Skip to content

Extract run_stage so both walk populations share one executor - #7499

Merged
briansrls merged 4 commits into
mainfrom
claude/pr-timing-analysis-3bm5e9
Jul 31, 2026
Merged

briansrls merged 4 commits into
mainfrom
claude/pr-timing-analysis-3bm5e9

Conversation

@briansrls

@briansrls briansrls commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Task #13, following #7470 and #7481. Extracts one stage executor for both walk populations, retains the full parsed resource profile that makes stage contracts enforceable, and closes receipt identity before the admission occupants become its first consumer.

This body was rewritten after review. An earlier version asserted several things that turned out to be false, and one of them caused a wrong code change. Those are corrected below rather than quietly dropped, because the false version is what made the wrong change look justified.


The prerequisite

Runnable::SingleClaim retained two of the four facts RunnableResourceProfile declares — heavy_whole_tree_resolve (as use_walk_memo) and execution_mode — and dropped spawns_host_compiler and the memory class at parse time.

That was invisible while only the ordinary batch path consumed profiles, because that path happens to need exactly the two that survived. It stops being invisible the moment one executor serves both populations: a shared run_stage cannot enforce a stage's declared resource contract against facts the parse threw away.

ParsedRunnableProfile retains all four. Two distinct absences now refuse rather than default:

  • a profile that exists but omits an axis → refusal (the node_frontier_selection precedent — a stale plan redeclares rather than inheriting silently)
  • no profile at all → ParsedProfileProvenance::Undeclared, and stages refuse it, because the values would be the parse's fail-closed fillers rather than the plan's statements, and reading a wall off invented facts is worse than having no wall

The extraction

Both populations run through run_stage: same unit grouping, same lane partition (batch_unit_lane), same derived cost clamp. The callers differ only in ordering and failure policy — FloorBatchStopPolicy for the ordinary floor, unconditional fail-fast between stages.

Admission is per-lane, not universal, and stating that precisely is the load-bearing correction. run_batch_unit takes an AdmittedSlot, and run_batch_unit is reached on the spawned lane only. Memo-lane and main-thread units run unadmitted. There is exactly one acquire_blocking site in the file.

The wall that was wrongly removed, and is restored

An earlier revision deleted the arm-time heavy-whole-tree-resolve refusal, arguing that stages now took the same lane partition as batches so a heavy claim was governed exactly as it would be in a batch.

The partition is shared; the admission is not. batch_unit_lane routes a heavy unit — and every unit sharing its entry — to UnitLane::Memo, which runs through run_memo_shared_claims, which takes no governor and acquires no slot. So a heavy stage claim would have resolved and evaluated on the main thread, unadmitted, while spawned units held slots: precisely the unbounded stacking the governor exists to prevent. The refusal is restored with that as its stated reason.

Wrapping the memo call in an ordinary slot is not the fix either — the slot would release while the resolved InterpContext stays resident in stage_memo for every later stage.

And the obvious repair — hold a slot for the memoized context's lifetime — deadlocks, which a later probe against decide_admission established. AdmittedSlot is a concurrency slot, not a memory reservation: a resident hold pins active >= 1, so the active == 0 progress floor never fires and every later admission returns Hold(WindowFull); width grows only in note_completion, which needs a completion, which needs an admission. The runner starts at target_width=1, so this is the default path, not a corner case. The real dissolve-on is splitting the governor's active counter into an execution slot and a resident memory reservation — its own work, on the path guarding against the exit-137 OOM kills, not a step inside this lane.

What the carrier now promises

The concurrency contract on walk_plan_note was weakened, because the executor can legitimately withdraw overlap without anything being wrong: same-entry same-mode claims are combined into one resolve group and run serially within it; memo-lane and discovery units run on the main thread; and at governor width 1 two spawned threads exist while one claim body is admitted at a time. Promising wall-time concurrency would make grouping, memo placement, and the governor into contract violations when they are the design.

What the admission occupants actually need is the absence of a guaranteed order, and that is what the type now states.

Receipt identity

On-success stage receipts were written to a bare shared path with no attempt identity. The occupants land next as their first consumer, so identity closes now — before there is a reader to fool. Per merge_admission_attempt_scope_note:

  • identity is stamped in the payload, not just the path, because a misrouted read must fail on the content too (path scoping is added as hygiene against workspace reuse on self-hosted runners, but the payload stamp is the wall)
  • an unidentified walk refuses rather than defaulting — a silent constant would make every local run one attempt and put the wrong-attempt refusal out of reach off CI
  • the refusal fires at arm time, so an unidentified walk fails in seconds rather than after a 20–30 minute floor
  • identity is demanded only when stages exist; a plan with no stages writes no attempt-scoped receipt, so requiring it there would be a refusal with no subject

GUNBC_WALK_ATTEMPT_ID is not an escape hatch: it supplies a required input the environment did not, and a value failing the segment law still refuses.

Controls, and the mutations that prove they discriminate

The concurrency contract was unreachable by a test while spawn-and-join sat inlined in the batch loop — which is how the first attempt at success stages promised concurrency while executing serially. spawn_units / join_units are split out so a latch can reach them.

control mutation result
stage_members_actually_overlap spawn_units runs each unit inline RED, serial signature [false, true]; join + panic controls stay green
attempt_identity_refuses_rather_than_defaulting_when_absent absent identity defaults to "local" RED, together with the partial-triple control; the three positive controls stay green

The bounded wait in the overlap control is a deadlock detector, never the assertion — the assertion is that each member saw the other, which slowness cannot fake and speed cannot satisfy serially.

The stage barrier is the join half plus a structural fact: run_walk's stage loop takes &mut stage_memo per iteration, so two iterations cannot overlap.

Verification

  • 48/48 executor suite
  • Both mutations above run and reverted; controls re-verified green after revert
  • Full CI green on the prior head (032bd81e6): build, heal, regen, ci floor
  • cargo fmt --all --check clean

Near-misses worth recording

The first fixture run reported exit 0 with no output through a grep, so a .dag parse error I had just introduced looked like a pass. An exit code is not a receipt when the filter can hide the diagnostic.

Separately, a walk_plan_note edit landed without regenerating the stage0 seed, redding regen. Both are why later commits here were held rather than pushed on green.

Not here

The admission occupants (capture_tested_subject, stamp_tested_floor, refresh_target_and_gate) go in their own PR. They do not exist yet — the pure classification half does, but the effectful half is new surface (git observation, receipt writes, gate refresh) and deserves its own before/after receipt.

They also need ci_floor_declared_resolve_count raised, which must land in the same commit that adds the escaping entry (declared > measured reds immediately). The operator has signed option A — pay the declared cold resolve rather than build the governor lease — and the exact delta will be measured before the number moves, since the carried "1→2" is analysis, not measurement.

Two further review items are dispatched separately: a production-path WalkPlan fixture, and a success-stage materialization receipt.

🤖 Generated with Claude Code

https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

Task #13. Closes the three gaps std.realization_schedule.walk_plan_note named, and
lands the prerequisite the review identified before them.

THE PREREQUISITE. Runnable::SingleClaim retained two of the four facts
RunnableResourceProfile declares -- heavy_whole_tree_resolve (as use_walk_memo) and
execution_mode -- and dropped spawns_host_compiler and the memory class at parse time.
That was invisible while only the ordinary batch path consumed profiles, because the
ordinary path happens to need exactly the two that survived. It stops being invisible
the moment ONE executor serves both populations: a shared run_stage cannot enforce a
stage's declared resource contract against facts the parse threw away. ParsedRunnableProfile
retains all four, and a profile that EXISTS but omits an axis is now a refusal rather
than a default -- the node_frontier_selection precedent, so a stale plan redeclares
instead of inheriting.

THE EXTRACTION. Both populations now run through run_stage: same unit grouping, same
lane partition, same governor admission (run_batch_unit takes an AdmittedSlot for the
unit's lifetime), same derived clamp. Stage members are therefore concurrent as the
carrier has always claimed rather than serial-and-hoped; each stage writes ITS OWN
receipt before the next begins, so a process death mid-sequence no longer erases the
record of stages that had completed; and the two callers differ only in ordering and
failure policy, which is the one real difference between them.

A WALL REPLACED, NOT REMOVED. The arm-time validator's heavy-whole-tree-resolve refusal
existed BECAUSE stages bypassed governor admission. They no longer do, so keeping it
would be a stale claim of exactly the kind this branch has twice been sent back for. What
refuses now is the class stages are genuinely not sized for -- spawns_host_compiler or
substantial residency -- because stages declare no clamp params
(gunbc_ci_floor_batch_clamp_params indexes the ORDINARY batches) and such a claim would
run admitted but unclamped. That refusal is derived from the whole profile, which is only
expressible because of the prerequisite above.

CONTROLS, PROVEN DISCRIMINATING. The concurrency contract was unreachable by a test while
spawn-and-join sat inlined in the batch loop -- which is exactly how the first attempt
promised concurrency while executing serially. spawn_units/join_units are split out so a
latch can reach them. stage_members_actually_overlap has each member increment a counter
and wait until it observes the other; a serial executor leaves the first waiting for a
peer that was never started. The bounded wait is a deadlock detector, never the
assertion. Mutation proof: making spawn_units run each unit inline reds exactly that
control with the serial signature [false, true] and leaves the join and panic controls
green. The stage BARRIER is the join half plus a structural fact -- run_walk's stage loop
takes &mut stage_memo per iteration, so two iterations cannot overlap.

Verified: 43/43 executor suite; the ordinary hot path exercised end-to-end through the
new executor against the budget RED-control fixture (batch progress line, claim PASS,
"floor contract finalized"); regen a clean seed update; cargo fmt clean.

Found while verifying, worth recording because it nearly shipped: the first fixture run
reported exit 0 with no output and I had it filtered through a grep, so a parse error I
had just introduced into dag/std/realization_schedule.dag (literal double quotes inside a
.dag string, terminating it early) looked like a pass. An exit code is not a receipt when
the filter can hide the diagnostic.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
@cursor

cursor Bot commented Jul 31, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@briansrls
briansrls marked this pull request as draft July 31, 2026 17:41
…perties

Review of #7499 (2026-07-31). Five of seven blockers. The first was a real defect of
mine and it is why this PR went back to draft.

BLOCKER 1 -- the removed wall was removed on a FALSE premise. #7499 claimed both
populations share "the same lane partition, governor admission, and AdmittedSlot", and
deleted the heavy-whole-tree-resolve refusal for on-success stages on that basis. The
partition is shared; the ADMISSION is not. There is exactly ONE
AdmittedSlot::acquire_blocking in this file, inside run_batch_unit on the SPAWNED lane.
batch_unit_lane routes a heavy unit -- and every unit sharing its entry -- to
UnitLane::Memo, which runs through run_memo_shared_claims: no governor parameter, no
slot. So a heavy stage claim would resolve and evaluate a whole tree on the main thread,
unadmitted, while spawned units hold slots. The refusal is restored with the real reason.

The fix is NOT to wrap the memo call in a slot: it would release while the resolved
InterpContext stays resident in stage_memo for every later stage. The dissolve-on is a
governor-aware resident lease whose lifetime is the memoized context's, released on drop
-- named in-code so the next author does not repeat the reasoning that produced this.

BLOCKER 2 -- over_budget now fails the stage. Stages pass None (the clamp roster indexes
ORDINARY batches), so it is unreachable today; wired now so adding a declared stage clamp
is one line rather than one line plus remembering this fold.

BLOCKER 4 -- absence is its own state. A profileless ClaimRef was assigned
heavy=false/spawns=false/Negligible, which is conservative for effects but OPTIMISTIC
about work nobody described, and became the same SingleClaim variant an explicitly
profiled runnable does -- so the validator could not tell "declared Negligible" from
"nothing declared". ParsedProfileProvenance::{Declared,Undeclared} splits them and stages
refuse Undeclared.

BLOCKER 5 -- the carrier contract was too strong. "Members WITHIN a stage run
concurrently" is not what the executor provides: same-entry same-mode claims are combined
into one group and run serially, memo and discovery units run on the main thread, and at
governor width 1 two spawned threads exist while one body is admitted. Now: "eligible
independent resolve groups MAY overlap, subject to resource admission; no sibling
ordering is guaranteed." That still supplies what the admission occupants need without
making grouping, memo placement, and the governor into contract violations.

Also: the ordinary batch message tested the cumulative any_failed, so under FullLedger
every batch after the first failure was announced as "batch N had failures" whether or
not it had any -- the same local-versus-aggregate conflation that made the falsifier alert
misattribute green components. The stop DECISION stays the walk's; only the message is
local.

NOT FIXED, and the PR stays in draft for them: the production-path WalkPlan fixture
(blocker 3 -- the helper latch proves spawn_units overlaps closures handed to it, not that
a real plan reaches it, and every listed regression would leave it green) and the
success-stage materialization receipt (blocker 6). Both are specified for separate
dispatch rather than rushed.

VERIFICATION STATE, stated rather than implied: cargo build clean; the full executor suite
and regen were still running when this was committed, because the container is ephemeral
and losing conservative fixes is worse than committing ahead of the suite. The PR is a
DRAFT and not a merge candidate; CI is the verdict. If the suite or regen reds, that is a
defect in this commit, not a flake.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
CI regen redded on fe927fc: that commit edited walk_plan_note in
dag/std/realization_schedule.dag, which is inside v1's regen input
closure, without regenerating src/v1/stage0/src/std_realization_schedule.rs.
One file stale. This is a defect in that commit, as its own message said
it would be if regen redded — not a flake.

Regenerating surfaced a second defect in the same note, and it is the
worse of the two. Two claims from the pre-review draft were still live:

  "same governor admission (`run_batch_unit` takes an `AdmittedSlot`
   for the unit's lifetime)"           -- stated of BOTH populations
  "Members within a stage are therefore CONCURRENT as this note has
   always claimed"

The first is the sentence that justified deleting the heavy-resolve
stage refusal (review 2026-07-31, blocker 1). fe927fc restored the
refusal in code but left the prose that caused its removal, so the
carrier asserted universal admission while the executor it describes
refuses precisely because admission is not universal -- in the one note
whose stated purpose is that "a carrier that promises more than its
executor delivers is the same defect this type exists to end." The
second contradicts the weakened overlap contract added earlier in that
same note by fe927fc.

The note now states admission per-lane: run_batch_unit is reached on the
SPAWNED lane only; memo-lane and main-thread units run UNADMITTED; and
that is why a heavy-whole-tree-resolve claim is refused a stage rather
than admitted narrowly, since it routes to the memo lane and its context
stays resident in stage_memo across later stages -- so wrapping the call
in an ordinary slot would not bound it either.

Verified by execution:
  - regen_stage0 --emit-fresh --verify: regen_divergence_count=0
    (the exact gate the CI regen job runs)
  - exactly one generated file differs from fresh self-compile
  - cargo build --release: v1-compiler recompiles clean, exit 0
  - cargo fmt --all --check: clean
  - cargo test --bin claim_executor: 43 passed, 0 failed
    (this is the fe927fc verification that was still running when
     that commit was pushed; it came back green)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
Blocker 7. On-success stage receipts were written to a bare shared path with
no attempt identity, and the occupants land next as their first consumer —
so identity closes now, before there is a reader to fool.

Per gunbc.merge_admission merge_admission_attempt_scope_note:

- Identity is stamped in the PAYLOAD, not just the path. Path identity alone
  is not enough because a misrouted read must fail on the content too. Path
  scoping is added as well, but as hygiene against workspace reuse on
  self-hosted runners; the payload stamp is the wall.
- An unidentified walk REFUSES rather than defaulting. The ruling names the
  failure exactly: a silent constant like a bare local would make every local
  run one attempt and put the wrong-attempt refusal out of reach off CI.
  GUNBC_WALK_ATTEMPT_ID supplies a required input the environment did not; a
  value failing the segment law still refuses, so no setting of it disables a
  refusal.
- The refusal fires at arm time, beside the shape refusal, so an unidentified
  walk fails in seconds rather than after a 20-30 minute floor. Identity is
  demanded only when stages exist: a plan with no stages writes no
  attempt-scoped receipt, so requiring it there would be a refusal with no
  subject.

Two structural choices, each because the first draft was worse:

- The Rust segment predicate is a declared seed-retained REALIZATION of
  std.types path_segment_is_safe, mirrored clause for clause, stating that on
  disagreement the .dag is right and the Rust is the defect. Otherwise it is a
  second rule for one law.
- compose_walk_attempt_id (pure) is split from observe_walk_attempt_id (env),
  mirroring merge_admission_produce's own split. Not tidiness: process env is
  global, so a test that set it would race every other test in the binary, and
  a rule reachable only by a racing test is a rule nobody checks.

Also corrects a claim I wrote two commits ago. The comment naming "a
governor-aware resident lease" as the dissolve-on for the heavy-resolve
refusal understated it the same way the admission overclaim did. Probed
against decide_admission: AdmittedSlot is a CONCURRENCY slot, not a memory
reservation. A resident hold pins active >= 1, so the active == 0 progress
floor never fires and later admissions return Hold(WindowFull); width grows
only in note_completion, which needs a completion, which needs an admission.
The runner starts at target_width=1, so this is the default path, not a corner
case. The real dissolve-on is SPLITTING the governor's active counter into an
execution slot and a resident memory reservation — its own work with its own
receipt, on the path guarding against the exit-137 OOM kills.

Verified: build clean, fmt clean, 5 new controls green and proven
discriminating by mutation (defaulting absent identity to "local" reds both
refusal controls and leaves the three positive controls green). No test
references the changed surfaces, and no .dag changed, so regen is unaffected.
The full 48-test suite was still running at commit time; if it reds, that is a
defect in this commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
@briansrls
briansrls marked this pull request as ready for review July 31, 2026 19:21
briansrls pushed a commit that referenced this pull request Jul 31, 2026
@briansrls
briansrls merged commit 7cff3d7 into main Jul 31, 2026
5 of 10 checks passed
@briansrls
briansrls deleted the claude/pr-timing-analysis-3bm5e9 branch July 31, 2026 20:44
briansrls pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
…licts.

Integrates #7499 attempt-scoped on-success receipts with blocker-6 success
materialization receipt: attempt-scoped path + attempt_id= payload, no
post-harvest reset (ordinary take is the boundary).

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
…locker 6).

Harvest ordinary-floor materialization before on_success_stages; write a second
receipt under target/floor-attempt-<attempt_id>/ after stage_memo drops, with
attempt_id= in the payload and the same keyed/unkeyed/memo fields. No
post-harvest reset — the ordinary take drains the accumulator atomically.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
briansrls added a commit that referenced this pull request Jul 31, 2026
)

* Close the four review blockers on the merged run_stage extraction

Follow-up to #7499 (merged as 7cff3d7). These were requested in review
but were not in the merged head, so they land as a fresh change on a
branch restarted from main rather than stacked on merged history.

1. walk_plan_note contradicted itself. It asserted both that heavy
   whole-tree stage claims refuse (the current implementation) and that
   the arm-time validator no longer refuses them (stale text from a prior
   revision). Because this is the canonical carrier, the generated stage0
   projection reproduced the contradiction. Replaced with a CLOSED
   enumeration of all five refusals — a partial list is how the
   contradiction arose, so the shape is the fix, not just the wording.

   Also corrected the dissolve-on. The four profile restrictions name
   DIFFERENT triggers and do not dissolve together, and the
   undeclared-profile refusal has none at all — it is the fail-closed
   floor. The heavy trigger is two ordered steps: split execution-slot
   from resident-reservation accounting, THEN take a context-lifetime
   reservation. Naming the lease alone understated it; a lease against
   today's single `active` counter deadlocks.

2. Rust comments still stated the retracted contract — "members run
   concurrently", "same governor admission", "same derived cost clamp".
   All now match the carrier: distinct spawned groups MAY overlap subject
   to per-lane admission; "same clamp MECHANISM", since ordinary batches
   supply clamp parameters and stages deliberately pass None.

3. Receipt identity was half closed, and the merged PR body claimed it was
   closed. Per-stage receipts were attempt-scoped and payload-stamped; the
   aggregate had identity in neither path nor payload. Both aggregate write
   sites are now scoped and stamped, including the skip case, which refuses
   rather than writing unattributably.

   `entry` is now carried ON ClaimResult rather than recovered by lookup:
   searching a stage's runnables for a matching function name would
   reproduce exactly the ambiguity that makes a function name insufficient
   as a declaration identity. 16 construction sites. The two with no single
   declaring entry — the unmapped-node sentinel and the discovery aggregate
   — say so explicitly, because a blank field reads as "unknown" when the
   truth is "not one entry". plan_site added to both receipt headers.

4. The §7 seed deferral for run_stage/spawn_units/join_units/receipt
   writers is authored here, at its own carrier, with a SCAFFOLD marker on
   the Rust. A first draft had it in the downstream fixture branch, which
   reverses ownership: the debt belongs to the change that added the Rust,
   and a consumer documenting its parent's deferral lets the parent land
   without one.

Verification state, stated exactly:
- The four #[cfg(test)] sites missing `entry` were found by running the
  suite UNFILTERED. `cargo build` does not compile test targets, so every
  "build clean" check in this arc was structurally incapable of catching
  them, and a grep filter then rendered the compile error as an empty
  section rather than as failure. Both gates are corrected: the chain now
  runs `cargo test --no-run` and pipes the suite through `tail`, not grep.
- Test-binary compile, regen, fmt, and suite were green on the pre-rebase
  tree. The same gate is re-running on this rebased base and had not
  finished when this was committed. If it reds, that is a defect in this
  commit, not a flake, and the next commit fixes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Regenerate the stage0 seed for the corrected walk_plan_note

The branch carried a std_realization_schedule.rs that did not match its
own .dag source: the carrier has walk_plan_run_stage_claim_executor_seed_deferral
and the corrected refusal enumeration, the seed had neither (611 lines vs
the 620 a fresh self-compile produces). `regen_stage0 --emit-fresh
--verify` now reports regen_divergence_count=0.

Cause, stated correctly after an initial misattribution: commit 242be6b
carried only the two authored files. Replaying the blocker fixes onto the
rebased main used a two-file patch by design — the seed had to be
regenerated against the new base rather than carried across — and it was
then committed before that regeneration ran.

An earlier version of THIS message blamed the CI auto-heal commit
(44393e0) that happened to sit in between, claiming it had pushed a
seed contradicting its own tree. That was false. Auto-heal changed
exactly one file, docs/plans/fail-closed-lockdown.md, and
std_realization_schedule.rs is not in its roster at all — it is a
regen_stage0 output, a different artifact family. The observation that
regen re-modifies the file at 44393e0 was correct; the inference that
heal had written it was not, and the discriminating check (does that
commit touch the file?) had not been run before the claim was made.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
…locker 6).

Rebased onto main after #7518 merge; harvest ordinary receipt before on-success stages and a separate attempt-scoped receipt after stage_memo drops, with attempt_id and plan_site and no post-harvest reset.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Jul 31, 2026
Fixture-only delta rebased on main after #7518: walk_plan_stage controls,
discovery exclusion, attempt-scoped receipt path authority, and #[ignore]
integration harness with separate stdout/stderr oracles.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 1, 2026
briansrls pushed a commit that referenced this pull request Aug 1, 2026
briansrls pushed a commit that referenced this pull request Aug 1, 2026
* Success-stage materialization receipt on attempt-scoped path (#7499 blocker 6).

Rebased onto main after #7518 merge; harvest ordinary receipt before on-success stages and a separate attempt-scoped receipt after stage_memo drops, with attempt_id and plan_site and no post-harvest reset.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 45737: HAND-RUST witness + hermetic accumulator tests.

Add ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag as the checkable scaffold receipt; serialize eval_call_memo under PROCESS_EVAL_RECOMPUTE_TEST_LOCK and restore GUNBC_RECOMPUTE_TRACE after locked sections so sibling ctx Drops cannot pollute separation-test equality.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 45752: bounded HAND-RUST deferral receipt.

Add explicit deferral, witness-realization plan anchor, and ROADMAP lane anchor rows; witness test asserts the bounded deferral receipt instead of scaffold-only existence.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 45756: refreshable recompute-trace cache for tests.

Replace the OnceLock latch with a refreshable process cache and have PROCESS_EVAL_RECOMPUTE_TEST_LOCK force trace on plus refresh before/after each locked region so parallel siblings cannot permanently disable tracing.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 45766: hermetic receipt test without cross-run equality.

Restore cwd after the materialization fixture via with_workspace_root_current_dir, and assert population separation within one staged walk (ordinary receipt before stages, success receipt after) instead of comparing keyed_calls across runs that parallel siblings could perturb.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 1, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
Fixture-only delta rebased on main after #7518: walk_plan_stage controls,
discovery exclusion, attempt-scoped receipt path authority, and #[ignore]
integration harness with separate stdout/stderr oracles.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
briansrls added a commit that referenced this pull request Aug 1, 2026
* Production-path stage executor fixture (#7499 blocker 3)

Fixture-only delta rebased on main after #7518: walk_plan_stage controls,
discovery exclusion, attempt-scoped receipt path authority, and #[ignore]
integration harness with separate stdout/stderr oracles.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Serialize walk_plan_stage harness runs against shared target/ paths

Parallel cargo test threads interleaved cleanup with overlap markers,
making the overlap+barrier control flaky. Hold a process-wide lock for
each claim_executor walk.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align panic barrier oracle with self-recursion depth refusal

The approved panic_member specimen fails at interpreter call-depth limit,
not infra=thread_panic. Harness still requires stage-2 fail-fast.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 45755: scaffold receipt + DAG-sourced harness authority

Add gunbc.walk_plan_stage_fixture_scaffold with enrolled witness; Rust
harness materializes attempt/receipt/path identity from common.dag via
walk_plan_stage_materialize_harness_authority_holds instead of forking
literals. Stage-2 marker path centralized in common.dag.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix harness bootstrap for isolated #[ignore] test runs (review 45760)

Materialize harness authority before pre-cleanup via ensure_harness_authority;
discover the authority file by self-locating payload (harness_authority_path
line) instead of forking common.dag's path literal in Rust.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix parse error in walk_plan_stage_fixture_scaffold dissolve trigger

Escape literal braces in \{plan,common\} so the dissolve-trigger string
does not trigger dag string interpolation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Filter harness authority discovery before strict parse (review 45776)

Skip unrelated target/ files unless they carry the harness_authority_path=
marker, so populated target/ directories do not panic during bootstrap.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* fix(walk-plan-stage): import recipe from plan in hand-rust witness

walk_plan_stage_overlap_barrier_recipe lives in plan.dag, not common.dag;
the receipt witness must resolve against the defining module.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(walk-plan-stage): drop unused harness authority thread_local

FixtureSession holds HarnessAuthority directly; the thread_local cache
left over from ensure_harness_authority was write-only dead code.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* fix(walk-plan-stage): resolve release claim_batch in fixture harness

Release integration tests build only the test binary; fall back to
target/release when CARGO_BIN_EXE and PROFILE are unset.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
* Close the four review blockers on the merged run_stage extraction

Follow-up to #7499 (merged as 7cff3d7). These were requested in review
but were not in the merged head, so they land as a fresh change on a
branch restarted from main rather than stacked on merged history.

1. walk_plan_note contradicted itself. It asserted both that heavy
   whole-tree stage claims refuse (the current implementation) and that
   the arm-time validator no longer refuses them (stale text from a prior
   revision). Because this is the canonical carrier, the generated stage0
   projection reproduced the contradiction. Replaced with a CLOSED
   enumeration of all five refusals — a partial list is how the
   contradiction arose, so the shape is the fix, not just the wording.

   Also corrected the dissolve-on. The four profile restrictions name
   DIFFERENT triggers and do not dissolve together, and the
   undeclared-profile refusal has none at all — it is the fail-closed
   floor. The heavy trigger is two ordered steps: split execution-slot
   from resident-reservation accounting, THEN take a context-lifetime
   reservation. Naming the lease alone understated it; a lease against
   today's single `active` counter deadlocks.

2. Rust comments still stated the retracted contract — "members run
   concurrently", "same governor admission", "same derived cost clamp".
   All now match the carrier: distinct spawned groups MAY overlap subject
   to per-lane admission; "same clamp MECHANISM", since ordinary batches
   supply clamp parameters and stages deliberately pass None.

3. Receipt identity was half closed, and the merged PR body claimed it was
   closed. Per-stage receipts were attempt-scoped and payload-stamped; the
   aggregate had identity in neither path nor payload. Both aggregate write
   sites are now scoped and stamped, including the skip case, which refuses
   rather than writing unattributably.

   `entry` is now carried ON ClaimResult rather than recovered by lookup:
   searching a stage's runnables for a matching function name would
   reproduce exactly the ambiguity that makes a function name insufficient
   as a declaration identity. 16 construction sites. The two with no single
   declaring entry — the unmapped-node sentinel and the discovery aggregate
   — say so explicitly, because a blank field reads as "unknown" when the
   truth is "not one entry". plan_site added to both receipt headers.

4. The §7 seed deferral for run_stage/spawn_units/join_units/receipt
   writers is authored here, at its own carrier, with a SCAFFOLD marker on
   the Rust. A first draft had it in the downstream fixture branch, which
   reverses ownership: the debt belongs to the change that added the Rust,
   and a consumer documenting its parent's deferral lets the parent land
   without one.

Verification state, stated exactly:
- The four #[cfg(test)] sites missing `entry` were found by running the
  suite UNFILTERED. `cargo build` does not compile test targets, so every
  "build clean" check in this arc was structurally incapable of catching
  them, and a grep filter then rendered the compile error as an empty
  section rather than as failure. Both gates are corrected: the chain now
  runs `cargo test --no-run` and pipes the suite through `tail`, not grep.
- Test-binary compile, regen, fmt, and suite were green on the pre-rebase
  tree. The same gate is re-running on this rebased base and had not
  finished when this was committed. If it reds, that is a defect in this
  commit, not a flake, and the next commit fixes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Success-stage materialization receipt on attempt-scoped path (#7499 blocker 6).

Harvest ordinary-floor materialization before on_success_stages; write a second
receipt under target/floor-attempt-<attempt_id>/ after stage_memo drops, with
attempt_id= in the payload and the same keyed/unkeyed/memo fields. No
post-harvest reset — the ordinary take drains the accumulator atomically.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align walk_plan_note and executor comments with per-lane admission (review 45660).

Heavy-whole-tree-resolve still refuses at arm time (memo lane, unadmitted);
retract the note's claim that the validator dropped that refusal. Update
spawn_units and run_walk comments to match the weaker overlap contract.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Mark walk_plan_stage production-path fixture tests ignored in default CI.

Each control is proven by execution via claim_executor recipes in
plan.dag; the integration tests remain for local/operator runs (~7m
each due to the naming-hygiene walk) without blocking every PR build.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Fix overlap_coordination sleep import for module-qualified service access.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Exclude walk_plan_stage fixtures from witness discovery (CI fix).

These Wet production-path controls are driven only via plan.dag
claim_executor recipes; as hermetic discovery witnesses they fail with
missing mock_response or BY-DESIGN reds when the PR touches their closure.
Mirror floor_skip's dir-grain FixtureExplicitRoster exclusion.

* chore: regenerate drifted generated artifacts (ci auto-heal)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Regenerate the stage0 seed for the corrected walk_plan_note

The branch carried a std_realization_schedule.rs that did not match its
own .dag source: the carrier has walk_plan_run_stage_claim_executor_seed_deferral
and the corrected refusal enumeration, the seed had neither (611 lines vs
the 620 a fresh self-compile produces). `regen_stage0 --emit-fresh
--verify` now reports regen_divergence_count=0.

Cause, stated correctly after an initial misattribution: commit 242be6b
carried only the two authored files. Replaying the blocker fixes onto the
rebased main used a two-file patch by design — the seed had to be
regenerated against the new base rather than carried across — and it was
then committed before that regeneration ran.

An earlier version of THIS message blamed the CI auto-heal commit
(44393e0) that happened to sit in between, claiming it had pushed a
seed contradicting its own tree. That was false. Auto-heal changed
exactly one file, docs/plans/fail-closed-lockdown.md, and
std_realization_schedule.rs is not in its roster at all — it is a
regen_stage0 output, a different artifact family. The observation that
regen re-modifies the file at 44393e0 was correct; the inference that
heal had written it was not, and the discriminating check (does that
commit touch the file?) had not been run before the claim was made.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K

* WIP: Dispatch D: v2 WalkPlan schedule-lens PR - rename ordinary lens to Reali

* Move floor naming helpers to their single authority (#7516)

* WIP: P1 cardinality kernel

* Complete floor naming authority move

* Import moved floor tokenizer helper

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Census floor naming CLI adapter

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* WIP: Dispatch A: production-path stage executor fixture (#7499 blocker 3) - f

* Fix walk_plan_stage fixtures for attempt-scoped receipts (review 45688).

Supply GUNBC_WALK_ATTEMPT_ID in the integration harness; route barrier,
cleanup, and poison claims through one path authority in common.dag.
Capture stdout and stderr separately (PASS/FAIL on stdout, progress on
stderr). Tighten panic and receipt-refusal oracles. Remove the run_stage
§7 deferral row and SCAFFOLD marker — owned by #7518, not the fixture PR.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Complete WalkPlan schedule lens coverage

* WIP: Dispatch D: v2 WalkPlan schedule-lens PR - rename ordinary lens to Reali

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Record measured admission resolve count and baseline

* Defuse merge-admission capture identity closure

* Name the de-fused carrier for its tested subject

* Lock tested-subject wire bytes across de-fusion

* Make admission-stage budgets and resolves honest

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Run merge subject capture in typed subprocess

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Keep merge-admission stages on the warm executor index

* Regenerate stage0 from the current compiler

* Resolve CI floor witness import merge

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Reconcile merge admission with grounded Git object IDs

* Merge repaired main while preserving warm admission stages

* WIP: Dispatch E: merge-admission occupants (task #14) atomic with orphaned sh

* Heal ci.yml on the merged tree; pass the typed stall deadline at the staging context's fetch (review 47488)

The heal job flagged .github/workflows/ci.yml drifted after the main merge —
workflow files are author-commit-required, so the main_wet regeneration lands
here (in-executor admission shape: shell stamp step deleted, wrapper 95m).

merge_admission_current_context.dag's FetchNoTags call predated this PR's
stall_deadline_seconds required input (cursor review 47488) — it now imports
and passes the same merge_admission_fetch_stall_deadline_seconds authority the
walk uses (single authority, no second constant). Entry compiles clean by
execution (gunbc compile --target dag, exit 0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Delete the dead include_admission_capture parameter (review 47503)

The Bool was threaded through floor_nodes / floor_data_dependencies /
floor_dependencies_with / floor_schedule_via_runner_for /
floor_schedule_for_with_capture, but no body ever read it — a parallel
representation of a decision the code does not make (the admission capture
actually rides WalkPlan.pre_walk_execution, not the schedule graph). The
parameter and the _with_capture wrapper delete; floor_schedule_for calls the
runner directly and gunbc_ci_floor_schedule_inner collapses onto it. Affected
witnesses green by execution (pr_native_batch pair, disjoint-budget pin,
ci_workflow_witness_holds).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Address review 47517: typed capture refusal, one untagged-oid decoder, named walk-overhead budget term, seed-deferral extension

1. capture_tested_subject no longer collapses seven failure causes to bare
   false: the core returns TestedSubjectCapture with a typed refusal coproduct,
   and the Bool claim projection durably writes the labeled cause to
   target/merge-admission-capture-refusal.txt (the population-budget-refusal
   pattern) before returning false; run_pre_walk_execution reads the wire into
   its located PRE-WALK-REFUSED line, with wire-absent reported as its own state.
2. The hex-length family guess moves to its single authority:
   extdeps.git.object_store git_object_id_from_untagged_hex decodes git's own
   untagged plumbing output (40/64 canonical widths, refusing others); the
   capture tool and merge_admission_walk both consume it and the per-consumer
   re-guess deletes.
3. The wrapper budget names the wall outside both populations:
   gunbc_ci_walk_overhead_allowance_minutes (5m) joins the sum, wrapper = 65m,
   so a slow pre-walk or finalization cannot silently eat the ordinary
   allowance; witness pins the three-term sum, ci.yml regenerated.
4. walk_plan_run_stage_claim_executor_seed_deferral extended to name the
   pre-walk parser, budget watchdogs, refusal writer, and memory snapshots as
   the same seed debt on the same dissolution trigger.

regen divergence 0; ci_workflow and disjoint-budget witnesses green; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Correct the stale lane-placement claim in merge_admission_walk_note (review 47528)

The note said the two on-success claims take spawned lanes; they route through
population_unit_lane to the main thread, and the executor's population_unit_lane
plus its tests are the placement authority. Doc-only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Type the stage-2 refresh refusal; the cause rides a durable wire into the stage-failure line (CI run 30764945450)

The floor redded at on-success stage 2 with refresh_current_target_and_gate
returning bare Bool(false) — review 47542 finding 3 made blocking: seven
failure causes conflated, the red undiagnosable from the log. Same repair
shape as the pre-walk capture: merge_target_refresh returns a typed sum
(MergeTargetRefreshRefusal — fetch-refused carrying the operation's own
stderr, attempt-identity-absent, subject/receipt wire missing, target-tree
observation refused with its cause, oid unparseable, verdict-denied with the
verdict label), and the Bool claim projection durably writes the labeled
cause to target/merge-admission-refresh-refusal.txt before returning false.
claim_executor's stage-failure line now reads that wire, so the next run
names its own cause. Also widens the pre-walk wire-absent message per review
47542 finding 1 (child-crashed vs wire-write-refused are indistinguishable
from the parent by construction, and the message now says so).

Walk entry compiles clean by execution (0 blocking); fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Route wire relpaths through paired consts, bin path through release_bin_rel_path, and declare the ratchet-off widening as a Scaffold Disposition (review 47596)

Finding 1: MERGE_ADMISSION_{CAPTURE,REFRESH}_REFUSAL_WIRE consts in claim_executor.rs
with pairing doc-comments; _seed_pairing notes beside both dag relpath authorities.
Finding 2: merge_admission_capture_transport routes the claim_batch bin path through
gunbc.cli_invoke release_bin_rel_path instead of minting the string.
Finding 3: merge_admission_refresh_ratchet_off_widening_{note,disposition} — the
ratchet-off else arm is a declared Scaffold bound to the
merge_freshness_verdict_is_consumed_to_block flip, per the fleet-gating shadow-phase
policy; the flip commit deletes the arm and the row together.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Consume the typed target tree hash directly; delete the debug-render re-parse that could never succeed (CI run 30769177034)

The typed refusal wire did its job on the first red it carried:
cause=target-oid-unparseable observed=GitSha1ObjectId { digest: ... } — the
stage-2 arm cast observe_merge_target_tree_hash's already-typed GitObjectId
to String (its record rendering) and re-parsed it as untagged hex, a §3
re-guess of a fact the producer's type already carries. The classifier takes
GitObjectId, so the hash now flows through directly; the unreachable-by-type
RefreshTargetOidUnparseable arm and the object_store import are deleted with
it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Replace the unevaluable '300 as Seconds' cast with a bare-literal data row (review 47638)

The interpreter has no cast into a branded scalar; the corpus idiom is a
bare-literal data row, the same shape as this PR's
merge_admission_fetch_stall_deadline_seconds = 240 which already executed on
CI. fetch_pr_head_ref now reads review_fetch_stall_deadline_seconds = 300.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Post-merge repairs: regenerate ci.yml from the merged authority, anchor wire reads at git toplevel, import std.decl_ref explicitly (reviews 47663, 47665)

- ci.yml regenerated via generated_artifact_gate main_wet on the merged tree:
  restores the heal skew-guard's stage0 emitted-Rust exclusions the text merge
  had dropped (review 47665 finding 2) and clears HealAuthorCommitRequired
  from run 30774448327.
- claim_executor's two refusal-wire reads now anchor on git rev-parse
  --show-toplevel, matching the .dag writers' git.Inspect.Toplevel() anchor,
  so a non-root cwd cannot turn a written typed cause into a false
  wire-absent (review 47663).
- merge_admission_walk.dag imports DeclarationRef/WholeDeclaration explicitly
  from std.decl_ref instead of relying on bare-name resolution (review 47665
  finding 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants