Skip to content

host_converge_realize: refuse multi-knob script concatenation - #8600

Merged
briansrls merged 2 commits into
mainfrom
refuse-multi-knob-concatenation-host-converge
Aug 20, 2026
Merged

briansrls merged 2 commits into
mainfrom
refuse-multi-knob-concatenation-host-converge

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Owned by session zesty-wren-670 (opened from a non-session branch).
Ownership basis: worktree-local artifact plus stated ability to act. NOT recalled authorship — the session cannot confirm authoring this PR post-compaction and has said so.


Summary

  • interpret_host_converge folds every implemented knob's effect_script into one concatenated string with no separator, and the host-effect runner gates Converged/NotConverged on that single script's exit code — i.e. the exit code of only the LAST command. A VerdictConverged resting on that exit code is silent wrongness: DESIGN §4b puts this class outside the guarantee ladder entirely, not a weak guarantee or a gap.
  • Measured liveness before filing (not sampled): gunbc_pinned_tree_knobs is unconditionally concatenated FIRST into every HostConverge.knobs list and targets the unimplemented GunbcPinnedTree arm, so the existing fail-closed all-or-nothing fold already refuses on knob Add SVG viz, test helpers, and makegen scaffold #1 before ever reaching a second (PerSlotMemoryCap) knob, for every real host today — with no knob-reordering fix available. The gap is structural, not a fact about hosts that happen to exist.
  • The repair is not set -e/&&-chaining the concatenated script — that would invest in the shell path this lane exists to delete. Instead, interpret_host_converge now refuses (typed, located ConvergeHostRefused) the moment a second knob's effect_script would be concatenated.
  • Full invalid-state/harm/rung/ceiling/next-trigger finding written directly onto the carrier as converge_host_multi_knob_concatenation_finding (a Disposition = Terminal), so the next author reads it where they're already standing rather than in a separate doc or work item.

Test plan

  • witness_multi_knob_script_concatenation_is_refused_not_silently_run — the discriminating RED: two PerSlotMemoryCap knobs must refuse, not silently concatenate
  • witness_single_implemented_knob_still_interprets — positive control: a single implemented knob still interprets normally
  • All 6 witnesses in host_converge_realize_witness_test.dag (4 pre-existing + 2 new) PASS via claim_batch, roster-matched, no truncation

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits August 19, 2026 23:18
… of running it as one silently-fused shell invocation

interpret_host_converge folds every implemented knob's effect_script into
one concatenated string with no separator between fragments, and the
host-effect runner gates Converged/NotConverged on that single script's
exit code — the exit code of only the LAST command. A verdict of
VerdictConverged resting on that exit code is silent wrongness: the class
DESIGN puts outside the guarantee ladder entirely, not a weak guarantee
or a gap.

Measured whether this path is live before filing: gunbc_pinned_tree_knobs
is concatenated first into every HostConverge.knobs list and targets the
unimplemented GunbcPinnedTree arm, so the existing fail-closed
all-or-nothing fold in interpret_host_converge already refuses on knob #1
before ever reaching a second (PerSlotMemoryCap) knob, for every real
host today, with no knob-reordering fix available. The gap is structural,
not sampled from the hosts that happen to exist.

The repair is not set -e/&&-chaining the concatenated script — that
invests in the shell path this lane exists to delete. Instead,
interpret_host_converge now refuses (typed, located ConvergeHostRefused)
the moment a second knob's effect_script would be concatenated, with the
full invalid-state/harm/rung/ceiling/trigger finding written onto the
carrier as converge_host_multi_knob_concatenation_finding.

witness_multi_knob_script_concatenation_is_refused_not_silently_run is
the discriminating RED: two PerSlotMemoryCap knobs must refuse, not
silently concatenate.
witness_single_implemented_knob_still_interprets is the positive control:
a single implemented knob still interprets normally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Per review: ConvergeHostRefused carries only reason: String, so this
refusal's cause collapses into the same prose field as
KnobUnimplemented — no caller can branch on why a host refused, and the
discriminating witness can only assert by string_contains on refusal
prose that no rule prevents a future edit from rewording. Naming this on
the finding rather than widening ConvergeHostRefused in this PR: the
refusal is worth having now at the strength it has, and turning a
free-today guard into a type-widening refactor would trade a landed wall
for an open branch. A typed refusal-cause variant, each cause counted, is
recorded as the natural next increment.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@briansrls
briansrls merged commit a6697a7 into main Aug 20, 2026
1 check passed
@briansrls
briansrls deleted the refuse-multi-knob-concatenation-host-converge branch August 20, 2026 01:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant