Repository navigation
host-convergence circuit: kill the paper transport (P0) + PerSlotMemoryCap reconcile loop, live-wired (P1/P1a) - #7121
Merged
Conversation
Convergence actuates ONLY via host_effect_apply's typed transports (operator
routing ruling: runtime-present hosts never get emitted bash). Delete the
bash-emission path and its committed product:
- rm dag/gunbc/fleet_converge_emit.dag (bash-emission: expected_fleet_converge_sh,
project_fleet_converge_to_doc, fresh_standup_bootstrap_* — the latter had NO
executing consumer, gated-artifact-only; the standup lane owns re-adding a
bootstrap fragment if/when a named consumer executes it). The typed path
(converge_apply/converge_apply_fleet) already lives in fleet_converge_apply.dag.
- rm .github/fleet-converge.sh (the generated product) + its FleetConvergeArtifact
registration in generated_artifact{,_emit}.dag (type variant, registry, path,
commit-policy, eq/predicate arms; drift-test registry count 14->13).
- rm dag/test/claim/fleet_converge_emit_test.dag + its commit_workflow enrollment.
- host_effect.dag: drop emit_artifact_then_thin_run_transport_scaffold (it bound the
deleted disposition); the EmitArtifactThenThinRun transport itself STAYS (general
infra: srv3-install/ci_deploy/nbd_proxy). fleet_converge_apply_witness_test drops
the assertion on the deleted scaffold.
- host_standup.dag: converge prefix authority re-pointed to fleet_converge_apply
(typed transport), paper-emit decl_ref removed.
THE WALL: remove "dag/gunbc/fleet_converge_emit" from
realization_vocabulary_containment realization_edge_path_prefixes. Nothing under
dag/gunbc/fleet_converge* may now emit ShellProgram/bash-AST vocabulary — a stray
import would red the containment lens.
Witnesses green: fleet_converge_apply, generated_artifact_drift, host_standup_spine,
commit_workflow, realization_vocabulary_containment (the wall).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…eceipts, hermetic)
The first NON-DEGENERATE membership_reconcile in the repo (desired vs a real
observed set, not observed=[]). The entire caps loop is ONE instantiation of the
grain-agnostic spine with a (key_of, key_eq, value_eq, ownership_of) bundle —
no forked reconcile.
- CapMember: a per-slot systemd drop-in keyed by file PATH (stable identity, so a
content drift is Modified->Upsert, never Remove+Add). Ownership DERIVED from the
path (managed 20/30/40-fleet-*.conf -> Owned; anything else -> foreign, Ensured),
never stored (§5 construction — inconsistent ownership/path unwritable).
- Interference domain = the drop-in directory itself, realized through the SAME
spine: a foreign occupant is observed-not-desired -> Removed -> not-owned ->
MemberTeardownRefused (R5: no effect arm, never deleted) -> membership_effects
ApplyRefused wholesale.
- cap_dropin_content derives "[Service]\n<property>=<bytes>\n" from the knob fields
(no hand strings); cap_upsert_script is the derived actuation (write + daemon-reload).
Four hermetic receipts, each with a RED control, all GREEN (auto-discovered CI
corpus consumer, not inert):
1. idempotence: observed==desired -> zero effects (EffectsReady empty).
2. perturb-and-heal: one drifted cap -> exactly that row Upsert (RED: no drift -> 0).
3. foreign occupant: unowned .d file -> ApplyRefused, zero teardowns
(RED: an OWNED removed file -> Teardown, proving the refusal discriminates).
4. derived content: [Service]/property/bytes derived (RED: different bytes differ).
Live srv1 apply/observe (interpreter->realize execution + fail-closed observe
provider) is the go-live integration; this commit is the proven pure fold.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
interpret_converge_knob now maps PerSlotMemoryCap -> KnobEffect carrying the derived cap_upsert_script (single content authority = host_axis_caps, no hand strings); every other target stays KnobUnimplemented. interpret_host_converge accumulates KnobEffect scripts and still short-circuits to ConvergeHostRefused on any unimplemented knob. realize_converge_in_process no longer grounds a fabricated exit_code 0 — it runs the interpreted script through run_shell_transport (in-process LocalShell) and grounds on the REAL exit; a nonzero exit is a typed, located NotConverged refusal. The latent §5 fail-open (dead only because everything refused) is gone. Safe on the hermetic floor: every real fleet host also carries pinned-tree / jobserver / runner-width knobs (still KnobUnimplemented), so interpret_host_converge refuses the whole host BEFORE realize reaches run_shell_transport — no witness shells out in CI. Verified green by execution: host_converge_realize_holds (SliceProperty still refuses) · srv3 memory witness flipped refuse->interpret (runner_memory_knob_apply_interpreted) · srv2 KnobFrontier receipt still refuses · fleet_converge_apply still refuses · 4 caps receipts + drift regression all true. Registers gunbc.plans.host_convergence_circuit_residue: the AcceptedWithResidue receipt. Landed = P0 + P1-core + P1a; counted residue = caps-only APPLY entry (the live one-liner still refuses whole-host on siblings today), the Wet-gating landmine, P1b observe provider, live srv1 receipts, P2 enrollment + wall, P3 axis framework. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
…etired; FleetConvergeArtifact deregistered) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 23, 2026
Both-append conflict resolutions: roster_registry keeps main's non_fold_residue_frontier row AND this PR's stage0_partition_crate_rows enrollment; roadmap_authority takes main's updated ts-group-census (the #7089/#7107 landing receipts) and keeps this PR's ts-group-partition-drift + ts-group-dissolve-typed rows, with partition-drift item (a) marked done by this change (the enrollment is in this PR). ROADMAP.md and ci.yml regenerated via main_wet on the merged tree, not hand-stitched — the only ci.yml delta vs main is dropping .github/fleet-converge.sh from the auto-heal roster (main deleted the file and its emitter in #7121; main's own ci.yml still lists it — latent drift its auto-heal will clear). roster_registry witnesses 5/5 green post-merge. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
…tered in #7121) The generated ci.yml auto-heal git-add list is derived from the artifact registry; #7121 removed FleetConvergeArtifact, so the regenerated list no longer names .github/fleet-converge.sh. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 23, 2026
…cile regen-job extraction with main's GithubActionsCiRegenJob gate lane Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
…sing leg rows (#7127) Root cause: the batch-3 floor panicked in `witness_execution_leg_label` (cli_run.rs:8508) — "no census TSV row for entry dag/test/claim/ci_heal_job_witness_test.dag (refuse — regenerate ...)". This is the correct fail-closed refusal (§5): the leg loader has no row for a witness entry the floor is about to run. The census TSV (docs/probes/witness_entry_eligibility_census.tsv) is a generated artifact regenerated only by hand via scripts/witness_entry_eligibility_census.sh (the witness_entry_eligibility_census_emit transport, which delegates every classification column to the v2.compiler.self_host.witness_entry_eligibility_census authority). Its committed bytes carried an 08:16-EDT snapshot (stamp 12:16Z) that predated a burst of PRs which added/relocated witness *_test.dag files under witness_layer_roots (ci_heal #7112, Belt B #7113, Lane D relocation #7098, host-convergence #7121, ...). Because the Rust sync test that checks census/roster freshness was removed from CI on 2026-07-11, the drift merged to main undetected and only surfaced as the floor panic on the first uncovered entry. The roster drifted by +10/-3 vs the census (857 -> 864): 10 entries added (ci_heal_job, component_dispatch_button, css_grain, dispatch_presentation, floor_discovery_hand_rust_equivalence, floor_discovery_roster_fixture, host_axis_caps, media_type, roadmap_sandbox, long/orchestration_while_emit) and 3 removed (fleet_converge_emit, roadmap_dashboard_emit_witness, the old workflow/orchestration_while_emit location). Fix (regenerate the artifact from its authority — no hand-forked classification): - regenerate census.tsv + histogram.txt via witness_entry_eligibility_census_emit (864 entries; every current roster entry now has a non-empty execution_leg) - bump witness_entry_eligibility_census_entry_count 857 -> 864 and the census_test `== 857` assertion to `== 864` - refresh the decorative stamp constant and the two prose "857" references Proof by execution: witness_entry_eligibility_census_tsv_sync_tests:: tsv_data_row_count_matches_declared_authority passes from the repo root (declared authority count 864 == committed TSV data rows 864). Claude-Session: https://claude.ai/code/session_014qyDtPF6EM5hvRiUDUG5fe Co-authored-by: Claude <noreply@anthropic.com>
7 of 8 tasks
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
…eanup (#7027) * fix(srv3): DirectLayout on-ISO autoinstall + os-install reconcile spine (T3/T4) Rebased onto main: StoragePolicyDirectLayout on seeded ISO autoinstall, split reconcile modules (core/types/receipt/apply/dry_run/record_approval), honest freeze scope and printf receipt echo, fail-closed observed_at parse, ServeReady virtual-media session match, and review-driven witness coverage. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(srv3): observe script bash syntax — drop stray HTTP_CODE= before if Serve receipt echo was concatenated into curl_tail as HTTP_CODE=if test…, breaking live reconcile observe on srv1. Witness guards the regression. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(srv3): observe script curl HTTP_CODE — remove extra closing paren $(curl … || echo 000) had a stray ) breaking bash on live srv1 observe. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(srv4): BMC onboarding gap analysis — srv3-hardcoded plan + gcloud not provisioned srv4 racked, BMC at FactoryDefault (403 PasswordChangeRequired). The rotation workflow (bmc_converge_credential_idempotent, wired into host_standup_spine) is fully modeled and fail-closed, but bottoms out on the srv3-hardcoded new_altra_onboarding_plan and assumes gcloud is present. Documents 4 gaps (G1 per-host parameterization [dispositive], G2 gcloud self-provision, G3 operator-token handler, G4 srv4 identity rows) for review before modeling. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(srv4): close BMC onboarding gaps — per-host plan, gcloud self-provision, operator-token handler, srv4 identity Full close of the four gaps from the analysis doc (PR #7027), so BMC onboarding is hands-off per-host instead of srv3-hardcoded: G1 — per-host parameterization: altra_onboarding_plan(bmc_host, secret_name) constructor + srv3_onboarding_plan / srv4_onboarding_plan rows replace the srv3-literal new_altra_onboarding_plan. Threaded `plan` through every bmc_onboard func; de-nicknamed srv3_gcp_project -> bmc_secrets_gcp_project (fleet-wide). Zero-arg per-host entries srv3_converge_credential / srv4_converge_credential are what the standup decl_ref + executor invoke. G2 — gcloud self-provision: modeled gcloud_cli_tool (extdeps/tools/gcloud.dag) + package_google_cloud_cli, and bmc_credential_actuator_toolchain_requirement (curl + gcloud) mirroring the OS-install toolchain-ensure. G3 — token de-fork: gunbc.auth.access_token_source with AccessTokenSource = GcloudPrintToken | OperatorSuppliedToken{token} and resolve_access_token, so an operator-supplied token is a first-class handler (drives rotation with no gcloud on the actuator). G4 — srv4 identity: operator_host_srv4 + srv4_bmc_endpoint (.195) in fleet_intent_network. Verified: full-corpus typecheck clean (850 modules, 0 errors) + 11 witnesses green by execution across every touched module, incl. a new discriminating srv4_plan_targets_195_with_srv4_secret and the updated endpoint-count witness. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc): mint OpenBMC-policy-compliant credential (found by live srv3/srv4 rotation) First live execution of the rotation flow (srv3's was never run green) surfaced that mint_bmc_credential's base64 octets are rejected by OpenBMC password validation (PropertyValueFormatError). A firmware-policy divergence also showed: srv4 (newer OpenBMC) accepts alphanumeric, but srv3 (OpenBMC 2.07.00, pwquality, MinPasswordLength 9 / MaxPasswordLength 20) requires a 4th character class. Fix: Urandom.ReadPassword — composition-guaranteed generator (>=1 upper/lower/ digit/special from the shell/JSON/basic-auth-safe set _.@#%-); mint_bmc_credential mints a 16-char such password (within 9-20, accepted by both firmwares). The fail-closed read-back gate correctly aborted every base64/alnum attempt before rotating, so no lockout. Both srv3 (secret bmc-srv3-admin v6) and srv4 (v2) are now live-rotated off factory 0penBmc; orphaned pre-rotation versions destroyed. Full-corpus typecheck clean (850 modules, 0 errors) + witnesses green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): model fleet SSH access — operator + automation public keys (durable in repo) SSH-who, the third principal facet alongside POSIX-who (fleet_posix_accounts) and GCP-who (fleet_operator_gcp_iam_member): - extdeps/access/ssh.dag: SshPublicKey type + authorized_keys line renderer. - gunbc/fleet_ssh_access.dag: operator MacBook key (global break-glass, logs in as briansrls) + fleet-automation key (machine access). Both PUBLIC keys grounded in the repo (public keys aren't secret). fleet_authorized_keys = both, applied to every host by breadth. - fleet_automation_ssh_privkey_secret → SecretRef to Secret Manager 'fleet-automation-ssh-key' (project gunbai-secrets, v1). The private key's only copy lives there; generated 2026-07-21, local copy shredded. - keys/fleet-ssh-public-keys.txt: plain-text backup of both public keys. FOLLOW-UP: fleet-automation-ssh-key has no secret-level IAM binding yet (project- scoped access). Lock to a dedicated automation SA with secretAccessor, mirroring bmc-assimilator on bmc-srv*-admin. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc): remove fabricated-fallback in onboarding_secret_id (§5 fail-closed) onboarding_secret_id matched plan.rotated_credential and, on the Chained arm, fabricated a secret id (plan.bmc.host; pre-existing code fabricated a literal) — a §5 "fabricated plausible output" fallback. Construction-first fix: narrow the plan field from rotated_credential: CredentialFlow to secret_name: NonEmptyStr, so the Chained state is unwritable and the function is total (plan.secret_name, no match, no fallback). Dropped now-unused std.credentials imports. Verified by execution: srv3/srv4 plan witnesses (now assert secret_name directly) + bmc_onboard load, all green. rotated_credential/Chained gone from the corpus. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): dedicated fleet-automation SA scoped to the SSH private key Created service account fleet-automation@gunbai-secrets (least-privilege: secretAccessor on fleet-automation-ssh-key only, mirroring bmc-assimilator's scoping). Grounded in the model: fleet_automation_sa_email + SecretOwner record tying the SA to the private-key secret, so "who owns the private key" is answered in the repo, not just in GCP. Binding applied out-of-band (provenance recorded); full WIF SecretAccessGrant modeling is follow-up. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(access): bake fleet SSH keys into autoinstall, disable password SSH Wire the access model into the OS install: UbuntuAutoinstallPayload gains ssh_authorized_keys (List<SshPublicKey>) + ssh_password_auth; os_install_emit renders the subiquity ssh section with authorized-keys (operator + automation public keys) and allow-pw. srv3 payloads set fleet_authorized_keys + allow-pw false — installed hosts trust the fleet keys and refuse password SSH. Verified by execution: srv3_os_install_emit witnesses green, incl. a new discriminating one asserting both key lines present + "allow-pw: false". Note: identity.password still carries the bootstrap hash; per-host strong console break-glass credential is part of Step B (per-host install identity). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(srv4): autoinstall payload + seeded-ISO rows (Step B) srv4 host identity baked at install time: srv4_autoinstall_identity (hostname srv4, console break-glass hash; plaintext in Secret Manager host-srv4-console) + srv4_ubuntu_autoinstall_on_iso (NoCloudLocal, DirectLayout, fleet SSH keys, allow-pw false). srv4 seeded-media artifact rows + srv4_seeded_install_media_remaster mirror srv3, driven by the same install_media_remaster_script builder. Dry-run verified (typechecks, script generates, ExitSuccess). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): model UEFI Shell + boot-config solver (dissolve manual UEFI GUI step) The manual "enter UEFI setup, enable PXE / set boot" GUI step becomes a grounded, solvable model: - extdeps/firmware/uefi_shell.dag: UEFI Shell command surface (bcfg boot dump/add/mv/rm, map, reset) cited to the UEFI Shell 2.2 spec, with a renderer to the real command text + a script folder. - gunbc/uefi_boot_config.dag: DesiredBootSource (install media | PXE entry) -> bcfg command sequence — the UEFI-shell realization of the same "what to boot" intent the Redfish BootSourceOverride path already models (§2, one intent / two realizations). srv4_uefi_install_boot targets fs0:\EFI\BOOT\BOOTAA64.EFI. Verified by execution: witnesses assert the exact bcfg sequence for install-media boot and for PXE-entry reorder. Next: SOL send transport (extend serial_console, currently capture-only) to drive these over obmc-console into srv4's UEFI shell. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi/sol): SOL send transport + drive UEFI-shell boot-config over IPMI SOL Confirmed live first (operator's caution): the ASRock ALTRAD8UD OpenBMC 2.07.00 supports IPMI SOL (ipmitool -I lanplus sol info → Enabled, ADMINISTRATOR, port 623). That capability was unmodeled — grounded it now: BmcCapability gains CapabilitySerialConsole, added to the 2.07.00 list with a live-probe provenance row. Transport: extdeps.bmc.serial_console gains SolConsoleTransport::IpmiSol + SolConsoleSendIntent + sol_console_send_script (ipmitool sol activate with piped input via IPMI_PASSWORD -E; obmc-console send arm too; RedfishSerialInterface send fail-closed as read-only). Runner: gunbc.uefi_shell_over_sol turns the solved bcfg sequence into serial input (\r-submitted) and a SOL send script; srv4_uefi_boot_config_sol_send_intent targets .195. So the manual UEFI GUI step is now: solve DesiredBootSource → bcfg → drive over SOL, fully executable. Verified by execution: witnesses assert the srv4 send carries the bcfg sequence, the script uses ipmitool sol activate, and the ASRock 2.07.00 row declares the serial-console capability. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(sol): IpmiSol exhaustiveness in srv3_sol_console_capture witness Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): model the UEFI Shell command surface + observable environment Back up and ground the real shell interaction (not ad-hoc poking): - Command surface expanded: connect -r (ConnectRecursive), devices (ListDevices), ifconfig (list / set dhcp / set static) alongside bcfg/map/reset — the commands actually used driving srv4 over SOL, cited to the UEFI Shell 2.2 spec. - Observable environment types: UefiNetworkInterface (+ UefiMediaState), UefiBootOption, UefiDeviceMapping, UefiShellEnvironment — so the interaction is observe->decide->act. - gunbc.srv4_uefi_observed: srv4's ACTUAL environment captured live over SOL 2026-07-21 (map -r, bcfg boot dump -v, ifconfig -l): NVMe with Windows Boot Manager + EFI Shell, eth0/eth2 media present (eth0 link-local 169.254.0.18), eth1/eth3 disconnected. Finding that motivated this: UEFI network stack is ALREADY up in srv4's shell (eth0 has media) — PXE-enable via GUI is unnecessary; ifconfig -s eth0 dhcp reaches the network directly. Windows-on-disk confirmed (operator OK'd wipe). Verified by execution: new commands render, srv4 observed env asserts eth0-has-link + Windows-present. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(uefi): boot-install decision/diagnostic model (observe→diagnose→decide→act) Generalize the "we're at a UEFI shell, now what?" case into a goal-directed decision procedure over the observed environment: - DesiredOutcome = InstalledFleetNode (the goal: wipe + unattended Ubuntu). - diagnose_boot_install(env) -> BootInstallSituation: pure read of the observed UefiShellEnvironment → InstallMediaReady | NetworkReady | NetworkUpNeedsDhcp | NoBootSourceAvailable. Fail-closed: no media + no link says so, never pretends. - decide_boot_install(situation, goal) -> BootInstallAction: goal-directed; refusal is a first-class outcome (RefuseNoSource), not a silent no-op. - boot_install_commands(action) -> List<UefiShellCommand>?: Absent for a refusal — a caller cannot extract a "do nothing" sequence and mistake it for progress. Grounded on srv4's real observed env: diagnoses NetworkUpNeedsDhcp{eth0} (media up, link-local) → DhcpThenNetworkBoot → ifconfig -s eth0 dhcp. Discriminating fail-closed control witness: no-media/no-link env → RefuseNoSource → Absent commands. Verified by execution. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc): model self-contained BMC netboot serve (no runtime central server) Answering "why srv1?" — it isn't needed at runtime. Model the BMC as the netboot host: gunbc.bmc_netboot_serve.BmcNetbootServePlan + srv4 instance. - bmc_netboot_serve_command: busybox httpd -f -p 8080 -h /tmp/netboot (the BMC hosts the ~88MB bootstrap: kernel/initrd/grub + a staged static busybox). - bmc_netboot_grub_cfg: boots /vmlinuz + /initrd with url= at the Ubuntu MIRROR (host streams the ~1.5GB bulk directly, never on the BMC) and ds=nocloud-net;s= at the BMC's own seed dir. - bmc_netboot_nocloud_user_data: the served seed = autoinstall_user_data(srv4 payload) — carries fleet SSH keys + allow-pw:false, same emit as the on-ISO path. So provisioning is BMC + internet: no central serve host at runtime; srv1's only role is one-time (cacheable) extraction of the 88MB bootstrap from the ISO. Scaffold-marked (medium-as-string ssh/httpd glue) like nbd_proxy_serve. Verified by execution: grub.cfg targets mirror-bulk + BMC-seed, serve cmd is busybox httpd, served seed carries the fleet keys. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * refactor(bmc/netboot): model components structurally in extdeps (no concat blobs) Per operator direction — model each piece appropriately in extdeps first, legibly, instead of hand-built concat strings: - extdeps/firmware/kernel_cmdline.dag: KernelCmdlineArg = KernelFlag | KernelKeyValue; kernel_cmdline_render via join/map (cited to kernel-parameters.rst). - extdeps/bootloader/grub.dag: GrubConfig / GrubMenuEntry (structured), grub_config_render via join — replaces the string-blob grub cmdline pattern (cited to the GRUB manual). - extdeps/tools/busybox.dag: busybox CliTool + service busybox.Httpd.Serve with structured argv transport (the idiomatic form, like curl.Http). - extdeps/firmware/uefi_http_boot.dag: UefiHttpBootEntry + provisioning variants (cited to UEFI 2.10 HTTP Boot). gunbc.bmc_netboot_serve recomposed to build a GrubConfig + UefiHttpBootEntry from the plan (no bespoke concat); grub.cfg, http-boot target, and BMC-served nocloud seed all derive from structured values. Bulk from the Ubuntu mirror, seed from the BMC. Verified by execution: grub.cfg renders the full structured cmdline, http-boot entry targets the BMC url, served seed carries the fleet keys. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): model BMC ssh transport + structured staging manifest - extdeps/bmc/ssh.dag: service bmc.Ssh (ExecScript + PutFile) over sshpass -e (password via SSHPASS env, never argv) — structured argv, mirrors curl.Http. - gunbc.bmc_netboot_serve: staging modeled as a structured manifest (BmcStagedFile / StagedContentSource = InlineText | LocalArtifact | FetchFromUri): busybox+kernel+initrd+grub as LocalArtifact, the rendered grub.cfg + nocloud user-data/meta-data as InlineText. Separates WHAT must be on the BMC from HOW it gets there. Verified: manifest stages the rendered grub.cfg (ds=nocloud-net) and the seed (fleet keys) inline, 7 files. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(exec): transport seam — one command, N transports (§3, no forked blobs) extdeps/exec/command.dag: ShellCommand { argv } + CommandTransport = LocalShell | SshExec { ssh_target }; command_over_transport wraps a command's argv with the transport prefix; shell_command_render joins to a string. One operation, chosen transport — not a per-site command blob. - busybox: service busybox.Httpd removed in favor of busybox_httpd_command -> ShellCommand (single authority for the command shape; runs local OR over BMC-ssh via the seam, no dual representation). - bmc.Ssh: ExecScript removed (superseded by SshExec transport); PutFile kept for file transfer. - bmc_netboot_serve: the serve command is busybox_httpd_command over bmc_transport (SshExec root@bmc); local and BMC renderings both derive from it. Discriminating witness serve_command_one_shape_two_transports: the same command renders "busybox httpd -p 8080 -h /tmp/netboot" locally and the sshpass-wrapped form over the BMC transport. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): orchestration provision func (realize via the seam) bmc_netboot_provision: sequences the staged manifest + serve — mkdir + serve go through the extdeps.exec.command seam (bmc_netboot_run_bmc), artifacts via bmc.Ssh.PutFile, rendered grub.cfg/seed via Filesystem.Write then PutFile. process_exit_first_failure collects the first failure (no fabricated success). srv4_bmc_netboot_provision is the zero-arg entry. bmc.Ssh.PutFile gains a mock_response for hermetic dry-run. Marked realization scaffold. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc/netboot): httpd command uses the staged busybox binary (found by live run) Live provision revealed the serve invoked the BMC's system busybox (no httpd applet) instead of our staged static busybox. busybox_httpd_command now takes busybox_bin; bmc_netboot_serve_command_local passes the staged path (/tmp/netboot/busybox). Witness updated to the staged-path rendering. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * feat(bmc/netboot): model the busybox cross-build (reproducible, not manual) - extdeps/exec/command: shell_command_render now shell-quotes each arg (handles args with spaces like EXTRA_CFLAGS="-march=... -mfloat-abi=..."), robustness fix. - gunbc/command_runner: run_shell_command / run_shell_commands — generic sequential runner over the seam with short-circuit (fold-with-effects, verified). - extdeps/tools/busybox: busybox_source_1_36_1_url; apt package_gcc_arm_linux_gnueabi. - gunbc/busybox_bmc_build: BusyboxCrossBuildPlan + busybox_build_commands (fetch → extract → defconfig → enable static → disable TC → cross-compile armv5te soft-float → install artifact) + busybox_bmc_build_run. Solves the BMC-httpd wall found live: the AST2500 (armv6, no VFP) SIGILLs on prebuilt busybox httpd; our conservative-flags build runs clean (verified: httpd serves HTTP 200 on the BMC). busybox_bmc_build_run regenerated the artifact from source end-to-end. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(bmc/netboot): srv4 boot NIC is eth2 (leases DHCP), not eth0 (found live) eth0 has media but its UEFI DHCP falls back to link-local; eth2 leases 192.168.1.196 on the LAN segment with the BMC. Plan boot_interface + witness updated. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * srv4 fleet subsumption + BMC virtual-media install path + modeling cleanup Subsume srv4 into the fleet and get it onto GitHub Actions runners, plus the supporting install-path modeling and several dissolved shell/§3 forks found along the way. Fleet membership (srv4): - srv4_host + samsung_970_evo_500gb_catalog (its actual drive, cited), LAN endpoint 192.168.1.196, srv4_offer, deployed_intent_v1_srv4. Placement solver now allocates srv4 runner slots (fleet_concurrent_runs 30->40). Runner deploy (the width-INCREASE gap, now modeled): - runner_host_deploy.dag: RunnerHostDeploy intent citing the ctrl installer (install-actions-runner.sh) as the bound realization handler (§3 cite-upstream, not re-coined). Renders the CTRL_RUNNER_* invocation, the App-key SecretRef, and the actions-runner@srv4-NN enables. srv4: user briansrls, 5 slots (disk-cap note for the 500GB NVMe vs 2TB fleet). Execution-surface honesty + toolchain provisioning (§5 model-reality gap): - fleet_intent_execution_surface no longer lies: container_runtime Present{Docker} + toolchains [sccache] instead of none/[]. - extdeps/cache/sccache.dag: SccacheBinaryRelease (pinned v0.15.0 + per-arch sha256, cited to mozilla/sccache/releases) + install script. - extdeps/container/docker_ce.dag: DockerCeAptRepo + packages + rootless-docker apt prereq install, cited to docs.docker.com. BMC virtual-media install path (used to install srv4 end-to-end): - extdeps/storage/nbd.dag, extdeps/linux/usb_gadget.dag (typed ConfigfsOp list, not scattered concats), gunbc/bmc_virtual_media.dag: nbd-server -> nbd-client -> configfs mass_storage USB gadget. Unified under extdeps/bmc/virtual_media.dag VirtualMediaIntent with the existing nbd-proxy-websocat path (§3 fork dissolved). - extdeps/firmware/uefi_shell.dag + gunbc/bmc_netboot_shell_boot.dag: shell-native tftp/execute boot modeling. Install bugfixes (root-caused live, captured in the model + witnesses): - grub.dag: quote kernel cmdline args containing ';' (grub command separator) — ds=nocloud;s=... was truncated at ';', dropping the seedfrom, so autoinstall fell to interactive. grub_cmdline_arg_render + the seeded-media builders quote it. - ubuntu_seeded_install_media_remaster.dag: xorriso -boot_image any replay (was mkisofs, which destroyed the arm64 El Torito/ESP boot structure); instance-id derived from hostname (was hardcoded srv3). All new modeling lands with witnesses (green) and dissolution markers on the shell-as-string leaves. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * plans: fleet subsumption manual-gaps receipt (srv4 hand-steps -> modeling backlog) Modeled plan doc capturing every step of srv4 install+subsumption that was done by hand — each a modeling gap. Two families: (A) credential handling (every temp credential file = a missing MaterializedSecret lifecycle; reach-secrets ADC; SecretRef liveness after the stale App-key 401) and (B) provisioning (runner SLOT provisioning = the width-INCREASE gap fleet-converge.sh already names, documented in full: pinned ActionsRunnerRelease + per-slot dir seed + count reconcile, all hand-unrolled this time; fleet runner-user; fresh-host prereqs; configfs virtual-media install actuator + media-detach lifecycle). Each item carries acceptance tier + RED control; the plan's dissolution trigger retires item-by-item, fully gone when srv5 subsumes with zero hand-run shell. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * review 41721: shell_quote escapes embedded apostrophes (witnessed); IPv4 link-local/removable-media classifiers grounded on extdeps.firmware.uefi_shell rows (prefix test, cited tokens, dissolve-on to parsed device-path); bmc_netboot_provision folds the staging manifest (single authority; hand-unrolled sequence deleted; FetchFromUri refuses typed) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * plans: fold srv4 host-convergence OOM receipt into the manual-gaps doc Section C added: the 2026-07-23 follow-on where srv4 OOM-killed live PR CI. Sharper framing than the install-time hand-steps — this is an ENROLLMENT failure: srv4 is not a member of the modeled fleet (fleet_intent declares srv1/2/3 only), so the converge derivation cannot name it; the runner installer hand-pointed at srv4 made it a member in GitHub's eyes and a ghost in the model. Records: (1) model-without-actuator + emit-unprovable (KnobUnimplemented refusal AND fleet_converge_emit at 104 compile errors, so converge can neither apply nor emit today) — the displaced-cost pricing for 2-converge-reland; (2) the interim actuation receipt (swap 8->127G, per-slot MemoryMax/SwapMax inf->16G/32G derived-equal on identical 125GiB RAM, oomd installed+active, reclaim timer active — each interim, dissolution = enrollment + converge lane); (3) the three fixes it prices — actuation lane, SwapDevice modeled axis, and the enrollment wall as construction (installer refuses on a host absent from fleet_intent). Canonical host-state rows stay on the operator sheet (1a lane); this doc is the incident receipt. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * crypto.hash: single-variant coproduct via leading-pipe form; verify-line rendering re-homed beside the Digest authority type HashAlgorithm = Sha256 parsed as a type ALIAS to a nonexistent type (the grammar's single-name RHS form), so no Sha256 variant constructor existed and the sccache digest witness failed at runtime with 'undefined variable: Sha256'. The leading-pipe form selects the coproduct parse path explicitly. digest_shell_verify_line moves into extdeps.crypto.hash so the match over HashAlgorithm lives beside its authority; sccache.dag consumes it with the file path as a parameter. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * Regenerate DESIGN.md + fleet-converge.sh from .dag authorities (drift gate fix) CI generated_artifact_drift_gate_passes was red on 05c6a3b from two latent drifts, both now regenerated from their authorities via main_wet: - DESIGN.md: the srv4 open-threads bullet was hand-added to the projection but not to design_document.dag (its authority). Added as an li() row there; DESIGN.md regenerated to match. docs/plans/srv4-bmc-onboarding-gap.md is a genuinely new file needing a reference, so the bullet stays — just homed in the .dag single authority, not the generated .md. - .github/fleet-converge.sh: srv4 fleet enrollment updated the FleetConvergeArtifact authority; the committed script lacked the 'gunbc converge --host srv4' line. Regenerated. Verified: generated_artifact_drift_gate_passes returns true (exit 0). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * De-fork BMC scp transport onto the single ssh/scp posture authority (review 41797) bmc/ssh.dag (new in this PR) re-minted the sshpass -e + StrictHostKeyChecking=no + UserKnownHostsFile=/dev/null posture that extdeps.exec.command establishes as the single authority — a §3 parallel representation in the same PR that adds the unified transport seam. Fixed by construction, not a second copy: - command.dag: extract sshpass_prefix() and ssh_host_key_override_opts() shared helpers; ssh_exec_prefix now composes them; add scp_command(local, remote) that reuses the SAME two helpers (scp is a distinct binary with the host in remote_target, so it cannot compose through command_over_transport's ssh prefix — but it shares the posture authority). - bmc_netboot_serve.dag: bmc_netboot_put_path renders scp_command via the same shell.Exec.Run + shell_command_render path as bmc_netboot_run_bmc; the extdeps.bmc.ssh import and the whole bmc.Ssh service are deleted. - Two discriminating witnesses: scp render carries the exact shared posture argv; red control asserts no second/forked posture. All bmc_netboot_serve witnesses PASS; gate-equivalent compile has zero hard diagnostics. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * De-fork BMC scp: trigger-text + discriminating witnesses (review 41797) Completes the scp de-fork commit: dissolution trigger now names scp_command (the single ssh/scp posture authority) instead of the deleted bmc.Ssh.PutFile, and adds two witnesses proving the scp path carries the shared posture argv and never a second/forked one. All bmc_netboot_serve witnesses PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * WIP: srv4 pr * Accept #7121 deletion of .github/fleet-converge.sh (paper transport retired; FleetConvergeArtifact deregistered) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Regen ci.yml: drop fleet-converge.sh from auto-heal add-list (deregistered in #7121) The generated ci.yml auto-heal git-add list is derived from the artifact registry; #7121 removed FleetConvergeArtifact, so the regenerated list no longer names .github/fleet-converge.sh. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Regen ROADMAP.md: restore main's ts-ui-model row + drop trailing blank line (serializer drift) A bad merge had reverted main's belt-B roadmap row from roadmap_authority.dag; restored from main. Regenerating with a fresh seed also drops a trailing blank line the current markdown serializer no longer emits (main's committed copy is stale, kept green there by the auto-heal job). Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Merge main + regen artifacts with new-emitter seed (drop ROADMAP.md trailing line) Branch was behind main's v1_compiler_emit_rust.rs (Lane D #7098); merged main and rebuilt the seed. Emitted-Rust artifacts now match; ROADMAP.md re-regenerated without main's stale trailing blank line. Fixes generated_artifact_drift_gate. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: srv4 pr * Enroll srv4 witnesses in the eligibility census (864 -> 876) My PR added ~12 witness test entries; main's witness_entry_eligibility_census (#7111) fail-closes the floor when a witness entry has no census TSV row (panic at cli_run.rs:8508). Bumped the declared count 864->876, regenerated the census TSV + histogram, updated the count assertion. Sync + count witnesses green by execution; the previously-panicking argv_command_render entry is now present. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Merge main (#7110) + regen census TSV to match merged roster Kept branch current with main's witness/census churn; regenerated the eligibility census TSV+histogram so committed == emit(merged roster) (876 entries, emit's internal roster==count check green). Generated-artifact drift clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 23, 2026
…ift on PRs (#7126) * WIP: ci chores * WIP: ci chores * WIP: ci chores * CI self-heal: derived remedy classification + P0 fixed-point witness + roadmap row Splits every floor gate by remedy KIND (gunbc.ci_remedy): RemedyDerivation (pure projection of the tree — pipeline may chore-commit) vs RemedyJudgment (fail-closed default — detect + refuse, never fix). Derivation is grounded on existing authorities, not hand-listed: the GeneratedArtifactRegen channel heals exactly committed_generated_artifacts() (the registry the drift gate guards), walled by ci_remedy_witness_test with two RED controls. P0 (byte-idempotent regen) measured ALREADY-SATISFIED: main_wet yields zero diff on a clean tree, twice. Executable fixed-point leg added to generated_artifact_drift_test (reads real committed bytes; RED control perturbs). ROADMAP row ts-loop-selfheal regenerated from authority. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * Heal commit scope: stage only registry paths, not git add -A (review 41703) Address cursor review 41703 REQUEST_CHANGES on #7112: - ci_heal_shell_lines now stages EXACTLY committed_generated_artifact_paths() (git add over the registry, then git diff --cached --quiet) instead of git add -A, so an unattended push to main can never sweep incidental runner dirt — artifact-only by construction (DESIGN §5 no-silent-widen). - Add ci_heal_commit_push_shell_emit_scaffold (Disposition = Scaffold) + dissolution trigger for the hand-authored git transport, matching the sibling CI-shell scaffolds; dissolves when shell→intent models git commit/push as typed host effects. - New heal_commit_scope_is_artifact_only witness pins the scope (contains scoped git add + --cached, no git add -A) as a discriminating control. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * WIP: ci chores * WIP: ci chores * Regen ROADMAP.md for heal loop-safety note correction (review 41782) * WIP: ci chores * WIP: ci chores * WIP: ci chores * WIP: ci chores * Merge origin/main: absorb #7121 fleet-converge removal + #7090; reconcile regen-job extraction with main's GithubActionsCiRegenJob gate lane Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * Update heal witness for PR+push heal: pr_and_push guard, existence-guarded add, branch-aware push (5 discriminating controls) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * Review 41904: sync ts-loop-selfheal roadmap row to PR+push heal; add branch-head checkout witness control Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Resolve ci.yml merge conflict: regenerate from merged authority (dashboard auto-committed the conflicted marker) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * Heal telemetry: align heal step name + regen notice title to the branch-aware / own-regen-job wiring (review 41924) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * WIP: ci chores * Heal: restrict to pull_request only; main drift fails ci instead of auto-pushing main is protected by a ruleset requiring the 'ci' check, so a heal push to main is rejected (GH013). Operator-directed: don't auto-heal main — on main the ci job's own drift gate reds if regen ever drifts, which is correct since a change reaching main should already be green from its PR heal. ci_regen_heal_if drops the 'push' arm; witness heal_job_runs_on_pr_only reds if it returns. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 23, 2026
* CI floor endgame: per-batch claim pool, teardown fast-exit, selection-control shared index, discovery phase receipts, THE COST WALL, wet-lane re-homes (D1-D6) D1: batch-0's claim-backed gates share ONE pooled claim_batch child (tools.cheap_gate_pool — the union of the two concern authorities, ByDerivation; K sub-pools sized to the slot via cheap_gate_pool_max_claims_per_child, the section-9.1 cliff wall; child stays a separate process). New CheapClaimPoolGate runs it; layering/ extdeps gates became non-vacuous enrollment walls asserting chunk-transform totality (bare pool membership would be a tautology). Ingest's 4 mktemp overlay children stay — the genuine constraint, named in-row (ingest_pool_separation_note). D2: floor_terminal_fast_exit after receipts flush skips the 2.5-3.1min Drop walk of the ~16GB retained store (twice-confirmed). Exit code preserved (walk_exit_code, unit-pinned); truncated receipts still red (unwritable_receipt_base_reds_not_vanishes RED control). Terminal path only. D3: the selection-control step's 4m51s was three cold whole-pool index builds inside floor_skip_discovery_witness; the warmup case now rides resolve_entry_graph_shared (one shared build + the deliberately-cold Class-B control build, named). Step stays per-PR; ledger row added. D4: discovery pump phases land as typed rows in the floor resolve receipt (discovery_pump_wall_ms / roster_walk / diff_observe / frontier_attribution / shared_index_build / preresolve_calibration / runner_resolve + corpus resolve/eval serial sums). Lever-1 stays retired as priced; the fresh profile names the next mechanism before any spend. D5 THE COST WALL: per-batch wall budgets as data (gunbc.ci_spec.gunbc_ci_floor_batch_wall_budget_seconds, sum 53min under the 55min cap; per-batch never per-run — the plumbing-PR profile), read fail-closed at arm time, enforced as typed FLOOR-BATCH-OVER-BUDGET refusals (never a widen), recorded as typed receipt rows (target/floor-batch-wall-receipt.txt). Ruling reconciliation in the carrier note (budgets are admission/scheduling, never witness verdicts — the 5s-eval-law split; endgame brief operator is the sign-off). Raise requires an appended receipt note. RED control both directions proven by execution on the tighten-only injection fixture (budget_red_control_plan.dag). D6: bin_witness_wet_per_row_wall_budget_seconds=60; the two rows over it (floor_skip keystone 289s — also a per-PR duplicate of the selection-control step — and cross_shard_seam live-tree 183s) re-home to falsifier wet lane 5 as typed frontier rows (falsifier_rehomed_bin_wet_rows, reasons + dissolve_on, registry enrolled); 52 rows remain the per-PR smoke subset. Also: carries #7123's docs baseline (journey + attribution 9-9.2, now linked into the doc graph), appends attribution 9.3 with the <=30min post-merge prediction, retires completed lever rows, appends the cost-wall landing to the timeout-note bounce history, and heals ci.yml's stale fleet-converge.sh heal-line (its artifact and registration were deleted by #7121; the committed yml predated the regen). Proven by execution: executor battery 18/18; budget gate RED (witness PASSes, batch refusal fires, exit 1, OverBudget receipt row) and GREEN (exit 0, WithinBudget) on the fixture plan; ONE claim_batch child ran all 4 batch-0 gates with the ONE nested 12-claim pooled child (3 PASS + drift PASS post-regen); chunk-totality witnesses 4/4 incl. the RED discriminator; ci_floor_plan_witnesses PASS (membership 4, falsifier 5 lanes, budget coverage); whole-tree compile: zero new error identities vs main (main itself reds 2,647 pre-existing unlisted-import rows — the flagged non-goal); doc-reachability wall green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * Merge main + heal ROADMAP.md trailing-newline drift on the merged tree The PR's first floor run failed exactly one gate: generated_artifact_drift on ROADMAP.md — main's committed copy (post-#7118) carries a trailing blank line its own generator does not emit, so the merge tree drifted. Regenerated via main_wet on the merged authorities; ci.yml converged byte-identical with main's auto-heal of the fleet-converge line this branch had healed independently. Budget-coverage witness re-proven true on the merged tree (7 batches, 7 budget rows). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * D6 follow-through: FalsifierRehomedBinWet consumer cadence — the re-homed rows name their executing consumer (Phase 0(b)) The a9744d3 floor red was WITNESS ADMISSION REFUSAL cause=UnexecutedDeferredWitness count=2: the D6 re-home removed the two rows from bin_witness_wet_entries but the admission machinery had no concept of the new falsifier lane, so the excluded witnesses read as enrolled-with-zero-consumers — the invariant working as built. Wired through every reader: std.witness_admission gains the FalsifierRehomedBinWet cadence variant; ci_layer_roots re-exports it, flips floor_skip_discovery_witness_test.dag's exclusion row onto it (with its own reason/dissolve strings; the seam file stays BinWitnessWet — its algebra row still backs it), and adds the witness_exclusion_row_is_rehomed_bin_wet predicate (all 7 existing cadence matches gain the arm); v2.workflow.witness_admission routes consumer_for_explicit_rosters and the explicit-consumer manifest through falsifier_rehomed_bin_wet_entries and adds rehomed backing to witness_exclusion_explicit_roster_rows_consistent (new param); cli_run's source-scan classifier gains the RehomedBinWetRow head and the classification roster gains the name; the refusal message names the lane. Proven by execution: reconciliation witnesses 5/5 green incl. the NEW RED control (an unbacked FalsifierRehomedBinWet row reds); witness_admission_invariant_holds green with the two new rows (the keystone row classifies FalsifierRehomedBinWet and the manifest covers it); Rust unit test pins the RehomedBinWetRow head parse. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * Operator sign-off round: budget-note signature + follow-up rows, D2 comment scope fix, 9.3 process lesson + on-call notes - gunbc_ci_floor_batch_wall_budget_note gains the dated operator signature (briansrls 2026-07-23) affirming the admission/verdict reading — the declared human-signed exemption row the 2026-07-10 ruling requires — and the amended raise discipline (raising needs a dated operator-signed line naming run id + enrollment; tightening by ordinary receipt note; remedy is diagnose-or-signed-raise, never rerun), plus three named follow-up rows: the prelude coverage hole (~5min before batch-1 arms is outside every budget), identity-keyed budgets (index coupling rides the ComputationIdentity lane), and the K=16 union-RSS receipt (provisional until the pooled child's per-shard-peak-rss lands in a CI log; local proxy 1.82GB). - floor_terminal_fast_exit doc corrected: it is the common tail of run()'s walk path (all plan walks), not floor-only. - Attribution 9.3 gains the process lesson (every piece proven by execution except one full floor walk — the lane that redded, twice) and the on-call pre-positioning (batches 3/6 at 1.29x/1.45x headroom inside slot noise; first organic over-budget expected within days; diagnose-or-signed-raise, never pre-widen). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * Admission head-scan: word-boundary guard — a head substring inside a longer identifier is not a roster row Run 30033250697 panicked (exit 101, fail-closed as designed) because the raw substring scan matched bin_wet( inside the NEW predicate name witness_exclusion_row_is_rehomed_bin_wet(row: ...) — no entry: literal in the window, so the scanner stopped the line. The class fix: a head occurrence preceded by an identifier char is a longer name, skipped before parsing. Unit-pinned both ways (head_scan_ignores_longer_identifiers_containing_a_head; the live-file witness_admission_deferred_rows_have_consumers test now covers the exact CI path — it sat in the locally OOM-killed battery, which is how this escaped: the section-9.3 process lesson at unit grain). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * Census re-admission: regenerate witness_entry_eligibility_census for cheap_gate_pool_test (864 -> 865) Run 30035504886's exit-101 was #7127's census refusal working correctly: the floor's witness_execution_leg_label refuses any discovery entry with no census TSV row, and this branch's new dag/test/claim/ cheap_gate_pool_test.dag postdated the committed census. Regenerated via scripts/witness_entry_eligibility_census.sh (the emit transport itself refused at 865 roster vs 864 declared — fail-closed both ways), witness_entry_eligibility_census_entry_count bumped 864 -> 865, and the three .dag sync witnesses proven green by execution through claim_batch (declared-count exposed, carrier paths, tsv sync). The Rust sync test is CWD-fragile by construction (relative witness_layer_roots under cargo's package-dir cwd — the same pre-existing local-suite class as the two scope-test failures reproduced on pristine main); the .dag witnesses are the CI-executing consumers. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 * Heal census-count hand-pin drift: witness literal + note 876 -> 880 fbd55eb's floor red was the census_count witness (from main's #7127) — witness_entry_eligibility_census_count_holds hardcodes the entry count as a literal (== 876) SEPARATE from the data constant this branch already bumped to 880, so 880 == 876 was false. The tsv-sync witness could not catch it (it checks declared == TSV-rows, both statically 880). Verified the true count is 880, not an emit artifact: tree clean (zero untracked test files), independent git-tracked find of *_test.dag with test fn/data = 880, TSV data rows = 880, cheap_gate_pool_test present. Decomposition: main's committed 876 is STALE — main's live find is 879 (git ls-tree find on origin/main), undetected because affected-set selection skips this witness on PRs that do not touch its import closure; this plumbing PR's affected set is the first to run it against the drifted tree. So 880 = main's true 879 + this PR's cheap_gate_pool (+1), and updating the literal HEALS main's 3-file latent census drift in passing. The count lives in four hand-synced copies (this literal, its note, witness_entry_eligibility_census_entry_count, the committed TSV) — a §3 parallel-representation main's carrier keeps in sync by hand; restructure is out of this PR's scope, noted in the witness note. Proven by execution: all census witnesses across census_test / classification_test / tsv_sync_test green through claim_batch (count_holds, the six classification rows incl. bulk-pending default for the new entry, tsv sync). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2Rc3TWb8FFexdVQDNbb44 --------- Co-authored-by: Claude <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Jul 25, 2026
…ipt shape declared Migrated: ts-loop-pattern (the named loop + the ask), ts-loop-selfheal (the structural exit — both operator rulings preserved VERBATIM as dated updates, mechanism notes preserved with the #7121 guard), ts-loop-buildretry (the widening-arm masking row), ts-loop-falsifier (the 29-red narrative with its exit condition as first_slice). Shape ruling applied (operator-signed this session for ts-pr-*; extended here by the same rule): one-fact receipt rows do NOT migrate — a ticket around a narrative one-liner is nine empty fields of costume. Stays prose by declared shape: ts-loop-fmt/docsonly/prepush/stale-roster (closed incident receipts), ts-loop-deploy (pointer receipt). The parent ticket's update row declares this so the frontier count reads honestly. ROADMAP.md regenerated (main_wet); page keystone (brief budget over the new briefs), emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 25, 2026
…(tranche 1: dispatch-lifecycle cluster) (#7240) * W2-bulk tranche 1: the dispatch-lifecycle cluster migrates onto the ticket contract (6 rows, 161 -> 155 legacy) First tranche of the bulk migration (task queued behind the composition session; the five exemplars are the contract, operator-signed on the rendered archetype). Rows: ts-dispatch-lifecycle, ts-dispatch-verdict, ts-dispatch-rework (ticket_row — unsized discipline rows), ts-wf-shape (ticket_row), ts-wf-belt-refusals, ts-wf-progress (ticket_wi — sized, sizing preserved). Honesty rules applied, and they are the tranche's real content: - fields carry ONLY what the prose stated; a field the prose never filled is an honest empty (the renderer omits it), never a fabrication; - dates come from the prose itself (authored_on only where the row named one; last_verified_on stays empty — migration is not verification); - history moves to the updates axis WITH its dates (ts-wf-shape's #7113 reconciliation-seam note preserved as a dated update, marked since-landed, rather than deleted or left masquerading as current); - Accept lines map to their honest fields (belt-refusals' became red_control; progress's became first_slice), each marked in the migration update; - ambiguous rows stay on the counted legacy frontier rather than guessed — none in this cluster needed it. ROADMAP.md regenerated through the generated-artifact gate (main_wet); the md projects headline — brief per the signed W2 contract (full fields render on the served page; the authority carries everything). Receipts by execution: roadmap_page_keystone (including the 100-word brief-budget census over the six new briefs), roadmap_emit, roadmap_authority all green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 2: the loop cluster (4 rows, 155 -> 151 legacy); receipt shape declared Migrated: ts-loop-pattern (the named loop + the ask), ts-loop-selfheal (the structural exit — both operator rulings preserved VERBATIM as dated updates, mechanism notes preserved with the #7121 guard), ts-loop-buildretry (the widening-arm masking row), ts-loop-falsifier (the 29-red narrative with its exit condition as first_slice). Shape ruling applied (operator-signed this session for ts-pr-*; extended here by the same rule): one-fact receipt rows do NOT migrate — a ticket around a narrative one-liner is nine empty fields of costume. Stays prose by declared shape: ts-loop-fmt/docsonly/prepush/stale-roster (closed incident receipts), ts-loop-deploy (pointer receipt). The parent ticket's update row declares this so the frontier count reads honestly. ROADMAP.md regenerated (main_wet); page keystone (brief budget over the new briefs), emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 3: the observation family (6 rows, 151 -> 145 legacy) ts-obs-anchor (the five laws; reference implementation studied by execution), ts-obs-model (P0 carriers), ts-obs-ci-renderer (P1, the pain point), ts-obs-tty (P2), ts-obs-census-wall (P3), ts-observation-contract (the equivalence bar). Accept lines and REDs mapped to red_control / first_slice, marked per row. The family's branch state recorded honestly: each row carries a dated update — verified this session — that the lane's implementation lives on #7216's unmerged branch (supersedes #7162) and lands at its merge; last_verified_on set only on those rows, because that verification actually happened. The composition PR's altitude convergence row already watches the same merge. The brief-budget census fired mid-tranche (ts-obs-anchor=101, located node + count exactly as designed) and the brief was trimmed one word — the wall working, recorded because a census that never fires is the one to distrust. ROADMAP.md regenerated; page keystone, emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk: the re-sweep hold becomes a typed, counted state (management sharpening 1) The 13 ts-pr-* children move from a prose flag to w2_bulk_resweep_held — typed rows, counted, with ts-pr-audit's sweep as the declared dissolve-on — so the legacy frontier decomposes honestly into not-yet-migrated vs held-for-disposition, and the operator's re-sweep has a mechanical worklist. ts-pr-audit itself migrates to a ticket (its sweep instruction is the first_slice; the sweep is the handback — each child's disposition is the operator's call). The lighter one-fact row species is deliberately NOT minted (management sharpening 2, second-consumer discipline): the sweep will disposition most of these away, and the hold makes deferring that call cheap. Witnesses by execution: every held id resolves to a live AuthoredLine (a held id whose row was migrated, superseded, or deleted reds carrying the id — the hold outlived its state); planted REDs on a nonexistent id AND on an already-migrated ticket id. ROADMAP.md regenerated; page/emit/authority green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 4: the lens family (6 rows, 145 -> 139 legacy) ts-lens-endgame (the v2-door dependency named precisely, milestones preserved), ts-lens-door (M-L1; the Accept T2->T5 block became red_control, the three-compile-sites scope review became current_state), ts-lens-treewide (M-L2; the W3 typed-module-store convergence preserved), ts-lens- contract-truth (M-L3; the twice-verified counted state — 55 ids / 46 contracts / 9 missing including live Determinism — lands as current_state with its verification date as last_verified_on, the one tranche row where that field is honestly non-empty from the prose itself), ts-lens- complexity-scope (M-L4; the red-by-design blockers and the space-complexity re-home rider preserved), ts-lens-terminal (the 2c fan-in node). ROADMAP.md regenerated; page keystone (brief budget over six new briefs), emit, authority, and the re-sweep hold witness green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 5: the group-taxonomy family (5 rows, 139 -> 134 legacy) ts-group-u (the membership taxonomy — positional/derived/frontier/nickname with the mint->frontier->query pipeline), ts-group-family (the #7069 re-key; the 744-rows-Derived sequencing fact preserved as an update), ts-group-census (the swept roster ledger; landed items in the brief, storage-grain residue as current_state), ts-group-dissolve-typed (the OnRoadmapNode coupling; its lens became red_control), ts-group- partition-drift (the incident receipt; both drift incidents in the brief, the regen two-generation side receipt preserved dated). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 6: the host-state family (5 rows, 134 -> 129 legacy) ts-host-state (the parent gap — both 2026-07-22 tail incidents as displaced_cost, the srv4 live-fire receipts as current_state, the 0-to-3 dispatch brief as first_slice with the operator's claims-intersection ruling, TakeoverRuling as red_control), ts-host-frontier (the Derived|OwnedMember|ForeignWithContract classification), ts-host-antientropy (the host falsifier), ts-host-cdtransport (deploy from content, not the runner workspace), ts-host-genlease (StaleDesiredState + subtree lease; the 21:49 overlap receipt as displaced_cost). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 7: the native family (5 rows, 129 -> 124 legacy) ts-native-bulk (the arc; operator re-pricing + sizing preserved dated), ts-native-census (derived-denominator discipline made structural: stale-on-arrival counts kept ONLY as dated snapshots in current_state, the deleted-drifting-copies history preserved), ts-native-seams (the measurement-settled crate grain), ts-native-flip (the three-section PR), ts-native-flip-revert (the working-as-designed receipt; the twice-corrected re-flip gate as current_state; the one-authority rule — the carrier's dissolve_on strings, never a roadmap paraphrase — lands as handback, which is exactly what that clause is). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 8: the ci + access clusters (7 rows, 124 -> 117 legacy) ts-ci-definition (the three-clause functionality bar; today's failures as current_state), ts-ci-claimed (the do-not-re-plan ledger; sequencing rule preserved — a fast CI that lies is worse than a slow one), ts-ci-ergonomics (the priced touchpoints; the inventory as first_slice), ts-ci-options (the three merge-gate options; the pick is the operator's — handback), ts-access-model (the transport-accident gap; grants shape), ts-access- orgtailnet (operator-owned creation — handback), ts-access-dispatch-auth (go-live precondition; do-NOT-drop-the-front as handback). ROADMAP.md regenerated; page/emit/authority green by execution. Rider: #7239 (the flips PR) merged on its green floor this tranche — the gutter split and signed PROVISIONAL marks are on main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 9: misc batch A (5 rows, 117 -> 112 legacy) ts-authority-converge (the sprint entry point; the parity-window carrier contradiction as current_state, the option-b gating ruling dated), ts-concat-class (the 2,798-site census with its atom-never-composition ruling), ts-deploy-tail (the DONE incident — its four dated receipt waves, including the credential-leak find and #7086's construction fix, become the updates thread the blob never had), ts-doc-anchor (carrier-anchored sessions), ts-effects-providers (the conflated-counts honesty catch as current_state; the boundary-enforcement clause as red_control). ts-branches stays: a closed all-dispositioned receipt, not a blob. ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 10: misc batch B — the interpreter-endgame cluster (6 rows, 112 -> 106 legacy) ts-evaluator-complete (the two-typed-exits bar; refusal-never-fallback), ts-executor-seams (critical slice, hollowing fenced to out_of_scope with its stale-on-arrival count rule), ts-falsifier-nfr (DONE — root-cause and landed rows as the updates thread; the NEW-find clause as red_control), ts-floor-memory (the ceiling pin; confirm-caps as first_slice), ts-interp-delete (the delete bar; the missing interpreter-file-only milestone note as current_state), ts-interp-endgame (the three finish lines named apart; the counted-fourth-role enrollment as first_slice). ts-intake-discipline stays: a one-sentence standing rule, not a blob. ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 11: misc batch C (5 rows, 106 -> 101 legacy) ts-lying-stamp (the recurrence class; the 5th occurrence dated; the decide-once as first_slice AND handback — it is a ruling), ts-material-ci (the kernel row; the corrected sequencing as current_state; the different-denominators watch-flag as red_control — land the fresh receipt BEFORE repricing), ts-merge-gate (the re-evidence), ts-quarantine (the link-grain dress rehearsal; the deletion-receipt clause as red_control), ts-queue (ops hygiene; the zombie cancel as first_slice). Stay by shape: ts-modeling-pass (a per-PR checklist rule), ts-overnight (done accounting receipt). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 12: the final ts batch (11 rows, 101 -> 90 legacy) — the ts-* sheet is done ts-review-sweep (the operator checklist; falsifier-dark prioritization as first_slice), ts-seed-interim (the 8-percent-in-33h receipt as displaced_cost, counts dated by the wave snapshot), ts-seed-ratchet (SeedGrowthJustification as the frontier pattern on the seed itself), ts-seed-data-out (the landed roster move; the live dual-representation mirror as current_state), ts-seed-intake (the thin-transport policy), ts-standing-intent (the ask-once row — with the state-response census recorded as its third idling consumer), ts-store-econ (the ForciblySerial narrow point: three lanes converge, said out loud in displaced_cost; the review-hardened RED battery preserved whole), ts-unconsumed (the sweep), ts-wave-reds (DONE — the three-collision heal chain as dated updates, including the opposite-way drift lesson), ts-wf-lens-walls (the roadmap lens trio), ts-zero-hand (the terminal ruling; the third carrier contradiction as current_state, the never-delay sequencing as out_of_scope). Stay by shape: ts-roadmap-drift (done receipt), ts-sustainable-close (one-sentence rule). With this tranche every ts-* row is dispositioned: migrated, typed-held, or declared by shape. ROADMAP.md regenerated; page/emit/authority + the hold witness green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 13: lane 1 — the CI-floor lane (16 rows) + carrier-preserving constructors New constructors first, because the wall fired before the work: ticket_doc / ticket_pp — the exact siblings authored_doc/authored_pp are to authored(). Without them, migrating a pointer-carrying row through ticket_row would silently DROP its carriers (the doc-graph's inbound links) — content loss the migration's own rules forbid. The doc-graph orphan witness runs green over the migrated lane as the executing proof the pointers survived. Migrated: 1-nightly (done, audit-dated) · 1-double-resolve · 1-sccache-falsegreens (the cache-lies live-repro residue as current_state) · 1-wallclock-measured (void profile numbers said so, dated) · 1-placement-authority · 1-sched-resource-aware (the re-base ruling; tracker link preserved inline) · 1-affected-set-defork(doc) · 1-budget-tree(pp, both pointers kept) · 1-builtin-registry(pp) · 1-floor-right-things(doc) · 1-g1-placement(doc) · 1-g2-runner (the modeled-envelope Accept as red_control) · 1-g3-caps · 1-g4-dispatch(pp) · 1-g5-rust-selection(doc) · 1-resolver-pathology-b(wi, sizing preserved). NEW SHAPE RULE, applied and declared: an operator-SIGNED row does not get edited under its signature — 1-bics-design and 1-resolver-pathology-a stay as attested receipts (the signoff attests the node as signed; migrating the line under it would change what was signed). ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 14: lane 3 — the audit lane (5 rows) 3-audit-affected-set (done; the three-clause discharge with its live discrimination receipt), 3-audit-artifact-freshness (green-on-branch is not green-on-main; the operator ask preserved verbatim in the migration update), 3-audit-cache-honesty, 3-enforcement-intent (the landed inventory re-based; the state-response census recorded as its third idling consumer, closing the loop management asked to watch), 3-cost-risk-benefit (the 2026-07-12 working-session capture — the argmax framing, the deferred-and-detected invariant, the wet-is-sacred inversion, the missing-pieces list highlighted not papered over; carriers preserved via ticket_pp). 3-audit-gate-inventory stays: operator-signed attested receipt. ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix the authority witness's stale headline pin (the tranche-14 red, caught and owned) roadmap_authority_witnesses redded on tranche 14 — witness_audit_lane_present pinned the affected-set headline WITH its inline audit date, which the migration moved to a dated update per the convention every tranche has applied. The pin moves with the authority (the slice-2 shape: the witness reds on the change by design, then re-attests). The red was committed before it was seen — the battery ran in the same chained command as the commit; this fix commit is the stopped-line analysis, and the chain is split from here on so a red blocks the commit it belongs to. Forward note for lane 2: witness_fabric_design_rule pins lane-2 row strings ("stateless frontend MVP on fabric" et al) — those pins update alongside their rows' migration, deliberately, not as surprises. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 15: lanes 5 and 6 (12 rows) Lane 5: 5-cargo-green-continuous (done — resolved-by-construction, the unwritable failure mode stated), 5-regen-cutover (done — same discharge class, migrated for consistency with 1-nightly/3-audit-affected-set), 5-defork (the shadowed-shell.Which incident as displaced_cost), 5-dissolve- patches (the 7→25 regrowth re-measure dated), 5-emitted-crate-partition, 5-root-b, 5-seed-honesty (the fail-open-by-construction confession preserved whole; FLAGs A–D as handback), 5-test-migration (wi; the operator's scrutinize-first ruling as handback; the typed-retirement-path as first_slice), 5-v1coupled (one-liner, migrated for its deferral field). Lane 6: 6-shell-emission(doc), 6-shell-intent-phase1(doc — sign-off PENDING as current_state, the flip instruction as handback), 6-shell-slice2(doc — same pattern, the FLAG discharge dates kept). Stay signed: 6-shell-slice0, 6-shell-slice1 (operator-signed attested). ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution BEFORE this commit (chain split per the tranche-14 lesson). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Record the write-interface assessment (operator question, mid-bulk) The migration is not the interface's right first consumer (editorial half irreducible; mechanical half already execution-verified per tranche). The recurring consumer is typed TicketUpdate APPEND — belt verdicts, session write-backs, dissolution firings — with the updates axis as the first API. Assessment as a data row beside the constructors so it is not re-derived. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 16: lane 2 batch 1 — floor-throughput + fabric-allocation (9 rows) 2-compile-clean-serial (lever a landed, the 37.6x receipt kept; lever c residue as current_state), 2-compile-clean-shard-a (done, the OWNED wrapper preserved — owner string survives migration), 2-compile-clean-shard-b (the full Accept checklist as red_control with its planted RED), 2-admission- model (the operator's 1-core-3GiB directive dated; derive-never-hand-set as red_control), 2-cap-deconflation (three facts in three mechanisms; the no-conflated-survivor receipt as first_slice), 2-burstlease (non-death before utilization), 2-strictlease (four nouns no scheduler; the read-back-never-asserted Accept), 2-provider-offer (the dormant design-break probe with its four witnesses), 2-shape-labels (runs-on as projection; the later-architecture fence as out_of_scope). ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 17: lane 2 batch 2 — merge-admission + converge spine (9 rows) 2-merge-admission(pp — HELD as current_state, the green-on-branch evidence as displaced_cost), 2-cd-transport (done, owned wrapper preserved — the placement-is-not-proof premise), 2-converge-reland (the landed inventory in the brief, the full T4 accept as red_control, the ReadAbsent bind note as current_state), 2-fleet-hardening (the ungated-return debt), 2-host-admission (two modes; the post-patch-values RED and the counters-did-NOT-increase receipt), 2-live-read-seam (the no-mutation fence; first-slice-does-not-close preserved), 2-live-read-runner-memory (done, owned; stop-and-return as handback), 2-periodic-actuation (a timer existing is not acceptance), 2-privilege-model (done, owned; typed refusal BEFORE mutation). ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 18: lane 2 batch 3 — the SCM cluster + fabric services (10 rows) The scm family (infra-econ with its cited GitLab 10-K carriers · node-merge's keyed-diff-over-identity core · publication-ladder with the pick-two churn-blinding fence as out_of_scope · remote-realization's protection-IS-billing · visibility-stage0, your 2026-07-25 plan, its T3 Accept as red_control), 2-stateless-frontend (milestone A landed, B + the unmergedPages cutover as current_state), 2-emit-partition (owned; the four leftovers a-d; the atom-never-composition wall as red_control), 2-p3, 2-session-slice (the humming apply-rule), 2-service-receipt (the T4 read-back Accept with its three NotConverged REDs). with_plan and owned wrappers preserved throughout. ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 19: lane 2 complete — placement, host-effect, srv3/os-install (15 rows) 2-ci-two-tier-placement(doc — the 5-second rule; fail-closed admission), 2-test-decomposition-wcf (with_plan; the W/C/F cut with attribute-before- decompose), 2-host-effect-phases(doc), 2-keyed-delta-fold (accepts a+b met; the (c) proof-by-consumption fork as first_slice — re-point or wire, deliberately), 2-oom-consumer(doc — never EAGAIN-shaped), 2-runner- allocation-v0 (the operational milestone; its full T4 Accept and RED battery; not-complete-while-any-hand-edit preserved), 2-temporal-effect- spine-a (done, owned), 2-resource-namespace-upsert-a (done), 2-os-install-deduction-a (done, owned), 2-srv3-install-reconcile-a (done), 2-srv3-osinstalled(doc), 2-install-media-generic-layer, 2-nbd-serve-held- session-lease (done; the do-not-mint-a-parallel-lease-vocabulary rule), 2-srv3-boot-action-diagnostic, 2-os-install-generic-naming. Near-miss, owned: the deduction-a owner string was fabricated from the sibling's pattern where my read had truncated it — caught before commit by diffing the removed lines, restored to the true value (zesty-bat-588, the same dispatch batch). The rule stands: a field the source states is copied, never patterned. ROADMAP.md regenerated; battery green BEFORE commit (incl. hold witness). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 20: ts-ui-model — the sheet's largest blob, and the migratable frontier CLOSES The 6,223-char verdict specimen decomposed: the five phases + D1-D5 as the brief (budget census fired at 123 words pre-commit — the split chain working — trimmed under the bar), the candidate AcceptedWithResidue verdict as current_state with MERGE IS NOT DONE preserved, the full receipt battery as red_control, the named residues and arcs as out_of_scope, the verdict itself as handback (the operator's three questions set the status). One honest time-axis correction, dated rather than silently rewritten: the P3 flex-container residue ("deferred, unverifiable without a browser") has since been DISCHARGED — the remodel round-5 head line and #7234's RoadmapRow archetype are its discharge, with the operator as the browser. With this row every AuthoredLine on the sheet is dispositioned: MIGRATED (the ticket corpus), TYPED-HELD (13, the re-sweep worklist, witnessed), DECLARED BY SHAPE (closed receipts + one-sentence rules), or OPERATOR-SIGNED (5, never edited under a signature). ROADMAP.md regenerated; full battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian <briansrls@MacBook-Pro.local> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Single PR off
main. Brief steps 0–3: P0 and P1 (core + P1a) land here; P1b/P2/P3 are counted AcceptedWithResidue, registered as the plan rowgunbc.plans.host_convergence_circuit_residue.P0 — the paper transport is deleted
fleet_converge_emit.dag(bash-emission wrappers, no external consumer),.github/fleet-converge.sh,FleetConvergeArtifact(type + registry + drift arms), the emit test + its enrollment. Converge actuates only viahost_effect_applytyped transports.dag/gunbc/fleet_converge_emitfromrealization_vocabulary_containment→ nothing underfleet_converge*may emitShellProgramvocab (a stray import reds the containment lens).EmitArtifactThenThinRuntransport stays — general infra (srv3-install / ci_deploy / nbd_proxy).P1 core — PerSlotMemoryCap is one
membership_reconciledag/gunbc/host_axis_caps.dag— the repo's first non-degenerate reconcile (desired vs a real observed set, notobserved=[]). One spine instantiation with a(key_of, key_eq, value_eq, ownership_of)bundle; ownership derived from the drop-in path (never stored, §5); interference domain = the drop-in directory, realized through the same spine (foreign occupant →MemberTeardownRefused, R5, no effect arm, never deleted).4 hermetic receipts, each with a RED control, all GREEN (auto-discovered CI corpus consumer):
.d→ ApplyRefused, zero teardowns (RED: an owned removed file does teardown)[Service]/property/bytes derived, no hand strings (RED: different bytes differ)P1a — interpreter closed + realize executes for real
interpret_converge_knob:PerSlotMemoryCap → KnobEffect(derived script from the singlehost_axis_capsauthority). No longer falsely refuses caps.realize_converge_in_process: the fabricatedexit_code: 0is gone — runs the script viarun_shell_transport(LocalShell) and grounds on the real exit; nonzero → typedNotConvergedrefusal. This was a latent §5 fail-open, dead only because everything refused.KnobUnimplemented), sointerpret_host_convergerefuses the whole host beforerealizeshells out — no CI witness executes.Verified green by execution (
gunbc run --claim-run)AcceptedWithResidue (counted — full text in the registered plan row)
gunbc converge --host srv1still refuses whole-host (correct fail-closed on the sibling knobs); the only caps-scoped route is read-back. Needs a mode-gated caps-only apply route (coupled to Codex/graph viz test helpers #2)..ddir; unreadable → typed refusal, never empty; callable standalone for cadence reuse).HostMemoryPopulation) + the enrollment wall (installer refuses on a host absent fromfleet_intent).HostAxisBundle, cited-extdeps interference via effect-grants ⊑,TakeoverRulingas the only signed foreign-teardown path,UnmodeledOccupantrefusal; swap-device + reclaim-timer as declared frontier axis rows).Hard rule honored throughout: a failure arm refuses, never widens — no observe-all, no assume-owned, no auto-disable, no fabricated success.
🤖 Generated with Claude Code