Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 3 additions & 23 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -166,12 +166,12 @@ jobs:
exit 0
fi
fi
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_regen_floor_batches --notice-title "self-host fixed-point (regen + staleness) — required; own regen job upstream of ci"
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_regen_floor_plan --notice-title "self-host fixed-point (regen + staleness) — required; own regen job upstream of ci"
timeout-minutes: 15
ci:
runs-on: [self-hosted, linux, arm64]
needs: [build, regen]
timeout-minutes: 100
timeout-minutes: 90
steps:
- name: Checkout
uses: actions/checkout@v5
Expand Down Expand Up @@ -210,7 +210,7 @@ jobs:
# REMOVED 2026-07-21 (gunbc#7023 / proud-cat-517): the documentation_only_skip shell shortcut exited before claim_executor, bypassing the witness corpus entirely on docs-only PRs. That bypassed the existing ReadsLiveTree never-predict-skip lane — doc_reachability_witness_test.dag already declared ReadsLiveTree since #6654, but the shell never reached selection. Docs-only PRs now run the normal floor (SelectionApplied): import-closure skips non-live-tree witnesses cheaply; ReadsLiveTree rows (doc-graph wall, corpus-read host-fed lenses) always run. The isolated pre-executor skip-label binary and its unreachable persistent disposition transport retired afterward; compile-clean docs-universe scoping remains independently exercised on the live floor path.
git fetch --no-tags origin main 2>/dev/null || true
set +e
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_floor_batches --notice-title "v2 claim corpus"
"$ROOT/target/release/claim_executor" --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_floor_plan --notice-title "v2 claim corpus"
FLOOR_EXIT=$?
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
CI_FLOOR_EXIT=$FLOOR_EXIT "$ROOT/target/release/gunbc" run --source-root dag --entry dag/tools/merge_admission_stamp.dag --function main
Expand All @@ -225,26 +225,6 @@ jobs:
if [ -f "$d/memory.peak" ]; then echo "[calibration] floor_peak_post=$(cat "$d/memory.peak") floor_outcome=${{ steps.floor.outcome }} cgroup=$d (observation label: floor_outcome=success is an EXACT point; any other outcome is a CENSORED lower bound - the process was killed while exceeding the read, so true demand is strictly greater. scope per the floor_peak_pre line: reset=ok means this IS the floor peak; scope=span compares against pre_peak)"; else echo "[calibration] floor_peak_post floor_outcome=${{ steps.floor.outcome }} scope=unavailable (no memory.peak ancestor)"; fi
if: always()
timeout-minutes: 5
- name: Floor resolve receipt gate (declared cold-resolve count)
run: |
if ! test -f target/floor-resolve-receipt.txt; then echo "floor resolve receipt missing - fail closed"; exit 1; fi
n=$(sed -n 's/^resolves_total=//p' target/floor-resolve-receipt.txt)
if test -z "$n"; then echo "floor resolve receipt malformed - fail closed"; exit 1; fi
if test "$n" -ne 1; then echo "floor resolve count $n differs from declared 1: duplicate-computation debt changed - update ci_floor_declared_resolve_count consciously (dag/gunbc/ci_materialization.dag)"; exit 1; fi
echo "floor resolve count $n matches declared 1 (declared cold-resolve receipt)"
timeout-minutes: 5
- name: Floor materialization receipt gate (demand ledger; disclosure gate — count pins retracted, walls tracked in ci_materialization.dag)
run: |
if ! test -f target/floor-materialization-receipt.txt; then echo "floor materialization receipt missing - fail closed"; exit 1; fi
k=$(sed -n 's/^keyed_calls=//p' target/floor-materialization-receipt.txt)
u=$(sed -n 's/^unkeyed_calls=//p' target/floor-materialization-receipt.txt)
d=$(sed -n 's/^duplicated_keys=//p' target/floor-materialization-receipt.txt)
if test -z "$k"; then echo "floor materialization receipt malformed - fail closed"; exit 1; fi
if test -z "$u"; then echo "floor materialization receipt malformed - fail closed"; exit 1; fi
if test -z "$d"; then echo "floor materialization receipt malformed - fail closed"; exit 1; fi
if test "$k" -eq 0; then echo "floor evaluated zero keyed calls - ledger disabled or floor empty - fail closed"; exit 1; fi
echo "floor materialization receipt: keyed=$k unkeyed=$u duplicated=$d (disclosure gate; count pins retracted 2026-07-10 — schedule-jittered per-ctx grain + diff-dependent affected-set denominator; walls forward: unkeyed==0 on closure identity, duplicated on structural frame grain)"
timeout-minutes: 5
- name: Merge-admission gate (receipt required; freshness block held until GatingEnforced)
run: |
'git' 'fetch' '--no-tags' 'origin' 'main' && 'env' '-C' '.' 'target/release/gunbc' 'run' '--source-root' 'dag' '--entry' 'dag/tools/merge_admission_gate.dag' '--function' 'main'
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/falsifier.yml
Original file line number Diff line number Diff line change
Expand Up @@ -108,7 +108,7 @@ jobs:
id: floor
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_falsifier_batches
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_falsifier_plan
env:
GUNBC_CI_DIFF_BASE: HEAD~20
GUNBC_CI_DIFF_HEAD: HEAD
Expand All @@ -126,7 +126,7 @@ jobs:
- name: compile-clean whole-tree cold control (scoped-PR admission counterpart)
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_plan_artifact_batches
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_plan_artifact_plan
env:
GUNBC_CI_COMPILE_CLEAN_COLD_CONTROL: 1
timeout-minutes: 30
Expand Down
72 changes: 0 additions & 72 deletions dag/gunbc/ci_materialization.dag
Original file line number Diff line number Diff line change
Expand Up @@ -171,15 +171,6 @@ data ci_floor_resolve_receipt_path: String = "target/floor-resolve-receipt.txt"

data ci_floor_declared_resolve_count: Int = 1

data ci_floor_resolve_receipt_gate_shell_emit_dissolution_trigger: Disposition = Scaffold {
dissolves_to: RealizationDispatch,
bind: DeclarationRef {
module_path: "gunbc.ci_materialization",
decl_name: "ci_floor_resolve_receipt_gate_script",
field: WholeDeclaration
}
}

data ci_sccache_provider_shell_injection_dissolution_trigger: Disposition = Scaffold {
dissolves_to: RealizationDispatch,
bind: DeclarationRef {
Expand All @@ -193,67 +184,4 @@ data ci_floor_materialization_receipt_note: String = "Increment 1 of INFERRED ma

data ci_floor_materialization_receipt_path: String = "target/floor-materialization-receipt.txt"

data ci_floor_materialization_receipt_gate_shell_emit_dissolution_trigger: Disposition = Scaffold {
dissolves_to: RealizationDispatch,
bind: DeclarationRef {
module_path: "gunbc.ci_materialization",
decl_name: "ci_floor_materialization_receipt_gate_script",
field: WholeDeclaration
}
}

fn ci_floor_materialization_receipt_gate_script() -> String {
let missing = concat(
concat("if ! test -f ", ci_floor_materialization_receipt_path),
"; then echo \"floor materialization receipt missing - fail closed\"; exit 1; fi\n"
)
let read_keyed = concat(
concat("k=$(sed -n 's/^keyed_calls=//p' ", ci_floor_materialization_receipt_path),
")\n"
)
let read_unkeyed = concat(
concat("u=$(sed -n 's/^unkeyed_calls=//p' ", ci_floor_materialization_receipt_path),
")\n"
)
let read_duplicated = concat(
concat("d=$(sed -n 's/^duplicated_keys=//p' ", ci_floor_materialization_receipt_path),
")\n"
)
let malformed = "if test -z \"$k\"; then echo \"floor materialization receipt malformed - fail closed\"; exit 1; fi\nif test -z \"$u\"; then echo \"floor materialization receipt malformed - fail closed\"; exit 1; fi\nif test -z \"$d\"; then echo \"floor materialization receipt malformed - fail closed\"; exit 1; fi\n"
let keyed_nonzero = "if test \"$k\" -eq 0; then echo \"floor evaluated zero keyed calls - ledger disabled or floor empty - fail closed\"; exit 1; fi\n"
let ok_line = "echo \"floor materialization receipt: keyed=$k unkeyed=$u duplicated=$d (disclosure gate; count pins retracted 2026-07-10 — schedule-jittered per-ctx grain + diff-dependent affected-set denominator; walls forward: unkeyed==0 on closure identity, duplicated on structural frame grain)\""
concat(
concat(concat(missing, read_keyed), concat(read_unkeyed, read_duplicated)),
concat(concat(malformed, keyed_nonzero), ok_line)
)
}

fn ci_floor_resolve_receipt_gate_script() -> String {
concat(
concat(
concat(
concat("if ! test -f ", ci_floor_resolve_receipt_path),
concat("; then echo \"floor resolve receipt missing - fail closed\"; exit 1; fi\n", "n=$(sed -n 's/^resolves_total=//p' ")
),
concat(
concat(ci_floor_resolve_receipt_path, ")\n"),
"if test -z \"$n\"; then echo \"floor resolve receipt malformed - fail closed\"; exit 1; fi\n"
)
),
concat(
concat(
concat("if test \"$n\" -ne ", to_string(ci_floor_declared_resolve_count)),
concat("; then echo \"floor resolve count $n differs from declared ", to_string(ci_floor_declared_resolve_count))
),
concat(
": duplicate-computation debt changed - update ci_floor_declared_resolve_count consciously (dag/gunbc/ci_materialization.dag)\"; exit 1; fi\n",
concat(
concat("echo \"floor resolve count $n matches declared ", to_string(ci_floor_declared_resolve_count)),
" (declared cold-resolve receipt)\""
)
)
)
)
}

data ci_sccache_provider_skip_is_counted_note: String = "The skip arm is LOUD and COUNTED, not silent (§5: a degradation must be a typed, located, countable diagnostic so its frequency is observable and prioritizable). This guard was a bare `if` with no else until 2026-07-24 — when the daemon was down the release build simply ran uncached, and the deficit's frequency was zero by construction, so it never ranked for fixing (shell→dag census §4.I lists it as an absorbing fallback). It is NOT yet a refusal: STEP 2 of the srvN build-cache design flips this to fail-closed, and that flip is operator-sequenced AFTER a live T4 read-back proves P1b provisioning converges on srv1/srv2/srv4 — refusing before then would red the whole fleet, which is why the interim is loudness rather than a wall. The receipt line names the host, so a single misconfigured runner is attributable rather than fleet-wide noise."
8 changes: 4 additions & 4 deletions dag/gunbc/ci_spec.dag

Large diffs are not rendered by default.

38 changes: 4 additions & 34 deletions dag/gunbc/ci_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -20,10 +20,6 @@ import v2.workflow.ci_merge_admission_gate_emit {
import gunbc.ci_workflow_expressions { ci_deploy_push_to_main_if, ci_regen_heal_if }
import gunbc.commit_workflow { commit_gate_roster, project_ci_floor_gates, project_ci_floor_witness_entries }
import gunbc.ci_runner_target { gunbc_ci_selected_runner_spec, ci_runner_target_ram_speed_budget, selected_ci_runner_target }
import gunbc.ci_materialization {
ci_floor_resolve_receipt_gate_script,
ci_floor_materialization_receipt_gate_script
}
import gunbc.ci_compile_jobs { ci_compile_jobs, compile_jobs_count_or_serial }
import gunbc.ci_floor_measurement { gunbc_ci_runner_slot_ram_speed_ceiling }
import v2.workflow.ci_floor_peak_emit {
Expand Down Expand Up @@ -366,34 +362,6 @@ fn ci_floor_peak_post_step() -> Step {
}
}

fn ci_floor_resolve_receipt_gate_step() -> Step {
RunStep {
name: Present { value: "Floor resolve receipt gate (declared cold-resolve count)" },
id: none,
run: ci_floor_resolve_receipt_gate_script(),
shell: none,
env: none,
working_directory: none,
if_condition: none,
continue_on_error: none,
timeout_minutes: Present { value: gunbc_ci_aux_step_timeout_minutes }
}
}

fn ci_floor_materialization_receipt_gate_step() -> Step {
RunStep {
name: Present { value: "Floor materialization receipt gate (demand ledger; disclosure gate — count pins retracted, walls tracked in ci_materialization.dag)" },
id: none,
run: ci_floor_materialization_receipt_gate_script(),
shell: none,
env: none,
working_directory: none,
if_condition: none,
continue_on_error: none,
timeout_minutes: Present { value: gunbc_ci_aux_step_timeout_minutes }
}
}

data merge_admission_gate_step_name: String = "Merge-admission gate (receipt required; freshness block held until GatingEnforced)"

data merge_admission_ci_gate_step_disposition: Disposition = Terminal {
Expand Down Expand Up @@ -479,8 +447,10 @@ fn gunbc_ci_build_job_backstop_timeout_minutes() -> Int {
gunbc_ci_aux_step_timeout_minutes + gunbc_ci_release_build_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_artifact_transfer_step_timeout_minutes + gunbc_ci_prelude_allowance_minutes
}

data gunbc_ci_receipt_gate_steps_moved_in_executor_note: String = "The resolve-receipt and materialization-receipt gate STEPS are deleted (ruling 2026-07-30): their laws — resolves_total equals the declared count, and the materialization receipt exists/parses/keyed nonzero — now run INSIDE claim_executor as ordinary-floor finalization (run_walk, FloorFinalization), so a receipt-law violation blocks every on-success stage instead of redding a step AFTER admission had already stamped. The two aux terms leave the backstop sum in the same motion, keeping it the exact step-sum + prelude the witness pins. The receipt FILES keep writing — they are observability the falsifier and operators read — only the shell re-validation of them is gone, because keeping it would be a second representation of the floor-completion rule."

fn gunbc_ci_job_backstop_timeout_minutes() -> Int {
gunbc_ci_artifact_transfer_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_floor_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_prelude_allowance_minutes
gunbc_ci_artifact_transfer_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_floor_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_aux_step_timeout_minutes + gunbc_ci_prelude_allowance_minutes
}

fn gunbc_ci_regen_job_backstop_timeout_minutes() -> Int {
Expand Down Expand Up @@ -615,7 +585,7 @@ fn ci_job() -> Job {
id: "ci",
name: none,
runner: gunbc_ci_selected_runner_spec(),
steps: concat(ci_floor_job_prelude_steps(), [ci_release_bins_download_step(), ci_release_bins_unpack_verify_step(), ci_floor_peak_pre_step(), ci_floor_step(), ci_floor_peak_post_step(), ci_floor_resolve_receipt_gate_step(), ci_floor_materialization_receipt_gate_step(), ci_merge_admission_gate_step()]),
steps: concat(ci_floor_job_prelude_steps(), [ci_release_bins_download_step(), ci_release_bins_unpack_verify_step(), ci_floor_peak_pre_step(), ci_floor_step(), ci_floor_peak_post_step(), ci_merge_admission_gate_step()]),
needs: ["build", "regen"],
env: none,
outputs: none,
Expand Down
Loading
Loading