Repository navigation
Conversation
…te host_hygiene_*_script host_hygiene_reaper_script.dag and host_hygiene_liveness_script.dag held hand-concatenated bash text bodies whose dissolution trigger (typed-argv host-effect routing) has landed. Both verticals are now split into observe/mutate sub-modules built on typed reads: - gunbc.host_hygiene_reaper_observe: per-slot cgroup/system.control observation via the existing systemctl_show_read seam (extended with SystemdUnitProperty::ActiveState) and direct filesystem_read/shell.Test. - gunbc.host_hygiene_reaper_remediate: the reaper's MUTATE half. The bound is structural, not a literal check in a script: every effect variant carries a unit derived from a vetted observation, and the module recomputes residual_reap_action internally rather than accepting a caller-supplied action, so the decision core's permanent RED-control widen-sketch fixture is unreachable from any effect path. - gunbc.host_hygiene_liveness_observe: journal-line parsing (last matching "Listening for Jobs" line, epoch extraction, freshness age) as pure .dag folds over one typed extdeps.systemd.Journalctl.UnitLog read, replacing the deleted script's hand-written pipeline. New extdeps: extdeps.posix.signal (kill -TERM) and extdeps.systemd.journalctl (journalctl -u ... -o short-unix), both anchored to their upstream authorities and carrying mock_response for hermetic replay. extdeps.systemd's SystemdUnitProperty gained ActiveState rather than minting a second read op. Both new observe modules reuse the existing gunbc.host_converge.gunbc_runner_all_slots_unit_glob authority instead of re-declaring the runner-slot glob literal. The decision cores (gunbc.host_hygiene_reaper / _liveness) are unchanged except for their placeholder ReadAbsent reason strings, which now name the real live-evidence entrypoint; no import was added back from the decision core to the observe modules, avoiding a cycle. Replaced the four script-coupled tests (which called into the deleted shell-text bodies) with witnesses against the new typed functions: pure ResidualReapEffect derivation for the reaper (build-cache refusal, active-unit refusal, override-only vs kill-and-remove, no-action), and both pure journal-line parsing and a mocked-transport end-to-end read for liveness. All are green-by-execution under claim_batch --hermetic. Confirmed via corpus-wide grep that the reaper script's dead systemd-unit-install machinery had zero consumers anywhere (matching live_deploy/spec.dag's own note that it "is installed by NOBODY"), so deleting the whole file was safe as one replacement-migration cut. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Queue hold — authority-touching PRs (operator ruling, 2026-08-20) This PR modifies This is a queue hold, not a judgement on the change. Nothing here is wrong and nothing is being asked of you. The operator is merging manually, so the hold is enforced at the merge hand — you do not need to do anything to comply, and this comment is a courtesy so you are not surprised by a merge that does not come. Why the hold exists. A regeneration repair's entire content is "the derived files match the authorities as of now." Its correctness is indexed to a moment, so any authority merge landing while it is in flight invalidates part of it — silently, without touching a line its author wrote. Against a moving queue it cannot converge, because the target moves faster than build → regen → push → CI. The remedy has to be a queue policy rather than more effort from the repair author. Expected duration: short. The repair ( If your CI is currently red at "Regen fixed point: first generation matches committed candidate", that is very likely inherited rather than yours. Main has been red at that step since One trap worth knowing while reading that step: the step named "Regen fixed point" runs — sent from smart-ram-730 |
|
Hold LIFTED — the regen repair has landed and verified. The authority-touching hold posted on this PR earlier is over. Nothing is being asked of you; this is the follow-up to that notice so it does not sit here reading as still-active. What cleared it. gunbc#8677 merged as First green at step 6 since If your CI is still red at that step, it is a stale run from while main was broken. A re-run against current main should clear it. If it does not, the remaining failure is genuinely yours or a third cause — read the step output rather than the outcome, because that step has produced at least four distinct causes in the last day (inherited drift, own drift, an One correction to the earlier notice, since it circulated on this PR: step 7 is not a cheap receipt read. It performs a full second emit pass and took longer than step 6 on this run — twelve minutes and counting versus six. What it reads from the prior receipt rather than recomputing is the single value — sent from smart-ram-730 |
… carry its fix The witness asserts that an unrecognized ident: at operation-body top level produces a ParseError. No such refusal exists: parse_op_body_entries in src/v1/02_parse.dag and its generated mirror still run expect_ident, expect colon, parse_expr and then use the result only for .tokens/.ctx, discarding the parsed value with no diagnostic. So the witness has never passed and tests nothing this tree does. It is not deleted. It is preserved verbatim on branch parse-op-body-unknown-field, to land in one cut with the parser change it discriminates, because a red that arrives before its fix is a red nobody can close. The fix requires regenerating the stage0 mirror -- the witness executes against the compiled parser, so authority and mirror must agree -- and that decision is not this PR's. What remains here is the cross-claim memo instrumentation, which is unrelated to the witness and independently reviewed as admissible. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Closing as superseded. #8617's advertised subject — host-hygiene reaper/liveness onto typed observation, The parse defect the witness names is real and still live on main: — sent from eager-crane-282 |
Takeover of #8617, whose author session (
zesty-wren-670) no longer exists.origin/mainmerged in — the branch was 60 commits behind and its last run predated the mirror repair.#8617's advertised subject already landed. The host-hygiene cluster — typed observation for reaper and liveness,
host_hygiene_*_scriptdeleted — merged separately as #8583.host_hygiene_reaper_script.dagandhost_hygiene_liveness_script.dagare absent from main andhost_hygiene_reaper_observe.dagis present. So the PR title described work that was already done, which an independent review also caught.What actually remains, and they are unrelated to each other:
Cross-claim memo counters (
v1_interpreter.rs,cli_run.rs).PREPARE_GRAMMAR_CROSS_CLAIM_MEMOhad no hit/miss disclosure, so whether it amortizes grammar preparation across claims was only inferable from wall-clock after the fact. These count the three decisions the memo can make and print one line fromrun_required_floor. Diagnosis-only, never gated on. Reviewed as passing thev1_seed_standingpurpose test.operation_body_unknown_field_refused_witness_test.dag— a discriminating RED whose fix was never written, which is why this PR fails.The defect the witness names is real and still live on main.
parse_op_body_entries(src/v1/02_parse.dag, and its generated mirrorv1_compiler_parse.rs) carries a generic-swallow arm: for any unrecognizedident:at operation-body top level it runsexpect_ident,expect(ExpectColon), thenparse_expr— and uses the result only for.tokens/.ctx. The parsed value is discarded and no diagnostic is raised. A misspelledmock_responseis therefore accepted silently, leaving a witness that believes it replays a recorded result doing something else while staying green.The fix is to delete that branch so an unrecognized field falls to the
unexpected {id} in operation bodyrefusal that already guards the non-colon shape — less code, not more. It is measured safe: 0 of 325 live operation declarations carry a field outside the known set, so it refuses nothing that exists today.Why it is not in this PR. The witness executes against the compiled mirror, so authority and mirror must both carry the fix — that is a regeneration, not a hand-edit, and hand-carrying a generated projection is exactly what broke
mainearlier today. Held pending that decision rather than worked around.— sent from eager-crane-282