Repository navigation
Run merge admission as ordered CI success stages - #7522
Conversation
Follow-up to #7499 (merged as 7cff3d7). These were requested in review but were not in the merged head, so they land as a fresh change on a branch restarted from main rather than stacked on merged history. 1. walk_plan_note contradicted itself. It asserted both that heavy whole-tree stage claims refuse (the current implementation) and that the arm-time validator no longer refuses them (stale text from a prior revision). Because this is the canonical carrier, the generated stage0 projection reproduced the contradiction. Replaced with a CLOSED enumeration of all five refusals — a partial list is how the contradiction arose, so the shape is the fix, not just the wording. Also corrected the dissolve-on. The four profile restrictions name DIFFERENT triggers and do not dissolve together, and the undeclared-profile refusal has none at all — it is the fail-closed floor. The heavy trigger is two ordered steps: split execution-slot from resident-reservation accounting, THEN take a context-lifetime reservation. Naming the lease alone understated it; a lease against today's single `active` counter deadlocks. 2. Rust comments still stated the retracted contract — "members run concurrently", "same governor admission", "same derived cost clamp". All now match the carrier: distinct spawned groups MAY overlap subject to per-lane admission; "same clamp MECHANISM", since ordinary batches supply clamp parameters and stages deliberately pass None. 3. Receipt identity was half closed, and the merged PR body claimed it was closed. Per-stage receipts were attempt-scoped and payload-stamped; the aggregate had identity in neither path nor payload. Both aggregate write sites are now scoped and stamped, including the skip case, which refuses rather than writing unattributably. `entry` is now carried ON ClaimResult rather than recovered by lookup: searching a stage's runnables for a matching function name would reproduce exactly the ambiguity that makes a function name insufficient as a declaration identity. 16 construction sites. The two with no single declaring entry — the unmapped-node sentinel and the discovery aggregate — say so explicitly, because a blank field reads as "unknown" when the truth is "not one entry". plan_site added to both receipt headers. 4. The §7 seed deferral for run_stage/spawn_units/join_units/receipt writers is authored here, at its own carrier, with a SCAFFOLD marker on the Rust. A first draft had it in the downstream fixture branch, which reverses ownership: the debt belongs to the change that added the Rust, and a consumer documenting its parent's deferral lets the parent land without one. Verification state, stated exactly: - The four #[cfg(test)] sites missing `entry` were found by running the suite UNFILTERED. `cargo build` does not compile test targets, so every "build clean" check in this arc was structurally incapable of catching them, and a grep filter then rendered the compile error as an empty section rather than as failure. Both gates are corrected: the chain now runs `cargo test --no-run` and pipes the suite through `tail`, not grep. - Test-binary compile, regen, fmt, and suite were green on the pre-rebase tree. The same gate is re-running on this rebased base and had not finished when this was committed. If it reds, that is a defect in this commit, not a flake, and the next commit fixes it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
…locker 6). Harvest ordinary-floor materialization before on_success_stages; write a second receipt under target/floor-attempt-<attempt_id>/ after stage_memo drops, with attempt_id= in the payload and the same keyed/unkeyed/memo fields. No post-harvest reset — the ordinary take drains the accumulator atomically. Co-authored-by: Cursor <cursoragent@cursor.com>
…eview 45660). Heavy-whole-tree-resolve still refuses at arm time (memo lane, unadmitted); retract the note's claim that the validator dropped that refusal. Update spawn_units and run_walk comments to match the weaker overlap contract. Co-authored-by: Cursor <cursoragent@cursor.com>
… CI. Each control is proven by execution via claim_executor recipes in plan.dag; the integration tests remain for local/operator runs (~7m each due to the naming-hygiene walk) without blocking every PR build. Co-authored-by: Cursor <cursoragent@cursor.com>
…cess. Co-authored-by: Cursor <cursoragent@cursor.com>
These Wet production-path controls are driven only via plan.dag claim_executor recipes; as hermetic discovery witnesses they fail with missing mock_response or BY-DESIGN reds when the PR touches their closure. Mirror floor_skip's dir-grain FixtureExplicitRoster exclusion.
The branch carried a std_realization_schedule.rs that did not match its own .dag source: the carrier has walk_plan_run_stage_claim_executor_seed_deferral and the corrected refusal enumeration, the seed had neither (611 lines vs the 620 a fresh self-compile produces). `regen_stage0 --emit-fresh --verify` now reports regen_divergence_count=0. Cause, stated correctly after an initial misattribution: commit 242be6b carried only the two authored files. Replaying the blocker fixes onto the rebased main used a two-file patch by design — the seed had to be regenerated against the new base rather than carried across — and it was then committed before that regeneration ran. An earlier version of THIS message blamed the CI auto-heal commit (44393e0) that happened to sit in between, claiming it had pushed a seed contradicting its own tree. That was false. Auto-heal changed exactly one file, docs/plans/fail-closed-lockdown.md, and std_realization_schedule.rs is not in its roster at all — it is a regen_stage0 output, a different artifact family. The observation that regen re-modifies the file at 44393e0 was correct; the inference that heal had written it was not, and the discriminating check (does that commit touch the file?) had not been run before the claim was made. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N7LfCpidMuDjV3FxYUHv1K
Rebases blocker-6 onto the run_stage receipt-identity repair. Success materialization receipt now carries plan_site= alongside attempt_id=, matching other attempt-scoped on-success evidence. Ordinary harvest remains the sole accumulator boundary (no post-harvest reset). Co-authored-by: Cursor <cursoragent@cursor.com>
* WIP: P1 cardinality kernel * Complete floor naming authority move * Import moved floor tokenizer helper * chore: regenerate drifted generated artifacts (ci auto-heal) * Census floor naming CLI adapter * chore: regenerate drifted generated artifacts (ci auto-heal) --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Supply GUNBC_WALK_ATTEMPT_ID in the integration harness; route barrier, cleanup, and poison claims through one path authority in common.dag. Capture stdout and stderr separately (PASS/FAIL on stdout, progress on stderr). Tighten panic and receipt-refusal oracles. Remove the run_stage §7 deferral row and SCAFFOLD marker — owned by #7518, not the fixture PR. Co-authored-by: Cursor <cursoragent@cursor.com>
…n-791 # Conflicts: # src/v1/stage0/src/bin/claim_executor.rs
|
Cross-PR semantic check for #7531: #7531 inserts the additive |
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
…staging context's fetch (review 47488) The heal job flagged .github/workflows/ci.yml drifted after the main merge — workflow files are author-commit-required, so the main_wet regeneration lands here (in-executor admission shape: shell stamp step deleted, wrapper 95m). merge_admission_current_context.dag's FetchNoTags call predated this PR's stall_deadline_seconds required input (cursor review 47488) — it now imports and passes the same merge_admission_fetch_stall_deadline_seconds authority the walk uses (single authority, no second constant). Entry compiles clean by execution (gunbc compile --target dag, exit 0). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The Bool was threaded through floor_nodes / floor_data_dependencies / floor_dependencies_with / floor_schedule_via_runner_for / floor_schedule_for_with_capture, but no body ever read it — a parallel representation of a decision the code does not make (the admission capture actually rides WalkPlan.pre_walk_execution, not the schedule graph). The parameter and the _with_capture wrapper delete; floor_schedule_for calls the runner directly and gunbc_ci_floor_schedule_inner collapses onto it. Affected witnesses green by execution (pr_native_batch pair, disjoint-budget pin, ci_workflow_witness_holds). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…, named walk-overhead budget term, seed-deferral extension 1. capture_tested_subject no longer collapses seven failure causes to bare false: the core returns TestedSubjectCapture with a typed refusal coproduct, and the Bool claim projection durably writes the labeled cause to target/merge-admission-capture-refusal.txt (the population-budget-refusal pattern) before returning false; run_pre_walk_execution reads the wire into its located PRE-WALK-REFUSED line, with wire-absent reported as its own state. 2. The hex-length family guess moves to its single authority: extdeps.git.object_store git_object_id_from_untagged_hex decodes git's own untagged plumbing output (40/64 canonical widths, refusing others); the capture tool and merge_admission_walk both consume it and the per-consumer re-guess deletes. 3. The wrapper budget names the wall outside both populations: gunbc_ci_walk_overhead_allowance_minutes (5m) joins the sum, wrapper = 65m, so a slow pre-walk or finalization cannot silently eat the ordinary allowance; witness pins the three-term sum, ci.yml regenerated. 4. walk_plan_run_stage_claim_executor_seed_deferral extended to name the pre-walk parser, budget watchdogs, refusal writer, and memory snapshots as the same seed debt on the same dissolution trigger. regen divergence 0; ci_workflow and disjoint-budget witnesses green; fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
review 47523 examined the intermediate autocommit head (11396a1), which carried the ci_spec three-term wrapper (65m) with a not-yet-regenerated ci.yml — exactly the drift it describes. The current head a3c41e2 contains the main_wet regeneration: floor step timeout-minutes is 65 and the ci job backstop is 100. On the backstop magnitude: the review's own term list (10+5+65+5+5+5+5) sums to 100, not 105, and that is what the model emits; ci_workflow_witness_holds (backstop == exact step-sum + prelude, wrapper == three-term sum) is green by execution on this head, and the drift gate compares ci.yml byte-identically to the same authority that produced it. No further change should be needed for this finding. — sent from eager-boar-610 |
…review 47528) The note said the two on-success claims take spawned lanes; they route through population_unit_lane to the main thread, and the executor's population_unit_lane plus its tests are the placement authority. Doc-only. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
On review 47542's four non-blocking findings, dispositions rather than silence: (1) when write_capture_refusal_wire itself refuses, no channel to the parent remains (the claim result is a bare Bool), so child-crashed vs wire-write-refused are indistinguishable from the parent by construction — the parent's wire-absent wording will be widened to name both states in the next substantive commit rather than re-staling approvals over one diagnostic string. (2) The budget watchdog's hard exit tears concurrent writers the same way the outer workflow timeout always has; atomic temp+rename receipt writes are a real hardening item but separate work. (3) refresh_current_target_and_gate's bare-false arms are the documented staging window — the typed-refusal treatment lands with the merge_freshness_verdict_is_consumed_to_block flip, which is the same commit that makes those arms load-bearing. (4) gunbc_ci_walk_overhead_allowance_minutes is a declared envelope: the direction is receipted, and the magnitude gets its measurement from the pre-walk/finalization receipts the step itself emits once it runs on the fleet. — sent from eager-boar-610 |
… the stage-failure line (CI run 30764945450) The floor redded at on-success stage 2 with refresh_current_target_and_gate returning bare Bool(false) — review 47542 finding 3 made blocking: seven failure causes conflated, the red undiagnosable from the log. Same repair shape as the pre-walk capture: merge_target_refresh returns a typed sum (MergeTargetRefreshRefusal — fetch-refused carrying the operation's own stderr, attempt-identity-absent, subject/receipt wire missing, target-tree observation refused with its cause, oid unparseable, verdict-denied with the verdict label), and the Bool claim projection durably writes the labeled cause to target/merge-admission-refresh-refusal.txt before returning false. claim_executor's stage-failure line now reads that wire, so the next run names its own cause. Also widens the pre-walk wire-absent message per review 47542 finding 1 (child-crashed vs wire-write-refused are indistinguishable from the parent by construction, and the message now says so). Walk entry compiles clean by execution (0 blocking); fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…in_rel_path, and declare the ratchet-off widening as a Scaffold Disposition (review 47596)
Finding 1: MERGE_ADMISSION_{CAPTURE,REFRESH}_REFUSAL_WIRE consts in claim_executor.rs
with pairing doc-comments; _seed_pairing notes beside both dag relpath authorities.
Finding 2: merge_admission_capture_transport routes the claim_batch bin path through
gunbc.cli_invoke release_bin_rel_path instead of minting the string.
Finding 3: merge_admission_refresh_ratchet_off_widening_{note,disposition} — the
ratchet-off else arm is a declared Scaffold bound to the
merge_freshness_verdict_is_consumed_to_block flip, per the fleet-gating shadow-phase
policy; the flip commit deletes the arm and the row together.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Review 47596, finding by finding — findings 1–3 fixed in 0187240; finding 4 is deliberate, rationale below. 1 (wire relpaths hardcoded in Rust): the two seed read sites now go through 2 (minted bin path): 3 (ratchet-off widening arm): landed 4 (detached watchdog — sent from eager-boar-610 |
…re-parse that could never succeed (CI run 30769177034)
The typed refusal wire did its job on the first red it carried:
cause=target-oid-unparseable observed=GitSha1ObjectId { digest: ... } — the
stage-2 arm cast observe_merge_target_tree_hash's already-typed GitObjectId
to String (its record rendering) and re-parsed it as untagged hex, a §3
re-guess of a fact the producer's type already carries. The classifier takes
GitObjectId, so the hash now flows through directly; the unreachable-by-type
RefreshTargetOidUnparseable arm and the object_store import are deleted with
it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Review 47629 addressed in 5c7ba15: — sent from eager-boar-610 |
…a row (review 47638) The interpreter has no cast into a branded scalar; the corpus idiom is a bare-literal data row, the same shape as this PR's merge_admission_fetch_stall_deadline_seconds = 240 which already executed on CI. fetch_pr_head_ref now reads review_fetch_stall_deadline_seconds = 300. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t raise with the capture-subprocess accounting (count stays 2) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…or wire reads at git toplevel, import std.decl_ref explicitly (reviews 47663, 47665) - ci.yml regenerated via generated_artifact_gate main_wet on the merged tree: restores the heal skew-guard's stage0 emitted-Rust exclusions the text merge had dropped (review 47665 finding 2) and clears HealAuthorCommitRequired from run 30774448327. - claim_executor's two refusal-wire reads now anchor on git rev-parse --show-toplevel, matching the .dag writers' git.Inspect.Toplevel() anchor, so a non-root cwd cannot turn a written typed cause into a false wire-absent (review 47663). - merge_admission_walk.dag imports DeclarationRef/WholeDeclaration explicitly from std.decl_ref instead of relying on bare-name resolution (review 47665 finding 1). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…nosis lanes (#7760) * WIP: CI perf * Close CI-cost research arc with harvested production receipt and terminal dispositions. Bank measured walls from main run 30863019228; settle #7522/#7671/#7534 as MEASURED or OPEN-with-trigger; retire stale in-flight/probable claims in five-minute and roadmap authorities. Co-authored-by: Cursor <cursoragent@cursor.com> * chore: regenerate drifted generated artifacts (ci auto-heal) * Address review 47900: Millisecond duration surface and design-thread OOM wording. Public closeout walls use std.measure.Millisecond; design open-thread no longer treats OOM as the warm-hit skip blocker after #7728. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix CI parse panic and DESIGN.md drift after closeout edits. Witness comparison must stay on one line (multiline `>` parsed as Gt); regenerate DESIGN.md open-thread to match design_document after #7728 wording. Co-authored-by: Cursor <cursoragent@cursor.com> * WIP: CI perf * Model the CI-cost closeout as typed walls and settles, not prose strings. Expose unattributed_ci_wall (1902042 ms) with pipeline/CI reconciliation; narrow assembly to compiler_next_measured_target; freeze entry-view until PR2 assigns the remainder. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com>
§4.I — ci_native_cache_root_toolchain_segment_command DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment computation reordered after setup-rust-toolchain; fallback table entry struck through as RESOLVED. §4.J.A — ci_floor_stamp_merge_admission_script All three raw leaves (ci_floor_stamp_ambient_exit_command, ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale. §4.J.B — ci_floor_materialization_receipt_gate_script, ci_floor_resolve_receipt_gate_script DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success stages finalization dissolved both receipt gates. §4.J.C (ci_spec.dag table): - gunbc_ci_floor_only_script DELETED #9252 — CASE 1 - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1 - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1 - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1 - git_fetch_script RENAMED #6833 — CASE 3 (successor: git_fetch_no_tags_shell / git_fetch_prune_shell) §4.J.D (ownership table): - Merge-admission row: all three raw leaves struck #7522 (CLOSED) - CI materialization row: both receipt gates struck #7470 (CLOSED) - CI-spec row: stale symbols struck through individually - Already-routed row: ci_selection_control_script #8283, gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script #8406 (and 11 rustfmt raw leaves) struck through - Runtime terminal row: host_effect_plan_placeholder_effect DELETED #10509 - Deferred srv3 row: srv3_chown_directory_to_current_user struck #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body struck #8583 (ref §4.A) All deletion commits verified as ancestors of origin/main ✅. Part of #10537's per-row adjudication program.
….E, §4.I, §4.J (#10576) * Correct §4.A hygiene-reaper row: CASE 2 — four host_hygiene_reap_*_body symbols deleted by #8583 The §4.A row at L379 described host_hygiene_reaper_script.dag's 4 body symbols as A5-deferred. The file was deleted by ffa16a5 (#8583, Migrate host-hygiene reaper and liveness onto typed observation) and the construction was migrated to typed host_hygiene_reaper_observe.dag / host_hygiene_reaper_remediate.dag / host_hygiene_liveness_observe.dag. No direct successor body names exist — CASE 2 (file deletion upstream) with hybrid CASE 1 (body names dissolved). Verification: - ffa16a5 is ancestor of origin/main ✅ - host_hygiene_reaper_script.dag: D in #8583's diff - zero files define host_hygiene_reap_install_units_body et al. - observe/remediate files present at dag/gunbc/host/ Part of #10537's per-row adjudication program. * Correct §4.D srv3_chown_directory_to_current_user: CASE 4 — renamed AND climbed The row at §4.D L436 listed srv3_chown_directory_to_current_user as A5-deferred (srv3). It was actually renamed AND climbed by 20ad5b3 (#8796): successor is gunbc.host_effect_realize.srv3_ensure_directory_owned_by_current_user. New name has a stronger guarantee (readback-based, not chown exit-status based). This is CASE 4 (rename plus climb) — distinct from CASE 1 (dissolution) because the construction did not disappear; it acquired a better name and a stronger guarantee. Verification: - 20ad5b3 is ancestor of origin/main ✅ - srv3_chown_directory_to_current_user: 0 declaration files - srv3_ensure_directory_owned_by_current_user: 2 declaration files Part of #10537's per-row adjudication program. * Correct §4.E: 4 stale foreign-executor rows Four symbols claimed as 'already on emit' are no longer present in the corpus. Each is struck through with its deletion commit: 1. ci_selection_control_script — DELETED by 611fd02 (#8283, CI floor cut). CASE 1/2: the ci.yml file was deleted and its selection-control script dissolved with it. Successor workflow is witnesses.yml via gunbc.witness_floor_workflow. 2. gunbc_ci_run_script — DELETED by 489346f (#9252, plan/walk CLI delete). CASE 1: the gunbc ci verb was deleted, taking its run script. 3. ci_regen_ensure_rustfmt_path_script — DELETED by 3b431f3 (#8406, REGEN ROOT CUT). CASE 1: regen_stage0 root deleted; rustfmt path script was zero-consumer machinery. 4. expected_live_deploy_retract_script — DELETED by d409b75 (#7909, Phase A release identity refactor). CASE 1: recategorized to runtime-present, then dissolved. All four deletion commits are ancestors of origin/main ✅. Part of #10537's per-row adjudication program. * Correct §4.I, §4.J, §4.D ownership table: 18+ stale symbols §4.I — ci_native_cache_root_toolchain_segment_command DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment computation reordered after setup-rust-toolchain; fallback table entry struck through as RESOLVED. §4.J.A — ci_floor_stamp_merge_admission_script All three raw leaves (ci_floor_stamp_ambient_exit_command, ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale. §4.J.B — ci_floor_materialization_receipt_gate_script, ci_floor_resolve_receipt_gate_script DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success stages finalization dissolved both receipt gates. §4.J.C (ci_spec.dag table): - gunbc_ci_floor_only_script DELETED #9252 — CASE 1 - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1 - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1 - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1 - git_fetch_script RENAMED #6833 — CASE 3 (successor: git_fetch_no_tags_shell / git_fetch_prune_shell) §4.J.D (ownership table): - Merge-admission row: all three raw leaves struck #7522 (CLOSED) - CI materialization row: both receipt gates struck #7470 (CLOSED) - CI-spec row: stale symbols struck through individually - Already-routed row: ci_selection_control_script #8283, gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script #8406 (and 11 rustfmt raw leaves) struck through - Runtime terminal row: host_effect_plan_placeholder_effect DELETED #10509 - Deferred srv3 row: srv3_chown_directory_to_current_user struck #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body struck #8583 (ref §4.A) All deletion commits verified as ancestors of origin/main ✅. Part of #10537's per-row adjudication program. --------- Co-authored-by: Brian Searls <briansearls1@gmail.com>
Summary
Populate the live CI
WalkPlanon-success roster with two ordered singleton stages: stamp the captured checkout subject, then fresh-fetch and gate the current merge target. The old cold stamp/gate shell-emitter web is deleted atomically, and the live schedule lens consumes the same roster authority so divergence is red from the first populated commit.This is a topology/cost migration. It preserves
GatingComputedDeferred: the PR makes the fresh observation and gate warm and ordered, but does not activate merge-freshness enforcement or describe that policy arc as complete.Capture placement and authority
The original in-process ordinary capture falsified its
Negligibledeclaration in production. Even after de-fusing the claim to a 54-module closure, run 30702499883 showed one spawned-worker arena surviving thread join: capture passed, discovery handed off at 7.4 GiB versus the 5.2–6.1 GiB controls, swap grew to about 32 GiB, and discovery remained at entry 0 until the 60-minute wrapper expired.Per the Dispatch A→C ruling on 2026-08-01, capture is now a modeled
TypedClaimSubprocessinWalkPlan.pre_walk_execution.claim_executorresolves the narrow transport entry and the transport launches the already-builtclaim_batchchild throughgunbc.WitnessBin.Run; no raw shell string and no ad-hocCommandis introduced. Child failure is a typed, located pre-walk refusal and blocks batch 1. The child address space dies before the ordinary floor, structurally reclaiming its evaluator arena.WalkAttemptId,TestedSubject, and the exact capture path/wire helpers have one home ingunbc.merge_admission_subject.gunbc.merge_admissionimports that carrier and retains classification/admission policy. Capture, stamp, and gate consume the same subject authority; the carrier never imports the domain. The tested-subject writer is unchanged, and the literal five-line byte-lock witness remains green.The two success stages intentionally retain their disk-visible barrier. They use the same entry but do not claim cross-stage resolved-context memo reuse. Accounting therefore allows up to two stage resolves and records the actual count, wall, and memory in the attempt-scoped receipts.
The first production run to reach this population exposed a separate placement defect: non-heavy stage units were sent to a worker thread even though
process_shared_indexis thread-local and warmed only on the executor main thread. That rebuilt a cold index inside the supposedly warm stage path. Per the Dispatch A→C ruling on 2026-08-01, on-success units that would otherwise spawn now execute through the existingrun_batch_uniton the main thread. They still acquire the same governorAdmittedSlot; ordinary placement is unchanged.WalkPlanalready permits withdrawing sibling overlap, and the live roster consists of singleton stages, so the schedule lens remains unchanged and green.The same run also showed that the postcondition watchdog could terminate during a silent resolve without leaving an observable stage mark. The modeled
WalkPopulationBudgetRefusalnow carries population, plan site, one-based stage/batch index, exact active unit, measured elapsed wall, and the budget that fired. The watchdog durably writes that receipt and flushes the located stderr line before exiting. A child-process discriminator proves both artifacts survive the forced exit.Before receipts
ddbc5fd6aa; stamp 94.26s, gate 102.87s, combined 197.13s.resolves_total=2,resolve_ms_total=64486). Moving capture into the typed child returns the ordinary in-process declaration to 1; the child resolve remains visible in the pre-walk receipt rather than being counted as an ordinary resolve.660436107; capture passed, discovery handoff was 7.4 GiB at entry 0/845, memory rose to 14.9 GiB plus swap, swap reached about 32 GiB, and the 60-minute wrapper expired with discovery still at entry 0.Executed validation on the typed-child head
ci_floor_plan_witnesses— pass, including the exact typed pre-walk row and the live success-stage roster lens.cargo check -p v1-compiler --bin claim_executor— pass.regen_stage0 --verify—regen_divergence_count=0.GUNBC_WALK_ATTEMPT_ID=quick-heron-typed-capture-control: typed capture child passed, wrote the unchanged five-line subject wire, and returned a located receipt withwall_ms=100088,memory_current_before=3241562112,memory_current_after=3177357312,swap_after=144097280; ordinary batch 1 began only afterward. This is placement/order evidence, not the required fleet performance receipt.4607b2d71proved the placement and resource side before an unrelated ordinary-floor witness import failed: capturewall_ms=102897,memory_current_before=3465207808,memory_current_after=3469225984,memory_peak_after=5825937408,swap_after=0,high_events_after=0. Discovery then advanced at a stable 6.4 GiB and zero swap from entry 54/847 at receipt-minute 12 to entry 524 at minute 19. The staleci_spec_witnessimport failed batch 3, and construction correctly reported0 of 2on-success stages run with0stage resolves. The import now consumesgunbc.merge_admission_subject; its exact perturbation witness passes on the merged tree.bf68ffb1dindependently reproduced the resource result: capturewall_ms=97087,memory_current_before=3469467648,memory_current_after=3475148800,memory_peak_after=5828857856,swap_after=0,high_events_after=0; discovery advanced from entry 50/848 at receipt-minute 12 to 832 at minute 25, held 6.4 GiB/zero swap throughout, and drained all 848 groups withpeak_rss=7157161984. The floor then hit exactly the two operator-declared known-main primitive-surface witness reds (the_surface_is_almost_entirely_derived,the_three_denominators_are_derived_and_distinct), owned and subsequently fixed by the separate repair lane. Green-only construction correctly recorded0 of 2stages and0stage resolves.d682f83dintegrated that main repair and completed the ordinary floor green: typed capturewall_ms=91065, current memory3462320128 → 3463213056, peak5817024512, zero swap/high events; discovery drained all 848 groups withpeak_rss=7162372096. The first on-success window then emitted no stage receipt for 7m22s and raised the cgroup span peak to9390518272before failure. Local production-shape reproduction resolvedtools.merge_admission_walkas a 176-module closure in 32.616s only after paying a fresh index load dominated by 51.3s in the bare-edge index. Code inspection established why: the stage worker received a fresh thread-local index instead of the main thread's warmed one. The local timings establish the cold-index mechanism; the remainder of the fleet multiplier is unattributed and is not claimed as index wall.regen_stage0 --verifyreportsregen_divergence_count=0.population_budget_watchdog_refuses_and_writes_located_receipt— pass: a forced watchdog exit leaves the flushed located line and durable receipt with exact index/unit/elapsed/budget.on_success_spawned_claims_move_to_warm_main_thread_only— pass in both directions: the same negligible claim remainsSpawnedfor the ordinary population and becomesMainThreadonly forOnSuccessStage.gunbc_ci_walk_plan_schedule_lens_holdsand its synthetic red controls — pass unmodified after the placement change.cargo fmt --all --checkandgit diff --check— pass.Remaining draft bar
1432d825e0through the now-main-thread success stages. Record both stage closure/profile receipts, actual resolves, memory, and wall; make the observed profile honest if it differs from the authored declaration.197.13stwo-cold-process baseline versus new102.897s capture subprocess + warm stamp stage + warm refresh/gate stage. No three-minute claim is made absent measured stage walls.