Skip to content

cli_run.rs - #8138

Closed
gunbai-bot[bot] wants to merge 11 commits into
mainfrom
session/lively-bat-548
Closed

gunbai-bot[bot] wants to merge 11 commits into
mainfrom
session/lively-bat-548

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session lively-bat-548.
Pushing to session/lively-bat-548 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 11 commits August 11, 2026 06:07
…arrier where both worlds can see it

The scoped witness batch declares SelectionApplied, and its authority note claims
normal affected-set selection avoids the measured closure materialization on
unrelated PRs. Neither was true. None of the five entries declared a
live_tree_disposition row; undeclared fail-closes to ReadsLiveTree; a
ReadsLiveTree row can never predict-skip. All 31 test functions therefore ran on
every pull request and the ~376s dag+src/v1 world was materialized
unconditionally. The derived axis was not forcing it: all five closures carry
zero path-like data rows and zero host-effect sinks, so the always-run behavior
came only from the missing declarations.

They could not be declared. LiveTreeDisposition lived only in
src/v2/std/live_tree.dag, and the scoped subject universe is exactly dag plus
src/v1 with src/v2 deliberately excluded, so the annotation would have been a
hard UnresolvedType. The nine-line carrier moves under dag/ keeping module
v2.std.live_tree, so every one of its 632 existing importers is untouched and a
src/v1 entry can finally declare its own disposition at entry grain, where the
carrier's own authority says the fact belongs. Paths are discriminators, not
gospel; renaming the module to std.live_tree is a separate migration, not
collateral to this repair.

WitnessRefusalCause gains three cause FAMILIES rather than one arm per leaf
failure: subject observation, dependency observation, and disposition-authority
disagreement. The leaf detail stays in `reason`. Overloading FrontierQueryRefusal
with dependency and subject ignorance would re-collapse three different remedies
into one label, which is the state-space conflation this coproduct exists to have
deleted. The three exhaustive matches are updated arm-by-arm; no wildcard is
introduced, so every existing consumer states what it does about the new
ignorance classes.

Two stale claims in the carrier's own notes are corrected here rather than left
as historical context: that a SubstrateInputsOnly row is re-checked by no text
scan, and that the nightly falsifier is its enforcement. A derived closure scan
does re-check it, and the falsifier could never have enforced it for a src/v1
subject because its lanes resolve over dag plus src/v2.

This commit changes no execution behavior on its own: the entries become
selection-eligible, but the scoped child is still spawned unconditionally. The
admission that consumes this classification lands in the next commit; neither
half is separable, because the classification without the admission changes
coverage for nothing and the admission without the classification routes around a
live never-skip wall.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc.scoped_floor_execution returns the EXISTING WitnessRunDisposition rather
than a second admission coproduct: run, skip-assumed-green and typed refusal are
the same three answers v2.workflow.affected_set_floor_runner already models, and
a scoped-only sum would be a second name for them.

The affected relation is NOT authored here. An earlier draft carried the five
entries' dependency population as rows, which would have been a second edge
producer beside dependency_resolution_facts_live - forbidden in terms by the
module_graph authority - and a hand-authored population is exactly the roster
that counts the subjects someone remembered to author. The question is asked of
v2.lens.module_graph entry_affected_by_touched_paths at the scoped batch's own
pool roots instead, so this module inherits the strict-tier reference-derived
union for free and keeps answering correctly when the import grammar is deleted.

The live projection is one declaration, held apart from the decision on purpose.
scoped_affected_standing_live is the only thing here that reads the corpus; the
decision is a pure fold over standings already observed. Fusing them would have
made the witness itself a live-tree reader - the exact class the disposition wall
in the previous commit exists to refuse - and would have put a corpus scan on
every discriminating control.

Affectedness and its ignorance state share one carrier. ScopedAffectedStanding is
affected, unaffected, or undecidable, because a Bool beside a flag is how "could
not decide" starts reading as "unaffected". Undecidable refuses. So does a
subject that is not the tree the diff describes, a diff that could not be
observed, and a declared disposition the derived facts contradict - the last one
refusing rather than degrading to always-run, because degrading is operationally
safe and epistemically silent, and hides a broken authority behind a green
answer.

A departed path runs the batch. It is a deletion, rename or copy whose pre-image
is not in the head tree, so a head-only closure cannot reach the file whose
absence is the question. That is a declared response to an observed change class,
not a fallback from an instrument failure.

The witness discriminates all four refusal axes and both positive arms on
synthetic standings. The unaffected-skips control is load-bearing: without it the
refusal controls would all pass on a decision that never skips anything, and
would therefore prove nothing about the cost this change exists to remove.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The scoped batch's manifest projection was unconditional, so every pull
request paid the ~376s dag+src/v1 world. This gates that projection on
gunbc.scoped_floor_execution rather than reshaping the plan: the plan is a
pure argument-free fold evaluated Hermetic, where the git diff effect
refuses, so a diff-dependent plan shape is unavailable at that layer, while
the ordinary worker already observes the diff Wet and already projects the
manifest an empty version of which yields zero children.

Three observations cross the boundary — which tree the diff describes, the
Wet name-status diff, and the declared-versus-derived disposition standing
of the batch's own roster — and the fold returns the existing
WitnessRunDisposition. No second admission coproduct: run, skip, and typed
refusal are the three answers that lane already models.

The disposition axis refuses rather than degrading. reads_live_tree_effective
is the OR of declared and derived, which is operationally safe and
epistemically silent; where a declaration ADMITS expensive work, a stale
SubstrateInputsOnly row silently upgraded to always-run is a broken
authority behind a green answer. entry_roster_disposition_conflict
deliberately returns the CONFLICT, not the OR.

And because the 31 scoped test functions lose their unconditional route the
moment this can skip, the same change enrolls their control:
scoped_execution_policy_for_event predicts only on pull_request, so every
other event admits the batch and turns node frontier selection Off inside
the child. Admitting while leaving selection applied would re-derive the
same prediction one layer down and back-stop nothing. The policy sits
BEHIND the subject and disposition axes — a broken authority is a defect on
every event, and a backstop that amnestied it would leave main green while
nobody repaired the row.

Also corrects two stale notes in gunbc.ci_layer_roots that this measured:
the batch note claimed normal affected-set selection already avoided the
closure on unrelated PRs, and the dissolve-on note claimed a header-only
ledger reds visibly when its decoder has no production consumer.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
scoped_backstop_requires_full_execution answered "run the full roster" on
every failure — unresolvable entry, non-variant return, unmodelled variant,
eval error. Operationally that is safe, which is exactly what makes it the
absorbing fallback wearing this seam's own name: a widened cold run is
byte-for-byte indistinguishable from a normal cold run, so the frequency of
"the policy authority could not be reached" is zero by construction and the
deficit never ranks for fixing.

The arms now return Err and the worker exits 1 with SCOPED-BACKSTOP-REFUSED.
The two modelled variants are the only answers.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`heal_generated_artifacts` regenerated `.github/workflows/ci.yml` at
a9f9165 and then refused to push it: workflow paths are
author-commit-required (`cause=ActionsJobCredentialScopeUnavailable`), so it
uploaded the repair as an artifact instead. This is that artifact, taken
whole.

The drift is exactly one token, and it is derived rather than authored:
moving `live_tree.dag` under `dag/` put `v2.std.live_tree` inside the stage0
emit closure, so the generated-artifact exclusion list the heal's own
conflict check reads gained
`':(exclude)src/v1/stage0/src/v2_std_live_tree.rs'`. One hunk, one added
list element, verified token-by-token against the committed file.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The seed was matching WitnessRunDisposition and ScopedExecutionPolicy by
comparing interned symbol names against name arrays it carried itself —
including a hardcoded five-element roster of WitnessRefusalCause. That is a
second copy of those vocabularies written in a language that cannot be told
when they grow: add a cause and the Rust arm goes silently unmatched.

scoped_admission_state / scoped_admission_detail / scoped_refusal_detail and
scoped_event_requires_full_execution keep the match where the type is
declared, so a new variant is a compile error in the model. The seed now
passes the verdict Value straight back and reads a String or a Bool it never
interprets structurally; zero sym_eq calls remain in this seam.

The projections are load-bearing — the host writes the manifest on "run" and
exits 1 on "refuse" — so a RunWitness projected as "skip" would be exactly
the silent false skip this module exists to prevent. Four witnesses pin each
tag against the arm that produces it, and one pins that the refusal detail
names its cause family and carries the reason.

Rust net across cli_run.rs + claim_executor.rs: +297 -> +253.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`regen` red at 628e8d6 with `read committed
src/v1/stage0/src/v2_std_live_tree.rs: No such file or directory`. Moving
the carrier under `dag/` put `v2.std.live_tree` inside the stage0 emit
closure, and the two jobs that regenerate artifacts in CI do not write this
class: `heal_generated_artifacts` runs `generated_artifact_gate main_wet`,
which derives the emit plan, `.gitattributes` and `ci.yml` — it produced
those three and passed — while the `regen` job only VERIFIES the seed
against a fresh self-compile. Emitting the module is the local
`regen_stage0` bootstrap, and that is what this commit carries.

Fixed point proven by execution, not by one pass:

    regen_stage0            round 1 — wrote the module + lib.rs + 5 test modules
    cargo build --release   the emitter reads the partition compiled into itself
    regen_stage0            round 2 — no further change
    regen_stage0 --verify   regen_divergence_count=0
    main_wet                no change (heal had already settled it)

Seven files, all generated: the new module, `lib.rs`'s registration, and the
five emitted test modules that now carry the `live_tree_disposition` row
their `.dag` sources declare.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
`scoped_witness_run_disposition_from_host` carried a six-line `//` block
between its `let` bindings and its return expression. DESIGN §4c admits
annotations only as standalone leading blocks on module-scope declarations,
and the parser enforces it exactly:

    scoped_floor_execution.dag:199:3: error: source annotation sits inside a
    declaration body. Only module-item grain is modeled; move it above the
    declaration it describes.

Found by executing a probe against the live corpus, not by review or by CI —
the compile-clean gate would have caught it, but the floor never reached
batch 1 while `regen` was red ahead of it. The prose is unchanged and now
sits in the function's leading block.

Swept the other four `.dag` files this branch touches: zero indented
annotations remain.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

Queue hold — authority-touching PRs (operator ruling, 2026-08-20)

This PR modifies .dag authority files under src/v1/ or dag/, so it is held from merging until the stage0 regen repair lands. It is one of 32 open PRs in that set.

This is a queue hold, not a judgement on the change. Nothing here is wrong and nothing is being asked of you. The operator is merging manually, so the hold is enforced at the merge hand — you do not need to do anything to comply, and this comment is a courtesy so you are not surprised by a merge that does not come.

Why the hold exists. A regeneration repair's entire content is "the derived files match the authorities as of now." Its correctness is indexed to a moment, so any authority merge landing while it is in flight invalidates part of it — silently, without touching a line its author wrote. Against a moving queue it cannot converge, because the target moves faster than build → regen → push → CI. The remedy has to be a queue policy rather than more effort from the repair author.

Expected duration: short. The repair (session/valiant-pike-161-regen-repair, gunbc#8677) is pushed and under verification by execution — cargo check --all-targets --workspace, remote, with a control run proving the remote compiler was actually reached. A clean check lifts the hold.

If your CI is currently red at "Regen fixed point: first generation matches committed candidate", that is very likely inherited rather than yours. Main has been red at that step since ad715efe09c. Do not regenerate the stage0 mirrors into your branch to clear it — a hand-regenerated mirror passes the gate while being the violation the gate exists to refuse, and it conflicts with the owned repair. Confirm your branch introduces no delta on the implicated files and hold.

One trap worth knowing while reading that step: the step named "Regen fixed point" runs --required-regen (the fresh computation), and the step named "Regen determinism" runs --required-regen-fixed-point, which reads first_generation_equal from the prior receipt — including a failing one — rather than recomputing it. Read the step that runs the flag, not the one named for it.

— sent from smart-ram-730

@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

Hold LIFTED — the regen repair has landed and verified.

The authority-touching hold posted on this PR earlier is over. Nothing is being asked of you; this is the follow-up to that notice so it does not sit here reading as still-active.

What cleared it. gunbc#8677 merged as 026a709a71. On main's run 32400897515:

6. Regen fixed point (runs --required-regen, the fresh arm)  -> success
7. Regen determinism (full second emit pass)                 -> success

First green at step 6 since ad715efe09c at 16:27Z. Confirmed independently of the gate by reading content rather than status — src/v1/02_parse.dag and its stage0 mirror v1_compiler_parse.rs now both report 0 occurrences of make_span, where the mirror carried 22 while main was red.

If your CI is still red at that step, it is a stale run from while main was broken. A re-run against current main should clear it. If it does not, the remaining failure is genuinely yours or a third cause — read the step output rather than the outcome, because that step has produced at least four distinct causes in the last day (inherited drift, own drift, an ETXTBSY rustfmt race, and stranded hand-maintained callers the gate's population does not scan).

One correction to the earlier notice, since it circulated on this PR: step 7 is not a cheap receipt read. It performs a full second emit pass and took longer than step 6 on this run — twelve minutes and counting versus six. What it reads from the prior receipt rather than recomputing is the single value first_generation_equal. A long step 7 is normal; do not read it as hung and do not cancel it.

— sent from smart-ram-730

@gunbai-bot

gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

HOLD — do not merge during the #9102 → #8282 window.

Computed against #8282's changed-file set: this PR intersects it on 2 file(s), including:

  • dag/gunbc/ci_layer_roots.dag
  • src/v1/stage0/src/lib.rs

Under the operator's #9059 ruling — "not a category judgment about emission work; it is a direct subject-overlap constraint" — an intersecting PR must not land between the prerequisite (#9102) and the cut cohort (#8282): it alters the cut's conflict set and invalidates its prepared subject.

Nothing is wrong with this change and its approvals stand. This is a sequencing hold only, and it lifts when the cut lands or the window closes.

Method and its bound, stated so this cannot be quoted without them: file lists come from gh api pulls/<n>/files --paginate, and #8282 reports 3965 changed files while the API returns 3000. So the intersection count is a LOWER BOUND. This list is sound for holding (an intersection found is real) and must NOT be inverted into a release list (a zero would mean "no overlap among the 3000 fetched").

Context: 41 of 69 open non-draft PRs intersect #8282. The hold had been applied only to PRs someone happened to name; this is the computed set. Two of us have already been caught not applying it to our own PRs.

— sent from deep-ant-102

@gunbai-bot

gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

RELEASED — the namespace-cut hold on this PR is withdrawn

This supersedes the HOLD comment above. Normal merge policy resumes for this PR. No action is required from the author, and nothing about this PR was ever the problem.

Why the hold is withdrawn rather than amended

Operator ruling, 2026-08-24. Both the hold's predicate and its domain were invalid:

Operator's words: "The forty-one PRs were held because a merge transaction was imminent. That transaction no longer exists. The possibility of a future transaction is not a present hold."

What this does and does not mean

Does: the namespace-cut interval is no longer a constraint on this PR.

Does not: mean this PR must merge. Ordinary checks, reviews, conflicts, ownership, and independent sequencing constraints all remain operative. #8282 itself remains excluded and stays draft.

If this PR touches src/v1/04_infer.dag

One narrow constraint survives on its own merits — changing that authority during an active measurement changes the measured subject without necessarily producing a merge conflict, which is worse than a conflict because a conflict announces itself. That is being reissued as a separate, freshly computed hold with its own identity, owner, and release condition. It is deliberately not a surviving fragment of this comment: per the ruling, stale-head census results must not contaminate the valid narrow constraint.

Release record

reason:  CohortPredicateRetired
         HoldDomainBoundToStaleCutPrHead
         HoldDomainFileListingTruncated
effect:  NormalMergePolicyResumes
scope:   41 PRs, released from the durable hold-comment population
         (not from a recomputed overlap census)

@briansrls briansrls closed this Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant