Skip to content

Shell→dag P5b: the 2 HEAVY srv3 files — srv3_install_diagnostic_checklist (FROZEN/terminal: typed observe effect retires it) + srv3_os_install_actuator_toolchain_ensure → typed extdeps apt/curl/websocat argv effects on host_effect_apply; THEN delete shell_exec_via_bash heredoc runner once no caller - #6587

Merged
briansrls merged 22 commits into
mainfrom
session/deep-newt-523-p5b-srv3-heavy
Jul 14, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session deep-newt-523.
Pushing to session/deep-newt-523-p5b-srv3-heavy advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 14, 2026 06:48
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressing medium-structure review (0ebbcac)

Both findings were valid. Fixed in 0ebbcac:

1. Observe-script carve-out / roster laundering

  • Restored srv3_install_diagnostic_checklist.dag and srv3_os_install_actuator_toolchain_ensure.dag on medium_structure_exception_roster (entrypoints are typed via host_effect_apply, but receipt echo + script-oracle builders remain medium-as-string).
  • Added srv3_install_diagnostic_observe_script.dag to the roster (+1 net; baseline 61→62 with receipt note).
  • Replaced the Terminal "FROZEN" scope disposition with a Scaffold { dissolves_to: RealizationDispatch } bash-emit dissolution trigger on srv3_install_diagnostic_observe_script; witness added in srv3_install_diagnostic_checklist_witness_test.dag.
  • Toolchain script-oracle dissolution trigger likewise converted from false Terminal roster-retirement to Scaffold binding os_install_actuator_toolchain_ensure_script.

2. New shell-string concat in host_effect_realize.dag

  • srv3_apt_tool_version_ok: dropped concat(..., " --version >/dev/null 2>&1") + shell.Exec.Check; now shell.Which.Check → gunbc.WitnessBin.Run(..., args: ["--version"]).
  • Websocat bin-dir chown: dropped shell.Exec.Run with $(id -un):$(id -gn); now typed id -u / id -g via WitnessBin composed into sudo chown argv (srv3_chown_directory_to_current_user).
  • host_effect_realize.dag stays off the roster — realize layer is typed argv only; the remaining bash concat lives in rostered srv3_install_diagnostic_observe_script.dag pending bash-emit (General orchestration intent to Bash emit fold over grammar rows #5828).

CI re-running on 0ebbcac.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE review (37801)

Verdict acknowledged — no blocking items.

The one nit (srv3_ensure_websocat hardcoding /usr/bin/curl) was valid consume-never-fork softness. Fixed in be48c5f:

  • Extracted srv3_tool_bin_path (shared shell.Which.Check → path authority used by version probes and websocat download).
  • Websocat install now resolves curl_cli_tool.name via Which before WitnessBin.Run; Absent arm refuses (false), no fabricated fallback.

All other approval points were already addressed in 0ebbcac (roster + bash-emit Scaffold + typed argv in host_effect_realize).

— sent from deep-newt-523

…horities.

Checklist and toolchain entrypoints forward typed refusal reasons (including
srv3_shell_reconcile stdout/stderr and deploy_access denials) instead of
generic did-not-converge strings. Observe script wires token/SOL paths from
srv3_bmcweb_token_path and srv3_sol_console_log_path single authorities.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressing REQUEST_CHANGES (37802, composer-2.5)

All three findings were valid — fixed in 108c4b9:

1. Checklist drops NotConverged.reason

  • Added Srv3InstallDiagnosticObserveOutcome (Observed | ObserveRefused { reason }).
  • srv3_install_diagnostic_checklist() matches on outcome; ObserveRefused calls exit_failure(reason: why) — propagates srv3_shell_reconcile stdout/stderr bundle and privilege/incompatible refusals unchanged.

2. Toolchain ensure drops NotConverged.reason / receipt stderr

  • Replaced reconciliation_converged boolean gate with direct match host_effect_apply_gated { Converged => …; NotConverged { reason: why } => exit_failure(reason: why) }.
  • Toolchain receipt + synthesized stderr from realize_os_install_actuator_toolchain_ensure now reach CLI via the typed why string.

3. Re-minted token/SOL path authorities

  • Deleted srv3_bmcweb_token_path_for_observe / srv3_sol_console_log_path_for_observe from observe_script.
  • srv3_os_install_diagnostic + host_effect_realize wire srv3_bmcweb_token_path (srv3_os_install_actuate) and srv3_sol_console_log_path (srv3_sol_console_capture) — same literals, single authority, no fork.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37816, composer-2.5)

Verdict acknowledged — no findings, no further code changes.

Confirms 108c4b9 addressed the prior REQUEST_CHANGES (37802): NotConverged propagation, canonical srv3_bmcweb_token_path / srv3_sol_console_log_path wiring, roster/scaffold discipline intact. Scope 3 (shell_exec_via_bash runner deletion) remains gated on three-merge resolve per calm-ferret-849 sequencing (#6586 + #6596 + this PR).

— sent from deep-newt-523

briansrls and others added 2 commits July 14, 2026 07:39
Witnesses now assert srv3_actuator_toolchain_* invariants on the live
host_effect_realize argv path. Delete unused bash script builders.
Coalesce duplicate srv3_os_install_diagnostic imports in reconcile modules.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressing REQUEST_CHANGES (37817, opus)

Both findings valid — fixed in cafb956 + 59d0765:

1. Doubled srv3_os_install_diagnostic imports

  • Coalesced into one import block in srv3_os_install_reconcile_apply.dag and srv3_os_install_reconcile_dry_run.dag.

2. Toolchain witnesses grep dead script

  • Deleted os_install_actuator_toolchain_ensure_script() and all bash builder helpers from srv3_os_install_actuator_toolchain_ensure.dag (entrypoint-only module now).
  • Witnesses re-anchored on live realizer in host_effect_realize.dag:
    • srv3_actuator_toolchain_privileged_apt_install_args (single argv authority used by srv3_privileged_apt_install)
    • srv3_actuator_toolchain_realizer_apt_install_is_privileged_gated
    • srv3_actuator_toolchain_realizer_websocat_uses_github_release_not_apt
    • srv3_actuator_toolchain_realizer_websocat_installs_to_modeled_path_with_namespace_upsert
  • Dissolution Scaffold now binds realize_os_install_actuator_toolchain_ensure in host_effect_realize.
  • srv3_os_install_actuator_toolchain_ensure.dag removed from medium_structure roster (no remaining medium-as-string surface).

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37824, opus)

Verdict acknowledged — no blocking items.

Non-blocking nits addressed in a914a32:

  1. Duplicate failure-reason helper — srv3_shell_exec_failure_reason deleted; shell_exec_failure_reason_headered(observed, header) is the single authority; srv3 reconcile passes its header string.
  2. Roster note contradiction — medium_structure_clean_tree_unquarantine_note updated: checklist restored + observe_script added; toolchain_ensure removed from roster after script-oracle deletion.
  3. PR title "THEN delete shell_exec_via_bash" — intentionally aspirational scope 3, gated on three-merge resolve (Shell→dag P5a: the 7 MECHANICAL srv3 tail files → typed observe/effect rows on host_effect_apply (their dissolution triggers already name this destination; receipt echoes → typed receipts); do NOT delete gunbc.shell_bash_runner.shell_exec_via_bash yet (P5b owns that deletion once no caller remains); #6586 + Shell→dag B1 (operator-signed 2026-07-14: in-process typed reconcile): ubuntu_install_media_fetch.dag (21 RawLines) + ubuntu_seeded_install_media_remaster.dag (39 RawLines) stop emitting shell ENTIRELY — replace ShellProgram/serialize_bash with in-process typed reconcile: observe(path) → Observation #6596 + this PR) per calm-ferret-849; not claimed delivered in code.

— sent from deep-newt-523

Terminal reason must not claim extdeps.apt.PackageManager.Install /
curl.Http realization while host_effect_realize still composes generic
WitnessBin.Run argv (composer 37826).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressing REQUEST_CHANGES (37826, composer-2.5)

Finding valid — fixed in d9cbc332:

srv3_os_install_actuator_toolchain_ensure_scaffold Terminal reason no longer claims "typed apt/curl/websocat argv effects". It now matches the checklist honesty pattern: entrypoint routes through host_effect_apply, while host_effect_realize still composes generic WitnessBin.Run hand-built argv pending extdeps.apt.PackageManager.Install / curl.Http dispatch.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Addressing REQUEST_CHANGES (37836, composer-2.5)

Finding was valid — fixed in 6c0e287:

Host-placement / transport mismatch

realize_os_install_actuator_toolchain_ensure now reads effect_intent.transport and threads it through all toolchain mutations (not only the gated privilege check):

  • srv3_transport_witness_bin_success — LocalShell → gunbc.WitnessBin.Run; SshShell → ssh_session_exec with composed argv (same dispatch shape as deploy_access_sudo_check_cmd and run_shell_transport for observe).
  • srv3_apt_tool_present / srv3_tool_bin_path / srv3_apt_tool_version_ok — command -v + version probes honor SSH host.
  • srv3_privileged_apt_install, websocat mkdir/curl/chmod, srv3_chown_directory_to_current_user, srv3_transport_test_executable — all transport-dispatched.
  • EmitArtifactThenThinRun — fail-closed refusal at realize entry (not silently false in helpers).

Witness added in f30d227c: os_install_actuator_toolchain_ensure_rejects_emit_artifact_transport.

CI re-running on f30d227c.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37846, composer-2.5)

Verdict acknowledged — no findings, no further code changes.

Confirms P5b scope: two heavy srv3 entrypoints on typed host_effect_apply/host_effect_apply_gated, fail-closed target/transport mismatches, honest Scaffold/Terminal dispositions, roster hygiene (toolchain dropped, observe-script carved out), transport witnesses (f30d227c). shell_exec_via_bash retention matches stated conditional scope — deletion gated on three-merge resolve (#6586 + #6596 + this PR).

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37848, claude-opus-4-7)

Verdict acknowledged. SSH shell-string nit noted — non-blocking, no code change in this PR.

Verified against 6c0e287 / f30d227c: the SshShell arms in srv3_transport_* helpers do compose command strings for ssh_session_exec (concat("test -x ", path), command -v, srv3_join_shell_words, etc.). Finding is structurally accurate.

Why it stays in this PR (interim, not silent dilution):

  1. LocalShell is typed argv — gunbc.WitnessBin.Run / shell.Which / shell.Test (construction-side); only the SSH handler gap serializes.
  2. Same class already rostered upstream — ci_deploy_access.dag (deploy_access_sudo_check_cmd, deploy_access_observed_principal) uses identical ssh_session_exec(host, concat(...)) over SshShell; it is on medium_structure_exception_roster. This PR's transport dispatch mirrors that established handler pattern to fix the §5 host-placement bug (privilege over SSH, mutations local).
  3. Observe medium-as-string is honestly carved — rostered srv3_install_diagnostic_observe_script.dag + Scaffold; realize layer delegates via run_shell_transport + shell_exec_via_bash only for that rostered script.
  4. Follow-up (out of P5b) — dissolve SSH arms via SshShell → typed argv handler split (or shared transport helper extracted beside rostered ci_deploy_access) once extdeps dispatch lands; not expanding roster baseline for realize-layer glue in a migration PR whose stated gate is the two heavy entrypoints.

— sent from deep-newt-523

briansrls and others added 7 commits July 14, 2026 09:17
Union P5a typed effect variants with P5b heavy entrypoints; route P5b
realizers before srv3_host_effect_script_for; reconcile apply/dry_run
stay on srv3_host_effect_apply; path authorities via srv3_actuate_shell_paths.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37918, claude-opus-4-7)

Verdict acknowledged. SSH argv concat advisory noted — non-blocking, already partially addressed in feb5a077.

Verified: srv3_join_shell_words / srv3_transport_witness_bin_success SshShell arms do compose command strings for ssh_session_exec; host_effect_realize.dag is off medium_structure_exception_roster.

Why no roster/scaffold addition in this PR: P5b scope is the two heavy entrypoints on typed HostEffect; SSH transport glue mirrors rostered ci_deploy_access.dag (deploy_access_sudo_check_cmd same ssh_session_exec+concat pattern). srv3_join_shell_words_controlled_args_note (landed feb5a077) documents controlled-literals-only until typed argv dispatch over SSH — same interim posture as opus 37905 nit. Full dissolution = shared SshShell → typed argv handler (follow-up, not P5b roster baseline growth).

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Main merge complete — 7831c66

Merged origin/main (#6604: fleet_converge_cli _ => fallback exhaustiveness + nightly reds). Conflict resolution: dropped per-variant HostEffect arms in converge_cli_applied_knob_count in favor of main's wildcard (P5a+P5b union unchanged in host_effect.dag).

Merged head: 7831c66 (parent feb5a077 + 8693f60).

P5b scope unchanged: two heavy srv3 entrypoints on typed HostEffect + host_effect_apply/host_effect_apply_gated. Awaiting CI + fresh api-review on this head.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37965, composer-2.5)

Verdict acknowledged — no findings, no code changes.

Verified at 7831c66 (post-main-merge head): both heavy srv3 entrypoints route through typed HostEffect + host_effect_apply/host_effect_apply_gated; toolchain ensure uses WitnessBin argv on LocalShell (no concat bash script); diagnostic observe is fail-closed via Srv3InstallDiagnosticObserve with refusal witnesses; medium-structure roster baseline 62 with honest Scaffold on carved-out observe-script module. Remaining bash-emit / shell_exec_via_bash debt explicitly scoped to wave follow-up per PR title "THEN" clause — unchanged.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (37969, claude-opus-4-7)

Verdict acknowledged. SSH argv concat advisory accepted — non-blocking, no code change in this PR.

Verified at 7831c66: srv3_transport_witness_bin_success, srv3_apt_tool_present, srv3_tool_bin_path, and srv3_chown_directory_to_current_user SshShell arms compose command strings via concat/ssh_session_exec; LocalShell arms use typed WitnessBin.Run argv. On-carrier srv3_join_shell_words_controlled_args_note (landed feb5a077) documents controlled-literals-only until typed SSH argv dispatch.

Why no roster entry here: P5b scope is the two heavy entrypoints on typed HostEffect; SSH transport glue mirrors rostered ci_deploy_access.dag (deploy_access_sudo_check_cmd same pattern). Adding host_effect_realize.dag to the roster would grow baseline without dissolving the concat in this PR — follow-up = shared SshShell → typed argv handler (same dissolution target named in prior opus/composer approvals 37905/37918).

— sent from deep-newt-523

briansrls and others added 2 commits July 14, 2026 19:04
Remove leftover conflict markers from main merge; keep P5b dedicated
realizers alongside SetHostnameCas HostnameOnHost routing in the
exhaustive resolve_host_effect_cell / host_effect_apply folds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Re: REQUEST_CHANGES review @ 3ed36d19 (dashboard review 38007)

Verified against current tree — already addressed on latest head 986b13a2 (post-review):

  1. Conflict markers — present at 3ed36d19 (<<<<<<< HEAD in host_effect_realize.dag); absent on 986b13a2 (grep clean).
  2. SetHostnameCas / HostnameOnHost — dropped in the conflicted intermediate; restored on current head (SetHostnameCas → HostnameOnHost in HostOs arm; HostnameOnHost apply/gated/directive arms present).

This session (snappy-swift-211) is archived after #6595 merge (9bc98114); it does not own #6587 and is not pushing further commits here. The finding was valid on the reviewed SHA; the #6587 branch owner should re-trigger review on 986b13a2 to clear REQUEST_CHANGES.

— sent from snappy-swift-211

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Re: APPROVE review 38014 @ 986b13a2

Verified: approval matches current head — typed srv3 effects on host_effect_apply, observe carve-out scaffold, toolchain oracle removal, roster swap, and prior conflict/SetHostnameCas regressions are resolved on this SHA (see prior snappy-swift-211 note on 3ed36d19 → 986b13a2).

No fix commit from snappy-swift-211 (archived; #6595 merged @ 9bc98114). This APPROVE is valid for #6587's owning lane; not actionable here.

— sent from snappy-swift-211

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (38014, composer-2.5)

Verdict acknowledged — no findings, no code changes.

Verified at 986b13a2: both heavy srv3 entrypoints on typed HostEffect + host_effect_apply/host_effect_apply_gated; observe script rostered (srv3_install_diagnostic_observe_script.dag) with bash-emit Scaffold; toolchain script-oracle builders removed from entrypoint; fail-closed transport/target witnesses live; roster baseline 62 (toolchain_ensure off, observe_script on). Remaining shell_exec_via_bash/concat debt explicitly scaffolded per PR title "THEN delete" — unchanged.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (38016, claude-opus-4-7)

Verdict acknowledged. Advisory nits accepted — no code changes in this PR.

  1. Observe-script medium-as-string — confirmed enrolled: medium_structure_exception_roster row at medium_structure_containment.dag:199, on-carrier Scaffold { dissolves_to: RealizationDispatch } on srv3_install_diagnostic_observe_script.dag. Transient bash-emit debt on correct side of wall.

  2. Per-effect ResolvedHostEffectCell variants — accepted as same pattern as pre-existing HostnameOnHost/ConvergeOnHost siblings; dissolution target = single realizer-dispatch surface (follow-up, not P5b scope growth).

  3. Synthesized toolchain reconcile evidence — srv3_toolchain_ensure_reconcile already uses honest header "OsInstallActuatorToolchainEnsure synthesized receipt from typed per-tool ensure results" (landed feb5a077); acknowledges ShellEffectApplied is a receipt carrier for typed WitnessBin results, not a literal shell exec. Dedicated ToolchainEnsureApplied evidence variant = follow-up when effect-evidence lattice is next extended.

— sent from deep-newt-523

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Re: APPROVE review 38016 @ 986b13a2 (claude)

Verified all three non-blocking notes against current head:

  1. srv3_install_diagnostic_observe_script.dag — medium-as-string bash via concat; discipline satisfied: on-carrier Scaffold { dissolves_to: RealizationDispatch } (bash-emit trigger) + roster row at medium_structure_containment.dag:199, baseline still 62 with documented swap. No change needed.

  2. host_effect_realize.dag resolve-cell variants — Srv3DiagnosticObserveOnHost / OsInstallActuatorToolchainOnHost follow the existing per-effect variant pattern (HostnameOnHost, ConvergeOnHost, …). Acknowledged as corroboration for eventual realizer-dispatch dissolution; not a P5b regression.

  3. srv3_toolchain_ensure_reconcile evidence — confirmed: typed WitnessBin.Run path synthesizes ShellExecObserved then ShellEffectApplied (lines ~556–562). Valid stretch; tracked as follow-on debt (dedicated toolchain evidence variant), not blocking this PR’s typed-entrypoint migration.

CI: latest build fail was self-hosted runner communication loss (run 29361099502), not a compile error on this SHA. Re-ran failed jobs.

No fix commit from snappy-swift-211 (6595 lane archived); findings accepted as documented above.

— sent from snappy-swift-211

@briansrls
briansrls merged commit 8f57815 into main Jul 14, 2026
3 of 4 checks passed
@briansrls
briansrls deleted the session/deep-newt-523-p5b-srv3-heavy branch July 14, 2026 20:32
@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Coordinator response — feedback item 1 (APPROVE 38014, composer-2.5)

Already addressed — no fix commit.

Verified against merged main @ 8f5781577 (#6587 landed 2026-07-14T20:32:56Z):

Approval claim Status on merge commit
Both heavy srv3 entrypoints → typed HostEffect + host_effect_apply/host_effect_apply_gated ✅ srv3_install_diagnostic_checklist.dag (Srv3InstallDiagnosticObserve); srv3_os_install_actuator_toolchain_ensure.dag (host_effect_apply_gated)
Observe script carved + rostered with bash-emit Scaffold ✅ srv3_install_diagnostic_observe_script.dag on roster; on-carrier dissolution trigger
Toolchain script-oracle builders removed from entrypoint ✅ entrypoint-only module; realizer in host_effect_realize
Roster baseline 62 (toolchain_ensure off, observe_script on) ✅ medium_structure_exception_roster_size_baseline: 62; note documents swap
Remaining shell_exec_via_bash debt explicitly scaffolded ✅ dissolution triggers + PR title "THEN delete" sequencing unchanged

Lane owner (deep-newt-523) already posted matching responses @ 986b13a2 pre-merge. No duplicate code changes.

Feedback item 2 (+1 queued: APPROVE 38016, claude-opus-4-7)

Same disposition — advisory nits only; lane response @ 19:33 covers all three points. No coordinator action.

Merge readiness (re-evaluated)

Gate Status
≥2 api-review APPROVE ✅ 38014 + 38016 (+ prior review chain)
No REQUEST_CHANGES ✅ (38007 conflict regression cleared on 986b13a2 pre-merge)
mergeable=CLEAN ✅ merged
CI green ✅ build + ci SUCCESS on merge run

Stopping — operator merged manually; no further work on #6587.

— sent from nimble-boar-198

@gunbai-bot

gunbai-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor Author

Response to APPROVE (38016, claude-opus-4-7)

Verdict acknowledged — all three findings verified on merged main @ 8f5781577. No fix commit (PR already operator-merged; findings are non-blocking advisory).

Finding 1 — observe-script medium-as-string (srv3_install_diagnostic_observe_script.dag)

Valid, discipline satisfied.

  • Module builds bash via nested concat (medium-as-string class).
  • Enrolled on medium_structure_exception_roster @ medium_structure_containment.dag:199.
  • On-carrier Scaffold { dissolves_to: RealizationDispatch } with bash-emit dissolution trigger present.
  • Executable backstop (v2.lens.medium_structure_containment) covers it; baseline stays 62 with documented P5b swap note.

Transient debt is on the correct side of the wall — no change.

Finding 2 — per-effect ResolvedHostEffectCell variants (host_effect_realize.dag:79-80, dispatch @ ~702)

Valid observation, not a P5b regression.

  • Srv3DiagnosticObserveOnHost / OsInstallActuatorToolchainOnHost follow the existing per-effect variant pattern (HostnameOnHost, ConvergeOnHost, ShellOnHost, …).
  • Each new variant corroborates the eventual realizer-dispatch dissolution target; tracking as follow-up, not blocking this PR’s typed-entrypoint migration.

Finding 3 — srv3_toolchain_ensure_reconcile evidence stretch (host_effect_realize.dag:234, synthesis @ ~556)

Valid stretch, partially mitigated on merge head.

  • LocalShell path is typed WitnessBin.Run per-tool checks; reconcile synthesizes ShellExecObserved then ShellEffectApplied evidence.
  • Failure arm already uses honest header: "OsInstallActuatorToolchainEnsure synthesized receipt from typed per-tool ensure results" (not a literal shell exec claim).
  • Dedicated ToolchainEnsureApplied evidence variant = follow-up when effect-evidence lattice extends; not blocking.

Lane owner responses @ 986b13a2 (19:33, 19:38) match the above — no duplicate commits.

Merge readiness (re-evaluated)

Gate Status
≥2 api-review APPROVE ✅ 38014 + 38016
No REQUEST_CHANGES ✅
mergeable=CLEAN ✅ merged @ 2026-07-14T20:32:56Z
CI green ✅ build + ci SUCCESS

Stopping — operator merged; no further work on #6587.

— sent from nimble-boar-198

briansrls added a commit that referenced this pull request Jul 14, 2026
… it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 14, 2026
…ous kind-path check

Two independent floor reds, both blocking the queue, fixed together per operator request (single PR):

1. Batch-1 compile-clean (non-exhaustive match): #6587 added the Srv3InstallDiagnosticObserve
   and OsInstallActuatorToolchainEnsure HostEffect variants but did not update
   converge_cli_applied_knob_count (dag/gunbc/fleet_converge_cli.dag). Its explicit-arm match
   (no wildcard — #6604's fail-closed design) correctly rejected them at compile-clean. Add both
   arms => fallback, consistent with all non-ConvergePlan siblings; the match now covers all 18
   HostEffect variants. (SetHostnameCas already landed on main via #6625.)

2. Batch-2 roster witness (ci_floor_optin_roster_witnesses): witness_entry_kind_path_agree
   demanded ExecutionWitnessKind entries live under src/v2/test/claim/execution/, colliding with
   the operator's 5s-rule (>5s witnesses live under long/), where the Gate-1 keystones correctly
   live. The check is vacuous (DESIGN §5 second-representation): scheduling partitions by w.kind
   (entry_kind_is_execution), discovery is dir-gated, and witness_kind_wins_over_path already pins
   kind as authoritative. Delete the cluster (execution_corpus_scope_prefix + the two agreement
   fns) and its two live consumers (witness_live_roster_kind_path_agree,
   witness_projected_ci_entries_kind_stamped).

Verified by execution: whole-tree compile-clean 0 diagnostics; ci_floor_optin_roster_witnesses,
commit_workflow_span_kind_witnesses, commit_workflow_witnesses all green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 14, 2026
…ous kind-path check (#6633)

Two independent floor reds, both blocking the queue, fixed together per operator request (single PR):

1. Batch-1 compile-clean (non-exhaustive match): #6587 added the Srv3InstallDiagnosticObserve
   and OsInstallActuatorToolchainEnsure HostEffect variants but did not update
   converge_cli_applied_knob_count (dag/gunbc/fleet_converge_cli.dag). Its explicit-arm match
   (no wildcard — #6604's fail-closed design) correctly rejected them at compile-clean. Add both
   arms => fallback, consistent with all non-ConvergePlan siblings; the match now covers all 18
   HostEffect variants. (SetHostnameCas already landed on main via #6625.)

2. Batch-2 roster witness (ci_floor_optin_roster_witnesses): witness_entry_kind_path_agree
   demanded ExecutionWitnessKind entries live under src/v2/test/claim/execution/, colliding with
   the operator's 5s-rule (>5s witnesses live under long/), where the Gate-1 keystones correctly
   live. The check is vacuous (DESIGN §5 second-representation): scheduling partitions by w.kind
   (entry_kind_is_execution), discovery is dir-gated, and witness_kind_wins_over_path already pins
   kind as authoritative. Delete the cluster (execution_corpus_scope_prefix + the two agreement
   fns) and its two live consumers (witness_live_roster_kind_path_agree,
   witness_projected_ci_entries_kind_stamped).

Verified by execution: whole-tree compile-clean 0 diagnostics; ci_floor_optin_roster_witnesses,
commit_workflow_span_kind_witnesses, commit_workflow_witnesses all green.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 14, 2026
Merge 21da4af dropped Srv3InstallDiagnosticObserve and
OsInstallActuatorToolchainEnsure HostEffect match arms added by main

Co-authored-by: Cursor <cursoragent@cursor.com>
#6587/#6625, breaking compile-clean on the non-exhaustive match.
briansrls added a commit that referenced this pull request Jul 14, 2026
…nts from #6619 + #6587 landed armless) (#6634)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 14, 2026
Merge 21da4af dropped Srv3InstallDiagnosticObserve and
OsInstallActuatorToolchainEnsure HostEffect match arms added by main

Co-authored-by: Cursor <cursoragent@cursor.com>
#6587/#6625, breaking compile-clean on the non-exhaustive match.
briansrls added a commit that referenced this pull request Jul 15, 2026
…lDiagnosticObserve/OsInstallActuatorToolchainEnsure arms (#6651)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 16, 2026
… 2 receipts recorded pending operator sign-off (#6734)

* shell→dag arc: record operator flag signs on the census carrier (2a(i)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address #6571 review: reconcile P2/B1 consequence (for/heredoc band superseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* Fix #6571 CI red: ROADMAP.md is a GENERATED projection — move the slice-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fix quadratic receipt-emit fold (bare-minimum-cost ruling): left-associated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* Complete the HostEffect arm set: dedupe SetHostnameCas (merge doubled it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: shell -> dag

* WIP: shell -> dag

* plans: refresh shell_emission_model status — Slices 0/1(If band)/2 have LANDED

The .dag carrier is the authority (§6), and its status lines had gone stale
against the tree. Verified by reading the live tree on 2026-07-16, not by grep:

- Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a
  real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations,
  on_exhausted}; :235 routes it through orch_emit_step, with
  ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift
  gate and the yaml parse gate rather than masking with a hand-spelled fallback).
  Its stated precondition is also resolved: Retry.on_exhausted is no longer
  emitter-ignored (05_emit_orchestration.dag:503 -> :627).
- Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and
  every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03
  pre-runtime census found zero justified sites) — a decision, not a gap.
- Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via
  gunbc converge --host + the sanctioned fresh-standup bootstrap arm);
  EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST
/ the For-While scope ruling / the bash-minimization rule all stand as signed.
Only status facts changed.

Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto
finished work today. Added an explicit warning that status lines here are
load-bearing and the tree is the ground truth.

docs/plans/shell-emission-model.md regenerated via the generated-artifact gate
(PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: shell -> dag

* plans: address review 38787 — Slice 1 marker + stop contradicting the roadmap authority

Both findings from cursor/composer-2.5 verified against the tree and valid.

Finding 1 (Slice 1 §5 row had no LANDED marker while §1 said it landed):
FIXED. The §5 Slice 1 row now records LANDED with its receipts (#6475, tier-2
band #6566, operator-signed as 6-shell-slice1) and states that For/While refuse
BY DESIGN rather than reading as unfinished work. That inconsistency was exactly
the failure mode this PR exists to fix.

Finding 2 (roadmap_authority.dag 6-shell-slice2 is done:false while this PR
claimed Slice 2 LANDED — two carriers disagreeing, §3):
VALID, fixed in the other direction from what the review suggested, for a reason
the review did not have: every done:true row in roadmap_authority.dag is wrapped
in sign(s: signed(by: "operator", works: true, scope_equivalent: true,
as_expected: true)). That is an OPERATOR ATTESTATION. There is no precedent in
that carrier for done:true + Unsigned. So "follow the same pattern for Slice 2"
would mean forging an operator signature, which I will not do.

Instead this doc stops asserting a verdict it has no authority to give:
- roadmap_authority.dag is named as THE status authority; this doc must not
  contradict it.
- The Slice 2 row now reports only what tree receipts prove (.github/
  fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and
  emits one artifact; EmitArtifactThenThinRun is a live transport arm) and marks
  the slice WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING.
- FLAGs 2a(i)/2b/2c named in the roadmap row are not resolvable from tree
  receipts, so the verdict is explicitly left to the operator.
- §1 is reworded to match, so the two sections no longer disagree either.

Also noted: the "~275 lines / 12+ fn defs" fleet_converge_emit row in the
residual census is stale against the current emitter (same class of staleness
this PR fixes).

docs/plans/shell-emission-model.md regenerated (PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 18, 2026
Root cause was the inverse of the working theory: the 8 missing names
(nbd_proxy_serve_script, nbd_proxy_serve_program_statement_count,
nbd_proxy_serve_program_foreground_command_is_websocat,
nbd_proxy_serve_bash_emit_dissolution_trigger, install_media_fetch_script,
os_install_actuator_toolchain_ensure_script{,_uses_github_release_not_apt_for_websocat},
os_install_actuator_toolchain_ensure_is_privileged_gated_for_apt) were
deliberately deleted on main by the Shell->dag migration (#6587 8f57815,
#6596 c8169ef, #6629 9ffeb27, all ancestors of merge-base c2859a6),
with their consuming tests updated in the same PRs. The strip re-apply
(ab44ec2) clobbered 6 consuming files back to pre-migration content,
leaving dangling references. Re-adding the old decls would resurrect the
terminally-deleted bash sidecar (e06ea6a, operator ruling 2026-07-18).

Fix: restore the 6 consuming files to their merge-base c2859a6 content
(identical to merged-main tip 14c8d29), minus import blocks, plus the
8 qualification lines D1/D2 precedent requires (std.disposition.Terminal,
3x std.resources.Network, 3x gunbc.srv3_nbd_proxy_serve_intent.*,
extdeps.bmc.webui.nbd_proxy_serve.srv3_nbd_proxy_local_port).

Histogram: TOTAL_HARD 149 -> 136 (-13 = exactly the family sites);
all 8 family NAME rows gone; zero new SITE rows (site-level diff clean;
8 new NAME-table entries are top-50 truncation backfill, present as
baseline sites in untouched files).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Jul 20, 2026
…-derived loader (salvage) (#6848)

* reland increment: expand generic-product scrutinees from census decls (194 -> 180)

A value typed by a census-resolved fn sig carries its ANNOTATION nominal (the
qualified name as written), not a resolved structure. expand_scrut_from_decl
returned generic PRODUCT decls unexpanded (else-arm scrut_node), so record
destructures over such values fell through name comparison (dotted scrut name vs
bare ctor) into VariantNotFound — the UpsertClassification x14 family. The
generic-product arm now instantiates the decl's fields with the use-site args
(same substitute_type_slots the alias arm uses); record_destructure compares the
scrutinee's base name (qualified_last_segment) so unexpanded dotted nominals
still destructure.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Revert "WIP: namespace migration"

This reverts commit 485853c.

* WIP: namespace migration

* reland increment: qualification-invariant brand comparison + transparent-alias grounding (180 -> 154)

TypeMismatch family root: nominal_call_arg_brand_mismatch compared authored
name STRINGS, which broke two ways post-strip. (1) A qualified spelling on one
side (extdeps.github.pulls.PullRequest formal vs PullRequest actual — the same
decl) read as a brand conflict: names now compare by qualified_last_segment,
which exactly restores pre-strip precision (bare-vs-bare). (2) Transparent
primitive aliases (Timestamp = String) are brand-ERASING by design
(is_transparent_primitive_alias_rhs), but census-path resolution grounds one
side to the kernel type while the other keeps its authored spelling; a new
brand_grounds_transparently_to exception treats a brand as equal to the kernel
type its alias grounds to (both directions). kernel_value_declared_type_mismatch
gets the same last-segment normalization. GUNBC_ARG_PROBE/GUNBC_PEEL_PROBE
env-gated probes added (inert; removed before the re-land gate).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Qualify-on-borrow hardening: qualification-invariant compares + container dispatch

Burndown 154 -> 149 (whole-tree compile-clean, honest corpus), net of the
qualify-on-borrow landing (181 peak at the raw seed mirror):

- type_name_compatible (00_core): both-dotted -> exact path equality; mixed
  bare/dotted -> last-segment (pre-migration precision, end-state precision
  when both sides qualify). Wired into node_type_compatible fallback,
  node_type_equals_core (all name arms), prefer_specific_type (join keeps
  the structured side over a name-compatible bare leaf).
- module_path_segments + qualified_last_segment moved 04_env -> 00_core
  (single authority; 04_env re-exports for existing importers).
- Container dispatch is qualification-invariant: canonical_template_name,
  is_declared_container_alias_spelling, node_is_set_collection normalize via
  qualified_last_segment before the container_template_algebra table
  (std.types.Map IS Map; -4 InternalError).
- medium_fidelity_witness_test: qualify the 4 Medium<...> return annotations
  (bare Medium is census-ambiguous from test.claim.* -> correct tie-refusal;
  the D2 pass had qualified ctor heads but not annotations).
- Probes GUNBC_VNF_PROBE / GUNBC_SIG_PROBE added (env-gated, removed before
  the reland gate).

Known residue (measured, tracked): std.computation kernel_algebra_profile
|> get pair (2, method-path, next lane); std.fermi |> first pair is
pre-existing (visible pre-154); reference_deps generic-param leak family
morphs (T-field rows).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* Restore nbd/actuate/toolchain decl family (import-stripped)

Root cause was the inverse of the working theory: the 8 missing names
(nbd_proxy_serve_script, nbd_proxy_serve_program_statement_count,
nbd_proxy_serve_program_foreground_command_is_websocat,
nbd_proxy_serve_bash_emit_dissolution_trigger, install_media_fetch_script,
os_install_actuator_toolchain_ensure_script{,_uses_github_release_not_apt_for_websocat},
os_install_actuator_toolchain_ensure_is_privileged_gated_for_apt) were
deliberately deleted on main by the Shell->dag migration (#6587 8f57815,
#6596 c8169ef, #6629 9ffeb27, all ancestors of merge-base c2859a6),
with their consuming tests updated in the same PRs. The strip re-apply
(ab44ec2) clobbered 6 consuming files back to pre-migration content,
leaving dangling references. Re-adding the old decls would resurrect the
terminally-deleted bash sidecar (e06ea6a, operator ruling 2026-07-18).

Fix: restore the 6 consuming files to their merge-base c2859a6 content
(identical to merged-main tip 14c8d29), minus import blocks, plus the
8 qualification lines D1/D2 precedent requires (std.disposition.Terminal,
3x std.resources.Network, 3x gunbc.srv3_nbd_proxy_serve_intent.*,
extdeps.bmc.webui.nbd_proxy_serve.srv3_nbd_proxy_local_port).

Histogram: TOTAL_HARD 149 -> 136 (-13 = exactly the family sites);
all 8 family NAME rows gone; zero new SITE rows (site-level diff clean;
8 new NAME-table entries are top-50 truncation backfill, present as
baseline sites in untouched files).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Convergence sweep 1: un-resurrect main's de-forks + witness-lane closure unification

149 -> 123 whole-tree; witness roster 299 -> ~10 fatal. Two independent roots,
one class: the strip re-apply (ab44ec2) resurrected pre-migration file
content that main had since consolidated — a silent census poison (§3 forks
by resurrection).

- src/v2/std/algebra.dag: take main's (#6715 dissolved the v2 algebra tower
  onto std.algebra; the branch carried the old stacked fork, so flat literals
  in diagnostic/nat/logic refused, and after the first restore the stale
  stacked CONSUMERS integer.dag/seed_debt flipped red — both now main's).
- src/v2/lens/{effect,idempotency,ownership,parallelism}.dag: take main's
  (lens-commons consolidation into algebraic_composition.dag; the branch had
  hand-cemented stub forks like `type EffectClassification {}`).
- Cherry-pick a6e9f4f9cd: nbd/actuate/toolchain family — the 6 consuming
  files restored to merge-base-minus-imports (the decls were deliberately
  deleted on main by the Shell->dag migration; full provenance in that
  commit body). -13, exactly the family.
- cli_run: extend_with_reference_closure extracted — the ONE reference-
  closure authority now serves BOTH the whole-tree walk and the per-entry
  claim/witness loader (was a §3 fork: the roster path missed reference-only
  deps entirely).
- find_witness_project_to_core_controls + derivable_coercion_task_id:
  qualify one dotted reference per foreign module (Rule-1: references ARE
  the dep edges; a bare-only file has no closure) + Named->v2.std.node.Named
  (non-unique variant). Witness file 298 errors -> 5 (owned families).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Mechanical burndown: classifier-driven qualifications + stale-file adoption (123 -> 89)

From the residue-classification agent's bucket list (all census-verified):
- Bucket (a) source qualifications: merge_admission Success/Failure ->
  extdeps.github.checks.* (the borrowing-module alias path), review/review_codex
  state Open -> extdeps.github.pulls.Open, upsert Absent (builtin-Witness
  collision), srv3_install_media Present{observed_sha256} (bare Present hit
  builtin Witness.Present), roadmap authored() -> gunbc.roadmap_authority
  (nearest-ancestor picked the test sibling by design; source must qualify),
  01_tokenize Empty/None/Accepted/Rejected -> std.algebra./v2.std.diagnostic.*,
  coverage + grammar_coverage Empty.
- Bucket (b) stale strip-era copies -> origin/main content minus imports:
  fleet_converge_cli (ProvisionBuildCache arm), falsifier_workflow test
  (cadence rename + semantics), host_build_cache_provision test (rewritten on
  main), behavioral.dag (DeterminismAxis -> std.determinism.Determinism, the
  open-thread-E rename the stale hunk had reverted).
- Deliberately NOT qualified (reverted after measurement): 02_parse
  OccurrenceIdAllocator/SpanIndex and grammar_coverage DeclFact/
  whole_corpus_scope/normalize — those reference edges pull the v2-internals
  subtree (occurrence_id/provenance/normalize -> compilers/sugar + standing_intent
  closures) into the corpus: +75 latent debts and census uniqueness flips
  (Accepted/Rejected aliases). That subtree opens as its own measured batch
  with the witness-roster lane (Increment B), not as a side effect.
- env_with_type_variable_bindings extracted to 04_env (consolidates
  resolve_item_types' inline type-param fold; no behavior change). The
  borrowed-sig resolve-at-borrow experiment was REVERTED after measurement:
  per-lookup resolve_node blows up wall-clock (>10min vs 103s) because the
  borrower's env lacks the owner's recursive-type facts (FreeMonoid expands to
  the depth bound per call). Needs the once-per-module hoist; benched.

Ordering/Equal/Less/Greater rows cleared for free with the algebra-fork
dissolution (previous commit), as the classifier predicted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Kernel container dispatch: one canonicalizer, qualification- and carrier-invariant (89 -> 82)

Root (get-pair agent, proven by probe chain): the kernel algebra machinery is
keyed on raw canonical spellings ("Map"/"List") at MULTIPLE reads — the
profile lookup (enrich_kernel_type, lookup_structural_method), the
container_param_name table behind make_container_type/make_map_type, the
template-match compare (apply_type_substitution ContainerOf), and
is_container_type/container_expected_arity via receiver_name_str. A receiver
spelled by qualify-on-borrow (std.types.Map) or alias-expanded to its carrier
(FreeMonoid, std.algebra.FreeMonoid) sails past the invariant classifiers and
misses these reads; the method-pipe fallback then absorbs the miss by
returning the receiver type, surfacing two hops later as VariantNotFound
Present/Absent (std.computation kernel_algebra_profile |> get; std.fermi
|> first — the latter pre-existing with bare FreeMonoid).

Fix: container_kind_canonical(name) = last-segment, then carrier->canonical
inversion DERIVED from container_template_alias_rows (sorted fold, no minted
table) — applied at the profile lookup (kernel_profile_lookup) and every
authored-name entry into the kind-keyed tables. The interim
missing-kernel-container-profile guard rows this exposed (+66 at the halfway
point) confirmed the reads were reachable and are now all green.

Benched follow-up (own increment, own receipt): the method-pipe fallback's
final else still answers a dispatch miss with the receiver type — an
absorbing fallback to convert to a typed refusal; every currently-absorbed
miss becomes a counted diagnostic.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* Borrowed-sig hoist: census pass 2 resolves generic fn sig returns once per decl at owner position (82 -> 71)

The census stored raw pre-typecheck fn nodes, so borrowed generic fns leaked
bare type-param leaves (T/V/E) into consumers. Pass 2 (census_with_resolved_fn_sigs)
resolves each borrowable generic sig's return ONCE at census build in a synthetic
owner-position env (module_path = declaring module, symbol_index = completed pass-1
census, type params bound as TypeVariables via env_with_type_variable_bindings) —
order-independent, once per decl (the per-lookup variant re-resolved recursive
carriers to the depth bound per call, >10min), fail-closed staged: any resolution
diagnostic keeps the raw binding (upgraded | raw is a typed frontier, not a widen).
Wall-clock unchanged (~97s). Cleared: payload-on-V x8, refusals-on-T x2, facts-on-T x1.
Remaining: service-op output family (~30, next increment widens pass 2 to services),
T-family residue kept raw by the diagnostic gate (~19, diagnosing).

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Qualify only reference positions: declaration names (variants, fields) are never rewritten (25 -> 16)

Root: qualified_value_projection passed a projected COPRODUCT decl through
qualify_borrowed_type_names, whose whole-subtree walk renamed variant
DECLARATION leaves (Independent -> std.realization.Independent) - every bare
match arm then missed (VariantNotFound + exhaustiveness demanding dotted names,
firing in the OWNER file std/realization.dag itself). Fix at the authority:
qualify_borrowed_type_names now switches on structure - a NoConnective node's
children are generic args (references, rename-eligible); a structured node's
children are DECLARATIONS, walked by qualify_decl_reference_positions (keep the
name, qualify the inferred payload, recurse) - the same walk the census type-decl
pass (2b) uses, consolidated into 04_env as the one authority
(qualify_declaration_position_invariant note). Also cleared: LitNull exhaustiveness
(none => counts as Absent) in the same push, plus the anonymous-Conj nonempty row.

16 = Increment-B subtree 7 (SpanIndex/OccurrenceIdAllocator/DeclFact/whole_corpus_scope/normalize)
+ Frame x2, Job id, mid-on-M, NanosecondDuration x2, Secret-vs-String x2, Terminal.

* WIP: namespace migration

* Expected-driven variant ctor + Frame source qualification (16 -> 13)

record_lit_variant_from_expected: when a ctor's bare name is census-ambiguous but
the EXPECTED type resolves to a coproduct carrying a variant with that last
segment, the ctor types against that variant (fields + result type + presence) -
the sanctioned namespace-only-Y position-info rule (expected type filters to one,
never picks among unrelated candidates). Clears Terminal (data _: Disposition =
Terminal{...} with Terminal census-ambiguous). Frame x2: extdeps/render/terminal
sigs qualify std.render.Frame (genuine homonym vs std.materialization_ladder.Frame,
lcp-0 tie from extdeps position refuses correctly).

13 = Increment-B subtree 7 + Job-id 1 + mid-on-M 1 + NanosecondDuration 2 + Secret 2.

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Kernel-brand preservation through census resolution + pure-alias transparency (13 -> 9)

Secret x2: Secret is IN kernel_type_set, so kernel_value_declared_type_mismatch
walls String-vs-Secret deliberately - but peel/preserve treated brand-over-
primitive as transparent and stripped Secret -> String (an OLD contradiction the
namespace exposure surfaced; previously masked by output opacity). Fix at the
authority: preserve_nominal_brand_on_resolve / peel_nominal_alias_identity keep a
brand whose last segment is itself a kernel type; the census op-output/sig
upgrades route through preserve_nominal_brand_on_resolve (ad-hoc erasure guard
deleted). NanosecondDuration x2: brand_grounds_transparently_to widened to
template-name equality - a pure alias (type X = Measure<...>) is transparent to
its template per section 4, so List<NanosecondDuration> flows where
List<Measure<Time,S,Nat>> is expected.

9 = Increment-B v2-internals subtree 7 + Job-id 1 + mid-on-M 1.

* WIP: namespace migration

* Witness-roster cascade: rust_wire_serde entry chain qualified through v2 core (roster advances past 2 files)

The roster's fail-closed walk advanced past the old T-family fatals (cleared by
the sig hoist) into rust_wire_serde_naming_policy_test: qualified the file's
annotations (v2.std.verification.UnifiedTestClaim x3, v2.std.live_tree.LiveTreeDisposition),
fixture refs (v2.extdeps.languages.rust_wire_serde.*), fn refs
(v2.compiler.translate.target_serialize_source_from_model, v2.std.compilers.target_model.TargetModel),
and the pulled modules' own bare foreign refs (rust_wire_serde -> std.serialization
naming variants + extdeps.languages.rust.emit serde attrs; rust.dag ->
v2.std.grounding fact-bundle fns). Current fatal: 'variant Cons not found in
FreeMonoid' at v2.std.collection List alias - probe shows every bare variant
lookup's scrut DOES carry the variant (the variant_not_found_result calls are
EAGER fallback evaluations discarded on direct-match hit - v1 is strict), so the
surviving diagnostic comes from another emitter; next increment starts there.
Temp VNF child-dump probe left env-gated (GUNBC_VNF_PROBE, removed before gate).

* Hygiene walker: live_tree_disposition row accepts qualified annotation/value spellings (fixes CI early-exit at ec18d98)

The witness naming-hygiene pre-plan text scan (parse_entry_live_tree_disposition,
cli_run.rs hand-seed) compared the annotation and variant by LITERAL prefix, so
the namespace lane's qualified spelling (data live_tree_disposition:
v2.std.live_tree.LiveTreeDisposition = SubstrateInputsOnly, present in 2 witness
files) tripped 'malformed row' and killed CI at 64s before the floor ran. Same
defect class as the session's compare fixes: a raw name compare that is not
qualification-invariant. The scan now compares the last dot-segment of both the
annotation and the initializer variant (mirroring type_name_compatible's
mixed-spelling rule); the typechecked roster compile stays the authority behind
the text scan. Verified locally: claim_executor pre-plan hygiene walk completes
and the floor proceeds (its redness is the known burndown state, 9 rows +
roster fatal).

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* Increment B frontier: qualify map_get/None (kernel-tier bypass), standing_intent+vocab universe, artifact refinement refs, memo carriers, Frame, dag-test cross-corpus collisions (GeneratedArtifact/DesignArtifact/Grounding) — histogram 30 -> measuring; census probe now takes name list via GUNBC_CENSUS_PROBE

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* map_get kernel-vs-v2 fork: qualify all 31 Outcome-shaped bare map_get callers to v2.std.collection.map_get; grounding host_run/verdict quals; rust.dag TargetGenericApply missing field_label_separator (latent defect unmasked); census leaf-binding qualify arm (data/0-param-fn/alias inferred, .dag + seed)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* roster: pattern alias-arm re-expansion (expand_scrut_from_decl has_inferred_alias recurses expansion on substituted target — clears List/FreeMonoid VNF class); qualify sg2_type_expression_projection refs (main-merged file, per-entry closure)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* sg2 test: qualify all borrowed rust.dag refs + cross-test rust_add fixtures (caret symbol literals untouched)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* sg2 test: comprehensive owner-resolved qualification (translate/target_model/verification/content_hash refs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* rust_add_emit_translate + sg2 tests: owner-resolved qualification sweep (eval/translate/emit/rust/live_tree/verification refs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* determinism lens owner-split quals (std.determinism verbs+variants, v2.std.determinism DeterminismFact); infer_ground_add InterpretationAlgebra literal completed with match: MatchInterpreter (latent missing-field defect unmasked by deeper typing)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* DeterminismAxis ghost-name re-grounded on std.determinism.Determinism (open-thread task E consumer-safe rename, unmasked by closure); compile_gate accumulator_copy_findings qual

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* merge-stripped files: apply main's import maps as qualifications (analyze 123, contract 339, sg_claims_test 62, fold_analysis_test 33); rust_enum_derives -> extdeps.languages.rust.emit

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* compiler-layer frontier quals: cross_tree resolution/import_model, cache_identity ids, SymbolicCost

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* cross_tree resolution: qualify LayerPrefix variant values to v2.std.layer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* complete Wave-1 Gate-1 C1 migration branch-side: delete stale copied_port_fact_registry fold locals in complexity_accumulator_copy.dag, re-ground classify_call on v2.lens.cost.copied_port_citations.copied_port_index_of; qualify materialization_carriers memo ids (extdeps.realization.*, extdeps.cache.materialization)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify PerturbationVerdict (std.perturbation authority), Diagnostics None values in 03_name_resolve + rust_add test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* census: variant alias enters global_bare only when no item decl claims the name (Job type-vs-variant tie); roster owned-data walk keys on per-module item_registry (lens_module_gate homonym); qualify accelerator witness test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* pre-qualify cross-module fn calls in import-stripped accelerator demo modules

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualify accelerator demo layer: approximate_field/numerical_fidelity/gpu.types/vendor.nvidia/live_tree owners; revert kernel to_string quals

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* interpreter: register fn_nodes under qualified module.name keys (dotted runtime calls); qualify gpu witness layer

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualified value projection: kernel_span ident so authored_name reads spine.dotted everywhere; interpreter eval_var dotted fallback via qualified fn_nodes; revert kernel to_string qual in gpu module

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* patterns: drop destructive re-resolution of substituted Disj scrut (resolver rebuilt arm payloads from raw decl); scope TypeVariable slot-binding to pattern expansion (resolver unchanged — corpus-wide cost regression); interpreter: qualified unit-variant values from compile-side inferred owner; qualify model witness test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* qualify iam validation test + simd data ref; SIGPATH4 probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* iam test: Deny is std.access.Deny (payload variant), not aws_iam Effect.Deny; SIGPATH5 probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* revert substitute_generics inferred-walk (param capture; M.mid stays declared pre-existing residue)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify access_layer_extension test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* qualify redfish_rbac_policy refs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* bulk-qualify all import-stripped dag/test/claim files (252 files, 8386 refs) via unique-owner sweep

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* revert 160 field-label qualification artifacts; interpreter: variant identity compares last dot-segment (qualified ctor/pattern spellings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* interpreter: variant identity normalized to bare arm name at construction (qualified ctor heads and value bindings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* revert 31 parse-broken files from bulk sweep to pre-sweep state (dots in label/pattern/decl positions); re-qualify individually later

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* pre-gate: finish GUNBC probe-block strip (remove dangling multi-line condition fragments)

Completes the operator-agreed pre-gate scope on top of the auto-WIP snapshot
c4872e2 (which carried the comparator narrowing to pattern-side-only and
the bulk of the probe strip, but raced the strip mid-edit and pushed 6
dangling '&& ...' condition fragments that broke the seed build — the CI
build failure at c4872e2).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* restore prose reference inside merge_lifecycle incident-note string (over-stripped by the 160-artifact regex revert)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* infer: qualified payload-variant construction (roster items 1+8) — stamp parent_enum for dotted spellings (#6869)

* WIP: 6848 cleanup

* ci: re-run against current namespace-wave1-reland base (prior run predates 4 base commits)

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* WIP: namespace migration

* remove stray n89.txt (WIP-harness histogram dump; forced whole-tree compile-clean scope on every CI run)

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* M.mid green: stamp decl-param field types TypeVariable at extraction (main parity); census fill = whole indexed pool

Two fixes, both measured against the gate-equivalent whole-tree compile:

1. M.mid (batch-1 blocker, roster item 4): a field type extracted from a
   param-carrying decl whose spelling is the decl's own type param IS that
   decl's type variable — stamp it Tv at extraction
   (stamp_field_type_from_decl_params, seed + 04_infer.dag authority).
   Main serves exactly this shape (measured ftype[M inf=Tv(M)]) and stays
   green via the Tv deferral arm; the branch's whole-tree path served the
   param bare and unstamped, turning the latent generic-payload hole into
   the loud 'no field mid on type M'. Red control: the witness row present
   -> absent under the whole-tree gate with ZERO other set-diff. Note: main
   is deferral-green, not correct — r.member.mid has never been typechecked
   anywhere; the L1 unchecked-access class stays open as typed debt
   (follow-up: shadowing-aware inferred-walk substitution).
   Also: local_binding_for_item Tv-stamps decl-body param occurrences at
   census-entry construction, and census_upgrade_type_decl_binding tv-binds
   the decl's own params in its env (was []) — census copies now carry the
   local-resolver shape.

2. Census fill = whole indexed pool (namespace design 7.5: fill = whole
   tree; policy gates lookup, never fill): build_symbol_index_for_reconcile
   builds ONE parse-grade census over every indexed module (sorted,
   deterministic), cached per process; merge_symbol_indices deleted — its
   fold dropped provider global_bare (fail-open). Zero diagnostic set-diff
   on the gate; reconcile wall-clock 117s -> 98s.

Whole-tree gate: 35 -> 29 hard diagnostics this session; all 29 remaining
are the single v2.* cross-tree reference class (dotted refs to src/v2
modules outside the import closure — next fix is reference-derived deps in
resolve_transitively, the Rule-1 end-state).

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* namespace census layering: bare = own tree-closure, qualified = whole pool

Batch-1 (whole-tree --target dag gate) GREEN for the first time on this branch:
0 hard diagnostics (was 29 v2.* cross-tree rows), 2206 UnlistedImportUse
advisories (pre-existing non-gating burndown class, grown by design as the wave
strips imports).

Mechanism (namespace-resolution-design.md 7.5: fill = whole tree; policy gates
lookup, never fill):
- closure census stays byte-identical to the no-fill build (bare visibility,
  variant-alias corpus gating, services all closure-scoped) — a pool homonym
  cannot shift what a compiled module's bare names mean (measured: whole-pool
  single census vanished bare GET/Persistent/JsonValue across 28 witness rows)
- census-only fill modules are PARSE-GRADE (tokenize+parse, never resolve:
  resolving fill against a fill-only pool fabricated 797 unresolved-import
  diagnostics about the view, not the modules) and enter a qualified-only
  entries underlay (build_symbol_index_qualified_fill)
- cli_run typecheck additionally underlays each module's OWN tree-closure bare
  census (root modules + import-reached pool modules — gate parity by
  construction, e.g. dag witnesses' bare LiveTreeDisposition declared only in
  v2.std.live_tree), lazily per root (tree_bare_census_for_root)

Proven by execution: gate exit 0 (2m14s); claim_batch on the GET witness now
resolves fully green (was 60+ typecheck errors) and fails only at the known
interpreter fn-registry gap (no such function at runtime — the loader does not
yet derive deps from bare references; batch-2 will quantify that class).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* loader: bare-reference closure via tree census (Rule-1 direction) + discovery qualified-variant fix + .dag mirrors

The import-stripped corpus (83% of dag/test/claim and src/v2) had no import
edges to follow, so witness closures loaded 1 file: typecheck resolved names
through the census while the interpreter never loaded their bodies — 106 of 107
batch-2 FAILs were 'no such function'. The loader now derives deps from names
(namespace Rule-1 direction): entry closure = imports + dotted refs + BARE refs
resolved exactly as typecheck will (census-unique -> that module; ambiguous ->
nearest-ancestor from the referencing module's containment position; tie ->
load nothing, typecheck stays the loud authority), iterated with the dotted
scan to a joint fixpoint (load_sources_for_entry_with_pool).

Pull discipline (measured, not guessed):
- callable-shaped references only: call position 'name(' (the discriminator a
  census stub cannot provide — fn bodies are stripped, so a 0-arg fn and a
  type alias share a census shape) or a census sig with value params (named fn
  passed as argument); types/variants never pull (census-served at typecheck,
  value tags at runtime)
- test-claim modules never serve as providers (execution roots, not deps; an
  over-pulled quarantined v2 test module red under the entry's view killed an
  unrelated dag witness via its 2-param 'edge' helper)

Also: discovery roster accepts qualified coproduct constructors (the #6869
payload-variant class — arm check + stored decl name use the bare last
segment); .dag authority mirrors for the census layering (04_infer.dag
node-base census refactor + layer fns + census-extra twins, compile.dag
census_only_sources + parse_census_fill_sources) — v1 closure typechecks clean.

Proven by execution: gunbhub GET witness (import-stripped, 60+ typecheck errors
at session start, then runtime no-such-function) now PASSES end-to-end through
claim_batch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* claim_batch: continue past group resolve failures (counted FAIL rows, exit stays 1) + bare-pull diagnostic trace

Abort-on-first-red truncated the corpus measurement to one red class per run;
a failed group's witnesses now report FAIL and the batch continues. Read-only
GUNBC_BARE_PULL_TRACE=1 prints each bare-name pull edge (file -> name ->
module) for locating over-pull homonyms.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* typecheck: body-scope binders shadow census fn sigs; loader: service-chain pulls, stripped-file scan gate, binder/key-position lexer; census: kernel names never bare-aliased

Root-causes the CI batch-1 + post-floor reds (dual-surface divergence between
the gunbc-compile gate and the cli_run floor/run surfaces):

- ExprCall sig lookup gates on new InferScope.body_locals (let/match/params) —
  nearest-first precedence; a census-unique homonym (v2 lens test fn classify
  -> Optional<Finding>) no longer out-precedes a let callee (refinement.dag
  match scrutinee red: variant not found in Optional + missing Absent/Present).
- Loader pulls service providers via dotted-chain prefixes against the services
  census (cron.Tab.List() -> extdeps.cron; llm.Codex -> extdeps.llm.cli) — the
  stripped import's only remaining edge.
- Name-derived pulls run for import-stripped files only; binder (let/data) and
  key (name:) positions no longer collect candidates — kills the over-pull that
  coupled unrelated runs to review-agent tooling health ('repo', 'row').
- Census bare variant aliases never claim kernel names (overlay_skips_kernel_name
  authority): a lone closure enum declaring Absent hijacked the kernel Optional
  variant on shrunk closures; qualified module.Vname aliases stay.

Verified: whole-tree gate (dag+v2) exit 0; v1 mirror gate exit 0; exact CI
command gunbc run merge_admission_stamp exit 0; gunbhub/refinement/cron
witnesses PASS. .dag authorities mirrored (04_infer, 05_emit).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* loader: normalize source roots for tree lookup (CI absolute-root no-op), pool-census cross-tree fallback, dotted-head data-const pulls; fixtures: restore floor_skip imports; frontier: deletion hunks attribute to the following line

- source_tree_root_of now normalizes roots to workspace-relative before
  comparing: CI's claim_executor passes absolute --source-root paths, so the
  bare-reference loader AND the per-module census underlay silently no-oped in
  CI while working locally — the core CI-vs-local divergence.
- Loader falls back to a whole-pool census on an own-tree miss (same-tree names
  keep priority) so cross-tree bare refs pull their provider (a v2 module's
  gunbc_ci_spec -> dag/gunbc/ci_spec.dag).
- Dotted-chain heads that are never body-bound resolve as bare data-const
  references (gunbc_ci_spec.diff_policy pulls ci_spec.dag); bound heads
  (let repo; repo.x) stay excluded.
- floor_skip fixtures restored to main's import-bearing form (import-only
  diffs; the frontier resolves them through the raw path).
- Deletion-only diff hunks (+L,0) attribute to line L+1 (the gap sits between
  L and L+1), unifying -U0 and with-context semantics; import-block strips
  under a module header no longer false-fire the line-1 fail-closed refusal;
  +0,0 (module line deleted) still refuses.

Verified: fail_closed_edit_before_first_decl green; both whole-tree gates
exit 0; gunbhub/stamp/refinement/cron witnesses PASS; absolute-root control
(CI-shaped invocation) PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* remove temporary free-call probe witness

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* remove temporary serializer probe witness

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* accelerator: de-qualify builtin-intercepted kernel calls + rename float elem twin; output_policy Diagnostic qualify; hardware_selection bandwidth_count nickname dissolved; drop probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* corpus residue: de-qualify None compares (orch_if x7, rust_add x3); restore 02_parse+bisect+rust_add imports; native is_empty interp method (bridge parity); revert 3 strip-casualty witnesses; re-stamp 5 ReadsLiveTree

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* Merge origin/main (11 commits: cssl/std_dup, belt 2b, shell-intent P0/P1); conflicts resolved main-side for strip-only files; module_path field re-applied at 4 new TypeEnv sites

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848: revert os_systemd_witness_test to main (sweep-qualified refs made SystemdUnitStatus a stale roster entry); drop tmp probe

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848: drop tmp probe plan

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* 6848 cleanup: revert cli_run advisory-batch + governor width-seed hacks to main (operator will rework separately); restore provenance/diagnostic std import blocks (occurrence_id executor-surface fix)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* cleanup: remove GUNBC_FLOOR_INITIAL_WIDTH governor seed again (auto-committer re-captured it during a scratch build); param-leak fix: build_type_env param_bindings excludes body-carrying fns (module-wide value-param Tv leak, main-parity restored); ToolResultText fixture to positional authority shape

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* regen convergence round: emitter lowers Present/Absent with unknown parent to Some/None (both pattern twins, dag+seed mirror; bare variant pattern was never-valid Rust); algebra_method_template_name homed beside AlgebraProfile in dag/std/algebra.dag (was cross-module bare ref in 04_lookup, emit-unqualifiable); compile.dag imports reconcile_with_census_extra; presence wall: census-ambiguity may only skip when no local/import binding resolves the shape (absorbing-skip fix, 04_infer); tests: parse-cache pool-census contract, tier2 census pins to KnownAmbiguous post-triage, module_authority to namespace-only contract; seed restored to 54e24de baseline (auto-committer had captured a broken accept-fresh)

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* regen fixed-point round: split_sig_params sig-typed helper (SigParamSplit) replaces filter/fold idioms the emitter cannot classify over an unresolved receiver; explicit Present wrap at the two census Tv-stamp node_with_inferred sites; CostAccount.time axis spelled at owner Quantity (emitter field-vs-sig variant-as-type-arg fork, note + dissolve trigger); seed = regen_stage0 output, workspace builds clean

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* bare-reference closure: declaration-grain execution-root guard + bound-name filter (review finding 2)

File-grain test-fn skip silently dropped plain-fn providers living beside test rows
(infer_emit_compile_anchor -> anchor_rust_add_emit_accepts died no-such-function at
runtime). Skip is now declaration-grain: only when the resolved name itself is a
test fn / test data row in the provider. Symmetric precision fix on the collector:
plain bare names now subtract the file's own bound set (params, named-arg keys,
let/data binders) exactly as dotted-chain heads already did - lens unit_modeling's
edge param no longer pulls v2.test.manual.ownership_movable (unresolvable src/v1
imports) into unrelated entries. Verified: anchor entry resolves and executes the
cross-file fn; bad pull absent from GUNBC_BARE_PULL_TRACE.

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* test contracts updated to the branch authorities (coproduct wire wall-promotion, reexport control dissolution)

coproduct wire x2: the missing-field presence wall now stops malformed
InternallyTaggedObject literals at TYPECHECK (census-ambiguity absorbing skip closed);
tests assert the typed refusal instead of the decode-time compile_error backstop,
which remains for shapes the literal wall cannot see (bare naming-policy variants).
variant_reexport red control: perturbation dissolved twice over - empty
variant_surfaces+symbol_index resolve via the ancestry global_bare merge, and
dropping the declaring module binds imported names declared-weak (L1 typed-debt
deferral) - converted to purity witnesses + a documented RED-control debt pending
the strict missing-name wall. tier2 census reachability pin (2 AmbiguousBare sites
on extdeps_external_authority_anchor) parked on the non-required rust_tests lane
for post-merge triage.

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* closure: service-backed builtins declare their provider pull (side-effect-import class)

A builtin that dispatches through a service (filesystem_read -> Filesystem.Read)
needs the provider module loaded for its service registration, but contributes no
name any census can resolve - the builtin identifier is the interpreters, not a
modules. Under imports that edge was the name-less import
extdeps.filesystem.filesystem_io; the strip removed it and NOTHING can re-derive it
from names. This is the one genuine hole in the name-derived closure story, and it
is now a declared table (BUILTIN_REQUIRED_SERVICE_KEYS) resolved through the same
services census a dotted service head uses. Rows mirror the interpreters hard
service REQUIREMENT gates only; the optional ones (Clock.UnixSecs, shell.Env.Get)
fall back to a transport and create no closure obligation. A missing row never
fabricates - the builtins own gate still refuses, typed and located, which is
exactly how this row was found (CI 29722434993 batch 3, via interp_recorded_fixture
nested replay). Verified: closure 1 module -> 7, witness_read_via_builtin_roundtrip
PASS.

* WIP: 6848 cleanup

* revert an unjustified guard: the variant/standalone homonym mis-emission is PRE-EXISTING, not a regression

An audit flagged the nullary-variant parent stamp for mis-emitting a standalone
struct literal whose name collides with a nullary variant arm of some coproduct
(fn make() -> Standalone emitting Coll::Standalone { a, b }). Reproduced it, then
tested the attribution: with the stamp redirect forced OFF (main-equivalent), the
emission is BYTE-IDENTICAL. The defect lives on the parent_enum/emit path
(lookup_variant_parent_enum feeding ExprRecordLit.parent_enum), which this branch
does not touch - it is pre-existing on main and belongs in its own typed row, not
here. The guard I had added therefore fixed nothing and is reverted; probes
(variant join, fold-lambda join, collision) all recompile clean without it.

* WIP: 6848 cleanup

* restore the type-confusion wall the variant stamp dropped (audit finding, CONFIRMED)

The nullary-variant parent stamp applied unconditionally, so a name that is a
GENUINE top-level declaration AND a nullary variant arm of some coproduct got
stamped as the coproduct. Reproduced with a main-parity control: type Color = Red |
Blue + type Red { hue: Int } + if f { Red { hue: 5 } } else { Blue } -> main REFUSES
(Product(Red) vs Coproduct(Color)); the branch emitted 0 diagnostics and invalid
Rust (Color::Red { hue } on a nullary arm, E0559, plus a duplicate pub struct Red).
My first attribution of this to a pre-existing emit path was WRONG - that probe used
a non-discriminating shape; the paired redirect-disabled control settles it.

Fix reuses the existing single authority rather than adding a second rule: the
redirect now fires only when binding_declares_name is FALSE for the literal's name -
exactly the predicate lookup_type_by_name already uses to decide declaration vs
variant-arm projection (04_env.dag). Both arms verified: the wall refuses again at
main parity, and the motivating variant-join probes (nullary-vs-payload if-join,
fold-lambda join) stay clean. Regen byte-stable, workspace builds, fmt clean.

Audited-by: adversarial workflow wf_cc7dd19e-87e (two independent reproductions).

* WIP: 6848 cleanup

* Revert probe edit: drop the temporary import extdeps.cloud.gcp.gcp restored in credentials.dag while running the gcp_oauth discriminating control (the control was NEGATIVE - restoring the import does not fix the mock-key failure, so the strip is exonerated for that witness)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* WIP: 6848 cleanup

* Wire strict-tier reference-derived edges into the affected set; delete the widen arm

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

* Split loader and selection edge tiers; fix the precompute regression the shared tier caused

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* WIP: 6848 cleanup

---------

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant