Repository navigation
Roadmap dispatch go-live receipt: first live end-to-end dispatch on srv1 - #7096
Merged
Merged
Conversation
…rv1 (gap 2 closed by execution) + gap 1 closed by the first green deploy; re-dispatch one-shot class filed as a sized ready row Co-authored-by: Cursor <cursoragent@cursor.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
…rendered 'failed'; RED-witnessed on retired j.ok) + claude CLI dependency modeled: extdeps trust-store classifier + belt spawn preflight with typed refusals Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 23, 2026
…ternal (no inline JS string) Rebuilds dispatch_client_js as ONE modeled TsProgram (gunbc.roadmap_component. dispatch_client_program) over extdeps.languages.typescript.program — never a hand-concatenated JS string (the dispatch-button incident's root class, §5). The ok-predicate is a ts_binop `||` chain DERIVED from belt_dispatch_ok_status_labels, so the retired belt-A ok/node read cannot return. Per operator steer (inline <script> is a hack): the script is EMITTED as an external asset and referenced by <script src>, the moodboard reframe_watcher pattern — not inlined. Belt B (roadmap_serve) serves it at roadmap_dispatch_asset_path with a new text/javascript content type (extdeps.http.server.TextJavascriptUtf8). belt_dispatch_path_prefix moved to the wire-vocabulary home (belt_actuate) to break the page<->component cycle. WALL (P1): page_script_census walks the served page tree and refuses two shapes fail-closed — an inline <script> with hand JS text, and a <script src> to an unknown asset. Green over the real page; both REDs (resurrected inline string; rogue src) locate their violation. #7096's j.ok RED preserved, now against the served asset (witness_dispatch_asset_reads_belt_b_status_contract). Deleted: the string dispatch_client_js + its scaffold disposition row. Belt A's retired node_http roadmap emit inherits the <script src> ref but does not serve the asset; it is dead (not deployed, only witnessed) and P5 deletes it — its witnesses assert page structure + server routes, not the client script, so green. Green by execution: roadmap_page, roadmap_serve, component, register walls, roadmap_dashboard_emit, typescript serializer, static_site, live_deploy emit, node_http, gunbhub, http_serve_route — all pass; emitted JS verified well-formed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med
briansrls
pushed a commit
that referenced
this pull request
Jul 23, 2026
…ternal (no inline JS string) Rebuilds dispatch_client_js as ONE modeled TsProgram (gunbc.roadmap_component. dispatch_client_program) over extdeps.languages.typescript.program — never a hand-concatenated JS string (the dispatch-button incident's root class, §5). The ok-predicate is a ts_binop `||` chain DERIVED from belt_dispatch_ok_status_labels, so the retired belt-A ok/node read cannot return. Per operator steer (inline <script> is a hack): the script is EMITTED as an external asset and referenced by <script src>, the moodboard reframe_watcher pattern — not inlined. Belt B (roadmap_serve) serves it at roadmap_dispatch_asset_path with a new text/javascript content type (extdeps.http.server.TextJavascriptUtf8). belt_dispatch_path_prefix moved to the wire-vocabulary home (belt_actuate) to break the page<->component cycle. WALL (P1): page_script_census walks the served page tree and refuses two shapes fail-closed — an inline <script> with hand JS text, and a <script src> to an unknown asset. Green over the real page; both REDs (resurrected inline string; rogue src) locate their violation. #7096's j.ok RED preserved, now against the served asset (witness_dispatch_asset_reads_belt_b_status_contract). Deleted: the string dispatch_client_js + its scaffold disposition row. Belt A's retired node_http roadmap emit inherits the <script src> ref but does not serve the asset; it is dead (not deployed, only witnessed) and P5 deletes it — its witnesses assert page structure + server routes, not the client script, so green. Green by execution: roadmap_page, roadmap_serve, component, register walls, roadmap_dashboard_emit, typescript serializer, static_site, live_deploy emit, node_http, gunbhub, http_serve_route — all pass; emitted JS verified well-formed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
* P0 UI-model: component concept + DispatchButton (states derived from wire authority) + token scales The component concept as a design-register sibling of the surface archetype: a component = element structure x role/material bindings x interaction STATES x wire-contract binding, held as one row (gunbc.design.component). Totality is cross-checked BOTH directions against the wire vocabulary — a wire label with no state row and a state fabricating a label the wire never sends each red. DispatchButton is the first instantiation (gunbc.roadmap_component), living one layer above the register because it binds the belt vocabulary: its terminal states are DERIVED from belt_dispatch_all_status_labels (a new authority grounded in belt_dispatch_status_label via one exemplar per variant), so the button's state set cannot drift from what belt B answers. Role split follows the ok-label authority: ok -> figure, refusal -> boundary; idle -> text, requested -> text-dim. Token axes added to gunbc.design.scale: spacing scale, type scale, font stack, plus the dimension companion so 'no raw px' can be total (consumed in P2). The :root block is the one home of length/font literals, excluded from the P2 census by scope exactly as the theme var block is excluded from the color census. Keystone green by execution (component_dispatch_button_keystone_holds): totality green, dropped-state RED locates the missing label, role split proven derived. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * P1 UI-model: dispatch client script is a modeled TsProgram, served external (no inline JS string) Rebuilds dispatch_client_js as ONE modeled TsProgram (gunbc.roadmap_component. dispatch_client_program) over extdeps.languages.typescript.program — never a hand-concatenated JS string (the dispatch-button incident's root class, §5). The ok-predicate is a ts_binop `||` chain DERIVED from belt_dispatch_ok_status_labels, so the retired belt-A ok/node read cannot return. Per operator steer (inline <script> is a hack): the script is EMITTED as an external asset and referenced by <script src>, the moodboard reframe_watcher pattern — not inlined. Belt B (roadmap_serve) serves it at roadmap_dispatch_asset_path with a new text/javascript content type (extdeps.http.server.TextJavascriptUtf8). belt_dispatch_path_prefix moved to the wire-vocabulary home (belt_actuate) to break the page<->component cycle. WALL (P1): page_script_census walks the served page tree and refuses two shapes fail-closed — an inline <script> with hand JS text, and a <script src> to an unknown asset. Green over the real page; both REDs (resurrected inline string; rogue src) locate their violation. #7096's j.ok RED preserved, now against the served asset (witness_dispatch_asset_reads_belt_b_status_contract). Deleted: the string dispatch_client_js + its scaffold disposition row. Belt A's retired node_http roadmap emit inherits the <script src> ref but does not serve the asset; it is dead (not deployed, only witnessed) and P5 deletes it — its witnesses assert page structure + server routes, not the client script, so green. Green by execution: roadmap_page, roadmap_serve, component, register walls, roadmap_dashboard_emit, typescript serializer, static_site, live_deploy emit, node_http, gunbhub, http_serve_route — all pass; emitted JS verified well-formed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * P2 UI-model: migrate roadmap_style length/font literals onto gunbc.design.scale tokens Every raw px / font-family literal in roadmap_instance_rules now routes through a gunbc.design.scale token var (spacing / type / font stack + the dimension companion), with scale_root_css() emitted in :root beside the theme vars. The scale :root block is the single home of the literals — the analog of the theme var block the unthemed-color census excludes by scope. WALL (P2): untokened_length_decls (gunbc.design.theme_transition, the length/font sibling of unthemed_color_decls) refuses any rule value carrying a raw px or a quoted font family. Green over roadmap_instance_rules(); RED control (witness_local_px_literal_refused) locates an injected 14px; witness_scale_block_ is_the_px_home proves the literal lives only in the token block. The existing walls (unthemed-color, brass-never-text, reduced-motion, archetype demand) stay green — the visual-regression net. Proven visually-neutral by execution: resolving every var(--scale-token) back to its value reproduces the pre-P2 CSS byte-for-byte. The lift-parity drift digest for roadmap_css is re-pinned accordingly (bde723955c44b23c), with the rationale recorded on the carrier. Residue named: gunbc.site.moodboard.figure_rules (imported into roadmap_rules) still carries raw border/radius px; its dimension-token lift is moodboard's own follow-on (sibling of the color lift), so the length census scopes to this module's authored rules. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * P3 UI-model: dispatch presentation — reserved width from the label authority, chip materials, located fields Reserved width is a PROJECTION of the wire vocabulary, not a hand pixel: .dispatch-btn min-width = the longest belt_dispatch_all_status_labels label (in ch) + a fixed gutter, so a text swap (dispatch -> dispatching... -> already_done_signed_off) never reflows the row — the layout jump dies as a class. Add a longer wire arm and the width grows by derivation (RED control proves it). Chip material per state: the client script flips a modifier class per terminal (dispatch-ok / dispatch-refused / dispatch-requested — one class authority shared by JS, CSS, and the P4 gallery), and each class paints the P0 state's role (ok -> figure, refusal -> boundary, requested -> text-dim). The witness cross- checks the shipped css rule against the state role EXACTLY, so a role drift reds. BoundaryRole added to the dashboard archetype's role demand (refusal chips use var(--boundary)); the archetype demand cross-check stays green. Located fields surface, not console-only: on a terminal the button sets its title to step+detail (spawn_failed) or reason/status, visible on hover — the retired console-only path is gone (console.log kept as a debug companion). Digest re-pinned for the intentional P3 styling (d429082785865b86). Residue named (AcceptedWithResidue within P3): separators stay the tokened per-child margins (which separate correctly post-P2), not a flex-container "by construction" refactor — that changes the node head's title-wrap behavior, an unverifiable visual change without a browser, so it is deferred rather than shipped blind (§5). The reserved width already kills the button reflow, the brief's flagged layout jump. Green by execution: dispatch_presentation, register (walls + archetype demand), page, lift parity. Emitted JS verified well-formed. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * P4 UI-model: /sandbox design surface — register depths + component gallery + live echo GET /sandbox renders the register at every depth (roles under both themes as paired swatches, scales) plus the dispatch button in EVERY state as a static gallery (which doubles as the visual witness), plus one live instance per wire arm. All derived from the same authorities the live surfaces use, so the sandbox cannot drift from production. Gallery totality is the wire vocabulary re-witnessed as coverage: one static instance per belt_dispatch_status_label variant; drop a state -> RED (located). POST /sandbox/echo?status=LABEL answers ANY wire arm on demand with the SAME belt_dispatch_result_json_value production sends, so every state is pressable without spawning a session. The live instances reuse the EXACT dispatch client program (dispatch_client_program_for — one behavior, two bindings; the sandbox only swaps the fetch URL), so they render identically to the real button. Echo is fail-closed: an unknown/missing status refuses 400 naming the valid set. New: extdeps.uri_path.uri_query_param (query parsing, the URI concern's home); belt_dispatch_result_for_label (label -> exemplar, grounded in the roster); three serve routes (GET /sandbox, GET /assets/sandbox.js, POST /sandbox/echo). Local execution receipt (gunbc serve, scratch port): GET / , /roadmap, /sandbox all 200 text/html; /assets/*.js 200 text/javascript; POST /sandbox/echo for all six arms returns the belt JSON (spawn_failed carries step+detail for the title); bogus -> 400. Green by execution: roadmap_sandbox, roadmap_serve (10 routes), plus all prior keystones (no regression). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * P5 UI-model: disposition — delete the dead belt-A roadmap node-http emit + dispatch exec route node_http_server_emit was the belt-A server, retired from deploy membership (belt B / gunbc serve replaced it — live_deploy is `gunbc serve`, not an emitted server.js). This PR proved belt B end-to-end by execution. So the dead belt-A ROADMAP emit is DELETED, not merely marked: every roadmap_dashboard_* emitter, the roadmap static route table, and the belt-A smuggled-exec dispatch route (BeltDispatchRouteConfig + the execFile-gunbc handler + the env-var channel — the exact shell-out belt B dissolves to an in-process call). The generic spec's dispatch field is gone with it. The module SURVIVES only for the gunbhub static-server emit (gunbhub_node_http_server_source, the sole live consumer via dag/tools/emit_host_transport.dag) — a static server with no dispatch. An explicit disposition note names that remaining consumer and its own dissolution trigger (gunbhub -> belt B, the named follow-on; gunbhub_serve is out of scope). No silent zombie: removed, not marked. Witnesses: deleted roadmap_dashboard_emit_witness_test (all belt-A roadmap emit; gunbhub coverage stays in node_http_server_emit_test); trimmed the belt-A node-server witnesses from roadmap_static_site (the "static site is served" property now lives on belt B, covered by roadmap_serve_witness) and live_deploy/emit_test. Green by execution: node_http_server_emit_test (gunbhub emit intact), gunbhub_serve, roadmap_static_site, live_deploy_emit; emit_host_transport gunbhub emit resolves; no dangling references to the deleted symbols. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * UI-model: task-sheet verdict row (ts-ui-model) + ROADMAP.md regen Adds the sheet row recording this PR's verdict fields — all five phases shipped, green by execution, with named within-phase residues (P3 flex-separator refactor deferred as unverifiable without a browser; P2 moodboard dimension-px is moodboard's own lift; P5 gunbhub node_http emit remains) — awaiting the review verdict (NeedsRework is a normal outcome; the review moves the row). Filed in the work-intake lane beside ts-dispatch-elevate. ROADMAP.md regenerated from the authority via main_wet (drift gate clean; only ROADMAP.md drifted — the other committed artifacts rewrote identically). Roadmap witnesses green (roadmap_gate, roadmap_authority, roadmap_page). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * D1-D4 UI-model dissolution: typed wire vocabulary, typed lengths, exemplar roster Pure re-grounding of the anemic seams the P0-P5 UI consumers exposed (operator + audit review 2026-07-23). Emitted bytes and wire strings are unchanged; each item carries its receipt. D1 MediaType (dag/extdeps/http/server.dag): the fused HttpContentType enum hid media-type x charset inside variant names and hand-composed the wire strings. Modeled as RFC 9110 8.3.1 says it — MediaType { top_level: closed RFC 6838 registry enum, subtype: String, parameters: List<MediaTypeParameter> } with charset a cited parameter row (IANA charset registry, utf-8 per RFC 3629). http_content_type_wire_label -> media_type_wire_label serializes over the structure; ApplicationOctetStream is an empty parameter list, not a special variant. The fused enum is deleted; the five presets are grounded MediaType rows; four consumers (roadmap_serve, roadmap_static_site, node_http_server_emit, gunbhub_serve) + five witnesses migrated. New media_type_witness pins all wire strings byte-exact with RED controls (perturbed parameter/subtype). D2 typed HTTP status (same file): belt_dispatch_status and serve_text_response re-grounded on HttpStatus (the typed carrier, RFC 9110 status registry); the bare Int now appears only at the ServeWireResponse wire seam. Per-variant codes (200/200/404/409/503/502) pinned unchanged. D3 CssLength (new dag/extdeps/languages/css/values.dag, cited CSS Values & Units + CSS Fonts 4): ScaleToken.value: String -> typed ScaleValue (CssLength magnitude x unit | CssFontStack list-of-families). The value-encoded token name is DERIVED from the magnitude by length_token (space-4 from px 4), so the name/value fork is unwritable by construction. dispatch_reserved_width's join-with-"ch" migrates to css_ch/CssLength. roadmap_css() emission is byte-identical (verified); lift-parity digest holds. D4 exemplar roster (roadmap_belt_actuate + gunbc.roster_registry): belt_dispatch_result_exemplars is a hand variant enumeration; enrolled as a DeclaredFrontier row (reason + dissolve_on). Reconciliation witness pins the exemplar-derived label set against the independent wire-contract pin, with a RED control (a missing-variant list reds). Verified by execution: media_type, extdeps_round2, http_serve_route, roadmap_serve, roadmap_static_site, gunbhub_serve, design_register_lift_parity, component, presentation, sandbox, register, roadmap_belt_actuate, roster_registry. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * D5 UI-model dissolution: typed CSS grain (property names + selector subjects) The last stringly medium in the served stack: CSS selectors and property names were raw strings inside otherwise-typed BuildRule/CssDecl rows. Landed the BOUNDED grain, byte-identical emission (the acceptance oracle). New authority extdeps/languages/css: - properties.dag: CssPropertyName enumerates EXACTLY the register's emitted properties (upstream spellings, cited W3C property index); CustomProperty for --author-defined vars (token/theme); RawProperty a COUNTED escape for a non-standard name (the single accent-study 'code-spacing'). - selectors.dag: SelectorSubject = ClassSelector | ElementSelector | PseudoSuffix | RawSelector (cited Selectors 4). RawSelector is the COUNTED frontier for descendant/compound/functional-pseudo selectors, carrying exact text so emission is byte-identical; raw_selector_count is the honest residue number. - values.dag (from D3) rounds out the grain. Re-grounded shared machinery: material.CssDecl.prop -> CssPropertyName, BuildRule StaticRule.selector / ResponseRule.subject -> SelectorSubject; decl, transition_decl, serialize_decls, response selectors, css_block callers, and the theme_transition census all serialize via css_property_wire / selector_subject_wire. Consumers migrated mechanically: theme (role_decl signature + custom-property + color-scheme), scale (custom-property), roadmap_style, roadmap_sandbox, roadmap_interaction, site/moodboard, site/accent_study, and the register/ presentation/site witnesses. Cursor imported explicitly where used (collides with review_verdict.Cursor); every other arm resolves globally. Residue (honest, counted): RawSelector in the production register + RawProperty for code-spacing — both dissolve when the combinator grammar / larger property set lands (named in the module notes). Acceptance: roadmap_css() byte-identical (sha unchanged); lift-parity digest + site/roadmap register witnesses green (site emissions byte-identical); whole-tree dag compile has zero hard errors and zero silent-picks from the grain. New css_grain_witness pins the serializers with RED controls + a RawSelector census. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * UI-model D1-D5: task-sheet dissolution receipt (ts-ui-model) + ROADMAP.md regen Record the anemia-dissolution follow-up (D1-D5) on the ts-ui-model sheet row: the pure re-groundings that landed (typed MediaType wire vocabulary, typed HttpStatus, typed CssLength/FontStack with the derive-name fork wall, exemplar roster enrollment, typed CSS property/selector grain), the counted residue (RawSelector 18, RawProperty 1, and the named arcs), and the local serve receipt. ROADMAP.md regenerated to the fixed point. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med * Regen stage0 seed for P4's uri_query_param (self-host fixed-point) P4 added uri_query_string / uri_query_param / uri_query_param_note to extdeps/uri_path.dag (the /sandbox/echo?status= query parsing) but did not regenerate the committed emitted Rust seed, so the RegenVerifyGate (self-host fixed-point) was red on the floor. regen_stage0 re-emits the whole stage0 seed; only extdeps_uri_path.rs changed (the other 98 files re-emit byte-identically). The new functions are pub (exported lib API, not dead_code under -D warnings). regen_stage0 --verify: regen_divergence_count=0 (committed stage0 matches fresh self-compile); crate rebuilds clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019SfKm4AxRS3e6nX2kA8med --------- Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ts-dispatch-elevaterow: gap 2 (live end-to-end receipt) closed by execution —POST /dispatch/2-dispatch-actuatoron srv1 spawned a real claude session in a worktree (independent read-back:tmux ls, worktree/branch, transcript file); second POST →already_live; bogus node →node_not_found. One refusal converged live: claude's per-path workspace-trust dialog blocked the first spawn (--dangerously-skip-permissionsdoes not cover it); ancestor-dir trust inheritance proven by execution, so the ONE root/opt/gunbc/dispatch-worktreesis now seeded in srv1's~/.claude.json(interim hand-provisioning, same class as the host_layout paths).deploy_dashboard_srv1— first green deploy post-Deploy-tail fix: tree-sync .git whitelist (perm + credential classes unwritable) + operator-TODO lanes 2a/5a/7 and PR-audit updates #7086 — and srv1 converged by independent read (/opt/gunbc/gunbcHEAD == main HEAD, binary refreshed,/healthzok).ts-dispatch-redispatch: re-dispatch after Stop is one-shot per node — (a) worktree+branch debris makes the next POST a typedspawn_failed, (b) after cleanup claude exits 1 withSession ID <uuid> is already in use(deterministic per-node UUID vs archived transcript). Dispatchable from the roadmap itself.main_wetondag/tools/generated_artifact_gate.dag(no hand edits).Test plan
roadmap_gate·generated_artifact_drift·roadmap_spawner·roadmap_frontier·roadmap_static_site·roadmap_belt(both fns) ·roadmap_authority·roadmap_pagetools.roadmap_dispatchemission: ready count 13 → 14,ts-dispatch-redispatchpresent inreadydispatch-worktreesempty, nodispatch/*branch, no dispatch tmux session)Made with Cursor