Skip to content

Retire path location as sufficient admission for new witnesses; freeze and count the legacy path-only debt - #7804

Merged
briansrls merged 7 commits into
mainfrom
session/merry-raven-690
Aug 5, 2026
Merged

briansrls merged 7 commits into
mainfrom
session/merry-raven-690

Conversation

@briansrls

@briansrls briansrls commented Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

Scope, stated at what it achieves: retire path location as sufficient admission for a NEW witness, and freeze and count the legacy path-only debt. long/ remains an organizational home until that population reaches zero.

The defect

A directory was deciding an admission question, and the answer was always yes.

A witness leaves per-PR discovery for one of two reasons: an exact admission naming the cadence that executes it, or a broad path policy row. The admission side was already correct — explicit_witness_admission_cadence_executes refuses OfflineLocalRecipe on an admission row precisely so an admission cannot satisfy the has-a-consumer wall while executing nowhere. The path side had no such wall: witness_admission_refusal_for_row refused only NoConsumer, so a row an offline directory claimed was admitted unconditionally.

The live transformation that permitted:

a required per-PR witness goes over the 5s fast-lane budget → its file is moved under test/claim/long/ → it leaves per-PR discovery → no cadence row is added → nothing executes it → and admission holds.

Green CI, zero executed coverage, source file left behind. That is not deferral; it is deletion of the evidence with the file retained.

Specimen, verified by execution

gunbc#7762 commit 0cfd199f8 — "Move frontier probe closure matrix to long lane to fix CI fast-lane budget failures" — renamed src/v2/test/claim/workflow/frontier_probe_closure_matrix_test.dag to src/v2/test/claim/long/frontier_probe_closure_matrix_test.dag. Thirteen test fns crossed in that rename. What the commit added beside them was a data row holding a claim_batch command line — prose naming a recipe, not a consumer that runs — and the file appeared in no cadence roster. A later commit on the same branch split eight of the thirteen back onto the per-PR path, which is the right repair and also the proof that nothing mechanical forced it: the split happened because a reviewer looked, and the admission wall said yes either way.

The backstop that was not one

long_lane_exclusion_note and the Form-C blessing in roster_registry both justified the long/ home on the ground that the 5s eval deadline makes an over-budget fast-lane witness unwritable-in-place. That is false and both are retracted here. The deadline is evaluated only while a witness runs, and relocation is exactly the act that stops it running — the backstop is disarmed by the move it was supposed to govern. BudgetExceeded stays what it is: an interruption plus a measured lower bound on cost, never a semantic verdict, and never discharged by causing a relocation.

Scope: the hole is the fallback, not the directory

The brief named long/; the measurement says the defect is the OfflineLocalRecipe path-policy fallback wherever it applies. test/claim/execution/ and test/manual/ carry the identical arm.

population identities entries
admitted by path policy alone, no executing consumer 701 152
…of which under test/claim/long/ 279 63
…other offline paths (execution/, manual/, enforcement/, file-grain rows) 422 89

(The first measurement was 732/155. It came down when the third consumer source below was honored — 31 of those identities already run.)

Freezing only long/ would have relocated the hatch rather than closed it — 60% of the population is outside it.

Two axes, because tolerated is not covered

The first shape of this wall returned one success arm for both — the same arm a real cadence returns — for a frozen legacy row, and then read the green live gate as evidence that every current row is admitted. A frozen row has no executing consumer; that is the entire content of its debt. Freezing establishes that the unexecuted hole existed at the cut and cannot grow. It does not establish coverage. Returning success made the same fact answer differently depending on which door it entered: exact function-grain admission correctly refuses OfflineLocalRecipe because a local recipe is not an executing cadence, while path policy was returning success for exactly that. (Operator ruling, blocking.)

WitnessExecutionStanding = WitnessHasExecutingConsumer{cadence}   -- covered
                         | LegacyFrozenPathDeferral               -- tolerated, NOT covered
                         | UnclassifiedPathDeferral               -- refused (the forward hole)
                         | UnexecutedDeferredWitness              -- refused (nothing claims it)

FrozenBaselineStanding   = Allowed | Shrank | Grew | Stale        -- a property of the ROSTER

The coverage gate admits only the first arm, so the dark population never reads as covered and anything downstream asking is this behavior exercised receives no. The floor gate additionally tolerates LegacyFrozenPathDeferral while the baseline axis holds — so the tree stays green through the migration without anything claiming those rows execute. The deferred-discovery receipt now prints the frozen population explicitly as unexecuted debt.

The seed realization is accounted for

505 production lines and 364 test lines entered cli_run.rs (against 30 removed; the first pair authored here, 487/371, was measured before the handbacks were amended in and is corrected in the carrier with its drift recorded rather than overwritten), the largest hand-maintained Rust wall in the program, already growing against its own hollowing plan. A modeled policy does not exempt its realization. gunbc.cli_run_witness_deferral_freeze_scaffold carries the typed Scaffold disposition, the measured landing delta, and an ordered dissolution: seed scan → emitted/native projection (the parse helpers go) → the classification path (the rest goes); or the frozen population reaching zero, which deletes all of it with the freeze itself.

What landed

  1. std.witness_admission gains UnclassifiedPathDeferral — a refusal arm, sibling to UnexecutedDeferredWitness. They stay separate because the remedies differ: one matches no policy at all, the other was claimed by a directory. One arm would have hidden 732 identities behind a nearly-empty class.
  2. gunbc.witness_deferral_freeze — the frozen legacy population at (entry, function) grain. Enumerated, never a predicate: a new file under long/ does not join it and refuses on its first PR.
  3. Forward join — an offline-classified witness outside the freeze and outside gunbc.explicit_witness_admission refuses.
  4. Backward join — a frozen row naming a witness the tree no longer carries (file gone, decl gone, or path no longer offline-classified) refuses as StaleFrozenPathDeferral, so a row cannot outlive its witness and be inherited by the next name.
  5. Third consumer source honored — commit_gate_roster's CommitWitnessClaim rows project into explicit entries, and explicit rows merge after discovery with no exclusion filter, so an enrolled witness under an offline path executes even though the path excludes it. The first revision of this wall read only two authorities and would have refused 31 identities that already run — fail-closed, and still a wrong answer. Only surfaces that execute admit (GitPrePushHook has been fmt-only since 2026-07-25). Found by a manager's correction to a prediction in this body, not by a test.
  6. Monotonicity gate — the roster may only shrink: gaining identities against the diff baseline refuses (FrozenPathDeferralGrew). Without this the ratchet is diligence, not construction — an author could append a row in the same PR that adds the witness. An unresolvable baseline refuses rather than passing unchecked; the single non-refusing arm is the roster being absent at base, which is this change and is unreachable once the roster is on main.

test/claim/long/ still organizes the files. It no longer answers the admission question.

A frozen row asserts membership, not a verdict

It carries no cause, purpose, cost or consumer — deliberately, because none exists. At least three dispositions live in the frozen population and they owe different things: a permanent regression witness owes a scheduled consumer (an offline recipe establishes that this head was tested once, never that a later regression will be observed); a terminating one-shot survey owes no cadence at all — it has no later, and demanding one would enroll a job whose whole purpose is to be deleted; a witness with no discriminating red owes deletion rather than either. The mechanism cannot yet tell them apart, so it labels none of them, and the live terminating specimen already in the roster is named in the carrier. Typing that arm is stricter than typing a cadence, not looser: a one-shot owes a pinned subject, a mechanically checkable dissolution and a deadline after which an undissolved one-shot refuses — without the deadline every permanent witness simply claims to be a one-shot.

Green by execution

17 .dag witnesses, fixture-shaped and cheap — mechanism on fixtures, per the decomposition rule this PR's own wall enforces (a census may be irreducible; a mechanism never is). Every positive claim holds the row, the pattern and the exclusion verdict fixed and moves only freeze membership — the fact the wall added:

PASS witness_deferral_freeze_unfrozen_offline_row_refuses
PASS witness_deferral_freeze_frozen_row_is_not_covered
PASS witness_deferral_freeze_frozen_row_is_tolerated_by_the_floor
PASS witness_deferral_freeze_grown_baseline_withdraws_the_toleration
PASS witness_deferral_freeze_empty_roster_refuses_the_same_row
PASS witness_deferral_freeze_fixture_path_is_unaffected
PASS witness_deferral_freeze_unclaimed_path_stays_unexecuted_deferred
PASS witness_deferral_freeze_included_row_is_never_refused
PASS witness_deferral_freeze_join_is_by_identity_not_by_entry
PASS witness_deferral_freeze_live_rows_join_the_discovered_population
PASS witness_deferral_freeze_departed_row_fails_the_join
PASS witness_deferral_freeze_empty_function_list_is_malformed
PASS witness_deferral_freeze_live_roster_is_well_formed
PASS witness_deferral_freeze_commit_roster_enrollment_admits
PASS witness_deferral_freeze_commit_roster_row_is_not_frozen
PASS witness_deferral_freeze_rust_realization_is_declared_scaffold
PASS witness_deferral_freeze_rust_realization_names_a_dissolution

9 Rust controls, including appending_a_row_to_the_live_roster_source_refuses — the discriminating case over the real roster, not a hand-made pair.

Live gates, against the real tree: witness_admission_deferred_rows_refuse_none_and_frozen_debt_is_counted_uncovered — deliberately not named "every deferred row has a consumer", which is what the first version asserted and was false; what holds is that no row refuses and the tolerated population is counted as uncovered and frozen_path_deferral_roster_carries_no_stale_rows (every frozen identity still exists and is still offline-classified).

Executed refusal receipt — one freeze row planted in the working tree, live git baseline gate run:

thread 'frozen_roster_monotonicity_reads_a_real_baseline' panicked:
the roster cannot have grown against itself:
["src/v2/test/claim/long/relocated_matrix_test.dag::relocated_matrix_holds"]

Row reverted; gate green again.

Adjacent suites unaffected: witness_admission_test 15/15, exact_witness_admission_witness_test 9/9, witness_exclusion_reconciliation_test 8/8, roster_registry_test 5/5, generated_artifact_drift_test 7/7.

What this does NOT claim

  • Modified-in-place is not covered. Identity grain refuses a new function under an offline path; it cannot see a frozen function whose body grew a corpus scan, because the identity did not change. Next trigger: the cost half — a per-witness declared cost envelope the measured eval is checked against. A per-file content pin was rejected as a stand-in: a hash an author must hand-bump on every unrelated touch is a change detector, and change detectors train the blind bump.
  • No purpose taxonomy yet. A frozen row records identity only. That these 732 identities were admitted with no declared purpose, cost or consumer is the debt — the taxonomy is the next slice.
  • frozen_path_deferral_identity_count is a receipt, never an oracle. The roster was authored from the current tree, so a count equality would compare a measurement to a copy of itself and go green on any pair of compensating edits. Completeness here is the identity join, in both directions. The in-carrier note says so, load-bearing.
  • One adjacent case named, not closed: a falsifier_self_host_wet row reaches WitnessAdmissionHolds through the explicit arm while its cadence is inactive. Same shape one layer in, but it is a counted roster with a named owner and a dated trigger rather than a directory admitting silently.

Dissolution

The freeze reaching empty deletes the path-policy pass-through arm, the test/claim/long/ dir row and this roster together — at which point OfflineLocalRecipe stops being an admission answer at all.

Brian Searls and others added 3 commits August 4, 2026 19:12
…lation and refuse new unclassified deferrals

A directory was deciding an admission question, and the answer was always
yes. A witness over the five-second fast-lane budget could be moved under
test/claim/long/, leave per-PR discovery, gain no cadence row, execute
nowhere, and still pass admission -- because the deferred-row refusal
fired only on NoConsumer while OfflineLocalRecipe, the verdict a broad
path pattern produces, was accepted unconditionally.

Specimen, verified by execution: gunbc#7762 commit 0cfd199 relocated a
thirteen-function discriminating matrix into test/claim/long/ under the
title "fix CI fast-lane budget failures", adding a claim_batch command
line as a data row and no cadence. The eval-deadline backstop the long/
home was blessed on does not cover this: the deadline is evaluated only
while a witness runs, and relocation is exactly what stops it running.
Both places that carried that blessing are corrected here.

- std.witness_admission gains UnclassifiedPathDeferral, a refusal arm
  distinct from UnexecutedDeferredWitness because the remedies differ.
- gunbc.witness_deferral_freeze enumerates the 732 (entry, function)
  identities across 155 entries that path policy had already admitted --
  an enumerated set, never a predicate, so a new file under long/ does
  not join it.
- The join runs in both directions: an offline-classified witness outside
  the freeze and outside gunbc.explicit_witness_admission refuses, and a
  frozen row the tree no longer carries refuses as stale.
- The roster may only shrink: growth against the diff baseline refuses,
  and an unresolvable baseline refuses rather than passing unchecked.

Scope note: the hole is the OfflineLocalRecipe fallback wherever it
applies, not the directory. 303 of the 732 identities are under long/;
freezing only long/ would have relocated the hatch to test/claim/execution/
and test/manual/, which carry the identical arm.

Green by execution: 11 .dag fixture witnesses (4ms total eval), 9 Rust
controls including the perturbation of the live roster source, and the
live gates witness_admission_deferred_rows_have_consumers and the stale
join against the real tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Witness cost/purpose/admission: retire long/ as authority Retire long/ as an admission authority: freeze the path-deferral population, refuse new unclassified deferrals Aug 4, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 4, 2026 20:20
@cursor

cursor Bot commented Aug 4, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

…cuting consumer

The first revision of the wall read two authorities for "does anything
execute this witness" and there are three. commit_gate_roster carries
CommitWitnessClaim rows at check_fn grain; project_ci_floor_witness_entries
and project_falsifier_witness_entries turn them into explicit entries, and
explicit rows merge after discovery with no exclusion filter -- so an
enrolled witness under an offline path executes even though the path
excludes it. ci_layer_roots enforcement_coverage_exclusion_note already
records the same fact from the other side: offlining such a witness took
TWO edits, the exclusion row and the deletion of its enrollment.

Measured: 31 of the frozen identities are enrolled on GithubActionsCiJob
today. Without this the wall would have refused witnesses that already
run -- fail-closed, and still a wrong answer, landing on unrelated lanes
as a surprise red.

- The host explicit-consumer key set reads commit_workflow, gated on
  surfaces that actually execute (GitPrePushHook has been fmt-only since
  2026-07-25 and runs no witness, so it does not admit).
- The .dag admission fold consults the same projections. The cadence
  vocabulary is deliberately not widened: WitnessConsumerCadence has no
  enrollment-surface arm, and minting one would ripple through every total
  match over it for a fact only the admission fold reads. Named, with its
  dissolve-on.
- The freeze sheds the 31 now-attributed identities: 732 -> 701 across 152
  entries. An enrolled witness must not ALSO be frozen, or one fact is
  restated in two places.

Also, per review of the population being frozen: a frozen row asserts
MEMBERSHIP at the freeze point and no verdict. At least three dispositions
live in it -- a permanent regression witness owes a cadence, a terminating
one-shot survey owes none (it has no later; it owes a pinned subject, a
checkable dissolution and a deadline), and a witness with no discriminating
red owes deletion. The mechanism cannot yet tell them apart, so it labels
none of them; the live terminating specimen already in the roster is named.

Green by execution: 13 .dag witnesses (two new, on a LIVE enrolled row
rather than a fixture, since the defect was precisely that the live
authority was unread), 11 Rust controls including the executing-surface
filter, and the four adjacent admission suites unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Retire long/ as an admission authority: freeze the path-deferral population, refuse new unclassified deferrals Retire path location as sufficient admission for new witnesses; freeze and count the legacy path-only debt Aug 4, 2026
…the seed realization

Two required handbacks from the operator's REQUEST CHANGES on this PR.

ONE -- "allowed to remain" was being reported as "has an executing
consumer". The first shape returned WitnessAdmissionHolds -- the same arm
a real cadence returns -- for a frozen legacy row, and then read the green
live gate as evidence that every current row is admitted. But a frozen row
has NO executing consumer; that is the entire content of its debt. The
same fact was answering differently depending on which door it entered:
exact function-grain admission correctly refuses OfflineLocalRecipe
because a local recipe is not an executing cadence, while path policy was
returning success for exactly that.

Admission now derives from two independent axes:

  WitnessExecutionStanding  = WitnessHasExecutingConsumer{cadence}
                            | LegacyFrozenPathDeferral
                            | UnclassifiedPathDeferral
                            | UnexecutedDeferredWitness
  FrozenBaselineStanding    = Allowed | Shrank | Grew | Stale

The COVERAGE gate admits only the first arm, so the dark population never
reads as covered and anything downstream asking "is this behavior
exercised" receives no. The FLOOR gate additionally tolerates
LegacyFrozenPathDeferral while the baseline axis holds, so the tree stays
green under the migration ratchet without anything claiming those rows
execute. The host mirrors the split arm for arm, and the deferred-discovery
receipt now reports the frozen population explicitly as unexecuted debt
rather than folding it into a green count.

TWO -- the seed realization is accounted for. 487 production lines and 371
test lines entered cli_run.rs, the largest hand-maintained Rust wall in
the program, already growing against its own hollowing plan. The .dag side
being the authority does not exempt the realization.
gunbc.cli_run_witness_deferral_freeze_scaffold carries the typed Scaffold
disposition, the measured landing delta, and an ordered dissolution: seed
scan, then emitted/native projection (the parse helpers go), then the
classification path (the rest goes) -- or the frozen population reaching
zero, which deletes all of it with the freeze itself.

Scope restated to what it achieves: retire path location as sufficient
admission for NEW witnesses, and freeze and count the legacy path-only
debt. long/ remains an organizational home until that population is zero.

Green by execution: 17 .dag witnesses (frozen row not covered, same row
tolerated by the floor, grown baseline withdraws the toleration), 11 Rust
controls, and the live gate renamed to what it actually proves -- no row
refuses, and the tolerated population is counted uncovered.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/merry-raven-690 branch from 365a98d to 8646958 Compare August 4, 2026 21:34
…sidues

The scaffold carrier claimed 487 production + 371 test added lines in
cli_run.rs. The tree holds 505 + 364 added against 30 removed. The original
pair was measured before the two operator handbacks were amended into this
branch and never re-measured, so it understated the total and misallocated
between the halves.

Nothing consumed those figures, which is exactly why it survived: a stated
fact with no consumer has no mechanism to notice itself going stale. The row
asserts its accounting "is a fact rather than an impression", so a wrong
figure there is this PR's own subject one layer in.

The carrier now states the corrected figures, carries the removals as their
own row, records the measurement recipe so the number is reproducible rather
than merely asserted, and keeps the wrong values visible with why they
drifted instead of silently overwriting them.

Surfaced by review 48200 quoting a 897-line growth: at the head that review
read, the diff was 867 added + 30 removed, so its figure was lines TOUCHED
and was never in conflict. Answering it is what exposed the drift, which is
the argument for naming both halves.

Two residues ride along, both previously deferred as not worth a head:
- the DeferredAdmissionCause doc comment named WitnessAdmissionRefusal, a
  type the handback retired, and overstated the correspondence; it carries
  only the two REFUSING arms of WitnessExecutionStanding
- an unused `import std.types { Int }` in v2.workflow.witness_admission

Verified: witness_admission 15/15, witness_deferral_freeze 17/17,
cargo check --workspace clean, cargo fmt --check clean.

Whole-tree `gunbc compile --target dag` reds with 9 diagnostics in
rust_test_fixtures.dag, lens/enforcement/receipts.dag and 06_translate.dag —
reproduced byte-identically at origin/main b56ae60, so pre-existing and
outside this diff. Reported separately.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 278b282 into main Aug 5, 2026
5 checks passed
@briansrls
briansrls deleted the session/merry-raven-690 branch August 5, 2026 03:10
gunbai-bot Bot pushed a commit that referenced this pull request Aug 5, 2026
Operator correction 2026-08-05: 5000ms is the executor fail-stop, not a
witness budget; the migration threshold is 500ms, and re-homing a file to
long/ is not a migration unless the operation is inherently external or
whole-system. This note previously cited an "operator 5s fast-lane rule"
as its justification, which read the policy wrongly.

The 11 rows enrolled in the previous commit stay enrolled: the long dir is
excluded from per-PR discovery, so those witnesses previously executed
NOWHERE, and enrolled-and-scheduled dominates unscheduled. Confirmed by
still-bat-561 and loyal-ram-550 independently, the latter citing #7804's
operator-signed note that "ALLOWED TO REMAIN and HAS AN EXECUTING CONSUMER
are different facts". What changes is the claim being made: enrollment is
no longer describable as completed migration.

Records the cost class (expensive graph/load/resolve setup -> acquire the
population once), the measurement that bounds any plan (682 of 930 entries
resolve at 1000ms+, max 11223ms, shared per file -- so splitting a witness
makes one resolve serve more rows, it does not make the entry cheaper),
and the real migration shape (recursive composition, precedent #7791).

The dissolve_on strings on the rows still cite the 5000ms kill cap and are
wrong today. Deliberately not mass re-pointed here: that converts
dissolvable rows into permanent residents with no migration plan behind
them, and belongs to the single change that lands the typed 500ms
threshold (merry-raven-690's lane).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant