Repository navigation
Conversation
…hit keys, arm from loader closure The three post-merge retention defects from the ci-two-tier-placement-redesign §5 review (routed to the #7129 worker) plus the two §7 acceptance controls. Sequenced first: the falsifier cannot go green — and no downstream placement row can cite true retention receipts — until these hold. D0.1 — compile-clean aggregate memo unpin. The whole-tree gate resolved through resolved_graph_from_sources_with_index, pinning the aggregate ResolvedGraph (hence every TypedModule) in resolved_graph_memo for the process lifetime — a large slice of the measured 9.2GB resident floor. Thread a ResolvedGraphMemoShare::{Memoize,Ephemeral} flag: the gate resolves Ephemeral (no aggregate pin); per-entry discovery keeps memoizing. The per-module typed-cache warming that IS the gate's purpose is unaffected. D0.2 — prewarm all-hit registration. try_reconcile_all_cache_hits assembled and returned on all-hit WITHOUT index_record_schedule_module, so a prewarmed run armed retention referencing nothing (completion reported evictions while removing nothing). Record each confirmed hit in the probe, same key forms as the slow path. D0.3 — arm from the loader's exact closure (the #6985 Class-B root, third appearance). Arming used selection_adjacency; the discovery loader load_sources_for_entry_with_pool reaches wider via qualified-projection references from import-bearing files, so those modules were re-cached after eviction and never re-evicted or counted — an invisible resident leak. Arm from the loader itself (not a re-derived BFS that could become a fourth divergence); cost-neutral because the loader memoizes into entry_closure_sources, which discovery reuses. Removed the now-dead selection_closure_live_paths_with_facts. D0.4 — the two §7 acceptance controls. index_schedule_entry_completed dropped the resolved-graph pin unconditionally, so the eviction-disabled retain-all baseline understated peak retention; gate it on evict_enabled. The E2E control armed BEFORE prewarming (the order-blindness that let D0.2 pass green), so it never exercised the all-hit probe; restructure to prewarm -> clear graph memo -> arm -> re-resolve through the probe, and add a real-index retain-all RED. Verified green by execution: 7/7 schedule_retention tests, incl. the two restructured REDs (E2E arm-after-prewarm; real-index retain-all). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
…l-closed admission The placement-axis half of ci-two-tier-placement-redesign.md D3, buildable ahead of the D2 srv warm-cost probe. Placement is modeled as DATA (Placement = PrTier | Gauntlet), never per-site prose, with a FAIL-CLOSED admission law: a check is admissible as PrTier only with (a) a measured warm-cost receipt within the fast-lane budget AND (b) a hermetic/ephemeral classification; unmeasured or unclassified => inadmissible as PrTier, so its only valid placement is Gauntlet. No row rides the fast path by taste. The 5s threshold is REUSED from the single fast-lane authority (gunbc_ci_fast_lane_eval_budget_ms, v2.workflow.ci_floor_plan) — never a second 5s definition (DESIGN §3). Verified green by execution (claim_batch, 4 witnesses): - Gauntlet always admissible - a within-budget hermetic PrTier admissible - RED control: an over-budget (6000ms > 5s) PrTier is refused - RED control: an unclassified PrTier is refused The controls pin the threshold discriminatingly (1600ms admits, 6000ms refuses) and the classification gate (Hermetic admits, Unclassified refuses). Deferred to PR-1 (D2-gated): filling the roster of real checks with measured receipts (flipping rows to PrTier as srv warm-cost lands), wiring the law onto the live check rows, and the Gauntlet workflow split (D3b). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
… authority
Per ci-two-tier-placement-redesign.md §11. Introduces DiffBaseline
(MergeTarget | PushParent | OperatorOverride{ref}) as the single authority for
"which git ref a diff/merge selects against", grounded on the extdeps.git atoms
(GitRef, git_remote_ref_parts). resolve_diff_baseline is a pure, fail-closed fold
over injected env values — a PushParent with no parent ref REFUSES rather than
fabricating a ref.
Live consequence fixed (site 1, floor selection): a stacked PR now selects
against its real merge target (origin/$GITHUB_BASE_REF), not origin/main.
DiffPolicy.base becomes a DiffBaseline; floor_diff_observe.floor_resolved_base
resolves it at eval time from GITHUB_BASE_REF, fail-closed to UnifiedDiffFail
(the floor widens to the full corpus) on an unresolvable base — never a silent
wrong selection.
Fork dissolution (no behavior change) — sites 2/3/4 re-ground the same literal
onto the authority: merge_admission_produce (merges into main),
roadmap_dispatch_actuator (branches from main), ci_workflow Push/PR triggers
(main). The ci_merge_base_ref alias and the dead ci_merge_base_diff_range are
deleted.
Also carries the parked miscite fix (rust_tests_removed_disposition ->
commit_gate_rust_suite_removed_disposition) in DESIGN.md / design_document.dag /
ci_spec.dag, per plan §3.3.
Verified by execution: ci_diff_baseline_witness_test (6/6, incl. the
discriminating stacked-PR pair and the PushParent-refuses fail-closed control);
ci_spec_witnesses (fetch renders "origin $GITHUB_BASE_REF"; single authority);
roadmap_dispatch_actuator_witnesses. ci.yml + DESIGN.md regenerated via main_wet
(drift clean; the two floor/regen fetch lines now expand $GITHUB_BASE_REF).
floor_diff_observe_witness_test runs green in the floor's wet mode; its eval-time
env reads are unmockable under claim_batch strict-hermetic, a PRE-EXISTING
harness limitation confirmed by a clean-tree stash run of the same witness (this
change adds no new hermetic red).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
Operator ruling: PR-0/PR-1 split dissolved; #7162 absorbs all remaining pieces. Build order: clamps first (self-greening — the floor reads CiSpec from the PR tree). D4's gate restated for the growing PR: a branch falsifier run is the deletion receipt (main-cadence green impossible pre-merge by construction); one green cold run post-D0 triples as D0 acceptance, D4 receipt, and cold-side probe timings. D5's Env.Get mock is its own named part, finished in-PR. Probe: worker-driven workflow_dispatch on fleet slots, serial, >=2 hosts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
P0 of the progress-and-observation lane (docs/plans/progress-observation-design.md, operator-signed 2026-07-23; §6b/§6c doctrine from #7169 folded in). Model only — no renderer, no emit site touched. ObservationEvent = subject (a typed containment path: run ⊃ batch ⊃ entry ⊃ module ⊃ phase) × Begin | Step{k,n} | Concluded{outcome} × measured facts. Outcomes are a closed sum with Refused DISTINCT from Failed — the reference implementation conflates them, which is how a deliberate refusal reads as a crash. Grounded on existing authorities rather than minted: - ancestry reuses std.effect_grant.path_is_prefix (one prefix relation, not a second walk) - over-budget arithmetic calls std.temporal_effect.stall_budget_verdict - change kind projects from std.change.KeyedDiffHunk — no second added/modified/removed enum - glyphs extend std.symbols + extdeps.render.glyphs rows (the one table), never a fork - module_path/source_path carry std's existing representation (std.decl_ref's), with convergence to QualifiedName/SourceRef declared, not assumed Derived, never hand-set: AttentionLevel from a supplied basis (the signed clamp constants — no threshold is invented in this module); BlockedOn from SchedulerHold, which is held in lockstep with the seed governor's HoldReason by execution; T from the heartbeat period the seed actually sleeps, declared a Scaffold with the measured quiet-time distribution as its dissolve-on. Construction over validation: the no-op sum is closed (docs-policy | uncovered | no-decls-touched | generated-artifact | departed-path), so a bare unlabelled "nothing" is unwritable rather than censused after the fact; uncovered derives a visible nudge, departed-path is typed as a widen and not a no-op. Green by execution, with discriminating REDs proven by perturbation: - 28 model conjuncts + 6 lockstep conjuncts PASS - orphaned law row (enforced_by names a missing declaration) → RED - Refused/Failed collapsed onto one glyph → RED (both distinctness and collapse laws) - glyph-table row perturbed → presentation moves → RED (single authority, by execution) Compile-clean attributed: the closure's 47 errors are pre-existing in std/measure.dag (46) and std/effect_grant.dag (1) — identical counts compiling those entries alone; zero attributable to this change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Addresses the blocking finding on the three coproduct predicates, taking its stronger alternative (dissolve into the canonical surface) rather than only its weaker one (add a disposition receipt). The finding was right about the real defect: observation_class_is_intrinsic_anomaly was a second hand-written table beside observation_presentation, and a witness asserted the two agreed. That witness was validation standing exactly where construction was available — it conceded the tables could disagree and promised to notice. Fix: ObservationDensity (RoutineCollapsible | SummaryAlwaysShown | AnomalyExpanded) is now the one table. collapsible, expands_fully and intrinsic-anomaly are all derived projections of it, so disagreement is unwritable rather than detected. The three display states stay distinct — the run summary is neither routine nor an anomaly, which a single boolean would have forced it to borrow. Disposition receipts added for the remaining structural readers, matching the cited materialization_ladder pattern: outcome/class, subject/grain/hold, and selection no-op. Each states why it is Terminal and names its discriminating corpus rather than asserting terminality. Witness roles now separated and both proven by execution: - w_density_is_the_single_display_authority — the content check; reds when a class's density changes (verified: ClassRefused → RoutineCollapsible reds it, and reds ONLY it, since the projections cannot disagree) - w_presentation_projects_density_rather_than_restating_it plus the two collapse witnesses — construction guards; red when the presentation stops projecting density (verified: hardcoding collapsible: true reds all three) Full suite green: 30 model conjuncts, 6 lockstep conjuncts. Compile-clean unchanged — 47 errors, all pre-existing in std/measure.dag (46) and std/effect_grant.dag (1), zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The finding is correct and the hard-blocker applies: avg10_centi was a percentage magnitude with a scale carried on bare Nat, and the note beside it self-justified the conflation rather than tracking it. Fix consumes an EXISTING carrier rather than minting one, which the corpus had already asked for in advance. std.measure.basis_point_dissolve_on warns: "else a third dimensionless-ratio use-case mints a third nickname" — this module is exactly that third use-case, so minting PerMille or a Percentage quantity would have walked into the failure the row names. BasisPoint's own note declares its semantic axis as utilization ratios, which is what a PSI stall share is. Resolution is exact rather than truncated: the governor reads one decimal of a percentage and a basis point is a hundredth of a percentage point, so 37.5 percent is 3750 with nothing lost. Percent (Dimensionless, One) would have truncated it. Note rewritten to state the grounding and the deliberate non-mint, replacing the self-justification. When the Ratio<Scale> unification that dissolve-on calls for lands, this field follows Percent and BasisPoint onto it with no change of meaning. Suite green: 31 model conjuncts, 6 lockstep conjuncts. Compile-clean unchanged — 47 pre-existing errors in std/measure.dag (46) and std/effect_grant.dag (1), zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…t list Per ci-two-tier-placement-redesign.md §9.8 (operator 2026-07-24). Replaces the hand-set gunbc_ci_floor_batch_wall_budget_seconds list — a scalar wall budget that conflated workload size (diff-proportional selection), host speed, and per-unit cost creep — with a per-batch clamp computed at run time: clamp_ms = overhead_seconds*1000 + runtime_unit_count * per_unit_ms. The load-bearing row is the discovery witness batch (index 2): 300s + 1000ms per witness, so a full corpus of ~2316 witnesses clamps at ~44min (under the 55-min step cap, with headroom over the observed 1344-1629s walls) while a runaway reds proportionally, instead of the fixed 1320s that redded legitimate hub-file PRs. Fixed-count gate batches carry rate 0 at their measured basis; index 3 (wet corpora) stays a declared fixed overhead pending the D2 probe's wet-per-witness rate. Authority: gunbc.ci_spec FloorBatchClamp + gunbc_ci_floor_batch_clamp_params (index-aligned to the 7 batches; the cover-schedule witness pins the alignment) + gunbc_ci_floor_batch_clamp_note (carries the raise discipline from the kept static-era note). The 5s per-WITNESS max is unchanged — still the single gunbc_ci_fast_lane_eval_budget_ms authority, never redefined here. claim_executor reads the two index-aligned param lists fail-closed, derives the per-batch unit count from batch_results (corpus_witnesses for discovery aggregates, 1 per gate row — the runtime datum the static list ignored), computes the clamp at enforcement, and refuses over-clamp as a typed FLOOR-BATCH-OVER-BUDGET (never a widen). The GUNBC_FLOOR_BATCH_BUDGET_TIGHTEN_MS RED-control hook now lowers the COMPUTED clamp. The receipt emits batch_N_units / batch_N_clamp_ms / verdict; its unit test is updated. Both run_walk call sites carry the new param. Verified by execution: build clean; ci_floor_plan_witnesses green (the three new clamp witnesses + cover-schedule). The receipt verdict unit test and the fixture RED control (budget_red_control_plan; TIGHTEN_MS=0 -> clamp 0 -> the FLOOR-BATCH-OVER-BUDGET refusal) are the e2e enforcement confirmations; the fixture's control witness triggers a whole-tree emit that OOMs alongside a compile in this container, so both run as a clean post-commit confirmation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
… my redundant D5 Main advanced to 12e2ed5 while this branch was built. #7146 ("Derive the diff baseline from the CI event; kill the origin/main fork") landed the *exact* purpose of my D5 independently, and more completely: a dedicated gunbc.diff_baseline module with a CiDiffEvent-modeled, RED-testable pure resolver that HALTS the floor with a typed AFFECTED-SET REFUSAL on an unrecognized event (fail-closed) rather than defaulting. It is the single authority now, so my D5 is redundant and dropped. Conflict resolution (all 8 D5 files): took main's #7146 version wholesale — floor_diff_observe, merge_admission_produce, roadmap_dispatch_actuator, ci_workflow, ci_spec_witness_test, floor_diff_observe_witness_test, ci_spec; deleted ci_diff_defaults.dag (main moved DiffBaseline to gunbc.diff_baseline). My D5's DiffBaseline/ci_diff_defaults changes are gone; the miscite fix and Piece 3 stay. Re-applied onto main's ci_spec.dag/ci_workflow.dag the parts that are NOT D5: - Piece 3 derived clamp (FloorBatchClamp + gunbc_ci_floor_batch_clamp_params + clamp_note), replacing main's static gunbc_ci_floor_batch_wall_budget_seconds list (which had two operator-signed raises 1320->1440->1680 the clamp supersedes; the raise history is kept in the SUPERSEDED gunbc_ci_floor_batch_wall_budget_note). - The parked miscite fix (rust_tests_removed_disposition -> commit_gate_rust_suite_removed_disposition). - The ci_workflow prose re-point to the clamp authority. D0 (cli_run.rs retention) + main's #7146 cli_run.rs auto-merged non-overlapping; D3 (ci_placement.dag) and the rest of Piece 3 (ci_floor_plan.dag, claim_executor.rs, budget_red_control_plan.dag, ci_floor_plan_witness_test.dag, ci_layer_roots.dag) carried through. Verified: ci_floor_plan_witnesses green on the merged tree (346 modules; the three clamp witnesses + cover-schedule). Rust rebuild + regen follow. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
…ned D5 witness The merge that adopted #7146's landed gunbc.diff_baseline (and dropped my redundant D5 gunbc.ci_diff_defaults) left two remnants: - .github/workflows/ci.yml carried an auto-merge artifact — the regen step and floor step fetched `origin $GITHUB_BASE_REF` (my dropped D5's bare-var form) instead of `origin main` (#7146's authority, which resolves the diff baseline at floor eval-time via resolve_diff_baseline, not at fetch time). Re-running `gunbc ci` regen re-derives ci.yml from the merged ci_workflow.dag, restoring the `origin main` fetch. - src/v2/test/claim/ci_diff_baseline_witness_test.dag imported the deleted gunbc.ci_diff_defaults module (my D5 authority), which would break the corpus compile. Its 6 witnesses are strictly superseded by #7146's landed dag/test/claim/diff_baseline_witness_test.dag (11 witnesses, with stronger fail-closed semantics on PR absent-base). Deleted as dead weight. Co-Authored-By: Claude <noreply@anthropic.com>
…ps, lens-door, observation UX contract (#7169) * Plan §9.8: fleet-wide budget diagnosis — no regression, mis-denominated budget Seven observed full-corpus batch-3 walls (1344-1629s) across five branches, every sampled failure with all witnesses passing and memory healthy; main 12/12 green through #7129's merge. A scalar wall-time budget conflates workload size (diff-proportional by design), host speed, and per-entry cost creep (the actual regression dial, stable ~1.57-2.0 s/entry). Interim: one signed raise to ~1680s on main's row; durable: re-denominated budget (overhead + units x rate[host-class]) riding PR-1's CiSpec work. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan: operator rulings — atomic PR-1 with lens-door reintroduction; two-constant clamp model Witness clamps: 5s hard max per witness (existing fast-lane authority, unchanged) + 1s expected-average as the aggregate coefficient (batch = overhead + units x avg; full corpus ~44min under the 55m cap). Hand-set budget rows delete; constants signed via the existing budget_note discipline. PR-1 is the atomic full rework (no migrations): placement roster + gauntlet split + DiffBaseline + derived clamps + ts-lens-door (v2-door routing, empty_complexity_report stamping deleted, complexity lens AuditOnly -> Blocking with planted-quadratic RED). Pre-PR probe gains the lens-audit inventory so the door flips knowing its red set. D4 rides PR-1 iff a green cadence run exists at landing. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: §6b addendum — interaction with the CI two-tier rework Model and laws unchanged; CI renderer contract gains three event classes (derived-clamp refusals with their arithmetic, placement dispositions, lens findings), heartbeat keys on clamp units, AttentionLevel grounds on the signed constants, pain point migrates to the gauntlet context, and P1 sequences after the atomic CI PR to avoid double-churning the floor's emit sites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: atomic-PR ruling, human-legibility contract, §6c frontend relation One atomic PR (P0-P3 together, after the CI rework PR). Heartbeat: identity-first, vitals-suffix, human units, once/minute max; raw byte dumps are census violations — [floor-memory]'s current shape is the named negative example. §6c: register thesis shared with the site lane; glyph color roles re-ground on gunbc.design.* when it lands (dissolution trigger, not dependency); dashboard belt B = renderer N+1 of the same JSONL stream; gunb.ai terminal a future renderer of the shared schema. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: tone ruling — plain sentences, real emojis, clock pulse Arm's-length lines are readable sentences, never key=value chains (dense form lives in receipt boxes/files); glyphs are real emojis from the one glyph authority with the reward-animal rows kept; the periodic status line uses the clock, not the heart. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: selection prominence — the diff→runs chain is the preamble centerpiece Per-file attribution (touched file → selected entries/witnesses), skip count with the falsifier audit pointer, now-vs-later placement split, and widening named in plain language with the causing file. Same selection authority projected per file — no new telemetry. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: attribution grain is the declaration, not the file Under each touched file, the qualified names the diff actually touches (hunks intersect declaration spans) with change kind, then the witness count attributed at selection's real grain (module closure today, stated honestly); decl-grain selection shrinks the same display when the namespace lane lands it — the UI leads, selection catches up. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Progress-observation plan: change-kind coloring + typed no-op taxonomy Git-diff convention colors (green/yellow/red) as glyph-authority rows, textual kind tag always beside color. No-ops are a closed sum — docs-policy, uncovered (a visible coverage nudge), no-decls-touched, generated-artifact, deletion (widens, not a no-op) — a bare unlabeled 'nothing' is a census violation (the Option/None conflation pattern applied to UX). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan §8: two blessed stage collapses + best/worst-case envelope Regen job folds into the floor as a spec row (serial chain becomes build → ci → deploy; cold control stays a gauntlet row on main); the two receipt gates fold into merge admission. Envelope: leaf PR 6-8 min; whole-repo diff ~35-41 min honest wall (clamp ceiling ~44m, 55m cap), with the cold-build and memory-pathology tails named and the shrink path owned by store-econ/native-flip + W3. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan §8: delivery restructure — #7162 grows to hold everything Operator ruling: PR-0/PR-1 split dissolved; #7162 absorbs all remaining pieces. Build order: clamps first (self-greening — the floor reads CiSpec from the PR tree). D4's gate restated for the growing PR: a branch falsifier run is the deletion receipt (main-cadence green impossible pre-merge by construction); one green cold run post-D0 triples as D0 acceptance, D4 receipt, and cold-side probe timings. D5's Env.Get mock is its own named part, finished in-PR. Probe: worker-driven workflow_dispatch on fleet slots, serial, >=2 hosts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Parse: interpolation-body errors name the context + the literal-brace escape; witness locks escape semantics The ${...}-in-strings gotcha, root-caused: interpolation triggers on '{' + identifier (the dollar is irrelevant), and a failed interpolation-body parse escaped as a bare expression error ('expected RParen, found Colon') with no pointer to the existing \{ escape — which works, verified by execution (the principled shell form is "$\{VAR:-default}"; no bare-dollar workaround needed). parse_interp_parts now wraps body-parse failures with the interpolation context and the escape hint. Witness battery (4 claims, green by execution) locks the escape semantics via discriminating lengths. STAGED: stage0 regen for the 02_parse change is fail-closed BLOCKED on a main-head breakage this work exposed — regen_stage0's v2-self-compile leg cannot resolve name_resolution_policy_is_namespace_only from 04_env/04_sigs (calls landed in #7093; resolution broken by the 09:0x emit-import-closure wave). Pre-existing on the clean tree, verified by stash + --verify. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Parse: close the interpolation fallback fail-open; regenerate stage0; retract the main-breakage alert CORRECTION: main was never broken — the regen 'breakage' was this session's stale debug binaries (name_resolution_policy_is_namespace_only is a native builtin registered post-#7093; a fresh build resolves it, and main is green 12/12 through the 09:0x wave). The prior commit's STAGED note is superseded here. The real second defect, found by reproducing the worker's exact error shape: parse_interp_parts' fallback arm returned SUCCESS on an unexpected token after an interpolation expression (a fail-open — a well-formed node handed back mid-string), letting the caller trip later with the context-free 'expected RParen, found Colon'. The arm now refuses with the interpolation context + literal-brace hint. Verified by execution: the worker's shape now reports the hint; regen_stage0 --verify is byte-clean (regen_divergence_count=0 — no legitimate interpolation in the closure relied on the silent arm); the escaped form evaluates to ${GITHUB_BASE_REF:-origin/main} exactly; 4/4 escape witnesses PASS. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * DESIGN §5: the workaround rule — an absorbing fallback executed by the author Operator ruling 2026-07-24: noticing you are implementing a workaround IS the line-stop signal — back up, reassess, root-cause or flag for help; the only landing states are the real fix or a declared scaffold with a named dissolution trigger. A workaround is an unmarked scaffold; the marking is the entire difference. Added to the recurring-failure-modes roster as 'unmarked workaround'. Receipt: the ${…}-in-strings dodge — the bare-$ respelling concealed the existing \{ escape and two real parser defects; stopping the line surfaced all three within the hour. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Dashboard: raw-text serialization fix + progressive disclosure + register corrections Root cause of the dead strikethrough (operator screenshots 2026-07-24): inline <style> text was HTML-escaped, emitting '.node-superseded > .title' — an inert selector in every browser. Per the HTML spec's raw-text elements (script, style), std.markup's MarkupMedium gains raw_text_tags and emits their text raw; try_serialize_html_source refuses fail-closed when raw-text content contains its own close sequence (same escape class as the dispatch-button inline-script incident — the style copy was never fixed). Page: rows render their LEAD (first ' — '/'. ' segment) with the full brief behind a native <details> disclosure (188 blocks; zero JS). Style: .status Width→MinWidth (the 'superseded' chip overflowed its fixed box into the title); .roadmap/.daily-workspace gain auto side margins (centered); dispatch-btn carries the figure-role border accent (actions carry the accent; status stays quiet). Witnesses: 6 new page claims incl. the unescaped-combinator check and the raw-text refusal RED; 10/10 green by execution; markdown/jsx media unchanged (raw_text_tags: []) and main_wet byte-stable. Named follow-up (belt B lane): deploy refreshes files but the serve path's artifact/process refresh is unproven — the live page lagged tree styling; a served-page fingerprint check belongs in live_deploy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan: the roadmap as a daily workspace — readable, observable, tactile Three pillars with exists/missing stated honestly: P1 readability (largely landed 2026-07-24, section-collapse residue); P2 observable dispatch — the stateful workflow: GET /sessions projection from belt B's existing observe half, live row states, Stop/re-dispatch verbs (absorbs the filed ts-dispatch-redispatch), progress depth via the observation lane's stream (renderer N+1 by contract); P3 the feel register — gunbc.design.motion tokens + the acknowledgment law (total assignment, censused like unthemed colors), dashboard as first consumer on existing state flips, sound a named later axis. Doc bound to roadmap_page_for_authority. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * UX plan: the dispatch button's full lifecycle + the analog root principle Operator-directed exemplar: one control end to end. The story: rest → pressed (ack on DOWN, act on UP) → requested (still, distinct — no pulse; the keyframes wall holds) → spawned (settle beat, morphs into the workflow-stage chip) → working (live stages from P2a, changes animate, steady states still) → done (settle + re-arm; re-dispatch fix in scope) → refused (blocked-travel dip + typed reason). Every edge a tokenized row, totality censused. Root principle recorded for gunbc.design.principles: simulate real analog behavior — every control an individual physical instrument (car-knob rule): travel, mass, detents, mechanical state; still-until-touched is analog honesty; sound = mechanism click, later axis. Register inventory: hover/press rows exist; missing = transform responses, settle_spring easing, lifecycle edges, sessions read. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * UX plan: binding end-to-end contract for the dispatch exemplar Six person-observable checkpoints; the consumption rule (no register row lands without its consumer in the same PR); the single-line-item workflow representation (stages as detent positions, not a progress bar; history as belt-fact projections); everything else in Pillar 3 explicitly parked; two PRs total with PR-A independently shippable as the anti-shelf-ware test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Observation plan: atomic ruling reaffirmed — completeness is the merge bar Operator 2026-07-24, against the P0-carve-out argument: one PR, P0-P3 entirely, after the CI rework. The controlling rationale is completeness (only finished work merges — landed vocabulary with no renderer is the consumed-by-nothing state the consumption rule forbids); the shared-emit-site rationale is secondary and not load-bearing. #7168 grows to P0-P3 rather than merging alone. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plan §11: D5 discharged — superseded by #7146's gunbc.diff_baseline on main Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg --------- Co-authored-by: Claude <noreply@anthropic.com>
…ance Second phase of the atomic P0-P3 observation PR (operator ruling: only finished work merges; a landed event model with no renderer is vocabulary nobody can see). gunbc.observation_ci_render projects the std.observation stream into append-only log lines. It computes nothing and holds no telemetry source — every number it prints arrives in an event or a heartbeat sample the process already had — which is precisely what makes replaying a real captured run possible rather than a synthetic fixture. FLAGSHIP ACCEPTANCE, green by execution: the fixture is run 30044816605's actual log, not a reconstruction. Its heartbeat at t=33m carried current=16107200512 swap=34359738368 psi_some_avg10=9.01 and named no subject at all, while the process sat inside v2.compiler.normalized_tree for 606984ms and disclosed that only at walk end. Re-rendered through the escalation law the same window produces named activity: identity-first heartbeats in human units (15.0 GiB, not the raw byte dump), the quiet module surfaced at T, and the memory-reclaim cause surfaced at 2T. Contracts from section 6b in force: plain-sentence tone, real emojis from the one glyph authority with the clock pulse, identity before vitals, durations on every outcome line, refusals restated at the end so log truncation cannot hide them, and relayed subject text neutralized through the existing GitHub guard so a child's stderr cannot mint workflow commands in the parent run. Law 4 made structural: line placement is DERIVED from attention, so a refusal cannot be written into a collapsed group — the group is exactly where a reader will not look. Escalation has two rates: reveal depth grows linearly (one tree level per threshold) while emission points double (T, 2T, 4T), so a window that stays quiet escalates without becoming a per-minute drumbeat, bounded by construction. Three REDs proven by perturbation, as the ruling requires: - planted silent phase (escalation never emits) reds responsiveness - an orphaned Begin reds the watchdog - a Refused placed inside a collapsed group reds Review 42203 (three findings, all correct, all fixed): - ci_gibibyte_tenths respelled the GiB scale factor as a literal; it now consumes std.measure.gibibyte_scale_factor_bytes, and the duration helper consumes seconds_per_minute plus a new milliseconds_per_second added beside its siblings in that authority. A unit authority forked inside a formatting helper is easy to miss because it looks like arithmetic. - the run summary picked the refused glyph whenever refusals+failures>0, so a failures-only run rendered as refused — collapsing at the last line exactly what the outcome sum exists to establish. Failures now dominate the glyph, refusals keep their own, both counts stay in the text. - an unavailable duration silently vanished from concluded lines, breaking the model's own rule that an absent measurement names its cause. It now says so. Each fix carries a witness; the summary fix carries its own RED. Suite green: 31 model, 6 lockstep, 18 renderer conjuncts. Compile-clean unchanged at 47 pre-existing errors, zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…iction-claims-wzwgbf
…rriers Third phase of the atomic P0-P3 observation PR. gunbc.observation_tty_render projects the SAME std.observation stream the CI renderer projects — a sibling, not a successor and not a second model. The two differ only where the medium differs: a terminal can be repainted, so routine progress overwrites one line in place and stays quiet; a CI log cannot, so it appends. Everything they share — the event vocabulary, the density authority, the glyph table, the duration/byte/percent projections, the hold-cause text — is imported from the CI renderer or the model, never re-derived. A witness proves the sibling property by execution: the same event drives both surfaces and moves together. The three upgrades over the reference implementation are INHERITED from the shared carriers, not re-earned: outcome lines carry durations, Refused is distinct from Failed, and dwell escalation is recursive. The reference has none of the three; the TTY renderer gets them for free by projecting the same model. Law 4's asymmetry, expressed here as cursor action rather than group placement: repaint-vs-scroll is DERIVED from attention, so a refusal cannot be repainted away — overwriting it would erase it the instant the next line arrived, the terminal form of burying it in a collapsed group. Required preamble (no anonymous process), BlockedOn inline with named remaining (a bounded estimate prints the time; an unknown one prints why, never a fabricated ETA), and the reward animal on Final drawn deterministically from the one glyph authority so replay is preserved and a non-emoji terminal degrades to a word. Also in this commit: the self-host regen of the seed. P1 added milliseconds_per_second to dag/std/measure.dag, a seed-emitted module, so src/v1/stage0/src/std_measure.rs is regenerated to match — the required same-PR regen for a generated-artifact source edit. Fixed point verified by rebuilding regen_stage0 from the new seed and re-running to zero drift. Suite green: 31 model, 6 lockstep, 18 CI-renderer, 10 TTY-renderer conjuncts. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Fourth and final phase of the atomic P0-P3 observation PR. gunbc.observation_emit_census is the census authority. Every place the floor emits a progress line is either a projection of the observation event stream or a counted frontier row with a reason and a dissolve-on — the same discipline the site lane uses for unthemed colours. EmitSiteDisposition is a closed sum, so a site cannot be half-classified, and there is no third arm for a site the census has not looked at: the roster's completeness is what the witness checks against the seed. The roster carries the structured-tag emit families that exist regardless of the CI rework: [floor-memory], [typecheck-attribution], [gantt], [governor], [measurement]. The named negative example the operator called out — the [floor-memory] raw byte dump — is a rostered frontier row, so the census already carries the very site it exists to kill, with its dissolve-on naming the P1 heartbeat projection that replaces it. Sequencing per the ruling and design section 6b: the CI two-tier rework rewrites the floor's emit sites, so the exhaustive per-print wall over the ~75 raw eprintlns in claim_executor is a declared frontier gated on this PR rebasing over that rework and re-censusing. Censusing sites about to be rewritten is the double-churn the operator ruled out. What lands now is the census model, the roster, and the executable hygiene witness — never a hidden zero: five families migrated-pending, the raw-print residue counted, and the witness holding the roster against the seed so it cannot rot into a lie. Executable, not inert: the witness reads the live seed and reds when a rostered marker has vanished (staleness — proven by a RED control) or when a frontier row lacks a real dissolve-on. The [floor-memory] shape is checked positively — still present, still classified frontier — so the census cannot quietly drop it. This completes P0-P3. Full suite green by execution: 31 model, 6 lockstep, 18 CI-renderer, 10 TTY-renderer, 6 census conjuncts, each with discriminating REDs proven by perturbation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ition, 2026-07-24) The 1000ms aggregate coefficient now records its basis in gunbc_ci_floor_batch_clamp_note: host class (srv arm64 self-hosted, capped) x the adaptive governor's realized worker width, denominated against the observed 0.58-0.70 s/witness (the 1344-1629s full-corpus fleet envelope over ~2316 witnesses). Naming the basis makes a future width or fleet change a deliberate re-sign of the constant, never a rediscovered fleet-wide red; the ~1.4-1.7x headroom over the observed top rate is exactly the >=~1.6x runaway the clamp catches, with sub-threshold creep owned by the gauntlet's per-cadence s/unit receipt. Co-Authored-By: Claude <noreply@anthropic.com>
…timings Instruments claim_executor with write_gate_warm_cost_receipt — one row per gate/claim (eval wall + resolve + combined warm_ms) and a discovery row carrying the per-witness rate — derived from the ClaimResult timings the walk already records (operator ruling 2026-07-24: instrument the existing floor, no throwaway probe workflow). Written to target/floor-gate-warm-cost-receipt.tsv and mirrored to the log as [gate-warm-cost] rows so the placement probe lifts it from get_job_logs on a fleet run. This is the placement roster's measurement basis: a gate rides PrTier only if its measured warm cost is within the 5s fast-lane budget, else fail-closed to Gauntlet (v2.workflow.ci_placement). Every floor run now auto-emits it; run cold-then-warm on >=2 hosts and the roster records value + host basis. Verified green-by-execution locally (single-claim row); the discovery-row path verifies in the next full-corpus CI floor. Fail-closed on a write error, consistent with the other floor receipts; never a verdict term. Co-Authored-By: Claude <noreply@anthropic.com>
The operator's "show me": proven-by-witness without a visible sample is the
fluent-but-unseen trap. dag/test/claim/observation_crawl_replay_test.dag
renders the captured crawl window of run 30044816605 through the P1 CI renderer
as one assembled block and asserts it by execution:
- names the module where the capture was silent ("still in witness discovery:
entry 214 of 602, now typecheck v2.compiler.normalized_tree", surfaced at T,
the memory-reclaim cause at 2T)
- uses human units, never the raw byte dump (15.0 GiB, not 16107200512)
- ends in a named refusal summary, not a silent 55-minute timeout
observation_crawl_after_block() is the exact function the PR body's after-sample
is produced from, so the pasted before/after is a projection of a green run
rather than prose. Every input number is read off the real log.
The earlier gunbc/observation_crawl_demo.dag (a run-entry that returned a String
and so errored on the ProcessExit contract) is replaced by this witness — a
green check is worth more than a run-entry that prints then fails.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Operator 2026-07-24 (third sequencing revision): instead of landing after the CI rework, the complete P0-P3 observation branch merges INTO #7162 — emit sites rewritten once in final shape, new log format visible in the PR's own runs upfront. Ownership: #7162 worker merges and wires the five rostered families now; eprintln residue stays a counted frontier until the remaining floor pieces land; observation worker reviews against their own REDs; #7168 closes as absorbed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
…ges into #7162) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
…ude/ci-executor-eviction-claims-wzwgbf
…7162 Operator 2026-07-24: atomic means the old CI output machinery is gone at merge, not rostered-pending. Integration dissolved the double-churn rationale, so the eprintln/echo frontier's dissolve-on is now in-PR: zero frontier rows for in-repo display sites at merge, old print calls deleted. Census wall survives for NEW prints; receipt files and output_policy instrumentation tiers exempt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg
… kill the [file] firehose The floor's [file] read firehose (2265 lines / ~99% of the log, measured by execution) was the pre-plan naming-hygiene walk reading the whole source tree at the OutputDecision Full default, because install_output_policy ran AFTER the walk (claim_executor.rs order). gunbc.output_policy already models Instrumentation => Suppressed at Normal (CI's default verbosity) and ShellTrace => Condensed — the walk just never saw the policy. Fix: install the policy (and group syntax) FIRST, before the naming walk and every subsequent corpus read, so all host-effect traces are funnelled per the .dag authority. Verified by execution on the minimal smoke plan: [file] read 2265 -> 0, total log 2613 -> 24 lines, claim still PASS (exit 0). The Ambient semantics hold — the policy's divergence rule (ExpectedOutcome/ObservedOutcome) still expands a captured stream on failure, so a red effect is never silenced; only the green firehose is. This is the highest-leverage lever of the observation-emit census flip (the echo class the census targets). Follow-on commits route the display families ([floor-memory], [gantt], [governor], [measurement], [t+..]) through the observation stream as Ambient projections (the ✅/🕐/🚫 format matching #7168's "after" block). Co-Authored-By: Claude <noreply@anthropic.com>
…uthority
Step 2 of the flip (format), after step 1 (the [file] firehose, volume). The
prelude phase marks are the visible display class in the short regen job's log;
they now render through the single-authority observation renderer instead of a
raw [t+…] byte string the seed would fork the format into.
before: claim_executor: [t+86.1s] naming-hygiene walk complete
after: ✅ naming-hygiene walk done in 48 seconds
- New seed→.dag boundary gunbc.observation_seed_render: primitive args in, a
rendered line out — exactly as cli_run.install_output_policy calls
output_policy.resolve_channel_policy. A phase concluding is modelled as a
Concluded event on a PhaseSegment subject, projected by
ci_event_line ∘ ci_render_line, so the FORMAT stays single-authority in
gunbc.observation_ci_render and the seed constructs no format of its own.
- The raw [t+{:.1}s] eprintln is DELETED, not suppressed (grep-clean for the
print). §5: on a renderer-unreachable failure the arm names the degradation
loudly and never reproduces the old marker.
- Per-phase walls (delta since the last mark), not a running t+, so the log
itemizes which prelude phase is slow — the step toward the per-phase receipt
keys the ci_spec prelude-coverage-hole follow-up (row a) calls for.
- Green by execution: phase_mark_renders_through_the_observation_render_authority
resolves the adapter through a real interpreter and asserts human units + the
completed glyph + NO [t+ marker (the discriminating RED). The seed→.dag
resolve is memoized, so the renderer resolves once and later marks are cache
hits. Rust-called-.dag-unimported has precedent (output_policy.dag).
Next in the series: the rostered census families. floor-memory (the flagship
byte dump) needs its subject feed plumbed first so it renders honestly (entry X
of Y, never a fabricated 0 of 0), then gantt/governor/typecheck-attribution,
each flipping its census row (CountedFrontierSite → MigratedToObservation) with
the witness restructured to assert the raw marker is gone — the "witness fixes"
step of flip → witness fixes → roster.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
…ld_residue) The progress-and-observation merge (#7168) added observation_ci_render.dag, whose ci_hold_cause_text names the two memory-pressure SchedulerHold variants specifically and gives the other five a generic cause via a top-level wildcard arm — a non_fold_residue site. It landed unrostered because per-PR affected-set selection predict-skips the corpus-read nfr witness (the masking class the roster's dated rows document), so it reds only on a cold whole-corpus sweep (falsifier / merge-to-main), not on the selected PR floor. That is the census wall doing its job on its own author. Roster it (gunbc.non_fold_residue, one FrontierRow, reason + dissolution trigger toward a total match), matching the established masking-class fix and preserving the observation author's design. Green by execution: observation_hold_cause_wildcard_is_rostered asserts the live roster now carries dag/gunbc/observation_ci_render.dag::ci_hold_cause_text via the same host reader the corpus scan uses — reds if the row's key drifts from the scan's {rel}::{fn} key or the hand edit malformed the 126-row list. design_register_lift_parity (the other cold-red thought to be surfaced by the merge) is NOT touched: this branch's gunbc.site.* inputs are byte-identical to main and recent main-push runs are green cold, so it is green here too — not attributable to this PR. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
… strings Foundation for migrating the [floor-memory] byte dump to the observation heartbeat. Adds gunbc.observation_seed_render.seed_heartbeat_line: the seed→.dag boundary that takes the primitives the heartbeat thread has (elapsed, batch label, entry position, memory vitals) and projects them through the one renderer (ci_heartbeat_line ∘ ci_render_line) — identity first, human units, no raw byte dump. The subject is batch-grain by construction: the floor walks entries in parallel, so there is no single active module to name, and the primitive interface carries none — never a fabricated per-module "now typecheck X". Green by execution: seed_heartbeat_line_renders_identity_first_in_human_units pins the exact bytes for two samples through the real interpreter: 🕐 33 minutes in — still in witness discovery: entry 214 of 602. memory 15.0 GiB, swap 32.0 GiB, pressure 9.0% 🕐 500ms in — still in self-host fixed-point: entry 0 of 2. memory unreadable (cgroup field unreadable), swap 0.0 GiB, pressure unreadable (cgroup field unreadable) The first is the captured crawl window re-rendered from the seed's own vitals (raw byte value absent); the second proves an unreadable cgroup field names its cause, never a fabricated zero (observation law 2 / §5). These golden strings are the oracle the Rust mirror is proven byte-equal to in 4b. Why a Rust mirror next, not an interpreter call: the heartbeat runs on a detached liveness thread in a memory-constrained context — resolving the renderer there would build a duplicate module index, consuming the very memory it watches (§2), and the thread exists to stay alive when the main interpreter is busy. 4b adds that mirror (proven == this oracle), plumbs the subject feed, wires it, deletes the byte dump, and flips the census row. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1
Measurement peak-RSS/cgroup dumps project through ci_measurement_rss_line (seed_peak_rss_line ↔ render_peak_rss_line_mirror; identity-first, human GiB). Shell host-effects become ObservationEvents: Ambient Begin/Done still gated by ShellTrace; Anomaly Failed gated by effect_stream disposition alone (never silenced by ShellTrace Suppressed), with law-4 idempotent group_end, self- describing `$ argv (exit=N)`, and empty-stderr surfacing. ShellTrace/ disposition tables left unread for the interim Condensed-at-Normal split. Census: measurement + shell MigratedToObservation; tagged frontier count 0; 76 raw eprintln residue recounted. Standing check: claim_batch census witnesses PASS before push. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…tive env read (#7191) * UX plan: sound joins the dispatch exemplar (operator override — see/hear it working) Checkpoint 7: mechanism click on press (pointer-down is a user gesture, autoplay-legal), settle tone on accept, dull thud on refusal — synthesized WebAudio rows (event-class -> frequency/duration/envelope) in the register, no assets; steady states silent as idle machines; minimal mute model (persisted toggle). PR-A carries the press-click; PR-B the lifecycle tones. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Plans: integration ruling — observation stack merges into #7162 Operator 2026-07-24 (third sequencing revision): instead of landing after the CI rework, the complete P0-P3 observation branch merges INTO #7162 — emit sites rewritten once in final shape, new log format visible in the PR's own runs upfront. Ownership: #7162 worker merges and wires the five rostered families now; eprintln residue stays a counted frontier until the remaining floor pieces land; observation worker reviews against their own REDs; #7168 closes as absorbed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * CI plan §8: integration ruling cross-reference (observation stack merges into #7162) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Observation plan: cleanup ruling — old display machinery deletes IN #7162 Operator 2026-07-24: atomic means the old CI output machinery is gone at merge, not rostered-pending. Integration dissolved the double-churn rationale, so the eprintln/echo frontier's dissolve-on is now in-PR: zero frontier rows for in-repo display sites at merge, old print calls deleted. Census wall survives for NEW prints; receipt files and output_policy instrumentation tiers exempt. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * Interpreter: read this process's own environment natively, not via a printenv subprocess wet_env_var spawned `printenv NAME` to ask for a value the process already holds in its own environment — a modeled operation realized by the wrong handler (§3(b): the shape is name -> value?; the shell argv is ONE handler, and never the right one when the target IS the reading process). Now std::env::var, semantics preserved exactly (unset -> None, empty -> None, trimmed). SCOPE, honestly: this fixes the interpreter's own env-token fallback only. The corpus's modeled shell.Env.Get calls STILL spawn printenv — verified by execution after this change (probe: '[shell] printenv GUNBC_ENV_PROBE'). That path needs a native transport KIND, which is a grammar-level change: transport kinds are parser-whitelisted (02_parse.dag rest|shell|file), the predicate lives in generated v1_std_core.rs, and the dispatch chain is in the hand-maintained interpreter. Filed as the transport-decomposition lane's cheapest first consumer rather than improvised here — it also collides with the floor rework's live edits to these files. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fdkaGGLUKpLRwwqxp5sLg * CI re-run: regen red was srv3-04 missing rustfmt in isolated toolchain — host provisioning, not this diff Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NU5SWj7DmhqHaa963gsEXG --------- Co-authored-by: Claude <noreply@anthropic.com>
Whole-tree compile-clean failed: bare SelectionNoOp.GeneratedArtifact collided with v2.std.artifact.GeneratedArtifact and gunbc.generated_artifact.GeneratedArtifact. Mint via selection_noop_generated_artifact in the defining module so the variant resolves unambiguously. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
|
Operator live-log review (run 30142403230) — four findings for the remaining wiring, two of them design input for the held pass.
Also noting for the record: the red itself ( Generated by Claude Code |
…bidir, failure-receipt miss Operator live-log review (run 30142403230) — four pieces in one pass: - Shell subjects are typed service.op intents; argv only in Failed.error. Ambient ShellTrace is Suppressed at Normal (silent scaffolding); Anomaly still surfaces via divergence alone (Quiet no longer forces StreamSuppressed). - Governor receipt uses StatusPulse (not Done glyph); peak RSS / governor / cgroup wrap in one "floor receipts" group. - Census roster grows four CountedFrontierSite rows ([floor-drain], [gate-warm-cost], [receipt], [file]) with a bidirectional hygiene witness. - Undeclared *_failure_receipt companions (NoMainFunction) treat as empty detail instead of stuffing failure_receipt_refused onto ordinary Bool(false) reds. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…7178 cost) (#7204) The namespace-only flip #7178 (merged 2026-07-25) makes bare references resolve by containment-walk (#6848 per-entry bare-reference fixpoint), adding ~200s to the affected-set discovery-corpus resolve wall vs the import-scoped basis the prior 1680 was sized on (#7137, all pre-flip). This is a real, attributed cost shift, not a per-PR regression: THREE disjoint post-flip observations exceed 1680 -- #7198 (run 30140810666) 1820001ms, #7188 (run 30142221249) 1859345ms, and the falsifier lane's warm post-flip run (~36min, same signature). Operator-signed raise (briansrls, 2026-07-25): 2100s (35min), sized to the +/-20% fleet host envelope over the observations so a slow-host broad-touch run does not round-trip this row a third time. STOPGAP until #6848 cuts per-entry resolve (dispatched as a lane) and the row dissolves into #7162's derived clamp. Remedy stays diagnose-or-signed-raise, never rerun. Standalone budget PR -- unblocks the fleet (#7198, #7188, and main's next push all red on batch-3 over-budget) in one commit, disjoint from the feature lanes. Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bring design_register_lift_parity digest re-pin (#7169), namespace-flip aftermath, and related main landings. Keep this PR's derived FloorBatchClamp authority over main's stopgap static 2100s batch-3 raise (#7204) — the clamp is the mechanism that raise was awaiting. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ewire Dissolves the post-namespace-flip batch-3 resolve wall (~200s/run) by hoisting module_exported_type_names once per module instead of linear-scanning exports once per (consumer × inherited key × direct import). Brings assembly-split resolve-stage instrumentation from the same lane. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…it tags Merge-admission stamp is `gunbc run`, which never installed output_policy — so ShellTrace fell back to Full and every Ambient Begin/Done still printed despite named-intent subjects. Install policy + group syntax at handle_run startup (same as claim_executor). Census grows [resolve-split]/[assembly-split] frontier rows so #7205's new tags stay bidirectional. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Pull the two new commits past the prior merge base (86318c1) so this branch carries the latest dissolve of the post-flip batch-3 resolve wall. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ter) Pull the two new #7205 commits (export_index canonical = fold element — kills the O(|bindings|^2) rescan). Route OnTarget shell.Env.Get through wet_env_var instead of printenv so optional floor_diff injections (GUNBC_CI_DIFF_*) no longer paint ❌ Anomaly Failed when unset — reading this process's env is not a host effect (§3(b) / shell-to-dag census 0b). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
Take main's landed #7205 polish (index-backed local_names / review 42566, corpus receipts in the diagnosis plan, assembly-split comment) over the pre-land WIP copies on this branch. Keep this PR's observation-lane cli_run changes beside the comment merge. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
|
Superseded by #7216 — closing. Operator-directed, and the subsumption is proven rather than assumed: Nothing on this branch is dropped: #7216's head contains Two things worth recording here, since they came out of debugging this branch's CI runs: The red on this branch was never yours. It reached main green because it never ran there — the binary witness declares no source-ref edge to the Rust it is compiled from, so the affected set can't see it; main's run at The four live-log findings from the 2026-07-25 review are carried into #7216's body as a counted list, including the correction that #4's mechanism was misdiagnosed (the invoker is Generated by Claude Code |
…rived fold/expand The workspace becomes the THIRD renderer of the observation model's "routine collapses, anomaly expands" (composition slice 3). LAW — gunbc.roadmap_altitude, a local derivation in std.observation's exact shape (attention derived-never-chosen, density derived from attention, one projection): done/superseded -> routine (folds), open/review -> working (holds), fail/loud -> anomaly (expands), with FAIL-CLOSED arms — an unmodeled status or band key is an anomaly, never quietly routine. No signature accepts per-section or per-node curation input, so hand-curation is unwritable, not discouraged. DECLARED CONVERGENCE ROW: std.observation lives on #7216's unmerged branch (supersedes #7162, the brief's original number — verified, and the successor read before shaping this). Dissolve-on: #7216 merges — RowAttention re-grounds on AttentionLevel, RowDensity on PresentationDensity, this module shrinks to the workspace's subject mapping. RENDER — node-bearing sections and frontier buckets become BANDS: a details.section-fold whose summary carries the title plus derived counts ("2 open · 1 review · 12 done", zeros omitted, unknown counted loudly), open exactly when non-routine work is inside. Prose-only sections have no altitude axis and stay flat. CLIENT — the terminal apply flips the row's disclosure open when the band's density says expands; the emitted predicate (false || band === 'fail' || band === 'loud') is DERIVED by folding the wire-band rows through the law. Receipts by execution: 8 altitude witnesses green — derivation totality with fail-closed REDs, counts wire pinned, fold/open proven over RENDERED fixtures (the two fixtures differ by exactly one working member), the derived chain pinned in the served asset with a negative arm. Fixture lesson kept as its own witness: a done-but-UNSIGNED node renders review and review is WORKING — the attention law agreeing with the sign-off gate (the operator's pending gesture holds a section open). Full battery green including roadmap_emit (the committed ROADMAP.md untouched). Digest re-pinned 5cfdb3c06e603e38, derived by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…page altitude, anomaly evidence (#7234) * Slice 1: the interaction-totality machinery — StateResponse, ResponseScope, family census The composition session's first slice (roadmap-workspace-remodel-plan, round 5; operator question: how do we prevent the flash class?). No new framework — the detent-table pattern generalized past transforms, as one new design module plus the dispatch instrument's rows. CONSTRUCTION — gunbc.design.state_response: a component declares its state family once (dispatch_state_family: the state-class-to-band mapping, previously spelled at THREE sites — the style's four per-state paint StaticRules, the receipt rules' four hand call sites, the base rule's inline invite vars) and each stateful channel once as a function of state. The realize folds multiply every channel across the roster: a missing family member is unwritable by totality of the fold, and joining the family is a one-row edit. DECLARATION — ChannelScope = PerStateFamily | ConstantByLaw{ruling: DeclarationRef}: the table's element type has no third arm, so the undeclared middle where the flash bug lived stops being representable. First ConstantByLaw rows: the approach ring (ruling = dispatch_brighten_neutral_note, the recorded band-neutral-emphasis ruling) and the engage sound (ruling = dispatch_sound_constant_ratchet_note, a declared ratchet with its dissolution trigger on sound_growth_trigger — never silent). CENSUS — executed over the EMITTED CSS, never only the rows: every (member x channel) cell resolves in-family or sits under a signed constant. 20 cells + 2 signed constants, counted; faults typed and located (FamilyVarUndefined | ChannelValueMissing | CrossFamilyValue{foreign_key}) per the detent-edge lesson that conflated fault kinds fail open. Shaped for later StandingIntent enrollment; the registry deliberately not built. SPECIMEN — the round-5 press fix re-derived through the fold, proven by byte-oracle: roadmap_css() emission is byte-identical (digest 50410951147178f6 unchanged, zero re-pin). Also dissolved onto the roster: the four per-state paint rules, the base rule's rest paint (state_rest_decl splices at authored positions), and the band var-name grammar (prefix from the family row, suffixes from the role enum). Receipts, all by execution on the merged tree: 8 keystones green (register/tactile/palette/page/dispatch-presentation/component-button/sandbox/ lift-parity), 5 new census witnesses green including two planted REDs — the cross-wired family locates CrossFamilyValue{fail} on the ok cells, the dropped-member family locates ChannelValueMissing on every loud cell — and the fold-totality witness (one response rule per roster member). Rider: dag/extdeps/web_audio note corrected — the 'no resume dance needed' inference was refuted by measurement (operator's ears, W1d A.2) and had been fixed in the consumer but never in the cited layer; the extdeps row now states the API fact (gesture makes resume() permitted, never unnecessary) and points at sound_preamble_note for the consumer contract. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Record the fourth-round rulings and the depth/motion reference set Session decisions 2026-07-25, recorded in the remodel plan (carrier rows deliberately deferred to their first consumers, per the register's own no-consumerless-rows discipline): - The "active operation may breathe" amendment SIGNED at the WIDE scope: MotionTrigger gains a general Sustained variant in the motion/depth PR; the decorative-vs-operational distinction demotes from type to counted census, stated at signing. - W2-exemplars re-sequenced: after the RoadmapRow archetype, own dispatch ahead of W2-bulk; the stale Sequencing line corrected (#7177 closed without them by the composition carve-out, not by omission). - The operator-supplied depth/motion references recorded with their concept anchors and port constraints (proxemic glow with the enveloped-breath mechanism; SUPERHOT cue decomposition with barrel excluded; Discord elevation as ElevationPlane shape; train-window parallax grounded on the layer DAG's real churn gradient) plus the sandbox demo ladder. The DesignProvenance carrier lands with the depth-studies PR. Doc-graph witnesses green (the plan doc is already a bound root). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Slice 2: the RoadmapRow archetype — declared grid, chip-scale actuator derived from row scale The row is the component (composition slice 2; refines the round-5 flex head line, does not rebuild it). ARCHETYPE — gunbc.roadmap_component.roadmap_row_archetype: the five regions declared as data (status chip | title | meta | disclosure | actuator), each with a typed placement — chip and actuator own auto head tracks (identity left, action right), title owns the flex track, meta flows IN the title's cell (badge count varies, so meta is a flow, never a ragged column), disclosure sits under the head on its landed indent. The grid template is DERIVED from the placements (roadmap_row_grid_template = "auto 1fr auto" by fold, no magic string); density rides two tokens on the scale grammar (h-row, the row gutter) — no bare pixels. ACTUATOR — chip-scale in rows per the SIGNED ruling (2026-07-24): the row-scope override derives its extent from the ROW's token (min-height var(--h-row)) and its width ceiling from the same caption-derived reservation the base declares — min-width and max-width one authority, so a caption morph can never reflow the row. The full-size specimen keeps h-control BY SELECTOR SCOPE: the override applies only under .node-head, so the sandbox gallery renders the design-surface grain with the SAME press physics (detent + receipt folds target .dispatch-btn at both scales, per-family-honest — slice 1's census green over the new emission). DOM — node-mid wrapper (the title track's cell) in node_head_row; the margin-left:auto pusher rule deletes (the grid's third track places the actuator). CSS grain grows three cited property rows (grid-template-columns, text-overflow, white-space). DIGEST — re-pinned 8d2372be4c9d6d61, derived by execution; slice 1 was proven byte-identical against the previous pin first, so the two changes are separately attested. WITNESSES (new file, all by execution): the archetype-derived head block + node-mid block verbatim in the emitted CSS; the served page carries the cells; actuator derived-not-set (positive + planted RED on the hand-retune shape); density cells tokened. Full battery green: 8 keystones + slice-1 census + css grain. PROVISIONAL rows (iteration protocol, one-liner flips at the pass): h-row = 24px; overflow guard clips without an ellipsis glyph (real ellipsis needs a caption span, which moves the client textContent target — named, not smuggled); row gutter stays the landed space-4. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Slice 3: page altitude from the attention law — bands with counts, derived fold/expand The workspace becomes the THIRD renderer of the observation model's "routine collapses, anomaly expands" (composition slice 3). LAW — gunbc.roadmap_altitude, a local derivation in std.observation's exact shape (attention derived-never-chosen, density derived from attention, one projection): done/superseded -> routine (folds), open/review -> working (holds), fail/loud -> anomaly (expands), with FAIL-CLOSED arms — an unmodeled status or band key is an anomaly, never quietly routine. No signature accepts per-section or per-node curation input, so hand-curation is unwritable, not discouraged. DECLARED CONVERGENCE ROW: std.observation lives on #7216's unmerged branch (supersedes #7162, the brief's original number — verified, and the successor read before shaping this). Dissolve-on: #7216 merges — RowAttention re-grounds on AttentionLevel, RowDensity on PresentationDensity, this module shrinks to the workspace's subject mapping. RENDER — node-bearing sections and frontier buckets become BANDS: a details.section-fold whose summary carries the title plus derived counts ("2 open · 1 review · 12 done", zeros omitted, unknown counted loudly), open exactly when non-routine work is inside. Prose-only sections have no altitude axis and stay flat. CLIENT — the terminal apply flips the row's disclosure open when the band's density says expands; the emitted predicate (false || band === 'fail' || band === 'loud') is DERIVED by folding the wire-band rows through the law. Receipts by execution: 8 altitude witnesses green — derivation totality with fail-closed REDs, counts wire pinned, fold/open proven over RENDERED fixtures (the two fixtures differ by exactly one working member), the derived chain pinned in the served asset with a negative arm. Fixture lesson kept as its own witness: a done-but-UNSIGNED node renders review and review is WORKING — the attention law agreeing with the sign-off gate (the operator's pending gesture holds a section open). Full battery green including roadmap_emit (the committed ROADMAP.md untouched). Digest re-pinned 5cfdb3c06e603e38, derived by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Slice 4: anomaly evidence is a surface — the loud reason as the disclosure's first line The loud band's located reason (step: detail, or the wire reason) renders as the first line of the row's disclosure — persistent, inspectable in the DOM — and the title attribute stays a convenience channel, never the only carrier (composition slice 4). CLIENT — in the terminal apply, gated on the loud band with the disclosure in hand: upsert .disclosure-reason (query, create-if-absent, insert after the summary so it IS the first line), textContent from the same computed `why` the title channel projects. Fail-closed: an empty wire reason writes "belt fault — no located reason on the wire" — a true statement, never an empty line that reads as fine. STYLE — one rule: text-12, theme ink, loud's own hue as a border-left edge mark, tokened lengths. Digest re-pinned 3a0411e16e69f2ab, derived by execution. WITNESSES — the surface predicate (upsert + insertion + why + fail-closed placeholder, loud-gated); the planted RED: a title-only fixture — the real title assignment's own shape with no disclosure machinery around it — must fail the same predicate; the title convenience channel asserted still present; the styled block pinned verbatim. Full battery green: 8 keystones + slice 1/2/3 witnesses + roadmap_emit + doc graph. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Composition close-out: carrier rows flipped to landed All four slices LANDED on #7234, marked on the carrier per the done-line; PROVISIONAL rows listed in the PR body; the person-observable checkpoints await the operator's pass on the live page. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * R4 closed by ear: sound is fine as is (operator, 2026-07-25) The last open review-round item. The resume() fix was the real candidate; the modeled parameters stand un-retuned per the by-ear-first discipline. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian <briansrls@MacBook-Pro.local> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
ts-obs-anchor (the five laws; reference implementation studied by execution), ts-obs-model (P0 carriers), ts-obs-ci-renderer (P1, the pain point), ts-obs-tty (P2), ts-obs-census-wall (P3), ts-observation-contract (the equivalence bar). Accept lines and REDs mapped to red_control / first_slice, marked per row. The family's branch state recorded honestly: each row carries a dated update — verified this session — that the lane's implementation lives on #7216's unmerged branch (supersedes #7162) and lands at its merge; last_verified_on set only on those rows, because that verification actually happened. The composition PR's altitude convergence row already watches the same merge. The brief-budget census fired mid-tranche (ts-obs-anchor=101, located node + count exactly as designed) and the brief was trimmed one word — the wall working, recorded because a census that never fires is the one to distrust. ROADMAP.md regenerated; page keystone, emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…(tranche 1: dispatch-lifecycle cluster) (#7240) * W2-bulk tranche 1: the dispatch-lifecycle cluster migrates onto the ticket contract (6 rows, 161 -> 155 legacy) First tranche of the bulk migration (task queued behind the composition session; the five exemplars are the contract, operator-signed on the rendered archetype). Rows: ts-dispatch-lifecycle, ts-dispatch-verdict, ts-dispatch-rework (ticket_row — unsized discipline rows), ts-wf-shape (ticket_row), ts-wf-belt-refusals, ts-wf-progress (ticket_wi — sized, sizing preserved). Honesty rules applied, and they are the tranche's real content: - fields carry ONLY what the prose stated; a field the prose never filled is an honest empty (the renderer omits it), never a fabrication; - dates come from the prose itself (authored_on only where the row named one; last_verified_on stays empty — migration is not verification); - history moves to the updates axis WITH its dates (ts-wf-shape's #7113 reconciliation-seam note preserved as a dated update, marked since-landed, rather than deleted or left masquerading as current); - Accept lines map to their honest fields (belt-refusals' became red_control; progress's became first_slice), each marked in the migration update; - ambiguous rows stay on the counted legacy frontier rather than guessed — none in this cluster needed it. ROADMAP.md regenerated through the generated-artifact gate (main_wet); the md projects headline — brief per the signed W2 contract (full fields render on the served page; the authority carries everything). Receipts by execution: roadmap_page_keystone (including the 100-word brief-budget census over the six new briefs), roadmap_emit, roadmap_authority all green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 2: the loop cluster (4 rows, 155 -> 151 legacy); receipt shape declared Migrated: ts-loop-pattern (the named loop + the ask), ts-loop-selfheal (the structural exit — both operator rulings preserved VERBATIM as dated updates, mechanism notes preserved with the #7121 guard), ts-loop-buildretry (the widening-arm masking row), ts-loop-falsifier (the 29-red narrative with its exit condition as first_slice). Shape ruling applied (operator-signed this session for ts-pr-*; extended here by the same rule): one-fact receipt rows do NOT migrate — a ticket around a narrative one-liner is nine empty fields of costume. Stays prose by declared shape: ts-loop-fmt/docsonly/prepush/stale-roster (closed incident receipts), ts-loop-deploy (pointer receipt). The parent ticket's update row declares this so the frontier count reads honestly. ROADMAP.md regenerated (main_wet); page keystone (brief budget over the new briefs), emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 3: the observation family (6 rows, 151 -> 145 legacy) ts-obs-anchor (the five laws; reference implementation studied by execution), ts-obs-model (P0 carriers), ts-obs-ci-renderer (P1, the pain point), ts-obs-tty (P2), ts-obs-census-wall (P3), ts-observation-contract (the equivalence bar). Accept lines and REDs mapped to red_control / first_slice, marked per row. The family's branch state recorded honestly: each row carries a dated update — verified this session — that the lane's implementation lives on #7216's unmerged branch (supersedes #7162) and lands at its merge; last_verified_on set only on those rows, because that verification actually happened. The composition PR's altitude convergence row already watches the same merge. The brief-budget census fired mid-tranche (ts-obs-anchor=101, located node + count exactly as designed) and the brief was trimmed one word — the wall working, recorded because a census that never fires is the one to distrust. ROADMAP.md regenerated; page keystone, emit, authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk: the re-sweep hold becomes a typed, counted state (management sharpening 1) The 13 ts-pr-* children move from a prose flag to w2_bulk_resweep_held — typed rows, counted, with ts-pr-audit's sweep as the declared dissolve-on — so the legacy frontier decomposes honestly into not-yet-migrated vs held-for-disposition, and the operator's re-sweep has a mechanical worklist. ts-pr-audit itself migrates to a ticket (its sweep instruction is the first_slice; the sweep is the handback — each child's disposition is the operator's call). The lighter one-fact row species is deliberately NOT minted (management sharpening 2, second-consumer discipline): the sweep will disposition most of these away, and the hold makes deferring that call cheap. Witnesses by execution: every held id resolves to a live AuthoredLine (a held id whose row was migrated, superseded, or deleted reds carrying the id — the hold outlived its state); planted REDs on a nonexistent id AND on an already-migrated ticket id. ROADMAP.md regenerated; page/emit/authority green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 4: the lens family (6 rows, 145 -> 139 legacy) ts-lens-endgame (the v2-door dependency named precisely, milestones preserved), ts-lens-door (M-L1; the Accept T2->T5 block became red_control, the three-compile-sites scope review became current_state), ts-lens-treewide (M-L2; the W3 typed-module-store convergence preserved), ts-lens- contract-truth (M-L3; the twice-verified counted state — 55 ids / 46 contracts / 9 missing including live Determinism — lands as current_state with its verification date as last_verified_on, the one tranche row where that field is honestly non-empty from the prose itself), ts-lens- complexity-scope (M-L4; the red-by-design blockers and the space-complexity re-home rider preserved), ts-lens-terminal (the 2c fan-in node). ROADMAP.md regenerated; page keystone (brief budget over six new briefs), emit, authority, and the re-sweep hold witness green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 5: the group-taxonomy family (5 rows, 139 -> 134 legacy) ts-group-u (the membership taxonomy — positional/derived/frontier/nickname with the mint->frontier->query pipeline), ts-group-family (the #7069 re-key; the 744-rows-Derived sequencing fact preserved as an update), ts-group-census (the swept roster ledger; landed items in the brief, storage-grain residue as current_state), ts-group-dissolve-typed (the OnRoadmapNode coupling; its lens became red_control), ts-group- partition-drift (the incident receipt; both drift incidents in the brief, the regen two-generation side receipt preserved dated). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 6: the host-state family (5 rows, 134 -> 129 legacy) ts-host-state (the parent gap — both 2026-07-22 tail incidents as displaced_cost, the srv4 live-fire receipts as current_state, the 0-to-3 dispatch brief as first_slice with the operator's claims-intersection ruling, TakeoverRuling as red_control), ts-host-frontier (the Derived|OwnedMember|ForeignWithContract classification), ts-host-antientropy (the host falsifier), ts-host-cdtransport (deploy from content, not the runner workspace), ts-host-genlease (StaleDesiredState + subtree lease; the 21:49 overlap receipt as displaced_cost). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 7: the native family (5 rows, 129 -> 124 legacy) ts-native-bulk (the arc; operator re-pricing + sizing preserved dated), ts-native-census (derived-denominator discipline made structural: stale-on-arrival counts kept ONLY as dated snapshots in current_state, the deleted-drifting-copies history preserved), ts-native-seams (the measurement-settled crate grain), ts-native-flip (the three-section PR), ts-native-flip-revert (the working-as-designed receipt; the twice-corrected re-flip gate as current_state; the one-authority rule — the carrier's dissolve_on strings, never a roadmap paraphrase — lands as handback, which is exactly what that clause is). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 8: the ci + access clusters (7 rows, 124 -> 117 legacy) ts-ci-definition (the three-clause functionality bar; today's failures as current_state), ts-ci-claimed (the do-not-re-plan ledger; sequencing rule preserved — a fast CI that lies is worse than a slow one), ts-ci-ergonomics (the priced touchpoints; the inventory as first_slice), ts-ci-options (the three merge-gate options; the pick is the operator's — handback), ts-access-model (the transport-accident gap; grants shape), ts-access- orgtailnet (operator-owned creation — handback), ts-access-dispatch-auth (go-live precondition; do-NOT-drop-the-front as handback). ROADMAP.md regenerated; page/emit/authority green by execution. Rider: #7239 (the flips PR) merged on its green floor this tranche — the gutter split and signed PROVISIONAL marks are on main. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 9: misc batch A (5 rows, 117 -> 112 legacy) ts-authority-converge (the sprint entry point; the parity-window carrier contradiction as current_state, the option-b gating ruling dated), ts-concat-class (the 2,798-site census with its atom-never-composition ruling), ts-deploy-tail (the DONE incident — its four dated receipt waves, including the credential-leak find and #7086's construction fix, become the updates thread the blob never had), ts-doc-anchor (carrier-anchored sessions), ts-effects-providers (the conflated-counts honesty catch as current_state; the boundary-enforcement clause as red_control). ts-branches stays: a closed all-dispositioned receipt, not a blob. ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 10: misc batch B — the interpreter-endgame cluster (6 rows, 112 -> 106 legacy) ts-evaluator-complete (the two-typed-exits bar; refusal-never-fallback), ts-executor-seams (critical slice, hollowing fenced to out_of_scope with its stale-on-arrival count rule), ts-falsifier-nfr (DONE — root-cause and landed rows as the updates thread; the NEW-find clause as red_control), ts-floor-memory (the ceiling pin; confirm-caps as first_slice), ts-interp-delete (the delete bar; the missing interpreter-file-only milestone note as current_state), ts-interp-endgame (the three finish lines named apart; the counted-fourth-role enrollment as first_slice). ts-intake-discipline stays: a one-sentence standing rule, not a blob. ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 11: misc batch C (5 rows, 106 -> 101 legacy) ts-lying-stamp (the recurrence class; the 5th occurrence dated; the decide-once as first_slice AND handback — it is a ruling), ts-material-ci (the kernel row; the corrected sequencing as current_state; the different-denominators watch-flag as red_control — land the fresh receipt BEFORE repricing), ts-merge-gate (the re-evidence), ts-quarantine (the link-grain dress rehearsal; the deletion-receipt clause as red_control), ts-queue (ops hygiene; the zombie cancel as first_slice). Stay by shape: ts-modeling-pass (a per-PR checklist rule), ts-overnight (done accounting receipt). ROADMAP.md regenerated; page/emit/authority green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 12: the final ts batch (11 rows, 101 -> 90 legacy) — the ts-* sheet is done ts-review-sweep (the operator checklist; falsifier-dark prioritization as first_slice), ts-seed-interim (the 8-percent-in-33h receipt as displaced_cost, counts dated by the wave snapshot), ts-seed-ratchet (SeedGrowthJustification as the frontier pattern on the seed itself), ts-seed-data-out (the landed roster move; the live dual-representation mirror as current_state), ts-seed-intake (the thin-transport policy), ts-standing-intent (the ask-once row — with the state-response census recorded as its third idling consumer), ts-store-econ (the ForciblySerial narrow point: three lanes converge, said out loud in displaced_cost; the review-hardened RED battery preserved whole), ts-unconsumed (the sweep), ts-wave-reds (DONE — the three-collision heal chain as dated updates, including the opposite-way drift lesson), ts-wf-lens-walls (the roadmap lens trio), ts-zero-hand (the terminal ruling; the third carrier contradiction as current_state, the never-delay sequencing as out_of_scope). Stay by shape: ts-roadmap-drift (done receipt), ts-sustainable-close (one-sentence rule). With this tranche every ts-* row is dispositioned: migrated, typed-held, or declared by shape. ROADMAP.md regenerated; page/emit/authority + the hold witness green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 13: lane 1 — the CI-floor lane (16 rows) + carrier-preserving constructors New constructors first, because the wall fired before the work: ticket_doc / ticket_pp — the exact siblings authored_doc/authored_pp are to authored(). Without them, migrating a pointer-carrying row through ticket_row would silently DROP its carriers (the doc-graph's inbound links) — content loss the migration's own rules forbid. The doc-graph orphan witness runs green over the migrated lane as the executing proof the pointers survived. Migrated: 1-nightly (done, audit-dated) · 1-double-resolve · 1-sccache-falsegreens (the cache-lies live-repro residue as current_state) · 1-wallclock-measured (void profile numbers said so, dated) · 1-placement-authority · 1-sched-resource-aware (the re-base ruling; tracker link preserved inline) · 1-affected-set-defork(doc) · 1-budget-tree(pp, both pointers kept) · 1-builtin-registry(pp) · 1-floor-right-things(doc) · 1-g1-placement(doc) · 1-g2-runner (the modeled-envelope Accept as red_control) · 1-g3-caps · 1-g4-dispatch(pp) · 1-g5-rust-selection(doc) · 1-resolver-pathology-b(wi, sizing preserved). NEW SHAPE RULE, applied and declared: an operator-SIGNED row does not get edited under its signature — 1-bics-design and 1-resolver-pathology-a stay as attested receipts (the signoff attests the node as signed; migrating the line under it would change what was signed). ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 14: lane 3 — the audit lane (5 rows) 3-audit-affected-set (done; the three-clause discharge with its live discrimination receipt), 3-audit-artifact-freshness (green-on-branch is not green-on-main; the operator ask preserved verbatim in the migration update), 3-audit-cache-honesty, 3-enforcement-intent (the landed inventory re-based; the state-response census recorded as its third idling consumer, closing the loop management asked to watch), 3-cost-risk-benefit (the 2026-07-12 working-session capture — the argmax framing, the deferred-and-detected invariant, the wet-is-sacred inversion, the missing-pieces list highlighted not papered over; carriers preserved via ticket_pp). 3-audit-gate-inventory stays: operator-signed attested receipt. ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix the authority witness's stale headline pin (the tranche-14 red, caught and owned) roadmap_authority_witnesses redded on tranche 14 — witness_audit_lane_present pinned the affected-set headline WITH its inline audit date, which the migration moved to a dated update per the convention every tranche has applied. The pin moves with the authority (the slice-2 shape: the witness reds on the change by design, then re-attests). The red was committed before it was seen — the battery ran in the same chained command as the commit; this fix commit is the stopped-line analysis, and the chain is split from here on so a red blocks the commit it belongs to. Forward note for lane 2: witness_fabric_design_rule pins lane-2 row strings ("stateless frontend MVP on fabric" et al) — those pins update alongside their rows' migration, deliberately, not as surprises. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 15: lanes 5 and 6 (12 rows) Lane 5: 5-cargo-green-continuous (done — resolved-by-construction, the unwritable failure mode stated), 5-regen-cutover (done — same discharge class, migrated for consistency with 1-nightly/3-audit-affected-set), 5-defork (the shadowed-shell.Which incident as displaced_cost), 5-dissolve- patches (the 7→25 regrowth re-measure dated), 5-emitted-crate-partition, 5-root-b, 5-seed-honesty (the fail-open-by-construction confession preserved whole; FLAGs A–D as handback), 5-test-migration (wi; the operator's scrutinize-first ruling as handback; the typed-retirement-path as first_slice), 5-v1coupled (one-liner, migrated for its deferral field). Lane 6: 6-shell-emission(doc), 6-shell-intent-phase1(doc — sign-off PENDING as current_state, the flip instruction as handback), 6-shell-slice2(doc — same pattern, the FLAG discharge dates kept). Stay signed: 6-shell-slice0, 6-shell-slice1 (operator-signed attested). ROADMAP.md regenerated; page/emit/authority + doc-graph green by execution BEFORE this commit (chain split per the tranche-14 lesson). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Record the write-interface assessment (operator question, mid-bulk) The migration is not the interface's right first consumer (editorial half irreducible; mechanical half already execution-verified per tranche). The recurring consumer is typed TicketUpdate APPEND — belt verdicts, session write-backs, dissolution firings — with the updates axis as the first API. Assessment as a data row beside the constructors so it is not re-derived. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 16: lane 2 batch 1 — floor-throughput + fabric-allocation (9 rows) 2-compile-clean-serial (lever a landed, the 37.6x receipt kept; lever c residue as current_state), 2-compile-clean-shard-a (done, the OWNED wrapper preserved — owner string survives migration), 2-compile-clean-shard-b (the full Accept checklist as red_control with its planted RED), 2-admission- model (the operator's 1-core-3GiB directive dated; derive-never-hand-set as red_control), 2-cap-deconflation (three facts in three mechanisms; the no-conflated-survivor receipt as first_slice), 2-burstlease (non-death before utilization), 2-strictlease (four nouns no scheduler; the read-back-never-asserted Accept), 2-provider-offer (the dormant design-break probe with its four witnesses), 2-shape-labels (runs-on as projection; the later-architecture fence as out_of_scope). ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 17: lane 2 batch 2 — merge-admission + converge spine (9 rows) 2-merge-admission(pp — HELD as current_state, the green-on-branch evidence as displaced_cost), 2-cd-transport (done, owned wrapper preserved — the placement-is-not-proof premise), 2-converge-reland (the landed inventory in the brief, the full T4 accept as red_control, the ReadAbsent bind note as current_state), 2-fleet-hardening (the ungated-return debt), 2-host-admission (two modes; the post-patch-values RED and the counters-did-NOT-increase receipt), 2-live-read-seam (the no-mutation fence; first-slice-does-not-close preserved), 2-live-read-runner-memory (done, owned; stop-and-return as handback), 2-periodic-actuation (a timer existing is not acceptance), 2-privilege-model (done, owned; typed refusal BEFORE mutation). ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 18: lane 2 batch 3 — the SCM cluster + fabric services (10 rows) The scm family (infra-econ with its cited GitLab 10-K carriers · node-merge's keyed-diff-over-identity core · publication-ladder with the pick-two churn-blinding fence as out_of_scope · remote-realization's protection-IS-billing · visibility-stage0, your 2026-07-25 plan, its T3 Accept as red_control), 2-stateless-frontend (milestone A landed, B + the unmergedPages cutover as current_state), 2-emit-partition (owned; the four leftovers a-d; the atom-never-composition wall as red_control), 2-p3, 2-session-slice (the humming apply-rule), 2-service-receipt (the T4 read-back Accept with its three NotConverged REDs). with_plan and owned wrappers preserved throughout. ROADMAP.md regenerated; battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 19: lane 2 complete — placement, host-effect, srv3/os-install (15 rows) 2-ci-two-tier-placement(doc — the 5-second rule; fail-closed admission), 2-test-decomposition-wcf (with_plan; the W/C/F cut with attribute-before- decompose), 2-host-effect-phases(doc), 2-keyed-delta-fold (accepts a+b met; the (c) proof-by-consumption fork as first_slice — re-point or wire, deliberately), 2-oom-consumer(doc — never EAGAIN-shaped), 2-runner- allocation-v0 (the operational milestone; its full T4 Accept and RED battery; not-complete-while-any-hand-edit preserved), 2-temporal-effect- spine-a (done, owned), 2-resource-namespace-upsert-a (done), 2-os-install-deduction-a (done, owned), 2-srv3-install-reconcile-a (done), 2-srv3-osinstalled(doc), 2-install-media-generic-layer, 2-nbd-serve-held- session-lease (done; the do-not-mint-a-parallel-lease-vocabulary rule), 2-srv3-boot-action-diagnostic, 2-os-install-generic-naming. Near-miss, owned: the deduction-a owner string was fabricated from the sibling's pattern where my read had truncated it — caught before commit by diffing the removed lines, restored to the true value (zesty-bat-588, the same dispatch batch). The rule stands: a field the source states is copied, never patterned. ROADMAP.md regenerated; battery green BEFORE commit (incl. hold witness). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * W2-bulk tranche 20: ts-ui-model — the sheet's largest blob, and the migratable frontier CLOSES The 6,223-char verdict specimen decomposed: the five phases + D1-D5 as the brief (budget census fired at 123 words pre-commit — the split chain working — trimmed under the bar), the candidate AcceptedWithResidue verdict as current_state with MERGE IS NOT DONE preserved, the full receipt battery as red_control, the named residues and arcs as out_of_scope, the verdict itself as handback (the operator's three questions set the status). One honest time-axis correction, dated rather than silently rewritten: the P3 flex-container residue ("deferred, unverifiable without a browser") has since been DISCHARGED — the remodel round-5 head line and #7234's RoadmapRow archetype are its discharge, with the operator as the browser. With this row every AuthoredLine on the sheet is dispositioned: MIGRATED (the ticket corpus), TYPED-HELD (13, the re-sweep worklist, witnessed), DECLARED BY SHAPE (closed receipts + one-sentence rules), or OPERATOR-SIGNED (5, never edited under a signature). ROADMAP.md regenerated; full battery green BEFORE commit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Brian <briansrls@MacBook-Pro.local> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…s debugging it surfaced (supersedes #7162) (#7216) * D0 retention-truth close-out: unpin compile-clean memo, register all-hit keys, arm from loader closure The three post-merge retention defects from the ci-two-tier-placement-redesign §5 review (routed to the #7129 worker) plus the two §7 acceptance controls. Sequenced first: the falsifier cannot go green — and no downstream placement row can cite true retention receipts — until these hold. D0.1 — compile-clean aggregate memo unpin. The whole-tree gate resolved through resolved_graph_from_sources_with_index, pinning the aggregate ResolvedGraph (hence every TypedModule) in resolved_graph_memo for the process lifetime — a large slice of the measured 9.2GB resident floor. Thread a ResolvedGraphMemoShare::{Memoize,Ephemeral} flag: the gate resolves Ephemeral (no aggregate pin); per-entry discovery keeps memoizing. The per-module typed-cache warming that IS the gate's purpose is unaffected. D0.2 — prewarm all-hit registration. try_reconcile_all_cache_hits assembled and returned on all-hit WITHOUT index_record_schedule_module, so a prewarmed run armed retention referencing nothing (completion reported evictions while removing nothing). Record each confirmed hit in the probe, same key forms as the slow path. D0.3 — arm from the loader's exact closure (the #6985 Class-B root, third appearance). Arming used selection_adjacency; the discovery loader load_sources_for_entry_with_pool reaches wider via qualified-projection references from import-bearing files, so those modules were re-cached after eviction and never re-evicted or counted — an invisible resident leak. Arm from the loader itself (not a re-derived BFS that could become a fourth divergence); cost-neutral because the loader memoizes into entry_closure_sources, which discovery reuses. Removed the now-dead selection_closure_live_paths_with_facts. D0.4 — the two §7 acceptance controls. index_schedule_entry_completed dropped the resolved-graph pin unconditionally, so the eviction-disabled retain-all baseline understated peak retention; gate it on evict_enabled. The E2E control armed BEFORE prewarming (the order-blindness that let D0.2 pass green), so it never exercised the all-hit probe; restructure to prewarm -> clear graph memo -> arm -> re-resolve through the probe, and add a real-index retain-all RED. Verified green by execution: 7/7 schedule_retention tests, incl. the two restructured REDs (E2E arm-after-prewarm; real-index retain-all). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * D3 mechanism: two-tier CI placement axis (PrTier | Gauntlet) with fail-closed admission The placement-axis half of ci-two-tier-placement-redesign.md D3, buildable ahead of the D2 srv warm-cost probe. Placement is modeled as DATA (Placement = PrTier | Gauntlet), never per-site prose, with a FAIL-CLOSED admission law: a check is admissible as PrTier only with (a) a measured warm-cost receipt within the fast-lane budget AND (b) a hermetic/ephemeral classification; unmeasured or unclassified => inadmissible as PrTier, so its only valid placement is Gauntlet. No row rides the fast path by taste. The 5s threshold is REUSED from the single fast-lane authority (gunbc_ci_fast_lane_eval_budget_ms, v2.workflow.ci_floor_plan) — never a second 5s definition (DESIGN §3). Verified green by execution (claim_batch, 4 witnesses): - Gauntlet always admissible - a within-budget hermetic PrTier admissible - RED control: an over-budget (6000ms > 5s) PrTier is refused - RED control: an unclassified PrTier is refused The controls pin the threshold discriminatingly (1600ms admits, 6000ms refuses) and the classification gate (Hermetic admits, Unclassified refuses). Deferred to PR-1 (D2-gated): filling the roster of real checks with measured receipts (flipping rows to PrTier as srv warm-cost lands), wiring the law onto the live check rows, and the Gauntlet workflow split (D3b). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * D5 DiffBaseline: dissolve the origin/main literal into a typed single authority Per ci-two-tier-placement-redesign.md §11. Introduces DiffBaseline (MergeTarget | PushParent | OperatorOverride{ref}) as the single authority for "which git ref a diff/merge selects against", grounded on the extdeps.git atoms (GitRef, git_remote_ref_parts). resolve_diff_baseline is a pure, fail-closed fold over injected env values — a PushParent with no parent ref REFUSES rather than fabricating a ref. Live consequence fixed (site 1, floor selection): a stacked PR now selects against its real merge target (origin/$GITHUB_BASE_REF), not origin/main. DiffPolicy.base becomes a DiffBaseline; floor_diff_observe.floor_resolved_base resolves it at eval time from GITHUB_BASE_REF, fail-closed to UnifiedDiffFail (the floor widens to the full corpus) on an unresolvable base — never a silent wrong selection. Fork dissolution (no behavior change) — sites 2/3/4 re-ground the same literal onto the authority: merge_admission_produce (merges into main), roadmap_dispatch_actuator (branches from main), ci_workflow Push/PR triggers (main). The ci_merge_base_ref alias and the dead ci_merge_base_diff_range are deleted. Also carries the parked miscite fix (rust_tests_removed_disposition -> commit_gate_rust_suite_removed_disposition) in DESIGN.md / design_document.dag / ci_spec.dag, per plan §3.3. Verified by execution: ci_diff_baseline_witness_test (6/6, incl. the discriminating stacked-PR pair and the PushParent-refuses fail-closed control); ci_spec_witnesses (fetch renders "origin $GITHUB_BASE_REF"; single authority); roadmap_dispatch_actuator_witnesses. ci.yml + DESIGN.md regenerated via main_wet (drift clean; the two floor/regen fetch lines now expand $GITHUB_BASE_REF). floor_diff_observe_witness_test runs green in the floor's wet mode; its eval-time env reads are unmockable under claim_batch strict-hermetic, a PRE-EXISTING harness limitation confirmed by a clean-tree stash run of the same witness (this change adds no new hermetic red). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Progress/observation P0: the event model, five laws, one glyph authority P0 of the progress-and-observation lane (docs/plans/progress-observation-design.md, operator-signed 2026-07-23; §6b/§6c doctrine from #7169 folded in). Model only — no renderer, no emit site touched. ObservationEvent = subject (a typed containment path: run ⊃ batch ⊃ entry ⊃ module ⊃ phase) × Begin | Step{k,n} | Concluded{outcome} × measured facts. Outcomes are a closed sum with Refused DISTINCT from Failed — the reference implementation conflates them, which is how a deliberate refusal reads as a crash. Grounded on existing authorities rather than minted: - ancestry reuses std.effect_grant.path_is_prefix (one prefix relation, not a second walk) - over-budget arithmetic calls std.temporal_effect.stall_budget_verdict - change kind projects from std.change.KeyedDiffHunk — no second added/modified/removed enum - glyphs extend std.symbols + extdeps.render.glyphs rows (the one table), never a fork - module_path/source_path carry std's existing representation (std.decl_ref's), with convergence to QualifiedName/SourceRef declared, not assumed Derived, never hand-set: AttentionLevel from a supplied basis (the signed clamp constants — no threshold is invented in this module); BlockedOn from SchedulerHold, which is held in lockstep with the seed governor's HoldReason by execution; T from the heartbeat period the seed actually sleeps, declared a Scaffold with the measured quiet-time distribution as its dissolve-on. Construction over validation: the no-op sum is closed (docs-policy | uncovered | no-decls-touched | generated-artifact | departed-path), so a bare unlabelled "nothing" is unwritable rather than censused after the fact; uncovered derives a visible nudge, departed-path is typed as a widen and not a no-op. Green by execution, with discriminating REDs proven by perturbation: - 28 model conjuncts + 6 lockstep conjuncts PASS - orphaned law row (enforced_by names a missing declaration) → RED - Refused/Failed collapsed onto one glyph → RED (both distinctness and collapse laws) - glyph-table row perturbed → presentation moves → RED (single authority, by execution) Compile-clean attributed: the closure's 47 errors are pre-existing in std/measure.dag (46) and std/effect_grant.dag (1) — identical counts compiling those entries alone; zero attributable to this change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Review 42157: collapse the duplicate display tables into one authority Addresses the blocking finding on the three coproduct predicates, taking its stronger alternative (dissolve into the canonical surface) rather than only its weaker one (add a disposition receipt). The finding was right about the real defect: observation_class_is_intrinsic_anomaly was a second hand-written table beside observation_presentation, and a witness asserted the two agreed. That witness was validation standing exactly where construction was available — it conceded the tables could disagree and promised to notice. Fix: ObservationDensity (RoutineCollapsible | SummaryAlwaysShown | AnomalyExpanded) is now the one table. collapsible, expands_fully and intrinsic-anomaly are all derived projections of it, so disagreement is unwritable rather than detected. The three display states stay distinct — the run summary is neither routine nor an anomaly, which a single boolean would have forced it to borrow. Disposition receipts added for the remaining structural readers, matching the cited materialization_ladder pattern: outcome/class, subject/grain/hold, and selection no-op. Each states why it is Terminal and names its discriminating corpus rather than asserting terminality. Witness roles now separated and both proven by execution: - w_density_is_the_single_display_authority — the content check; reds when a class's density changes (verified: ClassRefused → RoutineCollapsible reds it, and reds ONLY it, since the projections cannot disagree) - w_presentation_projects_density_rather_than_restating_it plus the two collapse witnesses — construction guards; red when the presentation stops projecting density (verified: hardcoding collapsible: true reds all three) Full suite green: 30 model conjuncts, 6 lockstep conjuncts. Compile-clean unchanged — 47 errors, all pre-existing in std/measure.dag (46) and std/effect_grant.dag (1), zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Review 42166: ground PSI avg10 on std.measure.BasisPoint The finding is correct and the hard-blocker applies: avg10_centi was a percentage magnitude with a scale carried on bare Nat, and the note beside it self-justified the conflation rather than tracking it. Fix consumes an EXISTING carrier rather than minting one, which the corpus had already asked for in advance. std.measure.basis_point_dissolve_on warns: "else a third dimensionless-ratio use-case mints a third nickname" — this module is exactly that third use-case, so minting PerMille or a Percentage quantity would have walked into the failure the row names. BasisPoint's own note declares its semantic axis as utilization ratios, which is what a PSI stall share is. Resolution is exact rather than truncated: the governor reads one decimal of a percentage and a basis point is a hundredth of a percentage point, so 37.5 percent is 3750 with nothing lost. Percent (Dimensionless, One) would have truncated it. Note rewritten to state the grounding and the deliberate non-mint, replacing the self-justification. When the Ratio<Scale> unification that dissolve-on calls for lands, this field follows Percent and BasisPoint onto it with no change of meaning. Suite green: 31 model conjuncts, 6 lockstep conjuncts. Compile-clean unchanged — 47 pre-existing errors in std/measure.dag (46) and std/effect_grant.dag (1), zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Piece 3: derived per-batch floor clamp — delete the static wall-budget list Per ci-two-tier-placement-redesign.md §9.8 (operator 2026-07-24). Replaces the hand-set gunbc_ci_floor_batch_wall_budget_seconds list — a scalar wall budget that conflated workload size (diff-proportional selection), host speed, and per-unit cost creep — with a per-batch clamp computed at run time: clamp_ms = overhead_seconds*1000 + runtime_unit_count * per_unit_ms. The load-bearing row is the discovery witness batch (index 2): 300s + 1000ms per witness, so a full corpus of ~2316 witnesses clamps at ~44min (under the 55-min step cap, with headroom over the observed 1344-1629s walls) while a runaway reds proportionally, instead of the fixed 1320s that redded legitimate hub-file PRs. Fixed-count gate batches carry rate 0 at their measured basis; index 3 (wet corpora) stays a declared fixed overhead pending the D2 probe's wet-per-witness rate. Authority: gunbc.ci_spec FloorBatchClamp + gunbc_ci_floor_batch_clamp_params (index-aligned to the 7 batches; the cover-schedule witness pins the alignment) + gunbc_ci_floor_batch_clamp_note (carries the raise discipline from the kept static-era note). The 5s per-WITNESS max is unchanged — still the single gunbc_ci_fast_lane_eval_budget_ms authority, never redefined here. claim_executor reads the two index-aligned param lists fail-closed, derives the per-batch unit count from batch_results (corpus_witnesses for discovery aggregates, 1 per gate row — the runtime datum the static list ignored), computes the clamp at enforcement, and refuses over-clamp as a typed FLOOR-BATCH-OVER-BUDGET (never a widen). The GUNBC_FLOOR_BATCH_BUDGET_TIGHTEN_MS RED-control hook now lowers the COMPUTED clamp. The receipt emits batch_N_units / batch_N_clamp_ms / verdict; its unit test is updated. Both run_walk call sites carry the new param. Verified by execution: build clean; ci_floor_plan_witnesses green (the three new clamp witnesses + cover-schedule). The receipt verdict unit test and the fixture RED control (budget_red_control_plan; TIGHTEN_MS=0 -> clamp 0 -> the FLOOR-BATCH-OVER-BUDGET refusal) are the e2e enforcement confirmations; the fixture's control witness triggers a whole-tree emit that OOMs alongside a compile in this container, so both run as a clean post-commit confirmation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Finish #7146 adoption: regen ci.yml from merged authority, drop orphaned D5 witness The merge that adopted #7146's landed gunbc.diff_baseline (and dropped my redundant D5 gunbc.ci_diff_defaults) left two remnants: - .github/workflows/ci.yml carried an auto-merge artifact — the regen step and floor step fetched `origin $GITHUB_BASE_REF` (my dropped D5's bare-var form) instead of `origin main` (#7146's authority, which resolves the diff baseline at floor eval-time via resolve_diff_baseline, not at fetch time). Re-running `gunbc ci` regen re-derives ci.yml from the merged ci_workflow.dag, restoring the `origin main` fetch. - src/v2/test/claim/ci_diff_baseline_witness_test.dag imported the deleted gunbc.ci_diff_defaults module (my D5 authority), which would break the corpus compile. Its 6 witnesses are strictly superseded by #7146's landed dag/test/claim/diff_baseline_witness_test.dag (11 witnesses, with stronger fail-closed semantics on PR absent-base). Deleted as dead weight. Co-Authored-By: Claude <noreply@anthropic.com> * P1: the CI-log renderer, with the captured crawl window as its acceptance Second phase of the atomic P0-P3 observation PR (operator ruling: only finished work merges; a landed event model with no renderer is vocabulary nobody can see). gunbc.observation_ci_render projects the std.observation stream into append-only log lines. It computes nothing and holds no telemetry source — every number it prints arrives in an event or a heartbeat sample the process already had — which is precisely what makes replaying a real captured run possible rather than a synthetic fixture. FLAGSHIP ACCEPTANCE, green by execution: the fixture is run 30044816605's actual log, not a reconstruction. Its heartbeat at t=33m carried current=16107200512 swap=34359738368 psi_some_avg10=9.01 and named no subject at all, while the process sat inside v2.compiler.normalized_tree for 606984ms and disclosed that only at walk end. Re-rendered through the escalation law the same window produces named activity: identity-first heartbeats in human units (15.0 GiB, not the raw byte dump), the quiet module surfaced at T, and the memory-reclaim cause surfaced at 2T. Contracts from section 6b in force: plain-sentence tone, real emojis from the one glyph authority with the clock pulse, identity before vitals, durations on every outcome line, refusals restated at the end so log truncation cannot hide them, and relayed subject text neutralized through the existing GitHub guard so a child's stderr cannot mint workflow commands in the parent run. Law 4 made structural: line placement is DERIVED from attention, so a refusal cannot be written into a collapsed group — the group is exactly where a reader will not look. Escalation has two rates: reveal depth grows linearly (one tree level per threshold) while emission points double (T, 2T, 4T), so a window that stays quiet escalates without becoming a per-minute drumbeat, bounded by construction. Three REDs proven by perturbation, as the ruling requires: - planted silent phase (escalation never emits) reds responsiveness - an orphaned Begin reds the watchdog - a Refused placed inside a collapsed group reds Review 42203 (three findings, all correct, all fixed): - ci_gibibyte_tenths respelled the GiB scale factor as a literal; it now consumes std.measure.gibibyte_scale_factor_bytes, and the duration helper consumes seconds_per_minute plus a new milliseconds_per_second added beside its siblings in that authority. A unit authority forked inside a formatting helper is easy to miss because it looks like arithmetic. - the run summary picked the refused glyph whenever refusals+failures>0, so a failures-only run rendered as refused — collapsing at the last line exactly what the outcome sum exists to establish. Failures now dominate the glyph, refusals keep their own, both counts stay in the text. - an unavailable duration silently vanished from concluded lines, breaking the model's own rule that an absent measurement names its cause. It now says so. Each fix carries a witness; the summary fix carries its own RED. Suite green: 31 model, 6 lockstep, 18 renderer conjuncts. Compile-clean unchanged at 47 pre-existing errors, zero attributable here. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * P2: the interactive TTY renderer, a sibling projection of the same carriers Third phase of the atomic P0-P3 observation PR. gunbc.observation_tty_render projects the SAME std.observation stream the CI renderer projects — a sibling, not a successor and not a second model. The two differ only where the medium differs: a terminal can be repainted, so routine progress overwrites one line in place and stays quiet; a CI log cannot, so it appends. Everything they share — the event vocabulary, the density authority, the glyph table, the duration/byte/percent projections, the hold-cause text — is imported from the CI renderer or the model, never re-derived. A witness proves the sibling property by execution: the same event drives both surfaces and moves together. The three upgrades over the reference implementation are INHERITED from the shared carriers, not re-earned: outcome lines carry durations, Refused is distinct from Failed, and dwell escalation is recursive. The reference has none of the three; the TTY renderer gets them for free by projecting the same model. Law 4's asymmetry, expressed here as cursor action rather than group placement: repaint-vs-scroll is DERIVED from attention, so a refusal cannot be repainted away — overwriting it would erase it the instant the next line arrived, the terminal form of burying it in a collapsed group. Required preamble (no anonymous process), BlockedOn inline with named remaining (a bounded estimate prints the time; an unknown one prints why, never a fabricated ETA), and the reward animal on Final drawn deterministically from the one glyph authority so replay is preserved and a non-emoji terminal degrades to a word. Also in this commit: the self-host regen of the seed. P1 added milliseconds_per_second to dag/std/measure.dag, a seed-emitted module, so src/v1/stage0/src/std_measure.rs is regenerated to match — the required same-PR regen for a generated-artifact source edit. Fixed point verified by rebuilding regen_stage0 from the new seed and re-running to zero drift. Suite green: 31 model, 6 lockstep, 18 CI-renderer, 10 TTY-renderer conjuncts. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * P3: the emit-site census wall Fourth and final phase of the atomic P0-P3 observation PR. gunbc.observation_emit_census is the census authority. Every place the floor emits a progress line is either a projection of the observation event stream or a counted frontier row with a reason and a dissolve-on — the same discipline the site lane uses for unthemed colours. EmitSiteDisposition is a closed sum, so a site cannot be half-classified, and there is no third arm for a site the census has not looked at: the roster's completeness is what the witness checks against the seed. The roster carries the structured-tag emit families that exist regardless of the CI rework: [floor-memory], [typecheck-attribution], [gantt], [governor], [measurement]. The named negative example the operator called out — the [floor-memory] raw byte dump — is a rostered frontier row, so the census already carries the very site it exists to kill, with its dissolve-on naming the P1 heartbeat projection that replaces it. Sequencing per the ruling and design section 6b: the CI two-tier rework rewrites the floor's emit sites, so the exhaustive per-print wall over the ~75 raw eprintlns in claim_executor is a declared frontier gated on this PR rebasing over that rework and re-censusing. Censusing sites about to be rewritten is the double-churn the operator ruled out. What lands now is the census model, the roster, and the executable hygiene witness — never a hidden zero: five families migrated-pending, the raw-print residue counted, and the witness holding the roster against the seed so it cannot rot into a lie. Executable, not inert: the witness reads the live seed and reds when a rostered marker has vanished (staleness — proven by a RED control) or when a frontier row lacks a real dissolve-on. The [floor-memory] shape is checked positively — still present, still classified frontier — so the census cannot quietly drop it. This completes P0-P3. Full suite green by execution: 31 model, 6 lockstep, 18 CI-renderer, 10 TTY-renderer, 6 census conjuncts, each with discriminating REDs proven by perturbation. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Piece 3: name the clamp coefficient's measurement basis (operator addition, 2026-07-24) The 1000ms aggregate coefficient now records its basis in gunbc_ci_floor_batch_clamp_note: host class (srv arm64 self-hosted, capped) x the adaptive governor's realized worker width, denominated against the observed 0.58-0.70 s/witness (the 1344-1629s full-corpus fleet envelope over ~2316 witnesses). Naming the basis makes a future width or fleet change a deliberate re-sign of the constant, never a rediscovered fleet-wide red; the ~1.4-1.7x headroom over the observed top rate is exactly the >=~1.6x runaway the clamp catches, with sub-threshold creep owned by the gauntlet's per-cadence s/unit receipt. Co-Authored-By: Claude <noreply@anthropic.com> * Probe (①/②): emit a per-gate warm-cost TSV from the floor's existing timings Instruments claim_executor with write_gate_warm_cost_receipt — one row per gate/claim (eval wall + resolve + combined warm_ms) and a discovery row carrying the per-witness rate — derived from the ClaimResult timings the walk already records (operator ruling 2026-07-24: instrument the existing floor, no throwaway probe workflow). Written to target/floor-gate-warm-cost-receipt.tsv and mirrored to the log as [gate-warm-cost] rows so the placement probe lifts it from get_job_logs on a fleet run. This is the placement roster's measurement basis: a gate rides PrTier only if its measured warm cost is within the 5s fast-lane budget, else fail-closed to Gauntlet (v2.workflow.ci_placement). Every floor run now auto-emits it; run cold-then-warm on >=2 hosts and the roster records value + host basis. Verified green-by-execution locally (single-claim row); the discovery-row path verifies in the next full-corpus CI floor. Fail-closed on a write error, consistent with the other floor receipts; never a verdict term. Co-Authored-By: Claude <noreply@anthropic.com> * Flagship replay as a green witness — the before/after made executable The operator's "show me": proven-by-witness without a visible sample is the fluent-but-unseen trap. dag/test/claim/observation_crawl_replay_test.dag renders the captured crawl window of run 30044816605 through the P1 CI renderer as one assembled block and asserts it by execution: - names the module where the capture was silent ("still in witness discovery: entry 214 of 602, now typecheck v2.compiler.normalized_tree", surfaced at T, the memory-reclaim cause at 2T) - uses human units, never the raw byte dump (15.0 GiB, not 16107200512) - ends in a named refusal summary, not a silent 55-minute timeout observation_crawl_after_block() is the exact function the PR body's after-sample is produced from, so the pasted before/after is a projection of a green run rather than prose. Every input number is read off the real log. The earlier gunbc/observation_crawl_demo.dag (a run-entry that returned a String and so errored on the ProcessExit contract) is replaced by this witness — a green check is worth more than a run-entry that prints then fails. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * Wiring flip (1/n): install the output policy BEFORE the naming walk — kill the [file] firehose The floor's [file] read firehose (2265 lines / ~99% of the log, measured by execution) was the pre-plan naming-hygiene walk reading the whole source tree at the OutputDecision Full default, because install_output_policy ran AFTER the walk (claim_executor.rs order). gunbc.output_policy already models Instrumentation => Suppressed at Normal (CI's default verbosity) and ShellTrace => Condensed — the walk just never saw the policy. Fix: install the policy (and group syntax) FIRST, before the naming walk and every subsequent corpus read, so all host-effect traces are funnelled per the .dag authority. Verified by execution on the minimal smoke plan: [file] read 2265 -> 0, total log 2613 -> 24 lines, claim still PASS (exit 0). The Ambient semantics hold — the policy's divergence rule (ExpectedOutcome/ObservedOutcome) still expands a captured stream on failure, so a red effect is never silenced; only the green firehose is. This is the highest-leverage lever of the observation-emit census flip (the echo class the census targets). Follow-on commits route the display families ([floor-memory], [gantt], [governor], [measurement], [t+..]) through the observation stream as Ambient projections (the ✅/🕐/🚫 format matching #7168's "after" block). Co-Authored-By: Claude <noreply@anthropic.com> * Wiring flip (2/n): render floor phase marks through the observation authority Step 2 of the flip (format), after step 1 (the [file] firehose, volume). The prelude phase marks are the visible display class in the short regen job's log; they now render through the single-authority observation renderer instead of a raw [t+…] byte string the seed would fork the format into. before: claim_executor: [t+86.1s] naming-hygiene walk complete after: ✅ naming-hygiene walk done in 48 seconds - New seed→.dag boundary gunbc.observation_seed_render: primitive args in, a rendered line out — exactly as cli_run.install_output_policy calls output_policy.resolve_channel_policy. A phase concluding is modelled as a Concluded event on a PhaseSegment subject, projected by ci_event_line ∘ ci_render_line, so the FORMAT stays single-authority in gunbc.observation_ci_render and the seed constructs no format of its own. - The raw [t+{:.1}s] eprintln is DELETED, not suppressed (grep-clean for the print). §5: on a renderer-unreachable failure the arm names the degradation loudly and never reproduces the old marker. - Per-phase walls (delta since the last mark), not a running t+, so the log itemizes which prelude phase is slow — the step toward the per-phase receipt keys the ci_spec prelude-coverage-hole follow-up (row a) calls for. - Green by execution: phase_mark_renders_through_the_observation_render_authority resolves the adapter through a real interpreter and asserts human units + the completed glyph + NO [t+ marker (the discriminating RED). The seed→.dag resolve is memoized, so the renderer resolves once and later marks are cache hits. Rust-called-.dag-unimported has precedent (output_policy.dag). Next in the series: the rostered census families. floor-memory (the flagship byte dump) needs its subject feed plumbed first so it renders honestly (entry X of Y, never a fabricated 0 of 0), then gantt/governor/typecheck-attribution, each flipping its census row (CountedFrontierSite → MigratedToObservation) with the witness restructured to assert the raw marker is gone — the "witness fixes" step of flip → witness fixes → roster. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Witness fix: roster the observation stack's one wildcard site (non_fold_residue) The progress-and-observation merge (#7168) added observation_ci_render.dag, whose ci_hold_cause_text names the two memory-pressure SchedulerHold variants specifically and gives the other five a generic cause via a top-level wildcard arm — a non_fold_residue site. It landed unrostered because per-PR affected-set selection predict-skips the corpus-read nfr witness (the masking class the roster's dated rows document), so it reds only on a cold whole-corpus sweep (falsifier / merge-to-main), not on the selected PR floor. That is the census wall doing its job on its own author. Roster it (gunbc.non_fold_residue, one FrontierRow, reason + dissolution trigger toward a total match), matching the established masking-class fix and preserving the observation author's design. Green by execution: observation_hold_cause_wildcard_is_rostered asserts the live roster now carries dag/gunbc/observation_ci_render.dag::ci_hold_cause_text via the same host reader the corpus scan uses — reds if the row's key drifts from the scan's {rel}::{fn} key or the hand edit malformed the 126-row list. design_register_lift_parity (the other cold-red thought to be surfaced by the merge) is NOT touched: this branch's gunbc.site.* inputs are byte-identical to main and recent main-push runs are green cold, so it is green here too — not attributable to this PR. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Wiring flip (4a/n): the floor-memory heartbeat's seed oracle + golden strings Foundation for migrating the [floor-memory] byte dump to the observation heartbeat. Adds gunbc.observation_seed_render.seed_heartbeat_line: the seed→.dag boundary that takes the primitives the heartbeat thread has (elapsed, batch label, entry position, memory vitals) and projects them through the one renderer (ci_heartbeat_line ∘ ci_render_line) — identity first, human units, no raw byte dump. The subject is batch-grain by construction: the floor walks entries in parallel, so there is no single active module to name, and the primitive interface carries none — never a fabricated per-module "now typecheck X". Green by execution: seed_heartbeat_line_renders_identity_first_in_human_units pins the exact bytes for two samples through the real interpreter: 🕐 33 minutes in — still in witness discovery: entry 214 of 602. memory 15.0 GiB, swap 32.0 GiB, pressure 9.0% 🕐 500ms in — still in self-host fixed-point: entry 0 of 2. memory unreadable (cgroup field unreadable), swap 0.0 GiB, pressure unreadable (cgroup field unreadable) The first is the captured crawl window re-rendered from the seed's own vitals (raw byte value absent); the second proves an unreadable cgroup field names its cause, never a fabricated zero (observation law 2 / §5). These golden strings are the oracle the Rust mirror is proven byte-equal to in 4b. Why a Rust mirror next, not an interpreter call: the heartbeat runs on a detached liveness thread in a memory-constrained context — resolving the renderer there would build a duplicate module index, consuming the very memory it watches (§2), and the thread exists to stay alive when the main interpreter is busy. 4b adds that mirror (proven == this oracle), plumbs the subject feed, wires it, deletes the byte dump, and flips the census row. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * File finding: shell.Env.Get realized as a printenv subprocess (transport-decomposition lane) Operator-directed finding (2026-07-24), do-not-fix-here. Records in the residual-shell census (§0b) a class distinct from that doc's shell-EMISSION axis: modeled ops whose interface shape is right but whose single hardwired transport is a shell escape where a NATIVE in-process handler is correct — the verbatim §3(b) N×M-adapter tell. shell.Env.Get (extdeps/shell/shell.dag:42) reads an env var the process already holds in its own environment by spawning `printenv` (wet_env_var, v1_interpreter.rs:5096). Reading your own environment is not a host effect; std::env::var is the native handler, chosen when locality is OnTarget, with shell/ssh reserved for a var on another host. Sibling: shell.Which.Check (`command -v`), already in the census. One root, three lanes. Not a floor-time lever (~ms/spawn); filed so the deficit is counted and prioritizable (§6), never absorbed into "it's only a few ms." Its native read is the lane's cheapest first consumer (a pure in-process read, no host_effect_apply even). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Wiring flip (5/n): shell-echo §5 split — routine Ambient, failure Anomaly self-describing The [shell]/$ echo class still printed at Normal after the firehose fix: it is the ShellTrace channel at Condensed, not the Instrumentation channel that [file] read rode. But naive "suppress ShellTrace at Normal" is a §5 fail-open — the failure stderr block rides the SAME channel via trace_emit(), so Suppressed would silence failures too. That Condensed was load-bearing. Root (operator's naming): one channel carrying two content classes with OPPOSITE attention — routine scaffolding (Ambient) and failure evidence (Anomaly) — a state-space conflation at the channel grain, exactly what the observation model dissolves by deriving attention per event, not per channel (law 4: routine collapses, anomaly expands). The fix uses the two EXISTING mechanisms, each governing its class — no third decision mechanism: - Routine ($ argv pre-spawn echo + [shell] done exit=… count) → the ShellTrace CHANNEL → Suppressed at Normal (Instrumentation's debug-only shape), Full at Verbose. - Failure evidence (stderr block) → the effect_stream DISPOSITION (SurfaceContent) ALONE, not the channel, so suppressing the routine echo cannot silence a failure. Two upgrades the disposition-gated block gains, both §5-correct now that the count is silent at Normal: 1. SELF-DESCRIBING — the block carries its own `$ <argv>`, so the failing command never scrolls away from its stderr (the pre-spawn echo it used to borrow from is gone at Normal). Strictly better than what suppression would have taken away. 2. SURFACES ON EMPTY STDERR — the block names the exit even when the command wrote nothing, because the routine count that used to carry the exit is now silent. Proven by execution: four-corner effect-stream suite kept; new discriminating RED at_normal_a_failing_effect_surfaces_its_command_a_passing_one_is_silent (passing → None; failing → `$ <argv>` + stderr) + stderr_block_surfaces_on_surface_content_even_with_empty_stderr. Channel witness updated (w_shell_trace_routine_is_debug_only: Suppressed at Normal). Convergence named in output_policy.dag: when shell effects become observation events, trace_emit(channel) stops being the gate and derived attention replaces this split. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Revert "Wiring flip (5/n): shell-echo §5 split" — approach was wrong, unbreak the branch This reverts commit 60a4496. Two defects, the second fatal to the approach: 1. Parse break (caught late): the witness carried `//` comments, but daglang has NO line-comment syntax — documentation is `data …_note: String` only. build_module_path_index scans every .dag at install_output_policy startup, so the parse error panicked the whole floor, not just that witness. LESSON: verify .dag by execution before pushing; a Rust-lib test does not exercise the .dag parse/resolve path. 2. The approach itself was wrong (the real reason for the full revert). Making ShellTrace Suppressed at Normal does not just silence the routine echo — effect_stream_disposition is GATED BY channel_decision: match channel_decision(channel, verbosity) { Suppressed => StreamSuppressed // failures silenced Condensed => divergence_disposition(…) // divergence surfaces, agreement counts Full => SurfaceContent } So Condensed-at-Normal is load-bearing TWICE (trace_emit AND the divergence disposition), and host-effect grouping keys on the same channel. Suppressing it is a §5 fail-open (a real failing effect's stderr goes silent at Normal); the Rust test passed only because it read the hardcoded EFFECT_STREAM_POLICY_FALLBACK, masking the installed-policy break. The alternative (route routine → Instrumentation, keep ShellTrace Condensed) leaves empty `##[group]` brackets and buries the failure block inside the collapsed section. FINDING for the redo: the channel↔disposition↔grouping coupling IS the "one channel, two content classes" conflation the operator named — and there is no clean immediate fix that does not touch it. The correct fix decouples the failure disposition from the routine channel verbosity (the "bigger lift" flagged as needing a design steer), which lands back at the operator's "Hold — I'll steer". The self-describing failure-block design (carries its own argv, surfaces on empty stderr) is sound and preserved in 60a4496's history for reuse. Branch returns to the green b35a4b3 state. Shell-echo goes back to HELD pending the disposition-decoupling design decision. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TUqWZP4HTVyUfW4qRqWya1 * Wiring flip (4b/n): floor-memory heartbeat via render_heartbeat_line_mirror Flagship of the observation wiring flip: replace the [floor-memory] raw byte dump with the identity-first 🕐 heartbeat, proven byte-equal to the 4a seed oracle (seed_heartbeat_line). - render_heartbeat_line_mirror: pure Rust mirror of ci_heartbeat_line ∘ ci_render_line — the heartbeat thread cannot call the interpreter (duplicate module index under the memory envelope it watches). Discriminating RED render_heartbeat_line_mirror_matches_seed_oracle pins byte-equality on the crawl-window and unreadable-field goldens. - HeartbeatFeed (cli_run): process-global batch label + entries done/total, armed only when entry_total is known and non-zero (never a fabricated 0-of-0). Updated at batch-enter and at the existing index_schedule_entry_completed per-entry point (SingleClaim path increments per claim result). Discovery fills the total once the roster's entry-group count is known. - Delete the byte dump; keep the regime-disclosure line (marker stays for census hygiene). Flip floor_memory_site → MigratedToObservation; restructure census/lockstep witnesses (frontier 5→4, dump shape asserted gone). - Also: strip invalid // comments from output_policy_witness_test.dag that the shell-echo §5 commit left (dag has no // comments — parse Slash). Co-Authored-By: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * cargo fmt: claim_executor + cli_run after floor-memory 4b / main merge CI build failed at the fmt --all --check gate (assert_eq! wrapping + HeartbeatFeed Mutex.lock() chain). No behavior change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Wiring flip: [gantt] → Begin/Concluded PhaseSegment observation projection Compile-path trace_mark and GUNBC_FLOOR_GANTT emit through phase_begin_line / phase_concluded_line mirrors (byte-equal to the seed oracle; interpreter render from inside compile would recurse). Census row MigratedToObservation; raw t_ms/rss_mib shapes gone. Frontier 4→3. Verified via claim_batch on observation_emit_census_witnesses. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Wiring flip: [governor] → ci_hold_cause_text / StatusBlocked observation projection HoldReason emits through seed_governor_hold_line (mirror render_governor_hold_line_mirror); hard/creep/receipt/startup lines lose the raw [governor] key=value shape. Census MigratedToObservation; frontier 3→2. Mirror↔oracle byte equality for PsiPressure and CurrentHighWater. Verified via claim_batch + memory_governor unit tests. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * cargo fmt: claim_executor after governor hold oracle RED Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Fix runtime_rust.dag: escape Rust format braces for daglang parse daglang treats {ident} inside string literals as interpolation; the gantt mirror's format!("{glyph}…") (and use std::sync::{Mutex,…}) panicked the regen self-compile. Escape as \{…\} so the emitted Rust keeps real braces. Emitter twin resynced; byte-equal to v1_rt.rs. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Wiring flip: [typecheck-attribution] → ModuleSegment+PhaseSegment observation Per-module typecheck Begin/Concluded via typecheck_*_line mirrors (render_typecheck_*_line_mirror); 2s pathology threshold preserved. Census MigratedToObservation; frontier 2→1. Mirror↔oracle RED for the captured crawl fixture module. Verified via claim_batch. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Wiring flip: [measurement] + shell-echo → ObservationEvents (one pass) Measurement peak-RSS/cgroup dumps project through ci_measurement_rss_line (seed_peak_rss_line ↔ render_peak_rss_line_mirror; identity-first, human GiB). Shell host-effects become ObservationEvents: Ambient Begin/Done still gated by ShellTrace; Anomaly Failed gated by effect_stream disposition alone (never silenced by ShellTrace Suppressed), with law-4 idempotent group_end, self- describing `$ argv (exit=N)`, and empty-stderr surfacing. ShellTrace/ disposition tables left unread for the interim Condensed-at-Normal split. Census: measurement + shell MigratedToObservation; tagged frontier count 0; 76 raw eprintln residue recounted. Standing check: claim_batch census witnesses PASS before push. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Fix GeneratedArtifact name collision in observation_model witnesses Whole-tree compile-clean failed: bare SelectionNoOp.GeneratedArtifact collided with v2.std.artifact.GeneratedArtifact and gunbc.generated_artifact.GeneratedArtifact. Mint via selection_noop_generated_artifact in the defining module so the variant resolves unambiguously. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Observation aesthetics: named-intent shell, glyph discipline, census bidir, failure-receipt miss Operator live-log review (run 30142403230) — four pieces in one pass: - Shell subjects are typed service.op intents; argv only in Failed.error. Ambient ShellTrace is Suppressed at Normal (silent scaffolding); Anomaly still surfaces via divergence alone (Quiet no longer forces StreamSuppressed). - Governor receipt uses StatusPulse (not Done glyph); peak RSS / governor / cgroup wrap in one "floor receipts" group. - Census roster grows four CountedFrontierSite rows ([floor-drain], [gate-warm-cost], [receipt], [file]) with a bidirectional hygiene witness. - Undeclared *_failure_receipt companions (NoMainFunction) treat as empty detail instead of stuffing failure_receipt_refused onto ordinary Bool(false) reds. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * Silence Ambient shell on gunbc run; roster #7205 resolve/assembly split tags Merge-admission stamp is `gunbc run`, which never installed output_policy — so ShellTrace fell back to Full and every Ambient Begin/Done still printed despite named-intent subjects. Install policy + group syntax at handle_run startup (same as claim_executor). Census grows [resolve-split]/[assembly-split] frontier rows so #7205's new tags stay bidirectional. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * WIP: Floor #6848: memoize the per-entry bare-reference fixpoint so post-flip * Re-merge #7205 tip + native shell.Env.Get (kill printenv Anomaly clutter) Pull the two new #7205 commits (export_index canonical = fold element — kills the O(|bindings|^2) rescan). Route OnTarget shell.Env.Get through wet_env_var instead of printenv so optional floor_diff injections (GUNBC_CI_DIFF_*) no longer paint ❌ Anomaly Failed when unset — reading this process's env is not a host effect (§3(b) / shell-to-dag census 0b). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * infer_semantics: unstale the slice control after #7196 admitted list slicing #7196 (bb4347d, on main) deliberately extended `check_slice_access_node` to admit ordered element collections — adding `base_is_list`, widening the refusal arm to `base_is_string || base_is_list`, and returning the base type rather than String on the list arm. `invalid_slice_returns_compiler_error_type` still pinned the withdrawn refusal, so it asserted one diagnostic where the compiler now correctly produces none: assertion `left == right` failed left: 0 right: 1 The witness went stale; the compiler did not. Repointed the negative control at a `Map` base — `ordered_element_collections()` (std_types.rs) holds `List` alone, so a Map is neither String nor an ordered element collection and must still refuse — and added the positive control #7196 admitted but never witnessed: a `List<Int>` slice yields no diagnostic and preserves `List`. Reproduced locally before the change (identical left 0 / right 1) and green after. Both controls proven live by perturbation: restoring the `List` base reds the negative control, expecting `String` reds the positive one. Note on how this reached main green: the witness never ran there. It is a binary witness whose transport (dag/tools/infer_semantics_witness_transport.dag) declares no dependency on v1_compiler_infer_access.rs, so the affected set cannot see the edge; main's run at bb4347d observed an empty diff and skipped 1761 of 2373 witnesses, this one among them. That selection escape is a separate defect and is not addressed here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * gunbc run: add --arg name=value, the missing parameter channel at the .dag seam `Commands::Run` was zero-arity by construction: `run_in_context` (v1_interpreter.rs:1543) ends in `call_function(ctx, &item_node, &[], &env)` — an empty argument slice — while `run_in_context_with_args` has sat twenty lines below at :1564 the whole time, already used internally by claim_executor.rs:166. Only the CLI flag was missing. The consequence is repo-wide and stated in the corpus itself (dag/gunbc/roadmap_belt_actuate.dag:689): "gunbc run --function cannot pass an argument (there is no --arg flag), so the node id enters through the environment". Every value that must reach a `.dag` entry crosses as an environment variable instead — 34 live GUNBC_* names across 77 read sites, including intra-process uses where sender and receiver share a PID (floor_skip_discovery_witness.rs:112-127 set_vars a synthetic diff and reads it back in the same process). The environment wins by economics, not design: adding a modeled parameter costs an edit to `cli_run`'s 29,626 lines of SeedRetained hand-Rust, adding an env var costs one line on each side, and `NamespaceTree` (dag/std/effect_grant.dag:26-31) has no environment arm, so no grant bounds it and no lens counts it. Named-only by construction: a `.dag` entry's parameters are named, so positional order across the CLI boundary would be an unchecked coincidence. A missing `=` or an empty name refuses with exit 2 before the compile runs (§5) rather than guessing a position, and one malformed spec refuses the whole list — a partial parse would silently drop a caller's argument. Values enter as `Value::Str`; no coercion is fabricated here. One path, not two: with an empty --arg list `run_in_context_with_args` passes the same empty slice `run_in_context` did, so the zero-arity path is unchanged rather than branched around. Threaded through the emission authority (src/v1/05_emit_rust.dag:10270 variant, :10495 match arm) and its seed mirror in v1_compiler_emit_rust.rs so regen stays a fixed point. Proven by execution against the built binary, not by typecheck: --arg node_id=roadmap-7 -> ExitSuccess, exit 0 --arg node_id=wrong-node -> callee received "wrong-node" (the value transports, not merely the flag parses), exit 1 --arg node_id -> exit 2, "expected `name=value`" --arg =orphan -> exit 2, "empty parameter name before `=`" --arg ok=1 broken also=2 -> exit 2, whole list refused no --arg -> zero-arity path unchanged Plus six unit tests (three of them RED controls) and `05_emit_rust.dag` compiled through the real pipeline: 0 blocking errors. Known gap, not papered over: the unit tests run under `cargo test`, which left CI on 2026-07-11 (gunbc.commit_workflow rust_tests_removed_disposition). An enrolled floor witness for this channel is a follow-on. Retiring the parameter-shaped env vars onto this flag — GUNBC_BELT_NODE_ID, GUNBC_CI_DIFF_*, CI_FLOOR_EXIT — is also follow-on; this commit adds the channel, it does not yet migrate the callers. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * CI floor: give re-homed witnesses a real scheduled lane (FalsifierCadenceJob) Batch 4 breaches its clamp on every run of this PR — 571556ms (srv3-01) / 613864ms (srv2-02) against clamp_ms=420000 at units=74, authority gunbc.ci_spec gunbc_ci_floor_batch_clamp_params[3]. Both batch-4 groups PASS; it is the wall, not a witness. Per the operator ruling, six declared rows move off the per-PR floor to the 4-hour falsifier cadence: the three wave1_gate1_d_* rows (141s + 29s + 27s) and the three affected-set provenance walls (14s + 13s + 13s), measured in the run-30148859947 slow-witness tables. That removes ~237s of eval, landing batch 4 near 334-377s under the unchanged 420s clamp. The vehicle is NOT gunbc.ci_layer_roots falsifier_rehomed_bin_wet_rows. That roster is specifically the bin_witness_wet_entries per-row-budget overflow (constructor bin_wet, budget datum bin_witness_wet_per_row_wall_budget_seconds) and does not model CommitWitnessClaim rows; re-homing through it would mint a second re-home authority. Instead this extends the axis that already answers "where does this check run" — the enrollment surface — with a fourth variant, FalsifierCadenceJob, plus the batch that reads it. The batch lands in the SAME change as the surface deliberately: a surface tag with no consumer is enrollment-by-illusion, which is the state ~54 files under test/claim/long/ are already in (excluded from discovery at dir grain, not walked by the falsifier, enrolled nowhere) and it would present as a clean green diff. gauntlet_lane_enrollment_witness_test reds per-PR if a row ever sits on the surface without reaching a batch. Two entries split at the check_fn rather than moving whole, so each concern keeps per-PR coverage at the cheap grain and loses only the wet grain: affected_set_provenance_producer keeps its four <=161ms fns on the floor, parse_binding_fidelity keeps witness_resolve_distinct_param_bindings_holds. FOUND BY THE WALL, first execution: the doc-reachability witness (doc_graph_has_no_orphan_docs, doc_graph_has_no_dangling_links) rode surfaces: [GitPrePushHook] alone — enforced only by a mechanism this repo has already ruled is not an enforcement authority (opt-in per clone, bypassable with --no-verify, absent in container worktrees, proven ineffective by #6658). Orphaned docs and dangling links had no wall on any CI path. Fixed by adding the cadence surface, NOT by widening witness_enrollment_is_scheduled to accept the hook — widening the predicate until the failure disappears is the absorbing fallback, and would have re-buried the finding that surfaced it. Placement (PrTier | Gauntlet) is the intended end-state authority and is recorded as the dissolve-on, not wired here: PrTier is unwritable without a WarmCostReceipt whose measured_ms is within the 5s fast-lane budget, so wiring it onto all 36 CommitWitnessClaim rows needs a per-row measured receipt and the D2 warm-cost probe has not run. Fabricating those receipts is the fail-open the placement law exists to forbid; defaulting the unmeasured rows to Gauntlet would de-enroll all 36 at once. Encouraging convergence: the 5s law selects exactly the twelve rows measured over 5s and admits every other batch-4 row at <=1s, so placement and this surface agree on today's roster. dag_compile_clean_perturb_receipts_holds is deliberately NOT re-homed. It was retained by the 2026-07-23 ruling by name because it measured 53s, under the 60s per-row budget; it now measures 141s. Re-homing a row that got 2.7x slower answers the wrong question and would zero the deficit's frequency by construction. Its growth is diagnosed separately. Proven by execution: all three files compile clean (0 blocking errors); gauntlet_lane_enrollment_witness_test 3/3 green in 3ms, inside the fast lane. Both claims proven live by perturbation — reverting one re-home reds _rehomed_rows_are_cadence_enrolled_holds, and _is_never_bare_deenrollment_holds was RED against the live roster before the doc-reachability fix and green after. The RED control discriminates a synthetic bare de-enrollment. commit_witness_claim_roster_holds (the #7060 stale-pair class, live) PASS. No generated-artifact drift: the ymls invoke plan functions, so batches compute at run time and the falsifier picks up the new batch. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * CI floor: operator-signed interim clamp raise, batch 4 420s -> 540s Signs the margin ruling for the budget family, not just this number. A clamp was doing double duty: merge-refusal threshold ("this must not merge") and growth detector ("something got slower — look"). Tight margins serve the second job and demonstrably worked — perturb's 53s -> 141s growth was caught precisely because the clamp was tight. But they make the FIRST job fire on host roulette, and a breach meaning "you landed on srv2-02" trains the on-call to rerun, which is crying-wolf wearing budget clothes. Policy signed here: clamps are sized to cover MEASURED fleet spread, so a breach means content grew, never which host answered. The growth-detector job moves to per-row trend receipts on the falsifier cadence — that piece is what makes a wider clamp safe, and it is sequenced next behind the perturb diagnosis. Basis for 540: post-re-home projection 377s (worst observed wall 613864ms minus the ~237s the six re-homed rows carried) x 1.2 worst observed spread = ~452s, + ~20% policy margin = 540 (whole-minute grain). Run ids: 30148859947 @ 619bba5 wall_ms=613864 units=74 srv2-02; 30163496549 @ 9f87967 wall_ms=571556 units=74 srv3-01 — identical content, 7.5% apart, which is the spread this funds. Enrollment that grew the batch: NONE. Batch 4 shrank this cycle (units 74 -> 68). The raise buys spread coverage on a batch that got smaller. Not the forbidden widen: batch 4's per_unit_ms is 0, which the clamp note already calls "a declared calibration gap, not a hidden default". 540 funds that gap with a dated, dissolving interim rather than leaving a flat rate to fire on variance. It refuses exactly as before — only the threshold moved, on a stated measurement, not to make a red go away. Dissolve-on: the perturb diagnosis lands (141s = 38% of the remaining batch; returning it toward its 53s basis puts worst case near 350s, under even the retired 420) AND the D2 per-unit rate replaces the flat clamp. The wet-receipt 600s budget (the 707s falsifier red) has the same disease — ten-day-stale basis, zero spread allowance — and the policy above governs it, but its NUMBER is deliberately not moved here: it is gated on its own sccache-vs-growth attribution so the dosing lands with a measurement rather than by analogy. Host spread is not weather: srv1/srv2 still run pre-#7213 sccache units and are typed expected-latent-defective until re-provisioned, so part of the 7.5-20% collapses when the fleet lane re-converges them. Proven: ci_spec compiles clean; witness_floor_batch_clamp_params_cover_schedule, _overhead_all_positive, _rate_all_nonneg all PASS. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * Extend the falsifier batch-count pin for the FalsifierCadenceJob batch 779e9dc appended gunbc_falsifier_cadence_witness_batch to gunbc_falsifier_batches() without extending falsifier_plan_structure_holds, which pins the schedule's batch count: let expected_batches = 1 + wet + probe + silent_pick + rehomed (length(xs: batches) == expected_batches) && ... So length was expected_batches + 1 and the witness returned false, redding ci_floor_plan_witnesses and with it batch 3 on run 30166208268. The pin worked exactly as designed — it exists to red when a batch is added without being declared, and that is what it did. Note what this masked: batch 3 failing stopped the walk before dependent batches, so batch 4 never ran on that run and the re-home + 540 clamp are still UNMEASURED in CI. The floor-batch-wall receipt read "3 batch(es), 0 over budget" — green on the batches that ran, not evidence about batch 4. The fix is not a count bump. falsifier_cadence_witness_batch_holds mirrors the silent-pick sibling and checks the batch's actual shape: SelectionApplied, zero scan_dirs, entry count matching falsifier_cadence_witness_entries(), Wet execution mode, spawns_host_compiler, and NOT heavy_whole_tree_resolve. The rehomed sibling is only counted, never shape-checked; this one is both. Proven live by perturbation, not just by going green: flipping the cadence batch's execution_mode from Wet to Hermetic reds falsifier_plan_structure_holds. Verified green together with ci_floor_optin_roster_witnesses, ci_corpus_discovery_flip_witnesses, and all three gauntlet_lane_enrollment_witness_test claims. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * Decode \xNN in .dag string literals — no authored colour had ever rendered process_escapes resolved exactly six escapes (\" \\ \n \t \{ \}) and fell through on everything else to concat("\\", next), preserving the backslash. So "\x1b" was never an ESC byte: it was the four characters backslash-x-1-b. Every ANSI code this repo authored in .dag emitted as literal text — extdeps/render/ansi.dag csi_esc, extdeps/render/terminal.dag's reset, and gunbc/ci_render.dag's red/reset. That is the `\x1b[38;5;196m🔥` seen in the TOP SLOWEST WITNESSES table of run 30167957464, which read as a renderer leaking colours onto the CI path and was neither: the raw GitHub log carries real escapes everywhere else, so the defect was the decode, not the target. Fixed at the authority (src/v1/01_tokenize.dag), not the generated seed, via the already-registered from_code_point builtin — no new builtin. The seed file is regenerated by regen_stage0; it is `// Generated by v1 compiler`. Regen produced exactly this one file's delta, so the self-host fixed point held across the change. The witness that should have caught this could not. It compared one undecoded literal against another (code == "\x1b[38;5;34m"), so both sides were equally wrong and it agreed with itself throughout — the vacuous-oracle shape DESIGN §5 names, a check satisfiable by editing the declaration while the realization lies. Its two replacements test properties of the DECODE rather than of the spelling: the first character's code point is 27, and the decoded string contains no backslash. Neither can be satisfied by editing a literal on either side. Both were proven RED against the pre-fix binary before regen was paid for, and green after. Unknown-escape passthrough is knowingly RETAINED, and marked rather than left silent: 🟡 dissolve-on tokenizer_unknown_escape_strict_close. Refusing today would red 142 occurrences across 38 files — overwhelmingly regex fragments (\' 28, \. 19, \| 13, \/ 12, \B 10) that intend the backslash to survive — so the strict close needs a raw-string carrier to migrate onto first, and lands with a corpus-wide compile receipt because it changes parse semantics for every lane that compiles through this tokenizer. Not the four sites a \x-only count suggests. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013GELyMsZrGgZRrxte2TCsk * Layer 1: bind ExpectedOutcome from the call site, not the transport v1_interpreter.rs carried `let expected = ExpectedOutcome::ExpectSuccess` hardwired at dispatch_shell, with a comment saying where the declaration should live was still open. It is now read from the call site. The whole downstream apparatus already existed and was pinned — gunbc.output_policy's four corners, outcome_diverges, the Rust mirror in EFFECT_STREAM_POLICY_FALLBACK. Only the binding was missing, which is why output_policy.dag:105 could already describe the payoff in writing. WHERE IT LIVES, and the two homes that look right and are not: param_env is wrong because param_env IS the request: content_hash_service_inputs iterates op_node.params and looks each up there, so a service-op `input {}` would join the digest and two invocations differing only in what the caller expected would become different cache identities for the same request. The transport is wrong less obviously, and this is the trap. The nearest local precedent — transport_stdin, transport_response_format via find_property — points straight at it. But dispatch_service_wet receives the transport from op_node.transport.or(service_node.transport): the extdeps service-op DECLARATION, shared by every caller. Hanging the expectation there makes it a per-operation fact, so a red control and a genuine check both calling shell.Test.IsFile could not differ — and caller policy declared in extdeps is the DESIGN §3 layer inversion the original comment warned about. It would have compiled and read as green while being wrong twice. So it is a reserved argument on the call node, partitioned out in eval_method_call before bu…
Summary
Atomic delivery of the CI two-tier placement rework and the progress-observation lane on this PR (
docs/plans/ci-two-tier-placement-redesign.md,docs/plans/progress-observation-design.md). Under atomic delivery the body describes everything that merges — not only the original D0+D3 mechanism slice.Definition of done: this PR's own final CI floor run renders in the new observation format; that last green floor before merge is the demo.
Landed
D0 — retention-truth close-out (
cli_run.rs)Compile-clean aggregate memo unpin (
ResolvedGraphMemoShare::{Memoize, Ephemeral}), prewarm all-hit registration, arm from the loader's exact closure, §7 acceptance controls.D3 — placement-axis mechanism (
ci_placement.dag+ witnesses)Placement = PrTier | Gauntlet, fail-closed admission. Mechanism landed; not yet live-wired onto check rows.Piece 3 — derived floor clamps
gunbc_ci_floor_batch_clamp_paramsinci_spec.dag.Observation P0–P3 + wiring flips
Model, CI/TTY renderers, seed boundary, census/lockstep witnesses. Migrated to observation: floor-memory (mirror↔oracle byte equality; 0-of-0 RED), [gantt], [governor], [typecheck-attribution]. Frontier: [measurement] + shell-echo-as-events (one pass, in flight), then the ~75-site raw
eprintlnre-census.Warm-cost TSV emitter
Live in
claim_executor; fleet receipt / roster fill still open.Shell-echo revert (endorsed)
60a4496→ correctly revertedd595163(//in.dag; disposition gated by channel / tests hit fallback). Steer: fold into observation wiring (Ambient/Anomaly per event); leave ShellTrace/disposition/grouping untouched until the event path carries traffic; carry forward self-describing$ <argv>+ empty-stderr exit naming.Standing checks (every commit)
(a)
.dagvia the real pipeline before push; no//; prose =data …_note: String.(b) Policy witnesses against the installed policy; a perturb control proves which table.
Merge-bar ledger
None of D3b / lens-door / stage collapses / expectation sheet was consciously dropped.
🤖 Generated with Claude Code