Skip to content

The lockstep the decline was hiding: repoint the heartbeat rows at the seed that beats, and repair the zero it was inventing - #9297

Merged
briansrls merged 3 commits into
mainfrom
session/sharp-lark-585
Aug 27, 2026
Merged

briansrls merged 3 commits into
mainfrom
session/sharp-lark-585

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

The lockstep the decline was hiding: repoint the heartbeat rows at the seed that beats, and repair the zero it was inventing

test.claim.observation_lockstep_witness_test carried two rows over
src/v1/stage0/src/bin/claim_executor.rs asking for from_secs(60),
floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror and
heartbeat_feed_snapshot. #9228 deleted the plan/walk surface all five lived on,
so both rows have been FALSE since it merged. Nothing said so: the module
declares ReadsLiveTree, the required floor declines it before the fold, and a
decline renders identically to a pass -- DESIGN's execution-provenance row, in
the form that lets a lockstep outlive the thing it locks to.

NOT A RETIREMENT, A MOVE. The floor still beats once a minute:
cli_run.rs spawn_floor_heartbeat, period GUNBC_FLOOR_HEARTBEAT_SECS defaulting
to 60, emitting a raw [floor-heartbeat] line with no projection behind it.
gunbc.observation_emit_census already carries that successor as a
CountedFrontierSite with its restoration trigger, so what was missing was not the
fact but the citation. Both rows now read the successor, so the derivation
observation_dwell_threshold rests on is grounded in the seed again.

THE NO-FABRICATION ROW WAS RED BY EXECUTION WHEN IT WAS WRITTEN, which is the
repair rather than the reporting. floor_resource_sample answered a fabricated 0
for rss_kb, cpu_ms and majflt while its own cgroup and vmstat readers already
answered na. So rss_kb=0 meant EITHER no resident pages -- which a live process
cannot have -- OR an unreadable /proc/self/statm, in the one instrument that
exists to settle a memory contradiction. Two conventions in one line, and the
invented one was silent. Repaired to the single na sentinel, cpu all-or-nothing
because a half-read stat cannot be summed. The row's third conjunct asks for the
FABRICATING spelling to be ABSENT, so restoring the zero reds here.

THE FEED IS DELETED BECAUSE ITS CONSUMER WAS. cli_run's HeartbeatFeed was read
only by claim_executor's deleted mirror; heartbeat_feed_enter_batch has had no
production caller since, so the two surviving writers fed a feed that could never
arm and no reader. Its 0-of-0 red control goes with its subject -- not a §4b(4)
climb, nothing climbed, the subject left. Leaving it standing is what would let a
future lockstep row go green over dead code, which is how this one broke.

Three stale prose citations repaired with it: std.observation's heartbeat-period
note and human-units contract both named the deleted emitter in the present
tense, and gunbc.observation_seed_render's seed_heartbeat_line claimed a
byte-equality mirror holds it. It does not; the fn is retained as the target of
the census's declared restoration, and the note now says so.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com


Measured, before and after, on src/v1/stage0/src/cli_run.rs (the needles are the rows' own predicates):

needle required before after
[floor-heartbeat] wall_s= present — 1
GUNBC_FLOOR_HEARTBEAT_SECS present — 2
.unwrap_or(60) present — 1
unwrap_or_else(na) present 2 4
.map(|pages| (pages * 4).to_string()) present 0 1
.map(|pages| pages * 4) absent 1 0
GUNBC_FLOOR_HEARTBEAT_MINUTES absent 0 0
floor-memory-heartbeat absent 0 0

The five needles the two old rows asked for — from_secs(60), floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror, heartbeat_feed_snapshot — measure 0 in claim_executor.rs on main.

What is not claimed. This does not restore the heartbeat projection. gunbc.observation_seed_render seed_heartbeat_line stays an oracle with no mirror, and gunbc.observation_emit_census keeps [floor-heartbeat] / [floor-claim-memory] as CountedFrontierSite rows with their existing dissolution trigger — that restoration is a separate change. This module also stays ReadsLiveTree, so the required floor still declines it; the decline is what hid the staleness, and lifting it is its own construction rather than a line in this diff.

…e seed that beats, and repair the zero it was inventing

test.claim.observation_lockstep_witness_test carried two rows over
src/v1/stage0/src/bin/claim_executor.rs asking for from_secs(60),
floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror and
heartbeat_feed_snapshot. #9228 deleted the plan/walk surface all five lived on,
so both rows have been FALSE since it merged. Nothing said so: the module
declares ReadsLiveTree, the required floor declines it before the fold, and a
decline renders identically to a pass -- DESIGN's execution-provenance row, in
the form that lets a lockstep outlive the thing it locks to.

NOT A RETIREMENT, A MOVE. The floor still beats once a minute:
cli_run.rs spawn_floor_heartbeat, period GUNBC_FLOOR_HEARTBEAT_SECS defaulting
to 60, emitting a raw [floor-heartbeat] line with no projection behind it.
gunbc.observation_emit_census already carries that successor as a
CountedFrontierSite with its restoration trigger, so what was missing was not the
fact but the citation. Both rows now read the successor, so the derivation
observation_dwell_threshold rests on is grounded in the seed again.

THE NO-FABRICATION ROW WAS RED BY EXECUTION WHEN IT WAS WRITTEN, which is the
repair rather than the reporting. floor_resource_sample answered a fabricated 0
for rss_kb, cpu_ms and majflt while its own cgroup and vmstat readers already
answered `na`. So rss_kb=0 meant EITHER no resident pages -- which a live process
cannot have -- OR an unreadable /proc/self/statm, in the one instrument that
exists to settle a memory contradiction. Two conventions in one line, and the
invented one was silent. Repaired to the single `na` sentinel, cpu all-or-nothing
because a half-read stat cannot be summed. The row's third conjunct asks for the
FABRICATING spelling to be ABSENT, so restoring the zero reds here.

THE FEED IS DELETED BECAUSE ITS CONSUMER WAS. cli_run's HeartbeatFeed was read
only by claim_executor's deleted mirror; heartbeat_feed_enter_batch has had no
production caller since, so the two surviving writers fed a feed that could never
arm and no reader. Its 0-of-0 red control goes with its subject -- not a §4b(4)
climb, nothing climbed, the subject left. Leaving it standing is what would let a
future lockstep row go green over dead code, which is how this one broke.

Three stale prose citations repaired with it: std.observation's heartbeat-period
note and human-units contract both named the deleted emitter in the present
tense, and gunbc.observation_seed_render's seed_heartbeat_line claimed a
byte-equality mirror holds it. It does not; the fn is retained as the target of
the census's declared restoration, and the note now says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Two observation_lockstep heartbeat rows red (cadence, no-fabrication): repair the lockstep facts the decline was hiding The lockstep the decline was hiding: repoint the heartbeat rows at the seed that beats, and repair the zero it was inventing Aug 26, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 26, 2026 05:30
@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Green-by-execution, with the discriminating RED. gunbc run --entry dag/test/claim/observation_lockstep_witness_test.dag --function <row> evaluates the row and then refuses to map a Bool to an exit code — that refusal line carries the value, so it is the result.

w_heartbeat_period_matches_the_seed_cadence — 3× [file] read src/v1/stage0/src/cli_run.rs (one per conjunct), then:

error: function `w_heartbeat_period_matches_the_seed_cadence` returned `true`, not `ProcessExit`.

w_heartbeat_source_still_refuses_to_fabricate — 3× the same read, then:

error: function `w_heartbeat_source_still_refuses_to_fabricate` returned `true`, not `ProcessExit`.

The RED. Mutating floor_resource_sample's RSS reader back to the fabricating spelling — .map(|pages| pages * 4) followed by a separate .to_string(), so the emitted value is byte-identical and only the spelling the row forbids returns — and re-running the same row unchanged:

error: function `w_heartbeat_source_still_refuses_to_fabricate` returned `false`, not `ProcessExit`.

Restored; worktree clean; row back to true. So it is not a row that is permanently green over a fact nothing can flip: reinstating the invented zero reds it.

Contrast with what this replaced — all five needles the two old rows asked of claim_executor.rs measure 0 on main (from_secs(60), floor-memory-heartbeat, refusing to fabricate, render_heartbeat_line_mirror, heartbeat_feed_snapshot), and nothing reported it because the module is DeclinedLiveTree.

…to a spelling four readers share

THE FINDING IS CORRECT AND THE ROW WAS THE FAILURE IT DESCRIBES. Its first
draft asked for `unwrap_or_else(na)` and for the absence of the fabricating
`.map(|pages| pages * 4)`. The first needle also matches the cgroup and vmstat
readers, which have nothing to do with the field under test, so a regression
that fabricated a zero for RSS *after* the string conversion --

    .map(|pages| (pages * 4).to_string())
    .unwrap_or_else(|| 0.to_string())

-- satisfies all three conjuncts. My own RED control mutated the one shape the
third conjunct forbids and therefore proved less than it appeared to: the row
detected the mutation I chose, not the class it named. A check that passes over
the regression it is cited for is worse than absent (DESIGN 4b), and this one
was already cited in the PR body as the standing control.

THE REPAIR IS IN THE SEED, NOT IN A LONGER NEEDLE. Each field is now produced by
ONE line that names the field, and one renderer decides what an absent reading
looks like:

    fn floor_sampled_field(v: Option<u64>) -> String   // Some -> number, None -> sentinel
    fn floor_statm_rss_kb() -> Option<u64>             // None is the ONLY absent answer
    let rss_kb = floor_sampled_field(floor_statm_rss_kb());
    let majflt = floor_sampled_field(tick(9));
    let cpu_ms = floor_sampled_field(match (tick(11), tick(12)) { .. });

No field renders itself any more, so "fabricate a zero for this one field" is
necessarily an edit to a line that names that field. The four conjuncts are
those four lines, each measured unique in the file. Substituting a number for
RSS means deleting the rss_kb conjunct; weakening the sentinel means deleting
the renderer's None arm. The escape the review found has no spelling left.

`4` also stops being a bare literal in the RSS path (`KB_PER_PAGE`), which is
what made the old needle collide with an arithmetic shape rather than a fact.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in 37beba44ba7. The finding is correct, and it is the sharper form of it that matters: my own RED control detected the mutation I happened to choose, not the class the row names — the exact shape you describe (fabricated zero after the string conversion) satisfied all three conjuncts, and the row was already cited in the PR body as the standing control. A check that passes over the regression it is cited for is worse than absent.

Repaired in the seed rather than by a longer needle, because binding a needle to a larger slice of one expression is still a check over a spelling. Each field is now produced by one line that names the field, and one renderer decides what an absent reading looks like:

fn floor_sampled_field(v: Option<u64>) -> String   // Some -> the number, None -> the sentinel
fn floor_statm_rss_kb() -> Option<u64>             // None is the ONLY absent answer, never Some(0)

let rss_kb = floor_sampled_field(floor_statm_rss_kb());
let majflt = floor_sampled_field(tick(9));
let cpu_ms = floor_sampled_field(match (tick(11), tick(12)) { .. });

No field renders itself any more, so fabricating a zero for one field is necessarily an edit to the line naming that field. The row's four conjuncts are those four lines plus the renderer's None => FLOOR_SAMPLE_UNREADABLE.to_string(), arm — each measured to occur exactly once in cli_run.rs. Substituting a number for RSS deletes the rss_kb conjunct; weakening the sentinel deletes the renderer arm. Your escape has no spelling left, and neither does the shared-fallback collision that allowed it: unwrap_or_else(na) is no longer asked for at all.

The bare 4 in the RSS path also became KB_PER_PAGE — a needle colliding with an arithmetic shape rather than a fact was the other half of why the old conjunct was weak.

floor_resource_sample is host Rust with no .dag reachability, so exercising it directly from the witness is not available to this module; naming the per-field production sites is the strongest binding the substrate offers here, and it is a real one rather than a substring coincidence.

@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Mutation receipt for review 56124, run against the fix on a stable binary.

The mutation is your escape expressed against the new structure — a fabricated zero for RSS that still routes through a string conversion and leaves both shared spellings intact, so the old row would have passed it:

-    let rss_kb = floor_sampled_field(floor_statm_rss_kb());
+    let rss_kb = floor_statm_rss_kb().unwrap_or(0).to_string();

Measured with the mutation installed: unwrap_or_else(na) still occurs 2× and None => FLOOR_SAMPLE_UNREADABLE.to_string(), still occurs 1× — i.e. every spelling the first draft asked for survives the regression, which is exactly the defect you identified.

The row, unchanged, run over that tree — four [file] read src/v1/stage0/src/cli_run.rs, one per conjunct, then:

error: function `w_heartbeat_source_still_refuses_to_fabricate` returned `false`, not `ProcessExit`.

Restored; worktree clean. The escape now reds, and it reds on the conjunct that names the field rather than on a spelling coincidence.

(An earlier attempt at this control died mid-run — resolve cache: cannot read compiler executable "...gunbc (deleted)" — because a concurrent rebuild replaced the binary underneath it. That was a harness fault, not a result, and it is why this run uses a copied binary; recording it so the two are not confused.)

— sent from sharp-lark-585

@gunbai-bot

gunbai-bot Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Paired arms, same binary, one sequence — completing the receipt above so the RED is not read on its own.

Mutated (let rss_kb = floor_statm_rss_kb().unwrap_or(0).to_string();) — four [file] read, one per conjunct:

error: function `w_heartbeat_source_still_refuses_to_fabricate` returned `false`, not `ProcessExit`.

Restored, worktree clean, same command, same binary:

error: function `w_heartbeat_source_still_refuses_to_fabricate` returned `true`, not `ProcessExit`.

A RED alone would only show the row can fail; the pair shows it fails on the regression and passes on the repair, with nothing else varying between the two runs.

— sent from sharp-lark-585

@briansrls
briansrls merged commit c7aa9ba into main Aug 27, 2026
3 checks passed
@briansrls
briansrls deleted the session/sharp-lark-585 branch August 27, 2026 01:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant