Skip to content

Two DESIGN passages lived only in the projection, where the next regen deletes them - #9463

Closed
gunbai-bot[bot] wants to merge 26 commits into
mainfrom
session/warm-hawk-909
Closed

gunbai-bot[bot] wants to merge 26 commits into
mainfrom
session/warm-hawk-909

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

DESIGN.md is a generated projection of dag/gunbc/design_document.dag and dag/gunbc/recurring_failure_mode.dag. Three passages had been hand-edited into the projection and never reached an authority. That is not content the repository holds — it is content awaiting silent deletion by the next person to run the gate.

What was orphaned

1. The repo_ruleset ruling (first commit) — 1685 characters describing what gunbc.repo_ruleset converges, what it does not claim (an actuation with a read-back is not a wall), and why a ruleset edit was rejected in favour of the aggregation job.

2. The emit-stage census result (second commit) — the authority still read POPULATION: UNCOUNTED AND UNBOUNDED and mentioned gunbc.emit_stage_blocking_population_census zero times, while that carrier exists in dag/ and the projection carried its full result: the observable three, the latent at-least-eleven, the unreachable upper bound, and the declaration that §4b(3) is still unmet. A regen would have reverted the row to a state its own carrier contradicts.

3. The bound-shaped closure failure mode (second commit) — present in the projection, absent from gunbc.recurring_failure_mode, which is the roster the paragraph renders from. Added as a row after positional_citation, preserving that carrier's documented empty-diff oracle: rows carry their sentence byte-for-byte and render in roster order, so the split is verified by the projection not changing.

How they were found, and why it matters

By regenerating, not by reading. That is the only instrument that can find this class — a hand-edit to a generated file is invisible to every gate that reads the file, and visible only to the generator.

The same check caught the first restoration being incomplete: it left 5 bytes behind, and those 5 bytes were two tense corrections the inserted text required (already records → recorded at the time, is not a .dag fact → was not a .dag fact), not cosmetic residue. Orphaned prose is not a stray paragraph; it is an edit with dependencies on its surroundings. That is why passage 2 was ported as a unit rather than spliced.

Verification

Executed, not inspected. Regenerate via gunbc run --entry dag/tools/generated_artifact_gate.dag --function main_wet, then confirm the only remaining DESIGN.md delta is purely additive: 3445 characters of diagnostic name accurate about the situation, a row a landed authority was already producing and the projection had not caught up to. Measured opcode-by-opcode — zero deletions, zero replacements.

Passage 2's line now regenerates byte-identically, which is the discriminating result: before the fix, regeneration changed that line.

🤖 Generated with Claude Code

Brian Searls and others added 24 commits August 26, 2026 19:30
… ratchet by symbol

Opened by operator ruling 2026-08-26: v2 self-hosts the ENTIRE v2 corpus, started
from scratch, superseding the 2026-08-16 root-partition document whose evidence
base was bankrupted (all ten probe links dangling, census a month stale, its
instrument deleted).

The plan is a .dag Plan carrier rather than a hand-authored .md so that its claims
are joined to symbols a machine checks: v2_corpus_self_host_ratchet_bindings names
the ratchet, the measurement instrument, the hosting admission and the emission
phase as DeclarationRefs, which the ingestion-time citation wall resolves on every
required run. A section that goes stale because its mechanism was renamed refuses
here instead of reading as current -- the failure mode that killed the last anchor.

Records two findings the program depends on: the required v2-emission phase never
invokes cargo ("stopping before cargo"), so no required check measures rustc; and
the whole-corpus compile IS hostable on a CI runner, correcting a report that no
host could run it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The plan landed with both a .dag Plan carrier and a hand-authored docs/plans .md.
That is a second representation of one fact with no authority over it -- the §2/§3
parallel-representation debt -- and it would drift from the carrier silently, since
nothing joins them.

Evidence the .md is not required: gunbc.plans.branch_merge_admission_model is a
registered plan with no docs/plans markdown at all. The Plan type already carries
plan_to_document, so the markdown is DERIVED where it is wanted rather than
authored beside the source it restates.

Operator steer 2026-08-26: design doc changes are .dag changes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Second anchor requested by the operator alongside the v2-corpus-self-host
plan. Material supplied by the owning session (snappy-dove-250) on request.

Bound to two symbols only -- gunbc.namespace_cut_landing_order
current_landing_order and namespace_cut_grammar_last_ruling -- both
verified to resolve before authoring. Everything else is marked as prose
in the text rather than given a citation it cannot support. A long
half-bound roster would assert that the ingestion-time citation wall is
checking claims it is not checking.

Three things the plan deliberately does not smooth over:

- The strip measurement is STALE AS A POPULATION and current only as a
  CLASS TAXONOMY. The corpus sha256 is the anchor, not the commit line.
- smart-wolf-868's placement at Step 2 is ASSUMED, not measured, and is
  labelled so where it appears.
- Whether the namespace cut blocks v2 self-compile or the reverse is an
  OPEN QUESTION carried to the operator, not a position taken here. It
  changes wave ordering in both plans.

Ordering claims bind to the carrier, never to a document sentence: the
execution document is superseded on ORDER only (operator, 2026-08-25),
which is why grammar deletion lands LAST rather than first.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Four fixes, all from review rather than from me.

1. S1 asserted #9346 was "still OPEN with conflicts ... contrary to a
   report that both had merged". #9346 is MERGED (2026-08-26T19:06:10Z,
   7fcdbdc, verified an ancestor of main). The line did not merely
   carry a stale fact -- it instructed the reader to distrust an accurate
   source, in an ACTIVE anchor. Fixed by DELETING the assertion rather
   than updating it, and recording the rule: a plan carrier must not
   assert the open/closed state of a PR. It rots in hours, it is free to
   re-derive at read time, and nothing refuses when it goes stale. This
   is the one class the evidence-bankruptcy rule could not have caught,
   since it is not a measurement at all.

2. The seed partition table is a TRANSCRIPTION with no entry point.
   An independent re-run of the described procedure on the same commit
   reproduced every figure exactly except emitted lines: 166,834 vs
   166,727, the total carrying the same delta. No conclusion turns on
   107 lines; the finding is that a described procedure and an
   instrument are different things, which is what name-the-instrument
   predicts. Named as the gap it is.

3. The superseded census's CONCENTRATION is restated as a hypothesis
   with a test attached. Its two halves do not decay alike: the
   magnitude is inert without a board, but the concentration is a claim
   about the emitter's failure distribution and the emitter has been
   changed for a month by lanes whose purpose is moving it. A magnitude
   drifts; a concentration can invert, and sequencing by a stale one
   puts effort where the wins are already taken.

4. Import/namespace section 5 no longer claims the eleven classes "are
   still the right partition". Nothing has tested that. The taxonomy is
   what survives; its COMPLETENESS is unverified, since a class of
   breakage introduced since the measurement would not appear in it.
   Staleness is now stated as MEASURED -- the anchor recipe re-run gives
   a different corpus hash on a tree behind main.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The rule against asserting PR state in a carrier was filed against #9346,
which had merely gone stale. A stronger receipt arrived the same night on
#9349: three readings within minutes -- dashboard reporting failing from a
superseded run, a peer re-deriving green at check-run level, and a third
check finding the head had moved again and the PR was mid-run. Each was
correct when taken; none described the PR when quoted.

That is the case #9346 could not make. There a correct measurement never
existed; here there was a correct measurement at BOTH ends and the shared
conclusion was still wrong. The mechanism is that a PR-state sentence has
no spelling for AS OF WHICH HEAD, so a true reading and a stale one become
indistinguishable the moment either is passed on -- which is precisely what
CORRECTING the line would have reproduced, and why it was deleted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Operator ruling 2026-08-26 answered the sequencing question both plans had
open, and answered it at a different grain than it was asked: neither
program blocks the other whole. Self-host's proof envelope blocks the FIRST
namespace semantic wave; namespace completion blocks self-host's
IRREVERSIBLE retirement step. A braid, not a total order -- and collapsing
it back to a program order yields a different plan in either direction.

The ruling closed with an explicit instruction to carry the precedence
edges ONCE and not duplicate them as prose in both carriers, which is §3
applied to a fact with two natural homes: two copies are one fact with two
authorities, and they diverge on the first amendment. So
gunbc.compiler_frontend_program_interlock owns the relation and both plans
cite it; their prose renders it.

milestone_prerequisites is a TOTAL FUNCTION over a closed milestone
variant, not a list of edges. A list is satisfied by omission -- a
milestone nobody wrote an edge for silently has no prerequisites and the
failure is invisible. The exhaustive match makes an unstated prerequisite
fail to compile (§5, construction over validation). Same shape for the
admission predicate, which admits on UNADJUDICATED delta being empty
rather than delta being empty: expected cut motion may occur, unevaluated
motion may not. A wall demanding zero delta would refuse the cut itself and
then be repaired by weakening it.

Executable consequence recorded in the namespace plan: its disclosed "no CI
mechanism" gap becomes a BLOCKER gating Step 1 by name, with preparatory
work explicitly unaffected. Its section 7 stops being an open question and
becomes a projection of the carrier.

Two corrections from the operator's exact-head review:

- The ratchet clause said counts are "display only and decide nothing".
  The ratchet owner measured that as literally false. Replaced with their
  wording: no cardinality is a gate oracle, but emptiness decides whether a
  population is inhabited or evaluated -- including the distinction between
  an empty roster and an identified roster with no failures -- and the
  roster DIGEST, not its count, is its identity.
- The status block claimed "no transcribed instrument output" while the
  next section explicitly carries a transcription and names its missing
  producer. It no longer claims both states.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The build lane's parse phase refused:

  module index refused: 1 unparseable .dag source(s)
    dag/gunbc/plans/import_namespace_program.dag:8636-9127:
    expected expression, found Unknown

My error, and it is an escaping-layer mistake rather than a .dag one. I
authored the section through a Python here-doc and wrote \\' inside a
triple-quoted Python string to protect the apostrophe from PYTHON. Python
emitted a literal \' into the .dag file, where a double-quoted string needs
no escape for an apostrophe and \' is not a valid escape -- so the lexer
produced Unknown and the parser refused at the enclosing expression.

Four occurrences across three lines, all in the one file the index named;
the other two new modules parsed clean, which is why the refusal counted
exactly one source.

Worth noting the wall worked as designed: this was caught by the parse
sweep in the build lane, at the phase DESIGN records as sweeping src/v1,
dag and src/v2 from one roster, before anything downstream consumed it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Two findings, and the first splits rather than landing whole.

FINDING 1 -- predicate dissolution. The rule is real and I verified its
scope before acting: std.execution_mode records that the 2026-07-12
dissolution deleted SINGLE-VARIANT NICKNAMES (is_hermetic/is_record), and
that a predicate deciding a SEMANTIC PARTITION survives it --
execution_mode_is_wet_dispatch groups three variants into two because Wet
and Record share dispatch semantics, keeping one authority instead of an
inline match at every consumer.

  namespace_change_admitted_before_wall: two variants mapped one-to-one
  onto true/false. That is a nickname for a variant test. DELETED. Its
  distinction already lives in NamespaceChangeClass, which consumers match
  on, and the plan's citation is repointed to the type.

  delta_disposition_auto_admitted: nine dispositions partitioned three-to-
  six on whether the wall auto-admits them. That is the surviving shape,
  on the grounds std.execution_mode records by name. RETAINED, with the
  argument written beside it so the next reader does not re-litigate it.

FINDING 2 -- prose drift. Upheld. Section 7 enumerated both precedence
edges while asserting the carrier was their only home, which is worse than
either alone: a symbol citation verifies a declaration EXISTS and never
that prose about it still AGREES with it, so enumerated edges beside a
citation are precisely the drift single authority prevents. The prose now
renders the relation without restating it, says explicitly that it is not
authority for the edges, and points at milestone_prerequisites for the
gate condition instead of repeating it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…orrected

Two narrow semantic checks raised on 620a118.

1. The ruling gates the first namespace wave on S2 + S3 + S4. The closed
   milestone SelfHostCargoRatchetEnrolled named S3 and S4 and left the S2
   whole-corpus census implicit inside the phrase "proof envelope".

   That is a real gap rather than a naming preference, and the reason is
   worth stating because it is a limit of the construction this carrier
   leans on: the closed variant makes an omitted MILESTONE fail to compile,
   but it cannot make an omitted FACT fail to compile when that fact hides
   inside a composite name. Totality protects the enumeration, never the
   contents of an element of it. So a required precondition had become
   unenforceable in the very carrier built to enforce preconditions.

   Fixed by adding SelfHostWholeCorpusPopulationDerived as its own variant
   rather than by renaming the composite, since renaming would have left
   the fact implicit and merely better labelled. NamespaceFirstSemanticWave
   now requires all three.

   The general rule is recorded beside it: when a construction derives its
   guarantee from exhaustiveness, every fact the guarantee must cover has
   to be its own element -- a composite element is a place for a fact to
   hide from the check that makes the construction worth having.

2. Section 9 announced the ordering relation as retired and then closed by
   counting "Four gaps". Now three live gaps plus one retired question,
   with the retired bullet kept only so a reader of an earlier revision
   does not hunt for an answered question.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Deleted delta_disposition_auto_admitted, and the reason is independent of
the question it was reviewed under.

THE REVIEW'S STATED GROUND DOES NOT HOLD. The finding cites "the exact
predicate/walker-dissolution shape prohibited by DESIGN.md". DESIGN.md
contains zero occurrences of "walker", and its only predicate clauses say
that a general fn(T) -> Bool refinement does not lift to proof and that a
caller-supplied validator is defeasible -- both claims about the guarantee
ladder, neither a prohibition on Bool projections. The predicate-dissolution
rule is real but lives in the corpus, at std.execution_mode, and that row
states the surviving case explicitly: a two-variant semantic partition is
kept where a single-variant nickname is deleted, because deciding a
partition once keeps one authority instead of an inline match at every
consumer.

DELETED ANYWAY, ON A GROUND THAT DOES HOLD: it had no consumer. Measured --
the only reference in the tree was a DeclarationRef in this PR's own plan.
The wave-admission wall that would classify deltas does not exist yet, and
DESIGN section 6 names a new artifact with no final consumer as
experimental residue. A partition nobody computes over is a guess about
what a future consumer will want, and the surviving-partition argument
presupposes consumers that would otherwise inline the match. There are
none, so the argument does not apply to this predicate either.

The operator's ruled partition is preserved as an annotation, where it
cannot be mistaken for an executing mechanism, and the plan's citation is
repointed to NamespaceDeltaDisposition. The type stays: it carries the
ruled vocabulary and the wall will match on it directly. Bool is dropped
from the imports.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
review 56376 found that SelfHostCargoRatchetEnrolled carried no prerequisite
while its own label named S4, and the plan defines S4 as enrolment against S2's
population. The typed interlock therefore permitted enrolling the ratchet before
the population it ratchets against exists.

The review offered two repairs. Adding S2 as a prerequisite to the fused variant
is the wrong one: S3 (enrol a cargo-executing phase) genuinely has no
prerequisite, so that repair closes the permissive half by introducing a
false-blocking half. The variant is composite, and its two halves have different
prerequisites, so a single prerequisite list must state either the minimum or the
maximum and both are wrong. The repair is the split.

This file's own annotation already stated the rule -- a composite element is a
place for a fact to hide from the exhaustiveness check that makes the
construction worth having -- and this instance was left standing in the same
diff that wrote it down. The annotation now carries the second instance, since a
rule with one instance reads as a repair and a rule with two reads as a rule.

Prerequisites are direct edges rather than the transitive closure: S2 is not
repeated on NamespaceFirstSemanticWave because S4 now carries it, so a later
correction to S4 cannot leave a stale duplicate standing (DESIGN section 2).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…f one shape

loyal-lark-254 found that SelfHostRatchetEnrolled was itself composite. It fused
enrolling the ratchet as an OBSERVATION -- taken, persisted, never able to fail a
merge -- with enrolling it as a GATE. Their prerequisites differ: an observation
needs no population to be about, since what it refuses is the inability to take
or persist it; a gate is meaningless without the identity-grain population it
gates against.

Fused, the variant read as a prerequisite over both. That would have blocked
observation work an operator ruling had already authorised, via a carrier that
landed after the ruling -- a single-authority collision committed by the file
built to prevent them.

NamespaceFirstSemanticWave now depends on the GATE form, since what the namespace
plan says gates Step 1 is an enforcing mechanism over the import population, and
an observation cannot enforce.

Three instances of one shape in one file is the finding, not three repairs. Each
was a variant fusing two facts whose prerequisites differ, and each was invisible
to the exhaustiveness check that is this construction's whole reason for
existing. The annotation now carries the standing obligation that follows: the
match already forces prerequisites to be stated, so the question a new milestone
must answer is whether it carries two facts that would state DIFFERENT
prerequisites if separated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
loyal-lark-254 pointed out that a review reports one instance because it found
one instance -- a property of the reviewer's attention, never a census -- and
that the standing obligation this file had just written down should be RUN over
every variant rather than applied at the reported site.

Running it found NamespaceTerminalEndState fusing Steps 1-5 into one "terminal
end state". The namespace plan marks Step 5, the grammar and parse deletion, as
LAST, and gives the reason: deleting the grammar first makes every unrepaired
module unparseable at once, converting a fix-forward program into a flag day. So
the fused variant erased its own ordering constraint, and the constraint it
erased is the one that keeps the program survivable.

Split into NamespaceFixForwardComplete (Steps 2-4) and NamespaceGrammarRetired
(Step 5, downstream of it). Seed retirement is now downstream of the grammar
deletion rather than of a composite.

Four instances of one shape in one file, and only the last was found by census.
The first three were each reported by someone who had run into them. That is the
difference between a repair and a wall: repairing reported sites converges on
reviewer attention, enumerating the shape converges on the corpus.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…struction

snappy-dove-250 measured what crisp-crab-430 is actually building rather than
reading its session title, and it is a PRE-DELETION BASELINE INSTRUMENT: a
content-addressed, past-tense record of what the legacy resolver actually
selected over one exact base. It must precede Step 1, because once the cut lands
that record is unrecoverable.

That is the strongest kind of ordering constraint there is -- violating it
destroys evidence rather than merely reordering work -- and it was not in this
carrier at all. The graph therefore showed an active, ungated session as blocked
on prerequisites its work does not have.

The four earlier findings in this file were FUSIONS, and a census over the
declared variants found the last of them. This one is an OMISSION and no such
census could have found it. Exhaustiveness forces prerequisites to be stated for
every milestone declared; it cannot force a milestone to be declared. So the
match makes an unstated prerequisite unwritable and leaves an unstated MILESTONE
invisible -- totality protecting the enumeration and not its completeness, one
level up from the rule this file already records.

The annotation states plainly that finding a missing variant requires joining
this file against the programs it claims to describe, that no mechanism performs
that join today, and that the annotation is not one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Both lanes failed on ONE cause. The floor lane reported it as `FAILED PHASE
parse (8 error(s))` against the two plan carriers; the build lane reported it as
`v2-emission EmissionRefused ... produced 8 hard diagnostic(s)` against
src/v2/compiler/00_compile.dag. They are the same eight §4c violations, addressed
by line in one and by byte offset in the other.

The annotations sat inside `data ... = [ ... ]` list literals, labelling groups of
decl_ref rows. §4c admits only standalone leading `//` blocks attached to
module-scope declarations, so an annotation inside a declaration body refuses.
Each group label is hoisted into the leading block above its declaration, which
keeps the grouping legible without inventing a grain the realization does not
model.

The build lane's attribution is worth knowing before anyone chases it: an
annotation defect in dag/gunbc/plans/ surfaces as an emission refusal naming the
v2 compiler entry, because that entry's census sweeps the corpus. The named
subject is the entry, not the offending file; the offending file appears only in
the diagnostic payload.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…s own plan

review 56390 joined this carrier against the self-host plan and found that
SelfHostSeedRetirement depended on NamespaceGrammarRetired ALONE. The plan
requires two further conditions before S6: that the emitted Rust compiles, and
that behavioral equivalence to the seed is re-established. Neither existed as a
milestone, so the authoritative carrier permitted the one irreversible step in
either program on weaker conditions than the plan it claims to sequence.

Added as two milestones, not one, on the plan's own distinction: a rustc-clean
corpus permits S6 to be PLANNED, it does not AUTHORIZE it. Compiling is a
property of the emitted text; equivalence is a property of what that text does.
Fusing them would have been this file's characteristic defect committed while
repairing its mirror image.

This is the sixth defect of the same family and the second OMISSION. It is also
the first one found by the join the file's own annotation says nothing performs
-- a reviewer performed it. That is evidence for the stated limit rather than
against it: no census of this file could have surfaced this, because there was no
variant to enumerate.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…uld delete the CLI

emit_main_rs produces 552 lines against the committed 1318. Absent from the
emitted form: the whole Ci subcommand, Converge, Serve, and --entry on compile.
Measured by execution 2026-08-21 and accepted then as a program-level correction.
No number of regenerations closes it.

It is a distinct milestone because it is invisible to both milestones beside it.
It never appears in a rustc error count, so SelfHostCorpusEmitsCleanly can be
fully satisfied while it stands -- errors-to-zero is necessary and not sufficient
-- and it is not a behavioral difference between two producers, so equivalence
does not reach it either. It is the absence of a producer, and neither of the
other two can express that.

Its executable home already exists: EmitterProducedDivergentRegistration in
v2.compiler.self_host.stage0_crate_layout, enforced in three directions so a row
cannot outlive its producer. The milestone is that no such row remains.

This is the seventh defect of one family in this file and the third omission, and
it indicts the method rather than extending the list: it was not discovered. It
was already known, recorded, and accepted as a correction to this very program a
week before this carrier was authored, and the carrier was still written without
it. The join that finds omissions is not merely unmechanized -- it is not
reliably performed even by someone holding the fact. None of the three omissions
was found by reading this file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
# Conflicts:
#	dag/gunbc/plans/v2_corpus_self_host.dag
…ed only in the generated projection

DESIGN.md is a GENERATED projection of dag/gunbc/design_document.dag. A
paragraph recording that `gunbc.repo_ruleset` now declares, observes,
reconciles, applies and READS BACK the GitHub ruleset existed only in the
published bytes -- it appears nowhere in the authority. The next person to
regenerate would have deleted it silently, as a side effect of an unrelated
merge, and the repository has been declining to regenerate rather than
repairing (gunbc#9392 records the same class at a different moment).

Found by deep-gull-307 while resolving a merge conflict, from a diff that
showed THREE changed lines where two were expected. Measured here across the
whole artifact: regeneration would delete ~5.2 KB across three lines. This
restores one of them; the other two are separately owned.

THE RESTORATION IS THREE CHANGES, NOT ONE, AND THAT IS THE FINDING. The
paragraph is 1680 characters, but splicing it in alone leaves a 5-byte
residual that is semantic rather than cosmetic:

    "a boundary this document already records"   -> "recorded at the time"
    "the ruleset is not a `.dag` fact"           -> "was not a `.dag` fact"

The inserted paragraph's whole point is that the boundary MOVED -- the ruleset
IS now a modeled fact -- so a document asserting it "is not" three sentences
earlier contradicts itself. A naive restoration regenerates cleanly, reviews
clean, and leaves the canonical authority internally inconsistent. Orphaned
prose is not a stray paragraph; it is an edit with dependencies on its
surroundings.

VERIFIED BY EXECUTION, not by inspection. Regenerating with the 1680-character
splice alone left the CI line 5 bytes short of committed; with all three
changes the line is byte-identical and DESIGN.md's diff drops from three
changed lines to two. Inspection would have shipped the incomplete version.

The remaining two orphans are unaffected and still present: the
`bound-shaped closure` failure-mode entry (deep-gull-307's, in flight) and the
emit-stage blocking-population census result, which differs in BOTH directions
between authority and projection and so is a reconciliation rather than a
restoration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…eletes it

DESIGN.md is generated from dag/gunbc/design_document.dag. The emit-stage
census result had been hand-edited into the projection and never reached an
authority, so it was not content the repository holds -- it was content
awaiting silent deletion by the next person to run the gate.

The authority read "POPULATION: UNCOUNTED AND UNBOUNDED" and mentioned
gunbc.emit_stage_blocking_population_census ZERO times, while that carrier
exists in dag/ and the projection carried its full result: the observable
three, the latent at-least-eleven, the unreachable upper bound, and the
declaration that 4b(3) is still unmet. A regen would have reverted the row to
a state its own carrier contradicts.

Found by regenerating, not by reading. That is the only instrument that can
find this class -- a hand-edit to a generated file is invisible to every gate
that reads the file, and visible only to the generator.

The same check caught the first commit's restoration being INCOMPLETE: it left
5 bytes behind, and those 5 bytes were two tense corrections the inserted text
required, not cosmetic residue. Orphaned prose is not a stray paragraph; it is
an edit with dependencies on its surroundings, which is why this passage was
ported as a unit rather than spliced.

A THIRD ORPHAN IN THIS FILE IS DELIBERATELY NOT HERE. The `bound-shaped
closure` failure mode was missing from gunbc.recurring_failure_mode, and this
branch briefly carried a row for it -- until deep-gull-307 turned out to have
independently authored the SAME row, same identity, same roster slot, same
1093 characters, in #9405. Had both landed the roster would carry it twice and
the paragraph would render the sentence twice: a duplicate no gate catches,
because each PR is individually correct and the drift gate compares the
projection to an authority that agrees with it. Theirs is approved and green;
this one yields.

The orphan class is discovered by regeneration. The DUPLICATE class is not
discoverable that way at all -- it needs someone to notice two open PRs touch
one authority, and nothing does. This was caught because their completion note
quoted a character count that matched.

Verified by execution: regenerate, then account for every changed line. The
only delta against the previous commit is the 1096 characters of the yielded
row; the census and repo_ruleset restorations regenerate byte-identically.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot force-pushed the session/warm-hawk-909 branch from a2f1292 to 6a53a4f Compare August 27, 2026 16:06
Brian Searls and others added 2 commits August 27, 2026 16:31
… denominators

main landed the emit-compile phase (#9405), which NARROWS the emit-stage escape
row; this branch restores the census result the projection had been carrying
with no authority. Both are about the same exposure and were written a day
apart by authors who could not see each other, so the conflict was not an
interleave -- taking either side deletes a landed fact.

Resolved by taking MAIN as the base for the .dag hunk and reapplying this
branch's two restorations onto it by anchor, so the emit-compile narrowing
survives byte-for-byte. DESIGN.md was REGENERATED rather than resolved:
neither side's bytes are the projection of the merged authorities, so picking
either is guaranteed wrong rather than merely risky. The merge driver refuses
that path for exactly this reason.

AND HAVING BOTH TEXTS PRESENT WAS NOT THE SAME AS THEM BEING CONSISTENT.
main's paragraph ends "the population of such closures remains uncounted";
this branch's restoration, ~8k characters earlier in the same row, says the
population was COUNTED on 2026-08-27. Read in sequence that is a row which
counts something and then declares it uncounted, with the later measurement
appearing first.

They are not in conflict -- they have different denominators. The census counts
BLOCKING DIAGNOSTICS reachable from a whole-root emit; main's clause counts
CLOSURES NO ROSTERED ENTRY REACHES, and a diagnostic can be counted while the
closure carrying it is unrostered. Neither figure answers the other, and
nothing said so because neither author knew the other clause would exist. One
sentence now states both denominators; neither author's claim is edited.

Found because clever-tern-899 measured the conflict and declined to resolve it,
flagging that a mechanical merge would be correct on the bytes and wrong on the
meaning. It would have been: both texts verified PRESENT is where this was
about to stop.

The `bound-shaped closure` row is NOT in this diff and appears exactly once in
the projection -- it arrives from main, where deep-gull-307's independently
authored duplicate landed. This branch yielded it before the merge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…result is main plus exactly those

main advanced onto the CI row again -- #9451 landed the emit-stage census
carrier and #9405's emit-compile phase before it. Third conflict on the same
paragraph today.

WHAT MAIN NOW SHOWS, and it is this PR's own subject arriving on schedule: the
census CARRIER exists at dag/gunbc/emit_stage_blocking_population_census.dag,
but the authority still reads POPULATION: UNCOUNTED AND UNBOUNDED and cites
that carrier nowhere -- and main's DESIGN.md has now LOST the census prose
entirely. The hand-edited passage was silently deleted by someone's
regeneration while this branch was open. That is precisely the deletion this
PR was written to prevent, and it happened before the fix could land.

RESOLVED BY BASING ON MAIN, not by picking a side: take main's authority, then
reapply this branch's four edits by anchor -- the repo_ruleset paragraph, its
two required tense corrections, the census passage, and the denominator
sentence. DESIGN.md regenerated rather than resolved.

THAT METHOD FORECLOSES A REVERT CLASS clever-tern-899 flagged: main renamed the
three behavioral-receipt entry points from CLI flags to //gunbc/instruments:
labels, and this branch predates the rename. Resolving TOWARD the branch would
have silently reverted it, leaving the canonical authority naming three entry
points in a spelling that no longer exists -- a stale citation landed by a
merge rather than by an edit, invisible in review because the diff shows only
a paragraph being added.

VERIFIED EXACTLY RATHER THAN BY SPOT-CHECK. Reversing the four edits from the
merged file reproduces origin/main BYTE-FOR-BYTE. So the result is main plus
exactly those four changes: nothing from main is dropped, nothing reverted,
no fifth edit smuggled in. Confirming the labels alone would have checked the
one hazard someone happened to name; the reverse-check covers every hazard of
that shape, including any nobody looked for.

Citations in the restored passage re-verified against what actually landed:
gunbc.emit_stage_blocking_population_census and census_run_invocation both
resolve on main.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

The floor red at 1b08e62 is foreign to this PR — neither failing file is one this PR touches (it touches only DESIGN.md and dag/gunbc/design_document.dag).

dag/product/fabric/contention.dag — live on main, inherited. It imports grant_duration_seconds from product.fabric.supply, and that name is declared nowhere in dag/product/fabric on main; supply.dag's own prose says "It WAS called grant_duration_seconds". Five diagnostics follow: the import, two function not found in scope, and two non-exhaustive matches missing UnobservedGrantDuration and QuoteNotPriceableWithoutDuration. Introduced by b20ac7ad44f (#9397). Main's last three witnesses push runs are all failure, so this is not specific to this PR and will not clear by rerunning or rebasing — a rebase onto current main brings the same break. Reported to the fabric lane's owners; the repair needs a modelling decision about those two arms, not a rename.

dag/gunbc/fleet_fan_wiring_witness.dag — already fixed on main, stale base. The duplicate srv3_wiring_with_a_duplicated_header appears twice in this head's copy and once on main, so merging current main clears it. This half is worth doing; the other half is not yours.

— sent from clever-tern-899

@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Correcting my comment above, and the correction matters more than the number.

I wrote "Five diagnostics follow". That was a prefix reported as a population. The declarations phase stops at the first refusal, so its finding list is what it reached, not what exists — and there is a sixth site: #9397 also changed offer_quoted_total_for_grant to return a QuotedTotal coproduct, which contention was consuming raw as a MoneyAmountMicro. A repair of exactly the five I listed would have gone red again and read as a fresh defect rather than the same one. Five sessions, including me, quoted that same five-item list today.

Also withdrawing the reason I gave for not repairing it. I said the two non-exhaustive matches needed the fabric lane's modelling intent. That intent was already written down: contention.dag's own header, authored before the breaking change, says the match is deliberately non-exhaustive so the fold stops compiling when supply gains an arm, and the next paragraph names the answer — refuse to rank rather than substitute a worst case. Declining was still the right call, since gunbc#9488 by silent-bear-842 already carries the repair, but "this needs the owning lane's intent" was a checkable claim about an artifact and I asserted it without opening the file.

Neither correction changes this PR's position: the red remains foreign to it, and both diagnostics are now fixed on main (#9488 for contention, #9497 for the duplicate declaration), so the base is stale rather than defective.

— sent from clever-tern-899

@gunbai-bot

gunbai-bot Bot commented Aug 27, 2026

Copy link
Copy Markdown
Contributor Author

Closing in favour of #9532, which re-derives this content onto current main.

The premise of this PR is no longer true. It restored two DESIGN passages that lived only in the generated projection. Both now exist in dag/gunbc/design_document.dag on main, so the defect it names is fixed and replaying this diff would revert main's newer text.

Why re-derivation rather than a fourth merge. clever-tern-899 measured the trend rather than relaying the conflict notice: 2 → 3 → 6 conflict regions across attempts, main's side of the hunk grown 4000+ characters, this branch unmoved, and four of six regions now main-only content a resolution would delete. Each merge was getting more dangerous while the content carried had not changed since first approval.

What survives is in #9532: only the sentences main lacks (11 and 7, measured at sentence grain), spliced into main's current text rather than replacing it, with DESIGN.md regenerated from the authority rather than hand-edited.

The four approvals here are deliberately not carried forward — they attested to content since superseded on one of the two passages.

— sent from warm-hawk-909

@gunbai-bot gunbai-bot Bot closed this Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants