Repository navigation
C-note correction: the build-cache verdict fold is an unconsumed authority, not dead code - #8623
Conversation
…ot the universal effect model gunbc#8467 establishes that an argv array is a serialization, exactly as bash text is a serialization of a bash AST. Accepted. But stated without a boundary it reads as replacing every typed effect with a CLI tree, which moves the authority downward into one realization technology -- the section 3 violation this lane exists to name, one layer below where it usually appears. So the two lanes are one migration program with a named boundary. This lane owns the semantic destination and site routing: the authority stays the typed domain operation or typed HostEffect, and it decides whether a realization is native, REST, filesystem, library, CLI-backed, or necessarily text-emitting. #8467 owns the inside of the CLI-backed cell. A native handler reaches no CLI surface at all. The census also carried a stale unit. Sizing by argv occurrence, then by executable head, then by tool each produced an inflated remainder, because a tool vertical, its site cutovers and its host_effect_apply caller are commonly ONE vertical whose acceptance condition is the old site's deletion. The measured shape, production only: transport shell 236 lines / 48 files -- 230 lines / 45 files in extdeps argv: 457 lines -- 275 extdeps, 172 gunbc, 10 src/v2 bridge calls 48 across 13 files fn *_argv 333, of which ~158 model no tool at all transport shell is overwhelmingly an extdeps population, i.e. beneath already-typed operations. This lane's original job -- getting shell out of the intent -- is substantially done; the remainder is transport depth. Recorded with the caution that a transport shell block is not a shell program at all: the seed executes it as Command::new(&argv[0]).args(&argv[1..]). Two finish lines are therefore named separately, SHELL-DAG and CLI-AUTHORITY, so a row complete against the first but owing the second reads as the boundary working rather than as incomplete work. A SHELL-DAG row is never blocked on CLI-AUTHORITY. One live instance found while verifying: extdeps.exec.command command_over_transport builds append(ssh_exec_prefix, command.argv) -- the exact SSH-as-prefix shape the boundary forbids -- in production, beneath the generic runner, which is the mechanism by which remote argument boundaries are lost. It shares a file with command_runner's argv -> quoted text -> heredoc round trip, whose carrier already declared the repair in command_runner_dissolution_trigger. The runner cut and the SSH target are one vertical. No code changes. DESIGN.md needs no edit and says so in the text: its shell -> intent row already routes runtime-present sites to typed effects and confines emission to foreign executors and bootstrap, so the boundary falsifies no sentence in it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…weaken the sequencing claim Review on #8535 found the first commit did the exact thing this document warns about five times: it appended a corrected boundary beside stale operational text without deleting the text it supersedes. The finding is correct and the stale claim is load-bearing. TransportScript has not been a transparent brand since #7962. It is a sole_constructor record whose single mint transport_script_seal is admit_callers-sealed to two production declarations, and the cast form closed with it -- 04_infer sole_constructor_construction_diags judges a cast into a sealed type. Both documents still asserted, in the present tense and in fourteen places, that the brand is transparent, that `String as TransportScript` is writable from any module, and that direct shell.Exec.Run is guarded by validation rather than construction. All false at this head. Enumerated by claim across both authorities rather than fixing the site under review -- the document's own standing rule, added after the fifth time this class recurred -- and rewrote every occurrence in place: section 3's terminal paragraph, 4.F's heading and three table cells, the 4 dissolution trigger, 5's end-state paragraph, 5.E's heading, premise and ruling block, the wind-down ledger row, the meta-exec row, and both sites in the invariant doc. The leak fixture is reclassified as scan input and historical record; it can no longer be cited as evidence the cast compiles. What actually survives is smaller and different in kind: the two admitted bridges take a bare body String, so arbitrary text still reaches a transport through a counted, reason-bearing, dissolves_to-carrying call. Conspicuous, not impossible, and it dissolves by per-site migration rather than by further wall work. Also from the review, each verified before acting: - The bridge count named no files. Enumerated all 13. Three -- package_delivery, codex_app_server_press, bmc_netboot_serve -- are absent from the section 4 punch-list that still calls itself complete at 78f43c3. Recorded as that snapshot's correction, not as a second census. - A classification question the count concealed: package_delivery (7 calls) and codex_app_server_press (3) route through retained_foreign, whose dissolves_to is the Bash emitter, while both appear to run inside a present gunbc runtime. If so, ten calls declare the wrong destination. Flagged for their owners; the executor window decides it and this document does not own that fact. - "A SHELL-DAG row is never blocked on CLI-AUTHORITY" was true of the homing decision and false as a sequencing rule, with the counter-example named in the same document: command_runner's cutover needs the structured process-argv carrier, and its SSH arm the nested shell-command target. Reworded. - Added an explicit statement that this is a boundary and scoping increment, not a closeout receipt -- neither finish line is met at this commit. Merged main to pick up #8467, now landed, so the cross-PR references describe a merged authority rather than an open branch. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The boundary section asserted DESIGN.md needed no edit BECAUSE its shell -> intent open-thread row already routed runtime-present sites to typed effects. That row is gone: #8476 cut DESIGN to ~9.5k words and removed open-threads wholesale, and this branch merged main two commits ago. The conclusion survives, the reason does not. What the boundary instantiates now is section 3 general paragraph -- interface, realization and policy are three facts, transport is a Realization handler one of N, dispatch sits peripheral -- so a CLI-backed handler is that shape at the tool seam and DESIGN still needs no edit. Caught while verifying the previous commit against the rewritten DESIGN rather than the one the clause was written against, which is the same check the previous commit performed on fourteen other claims. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…te the dead import it names The census flagged three modules as possibly-misfiled -- package_delivery, codex_app_server_press and provider_wire_evidence route through retained_foreign, whose dissolves_to is the Bash emitter (foreign executors and pre-runtime bootstrap), while appearing to run inside a present gunbc runtime. It recorded that as "a question for their owners -- the executor window is the deciding fact and this document does not own it." The question was decidable without them. package_delivery calls shell.Mkdir.Parents and shell.Find.FilesAndSymlinksWithMode -- typed operations that cannot execute without a present runtime -- in the same function bodies that then fall back to retained_foreign. A function that interleaves a typed operation with a retained foreign script is runtime-present by the fact that its first half ran. So the six remaining calls declare the wrong dissolution target. Three corrections fall out, all measured on 98d7147: - provider_wire_evidence has ZERO retained_foreign call sites. Its effects became typed extdeps.shell operations under review 50540; what survived was an unused import, deleted here. It is struck from the bucket, which is 12 rather than 13, struck through rather than dropped -- a census row that vanishes without explanation cannot be told from one that was never measured. - The call counts are stale in the direction the census warns about elsewhere: 5 and 1, not 7 and 3. - package_materialized_tree_observation_note records replacing a find-piped-to-sort string with shell.Find plus in-substrate std sort, because the string form escaped its quoting on a root containing an apostrophe and forked an authority extdeps.shell already owned. That migration landed at ONE site; another instance remains in the same module with the same shape and the same exposure. A carrier that records a fix should name the population it fixed, or the next reader takes the note as coverage. Local whole-corpus compile was started and killed at 15 minutes without terminating, so it is INCONCLUSIVE rather than clean -- stated rather than omitted. The deleted import is verified unreferenced by grep; CI's floor is the census. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Conflict was in docs/plans/shell-to-dag-residual-census-and-arc-completion.md only -- a hand-authored markdown file, not a generated projection (checked line 1 before resolving). Both conflicting regions were this branch's new text against the PRE-EDIT ORIGINAL, not against anyone else's change: main's edits to this file (#8595's LANDED row) are elsewhere and auto-merged cleanly. Verified by diffing the resolved file against origin/main and reading every removed line -- all ten are exactly the text this branch deliberately replaced. Merge commit rather than rebase, per repo policy: no force-push, so no dropped dashboard approvals. The nag asked for a rebase; the policy asks for a merge, and the merge reaches an identical end state without moving the head under review. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The C-note filed BuildCacheDaemonObservation / provision_build_cache_verdict / placement_verdict / build_cache_provision_gate_accepts as pre-existing dead production code with a deletion plan. I re-ran the census before acting on it. The zero-caller number reproduces exactly: 8 call sites for the gate, all in one witness file; zero production callers for any of the four symbols. The characterization does not. Reading the module's own receipt rather than the grep output, lane_e_srv1_ci_noncompletion_root_cause_receipt names placement_verdict as the FIX AUTHORITY for the stranded-sccache-server incident that killed CI builds at the 15m compile ceiling, and records that class as "INCIDENT CLEARED, NOT REPAIRED". Nine production modules import the module for other declarations, so the symbol-level zero sits inside a live file. That makes this a §4b rung finding, not a §2 redundancy one: the fold is correct and unasked. Green witnesses establish correctness, not that the class is guarded, and reporting them as the latter reads a rung above where the class sits. The deletion would have applied cleanly, taken the witnesses with it, broken nothing, and removed the named remedy for a recurrable CI-capacity incident -- with the witnesses' greenness as the property that made it look safe. Disposition changed from delete to wire-it-up, with the one measurement that could still make it benign named as the first thing to test. No code touched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…cement The correction said nobody should wire anything before establishing whether the provisioning path is ungated or gated by an equivalent check under another name. Measured on origin/main by reading the three modules involved. There is a check under a different name and it is not equivalent. realize_provision_build_cache gates on provision_build_cache_catalog_gate_verdict, which is pure catalog-id validation in a third module -- unknown id refuses, a non-sccache_local id refuses, otherwise realizable. It never observes placement, principal, unit ownership or lifecycle, so passing it says nothing about the stranded-daemon class the incident receipt names placement_verdict as the fix for. host_effect_realize matches none of the admission symbols. Two unconsumed authorities, not one: build_cache_ensure's admit_ensure_build_cache_instance is in the same state. Both name the same single next consumer, realize_provision_build_cache_body, so this is one wiring job rather than two -- materially smaller than the correction implied. The tree recorded this itself in ensure_effect_grain_migration_note. Verified against the code rather than quoted, since tonight's repeated failure was a correct measurement of a subject that had moved. It has not moved. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… kernel
The guarantee-recovery doc's calibration example read "a nonliteral refined
argument is RuntimeBoundaryOnly" -- a check that fires at the runtime boundary
rather than at compile time. Measured across all three kernels the refinement
family uses, that is true of none of them.
String the conversion runs and is the identity.
Executed: "" as NonEmptyStr returns "".
Int the only conversion refuses every value, so it is never used;
values arrive by declaration and no conversion runs.
Executed: the cast refuses a valid 5 identically to -1, and -1
reaching an EpochMs-declared parameter comes back unchanged.
collection a sound unforgeable wall -- private tuple field, new the only
door -- with zero call sites corpus-wide, and zero refinement
declarations over any collection base behind it.
A gate that passes everything, a gate nobody walks through, and a wall with no
door behind it. The Int row most needs stating: "fail-closed by absence of
capability" reads as safe and is not, since 74 declared positions against
effectively zero casts means the refusing conversion is almost never on the path.
This is the document's own section 4b failure rather than a wording slip: one
state was recorded for a class whose paths differ, and it was the strongest of
them. Each kernel needs a different remedy, so the row cannot be weakened -- it
has to be split.
Population recorded as a dated measurement with its limits: 3939 across 612
files at a750b67, four pre-committed predicates passing including a by-name
planted control, reproduced exactly on separate runners, corroborated by an
independent static scan smaller in the predicted direction. The instrument was
deleted, so the number is not reproducible without rebuilding it, and it is an
unverified-obligation population -- the census cannot distinguish violated from
unverified.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rv3 deferral measurement Two corrections to the residual census, both measured at origin/main 4cec10f. srv3_join_shell_words has zero definitions and zero mentions on main; it was cited in two places (the §1.C row and the §4.D deferred table) as a live srv3 transport helper. Removed from both. The five sibling symbols cited beside it all still resolve in gunbc.host_effect_realize and are left untouched. The srv3 deferral's premise is refuted by typed refusal: all 22 EmitArtifactThenThinRun arms in gunbc.host_effect_realize refuse, none accept, and the refusal names "reserved for ConvergePlan (host-effect Phase D)." The control widens it past that file -- the variant is realized nowhere in the tree; the three sites that appear to accept it are classifiers returning a Bool or the variant name for totality. So nothing is pending cutover and no srv3 site waits on a Phase D that exists. That settles the premise, not the disposition. Whether the srv* actuator graph survives at all is an operator decision, and migrating 22 call sites in a subgraph slated for deletion by another route is wasted work under a different premise than the original. Recorded as due for re-decision rather than expired. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tly one realizer The paragraph committed earlier today claimed EmitArtifactThenThinRun is realized nowhere in the tree and is therefore declared-but-unrealized. That is false, by exactly one path, in the file the claim examined most closely. realize_converge_on_host splits its EmitArtifactThenThinRun arm on gunbc_apply_mode_for_host: FreshStandup refuses as fail-closed Unimplemented, but ExistingHostQuiescentReload calls realize_converge_in_process -- the identical call the LocalShell arm makes. For an existing quiescent host the transport takes the same path as the shell transport. The sibling SshShell and FleetSsh refusals direct the caller to "use EmitArtifactThenThinRun", which points the same way. Two disguises produced the wrong count and each survives a scan written for the other: a refusal shaped as a success-valued record (hostname_set answers HostnameSetCasApplyFailed with the refusal in a stderr field, invisible to a NotConverged scan), and a realizer behind a refusing first sub-arm (the arm above, whose opening lines read as a refusal). Reading all 24 bodies was the only method that survived; the corrected text records both disguises so the next reader does not re-derive them. The srv3 conclusion is unchanged. The realizing path is for HostConverge, not for any srv3 effect -- every Srv3* arm still refuses. Only the supporting sentence changes: not "realized nowhere so nothing is pending" but "exactly one realizer, and srv3 is not on it." Corrected in place rather than annotated beside, per the standing rule against two accounts of one fact. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The What fails: Why it is not this PR: the entire diff is two Where it comes from — bisected, not inferred.
That commit changes Why I stopped rather than fixed it: closing this requires regenerating the stage0 mirror. Fleet policy is no regen, no mirror repair, no hand-carrying generated projections — escalate instead. Escalated. Every other merge requirement on this PR is green: 4 approvals, no REQUEST_CHANGES, no active reviews on this head, — sent from eager-crane-282 |
The paragraph recording how the one-realizer finding was measured stated that all 24 arm bodies had been read. That number came from the manual audits and is wrong. Measured at 4cec10f: 41 EmitArtifactThenThinRun occurrences -- 1 variant declaration in gunbc.host_effect, 36 production match arms across 14 modules, 4 in dag/test/claim. Neither manual audit reached 36 and neither mentioned gunbc.host_effect_codex_supervised_turn, whose arm answers CodexSupervisedSessionApplyRefused: a refusal named by its record rather than by a refusal type, which is the same disguise class the paragraph documents. The finding is unchanged -- exactly one arm realizes, realize_converge_on_host under ExistingHostQuiescentReload. What was wrong was the stated size of what had been examined, inside the paragraph about examining carefully. Recorded as a dated measurement at a named SHA for a derived detector to reproduce and reconcile against, explicitly not as a fixed law, since migrations are expected to change it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tend
Answering the census brief's stop condition -- whether existing parsed-body
facts can carry the derived census -- surfaced a lens already answering
approximately this question, which a later reader could mistake for coverage.
v2.lens.effect_reach classifies host-effect sinks and carries a ShellExecRunSink
variant. But sink_kind_for_callee selects by name equality against a remembered
callee-text list ("Run", "shell.Exec.Run", "Exec.Run", "WitnessBin.Run",
"Read"), everything else falling to UnknownHostEffectSink. That is the forbidden
seed form -- where we remember doing it rather than what interprets bytes as
shell -- and it cannot see sh -c, sh -s on stdin, or a sudo -S sh -s wrapper. It
carries the same blind spot this census carried before Spark was found.
Two bounds on its weight: it classifies from callee text rather than resolved
callee identity, the text-scanning substitution the brief's stop condition
forbids; and enforcement_live_witness_test asserts its contract is unbound, the
corpus's own record that it has no enrolled consumer.
Disposition is supersede rather than extend: a census seeded from interpretation
semantics subsumes its whole sink vocabulary, while extending it would inherit
its selection principle. Recorded so the derived cut treats it as prior art with
a known-narrow frontier, and so its ShellExecRunSink rows are never read as an
existing shell-reach population.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The census document's C-note filed
BuildCacheDaemonObservation/provision_build_cache_verdict/placement_verdict/build_cache_provision_gate_acceptsas pre-existing dead production code, with a deletion plan and a rehoming note for one witness helper. I re-ran the census before acting on it.The number reproduces.
build_cache_provision_gate_accepts(— one definition, eight call sites, all indag/test/claim/host_build_cache_provision_design_witness_test.dag. Zero production callers for any of the four symbols.The characterization does not. Two measurements the original census did not make:
lane_e_srv1_ci_noncompletion_root_cause_receiptnamesplacement_verdictas the fix authority for the stranded-sccache-server incident that killed CI builds at the 15-minute compile ceiling, and records that class asINCIDENT CLEARED, NOT REPAIRED ... the class can strand again the next time a slot retires while holding the server.gunbc.host_build_cache_provisionfor other declarations. The symbol-level zero sits inside a live, heavily-imported file — the shape that reads as dead from a whole-file glance and is not.So this is a §4b rung finding rather than a §2 redundancy one: the fold is correct and unasked. The refusal named as the remedy is computed by a function no production caller calls. Green witnesses establish that the fold is correct, not that the class is guarded; reported as the latter, the class reads a rung above where it sits — the inflation §4b calls worse than sitting low, because an inflated class never ranks for climbing.
The deletion would have applied cleanly, taken the witnesses with it, broken nothing, and removed the named remedy for a recurrable CI-capacity incident, leaving a prose receipt pointing at a symbol that no longer exists. The witnesses' greenness was precisely the property that made removal look safe.
Disposition changed from delete to wire it up, and the one measurement that could still make the finding benign — that the provisioning path is genuinely ungated rather than gated by an equivalent check under another name — is named as the first thing to test. The superseded
refuses()rehoming note is kept rather than dropped, in case a future measurement re-establishes the deletion case.No code is touched. This is a documentation correction to a disposition I measured as wrong, made in the file that owns the fact rather than left standing for the next reader to act on.