Skip to content

Repair main: repoint rest.dag's ContentHash import to std.content_hash - #7656

Merged
briansrls merged 3 commits into
mainfrom
fix/rest-contenthash-import
Aug 2, 2026
Merged

briansrls merged 3 commits into
mainfrom
fix/rest-contenthash-import

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 2, 2026

Copy link
Copy Markdown
Contributor

main is red. This is a one-line repair, cut as its own PR so it does not wait on any lane's review queue.

The break

#7480 moved ContentHash out of std.types into std.content_hash as part of the hash-family grounding. dag/extdeps/transports/rest.dag was cut before that removal and merged after it (#7552 / #7600), so its std.types import still names a symbol that no longer exists:

dag/extdeps/transports/rest.dag:3:140: error: name 'ContentHash' not found in module 'std.types' (imported by 'extdeps.transports.rest')

This refuses resolve for every entry whose closure reaches rest.dag, which is why heal_generated_artifacts fails at main_wet on PRs that touch none of this. It is the post-cutover race class: both PRs were individually green, and the ordering produced the red.

Why the repair is mechanical rather than a modeling choice

The union ContentHash still exists on main, and std.content_hash is where every other consumer already imports it from — extdeps.docker, extdeps.container.oci.types, and others. rest.dag was simply missed.

Its two uses are RestAuthenticated.digest and RestReplayKey.input_digest. Neither is in #7480's list of carriers that must narrow to a specific family (OciDescriptor.digest, GateRosterHash, v2.std.node.Hash), so the union stays correct here. No family decision is being made in this PR.

Verification

By execution on clean origin/main plus this one line: main_wet on dag/tools/generated_artifact_gate.dag resolves the whole corpus and completes ExitSuccess, with zero generated-artifact drift — confirming the heal failure was purely the resolve error and nothing downstream had also drifted.

🤖 Generated with Claude Code

main is red. #7480 moved ContentHash out of std.types into std.content_hash as
part of the hash-family grounding, but dag/extdeps/transports/rest.dag was cut
before that removal and merged after it, so its std.types import still names a
symbol that no longer exists:

  dag/extdeps/transports/rest.dag:3:140: error: name 'ContentHash' not found in
  module 'std.types' (imported by 'extdeps.transports.rest')

That refuses resolve for every entry whose closure reaches rest.dag, which is
why the heal_generated_artifacts job fails at main_wet on unrelated PRs.

The repair is mechanical, not a modeling choice: the union ContentHash still
exists and std.content_hash is where every other consumer already imports it
from (extdeps.docker, extdeps.container.oci.types, and others on main). rest.dag
uses it at RestAuthenticated.digest and RestReplayKey.input_digest, neither of
which is in #7480's list of carriers that must narrow to a specific family, so
the union remains correct here.

Verified by execution on clean origin/main plus this line: main_wet resolves the
whole corpus and completes ExitSuccess, with zero generated-artifact drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Second half of the same post-cutover race. The ci job fails at
extdeps_scope_placement_gate_passes -> Bool(false), and the refused path is
dag/extdeps/container/oci/digest.dag: #7480 added it after
legacy_manifest_freeze_sha and enrolled it in neither scope_carrier_paths nor
scope_machinery_exempt_paths. The gate diffs freeze..HEAD, so this reds every
PR, not just the one that introduced it.

Computed rather than guessed: of the 7 .dag files added under dag/extdeps since
the freeze SHA, digest.dag is the only one absent from the frontier rosters.

It is a real external-model carrier, not machinery, so it takes the carrier
route the gate's own message prescribes: declare extdeps_model_scope and join
scope_carrier_paths. It already carries its extdeps_external_authority_anchor
(OCI image-spec descriptor.md), so only the scope declaration was missing. The
subject names OciContentDigest, which its own authority note identifies as what
the module models.

The frozen legacy manifest is deliberately NOT touched: it is remove-only, and a
post-freeze file cannot be smuggled into it.

external_model_scope_witness_test 22/22 green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot force-pushed the fix/rest-contenthash-import branch from 40e97dc to c2ccca1 Compare August 2, 2026 02:12
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Main is red on extdeps.transports.rest importing ContentHash from std.types
after #7480 moved it to std.content_hash. A dedicated repair PR (#7656) plus
#7650 and #7648 already carry the fix, and the full repair also needs the
coproduct construction in rest_exchange_replay_test.dag. Keeping #7660 scoped
to the gate rather than racing three lanes on the same file.
…ence emit defect

regen_verify_gate_passes went red because the scope declaration added to
oci/digest.dag is inside the regen input closure, so the committed generated
Rust was stale. Regenerated rather than hand-picked: exactly one generated file
changed, matching the one declaration added.

Regenerating surfaced a real emitter defect. The fully qualified self-reference
extdeps.container.oci.digest.extdeps_external_authority_anchor -- the exact form
the actions_environment precedent uses -- emits
crate::extdeps_cargo::extdeps_external_authority_anchor.clone(): the wrong
module, and a fn item rather than a call, so stage0 fails E0308. The precedent
never exercised it because actions_environment.dag is not in the regen closure.

The bare same-module reference emits correctly and is the natural spelling for a
sibling declaration, so it is not a respelling chosen to dodge an obstacle. What
would have been the workaround is picking it silently, so the defect is recorded
in the carrier with a dissolution trigger rather than left for the next author to
rediscover. The emitter defect is NOT fixed here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 1ee4053 into main Aug 2, 2026
3 checks passed
@briansrls
briansrls deleted the fix/rest-contenthash-import branch August 2, 2026 02:45
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Branch missed main's #7656 repair: ContentHash lives in std.content_hash,
not std.types. That resolve failure blocked main_wet, heal_generated_artifacts,
and the floor drift gates. Regenerated ci.yml for upload-step field order.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Fleet hold lifted: ContentHash/rest.dag repaired on main (#7656);
session_dashboard enrollment present. Ordinary merge into draft B.
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Refresh staged slice-A onto post-#7656 main before PR open.
briansrls pushed a commit that referenced this pull request Aug 2, 2026
…7663)

#7480 made ContentHash a family coproduct, so the bare string literal in
probe_invocation no longer inhabits it and the tree carried one hard
diagnostic: expected 'Coproduct(ContentHash)', got 'Primitive(String)'.
#7656 fixed rest.dag's import; this is the next error behind it.

Rehydrates through the sanctioned path named by content_hash_family_grounding_note
(as_content_hash_structural over structural_content_hash) rather than labeling
arbitrary text, preserving the same 0000000000000000 digest value so fixture
identity is unchanged.

Verified: gate-equivalent compile goes from 1 hard diagnostic to 0 blocking errors.

NOT sufficient on its own -- see the PR body: six rest_exchange_replay witnesses
are separately regressed by #7480 and are proven red by baseline.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
…olvedType.

Post-#7480/#7656 byte spans drifted so provisional admission missed sites and
emptied func_env cascaded. Re-census compile-clean + heal extras; exclude all
UnresolvedType from the typecheck_module env abort (UnlistedImportUse parity).

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
…7665

The HAND-RUST receipt opened with 'This PR touches v1_interpreter.rs',
which stopped being true when main's piecemeal heal chain (#7656/#7663/
#7665) landed the same repair and the merge dissolved this branch's
inline copy into main's factored helper. The receipt stays as the
program record of the repair's class and triggers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
Refresh onto tip with ContentHash layers repaired (#7656/#7663/#7665).
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
briansrls pushed a commit that referenced this pull request Aug 2, 2026
…loud (#7660)

* WIP: main extdeps red

* WIP: main extdeps red

* Split the extdeps scope-placement gate's two bases; make its refusal loud

The placement arm now reads origin/main...HEAD (what THIS change adds) while the
freeze arm keeps legacy_manifest_freeze_sha..HEAD (the whole post-freeze
population it inherently needs). Feeding both arms the freeze base meant one
unrostered file on main refused every open branch, so the blocked party was
never the party at fault.

Loudness: claim_executor now projects the failure-receipt companion that
cli_run has projected since the Lane B agreement work, and the companion name
derives from _passes as well as _holds. Without both, the gate witnesses were
unreachable from that channel and ten consecutive main reds reported nothing
but 'returned Bool(false)'.

* Rename observation variant off the DiffLine collision

* TEMP probe (to be reverted)

* Revert "TEMP probe (to be reverted)"

This reverts commit 77382ce.

* Correct the base-split witness note: the kernel controls cannot see the base

The renamed control asserts what it actually tests (an empty change set admits).
The base wiring is one frame above these pure fns and is covered by executing
the wet gate under a roster perturbation, recorded in the PR.

* Discharge the hand-Rust disposition for the failure-receipt projection (review 47022)

Names the lane (v1 exit), the concrete ROADMAP row (Get hand-written Rust in
this repository down to zero, authority dag/gunbc/v1_deletion_plan.dag), and
the dissolution trigger (deleted WITH claim_executor, not migrated ahead of it).

States the measurable facts rather than asserting a census movement: zero new
tracked-Rust paths, so the path-grain population is unchanged, and HandAuthoredLOC
is an explicitly deferred axis of stage0_rust_honest_frontier_projection, so there
is no line census to shrink.

* WIP: main extdeps red

* Drop the rest.dag ContentHash repair: already owned by #7656

Main is red on extdeps.transports.rest importing ContentHash from std.types
after #7480 moved it to std.content_hash. A dedicated repair PR (#7656) plus
#7650 and #7648 already carry the fix, and the full repair also needs the
coproduct construction in rest_exchange_replay_test.dag. Keeping #7660 scoped
to the gate rather than racing three lanes on the same file.

* WIP: main extdeps red

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls added a commit that referenced this pull request Aug 2, 2026
…failed auto-heal. GitHub refuses to let the App update .github/workflows/** without workflows permission, so the heal job today makes a push it KNOWS will be rejected and reds as an infrastructure accident. Do NOT grant broad workf (#7659)

* WIP: Model generated workflow drift as author-commit-required rather than fai

* Fix heal author-commit-required: parse error, ci.yml regen, witnesses.

The WIP commit left a ternary concat in ci_heal_author_commit_drift_lines
that failed to parse, blocking regen and heal_generated_artifacts. Finish
the heal-policy rename, package workflow drift as an artifact with typed
HealAuthorCommitRequired diagnostics, and regenerate ci.yml for the new
heal job steps.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix rest.dag ContentHash import and align ci.yml with emitter.

Branch missed main's #7656 repair: ContentHash lives in std.content_hash,
not std.types. That resolve failure blocked main_wet, heal_generated_artifacts,
and the floor drift gates. Regenerated ci.yml for upload-step field order.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 47123: partition heal policy, widen scaffold note.

Replace artifact_is_auto_push_eligible bool-walker with
partition_committed_by_heal_policy fold over the HealPolicy coproduct.
Update ci_heal_commit_push_shell_emit_dissolution_trigger to cover the
full enrolled heal commit shell surface (git staging, author-commit
drift detection, repair packaging) awaiting shell→intent dissolution.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls pushed a commit that referenced this pull request Aug 2, 2026
…uling 2026-08-02) (#7651)

* Generated-file conflict policy: lane charter recording the 2026-08-01 operator ruling

Four-case integration policy (deterministic projection / hand-authored
authority / keyed set-map / roster-naming-outputs), derivation chain with
.gitattributes and git config as projections never authority, commit-writer
admission with the 218dea6 reproduction as lane 1, landing order, and the
hard-reject bars.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: what is our conflict policy for generated files?

* Address review 46546: state the interim status of the invert-hand-maintained row explicitly

The amendment rides with lane 2's implementation by operator sequencing:
amending the row before the modeled policy lands would make the planning
authority assert an emitted .gitattributes while the tree's file is still
hand-authored. The charter now states the interim so no two-instructions
reading exists.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 46572: anchor lane 3's carrier in the charter's typed work set

Adds gunbc.stage0_emit_model generated_stage0_files to additional_works —
it exists on main today and is lane 3's subject. Lane 4's keyed-roster
carrier is deliberately NOT cited: it does not exist on main yet, and its
on-main admission surface (commit_gate_roster) is already anchored.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 46587: cite the invert-hand-maintained row symbolically

gunbc.plans.invert_hand_maintained invert_hand_maintained_body, not a
line number in the projected markdown — the charter's own §3 rule.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Encode the operator second-pass acceptance walls per lane and the corrected merge sequence

Lane 1: complete staged-index observation (population equality, observed
classification, bound provenance receipt, forgery REDs), writer bindings
as countable carriers. Lane 2: converge before the first Git consumer;
named countable clone-rollout carrier; typed read-back refusals; derived
stage0 paths feed merge attributes. Lane 3: refusal preserved through
supply->plan->generation->writer; located output-path collision refusal.
Lane 4: a live path-keyed carrier consumes keyed construction end-to-end;
canonical verdict never collapsed to Bool; coordinator sequencing note on
the deleted incident carrier.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Charter candidate-scoped gates + atomic landing admission (operator ruling 2026-08-02)

The merge-freshness program the conflict-policy charter named out of
scope: three verified defects (freeze-anchored placement subject with
false law text, missing landing-candidate validation, ProcessExit
evidence collapsed to Bool before FullLedger), the three-subject
observation split, the typed accumulated verdict, the
RunnableProcessExitClaim migration, the MergeQueueOnly/ALLGREEN landing
policy absorbing the existing GatingEnforced trigger, acceptance set
A-F, landing sequence with the queue-first sequencing bar, and the
coordinator's verification receipts and sharpenings. Step 0 recorded as
already discharged (session_dashboard enrolled; #7644 closed unmerged).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 46971 (commit vs tree subjects) and repair main's stale ContentHash import

IntegrationCandidate now carries base_commit/candidate_commit as the
ancestry subjects merge-base actually computes over, with candidate_tree
retained separately as the exact-tree admission subject; freeze-law
carriers follow. Also repoints dag/extdeps/transports/rest.dag's
ContentHash import to std.content_hash — main's #7480 re-home left this
module importing from std.types, which breaks main_wet's closure on any
branch (the heal job's failure here); fix identical to #7609's.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* WIP: what is our conflict policy for generated files?

* Complete the fleet heal: seed mints the grounded ContentHash, digest.dag enrolls, regen converges

Three coupled repairs riding the charter PR because main is red without
them: (1) v1_interpreter rest_bound_invocation_value minted a bare Str
input_digest while #7480's model requires the Fnv1a64(Fnv1a64Structural)
coproduct arm — every fixture-match replay witness silently failed
(model/realization fork, hidden behind main's compile error); the seed
now mints the coproduct shape (probed empirically: positional field 0).
(2) dag/extdeps/container/oci/digest.dag gains its ExternalModelScope and
scope_carrier_paths enrollment — the unenrolled-file case the operator's
verdict named live; placement gate now ExitSuccess. (3) regenerated
extdeps_container_oci_digest.rs for the new declaration; fixed point
converges. EMITTER DEFECT FLAGGED, not fixed here: the fully-qualified
module-local reference extdeps.container.oci.digest.extdeps_external_authority_anchor
emitted as crate::extdeps_cargo::... (wrong module, E0308) — first
enrolled carrier in the emitted set exposed the dotted-path resolution
class; the declaration uses the module-local spelling and the defect
belongs to the dotted-path emitter bucket.

Local receipts: replay witnesses 9/9 PASS, placement gate ExitSuccess,
dry artifact gate ExitSuccess, regen second pass clean, build 0 errors.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 47056: tree-kind carrier + HAND-RUST receipt

candidate_tree is now GitTreeObjectId — a kind-refined carrier the
implementation lane introduces in extdeps.git.object_store (which today
types even GitCommitObject.tree as generic GitObjectId; the lane
re-grounds every kind-fixed position, not a charter-local special) so a
blob or tag is unrepresentable as a landing subject. Added the HAND-RUST
GATE receipt for the v1_interpreter rest replay bridge hunk: a
model-conformance repair to an existing seed mint (no new decision
surface; dissolves with the seed's rest transport bridge), checkable by
the 6-red-then-9-green replay witness split.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 47071: DefaultBranchAudit subject is GitTreeObjectId too

Same class as the IntegrationCandidate fix — every audit/admission
subject in the charter is a tree by construction. Swept the doc for
remaining generic GitObjectId type positions; the three other mentions
are prose about the generic carrier itself.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Address review 47097: verdict total over both surfaces, subject on the wrapper, receipt names lane + ROADMAP row

ExtdepsScopeVerdict gains DefaultBranchAuditCovered (the audit surface
had no faithful success result) and ExtdepsScopeRefused carries the run's
ExtdepsScopeEvaluation subject once at the wrapper — refusal arms keep
only law-local facts, the six duplicated per-arm candidate fields delete,
and the rendering law now names identities that flow forward rather than
demanding base/tree on arms that never carried them. HAND-RUST receipt
gains the explicit-deferral header naming the v1-exit lane (zero
hand-maintained Rust finish line) and the witness-realization rest-bridge
trigger, matching the compile-clean-forcecheck receipt form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Receipt records its landing vehicle: the interpreter hunk merged via #7665

The HAND-RUST receipt opened with 'This PR touches v1_interpreter.rs',
which stopped being true when main's piecemeal heal chain (#7656/#7663/
#7665) landed the same repair and the merge dissolved this branch's
inline copy into main's factored helper. The receipt stays as the
program record of the repair's class and triggers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
…olvedType.

Post-#7480/#7656 byte spans drifted so provisional admission missed sites and
emptied func_env cascaded. Re-census compile-clean + heal extras; exclude all
UnresolvedType from the typecheck_module env abort (UnlistedImportUse parity).

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 2, 2026
…olvedType.

Post-#7480/#7656 byte spans drifted so provisional admission missed sites and
emptied func_env cascaded. Re-census compile-clean + heal extras; exclude all
UnresolvedType from the typecheck_module env abort (UnlistedImportUse parity).

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant