Repository navigation
cli_run.rs - #8138
cli_run.rs#8138gunbai-bot[bot] wants to merge 11 commits into
Conversation
…arrier where both worlds can see it The scoped witness batch declares SelectionApplied, and its authority note claims normal affected-set selection avoids the measured closure materialization on unrelated PRs. Neither was true. None of the five entries declared a live_tree_disposition row; undeclared fail-closes to ReadsLiveTree; a ReadsLiveTree row can never predict-skip. All 31 test functions therefore ran on every pull request and the ~376s dag+src/v1 world was materialized unconditionally. The derived axis was not forcing it: all five closures carry zero path-like data rows and zero host-effect sinks, so the always-run behavior came only from the missing declarations. They could not be declared. LiveTreeDisposition lived only in src/v2/std/live_tree.dag, and the scoped subject universe is exactly dag plus src/v1 with src/v2 deliberately excluded, so the annotation would have been a hard UnresolvedType. The nine-line carrier moves under dag/ keeping module v2.std.live_tree, so every one of its 632 existing importers is untouched and a src/v1 entry can finally declare its own disposition at entry grain, where the carrier's own authority says the fact belongs. Paths are discriminators, not gospel; renaming the module to std.live_tree is a separate migration, not collateral to this repair. WitnessRefusalCause gains three cause FAMILIES rather than one arm per leaf failure: subject observation, dependency observation, and disposition-authority disagreement. The leaf detail stays in `reason`. Overloading FrontierQueryRefusal with dependency and subject ignorance would re-collapse three different remedies into one label, which is the state-space conflation this coproduct exists to have deleted. The three exhaustive matches are updated arm-by-arm; no wildcard is introduced, so every existing consumer states what it does about the new ignorance classes. Two stale claims in the carrier's own notes are corrected here rather than left as historical context: that a SubstrateInputsOnly row is re-checked by no text scan, and that the nightly falsifier is its enforcement. A derived closure scan does re-check it, and the falsifier could never have enforced it for a src/v1 subject because its lanes resolve over dag plus src/v2. This commit changes no execution behavior on its own: the entries become selection-eligible, but the scoped child is still spawned unconditionally. The admission that consumes this classification lands in the next commit; neither half is separable, because the classification without the admission changes coverage for nothing and the admission without the classification routes around a live never-skip wall. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc.scoped_floor_execution returns the EXISTING WitnessRunDisposition rather than a second admission coproduct: run, skip-assumed-green and typed refusal are the same three answers v2.workflow.affected_set_floor_runner already models, and a scoped-only sum would be a second name for them. The affected relation is NOT authored here. An earlier draft carried the five entries' dependency population as rows, which would have been a second edge producer beside dependency_resolution_facts_live - forbidden in terms by the module_graph authority - and a hand-authored population is exactly the roster that counts the subjects someone remembered to author. The question is asked of v2.lens.module_graph entry_affected_by_touched_paths at the scoped batch's own pool roots instead, so this module inherits the strict-tier reference-derived union for free and keeps answering correctly when the import grammar is deleted. The live projection is one declaration, held apart from the decision on purpose. scoped_affected_standing_live is the only thing here that reads the corpus; the decision is a pure fold over standings already observed. Fusing them would have made the witness itself a live-tree reader - the exact class the disposition wall in the previous commit exists to refuse - and would have put a corpus scan on every discriminating control. Affectedness and its ignorance state share one carrier. ScopedAffectedStanding is affected, unaffected, or undecidable, because a Bool beside a flag is how "could not decide" starts reading as "unaffected". Undecidable refuses. So does a subject that is not the tree the diff describes, a diff that could not be observed, and a declared disposition the derived facts contradict - the last one refusing rather than degrading to always-run, because degrading is operationally safe and epistemically silent, and hides a broken authority behind a green answer. A departed path runs the batch. It is a deletion, rename or copy whose pre-image is not in the head tree, so a head-only closure cannot reach the file whose absence is the question. That is a declared response to an observed change class, not a fallback from an instrument failure. The witness discriminates all four refusal axes and both positive arms on synthetic standings. The unaffected-skips control is load-bearing: without it the refusal controls would all pass on a decision that never skips anything, and would therefore prove nothing about the cost this change exists to remove. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The scoped batch's manifest projection was unconditional, so every pull request paid the ~376s dag+src/v1 world. This gates that projection on gunbc.scoped_floor_execution rather than reshaping the plan: the plan is a pure argument-free fold evaluated Hermetic, where the git diff effect refuses, so a diff-dependent plan shape is unavailable at that layer, while the ordinary worker already observes the diff Wet and already projects the manifest an empty version of which yields zero children. Three observations cross the boundary — which tree the diff describes, the Wet name-status diff, and the declared-versus-derived disposition standing of the batch's own roster — and the fold returns the existing WitnessRunDisposition. No second admission coproduct: run, skip, and typed refusal are the three answers that lane already models. The disposition axis refuses rather than degrading. reads_live_tree_effective is the OR of declared and derived, which is operationally safe and epistemically silent; where a declaration ADMITS expensive work, a stale SubstrateInputsOnly row silently upgraded to always-run is a broken authority behind a green answer. entry_roster_disposition_conflict deliberately returns the CONFLICT, not the OR. And because the 31 scoped test functions lose their unconditional route the moment this can skip, the same change enrolls their control: scoped_execution_policy_for_event predicts only on pull_request, so every other event admits the batch and turns node frontier selection Off inside the child. Admitting while leaving selection applied would re-derive the same prediction one layer down and back-stop nothing. The policy sits BEHIND the subject and disposition axes — a broken authority is a defect on every event, and a backstop that amnestied it would leave main green while nobody repaired the row. Also corrects two stale notes in gunbc.ci_layer_roots that this measured: the batch note claimed normal affected-set selection already avoided the closure on unrelated PRs, and the dissolve-on note claimed a header-only ledger reds visibly when its decoder has no production consumer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sion/lively-bat-548
scoped_backstop_requires_full_execution answered "run the full roster" on every failure — unresolvable entry, non-variant return, unmodelled variant, eval error. Operationally that is safe, which is exactly what makes it the absorbing fallback wearing this seam's own name: a widened cold run is byte-for-byte indistinguishable from a normal cold run, so the frequency of "the policy authority could not be reached" is zero by construction and the deficit never ranks for fixing. The arms now return Err and the worker exits 1 with SCOPED-BACKSTOP-REFUSED. The two modelled variants are the only answers. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`heal_generated_artifacts` regenerated `.github/workflows/ci.yml` at a9f9165 and then refused to push it: workflow paths are author-commit-required (`cause=ActionsJobCredentialScopeUnavailable`), so it uploaded the repair as an artifact instead. This is that artifact, taken whole. The drift is exactly one token, and it is derived rather than authored: moving `live_tree.dag` under `dag/` put `v2.std.live_tree` inside the stage0 emit closure, so the generated-artifact exclusion list the heal's own conflict check reads gained `':(exclude)src/v1/stage0/src/v2_std_live_tree.rs'`. One hunk, one added list element, verified token-by-token against the committed file. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The seed was matching WitnessRunDisposition and ScopedExecutionPolicy by comparing interned symbol names against name arrays it carried itself — including a hardcoded five-element roster of WitnessRefusalCause. That is a second copy of those vocabularies written in a language that cannot be told when they grow: add a cause and the Rust arm goes silently unmatched. scoped_admission_state / scoped_admission_detail / scoped_refusal_detail and scoped_event_requires_full_execution keep the match where the type is declared, so a new variant is a compile error in the model. The seed now passes the verdict Value straight back and reads a String or a Bool it never interprets structurally; zero sym_eq calls remain in this seam. The projections are load-bearing — the host writes the manifest on "run" and exits 1 on "refuse" — so a RunWitness projected as "skip" would be exactly the silent false skip this module exists to prevent. Four witnesses pin each tag against the arm that produces it, and one pins that the refusal detail names its cause family and carries the reason. Rust net across cli_run.rs + claim_executor.rs: +297 -> +253. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`regen` red at 628e8d6 with `read committed src/v1/stage0/src/v2_std_live_tree.rs: No such file or directory`. Moving the carrier under `dag/` put `v2.std.live_tree` inside the stage0 emit closure, and the two jobs that regenerate artifacts in CI do not write this class: `heal_generated_artifacts` runs `generated_artifact_gate main_wet`, which derives the emit plan, `.gitattributes` and `ci.yml` — it produced those three and passed — while the `regen` job only VERIFIES the seed against a fresh self-compile. Emitting the module is the local `regen_stage0` bootstrap, and that is what this commit carries. Fixed point proven by execution, not by one pass: regen_stage0 round 1 — wrote the module + lib.rs + 5 test modules cargo build --release the emitter reads the partition compiled into itself regen_stage0 round 2 — no further change regen_stage0 --verify regen_divergence_count=0 main_wet no change (heal had already settled it) Seven files, all generated: the new module, `lib.rs`'s registration, and the five emitted test modules that now carry the `live_tree_disposition` row their `.dag` sources declare. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`scoped_witness_run_disposition_from_host` carried a six-line `//` block
between its `let` bindings and its return expression. DESIGN §4c admits
annotations only as standalone leading blocks on module-scope declarations,
and the parser enforces it exactly:
scoped_floor_execution.dag:199:3: error: source annotation sits inside a
declaration body. Only module-item grain is modeled; move it above the
declaration it describes.
Found by executing a probe against the live corpus, not by review or by CI —
the compile-clean gate would have caught it, but the floor never reached
batch 1 while `regen` was red ahead of it. The prose is unchanged and now
sits in the function's leading block.
Swept the other four `.dag` files this branch touches: zero indented
annotations remain.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Queue hold — authority-touching PRs (operator ruling, 2026-08-20) This PR modifies This is a queue hold, not a judgement on the change. Nothing here is wrong and nothing is being asked of you. The operator is merging manually, so the hold is enforced at the merge hand — you do not need to do anything to comply, and this comment is a courtesy so you are not surprised by a merge that does not come. Why the hold exists. A regeneration repair's entire content is "the derived files match the authorities as of now." Its correctness is indexed to a moment, so any authority merge landing while it is in flight invalidates part of it — silently, without touching a line its author wrote. Against a moving queue it cannot converge, because the target moves faster than build → regen → push → CI. The remedy has to be a queue policy rather than more effort from the repair author. Expected duration: short. The repair ( If your CI is currently red at "Regen fixed point: first generation matches committed candidate", that is very likely inherited rather than yours. Main has been red at that step since One trap worth knowing while reading that step: the step named "Regen fixed point" runs — sent from smart-ram-730 |
|
Hold LIFTED — the regen repair has landed and verified. The authority-touching hold posted on this PR earlier is over. Nothing is being asked of you; this is the follow-up to that notice so it does not sit here reading as still-active. What cleared it. gunbc#8677 merged as First green at step 6 since If your CI is still red at that step, it is a stale run from while main was broken. A re-run against current main should clear it. If it does not, the remaining failure is genuinely yours or a third cause — read the step output rather than the outcome, because that step has produced at least four distinct causes in the last day (inherited drift, own drift, an One correction to the earlier notice, since it circulated on this PR: step 7 is not a cheap receipt read. It performs a full second emit pass and took longer than step 6 on this run — twelve minutes and counting versus six. What it reads from the prior receipt rather than recomputing is the single value — sent from smart-ram-730 |
|
HOLD — do not merge during the #9102 → #8282 window. Computed against #8282's changed-file set: this PR intersects it on 2 file(s), including:
Under the operator's #9059 ruling — "not a category judgment about emission work; it is a direct subject-overlap constraint" — an intersecting PR must not land between the prerequisite (#9102) and the cut cohort (#8282): it alters the cut's conflict set and invalidates its prepared subject. Nothing is wrong with this change and its approvals stand. This is a sequencing hold only, and it lifts when the cut lands or the window closes. Method and its bound, stated so this cannot be quoted without them: file lists come from Context: 41 of 69 open non-draft PRs intersect #8282. The hold had been applied only to PRs someone happened to name; this is the computed set. Two of us have already been caught not applying it to our own PRs. — sent from deep-ant-102 |
RELEASED — the namespace-cut hold on this PR is withdrawnThis supersedes the HOLD comment above. Normal merge policy resumes for this PR. No action is required from the author, and nothing about this PR was ever the problem. Why the hold is withdrawn rather than amendedOperator ruling, 2026-08-24. Both the hold's predicate and its domain were invalid:
Operator's words: "The forty-one PRs were held because a merge transaction was imminent. That transaction no longer exists. The possibility of a future transaction is not a present hold." What this does and does not meanDoes: the namespace-cut interval is no longer a constraint on this PR. Does not: mean this PR must merge. Ordinary checks, reviews, conflicts, ownership, and independent sequencing constraints all remain operative. #8282 itself remains excluded and stays draft. If this PR touches
|
Auto-opened by session-dashboard for session
lively-bat-548.Pushing to
session/lively-bat-548advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan