Skip to content

Fix toolchain-unresolved fabrication: reorder the cache-segment computation after setup-rust-toolchain, then refuse instead of emitting a fabricated segment - #7436

Merged
briansrls merged 12 commits into
mainfrom
session/snappy-wolf-25
Jul 30, 2026

Conversation

@briansrls

@briansrls briansrls commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Move native-cache toolchain segment derivation (GUNBC_TOOLCHAIN_SEG / GUNBC_NATIVE_CACHE_ROOT) out of the isolate-toolchain prelude step and into a dedicated step after setup-rust-toolchain, so rustc -V names the installed toolchain rather than ambient runner state.
  • Replace the toolchain-unresolved absorbing fallback with a typed refusal (::error:: + exit 1) when rustc -V fails (DESIGN §5).
  • Add dag/test/claim/ci_native_cache_root_witness_test.dag with discriminating RED controls: fabrication literal reintroduction reds; isolate emission must exclude segment derivation; prelude model pins segment step after Setup Rust.
  • Regenerate .github/workflows/ci.yml and .github/workflows/falsifier.yml from the .dag authority.

Cache note: reordering the segment invalidates existing RUNNER_TOOL_CACHE/gunbc-native/* warm paths keyed under the old (fabricated or ambient-wrong) segment. That one-time cold miss is expected and preferable to a poisoned shared root.

Test plan

  • ci_native_cache_root_witness_test.dag — reorder + refuse + RED controls (floor discovery)
  • CI generated-artifact drift gate (ci.yml / falsifier.yml byte-match expected_ci_yml() / expected_falsifier_yml())
  • Build job prelude: isolate step has no rustc -V; "Derive native-cache root" step between Setup Rust and Pin rustup default

Brian Searls and others added 2 commits July 29, 2026 21:41
The generated workflows now derive GUNBC_TOOLCHAIN_SEG after setup-rust-toolchain and refuse when rustc -V fails, matching the ci_workflow_run_emit authority.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review July 29, 2026 21:44
Brian Searls and others added 2 commits July 29, 2026 22:09
Witnesses refuse if toolchain-unresolved can reappear, assert isolate emission
excludes segment derivation, and pin prelude ordering after setup-rust-toolchain.

Co-authored-by: Cursor <cursoragent@cursor.com>
Check `if ! GUNBC_TOOLCHAIN_SEG=$(rustc -V ...)` before using the segment,
not just empty output from a failing rustc. Add dissolve-on scaffold marker
on ci_native_cache_root_script emission per hand-shell gate (review 44669).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Addressed review 44669 in bbcdc40:

rustc exit status (finding 1): Segment derivation now uses if ! GUNBC_TOOLCHAIN_SEG=$(rustc -V ...); then ::error:: + exit 1; fi before mkdir/echo, with a separate empty-output refusal. Witness predicate updated to require the if ! arm.

Hand-shell scaffold (finding 2): ci_native_cache_root_script now prepends the 🟡 dissolve-on: marker and carries ci_native_cache_root_shell_emit_scaffold (same pattern as ci_release_build_emit / ci_regen_rustfmt_path_emit). Witnesses pin both the emitted marker and the scaffold disposition row.

Isolate/pin prelude steps remain in the pre-existing unmarked ci_workflow_run_emit bucket (shell→intent census §4.E); this PR only marks the new native-cache step surface.

— sent from snappy-wolf-25

Brian Searls and others added 3 commits July 29, 2026 22:31
The prior `if ! SEG=$(rustc -V | tr ...)` arm was inert without pipefail
because the pipeline status is tr's. Under GHA bash -e, a bare capture
followed by $? never reaches the check. Use `if ! RAW=$(rustc -V)` for
the real status authority, transform in a separate step, keep emptiness
as the post-transform edge-case refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>
The dag parser rejects DotDot in record patterns; expand UsesStep/RunStep
matches to explicit wildcard fields so regen and heal_generated_artifacts
can index the witness module.

Co-authored-by: Cursor <cursoragent@cursor.com>
@cursor

cursor Bot commented Jul 29, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

Brian Searls and others added 3 commits July 29, 2026 23:44
The ed6a5e3 run hit the 45-minute step limit during a cache-miss
cargo compile; dag witnesses and generated-artifact drift gate are green
locally.

Co-authored-by: Cursor <cursoragent@cursor.com>
Remove ci_step_is_* / CiPreludeOrderAcc fold from gunbc.ci_workflow
(codex review 44779 finding 2). Prelude ordering is now pinned by a
bridge substring derived from ci_setup_rust_home() and the shared step
name constant, checked against expected_ci_yml/falsifier_yml.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Response to codex review 44779 (REQUEST_CHANGES):

Finding 1 — shell-as-string in ci_workflow_run_emit: Not fixing in this PR. The native-cache step follows the same foreign-executor emit path as the pre-existing isolate/pin/selection-control rows in ci_workflow_run_emit.dag (all String → Run.command via orch_emit_pipeline). This PR's scoped change is reorder + fail-closed refusal of the toolchain-unresolved absorbing fallback, not shell→intent Phase 2 migration. The new surface is explicitly marked 🟡 Scaffold with dissolution trigger #5828 / shell→intent Phase 2 (same contract as ci_regen_ensure_rustfmt_path_script). Typed toolchain probe on host_effect_apply is the named dissolve-on, not an in-PR rewrite of the whole emit bucket.

Finding 2 — ci_step_is_* Step predicates: Fixed in latest push. Removed ci_step_is_setup_rust / ci_step_is_native_cache_derive and the CiPreludeOrderAcc fold from gunbc.ci_workflow. Prelude ordering is now witnessed via ci_native_cache_prelude_order_bridge() — a yaml bridge substring derived from ci_setup_rust_home() + the shared step-name constant, checked against expected_ci_yml() / expected_falsifier_yml() — so ordering is pinned on the emitted projection without storage-shape Step matches in the authority module.

— sent from snappy-wolf-25

Brian Searls and others added 2 commits July 30, 2026 00:42
…brittleness.

Record on ci_native_cache_prelude_order_bridge_note that the yaml substring
witness over-constrains ordering (false-RED only) because non-fold-residue
forbids the Step-coproduct match a structural predicate would need.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls merged commit 003d960 into main Jul 30, 2026
5 checks passed
@briansrls
briansrls deleted the session/snappy-wolf-25 branch July 30, 2026 01:50
gunbai-bot Bot pushed a commit that referenced this pull request Sep 5, 2026
§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.
briansrls added a commit that referenced this pull request Sep 5, 2026
….E, §4.I, §4.J (#10576)

* Correct §4.A hygiene-reaper row: CASE 2 — four host_hygiene_reap_*_body symbols deleted by #8583

The §4.A row at L379 described host_hygiene_reaper_script.dag's 4
body symbols as A5-deferred. The file was deleted by ffa16a5
(#8583, Migrate host-hygiene reaper and liveness onto typed observation)
and the construction was migrated to typed host_hygiene_reaper_observe.dag
/ host_hygiene_reaper_remediate.dag / host_hygiene_liveness_observe.dag.
No direct successor body names exist — CASE 2 (file deletion upstream)
with hybrid CASE 1 (body names dissolved).

Verification:
- ffa16a5 is ancestor of origin/main ✅
- host_hygiene_reaper_script.dag: D in #8583's diff
- zero files define host_hygiene_reap_install_units_body et al.
- observe/remediate files present at dag/gunbc/host/

Part of #10537's per-row adjudication program.

* Correct §4.D srv3_chown_directory_to_current_user: CASE 4 — renamed AND climbed

The row at §4.D L436 listed srv3_chown_directory_to_current_user
as A5-deferred (srv3). It was actually renamed AND climbed by
20ad5b3 (#8796): successor is
gunbc.host_effect_realize.srv3_ensure_directory_owned_by_current_user.
New name has a stronger guarantee (readback-based, not chown exit-status
based).

This is CASE 4 (rename plus climb) — distinct from CASE 1 (dissolution)
because the construction did not disappear; it acquired a better name
and a stronger guarantee.

Verification:
- 20ad5b3 is ancestor of origin/main ✅
- srv3_chown_directory_to_current_user: 0 declaration files
- srv3_ensure_directory_owned_by_current_user: 2 declaration files

Part of #10537's per-row adjudication program.

* Correct §4.E: 4 stale foreign-executor rows

Four symbols claimed as 'already on emit' are no longer present in the
corpus. Each is struck through with its deletion commit:

1. ci_selection_control_script — DELETED by 611fd02 (#8283, CI floor cut).
   CASE 1/2: the ci.yml file was deleted and its selection-control script
   dissolved with it. Successor workflow is witnesses.yml via
   gunbc.witness_floor_workflow.

2. gunbc_ci_run_script — DELETED by 489346f (#9252, plan/walk CLI delete).
   CASE 1: the gunbc ci verb was deleted, taking its run script.

3. ci_regen_ensure_rustfmt_path_script — DELETED by 3b431f3 (#8406,
   REGEN ROOT CUT). CASE 1: regen_stage0 root deleted; rustfmt path
   script was zero-consumer machinery.

4. expected_live_deploy_retract_script — DELETED by d409b75 (#7909,
   Phase A release identity refactor). CASE 1: recategorized to
   runtime-present, then dissolved.

All four deletion commits are ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

* Correct §4.I, §4.J, §4.D ownership table: 18+ stale symbols

§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant