Skip to content

Lane C: native host-effect transport for emitted crates - #7099

Merged
briansrls merged 23 commits into
mainfrom
session/neat-carp-312
Jul 23, 2026
Merged

briansrls merged 23 commits into
mainfrom
session/neat-carp-312

Conversation

@briansrls

@briansrls briansrls commented Jul 23, 2026 •

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session neat-carp-312.
Pushing to session/neat-carp-312 advances this PR.

Summary

Lane C of the XL dispatch wave: adds two native (emitted-Rust) host-effect witness families — filesystem_read and shell_exec_run — to the emit-host execution path, each proven equal to the interpreter by execution on the same workspace, plus a construction-time confinement wall gating which families may ever build a real HostTransportDescriptor for an emitted binary.

What changed

  • filesystem_read and shell_exec_run native families (src/v2/extdeps/languages/rust_test.dag): each family's emitted Rust argv/handler is derived from the same extdeps op rows the interpreter reads (shell_materialize_argv_for_operation against dag/extdeps/shell/exec.dag for shell.Exec.Run — no hand-typed second dispatch).
  • Agreement witnesses (src/v2/test/claim/execution/emit_host_filesystem_read_equals_eval_test.dag, emit_host_shell_exec_run_equals_eval_test.dag): both legs (interpreted eval + native emitted binary) run against the same workspace and are proven byte-identical by execution.
  • Confinement wall (src/v2/lens/emitted_binary_effect_confinement.dag): a construction-time gate (WallNow{SingleAuthority}) at the .dag-level call site that builds a HostTransportDescriptor for an emitted binary. Only rostered families (filesystem_read_family, shell_exec_run_family) admit; anything else returns HostRuntimeRowAbsent (reuses the existing TargetEmitHostRuntimeRow refusal carrier, no new parallel refusal type). RED control (src/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag) proves a synthetic unrostered family name refuses via the real gated call site.
  • native_routing_frontier roster: added both new families as InterpretedRetained{reason: "no_cached_no_evict_carrier"} (conservative — not falsely marked NativeRouted); bumped native_routing_frontier_family_count_expected 9→11. No existing row's family/disposition touched.
  • Lens registry enrollment: v2.lens.emitted_binary_effect_confinement added as a new LensIdV0 (EmittedBinaryEffectConfinement) to v2.lens.registry and its exhaustive dispatch in v2.lens.enforcement.lens_module_gate, satisfying the corpus-wide lens_registry_completeness_holds_live gate.

Exit receipts (per parent mandate)

  • (a) both native witnesses green by execution, same workspace:
    • PASS emit_host_filesystem_read_equals_eval_all_holds (188ms)
    • PASS emit_host_shell_exec_run_equals_eval_all_holds (188ms)
  • (b) confinement roster + RED control green:
    • PASS emitted_family_effect_admitted_refuses_unrostered_family
    • PASS emitted_family_runtime_row_gated_refuses_unrostered_family (synthetic unrostered family → HostRuntimeRowAbsent via the real emitted_family_runtime_row_gated call site)
    • PASS emitted_family_runtime_row_gated_admits_rostered_filesystem_read_family
  • (c) derivation receipt: shell_exec_run_witness_argv() calls shell_materialize_argv_for_operation("dag/extdeps/shell/exec.dag", "shell.Exec", "Run", ...) — the emitted argv is read from the same .dag op row the interpreter's dispatch_shell reads, not a duplicated literal.

Test plan

  • claim_batch --hermetic --entry src/v2/lens/registry/completeness_test.dag --function lens_registry_completeness_holds_live → PASS
  • claim_batch --hermetic --entry src/v2/test/claim/self_host/native_routing_frontier_test.dag --function native_routing_frontier_witnesses → PASS
  • claim_batch --hermetic --entry src/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag --functions ... (3 witnesses) → all PASS
  • claim_batch --wet --entry .../emit_host_filesystem_read_equals_eval_test.dag --function emit_host_filesystem_read_equals_eval_all_holds → PASS
  • claim_batch --wet --entry .../emit_host_shell_exec_run_equals_eval_test.dag --function emit_host_shell_exec_run_equals_eval_all_holds → PASS
  • CI ci GitHub Action check: in progress on latest push (merged origin/main to pick up CI fail-fast: cheap-gate early batch (SIMPLE declared membership + dissolution trigger) + event-scoped stop policy #7088).

Re-verified at current head (319f445, 2026-07-23, fresh local claim_batch build)

  • PASS emit_host_filesystem_read_equals_eval_holds (173ms)
  • PASS emit_host_shell_exec_run_equals_eval_holds (127ms)
  • PASS emitted_family_runtime_row_gated_refuses_unrostered_family (RED control)
  • PASS emitted_family_runtime_row_gated_admits_rostered_filesystem_read_family
  • PASS native_routing_frontier_witnesses
  • PASS lens_registry_completeness_holds_live
  • Single-authority confirmed by inspection: both rust_test.dag's emitted-argv construction and the eval-side witness call shell_materialize_argv_for_operation against dag/extdeps/shell/exec.dag's shell.Exec.Run row — one derivation, not a hand-typed second dispatch.
  • Confinement ordering confirmed: the roster rows (filesystem_read_family, shell_exec_run_family) and the emitted_binary_effect_confinement wall land in this same PR, before either family's emitted binary can build a real HostTransportDescriptor — construction wall, not a follow-up.
  • lens_module_gate gated-file edit confirmed complete: EmittedBinaryEffectConfinement is enrolled in v2.lens.registry (+11 lines) and has an exhaustive dispatch arm in lens_module_gate.dag; lens_registry_completeness_holds_live passes.
  • GitHub ci check: in progress (self-hosted runner queue contention from the parallel XL-dispatch-wave lanes; multiple re-merges of an advancing main have restarted it several times — each restart's diff confirmed clean, only this PR's 9 files vs origin/main). build check (compile-clean) passes.

@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 23, 2026 12:35
@cursor

cursor Bot commented Jul 23, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Addressed review 41854 (DESIGN.md §3 layer inversion): moved emitted_effect_family_roster, list_contains_str, emitted_family_effect_admitted, and emitted_family_runtime_row_gated from v2.lens.emitted_binary_effect_confinement down to v2.std.host_transport (commit c7f8000), which already houses the sibling EmitHostRuntimeRow/TargetEmitHostRuntimeRow carriers these functions build on. The lens module now only carries the construction-justification doc row and its WallNow{SingleAuthority} metadata, whose DeclarationRef.module_path now points at v2.std.host_transport.

src/v2/extdeps/languages/rust_test.dag's two call sites (lines 4033/4133) needed no edit — they were already bare (zero-import) references, and the corpus's bare-reference resolution is name-uniqueness-based, so they now resolve to the std-tier definition automatically. emitted_binary_effect_confinement_red_control_test.dag's explicit import was updated to pull the two functions from v2.std.host_transport instead of the lens module.

Re-verified green by execution at the new head:

  • PASS emitted_family_effect_admitted_refuses_unrostered_family
  • PASS emitted_family_runtime_row_gated_refuses_unrostered_family (RED control)
  • PASS emitted_family_runtime_row_gated_admits_rostered_filesystem_read_family
  • PASS emit_host_filesystem_read_equals_eval_holds
  • PASS emit_host_shell_exec_run_equals_eval_holds
  • PASS native_routing_frontier_witnesses
  • PASS lens_registry_completeness_holds_live

Confirmed the fix: grep -rn "v2\.lens\." src/v2/extdeps dag/extdeps now returns zero matches, same as before the finding — extdeps no longer references the lens tier at all.

— sent from neat-carp-312

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Addressed review 41864 finding #1 (hand-rolled family: String sum instead of a real closed type).

Replaced emitted_effect_family_roster: List<String> + emitted_family_effect_admitted(family: String) -> Bool in v2.std.host_transport with a genuine closed sum:

type EmittedEffectFamily
  = FilesystemReadFamily
  | ShellExecRunFamily

emitted_family_runtime_row_gated now takes family: EmittedEffectFamily and dispatches via an exhaustive match over both variants — an unrostered family name is unrepresentable, not merely rejected by a runtime membership check, and a future third variant fails to compile at this call site until named (DESIGN.md §5 construction over validation). Call sites in rust_test.dag updated to the enum constructors. The RED-control test file (emitted_binary_effect_confinement_red_control_test.dag) was reworked accordingly: the two "refuses an unrostered family" tests are gone (there's no longer a value to construct that would exercise them — that's the point of the fix), and the two "admits a rostered family" tests now cover both FilesystemReadFamily and ShellExecRunFamily directly. The ConstructionJustification/LensContract DeclarationRef authority pointers in emitted_binary_effect_confinement.dag and enforcement/contract.dag were updated from the deleted emitted_effect_family_roster to the new EmittedEffectFamily type declaration, and the LensContract's bound consumer witness function was repointed to a still-existing test (emitted_binary_effect_confinement_authority_points_at_host_transport) since its prior target was one of the deleted tests. The commit-gate roster enrollment in dag/gunbc/commit_workflow.dag was updated to match the renamed/removed test functions.

Verified green-by-execution (claim_batch --wet) on the current head:

  • emitted_family_runtime_row_gated_admits_rostered_filesystem_read_family
  • emitted_family_runtime_row_gated_admits_rostered_shell_exec_run_family
  • emitted_binary_effect_confinement_authority_points_at_host_transport
  • emit_host_filesystem_read_equals_eval_all_holds (real host-effect execution equivalence, unaffected by the type change — proves the call sites still resolve/compile)
  • emit_host_shell_exec_run_equals_eval_all_holds (same)
  • enforcement_consistency_gate_holds (the LensContract liveness check, confirming the repointed authority + consumer witness are internally consistent)

This also means review 41873's approval (which praised the now-superseded roster/predicate design) is stale against the current head — a fresh review will need to run against this commit.

— sent from neat-carp-312

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Addressed review 41880 (coverage-by-illusion on the two new parity witnesses).

Valid finding. emit_host_filesystem_read_equals_eval_all_holds and emit_host_shell_exec_run_equals_eval_all_holds were added under test/claim/execution/ (excluded from discovery by the dir-grain WitnessExclusionRow in ci_layer_roots.dag) and enrolled in native_routing_frontier_roster, but native_routing_frontier only proves the routing frontier's disposition/count facts — it does not run the parity witness itself. The only thing actually enrolled to run them was wet_receipt_enrollment_witness_test.dag's own self-consistency check, not the nightly falsifier. So the two witnesses that prove Lane C's core deliverable (emit->build->run parity for the new families) had no executing CI consumer — exactly the DESIGN §5/§6 gap called out.

Fixed by adding both to falsifier_native_cache_cold_entries in src/v2/compiler/self_host/wet_receipt_enrollment.dag, alongside the existing 9 standalone emit_host_<family>_equals_eval_test.dag witnesses (same shape: no compile_skipped assertion, so COLD-VALID under the nightly GUNBC_CI_NATIVE_CACHE_COLD_CONTROL falsifier). Updated the stale "9 standalone" count in falsifier_native_cache_cold_roster_note to 11 and appended a dated note explaining the extension.

Verified green-by-execution on the current head:

  • wet_receipt_enrollment_witnesses (the roster's own self-consistency witness)
  • ci_floor_plan_witnesses (the CI plan that consumes falsifier_native_cache_cold_roster())
  • emit_host_filesystem_read_equals_eval_all_holds / emit_host_shell_exec_run_equals_eval_all_holds still pass directly (unaffected by the enrollment change, confirming the roster addition is additive, not a rewrite of the witnesses themselves)

— sent from neat-carp-312

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Investigated the CI failure on head 3c5ed5d. Not a code defect — infra-level timeout under shared-runner memory contention:

The gunbc ci floor job entered its adaptive discovery corpus (batch 4: 2228 witnesses across 670 entries) at 14:22:14Z. Within a minute the memory governor hit memory.current over its declared high-water mark and dropped target_width from 2 to 1 ([governor] creep back-off / hard back-off), and stayed pinned at width 1 for the rest of the run — effectively serializing the whole corpus. It never OOM-killed (oom_kill +0 throughout), it just ran too slowly at width 1 to finish inside the 55-minute job timeout (##[error]The action 'gunbc ci (.dag witnesses + gates)' has timed out after 55 minutes).

Checking concurrent runner load at that time: 4 other ci/affected-set-falsifier workflow runs were in_progress on this shared infra during the same window (gentle-raven-495, keen-ibex-888, a claude/ci-compilation-caching branch, and main's affected-set-falsifier), consistent with cross-job memory pressure driving the governor's width throttle. My diff's own footprint here is negligible (3 new witness functions, ~30 lines, plus 2 roster-enrollment lines) — nowhere near enough to explain a 2228-witness corpus dropping to serial width. This matches a known pattern in this repo (adaptive-width floor going Amdahl-negative under memory pressure: serial ~12min vs contended 47min+).

No code change is warranted for a transient resource-contention timeout — retrying is the correct remedy here (DESIGN §5: don't fabricate a fix for a class of failure this isn't). Reran the failed job (gh run rerun 30014081173 --failed); a fresh ci run is now queued on this same head.

— sent from neat-carp-312

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Second consecutive CI timeout on this head, identical signature to the first: memory governor pinned at target_width 1→1 (hard back-off, oom_kill +0 throughout — never an actual OOM), 55-minute job timeout. Confirmed still not a code defect — reran and it failed the exact same way (job 89245733076, completed 16:00:25Z).

Runner contention has gotten worse, not better: 7 other ci/affected-set-falsifier workflow runs are in_progress right now across main and several session branches, vs. 4 concurrent runs during the first failure. This is consistent with the shared floor infra being saturated at the moment, independent of this PR's diff.

Reran once more (job 89261323658, queued 16:02:28Z on the same head). If this third attempt also times out with the identical governor-throttle signature, that's a signal worth the operator's attention as a standing infra issue (the floor's adaptive-width governor going Amdahl-negative under contention — matches the known "Floor width is Amdahl-NEGATIVE" pattern), rather than something further reruns from this session can fix.

— sent from neat-carp-312

@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

CI failure on head 0db06e6 is NOT a Lane C regression: batch-1 generated_artifact_drift_gate_passes fails because the committed .github/workflows/ci.yml still lists .github/fleet-converge.sh in its heal-step git add, a path deleted by #7121 (ac89afbe6) without a corresponding ci.yml regen landing on main. Confirmed this is breaking main's own CI too (heal_generated_artifacts job exit-128s with fatal: pathspec '.github/fleet-converge.sh' did not match any files on recent main pushes) — a pre-existing main-red, not something introduced by this branch's merge.

PR #7126 ("CI: regen upstream of ci (build→regen→ci→deploy) + heal auto-fixes drift on PRs") already fixes this exact incident (its description explicitly names the #7121 fleet-converge case) and is currently running (regen/heal in progress). Rather than duplicate that fix here, this PR will rerun/rebase once #7126 merges to main.

— sent from neat-carp-312

@briansrls
briansrls merged commit d4c957a into main Jul 23, 2026
2 of 3 checks passed
@briansrls
briansrls deleted the session/neat-carp-312 branch July 23, 2026 18:18
briansrls added a commit that referenced this pull request Jul 24, 2026
… apart, two operator rulings recorded (#7132)

* Roadmap 2b: interpreter-deletion endgame lane — the three deletions named apart, two operator rulings recorded (zero hand-maintained Rust; effects as emitted per-language providers)

New section group 2b (Track B past strong self-host), reconciled against the
verified state on main rather than memory:

- ts-interp-endgame: the delete-v1 conflation split into its three finish
  lines — compiler (§1 gates, undisturbed), interpreter (2a bulk arc + this
  lane), host-physics (pinned v2-EMITTED kernel per seed census).
- ts-zero-hand: operator ruling 2026-07-23 — hand-MAINTAINED Rust goes to
  exactly zero; the pinned kernel is emitted from cited models; the hand
  roster (25 files + module_path_index, growing) becomes a counted burn-down
  frontier with a new-additions-need-dissolution-triggers review bar; names
  the two doc contradictions to fix (interpreter-kernel-d collapse-vs-pin
  either-or resolves to collapse-then-emit; witness-realization P4's
  claim_executor not-an-emit-target corrected to not-YET per census).
- ts-effects-providers: operator ruling — effects are per-language library
  models (effect providers) emitted like everything else; TargetModel
  runtime_row class carries the interface; 2 of ~9 host-effect families
  landed (#7099), rest are rows not architecture.
- ts-store-econ: the durable BUDGETED artifact-store tier + floor
  consultation is the single gate on the 2a flip (every family retained on
  no_cached_no_evict_carrier); resolved_graph_cache and #7129 eviction
  dissolve INTO it per kernel-D.
- ts-material-ci: materialization kernel in CI (the fold both substrates
  consume); unkeyed-collapse watch-flag (0.6 percent vs historic 47).
- ts-interp-delete: the terminal conditions, with the 2a re-pricing (loud
  in-PR agreement, no drip-feed windows) and cli_run hollowing explicitly
  OFF the interpreter critical path.

Also: ts-native-flip-revert row updated with the landed divergence carrier
receipt (v2.std.native_agreement) — re-flip now gated only on the store.

ROADMAP.md regenerated via main_wet (only ROADMAP.md + authority changed;
all other artifacts byte-identical). roadmap_authority witnesses green
(frame/reset/subgroup/emit-refs).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Roadmap 2b rework per review: bind to v1_deletion_plan authority, real dependency edges, corrections + new 2c lens-enforcement group

Every review claim was verified against the tree before accepting; all
load-bearing ones held. Changes:

- 2b is now explicitly a PROJECTION of gunbc.v1_deletion_plan (which
  exists and declares itself the plan authority — the prior block was a
  partial fork); new ts-authority-converge row extends the carrier with
  the execution-track bricks (observation contract, divergence root
  cause, materialization-provider interface, evaluator completeness,
  executor seams, quarantine rehearsal) instead of restating them here.
- Edges now encode the actual dependency graph (RoadmapEdge is
  dependency-gating per roadmap_spawner node_dep_done, not containment):
  store-econ -> material-ci and the 2a flip; observation-contract ->
  flip; evaluator/effects/material/seams -> quarantine -> delete;
  zero-hand after delete as its own terminal milestone.
- ts-native-flip-revert corrected: re-flip is NOT gated only on the
  store — the frontier dissolve_on requires the divergence root-caused
  with member + both values named plus a fresh warm per-host receipt
  (the loudness carrier names failures, it does not resolve them).
- ts-effects-providers: the three conflated populations named apart
  (2 EmittedEffectFamily variants / 9 witness families / ~35 host-fed
  entries); work item is a typed operation-keyed census; boundary
  enforcement (host_run_boundary_admission pending) called out so the
  agency problem does not move into generated providers.
- ts-store-econ: provider-interface-first ordering; artifact store,
  resolved_graph_cache, and #7129 schedule-retention become SIBLING
  provider rows under the materialization kernel, never one merged store.
- ts-material-ci: eval/realize/materialize kept distinct (materialize is
  analysis-side per its own note; realize_pack advisory); the 0.6 percent
  unkeyed receipt bounded properly (run 30027001708 partial-run vs
  committed whole-run ~47.6 — different denominators, record not reprice).
- New rows: ts-observation-contract, ts-evaluator-complete (reject arms +
  missing CPU-deadline/call-depth guards), ts-executor-seams (critical
  slice vs full hollowing), ts-quarantine (deletion dress rehearsal).
- New group 2c (operator request): lens enforcement live in CI —
  per-lens disposition + receipt (zero inert lenses, not 55-blocking;
  complexity is AuditOnly/NoConsumerWitness today), fn-body visibility
  as the real dependency (42 contracts pending reflection; space
  complexity re-homes off src/v1 before terminal deletion), coverage
  re-enrollment priced through the D5 budget wall.

ROADMAP.md regenerated via main_wet (only ROADMAP.md + authority
changed); roadmap_authority witnesses green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Roadmap 2b/2c: absorb the #7135 adversarial pass — synthesis of both review sets, with two claims adjudicated against the tree

Integrates every verified correction from the adversarial pass (stacked
as #7135 on the pre-rework commit, now absorbed here):

- 9-of-11 precision on the frontier retention reasons (complement +
  meet_join at agreement_red_on_main; the store gates the other nine
  families' FIRST flip, not the reverted pair's re-flip).
- Cache-root truth: ci.yml pins GUNBC_NATIVE_CACHE_ROOT to the runner
  tool-cache (durable, R2-keyed); what's missing is budget/eviction
  authority + the executor-grain consult, not 'no store at all'.
- Gate-1 gloss corrected to the carrier definition (GateEmitterFixedPoint
  = the emitter re-emits itself) + prereq_drift_ruling_2026_07_23 cited.
- interpreter_surviving_roles named as the roles carrier; the un-rostered
  wet-workflow surfaces (serve/belt, main_wet, gunbc ci, pre-push, probe
  bins) become an enrollment obligation AND a delete condition.
- Third carrier contradiction recorded (^hand_queue_drain: 7-files prose
  vs live 25-file roster; pins-not-drain-targets vs the collapse ruling).
- 2a census staleness: 876 entries not 744, first_error_class still
  CensusPending; totality denominator must be derived (group 5a).
- ts-store-econ SIZED (IntricacyHigh/VolumeMedium) with Accept + RED,
  provider shape as ONE CacheLookupResult contract with N sibling
  provider rows (store tier, resolved_graph_cache, recorded_fixture,
  #7129 schedule-retention, W3).
- 2c upgraded to the five-row v2-door lane (M-L1 door / M-L2 treewide
  store-priced / M-L3 contract truth / M-L4 complexity scope), keeping
  this branch's disposition taxonomy and the space-complexity re-home
  rider; cross-edge ts-lens-treewide -> ts-store-econ.

Two adjudications where the reviews conflicted, settled by direct read:
(1) Filesystem Delete/List EXIST (filesystem_io.dag operation Delete;
artifact_fs_delete/artifact_fs_list in the fs transport) — review 1 was
right; the artifact_store_fs transport NOTE is the stale artifact, and
ts-store-econ now says wiring-counted-eviction, not modeling. (2) the
zero-hand edge direction: full zero-hand stays AFTER the delete (its own
terminal milestone); the narrower ^hand_queue_drain brick precedes
QUARANTINE per the carrier's prereq ruling — both encoded, neither
review's blanket edge taken.

ROADMAP.md regenerated via main_wet; roadmap_authority witnesses green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Roadmap 2b/2c: apply the 9bfe09c re-review — safe ordering edges, converge-gated execution track, hardened store REDs, link-grain quarantine, 2c totality wall + terminal

- Edges: flip now child of census + seams + flip-revert (root-cause
  precedes the bulk flip); quarantine child of flip; evaluator-complete /
  executor-seams / effects-providers child of authority-converge (option
  b: the projection claim true by construction until the carrier gains
  its bricks).
- Hand-drain contradiction resolved: the kernel-D/hand_queue_drain
  carrier FIXES are ts-authority-converge's deliverable; material-ci
  re-pointed; terminal zero-hand burn-down stays after the delete.
- Census literals de-literalized: histogram carrier is the denominator
  authority (876->880 in one day proved the point); snapshots dated.
- ts-store-econ RED battery hardened: verdict-equality primary +
  byte-purity on the keyed artifact (sound per C.2 #6576 seed emitter
  map_keys-free by construction), same-key corruption refuses on read
  (content_verified_on_read flips true), concurrent puts atomic; the row
  named as the ForciblySerial bottleneck (2a flip + lens M-L2 + kernel
  converge on it).
- Quarantine at LINK grain: v1_interpreter omitted from the built
  artifact (cfg/feature or crate split) — source-inaccessible proves
  nothing about a linked module.
- 2c: anchor precision (no lens on the compile DOOR; witnesses run
  elsewhere); M-L1 scoped to all THREE seed-path compile sites (PR gate,
  falsifier cold control, regen); M-L2 names W3 typed-module tier as the
  specific provider; M-L3 counts verified (55 ids / 47 contracts / 44
  AuditOnly / 9 uncovered incl. the LIVE Determinism gate) + the
  registry-contract totality wall first; ts-lens-terminal added as the
  fan-in node with edges from treewide + contract-truth +
  complexity-scope.

Verification pushbacks recorded: authored_wi sizes with
acceptance: ManualAcceptance (not empty — the belt cannot dispatch
bar-less); the seed emitter HAS a determinism guarantee by construction
(C.2 #6576), so the byte-purity oracle stands on the keyed artifact.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Roadmap 2b/2c: apply the green-verification review — five fixes, none structural

1. Flip-revert row twice-corrected: the pair's re-flip gate is EXACTLY
   the frontier's own dissolve_on (root-cause + fresh warm receipt, NO
   store clause — the pair rides the cached leg); my earlier correction
   over-gated in the opposite direction from the original under-gate.
   One authority: the carrier's strings, never a roadmap paraphrase.
2. ts-effects-providers: the stale ~35 host-fed literal replaced with
   the classified truth (6 so far, 700 pending, eventual count unknown;
   histogram carrier is the authority).
3. M-L3 counts reconciled: 46 contracts (44 AuditOnly + 2 Blocking),
   consistent with 55 − 9; the 47 was a grep over-count.
4. Wet-surfaces roles-roster enrollment now OWNED: added to
   ts-authority-converge's brick list (it was delete-blocking with no
   owner).
5. Dispatchability: ts-authority-converge sized (IntricacyMedium/
   VolumeMedium — it is the sprint's entry point and concrete carrier
   work); the 2c anchor-grouping edges removed so ts-lens-door is not
   gated behind an umbrella that never completes (edges are for real
   deps only — the 2b block already followed this rule).

Trivia: evaluator module path corrected to v2.extdeps.runtimes.*;
cli_run line-count de-literalized (~28k and growing); 2b label reframed
'decoupled from strong self-host' to match the content.

Regen byte-idempotent; roadmap_authority witnesses green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Roadmap 2d + plan doc: progress & observation — process→outcome discipline, one event model, N renderers

docs/plans/progress-observation-design.md: the five operator-signed laws
(process→outcome no orphans; heartbeat carries identity; recursive dwell
escalation; quiet at arm's length; every response true), the P0 event
model (Refused distinct from Failed; BlockedOn DERIVED from governor
facts; one glyph/material authority incl. the reward-animal rows), and
per-context FORMAT CONTRACTS: CI log (append-only, heartbeat+escalation
first-class — the reference implementation's gap), interactive TTY,
receipt/JSONL (replayable; existing receipts become derived views),
dashboard (schema-only), pipe. Reference implementation gunb-ai/gunb.ai
tools/terminal studied BY EXECUTION (tests green; driven live in
TTY/CI/failure modes): lift contention/nesting/boxes/reward; fix CI
silence, Failed/Refused conflation, hand-mirrored emoji duals.

Roadmap 2d: ts-obs-anchor + sized ts-obs-model (P0) + sized
ts-obs-ci-renderer (P1, flagship = re-render the captured crawl window
of run 30044816605) + ts-obs-tty (P2) + ts-obs-census-wall (P3), edges
encoding P0→P1/P2→P3. Doc-graph bind added; reachability witnesses 4/4
and roadmap witnesses green; ROADMAP.md regenerated via main_wet.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Plan: CI two-tier placement redesign — the 5-second rule

Records the 2026-07-24 operator decisions: placement by measured warm cost
(≤5s rides the PR path, wet admissible if fast + hermetic-classified),
DELETE the per-PR selection-control audit step (falsifier cadence is the
surviving control), Rust seed stays tested-by-execution in CI. Dependency
order D0–D5 with the post-merge #7129 P1s folded into D0 and the
run_claims_in_process activation blockers into D1. Doc bound to
gunbc.ci_spec.gunbc_ci_spec; dissolves when D3's placement axis lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Plan: single-PR delivery structure + expectation sheet + sign-off checklist

Operator directive 2026-07-24: no staged drag-out — pre-PR probe does all
measurement, one redesign PR lands D1+D3+D4+D5 atomically (single revert),
D0 close-out routed to the #7129 worker and sequenced first (shared
cli_run.rs). Before/after sheet with falsification bounds per row; §9
decision checklist for reviewer sign-off.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Plan: issue-closure checklist worked through by execution; three corrections

Verification pass before operator review (2026-07-24): (1) D1 already
LANDED on main — #7122 + #7128 pooled the 26 cold children to 6, verified
by counting readiness probes in run 30052571652's ci log; plan re-framed,
in-process activation split off as deferred D1b with its fail-open
confirmed by direct read of cli_run.rs:9580. (2) D4 audit deletion now
BLOCKED on falsifier health — the cadence is red 5/5 by crawl-timeout
(run 30044928186: cgroup 16.1G pinned, swap saturated, 170m cap), so the
per-PR audit is currently the only working selection control. (3) The 5s
threshold reuses the existing fast-lane law carrier (thread-CPU budget,
typed refusal) — no second authority. §10 checklist: 14 rows, each with
status + how verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Plan + roadmap: apply the #7132 review round — fourth carrier contradiction, staleness, D5 brief in-tree

All five findings verified against the tree before applying: (1) parity_window
required_consecutive_green_windows=3 + frontier dissolve_on strings contradict
the 2a re-pricing (no first flip writable with the falsifier red) — joins
ts-authority-converge's stale-prose deliverables as the FOURTH contradiction;
(2) ts-store-econ's '#7129 in flight' corrected to merged + PR-0 close-out;
(3) rust-suite disposition miscite fixed at its authorities (design_document,
ci_spec — DESIGN.md reprojects; actual decl commit_gate_rust_suite_removed_disposition);
(4) roster rows corrected to post-pooling reality (6 = 1 union + 4 ingest-overlay
by construction per ingest_pool_separation_note + 1 reads-class; batch-6 414s not
12.15m); zero-hand tag repointed at ts-seed-interim; (5) D4 leaves PR-1 — fast-follow
micro-PR gated on first green cadence (§9.7). Implementer round folded in: D1b
scope refinement (plain resolve_entry_graph — spawns removed, per-entry resolves
not), 5s threshold-vs-mechanism caveat (§9.1), and §11 lands the DiffBaseline
brief in-tree (previously chat-only). ROADMAP.md regenerated via main_wet.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

* Split hub-file token fixes out of this PR; record the batch-3 budget finding

Run 30063529282 refused batch 3 at 24m59s vs the 22m budget: the one-token
miscite fixes in ci_spec.dag + design_document.dag are hub files, so
selection legitimately ran the full corpus (2,315 witnesses, ALL PASS,
RSS healthy) — the honest full-corpus wall exceeds the budget. Attribution
clean: same branch without the hub files was green (0d54cdc). Fixes
reverted here to ride PR-1 (which pays full corpus anyway); DESIGN.md
re-projected from its reverted authority. Systemic implication recorded:
PR-1 necessarily touches CiSpec and will face the same wall — §9.8 decision
(receipt-noted raise sized by the D2 probe) + checklist row 15. The budget
wall itself worked as designed; no widen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant