Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
7244249
heal: apply the binary/source skew remedy automatically instead of pr…
Jul 29, 2026
7e80540
Merge remote-tracking branch 'origin/heal-auto-remedy' into session/q…
Jul 29, 2026
c3dba1a
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
6b8c9b4
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
a189f0c
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
c6ea277
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
d3bd790
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
b0c5ca4
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
18ef7db
Merge remote-tracking branch 'origin/main' into session/quiet-wren-607
Jul 29, 2026
5ec7208
Render the heal skew guard from a typed Pipeline; delete its shell sc…
Jul 29, 2026
d108530
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
03aab19
Merge remote-tracking branch 'origin/main' into session/quiet-wren-607
Jul 29, 2026
4c49f99
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
021987c
Merge main; keep the modeled guard and drop the duplicated note row
Jul 29, 2026
f872171
Merge remote-tracking branch 'origin/main' into session/quiet-wren-607
Jul 29, 2026
339583b
Cite xargs in extdeps and shrink the guard's hand-spelled shell to on…
Jul 29, 2026
37a3352
WIP: heal deferral completion + BMC/srvN
Jul 29, 2026
1fb763d
Remove two empty junk files created by a shell quoting slip
Jul 29, 2026
73ebe0d
Merge remote-tracking branch 'origin/main' into session/quiet-wren-607
Jul 29, 2026
ab448b1
Make the heal remedy merge BUILT_FROM, not the moving base
Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
87 changes: 37 additions & 50 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -293,59 +293,46 @@ jobs:
- name: Refuse a binary/source revision skew (the release binary is built from the PR merge ref; this job checked out the branch head)
run: |
BUILT_FROM="${{ github.sha }}"
BASE_REF="${{ github.base_ref }}"
GENERATED_ARTIFACTS=".github/workflows/ci.yml .github/workflows/falsifier.yml .gitignore ROADMAP.md DESIGN.md .githooks/pre-push .githooks/pre-commit dag/gunbc/stage0_crate_layout_generated.dag src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs dag/gunbc/stage0_crate_partition_generated.dag .github/live-deploy-srv1-apply.sh .github/live-deploy-srv1-retract.sh docs/plans/idea-machine.md docs/plans/algebraic-rewrite-optimization.md docs/plans/dag-v2-defork-audit.md docs/plans/v2-self-hosting.md docs/plans/m5-fixture-store-consolidation.md docs/plans/model-realization-fork.md docs/plans/value-null-split.md docs/plans/ci-merge-freshness.md docs/plans/seed-debt-bundle-item-2.md docs/plans/axiom-syllogism-lens.md docs/plans/invert-hand-maintained.md docs/plans/fail-closed-lockdown.md docs/plans/format-model-reconciliation.md docs/plans/regime2-shared-emission-fold.md docs/plans/shell-emission-model.md docs/plans/construction-justification-rule.md docs/plans/emission-ingestion-inverse.md docs/plans/testgen-oracle.md docs/plans/disposition-carrier.md docs/plans/fold-ergonomics.md docs/plans/m4-universal-hermetic-corpus.md docs/plans/wiring-liveness-preflight.md docs/plans/interpreter-kernel-d.md docs/plans/inert-layer-lens.md docs/plans/compile-clean-forcecheck.md docs/plans/expressibility-frontier.md docs/plans/p1-where-clause-lowering.md docs/plans/intent-linearity-design-draft.md docs/plans/solve-higher-order-design.md docs/plans/language-target-self-host-frontier.md docs/plans/self-applying-lenses.md docs/plans/budget-tree.md docs/plans/cardinality-refinement.md docs/plans/compute-envelope-model.md docs/plans/input-envelope-roadmap.md docs/plans/ci-selection-vs-scheduling.md docs/plans/ci-process-end-to-end.md docs/plans/ci-oom-reclassification.md docs/plans/bounded-input-cost-envelope-scheduling.md docs/plans/ci-humming.md docs/plans/edge-b-rust-dag-provenance-brief.md docs/plans/resolver-type-name-collision-wall.md docs/plans/realization-measurement-loop.md docs/plans/host-effect-orchestration.md docs/plans/ci-floor-fractal-gantt.md docs/plans/resolver-pathology-profile-receipt.md docs/plans/representation-minimization.md docs/plans/reference-grounding-migration.md docs/plans/typescript-gap-census.md docs/plans/cli-run-hollowing-plan.md docs/plans/fleet-acceptance-criteria.md docs/plans/structural-quadratic-wall-coverage-audit.md docs/plans/ci-performance-tanking-evidence.md"
git fetch --quiet origin "$BUILT_FROM" 2>/dev/null || git fetch --quiet origin "${{ github.ref }}" 2>/dev/null || true
if git fetch --quiet origin "$BUILT_FROM" 2>/dev/null || git fetch --quiet origin "${{ github.ref }}" 2>/dev/null; then :; else :; fi
if ! git rev-parse --verify --quiet "$BUILT_FROM" >/dev/null; then
echo "heal refused: cannot resolve the revision the release binary was built from" >&2
echo " wanted: $BUILT_FROM (github.sha — the ref the build job compiled)" >&2
echo " without it this job cannot establish that its binary and its tree agree." >&2
exit 1
echo "heal refused: cannot resolve the revision the release binary was built from" >&2
echo " wanted: $BUILT_FROM (github.sha — the ref the build job compiled)" >&2
echo " without it this job cannot establish that its binary and its tree agree." >&2
exit 1
fi
seed_ahead() { git rev-list HEAD.."$BUILT_FROM" -- src/v1 | head -20; }
SEED_AHEAD=$(seed_ahead)
SEED_AHEAD="$(git rev-list HEAD.."$BUILT_FROM" -- src/v1)"
if [ -n "$SEED_AHEAD" ]; then
echo "heal: binary/source revision skew — the branch head lacks these seed (src/v1) commits:" >&2
echo "$SEED_AHEAD" | sed 's/^/ /' >&2
echo "heal: applying the remedy automatically (merging origin/$BASE_REF into this branch)" >&2
git config user.name "gunbc-ci-auto-heal"
git config user.email "gunbc-ci-auto-heal@users.noreply.github.com"
git fetch --quiet origin "$BASE_REF" || true
if git merge --no-edit "origin/$BASE_REF"; then
if [ -n "$(seed_ahead)" ]; then
echo "heal refused: still skewed after merging origin/$BASE_REF" >&2
echo " the base moved again during this run; the next run will re-attempt." >&2
exit 1
fi
echo "heal: remedy applied — tree now carries the binary's seed revision" >&2
else
CONFLICTS=$(git diff --name-only --diff-filter=U)
AUTHORED=""
for c in $CONFLICTS; do
case " $GENERATED_ARTIFACTS " in
*" $c "*) ;;
*) AUTHORED="$AUTHORED $c" ;;
esac
done
if [ -n "$AUTHORED" ]; then
echo "heal refused: binary/source revision skew, and the remedy CONFLICTS in authored files" >&2
echo " conflicting paths:" >&2
echo "$CONFLICTS" | sed 's/^/ /' >&2
echo " authored (not generated, so not auto-resolvable):" >&2
for a in $AUTHORED; do echo " $a" >&2; done
git merge --abort || true
echo " a semantic conflict is the author's to resolve; this job will not guess." >&2
exit 1
fi
echo "heal: conflicts are confined to registered generated artifacts; regeneration is authoritative" >&2
for c in $CONFLICTS; do echo " $c" >&2; git checkout --ours -- "$c" 2>/dev/null || true; git add "$c"; done
git commit --no-verify --no-edit >/dev/null
if [ -n "$(seed_ahead)" ]; then
echo "heal refused: still skewed after merging origin/$BASE_REF" >&2
exit 1
fi
echo "heal: remedy applied — tree now carries the binary's seed revision" >&2
fi
echo "heal: binary/source revision skew — the branch head lacks these seed (src/v1) commits:" >&2
echo "$SEED_AHEAD" | head -20 | sed 's/^/ /' >&2
echo "heal: applying the remedy automatically (merging $BUILT_FROM — the revision the binary was built from — into this branch)" >&2
git config user.name gunbc-ci-auto-heal
git config user.email gunbc-ci-auto-heal@users.noreply.github.com
if ! git merge --no-edit "$BUILT_FROM"; then
CONFLICTS="$(git diff --name-only --diff-filter=U)"
AUTHORED_CONFLICTS="$(git diff --name-only --diff-filter=U -- . ':(exclude).github/workflows/ci.yml' ':(exclude).github/workflows/falsifier.yml' ':(exclude).gitignore' ':(exclude)ROADMAP.md' ':(exclude)DESIGN.md' ':(exclude).githooks/pre-push' ':(exclude).githooks/pre-commit' ':(exclude)dag/gunbc/stage0_crate_layout_generated.dag' ':(exclude)src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs' ':(exclude)dag/gunbc/stage0_crate_partition_generated.dag' ':(exclude).github/live-deploy-srv1-apply.sh' ':(exclude).github/live-deploy-srv1-retract.sh' ':(exclude)docs/plans/idea-machine.md' ':(exclude)docs/plans/algebraic-rewrite-optimization.md' ':(exclude)docs/plans/dag-v2-defork-audit.md' ':(exclude)docs/plans/v2-self-hosting.md' ':(exclude)docs/plans/m5-fixture-store-consolidation.md' ':(exclude)docs/plans/model-realization-fork.md' ':(exclude)docs/plans/value-null-split.md' ':(exclude)docs/plans/ci-merge-freshness.md' ':(exclude)docs/plans/seed-debt-bundle-item-2.md' ':(exclude)docs/plans/axiom-syllogism-lens.md' ':(exclude)docs/plans/invert-hand-maintained.md' ':(exclude)docs/plans/fail-closed-lockdown.md' ':(exclude)docs/plans/format-model-reconciliation.md' ':(exclude)docs/plans/regime2-shared-emission-fold.md' ':(exclude)docs/plans/shell-emission-model.md' ':(exclude)docs/plans/construction-justification-rule.md' ':(exclude)docs/plans/emission-ingestion-inverse.md' ':(exclude)docs/plans/testgen-oracle.md' ':(exclude)docs/plans/disposition-carrier.md' ':(exclude)docs/plans/fold-ergonomics.md' ':(exclude)docs/plans/m4-universal-hermetic-corpus.md' ':(exclude)docs/plans/wiring-liveness-preflight.md' ':(exclude)docs/plans/interpreter-kernel-d.md' ':(exclude)docs/plans/inert-layer-lens.md' ':(exclude)docs/plans/compile-clean-forcecheck.md' ':(exclude)docs/plans/expressibility-frontier.md' ':(exclude)docs/plans/p1-where-clause-lowering.md' ':(exclude)docs/plans/intent-linearity-design-draft.md' ':(exclude)docs/plans/solve-higher-order-design.md' ':(exclude)docs/plans/language-target-self-host-frontier.md' ':(exclude)docs/plans/self-applying-lenses.md' ':(exclude)docs/plans/budget-tree.md' ':(exclude)docs/plans/cardinality-refinement.md' ':(exclude)docs/plans/compute-envelope-model.md' ':(exclude)docs/plans/input-envelope-roadmap.md' ':(exclude)docs/plans/ci-selection-vs-scheduling.md' ':(exclude)docs/plans/ci-process-end-to-end.md' ':(exclude)docs/plans/ci-oom-reclassification.md' ':(exclude)docs/plans/bounded-input-cost-envelope-scheduling.md' ':(exclude)docs/plans/ci-humming.md' ':(exclude)docs/plans/edge-b-rust-dag-provenance-brief.md' ':(exclude)docs/plans/resolver-type-name-collision-wall.md' ':(exclude)docs/plans/realization-measurement-loop.md' ':(exclude)docs/plans/host-effect-orchestration.md' ':(exclude)docs/plans/ci-floor-fractal-gantt.md' ':(exclude)docs/plans/resolver-pathology-profile-receipt.md' ':(exclude)docs/plans/representation-minimization.md' ':(exclude)docs/plans/reference-grounding-migration.md' ':(exclude)docs/plans/typescript-gap-census.md' ':(exclude)docs/plans/cli-run-hollowing-plan.md' ':(exclude)docs/plans/fleet-acceptance-criteria.md' ':(exclude)docs/plans/structural-quadratic-wall-coverage-audit.md' ':(exclude)docs/plans/ci-performance-tanking-evidence.md')"
if [ -n "$AUTHORED_CONFLICTS" ]; then
echo "heal refused: binary/source revision skew, and the remedy CONFLICTS in authored files" >&2
echo " conflicting paths:" >&2
echo "$CONFLICTS" | head -20 | sed 's/^/ /' >&2
echo " authored (not a registered generated artifact, so not auto-resolvable):" >&2
echo "$AUTHORED_CONFLICTS" | head -20 | sed 's/^/ /' >&2
echo " a semantic conflict is the author's to resolve; this job will not guess." >&2
git merge --abort
exit 1
fi
echo "heal: conflicts are confined to registered generated artifacts; regeneration is authoritative" >&2
echo "$CONFLICTS" | head -20 | sed 's/^/ /' >&2
git diff --name-only --diff-filter=U -z | xargs -0 git checkout --ours --
git diff --name-only --diff-filter=U -z | xargs -0 git add
git commit --no-verify --no-edit >/dev/null
fi
SEED_AHEAD_AFTER="$(git rev-list HEAD.."$BUILT_FROM" -- src/v1)"
if [ -n "$SEED_AHEAD_AFTER" ]; then
echo "heal refused: still skewed after merging $BUILT_FROM" >&2
echo " this arm should be unreachable — merging BUILT_FROM makes it an ancestor of HEAD, so the seed-ahead set is empty by construction. Reaching it means that invariant broke; do not re-run, investigate." >&2
exit 1
fi
echo "heal: remedy applied — tree now carries the binary's seed revision" >&2
fi
echo "heal preflight: binary revision $BUILT_FROM carries no seed commits missing from this tree"
timeout-minutes: 5
Expand Down
31 changes: 31 additions & 0 deletions dag/extdeps/exec/xargs.dag
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
module extdeps.exec.xargs

import std.types { String, List }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "pubs.opengroup.org/onlinepubs/9699919799/utilities/xargs.html"
}
}

data xargs_null_delimited_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "man7.org/linux/man-pages/man1/xargs.1.html"
}
}

data xargs_null_delimited_fidelity_note: String = "TWO AUTHORITIES BECAUSE `-0` IS NOT POSIX. The POSIX xargs utility (anchor above) reads a whitespace-delimited, quote-honouring argument stream and defines no null-delimited mode; `-0` / `--null` is a GNU findutils extension (second anchor, xargs(1)), also present in BSD xargs. Declaring only the POSIX anchor would cite an authority that does not contain the option this module spells, so both are named and the extension is attributed to the one that defines it (DESIGN §3 — keep the real upstream's names and say which spec a flag comes from).\n\nWHY NULL DELIMITING IS THE ONLY MODE MODELED HERE. Under the default delimiting rules a path containing a space, a tab, a newline, or a quote character is split or de-quoted into the wrong arguments — silently, producing operations against paths that were never in the input set. That is the fabricated-plausible-output arm §5 forbids, so the whitespace mode is deliberately absent rather than offered and warned about: the producer side must emit NUL-separated records (git's `-z`, find's `-print0`) and this shape consumes exactly that. A caller wanting the POSIX default mode is asking for the unsafe reading and should be refused, not accommodated."

data xargs_arg_limit_relation_note: String = "WHAT XARGS IS FOR, AND WHY IT LIVES BESIDE exec_arg_limit. xargs exists because execve(2) bounds how much argv a single spawn may carry: it batches a long input stream into as many invocations of the sink command as the limit requires. extdeps.exec.exec_arg_limit models the per-argument ceiling (MAX_ARG_STRLEN) of that same boundary, so the two are facts about one host interface and share this folder. This module does NOT re-derive a batch size: xargs computes its own from the live limit, and a second copy here would be a §3 fork of a number the tool already owns — the reason the shape below carries no `-s` / `-n` operand."

fn xargs_null_delimited_args() -> List<String> {
["xargs", "-0"]
}

fn shape_xargs_null_delimited_argv(sink_argv: List<String>) -> List<String> {
concat(xargs_null_delimited_args(), sink_argv)
}
84 changes: 84 additions & 0 deletions dag/extdeps/git/git.dag
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,34 @@ data git_diff_external_authority_anchor: ExternalAuthority = ExternalAuthority {
}
}

data git_rev_list_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "git-scm.com/docs/git-rev-list"
}
}

data git_merge_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "git-scm.com/docs/git-merge"
}
}

data git_checkout_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "git-scm.com/docs/git-checkout"
}
}

data git_pathspec_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "git-scm.com/docs/gitglossary"
}
}

type ObjectType = BlobObj | TreeObj | CommitObj | TagObj

type GitAuthor {
Expand Down Expand Up @@ -300,6 +328,62 @@ fn shape_git_branch_show_current_argv() -> List<String> {
["git", "branch", "--show-current"]
}

data git_pathspec_exclude_note: String = "PATHSPEC MAGIC IS GIT'S INTERFACE; WHICH PATHS TO EXCLUDE IS NOT (DESIGN §3 (a)/(c) split). gitglossary(7) 'pathspec' defines the long-form magic word `exclude` — a pathspec of the form `:(exclude)<pattern>` removes matching paths from the set an otherwise-matching pathspec selected, and git requires at least one positive pathspec beside it for there to be a set to subtract from (hence the leading `.` that shape_git_diff_unmerged_pathspec_args emits). This module owns only that SPELLING. The exclusion LIST is a caller's business policy — a workflow fact — and passing pathspec WORDS as a parameter is what keeps this row from becoming the layer inversion §3 names (an argv carrying a literal it should receive as an argument).\n\nA PATHSPEC WORD IS NOT A SHELL WORD, AND THIS MODULE DELIBERATELY DOES NOT QUOTE IT. `:(exclude)p` contains `(` and `)`, which are bash metacharacters, so any shell realization that joins this word into a command line unquoted emits a SYNTAX ERROR — proven by execution, not reasoned: the first cut of the heal skew guard did exactly that and `bash -n` rejected the emitted line. git_shell_join_argv is a join over already-spelled words, not a quoter, and must not become one (its existing callers pass words that are already quoted, so quoting there would double-quote them). Quoting therefore belongs to the emitting realization, which is the only layer that knows the target shell — see v2.workflow.ci_heal_skew_guard_emit ci_heal_skew_shell_single_quoted. Callers composing a pathspec into shell MUST quote the whole word."

fn git_pathspec_exclude(path: String) -> String {
concat(":(exclude)", path)
}

data git_argv_program_note: String = "Each shape below is declared as an ARGS list (the operands after the `git` program) with an `_argv` sibling that prepends the program. Both spellings have live consumers and neither is derived by hand: `_argv` feeds git_shell_join_argv for a whole-command leaf, `_args` feeds a command-substitution carrier that already holds `git` as its callee. One authority, two projections — not two lists to keep in step."

fn git_argv_of_args(args: List<String>) -> List<String> {
concat(["git"], args)
}

fn shape_git_diff_unmerged_args() -> List<String> {
["diff", "--name-only", "--diff-filter=U"]
}

fn shape_git_diff_unmerged_nul_argv() -> List<String> {
git_argv_of_args(args: concat(shape_git_diff_unmerged_args(), ["-z"]))
}

fn shape_git_diff_unmerged_pathspec_args(pathspec_words: List<String>) -> List<String> {
concat(concat(shape_git_diff_unmerged_args(), ["--", "."]), pathspec_words)
}

fn shape_git_rev_list_ahead_path_limited_args(target: String, path: String) -> List<String> {
["rev-list", concat("HEAD..", target), "--", path]
}

fn shape_git_merge_no_edit_argv(ref: String) -> List<String> {
["git", "merge", "--no-edit", ref]
}

fn shape_git_merge_abort_argv() -> List<String> {
["git", "merge", "--abort"]
}

fn shape_git_checkout_ours_argv() -> List<String> {
["git", "checkout", "--ours", "--"]
}

fn shape_git_add_argv() -> List<String> {
["git", "add"]
}

fn shape_git_commit_no_verify_no_edit_argv() -> List<String> {
["git", "commit", "--no-verify", "--no-edit"]
}

fn shape_git_config_argv(key: String, value: String) -> List<String> {
["git", "config", key, value]
}

fn shape_git_rev_parse_verify_quiet_argv(target: String) -> List<String> {
["git", "rev-parse", "--verify", "--quiet", target]
}

fn git_observe_meta_shell_fragment() -> String {
concat(
"git branch=$(", concat(git_shell_join_argv(argv: shape_git_branch_show_current_argv()), " 2>/dev/null || echo unknown)"),
Expand Down
Loading
Loading