Repository navigation
shell -> dag - #8703
shell -> dag#8703briansrls wants to merge 1 commit into
Conversation
…ider cannot be emitted deploy.yml ran `cargo build --release -p v1-compiler --bin gunbc` as step two with no toolchain provider anywhere in the file -- the only `uses:` in all 42 lines was the checkout -- and died on `cargo: command not found` 30 out of 30 runs without ever reaching its terminal step. Nothing in this repository could refuse it, because by the time a job is List<Step> a step that NEEDS a toolchain and one that PROVIDES it are indistinguishable. Receipt for that claim: git show a4677f3:.github/workflows/deploy.yml (deleted in 5814d0d). Counted with positive controls on the same scan of the same input -- cargo=1, uses:=1, name:=6 all nonzero, so setup-rust-toolchain=0 is a real zero rather than a broken pattern. WHAT THIS ADDS. gunbc.workflow_capability_closure models a step's relationship to the capabilities its job needs -- Provides / Consumes / Neutral over the EXISTING ExecutionCapability vocabulary (CargoCapability et al), not a second one -- and folds the steps IN ORDER, so a capability counts as available only once a preceding step has provided it. It sits ABOVE extdeps.github.actions and does not touch it. RunStep { run: String } is a faithful model of the GitHub wire format; the defect is product modules constructing that wire representation directly for operations whose semantics are known. Editing Step would re-coin the upstream spec (§3). STRUCTURAL, NOT TEXTUAL, and the reason is measured: the same consumption is spelled `cargo build` in one workflow and `"$CARGO_BIN" build` in another. My own regex over the second form returned a confident ZERO on a file that invokes cargo twice, because a closing quote sits between the name and the space. THE BINDING, which is what makes this a change rather than a demonstration. witness_floor_bound_steps is ONE list carrying both the Step and its role; witness_floor_steps and witness_floor_step_annotations are both projections of it, so they cannot drift. A hand-maintained roles list beside the steps list would be the §3 fork this closure exists to close, reintroduced as its own fix. expected_witness_floor_yml now REFUSES: a job whose consumer has no preceding provider yields a refusal marker instead of yaml. A check only tests call is specification-without-execution -- green forever while the emitter produces the broken workflow beside it. EVIDENCE, every witness falsified by a different plausible wrong implementation: witness base M1 M2 M3c vacuous blanket order-insensitive no-provider job refuses true false true true provider-first job admitted true true false true provider-after-consumer refuses true false true false M3c is the one that proves ordering is the content of the claim: a check asking only "does this job contain a toolchain anywhere" passes a job broken exactly the way deploy.yml was. Binding proven in both directions (M4, toolchain retagged neutral): mutated: refusal_marker=1 yaml_name_line=0 <- refusal REPLACES, not decorates restored: refusal_marker=0 yaml_name_line=1 Emission is byte-identical to the committed .github/workflows/witnesses.yml (1428 bytes both sides), so the step-construction refactor is behaviour-preserving and no regeneration is required. RUNG, HONESTLY. Mechanically preventable for the one job that is bound. Every other workflow can still be assembled as bare Steps and bypass closure entirely -- fleet-converge.yml is not bound by this cut. Next-rung trigger: binding the remaining emitters, at which point an unannotated job becomes the unwritable state rather than merely the unchecked one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Closing this rather than rebasing it, because rebasing would be repairing a branch whose content has already landed by another route.
The work this PR existed to deliver — binding the CI prelude steps to a declared capability role instead of an unchecked inline literal list — is delivered by #8734 ( Nothing is dropped by closing this. If review later wants the two rows that appear only here ( |
Auto-opened by session-dashboard for session
eager-crane-282.Pushing to
prelude-capability-bindingadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan