Repository navigation
Net shared-artifact fill out of the CPU evaluation deadline: the fourth home of one accounting rule - #9612
Merged
Conversation
…27 attribution ruling on the clock it is enforced against The floor's cost axis blocks merges, and on main it refuses over two rows whose own cost is 0ms and 1ms. test.claim.transport_script_wall_compile_red's two RED controls refused main run 33145062452 at ~18100ms against a 10000ms WALL requirement. The floor's own instrument says what that figure is, on those exact rows: wall_red_string_join_into_retained_record_refuses marginal_cpu_ms=0 fill_cpu_ms=18966 wall_red_deleted_free_minter_refuses marginal_cpu_ms=1 fill_cpu_ms=18823 Both provenance=filled-shared-artifact, both triggered_by themselves. They are first payers for a shared memo every later claim naming the same source then reads free -- not expensive witnesses. Across all 12949 rows of that run the MAXIMUM marginal_cpu_ms is 72 and only three rows have fill>5000ms, so there is no expensive witness on the floor at all; there are first payers. WHY THIS WAS ALREADY DECIDED AND STILL HAPPENED. The 2026-08-27 operator-line ruling -- a shared-artifact fill is not this claim's marginal cost, and charging it makes a merge-blocking ceiling a function of EXECUTION ORDER rather than of the tree -- is implemented in run_claim_measured. On the CPU clock. The comment directly above the wall figure said in its own words that wall_nanos stayed the measurement basis unchanged, and wall_budget_completion_outcome enforced on that unadjusted number. One accounting rule with two homes, one of which does not apply it: the DESIGN section 3 failure the CPU comment sitting six lines above it already names. WHAT LANDS. Fill wall time is recorded at both memo-miss sites, beside the CPU recording and never without it, so a fill cannot be counted on one clock and not the other -- which is the state that produced this. The claim loop splits the wall clock through a named marginal_wall_nanos, and the receipt records the quantity actually enforced, per the rule the CPU side's own comment states. SPLIT, NEVER DROPPED. Both halves are reported as new marginal_wall_ms / fill_wall_ms / measured_wall_ms columns on the [floor-shared-fill] line and they sum to what the claim spent. The report guard now fires on EITHER clock's fill: a fill that blocks on I/O can spend wall time while charging almost no CPU, and under the previous CPU-keyed guard that fill would have been subtracted from the enforced figure and reported nowhere -- a cost dropped rather than split, which is the one thing the ruling forbids. WHY THE ROOT AND NOT THE ROWS. The defect is not a property of these two rows. It belongs to whichever row reaches a shared memo first, which is a function of discovery order, so withholding this pair leaves the mechanism live and the same refusal reappears on a different pair when the corpus reorders -- with a withhold established as the remedy. That is the absorbing fallback: the deficit's frequency driven to zero by construction while the cause stands. EVIDENCE, AND WHAT IT DOES NOT COVER. The three added controls establish the arithmetic and that the ceiling still refuses an unsplit figure -- the second arm is what makes the first a control rather than a restatement, so the pair fails if the split is removed AND if the ceiling stops firing. They drive marginal_wall_nanos directly, so they do NOT establish that production still calls it and would pass if that wiring were deleted. The executing consumer for the wiring is the floor run itself: these two rows refuse on main and must reach a verdict here, which is a discriminating input rather than a fresh green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cost axis declared rather than absorbed #9106 deleted the floor's stale live-tree decline -- a file-grain prediction that a live-tree reader could not join the hermetic fold, which had stopped agreeing with what the interpreter does. Deleting it was correct and it admitted a population that had never executed. Main has been red on four causes since. Measured on run 33145062452 (3a8344b): failed=47 interrupted_before_verdict=44 completed_over_cost_requirement=2 stale_quarantine=1. TWO OF THE FOUR CLOSE HERE, and both are the existing mechanism's own paths rather than new machinery. chunk_24 enrols the 47. Every one EXECUTES, REACHES ITS SUBJECT AND ANSWERS FALSE -- the run classifies each as `returned Bool(false)`, which is the semantic verdict this roster is defined over. None overlaps `floor_route_gap` (checked at identity grain: zero), none is already enrolled (zero), none is a budget outcome. THE TREE ALREADY DEMANDED THIS, which is what makes enrolment the intended completion rather than a convenient one. `quarantine_probe_disposition_witness_test` `the_former_live_tree_declined_row_is_now_expected_red` asserts that `legacy_test_behavior_unclassified_frontier_is_zero` is held by this roster. It was authored against the post-#9106 world and has failed every run since, because the row it names was never added -- and that witness is itself one of the 47. Four rows are therefore expected to leave chunk_24 on the first run after it lands, by the roster's own removal path rather than by an edit. The stale-quarantine row comes out: `duplicate_definition_in_one_module_is_refused` is enrolled and PASSING, and the run named it and asked. Repayment and deletion are one act. THE OTHER TWO ARE DECLARED, NOT ABSORBED, and the diff deliberately does not touch them. An interrupted row produced NO VERDICT; enrolling it would assert "this runs and fails and someone is fixing it" about an identity that never answered -- the exact 101-row mistake this file's header opens with, and `ExpectedRedArm` refuses budget outcomes by construction so it would not take. The 2 completed-over-cost rows answered, but what they owe is a cost and not a failure. Cost is not a verdict. The population is bounded and measured at identity grain: 44 interrupted, all CPU-clock against 5000ms, concentrated in live-tree corpus witnesses (13 grammar_coverage_witness, 6 enforcement_live_witness, 6 accumulator_copy_roster_gate, rest across 10 modules); 2 completed-over-cost, both transport_script_wall_compile_red, wall clock at 18882ms and 19024ms against 10000ms. Every interrupted figure is a LOWER BOUND, so their real cost is unmeasured. WHERE THEY GO IS NOT A NEW MECHANISM. `required_floor` names the remedies exhaustively -- reduce what the witness reaches for, or a lane declaring its own dated ceiling -- and rules relocation out. A carrier for exactly this axis is already built and open as gunbc#9517 (`v2.workflow.floor_cost_debt` + a `DeclinedCostDebt` arm), and its roster returns `Empty`: the machinery landed without its population. These 46 are that population. Authoring them into a module that is not on main would fork the authority, so they are handed to that lane at identity grain instead of duplicated here. RUNG (DESIGN 4b(3)): the cost axis stays below the floor's bar -- the run still stops, so nothing is silently admitted, but 46 identities reach no usable verdict every run and no mechanism on main holds them. RESTORATION TRIGGER: #9517's roster carries these 46 under its O=R admission -- and NOT when #9517 merely merges, because #9517 as it stands closes zero of them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NHhQMNap6UfsQbkmVEQm7J
…relaying it The chunk_24 declaration asserted that #9517's floor_cost_debt roster returns Empty on the authority of a relayed reading. That reading was correct, and a correct relayed claim is still a claim this file cannot check. Read directly: floor_cost_debt_chunks() on origin/session/witty-wren-148 is Empty {} and the file authors no qualified-name literal, so floor_cost_debt_holds answers false for every name and nothing is ever DeclinedCostDebt. The consequence is what the restoration trigger already turns on and is now stated where a reader meets it: #9517 merging closes none of these 46. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NHhQMNap6UfsQbkmVEQm7J
…number the chunk TWO FIXES, both about the same failure mode arriving on different clocks. THE STALE ASSERTION. The previous commit recorded, as a first-hand reading, that #9517's floor_cost_debt roster returns Empty. The reading was honest and it was wrong within the hour -- that branch was moving while I read it, and its roster now carries a population including these 46. A bare present-tense claim about ANOTHER LANE'S HEAD has no producer on this side of the boundary that could re-derive it, so nothing here refuses when it goes false. The sentence is deleted rather than re-pinned to a newer number, because a second number rots the same way. What survives is only what this module can stand behind: these 46 are absent from this roster, deliberately, and why. The restoration trigger is restated to name the CAPABILITY (DESIGN 4b(3), 2026-08-26): a roster ON MAIN carrying the 46 under O=R admission. Explicitly not "#9517 merges", since a merge of an empty roster closes none of them, and explicitly not "that lane enrols them", because an enrolment on an unmerged branch changes nothing about what the required run on main observes. Both of those would fire while main stayed red on 46 rows. THE CHUNK IS NO LONGER NUMBERED. Three open branches each mint floor_expected_red_chunk_24 into this file: this one, #9587 (one add-slice row) and #9569 (six sole_constructor rows, which are also six of the 47 here). The numeric suffix is a shared mutable counter every concurrent lane computes independently from the same base, so collision is the expected outcome, not a risk. And it is worse than an ordinary conflict. Two lanes appending a same-named fn at different offsets can merge with NO conflict markers, leaving one file with two definitions of one name, and this repository has measured what happens then: test.claim.duplicate_definition_binding_probe exists because a duplicate definition is silently accepted and the later binding wins. The merge would not fail; it would quietly drop one lane's rows and stay green. A position-derived name is a second naming scheme for something the declaration already names (DESIGN section 3), and this is that rule's cost arriving in the merge graph. A meaning-carrying name cannot be independently derived by two lanes, so the collision becomes unrepresentable instead of detected. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NHhQMNap6UfsQbkmVEQm7J
…ty strings cannot distinguish
All 47 stay enrolled. What changes is what the header claims about them.
THE OVERCLAIM. The chunk said every row "EXECUTES, REACHES ITS SUBJECT AND ANSWERS
FALSE". The run establishes the first and third and not the second: Bool has no
spelling for "I could not observe my subject", so an unreached subject and a
genuine NO both render as returned Bool(false). That is this document's own
execution-provenance-loss class, and the clause is removed rather than softened
because a reader quoting it would be quoting a property nothing measured.
THE THREE GROUPS. A row here is a bare identity string with no reason field, so
enrolment says exactly one thing about 47 rows failing for at least six causes
with different remedies. Named in the header as follow-ups, verified against the
cited files rather than accepted on report:
1. The three guarantee_floor_class_probe_witness generic-instantiation rows fail
because a WALL LANDED, not because the hole is open. Discriminating evidence:
both of that hole's controls PASS and the sibling field_through_generics hole
probe also passes, so the harness reached the judgment and the other hole is
genuinely still open -- a harness seeing nothing would have taken the sibling
down too. That module's own scope note prescribes the remedy verbatim: rewrite
as ExpectBlockingRefusal rather than delete the probe, which is DESIGN 4b(4).
2. The four sole_constructor f10 rows answered an open question the first time
they ran. Their annotation states a question, not a marked red, and the answer
is yes: _ab fails while _ba passes on identical source with imports swapped,
and the two direct probes fail in opposite directions -- last-import-wins. The
distinction is decidable in the file: f13 and f19, enrolled here on the same
footing, carry an explicit "Deliberately RED" marking and the f10 four do not.
3. The three cost_coverage_witness rows are the subject-reachability candidate.
That module's 7 passing fns are the ones that survive an empty subject; the 3
failing ones demand non-zero content. Consistent with a genuine NO and equally
consistent with a subject never reached. Enrolled as failing, which is what was
observed; not asserted to be semantic.
WHY FOLLOW-UPS AND NOT A SPLIT. Enrolment is a reversible holding state with a loud
exit: the floor refuses on an enrolled row that starts passing and names it, which
is the same path by which this change removes one. So none of the three can be left
quietly at rest. Against that, holding rows back keeps the floor red, and the
compute fabric is fail-closed on the floor -- gunbc.fleet_desired_admission refuses
to advance the desired ref until the floor concludes Success on some revision.
A STALE PREMISE FOUND WHILE CHECKING THE ABOVE.
gunbc.declined_live_tree_defect_classification states it "must never become" an
expected-red enrolment "because the floor does not run it at all". Eight of the
modules it classifies contain rows enrolled here, and the floor DOES now run them --
they are in run 33145062452's FAIL lines. The clause is not wrong about authority
substitution in general; its REASON has been overtaken by #9106. Not edited here,
because it is that carrier's to correct and a second account of one fact is the
defect either way.
The triage behind groups 1-3 is crisp-newt-899's, checked here against the files.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NHhQMNap6UfsQbkmVEQm7J
…wrong by one in an instructive way Run 33154432928 on a474f45: failed=0 stale_quarantine=3. WHAT WAS PREDICTED, registered in the PR body before the run: enrolling legacy_test_behavior_unclassified_frontier_is_zero satisfies the assertion the three quarantine_probe_disposition_witness_test claims make ABOUT this roster, so they stop failing and report STALE-QUARANTINE. The floor named exactly those three. They are removed here by the roster's own removal path. THE PREDICTION SAID FOUR. The fourth name was legacy_test_behavior_unclassified_frontier_is_zero itself, and it did not flip -- correctly. It is the row the join is ABOUT, not a row that passes as a consequence: it still fails on its own subject and this roster still holds it. I conflated "the identity a witness names" with "an identity that changes state when the witness is satisfied", and a join has both roles in it at once. That is recorded in the header rather than quietly corrected, because the error is the more instructive half of the result. WHY THE ENROLMENT WAS STILL RIGHT FOR ALL THREE, and this is what keeps the removal from reading as a mistake being fixed: they failed on main and answered false, so they met this roster's admission when they were added. What removed them is that the same change repaired their subject. A roster that could not hold a row for one run and release it on the next would force an author to predict the repair perfectly before landing it -- and the loud STALE-QUARANTINE exit is exactly the mechanism that makes holding safe. FLOOR STATE AFTER THIS: failed=0, stale_quarantine=0 expected. The verdict axis closes. The 44 interrupted and 2 completed-over-cost remain and are the declared cost axis, owned by #9517; required_floor_outcome_is_clean makes interrupted_before_verdict.is_empty() a conjunct at claim_executor.rs:1766, so main stays red until that lane lands. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NHhQMNap6UfsQbkmVEQm7J
…th home of one accounting rule The required floor refuses on interrupted_before_verdict, 44 rows on run 33185280160, every one of them on the Cpu clock. Those interruptions are produced by a deadline that charges a claim for work every later claim reads free. THE RULE IS NOT NEW AND THIS IS ITS FOURTH HOME. The 2026-08-27 operator-line ruling -- a shared-artifact fill is not this claim's marginal cost, and charging it makes a merge-blocking ceiling a function of EXECUTION ORDER rather than of the tree -- has now been applied one site at a time: the completion-side CPU split, then the completion-side WALL split, and now the CPU deadline. Each application happened only after that site's omission had cost something. WHY POST-HOC NETTING COULD NOT REACH THIS. run_claim_measured nets at COMPLETION; the deadline fires DURING execution on a baseline taken from raw thread_cpu_nanos(). A row killed mid-fill never reaches the netting at all. Worse for exactly the population at issue: per std.evaluation_budget's PREEMPTION-1 note the poll is only read between eval_expr calls and compile_dag_rust_emit_check never calls back into eval_expr, so the deadline fires at the first poll AFTER a compile fill returns, having been charged the whole thing. The row completes the fill, every later claim reads the memo free, and the row that paid for it dies. THE CONSTRUCTION IS A CLOCK, NOT A BASELINE PAIR. budgeted_cpu_nanos() is thread CPU less this thread's accumulated fill, and every CPU budget site reads it -- arm_eval_deadline, eval_deadline_remaining_ms, the stride poll, and the enter_evaluation_budget scoped guard. Because both the arming instant and the polling instant come from that one function, the fill accrued between them cancels inside a subtraction that already exists. The alternative -- storing a (cpu, fill) baseline tuple and subtracting at each poll -- requires every present and future site to REMEMBER to net, and a site that forgets is a silent defect. Here there is nothing to forget (DESIGN 5, construction over validation). It is monotone, which a deadline requires: fill is measured on the same thread clock inside the miss path, so raw CPU rises by at least as much as fill over any interval and the difference never decreases. THE COUNTER MOVED, AND HAD TO. It now lives in v1_interpreter with cli_run delegating, because the deadline must net the same quantity WHILE a claim runs and the interpreter cannot read a cell cli_run owns. One counter with two readers rather than two counters that drift -- which is the same one-rule-many-homes defect this commit repairs, avoided rather than repeated. EVIDENCE. Three controls, and the discriminating pair is established by execution: with budgeted_cpu_nanos reverted to raw thread_cpu_nanos, the fill assertion and the monotonicity assertion both FAIL while the ordinary-work control still passes -- a control insensitive to the fix, which is what makes the other two informative. Three earlier formulations of that test were wrong and are recorded in the test's own annotations, because each failed while the production code was correct: one compared against a spin loop's measured cost and the runner reported zero, conflating a dead clock with broken netting; one asserted an identity between deltas spanning different overlapping intervals; one injected a fill larger than the thread's own CPU, a state production cannot reach because a fill is bounded by the raw clock by construction. WHAT IS NOT CLAIMED. No floor run has adjudicated this, so nothing is asserted about how many of the 44 clear. Two opposite predictions were registered before the fact and only a run decides. If NEITHER group moves, the netting did not reach the deadline path and the result says nothing about cost. THE WALL DEADLINE IS UNREPAIRED AND DECLARED. It still arms on a raw Instant and still charges a fill to whoever paid it. All 44 interruptions are Cpu, so the arm is currently unexercised -- a fact about today's population, not the mechanism -- so it is a countable obligation in gunbc.guarantee_rung_drop whose trigger is an OBSERVATION that fires from the ledger without anyone remembering the row exists: the first INTERRUPTED-BEFORE-VERDICT row whose clock is Wall. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… cheap, so they leave the roster v2.workflow.floor_cost_debt withholds 276 identities from the floor's plan -- suppress_withheld removes them before the fold, so a withheld row does not execute at all. Both transport_script_wall_compile_red rows were in it. WHY THAT HAD TO CHANGE IN THIS PR RATHER THAN LATER. While those rows sat in the roster the floor reported completed_over_cost_requirement=0 BECAUSE THEY DID NOT RUN, which is indistinguishable in that counter from this branch's wall netting having repaired them. The fix's discriminating evidence is precisely those two rows reaching a verdict where they previously refused, and a withheld row produces no verdict to transition. Landing the netting while they stayed withheld would have shipped a repair with no observable consumer. THE DELETION IS THE CONTRACT'S OWN PRESCRIBED EXIT, not a judgement call made here. floor_cost_debt's header names this lane and states the condition: 'cool-koi-235 is repairing it at the root by netting fill out of the wall clock as it already is for CPU; when that lands these two become cheap rather than invisible and their rows should be DELETED, which is the ordinary shrink this contract is built for.' That condition is now met. The same header explains why it declined to drop them pre-emptively -- 'dropping a row whose cost is an artifact is right only once the artifact is gone' -- and that reasoning is kept in the past tense rather than deleted, because it is what lets a later reader tell this shrink from a premature one. CHECKED BEFORE EDITING, because suppress_withheld applies to THREE rosters and a deletion here makes any dormant enrolment elsewhere observable again: neither identity appears in floor_expected_red, floor_route_gap or floor_non_verdict, so nothing wakes. They return to ordinary execution with no disposition attached. Also checked: no witness asserts either identity's membership in this roster -- the discovery census witness pins a different member on purpose, the seed-growth carrier enumerates no identities, and required_floor's mention is historical calibration prose. Their own marginal work is 0ms and 1ms. What withholding hid was an accounting artifact, not a cost. The two current-population counts in the header move 276 -> 274. The two historical figures in the same file do not: they describe a superseded roster and a measurement taken on a different tree, and rewriting them would destroy the provenance the file keeps deliberately. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…n's new roster The textual conflict is an append/append at end of file -- my wall_deadline_shared_fill_attribution_stall row against main's heterogeneous_child_list_stall. Keeping both is necessary and NOT sufficient: main also landed all_guarantee_stalls, a hand-maintained roster over which every_stall_is_below_its_ceiling and every_stall_names_a_trigger are universally quantified. A row kept textually but left out of that list is invisible to both folds -- the semantic half of the conflict, which the text merge cannot see and which the file's own header names as a real weakness. The row is therefore enrolled. Nothing pins the roster to a literal count (the witness asserts size > 0 and size([]) == 0), so enrolment widens the quantifiers' domain without moving any counted claim. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
6 tasks
Contributor
|
Review 57310 is correct and I have verified it independently on main: the closing brace is genuinely absent, the file's brace balance is +1 against 0 on a peer carrier, and this PR's merge commit is main's current HEAD. Repair is open as #9630 — one character, no semantic change to the row. Noting for the record that neither this PR's head ( — sent from swift-badger-524 |
This was referenced Aug 28, 2026
Merged
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 28, 2026
… does not parse #9612 added wall_deadline_shared_fill_attribution_stall and ended it at next_rung_trigger with no closing brace, so the next `data` declaration begins inside the record literal. Every peer stall in the file closes with `}` before the next declaration, and the file's own brace balance is +1 against 0 on a peer carrier (floor_cost_debt). The module is the canonical §4b(3) rung-drop carrier and all_guarantee_stalls now references the new row, so the parse phase of the required run cannot get past it. Neither #9612's head (794e042) nor its merge commit (e910a39) has any workflow run recorded, which is why the defect reached main with no verdict against it. One character. No semantic content: the row, its population and its trigger are exactly as #9612 authored them. Found by review 57310 on #9612, which raised it as REQUEST_CHANGES after the PR had already merged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 28, 2026
…iers to PlanIsAuthorityOnly cli_run.rs: main @ e910a39 (#9612) re-added the three shared-artifact wall-fill definitions that a231ccb (#9609) had already landed a minute earlier — duplicate fn/static definitions, E0428, so main's head does not build; its own CI runs are still queued behind the backlog. The second, byte-identical copies are removed. Plan carriers: every carrier whose committed markdown projection was deleted in this cleanup now declares PlanIsAuthorityOnly with the ruling, per the a295e17 precedent — the registry row is what made the deleted .md expected on disk, and flipping it is the modeled path that keeps the generated-artifact phase green without resurrecting the files. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
briansrls
added a commit
that referenced
this pull request
Aug 28, 2026
* Stability plan: CI to minutes via indexes + closure-digest verdict cache, 47-red triage, srv1 convergence, repo cleanup census Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Delete 21 orphan docs: unreferenced from dag/, src/, CI, DESIGN/ROADMAP, and every other doc Reference census: each basename grep'd across all tracked non-docs content and across docs/ itself; zero consumers. The srv1_residue_rehearsal receipt's path-string mentions are a host-disk snapshot, not consumers. docs/briefs loses 5 of 8 one-day lane briefs; docs/plans loses 15; the remainder await disposition in docs/plans/repo-stability-2026-08.md P4. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan log: record first orphan-doc cut Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Delete tools/ receipt dumps and 33 more stale off-topic plan docs tools/: all five persisted receipt/manifest files (m1c_bulk0_*, extdeps_scope census) removed per operator ruling — derived data is not committed; only .dag code to re-derive it belongs in tree. Their only in-tree mentions are path strings in the srv1_residue_rehearsal host-disk snapshot receipt. docs/plans: 33 files last touched 2026-06..08-14, off the live workstreams (v2 self-host, fabric, roadmap, namespace/import migration, scm, CI stability), and whose only references are the srv1 disk-snapshot strings, each other, or nothing. 112 further old off-topic plans are deferred because live carriers (roadmap_authority, dag plan carriers, cli_run.rs, lens modules) cite them; those need carrier-row edits, tracked in docs/plans/repo-stability-2026-08.md P4/P5. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Delete src/v2/experimental (empty quarantine); plan log update Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Delete docs/plans/receipts + measurements: 13.5M of persisted measurement dumps Operator ruling: derived data is never committed — only the .dag code to re-derive it. Verified no executing consumer: every in-tree mention of these paths is prose (annotations, note strings, the srv1 disk-snapshot rows, a roadmap handback sentence); nothing reads them at witness or compile time. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Delete 112 stale off-topic plan docs (operator ruling: content-based purge) All last touched 2026-06..08-14 and off the live workstreams (v2 self-host, fabric, roadmap, namespace/import migration, scm, CI stability). Citing comments and prose pointers in dag/src carriers are stripped in the follow-up commits; historical receipts (srv1 disk snapshot, roadmap acceptance history, digest-bearing fixtures) are left as-is since they describe past states. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Dedupe cli_run.rs (main-head build break) and flip 48 stale plan carriers to PlanIsAuthorityOnly cli_run.rs: main @ e910a39 (#9612) re-added the three shared-artifact wall-fill definitions that a231ccb (#9609) had already landed a minute earlier — duplicate fn/static definitions, E0428, so main's head does not build; its own CI runs are still queued behind the backlog. The second, byte-identical copies are removed. Plan carriers: every carrier whose committed markdown projection was deleted in this cleanup now declares PlanIsAuthorityOnly with the ruling, per the a295e17 precedent — the registry row is what made the deleted .md expected on disk, and flipping it is the modeled path that keeps the generated-artifact phase green without resurrecting the files. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Strip comment pointers to deleted plan docs (45 mentions, 13 files) Comment-channel only (§4c: annotations never reach emission, so no mirror or projection drifts). String-field citations in roadmap_authority and stale plan carrier bodies are deferred to the roadmap/plans content refresh, where those rows are edited with their projections regenerated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan log: fourth cut + main build-break finding Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y --------- Co-authored-by: Claude <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 28, 2026
…th (3x E0428 + unclosed record literal) (#9634) * main does not compile: delete the duplicated shared-artifact fill-wall block in cli_run.rs #9609 and #9612 each added the same wall-clock fill accounting block. Their insertions are ADJACENT rather than overlapping, so the squash merges text-merged both with no conflict and neither PR was ever compiled against the other. main e910a39 therefore carries three duplicate definitions: SHARED_ARTIFACT_FILL_WALL_NANOS static, 2560 and 2573 record_shared_artifact_fill_wall fn, 2593 and 2601 shared_artifact_fill_wall_nanos pub fn, 2613 and 2619 and v1-compiler fails with three E0428. The blast radius is the whole repository, not one PR: both required lanes die at their FIRST step, Build the witness fold, before any .dag phase runs. Nothing on any branch can go green while this stands. THERE IS NO CANONICITY QUESTION. All three pairs are BYTE-IDENTICAL, doc comment and body, verified by diff over their exact boundaries -- the two lanes authored literally the same text. Deleting the second copy of each is a semantic no-op, so this needs no ruling about whose accounting survives. Deletions only: 27 lines removed, 0 added. Verified by execution, with a discriminating control on the same instrument: cargo check -p v1-compiler --lib on main's file -> 3x E0428, exit 101 cargo check -p v1-compiler --lib repaired -> Finished, exit 0 cargo check -p v1-compiler --bins repaired -> Finished, exit 0 Reported independently by clever-crab-449, silent-bear-842 and loyal-raven-764, none of whose diffs touch cli_run.rs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * Close the unclosed record literal in guarantee_rung_drop: main's HEAD does not parse #9612 added wall_deadline_shared_fill_attribution_stall and ended it at next_rung_trigger with no closing brace, so the next `data` declaration begins inside the record literal. Every peer stall in the file closes with `}` before the next declaration, and the file's own brace balance is +1 against 0 on a peer carrier (floor_cost_debt). The module is the canonical §4b(3) rung-drop carrier and all_guarantee_stalls now references the new row, so the parse phase of the required run cannot get past it. Neither #9612's head (794e042) nor its merge commit (e910a39) has any workflow run recorded, which is why the defect reached main with no verdict against it. One character. No semantic content: the row, its population and its trigger are exactly as #9612 authored them. Found by review 57310 on #9612, which raised it as REQUEST_CHANGES after the PR had already merged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 28, 2026
…ontier fixture exemptions, BMC demand-curve type error Both pre-date this branch and were invisible while #9612's parse refusal kept every required phase from running; this branch's head is the first to reach the declarations census and the floor's strict preparation, so they surfaced here. - declaration_index.rs FIXTURE_CARRIER_CITATION_EXEMPTIONS: #9607 re-pointed test.claim.annotation_carrier's planted rows at the deliberately-fictional test.fixture.frontier without updating the exemption roster. Add the four rows for the new deliberately-absent citations and delete the spent extdeps.network.mac row the census itself demands removed. - extdeps/bmc/pid_control_program.dag curve_points_agree: the output half compared a ZoneDemandValue where decimal_measures_agree declares a Measure; compare the ExactDecimal magnitudes directly (verified: the entry now compiles with 0 blocking diagnostics). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh
briansrls
pushed a commit
that referenced
this pull request
Aug 28, 2026
Both sides of the merge fixed #9612's unclosed record identically; the auto- merge kept both hunks' markers. Smoke-verified: the converge actuator (now at dag/gunbc/repo/ after the filename reorg) compiles and executes again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
briansrls
pushed a commit
that referenced
this pull request
Aug 28, 2026
…ery PR's floor All landed on main inside the masked window (#9612's parse refusal kept the floor from typechecking anything); this branch is the first head to reach strict preparation, so they surface here. Seven are ported verbatim from #9646 (capacity_class on the training fixtures, value CustomerExecutableCapacity per that PR's model reading — it no-ops when that PR merges); four are fixed here: - source_integration_landing_spine: the Optional-receiver '|> map' at the additional-continuation arm becomes a match (the module's own idiom two arms up), and the module's unresolved-method frontier row in v1/04_infer.dag is deleted per the diagnostic's own prescription — the deficit fully dissolves, so the row must not keep its ground. - fabric_terminal_contract_witness_test: the positive-control receipt is bound as Receipt<NonEmptyStr> before the call, so the payload's P no longer infers String against the NonEmptyStr grant. - repository_convergence_placement: drop the primary_path argument; repository_converge_wet derives it internally and no longer declares the parameter. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh
briansrls
added a commit
that referenced
this pull request
Aug 29, 2026
* Close the guarantee_rung_drop parse refusal and the generated-artifact drift the masked window accumulated - guarantee_rung_drop.dag: restore the missing closing brace on the wall_deadline GuaranteeStall record (#9612); the unparseable module refused the whole module index, so both required lanes died before any drift adjudication could run. - gitignore authority/model/emit: delete the seven hardcoded .py allowlist variants whose subjects the measurement bankruptcy and the plan-markdown cut deleted; drop the gate test fn that pinned those literal rows (a tree-copied oracle). - generated_artifact.dag: repoint the two stage0 generated .dag ArtifactLocation rows to dag/gunbc/stage0/, where #9637 moved the files; the registry still named the old directory. - Regenerate .gitignore, .gitattributes, and .githooks via generated_artifact_gate main_wet: .gitattributes drops the 41 merge-driver rows for plan markdowns #9635 deleted (verified by executing expected_gitattributes()); .gitignore drops the dead allowlist rows and gains the derived ignore rows for authority-only plan markdowns; hook headers pick up the post-reorg githooks/ module paths. - Delete dag/config/codegen_paths.dag: an orphan module no closure reaches, describing a layout that no longer exists. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Remodel .gitignore: producer-declared workspace footprints with typed ignore reasons Replaces gunbc.gitignore_model + gunbc.gitignore_authority (one nullary variant per path, patterns restated in a central emit match — the shape that let seven dead allowlist rows emit unnoticed) with a producer-owned derivation: - std.workspace_artifact: the agnostic shape — WorkspaceArtifact {pattern, meaning, reason} with a closed IgnoreReason vocabulary, and WorkspaceFootprint with CitedUpstream/RepoTool provenance. - Each extdeps product declares its own footprint beside its citation (cargo, cargo-tarpaulin, CPython/PEP 3147, npm, tmux, macOS Finder, Windows Explorer, JetBrains, VS Code, Vim, Emacs, dotenv); repo-chosen locations are parameters, so policy stays a workflow fact. - gunbc.repo_workspace joins extdeps footprints with the repo's own tools' declarations (each naming its owner module) — onboarding a concept now naturally carries what files it introduces, what they mean, and why they are untracked. - gunbc.gitignore_emit becomes a pure renderer: it declares no pattern of its own; the emitted file carries each pattern's reason and meaning as comments. Generated-artifact rows remain a separate arm derived from gunbc.generated_artifact commit policy. - src/v1/runtime_rust.dag: align the emitted trace_mark doc comment with the #9635 hand-edit of the generated v1_rt.rs mirror, restoring regen first-generation equality (drift was masked on main by the guarantee_rung_drop parse refusal). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Install the stage0 mirror for std.workspace_artifact The new module entered the v1 seed closure, so --required-regen refused with 'emitted surface has no committed mirror'; this installs the candidate the regen run produced (std_workspace_artifact.rs plus its lib.rs module line), unmodified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Install the regen-produced stage0 mirrors the remodel drifted --required-regen names four drifted surfaces, each a direct consequence of this branch's edits: extdeps_cargo.rs (cargo.dag gained its workspace footprint), v1_compiler_runtime_rust.rs and v1_rt.rs (the trace_mark doc comment realignment), and emitted_population.rs (the population gained std_workspace_artifact). All four installed from the regen candidate tree unmodified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Use concat, not append, for the cargo footprint list join The emitted v1_rt::append takes (list, one item) while the interpreter's append(list, items:) concatenates lists — cargo.dag is the first mirrored seed module to hit that divergence, so its emitted mirror failed to compile (E0308 at extdeps_cargo.rs:277). concat has the same list-concatenation meaning in both realizations. The regenerated mirror follows in the next commit once the fixed-point verification completes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Install the second-generation mirrors: concat-form extdeps_cargo, corrected v1_rt extdeps_cargo.rs is the regenerated mirror of the concat fix (compiles clean; verified by cargo locally). v1_rt.rs corrects a first-generation install in the previous mirror commit: that candidate was emitted by the pre-fix binary, so it reverted the trace_mark doc comment while the generator mirror in the same commit moved forward; this is the second generation's output, matching what the current generator emits. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Port two masked-window main defects this branch unblocked CI into: frontier fixture exemptions, BMC demand-curve type error Both pre-date this branch and were invisible while #9612's parse refusal kept every required phase from running; this branch's head is the first to reach the declarations census and the floor's strict preparation, so they surfaced here. - declaration_index.rs FIXTURE_CARRIER_CITATION_EXEMPTIONS: #9607 re-pointed test.claim.annotation_carrier's planted rows at the deliberately-fictional test.fixture.frontier without updating the exemption roster. Add the four rows for the new deliberately-absent citations and delete the spent extdeps.network.mac row the census itself demands removed. - extdeps/bmc/pid_control_program.dag curve_points_agree: the output half compared a ZoneDemandValue where decimal_measures_agree declares a Measure; compare the ExactDecimal magnitudes directly (verified: the entry now compiles with 0 blocking diagnostics). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Close the remaining eleven strict-preparation diagnostics blocking every PR's floor All landed on main inside the masked window (#9612's parse refusal kept the floor from typechecking anything); this branch is the first head to reach strict preparation, so they surface here. Seven are ported verbatim from #9646 (capacity_class on the training fixtures, value CustomerExecutableCapacity per that PR's model reading — it no-ops when that PR merges); four are fixed here: - source_integration_landing_spine: the Optional-receiver '|> map' at the additional-continuation arm becomes a match (the module's own idiom two arms up), and the module's unresolved-method frontier row in v1/04_infer.dag is deleted per the diagnostic's own prescription — the deficit fully dissolves, so the row must not keep its ground. - fabric_terminal_contract_witness_test: the positive-control receipt is bound as Receipt<NonEmptyStr> before the call, so the payload's P no longer infers String against the NonEmptyStr grant. - repository_convergence_placement: drop the primary_path argument; repository_converge_wet derives it internally and no longer declares the parameter. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Resolve the three remaining audit leftovers: delete the import-strip dumps, register js_site's generated pages, keep the bound probe receipt - docs/plans/import-strip-measurement/ and import-strip-residual-ledger.tsv: deleted as unconsumed transcription per the measurement-bankruptcy principle (unconsumed transcription disappears; consumed evidence stays attached to its consumer). Neither is bound in gunbc.doc_graph_roots — the bound import-strip doc is a different, surviving plan markdown. The citing plan's prose now records the deletion. - dag/examples/js_site/generated/: the six committed generated files were produced by examples.js_site_emit and adjudicated by nothing. They are now JsSitePageArtifact rows in gunbc.generated_artifact (derived from the page roster, not hand-listed), located by js_site_emit's own path fns and generated through its pure per-page projections, so the generated-artifact drift phase adjudicates them like every other committed generated artifact. - docs/probes/leading_minus_continuation_silently_truncates_2026-08-23.md: no change, deliberately — gunbc.doc_graph_roots already binds it as consumed evidence under an operator ruling that reverted its deletion. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Install the infer mirror for the frontier-row deletion; adjudicate js_site under the drift gate - src/v1/stage0/src/v1_compiler_infer.rs: regenerated mirror of the 04_infer.dag frontier-row deletion; --required-regen reports first_generation_equal=true on this tree after one rebuild, and the landing_spine entry now compiles with 0 blocking diagnostics. - generated_artifact_emit: the extra-validation match gains its JsSitePageArtifact arm (main_wet's fail-closed non-exhaustive refusal caught the omission). - .gitattributes: regenerated; the six js_site pages join the derived merge-driver population. main_wet regenerates the pages byte-identical to what was committed, so registration changes no page content. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh * Converge v1_rt on the authority's citation text after the merge of main Main closed the v1_rt drift by restoring the mirror to the old docs/plans/ci-floor-fractal-gantt.md citation; this branch had moved the authority to 'ci-floor-fractal-gantt (plan doc deleted 2026-08-28)'. Both were internally consistent and disagreed. The deciding fact: the plan doc does not exist on the merged tree (#9635 deleted it; gunbc.plans.ci_floor_fractal_gantt is authority-only), so main's direction re-landed a citation to a nonexistent file — the §3 stale-citation class. The authority-side text survives the merge in runtime_rust.dag and its generator mirror; this installs the emitted v1_rt.rs so the pair agrees, verified by --required-regen on this tree. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CQPnTvxdvVjBLzjL6bcWVh --------- Co-authored-by: Claude <noreply@anthropic.com>
briansrls
added a commit
that referenced
this pull request
Aug 29, 2026
…osition (13 clusters to named submodules) (#9648) * guarantee_rung_drop: close the record #9612 left unterminated The wall_deadline_shared_fill_attribution_stall record landed without its closing brace, so every gunbc run over the dag root refused at module index (expected expression, found Eq) -- the same collided merge that duplicated the cli_run.rs definitions. With the brace, the documented converge actuator entry runs end-to-end again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan: hand off the per-invocation whole-tree tax finding Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Correct the pool-tax finding: linear ~20-25ms/pool-module eager graph facts, no cwd switch; fast controls were panics Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split 1/n: move seven census clusters to cli_run/ submodules (pure code motion) test_migration, compile_clean, non_fold_residue, class_b_census, languages_census, external_authority, inert_carrier — 107 items, ~2.1k lines. Mechanics: each cluster becomes a cli_run/ submodule with 'use super::*' back into the parent plus the parent's use-header; the parent re-exports 'pub(crate) use <mod>::*' so every existing path keeps resolving. Private moved items widen to pub(crate), which rewraps a few signatures under rustfmt. No semantic change; build-verified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split 2/n: witness_gates, emit_host, complexity_gates, doc_graph, declared_refs, census_heads (pure code motion) 89 items, ~2.1k lines. Bin-consumed pub fns get explicit pub use re-exports (the pub(crate) glob does not cross the lib/bin crate boundary). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split: widen eight report/plan types to pub(crate) (private-interface lints; CI sets -D warnings) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan log: cli_run decomposition progress and the two deferred cores Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split 3/n: fallback_arm_census, p1_cohort, owned_data, live_read_decode, active_workset (pure code motion) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Remove merge markers both brace-fixes left in guarantee_rung_drop.dag Both sides of the merge fixed #9612's unclosed record identically; the auto- merge kept both hunks' markers. Smoke-verified: the converge actuator (now at dag/gunbc/repo/ after the filename reorg) compiles and executes again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split 4/n: entry_resolve — the resolver/index core (75 items, ~2.5k lines, pure code motion) The pool-tax subject now has its own reviewable home: module path index, module-graph facts, import closures, the process shared index and resolve store (thread_local statics widened to pub(crate)), typed-module cache, multi-entry index shell, resolve stage/span accounting. Bin-consumed fns get explicit pub use; two cache types widened for the private-interface lint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * cli_run split 5/n: required_floor_runner — the floor fold and claim execution (49 items, ~4.8k lines, pure code motion) run_required_floor, claim evaluation/measurement, discovery corpus, diff observation, prepared-subject inventory, resource sampling, cgroup envelope, route-gap expectations, floor stream/verbosity plumbing. Same recipe: bin- consumed fns re-exported pub; two expectation/edit types widened for the private-interface lint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan log: resolver core and floor runner moved Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan: standing dependency map (store/native/delete-eval-loop) and the single pre-registered execution test Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Plan log: bisect pins the trim-Null runtime regression to #9344 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y * Fix #9344's effect-output regression: the from-key property value is the string literal it was authored as Bisect pinned main's runtime failure (trim expects a string, got Null on the converge actuator) to 655f82a (#9344). Mechanism: the rewritten parse_optional_from_key built the from_key property's value node with NoExprData (key carried only as a node NAME), and the new field_to_child_node passes parsed properties through instead of re-materializing them — but the interpreter's extract_from_key accepts only ExprLiteral{LitStr}, so every 'output field from "channel"' mapping silently missed, the output key fell back to the field name, and effect-result fields decoded as Null (git.Core.ConfigLocalGetInRepo: .success survived by name, .value did not). The from token IS a string literal in the grammar (ShLitStr), so the fix makes the property value carry ExprLiteral{LitStr{key}} at the one construction site in v1.compiler.parse parse_optional_from_key; the mirror is regenerated via --required-regen (surface drift resolved by installing the candidate). Smoke: the converge actuator executes end-to-end again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y --------- Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #9609 (its commits are included; base is
mainso the required workflow actually runs — a stacked base would produce no run at all, which renders identically to a queued one).#9609 closes three of the floor's four blocking causes and cannot go green alone: the verdict is a nine-way conjunction and
interrupted_before_verdictis one of the conjuncts. This closes the fourth.The defect
44 rows interrupt against the 5000ms CPU ceiling, all 44 on the
Cpuclock. They are interrupted by a deadline that charges a claim for work every later claim reads free.The 2026-08-27 ruling — a shared-artifact fill is not this claim's marginal cost; charging it makes a merge-blocking ceiling a function of execution order rather than of the tree — is not new here. This is its fourth home, applied one site at a time: the completion-side CPU split, the completion-side wall split (#9609), and now the deadline. Each application happened only after that site's omission had cost something.
Post-hoc netting could never reach this.
run_claim_measurednets at completion; the deadline fires during execution against a rawthread_cpu_nanos()baseline. And perstd.evaluation_budget's PREEMPTION-1 note, the poll is only read betweeneval_exprcalls whilecompile_dag_rust_emit_checknever calls back into it — so for exactly these compile-heavy fills the deadline fires at the first poll after the fill returns, having been charged the whole thing. The row completes the fill, everyone else reads the memo free, and the row that paid dies.The construction
A clock, not a baseline pair:
read by every CPU budget site —
arm_eval_deadline,eval_deadline_remaining_ms, the stride poll, and theenter_evaluation_budgetscoped guard. Both the arming and polling instants come from that one function, so the fill accrued between them cancels inside a subtraction that already exists.The alternative — storing a
(cpu, fill)baseline tuple and subtracting at each poll — requires every present and future site to remember to net, and a site that forgets is a silent defect. Here there is nothing to forget. Given this rule has already been missed at three separate homes, that difference is the point.Monotone, which a deadline requires: fill is measured on the same thread clock inside the miss path, so raw CPU rises by at least as much as fill over any interval.
The counter moved into
v1_interpreterwithcli_rundelegating — the deadline must net the quantity while a claim runs and the interpreter cannot read a cellcli_runowns. One counter with two readers rather than two that drift: the same one-rule-many-homes defect this PR repairs, avoided rather than repeated.Evidence
Three controls, and the discriminating pair is established by execution: with
budgeted_cpu_nanosreverted to rawthread_cpu_nanos(), the fill assertion and the monotonicity assertion both fail while the ordinary-work control still passes — a control insensitive to the fix is what makes the other two informative.Three earlier formulations of that test were wrong, and are recorded in the test's own annotations because each failed while the production code was correct:
budget_drop + raw_advance == FILL— an identity between deltas spanning different overlapping intervals.What is not claimed
No floor run has adjudicated this, so nothing is asserted about how many of the 44 clear. Two opposite predictions were registered before the fact. Three outcomes were pre-named so none gets explained away afterwards:
One trap for anyone measuring the residue:
[floor-shared-fill]is emitted in the completion path, so an interrupted row cannot emit it whether or not it accrued fill. Today's zero is not a baseline of zero fill — absence of the line and being interrupted are confounded by construction.The wall deadline is unrepaired and declared
It still arms on a raw
Instant. All 44 interruptions areCpu, so the arm is currently unexercised — a fact about today's population, not the mechanism. It is a countable obligation ingunbc.guarantee_rung_dropwhose trigger is an observation that fires from the ledger without anyone remembering the row exists: the firstINTERRUPTED-BEFORE-VERDICTrow whose clock isWall.THE SUBJECT MOVED UNDER THIS PR, AND EVERY "44" ABOVE IS DATED RATHER THAN CURRENT (2026-08-28, added under wind-down)
Everything above about "the 44" is a measurement of run 33185280160 against a 5000ms CPU ceiling on a roster with nothing withheld. Main has since left that tree in two independent ways, and neither is a correction to this PR's mechanism:
floor_cost_debt. A withheld row does not execute, so it cannot interrupt and cannot appear in any counter.completed_over_cost_requirement=0on current main therefore means suppressed, not repaired.What this does NOT change: the fix here is at the deadline's accounting —
budgeted_cpu_nanos()nets recorded shared-artifact fill out of the CPU clock the deadline reads — and that is a statement about the mechanism, not about any population size. Its evidence is the three unit tests plus the revert arm (netting removed → 2 of 3 red, control green), which are independent of both the ceiling and the roster.What it does change: the two pre-registered predictions above are retired, not adjudicated. They were forecasts about how many of a specific 44 would clear, and that population no longer exists to be measured. Nothing here should be read as either prediction having been confirmed or refuted.
The residual interrupted population against the 500ms line, with 276 rows withheld, is unmeasured. Measuring it is forward work and is deliberately not done under the current freeze; it is recorded here as the open question rather than left implied.
The wall-arm claim in the rung-drop section is likewise dated: "all 44 are
Cpu" was true of that run. The row's trigger is an observation precisely so it does not depend on that remaining true.— sent from cool-koi-235