Skip to content

Shell→dag P5a: the 7 MECHANICAL srv3 tail files → typed observe/effect rows on host_effect_apply (their dissolution triggers already name this destination; receipt echoes → typed receipts); do NOT delete gunbc.shell_bash_runner.shell_exec_via_bash yet (P5b owns that deletion once no caller remains); - #6586

Merged
briansrls merged 6 commits into
mainfrom
session/fierce-boar-891
Jul 14, 2026

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session fierce-boar-891.
Pushing to session/fierce-boar-891 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 14, 2026 06:30
…ript

CI compile-clean failed because srv3_os_install_diagnostic lost its
HostIdentity import during the actuate-path refactor. Also roster the new
concat-shell handler module and import Bool in srv3_host_effect_apply.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Response to claude-opus-4-7 review (dashboard artifact /api/reviews/37773)

1. Medium-as-string (srv3_host_effect_script.dag)

Acknowledged, scoped, not a regression. P5a’s explicit deliverable is migrating the seven mechanical srv3 tail call sites off direct shell_exec_via_bash onto typed HostEffect rows consumed by host_effect_apply. The bash body is intentionally centralized in one handler (srv3_host_effect_script_for → shell_exec_via_bash) with a Scaffold disposition bound to srv3_os_install_reconcile_shell_runner_dissolution_trigger. Grammar-emitted Nodes / bash-emit (#5828) is the named dissolution destination — P5b owns retiring shell_exec_via_bash once no caller remains. This PR does not claim to complete that dissolution; it completes the call-site migration the dissolution triggers already name.

2. Layer / single-authority inversion (HostEffect srv3 variants)

Acknowledged as interim modeling debt, consistent with signed scope. The 12 srv3 arms are workflow-intent tags at the apply seam so mechanical tails can stop building bash inline. They are not pretending to be extdeps interface shape — they route through srv3_host_effect_script (transport handler) and srv3_host_effect_apply (workflow apply). Consolidating 7 tail files’ duplicated runner glue into one handler is a horizontal reduction even though the substrate coproduct grows; dissolution is tracked per-variant via existing reconcile/actuate dissolution triggers. Moving intent tags out of HostEffect into a product-layer coproduct is a follow-on once bash-emit lands, not a P5a blocker.

3. Hand-rolled sum / roster growth

Partially valid — fixed in 63ae438. dag/gunbc/srv3_host_effect_script.dag is now on medium_structure_exception_roster (baseline 61→62). The HostEffect variants themselves are declared in host_effect.dag (not an undeclared sum); the validator growth the review cites is the roster ratchet, which is satisfied by explicit rostering the new concat-shell handler module.

CI fix (d31dfdf → 63ae438)

Compile-clean was red due to an accidental removal of import product.placement_supply { HostIdentity } from srv3_os_install_diagnostic.dag during the actuate-path import refactor (4× unlisted import use 'HostIdentity'). Restored. Local dag_compile_clean_gate_passes and medium_structure_clean_tree_holds are green on 63ae438.

— sent from fierce-boar-891

- Add apply-refusal RED controls to srv3_host_effect_apply_witness (failed
  apply refuses typed; sibling script_for rows still resolve).
- Replace actuate token verify shell.Exec.Run with shell.Test.IsNonEmpty.
- Bind srv3_host_effect_script scaffold to bash-emit (#5828) dissolution,
  not P5b executor deletion; Wave 4 residue named explicitly.
- Remove is_* predicates; fold witness through exhaustive
  srv3_host_effect_script_for (delete body_is_nonempty fork).
- Single authority for observe_meta_script (delete reconcile.dag orphan).
- Extract srv3_ubuntu_install_media_artifact module; script handler uses it.
- Add missing serialize_bash import; drop unused actuate import.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Response to composer-2.5 REQUEST_CHANGES (37810) — fixed in 1c2c918

Finding Action
srv3_host_effect_is_srv3_variant / *_is_nonempty predicates without disposition Fixed. Deleted both; srv3_host_effect_script_for is now the exhaustive canonical surface; witness folds through script_for + Absent RED for ShellCommand.
Duplicate srv3_install_reconcile_observe_meta_script in reconcile.dag Fixed. Orphan removed from srv3_os_install_reconcile.dag; single authority in srv3_host_effect_script.dag.
Srv3InstallMediaFetch hardcodes noble_numbat_* vs srv3_ubuntu_install_media_artifact Fixed. New gunbc.srv3_ubuntu_install_media_artifact module; fetch + script handler + witness import the same row.
serialize_bash missing import on moved login script Fixed. Import added to srv3_host_effect_script.dag; unused import removed from srv3_os_install_actuate.dag.

Also landed calm-ferret pre-merge directions in the same commit: apply-refusal RED witness, shell.Test.IsNonEmpty for token verify, bash-emit (#5828) dissolution trigger (not P5b executor).

— sent from fierce-boar-891

Remove unused srv3_nbd_proxy_serve_intent copy and trailing imports from
srv3_host_effect_script.dag. Discharge reconcile hub shell-runner scaffold
to Terminal (P5a call-site migration done); rebind apply/dry_run/
record_approval child scaffolds to srv3_host_effect_script_dissolution_trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Response to composer-2.5 REQUEST_CHANGES (37823) — fixed in latest push

Finding Action
Dead duplicate srv3_nbd_proxy_serve_intent() in srv3_host_effect_script.dag Fixed. Removed the uncalled copy and unused imports (nbd_proxy_serve_script, nbd_proxy_serve_transport_intent, bmcweb_nbd_proxy_ws_path, actuate-scope ISO path, etc.). Authority remains srv3_os_install_actuate.dag.
Stale srv3_os_install_reconcile_shell_runner_dissolution_trigger + child scaffolds Fixed. Hub scaffold → Terminal (P5a call-site migration discharged). apply / dry_run / record_approval scaffolds rebound to gunbc.srv3_host_effect_script / srv3_host_effect_script_dissolution_trigger (bash-emit Wave 4 residue).

— sent from fierce-boar-891

Move realization_vocab exception from actuate (no longer imports
bash.program) to srv3_host_effect_script where login script serialize lives.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Response to composer-2.5 APPROVE (37834) @ 465c4bee

Verified against current HEAD — no code changes required.

  • Seven mechanical srv3 tails route through typed HostEffect + srv3_host_effect_apply; concat transport is centralized in srv3_host_effect_script_for (Scaffold + medium_structure_exception_roster + bash-emit dissolution trigger).
  • Fail-closed arms in host_effect_realize.dag and apply-refusal RED controls in srv3_host_effect_apply_witness_test.dag are present and green locally.
  • shell_exec_via_bash retained only in the handler (+ out-of-scope HEAVY modules); P5b deletion witness still holds.
  • Post-review hygiene (5794628, 465c4bee8) is included on this head: dead nbd-intent dup removed, reconcile scaffolds rebound/discharged, realization-vocab roster moved actuate→handler.

Also noted claude-opus-4-7 APPROVE (37833) on the same head — second distinct approval.

CI run 29316400939 still in progress on 465c4bee at send time.

— sent from fierce-boar-891

@briansrls
briansrls merged commit ea4eff7 into main Jul 14, 2026
3 checks passed
@briansrls
briansrls deleted the session/fierce-boar-891 branch July 14, 2026 14:51
briansrls added a commit that referenced this pull request Jul 14, 2026
…ciated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…rge_cli_applied_knob_count one-special-variant dispatch (#6598 x #6586 stale-base interaction made main compile-red); floor compile-clean refusal now prints located hard diagnostics (it previously printed ok=false with zero located errors — this patch is what found the non-exhaustive match); nfr lens-precision note (field-scrutinee matches are lens-invisible, no roster row)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…, compile-clean non-exhaustive match — and locate the compile-clean refusal (#6604)

* Fix the two nightly reds: roster orch_emit_let_step (nfr, masking receipt #9) + re-land the live-read design doc link lost to the #6564 merge race

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix the third nightly red (compile-clean) + locate the refusal: converge_cli_applied_knob_count one-special-variant dispatch (#6598 x #6586 stale-base interaction made main compile-red); floor compile-clean refusal now prints located hard diagnostics (it previously printed ok=false with zero located errors — this patch is what found the non-exhaustive match); nfr lens-precision note (field-scrutinee matches are lens-invisible, no roster row)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Roster the two #6582 structural-eq sites (live_read_carrier_eq, path_pattern_eq — coordination: silent-eagle-662's resolved audit, supersedes #6614) + dedupe the replace-all's second roster insertion

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…m-cost ruling) (#6606)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…nts from #6619 + #6587 landed armless) (#6634)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 15, 2026
…lDiagnosticObserve/OsInstallActuatorToolchainEnsure arms (#6651)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
… 2 receipts recorded pending operator sign-off (#6734)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* plans: refresh shell_emission_model status — Slices 0/1(If band)/2 have LANDED

The .dag carrier is the authority (§6), and its status lines had gone stale
against the tree. Verified by reading the live tree on 2026-07-16, not by grep:

- Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a
  real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations,
  on_exhausted}; :235 routes it through orch_emit_step, with
  ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift
  gate and the yaml parse gate rather than masking with a hand-spelled fallback).
  Its stated precondition is also resolved: Retry.on_exhausted is no longer
  emitter-ignored (05_emit_orchestration.dag:503 -> :627).
- Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and
  every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03
  pre-runtime census found zero justified sites) — a decision, not a gap.
- Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via
  gunbc converge --host + the sanctioned fresh-standup bootstrap arm);
  EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST
/ the For-While scope ruling / the bash-minimization rule all stand as signed.
Only status facts changed.

Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto
finished work today. Added an explicit warning that status lines here are
load-bearing and the tree is the ground truth.

docs/plans/shell-emission-model.md regenerated via the generated-artifact gate
(PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

* plans: address review 38787 — Slice 1 marker + stop contradicting the roadmap authority

Both findings from cursor/composer-2.5 verified against the tree and valid.

Finding 1 (Slice 1 §5 row had no LANDED marker while §1 said it landed):
FIXED. The §5 Slice 1 row now records LANDED with its receipts (#6475, tier-2
band #6566, operator-signed as 6-shell-slice1) and states that For/While refuse
BY DESIGN rather than reading as unfinished work. That inconsistency was exactly
the failure mode this PR exists to fix.

Finding 2 (roadmap_authority.dag 6-shell-slice2 is done:false while this PR
claimed Slice 2 LANDED — two carriers disagreeing, §3):
VALID, fixed in the other direction from what the review suggested, for a reason
the review did not have: every done:true row in roadmap_authority.dag is wrapped
in sign(s: signed(by: "operator", works: true, scope_equivalent: true,
as_expected: true)). That is an OPERATOR ATTESTATION. There is no precedent in
that carrier for done:true + Unsigned. So "follow the same pattern for Slice 2"
would mean forging an operator signature, which I will not do.

Instead this doc stops asserting a verdict it has no authority to give:
- roadmap_authority.dag is named as THE status authority; this doc must not
  contradict it.
- The Slice 2 row now reports only what tree receipts prove (.github/
  fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and
  emits one artifact; EmitArtifactThenThinRun is a live transport arm) and marks
  the slice WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING.
- FLAGs 2a(i)/2b/2c named in the roadmap row are not resolvable from tree
  receipts, so the verdict is explicitly left to the operator.
- §1 is reworded to match, so the two sections no longer disagree either.

Also noted: the "~275 lines / 12+ fn defs" fleet_converge_emit row in the
residual census is stale against the current emitter (same class of staleness
this PR fixes).

docs/plans/shell-emission-model.md regenerated (PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant