Repository navigation
Scoped gunbc run observation TTY and pipe consumer - #7348
Conversation
…sion/jolly-hawk-270
|
Addressed the actionable PTY finding from review 44042: the PTY capture test now fails closed when util-linux The Bool |
|
Regarding review 44096: the hand-Rust seam is explicitly covered by the merged #7350 SeedGrowthJustification authority now on main. That row names the owning interpreter-facing seam extraction/cli_run hollowing lane and the concrete generated host-effect bridge dissolution trigger; the scoped bridge remains retained only until that dependency lands. The current five-file diff cites this authority in the PR body and observation seed note, with no emitter or parallel authority changes. No additional code change is warranted within this approved boundary. — sent from jolly-hawk-270 |
Main added one row, fleet-dashboard-instance-membership (#7395), authored before the plain-language rewrite landed and so written in the old register. Rewritten here to match the rest — otherwise the newest row is the one that reads worst, which is exactly the complaint the rewrite answers. Only ROADMAP.md conflicted; the authority auto-merged. ROADMAP.md is regenerated rather than hand-resolved, under the same validation as before: the renderer first reproduces origin/main's committed file from origin/main's authority byte-for-byte (50 rows), then emits this tree. Counts move to 51 declared / 2 accepted / 49 active and the page witness assertion moves with them. Both acceptance digests recomputed and unchanged, so main did not touch the accepted rows' criteria. Brief and lead budgets still clear: longest brief 43 words against 100, longest lead 84 characters against 300. Two rows on this roadmap now have merged implementations that this change deliberately does not accept: pderive-static-supplemental-contract (#7324) and observation-scoped-run-consumer (#7348). Merged code is review evidence; a row closes on a receipt naming its executed test and delivered artifacts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TrmQVbQ37wSeuAEHRwCYnS
…ry missing function as "no main" (#7401) The generated-artifact heal ran a binary and a source tree from DIFFERENT revisions. `build` compiles the default pull_request checkout — the merge ref — while `heal` checks out `github.head_ref`, the branch head, because it pushes the regeneration back. Nothing paired them. A generated artifact's identity is (authority source x compiler), and the job silently combined two revisions of it. Latent until a seed change adds a Rust->.dag call. #7348 landed the scoped-run observation seed, whose Rust calls gunbc.observation_seed_render.scoped_run_begin_write_measured; every open PR whose branch head predated it went red at once (#7392, #7394, #7395 — identical failure, none of them at fault), while main stayed green because ci_regen_heal_if skips this job on push. The regression was invisible where it landed and blamed three PRs that did not cause it. Reproduced by execution: ONE binary built from the merge ref, run against a pre-#7348 tree reproduces the exact CI failure; run against the same tree with the advance merged in it exits 0 with zero drift. The guard compares the tree against `github.sha` — the revision the build job actually compiled — not against `origin/main`. Per operator ruling 2026-07-29, `origin/main` names several different things (this runner's, a developer's, the real source of truth) and can race an advance mid-run; the binary's own provenance has no such ambiguity and is known exactly within the same workflow run. An unresolvable provenance refuses rather than assuming agreement. It is deliberately narrow: only SEED (src/v1) commits can introduce a Rust->.dag expectation, so a .dag-only advance cannot skew a compiled binary and does not red the PR. At the incident's branch point the set is two commits, one of which IS 445bac3 (#7348) — the guard names the responsible commit in its own refusal; at current main and post-merge it is empty and silent. Preventing a stale branch from MERGING is deliberately out of scope: that needs a source-of-truth model the repo does not have yet (SCM lane, after v1 deletion). Landed as a declared Scaffold — validation where construction (heal building from the tree it heals) was too expensive today — with that named dissolution trigger. Second, independent defect, and the reason this cost hours to find: both run_in_context and run_in_context_with_args threw away the name they had just failed to look up and reported InterpError::NoMainFunction, so EVERY missing named function surfaced as "no main function found". main_wet was never missing. NoSuchFunction { name } already existed; both sites now use it, and since those were NoMainFunction's only two constructors the variant is deleted rather than left unconstructible. Its one consumer, run_claim_failure_receipt, had to match both variants precisely because of this bug and now matches the single honest arm. Proven by a discriminating run: the same failure now reads "no such function: scoped_run_begin_write_measured". Verified: whole-tree compile 0 blocking errors; generated_artifact_drift_test 8/8 including witness_committed_is_fixed_point (ci.yml regenerated from the model, not hand-edited) and its RED control; observation_seed_scoped_run_witness_test 10/10; cargo test --test scoped_run_observation 7/7; cargo fmt --all --check clean; emitted guard bash -n clean. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
… stub, two live rosters.
review 53574 finding 1, plus two rosters no review found.
ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the
rustfmt-PATH shell for the regen job; its own note names regen_stage0's
standalone rustfmt spawn as the whole subject. With regen deleted the module
has no subject, and its only consumers were its own golden test and one
witness file — kept alive by its own test, which is the attractor DESIGN
section 3 says to uproot rather than leave as quarry. Module and test deleted.
EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in
tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows
refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which
survives the cut, so the frontier row is re-declared locally as
witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep
the evidence for surviving claims, delete only the machinery.
HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded
echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper
better deleted than stubbed. Deleting it made three notes false in the present
tense ('The guard below refuses...' referring to nothing), so each now opens
with a RETIRED marker and reads as history. They are not deleted: they carry
the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row
deleted for one reason takes everything in it.
TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review.
devboot/program.dag offered_programs() still offered regen_stage0 as a
buildable target — its note reasons carefully about the missing-from-here
direction and does not cover this one, a name offered here that exists
nowhere. fallback_arm_census.dag inventoried the deleted
src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned
count 25 -> 24 across three sites, because the count is encoded in a
DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in
the literal and the witness import. A count baked into a symbol is the
hand-count-beside-structure class, and it is why deleting one row touched two
files.
…ired-regen fold (#8406) * Delete regen_stage0 root and its machinery (replacement migration cut). Remove the regen driver binary, stage0 emit-plan authorities, regen verify gates/transports, skip witness, and the regen region in cli_run/v1_interpreter. Production regen CI was already gone; this deletes zero-consumer machinery per the regen root cut program. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix forward after regen_stage0 deletion so CI builds again. Restore required-regen as one claim_executor fold, remove stale gate and witness references to deleted comparison and emit-plan machinery, and repair the DAG corpus imports that blocked compilation. Co-authored-by: Cursor <cursoragent@cursor.com> * Refuse empty regen populations and carry ruling in PR description contract. The required-regen fold now grounds planned population on committed stage0 files, refuses empty emit or missing candidate trees before any digest comparison, and adds admission witnesses so zero equals zero cannot report green. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove deleted regen bins from ci_release_bins and regenerate fleet-converge. Union the regen root cut with #8409 by dropping regen_stage0, regen_floor_skip_witness, and resolution_divergence_census from the derived pack authority and re-emitting fleet-converge.yml via main_wet. Co-authored-by: Cursor <cursoragent@cursor.com> * Align gitattributes witness with committed-only projection paths. After stage0_emit_plan removal, merge policy rows derive from committed generated artifacts only — pin the witness to v1_interpreter_dispatch_generated.rs instead of plan-derived std_algebra.rs. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix witness_holds to call dispatch projection test Co-authored-by: Cursor <cursoragent@cursor.com> * Dissolve regen private forks into cli_run general utilities. Move regen_input_sources and regen_source_roots to cli_run using build_module_path_index and collect_dag_files_result; drop duplicate walkers, path helpers, and fnv1a64 from required_regen_host (667 lines). Co-authored-by: Cursor <cursoragent@cursor.com> * Fix required_regen fold_list empty types for string path accumulators. Use no_string_paths instead of no_regen_refusals so drift and hand-unverifiable folds accumulate List<String>, matching collect_* helpers. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix witness floor regressions from regen cut collateral damage. Restore native_len Str fast path (reverts accidental deletion), derive generated stage0 paths from generated_artifact registry instead of live git observation, retire deleted scaffold builtin witness, and drop a greened roadmap_static_site row from floor_expected_red. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor_expected_red chunk_10 brace balance after roster removal. Removing witness_site_artifact_model_populated left an extra closing brace that broke module parse and cascaded into annotation errors during strict preparation. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix stage0 lifecycle paths and shrink expected-red roster after merge. Registry-based derived_generated_stage0_repo_paths now excludes layout overlap filenames like the prior git observation filter, restoring disjoint hand/generated semantics and lifecycle totality witnesses. Remove two witnesses that passed on the latest floor run. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor witnesses: board admission match, stage0 lifecycle, budget band. Route BoardArticleRefusal discrimination through board_article_refusal_kind at the admission authority so cross-module witness matches do not fall through at runtime. Restore generated_stage0_files supply for lifecycle disjointness after the regen cut removed the emit-plan carrier. Raise required-floor claim budget to 1000ms to clear throttle-inflated marginal rows on long cgroup-throttled folds. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor CI: match qualified patterns, shrink expected-red roster. Interpreter Record-pattern matching now falls back to the bare variant segment like the Variant arm, so cross-module match arms on coproduct refusals do not fall through non-exhaustive. Type empty BoardArticleRefusal list folds at the admission authority so refusal literals carry parent_enum. Remove 100 witnesses that passed while still enrolled in floor_expected_red. Co-authored-by: Cursor <cursoragent@cursor.com> * Align expected-red roster with main after rebase. Drop identities main removed with the silent-pick gate retirement (#8409) so the roster matches post-rebase main. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop deleted regen/stage0 builtins from generated dispatch. The interpreter no longer implements stage0_emission_source_identities_host or regen_verify failure-detail hosts; keep the generated EvalBuiltinArm match exhaustive so claim_executor builds. Co-authored-by: Cursor <cursoragent@cursor.com> * Shrink expected-red roster: roadmap_page authority witness now passes. CI at 826bcde reported witness_authority_serializes_with_structure passing while still enrolled; remove it so the floor fold can green. Co-authored-by: Cursor <cursoragent@cursor.com> * Re-apply regen builtin deletions lost to the merge resolution. The merge took main's v1_interpreter.rs wholesale, restoring three builtin arms this cut deleted (stage0_emission_source_identities_host and the two regen_verify_gate failure-detail arms). Their dispatch entries are gone, so the macro no longer matched. Deletions re-applied; main's record-pattern helper is kept. * Delete the inert phase-receipt carrier from required_regen (review 53501). review 53501 flagged RequiredRegenPhaseReceipt.elapsed_ms as a flat-scalar duration at a substrate seam. The deeper defect is that the carrier never carried anything: the host's time_phase() ignored both its accumulator and its name and returned f() unchanged, so `phases` was allocated empty, passed through the admission fold unread, and stored in every attempt as []. Nothing in the verdict reads it and no host path populates it. Re-typing the field on std.types Milliseconds would have grounded a unit that is never measured. Deleted instead: the type, the field, the parameter, the no-op time_phase, and the four [] literals in the witness. Elapsed is still reported by the host's own measured run_started.elapsed(). * Delete the dead regen CI-script subtree and dissolve the hollow projection-source coproduct. Two residues this cut left standing. ci_spec.dag still carried regen_floor_skip_witness_bin, its policy note, and the two script emitters that composed them (ci_regen_floor_skip_shortcut_script, gunbc_ci_regen_floor_only_script, gunbc_ci_regen_floor_run). They emitted a shell invocation of a binary this cut deleted, and no surviving workflow reaches them — .github/workflows carries only witnesses.yml and fleet-converge.yml, neither of which mentions regen. gunbc_ci_regen_floor_run had no caller outside its own module. Deleted, with the two imports that served only it. The regen-job GATE surface (project_ci_regen_job_gates, gunbc_ci_regen_floor_gates) is deliberately untouched: it is load-bearing to the enrollment-asymmetry wall in gunbc.commit_workflow and has live witness consumers. generated_projection_paths.dag carried GeneratedProjectionPathSource as a two-arm coproduct whose second arm, Stage0EmitPlanRetired, was uninhabited by construction after the stage0_emit_plan deletion (review 53512, advisory). With one source the axis carries nothing: the collision refusal named first_source and duplicate_source, both of which could only ever be CommittedGeneratedArtifact — a distinction the type promised and the population could not supply. The coproduct and the row's source field are deleted; the collision refusal keeps the path, which is the fact it actually establishes, and still refuses two committed artifacts claiming one path. Verified by execution on the merged tree: test.claim.gitattributes_emit_witness witness_holds returns true, and dag/gunbc/ci_spec.dag resolves. * Delete required_regen_fixed_point_admission and FixedPointRefused: zero consumers, vacuous verdict. Neither name had a consumer anywhere in the tree — not production, not a witness. The host answers the fixed-point question itself: claim_executor's --required-regen-fixed-point calls cli_run::run_required_regen_fixed_point, which compares pass-1 and pass-2 digests in Rust and never evaluates this module. The success arm was also vacuous. It constructed RequiredRegenAttempt with generated_outcomes: [] and hand_outcomes: [] — the exact shape its sibling required_regen_sync_admission refuses as EmptyCommittedPopulation and EmptyEmitResult. A consumer receiving that verdict and asking how many surfaces matched would read zero, indistinguishable from a genuinely empty run. review 53522 read the reuse of RequiredRegenSyncRunnable as a naming smell; the name was the smaller half. Verified by execution on the merged tree: all five claims in required_regen_admission_witness_test return true individually, not only through the witness_holds conjunction. The wider finding this came out of — that the whole required_regen fold has no production consumer — is NOT addressed here and is with the operator. * Delete the interpreter's cross-claim memo for a function this cut removes. v1_interpreter.rs carried a hardcoded cross-claim memo keyed on the exact name "ci_heal_binary_source_skew_guard_script" at two sites, a getter and a setter. That name resolved on main against the unprefixed declaration in src/v2/workflow/ci_heal_skew_guard_emit.dag, which this branch deletes; no unprefixed declaration survives anywhere in the tree, so both branches match nothing. They are dead because of this cut, which makes this the only PR that can honestly remove them. ZERO_ARG_PURE_CROSS_CLAIM_MEMO goes with them. Its only reader and only writer were those two branches, so leaving the thread_local would keep a map that is never written and only cleared — the same dead-machinery class one level down. CROSS_CLAIM_FN_KEEPALIVE stays: the prepare_grammar path still uses it. Stated rather than left to be found, because it changes how the remaining half of that block should be read: deep-moth-771 established today that the prepare_grammar memo beside it CANNOT FIRE — its key bails on Value::Closure and every grammar in the corpus carries one (sync_tokens is a Set with a closure member, including the empty grammar in std/grammar.dag). That is the grammar lane's to resolve, not this cut's. With this deletion the thread_local holds one memo that cannot hit and one keepalive serving it. cargo build --release --bin claim_executor --bin gunbc green. * Delete the regen cut's remaining leaves: orphan rustfmt emitter, heal stub, two live rosters. review 53574 finding 1, plus two rosters no review found. ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the rustfmt-PATH shell for the regen job; its own note names regen_stage0's standalone rustfmt spawn as the whole subject. With regen deleted the module has no subject, and its only consumers were its own golden test and one witness file — kept alive by its own test, which is the attractor DESIGN section 3 says to uproot rather than leave as quarry. Module and test deleted. EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which survives the cut, so the frontier row is re-declared locally as witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep the evidence for surviving claims, delete only the machinery. HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper better deleted than stubbed. Deleting it made three notes false in the present tense ('The guard below refuses...' referring to nothing), so each now opens with a RETIRED marker and reads as history. They are not deleted: they carry the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row deleted for one reason takes everything in it. TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review. devboot/program.dag offered_programs() still offered regen_stage0 as a buildable target — its note reasons carefully about the missing-from-here direction and does not cover this one, a name offered here that exists nowhere. fallback_arm_census.dag inventoried the deleted src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned count 25 -> 24 across three sites, because the count is encoded in a DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in the literal and the witness import. A count baked into a symbol is the hand-count-beside-structure class, and it is why deleting one row touched two files. * Stop DESIGN.md reciting regen_stage0 as a survivor of the floor cut (review 53574). The CI rung-drop bullet read: 'the regen_stage0 self-host fixed point and its regen_input_sources closure likewise survive, with only the required job that ran them removed.' That was true when written. This PR deletes regen_stage0.rs outright along with RegenVerifyGate and SelfHostStalenessGate, so the sentence would ship FALSE in the canonical authority — README and CLAUDE symlink to DESIGN.md, and every session plans from it. It is the exact failure the same paragraph names: a knowingly-false recital in the canonical authority is premise contamination, because each reader grounds a decision on something that no longer exists. Landing that class INTO the paragraph that defines it is the part worth refusing. The clause is REWRITTEN, not annotated — a second sentence beside the old one would be two accounts of one fact, the section 3 duplication, in a bullet already carrying a declared rung drop. It now separates the halves that this cut separates: the regen_input_sources import closure survives and is read by v1_compiler.required_regen_host, while the binary that consumed it and the two gates that invoked it are deleted at the root, leaving claim_executor --required-regen-fixed-point as the only answer to the fixed-point question. It also records that the old clause was true when written and which half this cut falsified, so the change is legible rather than silent. DESIGN.md is REGENERATED through generated_artifact_gate main_wet, not hand-edited — it is a projection of gunbc.design_document and a hand edit is reverted by drift heal. One line changed, matching the one carrier edit. --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
… its only inhabitant (#8485) * Delete regen_stage0 root and its machinery (replacement migration cut). Remove the regen driver binary, stage0 emit-plan authorities, regen verify gates/transports, skip witness, and the regen region in cli_run/v1_interpreter. Production regen CI was already gone; this deletes zero-consumer machinery per the regen root cut program. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix forward after regen_stage0 deletion so CI builds again. Restore required-regen as one claim_executor fold, remove stale gate and witness references to deleted comparison and emit-plan machinery, and repair the DAG corpus imports that blocked compilation. Co-authored-by: Cursor <cursoragent@cursor.com> * Refuse empty regen populations and carry ruling in PR description contract. The required-regen fold now grounds planned population on committed stage0 files, refuses empty emit or missing candidate trees before any digest comparison, and adds admission witnesses so zero equals zero cannot report green. Co-authored-by: Cursor <cursoragent@cursor.com> * Remove deleted regen bins from ci_release_bins and regenerate fleet-converge. Union the regen root cut with #8409 by dropping regen_stage0, regen_floor_skip_witness, and resolution_divergence_census from the derived pack authority and re-emitting fleet-converge.yml via main_wet. Co-authored-by: Cursor <cursoragent@cursor.com> * Align gitattributes witness with committed-only projection paths. After stage0_emit_plan removal, merge policy rows derive from committed generated artifacts only — pin the witness to v1_interpreter_dispatch_generated.rs instead of plan-derived std_algebra.rs. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix witness_holds to call dispatch projection test Co-authored-by: Cursor <cursoragent@cursor.com> * Dissolve regen private forks into cli_run general utilities. Move regen_input_sources and regen_source_roots to cli_run using build_module_path_index and collect_dag_files_result; drop duplicate walkers, path helpers, and fnv1a64 from required_regen_host (667 lines). Co-authored-by: Cursor <cursoragent@cursor.com> * Fix required_regen fold_list empty types for string path accumulators. Use no_string_paths instead of no_regen_refusals so drift and hand-unverifiable folds accumulate List<String>, matching collect_* helpers. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix witness floor regressions from regen cut collateral damage. Restore native_len Str fast path (reverts accidental deletion), derive generated stage0 paths from generated_artifact registry instead of live git observation, retire deleted scaffold builtin witness, and drop a greened roadmap_static_site row from floor_expected_red. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor_expected_red chunk_10 brace balance after roster removal. Removing witness_site_artifact_model_populated left an extra closing brace that broke module parse and cascaded into annotation errors during strict preparation. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix stage0 lifecycle paths and shrink expected-red roster after merge. Registry-based derived_generated_stage0_repo_paths now excludes layout overlap filenames like the prior git observation filter, restoring disjoint hand/generated semantics and lifecycle totality witnesses. Remove two witnesses that passed on the latest floor run. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor witnesses: board admission match, stage0 lifecycle, budget band. Route BoardArticleRefusal discrimination through board_article_refusal_kind at the admission authority so cross-module witness matches do not fall through at runtime. Restore generated_stage0_files supply for lifecycle disjointness after the regen cut removed the emit-plan carrier. Raise required-floor claim budget to 1000ms to clear throttle-inflated marginal rows on long cgroup-throttled folds. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix floor CI: match qualified patterns, shrink expected-red roster. Interpreter Record-pattern matching now falls back to the bare variant segment like the Variant arm, so cross-module match arms on coproduct refusals do not fall through non-exhaustive. Type empty BoardArticleRefusal list folds at the admission authority so refusal literals carry parent_enum. Remove 100 witnesses that passed while still enrolled in floor_expected_red. Co-authored-by: Cursor <cursoragent@cursor.com> * Align expected-red roster with main after rebase. Drop identities main removed with the silent-pick gate retirement (#8409) so the roster matches post-rebase main. Co-authored-by: Cursor <cursoragent@cursor.com> * Drop deleted regen/stage0 builtins from generated dispatch. The interpreter no longer implements stage0_emission_source_identities_host or regen_verify failure-detail hosts; keep the generated EvalBuiltinArm match exhaustive so claim_executor builds. Co-authored-by: Cursor <cursoragent@cursor.com> * Shrink expected-red roster: roadmap_page authority witness now passes. CI at 826bcde reported witness_authority_serializes_with_structure passing while still enrolled; remove it so the floor fold can green. Co-authored-by: Cursor <cursoragent@cursor.com> * Re-apply regen builtin deletions lost to the merge resolution. The merge took main's v1_interpreter.rs wholesale, restoring three builtin arms this cut deleted (stage0_emission_source_identities_host and the two regen_verify_gate failure-detail arms). Their dispatch entries are gone, so the macro no longer matched. Deletions re-applied; main's record-pattern helper is kept. * Delete the inert phase-receipt carrier from required_regen (review 53501). review 53501 flagged RequiredRegenPhaseReceipt.elapsed_ms as a flat-scalar duration at a substrate seam. The deeper defect is that the carrier never carried anything: the host's time_phase() ignored both its accumulator and its name and returned f() unchanged, so `phases` was allocated empty, passed through the admission fold unread, and stored in every attempt as []. Nothing in the verdict reads it and no host path populates it. Re-typing the field on std.types Milliseconds would have grounded a unit that is never measured. Deleted instead: the type, the field, the parameter, the no-op time_phase, and the four [] literals in the witness. Elapsed is still reported by the host's own measured run_started.elapsed(). * Delete the dead regen CI-script subtree and dissolve the hollow projection-source coproduct. Two residues this cut left standing. ci_spec.dag still carried regen_floor_skip_witness_bin, its policy note, and the two script emitters that composed them (ci_regen_floor_skip_shortcut_script, gunbc_ci_regen_floor_only_script, gunbc_ci_regen_floor_run). They emitted a shell invocation of a binary this cut deleted, and no surviving workflow reaches them — .github/workflows carries only witnesses.yml and fleet-converge.yml, neither of which mentions regen. gunbc_ci_regen_floor_run had no caller outside its own module. Deleted, with the two imports that served only it. The regen-job GATE surface (project_ci_regen_job_gates, gunbc_ci_regen_floor_gates) is deliberately untouched: it is load-bearing to the enrollment-asymmetry wall in gunbc.commit_workflow and has live witness consumers. generated_projection_paths.dag carried GeneratedProjectionPathSource as a two-arm coproduct whose second arm, Stage0EmitPlanRetired, was uninhabited by construction after the stage0_emit_plan deletion (review 53512, advisory). With one source the axis carries nothing: the collision refusal named first_source and duplicate_source, both of which could only ever be CommittedGeneratedArtifact — a distinction the type promised and the population could not supply. The coproduct and the row's source field are deleted; the collision refusal keeps the path, which is the fact it actually establishes, and still refuses two committed artifacts claiming one path. Verified by execution on the merged tree: test.claim.gitattributes_emit_witness witness_holds returns true, and dag/gunbc/ci_spec.dag resolves. * Delete required_regen_fixed_point_admission and FixedPointRefused: zero consumers, vacuous verdict. Neither name had a consumer anywhere in the tree — not production, not a witness. The host answers the fixed-point question itself: claim_executor's --required-regen-fixed-point calls cli_run::run_required_regen_fixed_point, which compares pass-1 and pass-2 digests in Rust and never evaluates this module. The success arm was also vacuous. It constructed RequiredRegenAttempt with generated_outcomes: [] and hand_outcomes: [] — the exact shape its sibling required_regen_sync_admission refuses as EmptyCommittedPopulation and EmptyEmitResult. A consumer receiving that verdict and asking how many surfaces matched would read zero, indistinguishable from a genuinely empty run. review 53522 read the reuse of RequiredRegenSyncRunnable as a naming smell; the name was the smaller half. Verified by execution on the merged tree: all five claims in required_regen_admission_witness_test return true individually, not only through the witness_holds conjunction. The wider finding this came out of — that the whole required_regen fold has no production consumer — is NOT addressed here and is with the operator. * Delete the interpreter's cross-claim memo for a function this cut removes. v1_interpreter.rs carried a hardcoded cross-claim memo keyed on the exact name "ci_heal_binary_source_skew_guard_script" at two sites, a getter and a setter. That name resolved on main against the unprefixed declaration in src/v2/workflow/ci_heal_skew_guard_emit.dag, which this branch deletes; no unprefixed declaration survives anywhere in the tree, so both branches match nothing. They are dead because of this cut, which makes this the only PR that can honestly remove them. ZERO_ARG_PURE_CROSS_CLAIM_MEMO goes with them. Its only reader and only writer were those two branches, so leaving the thread_local would keep a map that is never written and only cleared — the same dead-machinery class one level down. CROSS_CLAIM_FN_KEEPALIVE stays: the prepare_grammar path still uses it. Stated rather than left to be found, because it changes how the remaining half of that block should be read: deep-moth-771 established today that the prepare_grammar memo beside it CANNOT FIRE — its key bails on Value::Closure and every grammar in the corpus carries one (sync_tokens is a Set with a closure member, including the empty grammar in std/grammar.dag). That is the grammar lane's to resolve, not this cut's. With this deletion the thread_local holds one memo that cannot hit and one keepalive serving it. cargo build --release --bin claim_executor --bin gunbc green. * Delete the regen cut's remaining leaves: orphan rustfmt emitter, heal stub, two live rosters. review 53574 finding 1, plus two rosters no review found. ORPHAN MODULE. src/v2/workflow/ci_regen_rustfmt_path_emit.dag emitted the rustfmt-PATH shell for the regen job; its own note names regen_stage0's standalone rustfmt spawn as the whole subject. With regen deleted the module has no subject, and its only consumers were its own golden test and one witness file — kept alive by its own test, which is the attractor DESIGN section 3 says to uproot rather than leave as quarry. Module and test deleted. EVIDENCE RE-ENROLLED, NOT RETIRED. The review named one consumer in tool_readiness_witness_test.dag; there are FOUR, including the duplicate-rows refusal control. Their subject is tool_readiness's UnpinnedFrontier arm, which survives the cut, so the frontier row is re-declared locally as witness_unpinned_frontier_row and all four re-pointed. Section 3 step 6: keep the evidence for surviving claims, delete only the machinery. HEAL STUB. gunbc_ci_heal_binary_source_skew_guard_script was a hardcoded echo-and-exit-1 with no caller and no emitting workflow — a dead wrapper better deleted than stubbed. Deleting it made three notes false in the present tense ('The guard below refuses...' referring to nothing), so each now opens with a RETIRED marker and reads as history. They are not deleted: they carry the 2026-07-29 operator ruling and the #7348 incident receipt, and a prose row deleted for one reason takes everything in it. TWO LIVE ROSTERS, found by sweeping for the deleted name rather than by review. devboot/program.dag offered_programs() still offered regen_stage0 as a buildable target — its note reasons carefully about the missing-from-here direction and does not cover this one, a name offered here that exists nowhere. fallback_arm_census.dag inventoried the deleted src/v1/stage0/src/bin/regen_stage0.rs; removing that row moved the pinned count 25 -> 24 across three sites, because the count is encoded in a DECLARATION NAME (fallback_arm_seed_inventory_count_is_25_holds) as well as in the literal and the witness import. A count baked into a symbol is the hand-count-beside-structure class, and it is why deleting one row touched two files. * Stop DESIGN.md reciting regen_stage0 as a survivor of the floor cut (review 53574). The CI rung-drop bullet read: 'the regen_stage0 self-host fixed point and its regen_input_sources closure likewise survive, with only the required job that ran them removed.' That was true when written. This PR deletes regen_stage0.rs outright along with RegenVerifyGate and SelfHostStalenessGate, so the sentence would ship FALSE in the canonical authority — README and CLAUDE symlink to DESIGN.md, and every session plans from it. It is the exact failure the same paragraph names: a knowingly-false recital in the canonical authority is premise contamination, because each reader grounds a decision on something that no longer exists. Landing that class INTO the paragraph that defines it is the part worth refusing. The clause is REWRITTEN, not annotated — a second sentence beside the old one would be two accounts of one fact, the section 3 duplication, in a bullet already carrying a declared rung drop. It now separates the halves that this cut separates: the regen_input_sources import closure survives and is read by v1_compiler.required_regen_host, while the binary that consumed it and the two gates that invoked it are deleted at the root, leaving claim_executor --required-regen-fixed-point as the only answer to the fixed-point question. It also records that the old clause was true when written and which half this cut falsified, so the change is legible rather than silent. DESIGN.md is REGENERATED through generated_artifact_gate main_wet, not hand-edited — it is a projection of gunbc.design_document and a hand edit is reverted by drift heal. One line changed, matching the one carrier edit. * WIP: 8406 ownership --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Scoped gunbc
runTTY/pipe observation consumer, synchronized onto current main after #7350 merged the requiredSeedGrowthJustificationauthority.The dedicated
gunbc.observation_seed_rendergraph projects density-aware TTY emission and terminal-wire state. The scoped host seam transports canonicalNanosecond/Millisecondrecords and retains the authoredDynamicLineState; it only decodes typed projections and receipts. CleanFinalremainsMeasuredUnavailablewhen attention basis is unavailable, while clean-run end timing is a separate typed receipt. Runtime identity comes from the interpreter's actual selectedfn_nodesnode with normalized, fail-closed module-path matching.Exact five-file scope:
dag/gunbc/observation_seed_render.dagdag/test/claim/observation_seed_scoped_run_witness_test.dagsrc/v1/stage0/src/cli_run.rssrc/v1/stage0/src/v1_interpreter.rssrc/v1/stage0/tests/scoped_run_observation.rsNo parallel identity registry, emitter/main changes, floor, placement, workflow, or additional production consumer.
Exact-head receipts for
c0a3f40ed738ca0e736b61b1a5cb81fb16c2af01:5ee2c5fd-1e86-46c5-baef-fe4b1ec9dfb7.77253944-833d-4c19-85b8-7161039c139f; subsequent changes are main synchronization merges, and the five-file PR diff is unchanged.1ns/999999ns/1000000nspreservation, unmeasured clean Final plus typed end receipt, canonicalDynamicLineState, TERM=dumb downgrade, pipe append, and failure/refusal precedence.git diff --check: clean.Prior review findings:
DynamicLineState.util-linux scriptis unavailable or unsuccessful.SeedGrowthJustificationwith its concrete interpreter-seam dissolution trigger.Manager audit: clear against DESIGN §§2–6 and the ROADMAP observation dependency chain. The seed bridge remains bounded by #7350 and the exact five-file consumer boundary.