Skip to content

Delete the plan/walk surface nothing could reach (claim_executor 21,366 -> 11,508) - #9228

Merged
briansrls merged 7 commits into
mainfrom
session/merry-bear-547
Aug 25, 2026
Merged

briansrls merged 7 commits into
mainfrom
session/merry-bear-547

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

First cut of the "move off claim_executor" program. -9,858 lines (-46%), zero dead-code warnings, fmt clean, live modes proven by execution.

The structural fact

run() required --plan-entry after every --required-* arm returned — and nothing supplies it. Not a workflow, not a hook, not an emitted yml. The plan function it defaulted to named src/v2/workflow/ci_floor_plan.dag, which the 2026-08-15 floor cut deleted.

So the plan walk, batch executor, coordinator/worker protocol, scoped-request machinery, perturb re-walk and falsifier failure-class helpers were unreachable, not merely unoccupied. DESIGN's reachability-read-as-occupancy row asks three questions; this population answers no to the first two, not just the third — the governing mechanism was removed, so no caller-authorable input reaches these arms.

The coordinator is the sharpest case: maybe_run_floor_coordinator is the first thing main() does and returns None immediately unless --plan-function names a plan entry that does not exist. It spawned this binary as its own child from an arm that never armed.

What the census surfaced

Cutting at the root rather than the leaves is what made this measurable:

step result
delete the walk 251 items fall unreferenced
delete those 27 cli_run imports fall unused

That second number is a fact about cli_run.rs, not this file: active_workset_admit, the heartbeat feed, the discovery roster snapshot, histogram/percentile projections, install_floor_compile_clean_receipt and 22 more existed only to feed machinery with no caller.

Verified by execution (release binary)

invocation result
--required-ci the one mode witnesses.yml invokes — untouched
--verify-build-artifacts fleet-converge.yml, both jobs — untouched
no mode exit 2, typed refusal naming the live modes
--plan-entry exit 2, unknown argument
--verify-build-artifacts on a present binary exit 0
--verify-build-artifacts on an absent one exit 1, fail-closed

The last pair is the discriminating red — that mode exists to refuse a "successful" build that produced a missing or zero-byte artifact, so a green without its red would establish nothing.

The no-mode arm refuses rather than defaulting. A silent success there would be the absorbing fallback one level up from the machinery just deleted.

What this does NOT claim

The .dag residue is not repaired here and is named rather than left to be rediscovered:

  • gunbc.cli_invoke still builds --plan-entry / --plan-function / --notice-title argv — dead transport, no workflow contains those words
  • PlanFunction survives in ci_spec / cli_services with its witness
  • src/v2/test/fixture/walk_plan_stage/ is a fixture family whose only execution route was the recipes this PR deletes. Eight external touchpoints including a Rust integration test — its own census and its own cut, not a tail this one can sweep.

Nothing in CI executed any of that before this PR or after it.

Context

Part of the operator-directed program to delete cli_run.rs (47,491) and claim_executor.rs into .dag behind a Bazel-compatible gunbc build / gunbc test surface. Measured consumer census for this binary: ~500 of 21,366 lines were on a live path, and every live mode is a thin argv shim delegating into cli_run — the engine was never in this file. Companion lanes are live on the enumeration primitive (#9221), the CLI dispatch model, and the cli_run gate-global retype.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 7 commits August 25, 2026 19:34
…symbols it was importing to do it

claim_executor: 21,366 -> 11,508 lines. Zero dead-code warnings, zero errors,
fmt clean, and the two live modes verified by execution.

WHY THIS IS A REACHABILITY CUT AND NOT AN OCCUPANCY ONE. run() required
--plan-entry after every --required-* arm returned, and nothing supplies
--plan-entry: not a workflow, not a hook, not an emitted yml. The plan function
it defaulted to named src/v2/workflow/ci_floor_plan.dag, which the 2026-08-15
floor cut deleted. So the plan walk, the batch executor, the coordinator/worker
protocol, the scoped-request machinery, the perturb re-walk, the falsifier
failure-class helpers and their terminal reporting were not quiet guards that
happened to be empty -- their governing MECHANISM was removed, and no input any
caller can author reaches them. DESIGN's reachability-read-as-occupancy row asks
three questions; this population answers no to the first two, not merely to the
third.

The coordinator is the sharpest case: maybe_run_floor_coordinator is the first
thing main() does, and it returns None immediately unless --plan-function names
a plan entry that does not exist. It spawned this binary as its own child with
--floor-worker-role/--scoped-batch-id, from an arm that never armed.

WHAT THE CENSUS SURFACED, which is the point of cutting at the root rather than
the leaves. Removing the walk left 251 items unreferenced; deleting those left
27 cli_run imports unused -- active_workset_admit, the heartbeat feed, the
discovery roster snapshot, the histogram/percentile projections,
install_floor_compile_clean_receipt and the rest. That is a measurement about
cli_run.rs, not about this file: a quarter of the seam between the two existed
only to feed machinery with no caller.

WHAT REMAINS AND IS PROVEN BY EXECUTION (release binary, four cases):
  --required-ci                          the one mode witnesses.yml invokes
  --verify-build-artifacts               fleet-converge.yml, both jobs
  no mode                     -> exit 2, typed refusal naming the live modes
  --plan-entry                -> exit 2, unknown argument
  --verify-build-artifacts on a present binary   -> exit 0
  --verify-build-artifacts on an absent one      -> exit 1, fail-closed
The last pair is the discriminating red: the mode's whole purpose is refusing a
'successful' build that produced a missing or zero-byte artifact, so a green
without its red would establish nothing.

The no-mode arm REFUSES rather than falling through to a default. An argv this
binary no longer understands must stop the line; a silent success would be the
absorbing fallback one level up from the machinery just deleted.

WHAT THIS DOES NOT CLAIM. The .dag residue is NOT repaired here and is named
rather than left to be rediscovered: gunbc.cli_invoke still builds
--plan-entry/--plan-function/--notice-title argv (dead transport -- no workflow
contains those words), PlanFunction survives in ci_spec/cli_services with its
witness, and src/v2/test/fixture/walk_plan_stage/ is a fixture family whose only
execution route was the recipes this commit deletes. That family has eight
external touchpoints including a Rust integration test, so it is its own census
and its own cut, not a tail this one can sweep. Nothing in CI executed any of it
before this commit or after it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review on #9228 named two (FloorBatchClampAuthority, ResolvedFloorBatchClamp) as
the ones it spot-checked. There were five: ParsedRunnableProfile,
ProcessTermination and ScopedExecutionRequest carry the same shape. Swept by
pattern rather than by the two cited, because a cosmetic residue found by
inspection is a population, not a list -- fixing only the named two would leave
three identical stubs behind and read as though the class had been handled.

Each is the shell of an impl whose every method was deleted as unreachable. The
types themselves are still constructed and are unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…census

A workflow_dispatch job with ZERO runs in its entire existence, its .dag emitter
(286 lines), its GeneratedArtifact registration, the claim_executor mode, and the
266-line cli_run census that had no other consumer.

WHY THE WHOLE CHAIN AND NOT JUST THE FLAG. The mode was the census's only caller
and the workflow was the mode's only caller, so deleting any one link would have
left the other two as an authority for a fact nothing asks. The fail-closed
census did the finding: removing the GeneratedArtifact variant surfaced five more
sites (the roster list, the commit-policy arm, the equality arm, the emit import
and the yml-parse arm) that a name-grep of the workflow path alone would have
missed.

THIS IS A DECLARED CAPABILITY DROP, not a dead-code sweep, and saying so is the
point of the entry. WHAT IS GONE: the only route to a located corpus-wide
type-judgment population -- the blocking/advisory/unclassified partition over the
required run's own subject, with its planted control. DESIGN 4b names exactly
this gap in the other direction: the advisory residue is computed on every
required run and counted by nothing, and a frontier whose deficit frequency is
unobservable never ranks for climbing. That argument is why the mode was built.

WHY IT GOES ANYWAY: it was never executed once. An instrument nobody has ever
run is specification-without-execution, not coverage, and a workflow_dispatch job
nobody dispatches cannot be the thing that makes a frequency observable. Keeping
the flag while deleting the workflow would be worse -- a surviving mode no
workflow invokes guards nothing and would be cited as though it did.

POPULATION: one capability, the corpus type-judgment measurement. PREVIOUS
STATE: reachable by manual dispatch, never reached. TEMPORARY STATE: no route.
RESTORATION TRIGGER: the measurement returns as a QUERY over the build/test
target graph -- the population is a property of what the required run compiled,
which is exactly what a target-graph query answers -- rather than as a mode on a
binary this program is deleting. It does not return as a flag.

NOT CLAIMED: this does not repair src/v1/stage0/src/bin/infer_semantics_witness.rs,
which #8952 (ffb0170) broke by adding TypeEnv.authored_import_names without
updating six initializers there. That binary is in fleet-converge.yml's build
list and does not compile on main today; it is untouched here and is not this
cut's to fix.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cli_run tests review 55847 caught

Review 55847 found four tests in cli_run.rs still referencing corpus_judgment_*
symbols the census deletion removed. It was right, and it had found one end of a
larger population: 542 test functions across the two files tested machinery this
branch deleted. claim_executor 11,380 -> 6,270.

WHY THE REVIEWER SAW FOUR AND NOT 546. Two masks, and the second is the one worth
recording. My own verification ran `cargo check --bin claim_executor` WITHOUT
`--tests`, so a test module referencing a deleted symbol produced no diagnostic
at all -- the deletion was verified against a target that does not compile tests.
Then, when I did run --tests, the seed's lib failed FIRST on main's unrelated
TypeEnv breakage, and 526 downstream errors were masked behind that one. A masked
run and a clean run rendered identically: 526 errors and 1 error look like
progress rather than a different question being answered. DESIGN's
execution-provenance row names exactly this, and it cost two wasted sweeps here.

DELETED SURGICALLY, NOT WHOLESALE, and the distinction is load-bearing. The
obvious cut was `mod tests` entire -- 5,514 lines, 518 of the 526 errors. It
would have been wrong: `verify_build_artifacts_reds_on_zero_byte` lives in that
module and is the discriminating RED for a mode fleet-converge.yml invokes twice.
So the cut deletes only test functions that FAIL TO COMPILE because their subject
is gone, iterated to a fixed point against the compiler. 38 tests survive,
including all four verify_build_artifacts controls (accepts / zero-byte / missing
/ empty-arglist) and the five attempt_identity refusals.

That is the enumerate-before-deleting rule applied to a test module: a module is
deleted for one reason and takes everything in it unless its contents are
enumerated first. The compiler did the enumeration.

WHAT IS NOT CLAIMED. src/v1/stage0/src/bin/infer_semantics_witness.rs is still
broken by #8952 (six TypeEnv initializers) and is untouched here; it is in
fleet-converge.yml's build list and does not compile on main. The one-line lib
fix at cli_run.rs is present because without it nothing on this branch can
compile tests at all -- deep-ram-742 ships the same repair in #9222 and the
duplicate is deliberate, not a fork: identical text, and whichever lands second
merges clean or drops out.

.gitattributes loses its corpus-type-judgment merge row, which review 55847 also
flagged. That row is DERIVED from the artifact roster this branch already
trimmed, so the committed file was stale against its own authority rather than
carrying an independent fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…e time

Review 55875 is correct and the finding is the important kind -- not a leftover,
a REACHABLE MUTATING PATH behind a deletion I had claimed was complete.

WHAT I GOT WRONG. main() read std::env::args() ITSELF and dispatched
maybe_run_floor_coordinator before run() parsed anything. So deleting
--plan-function from run()'s parser did nothing to the coordinator's
reachability. My earlier claim that the coordinator "returns None immediately
unless --plan-function names a plan entry that does not exist" described the
guard correctly and the DISPATCH not at all: the guard tests argv, and argv still
carried the flag.

WHY IT WAS WORSE THAN BEFORE THIS BRANCH, which is what makes it a defect rather
than an incomplete cut. With --plan-function deleted from one parser and live in
the other, the flag answered `unknown argument` for every value EXCEPT
gunbc_ci_floor_plan -- the one value that ran the entire coordinator. And that
path is not inert: it create_dir_all's a receipt directory, remove_file's the
worker-observation receipt, the scoped-execution requests and the phase journal,
arms a scoped receipt and spawns workers, all before any refusal could fire. A
deletion that leaves the single most destructive entry point as the only reachable
one is the opposite of fail-closed.

THE LESSON IS THE CUT'S, NOT THE COORDINATOR'S: a flag is not deleted when one of
two parsers stops reading it. The repair is at the root -- main() no longer reads
argv at all, run() is the only thing that does -- and the census then took the
worker/scoped-request machinery with it: 6,275 -> 5,069 lines, 57 further test
functions whose subjects went, iterated to a joint fixed point over errors and
dead code.

PROVEN BY EXECUTION, on the exact invocation the review named:
  claim_executor --plan-function gunbc_ci_floor_plan --source-root dag
    -> "unknown argument: --plan-function", EXIT=2, and no receipt file created
  --verify-build-artifacts on a present binary -> 0
  --verify-build-artifacts on an absent one    -> 1
The negative control matters here specifically: the bug was that a mutating path
ran before the refusal, so "it refuses" is only half the claim -- the other half
is that nothing was written on the way to refusing.

claim_executor is now 5,069 lines against 21,366 on main.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… warnings and my check did not

CI red at bda1331, all three jobs, one root cause: ExitStatus, std::time::Instant,
build_floor_discovery_request and verify_floor_discovery_terminal_for_coordinator
lost their last users when the coordinator and its worker machinery went, and the
required build compiles with -D warnings, so an unused import is an ERROR there.
`floor` failed identically; `witnesses` is only the gate that reports both.

THIS IS THE THIRD TIME ON THIS BRANCH THAT A CHECK WAS GREEN AND THE CLAIM WAS
WRONG, and it is the same defect each time: verifying a deletion against a target
that cannot observe its dependents. --bin without --tests could not see 526
orphaned test references. A broken lib masked those behind one error. And a bare
cargo check cannot see an unused import, because unused-imports is a WARNING
until -D warnings makes it fatal -- so the instrument I was steering by was
strictly weaker than the one that gates merge.

The repair is to use the gating instrument, and to PROVE it is the one running
rather than assume the flag arrived. Planted control, executed: with
RUSTFLAGS="-D warnings" forwarded (ctrl-build prints `forwarding env: RUSTFLAGS`),
an added `use std::collections::BTreeSet;` produces `error: unused import`, not a
warning. The clean result on the real tree is therefore load-bearing rather than
a flag that silently never reached rustc.

No behavior change: four import names, zero call sites.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ch was masking this branch's test-target observation
@briansrls
briansrls merged commit 151e771 into main Aug 25, 2026
2 checks passed
@briansrls
briansrls deleted the session/merry-bear-547 branch August 25, 2026 23:07
gunbai-bot Bot pushed a commit that referenced this pull request Aug 25, 2026
… test target main inherited

Rebuilt on current main rather than merged into it. The old branch shared three
commits with #9228 and conflicted in twelve hunks where "ours" was a
pre-deletion snapshot -- hand-resolving that risks silently restoring code
#9228 had just deleted, so the two intentional changes were replayed onto main
instead. Force-push is the honest vehicle here; a merge commit would have carried
a resolution nobody could audit.

THE ENROLMENT IS THE POINT, and it is a climb rather than a cut.
run_required_v2_emission_selftest -- the red fixture that must be refused on the
annotation cause and the green fixture that must emit -- was reachable ONLY
through a standalone flag no workflow invoked. So the required run's v2-emission
phase ran a producer whose REFUSAL had never once been shown to fire; a green
established that the emitter emitted, not that it still refuses what it must.
DESIGN 4b(4): a class's discriminating RED and positive control stay ENROLLED as
the evidence the rung is real. Unenrolled evidence is not weaker evidence, it is
none. It now runs inside the phase, ahead of the producer, and a failure lands in
phase_failures like any other. Measured before enrolling: passes, about a second.
The standalone flag goes in the same motion -- two routes to one fact, and only
the enrolled one executes.

TWO MODES DELETED, and only two:
- --measure-cgroup-peak: its own comment names the `rust_tests` job as its caller.
  That job was deleted. An orphan whose stated consumer is gone.
- --required-cited-symbol: DESIGN's 2026-08-23 row already declares this drop and
  states the surviving flag guards nothing, with a restoration trigger putting the
  wall at ingestion. Deleting the flag agrees with that row rather than leaving a
  mode that reads as coverage.

KEPT AGAINST THIS PROGRAM'S OWN BIAS: --heads-reading-differential and the three
--behavioral-receipt-* modes are INSTRUMENTS with entry points, not gates.
DESIGN's 2026-08-24 ruling is that a measurement worth re-deriving is worth an
entry point. The target-model lane confirms both shapes they need are expressible
(addressable but absent from the //:required roster; a differential needs its own
TestStanding arm rather than the Bazel status arm, which carries only
PASSED/FAILED and would erase the divergence). They migrate; they do not get
rescued.

ALSO REPAIRS WHAT MAIN INHERITED. #9228 merged before its last commit landed, so
main carries four errors in claim_executor's TEST target: an orphaned
witness_walk_flags_tests module and a cfg(test) classify_witness_expectations
helper over three deleted types, plus seven dead test helpers and the imports the
cited-symbol deletion orphaned. CI cannot see these -- the required run compiles
--bin, never --tests.

EVIDENCE, both controls run rather than one:
- transport: ctrl-build reports `forwarding env: RUSTFLAGS`, so -D warnings
  reached rustc.
- subject: a planted `super::deliberately_absent_symbol_zzz()` produces its exact
  diagnostic under this branch's own --tests invocation, proving test modules
  entered the observed population. Clean is therefore a measurement, not a
  silence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
CI on 45270ab: both lanes died at "Build the witness fold" with the lane steps
SKIPPED, so nothing was checked -- one compile failure reported three times, not
three failures.

  error: unused imports: `make_eval_context`, `resolve_entry_graph_shared`, and `run_value`
  error: unused imports: `ExecutionMode`, `InterpContext`, and `Value`
  error: could not compile `v1-compiler` (bin "claim_executor") due to 2 previous errors

NEITHER BRANCH HAS THIS DEFECT ALONE. main's #9228 ("Delete the plan/walk surface
nothing could reach", claim_executor 21,366 -> 11,508) removed the last callers
of all six; this branch kept the import list. The imports go dead only in the
merge, and CI evaluates the merge ref, which is why the head built clean here and
failed there. Every surviving use is fully qualified
(v1_compiler::cli_run::make_eval_context), and `Value` is re-imported locally at
its one use site, so the removals are safe.

TWO DEFECTS IN MY OWN INSTRUMENT, named because both fail toward a green:

1. CI builds with -D warnings and the workflow never says so --
   actions-rust-lang/setup-rust-toolchain@v1.16.0 sets RUSTFLAGS: -D warnings by
   default. Local dispatches built without it, so unused imports were warnings
   here and errors there. Reproduced with RUSTFLAGS forwarded: BUILD-RC=0.

2. My build checks grepped `^error`, but cargo emits ANSI escapes, so the real
   line is \e[1m\e[91merror and never matches at column 0. Every "no errors" I
   reported from those dispatches read a filter that COULD NOT MATCH AN ERROR.
   That is the worse of the two: it would have hidden any compile failure, not
   just this class.

VERIFIED ON THE MERGED TREE, under CI's own strictness:
  cargo build --release --bin claim_executor --bin gunbc, RUSTFLAGS=-D warnings  rc=0
  claim_executor --required-regen   first_generation_equal=true, no drift
  main_wet x2, all three projections byte-IDENTICAL before and after:
    ba373e57...  DESIGN.md
    26148967...  dag/gunbc/stage0_crate_layout_generated.dag
    698a5209...  src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs
  so the text-merged DESIGN.md IS the projection of the merged authorities and
  owes no regeneration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot added a commit that referenced this pull request Aug 26, 2026
… integrity, the cited-symbol wall, and module authorship facts on ONE construction, as DESIGN's two next-rung triggers require, instead of three corpus walks (#9211)

* wip: ingestion-time per-module declaration index

* declaration index: debt roster, mode deletion, seed-growth carrier, DESIGN rows

* The kernel-type escape is admitted by the seed, so count it instead of hiding it

v1.compiler.resolve get_exported_names appends every kernel_type_set key to
every module's export surface, so `import m { Int }` is admitted whatever `m`
declares. Measured against the installed compiler: a module whose whole body is
one fn returning Int, imported as `{ Int, String, Bool }`, compiles to 6 files
with 0 diagnostics -- readable because the same root with a bogus member refuses
with a located MissingExport.

The index mirrored that with a bare `continue`, which zeroes the deficit's
frequency by construction and is why nothing ever ranked it for repair. It
cannot be refused here: editing get_exported_names is NewLanguageBehavior and
the v1 freeze refuses it. So it is now counted as import_members_kernel_named
and printed beside every other denominator.

Kernel-named and declared are independent axes: over std.types, five of the
eight keys are genuinely declared (Bool, Secret, Json, Unit, Bytes) and three
are not (Int, String, Float). The predicate splits them by asking
import_surface_has first, and the fixture now asserts that behaviour rather
than leaving it to the ordering.

Also records why the authorship arm is not a second MandatoryTagRegion: that
door does not fire on the gunbc compile path, measured at 5 files 0 diagnostics
against a positive control. And answers the debt contract's four conditions,
including the two-directional typed disposition that separates 'repaired the
citation' from 'deleted a row to buy a green'.

* Scope the debt roster to the corpus it is a fact about, and make its own red authorable (review 55817)

index_findings folded in citation_debt_findings, which joins the 38-row
production roster against whatever index it is handed. A fixture tree holds a
handful of probe.* modules, so all 38 rows were trivially absent and every
fixture received 38 CitationDebtRowStale findings it never planted. Measured:
1 passed, 8 failed -- every planted-red and every positive control in the file,
i.e. the whole of this change's DESIGN 4b evidence, was non-executing.

The repair is a denominator fix rather than a gate. The four index-derived arms
ask questions about the modules in front of them and are meaningful over any
tree; the debt roster is a fact about ONE corpus. So it moves to corpus_findings,
which the required run and the standalone sweep call, and index_findings keeps
the four. Gating the arm on a corpus-shape signal was the other available repair
and would have been a smuggled heuristic (DESIGN 4).

The arm's own red was also unauthorable, which the review did not say and which
is the finding underneath it: the roster was read from inside the function, so
no fixture could hand it one. The join now takes its roster as a parameter and
both directions of the contract are planted -- a row whose citation still
refuses is live and suppresses that citation's finding, a row whose citation
stopped refusing is spent and refuses by name -- plus a regression control
asserting the arm is absent from index_findings and present in corpus_findings.

* Close the class the review found one instance of: both rosters are parameters, defaulting empty

review 55817 found citation_debt_findings reading PRE_EXISTING_CITATION_DEBT
from module scope, which made its own RED unauthorable. Asking the same question
of the other four arms found a second instance, and a worse one:
cited_symbol_findings SUPPRESSED citations against the same constant. A spurious
refusal is loud; a spurious suppression is a citation the wall quietly declines
to judge, so that arm could have stopped enrolling an entire class with every
fixture green.

Both rosters are now parameters and both default to EMPTY rather than the
production constant, so index_findings judges every citation in whatever tree it
is handed and the roster is reachable from exactly one place, corpus_findings.

This also corrects an assertion I added in the previous commit: it claimed an
enrolled debt row suppresses its citation's finding while calling index_findings,
which reads the production roster and does not contain the fixture's row. It now
uses the parameterized form and pairs it with the empty-roster case, because
'suppressed' means nothing unless the same tree refuses when unenrolled.

The other two arms were checked and are not this class: import_member_findings
reads kernel_type_set, a language fact whose behaviour the fixture exercises with
a real kernel name, and lens_authorship_findings reads the decl name it checks
for. Both REDs are authorable.

* Close the seam the repair created, name the empty-default rule, fix two fixture bugs

SEAM: both rosters now enter from one place, corpus_findings, which makes the
WIRING a fact needing evidence -- unreachable-from-index_findings is proven by
construction, but reachable-from-corpus_findings was an assertion about a call
site. Pass an empty roster there and the suppression arm would be perfectly
evidenced at the fixture boundary and silently disabled where it matters.
corpus_findings_is_wired_to_the_production_suppression_roster declares a module
the production roster names and requires the same tree refused unenrolled and
suppressed enrolled.

RULE: a policy roster passed as a parameter defaults to the IDENTITY ELEMENT OF
THE JUDGMENT, never to the production value. Empty means judge everything, the
strictest answer, so a forgetful caller gets MORE refusals. Defaulting to the
production roster would give a forgetful caller silent suppression -- the defect
the parameter exists to close, reintroduced through the default.

FIXTURE BUGS, both mine, both found by execution rather than by reading:
- kernel_named_counter_splits_declared_from_undeclared authored its
  declares-nothing module with the wrong module header, so the import target did
  not exist and the claim was skipped as target-absent: counted 0, expected 1.
- the same fixture used a single-variant coproduct, which needs a leading pipe;
  it now uses a two-variant form that parses unambiguously.
- a_debt_row_whose_citation_still_refuses_is_live asserted suppression through
  index_findings, which reads no roster (fixed in the previous commit).

* Every planted red asserts its own plant is well-formed before the guard's verdict

Two fixture defects in this file produced EXACTLY the observation a broken guard
produces:

  wrong module header      -> import target absent -> claim SKIPPED  -> no finding
  single-variant coproduct -> parse question       -> not admitted   -> no finding

A malformed plant and a broken guard are indistinguishable at the assertion, so
'no finding' was a three-way ambiguity -- fixture malformed, plant never reached,
guard broken -- and the repair pressure points at the production predicate. That
is how a correct guard nearly got 'fixed' to satisfy a bad fixture. It is the
not-applicable-versus-malformed conflation DESIGN names, arrived at from the
fixture side: SKIPPED and ADMITTED are different states and the assertion could
not see the difference.

plant / plant_declares / plant_import_target_resolves / plant_cites assert the
fixture is well-formed and that the claim REACHED the admit-or-refuse decision,
before any assertion about the verdict. Then the guard's answer is the only
remaining variable, and a failure says which of the three it was.

* The corpus run found the roster's own prose false and one row's field wrong

MEASURED, one dispatch, 3993 files parse-clean:
  modules=3993 declared=76851 import_members=80076 citations=1496 debt=41
  in_fixtures=161 outside_index=134 kernel_named=1944 lens_modules=71

Two defects, both in the inherited roster, both found by running the wall rather
than by reading it.

1. THE PROSE WAS FALSE. The roster's doc comment claimed four rows at its end
were the deleted census's planted controls. Enumerating all 38 rows finds no such
row -- the rows were never added, only described -- and the corpus run duly
reported all four controls as ordinary refusals. They are deliberately false
citations, the discriminating evidence that a resolver refuses; a wall that
refuses them refuses the evidence for its own mechanism.

They are NOT enrolled as debt, because debt is a monotone contract that may only
shrink and these never retire (DESIGN 4b(4): an expecting-red probe that greens
flips to a permanent regression control). PLANTED_CONTROL_CITATIONS is a separate
carrier whose staleness arm is INVERTED: a debt row refuses when its citation
stops refusing; a control row refuses when its citation stops refusing too, but
because the control has lost its discriminating power. Same trigger, opposite
meaning, so two carriers rather than one with a flag.

The false claim is recorded as false rather than silently corrected. A stale
statement inside the carrier built to stop stale statements is the specimen.

2. ONE ROSTER ROW'S FIELD WAS WRONG, and it produced two CONTRADICTORY findings
about one citation in one run: extdeps.tcgplayer.store cites UpdateSkuPrice with
field NamedField { price }, while its roster row carried an empty field. So the
suppression missed it (reported CITED-DECLARATION-ABSENT) and the staleness arm
saw no live row for the empty-field identity (reported CITATION-DEBT-ROW-STALE).
One identity error, both arms wrong, in opposite directions.

* Paired inverse arms must run in one report; assert the desynchronization instead of noticing it

One roster row carrying an empty field where its citation carries
NamedField { price } made the two arms report CONTRADICTORY findings about ONE
citation in ONE run: the suppression arm called it unenrolled debt, the staleness
arm called its row spent. Both locally correct, both wrong.

NEITHER ARM CAN DETECT THAT ALONE -- each is right about its own half -- so the
only observable is the two answers being present together and disagreeing. That
was caught by a human reading two lines of a report, which is not a mechanism.

Two things follow, and neither is the row fix (already landed):

1. THE RULE, recorded on corpus_findings because that is where a future split
   would be decided: paired inverse arms must run in one report over one subject
   set. Splitting them across jobs, cadences or roster arguments does not weaken
   the pair, it destroys it, and the reasons for splitting are usually good ones
   about job granularity. Someone will propose it; the receipt is there for them.

2. THE WALL: a_roster_row_on_the_wrong_identity_desynchronizes_both_arms plants
   the exact identity mismatch and requires BOTH findings to appear, then repairs
   the row to the citation's real identity and requires NEITHER. That converts a
   lucky catch into something that fails by execution.

* Fix the test import block my own codemod silently failed to update

The plant-precondition and planted-control commits added helpers using index_get,
DeclarationIndex, ModuleDeclarationRecord and planted_control_findings_against,
and the edits meant to add them to the use block were plain string replaces
against a form cargo fmt had already reflowed. They matched nothing and said so
to nobody, so the test target stopped compiling: E0425 cannot find function
index_get, E0425 cannot find type DeclarationIndex, 7 errors.

Caught by execution, not by review: the corpus half of that dispatch ran and
printed its findings while the suite half never compiled, which is exactly the
shape where a run looks productive and one of its two questions was never asked.

Every other edit in this branch asserted its match count; the import edits did
not, which is the whole difference. Rewritten by matching the use block as a
unit with an assertion on the match count, and every symbol the file references
was checked as exported before committing.

* Correct an overclaim in my own carrier: decl_facts IS still consulted by the required run

The seed-growth carrier said the corpus-walk half of the DESIGN triggers is
discharged and 'decl_facts is no longer consulted by any required check'. The
first half is right for the three questions this change answers; the second half
is false and I wrote it without checking.

decl_facts has live .dag consumers, and several are floor-discovered witness
modules -- decl_facts_reflection_witness_test, record_construction_census_witness_test,
floor_expected_red_coherence_witness_test among them -- so the corpus walk still
executes inside the required floor for their sake. What IS true is narrower and
still worth the change: the citation wall no longer reaches decl_facts at all,
because --required-cited-symbol and its lens are off the required path entirely,
and the three integrity questions now come from one construction instead of three
walks. Retiring the remaining consumers is a separate cut.

Caught by re-reading the request against the carrier rather than by a checker,
which is the same failure this PR exists to make mechanical: a claim about a
population nobody had counted.

* Declare the residue this wall does not close: it checks symbol resolution, not claim truth

A citation wall answers 'does this name exist'. Nothing in this construction
answers 'is this count right', and the two halves are independent. Named as
declared residue so the next reader finds the gap instead of assuming the wall
covers it.

The distinction is measured, not hypothetical -- twice on this branch, both times
inside typed carriers, both times a population claim nobody had counted:

  the debt roster's doc comment  'four rows at the end are the planted controls'
                                 -> the rows were never added, only described
  this carrier, same author      'decl_facts is no longer consulted by any
                                 required check' -> three live floor-discovered
                                 consumers

Why the wall cannot reach either: decl_facts is a REAL SYMBOL that RESOLVES. The
sentence claiming nothing consults it would pass a cited-symbol census cleanly,
because every name in it is true and only the QUANTIFIER is false. DESIGN 4c
states the general form -- prose is unfalsifiable by construction, which is why a
count belongs in a typed carrier and not in a sentence.

Rung stated honestly: one was caught by running the wall, the other by re-reading
the carrier before merge. The second is review diligence, so the class sits at
MITIGATABLE and nothing here climbs it. NEXT-RUNG TRIGGER: a quantified claim in
a carrier is DERIVED rather than AUTHORED, so the sentence cannot disagree with
the corpus because it is not a sentence.

* Record that the four control identities are the surviving authority when the dead lens is cut

Review 55841 asked to confirm v2.lens.cited_symbol_resolution is retired rather
than left as dead parallel representation. Measured rather than asserted, because
'it is dead' is the claim shape this branch already got wrong once: of the 27
symbols unique to that lens, the only references outside it are one prose row in
gunbc.roster_registry, two prose mentions in fast witnesses (a String note and a
// comment), and nine real uses in the long/ witness, which is declined before the
fold and never executes. NO EXECUTING witness calls any function it declares.

So it is dead, not competing. But this change does add a second copy of the four
planted-control identities, and the duplication needed a named terminus rather
than an assurance. Recorded: when the lens is cut, these identities are the
SURVIVING authority -- the deletion removes the dead copy, never the evidence.
DESIGN 4b(4) keeps a discriminating control enrolled when its machinery goes, and
a cut that swept the lens's controls into the funeral would erase the four probes
that prove this wall's refusal arms are real.

* Regenerate the three projections the new seed file and its DESIGN rows move

declaration_index.rs is a hand-written seed file. The branch registered it in
both authorities -- seed_retention_frontier and stage0_crate_layout -- and never
regenerated the projection those authorities feed, so the regen phase saw a
committed mirror the emitter does not produce ("committed mirror is no longer
emitted") and the two crate-layout witnesses that join frontier to generated
filenames both went red. One missing regeneration, three CI failures.

DESIGN.md is the third projection and was invisible from the failure list: this
branch edits gunbc.design_document (the fired §6 construction-justification
trigger, the retired cited-symbol row), so its projection was stale too and would
have been the next cycle's red from a different file.

Produced by running the emitter to a FIXED POINT -- dag/tools/generated_artifact_gate.dag
main_wet, looped until git status stopped changing, which took two rounds -- not
by hand-matching the expected output. The files say do not hand-edit, and a
hand-written file that happens to equal what the emitter would produce passes the
gate while leaving the emitter unproven.

Every installed byte verified against the emitter's own sha256 on the runner
before any confirming run:

  261489671103b4d8c1cce69934cbaaf23fd401a379e0de0eb941a42b48ca92bc  dag/gunbc/stage0_crate_layout_generated.dag
  698a52094e48cdf3964a5c2a5df4266a5892de49f4f0516521beaf041fef2d79  src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs
  8d075c7cd37af217326c689bbbcefbbe1c3024c7b53cad5f93eec75e91cc652f  DESIGN.md

A second dispatch re-emitted over the installed copies and reproduced them
unchanged, which is the independent half of that check.

The declaration index itself was already green on the required path at the
previous head and is untouched here: modules=3993 declared=76852 citations=1496
debt=42 kernel_named=1944 lens_modules=71, no findings.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The wall's disclosed outside-index boundary rotted this PR's own roster (review 55899)

dag/gunbc/declaration_index_seed_growth.dag cited
v1_compiler.declaration_index citation_is_pre_existing_debt. That predicate was
RENAMED to citation_in_roster earlier on this branch, by the repair that made the
debt roster a parameter defaulted to the identity element. The code and every
caller moved; the roster row did not. So the carrier declaring this PR's
hand-Rust obligation cited a symbol this PR had deleted -- the exact DESIGN §3
stale-citation class this PR exists to close, inside the PR's own authority.

WHY THE WALL DID NOT REFUSE IT. The wall resolves a citation against the index,
and the index is built from swept .dag modules. v1_compiler is a hand-Rust
namespace root no swept module declares, so citation_is_outside_index COUNTS it
rather than refusing -- exactly as the carrier's disclosed boundary says. What
that disclosure did not say, and now does: the seed-growth carriers are precisely
the rosters that name hand-Rust items, so they are the one population where a
rename in the same commit silently rots its own citation. The wall's coverage and
the rosters that most need covering are disjoint.

CHECKED AT CLASS GRAIN, NOT AT THE REPORTED INSTANCE. All 55 roster rows resolved
against a definition in the five hand-Rust files the carrier enumerates: 54
resolved, 1 did not -- the row review found. The "+55, all enumerated" claim was
therefore true of the COUNT while false of one row's CONTENT, which patching only
the reported line would have left unmeasured.

Recorded as a specimen row rather than silently corrected -- the same discipline
the false-quantifier row already applies to its two specimens -- with its
next-rung trigger (resolve hand-Rust citations against an index of hand-Rust
declarations, strictly larger than this PR and not attempted here) and an honest
rung: mitigatable, review diligence.

VERIFIED: v1_src_dag_parse over the merged tree, 3997 file(s) parse-clean, zero
findings, declarations modules=3997 declared=76950 import_members=80221
citations=1496 debt=42 in_fixtures=161 outside_index=134 kernel_named=1948
lens_modules=71.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The third projection: the seed-emitted mirror the artifact gate does not produce

CI: required-ci: regen FAIL generated surface drift:
gunbc_stage0_crate_layout_generated.rs

ONE AUTHORITY, TWO EMITTERS, AND I HAD ONLY RUN ONE. Editing
dag/gunbc/stage0_crate_layout_generated.dag moves THREE artifacts, produced by
two different emitters:

  main_wet (dag/tools/generated_artifact_gate.dag)
    dag/gunbc/stage0_crate_layout_generated.dag
    src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs
    DESIGN.md

  regen (claim_executor --required-regen)
    src/v1/stage0/src/gunbc_stage0_crate_layout_generated.rs

The previous commit iterated main_wet to a FIXED POINT and hash-verified every
byte of its outputs. That was correct and could never have surfaced this file,
because main_wet does not produce it. A FIXED POINT IS ONLY A FIXED POINT OF THE
OPERATOR YOU ITERATED. The two Rust mirrors sit in the same directory with nearly
the same name -- bootstrap_stage0_... and gunbc_stage0_..., one per emitter -- so
the missed one reads as a duplicate of the checked one.

REPRODUCED RATHER THAN INFERRED, which mattered: main at efc880a ALSO fails
witnesses.yml in the BUILD lane with floor green, so every surface signal said
inherited. Running the exact lane
(claim_executor --required-ci --required-lane build) named a file that exists
only on this branch. main's build job died before its steps reported a
conclusion at all -- an infrastructure death wearing a lane name, which could not
have produced this symptom. Two reds, one lane name, unrelated causes.

REPAIRED BY THE DOCUMENTED RECIPE, not one pass, because the first pass runs a
binary that PREDATES the change it emits and can self-verify at divergence 0 for
the wrong reason:

  pass 1  first_generation_equal=false  FAIL generated surface drift
  install target/stage0-regen-candidate/src/gunbc_stage0_crate_layout_generated.rs
  rebuild from the installed seed        Finished in 4m12s
  pass 2  first_generation_equal=true    no failure

Installed bytes verified against the runner's sha256:

  e70d37012c0ee094583ed0dc3c1098cb55f06008e90867ba1a894059980e6a6a

The diff is one insertion, "declaration_index.rs".to_string(), which confirms the
diagnosis rather than merely clearing the gate.

THE FLOOR LANE IS ALREADY GREEN ON THE PARENT COMMIT (run 32907180281):
phases_run=2 failed=0, parse OK 3997 file(s) parse-clean, declarations
modules=3997 declared=76950 citations=1496 debt=42 kernel_named=1948
lens_modules=71 -- so the two crate-layout witnesses that failed on ea31e92
now pass, and the declaration index matches the runner measurement digit for
digit. This commit closes the last of the three original failures.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Drop six imports that main's #9228 deletion made dead in the merge

CI on 45270ab: both lanes died at "Build the witness fold" with the lane steps
SKIPPED, so nothing was checked -- one compile failure reported three times, not
three failures.

  error: unused imports: `make_eval_context`, `resolve_entry_graph_shared`, and `run_value`
  error: unused imports: `ExecutionMode`, `InterpContext`, and `Value`
  error: could not compile `v1-compiler` (bin "claim_executor") due to 2 previous errors

NEITHER BRANCH HAS THIS DEFECT ALONE. main's #9228 ("Delete the plan/walk surface
nothing could reach", claim_executor 21,366 -> 11,508) removed the last callers
of all six; this branch kept the import list. The imports go dead only in the
merge, and CI evaluates the merge ref, which is why the head built clean here and
failed there. Every surviving use is fully qualified
(v1_compiler::cli_run::make_eval_context), and `Value` is re-imported locally at
its one use site, so the removals are safe.

TWO DEFECTS IN MY OWN INSTRUMENT, named because both fail toward a green:

1. CI builds with -D warnings and the workflow never says so --
   actions-rust-lang/setup-rust-toolchain@v1.16.0 sets RUSTFLAGS: -D warnings by
   default. Local dispatches built without it, so unused imports were warnings
   here and errors there. Reproduced with RUSTFLAGS forwarded: BUILD-RC=0.

2. My build checks grepped `^error`, but cargo emits ANSI escapes, so the real
   line is \e[1m\e[91merror and never matches at column 0. Every "no errors" I
   reported from those dispatches read a filter that COULD NOT MATCH AN ERROR.
   That is the worse of the two: it would have hidden any compile failure, not
   just this class.

VERIFIED ON THE MERGED TREE, under CI's own strictness:
  cargo build --release --bin claim_executor --bin gunbc, RUSTFLAGS=-D warnings  rc=0
  claim_executor --required-regen   first_generation_equal=true, no drift
  main_wet x2, all three projections byte-IDENTICAL before and after:
    ba373e57...  DESIGN.md
    26148967...  dag/gunbc/stage0_crate_layout_generated.dag
    698a5209...  src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs
  so the text-merged DESIGN.md IS the projection of the merged authorities and
  owes no regeneration.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Carrier identity is not a licence: the fixture exemption moves to citation grain (review 55939)

Both citation arms skipped every citation in a module module_is_fixture_carrier
answered true for. The justification was real and still is -- a witness proving
the resolver refuses an absent symbol has to AUTHOR an absent symbol, so its
false citation is its evidence rather than its defect. The defect was that the
EXEMPTION WAS KEYED ON THE MODULE while the justification is a property of the
CITATION.

WHAT SETTLED IT WAS THE MEASUREMENT, NOT THE ARGUMENT. Of 161 citations authored
inside fixture carriers, 128 RESOLVE: ordinary citations of real authorities that
happen to live in a test module. The skip was shielding 128 real citations to
protect 33 sites, and reporting the rest as in_fixtures did not restore
integrity. A counted hole is still a hole.

THE HOLE WAS OCCUPIED, which is what separates a defect from a disclosed
boundary. Two enrolled identities are ordinary staleness with nothing to do with
fixture intent:
  - dag.test.claim.witness_purpose_taxonomy_witness -- a dag.-prefixed module
    path no module declares; the real module is test.claim.*. A plain typo.
  - std.disposition Disposition field marker -- a real authority and a real
    declaration with an absent field, cited twice.

THE REPAIR. Both arms now judge fixture carriers, and
FIXTURE_CARRIER_CITATION_EXEMPTIONS enumerates 31 identities at (module,
declaration, field) grain. It is NOT a debt contract and does not claim to be:
§5's condition 3 wants a terminal state of empty and this one's is not -- a
planted control such as NoSuchDecl_G1_RED is permanent by design. What it shares
with the debt roster is what makes either safe rather than a suppression list:
MONOTONE, and REFUSES WHEN SPENT through the same inverse arm. Also fixed a
diagnostic that would have named PRE_EXISTING_CITATION_DEBT for a row held by a
different roster -- a spent-row message naming the wrong list sends the reader to
a file that does not contain the row.

HOW THE ROWS WERE OBTAINED, because the first attempt was wrong AND THE MECHANISM
CAUGHT ITS AUTHOR. Extracting identities by parsing rendered diagnostics silently
dropped the FIELD -- a CitedDeclarationAbsent message never prints one -- so rows
for citations carrying a NamedField whose DECLARATION is absent matched nothing.
The corpus run then reported the same citation as BOTH refusing AND its row as
spent: the paired-inverse-arm desynchronization this module documents and tests
for, firing on me, inside one run. Rows are now derived from the index, from the
same CitedSymbol values the matcher compares. Five further refusing identities
are deliberately excluded -- already enrolled in PRE_EXISTING_CITATION_DEBT or
PLANTED_CONTROL_CITATIONS, and a second row for one citation is duplicate
authority with a double stale-arm report.

RUNG: unchanged at mechanically preventable. This is a WIDENING of the enrolled
population, not a climb -- 128 citations that were never judged now are.

VERIFIED, under CI's own strictness (RUSTFLAGS=-D warnings):
  cargo test --test declaration_index_integrity   21 passed; 0 failed
  v1_src_dag_parse over the corpus                rc=0, ZERO findings
    3997 file(s) parse-clean; modules=3997 declared=76981 import_members=80186
    citations=1493 debt=42 in_fixtures=161 outside_index=134 kernel_named=1947
    lens_modules=71

Three new fixture-boundary tests, each asserting its plant before the guard's
verdict: a refusing citation inside a carrier is judged; exempting one citation
leaves its sibling in the same module refusing; an exemption over a resolving
citation refuses as spent and names its roster.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Declare the 29 unclassified exemption rows as a stall, not a settled boundary

The fixture roster enrolls 31 identities. Two are decidable by inspection and are
named in the carrier prose as ordinary staleness. THE OTHER 29 ARE NOT
CLASSIFIED, and leaving that as prose would let them read as settled -- which is
exactly where a real defect sits unseen, demonstrated rather than hypothesised,
because two were found sitting there.

Not deciding them is still right: deciding what another author MEANT across 29
rows is the judgement §5 warns turns a stale citation into a confidently wrong
one. The repair is to DECLARE the stall rather than to resolve it, which is the
difference between a boundary disclosed and one merely not crossed.

declaration_index_fixture_exemption_classification_stall, a GuaranteeStall:

  current      Mitigatable
  ceiling      MechanicallyPreventable      (below ceiling, so it reads as a
                                             stall rather than a class that
                                             already arrived)
  blocker      AwaitsOneGrounding           NOT ClimbableButUnbuilt: what is
                                             missing is a DECIDABLE CRITERION,
                                             not effort. Nothing distinguishes a
                                             citation its author meant to refuse
                                             from one that rotted; the
                                             distinction lives in authoring
                                             intent, which no Accepted program
                                             can read.
  population   BoundedPopulation, 29 members at identity grain -- genuinely
               bounded, so UncountedNotEnumerable would be the
               empty-observation narrow.
  trigger      a witness declares each citation it plants to refuse as a typed
               row beside the citation, at which point the deliberate half is
               DERIVED, this roster shrinks to the genuinely stale remainder,
               and that remainder becomes ordinary debt with a terminal state of
               empty.

The 29 is derived by subtracting the two named specimens from the 31, not
asserted, so the number in the prose and the number in the row are one fact.

VERIFIED: 3997 file(s) parse-clean, rc=0, ZERO findings. The new
gunbc.guarantee_rung_drop import members resolve -- import_members 80186 -> 80191
with no IMPORT-MEMBER-ABSENT finding, which is this change's own wall checking
this change's own edit.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…or retire the observation emitter migration census (#9274)

* The census pinned each row to a file, so #9228's claim_executor shrink reported four code moves as census events — and hid the one real one, a migration reverting to raw emits

Five `gunbc.observation_emit_census` rows went red at once. Measured: exactly
one was a census event.

`CensusedEmitSite` carried `source_file: NonEmptyStr`, whose only consumer in
the corpus was the witness's `census_marker_present` — read that one file,
grep it. That is a positional citation in the sense DESIGN §3 rules against,
and it rots in the way this census cannot tolerate: it goes false when an emit
MOVES, which is not a census fact. #9228 deleted claim_executor's unreachable
plan/walk surface (21,366 -> 11,508 lines) and four rows reded while their tag
families sat untouched in sibling seed files ([receipt], [resolve-split],
[assembly-split], [witness-row-cost]). Four false reds beside one true one is
worse than no check: the true one is indistinguishable in the noise.

THE ONE REAL EVENT, and it is a REGRESSION, not the retirement it looks like.
[floor-memory] was a MigratedToObservation row: the floor's periodic progress
line rendered through `ci_heartbeat_line` via the seed mirror
`render_heartbeat_line_mirror`. Neither the marker nor the mirror occurs
anywhere under src/ any more (one doc comment names the mirror). Read no
further, that is a retirement. It is not: the floor still emits a periodic
progress line and a per-claim RSS line, now as raw `[floor-heartbeat]` and
`[floor-claim-memory]` eprintlns in cli_run.rs with no projection behind them.
A projection was deleted and raw emits took its job under new names. Deleting
the row as a completed retirement — which is what marker-absence alone
supports — would have booked a reversal as progress.

WHAT LANDS

- `source_file` deleted from the type. Presence is asked of the SEED
  (`seed_emit_sources`, folded), so a marker that moves stays green and a
  marker that leaves reds. Fail-closed on its own denominator: a new witness
  reds if any listed source stops reading non-empty.
- `floor_heartbeat_site` and `floor_claim_memory_site` enrolled as
  CountedFrontierSite; frontier count rises by two, which is the honest
  direction. `w_the_floor_heartbeat_projection_is_absent_from_the_seed` is the
  discriminating probe — three conjuncts, because marker-absent and
  mirror-absent alone cannot tell retirement from regression; only a raw
  successor emitting can. It reds when the debt is paid, forcing
  reclassification in the same change.
- The floor-memory raw-shape probe is deleted with its subject. Not the
  §4b(4) keep-the-evidence case: nothing climbed, so there is no rung to hold.
- `claim_executor discovery_claim_result`, cited as [witness-row-cost]'s
  grounding, RESOLVES TO NOTHING — fabricated 2026-08-22 and copied into the
  retirement acceptance, so one invented symbol became two files' evidence.
  Corrected to the `witness_cost_*` helpers in cli_run.rs, in both.
- Raw-shape probes: mirror positives widened to the seed; the three negatives
  measured to be ambiguous seed-wide (`t_ms=`, `current={}`, `bytes (VmHWM)` —
  4, 3 and 2 unrelated occurrences) stay file-scoped.

WHAT IS DECLARED, NOT FIXED. The bidirectional claim is false as stated: 57
bracket-tag spellings live in the six seed sources against 13 rostered tags,
so 44 are unrostered — an UPPER BOUND from a spelling grep, not the frontier
debt, and quoted as the shape of the gap rather than its size. It is not
repaired by hand-authoring 44 rows, which multiplies the surface that rots.
The next-rung trigger is a substrate capability rather than effort: the
interpreter registers `string_contains` and `string_length` and nothing else
over strings, so a fold can ask whether text contains a pattern and cannot ask
where, how many, or what else of this shape. Membership is decidable;
enumeration is not reachable. Occurrence-grain discovery — the durable fix
this module has named as its residue three times — is not expressible in .dag
today.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016BTuU9MJgDAtC2h3akqzLD

* The reversal probe's mirror conjunct asked for a name, and a doc comment answered: ask for the call form

Executed, the probe returned false. `render_heartbeat_line_mirror` still occurs
once in cli_run.rs -- in a doc comment, in backticks, naming the deleted
mirror. A substring test cannot tell a call from a mention.

The conjunct now asks for `render_heartbeat_line_mirror(` with the open paren:
an approximation of 'a call site, not a mention', not a fix, and one that fails
toward red rather than green.

WHY IT WAS WRONG WHEN WRITTEN: the first draft was verified by shell grep over
src/ and reded when executed. The difference was the denominator -- the check
folds seed_emit_sources, which includes cli_run.rs where the comment lives. A
measurement taken with a different instrument than the check runs is not
evidence about the check.

18 of 18 witness identities green by execution.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016BTuU9MJgDAtC2h3akqzLD

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 26, 2026
…ction, cli_invoke builders, walk_plan_stage fixture family) (#9252)

* Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns

#9228 deleted claim_executor's plan/walk surface and named its .dag residue rather
than sweeping it. This is that cut, plus one repair the census surfaced.

WHAT WENT, AT THE ROOT:

  PlanFunction and the plan argv builders. The coproduct modelled a closed roster of
  --plan-function targets; the flag no longer parses and the entry every variant named
  (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with
  it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the
  notice-title normalizer and shell suffix that existed only to feed them,
  claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/
  floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and
  gunbc_ci_floor_only_script.

  The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode
  (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell,
  release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is
  NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it
  records is still open for that one spelling.

  gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The
  second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that,
  and a second route to it here is the parallel authority the floor cut removed.

  The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore]
  harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness
  row. Their sole driver was the plan.dag recipes #9228 deleted.

  v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition::
  DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That
  arm's roster was one prefix and the family above was its entire population; its own header
  said "DISSOLVES when the fixture stops authoring test fns", and this is that condition.
  Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both
  sides deleted here.

  The pre-push witness-corpus gate. Not on the brief, found by the flag census:
  pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted
  floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only;
  its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms
  a gate" are deleted rather than weakened -- measured against the roster, the corpus binding
  was the only thing making them true, so they were green against the plan and false about the
  hook anyone runs.

THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope):

  Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION
  witness, which has nothing to do with plan/walk. Its own note records that these same
  specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which
  died with affected-set selection. This would have been the third home.

  They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns:
  three modules, no test fn, no effects, one consumer. No discovery exclusion is needed
  because there is nothing to discover, which is a stronger construction than the dir-grain
  exclusion the old home required.

  AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was
  ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied
  every row and the "strict-subset proof" the note describes was checked by nothing.
  ExpectScopedExactly compares the selected list to the expected list.

EVIDENCE, by execution on a release gunbc (remote, one dispatch):
  control    witness_touched_path_dispositions_hold -> true
  mutation   give scope_isolated an import edge to scope_shared -> false
  The mutation is exactly the strict-subset violation; the old assertion could not see it.

Rust: cargo check -p v1-compiler --bins clean, fmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Repair the scope-disposition witness's per-PR half, which the floor caught

dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining
and pins the disposition row count. Both moved with the rehoming and I checked only the
long-lane witness, so strict preparation refused with a name-resolution error before any
site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with
it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster
growing by one row because the strict-subset proof needs three specimens where the old
home carried two.

The pin doing its job here is the argument for keeping it: a count that had to be updated
by hand is exactly what stopped this rehoming from silently shipping a roster of a
different size than the one the note describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI

REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct.

WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script()
alone, because its other half emitted a `claim_executor --plan-entry` line naming an
entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived
was a callable verb that builds the release binaries, verifies the artifacts, and exits
0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure
mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported
under the name of the larger one. §5's absorbing-fallback rule is about a failure arm
that widens; this is its mirror at the success arm, a green that narrowed.

WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the
reviewer's other option and I am not taking it, on the grounds this branch already
argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a
second route to it is the parallel authority the floor cut removed. The verb also has no
distinct job left -- "build the release binaries and verify the artifacts" already has a
name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is
not an authority that lost its body; it is a name with nothing left to denote.

THE CENSUS, cut at the root and followed where it led:
  dag/tools/gunbc_ci.dag                     the entry module, deleted
  main.rs Commands::Ci + its arm             the CLI verb
  gunbc.cli_dispatch_surface "ci" row        the modeled CLI surface
  gunbc_cli_dispatch_surface.rs              its generated mirror
  v2.workflow.ci_release_build_emit          gunbc_ci_run_script, the wrapper
  std.emit_on_demand gunbc_ci_emission_surface   the wet-surface row naming tools.gunbc_ci main
  emit_on_demand_kernel_witness_test         its enrollment assertion
  wall_residue_live_test residue_gunbc_ci_clean  a test fn whose subject was the deleted file

ci_release_build_script itself is UNTOUCHED and still has three consumers
(ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes.

EVIDENCE, build lane on this tree (remote, one dispatch):
  required-ci: lane=build phases_run=2 failed=0
  regen first_generation_equal=true    -- the mirror edit is byte-equal to the emitter's
                                          own output, established by the gate rather than
                                          by my reading of the diff
  v2-emission blocking=0, census 3792 -> 3791, the one deleted module

The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands
needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Name the admission order's next-rung trigger, so the gap reads as unbuilt

The header already said the surviving long-home-over-live-tree precedence has
no executing discriminator and must not be cited as covered. It did not say
what would make it coverable again, which leaves a reader unable to tell
cannot-cover-yet from nobody-built-it -- the distinction DESIGN 4b(2) exists to
keep.

The trigger is a decline whose subject CAN collide with an existing one: a site
that legitimately satisfies two decline reasons at once, so which reason it
reports is a decision some input can get wrong. At that point a discriminating
witness is authorable and is owed. Until then the correct response to the
absence is to build that collision case, not to re-point a witness at a subject
that cannot disagree with itself -- which would be permanently green by
construction, and cited as coverage.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 26, 2026
…ction, cli_invoke builders, walk_plan_stage fixture family) (#9286)

* Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns

#9228 deleted claim_executor's plan/walk surface and named its .dag residue rather
than sweeping it. This is that cut, plus one repair the census surfaced.

WHAT WENT, AT THE ROOT:

  PlanFunction and the plan argv builders. The coproduct modelled a closed roster of
  --plan-function targets; the flag no longer parses and the entry every variant named
  (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with
  it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the
  notice-title normalizer and shell suffix that existed only to feed them,
  claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/
  floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and
  gunbc_ci_floor_only_script.

  The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode
  (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell,
  release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is
  NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it
  records is still open for that one spelling.

  gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The
  second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that,
  and a second route to it here is the parallel authority the floor cut removed.

  The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore]
  harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness
  row. Their sole driver was the plan.dag recipes #9228 deleted.

  v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition::
  DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That
  arm's roster was one prefix and the family above was its entire population; its own header
  said "DISSOLVES when the fixture stops authoring test fns", and this is that condition.
  Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both
  sides deleted here.

  The pre-push witness-corpus gate. Not on the brief, found by the flag census:
  pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted
  floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only;
  its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms
  a gate" are deleted rather than weakened -- measured against the roster, the corpus binding
  was the only thing making them true, so they were green against the plan and false about the
  hook anyone runs.

THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope):

  Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION
  witness, which has nothing to do with plan/walk. Its own note records that these same
  specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which
  died with affected-set selection. This would have been the third home.

  They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns:
  three modules, no test fn, no effects, one consumer. No discovery exclusion is needed
  because there is nothing to discover, which is a stronger construction than the dir-grain
  exclusion the old home required.

  AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was
  ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied
  every row and the "strict-subset proof" the note describes was checked by nothing.
  ExpectScopedExactly compares the selected list to the expected list.

EVIDENCE, by execution on a release gunbc (remote, one dispatch):
  control    witness_touched_path_dispositions_hold -> true
  mutation   give scope_isolated an import edge to scope_shared -> false
  The mutation is exactly the strict-subset violation; the old assertion could not see it.

Rust: cargo check -p v1-compiler --bins clean, fmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Repair the scope-disposition witness's per-PR half, which the floor caught

dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining
and pins the disposition row count. Both moved with the rehoming and I checked only the
long-lane witness, so strict preparation refused with a name-resolution error before any
site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with
it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster
growing by one row because the strict-subset proof needs three specimens where the old
home carried two.

The pin doing its job here is the argument for keeping it: a count that had to be updated
by hand is exactly what stopped this rehoming from silently shipping a roster of a
different size than the one the note describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI

REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct.

WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script()
alone, because its other half emitted a `claim_executor --plan-entry` line naming an
entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived
was a callable verb that builds the release binaries, verifies the artifacts, and exits
0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure
mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported
under the name of the larger one. §5's absorbing-fallback rule is about a failure arm
that widens; this is its mirror at the success arm, a green that narrowed.

WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the
reviewer's other option and I am not taking it, on the grounds this branch already
argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a
second route to it is the parallel authority the floor cut removed. The verb also has no
distinct job left -- "build the release binaries and verify the artifacts" already has a
name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is
not an authority that lost its body; it is a name with nothing left to denote.

THE CENSUS, cut at the root and followed where it led:
  dag/tools/gunbc_ci.dag                     the entry module, deleted
  main.rs Commands::Ci + its arm             the CLI verb
  gunbc.cli_dispatch_surface "ci" row        the modeled CLI surface
  gunbc_cli_dispatch_surface.rs              its generated mirror
  v2.workflow.ci_release_build_emit          gunbc_ci_run_script, the wrapper
  std.emit_on_demand gunbc_ci_emission_surface   the wet-surface row naming tools.gunbc_ci main
  emit_on_demand_kernel_witness_test         its enrollment assertion
  wall_residue_live_test residue_gunbc_ci_clean  a test fn whose subject was the deleted file

ci_release_build_script itself is UNTOUCHED and still has three consumers
(ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes.

EVIDENCE, build lane on this tree (remote, one dispatch):
  required-ci: lane=build phases_run=2 failed=0
  regen first_generation_equal=true    -- the mirror edit is byte-equal to the emitter's
                                          own output, established by the gate rather than
                                          by my reading of the diff
  v2-emission blocking=0, census 3792 -> 3791, the one deleted module

The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands
needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete v2.lens.cited_symbol_resolution, and keep the twelve of its twenty-seven witnesses that were never its

DESIGN authorised this cut and got its population wrong, which is the finding rather than
a footnote. The row read "v2.lens.cited_symbol_resolution and its sixteen witnesses are not
deleted -- they are unreachable from any required check and are dead rather than competing".
Both halves of that population claim are false, and this change corrects the row in the same
diff that falsifies it.

SIXTEEN WAS THE COUNT AT #7707, when the lens landed. The file grew twice after
(#8673 enrolled roster_registry, #8775 the two instance-gap carriers) and held 27 `test fn`
identities. `gunbc.ci_layer_roots` said "eighteen". Three numbers, three snapshots of a
growing file, none of them current -- the transcribed-measurement class the standing rule
already names. The replacement rows name their subject and no number.

AND "DEAD" WAS TRUE OF THE LENS AND FALSE OF A THIRD OF ITS WITNESSES. Measured against the
seven symbols that file imported FROM the lens, 6 of the 27 touch one. The other 21 do not.
"The lens and its witnesses" was never one population, and the three-way split is:

  6  LENS-BOUND -- die with it. The census-green claim, the three planted-control rows, the
     enrolled-population exemption identity, the ambiguous control. `declaration_index`
     re-derives this machinery as PLANTED_CONTROL_CITATIONS plus PlantedControlNoLongerRefuses.

  6  RESOLVER-BOUND -- MOVED, not deleted, to test.claim.long.decl_ref_resolution_witness_test.
     They call `resolve_declaration_ref`, which lives in `v2.std.decl_ref_resolution` -- a
     module that SURVIVES with four other consumers -- and they are the only rows in the tree
     that execute its five-arm refusal. Deleting them because they sat in a file named for
     the lens would be the §4b(4) failure exactly: a climb deletes the redundant PRODUCTION
     machinery, never the discriminating RED and positive control.

  15 CARRIER-BOUND -- MOVED to test.claim.long.carrier_reference_integrity_witness_test.
     Population and projection claims about the four carriers that PROJECT DeclarationRefs.
     Their resolution half is subsumed; their population half is subsumed by nothing.

SUBSUMPTION IS SCOPED, not general: `declaration_index` extracts TYPED-LITERAL citations --
DeclarationRef record literals and the decl_ref/decl_field_ref constructors -- and reports
computed reference fields as a coverage boundary. A prose reference inside a String is
covered by nothing, before or after, and this change does not claim otherwise.

THE PER-PR WITNESS IS RENAMED, NOT DELETED. test.claim.cited_symbol_resolution_witness_test
never imported the lens; its one claim is a three-term bucket partition over
gunbc.doc_graph_roots. Two readers independently concluded from its NAME that the resolution
law was enforced per-PR -- it was not, a bucket identity was -- and after this cut it would
have been the only cited-symbol-named thing left in the tree, reading as the law's residue.
It is now test.claim.doc_graph_reference_partition_witness_test. Same borrowed-authority
shape as #9252's fixture rehome, one layer up: there the home was borrowed, here the name.

WHAT THE WALL ITSELF NAMED, because this was cut delete-first and the census is the deletion.
The first corpus run after the cut reported six refusals: two IMPORT-MEMBER-ABSENT for a
`CitedSymbolResolution` lens-id the registry no longer declares, and four
PLANTED-CONTROL-RESOLVES for the exact rows #9211 declared as this cut's residue ("they
delete with the lens, not before it"). Every one predicted, none discovered by reading.

AND ONE GAP THE ROSTER DELETION WOULD HAVE OPENED, which is why those four rows are not
simply removed. Each named one refusal arm of the cited-symbol wall. Three of the four arms
already had controlled fixtures in tests/declaration_index_integrity.rs. THE FOURTH DID NOT:
measured, the string `CitedFieldAbsent` did not occur in that file at all, so its only
evidence anywhere was the planted row I was deleting. Deleting it would have left a refusal
arm with nothing executing against it -- §4b(4) again, one level up from where I first hit it.
`citation_to_an_absent_field_is_refused_and_a_present_field_is_not` is authored here, with
its positive control, and a controlled fixture is the stronger oracle anyway (§5): the
planted row only ever asserted that one hand-authored citation still refuses.

PLANTED_CONTROL_CITATIONS is left EMPTY rather than deleted. Mechanism reachable, join
reachable, occupancy zero -- a healthy guard being quiet, not a dead one.

EVIDENCE, by execution (remote, release binaries):
                              before        after
  parse-clean files           4012          4011      the lens module
  modules                     4012          4011
  citations                   1470          1466      the lens's four planted citations
  lens_modules                71            70
  debt                        42            42        UNCHANGED
  corpus findings             0             0
  declaration_index_integrity 21 passed     22 passed the new field-absent pair

THE DEBT COUNTS RECONCILE, and the brief's "46" is none of them. 38 = roster rows, counted.
46 = citation SITES at the time the roster's doc comment was written. 42 = citations
currently suppressed by a row, the live measurement. debt is 42 before and after, and a row
that stopped reproducing refuses as CitationDebtRowStale -- none did, which is the executable
form of "the defects are still found".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
briansrls pushed a commit that referenced this pull request Aug 27, 2026
… the test target main inherited (#9230)

* Enrol the v2-emission selftest; delete two orphaned modes; repair the test target main inherited

Rebuilt on current main rather than merged into it. The old branch shared three
commits with #9228 and conflicted in twelve hunks where "ours" was a
pre-deletion snapshot -- hand-resolving that risks silently restoring code
#9228 had just deleted, so the two intentional changes were replayed onto main
instead. Force-push is the honest vehicle here; a merge commit would have carried
a resolution nobody could audit.

THE ENROLMENT IS THE POINT, and it is a climb rather than a cut.
run_required_v2_emission_selftest -- the red fixture that must be refused on the
annotation cause and the green fixture that must emit -- was reachable ONLY
through a standalone flag no workflow invoked. So the required run's v2-emission
phase ran a producer whose REFUSAL had never once been shown to fire; a green
established that the emitter emitted, not that it still refuses what it must.
DESIGN 4b(4): a class's discriminating RED and positive control stay ENROLLED as
the evidence the rung is real. Unenrolled evidence is not weaker evidence, it is
none. It now runs inside the phase, ahead of the producer, and a failure lands in
phase_failures like any other. Measured before enrolling: passes, about a second.
The standalone flag goes in the same motion -- two routes to one fact, and only
the enrolled one executes.

TWO MODES DELETED, and only two:
- --measure-cgroup-peak: its own comment names the `rust_tests` job as its caller.
  That job was deleted. An orphan whose stated consumer is gone.
- --required-cited-symbol: DESIGN's 2026-08-23 row already declares this drop and
  states the surviving flag guards nothing, with a restoration trigger putting the
  wall at ingestion. Deleting the flag agrees with that row rather than leaving a
  mode that reads as coverage.

KEPT AGAINST THIS PROGRAM'S OWN BIAS: --heads-reading-differential and the three
--behavioral-receipt-* modes are INSTRUMENTS with entry points, not gates.
DESIGN's 2026-08-24 ruling is that a measurement worth re-deriving is worth an
entry point. The target-model lane confirms both shapes they need are expressible
(addressable but absent from the //:required roster; a differential needs its own
TestStanding arm rather than the Bazel status arm, which carries only
PASSED/FAILED and would erase the divergence). They migrate; they do not get
rescued.

ALSO REPAIRS WHAT MAIN INHERITED. #9228 merged before its last commit landed, so
main carries four errors in claim_executor's TEST target: an orphaned
witness_walk_flags_tests module and a cfg(test) classify_witness_expectations
helper over three deleted types, plus seven dead test helpers and the imports the
cited-symbol deletion orphaned. CI cannot see these -- the required run compiles
--bin, never --tests.

EVIDENCE, both controls run rather than one:
- transport: ctrl-build reports `forwarding env: RUSTFLAGS`, so -D warnings
  reached rustc.
- subject: a planted `super::deliberately_absent_symbol_zzz()` produces its exact
  diagnostic under this branch's own --tests invocation, proving test modules
  entered the observed population. Clean is therefore a measurement, not a
  silence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Six authorities asserted a flag this PR deletes; correct them, and regen surfaces a security fix that never reached its workflow

Review 55934 is correct and the finding is the one that matters most in a
deletion: the code changed and the canonical authorities did not, so DESIGN and
four carriers were left asserting that `--required-cited-symbol` is a live flag
that runs the census standalone. After this PR that sentence returns `unknown
argument` and exits 2. A knowingly-false recital in the canonical authority is
premise contamination -- a reader planning against it budgets for an invocation
that cannot run -- and it is exactly the drift these documents were rewritten to
close on 2026-08-25.

CORRECTED, all six, in the same PR as the deletion rather than after it:
  dag/gunbc/design_document.dag (the rung-drop row, and DESIGN.md regenerated)
  src/v2/lens/cited_symbol_resolution.dag (two rows)
  dag/gunbc/doc_graph_roots.dag
  dag/gunbc/fabric_capacity_class_gap.dag        (past tense)
  dag/test/claim/build_cache_endpoint_observe_test.dag (past tense)

THE RUNG DOES NOT DROP AGAIN, and every correction says so rather than quietly
implying a second drop. The clause being replaced already argued that a mode no
workflow invokes guards nothing; removing that mode therefore takes away no
enforcement, and the class sat at mitigatable on review diligence before the
deletion and sits there after it. What the deletion removes is the ON-DEMAND
RE-DERIVATION ROUTE -- with the flag and its Rust census both gone there is now
no way to run this census over the live corpus at all. That is a capability loss,
not a rung change, and conflating the two would be the same 4b(1) inflation the
original clause was written to avoid, run in reverse.

THE REGEN SURFACED SOMETHING ELSE, AND IT IS NOT MINE. Regenerating the committed
artifacts from their authorities also rewrote .github/workflows/fleet-converge.yml.
That change belongs to #9226 -- "A credential in a command line is read by every
process on the host, and on this fleet that is measured" -- which moved the
Secret Manager bearer token out of the curl argv and into a header file, landed a
witness asserting the header-file form, and NEVER REGENERATED THE WORKFLOW. So
the model has said `-H @"$HDR_FILE"` since that merge while the emitted workflow
that actually runs has kept `-H "Authorization: Bearer $WIF_ACCESS_TOKEN"` on the
command line, readable from /proc by every process on the runner. The witness
passes because it asserts against the authority, not against the artifact.

It is included rather than reverted because the alternative is worse: running a
generator and committing only the part of its output that suits this PR is
cherry-picking, and it would leave a security repair inert while looking applied.
The generated-artifact drift gate that would have caught this is in the set
DESIGN's CI entry lists as UNGUARDED since the floor cut -- so nothing was going
to catch it, and it was found only because this PR had an unrelated reason to
regenerate.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The canonical authority cited a real module as the home of a symbol it does not define

DESIGN's floor clause read `v2.workflow.required_floor` `run_required_floor`. The
module is real; the symbol is not in it. `run_required_floor` is defined in
`src/v1/stage0/src/cli_run.rs` and every other citation in the corpus names it as
`v1_compiler.cli_run` `run_required_floor` -- this was the only occurrence of the
wrong form, and it was in the one document every session reads first.

The v2 module is not unrelated, which is why the repair names both rather than
swapping one for the other: it owns the admission, cost-line and preparation-safety
policy the fold consults. What it does not own is the fold. Citing the policy carrier
as the driver is the same authority-substitution shape DESIGN already records --
both halves check out and only the arrow between them is invented.

Worth stating plainly because it lands in a PR that deletes the census: this is
precisely the defect `--required-cited-symbol` refused, and it was found by hand
three days after that job was cut. The rung-drop row I corrected earlier in this PR
predicted an unbounded future population; this is the first counted member of it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Four authority rows asserted the gap this PR's own merge had already closed

review 56048 (REQUEST_CHANGES) found three changed rows still saying cited-symbol
checking is review diligence and cannot be re-derived, while DESIGN.md in the same
tree records the rung restored. The finding is correct and the cause is mine: those
edits were true when written, and taking main's retirement row in the merge made them
false without touching them. A PR that contradicts itself across four files is the
premise contamination this branch has spent the night correcting elsewhere.

Corrected to describe the replacement rather than the drop: v1_compiler.declaration_index
resolves every authored DeclarationRef inside the parse phase of --required-ci, at
ingestion from the module's own source, strictly wider than what was dropped.

The fourth row the review did not name is the worst of them and is fixed here too.
fabric_capacity_class_gap asserted, as a heading and in the present tense, THE CITATIONS
IN THIS MODULE ARE NOT CHECKED BY ANYTHING -- measured, correctly, against a census that
enrolled five hand-named carriers. The declaration index enrolls by walking the Node tree
for DeclarationRef literals, so a module cannot be outside it by omission, and those
eight citations are now enrolled. The measurement is kept rather than deleted because it
was taken rather than assumed; what changes is that it now reads as the account of a
closed gap. Left standing, it would have told a future reader that a checked module was
unchecked -- worse than the three flagged rows, which merely understated a rung.

build_cache_endpoint_observe_test is deliberately NOT changed: its subject is annotation
grain enforced in the floor's preparation, which is unaffected by which census runs
beside it, and it already says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Moving the bearer token out of argv and leaving it on disk is the same exposure at a different address

review 56110 (REQUEST_CHANGES) is correct and this is my defect. The fleet prelude
DISARMS its EXIT trap so the ssh-agent outlives the step, and it did so after removing
only KEY_FILE -- so the token I moved out of argv in this same PR sat in RUNNER_TEMP
for the remainder of the job. The security repair was half a repair.

FIXED BY LIFETIME, NOT BY CLEANUP. HDR_FILE is consumed by exactly one curl, so it is
removed on the line after that curl rather than added to the later rm the review
suggested. The credential ceases to exist when its only consumer is done with it, which
is a shorter window than any exit path can offer and does not depend on which trap is
armed when the step ends. The trap still covers the failure arm between creation and
that removal, which is the only interval where the file can genuinely outlive the shell.

The spark prelude is NOT affected and is not changed: it keeps its trap armed through
step exit, so its header file is cleaned there. Only the fleet prelude disarms.

The authority annotation asserted the thing that was false -- "Each prelude's existing
trap removes HDR_FILE on exit" -- which is how the defect survived authoring and review
of the original change. Corrected in place, naming which prelude it holds for and which
it does not.

WITNESS, PROVEN BOTH WAYS BY EXECUTION. The existing tests only ask HOW the header
reaches curl, so they stayed green through the entire defect. The new one asserts
ADJACENCY -- the removal on the line immediately after the consuming curl -- rather than
presence, because presence stays green if the removal drifts below `trap - EXIT`, which
is the defect itself. Green: exit 0. Red: delete the rm row from the authority and it
exits 1 with "adjacency absent". Authority restored and verified byte-identical after.

A position comparison would have been the more obvious spelling and I did not use it:
this corpus has no index primitive, and minting one so a test can measure a shell string
would be adding an authority to check a claim.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A comment cited a deleted flag as the precedent for keeping another mode's ordering

review 56142 (APPROVE, non-blocking). The ordering rationale for
--emit-partition-crates named --verify-build-artifacts AND --measure-cgroup-peak as its
two co-examples; this PR deletes the second, so the sentence justified a real ordering
by pointing at a mode that no longer exists.

Small, and worth doing rather than deferring for the reason this branch has now hit
four times: a stale citation does not announce itself, and the next reader takes the
comment as the account of why the ordering is safe. The ordering IS safe and the
remaining co-example carries the argument alone.

Swept the corpus for the three deleted flags rather than fixing only the cited line.
The only surviving matches are run_required_v2_emission_selftest's definition in
cli_run and its call from the enrolled V2Emission phase -- that is the function this PR
puts on the required path, not the flag it removes, so both are correct and stay.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Rehome the orphaned dichotomy-over-three-states paragraph into its authority before a regeneration deletes it

DESIGN.md on main carried 1733 characters that `gunbc.recurring_failure_mode` did
not: the second form of state-space conflation, its gunbc#9324 specimen, and its
recognition rule. Measured by running the generated-artifact gate on a bare
worktree at main 0aa09c1 -- `M DESIGN.md`, one line, one insertion one deletion
-- and by grep: the text appears nowhere under dag/ or src/v2/.

So the projection disagreed with its source in the document that defines the rule
against exactly that, and the failure mode was not the disagreement but its
remedy: ANY regeneration silently deletes prose no authority holds. This PR
already regenerates DESIGN.md as part of resolving a merge-driver refusal, so it
was itself the change that would have destroyed it -- caught only because a peer
lane reported the drift while resolving a different PR.

The repair is the one DESIGN section 3 prescribes: a fact's home is its layer, so
the paragraph moves into the carrier that owns the recurring-failure-mode roster
and the projection derives it. Verified by execution: the regenerated failure-mode
line is now byte-identical to main's, and a second gate run is a no-op, so the
tree is a fixed point of its own emitter rather than merely agreeing once.

Nothing here is authored: the text is main's, moved to where it can survive.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 27, 2026
…e seed that beats, and repair the zero it was inventing (#9297)

* The lockstep the decline was hiding: repoint the heartbeat rows at the seed that beats, and repair the zero it was inventing

test.claim.observation_lockstep_witness_test carried two rows over
src/v1/stage0/src/bin/claim_executor.rs asking for from_secs(60),
floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror and
heartbeat_feed_snapshot. #9228 deleted the plan/walk surface all five lived on,
so both rows have been FALSE since it merged. Nothing said so: the module
declares ReadsLiveTree, the required floor declines it before the fold, and a
decline renders identically to a pass -- DESIGN's execution-provenance row, in
the form that lets a lockstep outlive the thing it locks to.

NOT A RETIREMENT, A MOVE. The floor still beats once a minute:
cli_run.rs spawn_floor_heartbeat, period GUNBC_FLOOR_HEARTBEAT_SECS defaulting
to 60, emitting a raw [floor-heartbeat] line with no projection behind it.
gunbc.observation_emit_census already carries that successor as a
CountedFrontierSite with its restoration trigger, so what was missing was not the
fact but the citation. Both rows now read the successor, so the derivation
observation_dwell_threshold rests on is grounded in the seed again.

THE NO-FABRICATION ROW WAS RED BY EXECUTION WHEN IT WAS WRITTEN, which is the
repair rather than the reporting. floor_resource_sample answered a fabricated 0
for rss_kb, cpu_ms and majflt while its own cgroup and vmstat readers already
answered `na`. So rss_kb=0 meant EITHER no resident pages -- which a live process
cannot have -- OR an unreadable /proc/self/statm, in the one instrument that
exists to settle a memory contradiction. Two conventions in one line, and the
invented one was silent. Repaired to the single `na` sentinel, cpu all-or-nothing
because a half-read stat cannot be summed. The row's third conjunct asks for the
FABRICATING spelling to be ABSENT, so restoring the zero reds here.

THE FEED IS DELETED BECAUSE ITS CONSUMER WAS. cli_run's HeartbeatFeed was read
only by claim_executor's deleted mirror; heartbeat_feed_enter_batch has had no
production caller since, so the two surviving writers fed a feed that could never
arm and no reader. Its 0-of-0 red control goes with its subject -- not a §4b(4)
climb, nothing climbed, the subject left. Leaving it standing is what would let a
future lockstep row go green over dead code, which is how this one broke.

Three stale prose citations repaired with it: std.observation's heartbeat-period
note and human-units contract both named the deleted emitter in the present
tense, and gunbc.observation_seed_render's seed_heartbeat_line claimed a
byte-equality mirror holds it. It does not; the fn is retained as the target of
the census's declared restoration, and the note now says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* review 56124: bind the no-fabrication row to the field it names, not to a spelling four readers share

THE FINDING IS CORRECT AND THE ROW WAS THE FAILURE IT DESCRIBES. Its first
draft asked for `unwrap_or_else(na)` and for the absence of the fabricating
`.map(|pages| pages * 4)`. The first needle also matches the cgroup and vmstat
readers, which have nothing to do with the field under test, so a regression
that fabricated a zero for RSS *after* the string conversion --

    .map(|pages| (pages * 4).to_string())
    .unwrap_or_else(|| 0.to_string())

-- satisfies all three conjuncts. My own RED control mutated the one shape the
third conjunct forbids and therefore proved less than it appeared to: the row
detected the mutation I chose, not the class it named. A check that passes over
the regression it is cited for is worse than absent (DESIGN 4b), and this one
was already cited in the PR body as the standing control.

THE REPAIR IS IN THE SEED, NOT IN A LONGER NEEDLE. Each field is now produced by
ONE line that names the field, and one renderer decides what an absent reading
looks like:

    fn floor_sampled_field(v: Option<u64>) -> String   // Some -> number, None -> sentinel
    fn floor_statm_rss_kb() -> Option<u64>             // None is the ONLY absent answer
    let rss_kb = floor_sampled_field(floor_statm_rss_kb());
    let majflt = floor_sampled_field(tick(9));
    let cpu_ms = floor_sampled_field(match (tick(11), tick(12)) { .. });

No field renders itself any more, so "fabricate a zero for this one field" is
necessarily an edit to a line that names that field. The four conjuncts are
those four lines, each measured unique in the file. Substituting a number for
RSS means deleting the rss_kb conjunct; weakening the sentinel means deleting
the renderer's None arm. The escape the review found has no spelling left.

`4` also stops being a bare literal in the RSS path (`KB_PER_PAGE`), which is
what made the old needle collide with an arithmetic shape rather than a fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 27, 2026
…and the third cli_invoke/walk_plan_stage deletion increment (#9391)

* Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns

#9228 deleted claim_executor's plan/walk surface and named its .dag residue rather
than sweeping it. This is that cut, plus one repair the census surfaced.

WHAT WENT, AT THE ROOT:

  PlanFunction and the plan argv builders. The coproduct modelled a closed roster of
  --plan-function targets; the flag no longer parses and the entry every variant named
  (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with
  it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the
  notice-title normalizer and shell suffix that existed only to feed them,
  claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/
  floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and
  gunbc_ci_floor_only_script.

  The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode
  (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell,
  release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is
  NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it
  records is still open for that one spelling.

  gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The
  second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that,
  and a second route to it here is the parallel authority the floor cut removed.

  The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore]
  harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness
  row. Their sole driver was the plan.dag recipes #9228 deleted.

  v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition::
  DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That
  arm's roster was one prefix and the family above was its entire population; its own header
  said "DISSOLVES when the fixture stops authoring test fns", and this is that condition.
  Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both
  sides deleted here.

  The pre-push witness-corpus gate. Not on the brief, found by the flag census:
  pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted
  floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only;
  its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms
  a gate" are deleted rather than weakened -- measured against the roster, the corpus binding
  was the only thing making them true, so they were green against the plan and false about the
  hook anyone runs.

THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope):

  Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION
  witness, which has nothing to do with plan/walk. Its own note records that these same
  specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which
  died with affected-set selection. This would have been the third home.

  They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns:
  three modules, no test fn, no effects, one consumer. No discovery exclusion is needed
  because there is nothing to discover, which is a stronger construction than the dir-grain
  exclusion the old home required.

  AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was
  ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied
  every row and the "strict-subset proof" the note describes was checked by nothing.
  ExpectScopedExactly compares the selected list to the expected list.

EVIDENCE, by execution on a release gunbc (remote, one dispatch):
  control    witness_touched_path_dispositions_hold -> true
  mutation   give scope_isolated an import edge to scope_shared -> false
  The mutation is exactly the strict-subset violation; the old assertion could not see it.

Rust: cargo check -p v1-compiler --bins clean, fmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Repair the scope-disposition witness's per-PR half, which the floor caught

dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining
and pins the disposition row count. Both moved with the rehoming and I checked only the
long-lane witness, so strict preparation refused with a name-resolution error before any
site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with
it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster
growing by one row because the strict-subset proof needs three specimens where the old
home carried two.

The pin doing its job here is the argument for keeping it: a count that had to be updated
by hand is exactly what stopped this rehoming from silently shipping a roster of a
different size than the one the note describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI

REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct.

WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script()
alone, because its other half emitted a `claim_executor --plan-entry` line naming an
entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived
was a callable verb that builds the release binaries, verifies the artifacts, and exits
0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure
mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported
under the name of the larger one. §5's absorbing-fallback rule is about a failure arm
that widens; this is its mirror at the success arm, a green that narrowed.

WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the
reviewer's other option and I am not taking it, on the grounds this branch already
argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a
second route to it is the parallel authority the floor cut removed. The verb also has no
distinct job left -- "build the release binaries and verify the artifacts" already has a
name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is
not an authority that lost its body; it is a name with nothing left to denote.

THE CENSUS, cut at the root and followed where it led:
  dag/tools/gunbc_ci.dag                     the entry module, deleted
  main.rs Commands::Ci + its arm             the CLI verb
  gunbc.cli_dispatch_surface "ci" row        the modeled CLI surface
  gunbc_cli_dispatch_surface.rs              its generated mirror
  v2.workflow.ci_release_build_emit          gunbc_ci_run_script, the wrapper
  std.emit_on_demand gunbc_ci_emission_surface   the wet-surface row naming tools.gunbc_ci main
  emit_on_demand_kernel_witness_test         its enrollment assertion
  wall_residue_live_test residue_gunbc_ci_clean  a test fn whose subject was the deleted file

ci_release_build_script itself is UNTOUCHED and still has three consumers
(ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes.

EVIDENCE, build lane on this tree (remote, one dispatch):
  required-ci: lane=build phases_run=2 failed=0
  regen first_generation_equal=true    -- the mirror edit is byte-equal to the emitter's
                                          own output, established by the gate rather than
                                          by my reading of the diff
  v2-emission blocking=0, census 3792 -> 3791, the one deleted module

The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands
needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Name the admission order's next-rung trigger, so the gap reads as unbuilt

The header already said the surviving long-home-over-live-tree precedence has
no executing discriminator and must not be cited as covered. It did not say
what would make it coverable again, which leaves a reader unable to tell
cannot-cover-yet from nobody-built-it -- the distinction DESIGN 4b(2) exists to
keep.

The trigger is a decline whose subject CAN collide with an existing one: a site
that legitimately satisfies two decline reasons at once, so which reason it
reports is a decision some input can get wrong. At that point a discriminating
witness is authorable and is owed. Until then the correct response to the
absence is to build that collision case, not to re-point a witness at a subject
that cannot disagree with itself -- which would be permanently green by
construction, and cited as coverage.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 1, 2026
…itations found BOTH were false

XL-N caught two defects in the row. Both are fixed, and the second one turned
the row's own content inside out in a way worth recording.

DEFECT 1, THE REMEDY WAS ONE ARM AND NEEDED THREE. "Past tense with the date,
never deletion" is correct only for a claim that WAS true and whose executor
died. Past-tensing a never-true claim manufactures a false historical statement
— "X USED TO resolve Y" asserts an execution that also never happened. And my
own item 1 shows a third case: the instrument_sandbox live half DOES execute,
via a local recipe, and OfflineLocalRecipe HAS a route — so the sentence names
the WRONG AUTHORITY for a live relation, and past-tensing it would record a live
relation as dead. That is a new contamination in the opposite direction,
produced by the remedy itself, which is exactly what this row exists to name.
A remedy mechanical enough to apply without reading WILL be applied without
reading. The row now carries one remedy arm per origin, and the
"never deletion" absolute is softened to a default: a sentence whose entire
content is a false execution claim has no reasoning to preserve.

DEFECT 2, AND IT IS THE MORE USEFUL ONE. XL-N asked me to verify the two
cli_run.rs notes rather than inherit them, on the grounds that a row about
unbacked claims should not itself contain one. It did contain two — and
verifying killed BOTH of my origin-B citations:

- floor_component_resource_checkpoint_note and
  floor_component_phase_journal_scaffold_note were REAL `data …: String`
  declarations in gunbc.floor_component_receipt. They were removed on
  2026-08-30 by the prose-bankruptcy sweep #9752, which converted module-scope
  commentary rows into §4c annotations corpus-wide.
- claim_executor DID resolve gunbc.floor_component_receipt:
  write_floor_component_receipt_at joined gunbc/floor_component_receipt.dag
  directly, from #7467 (2026-07-30) until #9228 deleted it (2026-08-25).

So ORIGIN B — never backed at all — HAS ZERO VERIFIED INSTANCES here. It is
recorded as conceivable and unmeasured, with its remedy arm, rather than as a
population. I had asserted a two-origin class on the strength of two claims I
had not checked.

WHAT THE VERIFICATION FOUND INSTEAD is a third real origin with a corpus-wide
producer: THE CITED SYMBOL DIED WHILE ITS CONTENT SURVIVED AS AN ANNOTATION.
§4c makes an annotation uncitable by construction — no Accepted program can
read one — so every citation of a row #9752 converted was dangling the moment
that sweep landed. The population is that sweep's diff, not anything about this
module. Its remedy is its own arm: name the module and the FACT, since there is
no symbol left to cite; past-tensing would report the content as gone when only
its citability is.

RECOGNITION RULE EARNED, and it is now in the row: "resolves nowhere NOW" is
not "never resolved". The distinction is decided by history, not by the working
tree, and the instrument is `git log --all -S` over the DECLARATION FORM —
which also separates the two attested origins by showing WHAT deleted the
referent. Nothing but a reviewer asking for verification caught this.

CORRECTIONS TO WHAT I ALREADY LANDED, applying the arms to my own diff:
- ci_failure_class: my first pass DELETED the claim_executor comparison as
  false. It was true. Restored in the past tense with both dates, as the worked
  precedent it still is — remedy arm 1, not arm 4.
- cli_run.rs, both sites: my first pass said the two notes "resolved in neither
  the receipt module nor anywhere else". False. Now records that #9752 made them
  uncitable and the pair was deleted after — remedy arm 2.

docs/design-ledgers.md reprojected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz
gunbai-bot Bot added a commit that referenced this pull request Sep 1, 2026
…model with no producer, reciting a deleted transport in the present tense (#9858)

* XL-0-RECEIPT: delete the floor component receipt pair — a well-built model with no producer, reciting a deleted transport in the present tense

gunbc.floor_component_receipt and gunbc.floor_component_receipt_document
describe, in the present tense, an alert that downloads an artifact named
floor-component-receipt from a run id it is given and reads four named fields.
That alert was falsifier-alert.yml, deleted on 2026-08-15 in the CI cut. A
later lane read the module, believed the transport live, planned against it,
and was corrected by its reviewing authority. That is premise contamination —
the class the CI rung drop names in its own words — appearing in a module
rather than in the canonical authority.

CENSUS (reproduced on main 37e705c, not inherited), per medium, because a
survivor stops being reached silently and a reach measurement over one medium
reads exactly like a reach measurement:

- PRODUCER: none. Nothing in src/ or dag/ writes target/floor-component-receipt.json;
  no Rust carries the schema string floor-component-receipt/v1 or its members.
- CONSUMER, workflow argv: witnesses.yml uploads exactly four artifacts —
  required-floor-disposition, expected-red-roster-join, long-home-storage-agreement,
  required-floor-claim-cost. The receipt is not among them, and only
  witnesses.yml / fleet-converge.yml / fleet-desired.yml remain.
- CONSUMER, import graph: the only importer of either module is their own
  witness test, which is a PEER of the subject, not a guard over a survivor.
- CONSUMER, exported symbols: FloorComponentReceipt, FloorComponentReceiptDocument,
  FloorComponentReceiptSubject, ComponentAlertSummary and the schema/path/artifact-name
  rows resolve nowhere outside the pair. FloorComponentFailureMode and
  ComponentOutcomeRead appear only in two gunbc.non_fold_residue prose rows.
- CONSUMER, Cargo [[bin]]: none. Rust: one string literal used as a test label
  in cli_run.rs, not a call.

WHY THIS IS NOT A QUIET GUARD. Three questions decide: mechanism existence,
join reachability, current occupancy. Yes/yes/zero is a healthy guard being
quiet. Here the answer is NO at the first — there is no producer at all, so the
join is UNREACHABLE rather than merely unoccupied. That distinction is the
whole difference between retiring a dead model and deleting a live wall.

DISPOSITION: delete. This completes floor-cut Step 2, which already named both
files by identity as machinery that "falls out" once reachability confirms —
they survived the cut and stopped being reached, which is exactly the third
bound that plan records the census cannot see. DESIGN section 6: a new artifact
with no final consumer is experimental residue, and the reviewer's test is
whether it survives the terminal architecture AND is consumed by it. The model
is well built; that is not an answer to that test.

Landed with it: the two non_fold_residue frontier rows and their reason and
dissolution strings; and every surviving citation of the pair rewritten to the
past tense with the deletion and its date recorded, because a citation left
naming a deleted symbol fakes a grep hit for the next reader. Two of those were
already false before this change — ci_failure_class claimed claim_executor
"already resolves gunbc.floor_component_receipt" (it never did), and cli_run.rs
twice cited floor_component_resource_checkpoint_note and
floor_component_phase_journal_scaffold_note, which resolved in neither the
receipt module nor anywhere else.

DURABLE HOME for the finding: a receipt appended to the
reachability_read_as_occupancy row in gunbc.recurring_failure_mode, which had
only the "do not delete a quiet guard" pole and now carries the discriminating
counter-specimen for the other one. docs/design-ledgers.md is reprojected.

NOT WIDENED, flagged instead: src/v2/workflow/ci_floor_peak_emit still emits a
shell echo naming "the floor-component-receipt artifact", and its own emission
does not appear in witnesses.yml. That is a separate unconsumed emit surface,
not this cut.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz

* Roster the class at its real grain: unbacked_execution_claim, one class with two origins

XL-N extended the lane: the receipt's present-tense recital is probably not
alone, and if so the class is not about the falsifier and not about the receipt.
It is PROSE ASSERTING A LIVE EXECUTING RELATION THAT NO AUTHORITY BACKS. New
roster row gunbc.recurring_failure_mode unbacked_execution_claim, projected into
DESIGN.md's index and docs/design-ledgers.md; the recital half is lifted off
reachability_read_as_occupancy, which keeps only the consequence for ITS rule
(a good model with no consumer is still residue) and points at the new row.

ONE CLASS, TWO ORIGINS, and that is a decision with a reason. Origin A is
falsified by a later deletion (the receipt's alert). Origin B is FALSE WHEN
WRITTEN — ci_failure_class claimed claim_executor "already resolves
gunbc.floor_component_receipt" and it never did; cli_run.rs twice cited two
notes that resolve nowhere. The origins differ, but the recognition rule and the
remedy are identical, so they are a FIELD of one row rather than two rows; two
rows would fork one recognition rule.

I APPLIED XL-N's TEST, not the runs/enrolled one, reading each line in context
rather than from the grep window. std.witness_admission
witness_cadence_has_scheduled_route is the single authority: does the prose
imply a live route for an arm it says is routeless?

RESULT: SIX CANDIDATES, FIVE CONTAMINATING, ONE FALSE POSITIVE.

CONTAMINATING (none in modules this PR otherwise touches — listed for routing,
deliberately NOT fixed here, per the stop line):

1. dag/test/claim/instrument_sandbox_witness_test.dag
   fixture_line_remaining's preceding annotation: "stays per-PR while the live
   half runs on the falsifier lane". The live half is
   dag/test/claim/long/instrument_sandbox_live_witness_test.dag, enrolled on
   gunbc.ci_layer_roots falsifier_substrate_long_lane_rows =
   FalsifierSubstrateLongLane, routeless. Present-tense "runs". The same file's
   line 55 also claims that half moved "with a named executing consumer".
   NOTE: that half DOES carry a local recipe, and OfflineLocalRecipe has a route
   — so the repair is to name the recipe, not to call the witness unexecuted.

2. dag/test/claim/self_host_use_site_verdict_behavioral_witness_test.dag
   self_host_use_site_verdict_behavioral_receipt_holds's annotation:
   "Live host effects — nightly falsifier Wet batch when frontier row is
   SelfEmitted with binding". FalsifierSelfHostWet, routeless. The condition is
   about frontier state, not about the cadence existing.

3. dag/test/claim/self_host_body_producer_behavioral_witness_test.dag
   self_host_body_producer_behavioral_receipt_holds's annotation: same sentence,
   same arm.

4. dag/test/claim/self_host_logic_behavioral_witness_test.dag
   self_host_logic_behavioral_receipt_holds's annotation: "so it RUNS IN the
   nightly falsifier Wet follow-on batch (falsifier_self_host_wet_entries), not
   per-PR hermetic discovery or bin_witness_wet". The strongest instance —
   explicit present-tense execution, naming the routeless arm, and contrasting
   it against the one cadence that does have a route.

5. dag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag
   the annotation above perturb_cross_tree_import_corpus_green_holds:
   "Enrolled on falsifier_rehomed_bin_wet_entries (nightly batch 5)".
   THIS IS THE ARM THE NAIVE DISCRIMINATOR LOSES. "Enrolled on" is TRUE.
   "(nightly batch 5)" asserts a cadence that executes, and
   FalsifierRehomedBinWet is routeless. Minimal repair: strike "nightly" — the
   line already carries a local recipe, which is a real route.

FALSE POSITIVE, and it is the exemplar of the remedy rather than a specimen:

6. dag/gunbc/commit_workflow.dag, the annotation above
   ci_floor_witness_enrollment_note's neighbours: "moved from per-PR to the
   4-hour falsifier cadence" sits inside a block opening "RETIRED 2026-08-20 —
   the subject of this row no longer exists" and attributes the sentence to an
   "ORIGINAL CLAIM (operator ruling 2026-07-25)". Correctly framed already.
   Second false positive, already known and not re-derived:
   gunbc.rust_item_host_observation's "executes as the falsifier" — falsifier as
   a ROLE, the discriminating test, matching every keyword and meaning nothing
   of the kind.

WHY THE REMEDY IS PAST TENSE AND NOT DELETION: the reasoning these sentences
support usually survives its executor, and a reader who finds a dangling claim
silently removed learns nothing. That is positional_citation's neighbouring
rule — a citation left naming a deleted symbol fakes a grep hit — so the
correction records the deletion rather than removing the name.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz

* The remedy field branches on origin — and verifying my own origin-B citations found BOTH were false

XL-N caught two defects in the row. Both are fixed, and the second one turned
the row's own content inside out in a way worth recording.

DEFECT 1, THE REMEDY WAS ONE ARM AND NEEDED THREE. "Past tense with the date,
never deletion" is correct only for a claim that WAS true and whose executor
died. Past-tensing a never-true claim manufactures a false historical statement
— "X USED TO resolve Y" asserts an execution that also never happened. And my
own item 1 shows a third case: the instrument_sandbox live half DOES execute,
via a local recipe, and OfflineLocalRecipe HAS a route — so the sentence names
the WRONG AUTHORITY for a live relation, and past-tensing it would record a live
relation as dead. That is a new contamination in the opposite direction,
produced by the remedy itself, which is exactly what this row exists to name.
A remedy mechanical enough to apply without reading WILL be applied without
reading. The row now carries one remedy arm per origin, and the
"never deletion" absolute is softened to a default: a sentence whose entire
content is a false execution claim has no reasoning to preserve.

DEFECT 2, AND IT IS THE MORE USEFUL ONE. XL-N asked me to verify the two
cli_run.rs notes rather than inherit them, on the grounds that a row about
unbacked claims should not itself contain one. It did contain two — and
verifying killed BOTH of my origin-B citations:

- floor_component_resource_checkpoint_note and
  floor_component_phase_journal_scaffold_note were REAL `data …: String`
  declarations in gunbc.floor_component_receipt. They were removed on
  2026-08-30 by the prose-bankruptcy sweep #9752, which converted module-scope
  commentary rows into §4c annotations corpus-wide.
- claim_executor DID resolve gunbc.floor_component_receipt:
  write_floor_component_receipt_at joined gunbc/floor_component_receipt.dag
  directly, from #7467 (2026-07-30) until #9228 deleted it (2026-08-25).

So ORIGIN B — never backed at all — HAS ZERO VERIFIED INSTANCES here. It is
recorded as conceivable and unmeasured, with its remedy arm, rather than as a
population. I had asserted a two-origin class on the strength of two claims I
had not checked.

WHAT THE VERIFICATION FOUND INSTEAD is a third real origin with a corpus-wide
producer: THE CITED SYMBOL DIED WHILE ITS CONTENT SURVIVED AS AN ANNOTATION.
§4c makes an annotation uncitable by construction — no Accepted program can
read one — so every citation of a row #9752 converted was dangling the moment
that sweep landed. The population is that sweep's diff, not anything about this
module. Its remedy is its own arm: name the module and the FACT, since there is
no symbol left to cite; past-tensing would report the content as gone when only
its citability is.

RECOGNITION RULE EARNED, and it is now in the row: "resolves nowhere NOW" is
not "never resolved". The distinction is decided by history, not by the working
tree, and the instrument is `git log --all -S` over the DECLARATION FORM —
which also separates the two attested origins by showing WHAT deleted the
referent. Nothing but a reviewer asking for verification caught this.

CORRECTIONS TO WHAT I ALREADY LANDED, applying the arms to my own diff:
- ci_failure_class: my first pass DELETED the claim_executor comparison as
  false. It was true. Restored in the past tense with both dates, as the worked
  precedent it still is — remedy arm 1, not arm 4.
- cli_run.rs, both sites: my first pass said the two notes "resolved in neither
  the receipt module nor anywhere else". False. Now records that #9752 made them
  uncitable and the pair was deleted after — remedy arm 2.

docs/design-ledgers.md reprojected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz

* Cite the census that already owns this population instead of minting a second authority

Found while pre-reading the five corrections for PR two:
gunbc.deleted_cadence_reference_census ALREADY EXISTS and already owns the
falsifier-cadence instance of this class. Twelve sites, a
DeletedCadenceReferenceStanding vocabulary whose PremiseInvalidated arm is
exactly "the prose asserts a cadence that no longer executes", and one
GuaranteeRungDrop filed ONCE for the shared executor rather than per site —
with its own note explaining that twelve copies of five fields would be twelve
places to update when the route returns.

The row I was about to land described that population as though it were an
open finding. That is a second authority for a fact that already has one —
the §3 violation this row's own remedy exists to prevent, committed inside the
row, which is the third time this lane has caught the class reproducing itself
in its own remedy.

The row now CITES the census and copies nothing from it. What stays here is
only the recognition rule and the remedy arms, which generalize past the
falsifier; the population, its standings and its drop stay where they already
live.

TWO THINGS THIS CHANGES FOR PR TWO, recorded now so the next session does not
re-derive them:

1. My five corrections are NOT in the census's twelve. The census subject is
   "authority rows whose stated enforcement, audit or backstop was the
   affected-set falsifier cadence" — rows that RELIED on the cadence. My five
   are witness-test annotations asserting their OWN cadence. Whether that is
   the same subject or an adjacent one is the first question PR two answers,
   and it is answered against the census's declared subject, not by me.
   Either way the five get enrolled or the subject gets widened deliberately —
   they do not get freelance prose edits beside an existing authority.

2. The corpus has already applied my remedy arm 1 correctly, twice, in the
   exact wording the row now recommends: ci_layer_roots bin_witness_wet_note
   carries "THE JUSTIFYING HALF OF THAT SENTENCE IS PAST TENSE (2026-08-26)"
   with the deleting commit and the census citation, and
   namespace_import_closure_behavioral_transport nic_doc carries
   "classification is membership, not execution". Those are the exemplars PR
   two should match rather than invent a house style beside.

docs/design-ledgers.md reprojected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz

* Origin 2's population is ZERO, not the sweep's diff — and the correction is better than the claim was

gentle-bear-446 (XL-0-CITE) measured the population I flagged and it is zero.
I verified both of their load-bearing facts rather than inheriting them.

WHAT I HAD WRONG. The row reasoned that because §4c makes annotations
uncitable, the prose-bankruptcy sweep broke every citation of a converted row,
making the population the sweep's own diff. The premise is right and the
conclusion is backwards: v1_compiler.cli_run annotation_erased_scan_text feeds
the semantic passes, so annotation text is not in the tree the harvester walks,
and v1_compiler.declaration_index admits citations from exactly two producers,
citation_from_record_literal and citation_from_constructor_call. A plain name in
annotation prose was never a citation, so the sweep could not break one.
Measured zero today AND as of the sweep commit, on a control that discriminates
in both directions — so it is not a zero produced by someone repairing it later.

WHAT THAT LEAVES IS A BETTER ROW, not a smaller one. These citations bind
READERS and no mechanism, so they belong in §4b's OUTSIDE THE MODELED GUARANTEE
column — observed and repaired by reading, never gated. Calling them a
dangling-citation population would have been rung inflation about a check that
by construction cannot see them. The two cli_run sites remain genuine instances
of the harm, and the honest statement is that no mechanical census would have
found them.

SECOND CORRECTION, TO A DATE BOTH I AND MY MANAGER REASONED FROM. We both
framed this as a measurement of what the cited-symbol drop cost while it stood.
It was not standing. Verified in the drop's own row: "THE RESTORATION TRIGGER
FIRED ON 2026-08-25 AND THIS ROW IS RETIRED AS A DROP", restored strictly wider
as v1_compiler.declaration_index in the parse phase of --required-ci. The sweep
landed 2026-08-30, five days AFTER, under a live and wider check.

AND THAT MISFRAMING HAS A CAUSE WORTH ROUTING, which I am reporting rather than
fixing because it is load-bearing §4b modeling and outside this disposition:

  gunbc.design_document, the §4b rung-drop list — DESIGN.md's
  "The ones standing today:" is projected by
  `map(rung_drop_roster, d => …)` with NO filter, so it enumerates every row in
  the roster including retired ones. One of the nine listed is retired. The
  retirement is recorded only in prose inside the row's own body, so the
  projection cannot filter on it: the fix is a modeled retirement field on the
  drop carrier, not a predicate over existing data. This is the canonical
  authority asserting a live state its own ledger contradicts — this row's class
  in the document that defines it — and it is what led two sessions tonight to
  reason about an unguarded window that did not exist.

docs/design-ledgers.md reprojected.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Li6e7cEDFodeBV7uPi3yTz

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
…h the observation model again

Lane B of the process-observability brief.

Row: conformance-observability on gunbc.design_argument conformance_domains, homed on
std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and
gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting;
repository populations stay with gunbc.repository_census_observation, delivery with effects.

Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation
row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in
gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall,
seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults,
rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the
stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its
own rate/share functions. seed_heartbeat_line is the oracle over that input space;
cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no
interpreter on that thread); floor_resource_sample and the stall window become typed
producers (FloorResourceSample, floor_stall_window_observation) with None for unread
sources -- nothing formats a number outside the mirror.

Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes
on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat,
the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing;
cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror
byte-equal to the interpreter on the same two specimens (off the merge path: rung drop
rust_unit_tests_off_the_merge_path).

Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and
consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is
ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep.
seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory]
lived only in required_floor_runner.rs, so the census could not find its own row and the
declined hygiene suite reported nothing. New executing witness
observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep)
are repaired to the restored subject and their standing restated -- the lockstep
no-fabrication row had gone false a second time on the same cli_run split.

DESIGN.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH
briansrls pushed a commit that referenced this pull request Sep 11, 2026
…h the observation model again (#11017)

* §3b decision/selection conformance row; §3d reviewer narrowed to the hard laws

Adds the conformance-decision domain to gunbc.design_argument conformance_domains,
homed on std.decision (DecisionSubject, RealizationSelectionResult, SelectionReceipt,
select_realization) and std.pareto (SelectionAxis, ParetoEntry, DominanceVerdict).
The row is narrow: inhabitance of the decision/Pareto models, or a stated departure.
Consumer route for the home: gunbc.spark.serving_deployment_selection
select_serving_deployment and product.fleet_operating_point fleet_operating_point_selection
call select_realization; exercised by test.claim.spark.serving_deployment_selection_witness_test
and test.claim.realization_selection_witness_test.

The s3d.selection-precedes-convergence reviewer keeps only the hard laws (no answer
outrunning field/constraints/evidence/policy; a front is not a winner; missing funded
evidence is never a fabricated zero or settled fact; goal assessment/ensure never choose)
and says a stated home departure excuses none of them. Home-inhabitance tells moved to
the conformance row.

Witness: a_stated_departure_from_the_decision_home_is_admitted_while_the_selection_law_still_fails
folds one plan through the existing review machinery -- conformance-decision answers
DivergesStated (approved with reason), selection-precedes-convergence requests changes on the
same file, the report fails; the converse plan with the laws honoured approves.

gunbc.design_document: "missing authority" -> "selection authority" in §3d; §3b no longer
claims the overlap counter proves the partition (review_criterion_identities_are_unique proves
unique keys only and disclaims semantic exclusivity); scope/ownership mismatch distinguished
from a non-resolving citation; §3d records the admitted row and that the effectful
convergence cycle (plan, admission, actuation, readback) still has no consumed home.
DESIGN.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

* §3b observability conformance row; the floor heartbeat renders through the observation model again

Lane B of the process-observability brief.

Row: conformance-observability on gunbc.design_argument conformance_domains, homed on
std.observation (ObservationEvent, RecordedObservation, ObservationPresentation) and
gunbc.observation_ci_render (ci_event_line, ci_render_line). Scoped to process reporting;
repository populations stay with gunbc.repository_census_observation, delivery with effects.

Heartbeat repair (gunbc.observation_emit_census floor_heartbeat_site, a MigratedToObservation
row #9228 silently reverted to a raw [floor-heartbeat] eprintln): HeartbeatSample in
gunbc.observation_ci_render is REPLACED with the one-attempt floor's real sample -- wall,
seam subject, and every /proc and cgroup reading as a Measured arm (cpu delta, major faults,
rss, cgroup charge, high/max/local-high events, host swap-in and major faults) plus the
stall window as gunbc.memory_stall_refusal's own MemoryStallObservation, rendered by its
own rate/share functions. seed_heartbeat_line is the oracle over that input space;
cli_run render_heartbeat_line_mirror is the seed mirror the liveness thread calls (no
interpreter on that thread); floor_resource_sample and the stall window become typed
producers (FloorResourceSample, floor_stall_window_observation) with None for unread
sources -- nothing formats a number outside the mirror.

Evidence: test.claim.observation_seed_heartbeat_witness_test (SubstrateInputsOnly, executes
on the floor) pins the oracle's exact bytes for a fully-read beat and an all-unreadable beat,
the refusal-authority stall arithmetic, no fabricated zero, and a zero-wall window refusing;
cli_run heartbeat_tests::render_heartbeat_line_mirror_matches_seed_oracle holds the mirror
byte-equal to the interpreter on the same two specimens (off the merge path: rung drop
rust_unit_tests_off_the_merge_path).

Census extension: CensusedEmitSite gains producer (DeclarationRef into hand Rust) and
consumption (MachineConsumed | HumanPresentationOnly | ConsumerUnresolved); every row is
ConsumerUnresolved with its in-repo search stated, never human-only on a prefix grep.
seed_emit_sources gains the cli_run/ split files it had fallen behind: [floor-claim-memory]
lived only in required_floor_runner.rs, so the census could not find its own row and the
declined hygiene suite reported nothing. New executing witness
observation_emit_census_producer_witness_test; the declined suites (emit census, lockstep)
are repaired to the restored subject and their standing restated -- the lockstep
no-fabrication row had gone false a second time on the same cli_run split.

DESIGN.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

* floor_sampled_field keeps its sentinel beside its remaining consumer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

* the heartbeat mirror is crate-visible like its sample

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

* seed_heartbeat_line takes std.measure carriers across the seam

Review 63436: cpu_ms/cgroup_charge_bytes/stall_window_ms/stall_user_cpu_ms (and
elapsed_ms, rss_bytes) were bare Nat with a unit suffix. They are now Millisecond /
ByteSize, on the precedent of ci_batch_summary_text's `work: Nanosecond`; the seed test
builds each carrier through the interpreter's millisecond / byte_size constructor, so a
caller handing the wrong unit cannot typecheck. Dimensionless counts stay Nat.
Oracle test green locally (3/3); floor witness 5/5.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012n8gXc7UmPvcSqoPdHR4ZH

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant