Repository navigation
host_converge_realize: refuse multi-knob script concatenation - #8600
Merged
Merged
Conversation
… of running it as one silently-fused shell invocation interpret_host_converge folds every implemented knob's effect_script into one concatenated string with no separator between fragments, and the host-effect runner gates Converged/NotConverged on that single script's exit code — the exit code of only the LAST command. A verdict of VerdictConverged resting on that exit code is silent wrongness: the class DESIGN puts outside the guarantee ladder entirely, not a weak guarantee or a gap. Measured whether this path is live before filing: gunbc_pinned_tree_knobs is concatenated first into every HostConverge.knobs list and targets the unimplemented GunbcPinnedTree arm, so the existing fail-closed all-or-nothing fold in interpret_host_converge already refuses on knob #1 before ever reaching a second (PerSlotMemoryCap) knob, for every real host today, with no knob-reordering fix available. The gap is structural, not sampled from the hosts that happen to exist. The repair is not set -e/&&-chaining the concatenated script — that invests in the shell path this lane exists to delete. Instead, interpret_host_converge now refuses (typed, located ConvergeHostRefused) the moment a second knob's effect_script would be concatenated, with the full invalid-state/harm/rung/ceiling/trigger finding written onto the carrier as converge_host_multi_knob_concatenation_finding. witness_multi_knob_script_concatenation_is_refused_not_silently_run is the discriminating RED: two PerSlotMemoryCap knobs must refuse, not silently concatenate. witness_single_implemented_knob_still_interprets is the positive control: a single implemented knob still interprets normally. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Per review: ConvergeHostRefused carries only reason: String, so this refusal's cause collapses into the same prose field as KnobUnimplemented — no caller can branch on why a host refused, and the discriminating witness can only assert by string_contains on refusal prose that no rule prevents a future edit from rewording. Naming this on the finding rather than widening ConvergeHostRefused in this PR: the refusal is worth having now at the strength it has, and turning a free-today guard into a type-widening refactor would trade a landed wall for an open branch. A typed refusal-cause variant, each cause counted, is recorded as the natural next increment. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owned by session
zesty-wren-670(opened from a non-session branch).Ownership basis: worktree-local artifact plus stated ability to act. NOT recalled authorship — the session cannot confirm authoring this PR post-compaction and has said so.
Summary
interpret_host_convergefolds every implemented knob'seffect_scriptinto one concatenated string with no separator, and the host-effect runner gatesConverged/NotConvergedon that single script's exit code — i.e. the exit code of only the LAST command. AVerdictConvergedresting on that exit code is silent wrongness: DESIGN §4b puts this class outside the guarantee ladder entirely, not a weak guarantee or a gap.gunbc_pinned_tree_knobsis unconditionally concatenated FIRST into everyHostConverge.knobslist and targets the unimplementedGunbcPinnedTreearm, so the existing fail-closed all-or-nothing fold already refuses on knob Add SVG viz, test helpers, and makegen scaffold #1 before ever reaching a second (PerSlotMemoryCap) knob, for every real host today — with no knob-reordering fix available. The gap is structural, not a fact about hosts that happen to exist.set -e/&&-chaining the concatenated script — that would invest in the shell path this lane exists to delete. Instead,interpret_host_convergenow refuses (typed, locatedConvergeHostRefused) the moment a second knob'seffect_scriptwould be concatenated.converge_host_multi_knob_concatenation_finding(aDisposition = Terminal), so the next author reads it where they're already standing rather than in a separate doc or work item.Test plan
witness_multi_knob_script_concatenation_is_refused_not_silently_run— the discriminating RED: twoPerSlotMemoryCapknobs must refuse, not silently concatenatewitness_single_implemented_knob_still_interprets— positive control: a single implemented knob still interprets normallyhost_converge_realize_witness_test.dag(4 pre-existing + 2 new) PASS viaclaim_batch, roster-matched, no truncation🤖 Generated with Claude Code