Repository navigation
Retire path location as sufficient admission for new witnesses; freeze and count the legacy path-only debt - #7804
Merged
Merged
Conversation
…lation and refuse new unclassified deferrals A directory was deciding an admission question, and the answer was always yes. A witness over the five-second fast-lane budget could be moved under test/claim/long/, leave per-PR discovery, gain no cadence row, execute nowhere, and still pass admission -- because the deferred-row refusal fired only on NoConsumer while OfflineLocalRecipe, the verdict a broad path pattern produces, was accepted unconditionally. Specimen, verified by execution: gunbc#7762 commit 0cfd199 relocated a thirteen-function discriminating matrix into test/claim/long/ under the title "fix CI fast-lane budget failures", adding a claim_batch command line as a data row and no cadence. The eval-deadline backstop the long/ home was blessed on does not cover this: the deadline is evaluated only while a witness runs, and relocation is exactly what stops it running. Both places that carried that blessing are corrected here. - std.witness_admission gains UnclassifiedPathDeferral, a refusal arm distinct from UnexecutedDeferredWitness because the remedies differ. - gunbc.witness_deferral_freeze enumerates the 732 (entry, function) identities across 155 entries that path policy had already admitted -- an enumerated set, never a predicate, so a new file under long/ does not join it. - The join runs in both directions: an offline-classified witness outside the freeze and outside gunbc.explicit_witness_admission refuses, and a frozen row the tree no longer carries refuses as stale. - The roster may only shrink: growth against the diff baseline refuses, and an unresolvable baseline refuses rather than passing unchecked. Scope note: the hole is the OfflineLocalRecipe fallback wherever it applies, not the directory. 303 of the 732 identities are under long/; freezing only long/ would have relocated the hatch to test/claim/execution/ and test/manual/, which carry the identical arm. Green by execution: 11 .dag fixture witnesses (4ms total eval), 9 Rust controls including the perturbation of the live roster source, and the live gates witness_admission_deferred_rows_have_consumers and the stale join against the real tree. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Merged
3 of 4 tasks
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
…cuting consumer The first revision of the wall read two authorities for "does anything execute this witness" and there are three. commit_gate_roster carries CommitWitnessClaim rows at check_fn grain; project_ci_floor_witness_entries and project_falsifier_witness_entries turn them into explicit entries, and explicit rows merge after discovery with no exclusion filter -- so an enrolled witness under an offline path executes even though the path excludes it. ci_layer_roots enforcement_coverage_exclusion_note already records the same fact from the other side: offlining such a witness took TWO edits, the exclusion row and the deletion of its enrollment. Measured: 31 of the frozen identities are enrolled on GithubActionsCiJob today. Without this the wall would have refused witnesses that already run -- fail-closed, and still a wrong answer, landing on unrelated lanes as a surprise red. - The host explicit-consumer key set reads commit_workflow, gated on surfaces that actually execute (GitPrePushHook has been fmt-only since 2026-07-25 and runs no witness, so it does not admit). - The .dag admission fold consults the same projections. The cadence vocabulary is deliberately not widened: WitnessConsumerCadence has no enrollment-surface arm, and minting one would ripple through every total match over it for a fact only the admission fold reads. Named, with its dissolve-on. - The freeze sheds the 31 now-attributed identities: 732 -> 701 across 152 entries. An enrolled witness must not ALSO be frozen, or one fact is restated in two places. Also, per review of the population being frozen: a frozen row asserts MEMBERSHIP at the freeze point and no verdict. At least three dispositions live in it -- a permanent regression witness owes a cadence, a terminating one-shot survey owes none (it has no later; it owes a pinned subject, a checkable dissolution and a deadline), and a witness with no discriminating red owes deletion. The mechanism cannot yet tell them apart, so it labels none of them; the live terminating specimen already in the roster is named. Green by execution: 13 .dag witnesses (two new, on a LIVE enrolled row rather than a fixture, since the defect was precisely that the live authority was unread), 11 Rust controls including the executing-surface filter, and the four adjacent admission suites unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…the seed realization
Two required handbacks from the operator's REQUEST CHANGES on this PR.
ONE -- "allowed to remain" was being reported as "has an executing
consumer". The first shape returned WitnessAdmissionHolds -- the same arm
a real cadence returns -- for a frozen legacy row, and then read the green
live gate as evidence that every current row is admitted. But a frozen row
has NO executing consumer; that is the entire content of its debt. The
same fact was answering differently depending on which door it entered:
exact function-grain admission correctly refuses OfflineLocalRecipe
because a local recipe is not an executing cadence, while path policy was
returning success for exactly that.
Admission now derives from two independent axes:
WitnessExecutionStanding = WitnessHasExecutingConsumer{cadence}
| LegacyFrozenPathDeferral
| UnclassifiedPathDeferral
| UnexecutedDeferredWitness
FrozenBaselineStanding = Allowed | Shrank | Grew | Stale
The COVERAGE gate admits only the first arm, so the dark population never
reads as covered and anything downstream asking "is this behavior
exercised" receives no. The FLOOR gate additionally tolerates
LegacyFrozenPathDeferral while the baseline axis holds, so the tree stays
green under the migration ratchet without anything claiming those rows
execute. The host mirrors the split arm for arm, and the deferred-discovery
receipt now reports the frozen population explicitly as unexecuted debt
rather than folding it into a green count.
TWO -- the seed realization is accounted for. 487 production lines and 371
test lines entered cli_run.rs, the largest hand-maintained Rust wall in
the program, already growing against its own hollowing plan. The .dag side
being the authority does not exempt the realization.
gunbc.cli_run_witness_deferral_freeze_scaffold carries the typed Scaffold
disposition, the measured landing delta, and an ordered dissolution: seed
scan, then emitted/native projection (the parse helpers go), then the
classification path (the rest goes) -- or the frozen population reaching
zero, which deletes all of it with the freeze itself.
Scope restated to what it achieves: retire path location as sufficient
admission for NEW witnesses, and freeze and count the legacy path-only
debt. long/ remains an organizational home until that population is zero.
Green by execution: 17 .dag witnesses (frozen row not covered, same row
tolerated by the floor, grown baseline withdraws the toleration), 11 Rust
controls, and the live gate renamed to what it actually proves -- no row
refuses, and the tolerated population is counted uncovered.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot
Bot
force-pushed
the
session/merry-raven-690
branch
from
August 4, 2026 21:34
365a98d to
8646958
Compare
…sidues
The scaffold carrier claimed 487 production + 371 test added lines in
cli_run.rs. The tree holds 505 + 364 added against 30 removed. The original
pair was measured before the two operator handbacks were amended into this
branch and never re-measured, so it understated the total and misallocated
between the halves.
Nothing consumed those figures, which is exactly why it survived: a stated
fact with no consumer has no mechanism to notice itself going stale. The row
asserts its accounting "is a fact rather than an impression", so a wrong
figure there is this PR's own subject one layer in.
The carrier now states the corrected figures, carries the removals as their
own row, records the measurement recipe so the number is reproducible rather
than merely asserted, and keeps the wrong values visible with why they
drifted instead of silently overwriting them.
Surfaced by review 48200 quoting a 897-line growth: at the head that review
read, the diff was 867 added + 30 removed, so its figure was lines TOUCHED
and was never in conflict. Answering it is what exposed the drift, which is
the argument for naming both halves.
Two residues ride along, both previously deferred as not worth a head:
- the DeferredAdmissionCause doc comment named WitnessAdmissionRefusal, a
type the handback retired, and overstated the correspondence; it carries
only the two REFUSING arms of WitnessExecutionStanding
- an unused `import std.types { Int }` in v2.workflow.witness_admission
Verified: witness_admission 15/15, witness_deferral_freeze 17/17,
cargo check --workspace clean, cargo fmt --check clean.
Whole-tree `gunbc compile --target dag` reds with 9 diagnostics in
rust_test_fixtures.dag, lens/enforcement/receipts.dag and 06_translate.dag —
reproduced byte-identically at origin/main b56ae60, so pre-existing and
outside this diff. Reported separately.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 5, 2026
Operator correction 2026-08-05: 5000ms is the executor fail-stop, not a witness budget; the migration threshold is 500ms, and re-homing a file to long/ is not a migration unless the operation is inherently external or whole-system. This note previously cited an "operator 5s fast-lane rule" as its justification, which read the policy wrongly. The 11 rows enrolled in the previous commit stay enrolled: the long dir is excluded from per-PR discovery, so those witnesses previously executed NOWHERE, and enrolled-and-scheduled dominates unscheduled. Confirmed by still-bat-561 and loyal-ram-550 independently, the latter citing #7804's operator-signed note that "ALLOWED TO REMAIN and HAS AN EXECUTING CONSUMER are different facts". What changes is the claim being made: enrollment is no longer describable as completed migration. Records the cost class (expensive graph/load/resolve setup -> acquire the population once), the measurement that bounds any plan (682 of 930 entries resolve at 1000ms+, max 11223ms, shared per file -- so splitting a witness makes one resolve serve more rows, it does not make the entry cheaper), and the real migration shape (recursive composition, precedent #7791). The dissolve_on strings on the rows still cite the 5000ms kill cap and are wrong today. Deliberately not mass re-pointed here: that converts dissolvable rows into permanent residents with no migration plan behind them, and belongs to the single change that lands the typed 500ms threshold (merry-raven-690's lane). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 5, 2026
9 of 11 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The defect
A directory was deciding an admission question, and the answer was always yes.
A witness leaves per-PR discovery for one of two reasons: an exact admission naming the cadence that executes it, or a broad path policy row. The admission side was already correct —
explicit_witness_admission_cadence_executesrefusesOfflineLocalRecipeon an admission row precisely so an admission cannot satisfy the has-a-consumer wall while executing nowhere. The path side had no such wall:witness_admission_refusal_for_rowrefused onlyNoConsumer, so a row an offline directory claimed was admitted unconditionally.The live transformation that permitted:
Green CI, zero executed coverage, source file left behind. That is not deferral; it is deletion of the evidence with the file retained.
Specimen, verified by execution
gunbc#7762commit0cfd199f8— "Move frontier probe closure matrix to long lane to fix CI fast-lane budget failures" — renamedsrc/v2/test/claim/workflow/frontier_probe_closure_matrix_test.dagtosrc/v2/test/claim/long/frontier_probe_closure_matrix_test.dag. Thirteentest fns crossed in that rename. What the commit added beside them was adatarow holding aclaim_batchcommand line — prose naming a recipe, not a consumer that runs — and the file appeared in no cadence roster. A later commit on the same branch split eight of the thirteen back onto the per-PR path, which is the right repair and also the proof that nothing mechanical forced it: the split happened because a reviewer looked, and the admission wall said yes either way.The backstop that was not one
long_lane_exclusion_noteand the Form-C blessing inroster_registryboth justified thelong/home on the ground that the 5s eval deadline makes an over-budget fast-lane witness unwritable-in-place. That is false and both are retracted here. The deadline is evaluated only while a witness runs, and relocation is exactly the act that stops it running — the backstop is disarmed by the move it was supposed to govern.BudgetExceededstays what it is: an interruption plus a measured lower bound on cost, never a semantic verdict, and never discharged by causing a relocation.Scope: the hole is the fallback, not the directory
The brief named
long/; the measurement says the defect is theOfflineLocalRecipepath-policy fallback wherever it applies.test/claim/execution/andtest/manual/carry the identical arm.test/claim/long/execution/,manual/,enforcement/, file-grain rows)(The first measurement was 732/155. It came down when the third consumer source below was honored — 31 of those identities already run.)
Freezing only
long/would have relocated the hatch rather than closed it — 60% of the population is outside it.Two axes, because tolerated is not covered
The first shape of this wall returned one success arm for both — the same arm a real cadence returns — for a frozen legacy row, and then read the green live gate as evidence that every current row is admitted. A frozen row has no executing consumer; that is the entire content of its debt. Freezing establishes that the unexecuted hole existed at the cut and cannot grow. It does not establish coverage. Returning success made the same fact answer differently depending on which door it entered: exact function-grain admission correctly refuses
OfflineLocalRecipebecause a local recipe is not an executing cadence, while path policy was returning success for exactly that. (Operator ruling, blocking.)The coverage gate admits only the first arm, so the dark population never reads as covered and anything downstream asking is this behavior exercised receives no. The floor gate additionally tolerates
LegacyFrozenPathDeferralwhile the baseline axis holds — so the tree stays green through the migration without anything claiming those rows execute. The deferred-discovery receipt now prints the frozen population explicitly as unexecuted debt.The seed realization is accounted for
505 production lines and 364 test lines entered
cli_run.rs(against 30 removed; the first pair authored here, 487/371, was measured before the handbacks were amended in and is corrected in the carrier with its drift recorded rather than overwritten), the largest hand-maintained Rust wall in the program, already growing against its own hollowing plan. A modeled policy does not exempt its realization.gunbc.cli_run_witness_deferral_freeze_scaffoldcarries the typedScaffolddisposition, the measured landing delta, and an ordered dissolution: seed scan → emitted/native projection (the parse helpers go) → the classification path (the rest goes); or the frozen population reaching zero, which deletes all of it with the freeze itself.What landed
std.witness_admissiongainsUnclassifiedPathDeferral— a refusal arm, sibling toUnexecutedDeferredWitness. They stay separate because the remedies differ: one matches no policy at all, the other was claimed by a directory. One arm would have hidden 732 identities behind a nearly-empty class.gunbc.witness_deferral_freeze— the frozen legacy population at(entry, function)grain. Enumerated, never a predicate: a new file underlong/does not join it and refuses on its first PR.gunbc.explicit_witness_admissionrefuses.StaleFrozenPathDeferral, so a row cannot outlive its witness and be inherited by the next name.commit_gate_roster'sCommitWitnessClaimrows project into explicit entries, and explicit rows merge after discovery with no exclusion filter, so an enrolled witness under an offline path executes even though the path excludes it. The first revision of this wall read only two authorities and would have refused 31 identities that already run — fail-closed, and still a wrong answer. Only surfaces that execute admit (GitPrePushHookhas been fmt-only since 2026-07-25). Found by a manager's correction to a prediction in this body, not by a test.FrozenPathDeferralGrew). Without this the ratchet is diligence, not construction — an author could append a row in the same PR that adds the witness. An unresolvable baseline refuses rather than passing unchecked; the single non-refusing arm is the roster being absent at base, which is this change and is unreachable once the roster is on main.test/claim/long/still organizes the files. It no longer answers the admission question.A frozen row asserts membership, not a verdict
It carries no cause, purpose, cost or consumer — deliberately, because none exists. At least three dispositions live in the frozen population and they owe different things: a permanent regression witness owes a scheduled consumer (an offline recipe establishes that this head was tested once, never that a later regression will be observed); a terminating one-shot survey owes no cadence at all — it has no later, and demanding one would enroll a job whose whole purpose is to be deleted; a witness with no discriminating red owes deletion rather than either. The mechanism cannot yet tell them apart, so it labels none of them, and the live terminating specimen already in the roster is named in the carrier. Typing that arm is stricter than typing a cadence, not looser: a one-shot owes a pinned subject, a mechanically checkable dissolution and a deadline after which an undissolved one-shot refuses — without the deadline every permanent witness simply claims to be a one-shot.
Green by execution
17
.dagwitnesses, fixture-shaped and cheap — mechanism on fixtures, per the decomposition rule this PR's own wall enforces (a census may be irreducible; a mechanism never is). Every positive claim holds the row, the pattern and the exclusion verdict fixed and moves only freeze membership — the fact the wall added:9 Rust controls, including
appending_a_row_to_the_live_roster_source_refuses— the discriminating case over the real roster, not a hand-made pair.Live gates, against the real tree:
witness_admission_deferred_rows_refuse_none_and_frozen_debt_is_counted_uncovered— deliberately not named "every deferred row has a consumer", which is what the first version asserted and was false; what holds is that no row refuses and the tolerated population is counted as uncovered andfrozen_path_deferral_roster_carries_no_stale_rows(every frozen identity still exists and is still offline-classified).Executed refusal receipt — one freeze row planted in the working tree, live git baseline gate run:
Row reverted; gate green again.
Adjacent suites unaffected:
witness_admission_test15/15,exact_witness_admission_witness_test9/9,witness_exclusion_reconciliation_test8/8,roster_registry_test5/5,generated_artifact_drift_test7/7.What this does NOT claim
frozen_path_deferral_identity_countis a receipt, never an oracle. The roster was authored from the current tree, so a count equality would compare a measurement to a copy of itself and go green on any pair of compensating edits. Completeness here is the identity join, in both directions. The in-carrier note says so, load-bearing.falsifier_self_host_wetrow reachesWitnessAdmissionHoldsthrough the explicit arm while its cadence is inactive. Same shape one layer in, but it is a counted roster with a named owner and a dated trigger rather than a directory admitting silently.Dissolution
The freeze reaching empty deletes the path-policy pass-through arm, the
test/claim/long/dir row and this roster together — at which pointOfflineLocalRecipestops being an admission answer at all.