Repository navigation
Delete the plan/walk surface nothing could reach (claim_executor 21,366 -> 11,508) - #9228
Merged
Merged
Conversation
…symbols it was importing to do it claim_executor: 21,366 -> 11,508 lines. Zero dead-code warnings, zero errors, fmt clean, and the two live modes verified by execution. WHY THIS IS A REACHABILITY CUT AND NOT AN OCCUPANCY ONE. run() required --plan-entry after every --required-* arm returned, and nothing supplies --plan-entry: not a workflow, not a hook, not an emitted yml. The plan function it defaulted to named src/v2/workflow/ci_floor_plan.dag, which the 2026-08-15 floor cut deleted. So the plan walk, the batch executor, the coordinator/worker protocol, the scoped-request machinery, the perturb re-walk, the falsifier failure-class helpers and their terminal reporting were not quiet guards that happened to be empty -- their governing MECHANISM was removed, and no input any caller can author reaches them. DESIGN's reachability-read-as-occupancy row asks three questions; this population answers no to the first two, not merely to the third. The coordinator is the sharpest case: maybe_run_floor_coordinator is the first thing main() does, and it returns None immediately unless --plan-function names a plan entry that does not exist. It spawned this binary as its own child with --floor-worker-role/--scoped-batch-id, from an arm that never armed. WHAT THE CENSUS SURFACED, which is the point of cutting at the root rather than the leaves. Removing the walk left 251 items unreferenced; deleting those left 27 cli_run imports unused -- active_workset_admit, the heartbeat feed, the discovery roster snapshot, the histogram/percentile projections, install_floor_compile_clean_receipt and the rest. That is a measurement about cli_run.rs, not about this file: a quarter of the seam between the two existed only to feed machinery with no caller. WHAT REMAINS AND IS PROVEN BY EXECUTION (release binary, four cases): --required-ci the one mode witnesses.yml invokes --verify-build-artifacts fleet-converge.yml, both jobs no mode -> exit 2, typed refusal naming the live modes --plan-entry -> exit 2, unknown argument --verify-build-artifacts on a present binary -> exit 0 --verify-build-artifacts on an absent one -> exit 1, fail-closed The last pair is the discriminating red: the mode's whole purpose is refusing a 'successful' build that produced a missing or zero-byte artifact, so a green without its red would establish nothing. The no-mode arm REFUSES rather than falling through to a default. An argv this binary no longer understands must stop the line; a silent success would be the absorbing fallback one level up from the machinery just deleted. WHAT THIS DOES NOT CLAIM. The .dag residue is NOT repaired here and is named rather than left to be rediscovered: gunbc.cli_invoke still builds --plan-entry/--plan-function/--notice-title argv (dead transport -- no workflow contains those words), PlanFunction survives in ci_spec/cli_services with its witness, and src/v2/test/fixture/walk_plan_stage/ is a fixture family whose only execution route was the recipes this commit deletes. That family has eight external touchpoints including a Rust integration test, so it is its own census and its own cut, not a tail this one can sweep. Nothing in CI executed any of it before this commit or after it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review on #9228 named two (FloorBatchClampAuthority, ResolvedFloorBatchClamp) as the ones it spot-checked. There were five: ParsedRunnableProfile, ProcessTermination and ScopedExecutionRequest carry the same shape. Swept by pattern rather than by the two cited, because a cosmetic residue found by inspection is a population, not a list -- fixing only the named two would leave three identical stubs behind and read as though the class had been handled. Each is the shell of an impl whose every method was deleted as unreachable. The types themselves are still constructed and are unaffected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…census A workflow_dispatch job with ZERO runs in its entire existence, its .dag emitter (286 lines), its GeneratedArtifact registration, the claim_executor mode, and the 266-line cli_run census that had no other consumer. WHY THE WHOLE CHAIN AND NOT JUST THE FLAG. The mode was the census's only caller and the workflow was the mode's only caller, so deleting any one link would have left the other two as an authority for a fact nothing asks. The fail-closed census did the finding: removing the GeneratedArtifact variant surfaced five more sites (the roster list, the commit-policy arm, the equality arm, the emit import and the yml-parse arm) that a name-grep of the workflow path alone would have missed. THIS IS A DECLARED CAPABILITY DROP, not a dead-code sweep, and saying so is the point of the entry. WHAT IS GONE: the only route to a located corpus-wide type-judgment population -- the blocking/advisory/unclassified partition over the required run's own subject, with its planted control. DESIGN 4b names exactly this gap in the other direction: the advisory residue is computed on every required run and counted by nothing, and a frontier whose deficit frequency is unobservable never ranks for climbing. That argument is why the mode was built. WHY IT GOES ANYWAY: it was never executed once. An instrument nobody has ever run is specification-without-execution, not coverage, and a workflow_dispatch job nobody dispatches cannot be the thing that makes a frequency observable. Keeping the flag while deleting the workflow would be worse -- a surviving mode no workflow invokes guards nothing and would be cited as though it did. POPULATION: one capability, the corpus type-judgment measurement. PREVIOUS STATE: reachable by manual dispatch, never reached. TEMPORARY STATE: no route. RESTORATION TRIGGER: the measurement returns as a QUERY over the build/test target graph -- the population is a property of what the required run compiled, which is exactly what a target-graph query answers -- rather than as a mode on a binary this program is deleting. It does not return as a flag. NOT CLAIMED: this does not repair src/v1/stage0/src/bin/infer_semantics_witness.rs, which #8952 (ffb0170) broke by adding TypeEnv.authored_import_names without updating six initializers there. That binary is in fleet-converge.yml's build list and does not compile on main today; it is untouched here and is not this cut's to fix. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cli_run tests review 55847 caught Review 55847 found four tests in cli_run.rs still referencing corpus_judgment_* symbols the census deletion removed. It was right, and it had found one end of a larger population: 542 test functions across the two files tested machinery this branch deleted. claim_executor 11,380 -> 6,270. WHY THE REVIEWER SAW FOUR AND NOT 546. Two masks, and the second is the one worth recording. My own verification ran `cargo check --bin claim_executor` WITHOUT `--tests`, so a test module referencing a deleted symbol produced no diagnostic at all -- the deletion was verified against a target that does not compile tests. Then, when I did run --tests, the seed's lib failed FIRST on main's unrelated TypeEnv breakage, and 526 downstream errors were masked behind that one. A masked run and a clean run rendered identically: 526 errors and 1 error look like progress rather than a different question being answered. DESIGN's execution-provenance row names exactly this, and it cost two wasted sweeps here. DELETED SURGICALLY, NOT WHOLESALE, and the distinction is load-bearing. The obvious cut was `mod tests` entire -- 5,514 lines, 518 of the 526 errors. It would have been wrong: `verify_build_artifacts_reds_on_zero_byte` lives in that module and is the discriminating RED for a mode fleet-converge.yml invokes twice. So the cut deletes only test functions that FAIL TO COMPILE because their subject is gone, iterated to a fixed point against the compiler. 38 tests survive, including all four verify_build_artifacts controls (accepts / zero-byte / missing / empty-arglist) and the five attempt_identity refusals. That is the enumerate-before-deleting rule applied to a test module: a module is deleted for one reason and takes everything in it unless its contents are enumerated first. The compiler did the enumeration. WHAT IS NOT CLAIMED. src/v1/stage0/src/bin/infer_semantics_witness.rs is still broken by #8952 (six TypeEnv initializers) and is untouched here; it is in fleet-converge.yml's build list and does not compile on main. The one-line lib fix at cli_run.rs is present because without it nothing on this branch can compile tests at all -- deep-ram-742 ships the same repair in #9222 and the duplicate is deliberate, not a fork: identical text, and whichever lands second merges clean or drops out. .gitattributes loses its corpus-type-judgment merge row, which review 55847 also flagged. That row is DERIVED from the artifact roster this branch already trimmed, so the committed file was stale against its own authority rather than carrying an independent fact. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e time
Review 55875 is correct and the finding is the important kind -- not a leftover,
a REACHABLE MUTATING PATH behind a deletion I had claimed was complete.
WHAT I GOT WRONG. main() read std::env::args() ITSELF and dispatched
maybe_run_floor_coordinator before run() parsed anything. So deleting
--plan-function from run()'s parser did nothing to the coordinator's
reachability. My earlier claim that the coordinator "returns None immediately
unless --plan-function names a plan entry that does not exist" described the
guard correctly and the DISPATCH not at all: the guard tests argv, and argv still
carried the flag.
WHY IT WAS WORSE THAN BEFORE THIS BRANCH, which is what makes it a defect rather
than an incomplete cut. With --plan-function deleted from one parser and live in
the other, the flag answered `unknown argument` for every value EXCEPT
gunbc_ci_floor_plan -- the one value that ran the entire coordinator. And that
path is not inert: it create_dir_all's a receipt directory, remove_file's the
worker-observation receipt, the scoped-execution requests and the phase journal,
arms a scoped receipt and spawns workers, all before any refusal could fire. A
deletion that leaves the single most destructive entry point as the only reachable
one is the opposite of fail-closed.
THE LESSON IS THE CUT'S, NOT THE COORDINATOR'S: a flag is not deleted when one of
two parsers stops reading it. The repair is at the root -- main() no longer reads
argv at all, run() is the only thing that does -- and the census then took the
worker/scoped-request machinery with it: 6,275 -> 5,069 lines, 57 further test
functions whose subjects went, iterated to a joint fixed point over errors and
dead code.
PROVEN BY EXECUTION, on the exact invocation the review named:
claim_executor --plan-function gunbc_ci_floor_plan --source-root dag
-> "unknown argument: --plan-function", EXIT=2, and no receipt file created
--verify-build-artifacts on a present binary -> 0
--verify-build-artifacts on an absent one -> 1
The negative control matters here specifically: the bug was that a mutating path
ran before the refusal, so "it refuses" is only half the claim -- the other half
is that nothing was written on the way to refusing.
claim_executor is now 5,069 lines against 21,366 on main.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… warnings and my check did not CI red at bda1331, all three jobs, one root cause: ExitStatus, std::time::Instant, build_floor_discovery_request and verify_floor_discovery_terminal_for_coordinator lost their last users when the coordinator and its worker machinery went, and the required build compiles with -D warnings, so an unused import is an ERROR there. `floor` failed identically; `witnesses` is only the gate that reports both. THIS IS THE THIRD TIME ON THIS BRANCH THAT A CHECK WAS GREEN AND THE CLAIM WAS WRONG, and it is the same defect each time: verifying a deletion against a target that cannot observe its dependents. --bin without --tests could not see 526 orphaned test references. A broken lib masked those behind one error. And a bare cargo check cannot see an unused import, because unused-imports is a WARNING until -D warnings makes it fatal -- so the instrument I was steering by was strictly weaker than the one that gates merge. The repair is to use the gating instrument, and to PROVE it is the one running rather than assume the flag arrived. Planted control, executed: with RUSTFLAGS="-D warnings" forwarded (ctrl-build prints `forwarding env: RUSTFLAGS`), an added `use std::collections::BTreeSet;` produces `error: unused import`, not a warning. The clean result on the real tree is therefore load-bearing rather than a flag that silently never reached rustc. No behavior change: four import names, zero call sites. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ch was masking this branch's test-target observation
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 25, 2026
… test target main inherited Rebuilt on current main rather than merged into it. The old branch shared three commits with #9228 and conflicted in twelve hunks where "ours" was a pre-deletion snapshot -- hand-resolving that risks silently restoring code #9228 had just deleted, so the two intentional changes were replayed onto main instead. Force-push is the honest vehicle here; a merge commit would have carried a resolution nobody could audit. THE ENROLMENT IS THE POINT, and it is a climb rather than a cut. run_required_v2_emission_selftest -- the red fixture that must be refused on the annotation cause and the green fixture that must emit -- was reachable ONLY through a standalone flag no workflow invoked. So the required run's v2-emission phase ran a producer whose REFUSAL had never once been shown to fire; a green established that the emitter emitted, not that it still refuses what it must. DESIGN 4b(4): a class's discriminating RED and positive control stay ENROLLED as the evidence the rung is real. Unenrolled evidence is not weaker evidence, it is none. It now runs inside the phase, ahead of the producer, and a failure lands in phase_failures like any other. Measured before enrolling: passes, about a second. The standalone flag goes in the same motion -- two routes to one fact, and only the enrolled one executes. TWO MODES DELETED, and only two: - --measure-cgroup-peak: its own comment names the `rust_tests` job as its caller. That job was deleted. An orphan whose stated consumer is gone. - --required-cited-symbol: DESIGN's 2026-08-23 row already declares this drop and states the surviving flag guards nothing, with a restoration trigger putting the wall at ingestion. Deleting the flag agrees with that row rather than leaving a mode that reads as coverage. KEPT AGAINST THIS PROGRAM'S OWN BIAS: --heads-reading-differential and the three --behavioral-receipt-* modes are INSTRUMENTS with entry points, not gates. DESIGN's 2026-08-24 ruling is that a measurement worth re-deriving is worth an entry point. The target-model lane confirms both shapes they need are expressible (addressable but absent from the //:required roster; a differential needs its own TestStanding arm rather than the Bazel status arm, which carries only PASSED/FAILED and would erase the divergence). They migrate; they do not get rescued. ALSO REPAIRS WHAT MAIN INHERITED. #9228 merged before its last commit landed, so main carries four errors in claim_executor's TEST target: an orphaned witness_walk_flags_tests module and a cfg(test) classify_witness_expectations helper over three deleted types, plus seven dead test helpers and the imports the cited-symbol deletion orphaned. CI cannot see these -- the required run compiles --bin, never --tests. EVIDENCE, both controls run rather than one: - transport: ctrl-build reports `forwarding env: RUSTFLAGS`, so -D warnings reached rustc. - subject: a planted `super::deliberately_absent_symbol_zzz()` produces its exact diagnostic under this branch's own --tests invocation, proving test modules entered the observed population. Clean is therefore a measurement, not a silence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 26, 2026
CI on 45270ab: both lanes died at "Build the witness fold" with the lane steps SKIPPED, so nothing was checked -- one compile failure reported three times, not three failures. error: unused imports: `make_eval_context`, `resolve_entry_graph_shared`, and `run_value` error: unused imports: `ExecutionMode`, `InterpContext`, and `Value` error: could not compile `v1-compiler` (bin "claim_executor") due to 2 previous errors NEITHER BRANCH HAS THIS DEFECT ALONE. main's #9228 ("Delete the plan/walk surface nothing could reach", claim_executor 21,366 -> 11,508) removed the last callers of all six; this branch kept the import list. The imports go dead only in the merge, and CI evaluates the merge ref, which is why the head built clean here and failed there. Every surviving use is fully qualified (v1_compiler::cli_run::make_eval_context), and `Value` is re-imported locally at its one use site, so the removals are safe. TWO DEFECTS IN MY OWN INSTRUMENT, named because both fail toward a green: 1. CI builds with -D warnings and the workflow never says so -- actions-rust-lang/setup-rust-toolchain@v1.16.0 sets RUSTFLAGS: -D warnings by default. Local dispatches built without it, so unused imports were warnings here and errors there. Reproduced with RUSTFLAGS forwarded: BUILD-RC=0. 2. My build checks grepped `^error`, but cargo emits ANSI escapes, so the real line is \e[1m\e[91merror and never matches at column 0. Every "no errors" I reported from those dispatches read a filter that COULD NOT MATCH AN ERROR. That is the worse of the two: it would have hidden any compile failure, not just this class. VERIFIED ON THE MERGED TREE, under CI's own strictness: cargo build --release --bin claim_executor --bin gunbc, RUSTFLAGS=-D warnings rc=0 claim_executor --required-regen first_generation_equal=true, no drift main_wet x2, all three projections byte-IDENTICAL before and after: ba373e57... DESIGN.md 26148967... dag/gunbc/stage0_crate_layout_generated.dag 698a5209... src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs so the text-merged DESIGN.md IS the projection of the merged authorities and owes no regeneration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
added a commit
that referenced
this pull request
Aug 26, 2026
… integrity, the cited-symbol wall, and module authorship facts on ONE construction, as DESIGN's two next-rung triggers require, instead of three corpus walks (#9211) * wip: ingestion-time per-module declaration index * declaration index: debt roster, mode deletion, seed-growth carrier, DESIGN rows * The kernel-type escape is admitted by the seed, so count it instead of hiding it v1.compiler.resolve get_exported_names appends every kernel_type_set key to every module's export surface, so `import m { Int }` is admitted whatever `m` declares. Measured against the installed compiler: a module whose whole body is one fn returning Int, imported as `{ Int, String, Bool }`, compiles to 6 files with 0 diagnostics -- readable because the same root with a bogus member refuses with a located MissingExport. The index mirrored that with a bare `continue`, which zeroes the deficit's frequency by construction and is why nothing ever ranked it for repair. It cannot be refused here: editing get_exported_names is NewLanguageBehavior and the v1 freeze refuses it. So it is now counted as import_members_kernel_named and printed beside every other denominator. Kernel-named and declared are independent axes: over std.types, five of the eight keys are genuinely declared (Bool, Secret, Json, Unit, Bytes) and three are not (Int, String, Float). The predicate splits them by asking import_surface_has first, and the fixture now asserts that behaviour rather than leaving it to the ordering. Also records why the authorship arm is not a second MandatoryTagRegion: that door does not fire on the gunbc compile path, measured at 5 files 0 diagnostics against a positive control. And answers the debt contract's four conditions, including the two-directional typed disposition that separates 'repaired the citation' from 'deleted a row to buy a green'. * Scope the debt roster to the corpus it is a fact about, and make its own red authorable (review 55817) index_findings folded in citation_debt_findings, which joins the 38-row production roster against whatever index it is handed. A fixture tree holds a handful of probe.* modules, so all 38 rows were trivially absent and every fixture received 38 CitationDebtRowStale findings it never planted. Measured: 1 passed, 8 failed -- every planted-red and every positive control in the file, i.e. the whole of this change's DESIGN 4b evidence, was non-executing. The repair is a denominator fix rather than a gate. The four index-derived arms ask questions about the modules in front of them and are meaningful over any tree; the debt roster is a fact about ONE corpus. So it moves to corpus_findings, which the required run and the standalone sweep call, and index_findings keeps the four. Gating the arm on a corpus-shape signal was the other available repair and would have been a smuggled heuristic (DESIGN 4). The arm's own red was also unauthorable, which the review did not say and which is the finding underneath it: the roster was read from inside the function, so no fixture could hand it one. The join now takes its roster as a parameter and both directions of the contract are planted -- a row whose citation still refuses is live and suppresses that citation's finding, a row whose citation stopped refusing is spent and refuses by name -- plus a regression control asserting the arm is absent from index_findings and present in corpus_findings. * Close the class the review found one instance of: both rosters are parameters, defaulting empty review 55817 found citation_debt_findings reading PRE_EXISTING_CITATION_DEBT from module scope, which made its own RED unauthorable. Asking the same question of the other four arms found a second instance, and a worse one: cited_symbol_findings SUPPRESSED citations against the same constant. A spurious refusal is loud; a spurious suppression is a citation the wall quietly declines to judge, so that arm could have stopped enrolling an entire class with every fixture green. Both rosters are now parameters and both default to EMPTY rather than the production constant, so index_findings judges every citation in whatever tree it is handed and the roster is reachable from exactly one place, corpus_findings. This also corrects an assertion I added in the previous commit: it claimed an enrolled debt row suppresses its citation's finding while calling index_findings, which reads the production roster and does not contain the fixture's row. It now uses the parameterized form and pairs it with the empty-roster case, because 'suppressed' means nothing unless the same tree refuses when unenrolled. The other two arms were checked and are not this class: import_member_findings reads kernel_type_set, a language fact whose behaviour the fixture exercises with a real kernel name, and lens_authorship_findings reads the decl name it checks for. Both REDs are authorable. * Close the seam the repair created, name the empty-default rule, fix two fixture bugs SEAM: both rosters now enter from one place, corpus_findings, which makes the WIRING a fact needing evidence -- unreachable-from-index_findings is proven by construction, but reachable-from-corpus_findings was an assertion about a call site. Pass an empty roster there and the suppression arm would be perfectly evidenced at the fixture boundary and silently disabled where it matters. corpus_findings_is_wired_to_the_production_suppression_roster declares a module the production roster names and requires the same tree refused unenrolled and suppressed enrolled. RULE: a policy roster passed as a parameter defaults to the IDENTITY ELEMENT OF THE JUDGMENT, never to the production value. Empty means judge everything, the strictest answer, so a forgetful caller gets MORE refusals. Defaulting to the production roster would give a forgetful caller silent suppression -- the defect the parameter exists to close, reintroduced through the default. FIXTURE BUGS, both mine, both found by execution rather than by reading: - kernel_named_counter_splits_declared_from_undeclared authored its declares-nothing module with the wrong module header, so the import target did not exist and the claim was skipped as target-absent: counted 0, expected 1. - the same fixture used a single-variant coproduct, which needs a leading pipe; it now uses a two-variant form that parses unambiguously. - a_debt_row_whose_citation_still_refuses_is_live asserted suppression through index_findings, which reads no roster (fixed in the previous commit). * Every planted red asserts its own plant is well-formed before the guard's verdict Two fixture defects in this file produced EXACTLY the observation a broken guard produces: wrong module header -> import target absent -> claim SKIPPED -> no finding single-variant coproduct -> parse question -> not admitted -> no finding A malformed plant and a broken guard are indistinguishable at the assertion, so 'no finding' was a three-way ambiguity -- fixture malformed, plant never reached, guard broken -- and the repair pressure points at the production predicate. That is how a correct guard nearly got 'fixed' to satisfy a bad fixture. It is the not-applicable-versus-malformed conflation DESIGN names, arrived at from the fixture side: SKIPPED and ADMITTED are different states and the assertion could not see the difference. plant / plant_declares / plant_import_target_resolves / plant_cites assert the fixture is well-formed and that the claim REACHED the admit-or-refuse decision, before any assertion about the verdict. Then the guard's answer is the only remaining variable, and a failure says which of the three it was. * The corpus run found the roster's own prose false and one row's field wrong MEASURED, one dispatch, 3993 files parse-clean: modules=3993 declared=76851 import_members=80076 citations=1496 debt=41 in_fixtures=161 outside_index=134 kernel_named=1944 lens_modules=71 Two defects, both in the inherited roster, both found by running the wall rather than by reading it. 1. THE PROSE WAS FALSE. The roster's doc comment claimed four rows at its end were the deleted census's planted controls. Enumerating all 38 rows finds no such row -- the rows were never added, only described -- and the corpus run duly reported all four controls as ordinary refusals. They are deliberately false citations, the discriminating evidence that a resolver refuses; a wall that refuses them refuses the evidence for its own mechanism. They are NOT enrolled as debt, because debt is a monotone contract that may only shrink and these never retire (DESIGN 4b(4): an expecting-red probe that greens flips to a permanent regression control). PLANTED_CONTROL_CITATIONS is a separate carrier whose staleness arm is INVERTED: a debt row refuses when its citation stops refusing; a control row refuses when its citation stops refusing too, but because the control has lost its discriminating power. Same trigger, opposite meaning, so two carriers rather than one with a flag. The false claim is recorded as false rather than silently corrected. A stale statement inside the carrier built to stop stale statements is the specimen. 2. ONE ROSTER ROW'S FIELD WAS WRONG, and it produced two CONTRADICTORY findings about one citation in one run: extdeps.tcgplayer.store cites UpdateSkuPrice with field NamedField { price }, while its roster row carried an empty field. So the suppression missed it (reported CITED-DECLARATION-ABSENT) and the staleness arm saw no live row for the empty-field identity (reported CITATION-DEBT-ROW-STALE). One identity error, both arms wrong, in opposite directions. * Paired inverse arms must run in one report; assert the desynchronization instead of noticing it One roster row carrying an empty field where its citation carries NamedField { price } made the two arms report CONTRADICTORY findings about ONE citation in ONE run: the suppression arm called it unenrolled debt, the staleness arm called its row spent. Both locally correct, both wrong. NEITHER ARM CAN DETECT THAT ALONE -- each is right about its own half -- so the only observable is the two answers being present together and disagreeing. That was caught by a human reading two lines of a report, which is not a mechanism. Two things follow, and neither is the row fix (already landed): 1. THE RULE, recorded on corpus_findings because that is where a future split would be decided: paired inverse arms must run in one report over one subject set. Splitting them across jobs, cadences or roster arguments does not weaken the pair, it destroys it, and the reasons for splitting are usually good ones about job granularity. Someone will propose it; the receipt is there for them. 2. THE WALL: a_roster_row_on_the_wrong_identity_desynchronizes_both_arms plants the exact identity mismatch and requires BOTH findings to appear, then repairs the row to the citation's real identity and requires NEITHER. That converts a lucky catch into something that fails by execution. * Fix the test import block my own codemod silently failed to update The plant-precondition and planted-control commits added helpers using index_get, DeclarationIndex, ModuleDeclarationRecord and planted_control_findings_against, and the edits meant to add them to the use block were plain string replaces against a form cargo fmt had already reflowed. They matched nothing and said so to nobody, so the test target stopped compiling: E0425 cannot find function index_get, E0425 cannot find type DeclarationIndex, 7 errors. Caught by execution, not by review: the corpus half of that dispatch ran and printed its findings while the suite half never compiled, which is exactly the shape where a run looks productive and one of its two questions was never asked. Every other edit in this branch asserted its match count; the import edits did not, which is the whole difference. Rewritten by matching the use block as a unit with an assertion on the match count, and every symbol the file references was checked as exported before committing. * Correct an overclaim in my own carrier: decl_facts IS still consulted by the required run The seed-growth carrier said the corpus-walk half of the DESIGN triggers is discharged and 'decl_facts is no longer consulted by any required check'. The first half is right for the three questions this change answers; the second half is false and I wrote it without checking. decl_facts has live .dag consumers, and several are floor-discovered witness modules -- decl_facts_reflection_witness_test, record_construction_census_witness_test, floor_expected_red_coherence_witness_test among them -- so the corpus walk still executes inside the required floor for their sake. What IS true is narrower and still worth the change: the citation wall no longer reaches decl_facts at all, because --required-cited-symbol and its lens are off the required path entirely, and the three integrity questions now come from one construction instead of three walks. Retiring the remaining consumers is a separate cut. Caught by re-reading the request against the carrier rather than by a checker, which is the same failure this PR exists to make mechanical: a claim about a population nobody had counted. * Declare the residue this wall does not close: it checks symbol resolution, not claim truth A citation wall answers 'does this name exist'. Nothing in this construction answers 'is this count right', and the two halves are independent. Named as declared residue so the next reader finds the gap instead of assuming the wall covers it. The distinction is measured, not hypothetical -- twice on this branch, both times inside typed carriers, both times a population claim nobody had counted: the debt roster's doc comment 'four rows at the end are the planted controls' -> the rows were never added, only described this carrier, same author 'decl_facts is no longer consulted by any required check' -> three live floor-discovered consumers Why the wall cannot reach either: decl_facts is a REAL SYMBOL that RESOLVES. The sentence claiming nothing consults it would pass a cited-symbol census cleanly, because every name in it is true and only the QUANTIFIER is false. DESIGN 4c states the general form -- prose is unfalsifiable by construction, which is why a count belongs in a typed carrier and not in a sentence. Rung stated honestly: one was caught by running the wall, the other by re-reading the carrier before merge. The second is review diligence, so the class sits at MITIGATABLE and nothing here climbs it. NEXT-RUNG TRIGGER: a quantified claim in a carrier is DERIVED rather than AUTHORED, so the sentence cannot disagree with the corpus because it is not a sentence. * Record that the four control identities are the surviving authority when the dead lens is cut Review 55841 asked to confirm v2.lens.cited_symbol_resolution is retired rather than left as dead parallel representation. Measured rather than asserted, because 'it is dead' is the claim shape this branch already got wrong once: of the 27 symbols unique to that lens, the only references outside it are one prose row in gunbc.roster_registry, two prose mentions in fast witnesses (a String note and a // comment), and nine real uses in the long/ witness, which is declined before the fold and never executes. NO EXECUTING witness calls any function it declares. So it is dead, not competing. But this change does add a second copy of the four planted-control identities, and the duplication needed a named terminus rather than an assurance. Recorded: when the lens is cut, these identities are the SURVIVING authority -- the deletion removes the dead copy, never the evidence. DESIGN 4b(4) keeps a discriminating control enrolled when its machinery goes, and a cut that swept the lens's controls into the funeral would erase the four probes that prove this wall's refusal arms are real. * Regenerate the three projections the new seed file and its DESIGN rows move declaration_index.rs is a hand-written seed file. The branch registered it in both authorities -- seed_retention_frontier and stage0_crate_layout -- and never regenerated the projection those authorities feed, so the regen phase saw a committed mirror the emitter does not produce ("committed mirror is no longer emitted") and the two crate-layout witnesses that join frontier to generated filenames both went red. One missing regeneration, three CI failures. DESIGN.md is the third projection and was invisible from the failure list: this branch edits gunbc.design_document (the fired §6 construction-justification trigger, the retired cited-symbol row), so its projection was stale too and would have been the next cycle's red from a different file. Produced by running the emitter to a FIXED POINT -- dag/tools/generated_artifact_gate.dag main_wet, looped until git status stopped changing, which took two rounds -- not by hand-matching the expected output. The files say do not hand-edit, and a hand-written file that happens to equal what the emitter would produce passes the gate while leaving the emitter unproven. Every installed byte verified against the emitter's own sha256 on the runner before any confirming run: 261489671103b4d8c1cce69934cbaaf23fd401a379e0de0eb941a42b48ca92bc dag/gunbc/stage0_crate_layout_generated.dag 698a52094e48cdf3964a5c2a5df4266a5892de49f4f0516521beaf041fef2d79 src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs 8d075c7cd37af217326c689bbbcefbbe1c3024c7b53cad5f93eec75e91cc652f DESIGN.md A second dispatch re-emitted over the installed copies and reproduced them unchanged, which is the independent half of that check. The declaration index itself was already green on the required path at the previous head and is untouched here: modules=3993 declared=76852 citations=1496 debt=42 kernel_named=1944 lens_modules=71, no findings. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The wall's disclosed outside-index boundary rotted this PR's own roster (review 55899) dag/gunbc/declaration_index_seed_growth.dag cited v1_compiler.declaration_index citation_is_pre_existing_debt. That predicate was RENAMED to citation_in_roster earlier on this branch, by the repair that made the debt roster a parameter defaulted to the identity element. The code and every caller moved; the roster row did not. So the carrier declaring this PR's hand-Rust obligation cited a symbol this PR had deleted -- the exact DESIGN §3 stale-citation class this PR exists to close, inside the PR's own authority. WHY THE WALL DID NOT REFUSE IT. The wall resolves a citation against the index, and the index is built from swept .dag modules. v1_compiler is a hand-Rust namespace root no swept module declares, so citation_is_outside_index COUNTS it rather than refusing -- exactly as the carrier's disclosed boundary says. What that disclosure did not say, and now does: the seed-growth carriers are precisely the rosters that name hand-Rust items, so they are the one population where a rename in the same commit silently rots its own citation. The wall's coverage and the rosters that most need covering are disjoint. CHECKED AT CLASS GRAIN, NOT AT THE REPORTED INSTANCE. All 55 roster rows resolved against a definition in the five hand-Rust files the carrier enumerates: 54 resolved, 1 did not -- the row review found. The "+55, all enumerated" claim was therefore true of the COUNT while false of one row's CONTENT, which patching only the reported line would have left unmeasured. Recorded as a specimen row rather than silently corrected -- the same discipline the false-quantifier row already applies to its two specimens -- with its next-rung trigger (resolve hand-Rust citations against an index of hand-Rust declarations, strictly larger than this PR and not attempted here) and an honest rung: mitigatable, review diligence. VERIFIED: v1_src_dag_parse over the merged tree, 3997 file(s) parse-clean, zero findings, declarations modules=3997 declared=76950 import_members=80221 citations=1496 debt=42 in_fixtures=161 outside_index=134 kernel_named=1948 lens_modules=71. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The third projection: the seed-emitted mirror the artifact gate does not produce CI: required-ci: regen FAIL generated surface drift: gunbc_stage0_crate_layout_generated.rs ONE AUTHORITY, TWO EMITTERS, AND I HAD ONLY RUN ONE. Editing dag/gunbc/stage0_crate_layout_generated.dag moves THREE artifacts, produced by two different emitters: main_wet (dag/tools/generated_artifact_gate.dag) dag/gunbc/stage0_crate_layout_generated.dag src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs DESIGN.md regen (claim_executor --required-regen) src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs The previous commit iterated main_wet to a FIXED POINT and hash-verified every byte of its outputs. That was correct and could never have surfaced this file, because main_wet does not produce it. A FIXED POINT IS ONLY A FIXED POINT OF THE OPERATOR YOU ITERATED. The two Rust mirrors sit in the same directory with nearly the same name -- bootstrap_stage0_... and gunbc_stage0_..., one per emitter -- so the missed one reads as a duplicate of the checked one. REPRODUCED RATHER THAN INFERRED, which mattered: main at efc880a ALSO fails witnesses.yml in the BUILD lane with floor green, so every surface signal said inherited. Running the exact lane (claim_executor --required-ci --required-lane build) named a file that exists only on this branch. main's build job died before its steps reported a conclusion at all -- an infrastructure death wearing a lane name, which could not have produced this symptom. Two reds, one lane name, unrelated causes. REPAIRED BY THE DOCUMENTED RECIPE, not one pass, because the first pass runs a binary that PREDATES the change it emits and can self-verify at divergence 0 for the wrong reason: pass 1 first_generation_equal=false FAIL generated surface drift install target/stage0-regen-candidate/src/gunbc_stage0_crate_layout_generated.rs rebuild from the installed seed Finished in 4m12s pass 2 first_generation_equal=true no failure Installed bytes verified against the runner's sha256: e70d37012c0ee094583ed0dc3c1098cb55f06008e90867ba1a894059980e6a6a The diff is one insertion, "declaration_index.rs".to_string(), which confirms the diagnosis rather than merely clearing the gate. THE FLOOR LANE IS ALREADY GREEN ON THE PARENT COMMIT (run 32907180281): phases_run=2 failed=0, parse OK 3997 file(s) parse-clean, declarations modules=3997 declared=76950 citations=1496 debt=42 kernel_named=1948 lens_modules=71 -- so the two crate-layout witnesses that failed on ea31e92 now pass, and the declaration index matches the runner measurement digit for digit. This commit closes the last of the three original failures. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Drop six imports that main's #9228 deletion made dead in the merge CI on 45270ab: both lanes died at "Build the witness fold" with the lane steps SKIPPED, so nothing was checked -- one compile failure reported three times, not three failures. error: unused imports: `make_eval_context`, `resolve_entry_graph_shared`, and `run_value` error: unused imports: `ExecutionMode`, `InterpContext`, and `Value` error: could not compile `v1-compiler` (bin "claim_executor") due to 2 previous errors NEITHER BRANCH HAS THIS DEFECT ALONE. main's #9228 ("Delete the plan/walk surface nothing could reach", claim_executor 21,366 -> 11,508) removed the last callers of all six; this branch kept the import list. The imports go dead only in the merge, and CI evaluates the merge ref, which is why the head built clean here and failed there. Every surviving use is fully qualified (v1_compiler::cli_run::make_eval_context), and `Value` is re-imported locally at its one use site, so the removals are safe. TWO DEFECTS IN MY OWN INSTRUMENT, named because both fail toward a green: 1. CI builds with -D warnings and the workflow never says so -- actions-rust-lang/setup-rust-toolchain@v1.16.0 sets RUSTFLAGS: -D warnings by default. Local dispatches built without it, so unused imports were warnings here and errors there. Reproduced with RUSTFLAGS forwarded: BUILD-RC=0. 2. My build checks grepped `^error`, but cargo emits ANSI escapes, so the real line is \e[1m\e[91merror and never matches at column 0. Every "no errors" I reported from those dispatches read a filter that COULD NOT MATCH AN ERROR. That is the worse of the two: it would have hidden any compile failure, not just this class. VERIFIED ON THE MERGED TREE, under CI's own strictness: cargo build --release --bin claim_executor --bin gunbc, RUSTFLAGS=-D warnings rc=0 claim_executor --required-regen first_generation_equal=true, no drift main_wet x2, all three projections byte-IDENTICAL before and after: ba373e57... DESIGN.md 26148967... dag/gunbc/stage0_crate_layout_generated.dag 698a5209... src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs so the text-merged DESIGN.md IS the projection of the merged authorities and owes no regeneration. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Carrier identity is not a licence: the fixture exemption moves to citation grain (review 55939) Both citation arms skipped every citation in a module module_is_fixture_carrier answered true for. The justification was real and still is -- a witness proving the resolver refuses an absent symbol has to AUTHOR an absent symbol, so its false citation is its evidence rather than its defect. The defect was that the EXEMPTION WAS KEYED ON THE MODULE while the justification is a property of the CITATION. WHAT SETTLED IT WAS THE MEASUREMENT, NOT THE ARGUMENT. Of 161 citations authored inside fixture carriers, 128 RESOLVE: ordinary citations of real authorities that happen to live in a test module. The skip was shielding 128 real citations to protect 33 sites, and reporting the rest as in_fixtures did not restore integrity. A counted hole is still a hole. THE HOLE WAS OCCUPIED, which is what separates a defect from a disclosed boundary. Two enrolled identities are ordinary staleness with nothing to do with fixture intent: - dag.test.claim.witness_purpose_taxonomy_witness -- a dag.-prefixed module path no module declares; the real module is test.claim.*. A plain typo. - std.disposition Disposition field marker -- a real authority and a real declaration with an absent field, cited twice. THE REPAIR. Both arms now judge fixture carriers, and FIXTURE_CARRIER_CITATION_EXEMPTIONS enumerates 31 identities at (module, declaration, field) grain. It is NOT a debt contract and does not claim to be: §5's condition 3 wants a terminal state of empty and this one's is not -- a planted control such as NoSuchDecl_G1_RED is permanent by design. What it shares with the debt roster is what makes either safe rather than a suppression list: MONOTONE, and REFUSES WHEN SPENT through the same inverse arm. Also fixed a diagnostic that would have named PRE_EXISTING_CITATION_DEBT for a row held by a different roster -- a spent-row message naming the wrong list sends the reader to a file that does not contain the row. HOW THE ROWS WERE OBTAINED, because the first attempt was wrong AND THE MECHANISM CAUGHT ITS AUTHOR. Extracting identities by parsing rendered diagnostics silently dropped the FIELD -- a CitedDeclarationAbsent message never prints one -- so rows for citations carrying a NamedField whose DECLARATION is absent matched nothing. The corpus run then reported the same citation as BOTH refusing AND its row as spent: the paired-inverse-arm desynchronization this module documents and tests for, firing on me, inside one run. Rows are now derived from the index, from the same CitedSymbol values the matcher compares. Five further refusing identities are deliberately excluded -- already enrolled in PRE_EXISTING_CITATION_DEBT or PLANTED_CONTROL_CITATIONS, and a second row for one citation is duplicate authority with a double stale-arm report. RUNG: unchanged at mechanically preventable. This is a WIDENING of the enrolled population, not a climb -- 128 citations that were never judged now are. VERIFIED, under CI's own strictness (RUSTFLAGS=-D warnings): cargo test --test declaration_index_integrity 21 passed; 0 failed v1_src_dag_parse over the corpus rc=0, ZERO findings 3997 file(s) parse-clean; modules=3997 declared=76981 import_members=80186 citations=1493 debt=42 in_fixtures=161 outside_index=134 kernel_named=1947 lens_modules=71 Three new fixture-boundary tests, each asserting its plant before the guard's verdict: a refusing citation inside a carrier is judged; exempting one citation leaves its sibling in the same module refusing; an exemption over a resolving citation refuses as spent and names its roster. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Declare the 29 unclassified exemption rows as a stall, not a settled boundary The fixture roster enrolls 31 identities. Two are decidable by inspection and are named in the carrier prose as ordinary staleness. THE OTHER 29 ARE NOT CLASSIFIED, and leaving that as prose would let them read as settled -- which is exactly where a real defect sits unseen, demonstrated rather than hypothesised, because two were found sitting there. Not deciding them is still right: deciding what another author MEANT across 29 rows is the judgement §5 warns turns a stale citation into a confidently wrong one. The repair is to DECLARE the stall rather than to resolve it, which is the difference between a boundary disclosed and one merely not crossed. declaration_index_fixture_exemption_classification_stall, a GuaranteeStall: current Mitigatable ceiling MechanicallyPreventable (below ceiling, so it reads as a stall rather than a class that already arrived) blocker AwaitsOneGrounding NOT ClimbableButUnbuilt: what is missing is a DECIDABLE CRITERION, not effort. Nothing distinguishes a citation its author meant to refuse from one that rotted; the distinction lives in authoring intent, which no Accepted program can read. population BoundedPopulation, 29 members at identity grain -- genuinely bounded, so UncountedNotEnumerable would be the empty-observation narrow. trigger a witness declares each citation it plants to refuse as a typed row beside the citation, at which point the deliberate half is DERIVED, this roster shrinks to the genuinely stale remainder, and that remainder becomes ordinary debt with a terminal state of empty. The 29 is derived by subtracting the two named specimens from the 31, not asserted, so the number in the prose and the number in the row are one fact. VERIFIED: 3997 file(s) parse-clean, rc=0, ZERO findings. The new gunbc.guarantee_rung_drop import members resolve -- import_members 80186 -> 80191 with no IMPORT-MEMBER-ABSENT finding, which is this change's own wall checking this change's own edit. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 26, 2026
…or retire the observation emitter migration census (#9274) * The census pinned each row to a file, so #9228's claim_executor shrink reported four code moves as census events — and hid the one real one, a migration reverting to raw emits Five `gunbc.observation_emit_census` rows went red at once. Measured: exactly one was a census event. `CensusedEmitSite` carried `source_file: NonEmptyStr`, whose only consumer in the corpus was the witness's `census_marker_present` — read that one file, grep it. That is a positional citation in the sense DESIGN §3 rules against, and it rots in the way this census cannot tolerate: it goes false when an emit MOVES, which is not a census fact. #9228 deleted claim_executor's unreachable plan/walk surface (21,366 -> 11,508 lines) and four rows reded while their tag families sat untouched in sibling seed files ([receipt], [resolve-split], [assembly-split], [witness-row-cost]). Four false reds beside one true one is worse than no check: the true one is indistinguishable in the noise. THE ONE REAL EVENT, and it is a REGRESSION, not the retirement it looks like. [floor-memory] was a MigratedToObservation row: the floor's periodic progress line rendered through `ci_heartbeat_line` via the seed mirror `render_heartbeat_line_mirror`. Neither the marker nor the mirror occurs anywhere under src/ any more (one doc comment names the mirror). Read no further, that is a retirement. It is not: the floor still emits a periodic progress line and a per-claim RSS line, now as raw `[floor-heartbeat]` and `[floor-claim-memory]` eprintlns in cli_run.rs with no projection behind them. A projection was deleted and raw emits took its job under new names. Deleting the row as a completed retirement — which is what marker-absence alone supports — would have booked a reversal as progress. WHAT LANDS - `source_file` deleted from the type. Presence is asked of the SEED (`seed_emit_sources`, folded), so a marker that moves stays green and a marker that leaves reds. Fail-closed on its own denominator: a new witness reds if any listed source stops reading non-empty. - `floor_heartbeat_site` and `floor_claim_memory_site` enrolled as CountedFrontierSite; frontier count rises by two, which is the honest direction. `w_the_floor_heartbeat_projection_is_absent_from_the_seed` is the discriminating probe — three conjuncts, because marker-absent and mirror-absent alone cannot tell retirement from regression; only a raw successor emitting can. It reds when the debt is paid, forcing reclassification in the same change. - The floor-memory raw-shape probe is deleted with its subject. Not the §4b(4) keep-the-evidence case: nothing climbed, so there is no rung to hold. - `claim_executor discovery_claim_result`, cited as [witness-row-cost]'s grounding, RESOLVES TO NOTHING — fabricated 2026-08-22 and copied into the retirement acceptance, so one invented symbol became two files' evidence. Corrected to the `witness_cost_*` helpers in cli_run.rs, in both. - Raw-shape probes: mirror positives widened to the seed; the three negatives measured to be ambiguous seed-wide (`t_ms=`, `current={}`, `bytes (VmHWM)` — 4, 3 and 2 unrelated occurrences) stay file-scoped. WHAT IS DECLARED, NOT FIXED. The bidirectional claim is false as stated: 57 bracket-tag spellings live in the six seed sources against 13 rostered tags, so 44 are unrostered — an UPPER BOUND from a spelling grep, not the frontier debt, and quoted as the shape of the gap rather than its size. It is not repaired by hand-authoring 44 rows, which multiplies the surface that rots. The next-rung trigger is a substrate capability rather than effort: the interpreter registers `string_contains` and `string_length` and nothing else over strings, so a fold can ask whether text contains a pattern and cannot ask where, how many, or what else of this shape. Membership is decidable; enumeration is not reachable. Occurrence-grain discovery — the durable fix this module has named as its residue three times — is not expressible in .dag today. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016BTuU9MJgDAtC2h3akqzLD * The reversal probe's mirror conjunct asked for a name, and a doc comment answered: ask for the call form Executed, the probe returned false. `render_heartbeat_line_mirror` still occurs once in cli_run.rs -- in a doc comment, in backticks, naming the deleted mirror. A substring test cannot tell a call from a mention. The conjunct now asks for `render_heartbeat_line_mirror(` with the open paren: an approximation of 'a call site, not a mention', not a fix, and one that fails toward red rather than green. WHY IT WAS WRONG WHEN WRITTEN: the first draft was verified by shell grep over src/ and reded when executed. The difference was the denominator -- the check folds seed_emit_sources, which includes cli_run.rs where the comment lives. A measurement taken with a different instrument than the check runs is not evidence about the check. 18 of 18 witness identities green by execution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016BTuU9MJgDAtC2h3akqzLD --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 26, 2026
…ction, cli_invoke builders, walk_plan_stage fixture family) (#9252) * Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns #9228 deleted claim_executor's plan/walk surface and named its .dag residue rather than sweeping it. This is that cut, plus one repair the census surfaced. WHAT WENT, AT THE ROOT: PlanFunction and the plan argv builders. The coproduct modelled a closed roster of --plan-function targets; the flag no longer parses and the entry every variant named (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the notice-title normalizer and shell suffix that existed only to feed them, claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/ floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and gunbc_ci_floor_only_script. The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell, release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it records is still open for that one spelling. gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that, and a second route to it here is the parallel authority the floor cut removed. The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore] harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness row. Their sole driver was the plan.dag recipes #9228 deleted. v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition:: DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That arm's roster was one prefix and the family above was its entire population; its own header said "DISSOLVES when the fixture stops authoring test fns", and this is that condition. Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both sides deleted here. The pre-push witness-corpus gate. Not on the brief, found by the flag census: pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only; its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms a gate" are deleted rather than weakened -- measured against the roster, the corpus binding was the only thing making them true, so they were green against the plan and false about the hook anyone runs. THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope): Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION witness, which has nothing to do with plan/walk. Its own note records that these same specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which died with affected-set selection. This would have been the third home. They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns: three modules, no test fn, no effects, one consumer. No discovery exclusion is needed because there is nothing to discover, which is a stronger construction than the dir-grain exclusion the old home required. AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied every row and the "strict-subset proof" the note describes was checked by nothing. ExpectScopedExactly compares the selected list to the expected list. EVIDENCE, by execution on a release gunbc (remote, one dispatch): control witness_touched_path_dispositions_hold -> true mutation give scope_isolated an import edge to scope_shared -> false The mutation is exactly the strict-subset violation; the old assertion could not see it. Rust: cargo check -p v1-compiler --bins clean, fmt clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Repair the scope-disposition witness's per-PR half, which the floor caught dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining and pins the disposition row count. Both moved with the rehoming and I checked only the long-lane witness, so strict preparation refused with a name-resolution error before any site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster growing by one row because the strict-subset proof needs three specimens where the old home carried two. The pin doing its job here is the argument for keeping it: a count that had to be updated by hand is exactly what stopped this rehoming from silently shipping a roster of a different size than the one the note describes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct. WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script() alone, because its other half emitted a `claim_executor --plan-entry` line naming an entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived was a callable verb that builds the release binaries, verifies the artifacts, and exits 0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported under the name of the larger one. §5's absorbing-fallback rule is about a failure arm that widens; this is its mirror at the success arm, a green that narrowed. WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the reviewer's other option and I am not taking it, on the grounds this branch already argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a second route to it is the parallel authority the floor cut removed. The verb also has no distinct job left -- "build the release binaries and verify the artifacts" already has a name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is not an authority that lost its body; it is a name with nothing left to denote. THE CENSUS, cut at the root and followed where it led: dag/tools/gunbc_ci.dag the entry module, deleted main.rs Commands::Ci + its arm the CLI verb gunbc.cli_dispatch_surface "ci" row the modeled CLI surface gunbc_cli_dispatch_surface.rs its generated mirror v2.workflow.ci_release_build_emit gunbc_ci_run_script, the wrapper std.emit_on_demand gunbc_ci_emission_surface the wet-surface row naming tools.gunbc_ci main emit_on_demand_kernel_witness_test its enrollment assertion wall_residue_live_test residue_gunbc_ci_clean a test fn whose subject was the deleted file ci_release_build_script itself is UNTOUCHED and still has three consumers (ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes. EVIDENCE, build lane on this tree (remote, one dispatch): required-ci: lane=build phases_run=2 failed=0 regen first_generation_equal=true -- the mirror edit is byte-equal to the emitter's own output, established by the gate rather than by my reading of the diff v2-emission blocking=0, census 3792 -> 3791, the one deleted module The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Name the admission order's next-rung trigger, so the gap reads as unbuilt The header already said the surviving long-home-over-live-tree precedence has no executing discriminator and must not be cited as covered. It did not say what would make it coverable again, which leaves a reader unable to tell cannot-cover-yet from nobody-built-it -- the distinction DESIGN 4b(2) exists to keep. The trigger is a decline whose subject CAN collide with an existing one: a site that legitimately satisfies two decline reasons at once, so which reason it reports is a decision some input can get wrong. At that point a discriminating witness is authorable and is owed. Until then the correct response to the absence is to build that collision case, not to re-point a witness at a subject that cannot disagree with itself -- which would be permanently green by construction, and cited as coverage. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Aug 26, 2026
…ction, cli_invoke builders, walk_plan_stage fixture family) (#9286) * Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns #9228 deleted claim_executor's plan/walk surface and named its .dag residue rather than sweeping it. This is that cut, plus one repair the census surfaced. WHAT WENT, AT THE ROOT: PlanFunction and the plan argv builders. The coproduct modelled a closed roster of --plan-function targets; the flag no longer parses and the entry every variant named (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the notice-title normalizer and shell suffix that existed only to feed them, claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/ floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and gunbc_ci_floor_only_script. The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell, release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it records is still open for that one spelling. gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that, and a second route to it here is the parallel authority the floor cut removed. The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore] harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness row. Their sole driver was the plan.dag recipes #9228 deleted. v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition:: DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That arm's roster was one prefix and the family above was its entire population; its own header said "DISSOLVES when the fixture stops authoring test fns", and this is that condition. Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both sides deleted here. The pre-push witness-corpus gate. Not on the brief, found by the flag census: pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only; its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms a gate" are deleted rather than weakened -- measured against the roster, the corpus binding was the only thing making them true, so they were green against the plan and false about the hook anyone runs. THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope): Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION witness, which has nothing to do with plan/walk. Its own note records that these same specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which died with affected-set selection. This would have been the third home. They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns: three modules, no test fn, no effects, one consumer. No discovery exclusion is needed because there is nothing to discover, which is a stronger construction than the dir-grain exclusion the old home required. AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied every row and the "strict-subset proof" the note describes was checked by nothing. ExpectScopedExactly compares the selected list to the expected list. EVIDENCE, by execution on a release gunbc (remote, one dispatch): control witness_touched_path_dispositions_hold -> true mutation give scope_isolated an import edge to scope_shared -> false The mutation is exactly the strict-subset violation; the old assertion could not see it. Rust: cargo check -p v1-compiler --bins clean, fmt clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Repair the scope-disposition witness's per-PR half, which the floor caught dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining and pins the disposition row count. Both moved with the rehoming and I checked only the long-lane witness, so strict preparation refused with a name-resolution error before any site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster growing by one row because the strict-subset proof needs three specimens where the old home carried two. The pin doing its job here is the argument for keeping it: a count that had to be updated by hand is exactly what stopped this rehoming from silently shipping a roster of a different size than the one the note describes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct. WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script() alone, because its other half emitted a `claim_executor --plan-entry` line naming an entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived was a callable verb that builds the release binaries, verifies the artifacts, and exits 0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported under the name of the larger one. §5's absorbing-fallback rule is about a failure arm that widens; this is its mirror at the success arm, a green that narrowed. WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the reviewer's other option and I am not taking it, on the grounds this branch already argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a second route to it is the parallel authority the floor cut removed. The verb also has no distinct job left -- "build the release binaries and verify the artifacts" already has a name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is not an authority that lost its body; it is a name with nothing left to denote. THE CENSUS, cut at the root and followed where it led: dag/tools/gunbc_ci.dag the entry module, deleted main.rs Commands::Ci + its arm the CLI verb gunbc.cli_dispatch_surface "ci" row the modeled CLI surface gunbc_cli_dispatch_surface.rs its generated mirror v2.workflow.ci_release_build_emit gunbc_ci_run_script, the wrapper std.emit_on_demand gunbc_ci_emission_surface the wet-surface row naming tools.gunbc_ci main emit_on_demand_kernel_witness_test its enrollment assertion wall_residue_live_test residue_gunbc_ci_clean a test fn whose subject was the deleted file ci_release_build_script itself is UNTOUCHED and still has three consumers (ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes. EVIDENCE, build lane on this tree (remote, one dispatch): required-ci: lane=build phases_run=2 failed=0 regen first_generation_equal=true -- the mirror edit is byte-equal to the emitter's own output, established by the gate rather than by my reading of the diff v2-emission blocking=0, census 3792 -> 3791, the one deleted module The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Delete v2.lens.cited_symbol_resolution, and keep the twelve of its twenty-seven witnesses that were never its DESIGN authorised this cut and got its population wrong, which is the finding rather than a footnote. The row read "v2.lens.cited_symbol_resolution and its sixteen witnesses are not deleted -- they are unreachable from any required check and are dead rather than competing". Both halves of that population claim are false, and this change corrects the row in the same diff that falsifies it. SIXTEEN WAS THE COUNT AT #7707, when the lens landed. The file grew twice after (#8673 enrolled roster_registry, #8775 the two instance-gap carriers) and held 27 `test fn` identities. `gunbc.ci_layer_roots` said "eighteen". Three numbers, three snapshots of a growing file, none of them current -- the transcribed-measurement class the standing rule already names. The replacement rows name their subject and no number. AND "DEAD" WAS TRUE OF THE LENS AND FALSE OF A THIRD OF ITS WITNESSES. Measured against the seven symbols that file imported FROM the lens, 6 of the 27 touch one. The other 21 do not. "The lens and its witnesses" was never one population, and the three-way split is: 6 LENS-BOUND -- die with it. The census-green claim, the three planted-control rows, the enrolled-population exemption identity, the ambiguous control. `declaration_index` re-derives this machinery as PLANTED_CONTROL_CITATIONS plus PlantedControlNoLongerRefuses. 6 RESOLVER-BOUND -- MOVED, not deleted, to test.claim.long.decl_ref_resolution_witness_test. They call `resolve_declaration_ref`, which lives in `v2.std.decl_ref_resolution` -- a module that SURVIVES with four other consumers -- and they are the only rows in the tree that execute its five-arm refusal. Deleting them because they sat in a file named for the lens would be the §4b(4) failure exactly: a climb deletes the redundant PRODUCTION machinery, never the discriminating RED and positive control. 15 CARRIER-BOUND -- MOVED to test.claim.long.carrier_reference_integrity_witness_test. Population and projection claims about the four carriers that PROJECT DeclarationRefs. Their resolution half is subsumed; their population half is subsumed by nothing. SUBSUMPTION IS SCOPED, not general: `declaration_index` extracts TYPED-LITERAL citations -- DeclarationRef record literals and the decl_ref/decl_field_ref constructors -- and reports computed reference fields as a coverage boundary. A prose reference inside a String is covered by nothing, before or after, and this change does not claim otherwise. THE PER-PR WITNESS IS RENAMED, NOT DELETED. test.claim.cited_symbol_resolution_witness_test never imported the lens; its one claim is a three-term bucket partition over gunbc.doc_graph_roots. Two readers independently concluded from its NAME that the resolution law was enforced per-PR -- it was not, a bucket identity was -- and after this cut it would have been the only cited-symbol-named thing left in the tree, reading as the law's residue. It is now test.claim.doc_graph_reference_partition_witness_test. Same borrowed-authority shape as #9252's fixture rehome, one layer up: there the home was borrowed, here the name. WHAT THE WALL ITSELF NAMED, because this was cut delete-first and the census is the deletion. The first corpus run after the cut reported six refusals: two IMPORT-MEMBER-ABSENT for a `CitedSymbolResolution` lens-id the registry no longer declares, and four PLANTED-CONTROL-RESOLVES for the exact rows #9211 declared as this cut's residue ("they delete with the lens, not before it"). Every one predicted, none discovered by reading. AND ONE GAP THE ROSTER DELETION WOULD HAVE OPENED, which is why those four rows are not simply removed. Each named one refusal arm of the cited-symbol wall. Three of the four arms already had controlled fixtures in tests/declaration_index_integrity.rs. THE FOURTH DID NOT: measured, the string `CitedFieldAbsent` did not occur in that file at all, so its only evidence anywhere was the planted row I was deleting. Deleting it would have left a refusal arm with nothing executing against it -- §4b(4) again, one level up from where I first hit it. `citation_to_an_absent_field_is_refused_and_a_present_field_is_not` is authored here, with its positive control, and a controlled fixture is the stronger oracle anyway (§5): the planted row only ever asserted that one hand-authored citation still refuses. PLANTED_CONTROL_CITATIONS is left EMPTY rather than deleted. Mechanism reachable, join reachable, occupancy zero -- a healthy guard being quiet, not a dead one. EVIDENCE, by execution (remote, release binaries): before after parse-clean files 4012 4011 the lens module modules 4012 4011 citations 1470 1466 the lens's four planted citations lens_modules 71 70 debt 42 42 UNCHANGED corpus findings 0 0 declaration_index_integrity 21 passed 22 passed the new field-absent pair THE DEBT COUNTS RECONCILE, and the brief's "46" is none of them. 38 = roster rows, counted. 46 = citation SITES at the time the roster's doc comment was written. 42 = citations currently suppressed by a row, the live measurement. debt is 42 before and after, and a row that stopped reproducing refuses as CitationDebtRowStale -- none did, which is the executable form of "the defects are still found". Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 27, 2026
… the test target main inherited (#9230) * Enrol the v2-emission selftest; delete two orphaned modes; repair the test target main inherited Rebuilt on current main rather than merged into it. The old branch shared three commits with #9228 and conflicted in twelve hunks where "ours" was a pre-deletion snapshot -- hand-resolving that risks silently restoring code #9228 had just deleted, so the two intentional changes were replayed onto main instead. Force-push is the honest vehicle here; a merge commit would have carried a resolution nobody could audit. THE ENROLMENT IS THE POINT, and it is a climb rather than a cut. run_required_v2_emission_selftest -- the red fixture that must be refused on the annotation cause and the green fixture that must emit -- was reachable ONLY through a standalone flag no workflow invoked. So the required run's v2-emission phase ran a producer whose REFUSAL had never once been shown to fire; a green established that the emitter emitted, not that it still refuses what it must. DESIGN 4b(4): a class's discriminating RED and positive control stay ENROLLED as the evidence the rung is real. Unenrolled evidence is not weaker evidence, it is none. It now runs inside the phase, ahead of the producer, and a failure lands in phase_failures like any other. Measured before enrolling: passes, about a second. The standalone flag goes in the same motion -- two routes to one fact, and only the enrolled one executes. TWO MODES DELETED, and only two: - --measure-cgroup-peak: its own comment names the `rust_tests` job as its caller. That job was deleted. An orphan whose stated consumer is gone. - --required-cited-symbol: DESIGN's 2026-08-23 row already declares this drop and states the surviving flag guards nothing, with a restoration trigger putting the wall at ingestion. Deleting the flag agrees with that row rather than leaving a mode that reads as coverage. KEPT AGAINST THIS PROGRAM'S OWN BIAS: --heads-reading-differential and the three --behavioral-receipt-* modes are INSTRUMENTS with entry points, not gates. DESIGN's 2026-08-24 ruling is that a measurement worth re-deriving is worth an entry point. The target-model lane confirms both shapes they need are expressible (addressable but absent from the //:required roster; a differential needs its own TestStanding arm rather than the Bazel status arm, which carries only PASSED/FAILED and would erase the divergence). They migrate; they do not get rescued. ALSO REPAIRS WHAT MAIN INHERITED. #9228 merged before its last commit landed, so main carries four errors in claim_executor's TEST target: an orphaned witness_walk_flags_tests module and a cfg(test) classify_witness_expectations helper over three deleted types, plus seven dead test helpers and the imports the cited-symbol deletion orphaned. CI cannot see these -- the required run compiles --bin, never --tests. EVIDENCE, both controls run rather than one: - transport: ctrl-build reports `forwarding env: RUSTFLAGS`, so -D warnings reached rustc. - subject: a planted `super::deliberately_absent_symbol_zzz()` produces its exact diagnostic under this branch's own --tests invocation, proving test modules entered the observed population. Clean is therefore a measurement, not a silence. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Six authorities asserted a flag this PR deletes; correct them, and regen surfaces a security fix that never reached its workflow Review 55934 is correct and the finding is the one that matters most in a deletion: the code changed and the canonical authorities did not, so DESIGN and four carriers were left asserting that `--required-cited-symbol` is a live flag that runs the census standalone. After this PR that sentence returns `unknown argument` and exits 2. A knowingly-false recital in the canonical authority is premise contamination -- a reader planning against it budgets for an invocation that cannot run -- and it is exactly the drift these documents were rewritten to close on 2026-08-25. CORRECTED, all six, in the same PR as the deletion rather than after it: dag/gunbc/design_document.dag (the rung-drop row, and DESIGN.md regenerated) src/v2/lens/cited_symbol_resolution.dag (two rows) dag/gunbc/doc_graph_roots.dag dag/gunbc/fabric_capacity_class_gap.dag (past tense) dag/test/claim/build_cache_endpoint_observe_test.dag (past tense) THE RUNG DOES NOT DROP AGAIN, and every correction says so rather than quietly implying a second drop. The clause being replaced already argued that a mode no workflow invokes guards nothing; removing that mode therefore takes away no enforcement, and the class sat at mitigatable on review diligence before the deletion and sits there after it. What the deletion removes is the ON-DEMAND RE-DERIVATION ROUTE -- with the flag and its Rust census both gone there is now no way to run this census over the live corpus at all. That is a capability loss, not a rung change, and conflating the two would be the same 4b(1) inflation the original clause was written to avoid, run in reverse. THE REGEN SURFACED SOMETHING ELSE, AND IT IS NOT MINE. Regenerating the committed artifacts from their authorities also rewrote .github/workflows/fleet-converge.yml. That change belongs to #9226 -- "A credential in a command line is read by every process on the host, and on this fleet that is measured" -- which moved the Secret Manager bearer token out of the curl argv and into a header file, landed a witness asserting the header-file form, and NEVER REGENERATED THE WORKFLOW. So the model has said `-H @"$HDR_FILE"` since that merge while the emitted workflow that actually runs has kept `-H "Authorization: Bearer $WIF_ACCESS_TOKEN"` on the command line, readable from /proc by every process on the runner. The witness passes because it asserts against the authority, not against the artifact. It is included rather than reverted because the alternative is worse: running a generator and committing only the part of its output that suits this PR is cherry-picking, and it would leave a security repair inert while looking applied. The generated-artifact drift gate that would have caught this is in the set DESIGN's CI entry lists as UNGUARDED since the floor cut -- so nothing was going to catch it, and it was found only because this PR had an unrelated reason to regenerate. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * The canonical authority cited a real module as the home of a symbol it does not define DESIGN's floor clause read `v2.workflow.required_floor` `run_required_floor`. The module is real; the symbol is not in it. `run_required_floor` is defined in `src/v1/stage0/src/cli_run.rs` and every other citation in the corpus names it as `v1_compiler.cli_run` `run_required_floor` -- this was the only occurrence of the wrong form, and it was in the one document every session reads first. The v2 module is not unrelated, which is why the repair names both rather than swapping one for the other: it owns the admission, cost-line and preparation-safety policy the fold consults. What it does not own is the fold. Citing the policy carrier as the driver is the same authority-substitution shape DESIGN already records -- both halves check out and only the arrow between them is invented. Worth stating plainly because it lands in a PR that deletes the census: this is precisely the defect `--required-cited-symbol` refused, and it was found by hand three days after that job was cut. The rung-drop row I corrected earlier in this PR predicted an unbounded future population; this is the first counted member of it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Four authority rows asserted the gap this PR's own merge had already closed review 56048 (REQUEST_CHANGES) found three changed rows still saying cited-symbol checking is review diligence and cannot be re-derived, while DESIGN.md in the same tree records the rung restored. The finding is correct and the cause is mine: those edits were true when written, and taking main's retirement row in the merge made them false without touching them. A PR that contradicts itself across four files is the premise contamination this branch has spent the night correcting elsewhere. Corrected to describe the replacement rather than the drop: v1_compiler.declaration_index resolves every authored DeclarationRef inside the parse phase of --required-ci, at ingestion from the module's own source, strictly wider than what was dropped. The fourth row the review did not name is the worst of them and is fixed here too. fabric_capacity_class_gap asserted, as a heading and in the present tense, THE CITATIONS IN THIS MODULE ARE NOT CHECKED BY ANYTHING -- measured, correctly, against a census that enrolled five hand-named carriers. The declaration index enrolls by walking the Node tree for DeclarationRef literals, so a module cannot be outside it by omission, and those eight citations are now enrolled. The measurement is kept rather than deleted because it was taken rather than assumed; what changes is that it now reads as the account of a closed gap. Left standing, it would have told a future reader that a checked module was unchecked -- worse than the three flagged rows, which merely understated a rung. build_cache_endpoint_observe_test is deliberately NOT changed: its subject is annotation grain enforced in the floor's preparation, which is unaffected by which census runs beside it, and it already says so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Moving the bearer token out of argv and leaving it on disk is the same exposure at a different address review 56110 (REQUEST_CHANGES) is correct and this is my defect. The fleet prelude DISARMS its EXIT trap so the ssh-agent outlives the step, and it did so after removing only KEY_FILE -- so the token I moved out of argv in this same PR sat in RUNNER_TEMP for the remainder of the job. The security repair was half a repair. FIXED BY LIFETIME, NOT BY CLEANUP. HDR_FILE is consumed by exactly one curl, so it is removed on the line after that curl rather than added to the later rm the review suggested. The credential ceases to exist when its only consumer is done with it, which is a shorter window than any exit path can offer and does not depend on which trap is armed when the step ends. The trap still covers the failure arm between creation and that removal, which is the only interval where the file can genuinely outlive the shell. The spark prelude is NOT affected and is not changed: it keeps its trap armed through step exit, so its header file is cleaned there. Only the fleet prelude disarms. The authority annotation asserted the thing that was false -- "Each prelude's existing trap removes HDR_FILE on exit" -- which is how the defect survived authoring and review of the original change. Corrected in place, naming which prelude it holds for and which it does not. WITNESS, PROVEN BOTH WAYS BY EXECUTION. The existing tests only ask HOW the header reaches curl, so they stayed green through the entire defect. The new one asserts ADJACENCY -- the removal on the line immediately after the consuming curl -- rather than presence, because presence stays green if the removal drifts below `trap - EXIT`, which is the defect itself. Green: exit 0. Red: delete the rm row from the authority and it exits 1 with "adjacency absent". Authority restored and verified byte-identical after. A position comparison would have been the more obvious spelling and I did not use it: this corpus has no index primitive, and minting one so a test can measure a shell string would be adding an authority to check a claim. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * A comment cited a deleted flag as the precedent for keeping another mode's ordering review 56142 (APPROVE, non-blocking). The ordering rationale for --emit-partition-crates named --verify-build-artifacts AND --measure-cgroup-peak as its two co-examples; this PR deletes the second, so the sentence justified a real ordering by pointing at a mode that no longer exists. Small, and worth doing rather than deferring for the reason this branch has now hit four times: a stale citation does not announce itself, and the next reader takes the comment as the account of why the ordering is safe. The ordering IS safe and the remaining co-example carries the argument alone. Swept the corpus for the three deleted flags rather than fixing only the cited line. The only surviving matches are run_required_v2_emission_selftest's definition in cli_run and its call from the enrolled V2Emission phase -- that is the function this PR puts on the required path, not the flag it removes, so both are correct and stay. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Rehome the orphaned dichotomy-over-three-states paragraph into its authority before a regeneration deletes it DESIGN.md on main carried 1733 characters that `gunbc.recurring_failure_mode` did not: the second form of state-space conflation, its gunbc#9324 specimen, and its recognition rule. Measured by running the generated-artifact gate on a bare worktree at main 0aa09c1 -- `M DESIGN.md`, one line, one insertion one deletion -- and by grep: the text appears nowhere under dag/ or src/v2/. So the projection disagreed with its source in the document that defines the rule against exactly that, and the failure mode was not the disagreement but its remedy: ANY regeneration silently deletes prose no authority holds. This PR already regenerates DESIGN.md as part of resolving a merge-driver refusal, so it was itself the change that would have destroyed it -- caught only because a peer lane reported the drift while resolving a different PR. The repair is the one DESIGN section 3 prescribes: a fact's home is its layer, so the paragraph moves into the carrier that owns the recurring-failure-mode roster and the projection derives it. Verified by execution: the regenerated failure-mode line is now byte-identical to main's, and a second gate run is a no-op, so the tree is a fixed point of its own emitter rather than merely agreeing once. Nothing here is authored: the text is main's, moved to where it can survive. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 27, 2026
…e seed that beats, and repair the zero it was inventing (#9297) * The lockstep the decline was hiding: repoint the heartbeat rows at the seed that beats, and repair the zero it was inventing test.claim.observation_lockstep_witness_test carried two rows over src/v1/stage0/src/bin/claim_executor.rs asking for from_secs(60), floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror and heartbeat_feed_snapshot. #9228 deleted the plan/walk surface all five lived on, so both rows have been FALSE since it merged. Nothing said so: the module declares ReadsLiveTree, the required floor declines it before the fold, and a decline renders identically to a pass -- DESIGN's execution-provenance row, in the form that lets a lockstep outlive the thing it locks to. NOT A RETIREMENT, A MOVE. The floor still beats once a minute: cli_run.rs spawn_floor_heartbeat, period GUNBC_FLOOR_HEARTBEAT_SECS defaulting to 60, emitting a raw [floor-heartbeat] line with no projection behind it. gunbc.observation_emit_census already carries that successor as a CountedFrontierSite with its restoration trigger, so what was missing was not the fact but the citation. Both rows now read the successor, so the derivation observation_dwell_threshold rests on is grounded in the seed again. THE NO-FABRICATION ROW WAS RED BY EXECUTION WHEN IT WAS WRITTEN, which is the repair rather than the reporting. floor_resource_sample answered a fabricated 0 for rss_kb, cpu_ms and majflt while its own cgroup and vmstat readers already answered `na`. So rss_kb=0 meant EITHER no resident pages -- which a live process cannot have -- OR an unreadable /proc/self/statm, in the one instrument that exists to settle a memory contradiction. Two conventions in one line, and the invented one was silent. Repaired to the single `na` sentinel, cpu all-or-nothing because a half-read stat cannot be summed. The row's third conjunct asks for the FABRICATING spelling to be ABSENT, so restoring the zero reds here. THE FEED IS DELETED BECAUSE ITS CONSUMER WAS. cli_run's HeartbeatFeed was read only by claim_executor's deleted mirror; heartbeat_feed_enter_batch has had no production caller since, so the two surviving writers fed a feed that could never arm and no reader. Its 0-of-0 red control goes with its subject -- not a §4b(4) climb, nothing climbed, the subject left. Leaving it standing is what would let a future lockstep row go green over dead code, which is how this one broke. Three stale prose citations repaired with it: std.observation's heartbeat-period note and human-units contract both named the deleted emitter in the present tense, and gunbc.observation_seed_render's seed_heartbeat_line claimed a byte-equality mirror holds it. It does not; the fn is retained as the target of the census's declared restoration, and the note now says so. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * review 56124: bind the no-fabrication row to the field it names, not to a spelling four readers share THE FINDING IS CORRECT AND THE ROW WAS THE FAILURE IT DESCRIBES. Its first draft asked for `unwrap_or_else(na)` and for the absence of the fabricating `.map(|pages| pages * 4)`. The first needle also matches the cgroup and vmstat readers, which have nothing to do with the field under test, so a regression that fabricated a zero for RSS *after* the string conversion -- .map(|pages| (pages * 4).to_string()) .unwrap_or_else(|| 0.to_string()) -- satisfies all three conjuncts. My own RED control mutated the one shape the third conjunct forbids and therefore proved less than it appeared to: the row detected the mutation I chose, not the class it named. A check that passes over the regression it is cited for is worse than absent (DESIGN 4b), and this one was already cited in the PR body as the standing control. THE REPAIR IS IN THE SEED, NOT IN A LONGER NEEDLE. Each field is now produced by ONE line that names the field, and one renderer decides what an absent reading looks like: fn floor_sampled_field(v: Option<u64>) -> String // Some -> number, None -> sentinel fn floor_statm_rss_kb() -> Option<u64> // None is the ONLY absent answer let rss_kb = floor_sampled_field(floor_statm_rss_kb()); let majflt = floor_sampled_field(tick(9)); let cpu_ms = floor_sampled_field(match (tick(11), tick(12)) { .. }); No field renders itself any more, so "fabricate a zero for this one field" is necessarily an edit to a line that names that field. The four conjuncts are those four lines, each measured unique in the file. Substituting a number for RSS means deleting the rss_kb conjunct; weakening the sentinel means deleting the renderer's None arm. The escape the review found has no spelling left. `4` also stops being a bare literal in the RSS path (`KB_PER_PAGE`), which is what made the old needle collide with an arithmetic shape rather than a fact. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Aug 27, 2026
…and the third cli_invoke/walk_plan_stage deletion increment (#9391) * Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns #9228 deleted claim_executor's plan/walk surface and named its .dag residue rather than sweeping it. This is that cut, plus one repair the census surfaced. WHAT WENT, AT THE ROOT: PlanFunction and the plan argv builders. The coproduct modelled a closed roster of --plan-function targets; the flag no longer parses and the entry every variant named (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the notice-title normalizer and shell suffix that existed only to feed them, claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/ floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and gunbc_ci_floor_only_script. The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell, release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it records is still open for that one spelling. gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that, and a second route to it here is the parallel authority the floor cut removed. The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore] harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness row. Their sole driver was the plan.dag recipes #9228 deleted. v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition:: DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That arm's roster was one prefix and the family above was its entire population; its own header said "DISSOLVES when the fixture stops authoring test fns", and this is that condition. Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both sides deleted here. The pre-push witness-corpus gate. Not on the brief, found by the flag census: pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only; its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms a gate" are deleted rather than weakened -- measured against the roster, the corpus binding was the only thing making them true, so they were green against the plan and false about the hook anyone runs. THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope): Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION witness, which has nothing to do with plan/walk. Its own note records that these same specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which died with affected-set selection. This would have been the third home. They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns: three modules, no test fn, no effects, one consumer. No discovery exclusion is needed because there is nothing to discover, which is a stronger construction than the dir-grain exclusion the old home required. AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied every row and the "strict-subset proof" the note describes was checked by nothing. ExpectScopedExactly compares the selected list to the expected list. EVIDENCE, by execution on a release gunbc (remote, one dispatch): control witness_touched_path_dispositions_hold -> true mutation give scope_isolated an import edge to scope_shared -> false The mutation is exactly the strict-subset violation; the old assertion could not see it. Rust: cargo check -p v1-compiler --bins clean, fmt clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Repair the scope-disposition witness's per-PR half, which the floor caught dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining and pins the disposition row count. Both moved with the rehoming and I checked only the long-lane witness, so strict preparation refused with a name-resolution error before any site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster growing by one row because the strict-subset proof needs three specimens where the old home carried two. The pin doing its job here is the argument for keeping it: a count that had to be updated by hand is exactly what stopped this rehoming from silently shipping a roster of a different size than the one the note describes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct. WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script() alone, because its other half emitted a `claim_executor --plan-entry` line naming an entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived was a callable verb that builds the release binaries, verifies the artifacts, and exits 0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported under the name of the larger one. §5's absorbing-fallback rule is about a failure arm that widens; this is its mirror at the success arm, a green that narrowed. WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the reviewer's other option and I am not taking it, on the grounds this branch already argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a second route to it is the parallel authority the floor cut removed. The verb also has no distinct job left -- "build the release binaries and verify the artifacts" already has a name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is not an authority that lost its body; it is a name with nothing left to denote. THE CENSUS, cut at the root and followed where it led: dag/tools/gunbc_ci.dag the entry module, deleted main.rs Commands::Ci + its arm the CLI verb gunbc.cli_dispatch_surface "ci" row the modeled CLI surface gunbc_cli_dispatch_surface.rs its generated mirror v2.workflow.ci_release_build_emit gunbc_ci_run_script, the wrapper std.emit_on_demand gunbc_ci_emission_surface the wet-surface row naming tools.gunbc_ci main emit_on_demand_kernel_witness_test its enrollment assertion wall_residue_live_test residue_gunbc_ci_clean a test fn whose subject was the deleted file ci_release_build_script itself is UNTOUCHED and still has three consumers (ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes. EVIDENCE, build lane on this tree (remote, one dispatch): required-ci: lane=build phases_run=2 failed=0 regen first_generation_equal=true -- the mirror edit is byte-equal to the emitter's own output, established by the gate rather than by my reading of the diff v2-emission blocking=0, census 3792 -> 3791, the one deleted module The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * Name the admission order's next-rung trigger, so the gap reads as unbuilt The header already said the surviving long-home-over-live-tree precedence has no executing discriminator and must not be cited as covered. It did not say what would make it coverable again, which leaves a reader unable to tell cannot-cover-yet from nobody-built-it -- the distinction DESIGN 4b(2) exists to keep. The trigger is a decline whose subject CAN collide with an existing one: a site that legitimately satisfies two decline reasons at once, so which reason it reports is a decision some input can get wrong. At that point a discriminating witness is authorable and is owed. Until then the correct response to the absence is to build that collision case, not to re-point a witness at a subject that cannot disagree with itself -- which would be permanently green by construction, and cited as coverage. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 1, 2026
…itations found BOTH were false XL-N caught two defects in the row. Both are fixed, and the second one turned the row's own content inside out in a way worth recording. DEFECT 1, THE REMEDY WAS ONE ARM AND NEEDED THREE. "Past tense with the date, never deletion" is correct only for a claim that WAS true and whose executor died. Past-tensing a never-true claim manufactures a false historical statement — "X USED TO resolve Y" asserts an execution that also never happened. And my own item 1 shows a third case: the instrument_sandbox live half DOES execute, via a local recipe, and OfflineLocalRecipe HAS a route — so the sentence names the WRONG AUTHORITY for a live relation, and past-tensing it would record a live relation as dead. That is a new contamination in the opposite direction, produced by the remedy itself, which is exactly what this row exists to name. A remedy mechanical enough to apply without reading WILL be applied without reading. The row now carries one remedy arm per origin, and the "never deletion" absolute is softened to a default: a sentence whose entire content is a false execution claim has no reasoning to preserve. DEFECT 2, AND IT IS THE MORE USEFUL ONE. XL-N asked me to verify the two cli_run.rs notes rather than inherit them, on the grounds that a row about unbacked claims should not itself contain one. It did contain two — and verifying killed BOTH of my origin-B citations: - floor_component_resource_checkpoint_note and floor_component_phase_journal_scaffold_note were REAL `data …: String` declarations in gunbc.floor_component_receipt. They were removed on 2026-08-30 by the prose-bankruptcy sweep #9752, which converted module-scope commentary rows into §4c annotations corpus-wide. - claim_executor DID resolve gunbc.floor_component_receipt: write_floor_component_receipt_at joined gunbc/floor_component_receipt.dag directly, from #7467 (2026-07-30) until #9228 deleted it (2026-08-25). So ORIGIN B — never backed at all — HAS ZERO VERIFIED INSTANCES here. It is recorded as conceivable and unmeasured, with its remedy arm, rather than as a population. I had asserted a two-origin class on the strength of two claims I had not checked. WHAT THE VERIFICATION FOUND INSTEAD is a third real origin with a corpus-wide producer: THE CITED SYMBOL DIED WHILE ITS CONTENT SURVIVED AS AN ANNOTATION. §4c makes an annotation uncitable by construction — no Accepted program can read one — so every citation of a row #9752 converted was dangling the moment that sweep landed. The population is that sweep's diff, not anything about this module. Its remedy is its own arm: name the module and the FACT, since there is no symbol left to cite; past-tensing would report the content as gone when only its citability is. RECOGNITION RULE EARNED, and it is now in the row: "resolves nowhere NOW" is not "never resolved". The distinction is decided by history, not by the working tree, and the instrument is `git log --all -S` over the DECLARATION FORM — which also separates the two attested origins by showing WHAT deleted the referent. Nothing but a reviewer asking for verification caught this. CORRECTIONS TO WHAT I ALREADY LANDED, applying the arms to my own diff: - ci_failure_class: my first pass DELETED the claim_executor comparison as false. It was true. Restored in the past tense with both dates, as the worked precedent it still is — remedy arm 1, not arm 4. - cli_run.rs, both sites: my first pass said the two notes "resolved in neither the receipt module nor anywhere else". False. Now records that #9752 made them uncitable and the pair was deleted after — remedy arm 2. docs/design-ledgers.md reprojected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz
gunbai-bot Bot
added a commit
that referenced
this pull request
Sep 1, 2026
…model with no producer, reciting a deleted transport in the present tense (#9858) * XL-0-RECEIPT: delete the floor component receipt pair — a well-built model with no producer, reciting a deleted transport in the present tense gunbc.floor_component_receipt and gunbc.floor_component_receipt_document describe, in the present tense, an alert that downloads an artifact named floor-component-receipt from a run id it is given and reads four named fields. That alert was falsifier-alert.yml, deleted on 2026-08-15 in the CI cut. A later lane read the module, believed the transport live, planned against it, and was corrected by its reviewing authority. That is premise contamination — the class the CI rung drop names in its own words — appearing in a module rather than in the canonical authority. CENSUS (reproduced on main 37e705c, not inherited), per medium, because a survivor stops being reached silently and a reach measurement over one medium reads exactly like a reach measurement: - PRODUCER: none. Nothing in src/ or dag/ writes target/floor-component-receipt.json; no Rust carries the schema string floor-component-receipt/v1 or its members. - CONSUMER, workflow argv: witnesses.yml uploads exactly four artifacts — required-floor-disposition, expected-red-roster-join, long-home-storage-agreement, required-floor-claim-cost. The receipt is not among them, and only witnesses.yml / fleet-converge.yml / fleet-desired.yml remain. - CONSUMER, import graph: the only importer of either module is their own witness test, which is a PEER of the subject, not a guard over a survivor. - CONSUMER, exported symbols: FloorComponentReceipt, FloorComponentReceiptDocument, FloorComponentReceiptSubject, ComponentAlertSummary and the schema/path/artifact-name rows resolve nowhere outside the pair. FloorComponentFailureMode and ComponentOutcomeRead appear only in two gunbc.non_fold_residue prose rows. - CONSUMER, Cargo [[bin]]: none. Rust: one string literal used as a test label in cli_run.rs, not a call. WHY THIS IS NOT A QUIET GUARD. Three questions decide: mechanism existence, join reachability, current occupancy. Yes/yes/zero is a healthy guard being quiet. Here the answer is NO at the first — there is no producer at all, so the join is UNREACHABLE rather than merely unoccupied. That distinction is the whole difference between retiring a dead model and deleting a live wall. DISPOSITION: delete. This completes floor-cut Step 2, which already named both files by identity as machinery that "falls out" once reachability confirms — they survived the cut and stopped being reached, which is exactly the third bound that plan records the census cannot see. DESIGN section 6: a new artifact with no final consumer is experimental residue, and the reviewer's test is whether it survives the terminal architecture AND is consumed by it. The model is well built; that is not an answer to that test. Landed with it: the two non_fold_residue frontier rows and their reason and dissolution strings; and every surviving citation of the pair rewritten to the past tense with the deletion and its date recorded, because a citation left naming a deleted symbol fakes a grep hit for the next reader. Two of those were already false before this change — ci_failure_class claimed claim_executor "already resolves gunbc.floor_component_receipt" (it never did), and cli_run.rs twice cited floor_component_resource_checkpoint_note and floor_component_phase_journal_scaffold_note, which resolved in neither the receipt module nor anywhere else. DURABLE HOME for the finding: a receipt appended to the reachability_read_as_occupancy row in gunbc.recurring_failure_mode, which had only the "do not delete a quiet guard" pole and now carries the discriminating counter-specimen for the other one. docs/design-ledgers.md is reprojected. NOT WIDENED, flagged instead: src/v2/workflow/ci_floor_peak_emit still emits a shell echo naming "the floor-component-receipt artifact", and its own emission does not appear in witnesses.yml. That is a separate unconsumed emit surface, not this cut. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz * Roster the class at its real grain: unbacked_execution_claim, one class with two origins XL-N extended the lane: the receipt's present-tense recital is probably not alone, and if so the class is not about the falsifier and not about the receipt. It is PROSE ASSERTING A LIVE EXECUTING RELATION THAT NO AUTHORITY BACKS. New roster row gunbc.recurring_failure_mode unbacked_execution_claim, projected into DESIGN.md's index and docs/design-ledgers.md; the recital half is lifted off reachability_read_as_occupancy, which keeps only the consequence for ITS rule (a good model with no consumer is still residue) and points at the new row. ONE CLASS, TWO ORIGINS, and that is a decision with a reason. Origin A is falsified by a later deletion (the receipt's alert). Origin B is FALSE WHEN WRITTEN — ci_failure_class claimed claim_executor "already resolves gunbc.floor_component_receipt" and it never did; cli_run.rs twice cited two notes that resolve nowhere. The origins differ, but the recognition rule and the remedy are identical, so they are a FIELD of one row rather than two rows; two rows would fork one recognition rule. I APPLIED XL-N's TEST, not the runs/enrolled one, reading each line in context rather than from the grep window. std.witness_admission witness_cadence_has_scheduled_route is the single authority: does the prose imply a live route for an arm it says is routeless? RESULT: SIX CANDIDATES, FIVE CONTAMINATING, ONE FALSE POSITIVE. CONTAMINATING (none in modules this PR otherwise touches — listed for routing, deliberately NOT fixed here, per the stop line): 1. dag/test/claim/instrument_sandbox_witness_test.dag fixture_line_remaining's preceding annotation: "stays per-PR while the live half runs on the falsifier lane". The live half is dag/test/claim/long/instrument_sandbox_live_witness_test.dag, enrolled on gunbc.ci_layer_roots falsifier_substrate_long_lane_rows = FalsifierSubstrateLongLane, routeless. Present-tense "runs". The same file's line 55 also claims that half moved "with a named executing consumer". NOTE: that half DOES carry a local recipe, and OfflineLocalRecipe has a route — so the repair is to name the recipe, not to call the witness unexecuted. 2. dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag self_host_use_site_verdict_behavioral_receipt_holds's annotation: "Live host effects — nightly falsifier Wet batch when frontier row is SelfEmitted with binding". FalsifierSelfHostWet, routeless. The condition is about frontier state, not about the cadence existing. 3. dag/test/claim/self_host_body_producer_behavioral_witness_test.dag self_host_body_producer_behavioral_receipt_holds's annotation: same sentence, same arm. 4. dag/test/claim/self_host_logic_behavioral_witness_test.dag self_host_logic_behavioral_receipt_holds's annotation: "so it RUNS IN the nightly falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not per-PR hermetic discovery or bin_witness_wet". The strongest instance — explicit present-tense execution, naming the routeless arm, and contrasting it against the one cadence that does have a route. 5. dag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag the annotation above perturb_cross_tree_import_corpus_green_holds: "Enrolled on falsifier_rehomed_bin_wet_entries (nightly batch 5)". THIS IS THE ARM THE NAIVE DISCRIMINATOR LOSES. "Enrolled on" is TRUE. "(nightly batch 5)" asserts a cadence that executes, and FalsifierRehomedBinWet is routeless. Minimal repair: strike "nightly" — the line already carries a local recipe, which is a real route. FALSE POSITIVE, and it is the exemplar of the remedy rather than a specimen: 6. dag/gunbc/commit_workflow.dag, the annotation above ci_floor_witness_enrollment_note's neighbours: "moved from per-PR to the 4-hour falsifier cadence" sits inside a block opening "RETIRED 2026-08-20 — the subject of this row no longer exists" and attributes the sentence to an "ORIGINAL CLAIM (operator ruling 2026-07-25)". Correctly framed already. Second false positive, already known and not re-derived: gunbc.rust_item_host_observation's "executes as the falsifier" — falsifier as a ROLE, the discriminating test, matching every keyword and meaning nothing of the kind. WHY THE REMEDY IS PAST TENSE AND NOT DELETION: the reasoning these sentences support usually survives its executor, and a reader who finds a dangling claim silently removed learns nothing. That is positional_citation's neighbouring rule — a citation left naming a deleted symbol fakes a grep hit — so the correction records the deletion rather than removing the name. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz * The remedy field branches on origin — and verifying my own origin-B citations found BOTH were false XL-N caught two defects in the row. Both are fixed, and the second one turned the row's own content inside out in a way worth recording. DEFECT 1, THE REMEDY WAS ONE ARM AND NEEDED THREE. "Past tense with the date, never deletion" is correct only for a claim that WAS true and whose executor died. Past-tensing a never-true claim manufactures a false historical statement — "X USED TO resolve Y" asserts an execution that also never happened. And my own item 1 shows a third case: the instrument_sandbox live half DOES execute, via a local recipe, and OfflineLocalRecipe HAS a route — so the sentence names the WRONG AUTHORITY for a live relation, and past-tensing it would record a live relation as dead. That is a new contamination in the opposite direction, produced by the remedy itself, which is exactly what this row exists to name. A remedy mechanical enough to apply without reading WILL be applied without reading. The row now carries one remedy arm per origin, and the "never deletion" absolute is softened to a default: a sentence whose entire content is a false execution claim has no reasoning to preserve. DEFECT 2, AND IT IS THE MORE USEFUL ONE. XL-N asked me to verify the two cli_run.rs notes rather than inherit them, on the grounds that a row about unbacked claims should not itself contain one. It did contain two — and verifying killed BOTH of my origin-B citations: - floor_component_resource_checkpoint_note and floor_component_phase_journal_scaffold_note were REAL `data …: String` declarations in gunbc.floor_component_receipt. They were removed on 2026-08-30 by the prose-bankruptcy sweep #9752, which converted module-scope commentary rows into §4c annotations corpus-wide. - claim_executor DID resolve gunbc.floor_component_receipt: write_floor_component_receipt_at joined gunbc/floor_component_receipt.dag directly, from #7467 (2026-07-30) until #9228 deleted it (2026-08-25). So ORIGIN B — never backed at all — HAS ZERO VERIFIED INSTANCES here. It is recorded as conceivable and unmeasured, with its remedy arm, rather than as a population. I had asserted a two-origin class on the strength of two claims I had not checked. WHAT THE VERIFICATION FOUND INSTEAD is a third real origin with a corpus-wide producer: THE CITED SYMBOL DIED WHILE ITS CONTENT SURVIVED AS AN ANNOTATION. §4c makes an annotation uncitable by construction — no Accepted program can read one — so every citation of a row #9752 converted was dangling the moment that sweep landed. The population is that sweep's diff, not anything about this module. Its remedy is its own arm: name the module and the FACT, since there is no symbol left to cite; past-tensing would report the content as gone when only its citability is. RECOGNITION RULE EARNED, and it is now in the row: "resolves nowhere NOW" is not "never resolved". The distinction is decided by history, not by the working tree, and the instrument is `git log --all -S` over the DECLARATION FORM — which also separates the two attested origins by showing WHAT deleted the referent. Nothing but a reviewer asking for verification caught this. CORRECTIONS TO WHAT I ALREADY LANDED, applying the arms to my own diff: - ci_failure_class: my first pass DELETED the claim_executor comparison as false. It was true. Restored in the past tense with both dates, as the worked precedent it still is — remedy arm 1, not arm 4. - cli_run.rs, both sites: my first pass said the two notes "resolved in neither the receipt module nor anywhere else". False. Now records that #9752 made them uncitable and the pair was deleted after — remedy arm 2. docs/design-ledgers.md reprojected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz * Cite the census that already owns this population instead of minting a second authority Found while pre-reading the five corrections for PR two: gunbc.deleted_cadence_reference_census ALREADY EXISTS and already owns the falsifier-cadence instance of this class. Twelve sites, a DeletedCadenceReferenceStanding vocabulary whose PremiseInvalidated arm is exactly "the prose asserts a cadence that no longer executes", and one GuaranteeRungDrop filed ONCE for the shared executor rather than per site — with its own note explaining that twelve copies of five fields would be twelve places to update when the route returns. The row I was about to land described that population as though it were an open finding. That is a second authority for a fact that already has one — the §3 violation this row's own remedy exists to prevent, committed inside the row, which is the third time this lane has caught the class reproducing itself in its own remedy. The row now CITES the census and copies nothing from it. What stays here is only the recognition rule and the remedy arms, which generalize past the falsifier; the population, its standings and its drop stay where they already live. TWO THINGS THIS CHANGES FOR PR TWO, recorded now so the next session does not re-derive them: 1. My five corrections are NOT in the census's twelve. The census subject is "authority rows whose stated enforcement, audit or backstop was the affected-set falsifier cadence" — rows that RELIED on the cadence. My five are witness-test annotations asserting their OWN cadence. Whether that is the same subject or an adjacent one is the first question PR two answers, and it is answered against the census's declared subject, not by me. Either way the five get enrolled or the subject gets widened deliberately — they do not get freelance prose edits beside an existing authority. 2. The corpus has already applied my remedy arm 1 correctly, twice, in the exact wording the row now recommends: ci_layer_roots bin_witness_wet_note carries "THE JUSTIFYING HALF OF THAT SENTENCE IS PAST TENSE (2026-08-26)" with the deleting commit and the census citation, and namespace_import_closure_behavioral_transport nic_doc carries "classification is membership, not execution". Those are the exemplars PR two should match rather than invent a house style beside. docs/design-ledgers.md reprojected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz * Origin 2's population is ZERO, not the sweep's diff — and the correction is better than the claim was gentle-bear-446 (XL-0-CITE) measured the population I flagged and it is zero. I verified both of their load-bearing facts rather than inheriting them. WHAT I HAD WRONG. The row reasoned that because §4c makes annotations uncitable, the prose-bankruptcy sweep broke every citation of a converted row, making the population the sweep's own diff. The premise is right and the conclusion is backwards: v1_compiler.cli_run annotation_erased_scan_text feeds the semantic passes, so annotation text is not in the tree the harvester walks, and v1_compiler.declaration_index admits citations from exactly two producers, citation_from_record_literal and citation_from_constructor_call. A plain name in annotation prose was never a citation, so the sweep could not break one. Measured zero today AND as of the sweep commit, on a control that discriminates in both directions — so it is not a zero produced by someone repairing it later. WHAT THAT LEAVES IS A BETTER ROW, not a smaller one. These citations bind READERS and no mechanism, so they belong in §4b's OUTSIDE THE MODELED GUARANTEE column — observed and repaired by reading, never gated. Calling them a dangling-citation population would have been rung inflation about a check that by construction cannot see them. The two cli_run sites remain genuine instances of the harm, and the honest statement is that no mechanical census would have found them. SECOND CORRECTION, TO A DATE BOTH I AND MY MANAGER REASONED FROM. We both framed this as a measurement of what the cited-symbol drop cost while it stood. It was not standing. Verified in the drop's own row: "THE RESTORATION TRIGGER FIRED ON 2026-08-25 AND THIS ROW IS RETIRED AS A DROP", restored strictly wider as v1_compiler.declaration_index in the parse phase of --required-ci. The sweep landed 2026-08-30, five days AFTER, under a live and wider check. AND THAT MISFRAMING HAS A CAUSE WORTH ROUTING, which I am reporting rather than fixing because it is load-bearing §4b modeling and outside this disposition: gunbc.design_document, the §4b rung-drop list — DESIGN.md's "The ones standing today:" is projected by `map(rung_drop_roster, d => …)` with NO filter, so it enumerates every row in the roster including retired ones. One of the nine listed is retired. The retirement is recorded only in prose inside the row's own body, so the projection cannot filter on it: the fix is a modeled retirement field on the drop carrier, not a predicate over existing data. This is the canonical authority asserting a live state its own ledger contradicts — this row's class in the document that defines it — and it is what led two sessions tonight to reason about an unguarded window that did not exist. docs/design-ledgers.md reprojected. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 11, 2026
…h the observation model again Lane B of the process-observability brief. Row: conformance-observability on gunbc.design_argument conformance_domains, homed on std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting; repository populations stay with gunbc.repository_census_observation, delivery with effects. Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall, seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults, rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its own rate/share functions. seed_heartbeat_line is the oracle over that input space; cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no interpreter on that thread); floor_resource_sample and the stall window become typed producers (FloorResourceSample, floor_stall_window_observation) with None for unread sources -- nothing formats a number outside the mirror. Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat, the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing; cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror byte-equal to the interpreter on the same two specimens (off the merge path: rung drop rust_unit_tests_off_the_merge_path). Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep. seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory] lived only in required_floor_runner.rs, so the census could not find its own row and the declined hygiene suite reported nothing. New executing witness observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep) are repaired to the restored subject and their standing restated -- the lockstep no-fabrication row had gone false a second time on the same cli_run split. DESIGN.md regenerated via generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
briansrls
pushed a commit
that referenced
this pull request
Sep 11, 2026
…h the observation model again (#11017) * §3b decision/selection conformance row; §3d reviewer narrowed to the hard laws Adds the conformance-decision domain to gunbc.design_argument conformance_domains, homed on std.decision (DecisionSubject, RealizationSelectionResult, SelectionReceipt, select_realization) and std.pareto (SelectionAxis, ParetoEntry, DominanceVerdict). The row is narrow: inhabitance of the decision/Pareto models, or a stated departure. Consumer route for the home: gunbc.spark.serving_deployment_selection select_serving_deployment and product.fleet_operating_point fleet_operating_point_selection call select_realization; exercised by test.claim.spark.serving_deployment_selection_witness_test and test.claim.realization_selection_witness_test. The s3d.selection-precedes-convergence reviewer keeps only the hard laws (no answer outrunning field/constraints/evidence/policy; a front is not a winner; missing funded evidence is never a fabricated zero or settled fact; goal assessment/ensure never choose) and says a stated home departure excuses none of them. Home-inhabitance tells moved to the conformance row. Witness: a_stated_departure_from_the_decision_home_is_admitted_while_the_selection_law_still_fails folds one plan through the existing review machinery -- conformance-decision answers DivergesStated (approved with reason), selection-precedes-convergence requests changes on the same file, the report fails; the converse plan with the laws honoured approves. gunbc.design_document: "missing authority" -> "selection authority" in §3d; §3b no longer claims the overlap counter proves the partition (review_criterion_identities_are_unique proves unique keys only and disclaims semantic exclusivity); scope/ownership mismatch distinguished from a non-resolving citation; §3d records the admitted row and that the effectful convergence cycle (plan, admission, actuation, readback) still has no consumed home. DESIGN.md regenerated via generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH * §3b observability conformance row; the floor heartbeat renders through the observation model again Lane B of the process-observability brief. Row: conformance-observability on gunbc.design_argument conformance_domains, homed on std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting; repository populations stay with gunbc.repository_census_observation, delivery with effects. Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall, seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults, rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its own rate/share functions. seed_heartbeat_line is the oracle over that input space; cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no interpreter on that thread); floor_resource_sample and the stall window become typed producers (FloorResourceSample, floor_stall_window_observation) with None for unread sources -- nothing formats a number outside the mirror. Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat, the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing; cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror byte-equal to the interpreter on the same two specimens (off the merge path: rung drop rust_unit_tests_off_the_merge_path). Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep. seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory] lived only in required_floor_runner.rs, so the census could not find its own row and the declined hygiene suite reported nothing. New executing witness observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep) are repaired to the restored subject and their standing restated -- the lockstep no-fabrication row had gone false a second time on the same cli_run split. DESIGN.md regenerated via generated_artifact_gate main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH * floor_sampled_field keeps its sentinel beside its remaining consumer Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH * the heartbeat mirror is crate-visible like its sample Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH * seed_heartbeat_line takes std.measure carriers across the seam Review 63436: cpu_ms/cgroup_charge_bytes/stall_window_ms/stall_user_cpu_ms (and elapsed_ms, rss_bytes) were bare Nat with a unit suffix. They are now Millisecond / ByteSize, on the precedent of ci_batch_summary_text's `work: Nanosecond`; the seed test builds each carrier through the interpreter's millisecond / byte_size constructor, so a caller handing the wrong unit cannot typecheck. Dimensionless counts stay Nat. Oracle test green locally (3/3); floor witness 5/5. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First cut of the "move off claim_executor" program. -9,858 lines (-46%), zero dead-code warnings, fmt clean, live modes proven by execution.
The structural fact
run()required--plan-entryafter every--required-*arm returned — and nothing supplies it. Not a workflow, not a hook, not an emitted yml. The plan function it defaulted to namedsrc/v2/workflow/ci_floor_plan.dag, which the 2026-08-15 floor cut deleted.So the plan walk, batch executor, coordinator/worker protocol, scoped-request machinery, perturb re-walk and falsifier failure-class helpers were unreachable, not merely unoccupied. DESIGN's reachability-read-as-occupancy row asks three questions; this population answers no to the first two, not just the third — the governing mechanism was removed, so no caller-authorable input reaches these arms.
The coordinator is the sharpest case:
maybe_run_floor_coordinatoris the first thingmain()does and returnsNoneimmediately unless--plan-functionnames a plan entry that does not exist. It spawned this binary as its own child from an arm that never armed.What the census surfaced
Cutting at the root rather than the leaves is what made this measurable:
cli_runimports fall unusedThat second number is a fact about
cli_run.rs, not this file:active_workset_admit, the heartbeat feed, the discovery roster snapshot, histogram/percentile projections,install_floor_compile_clean_receiptand 22 more existed only to feed machinery with no caller.Verified by execution (release binary)
--required-ciwitnesses.ymlinvokes — untouched--verify-build-artifactsfleet-converge.yml, both jobs — untouched--plan-entry--verify-build-artifactson a present binary--verify-build-artifactson an absent oneThe last pair is the discriminating red — that mode exists to refuse a "successful" build that produced a missing or zero-byte artifact, so a green without its red would establish nothing.
The no-mode arm refuses rather than defaulting. A silent success there would be the absorbing fallback one level up from the machinery just deleted.
What this does NOT claim
The
.dagresidue is not repaired here and is named rather than left to be rediscovered:gunbc.cli_invokestill builds--plan-entry/--plan-function/--notice-titleargv — dead transport, no workflow contains those wordsPlanFunctionsurvives inci_spec/cli_serviceswith its witnesssrc/v2/test/fixture/walk_plan_stage/is a fixture family whose only execution route was the recipes this PR deletes. Eight external touchpoints including a Rust integration test — its own census and its own cut, not a tail this one can sweep.Nothing in CI executed any of that before this PR or after it.
Context
Part of the operator-directed program to delete
cli_run.rs(47,491) andclaim_executor.rsinto.dagbehind a Bazel-compatiblegunbc build/gunbc testsurface. Measured consumer census for this binary: ~500 of 21,366 lines were on a live path, and every live mode is a thin argv shim delegating intocli_run— the engine was never in this file. Companion lanes are live on the enumeration primitive (#9221), the CLI dispatch model, and thecli_rungate-global retype.🤖 Generated with Claude Code