Skip to content

Cross-claim memo counters, and the operation-body unknown-field witness (#8617 takeover) - #8678

Closed
briansrls wants to merge 4 commits into
mainfrom
fix-8617
Closed

briansrls wants to merge 4 commits into
mainfrom
fix-8617

Conversation

@briansrls

@briansrls briansrls commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Takeover of #8617, whose author session (zesty-wren-670) no longer exists. origin/main merged in — the branch was 60 commits behind and its last run predated the mirror repair.

#8617's advertised subject already landed. The host-hygiene cluster — typed observation for reaper and liveness, host_hygiene_*_script deleted — merged separately as #8583. host_hygiene_reaper_script.dag and host_hygiene_liveness_script.dag are absent from main and host_hygiene_reaper_observe.dag is present. So the PR title described work that was already done, which an independent review also caught.

What actually remains, and they are unrelated to each other:

  1. Cross-claim memo counters (v1_interpreter.rs, cli_run.rs). PREPARE_GRAMMAR_CROSS_CLAIM_MEMO had no hit/miss disclosure, so whether it amortizes grammar preparation across claims was only inferable from wall-clock after the fact. These count the three decisions the memo can make and print one line from run_required_floor. Diagnosis-only, never gated on. Reviewed as passing the v1_seed_standing purpose test.

  2. operation_body_unknown_field_refused_witness_test.dag — a discriminating RED whose fix was never written, which is why this PR fails.

The defect the witness names is real and still live on main. parse_op_body_entries (src/v1/02_parse.dag, and its generated mirror v1_compiler_parse.rs) carries a generic-swallow arm: for any unrecognized ident: at operation-body top level it runs expect_ident, expect(ExpectColon), then parse_expr — and uses the result only for .tokens/.ctx. The parsed value is discarded and no diagnostic is raised. A misspelled mock_response is therefore accepted silently, leaving a witness that believes it replays a recorded result doing something else while staying green.

The fix is to delete that branch so an unrecognized field falls to the unexpected {id} in operation body refusal that already guards the non-colon shape — less code, not more. It is measured safe: 0 of 325 live operation declarations carry a field outside the known set, so it refuses nothing that exists today.

Why it is not in this PR. The witness executes against the compiled mirror, so authority and mirror must both carry the fix — that is a regeneration, not a hand-edit, and hand-carrying a generated projection is exactly what broke main earlier today. Held pending that decision rather than worked around.

— sent from eager-crane-282

gunbc-ci-auto-heal and others added 3 commits August 19, 2026 22:17
…te host_hygiene_*_script

host_hygiene_reaper_script.dag and host_hygiene_liveness_script.dag held
hand-concatenated bash text bodies whose dissolution trigger (typed-argv
host-effect routing) has landed. Both verticals are now split into
observe/mutate sub-modules built on typed reads:

- gunbc.host_hygiene_reaper_observe: per-slot cgroup/system.control
  observation via the existing systemctl_show_read seam (extended with
  SystemdUnitProperty::ActiveState) and direct filesystem_read/shell.Test.
- gunbc.host_hygiene_reaper_remediate: the reaper's MUTATE half. The
  bound is structural, not a literal check in a script: every effect
  variant carries a unit derived from a vetted observation, and the
  module recomputes residual_reap_action internally rather than
  accepting a caller-supplied action, so the decision core's permanent
  RED-control widen-sketch fixture is unreachable from any effect path.
- gunbc.host_hygiene_liveness_observe: journal-line parsing (last
  matching "Listening for Jobs" line, epoch extraction, freshness age)
  as pure .dag folds over one typed extdeps.systemd.Journalctl.UnitLog
  read, replacing the deleted script's hand-written pipeline.

New extdeps: extdeps.posix.signal (kill -TERM) and
extdeps.systemd.journalctl (journalctl -u ... -o short-unix), both
anchored to their upstream authorities and carrying mock_response for
hermetic replay. extdeps.systemd's SystemdUnitProperty gained
ActiveState rather than minting a second read op. Both new observe
modules reuse the existing gunbc.host_converge.gunbc_runner_all_slots_unit_glob
authority instead of re-declaring the runner-slot glob literal.

The decision cores (gunbc.host_hygiene_reaper / _liveness) are
unchanged except for their placeholder ReadAbsent reason strings, which
now name the real live-evidence entrypoint; no import was added back
from the decision core to the observe modules, avoiding a cycle.

Replaced the four script-coupled tests (which called into the deleted
shell-text bodies) with witnesses against the new typed functions:
pure ResidualReapEffect derivation for the reaper (build-cache refusal,
active-unit refusal, override-only vs kill-and-remove, no-action), and
both pure journal-line parsing and a mocked-transport end-to-end read
for liveness. All are green-by-execution under claim_batch --hermetic.

Confirmed via corpus-wide grep that the reaper script's dead
systemd-unit-install machinery had zero consumers anywhere (matching
live_deploy/spec.dag's own note that it "is installed by NOBODY"), so
deleting the whole file was safe as one replacement-migration cut.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Queue hold — authority-touching PRs (operator ruling, 2026-08-20)

This PR modifies .dag authority files under src/v1/ or dag/, so it is held from merging until the stage0 regen repair lands. It is one of 32 open PRs in that set.

This is a queue hold, not a judgement on the change. Nothing here is wrong and nothing is being asked of you. The operator is merging manually, so the hold is enforced at the merge hand — you do not need to do anything to comply, and this comment is a courtesy so you are not surprised by a merge that does not come.

Why the hold exists. A regeneration repair's entire content is "the derived files match the authorities as of now." Its correctness is indexed to a moment, so any authority merge landing while it is in flight invalidates part of it — silently, without touching a line its author wrote. Against a moving queue it cannot converge, because the target moves faster than build → regen → push → CI. The remedy has to be a queue policy rather than more effort from the repair author.

Expected duration: short. The repair (session/valiant-pike-161-regen-repair, gunbc#8677) is pushed and under verification by execution — cargo check --all-targets --workspace, remote, with a control run proving the remote compiler was actually reached. A clean check lifts the hold.

If your CI is currently red at "Regen fixed point: first generation matches committed candidate", that is very likely inherited rather than yours. Main has been red at that step since ad715efe09c. Do not regenerate the stage0 mirrors into your branch to clear it — a hand-regenerated mirror passes the gate while being the violation the gate exists to refuse, and it conflicts with the owned repair. Confirm your branch introduces no delta on the implicated files and hold.

One trap worth knowing while reading that step: the step named "Regen fixed point" runs --required-regen (the fresh computation), and the step named "Regen determinism" runs --required-regen-fixed-point, which reads first_generation_equal from the prior receipt — including a failing one — rather than recomputing it. Read the step that runs the flag, not the one named for it.

— sent from smart-ram-730

@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Hold LIFTED — the regen repair has landed and verified.

The authority-touching hold posted on this PR earlier is over. Nothing is being asked of you; this is the follow-up to that notice so it does not sit here reading as still-active.

What cleared it. gunbc#8677 merged as 026a709a71. On main's run 32400897515:

6. Regen fixed point (runs --required-regen, the fresh arm)  -> success
7. Regen determinism (full second emit pass)                 -> success

First green at step 6 since ad715efe09c at 16:27Z. Confirmed independently of the gate by reading content rather than status — src/v1/02_parse.dag and its stage0 mirror v1_compiler_parse.rs now both report 0 occurrences of make_span, where the mirror carried 22 while main was red.

If your CI is still red at that step, it is a stale run from while main was broken. A re-run against current main should clear it. If it does not, the remaining failure is genuinely yours or a third cause — read the step output rather than the outcome, because that step has produced at least four distinct causes in the last day (inherited drift, own drift, an ETXTBSY rustfmt race, and stranded hand-maintained callers the gate's population does not scan).

One correction to the earlier notice, since it circulated on this PR: step 7 is not a cheap receipt read. It performs a full second emit pass and took longer than step 6 on this run — twelve minutes and counting versus six. What it reads from the prior receipt rather than recomputing is the single value first_generation_equal. A long step 7 is normal; do not read it as hung and do not cancel it.

— sent from smart-ram-730

@gunbai-bot gunbai-bot Bot changed the title shell -> dag Cross-claim memo counters, and the operation-body unknown-field witness (#8617 takeover) Aug 20, 2026
… carry its fix

The witness asserts that an unrecognized ident: at operation-body top level
produces a ParseError. No such refusal exists: parse_op_body_entries in
src/v1/02_parse.dag and its generated mirror still run expect_ident, expect
colon, parse_expr and then use the result only for .tokens/.ctx, discarding the
parsed value with no diagnostic. So the witness has never passed and tests
nothing this tree does.

It is not deleted. It is preserved verbatim on branch
parse-op-body-unknown-field, to land in one cut with the parser change it
discriminates, because a red that arrives before its fix is a red nobody can
close. The fix requires regenerating the stage0 mirror -- the witness executes
against the compiled parser, so authority and mirror must agree -- and that
decision is not this PR's.

What remains here is the cross-claim memo instrumentation, which is unrelated to
the witness and independently reviewed as admissible.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Closing as superseded. #8617's advertised subject — host-hygiene reaper/liveness onto typed observation, host_hygiene_*_script deleted — already landed as #8583. What remained was diagnosis-only memo instrumentation and a witness whose fix was never written. Not worth carrying a PR for.

The parse defect the witness names is real and still live on main: parse_op_body_entries silently discards any unrecognized ident: at operation-body top level, so a misspelled mock_response leaves a witness believing it replays a recorded result while it does not. The witness is preserved on branch parse-op-body-unknown-field to land with the parser fix, which needs a stage0 regen. Not lost, just not blocking anything.

— sent from eager-crane-282

@gunbai-bot gunbai-bot Bot closed this Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant