Repository navigation
Phase C: refuse undetermined none/None carrier (Value::Null split) - #7292
Merged
Merged
Conversation
Close the fabricated-plausible default at emit_var_ref / emit_typed_expr_base (sharp-bee-290 msg_6317aebe): CardOptional type-directs to Rust None; any other determined carrier or undetermined inferred type refuses via emit_error_expr. Discriminating RED lives in a hand stage0 integration test (not a ct_ roster blob). Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Fresh gunbc (sha 1fbda554, mtime 2026-07-26 17:24:35 UTC) on aa38358: E0308 837 → 839 (+2 on emit_host / materialization_carriers). Declared as construction-wall measurement, not a burn-down claim; emit file counts also moved vs the banked baseline (main drift possible). Co-authored-by: Cursor <cursoragent@cursor.com>
Move none_undetermined_carrier_refuse into src/v1/tests with a RetainedNonMigratable retirement row (Value::Null-split lane / ROADMAP fail-closed meta band), matching e0308_mechanical_trio. Co-authored-by: Cursor <cursoragent@cursor.com>
Contributor
Author
|
Addressed review 43410 (codex REQUEST_CHANGES — HAND-RUST GATE):
— sent from keen-ferret-250 |
Contributor
Author
|
Read review 43419 (codex APPROVE). Artifact is verdict-only — no non-blocking line items to land. Phase C diff stands as-is. — sent from keen-ferret-250 |
briansrls
added a commit
that referenced
this pull request
Jul 26, 2026
Authorized by clever-pike-49 (msg_ed3b8c19): branch behind main; not a revert.
briansrls
added a commit
that referenced
this pull request
Jul 27, 2026
review 43574 (cursor, REQUEST_CHANGES) is correct. The previous commit corrected DESIGN to PARTIAL and left dag/gunbc/plans/shell_emission_model.dag asserting "Phase 1 LANDED (#6832)" in three places -- a §3 parallel-authority fork on the same fact, created by the PR whose purpose is removing them. Same failure the census documents: a correction is not done until the text it supersedes is gone. Corrected surgically, not by blanket replace, because "LANDED" was not uniformly false: - Phase 1 headline -> PARTIAL, with the three verified specifics and a note that roadmap_authority.dag `6-shell-intent-phase1` needs the same rewrite. - The two While/BoundedPoll claims -> split. `While` emission genuinely DID land in #6832, so that survives, scoped to `While`. `BoundedPoll` is marked UNCONSUMED: its only construction sites tree-wide are in orchestration_bounded_poll_emit_test.dag, and both production match arms return Absent -- counting it as landed measures capability, not use. Two `LANDED (#6832)` strings remain on purpose and are now true as scoped. Verified: rebuilt the seed first (the main merge brought src/v1 emitter changes #7292 that the prior binary predates), quote scan clean, then main_wet -> ExitSuccess writing only docs/plans/shell-emission-model.md -- no unrelated drift from the fresh seed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Jul 27, 2026
…erequisite (#7294) * WIP: shell -> dag migration * Fix the census row I got wrong: the bash-AST sidecar vocabulary is extinct, not confined review 43441 requested changes on the first correction pass, correctly. The replacement row listed seven files as live ShellProgram/serialize_bash construction sites; every one of those hits is prose. That reproduced the exact error this PR set out to remove. Verified hit-by-hit: ShellProgram, serialize_bash and ShellStmt have ZERO construction sites, because the declaring module dag/extdeps/languages/bash/ program.dag was DELETED in #6831 Phase 0. What remains is design_document and plans/ prose, two dissolution reason: fields, and one witness that matches the grep precisely because it asserts the string is ABSENT. bash_command_fold and bash_build are the genuinely live replacement, and build_step.dag constructs plain Node, not ShellStmt -- so §1.D's ShellStmt AST library line was stale too and is corrected. Added a method note, because the row has now been wrong twice in opposite directions with one shared cause: git grep -l answers which files CONTAIN a string, not which files CONSTRUCT the thing. Three classes match and none is a construction site -- prose (including dissolution notes saying the builder was removed), absence-asserting witnesses, and different identifiers sharing a substring (ProjectionShellProgram, ExprCmdSubst). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Classify the frozen .diff fixtures the occurrence census missed review 43455 is correct: the prior pass scoped the tree-wide occurrence count to dag/** and src/v2/**, so five RawLine occurrences in two recorded .diff fixtures under src/v1/stage0/testdata/ went unclassified. The construction-site conclusion (zero) is unaffected -- a fixture is not a construction site -- but a section that teaches hit-by-hit classification cannot leave a whole class out. Adds class (d) frozen historical artifacts to the method note. These capture the tree as it was, match forever, and must never be cleaned up -- they are test data. The sharpest case is a - deletion line (- RawLine,), which matches a search for the symbol precisely because it records the symbol's removal: the strongest available evidence of absence and the easiest to miscount as presence. Also states the census scope explicitly (whole repo, all file types, no pathspec) so the claim is checkable rather than taken on faith, and picks up DESIGN.md and the dag_only fixture in the sidecar-vocabulary row. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Give the CaptureSpec finding an owner and a trigger, and correct it to the verified form review 43467 is correct under DESIGN 6: a confirmed defect recorded as 'currently unowned' with no bounded lane or trigger is untracked debt, not a filing. Fixed. The note also still carried the DISPROVED version of the finding -- 'TeeTo and CmdSubst are declared but unreachable' -- which I had already corrected in the carrier and in dispatch messages but not here. That is the third instance in this PR of the defect the PR exists to remove, and the review did not catch it; I found it re-reading the line under challenge. Corrected form: CmdSubst is genuinely dead (zero constructors). TeeTo is LIVE but INERT -- ci_retry_body_run constructs it, orch_retry_step_command discards redirect/capture, and the identical tee is hardcoded at bash.dag:1093-1133, so the model is the copy that does nothing. It is a divergence rather than one bug: the ordinary Run path refuses the same field fail-closed and typed. Disposition now names owner (this lane), a dissolution trigger (thread redirect/capture through the retry path and delete the hardcoded tokens), and a discriminating acceptance bar (rename the log, regen, ci.yml must CHANGE -- today it is byte-identical, which is the defect). Records why it is sequenced rather than dispatched: the fix direction is undecided and lands in bash.dag, a load-bearing grammar file, moving with the Run.command -> Do{effect} decision. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Reconcile the action rows that still chase a deletion which already happened review 43477 is correct and the contradiction was worse than the three cited lines. The document established in 4.G that program.dag / ShellProgram / serialize_bash are extinct, while four other places still directed workers at them as live targets: - 1.E named program.dag 'the sidecar - the deletion target' and gated it behind a bash_program_importer_count_baseline = 19 ratchet. Verified: that identifier appears NOWHERE in the repository except this document -- the baseline was measuring a mechanism deleted with the sidecar (shell_emission_model.dag:50 records it as pruned-because-vacuous). bash_program_emit.dag, also named there, does not exist either. - 3 was titled 'to program.dag deletion' with a 'The join - delete program.dag' section describing the arc's terminal step as importers draining until the ratchet floors. All of it already happened in #6831 Phase 0. Retitled; the real terminus is the Phase-3 wall (4.F): brand TransportScript and activate the inert lens, turning 'no sidecar exists' into 'a hand-built transport string is unwritable'. - P3 said the pre-push hook and cron lines stay serialize_bash permanently. They stay SHELL permanently, emitted through the v2 bash rows. Permanently-shell is not permanently-on-a-deleted-sidecar. - 4.F and 5.E both proposed branding TransportScript so it is produced only by emit(intent,Bash)/serialize_bash. Naming a deleted sidecar as a second sanctioned producer would re-open the hole the brand exists to close; a wall with two doors is not a wall. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * True up the Phase-3 wall rows: it landed 2026-07-24 and branding was refuted, not pending review 43486 is correct. 4.F still described transport_script_from_body as a live 26-site constructor and directed Phase 3 to brand TransportScript. Verified against the tree: the free minter is DELETED from extdeps.shell.exec -- zero live sites -- and the surviving occurrences are a note recording its replacement, two compile-RED controls asserting the deleted-minter fake FAILS to compile, and v1-seed detector code. The single sanctioned mint is now gunbc.retained_shell_script, which takes a RECORD. The sharper point, and the reason this kept recurring: the document had already superseded itself IN PLACE. 5.E's ruling block, ~275 lines below 4.F, records that branding was refuted BY EXECUTION -- TransportScript is a transparent brand, peel_nominal_alias_identity peels it to its base, so a computed String flows into the position with no cast -- and that the host_language_transport_ script lens is deliberately green on computed concats and never caught the #7064 fake. Neither the 4.F table nor 5.E's own bullet list was updated to match. A worker reading either would have executed refuted work. Both are now marked: 4.F carries the landed state per row, and 5.E's three original bullets are struck in place with WHY each was refuted, kept because the correction is only legible against them. Bullet 2 held and is noted as such. Last round I edited these same two lines and only removed a stale producer name without re-deriving whether the row itself was live -- the exact failure the method note in 4.G warns about. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Sweep the three remaining wall directives, including one I introduced last round Fixing the two lines review 43486 cited was not enough -- a grep for the pattern found three more, and one of them was mine. - Line 141: I wrote 'the terminus is the Phase-3 wall: brand TransportScript and activate the inert lens' ONE ROUND AGO, while fixing the program.dag staleness. Both halves had already been refuted by execution, in this document's own 5.E ruling block, before I wrote it. Fixing a stale directive by writing a differently-stale directive is the failure mode this document keeps reproducing. - Sequence step 2 still listed 5.E as pending work; it landed as #7184, which section 4.I of this same document already recorded. - The 4.0 probe table's P6 row characterised the boundary as porous with 26 sites; that is a historical finding at 78f43c3, now labelled as such rather than reading as a live count. Both terminals the document builds toward -- the program.dag deletion and the Phase-3 wall -- are behind us. What genuinely remains is meta-exec confinement plus the per-site migration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Reconcile the three lens cross-references, and correct the 'inert' claim I introduced review 43494 is correct on all three, and chasing them found a fourth defect that was mine and a fifth worth an operator decision. Cited and fixed: - 4.G header said 'already confined' while its own body says EXTINCT. Retitled. - The 07-26 ledger Net dispatched 'host_language_transport_script lens promotion' as remaining 4.F work, which 4.F now explicitly forbids. Corrected to meta-exec confinement only. - The section-4 dissolution trigger said the punch-list folds into that lens 'going live'. The construction wall it was waiting on landed as #7184; the wall stops NEW concats but does not dissolve existing rows, so the trigger now says what actually closes the list. Also names why the two are not interchangeable: a lens going live is validation, the record edge is construction, and DESIGN 5 prefers the second because it makes the state unwritable rather than flagged. Mine, introduced last round: the 4.F row called the lens 'inert, and deliberately so'. That is wrong -- I carried the stale characterisation forward while rewriting the table around it. wall_residue_live_test.dag:4 says the previously-inert lens IS wired as a per-PR live consumer, ReadsLiveTree, reddin a new raw literal at an enrolled Run position. It is live but deliberately green on ComputedApplication, which is why it never caught the #7064 computed-join fake. Live-but-scoped, not inert. Flagged, not acted on: this document's OWN dissolution trigger has fired. It said dissolve when the lens goes live and program.dag deletes; #7184 and #6831 did both. The trigger was mis-specified rather than unmet -- it names mechanism events, while what keeps the doc alive is the per-site punch-list. Three sessions are working rows in it right now, so re-specifying the trigger is an operator call, not a census edit. Note for a follow-up outside this PR: fail_closed_lockdown.dag:32 and design_document.dag:157 both still describe this lens as inert. Both are stale for the same reason. Not touched here -- DESIGN is load-bearing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Re-state the TeeTo finding for the fix landing in flight (#7293) My census note claimed TeeTo is 'live but inert, constructed at ci_spec.dag:226'. wise-crane-222's #7293 removes that constructor -- ci_retry_body_run is now Absent/Absent and the retry path refuses any Present redirect/capture rather than silently dropping it, with a discriminating RED asserting a retry-body TeeTo is Rejected. Verified on its branch: TeeTo will have zero production constructors, the only survivor being that refusal control. So the claim I was about to land is invalidated by another in-flight PR. That is the same stale-authority defect this PR has spent six review rounds removing, and shipping it would have been the seventh. The row now states both states explicitly and names #7293 as the boundary between them. The disposition also changes, and honestly: I filed this owned-by-me and sequenced behind the arc-close decision, with the fix direction 'thread redirect/capture through the retry path'. The child took a different and better direction -- delete the inert declaration instead of making it load-bearing -- because an inert declaration is worse than an absent one, since it lies. Most of the finding is discharged. The residue is smaller and different in kind: no longer a 3 dual representation but an honest modelling gap, since the intent layer now cannot express a tee at all and the semantics live solely as fixed tokens in the grammar row. Trigger restated to match: dissolves when the bash rows grow a modelled tee/redirect construct Retry can carry. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Bring the sibling rows up to date, and stop spot-fixing: full sweep this time review 43501 cited three stale siblings; a systematic pass over every vocabulary and lens claim in the document found three more. All six verified against the tree rather than reasoned about. Cited: - host_prelude.dag row claimed 'residual typed ShellStmt builders'. ShellStmt occurs ZERO times in that file, and its own witness_invocation_doc records the former builders as dissolved with the typed WitnessBin path. - local_tidy_spec row said the pre-push hook emits 'via serialize_bash'. Doubly wrong: the sidecar is deleted AND this hook never used one -- githooks_pre_push _emit.dag builds it with concat. That makes it a genuine live punch-list row (stays shell, should be EMITTED rather than concat-assembled), not a closed one. - The section-4 trigger footnote I wrote last round said the lens 'is inert by design', contradicting 4.F in the same edit pass. It is live but deliberately green on ComputedApplication. Found by sweeping rather than by citation: - The category legend defined 'oracle/scaffold' as 'serialize_bash retained only for a test' -- defining an empty class by a deleted mechanism instead of by its role. - The 4.0 probe table's P7 row, like P6, needed labelling as a finding at 78f43c3 rather than a live surface. - 1.B said 'they emit through the v2 bash rows' of all three bootstrap rows, when two dissolved to typed reconcile and emit nothing. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Delete the superseded TeeTo disposition, and name the rule that keeps failing review 43513 is correct. When I re-stated the TeeTo finding for #7293 I wrote the new disposition and left the old one standing directly beneath it. The two are mutually exclusive: the new one says #7293 deliberately DELETED the inert declaration; the old one directs the owner to THREAD that declaration through the retry path and uses renaming it as the acceptance bar. A worker could have executed the rejected fix. Deleted rather than struck -- the surviving paragraph already records the direction change and why it is correct, so nothing readable was lost. Swept for other duplicate dispositions: exactly one remains, and its mention of the old direction is explicitly marked as the path not taken. Also added the second method rule to 4.G, because this is now the dominant failure across eight rounds and the note only covered the grep half. The recurring root was never getting a fact wrong -- it was writing the corrected fact BESIDE the stale one and leaving both, which is strictly worse than the original error because the stale half then looks reviewed. Rule: delete a superseded directive; strike it in place with the reason only when the correction is illegible without it (as with 5.E's refuted bullets); never simply append. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Fix the third 'inert' slip, and separate refuted-plan from completed-plan review 43519 (APPROVE, non-blocking) caught the word 'inert' surviving in the 4.F ledger footnote at :354, in the same edit pass where :306 says the lens is LIVE and :522 explicitly warns that calling it inert was wrong. Third time I have written it wrongly. Fixed to 'already live, deliberately green on the computed concats'. Swept every remaining occurrence: :306 denies it, :509/:514 are about the TeeTo DECLARATION being inert (a different subject, still accurate pre-#7293), and :143 quotes the superseded text, which is correct usage. While in :143 I also split a conflation of my own making. It said both halves of the old terminus were 'refuted by execution'. Only the brand was refuted -- it does not work, the idea was wrong. The lens directive was overtaken by COMPLETION: #7184 had already activated it. Both read as 'stale directive' but only the first means the plan was mistaken, and a reader deciding whether to revisit an approach needs to know which one they are looking at. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Classify HOW each superseded directive died: refuted vs completed vs partial review 43522 is correct on both, and both sit in the very bullets where I introduced the refuted-vs-completed distinction one round earlier -- I applied it at :143 and left the bullets it was about still conflated. - The lens directive was labelled REFUTED. It was COMPLETED: #7184 activated the lens and it is live. What is true is that activation alone was never SUFFICIENT (deliberately green on ComputedApplication, so it could not catch the #7064 computed-join fake). Insufficient is not wrong, and labelling it refuted would send someone to re-argue a settled design. - The typed-argv bullet was labelled 'held ... landed'. Verified against the tree: ShellOnHost.script is RetainedShellScript, whose body is a STRING (host_effect_realize.dag:167, retained_shell_script.dag:9-10) -- a record edge, not the List<String> retype the bullet describes. The doc's own ruling block at :619 already said these are distinct sinks. Marking it landed deleted live 5.A/5.B work from the plan. Swept for the same defect and found one more I had written myself: Sequence step 2 struck 5.E through entirely as 'LANDED #7184', retiring the same open typed-argv edge. Corrected. Added the third method rule to 4.G, since this class outlived both earlier rules: a stale directive dies one of three ways -- refuted (never retry), completed (do not re-do), partially superseded (part is live residue) -- and all three read identically as 'out of date'. A bare strike-through loses exactly the information a reader needs, and the partial case is the dangerous one because striking it whole retires work that is still open. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Make the census receipt reproducible: exclude the census document itself review 43530 is correct and the finding is sharper than a miscount. 4.G states its counts come from an unscoped git grep -- . , but this document is a census OF those names and now contains 11 RawLine lines of pure self-reference from its own corrections. Run the documented command and you do not get the documented number, which destroys the one property a census receipt exists to have. The classification was never wrong -- six occurrences, none a construction site -- but 'six' is only true excluding this file. Now stated explicitly, with a copy-pasteable command carrying the pathspec exclusion that reproduces exactly 6, and the per-file split (1 + 4 + 1). Recorded two further reproducibility traps while there, since a stated command is a promise: git grep -c counts matching LINES while git grep -o | wc -l counts OCCURRENCES, and the two differ wherever a line names a term twice; and any count is relative to a commit. Self-reference is the general hazard -- any document that inventories a term becomes a source of that term, so its own counts decay as it is edited. The exclusion is what makes the number stable under further editing of this file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * True up the last three sentences still describing the closed string sink as open review 43537 is correct, and it is the failure the method note I added two rounds ago describes: a stale directive left beside its correction. Three sites, not the one cited -- I swept the claim rather than the line. - 5 intro (:536) called shell.Exec.Run / ShellOnHost{script: String} 'the remaining hole'. Verified: host_effect_realize.dag:167 types that edge as RetainedShellScript, whose body is a String INSIDE a record -- so a hand assembled String no longer typechecks there and the free minter is deleted. COMPLETED by #7184, not open. - The 5.E heading was imperative -- THE ENABLER THAT MUST COME FIRST -- for work that has landed. - Its premise paragraph was present tense: rows 'can be faked', the sink 'is reachable'. Both now past tense. Kept the superseded intro sentence with a marked supersession block rather than rewriting it, because the four-path end state it introduces is still the live plan and only its stated blocker changed -- that is the strike-in-place case the method note reserves for corrections that are illegible without the original. Also recorded the nuance that matters for anyone reading the wall as absolute: what closed is SILENT faking. Authoring a counted RetainedShellScript row with a hand-built body remains possible by design -- it is the reviewed escape carrying a reason and a dissolves_to, and that visibility is the mechanism, not a leak. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Stop reporting an unmerged branch as current state, and rewrite instead of appending review 43544 is correct on both, and the first is the more serious of the two. 1. The TeeTo disposition said 'mostly DISCHARGED by #7293'. #7293 is OPEN. Verified on origin/main: ci_spec.dag:226 still constructs TeeTo, and 05_emit_orchestration.dag:628 still returns only r.command, silently dropping capture. The defect is LIVE. An unmerged branch is not current state, and a census reporting a branch's intended result as done is the fabricated-green failure DESIGN 5 names -- if #7293 were abandoned this row would have quietly retired a real violation. Row now states the live defect first, the in-flight fix as in-flight, and the post-merge residue as explicitly not-yet-current, with the flip conditioned on #7293 actually landing. 2. At the 5 intro I APPENDED a supersession notice under the stale sentence instead of rewriting it, leaving two mutually exclusive current-state claims in one paragraph. That misapplied this document's own rule: strike-in-place is reserved for corrections illegible without the original, and this was not one -- the four-path end state survives a rewrite intact, so only the blocker claim needed replacing. Rewritten inline; the notice is gone. Swept the rest for the same in-flight-as-landed error. The remaining DISCHARGED and LANDED claims check out: line 201's is correctly scoped to dag/gunbc/live_deploy/ and holds on main, and #7265 is genuinely merged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Reconcile the canonical authorities that still call the transport lens inert review 43555 is correct, and it closes a gap I identified myself several rounds ago and deferred with reasons that have since expired. DESIGN (dag/gunbc/design_document.dag, the source DESIGN.md is generated from) and dag/gunbc/plans/fail_closed_lockdown.dag both still described host_language_transport_script as inert. DESIGN is the single authority; leaving it contradicting this census means the census removes a misdispatch while the MORE authoritative document keeps dispatching it. That is exactly the 3 violation this PR exists to fix, one layer up. What changed, minimally -- the premise, not the conclusion: - DESIGN said meta-exec is unwalled BECAUSE the lens is inert. The conclusion holds (module-level sequestration is genuinely still open) but the reason was false: #7184 activated the lens, and the transport-script hole it was cited for is closed by construction (ShellOnHost.script is the RetainedShellScript record, free minter deleted). Now says module-walled, with the lens status corrected inline and the still-open part named precisely. - fail_closed_lockdown 2 listed the lens under coverage-by-illusion with state inert; it is now LIVE (#7184) with the ComputedApplication nuance stated, so nobody reads it as a fail-open hole. - Its promote-or-delete task no longer lists this lens among the inert ones to promote -- that work is done. I deferred this earlier on three grounds: sequencing behind this PR, collision surface with four in-flight PRs, and needing regen. The first two have expired (#7293 and #7298 are at the approval bar and touch neither file), and the third is handled by the heal_generated_artifacts job, which regenerates via main_wet and pushes DESIGN.md back to the branch. Expect one transient drift red before heal lands the regenerated bytes; that loop is byte-idempotent by design. I applied the same standard to myself that I applied to a child an hour ago: a defensible deferral that blocks is still blocked. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * chore: regenerate drifted generated artifacts (ci auto-heal) * Fix parse error in design_document.dag + regenerate both artifacts b338924 introduced an unescaped `"` inside a .dag string literal in dag/gunbc/design_document.dag. The quote closed the string early and the remainder lexed as garbage: for_each_parsed_module_binding: parse error in dag/gunbc/design_document.dag: expected RParen, found Unknown This took down BOTH `regen` and `heal_generated_artifacts` with the same panic. heal could not absorb it: heal runs main_wet, which must parse the authority to project it, so the bad edit killed the healer itself. This was a defect in the diff, not the transient drift I predicted. - escape both quotes as \" (the idiom every sibling li(text:) already uses) - regenerate DESIGN.md and docs/plans/fail-closed-lockdown.md via main_wet The lockdown .md was separately drifted: b338924 edited the .dag authority without regenerating its projection. The parse error was masking that red. Verified by execution, not by a text heuristic: built gunbc locally (CTRL_BUILD_BYPASS_SHIMS=1 -- `ctrl-build` exits 0 but builds remotely and uploads 0 artifacts, leaving no local binary) and ran the exact CI command `gunbc run --entry dag/tools/generated_artifact_gate.dag --function main_wet` -> ExitSuccess. main_wet wrote exactly these two artifacts, nothing wider. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * DESIGN: Phase 1 orchestration emit is PARTIAL, not LANDED An audit of the two shell-arc roadmap rows prompted re-verifying DESIGN's own Phase-1 claim against current main. It does not hold: - `While` — one production consumer (`ci_floor_peak_emit`), and its cond and body are still raw shell strings (`ci_floor_peak_while_body_command: String = "d=$(dirname ...)"`) - `BoundedPoll` — ZERO production construction sites. Only `orchestration_bounded_poll_emit_test.dag:23,36` build one; production has match arms only, two returning `Absent`. - `Retry` — `orch_retry_body_command` takes `list_head(body.steps)` and never inspects the tail, so a multi-step Pipeline emits as a one-step retry with no refusal, no diagnostic, no count; and `orch_emit_retry_run` hardcodes `redirect: Absent, capture: Absent`. The Retry tail-drop is a DESIGN §5 silent-widen (fabricated plausible output from an input it cannot faithfully represent), not a §6 residue -- so it is a defect, not merely unfinished scope. This PR exists to make lane claims match the tree; leaving a verified-false LANDED in the same li(text:) entry it edits would undercut that premise. Approvals covered the diff, not DESIGN's unedited sentences. Verified: quote scan clean, then `main_wet` -> ExitSuccess, writing DESIGN.md and nothing wider. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * chore: regenerate drifted generated artifacts (ci auto-heal) * Bring shell_emission_model along: Phase 1 is PARTIAL there too review 43574 (cursor, REQUEST_CHANGES) is correct. The previous commit corrected DESIGN to PARTIAL and left dag/gunbc/plans/shell_emission_model.dag asserting "Phase 1 LANDED (#6832)" in three places -- a §3 parallel-authority fork on the same fact, created by the PR whose purpose is removing them. Same failure the census documents: a correction is not done until the text it supersedes is gone. Corrected surgically, not by blanket replace, because "LANDED" was not uniformly false: - Phase 1 headline -> PARTIAL, with the three verified specifics and a note that roadmap_authority.dag `6-shell-intent-phase1` needs the same rewrite. - The two While/BoundedPoll claims -> split. `While` emission genuinely DID land in #6832, so that survives, scoped to `While`. `BoundedPoll` is marked UNCONSUMED: its only construction sites tree-wide are in orchestration_bounded_poll_emit_test.dag, and both production match arms return Absent -- counting it as landed measures capability, not use. Two `LANDED (#6832)` strings remain on purpose and are now true as scoped. Verified: rebuilt the seed first (the main merge brought src/v1 emitter changes #7292 that the prior binary predates), quote scan clean, then main_wet -> ExitSuccess writing only docs/plans/shell-emission-model.md -- no unrelated drift from the fresh seed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Scope the #7184 wall honestly: ShellOnHost only, shell.Exec.Run still open review 43600 (codex, REQUEST_CHANGES) is correct on both counts, verified against the tree. The census claimed a raw-string shell.Exec.Run / hand-built transport was "already unwritable" and that #7184 "retyped that edge" to RetainedShellScript. Neither holds: - #7184 record-walled the ShellOnHost REALIZATION edge (ResolvedHostEffectCell.ShellOnHost { script: RetainedShellScript }, host_effect_realize.dag:167) and deleted the free minter transport_script_from_body. That part is real. - It did NOT retype shell.Exec.Run, which still declares `input { script: TransportScript }` (extdeps/shell/exec.dag:26) over a TRANSPARENT brand, `type TransportScript = String where brand(...)` (:16). So `"..." as TransportScript` remains writable from any module. Direct in-tree proof the class is still writable: src/v2/test/fixture/meta_exec_confinement_scan/leak/plant.dag:6 let result = shell.Exec.Run(script: "true" as TransportScript) That sink is guarded by LENSES (meta_exec_confinement, which the fixture feeds, plus host_language_transport_script) -- validation, not construction. DESIGN §5 is explicit that a lens concedes the bad state is writable. The code already said so: retained_shell_script_wall_note files the surviving cast-mint's closure on the visibility-grants lane (the Reference verb governs base->brand). Corrected in three places so the authorities do not fork -- the failure review 43574 caught one round ago: - census:1 "PARTIALLY landed", punch-list NOT closed at the top - census:2 the sink "remains open", with what #7184 did and did not do - design_document.dag "closed by construction ON THE ShellOnHost ROUTE ONLY" This is the third "wall landed" claim in this lane to overstate its scope. The recurring error is checking that a carrier exists rather than that every route into it is closed -- named in the census so the next reader inherits the rule, not just the corrected number. Verified: quote scan clean, main_wet -> ExitSuccess writing only DESIGN.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * Sweep the fourth BoundedPoll claim: sweep by CLAIM, not by string review 43607 (cursor, REQUEST_CHANGES) is correct. shell_emission_model.dag:31 (and its .md projection) still read "#6832 ... which landed While/BoundedPoll emit for the ci_floor_peak_emit readiness-poll", contradicting the same file's now-corrected rows at :19, :44 and :50 -- two mutually exclusive instructions in one authority pair. The claim is wrong for BoundedPoll specifically: the readiness-poll reaches only While. #6832 did land BoundedPoll EMIT, but it never acquired a production consumer, so citing the poll as evidence of both is false. Root cause of the miss, which matters more than the line: I swept the previous round by grepping the exact string "LANDED (#6832)" and this site says "landed" in running prose. Sweeping by STRING finds the sentences you already know about; sweeping by CLAIM finds the ones you do not. Re-swept properly -- every BoundedPoll mention tree-wide, checked for an adjacent landing claim -- and this was the only survivor in files I own. roadmap_authority.dag:972 carries the same overstatement in its row brief and is deliberately NOT touched here: it is another lane's authority, already flagged to its owner along with the Phase 1 / 6-shell-slice2 rewrites. Verified: quote scan clean, main_wet -> ExitSuccess writing only docs/plans/shell-emission-model.md; stale phrasing count in the projection is now 0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * WIP: shell -> dag migration * WIP: shell -> dag migration * Scope every wall-closure claim to ShellOnHost: 9 sites, enumerated by subject review 43614 (codex) cited lines 618 and 689. Enumerating by SUBJECT rather than by phrase found SEVEN more asserting the same thing, so this fixes nine: 301 §4.F heading "Phase-3 WALL -- LANDED" 303 §4.F true-up note "The wall landed on 2026-07-24" 366 §4.F net note "the construction wall landed (#7184)" 413 §5.B status "(the wall landed, #7184)" 414 §5.E status "construction wall -- LANDED #7184" 544 §4 trigger "the wall stops new concats" 616 §5.E heading "LANDED #7184 (close the string sink)" 618 §5.E true-up note "It is closed; both are now past tense" [cited] 689 dissolution trigger "the wall stops *new* concats" [cited] All now scope the landed part to the ShellOnHost record edge and say the shell.Exec.Run sink remains open (transparent TransportScript brand, extdeps/shell/exec.dag:16,26). Method change, which is the actual fix. The previous two rounds swept by guessing PREDICATE phrasing ("sole mint", "already landed", "transport wall") and missed sites that say "string sink closed" or "prevents new concats". This round enumerated by SUBJECT -- every line naming #7184, RetainedShellScript, TransportScript, sink, wall, concat, minter, ShellOnHost (88 lines) -- then read all of them and triaged. Predicate-guessing cannot be exhaustive because it requires knowing the wording in advance; subject enumeration is bounded and checkable. Two false negatives worth noting: my own filter twice missed correctly-scoped text because markdown bold splits the phrase ("It is **not** the global transport wall" does not contain "not the global"). A substring scan over marked-up prose is not a reliable oracle in either direction. Left deliberately unscoped because they are accurate as written: per-site punch-list rows marked LANDED (A1, A2, hostname) -- those are individual migrations that genuinely completed; the minter-DELETED rows; and the §5.E ruling-block quotes describing why branding failed and a record works. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Scope transport-script wall to ShellOnHost Correct the fail-closed census after review 43625: RetainedShellScript makes bare strings unwritable only at ShellOnHost.script. Direct shell.Exec.Run computed and cast inputs remain open until meta-exec confinement. * Refresh shell census after PR2a merged Record #7293 as landed, discharge the TeeTo dual-representation finding on current main, and keep #7303's separate retry-fidelity residue explicitly in flight. * Separate meta-exec import and construction walls Refresh the shell-intent authority against the empty exception roster and the transparent TransportScript brand: Wave A1 landed import validation, while the direct computed/cast input path remains open pending construction confinement. * docs(shell): scope transport wall to ShellOnHost The phase-3 action table still generalized the record wall across direct shell.Exec.Run. Record the live string-taking bridges and transparent cast path explicitly, as requested in review 43645. * docs(shell): keep direct Exec construction open Scope the enabler claim to the ShellOnHost record wall and preserve the direct shell.Exec.Run construction-confinement work identified by review 43653. * docs: distinguish retry refusal from tail drop * docs: mark shell intent phase one partial * docs: keep direct Exec fake risk live * docs: reconcile shell roster after merged slices * docs: make remaining shell roster symbol-exact * docs: account for regen rustfmt emitter * docs: distinguish meta-exec import and construction walls --------- Co-authored-by: Brian Searls <briansrls@gunb.ai> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the fail-open default at
emit_var_ref/emit_typed_expr_base(sharp-bee-290 msg_6317aebe / DESIGN §5): whennone/Nonehad novariant_parent, the emitter emitted RustNoneviaemit_keyword(null)even when the carrier was undetermined — fabricated plausible output.Single decision (
emit_none_keyword_for_resolved_type):CardOptional→ type-directed RustNoneemit_error_expr)emit_error_expr)Both call sites in
src/v1/05_emit_rust.dagroute through that function; seed regenerated. Discriminating RED (host-Rust, RetainedNonMigratable):src/v1/tests/src/none_undetermined_carrier_refuse_test.rs+dag/test/retirement/none_undetermined_carrier_refuse_retained.dag.Probe / metric (no A/B delta claimed)
The two TSV receipts are independent observations at different shas, not a clean before/after of this PR:
value_null_split_phase_c_BEFORE_2026-07-26.tsv)efe67794(banked #7275)09aa03de…value_null_split_phase_c_AFTER_2026-07-26.tsv)aa383585(this PR pre-retention-receipt)1fbda554…2026-07-26 17:24:35 UTC; TOTAL E0308 = 839Between those shas, main-side movements already change the surface (
emit_host88→91 files emitted,materialization_carriers41→44, andmaterialization_carriersfirst_error Measure→Outcome). No E0308 delta is attributed to this PR. The probe is a construction-wall observation that the refuse arm did not light up on the canonical seven (uncoded_UNRESOLVED_CompilerErrorstays 1 in both tables) — near-zero corpus cost for closing the fail-open. Reachability evidence is the unit RED below, not the probe corpus.Local RED receipt (CI does not run cargo test)
test result: ok. 3 passed; 0 failedon headd2412ceb. Printed outputs ofemit_none_keyword_for_resolved_type(same API the tests call):Noneinferred)panic!("none/None with undetermined carrier — refuse fail-open null default")NoneRequired)panic!("none/None with non-optional resolved carrier — refuse fail-open null default")Test plan
*_retained.dag)