Skip to content
1 change: 1 addition & 0 deletions dag/extdeps/exec/command.dag
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,7 @@ fn argv_command(program: NonEmptyStr, arguments: List<String>) -> ArgvCommand
decl_ref(module_path: "extdeps.tools.gnu_coreutils", decl_name: "true_command"),
decl_ref(module_path: "extdeps.tools.gnu_coreutils", decl_name: "whoami_command"),
decl_ref(module_path: "extdeps.tools.gnu_coreutils", decl_name: "readlink_command"),
decl_ref(module_path: "extdeps.tools.gnu_coreutils", decl_name: "ls_one_per_line_command"),
decl_ref(module_path: "extdeps.tools.findutils", decl_name: "find_symlink_target_glob_command"),
decl_ref(module_path: "extdeps.tools.chmod", decl_name: "chmod_set_mode_command"),
decl_ref(module_path: "extdeps.tools.stat", decl_name: "stat_owner_user_name_command"),
Expand Down
12 changes: 12 additions & 0 deletions dag/extdeps/tools/gnu_coreutils.dag
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,18 @@ data printf_program: NonEmptyStr = "printf"
data true_program: NonEmptyStr = "true"
data whoami_program: NonEmptyStr = "whoami"
data readlink_program: NonEmptyStr = "readlink"
data ls_program: NonEmptyStr = "ls"

// -1 ALONE, AND THE NAME CARRIES IT FOR THE SAME REASON rm_force_command's DOES. `-1` forces ONE
// ENTRY PER LINE, which is what makes the output splittable by the caller: ls(1) columnates when
// stdout is a terminal and emits one-per-line when it is a pipe, so a caller that does not pass -1
// is depending on where its output happens to go. It does NOT recurse and does NOT include dotfiles
// -- that is -a, a different question with a different answer -- so this enumerates exactly the
// non-hidden entries DIRECTLY under `path`. A caller needing hidden entries or a recursive walk
// needs its own builder and its own name, not a flags parameter here.
fn ls_one_per_line_command(path: String) -> ArgvCommand {
argv_command(program: ls_program, arguments: ["-1", path])
}

fn cat_command(path: String) -> ArgvCommand {
argv_command(program: cat_program, arguments: [path])
Expand Down
6 changes: 6 additions & 0 deletions dag/gunbc/ci_layer_roots.dag
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,12 @@ data witness_exclusion_frontier: List<WitnessExclusionRow> = [
reason: "interpreted corpus walk prices out of every CI lane (measured ~33s/module parse, hours full run; see corpus_witness_note in the test file); the CI-cadence corpus consumer is the retained host projection v2.lens.mandatory_tag.corpus_scan",
dissolution: unbound_dissolution(description: "witness realization executes the corpus walk at native speed; then the witness enrolls and this row deletes")
},
WitnessExclusionRow {
pattern: "long/qualified_spelling_identity_witness_test.dag",
classification: OfflineLocalRecipe,
reason: "QUARANTINED ON OPERATOR RULING 2026-08-23, AND THE MEASUREMENT IS WHY IT IS ALSO A FILED DEFECT RATHER THAN ONLY A COST ROW. qualified_spelling_takes_the_shared_layer completed and then exceeded the 5000ms executor fail-stop by 11x -- wall_ms=57337, cpu_ms=57193 on run 32657761997 -- while growing RSS by 1.22GB to a 11.70GB process. THE SPLIT THAT WAS SUPPOSED TO FIX THIS DID NOT: gunbc#8984 measured the conjoined two-arm claim at 1.22GB, split the arms into separate test fns on that reasoning, and the QUALIFIED ARM ALONE still measures 1.22GB -- the identical figure -- while the bare arm appears in no over-cost or memory line at all. So the cost was never the two live compile_dag_rust_emit_check calls; it is specific to the qualified-name resolution path, which is the path #8984 exists to repair. This row therefore quarantines a witness AND records an unexplained cost-shape defect; it is not a witness that is merely heavy. WHY IT WAS NOT CAUGHT BEFORE MERGE: #8984 landed in the batch after the last green main run, while main refused at floor PREPARATION on an unrelated ArgvCommand seal break, so its floor phase never executed and this row never surfaced on its own check -- the same masking that hid gunbc#9022's roster defect in the same batch. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/qualified_spelling_identity_witness_test.dag --functions qualified_spelling_takes_the_shared_layer,bare_spelling_shared_layer_is_unchanged",
dissolution: unbound_dissolution(description: "the qualified-name resolution cost defect is root-caused and repaired, at which point the arm measures under gunbc_ci_fast_lane_eval_budget_ms and this row deletes with the move back to dag/test/claim/. This row does NOT dissolve on a per-witness cost envelope: an envelope large enough to admit 1.22GB and 57s would admit the defect rather than measure it, and the operator's ruling was to quarantine AND find the cause, not to raise the ceiling")
},
WitnessExclusionRow {
pattern: "long/cited_symbol_resolution_witness_test.dag",
classification: OfflineLocalRecipe,
Expand Down
4 changes: 2 additions & 2 deletions dag/gunbc/runner_slot_provision.dag
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ import gunbc.command_runner {
run_shell_command_capture,
LocalExec,
}
import extdeps.exec.command { ArgvCommand }
import extdeps.tools.gnu_coreutils { ls_one_per_line_command }

// RunnerSlotProvision owns runner installation end-to-end in gunbc (operator ruling 2026-08-06:
// ctrl is a dead repo; prior ctrl:install-actions-runner citations are void legacy pointers).
Expand Down Expand Up @@ -237,7 +237,7 @@ func observe_runner_slot_members_wet() -> RunnerSlotObservation
uses net: Network
{
match run_shell_command_capture(
command: ArgvCommand { argv: ["ls", "-1", actions_runner_base_dir] },
command: ls_one_per_line_command(path: actions_runner_base_dir),
transport: LocalExec,
) {
ProcessRefused { exit_code: code, stderr: err } =>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
module test.claim.qualified_spelling_identity_witness_test
module test.claim.long.qualified_spelling_identity_witness_test

data qualified_spelling_identity_note: String = "THE EMITTER CONTRACT, IN THE DIRECTION THE CORPUS IS MOVING. Same resolved declaration, different authored spelling, must produce the same Rust. Its converse is the container-head law already recorded in this repository -- same leaf, different resolved identity, must produce different Rust -- and both are one principle: emission is decided from RESOLVED IDENTITY, never from the authored string. MECHANISM: emit_field_value_with_context decided the shared reference layer of a record-literal FIELD VALUE with set_contains(shared_types, rc_name) where rc_name is the name AS AUTHORED, while shared_types is keyed on the bare declared name (the same mismatch alias_rhs_qualified_name_routing_note records for every other lookup on that path). A qualified spelling matched nothing, so the field value was emitted UNWRAPPED into a field whose declared type is Rc<T> -- not a style difference but a type error rustc reports as E0308, and one that no amount of correct declaration can compensate for. needs_box_wrapping read the same authored spelling for the same decision and is repaired with it. MEASURED, minimal, both arms in one fixture: the qualified consumer emitted `uri: QualspellUri \{` where the bare consumer emitted `uri: Rc::new(QualspellUri \{`, against one provider both consumers reference. WHY MAIN IS GREEN WITHOUT THIS: the measured v1 seed closure contains almost no qualified type reference, so an ordinary green regen exercises the bare arm only -- which is exactly why this witness authors the qualified arm rather than relying on the corpus to contain one. 4066 qualified dotted type references already exist corpus-wide (555 files, 2314 of them in src/v2) and enter the seed closure as v2 self-hosting advances, so the population that reaches this path grows with the roadmap. ZERO-DRIFT: qualified_last_segment is the identity on an unqualified name, so every bare spelling emits exactly as before -- receipt, a full required-regen over the 132-module subject drifted only v1_compiler_emit_rust.rs, this repair itself. DECLARED RESIDUE, not covered here and not claimed: a qualified reference to a zero-parameter ALIAS is still peeled to its target, and where that target lives in a THIRD module the peeled name reaches the output with no use-line (E0412). Located cause: a qualified reference parses as a module-projection spine, so it fails the NoConnective-and-childless guard on the alias-preserving branch of render_rust_fn_sig_type and never reaches the alias lookup at all. The fixture already carries that shape (QualspellFloor aliases into test.fixture.qualspell_target) so the next repair has its RED waiting. dissolve-on: never -- permanent regression control for the spelling-identity law. COST, MEASURED ON THE FIRST CI RUN RATHER THAN PREDICTED: as a single conjoined claim this witness was the floor worst single claim at 1.22GB RSS growth, against 0.12GB for the whole rest of the roster on the same-day main run -- both compile_dag_rust_emit_check calls are live inside one claim and each builds a corpus-wide scope. The two arms are therefore separate test fns: they are independent propositions (the RED and its regression control), a failure now names WHICH arm broke instead of one conjoined false, and each compile is evaluated and collected on its own. DESIGN section 6 bare-minimum-cost -- a proven cost-shape defect is fixed regardless of the realized n, and this one measured 10x the roster worst."

Expand Down
28 changes: 27 additions & 1 deletion dag/test/claim/runner_host_deploy_witness_test.dag
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@ module test.claim.runner_host_deploy
import std.logic { Bool }
import std.types { list_length }
import extdeps.exec.command { shell_command_render }
import extdeps.sudo.elevation { sudo_binary_path, sudo_non_interactive_flag }
import extdeps.systemd.systemctl { systemctl_program }
import gunbc.runner_host_deploy {
srv4_runner_host_deploy,
gunbc_ci_github_app,
Expand Down Expand Up @@ -87,6 +89,20 @@ test fn srv4_runner_app_from_secret_manager() -> Bool {
// the instances the roster names, one per slot, zero-padded and one-based. That relation is what
// would break if the two ever diverged, and it holds at any width. The name changes with it, since
// a row called _six_ that no longer asserts six is worse than either.
//
// THE INVOCATION CONJUNCT NAMED ITS PROGRAMS AND #8919 MOVED THEM UNDER IT. It read
// "'sudo' 'systemctl' 'enable' '--now'" -- correct against the hand-built argv this row was written
// for, and false the moment runner_enable_command_argv started routing through
// extdeps.systemd.systemctl systemctl_enable_now_command, which mints through the sealed
// argv_command with sudo_binary_path as the program and inserts sudo's non-interactive flag. The
// spelling was a THIRD authoring of facts extdeps.sudo.elevation and extdeps.systemd.systemctl
// already own, so it rotted exactly the way a re-spelling does (DESIGN section 3).
//
// The two conjuncts now cite those authorities instead of re-spelling them, and they are split
// because they assert different things: that activation ELEVATES non-interactively, and that it
// reaches systemctl's enable --now. `enable` and `--now` stay literal because they are systemctl's
// own operands, spelled inline by the builder rather than derived from any row -- so they remain
// discriminating, and a command that listed the units without the verb still fails here.
test fn srv4_enables_its_declared_runner_instances() -> Bool {
let names = runner_instance_names(deploy: srv4_runner_host_deploy)
let enable = match runner_activate_command(admission: admit_runner_activation(host_admission: admit_runner_host(deploy: srv4_runner_host_deploy), cache_ready: witness_ready_receipt(), pool_ready: witness_ready_pool())) {
Expand All @@ -101,7 +117,17 @@ test fn srv4_enables_its_declared_runner_instances() -> Bool {
s: enable,
pattern: concat("srv4-", runner_slot_index_suffix(index: srv4_runner_host_deploy.runner_count + 1)),
)
&& string_contains(s: enable, pattern: "'sudo' 'systemctl' 'enable' '--now'")
&& string_contains(
s: enable,
pattern: concat(
concat("'", sudo_binary_path as String),
concat("' '", concat(sudo_non_interactive_flag as String, "'")),
),
)
&& string_contains(
s: enable,
pattern: concat(concat("'", systemctl_program as String), "' 'enable' '--now'"),
)
}

data unenrolled_host_fixture: RunnerHostDeploy = RunnerHostDeploy {
Expand Down
2 changes: 1 addition & 1 deletion dag/test/fixture/qualspell_provider.dag
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
module test.fixture.qualspell_provider

data qualspell_provider_fixture_note: String = "Provider fixture for test.claim.qualified_spelling_identity_witness_test: one shared nominal RECORD (QualspellUri) and a HOLDER whose field declares it, which is the smallest pair that puts a record literal in a FIELD position whose declared type sits at the shared reference layer. No imports, so the witness closure stays minimal (witness-cost ruling, DESIGN open thread 2026-08-04). The names are deliberately unlike anything in the seed, so a homonym in the bare-name registry cannot satisfy the assertions by accident. SCOPE, learned by execution rather than assumed: this module stays self-contained because compile_dag_rust_emit_check compiles the probe against a restricted source set -- an earlier revision aliased into a THIRD fixture module and the check went red on the BARE control, which is the harness refusing the closure, not the emitter failing. The alias-peel class therefore has no witness here and is carried as declared residue in the claim note."
data qualspell_provider_fixture_note: String = "Provider fixture for test.claim.long.qualified_spelling_identity_witness_test (moved to the long/ home 2026-08-23, see gunbc.ci_layer_roots): one shared nominal RECORD (QualspellUri) and a HOLDER whose field declares it, which is the smallest pair that puts a record literal in a FIELD position whose declared type sits at the shared reference layer. No imports, so the witness closure stays minimal (witness-cost ruling, DESIGN open thread 2026-08-04). The names are deliberately unlike anything in the seed, so a homonym in the bare-name registry cannot satisfy the assertions by accident. SCOPE, learned by execution rather than assumed: this module stays self-contained because compile_dag_rust_emit_check compiles the probe against a restricted source set -- an earlier revision aliased into a THIRD fixture module and the check went red on the BARE control, which is the harness refusing the closure, not the emitter failing. The alias-peel class therefore has no witness here and is carried as declared residue in the claim note."

type QualspellScheme
= QualspellHttp
Expand Down
25 changes: 24 additions & 1 deletion src/v2/workflow/floor_expected_red.dag
Original file line number Diff line number Diff line change
Expand Up @@ -504,6 +504,26 @@ fn floor_expected_red_chunks() -> List<List<String>> {
// Mock-totality's 21 expected-red rows were stale-quarantined by the explicit-import
// closure in v2.test.lens_mock_totality. Keep the historical chunk rows for provenance,
// but exclude the now-green family from the live expected-red roster.
//
// THE THREE compile_accepted_unevaluable_program_control ROWS ARE EXCLUDED FOR THE OPPOSITE
// REASON, AND CHUNK 21 SAYS SO IN A SENTENCE EXECUTION REFUTES. That chunk's annotation reads
// "until it lands they are held here so that admission does not red main". Held-in-the-roster is
// exactly what reds main: the floor requires every ENROLLED identity to be observed among the
// EXECUTED claims, so an identity that is enrolled and never planned refuses the whole run with
// cause=ExpectedRedIdentityDidNotExecute. It is not a quiet parking spot. Measured twice, on the
// authoring PR's own run (32644795043, which was merged red) and again on gunbc#9031
// (32649496046), where it was the sole floor refusal once the ArgvCommand seal that had been
// masking it was repaired.
//
// The rows are correct and stay in chunk 21. What is wrong is only their LIVENESS: the file
// declares ReadsLiveTree, the DeclinedLiveTree arm declines it (declined_live=899 on that run),
// and the arm's deletion is still unmerged (gunbc#8977, gunbc#8982 both OPEN at the time of
// writing) -- so the enrolment was authored against a precondition that had not landed.
//
// RESTORATION TRIGGER, and it is a COUPLING someone must honour rather than a note: when either
// #8977 or #8982 lands and these identities become executable, DELETE these three exclusions in
// the same change. They are reds, so once they execute while excluded they count as ordinary
// failures and red the build -- the exclusion must not outlive the decline that motivated it.
fn floor_expected_red_is_live(name: String) -> Bool {
!(name == "v2.test.lens_mock_totality.cron_mock_totality.cron_mock_consumer_is_total_holds"
|| name == "v2.test.lens_mock_totality.cron_mock_totality.cron_mock_omitted_member_is_red_holds"
Expand All @@ -525,7 +545,10 @@ fn floor_expected_red_is_live(name: String) -> Bool {
|| name == "v2.test.lens_mock_totality.sec_edgar_mock_totality.sec_edgar_mock_consumer_is_total_holds"
|| name == "v2.test.lens_mock_totality.sec_edgar_mock_totality.sec_edgar_mock_omitted_member_is_red_holds"
|| name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_consumer_is_total_holds"
|| name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_omitted_member_is_red_holds")
|| name == "v2.test.lens_mock_totality.shell_mock_totality.shell_mock_omitted_member_is_red_holds"
|| name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_extra_argument_must_refuse_at_compile"
|| name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_missing_argument_must_refuse_at_compile"
|| name == "test.claim.compile_accepted_unevaluable_program_control.primitive_call_with_wrong_argument_type_must_refuse_at_compile")
}

fn floor_expected_red_roster() -> List<String> {
Expand Down
Loading