Skip to content

Class B trim: pool-independent binding repair + live specimen - #8062

Merged
briansrls merged 16 commits into
mainfrom
session/lively-bat-817
Aug 9, 2026
Merged

briansrls merged 16 commits into
mainfrom
session/lively-bat-817

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Owns the pool-independent binding repair (Class B trim: pool-independent binding repair + live specimen #8062 operator verdict): trim free-call requires import std.algebra { trim } via listed_import_required_bare_call_blocked in v1.compiler.infer_env — gates func-env parent lookup, global_bare, ancestry bindings, and the algebra method-bridge path. Bare trim() refuses even when std.algebra is already in the compilation pool (coincidence success deleted).
  • Live specimens under fixtures/class_b_trim/; six executing tests in v1-compiler-tests (explicit import ListedImport in narrow pool; bare trim refuses with/without algebra in pool; perturbation stable; FreeMonoid receiver refuses).
  • v1.compiler.emit_rust adds explicit import std.algebra { trim } for its trim(s) use (regen green).

66-file span — generated vs authored

Category Count Examples
Authored .dag ~51 Corpus import std.algebra { trim } churn (~45); lane fixtures/tests (fixtures/class_b_trim/, class_b_trim_specimen_test.rs); infer binding edits (04_env.dag, 04_infer.dag, 04_lookup.dag, 05_emit_rust.dag, algebra.dag); receipt doc
Generated stage0/src/*.rs ~8 std_algebra.rs, v1_compiler_emit_rust.rs, interpreter trim arm; regen from infer env/lookup/infer (v1_compiler_infer_env.rs, v1_compiler_infer_lookup.rs, v1_compiler_infer.rs)
Other authored ~7 src/v1/tests/ enrollment, scattered workflow/tool .dag trim imports, docs/probes/

Most churn is selective-import hygiene, not new semantics.

Test plan

Made with Cursor

gunbc-ci-auto-heal and others added 3 commits August 8, 2026 22:37
trim is outside the substrate free-call builtin registry; it compiles only when std.algebra is already in the pool while the consumer imports std.types alone. v1-compiler-tests exercises narrow-pool failure, coincidence compile, direct-import check, perturbation stability, and FreeMonoid receiver refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>
…tion.

Declare importable fn trim in std.algebra with explicit trim imports across
free-call sites, free_call.trim runtime dispatch, and specimen tests proving
narrow-pool binding via ListedImport rather than pool coincidence. Rename
TopologyEdge.port to connector_label to close bare-primitive-nicknames-concept
on the fixture types overlay.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop the verbatim std.types copy that re-minted Duration outside std.measure;
the narrow-pool fixture now shadows only String/Bool kernel imports while
std.algebra enters via explicit trim import from dag/std.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

review 50607 (REQUEST_CHANGES) — fixed in f845b09

The blocking row at fixtures/class_b_trim/narrow_pool/dag/std/types.dag:172 (Duration re-mint) is addressed: the 336-line verbatim dag/std/types.dag shadow is replaced by a 3-line minimal overlay (note only — no std.algebra import, no Duration, no container/kernel scaffolding). Narrow-pool binding still exercises explicit import std.algebra { trim } resolved from dag/std while the overlay withholds transitive algebra via std.types; all five class_b_trim_specimen tests remain green.

— sent from lively-bat-817

gunbc-ci-auto-heal and others added 4 commits August 8, 2026 23:01
Replace the dead-branch tautology with a plain identity body and note
that free_call.trim is the semantic runtime authority (review 50610).

Co-authored-by: Cursor <cursoragent@cursor.com>
* Fix silent floor terminal exits and orphan worker processes.

Post-walk compile_clean and receipt-write failures now populate located refusal details, emit falsifier classification, and journal walk-terminal rows before fast-exit; the coordinator replays worker terminal detail on failure and arms PR_SET_PDEATHSIG so timed-out steps do not leave orphaned claim_executors.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Journal pre-walk worker terminal refusals on the main return path.

Workers that fail before floor_terminal_fast_exit now emit the same walk-terminal journal/stderr row as post-walk failures; drop duplicate coordinator-observation journal on worker failure replay.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Gate PR_SET_PDEATHSIG worker spawn hook on Linux only.

prctl is not available on macOS; #[cfg(unix)] was too broad for the new pre_exec arm.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
The std.algebra trim free function declares parameter `s`, not `seg`.

Co-authored-by: Cursor <cursoragent@cursor.com>
Add trim_free_call_fails_in_narrow_pool_without_algebra_coincidence compiling
coincidence_specimen.dag against the two-root narrow pool (no dag/std) and
assert trim does not resolve via pool coincidence; pair with a PoolCoincidence
positive binding control. Regen stage0 so extdeps.uri trim import and std.algebra
trim export match the emitter.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

review 50618 — addressed in 0c11b1f

Restored the narrow-pool coincidence negative control as trim_free_call_fails_in_narrow_pool_without_algebra_coincidence: it compiles fixtures/class_b_trim/coincidence_specimen.dag against the two-root narrow pool (narrow_pool + fixtures/class_b_trim, no dag/std) and asserts trim does not resolve via observe_declared_import_closure_symbol_binding (symbol must stay unbound when std.algebra is absent from the pool). Paired RED/positive control trim_coincidence_free_call_binds_via_pool_when_algebra_in_closure proves the same entry binds trim with PoolCoincidence when std.algebra is in the declared-import closure via real std.types transitive import.

Also kept trim_free_call_refuses_in_narrow_pool_without_algebra_authority for the explicit-import refusal shape (unresolved std.algebra when listing import std.algebra { trim } without dag/std in the pool). Receipt updated to eight enrolled tests.

CI (cd46f42 regen failure): ran regen_stage0 so extdeps_uri.rs carries pub use crate::std_algebra::trim and std_algebra.rs exports trim — matches the emitter output that regen_verify expected.

— sent from lively-bat-817

Documents the import-strip Class B lane, why pool-overlay probes stay in
v1-compiler-tests, and the closure-independent-binding dissolution trigger.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor Author

review 50623 — addressed in 40da942

Added the standard SCAFFOLD (DESIGN §7 HAND-RUST GATE — explicit deferral) block to class_b_trim_specimen_test.rs (module doc, matching import_visibility_pool_coincidence_test.rs / cross_representation_equality_test.rs pattern): names the import-strip #6985 Class B lane, why narrow-pool overlay probes must stay in v1-compiler-tests (compile_declared_import_closure_only_with_pool + fixtures/class_b_trim/narrow_pool/ while trim lacks an item_registry row for the enrolled Class B gate), and sole dissolution — closure-independent bare trim binding (trim_free_function_authority_note trigger) with migration of fixtures into enrolled dag/test/claim/class_b_trim_* witness rows and deletion of this Rust module in the same change.

— sent from lively-bat-817

…on prerequisite (#7924)

* Cut exact-initializer-identity successor from main (#7855 operator verdict).

Lift foundation only from session/tidy-boar-761: two-root duplicate_qn
fixture, fixture-scoped pool_roots, type-env projection marshal (WIP —
structural blockers from operator review remain), dimensionless Rust
controls, decl_facts-vs-compile population divergence note.

Copy #7796 prereq bank: decl_facts_skeleton, qualified-name resolution
fixtures, 12 skeleton witness cases, constructor-lexeme negative
boundary tests.

Does not include tidy-boar CI retry commits or unrelated branch surface.
Successor scope: ExactDeclarationIdentity carrier, binding_kind gate,
eight executing controls, exact whole-tree marshal/refusal census.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix pool_roots fork: one authority in fixture witness_support.

The lift merged two lineages that both declared decl_facts_reflection_fixture_pool_roots with different populations. Consolidate the six-root walk in test.fixture.decl_facts_reflection.witness_support; projection witnesses import that row. Skeleton lexeme witnesses use an explicit narrower decl_facts_skeleton_fixture_pool_roots.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI build: sync stage0 with main gate and witness-cost surfaces.

The tidy-boar lift left cli_run and v1_interpreter behind main: missing CompilerDiagnostic histogram arms, gate failure-detail builtins, and the WitnessRowCost struct claim_executor expects. Restore those surfaces without changing the decl-facts lift.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI build: sync stage0 with main gate and witness-cost surfaces.

The tidy-boar lift left cli_run and v1_interpreter behind main: missing CompilerDiagnostic histogram arms, gate failure-detail builtins, and the WitnessRowCost struct claim_executor expects. Restore those surfaces without changing the decl-facts lift.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Ground exact variant identity on parent/arm declaration carriers and VariantValueBinding gate.

ResolvedVariantIdentity now carries full ExactDeclarationIdentity for parent and arm instead of lossy qualified-name pairs; marshaling projects parent_type and arm alongside legacy parent_qualified_name/variant_name fields. Variant-value resolution requires infer-stamped VariantValueBinding and resolves parent coproduct through the binding's parent_enum authority rather than spelling plus annotation heuristics.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add VariantValueBinding and module-order controls for exact initializer identity.

Control 1: planted scaffold_with_data_ref specimen plus executing .dag and Rust witnesses prove a data-item reference with coproduct annotation marshals NotVariantValueProjection, not a variant value. Control 4: reversed source-file order leaves constructor parent identity unchanged. Also gate call_env_depth witness behind an armed atomic (default off) and fix namespace_alias_decl_test module gating.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix compile-clean gate: restore ensure_is_converged imports from main.

Merge carry dropped gunbc.build_cache_ensure and gunbc.compile_pool_ensure
imports in their witness tests. Also land control 5: ExactDeclarationIdentity
lookup grain with executing witnesses for duplicate-qn distinctness and
duplicate-exact-identity ambiguity.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix batch-3 decl_facts witnesses without growing migration debt.

Group B: projection helpers read initializer roots (plain record + coproduct).
Group A: pool-corpus duplicate bare-type index lets decl_facts marshal ambiguous
variant values when witness ctx.modules is narrower than the fixture pool.
Group C: delete redundant skeleton Rust test; retain only source-order seam test
with a typed retirement row (no baseline bump).

Co-authored-by: Cursor <cursoragent@cursor.com>

* Register decl_facts_marshal_bridge in stage0 crate layout for regen.

Hand-added pub mod without frontier registration made regen_verify fail:
fresh emit omitted the module while the committed lib.rs carried it.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix batch-3 discovery re-eval of duplicate OtherTwo side-effect row.

The entry module duplicated witness_support's ambiguous_shared_b closure
loader; corpus re-eval of that local data row ran without OtherTwo in scope.
Closure loading stays on witness_support's enrolled side-effect row.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore ambiguous_shared_b import without duplicate side-effect data row.

Import-only closure load keeps Group A green; removing the local
OtherTwo data row avoids batch-3 discovery re-eval undefined-variable failure.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align nullary reflection witnesses with initializer projection trees.

Skeleton lexeme walks on fact.node no longer apply after DeclFact.node became projection roots; assert resolved variant identity via projection helpers instead.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Remove re-evaluable OtherTwo side-effect row from witness_support.

Discovery corpus re-evaluates imported closure-loader data rows without variant imports in scope; keep ambiguous_shared_b closure load via initializer_projection import only.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Trust importing-module TypeBinding for variant resolution; remove pool ambiguity scan.

Delete cross-module bare-name candidate machinery, decl_facts_marshal_bridge, and variant_to_enum sentinel; explicit A import must resolve uniquely to ambiguous_shared_a. Update witnesses and Rust controls accordingly; remove duplicate qualified-name witness and dead closure-loader row.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix vacuous A/B witnesses and pool-grain duplicate lookup; drop Rust CI enrollment.

Add ambiguous_b_specimen as a legitimate B consumer so explicit-import controls
exercise both modules in the entry closure. Replace the vacuous single-module
witness with discriminating positive and negative controls. Route duplicate-QN
per-candidate uniqueness through PoolDeclarationIdentity instead of a parse-pool
row masquerading as exact identity. Remove the enrolled Rust source-order suite
from v1-compiler-tests CI.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename Exact carriers to ResolvedDeclarationLocator; honest locator grain.

Drop ExactDeclarationIdentity/ExactVariantIdentity aliases. Rust projection
carriers are ResolvedDeclarationLocator and ResolvedVariantLocator; dag model
matches. Rename duplicate-QN witness helper to pool-declaration lookup grain.
Occurrence identity is not claimed anywhere on the branch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix CI: re-home over-budget qualified-decl ref witness to long lane.

cross_module_qualified_reference_emits_call_from_correct_module exceeded
the 5000ms per-PR CPU budget (chronic on main, unrelated to decl_facts).
Move it to test/claim/long/ with a lighter std.unicode.types fixture;
keep the fast same-module control per-PR.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix node-frontier refusal: restore long witness module declaration.

Changing line 1 of an existing long-lane file trips diff-before-first-declaration
fail-closed in node-frontier population. Keep main's module name; only the
unicode fixture and note differ from main.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix scoped v1 witness batch FLOOR-BATCH-OVER-BUDGET on CI.

The scoped child exceeded its 360s batch-owned clamp (~376s measured at
93b1373 locally; CI run 31223532865 exited 1 after the same wall).
Raise the v1_claim_scoped_witness_batch clamp to 480s with a receipted
note (375.6s observed x 1.2 fleet margin). Initialize the scoped
witness receipt header in scoped floor workers so append does not fail
when the file is absent.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Pin scoped batch clamp witness to 480s after clamp raise.

witness_v1_claim_scoped_batch_is_file_grain_and_batch_owned still asserted
the retired 360s batch-owned clamp; update to match v1_claim_scoped_witness_batch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Bind spark-standup-program-accounting doc to gunbc doc graph roots.

Fleet-blocking main red: doc_graph_has_no_orphan_docs failed because
docs/plans/spark-standup-program-accounting.md landed in #7972 with no
HandAuthoredDocBind row. Mirrors owned-ci-control-plane-design binding.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Revert "Bind spark-standup-program-accounting doc to gunbc doc graph roots."

This reverts commit d303674.

* Bind spark-standup-program-accounting.md into the doc graph (main red, from #7972)

#7972 landed docs/plans/spark-standup-program-accounting.md with no doc-graph
binding, so doc_graph_has_no_orphan_docs reds on main and every branch merging
main inherits it. My PR, my orphan.

Verified rather than assumed. Subject: 0 bindings corpus-wide. Positive control:
owned-ci-control-plane-design.md, added by a DIFFERENT PR in the SAME window,
returns 4 — same query, same window, one bound and one not, so the zero is a real
negative and not a broken grep.

Discriminating control on the fix itself: the gate returns false with the row
removed and true with it restored, so the row is what closes it rather than
something else in the window.

Every cited symbol grep-verified before authoring — fleet_subsumption_manual_gaps_plan,
dgx_spark_arrival_standing, dgx_spark_router_bindings all exist. Two plausible names
I first reached for did not, and are not in the row.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Revert "Bind spark-standup-program-accounting.md into the doc graph (main red, from #7972)"

This reverts commit d47618b.

* Update floor batch clamp witnesses for 480s scoped-batch overhead.

Main's authority witness expected 360s; this branch receipted raise to
480s in gunbc.ci_layer_roots v1_claim_scoped_witness_batch.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 50585: restore fail-closed call binding and cache keepalives.

- Re-instate duplicate named/positional argument refusal (CallContractMismatch)
- Route observed_peak_resident_bytes through cli_run::peak_rss_vhwm_bytes
- Restore pointer-cache keepalives for param_name, var_sym, call_func_name
- Align decl_facts_reflection witness note with landed nullary-value controls

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address review 50590: honest fn-node lookup and marshal entry gate.

Rename lookup_typed_item to lookup_fn_node; marshal DataItem projections
from the typechecked item node and refuse when registry knows a data item
but fn_nodes lacks the subject. Add dissolve-on notes for skeleton lexeme
aliases and data_initializer_identity seed-retained scaffold.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix record-literal coproduct resolution to honor explicit imports.

Remove the module-pool first-pick in coproduct_type_item_with_variant_children
and pass the import-resolved type_item directly into marshal_coproduct_record_projection,
so duplicate bare coproduct names cannot override the importing module binding.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Route eval_decl_facts DataItem marshal through lookup_fn_node seam.

eval_decl_facts now delegates DataItem node marshaling to
marshal_data_initializer_projection so enrolled .dag witnesses exercise
the same typechecked path as Rust seam tests. Update gap notes to match.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix review 50602: witness import and wire retained Rust test module.

Import decl_facts_reflection_nullary_value_projection in the initializer
projection witness module and register decl_facts_dimensionless_projection_test
in v1-compiler-tests lib.rs so the retirement row matches executing coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Restore symbol_index_fill_overlay_direction_test module enrollment.

Re-add the lib.rs mod line dropped during decl_facts test wiring so the
fill-overlay direction regression control cited in 04_infer remains executed.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls and others added 2 commits August 8, 2026 20:15
…8034)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Replace identity trim body with a pure-dag seam and route emitted std.algebra::trim through v1_rt::trim via rust_host_string_op_fn_emit. Restore TopologyEdge.port (revert connector_label rename from trim PR scope).

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

review 50629 (Opus REQUEST_CHANGES)

Finding 1 — lying trim body — fixed (cd7e593)

The identity body fn trim(s: String) -> String { s } is gone. Current authority split:

Surface Behavior
dag/std/algebra.dag Declared body is a pure-dag seam (from_code_point(1 / 0)), not executable trim semantics — same pattern as std.encoding utf8_decode_bytes, without importing std.bytes (that import closes std.algebra → std.bytes → … → std.types → std.algebra and blocks regen).
std_algebra::trim (emitted) v1_rt::trim(s) via new rust_host_string_op_fn_emit arm in src/v1/05_emit_rust.dag — no identity twin.
free_call.trim / call sites Still v1_rt::trim (unchanged).

trim_free_function_authority_note now names std.primitives trim_contract as host realization authority (typed carrier reference, not prose-only divergence).

cargo test -p v1-compiler-tests class_b_trim_specimen — 8/8 green after regen_stage0.

Finding 2 — TopologyEdge.port → connector_label scope creep — reverted (cd7e593)

Restored port in dag/std/types.dag + std_types.rs. No trim-related rationale; will land separately if/when needed.

— sent from lively-bat-817

@gunbai-bot

gunbai-bot Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

REQUEST CHANGES in substance (formal RC blocked: same PR author) — (operator verdict 2026-08-09, relayed by manager): this is a valuable live specimen, but a reproduction that preserves the coincidence is not the completed repair — and per the no-diagnosis-PR ruling, #8062 must OWN the pool-independent binding fix. Required end state:

  • explicit import → provider included in the exact closure → resolves regardless of unrelated pool contents;
  • no explicit import → REFUSES even when the provider happens to be loaded (delete the retained coincidence-success expectation — that passing case IS the defect);
  • unrelated pool perturbation → no change in resolution;
  • ambiguous providers → typed ambiguity carrying candidate identities.

Applied consumer: #8054's formerly failing narrow batch.

Also: the PR body's "five tests" claim is stale — the changed Rust test module carries a larger suite and the PR spans 66 files; provide a clean generated-versus-authored breakdown before merge.

— sent from witty-raven-412

Bare free-call trim now requires listed import via closure_independent
registry in infer_env (func sig, global_bare, ancestry, method-bridge paths);
coincidence success is refused. Six specimen tests; emit_rust adds explicit trim import.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot gunbai-bot Bot changed the title Class B live specimen: trim binds by pool-membership coincidence Class B trim: pool-independent binding repair + live specimen Aug 9, 2026
@gunbai-bot

gunbai-bot Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

review 50669 — not fixing (method-syntax modules are unaffected; gate is free-call only)

The finding conflates two inference paths:

  1. Free-call / global-bare trim — trim(s) or unresolved trim(...) where the callee name is trim. This is what bare_free_call_requires_listed_import + listed_import_required_bare_call_blocked gate (v1.compiler.infer_env / 04_env.dag): lookup in lookup_binding_by_name, lookup_func_sig, and the ExprCall method-bridge fallback at 04_infer.dag when lookup_func_sig returned none and the compiler tries trim(receiver) as an algebra method bridge for the call spelling. That bridge is intentionally blocked without trim in source_visible_names (i.e. without import std.algebra { trim }).

  2. Receiver method syntax s.trim() — ExprMethodCall at 04_infer.dag (~3461–3523). This path calls resolve_known_method_node directly and does not consult listed_import_required_bare_call_blocked. Method trim on String still resolves from the FreeMonoid<String> algebra template when std.algebra is pool-present — the intended pool-independent fix targets bare name binding, not receiver-method dispatch on a typed String carrier.

The five flagged modules use method syntax on String (or cast-to-String) receivers, not free-call trim(...) without import:

  • package_delivery.dag — (observed.version as String).trim(), (read.content as String).trim(), kernel.trim() / machine.trim() on string locals
  • same pattern in roadmap_publish_observe.dag, codex_app_server_press.dag, provider_wire_evidence.dag, nopasswd_execute_probe_check_op.dag

Executed on head (c6cab96): claim_batch --entry resolve for all five modules completes with no trim binding refusal and no witness FAIL (clean frontend/normalize/reconcile/typecheck). Adding import std.algebra { trim } there would be redundant for method syntax and would mis-document the authority (the listed-import requirement is for the free-function name, per trim_free_function_authority_note in dag/std/algebra.dag).

Narrowing the gate to “free-call only” is already what the implementation does; widening it to block ExprMethodCall would be a separate product change and is out of scope for Class B trim free-call coincidence.

— sent from lively-bat-817

… joins (#8056)

Three witnesses asserted the derived host/phase matrix against
enrollments.length() * host_standup_spine.length(). That is a count
equality over a rectangle: it cannot tell a correct matrix from one that
hands every host every spine step, which is exactly the shape a
participation-scoped program is supposed to make impossible. DESIGN.md
section 5 rules that completeness is an identity join, not a count.

They are now joins derived from each enrollment's participation-selected
program:

  - per-enrollment cell count == program_step_count(assimilation_program_for)
  - duplicate-free over host_phase_cell_key
  - matrix hosts are exactly the enrolled roster, no strays
  - unmodeled count cross-checked against a disposition filter over the
    same matrix, rather than against a rectangle
  - runner enrollments still contribute exactly the whole spine

srv5 and srv6 are enrolled as InferenceServingParticipation, which
selects exactly four shared obligations each and no runner-only one.
ENROLLED IS NOT CONVERGED: all eight Spark cells are honestly
unobserved, and a witness asserts that so a future producer reds here
instead of silently upgrading the claim. Positive controls keep both
sides non-vacuous -- runner-only obligations do exist on runner hosts,
and the spine does carry gap phases.

Unblocking root fix, not scope creep: gunbc.roadmap_instrument_sandbox
defined fn cell(s:) and fn row(cells:) alongside gunbc.plans.md_helpers'
fn cell(text:) and fn row(cells:) -- a section 3 homonym pair. Editing
this witness widened its closure enough to pull both definers into the
pool, after which the plan modules' explicit `cell` imports lost to pool
coincidence (#6985 Class B) and every witness in the file failed with
"calling 'cell': no parameter named 'text'". The HTML-fragment builders
are renamed fragment_cell / fragment_row; md_helpers keeps the plain
names. The sandbox keystone still passes.

Green by execution, eight witnesses, one at a time on the live tree.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 2 commits August 9, 2026 02:42
Names the infer-layer FaithfulFreeMonoid vs String receiver split, pins trim_method_form_fails_on_freemonoid_receiver, and records dissolve-on as type-node unification — separate from the trim binding-bridge repair.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls merged commit 21eca9a into main Aug 9, 2026
6 of 8 checks passed
@briansrls
briansrls deleted the session/lively-bat-817 branch August 9, 2026 03:35
briansrls pushed a commit that referenced this pull request Aug 9, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 9, 2026
…is head

Fixes review 50740: the committed receipts pinned a pre-repair commit while the
diff consolidated the very forks the ledger listed as open, so the measurement
authority and the fix disagreed inside one PR. Everything is now regenerated on
the head that carries the repair, and sections 15.1-15.5 carry an explicit
pointer saying their numbers are the pre-repair reading.

MEASURED, not predicted: corpus_hygiene 152 -> 0. The disposition is absent from
the ledger rather than reduced. Reconciliation checked by the classifier:
stripped 3,100 = control 22 + attributable 3,078 = sum of ledger rows.

Also fixes a defect the regeneration caught in my own work. The first run
reported corpus_hygiene: 2, which was a rename of mine colliding with an
existing import_resolution_facts_live in v2.lens.module_graph -- I had named it
for its return type when the distinguishing fact is its source. It is now
reference_derived_import_resolution_facts_live, and both are unique.

Three numbers moved for reasons that are NOT this repair, stated so the tables
are not read as a scoreboard: the unstripped control rose 12 -> 22, and
compiling origin/main alone reproduces 22, so the hygiene batch adds zero
diagnostics; the corpus grew to 16,375 imports across 2,579 files; and
unique_decl_unresolved_mechanism_unobserved rose to 1,885. All three follow main
landing #8062, #8061 and #8068 during the work.

The section states plainly that this does not close import deletion. What it
buys is that no one can point at a miscellaneous naming tail to justify a
workaround; the remaining residual is one integration vertical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 9, 2026
…t it

Three findings from review 50752, all confirmed against the code.

THE ROOT ONE IS THE THIRD. The page claims serialized repo_atlas_section
while the route served repo_atlas_page, so twelve green claims covered a
shape the handler never returns — a headless, unstyled page stayed green
through all of them. A claim aimed at the wrong subject is not a weak claim;
it is not a claim about the product at all. repo_atlas_document now takes the
snapshot as a parameter and IS the served shape, repo_atlas_page is the thin
live binding, and every page claim drives the document with fixtures.

The other two are what that miscovered subject was hiding.

repo_atlas_page emitted a bare <main> with no charset, viewport, title,
stylesheet, or header, unlike every sibling on the same serve table. It now
emits a full document through the same pattern.

No CSS existed for atlas-dot, atlas-dot-changed, atlas-impact-ring or the
readouts, so on the live route a real SCM change mark was visually identical
to an ordinary structural cell while the carrier's own note claimed the four
channels stay "distinguishable at a glance". That is rung inflation — a note
asserting a property the artifact did not have. atlas_rules derives the
stylesheet from the design register: structure is FigureRole below full
strength, a direct change is FigureLitRole at full strength (brightness is the
change channel and nothing else uses it), impact is a STROKE on a separate
concentric circle so affected and changed cannot be confused, and a shared
cell strokes its own dot in the structure colour — denser without borrowing
the change channel. Glow stays absent: it belongs to selection, and an unused
channel is safer than one that collides with occupancy later.

Retargeting immediately caught a real interaction: with the stylesheet
embedded, ".atlas-dot-changed" appears in every document as a CSS RULE, so the
negative half of the change-mark claim matched the stylesheet. The needle is
now the emitted class attribute, which distinguishes a rule that exists from a
mark that was applied.

Also merges origin/main. The heal job was red on `trim` not in scope in
extdeps/uri.dag and repo_local_git_config.dag — files this branch never
touched. fn trim is defined in dag/std/algebra.dag by #8062 (Class B
pool-independent binding repair), which landed after this branch point; the
branch had no definition at all. Base skew, not a defect here.

Verification on the merged tree: 23 projection + 16 page + 16 serve claims
green by execution. Live render 459,332 bytes, styled, complete document.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 9, 2026
… number

review 50759, both findings, with one correction to the first.

WITNESS IMPORT: dag/test/claim/scaffold_disposition_census_fixture_witness_test
imported decl_facts_matching_qualified_name from v2.std.decl_ref_resolution,
which this PR stopped declaring. The single-authority half is right and is
fixed -- it now imports from the declaring module v2.std.decl_facts_skeleton.
The COMPILE-BREAK half does not reproduce: v2.std.decl_ref_resolution imports
the symbol, so the re-export resolves, and the witness ran green (returns true)
BEFORE the repoint as well as after. Recorded because "verify each item against
the current code" cuts both ways; the fix is worth making on single-authority
grounds, not because the tree was broken.

README: the two flagged lines were a sample, not the population. Swept the file
and corrected five stale claims -- the 3,050-row figure, the strip expectation
(16,315/2,574 -> 16,375/2,579), the verification reconciliation
(3,062 = 12 + 3,050 -> 3,100 = 22 + 3,078), the manifest row count, and the
--control-count/expect lines the review named.

The tool-identity section was not merely stale, it was FALSE, and that is the
one worth reading. It claimed no .rs changed between 1eadad4 and the
measured base so the original binary stayed current. Main then landed #8062,
which changes src/v1 binding behaviour, and the binary was rebuilt. The section
now records what that cost: the heal entry passed locally under the old binary
while failing in CI under the new one, so a binary older than the substrate it
judges reports a compiler that no longer exists. Rebuild whenever src/v1 moves.

Verified by execution, not by reading: the README recipe was run and its stated
numbers reproduce (16,375 across 2,579; 3,100 = 22 + 3,078; rows 3,078 OK), and
the repointed witness still returns true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 9, 2026
… the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff
briansrls pushed a commit that referenced this pull request Aug 9, 2026
* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0: dispatch trigger, checkpoint structure, permanence laws (operator ruling 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
…sure the stripped residual (#8067)

* Re-measure the repo-wide import strip, and disambiguate the three homonyms that carry half of it

Whole-corpus strip measurement (docs section 15 of the cascade diagnosis, the
DESIGN-linked authority for this lane rather than a new orphan doc), plus the
part of the residue that is corpus hygiene rather than a compiler deficit.

Measurement: gunbc rebuilt from main at 1eadad4 (a stale binary would have
measured a substrate that #7924 replaced), two scratch trees, a brace-depth-aware
strip of 16,315 import declarations across 2,574 files with zero residue.
Control 12 hard diagnostics, stripped 5,827 -> 5,815 strip-attributable over 801
files and 486 names; 69% of stripped files compile clean. Joining every failing
name against a corpus declaration index splits the residue: 50% homonyms (32
names), 28% the documented Class B population, 10% variant tags, 11% cascade.
The classes are indistinguishable by diagnostic text, so the join is what ranks
the work.

Fix, for the homonym half only: `cell`, `row` and `note` were each declared
twice with unrelated return types (a MarkdownTableCell/Row table helper in
gunbc.plans.md_helpers, a markup Fragment helper in the instrument pages). Two
concepts sharing a short name is a homonym, not a section 3 fork, so the
correction is disambiguation and not consolidation: the instrument-local
declarations become instrument_cell / instrument_row / instrument_note, names
derived from the instrument_cell_class / instrument_row_class /
instrument_note_class they already build. All three names are now corpus-unique,
which removes 2,765 of the 5,815 (48%) at the authoring layer.

This does not unblock the strip. Classes B and C are unchanged and remain the
blocker, and section 13's wave rule stands. Verified by execution: whole-tree
`gunbc compile --target dag` on the renamed tree produces the same 12 baseline
diagnostics as before the rename.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Replace the predicted Class A drop with the measured one

Section 15.5 predicted 2,765 removed diagnostics from the classification
arithmetic. Re-ran the strip against the renamed tree with the same binary and
the same brace-depth-aware pass: 5,815 -> 3,047, measured removal 2,768 (47.6%),
three more than predicted because cascade diagnostics went with them. Zero
cell/row/note failures remain, so the class is closed rather than reduced.

Also records why the ~150-diagnostic Class A tail is not uniformly mechanical
(half genuine forks needing an authority decision, half cross-domain homonyms),
and notes that consolidating a fork temporarily adds the import edge this lane
deletes -- an ordering artifact, since a corpus-unique name resolves bare.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Withdraw the duplicate rename, reconcile the census, and withdraw the Class C label

Three corrections to the measurement, and one withdrawal.

WITHDRAWN: the cell/row rename. Open #8056 authored it first (fragment_cell /
fragment_row, same two files) after independently observing explicit imports
losing to pool coincidence. This session measured the same repair under different
names without checking for an existing fix PR. Both instrument files are restored
to main, so #8056 owns that repair and one defect is not repaired twice. `note`
(declared twice across the sandbox and motion modules) is NOT covered by #8056
and is recorded as the uncovered sibling rather than edited here, since its
declarations sit adjacent to #8056's lines.

CENSUS: the published four classes summed to 5,803 against a stated 5,815. The
missing 12 are diagnostics carrying no quoted name for the join to key on (eight
indexing, four if-branch mismatches). They are now an explicit unclassified row
and the ledger identity is stated, so the residual reconciles exactly. Their
count coinciding with the control's 12 is a coincidence, called out as one; one
of the four is the Product(<anon>) fabrication shape, so part of that row is
Class-B damage in disguise.

CLASS C: the label is withdrawn. The section described the 599 rows as the
arity-zero/variant-tag population that section 3 predicts -- a hypothesis THIS
DOCUMENT's section 5 refutes by execution. Re-asserting it while citing the
refuted section is the stale-citation class in the document that recorded the
refutation. The rows now carry a named re-proof procedure and are explicitly not
evidence for a language feature.

Also: Class A is split four ways, since global textual uniqueness is not the
namespace model's rule -- it preserves distinct same-spelled declarations and
feeds candidates to the ambiguity fold; the 69%-clean reading is qualified
against the measurement-only discriminator and the fabrication arm; the framing
no longer implies a countdown, and states the closing frontier as 2 with E and F
unavailable.

Adds docs/plans/import-strip-residual-ledger.tsv: the exact 3,047-row residual
worklist, dispositions summing to the row count, with provider_in_loaded_closure
carried as unobserved (it needs loader instrumentation, and guessing it would
fabricate the E/F measurement) and no_declaration_found documented as an index
limitation rather than a fifth class.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Withdraw "frontier 2" and "exact worklist"; commit the reproducer; re-measure on the current base

Six required changes from review, each verified against the carriers rather than
taken on the reviewer's word.

FRONTIER 2 IS WITHDRAWN. The roadmap prose was ahead of its own executable
closing authority. gunbc.namespace_reference_derived_closure_contract
namespace_reference_derived_closure_acceptance_admissions returns SIX
ReferenceDerivedClosureUnavailable rows -- including the four A-D capabilities,
trigger P2aStructuralCandidateProducer7515 -- and
reference_derived_closure_closing_contract_holds is false above frontier zero.
Section 15.0 replaces the single frontier with a three-level maturity matrix
(A-D parser-fixture evidence; E/F carrier/fixture evidence; permanent
ordinary-path contract all six unavailable), citing the carriers that say so
themselves: namespace_clause_e_projection_law_note excludes
OrdinaryLoadedCompilationClosure, module_path_file_row_dissolution_note carries
its row as a scaffold until B2, and roadmap_authority's
namespace_cross_file_provenance_lane_integration_note states outright that B1
fixture carriers do not close the lane. The missing work is an integration
vertical, not two algebra arms.

CLASS B IS NOT E. The prior revision dispositioned 1,656 rows as clause E while
every row recorded provider_in_loaded_closure=unobserved; both cannot stand. The
disposition is now unique_decl_unresolved_mechanism_unobserved, and the doc
enumerates the five mechanisms the evidence cannot distinguish. The
live_tree.dag lead (943 rows, 31% of the residual) survives as a strong lead,
labelled as one.

EXACT WORKLIST IS WITHDRAWN: 1,109 rows are explicitly unclassified or
downstream and 1,656 carry an unobserved mechanism; only 152 are hygiene.

THE 505-ROW BUCKET IS SPLIT six ways -- variant_owner_unindexed 249,
ordinary_callee_unindexed 133, field_on_unresolved_or_wrong_type 88,
method_on_unresolved_receiver 22, record_shape_cascade 12,
unindexed_symbol_candidate 1 -- because count/first/split/ends_with are methods
on unresolved receivers and steps/kind/qualified_name are fields downstream of a
missing parent type, not index gaps.

CLASS C PROVIDERS ARE CANDIDATES. The single provider_module column laundered a
same-leaf index hit into a binding fact; the ledger now carries
candidate_provider_modules, candidate_count, intended_provider=unobserved and
accepted_binding=unobserved.

REPRODUCIBILITY. docs/plans/import-strip-measurement/ commits the brace-aware
stripper (now emitting a per-file manifest), the classifier, raw control and
stripped diagnostics, the duplicate-declaration census, summary totals, corpus
hash, measured commit, tool identity, and the deterministic command sequence.
The stripper was verified to reproduce the measured tree byte-identically, and
the classifier reproduces the committed ledger. Registered as a scaffold with a
dissolution trigger: when B2 lands, the ledger becomes a projection of the
loader's accepted-binding output and these scripts delete.

RE-MEASURED ON THE CURRENT BASE, post-#8056: control 12, stripped 3,062,
attributable 3,050, reconciliation checked by the classifier rather than
asserted. Supersedes the 5,815 reading taken at 1eadad4; the two are not a
trend.

Also fixes a fabricated citation this section introduced -- DESIGN.md has no
"Current state - stale binary phantom breakage" heading (that is this session's
memory index, not DESIGN), and "known-positive" is this document's term, not
DESIGN's. Caught in review; it is the same stale-citation class the section
lectures about.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Land the two reproducer scripts the README claims (repo-wide *.py ignore silently dropped them)

review 50719 is correct: the README documented a reproducer invoking
strip_imports.py and classify_residual.py, and neither file was in the tree. The
cause was .gitignore:113 `*.py`, a deliberate repo-wide rule -- `git add -A`
skipped both silently, and the explicit `git add` that followed had its
"ignored file" error suppressed by a 2>/dev/null I should not have written.
So the PR asserted regenerability while shipping only the receipts: the exact
specification-without-execution gap DESIGN section 5 names, in a PR whose
subject is measurement honesty.

Fixed by following the convention already in .gitignore rather than force-adding:
two negation entries beside the existing
!docs/plans/witness-subject-execution-audit.py and
!docs/probes/dissolution_census_a_ci_layer_roots_project.py exemptions. There is
established precedent for committed measurement scripts under docs/ --
docs/probes/namespace_census_2026-07-31/ is an entire directory of them -- and
the ignore rule's own comment scopes itself to the .dag/.rs substrate, which
docs/ is not. A negation entry records the exemption where a reader will find
it; `git add -f` would have hidden it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Record the tracked-content-only verification of the reproducer claim

The README asserted regenerability; now it carries the execution that
establishes it. Running the committed scripts against a `git archive HEAD`
export -- only what a fresh clone receives -- reproduces the manifest and the
3,050-row ledger byte-identically, with the classifier printing its own
reconciliation. Also records why the scripts were missing, so the next author
meets the *.py rule with an explanation instead of the same silent drop.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add the reproducer-script exemptions to the .gitignore AUTHORITY, not the artifact

review 50727 is correct, and identifies the durable fix I had missed. My
previous commit hand-edited .gitignore -- a GENERATED artifact emitted from
gunbc.gitignore_authority -- so CI auto-heal regenerated it from the authority
and removed both entries in 1505281, leaving the README describing
exemptions the tree did not carry. Editing a projection instead of its authority
is the DESIGN section 3 single-authority violation, and the artifact winning is
the mechanism working correctly, not a race.

The entries now exist where they are derived from:
  gitignore_model.dag        two GitignoreArtifact variants
  gitignore_authority.dag    both added to the PythonLocalDevScript group
  gitignore_emit.dag         render arms for the two paths
then regenerated via the documented actuator
(dag/tools/generated_artifact_gate.dag main_wet), which is what auto-heal itself
runs -- so the next heal reproduces these lines instead of deleting them.

Proven by execution rather than by reasoning about it: a second consecutive heal
run reproduces .gitignore byte-identically (regen fixed point), and the compiler
refused the intermediate state where the variants were referenced from the
authority/emit import lists before being declared in the model -- which is how
the third module was found.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Hygiene batch 1: consolidate three true forks onto their single authorities

declaration_ref_eq + declaration_ref_in_list (44 of the 152 hygiene rows):
gunbc.commit_workflow carried a semantically identical copy of std.roster_frontier's
DeclarationRef equality. Deleted; the std authority is imported. Two consequences
that had to move with it: declaration_field_eq became dead once its only caller
went, so it is deleted rather than left as a dead scaffold, and the std authority
names its list parameter `refs` where the local copy said `declarations`, so all
four call sites moved.

Milliwatt / milliwatt / milliwatt_count (2 rows): product.hardware_selection
redeclared std.measure's SI unit family verbatim. Deleted and imported; three
witness call sites that named product.hardware_selection.milliwatt repointed.

srv3_nbd_proxy_local_port (5 rows): extdeps.bmc.webui.nbd_proxy_serve holds the
cited upstream port fact and gunbc.srv3_os_install_diagnostic held a copy. The
copy is deleted and the extdeps authority imported -- the direction the external
upstream decomposition rule requires.

Verified: whole-tree `gunbc compile --target dag` produces the same 12 baseline
diagnostics as before the change.

The imports added here are transitional. They dissolve with the ordinary-loader
changeover, when a corpus-unique name resolves bare; they must not be scored as
import growth against the deletion lane.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* wip: hygiene batch 2 (renames + classifier corrections)

* Hygiene batch 2: close the remaining homonym and fork families

Consolidated onto one authority: decl_facts_matching_qualified_name (identical
bodies, both in v2 std) onto v2.std.decl_facts_skeleton; gnu_bash_subject_ref
onto the DERIVED row in gunbc.language_target_registry, deleting the hardcoded
DeclarationRef literal that duplicated it.

Renamed as genuine homonyms -- different concepts that shared a leaf:
PublicationSubject splits into RoadmapPublicationSubject (a roadmap publication
attempt: node, branch, head) and PublicProjectionSubject (a content projection:
subject/content identity, path), 31 rows and the largest single family;
NetworkInterface -> DockerContainerNetworkInterfaceStats with the product
topology keeping the name; ampere -> ampere_vendor with the SI unit constructor
keeping it; shape_from_catalog -> cpu_/gpu_; ChangeClassification ->
Bootstrap.../ChangeRealization...; path_has_prefix -> rust_source_path_has_prefix;
note -> instrument_note / motion_note; reference_resolution_facts_live ->
import_resolution_facts_live on the module_graph side, where the name now
follows the ImportResolutionFact it returns.

Renamed as fixture-locals: five witness-local nid helpers, authored ->
authored_status_fixture, site_artifact_digest -> fixture_site_artifact_digest,
fixture_repository -> git_/mercurial_/pijul_, decl_facts_reflection_fixture_facts
-> decl_facts_reflection_witness_support_facts.

Renamed BOTH sides where the bodies actually diverge, so the fork is visible
rather than latent: runner_slot_unit_name and RunnerReplacementCause (the
recovery module's copies build a different unit name and enumerate different
causes than gunbc.runner_lifecycle, which carries Disposition = SingleAuthority),
and current_walk_attempt_id (env_var/none vs optional_env/empty-string). These
are named, not fixed; two functions still compute a systemd unit name
differently and that is a latent defect this PR surfaces rather than resolves.

Per-spec w3c tokens are named for the spec that owns them: accelerometer.dag
keeps accelerometer_permission_name, and the DeviceMotion spec's copy becomes
device_motion_accelerometer_permission_name; interfaces_are_secure_context_only
gains an API-family prefix on each side. Each upstream spec module owns its own
facts, so a shared token is not consolidated across specs.

One specimen worth keeping, found by execution during the consumer sweep:
renaming the git fixture made another module's bare `fixture_repository` bind to
an unrelated declaration in a different witness file, producing five bogus
"no field on type Repository" errors. That is pool coincidence reproduced on the
UNSTRIPPED tree -- the same mechanism as the Class B residual, and an argument
for these renames rather than against them.

All 30 families are now corpus-unique.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Close the hygiene bucket: 152 actionable rows to 0, re-measured on this head

Fixes review 50740: the committed receipts pinned a pre-repair commit while the
diff consolidated the very forks the ledger listed as open, so the measurement
authority and the fix disagreed inside one PR. Everything is now regenerated on
the head that carries the repair, and sections 15.1-15.5 carry an explicit
pointer saying their numbers are the pre-repair reading.

MEASURED, not predicted: corpus_hygiene 152 -> 0. The disposition is absent from
the ledger rather than reduced. Reconciliation checked by the classifier:
stripped 3,100 = control 22 + attributable 3,078 = sum of ledger rows.

Also fixes a defect the regeneration caught in my own work. The first run
reported corpus_hygiene: 2, which was a rename of mine colliding with an
existing import_resolution_facts_live in v2.lens.module_graph -- I had named it
for its return type when the distinguishing fact is its source. It is now
reference_derived_import_resolution_facts_live, and both are unique.

Three numbers moved for reasons that are NOT this repair, stated so the tables
are not read as a scoreboard: the unstripped control rose 12 -> 22, and
compiling origin/main alone reproduces 22, so the hygiene batch adds zero
diagnostics; the corpus grew to 16,375 imports across 2,579 files; and
unique_decl_unresolved_mechanism_unobserved rose to 1,885. All three follow main
landing #8062, #8061 and #8068 during the work.

The section states plainly that this does not close import deletion. What it
buys is that no one can point at a miscellaneous naming tail to justify a
workaround; the remaining residual is one integration vertical.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Stamp the receipts with the commit the measurement was taken at

The corpus hash covers dag/ and src/v2/ .dag files only, so it is stable across
this docs-only commit; the commit line now names the head that carries the
hygiene close rather than the one before it.

* Repair the module_graph edge-source regression this PR introduced

review 50749 found a semantic bug in production lens code, introduced by my own
rename. The blunt pass over reference_resolution_facts_live rewrote four sites in
v2.lens.module_graph -- the declaration, the CALL SITE inside
dependency_resolution_facts_live, and two prose rows -- and when I later fixed
the name collision I repaired only the declaration. That left reference_edges:
sourced from import_resolution_facts_live, the same producer already feeding
import_edges:, so bare-reference dependency edges were silently dropped from the
module graph that feeds affected-set selection, import closure and compile-clean
scope.

Repaired: the call site takes reference_derived_import_resolution_facts_live, and
both prose rows are reconstructed from main so they differ by exactly the rename.
Audited the whole file against origin/main -- all four changed lines are the
intended rename and nothing else.

WHY NOTHING CAUGHT IT, which matters more than the fix. Both helpers have the
identical signature (List<String>, List<String>, List<String>) ->
List<ImportResolutionFact>, so the substitution is type-correct and the
whole-tree compile stayed green at baseline THROUGH the regression -- the check I
was relying on cannot see this class. And no witness in the corpus references
dependency_resolution_facts_live or union_import_resolution_fact_lists at all, so
the two-source union has no discriminating control and a wrong producer there is
invisible to the executing corpus.

The coverage gap is recorded in section 15.7 rather than closed here: a real
control needs a fixture where a module is reachable by bare reference but NOT by
import, which is the same fixture shape the ordinary-loader vertical needs and
belongs with it rather than bolted onto a naming PR.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Regenerate the receipts on the head carrying the module_graph repair

Residual is unchanged (3,078 rows, reconciliation OK) because the repair changed
a call site inside a lens, not the corpus name structure -- but the receipts now
name the head that carries the fix rather than the one before it.

* Stamp the corpus hash and measured commit

* Repoint the witness at the declaring module; align every stale README number

review 50759, both findings, with one correction to the first.

WITNESS IMPORT: dag/test/claim/scaffold_disposition_census_fixture_witness_test
imported decl_facts_matching_qualified_name from v2.std.decl_ref_resolution,
which this PR stopped declaring. The single-authority half is right and is
fixed -- it now imports from the declaring module v2.std.decl_facts_skeleton.
The COMPILE-BREAK half does not reproduce: v2.std.decl_ref_resolution imports
the symbol, so the re-export resolves, and the witness ran green (returns true)
BEFORE the repoint as well as after. Recorded because "verify each item against
the current code" cuts both ways; the fix is worth making on single-authority
grounds, not because the tree was broken.

README: the two flagged lines were a sample, not the population. Swept the file
and corrected five stale claims -- the 3,050-row figure, the strip expectation
(16,315/2,574 -> 16,375/2,579), the verification reconciliation
(3,062 = 12 + 3,050 -> 3,100 = 22 + 3,078), the manifest row count, and the
--control-count/expect lines the review named.

The tool-identity section was not merely stale, it was FALSE, and that is the
one worth reading. It claimed no .rs changed between 1eadad4 and the
measured base so the original binary stayed current. Main then landed #8062,
which changes src/v1 binding behaviour, and the binary was rebuilt. The section
now records what that cost: the heal entry passed locally under the old binary
while failing in CI under the new one, so a binary older than the substrate it
judges reports a compiler that no longer exists. Rebuild whenever src/v1 moves.

Verified by execution, not by reading: the README recipe was run and its stated
numbers reproduce (16,375 across 2,579; 3,100 = 22 + 3,078; rows 3,078 OK), and
the repointed witness still returns true.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* wip: refresh control receipt at HEAD

* Re-stamp the measurement anchor at HEAD, and prove each half rather than assume it

review 50765: the stamp pinned 9325d29 while HEAD carried a later corpus edit
(the witness import repoint), so the hash no longer described the tree the
receipt claims to cover -- the same stale-receipt class section 15.6 names, in
the receipt that documents it.

The review suggested the ledger and diagnostics were "likely unchanged". Both
halves are now established instead of assumed, and they needed different
arguments:

STRIPPED half, by construction: the only post-measurement edit was an import
line, and the strip deletes every import line, so the stripped tree at HEAD is
BYTE-IDENTICAL to the one measured (verified with diff -rq over both source
roots, and the manifest matches). The stripped diagnostics therefore cannot
differ -- no recompile can change that.

CONTROL half, by measurement: the control retains the changed import, so it was
recompiled at HEAD. 22 diagnostics, and the log differs from the committed
receipt ONLY in wall-clock lines. That is now documented rather than papered
over: the README records which receipt content is not byte-reproducible and
gives the filtered diff used to check it, so a future comparison does not read a
timing delta as a measurement change. Nothing derives from the durations.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Make the measurement anchor self-verifying instead of chasing the commit id

A stamp written into a tracked file names an ancestor by construction -- the
commit cannot contain its own id -- so re-stamping to catch HEAD is a loop that
never closes and always reads one commit stale. The hash is the real anchor: it
covers dag/ and src/v2/ .dag files, so docs-only commits do not move it. The
receipt now says so and gives the one-line command that decides whether it
describes the reader's tree, which is checkable at any commit rather than
requiring trust in either line.

* Repair three review blockers: CSS wire, fail-open classifier, edge-source control

1. THE `note` RENAME CHANGED A WIRE VALUE, NOT ONLY A SYMBOL. In
   "instrument-note" the token sits between a hyphen and a quote, neither of
   which is a word character, so a word-boundary rename matched inside the
   string literal: the sandbox emitted "instrument-instrument_note" and motion
   emitted "instrument-motion_note", and the motion page's notes silently
   stopped matching the stylesheet rule that styles them. Nothing in the
   repository could refuse it — a class name is resolved by the browser against
   CSS text.

   Repaired by CONSOLIDATION rather than by two corrected copies: motion already
   imported from the sandbox, so it now imports instrument_note and its
   duplicate helper is deleted. One helper cannot drift from itself.

   The whole corpus was then audited for the same class, not just this site: the
   multiset of every string literal in every .dag file was compared against the
   merge base. Exactly three literal changes are mine — this one, and two prose
   annotations that correctly re-cite renamed symbols — plus the gnu_bash_subject_ref
   consolidation. No other wire value moved.

   Witness: witness_note_class_wire_matches_stylesheet_selector, green, and red
   under either exact corrupted spelling.

2. THE CLASSIFIER'S TWO EXCUSING RULES WERE THRESHOLDS, AND THEY FAILED OPEN AT
   THE ONE NUMBER UNDER TEST. "Ten or more declarations is a convention" and
   "every candidate path contains .fixture. is an intentional collision" both
   remove rows from the hygiene bucket by shape, and that bucket is asserted at
   ZERO. Each subject is now NAMED and its defining property CHECKED against the
   tree — conventions must be one-per-module under a declared prefix, fixtures
   must match an exact pinned module set — and a subject that stops satisfying
   its property lands in `duplicate_unclassified`, which is loud and counted,
   never silently excused.

   Six controls in classifier_controls.py, all holding: a planted ten-declaration
   accidental fork stays hygiene, an unknown duplicate across two fixture modules
   stays hygiene, a convention name declared twice in one module is not excused,
   an ambiguity name with a third declaration is not excused, and both named
   subjects keep their dispositions.

3. NOTHING EXECUTED THE TWO-SOURCE UNION. dependency_resolution_facts_live unions
   two producers that share a signature, so the call site that passed the import
   producer into both arms compiled clean and returned well-formed edges while
   dropping every reference-only dependency. A unit test of the fold would not
   have caught it; the defect is in which producers the production function calls.

   So the production function is pointed at a four-module fixture and asserted at
   identity grain in both directions. Restoring the doubled arm reds two of the
   five witnesses.

   The fixture's shape is DERIVED from the seam rather than invented: the two
   producers are disjoint by file — reference_resolution_facts emits nothing for
   a file carrying imports — so the reference-only dependency must live in an
   import-less consumer, and a same-path duplicate is unconstructible. The
   witness says so instead of asserting a dedup that cannot arise.

classifier_controls.py is registered in the gitignore authority; the repo-wide
*.py rule dropped this lane's scripts silently once already (review 50719).

* Regenerate receipts on the repaired head; record the classifier and edge-source repairs

Control 22 -> 10 (main's #8072 healed part of the annotation-grain class), corpus
16,382 imports / 2,583 files, stripped 3,098 = control 10 + attributable 3,088,
reconciliation OK. corpus_hygiene is absent from the ledger at ZERO, and so is
duplicate_unclassified - so the two remaining excusing dispositions did not
absorb anything: each was checked against the tree and both held.

All 10 control diagnostics sit in host_phase_status_witness_test.dag, which this
branch does not touch, so the hygiene batch still adds zero diagnostics - now
evidenced by the located diagnostics themselves rather than by a separate run of
main. The four new fixture modules contribute zero, measured, not assumed.

Also retires the doc's claim that the convention rule is 'derived, not a list'.
That was the fail-open threshold, and the section that says so is the section
asserting zero.

* Regenerate receipts on the merged head

Main advanced (#8054, #8069), so the corpus hash moved and the receipts no longer
described the tree. Re-measured rather than left stale: control 10 (unchanged,
same annotation-grain file this branch does not touch), corpus 16,388 imports
across 2,583 files, 3,160 = 10 + 3,150, reconciliation OK.

corpus_hygiene remains ABSENT AT ZERO through a main advance that added 62
residual rows - which is the more informative reading than the first zero was:
the close survives the corpus moving underneath it, because it removed forks
rather than pinning a snapshot. duplicate_unclassified is also zero, so both
named excusing dispositions still satisfy their checked properties on a corpus
neither was authored against.

All witnesses re-run green on this head, and the anchor re-verifies.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 9, 2026
…ay (#8071)

* Repo atlas sandbox: stable module raster with a real SCM change overlay

A static, server-rendered atlas of the live .dag module population at
/sandbox/repo-atlas. No stream, no canvas runtime, no WebGPU, no incremental
graph mutation, and no agent occupancy.

THE LAW ON THE CARRIER: SCM tells the atlas what changed; the semantic graph
tells it what structure now exists; the reverse-impact reading tells it what
may be affected; actor observations later tell it who is touching what. None
of those facts may substitute for another. Each is a separate field with its
own absence arm.

gunbc.repo_atlas_projection mints exactly one concept — AtlasAddress{ring,slot},
a renderer-neutral ordinal position — and consumes ModuleDeclarationFact,
ModuleIdentity, GitDiffStatusEntry and ImpactReading from their existing
authorities. The address is a pure function of semantic identity: it never
receives the population, so adding an unrelated module moves nothing.
Collisions share a cell with an occupant list rather than displacing, which is
also what caps rendered elements by cell count.

The address derives from a bounded 12-hex-digit prefix of the std.content_hash
digest — a projection of that hash, never a second hash; 16 digits overflow
i64. Sixteen declared rings sum to 3392 cells against 3403 live modules.

Head-only limit stated as a type, not absorbed: deleted paths and renamed old
paths cannot be resolved against the head, so they land in unprojected_changes
rather than being assigned to whatever module occupies that path now. Unmerged,
pairing-broken, unknown and truncated observations refuse the whole overlay
instead of dropping the bad entry and drawing a clean-looking rest.

GitDiffChangeStatus carries NINE arms; DiffPairingBrokenStatus is enumerated
here rather than left to a default.

The page emits four co-registered SVG groups sharing one coordinate frame.
Ring and slot lower through nested transforms, so no trigonometry enters the
model and a future renderer computes different numbers from the same address.
The impact plane is emitted only from a real reading; with none, the readout
says impact not computed rather than drawing zero affected modules.

Measured on the live tree: 2168 occupied cells, 437,522 bytes of HTML.

Verification: 23 projection claims, 12 page claims, 16 serve claims green by
execution. Two walls mutation-tested — making deleted paths resolve against the
head reds the departure claim, and removing the unmerged refusal reds that
claim while the untouched pairing-broken claim stays green, so the suite
discriminates at the mutation rather than everywhere.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Serve the atlas as a complete styled document, and point the claims at it

Three findings from review 50752, all confirmed against the code.

THE ROOT ONE IS THE THIRD. The page claims serialized repo_atlas_section
while the route served repo_atlas_page, so twelve green claims covered a
shape the handler never returns — a headless, unstyled page stayed green
through all of them. A claim aimed at the wrong subject is not a weak claim;
it is not a claim about the product at all. repo_atlas_document now takes the
snapshot as a parameter and IS the served shape, repo_atlas_page is the thin
live binding, and every page claim drives the document with fixtures.

The other two are what that miscovered subject was hiding.

repo_atlas_page emitted a bare <main> with no charset, viewport, title,
stylesheet, or header, unlike every sibling on the same serve table. It now
emits a full document through the same pattern.

No CSS existed for atlas-dot, atlas-dot-changed, atlas-impact-ring or the
readouts, so on the live route a real SCM change mark was visually identical
to an ordinary structural cell while the carrier's own note claimed the four
channels stay "distinguishable at a glance". That is rung inflation — a note
asserting a property the artifact did not have. atlas_rules derives the
stylesheet from the design register: structure is FigureRole below full
strength, a direct change is FigureLitRole at full strength (brightness is the
change channel and nothing else uses it), impact is a STROKE on a separate
concentric circle so affected and changed cannot be confused, and a shared
cell strokes its own dot in the structure colour — denser without borrowing
the change channel. Glow stays absent: it belongs to selection, and an unused
channel is safer than one that collides with occupancy later.

Retargeting immediately caught a real interaction: with the stylesheet
embedded, ".atlas-dot-changed" appears in every document as a CSS RULE, so the
negative half of the change-mark claim matched the stylesheet. The needle is
now the emitted class attribute, which distinguishes a rule that exists from a
mark that was applied.

Also merges origin/main. The heal job was red on `trim` not in scope in
extdeps/uri.dag and repo_local_git_config.dag — files this branch never
touched. fn trim is defined in dag/std/algebra.dag by #8062 (Class B
pool-independent binding repair), which landed after this branch point; the
branch had no definition at all. Base skew, not a defect here.

Verification on the merged tree: 23 projection + 16 page + 16 serve claims
green by execution. Live render 459,332 bytes, styled, complete document.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Five load-bearing corrections: comparison identity, plane split, angular precision

All five findings verified against the code before fixing; three changed what
the atlas literally draws.

1. COMPARISON IDENTITY. AtlasChangeOverlay had only Projected and Refused, so
an authored empty diff — nobody ran a comparison — rendered identically to a
comparison that ran and found nothing. Bottom-as-answer conflated with
bottom-as-ignorance, in the field whose entire job is saying what changed, two
fields away from the impact carrier that already gets this right.
AtlasChangeObservation adds NotObserved / Observed{comparison,diff} /
Unavailable{cause}; AtlasComparison carries exact base, head and relation and
the readout prints all three.

The page was ALREADY wet — module_declaration_facts_live reads the working
tree — so moving only the Git read would have split one observation across two
seams. Both live reads now sit in repo_atlas_observe_changes and the pure
repo_atlas_document receives a completed snapshot. The head is BOUND, not
assumed: a subject is claimed only when git status --porcelain is observed
empty, because a dirty tree means the module facts and the comparison describe
different worlds. Executed receipt on this tree: it correctly refused with
ComparisonHeadUnbound. StatusPorcelain and RevParse are readonly additions to
the EXISTING extdeps.git module — no new extdeps module, preflight intact.
First-parent HEAD^..HEAD, deliberately not CI baseline semantics.

2. PLANE SPLIT. The module claimed four independently transformable planes
while expressing a change as a class on the STRUCTURE circle — the claim in
prose, the fusion in markup. atlas_change_plane is its own group. A second
defect dissolved with it: marking the structural dot marked the CELL, so in a
shared cell every occupant read as changed when one was; the change plane now
marks changed OCCUPANTS and titles them alone. Dead atlas-dot-impacted class
removed.

3. ANGULAR COLLAPSE. The serializer divided millidegrees by 1000 and emitted
whole degrees. Measured against the declared table: ring 14 collapsed 8 slots,
ring 15 collapsed 32 — 40 distinct addresses drawn on top of one another
before any hash collision, and worse than a collision, which the model handles
honestly by sharing a cell. Three padded decimals now; live render shows
rotate(204.545). The witness pins the exact pairs that collapsed.

4. STATUS TOTALITY. Three folds used wildcards, so a tenth upstream arm would
have compiled clean and become an ordinary non-departed change. All nine arms
enumerated; a new upstream status now fails to typecheck.

5. COLLISION CONTROL. The old claim passed when the planted names did NOT
collide, and its companion drove the same identity twice, which is a duplicate
fact rather than a collision. Two distinct names that genuinely collide, with
the collision REQUIRED. The separate duplicate-fact question is decided:
identities deduplicate before cells exist, so one subject observed twice does
not inflate density.

Two cost shapes fixed while here, both the idiom
dedup_import_resolution_facts_cost_note condemns: the cell order list and the
identity dedup now cons-and-reverse with map-backed membership rather than
appending or linear-scanning.

Keyboard: the atlas is ONE focus stop. Per-cell tabindex over 2168 cells was a
2168-stop trap.

Verification: 26 projection + 21 page + 16 serve claims green. Four mutations
discriminate — deleted-resolves-against-head, unmerged-stops-refusing (control
arm stays green), not-observed-collapses-to-empty, and whole-degree rotation.
The last is the sharpest: the transform-text claim fails while the model-level
claim stays green, which is why the claim is on emitted text.

Measured: 439,965 bytes, 2168 occupied cells. Cold 148.4s, second run 152.6s,
byte-identical — gunbc run recompiles each time, so this harness has NO warm
path and the figure is closure compile (frontend 8s + reconcile 12s + the
bare-reference closure), not atlas render. A real cold-vs-warm split needs a
served process and is owed with the browser receipt.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Route SCM inspection through git.Inspect instead of forking git.Core

Both findings confirmed against the code (review 50800).

THE FORK. git.Inspect already owns WorkingTreeStatus and HeadCommit, and its
own module note ends "No second Git inspection surface remains in
extdeps.git." The previous commit added StatusPorcelain and RevParse to
git.Core anyway — a parallel authority beside the one that exists, in a slice
whose carrier header claims it consumes existing authorities rather than
forking them. I grepped git.dag for the operation names and never looked for
an inspection module, which is the DFS-the-concept-DAG step DESIGN 2 asks for
and I skipped. Both operations are reverted; extdeps.git is untouched by this
PR again, so the extdeps preflight result is a clean no-change rather than an
argued-for addition.

THE ARGV, WHICH WAS THE MATERIAL HALF. WorkingTreeStatus pins --porcelain=v1,
-z and --untracked-files=all. The one that mattered is the last: plain
--porcelain honours a repository-local status.showUntrackedFiles=no, so a tree
carrying untracked files could report an EMPTY status while
module_declaration_facts_live still read those files. The atlas binds its
subject on exactly that emptiness, so the weaker argv could have bound a
subject to a tree the comparison does not describe — a fail-open on the
head-binding wall this slice exists to add, reachable by local config alone.
Re-deriving an argv the authority had already gotten right was the whole
defect.

Executed receipt: the page renders through git.Inspect and still refuses with
ComparisonHeadUnbound on this dirty tree, now naming untracked files among the
causes.

26 projection + 21 page + 16 serve claims green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Cons-and-reverse the projection accumulator, the last quadratic in the slice

Named as a non-blocking consistency nit in review 50810, taken because DESIGN
6 does not leave it optional: a proven cost-shape defect is always fixed
regardless of the realized n, and pricing a per-site exception is itself the
redundant work the rule exists to remove.

The internal contradiction is the sharper reason. This PR already carries two
notes condemning concat(acc, [x]) as the idiom that cost another lane an OOM
and then 900 seconds — while atlas_project_entry did exactly that per diff
entry, on both lists. A future reader would have found the code and the notes
disagreeing in one module.

"The diff is small here" is also not a time-stable fact: this same fold
answers a two-file PR and a thousand-file merge, and reuse is what changes n.

The fields are named marks_rev / unprojected_rev so a later edit cannot append
to them believing they are in final order. Consing seeds in order and
reversing the flat result once restores the original order exactly, so the
projection is unchanged by construction — the multi-seed ordering claim and
the departed-path ordering claims still hold.

26 projection + 21 page claims green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the dead cell-marked predicate and its unused import

Both flagged as cleanup nits in review 50816 and both verified dead: after the
change plane was split out, atlas_cell_any_marked lost its only caller to
atlas_changed_occupants and has zero references anywhere in the tree, and
atlas_impact_is_exact is imported by the page module and never used.

Taken rather than deferred because DESIGN 5 names dead scaffolds a decidable
wall-now class, and these are two declarations in a module this PR is
introducing — shipping a brand-new file already carrying dead surface is the
cheapest possible thing not to do. Both reviewers declined to elevate them,
which is right; they are not correctness defects and this is the last change.

26 projection + 21 page claims green, unchanged by the deletion.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Follow ImpactReading losing its cycles field on main

The floor's compile-clean gate refused: field 'cycles' not found in type
'ImpactReading', at the three sites where these witnesses construct a fixture
reading. Local runs were green throughout, because CI evaluates the pull
request's MERGE REF — this branch against CURRENT main — while the local tree
sat at the base it was merged from. Base skew again, and this time it reached
the code rather than a neighbouring lane.

Cause: #8054 removed cycles from ImpactReading. Nothing in this slice ever
read that field; the witnesses only had to supply it to construct the record,
so the fixtures drop it and the projection is untouched.

Worth naming, since it is the second base-skew red on this PR: a green local
witness run does not establish that the merge ref compiles, and the two
diverge silently whenever main moves under a long-lived branch. The
compile-clean gate is what caught it both times.

26 projection + 21 page + 16 serve claims green on the merged tree.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 10, 2026
…map onto the 2026-08-10 stop (#8116)

* Roadmap: declare the infrastructure lanes, and make main the fleet's desired state

The roadmap carried no node for most of what is now the priority. Verified
against the authority before writing anything: zero hits for TasksMax, sccache,
compile pool, build cache, Spark, ctrl-build, or the generated-file merge
driver; one incidental hit for GitHub Actions ownership. The three "watchdog"
hits are observation-collapse-watchdog-restatement, a display concept that
happens to share the word with the runner recovery timer.

The fleet lane's six rows all say the same shape - given a stated setting,
apply it and read it back. None binds MAIN as where that stated setting comes
from, which is exactly the gap: the mechanism half was modelled and the
authority half never was.

Meanwhile the work exists in design documents nothing on the roadmap points at.
generated-file-conflict-policy.md is operator-ruled with four chartered lanes
and no nodes. fleet-self-converge-enforcement-design.md names the self-converge
timer as missing on every host and calls it the highest-risk gap. It also cited
roadmap node 2-periodic-actuation, deleted in the 2026-07-27 refresh - repointed
here to its successor fleet-anti-entropy-hygiene rather than left dangling.

Sixteen nodes across five lanes, three of them new:

  fleet +5              main-revision-authority, atomic-convergence-verdict,
                        runner-host-convergence, runner-broker-recovery,
                        spark-inference-serving
  ci-placement +1       compile-pool-envelope
  ci-control (new) 4    owned-execution, executed-coverage-receipt,
                        check-projection, actions-runner-retirement,
                        remote-build-containment
  generated-artifact 2  projection-registry-containment, commit-policy-census
  ci-cost +2            arc-reconciliation, build-once-per-subject
  judgment (new) 1      mechanical-review-service

Focus moves from the v1 exit and guarantee-ladder lanes to the infrastructure
lanes. Nothing is deleted or parked: 98 hidden rows are counted on the page and
one row restores the full view.

The judgment lane is deliberately off the page while its prerequisite is on it.

One witness repair, and it is not cosmetic. witness_projection_is_active_only
rendered through roadmap_authority(), which applies the focus, while both its
negative controls name ACCEPTED nodes. Any focus that stops selecting the
namespace and P-derive lanes therefore makes them absent because HIDDEN, and the
claim greens while proving nothing about acceptance. It now reads the
focus-independent view, where absence can only mean accepted - the same reason
witness_rendered_nodes_are_declared_or_derived already reads both documents.
Proven discriminating by planting an active node's headline as a negative
control (FAIL) and restoring it (PASS).

Executed: generated-artifact drift gate green after regeneration; 44/44
roadmap_authority witnesses; 39/39 roadmap_page; 13/13 roadmap_frontier;
7/7 roadmap_emit.

No acceptance receipts recorded. 123 nodes are active and only 9 carry a bound
closing check; merged is not accepted, and manufacturing receipts for 51 merges
would be the rung inflation this authority spends paragraphs forbidding.
roadmap-receipt-continuity is the one mechanically decidable candidate and is
left for the operator.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Compute fabric above CI, and the two nodes the wind-down inventory named

Two corrections to the previous commit.

ONE: the compute fabric was missing, and owning CI was standing where it
should have been. Building, checking, regenerating, changing machines,
serving models and eventually judging changes are four consumers of one
fabric, not four execution systems, and the previous cut put the build
story underneath ci-control - which makes owned CI the definition of a
build rather than one caller of it.

  compute-exact-work-contract
      exact subject in, one of five typed endings out. A branch name or
      a working directory is not a subject. A provider that cannot serve
      the requested operation class refuses BEFORE running rather than
      answering a smaller question.

  compute-artifact-return-and-materialization
      a write-producing computation cannot report success while its
      declared outputs are unreachable. That is the exact live defect:
      a remote run finished successfully, produced nothing locally, and
      the stale binary left behind was compared against itself.

It grounds on docs/plans/execution-spine-design.md rather than minting a
parallel concept. That document is operator-SIGNED (FLAGS A-E, 2026-07-09)
and its thesis is already that realization and materialization are the only
downstream readers of the dependency view - which is the fabric being asked
for. Minting a second scheduler beside it would have been the nicknaming
DESIGN section 3 forbids, in the place it costs most.

ci-owned-execution, ci-remote-build-containment, fleet-runner-host-convergence
and fleet-spark-inference-serving now depend on it. ci-remote-build-containment
is restated as what it actually is: a MIGRATION, whose only permitted additions
are refusals, and which is deleted once its useful behaviour is a provider
behind the contract. Remote execution does not live there.

TWO: two nodes the inventory named that genuinely had no home.

  ci-floor-discovery-snapshot
      the ordinary and scoped workers each walk the corpus in separate
      processes; the second walk measures around 284 seconds. It carries
      the complete typed result, never a pass-or-fail flag, and a consumer
      that finds it absent, damaged or wrong-subject refuses instead of
      recomputing. Distinct from phased-single-process-ci, which removes
      the cross-PHASE duplicate; this removes the cross-WORKER one.

  compiler-declaration-floor
      a value was observed flowing through a field declared as the wrong
      type while all fifty-two behaviour witnesses over it stayed green.
      Five planted defects refused separately, plus an unchanged-behaviour
      control so the wall cannot be satisfied by refusing more of the
      language. No rung asserted - the claims carrier says where it stands.

Focus adds compute. 100 hidden rows counted on the page.

The focus note now states plainly what a focus is NOT. Off the page sits
real retained work with real remaining boundaries, and nothing currently
records why a hidden lane is paused or what restarts it - a lane frozen
behind infrastructure, one draining to merge, and one parked because its
hypothesis was falsified are three states that all read identically as
absent. That is a missing dimension on the node, and it is named as landing
next rather than papered over here.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Deduplication before consumers, and the mechanism chain that removes preparation

The compute contract as landed said exact subject in, typed ending out. It did
not say identical computations collapse to one producer, and it did not say the
fabric owns admission. Without both, handing agents a compute interface is a
tidier way for ten callers to launch ten cold builds of one tree - the exact
failure the lane exists to prevent.

  compute-deduplication-and-admission
      two requests naming the same computation are one piece of work: one
      producer, everyone else a consumer of its result. The fabric decides
      how many cold builds a machine carries, what the pool's total demand
      may be, which host serves a request, and what order competing work is
      served in - and tells a caller which of those it waits on. Requests
      differing anywhere in the identity must NOT collapse, and a capacity
      refusal is counted rather than becoming an invisible queue.

It stands IN FRONT OF ci-owned-execution in the graph rather than beside it.
Owning CI adds a consumer, and a consumer added before the duplication is
removed multiplies the load instead of sharing it.

The mechanism staircase, each removing a DIFFERENT duplicate:

  ci-scoped-worker-shared-substrate   the second initialised world. Isolation
                                      keeps meaning separate mutable scratch
                                      and lifetime, never recomputing facts
                                      already fixed and immutable.
  ci-selection-before-preparation     preparation that precedes selection.
                                      Selection is sharp about meaning and
                                      blunt about cost: it concludes the
                                      corpus is irrelevant after discovering,
                                      naming, rostering and indexing it.
  ci-streaming-realization            the barrier between preparing and
                                      executing. Its acceptance property is
                                      that the first witness executes before
                                      the last selected entry is prepared.

Chained by dependency edges rather than declared as a set, so at most the next
one is startable and the limit on concurrent performance mechanisms falls out
of the graph instead of being prose nothing enforces. phased-single-process-ci
now sits behind the scoped-substrate row for the same reason. Width two is
deliberately absent from the chain and stays parked: the tested implementation
shared typed bytes while each worker still built its own world.

compute_consumer_admission_sequencing_note records the ruling and, separately,
that native realization and shared preparation are ONE programme. Emitting a
native bundle is the right destination and the miniature is decisive at its
scale, but the cited production enrolment delivered zero of three native and
three of three fallback, so the required path took no benefit - and native
bodies surrounded by duplicated preparation would still be bad CI.

Executed: drift gate green after regeneration; roadmap_authority 44/44.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Review response: native cutover unblocked, thresholds out of RED controls, dedup bound to a real build

Four review findings acted on. The lifecycle finding is answered by sequencing
rather than by content and is stated at the end.

NATIVE CUTOVER WAS STALE AND ORDERED BACKWARDS. native-selected-witness-bundle
read "merge #7599 once controls clear" and "fallback counts trending to zero".
#7599 is MERGED, and the cited production enrolment ran none of its three
selected members natively and fell back on all three. So the mechanism exists,
the required path takes no benefit, and the node was still describing the
mechanism as the work.

It is now a REPLACEMENT: emit the bundle, execute the selected population by
direct call, and DELETE that population's interpreter scheduling in the same
change. Interpretation survives only as a named differential control on a
cadence, never as a success arm the production path falls through to. Fallback,
interpreted and unavailable all at zero is the bar, not a residue to trend.

Its two parent edges are removed and one is REVERSED: five-minute-ci-gate now
depends on the cutover. The gate is an aggregate outcome, so making the cutover
wait for it meant the one step that removes the interpreter from the required
path could not start until the programme it contributes to had succeeded. The
warm-merge edge went with it - no input dependency was ever shown; the bundle
needs a selected population, an emitter and a toolchain, none of which merge
admission supplies. The node now has no parents and is startable.

witness_five_minute_ci_gate_program_chain_is_explicit CAUGHT THIS, which is
what it is for. It pinned the old edge shape, so the reordering had to be
deliberate rather than incidental. Updated to require the reversed edge and to
assert BOTH old edges absent, so the previous direction cannot return silently.

TIME THRESHOLD REMOVED FROM A SEMANTIC RED CONTROL. ci-scoped-worker-shared-
substrate required "the scoped segment falls by at least three minutes". That
is a tree-measured number standing in for a structural claim - the same shape
DESIGN section 5 rejects for census pins. Replaced with what the row actually
means: no second source loading, no second index construction, no second
initialised world, same population, same outcomes, bounded scratch, no path
back to cold construction. Wall, CPU and memory sit beside it as observations.
A timer moving cannot claim a duplicate was removed, and a duplicate genuinely
removed is not disqualified by a noisy host.

DEDUPLICATION IS BOUND TO A REAL ARTEFACT BUILD. Its first slice was open to
being demonstrated on two read-only checks collapsing into one verdict - the
one case where duplicate work costs nothing, while the case that swamps the
fleet is two cold builds. It now names two agent sessions requesting the same
artefact-producing build, one producer, one compilation, one returned output,
two attached consumers - and it depends on artifact return rather than
standing beside it.

LIFECYCLE: not in this PR, by agreement with the review. ProgramDisposition and
the work-item agreement land first as their own change and this stacks behind
them; RoadmapNode is constructed in 19 files and that shape change deserves an
isolated review rather than riding a 24-node expansion.

Executed: drift gate green after regeneration; roadmap_authority 44/44 with the
chain witness green on the new direction.

CI failure on b47d383 was infrastructure, established two ways: the regen job
died at "Setup Rust" with rustup ETXTBSY (exit 126, 10s in, before any content
ran) because runner slots share one home directory; and gunbc.roadmap_authority
is absent from the 112-module regen input closure, so this change cannot alter
regen output. regen_stage0 --verify run locally reports divergence count 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Lane 1 gets its node: commit-writer admission is scheduled first, not implied

Review response (PR #8034 review, finding 1): the conflict-policy charter's
four lanes were covered two-of-four, and the uncovered pair included lane 1 —
the one the charter titles "FIRST: the live safety hole" and the one
gunbc.repo_local_git_config's authority note names as the boundary a writer
cannot pass. A generated-artifact lane whose first row is the population and
whose absent row is the writer reads, on the page, as if the safety hole is
scheduled. Now it is scheduled, as the parent of the lane-2/3 chain, matching
the charter's own transaction ("prove no unmerged index entries — lane 1
predicate").

The node transcribes the charter's two refusal arms (unmerged-stage refusal;
staged-blob conflict-marker-grammar refusal) and the operator's second-pass
acceptance wall (complete staged-index observation, observed-not-declared
classification, provenance-receipt fixture exemption, writer bindings as
countable carriers). ROADMAP.md regenerated via generated_artifact_gate
main_wet; all 44 roadmap witnesses green by execution with the node in place.

Deferred per the same review's recommendation, recorded here: lane 4 (keyed
rosters get set/map construction semantics) and the execution-spine-design.md
doc-graph binding (needs a typed HandAuthoredDocBind anchor or a plan
registration) stack behind the sequenced work-item PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Consolidation: quarry #8033, add the deterministic confidence lane, reframe owned CI

Operator consolidation ruling (2026-08-08): #8034 is the sole roadmap authority
branch; #8033's parallel edits port here rather than merging beside it.

Ported from #8033, at their exact homes rather than as new identities:
- placement-compile-pool-envelope absorbs the task-vs-outer-budget distinction
  as typed acceptance classes (ProcessAdmissionExhausted, OuterResourceEnvelopeKilled,
  EffectiveLimitMismatch, CompilePoolPlacementRefused) plus the 8.8%-of-visible-limit
  receipt. No second placement identity.
- The five false-verification incident classes map to their existing exact homes
  in false_verification_incident_mapping_note; the proposed umbrella node does
  not port (a coarse identity over mechanisms this graph already decomposes is
  the §3 second authority).
- ci-gate-contention-independent-verdict lands as the one genuine gap, recut
  qualitatively: host load cannot decide a semantic merge verdict; timeout is a
  typed execution outcome, never assertion failure; the cutoff is never widened.

New lane: confidence-semantic-impact-query (owner confidence, on the focused
page) — the deterministic repository-inspection product, explicitly independent
of LLM/Spark; judgment-mechanical-review-service now depends on it as its
grounding packet. First consumer is one real corpus query usable by a person,
not a fixture suite.

Reframed: ci-owned-execution's old floor is quarry + shadow oracle, not the
template — obligations port only on a proven disagreement; first slice is the
exact-subject → bounded population → emitted bundle → owned execution → typed
receipt chain with the old path shadowing.

Updated: the focus note's namespace standing now carries the 2026-08-08
exact-subject re-observation (A–D established, E/F unavailable under P2a
triggers, frontier 2), superseding the stale none-of-six wording.

Structure: 151 unique ids, acyclic, no dangling edges, all cited paths resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Spark enrollment as fleet membership, and abstraction formation on the confidence chain

Two operator directions (2026-08-08), landed as four graph changes.

fleet-spark-host-enrollment: srv5/srv6 stop being hand-managed boxes. The
endpoint rows are DERIVED as a downstream projection joining procurement
identity and network allocation — re-typing the reserved address literal
refuses (§3 fork), a reverse import into the network intent refuses (the
measured cycle: procurement already imports it), and a second host-identity
authority refuses. Enrollment carries a GB10 inference envelope, never
runner-style thread capacity. Identity converge + reach ride the installed
fleet key. fleet-spark-inference-serving now depends on it; runtime, model
revision, auth and the collector bundle stay in the serving row, sequenced
separately per the operator's "1 and 2 now".

abstraction-candidate-discovery (owner confidence): descriptive grouping of
subjects observationally equivalent under a NAMED lens, carrying the
distinctions the quotient would erase, nearest existing authorities, and
over-collapse/demand standing. Descriptive evidence only — the normative
"these should share a layer" is an explicit bridge in the judgment row, per
the abstraction-calculus mode-crossing rule. Deterministic: no Spark, no LLM.
First slice hard-stops on an APPLIED acceptance (consumer migrated, duplicate
deleted, receipts equal) so discovery cannot become an inert analysis
service. REDs plant the three negative classes: keep-distinct on a
load-bearing distinction, projection-missing on a downstream-join pair (the
Spark endpoint session is the live receipt), demand-absent on a
consumer-less candidate.

judgment-mechanical-review-service broadens to the abstraction/modeling
ruling vocabulary (existing-authority, likely-duplicate,
candidate-new-abstraction, projection-missing, reprime-candidate,
keep-distinct, over-collapse-risk, missing-consumer/actuator/readback,
unknown) and gains the discovery dependency. Chain: confidence → discovery
→ judgment ← spark-serving; the Spark ranks and explains over exact packets,
it never becomes the repository index.

Structure: 153 unique ids, acyclic, no dangling edges; ROADMAP.md
regenerated via main_wet; 44/44 roadmap witnesses green by execution.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate ROADMAP.md from the merged authorities

Post-merge projection: the conflict on the generated file was taken
provisionally and the bytes here are main_wet's output over the merged
authority state, per the generated-file policy (regenerate, never
hand-resolve).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Bind the Spark standup accounting doc: main's floor has been red since #7972 landed it orphaned

docs/plans/spark-standup-program-accounting.md landed in the #7972 omega with
no HandAuthoredDocBind and no inbound link, so doc_graph_has_no_orphan_docs
(and doc_graph_is_clean) have correctly refused every main push since the
last green at 4cdcd57 — the doc-reachability wall working as designed,
fleet-wide. Attribution receipt: replaying the doc-graph reachability rule
(ROADMAP.md/DESIGN.md/runbook roots + registered plans + hand binds, markdown
links as edges) over last-green main, current main, and a candidate branch
shows exactly one orphan appearing in the window, this doc.

The bind anchors on the physical facts the doc records —
gunbc.dgx_spark_procurement spark_a3ee_reservation / spark_3bd5_reservation —
and its dissolution names the follow-up the doc itself declares: the Spark
standup program landing as roadmap rows, findings migrating to typed
carriers, then the doc registers as a plan or deletes and the bind deletes
with it.

Verified by execution: doc_graph_has_no_orphan_docs and doc_graph_is_clean
both PASS on this tree; both FAIL on its parent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Floor fixes: four boundaries back inside the brief budget; ROADMAP reprojected

The floor's brief-budget witness (100 words of authored boundary per ticket,
gunbc.roadmap_page ticket_brief_word_budget) redded on four nodes this branch
authored or lengthened: ci-owned-execution (104), commit-writer-admission
(106), abstraction-candidate-discovery (114), judgment-mechanical-review-
service (114). Each boundary is trimmed to <=100 tokens with no clause of the
bar dropped — overflow either compressed or already carried by the node's
other fields (abstraction discovery's no-model-server fact lives in its
out_of_scope). Max boundary is now 99.

The sibling doc-graph reds are main's breakage (the #7972 omega landed
docs/plans/spark-standup-program-accounting.md orphaned; every push since
last-green 4cdcd57 refused): fixed for the fleet in PR #8053 and carried
here by cherry-pick so this branch's floor does not wait on that merge.

Verified by execution on this tree: witness_ticket_brief_budget_holds_and_reds
PASS, doc_graph_has_no_orphan_docs PASS, doc_graph_is_clean PASS, roadmap
suite 44/44, regen ExitSuccess.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Final Spark/convergence recut per executive verdict

Narrow Spark enrollment to membership/profile/endpoint with honestly
Unobserved cells; join lifecycle cells into the fleet convergence
verdict and name the one-producer defect; spell the inference-serving
internal path; make the fleet participation migration the first
abstraction-candidate-discovery specimen.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Add ci2-complete-native-cost-receipt: whole-corpus native shadow experiment as the bounded cutover's immediate successor

Operator direction 2026-08-08: keep CI2-0's bounded acceptance attainable;
measure emission/compilation/execution walls separately over the complete
roster, then decide from the measured warm wall whether per-PR selection
remains load-bearing or is deleted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI-0 recut: one row, one PR — fallback deleted, whole corpus classified, emitted, executed, authoritative (operator 2026-08-08)

Collapses diagnosis-precursor / bounded-cutover / whole-corpus-receipt
into a single state transition on native-selected-witness-bundle;
deletes the ci2-complete-native-cost-receipt row added earlier today.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Add roadmap-serve-emitted-realization: dissolve the interpreted serve scaffold via emit-on-demand (srv1 outage 2026-08-08)

Interpreted concat clones its accumulator (quadratic); emitted concat
moves (linear). Order: emit wiring first, content-hashed bodies second,
concurrency last; request deadline regardless; belt GcpProjectId fix
folded in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Reconcile #8034 per operator review: record #8054 failed acceptance on confidence-semantic-impact-query; collapse five-minute-gate parent onto the CI-0 one-PR child (cursor review 50559 §3 finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire compiler-declaration-floor into guarantee_ladder_edges (cursor review 50566)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Catch #8034 up to the day's rulings: CI-0 staged (3-member merge, producer successor, v2-only terminal), general-witness-body-producer row with construct census, CONFIDENCE post-rework standing, structural fork detector as abstraction-discovery first slice

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Operator amendment: two judgment modes over one evidence substrate, semantic judgment receipt, model-selection successor, serving infra acceptance, participation-criterion detector, forward-intent refusals

Incorporates worker corrections: participation over shape as the
mechanical criterion; consumer-verb stringly-enum class moved into the
deterministic detector; runner-vs-inference capacity control marked
not-yet-built.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire fleet-runner-broker-recovery into the fleet graph (cursor review 50583)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Wire ci-executed-coverage-receipt and ci-gate-contention-independent-verdict as prerequisites of ci-check-projection (cursor review 50587)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* De-number the gate program prose: dispatch order follows graph edges (cursor review 50595 non-blocking finding)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* CI2-0 mandate recut: one node, complete v2 witness-execution cutover in #8043 — producer successor row deleted (operator mandate 2026-08-08)

The census's 3-of-9,353 was circular (restated enrollment, never
attempted realization); the fixture route's limits were mistaken for
compiler limits. No successor PRs; canonical-pipeline wiring, per-identity
semantic-kind x realization-standing from actual attempts, predecessor
deletion, and the whole-population receipt all land in #8043.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Dirty-worktree verification as compute's first daily consumer (operator verdict 2026-08-08)

Amends compute-exact-work-contract first_slice: exact dirty-tree snapshot
runs all affected (or explicitly conservatively complete) v2 tests, exact
receipt at most 5s warm, BaseUnstable a distinct answer; confidence
optional for narrowing, never correctness. No new node.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0 node and the two-command product interface (operator convergence mandate 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main: link the #8062 probe receipt, admit its specimen module to the debt ceiling, read trim's input in its seam

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Move the probe-receipt link to the emitting plan authority (review 50763)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Regenerate model-realization-fork.md from the amended authority

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Hoist in-body annotations to module grain in two witness files (12 §4c refusals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* V2-LENS-0: dispatch trigger, checkpoint structure, permanence laws (operator ruling 2026-08-09)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Record the four-lane closeout and the root it identified

Four lanes (CONVERGE, CI RESET, CI2-0, DEVBOOT-0) closed 2026-08-10 with zero
displacement between them. Each was asked for the root with evidence and
explicitly invited to reject the manager's hypothesis; all four declined to
confirm it.

The re-cut that matters: of 11 rejecting members in one real std closure, 5 are
normalize contradicting its OWN declared contract (retaining wrapper
declarations, then rejecting the tree those retentions live in via its own
module-grain well_formed gate) and only 3 are genuine frontend gaps. A broken
contract is a bounded repair; a missing capability is a program.

Synthesis across the four: nothing could be verified incrementally — the
acceptance contract demanded the whole corpus and moved between measurements,
the mechanism demanded 60-75 minutes and gated deploys as well as merges, and
the instruments built to escape both were themselves unverified.

Written to git rather than left in message threads because five sessions were
archived today holding measurements, one leaving a PR whose premise had been
reverted underneath it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal main's SubstrateLongLaneRow schema break, and reconcile the roadmap onto the 2026-08-10 stop

Two things, the first a live main repair found while validating the second.

MAIN IS RED AND NOTHING WAS GOING TO CATCH IT. #8114 (24ff2da) added 18
SubstrateLongLaneRow literals carrying `dissolve_on:`; #8059 (45e7024)
merged after it and renamed that field to `dissolution: DissolutionCondition`.
Each PR was green alone and the pair is red — the merge race a merge queue
exists to prevent, landing during the runner outage, so no run has reported it.
All 18 now carry `unbound_dissolution(description: ...)` and name their sibling
row explicitly rather than saying "same as sibling row", which is the vague
prose #8059 was eliminating. Verified: compiling ci_layer_roots' closure emits
zero SubstrateLongLaneRow diagnostics (the residual exit=1 is the pre-existing
25-row §4c population in host_phase_status_witness_test.dag, untouched here).

ROADMAP RECONCILIATION. ROADMAP.md is a generated artifact; the authority is
dag/gunbc/roadmap_authority.dag. Baseline control first: the unedited authority
reproduces the committed ROADMAP.md exactly, modulo one trailing newline the
CLI adds — so the instrument was validated before it was trusted.

The structural fix: edge(five-minute-ci-gate -> native-selected-witness-bundle)
is DELETED. The entire CI-cost chain — discovery snapshot, scoped substrate,
early selection, streaming — hung beneath a node that is now stopped and can
never be accepted, so every floor row was unschedulable. It was also backwards
on the merits: a 3,290s floor carries 97s of witness evaluation, so an
infinitely fast evaluator leaves ~97% of the floor standing and native
execution was never the CI-cost lever.

Four rows follow from that:

- native-selected-witness-bundle re-cut from "complete cutover in one PR" to
  the self-host frontier it always was (operator root 3). The frontier is
  stated as measured: of 11 rejecting members in one real 15-file std closure,
  5 are normalize contract violations, 2 the graft guard working, 3 genuine
  LEX/PARSE gaps, 1 uncaptured. A broken contract is a bounded repair; a
  missing capability is a program — they do not schedule together. The sugar
  chain is deferred WITH its SHAs (6888b97 -> f62e838 -> c84842c):
  cherry-picked clean onto main it is 5/5 FAIL, because separability was
  asserted from a description and refuted by execution.
- five-minute-ci-gate carries the measured decomposition rather than a
  narrative: 1,422s discovery/setup, 690s scoped worker, 97s evaluation;
  duplicate discovery 295.7s + 284.3s; selection paid after preparation;
  one missing typed key costing 82-96% of a cold symbol-index build.
- five_minute_ci_gate_program_note updated, because DESIGN cites it as the
  single authority for sub-lane scope and dispatch order and must not carry
  a second copy.
- v2-lens-suite-execution's trigger ("after CI2-0 terminal acceptance") is
  unreachable and now says so. It KEEPS its dependency deliberately: its own
  handback demands zero v1 lens-body executions, so relaxing the trigger would
  only move the frontier into the handback.

Regenerated ROADMAP.md from the edited authority; the lead-budget lens returns
[] (no violations).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* Heal the second half of the #8059 schema break: HasTrigger is not a constructor

wise-boar-328 hit a symptom my first commit did not cover, reproducing it
independently while merging main into #8109. Checked rather than assumed, and
it is real: dag/gunbc/doc_graph_roots.dag calls `HasTrigger { text: ... }` in
81 places and HasTrigger is DEFINED NOWHERE IN THE TREE.

All 81 were introduced by #8059 (45e7024) itself — the same PR that renamed
SubstrateLongLaneRow.dissolve_on. So that PR shipped a nonexistent constructor
81 times and merged during the runner outage, where nothing executed it.

The intended form is not a guess. The field is typed:

  HandAuthoredDocBind.dissolution: PlanRetirement
  PlanRetirement = PlanRetiresWhen { condition: DissolutionCondition }
                 | PlanHasNoRetirement

and the file ALREADY IMPORTS both `PlanRetiresWhen` and `unbound_dissolution`
while using neither — the imports were written for the correct form and the
constructor call was wrong. Each payload is free text describing when the plan
retires, which is UnboundDissolution by construction (BoundDissolution carries
a DeclarationRef, not prose), so every row becomes:

  dissolution: PlanRetiresWhen { condition: unbound_dissolution(description: ...) }

Verified by execution: compiling doc_graph_roots' closure emits zero errors and
zero HasTrigger/PlanRetirement/dissolution diagnostics. The residual 25 hard
diagnostics are the pre-existing §4c annotation population in
host_phase_status_witness_test.dag, untouched and unrelated.

Main needed both halves; the first commit alone would have left it red.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

* The cancelled-check row stops predicting and carries its three receipts

gunbc.ci_process_end_to_end already legislated this class — "no check present
means not yet observed and never counts as satisfied; cancelled, timed out,
refused by the infrastructure, and genuinely failed stay four different things"
— but its displaced_cost was written as a PREDICTION ("an absent check
currently reads the same as one that passed elsewhere"), so nothing made it
rank. It now carries measurement, supplied by calm-ram-435 who had recorded the
class before tonight:

  #7932 @ 493de34 (2026-08-07)  a CANCELLED required ci folded into PASS; the
                                tally reported MERGE CRITERIA MET while GitHub
                                held mergeStateStatus=BLOCKED
  #8051 @ b4a8d5d               two runs on one head; the concurrency-cancelled
                                one pinned checks_state at PENDING beside a
                                SUCCESS row
  #8059 (2026-08-10)            merged on a cancelled run → 99 sites, two files

THE SKEW RUNS BOTH WAYS. One cancelled row reads as pass in one direction and
as pending in the other, so no single sign-correction closes it — which is why
red_control now demands an executed control for EACH direction, and says the
verdict derives from the authoritative merge state rather than from aggregating
rollup rows. It also names the adjacent trap: mergeable: MERGEABLE is GitHub's
conflict-freedom field, not a checks verdict, so it is never a second
confirmation of anything.

What #8059 cost is stated as the receipt rather than as a story: main could not
derive its own generated artifacts, every PR adding an emitted module was
blocked, three sessions each found it believing their own branch was broken,
and two independently wrote the same 81-row repair within a minute. None of the
99 is a review gap and none is a review fix — each is a type error the compiler
decides in milliseconds. The only thing that had to happen was for the checks
to run.

Verified: main_wet EXIT=0 with drift confined to this authority edit and its
regenerated ROADMAP.md projection; lead-budget lens returns [].

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018gTJKsR5YdkaEc2SUGN9ff

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant