --source-root src/v2 --source-root dag \
  --entry src/v2/test/claim/manual/emit_host_classical_not_ingested_equals_eval_test.dag \
  --function emit_host_classical_not_ingested_equals_eval_holds \
  --function emit_host_classical_not_ingested_swapped_refuses_holds \
  --function ingested_classical_not_real_infer_holds \
  --function ingested_classical_not_match_only_param_scrutinee_infer_refuses_holds \
  --function ingested_classical_not_arrow_empty_domain_infer_refuses_holds \
  --entry src/v2/test/claim/manual/match_infer_fail_open_audit_test.dag \
  --function classical_not_int_match_arrow_real_infer_holds \
  --function complement_body_real_infer_refuses_unsupported_pattern_holds \
  --function complement_arrow_real_infer_refuses_unsupported_pattern_holds \
  --function classical_not_int_match_non_octet_arm_rejects_holds \
  --wet

Worker attestation

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why.
  • Tests run: claim_batch wet — 9/9 PASS (see above).
  • Closes work item: n/a (Wave 1 exit milestone).
  • No surprise commits.
  • No secrets / credentials / large binaries.

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37312) — Acknowledged. Verdict APPROVE stands; findings verified on frozen tip 2e856a5617, no merge-blocking action.

Finding 1 (octet-channel dissolution note vs tracked row): Valid §6 observation. target_value_expr_int_bool_octet_channel_dissolution_note names the concept but lacks the SeedRetained { migration_trigger: … } row style that body_lowering_interim_scaffold_row_match_hand_walker carries (migration_trigger: ^migrate_when_general_body_producer_lands). Agree this should gain a counted frontier row (or ROADMAP anchor to octet↔bool codec inhabitation) in post-exit FLAG D / breadth work — not a 1.6 merge blocker; bridge is honestly marked transient and proven by equals_eval + swapped RED.

Finding 2 (03_normalize deferred-lower dispatch): Verified. Deferred emitted surfaces (dag_surface_pattern, dag_surface_match_arm, dag_surface_match_arm_stmt_body) take the body_lower_finish(n, folded=n) path before normalize_sugar_finish, bypassing normalize_node_fold_children at that node — intentional: body_lower_finish descends internally. Covered green by body_lowering_match_* witnesses (normalize accepts, arms found, unnavigable-arm refuses). No bypass observed on current corpus; if a mid-recursion pattern gap surfaces, it will red there first.

Branch frozen at 2e856a5617 per operator hold — no push for scaffold-row follow-up here.

— sent from eager-heron-120

briansrls and others added 2 commits July 12, 2026 14:52
Operator ruling 2026-07-12 — fail fast while debugging the serial floor
wall separately. gunbc_ci_job_backstop drops 600m -> 180m accordingly.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

cursor/composer-2.5 APPROVE (@37321) — Verified on tip 35f212fa5d. Findings None stands: 1.6 scope intact (match body lowering, Int/bool octet emit bridge with explicit target_value_expr_match_is_int_bool_octet_channel gate, infer Int-scrutinee bool-literal arms, durable emit_host_classical_not_ingested_equals_eval + RED siblings). Scaffold markers present (body_lowering_interim_scaffold_rows, target_value_expr_int_bool_octet_channel_dissolution_note, infer_match_int_scrutinee_bool_literal_body_note). CI timeout 270m→60m carries receipt in gunbc_ci_floor_step_timeout_discovery_flip_note (fail-fast, not widen/skip). No code change required.

Merge readiness: 2× APPROVE (claude-opus-4-7 @37312 + composer-2.5 @37321), mergeable=CLEAN, ci job in flight on 35f212fa5d. Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37322) — All four notes verified on tip 35f212fa5d. Verdict APPROVE stands; none are merge-blocking. No code change on the frozen 1.6 slice.

Finding 1 (04_infer.dag infer_match_bool_arm_body_type + raw infer_match_int_scrutinee_bool_literal_body_note): Valid §6 observation — the Int body-type ground at arm-row construction is honestly marked but only as a String dissolve-on note, not a counted BodyLoweringInterimScaffoldRow / ConstructionJustification roster entry like body_lowering_interim_scaffold_row_match_hand_walker. Agree this should promote to a gated scaffold row (or share the octet↔bool codec migration_trigger) in post-exit FLAG D / breadth work; equals_eval + classical_not_int_match_non_octet_arm_rejects_holds already prove the channel is gated, not silent default.

Finding 2 (std/compilers/target_model.dag octet-channel bridge + classifier predicates): Valid pattern warning. Bridge is explicitly gated (target_value_expr_match_is_int_bool_octet_channel must hold before x != 0 rewrite); target_value_expr_int_bool_octet_channel_dissolution_note names codec inhabitation as the delete trigger. Classifiers are staging-only — they delete with the codec, not persist as a second authority (same post-exit debt as @37312 finding 1).

Finding 3 (body_lowering_fold.dag symbol_lexeme == "Bool" branch): Valid §3 fork seed; pre-existing "Int" lexeme pattern extended here, not a new category. Grounding target is a builtin type catalog (single authority for Int/Bool bindings), tracked for general-body-producer / namespace lane — out of 1.6 scope.

Finding 4 (CI 270m→60m): Confirmed operator-signed with cited receipt (gunbc_ci_floor_step_timeout_discovery_flip_note, run 29183446733). Fail-fast cap, not absorbing fallback.

Merge readiness: 2× APPROVE (composer-2.5 @37321 + claude-opus-4-7 @37322), mergeable=CLEAN, ci floor job still pending on 35f212fa5d. Not merging (operator manual merge policy).

— sent from eager-heron-120

briansrls and others added 2 commits July 12, 2026 16:10
…_workflow).

Run 29197126623 @ 35f212f killed at 60m with batch-1 PASS and batch-2 still in silent eval — ci_workflow already restored to 270m in 08c9f67 but ci.yml still carried 60m/180m caps.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

CI fix (0dc4de6) — Run 29197126623 failed because ci.yml still enforced 60m floor step / 180m job backstop while ci_workflow.dag was already restored to 270m in 08c9f67 (generated-artifact drift). Batch-1 compile-clean PASS; batch-2 killed mid silent eval at t=60m (0 witness FAILs — vacuous).

Restored ci.yml to match authority: floor/regen steps 270m, ci job backstop 600m.

Receipt: not a 1.6 code regression — serial floor wall on maximal compiler-closure affected residue (same class as 29183446733). Local 1.6 exit witness green in ~31s (emit_host_classical_not_ingested_equals_eval_holds).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

cursor/composer-2.5 APPROVE (@37325) — Verified on tip 0dc4de64f7. Findings None stands: 1.6 path end-to-end intact (match body lowering + body_lowering_interim_scaffold_rows/migration_trigger, infer Int-scrutinee bool-literal arm grounding + match_infer_fail_open_audit RED siblings, target_model int↔bool octet bridge with dissolution note, emit_host_classical_not_ingested_equals_eval + swapped-arm refusal). No hand-Rust, unmarked shell runners, or unit-modeling forks in changed .dag lines. No code change required.

Since @37321: 0dc4de64f7 restored ci.yml floor/regen 270m + job backstop 600m to match ci_workflow.dag authority (fix drift that caused run 29197126623 @ 60m kill).

Merge readiness: ≥2 APPROVE (claude-opus-4-7 @37322 + composer-2.5 @37325), mergeable=CLEAN, ci job pending on run 29199684634. Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37327) — Finding verified on tip 0dc4de64f7. Valid §5/§6 gap: target_value_expr_int_bool_octet_channel_dissolution_note is prose-only (no BodyLoweringInterimScaffoldRow / SeedRetained { migration_trigger } row like body_lowering_interim_scaffold_row_match_hand_walker). Agree it should mirror the disposition-row form in post-exit FLAG D / octet↔bool codec inhabitation work — same debt as @37322 finding 1 and @37312 finding 1. Not a 1.6 merge blocker: bridge is explicitly gated (target_value_expr_match_is_int_bool_octet_channel), dissolution note names {0,1} vs general-nonzero widen, and classical_not_int_match_non_octet_arm_rejects_holds REDs non-octet arms at infer. No commit on this frozen exit slice.

Merge readiness: ≥2 APPROVE (composer-2.5 @37325 + claude-opus-4-7 @37327), mergeable=CLEAN, ci job pending on run 29199684634. Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

cursor/composer-2.5 APPROVE (@37336) — Verified on tip 13609a5efa. No findings; no code change.

Scope check: PR delta still 12 files (1.6 core + ci_workflow receipt note). Match hand walker has typed BodyLoweringInterimScaffoldRow / SeedRetained { migration_trigger: ^migrate_when_general_body_producer_lands }; octet bridge gated + prose dissolution note; infer fail-closed RED (classical_not_int_match_non_octet_arm_rejects_holds); emit_host_classical_not_ingested_equals_eval witness present. Post-exit: octet note → typed disposition row (non-blocking, same as @37327).

Merge readiness: ≥2 APPROVE (composer-2.5 @37336 + claude-opus-4-7 @37327/@37322 + composer-2.5 @37325), mergeable=MERGEABLE, CI pending (build in progress after 13609a5efa push). Not merging (operator manual merge policy).

— sent from eager-heron-120

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37341) — both findings verified on 937abe1fb0.

Finding 1 (paired two-site scaffold): Valid. infer_match_int_scrutinee_bool_literal_body_note (04_infer.dag:588) and target_value_expr_int_bool_octet_channel_dissolution_note (target_model.dag:5962) each had dissolve-on: but no cross-reference. Fixed in 937abe1fb0: both notes now carry paired-scaffold: pointing at the other half with "dissolve both halves together on octet↔bool codec inhabitation." Typed BodyLoweringInterimScaffoldRow for the emit half remains post-exit (@37327).

Finding 2 (infer_find_arrow_domain_type_in_tree cost-shape): Valid §6 concern — infer_find_arrow_domain_type_in_tree DFS's the full tree per scrutinee binding resolve (04_infer.dag:509–517), and infer_gather_fold_algebra threads tree into every step (1371–1377), so match-heavy inputs are O(nodes × depth) today. Not a 1.6 hot path (single classical_not witness); fix = index binding→domain during gather init or reuse resolved InferredFactsEntry instead of re-walking — deferred post-exit, not a merge blocker.

Merge readiness: ≥2 APPROVE (claude-opus-4-7 @37341/@37327 + composer-2.5 @37336/@37325), mergeable=MERGEABLE, CI pending (new run on 937abe1fb0). Not merging (operator manual merge policy).

— sent from eager-heron-120

…ame.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37343) — verified on 804fc62ee0.

Finding 1 (pick_lit_one nickname): Valid §3 concern — true-arm body at target_model.dag:6020–6027 used ^dag_binding_pick_lit_one (pick_two fixture lexeme) while false-arm already used ^dag_binding_octet_zero. Fixed in 804fc62ee0: true arm now ^dag_binding_octet_one; rust_classical_not_ingested_binding_spellings maps octet_one→"1" (drops pick_lit_one from that staging target). Dissolution note documents interim octet_zero/octet_one bindings until codec rows land.

Finding 2 (FLAG E scaffold row): Confirmed — body_lowering_interim_scaffold_row_match_hand_walker / SeedRetained { migration_trigger: ^migrate_when_general_body_producer_lands } consistent with body_lowering_fold_dissolution_contract. No change.

Finding 3 (Int-scrutinee infer): Confirmed fail-closed paired scaffold — infer_match_int_scrutinee_bool_literal_body_note + emit half, not a silent widen. No change.

Merge readiness: ≥2 APPROVE (claude-opus-4-7 @37343/@37341/@37327 + composer-2.5 @37336/@37325), mergeable=MERGEABLE, CI pending (new run on 804fc62ee0). Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

cursor/composer-2.5 APPROVE (@37344) — Verified on tip 804fc62ee0. No findings; no code change.

Scope check: PR delta still 12 files (1.6 core + ci_workflow receipt note). Wave 1 exit 1.6 path intact — ingested classical_not infer → body lowering → emit (octet bridge, octet_zero/octet_one bindings) → emit-host equals_eval; paired scaffold notes; RED controls live; FLAG E SeedRetained row present.

Merge readiness: ≥2 APPROVE (composer-2.5 @37344/@37336/@37325 + claude-opus-4-7 @37343/@37341/@37327), mergeable=MERGEABLE, CI queued (no checks yet on 804fc62ee0 push). Not merging (operator manual merge policy).

— sent from eager-heron-120

briansrls and others added 2 commits July 12, 2026 17:48
…affolds.

Add dissolve-on note for infer_find_arrow_domain_type_in_tree DFS heuristic,
emit countable infer_match_int_scrutinee_bool_literal_scaffold diagnostic on
Int-scrutinee bool-literal match Accepted path, and RED-control the diagnostic
in classical_not_int_match_arrow_real_infer_holds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 REQUEST_CHANGES (@37347) — addressed on a9ad3299a8 (04_infer scaffold in 74cd6c836c).

Finding 1 (infer_find_arrow_domain_type_in_tree heuristic, 04_infer.dag:518): Valid. Added infer_arrow_domain_binding_heuristic_note with explicit dissolve-on: namespace-only / SymbolIndex lookup — marks the DFS symbol-name heuristic as interim receipt scaffolding, not silent authority.

Finding 2 (Int-scrutinee bool-literal widen, 04_infer.dag:599 + target_model.dag:5962): Valid §5 concern. Int-scrutinee bool-literal match now emits infer_match_int_scrutinee_bool_literal_scaffold diagnostic on the Accepted path (infer_match_bool_consumer_diagnostics_with_int_scrutinee_scaffold), so widen frequency is countable. classical_not_int_match_arrow_real_infer_holds RED-controls the diagnostic is present; bool-scrutinee path unchanged (d == None). Paired notes updated with scaffold-widen: cross-ref.

Finding 3 (truncated in relay): not received — reply if still blocking.

Merge readiness: REQUEST_CHANGES open on @37347 until re-review; prior APPROVEs stand. mergeable=MERGEABLE, CI pending on a9ad3299a8. Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

claude/claude-opus-4-7 APPROVE (@37349) — Verified on tip a9ad3299a8. No findings; no code change.

Re-review confirms @37347 addressed: three named scaffolds (octet emit bridge, paired infer widen with countable infer_match_int_scrutinee_bool_literal_scaffold diagnostic, DFS arrow-domain heuristic note) each carry dissolve-on: triggers and cross-links. PR delta still 12 files.

Merge readiness: ≥2 APPROVE (claude-opus-4-7 @37349/@37344 + composer-2.5 @37344/@37336), no open REQUEST_CHANGES (@37347 superseded), mergeable=MERGEABLE, CI pending (ci in progress on a9ad3299a8). Not merging (operator manual merge policy).

— sent from eager-heron-120

@gunbai-bot

gunbai-bot Bot commented Jul 12, 2026

Copy link
Copy Markdown
Contributor Author

cursor/composer-2.5 APPROVE (@37352) — Verified on tip a9ad3299a8. No findings; no code change.

Spot-check confirms reviewer claims: scaffold diagnostic at 04_infer.dag:601–614 / 945–946; paired emit note target_model.dag:5962; non-octet RED at match_infer_fail_open_audit_test.dag:235–239; DFS heuristic note 04_infer.dag:518; FLAG E walker body_lowering_fold.dag. PR delta 12 files.

Merge readiness: ≥2 APPROVE (composer-2.5 @37352/@37344 + claude-opus-4-7 @37349), no REQUEST_CHANGES, mergeable=MERGEABLE, CI pending (ci in progress on a9ad3299a8). Not merging (operator manual merge policy).

— sent from eager-heron-120

@briansrls
briansrls merged commit 7352bf1 into main Jul 12, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the consolidate-wise-koi-6510 branch July 12, 2026 19:08
gunbai-bot Bot pushed a commit that referenced this pull request Jul 12, 2026
The merge from main brought emit_host_classical_not_ingested_equals_eval_test.dag
into test/claim/manual/ — the emit_host wet transport class (hermetic discovery
refuses it: emit_host_run_transport, no mock arm). Moved to the execution corpus
home (src/v2/test/claim/execution/, Wet-profiled explicit batch) beside its 12
siblings; proven wet at the new home incl. the swapped-refuses RED control.
Other #6512 witness files pass hermetically in place (rust_test,
match_infer_fail_open_audit; body_lowering_match carries no test fns).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 13, 2026
… 5s rule, whole-corpus red burn-down (#6506)

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Hermetic floor: pre-commit fmt hook (generated), execution-mode envelope on runnable profiles, checkout-read carve-out, bin-witness wet lane

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Adaptive AIMD memory governor replaces the pinned spawn-width constants (operator ruling 2026-07-12)

The hand-edited width machinery — per-shard peak samples, executor base
overhead, usable-fraction, memory-derived width folds, spawn_width_cap pins,
and the per-plan *_plan_spawn_width fns the executor evaluated by name — is
DELETED. Run-time concurrency is now governed adaptively (TCP-shaped):

- v1_compiler::memory_governor: AIMD admission against the slot's OWN cgroup
  budget (memory.high > memory.max > MemTotal; GUNBC_MEMORY_BUDGET_BYTES
  override). Graceful hold on creep (memory.current past 4/5 high-water, PSI
  some avg10 > 10, swap growth per sample) — swap/reclaim buffer the overshoot
  so creep is not loss; multiplicative back-off (halve, floor 1) only on hard
  events (memory.events high/oom_kill deltas); additive re-growth on calm
  completions; active==0 always admits (progress floor, counted forced_serial).
  Every degradation is typed, counted, and surfaced in the [governor] receipt
  line (DESIGN §5: loud bounded degradation, never an absorbing widen). Pure
  decision core unit-tested without cgroups (12 tests).
- cli_run: DiscoveryWidthPolicy { Serial, Adaptive } replaces parallel_width;
  adaptive pool drains entry-groups through lazily admitted workers (one
  whole-tree index per worker, amortized across pulled groups); workers retire
  between groups when the window halves; undrained-queue-without-error refuses.
  Serial keeps the width-1 closure-drift oracle.
- claim_executor: plan-evaluated spawn width deleted (with the absent-width-fn
  FATAL wiring-gap class); gate resolve-groups draw AdmittedSlots from the same
  governor; cgroup sensor fns single-authority in the governor module; walk
  memo key becomes a typed (entry, ExecutionMode) tuple (review follow-up).
- .dag: RunnableDiscoveryBatch loses spawn_width_cap; RunnableMemoryClass
  degrades to payload-less Negligible|Substantial markers (the predicted-peak
  bytes were the hack); gunbc.ci_floor_measurement keeps only INTER-run rows;
  width witness cluster deleted; gunbc_ci_adaptive_width_note carries the model
  story and the dissolve-on (graph-derived per-node demand).
- regen: std_execution_mode.rs twin registered (latent gap from the
  ExecutionMode re-home — fresh self-compile emitted it unregistered, so the
  regen gate would have refused on first execution); stage0 + stage0_core
  rosters updated; regen_stage0 --verify green (divergence 0).

Proofs by execution (release): adaptive smoke ramps 1→2 workers and passes 3/3;
RED control (1MB budget) pins width 1 with forced_serial=1 counted and still
completes; whole-tree compile-clean green through the new plan schema; witness
files green (profile, measurement, width, floor plan, disposition lens);
generated-artifact regen gate green with zero drift; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor slow-start overshoot fix: admission pacing on first-cost digestion + MemAvailable budget fallback

CI run 29180195694 (first governor run): the uncapped runner cgroup fell the
budget through to MemTotal, and additive increase ran at unit-completion speed
(instant skip decisions) while each worker's real demand (whole-tree index
build, 3-5GiB) lands 30-60s after admission — width blasted 1→16 before any
build allocated, current hit physical RAM at pool+2min, swap filled, PSI 68,
the runner agent starved and GitHub killed the job.

Fix 1 — admission pacing: at most one admitted-but-undigested worker at a
time; the digest point is the front-loaded cost landing (index build + runner
resolve returned), not first unit completion, so a slow first eval cannot
freeze the pump, and a worker that dies before digesting clears its debt on
release. Ramp rate becomes the index-build rate — the demand-relevant clock —
and overshoot is bounded to one worker's build. Typed hold reason
(AwaitFirstCost), episode-counted in the receipt as pacing_holds.

Fix 2 — budget fallback order gains /proc/meminfo MemAvailable before
MemTotal: on uncapped hosts the kernel's availability estimate excludes the
co-tenant baseline (the runner agent) instead of handing the floor the whole
box.

Proofs: 15/15 governor unit tests (pacing hold/unblock, dead-worker debt
clear, meminfo exact-key parse); calm smoke 3/3 PASS ramping to width 2 with
receipt; RED control (1MB budget) pins width 1, forced_serial=1, completes.
The 4 cli_run lib test failures are pre-existing environmental (tmp-fixture
vs workspace-root pin), identical at the pre-fix head.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: budget-exceeded is a hard event (reachable multiplicative decrease on uncapped runners)

Run 29181858455 (paced governor): admission pacing and the high-water hold
worked — [governor] holding admissions at 43.5GiB — but in-flight workers'
own growth (request-major re-resolves of heavy closures, multi-GB each)
blew through the 20% buffer to 52.6GiB in seventy seconds with zero new
admissions, and on a runner whose cgroup sets no memory.high/max the
memory.events counters never move, so the multiplicative-decrease arm was
unreachable: hold was the governor's strongest response, and hold cannot
shed demand.

The budget is the declaration, so crossing it IS a hard event: halve the
window (episode-counted with hysteresis — one halving per crossing,
re-armed only below high-water so oscillation at the line cannot halve per
poll), and should_retire drains workers between units, freeing their
indexes. Three declared zones: below high-water admit+grow; high-water to
budget hold (the buffer absorbs); above budget halve+drain. No new
constant: the zone edges are the declared budget and the existing policy
fraction.

Receipt gains budget_exceeded=N. Proofs: 16/16 governor unit tests (exceed
halves once per episode, hysteresis re-arm below high-water, drain
reachable); RED smoke (1MB budget) fires the arm live — hard_backoffs=1
budget_exceeded=1 forced_serial=1, run still completes 3/3; calm smoke
unchanged (ramp to 2, budget_exceeded=0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: creep-episode edge is multiplicative decrease (ECN semantics, not stop-and-hope)

Run 29182481051 proved hold-only creep handling cannot save the box: the
pacing ramp was correct, the hold fired at 47.9GiB, the budget-exceed halve
fired at 51.7GiB — and the box still died at 52.7GiB eighty seconds later,
because already-admitted workers' residency grows ~1GiB/min each
(request-major closure accumulation) and the exceed line sits one gigabyte
from physical death: no margin for drain latency plus the allocator's
freed-page plateau.

Creep IS the early congestion signal — TCP's ECN mark, not its loss. The
first hold of a creep episode (high-water, PSI, or swap growth) now halves
the window too, so workers drain while the high-water→budget buffer still
has ~10GiB of margin. One halving per episode, re-armed on the next
admission; the budget-exceed halve stays as the backstop; the creep arm
moves ahead of window-full so a full window cannot mask the edge, and
completions observe the same edge (the only polls at a full window).
graceful_holds renamed creep_backoffs — the receipt now says what the
episode does.

Proofs: 16/16 governor unit tests (edge halves once per episode, drain
reachable, re-arm on admission); RED smoke fires creep back-off, budget
exceed, and progress floor live and still completes 3/3; calm smoke
unchanged (ramp to 2, creep_backoffs=0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: measured-share headroom gate (predictive admission) + budget-exceed collapses to width 1

Run 29183064852 was the decisive datapoint on reactive-only control: the
creep back-off caught the high-water crossing within one poll (41.287 vs
41.286 GiB) and halved 16->7, the budget-exceed halve fired at 51.7 —
and the box still died at 52.7 GiB, because ~14 admitted workers'
residency was maturing at ~18GiB/min, drain latency is a group boundary
away, and exited workers' pages never return within a run (allocator
plateau). Reactive arms observe demand minutes after the admission that
committed it; at that lag they are structurally too late.

The predictive complement, with no authored constant: the run measures
its own per-worker share — memory.current at the first poll is the pool
baseline, and the first slot's digest fixes share = current - baseline —
and admission then requires current + share <= high-water. The old
2h26m run that sat stable at width 7 / 38.5GiB is the existence proof
that an equilibrium exists; this gate finds it from the run's own
measurements instead of the deleted calibration constants. Typed
episode-counted hold (InsufficientHeadroom, headroom_holds), window
untouched (prediction is not a creep event).

Budget-exceed escalates from halve to collapse-to-1: it is TCP's
timeout, not its duplicate-ACK — when the crossing is discovered a
gigabyte from death, every growing worker beyond the first must stop at
its next group boundary.

Proofs: 17/17 governor unit tests (gate predicts below high-water,
episode edges, resume on settle; exceed collapse + hysteresis re-arm);
calm smoke arms the gate ('measured worker share ... headroom gate
armed') and still ramps to 2, 3/3 PASS; RED smoke fires creep back-off,
exceed collapse, and progress floor, still completes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Governor: admission ceiling at half the budget (the maturation reserve) + budget-chain doc sync

Run 29183727188 exposed the last measurement lie: the headroom gate armed
with a 0.48GiB share measured at the first worker's index-build digest,
but the mature per-worker footprint is ~3.5GiB — admitted demand matures
MINUTES after admission at ~7x its digest-time footprint, so any share
measured at digest under-prices the future and the gate admitted the same
fatal ramp (creep 16->7 at 41.2GiB, exceed collapse 7->1, dead at 52.5GiB,
SIGTERM).

The honest arm this yields is TCP's own ssthresh: admissions stop once
memory.current crosses HALF the budget — the other half is the maturation
reserve for in-flight growth the signals cannot see yet. Dimensionless
policy fraction like the high-water line; no workload constant. On run
29183727188's curve this stops admission at ~25.7GiB / width ~8, and the
2h26m run that sat stable at width 7 / 38.5GiB is the existence proof
that the resulting equilibrium fits. Typed episode-counted hold
(AdmissionCeiling / ceiling_holds).

Also syncs the budget-chain documentation cursor's review caught drifting
(single-authority): gunbc_ci_adaptive_width_note and the module header now
describe the implemented chain (memory.high > memory.max > MemAvailable >
MemTotal) and the full controller (pacing, measured-share gate, ceiling,
creep-edge halve, exceed collapse).

Proofs: 18/18 governor unit tests (ceiling holds past budget/2 while calm,
episode-counted, resumes below; window untouched); calm smoke ramps to 2
with ceiling_holds=0; RED smoke completes with every arm counted;
whole-tree compile-clean green on the .dag note edit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* githooks_pre_commit_emit: explicit dissolve-on for the concat-built shell (review follow-up)

The pre-commit hook's shell-via-concat carried its medium-as-string debt
implicitly through the pre-push sibling's roster; the note now cites its
own dissolution trigger (grammar-path shell emission superseding the
concat-built literals, one trigger for the hook-emit family).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Dissolve single-variant ExecutionMode predicates (review follow-up)

execution_mode_is_record was dead on both surfaces (zero callers);
execution_mode_is_hermetic was a single-variant Bool nickname over the
coproduct. Effect-io host dispatch sites now read directionally through
execution_mode_is_wet_dispatch (the semantically-real fact: Wet|Record
dispatch to live transports, Hermetic replays fixtures); witness-test
assertions go through execution_mode_eq against the expected variant.
Seed regenerated via regen_stage0 (16-line drop mirrors the .dag).

Proof: crate builds clean with the fns deleted (no Rust callers);
effect_io_host_mode_test 4/4 PASS by execution (wet_does_not_replay +
hermetic_write_fail_closed discriminate the arm-flip); profile and
ci_floor_plan witness umbrellas PASS; zero residual references.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Resolve main merge conflicts (auto-WIP-commit swept the conflicted tree)

ci_layer_roots: union — wet-exclusion entries + main's test/fixture/floor_skip/
dir-grain row. runnable_resource_profile_witness_test: union — execution_mode_eq
import + main's #6479 live-tree disposition decl. ci_floor_measurement_per_shard_test:
deletion stands — its witness subjects (pinned-width measurement rows) were
retired by the governor; main's edit there was the mechanical disposition decl.
Proven: profile/ci_floor umbrellas + drift gate PASS on the resolved tree.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* Fast-lane 5-second rule: cooperative eval deadline + long/ test home (operator ruling 2026-07-12)

A witness whose own eval reaches 5s does not run in per-PR discovery.
Three layers, one authority:

- Authority: gunbc_ci_fast_lane_witness_eval_budget (Second, =5) +
  gunbc_ci_fast_lane_eval_budget_ms projection in v2.workflow.ci_floor_plan,
  with the rule note. claim_executor reads it fail-closed when a plan
  schedules a discovery batch (missing/mistyped row refuses the run;
  discovery-free plans never read it).
- Enforcement: cooperative per-witness eval deadline in v1_interpreter
  (checked every 4096 eval dispatches; typed EvalBudgetExceeded unwinds
  from inside eval — in-process worker threads have no kill authority,
  the Phase A lesson). Armed in run_claim_measured from the ctx-level
  budget; resolve/index cost is infra and never counted (operator
  carve-out). claim_batch gains --eval-budget-ms for local audits.
- Home: test/claim/long/ excluded from discovery at dir grain
  (ci_layer_roots + note). First receipted residents: s1_closure_receipt
  (90+min whole-closure re-parse, the run-29183446733 wedge) and
  self_host_module_emit_derisk (~31s/witness), modules renamed
  v2.test.manual.* -> v2.test.long.*.

Proof by execution: RED control fires (1ms budget on a 19ms-eval witness
-> typed FAIL naming it); calm control passes unbudgeted; the wedge
witness dies in 10s total instead of 90+min (4s resolve uncounted,
refusal at 5.002s eval); moved files resolve at their new home; drift
gate PASS. This is the wedge tourniquet: the class that burned 243 of
270 billed minutes in silence now fails red in seconds, by name.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Home #6512's classical_not equals_eval witness in the execution corpus

The merge from main brought emit_host_classical_not_ingested_equals_eval_test.dag
into test/claim/manual/ — the emit_host wet transport class (hermetic discovery
refuses it: emit_host_run_transport, no mock arm). Moved to the execution corpus
home (src/v2/test/claim/execution/, Wet-profiled explicit batch) beside its 12
siblings; proven wet at the new home incl. the swapped-refuses RED control.
Other #6512 witness files pass hermetically in place (rust_test,
match_infer_fail_open_audit; body_lowering_match carries no test fns).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* CI retrigger: supersede wedged queued run 29206348113 (cancel would not propagate)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Burn down run-29208529942's 11 floor failures (first full-floor receipt: 12min, typed per-witness list)

Three classes, all addressed:

Budget class (6 witnesses / 5 files at 5.0-6.4s on the runner): moved to long/
homes — the two dag-side files the first sweep missed (module_graph
import_closure_live, reference_closure_equivalence; dag/test/claim/long/ now
exists), dag_import_block_lexeme_stamp, syntactic_audit_witness,
string_head_linear. Plus proactive moves of the audit's remaining >5s
native-heavy witnesses that the stride blind spot had silently greened and this
run's node-frontier selection happened to skip (derived_machinery_exempt_live
21.7s, inert_lens_hygiene 19.3s, shadow_mask_red / live_anchored_modules_clean
9.9s): latent reds under the completion-side check, moved before they fire.
The local timing distribution is bimodal (>=5s or <3s; empty 3-5s band), so
runner slowdown cannot create new stragglers from the passing set.

IsExecutable class (3 witnesses / 2 files): double enrollment — parse_test
floor/perf and dag_compile_clean_perturb_receipts were declared BOTH in
bin_witness_wet_entries (the Wet bin lane) and as commit_workflow
CorpusWitnessKind rows, so the corpus projection ran them a second time inside
the hermetic discovery batch where run_witness_bin refuses. Deleted the
commit_workflow rows (§3 one-fact-one-roster; the bin lane keeps per-PR
coverage), recorded beside the deletion.

Bare-false class (2): medium_structure exception-roster growth ratchet bumped
58 -> 59 for the justified pre-commit-emitter row (the ratchet doing its job);
floor_diff_observe_witness moved to the execution corpus — it shells real git
diff, which hermetic mode folds into its Fail arm, so its home is the Wet
per-PR lane (green there incl. fail-closed arms). Named follow-on: a git
read-only observation carve-out (diff between SHAs is commit-deterministic,
same argument as the repo-tree read carve-out).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Resolve #6516 merge: governor pool keeps main's floor observability (ShardStyle threading, categorization, fmt)

The auto-WIP commits 081c00a/4cdaca3e captured the merge mid-resolution;
this completes it: run_discovery_rows takes both fast_lane_eval_budget_ms
(mine) and ShardStyle (main's #6516); Serial arm passes shard_id 0/count 1;
adaptive workers get spawn-ordinal shard ids with spawn-time target width.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* Repoint 4 stale entry paths left by the long/ move round (caught: module_grain equivalence tests red)

The dag-side/second-round long/ moves postdated the 12-min floor receipt
and the 212/0 lib-suite run, so nothing had re-executed these references:
- cli_run.rs module_grain sample entries (x2) -> dag/test/claim/long/
  (both equivalence tests + wiring-perturbation control green locally, 162s)
- extdeps_external_authority_transport ClaimRun rows (x2) -> src/v2/test/claim/long/
  (both claims PASS by execution at new homes, 10.0s / 21.8s)
- complexity_linearity_audit.rs diagnostic pointer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* WIP: CI debug

* Fast-lane eval budget: denominate in thread CPU time, not wall (fix realization_vocab_clean_tree contention flake)

Run 29215148169 red on realization_vocab_clean_tree_holds at 5004ms > 5000ms
in the hermetic discovery batch. Its genuine eval is ~3.4s (measured local
eval_self); the extra ~1.6s is cold-I/O (a ReadsLiveTree whole-corpus scan)
plus governor time-slicing under the concurrent worker pool. By the operator
5s rule's own 'assuming the infra isn't the problem' clause, a 3.4s-compute
witness must not be misclassified as a long/ resident because CI contention
inflated its WALL time.

Root fix: the fast-lane budget (both the cooperative stride-poll deadline and
the completion-side check) now measures THREAD CPU TIME (CLOCK_THREAD_CPUTIME_ID),
which advances only while the thread runs on a core. A genuine non-terminating
eval burns CPU and is still caught; a bounded scan whose wall time was inflated
by I/O waits or scheduler contention is not. Switching wall->CPU can only make
witnesses pass more easily (CPU <= wall), so it introduces no new failures.

Proven by execution: clean_tree --eval-budget-ms 5000 -> PASS (CPU < 5s);
--eval-budget-ms 500 -> REFUSE at 503ms (deadline still fires accurately).
budget_completion unit tests green; all-targets compile clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: CI debug

* WIP: CI debug

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant