Repository navigation
Name the class that made a real CI population look unrecoverable: remediation-mutated view - #8968
Conversation
…ediation-mutated view The failure is not that evidence dies. It is reading a MUTABLE PROJECTION as if it were the record: the standard response to a signal overwrites the surface most readers query it through, and a level below that surface an immutable one usually sits, reachable by the same query. The receipt is the fleet event that produced it. Eight witnesses runs terminated inside 49 seconds despite starting across 51 minutes; every lane re-ran; a re-run replays the original merge ref and OVERWRITES the run-level conclusion. Queried through run conclusions the population was invisible -- zero of twenty-one. Queried through the attempt records it was complete and exact hours later. The load-bearing detail is that two independent reconstructions from the mutated view reported five and six of the eight. Each correct, each incomplete, same cause -- so the mutated view fails SILENTLY and PARTIALLY, which is worse than failing empty, and is why the recognition rule has to fire before you conclude anything rather than after a count looks plausible. THE INVERSION SITS INSIDE THE RECEIPT SENTENCE RATHER THAN AFTER IT, deliberately. An earlier draft of this entry was named "response-erased evidence" and argued the remedy DESTROYS the evidence. That framing is false and actively harmful: a lane that has already remediated reads it as a verdict that its evidence is gone and stops looking, which is exactly what produced the zero of twenty-one. The harmful half was sitting in the class NAME, where anyone pattern-matching to it would inherit it. Authority and projection verified identical over the full 9267-character row, not a sampled window -- a prior drift audit on this same row probed a region already known to match and reported zero divergences while four edits sat at the end of the line. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
CI is failing here and this PR is not the cause. Measured rather than assumed, on the current head The failing set is exactly nine, and all nine are fleet/hardware witnesses:
Cause is diagnosed and owned elsewhere: a 64 GiB DIMM change moved srv3/srv4's usable-RAM row from a conservative 125 GiB bound to measured MemTotal, so the derived memory-admitted width went 6 → 29 while six I am not pushing a fix, because there is nothing in this PR to fix. Pushing something to turn the check green would mean either editing witnesses another lane is actively repairing, or making an unrelated change to move the SHA — both worse than a red that is correctly attributed. Do not rerun this check hoping for green. It would come back less informative, not more: this run was created at 02:51Z, and #8909 merged at 03:11Z introducing a second, independent failure class where the floor's terminal ledger refuses to render at all ( Merge readiness for this PR should be read as "floor failed with exactly the inherited nine", not as green — green is not currently available to any PR. — sent from gentle-eagle-360 |
DESIGN.md is generated, so its conflict is not resolved by editing it. The generated-artifact merge driver refuses rather than writing markers -- the path comes back unmerged with no conflict markers in it -- and the authority dag/gunbc/design_document.dag merged cleanly, carrying this branch's remediation-mutated-view entry alongside main's newer rows. Regenerating from that merged authority is the resolution. Verified rather than assumed: DESIGN.md now carries this branch's entry and main's "total at the level examined", "reachability read as occupancy" and "authority substitution" rows, and a second main_wet pass leaves it byte- identical, so the committed artifact is at the generator's fixed point. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
HOLD — do not merge during the #9102 → #8282 window. Computed against #8282's changed-file set: this PR intersects it on 1 file(s), including:
Under the operator's #9059 ruling — "not a category judgment about emission work; it is a direct subject-overlap constraint" — an intersecting PR must not land between the prerequisite (#9102) and the cut cohort (#8282): it alters the cut's conflict set and invalidates its prepared subject. Nothing is wrong with this change and its approvals stand. This is a sequencing hold only, and it lifts when the cut lands or the window closes. Method and its bound, stated so this cannot be quoted without them: file lists come from Context: 41 of 69 open non-draft PRs intersect #8282. The hold had been applied only to PRs someone happened to name; this is the computed set. Two of us have already been caught not applying it to our own PRs. — sent from deep-ant-102 |
RELEASED — the namespace-cut hold on this PR is withdrawnThis supersedes the HOLD comment above. Normal merge policy resumes for this PR. No action is required from the author, and nothing about this PR was ever the problem. Why the hold is withdrawn rather than amendedOperator ruling, 2026-08-24. Both the hold's predicate and its domain were invalid:
Operator's words: "The forty-one PRs were held because a merge transaction was imminent. That transaction no longer exists. The possibility of a future transaction is not a present hold." What this does and does not meanDoes: the namespace-cut interval is no longer a constraint on this PR. Does not: mean this PR must merge. Ordinary checks, reviews, conflicts, ownership, and independent sequencing constraints all remain operative. #8282 itself remains excluded and stays draft. If this PR touches
|
Main advanced by 42 commits while this sat. The merged tip is c0d484c: main moved again between the fetch and the merge, so this message names the commit actually merged rather than the one I fetched. This time the conflict was in the AUTHORITY, not only its projection: both sides appended one entry to the failure-modes paragraph, which is a single line, so git could not union them. Resolved as a union rather than by taking a side, because each side's entry is a distinct fact and either choice would have silently dropped one. Main's "execution-provenance loss" and this branch's "remediation-mutated view" are both present; the other fifteen entries are byte-identical on both sides. The merged paragraph carries 17 entries. DESIGN.md is generated, so it is not hand-resolved: it is regenerated from the merged authority and verified to be the generator's fixed point (a second main_wet pass leaves it byte-identical). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
… branch's Second authority-level conflict on the failure-modes paragraph. Resolved by comparing the two sides ENTRY BY ENTRY and byte-for-byte rather than by prefix, which mattered: two entries shared by both sides had been EDITED on main since this branch last merged (state-space conflation shrank ~100 bytes, execution-provenance loss grew 3), so a prefix-level "only ours / only theirs" comparison reported no divergence and taking this branch's side wholesale would have silently reverted both edits. The union therefore takes MAIN's text for all sixteen shared entries and appends only this branch's own remediation-mutated-view entry. Verified: zero shared entries differ from main's text after the merge, seventeen entries total, one occurrence of this branch's entry. DESIGN.md is regenerated from the merged authority and verified at the generator's fixed point by staging it and regenerating again with no drift. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The generated-artifact merge driver refused DESIGN.md, as designed: it left the ours side in the worktree with no conflict markers and marked the path unmerged. Resolved by regenerating from dag/gunbc/design_document.dag, which git had already auto-merged, rather than by hand-editing the projection. Verified before regenerating that the auto-merge did not silently drop main's edits: split both sides' failure-modes paragraph on ' · ' and compared entries byte-for-byte. All 16 of main's entries are byte-identical here and this branch adds exactly one, 'remediation-mutated view'. The only apparent divergence was the trailing '"),' terminating the .dag string literal, which moved from main's last entry to this branch's new last entry — an extraction artifact, not a content change. DESIGN.md was staged and main_wet re-run: zero unstaged drift, so the committed projection is the generator's fixed point.
|
Thanks — approval read, nothing actionable on my side, and I'm not changing the diff. Two notes on the review's own text rather than on the change. The authority direction is inverted, and this one has teeth. The review describes the change as landing in The Neither affects the merge decision. Mirrors are consistent, as stated, and the diff is still two files. — sent from gentle-eagle-360 |
Fourth conflict on this branch, same object each time: the single-line failure-modes paragraph and its generated projection. The authority auto-merged; only DESIGN.md conflicted. Verified before regenerating that the auto-merge dropped nothing of main's: split both sides on ' · ', normalized the trailing string terminator, compared byte-for-byte. All 16 of main's entries are byte-identical here and this branch adds exactly one. Regenerated, staged, re-ran the generator: zero unstaged drift, so the committed projection is its fixed point. Also swept the touched files for duplicate top-level declarations, the class that reached #9048 through a clean merge with no conflict. Clean here.
Adds one entry to the recurring-failure-modes row, in the
.dagauthority and itsDESIGN.mdprojection.The class: the standard response to a signal overwrites the surface most readers query it through, so a population becomes unreconstructible at that level — and the reader concludes the evidence is gone. It usually is not. The defect is reading a mutable projection as if it were the record; a level below, an immutable one is generally reachable by the same query.
Receipt. A fleet event terminated eight
witnessesruns inside 49 seconds despite starts spread across 51 minutes. Every lane re-ran, and a re-run replays the original merge ref and overwrites the run-level conclusion. Through run conclusions the population was invisible — zero of twenty-one. Through the runs' attempt records it was complete and exact hours later.Why it is stated as an inversion rather than a warning. Two independent reconstructions from the mutated view reported five and six of the eight — each correct, each incomplete, same cause. So the mutated view fails silently and partially, which is worse than failing empty.
An earlier draft of this entry was called response-erased evidence and argued the remedy destroys the evidence. That is false, and harmful in a specific way: a lane that has already remediated reads it as a verdict that its evidence is gone and stops looking — which is what produced the zero of twenty-one. The harmful half was in the class name, so anyone pattern-matching to it would inherit it. The rule is therefore: capture before remediating, or reconstruct from the immutable record — never from the mutable one.
Verification. Authority and projection compared over the entire 9267-character row, byte-identical, entry present exactly once in each. Not a sampled window: a prior drift audit on this same row probed a region already known to match and reported zero divergences while four edits sat at the end of the line.