Repository navigation
Lane C: native host-effect transport for emitted crates - #7099
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
Addressed review 41854 (DESIGN.md §3 layer inversion): moved
Re-verified green by execution at the new head:
Confirmed the fix: — sent from neat-carp-312 |
|
Addressed review 41864 finding #1 (hand-rolled Replaced
Verified green-by-execution (
This also means review 41873's approval (which praised the now-superseded roster/predicate design) is stale against the current head — a fresh review will need to run against this commit. — sent from neat-carp-312 |
|
Addressed review 41880 (coverage-by-illusion on the two new parity witnesses). Valid finding. Fixed by adding both to Verified green-by-execution on the current head:
— sent from neat-carp-312 |
|
Investigated the CI failure on head The Checking concurrent runner load at that time: 4 other No code change is warranted for a transient resource-contention timeout — retrying is the correct remedy here (DESIGN §5: don't fabricate a fix for a class of failure this isn't). Reran the failed job ( — sent from neat-carp-312 |
|
Second consecutive CI timeout on this head, identical signature to the first: memory governor pinned at Runner contention has gotten worse, not better: 7 other Reran once more (job — sent from neat-carp-312 |
|
CI failure on head 0db06e6 is NOT a Lane C regression: batch-1 PR #7126 ("CI: regen upstream of ci (build→regen→ci→deploy) + heal auto-fixes drift on PRs") already fixes this exact incident (its description explicitly names the #7121 fleet-converge case) and is currently running (regen/heal in progress). Rather than duplicate that fix here, this PR will rerun/rebase once #7126 merges to main. — sent from neat-carp-312 |
… apart, two operator rulings recorded (#7132) * Roadmap 2b: interpreter-deletion endgame lane — the three deletions named apart, two operator rulings recorded (zero hand-maintained Rust; effects as emitted per-language providers) New section group 2b (Track B past strong self-host), reconciled against the verified state on main rather than memory: - ts-interp-endgame: the delete-v1 conflation split into its three finish lines — compiler (§1 gates, undisturbed), interpreter (2a bulk arc + this lane), host-physics (pinned v2-EMITTED kernel per seed census). - ts-zero-hand: operator ruling 2026-07-23 — hand-MAINTAINED Rust goes to exactly zero; the pinned kernel is emitted from cited models; the hand roster (25 files + module_path_index, growing) becomes a counted burn-down frontier with a new-additions-need-dissolution-triggers review bar; names the two doc contradictions to fix (interpreter-kernel-d collapse-vs-pin either-or resolves to collapse-then-emit; witness-realization P4's claim_executor not-an-emit-target corrected to not-YET per census). - ts-effects-providers: operator ruling — effects are per-language library models (effect providers) emitted like everything else; TargetModel runtime_row class carries the interface; 2 of ~9 host-effect families landed (#7099), rest are rows not architecture. - ts-store-econ: the durable BUDGETED artifact-store tier + floor consultation is the single gate on the 2a flip (every family retained on no_cached_no_evict_carrier); resolved_graph_cache and #7129 eviction dissolve INTO it per kernel-D. - ts-material-ci: materialization kernel in CI (the fold both substrates consume); unkeyed-collapse watch-flag (0.6 percent vs historic 47). - ts-interp-delete: the terminal conditions, with the 2a re-pricing (loud in-PR agreement, no drip-feed windows) and cli_run hollowing explicitly OFF the interpreter critical path. Also: ts-native-flip-revert row updated with the landed divergence carrier receipt (v2.std.native_agreement) — re-flip now gated only on the store. ROADMAP.md regenerated via main_wet (only ROADMAP.md + authority changed; all other artifacts byte-identical). roadmap_authority witnesses green (frame/reset/subgroup/emit-refs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Roadmap 2b rework per review: bind to v1_deletion_plan authority, real dependency edges, corrections + new 2c lens-enforcement group Every review claim was verified against the tree before accepting; all load-bearing ones held. Changes: - 2b is now explicitly a PROJECTION of gunbc.v1_deletion_plan (which exists and declares itself the plan authority — the prior block was a partial fork); new ts-authority-converge row extends the carrier with the execution-track bricks (observation contract, divergence root cause, materialization-provider interface, evaluator completeness, executor seams, quarantine rehearsal) instead of restating them here. - Edges now encode the actual dependency graph (RoadmapEdge is dependency-gating per roadmap_spawner node_dep_done, not containment): store-econ -> material-ci and the 2a flip; observation-contract -> flip; evaluator/effects/material/seams -> quarantine -> delete; zero-hand after delete as its own terminal milestone. - ts-native-flip-revert corrected: re-flip is NOT gated only on the store — the frontier dissolve_on requires the divergence root-caused with member + both values named plus a fresh warm per-host receipt (the loudness carrier names failures, it does not resolve them). - ts-effects-providers: the three conflated populations named apart (2 EmittedEffectFamily variants / 9 witness families / ~35 host-fed entries); work item is a typed operation-keyed census; boundary enforcement (host_run_boundary_admission pending) called out so the agency problem does not move into generated providers. - ts-store-econ: provider-interface-first ordering; artifact store, resolved_graph_cache, and #7129 schedule-retention become SIBLING provider rows under the materialization kernel, never one merged store. - ts-material-ci: eval/realize/materialize kept distinct (materialize is analysis-side per its own note; realize_pack advisory); the 0.6 percent unkeyed receipt bounded properly (run 30027001708 partial-run vs committed whole-run ~47.6 — different denominators, record not reprice). - New rows: ts-observation-contract, ts-evaluator-complete (reject arms + missing CPU-deadline/call-depth guards), ts-executor-seams (critical slice vs full hollowing), ts-quarantine (deletion dress rehearsal). - New group 2c (operator request): lens enforcement live in CI — per-lens disposition + receipt (zero inert lenses, not 55-blocking; complexity is AuditOnly/NoConsumerWitness today), fn-body visibility as the real dependency (42 contracts pending reflection; space complexity re-homes off src/v1 before terminal deletion), coverage re-enrollment priced through the D5 budget wall. ROADMAP.md regenerated via main_wet (only ROADMAP.md + authority changed); roadmap_authority witnesses green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Roadmap 2b/2c: absorb the #7135 adversarial pass — synthesis of both review sets, with two claims adjudicated against the tree Integrates every verified correction from the adversarial pass (stacked as #7135 on the pre-rework commit, now absorbed here): - 9-of-11 precision on the frontier retention reasons (complement + meet_join at agreement_red_on_main; the store gates the other nine families' FIRST flip, not the reverted pair's re-flip). - Cache-root truth: ci.yml pins GUNBC_NATIVE_CACHE_ROOT to the runner tool-cache (durable, R2-keyed); what's missing is budget/eviction authority + the executor-grain consult, not 'no store at all'. - Gate-1 gloss corrected to the carrier definition (GateEmitterFixedPoint = the emitter re-emits itself) + prereq_drift_ruling_2026_07_23 cited. - interpreter_surviving_roles named as the roles carrier; the un-rostered wet-workflow surfaces (serve/belt, main_wet, gunbc ci, pre-push, probe bins) become an enrollment obligation AND a delete condition. - Third carrier contradiction recorded (^hand_queue_drain: 7-files prose vs live 25-file roster; pins-not-drain-targets vs the collapse ruling). - 2a census staleness: 876 entries not 744, first_error_class still CensusPending; totality denominator must be derived (group 5a). - ts-store-econ SIZED (IntricacyHigh/VolumeMedium) with Accept + RED, provider shape as ONE CacheLookupResult contract with N sibling provider rows (store tier, resolved_graph_cache, recorded_fixture, #7129 schedule-retention, W3). - 2c upgraded to the five-row v2-door lane (M-L1 door / M-L2 treewide store-priced / M-L3 contract truth / M-L4 complexity scope), keeping this branch's disposition taxonomy and the space-complexity re-home rider; cross-edge ts-lens-treewide -> ts-store-econ. Two adjudications where the reviews conflicted, settled by direct read: (1) Filesystem Delete/List EXIST (filesystem_io.dag operation Delete; artifact_fs_delete/artifact_fs_list in the fs transport) — review 1 was right; the artifact_store_fs transport NOTE is the stale artifact, and ts-store-econ now says wiring-counted-eviction, not modeling. (2) the zero-hand edge direction: full zero-hand stays AFTER the delete (its own terminal milestone); the narrower ^hand_queue_drain brick precedes QUARANTINE per the carrier's prereq ruling — both encoded, neither review's blanket edge taken. ROADMAP.md regenerated via main_wet; roadmap_authority witnesses green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Roadmap 2b/2c: apply the 9bfe09c re-review — safe ordering edges, converge-gated execution track, hardened store REDs, link-grain quarantine, 2c totality wall + terminal - Edges: flip now child of census + seams + flip-revert (root-cause precedes the bulk flip); quarantine child of flip; evaluator-complete / executor-seams / effects-providers child of authority-converge (option b: the projection claim true by construction until the carrier gains its bricks). - Hand-drain contradiction resolved: the kernel-D/hand_queue_drain carrier FIXES are ts-authority-converge's deliverable; material-ci re-pointed; terminal zero-hand burn-down stays after the delete. - Census literals de-literalized: histogram carrier is the denominator authority (876->880 in one day proved the point); snapshots dated. - ts-store-econ RED battery hardened: verdict-equality primary + byte-purity on the keyed artifact (sound per C.2 #6576 seed emitter map_keys-free by construction), same-key corruption refuses on read (content_verified_on_read flips true), concurrent puts atomic; the row named as the ForciblySerial bottleneck (2a flip + lens M-L2 + kernel converge on it). - Quarantine at LINK grain: v1_interpreter omitted from the built artifact (cfg/feature or crate split) — source-inaccessible proves nothing about a linked module. - 2c: anchor precision (no lens on the compile DOOR; witnesses run elsewhere); M-L1 scoped to all THREE seed-path compile sites (PR gate, falsifier cold control, regen); M-L2 names W3 typed-module tier as the specific provider; M-L3 counts verified (55 ids / 47 contracts / 44 AuditOnly / 9 uncovered incl. the LIVE Determinism gate) + the registry-contract totality wall first; ts-lens-terminal added as the fan-in node with edges from treewide + contract-truth + complexity-scope. Verification pushbacks recorded: authored_wi sizes with acceptance: ManualAcceptance (not empty — the belt cannot dispatch bar-less); the seed emitter HAS a determinism guarantee by construction (C.2 #6576), so the byte-purity oracle stands on the keyed artifact. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Roadmap 2b/2c: apply the green-verification review — five fixes, none structural 1. Flip-revert row twice-corrected: the pair's re-flip gate is EXACTLY the frontier's own dissolve_on (root-cause + fresh warm receipt, NO store clause — the pair rides the cached leg); my earlier correction over-gated in the opposite direction from the original under-gate. One authority: the carrier's strings, never a roadmap paraphrase. 2. ts-effects-providers: the stale ~35 host-fed literal replaced with the classified truth (6 so far, 700 pending, eventual count unknown; histogram carrier is the authority). 3. M-L3 counts reconciled: 46 contracts (44 AuditOnly + 2 Blocking), consistent with 55 − 9; the 47 was a grep over-count. 4. Wet-surfaces roles-roster enrollment now OWNED: added to ts-authority-converge's brick list (it was delete-blocking with no owner). 5. Dispatchability: ts-authority-converge sized (IntricacyMedium/ VolumeMedium — it is the sprint's entry point and concrete carrier work); the 2c anchor-grouping edges removed so ts-lens-door is not gated behind an umbrella that never completes (edges are for real deps only — the 2b block already followed this rule). Trivia: evaluator module path corrected to v2.extdeps.runtimes.*; cli_run line-count de-literalized (~28k and growing); 2b label reframed 'decoupled from strong self-host' to match the content. Regen byte-idempotent; roadmap_authority witnesses green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Roadmap 2d + plan doc: progress & observation — process→outcome discipline, one event model, N renderers docs/plans/progress-observation-design.md: the five operator-signed laws (process→outcome no orphans; heartbeat carries identity; recursive dwell escalation; quiet at arm's length; every response true), the P0 event model (Refused distinct from Failed; BlockedOn DERIVED from governor facts; one glyph/material authority incl. the reward-animal rows), and per-context FORMAT CONTRACTS: CI log (append-only, heartbeat+escalation first-class — the reference implementation's gap), interactive TTY, receipt/JSONL (replayable; existing receipts become derived views), dashboard (schema-only), pipe. Reference implementation gunb-ai/gunb.ai tools/terminal studied BY EXECUTION (tests green; driven live in TTY/CI/failure modes): lift contention/nesting/boxes/reward; fix CI silence, Failed/Refused conflation, hand-mirrored emoji duals. Roadmap 2d: ts-obs-anchor + sized ts-obs-model (P0) + sized ts-obs-ci-renderer (P1, flagship = re-render the captured crawl window of run 30044816605) + ts-obs-tty (P2) + ts-obs-census-wall (P3), edges encoding P0→P1/P2→P3. Doc-graph bind added; reachability witnesses 4/4 and roadmap witnesses green; ROADMAP.md regenerated via main_wet. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan: CI two-tier placement redesign — the 5-second rule Records the 2026-07-24 operator decisions: placement by measured warm cost (≤5s rides the PR path, wet admissible if fast + hermetic-classified), DELETE the per-PR selection-control audit step (falsifier cadence is the surviving control), Rust seed stays tested-by-execution in CI. Dependency order D0–D5 with the post-merge #7129 P1s folded into D0 and the run_claims_in_process activation blockers into D1. Doc bound to gunbc.ci_spec.gunbc_ci_spec; dissolves when D3's placement axis lands. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan: single-PR delivery structure + expectation sheet + sign-off checklist Operator directive 2026-07-24: no staged drag-out — pre-PR probe does all measurement, one redesign PR lands D1+D3+D4+D5 atomically (single revert), D0 close-out routed to the #7129 worker and sequenced first (shared cli_run.rs). Before/after sheet with falsification bounds per row; §9 decision checklist for reviewer sign-off. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan: issue-closure checklist worked through by execution; three corrections Verification pass before operator review (2026-07-24): (1) D1 already LANDED on main — #7122 + #7128 pooled the 26 cold children to 6, verified by counting readiness probes in run 30052571652's ci log; plan re-framed, in-process activation split off as deferred D1b with its fail-open confirmed by direct read of cli_run.rs:9580. (2) D4 audit deletion now BLOCKED on falsifier health — the cadence is red 5/5 by crawl-timeout (run 30044928186: cgroup 16.1G pinned, swap saturated, 170m cap), so the per-PR audit is currently the only working selection control. (3) The 5s threshold reuses the existing fast-lane law carrier (thread-CPU budget, typed refusal) — no second authority. §10 checklist: 14 rows, each with status + how verified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan + roadmap: apply the #7132 review round — fourth carrier contradiction, staleness, D5 brief in-tree All five findings verified against the tree before applying: (1) parity_window required_consecutive_green_windows=3 + frontier dissolve_on strings contradict the 2a re-pricing (no first flip writable with the falsifier red) — joins ts-authority-converge's stale-prose deliverables as the FOURTH contradiction; (2) ts-store-econ's '#7129 in flight' corrected to merged + PR-0 close-out; (3) rust-suite disposition miscite fixed at its authorities (design_document, ci_spec — DESIGN.md reprojects; actual decl commit_gate_rust_suite_removed_disposition); (4) roster rows corrected to post-pooling reality (6 = 1 union + 4 ingest-overlay by construction per ingest_pool_separation_note + 1 reads-class; batch-6 414s not 12.15m); zero-hand tag repointed at ts-seed-interim; (5) D4 leaves PR-1 — fast-follow micro-PR gated on first green cadence (§9.7). Implementer round folded in: D1b scope refinement (plain resolve_entry_graph — spawns removed, per-entry resolves not), 5s threshold-vs-mechanism caveat (§9.1), and §11 lands the DiffBaseline brief in-tree (previously chat-only). ROADMAP.md regenerated via main_wet. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Split hub-file token fixes out of this PR; record the batch-3 budget finding Run 30063529282 refused batch 3 at 24m59s vs the 22m budget: the one-token miscite fixes in ci_spec.dag + design_document.dag are hub files, so selection legitimately ran the full corpus (2,315 witnesses, ALL PASS, RSS healthy) — the honest full-corpus wall exceeds the budget. Attribution clean: same branch without the hub files was green (0d54cdc). Fixes reverted here to ride PR-1 (which pays full corpus anyway); DESIGN.md re-projected from its reverted authority. Systemic implication recorded: PR-1 necessarily touches CiSpec and will face the same wall — §9.8 decision (receipt-noted raise sized by the D2 probe) + checklist row 15. The budget wall itself worked as designed; no widen. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg --------- Co-authored-by: Claude <noreply@anthropic.com>
Auto-opened by session-dashboard for session
neat-carp-312.Pushing to
session/neat-carp-312advances this PR.Summary
Lane C of the XL dispatch wave: adds two native (emitted-Rust) host-effect witness families —
filesystem_readandshell_exec_run— to the emit-host execution path, each proven equal to the interpreter by execution on the same workspace, plus a construction-time confinement wall gating which families may ever build a realHostTransportDescriptorfor an emitted binary.What changed
filesystem_readandshell_exec_runnative families (src/v2/extdeps/languages/rust_test.dag): each family's emitted Rust argv/handler is derived from the sameextdepsop rows the interpreter reads (shell_materialize_argv_for_operationagainstdag/extdeps/shell/exec.dagforshell.Exec.Run— no hand-typed second dispatch).src/v2/test/claim/execution/emit_host_filesystem_read_equals_eval_test.dag,emit_host_shell_exec_run_equals_eval_test.dag): both legs (interpretedeval+ native emitted binary) run against the same workspace and are proven byte-identical by execution.src/v2/lens/emitted_binary_effect_confinement.dag): a construction-time gate (WallNow{SingleAuthority}) at the.dag-level call site that builds aHostTransportDescriptorfor an emitted binary. Only rostered families (filesystem_read_family,shell_exec_run_family) admit; anything else returnsHostRuntimeRowAbsent(reuses the existingTargetEmitHostRuntimeRowrefusal carrier, no new parallel refusal type). RED control (src/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag) proves a synthetic unrostered family name refuses via the real gated call site.native_routing_frontierroster: added both new families asInterpretedRetained{reason: "no_cached_no_evict_carrier"}(conservative — not falsely markedNativeRouted); bumpednative_routing_frontier_family_count_expected9→11. No existing row's family/disposition touched.v2.lens.emitted_binary_effect_confinementadded as a newLensIdV0(EmittedBinaryEffectConfinement) tov2.lens.registryand its exhaustive dispatch inv2.lens.enforcement.lens_module_gate, satisfying the corpus-widelens_registry_completeness_holds_livegate.Exit receipts (per parent mandate)
PASS emit_host_filesystem_read_equals_eval_all_holds(188ms)PASS emit_host_shell_exec_run_equals_eval_all_holds(188ms)PASS emitted_family_effect_admitted_refuses_unrostered_familyPASS emitted_family_runtime_row_gated_refuses_unrostered_family(synthetic unrostered family →HostRuntimeRowAbsentvia the realemitted_family_runtime_row_gatedcall site)PASS emitted_family_runtime_row_gated_admits_rostered_filesystem_read_familyshell_exec_run_witness_argv()callsshell_materialize_argv_for_operation("dag/extdeps/shell/exec.dag", "shell.Exec", "Run", ...)— the emitted argv is read from the same.dagop row the interpreter'sdispatch_shellreads, not a duplicated literal.Test plan
claim_batch --hermetic --entry src/v2/lens/registry/completeness_test.dag --function lens_registry_completeness_holds_live→ PASSclaim_batch --hermetic --entry src/v2/test/claim/self_host/native_routing_frontier_test.dag --function native_routing_frontier_witnesses→ PASSclaim_batch --hermetic --entry src/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag --functions ...(3 witnesses) → all PASSclaim_batch --wet --entry .../emit_host_filesystem_read_equals_eval_test.dag --function emit_host_filesystem_read_equals_eval_all_holds→ PASSclaim_batch --wet --entry .../emit_host_shell_exec_run_equals_eval_test.dag --function emit_host_shell_exec_run_equals_eval_all_holds→ PASSciGitHub Action check: in progress on latest push (merged origin/main to pick up CI fail-fast: cheap-gate early batch (SIMPLE declared membership + dissolution trigger) + event-scoped stop policy #7088).Re-verified at current head (319f445, 2026-07-23, fresh local
claim_batchbuild)PASS emit_host_filesystem_read_equals_eval_holds(173ms)PASS emit_host_shell_exec_run_equals_eval_holds(127ms)PASS emitted_family_runtime_row_gated_refuses_unrostered_family(RED control)PASS emitted_family_runtime_row_gated_admits_rostered_filesystem_read_familyPASS native_routing_frontier_witnessesPASS lens_registry_completeness_holds_liverust_test.dag's emitted-argv construction and the eval-side witness callshell_materialize_argv_for_operationagainstdag/extdeps/shell/exec.dag'sshell.Exec.Runrow — one derivation, not a hand-typed second dispatch.filesystem_read_family,shell_exec_run_family) and theemitted_binary_effect_confinementwall land in this same PR, before either family's emitted binary can build a realHostTransportDescriptor— construction wall, not a follow-up.lens_module_gategated-file edit confirmed complete:EmittedBinaryEffectConfinementis enrolled inv2.lens.registry(+11 lines) and has an exhaustive dispatch arm inlens_module_gate.dag;lens_registry_completeness_holds_livepasses.cicheck: in progress (self-hosted runner queue contention from the parallel XL-dispatch-wave lanes; multiple re-merges of an advancingmainhave restarted it several times — each restart's diff confirmed clean, only this PR's 9 files vsorigin/main).buildcheck (compile-clean) passes.