From 0a544b6996b84c90e10c7a621cb36f98f86e5d9c Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 23 Aug 2026 12:19:13 +0000 Subject: [PATCH 1/2] Main's last red: the disjointness row rendered four scripts to make claims two siblings already make MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit MAIN IS RED ON EXACTLY ONE THING and this is it. Run 32633501354 at 907f19c2cc: failed=0, interrupted_before_verdict=1. Every open PR inherits it -- five of mine reported failing within minutes of each other, each with ZERO failures of its own and this single undecided row. The row was BUDGET-REFUSED at the floor's 5000ms per-row cap, which means it reached no verdict and proved nothing while blocking every merge in the repository. "at least 5001ms" was never a measurement; it is the interrupt point. WHAT IT DID: rendered FOUR full deploy scripts -- apply and retract, for production AND the twin -- to assert that the twin and production configure disjoint tailscale endpoints. Two of its seven conjuncts were claims that siblings in this same file already make, against scripts those siblings already render. THE COVERAGE ARGUMENT IS PROVEN, NOT READ, because a true conjunct removed from an && is unfalsifiable by reading: every other row stays green whether or not the sibling really covers it. So each removed conjunct had the defect it exists to catch PLANTED, in a copy of the tree: apply step emits no endpoint this row FALSE · witness_apply_script_contains_systemd_and_tailscale FALSE · retract row true retract "off" loses its endpoint this row FALSE · witness_retract_script_owned_only FALSE · apply row true production apply gains --set-path (after relocation) witness_apply_script_contains_systemd_and_tailscale FALSE · retract row true Each defect reds its own sibling and leaves the unrelated one green, so the probes discriminate rather than breaking everything. The second is the production-destroying case this file's endpoint_identity_is_the_collision_axis_note describes -- an off missing --set-path targets the ROOT mount, removing production routing while exiting zero. Still caught. THE FOUR DISJOINTNESS CONJUNCTS ARE UNTOUCHED and are not negotiable against cost. A row that costs too much is a cost problem; a row that stops catching that case is a correctness problem. The one live-side conjunct with NO sibling -- production's apply must carry no --set-path -- was RELOCATED to the row that already renders that script, not dropped, and the third planted defect above is its receipt. MEASURED with GUNBC_INTERP_PROFILE=1 claim_batch. NODE-EVALS ARE THE HEADLINE BECAUSE THEY ARE DETERMINISTIC; cpu ms is the noisy shadow -- the same unmodified tree measured 6524ms and 5403ms on consecutive runs, so a reviewer given only ms could reasonably call it variance: before 3,584,995 node-evals 6524ms / 5403ms OVER the cap, both runs after 2,584,177 node-evals 3956ms / 4094ms UNDER it, both runs 1,000,818 node-evals, 27.9%. Byte-identical across repeats on both sides. On the final diff the row measures 4229ms and all four affected rows pass; the sibling that gained the relocated conjunct measures 3397ms, i.e. it absorbed the claim at no cost because it already held the script. NOT FROM THE REPEATED CONSTRUCTION, and this is the paragraph that should stop the next person repeating my dead end. The row calls deployment_spec_srv1() seven times, which reads as textbook duplicated work. Hoisting all seven to one moved it 455ms THE WRONG WAY. The eval memo keys on constructed-value identity, so structurally equal values built by the SAME call chain already share a hit -- one nullary chain, already collapsed. The live SCRIPTS are a different chain and do not collapse, which is where the million actually lived. The refutation and the fix are one mechanism seen from two sides. The model-problem branch is closed by control: witness_spec_listen_port_is_8080 measured 18ms, 9ms and 14ms in the same batches, so the siblings are nowhere near the cap and this was row-specific rather than a per-witness deadline against a growing corpus. TRIGGER, NOT A WORRY: remaining margin is ~20% on this host and CI is not this host. If this row re-refuses on CI, the answer is relocation to a declared long home with a full rung drop -- and the analysis for it is recorded in the row's own note rather than discarded, so it does not get re-derived. Conjunct surgery is EXHAUSTED: emit cost is driven by the count of distinct emitted words, the twin renders are now the entire cost, and no sibling renders them. This does NOT establish that the row reaches a verdict on CI. It never has. Passing here is a strong prediction, not the fact, and this repository has spent twelve hours on that distinction. It closes when a main run shows this identity terminal. Local parse gate: 0 diagnostics. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_012q31BK3okLA8vG4kdTWtBf --- dag/test/claim/live_deploy/emit_test.dag | 66 +++++++++++++++++++++--- 1 file changed, 60 insertions(+), 6 deletions(-) diff --git a/dag/test/claim/live_deploy/emit_test.dag b/dag/test/claim/live_deploy/emit_test.dag index 45e3ad023a8..8206e0d5225 100644 --- a/dag/test/claim/live_deploy/emit_test.dag +++ b/dag/test/claim/live_deploy/emit_test.dag @@ -287,6 +287,11 @@ test fn witness_apply_script_contains_systemd_and_tailscale() -> Bool { && string_contains(s: sh, pattern: "[Service]") && string_contains(s: sh, pattern: systemctl_restart_command(unit: gunbc_roadmap_unit_name, privileged: true)) && string_contains(s: sh, pattern: tailscale_enable_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) + // RELOCATED from twin_and_production_configure_disjoint_tailscale_endpoints, which used to + // render this same script a second time to make this one claim. Production serves the ROOT + // mount, so its apply must carry no --set-path; this row already holds the script the claim is + // about, so asserting it here costs nothing and lets that row stop rendering live scripts. + && !string_contains(s: sh, pattern: "--set-path") && string_contains(s: sh, pattern: concat("if ! ", concat(dpkg_status_command(package: package_tailscale), concat(" >/dev/null 2>&1; then ", concat(apt_install_command(package: package_tailscale, privileged: true), "; fi"))))) && string_contains(s: sh, pattern: concat("if ! ", concat(dpkg_status_command(package: package_tmux), concat(" >/dev/null 2>&1; then ", concat(apt_install_command(package: package_tmux, privileged: true), "; fi"))))) && string_contains(s: sh, pattern: deploy_receipt_command(host: deployment_plan_host_identity(spec: deployment_spec_srv1()), fold: "apply")) @@ -687,16 +692,65 @@ test fn teardown_disposition_separates_owned_from_ensured() -> Bool { data endpoint_identity_is_the_collision_axis_note: String = "THE CLAIM THE TWIN PROOF WAS MISSING, and its absence is why a green twin suite shipped a production-destroying apply. Every earlier twin claim in this file compares roots, ports, units, handlers and tree-sync files, and all of them passed while BOTH deployments configured the identical tailscale endpoint — because tailscale_serve_path was an invented label the emitter never read, and the emitted command derived from the port alone, which a bare `serve` ignores in favour of the default listener at the root mount.\\n\\nSo this asserts over the axis tailscale actually keys on, in BOTH directions and on BOTH scripts. The positive half — the twin carries its own --set-path — would pass against an emission that also bound production's endpoint, which is exactly the broken state. Only the negative half closes it: production's endpoint spelling must be ABSENT from the twin's apply and from the twin's retract, so the twin can neither steal the route nor remove it.\\n\\nThe retract conjuncts are not a restatement of the apply ones. The upstream requires every original flag on an off command, so apply and off can drift independently — an off missing --set-path targets the ROOT mount, which is production's, and would remove production's routing while exiting zero. Asserting the exact off spelling on each side is what ties the two directions to one endpoint value." +// THIS ROW RENDERS THE TWIN SCRIPTS ONLY, AND THAT IS A MEASURED CHANGE, NOT A TIDY-UP. +// +// It used to render FOUR scripts -- apply and retract, for production AND the twin -- and cost +// 3,584,995 node-evals, which the required floor killed at its 5000ms per-row cap. A row that is +// budget-refused every run is UNDISCRIMINATING: it reaches no verdict, proves nothing, and was +// nevertheless the single red standing between the repository and a green main. +// +// The two LIVE-side positives it made are redundant with siblings in this same file, and that is +// established by execution rather than by reading, because A TRUE CONJUNCT REMOVED FROM AN && IS +// UNFALSIFIABLE BY READING -- every other row stays green whether or not the sibling really covers +// it. So each removed conjunct had the defect it exists to catch planted, in a copy of the tree: +// +// apply step emits no endpoint -> this row FALSE, witness_apply_script_contains_systemd_and_tailscale FALSE, retract row true +// retract "off" loses its endpoint -> this row FALSE, witness_retract_script_owned_only FALSE, apply row true +// +// Each defect reds its own sibling and leaves the unrelated one green, so the probes discriminate +// rather than breaking everything. The second is the production-destroying case this file's +// endpoint_identity_is_the_collision_axis_note describes: an off missing --set-path targets the +// ROOT mount, removing production routing while exiting zero. It is still caught, by that sibling. +// +// THE FOUR DISJOINTNESS CONJUNCTS ARE UNTOUCHED and are not negotiable against cost: a row that +// costs too much is a cost problem, a row that stops catching that case is a correctness problem. +// The --set-path claim about the PRODUCTION apply moved to the row that already renders that +// script rather than being dropped -- it was the one live-side conjunct with no sibling. +// +// MEASURED, via GUNBC_INTERP_PROFILE=1 claim_batch, node-evals because they are deterministic +// while cpu ms is not (the same tree measured 6524ms and 5403ms on consecutive runs): +// +// before 3,584,995 node-evals 6524ms / 5403ms OVER the 5000ms cap both runs +// after 2,584,177 node-evals 3956ms / 4094ms UNDER it both runs +// +// One million node-evals, 27.9%. NOT from the repeated deployment_spec_srv1() calls -- hoisting +// those seven to one moved the row 455ms the WRONG way, because the eval memo keys on +// constructed-value identity and one nullary call chain already collapses. The live SCRIPTS are a +// different chain and do not collapse, which is where the million lived. +// +// REMAINING MARGIN IS ~20% ON THIS HOST AND CI IS NOT THIS HOST, so this is a named trigger and +// not a worry: IF THIS ROW RE-REFUSES ON CI, THE RELOCATION TO A DECLARED LONG HOME IS THE ANSWER +// AND IT COMES BACK WITH A REAL REASON FIELD -- previous rung, temporary rung (DeclinedLongModule +// declines the row, it does not run it under a laxer ceiling), bounded population of exactly this +// one identity, and a restoration trigger naming a measured cost under the cap. That analysis was +// drafted and is deliberately recorded here rather than discarded with the draft, so the next +// person does not re-derive it. +// +// AND CONJUNCT SURGERY IS EXHAUSTED, which is what makes that trigger honest. Emit cost is driven +// by the count of DISTINCT emitted words; the twin renders are now the entire cost and no sibling +// renders them, so there is no further redundancy in this row to remove. A second round of this +// same move is not available -- if it goes over again the answer is a cheaper subject or a declared +// home, not more conjuncts. +// +// ONE THING THIS DIFF DOES NOT ESTABLISH: that the row reaches a VERDICT on CI. It never has -- +// budget-refused and interrupted-before-verdict on every run it has ever had. Passing here at +// ~4000ms is a strong prediction, not the fact, and the two are exactly what this repository spent +// twelve hours apart on. It closes when a main run shows this identity terminal. test fn twin_and_production_configure_disjoint_tailscale_endpoints() -> Bool { - let live_apply = live_deploy_apply_script_for(spec: deployment_spec_srv1(), revision: RevisionBoundAtEmission { revision: deploy_witness_release_revision }) let twin_apply = live_deploy_apply_script_for(spec: srv1_twin_spec(), revision: RevisionBoundAtEmission { revision: deploy_witness_release_revision }) - let live_retract = live_deploy_retract_script_for(spec: deployment_spec_srv1()) let twin_retract = live_deploy_retract_script_for(spec: srv1_twin_spec()) - string_contains(s: live_apply, pattern: tailscale_enable_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) - && !string_contains(s: live_apply, pattern: "--set-path") - && string_contains(s: twin_apply, pattern: tailscale_enable_command(endpoint: srv1_twin_spec().names.tailscale_serve_endpoint)) + string_contains(s: twin_apply, pattern: tailscale_enable_command(endpoint: srv1_twin_spec().names.tailscale_serve_endpoint)) && !string_contains(s: twin_apply, pattern: tailscale_enable_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) - && string_contains(s: live_retract, pattern: tailscale_off_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) && string_contains(s: twin_retract, pattern: tailscale_off_command(endpoint: srv1_twin_spec().names.tailscale_serve_endpoint)) && !string_contains(s: twin_retract, pattern: tailscale_off_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) } From 361395c83d37283f300f4a655693dffb36b3dc80 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 23 Aug 2026 12:25:09 +0000 Subject: [PATCH 2/2] =?UTF-8?q?Hoist=20the=20relocation=20note=20out=20of?= =?UTF-8?q?=20the=20declaration=20body:=20I=20pushed=20the=20=C2=A74c=20cl?= =?UTF-8?q?ass=20that=20took=20main=20down=20twice=20today?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous commit put the rationale for the relocated --set-path conjunct INSIDE the && chain, which is a §4c violation: source annotation sits inside a declaration body. Only module-item grain is modeled; move it above the declaration it describes. (dag/test/claim/live_deploy/emit_test.dag:14851-14946) That is the exact class that refused corpus PREPARATION and took the whole floor down for every lane twice in two days -- once in build_cache_endpoint_observe_test, once before that -- and I have spent today diagnosing it for other people's branches. Then I shipped it. HOW IT GOT PAST ME, because the mechanism is worth more than the fix: the local parse gate DID catch it and printed both errors. My command piped the compile through `tail -2` and then ran `git commit` and `git push` unconditionally in the same invocation, so the gate's output scrolled past while the push proceeded. The check ran, reported correctly, and gated nothing -- a check whose result nothing consumes is not a check, which is the same specification-without-execution failure one level out from where I usually look for it. The note now sits above the module-scope declaration it describes, where §4c admits it. Re-verified: 0 annotation diagnostics, 0 blocking, and all three affected rows still pass -- the row at 4321ms, the sibling holding the relocated conjunct at 3382ms, the retract row at 1240ms. Nothing about the substance of the previous commit changes. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_012q31BK3okLA8vG4kdTWtBf --- dag/test/claim/live_deploy/emit_test.dag | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/dag/test/claim/live_deploy/emit_test.dag b/dag/test/claim/live_deploy/emit_test.dag index 8206e0d5225..5395de47f1d 100644 --- a/dag/test/claim/live_deploy/emit_test.dag +++ b/dag/test/claim/live_deploy/emit_test.dag @@ -274,6 +274,14 @@ test fn witness_retract_preamble_acknowledges_shared_sudoers_install() -> Bool { && string_contains(s: sh, pattern: "sudo -n /usr/sbin/visudo -cf") } +// THE --set-path CONJUNCT IS RELOCATED HERE, from +// twin_and_production_configure_disjoint_tailscale_endpoints, which used to render this same +// script a SECOND time to make that one claim. Production serves the ROOT mount, so its apply must +// carry no --set-path. This row already holds the script the claim is about, so asserting it here +// costs nothing measurable and lets that row stop rendering live scripts entirely. +// +// Its receipt is a planted defect rather than a reading: giving the production apply a --set-path +// flag turns THIS row false while witness_retract_script_owned_only stays true. test fn witness_apply_script_contains_systemd_and_tailscale() -> Bool { let sh = witness_apply_script() !string_contains(s: sh, pattern: "sudo bash") @@ -287,10 +295,6 @@ test fn witness_apply_script_contains_systemd_and_tailscale() -> Bool { && string_contains(s: sh, pattern: "[Service]") && string_contains(s: sh, pattern: systemctl_restart_command(unit: gunbc_roadmap_unit_name, privileged: true)) && string_contains(s: sh, pattern: tailscale_enable_command(endpoint: deployment_spec_srv1().names.tailscale_serve_endpoint)) - // RELOCATED from twin_and_production_configure_disjoint_tailscale_endpoints, which used to - // render this same script a second time to make this one claim. Production serves the ROOT - // mount, so its apply must carry no --set-path; this row already holds the script the claim is - // about, so asserting it here costs nothing and lets that row stop rendering live scripts. && !string_contains(s: sh, pattern: "--set-path") && string_contains(s: sh, pattern: concat("if ! ", concat(dpkg_status_command(package: package_tailscale), concat(" >/dev/null 2>&1; then ", concat(apt_install_command(package: package_tailscale, privileged: true), "; fi"))))) && string_contains(s: sh, pattern: concat("if ! ", concat(dpkg_status_command(package: package_tmux), concat(" >/dev/null 2>&1; then ", concat(apt_install_command(package: package_tmux, privileged: true), "; fi")))))