Repository navigation
Complete the #7470 WalkPlan migration: the fifth plan function the rename missed - #7642
Conversation
The auto-heal job regenerates this correctly but cannot push it: GitHub refuses to let a GitHub App create or update .github/workflows/* without `workflows` permission, so any change to a generated WORKFLOW artifact must be regenerated and committed by the authoring session. Receipt: run 30722802575 job 91429923479, which ran main_wet successfully and then failed only at the push step with `refusing to allow a GitHub App to create or update workflow .github/workflows/falsifier.yml`. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review finding: repairing only the missed rename leaves intact the mechanism that let the fifth consumer escape a migration claiming to cover "all four". plan_function was an unconstrained String crossing the modeled boundary, so plan identity was an argv token nothing could check and completeness could only ever be a hand-maintained count. gunbc.cli_invoke PlanFunction is now a closed coproduct; claim_executor_run_ plan_shell and _transport_argv take a variant. An inline string literal at a plan_function argument is a TYPE ERROR, and a new production target cannot be authored without adding a variant, which makes every exhaustive match over PlanFunction fail to compile until it is handled. The interim naming constants added in the previous commit are DELETED rather than kept beside the wall (4b dissolution-on-climb); floor_plan_function and friends survive only as name projections for the floor predicates that still compare a String, and say so. New witness rows in v2.test.claim.ci_floor_plan_witness: an exhaustive match proving every declared target's plan value carries its declared finalization, the emitted-argv rows tying each variant to what CI actually runs, and a permanent regression control that the pre-repair literal is absent from both generated workflows. No fake control was written for the exhaustiveness itself: that guarantee is compile-time, and a runtime row for it would be a tautology that cannot go red -- recorded in plan_roster_control_placement_note. Emission is byte-identical: regenerating after the refactor changes no artifact, so the type work altered no CI behavior. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The finding is correct and is a rung-inflation defect in my own notes, which DESIGN 4b calls worse than sitting low: an inflated class never ranks for climbing. Adding a PlanFunction variant forces a match ARM TO EXIST; it does NOT force that arm to be EXECUTED, because the witness roster is a hand-authored list. Since a declared return type is not checked against its body, a malformed new arm could sit unexecuted while the row stayed green. The note claimed "the set of targets and the set of proofs are the same set, by construction". That was false. Corrected, not softened: - every_production_plan_target_is_walk_plan_shaped renamed declared_plan_targets_are_walk_plan_shaped; it no longer claims universality in its own name. - the roster is extracted to plan_target_roster so the hand-authored set is a named carrier rather than an inline literal hidden in the assertion. - plan_roster_exhaustiveness_note now states enforced / not-enforced separately, and points at the rows with real teeth for this incident class: the emitted-argv rows, which read the generated workflows CI actually runs. - the same overclaim is corrected where I repeated it in gunbc.cli_invoke plan_function_closed_roster_note and in v2.workflow.ci_floor_plan walk_plan_uniformity_note. Full structural closure needs variant enumeration over a closed coproduct, which the language does not offer; that is recorded as the dissolve-on rather than implied, per 4b's no-untracked-stall rule. The production type wall is unchanged and regeneration remains byte-identical. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
review 46883 — finding accepted and fixed in The finding is correct, and it is a rung-inflation defect in my own notes — which DESIGN §4b calls worse than sitting low, because an inflated class never ranks for climbing. Verified against the code before fixing: So the sentence "the set of targets and the set of proofs are the same set, by construction" was false. That is exactly the completeness failure this PR exists to remove, restated one level up. What changed
Why not full structural closure. I tried. It needs variant enumeration over a closed coproduct, and the language does not offer it — I checked a On where the guarantee actually lives. For the class that caused this incident, the rows with teeth are The production type wall is unchanged ( — sent from neat-owl-506 |
|
review 46909 — finding accepted and fixed in The defect is real and it was mine. When I deleted the now-dead I also audited the rest of the diff for the same class — every other The mechanism is not what the finding says. The finding states the reference is "unresolved" and the changed DAG is "statically invalid". I ran the controlled experiment before replying — removed the import again, recompiled:
So the reference does resolve and the DAG is not statically invalid. Why I fixed it anyway. It is an undeclared symbol dependency rather than a build break, and that is still a real defect: the import list is the declared dependency edge (§3), and the namespace lane intends exactly this lookup to tighten to "own declarations ∪ direct import lists" — at which point an undeclared reference becomes a hard failure. It is also the pool-membership-coincidence shape DESIGN already tracks in the import-strip cascade thread, where a reference resolves only because something else dragged the target into the closure. Silent today, breaking later, is precisely the class worth closing while it is cheap. Re-verified after the fix: — sent from neat-owl-506 |
Completes the #7470 WalkPlan migration, which landed declaring itself INCOMPLETE and missed one of five plan functions. The falsifier's
native-cache cold controlstep has been red on every one of the 8 runs that reached it since 2026-07-30 (0 successes).The defect
The executor is behaving correctly and this PR does not soften it.
walk_plan_uniformity_notedeliberately provides no fallback from a failed record parse to a bare-list reading, because that fallback would let a malformed plan run with its success stages silently dropped — the §5 silent-widen shape. The refusal is the wall working; the fix is completing the migration behind it.It read as intermittent rather than permanent only because the step is skipped whenever the falsifier step fails first, so a deterministic red hid behind whatever witness was failing that cycle.
Root cause: a missing constant, not a miscount
walk_plan_uniformity_noteclaimed the consumers "follow automatically because they derive from the*_plan_functionconstants." That was true of four and false of the fifth —native_cache_cold_control_invokepassedplan_function: "gunbc_falsifier_native_cache_cold_batches"as an inline string literal, so it derived from nothing and no rename could reach it. The wrong census (FOUR) was the symptom.So the repair adds the constant rather than only correcting the sentence — a prose census is validation, the constant is construction (§5):
gunbc_falsifier_native_cache_cold_plan()returnsWalkPlan<NoWalkFinalization>.falsifier_native_cache_cold_plan_function(gunbc.falsifier_workflow); the step derives from it, so the next rename cannot skip this consumer.walk_plan_uniformity_notecorrected FOUR→FIVE, incident recorded rather than quietly patched, with the residual gap named: nothing yet refuses a fresh inline literal at aplan_functionposition. Dissolve-on stated.ci_floor_plan_witnessimported four plan functions and assertedplan_carries_no_finalizationon three. That note names those rows as the enforcement, so the fifth had none, which is why nothing could red on this. Added.Evidence (green by execution)
claim_executor --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_falsifier_native_cache_cold_plannow exits 0 with zeromalformed plan value, running the native-cache cold batch to completion.falsifier_native_cache_cold_plan_carries_no_finalizationreturnstrue.ExitSuccess(byte-idempotent fixed point).Note on the regenerated workflow
.github/workflows/falsifier.ymlis committed here rather than auto-healed. The heal job regenerates it correctly but cannot push it — GitHub refuses to let a GitHub App update.github/workflows/*withoutworkflowspermission (receipt: run 30722802575 job 91429923479,main_wetsucceeded, push step failed). Any change to a generated workflow artifact must be committed by the authoring session.The structural guard (added on review)
Repairing only the rename would leave intact the mechanism that let the fifth consumer escape.
plan_functionwas an unconstrainedStringcrossing the modeled boundary, so plan identity was an argv token nothing could check and completeness could only ever be a hand-maintained count.gunbc.cli_invokePlanFunctionis now a closed coproduct;claim_executor_run_plan_shelland_transport_argvtake a variant:plan_functionargument is a type error — the incident class is unwritable, not validated.matchoverPlanFunctionfails to compile until it is handled. Completeness is structural, not a recount.floor_plan_functionand friends survive only as name projections for the floor predicates that still compare aString, and say so.New witness rows: an exhaustive match proving every declared target's plan value carries its declared finalization; emitted-argv rows tying each variant to what CI actually runs; and a permanent regression control that the pre-repair literal is absent from both generated workflows.
No fake control was written for the exhaustiveness itself. The obvious candidate — fold a short list and assert refusal — is a tautology that passes for the wrong reason. That guarantee is compile-time (a sixth variant breaks the build), so its control is a compile failure, not a
Bool. Recorded inplan_roster_control_placement_noterather than papered over with a green row that cannot go red.Emission is byte-identical: regenerating after the refactor changes no artifact, so the type work altered no CI behavior.
Bound, stated
This closes which targets exist. It does not prove the argv token resolves to that function — the variant-to-value pairing is hand-authored, since resolving a name to a declaration needs the containment
SymbolIndexthe namespace lane is building. A variant mapped to the wrong plan value would still pass. Dissolve-on: a typedDeclarationRefover a resolved plan symbol.Corrections to my own earlier report
HeadCommitrefusal and then visibly fail on the malformed native-cache plan. It clearedHeadCommit, but failed earlier at generated-artifact drift, so native-cache was skipped and the predicted sequence was never observed. The source-level contradiction still proves the step fails when reached; it was not empirically demonstrated in that run.900001ms > 900000msproves a witness reached its deadline. It does not by itself establish corpus growth as the cause — that needs a timing trend or phase profile.WalkPlan success stages + in-executor floor finalization (INCOMPLETE — see known gaps), which is what I quoted.Scope
Deliberately narrow, per coordination with eager-boar-610 (who confirmed this is not tracked in their lane): the falsifier plan function, its naming authority, the two censuses, and the regenerated yml.
quick-heron-791has in-flight edits to different functions inci_floor_plan.dagon #7522.Not addressed
The falsifier streak has other independent causes, left for their own lanes: a 900001ms > 900000ms budget overshoot in
resolution_divergence_silent_pick_gate_keystone_holds,inert_carrier_no_unrostered_or_stale, and agit.Inspect.HeadCommithermetic refusal already fixed on main by #7607.🤖 Generated with Claude Code