Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/falsifier.yml
Original file line number Diff line number Diff line change
Expand Up @@ -133,7 +133,7 @@ jobs:
- name: native-cache cold control (warm-tier admission counterpart)
run: |
ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_falsifier_native_cache_cold_batches
"$ROOT/target/release/claim_executor" --source-root dag --source-root src/v2 --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_falsifier_native_cache_cold_plan
env:
GUNBC_CI_NATIVE_CACHE_COLD_CONTROL: 1
timeout-minutes: 30
Expand Down
18 changes: 12 additions & 6 deletions dag/gunbc/ci_spec.dag
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,11 @@ import gunbc.ci_layer_roots {
}
import gunbc.cli_invoke {
claim_executor_run_plan_shell,
PlanFunction,
CiFloorPlan,
CiRegenFloorPlan,
CiPlanArtifactPlan,
plan_function_name,
claim_executor_verify_artifacts_shell,
gunbc_run_shell
}
Expand Down Expand Up @@ -361,12 +366,13 @@ fn git_fetch_script(policy: DiffPolicy) -> String {
}

data floor_plan_entry: String = "src/v2/workflow/ci_floor_plan.dag"
data floor_plan_function: String = "gunbc_ci_floor_plan"
data plan_artifact_plan_function: String = "gunbc_ci_plan_artifact_plan"
data regen_floor_plan_function: String = "gunbc_ci_regen_floor_plan"
data plan_function_string_projection_note: String = "These two are the NAME PROJECTION of gunbc.cli_invoke PlanFunction, not a second authority. The coproduct is where the roster is closed; these exist because the floor's own policy predicates (v2.workflow.ci_floor_plan gunbc_ci_floor_plan_uses_batch_stop_policy, gunbc_floor_arm_time_budget_refusal_applies) compare a plan identity as a String, and the claim_executor side receives it as an argv token. Deriving them through plan_function_name keeps one authority (§3): a rename edits the coproduct's match arm and both the argv and these comparisons follow, where three independent literals were exactly the fork that let the falsifier's fifth target drift. They delete when those predicates take a PlanFunction instead of a String."

data floor_plan_function: String = plan_function_name(p: CiFloorPlan)
data plan_artifact_plan_function: String = plan_function_name(p: CiPlanArtifactPlan)

fn scheduler_invoke_with(spec: CiSpec, plan_function: String) -> String {

fn scheduler_invoke_with(spec: CiSpec, plan_function: PlanFunction) -> String {
claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: floor_plan_entry,
Expand All @@ -377,7 +383,7 @@ fn scheduler_invoke_with(spec: CiSpec, plan_function: String) -> String {
}

fn scheduler_invoke(spec: CiSpec) -> String {
scheduler_invoke_with(spec: spec, plan_function: floor_plan_function)
scheduler_invoke_with(spec: spec, plan_function: CiFloorPlan)
}

fn gunbc_ci_floor_only_script(spec: CiSpec) -> String {
Expand Down Expand Up @@ -428,7 +434,7 @@ fn gunbc_ci_regen_floor_only_script(spec: CiSpec) -> String {
concat(git_fetch_script(policy: spec.diff_policy), "\n"),
concat(
concat(ci_regen_floor_skip_shortcut_script(), "\n"),
concat(scheduler_invoke_with(spec: spec, plan_function: regen_floor_plan_function), "\n")
concat(scheduler_invoke_with(spec: spec, plan_function: CiRegenFloorPlan), "\n")
)
)
)
Expand Down
27 changes: 23 additions & 4 deletions dag/gunbc/cli_invoke.dag
Original file line number Diff line number Diff line change
Expand Up @@ -53,15 +53,34 @@ fn claim_executor_notice_title_normalized(notice_title: String?) -> String? {
}
}

type PlanFunction
= CiFloorPlan
| CiRegenFloorPlan
| CiPlanArtifactPlan
| FalsifierPlan
| FalsifierNativeCacheColdPlan

data plan_function_closed_roster_note: String = "THE CLOSED ROSTER OF PRODUCTION ClaimExecutor PLAN TARGETS, and it is a coproduct rather than a String parameter because a String is what let a plan target escape a migration that claimed to cover all of them. plan_function was an unconstrained String crossing the modeled boundary, so plan identity was carried by an argv token nothing could check: gunbc.falsifier_workflow passed the literal \"gunbc_falsifier_native_cache_cold_batches\", derived from no authority, and the 2026-07-30 WalkPlan rename — whose completeness argument was a hand-maintained count of four — could not reach it. The executor then correctly refused the stale shape on every falsifier run that armed that step.\n\nWHAT THE TYPE BUYS, stated as the guarantee rather than the intent: an inline string literal at a plan_function argument is now a TYPE ERROR, so the class that produced this incident is unwritable rather than validated (§5 construction-over-validation). The roster is closed by the coproduct, so a new production plan target cannot be authored without adding a variant, and every exhaustive match over PlanFunction — plan_function_name here, plan_variant_is_walk_plan_shaped in v2.test.claim.ci_floor_plan_witness — fails to compile until that variant is handled.\n\nTHE LIMIT OF THAT, corrected after review 46883 rejected the stronger claim this paragraph used to make. Compile-time forces an ARM TO EXIST for every variant; it does not force that arm to be EXECUTED by any witness, because the witness roster is a hand-authored list. So the guarantee is 'no target can exist unhandled', NOT 'the target set and the proof set are the same set'. The census is narrowed, not abolished, and saying otherwise would repeat the completeness failure this type exists to prevent.\n\nWHAT IT DOES NOT BUY, named rather than implied: the variant-to-plan-function-value pairing in the witness is still hand-authored, because resolving an argv token to a declaration needs the containment SymbolIndex the namespace lane is building — the type closes WHICH targets exist, not that each names a function whose declared return is WalkPlan<F>. Dissolve-on: a typed declaration reference (std.decl_ref.DeclarationRef over a resolved plan symbol) replaces the name projection, at which point plan_function_name and the witness's hand pairing both delete."

fn plan_function_name(p: PlanFunction) -> String {
match p {
CiFloorPlan => "gunbc_ci_floor_plan"
CiRegenFloorPlan => "gunbc_ci_regen_floor_plan"
CiPlanArtifactPlan => "gunbc_ci_plan_artifact_plan"
FalsifierPlan => "gunbc_falsifier_plan"
FalsifierNativeCacheColdPlan => "gunbc_falsifier_native_cache_cold_plan"
}
}

fn claim_executor_run_plan_transport_argv(
source_roots: List<String>,
plan_entry: String,
plan_function: String,
plan_function: PlanFunction,
notice_title: String?
) -> List<String> {
let base = concat(
source_root_transport_argv(roots: source_roots),
["--plan-entry", plan_entry, "--plan-function", plan_function]
["--plan-entry", plan_entry, "--plan-function", plan_function_name(p: plan_function)]
)
match claim_executor_notice_title_normalized(notice_title: notice_title) {
Present { value: title } => concat(base, ["--notice-title", title])
Expand Down Expand Up @@ -101,7 +120,7 @@ fn claim_executor_notice_title_shell_suffix(notice_title: String?) -> String {
fn claim_executor_run_plan_shell(
source_roots: List<String>,
plan_entry: String,
plan_function: String,
plan_function: PlanFunction,
notice_title: String?,
rooted: Bool
) -> String {
Expand All @@ -115,7 +134,7 @@ fn claim_executor_run_plan_shell(
concat(
concat(claim_executor_bin_shell(), flags),
concat(
concat(concat(" --plan-entry ", plan_entry), concat(" --plan-function ", plan_function)),
concat(concat(" --plan-entry ", plan_entry), concat(" --plan-function ", plan_function_name(p: plan_function))),
notice
)
)
Expand Down
3 changes: 2 additions & 1 deletion dag/gunbc/cli_services.dag
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@ module gunbc.cli_services

import std.types { FilePath, String }
import gunbc.cli_invoke {
PlanFunction,
claim_executor_run_plan_transport_argv,
claim_executor_verify_artifacts_transport_argv,
gunbc_run_transport_argv
Expand Down Expand Up @@ -52,7 +53,7 @@ service claim_executor.Executor {
bin_path: FilePath
source_roots: List<String>
plan_entry: String
plan_function: String
plan_function: PlanFunction
notice_title: String?
}
output {
Expand Down
19 changes: 12 additions & 7 deletions dag/gunbc/falsifier_workflow.dag
Original file line number Diff line number Diff line change
Expand Up @@ -23,12 +23,15 @@ import gunbc.floor_component_receipt {
floor_component_receipt_artifact_name
}
import gunbc.ci_runner_target { gunbc_ci_selected_runner_spec }
import gunbc.ci_spec { plan_artifact_plan_function }
import gunbc.merge_admission_produce { ci_repo_root_shell }
import gunbc.ci_layer_roots { witness_layer_roots }
import gunbc.cli_invoke {
CiPlanArtifactPlan,
FalsifierPlan,
FalsifierNativeCacheColdPlan,
plan_function_name,
claim_executor_run_plan_shell
}
import gunbc.merge_admission_produce { ci_repo_root_shell }
import gunbc.ci_layer_roots { witness_layer_roots }
import extdeps.languages.yaml.emit { serialize_yaml }
import extdeps.languages.yaml.gha_workflow { project_workflow_to_yaml }
import std.types { NonEmptyStr }
Expand Down Expand Up @@ -71,15 +74,15 @@ fn gunbc_falsifier_step_timeout_basis_is_measured_not_composed() -> Bool {

data gunbc_falsifier_step_timeout_note: String = "120 -> 170 (2026-07-11, run 29135185172 receipt): the first corpus-reaching cold run was TIME-killed at the 120-min step ceiling with the corpus incomplete (1970 rows, closure 1396 modules, width 1) and floor peak 16146612224 bytes against a 16GiB slot budget, still growing - so 120 censored the measurement without bounding anything real (the memory cap is the true wall). 170 lets a nightly run reach either completion (exact-labeled receipt) or the cap kill (censored-labeled receipt); both are the falsifier doing its measurement job, and the job backstop DERIVES from this value so it stretches in step. Revisit down when the resolver graph-major module split (S2a move 2) shrinks cold-resolve wall and residency."

data falsifier_plan_function: String = "gunbc_falsifier_plan"
data falsifier_plan_function: String = plan_function_name(p: FalsifierPlan)

fn falsifier_invoke() -> String {
concat(
concat("ROOT=", concat(ci_repo_root_shell(), "\n")),
claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: falsifier_plan_function,
plan_function: FalsifierPlan,
notice_title: Absent,
rooted: false
)
Expand Down Expand Up @@ -115,7 +118,7 @@ fn compile_clean_cold_control_invoke() -> String {
claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: plan_artifact_plan_function,
plan_function: CiPlanArtifactPlan,
notice_title: Absent,
rooted: false
)
Expand All @@ -138,6 +141,8 @@ fn compile_clean_cold_control_step() -> Step {
}
}

data falsifier_native_cache_cold_plan_target_note: String = "THE STEP WHOSE PLAN TARGET ESCAPED THE #7470 MIGRATION, kept as the receipt for why the target is now a typed variant instead of an argv token. Every other consumer derived its plan name from a constant, so the 2026-07-30 WalkPlan rename reached all four automatically; this step alone passed the inline literal \"gunbc_falsifier_native_cache_cold_batches\", derived from nothing, and was left behind returning a bare List<List<Runnable>>. The executor's strict parser then refused it on every one of the 8 falsifier runs that armed this step (0 successes), and it read as intermittent only because the step is skipped whenever the falsifier step fails first.\n\nThe first repair here added a naming constant beside the other four. That was still validation — it made the rename reach this site but left the next author free to type a fresh literal. The constant was therefore DELETED in the same change that introduced gunbc.cli_invoke PlanFunction: an inline literal at this argument is now a type error, so the roster is closed by construction and a String projection with no consumer would be exactly the inert carrier §2 forbids. Dissolution-on-climb (§4b): the wall replaces the lower-rung machinery rather than accumulating beside it."

data gunbc_falsifier_native_cache_cold_control_timeout_minutes: Int = 30

data gunbc_falsifier_native_cache_cold_control_note: String = "Native-cache cold control (P6 durable-cache rail, 2026-07-21): the nightly Wet emit-on-demand/self-host receipt batch re-executed with GUNBC_CI_NATIVE_CACHE_COLD_CONTROL=1, which makes emit_host_run_transport_cached ignore every .native_ready marker — the full emit+cargo+run chain runs cold on the falsifier cadence while the main falsifier_step's run of the same batch stays warm (the warm-rate receipt the per-PR enrollment decision reads). Widen-to-more-checking control arm, not an escape hatch: the env can only force the transport to do MORE work, never skip it. Mirrors compile_clean_cold_control_step."
Expand All @@ -148,7 +153,7 @@ fn native_cache_cold_control_invoke() -> String {
claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: "gunbc_falsifier_native_cache_cold_batches",
plan_function: FalsifierNativeCacheColdPlan,
notice_title: Absent,
rooted: false
)
Expand Down
9 changes: 5 additions & 4 deletions dag/test/claim/gunbc_invoke_witness_test.dag
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
module test.claim.gunbc_invoke_witness

import gunbc.cli_invoke {
CiFloorPlan,
claim_executor_run_plan_shell,
claim_executor_run_plan_transport_argv,
claim_executor_verify_artifacts_shell,
Expand Down Expand Up @@ -53,7 +54,7 @@ test fn gunbc_invoke_scheduler_matches_modeled_shell_holds() -> Bool {
let modeled = claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: "gunbc_ci_floor_plan",
plan_function: CiFloorPlan,
notice_title: Present { value: gunbc_ci_spec.notice_title },
rooted: true
)
Expand All @@ -79,7 +80,7 @@ test fn gunbc_invoke_empty_notice_title_omits_flag_holds() -> Bool {
let shell = claim_executor_run_plan_shell(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: "gunbc_ci_floor_plan",
plan_function: CiFloorPlan,
notice_title: Present { value: "" },
rooted: true
)
Expand All @@ -94,14 +95,14 @@ test fn gunbc_invoke_transport_argv_empty_notice_title_omits_flag_holds() -> Boo
let argv = claim_executor_run_plan_transport_argv(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: "gunbc_ci_floor_plan",
plan_function: CiFloorPlan,
notice_title: Present { value: "" }
)
!transport_argv_contains_flag(argv: argv, flag: "--notice-title")
&& claim_executor_run_plan_transport_argv(
source_roots: witness_layer_roots,
plan_entry: "src/v2/workflow/ci_floor_plan.dag",
plan_function: "gunbc_ci_floor_plan",
plan_function: CiFloorPlan,
notice_title: Absent
) == argv
}
Expand Down
Loading
Loading