Skip to content

Run merge admission as ordered CI success stages - #7522

Merged
briansrls merged 74 commits into
mainfrom
session/quick-heron-791
Aug 3, 2026
Merged

briansrls merged 74 commits into
mainfrom
session/quick-heron-791

Conversation

@briansrls

@briansrls briansrls commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Populate the live CI WalkPlan on-success roster with two ordered singleton stages: stamp the captured checkout subject, then fresh-fetch and gate the current merge target. The old cold stamp/gate shell-emitter web is deleted atomically, and the live schedule lens consumes the same roster authority so divergence is red from the first populated commit.

This is a topology/cost migration. It preserves GatingComputedDeferred: the PR makes the fresh observation and gate warm and ordered, but does not activate merge-freshness enforcement or describe that policy arc as complete.

Capture placement and authority

The original in-process ordinary capture falsified its Negligible declaration in production. Even after de-fusing the claim to a 54-module closure, run 30702499883 showed one spawned-worker arena surviving thread join: capture passed, discovery handed off at 7.4 GiB versus the 5.2–6.1 GiB controls, swap grew to about 32 GiB, and discovery remained at entry 0 until the 60-minute wrapper expired.

Per the Dispatch A→C ruling on 2026-08-01, capture is now a modeled TypedClaimSubprocess in WalkPlan.pre_walk_execution. claim_executor resolves the narrow transport entry and the transport launches the already-built claim_batch child through gunbc.WitnessBin.Run; no raw shell string and no ad-hoc Command is introduced. Child failure is a typed, located pre-walk refusal and blocks batch 1. The child address space dies before the ordinary floor, structurally reclaiming its evaluator arena.

WalkAttemptId, TestedSubject, and the exact capture path/wire helpers have one home in gunbc.merge_admission_subject. gunbc.merge_admission imports that carrier and retains classification/admission policy. Capture, stamp, and gate consume the same subject authority; the carrier never imports the domain. The tested-subject writer is unchanged, and the literal five-line byte-lock witness remains green.

The two success stages intentionally retain their disk-visible barrier. They use the same entry but do not claim cross-stage resolved-context memo reuse. Accounting therefore allows up to two stage resolves and records the actual count, wall, and memory in the attempt-scoped receipts.

The first production run to reach this population exposed a separate placement defect: non-heavy stage units were sent to a worker thread even though process_shared_index is thread-local and warmed only on the executor main thread. That rebuilt a cold index inside the supposedly warm stage path. Per the Dispatch A→C ruling on 2026-08-01, on-success units that would otherwise spawn now execute through the existing run_batch_unit on the main thread. They still acquire the same governor AdmittedSlot; ordinary placement is unchanged. WalkPlan already permits withdrawing sibling overlap, and the live roster consists of singleton stages, so the schedule lens remains unchanged and green.

The same run also showed that the postcondition watchdog could terminate during a silent resolve without leaving an observable stage mark. The modeled WalkPopulationBudgetRefusal now carries population, plan site, one-based stage/batch index, exact active unit, measured elapsed wall, and the budget that fired. The watchdog durably writes that receipt and flushes the located stderr line before exiting. A child-process discriminator proves both artifacts survive the forced exit.

Before receipts

  • Current-main cold baseline: run 30671526012, job 91291716818 at ddbc5fd6aa; stamp 94.26s, gate 102.87s, combined 197.13s.
  • Temporary first placement: the ordinary capture raised the measured floor resolve count 1 → 2 (resolves_total=2, resolve_ms_total=64486). Moving capture into the typed child returns the ordinary in-process declaration to 1; the child resolve remains visible in the pre-walk receipt rather than being counted as an ordinary resolve.
  • Production false-profile RED: run 30702499883, job 91377903771 at 660436107; capture passed, discovery handoff was 7.4 GiB at entry 0/845, memory rose to 14.9 GiB plus swap, swap reached about 32 GiB, and the 60-minute wrapper expired with discovery still at entry 0.
  • No-capture control: run 30691107295, job 91346262897; discovery reached entry 46/843 by minute 8 and entry 177 by minute 10 around 5.2–5.4 GiB with no swap, finishing green in 26m49s. The closure delta was only +4 nodes/+36 rows, while the retained memory delta matched the 2.1 GiB first-worker share.

Executed validation on the typed-child head

  • ci_floor_plan_witnesses — pass, including the exact typed pre-walk row and the live success-stage roster lens.
  • cargo check -p v1-compiler --bin claim_executor — pass.
  • regen_stage0 --verify — regen_divergence_count=0.
  • Production-shaped local control using the real floor plan and GUNBC_WALK_ATTEMPT_ID=quick-heron-typed-capture-control: typed capture child passed, wrote the unchanged five-line subject wire, and returned a located receipt with wall_ms=100088, memory_current_before=3241562112, memory_current_after=3177357312, swap_after=144097280; ordinary batch 1 began only afterward. This is placement/order evidence, not the required fleet performance receipt.
  • Fleet run 30708195963 at 4607b2d71 proved the placement and resource side before an unrelated ordinary-floor witness import failed: capture wall_ms=102897, memory_current_before=3465207808, memory_current_after=3469225984, memory_peak_after=5825937408, swap_after=0, high_events_after=0. Discovery then advanced at a stable 6.4 GiB and zero swap from entry 54/847 at receipt-minute 12 to entry 524 at minute 19. The stale ci_spec_witness import failed batch 3, and construction correctly reported 0 of 2 on-success stages run with 0 stage resolves. The import now consumes gunbc.merge_admission_subject; its exact perturbation witness passes on the merged tree.
  • Run 30710230296 at bf68ffb1d independently reproduced the resource result: capture wall_ms=97087, memory_current_before=3469467648, memory_current_after=3475148800, memory_peak_after=5828857856, swap_after=0, high_events_after=0; discovery advanced from entry 50/848 at receipt-minute 12 to 832 at minute 25, held 6.4 GiB/zero swap throughout, and drained all 848 groups with peak_rss=7157161984. The floor then hit exactly the two operator-declared known-main primitive-surface witness reds (the_surface_is_almost_entirely_derived, the_three_denominators_are_derived_and_distinct), owned and subsequently fixed by the separate repair lane. Green-only construction correctly recorded 0 of 2 stages and 0 stage resolves.
  • Run 30712984494 at d682f83d integrated that main repair and completed the ordinary floor green: typed capture wall_ms=91065, current memory 3462320128 → 3463213056, peak 5817024512, zero swap/high events; discovery drained all 848 groups with peak_rss=7162372096. The first on-success window then emitted no stage receipt for 7m22s and raised the cgroup span peak to 9390518272 before failure. Local production-shape reproduction resolved tools.merge_admission_walk as a 176-module closure in 32.616s only after paying a fresh index load dominated by 51.3s in the bare-edge index. Code inspection established why: the stage worker received a fresh thread-local index instead of the main thread's warmed one. The local timings establish the cold-index mechanism; the remainder of the fleet multiplier is unattributed and is not claimed as index wall.
  • The 102.897s capture wall is predominantly the narrow child paying cold compiler/index startup, not the semantic Git observations themselves. Per operator ruling, this PR does not add a capture-specific shortcut: dissolution belongs to the pre-index-materialization-lookup/native-realization program, where the child can consume a shared precomputed artifact.
  • After integrating current main, the exact live-plan witness, declared resolve-count projection, and disjoint 55m/5m budget witness all pass; current-source regen_stage0 --verify reports regen_divergence_count=0.
  • population_budget_watchdog_refuses_and_writes_located_receipt — pass: a forced watchdog exit leaves the flushed located line and durable receipt with exact index/unit/elapsed/budget.
  • on_success_spawned_claims_move_to_warm_main_thread_only — pass in both directions: the same negligible claim remains Spawned for the ordinary population and becomes MainThread only for OnSuccessStage.
  • gunbc_ci_walk_plan_schedule_lens_holds and its synthetic red controls — pass unmodified after the placement change.
  • cargo fmt --all --check and git diff --check — pass.

Remaining draft bar

  • Rerun final head 1432d825e0 through the now-main-thread success stages. Record both stage closure/profile receipts, actual resolves, memory, and wall; make the observed profile honest if it differs from the authored declaration.
  • Compare total admission-related wall honestly: old 197.13s two-cold-process baseline versus new 102.897s capture subprocess + warm stamp stage + warm refresh/gate stage. No three-minute claim is made absent measured stage walls.
  • Complete final-head CI and the normal review bar before undrafting.

claude and others added 29 commits July 31, 2026 20:47
Follow-up to #7499 (merged as 7cff3d7). These were requested in review
but were not in the merged head, so they land as a fresh change on a
branch restarted from main rather than stacked on merged history.

1. walk_plan_note contradicted itself. It asserted both that heavy
   whole-tree stage claims refuse (the current implementation) and that
   the arm-time validator no longer refuses them (stale text from a prior
   revision). Because this is the canonical carrier, the generated stage0
   projection reproduced the contradiction. Replaced with a CLOSED
   enumeration of all five refusals — a partial list is how the
   contradiction arose, so the shape is the fix, not just the wording.

   Also corrected the dissolve-on. The four profile restrictions name
   DIFFERENT triggers and do not dissolve together, and the
   undeclared-profile refusal has none at all — it is the fail-closed
   floor. The heavy trigger is two ordered steps: split execution-slot
   from resident-reservation accounting, THEN take a context-lifetime
   reservation. Naming the lease alone understated it; a lease against
   today's single `active` counter deadlocks.

2. Rust comments still stated the retracted contract — "members run
   concurrently", "same governor admission", "same derived cost clamp".
   All now match the carrier: distinct spawned groups MAY overlap subject
   to per-lane admission; "same clamp MECHANISM", since ordinary batches
   supply clamp parameters and stages deliberately pass None.

3. Receipt identity was half closed, and the merged PR body claimed it was
   closed. Per-stage receipts were attempt-scoped and payload-stamped; the
   aggregate had identity in neither path nor payload. Both aggregate write
   sites are now scoped and stamped, including the skip case, which refuses
   rather than writing unattributably.

   `entry` is now carried ON ClaimResult rather than recovered by lookup:
   searching a stage's runnables for a matching function name would
   reproduce exactly the ambiguity that makes a function name insufficient
   as a declaration identity. 16 construction sites. The two with no single
   declaring entry — the unmapped-node sentinel and the discovery aggregate
   — say so explicitly, because a blank field reads as "unknown" when the
   truth is "not one entry". plan_site added to both receipt headers.

4. The §7 seed deferral for run_stage/spawn_units/join_units/receipt
   writers is authored here, at its own carrier, with a SCAFFOLD marker on
   the Rust. A first draft had it in the downstream fixture branch, which
   reverses ownership: the debt belongs to the change that added the Rust,
   and a consumer documenting its parent's deferral lets the parent land
   without one.

Verification state, stated exactly:
- The four #[cfg(test)] sites missing `entry` were found by running the
  suite UNFILTERED. `cargo build` does not compile test targets, so every
  "build clean" check in this arc was structurally incapable of catching
  them, and a grep filter then rendered the compile error as an empty
  section rather than as failure. Both gates are corrected: the chain now
  runs `cargo test --no-run` and pipes the suite through `tail`, not grep.
- Test-binary compile, regen, fmt, and suite were green on the pre-rebase
  tree. The same gate is re-running on this rebased base and had not
  finished when this was committed. If it reds, that is a defect in this
  commit, not a flake, and the next commit fixes it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
…locker 6).

Harvest ordinary-floor materialization before on_success_stages; write a second
receipt under target/floor-attempt-<attempt_id>/ after stage_memo drops, with
attempt_id= in the payload and the same keyed/unkeyed/memo fields. No
post-harvest reset — the ordinary take drains the accumulator atomically.

Co-authored-by: Cursor <cursoragent@cursor.com>
…eview 45660).

Heavy-whole-tree-resolve still refuses at arm time (memo lane, unadmitted);
retract the note's claim that the validator dropped that refusal. Update
spawn_units and run_walk comments to match the weaker overlap contract.

Co-authored-by: Cursor <cursoragent@cursor.com>
… CI.

Each control is proven by execution via claim_executor recipes in
plan.dag; the integration tests remain for local/operator runs (~7m
each due to the naming-hygiene walk) without blocking every PR build.

Co-authored-by: Cursor <cursoragent@cursor.com>
…cess.

Co-authored-by: Cursor <cursoragent@cursor.com>
These Wet production-path controls are driven only via plan.dag
claim_executor recipes; as hermetic discovery witnesses they fail with
missing mock_response or BY-DESIGN reds when the PR touches their closure.
Mirror floor_skip's dir-grain FixtureExplicitRoster exclusion.
The branch carried a std_realization_schedule.rs that did not match its
own .dag source: the carrier has walk_plan_run_stage_claim_executor_seed_deferral
and the corrected refusal enumeration, the seed had neither (611 lines vs
the 620 a fresh self-compile produces). `regen_stage0 --emit-fresh
--verify` now reports regen_divergence_count=0.

Cause, stated correctly after an initial misattribution: commit 242be6b
carried only the two authored files. Replaying the blocker fixes onto the
rebased main used a two-file patch by design — the seed had to be
regenerated against the new base rather than carried across — and it was
then committed before that regeneration ran.

An earlier version of THIS message blamed the CI auto-heal commit
(44393e0) that happened to sit in between, claiming it had pushed a
seed contradicting its own tree. That was false. Auto-heal changed
exactly one file, docs/plans/fail-closed-lockdown.md, and
std_realization_schedule.rs is not in its roster at all — it is a
regen_stage0 output, a different artifact family. The observation that
regen re-modifies the file at 44393e0 was correct; the inference that
heal had written it was not, and the discriminating check (does that
commit touch the file?) had not been run before the claim was made.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
Rebases blocker-6 onto the run_stage receipt-identity repair. Success
materialization receipt now carries plan_site= alongside attempt_id=,
matching other attempt-scoped on-success evidence. Ordinary harvest
remains the sole accumulator boundary (no post-harvest reset).

Co-authored-by: Cursor <cursoragent@cursor.com>
* WIP: P1 cardinality kernel

* Complete floor naming authority move

* Import moved floor tokenizer helper

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Census floor naming CLI adapter

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Supply GUNBC_WALK_ATTEMPT_ID in the integration harness; route barrier,
cleanup, and poison claims through one path authority in common.dag.
Capture stdout and stderr separately (PASS/FAIL on stdout, progress on
stderr). Tighten panic and receipt-refusal oracles. Remove the run_stage
§7 deferral row and SCAFFOLD marker — owned by #7518, not the fixture PR.

Co-authored-by: Cursor <cursoragent@cursor.com>
…n-791

# Conflicts:
#	src/v1/stage0/src/bin/claim_executor.rs
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Cross-PR semantic check for #7531: #7531 inserts the additive CheckCoverage carrier/fold before the receipt constructors. Its classify_check_coverage_admission path does not call legacy classify_merge_admission_verdict; it reuses only check_conclusion_admits_merge_admission_floor, which this PR leaves unchanged. The current 33-line replacement after the legacy classifier extracts WalkAttemptId / TestedSubject, so there is no hidden semantic dependency despite the shared file. Please re-run #7531’s check_coverage_admission_witness_test if this PR lands second.

@cursor

cursor Bot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

gunbc-ci-auto-heal and others added 5 commits August 2, 2026 17:58
…staging context's fetch (review 47488)

The heal job flagged .github/workflows/ci.yml drifted after the main merge —
workflow files are author-commit-required, so the main_wet regeneration lands
here (in-executor admission shape: shell stamp step deleted, wrapper 95m).

merge_admission_current_context.dag's FetchNoTags call predated this PR's
stall_deadline_seconds required input (cursor review 47488) — it now imports
and passes the same merge_admission_fetch_stall_deadline_seconds authority the
walk uses (single authority, no second constant). Entry compiles clean by
execution (gunbc compile --target dag, exit 0).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The Bool was threaded through floor_nodes / floor_data_dependencies /
floor_dependencies_with / floor_schedule_via_runner_for /
floor_schedule_for_with_capture, but no body ever read it — a parallel
representation of a decision the code does not make (the admission capture
actually rides WalkPlan.pre_walk_execution, not the schedule graph). The
parameter and the _with_capture wrapper delete; floor_schedule_for calls the
runner directly and gunbc_ci_floor_schedule_inner collapses onto it. Affected
witnesses green by execution (pr_native_batch pair, disjoint-budget pin,
ci_workflow_witness_holds).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…, named walk-overhead budget term, seed-deferral extension

1. capture_tested_subject no longer collapses seven failure causes to bare
   false: the core returns TestedSubjectCapture with a typed refusal coproduct,
   and the Bool claim projection durably writes the labeled cause to
   target/merge-admission-capture-refusal.txt (the population-budget-refusal
   pattern) before returning false; run_pre_walk_execution reads the wire into
   its located PRE-WALK-REFUSED line, with wire-absent reported as its own state.
2. The hex-length family guess moves to its single authority:
   extdeps.git.object_store git_object_id_from_untagged_hex decodes git's own
   untagged plumbing output (40/64 canonical widths, refusing others); the
   capture tool and merge_admission_walk both consume it and the per-consumer
   re-guess deletes.
3. The wrapper budget names the wall outside both populations:
   gunbc_ci_walk_overhead_allowance_minutes (5m) joins the sum, wrapper = 65m,
   so a slow pre-walk or finalization cannot silently eat the ordinary
   allowance; witness pins the three-term sum, ci.yml regenerated.
4. walk_plan_run_stage_claim_executor_seed_deferral extended to name the
   pre-walk parser, budget watchdogs, refusal writer, and memory snapshots as
   the same seed debt on the same dissolution trigger.

regen divergence 0; ci_workflow and disjoint-budget witnesses green; fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

review 47523 examined the intermediate autocommit head (11396a1), which carried the ci_spec three-term wrapper (65m) with a not-yet-regenerated ci.yml — exactly the drift it describes. The current head a3c41e2 contains the main_wet regeneration: floor step timeout-minutes is 65 and the ci job backstop is 100. On the backstop magnitude: the review's own term list (10+5+65+5+5+5+5) sums to 100, not 105, and that is what the model emits; ci_workflow_witness_holds (backstop == exact step-sum + prelude, wrapper == three-term sum) is green by execution on this head, and the drift gate compares ci.yml byte-identically to the same authority that produced it. No further change should be needed for this finding. — sent from eager-boar-610

…review 47528)

The note said the two on-success claims take spawned lanes; they route through
population_unit_lane to the main thread, and the executor's population_unit_lane
plus its tests are the placement authority. Doc-only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

On review 47542's four non-blocking findings, dispositions rather than silence: (1) when write_capture_refusal_wire itself refuses, no channel to the parent remains (the claim result is a bare Bool), so child-crashed vs wire-write-refused are indistinguishable from the parent by construction — the parent's wire-absent wording will be widened to name both states in the next substantive commit rather than re-staling approvals over one diagnostic string. (2) The budget watchdog's hard exit tears concurrent writers the same way the outer workflow timeout always has; atomic temp+rename receipt writes are a real hardening item but separate work. (3) refresh_current_target_and_gate's bare-false arms are the documented staging window — the typed-refusal treatment lands with the merge_freshness_verdict_is_consumed_to_block flip, which is the same commit that makes those arms load-bearing. (4) gunbc_ci_walk_overhead_allowance_minutes is a declared envelope: the direction is receipted, and the magnitude gets its measurement from the pre-walk/finalization receipts the step itself emits once it runs on the fleet. — sent from eager-boar-610

gunbc-ci-auto-heal and others added 3 commits August 2, 2026 21:38
… the stage-failure line (CI run 30764945450)

The floor redded at on-success stage 2 with refresh_current_target_and_gate
returning bare Bool(false) — review 47542 finding 3 made blocking: seven
failure causes conflated, the red undiagnosable from the log. Same repair
shape as the pre-walk capture: merge_target_refresh returns a typed sum
(MergeTargetRefreshRefusal — fetch-refused carrying the operation's own
stderr, attempt-identity-absent, subject/receipt wire missing, target-tree
observation refused with its cause, oid unparseable, verdict-denied with the
verdict label), and the Bool claim projection durably writes the labeled
cause to target/merge-admission-refresh-refusal.txt before returning false.
claim_executor's stage-failure line now reads that wire, so the next run
names its own cause. Also widens the pre-walk wire-absent message per review
47542 finding 1 (child-crashed vs wire-write-refused are indistinguishable
from the parent by construction, and the message now says so).

Walk entry compiles clean by execution (0 blocking); fmt clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…in_rel_path, and declare the ratchet-off widening as a Scaffold Disposition (review 47596)

Finding 1: MERGE_ADMISSION_{CAPTURE,REFRESH}_REFUSAL_WIRE consts in claim_executor.rs
with pairing doc-comments; _seed_pairing notes beside both dag relpath authorities.
Finding 2: merge_admission_capture_transport routes the claim_batch bin path through
gunbc.cli_invoke release_bin_rel_path instead of minting the string.
Finding 3: merge_admission_refresh_ratchet_off_widening_{note,disposition} — the
ratchet-off else arm is a declared Scaffold bound to the
merge_freshness_verdict_is_consumed_to_block flip, per the fleet-gating shadow-phase
policy; the flip commit deletes the arm and the row together.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Review 47596, finding by finding — findings 1–3 fixed in 0187240; finding 4 is deliberate, rationale below.

1 (wire relpaths hardcoded in Rust): the two seed read sites now go through MERGE_ADMISSION_CAPTURE_REFUSAL_WIRE / MERGE_ADMISSION_REFRESH_REFUSAL_WIRE consts whose doc-comment names the paired .dag authority, and both dag relpath data rows carry a _seed_pairing note pointing back at the const — the same paired-literal discipline as floor-population-budget-refusal.txt, under walk_plan_run_stage_claim_executor_seed_deferral. The seed cannot import a .dag datum, so the pairing note on BOTH ends is the strongest available wall short of the self-host frontier.

2 (minted bin path): merge_admission_capture_transport now routes through gunbc.cli_invoke release_bin_rel_path(bin_name: "claim_batch").

3 (ratchet-off widening arm): landed merge_admission_refresh_ratchet_off_widening_note + a co-located Disposition = Scaffold row bound to gunbc.ci_failure_class merge_freshness_verdict_is_consumed_to_block — the flip commit deletes the else arm (verdict match becomes unconditional) and the row together. The arm itself stays: the fleet-gating policy requires the shadow phase (verdict computed and receipted, never blocking unrelated PRs) before the mechanism may deny.

4 (detached watchdog process::exit(1)): deliberate, not fixed — the exit IS the enforcement of the declared population ceiling. The cooperative check at the batch boundary only fires between batches; a single wedged unit (hung fetch, interpreter loop inside one claim) never reaches the next boundary, so without the detached thread the ceiling is advisory exactly in the case it exists for. Ordering inside the watchdog is receipt-first: it writes the typed PopulationBudgetRefusal receipt and flushes stderr sequentially on the same thread before exit(1), so the post-mortem artifact for the overrun case is complete by construction. On the race with finalization writes: the watchdog can only fire while armed, i.e. while the population has genuinely overrun its declared budget — in that state the materialization receipt is already not going to be a within-budget receipt, and the designated artifact for the state is the budget refusal. The realistic alternative is not a graceful drain: it is the CI wrapper timeout, which is a SIGKILL that writes nothing. The watchdog converts that opaque kill into a typed, located, counted refusal.

— sent from eager-boar-610

gunbc-ci-auto-heal and others added 2 commits August 2, 2026 23:10
…re-parse that could never succeed (CI run 30769177034)

The typed refusal wire did its job on the first red it carried:
cause=target-oid-unparseable observed=GitSha1ObjectId { digest: ... } — the
stage-2 arm cast observe_merge_target_tree_hash's already-typed GitObjectId
to String (its record rendering) and re-parsed it as untagged hex, a §3
re-guess of a fact the producer's type already carries. The classifier takes
GitObjectId, so the hash now flows through directly; the unreachable-by-type
RefreshTargetOidUnparseable arm and the object_store import are deleted with
it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

Review 47629 addressed in 5c7ba15: parse_git_tree_object_id is deleted and both call sites (target tree observation and the v1 receipt wire parse) now route through extdeps.git.object_store git_object_id_from_untagged_hex. On the v1 wire's eligibility for the untagged decoder: git_object_id_wire_hex renders bare unprefixed hex, so width-based family inference is the factually correct read-back for that legacy wire (the family-prefixed <family>:<hex> form is the v2 wire only), and the producer witnesses prove the round-trip by execution — 11/11 PASS locally including wire_roundtrip_preserves_admission_fields.

— sent from eager-boar-610

gunbc-ci-auto-heal and others added 3 commits August 2, 2026 23:49
…a row (review 47638)

The interpreter has no cast into a branded scalar; the corpus idiom is a
bare-literal data row, the same shape as this PR's
merge_admission_fetch_stall_deadline_seconds = 240 which already executed on
CI. fetch_pr_head_ref now reads review_fetch_stall_deadline_seconds = 300.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t raise with the capture-subprocess accounting (count stays 2)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…or wire reads at git toplevel, import std.decl_ref explicitly (reviews 47663, 47665)

- ci.yml regenerated via generated_artifact_gate main_wet on the merged tree:
  restores the heal skew-guard's stage0 emitted-Rust exclusions the text merge
  had dropped (review 47665 finding 2) and clears HealAuthorCommitRequired
  from run 30774448327.
- claim_executor's two refusal-wire reads now anchor on git rev-parse
  --show-toplevel, matching the .dag writers' git.Inspect.Toplevel() anchor,
  so a non-root cwd cannot turn a written typed cause into a false
  wire-absent (review 47663).
- merge_admission_walk.dag imports DeclarationRef/WholeDeclaration explicitly
  from std.decl_ref instead of relying on bare-name resolution (review 47665
  finding 1).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@briansrls
briansrls merged commit 87a4af3 into main Aug 3, 2026
4 checks passed
@briansrls
briansrls deleted the session/quick-heron-791 branch August 3, 2026 01:41
gunbai-bot Bot pushed a commit that referenced this pull request Aug 4, 2026
…inal dispositions.

Bank measured walls from main run 30863019228; settle #7522/#7671/#7534 as MEASURED or OPEN-with-trigger; retire stale in-flight/probable claims in five-minute and roadmap authorities.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 4, 2026
…nosis lanes (#7760)

* WIP: CI perf

* Close CI-cost research arc with harvested production receipt and terminal dispositions.

Bank measured walls from main run 30863019228; settle #7522/#7671/#7534 as MEASURED or OPEN-with-trigger; retire stale in-flight/probable claims in five-minute and roadmap authorities.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Address review 47900: Millisecond duration surface and design-thread OOM wording.

Public closeout walls use std.measure.Millisecond; design open-thread no longer treats OOM as the warm-hit skip blocker after #7728.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI parse panic and DESIGN.md drift after closeout edits.

Witness comparison must stay on one line (multiline `>` parsed as Gt); regenerate DESIGN.md open-thread to match design_document after #7728 wording.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: CI perf

* Model the CI-cost closeout as typed walls and settles, not prose strings.

Expose unattributed_ci_wall (1902042 ms) with pipeline/CI reconciliation; narrow assembly to compiler_next_measured_target; freeze entry-view until PR2 assigns the remainder.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 5, 2026
§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.
briansrls added a commit that referenced this pull request Sep 5, 2026
….E, §4.I, §4.J (#10576)

* Correct §4.A hygiene-reaper row: CASE 2 — four host_hygiene_reap_*_body symbols deleted by #8583

The §4.A row at L379 described host_hygiene_reaper_script.dag's 4
body symbols as A5-deferred. The file was deleted by ffa16a5
(#8583, Migrate host-hygiene reaper and liveness onto typed observation)
and the construction was migrated to typed host_hygiene_reaper_observe.dag
/ host_hygiene_reaper_remediate.dag / host_hygiene_liveness_observe.dag.
No direct successor body names exist — CASE 2 (file deletion upstream)
with hybrid CASE 1 (body names dissolved).

Verification:
- ffa16a5 is ancestor of origin/main ✅
- host_hygiene_reaper_script.dag: D in #8583's diff
- zero files define host_hygiene_reap_install_units_body et al.
- observe/remediate files present at dag/gunbc/host/

Part of #10537's per-row adjudication program.

* Correct §4.D srv3_chown_directory_to_current_user: CASE 4 — renamed AND climbed

The row at §4.D L436 listed srv3_chown_directory_to_current_user
as A5-deferred (srv3). It was actually renamed AND climbed by
20ad5b3 (#8796): successor is
gunbc.host_effect_realize.srv3_ensure_directory_owned_by_current_user.
New name has a stronger guarantee (readback-based, not chown exit-status
based).

This is CASE 4 (rename plus climb) — distinct from CASE 1 (dissolution)
because the construction did not disappear; it acquired a better name
and a stronger guarantee.

Verification:
- 20ad5b3 is ancestor of origin/main ✅
- srv3_chown_directory_to_current_user: 0 declaration files
- srv3_ensure_directory_owned_by_current_user: 2 declaration files

Part of #10537's per-row adjudication program.

* Correct §4.E: 4 stale foreign-executor rows

Four symbols claimed as 'already on emit' are no longer present in the
corpus. Each is struck through with its deletion commit:

1. ci_selection_control_script — DELETED by 611fd02 (#8283, CI floor cut).
   CASE 1/2: the ci.yml file was deleted and its selection-control script
   dissolved with it. Successor workflow is witnesses.yml via
   gunbc.witness_floor_workflow.

2. gunbc_ci_run_script — DELETED by 489346f (#9252, plan/walk CLI delete).
   CASE 1: the gunbc ci verb was deleted, taking its run script.

3. ci_regen_ensure_rustfmt_path_script — DELETED by 3b431f3 (#8406,
   REGEN ROOT CUT). CASE 1: regen_stage0 root deleted; rustfmt path
   script was zero-consumer machinery.

4. expected_live_deploy_retract_script — DELETED by d409b75 (#7909,
   Phase A release identity refactor). CASE 1: recategorized to
   runtime-present, then dissolved.

All four deletion commits are ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

* Correct §4.I, §4.J, §4.D ownership table: 18+ stale symbols

§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants