Repository navigation
Shell→dag P5a: the 7 MECHANICAL srv3 tail files → typed observe/effect rows on host_effect_apply (their dissolution triggers already name this destination; receipt echoes → typed receipts); do NOT delete gunbc.shell_bash_runner.shell_exec_via_bash yet (P5b owns that deletion once no caller remains); - #6586
Conversation
…ript CI compile-clean failed because srv3_os_install_diagnostic lost its HostIdentity import during the actuate-path refactor. Also roster the new concat-shell handler module and import Bool in srv3_host_effect_apply. Co-authored-by: Cursor <cursoragent@cursor.com>
Response to claude-opus-4-7 review (dashboard artifact /api/reviews/37773)1. Medium-as-string (
|
- Add apply-refusal RED controls to srv3_host_effect_apply_witness (failed apply refuses typed; sibling script_for rows still resolve). - Replace actuate token verify shell.Exec.Run with shell.Test.IsNonEmpty. - Bind srv3_host_effect_script scaffold to bash-emit (#5828) dissolution, not P5b executor deletion; Wave 4 residue named explicitly. - Remove is_* predicates; fold witness through exhaustive srv3_host_effect_script_for (delete body_is_nonempty fork). - Single authority for observe_meta_script (delete reconcile.dag orphan). - Extract srv3_ubuntu_install_media_artifact module; script handler uses it. - Add missing serialize_bash import; drop unused actuate import. Co-authored-by: Cursor <cursoragent@cursor.com>
Response to composer-2.5 REQUEST_CHANGES (37810) — fixed in
|
| Finding | Action |
|---|---|
srv3_host_effect_is_srv3_variant / *_is_nonempty predicates without disposition |
Fixed. Deleted both; srv3_host_effect_script_for is now the exhaustive canonical surface; witness folds through script_for + Absent RED for ShellCommand. |
Duplicate srv3_install_reconcile_observe_meta_script in reconcile.dag |
Fixed. Orphan removed from srv3_os_install_reconcile.dag; single authority in srv3_host_effect_script.dag. |
Srv3InstallMediaFetch hardcodes noble_numbat_* vs srv3_ubuntu_install_media_artifact |
Fixed. New gunbc.srv3_ubuntu_install_media_artifact module; fetch + script handler + witness import the same row. |
serialize_bash missing import on moved login script |
Fixed. Import added to srv3_host_effect_script.dag; unused import removed from srv3_os_install_actuate.dag. |
Also landed calm-ferret pre-merge directions in the same commit: apply-refusal RED witness, shell.Test.IsNonEmpty for token verify, bash-emit (#5828) dissolution trigger (not P5b executor).
— sent from fierce-boar-891
Remove unused srv3_nbd_proxy_serve_intent copy and trailing imports from srv3_host_effect_script.dag. Discharge reconcile hub shell-runner scaffold to Terminal (P5a call-site migration done); rebind apply/dry_run/ record_approval child scaffolds to srv3_host_effect_script_dissolution_trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
Response to composer-2.5 REQUEST_CHANGES (37823) — fixed in latest push
— sent from fierce-boar-891 |
Move realization_vocab exception from actuate (no longer imports bash.program) to srv3_host_effect_script where login script serialize lives. Co-authored-by: Cursor <cursoragent@cursor.com>
Response to composer-2.5 APPROVE (37834) @
|
…ciated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rge_cli_applied_knob_count one-special-variant dispatch (#6598 x #6586 stale-base interaction made main compile-red); floor compile-clean refusal now prints located hard diagnostics (it previously printed ok=false with zero located errors — this patch is what found the non-exhaustive match); nfr lens-precision note (field-scrutinee matches are lens-invisible, no roster row) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…, compile-clean non-exhaustive match — and locate the compile-clean refusal (#6604) * Fix the two nightly reds: roster orch_emit_let_step (nfr, masking receipt #9) + re-land the live-read design doc link lost to the #6564 merge race Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix the third nightly red (compile-clean) + locate the refusal: converge_cli_applied_knob_count one-special-variant dispatch (#6598 x #6586 stale-base interaction made main compile-red); floor compile-clean refusal now prints located hard diagnostics (it previously printed ok=false with zero located errors — this patch is what found the non-exhaustive match); nfr lens-precision note (field-scrutinee matches are lens-invisible, no roster row) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Roster the two #6582 structural-eq sites (live_read_carrier_eq, path_pattern_eq — coordination: silent-eagle-662's resolved audit, supersedes #6614) + dedupe the replace-all's second roster insertion Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…m-cost ruling) (#6606) * shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…nts from #6619 + #6587 landed armless) (#6634) * shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * WIP: shell -> dag * Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…lDiagnosticObserve/OsInstallActuatorToolchainEnsure arms (#6651) * shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * WIP: shell -> dag * Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
… 2 receipts recorded pending operator sign-off (#6734) * shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * WIP: shell -> dag * Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: shell -> dag * WIP: shell -> dag * plans: refresh shell_emission_model status — Slices 0/1(If band)/2 have LANDED The .dag carrier is the authority (§6), and its status lines had gone stale against the tree. Verified by reading the live tree on 2026-07-16, not by grep: - Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations, on_exhausted}; :235 routes it through orch_emit_step, with ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift gate and the yaml parse gate rather than masking with a hand-spelled fallback). Its stated precondition is also resolved: Retry.on_exhausted is no longer emitter-ignored (05_emit_orchestration.dag:503 -> :627). - Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03 pre-runtime census found zero justified sites) — a decision, not a gap. - Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via gunbc converge --host + the sanctioned fresh-standup bootstrap arm); EmitArtifactThenThinRun is a live transport: arm, no longer prose-only. Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST / the For-While scope ruling / the bash-minimization rule all stand as signed. Only status facts changed. Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto finished work today. Added an explicit warning that status lines here are load-bearing and the tree is the ground truth. docs/plans/shell-emission-model.md regenerated via the generated-artifact gate (PASS main_wet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: shell -> dag * plans: address review 38787 — Slice 1 marker + stop contradicting the roadmap authority Both findings from cursor/composer-2.5 verified against the tree and valid. Finding 1 (Slice 1 §5 row had no LANDED marker while §1 said it landed): FIXED. The §5 Slice 1 row now records LANDED with its receipts (#6475, tier-2 band #6566, operator-signed as 6-shell-slice1) and states that For/While refuse BY DESIGN rather than reading as unfinished work. That inconsistency was exactly the failure mode this PR exists to fix. Finding 2 (roadmap_authority.dag 6-shell-slice2 is done:false while this PR claimed Slice 2 LANDED — two carriers disagreeing, §3): VALID, fixed in the other direction from what the review suggested, for a reason the review did not have: every done:true row in roadmap_authority.dag is wrapped in sign(s: signed(by: "operator", works: true, scope_equivalent: true, as_expected: true)). That is an OPERATOR ATTESTATION. There is no precedent in that carrier for done:true + Unsigned. So "follow the same pattern for Slice 2" would mean forging an operator signature, which I will not do. Instead this doc stops asserting a verdict it has no authority to give: - roadmap_authority.dag is named as THE status authority; this doc must not contradict it. - The Slice 2 row now reports only what tree receipts prove (.github/ fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and emits one artifact; EmitArtifactThenThinRun is a live transport arm) and marks the slice WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING. - FLAGs 2a(i)/2b/2c named in the roadmap row are not resolvable from tree receipts, so the verdict is explicitly left to the operator. - §1 is reworded to match, so the two sections no longer disagree either. Also noted: the "~275 lines / 12+ fn defs" fleet_converge_emit row in the residual census is stale against the current emitter (same class of staleness this PR fixes). docs/plans/shell-emission-model.md regenerated (PASS main_wet). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Auto-opened by session-dashboard for session
fierce-boar-891.Pushing to
session/fierce-boar-891advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan