Skip to content

Bundle selected logic witnesses into one native process - #7599

Merged
briansrls merged 33 commits into
mainfrom
session/cool-wren-804
Aug 2, 2026
Merged

briansrls merged 33 commits into
mainfrom
session/cool-wren-804

Conversation

@briansrls

@briansrls briansrls commented Aug 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Model SelectedWitnessPlan, content-addressed bundle identity, stable shard policy, counted interpreter-frontier rows, typed receipts, and fail-closed admission in .dag.
  • Realize the selected meet/join/complement population as one generated native artifact whose main makes three direct calls in one process.
  • Keep the interpreter as the cutover oracle: admission requires member verdict equivalence and live planted-RED evidence; stale compiler or plan identity, roster drift, missing native realization, warm-artifact miss, divergence, and invalid process counts refuse explicitly.

This is the first executable selected-entry slice. It does not change floor scheduling; the production selector can consume this execution kind in the follow-up cutover.

Bundle receipts

  • Complete 20-witness entry: 20/20 passed. Correct and wrong-body artifacts each logged compile_skipped=false followed by compile_skipped=true across two host processes.
  • Correct bundle cold plus warm host witness: 993 ms. Wrong-body cold plus warm RED: 977 ms.
  • Already-built native bundle, direct execution of all three calls: 3 ms wall. Existing warm cargo run --quiet development transport: 457 ms with zero compile. Three interpreter controls: 20 ms total.
  • Latest-head critical rerun after current-main integration: 5/5 passed, including cold/warm reuse, member-drift refusal, interpreter green, primary rows, and discriminating planted RED.

Current-main integration receipt

  • Integrated the REST repair series through main dbc87b21e0; latest main b951e724c2 adds unrelated compiler/roadmap work, and GitHub reports the branch mergeable with no conflict.
  • Adapted bundle identities to the grounded Fnv1a64Structural ContentHash family and kept exact member equality structural rather than hash-equality-based.
  • Rebuilt claim_batch after the seed change and executed REST replay 9/9.
  • RestAuthenticated.digest and RestBoundOperationInvocation.input_digest now share the modeled Fnv1a64Structural record mint. The authenticated mint seam is execution-proven by rest_authenticated_identity_matches_dag_constructed_value: seed identity equals the .dag-authored FNV identity, with a secret-inequality control. The end-to-end authenticated replay path remains explicitly deferred in rest_authenticated_digest_witness_note until the service-input limb migrates from host value_hash to the modeled FNV primitives.
  • The exact formerly-red extdeps_scope_placement_gate_passes witness now passes locally in its wet profile after consuming main's OCI enrollment repair.

Test plan

  • CTRL_BUILD_MODE=local cargo build -p v1-compiler --bin claim_batch
  • claim_batch over all 20 functions in native_selected_witness_bundle_test.dag with --claim-run --wet — 20/20 passed.
  • Latest-head focused native bundle rerun — 5/5 passed.
  • Latest-head rest_exchange_replay_test.dag rerun — 9/9 passed.
  • cargo test -p v1-compiler-tests rest_authenticated_identity_matches_dag_constructed_value -- --nocapture — 1/1 passed.
  • claim_batch --wet --source-root dag --source-root src/v2 --entry dag/tools/floor_effect_gate_witness.dag --function extdeps_scope_placement_gate_passes — passed.
  • cargo fmt --all -- --check
  • git diff --check origin/main...HEAD
  • Exact-head CI run 30731615199 is green: build 3m39s, heal 2m13s, regen 9m33s, and full floor plus merge admission 43m08s.

Primitive-surface authorized delta

The modeled observed_monotonic_nanos realization adds exactly one derived interpreter free-call row, one distinct arm identity, and one authored spelling. Executed census output reads derived=184, distinct identities=175, and authored spellings=162, versus the prior 183/174/161. observed_monotonic_nanos_arm_is_one_derived_free_call attributes the complete +1/+1/+1 delta to free_call.observed_monotonic_nanos; no second arm is absorbed into the expected bump.

Worker attestation

  • The title and body describe the change and its boundary.
  • Tests and executed receipts are listed above.
  • This closes an internal dashboard work item, not a GitHub issue.
  • No secrets, credentials, or large binaries are staged.

@gunbai-bot gunbai-bot Bot changed the title Dispatch L: native-selected-witness-bundle - realize the selected production witness set as one content-addressed native bundle (or small stable shard set): SelectedWitnessPlan -> native bundle -> one process -> direct function calls -> typed receipt; interpreter stays as equivalence oracle during c Bundle selected logic witnesses into one native process Aug 1, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 1, 2026 16:51
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46399 in 6fabafc: NativeWitnessBundleExecutionReceipt now carries both walls as NanosecondDuration (Measure<Time, Nano, Nat>), with raw Int conversion confined to the monotonic observation boundary. Focused typed-admission, correct cold/warm equivalence, and wrong-body divergence witnesses all pass.

@cursor

cursor Bot commented Aug 1, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46457 in 4c27584:

  • execution admission now takes the selected plan and current compiler identity, refuses empty native plans, stale compilers, plan drift, frontier-count drift, and any incomplete/reordered/extra executed-member roster;
  • verdict comparison now uses the canonical equality surface instead of a hand-written coproduct predicate;
  • the monotonic observation seed arm now has an explicit v1-hand-queue-drain deferral tied to ROADMAP’s zero-hand-Rust row and v1_deletion_plan authority.

The expanded executable bundle suite passes 25/25 locally, including the new fail-closed refusal controls; formatting and diff checks are clean. — sent from cool-wren-804

gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
Settle native-at-small-scale (#7599 BANKED), register the six-step
dependency sequence and staged expectations A/B/C, and add the
warm-merge → native-bundle sequence edge.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Addressed review 46478 in 2f9e780:

  • the bundle’s single host-only fn main/stdout wrapper now carries an explicit bounded SCAFFOLD disposition, named feature:rust-target-host-entrypoint-grammar, and a concrete dissolve-on deletion trigger into the canonical Rust TargetModel grammar-row inverse;
  • native and interpreted wall observations now become NanosecondDuration at their observation boundaries and remain typed through receipt construction.

Branch-local executable validation passed for both the correct cold/warm equivalence witness and the planted wrong-body RED witness; each resolved the 119-source closure, logged cold then compile_skipped=true, and returned true. Current-head CI build is also green; regen/heal are running. — sent from cool-wren-804

gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
…ceipts.

Executed 25/25 witnesses at head 2f9e780; timing ratio figures are
claimed-not-verified (PR body) until merge + fleet rerun. Regenerated DESIGN.md.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

CI failure at 2f9e780 was three witnesses. The two primitive-surface failures were the known main regression and are repaired by #7614, now merged into this branch. The third was inert_carrier_no_unrostered_or_stale: the live lens identified CompileDiagnosticCensus, a model-first carrier from #7575 whose current guarantee-probe consumer is witness-only. Commit 0085f7e adds the counted frontier row (dissolving when the production probe-admission reader lands) and explicit imports needed for a scoped check. The exact failing witness now executes as true; git diff --check and formatting are clean. — sent from cool-wren-804

@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

Review 46547’s temporary debug_current_inert_carrier_names test was removed in c1478e7 before the current head. The current tree contains neither the test nor its eprintln!; only the resulting typed frontier fix remains. — sent from cool-wren-804

gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
Settle native-at-small-scale (#7599 BANKED), register the six-step
dependency sequence and staged expectations A/B/C, and add the
warm-merge → native-bundle sequence edge.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 1, 2026
…ceipts.

Executed 25/25 witnesses at head 2f9e780; timing ratio figures are
claimed-not-verified (PR body) until merge + fleet rerun. Regenerated DESIGN.md.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 1, 2026

Copy link
Copy Markdown
Contributor

CI run 30714914288 failed only the primitive-surface exact-count receipt. Executed census output on the branch reads 184 derived rows, 175 distinct identities, and 162 authored spellings: exactly +1/+1/+1 from the prior 183/174/161. Commits 10adba0 and 29f4a43 update the exact receipt and add observed_monotonic_nanos_arm_is_one_derived_free_call, which proves the sole delta is free_call.observed_monotonic_nanos on DerivedFromDispatch through eval_builtin_inner. Both formerly failing witnesses and the new attribution witness pass locally; formatting and diff checks are clean. Fresh CI run 30717947188 is queued. — sent from cool-wren-804

briansrls added a commit that referenced this pull request Aug 1, 2026
…roadmap authority - product boundary: an ordinary source edit reaches a required CI verdict in five minutes without recomputing any semantic fact whose inputs did not change; six sub-lanes (warm-merge-admission, native-selected-wit (#7597)

* WIP: Dispatch K: register the five-minute-ci-gate program boundary in the roa

* Fix five-minute-ci-gate roadmap authority per dispatch K spec.

Correct six sub-lanes, close entry-graph-union as sibling disposition,
and restore required red_control on all ticket fields so main_wet and
the generated-artifact drift gate can execute.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Incorporate operator sequence revision for five-minute-ci-gate (#7597).

Settle native-at-small-scale (#7599 BANKED), register the six-step
dependency sequence and staged expectations A/B/C, and add the
warm-merge → native-bundle sequence edge.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* WIP: Dispatch K: register the five-minute-ci-gate program boundary in the roa

* WIP: Dispatch K: register the five-minute-ci-gate program boundary in the roa

* Correct #7599 rung honesty: in-flight not BANKED, verified witness receipts.

Executed 25/25 witnesses at head 2f9e780; timing ratio figures are
claimed-not-verified (PR body) until merge + fleet rerun. Regenerated DESIGN.md.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rebase on main and regenerate ROADMAP.md after conflict resolution.

Keeps #7533 entry-graph-union adjudication from main; five-minute-ci-gate
registration preserved from branch.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Brian Searls added 2 commits August 1, 2026 21:53
# Conflicts:
#	dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag
@briansrls
briansrls merged commit 1ebff27 into main Aug 2, 2026
5 checks passed
@briansrls
briansrls deleted the session/cool-wren-804 branch August 2, 2026 14:14
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Documents the #7599 Time rekey and #7555 Empty enrollment that
unblocked heal/regen naming-hygiene after the main rebase.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 2, 2026
…henticated_digest_witness_note (#7672)

PR #7599 absorbed #7648's REST content from a pre-correction head: the
carriers, mint, and pin landed intact, but the note regressed to the
version claiming 'the mint seam is mechanically prevented by the executed
pin'. Commit 85a5ac4 on #7648 had retracted exactly that sentence,
verified against ci.yml and gunbc.ci_layer_roots witness_layer_roots: CI's
only contact with v1-compiler-tests is a compile gate (no test execution)
and floor discovery excludes src/v1/tests, so the pin executes in no
admission path. DESIGN 4b defines mechanically preventable as a mechanism
that reliably exposes AND blocks; reporting the class at that rung is rung
inflation, which 4b names worse than sitting low because an inflated class
never ranks for climbing.

The absorption also dropped the review 47065 hand-Rust receipt: the
v1-hand-queue-drain lane (dag/gunbc/v1_deletion_plan.dag) owns the interim
seed bridge in rest_auth_identity_value, fnv1a64_structural_value, and
rest_authenticated_identity_for_witness, with deletion of those three
symbols while the discriminating witness stays enrolled as the checkable
dissolution receipt; and the NOT-NEW-DEBT pointer to
content_hash_cross_family_eq_v1_seed_bridge_note recording that the whole
seed-bridge control family shares the enrollment gap.

One data-row string edit, spliced verbatim from the final #7648 head
45e5875 whose floor ran green on this exact text. Regression: 9/9
rest_exchange_replay_test witnesses green by execution against the edit.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Documents the #7599 Time rekey and #7555 Empty enrollment that
unblocked heal/regen naming-hygiene after the main rebase.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
… → merged, banking trigger fired

The program note (gunbc.roadmap_authority five_minute_ci_gate_program_note) and
the DESIGN row still described #7599 as an in-flight executing slice with its
banking trigger pending. #7599 merged 2026-08-02 (merge 1ebff27), so the
trigger those rows named has fired. Both sentences now state the dated merged
fact; the registered operator sequence and the first_slice record of what the
registration slice registered are untouched. DESIGN.md regenerated same-commit
via the generated-artifact gate (main_wet), executed green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…slice): bounded production witness population -> content-addressed native bundle/shards on the real CI floor, full transition receipt (#7671)

* WIP: Production selector cutover into the native execution kind (post-#7599 s

* WIP: Production selector cutover into the native execution kind (post-#7599 s

* Model transition receipt memory as ByteSize

* Refuse fallback without planted red equivalence

* WIP: Production selector cutover into the native execution kind (post-#7599 s

* Keep native transition counts verdict-honest

* Merge main into the cutover slice: adopt RunnableBatchClamp typed-unit rows (+ index-5 native row), compose ScopedWitnessBatch beside NativeBundle

Three conflicts, all compositions of independent additions:
- ci_spec.dag: main (#7569) re-modeled the clamp table as RunnableBatchClamp
  with typed second/millisecond units; the native batch's companion row (125s,
  operator-ruled basis note kept) is re-expressed in that shape.
- claim_executor.rs runnable fold: keep the guarded Discovery + NativeBundle
  partition, add main's ScopedWitnessBatch -> ScopedDiscovery arm beside it.
- claim_executor.rs function census arm: Discovery | ScopedDiscovery |
  NativeBundle all non-function units in one arm.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Integrate main into the cutover slice: native-bundle wire-codec arms, re-pin the floor-append witness on the base plan

Main's #7569 landed a WitnessKind wire codec (scoped_witness_kind_label/_from_label)
whose exhaustive matches would not compile against the new NativeBundleWitnessKind
variant — the closed-coproduct wall working as designed. Fixed in the dag authority
(native-bundle arms in both directions) and regenerated stage0 (divergence 0).

witness_floor_appends_one_selected_native_batch red on the merged tree for two
reasons: gunbc_ci_floor_realization_plan().schedule is now defined AS
gunbc_ci_floor_ordinary_batches() (x == x + 1 unsatisfiable), and ordinary batches
additionally append one batch per scoped_witness_batches row. Re-pinned against the
base plan gunbc_ci_floor_realization_plan_for(spec: gunbc_ci_spec) plus the scoped
count, keeping +1-native the discriminated quantity. Both enrollment witnesses green
by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Repair the stale stage0 crate partition: regenerate with a freshly built seed (review 47484)

The previous head's regen ran with a stale regen_stage0 binary and committed a
half-completed partition — a new v1-stage0-extdeps-base crate holding three
modules while extdeps_units_*/std_occurrence_identity/std_trait_derive_shape/
v1_compiler_infer_occurrence_binding were dropped from their crates without
relocation, breaking the partition workspace members (cursor review 47484) and
redding CI's regen self-host gate ('Stage0 split crate boundary files are
stale'). Regenerated in the correct order (build seed from committed tree ->
regen -> rebuild -> --verify divergence 0): the partition reverts to the
derived state, stage0_extdeps_base leaves the workspace and is deleted.
cargo check --workspace green; fmt clean.

Also softens the native_selected_bundle_process carrier note per review 47480:
the planted-red twin and oracle names are seed convention today, not carrier
fields — declared honestly with the existing dissolve-on.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: Dispatch A->C

* Count the enrolled native batch in the enrolled-set preservation witness

witness_floor_schedule_preserves_enrolled_set redded on CI (run 30762089274):
gunbc_ci_floor_ordinary_batches appends the selected native batch when the
frontier enrolls it, but gunbc_ci_floor_enrolled_runnable_labels_for still
projected only gates + corpus + scoped batches, so the length check failed by
exactly the appended batch. The enrolled side now appends the same runnable's
label under the same gunbc_pr_native_batch_enrolled() condition the schedule
uses — one enrollment authority read by both sides. ci_floor_plan_witnesses,
ci_corpus_discovery_flip_witnesses, and the native pair green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Fallback arms on native outage, never divergence; transport causes reach the wire (CI receipt run 30764923923)

The floor redded on srv4-03 with all 3 selected members unavailable and
verdict refused:equivalence_or_planted_red — review 47508's advisory made
real: fallback required the planted RED's NATIVE run to succeed, which in a
native-toolchain outage it cannot, so the counted-fallback arm was unreachable
in exactly the outage it was modeled for (NativeProductionTransitionFallback
{ cause: NativeUnavailableCause }), and a toolchain outage became a hard
floor red with its cause dropped on the floor.

Split the folded bit: DIVERGENCE (native ran, produced undeclared output)
still hard-refuses — an auto-pick would mask it, per the bundle note's
'divergence is a hard refusal, never an auto-pick'. OUTAGE (transport refused
or process failed) arms the counted fallback when the interpreter oracle is
green AND the planted RED's ORACLE discriminates — the discriminating-RED
evidence for the thing actually consumed under fallback. Acceptance keeps the
full native bar including planted-red native equivalence. New verdict string
refused:native_divergence separates the classes; the cold/warm/planted
transport causes now print to stderr and ride the FAIL/fallback detail (the
TSV receipt shape is unchanged — it is a parsed contract). Seed tests cover
outage-fallback, no-discrimination-no-fallback, divergence-never-fallback,
and the acceptance bar.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Consciously raise ci_floor_declared_resolve_count 1 -> 2: the enrolled native batch is an escaping entry class (Receipt 9, CI run 30767841790)

The floor gate worked as designed: run 30767841790's batch 6 PASSED via the
counted outage fallback (transport causes located on the wire), and the sole
red was FLOOR-FINALIZATION-REFUSED resolve count 2 != declared 1 —
gunbc_pr_native_batch is a RunnableSingleClaim on its own entry file, paying
its own cold closure resolve per the empirical law in
ci_floor_resolve_receipt_note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 3, 2026
… → merged (#7710)

* WIP: pure business 8/1

* Regenerate DESIGN.md from the re-anchored five-minute row

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regenerate DESIGN.md after merge (auto-sweep committed the conflicted file)

The mid-merge auto-commit captured DESIGN.md with conflict markers.
DESIGN.md is a registered generated artifact — regeneration from the
resolved design_document.dag via main_wet is the authoritative merge
resolution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Reword program step 6 off the superseded five-minute objective (review 47439)

Step 6 still called five minutes 'the objective'; it now names the
bare-minimum-computation contract as the objective, with five minutes as
the Stage C distress checkpoint bound only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: pure business 8/1

* Refresh the #7599 observation in the five-minute-gate rows: in-flight → merged, banking trigger fired

The program note (gunbc.roadmap_authority five_minute_ci_gate_program_note) and
the DESIGN row still described #7599 as an in-flight executing slice with its
banking trigger pending. #7599 merged 2026-08-02 (merge 1ebff27), so the
trigger those rows named has fired. Both sentences now state the dated merged
fact; the registered operator sequence and the first_slice record of what the
registration slice registered are untouched. DESIGN.md regenerated same-commit
via the generated-artifact gate (main_wet), executed green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 3, 2026
… generator)

DESIGN.md is a generated projection of dag/gunbc/design_document.dag, and
git merged the two files INDEPENDENTLY: the .dag authority auto-merged to
main's newer version while the .md kept this branch's older text for the
five-minute-CI-gate row. No conflict markers, no complaint — the result
looked finished and was not a fixed point of its own generator.

The stale text asserted the native-execution slice was "settled at branch
head 2f9e780 (in-flight executing slice ... banking trigger = #7599
merge)". The generator emits "settled and banked - merged 2026-08-02
(merge 1ebff27; ... at pre-merge head 2f9e780)". So the canonical
design authority would have shipped claiming a load-bearing lane was
still in flight after it had merged and banked — a stale status claim in
the document every other row cites.

Regenerated via tools.generated_artifact_gate main_wet rather than
hand-patched, because the generator is the authority and hand-editing a
generated projection is what produced the divergence class in the first
place. Only DESIGN.md moved; the other 14 committed artifacts were
already fixed points.

By execution, on the merged tree with a seed built from it:
  FAIL witness_committed_is_fixed_point          (before regen)
  PASS witness_committed_fixed_point_red_control (before regen — oracle
       proven discriminating, so the FAIL was real divergence and not a
       merge-broken check)
  PASS witness_committed_is_fixed_point          (after regen)
  PASS witness_committed_fixed_point_red_control
  PASS witness_per_artifact_red_receipts
  PASS witness_all_known_committed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…7718)

* WIP: pure business 8/1

* Regenerate DESIGN.md from the re-anchored five-minute row

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regenerate DESIGN.md after merge (auto-sweep committed the conflicted file)

The mid-merge auto-commit captured DESIGN.md with conflict markers.
DESIGN.md is a registered generated artifact — regeneration from the
resolved design_document.dag via main_wet is the authoritative merge
resolution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Reword program step 6 off the superseded five-minute objective (review 47439)

Step 6 still called five minutes 'the objective'; it now names the
bare-minimum-computation contract as the objective, with five minutes as
the Stage C distress checkpoint bound only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: pure business 8/1

* Refresh the #7599 observation in the five-minute-gate rows: in-flight → merged, banking trigger fired

The program note (gunbc.roadmap_authority five_minute_ci_gate_program_note) and
the DESIGN row still described #7599 as an in-flight executing slice with its
banking trigger pending. #7599 merged 2026-08-02 (merge 1ebff27), so the
trigger those rows named has fired. Both sentences now state the dated merged
fact; the registered operator sequence and the first_slice record of what the
registration slice registered are untouched. DESIGN.md regenerated same-commit
via the generated-artifact gate (main_wet), executed green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: pure business 8/1

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Record the native-at-small-scale status once, in one typed receipt

Operator ruling on #7710: that PR wrote the same advancing observation --
native-at-small-scale evidence landed, with its pull request, merge commit,
evaluated head and pass count -- independently into gunbc.roadmap_authority
five_minute_ci_gate_program_note AND into gunbc.design_document (and so into
generated DESIGN.md). Two hand-maintained copies of one mutable status is the
DESIGN section 3 dual representation: someone updates one, the other goes
stale silently, and both read as authoritative.

The split this lands is the operator's. The DURABLE DESIGN FACT is two clauses
-- native-at-small-scale evidence has landed; operational migration rate
remains open -- and stays in the design criteria. The pull request, merge
commit, evaluated head and executing witness are EXECUTION EVIDENCE and now
live in exactly one typed carrier, gunbc.native_witness_transition_receipt,
which both documents cite by symbol rather than restate.

No pass count is stored anywhere. #7710 recorded 25 of 25 witness receipts;
that module declares 31 test functions today, so the transcribed count was
stale within a day and no oracle here could have caught it. The per-member
verdicts already have one authority in std.selected_witness_bundle
NativeWitnessBundleExecutionReceipt member_equivalence.

The receipt's standing is DERIVED, never stored: the head the witnesses ran at
and the commit that landed them are different commits, so
transition_evidence_standing returns EvidenceExecutedBeforeLanding naming both
rather than letting pre-merge evidence be quoted as verified-at-the-merged-tree.
That honesty was prose in #7710; it is structure now.

This is not an acceptance. RoadmapAcceptanceReceipt remains the only fact
node_accepted consults; the native-selected-witness-bundle node stays open.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…ver material, bounded attraction (#7714)

* WIP: frontend iteration

* S1 selective-spectacle register amendment: salience roles, emission over material, bounded attraction

Operator recalibration 2026-08-02: the register overcorrected against cheap
spectacle into uniform austerity — the correction is calm field; luminous
focus; physical response; every response true (register_thesis revised, the
amendment record kept beside it).

New authority gunbc.design.salience:
- SalienceRole (Ground|Supporting|Focal|Critical) with ONE budget table
  granting chroma/emission/motion/sound per role — energy is scarce, focal,
  and caused, never a per-site decision.
- EmissionSpec: emission is a layer over restrained material (the CRT model),
  the register's second declared exemption lane beside DataVizArea — scoped by
  salience role. emission_for refuses typed: wrong role, outside the envelope
  (low-alpha corona, bounded spread), or with no non-emission discriminator,
  so reduced-motion/no-emission renderings preserve every distinction by
  construction. No pulse/duration field exists — a periodic glow is ambient
  motion and stays unwritable.
- region_focal_admission: at most one ordinary focal subject per interaction
  region (typed FocalBudgetExceeded refusal); Critical may interrupt.
- AttractionField: bounded plate travel inside a fixed hit region — the
  carrier has no position/hit-region field, settle borrows settle_spring
  (no second spring minted). Reference numbers read from the operator's
  dynamic-tierlist login source; its lesson recorded (lag is the material),
  its excess rejected by the envelope.

gunbc.design.principles gains selective-spectacle / emission-over-material /
bounded-attraction rows, each enforced_by a real salience declaration.
DESIGN.md regenerated (site-subsumption row records the thesis revision).
Digests re-derived by execution: moodboard html/thesis and accent-study html
move (both render the thesis), moodboard css unmoved (scope evidence).

Witnesses: test.claim.salience_witness 11 PASS (5 RED controls);
design_register_lift_parity 5 PASS; site_register 1 PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Wire the three digest witnesses to their derived-digest helpers

The floor's orphan-helper hygiene gate stopped the line on this PR:
moodboard_css_derived_digest, moodboard_html_derived_digest, and
accent_study_html_derived_digest were unreachable from any test fn / test
data, because the three witnesses still called
emission_content_digest(s: <surface>()) inline instead of the named
helpers this PR introduced beside them.

Wired rather than deleted, for two reasons. The repin note in this file
cites moodboard_html_derived_digest and accent_study_html_derived_digest
BY NAME as the symbols run on 2026-08-02 to derive the moved digests, so
deleting them would leave the canonical note citing symbols that do not
exist — the fabricated-symbol class DESIGN's cite-the-symbol rule (§3)
exists to prevent. And it is the shape the file already had:
witness_roadmap_css_digest_pinned consumes roadmap_css_derived_digest, so
the derived-digest expression lives once per surface (§2) rather than
being respelled at each witness.

Checked before choosing this fix: reachability is a transitive fixpoint
(reach_fixpoint_pass over a frontier, gunbc.test_module_hygiene), so
routing the witnesses through the helpers keeps emission_content_digest
reachable rather than orphaning it in turn. All five plain fns in the
module are now reachable.

By execution, this tree:
  PASS witness_moodboard_css_digest_pinned
  PASS witness_moodboard_html_digest_pinned
  PASS witness_accent_study_html_digest_pinned
  PASS witness_roadmap_css_digest_pinned
  PASS witness_moodboard_thesis_themes_digest_pinned

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Unit-comparability wall in the salience envelopes (WIP checkpoint before main merge)

* Regenerate DESIGN.md after the main merge (text merge left it off its generator)

DESIGN.md is a generated projection of dag/gunbc/design_document.dag, and
git merged the two files INDEPENDENTLY: the .dag authority auto-merged to
main's newer version while the .md kept this branch's older text for the
five-minute-CI-gate row. No conflict markers, no complaint — the result
looked finished and was not a fixed point of its own generator.

The stale text asserted the native-execution slice was "settled at branch
head 2f9e780 (in-flight executing slice ... banking trigger = #7599
merge)". The generator emits "settled and banked - merged 2026-08-02
(merge 1ebff27; ... at pre-merge head 2f9e780)". So the canonical
design authority would have shipped claiming a load-bearing lane was
still in flight after it had merged and banked — a stale status claim in
the document every other row cites.

Regenerated via tools.generated_artifact_gate main_wet rather than
hand-patched, because the generator is the authority and hand-editing a
generated projection is what produced the divergence class in the first
place. Only DESIGN.md moved; the other 14 committed artifacts were
already fixed points.

By execution, on the merged tree with a seed built from it:
  FAIL witness_committed_is_fixed_point          (before regen)
  PASS witness_committed_fixed_point_red_control (before regen — oracle
       proven discriminating, so the FAIL was real divergence and not a
       merge-broken check)
  PASS witness_committed_is_fixed_point          (after regen)
  PASS witness_committed_fixed_point_red_control
  PASS witness_per_artifact_red_receipts
  PASS witness_all_known_committed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Count roles by predicate, not by a boolean mode flag (review finding)

count_roles(assignments, focal: Bool) was a two-mode fold: the flag chose
between two independent counts, so region_focal_admission read
count_roles(assignments, focal: false) to mean "count the critical ones"
— a domain concept encoded as a bare Bool, legible only if you knew which
branch false selected. count_roles_where now takes the admission
predicate itself, which names the intent at the call site and leaves ONE
fold rather than a two-mode one.

Shape follows the std precedent rather than being invented here:
std.materialization_ladder first_provider_where takes
wanted: fn(CacheProvider) -> Bool and is called with a lambda over a
named coproduct predicate (p => provider_is_copy_tier(p: p)).

The same review also asked to DELETE role_is_focal / role_is_critical as
a predicate-dissolution antipattern. Declined, for reasons that outlast
this PR: (1) the cited rule is not in CLAUDE.md/DESIGN.md — every use of
"dissolution" there is about scaffolds and guarantee-ladder climbs;
(2) the stated justification, that the sole caller "already matches on
the role", was not true of the code — count_roles branched on the Bool
and called the predicates, so there was no match to inline into; (3) the
design layer already carries five predicates of exactly this shape
(state_kind_is_terminal, trigger_is_state_class, decl_is_color,
decl_is_role_themed, decl_is_literal_color) and the std precedent above
KEEPS its provider_is_* predicates and passes them into the generic fold.
Deleting these two would fork from that convention, which is the §3
violation rather than the fix. This commit converges onto the precedent.

By execution, on the merged tree:
  PASS salience_keystone_holds
  PASS witness_red_two_focal_subjects_in_one_region_refuse
  PASS witness_critical_interrupts_without_dethroning_the_focal_subject
  PASS witness_red_rem_emission_is_not_comparable_to_a_px_bound
  PASS witness_red_rem_attraction_is_not_comparable_to_a_px_bound

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 3, 2026
…ejects drift (#7727)

* WIP: pure business 8/1

* Regenerate DESIGN.md from the re-anchored five-minute row

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Regenerate DESIGN.md after merge (auto-sweep committed the conflicted file)

The mid-merge auto-commit captured DESIGN.md with conflict markers.
DESIGN.md is a registered generated artifact — regeneration from the
resolved design_document.dag via main_wet is the authoritative merge
resolution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Reword program step 6 off the superseded five-minute objective (review 47439)

Step 6 still called five minutes 'the objective'; it now names the
bare-minimum-computation contract as the objective, with five minutes as
the Stage C distress checkpoint bound only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: pure business 8/1

* Refresh the #7599 observation in the five-minute-gate rows: in-flight → merged, banking trigger fired

The program note (gunbc.roadmap_authority five_minute_ci_gate_program_note) and
the DESIGN row still described #7599 as an in-flight executing slice with its
banking trigger pending. #7599 merged 2026-08-02 (merge 1ebff27), so the
trigger those rows named has fired. Both sentences now state the dated merged
fact; the registered operator sequence and the first_slice record of what the
registration slice registered are untouched. DESIGN.md regenerated same-commit
via the generated-artifact gate (main_wet), executed green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: pure business 8/1

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Record the native-at-small-scale status once, in one typed receipt

Operator ruling on #7710: that PR wrote the same advancing observation --
native-at-small-scale evidence landed, with its pull request, merge commit,
evaluated head and pass count -- independently into gunbc.roadmap_authority
five_minute_ci_gate_program_note AND into gunbc.design_document (and so into
generated DESIGN.md). Two hand-maintained copies of one mutable status is the
DESIGN section 3 dual representation: someone updates one, the other goes
stale silently, and both read as authoritative.

The split this lands is the operator's. The DURABLE DESIGN FACT is two clauses
-- native-at-small-scale evidence has landed; operational migration rate
remains open -- and stays in the design criteria. The pull request, merge
commit, evaluated head and executing witness are EXECUTION EVIDENCE and now
live in exactly one typed carrier, gunbc.native_witness_transition_receipt,
which both documents cite by symbol rather than restate.

No pass count is stored anywhere. #7710 recorded 25 of 25 witness receipts;
that module declares 31 test functions today, so the transcribed count was
stale within a day and no oracle here could have caught it. The per-member
verdicts already have one authority in std.selected_witness_bundle
NativeWitnessBundleExecutionReceipt member_equivalence.

The receipt's standing is DERIVED, never stored: the head the witnesses ran at
and the commit that landed them are different commits, so
transition_evidence_standing returns EvidenceExecutedBeforeLanding naming both
rather than letting pre-merge evidence be quoted as verified-at-the-merged-tree.
That honesty was prose in #7710; it is structure now.

This is not an acceptance. RoadmapAcceptanceReceipt remains the only fact
node_accepted consults; the native-selected-witness-bundle node stays open.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Restore DESIGN.md to main's committed projection (this branch changes no authority)

* Prove the receipt's own citation resolves, executes, and rejects drift

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 7, 2026
…rols, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff
briansrls added a commit that referenced this pull request Aug 9, 2026
…8034)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls added a commit that referenced this pull request Aug 9, 2026
* Add Class B live specimen for trim pool-membership coincidence.

trim is outside the substrate free-call builtin registry; it compiles only when std.algebra is already in the pool while the consumer imports std.types alone. v1-compiler-tests exercises narrow-pool failure, coincidence compile, direct-import check, perturbation stability, and FreeMonoid receiver refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Land trim free-function authority and fix TopologyEdge modeling violation.

Declare importable fn trim in std.algebra with explicit trim imports across
free-call sites, free_call.trim runtime dispatch, and specimen tests proving
narrow-pool binding via ListedImport rather than pool coincidence. Rename
TopologyEdge.port to connector_label to close bare-primitive-nicknames-concept
on the fixture types overlay.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Replace narrow-pool types overlay with minimal trim stub.

Drop the verbatim std.types copy that re-minted Duration outside std.measure;
the narrow-pool fixture now shadows only String/Bool kernel imports while
std.algebra enters via explicit trim import from dag/std.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Clarify trim fn body as typecheck-only identity stub.

Replace the dead-branch tautology with a plain identity body and note
that free_call.trim is the semantic runtime authority (review 50610).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix silent floor terminal exits and orphan worker processes (#8060)

* Fix silent floor terminal exits and orphan worker processes.

Post-walk compile_clean and receipt-write failures now populate located refusal details, emit falsifier classification, and journal walk-terminal rows before fast-exit; the coordinator replays worker terminal detail on failure and arms PR_SET_PDEATHSIG so timed-out steps do not leave orphaned claim_executors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Journal pre-walk worker terminal refusals on the main return path.

Workers that fail before floor_terminal_fast_exit now emit the same walk-terminal journal/stderr row as post-walk failures; drop duplicate coordinator-observation journal on worker failure replay.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Gate PR_SET_PDEATHSIG worker spawn hook on Linux only.

prctl is not available on macOS; #[cfg(unix)] was too broad for the new pre_exec arm.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix trim call shape in floor_discovery_producer.

The std.algebra trim free function declares parameter `s`, not `seg`.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore coincidence narrow-pool negative control and regen trim exports.

Add trim_free_call_fails_in_narrow_pool_without_algebra_coincidence compiling
coincidence_specimen.dag against the two-root narrow pool (no dag/std) and
assert trim does not resolve via pool coincidence; pair with a PoolCoincidence
positive binding control. Regen stage0 so extdeps.uri trim import and std.algebra
trim export match the emitter.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add HAND-RUST scaffold deferral to class_b_trim_specimen_test.

Documents the import-strip Class B lane, why pool-overlay probes stay in
v1-compiler-tests, and the closure-independent-binding dissolution trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>

* decl_facts: explicit-import resolution + resolved parent/arm projection prerequisite (#7924)

* Cut exact-initializer-identity successor from main (#7855 operator verdict).

Lift foundation only from session/tidy-boar-761: two-root duplicate_qn
fixture, fixture-scoped pool_roots, type-env projection marshal (WIP —
structural blockers from operator review remain), dimensionless Rust
controls, decl_facts-vs-compile population divergence note.

Copy #7796 prereq bank: decl_facts_skeleton, qualified-name resolution
fixtures, 12 skeleton witness cases, constructor-lexeme negative
boundary tests.

Does not include tidy-boar CI retry commits or unrelated branch surface.
Successor scope: ExactDeclarationIdentity carrier, binding_kind gate,
eight executing controls, exact whole-tree marshal/refusal census.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix pool_roots fork: one authority in fixture witness_support.

The lift merged two lineages that both declared decl_facts_reflection_fixture_pool_roots with different populations. Consolidate the six-root walk in test.fixture.decl_facts_reflection.witness_support; projection witnesses import that row. Skeleton lexeme witnesses use an explicit narrower decl_facts_skeleton_fixture_pool_roots.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI build: sync stage0 with main gate and witness-cost surfaces.

The tidy-boar lift left cli_run and v1_interpreter behind main: missing CompilerDiagnostic histogram arms, gate failure-detail builtins, and the WitnessRowCost struct claim_executor expects. Restore those surfaces without changing the decl-facts lift.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI build: sync stage0 with main gate and witness-cost surfaces.

The tidy-boar lift left cli_run and v1_interpreter behind main: missing CompilerDiagnostic histogram arms, gate failure-detail builtins, and the WitnessRowCost struct claim_executor expects. Restore those surfaces without changing the decl-facts lift.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Ground exact variant identity on parent/arm declaration carriers and VariantValueBinding gate.

ResolvedVariantIdentity now carries full ExactDeclarationIdentity for parent and arm instead of lossy qualified-name pairs; marshaling projects parent_type and arm alongside legacy parent_qualified_name/variant_name fields. Variant-value resolution requires infer-stamped VariantValueBinding and resolves parent coproduct through the binding's parent_enum authority rather than spelling plus annotation heuristics.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add VariantValueBinding and module-order controls for exact initializer identity.

Control 1: planted scaffold_with_data_ref specimen plus executing .dag and Rust witnesses prove a data-item reference with coproduct annotation marshals NotVariantValueProjection, not a variant value. Control 4: reversed source-file order leaves constructor parent identity unchanged. Also gate call_env_depth witness behind an armed atomic (default off) and fix namespace_alias_decl_test module gating.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix compile-clean gate: restore ensure_is_converged imports from main.

Merge carry dropped gunbc.build_cache_ensure and gunbc.compile_pool_ensure
imports in their witness tests. Also land control 5: ExactDeclarationIdentity
lookup grain with executing witnesses for duplicate-qn distinctness and
duplicate-exact-identity ambiguity.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix batch-3 decl_facts witnesses without growing migration debt.

Group B: projection helpers read initializer roots (plain record + coproduct).
Group A: pool-corpus duplicate bare-type index lets decl_facts marshal ambiguous
variant values when witness ctx.modules is narrower than the fixture pool.
Group C: delete redundant skeleton Rust test; retain only source-order seam test
with a typed retirement row (no baseline bump).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Register decl_facts_marshal_bridge in stage0 crate layout for regen.

Hand-added pub mod without frontier registration made regen_verify fail:
fresh emit omitted the module while the committed lib.rs carried it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix batch-3 discovery re-eval of duplicate OtherTwo side-effect row.

The entry module duplicated witness_support's ambiguous_shared_b closure
loader; corpus re-eval of that local data row ran without OtherTwo in scope.
Closure loading stays on witness_support's enrolled side-effect row.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore ambiguous_shared_b import without duplicate side-effect data row.

Import-only closure load keeps Group A green; removing the local
OtherTwo data row avoids batch-3 discovery re-eval undefined-variable failure.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align nullary reflection witnesses with initializer projection trees.

Skeleton lexeme walks on fact.node no longer apply after DeclFact.node became projection roots; assert resolved variant identity via projection helpers instead.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove re-evaluable OtherTwo side-effect row from witness_support.

Discovery corpus re-evaluates imported closure-loader data rows without variant imports in scope; keep ambiguous_shared_b closure load via initializer_projection import only.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Trust importing-module TypeBinding for variant resolution; remove pool ambiguity scan.

Delete cross-module bare-name candidate machinery, decl_facts_marshal_bridge, and variant_to_enum sentinel; explicit A import must resolve uniquely to ambiguous_shared_a. Update witnesses and Rust controls accordingly; remove duplicate qualified-name witness and dead closure-loader row.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix vacuous A/B witnesses and pool-grain duplicate lookup; drop Rust CI enrollment.

Add ambiguous_b_specimen as a legitimate B consumer so explicit-import controls
exercise both modules in the entry closure. Replace the vacuous single-module
witness with discriminating positive and negative controls. Route duplicate-QN
per-candidate uniqueness through PoolDeclarationIdentity instead of a parse-pool
row masquerading as exact identity. Remove the enrolled Rust source-order suite
from v1-compiler-tests CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename Exact carriers to ResolvedDeclarationLocator; honest locator grain.

Drop ExactDeclarationIdentity/ExactVariantIdentity aliases. Rust projection
carriers are ResolvedDeclarationLocator and ResolvedVariantLocator; dag model
matches. Rename duplicate-QN witness helper to pool-declaration lookup grain.
Occurrence identity is not claimed anywhere on the branch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: re-home over-budget qualified-decl ref witness to long lane.

cross_module_qualified_reference_emits_call_from_correct_module exceeded
the 5000ms per-PR CPU budget (chronic on main, unrelated to decl_facts).
Move it to test/claim/long/ with a lighter std.unicode.types fixture;
keep the fast same-module control per-PR.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix node-frontier refusal: restore long witness module declaration.

Changing line 1 of an existing long-lane file trips diff-before-first-declaration
fail-closed in node-frontier population. Keep main's module name; only the
unicode fixture and note differ from main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix scoped v1 witness batch FLOOR-BATCH-OVER-BUDGET on CI.

The scoped child exceeded its 360s batch-owned clamp (~376s measured at
93b1373 locally; CI run 31223532865 exited 1 after the same wall).
Raise the v1_claim_scoped_witness_batch clamp to 480s with a receipted
note (375.6s observed x 1.2 fleet margin). Initialize the scoped
witness receipt header in scoped floor workers so append does not fail
when the file is absent.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Pin scoped batch clamp witness to 480s after clamp raise.

witness_v1_claim_scoped_batch_is_file_grain_and_batch_owned still asserted
the retired 360s batch-owned clamp; update to match v1_claim_scoped_witness_batch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Bind spark-standup-program-accounting doc to gunbc doc graph roots.

Fleet-blocking main red: doc_graph_has_no_orphan_docs failed because
docs/plans/spark-standup-program-accounting.md landed in #7972 with no
HandAuthoredDocBind row. Mirrors owned-ci-control-plane-design binding.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert "Bind spark-standup-program-accounting doc to gunbc doc graph roots."

This reverts commit d303674.

* Bind spark-standup-program-accounting.md into the doc graph (main red, from #7972)

#7972 landed docs/plans/spark-standup-program-accounting.md with no doc-graph
binding, so doc_graph_has_no_orphan_docs reds on main and every branch merging
main inherits it. My PR, my orphan.

Verified rather than assumed. Subject: 0 bindings corpus-wide. Positive control:
owned-ci-control-plane-design.md, added by a DIFFERENT PR in the SAME window,
returns 4 — same query, same window, one bound and one not, so the zero is a real
negative and not a broken grep.

Discriminating control on the fix itself: the gate returns false with the row
removed and true with it restored, so the row is what closes it rather than
something else in the window.

Every cited symbol grep-verified before authoring — fleet_subsumption_manual_gaps_plan,
dgx_spark_arrival_standing, dgx_spark_router_bindings all exist. Two plausible names
I first reached for did not, and are not in the row.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Revert "Bind spark-standup-program-accounting.md into the doc graph (main red, from #7972)"

This reverts commit d47618b.

* Update floor batch clamp witnesses for 480s scoped-batch overhead.

Main's authority witness expected 360s; this branch receipted raise to
480s in gunbc.ci_layer_roots v1_claim_scoped_witness_batch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 50585: restore fail-closed call binding and cache keepalives.

- Re-instate duplicate named/positional argument refusal (CallContractMismatch)
- Route observed_peak_resident_bytes through cli_run::peak_rss_vhwm_bytes
- Restore pointer-cache keepalives for param_name, var_sym, call_func_name
- Align decl_facts_reflection witness note with landed nullary-value controls

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 50590: honest fn-node lookup and marshal entry gate.

Rename lookup_typed_item to lookup_fn_node; marshal DataItem projections
from the typechecked item node and refuse when registry knows a data item
but fn_nodes lacks the subject. Add dissolve-on notes for skeleton lexeme
aliases and data_initializer_identity seed-retained scaffold.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix record-literal coproduct resolution to honor explicit imports.

Remove the module-pool first-pick in coproduct_type_item_with_variant_children
and pass the import-resolved type_item directly into marshal_coproduct_record_projection,
so duplicate bare coproduct names cannot override the importing module binding.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Route eval_decl_facts DataItem marshal through lookup_fn_node seam.

eval_decl_facts now delegates DataItem node marshaling to
marshal_data_initializer_projection so enrolled .dag witnesses exercise
the same typechecked path as Rust seam tests. Update gap notes to match.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix review 50602: witness import and wire retained Rust test module.

Import decl_facts_reflection_nullary_value_projection in the initializer
projection witness module and register decl_facts_dimensionless_projection_test
in v1-compiler-tests lib.rs so the retirement row matches executing coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore symbol_index_fill_overlay_direction_test module enrollment.

Re-add the lib.rs mod line dropped during decl_facts test wiring so the
fill-overlay direction regression control cited in 04_infer remains executed.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Recenter the roadmap on compute, CI ownership, and fleet convergence (#8034)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>

* Fix trim lying model per review 50629; revert TopologyEdge scope creep.

Replace identity trim body with a pure-dag seam and route emitted std.algebra::trim through v1_rt::trim via rust_host_string_op_fn_emit. Restore TopologyEdge.port (revert connector_label rename from trim PR scope).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Own pool-independent trim binding repair (#8062).

Bare free-call trim now requires listed import via closure_independent
registry in infer_env (func sig, global_bare, ancestry, method-bridge paths);
coincidence success is refused. Six specimen tests; emit_rust adds explicit trim import.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Enroll both Sparks; replace the matrix rectangle counts with identity joins (#8056)

Three witnesses asserted the derived host/phase matrix against
enrollments.length() * host_standup_spine.length(). That is a count
equality over a rectangle: it cannot tell a correct matrix from one that
hands every host every spine step, which is exactly the shape a
participation-scoped program is supposed to make impossible. DESIGN.md
section 5 rules that completeness is an identity join, not a count.

They are now joins derived from each enrollment's participation-selected
program:

  - per-enrollment cell count == program_step_count(assimilation_program_for)
  - duplicate-free over host_phase_cell_key
  - matrix hosts are exactly the enrolled roster, no strays
  - unmodeled count cross-checked against a disposition filter over the
    same matrix, rather than against a rectangle
  - runner enrollments still contribute exactly the whole spine

srv5 and srv6 are enrolled as InferenceServingParticipation, which
selects exactly four shared obligations each and no runner-only one.
ENROLLED IS NOT CONVERGED: all eight Spark cells are honestly
unobserved, and a witness asserts that so a future producer reds here
instead of silently upgrading the claim. Positive controls keep both
sides non-vacuous -- runner-only obligations do exist on runner hosts,
and the spine does carry gap phases.

Unblocking root fix, not scope creep: gunbc.roadmap_instrument_sandbox
defined fn cell(s:) and fn row(cells:) alongside gunbc.plans.md_helpers'
fn cell(text:) and fn row(cells:) -- a section 3 homonym pair. Editing
this witness widened its closure enough to pull both definers into the
pool, after which the plan modules' explicit `cell` imports lost to pool
coincidence (#6985 Class B) and every witness in the file failed with
"calling 'cell': no parameter named 'text'". The HTML-fragment builders
are renamed fragment_cell / fragment_row; md_helpers keeps the plain
names. The sandbox keystone still passes.

Green by execution, eight witnesses, one at a time on the live tree.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Register service-op String wire projection method fork class (#8062).

Names the infer-layer FaithfulFreeMonoid vs String receiver split, pins trim_method_form_fails_on_freemonoid_receiver, and records dissolve-on as type-node unification — separate from the trim binding-bridge repair.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
… mandate 2026-08-09) (#8070)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0: dispatch trigger, checkpoint structure, permanence laws (operator ruling 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 10, 2026
…map onto the 2026-08-10 stop (#8116)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0: dispatch trigger, checkpoint structure, permanence laws (operator ruling 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Record the four-lane closeout and the root it identified

Four lanes (CONVERGE, CI RESET, CI2-0, DEVBOOT-0) closed 2026-08-10 with zero
displacement between them. Each was asked for the root with evidence and
explicitly invited to reject the manager's hypothesis; all four declined to
confirm it.

The re-cut that matters: of 11 rejecting members in one real std closure, 5 are
normalize contradicting its OWN declared contract (retaining wrapper
declarations, then rejecting the tree those retentions live in via its own
module-grain well_formed gate) and only 3 are genuine frontend gaps. A broken
contract is a bounded repair; a missing capability is a program.

Synthesis across the four: nothing could be verified incrementally — the
acceptance contract demanded the whole corpus and moved between measurements,
the mechanism demanded 60-75 minutes and gated deploys as well as merges, and
the instruments built to escape both were themselves unverified.

Written to git rather than left in message threads because five sessions were
archived today holding measurements, one leaving a PR whose premise had been
reverted underneath it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main's SubstrateLongLaneRow schema break, and reconcile the roadmap onto the 2026-08-10 stop

Two things, the first a live main repair found while validating the second.

MAIN IS RED AND NOTHING WAS GOING TO CATCH IT. #8114 (24ff2da) added 18
SubstrateLongLaneRow literals carrying `dissolve_on:`; #8059 (45e7024)
merged after it and renamed that field to `dissolution: DissolutionCondition`.
Each PR was green alone and the pair is red — the merge race a merge queue
exists to prevent, landing during the runner outage, so no run has reported it.
All 18 now carry `unbound_dissolution(description: ...)` and name their sibling
row explicitly rather than saying "same as sibling row", which is the vague
prose #8059 was eliminating. Verified: compiling ci_layer_roots' closure emits
zero SubstrateLongLaneRow diagnostics (the residual exit=1 is the pre-existing
25-row §4c population in host_phase_status_witness_test.dag, untouched here).

ROADMAP RECONCILIATION. ROADMAP.md is a generated artifact; the authority is
dag/gunbc/roadmap_authority.dag. Baseline control first: the unedited authority
reproduces the committed ROADMAP.md exactly, modulo one trailing newline the
CLI adds — so the instrument was validated before it was trusted.

The structural fix: edge(five-minute-ci-gate -> native-selected-witness-bundle)
is DELETED. The entire CI-cost chain — discovery snapshot, scoped substrate,
early selection, streaming — hung beneath a node that is now stopped and can
never be accepted, so every floor row was unschedulable. It was also backwards
on the merits: a 3,290s floor carries 97s of witness evaluation, so an
infinitely fast evaluator leaves ~97% of the floor standing and native
execution was never the CI-cost lever.

Four rows follow from that:

- native-selected-witness-bundle re-cut from "complete cutover in one PR" to
  the self-host frontier it always was (operator root 3). The frontier is
  stated as measured: of 11 rejecting members in one real 15-file std closure,
  5 are normalize contract violations, 2 the graft guard working, 3 genuine
  LEX/PARSE gaps, 1 uncaptured. A broken contract is a bounded repair; a
  missing capability is a program — they do not schedule together. The sugar
  chain is deferred WITH its SHAs (6888b97 -> f62e838 -> c84842c):
  cherry-picked clean onto main it is 5/5 FAIL, because separability was
  asserted from a description and refuted by execution.
- five-minute-ci-gate carries the measured decomposition rather than a
  narrative: 1,422s discovery/setup, 690s scoped worker, 97s evaluation;
  duplicate discovery 295.7s + 284.3s; selection paid after preparation;
  one missing typed key costing 82-96% of a cold symbol-index build.
- five_minute_ci_gate_program_note updated, because DESIGN cites it as the
  single authority for sub-lane scope and dispatch order and must not carry
  a second copy.
- v2-lens-suite-execution's trigger ("after CI2-0 terminal acceptance") is
  unreachable and now says so. It KEEPS its dependency deliberately: its own
  handback demands zero v1 lens-body executions, so relaxing the trigger would
  only move the frontier into the handback.

Regenerated ROADMAP.md from the edited authority; the lead-budget lens returns
[] (no violations).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal the second half of the #8059 schema break: HasTrigger is not a constructor

wise-boar-328 hit a symptom my first commit did not cover, reproducing it
independently while merging main into #8109. Checked rather than assumed, and
it is real: dag/gunbc/doc_graph_roots.dag calls `HasTrigger { text: ... }` in
81 places and HasTrigger is DEFINED NOWHERE IN THE TREE.

All 81 were introduced by #8059 (45e7024) itself — the same PR that renamed
SubstrateLongLaneRow.dissolve_on. So that PR shipped a nonexistent constructor
81 times and merged during the runner outage, where nothing executed it.

The intended form is not a guess. The field is typed:

  HandAuthoredDocBind.dissolution: PlanRetirement
  PlanRetirement = PlanRetiresWhen { condition: DissolutionCondition }
                 | PlanHasNoRetirement

and the file ALREADY IMPORTS both `PlanRetiresWhen` and `unbound_dissolution`
while using neither — the imports were written for the correct form and the
constructor call was wrong. Each payload is free text describing when the plan
retires, which is UnboundDissolution by construction (BoundDissolution carries
a DeclarationRef, not prose), so every row becomes:

  dissolution: PlanRetiresWhen { condition: unbound_dissolution(description: ...) }

Verified by execution: compiling doc_graph_roots' closure emits zero errors and
zero HasTrigger/PlanRetirement/dissolution diagnostics. The residual 25 hard
diagnostics are the pre-existing §4c annotation population in
host_phase_status_witness_test.dag, untouched and unrelated.

Main needed both halves; the first commit alone would have left it red.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* The cancelled-check row stops predicting and carries its three receipts

gunbc.ci_process_end_to_end already legislated this class — "no check present
means not yet observed and never counts as satisfied; cancelled, timed out,
refused by the infrastructure, and genuinely failed stay four different things"
— but its displaced_cost was written as a PREDICTION ("an absent check
currently reads the same as one that passed elsewhere"), so nothing made it
rank. It now carries measurement, supplied by calm-ram-435 who had recorded the
class before tonight:

  #7932 @ 493de34 (2026-08-07)  a CANCELLED required ci folded into PASS; the
                                tally reported MERGE CRITERIA MET while GitHub
                                held mergeStateStatus=BLOCKED
  #8051 @ b4a8d5d               two runs on one head; the concurrency-cancelled
                                one pinned checks_state at PENDING beside a
                                SUCCESS row
  #8059 (2026-08-10)            merged on a cancelled run → 99 sites, two files

THE SKEW RUNS BOTH WAYS. One cancelled row reads as pass in one direction and
as pending in the other, so no single sign-correction closes it — which is why
red_control now demands an executed control for EACH direction, and says the
verdict derives from the authoritative merge state rather than from aggregating
rollup rows. It also names the adjacent trap: mergeable: MERGEABLE is GitHub's
conflict-freedom field, not a checks verdict, so it is never a second
confirmation of anything.

What #8059 cost is stated as the receipt rather than as a story: main could not
derive its own generated artifacts, every PR adding an emitted module was
blocked, three sessions each found it believing their own branch was broken,
and two independently wrote the same 81-row repair within a minute. None of the
99 is a review gap and none is a review fix — each is a type error the compiler
decides in milliseconds. The only thing that had to happen was for the checks
to run.

Verified: main_wet EXIT=0 with drift confined to this authority edit and its
regenerated ROADMAP.md projection; lead-budget lens returns [].

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant