Skip to content

C-note correction: the build-cache verdict fold is an unconsumed authority, not dead code - #8623

Merged
briansrls merged 19 commits into
mainfrom
session/eager-crane-282
Aug 20, 2026
Merged

briansrls merged 19 commits into
mainfrom
session/eager-crane-282

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

The census document's C-note filed BuildCacheDaemonObservation / provision_build_cache_verdict / placement_verdict / build_cache_provision_gate_accepts as pre-existing dead production code, with a deletion plan and a rehoming note for one witness helper. I re-ran the census before acting on it.

The number reproduces. build_cache_provision_gate_accepts( — one definition, eight call sites, all in dag/test/claim/host_build_cache_provision_design_witness_test.dag. Zero production callers for any of the four symbols.

The characterization does not. Two measurements the original census did not make:

  1. The module's own lane_e_srv1_ci_noncompletion_root_cause_receipt names placement_verdict as the fix authority for the stranded-sccache-server incident that killed CI builds at the 15-minute compile ceiling, and records that class as INCIDENT CLEARED, NOT REPAIRED ... the class can strand again the next time a slot retires while holding the server.
  2. Nine production modules import gunbc.host_build_cache_provision for other declarations. The symbol-level zero sits inside a live, heavily-imported file — the shape that reads as dead from a whole-file glance and is not.

So this is a §4b rung finding rather than a §2 redundancy one: the fold is correct and unasked. The refusal named as the remedy is computed by a function no production caller calls. Green witnesses establish that the fold is correct, not that the class is guarded; reported as the latter, the class reads a rung above where it sits — the inflation §4b calls worse than sitting low, because an inflated class never ranks for climbing.

The deletion would have applied cleanly, taken the witnesses with it, broken nothing, and removed the named remedy for a recurrable CI-capacity incident, leaving a prose receipt pointing at a symbol that no longer exists. The witnesses' greenness was precisely the property that made removal look safe.

Disposition changed from delete to wire it up, and the one measurement that could still make the finding benign — that the provisioning path is genuinely ungated rather than gated by an equivalent check under another name — is named as the first thing to test. The superseded refuses() rehoming note is kept rather than dropped, in case a future measurement re-establishes the deletion case.

No code is touched. This is a documentation correction to a disposition I measured as wrong, made in the file that owns the fact rather than left standing for the next reader to act on.

Brian Searls and others added 16 commits August 19, 2026 07:44
…ot the universal effect model

gunbc#8467 establishes that an argv array is a serialization, exactly as bash
text is a serialization of a bash AST. Accepted. But stated without a boundary
it reads as replacing every typed effect with a CLI tree, which moves the
authority downward into one realization technology -- the section 3 violation
this lane exists to name, one layer below where it usually appears.

So the two lanes are one migration program with a named boundary. This lane
owns the semantic destination and site routing: the authority stays the typed
domain operation or typed HostEffect, and it decides whether a realization is
native, REST, filesystem, library, CLI-backed, or necessarily text-emitting.
#8467 owns the inside of the CLI-backed cell. A native handler reaches no CLI
surface at all.

The census also carried a stale unit. Sizing by argv occurrence, then by
executable head, then by tool each produced an inflated remainder, because a
tool vertical, its site cutovers and its host_effect_apply caller are commonly
ONE vertical whose acceptance condition is the old site's deletion. The
measured shape, production only:

  transport shell   236 lines / 48 files -- 230 lines / 45 files in extdeps
  argv:             457 lines -- 275 extdeps, 172 gunbc, 10 src/v2
  bridge calls      48 across 13 files
  fn *_argv         333, of which ~158 model no tool at all

transport shell is overwhelmingly an extdeps population, i.e. beneath
already-typed operations. This lane's original job -- getting shell out of the
intent -- is substantially done; the remainder is transport depth. Recorded
with the caution that a transport shell block is not a shell program at all:
the seed executes it as Command::new(&argv[0]).args(&argv[1..]).

Two finish lines are therefore named separately, SHELL-DAG and CLI-AUTHORITY,
so a row complete against the first but owing the second reads as the boundary
working rather than as incomplete work. A SHELL-DAG row is never blocked on
CLI-AUTHORITY.

One live instance found while verifying: extdeps.exec.command
command_over_transport builds append(ssh_exec_prefix, command.argv) -- the
exact SSH-as-prefix shape the boundary forbids -- in production, beneath the
generic runner, which is the mechanism by which remote argument boundaries are
lost. It shares a file with command_runner's argv -> quoted text -> heredoc
round trip, whose carrier already declared the repair in
command_runner_dissolution_trigger. The runner cut and the SSH target are one
vertical.

No code changes. DESIGN.md needs no edit and says so in the text: its shell ->
intent row already routes runtime-present sites to typed effects and confines
emission to foreign executors and bootstrap, so the boundary falsifies no
sentence in it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…weaken the sequencing claim

Review on #8535 found the first commit did the exact thing this document
warns about five times: it appended a corrected boundary beside stale
operational text without deleting the text it supersedes. The finding is
correct and the stale claim is load-bearing.

TransportScript has not been a transparent brand since #7962. It is a
sole_constructor record whose single mint transport_script_seal is
admit_callers-sealed to two production declarations, and the cast form closed
with it -- 04_infer sole_constructor_construction_diags judges a cast into a
sealed type. Both documents still asserted, in the present tense and in
fourteen places, that the brand is transparent, that `String as
TransportScript` is writable from any module, and that direct shell.Exec.Run
is guarded by validation rather than construction. All false at this head.

Enumerated by claim across both authorities rather than fixing the site under
review -- the document's own standing rule, added after the fifth time this
class recurred -- and rewrote every occurrence in place: section 3's terminal
paragraph, 4.F's heading and three table cells, the 4 dissolution trigger,
5's end-state paragraph, 5.E's heading, premise and ruling block, the
wind-down ledger row, the meta-exec row, and both sites in the invariant doc.
The leak fixture is reclassified as scan input and historical record; it can
no longer be cited as evidence the cast compiles.

What actually survives is smaller and different in kind: the two admitted
bridges take a bare body String, so arbitrary text still reaches a transport
through a counted, reason-bearing, dissolves_to-carrying call. Conspicuous,
not impossible, and it dissolves by per-site migration rather than by further
wall work.

Also from the review, each verified before acting:

- The bridge count named no files. Enumerated all 13. Three -- package_delivery,
  codex_app_server_press, bmc_netboot_serve -- are absent from the section 4
  punch-list that still calls itself complete at 78f43c3. Recorded as that
  snapshot's correction, not as a second census.

- A classification question the count concealed: package_delivery (7 calls) and
  codex_app_server_press (3) route through retained_foreign, whose dissolves_to
  is the Bash emitter, while both appear to run inside a present gunbc runtime.
  If so, ten calls declare the wrong destination. Flagged for their owners; the
  executor window decides it and this document does not own that fact.

- "A SHELL-DAG row is never blocked on CLI-AUTHORITY" was true of the homing
  decision and false as a sequencing rule, with the counter-example named in
  the same document: command_runner's cutover needs the structured process-argv
  carrier, and its SSH arm the nested shell-command target. Reworded.

- Added an explicit statement that this is a boundary and scoping increment,
  not a closeout receipt -- neither finish line is met at this commit.

Merged main to pick up #8467, now landed, so the cross-PR references describe a
merged authority rather than an open branch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The boundary section asserted DESIGN.md needed no edit BECAUSE its shell ->
intent open-thread row already routed runtime-present sites to typed effects.
That row is gone: #8476 cut DESIGN to ~9.5k words and removed open-threads
wholesale, and this branch merged main two commits ago.

The conclusion survives, the reason does not. What the boundary instantiates
now is section 3 general paragraph -- interface, realization and policy are
three facts, transport is a Realization handler one of N, dispatch sits
peripheral -- so a CLI-backed handler is that shape at the tool seam and
DESIGN still needs no edit.

Caught while verifying the previous commit against the rewritten DESIGN rather
than the one the clause was written against, which is the same check the
previous commit performed on fourteen other claims.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…te the dead import it names

The census flagged three modules as possibly-misfiled -- package_delivery,
codex_app_server_press and provider_wire_evidence route through retained_foreign,
whose dissolves_to is the Bash emitter (foreign executors and pre-runtime
bootstrap), while appearing to run inside a present gunbc runtime. It recorded
that as "a question for their owners -- the executor window is the deciding fact
and this document does not own it."

The question was decidable without them. package_delivery calls
shell.Mkdir.Parents and shell.Find.FilesAndSymlinksWithMode -- typed operations
that cannot execute without a present runtime -- in the same function bodies that
then fall back to retained_foreign. A function that interleaves a typed operation
with a retained foreign script is runtime-present by the fact that its first half
ran. So the six remaining calls declare the wrong dissolution target.

Three corrections fall out, all measured on 98d7147:

- provider_wire_evidence has ZERO retained_foreign call sites. Its effects became
  typed extdeps.shell operations under review 50540; what survived was an unused
  import, deleted here. It is struck from the bucket, which is 12 rather than 13,
  struck through rather than dropped -- a census row that vanishes without
  explanation cannot be told from one that was never measured.

- The call counts are stale in the direction the census warns about elsewhere:
  5 and 1, not 7 and 3.

- package_materialized_tree_observation_note records replacing a find-piped-to-sort
  string with shell.Find plus in-substrate std sort, because the string form escaped
  its quoting on a root containing an apostrophe and forked an authority
  extdeps.shell already owned. That migration landed at ONE site; another instance
  remains in the same module with the same shape and the same exposure. A carrier
  that records a fix should name the population it fixed, or the next reader takes
  the note as coverage.

Local whole-corpus compile was started and killed at 15 minutes without
terminating, so it is INCONCLUSIVE rather than clean -- stated rather than omitted.
The deleted import is verified unreferenced by grep; CI's floor is the census.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Conflict was in docs/plans/shell-to-dag-residual-census-and-arc-completion.md only
-- a hand-authored markdown file, not a generated projection (checked line 1 before
resolving). Both conflicting regions were this branch's new text against the
PRE-EDIT ORIGINAL, not against anyone else's change: main's edits to this file
(#8595's LANDED row) are elsewhere and auto-merged cleanly. Verified by diffing the
resolved file against origin/main and reading every removed line -- all ten are
exactly the text this branch deliberately replaced.

Merge commit rather than rebase, per repo policy: no force-push, so no dropped
dashboard approvals. The nag asked for a rebase; the policy asks for a merge, and
the merge reaches an identical end state without moving the head under review.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The C-note filed BuildCacheDaemonObservation / provision_build_cache_verdict /
placement_verdict / build_cache_provision_gate_accepts as pre-existing dead
production code with a deletion plan. I re-ran the census before acting on it.

The zero-caller number reproduces exactly: 8 call sites for the gate, all in
one witness file; zero production callers for any of the four symbols.

The characterization does not. Reading the module's own receipt rather than the
grep output, lane_e_srv1_ci_noncompletion_root_cause_receipt names
placement_verdict as the FIX AUTHORITY for the stranded-sccache-server incident
that killed CI builds at the 15m compile ceiling, and records that class as
"INCIDENT CLEARED, NOT REPAIRED". Nine production modules import the module for
other declarations, so the symbol-level zero sits inside a live file.

That makes this a §4b rung finding, not a §2 redundancy one: the fold is
correct and unasked. Green witnesses establish correctness, not that the class
is guarded, and reporting them as the latter reads a rung above where the class
sits. The deletion would have applied cleanly, taken the witnesses with it,
broken nothing, and removed the named remedy for a recurrable CI-capacity
incident -- with the witnesses' greenness as the property that made it look safe.

Disposition changed from delete to wire-it-up, with the one measurement that
could still make it benign named as the first thing to test. No code touched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…cement

The correction said nobody should wire anything before establishing whether
the provisioning path is ungated or gated by an equivalent check under another
name. Measured on origin/main by reading the three modules involved.

There is a check under a different name and it is not equivalent.
realize_provision_build_cache gates on provision_build_cache_catalog_gate_verdict,
which is pure catalog-id validation in a third module -- unknown id refuses, a
non-sccache_local id refuses, otherwise realizable. It never observes placement,
principal, unit ownership or lifecycle, so passing it says nothing about the
stranded-daemon class the incident receipt names placement_verdict as the fix for.
host_effect_realize matches none of the admission symbols.

Two unconsumed authorities, not one: build_cache_ensure's
admit_ensure_build_cache_instance is in the same state. Both name the same
single next consumer, realize_provision_build_cache_body, so this is one wiring
job rather than two -- materially smaller than the correction implied.

The tree recorded this itself in ensure_effect_grain_migration_note. Verified
against the code rather than quoted, since tonight's repeated failure was a
correct measurement of a subject that had moved. It has not moved.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… kernel

The guarantee-recovery doc's calibration example read "a nonliteral refined
argument is RuntimeBoundaryOnly" -- a check that fires at the runtime boundary
rather than at compile time. Measured across all three kernels the refinement
family uses, that is true of none of them.

  String      the conversion runs and is the identity.
              Executed: "" as NonEmptyStr returns "".
  Int         the only conversion refuses every value, so it is never used;
              values arrive by declaration and no conversion runs.
              Executed: the cast refuses a valid 5 identically to -1, and -1
              reaching an EpochMs-declared parameter comes back unchanged.
  collection  a sound unforgeable wall -- private tuple field, new the only
              door -- with zero call sites corpus-wide, and zero refinement
              declarations over any collection base behind it.

A gate that passes everything, a gate nobody walks through, and a wall with no
door behind it. The Int row most needs stating: "fail-closed by absence of
capability" reads as safe and is not, since 74 declared positions against
effectively zero casts means the refusing conversion is almost never on the path.

This is the document's own section 4b failure rather than a wording slip: one
state was recorded for a class whose paths differ, and it was the strongest of
them. Each kernel needs a different remedy, so the row cannot be weakened -- it
has to be split.

Population recorded as a dated measurement with its limits: 3939 across 612
files at a750b67, four pre-committed predicates passing including a by-name
planted control, reproduced exactly on separate runners, corroborated by an
independent static scan smaller in the predicted direction. The instrument was
deleted, so the number is not reproducible without rebuilding it, and it is an
unverified-obligation population -- the census cannot distinguish violated from
unverified.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rv3 deferral measurement

Two corrections to the residual census, both measured at origin/main 4cec10f.

srv3_join_shell_words has zero definitions and zero mentions on main; it was
cited in two places (the §1.C row and the §4.D deferred table) as a live srv3
transport helper. Removed from both. The five sibling symbols cited beside it
all still resolve in gunbc.host_effect_realize and are left untouched.

The srv3 deferral's premise is refuted by typed refusal: all 22
EmitArtifactThenThinRun arms in gunbc.host_effect_realize refuse, none accept,
and the refusal names "reserved for ConvergePlan (host-effect Phase D)." The
control widens it past that file -- the variant is realized nowhere in the tree;
the three sites that appear to accept it are classifiers returning a Bool or the
variant name for totality. So nothing is pending cutover and no srv3 site waits
on a Phase D that exists.

That settles the premise, not the disposition. Whether the srv* actuator graph
survives at all is an operator decision, and migrating 22 call sites in a
subgraph slated for deletion by another route is wasted work under a different
premise than the original. Recorded as due for re-decision rather than expired.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tly one realizer

The paragraph committed earlier today claimed EmitArtifactThenThinRun is
realized nowhere in the tree and is therefore declared-but-unrealized. That is
false, by exactly one path, in the file the claim examined most closely.

realize_converge_on_host splits its EmitArtifactThenThinRun arm on
gunbc_apply_mode_for_host: FreshStandup refuses as fail-closed Unimplemented,
but ExistingHostQuiescentReload calls realize_converge_in_process -- the
identical call the LocalShell arm makes. For an existing quiescent host the
transport takes the same path as the shell transport. The sibling SshShell and
FleetSsh refusals direct the caller to "use EmitArtifactThenThinRun", which
points the same way.

Two disguises produced the wrong count and each survives a scan written for the
other: a refusal shaped as a success-valued record (hostname_set answers
HostnameSetCasApplyFailed with the refusal in a stderr field, invisible to a
NotConverged scan), and a realizer behind a refusing first sub-arm (the arm
above, whose opening lines read as a refusal). Reading all 24 bodies was the
only method that survived; the corrected text records both disguises so the
next reader does not re-derive them.

The srv3 conclusion is unchanged. The realizing path is for HostConverge, not
for any srv3 effect -- every Srv3* arm still refuses. Only the supporting
sentence changes: not "realized nowhere so nothing is pending" but "exactly one
realizer, and srv3 is not on it."

Corrected in place rather than annotated beside, per the standing rule against
two accounts of one fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

The witnesses red on this PR is not caused by this PR, and I am not pushing a fix for it because the fix is a regen, which is under the fleet stop-the-line.

What fails: required-regen: FAIL generated surface drift: v1_compiler_emit_rust.rs (first_generation_equal=false, planned=129 executed=129).

Why it is not this PR: the entire diff is two .md files, 79 insertions, zero .dag and zero .rs.

Where it comes from — bisected, not inferred. witnesses on main is failing with the byte-identical error. The last green main run is 5fbbbeb70 (07:09Z); the first red is 5a71831dc (07:13Z). Exactly one commit sits between them:

That commit changes src/v1/05_emit_rust.dag and its own message records dropping the spliced mirror, having verified end-to-end through a temporary, uncommitted mirror splice. So the authority moved and the committed src/v1/stage0/src/v1_compiler_emit_rust.rs mirror did not — which is precisely the drift the regen fixed-point gate exists to refuse. The gate is doing its job; it was re-enrolled in witnesses.yml earlier today, so this is the first authority-vs-mirror divergence to meet it armed.

Why I stopped rather than fixed it: closing this requires regenerating the stage0 mirror. Fleet policy is no regen, no mirror repair, no hand-carrying generated projections — escalate instead. Escalated.

Every other merge requirement on this PR is green: 4 approvals, no REQUEST_CHANGES, no active reviews on this head, mergeable=MERGEABLE. checks is the only failing row, and it will stay red here until main is green again — this PR cannot turn it green from the inside.

— sent from eager-crane-282

Brian Searls and others added 3 commits August 20, 2026 09:49
The paragraph recording how the one-realizer finding was measured stated that
all 24 arm bodies had been read. That number came from the manual audits and is
wrong.

Measured at 4cec10f: 41 EmitArtifactThenThinRun
occurrences -- 1 variant declaration in gunbc.host_effect, 36 production match
arms across 14 modules, 4 in dag/test/claim. Neither manual audit reached 36 and
neither mentioned gunbc.host_effect_codex_supervised_turn, whose arm answers
CodexSupervisedSessionApplyRefused: a refusal named by its record rather than by
a refusal type, which is the same disguise class the paragraph documents.

The finding is unchanged -- exactly one arm realizes, realize_converge_on_host
under ExistingHostQuiescentReload. What was wrong was the stated size of what had
been examined, inside the paragraph about examining carefully.

Recorded as a dated measurement at a named SHA for a derived detector to
reproduce and reconcile against, explicitly not as a fixed law, since migrations
are expected to change it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tend

Answering the census brief's stop condition -- whether existing parsed-body
facts can carry the derived census -- surfaced a lens already answering
approximately this question, which a later reader could mistake for coverage.

v2.lens.effect_reach classifies host-effect sinks and carries a ShellExecRunSink
variant. But sink_kind_for_callee selects by name equality against a remembered
callee-text list ("Run", "shell.Exec.Run", "Exec.Run", "WitnessBin.Run",
"Read"), everything else falling to UnknownHostEffectSink. That is the forbidden
seed form -- where we remember doing it rather than what interprets bytes as
shell -- and it cannot see sh -c, sh -s on stdin, or a sudo -S sh -s wrapper. It
carries the same blind spot this census carried before Spark was found.

Two bounds on its weight: it classifies from callee text rather than resolved
callee identity, the text-scanning substitution the brief's stop condition
forbids; and enforcement_live_witness_test asserts its contract is unbound, the
corpus's own record that it has no enrolled consumer.

Disposition is supersede rather than extend: a census seeded from interpretation
semantics subsumes its whole sink vocabulary, while extending it would inherit
its selection principle. Recorded so the derived cut treats it as prior art with
a known-narrow frontier, and so its ShellExecRunSink rows are never read as an
existing shell-reach population.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 8ab76ae into main Aug 20, 2026
1 check passed
@briansrls
briansrls deleted the session/eager-crane-282 branch August 20, 2026 16:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant