Skip to content

Settle the census's misfiled-bucket question by measurement; delete the dead import it names - #8612

Merged
briansrls merged 9 commits into
mainfrom
session/eager-crane-282
Aug 20, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/eager-crane-282

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Settle the census's misfiled-bucket question by measurement, and delete the dead import it names

The census flagged three modules as possibly-misfiled -- package_delivery,
codex_app_server_press and provider_wire_evidence route through retained_foreign,
whose dissolves_to is the Bash emitter (foreign executors and pre-runtime
bootstrap), while appearing to run inside a present gunbc runtime. It recorded
that as "a question for their owners -- the executor window is the deciding fact
and this document does not own it."

The question was decidable without them. package_delivery calls
shell.Mkdir.Parents and shell.Find.FilesAndSymlinksWithMode -- typed operations
that cannot execute without a present runtime -- in the same function bodies that
then fall back to retained_foreign. A function that interleaves a typed operation
with a retained foreign script is runtime-present by the fact that its first half
ran. So the six remaining calls declare the wrong dissolution target.

Three corrections fall out, all measured on 98d7147:

  • provider_wire_evidence has ZERO retained_foreign call sites. Its effects became
    typed extdeps.shell operations under review 50540; what survived was an unused
    import, deleted here. It is struck from the bucket, which is 12 rather than 13,
    struck through rather than dropped -- a census row that vanishes without
    explanation cannot be told from one that was never measured.

  • The call counts are stale in the direction the census warns about elsewhere:
    5 and 1, not 7 and 3.

  • package_materialized_tree_observation_note records replacing a find-piped-to-sort
    string with shell.Find plus in-substrate std sort, because the string form escaped
    its quoting on a root containing an apostrophe and forked an authority
    extdeps.shell already owned. That migration landed at ONE site; another instance
    remains in the same module with the same shape and the same exposure. A carrier
    that records a fix should name the population it fixed, or the next reader takes
    the note as coverage.

Local whole-corpus compile was started and killed at 15 minutes without
terminating, so it is INCONCLUSIVE rather than clean -- stated rather than omitted.
The deleted import is verified unreferenced by grep; CI's floor is the census.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

Brian Searls and others added 9 commits August 19, 2026 07:44
…ot the universal effect model

gunbc#8467 establishes that an argv array is a serialization, exactly as bash
text is a serialization of a bash AST. Accepted. But stated without a boundary
it reads as replacing every typed effect with a CLI tree, which moves the
authority downward into one realization technology -- the section 3 violation
this lane exists to name, one layer below where it usually appears.

So the two lanes are one migration program with a named boundary. This lane
owns the semantic destination and site routing: the authority stays the typed
domain operation or typed HostEffect, and it decides whether a realization is
native, REST, filesystem, library, CLI-backed, or necessarily text-emitting.
#8467 owns the inside of the CLI-backed cell. A native handler reaches no CLI
surface at all.

The census also carried a stale unit. Sizing by argv occurrence, then by
executable head, then by tool each produced an inflated remainder, because a
tool vertical, its site cutovers and its host_effect_apply caller are commonly
ONE vertical whose acceptance condition is the old site's deletion. The
measured shape, production only:

  transport shell   236 lines / 48 files -- 230 lines / 45 files in extdeps
  argv:             457 lines -- 275 extdeps, 172 gunbc, 10 src/v2
  bridge calls      48 across 13 files
  fn *_argv         333, of which ~158 model no tool at all

transport shell is overwhelmingly an extdeps population, i.e. beneath
already-typed operations. This lane's original job -- getting shell out of the
intent -- is substantially done; the remainder is transport depth. Recorded
with the caution that a transport shell block is not a shell program at all:
the seed executes it as Command::new(&argv[0]).args(&argv[1..]).

Two finish lines are therefore named separately, SHELL-DAG and CLI-AUTHORITY,
so a row complete against the first but owing the second reads as the boundary
working rather than as incomplete work. A SHELL-DAG row is never blocked on
CLI-AUTHORITY.

One live instance found while verifying: extdeps.exec.command
command_over_transport builds append(ssh_exec_prefix, command.argv) -- the
exact SSH-as-prefix shape the boundary forbids -- in production, beneath the
generic runner, which is the mechanism by which remote argument boundaries are
lost. It shares a file with command_runner's argv -> quoted text -> heredoc
round trip, whose carrier already declared the repair in
command_runner_dissolution_trigger. The runner cut and the SSH target are one
vertical.

No code changes. DESIGN.md needs no edit and says so in the text: its shell ->
intent row already routes runtime-present sites to typed effects and confines
emission to foreign executors and bootstrap, so the boundary falsifies no
sentence in it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…weaken the sequencing claim

Review on #8535 found the first commit did the exact thing this document
warns about five times: it appended a corrected boundary beside stale
operational text without deleting the text it supersedes. The finding is
correct and the stale claim is load-bearing.

TransportScript has not been a transparent brand since #7962. It is a
sole_constructor record whose single mint transport_script_seal is
admit_callers-sealed to two production declarations, and the cast form closed
with it -- 04_infer sole_constructor_construction_diags judges a cast into a
sealed type. Both documents still asserted, in the present tense and in
fourteen places, that the brand is transparent, that `String as
TransportScript` is writable from any module, and that direct shell.Exec.Run
is guarded by validation rather than construction. All false at this head.

Enumerated by claim across both authorities rather than fixing the site under
review -- the document's own standing rule, added after the fifth time this
class recurred -- and rewrote every occurrence in place: section 3's terminal
paragraph, 4.F's heading and three table cells, the 4 dissolution trigger,
5's end-state paragraph, 5.E's heading, premise and ruling block, the
wind-down ledger row, the meta-exec row, and both sites in the invariant doc.
The leak fixture is reclassified as scan input and historical record; it can
no longer be cited as evidence the cast compiles.

What actually survives is smaller and different in kind: the two admitted
bridges take a bare body String, so arbitrary text still reaches a transport
through a counted, reason-bearing, dissolves_to-carrying call. Conspicuous,
not impossible, and it dissolves by per-site migration rather than by further
wall work.

Also from the review, each verified before acting:

- The bridge count named no files. Enumerated all 13. Three -- package_delivery,
  codex_app_server_press, bmc_netboot_serve -- are absent from the section 4
  punch-list that still calls itself complete at 78f43c3. Recorded as that
  snapshot's correction, not as a second census.

- A classification question the count concealed: package_delivery (7 calls) and
  codex_app_server_press (3) route through retained_foreign, whose dissolves_to
  is the Bash emitter, while both appear to run inside a present gunbc runtime.
  If so, ten calls declare the wrong destination. Flagged for their owners; the
  executor window decides it and this document does not own that fact.

- "A SHELL-DAG row is never blocked on CLI-AUTHORITY" was true of the homing
  decision and false as a sequencing rule, with the counter-example named in
  the same document: command_runner's cutover needs the structured process-argv
  carrier, and its SSH arm the nested shell-command target. Reworded.

- Added an explicit statement that this is a boundary and scoping increment,
  not a closeout receipt -- neither finish line is met at this commit.

Merged main to pick up #8467, now landed, so the cross-PR references describe a
merged authority rather than an open branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The boundary section asserted DESIGN.md needed no edit BECAUSE its shell ->
intent open-thread row already routed runtime-present sites to typed effects.
That row is gone: #8476 cut DESIGN to ~9.5k words and removed open-threads
wholesale, and this branch merged main two commits ago.

The conclusion survives, the reason does not. What the boundary instantiates
now is section 3 general paragraph -- interface, realization and policy are
three facts, transport is a Realization handler one of N, dispatch sits
peripheral -- so a CLI-backed handler is that shape at the tool seam and
DESIGN still needs no edit.

Caught while verifying the previous commit against the rewritten DESIGN rather
than the one the clause was written against, which is the same check the
previous commit performed on fourteen other claims.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…te the dead import it names

The census flagged three modules as possibly-misfiled -- package_delivery,
codex_app_server_press and provider_wire_evidence route through retained_foreign,
whose dissolves_to is the Bash emitter (foreign executors and pre-runtime
bootstrap), while appearing to run inside a present gunbc runtime. It recorded
that as "a question for their owners -- the executor window is the deciding fact
and this document does not own it."

The question was decidable without them. package_delivery calls
shell.Mkdir.Parents and shell.Find.FilesAndSymlinksWithMode -- typed operations
that cannot execute without a present runtime -- in the same function bodies that
then fall back to retained_foreign. A function that interleaves a typed operation
with a retained foreign script is runtime-present by the fact that its first half
ran. So the six remaining calls declare the wrong dissolution target.

Three corrections fall out, all measured on 98d7147:

- provider_wire_evidence has ZERO retained_foreign call sites. Its effects became
  typed extdeps.shell operations under review 50540; what survived was an unused
  import, deleted here. It is struck from the bucket, which is 12 rather than 13,
  struck through rather than dropped -- a census row that vanishes without
  explanation cannot be told from one that was never measured.

- The call counts are stale in the direction the census warns about elsewhere:
  5 and 1, not 7 and 3.

- package_materialized_tree_observation_note records replacing a find-piped-to-sort
  string with shell.Find plus in-substrate std sort, because the string form escaped
  its quoting on a root containing an apostrophe and forked an authority
  extdeps.shell already owned. That migration landed at ONE site; another instance
  remains in the same module with the same shape and the same exposure. A carrier
  that records a fix should name the population it fixed, or the next reader takes
  the note as coverage.

Local whole-corpus compile was started and killed at 15 minutes without
terminating, so it is INCONCLUSIVE rather than clean -- stated rather than omitted.
The deleted import is verified unreferenced by grep; CI's floor is the census.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Conflict was in docs/plans/shell-to-dag-residual-census-and-arc-completion.md only
-- a hand-authored markdown file, not a generated projection (checked line 1 before
resolving). Both conflicting regions were this branch's new text against the
PRE-EDIT ORIGINAL, not against anyone else's change: main's edits to this file
(#8595's LANDED row) are elsewhere and auto-merged cleanly. Verified by diffing the
resolved file against origin/main and reading every removed line -- all ten are
exactly the text this branch deliberately replaced.

Merge commit rather than rebase, per repo policy: no force-push, so no dropped
dashboard approvals. The nag asked for a rebase; the policy asks for a merge, and
the merge reaches an identical end state without moving the head under review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 7aef448 into main Aug 20, 2026
1 check passed
@briansrls
briansrls deleted the session/eager-crane-282 branch August 20, 2026 02:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant