diff --git a/dag/gunbc/witness_deferral_freeze.dag b/dag/gunbc/witness_deferral_freeze.dag index fd15cdc399c..3d3015bbbf8 100644 --- a/dag/gunbc/witness_deferral_freeze.dag +++ b/dag/gunbc/witness_deferral_freeze.dag @@ -91,7 +91,7 @@ data witness_deferral_freeze_forward_rule_rung_drop: GuaranteeRungDrop = Guarant restoration_trigger: "BOTH halves: a cadence that actually executes offline-homed witnesses exists, so a green witness under such a path has a truthful admission row to write; AND a required run enters the discovery-corpus path, so refuse_unexecuted_deferred_witnesses can fire when it does not" } -data witness_deferral_freeze_shrink_log_note: String = "SHRINK LOG. The 701-identity / 152-entry figures the notes around this one quote are the FREEZE-POINT BASELINE and are deliberately not restated as the roster's current size — a hand-maintained live count is the change detector DESIGN section 5's oracle rule rejects, and the roster below is the authority for what the population is right now. This row records migrations OUT, which is the only direction permitted, so that the baseline stays legible as history rather than decaying into a false present-tense claim. 2026-08-19 — dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], 2 identities (witness_srv3_nbd_proxy_apply_observe_unimplemented_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_dissolves_via_host_effect_nbd_proxy_serve), DELETED not migrated and not exempted: host_effect_nbd_proxy_serve_dissolution_trigger dissolved (observe-side port/unit read-back grounded on gunbc.systemctl_is_active_read; actuate-side typed argv dispatch via gunbc.systemd_run_transient / gunbc.systemctl_stop_run retired the WitnessBin scaffolding), so the module's disposition became std.disposition.Terminal and the two witness functions were rewritten under new names (witness_srv3_nbd_proxy_apply_emit_artifact_transport_observe_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_is_terminal_via_host_effect_nbd_proxy_serve) that assert the grounded/Terminal behavior instead of the old stub/Scaffold behavior. The old identities no longer exist in the tree under those names, so their frozen rows are StaleFrozenPathDeferral and delete in this change rather than after it; this is a shrink, and the remaining functions at this entry are untouched. 2026-08-19 — 24 entries (dag/test/claim/ci_exclusion_proof_test.dag, dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial], dag/test/claim/interp_recorded_fixture_witness_test.dag, dag/test/claim/random_bytes_csprng_witness_test.dag, dag/test/claim/self_host_00_compile_behavioral_witness_test.dag, dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag, dag/test/claim/self_host_02_parse_behavioral_witness_test.dag, dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag, dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag, dag/test/claim/self_host_04_infer_behavioral_witness_test.dag, dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag, dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag, dag/test/claim/self_host_program_partition_behavioral_witness_test.dag, dag/test/claim/self_host_source_authority_behavioral_witness_test.dag, dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_host_complement_equals_eval_test.dag, src/v2/test/claim/execution/emit_host_variant_construct_equals_eval_test.dag, src/v2/test/claim/execution/emit_ingest_python_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_type_decl_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_typescript_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/floor_diff_observe_witness_test.dag, src/v2/test/claim/execution/proactive_verification_ledger_overlap_execution_test.dag), 38 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_expected_red's known-red roster (removable only by observing a pass) and path-deferred here as LegacyFrozenPathDeferral (declared never-executed) — a contradictory intersection, because the required floor already treats each of these identities as an executing, known-red subject, so their freeze classification was stale rather than load-bearing; a frozen row naming a witness the required floor already runs has no LegacyFrozenPathDeferral standing left to protect. Computed by joining floor_expected_red_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string), at commit 063a604e0099c56c3e0a1f72af60d7a6199d1f0b: 38 of 669 qualified freeze identities across 24 entries collided. All 24 entries carry an independently executing consumer already (WitnessHasExecutingConsumer via floor_expected_red), so retirement here removes no coverage — 15 entries had every one of their functions collide and are deleted whole; 9 entries had only some functions collide and keep their remaining, non-colliding functions frozen. A construction wall (expected_red_freeze_intersection, wired into run_required_floor in src/v1/stage0/src/cli_run.rs) now refuses this exact contradiction going forward: any future frozen row whose qualified identity re-enters floor_expected_red_roster fails the required floor with a located, counted refusal naming the exact colliding identities and the git head the collision was observed at, rather than silently coexisting. 2026-08-19 — src/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag, 4 identities, and src/v2/test/claim/execution/long/pick_ingested_probe_test.dag, 1 identity, DELETED as subsumed or duplicate coverage, none migrated and none exempted. add_arrow_eval_tokenize_holds, add_arrow_eval_parse_holds and add_arrow_eval_normalize_holds were the shallow steps of a staircase whose deepest step, add_arrow_eval_resolve_holds, cannot reach resolve unless all three stages accepted, so four stages were costing ten stage-runs across four frames to assert what one row asserts; the survivor reds on exactly the refusals they redded on and what is lost is which stage failed. add_arrow_eval_produced_add_body_executes_holds had a body byte-identical to add_arrow_eval_source_driven_add_executes_holds — and BOTH ARE CURRENTLY RED, which is stated rather than left for a reader to assume a green row was removed: main head 5ee2572 fails the pair identically, along with add_arrow_eval_direct_runtime_holds, add_arrow_eval_generality_executes_holds and add_arrow_eval_lazy_arm_branch_suppression_holds, the five identities floor_expected_red already documents as enrolled-and-correctly-red before this module relocated. The surviving twin carries the red; deleting a duplicate of a failing claim removes a second report of one failure, not the report of it. pick_probe_resolved_else_arm_has_magnitude_child_holds differed from its then-arm sibling only in an arm index over one source at one stage, and both arms are now asserted against one bound resolved module; both passed on main and the merged row passes. In every case the assertion survives on a row that keeps it; none of this coverage is relocated because none of it was ever separate. 2026-08-19 — src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag, 1 identity (dag_add_emit_add_fn_accepts_holds), DELETED as duplicate coverage, not migrated and not exempted: its whole body was a call to its sibling dag_add_emit_matches_serialize_holds, so it asserted nothing that sibling did not already assert and paid a second full emit-and-serialize crossing to assert it, each claim evaluating in its own frame. Deleting it removes a crossing and no fact. This is a shrink by deletion of the witness, and the coverage it named is not relocated because it was never separate from the sibling row that keeps it. 2026-08-11 — dag/test/claim/long/inert_lens_hygiene_witness_test.dag, 2 identities, DELETED not migrated and not exempted: the inert-lens census the two witnesses read is gone from the tree entirely, along with the v2.lens.inert_lens module, its two host builtins and the registry/contract rows that obligated it, so the witnesses have no subject to execute against. A frozen row naming a witness the tree no longer carries is a StaleFrozenPathDeferral refusal, which is why the row deletes in the same change rather than after it. This is a shrink by deletion of the subject, NOT by a cadence enrolling the rows — the coverage those two witnesses provided is not relocated anywhere and the scope narrowing is declared in DESIGN §6. 2026-08-06 — src/v2/test/claim/long/realization_vocabulary_containment_witness_test.dag, 1 identity, MIGRATED not exempted: TS-0/LANG-2 enrolled realization_vocab_live_corpus_receipt_holds on falsifier_substrate_long_lane_rows (FalsifierSubstrateLongLane cadence), so the freeze row deletes and the live-corpus receipt executes on the scheduled lane. 2026-08-05 — src/v2/test/claim/long/orchestration_while_emit_test.dag, 14 identities, MIGRATED not exempted: the file returned to src/v2/workflow/orchestration_while_emit_test.dag, the per-PR-discovered path it occupied before gunbc#7098 relocated it, so its rows now classify as WitnessHasExecutingConsumer and the freeze row had to go — a row naming a witness the tree no longer carries at that entry is a StaleFrozenPathDeferral refusal, and its diagnostic says to delete it in the change that moved the witness. Measured eval justifying the return, on a load-average-28 host: 94 / 54 / 36 / 8 ms per witness against the 5000ms gunbc_ci_fast_lane_witness_eval_budget; those are wall figures against a thread-CPU budget, and cpu <= wall for one witness thread, so the bound runs the safe way. Rationale and the receipt live with the witness in orch_while_unfreeze_note." +data witness_deferral_freeze_shrink_log_note: String = "SHRINK LOG. The 701-identity / 152-entry figures the notes around this one quote are the FREEZE-POINT BASELINE and are deliberately not restated as the roster's current size — a hand-maintained live count is the change detector DESIGN section 5's oracle rule rejects, and the roster below is the authority for what the population is right now. This row records migrations OUT, which is the only direction permitted, so that the baseline stays legible as history rather than decaying into a false present-tense claim. 2026-08-24 — 2 entries (dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial]), 4 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_route_gap floor_route_gap_roster — a typed receipt that the required floor EXECUTED the identity and could not route it to its subject — and path-deferred here as LegacyFrozenPathDeferral, which declares the identity has no executing consumer. Both claims cannot hold of one identity. The contradiction is a property of main standalone and NOT a branch or merge artifact, which is stated explicitly because an earlier revision of this row cited a merge head and would have sent a future reader looking for a branch that no longer exists: at main head 8ab8a8e75af37a1f8b15021048ec3c5f6c98beb6 all four qualified identities are present in floor_route_gap_chunk_04, one occurrence each, having been added there when the three unconditional shell.Exec mock arms were deleted (gunbc#9049), while the frozen rows date from gunbc#7804's bulk sweep of legacy path-only debt. Computed the same way as the 2026-08-19 sweep below — joining floor_route_gap_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string) — 4 of 614 qualified freeze identities across 2 entries collided, against a route-gap denominator of 110 enrolled rows spanning every floor_route_gap_chunk_* function; the join is empty after this change, so the check is discriminating rather than vacuously green. Run 32761519653 observed the resulting RouteGapFreezeIntersection refusal. The typed refusal proves required-floor consumption to the effect boundary, so the LegacyFrozenPathDeferral rows are stale evidence rather than a live exemption; the route-gap receipts stay, because removing them instead would delete a true measurement to preserve a false classification and silently un-count four real no-route gaps. Nothing is rehomed by this retirement and no cadence receives it — the witnesses already execute on the required floor — so the disposition is DELETED, matching the 2026-08-19 38-identity sweep below, which is the same shape: a frozen row naming a witness an executing roster already consumes. Both entries are partial and every non-colliding sibling remains frozen. 2026-08-19 — dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], 2 identities (witness_srv3_nbd_proxy_apply_observe_unimplemented_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_dissolves_via_host_effect_nbd_proxy_serve), DELETED not migrated and not exempted: host_effect_nbd_proxy_serve_dissolution_trigger dissolved (observe-side port/unit read-back grounded on gunbc.systemctl_is_active_read; actuate-side typed argv dispatch via gunbc.systemd_run_transient / gunbc.systemctl_stop_run retired the WitnessBin scaffolding), so the module's disposition became std.disposition.Terminal and the two witness functions were rewritten under new names (witness_srv3_nbd_proxy_apply_emit_artifact_transport_observe_refuses_fail_closed, srv3_nbd_proxy_serve_realize_layer_is_terminal_via_host_effect_nbd_proxy_serve) that assert the grounded/Terminal behavior instead of the old stub/Scaffold behavior. The old identities no longer exist in the tree under those names, so their frozen rows are StaleFrozenPathDeferral and delete in this change rather than after it; this is a shrink, and the remaining functions at this entry are untouched. 2026-08-19 — 24 entries (dag/test/claim/ci_exclusion_proof_test.dag, dag/test/claim/deploy_access_privilege_witness_test.dag [partial], dag/test/claim/host_effect_apply_witness_test.dag [partial], dag/test/claim/interp_recorded_fixture_witness_test.dag, dag/test/claim/random_bytes_csprng_witness_test.dag, dag/test/claim/self_host_00_compile_behavioral_witness_test.dag, dag/test/claim/self_host_01_tokenize_behavioral_witness_test.dag, dag/test/claim/self_host_02_parse_behavioral_witness_test.dag, dag/test/claim/self_host_03_ingest_behavioral_witness_test.dag, dag/test/claim/self_host_03_resolve_behavioral_witness_test.dag, dag/test/claim/self_host_04_infer_behavioral_witness_test.dag, dag/test/claim/self_host_materialization_carriers_behavioral_witness_test.dag, dag/test/claim/self_host_program_assembly_behavioral_witness_test.dag, dag/test/claim/self_host_program_partition_behavioral_witness_test.dag, dag/test/claim/self_host_source_authority_behavioral_witness_test.dag, dag/test/claim/srv3_host_effect_apply_witness_test.dag [partial], src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_host_complement_equals_eval_test.dag, src/v2/test/claim/execution/emit_host_variant_construct_equals_eval_test.dag, src/v2/test/claim/execution/emit_ingest_python_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_type_decl_round_trip_test.dag [partial], src/v2/test/claim/execution/emit_ingest_typescript_same_language_round_trip_test.dag [partial], src/v2/test/claim/execution/floor_diff_observe_witness_test.dag, src/v2/test/claim/execution/proactive_verification_ledger_overlap_execution_test.dag), 38 identities, DELETED not exempted: these identities were simultaneously enrolled in v2.workflow.floor_expected_red's known-red roster (removable only by observing a pass) and path-deferred here as LegacyFrozenPathDeferral (declared never-executed) — a contradictory intersection, because the required floor already treats each of these identities as an executing, known-red subject, so their freeze classification was stale rather than load-bearing; a frozen row naming a witness the required floor already runs has no LegacyFrozenPathDeferral standing left to protect. Computed by joining floor_expected_red_roster against this file's frozen_path_deferrals, qualifying every frozen row through its own entry's module line (not its path string), at commit 063a604e0099c56c3e0a1f72af60d7a6199d1f0b: 38 of 669 qualified freeze identities across 24 entries collided. All 24 entries carry an independently executing consumer already (WitnessHasExecutingConsumer via floor_expected_red), so retirement here removes no coverage — 15 entries had every one of their functions collide and are deleted whole; 9 entries had only some functions collide and keep their remaining, non-colliding functions frozen. A construction wall (expected_red_freeze_intersection, wired into run_required_floor in src/v1/stage0/src/cli_run.rs) now refuses this exact contradiction going forward: any future frozen row whose qualified identity re-enters floor_expected_red_roster fails the required floor with a located, counted refusal naming the exact colliding identities and the git head the collision was observed at, rather than silently coexisting. 2026-08-19 — src/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag, 4 identities, and src/v2/test/claim/execution/long/pick_ingested_probe_test.dag, 1 identity, DELETED as subsumed or duplicate coverage, none migrated and none exempted. add_arrow_eval_tokenize_holds, add_arrow_eval_parse_holds and add_arrow_eval_normalize_holds were the shallow steps of a staircase whose deepest step, add_arrow_eval_resolve_holds, cannot reach resolve unless all three stages accepted, so four stages were costing ten stage-runs across four frames to assert what one row asserts; the survivor reds on exactly the refusals they redded on and what is lost is which stage failed. add_arrow_eval_produced_add_body_executes_holds had a body byte-identical to add_arrow_eval_source_driven_add_executes_holds — and BOTH ARE CURRENTLY RED, which is stated rather than left for a reader to assume a green row was removed: main head 5ee2572 fails the pair identically, along with add_arrow_eval_direct_runtime_holds, add_arrow_eval_generality_executes_holds and add_arrow_eval_lazy_arm_branch_suppression_holds, the five identities floor_expected_red already documents as enrolled-and-correctly-red before this module relocated. The surviving twin carries the red; deleting a duplicate of a failing claim removes a second report of one failure, not the report of it. pick_probe_resolved_else_arm_has_magnitude_child_holds differed from its then-arm sibling only in an arm index over one source at one stage, and both arms are now asserted against one bound resolved module; both passed on main and the merged row passes. In every case the assertion survives on a row that keeps it; none of this coverage is relocated because none of it was ever separate. 2026-08-19 — src/v2/test/claim/execution/dag_add_emit_round_trip_test.dag, 1 identity (dag_add_emit_add_fn_accepts_holds), DELETED as duplicate coverage, not migrated and not exempted: its whole body was a call to its sibling dag_add_emit_matches_serialize_holds, so it asserted nothing that sibling did not already assert and paid a second full emit-and-serialize crossing to assert it, each claim evaluating in its own frame. Deleting it removes a crossing and no fact. This is a shrink by deletion of the witness, and the coverage it named is not relocated because it was never separate from the sibling row that keeps it. 2026-08-11 — dag/test/claim/long/inert_lens_hygiene_witness_test.dag, 2 identities, DELETED not migrated and not exempted: the inert-lens census the two witnesses read is gone from the tree entirely, along with the v2.lens.inert_lens module, its two host builtins and the registry/contract rows that obligated it, so the witnesses have no subject to execute against. A frozen row naming a witness the tree no longer carries is a StaleFrozenPathDeferral refusal, which is why the row deletes in the same change rather than after it. This is a shrink by deletion of the subject, NOT by a cadence enrolling the rows — the coverage those two witnesses provided is not relocated anywhere and the scope narrowing is declared in DESIGN §6. 2026-08-06 — src/v2/test/claim/long/realization_vocabulary_containment_witness_test.dag, 1 identity, MIGRATED not exempted: TS-0/LANG-2 enrolled realization_vocab_live_corpus_receipt_holds on falsifier_substrate_long_lane_rows (FalsifierSubstrateLongLane cadence), so the freeze row deletes and the live-corpus receipt executes on the scheduled lane. 2026-08-05 — src/v2/test/claim/long/orchestration_while_emit_test.dag, 14 identities, MIGRATED not exempted: the file returned to src/v2/workflow/orchestration_while_emit_test.dag, the per-PR-discovered path it occupied before gunbc#7098 relocated it, so its rows now classify as WitnessHasExecutingConsumer and the freeze row had to go — a row naming a witness the tree no longer carries at that entry is a StaleFrozenPathDeferral refusal, and its diagnostic says to delete it in the change that moved the witness. Measured eval justifying the return, on a load-average-28 host: 94 / 54 / 36 / 8 ms per witness against the 5000ms gunbc_ci_fast_lane_witness_eval_budget; those are wall figures against a thread-CPU budget, and cpu <= wall for one witness thread, so the bound runs the safe way. Rationale and the receipt live with the witness in orch_while_unfreeze_note." data witness_deferral_freeze_purpose_frontier_note: String = "WHAT THIS FREEZE DELIBERATELY DOES NOT CARRY, so its coverage is not overread. A frozen row records IDENTITY only — that this exact (entry, function) was already deferred by path policy when the wall landed. It records no purpose, no measured cost, and no consumer, because it has none: the whole point of the freeze is that these 701 identities (152 entries, measured at the freeze point) were admitted without any of the three. The purpose taxonomy (which boundary, population, external effect, or resource contract justifies the size) and the per-witness cost envelope are the NEXT slice, and a frozen row is the debt marker that one is owed. @@ -134,8 +134,7 @@ data frozen_path_deferrals: List = [ functions: [ "witness_modeled_unprivileged_fixture_is_denied", "witness_unprivileged_mutation_refused_before_shell", - "witness_unprivileged_mutation_directive_is_refused_terminal", - "witness_privileged_fixture_mutation_applies" + "witness_unprivileged_mutation_directive_is_refused_terminal" ] }, FrozenPathDeferral { entry: "dag/test/claim/direct_rust_door_write_compile_witness_test.dag", functions: ["direct_rust_door_emit_write_compile_holds"] }, @@ -149,11 +148,9 @@ data frozen_path_deferrals: List = [ FrozenPathDeferral { entry: "dag/test/claim/host_effect_apply_witness_test.dag", functions: [ - "witness_shell_on_host_success_converges", "witness_redfish_on_bmc_unimplemented_fails_closed", "witness_redfish_on_hostos_typed_mismatch", "witness_shell_on_bmc_typed_mismatch", - "witness_oneshot_policy_terminal_not_converged", "witness_incompatible_is_refused_terminal", - "witness_converged_is_settled", + "witness_incompatible_is_refused_terminal", "witness_ssh_empty_script_fails_closed", "witness_identity_evidence_derives_oneshot_drive", "witness_converge_loop_evidence_derives_converge_drive",