Skip to content

Delete the .dag residue of the deleted plan/walk CLI surface (PlanFunction, cli_invoke builders, walk_plan_stage fixture family) - #9252

Merged
briansrls merged 8 commits into
mainfrom
session/crisp-swift-16
Aug 26, 2026
Merged

briansrls merged 8 commits into
mainfrom
session/crisp-swift-16

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session crisp-swift-16.
Pushing to session/crisp-swift-16 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 3 commits August 26, 2026 00:46
…ope-disposition witness a fixture home it owns

#9228 deleted claim_executor's plan/walk surface and named its .dag residue rather
than sweeping it. This is that cut, plus one repair the census surfaced.

WHAT WENT, AT THE ROOT:

  PlanFunction and the plan argv builders. The coproduct modelled a closed roster of
  --plan-function targets; the flag no longer parses and the entry every variant named
  (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with
  it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the
  notice-title normalizer and shell suffix that existed only to feed them,
  claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/
  floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and
  gunbc_ci_floor_only_script.

  The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode
  (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell,
  release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is
  NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it
  records is still open for that one spelling.

  gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The
  second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that,
  and a second route to it here is the parallel authority the floor cut removed.

  The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore]
  harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness
  row. Their sole driver was the plan.dag recipes #9228 deleted.

  v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition::
  DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That
  arm's roster was one prefix and the family above was its entire population; its own header
  said "DISSOLVES when the fixture stops authoring test fns", and this is that condition.
  Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both
  sides deleted here.

  The pre-push witness-corpus gate. Not on the brief, found by the flag census:
  pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted
  floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only;
  its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms
  a gate" are deleted rather than weakened -- measured against the roster, the corpus binding
  was the only thing making them true, so they were green against the plan and false about the
  hook anyone runs.

THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope):

  Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION
  witness, which has nothing to do with plan/walk. Its own note records that these same
  specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which
  died with affected-set selection. This would have been the third home.

  They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns:
  three modules, no test fn, no effects, one consumer. No discovery exclusion is needed
  because there is nothing to discover, which is a stronger construction than the dir-grain
  exclusion the old home required.

  AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was
  ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied
  every row and the "strict-subset proof" the note describes was checked by nothing.
  ExpectScopedExactly compares the selected list to the expected list.

EVIDENCE, by execution on a release gunbc (remote, one dispatch):
  control    witness_touched_path_dispositions_hold -> true
  mutation   give scope_isolated an import edge to scope_shared -> false
  The mutation is exactly the strict-subset violation; the old assertion could not see it.

Rust: cargo check -p v1-compiler --bins clean, fmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Conflict: ci_layer_roots' walk_plan_stage_control_fixture_exclusion_note. Main edited
the row beside it; this branch deletes the row itself with the fixture family. Took
this branch's side -- the 2026-07-11 fixture-home ruling it carried is restated in
witness_admission_fixture_note, which survives.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…aught

dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining
and pins the disposition row count. Both moved with the rehoming and I checked only the
long-lane witness, so strict preparation refused with a name-resolution error before any
site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with
it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster
growing by one row because the strict-subset proof needs three specimens where the old
home carried two.

The pin doing its job here is the argument for keeping it: a count that had to be updated
by hand is exactly what stopped this rehoming from silently shipping a roster of a
different size than the one the note describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 26, 2026 02:24
@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

MEASURED, floor lane green on d6bc492a7c9 (run 32919206285, job 98029189454, 48m29s):

this branch   [floor-phase] site-projection  sites=12601 files=1630 claims=11145 declined_long=554                    declined_live=902
              required-floor: offered=12601 routed=11145 declined_long=554 declined_live=902
              planned=11145 executed=11145 terminal=11145 passed=10990 known_red_held=30 failed=0

against the last green main run (32918313547, 5625bbd5e):

main          [floor-phase] site-projection  sites=12601 files=1639 claims=11136 declined_long=554 declined_fixture=9 declined_live=902
              required-floor: offered=12601 routed=11136 declined_long=554 declined_fixture=9 declined_live=902

declined_fixture=9 is gone — not zero, ABSENT: the disposition no longer exists, so the
partition is now offered = routed + declined_long + declined_live, and it closes
(11145 + 554 + 902 = 12601). SitePartitionInexact is the wall that would have caught an
arm quietly swallowing rows, and it did not fire. failed=0.

files drops by exactly 9, which is the 9 walk_plan_stage modules that authored test fns
(the family is 11 files; common.dag and overlap_coordination.dag author none).

WHAT I AM NOT CLAIMING, because it would be two trees compared as one. offered is 12601 on
both sides and routed rises by exactly 9. The 9 removed sites are attributable to this cut;
the 9 that replaced them in the denominator are not — main moved between the two runs, and I
have not established what it added. The honest statement is that this cut removes 9 sites from
discovery and the partition still closes, NOT that the roster is unchanged in size.

One correction to the brief that dispatched this. It said the nine members sit as permanent
residue on v2.workflow.floor_expected_red (2) and v2.workflow.floor_route_gap (7), and that
deleting them empties nine rows off two self-emptying ledgers. Grepped: neither roster carries
an authored row for any of them. That was the state the required_floor header DESCRIBES as
the cost of the arm being unstated — and the arm landing is what fixed it, before this PR. Since
then the nine were DeclinedFixtureMember at runtime. So the debt reduction is real but it is
one ledger, not two: nine sites leave discovery entirely, where before they were discovered,
counted, and declined on every run.

Discriminating red for the rehomed scope-disposition witness (release gunbc, remote, one dispatch):

control     witness_touched_path_dispositions_hold -> true
mutation    scope_isolated gains an import edge to scope_shared -> false

That mutation is exactly the strict-subset violation. Under the old ExpectScopedContaining
it would have stayed green, because membership is satisfied by a selector that returns the
whole roster — which is what made the rehoming worth doing rather than just relocating.

gunbc-ci-auto-heal and others added 2 commits August 26, 2026 03:05
…greens without running CI

REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct.

WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script()
alone, because its other half emitted a `claim_executor --plan-entry` line naming an
entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived
was a callable verb that builds the release binaries, verifies the artifacts, and exits
0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure
mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported
under the name of the larger one. §5's absorbing-fallback rule is about a failure arm
that widens; this is its mirror at the success arm, a green that narrowed.

WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the
reviewer's other option and I am not taking it, on the grounds this branch already
argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a
second route to it is the parallel authority the floor cut removed. The verb also has no
distinct job left -- "build the release binaries and verify the artifacts" already has a
name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is
not an authority that lost its body; it is a name with nothing left to denote.

THE CENSUS, cut at the root and followed where it led:
  dag/tools/gunbc_ci.dag                     the entry module, deleted
  main.rs Commands::Ci + its arm             the CLI verb
  gunbc.cli_dispatch_surface "ci" row        the modeled CLI surface
  gunbc_cli_dispatch_surface.rs              its generated mirror
  v2.workflow.ci_release_build_emit          gunbc_ci_run_script, the wrapper
  std.emit_on_demand gunbc_ci_emission_surface   the wet-surface row naming tools.gunbc_ci main
  emit_on_demand_kernel_witness_test         its enrollment assertion
  wall_residue_live_test residue_gunbc_ci_clean  a test fn whose subject was the deleted file

ci_release_build_script itself is UNTOUCHED and still has three consumers
(ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes.

EVIDENCE, build lane on this tree (remote, one dispatch):
  required-ci: lane=build phases_run=2 failed=0
  regen first_generation_equal=true    -- the mirror edit is byte-equal to the emitter's
                                          own output, established by the gate rather than
                                          by my reading of the diff
  v2-emission blocking=0, census 3792 -> 3791, the one deleted module

The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands
needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in b29781b7a19. review 56054 is right, and the framing is worth restating because it names a failure mode this branch was otherwise about removing.

The defect is not a wrong answer. It is a CORRECT answer to a much smaller question, reported under the name of the larger one: gunbc ci built the release binaries, verified the artifacts, and exited 0. DESIGN §5's absorbing-fallback rule covers a failure arm that widens; this is its mirror at the success arm, a green that narrowed. Same class, opposite side.

I took the first of your two options — delete the entry point — rather than binding it to claim_executor --required-ci, on the grounds this branch already argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a second route to it here is the parallel authority the floor cut removed. The verb also has no distinct job left. "Build the release binaries and verify the artifacts" already has a name, ci_release_build_script, and fleet-converge.yml already calls it — so the verb was not an authority that lost its body, it was a name with nothing left to denote.

Cut at the root and followed where it went: dag/tools/gunbc_ci.dag, Commands::Ci and its arm, the "ci" row in gunbc.cli_dispatch_surface and its generated mirror, gunbc_ci_run_script, std.emit_on_demand gunbc_ci_emission_surface and its enrollment assertion in emit_on_demand_kernel_witness_test, and residue_gunbc_ci_clean in wall_residue_live_test whose subject was the deleted file. ci_release_build_script is untouched — three consumers remain.

Evidence, build lane on this tree (remote, one dispatch):

required-ci: lane=build phases_run=2 failed=0
regen first_generation_equal=true
v2-emission blocking=0, census 3792 -> 3791

The regen line is the load-bearing one: I edited the generated mirror by hand, so first_generation_equal=true is the gate establishing that edit is byte-equal to what the emitter produces, rather than my reading of the diff. And gap_is_non_empty_while_the_divergence_row_stands still holds — it needs one AbsentFromEmitMainRs row and 17 remain.

ONE NOTE ON THE RED CI ON THE PREVIOUS SHA, since it will be in this PR's history and it was not a defect. All three lanes on run 32925394022 report fail, and all three were CANCELLED — gh pr checks renders cancelled and failed identically. The floor got 48 minutes in and was cancelled mid-fold at 10000/11204; the same floor passed on d6bc492a7c9 at 48m29s. I ran the build lane myself on the cancelled commit before its log was available and got phases_run=2 failed=0. Recording it because a reader scanning check states would otherwise conclude this branch broke something and then look for what.

— sent from crisp-swift-16

gunbai-bot Bot pushed a commit that referenced this pull request Aug 26, 2026
…enty-seven witnesses that were never its

DESIGN authorised this cut and got its population wrong, which is the finding rather than
a footnote. The row read "v2.lens.cited_symbol_resolution and its sixteen witnesses are not
deleted -- they are unreachable from any required check and are dead rather than competing".
Both halves of that population claim are false, and this change corrects the row in the same
diff that falsifies it.

SIXTEEN WAS THE COUNT AT #7707, when the lens landed. The file grew twice after
(#8673 enrolled roster_registry, #8775 the two instance-gap carriers) and held 27 `test fn`
identities. `gunbc.ci_layer_roots` said "eighteen". Three numbers, three snapshots of a
growing file, none of them current -- the transcribed-measurement class the standing rule
already names. The replacement rows name their subject and no number.

AND "DEAD" WAS TRUE OF THE LENS AND FALSE OF A THIRD OF ITS WITNESSES. Measured against the
seven symbols that file imported FROM the lens, 6 of the 27 touch one. The other 21 do not.
"The lens and its witnesses" was never one population, and the three-way split is:

  6  LENS-BOUND -- die with it. The census-green claim, the three planted-control rows, the
     enrolled-population exemption identity, the ambiguous control. `declaration_index`
     re-derives this machinery as PLANTED_CONTROL_CITATIONS plus PlantedControlNoLongerRefuses.

  6  RESOLVER-BOUND -- MOVED, not deleted, to test.claim.long.decl_ref_resolution_witness_test.
     They call `resolve_declaration_ref`, which lives in `v2.std.decl_ref_resolution` -- a
     module that SURVIVES with four other consumers -- and they are the only rows in the tree
     that execute its five-arm refusal. Deleting them because they sat in a file named for
     the lens would be the §4b(4) failure exactly: a climb deletes the redundant PRODUCTION
     machinery, never the discriminating RED and positive control.

  15 CARRIER-BOUND -- MOVED to test.claim.long.carrier_reference_integrity_witness_test.
     Population and projection claims about the four carriers that PROJECT DeclarationRefs.
     Their resolution half is subsumed; their population half is subsumed by nothing.

SUBSUMPTION IS SCOPED, not general: `declaration_index` extracts TYPED-LITERAL citations --
DeclarationRef record literals and the decl_ref/decl_field_ref constructors -- and reports
computed reference fields as a coverage boundary. A prose reference inside a String is
covered by nothing, before or after, and this change does not claim otherwise.

THE PER-PR WITNESS IS RENAMED, NOT DELETED. test.claim.cited_symbol_resolution_witness_test
never imported the lens; its one claim is a three-term bucket partition over
gunbc.doc_graph_roots. Two readers independently concluded from its NAME that the resolution
law was enforced per-PR -- it was not, a bucket identity was -- and after this cut it would
have been the only cited-symbol-named thing left in the tree, reading as the law's residue.
It is now test.claim.doc_graph_reference_partition_witness_test. Same borrowed-authority
shape as #9252's fixture rehome, one layer up: there the home was borrowed, here the name.

WHAT THE WALL ITSELF NAMED, because this was cut delete-first and the census is the deletion.
The first corpus run after the cut reported six refusals: two IMPORT-MEMBER-ABSENT for a
`CitedSymbolResolution` lens-id the registry no longer declares, and four
PLANTED-CONTROL-RESOLVES for the exact rows #9211 declared as this cut's residue ("they
delete with the lens, not before it"). Every one predicted, none discovered by reading.

AND ONE GAP THE ROSTER DELETION WOULD HAVE OPENED, which is why those four rows are not
simply removed. Each named one refusal arm of the cited-symbol wall. Three of the four arms
already had controlled fixtures in tests/declaration_index_integrity.rs. THE FOURTH DID NOT:
measured, the string `CitedFieldAbsent` did not occur in that file at all, so its only
evidence anywhere was the planted row I was deleting. Deleting it would have left a refusal
arm with nothing executing against it -- §4b(4) again, one level up from where I first hit it.
`citation_to_an_absent_field_is_refused_and_a_present_field_is_not` is authored here, with
its positive control, and a controlled fixture is the stronger oracle anyway (§5): the
planted row only ever asserted that one hand-authored citation still refuses.

PLANTED_CONTROL_CITATIONS is left EMPTY rather than deleted. Mechanism reachable, join
reachable, occupancy zero -- a healthy guard being quiet, not a dead one.

EVIDENCE, by execution (remote, release binaries):
                              before        after
  parse-clean files           4012          4011      the lens module
  modules                     4012          4011
  citations                   1470          1466      the lens's four planted citations
  lens_modules                71            70
  debt                        42            42        UNCHANGED
  corpus findings             0             0
  declaration_index_integrity 21 passed     22 passed the new field-absent pair

THE DEBT COUNTS RECONCILE, and the brief's "46" is none of them. 38 = roster rows, counted.
46 = citation SITES at the time the roster's doc comment was written. 42 = citations
currently suppressed by a row, the live measurement. debt is 42 before and after, and a row
that stopped reproducing refuses as CitationDebtRowStale -- none did, which is the executable
form of "the defects are still found".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
gunbc-ci-auto-heal and others added 3 commits August 26, 2026 05:25
…sposition

#9227 landed a .dag authority for the floor's admission order whose middle arm
was the fixture home this branch deletes. #9227's construction is kept whole --
ModulePrefixMatch, first_module_prefix_match, and the typed LiveTreeDisposition
input -- and only the fixture arm is cut, which is the wildcard-free wall doing
its job: three consumers failed to compile rather than inheriting an arm.

required_floor.dag: fixture_home_prefixes, DeclinedFixtureMember and the arm are
gone. #9227's header argued the ordering was load-bearing BECAUSE a fixture
member that also read the live tree had to report the permanent ownership fact
over the staged prediction. That argument dies with the arm, so it is rewritten
rather than left standing: the surviving long-home-over-live-tree precedence has
no executing discriminator, since no site can be both, and the header now says
so and says not to cite it as covered.

discovery_census.dag: the arm is removed from census_partition_step and
census_counts_add and the declined_fixture_member counter field with it.

discovery_census_witness_test.dag: w_fixture_home_dominates_live_tree is deleted
-- its subject is gone, and repointing it at a live fixture home is the borrowed
-home move this cut already refused once. The mixed population stays at five
sites, the fixture site becoming a second live-tree read, so every assertion
denominated in the population size is unchanged and only the arm it lands in
moved.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…uilt

The header already said the surviving long-home-over-live-tree precedence has
no executing discriminator and must not be cited as covered. It did not say
what would make it coverable again, which leaves a reader unable to tell
cannot-cover-yet from nobody-built-it -- the distinction DESIGN 4b(2) exists to
keep.

The trigger is a decline whose subject CAN collide with an existing one: a site
that legitimately satisfies two decline reasons at once, so which reason it
reports is a decision some input can get wrong. At that point a discriminating
witness is authorable and is owed. Until then the correct response to the
absence is to build that collision case, not to re-point a witness at a subject
that cannot disagree with itself -- which would be permanently green by
construction, and cited as coverage.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 489346f into main Aug 26, 2026
3 checks passed
@briansrls
briansrls deleted the session/crisp-swift-16 branch August 26, 2026 19:35
briansrls added a commit that referenced this pull request Aug 26, 2026
…ction, cli_invoke builders, walk_plan_stage fixture family) (#9286)

* Delete the .dag residue of the plan/walk CLI surface, and give the scope-disposition witness a fixture home it owns

#9228 deleted claim_executor's plan/walk surface and named its .dag residue rather
than sweeping it. This is that cut, plus one repair the census surfaced.

WHAT WENT, AT THE ROOT:

  PlanFunction and the plan argv builders. The coproduct modelled a closed roster of
  --plan-function targets; the flag no longer parses and the entry every variant named
  (src/v2/workflow/ci_floor_plan.dag) was deleted by the 2026-08-15 floor cut. Gone with
  it: claim_executor_run_plan_transport_argv, claim_executor_run_plan_shell, the
  notice-title normalizer and shell suffix that existed only to feed them,
  claim_executor.Executor.RunPlan, ci_spec's scheduler_invoke/scheduler_invoke_with/
  floor_plan_entry/floor_plan_function/plan_artifact_plan_function, and
  gunbc_ci_floor_only_script.

  The --verify-build-artifacts half is UNTOUCHED and deliberately so: it is a live mode
  (fleet-converge.yml), so claim_executor_verify_artifacts_shell, claim_executor_bin_shell,
  release_bin_shell_path and SourceRootShellStyle all stay. cli_invoke's dissolve trigger is
  NARROWED to name only what survives rather than deleted, since the shell-vs-argv fork it
  records is still open for that one spelling.

  gunbc_ci_run_script emitted the release build AND a claim_executor --plan-entry line. The
  second half is deleted, not repointed at --required-ci: witnesses.yml already invokes that,
  and a second route to it here is the parallel authority the floor cut removed.

  The walk_plan_stage fixture family, whole: 11 fixture modules, the 379-line #[ignore]
  harness, its scaffold row and witness, and the seed_retention_frontier retained_test_harness
  row. Their sole driver was the plan.dag recipes #9228 deleted.

  v2.workflow.required_floor fixture_home_prefixes() and RequiredFloorDisposition::
  DeclinedFixtureMember, with the cli_run.rs decode, branch, counter and TSV column. That
  arm's roster was one prefix and the family above was its entire population; its own header
  said "DISSOLVES when the fixture stops authoring test fns", and this is that condition.
  Coordinated with sleek-carp-211, who is modelling the enum in #9246 and asked for both
  sides deleted here.

  The pre-push witness-corpus gate. Not on the brief, found by the flag census:
  pre_push.rs built claim_executor and invoked --plan-entry/--plan-function on the deleted
  floor plan entry. Its EMISSION died 2026-07-25 when the operator made the hook fmt-only;
  its INVOCATION died 2026-08-25 with the flags. Two witness rows asserting "a .dag push arms
  a gate" are deleted rather than weakened -- measured against the roster, the corpus binding
  was the only thing making them true, so they were green against the plan and false about the
  hook anyone runs.

THE REPAIR THE CENSUS SURFACED (tools.dag_compile_clean_scope):

  Three walk_plan_stage files were pinned as the roster and pool of the SCOPE DISPOSITION
  witness, which has nothing to do with plan/walk. Its own note records that these same
  specimens already moved once for exactly this reason -- from test/fixture/floor_skip, which
  died with affected-set selection. This would have been the third home.

  They are rehomed to src/v2/test/fixture/compile_clean_scope/, a home this witness owns:
  three modules, no test fn, no effects, one consumer. No discovery exclusion is needed
  because there is nothing to discover, which is a stronger construction than the dir-grain
  exclusion the old home required.

  AND THE PROPERTY THE NOTE CLAIMED IS NOW ASSERTED. The expectation was
  ExpectScopedContaining -- MEMBERSHIP -- so a selector returning the whole roster satisfied
  every row and the "strict-subset proof" the note describes was checked by nothing.
  ExpectScopedExactly compares the selected list to the expected list.

EVIDENCE, by execution on a release gunbc (remote, one dispatch):
  control    witness_touched_path_dispositions_hold -> true
  mutation   give scope_isolated an import edge to scope_shared -> false
  The mutation is exactly the strict-subset violation; the old assertion could not see it.

Rust: cargo check -p v1-compiler --bins clean, fmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Repair the scope-disposition witness's per-PR half, which the floor caught

dag/test/claim/dag_compile_clean_scope_witness_test.dag imports ExpectScopedContaining
and pins the disposition row count. Both moved with the rehoming and I checked only the
long-lane witness, so strict preparation refused with a name-resolution error before any
site ran. Fixed at both ends: the import drops the deleted variant (ExpectSkip went with
it -- it was imported and never used), and the pin goes 7 -> 8, which is the roster
growing by one row because the strict-subset proof needs three specimens where the old
home carried two.

The pin doing its job here is the argument for keeping it: a count that had to be updated
by hand is exactly what stopped this rehoming from silently shipping a roster of a
different size than the one the note describes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete the `gunbc ci` verb rather than leave a command named ci that greens without running CI

REQUEST_CHANGES from codex/gpt-5.6-sol (review 56054), and the finding is correct.

WHAT I BROKE. This branch narrowed gunbc_ci_run_script to ci_release_build_script()
alone, because its other half emitted a `claim_executor --plan-entry` line naming an
entry the floor cut deleted. But `gunbc ci` is a real CLI subcommand, so what survived
was a callable verb that builds the release binaries, verifies the artifacts, and exits
0 -- under a name that says it ran CI. That is fail-open semantic dilution: the failure
mode is not a wrong answer, it is a CORRECT answer to a much smaller question, reported
under the name of the larger one. §5's absorbing-fallback rule is about a failure arm
that widens; this is its mirror at the success arm, a green that narrowed.

WHY DELETED AND NOT REBOUND. Binding the verb to `claim_executor --required-ci` was the
reviewer's other option and I am not taking it, on the grounds this branch already
argued in the commit that caused the defect: witnesses.yml invokes --required-ci, and a
second route to it is the parallel authority the floor cut removed. The verb also has no
distinct job left -- "build the release binaries and verify the artifacts" already has a
name, ci_release_build_script, and fleet-converge.yml already calls it. So the verb is
not an authority that lost its body; it is a name with nothing left to denote.

THE CENSUS, cut at the root and followed where it led:
  dag/tools/gunbc_ci.dag                     the entry module, deleted
  main.rs Commands::Ci + its arm             the CLI verb
  gunbc.cli_dispatch_surface "ci" row        the modeled CLI surface
  gunbc_cli_dispatch_surface.rs              its generated mirror
  v2.workflow.ci_release_build_emit          gunbc_ci_run_script, the wrapper
  std.emit_on_demand gunbc_ci_emission_surface   the wet-surface row naming tools.gunbc_ci main
  emit_on_demand_kernel_witness_test         its enrollment assertion
  wall_residue_live_test residue_gunbc_ci_clean  a test fn whose subject was the deleted file

ci_release_build_script itself is UNTOUCHED and still has three consumers
(ci_materialization, fleet_workflow_steps, fleet-converge.yml). Only the wrapper goes.

EVIDENCE, build lane on this tree (remote, one dispatch):
  required-ci: lane=build phases_run=2 failed=0
  regen first_generation_equal=true    -- the mirror edit is byte-equal to the emitter's
                                          own output, established by the gate rather than
                                          by my reading of the diff
  v2-emission blocking=0, census 3792 -> 3791, the one deleted module

The emitter-gap witness still holds: gap_is_non_empty_while_the_divergence_row_stands
needs at least one AbsentFromEmitMainRs row and 17 remain after this one goes.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Delete v2.lens.cited_symbol_resolution, and keep the twelve of its twenty-seven witnesses that were never its

DESIGN authorised this cut and got its population wrong, which is the finding rather than
a footnote. The row read "v2.lens.cited_symbol_resolution and its sixteen witnesses are not
deleted -- they are unreachable from any required check and are dead rather than competing".
Both halves of that population claim are false, and this change corrects the row in the same
diff that falsifies it.

SIXTEEN WAS THE COUNT AT #7707, when the lens landed. The file grew twice after
(#8673 enrolled roster_registry, #8775 the two instance-gap carriers) and held 27 `test fn`
identities. `gunbc.ci_layer_roots` said "eighteen". Three numbers, three snapshots of a
growing file, none of them current -- the transcribed-measurement class the standing rule
already names. The replacement rows name their subject and no number.

AND "DEAD" WAS TRUE OF THE LENS AND FALSE OF A THIRD OF ITS WITNESSES. Measured against the
seven symbols that file imported FROM the lens, 6 of the 27 touch one. The other 21 do not.
"The lens and its witnesses" was never one population, and the three-way split is:

  6  LENS-BOUND -- die with it. The census-green claim, the three planted-control rows, the
     enrolled-population exemption identity, the ambiguous control. `declaration_index`
     re-derives this machinery as PLANTED_CONTROL_CITATIONS plus PlantedControlNoLongerRefuses.

  6  RESOLVER-BOUND -- MOVED, not deleted, to test.claim.long.decl_ref_resolution_witness_test.
     They call `resolve_declaration_ref`, which lives in `v2.std.decl_ref_resolution` -- a
     module that SURVIVES with four other consumers -- and they are the only rows in the tree
     that execute its five-arm refusal. Deleting them because they sat in a file named for
     the lens would be the §4b(4) failure exactly: a climb deletes the redundant PRODUCTION
     machinery, never the discriminating RED and positive control.

  15 CARRIER-BOUND -- MOVED to test.claim.long.carrier_reference_integrity_witness_test.
     Population and projection claims about the four carriers that PROJECT DeclarationRefs.
     Their resolution half is subsumed; their population half is subsumed by nothing.

SUBSUMPTION IS SCOPED, not general: `declaration_index` extracts TYPED-LITERAL citations --
DeclarationRef record literals and the decl_ref/decl_field_ref constructors -- and reports
computed reference fields as a coverage boundary. A prose reference inside a String is
covered by nothing, before or after, and this change does not claim otherwise.

THE PER-PR WITNESS IS RENAMED, NOT DELETED. test.claim.cited_symbol_resolution_witness_test
never imported the lens; its one claim is a three-term bucket partition over
gunbc.doc_graph_roots. Two readers independently concluded from its NAME that the resolution
law was enforced per-PR -- it was not, a bucket identity was -- and after this cut it would
have been the only cited-symbol-named thing left in the tree, reading as the law's residue.
It is now test.claim.doc_graph_reference_partition_witness_test. Same borrowed-authority
shape as #9252's fixture rehome, one layer up: there the home was borrowed, here the name.

WHAT THE WALL ITSELF NAMED, because this was cut delete-first and the census is the deletion.
The first corpus run after the cut reported six refusals: two IMPORT-MEMBER-ABSENT for a
`CitedSymbolResolution` lens-id the registry no longer declares, and four
PLANTED-CONTROL-RESOLVES for the exact rows #9211 declared as this cut's residue ("they
delete with the lens, not before it"). Every one predicted, none discovered by reading.

AND ONE GAP THE ROSTER DELETION WOULD HAVE OPENED, which is why those four rows are not
simply removed. Each named one refusal arm of the cited-symbol wall. Three of the four arms
already had controlled fixtures in tests/declaration_index_integrity.rs. THE FOURTH DID NOT:
measured, the string `CitedFieldAbsent` did not occur in that file at all, so its only
evidence anywhere was the planted row I was deleting. Deleting it would have left a refusal
arm with nothing executing against it -- §4b(4) again, one level up from where I first hit it.
`citation_to_an_absent_field_is_refused_and_a_present_field_is_not` is authored here, with
its positive control, and a controlled fixture is the stronger oracle anyway (§5): the
planted row only ever asserted that one hand-authored citation still refuses.

PLANTED_CONTROL_CITATIONS is left EMPTY rather than deleted. Mechanism reachable, join
reachable, occupancy zero -- a healthy guard being quiet, not a dead one.

EVIDENCE, by execution (remote, release binaries):
                              before        after
  parse-clean files           4012          4011      the lens module
  modules                     4012          4011
  citations                   1470          1466      the lens's four planted citations
  lens_modules                71            70
  debt                        42            42        UNCHANGED
  corpus findings             0             0
  declaration_index_integrity 21 passed     22 passed the new field-absent pair

THE DEBT COUNTS RECONCILE, and the brief's "46" is none of them. 38 = roster rows, counted.
46 = citation SITES at the time the roster's doc comment was written. 42 = citations
currently suppressed by a row, the live measurement. debt is 42 before and after, and a row
that stopped reproducing refuses as CitationDebtRowStale -- none did, which is the executable
form of "the defects are still found".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
@briansrls
briansrls restored the session/crisp-swift-16 branch August 26, 2026 19:38
gunbai-bot Bot pushed a commit that referenced this pull request Sep 5, 2026
§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.
briansrls added a commit that referenced this pull request Sep 5, 2026
….E, §4.I, §4.J (#10576)

* Correct §4.A hygiene-reaper row: CASE 2 — four host_hygiene_reap_*_body symbols deleted by #8583

The §4.A row at L379 described host_hygiene_reaper_script.dag's 4
body symbols as A5-deferred. The file was deleted by ffa16a5
(#8583, Migrate host-hygiene reaper and liveness onto typed observation)
and the construction was migrated to typed host_hygiene_reaper_observe.dag
/ host_hygiene_reaper_remediate.dag / host_hygiene_liveness_observe.dag.
No direct successor body names exist — CASE 2 (file deletion upstream)
with hybrid CASE 1 (body names dissolved).

Verification:
- ffa16a5 is ancestor of origin/main ✅
- host_hygiene_reaper_script.dag: D in #8583's diff
- zero files define host_hygiene_reap_install_units_body et al.
- observe/remediate files present at dag/gunbc/host/

Part of #10537's per-row adjudication program.

* Correct §4.D srv3_chown_directory_to_current_user: CASE 4 — renamed AND climbed

The row at §4.D L436 listed srv3_chown_directory_to_current_user
as A5-deferred (srv3). It was actually renamed AND climbed by
20ad5b3 (#8796): successor is
gunbc.host_effect_realize.srv3_ensure_directory_owned_by_current_user.
New name has a stronger guarantee (readback-based, not chown exit-status
based).

This is CASE 4 (rename plus climb) — distinct from CASE 1 (dissolution)
because the construction did not disappear; it acquired a better name
and a stronger guarantee.

Verification:
- 20ad5b3 is ancestor of origin/main ✅
- srv3_chown_directory_to_current_user: 0 declaration files
- srv3_ensure_directory_owned_by_current_user: 2 declaration files

Part of #10537's per-row adjudication program.

* Correct §4.E: 4 stale foreign-executor rows

Four symbols claimed as 'already on emit' are no longer present in the
corpus. Each is struck through with its deletion commit:

1. ci_selection_control_script — DELETED by 611fd02 (#8283, CI floor cut).
   CASE 1/2: the ci.yml file was deleted and its selection-control script
   dissolved with it. Successor workflow is witnesses.yml via
   gunbc.witness_floor_workflow.

2. gunbc_ci_run_script — DELETED by 489346f (#9252, plan/walk CLI delete).
   CASE 1: the gunbc ci verb was deleted, taking its run script.

3. ci_regen_ensure_rustfmt_path_script — DELETED by 3b431f3 (#8406,
   REGEN ROOT CUT). CASE 1: regen_stage0 root deleted; rustfmt path
   script was zero-consumer machinery.

4. expected_live_deploy_retract_script — DELETED by d409b75 (#7909,
   Phase A release identity refactor). CASE 1: recategorized to
   runtime-present, then dissolved.

All four deletion commits are ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

* Correct §4.I, §4.J, §4.D ownership table: 18+ stale symbols

§4.I — ci_native_cache_root_toolchain_segment_command
  DELETED #7436 (003d960). CASE 1 dissolution — toolchain segment
  computation reordered after setup-rust-toolchain; fallback table entry
  struck through as RESOLVED.

§4.J.A — ci_floor_stamp_merge_admission_script
  All three raw leaves (ci_floor_stamp_ambient_exit_command,
  ci_floor_stamp_root_command, merge_admission_stamp_command) DELETED
  #7522 (87a4af3). CASE 1 dissolution. 'PARTIAL #7293' status stale.

§4.J.B — ci_floor_materialization_receipt_gate_script,
  ci_floor_resolve_receipt_gate_script
  DELETED #7470 (b01cdf4). CASE 1 dissolution — WalkPlan success
  stages finalization dissolved both receipt gates.

§4.J.C (ci_spec.dag table):
  - gunbc_ci_floor_only_script DELETED #9252 — CASE 1
  - ci_regen_floor_skip_shortcut_script DELETED #8406 — CASE 1
  - gunbc_ci_regen_floor_only_script DELETED #8406 — CASE 1
  - scheduler_invoke/scheduler_invoke_with DELETED #9252 — CASE 1
  - git_fetch_script RENAMED #6833 — CASE 3 (successor:
    git_fetch_no_tags_shell / git_fetch_prune_shell)

§4.J.D (ownership table):
  - Merge-admission row: all three raw leaves struck #7522 (CLOSED)
  - CI materialization row: both receipt gates struck #7470 (CLOSED)
  - CI-spec row: stale symbols struck through individually
  - Already-routed row: ci_selection_control_script #8283,
    gunbc_ci_run_script #9252, ci_regen_ensure_rustfmt_path_script
    #8406 (and 11 rustfmt raw leaves) struck through
  - Runtime terminal row: host_effect_plan_placeholder_effect
    DELETED #10509
  - Deferred srv3 row: srv3_chown_directory_to_current_user struck
    #8796 (ref §4.D), all 4 host_hygiene_reap_*_body + liveness body
    struck #8583 (ref §4.A)

All deletion commits verified as ancestors of origin/main ✅.

Part of #10537's per-row adjudication program.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant