Skip to content

Scoped gunbc run observation TTY and pipe consumer - #7348

Merged
briansrls merged 58 commits into
mainfrom
session/jolly-hawk-270
Jul 29, 2026
Merged

briansrls merged 58 commits into
mainfrom
session/jolly-hawk-270

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Scoped gunbc run TTY/pipe observation consumer, synchronized onto current main after #7350 merged the required SeedGrowthJustification authority.

The dedicated gunbc.observation_seed_render graph projects density-aware TTY emission and terminal-wire state. The scoped host seam transports canonical Nanosecond/Millisecond records and retains the authored DynamicLineState; it only decodes typed projections and receipts. Clean Final remains MeasuredUnavailable when attention basis is unavailable, while clean-run end timing is a separate typed receipt. Runtime identity comes from the interpreter's actual selected fn_nodes node with normalized, fail-closed module-path matching.

Exact five-file scope:

  • dag/gunbc/observation_seed_render.dag
  • dag/test/claim/observation_seed_scoped_run_witness_test.dag
  • src/v1/stage0/src/cli_run.rs
  • src/v1/stage0/src/v1_interpreter.rs
  • src/v1/stage0/tests/scoped_run_observation.rs

No parallel identity registry, emitter/main changes, floor, placement, workflow, or additional production consumer.

Exact-head receipts for c0a3f40ed738ca0e736b61b1a5cb81fb16c2af01:

  • Actions run 30407444169: build, heal-generated-artifacts, regen, and full CI passed.
  • Selected-node suffix-collision accessor RED: PASS on the preceding synchronized head, BuildBuddy 5ee2c5fd-1e86-46c5-baef-fe4b1ec9dfb7.
  • Scoped production integration: 7/7 PASS on the implementation head, BuildBuddy 77253944-833d-4c19-85b8-7161039c139f; subsequent changes are main synchronization merges, and the five-file PR diff is unchanged.
  • Authored scoped-run matrix: 10/10 PASS on the implementation head, including exact 1ns/999999ns/1000000ns preservation, unmeasured clean Final plus typed end receipt, canonical DynamicLineState, TERM=dumb downgrade, pipe append, and failure/refusal precedence.
  • git diff --check: clean.

Prior review findings:

  • review 44042's parallel Bool terminal state was removed; DAG and host now carry canonical DynamicLineState.
  • review 44042's PTY prerequisite now fails closed when util-linux script is unavailable or unsuccessful.
  • review 43926's typed-carrier and seed-growth requirements are satisfied by canonical measure records and Refresh roadmap authority to active dependency graph #7350's accepted SeedGrowthJustification with its concrete interpreter-seam dissolution trigger.

Manager audit: clear against DESIGN §§2–6 and the ROADMAP observation dependency chain. The seed bridge remains bounded by #7350 and the exact five-file consumer boundary.

briansrls and others added 20 commits July 27, 2026 16:58
@gunbai-bot gunbai-bot Bot changed the title CI observation P2 prerequisite: density-aware TTY projection and terminal-wire state model (no cli_run consumer) Scoped gunbc run observation TTY and pipe consumer Jul 28, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 28, 2026 19:24
@gunbai-bot

gunbai-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

Addressed the actionable PTY finding from review 44042: the PTY capture test now fails closed when util-linux script is unavailable instead of silently skipping (commit 92b1428).

The Bool next_open is the accepted exact wire encoding of the DAG-owned DynamicLineState transition at this host seam; Rust does not decide or construct the state. The scoped Rust bridge is the explicitly authorized consumer boundary, with the authored seed note naming its generated-host-effect dissolution trigger and #7350 SeedGrowthJustification dependency. Replacing that seam or introducing a parallel canonical-state transport would exceed the approved five-file consumer boundary. — sent from jolly-hawk-270

@gunbai-bot
gunbai-bot Bot marked this pull request as draft July 28, 2026 19:40
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 28, 2026 21:25
@gunbai-bot

gunbai-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor Author

Regarding review 44096: the hand-Rust seam is explicitly covered by the merged #7350 SeedGrowthJustification authority now on main. That row names the owning interpreter-facing seam extraction/cli_run hollowing lane and the concrete generated host-effect bridge dissolution trigger; the scoped bridge remains retained only until that dependency lands. The current five-file diff cites this authority in the PR body and observation seed note, with no emitter or parallel authority changes. No additional code change is warranted within this approved boundary. — sent from jolly-hawk-270

@briansrls
briansrls merged commit 445bac3 into main Jul 29, 2026
5 checks passed
@briansrls
briansrls deleted the session/jolly-hawk-270 branch July 29, 2026 00:34
briansrls pushed a commit that referenced this pull request Jul 29, 2026
Main added one row, fleet-dashboard-instance-membership (#7395), authored before
the plain-language rewrite landed and so written in the old register. Rewritten
here to match the rest — otherwise the newest row is the one that reads worst,
which is exactly the complaint the rewrite answers.

Only ROADMAP.md conflicted; the authority auto-merged. ROADMAP.md is regenerated
rather than hand-resolved, under the same validation as before: the renderer first
reproduces origin/main's committed file from origin/main's authority byte-for-byte
(50 rows), then emits this tree.

Counts move to 51 declared / 2 accepted / 49 active and the page witness assertion
moves with them. Both acceptance digests recomputed and unchanged, so main did not
touch the accepted rows' criteria. Brief and lead budgets still clear: longest
brief 43 words against 100, longest lead 84 characters against 300.

Two rows on this roadmap now have merged implementations that this change
deliberately does not accept: pderive-static-supplemental-contract (#7324) and
observation-scoped-run-consumer (#7348). Merged code is review evidence; a row
closes on a receipt naming its executed test and delivered artifacts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TrmQVbQ37wSeuAEHRwCYnS
briansrls added a commit that referenced this pull request Jul 29, 2026
…ry missing function as "no main" (#7401)

The generated-artifact heal ran a binary and a source tree from DIFFERENT
revisions. `build` compiles the default pull_request checkout — the merge ref —
while `heal` checks out `github.head_ref`, the branch head, because it pushes the
regeneration back. Nothing paired them. A generated artifact's identity is
(authority source x compiler), and the job silently combined two revisions of it.

Latent until a seed change adds a Rust->.dag call. #7348 landed the scoped-run
observation seed, whose Rust calls
gunbc.observation_seed_render.scoped_run_begin_write_measured; every open PR whose
branch head predated it went red at once (#7392, #7394, #7395 — identical failure,
none of them at fault), while main stayed green because ci_regen_heal_if skips
this job on push. The regression was invisible where it landed and blamed three
PRs that did not cause it.

Reproduced by execution: ONE binary built from the merge ref, run against a
pre-#7348 tree reproduces the exact CI failure; run against the same tree with the
advance merged in it exits 0 with zero drift.

The guard compares the tree against `github.sha` — the revision the build job
actually compiled — not against `origin/main`. Per operator ruling 2026-07-29,
`origin/main` names several different things (this runner's, a developer's, the
real source of truth) and can race an advance mid-run; the binary's own provenance
has no such ambiguity and is known exactly within the same workflow run. An
unresolvable provenance refuses rather than assuming agreement.

It is deliberately narrow: only SEED (src/v1) commits can introduce a Rust->.dag
expectation, so a .dag-only advance cannot skew a compiled binary and does not red
the PR. At the incident's branch point the set is two commits, one of which IS
445bac3 (#7348) — the guard names the responsible commit in its own refusal; at
current main and post-merge it is empty and silent. Preventing a stale branch from
MERGING is deliberately out of scope: that needs a source-of-truth model the repo
does not have yet (SCM lane, after v1 deletion). Landed as a declared Scaffold —
validation where construction (heal building from the tree it heals) was too
expensive today — with that named dissolution trigger.

Second, independent defect, and the reason this cost hours to find: both
run_in_context and run_in_context_with_args threw away the name they had just
failed to look up and reported InterpError::NoMainFunction, so EVERY missing named
function surfaced as "no main function found". main_wet was never missing.
NoSuchFunction { name } already existed; both sites now use it, and since those
were NoMainFunction's only two constructors the variant is deleted rather than
left unconstructible. Its one consumer, run_claim_failure_receipt, had to match
both variants precisely because of this bug and now matches the single honest arm.
Proven by a discriminating run: the same failure now reads
"no such function: scoped_run_begin_write_measured".

Verified: whole-tree compile 0 blocking errors; generated_artifact_drift_test 8/8
including witness_committed_is_fixed_point (ci.yml regenerated from the model, not
hand-edited) and its RED control; observation_seed_scoped_run_witness_test 10/10;
cargo test --test scoped_run_observation 7/7; cargo fmt --all --check clean;
emitted guard bash -n clean.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 19, 2026
… stub, two live rosters.

review 53574 finding 1, plus two rosters no review found.

ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the
rustfmt-PATH shell for the regen job; its own note names regen_stage0's
standalone rustfmt spawn as the whole subject. With regen deleted the module
has no subject, and its only consumers were its own golden test and one
witness file — kept alive by its own test, which is the attractor DESIGN
section 3 says to uproot rather than leave as quarry. Module and test deleted.

EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in
tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows
refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which
survives the cut, so the frontier row is re-declared locally as
witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep
the evidence for surviving claims, delete only the machinery.

HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded
echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper
better deleted than stubbed. Deleting it made three notes false in the present
tense ('The guard below refuses...' referring to nothing), so each now opens
with a RETIRED marker and reads as history. They are not deleted: they carry
the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row
deleted for one reason takes everything in it.

TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review.
devboot/program.dag offered_programs() still offered regen_stage0 as a
buildable target — its note reasons carefully about the missing-from-here
direction and does not cover this one, a name offered here that exists
nowhere. fallback_arm_census.dag inventoried the deleted
src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned
count 25 -> 24 across three sites, because the count is encoded in a
DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in
the literal and the witness import. A count baked into a symbol is the
hand-count-beside-structure class, and it is why deleting one row touched two
files.
briansrls pushed a commit that referenced this pull request Aug 19, 2026
…ired-regen fold (#8406)

* Delete regen_stage0 root and its machinery (replacement migration cut).

Remove the regen driver binary, stage0 emit-plan authorities, regen verify
gates/transports, skip witness, and the regen region in cli_run/v1_interpreter.
Production regen CI was already gone; this deletes zero-consumer machinery per
the regen root cut program.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix forward after regen_stage0 deletion so CI builds again.

Restore required-regen as one claim_executor fold, remove stale gate and witness references to deleted comparison and emit-plan machinery, and repair the DAG corpus imports that blocked compilation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refuse empty regen populations and carry ruling in PR description contract.

The required-regen fold now grounds planned population on committed stage0 files, refuses empty emit or missing candidate trees before any digest comparison, and adds admission witnesses so zero equals zero cannot report green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove deleted regen bins from ci_release_bins and regenerate fleet-converge.

Union the regen root cut with #8409 by dropping regen_stage0, regen_floor_skip_witness, and resolution_divergence_census from the derived pack authority and re-emitting fleet-converge.yml via main_wet.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align gitattributes witness with committed-only projection paths.

After stage0_emit_plan removal, merge policy rows derive from committed generated artifacts only — pin the witness to v1_interpreter_dispatch_generated.rs instead of plan-derived std_algebra.rs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix witness_holds to call dispatch projection test

Co-authored-by: Cursor <cursoragent@cursor.com>

* Dissolve regen private forks into cli_run general utilities.

Move regen_input_sources and regen_source_roots to cli_run using
build_module_path_index and collect_dag_files_result; drop duplicate
walkers, path helpers, and fnv1a64 from required_regen_host (667 lines).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix required_regen fold_list empty types for string path accumulators.

Use no_string_paths instead of no_regen_refusals so drift and hand-unverifiable
folds accumulate List<String>, matching collect_* helpers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix witness floor regressions from regen cut collateral damage.

Restore native_len Str fast path (reverts accidental deletion), derive
generated stage0 paths from generated_artifact registry instead of live
git observation, retire deleted scaffold builtin witness, and drop a
greened roadmap_static_site row from floor_expected_red.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor_expected_red chunk_10 brace balance after roster removal.

Removing witness_site_artifact_model_populated left an extra closing brace
that broke module parse and cascaded into annotation errors during strict
preparation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix stage0 lifecycle paths and shrink expected-red roster after merge.

Registry-based derived_generated_stage0_repo_paths now excludes layout
overlap filenames like the prior git observation filter, restoring disjoint
hand/generated semantics and lifecycle totality witnesses. Remove two
witnesses that passed on the latest floor run.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor witnesses: board admission match, stage0 lifecycle, budget band.

Route BoardArticleRefusal discrimination through board_article_refusal_kind at
the admission authority so cross-module witness matches do not fall through at
runtime. Restore generated_stage0_files supply for lifecycle disjointness after
the regen cut removed the emit-plan carrier. Raise required-floor claim budget
to 1000ms to clear throttle-inflated marginal rows on long cgroup-throttled folds.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor CI: match qualified patterns, shrink expected-red roster.

Interpreter Record-pattern matching now falls back to the bare variant
segment like the Variant arm, so cross-module match arms on coproduct
refusals do not fall through non-exhaustive. Type empty BoardArticleRefusal
list folds at the admission authority so refusal literals carry parent_enum.
Remove 100 witnesses that passed while still enrolled in floor_expected_red.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align expected-red roster with main after rebase.

Drop identities main removed with the silent-pick gate retirement (#8409) so the roster matches post-rebase main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop deleted regen/stage0 builtins from generated dispatch.

The interpreter no longer implements stage0_emission_source_identities_host or regen_verify failure-detail hosts; keep the generated EvalBuiltinArm match exhaustive so claim_executor builds.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Shrink expected-red roster: roadmap_page authority witness now passes.

CI at 826bcde reported witness_authority_serializes_with_structure passing while still enrolled; remove it so the floor fold can green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Re-apply regen builtin deletions lost to the merge resolution.

The merge took main's v1_interpreter.rs wholesale, restoring three builtin
arms this cut deleted (stage0_emission_source_identities_host and the two
regen_verify_gate failure-detail arms). Their dispatch entries are gone, so
the macro no longer matched. Deletions re-applied; main's record-pattern
helper is kept.

* Delete the inert phase-receipt carrier from required_regen (review 53501).

review 53501 flagged RequiredRegenPhaseReceipt.elapsed_ms as a flat-scalar
duration at a substrate seam. The deeper defect is that the carrier never
carried anything: the host's time_phase() ignored both its accumulator and
its name and returned f() unchanged, so `phases` was allocated empty, passed
through the admission fold unread, and stored in every attempt as []. Nothing
in the verdict reads it and no host path populates it.

Re-typing the field on std.types Milliseconds would have grounded a unit that
is never measured. Deleted instead: the type, the field, the parameter, the
no-op time_phase, and the four [] literals in the witness. Elapsed is still
reported by the host's own measured run_started.elapsed().

* Delete the dead regen CI-script subtree and dissolve the hollow projection-source coproduct.

Two residues this cut left standing.

ci_spec.dag still carried regen_floor_skip_witness_bin, its policy note, and
the two script emitters that composed them (ci_regen_floor_skip_shortcut_script,
gunbc_ci_regen_floor_only_script, gunbc_ci_regen_floor_run). They emitted a
shell invocation of a binary this cut deleted, and no surviving workflow reaches
them — .github/workflows carries only witnesses.yml and fleet-converge.yml,
neither of which mentions regen. gunbc_ci_regen_floor_run had no caller outside
its own module. Deleted, with the two imports that served only it. The regen-job
GATE surface (project_ci_regen_job_gates, gunbc_ci_regen_floor_gates) is
deliberately untouched: it is load-bearing to the enrollment-asymmetry wall in
gunbc.commit_workflow and has live witness consumers.

generated_projection_paths.dag carried GeneratedProjectionPathSource as a
two-arm coproduct whose second arm, Stage0EmitPlanRetired, was uninhabited by
construction after the stage0_emit_plan deletion (review 53512, advisory). With
one source the axis carries nothing: the collision refusal named first_source
and duplicate_source, both of which could only ever be CommittedGeneratedArtifact
— a distinction the type promised and the population could not supply. The
coproduct and the row's source field are deleted; the collision refusal keeps
the path, which is the fact it actually establishes, and still refuses two
committed artifacts claiming one path.

Verified by execution on the merged tree: test.claim.gitattributes_emit_witness
witness_holds returns true, and dag/gunbc/ci_spec.dag resolves.

* Delete required_regen_fixed_point_admission and FixedPointRefused: zero consumers, vacuous verdict.

Neither name had a consumer anywhere in the tree — not production, not a
witness. The host answers the fixed-point question itself: claim_executor's
--required-regen-fixed-point calls cli_run::run_required_regen_fixed_point,
which compares pass-1 and pass-2 digests in Rust and never evaluates this
module.

The success arm was also vacuous. It constructed RequiredRegenAttempt with
generated_outcomes: [] and hand_outcomes: [] — the exact shape its sibling
required_regen_sync_admission refuses as EmptyCommittedPopulation and
EmptyEmitResult. A consumer receiving that verdict and asking how many
surfaces matched would read zero, indistinguishable from a genuinely empty
run. review 53522 read the reuse of RequiredRegenSyncRunnable as a naming
smell; the name was the smaller half.

Verified by execution on the merged tree: all five claims in
required_regen_admission_witness_test return true individually, not only
through the witness_holds conjunction.

The wider finding this came out of — that the whole required_regen fold has
no production consumer — is NOT addressed here and is with the operator.

* Delete the interpreter's cross-claim memo for a function this cut removes.

v1_interpreter.rs carried a hardcoded cross-claim memo keyed on the exact
name "ci_heal_binary_source_skew_guard_script" at two sites, a getter and a
setter. That name resolved on main against the unprefixed declaration in
src/v2/workflow/ci_heal_skew_guard_emit.dag, which this branch deletes; no
unprefixed declaration survives anywhere in the tree, so both branches match
nothing. They are dead because of this cut, which makes this the only PR that
can honestly remove them.

ZERO_ARG_PURE_CROSS_CLAIM_MEMO goes with them. Its only reader and only
writer were those two branches, so leaving the thread_local would keep a map
that is never written and only cleared — the same dead-machinery class one
level down. CROSS_CLAIM_FN_KEEPALIVE stays: the prepare_grammar path still
uses it.

Stated rather than left to be found, because it changes how the remaining
half of that block should be read: deep-moth-771 established today that the
prepare_grammar memo beside it CANNOT FIRE — its key bails on Value::Closure
and every grammar in the corpus carries one (sync_tokens is a Set with a
closure member, including the empty grammar in std/grammar.dag). That is the
grammar lane's to resolve, not this cut's. With this deletion the thread_local
holds one memo that cannot hit and one keepalive serving it.

cargo build --release --bin claim_executor --bin gunbc green.

* Delete the regen cut's remaining leaves: orphan rustfmt emitter, heal stub, two live rosters.

review 53574 finding 1, plus two rosters no review found.

ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the
rustfmt-PATH shell for the regen job; its own note names regen_stage0's
standalone rustfmt spawn as the whole subject. With regen deleted the module
has no subject, and its only consumers were its own golden test and one
witness file — kept alive by its own test, which is the attractor DESIGN
section 3 says to uproot rather than leave as quarry. Module and test deleted.

EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in
tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows
refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which
survives the cut, so the frontier row is re-declared locally as
witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep
the evidence for surviving claims, delete only the machinery.

HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded
echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper
better deleted than stubbed. Deleting it made three notes false in the present
tense ('The guard below refuses...' referring to nothing), so each now opens
with a RETIRED marker and reads as history. They are not deleted: they carry
the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row
deleted for one reason takes everything in it.

TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review.
devboot/program.dag offered_programs() still offered regen_stage0 as a
buildable target — its note reasons carefully about the missing-from-here
direction and does not cover this one, a name offered here that exists
nowhere. fallback_arm_census.dag inventoried the deleted
src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned
count 25 -> 24 across three sites, because the count is encoded in a
DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in
the literal and the witness import. A count baked into a symbol is the
hand-count-beside-structure class, and it is why deleting one row touched two
files.

* Stop DESIGN.md reciting regen_stage0 as a survivor of the floor cut (review 53574).

The CI rung-drop bullet read: 'the regen_stage0 self-host fixed point and its
regen_input_sources closure likewise survive, with only the required job that
ran them removed.' That was true when written. This PR deletes regen_stage0.rs
outright along with RegenVerifyGate and SelfHostStalenessGate, so the sentence
would ship FALSE in the canonical authority — README and CLAUDE symlink to
DESIGN.md, and every session plans from it.

It is the exact failure the same paragraph names: a knowingly-false recital in
the canonical authority is premise contamination, because each reader grounds a
decision on something that no longer exists. Landing that class INTO the
paragraph that defines it is the part worth refusing.

The clause is REWRITTEN, not annotated — a second sentence beside the old one
would be two accounts of one fact, the section 3 duplication, in a bullet
already carrying a declared rung drop. It now separates the halves that this
cut separates: the regen_input_sources import closure survives and is read by
v1_compiler.required_regen_host, while the binary that consumed it and the two
gates that invoked it are deleted at the root, leaving
claim_executor --required-regen-fixed-point as the only answer to the
fixed-point question. It also records that the old clause was true when written
and which half this cut falsified, so the change is legible rather than silent.

DESIGN.md is REGENERATED through generated_artifact_gate main_wet, not
hand-edited — it is a projection of gunbc.design_document and a hand edit is
reverted by drift heal. One line changed, matching the one carrier edit.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 19, 2026
… its only inhabitant (#8485)

* Delete regen_stage0 root and its machinery (replacement migration cut).

Remove the regen driver binary, stage0 emit-plan authorities, regen verify
gates/transports, skip witness, and the regen region in cli_run/v1_interpreter.
Production regen CI was already gone; this deletes zero-consumer machinery per
the regen root cut program.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix forward after regen_stage0 deletion so CI builds again.

Restore required-regen as one claim_executor fold, remove stale gate and witness references to deleted comparison and emit-plan machinery, and repair the DAG corpus imports that blocked compilation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refuse empty regen populations and carry ruling in PR description contract.

The required-regen fold now grounds planned population on committed stage0 files, refuses empty emit or missing candidate trees before any digest comparison, and adds admission witnesses so zero equals zero cannot report green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove deleted regen bins from ci_release_bins and regenerate fleet-converge.

Union the regen root cut with #8409 by dropping regen_stage0, regen_floor_skip_witness, and resolution_divergence_census from the derived pack authority and re-emitting fleet-converge.yml via main_wet.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align gitattributes witness with committed-only projection paths.

After stage0_emit_plan removal, merge policy rows derive from committed generated artifacts only — pin the witness to v1_interpreter_dispatch_generated.rs instead of plan-derived std_algebra.rs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix witness_holds to call dispatch projection test

Co-authored-by: Cursor <cursoragent@cursor.com>

* Dissolve regen private forks into cli_run general utilities.

Move regen_input_sources and regen_source_roots to cli_run using
build_module_path_index and collect_dag_files_result; drop duplicate
walkers, path helpers, and fnv1a64 from required_regen_host (667 lines).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix required_regen fold_list empty types for string path accumulators.

Use no_string_paths instead of no_regen_refusals so drift and hand-unverifiable
folds accumulate List<String>, matching collect_* helpers.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix witness floor regressions from regen cut collateral damage.

Restore native_len Str fast path (reverts accidental deletion), derive
generated stage0 paths from generated_artifact registry instead of live
git observation, retire deleted scaffold builtin witness, and drop a
greened roadmap_static_site row from floor_expected_red.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor_expected_red chunk_10 brace balance after roster removal.

Removing witness_site_artifact_model_populated left an extra closing brace
that broke module parse and cascaded into annotation errors during strict
preparation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix stage0 lifecycle paths and shrink expected-red roster after merge.

Registry-based derived_generated_stage0_repo_paths now excludes layout
overlap filenames like the prior git observation filter, restoring disjoint
hand/generated semantics and lifecycle totality witnesses. Remove two
witnesses that passed on the latest floor run.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor witnesses: board admission match, stage0 lifecycle, budget band.

Route BoardArticleRefusal discrimination through board_article_refusal_kind at
the admission authority so cross-module witness matches do not fall through at
runtime. Restore generated_stage0_files supply for lifecycle disjointness after
the regen cut removed the emit-plan carrier. Raise required-floor claim budget
to 1000ms to clear throttle-inflated marginal rows on long cgroup-throttled folds.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix floor CI: match qualified patterns, shrink expected-red roster.

Interpreter Record-pattern matching now falls back to the bare variant
segment like the Variant arm, so cross-module match arms on coproduct
refusals do not fall through non-exhaustive. Type empty BoardArticleRefusal
list folds at the admission authority so refusal literals carry parent_enum.
Remove 100 witnesses that passed while still enrolled in floor_expected_red.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align expected-red roster with main after rebase.

Drop identities main removed with the silent-pick gate retirement (#8409) so the roster matches post-rebase main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop deleted regen/stage0 builtins from generated dispatch.

The interpreter no longer implements stage0_emission_source_identities_host or regen_verify failure-detail hosts; keep the generated EvalBuiltinArm match exhaustive so claim_executor builds.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Shrink expected-red roster: roadmap_page authority witness now passes.

CI at 826bcde reported witness_authority_serializes_with_structure passing while still enrolled; remove it so the floor fold can green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Re-apply regen builtin deletions lost to the merge resolution.

The merge took main's v1_interpreter.rs wholesale, restoring three builtin
arms this cut deleted (stage0_emission_source_identities_host and the two
regen_verify_gate failure-detail arms). Their dispatch entries are gone, so
the macro no longer matched. Deletions re-applied; main's record-pattern
helper is kept.

* Delete the inert phase-receipt carrier from required_regen (review 53501).

review 53501 flagged RequiredRegenPhaseReceipt.elapsed_ms as a flat-scalar
duration at a substrate seam. The deeper defect is that the carrier never
carried anything: the host's time_phase() ignored both its accumulator and
its name and returned f() unchanged, so `phases` was allocated empty, passed
through the admission fold unread, and stored in every attempt as []. Nothing
in the verdict reads it and no host path populates it.

Re-typing the field on std.types Milliseconds would have grounded a unit that
is never measured. Deleted instead: the type, the field, the parameter, the
no-op time_phase, and the four [] literals in the witness. Elapsed is still
reported by the host's own measured run_started.elapsed().

* Delete the dead regen CI-script subtree and dissolve the hollow projection-source coproduct.

Two residues this cut left standing.

ci_spec.dag still carried regen_floor_skip_witness_bin, its policy note, and
the two script emitters that composed them (ci_regen_floor_skip_shortcut_script,
gunbc_ci_regen_floor_only_script, gunbc_ci_regen_floor_run). They emitted a
shell invocation of a binary this cut deleted, and no surviving workflow reaches
them — .github/workflows carries only witnesses.yml and fleet-converge.yml,
neither of which mentions regen. gunbc_ci_regen_floor_run had no caller outside
its own module. Deleted, with the two imports that served only it. The regen-job
GATE surface (project_ci_regen_job_gates, gunbc_ci_regen_floor_gates) is
deliberately untouched: it is load-bearing to the enrollment-asymmetry wall in
gunbc.commit_workflow and has live witness consumers.

generated_projection_paths.dag carried GeneratedProjectionPathSource as a
two-arm coproduct whose second arm, Stage0EmitPlanRetired, was uninhabited by
construction after the stage0_emit_plan deletion (review 53512, advisory). With
one source the axis carries nothing: the collision refusal named first_source
and duplicate_source, both of which could only ever be CommittedGeneratedArtifact
— a distinction the type promised and the population could not supply. The
coproduct and the row's source field are deleted; the collision refusal keeps
the path, which is the fact it actually establishes, and still refuses two
committed artifacts claiming one path.

Verified by execution on the merged tree: test.claim.gitattributes_emit_witness
witness_holds returns true, and dag/gunbc/ci_spec.dag resolves.

* Delete required_regen_fixed_point_admission and FixedPointRefused: zero consumers, vacuous verdict.

Neither name had a consumer anywhere in the tree — not production, not a
witness. The host answers the fixed-point question itself: claim_executor's
--required-regen-fixed-point calls cli_run::run_required_regen_fixed_point,
which compares pass-1 and pass-2 digests in Rust and never evaluates this
module.

The success arm was also vacuous. It constructed RequiredRegenAttempt with
generated_outcomes: [] and hand_outcomes: [] — the exact shape its sibling
required_regen_sync_admission refuses as EmptyCommittedPopulation and
EmptyEmitResult. A consumer receiving that verdict and asking how many
surfaces matched would read zero, indistinguishable from a genuinely empty
run. review 53522 read the reuse of RequiredRegenSyncRunnable as a naming
smell; the name was the smaller half.

Verified by execution on the merged tree: all five claims in
required_regen_admission_witness_test return true individually, not only
through the witness_holds conjunction.

The wider finding this came out of — that the whole required_regen fold has
no production consumer — is NOT addressed here and is with the operator.

* Delete the interpreter's cross-claim memo for a function this cut removes.

v1_interpreter.rs carried a hardcoded cross-claim memo keyed on the exact
name "ci_heal_binary_source_skew_guard_script" at two sites, a getter and a
setter. That name resolved on main against the unprefixed declaration in
src/v2/workflow/ci_heal_skew_guard_emit.dag, which this branch deletes; no
unprefixed declaration survives anywhere in the tree, so both branches match
nothing. They are dead because of this cut, which makes this the only PR that
can honestly remove them.

ZERO_ARG_PURE_CROSS_CLAIM_MEMO goes with them. Its only reader and only
writer were those two branches, so leaving the thread_local would keep a map
that is never written and only cleared — the same dead-machinery class one
level down. CROSS_CLAIM_FN_KEEPALIVE stays: the prepare_grammar path still
uses it.

Stated rather than left to be found, because it changes how the remaining
half of that block should be read: deep-moth-771 established today that the
prepare_grammar memo beside it CANNOT FIRE — its key bails on Value::Closure
and every grammar in the corpus carries one (sync_tokens is a Set with a
closure member, including the empty grammar in std/grammar.dag). That is the
grammar lane's to resolve, not this cut's. With this deletion the thread_local
holds one memo that cannot hit and one keepalive serving it.

cargo build --release --bin claim_executor --bin gunbc green.

* Delete the regen cut's remaining leaves: orphan rustfmt emitter, heal stub, two live rosters.

review 53574 finding 1, plus two rosters no review found.

ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the
rustfmt-PATH shell for the regen job; its own note names regen_stage0's
standalone rustfmt spawn as the whole subject. With regen deleted the module
has no subject, and its only consumers were its own golden test and one
witness file — kept alive by its own test, which is the attractor DESIGN
section 3 says to uproot rather than leave as quarry. Module and test deleted.

EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in
tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows
refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which
survives the cut, so the frontier row is re-declared locally as
witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep
the evidence for surviving claims, delete only the machinery.

HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded
echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper
better deleted than stubbed. Deleting it made three notes false in the present
tense ('The guard below refuses...' referring to nothing), so each now opens
with a RETIRED marker and reads as history. They are not deleted: they carry
the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row
deleted for one reason takes everything in it.

TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review.
devboot/program.dag offered_programs() still offered regen_stage0 as a
buildable target — its note reasons carefully about the missing-from-here
direction and does not cover this one, a name offered here that exists
nowhere. fallback_arm_census.dag inventoried the deleted
src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned
count 25 -> 24 across three sites, because the count is encoded in a
DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in
the literal and the witness import. A count baked into a symbol is the
hand-count-beside-structure class, and it is why deleting one row touched two
files.

* Stop DESIGN.md reciting regen_stage0 as a survivor of the floor cut (review 53574).

The CI rung-drop bullet read: 'the regen_stage0 self-host fixed point and its
regen_input_sources closure likewise survive, with only the required job that
ran them removed.' That was true when written. This PR deletes regen_stage0.rs
outright along with RegenVerifyGate and SelfHostStalenessGate, so the sentence
would ship FALSE in the canonical authority — README and CLAUDE symlink to
DESIGN.md, and every session plans from it.

It is the exact failure the same paragraph names: a knowingly-false recital in
the canonical authority is premise contamination, because each reader grounds a
decision on something that no longer exists. Landing that class INTO the
paragraph that defines it is the part worth refusing.

The clause is REWRITTEN, not annotated — a second sentence beside the old one
would be two accounts of one fact, the section 3 duplication, in a bullet
already carrying a declared rung drop. It now separates the halves that this
cut separates: the regen_input_sources import closure survives and is read by
v1_compiler.required_regen_host, while the binary that consumed it and the two
gates that invoked it are deleted at the root, leaving
claim_executor --required-regen-fixed-point as the only answer to the
fixed-point question. It also records that the old clause was true when written
and which half this cut falsified, so the change is legible rather than silent.

DESIGN.md is REGENERATED through generated_artifact_gate main_wet, not
hand-edited — it is a projection of gunbc.design_document and a hand edit is
reverted by drift heal. One line changed, matching the one carrier edit.

* WIP: 8406 ownership

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant