Skip to content

Main emission is refusing on a trailing annotation, and no required phase can see it - #9027

Merged
briansrls merged 3 commits into
mainfrom
session/smart-ram-730-annot-emit-break
Aug 23, 2026
Merged

briansrls merged 3 commits into
mainfrom
session/smart-ram-730-annot-emit-break

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

What

gunbc compile --source-root dag --source-root src/v2 --entry src/v2/compiler/03_ingest.dag refuses on current main (faf6583461a): EMIT_REFUSE, emit_fail, no cargo log, CARGO_ERROR_TOTAL=n/a.

Measured this morning at 907f19c2cc7 the same entry emitted 177 files / 316 coded errors. So the emission board's subject stopped being producible during today's merges, and nothing reported it.

Cause

One file. §4c admits an annotation only as a standalone leading // block attached to a module-scope declaration. dag/test/manual/command_runner_local_argv_receipt_test.dag (from #8919) ends with a 62-line // block and no item after it, so the compiler refuses every span of it:

source annotation names no subject: no module item follows it.
Move it above the declaration it describes.

A corpus-wide scan finds exactly one such file, so the population is closed rather than sampled.

Repair

The block moves above the file's final declaration.

Every annotation line is preserved verbatim — diff of the sorted // lines before and after is a single added // separator. No prose rewritten, dropped, or summarised: a block deleted for one reason takes everything in it unless its contents are enumerated first.

What this says about the gate — more important than the fix

This is the second instance of this class today. #8976 landed an indented // inside a match arm this morning and broke the floor corpus-wide for 74 minutes; that one was caught only because the file was floor-enrolled.

This one sits in dag/test/manual/, which no required phase parses. The required run's three phases are the src/v1 .dag parse sweep, --required-regen, and the witness floor — none compiles a v2 entry. So an emission-breaking change landed on main and every gate stayed green. The only instrument that found it was a hand-run probe.

Rung

Mitigatable, and this is a repair of one instance, not a climb. The class stays writable and undetected.

Next-rung trigger: a required phase that compiles at least one v2 entry. The emission path has no gate at all today.

Test plan

  • Corpus-wide scan for .dag files whose last non-blank line is //: 1 before, 0 after.
  • Verbatim check: sorted // lines differ by exactly one added separator.
  • Emit verification against this branch running now; result posted here.

🤖 Generated with Claude Code

`gunbc compile --entry src/v2/compiler/03_ingest.dag` REFUSES on current main
(faf6583) with `EMIT_REFUSE` and no cargo log at all. Measured this morning
at 907f19c the same entry emitted 177 files and 316 coded errors, so the
board's subject stopped being producible at some point in today's merges.

The cause is one file. §4c admits an annotation only as a standalone leading
`//` block attached to a module-scope declaration; #8919 left a 62-line block at
end-of-file with no item following it, and the compiler correctly refuses every
span of it -- "source annotation names no subject: no module item follows it".
A corpus-wide scan finds exactly one such file, so the population is closed.

The repair moves the block above the file's final declaration. Every annotation
line is preserved verbatim (diff of sorted `//` lines is one added `//`
separator); no prose is rewritten, dropped, or summarised, because a block
deleted for one reason takes everything in it unless its contents are enumerated
first.

WHAT THIS SAYS ABOUT THE GATE, which matters more than the fix. This is the
SECOND instance of this class today: #8976 landed an indented `//` inside a
match arm this morning and broke the floor corpus-wide for 74 minutes. That one
was caught because the file was floor-enrolled. THIS one sits in
dag/test/manual/, which no required phase parses -- the required run's three
phases are the src/v1 `.dag` parse sweep, required-regen, and the witness floor,
and none of them compiles a v2 entry. So an emission-breaking change landed on
main and every gate stayed green.

RUNG, honestly: this change is a repair of one instance and NOT a climb. The
class remains writable and undetected. Its next-rung trigger is a required phase
that compiles at least one v2 entry -- the emission path has no gate at all
today, which is why the only instrument that found this was a hand-run probe.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

Emit verification — refusal cleared

Same command, same flags, one dispatch, on this branch:

gunbc compile --source-root dag --source-root src/v2 \
  --entry src/v2/compiler/03_ingest.dag --output-dir $OUT

0 blocking error(s), 503 advisory diagnostic(s)
EMITTED_RS=176

Against main faf6583461a, the identical invocation returns EMIT_REFUSE / emit_fail with no output tree and CARGO_ERROR_TOTAL=n/a. So the arms discriminate: refusal → 176 emitted modules, one annotation block moved, no other change in the diff.

Two things I am not claiming

176 is not comparable to the 177 measured at 907f19c2cc7. Main has taken a dozen-plus merges since that board, several of them emitter changes. The one-file delta is unattributed and this PR does not attribute it — differencing a count across two refs with a changed producer in between is exactly the confusion the probe's own column notes warn about.

This does not re-measure the board. 503 advisory diagnostics is the compile-stage count, not the cargo coded-error count; those are different instruments and must not be differenced against each other. The board number for current main is still untaken, and taking it is a separate job from restoring the ability to take it.

What remains open after this merges

The class stays writable and undetected. No required phase parses dag/test/manual/, and none compiles a v2 entry — so the emission path has no gate at all. This is the second instance of the annotation-placement class today; the first (#8976) was caught only because its file happened to be floor-enrolled. Next-rung trigger as stated in the PR body: a required phase that compiles at least one v2 entry.

— sent from smart-ram-730

@gunbai-bot

gunbai-bot Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor Author

This failure is inherited from main, not caused by this PR

The failing check is Required CI: parse, regen, witness floor on run 32647812417, and every error in it is at one call site this PR does not touch:

dag/gunbc/runner_slot_provision.dag:240:28: field 'argv' not found in type 'ArgvCommand'
dag/gunbc/runner_slot_provision.dag:240:14: sole_constructor type 'ArgvCommand' cannot be
                                             constructed outside its defining module
dag/gunbc/runner_slot_provision.dag:240:14: missing required field 'program'
dag/gunbc/runner_slot_provision.dag:240:14: missing required field 'arguments'

This PR's diff is one annotation block moved within one file under dag/test/manual/. It touches no type, no call site, and nothing on the resolve/typecheck path this refuses on.

The identical refusal reproduces on main itself — run 32646482842 at faf6583461a, a commit this branch is cut from and does not modify. So the failure is inherited by every open PR rather than caused by any of them.

Cause and fix: #8919 sealed ArgvCommand as a sole_constructor record while one call site kept the old flat shape. Repaired in #9032.

Why this PR cannot go green on its own, and why that is not a reason to widen it

The two breaks live on different paths:

  • the argv break stops strict preparation, so the floor never runs — that is what fails here;
  • the annotation break stops gunbc compile on a v2 entry, which no required phase executes — which is why this PR's own fix cannot show up as a green check at all.

So #9032 must land first; this PR then re-runs green. Merging the argv fix into this branch would fuse two unrelated repairs into one vehicle and make each harder to revert independently — the same reason the measurement carrier was kept out of #8982 today.

Nothing to push here. The verification that this PR's fix works is the emit A/B already posted above: EMIT_REFUSE on main → 176 modules with 0 blocking errors on this branch.

— sent from smart-ram-730

@briansrls
briansrls merged commit 1ed0205 into main Aug 23, 2026
2 checks passed
@briansrls
briansrls deleted the session/smart-ram-730-annot-emit-break branch August 23, 2026 23:54
briansrls pushed a commit that referenced this pull request Aug 24, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
… citations

Review 55234, two findings, both real.

The recipe measured `$(git rev-parse HEAD)` while the board is pinned to faf6583,
and named the parse blocker without saying how to lift it — so run the documented
recipe at the documented tree and it refuses with EMIT_REFUSE and produces nothing.
It now checks out the pinned SHA, takes the one repaired file from #9027's merge
commit, and passes the pinned SHA to PROBE_EXPECT_BASE_SHA. It also states why the
resulting HEAD-vs-tree difference cannot be misread by the stale stamp of defect 2:
the lifted file is dag/ subject data, case 1 of this document's own discriminator.

Six positional `.dag:NN` citations sat beside symbols that already named the same
declaration; all are dropped, and the three rt_functions() call sites are named by
their enclosing symbols instead of by grep line prefixes. What remains is the
file:line:col inside verbatim rustc output against the generated mirror, which is
the no-symbol-exists case §3 leaves to a position — now said explicitly.

Also: the count above the defect list said two while listing three.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
…ing on

CI on a4f3e69 went red with FAILED PHASE parse (52 errors), all 52 on
one file this branch does not touch:
dag/test/manual/command_runner_local_argv_receipt_test.dag. It is the
§4c refusal for an annotation that names no subject -- #8919 left a `//`
block at end-of-file with no declaration following it. Main repaired it
in 1ed0205 (#9027); this branch was cut before that commit and
carried the broken file forward.

The floor phase passed. The KNOWN-RED-RUNTIME-ERRORED lines filling the
log are reported-not-gating by construction and are not why the run went
red -- reading them as the failure would have cost an hour on the wrong
subject.

Both merge conflicts were GENERATED artifacts -- DESIGN.md and
.github/workflows/witnesses.yml -- while all three of their authorities
merged clean with zero markers. Resolved by regeneration rather than by
hand-editing bytes nobody authored: a hand-resolved generated file is
drift the next regen deletes silently, which is the same failure this
branch already had to repair once.

Verified by content, not by the merge succeeding: DESIGN.md differs from
origin/main by exactly one line (this branch's rung-drop row), carries
the corrected bounded-population wording, and still carries the §4b
passage ported in earlier. The regenerated witnesses.yml has zero `cited`
references -- the deletion holds -- and picks up main's new toolchain
step.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017HBx8dnz3oCiiHXoSBdtH2
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
…ontrol

Contributed by quiet-pike-368, who was one night from rewriting a correct change
to fix a defect they did not cause. Their board came back EMIT_REFUSE with zero
files and a plausible mechanism ready to blame; the control returned identical
refusals in both arms, and the real cause was a trailing // block in a file not
even in the compiled closure, since fixed as #9027.

This one guards ATTRIBUTION rather than the run. When the change is in the
compiler and the measurement is downstream, a red says nothing on its own: the
tree contains your change and everything else since your baseline. The failure
is not a wrong number, it is a CORRECT number attributed to the wrong cause,
with the author's own plausible mechanism supplying the false explanation.

Reverse-patch rather than checkout, because ctrl-build's remote does its own
git checkout --force and grafts a depth-1 clone at your commit, so a
checkout-between-arms is defeated or cannot reach the parent at all. Carried in
the script text, the patch survives whatever the runner did.

Three things make it an instrument: print git status after the revert (a
silently-failed revert gives two AFTER arms reading as "my change had no
effect"); rebuild between arms and delete the binary-identity stamp (both arms
share one HEAD by construction, so the stamp says already-built and arm two
reuses arm one's compiler); and read the rows that did NOT move, because a delta
on the target row is equally consistent with "fixed 8" and "fixed 12, broke 4
elsewhere".

Note it passes clauses 1-4 completely -- the run executed, on the right tree, the
subject stood alone, the arms were two arms. What is missing is any evidence
about WHOSE the difference is, which is why the guard is a second arm rather
than a better marker.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
briansrls pushed a commit that referenced this pull request Aug 24, 2026
Two of the three declared type parameters are reachable from no field,
variant payload, or other representation-bearing position. The interpreter
erases them; Rust does not, so the declaration is well-formed on one
realization path and ill-formed on the other.

Measured on clean main with the #9027 annotation blocker lifted and a
freshly built compiler: 122 -> 112 primary sites, E0392 4 -> 0 and
E0282 9 -> 3. No row relocated -- thirteen other error classes are
identical across both arms.

Frozen to the one source decision. EnforceableLens and EnforcedApplication
keep all three parameters and are untouched: both structurally represent
the full trio.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 24, 2026
… each with its evidence status (#9068)

* Five compiler-side mechanisms behind the affected-set emission board, each with its evidence status

Partitions the 24 rows landing in v2_lens_application.rs, std_change.rs and
v2_lens_affected_set.rs into six mechanisms with no residue; documents the five
compiler-side ones and names the sixth as already-owned so the arithmetic closes.
Two are measured by executed counterfactual, three are read from rustc text plus
.dag source, and that distinction is carried per-mechanism rather than flattened.

Proposes no repairs, deliberately.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Pin the reproduction and script the blocker-lift; drop the positional citations

Review 55234, two findings, both real.

The recipe measured `$(git rev-parse HEAD)` while the board is pinned to faf6583,
and named the parse blocker without saying how to lift it — so run the documented
recipe at the documented tree and it refuses with EMIT_REFUSE and produces nothing.
It now checks out the pinned SHA, takes the one repaired file from #9027's merge
commit, and passes the pinned SHA to PROBE_EXPECT_BASE_SHA. It also states why the
resulting HEAD-vs-tree difference cannot be misread by the stale stamp of defect 2:
the lifted file is dag/ subject data, case 1 of this document's own discriminator.

Six positional `.dag:NN` citations sat beside symbols that already named the same
declaration; all are dropped, and the three rt_functions() call sites are named by
their enclosing symbols instead of by grep line prefixes. What remains is the
file:line:col inside verbatim rustc output against the generated mirror, which is
the no-symbol-exists case §3 leaves to a position — now said explicitly.

Also: the count above the defect list said two while listing three.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Give every mechanism a disposition and a next trigger; unowned is declared, not implied

Review 55260 is right that "proposes no repairs" was doing two jobs at once. Declining
to pre-decide a fix is a stance on repair design; §4b(2) separately forbids leaving a
discovered class with no stated trigger, and the document had conflated the two.

Each of the six now carries a disposition and a trigger. A is a repair in flight
(#9041) with the one question the counterfactual cannot answer named and handed to the
module's author. C is owned by the corpus-wide ABSENT_CLONE_BOUND population and gets
no second trigger here, because a second one would be a second authority for one class.
D's lane is #8952. B, E and F are declared UNOWNED -- 7 rows between them, no lane holds
them -- with the promote-to-measured counterfactual named for each. Declaring them
unowned is the disposition: it makes their absence countable, where inventing a lane row
would manufacture an owner that does not exist.

The trigger for a read mechanism is an executed counterfactual, which is a trigger and
not a repair -- the same order the two measured mechanisms here already went through.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
briansrls pushed a commit that referenced this pull request Aug 24, 2026
…urement controls, and the rule under them (#9066)

* Record the dispatch-marker rule: a remote dispatch can exit 0 having executed nothing

Observed while verifying the carrier decomposition: a ctrl-build --remote
dispatch returned exit 0 with the payload never executed -- the log stopped
after git apply and no command output appeared at all. Reading that status
would have reported a green run from a dispatch that ran nothing.

The wrapper's exit code describes the DISPATCH, not the payload, so "ran and
printed nothing" and "never ran" are byte-identical through it and neither
errors. That is the empty-observation class DESIGN already names, moved one
layer out from the subject to the tooling that measures it -- and the
subject-level instance was live in the same session, an emission probe
returning "emitted files: 0" because the compiler had refused and written no
output directory at all.

The rule is to author markers and read those, so that a MISSING marker is
distinguishable from a ZERO marker. Written up at fleet grain rather than left
in a session message, at smart-ram-730's request, because it exists only
because its absence nearly produced a false green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Second clause: assert the subject, not only that you measured

The first clause guards whether the command ran. It does not guard what it ran
AGAINST, and that gap has its own specimen from the same evening: a
git merge --ff-only had failed, so a confirmation dispatch ran against a branch
that did not contain the commit under test. Head unchanged, payload executed,
every execution marker present -- and the run would have returned zero and read
as "the fix did not work".

The two clauses are complementary and neither implies the other: a dispatch that
never ran is caught by absent execution markers and says nothing about the tree;
a dispatch against the wrong tree has every execution marker present and is
caught only by a subject marker. "The fix does not work" and "the fix is not in
this tree" produce identical output, and only one of them is about the fix.

Raised by smart-ram-730 against the first revision, from their own near-miss.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Third clause: assert the subject stands alone; and prefer a content subject-marker over an ancestry one

THIRD CLAUSE, with the strongest receipt of the three. gunbc#8282, the namespace
cut, was abandoned after every measurement taken on it proved comparative --
conflict counts, import deltas, rehearsal tables -- and not one asked whether the
branch built on its own. It had not built in two days; a breaking commit dropped
36 emitted modules whose .dag authorities still exist, and 117 commits landed on
top. Nobody was careless: everybody was measuring, and every measurement was
relative to something carrying the same defect.

That completes the trilogy. Assert THAT you measured, assert WHAT you measured,
assert the subject STANDS ALONE -- and #8282 passes the first two, which is
exactly why the third is not implied by them. The check is one dispatch: build
the head alone in a fresh worktree, no merge, no working-tree patch. It has a
positive arm (a sibling branch cleared in a single dispatch the same night), so
it is a routine discriminator rather than a warning: "my change is incompatible
with main" and "my change cannot exist without itself" produce the same
confusing failure and are otherwise indistinguishable. The signature that lets
it run for days is recorded too -- hand-restoration does not converge and looks
like progress; 123 errors, then 122, then 271 across three rounds of adding back
what seemed missing.

ALSO REFINES CLAUSE 2 from my own bad run: a subject marker must be answerable
where it RUNS. These runners fetch with --depth=1, so git merge-base
--is-ancestor has no history to walk and reports NOT AN ANCESTOR for a commit
that is present -- measured, a branch that demonstrably contained the fix
reported HAS_9027=0. A marker that answers "no" because it cannot answer is the
same defect one level in. Prefer a content assertion over a history one.

Third clause requested by smart-ram-730 for fleet reach; this doc is where
anyone looks, and one clause here does what fourteen sends would.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fourth clause: two arms, two dispatches -- and state what all four have in common

A before/after run in ONE dispatch with a checkout between the arms is the
natural, efficient, obvious form, and it silently destroys the comparison.
Measured while deliberately trying to avoid this class: the mid-run checkout
failed, its failure was swallowed, and "before" ran on the same tree as "after".
Both arms reported identical shas -- which was the result being sought, so the
run read as a clean pass. It was measure() == measure(), produced by a
comparison that had lost its second operand. A lost operand does not report as a
lost operand; it reports as agreement.

Also states what the clauses have in common, which is the part that makes them a
rule rather than four anecdotes: every one is an instrument answering a question
narrower than the reader asked. The wrapper answers "did the dispatch succeed"
when asked "did the payload run". The ancestry check answers "can I see this in
my history" when asked "is this in my tree". The comparative measurement answers
"do these differ" when asked "does this work". The single dispatch answers "are
these equal" while holding one thing. Nothing lies and nothing errors in any of
them, which is why none has a failure arm and why each must be guarded by
asserting the missing question rather than by checking for an error.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Fifth clause: is this defect mine? -- the reverse-patch attribution control

Contributed by quiet-pike-368, who was one night from rewriting a correct change
to fix a defect they did not cause. Their board came back EMIT_REFUSE with zero
files and a plausible mechanism ready to blame; the control returned identical
refusals in both arms, and the real cause was a trailing // block in a file not
even in the compiled closure, since fixed as #9027.

This one guards ATTRIBUTION rather than the run. When the change is in the
compiler and the measurement is downstream, a red says nothing on its own: the
tree contains your change and everything else since your baseline. The failure
is not a wrong number, it is a CORRECT number attributed to the wrong cause,
with the author's own plausible mechanism supplying the false explanation.

Reverse-patch rather than checkout, because ctrl-build's remote does its own
git checkout --force and grafts a depth-1 clone at your commit, so a
checkout-between-arms is defeated or cannot reach the parent at all. Carried in
the script text, the patch survives whatever the runner did.

Three things make it an instrument: print git status after the revert (a
silently-failed revert gives two AFTER arms reading as "my change had no
effect"); rebuild between arms and delete the binary-identity stamp (both arms
share one HEAD by construction, so the stamp says already-built and arm two
reuses arm one's compiler); and read the rows that did NOT move, because a delta
on the target row is equally consistent with "fixed 8" and "fixed 12, broke 4
elsewhere".

Note it passes clauses 1-4 completely -- the run executed, on the right tree, the
subject stood alone, the arms were two arms. What is missing is any evidence
about WHOSE the difference is, which is why the guard is a second arm rather
than a better marker.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Clause 5: revert the generated mirror too, and fix a miscount

Both from quiet-pike-368's review of the clause they contributed.

SUBSTANTIVE: in a self-hosting tree the reverse patch must cover the GENERATED
MIRROR as well as the authority, because the mirror is what the binary is built
from. Their commit touched src/v1/05_emit_rust.dag and
src/v1/stage0/src/v1_compiler_emit_rust.rs and both had to be reverted.
Reverse-patching only the .dag leaves a BEFORE arm whose gunbc was built from
the AFTER mirror, so both arms measure the change, the rows come back identical,
and it reads as "my change had no effect". Same false null as the first
condition, through a door git status does not close: the revert genuinely
applied, the porcelain listing is honest, and the arm is still not a before arm.
git show <commit> --stat is the roster. The .dag is what the author thinks of as
their change; the mirror is what the compiler thinks of as its source.

NIT: the clause said "the two failures this clause names" and names one.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Lead with the unification, and record the doc's own discoverability failure

smart-ram-730's point, and it is right: the deliverable is not the five
techniques, it is the sentence that makes them one thing. Every failure here is
an instrument answering a question narrower than the reader asked -- did the
DISPATCH succeed vs did the PAYLOAD run; can I see this in my HISTORY vs is it
in my TREE; do these DIFFER vs does this WORK; are these EQUAL while holding one
thing; what is true of this TREE vs what did I DO. Nothing lies or errors in any
of them, which is exactly why none has a failure arm and why the guard is always
to assert the missing question rather than to check for an error. The five
clauses will go obsolete with the tooling; that paragraph will not, so it leads.

Also records the document's own discoverability failure, which is the sharper
half. curated_cargo_probe_one.sh's header already documented the 176-vs-177
trap, including that two sessions differenced the pair for forty minutes at a
prior ref -- and it was sprung again the same night on the people running that
very file. A rule recorded where the reader will not be standing is re-derived
at full price. The structural version, worth more than this doc: EMIT_COUNT_SRC
provenance belongs IN the emitted line, not in a header comment ABOUT the
emitted line. A number that states its own producer cannot be differenced
against one produced differently; a comment explaining that they differ can be,
and was.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A sixth clause: an agreeing arm-pair is clause 4's asymmetry, one layer down

`eager-lark-892` ran the control; `deep-ant-102` supplied the reporting-side
statement, relayed by `smart-ram-730`. Both asked for it to be written as a
RELOCATION of clause 4 rather than a sixth technique, and that is the point:
a reader who files it as another ad-hoc trick drops it the first time it is
inconvenient.

The asymmetry clause 4 already rests on -- a differing pair cannot have
shared a binary, so it is self-proving -- is exactly what makes an AGREEING
pair undecidable from its own output. Moving the comparison down to the
emitted bytes puts the arms back where they differ, and the same argument
then licenses the null.

The clause also states what binary provenance cannot do, because #9018
landing at 330f63c makes "the probe key is fixed" the natural thing to
believe. The key answers "was this built from the tree I named"; it never
answers "were the two things I compared different". A silently failed
checkout inside one dispatch defeats it while the key is CORRECT.

Both arms of the control were observed (2-of-176 differ, and 0-of-176), with
its two bounds stated: it proves the compilers differ, not that either is
correct, and it is scoped to one entry's closure.

Also records the sequential-local-dispatch-from-a-detached-checkout choice as
a design decision: `ctrl-build --remote` gives a two-arm dispatch one head and
two trees, and a sequential local run cannot express that state.

* Clause 1's precondition: only the party who knows the required answer can check

quiet-pike-368's, converged on with smart-ram-730 from two failures in one
night. Placed BEFORE clause 2 rather than appended, because it is not a
seventh technique -- it is what makes clause 1 performable. Clause 1 says a
missing marker must be spelled differently from a zero one; this says who is
capable of drawing that distinction at all, and the answer is never the reader
of the output.

The two instances are kept as a pair because the pairing is the content: an
emitter probe returning empty for all five modules, caught only by a positive
control; and a dashboard send that dropped a sentence's SUBJECT, reconstructed
correctly only because the surrounding paragraph over-determined it. Both
artifacts were WELL-FORMED -- a complete sentence, a complete empty result --
so nothing downstream could reach either. Remove the redundancy from the second
and the reader supplies what they already believed, arriving back in the
sender's voice as confirmation.

Concrete form kept verbatim because the abstract version gets nodded at:
distinct spelling for missing vs empty, a liveness count beside every zero,
and never 2>/dev/null on an instrument.

Receipt added from this lane, an hour old: a candidate-tree comparison printed
DIFFERS per mismatch and NOTHING when its file list was empty, so "the regen
candidate matches the committed mirror" and "find matched no files" rendered
identically. Only the regen verdict printed in the same output
(first_generation_equal=false) kept the empty list from reading as agreement.

* The third leg: assert what a green ENTAILS — and CANCELLED renders as `fail`

smart-ram-730's framing, and it generalises the existing clauses rather than
adding another: clause 1 asserts THAT you measured, clause 2 asserts WHAT you
measured, and this asserts what the green you got actually establishes. It
fires precisely when the first two pass -- the instrument ran, on the right
tree, and returned an honest success that covered a narrower question than the
reader was asking.

Three receipts from three lanes in one night: a .dag compile board read as
evidence about the emitted seed (it compiles source; required-regen answered
first_generation_equal=false with ten drifted mirrors immediately);
whole-tree compile-clean read as evidence a module emits ALONE, which it
cannot establish because the definers are only in the pool via someone else's
import; and `gh pr checks` rendering a CANCELLED run as `fail`.

The third gets its own section because it manufactures reds rather than
hiding them, and a manufactured red gets chased. witnesses.yml keys
concurrency on the resolved PR number while GitHub attributes a run by BRANCH,
so a stacked child's push cancels the PARENT PR's in-flight run and the parent
then reads fail indefinitely with nothing wrong in its diff. The
discriminators are tabulated -- conclusion `cancelled`, `steps: []`,
`runner_id: 0`, ~2 minute lifetime, and the job's head_branch being the
child's -- with the `gh api` line that shows them, because at a glance the two
states are the same word.

* Three more from quiet-pike-368, grouped by what actually caught them

All three are theirs and all three are re-runnable. Grouped rather than filed
as separate clauses because the pattern across them is one sentence they wrote:
a well-formed wrong number is the default output of an under-specified
instrument, and the only defence that worked in any of the three was carrying
something that could contradict it. None was caught by care.

TREATMENT THAT CANNOT REACH THE INSTRUMENT is genuinely a new shape here --
not a missing marker, not a narrower question: BOTH ARMS ARE HONEST AND THE
COMPARISON IS MEANINGLESS. A .dag patch measured through `gunbc compile`,
which runs the SEED BINARY; a .dag edit reaches an artifact only via regen, so
the patch could never have applied. Caught by md5sum of the binary being
identical across arms plus a 0.05s "build" after an rm -f.

A DIGEST THAT INCLUDES A PATH is the sharpest of the three because it
fabricates the study's desired positive: `xargs md5sum | md5sum` over a per-run
directory differs by construction on every run, including under a perfectly
deterministic producer. Exposed only by a second instrument contradicting it
(0 differing files under diff -rq while the hashes differed).

DENOMINATOR BEFORE TEST: 39 vs 79 hand-maintained seed files, where the
tempting suspect was the differing test and the measured answer was that the
two tests agree on all 169 files -- the separator was a non-recursive `*.rs`
glob. Their own note that this is the MORE COMMON half is kept, because a test
difference is visible in the code and a denominator difference is invisible in
both. Paired with deep-ant-102's intersect-the-populations clause, credited to
them.

* The marker must not match the request for the marker, and an exit code is not completion

Two additions to clause 1, both found by smart-ram-730, and the first is a
specimen located INSIDE this document's own remedy -- which is why it goes
beside the rule rather than in a footnote.

ctrl-build echoes the command before running it, so a transcript containing
MARKER_ALL_DONE contains it twice: once because you asked for it, once if the
payload reached the end. `grep -q MARKER_ALL_DONE` therefore succeeds on a
dispatch that ran nothing. The marker rule defeated by the marker. `grep -qx`
or an anchored `^MARKER_` skips the echo, which carries the whole script on one
line with the newlines escaped. Every EMITTED=-style table in this document has
the same exposure and the doc now says so.

That is the class one turn further in than the rest of the document: not an
instrument answering a narrower question, but the check matching its own
request. A transcript holding both the instruction and the result cannot be
searched for the result without excluding the instruction.

The second is the pair of receipts behind "read the marker, not the status",
and the pairing carries it: a 70-module sweep whose timeout killed ctrl-build
while a trailing echo returned exit 0, failure inferred only from missing data
rows and by luck; and a dispatch here that printed SUBJ_PF_ROW=1, the build
line, and then nothing -- no CI_EXIT marker, because the payload exceeded the
dispatch wall. As a missing marker that is unambiguous. As an exit code it was
a success. The shell answers whether the LAST command in the pipeline
succeeded; the question asked was whether the payload completed, and those
differ exactly when a timeout kills the thing you care about.

* Three more: the mirror that never arrived, the ledger that got it right, and why a retraction does not catch up

MIRROR DRIFT is the same shape as quiet-pike-368's treatment-cannot-reach-the-
instrument clause, given its own section because on this substrate it is the
DEFAULT rather than an exotic mistake -- four lanes hit it in one night on four
files. It is also the WORST member of the class: the others produce a wrong
number, this produces no error at all. Run succeeds, figures internally
consistent, control and treatment agree, and the agreement is an artifact of
the treatment never having been applied. A null from a stale binary is
indistinguishable from a null from a real one, which makes it silently
confirmatory and worst in exactly the probes built to keep their author honest
-- a pre-registration reading "unchanged -> risk not realised" is handed that
string by staleness.

THE LEDGER THAT GOT IT RIGHT is the same class from the winning side, and the
document needed one: `regen FAIL ... std_algebra.rs` printed seventeen minutes
before the floor refused for that reason, and the RELATION between the two is
the diagnosis. That is an argument for independent phases -- a line-stopping
regen would have shown the drift and hidden the floor error, and the next run
would have read as "the fix did not work" rather than "the fix has not
arrived", which have opposite remedies.

CORRECTIONS ARE PUSHED TO HOLDERS is smart-ram-730's, and both halves are kept
because they belong to different parties: a claim sent as a CAUTION came back
as a CLAIM with nothing misquoted -- the mood changed, and a claim propagates
where a caution prompts a check; and the reader traced carefully on the half
touching their own work and took the rest on trust. A retraction at the top of
a brief fixes the next reader and never the current one.

* An instrument answering NO question, and two dashboard failures with opposite remedies

Both from quiet-pike-368.

THE SPECIMEN is a genuinely different member: most failures here answer a
NARROWER question than the reader asked; this one answers none and is typeset
as an answer. A candidate-union dump returned empty for all five modules, which
is a perfectly good answer to the question asked -- it locates the defect on the
producer side -- and it was three stacked failures: a grep path missing the
`src/` segment, a `2>/dev/null` eating the resulting "No such file", and a
render that spells "no probe line present" as an EMPTY NAME SET, byte-identical
to "ran, union genuinely empty". Only a positive control separated them.

The repair is kept because it is at the RENDER rather than the query, which is
what makes it a remedy rather than a warning: `<no probe line>` distinct from
`[]`, plus a PROBE_LINES_TOTAL liveness count so a zero is visible as a zero
instead of inferred from absence.

THE LAG-VS-MISS ROW is two findings that share one symptom on the field that
gates merging, and they are filed separately at quiet-pike-368's insistence
rather than collapsed: `dashboard-ops reviews <n> <repo>` (wrong arg form)
returns well-formed JSON with zeros, so an open REQUEST_CHANGES reads as a
clean PR -- deterministic and dangerous. Ingestion lag in the WORKING form is
conservative and self-resolving. The discriminator is a head sha: real data
always carries one. Filing the lag case as the miss's specimen would put a
wrong example under a right rule, and the next person hitting a real miss would
find the documented symptom not matching.

* One defect presenting as two sequentially, and why the render repair sits above the rest

Both quiet-pike-368's framings, and the first is better than the version I sent
them. I had it as a two-maps gotcha; they saw it as the INVERSE of the class
this document already carries -- deep-ant's and theirs are one subject
presenting as two measurements, this is one defect presenting as two defects,
in sequence, with the second typeset so as to be misread.

The distinguishing feature is the LOCATION LIE, and it is why this is a row
rather than an instance of the narrower-question rule: the second refusal is
not answering a narrower question, it is answering ACCURATELY ABOUT A PLACE
THAT IS NOT WHERE THE DEFECT IS. `variant 'Present' not found in type
<payload>` points at the payload type's declaration line, and a reader who
trusts the pointer finds nothing wrong there because nothing IS wrong there.

Recognition rule kept in their words, since the sequencing is the tell rather
than the message: a refusal that appears only after you fixed an adjacent one,
pointing at a declaration far from the call site, is the next layer of the same
carrier until proven otherwise. With the corollary that costs a cycle either
way -- both maps need a regen round before either fix is observable, so a run
that still refuses is not evidence the fix was wrong.

Also their one-line justification for why the render repair outranks every
other remedy here: it is the only one that does not depend on the reader being
suspicious. Check-something rules fail against a tired author with an
explanation ready; making two states unspellable as each other at the point of
production has no such failure mode, which is DESIGN §5's
construction-over-validation applied to instruments rather than programs.

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant