Skip to content

shell→dag bucket A: last shell.Exec off host_runner_memory_cap_verify; meta-exec roster 3→0 + per-PR emptiness wall - #7241

Merged
briansrls merged 7 commits into
mainfrom
session/calm-pike-837
Jul 25, 2026
Merged

briansrls merged 7 commits into
mainfrom
session/calm-pike-837

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 25, 2026 •

Copy link
Copy Markdown
Contributor

shell→dag bucket A. Roster 3 → 0, every behavioral change green-by-execution with a discriminating RED.

1. host_runner_memory_cap_verify — last shell.Exec off the intent layer

The brief said "2 live shell.Exec" — there was 1 (the memory-property reads had already gone typed via systemctl_show_read). The remaining one was probed_at:

  • shell.Exec.Run(retained_runtime("date -Iseconds")) → clock_now_probed_at() (gunbc.clock_read → extdeps.clock Clock.Now) — the same single authority host_converge_slice1 already uses, so this removes a §3 fork rather than just a shell call.
  • Deleted with it: the extdeps.shell import, the retained_shell_script bridge, and host_runner_memory_cap_verify_transport_script_scaffold (its medium-as-string dissolution trigger no longer has a subject).
  • The refusal decision is factored into runner_memory_cap_verify_result_from_live_read(host, read: RunnerUnitMemoryLiveRead?), so the read-absent arm is executable hermetically. runner_memory_cap_verify_run keeps the knobs-absent guard before the live read, so no read-only op fires on a host with no knobs.

RED control (by execution): perturbing the absent arm to fabricate an empty read and report it Observed — the exact §5 widen — turns srv3_runner_memory_cap_plan_verify_holds FAIL; restored → PASS. Paired witnesses: none → Refused with the located reason, Present → Observed.

2. SetHostnameCas → os.Hostname.Set — already landed on main (#7194)

Verified, not assumed: host_effect_realize.dag's arm calls gunbc.hostname_set hostname_set_cas, whose hostname_set_local is os.Hostname.Set(desired:); SSH goes through typed_argv_exec_over_ssh; the CAS read reuses os.Hostname.ReadShort. host_effect_set_hostname_cas_script does not exist anywhere in tree. No code change was needed — recorded as DONE in the census instead. (Consequently no contact with host_effect_realize.dag, so no overlap with #7237.)

3. Roster 3 → 0

Both stale rows verified at 0 live shell.Exec before deletion:

  • dag/gunbc/tools/review.dag — imports only extdeps.git.
  • dag/gunbc/ci_deploy_target_host.dag — imports extdeps.shell for shell.Env.Get, which is not the confined extdeps.shell.exec (non_exec_import_is_not_leak_holds is the standing receipt).
  • dag/gunbc/host_runner_memory_cap_verify.dag — the genuine remainder, dissolved by item 1.

rostered_consumer_import_is_not_leak_holds was re-parameterized onto a synthetic roster: spelled against the canonical roster it would have passed for the wrong reason (no row to exempt) and silently stopped discriminating. It now asserts both directions, plus a new empty_canonical_roster_grants_no_exception_holds.

4. The dark-lane fix — measured, then designed

The diagnosis is confirmed: meta_exec_roster_sound_live existed but ran on no per-PR cadence; the only enrolled roster RED was synthetic (hand-written fact rows, blind to the live roster). That is why two stale rows survived merges.

The literal fix does not fit, and the measurement is part of the receipt: the live receipt evaluates in 13470ms cold over meta_exec_consumer_scan_roots, and still 11485ms over dag/gunbc alone, against a 5s fast-lane budget — next to an enrolled sibling costing 2ms. The cost is intrinsic to layer_import_facts_live over a real tree, so no narrower root rescues it. (Behind an already-warmed scan it reports 1852ms — borrowed warmth, not a cost this row may declare.)

What runs per-PR instead is stronger than soundness and needs no scan (§5 construction over validation): a stale row is only possible because the roster is a hand-written second representation of a fact the tree already carries. stale_count is bounded above by roster length, so length 0 proves soundness outright. meta_exec_roster_shrunk_to_empty_holds walls that state, costs 0ms, and reds by name in the same PR that re-adds a row — precisely the event that went unnoticed before.

The live receipt stays as a backstop in the long lane, now with a non-degeneracy control: over a clean tree a live scan is true either because nothing is stale or because the walk read nothing (⊤-as-answer vs ⊤-as-ignorance), and leak-candidate paths are legitimately empty, so the control asserts the underlying fact set is non-empty.

Named residue, not papered over: that long lane is still dark (not roster-enrolled). Dissolve-on is a falsifier batch admitting live-tree lens receipts; batch 6 exists but is declared for SubstrateInputsOnly fixture-shaped rows, so enrolling there is a lane-owner call, not mine to take silently.

5. Census true-up

§4.A/§4.C rows marked DONE for the hostname and date -Iseconds clusters; a 2026-07-25 ledger true-up block ahead of the stale 07-22 snapshot. Every claimed PR verified against origin/main — which corrected a line I had drafted from the brief: §5.A is COMPLETE, not partially remaining (ListUnits, Status, os.Id.Uid all landed on #7194 and are cited at their post-#7231 homes). §5.E is marked LANDED (#7184), so the wall-first pause on §5.B is discharged.

Receipts

🤖 Generated with Claude Code

briansrls and others added 7 commits July 25, 2026 20:04
…y; meta-exec roster 3->0 + per-PR emptiness wall; census true-up

- host_runner_memory_cap_verify probed_at: retained_runtime shell.Exec.Run(date -Iseconds)
  -> typed extdeps.clock Clock.Now via gunbc.clock_read (host_converge_slice1 precedent).
  extdeps.shell import, retained_shell_script bridge and the transport-script scaffold all deleted.
  Refusal decision refactored to runner_memory_cap_verify_result_from_live_read so the
  read-absent arm is executable hermetically; RED control proves a widen fails.
- meta_exec_confinement_exception_roster 3 -> 0: tools/review.dag and ci_deploy_target_host.dag
  verified stale (0 shell.Exec); host_runner_memory_cap_verify dissolved above.
- Per-PR enforcement is a construction wall (empty roster => stale_count 0, no scan);
  live receipt measured 13.5s cold vs a 5s fast-lane budget, homed in the long lane
  with a non-degeneracy control.
- Census section 4/5 + ledger trued up to main (#7184/#7192/#7193/#7194/#7215/#7231/#7233).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title shell→dag bucket A cleanup (one PR): (1) host_runner_memory_cap_verify 2 shell.Exec → typed systemctl op; (2) SetHostnameCas consumers → os.Hostname.Set op (INTEGRATE main; #7237 also edits host_effect_realize.dag, different arm); (3) DELETE 2 stale meta_exec_confinement roster rows (tools/review.da shell→dag bucket A: last shell.Exec off host_runner_memory_cap_verify; meta-exec roster 3→0 + per-PR emptiness wall Jul 25, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 25, 2026 21:01
@briansrls
briansrls merged commit 2fa07e8 into main Jul 25, 2026
7 of 10 checks passed
@briansrls
briansrls deleted the session/calm-pike-837 branch July 25, 2026 22:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant