diff --git a/.gitattributes b/.gitattributes index 7ebdcdbf87a..091465160e2 100644 --- a/.gitattributes +++ b/.gitattributes @@ -20,8 +20,8 @@ .gitignore merge=generated-artifact DESIGN.md merge=generated-artifact ROADMAP.md merge=generated-artifact -dag/gunbc/stage0_crate_layout_generated.dag merge=generated-artifact -dag/gunbc/stage0_crate_partition_generated.dag merge=generated-artifact +dag/gunbc/stage0/stage0_crate_layout_generated.dag merge=generated-artifact +dag/gunbc/stage0/stage0_crate_partition_generated.dag merge=generated-artifact docs/plans/algebraic-rewrite-optimization.md merge=generated-artifact docs/plans/axiom-syllogism-lens.md merge=generated-artifact docs/plans/bounded-input-cost-envelope-scheduling.md merge=generated-artifact diff --git a/.github/workflows/fleet-converge.yml b/.github/workflows/fleet-converge.yml index e7b1a0e0dbd..3d66ceef04c 100644 --- a/.github/workflows/fleet-converge.yml +++ b/.github/workflows/fleet-converge.yml @@ -185,7 +185,7 @@ jobs: id: plan run: | ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) - "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/fleet_converge_plan_cli.dag --function fleet_converge_plan_wet + "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/fleet/fleet_converge_plan_cli.dag --function fleet_converge_plan_wet if: github.event.inputs.mode == 'plan' timeout-minutes: 5 - name: Upload fleet converge plan artifact @@ -216,7 +216,7 @@ jobs: ACTUAL="$(cat /tmp/fleet-converge-plan/plan_content.hex)" if [ -z "${EXPECTED_HASH:-}" ] || [ "$EXPECTED_HASH" != "$ACTUAL" ]; then echo "::error::PlanArtifactHashMismatch expected=$EXPECTED_HASH actual=$ACTUAL" >&2; exit 1; fi ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) - "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/fleet_converge_plan_cli.dag --function fleet_converge_apply_wet + "$ROOT/target/release/gunbc" run --source-root "$ROOT/dag" --source-root "$ROOT/src/v2" --entry dag/gunbc/fleet/fleet_converge_plan_cli.dag --function fleet_converge_apply_wet env: EXPECTED_HASH: ${{ github.event.inputs.plan_artifact_hash }} if: github.event.inputs.mode == 'apply' diff --git a/.github/workflows/fleet-desired.yml b/.github/workflows/fleet-desired.yml index ce0bf964b1b..a953e1c18b9 100644 --- a/.github/workflows/fleet-desired.yml +++ b/.github/workflows/fleet-desired.yml @@ -52,7 +52,7 @@ jobs: - name: Decide whether the floor admits this revision run: | ROOT=$(git rev-parse --show-toplevel 2>/dev/null || pwd) - "$ROOT/target/release/gunbc" run --source-root dag --source-root src/v2 --entry dag/gunbc/fleet_desired_admission.dag --function admit_fleet_desired_from_floor_event_wet + "$ROOT/target/release/gunbc" run --source-root dag --source-root src/v2 --entry dag/gunbc/fleet/fleet_desired_admission.dag --function admit_fleet_desired_from_floor_event_wet - name: Execute the authorized fleet-desired advance run: | set -eu diff --git a/DESIGN.md b/DESIGN.md index 39e0279e3c0..d5edc46ec83 100644 --- a/DESIGN.md +++ b/DESIGN.md @@ -149,7 +149,7 @@ hollow alias (minimality ≠ grounding) · state-space conflation (an `Option`/` - `cargo test --workspace` · `cargo clippy --all-targets -- -D warnings` · `cargo fmt --all --check` - one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow` -- explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo_local_git_config.dag --function converge` +- explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge` - CI — **RUNG DROP, DECLARED (2026-08-15, the floor cut).** WHAT WAS HERE: one composed floor pass, `claim_executor` with a `--plan-entry` naming `src/v2/workflow/ci_floor_plan.dag`, a v2 scheduler deciding batches from `gunbc.ci_spec`, a compile-clean gate ordered ahead of everything else, per-PR discovery over `CiSpec.discovery_scan_dirs`, and a 4-hourly `affected-set-falsifier` cadence carrying the whole-tree cold controls. **ALL OF IT IS DELETED** — the workflows (`ci.yml`, `falsifier.yml`, `falsifier-alert.yml`), their `.dag` authorities, and ~30 witness modules. This paragraph previously recited that invocation in the present tense; it was false the moment the cut landed, and a knowingly-false recital in the canonical authority is premise contamination — every session reading it plans against a command that does not exist. WHAT RUNS NOW: one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once PER LANE — `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and `... --required-lane witnesses`, in TWO PARALLEL JOBS (the 2026-08-25 split described below; the invocation named `--required-floor` until the 2026-08-20 consolidation, also described below, and that flag still exists and still runs the fold alone, it is simply no longer what CI calls) — whose floor phase folds every discovered witness through one prepared subject via `v1_compiler.cli_run` `run_required_floor`, whose admission, cost-line and preparation-safety policy is owned by `v2.workflow.required_floor` (this clause named that module as the symbol home until 2026-08-26; the module is real and the symbol does not resolve there, which is exactly the §3 defect the `--required-cited-symbol` census would have refused before its 2026-08-23 drop). No plan entry, no plan function, no batch id, no worker role, no selection flag: the fold has no such concepts to configure — which PRESERVES the 2026-08-13 operator directive that no SELECTION shrinks the roster, by construction rather than by a flag someone must remember to set. **That directive is about selection, and an earlier revision of this clause stated it as `the whole discovered roster runs unshrunk`, which is false of the DISCOVERED roster and true only of the ROUTED one.** Measured on main run `32553487573` (`967b5bc1b92`, 2026-08-22T05:06Z): `offered=11812 routed=10439 declined_long=543 declined_live=830`. 1373 discovered sites — 11.6% — are declined by HOME POLICY before the fold sees them, so `planned` is the routed roster and never the discovered one. The floor's own line is honest about this (`every discovered site is exactly one of these`); only this document overclaimed, and the overclaim is the load-bearing kind, because a reader who takes `the whole discovered roster runs` literally will conclude that authoring a witness is sufficient for it to execute. It is not: a witness under a long or live home is discovered, counted, and never run. The decline mechanism is not a selection flag and the directive is not violated by it — the two are different questions, and conflating them is what made one true sentence and one false sentence read as the same claim. That directive's own carrier (`corpus_selection_off_note`) died with the floor; `gunbc.ci_spec` retains the history and now points here. **THE FOLD NOW EXECUTES, measured 2026-08-19.** Green on main, the latest measured `32553487573` (`967b5bc1b92`, 2026-08-22T05:06Z): `planned=10439 executed=10439 terminal=10439 passed=10132 known_red_held=206 failed=0 stale_quarantine=0 route_gap_held=101 over_cost_line_diagnostic=35`, ~30 min wall. The counts previously cited here were run `32515441229` of 2026-08-21 (`offered=11615 routed=10253 … passed=9946`) and had gone stale by 197 offered sites in under twelve hours; they are replaced rather than annotated, because two count sets in one clause is two accounts of one fact. That this clause has now been re-pointed twice in three days is itself the measurement: a transcribed receipt line is a *positional* citation of a run's output — §3's rule reaches it, since no edit here invalidates it and it rots anyway — so the standing question is now DECIDED (operator ruling, 2026-08-24): **name the instrument, never transcribe its output.** A measurement is cited by naming the producer that re-derives it — the run, the flag, the committed script — and never by copying its numbers into prose, exactly as §3 requires a citation to name a symbol rather than a line, and for the same reason: a transcribed number is unreachable from the thing that owns it, so it rots without anyone touching either end. The counters above are retained under that rule as a declared exception with their producing run named, because this clause's subject IS the rung drop and a drop is unreadable without the magnitude it dropped by; every other transcription in the corpus is debt. The ruling was priced, not preferred: the parallel measurement corpus it governs was BANKRUPTED the same day — `docs/probes/` deleted whole, 195 files and 50,601 lines, boards and captures and instruments alike, leaving NO `.sh` or `.py` anywhere in the repository outside `.githooks` — after a board asserting a compiler mechanism as a live defect was found to have merged EIGHT SECONDS after the commit that fixed it, and to have named the emitter carrier when the actual repair was two lines in the model. A lane had already selected that mechanism as its next work on the board's authority. **THE INSTRUMENTS WENT WITH THE PROSE, and the reason decides what the rule means (operator ruling, 2026-08-24): an ad-hoc `.sh` or `.py` in this repository is §6 UNMODELED REALIZATION — raw shell implementing semantics already expressible in `.dag` — so if a measurement is worth re-deriving it is worth an entry point, and if it is not worth an entry point it is not an instrument but a one-off.** This was ruled against a live objection, recorded because the objection was correct on its own facts and still lost: a peer had re-run `curated_cargo_probe_one.sh` that same hour to re-derive the emission board's headline from source, so the scripts had real consumers — LANES, which a census of `.dag` consumers cannot see, and which is why an earlier revision of this clause reported them as dead. The ruling does not deny that consumer; it denies that a stray script is the right carrier for it. So `name the instrument` names a `.dag` entry point, and the rule needs no exception for a referent it deleted: what is deleted is everything that cannot be re-derived from the tree, and what re-derives it is modeled or it does not exist. That is the §2 cost of a second representation with no authority, arriving faster than it can be authored, and it is why a measurement document is presumed redundant rather than merely stale. WHAT THIS DOES NOT CLAIM: the cut leaves a named residue it does not repair — gitignore un-ignore rows for deleted paths, prose notes across ~20 modules citing them, and the witnesses above, all still green over dead names. That residue is the next cut, not a gap this one closed. **`executed` answers a narrower question than every reader asks of it: it counts a witness reaching the fold, not its assertion running.** A witness whose subject is a subprocess exit status is planned, discovered, and counted `executed` while it is REFUSED BY CONSTRUCTION at the hermetic boundary — `run_required_floor`'s hermetic envelope rejects the host effect via `shell.Test.IsExecutable` before the subprocess is reached, in about a millisecond, which also rules out a budget refusal on timing. This is CORRECT, not a gap: mocking that refusal to let such a witness run would pass it against a fabricated exit status, the exact fabricated-plausible-output failure the witness exists to catch. It is a boundary of what the hermetic floor can cover, named here beside the counters rather than left for a reader to rediscover. This clause previously read that no witness had executed and that the fold refused during preparation; that was true when written and is now false, and it is corrected in place rather than left standing until the rest of the paragraph can be rewritten — because a knowingly-false recital is premise contamination whichever direction it points, and this one had already cost real work: a session measuring the TestClaim orphan population read it, concluded the floor had never run, and raised a sequencing question about roster growth that does not exist. The rung drop below is unaffected: the fold running green establishes that the replacement executes, not that the re-add queue has closed. WHAT IS UNGUARDED IN THE MEANTIME, named rather than left to be rediscovered (the generated-artifact drift gates were on this list until the `generated-artifact` phase described below took them off it): heal, the seven effect gates, the fmt gate, merge-admission stamping, the falsifier cadence, and the per-witness eval deadline that `gunbc_ci_fast_lane_witness_eval_budget` used to arm (`gunbc.witness_row_cost` `gunbc_ci_fast_lane_rule_note` carries that one's own drop). Each is a separate re-add, each re-derived from its own first principles under its own operator agreement rather than restored from the deleted machinery. RESTORATION TRIGGER: this paragraph is rewritten as an ordinary present-tense description — not amended, rewritten in one pass — when the re-add queue closes. Until then it describes a rung drop, and describing the replacement as finished would be the inflation §4b names as worse than sitting low. **WHAT SURVIVES UNTOUCHED, enumerated rather than swept away with the bullet** — this paragraph replaced a longer one, and a prose row is deleted for one reason and takes everything in it unless its contents are enumerated first (the same rule that governs deleting a witness file whole): the compile-clean scope authority `tools.dag_compile_clean_scope` and its import-closure selection (`entry_file_touched_via_import_closure`) are live and unmodified by the cut — but **live is not reachable, and an earlier revision of this clause said only the first**. It read that what is gone is the CI *job* that invoked them and not the authority; both halves are true and together they license a false inference, because SURVIVING A CUT AND BEING CALLABLE ARE DIFFERENT PROPERTIES and only the first was checked. Measured 2026-08-20: `entry_file_touched_via_import_closure` and `compile_clean_scope_plan_for_ci` are private `fn`s with ZERO references anywhere under `src/v1/stage0/src/bin`, no CLI flag reaches them, and the only `pub` surfaces into that chain — `witness_layer_roots_compile_clean_check` / `_emit_check` — return `Bool`, so they answer *is it clean* and can never answer *which entries would be selected*. A reader planning against the old sentence would budget an afternoon and find no caller; that is premise contamination of the same class this paragraph already corrects itself for twice. The authority survives and the capability does not, until something exposes a counting entry point; the `regen_input_sources` import closure survives and is now read by `v1_compiler.required_regen_host` — but the `regen_stage0` binary that consumed it, and the `RegenVerifyGate` / `SelfHostStalenessGate` pair that invoked it, are DELETED at the root (the regen cut), so the self-host fixed point is answered by `claim_executor --required-regen-fixed-point` and by nothing else. **THAT FLAG IS INVOKED AGAIN AS OF 2026-08-20**, so this is one re-add off the queue below rather than a standing gap. It was re-added as two `witnesses.yml` steps ordered ahead of the floor and CONSOLIDATED the same day (operator directive: the phases belong `within the witnesses step and within the gunbc binary, not at a github actions job level`) into ONE step running the phases in ONE process. **THAT 2026-08-20 DIRECTIVE IS NOW PARTLY SUPERSEDED, BY THE SAME OPERATOR, ON 2026-08-25** — `we can add it as a parallel job in github actions - we can do the same for regen now, we have more runners` / `basically i would put regen + v2 full compile in one job, and witnesses into another one`. The stated reason is a change in supply, not a change of mind about the earlier argument: the phases are mutually independent, so composing them into one process made the required check's wall clock a SUM of things that could have been a MAX, and more runners make the MAX purchasable. **THE DIRECTIVE HAS TWO HALVES AND ONLY ONE IS SUPERSEDED, which is why this clause states both rather than replacing one ruling with another.** SURVIVES — *within the gunbc binary*: the phases still live in `claim_executor`, each job makes ONE invocation and names a LANE, and no step's precondition reads another phase's verdict. The step-ladder defect the consolidation fixed (an `if:` naming a sibling step, silently conjoined with GitHub's implicit `success()`, so a regen red disarmed the whole floor) cannot return, because no step's condition can reach another phase's outcome. SUPERSEDED — *not at a github actions job level*: PARALLELISM IS NOT EXPRESSIBLE IN THE BINARY. Two phases running concurrently means two runners, two checkouts and two toolchains, and one process on one runner can thread but cannot acquire a second machine — nor would we want it to, at the floor's measured ~9.4 GiB peak. So the lane boundary is a job boundary of necessity, and what the directive was protecting against — SEQUENCING and PRECONDITIONS leaking into YAML — is exactly what does not cross it: the two jobs carry no `needs` edge and no condition on each other, which is the whole content of running them in parallel. So the invocation named at the top of this paragraph is superseded three times over and is now, exactly: TWO LANE JOBS, `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` (regen's first-generation comparison, the v2-emission compile, the emitted-closure cargo phase and the partition-crate boundary) and the same command with `--required-lane witnesses` (the `.dag` parse sweep and the witness floor fold), plus a THIRD job that gates on both. **THAT THIRD JOB IS NOT DECORATION AND THE FIRST CUT OF THE SPLIT DID NOT HAVE IT, which is the more useful half of this entry.** A GitHub required status check is produced by the JOB, not by the workflow, and the repository's `passing CI` ruleset is active, carries NO bypass actors, and names exactly ONE required context: `witnesses`. So splitting the phases into a second job made regen and v2-emission NON-BLOCKING -- the required check would have gone green over a regen drift or a v2 emission break and the PR would have been mergeable. That is fail-open (§5), and strictly worse than the serial run it replaced, because the serial job carried every phase into the one context that gates. THE REPAIR IS AN AGGREGATION JOB RATHER THAN A RULESET EDIT: the floor lane is renamed `floor`, and the name `witnesses` moves to a job that `needs` both lanes and whose only step reads both results and exits nonzero unless both are `success`. **THE CONDITION THAT MAKES THAT JOB RUN IS AT THE JOB LEVEL, AND THE FIRST CUT OF THE AGGREGATOR PUT IT ONLY ON THE STEP** -- the same fail-open committed one level in, caught by review 55795 and independently by a peer session within minutes of each other. `needs` carries an implicit job-level condition: a job that declares `needs` and no `if` is SKIPPED when a needed job fails, a skipped job never reaches its steps, and a step-level `always()` cannot rescue a job that never started. The job therefore declares `always()`, and that is the ONE place in the emission that departs from the file's `!cancelled()` house guard, stated here because a reader who knows the convention will otherwise correct it back and reopen the hole. Every other guard decides whether a STEP runs inside a job that is already running; this one decides WHETHER THE REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run leaves it skipped rather than answered. That turns the outcome on a question about GitHub nobody here has executed -- does a skipped or cancelled required check block a merge -- and the right response is not to measure it but to make the answer not matter: under `always()` the job always runs, always reads both results, and always reports on its own terms, so SKIPPED disappears from the required context. Construction over validation (§5), at the cost that a lawfully superseded run now reports this context red rather than cancelled, which is the correct reading rather than a regression. The two lane jobs still carry no `needs` edge on each other and still start together; only the aggregator waits. A ruleset edit would have worked too and was rejected on a boundary this document already records: the ruleset is not a `.dag` fact, so landing a change whose safety depends on someone editing a setting afterwards is a coverage gap with a promise attached and a real unguarded window. **THAT BOUNDARY MOVED, AND THE DECISION IT SUPPORTED DOES NOT.** `gunbc.repo_ruleset` now declares the desired ruleset -- enforcement, target, ref-name condition, the three rules, and the ONE required context, imported from `gunbc.witness_floor_workflow` `witness_floor_workflow_job_id` rather than spelled a second time -- observes the live one through `extdeps.github.rulesets`, reconciles the context roster through `gunbc.membership_reconcile`, applies drift with the whole-ruleset PUT, and READS BACK, claiming convergence only from the second observation and never from the apply's own 200. So the sentence in this bullet stating what the ruleset requires is no longer the only place that fact lives on our side of the boundary: `converge` actuates it and `verify` refuses on any divergence, with a typed reason per way it can diverge. WHAT DID NOT CHANGE, and why the aggregation job stays: convergence is an ACTUATION WITH A READ-BACK, not a wall. Nothing in this repository can constrain what GitHub admits to main, so an in-repo authority still cannot make a required context exist at the moment a merge is attempted -- it can only declare, apply and detect. The first cut's window argument therefore stands on its own terms; what is closed is the invisibility, not the boundary. WHAT IS NOT CLAIMED: NEITHER ENTRY POINT IS ENROLLED IN CI. `verify` is a route somebody runs, and until a required phase invokes it the class sits at *mitigatable* -- a drift is now detectable rather than detected, which is a real climb from unobservable and is not the same as a gate. Its next-rung trigger is that enrolment, which is a separate change under its own operator agreement. Found in review of gunbc#9203, against the live ruleset rather than against the workflow -- which is the only place the fact is visible, since nothing in the emitted YAML says which of its jobs gates. The partition is total by construction — `RequiredCiPhase::lane` is an exhaustive match, so a phase belonging to no job fails to compile rather than going silently unmeasured — and the lane is the ONLY thing the transport names: which phases a lane owns is decided in the binary, never in the YAML. **THE v2-EMISSION PHASE'S SUBJECT WIDENED IN THE SAME CHANGE**, from `dag/std/abi.dag` (the smallest entry in the tree) to `src/v2/compiler/00_compile.dag` (the v2 pipeline root, the widest closure one entry names). The row is `gunbc.ci_layer_roots` `required_v2_emission_entries` and it remains a cost decision rather than a Rust edit; what changed is the denominator, since the build lane's cost is now free up to the floor's duration rather than added to it. **WHAT THE SPLIT DOES NOT DO:** it restores nothing else from the deleted floor machinery — every item on the unguarded list above is still its own re-add under its own operator agreement — and it lands NO ratchet over the v2 compile's advisory-diagnostic population. That population is real and is the natural next subject, but a merge-blocking count pinned to a number measured on the current tree is exactly the oracle §5 forbids; an identity-grain monotone debt contract is a separate construction and is not claimed here. **THE PARSE PHASE STOPPED BEING src/v1-ONLY, 2026-08-23**, and it is stated here because the previous revision named the phase by the one root it walked. It now sweeps `src/v1`, `dag` and `src/v2` from one roster (`v1_compiler.cli_run` `DAG_PARSE_SWEEP_ROOTS`), shared with the standalone bin, and it admits source annotations per file rather than parsing alone -- `tokenize` routes `//` into the annotation channel and `parse` never decides grain, so the old walk returned clean for a file carrying an in-body annotation and the §4c refusal surfaced only at the floor's strict PREPARATION, where no witness executes at all. That is not a widening of the floor's source roots, which `gunbc.ci_layer_roots` `v1_dead_witness_tree_triage_receipt_remainder` rules out on NAME RESOLUTION grounds: this walk resolves nothing across files, so that objection cannot reach it. **THE PHASE ROSTER WAS CUT TO THREE BY OPERATOR RULING, 2026-08-21, WAS FOUR AGAIN AS OF #9035, AND IS FIVE AS OF THE PARTITION-CRATE PHASE, AND IS SIX AS OF THE EMIT-COMPILE PHASE.** The count is stated in the present tense here and it has now been wrong in BOTH directions, which is the reason it is written as a measurement rather than as a recollection: an earlier revision said four while enumerating a determinism pass no required run performed, that was corrected to three, and the three then went stale when #9035 enrolled a v2-emission phase that compiles one v2 entry — landed precisely because an emission break reached main and no gate could see it. The instrument is the required mode itself, which prints its own roster before any phase runs -- one `phase ` line per phase the lane owns and one `ROUTED to lane ` line per phase it does not, then `lane= phases_run=`. Read the roster from that announcement rather than from this sentence: the count moved twice in five days, and a transcribed roster size is exactly the positional citation the ruling above forbids. The fifth phase is `partition-crates`, in the build lane, which compares the derived stage0 partition's committed `lib.rs` and `Cargo.toml` against what `v1.compiler.stage0_crates` renders from the authority -- landed because those seven crates are workspace members nothing in CI builds, so a broken one sat on main while every required lane stayed green. **THAT COUNT IS NOW A PROPERTY OF THE ROSTER AND NOT OF A RUN**, because the 2026-08-25 split partitions the four across two jobs: a lane's own summary line reports `lane= phases_run=`, and each job additionally prints a `ROUTED to lane ` line for every phase it does not own, so one job's log still names the whole roster and where the rest is being measured. Reading a single job's `phases_run` as the roster size is the error that line exists to prevent. **A SIXTH PHASE, `generated-artifact`, IS THE FIRST ITEM TAKEN OFF THE UNGUARDED LIST ABOVE RATHER THAN A NEW SUBJECT.** It adjudicates every member of `gunbc.generated_artifact` `committed_generated_artifacts` against what its own authority generates, through the pure per-path projection `gunbc.generated_artifact_emit` `generated_artifact_body_for_path`, hosted by `v1_compiler.cli_run` `run_generated_artifact_boundary` in the build lane. THE PRODUCER WAS NEVER MISSING AND THE CALLER WAS, which is why this is a re-add and not a construction: `main_wet` on `dag/tools/generated_artifact_gate.dag` has always written these files and the projection has always been able to say what each path ought to hold, but from the floor cut until this phase the only route that ASKED it was `claim_executor`'s behavioural-receipt census, which asks only about paths of the form `src/v1/stage0/src/` because its subject is emitted Rust mirrors. So `DESIGN.md` and `ROADMAP.md` -- projections of `gunbc.design_document` and `gunbc.roadmap_authority` -- were computed by nothing and compared by nothing, and were maintained BY HAND in lockstep with their authorities. That is not a hypothetical: gunbc#9392 found the accumulated result the only way an unguarded artifact is ever found, by accident while doing something else, 2198 characters into the drift, and this document's own §4b(3) clause was among the text standing in the artifact with no authority behind it. **AND THE FIRST THING IT FOUND WAS NOT DRIFT, WHICH IS THE REUSABLE HALF.** Two of its four opening reds were ABSENT rather than drifted, and one of those markdown files had been DELETED ON PURPOSE by a295e17415, whose entire subject is the ruling that the .dag carrier is the authority. Regenerating it would have performed exactly what that commit refused, and the gate would then have gone green over the resurrection -- enforcing, permanently, the reverse of a decision already taken. THE GENERAL SHAPE: **a drift gate makes whatever it adjudicates BINDING**, so an absence that was inert before the gate becomes a line-stop after it, and the cheapest way to move the line is to regenerate. A dormant registry mistake is thereby converted into a standing obligation to recreate deleted files, silently, because the green looks identical either way. The stale half is the REGISTRY ROW and not the missing file, so the repair runs the other way: `gunbc.plan` `PlanProjection` makes a plan declare whether its markdown is a committed artifact at all, `PlanIsAuthorityOnly` carries the ruling that removed the projection, and the plan stays rostered, generated and refusable -- only whether its bytes are expected on disk changes. The rule for the next gate: **before a new adjudicator's first red is closed by producing the thing it says is missing, establish that the thing was ever supposed to exist.** WHAT THE PHASE DOES NOT CLAIM: it is READ-ONLY by construction -- there is no write path in it and no flag that opens one, because a gate that can also write its own subject is a gate whose green proves nothing -- and it restores nothing else from the deleted machinery; heal, the seven effect gates, the fmt gate, merge-admission stamping and the falsifier cadence remain their own re-adds. Its roster is ASKED of the authority, so an artifact added to `generated_artifact_registry` is enrolled with no edit to the host, and a rostered member that reaches NO verdict is counted and reported separately from a drifted one and stops the line on its own -- `0 drifted` over a population nothing asked about is the execution-provenance loss this document names, and the two counts are what keep it unrepresentable. **THAT COUNT IS NOW A PROPERTY OF THE ROSTER AND NOT OF A RUN**, because the 2026-08-25 split partitions the four across two jobs: a lane's own summary line reports `lane= phases_run=`, and each job additionally prints a `ROUTED to lane ` line for every phase it does not own, so one job's log still names the whole roster and where the rest is being measured. Reading a single job's `phases_run` as the roster size is the error that line exists to prevent. The five phases the 2026-08-21 ruling deleted stay deleted and are enumerated below; neither #9035 nor the partition-crate phase restored any of them, each added a new one, so both are roster ADDITIONS and not a reversal of that ruling. Five phases were deleted from the mode: merge-admission-capture, the regen determinism (fixed-point) pass and its in-memory pass-1 digest handoff, the behavioral receipt's controlled-fixture selftest, the behavioral receipt against the authorities a diff changed, and merge-admission-stamp. They were deleted rather than left reporting SKIPPED, because a phase whose only reachable state is a non-verdict has a deficit frequency of zero by construction and still reads as coverage on the ledger (§5, the absorbing fallback). The capabilities survive at their own entry points — `--required-regen-fixed-point`, `//gunbc/instruments:behavioral-receipt-plan`, `//gunbc/instruments:behavioral-receipt-selftest`, `//gunbc/instruments:behavioral-receipt-census` — none of which any workflow invokes; what ended is their enrolment in the required run, and the three measurements they carried (regen determinism, behavioural equivalence of a changed authority against its mirror, and the receipt's own discriminating arms) are simply no longer taken. That is a declared scope narrowing, and it returns merge-admission stamping to the unguarded list above rather than removing it from it. The remaining three phases are independent — the one real data dependency left with the phase that consumed it — so every phase runs even after an earlier failure and the run reports the complete ledger instead of letting the first defect hide the rest. The line still stops on any failed phase. It is recorded here with what made the gap real, because the steps were enrolled, STRIPPED, and re-enrolled inside twelve hours and a reader who finds only the enrolment will re-derive the strip. The strip was correct when made: the admission test is whether every red is closable by the author who caused it at the moment they caused it, and it was not -- the comparator normalized BOTH sides through rustfmt while writing the single-pass form, so after any candidate install the comparison was `normalize(normalize(emitted))` against `normalize(emitted)`, an identity only if rustfmt is idempotent. It is not, so the gate refused a tree byte-identical to its own artifact, permanently, and its only reachable green was the hand-edited mirror the gate exists to refuse -- a gate whose sole closing move is the forbidden action is not strict, it launders. Repairing it by raw-comparing the single-pass bytes then put it in direct contradiction with `cargo fmt --all --check`, which re-formats what is committed and so demands the NEXT pass: two gates consuming different passes of one artifact, each breaking the other. The resolution is that the emitted artifact is now written as a FIXED POINT of the formatter (bounded, exceeding the bound is a typed refusal), which makes the contradiction unrepresentable rather than detected and makes `cargo fmt` a no-op on it by definition -- the §5 construction move, and the general lesson is that any artifact with two consumers that normalize it must be stored in the normalizer's fixed point or the two consumers cannot both be satisfied. This clause previously read that the fixed point and its closure both survived with only their job removed; that was true when written and the regen cut falsified its first half, so it is rewritten here rather than annotated — a second sentence beside it would be two accounts of one fact; and parse remains grammar-owned — `ingest_yaml_source` (`dag/extdeps/languages/yaml/ingest.dag`), no shell or host parser — which was never a floor fact at all and is restated here so that dropping the bullet does not drop it. **TWO OPERATOR RULINGS ALSO LIVED IN THE REPLACED BULLET AND STILL HOLD**, restated because a ruling about what CI does *not* do is invisible once the paragraph describing CI is rewritten, and nothing in the new mechanism would contradict it loudly: the Rust test suite was removed from CI 2026-07-11 (operator ruling, recorded at `gunbc.commit_workflow` `commit_gate_rust_suite_removed_disposition`) and runs locally only; and clippy was removed from CI 2026-07-08, because a crate-wide `#![allow(clippy::all)]` made it zero-signal over ~44 minutes per run, leaving it a local dev check. Neither is reinstated by the replacement, and neither is the floor cut's to reverse. - **THE MEASUREMENT BANKRUPTCY DELETED A CAPABILITY, NOT ONLY ARTIFACTS, AND THIS ROW IS THAT DECLARATION (2026-08-24).** The bankruptcy above removed `docs/probes/` whole. Deleting the boards removes TRANSCRIPTIONS, which is the point; deleting the instruments removes a ROUTE, which is a different fact and is the one §4b(3) obliges a cut to declare. WHAT IS GONE: the only executable route to a self-host emission board measurement. PREVIOUS STATE — any lane could re-derive a per-entry board by running the committed probe script, last exercised 2026-08-24 against the then-current main, and that reading is what answered the operator when they asked what the emission trajectory was doing. TEMPORARY STATE — no route exists; the emission trajectory is not measurable from the tree, and a board figure quoted from here on names nothing that can produce it. BOUNDED POPULATION: one capability, the per-entry emission board. RESTORATION TRIGGER: a `.dag` entry point that emits, assembles and compiles one entry and returns the coded-diagnostic population, cited by name wherever a board figure is quoted — at which point the same figures become legitimate again unchanged, because the rule forbids transcribing output INSTEAD OF naming an instrument, and the defect today is that there is no instrument to name. **WHY THIS ROW EXISTS AT ALL, and it is the same reason the regen row beneath it does:** no dependent could refuse. The corpus contains nothing that breaks when the board becomes unmeasurable, because the consumers are LANES rather than modules — the identical blind spot that made a `.dag`-consumer census report the instruments as dead a few hours before this cut. So delete-first's census, which is normally the thing that surfaces a load-bearing deletion loudly, is structurally silent here, and a declared row is the only mechanism left. **THE TRIGGER HAS FIRED, AND THE ROW STAYS RATHER THAN RETIRING ON ITS AUTHOR'S SAY-SO.** The instrument is `tools.emission_entry_instrument` `measure_entry_emission`, invoked as `gunbc run --source-root dag --source-root src/v2 --entry dag/tools/emission_entry_instrument.dag --function measure --arg entry= --arg report=`. It runs the same spine the deleted probe script ran — emit one entry's closure, assemble it with `cssl_assemble`, build the assembled crate under cargo's JSON message format — and returns a TYPED measurement rather than a row of text: the emit-stage population from `gunbc.emit_diagnostic_observation` and the rustc coded-diagnostic population from `extdeps.cargo_diagnostic`, each member carrying its own identity and location, so two runs can be JOINED rather than only differenced. **WHAT THE CARRIER FIXES THAT THE SCRIPT DID NOT:** `EmissionMeasurement` has no spelling in which a stage that never ran renders as a stage that ran and found nothing — an unreached stage is its own variant naming the stage — and the emit decode REFUSES when the population it recovered disagrees with the compiler's own declared total, so an unrecognised diagnostic shape stops the line instead of quietly shrinking the answer. That is the execution-provenance-loss row applied to the instrument that most needed it. **WHAT IS NOT CLAIMED.** It is a measurement route and NOT a gate: no workflow invokes it, no phase enrols it, and its exit status reports whether the INSTRUMENT completed, never whether the subject was clean. The whole-corpus route is still refused by `gunbc.whole_corpus_compile_admission` and this does not change that; it is the per-entry route that module's own scope note says fits. Every other clause of the bankruptcy above stands unchanged, including that a figure copied into prose is debt whether or not a producer exists for it. - **THE REGEN CUT DELETED A PRODUCER ALONG WITH ITS BINARY, DECLARED NOTHING, AND THIS ROW IS THAT DECLARATION (2026-08-20).** It sits beside the CI entry above rather than inside it, because the two are different facts on different clocks — that paragraph narrates what the floor and regen cuts removed, this row declares one capability the regen cut removed in silence — and because a declaration wedged into the repository's most-edited paragraph collides with every unrelated edit to it (three merge conflicts in two hours, each one re-resolving prose neither side had touched). The regen cut re-derived the deleted binary's VERIFIER half — `claim_executor --required-regen`, which compares the committed stage0 mirror against a fresh emit — and did not re-derive its PRODUCER half: writing the emitted tree to disk unconditionally, whatever the comparison then says about it. `run_required_regen` did write a candidate tree, but only on the path where the emitted and committed populations already agreed; every refusal arm returned ahead of the write. The one population asymmetry an author can actually cause is adding a module to the v1 seed closure — its mirror is emitted-not-committed by construction on the first commit that introduces it — so from the cut until this entry, that change refused while naming a file no sanctioned route in the repository produced, and its only reachable green was a hand-authored mirror. That is the same laundering the fixed-point repair above closed one gate over, arrived at from the other direction: there, the gate's only closing move was forbidden; here, the gate's only closing move did not exist. WHAT THE RUNG DROP IS, stated at the honest grain: the class is not a compiler guarantee that fell a rung, it is an OPERATION that lost its only route, so it sat outside the ladder entirely — nothing to mitigate, because nothing could be attempted. Naming it as a declared drop rather than a defect is the point of the entry: the regen cut owed one under §4b(3) and filed none, and a capability deleted in silence is exactly what §3's delete-first doctrine says the census is supposed to surface loudly. It did not surface because no dependent could refuse — the author who needed the producer was outside the tree. THE RESTORATION, and its rung: production now precedes adjudication. `v2.workflow.required_regen` `required_regen_run` is the authority, and it holds the ordering by construction rather than by check — every arm that reports a verdict carries the `CandidateTree` the verdict was computed against, so refused-with-no-tree has no spelling once emit succeeded, and the one tree-less arm is reachable only where emit produced nothing at all (*structurally guaranteed*, §4b). The host `v1_compiler.required_regen_host` `run_required_regen` mirrors that ordering by hand and is therefore only *mitigatable*; its next-rung trigger is the host being derived from the carrier rather than written beside it. The gate did not weaken: it refuses the same populations with the same typed causes, and the refusal now names the directory holding the first mirror the author must install. diff --git a/ROADMAP.md b/ROADMAP.md index 1fa67ac4699..bb84ca535e9 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -1,6 +1,6 @@ # gunbc — Roadmap -`DESIGN.md` is the authority for why. This file projects the remaining committed deliverables and their dependency order from `dag/gunbc/roadmap_authority.dag`. The authority declares every node and records a typed acceptance receipt per accepted node; the active set is derived as declared minus validly accepted, so acceptance never deletes a row and this projection stays active-only. It carries no mutable pull-request, CI, session, or attempt state. Implementation evidence does not equal acceptance; a merged but unaccepted deliverable remains active. +`DESIGN.md` is the authority for why. This file projects the remaining committed deliverables and their dependency order from `dag/gunbc/roadmap/roadmap_authority.dag`. The authority declares every node and records a typed acceptance receipt per accepted node; the active set is derived as declared minus validly accepted, so acceptance never deletes a row and this projection stays active-only. It carries no mutable pull-request, CI, session, or attempt state. Implementation evidence does not equal acceptance; a merged but unaccepted deliverable remains active. Indented rows depend on the row above them. Some deliverables have additional cross-chain prerequisites represented by `RoadmapEdge` in the authority. Every active row requires explicit manual acceptance. Automatic admission from this refreshed authority is future work; the existing manual dispatch path remains live and outside this model slice. Ready may schedule only after every dependency is accepted; it never overrides a dependency or refusal. Parked plans remain reachable through the documentation graph but are not active roadmap rows. @@ -10,7 +10,7 @@ Parked context (non-dispatchable): [compiler algorithm survey](docs/plans/compil The graph has sixteen lanes: SCM compatibility · namespace · P-derive · observation · placement · compute · CI cost · CI control · generated artefacts · v1 exit (four finish lines: compiler fixed point, interpreter deleted, products v1-free, zero hand-maintained Rust) · shell · roadmap runtime · fleet/hygiene · judgment · hermetic toolchain · compiler-guarantee (the DESIGN §4b ladder climbs; rung STATE lives in the guarantee claims carrier and is emitted, never restated in tickets — [gap analysis](docs/plans/compiler-guarantee-recovery-gap-analysis.md)). The three independent SCM R0 models, the separate P−1 evidence carrier, R1 compatibility-shape extraction, and P0 user-contract/landing spine are accepted; the operator-authored P1 proof-kernel node is active and fail-closed pending its first discriminating closing validation, while P2 and later product lanes remain parked. The toolchain pin model is an independent root. The P-derive receipt feeds the emitter fixed point, so the v1 chain nests under it. Compute owns the one contract everything else asks for work through — an exact subject in, a typed ending and the outputs it promised back out — and it sits ABOVE CI rather than inside it, because owning CI, converging the fleet, serving models and eventually judging changes are four consumers of one fabric, not four execution systems. It grounds on the signed realization spine rather than minting a second scheduler beside it. CI control owns who starts, queues and hands out required work and how its result reaches GitHub; CI cost owns how much computation that work performs. Fleet owns whether a merge to main becomes applied machine state and whether that question has one answer. Node fields define boundary, first slice, RED control, exclusions, owner, and handback. -**Focused view — the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main.** 106 active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap_authority.dag` to restore the full page. 6 of the rows below are NOT lane deliverables — they are prerequisites pulled in from other lanes because lane work is blocked on them: observation-scoped-run-consumer, observation-scoped-run-seed-growth-justification, observation-scoped-run-seed-growth-justification-closing-contract, shell-gate-migration, shell-effectplan-to-bash, shell-typed-invocation. Hidden lanes remain readable through their carriers: [docs/plans/dag-scm-design.md](docs/plans/dag-scm-design.md) · [docs/plans/namespace-unique-on-chain-operational-plan.md](docs/plans/namespace-unique-on-chain-operational-plan.md) · [docs/plans/v2-self-hosting.md](docs/plans/v2-self-hosting.md) · [src/v2/compiler/05_emit.dag](src/v2/compiler/05_emit.dag) · [docs/plans/progress-observation-design.md](docs/plans/progress-observation-design.md) · [src/v2/compiler/self_host/candidate_generation.dag](src/v2/compiler/self_host/candidate_generation.dag) · [src/v2/compiler/self_host/wet_receipt_enrollment.dag](src/v2/compiler/self_host/wet_receipt_enrollment.dag) · [src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag](src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag) · [dag/gunbc/v1_deletion_plan.dag](dag/gunbc/v1_deletion_plan.dag) · [dag/gunbc/stage0_rust_host_observation.dag](dag/gunbc/stage0_rust_host_observation.dag) · [docs/plans/witness-realization-plan.md](docs/plans/witness-realization-plan.md) · [src/v1/05_emit_rust.dag](src/v1/05_emit_rust.dag) · [dag/gunbc/v1_interpreter_primitive_surface.dag](dag/gunbc/v1_interpreter_primitive_surface.dag) · [docs/plans/shell-to-dag-residual-census-and-arc-completion.md](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) · [docs/plans/roadmap-workspace-ux-plan.md](docs/plans/roadmap-workspace-ux-plan.md) · [docs/plans/provider-control-interface-audit.md](docs/plans/provider-control-interface-audit.md) · [docs/plans/enforcement-intent-design.md](docs/plans/enforcement-intent-design.md) · [docs/plans/hermetic-tool-provisioning-design.md](docs/plans/hermetic-tool-provisioning-design.md) · [dag/gunbc/capability_binding.dag](dag/gunbc/capability_binding.dag) · [dag/gunbc/roadmap_component.dag](dag/gunbc/roadmap_component.dag) · [dag/gunbc/design_document.dag](dag/gunbc/design_document.dag) · [docs/plans/compiler-guarantee-recovery-gap-analysis.md](docs/plans/compiler-guarantee-recovery-gap-analysis.md) · [docs/plans/cardinality-refinement.md](docs/plans/cardinality-refinement.md). +**Focused view — the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main.** 106 active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap/roadmap_authority.dag` to restore the full page. 6 of the rows below are NOT lane deliverables — they are prerequisites pulled in from other lanes because lane work is blocked on them: observation-scoped-run-consumer, observation-scoped-run-seed-growth-justification, observation-scoped-run-seed-growth-justification-closing-contract, shell-gate-migration, shell-effectplan-to-bash, shell-typed-invocation. Hidden lanes remain readable through their carriers: [docs/plans/dag-scm-design.md](docs/plans/dag-scm-design.md) · [docs/plans/namespace-unique-on-chain-operational-plan.md](docs/plans/namespace-unique-on-chain-operational-plan.md) · [docs/plans/v2-self-hosting.md](docs/plans/v2-self-hosting.md) · [src/v2/compiler/05_emit.dag](src/v2/compiler/05_emit.dag) · [docs/plans/progress-observation-design.md](docs/plans/progress-observation-design.md) · [src/v2/compiler/self_host/candidate_generation.dag](src/v2/compiler/self_host/candidate_generation.dag) · [src/v2/compiler/self_host/wet_receipt_enrollment.dag](src/v2/compiler/self_host/wet_receipt_enrollment.dag) · [src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag](src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag) · [dag/gunbc/v1/v1_deletion_plan.dag](dag/gunbc/v1/v1_deletion_plan.dag) · [dag/gunbc/stage0/stage0_rust_host_observation.dag](dag/gunbc/stage0/stage0_rust_host_observation.dag) · [docs/plans/witness-realization-plan.md](docs/plans/witness-realization-plan.md) · [src/v1/05_emit_rust.dag](src/v1/05_emit_rust.dag) · [dag/gunbc/v1/v1_interpreter_primitive_surface.dag](dag/gunbc/v1/v1_interpreter_primitive_surface.dag) · [docs/plans/shell-to-dag-residual-census-and-arc-completion.md](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) · [docs/plans/roadmap-workspace-ux-plan.md](docs/plans/roadmap-workspace-ux-plan.md) · [docs/plans/provider-control-interface-audit.md](docs/plans/provider-control-interface-audit.md) · [docs/plans/enforcement-intent-design.md](docs/plans/enforcement-intent-design.md) · [docs/plans/hermetic-tool-provisioning-design.md](docs/plans/hermetic-tool-provisioning-design.md) · [dag/gunbc/capability_binding.dag](dag/gunbc/capability_binding.dag) · [dag/gunbc/roadmap/roadmap_component.dag](dag/gunbc/roadmap/roadmap_component.dag) · [dag/gunbc/design_document.dag](dag/gunbc/design_document.dag) · [docs/plans/compiler-guarantee-recovery-gap-analysis.md](docs/plans/compiler-guarantee-recovery-gap-analysis.md) · [docs/plans/cardinality-refinement.md](docs/plans/cardinality-refinement.md). - [ ] **Describe what a command should do, instead of writing shell text** — Callers say which operation and which arguments; nobody hands over an opaque string of shell as the instruction. Why: Shell syntax embedded in decision-making code cannot be checked before it runs, and cannot be reused anywhere else. [authority](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) - [ ] **Turn a described plan into shell through one translator** — One place turns a described plan into a shell script, preserving order, captured output, and failure behaviour. Why: Deletes the per-workflow shell writers and the scripts assembled by gluing strings together. [authority](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) diff --git a/dag/extdeps/realization/emit_on_demand_host.dag b/dag/extdeps/realization/emit_on_demand_host.dag index f1e634c5f74..c1ea86870e8 100644 --- a/dag/extdeps/realization/emit_on_demand_host.dag +++ b/dag/extdeps/realization/emit_on_demand_host.dag @@ -26,7 +26,7 @@ data emit_on_demand_host_note: String = "P3 host-transport helpers (witness-real data emit_on_demand_host_concurrent_same_key_note: String = "Concurrent same-key story for persistent workspaces: identical outer closure key, input-realization digest, AND resolved build-context identity share a workspace — benign-by-identity because those segments cover the exact materialized workspace files, build argv, resolved tools, constructed environment, and Cargo configuration that realize them. A changed emitter/dispatcher realization, compiler, admitted environment row, or Cargo configuration cannot share the ready marker even when its inferred-tree closure digest is unchanged. Concurrent cold builds of identical inputs may still race before .native_ready; no atomic claim exists in the seed HAND-RUST transport yet. Dissolve-on: the self-emitted transport adds flock/claim when witness-family concurrency requires it." -data emit_on_demand_host_seed_deferral_note: String = "Pure Bootstrap receipt for the bounded existing HAND-RUST boundary: no new Rust file or parallel key authority is admitted. This seed observation/apply arm is explicitly deferred to ROADMAP row 'Make native materialization the shared execution kernel' (docs/plans/witness-realization-plan.md P3/P6) and the concrete dag/gunbc/v1_deletion_plan.dag ^witness_realization_kernel deletion row. Delete it when the self-emitted transport consumes ResolvedBuildContext and the dispatcher-change, environment-change, and cold/warm agreement witnesses stay green with the Rust helpers removed." +data emit_on_demand_host_seed_deferral_note: String = "Pure Bootstrap receipt for the bounded existing HAND-RUST boundary: no new Rust file or parallel key authority is admitted. This seed observation/apply arm is explicitly deferred to ROADMAP row 'Make native materialization the shared execution kernel' (docs/plans/witness-realization-plan.md P3/P6) and the concrete dag/gunbc/v1/v1_deletion_plan.dag ^witness_realization_kernel deletion row. Delete it when the self-emitted transport consumes ResolvedBuildContext and the dispatcher-change, environment-change, and cold/warm agreement witnesses stay green with the Rust helpers removed." type ObservedToolIdentity { tool_name: NonEmptyStr diff --git a/dag/extdeps/transports/rest.dag b/dag/extdeps/transports/rest.dag index f327d6731c2..991022b7b0b 100644 --- a/dag/extdeps/transports/rest.dag +++ b/dag/extdeps/transports/rest.dag @@ -82,7 +82,7 @@ type RestAuthSensitiveIdentity = RestUnauthenticated | RestAuthenticated { scheme: NonEmptyStr, digest: Fnv1a64Structural } -data rest_authenticated_digest_witness_note: String = "AUTHENTICATED ARM: PIN WITHDRAWN 2026-08-11 (gunbc#8146) - HEADER CORRECTED, was EXECUTED PIN; REPLAY-PATH DEFERRAL TYPED (review 47041, gunbc#7648). RestAuthenticated.digest is Fnv1a64Structural and the seed mint rest_auth_identity_value produces it via atom_identity_hash over '\\0' - the SAME fnv1a64 primitive std.content_hash.content_hash_atom realizes, so an authored fixture reproduces the digest through the modeled surface (content_hash_atom(value: \"\\0\")); an earlier spelling hashed with the host DefaultHasher, a value from outside the family this carrier names, which no dag fixture could ever author. WITHDRAWN EVIDENCE (2026-08-11, gunbc#8146, review 51198) - was EXECUTED EVIDENCE: rest_authenticated_identity_matches_dag_constructed_value (src/v1/tests/src/cross_representation_equality_test.rs, DELETED by the v1 Rust test-suite cutover; the assertion lived only there). It had not executed since the suite went --no-run, so this row was already nominal rather than newly broken. The seed mint itself is untouched. DISSOLVE-ON: re-establish the identity assertion as a floor witness. It previously pins the seed mint ==-equal to the dag-authored identity - RED under a bare-text digest, RED under a non-fnv1a64 digest - plus a secret-inequality control. WHAT REMAINS DEFERRED, AND WHY, TYPED: a full replay-path authenticated witness (fixture matched against a seed-produced invocation through the service dispatch) additionally requires the invocation input_digest, whose per-param limbs content_hash_service_inputs still derives via the host value_hash - not reproducible from .dag - so authoring the matching fixture is blocked on that limb pipeline migrating to the fnv1a64 primitives; that migration also moves the recorded-fixture store keys, so it is its own lane, not a fixture edit here. RUNG, CORRECTED FOR CI ENROLLMENT (calm-badger-682, verified against .github/workflows/ci.yml and gunbc.ci_layer_roots witness_layer_roots): CORRECTED AGAIN 2026-08-11 (gunbc#8146, review 51205) - this paragraph described a CI arrangement that no longer exists, and described it BACKWARDS relative to the change that removed it. It read that CI's only contact with the crate was 'cargo check -p v1-compiler-tests --tests (compile gate; no test execution)'. The build job now runs 'cargo test -p v1-compiler-tests --release' - the retained kernel EXECUTES in required CI, --no-run is gone from both authorities (v2.workflow.ci_v1_compiler_tests_compile_gate_emit and gunbc.ci_workflow) and from the emitted ci.yml. Two separate facts, deliberately not fused: the crate now executes in CI, AND this particular pin is no longer in it, because the module carrying it was deleted by that same cutover. So the reason this note names no executing consumer is deletion, not the old compile-only gate. witness_layer_roots remains dag plus src/v2, so floor discovery still never reaches src/v1/tests; measured, the pin passes locally in 1.66s and reds nothing anywhere. DESIGN 4b defines mechanically preventable as a mechanism that reliably exposes AND blocks, with safety depending on it executing and staying enrolled - so the mint seam sits BELOW that rung, and calling it mechanically prevented is rung inflation, which 4b names as worse than sitting low because an inflated class never ranks for climbing. Deleting the seam guard would leave this control present, compiling, and mute. NOT NEW DEBT FROM THIS PR: content_hash_cross_family_eq_v1_seed_bridge_note cites the same unexecuted crate for the cross-family backstop, so the whole family of seed-bridge controls shares this gap and it is recorded here rather than fixed. The end-to-end authenticated replay path remains unexecuted and must not be reported above either. HAND-RUST RECEIPT (review 47065): the ROADMAP row 'Work through the remaining hand-written files the products need' (authority dag/gunbc/v1_deletion_plan.dag, v1-hand-queue-drain lane) owns the interim seed bridge in rest_auth_identity_value, fnv1a64_structural_value, and rest_authenticated_identity_for_witness. DISSOLVE-ON: that row migrates REST invocation construction out of v1_interpreter; the checkable receipt is deletion of those three hand-Rust symbols while this discriminating equality/inequality witness remains enrolled against the replacement realization. Independently, the input-digest limb migration lands and an authenticated replay witness executes against a seed-produced invocation; this note then deletes." +data rest_authenticated_digest_witness_note: String = "AUTHENTICATED ARM: PIN WITHDRAWN 2026-08-11 (gunbc#8146) - HEADER CORRECTED, was EXECUTED PIN; REPLAY-PATH DEFERRAL TYPED (review 47041, gunbc#7648). RestAuthenticated.digest is Fnv1a64Structural and the seed mint rest_auth_identity_value produces it via atom_identity_hash over '\\0' - the SAME fnv1a64 primitive std.content_hash.content_hash_atom realizes, so an authored fixture reproduces the digest through the modeled surface (content_hash_atom(value: \"\\0\")); an earlier spelling hashed with the host DefaultHasher, a value from outside the family this carrier names, which no dag fixture could ever author. WITHDRAWN EVIDENCE (2026-08-11, gunbc#8146, review 51198) - was EXECUTED EVIDENCE: rest_authenticated_identity_matches_dag_constructed_value (src/v1/tests/src/cross_representation_equality_test.rs, DELETED by the v1 Rust test-suite cutover; the assertion lived only there). It had not executed since the suite went --no-run, so this row was already nominal rather than newly broken. The seed mint itself is untouched. DISSOLVE-ON: re-establish the identity assertion as a floor witness. It previously pins the seed mint ==-equal to the dag-authored identity - RED under a bare-text digest, RED under a non-fnv1a64 digest - plus a secret-inequality control. WHAT REMAINS DEFERRED, AND WHY, TYPED: a full replay-path authenticated witness (fixture matched against a seed-produced invocation through the service dispatch) additionally requires the invocation input_digest, whose per-param limbs content_hash_service_inputs still derives via the host value_hash - not reproducible from .dag - so authoring the matching fixture is blocked on that limb pipeline migrating to the fnv1a64 primitives; that migration also moves the recorded-fixture store keys, so it is its own lane, not a fixture edit here. RUNG, CORRECTED FOR CI ENROLLMENT (calm-badger-682, verified against .github/workflows/ci.yml and gunbc.ci_layer_roots witness_layer_roots): CORRECTED AGAIN 2026-08-11 (gunbc#8146, review 51205) - this paragraph described a CI arrangement that no longer exists, and described it BACKWARDS relative to the change that removed it. It read that CI's only contact with the crate was 'cargo check -p v1-compiler-tests --tests (compile gate; no test execution)'. The build job now runs 'cargo test -p v1-compiler-tests --release' - the retained kernel EXECUTES in required CI, --no-run is gone from both authorities (v2.workflow.ci_v1_compiler_tests_compile_gate_emit and gunbc.ci_workflow) and from the emitted ci.yml. Two separate facts, deliberately not fused: the crate now executes in CI, AND this particular pin is no longer in it, because the module carrying it was deleted by that same cutover. So the reason this note names no executing consumer is deletion, not the old compile-only gate. witness_layer_roots remains dag plus src/v2, so floor discovery still never reaches src/v1/tests; measured, the pin passes locally in 1.66s and reds nothing anywhere. DESIGN 4b defines mechanically preventable as a mechanism that reliably exposes AND blocks, with safety depending on it executing and staying enrolled - so the mint seam sits BELOW that rung, and calling it mechanically prevented is rung inflation, which 4b names as worse than sitting low because an inflated class never ranks for climbing. Deleting the seam guard would leave this control present, compiling, and mute. NOT NEW DEBT FROM THIS PR: content_hash_cross_family_eq_v1_seed_bridge_note cites the same unexecuted crate for the cross-family backstop, so the whole family of seed-bridge controls shares this gap and it is recorded here rather than fixed. The end-to-end authenticated replay path remains unexecuted and must not be reported above either. HAND-RUST RECEIPT (review 47065): the ROADMAP row 'Work through the remaining hand-written files the products need' (authority dag/gunbc/v1/v1_deletion_plan.dag, v1-hand-queue-drain lane) owns the interim seed bridge in rest_auth_identity_value, fnv1a64_structural_value, and rest_authenticated_identity_for_witness. DISSOLVE-ON: that row migrates REST invocation construction out of v1_interpreter; the checkable receipt is deletion of those three hand-Rust symbols while this discriminating equality/inequality witness remains enrolled against the replacement realization. Independently, the input-digest limb migration lands and an authenticated replay witness executes against a seed-produced invocation; this note then deletes." data rest_bound_invocation_note: String = "REST needs a specialization of v2.std.operation_argv.BoundOperationInvocation rather than pretending its shell-only binding list is enough. OperationRef remains the declaration identity authority. The specialization adds the HTTP method, fully realized URI target, the digest of every declared input, and an auth-sensitive digest whose preimage never enters the fixture. Together those facts make a replay exact: a fixture for another operation, path/query/body input, method, target, or credential identity cannot satisfy this invocation. Query and body values are already in the declared-input digest; constants are fixed by OperationRef." diff --git a/dag/gunbc/accelerator_demo_eval.dag b/dag/gunbc/accelerator_demo/accelerator_demo_eval.dag similarity index 100% rename from dag/gunbc/accelerator_demo_eval.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_eval.dag diff --git a/dag/gunbc/accelerator_demo_float_eval.dag b/dag/gunbc/accelerator_demo/accelerator_demo_float_eval.dag similarity index 100% rename from dag/gunbc/accelerator_demo_float_eval.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_float_eval.dag diff --git a/dag/gunbc/accelerator_demo_gpu.dag b/dag/gunbc/accelerator_demo/accelerator_demo_gpu.dag similarity index 100% rename from dag/gunbc/accelerator_demo_gpu.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_gpu.dag diff --git a/dag/gunbc/accelerator_demo_plan.dag b/dag/gunbc/accelerator_demo/accelerator_demo_plan.dag similarity index 100% rename from dag/gunbc/accelerator_demo_plan.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_plan.dag diff --git a/dag/gunbc/accelerator_demo_program.dag b/dag/gunbc/accelerator_demo/accelerator_demo_program.dag similarity index 100% rename from dag/gunbc/accelerator_demo_program.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_program.dag diff --git a/dag/gunbc/accelerator_demo_realize.dag b/dag/gunbc/accelerator_demo/accelerator_demo_realize.dag similarity index 100% rename from dag/gunbc/accelerator_demo_realize.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_realize.dag diff --git a/dag/gunbc/accelerator_demo_recognizer.dag b/dag/gunbc/accelerator_demo/accelerator_demo_recognizer.dag similarity index 100% rename from dag/gunbc/accelerator_demo_recognizer.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_recognizer.dag diff --git a/dag/gunbc/accelerator_demo_render.dag b/dag/gunbc/accelerator_demo/accelerator_demo_render.dag similarity index 100% rename from dag/gunbc/accelerator_demo_render.dag rename to dag/gunbc/accelerator_demo/accelerator_demo_render.dag diff --git a/dag/gunbc/bmc_converge.dag b/dag/gunbc/bmc/bmc_converge.dag similarity index 100% rename from dag/gunbc/bmc_converge.dag rename to dag/gunbc/bmc/bmc_converge.dag diff --git a/dag/gunbc/bmc_fan_alignment_standing.dag b/dag/gunbc/bmc/bmc_fan_alignment_standing.dag similarity index 100% rename from dag/gunbc/bmc_fan_alignment_standing.dag rename to dag/gunbc/bmc/bmc_fan_alignment_standing.dag diff --git a/dag/gunbc/bmc_fan_alignment_standing_witness.dag b/dag/gunbc/bmc/bmc_fan_alignment_standing_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_alignment_standing_witness.dag rename to dag/gunbc/bmc/bmc_fan_alignment_standing_witness.dag diff --git a/dag/gunbc/bmc_fan_converge.dag b/dag/gunbc/bmc/bmc_fan_converge.dag similarity index 100% rename from dag/gunbc/bmc_fan_converge.dag rename to dag/gunbc/bmc/bmc_fan_converge.dag diff --git a/dag/gunbc/bmc_fan_monitor.dag b/dag/gunbc/bmc/bmc_fan_monitor.dag similarity index 100% rename from dag/gunbc/bmc_fan_monitor.dag rename to dag/gunbc/bmc/bmc_fan_monitor.dag diff --git a/dag/gunbc/bmc_fan_program_capture.dag b/dag/gunbc/bmc/bmc_fan_program_capture.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_capture.dag rename to dag/gunbc/bmc/bmc_fan_program_capture.dag diff --git a/dag/gunbc/bmc_fan_program_capture_witness.dag b/dag/gunbc/bmc/bmc_fan_program_capture_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_capture_witness.dag rename to dag/gunbc/bmc/bmc_fan_program_capture_witness.dag diff --git a/dag/gunbc/bmc_fan_program_decode_witness.dag b/dag/gunbc/bmc/bmc_fan_program_decode_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_decode_witness.dag rename to dag/gunbc/bmc/bmc_fan_program_decode_witness.dag diff --git a/dag/gunbc/bmc_fan_program_interpretation.dag b/dag/gunbc/bmc/bmc_fan_program_interpretation.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_interpretation.dag rename to dag/gunbc/bmc/bmc_fan_program_interpretation.dag diff --git a/dag/gunbc/bmc_fan_program_observation.dag b/dag/gunbc/bmc/bmc_fan_program_observation.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_observation.dag rename to dag/gunbc/bmc/bmc_fan_program_observation.dag diff --git a/dag/gunbc/bmc_fan_program_observation_witness.dag b/dag/gunbc/bmc/bmc_fan_program_observation_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_observation_witness.dag rename to dag/gunbc/bmc/bmc_fan_program_observation_witness.dag diff --git a/dag/gunbc/bmc_fan_program_representability_witness.dag b/dag/gunbc/bmc/bmc_fan_program_representability_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_representability_witness.dag rename to dag/gunbc/bmc/bmc_fan_program_representability_witness.dag diff --git a/dag/gunbc/bmc_fan_program_syntax_boundary_witness.dag b/dag/gunbc/bmc/bmc_fan_program_syntax_boundary_witness.dag similarity index 100% rename from dag/gunbc/bmc_fan_program_syntax_boundary_witness.dag rename to dag/gunbc/bmc/bmc_fan_program_syntax_boundary_witness.dag diff --git a/dag/gunbc/bmc_fan_projection.dag b/dag/gunbc/bmc/bmc_fan_projection.dag similarity index 100% rename from dag/gunbc/bmc_fan_projection.dag rename to dag/gunbc/bmc/bmc_fan_projection.dag diff --git a/dag/gunbc/bmc_intent.dag b/dag/gunbc/bmc/bmc_intent.dag similarity index 100% rename from dag/gunbc/bmc_intent.dag rename to dag/gunbc/bmc/bmc_intent.dag diff --git a/dag/gunbc/bmc_netboot_serve.dag b/dag/gunbc/bmc/bmc_netboot_serve.dag similarity index 99% rename from dag/gunbc/bmc_netboot_serve.dag rename to dag/gunbc/bmc/bmc_netboot_serve.dag index 6f87139dcf0..d1ee737cca7 100644 --- a/dag/gunbc/bmc_netboot_serve.dag +++ b/dag/gunbc/bmc/bmc_netboot_serve.dag @@ -159,7 +159,7 @@ data bmc_netboot_provision_scaffold: Disposition = Scaffold { } } -data bmc_netboot_provision_dissolution_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: bmc_netboot_provision — the staging manifest (bmc_netboot_staging_manifest) IS the driver: provision folds its BmcStagedFile rows through bmc_netboot_stage_file (LocalArtifact scp / InlineText write+scp / FetchFromUri typed refusal), so the file list has one authority and the former hand-unrolled sequence is deleted. bmc_netboot_run_bmc and bmc_netboot_put_path no longer hand-roll their own retained_runtime/shell.Exec.Run heredoc glue (that was two bridge sites duplicating one pattern, §2/§3); both now call gunbc.command_runner.run_shell_command, the single authority for rendering an ArgvCommand+CommandTransport over the heredoc bridge — command_runner already carries its own dissolution obligation (command_runner_dissolution_trigger) for that bridge, so this module inherits rather than duplicates it. CORRECTED 2026-08-19 (this clause previously said the SshExec debt below was unchanged and out of scope; that is now false and is rewritten rather than left standing per DESIGN §3's stale-citation discipline): extdeps.exec.command command_over_transport's SshExec branch no longer composes ssh_exec_prefix ++ argv as a flat suffix. It folds the inner ArgvCommand through gunbc.remote_shell_command remote_exec_command_string into ONE RFC-4254-conformant, POSIX-single-quote-encoded command string (cited to IEEE 1003.1-2017 section 2.2.2), carried as ssh's single final argument — bmc_transport now names openbmc_dropbear_interpretation explicitly on SshExec so this fold runs, rather than refusing on Unknown. CORRECTED AGAIN (2026-08-20, this clause previously said the heredoc bridge -- command_runner's shell_exec_via_bash/retained_runtime hop -- was unchanged; that is now false too and is rewritten rather than left standing, same §3 discipline): command_runner's run site no longer matches on transport or hops through a bash heredoc for either arm -- it asks command_over_transport once for the outer ArgvCommand and hands it straight to shell.Exec.RunArgv. So this module's remaining debt is scoped to command_runner_dissolution_trigger's own first clause (host_effect_apply has not yet bound ArgvCommand execution), which command_runner still carries and this module inherits rather than duplicates. DISSOLVES WHEN host_effect_apply binds ArgvCommand execution (mkdir / scp / busybox-httpd-launch) as typed staging effects, and dag/gunbc/bmc_netboot_serve.dag retires command_runner.run_shell_command in favor of host_effect_apply") +data bmc_netboot_provision_dissolution_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: bmc_netboot_provision — the staging manifest (bmc_netboot_staging_manifest) IS the driver: provision folds its BmcStagedFile rows through bmc_netboot_stage_file (LocalArtifact scp / InlineText write+scp / FetchFromUri typed refusal), so the file list has one authority and the former hand-unrolled sequence is deleted. bmc_netboot_run_bmc and bmc_netboot_put_path no longer hand-roll their own retained_runtime/shell.Exec.Run heredoc glue (that was two bridge sites duplicating one pattern, §2/§3); both now call gunbc.command_runner.run_shell_command, the single authority for rendering an ArgvCommand+CommandTransport over the heredoc bridge — command_runner already carries its own dissolution obligation (command_runner_dissolution_trigger) for that bridge, so this module inherits rather than duplicates it. CORRECTED 2026-08-19 (this clause previously said the SshExec debt below was unchanged and out of scope; that is now false and is rewritten rather than left standing per DESIGN §3's stale-citation discipline): extdeps.exec.command command_over_transport's SshExec branch no longer composes ssh_exec_prefix ++ argv as a flat suffix. It folds the inner ArgvCommand through gunbc.remote_shell_command remote_exec_command_string into ONE RFC-4254-conformant, POSIX-single-quote-encoded command string (cited to IEEE 1003.1-2017 section 2.2.2), carried as ssh's single final argument — bmc_transport now names openbmc_dropbear_interpretation explicitly on SshExec so this fold runs, rather than refusing on Unknown. CORRECTED AGAIN (2026-08-20, this clause previously said the heredoc bridge -- command_runner's shell_exec_via_bash/retained_runtime hop -- was unchanged; that is now false too and is rewritten rather than left standing, same §3 discipline): command_runner's run site no longer matches on transport or hops through a bash heredoc for either arm -- it asks command_over_transport once for the outer ArgvCommand and hands it straight to shell.Exec.RunArgv. So this module's remaining debt is scoped to command_runner_dissolution_trigger's own first clause (host_effect_apply has not yet bound ArgvCommand execution), which command_runner still carries and this module inherits rather than duplicates. DISSOLVES WHEN host_effect_apply binds ArgvCommand execution (mkdir / scp / busybox-httpd-launch) as typed staging effects, and dag/gunbc/bmc/bmc_netboot_serve.dag retires command_runner.run_shell_command in favor of host_effect_apply") // IT TAKES A COMMAND, NOT A WORD LIST. Taking List made this function a second place an // argv could be hand-spelled -- and it was: its mkdir caller below built one inline. With diff --git a/dag/gunbc/bmc_netboot_shell_boot.dag b/dag/gunbc/bmc/bmc_netboot_shell_boot.dag similarity index 100% rename from dag/gunbc/bmc_netboot_shell_boot.dag rename to dag/gunbc/bmc/bmc_netboot_shell_boot.dag diff --git a/dag/gunbc/bmc_onboarding.dag b/dag/gunbc/bmc/bmc_onboarding.dag similarity index 100% rename from dag/gunbc/bmc_onboarding.dag rename to dag/gunbc/bmc/bmc_onboarding.dag diff --git a/dag/gunbc/bmc_virtual_media.dag b/dag/gunbc/bmc/bmc_virtual_media.dag similarity index 100% rename from dag/gunbc/bmc_virtual_media.dag rename to dag/gunbc/bmc/bmc_virtual_media.dag diff --git a/dag/gunbc/build_cache_endpoint_observation.dag b/dag/gunbc/build_cache/build_cache_endpoint_observation.dag similarity index 100% rename from dag/gunbc/build_cache_endpoint_observation.dag rename to dag/gunbc/build_cache/build_cache_endpoint_observation.dag diff --git a/dag/gunbc/build_cache_endpoint_observe.dag b/dag/gunbc/build_cache/build_cache_endpoint_observe.dag similarity index 100% rename from dag/gunbc/build_cache_endpoint_observe.dag rename to dag/gunbc/build_cache/build_cache_endpoint_observe.dag diff --git a/dag/gunbc/build_cache_endpoint_path.dag b/dag/gunbc/build_cache/build_cache_endpoint_path.dag similarity index 100% rename from dag/gunbc/build_cache_endpoint_path.dag rename to dag/gunbc/build_cache/build_cache_endpoint_path.dag diff --git a/dag/gunbc/build_cache_ensure.dag b/dag/gunbc/build_cache/build_cache_ensure.dag similarity index 100% rename from dag/gunbc/build_cache_ensure.dag rename to dag/gunbc/build_cache/build_cache_ensure.dag diff --git a/dag/gunbc/build_cache_instance.dag b/dag/gunbc/build_cache/build_cache_instance.dag similarity index 100% rename from dag/gunbc/build_cache_instance.dag rename to dag/gunbc/build_cache/build_cache_instance.dag diff --git a/dag/gunbc/build_cache_instance_readiness.dag b/dag/gunbc/build_cache/build_cache_instance_readiness.dag similarity index 100% rename from dag/gunbc/build_cache_instance_readiness.dag rename to dag/gunbc/build_cache/build_cache_instance_readiness.dag diff --git a/dag/gunbc/build_cache_latency_probe.dag b/dag/gunbc/build_cache/build_cache_latency_probe.dag similarity index 100% rename from dag/gunbc/build_cache_latency_probe.dag rename to dag/gunbc/build_cache/build_cache_latency_probe.dag diff --git a/dag/gunbc/build_cache_provision_verdict.dag b/dag/gunbc/build_cache/build_cache_provision_verdict.dag similarity index 100% rename from dag/gunbc/build_cache_provision_verdict.dag rename to dag/gunbc/build_cache/build_cache_provision_verdict.dag diff --git a/dag/gunbc/build_cache_unit.dag b/dag/gunbc/build_cache/build_cache_unit.dag similarity index 100% rename from dag/gunbc/build_cache_unit.dag rename to dag/gunbc/build_cache/build_cache_unit.dag diff --git a/dag/gunbc/ci_budget_tree.dag b/dag/gunbc/ci/ci_budget_tree.dag similarity index 100% rename from dag/gunbc/ci_budget_tree.dag rename to dag/gunbc/ci/ci_budget_tree.dag diff --git a/dag/gunbc/ci_build_job_v1_compiler_unit_receipt.dag b/dag/gunbc/ci/ci_build_job_v1_compiler_unit_receipt.dag similarity index 100% rename from dag/gunbc/ci_build_job_v1_compiler_unit_receipt.dag rename to dag/gunbc/ci/ci_build_job_v1_compiler_unit_receipt.dag diff --git a/dag/gunbc/ci_compile_jobs.dag b/dag/gunbc/ci/ci_compile_jobs.dag similarity index 100% rename from dag/gunbc/ci_compile_jobs.dag rename to dag/gunbc/ci/ci_compile_jobs.dag diff --git a/dag/gunbc/ci_compile_measurement.dag b/dag/gunbc/ci/ci_compile_measurement.dag similarity index 100% rename from dag/gunbc/ci_compile_measurement.dag rename to dag/gunbc/ci/ci_compile_measurement.dag diff --git a/dag/gunbc/ci_cost_arc_closeout_receipt.dag b/dag/gunbc/ci/ci_cost_arc_closeout_receipt.dag similarity index 100% rename from dag/gunbc/ci_cost_arc_closeout_receipt.dag rename to dag/gunbc/ci/ci_cost_arc_closeout_receipt.dag diff --git a/dag/gunbc/ci_deploy_access.dag b/dag/gunbc/ci/ci_deploy_access.dag similarity index 100% rename from dag/gunbc/ci_deploy_access.dag rename to dag/gunbc/ci/ci_deploy_access.dag diff --git a/dag/gunbc/ci_deploy_access_observe.dag b/dag/gunbc/ci/ci_deploy_access_observe.dag similarity index 100% rename from dag/gunbc/ci_deploy_access_observe.dag rename to dag/gunbc/ci/ci_deploy_access_observe.dag diff --git a/dag/gunbc/ci_deploy_sudoers.dag b/dag/gunbc/ci/ci_deploy_sudoers.dag similarity index 98% rename from dag/gunbc/ci_deploy_sudoers.dag rename to dag/gunbc/ci/ci_deploy_sudoers.dag index 0f9a0cc2007..5b570749372 100644 --- a/dag/gunbc/ci_deploy_sudoers.dag +++ b/dag/gunbc/ci/ci_deploy_sudoers.dag @@ -73,7 +73,7 @@ fn deploy_access_sudo_grants_lint_ok(access: DeployAccess) -> Bool { } fn deploy_sudoers_dropin_header() -> String { - "# GENERATED by dag/gunbc/ci_deploy_sudoers.dag — do not hand-edit\n" + "# GENERATED by dag/gunbc/ci/ci_deploy_sudoers.dag — do not hand-edit\n" } fn deploy_sudoers_line_for_grant(access: DeployAccess, g: PosixSudoGrant) -> String { diff --git a/dag/gunbc/ci_deploy_target_host.dag b/dag/gunbc/ci/ci_deploy_target_host.dag similarity index 100% rename from dag/gunbc/ci_deploy_target_host.dag rename to dag/gunbc/ci/ci_deploy_target_host.dag diff --git a/dag/gunbc/ci_failure_class.dag b/dag/gunbc/ci/ci_failure_class.dag similarity index 100% rename from dag/gunbc/ci_failure_class.dag rename to dag/gunbc/ci/ci_failure_class.dag diff --git a/dag/gunbc/ci_fleet.dag b/dag/gunbc/ci/ci_fleet.dag similarity index 100% rename from dag/gunbc/ci_fleet.dag rename to dag/gunbc/ci/ci_fleet.dag diff --git a/dag/gunbc/ci_floor_measurement.dag b/dag/gunbc/ci/ci_floor_measurement.dag similarity index 100% rename from dag/gunbc/ci_floor_measurement.dag rename to dag/gunbc/ci/ci_floor_measurement.dag diff --git a/dag/gunbc/ci_gate.dag b/dag/gunbc/ci/ci_gate.dag similarity index 100% rename from dag/gunbc/ci_gate.dag rename to dag/gunbc/ci/ci_gate.dag diff --git a/dag/gunbc/ci_heal_credential.dag b/dag/gunbc/ci/ci_heal_credential.dag similarity index 100% rename from dag/gunbc/ci_heal_credential.dag rename to dag/gunbc/ci/ci_heal_credential.dag diff --git a/dag/gunbc/ci_input_envelope.dag b/dag/gunbc/ci/ci_input_envelope.dag similarity index 100% rename from dag/gunbc/ci_input_envelope.dag rename to dag/gunbc/ci/ci_input_envelope.dag diff --git a/dag/gunbc/ci_layer_roots.dag b/dag/gunbc/ci/ci_layer_roots.dag similarity index 98% rename from dag/gunbc/ci_layer_roots.dag rename to dag/gunbc/ci/ci_layer_roots.dag index 1952bd99a3c..0b53f45879b 100644 --- a/dag/gunbc/ci_layer_roots.dag +++ b/dag/gunbc/ci/ci_layer_roots.dag @@ -226,7 +226,7 @@ data required_v2_emission_dissolution: DissolutionCondition = unbound_dissolutio // and mutation verdict, and `claim_executor --required-ci --required-lane build` re-derives // them. No figure from a run is transcribed here. data required_emit_compile_entries: List = [ - "dag/gunbc/ci_layer_roots.dag", + "dag/gunbc/ci/ci_layer_roots.dag", "dag/gunbc/scm/load_standing.dag", "dag/extdeps/uri.dag", "dag/std/measure.dag", @@ -350,7 +350,7 @@ data witness_exclusion_frontier: List = [ WitnessExclusionRow { pattern: "long/host_identity_single_authoring_witness_test.dag", classification: OfflineLocalRecipe, - reason: "Same class as the cited_symbol row above and admitted on the same grounds: a corpus-scale decl_facts census, not narrow business logic. MEASURED 2026-08-22 rather than estimated, because the CI figure that surfaced it is not a cost — the fast lane reported `cost at least 40605ms against 5000ms`, which is the interrupt point, so the true figure was UNMEASURED and unbounded above. Run uncapped, the walk is 10-27s on top of a 90.4s fixed compile-and-index overhead (isolated by timing a trivial witness through the identical binary and roots: 90403ms). NARROWING THE POOL IS NOT THE FIX AND WAS TESTED FIRST: [dag, src/v2] measured 117324ms and [dag/gunbc] 113638ms / 100515ms end-to-end, so the walk barely moves with pool size — the cost is the reflection acquisition, not the number of modules under the root. FILE-GRAIN POOLS ARE UNAVAILABLE, which is why the grain cannot simply be tightened -- but the surface REFUSES rather than answering emptily, and the difference is worth stating because the first version of this row got it backwards. corpus_dag_files_for_roots collects only `if root_path.is_dir()`, and reading that helper alone suggests a file path yields a silent empty pool. It does not: measured by execution, calling data_decl_type_facts with a single pool root naming the file dag/gunbc/fleet_intent_network.dag refuses with PoolRootContributesNothing carrying caller data_decl_type_facts, declared 1, and one defect pairing that path with the kind NamesFile -- typed, located, and naming the defect kind. A fail-closed guard sits above the helper, so the empty-observation narrow this row briefly claimed does not exist here. Against a 5000ms fail-stop and a 500ms mandatory-migration threshold this is two orders of magnitude out, so it is a home question, not a tuning one. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/host_identity_single_authoring_witness_test.dag --functions the_physical_inventory_authors_no_host_identity,the_intent_network_still_authors_the_six", + reason: "Same class as the cited_symbol row above and admitted on the same grounds: a corpus-scale decl_facts census, not narrow business logic. MEASURED 2026-08-22 rather than estimated, because the CI figure that surfaced it is not a cost — the fast lane reported `cost at least 40605ms against 5000ms`, which is the interrupt point, so the true figure was UNMEASURED and unbounded above. Run uncapped, the walk is 10-27s on top of a 90.4s fixed compile-and-index overhead (isolated by timing a trivial witness through the identical binary and roots: 90403ms). NARROWING THE POOL IS NOT THE FIX AND WAS TESTED FIRST: [dag, src/v2] measured 117324ms and [dag/gunbc] 113638ms / 100515ms end-to-end, so the walk barely moves with pool size — the cost is the reflection acquisition, not the number of modules under the root. FILE-GRAIN POOLS ARE UNAVAILABLE, which is why the grain cannot simply be tightened -- but the surface REFUSES rather than answering emptily, and the difference is worth stating because the first version of this row got it backwards. corpus_dag_files_for_roots collects only `if root_path.is_dir()`, and reading that helper alone suggests a file path yields a silent empty pool. It does not: measured by execution, calling data_decl_type_facts with a single pool root naming the file dag/gunbc/fleet/fleet_intent_network.dag refuses with PoolRootContributesNothing carrying caller data_decl_type_facts, declared 1, and one defect pairing that path with the kind NamesFile -- typed, located, and naming the defect kind. A fail-closed guard sits above the helper, so the empty-observation narrow this row briefly claimed does not exist here. Against a 5000ms fail-stop and a 500ms mandatory-migration threshold this is two orders of magnitude out, so it is a home question, not a tuning one. Local recipe: claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/long/host_identity_single_authoring_witness_test.dag --functions the_physical_inventory_authors_no_host_identity,the_intent_network_still_authors_the_six", dissolution: unbound_dissolution(description: "shared: this row deletes on the same trigger as the cited_symbol row — a decl_facts reflection surface cheap enough to enroll per-PR, or per-witness cost envelopes subsuming the test/claim/long/ dir grain. The two rows are one class and should dissolve together, not separately") }, WitnessExclusionRow { @@ -373,8 +373,8 @@ data witness_exclusion_frontier: List = [ WitnessExclusionRow { pattern: "fleet_revision_relation_wet_matrix_test.dag", classification: OfflineLocalRecipe, - reason: "wet/replay class (wet_integration_offline_note posture), substantiated by reading the carrier rather than by a floor red: every dispatching row reaches git.Inspect.MergeBase, which publishes no mock_response, so hermetic discovery REFUSES by construction rather than skipping. WHAT MAKES THIS ROW DIFFERENT FROM ITS SIBLINGS ABOVE, and the reason it is not merely 'another live-effects file': the recorded observations that WOULD make it hermetic already exist and are committed — the seven cases were recorded wet against a deterministic fixture repository and replay green from dag/test/fixtures/fleet-revision-relation. The blocker is that there is no way to hand them to a floor run. v2.std.witness_evaluation WitnessEvaluationFrame carries `rest_fixtures: List` and nothing else; its own note states that filesystem and environment replay bindings are intended to extend that carrier later, and no shell/service arm exists yet. The external store this file's recipe uses is a claim_batch flag (--fixture-store) and claim_executor has no equivalent, so neither route reaches the required floor. So the honest state is: the composition is PROVEN, and its proof executes nowhere the floor can see. THE PURE HALF IS NOT EXCLUDED — the merge-base fold's exit-code and relation controls stay discovery-enrolled in fleet_main_revision_witness_test.dag per-PR (exit_one_is_an_answer_and_exit_one_two_eight_is_an_absence_of_one, one_merge_base_decides_both_directions, a_successful_probe_with_undecodable_output_refuses); only the effectful composition runs here.", - dissolution: unbound_dissolution(description: "CLAIM_EXECUTOR GAINS THE EXTERNAL RECORDED-STORE ROUTE that claim_batch's --fixture-store already provides, so these nine rows' recorded answers reach a required-floor run. THIS TRIGGER WAS WRONG UNTIL 2026-08-22 AND NAMED A CHANGE THAT WOULD HAVE DISSOLVED NOTHING: it read 'a shell/service fixture arm on v2.std.witness_evaluation WitnessEvaluationFrame, beside rest_fixtures ... when it lands these nine rows enroll unchanged ... no second trigger is needed'. THERE ARE TWO DISJOINT REPLAY ROUTES AND THESE ROWS DO NOT USE THE FRAME ONE. The modeled route is WitnessEvaluationFrame's rest_fixtures resolved by extdeps.transports.rest rest_exchange_resolution, keyed by rest_bound_invocation_eq over named invocation fields; its only consumer in the corpus is dag/test/claim/rest_exchange_replay_test.dag. The external route is the host RecordedFixtureStore keyed by input_hash and selected by claim_batch --fixture-store. THIS FILE NEVER CONSTRUCTS WitnessEvaluationFrame — it names it only in prose — and its refusals under an emptied store read 'missing recorded fixture for git.Inspect.MergeBase (input_hash=...)', which is the external key; input_hash does not occur in rest.dag at all. So building the frame arm and deleting this exclusion on that basis would have enrolled nine rows that still cannot reach their fixtures. The frame's shell arm is still wanted for frame-route witnesses, and the frame's own note still anticipates it, but it is a DIFFERENT obligation and not this row's trigger. Evidence, executed 2026-08-22 rather than asserted: populated store 9 PASS; emptied store 2 PASS and 7 FAIL, each naming a distinct input_hash — the same asymmetry the control below specifies, which is what proves these rows consume recorded observations instead of reaching live git. The wet lane un-darkening is NOT the trigger either, because these rows do not need live git. Local recipe until then, and it carries its own discriminating controls: RECORD claim_batch --wet --record --fixture-store dag/test/fixtures/fleet-revision-relation --source-root dag --source-root src/v2 --entry dag/test/claim/fleet_revision_relation_wet_matrix_test.dag --functions identical_revisions_are_converged_without_dispatching_a_probe,identical_revisions_converge_even_when_the_path_is_not_a_repository,an_ancestor_current_is_a_forward_advance,an_ancestor_accepted_is_superseded,siblings_sharing_an_ancestor_are_neither_ancestor_of_the_other,an_orphan_root_has_no_common_ancestor,an_absent_object_is_unverifiable_not_unrelated,a_non_repository_path_is_unverifiable_rather_than_answering,no_merge_base_and_could_not_look_stay_distinguishable ; REPLAY the same command with --hermetic in place of --wet --record ; CONTROL replay again with --fixture-store pointing at an EMPTY directory — the two short-circuit rows must still PASS and the other seven must FAIL with `missing recorded fixture`, which is what proves the passing replay consumed recorded observations rather than reaching live git. The fixture repository is rebuilt by docs/plans/fleet-revision-relation-fixture.md") + reason: "wet/replay class (wet_integration_offline_note posture), substantiated by reading the carrier rather than by a floor red: every dispatching row reaches git.Inspect.MergeBase, which publishes no mock_response, so hermetic discovery REFUSES by construction rather than skipping. WHAT MAKES THIS ROW DIFFERENT FROM ITS SIBLINGS ABOVE, and the reason it is not merely 'another live-effects file': the recorded observations that WOULD make it hermetic already exist and are committed — the seven cases were recorded wet against a deterministic fixture repository and replay green from dag/test/fixture/fleet_revision_relation. The blocker is that there is no way to hand them to a floor run. v2.std.witness_evaluation WitnessEvaluationFrame carries `rest_fixtures: List` and nothing else; its own note states that filesystem and environment replay bindings are intended to extend that carrier later, and no shell/service arm exists yet. The external store this file's recipe uses is a claim_batch flag (--fixture-store) and claim_executor has no equivalent, so neither route reaches the required floor. So the honest state is: the composition is PROVEN, and its proof executes nowhere the floor can see. THE PURE HALF IS NOT EXCLUDED — the merge-base fold's exit-code and relation controls stay discovery-enrolled in fleet_main_revision_witness_test.dag per-PR (exit_one_is_an_answer_and_exit_one_two_eight_is_an_absence_of_one, one_merge_base_decides_both_directions, a_successful_probe_with_undecodable_output_refuses); only the effectful composition runs here.", + dissolution: unbound_dissolution(description: "CLAIM_EXECUTOR GAINS THE EXTERNAL RECORDED-STORE ROUTE that claim_batch's --fixture-store already provides, so these nine rows' recorded answers reach a required-floor run. THIS TRIGGER WAS WRONG UNTIL 2026-08-22 AND NAMED A CHANGE THAT WOULD HAVE DISSOLVED NOTHING: it read 'a shell/service fixture arm on v2.std.witness_evaluation WitnessEvaluationFrame, beside rest_fixtures ... when it lands these nine rows enroll unchanged ... no second trigger is needed'. THERE ARE TWO DISJOINT REPLAY ROUTES AND THESE ROWS DO NOT USE THE FRAME ONE. The modeled route is WitnessEvaluationFrame's rest_fixtures resolved by extdeps.transports.rest rest_exchange_resolution, keyed by rest_bound_invocation_eq over named invocation fields; its only consumer in the corpus is dag/test/claim/rest_exchange_replay_test.dag. The external route is the host RecordedFixtureStore keyed by input_hash and selected by claim_batch --fixture-store. THIS FILE NEVER CONSTRUCTS WitnessEvaluationFrame — it names it only in prose — and its refusals under an emptied store read 'missing recorded fixture for git.Inspect.MergeBase (input_hash=...)', which is the external key; input_hash does not occur in rest.dag at all. So building the frame arm and deleting this exclusion on that basis would have enrolled nine rows that still cannot reach their fixtures. The frame's shell arm is still wanted for frame-route witnesses, and the frame's own note still anticipates it, but it is a DIFFERENT obligation and not this row's trigger. Evidence, executed 2026-08-22 rather than asserted: populated store 9 PASS; emptied store 2 PASS and 7 FAIL, each naming a distinct input_hash — the same asymmetry the control below specifies, which is what proves these rows consume recorded observations instead of reaching live git. The wet lane un-darkening is NOT the trigger either, because these rows do not need live git. Local recipe until then, and it carries its own discriminating controls: RECORD claim_batch --wet --record --fixture-store dag/test/fixture/fleet_revision_relation --source-root dag --source-root src/v2 --entry dag/test/claim/fleet_revision_relation_wet_matrix_test.dag --functions identical_revisions_are_converged_without_dispatching_a_probe,identical_revisions_converge_even_when_the_path_is_not_a_repository,an_ancestor_current_is_a_forward_advance,an_ancestor_accepted_is_superseded,siblings_sharing_an_ancestor_are_neither_ancestor_of_the_other,an_orphan_root_has_no_common_ancestor,an_absent_object_is_unverifiable_not_unrelated,a_non_repository_path_is_unverifiable_rather_than_answering,no_merge_base_and_could_not_look_stay_distinguishable ; REPLAY the same command with --hermetic in place of --wet --record ; CONTROL replay again with --fixture-store pointing at an EMPTY directory — the two short-circuit rows must still PASS and the other seven must FAIL with `missing recorded fixture`, which is what proves the passing replay consumed recorded observations rather than reaching live git. The fixture repository is rebuilt by docs/plans/fleet-revision-relation-fixture.md") }, WitnessExclusionRow { pattern: "external_model_scope_live_cover_witness_test.dag", diff --git a/dag/gunbc/ci_materialization.dag b/dag/gunbc/ci/ci_materialization.dag similarity index 100% rename from dag/gunbc/ci_materialization.dag rename to dag/gunbc/ci/ci_materialization.dag diff --git a/dag/gunbc/ci_oom_reclassify.dag b/dag/gunbc/ci/ci_oom_reclassify.dag similarity index 100% rename from dag/gunbc/ci_oom_reclassify.dag rename to dag/gunbc/ci/ci_oom_reclassify.dag diff --git a/dag/gunbc/ci_release_bins.dag b/dag/gunbc/ci/ci_release_bins.dag similarity index 100% rename from dag/gunbc/ci_release_bins.dag rename to dag/gunbc/ci/ci_release_bins.dag diff --git a/dag/gunbc/ci_render.dag b/dag/gunbc/ci/ci_render.dag similarity index 100% rename from dag/gunbc/ci_render.dag rename to dag/gunbc/ci/ci_render.dag diff --git a/dag/gunbc/ci_runner_placement.dag b/dag/gunbc/ci/ci_runner_placement.dag similarity index 100% rename from dag/gunbc/ci_runner_placement.dag rename to dag/gunbc/ci/ci_runner_placement.dag diff --git a/dag/gunbc/ci_runner_target.dag b/dag/gunbc/ci/ci_runner_target.dag similarity index 100% rename from dag/gunbc/ci_runner_target.dag rename to dag/gunbc/ci/ci_runner_target.dag diff --git a/dag/gunbc/ci_spec.dag b/dag/gunbc/ci/ci_spec.dag similarity index 99% rename from dag/gunbc/ci_spec.dag rename to dag/gunbc/ci/ci_spec.dag index 2ae0fb4afeb..55196a55f0d 100644 --- a/dag/gunbc/ci_spec.dag +++ b/dag/gunbc/ci/ci_spec.dag @@ -461,22 +461,22 @@ type GunbcRunStepTarget { } data gunbc_ci_fleet_reach_probe_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/host_reach_identity_probe.dag", + entry: "dag/gunbc/host/host_reach_identity_probe.dag", function: "probe_fleet_reach_wet", } data gunbc_ci_multi_principal_probe_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_multi_principal_probe.dag", + entry: "dag/gunbc/fleet/fleet_multi_principal_probe.dag", function: "fleet_multi_principal_probe_wet", } data gunbc_ci_fleet_converge_plan_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_converge_plan_cli.dag", + entry: "dag/gunbc/fleet/fleet_converge_plan_cli.dag", function: "fleet_converge_plan_wet", } data gunbc_ci_fleet_converge_apply_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_converge_plan_cli.dag", + entry: "dag/gunbc/fleet/fleet_converge_plan_cli.dag", function: "fleet_converge_apply_wet", } @@ -506,27 +506,27 @@ data gunbc_ci_spark_serving_converge_slice_target: GunbcRunStepTarget = GunbcRun } data gunbc_ci_collect_fleet_convergence_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_receipt_collector.dag", + entry: "dag/gunbc/fleet/fleet_receipt_collector.dag", function: "collect_fleet_convergence_wet", } data gunbc_ci_fleet_host_key_scan_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_host_key_enrollment.dag", + entry: "dag/gunbc/fleet/fleet_host_key_enrollment.dag", function: "fleet_host_key_scan_wet", } data gunbc_ci_fleet_host_key_enroll_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_host_key_enrollment.dag", + entry: "dag/gunbc/fleet/fleet_host_key_enrollment.dag", function: "fleet_host_key_enroll_wet", } data gunbc_ci_probe_identity_observe_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_probe_identity_observe.dag", + entry: "dag/gunbc/fleet/fleet_probe_identity_observe.dag", function: "fleet_probe_identity_observe_wet", } data gunbc_ci_authorized_key_enroll_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/fleet_host_key_enrollment.dag", + entry: "dag/gunbc/fleet/fleet_host_key_enrollment.dag", function: "fleet_authorized_key_self_enroll_wet", } @@ -546,7 +546,7 @@ data gunbc_ci_heal_regen_target: GunbcRunStepTarget = GunbcRunStepTarget { } data gunbc_ci_heal_repo_local_git_config_target: GunbcRunStepTarget = GunbcRunStepTarget { - entry: "dag/gunbc/repo_local_git_config.dag", + entry: "dag/gunbc/repo/repo_local_git_config.dag", function: "converge", } diff --git a/dag/gunbc/ci_workflow_expressions.dag b/dag/gunbc/ci/ci_workflow_expressions.dag similarity index 100% rename from dag/gunbc/ci_workflow_expressions.dag rename to dag/gunbc/ci/ci_workflow_expressions.dag diff --git a/dag/gunbc/ci_yaml_validate.dag b/dag/gunbc/ci/ci_yaml_validate.dag similarity index 100% rename from dag/gunbc/ci_yaml_validate.dag rename to dag/gunbc/ci/ci_yaml_validate.dag diff --git a/dag/gunbc/cli_run_hand_rust_area_ledger.dag b/dag/gunbc/cli_run_hand_rust_area_ledger.dag index 3bfdea86b8c..42237115686 100644 --- a/dag/gunbc/cli_run_hand_rust_area_ledger.dag +++ b/dag/gunbc/cli_run_hand_rust_area_ledger.dag @@ -187,7 +187,7 @@ fn cli_run_hand_rust_area_rows() -> List { anchors: [ CliRunAreaAnchor { symbol: "floor_materialization" as NonEmptyStr, - anchor_home: "dag/gunbc/floor_materialization.dag" as NonEmptyStr + anchor_home: "dag/gunbc/floor/floor_materialization.dag" as NonEmptyStr }, CliRunAreaAnchor { symbol: "memory_governor" as NonEmptyStr, anchor_home: subject } ] diff --git a/dag/gunbc/cli_run_witness_admission_scaffold.dag b/dag/gunbc/cli_run_witness_admission_scaffold.dag index f683301abee..46bb63f9487 100644 --- a/dag/gunbc/cli_run_witness_admission_scaffold.dag +++ b/dag/gunbc/cli_run_witness_admission_scaffold.dag @@ -14,7 +14,7 @@ data cli_run_witness_admission_source_scan_scaffold: Disposition = Scaffold { } } -data cli_run_witness_admission_source_scan_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: witness_admission_explicit_consumer_keys + witness_admission_entry_function_keys_from_source — Phase 0(b) host text scan over dag/gunbc/ci_layer_roots.dag, src/v2/compiler/self_host/wet_receipt_enrollment.dag, and the cycle-free leaf src/v2/compiler/self_host/seed_emitter_behavioral_wet_known_red_entries.dag (review 44441/44487: wet_receipt aliases the leaf without parseable seed_emitter_behavioral_wet_known_red_entry( heads, so the leaf must be scanned until v2.workflow.witness_admission.witness_admission_explicit_consumer_manifest is host-consumed). NOT a census shrink — counted interim HAND-Rust growth until module-identity-storage-binding Phase 1(b). DISSOLVES WHEN cli_run.rs Chunk F lands (docs/plans/cli-run-reconcile-defork.md → host reads emitted manifest rows; file-grain expansion lives in the .dag authority) OR ROADMAP 5-dissolve-patches retires HAND witness-admission scan entirely.") +data cli_run_witness_admission_source_scan_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: witness_admission_explicit_consumer_keys + witness_admission_entry_function_keys_from_source — Phase 0(b) host text scan over dag/gunbc/ci/ci_layer_roots.dag, src/v2/compiler/self_host/wet_receipt_enrollment.dag, and the cycle-free leaf src/v2/compiler/self_host/seed_emitter_behavioral_wet_known_red_entries.dag (review 44441/44487: wet_receipt aliases the leaf without parseable seed_emitter_behavioral_wet_known_red_entry( heads, so the leaf must be scanned until v2.workflow.witness_admission.witness_admission_explicit_consumer_manifest is host-consumed). NOT a census shrink — counted interim HAND-Rust growth until module-identity-storage-binding Phase 1(b). DISSOLVES WHEN cli_run.rs Chunk F lands (docs/plans/cli-run-reconcile-defork.md → host reads emitted manifest rows; file-grain expansion lives in the .dag authority) OR ROADMAP 5-dissolve-patches retires HAND witness-admission scan entirely.") data cli_run_witness_admission_hand_rust_receipt_plan_anchor: String = "docs/plans/module-identity-storage-binding-design.md#phase-0-enrollment" diff --git a/dag/gunbc/design_document.dag b/dag/gunbc/design_document.dag index 026a26c1b2a..174c10c081a 100644 --- a/dag/gunbc/design_document.dag +++ b/dag/gunbc/design_document.dag @@ -182,7 +182,7 @@ fn building_checks_blocks() -> List { ul(items: [ li(text: "`cargo test --workspace` · `cargo clippy --all-targets -- -D warnings` · `cargo fmt --all --check`"), li(text: "one-time per clone: `git config core.hooksPath .githooks` — the only documented manual seed; generated pre-commit/pre-push hooks then idempotently converge `merge.generated-artifact.driver` and re-assert `core.hooksPath` via argv derived from `gunbc.repo_local_git_config` (clones that skip hooksPath degrade to vanilla text-merge for generated-artifact paths; drift gate still guards at CI). The driver REFUSES rather than answering `true`: git reaches a low-level merge driver only when both sides changed the path since the merge base — measured on a four-case matrix, one-sided and identical changes never reach it — and taking the ours side there dropped the other side's authority-derived bytes with no conflict, twice on #7836 against the stage0 seed. It now leaves the ours side in the worktree with no conflict markers, marks the path unmerged, and prints the regeneration recipe; the class is mechanically preventable, not structural, and its next-rung trigger is the commit-writer binding rows in `gunbc.commit_workflow`"), - li(text: "explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo_local_git_config.dag --function converge`"), + li(text: "explicit actuator (CI / tooling): `gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge`"), li(text: "CI — **RUNG DROP, DECLARED (2026-08-15, the floor cut).** WHAT WAS HERE: one composed floor pass, `claim_executor` with a `--plan-entry` naming `src/v2/workflow/ci_floor_plan.dag`, a v2 scheduler deciding batches from `gunbc.ci_spec`, a compile-clean gate ordered ahead of everything else, per-PR discovery over `CiSpec.discovery_scan_dirs`, and a 4-hourly `affected-set-falsifier` cadence carrying the whole-tree cold controls. **ALL OF IT IS DELETED** — the workflows (`ci.yml`, `falsifier.yml`, `falsifier-alert.yml`), their `.dag` authorities, and ~30 witness modules. This paragraph previously recited that invocation in the present tense; it was false the moment the cut landed, and a knowingly-false recital in the canonical authority is premise contamination — every session reading it plans against a command that does not exist. WHAT RUNS NOW: one emission, `gunbc.witness_floor_workflow` → `.github/workflows/witnesses.yml`, invoking our own binary once PER LANE — `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` and `... --required-lane witnesses`, in TWO PARALLEL JOBS (the 2026-08-25 split described below; the invocation named `--required-floor` until the 2026-08-20 consolidation, also described below, and that flag still exists and still runs the fold alone, it is simply no longer what CI calls) — whose floor phase folds every discovered witness through one prepared subject via `v1_compiler.cli_run` `run_required_floor`, whose admission, cost-line and preparation-safety policy is owned by `v2.workflow.required_floor` (this clause named that module as the symbol home until 2026-08-26; the module is real and the symbol does not resolve there, which is exactly the §3 defect the `--required-cited-symbol` census would have refused before its 2026-08-23 drop). No plan entry, no plan function, no batch id, no worker role, no selection flag: the fold has no such concepts to configure — which PRESERVES the 2026-08-13 operator directive that no SELECTION shrinks the roster, by construction rather than by a flag someone must remember to set. **That directive is about selection, and an earlier revision of this clause stated it as `the whole discovered roster runs unshrunk`, which is false of the DISCOVERED roster and true only of the ROUTED one.** Measured on main run `32553487573` (`967b5bc1b92`, 2026-08-22T05:06Z): `offered=11812 routed=10439 declined_long=543 declined_live=830`. 1373 discovered sites — 11.6% — are declined by HOME POLICY before the fold sees them, so `planned` is the routed roster and never the discovered one. The floor's own line is honest about this (`every discovered site is exactly one of these`); only this document overclaimed, and the overclaim is the load-bearing kind, because a reader who takes `the whole discovered roster runs` literally will conclude that authoring a witness is sufficient for it to execute. It is not: a witness under a long or live home is discovered, counted, and never run. The decline mechanism is not a selection flag and the directive is not violated by it — the two are different questions, and conflating them is what made one true sentence and one false sentence read as the same claim. That directive's own carrier (`corpus_selection_off_note`) died with the floor; `gunbc.ci_spec` retains the history and now points here. **THE FOLD NOW EXECUTES, measured 2026-08-19.** Green on main, the latest measured `32553487573` (`967b5bc1b92`, 2026-08-22T05:06Z): `planned=10439 executed=10439 terminal=10439 passed=10132 known_red_held=206 failed=0 stale_quarantine=0 route_gap_held=101 over_cost_line_diagnostic=35`, ~30 min wall. The counts previously cited here were run `32515441229` of 2026-08-21 (`offered=11615 routed=10253 … passed=9946`) and had gone stale by 197 offered sites in under twelve hours; they are replaced rather than annotated, because two count sets in one clause is two accounts of one fact. That this clause has now been re-pointed twice in three days is itself the measurement: a transcribed receipt line is a *positional* citation of a run's output — §3's rule reaches it, since no edit here invalidates it and it rots anyway — so the standing question is now DECIDED (operator ruling, 2026-08-24): **name the instrument, never transcribe its output.** A measurement is cited by naming the producer that re-derives it — the run, the flag, the committed script — and never by copying its numbers into prose, exactly as §3 requires a citation to name a symbol rather than a line, and for the same reason: a transcribed number is unreachable from the thing that owns it, so it rots without anyone touching either end. The counters above are retained under that rule as a declared exception with their producing run named, because this clause's subject IS the rung drop and a drop is unreadable without the magnitude it dropped by; every other transcription in the corpus is debt. The ruling was priced, not preferred: the parallel measurement corpus it governs was BANKRUPTED the same day — `docs/probes/` deleted whole, 195 files and 50,601 lines, boards and captures and instruments alike, leaving NO `.sh` or `.py` anywhere in the repository outside `.githooks` — after a board asserting a compiler mechanism as a live defect was found to have merged EIGHT SECONDS after the commit that fixed it, and to have named the emitter carrier when the actual repair was two lines in the model. A lane had already selected that mechanism as its next work on the board's authority. **THE INSTRUMENTS WENT WITH THE PROSE, and the reason decides what the rule means (operator ruling, 2026-08-24): an ad-hoc `.sh` or `.py` in this repository is §6 UNMODELED REALIZATION — raw shell implementing semantics already expressible in `.dag` — so if a measurement is worth re-deriving it is worth an entry point, and if it is not worth an entry point it is not an instrument but a one-off.** This was ruled against a live objection, recorded because the objection was correct on its own facts and still lost: a peer had re-run `curated_cargo_probe_one.sh` that same hour to re-derive the emission board's headline from source, so the scripts had real consumers — LANES, which a census of `.dag` consumers cannot see, and which is why an earlier revision of this clause reported them as dead. The ruling does not deny that consumer; it denies that a stray script is the right carrier for it. So `name the instrument` names a `.dag` entry point, and the rule needs no exception for a referent it deleted: what is deleted is everything that cannot be re-derived from the tree, and what re-derives it is modeled or it does not exist. That is the §2 cost of a second representation with no authority, arriving faster than it can be authored, and it is why a measurement document is presumed redundant rather than merely stale. WHAT THIS DOES NOT CLAIM: the cut leaves a named residue it does not repair — gitignore un-ignore rows for deleted paths, prose notes across ~20 modules citing them, and the witnesses above, all still green over dead names. That residue is the next cut, not a gap this one closed. **`executed` answers a narrower question than every reader asks of it: it counts a witness reaching the fold, not its assertion running.** A witness whose subject is a subprocess exit status is planned, discovered, and counted `executed` while it is REFUSED BY CONSTRUCTION at the hermetic boundary — `run_required_floor`'s hermetic envelope rejects the host effect via `shell.Test.IsExecutable` before the subprocess is reached, in about a millisecond, which also rules out a budget refusal on timing. This is CORRECT, not a gap: mocking that refusal to let such a witness run would pass it against a fabricated exit status, the exact fabricated-plausible-output failure the witness exists to catch. It is a boundary of what the hermetic floor can cover, named here beside the counters rather than left for a reader to rediscover. This clause previously read that no witness had executed and that the fold refused during preparation; that was true when written and is now false, and it is corrected in place rather than left standing until the rest of the paragraph can be rewritten — because a knowingly-false recital is premise contamination whichever direction it points, and this one had already cost real work: a session measuring the TestClaim orphan population read it, concluded the floor had never run, and raised a sequencing question about roster growth that does not exist. The rung drop below is unaffected: the fold running green establishes that the replacement executes, not that the re-add queue has closed. WHAT IS UNGUARDED IN THE MEANTIME, named rather than left to be rediscovered (the generated-artifact drift gates were on this list until the `generated-artifact` phase described below took them off it): heal, the seven effect gates, the fmt gate, merge-admission stamping, the falsifier cadence, and the per-witness eval deadline that `gunbc_ci_fast_lane_witness_eval_budget` used to arm (`gunbc.witness_row_cost` `gunbc_ci_fast_lane_rule_note` carries that one's own drop). Each is a separate re-add, each re-derived from its own first principles under its own operator agreement rather than restored from the deleted machinery. RESTORATION TRIGGER: this paragraph is rewritten as an ordinary present-tense description — not amended, rewritten in one pass — when the re-add queue closes. Until then it describes a rung drop, and describing the replacement as finished would be the inflation §4b names as worse than sitting low. **WHAT SURVIVES UNTOUCHED, enumerated rather than swept away with the bullet** — this paragraph replaced a longer one, and a prose row is deleted for one reason and takes everything in it unless its contents are enumerated first (the same rule that governs deleting a witness file whole): the compile-clean scope authority `tools.dag_compile_clean_scope` and its import-closure selection (`entry_file_touched_via_import_closure`) are live and unmodified by the cut — but **live is not reachable, and an earlier revision of this clause said only the first**. It read that what is gone is the CI *job* that invoked them and not the authority; both halves are true and together they license a false inference, because SURVIVING A CUT AND BEING CALLABLE ARE DIFFERENT PROPERTIES and only the first was checked. Measured 2026-08-20: `entry_file_touched_via_import_closure` and `compile_clean_scope_plan_for_ci` are private `fn`s with ZERO references anywhere under `src/v1/stage0/src/bin`, no CLI flag reaches them, and the only `pub` surfaces into that chain — `witness_layer_roots_compile_clean_check` / `_emit_check` — return `Bool`, so they answer *is it clean* and can never answer *which entries would be selected*. A reader planning against the old sentence would budget an afternoon and find no caller; that is premise contamination of the same class this paragraph already corrects itself for twice. The authority survives and the capability does not, until something exposes a counting entry point; the `regen_input_sources` import closure survives and is now read by `v1_compiler.required_regen_host` — but the `regen_stage0` binary that consumed it, and the `RegenVerifyGate` / `SelfHostStalenessGate` pair that invoked it, are DELETED at the root (the regen cut), so the self-host fixed point is answered by `claim_executor --required-regen-fixed-point` and by nothing else. **THAT FLAG IS INVOKED AGAIN AS OF 2026-08-20**, so this is one re-add off the queue below rather than a standing gap. It was re-added as two `witnesses.yml` steps ordered ahead of the floor and CONSOLIDATED the same day (operator directive: the phases belong `within the witnesses step and within the gunbc binary, not at a github actions job level`) into ONE step running the phases in ONE process. **THAT 2026-08-20 DIRECTIVE IS NOW PARTLY SUPERSEDED, BY THE SAME OPERATOR, ON 2026-08-25** — `we can add it as a parallel job in github actions - we can do the same for regen now, we have more runners` / `basically i would put regen + v2 full compile in one job, and witnesses into another one`. The stated reason is a change in supply, not a change of mind about the earlier argument: the phases are mutually independent, so composing them into one process made the required check's wall clock a SUM of things that could have been a MAX, and more runners make the MAX purchasable. **THE DIRECTIVE HAS TWO HALVES AND ONLY ONE IS SUPERSEDED, which is why this clause states both rather than replacing one ruling with another.** SURVIVES — *within the gunbc binary*: the phases still live in `claim_executor`, each job makes ONE invocation and names a LANE, and no step's precondition reads another phase's verdict. The step-ladder defect the consolidation fixed (an `if:` naming a sibling step, silently conjoined with GitHub's implicit `success()`, so a regen red disarmed the whole floor) cannot return, because no step's condition can reach another phase's outcome. SUPERSEDED — *not at a github actions job level*: PARALLELISM IS NOT EXPRESSIBLE IN THE BINARY. Two phases running concurrently means two runners, two checkouts and two toolchains, and one process on one runner can thread but cannot acquire a second machine — nor would we want it to, at the floor's measured ~9.4 GiB peak. So the lane boundary is a job boundary of necessity, and what the directive was protecting against — SEQUENCING and PRECONDITIONS leaking into YAML — is exactly what does not cross it: the two jobs carry no `needs` edge and no condition on each other, which is the whole content of running them in parallel. So the invocation named at the top of this paragraph is superseded three times over and is now, exactly: TWO LANE JOBS, `claim_executor --required-ci --source-root dag --source-root src/v2 --required-lane build` (regen's first-generation comparison, the v2-emission compile, the emitted-closure cargo phase and the partition-crate boundary) and the same command with `--required-lane witnesses` (the `.dag` parse sweep and the witness floor fold), plus a THIRD job that gates on both. **THAT THIRD JOB IS NOT DECORATION AND THE FIRST CUT OF THE SPLIT DID NOT HAVE IT, which is the more useful half of this entry.** A GitHub required status check is produced by the JOB, not by the workflow, and the repository's `passing CI` ruleset is active, carries NO bypass actors, and names exactly ONE required context: `witnesses`. So splitting the phases into a second job made regen and v2-emission NON-BLOCKING -- the required check would have gone green over a regen drift or a v2 emission break and the PR would have been mergeable. That is fail-open (§5), and strictly worse than the serial run it replaced, because the serial job carried every phase into the one context that gates. THE REPAIR IS AN AGGREGATION JOB RATHER THAN A RULESET EDIT: the floor lane is renamed `floor`, and the name `witnesses` moves to a job that `needs` both lanes and whose only step reads both results and exits nonzero unless both are `success`. **THE CONDITION THAT MAKES THAT JOB RUN IS AT THE JOB LEVEL, AND THE FIRST CUT OF THE AGGREGATOR PUT IT ONLY ON THE STEP** -- the same fail-open committed one level in, caught by review 55795 and independently by a peer session within minutes of each other. `needs` carries an implicit job-level condition: a job that declares `needs` and no `if` is SKIPPED when a needed job fails, a skipped job never reaches its steps, and a step-level `always()` cannot rescue a job that never started. The job therefore declares `always()`, and that is the ONE place in the emission that departs from the file's `!cancelled()` house guard, stated here because a reader who knows the convention will otherwise correct it back and reopen the hole. Every other guard decides whether a STEP runs inside a job that is already running; this one decides WHETHER THE REQUIRED CONTEXT EXISTS AT ALL, and under `!cancelled()` a cancelled run leaves it skipped rather than answered. That turns the outcome on a question about GitHub nobody here has executed -- does a skipped or cancelled required check block a merge -- and the right response is not to measure it but to make the answer not matter: under `always()` the job always runs, always reads both results, and always reports on its own terms, so SKIPPED disappears from the required context. Construction over validation (§5), at the cost that a lawfully superseded run now reports this context red rather than cancelled, which is the correct reading rather than a regression. The two lane jobs still carry no `needs` edge on each other and still start together; only the aggregator waits. A ruleset edit would have worked too and was rejected on a boundary this document already records: the ruleset is not a `.dag` fact, so landing a change whose safety depends on someone editing a setting afterwards is a coverage gap with a promise attached and a real unguarded window. **THAT BOUNDARY MOVED, AND THE DECISION IT SUPPORTED DOES NOT.** `gunbc.repo_ruleset` now declares the desired ruleset -- enforcement, target, ref-name condition, the three rules, and the ONE required context, imported from `gunbc.witness_floor_workflow` `witness_floor_workflow_job_id` rather than spelled a second time -- observes the live one through `extdeps.github.rulesets`, reconciles the context roster through `gunbc.membership_reconcile`, applies drift with the whole-ruleset PUT, and READS BACK, claiming convergence only from the second observation and never from the apply's own 200. So the sentence in this bullet stating what the ruleset requires is no longer the only place that fact lives on our side of the boundary: `converge` actuates it and `verify` refuses on any divergence, with a typed reason per way it can diverge. WHAT DID NOT CHANGE, and why the aggregation job stays: convergence is an ACTUATION WITH A READ-BACK, not a wall. Nothing in this repository can constrain what GitHub admits to main, so an in-repo authority still cannot make a required context exist at the moment a merge is attempted -- it can only declare, apply and detect. The first cut's window argument therefore stands on its own terms; what is closed is the invisibility, not the boundary. WHAT IS NOT CLAIMED: NEITHER ENTRY POINT IS ENROLLED IN CI. `verify` is a route somebody runs, and until a required phase invokes it the class sits at *mitigatable* -- a drift is now detectable rather than detected, which is a real climb from unobservable and is not the same as a gate. Its next-rung trigger is that enrolment, which is a separate change under its own operator agreement. Found in review of gunbc#9203, against the live ruleset rather than against the workflow -- which is the only place the fact is visible, since nothing in the emitted YAML says which of its jobs gates. The partition is total by construction — `RequiredCiPhase::lane` is an exhaustive match, so a phase belonging to no job fails to compile rather than going silently unmeasured — and the lane is the ONLY thing the transport names: which phases a lane owns is decided in the binary, never in the YAML. **THE v2-EMISSION PHASE'S SUBJECT WIDENED IN THE SAME CHANGE**, from `dag/std/abi.dag` (the smallest entry in the tree) to `src/v2/compiler/00_compile.dag` (the v2 pipeline root, the widest closure one entry names). The row is `gunbc.ci_layer_roots` `required_v2_emission_entries` and it remains a cost decision rather than a Rust edit; what changed is the denominator, since the build lane's cost is now free up to the floor's duration rather than added to it. **WHAT THE SPLIT DOES NOT DO:** it restores nothing else from the deleted floor machinery — every item on the unguarded list above is still its own re-add under its own operator agreement — and it lands NO ratchet over the v2 compile's advisory-diagnostic population. That population is real and is the natural next subject, but a merge-blocking count pinned to a number measured on the current tree is exactly the oracle §5 forbids; an identity-grain monotone debt contract is a separate construction and is not claimed here. **THE PARSE PHASE STOPPED BEING src/v1-ONLY, 2026-08-23**, and it is stated here because the previous revision named the phase by the one root it walked. It now sweeps `src/v1`, `dag` and `src/v2` from one roster (`v1_compiler.cli_run` `DAG_PARSE_SWEEP_ROOTS`), shared with the standalone bin, and it admits source annotations per file rather than parsing alone -- `tokenize` routes `//` into the annotation channel and `parse` never decides grain, so the old walk returned clean for a file carrying an in-body annotation and the §4c refusal surfaced only at the floor's strict PREPARATION, where no witness executes at all. That is not a widening of the floor's source roots, which `gunbc.ci_layer_roots` `v1_dead_witness_tree_triage_receipt_remainder` rules out on NAME RESOLUTION grounds: this walk resolves nothing across files, so that objection cannot reach it. **THE PHASE ROSTER WAS CUT TO THREE BY OPERATOR RULING, 2026-08-21, WAS FOUR AGAIN AS OF #9035, AND IS FIVE AS OF THE PARTITION-CRATE PHASE, AND IS SIX AS OF THE EMIT-COMPILE PHASE.** The count is stated in the present tense here and it has now been wrong in BOTH directions, which is the reason it is written as a measurement rather than as a recollection: an earlier revision said four while enumerating a determinism pass no required run performed, that was corrected to three, and the three then went stale when #9035 enrolled a v2-emission phase that compiles one v2 entry — landed precisely because an emission break reached main and no gate could see it. The instrument is the required mode itself, which prints its own roster before any phase runs -- one `phase ` line per phase the lane owns and one `ROUTED to lane ` line per phase it does not, then `lane= phases_run=`. Read the roster from that announcement rather than from this sentence: the count moved twice in five days, and a transcribed roster size is exactly the positional citation the ruling above forbids. The fifth phase is `partition-crates`, in the build lane, which compares the derived stage0 partition's committed `lib.rs` and `Cargo.toml` against what `v1.compiler.stage0_crates` renders from the authority -- landed because those seven crates are workspace members nothing in CI builds, so a broken one sat on main while every required lane stayed green. **THAT COUNT IS NOW A PROPERTY OF THE ROSTER AND NOT OF A RUN**, because the 2026-08-25 split partitions the four across two jobs: a lane's own summary line reports `lane= phases_run=`, and each job additionally prints a `ROUTED to lane ` line for every phase it does not own, so one job's log still names the whole roster and where the rest is being measured. Reading a single job's `phases_run` as the roster size is the error that line exists to prevent. **A SIXTH PHASE, `generated-artifact`, IS THE FIRST ITEM TAKEN OFF THE UNGUARDED LIST ABOVE RATHER THAN A NEW SUBJECT.** It adjudicates every member of `gunbc.generated_artifact` `committed_generated_artifacts` against what its own authority generates, through the pure per-path projection `gunbc.generated_artifact_emit` `generated_artifact_body_for_path`, hosted by `v1_compiler.cli_run` `run_generated_artifact_boundary` in the build lane. THE PRODUCER WAS NEVER MISSING AND THE CALLER WAS, which is why this is a re-add and not a construction: `main_wet` on `dag/tools/generated_artifact_gate.dag` has always written these files and the projection has always been able to say what each path ought to hold, but from the floor cut until this phase the only route that ASKED it was `claim_executor`'s behavioural-receipt census, which asks only about paths of the form `src/v1/stage0/src/` because its subject is emitted Rust mirrors. So `DESIGN.md` and `ROADMAP.md` -- projections of `gunbc.design_document` and `gunbc.roadmap_authority` -- were computed by nothing and compared by nothing, and were maintained BY HAND in lockstep with their authorities. That is not a hypothetical: gunbc#9392 found the accumulated result the only way an unguarded artifact is ever found, by accident while doing something else, 2198 characters into the drift, and this document's own §4b(3) clause was among the text standing in the artifact with no authority behind it. **AND THE FIRST THING IT FOUND WAS NOT DRIFT, WHICH IS THE REUSABLE HALF.** Two of its four opening reds were ABSENT rather than drifted, and one of those markdown files had been DELETED ON PURPOSE by a295e17415, whose entire subject is the ruling that the .dag carrier is the authority. Regenerating it would have performed exactly what that commit refused, and the gate would then have gone green over the resurrection -- enforcing, permanently, the reverse of a decision already taken. THE GENERAL SHAPE: **a drift gate makes whatever it adjudicates BINDING**, so an absence that was inert before the gate becomes a line-stop after it, and the cheapest way to move the line is to regenerate. A dormant registry mistake is thereby converted into a standing obligation to recreate deleted files, silently, because the green looks identical either way. The stale half is the REGISTRY ROW and not the missing file, so the repair runs the other way: `gunbc.plan` `PlanProjection` makes a plan declare whether its markdown is a committed artifact at all, `PlanIsAuthorityOnly` carries the ruling that removed the projection, and the plan stays rostered, generated and refusable -- only whether its bytes are expected on disk changes. The rule for the next gate: **before a new adjudicator's first red is closed by producing the thing it says is missing, establish that the thing was ever supposed to exist.** WHAT THE PHASE DOES NOT CLAIM: it is READ-ONLY by construction -- there is no write path in it and no flag that opens one, because a gate that can also write its own subject is a gate whose green proves nothing -- and it restores nothing else from the deleted machinery; heal, the seven effect gates, the fmt gate, merge-admission stamping and the falsifier cadence remain their own re-adds. Its roster is ASKED of the authority, so an artifact added to `generated_artifact_registry` is enrolled with no edit to the host, and a rostered member that reaches NO verdict is counted and reported separately from a drifted one and stops the line on its own -- `0 drifted` over a population nothing asked about is the execution-provenance loss this document names, and the two counts are what keep it unrepresentable. **THAT COUNT IS NOW A PROPERTY OF THE ROSTER AND NOT OF A RUN**, because the 2026-08-25 split partitions the four across two jobs: a lane's own summary line reports `lane= phases_run=`, and each job additionally prints a `ROUTED to lane ` line for every phase it does not own, so one job's log still names the whole roster and where the rest is being measured. Reading a single job's `phases_run` as the roster size is the error that line exists to prevent. The five phases the 2026-08-21 ruling deleted stay deleted and are enumerated below; neither #9035 nor the partition-crate phase restored any of them, each added a new one, so both are roster ADDITIONS and not a reversal of that ruling. Five phases were deleted from the mode: merge-admission-capture, the regen determinism (fixed-point) pass and its in-memory pass-1 digest handoff, the behavioral receipt's controlled-fixture selftest, the behavioral receipt against the authorities a diff changed, and merge-admission-stamp. They were deleted rather than left reporting SKIPPED, because a phase whose only reachable state is a non-verdict has a deficit frequency of zero by construction and still reads as coverage on the ledger (§5, the absorbing fallback). The capabilities survive at their own entry points — `--required-regen-fixed-point`, `//gunbc/instruments:behavioral-receipt-plan`, `//gunbc/instruments:behavioral-receipt-selftest`, `//gunbc/instruments:behavioral-receipt-census` — none of which any workflow invokes; what ended is their enrolment in the required run, and the three measurements they carried (regen determinism, behavioural equivalence of a changed authority against its mirror, and the receipt's own discriminating arms) are simply no longer taken. That is a declared scope narrowing, and it returns merge-admission stamping to the unguarded list above rather than removing it from it. The remaining three phases are independent — the one real data dependency left with the phase that consumed it — so every phase runs even after an earlier failure and the run reports the complete ledger instead of letting the first defect hide the rest. The line still stops on any failed phase. It is recorded here with what made the gap real, because the steps were enrolled, STRIPPED, and re-enrolled inside twelve hours and a reader who finds only the enrolment will re-derive the strip. The strip was correct when made: the admission test is whether every red is closable by the author who caused it at the moment they caused it, and it was not -- the comparator normalized BOTH sides through rustfmt while writing the single-pass form, so after any candidate install the comparison was `normalize(normalize(emitted))` against `normalize(emitted)`, an identity only if rustfmt is idempotent. It is not, so the gate refused a tree byte-identical to its own artifact, permanently, and its only reachable green was the hand-edited mirror the gate exists to refuse -- a gate whose sole closing move is the forbidden action is not strict, it launders. Repairing it by raw-comparing the single-pass bytes then put it in direct contradiction with `cargo fmt --all --check`, which re-formats what is committed and so demands the NEXT pass: two gates consuming different passes of one artifact, each breaking the other. The resolution is that the emitted artifact is now written as a FIXED POINT of the formatter (bounded, exceeding the bound is a typed refusal), which makes the contradiction unrepresentable rather than detected and makes `cargo fmt` a no-op on it by definition -- the §5 construction move, and the general lesson is that any artifact with two consumers that normalize it must be stored in the normalizer's fixed point or the two consumers cannot both be satisfied. This clause previously read that the fixed point and its closure both survived with only their job removed; that was true when written and the regen cut falsified its first half, so it is rewritten here rather than annotated — a second sentence beside it would be two accounts of one fact; and parse remains grammar-owned — `ingest_yaml_source` (`dag/extdeps/languages/yaml/ingest.dag`), no shell or host parser — which was never a floor fact at all and is restated here so that dropping the bullet does not drop it. **TWO OPERATOR RULINGS ALSO LIVED IN THE REPLACED BULLET AND STILL HOLD**, restated because a ruling about what CI does *not* do is invisible once the paragraph describing CI is rewritten, and nothing in the new mechanism would contradict it loudly: the Rust test suite was removed from CI 2026-07-11 (operator ruling, recorded at `gunbc.commit_workflow` `commit_gate_rust_suite_removed_disposition`) and runs locally only; and clippy was removed from CI 2026-07-08, because a crate-wide `#![allow(clippy::all)]` made it zero-signal over ~44 minutes per run, leaving it a local dev check. Neither is reinstated by the replacement, and neither is the floor cut's to reverse."), li(text: "**THE MEASUREMENT BANKRUPTCY DELETED A CAPABILITY, NOT ONLY ARTIFACTS, AND THIS ROW IS THAT DECLARATION (2026-08-24).** The bankruptcy above removed `docs/probes/` whole. Deleting the boards removes TRANSCRIPTIONS, which is the point; deleting the instruments removes a ROUTE, which is a different fact and is the one §4b(3) obliges a cut to declare. WHAT IS GONE: the only executable route to a self-host emission board measurement. PREVIOUS STATE — any lane could re-derive a per-entry board by running the committed probe script, last exercised 2026-08-24 against the then-current main, and that reading is what answered the operator when they asked what the emission trajectory was doing. TEMPORARY STATE — no route exists; the emission trajectory is not measurable from the tree, and a board figure quoted from here on names nothing that can produce it. BOUNDED POPULATION: one capability, the per-entry emission board. RESTORATION TRIGGER: a `.dag` entry point that emits, assembles and compiles one entry and returns the coded-diagnostic population, cited by name wherever a board figure is quoted — at which point the same figures become legitimate again unchanged, because the rule forbids transcribing output INSTEAD OF naming an instrument, and the defect today is that there is no instrument to name. **WHY THIS ROW EXISTS AT ALL, and it is the same reason the regen row beneath it does:** no dependent could refuse. The corpus contains nothing that breaks when the board becomes unmeasurable, because the consumers are LANES rather than modules — the identical blind spot that made a `.dag`-consumer census report the instruments as dead a few hours before this cut. So delete-first's census, which is normally the thing that surfaces a load-bearing deletion loudly, is structurally silent here, and a declared row is the only mechanism left. **THE TRIGGER HAS FIRED, AND THE ROW STAYS RATHER THAN RETIRING ON ITS AUTHOR'S SAY-SO.** The instrument is `tools.emission_entry_instrument` `measure_entry_emission`, invoked as `gunbc run --source-root dag --source-root src/v2 --entry dag/tools/emission_entry_instrument.dag --function measure --arg entry= --arg report=`. It runs the same spine the deleted probe script ran — emit one entry's closure, assemble it with `cssl_assemble`, build the assembled crate under cargo's JSON message format — and returns a TYPED measurement rather than a row of text: the emit-stage population from `gunbc.emit_diagnostic_observation` and the rustc coded-diagnostic population from `extdeps.cargo_diagnostic`, each member carrying its own identity and location, so two runs can be JOINED rather than only differenced. **WHAT THE CARRIER FIXES THAT THE SCRIPT DID NOT:** `EmissionMeasurement` has no spelling in which a stage that never ran renders as a stage that ran and found nothing — an unreached stage is its own variant naming the stage — and the emit decode REFUSES when the population it recovered disagrees with the compiler's own declared total, so an unrecognised diagnostic shape stops the line instead of quietly shrinking the answer. That is the execution-provenance-loss row applied to the instrument that most needed it. **WHAT IS NOT CLAIMED.** It is a measurement route and NOT a gate: no workflow invokes it, no phase enrols it, and its exit status reports whether the INSTRUMENT completed, never whether the subject was clean. The whole-corpus route is still refused by `gunbc.whole_corpus_compile_admission` and this does not change that; it is the per-entry route that module's own scope note says fits. Every other clause of the bankruptcy above stands unchanged, including that a figure copied into prose is debt whether or not a producer exists for it.") li(text: "**THE REGEN CUT DELETED A PRODUCER ALONG WITH ITS BINARY, DECLARED NOTHING, AND THIS ROW IS THAT DECLARATION (2026-08-20).** It sits beside the CI entry above rather than inside it, because the two are different facts on different clocks — that paragraph narrates what the floor and regen cuts removed, this row declares one capability the regen cut removed in silence — and because a declaration wedged into the repository's most-edited paragraph collides with every unrelated edit to it (three merge conflicts in two hours, each one re-resolving prose neither side had touched). The regen cut re-derived the deleted binary's VERIFIER half — `claim_executor --required-regen`, which compares the committed stage0 mirror against a fresh emit — and did not re-derive its PRODUCER half: writing the emitted tree to disk unconditionally, whatever the comparison then says about it. `run_required_regen` did write a candidate tree, but only on the path where the emitted and committed populations already agreed; every refusal arm returned ahead of the write. The one population asymmetry an author can actually cause is adding a module to the v1 seed closure — its mirror is emitted-not-committed by construction on the first commit that introduces it — so from the cut until this entry, that change refused while naming a file no sanctioned route in the repository produced, and its only reachable green was a hand-authored mirror. That is the same laundering the fixed-point repair above closed one gate over, arrived at from the other direction: there, the gate's only closing move was forbidden; here, the gate's only closing move did not exist. WHAT THE RUNG DROP IS, stated at the honest grain: the class is not a compiler guarantee that fell a rung, it is an OPERATION that lost its only route, so it sat outside the ladder entirely — nothing to mitigate, because nothing could be attempted. Naming it as a declared drop rather than a defect is the point of the entry: the regen cut owed one under §4b(3) and filed none, and a capability deleted in silence is exactly what §3's delete-first doctrine says the census is supposed to surface loudly. It did not surface because no dependent could refuse — the author who needed the producer was outside the tree. THE RESTORATION, and its rung: production now precedes adjudication. `v2.workflow.required_regen` `required_regen_run` is the authority, and it holds the ordering by construction rather than by check — every arm that reports a verdict carries the `CandidateTree` the verdict was computed against, so refused-with-no-tree has no spelling once emit succeeded, and the one tree-less arm is reachable only where emit produced nothing at all (*structurally guaranteed*, §4b). The host `v1_compiler.required_regen_host` `run_required_regen` mirrors that ordering by hand and is therefore only *mitigatable*; its next-rung trigger is the host being derived from the carrier rather than written beside it. The gate did not weaken: it refuses the same populations with the same typed causes, and the refusal now names the directory holding the first mirror the author must install."), diff --git a/dag/gunbc/dispatch_pipe_pane_emit.dag b/dag/gunbc/dispatch_pipe_pane_emit.dag index 6b34fb2ca41..1b7fa2b3474 100644 --- a/dag/gunbc/dispatch_pipe_pane_emit.dag +++ b/dag/gunbc/dispatch_pipe_pane_emit.dag @@ -7,7 +7,7 @@ import v2.workflow.bash_command_fold_serialize { bash_fold_serialize_node } import v2.std.diagnostic { Accepted, Rejected } import v2.std.node { Node } -data dispatch_event_pipe_emit_note: String = "review 44063. tmux pipe-pane's input contract IS one shell-command string, so the SEAM is permanent — but the payload is no longer hand-assembled. dispatch_event_pipe_intent builds the command as a bash AST (one command, five literal words) and dispatch_event_pipe_emission renders it through the signed v2.workflow.bash_command_fold_serialize backend, which is the same grammar the ingest side reads forward (DESIGN 4, one grammar read in both directions). This module exists BECAUSE the payload construction has to sit on a realization edge: v2.lens.realization_vocabulary_containment confines the bash-AST vocabulary to realization_edge_path_prefixes, and dag/gunbc/roadmap_dispatch_actuator.dag is a workflow module, not an emitter. The split is the containment rule working as designed, not an exception to it — the precedent is dag/gunbc/live_deploy/emit. Quoting is now the grammar's job, not the caller's: the lit-word production single-quotes every word and escapes an embedded quote, so extdeps.exec.command.shell_quote is no longer applied at this site. Verified by execution that the emitted spelling is behaviourally identical for this payload — a quoted command name still resolves the exec builtin (quoting suppresses alias and reserved-word recognition, not builtin lookup)." +data dispatch_event_pipe_emit_note: String = "review 44063. tmux pipe-pane's input contract IS one shell-command string, so the SEAM is permanent — but the payload is no longer hand-assembled. dispatch_event_pipe_intent builds the command as a bash AST (one command, five literal words) and dispatch_event_pipe_emission renders it through the signed v2.workflow.bash_command_fold_serialize backend, which is the same grammar the ingest side reads forward (DESIGN 4, one grammar read in both directions). This module exists BECAUSE the payload construction has to sit on a realization edge: v2.lens.realization_vocabulary_containment confines the bash-AST vocabulary to realization_edge_path_prefixes, and dag/gunbc/roadmap/roadmap_dispatch_actuator.dag is a workflow module, not an emitter. The split is the containment rule working as designed, not an exception to it — the precedent is dag/gunbc/live_deploy/emit. Quoting is now the grammar's job, not the caller's: the lit-word production single-quotes every word and escapes an embedded quote, so extdeps.exec.command.shell_quote is no longer applied at this site. Verified by execution that the emitted spelling is behaviourally identical for this payload — a quoted command name still resolves the exec builtin (quoting suppresses alias and reserved-word recognition, not builtin lookup)." fn dispatch_event_pipe_intent(tee_program: String, events_path: String) -> Node { bash_build_command_from_lits(lits: [ diff --git a/dag/gunbc/emitted_closure_compile_seed_growth.dag b/dag/gunbc/emitted_closure_compile_seed_growth.dag index 637270466a0..e1da77f9e1c 100644 --- a/dag/gunbc/emitted_closure_compile_seed_growth.dag +++ b/dag/gunbc/emitted_closure_compile_seed_growth.dag @@ -78,5 +78,5 @@ data emitted_closure_compile_seed_growth_justification: SeedGrowthJustification reason: "WHY RUST IS STILL NEEDED, and it is a REACHABILITY limit rather than a modeling gap. The subject is a required CI phase: it must run inside claim_executor, which is the only witness-executing consumer in the tree, and its stages are host effects -- writing an emitted tree to disk and spawning cargo over it. The required floor's hermetic envelope REFUSES host effects during preparation, so a .dag witness whose subject is a subprocess exit status is counted executed while its assertion never runs; DESIGN's Building-&-checks section records that boundary in as many words, and records that mocking the refusal would pass the witness against a fabricated exit status. So the phase has to live where the effects do, exactly as required_regen_host and partition_crate_boundary_host do.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE, ON PRECEDENT RATHER THAN ANALOGY. gunbc.v1_maintenance_standing v1_seed_standing admits a change by PURPOSE -- does it serve the v2 self-host program -- and the purpose test reaches the INSTRUMENT that measures that program, not only the program. This is that instrument in the most direct available sense: the self-host claim IS that the emitted tree compiles and behaves, and until now nothing on the merge path compiled an emitted tree at all. gunbc.floor_non_verdict_enrollment and gunbc.declaration_index_seed_growth are both admitted on that same footing. Classified against the five refused classes: NewLanguageBehavior -- no, the compile pipeline is byte-untouched, no diagnostic is added, moved or removed. NewCompatibilityObligation -- no, nothing is kept working for an old caller. NewEscapeHatchOrAdmissionRow -- no, and the direction is opposite: this adds a wall and adds no flag, env var or mode that skips it. SeedFeatureCompletion -- no, the seed compiler gains no capability; it compiles exactly what it compiled before. PublicSurfaceGrowth -- the nearest, and the test is a diff over THE EMITTED SEED'S EXPORTED DECLARATIONS: the file is wired by #[path] mod inside cli_run.rs exactly as declaration_index.rs, phase_profile.rs and partition_crate_boundary_host.rs are, so it contributes no pub mod line to the emitted lib.rs and its SeedRetainedIntrinsicRegistration carries has_pub_mod: false.\n\nWHAT IS NOT CLAIMED. This phase is not a compile of the corpus and must not be read as one: gunbc.whole_corpus_compile_admission refuses a whole-bundle compile on the default runner and records two EXIT=137 kills behind that refusal, so the subject is a bounded roster of entries in gunbc.ci_layer_roots required_emit_compile_entries. It carries no diagnostic count, no baseline and no ratchet -- a merge-blocking comparison against a population measured on the current tree is the tree-copied oracle DESIGN 5 rejects.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete this host when the phase's two host effects are modeled and a modeled actuator can perform them: writing an emitted file set to a directory, and invoking cargo over a manifest with a typed outcome. extdeps.cargo already models the manifest, the dependency rows and the target kinds, and extdeps.filesystem.filesystem_io models the write, so what is missing is the ACTUATION -- a modeled operation the required run can execute without the hermetic envelope refusing it. When that exists, run_emit_compile_entry becomes a .dag fold over those two operations and every item here is deleted, not re-homed. A PARTIAL migration is admissible and is the expected shape: the moment the cargo invocation is a modeled transport, run_cargo and the CargoVerdict vocabulary go first and the emission-to-disk half stays behind. What does NOT dissolve these items is the phase merely changing its roster, and what does NOT dissolve them is a hermetic witness asserting a fabricated exit status -- that would retire the evidence while retiring nothing it guards.", - current_boundary: "src/v1/stage0/src/emitted_closure_compile_host.rs; src/v1/stage0/src/cli_run.rs (the #[path] mod line and the re-export); src/v1/stage0/src/bin/claim_executor.rs (RequiredCiPhase::EmitCompile and its phase body); dag/gunbc/ci_layer_roots.dag required_emit_compile_entries; src/v2/compiler/self_host/stage0_crate_layout.dag; dag/gunbc/emitted_closure_compile_seed_growth.dag" + current_boundary: "src/v1/stage0/src/emitted_closure_compile_host.rs; src/v1/stage0/src/cli_run.rs (the #[path] mod line and the re-export); src/v1/stage0/src/bin/claim_executor.rs (RequiredCiPhase::EmitCompile and its phase body); dag/gunbc/ci/ci_layer_roots.dag required_emit_compile_entries; src/v2/compiler/self_host/stage0_crate_layout.dag; dag/gunbc/emitted_closure_compile_seed_growth.dag" } diff --git a/dag/gunbc/fabric_capacity_class_gap.dag b/dag/gunbc/fabric/fabric_capacity_class_gap.dag similarity index 100% rename from dag/gunbc/fabric_capacity_class_gap.dag rename to dag/gunbc/fabric/fabric_capacity_class_gap.dag diff --git a/dag/gunbc/fabric_cell_acquire.dag b/dag/gunbc/fabric/fabric_cell_acquire.dag similarity index 100% rename from dag/gunbc/fabric_cell_acquire.dag rename to dag/gunbc/fabric/fabric_cell_acquire.dag diff --git a/dag/gunbc/fabric_cell_converge.dag b/dag/gunbc/fabric/fabric_cell_converge.dag similarity index 100% rename from dag/gunbc/fabric_cell_converge.dag rename to dag/gunbc/fabric/fabric_cell_converge.dag diff --git a/dag/gunbc/fabric_cell_effect.dag b/dag/gunbc/fabric/fabric_cell_effect.dag similarity index 100% rename from dag/gunbc/fabric_cell_effect.dag rename to dag/gunbc/fabric/fabric_cell_effect.dag diff --git a/dag/gunbc/fabric_cell_host_root.dag b/dag/gunbc/fabric/fabric_cell_host_root.dag similarity index 100% rename from dag/gunbc/fabric_cell_host_root.dag rename to dag/gunbc/fabric/fabric_cell_host_root.dag diff --git a/dag/gunbc/fabric_cell_observation_admission.dag b/dag/gunbc/fabric/fabric_cell_observation_admission.dag similarity index 100% rename from dag/gunbc/fabric_cell_observation_admission.dag rename to dag/gunbc/fabric/fabric_cell_observation_admission.dag diff --git a/dag/gunbc/fabric_cell_observe.dag b/dag/gunbc/fabric/fabric_cell_observe.dag similarity index 100% rename from dag/gunbc/fabric_cell_observe.dag rename to dag/gunbc/fabric/fabric_cell_observe.dag diff --git a/dag/gunbc/fabric_cell_subject.dag b/dag/gunbc/fabric/fabric_cell_subject.dag similarity index 100% rename from dag/gunbc/fabric_cell_subject.dag rename to dag/gunbc/fabric/fabric_cell_subject.dag diff --git a/dag/gunbc/fabric_control_plane.dag b/dag/gunbc/fabric/fabric_control_plane.dag similarity index 100% rename from dag/gunbc/fabric_control_plane.dag rename to dag/gunbc/fabric/fabric_control_plane.dag diff --git a/dag/gunbc/fabric_control_plane_charge.dag b/dag/gunbc/fabric/fabric_control_plane_charge.dag similarity index 100% rename from dag/gunbc/fabric_control_plane_charge.dag rename to dag/gunbc/fabric/fabric_control_plane_charge.dag diff --git a/dag/gunbc/fabric_executor_class.dag b/dag/gunbc/fabric/fabric_executor_class.dag similarity index 100% rename from dag/gunbc/fabric_executor_class.dag rename to dag/gunbc/fabric/fabric_executor_class.dag diff --git a/dag/gunbc/fabric_floor_dispatch.dag b/dag/gunbc/fabric/fabric_floor_dispatch.dag similarity index 100% rename from dag/gunbc/fabric_floor_dispatch.dag rename to dag/gunbc/fabric/fabric_floor_dispatch.dag diff --git a/dag/gunbc/fabric_witness_run.dag b/dag/gunbc/fabric/fabric_witness_run.dag similarity index 100% rename from dag/gunbc/fabric_witness_run.dag rename to dag/gunbc/fabric/fabric_witness_run.dag diff --git a/dag/gunbc/fleet_bmc_firmware_evidence.dag b/dag/gunbc/fleet/fleet_bmc_firmware_evidence.dag similarity index 100% rename from dag/gunbc/fleet_bmc_firmware_evidence.dag rename to dag/gunbc/fleet/fleet_bmc_firmware_evidence.dag diff --git a/dag/gunbc/fleet_bmc_observation.dag b/dag/gunbc/fleet/fleet_bmc_observation.dag similarity index 100% rename from dag/gunbc/fleet_bmc_observation.dag rename to dag/gunbc/fleet/fleet_bmc_observation.dag diff --git a/dag/gunbc/fleet_bmc_state.dag b/dag/gunbc/fleet/fleet_bmc_state.dag similarity index 100% rename from dag/gunbc/fleet_bmc_state.dag rename to dag/gunbc/fleet/fleet_bmc_state.dag diff --git a/dag/gunbc/fleet_capacity_control.dag b/dag/gunbc/fleet/fleet_capacity_control.dag similarity index 100% rename from dag/gunbc/fleet_capacity_control.dag rename to dag/gunbc/fleet/fleet_capacity_control.dag diff --git a/dag/gunbc/fleet_capacity_panel.dag b/dag/gunbc/fleet/fleet_capacity_panel.dag similarity index 100% rename from dag/gunbc/fleet_capacity_panel.dag rename to dag/gunbc/fleet/fleet_capacity_panel.dag diff --git a/dag/gunbc/fleet_container.dag b/dag/gunbc/fleet/fleet_container.dag similarity index 100% rename from dag/gunbc/fleet_container.dag rename to dag/gunbc/fleet/fleet_container.dag diff --git a/dag/gunbc/fleet_converge_apply.dag b/dag/gunbc/fleet/fleet_converge_apply.dag similarity index 100% rename from dag/gunbc/fleet_converge_apply.dag rename to dag/gunbc/fleet/fleet_converge_apply.dag diff --git a/dag/gunbc/fleet_converge_cli.dag b/dag/gunbc/fleet/fleet_converge_cli.dag similarity index 100% rename from dag/gunbc/fleet_converge_cli.dag rename to dag/gunbc/fleet/fleet_converge_cli.dag diff --git a/dag/gunbc/fleet_converge_plan.dag b/dag/gunbc/fleet/fleet_converge_plan.dag similarity index 100% rename from dag/gunbc/fleet_converge_plan.dag rename to dag/gunbc/fleet/fleet_converge_plan.dag diff --git a/dag/gunbc/fleet_converge_plan_cli.dag b/dag/gunbc/fleet/fleet_converge_plan_cli.dag similarity index 100% rename from dag/gunbc/fleet_converge_plan_cli.dag rename to dag/gunbc/fleet/fleet_converge_plan_cli.dag diff --git a/dag/gunbc/fleet_converge_timer.dag b/dag/gunbc/fleet/fleet_converge_timer.dag similarity index 100% rename from dag/gunbc/fleet_converge_timer.dag rename to dag/gunbc/fleet/fleet_converge_timer.dag diff --git a/dag/gunbc/fleet_converge_workflow.dag b/dag/gunbc/fleet/fleet_converge_workflow.dag similarity index 100% rename from dag/gunbc/fleet_converge_workflow.dag rename to dag/gunbc/fleet/fleet_converge_workflow.dag diff --git a/dag/gunbc/fleet_convergence_verdict.dag b/dag/gunbc/fleet/fleet_convergence_verdict.dag similarity index 100% rename from dag/gunbc/fleet_convergence_verdict.dag rename to dag/gunbc/fleet/fleet_convergence_verdict.dag diff --git a/dag/gunbc/fleet_desired_admission.dag b/dag/gunbc/fleet/fleet_desired_admission.dag similarity index 100% rename from dag/gunbc/fleet_desired_admission.dag rename to dag/gunbc/fleet/fleet_desired_admission.dag diff --git a/dag/gunbc/fleet_desired_admission_workflow.dag b/dag/gunbc/fleet/fleet_desired_admission_workflow.dag similarity index 99% rename from dag/gunbc/fleet_desired_admission_workflow.dag rename to dag/gunbc/fleet/fleet_desired_admission_workflow.dag index a2d8c1ad5bb..32323ffc2d1 100644 --- a/dag/gunbc/fleet_desired_admission_workflow.dag +++ b/dag/gunbc/fleet/fleet_desired_admission_workflow.dag @@ -137,7 +137,7 @@ fn fleet_desired_admission_decide_step() -> Step { run: join([ "ROOT=", ci_repo_root_shell(), "\n", "\"$ROOT/target/release/gunbc\" run --source-root dag --source-root src/v2", - " --entry dag/gunbc/fleet_desired_admission.dag", + " --entry dag/gunbc/fleet/fleet_desired_admission.dag", " --function admit_fleet_desired_from_floor_event_wet\n", ], ""), shell: none, diff --git a/dag/gunbc/fleet_desired_observe.dag b/dag/gunbc/fleet/fleet_desired_observe.dag similarity index 100% rename from dag/gunbc/fleet_desired_observe.dag rename to dag/gunbc/fleet/fleet_desired_observe.dag diff --git a/dag/gunbc/fleet_fan_acoustic_evidence.dag b/dag/gunbc/fleet/fleet_fan_acoustic_evidence.dag similarity index 100% rename from dag/gunbc/fleet_fan_acoustic_evidence.dag rename to dag/gunbc/fleet/fleet_fan_acoustic_evidence.dag diff --git a/dag/gunbc/fleet_fan_tach_expectation.dag b/dag/gunbc/fleet/fleet_fan_tach_expectation.dag similarity index 100% rename from dag/gunbc/fleet_fan_tach_expectation.dag rename to dag/gunbc/fleet/fleet_fan_tach_expectation.dag diff --git a/dag/gunbc/fleet_fan_tach_health_witness.dag b/dag/gunbc/fleet/fleet_fan_tach_health_witness.dag similarity index 100% rename from dag/gunbc/fleet_fan_tach_health_witness.dag rename to dag/gunbc/fleet/fleet_fan_tach_health_witness.dag diff --git a/dag/gunbc/fleet_fan_tach_observation.dag b/dag/gunbc/fleet/fleet_fan_tach_observation.dag similarity index 100% rename from dag/gunbc/fleet_fan_tach_observation.dag rename to dag/gunbc/fleet/fleet_fan_tach_observation.dag diff --git a/dag/gunbc/fleet_fan_wiring.dag b/dag/gunbc/fleet/fleet_fan_wiring.dag similarity index 100% rename from dag/gunbc/fleet_fan_wiring.dag rename to dag/gunbc/fleet/fleet_fan_wiring.dag diff --git a/dag/gunbc/fleet_fan_wiring_witness.dag b/dag/gunbc/fleet/fleet_fan_wiring_witness.dag similarity index 100% rename from dag/gunbc/fleet_fan_wiring_witness.dag rename to dag/gunbc/fleet/fleet_fan_wiring_witness.dag diff --git a/dag/gunbc/fleet_hardware_standing_panel.dag b/dag/gunbc/fleet/fleet_hardware_standing_panel.dag similarity index 100% rename from dag/gunbc/fleet_hardware_standing_panel.dag rename to dag/gunbc/fleet/fleet_hardware_standing_panel.dag diff --git a/dag/gunbc/fleet_host_budget.dag b/dag/gunbc/fleet/fleet_host_budget.dag similarity index 100% rename from dag/gunbc/fleet_host_budget.dag rename to dag/gunbc/fleet/fleet_host_budget.dag diff --git a/dag/gunbc/fleet_host_key_enrollment.dag b/dag/gunbc/fleet/fleet_host_key_enrollment.dag similarity index 100% rename from dag/gunbc/fleet_host_key_enrollment.dag rename to dag/gunbc/fleet/fleet_host_key_enrollment.dag diff --git a/dag/gunbc/fleet_install_transport_observations.dag b/dag/gunbc/fleet/fleet_install_transport_observations.dag similarity index 100% rename from dag/gunbc/fleet_install_transport_observations.dag rename to dag/gunbc/fleet/fleet_install_transport_observations.dag diff --git a/dag/gunbc/fleet_intent.dag b/dag/gunbc/fleet/fleet_intent.dag similarity index 100% rename from dag/gunbc/fleet_intent.dag rename to dag/gunbc/fleet/fleet_intent.dag diff --git a/dag/gunbc/fleet_intent_network.dag b/dag/gunbc/fleet/fleet_intent_network.dag similarity index 100% rename from dag/gunbc/fleet_intent_network.dag rename to dag/gunbc/fleet/fleet_intent_network.dag diff --git a/dag/gunbc/fleet_known_hosts_anchor.dag b/dag/gunbc/fleet/fleet_known_hosts_anchor.dag similarity index 100% rename from dag/gunbc/fleet_known_hosts_anchor.dag rename to dag/gunbc/fleet/fleet_known_hosts_anchor.dag diff --git a/dag/gunbc/fleet_lifecycle_observation.dag b/dag/gunbc/fleet/fleet_lifecycle_observation.dag similarity index 100% rename from dag/gunbc/fleet_lifecycle_observation.dag rename to dag/gunbc/fleet/fleet_lifecycle_observation.dag diff --git a/dag/gunbc/fleet_main_revision.dag b/dag/gunbc/fleet/fleet_main_revision.dag similarity index 100% rename from dag/gunbc/fleet_main_revision.dag rename to dag/gunbc/fleet/fleet_main_revision.dag diff --git a/dag/gunbc/fleet_multi_principal_probe.dag b/dag/gunbc/fleet/fleet_multi_principal_probe.dag similarity index 100% rename from dag/gunbc/fleet_multi_principal_probe.dag rename to dag/gunbc/fleet/fleet_multi_principal_probe.dag diff --git a/dag/gunbc/fleet_physical_inventory.dag b/dag/gunbc/fleet/fleet_physical_inventory.dag similarity index 100% rename from dag/gunbc/fleet_physical_inventory.dag rename to dag/gunbc/fleet/fleet_physical_inventory.dag diff --git a/dag/gunbc/fleet_posix_accounts.dag b/dag/gunbc/fleet/fleet_posix_accounts.dag similarity index 100% rename from dag/gunbc/fleet_posix_accounts.dag rename to dag/gunbc/fleet/fleet_posix_accounts.dag diff --git a/dag/gunbc/fleet_probe_identity_observe.dag b/dag/gunbc/fleet/fleet_probe_identity_observe.dag similarity index 100% rename from dag/gunbc/fleet_probe_identity_observe.dag rename to dag/gunbc/fleet/fleet_probe_identity_observe.dag diff --git a/dag/gunbc/fleet_reach.dag b/dag/gunbc/fleet/fleet_reach.dag similarity index 100% rename from dag/gunbc/fleet_reach.dag rename to dag/gunbc/fleet/fleet_reach.dag diff --git a/dag/gunbc/fleet_reach_endpoint.dag b/dag/gunbc/fleet/fleet_reach_endpoint.dag similarity index 100% rename from dag/gunbc/fleet_reach_endpoint.dag rename to dag/gunbc/fleet/fleet_reach_endpoint.dag diff --git a/dag/gunbc/fleet_receipt_collector.dag b/dag/gunbc/fleet/fleet_receipt_collector.dag similarity index 100% rename from dag/gunbc/fleet_receipt_collector.dag rename to dag/gunbc/fleet/fleet_receipt_collector.dag diff --git a/dag/gunbc/fleet_revision_acceptance.dag b/dag/gunbc/fleet/fleet_revision_acceptance.dag similarity index 100% rename from dag/gunbc/fleet_revision_acceptance.dag rename to dag/gunbc/fleet/fleet_revision_acceptance.dag diff --git a/dag/gunbc/fleet_runner_connectivity.dag b/dag/gunbc/fleet/fleet_runner_connectivity.dag similarity index 100% rename from dag/gunbc/fleet_runner_connectivity.dag rename to dag/gunbc/fleet/fleet_runner_connectivity.dag diff --git a/dag/gunbc/fleet_secrets_config.dag b/dag/gunbc/fleet/fleet_secrets_config.dag similarity index 100% rename from dag/gunbc/fleet_secrets_config.dag rename to dag/gunbc/fleet/fleet_secrets_config.dag diff --git a/dag/gunbc/fleet_shell_transport_observation.dag b/dag/gunbc/fleet/fleet_shell_transport_observation.dag similarity index 100% rename from dag/gunbc/fleet_shell_transport_observation.dag rename to dag/gunbc/fleet/fleet_shell_transport_observation.dag diff --git a/dag/gunbc/fleet_show_effective_read.dag b/dag/gunbc/fleet/fleet_show_effective_read.dag similarity index 100% rename from dag/gunbc/fleet_show_effective_read.dag rename to dag/gunbc/fleet/fleet_show_effective_read.dag diff --git a/dag/gunbc/fleet_ssh_access.dag b/dag/gunbc/fleet/fleet_ssh_access.dag similarity index 100% rename from dag/gunbc/fleet_ssh_access.dag rename to dag/gunbc/fleet/fleet_ssh_access.dag diff --git a/dag/gunbc/fleet_ssh_credential_verify.dag b/dag/gunbc/fleet/fleet_ssh_credential_verify.dag similarity index 100% rename from dag/gunbc/fleet_ssh_credential_verify.dag rename to dag/gunbc/fleet/fleet_ssh_credential_verify.dag diff --git a/dag/gunbc/fleet_ssh_locus.dag b/dag/gunbc/fleet/fleet_ssh_locus.dag similarity index 100% rename from dag/gunbc/fleet_ssh_locus.dag rename to dag/gunbc/fleet/fleet_ssh_locus.dag diff --git a/dag/gunbc/fleet_workflow_steps.dag b/dag/gunbc/fleet/fleet_workflow_steps.dag similarity index 100% rename from dag/gunbc/fleet_workflow_steps.dag rename to dag/gunbc/fleet/fleet_workflow_steps.dag diff --git a/dag/gunbc/floor_attempt_standing.dag b/dag/gunbc/floor/floor_attempt_standing.dag similarity index 100% rename from dag/gunbc/floor_attempt_standing.dag rename to dag/gunbc/floor/floor_attempt_standing.dag diff --git a/dag/gunbc/floor_component_receipt.dag b/dag/gunbc/floor/floor_component_receipt.dag similarity index 100% rename from dag/gunbc/floor_component_receipt.dag rename to dag/gunbc/floor/floor_component_receipt.dag diff --git a/dag/gunbc/floor_component_receipt_document.dag b/dag/gunbc/floor/floor_component_receipt_document.dag similarity index 100% rename from dag/gunbc/floor_component_receipt_document.dag rename to dag/gunbc/floor/floor_component_receipt_document.dag diff --git a/dag/gunbc/floor_cost_debt_seed_growth.dag b/dag/gunbc/floor/floor_cost_debt_seed_growth.dag similarity index 100% rename from dag/gunbc/floor_cost_debt_seed_growth.dag rename to dag/gunbc/floor/floor_cost_debt_seed_growth.dag diff --git a/dag/gunbc/floor_discovery_scaffold.dag b/dag/gunbc/floor/floor_discovery_scaffold.dag similarity index 100% rename from dag/gunbc/floor_discovery_scaffold.dag rename to dag/gunbc/floor/floor_discovery_scaffold.dag diff --git a/dag/gunbc/floor_materialization.dag b/dag/gunbc/floor/floor_materialization.dag similarity index 100% rename from dag/gunbc/floor_materialization.dag rename to dag/gunbc/floor/floor_materialization.dag diff --git a/dag/gunbc/floor_non_verdict_classification.dag b/dag/gunbc/floor/floor_non_verdict_classification.dag similarity index 100% rename from dag/gunbc/floor_non_verdict_classification.dag rename to dag/gunbc/floor/floor_non_verdict_classification.dag diff --git a/dag/gunbc/floor_non_verdict_enrollment.dag b/dag/gunbc/floor/floor_non_verdict_enrollment.dag similarity index 100% rename from dag/gunbc/floor_non_verdict_enrollment.dag rename to dag/gunbc/floor/floor_non_verdict_enrollment.dag diff --git a/dag/gunbc/floor_route_gap_seed_growth.dag b/dag/gunbc/floor/floor_route_gap_seed_growth.dag similarity index 100% rename from dag/gunbc/floor_route_gap_seed_growth.dag rename to dag/gunbc/floor/floor_route_gap_seed_growth.dag diff --git a/dag/gunbc/githooks_pre_commit_emit.dag b/dag/gunbc/githooks/githooks_pre_commit_emit.dag similarity index 97% rename from dag/gunbc/githooks_pre_commit_emit.dag rename to dag/gunbc/githooks/githooks_pre_commit_emit.dag index 3db7b46a1ea..40e86a68589 100644 --- a/dag/gunbc/githooks_pre_commit_emit.dag +++ b/dag/gunbc/githooks/githooks_pre_commit_emit.dag @@ -71,7 +71,7 @@ fn emit_pre_commit_run_fmt() -> String { fn expected_githooks_pre_commit_sh() -> String { concat( concat( - "#!/usr/bin/env bash\n# GENERATED by dag/gunbc/githooks_pre_commit_emit.dag — DO NOT HAND-EDIT.\n", + "#!/usr/bin/env bash\n# GENERATED by dag/gunbc/githooks/githooks_pre_commit_emit.dag — DO NOT HAND-EDIT.\n", "set -euo pipefail\nROOT=\"", concat(git_toplevel_shell_subexpr(), "\"\ncd \"$ROOT\"\n") ), concat(emit_repo_local_git_config_converge_shell(), concat(emit_pre_commit_staged_scan(), emit_pre_commit_run_fmt())) diff --git a/dag/gunbc/githooks_pre_push_cli.dag b/dag/gunbc/githooks/githooks_pre_push_cli.dag similarity index 100% rename from dag/gunbc/githooks_pre_push_cli.dag rename to dag/gunbc/githooks/githooks_pre_push_cli.dag diff --git a/dag/gunbc/githooks_pre_push_emit.dag b/dag/gunbc/githooks/githooks_pre_push_emit.dag similarity index 98% rename from dag/gunbc/githooks_pre_push_emit.dag rename to dag/gunbc/githooks/githooks_pre_push_emit.dag index 24107ebded0..c1f39c4f25d 100644 --- a/dag/gunbc/githooks_pre_push_emit.dag +++ b/dag/gunbc/githooks/githooks_pre_push_emit.dag @@ -92,7 +92,7 @@ fn emit_pre_push_body() -> String { fn expected_githooks_pre_push_sh() -> String { concat( - "#!/usr/bin/env bash\n# GENERATED by dag/gunbc/githooks_pre_push_emit.dag — DO NOT HAND-EDIT.\n", + "#!/usr/bin/env bash\n# GENERATED by dag/gunbc/githooks/githooks_pre_push_emit.dag — DO NOT HAND-EDIT.\n", "set -euo pipefail\nROOT=\"", concat(git_toplevel_shell_subexpr(), "\"\ncd \"$ROOT\"\n"), concat(emit_repo_local_git_config_converge_shell(), emit_pre_push_body()) ) diff --git a/dag/gunbc/githooks_pre_push_fmt_transport_scaffold.dag b/dag/gunbc/githooks/githooks_pre_push_fmt_transport_scaffold.dag similarity index 100% rename from dag/gunbc/githooks_pre_push_fmt_transport_scaffold.dag rename to dag/gunbc/githooks/githooks_pre_push_fmt_transport_scaffold.dag diff --git a/dag/gunbc/githooks_pre_push_plan.dag b/dag/gunbc/githooks/githooks_pre_push_plan.dag similarity index 100% rename from dag/gunbc/githooks_pre_push_plan.dag rename to dag/gunbc/githooks/githooks_pre_push_plan.dag diff --git a/dag/gunbc/githooks_repo_local_git_config_emit.dag b/dag/gunbc/githooks/githooks_repo_local_git_config_emit.dag similarity index 100% rename from dag/gunbc/githooks_repo_local_git_config_emit.dag rename to dag/gunbc/githooks/githooks_repo_local_git_config_emit.dag diff --git a/dag/gunbc/host_assimilation_program.dag b/dag/gunbc/host/host_assimilation_program.dag similarity index 100% rename from dag/gunbc/host_assimilation_program.dag rename to dag/gunbc/host/host_assimilation_program.dag diff --git a/dag/gunbc/host_authorized_keys_reconcile.dag b/dag/gunbc/host/host_authorized_keys_reconcile.dag similarity index 100% rename from dag/gunbc/host_authorized_keys_reconcile.dag rename to dag/gunbc/host/host_authorized_keys_reconcile.dag diff --git a/dag/gunbc/host_axis_caps.dag b/dag/gunbc/host/host_axis_caps.dag similarity index 100% rename from dag/gunbc/host_axis_caps.dag rename to dag/gunbc/host/host_axis_caps.dag diff --git a/dag/gunbc/host_boot_supervision.dag b/dag/gunbc/host/host_boot_supervision.dag similarity index 100% rename from dag/gunbc/host_boot_supervision.dag rename to dag/gunbc/host/host_boot_supervision.dag diff --git a/dag/gunbc/host_budget_source.dag b/dag/gunbc/host/host_budget_source.dag similarity index 100% rename from dag/gunbc/host_budget_source.dag rename to dag/gunbc/host/host_budget_source.dag diff --git a/dag/gunbc/host_build_cache_catalog_gate.dag b/dag/gunbc/host/host_build_cache_catalog_gate.dag similarity index 100% rename from dag/gunbc/host_build_cache_catalog_gate.dag rename to dag/gunbc/host/host_build_cache_catalog_gate.dag diff --git a/dag/gunbc/host_build_cache_provision.dag b/dag/gunbc/host/host_build_cache_provision.dag similarity index 100% rename from dag/gunbc/host_build_cache_provision.dag rename to dag/gunbc/host/host_build_cache_provision.dag diff --git a/dag/gunbc/host_cli_dependency.dag b/dag/gunbc/host/host_cli_dependency.dag similarity index 100% rename from dag/gunbc/host_cli_dependency.dag rename to dag/gunbc/host/host_cli_dependency.dag diff --git a/dag/gunbc/host_codex_runtime_provision.dag b/dag/gunbc/host/host_codex_runtime_provision.dag similarity index 100% rename from dag/gunbc/host_codex_runtime_provision.dag rename to dag/gunbc/host/host_codex_runtime_provision.dag diff --git a/dag/gunbc/host_codex_runtime_provision_verdict.dag b/dag/gunbc/host/host_codex_runtime_provision_verdict.dag similarity index 100% rename from dag/gunbc/host_codex_runtime_provision_verdict.dag rename to dag/gunbc/host/host_codex_runtime_provision_verdict.dag diff --git a/dag/gunbc/host_compile_pool.dag b/dag/gunbc/host/host_compile_pool.dag similarity index 100% rename from dag/gunbc/host_compile_pool.dag rename to dag/gunbc/host/host_compile_pool.dag diff --git a/dag/gunbc/host_compile_pool_provision.dag b/dag/gunbc/host/host_compile_pool_provision.dag similarity index 100% rename from dag/gunbc/host_compile_pool_provision.dag rename to dag/gunbc/host/host_compile_pool_provision.dag diff --git a/dag/gunbc/host_converge.dag b/dag/gunbc/host/host_converge.dag similarity index 100% rename from dag/gunbc/host_converge.dag rename to dag/gunbc/host/host_converge.dag diff --git a/dag/gunbc/host_converge_delta.dag b/dag/gunbc/host/host_converge_delta.dag similarity index 100% rename from dag/gunbc/host_converge_delta.dag rename to dag/gunbc/host/host_converge_delta.dag diff --git a/dag/gunbc/host_converge_slice1.dag b/dag/gunbc/host/host_converge_slice1.dag similarity index 100% rename from dag/gunbc/host_converge_slice1.dag rename to dag/gunbc/host/host_converge_slice1.dag diff --git a/dag/gunbc/host_diagnostic_channel.dag b/dag/gunbc/host/host_diagnostic_channel.dag similarity index 100% rename from dag/gunbc/host_diagnostic_channel.dag rename to dag/gunbc/host/host_diagnostic_channel.dag diff --git a/dag/gunbc/host_disk_observation.dag b/dag/gunbc/host/host_disk_observation.dag similarity index 100% rename from dag/gunbc/host_disk_observation.dag rename to dag/gunbc/host/host_disk_observation.dag diff --git a/dag/gunbc/host_disk_reclaim.dag b/dag/gunbc/host/host_disk_reclaim.dag similarity index 100% rename from dag/gunbc/host_disk_reclaim.dag rename to dag/gunbc/host/host_disk_reclaim.dag diff --git a/dag/gunbc/host_disk_reclaim_units.dag b/dag/gunbc/host/host_disk_reclaim_units.dag similarity index 100% rename from dag/gunbc/host_disk_reclaim_units.dag rename to dag/gunbc/host/host_disk_reclaim_units.dag diff --git a/dag/gunbc/host_effect.dag b/dag/gunbc/host/host_effect.dag similarity index 100% rename from dag/gunbc/host_effect.dag rename to dag/gunbc/host/host_effect.dag diff --git a/dag/gunbc/host_effect_codex_supervised_turn.dag b/dag/gunbc/host/host_effect_codex_supervised_turn.dag similarity index 100% rename from dag/gunbc/host_effect_codex_supervised_turn.dag rename to dag/gunbc/host/host_effect_codex_supervised_turn.dag diff --git a/dag/gunbc/host_effect_nbd_proxy_serve.dag b/dag/gunbc/host/host_effect_nbd_proxy_serve.dag similarity index 100% rename from dag/gunbc/host_effect_nbd_proxy_serve.dag rename to dag/gunbc/host/host_effect_nbd_proxy_serve.dag diff --git a/dag/gunbc/host_effect_plan.dag b/dag/gunbc/host/host_effect_plan.dag similarity index 100% rename from dag/gunbc/host_effect_plan.dag rename to dag/gunbc/host/host_effect_plan.dag diff --git a/dag/gunbc/host_effect_realize.dag b/dag/gunbc/host/host_effect_realize.dag similarity index 99% rename from dag/gunbc/host_effect_realize.dag rename to dag/gunbc/host/host_effect_realize.dag index 02ebfa54bc6..5e8c76a9c76 100644 --- a/dag/gunbc/host_effect_realize.dag +++ b/dag/gunbc/host/host_effect_realize.dag @@ -1204,7 +1204,7 @@ fn codex_runtime_observe_step( } data codex_runtime_materialize_source_roots: List = ["dag", "src/v2"] -data codex_runtime_materialize_entry: String = "dag/gunbc/host_codex_runtime_provision.dag" +data codex_runtime_materialize_entry: String = "dag/gunbc/host/host_codex_runtime_provision.dag" data codex_runtime_materialize_function: String = "materialize_codex_runtime_on_local_host" fn codex_runtime_materialize_step( diff --git a/dag/gunbc/host_hygiene_liveness.dag b/dag/gunbc/host/host_hygiene_liveness.dag similarity index 100% rename from dag/gunbc/host_hygiene_liveness.dag rename to dag/gunbc/host/host_hygiene_liveness.dag diff --git a/dag/gunbc/host_hygiene_liveness_observe.dag b/dag/gunbc/host/host_hygiene_liveness_observe.dag similarity index 100% rename from dag/gunbc/host_hygiene_liveness_observe.dag rename to dag/gunbc/host/host_hygiene_liveness_observe.dag diff --git a/dag/gunbc/host_hygiene_reaper.dag b/dag/gunbc/host/host_hygiene_reaper.dag similarity index 100% rename from dag/gunbc/host_hygiene_reaper.dag rename to dag/gunbc/host/host_hygiene_reaper.dag diff --git a/dag/gunbc/host_hygiene_reaper_observe.dag b/dag/gunbc/host/host_hygiene_reaper_observe.dag similarity index 100% rename from dag/gunbc/host_hygiene_reaper_observe.dag rename to dag/gunbc/host/host_hygiene_reaper_observe.dag diff --git a/dag/gunbc/host_hygiene_reaper_remediate.dag b/dag/gunbc/host/host_hygiene_reaper_remediate.dag similarity index 100% rename from dag/gunbc/host_hygiene_reaper_remediate.dag rename to dag/gunbc/host/host_hygiene_reaper_remediate.dag diff --git a/dag/gunbc/host_identity_access.dag b/dag/gunbc/host/host_identity_access.dag similarity index 100% rename from dag/gunbc/host_identity_access.dag rename to dag/gunbc/host/host_identity_access.dag diff --git a/dag/gunbc/host_identity_adopt.dag b/dag/gunbc/host/host_identity_adopt.dag similarity index 100% rename from dag/gunbc/host_identity_adopt.dag rename to dag/gunbc/host/host_identity_adopt.dag diff --git a/dag/gunbc/host_identity_assimilation.dag b/dag/gunbc/host/host_identity_assimilation.dag similarity index 100% rename from dag/gunbc/host_identity_assimilation.dag rename to dag/gunbc/host/host_identity_assimilation.dag diff --git a/dag/gunbc/host_identity_converge.dag b/dag/gunbc/host/host_identity_converge.dag similarity index 100% rename from dag/gunbc/host_identity_converge.dag rename to dag/gunbc/host/host_identity_converge.dag diff --git a/dag/gunbc/host_identity_knob.dag b/dag/gunbc/host/host_identity_knob.dag similarity index 100% rename from dag/gunbc/host_identity_knob.dag rename to dag/gunbc/host/host_identity_knob.dag diff --git a/dag/gunbc/host_identity_observation.dag b/dag/gunbc/host/host_identity_observation.dag similarity index 100% rename from dag/gunbc/host_identity_observation.dag rename to dag/gunbc/host/host_identity_observation.dag diff --git a/dag/gunbc/host_layout.dag b/dag/gunbc/host/host_layout.dag similarity index 100% rename from dag/gunbc/host_layout.dag rename to dag/gunbc/host/host_layout.dag diff --git a/dag/gunbc/host_memory_qualification.dag b/dag/gunbc/host/host_memory_qualification.dag similarity index 100% rename from dag/gunbc/host_memory_qualification.dag rename to dag/gunbc/host/host_memory_qualification.dag diff --git a/dag/gunbc/host_network_diagnosis.dag b/dag/gunbc/host/host_network_diagnosis.dag similarity index 100% rename from dag/gunbc/host_network_diagnosis.dag rename to dag/gunbc/host/host_network_diagnosis.dag diff --git a/dag/gunbc/host_operation_exec.dag b/dag/gunbc/host/host_operation_exec.dag similarity index 100% rename from dag/gunbc/host_operation_exec.dag rename to dag/gunbc/host/host_operation_exec.dag diff --git a/dag/gunbc/host_phase_status.dag b/dag/gunbc/host/host_phase_status.dag similarity index 100% rename from dag/gunbc/host_phase_status.dag rename to dag/gunbc/host/host_phase_status.dag diff --git a/dag/gunbc/host_reach_identity_probe.dag b/dag/gunbc/host/host_reach_identity_probe.dag similarity index 100% rename from dag/gunbc/host_reach_identity_probe.dag rename to dag/gunbc/host/host_reach_identity_probe.dag diff --git a/dag/gunbc/host_realization.dag b/dag/gunbc/host/host_realization.dag similarity index 100% rename from dag/gunbc/host_realization.dag rename to dag/gunbc/host/host_realization.dag diff --git a/dag/gunbc/host_resource.dag b/dag/gunbc/host/host_resource.dag similarity index 100% rename from dag/gunbc/host_resource.dag rename to dag/gunbc/host/host_resource.dag diff --git a/dag/gunbc/host_runner_memory_cap_plan_emit.dag b/dag/gunbc/host/host_runner_memory_cap_plan_emit.dag similarity index 100% rename from dag/gunbc/host_runner_memory_cap_plan_emit.dag rename to dag/gunbc/host/host_runner_memory_cap_plan_emit.dag diff --git a/dag/gunbc/host_runner_memory_cap_verify.dag b/dag/gunbc/host/host_runner_memory_cap_verify.dag similarity index 100% rename from dag/gunbc/host_runner_memory_cap_verify.dag rename to dag/gunbc/host/host_runner_memory_cap_verify.dag diff --git a/dag/gunbc/host_runner_memory_provision.dag b/dag/gunbc/host/host_runner_memory_provision.dag similarity index 100% rename from dag/gunbc/host_runner_memory_provision.dag rename to dag/gunbc/host/host_runner_memory_provision.dag diff --git a/dag/gunbc/host_standup.dag b/dag/gunbc/host/host_standup.dag similarity index 100% rename from dag/gunbc/host_standup.dag rename to dag/gunbc/host/host_standup.dag diff --git a/dag/gunbc/host_standup_assimilation_deduction.dag b/dag/gunbc/host/host_standup_assimilation_deduction.dag similarity index 100% rename from dag/gunbc/host_standup_assimilation_deduction.dag rename to dag/gunbc/host/host_standup_assimilation_deduction.dag diff --git a/dag/gunbc/host_swap_backing.dag b/dag/gunbc/host/host_swap_backing.dag similarity index 100% rename from dag/gunbc/host_swap_backing.dag rename to dag/gunbc/host/host_swap_backing.dag diff --git a/dag/gunbc/host_toolchain_components.dag b/dag/gunbc/host/host_toolchain_components.dag similarity index 100% rename from dag/gunbc/host_toolchain_components.dag rename to dag/gunbc/host/host_toolchain_components.dag diff --git a/dag/gunbc/host_toolchain_ensure.dag b/dag/gunbc/host/host_toolchain_ensure.dag similarity index 100% rename from dag/gunbc/host_toolchain_ensure.dag rename to dag/gunbc/host/host_toolchain_ensure.dag diff --git a/dag/gunbc/live_deploy/emit.dag b/dag/gunbc/live_deploy/emit.dag index 7bb07be43f8..ff1cbf862e0 100644 --- a/dag/gunbc/live_deploy/emit.dag +++ b/dag/gunbc/live_deploy/emit.dag @@ -324,7 +324,7 @@ fn emit_systemd_unit_doc(spec: DeploymentSpec, revision: ReleaseRevisionBinding) ExecStart { command: join([ svc.serve_binary as String, " serve --source-root dag --source-root src/v2", - " --entry dag/gunbc/roadmap_serve.dag --function ", svc.serve_function as String, + " --entry dag/gunbc/roadmap/roadmap_serve.dag --function ", svc.serve_function as String, " --host ", host, " --port ", port, " --release-revision ", release_revision_execstart_text(binding: revision), eval_budget_flag_text(flag: "--eval-budget-cpu-ms", limit: svc.serve_cpu_limit), @@ -359,7 +359,7 @@ fn emit_belt_service_unit_doc(spec: DeploymentSpec) -> Doc { ExecStart { command: join([ svc.serve_binary as String, " run --source-root dag --source-root src/v2", - " --entry dag/gunbc/roadmap_belt_actuate.dag --function belt_run_once_cli", + " --entry dag/gunbc/roadmap/roadmap_belt_actuate.dag --function belt_run_once_cli", ], "") as NonEmptyStr }, ], install: NotInstallable, diff --git a/dag/gunbc/live_deploy/srv1_residue_rehearsal.dag b/dag/gunbc/live_deploy/srv1_residue_rehearsal.dag index 925b589a9e7..bf5ad8d0550 100644 --- a/dag/gunbc/live_deploy/srv1_residue_rehearsal.dag +++ b/dag/gunbc/live_deploy/srv1_residue_rehearsal.dag @@ -53,7 +53,7 @@ type PreservedWorktreeIdentity { branch: String } -data srv1_paths_becoming_tracked_wire: String = ".githooks/generated-artifact-merge\n.github/workflows/fleet-converge.yml\n.github/workflows/witnesses.yml\nLICENSES/MIT.txt\nLICENSING.md\ndag/examples/interp_test/interp_example.dag\ndag/extdeps/accounting/encumbrance.dag\ndag/extdeps/advertising/google_ads.dag\ndag/extdeps/advertising/meta_ads.dag\ndag/extdeps/advertising/types.dag\ndag/extdeps/ampere/mt_collins_product_brief/platform.dag\ndag/extdeps/ampere/mt_collins_product_brief/subject.dag\ndag/extdeps/ampere/scp_diagnostic.dag\ndag/extdeps/archive/format.dag\ndag/extdeps/assurance/claim_evidence.dag\ndag/extdeps/auth/jwt.dag\ndag/extdeps/auth/oidc.dag\ndag/extdeps/automation/playwright.dag\ndag/extdeps/bmc/aspeed_ast2500.dag\ndag/extdeps/bmc/ipmi.dag\ndag/extdeps/bmc/mock_corpus.dag\ndag/extdeps/bmc/openbmc_fan_control.dag\ndag/extdeps/bmc/openbmc_operation.dag\ndag/extdeps/bmc/openbmc_password_ssh_transport.dag\ndag/extdeps/bmc/virtual_media.dag\ndag/extdeps/boards/supermicro.dag\ndag/extdeps/boards/types.dag\ndag/extdeps/bootloader/grub.dag\ndag/extdeps/browser/chromium.dag\ndag/extdeps/browser/google_chrome.dag\ndag/extdeps/cache.dag\ndag/extdeps/cache/pin.dag\ndag/extdeps/chassis/rosewill.dag\ndag/extdeps/chassis/types.dag\ndag/extdeps/ci_runner/blacksmith.dag\ndag/extdeps/ci_runner/circleci.dag\ndag/extdeps/ci_runner/depot.dag\ndag/extdeps/ci_runner/github_actions.dag\ndag/extdeps/ci_runner/types.dag\ndag/extdeps/ci_runner/warpbuild.dag\ndag/extdeps/clock/ti_cdce913.dag\ndag/extdeps/cloud/gcp/auth_print_access_token.dag\ndag/extdeps/cloud_init/cloud_init.dag\ndag/extdeps/colo/centersquare.dag\ndag/extdeps/colo/colocation_america.dag\ndag/extdeps/colo/coresite.dag\ndag/extdeps/colo/dataverge.dag\ndag/extdeps/colo/digital_realty.dag\ndag/extdeps/colo/equinix.dag\ndag/extdeps/colo/evocative.dag\ndag/extdeps/colo/h5.dag\ndag/extdeps/colo/halsey_165.dag\ndag/extdeps/colo/hivelocity.dag\ndag/extdeps/colo/interserver.dag\ndag/extdeps/colo/iron_mountain.dag\ndag/extdeps/colo/natcoweb.dag\ndag/extdeps/colo/netrality.dag\ndag/extdeps/colo/qts.dag\ndag/extdeps/colo/summit.dag\ndag/extdeps/colo/three_sixty_five.dag\ndag/extdeps/colo/tierpoint.dag\ndag/extdeps/colo/types.dag\ndag/extdeps/connector/samtec_ftsh_105_01_l_dv.dag\ndag/extdeps/container/docker_ce.dag\ndag/extdeps/container/oci/digest.dag\ndag/extdeps/cooling/dynatron.dag\ndag/extdeps/cooling/types.dag\ndag/extdeps/cpu/ampere_altra_memory_controller.dag\ndag/extdeps/cpu/ampere_altra_package.dag\ndag/extdeps/cpu/ampere_altra_package_contact_map.dag\ndag/extdeps/cpu/ampere_altra_package_contacts.dag\ndag/extdeps/cpu/ampere_altra_package_table4_raw.dag\ndag/extdeps/cpu/ampere_altra_platform_hw_design/platform.dag\ndag/extdeps/cpu/ampere_altra_platform_hw_design/subject.dag\ndag/extdeps/cpu_attachment/ilm4926.dag\ndag/extdeps/crm/hubspot_lifecycle.dag\ndag/extdeps/crm/salesforce_opportunity.dag\ndag/extdeps/crypto/hash.dag\ndag/extdeps/currency/currency.dag\ndag/extdeps/darwin/rusage.dag\ndag/extdeps/darwin/sysctl.dag\ndag/extdeps/diagnostic_mock_corpus.dag\ndag/extdeps/energy/nj_electricity.dag\ndag/extdeps/exec/command.dag\ndag/extdeps/exec/exec_arg_limit.dag\ndag/extdeps/exec/xargs.dag\ndag/extdeps/filesystem/linux.dag\ndag/extdeps/firmware/kernel_cmdline.dag\ndag/extdeps/firmware/openbmc/subject.dag\ndag/extdeps/firmware/tianocore_edk2/subject.dag\ndag/extdeps/firmware/trusted_firmware_a/subject.dag\ndag/extdeps/firmware/types.dag\ndag/extdeps/firmware/uefi_http_boot.dag\ndag/extdeps/firmware/uefi_shell.dag\ndag/extdeps/git/inspect.dag\ndag/extdeps/git/publication_transport.dag\ndag/extdeps/github/actions_environment.dag\ndag/extdeps/github/actions_runner.dag\ndag/extdeps/github/actions_token.dag\ndag/extdeps/github/app.dag\ndag/extdeps/github/effect.dag\ndag/extdeps/github/issues.dag\ndag/extdeps/github/push_event.dag\ndag/extdeps/github/workflow_run_event.dag\ndag/extdeps/github/workflows.dag\ndag/extdeps/gnu/libc.dag\ndag/extdeps/instrument/pip_boy_3000.dag\ndag/extdeps/instrument/pip_boy_3000_mk_v.dag\ndag/extdeps/ipc/dpmx.dag\ndag/extdeps/land_pattern/types.dag\ndag/extdeps/languages/bash/subject.dag\ndag/extdeps/languages/c/subject.dag\ndag/extdeps/languages/cpp/subject.dag\ndag/extdeps/languages/css/properties.dag\ndag/extdeps/languages/css/selectors.dag\ndag/extdeps/languages/css/subject.dag\ndag/extdeps/languages/css/values.dag\ndag/extdeps/languages/ecmascript/subject.dag\ndag/extdeps/languages/go/subject.dag\ndag/extdeps/languages/html/subject.dag\ndag/extdeps/languages/java/subject.dag\ndag/extdeps/languages/json/parse.dag\ndag/extdeps/languages/json/subject.dag\ndag/extdeps/languages/jsx/subject.dag\ndag/extdeps/languages/kotlin/subject.dag\ndag/extdeps/languages/lean/overflow.dag\ndag/extdeps/languages/lean/subject.dag\ndag/extdeps/languages/llvm_ir/subject.dag\ndag/extdeps/languages/markdown/subject.dag\ndag/extdeps/languages/ptx/subject.dag\ndag/extdeps/languages/python/subject.dag\ndag/extdeps/languages/riscv/subject.dag\ndag/extdeps/languages/rust/derive_contracts.dag\ndag/extdeps/languages/rust/subject.dag\ndag/extdeps/languages/spice/subject.dag\ndag/extdeps/languages/swift/subject.dag\ndag/extdeps/languages/typescript/subject.dag\ndag/extdeps/languages/verilog/subject.dag\ndag/extdeps/languages/wasm/subject.dag\ndag/extdeps/languages/yaml/subject.dag\ndag/extdeps/linux/edac.dag\ndag/extdeps/linux/mock_corpus.dag\ndag/extdeps/linux/proc_meminfo.dag\ndag/extdeps/linux/proc_self_cgroup.dag\ndag/extdeps/linux/procfs.dag\ndag/extdeps/linux/rusage.dag\ndag/extdeps/linux/usb_gadget.dag\ndag/extdeps/llm/claude_agent_sdk_stream.dag\ndag/extdeps/llm/claude_sdk.dag\ndag/extdeps/llm/claude_setup_token_cli.dag\ndag/extdeps/llm/cli_lifecycle.dag\ndag/extdeps/llm/codex_app_server.dag\ndag/extdeps/llm/codex_app_server_stdio_session.dag\ndag/extdeps/llm/codex_auth.dag\ndag/extdeps/llm/cursor_cli.dag\ndag/extdeps/llm/cursor_sdk.dag\ndag/extdeps/llm/cursor_sdk_errors.dag\ndag/extdeps/llm/cursor_sdk_facts.dag\ndag/extdeps/llm/cursor_stream.dag\ndag/extdeps/memory/macronix_mx25l25673g.dag\ndag/extdeps/memory/microchip_at24cm02.dag\ndag/extdeps/memory/samsung.dag\ndag/extdeps/memory/te_ddr4_dimm_socket.dag\ndag/extdeps/memory/training.dag\ndag/extdeps/mercurial.dag\ndag/extdeps/netplan/netplan.dag\ndag/extdeps/network/address.dag\ndag/extdeps/network/endpoint.dag\ndag/extdeps/network/ipv4.dag\ndag/extdeps/network/ipv6.dag\ndag/extdeps/network/reach.dag\ndag/extdeps/network/switch_types.dag\ndag/extdeps/network/ti_dp83867.dag\ndag/extdeps/network/tp_link.dag\ndag/extdeps/npm.dag\ndag/extdeps/ocp/mt_jade/platform.dag\ndag/extdeps/ocp/mt_jade/subject.dag\ndag/extdeps/ocp/mt_mitchell/platform.dag\ndag/extdeps/ocp/mt_mitchell/subject.dag\ndag/extdeps/ocp/publication.dag\ndag/extdeps/ollama/api.dag\ndag/extdeps/ollama/binary_release.dag\ndag/extdeps/ollama/capability.dag\ndag/extdeps/ollama/gpu_support.dag\ndag/extdeps/ollama/server_env.dag\ndag/extdeps/os.dag\ndag/extdeps/os/debian.dag\ndag/extdeps/package.dag\ndag/extdeps/physics/bach_et_al_2013_double_slit.dag\ndag/extdeps/physics/chapman_et_al_1995_atom_interferometer_which_path.dag\ndag/extdeps/pijul.dag\ndag/extdeps/pin.dag\ndag/extdeps/posix/rusage.dag\ndag/extdeps/posix/shell_command_language.dag\ndag/extdeps/posix/signal.dag\ndag/extdeps/power/eaton_tripp_lite.dag\ndag/extdeps/power/ti_tps3808.dag\ndag/extdeps/power/ti_tps53688.dag\ndag/extdeps/power/types.dag\ndag/extdeps/pricing/billing_units.dag\ndag/extdeps/pricing/gitlab_subscription.dag\ndag/extdeps/pricing/object_storage.dag\ndag/extdeps/pricing/regional_compute.dag\ndag/extdeps/probes/provider_interface_acquisition.dag\ndag/extdeps/process/gnu_bash_exit.dag\ndag/extdeps/process/posix_exit.dag\ndag/extdeps/programmable_logic/ice40/configuration.dag\ndag/extdeps/programmable_logic/ice40/subject.dag\ndag/extdeps/programmable_logic/ice40/supply.dag\ndag/extdeps/project_schedule/cpm_pert.dag\ndag/extdeps/provisioning/ubuntu_install_media.dag\ndag/extdeps/provisioning/ubuntu_install_media_fetch.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media_remaster.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media_toolchain.dag\ndag/extdeps/publication.dag\ndag/extdeps/rack/navepoint.dag\ndag/extdeps/rack/types.dag\ndag/extdeps/realestate/nj_industrial.dag\ndag/extdeps/rust/cargo_message.dag\ndag/extdeps/rust/target_triple.dag\ndag/extdeps/sec/issuer/atlassian.dag\ndag/extdeps/sec/issuer/atlassian_facts.dag\ndag/extdeps/sec/issuer/microsoft.dag\ndag/extdeps/sec/issuer/microsoft_facts.dag\ndag/extdeps/sec/operating_metrics.dag\ndag/extdeps/shell.dag\ndag/extdeps/shell_mock_corpus.dag\ndag/extdeps/simulators/icarus_verilog/subject.dag\ndag/extdeps/simulators/ngspice/subject.dag\ndag/extdeps/ssh/client_options.dag\ndag/extdeps/ssh/keys.dag\ndag/extdeps/ssh/mock_corpus.dag\ndag/extdeps/ssh/password_session.dag\ndag/extdeps/ssh/session.dag\ndag/extdeps/standards/ieee_754_2019.dag\ndag/extdeps/standards/rfc_8118.dag\ndag/extdeps/standards/web_annotation.dag\ndag/extdeps/storage/amphenol_mdt420m01001.dag\ndag/extdeps/storage/nbd.dag\ndag/extdeps/storage/te_m2_ngff_connector.dag\ndag/extdeps/systemd/journalctl.dag\ndag/extdeps/systemd/oomd.dag\ndag/extdeps/systemd/systemctl.dag\ndag/extdeps/systemd/systemd.dag\ndag/extdeps/systemd/systemd_contracts.dag\ndag/extdeps/systemd/systemd_run.dag\ndag/extdeps/systemd/unit_file.dag\ndag/extdeps/systems/nvidia.dag\ndag/extdeps/systems/nvidia_dgx_spark_pxe.dag\ndag/extdeps/systems/nvidia_dgx_spark_setup.dag\ndag/extdeps/systems/nvidia_fleet_lifecycle.dag\ndag/extdeps/systems/types.dag\ndag/extdeps/time/rfc3339.dag\ndag/extdeps/toolchain/icestorm/subject.dag\ndag/extdeps/tools.dag\ndag/extdeps/tools/busybox.dag\ndag/extdeps/tools/diffutils.dag\ndag/extdeps/tools/free.dag\ndag/extdeps/tools/gcloud.dag\ndag/extdeps/tools/gnu_coreutils.dag\ndag/extdeps/tools/hostname.dag\ndag/extdeps/tools/id.dag\ndag/extdeps/tools/node.dag\ndag/extdeps/tools/npm.dag\ndag/extdeps/tools/pin.dag\ndag/extdeps/tools/rustfmt.dag\ndag/extdeps/tools/sha512sum.dag\ndag/extdeps/tools/wc.dag\ndag/extdeps/ucamco/gerber.dag\ndag/extdeps/unicode/blocks.dag\ndag/extdeps/unicode/display.dag\ndag/extdeps/units/dimensionless.dag\ndag/extdeps/units/iec_80000_13.dag\ndag/extdeps/units/iso8601.dag\ndag/extdeps/units/iso_80000_3.dag\ndag/extdeps/uuid/uuid.dag\ndag/extdeps/vendor/alphabet.dag\ndag/extdeps/vendor/amphenol.dag\ndag/extdeps/vendor/aspeed.dag\ndag/extdeps/vendor/asrock_rack.dag\ndag/extdeps/vendor/atlassian.dag\ndag/extdeps/vendor/dynatron.dag\ndag/extdeps/vendor/eaton.dag\ndag/extdeps/vendor/hubspot.dag\ndag/extdeps/vendor/lattice_semiconductor.dag\ndag/extdeps/vendor/lotes.dag\ndag/extdeps/vendor/macronix.dag\ndag/extdeps/vendor/meta_platforms.dag\ndag/extdeps/vendor/microchip_technology.dag\ndag/extdeps/vendor/microsoft.dag\ndag/extdeps/vendor/navepoint.dag\ndag/extdeps/vendor/rosewill.dag\ndag/extdeps/vendor/salesforce.dag\ndag/extdeps/vendor/samtec.dag\ndag/extdeps/vendor/texas_instruments.dag\ndag/extdeps/vendor/the_wand_company.dag\ndag/extdeps/vendor/tp_link.dag\ndag/extdeps/vendor/tyco_electronics.dag\ndag/extdeps/vendor/tyco_electronics_amp_kk.dag\ndag/extdeps/w3c/accelerometer.dag\ndag/extdeps/w3c/device_orientation_and_motion.dag\ndag/extdeps/w3c/generic_sensor.dag\ndag/extdeps/w3c/svg.dag\ndag/extdeps/web_audio/web_audio.dag\ndag/gunbc/apply.dag\ndag/gunbc/auth/access_token_source.dag\ndag/gunbc/auth/github_apps.dag\ndag/gunbc/auth/github_credential.dag\ndag/gunbc/auth/github_gcp_federation.dag\ndag/gunbc/auth/materialized_secret.dag\ndag/gunbc/auth/secret_rotation.dag\ndag/gunbc/bach_double_slit_observation.dag\ndag/gunbc/bach_double_slit_path_additivity_synthetic_fixture.dag\ndag/gunbc/bash_materialized_transport.dag\ndag/gunbc/bmc_converge.dag\ndag/gunbc/bmc_fan_converge.dag\ndag/gunbc/bmc_fan_monitor.dag\ndag/gunbc/bmc_fan_projection.dag\ndag/gunbc/bmc_intent.dag\ndag/gunbc/bmc_netboot_serve.dag\ndag/gunbc/bmc_netboot_shell_boot.dag\ndag/gunbc/bmc_virtual_media.dag\ndag/gunbc/build_cache_endpoint_observation.dag\ndag/gunbc/build_cache_endpoint_path.dag\ndag/gunbc/build_cache_ensure.dag\ndag/gunbc/build_cache_instance.dag\ndag/gunbc/build_cache_latency_probe.dag\ndag/gunbc/build_cache_unit.dag\ndag/gunbc/busybox_bmc_build.dag\ndag/gunbc/capability_binding.dag\ndag/gunbc/cargo_execution_placement.dag\ndag/gunbc/census_closure_frontier.dag\ndag/gunbc/change_realization.dag\ndag/gunbc/chapman_which_path_observation.dag\ndag/gunbc/ci_build_job_v1_compiler_unit_receipt.dag\ndag/gunbc/ci_cost_arc_closeout_receipt.dag\ndag/gunbc/ci_heal_credential.dag\ndag/gunbc/ci_release_bins.dag\ndag/gunbc/citation/pdf_safe_profile.dag\ndag/gunbc/citation/x86_64_abi_pdf_consumer.dag\ndag/gunbc/claim_evidence_probe_rule.dag\ndag/gunbc/class_b_import_closure_overlay.dag\ndag/gunbc/claude_setup_token_enrollment.dag\ndag/gunbc/cli_run_floor_lens_oracle_scaffold.dag\ndag/gunbc/cli_run_hand_rust_area_ledger.dag\ndag/gunbc/cli_run_witness_admission_scaffold.dag\ndag/gunbc/cli_run_witness_deferral_freeze_scaffold.dag\ndag/gunbc/clock_read.dag\ndag/gunbc/codex_app_server_press.dag\ndag/gunbc/codex_provider_runtime_receipt.dag\ndag/gunbc/codex_runtime_bundle.dag\ndag/gunbc/codex_runtime_paths.dag\ndag/gunbc/codex_supervised_turn.dag\ndag/gunbc/codex_supervised_turn_run.dag\ndag/gunbc/command_runner.dag\ndag/gunbc/compile_clean_cost_basis.tsv\ndag/gunbc/compile_clean_diagnostic_policy.dag\ndag/gunbc/compile_diagnostic_census.dag\ndag/gunbc/compile_pool_ensure.dag\ndag/gunbc/cursor_sdk_auth_probe.dag\ndag/gunbc/cursor_sdk_local_binding.dag\ndag/gunbc/cursor_sdk_provider_standing.dag\ndag/gunbc/cursor_sdk_secret_admission.dag\ndag/gunbc/declared_import_closure_binding.dag\ndag/gunbc/deployed_tree_remote.dag\ndag/gunbc/design/component.dag\ndag/gunbc/design/instrument_audition.dag\ndag/gunbc/design/instrument_bob.dag\ndag/gunbc/design/instrument_camera.dag\ndag/gunbc/design/instrument_physical.dag\ndag/gunbc/design/instrument_projection.dag\ndag/gunbc/design/interaction_cause.dag\ndag/gunbc/design/reference_instrument.dag\ndag/gunbc/design/salience.dag\ndag/gunbc/design/scale.dag\ndag/gunbc/design/sound.dag\ndag/gunbc/design/state_response.dag\ndag/gunbc/devboot/build.dag\ndag/gunbc/devboot/lease.dag\ndag/gunbc/devboot/outcome.dag\ndag/gunbc/devboot/produce.dag\ndag/gunbc/devboot/program.dag\ndag/gunbc/devboot/subject.dag\ndag/gunbc/devboot/transport.dag\ndag/gunbc/diff_baseline.dag\ndag/gunbc/dispatch_pipe_pane_emit.dag\ndag/gunbc/dispatch_selection.dag\ndag/gunbc/dissolution_census.dag\ndag/gunbc/dissolution_migration_census.dag\ndag/gunbc/documentary_refs.dag\ndag/gunbc/econ/acquisition.dag\ndag/gunbc/econ/free_tier_serving.dag\ndag/gunbc/econ/llm_attempt_receipt.dag\ndag/gunbc/econ/regional_compute_premium.dag\ndag/gunbc/econ/scm_serving_model.dag\ndag/gunbc/ensure.dag\ndag/gunbc/executor_schedule_retention.dag\ndag/gunbc/explicit_witness_admission.dag\ndag/gunbc/extdeps_scope_frontier.dag\ndag/gunbc/fleet_bmc_firmware_evidence.dag\ndag/gunbc/fleet_bmc_observation.dag\ndag/gunbc/fleet_bmc_state.dag\ndag/gunbc/fleet_converge_plan.dag\ndag/gunbc/fleet_converge_plan_cli.dag\ndag/gunbc/fleet_converge_timer.dag\ndag/gunbc/fleet_converge_workflow.dag\ndag/gunbc/fleet_convergence_verdict.dag\ndag/gunbc/fleet_desired_observe.dag\ndag/gunbc/fleet_host_key_enrollment.dag\ndag/gunbc/fleet_install_transport_observations.dag\ndag/gunbc/fleet_known_hosts_anchor.dag\ndag/gunbc/fleet_lifecycle_observation.dag\ndag/gunbc/fleet_main_revision.dag\ndag/gunbc/fleet_multi_principal_probe.dag\ndag/gunbc/fleet_physical_inventory.dag\ndag/gunbc/fleet_probe_identity_observe.dag\ndag/gunbc/fleet_reach.dag\ndag/gunbc/fleet_reach_endpoint.dag\ndag/gunbc/fleet_receipt_collector.dag\ndag/gunbc/fleet_runner_connectivity.dag\ndag/gunbc/fleet_secrets_config.dag\ndag/gunbc/fleet_shell_transport_observation.dag\ndag/gunbc/fleet_ssh_access.dag\ndag/gunbc/fleet_ssh_credential_verify.dag\ndag/gunbc/fleet_workflow_steps.dag\ndag/gunbc/float_add_associativity_observation.dag\ndag/gunbc/floor_component_receipt.dag\ndag/gunbc/floor_component_receipt_document.dag\ndag/gunbc/floor_discovery_scaffold.dag\ndag/gunbc/generated_artifact_assessment.dag\ndag/gunbc/generated_artifact_merge_driver.dag\ndag/gunbc/generated_artifact_observation.dag\ndag/gunbc/generated_projection_paths.dag\ndag/gunbc/git_diff_change_window.dag\ndag/gunbc/gitattributes_emit.dag\ndag/gunbc/githooks_pre_push_fmt_transport_scaffold.dag\ndag/gunbc/githooks_repo_local_git_config_emit.dag\ndag/gunbc/guarantee_measurement.dag\ndag/gunbc/guarantee_probe_corpus.dag\ndag/gunbc/heal_push_plan.dag\ndag/gunbc/heal_revalidation.dag\ndag/gunbc/host_assimilation_program.dag\ndag/gunbc/host_authorized_keys_reconcile.dag\ndag/gunbc/host_axis_caps.dag\ndag/gunbc/host_boot_supervision.dag\ndag/gunbc/host_budget_source.dag\ndag/gunbc/host_cli_dependency.dag\ndag/gunbc/host_codex_runtime_provision.dag\ndag/gunbc/host_codex_runtime_provision_verdict.dag\ndag/gunbc/host_compile_pool.dag\ndag/gunbc/host_diagnostic_channel.dag\ndag/gunbc/host_disk_observation.dag\ndag/gunbc/host_effect_codex_supervised_turn.dag\ndag/gunbc/host_hygiene_liveness_observe.dag\ndag/gunbc/host_hygiene_reaper_observe.dag\ndag/gunbc/host_hygiene_reaper_remediate.dag\ndag/gunbc/host_memory_qualification.dag\ndag/gunbc/host_network_diagnosis.dag\ndag/gunbc/host_phase_status.dag\ndag/gunbc/host_reach_identity_probe.dag\ndag/gunbc/host_realization.dag\ndag/gunbc/host_resource.dag\ndag/gunbc/host_swap_backing.dag\ndag/gunbc/host_toolchain_components.dag\ndag/gunbc/hostname_allocation.dag\ndag/gunbc/hostname_read.dag\ndag/gunbc/hostname_set.dag\ndag/gunbc/infer_occurrence_binding_scaffold.dag\ndag/gunbc/install_transport_qualification.dag\ndag/gunbc/interpreter_replacement_cut.dag\ndag/gunbc/language_module_home.dag\ndag/gunbc/language_source_scaffold_index.dag\ndag/gunbc/language_target_registry.dag\ndag/gunbc/legacy_extdeps_scope_frontier.tsv\ndag/gunbc/legacy_test_behavior_disposition.dag\ndag/gunbc/legacy_test_inflow.dag\ndag/gunbc/lifecycle_survivor_scan.dag\ndag/gunbc/live_deploy/candidate.dag\ndag/gunbc/live_deploy/deployed_tree_scope.dag\ndag/gunbc/live_deploy/revision.dag\ndag/gunbc/live_rust_observation.dag\ndag/gunbc/managed_directory.dag\ndag/gunbc/materialization_kernel_closing_frontier_audit.dag\ndag/gunbc/materialization_provider_consumer_scaffold.dag\ndag/gunbc/materialization_provider_targets.dag\ndag/gunbc/memory_provisioning.dag\ndag/gunbc/merge_admission_subject.dag\ndag/gunbc/model_artifact.dag\ndag/gunbc/namespace_census_receipt.dag\ndag/gunbc/namespace_clause_e_projection_law.dag\ndag/gunbc/namespace_pool_independence.dag\ndag/gunbc/namespace_reference_derived_closure_admission.dag\ndag/gunbc/namespace_reference_derived_closure_contract.dag\ndag/gunbc/native_scm_interaction_contract.dag\ndag/gunbc/native_witness_transition_receipt.dag\ndag/gunbc/non_fold_residue.dag\ndag/gunbc/observation_ci_render.dag\ndag/gunbc/observation_emit_census.dag\ndag/gunbc/observation_seed_render.dag\ndag/gunbc/observation_tty_render.dag\ndag/gunbc/occurrence_identity_acceptance_closure.dag\ndag/gunbc/ollama_runtime_bundle.dag\ndag/gunbc/os_install_claim_evidence.dag\ndag/gunbc/p1_retention_cohort_receipt.dag\ndag/gunbc/package_delivery.dag\ndag/gunbc/physics/bach_double_slit_path_additivity.dag\ndag/gunbc/physics/which_path_four_model_comparison.dag\ndag/gunbc/plans/affected_set_self_confirmation.dag\ndag/gunbc/plans/cli_run_hollowing_plan.dag\ndag/gunbc/plans/discrete_cost_derivation.dag\ndag/gunbc/plans/extdeps_modeling_preflight.dag\ndag/gunbc/plans/fleet_subsumption_manual_gaps.dag\ndag/gunbc/plans/host_convergence_circuit_residue.dag\ndag/gunbc/plans/transport_argv_anemia_dissolution.dag\ndag/gunbc/plans/v2_complexity_capability_parity.dag\ndag/gunbc/plans/value_null_split.dag\ndag/gunbc/principal_projection.dag\ndag/gunbc/prose_row_frontier.dag\ndag/gunbc/provider_account.dag\ndag/gunbc/provider_interface_binding.dag\ndag/gunbc/provider_readiness_claim_evidence.dag\ndag/gunbc/provider_standing.dag\ndag/gunbc/provider_standing_probe_bridge.dag\ndag/gunbc/provider_turn_adjudication.dag\ndag/gunbc/provider_wire_evidence.dag\ndag/gunbc/public_projection.dag\ndag/gunbc/publication_admission_delta.dag\ndag/gunbc/publication_decision.dag\ndag/gunbc/publication_policy.dag\ndag/gunbc/readback_independence.dag\ndag/gunbc/realization_vocab_confinement_census.dag\ndag/gunbc/regen_receipt.dag\ndag/gunbc/remote_operation.dag\ndag/gunbc/remote_shell_command.dag\ndag/gunbc/replacement_cut.dag\ndag/gunbc/repo_atlas_projection.dag\ndag/gunbc/repo_identity.dag\ndag/gunbc/repo_local_git_config.dag\ndag/gunbc/repo_local_git_config_clone_bootstrap.dag\ndag/gunbc/repository.dag\ndag/gunbc/repository_census_coverage.dag\ndag/gunbc/repository_census_observation.dag\ndag/gunbc/resolved_graph_cache_hand_rust_scaffold.dag\ndag/gunbc/retained_shell_script.dag\ndag/gunbc/roadmap_acceptance_event_history.jsonl\ndag/gunbc/roadmap_acceptance_history_carrier.dag\ndag/gunbc/roadmap_acceptance_history_observation.dag\ndag/gunbc/roadmap_acceptance_history_projection.dag\ndag/gunbc/roadmap_altitude.dag\ndag/gunbc/roadmap_component.dag\ndag/gunbc/roadmap_dashboard_instance.dag\ndag/gunbc/roadmap_dashboard_instance_apply.dag\ndag/gunbc/roadmap_dispatch_environment.dag\ndag/gunbc/roadmap_execution_contract.dag\ndag/gunbc/roadmap_focus.dag\ndag/gunbc/roadmap_forecast.dag\ndag/gunbc/roadmap_identity.dag\ndag/gunbc/roadmap_instrument_motion.dag\ndag/gunbc/roadmap_instrument_sandbox.dag\ndag/gunbc/roadmap_instrument_tuner.dag\ndag/gunbc/roadmap_presentation.dag\ndag/gunbc/roadmap_program_view.dag\ndag/gunbc/roadmap_provider_events.dag\ndag/gunbc/roadmap_publish.dag\ndag/gunbc/roadmap_publish_observe.dag\ndag/gunbc/roadmap_repo_atlas_sandbox.dag\ndag/gunbc/roadmap_sandbox.dag\ndag/gunbc/roadmap_site_surface_expect.dag\ndag/gunbc/roadmap_site_surface_observe.dag\ndag/gunbc/roadmap_site_surface_render.dag\ndag/gunbc/roadmap_site_surface_types.dag\ndag/gunbc/roadmap_site_surface_witness.dag\ndag/gunbc/roadmap_validation_oracle.dag\ndag/gunbc/roadmap_verification_receipt.dag\ndag/gunbc/roadmap_verify.dag\ndag/gunbc/roadmap_workflow_command.dag\ndag/gunbc/roadmap_workflow_progress.dag\ndag/gunbc/roadmap_workflow_stage.dag\ndag/gunbc/roster_registry.dag\ndag/gunbc/runner_activation.dag\ndag/gunbc/runner_broker_progress_watchdog.dag\ndag/gunbc/runner_capacity_operator_access.dag\ndag/gunbc/runner_capacity_plan.dag\ndag/gunbc/runner_capacity_realize.dag\ndag/gunbc/runner_connectivity_recovery.dag\ndag/gunbc/runner_connectivity_repair_plan.dag\ndag/gunbc/runner_host_deploy.dag\ndag/gunbc/runner_incarnation.dag\ndag/gunbc/runner_lifecycle.dag\ndag/gunbc/runner_lifecycle_realize.dag\ndag/gunbc/runner_shape_census.dag\ndag/gunbc/runner_slot_provision.dag\ndag/gunbc/running_release_identity.dag\ndag/gunbc/rust_decl_type_overlay.dag\ndag/gunbc/rust_item_identity.dag\ndag/gunbc/scm_compatibility/git.dag\ndag/gunbc/scm_compatibility/mercurial.dag\ndag/gunbc/scm_compatibility/pijul.dag\ndag/gunbc/scm_compatibility_shape.dag\ndag/gunbc/secret_provision.dag\ndag/gunbc/seed_growth.dag\ndag/gunbc/seed_growth_admission.dag\ndag/gunbc/self_host_artifact_materialization.dag\ndag/gunbc/self_host_promotion_obligations.dag\ndag/gunbc/served_surface_browser_observation.dag\ndag/gunbc/session_residency.dag\ndag/gunbc/shell_target_conformance.dag\ndag/gunbc/site/markup.dag\ndag/gunbc/source_admission_selection.dag\ndag/gunbc/source_integration_claim_evidence.dag\ndag/gunbc/source_integration_landing_spine.dag\ndag/gunbc/source_integration_proof_kernel.dag\ndag/gunbc/specification_citation_read_provenance.dag\ndag/gunbc/srv1_tasks_preapply_observation.dag\ndag/gunbc/srv4_uefi_observed.dag\ndag/gunbc/stage0_cargo_manifest.dag\ndag/gunbc/stage0_rust_honest_frontier_integration.dag\ndag/gunbc/stage0_rust_honest_frontier_projection.dag\ndag/gunbc/stage0_rust_host_observation.dag\ndag/gunbc/stage0_rust_lifecycle_totality.dag\ndag/gunbc/stage0_rust_maintenance_census_report.dag\ndag/gunbc/stage0_rust_product_reachability.dag\ndag/gunbc/stage0_rust_source_lifecycle_scaffold.dag\ndag/gunbc/systemctl_is_active_read.dag\ndag/gunbc/systemctl_list_units.dag\ndag/gunbc/systemctl_set_property.dag\ndag/gunbc/systemctl_status_read.dag\ndag/gunbc/systemctl_stop_run.dag\ndag/gunbc/systemd_run_transient.dag\ndag/gunbc/test_module_hygiene.dag\ndag/gunbc/tool_readiness.dag\ndag/gunbc/type_ref_hit_ne_bind_measure/authority.dag\ndag/gunbc/type_reference_binding_context.dag\ndag/gunbc/type_reference_containment_binding.dag\ndag/gunbc/typed_module_cache_capacity.dag\ndag/gunbc/typed_remote_file_write.dag\ndag/gunbc/uefi_boot_config.dag\ndag/gunbc/uefi_boot_install_decision.dag\ndag/gunbc/uefi_shell_over_sol.dag\ndag/gunbc/upstream_document_carriage.dag\ndag/gunbc/v1_complexity_capability_census.dag\ndag/gunbc/v1_complexity_decl_classification.dag\ndag/gunbc/v1_complexity_decl_classification_roster.dag\ndag/gunbc/v1_complexity_decl_classification_types.dag\ndag/gunbc/v1_interpreter_dispatch_emit.dag\ndag/gunbc/v1_interpreter_primitive_surface.dag\ndag/gunbc/v1_maintenance_standing.dag\ndag/gunbc/web_motion_binding.dag\ndag/gunbc/witness_deferral_freeze.dag\ndag/gunbc/witness_execution_class.dag\ndag/gunbc/witness_floor_workflow.dag\ndag/gunbc/witness_row_cost.dag\ndag/gunbc/witness_row_cost_basis.tsv\ndag/gunbc/worker_lifecycle.dag\ndag/gunbc/workflow_reconcile.dag\ndag/product/altra_motherboard/attachment_stack.dag\ndag/product/altra_motherboard/minimal_design.dag\ndag/product/altra_motherboard/pcb_world.dag\ndag/product/altra_motherboard/placement.dag\ndag/product/altra_motherboard/realization.dag\ndag/product/altra_motherboard/scene_emission.dag\ndag/product/build_fulfillment.dag\ndag/product/build_selection.dag\ndag/product/compute_board/admission.dag\ndag/product/compute_board/analog.dag\ndag/product/compute_board/article.dag\ndag/product/compute_board/composition.dag\ndag/product/compute_board/contact_population.dag\ndag/product/compute_board/device_binding.dag\ndag/product/compute_board/digital_control.dag\ndag/product/compute_board/emission_entry.dag\ndag/product/compute_board/intent.dag\ndag/product/compute_board/power_distribution.dag\ndag/product/compute_board/simulation_receipt.dag\ndag/product/compute_board/spice_projection.dag\ndag/product/compute_board/verilog_projection.dag\ndag/product/cooling_qualification.dag\ndag/product/electrical/connectivity.dag\ndag/product/fabric/budget.dag\ndag/product/fabric/demand.dag\ndag/product/fabric/execution.dag\ndag/product/fabric/identity.dag\ndag/product/fabric/supply.dag\ndag/product/fabric/work.dag\ndag/product/installed_bom_reconcile.dag\ndag/product/inventory.dag\ndag/product/node_power_envelope.dag\ndag/product/pcb/copper.dag\ndag/product/pcb/footprint.dag\ndag/product/pcb/physical.dag\ndag/product/pcb/plan_view.dag\ndag/product/pcb/scene.dag\ndag/product/pcb/stackup.dag\ndag/product/pcb/world.dag\ndag/product/rack_mount.dag\ndag/product/rack_power.dag\ndag/product/spatial_connectivity.dag\ndag/product/spatial_dimension.dag\ndag/product/spatial_edit.dag\ndag/product/spatial_projection.dag\ndag/product/spatial_world.dag\ndag/std/affine_space.dag\ndag/std/algebra_law.dag\ndag/std/attribution.dag\ndag/std/authorization_profile.dag\ndag/std/checked_arithmetic.dag\ndag/std/citation.dag\ndag/std/claim_evidence.dag\ndag/std/computation_identity.dag\ndag/std/coordinate_frame.dag\ndag/std/decimal.dag\ndag/std/dissolution.dag\ndag/std/euclidean_geometry.dag\ndag/std/evaluation_budget.dag\ndag/std/human_intervention.dag\ndag/std/interval.dag\ndag/std/key_relation.dag\ndag/std/keyed_roster.dag\ndag/std/keyed_row.dag\ndag/std/language_target_identity.dag\ndag/std/materialization_provider.dag\ndag/std/minted_identity.dag\ndag/std/observation.dag\ndag/std/occurrence_binding.dag\ndag/std/occurrence_binding_candidates.dag\ndag/std/occurrence_binding_resolve.dag\ndag/std/occurrence_identity.dag\ndag/std/orthogonal_geometry.dag\ndag/std/orthogonal_topology.dag\ndag/std/path_intent.dag\ndag/std/planar_projection.dag\ndag/std/primitive_identity.dag\ndag/std/process_termination.dag\ndag/std/reference_binding_observation.dag\ndag/std/roster_frontier.dag\ndag/std/selected_witness_bundle.dag\ndag/std/shell_stream_capture.dag\ndag/std/source_annotation.dag\ndag/std/spatial_frame.dag\ndag/std/spatial_knowledge.dag\ndag/std/state_durability.dag\ndag/std/trait_derive_shape.dag\ndag/std/unicode/types.dag\ndag/std/witness_admission.dag\ndag/std/witness_purpose.dag\ndag/test/claim/access_authorization_profile_witness_test.dag\ndag/test/claim/access_token_ensure_witness_test.dag\ndag/test/claim/acquisition_mechanism_witness_test.dag\ndag/test/claim/actions_job_grant_witness_test.dag\ndag/test/claim/advertising_interface_witness_test.dag\ndag/test/claim/affine_space_witness_test.dag\ndag/test/claim/altra_attachment_stack_witness_test.dag\ndag/test/claim/altra_contact_map_witness_test.dag\ndag/test/claim/altra_memory_controller_witness_test.dag\ndag/test/claim/altra_minimal_design_witness_test.dag\ndag/test/claim/altra_pcb_world_svg_witness_test.dag\ndag/test/claim/altra_placement_witness_test.dag\ndag/test/claim/altra_platform_and_mt_mitchell_authority_witness_test.dag\ndag/test/claim/altra_realization_witness_test.dag\ndag/test/claim/annotation_carrier_witness_test.dag\ndag/test/claim/annotation_erasure_emission_witness_test.dag\ndag/test/claim/anomaly_evidence_witness_test.dag\ndag/test/claim/anonymous_record_head_use_line_witness_test.dag\ndag/test/claim/argv_command_render_witness_test.dag\ndag/test/claim/aspeed_ast2500_management_paths_witness_test.dag\ndag/test/claim/attribution_span_witness_test.dag\ndag/test/claim/bach_double_slit_observation_witness_test.dag\ndag/test/claim/bach_double_slit_path_additivity_synthetic_fixture_witness_test.dag\ndag/test/claim/belt_tick_receipt_home_witness_test.dag\ndag/test/claim/bmc_fan_converge_witness_test.dag\ndag/test/claim/bmc_firmware_evidence_install_mechanism_witness_test.dag\ndag/test/claim/bmc_firmware_thermal_witness_test.dag\ndag/test/claim/bmc_live_receipts_witness_test.dag\ndag/test/claim/bmc_netboot_serve_witness_test.dag\ndag/test/claim/bmc_netboot_shell_boot_witness_test.dag\ndag/test/claim/bmc_typed_operations_witness_test.dag\ndag/test/claim/bmc_virtual_media_witness_test.dag\ndag/test/claim/board_part_land_pattern_witness_test.dag\ndag/test/claim/body_lowering_refusal_scope_test.dag\ndag/test/claim/body_lowering_rejection_propagation_test.dag\ndag/test/claim/branded_list_first_optional_witness_test.dag\ndag/test/claim/build_cache_endpoint_path_test.dag\ndag/test/claim/build_cache_ensure_test.dag\ndag/test/claim/build_cache_latency_probe_witness_test.dag\ndag/test/claim/build_cache_placement_observation_test.dag\ndag/test/claim/build_fulfillment_witness_test.dag\ndag/test/claim/build_latency_actions_collect_witness_test.dag\ndag/test/claim/build_selection_witness_test.dag\ndag/test/claim/busybox_bmc_build_witness_test.dag\ndag/test/claim/cache_retention_axes_witness_test.dag\ndag/test/claim/capability_binding_witness_test.dag\ndag/test/claim/caret_syntax_witness_test.dag\ndag/test/claim/cargo_artifact_selection_witness_test.dag\ndag/test/claim/cargo_execution_placement_witness_test.dag\ndag/test/claim/change_realization_witness_test.dag\ndag/test/claim/chapman_which_path_observation_witness_test.dag\ndag/test/claim/char_at_unicode_witness_test.dag\ndag/test/claim/cheap_gate_pool_test.dag\ndag/test/claim/check_coverage_admission_witness_test.dag\ndag/test/claim/checkpoint_identity_keying_witness_test.dag\ndag/test/claim/ci_cost_arc_closeout_receipt_witness_test.dag\ndag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag\ndag/test/claim/citation_cit0_witness_test.dag\ndag/test/claim/citation_cit1_consumer_witness_test.dag\ndag/test/claim/citation_cit1_witness_test.dag\ndag/test/claim/claim_indexed_evidence_witness_test.dag\ndag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag\ndag/test/claim/class_b_strip_receipt_witness_test.dag\ndag/test/claim/claude_sdk_parser_drop_live_witness_test.dag\ndag/test/claim/claude_sdk_parser_drop_witness_test.dag\ndag/test/claim/claude_setup_token_enrollment_witness_test.dag\ndag/test/claim/cli_run_floor_lens_oracle_witness_test.dag\ndag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag\ndag/test/claim/cli_run_witness_admission_hand_rust_witness_test.dag\ndag/test/claim/cli_surface_boundary_probe_test.dag\ndag/test/claim/codex_app_server_press_wet_witness_test.dag\ndag/test/claim/codex_app_server_press_witness_test.dag\ndag/test/claim/codex_device_prompt_witness_test.dag\ndag/test/claim/codex_package_delivery_wet_witness_test.dag\ndag/test/claim/codex_package_lock_parse_witness_test.dag\ndag/test/claim/codex_provider_runtime_receipt_witness_test.dag\ndag/test/claim/codex_supervised_turn_wet_witness_test.dag\ndag/test/claim/codex_supervised_turn_witness_test.dag\ndag/test/claim/commit_check_demand_witness_test.dag\ndag/test/claim/commit_witness_claim_roster_witness_test.dag\ndag/test/claim/commit_writer_admission_witness_test.dag\ndag/test/claim/commit_writer_heal_admission_real_execution_witness_test.dag\ndag/test/claim/commit_writer_index_selection_witness_test.dag\ndag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag\ndag/test/claim/compile_diagnostic_census_witness_test.dag\ndag/test/claim/compile_pool_ensure_test.dag\ndag/test/claim/component_dispatch_button_witness_test.dag\ndag/test/claim/compute_board_admission_witness_test.dag\ndag/test/claim/compute_board_article_witness_test.dag\ndag/test/claim/compute_board_emission_entry_witness_test.dag\ndag/test/claim/compute_board_physical_witness_test.dag\ndag/test/claim/compute_board_pin_chain_witness_test.dag\ndag/test/claim/compute_board_power_distribution_witness_test.dag\ndag/test/claim/compute_board_readiness_witness_test.dag\ndag/test/claim/compute_board_simulation_receipt_witness_test.dag\ndag/test/claim/compute_board_spice_projection_witness_test.dag\ndag/test/claim/compute_board_verilog_projection_witness_test.dag\ndag/test/claim/content_hash_family_grounded_witness_test.dag\ndag/test/claim/cooling_qualification_witness_test.dag\ndag/test/claim/cpu_socket_termination_witness_test.dag\ndag/test/claim/crm_stage_vocabulary_witness_test.dag\ndag/test/claim/cross_file_binding_assembly_witness_test.dag\ndag/test/claim/css_grain_witness_test.dag\ndag/test/claim/cursor_cli_invocation_witness_test.dag\ndag/test/claim/cursor_sdk_argv_projection_witness_test.dag\ndag/test/claim/cursor_sdk_auth_standing_witness_test.dag\ndag/test/claim/cursor_sdk_dispatch_bridge_witness_test.dag\ndag/test/claim/cursor_sdk_model_witness_test.dag\ndag/test/claim/cursor_sdk_stream_witness_test.dag\ndag/test/claim/dag_compile_clean_cli_floor_agreement_witness_test.dag\ndag/test/claim/dag_line_comment_annotation_channel_test.dag\ndag/test/claim/dag_parse_continuation_operator_witness_test.dag\ndag/test/claim/decl_facts_initializer_projection_witness_test.dag\ndag/test/claim/decl_facts_reflection_witness_support.dag\ndag/test/claim/decl_facts_reflection_witness_test.dag\ndag/test/claim/deploy_revision_witness_test.dag\ndag/test/claim/deployed_tree_remote_witness_test.dag\ndag/test/claim/devboot_build_product_witness_test.dag\ndag/test/claim/devboot_reuse_seams_witness_test.dag\ndag/test/claim/devboot_subject_identity_witness_test.dag\ndag/test/claim/dgx_spark_pxe_witness_test.dag\ndag/test/claim/dgx_spark_witness_test.dag\ndag/test/claim/diff_baseline_witness_test.dag\ndag/test/claim/diff_window_cross_seam_witness_test.dag\ndag/test/claim/direct_rust_door_write_compile_witness_test.dag\ndag/test/claim/dispatch_attempts_witness_test.dag\ndag/test/claim/dispatch_presentation_witness_test.dag\ndag/test/claim/dispatch_selection_witness_test.dag\ndag/test/claim/dispatch_stop_witness_test.dag\ndag/test/claim/dissolution_census_mechanism_witness_test.dag\ndag/test/claim/dissolution_migration_census_witness_test.dag\ndag/test/claim/documentary_refs_witness_test.dag\ndag/test/claim/e0308_mechanical_trio_test.dag\ndag/test/claim/e0599_emitter_decision_census_witness_test.dag\ndag/test/claim/e0599_probe_census_witness_test.dag\ndag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag\ndag/test/claim/electrical_design_identity_witness_test.dag\ndag/test/claim/emitted_lib_rs_module_declaration_witness_test.dag\ndag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag\ndag/test/claim/emitter_nested_refinement_cast_witness_test.dag\ndag/test/claim/emitter_optional_payload_cast_witness_test.dag\ndag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag\ndag/test/claim/ensure_witness_test.dag\ndag/test/claim/eval_cast_identity_witness_test.dag\ndag/test/claim/evaluation_budget_witness_test.dag\ndag/test/claim/exact_witness_admission_witness_test.dag\ndag/test/claim/executor_schedule_retention_test.dag\ndag/test/claim/expectation_frontier_witness_test.dag\ndag/test/claim/extdeps_llm_claude_trust_witness_test.dag\ndag/test/claim/external_model_scope_live_cover_witness_test.dag\ndag/test/claim/external_model_scope_witness_test.dag\ndag/test/claim/fabric_budget_encumbrance_witness_test.dag\ndag/test/claim/fabric_terminal_contract_witness_test.dag\ndag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag\ndag/test/claim/firmware_prerequisite_evidence_witness_test.dag\ndag/test/claim/fleet_container_demand_envelope_witness_test.dag\ndag/test/claim/fleet_converge_plan_witness_test.dag\ndag/test/claim/fleet_converge_privilege_hold_witness_test.dag\ndag/test/claim/fleet_convergence_verdict_witness_test.dag\ndag/test/claim/fleet_host_key_enrollment_witness_test.dag\ndag/test/claim/fleet_known_hosts_anchor_witness_test.dag\ndag/test/claim/fleet_main_revision_witness_test.dag\ndag/test/claim/fleet_observation_producers_witness_test.dag\ndag/test/claim/fleet_receipt_collector_witness_test.dag\ndag/test/claim/fleet_runner_connectivity_witness_test.dag\ndag/test/claim/fleet_ssh_credential_verify_witness_test.dag\ndag/test/claim/float_add_associativity_law_witness_test.dag\ndag/test/claim/floor_batch_clamp_authority_witness_test.dag\ndag/test/claim/floor_component_receipt_witness_test.dag\ndag/test/claim/floor_discovery_exact_subject_witness_test.dag\ndag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag\ndag/test/claim/floor_discovery_roster_fixture_test.dag\ndag/test/claim/floor_expected_red_coherence_witness_test.dag\ndag/test/claim/floor_preparation_witness_test.dag\ndag/test/claim/floor_resolve_realization_witness_test.dag\ndag/test/claim/free_tier_serving_witness_test.dag\ndag/test/claim/frontend_literal_and_compile_witness_test.dag\ndag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag\ndag/test/claim/generic_item_clone_bound_witness_test.dag\ndag/test/claim/gha_job_projection_witness_test.dag\ndag/test/claim/git_ls_remote_witness_test.dag\ndag/test/claim/git_upstream_model_witness_test.dag\ndag/test/claim/gitattributes_emit_witness_test.dag\ndag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag\ndag/test/claim/github_app_registry_witness_test.dag\ndag/test/claim/gitlab_10k_income_series_witness_test.dag\ndag/test/claim/grub_cmdline_quoting_witness_test.dag\ndag/test/claim/guarantee_measurement_witness_test.dag\ndag/test/claim/guarantee_probe_corpus_witness_test.dag\ndag/test/claim/hand_maintained_map_key_seed_witness_test.dag\ndag/test/claim/hash_checkpoint_retired_witness_test.dag\ndag/test/claim/heal_revalidation_witness_test.dag\ndag/test/claim/homomorphism_trait_derive_emit_witness_test.dag\ndag/test/claim/host_axis_caps_witness_test.dag\ndag/test/claim/host_budget_source_witness_test.dag\ndag/test/claim/host_cli_dependency_wet_witness_test.dag\ndag/test/claim/host_cli_dependency_witness_test.dag\ndag/test/claim/host_codex_runtime_provision_design_witness_test.dag\ndag/test/claim/host_compile_pool_test.dag\ndag/test/claim/host_memory_qualification_witness_test.dag\ndag/test/claim/host_network_diagnosis_witness_test.dag\ndag/test/claim/host_phase_status_witness_test.dag\ndag/test/claim/host_reach_identity_probe_witness_test.dag\ndag/test/claim/host_swap_backing_witness_test.dag\ndag/test/claim/host_toolchain_components_witness_test.dag\ndag/test/claim/hostname_allocation_witness_test.dag\ndag/test/claim/ice40_configuration_witness_test.dag\ndag/test/claim/ice40_supply_witness_test.dag\ndag/test/claim/ilm4926_designation_witness_test.dag\ndag/test/claim/infer_occurrence_binding_scaffold_witness_test.dag\ndag/test/claim/install_transport_qualification_witness_test.dag\ndag/test/claim/installed_bom_reconcile_witness_test.dag\ndag/test/claim/instrument_bob_witness_test.dag\ndag/test/claim/instrument_camera_witness_test.dag\ndag/test/claim/instrument_motion_page_witness_test.dag\ndag/test/claim/instrument_physical_witness_test.dag\ndag/test/claim/instrument_sandbox_witness_test.dag\ndag/test/claim/instrument_tuner_witness_test.dag\ndag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag\ndag/test/claim/interpreter_replacement_cut_witness_test.dag\ndag/test/claim/inventory_ledger_witness_test.dag\ndag/test/claim/jq_invocation_lowering_witness_test.dag\ndag/test/claim/json_parse_witness_test.dag\ndag/test/claim/json_protocol_schema_memory_split_wet_witness_test.dag\ndag/test/claim/jwt_oidc_claims_witness_test.dag\ndag/test/claim/keyed_roster_witness_test.dag\ndag/test/claim/lambda_capture_clone_required_witness_test.dag\ndag/test/claim/language_module_home_test.dag\ndag/test/claim/language_source_scaffold_index_test.dag\ndag/test/claim/language_target_identity_witness_test.dag\ndag/test/claim/language_target_registry_totality_test.dag\ndag/test/claim/language_target_subject_registration_test.dag\ndag/test/claim/ledger_tail_liveness_witness_test.dag\ndag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag\ndag/test/claim/legacy_test_behavior_disposition_witness_test.dag\ndag/test/claim/legacy_test_inflow_witness_test.dag\ndag/test/claim/lifecycle_survivor_corpus_census_test.dag\ndag/test/claim/lifecycle_survivor_scan_witness_test.dag\ndag/test/claim/live_deploy/candidate_checkout_witness_test.dag\ndag/test/claim/live_deploy/deploy_release_fixture.dag\ndag/test/claim/live_deploy/running_release_identity_witness_test.dag\ndag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag\ndag/test/claim/live_rust_observation_contract_test.dag\ndag/test/claim/llm_attempt_receipt_witness_test.dag\ndag/test/claim/local_tidy_fmt_outcome_test.dag\ndag/test/claim/long/commit_witness_claim_roster_witness_test.dag\ndag/test/claim/long/dag_arrow_lambda_witness_test.dag\ndag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag\ndag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag\ndag/test/claim/long/dissolution_census_witness_test.dag\ndag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag\ndag/test/claim/long/g2_data_reference_under_selection_witness_test.dag\ndag/test/claim/long/instrument_sandbox_live_witness_test.dag\ndag/test/claim/long/namespace_graft_body_dissolution_witness_test.dag\ndag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag\ndag/test/claim/long/realization_sweep_test.dag\ndag/test/claim/long/roadmap_page_witness_test.dag\ndag/test/claim/long/root_d_checkpoint_scalar_declared_arity_witness_test.dag\ndag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag\ndag/test/claim/long/v1_complexity_capability_census_resolution_test.dag\ndag/test/claim/long/v1_complexity_decl_classification_totality_test.dag\ndag/test/claim/long/where_refinement_enforcement_witness_test.dag\ndag/test/claim/managed_directory_witness_test.dag\ndag/test/claim/map_key_derive_requirement_witness_test.dag\ndag/test/claim/match_arm_pattern_identity_emission_witness_test.dag\ndag/test/claim/match_exhaustiveness_coproduct_witness_test.dag\ndag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag\ndag/test/claim/materialization_provider_consumer_hand_rust_witness_test.dag\ndag/test/claim/materialization_provider_witness_test.dag\ndag/test/claim/materialized_secret_witness_test.dag\ndag/test/claim/materialized_ssh_key_file_real_execution_witness_test.dag\ndag/test/claim/media_type_witness_test.dag\ndag/test/claim/memory_provisioning_witness_test.dag\ndag/test/claim/mercurial_upstream_model_witness_test.dag\ndag/test/claim/merge_admission_attempt_witness_test.dag\ndag/test/claim/model_artifact_identity_witness_test.dag\ndag/test/claim/module_graph_edge_source_witness_test.dag\ndag/test/claim/module_impact_query_witness_test.dag\ndag/test/claim/mt_jade_platform_witness_test.dag\ndag/test/claim/namespace_clause_e_projection_law_witness_test.dag\ndag/test/claim/namespace_occurrence_transport_test.dag\ndag/test/claim/namespace_pool_independence_witness_test.dag\ndag/test/claim/namespace_reference_derived_closure_acceptance_test.dag\ndag/test/claim/namespace_reference_derived_closure_contract_test.dag\ndag/test/claim/namespace_structural_root_exposure_generated_witness_test.dag\ndag/test/claim/native_scm_interaction_contract_witness_test.dag\ndag/test/claim/native_scm_interaction_scenario_fixture.dag\ndag/test/claim/native_witness_transition_receipt_witness_test.dag\ndag/test/claim/network_grounding_witness_test.dag\ndag/test/claim/no_fake_anomalies_witness_test.dag\ndag/test/claim/node_power_envelope_witness_test.dag\ndag/test/claim/non_fold_residue_frontier_test.dag\ndag/test/claim/normalize_retention_contract_probe_test.dag\ndag/test/claim/npm_sri_witness_test.dag\ndag/test/claim/observation_ci_render_witness_test.dag\ndag/test/claim/observation_crawl_replay_test.dag\ndag/test/claim/observation_emit_census_witness_test.dag\ndag/test/claim/observation_instant_witness_test.dag\ndag/test/claim/observation_lockstep_witness_test.dag\ndag/test/claim/observation_model_witness_test.dag\ndag/test/claim/observation_raw_print_retirement_acceptance_test.dag\ndag/test/claim/observation_rollup_witness_test.dag\ndag/test/claim/observation_seed_scoped_run_witness_test.dag\ndag/test/claim/observation_tty_render_witness_test.dag\ndag/test/claim/occurrence_binding_candidates_witness_test.dag\ndag/test/claim/occurrence_binding_resolve_witness_test.dag\ndag/test/claim/occurrence_binding_witness_test.dag\ndag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag\ndag/test/claim/occurrence_identity_witness_test.dag\ndag/test/claim/ollama_capability_witness_test.dag\ndag/test/claim/operation_argv_binding_wall_witness_test.dag\ndag/test/claim/operation_argv_corpus_witness_test.dag\ndag/test/claim/optional_carrier_signature_test.dag\ndag/test/claim/optional_consumer_fail_closed_test.dag\ndag/test/claim/orthogonal_geometry_witness_test.dag\ndag/test/claim/orthogonal_topology_witness_test.dag\ndag/test/claim/package_delivery_codex_integrity_witness_test.dag\ndag/test/claim/package_graph_witness_test.dag\ndag/test/claim/pareto_selection_witness_test.dag\ndag/test/claim/pcb_capability_established_witness_test.dag\ndag/test/claim/pcb_copper_witness_test.dag\ndag/test/claim/pcb_footprint_witness_test.dag\ndag/test/claim/pcb_stackup_witness_test.dag\ndag/test/claim/pijul_upstream_model_witness_test.dag\ndag/test/claim/planar_projection_witness_test.dag\ndag/test/claim/posix_principal_allocation_witness_test.dag\ndag/test/claim/preemption_reachability_witness_test.dag\ndag/test/claim/primitive_identity_join_witness_test.dag\ndag/test/claim/principal_projection_witness_test.dag\ndag/test/claim/proc_self_cgroup_real_execution_witness_test.dag\ndag/test/claim/proc_self_cgroup_witness_test.dag\ndag/test/claim/prose_row_introduction_witness_test.dag\ndag/test/claim/provider_account_admission_witness_test.dag\ndag/test/claim/provider_lifecycle_witness_test.dag\ndag/test/claim/provider_standing_probe_bridge_witness_test.dag\ndag/test/claim/provider_standing_selection_witness_test.dag\ndag/test/claim/provider_standing_witness_test.dag\ndag/test/claim/publication_publisher_witness_test.dag\ndag/test/claim/push_event_witness_test.dag\ndag/test/claim/push_event_witness_wet_test.dag\ndag/test/claim/qualified_declaration_reference_emit_witness_test.dag\ndag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag\ndag/test/claim/rack_mount_witness_test.dag\ndag/test/claim/rack_power_witness_test.dag\ndag/test/claim/readback_independence_witness_test.dag\ndag/test/claim/realization_attempt_keystone_test.dag\ndag/test/claim/realization_vocab_confinement_census_test.dag\ndag/test/claim/record_construction_census_witness_test.dag\ndag/test/claim/record_literal_call_arg_handoff_witness_test.dag\ndag/test/claim/recorded_observation_envelope_witness_test.dag\ndag/test/claim/reference_derived_authored_source_gate_witness_test.dag\ndag/test/claim/reference_derived_variant_induced_parent_gate_witness_test.dag\ndag/test/claim/reference_instrument_witness_test.dag\ndag/test/claim/regional_compute_witness_test.dag\ndag/test/claim/remote_shell_command_witness_test.dag\ndag/test/claim/replacement_cut_witness_test.dag\ndag/test/claim/repo_atlas_projection_witness_test.dag\ndag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag\ndag/test/claim/repo_local_git_config_real_execution_witness_test.dag\ndag/test/claim/repo_local_git_config_witness_test.dag\ndag/test/claim/repository_census_coverage_witness_test.dag\ndag/test/claim/repository_census_observation_witness_test.dag\ndag/test/claim/required_expr_newline_continuation_witness_test.dag\ndag/test/claim/required_regen_admission_witness_test.dag\ndag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag\ndag/test/claim/rest_exchange_replay_test.dag\ndag/test/claim/retained_shell_script_witness_test.dag\ndag/test/claim/roadmap_altitude_witness_test.dag\ndag/test/claim/roadmap_dashboard_instance_apply_witness_test.dag\ndag/test/claim/roadmap_dashboard_instance_witness_test.dag\ndag/test/claim/roadmap_dispatch_environment_witness_test.dag\ndag/test/claim/roadmap_execution_contract_witness_test.dag\ndag/test/claim/roadmap_focus_witness_test.dag\ndag/test/claim/roadmap_forecast_witness_test.dag\ndag/test/claim/roadmap_identity_witness_test.dag\ndag/test/claim/roadmap_presentation_witness_test.dag\ndag/test/claim/roadmap_program_view_live_corpus_receipt_test.dag\ndag/test/claim/roadmap_program_view_witness_test.dag\ndag/test/claim/roadmap_provider_events_witness_test.dag\ndag/test/claim/roadmap_publish_observe_witness_test.dag\ndag/test/claim/roadmap_publish_witness_test.dag\ndag/test/claim/roadmap_receipt_continuity_acceptance_fixture.dag\ndag/test/claim/roadmap_receipt_continuity_acceptance_test.dag\ndag/test/claim/roadmap_receipt_continuity_live_witness_test.dag\ndag/test/claim/roadmap_repo_atlas_sandbox_witness_test.dag\ndag/test/claim/roadmap_row_witness_test.dag\ndag/test/claim/roadmap_sandbox_witness_test.dag\ndag/test/claim/roadmap_site_surface_readiness_witness_test.dag\ndag/test/claim/roadmap_tactile_witness_test.dag\ndag/test/claim/roadmap_validation_oracle_witness_test.dag\ndag/test/claim/roadmap_verification_receipt_witness_test.dag\ndag/test/claim/roadmap_verify_witness_test.dag\ndag/test/claim/roadmap_workflow_command_witness_test.dag\ndag/test/claim/roadmap_workflow_progress_witness_test.dag\ndag/test/claim/root4_measure_missing_generics_witness_test.dag\ndag/test/claim/run_verdict_exit_status_fixture.dag\ndag/test/claim/run_verdict_exit_status_witness_test.dag\ndag/test/claim/runner_activation_wall_test.dag\ndag/test/claim/runner_broker_progress_watchdog_witness_test.dag\ndag/test/claim/runner_capacity_operator_access_witness_test.dag\ndag/test/claim/runner_capacity_plan_witness_test.dag\ndag/test/claim/runner_capacity_realize_witness_test.dag\ndag/test/claim/runner_connectivity_recovery_witness_test.dag\ndag/test/claim/runner_connectivity_repair_plan_witness_test.dag\ndag/test/claim/runner_host_deploy_witness_test.dag\ndag/test/claim/runner_lifecycle_witness_test.dag\ndag/test/claim/runner_replace_incarnation_seam_witness_test.dag\ndag/test/claim/runner_slot_installation_state_witness_test.dag\ndag/test/claim/runner_slot_provision_witness_test.dag\ndag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag\ndag/test/claim/rust_item_identity_witness_test.dag\ndag/test/claim/salience_witness_test.dag\ndag/test/claim/samsung_dram_module_witness_test.dag\ndag/test/claim/scaffold_disposition_census_fixture_witness_test.dag\ndag/test/claim/sccache_pin_witness_test.dag\ndag/test/claim/scm_agentic_stress_witness_test.dag\ndag/test/claim/scm_compatibility_git_witness_test.dag\ndag/test/claim/scm_compatibility_mercurial_witness_test.dag\ndag/test/claim/scm_compatibility_pijul_witness_test.dag\ndag/test/claim/scm_compatibility_shape_witness_test.dag\ndag/test/claim/scm_issuer_corpus_witness_test.dag\ndag/test/claim/scm_provider_matrix_witness_test.dag\ndag/test/claim/scm_serving_model_witness_test.dag\ndag/test/claim/secret_manager_access_version_witness_test.dag\ndag/test/claim/secret_provision_witness_test.dag\ndag/test/claim/secret_rotation_witness_test.dag\ndag/test/claim/seed_growth_admission_witness_test.dag\ndag/test/claim/seed_honesty_discharge_unavailable_test.dag\ndag/test/claim/self_host_artifact_materialization_real_execution_witness_test.dag\ndag/test/claim/self_host_artifact_materialization_witness_test.dag\ndag/test/claim/self_host_generation_identity_witness_test.dag\ndag/test/claim/self_host_promotion_admission_witness_test.dag\ndag/test/claim/self_host_promotion_obligations_witness_test.dag\ndag/test/claim/served_surface_browser_artifact_integrity_witness_test.dag\ndag/test/claim/served_surface_browser_observation_witness_test.dag\ndag/test/claim/serving_privilege_derivation_witness_test.dag\ndag/test/claim/session_residency_witness_test.dag\ndag/test/claim/sessions_panel_witness_test.dag\ndag/test/claim/shared_pool_encoding_control_test.dag\ndag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag\ndag/test/claim/shell_stream_capture_witness_test.dag\ndag/test/claim/shell_target_conformance_witness_test.dag\ndag/test/claim/source_admission_selection_witness_test.dag\ndag/test/claim/source_annotation_attachment_witness_test.dag\ndag/test/claim/source_integration_landing_spine_witness_test.dag\ndag/test/claim/source_integration_proof_kernel_acceptance_test.dag\ndag/test/claim/source_integration_proof_kernel_model_witness_test.dag\ndag/test/claim/spark_bootstrap_provision_witness_test.dag\ndag/test/claim/spark_capability_observation_witness_test.dag\ndag/test/claim/spark_credential_workflow_witness_test.dag\ndag/test/claim/spark_serving_converge_slice_witness_test.dag\ndag/test/claim/spark_serving_effect_wire_witness_test.dag\ndag/test/claim/spark_serving_full_plan_witness_test.dag\ndag/test/claim/spark_serving_member_realization_witness_test.dag\ndag/test/claim/spark_serving_membership_witness_test.dag\ndag/test/claim/spark_serving_observe_witness_test.dag\ndag/test/claim/spark_serving_realization_witness_test.dag\ndag/test/claim/spark_serving_release_witness_test.dag\ndag/test/claim/spark_serving_runtime_receipt_witness_test.dag\ndag/test/claim/spark_serving_write_unit_operation_witness_test.dag\ndag/test/claim/spatial_connectivity_witness_test.dag\ndag/test/claim/spatial_edit_witness_test.dag\ndag/test/claim/spatial_frame_scale_witness_test.dag\ndag/test/claim/spatial_knowledge_witness_test.dag\ndag/test/claim/spatial_placement_witness_test.dag\ndag/test/claim/spatial_projection_witness_test.dag\ndag/test/claim/spatial_units_witness_test.dag\ndag/test/claim/spatial_world_witness_test.dag\ndag/test/claim/srv1_tasks_preapply_observation_witness_test.dag\ndag/test/claim/srv3_subsumption_witness_test.dag\ndag/test/claim/ssh_client_options_witness_test.dag\ndag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag\ndag/test/claim/stage0_rust_honest_frontier_integration_witness_test.dag\ndag/test/claim/stage0_rust_honest_frontier_projection_witness_test.dag\ndag/test/claim/stage0_rust_host_observation_live_witness_test.dag\ndag/test/claim/stage0_rust_lifecycle_totality_witness_test.dag\ndag/test/claim/stage0_rust_maintenance_census_report_live_witness_test.dag\ndag/test/claim/stage0_rust_maintenance_census_report_witness_test.dag\ndag/test/claim/stage0_rust_product_reachability_witness_test.dag\ndag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag\ndag/test/claim/state_durability_witness_test.dag\ndag/test/claim/state_response_totality_witness_test.dag\ndag/test/claim/string_brace_escape_witness_test.dag\ndag/test/claim/string_length_char_count_witness_test.dag\ndag/test/claim/structured_application_mismatch_wall_witness_test.dag\ndag/test/claim/systemctl_status_read_scaffold_witness_test.dag\ndag/test/claim/systemd_unit_file_witness_test.dag\ndag/test/claim/tailscale_serve_route_key_witness_test.dag\ndag/test/claim/tailscale_serve_status_witness_test.dag\ndag/test/claim/terminal_wire_projection_witness_test.dag\ndag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag\ndag/test/claim/tmux_session_list_outcome_witness_test.dag\ndag/test/claim/tool_pin_witness_test.dag\ndag/test/claim/tool_readiness_witness_test.dag\ndag/test/claim/trait_bound_witness_test.dag\ndag/test/claim/transport_script_stdin_byte_fidelity_witness_test.dag\ndag/test/claim/transport_script_wall_compile_red_test.dag\ndag/test/claim/type_ref_hit_ne_bind_measure_witness_test.dag\ndag/test/claim/type_reference_binding_context_witness_test.dag\ndag/test/claim/type_reference_containment_binding_witness_test.dag\ndag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag\ndag/test/claim/typed_module_cache_capacity_witness_test.dag\ndag/test/claim/typed_remote_file_converge_witness_test.dag\ndag/test/claim/typed_remote_file_write_fleet_ssh_fixture.dag\ndag/test/claim/typed_remote_file_write_witness_test.dag\ndag/test/claim/uefi_boot_config_witness_test.dag\ndag/test/claim/uefi_boot_install_decision_witness_test.dag\ndag/test/claim/uefi_shell_environment_witness_test.dag\ndag/test/claim/uefi_shell_over_sol_witness_test.dag\ndag/test/claim/uri_percent_encode_witness_test.dag\ndag/test/claim/v1_complexity_capability_census_witness_test.dag\ndag/test/claim/v1_complexity_decl_classification_witness_test.dag\ndag/test/claim/v1_interpreter_primitive_dispatch_authority_acceptance_test.dag\ndag/test/claim/v1_interpreter_primitive_roster_acceptance_test.dag\ndag/test/claim/v1_interpreter_primitive_surface_witness_test.dag\ndag/test/claim/verification_evidence_addressing_witness_test.dag\ndag/test/claim/virtual_media_unification_witness_test.dag\ndag/test/claim/wc_byte_count_verification_witness_test.dag\ndag/test/claim/web_motion_binding_witness_test.dag\ndag/test/claim/witness_deferral_freeze_witness_test.dag\ndag/test/claim/witness_execution_class_live_census_test.dag\ndag/test/claim/witness_execution_class_test.dag\ndag/test/claim/witness_purpose_taxonomy_witness_test.dag\ndag/test/claim/witness_row_cost_drift_witness_test.dag\ndag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag\ndag/test/claim/witness_row_cost_projection_witness_test.dag\ndag/test/claim/workflow_dispatch_input_witness_test.dag\ndag/test/claim/workflow_reconcile_witness_test.dag\ndag/test/fixture/anonhead_provider.dag\ndag/test/fixture/argv_executable_position_probe.dag\ndag/test/fixture/codex_device_login/README.md\ndag/test/fixture/codex_device_login/device_auth_prompt_2026-07-30.txt\ndag/test/fixture/codex_device_login/device_auth_prompt_tmux_2026-07-30.txt\ndag/test/fixture/codex_provider_events/README.md\ndag/test/fixture/codex_provider_events/agent_message_turn_2026-07-29.jsonl\ndag/test/fixture/cross_file_clause_e_fixture.dag\ndag/test/fixture/cross_shard_seam/importee.dag\ndag/test/fixture/cross_shard_seam/importer.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_b_specimen.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_shared_a.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_shared_b.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_specimen.dag\ndag/test/fixture/decl_facts_reflection/globally_unique_carrier.dag\ndag/test/fixture/decl_facts_reflection/specimens.dag\ndag/test/fixture/decl_facts_reflection/unimported_globally_unique_user.dag\ndag/test/fixture/decl_facts_reflection/witness_support.dag\ndag/test/fixture/decl_facts_reflection_duplicate_qn/primary/shadow_module.dag\ndag/test/fixture/floor_expected_red_coherence/severed_chunk_fixture.dag\ndag/test/fixture/github_push_event/main_push.json\ndag/test/fixture/leaf_key_collision/cross_kind_data_fn/module_a.dag\ndag/test/fixture/leaf_key_collision/cross_kind_data_fn/module_b.dag\ndag/test/fixture/leaf_key_collision/cross_kind_fn_data/module_a.dag\ndag/test/fixture/leaf_key_collision/cross_kind_fn_data/module_b.dag\ndag/test/fixture/leaf_key_collision/module_a.dag\ndag/test/fixture/leaf_key_collision/module_b.dag\ndag/test/fixture/module_graph_edge_source/consumer_bare.dag\ndag/test/fixture/module_graph_edge_source/consumer_imported.dag\ndag/test/fixture/module_graph_edge_source/provider_imported.dag\ndag/test/fixture/module_graph_edge_source/provider_referenced.dag\ndag/test/fixture/provider_terminal/codex_account_rate_limits_exhausted_multibucket_2026-08-06.jsonl\ndag/test/fixture/provider_terminal/codex_account_read_chatgpt_redacted_2026-08-06.jsonl\ndag/test/fixture/record_construction_census/homonym.dag\ndag/test/fixture/record_construction_census/qualified.dag\ndag/test/fixture/record_construction_census/specimens.dag\ndag/test/fixture/rest_exchange_replay_probe.dag\ndag/test/fixture/scaffold_disposition_census/expected_classification.dag\ndag/test/fixture/scaffold_disposition_census/pool/decoy_nullary.dag\ndag/test/fixture/scaffold_disposition_census/pool/decoy_record.dag\ndag/test/fixture/scaffold_disposition_census/pool/specimens.dag\ndag/test/fixture/scaffold_disposition_census/pool_notes.dag\ndag/test/fixture/sole_constructor_sealed/admitted_caller.dag\ndag/test/fixture/sole_constructor_sealed/definer.dag\ndag/test/fixtures/browser/chromium_151_bodied_502.png\ndag/test/fixtures/browser/chromium_151_connection_refused.png\ndag/test/fixtures/browser/chromium_151_empty_502.png\ndag/test/manual/git_upstream_model_execution_test.dag\ndag/test/manual/mercurial_upstream_model_execution_test.dag\ndag/test/manual/pijul_upstream_model_execution_test.dag\ndag/test/manual/process_argv_expansion_receipt_test.dag\ndag/tools/body_lowering_population_probe.dag\ndag/tools/cheap_claim_pool_gate.dag\ndag/tools/cheap_gate_pool.dag\ndag/tools/ci_heal_dispatch.dag\ndag/tools/dag_compile_clean_cli_floor_agreement.dag\ndag/tools/direct_rust_door_transport.dag\ndag/tools/e0599_emitter_decision_census.dag\ndag/tools/e0599_probe_census.dag\ndag/tools/extdeps_scope_placement_gate.dag\ndag/tools/frontier_ingestion_probe.dag\ndag/tools/interpreter_dispatch_bijection_real_roster_transport.dag\ndag/tools/merge_admission_capture.dag\ndag/tools/merge_admission_capture_transport.dag\ndag/tools/merge_admission_current_context.dag\ndag/tools/merge_admission_walk.dag\ndag/tools/module_impact_query_front_door.dag\ndag/tools/namespace_structural_root_exposure_generated_witness_transport.dag\ndag/tools/prose_row_introduction_gate.dag\ndag/tools/publication_publisher.dag\ndag/tools/publication_push_shadow.dag\ndag/tools/self_host_03_normalize_declared_source_refs.dag\ndag/tools/self_host_03_normalize_shims/std_algebra.rs\ndag/tools/self_host_03_normalize_shims/std_types.rs\ndag/tools/self_host_03_normalize_shims/v2_compiler_namespace_graft.rs\ndag/tools/self_host_module_behavioral_transport_roster.dag\ndag/tools/self_host_std_bridge_shims/v2_std_integer.rs\ndocs/plans/arc-store-path-migration-decision.md\ndocs/plans/build-cache-placement-receipt.md\ndocs/plans/c1-cost-expr-authority-design.md\ndocs/plans/candidate-scoped-gates-atomic-landing.md\ndocs/plans/ci-floor-child-spawn-attribution.md\ndocs/plans/ci-floor-time-45-72-band-attribution.md\ndocs/plans/ci-invocation-fixed-tax-attribution.md\ndocs/plans/ci-minutes-product-design.md\ndocs/plans/ci-two-tier-placement-redesign.md\ndocs/plans/ci0-witness-execution-census.md\ndocs/plans/ci2-native-cutover-reobservation.md\ndocs/plans/cli-invocation-emission-design.md\ndocs/plans/cli-run-hollowing-plan.md\ndocs/plans/compiler-guarantee-recovery-gap-analysis.md\ndocs/plans/containment-binding-cross-module-type-references-design.md\ndocs/plans/content-hash-family-grounding.md\ndocs/plans/cross-platform-instrument-motion.md\ndocs/plans/dag-native-scm-design.md\ndocs/plans/dag-note-prose-census.md\ndocs/plans/dag-prose-policy-audit.md\ndocs/plans/dag-scm-design.md\ndocs/plans/determinism-boundary-relative.md\ndocs/plans/discrete-cost-derivation.md\ndocs/plans/disk-tier-repeat-resolve-closeout.md\ndocs/plans/dissolution-census-a-ci-layer-roots.md\ndocs/plans/e0599-implementation-proposal.md\ndocs/plans/emission-admission-stage-aware-pipeline-design.md\ndocs/plans/entry-graph-union-slice1-measurement.md\ndocs/plans/entry-graph-union-slice2-typecheck-attribution.md\ndocs/plans/entry-view-assembly-direction-receipt.md\ndocs/plans/extdeps-modeling-preflight.md\ndocs/plans/extdeps-positioning-restructure.md\ndocs/plans/extdeps-std-grounding-inventory.md\ndocs/plans/fabric-concept-reconciliation.md\ndocs/plans/fabric-recut-program.md\ndocs/plans/fallback-arm-census.md\ndocs/plans/fill-composition-overlay-direction-receipt.md\ndocs/plans/five-minute-ci-gate-design.md\ndocs/plans/floor-cut-replacement-plan.md\ndocs/plans/floor-expected-red-shrink-monotonicity-design.md\ndocs/plans/floor-prep-tax-program.md\ndocs/plans/floor-semantic-artifact-design.md\ndocs/plans/floor-shared-fill-ledger.md\ndocs/plans/for-sugar-over-fold.md\ndocs/plans/formal-concepts-extdeps-grounding.md\ndocs/plans/four-lane-closeout-and-root.md\ndocs/plans/generated-file-conflict-policy.md\ndocs/plans/git-plumbing-extdeps-authority-design.md\ndocs/plans/groupcompletion-pair-construction-design.md\ndocs/plans/hermetic-tool-provisioning-design.md\ndocs/plans/holds-base-runtime-error-investigation-receipts.md\ndocs/plans/hollow-alias-construction-wall.md\ndocs/plans/import-strip-measurement/README.md\ndocs/plans/import-strip-measurement/receipts/control-diagnostics.log\ndocs/plans/import-strip-measurement/receipts/declaration-census-duplicates.tsv\ndocs/plans/import-strip-measurement/receipts/stripped-diagnostics.log\ndocs/plans/import-strip-measurement/receipts/stripped-file-manifest.tsv\ndocs/plans/import-strip-measurement/receipts/subject-tree-hash.txt\ndocs/plans/import-strip-measurement/receipts/summary.txt\ndocs/plans/import-strip-residual-ledger.tsv\ndocs/plans/inner-cost-lanes-scoping.md\ndocs/plans/keying-relation-design.md\ndocs/plans/language-support-completion-design.md\ndocs/plans/m2-floor-retention-measurement-receipt.md\ndocs/plans/measurements/floor-slow-rows-2026-08-17.md\ndocs/plans/measurements/floor-slow-rows-2026-08-17.tsv\ndocs/plans/measurements/floor-slow-rows-2026-08-18.md\ndocs/plans/measurements/floor-slow-rows-2026-08-18.tsv\ndocs/plans/namespace-cut-replacement-plan.md\ndocs/plans/namespace-flip-last-28-root-a-two-std-defork.md\ndocs/plans/namespace-unique-on-chain-operational-plan.md\ndocs/plans/nat-grounding-unification-design.md\ndocs/plans/native-selected-witness-bundle-design.md\ndocs/plans/p1-retention-vs-drain-cohort-receipt.md\ndocs/plans/p3-classification-cost-ab-receipt.md\ndocs/plans/parked-questions.md\ndocs/plans/per-entry-assembly-decomposition-measurement.md\ndocs/plans/production-stage-origin-carrier-design.md\ndocs/plans/progress-observation-design.md\ndocs/plans/provider-control-interface-audit.md\ndocs/plans/push-event-affected-set-baseline-design.md\ndocs/plans/receipts/arc-1-shareability-frontier/after-r1.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/after-r2.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/base-r1.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/base-r2.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/subject.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/summary.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-broad-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-broad.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-narrow-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-narrow.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-typical-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-typical.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-amortization-n1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-amortization-n6.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-ci_floor_measurement-r1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-ci_floor_measurement-r2.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-generated_artifact_drift-r1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-generated_artifact_drift-r2.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition.txt\ndocs/plans/receipts/entry-graph-union-slice2/matrix-governor.log\ndocs/plans/receipts/entry-graph-union-slice2/matrix-run.log\ndocs/plans/receipts/entry-graph-union-slice2/receipt-broad-capped.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-broad-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-explicit-order-a.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-explicit-order-b.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-narrow-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-narrow-production.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-reorder-a.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-reorder-b.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-representative-50.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-typical-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-typical-production.json\ndocs/plans/receipts/entry-view-assembly-direction/after-r1.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/after-r1.tsv\ndocs/plans/receipts/entry-view-assembly-direction/after-r2.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/after-r2.tsv\ndocs/plans/receipts/entry-view-assembly-direction/base-arm-revert.patch\ndocs/plans/receipts/entry-view-assembly-direction/base-r1.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/base-r1.tsv\ndocs/plans/receipts/entry-view-assembly-direction/base-r2.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/base-r2.tsv\ndocs/plans/receipts/entry-view-assembly-direction/binary_sha256.txt\ndocs/plans/receipts/entry-view-assembly-direction/cohort.tsv\ndocs/plans/receipts/entry-view-assembly-direction/remote_cohort_run3.log\ndocs/plans/receipts/entry-view-assembly-direction/summary.json\ndocs/plans/receipts/fill-composition-overlay-direction/after-r1.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/after-r1.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/after-r2.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/after-r2.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/base-arm-revert.patch\ndocs/plans/receipts/fill-composition-overlay-direction/base-r1.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/base-r1.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/base-r2.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/base-r2.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/cohort.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/subject.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/summary.json\ndocs/plans/receipts/m2-floor-retention-falsifier-batch1.json\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-candidate-cli_run.patch\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-control-cli_run.patch\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-probe.patch\ndocs/plans/receipts/partition-floor-wall-mapping/ci-run-31156588100.snapshot.txt\ndocs/plans/receipts/per-entry-assembly-decomposition/representative-50-r1.txt\ndocs/plans/receipts/per-entry-assembly-decomposition/representative-50-r2.txt\ndocs/plans/receipts/wrapper-consolidation-neutrality/summary.json\ndocs/plans/reconcile-cost-root-cause.md\ndocs/plans/recursive-workflow-advancement-design.md\ndocs/plans/replacement-migration-doctrine.md\ndocs/plans/resolve-regression-journey.md\ndocs/plans/restore-src-v1-required-floor-stall-finding.md\ndocs/plans/review-surface-subject-map.md\ndocs/plans/roadmap-presentation-seam-design.md\ndocs/plans/roadmap-workspace-remodel-plan.md\ndocs/plans/roadmap-workspace-ux-plan.md\ndocs/plans/scaffold-admission-doctrine.md\ndocs/plans/seamless-deploys-design.md\ndocs/plans/secret-version-lifecycle.md\ndocs/plans/self-host-cargo-refusal-root-partition.md\ndocs/plans/sole-modeled-publisher-design.md\ndocs/plans/spark-standup-program-accounting.md\ndocs/plans/srv1-deploy-serialization-and-false-greens.md\ndocs/plans/srv4-bmc-onboarding-gap.md\ndocs/plans/test-decomposition-wcf-cut.md\ndocs/plans/v1rt-witness-diagnostic-carrier-decouple-design.md\ndocs/plans/v2-complexity-capability-parity.md\ndocs/plans/v2-frontend-std-ingestion-frontier-exact-head.md\ndocs/plans/v2-frontend-std-ingestion-frontier.md\ndocs/plans/value-null-split.md\ndocs/plans/width-2-crossover-receipt.md\ndocs/plans/witness-bridge-reobservation.md\ndocs/plans/witness-cost-derives-from-purpose.md\ndocs/plans/witness-cost-first-touch-attribution.md\ndocs/plans/witness-evidence-lifecycle-design.md\ndocs/plans/worker-private-memory-decomposition.md\nfixtures/builtin_shadow/free_call_shadow_specimen.dag\nfixtures/builtin_shadow/method_template_shadow_specimen.dag\nfixtures/class_b_import_closure/perturbation_overlay/src/v2/extdeps/languages/rust_pool_perturb_ambient.dag\nfixtures/class_b_import_closure/perturbation_overlay/src/v2/extdeps/languages/rust_test_decoy.dag\nfixtures/class_b_trim/coincidence_specimen.dag\nfixtures/class_b_trim/monoid_specimen.dag\nfixtures/class_b_trim/narrow_pool/dag/std/types.dag\nfixtures/class_b_trim/perturbation_overlay/dag/std/tr_import_ambient.dag\nfixtures/class_b_trim/specimen.dag\nfixtures/class_b_trim/wire_projection_specimen.dag\nprovider-runtime/codex/README.md\nprovider-runtime/codex/package-lock.json\nprovider-runtime/codex/package.json\nsrc/v1/04_occurrence_binding.dag\nsrc/v1/annotation_bind.dag\nsrc/v1/expected_red_roster_join.dag\nsrc/v1/frontend_observation.dag\nsrc/v1/gunbc/namespace_reference_derived_closure_production_observations.dag\nsrc/v1/gunbc/occurrence_binding_parser_walk.dag\nsrc/v1/stage0/build.rs\nsrc/v1/stage0/src/bin/codex_app_server_stdio_session.rs\nsrc/v1/stage0/src/bin/namespace_structural_root_exposure_generated_witness.rs\nsrc/v1/stage0/src/bin/p1_cohort_roster.txt\nsrc/v1/stage0/src/bin/p1_cohort_small_roster.txt\nsrc/v1/stage0/src/bounded_shell_host_drain.rs\nsrc/v1/stage0/src/cli_run/floor_discovery_snapshot.rs\nsrc/v1/stage0/src/cli_run/materialization_provider_consumer.rs\nsrc/v1/stage0/src/cli_run/roadmap_acceptance_history_carrier.rs\nsrc/v1/stage0/src/cli_run/shared_fill.rs\nsrc/v1/stage0/src/cli_run/test_module_hygiene_bridge.rs\nsrc/v1/stage0/src/codex_app_server_stdio_session.rs\nsrc/v1/stage0/src/data_initializer_identity.rs\nsrc/v1/stage0/src/derived_realization_schedule.rs\nsrc/v1/stage0/src/extdeps_container_oci_digest.rs\nsrc/v1/stage0/src/extdeps_units_dimensionless.rs\nsrc/v1/stage0/src/extdeps_units_iec_80000_13.rs\nsrc/v1/stage0/src/extdeps_units_iso8601.rs\nsrc/v1/stage0/src/extdeps_units_iso_80000_3.rs\nsrc/v1/stage0/src/gunbc_rust_decl_type_overlay.rs\nsrc/v1/stage0/src/required_regen_host.rs\nsrc/v1/stage0/src/std_checked_arithmetic.rs\nsrc/v1/stage0/src/std_dissolution.rs\nsrc/v1/stage0/src/std_keyed_roster.rs\nsrc/v1/stage0/src/std_keyed_row.rs\nsrc/v1/stage0/src/std_occurrence_binding.rs\nsrc/v1/stage0/src/std_occurrence_binding_candidates.rs\nsrc/v1/stage0/src/std_occurrence_binding_resolve.rs\nsrc/v1/stage0/src/std_occurrence_identity.rs\nsrc/v1/stage0/src/std_process_termination.rs\nsrc/v1/stage0/src/std_reference_binding_observation.rs\nsrc/v1/stage0/src/std_roster_frontier.rs\nsrc/v1/stage0/src/std_source_annotation.rs\nsrc/v1/stage0/src/std_trait_derive_shape.rs\nsrc/v1/stage0/src/std_unicode_types.rs\nsrc/v1/stage0/src/std_witness_admission.rs\nsrc/v1/stage0/src/v1_compiler_annotation_bind.rs\nsrc/v1/stage0/src/v1_compiler_expected_red_roster_join.rs\nsrc/v1/stage0/src/v1_compiler_frontend_observation.rs\nsrc/v1/stage0/src/v1_compiler_infer_occurrence_binding.rs\nsrc/v1/stage0/src/v1_compiler_trait_bound_witness.rs\nsrc/v1/stage0/src/v1_compiler_trait_derive_emit.rs\nsrc/v1/stage0/src/v1_gunbc_namespace_reference_derived_closure_production_observations.rs\nsrc/v1/stage0/src/v1_gunbc_occurrence_binding_parser_walk.rs\nsrc/v1/stage0/src/v1_interpreter_dispatch_generated.rs\nsrc/v1/stage0/src/v1_tests_claim_checkpoint_identity_keying_witness_test.rs\nsrc/v1/stage0/tests/bounded_shell_stream_capture_replay.rs\nsrc/v1/stage0/tests/interpreter_dispatch_authority.rs\nsrc/v1/stage0/tests/interpreter_dispatch_bijection_compile_red.rs\nsrc/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs\nsrc/v1/stage0/tests/namespace_occurrence_serde.rs\nsrc/v1/stage0/tests/scoped_run_observation.rs\nsrc/v1/stage0/tests/tokenize_escape_receipt.rs\nsrc/v1/tests/claim/checkpoint_identity_keying_witness_test.dag\nsrc/v1/tests/src/class_b_trim_specimen_test.rs\nsrc/v1/tests/src/decl_facts_dimensionless_projection_test.rs\nsrc/v1/tests/src/field_of_fractions_construction_test.rs\nsrc/v1/tests/src/field_of_fractions_single_declaration_test.rs\nsrc/v1/tests/src/materialization_provider_resolved_graph_consumer_test.rs\nsrc/v1/tests/src/namespace_unique_on_chain_policy_test.rs\nsrc/v1/tests/src/none_undetermined_carrier_refuse_test.rs\nsrc/v1/trait_bound_witness.dag\nsrc/v1/trait_derive_emit.dag\nsrc/v2/compiler/inferred_tree.dag\nsrc/v2/compiler/native_selected_bundle_process.dag\nsrc/v2/compiler/parse_diagnostic.dag\nsrc/v2/compiler/self_host/direct_rust_door_fixture.dag\nsrc/v2/compiler/self_host/direct_rust_door_ingest_fixture.dag\nsrc/v2/compiler/self_host/direct_rust_door_observation.dag\nsrc/v2/compiler/self_host/emit_coverage_frontier.dag\nsrc/v2/compiler/self_host/emitter_producer_provenance.dag\nsrc/v2/compiler/self_host/fixture_synthetic_emission.dag\nsrc/v2/compiler/self_host/frontier_probe_assemble_detail.dag\nsrc/v2/compiler/self_host/frontier_probe_semantic_family_receipt.dag\nsrc/v2/compiler/self_host/generation.dag\nsrc/v2/compiler/self_host/native_agreement_support.dag\nsrc/v2/compiler/self_host/native_routing_frontier.dag\nsrc/v2/compiler/self_host/parity_receipts_local.dag\nsrc/v2/compiler/self_host/parity_window.dag\nsrc/v2/compiler/self_host/promotion_admission.dag\nsrc/v2/compiler/self_host/seed_emitter_behavioral_wet_known_red_entries.dag\nsrc/v2/compiler/self_host/seed_emitter_behavioral_wet_module_bindings.dag\nsrc/v2/compiler/self_host/stage0_crate_layout.dag\nsrc/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag\nsrc/v2/compiler/self_host/witness_bulk_routing.dag\nsrc/v2/compiler/self_host/witness_entry_eligibility_census.dag\nsrc/v2/compiler/trait_derive_completeness.dag\nsrc/v2/extdeps/formats/icestorm_pcf.dag\nsrc/v2/extdeps/language_model/python_l1_static_test.dag\nsrc/v2/extdeps/language_model/python_r1_test.dag\nsrc/v2/extdeps/language_model/rust_r1_test.dag\nsrc/v2/extdeps/language_model/rust_r3_internal_test.dag\nsrc/v2/extdeps/languages/bash_proc_self_cgroup.dag\nsrc/v2/extdeps/languages/c_bool_literal_emit.dag\nsrc/v2/extdeps/languages/rust_test_fixtures.dag\nsrc/v2/lens/application/application_subterm_at_empty_path_test.dag\nsrc/v2/lens/application/apply_lens_enforce_uses_projection_test.dag\nsrc/v2/lens/application/apply_lens_introspect_rejection_is_advisory_test.dag\nsrc/v2/lens/application/empty_required_lenses_skip_gate_test.dag\nsrc/v2/lens/application/enforce_rejecting_gate_fires_test.dag\nsrc/v2/lens/application/introspect_clean_tree_passes_test.dag\nsrc/v2/lens/application/rejecting_lens_blocks_before_compile_test.dag\nsrc/v2/lens/application/substitute_at_ambiguous_duplicate_name_test.dag\nsrc/v2/lens/application/substitute_at_depth_three_test.dag\nsrc/v2/lens/application/substitute_at_depth_two_test.dag\nsrc/v2/lens/application/subterm_at_ambiguous_duplicate_name_test.dag\nsrc/v2/lens/cost/bounded_summation_test.dag\nsrc/v2/lens/cost/disj_max_test.dag\nsrc/v2/lens/cost/expr.dag\nsrc/v2/lens/cost/expr_refusal_test.dag\nsrc/v2/lens/cost/loop_illegal_named_test.dag\nsrc/v2/lens/cost/loop_linear_test.dag\nsrc/v2/lens/cost/loop_unknown_test.dag\nsrc/v2/lens/cost/map_linear_test.dag\nsrc/v2/lens/cost/nested_product_test.dag\nsrc/v2/lens/cost/p9_llvm_instruction_cost_registry_owner_test.dag\nsrc/v2/lens/cost/summary.dag\nsrc/v2/lens/cost/summary_span_test.dag\nsrc/v2/lens/cost/valuation.dag\nsrc/v2/lens/cost/valuation_test.dag\nsrc/v2/lens/coverage/discriminant_predicate_defect_key_test.dag\nsrc/v2/lens/coverage/near_miss_vacuous_not_parallel_test.dag\nsrc/v2/lens/coverage/parallel_authority_defect_key_test.dag\nsrc/v2/lens/coverage/sibling_degenerate_not_hollow_test.dag\nsrc/v2/lens/emitted_binary_effect_confinement.dag\nsrc/v2/lens/enforcement/complexity_contract_subject.dag\nsrc/v2/lens/enforcement/inventory.dag\nsrc/v2/lens/fact_density/computation_not_type_carrier_test.dag\nsrc/v2/lens/fact_density/conj_positional_only_no_fact_test.dag\nsrc/v2/lens/fact_density/fact_bundle_compile_lens_passes_test.dag\nsrc/v2/lens/fact_density/fact_bundle_named_test.dag\nsrc/v2/lens/fact_density/hollow_alias_blocked_in_run_gates_test.dag\nsrc/v2/lens/fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag\nsrc/v2/lens/fact_density/hollow_alias_compile_lens_rejects_test.dag\nsrc/v2/lens/fact_density/hollow_alias_nested_rejected_test.dag\nsrc/v2/lens/fact_density/hollow_alias_no_fact_test.dag\nsrc/v2/lens/fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag\nsrc/v2/lens/fact_density/kernel_ambient_bool_test.dag\nsrc/v2/lens/fallback_arm_census.dag\nsrc/v2/lens/idempotency/write_effect_test.dag\nsrc/v2/lens/lifecycle_carrier.dag\nsrc/v2/lens/lifecycle_carrier/raw_prose_field_flagged_test.dag\nsrc/v2/lens/module_impact_query.dag\nsrc/v2/lens/parallelism/data_dependency_test.dag\nsrc/v2/lens/production_qualification_origin_probe.dag\nsrc/v2/lens/roster_registry.dag\nsrc/v2/lens/synthesis/constant_not_dominated_by_linear_test.dag\nsrc/v2/lens/synthesis/exponential_dominates_polynomial_test.dag\nsrc/v2/lens/synthesis/factorial_dominates_exponential_test.dag\nsrc/v2/lens/synthesis/linear_not_dominated_by_polynomial_test.dag\nsrc/v2/lens/synthesis/synthesis_gap_information_theoretic_test.dag\nsrc/v2/lens/synthesis/synthesis_gap_polynomial_test.dag\nsrc/v2/lens/synthesis/synthesis_no_technique_diagnostic_test.dag\nsrc/v2/lens/vacuity_self_application_fixture.dag\nsrc/v2/std/algebra_laws/field_patch_monoid_test.dag\nsrc/v2/std/compilers/cli_surface.dag\nsrc/v2/std/compilers/coproduct_variant_shape.dag\nsrc/v2/std/data_initializer_identity.dag\nsrc/v2/std/decl_facts_skeleton.dag\nsrc/v2/std/decl_ref_resolution.dag\nsrc/v2/std/grammar_choice_ambiguity.dag\nsrc/v2/std/native_agreement.dag\nsrc/v2/std/operation_argv.dag\nsrc/v2/std/optional.dag\nsrc/v2/std/witness_evaluation.dag\nsrc/v2/std/witness_execution_routing.dag\nsrc/v2/test/claim/bash_program_fold_support.dag\nsrc/v2/test/claim/body_lowering/arrow_body_form_semantic_helpers.dag\nsrc/v2/test/claim/body_lowering/arrow_body_form_witness_test.dag\nsrc/v2/test/claim/body_lowering/atom_body_discriminator_helpers.dag\nsrc/v2/test/claim/body_lowering/frontier_three_state_test.dag\nsrc/v2/test/claim/body_lowering/infer_transform_binary_infix_witness_helpers.dag\nsrc/v2/test/claim/body_lowering/infer_transform_binary_infix_witness_test.dag\nsrc/v2/test/claim/body_lowering/long/atom_body_discriminator_witness_test.dag\nsrc/v2/test/claim/ci_placement_witness_test.dag\nsrc/v2/test/claim/claim_pipeline/infer_test.dag\nsrc/v2/test/claim/claim_pipeline/normalize_test.dag\nsrc/v2/test/claim/claim_pipeline/resolve_test.dag\nsrc/v2/test/claim/claim_pipeline/translate_test.dag\nsrc/v2/test/claim/complexity_contract_subject_partition_witness_test.dag\nsrc/v2/test/claim/computation_identity_test.dag\nsrc/v2/test/claim/concept_index_enumeration/concept_index_enumeration_test.dag\nsrc/v2/test/claim/discrimination_gate/discrimination_roster_test.dag\nsrc/v2/test/claim/effect_plan_bash_materialize_test.dag\nsrc/v2/test/claim/emit/bool_literal_projection_emit_test.dag\nsrc/v2/test/claim/emit/conditional_delimiting_test.dag\nsrc/v2/test/claim/emit/produced_decl_support_preserved_test.dag\nsrc/v2/test/claim/emit/produced_decl_two_target_test.dag\nsrc/v2/test/claim/emit/rust_production_closure_let_emit_test.dag\nsrc/v2/test/claim/emit/trait_derive_seed_emit_binding_test.dag\nsrc/v2/test/claim/emit/trait_derive_supplemental_generic_bound_contract_test.dag\nsrc/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag\nsrc/v2/test/claim/enforcement_inventory_witness_test.dag\nsrc/v2/test/claim/execution/emit_host_filesystem_read_equals_eval_test.dag\nsrc/v2/test/claim/execution/emit_host_shell_exec_run_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/bind_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/emit_host_classical_not_ingested_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/emit_host_native_only_verdict_test.dag\nsrc/v2/test/claim/execution/long/emit_host_produced_module_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/loop_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/pick_ingested_probe_test.dag\nsrc/v2/test/claim/execution/long/pick_ingested_structural_lowering_test.dag\nsrc/v2/test/claim/execution/native_selected_witness_bundle_production.dag\nsrc/v2/test/claim/execution/native_selected_witness_bundle_test.dag\nsrc/v2/test/claim/extdeps/spice_element_letter_test.dag\nsrc/v2/test/claim/fallback_arm_census_planted_test.dag\nsrc/v2/test/claim/generated/language_behavior_equivalence_test.dag\nsrc/v2/test/claim/generated/testgen_category_wishlist_test.dag\nsrc/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag\nsrc/v2/test/claim/identity_captured_navigation/long/roster_gate_test.dag\nsrc/v2/test/claim/infer_self_grounding_wall_test.dag\nsrc/v2/test/claim/layer_transition_test.dag\nsrc/v2/test/claim/lean_bit_width_admissibility_witness_test.dag\nsrc/v2/test/claim/lean_overflow_semantics_witness_test.dag\nsrc/v2/test/claim/long/a4_opacity_test.dag\nsrc/v2/test/claim/long/bash_program_real_probes_witness_test.dag\nsrc/v2/test/claim/long/direct_rust_door_production_group_test.dag\nsrc/v2/test/claim/long/effect_reach_test.dag\nsrc/v2/test/claim/long/fallback_arm_census_witness_test.dag\nsrc/v2/test/claim/long/frontier_probe_closure_matrix_integration_test.dag\nsrc/v2/test/claim/long/gauntlet_lane_enrollment_witness_test.dag\nsrc/v2/test/claim/long/infer_transform_binary_infix_witness_test.dag\nsrc/v2/test/claim/long/inhabitant_neutralization_e2e_witness_test.dag\nsrc/v2/test/claim/long/live_read_classification_test.dag\nsrc/v2/test/claim/long/native_routing_membership_receipt_test.dag\nsrc/v2/test/claim/long/production_qualification_origin_probe_witness_test.dag\nsrc/v2/test/claim/long/realization_sweep_probe_entry.dag\nsrc/v2/test/claim/long/typescript_descriptor_node_run_witness_test.dag\nsrc/v2/test/claim/long/vacuity_consumer_witness_long_test.dag\nsrc/v2/test/claim/manual/add_body_producer_claim_test.dag\nsrc/v2/test/claim/manual/body_lowering_infix_test.dag\nsrc/v2/test/claim/manual/body_lowering_match_test.dag\nsrc/v2/test/claim/manual/body_lowering_normalize_add_test.dag\nsrc/v2/test/claim/manual/body_lowering_projection_call_test.dag\nsrc/v2/test/claim/manual/body_lowering_variants_test.dag\nsrc/v2/test/claim/manual/bootstrap_footprint_anchor_test.dag\nsrc/v2/test/claim/manual/call_carrier_node_query_test.dag\nsrc/v2/test/claim/manual/content_hash_loop_bound_edge_order_test.dag\nsrc/v2/test/claim/manual/content_hash_named_edge_order_test.dag\nsrc/v2/test/claim/manual/e0599_phase_a_body_evidence_probe.dag\nsrc/v2/test/claim/manual/fold_source_test.dag\nsrc/v2/test/claim/manual/go_grammar_claim_test.dag\nsrc/v2/test/claim/manual/infer_bounded_lattice_completeness_anchor_test.dag\nsrc/v2/test/claim/manual/kotlin_grammar_claim_test.dag\nsrc/v2/test/claim/manual/llvm_ir_b2_omni_in_b_probe_test.dag\nsrc/v2/test/claim/manual/model_core_anchor_test.dag\nsrc/v2/test/claim/manual/nominal_distinctness_cross_call_test.dag\nsrc/v2/test/claim/manual/posix_output_capture_test.dag\nsrc/v2/test/claim/manual/process_numeric_refinements_test.dag\nsrc/v2/test/claim/manual/python_grammar_claim_test.dag\nsrc/v2/test/claim/manual/qualified_pattern_reconcile_test.dag\nsrc/v2/test/claim/manual/refinement_authoritative_constants_test.dag\nsrc/v2/test/claim/manual/refinement_ordered_iteration_test.dag\nsrc/v2/test/claim/manual/resolve_compile_anchor_test.dag\nsrc/v2/test/claim/manual/sg1b_signature_realization_failclosed_test.dag\nsrc/v2/test/claim/manual/sg2_mode2_non_grammar_emit_test.dag\nsrc/v2/test/claim/manual/sg2_type_expression_projection_test.dag\nsrc/v2/test/claim/manual/sg2_typescript_type_expression_projection_test.dag\nsrc/v2/test/claim/manual/sg5_set_non_ordable_falsification_test.dag\nsrc/v2/test/claim/manual/sg_collection_projection_test.dag\nsrc/v2/test/claim/manual/structured_body_dispatch_test.dag\nsrc/v2/test/claim/manual/structured_body_subsumption_set_test.dag\nsrc/v2/test/claim/manual/target_model_atom_lookup_dissolution_test.dag\nsrc/v2/test/claim/manual/target_model_operator_lookup_dissolution_test.dag\nsrc/v2/test/claim/manual/test_claim_cache_digest_sensitivity_test.dag\nsrc/v2/test/claim/manual/typescript_derive_grammar_relation_row_round_trip_test.dag\nsrc/v2/test/claim/manual/typescript_descriptor_node_run.dag\nsrc/v2/test/claim/manual/typescript_grammar_claim_test.dag\nsrc/v2/test/claim/manual/value_null_split_witness_test.dag\nsrc/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag\nsrc/v2/test/claim/name_resolve/admission_fail_closed_test.dag\nsrc/v2/test/claim/name_resolve/malformed_imported_root_test.dag\nsrc/v2/test/claim/namespace_graft/collapsed_reader_test.dag\nsrc/v2/test/claim/native_cache_fusion_test.dag\nsrc/v2/test/claim/normalized_tree_admission_test.dag\nsrc/v2/test/claim/parse/parse_binding_fidelity_support.dag\nsrc/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag\nsrc/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag\nsrc/v2/test/claim/realize_advisory_soundness_test.dag\nsrc/v2/test/claim/roster_registry_test.dag\nsrc/v2/test/claim/self_host/compiler_closure_ingest_boundary_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_emission_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_fixture_containment_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_group_algebra_test.dag\nsrc/v2/test/claim/self_host/emit_coverage_frontier_test.dag\nsrc/v2/test/claim/self_host/emitter_producer_provenance_witness_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_cause_location_roundtrip_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_cause_location_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_empty_ingest_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_overlap_detail_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_semantic_family_receipt_test.dag\nsrc/v2/test/claim/self_host/native_agreement_test.dag\nsrc/v2/test/claim/self_host/native_routing_frontier_test.dag\nsrc/v2/test/claim/self_host/parity_window_test.dag\nsrc/v2/test/claim/self_host/production_qualification_origin_probe_structural_fixture.dag\nsrc/v2/test/claim/self_host/production_qualification_origin_probe_witness_test.dag\nsrc/v2/test/claim/self_host/v2_emitter_direct_rust_door_contract_test.dag\nsrc/v2/test/claim/self_host/witness_bulk_routing_test.dag\nsrc/v2/test/claim/self_host/witness_entry_eligibility_census_classification_test.dag\nsrc/v2/test/claim/tokenize/annotation_channel_test.dag\nsrc/v2/test/claim/trait_derive_completeness_predicate_test.dag\nsrc/v2/test/claim/translate_underived_refusal_test.dag\nsrc/v2/test/claim/vacuity_consumer_witness_test.dag\nsrc/v2/test/claim/verilog_interlock_emission_test.dag\nsrc/v2/test/claim/workflow/frontier_probe_closure_matrix_test.dag\nsrc/v2/test/claim/workflow/frontier_probe_closure_readthrough_test.dag\nsrc/v2/test/claim/workflow/source_root_overflow_never_empty_witness_test.dag\nsrc/v2/test/fixture/coproduct_reflection_generic_wrapper.dag\nsrc/v2/test/fixture/frontier_probe_cause_location_manifest_fixture.dag\nsrc/v2/test/fixture/frontier_probe_elision_boundary_overlay.dag\nsrc/v2/test/manual/long/grounding_lens_whole_tree_test.dag\nsrc/v2/workflow/ci_heal_revalidation_preflight_emit.dag\nsrc/v2/workflow/ci_heal_revalidation_preflight_emit_test.dag\nsrc/v2/workflow/ci_materialization_emit.dag\nsrc/v2/workflow/ci_materialization_emit_test.dag\nsrc/v2/workflow/ci_placement.dag\nsrc/v2/workflow/ci_v1_compiler_tests_compile_gate_emit.dag\nsrc/v2/workflow/ci_v1_compiler_tests_compile_gate_emit_test.dag\nsrc/v2/workflow/class_b_import_closure_probe.dag\nsrc/v2/workflow/class_b_import_closure_transport.dag\nsrc/v2/workflow/commit_witness_claim_roster.dag\nsrc/v2/workflow/effect_plan_bash_materialize.dag\nsrc/v2/workflow/floor2_prepared_subject.dag\nsrc/v2/workflow/floor_compile_clean_predicates.dag\nsrc/v2/workflow/floor_discovery.dag\nsrc/v2/workflow/floor_discovery_producer.dag\nsrc/v2/workflow/floor_discovery_transport.dag\nsrc/v2/workflow/floor_expected_red.dag\nsrc/v2/workflow/floor_expected_red_coherence.dag\nsrc/v2/workflow/floor_naming_hygiene.dag\nsrc/v2/workflow/floor_preparation.dag\nsrc/v2/workflow/legacy_test_inflow_audit.dag\nsrc/v2/workflow/native_cache_fusion.dag\nsrc/v2/workflow/orchestration_bash_emit_support.dag\nsrc/v2/workflow/realization_attempt.dag\nsrc/v2/workflow/realization_sweep.dag\nsrc/v2/workflow/realize_advisory_soundness.dag\nsrc/v2/workflow/required_floor.dag\nsrc/v2/workflow/required_regen.dag\ntest/fixture_roots/decl_facts_reflection_duplicate_qn/shadow/shadow_module.dag\ntools/extdeps_scope_exact_census_receipt.txt\ntools/m1c1_subject_map_receipt.txt\ntools/m1c_bulk0_manifest.tsv\ntools/m1c_bulk0_residual.tsv\ntools/m1c_bulk0_subject_map_receipt.txt\n" +data srv1_paths_becoming_tracked_wire: String = ".githooks/generated-artifact-merge\n.github/workflows/fleet-converge.yml\n.github/workflows/witnesses.yml\nLICENSES/MIT.txt\nLICENSING.md\ndag/examples/interp_test/interp_example.dag\ndag/extdeps/accounting/encumbrance.dag\ndag/extdeps/advertising/google_ads.dag\ndag/extdeps/advertising/meta_ads.dag\ndag/extdeps/advertising/types.dag\ndag/extdeps/ampere/mt_collins_product_brief/platform.dag\ndag/extdeps/ampere/mt_collins_product_brief/subject.dag\ndag/extdeps/ampere/scp_diagnostic.dag\ndag/extdeps/archive/format.dag\ndag/extdeps/assurance/claim_evidence.dag\ndag/extdeps/auth/jwt.dag\ndag/extdeps/auth/oidc.dag\ndag/extdeps/automation/playwright.dag\ndag/extdeps/bmc/aspeed_ast2500.dag\ndag/extdeps/bmc/ipmi.dag\ndag/extdeps/bmc/mock_corpus.dag\ndag/extdeps/bmc/openbmc_fan_control.dag\ndag/extdeps/bmc/openbmc_operation.dag\ndag/extdeps/bmc/openbmc_password_ssh_transport.dag\ndag/extdeps/bmc/virtual_media.dag\ndag/extdeps/boards/supermicro.dag\ndag/extdeps/boards/types.dag\ndag/extdeps/bootloader/grub.dag\ndag/extdeps/browser/chromium.dag\ndag/extdeps/browser/google_chrome.dag\ndag/extdeps/cache.dag\ndag/extdeps/cache/pin.dag\ndag/extdeps/chassis/rosewill.dag\ndag/extdeps/chassis/types.dag\ndag/extdeps/ci_runner/blacksmith.dag\ndag/extdeps/ci_runner/circleci.dag\ndag/extdeps/ci_runner/depot.dag\ndag/extdeps/ci_runner/github_actions.dag\ndag/extdeps/ci_runner/types.dag\ndag/extdeps/ci_runner/warpbuild.dag\ndag/extdeps/clock/ti_cdce913.dag\ndag/extdeps/cloud/gcp/auth_print_access_token.dag\ndag/extdeps/cloud_init/cloud_init.dag\ndag/extdeps/colo/centersquare.dag\ndag/extdeps/colo/colocation_america.dag\ndag/extdeps/colo/coresite.dag\ndag/extdeps/colo/dataverge.dag\ndag/extdeps/colo/digital_realty.dag\ndag/extdeps/colo/equinix.dag\ndag/extdeps/colo/evocative.dag\ndag/extdeps/colo/h5.dag\ndag/extdeps/colo/halsey_165.dag\ndag/extdeps/colo/hivelocity.dag\ndag/extdeps/colo/interserver.dag\ndag/extdeps/colo/iron_mountain.dag\ndag/extdeps/colo/natcoweb.dag\ndag/extdeps/colo/netrality.dag\ndag/extdeps/colo/qts.dag\ndag/extdeps/colo/summit.dag\ndag/extdeps/colo/three_sixty_five.dag\ndag/extdeps/colo/tierpoint.dag\ndag/extdeps/colo/types.dag\ndag/extdeps/connector/samtec_ftsh_105_01_l_dv.dag\ndag/extdeps/container/docker_ce.dag\ndag/extdeps/container/oci/digest.dag\ndag/extdeps/cooling/dynatron.dag\ndag/extdeps/cooling/types.dag\ndag/extdeps/cpu/ampere_altra_memory_controller.dag\ndag/extdeps/cpu/ampere_altra_package.dag\ndag/extdeps/cpu/ampere_altra_package_contact_map.dag\ndag/extdeps/cpu/ampere_altra_package_contacts.dag\ndag/extdeps/cpu/ampere_altra_package_table4_raw.dag\ndag/extdeps/cpu/ampere_altra_platform_hw_design/platform.dag\ndag/extdeps/cpu/ampere_altra_platform_hw_design/subject.dag\ndag/extdeps/cpu_attachment/ilm4926.dag\ndag/extdeps/crm/hubspot_lifecycle.dag\ndag/extdeps/crm/salesforce_opportunity.dag\ndag/extdeps/crypto/hash.dag\ndag/extdeps/currency/currency.dag\ndag/extdeps/darwin/rusage.dag\ndag/extdeps/darwin/sysctl.dag\ndag/extdeps/diagnostic_mock_corpus.dag\ndag/extdeps/energy/nj_electricity.dag\ndag/extdeps/exec/command.dag\ndag/extdeps/exec/exec_arg_limit.dag\ndag/extdeps/exec/xargs.dag\ndag/extdeps/filesystem/linux.dag\ndag/extdeps/firmware/kernel_cmdline.dag\ndag/extdeps/firmware/openbmc/subject.dag\ndag/extdeps/firmware/tianocore_edk2/subject.dag\ndag/extdeps/firmware/trusted_firmware_a/subject.dag\ndag/extdeps/firmware/types.dag\ndag/extdeps/firmware/uefi_http_boot.dag\ndag/extdeps/firmware/uefi_shell.dag\ndag/extdeps/git/inspect.dag\ndag/extdeps/git/publication_transport.dag\ndag/extdeps/github/actions_environment.dag\ndag/extdeps/github/actions_runner.dag\ndag/extdeps/github/actions_token.dag\ndag/extdeps/github/app.dag\ndag/extdeps/github/effect.dag\ndag/extdeps/github/issues.dag\ndag/extdeps/github/push_event.dag\ndag/extdeps/github/workflow_run_event.dag\ndag/extdeps/github/workflows.dag\ndag/extdeps/gnu/libc.dag\ndag/extdeps/instrument/pip_boy_3000.dag\ndag/extdeps/instrument/pip_boy_3000_mk_v.dag\ndag/extdeps/ipc/dpmx.dag\ndag/extdeps/land_pattern/types.dag\ndag/extdeps/languages/bash/subject.dag\ndag/extdeps/languages/c/subject.dag\ndag/extdeps/languages/cpp/subject.dag\ndag/extdeps/languages/css/properties.dag\ndag/extdeps/languages/css/selectors.dag\ndag/extdeps/languages/css/subject.dag\ndag/extdeps/languages/css/values.dag\ndag/extdeps/languages/ecmascript/subject.dag\ndag/extdeps/languages/go/subject.dag\ndag/extdeps/languages/html/subject.dag\ndag/extdeps/languages/java/subject.dag\ndag/extdeps/languages/json/parse.dag\ndag/extdeps/languages/json/subject.dag\ndag/extdeps/languages/jsx/subject.dag\ndag/extdeps/languages/kotlin/subject.dag\ndag/extdeps/languages/lean/overflow.dag\ndag/extdeps/languages/lean/subject.dag\ndag/extdeps/languages/llvm_ir/subject.dag\ndag/extdeps/languages/markdown/subject.dag\ndag/extdeps/languages/ptx/subject.dag\ndag/extdeps/languages/python/subject.dag\ndag/extdeps/languages/riscv/subject.dag\ndag/extdeps/languages/rust/derive_contracts.dag\ndag/extdeps/languages/rust/subject.dag\ndag/extdeps/languages/spice/subject.dag\ndag/extdeps/languages/swift/subject.dag\ndag/extdeps/languages/typescript/subject.dag\ndag/extdeps/languages/verilog/subject.dag\ndag/extdeps/languages/wasm/subject.dag\ndag/extdeps/languages/yaml/subject.dag\ndag/extdeps/linux/edac.dag\ndag/extdeps/linux/mock_corpus.dag\ndag/extdeps/linux/proc_meminfo.dag\ndag/extdeps/linux/proc_self_cgroup.dag\ndag/extdeps/linux/procfs.dag\ndag/extdeps/linux/rusage.dag\ndag/extdeps/linux/usb_gadget.dag\ndag/extdeps/llm/claude_agent_sdk_stream.dag\ndag/extdeps/llm/claude_sdk.dag\ndag/extdeps/llm/claude_setup_token_cli.dag\ndag/extdeps/llm/cli_lifecycle.dag\ndag/extdeps/llm/codex_app_server.dag\ndag/extdeps/llm/codex_app_server_stdio_session.dag\ndag/extdeps/llm/codex_auth.dag\ndag/extdeps/llm/cursor_cli.dag\ndag/extdeps/llm/cursor_sdk.dag\ndag/extdeps/llm/cursor_sdk_errors.dag\ndag/extdeps/llm/cursor_sdk_facts.dag\ndag/extdeps/llm/cursor_stream.dag\ndag/extdeps/memory/macronix_mx25l25673g.dag\ndag/extdeps/memory/microchip_at24cm02.dag\ndag/extdeps/memory/samsung.dag\ndag/extdeps/memory/te_ddr4_dimm_socket.dag\ndag/extdeps/memory/training.dag\ndag/extdeps/mercurial.dag\ndag/extdeps/netplan/netplan.dag\ndag/extdeps/network/address.dag\ndag/extdeps/network/endpoint.dag\ndag/extdeps/network/ipv4.dag\ndag/extdeps/network/ipv6.dag\ndag/extdeps/network/reach.dag\ndag/extdeps/network/switch_types.dag\ndag/extdeps/network/ti_dp83867.dag\ndag/extdeps/network/tp_link.dag\ndag/extdeps/npm.dag\ndag/extdeps/ocp/mt_jade/platform.dag\ndag/extdeps/ocp/mt_jade/subject.dag\ndag/extdeps/ocp/mt_mitchell/platform.dag\ndag/extdeps/ocp/mt_mitchell/subject.dag\ndag/extdeps/ocp/publication.dag\ndag/extdeps/ollama/api.dag\ndag/extdeps/ollama/binary_release.dag\ndag/extdeps/ollama/capability.dag\ndag/extdeps/ollama/gpu_support.dag\ndag/extdeps/ollama/server_env.dag\ndag/extdeps/os.dag\ndag/extdeps/os/debian.dag\ndag/extdeps/package.dag\ndag/extdeps/physics/bach_et_al_2013_double_slit.dag\ndag/extdeps/physics/chapman_et_al_1995_atom_interferometer_which_path.dag\ndag/extdeps/pijul.dag\ndag/extdeps/pin.dag\ndag/extdeps/posix/rusage.dag\ndag/extdeps/posix/shell_command_language.dag\ndag/extdeps/posix/signal.dag\ndag/extdeps/power/eaton_tripp_lite.dag\ndag/extdeps/power/ti_tps3808.dag\ndag/extdeps/power/ti_tps53688.dag\ndag/extdeps/power/types.dag\ndag/extdeps/pricing/billing_units.dag\ndag/extdeps/pricing/gitlab_subscription.dag\ndag/extdeps/pricing/object_storage.dag\ndag/extdeps/pricing/regional_compute.dag\ndag/extdeps/probes/provider_interface_acquisition.dag\ndag/extdeps/process/gnu_bash_exit.dag\ndag/extdeps/process/posix_exit.dag\ndag/extdeps/programmable_logic/ice40/configuration.dag\ndag/extdeps/programmable_logic/ice40/subject.dag\ndag/extdeps/programmable_logic/ice40/supply.dag\ndag/extdeps/project_schedule/cpm_pert.dag\ndag/extdeps/provisioning/ubuntu_install_media.dag\ndag/extdeps/provisioning/ubuntu_install_media_fetch.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media_remaster.dag\ndag/extdeps/provisioning/ubuntu_seeded_install_media_toolchain.dag\ndag/extdeps/publication.dag\ndag/extdeps/rack/navepoint.dag\ndag/extdeps/rack/types.dag\ndag/extdeps/realestate/nj_industrial.dag\ndag/extdeps/rust/cargo_message.dag\ndag/extdeps/rust/target_triple.dag\ndag/extdeps/sec/issuer/atlassian.dag\ndag/extdeps/sec/issuer/atlassian_facts.dag\ndag/extdeps/sec/issuer/microsoft.dag\ndag/extdeps/sec/issuer/microsoft_facts.dag\ndag/extdeps/sec/operating_metrics.dag\ndag/extdeps/shell.dag\ndag/extdeps/shell_mock_corpus.dag\ndag/extdeps/simulators/icarus_verilog/subject.dag\ndag/extdeps/simulators/ngspice/subject.dag\ndag/extdeps/ssh/client_options.dag\ndag/extdeps/ssh/keys.dag\ndag/extdeps/ssh/mock_corpus.dag\ndag/extdeps/ssh/password_session.dag\ndag/extdeps/ssh/session.dag\ndag/extdeps/standards/ieee_754_2019.dag\ndag/extdeps/standards/rfc_8118.dag\ndag/extdeps/standards/web_annotation.dag\ndag/extdeps/storage/amphenol_mdt420m01001.dag\ndag/extdeps/storage/nbd.dag\ndag/extdeps/storage/te_m2_ngff_connector.dag\ndag/extdeps/systemd/journalctl.dag\ndag/extdeps/systemd/oomd.dag\ndag/extdeps/systemd/systemctl.dag\ndag/extdeps/systemd/systemd.dag\ndag/extdeps/systemd/systemd_contracts.dag\ndag/extdeps/systemd/systemd_run.dag\ndag/extdeps/systemd/unit_file.dag\ndag/extdeps/systems/nvidia.dag\ndag/extdeps/systems/nvidia_dgx_spark_pxe.dag\ndag/extdeps/systems/nvidia_dgx_spark_setup.dag\ndag/extdeps/systems/nvidia_fleet_lifecycle.dag\ndag/extdeps/systems/types.dag\ndag/extdeps/time/rfc3339.dag\ndag/extdeps/toolchain/icestorm/subject.dag\ndag/extdeps/tools.dag\ndag/extdeps/tools/busybox.dag\ndag/extdeps/tools/diffutils.dag\ndag/extdeps/tools/free.dag\ndag/extdeps/tools/gcloud.dag\ndag/extdeps/tools/gnu_coreutils.dag\ndag/extdeps/tools/hostname.dag\ndag/extdeps/tools/id.dag\ndag/extdeps/tools/node.dag\ndag/extdeps/tools/npm.dag\ndag/extdeps/tools/pin.dag\ndag/extdeps/tools/rustfmt.dag\ndag/extdeps/tools/sha512sum.dag\ndag/extdeps/tools/wc.dag\ndag/extdeps/ucamco/gerber.dag\ndag/extdeps/unicode/blocks.dag\ndag/extdeps/unicode/display.dag\ndag/extdeps/units/dimensionless.dag\ndag/extdeps/units/iec_80000_13.dag\ndag/extdeps/units/iso8601.dag\ndag/extdeps/units/iso_80000_3.dag\ndag/extdeps/uuid/uuid.dag\ndag/extdeps/vendor/alphabet.dag\ndag/extdeps/vendor/amphenol.dag\ndag/extdeps/vendor/aspeed.dag\ndag/extdeps/vendor/asrock_rack.dag\ndag/extdeps/vendor/atlassian.dag\ndag/extdeps/vendor/dynatron.dag\ndag/extdeps/vendor/eaton.dag\ndag/extdeps/vendor/hubspot.dag\ndag/extdeps/vendor/lattice_semiconductor.dag\ndag/extdeps/vendor/lotes.dag\ndag/extdeps/vendor/macronix.dag\ndag/extdeps/vendor/meta_platforms.dag\ndag/extdeps/vendor/microchip_technology.dag\ndag/extdeps/vendor/microsoft.dag\ndag/extdeps/vendor/navepoint.dag\ndag/extdeps/vendor/rosewill.dag\ndag/extdeps/vendor/salesforce.dag\ndag/extdeps/vendor/samtec.dag\ndag/extdeps/vendor/texas_instruments.dag\ndag/extdeps/vendor/the_wand_company.dag\ndag/extdeps/vendor/tp_link.dag\ndag/extdeps/vendor/tyco_electronics.dag\ndag/extdeps/vendor/tyco_electronics_amp_kk.dag\ndag/extdeps/w3c/accelerometer.dag\ndag/extdeps/w3c/device_orientation_and_motion.dag\ndag/extdeps/w3c/generic_sensor.dag\ndag/extdeps/w3c/svg.dag\ndag/extdeps/web_audio/web_audio.dag\ndag/gunbc/apply.dag\ndag/gunbc/auth/access_token_source.dag\ndag/gunbc/auth/github_apps.dag\ndag/gunbc/auth/github_credential.dag\ndag/gunbc/auth/github_gcp_federation.dag\ndag/gunbc/auth/materialized_secret.dag\ndag/gunbc/auth/secret_rotation.dag\ndag/gunbc/bach_double_slit_observation.dag\ndag/gunbc/bach_double_slit_path_additivity_synthetic_fixture.dag\ndag/gunbc/bash_materialized_transport.dag\ndag/gunbc/bmc/bmc_converge.dag\ndag/gunbc/bmc/bmc_fan_converge.dag\ndag/gunbc/bmc/bmc_fan_monitor.dag\ndag/gunbc/bmc/bmc_fan_projection.dag\ndag/gunbc/bmc/bmc_intent.dag\ndag/gunbc/bmc/bmc_netboot_serve.dag\ndag/gunbc/bmc/bmc_netboot_shell_boot.dag\ndag/gunbc/bmc/bmc_virtual_media.dag\ndag/gunbc/build_cache/build_cache_endpoint_observation.dag\ndag/gunbc/build_cache/build_cache_endpoint_path.dag\ndag/gunbc/build_cache/build_cache_ensure.dag\ndag/gunbc/build_cache/build_cache_instance.dag\ndag/gunbc/build_cache/build_cache_latency_probe.dag\ndag/gunbc/build_cache/build_cache_unit.dag\ndag/gunbc/busybox_bmc_build.dag\ndag/gunbc/capability_binding.dag\ndag/gunbc/cargo_execution_placement.dag\ndag/gunbc/census_closure_frontier.dag\ndag/gunbc/change_realization.dag\ndag/gunbc/chapman_which_path_observation.dag\ndag/gunbc/ci/ci_build_job_v1_compiler_unit_receipt.dag\ndag/gunbc/ci/ci_cost_arc_closeout_receipt.dag\ndag/gunbc/ci/ci_heal_credential.dag\ndag/gunbc/ci/ci_release_bins.dag\ndag/gunbc/citation/pdf_safe_profile.dag\ndag/gunbc/citation/x86_64_abi_pdf_consumer.dag\ndag/gunbc/claim_evidence_probe_rule.dag\ndag/gunbc/class_b_import_closure_overlay.dag\ndag/gunbc/claude_setup_token_enrollment.dag\ndag/gunbc/cli_run_floor_lens_oracle_scaffold.dag\ndag/gunbc/cli_run_hand_rust_area_ledger.dag\ndag/gunbc/cli_run_witness_admission_scaffold.dag\ndag/gunbc/cli_run_witness_deferral_freeze_scaffold.dag\ndag/gunbc/clock_read.dag\ndag/gunbc/codex_app_server_press.dag\ndag/gunbc/codex_provider_runtime_receipt.dag\ndag/gunbc/codex_runtime_bundle.dag\ndag/gunbc/codex_runtime_paths.dag\ndag/gunbc/codex_supervised_turn.dag\ndag/gunbc/codex_supervised_turn_run.dag\ndag/gunbc/command_runner.dag\ndag/gunbc/compile_clean_cost_basis.tsv\ndag/gunbc/compile_clean_diagnostic_policy.dag\ndag/gunbc/compile_diagnostic_census.dag\ndag/gunbc/compile_pool_ensure.dag\ndag/gunbc/cursor_sdk_auth_probe.dag\ndag/gunbc/cursor_sdk_local_binding.dag\ndag/gunbc/cursor_sdk_provider_standing.dag\ndag/gunbc/cursor_sdk_secret_admission.dag\ndag/gunbc/declared_import_closure_binding.dag\ndag/gunbc/deployed_tree_remote.dag\ndag/gunbc/design/component.dag\ndag/gunbc/design/instrument_audition.dag\ndag/gunbc/design/instrument_bob.dag\ndag/gunbc/design/instrument_camera.dag\ndag/gunbc/design/instrument_physical.dag\ndag/gunbc/design/instrument_projection.dag\ndag/gunbc/design/interaction_cause.dag\ndag/gunbc/design/reference_instrument.dag\ndag/gunbc/design/salience.dag\ndag/gunbc/design/scale.dag\ndag/gunbc/design/sound.dag\ndag/gunbc/design/state_response.dag\ndag/gunbc/devboot/build.dag\ndag/gunbc/devboot/lease.dag\ndag/gunbc/devboot/outcome.dag\ndag/gunbc/devboot/produce.dag\ndag/gunbc/devboot/program.dag\ndag/gunbc/devboot/subject.dag\ndag/gunbc/devboot/transport.dag\ndag/gunbc/diff_baseline.dag\ndag/gunbc/dispatch_pipe_pane_emit.dag\ndag/gunbc/dispatch_selection.dag\ndag/gunbc/dissolution_census.dag\ndag/gunbc/dissolution_migration_census.dag\ndag/gunbc/documentary_refs.dag\ndag/gunbc/econ/acquisition.dag\ndag/gunbc/econ/free_tier_serving.dag\ndag/gunbc/econ/llm_attempt_receipt.dag\ndag/gunbc/econ/regional_compute_premium.dag\ndag/gunbc/econ/scm_serving_model.dag\ndag/gunbc/ensure.dag\ndag/gunbc/executor_schedule_retention.dag\ndag/gunbc/explicit_witness_admission.dag\ndag/gunbc/extdeps_scope_frontier.dag\ndag/gunbc/fleet/fleet_bmc_firmware_evidence.dag\ndag/gunbc/fleet/fleet_bmc_observation.dag\ndag/gunbc/fleet/fleet_bmc_state.dag\ndag/gunbc/fleet/fleet_converge_plan.dag\ndag/gunbc/fleet/fleet_converge_plan_cli.dag\ndag/gunbc/fleet/fleet_converge_timer.dag\ndag/gunbc/fleet/fleet_converge_workflow.dag\ndag/gunbc/fleet/fleet_convergence_verdict.dag\ndag/gunbc/fleet/fleet_desired_observe.dag\ndag/gunbc/fleet/fleet_host_key_enrollment.dag\ndag/gunbc/fleet/fleet_install_transport_observations.dag\ndag/gunbc/fleet/fleet_known_hosts_anchor.dag\ndag/gunbc/fleet/fleet_lifecycle_observation.dag\ndag/gunbc/fleet/fleet_main_revision.dag\ndag/gunbc/fleet/fleet_multi_principal_probe.dag\ndag/gunbc/fleet/fleet_physical_inventory.dag\ndag/gunbc/fleet/fleet_probe_identity_observe.dag\ndag/gunbc/fleet/fleet_reach.dag\ndag/gunbc/fleet/fleet_reach_endpoint.dag\ndag/gunbc/fleet/fleet_receipt_collector.dag\ndag/gunbc/fleet/fleet_runner_connectivity.dag\ndag/gunbc/fleet/fleet_secrets_config.dag\ndag/gunbc/fleet/fleet_shell_transport_observation.dag\ndag/gunbc/fleet/fleet_ssh_access.dag\ndag/gunbc/fleet/fleet_ssh_credential_verify.dag\ndag/gunbc/fleet/fleet_workflow_steps.dag\ndag/gunbc/float_add_associativity_observation.dag\ndag/gunbc/floor/floor_component_receipt.dag\ndag/gunbc/floor/floor_component_receipt_document.dag\ndag/gunbc/floor/floor_discovery_scaffold.dag\ndag/gunbc/generated_artifact_assessment.dag\ndag/gunbc/generated_artifact_merge_driver.dag\ndag/gunbc/generated_artifact_observation.dag\ndag/gunbc/generated_projection_paths.dag\ndag/gunbc/git_diff_change_window.dag\ndag/gunbc/gitattributes_emit.dag\ndag/gunbc/githooks/githooks_pre_push_fmt_transport_scaffold.dag\ndag/gunbc/githooks/githooks_repo_local_git_config_emit.dag\ndag/gunbc/guarantee_measurement.dag\ndag/gunbc/guarantee_probe_corpus.dag\ndag/gunbc/heal_push_plan.dag\ndag/gunbc/heal_revalidation.dag\ndag/gunbc/host/host_assimilation_program.dag\ndag/gunbc/host/host_authorized_keys_reconcile.dag\ndag/gunbc/host/host_axis_caps.dag\ndag/gunbc/host/host_boot_supervision.dag\ndag/gunbc/host/host_budget_source.dag\ndag/gunbc/host/host_cli_dependency.dag\ndag/gunbc/host/host_codex_runtime_provision.dag\ndag/gunbc/host/host_codex_runtime_provision_verdict.dag\ndag/gunbc/host/host_compile_pool.dag\ndag/gunbc/host/host_diagnostic_channel.dag\ndag/gunbc/host/host_disk_observation.dag\ndag/gunbc/host/host_effect_codex_supervised_turn.dag\ndag/gunbc/host/host_hygiene_liveness_observe.dag\ndag/gunbc/host/host_hygiene_reaper_observe.dag\ndag/gunbc/host/host_hygiene_reaper_remediate.dag\ndag/gunbc/host/host_memory_qualification.dag\ndag/gunbc/host/host_network_diagnosis.dag\ndag/gunbc/host/host_phase_status.dag\ndag/gunbc/host/host_reach_identity_probe.dag\ndag/gunbc/host/host_realization.dag\ndag/gunbc/host/host_resource.dag\ndag/gunbc/host/host_swap_backing.dag\ndag/gunbc/host/host_toolchain_components.dag\ndag/gunbc/hostname_allocation.dag\ndag/gunbc/hostname_read.dag\ndag/gunbc/hostname_set.dag\ndag/gunbc/infer_occurrence_binding_scaffold.dag\ndag/gunbc/install_transport_qualification.dag\ndag/gunbc/interpreter_replacement_cut.dag\ndag/gunbc/language_module_home.dag\ndag/gunbc/language_source_scaffold_index.dag\ndag/gunbc/language_target_registry.dag\ndag/gunbc/legacy_extdeps_scope_frontier.tsv\ndag/gunbc/legacy_test_behavior_disposition.dag\ndag/gunbc/legacy_test_inflow.dag\ndag/gunbc/lifecycle_survivor_scan.dag\ndag/gunbc/live_deploy/candidate.dag\ndag/gunbc/live_deploy/deployed_tree_scope.dag\ndag/gunbc/live_deploy/revision.dag\ndag/gunbc/live_rust_observation.dag\ndag/gunbc/managed_directory.dag\ndag/gunbc/materialization_kernel_closing_frontier_audit.dag\ndag/gunbc/materialization_provider_consumer_scaffold.dag\ndag/gunbc/materialization_provider_targets.dag\ndag/gunbc/memory_provisioning.dag\ndag/gunbc/merge_admission_subject.dag\ndag/gunbc/model_artifact.dag\ndag/gunbc/namespace/namespace_census_receipt.dag\ndag/gunbc/namespace/namespace_clause_e_projection_law.dag\ndag/gunbc/namespace/namespace_pool_independence.dag\ndag/gunbc/namespace/namespace_reference_derived_closure_admission.dag\ndag/gunbc/namespace/namespace_reference_derived_closure_contract.dag\ndag/gunbc/native_scm_interaction_contract.dag\ndag/gunbc/native_witness_transition_receipt.dag\ndag/gunbc/non_fold_residue.dag\ndag/gunbc/observation_ci_render.dag\ndag/gunbc/observation_emit_census.dag\ndag/gunbc/observation_seed_render.dag\ndag/gunbc/observation_tty_render.dag\ndag/gunbc/occurrence_identity_acceptance_closure.dag\ndag/gunbc/ollama_runtime_bundle.dag\ndag/gunbc/os_install_claim_evidence.dag\ndag/gunbc/p1_retention_cohort_receipt.dag\ndag/gunbc/package_delivery.dag\ndag/gunbc/physics/bach_double_slit_path_additivity.dag\ndag/gunbc/physics/which_path_four_model_comparison.dag\ndag/gunbc/plans/affected_set_self_confirmation.dag\ndag/gunbc/plans/cli_run_hollowing_plan.dag\ndag/gunbc/plans/discrete_cost_derivation.dag\ndag/gunbc/plans/extdeps_modeling_preflight.dag\ndag/gunbc/plans/fleet_subsumption_manual_gaps.dag\ndag/gunbc/plans/host_convergence_circuit_residue.dag\ndag/gunbc/plans/transport_argv_anemia_dissolution.dag\ndag/gunbc/plans/v2_complexity_capability_parity.dag\ndag/gunbc/plans/value_null_split.dag\ndag/gunbc/principal_projection.dag\ndag/gunbc/prose_row_frontier.dag\ndag/gunbc/provider_account.dag\ndag/gunbc/provider_interface_binding.dag\ndag/gunbc/provider_readiness_claim_evidence.dag\ndag/gunbc/provider_standing.dag\ndag/gunbc/provider_standing_probe_bridge.dag\ndag/gunbc/provider_turn_adjudication.dag\ndag/gunbc/provider_wire_evidence.dag\ndag/gunbc/public_projection.dag\ndag/gunbc/publication_admission_delta.dag\ndag/gunbc/publication_decision.dag\ndag/gunbc/publication_policy.dag\ndag/gunbc/readback_independence.dag\ndag/gunbc/realization_vocab_confinement_census.dag\ndag/gunbc/regen_receipt.dag\ndag/gunbc/remote_operation.dag\ndag/gunbc/remote_shell_command.dag\ndag/gunbc/replacement_cut.dag\ndag/gunbc/repo/repo_atlas_projection.dag\ndag/gunbc/repo/repo_identity.dag\ndag/gunbc/repo/repo_local_git_config.dag\ndag/gunbc/repo/repo_local_git_config_clone_bootstrap.dag\ndag/gunbc/repository.dag\ndag/gunbc/repository_census_coverage.dag\ndag/gunbc/repository_census_observation.dag\ndag/gunbc/resolved_graph_cache_hand_rust_scaffold.dag\ndag/gunbc/retained_shell_script.dag\ndag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl\ndag/gunbc/roadmap/roadmap_acceptance_history_carrier.dag\ndag/gunbc/roadmap/roadmap_acceptance_history_observation.dag\ndag/gunbc/roadmap/roadmap_acceptance_history_projection.dag\ndag/gunbc/roadmap/roadmap_altitude.dag\ndag/gunbc/roadmap/roadmap_component.dag\ndag/gunbc/roadmap/roadmap_dashboard_instance.dag\ndag/gunbc/roadmap/roadmap_dashboard_instance_apply.dag\ndag/gunbc/roadmap/roadmap_dispatch_environment.dag\ndag/gunbc/roadmap/roadmap_execution_contract.dag\ndag/gunbc/roadmap/roadmap_focus.dag\ndag/gunbc/roadmap/roadmap_forecast.dag\ndag/gunbc/roadmap/roadmap_identity.dag\ndag/gunbc/roadmap/roadmap_instrument_motion.dag\ndag/gunbc/roadmap/roadmap_instrument_sandbox.dag\ndag/gunbc/roadmap/roadmap_instrument_tuner.dag\ndag/gunbc/roadmap/roadmap_presentation.dag\ndag/gunbc/roadmap/roadmap_program_view.dag\ndag/gunbc/roadmap/roadmap_provider_events.dag\ndag/gunbc/roadmap/roadmap_publish.dag\ndag/gunbc/roadmap/roadmap_publish_observe.dag\ndag/gunbc/roadmap/roadmap_repo_atlas_sandbox.dag\ndag/gunbc/roadmap/roadmap_sandbox.dag\ndag/gunbc/roadmap/roadmap_site_surface_expect.dag\ndag/gunbc/roadmap/roadmap_site_surface_observe.dag\ndag/gunbc/roadmap/roadmap_site_surface_render.dag\ndag/gunbc/roadmap/roadmap_site_surface_types.dag\ndag/gunbc/roadmap/roadmap_site_surface_witness.dag\ndag/gunbc/roadmap/roadmap_validation_oracle.dag\ndag/gunbc/roadmap/roadmap_verification_receipt.dag\ndag/gunbc/roadmap/roadmap_verify.dag\ndag/gunbc/roadmap/roadmap_workflow_command.dag\ndag/gunbc/roadmap/roadmap_workflow_progress.dag\ndag/gunbc/roadmap/roadmap_workflow_stage.dag\ndag/gunbc/roster_registry.dag\ndag/gunbc/runner/runner_activation.dag\ndag/gunbc/runner/runner_broker_progress_watchdog.dag\ndag/gunbc/runner/runner_capacity_operator_access.dag\ndag/gunbc/runner/runner_capacity_plan.dag\ndag/gunbc/runner/runner_capacity_realize.dag\ndag/gunbc/runner/runner_connectivity_recovery.dag\ndag/gunbc/runner/runner_connectivity_repair_plan.dag\ndag/gunbc/runner/runner_host_deploy.dag\ndag/gunbc/runner/runner_incarnation.dag\ndag/gunbc/runner/runner_lifecycle.dag\ndag/gunbc/runner/runner_lifecycle_realize.dag\ndag/gunbc/runner/runner_shape_census.dag\ndag/gunbc/runner/runner_slot_provision.dag\ndag/gunbc/running_release_identity.dag\ndag/gunbc/rust_decl_type_overlay.dag\ndag/gunbc/rust_item_identity.dag\ndag/gunbc/scm_compatibility/git.dag\ndag/gunbc/scm_compatibility/mercurial.dag\ndag/gunbc/scm_compatibility/pijul.dag\ndag/gunbc/scm_compatibility_shape.dag\ndag/gunbc/secret_provision.dag\ndag/gunbc/seed_growth.dag\ndag/gunbc/seed_growth_admission.dag\ndag/gunbc/self_host_artifact_materialization.dag\ndag/gunbc/self_host_promotion_obligations.dag\ndag/gunbc/served_surface_browser_observation.dag\ndag/gunbc/session_residency.dag\ndag/gunbc/shell_target_conformance.dag\ndag/gunbc/site/markup.dag\ndag/gunbc/source_admission_selection.dag\ndag/gunbc/source_integration_claim_evidence.dag\ndag/gunbc/source_integration_landing_spine.dag\ndag/gunbc/source_integration_proof_kernel.dag\ndag/gunbc/specification_citation_read_provenance.dag\ndag/gunbc/srv1_tasks_preapply_observation.dag\ndag/gunbc/srv4_uefi_observed.dag\ndag/gunbc/stage0/stage0_cargo_manifest.dag\ndag/gunbc/stage0/stage0_rust_honest_frontier_integration.dag\ndag/gunbc/stage0/stage0_rust_honest_frontier_projection.dag\ndag/gunbc/stage0/stage0_rust_host_observation.dag\ndag/gunbc/stage0/stage0_rust_lifecycle_totality.dag\ndag/gunbc/stage0/stage0_rust_maintenance_census_report.dag\ndag/gunbc/stage0/stage0_rust_product_reachability.dag\ndag/gunbc/stage0/stage0_rust_source_lifecycle_scaffold.dag\ndag/gunbc/systemctl_is_active_read.dag\ndag/gunbc/systemctl_list_units.dag\ndag/gunbc/systemctl_set_property.dag\ndag/gunbc/systemctl_status_read.dag\ndag/gunbc/systemctl_stop_run.dag\ndag/gunbc/systemd_run_transient.dag\ndag/gunbc/test_module_hygiene.dag\ndag/gunbc/tool_readiness.dag\ndag/gunbc/type_ref_hit_ne_bind_measure/authority.dag\ndag/gunbc/type_reference_binding_context.dag\ndag/gunbc/type_reference_containment_binding.dag\ndag/gunbc/typed_module_cache_capacity.dag\ndag/gunbc/typed_remote_file_write.dag\ndag/gunbc/uefi_boot_config.dag\ndag/gunbc/uefi_boot_install_decision.dag\ndag/gunbc/uefi_shell_over_sol.dag\ndag/gunbc/upstream_document_carriage.dag\ndag/gunbc/v1/v1_complexity_capability_census.dag\ndag/gunbc/v1/v1_complexity_decl_classification.dag\ndag/gunbc/v1/v1_complexity_decl_classification_roster.dag\ndag/gunbc/v1/v1_complexity_decl_classification_types.dag\ndag/gunbc/v1/v1_interpreter_dispatch_emit.dag\ndag/gunbc/v1/v1_interpreter_primitive_surface.dag\ndag/gunbc/v1/v1_maintenance_standing.dag\ndag/gunbc/web_motion_binding.dag\ndag/gunbc/witness/witness_deferral_freeze.dag\ndag/gunbc/witness/witness_execution_class.dag\ndag/gunbc/witness/witness_floor_workflow.dag\ndag/gunbc/witness/witness_row_cost.dag\ndag/gunbc/witness/witness_row_cost_basis.tsv\ndag/gunbc/worker_lifecycle.dag\ndag/gunbc/workflow_reconcile.dag\ndag/product/altra_motherboard/attachment_stack.dag\ndag/product/altra_motherboard/minimal_design.dag\ndag/product/altra_motherboard/pcb_world.dag\ndag/product/altra_motherboard/placement.dag\ndag/product/altra_motherboard/realization.dag\ndag/product/altra_motherboard/scene_emission.dag\ndag/product/build_fulfillment.dag\ndag/product/build_selection.dag\ndag/product/compute_board/admission.dag\ndag/product/compute_board/analog.dag\ndag/product/compute_board/article.dag\ndag/product/compute_board/composition.dag\ndag/product/compute_board/contact_population.dag\ndag/product/compute_board/device_binding.dag\ndag/product/compute_board/digital_control.dag\ndag/product/compute_board/emission_entry.dag\ndag/product/compute_board/intent.dag\ndag/product/compute_board/power_distribution.dag\ndag/product/compute_board/simulation_receipt.dag\ndag/product/compute_board/spice_projection.dag\ndag/product/compute_board/verilog_projection.dag\ndag/product/cooling_qualification.dag\ndag/product/electrical/connectivity.dag\ndag/product/fabric/budget.dag\ndag/product/fabric/demand.dag\ndag/product/fabric/execution.dag\ndag/product/fabric/identity.dag\ndag/product/fabric/supply.dag\ndag/product/fabric/work.dag\ndag/product/installed_bom_reconcile.dag\ndag/product/inventory.dag\ndag/product/node_power_envelope.dag\ndag/product/pcb/copper.dag\ndag/product/pcb/footprint.dag\ndag/product/pcb/physical.dag\ndag/product/pcb/plan_view.dag\ndag/product/pcb/scene.dag\ndag/product/pcb/stackup.dag\ndag/product/pcb/world.dag\ndag/product/rack_mount.dag\ndag/product/rack_power.dag\ndag/product/spatial_connectivity.dag\ndag/product/spatial_dimension.dag\ndag/product/spatial_edit.dag\ndag/product/spatial_projection.dag\ndag/product/spatial_world.dag\ndag/std/affine_space.dag\ndag/std/algebra_law.dag\ndag/std/attribution.dag\ndag/std/authorization_profile.dag\ndag/std/checked_arithmetic.dag\ndag/std/citation.dag\ndag/std/claim_evidence.dag\ndag/std/computation_identity.dag\ndag/std/coordinate_frame.dag\ndag/std/decimal.dag\ndag/std/dissolution.dag\ndag/std/euclidean_geometry.dag\ndag/std/evaluation_budget.dag\ndag/std/human_intervention.dag\ndag/std/interval.dag\ndag/std/key_relation.dag\ndag/std/keyed_roster.dag\ndag/std/keyed_row.dag\ndag/std/language_target_identity.dag\ndag/std/materialization_provider.dag\ndag/std/minted_identity.dag\ndag/std/observation.dag\ndag/std/occurrence_binding.dag\ndag/std/occurrence_binding_candidates.dag\ndag/std/occurrence_binding_resolve.dag\ndag/std/occurrence_identity.dag\ndag/std/orthogonal_geometry.dag\ndag/std/orthogonal_topology.dag\ndag/std/path_intent.dag\ndag/std/planar_projection.dag\ndag/std/primitive_identity.dag\ndag/std/process_termination.dag\ndag/std/reference_binding_observation.dag\ndag/std/roster_frontier.dag\ndag/std/selected_witness_bundle.dag\ndag/std/shell_stream_capture.dag\ndag/std/source_annotation.dag\ndag/std/spatial_frame.dag\ndag/std/spatial_knowledge.dag\ndag/std/state_durability.dag\ndag/std/trait_derive_shape.dag\ndag/std/unicode/types.dag\ndag/std/witness_admission.dag\ndag/std/witness_purpose.dag\ndag/test/claim/access_authorization_profile_witness_test.dag\ndag/test/claim/access_token_ensure_witness_test.dag\ndag/test/claim/acquisition_mechanism_witness_test.dag\ndag/test/claim/actions_job_grant_witness_test.dag\ndag/test/claim/advertising_interface_witness_test.dag\ndag/test/claim/affine_space_witness_test.dag\ndag/test/claim/altra_attachment_stack_witness_test.dag\ndag/test/claim/altra_contact_map_witness_test.dag\ndag/test/claim/altra_memory_controller_witness_test.dag\ndag/test/claim/altra_minimal_design_witness_test.dag\ndag/test/claim/altra_pcb_world_svg_witness_test.dag\ndag/test/claim/altra_placement_witness_test.dag\ndag/test/claim/altra_platform_and_mt_mitchell_authority_witness_test.dag\ndag/test/claim/altra_realization_witness_test.dag\ndag/test/claim/annotation_carrier_witness_test.dag\ndag/test/claim/annotation_erasure_emission_witness_test.dag\ndag/test/claim/anomaly_evidence_witness_test.dag\ndag/test/claim/anonymous_record_head_use_line_witness_test.dag\ndag/test/claim/argv_command_render_witness_test.dag\ndag/test/claim/aspeed_ast2500_management_paths_witness_test.dag\ndag/test/claim/attribution_span_witness_test.dag\ndag/test/claim/bach_double_slit_observation_witness_test.dag\ndag/test/claim/bach_double_slit_path_additivity_synthetic_fixture_witness_test.dag\ndag/test/claim/belt_tick_receipt_home_witness_test.dag\ndag/test/claim/bmc_fan_converge_witness_test.dag\ndag/test/claim/bmc_firmware_evidence_install_mechanism_witness_test.dag\ndag/test/claim/bmc_firmware_thermal_witness_test.dag\ndag/test/claim/bmc_live_receipts_witness_test.dag\ndag/test/claim/bmc_netboot_serve_witness_test.dag\ndag/test/claim/bmc_netboot_shell_boot_witness_test.dag\ndag/test/claim/bmc_typed_operations_witness_test.dag\ndag/test/claim/bmc_virtual_media_witness_test.dag\ndag/test/claim/board_part_land_pattern_witness_test.dag\ndag/test/claim/body_lowering_refusal_scope_test.dag\ndag/test/claim/body_lowering_rejection_propagation_test.dag\ndag/test/claim/branded_list_first_optional_witness_test.dag\ndag/test/claim/build_cache_endpoint_path_test.dag\ndag/test/claim/build_cache_ensure_test.dag\ndag/test/claim/build_cache_latency_probe_witness_test.dag\ndag/test/claim/build_cache_placement_observation_test.dag\ndag/test/claim/build_fulfillment_witness_test.dag\ndag/test/claim/build_latency_actions_collect_witness_test.dag\ndag/test/claim/build_selection_witness_test.dag\ndag/test/claim/busybox_bmc_build_witness_test.dag\ndag/test/claim/cache_retention_axes_witness_test.dag\ndag/test/claim/capability_binding_witness_test.dag\ndag/test/claim/caret_syntax_witness_test.dag\ndag/test/claim/cargo_artifact_selection_witness_test.dag\ndag/test/claim/cargo_execution_placement_witness_test.dag\ndag/test/claim/change_realization_witness_test.dag\ndag/test/claim/chapman_which_path_observation_witness_test.dag\ndag/test/claim/char_at_unicode_witness_test.dag\ndag/test/claim/cheap_gate_pool_test.dag\ndag/test/claim/check_coverage_admission_witness_test.dag\ndag/test/claim/checkpoint_identity_keying_witness_test.dag\ndag/test/claim/ci_cost_arc_closeout_receipt_witness_test.dag\ndag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag\ndag/test/claim/citation_cit0_witness_test.dag\ndag/test/claim/citation_cit1_consumer_witness_test.dag\ndag/test/claim/citation_cit1_witness_test.dag\ndag/test/claim/claim_indexed_evidence_witness_test.dag\ndag/test/claim/class_b_import_closure_binding_refusal_witness_test.dag\ndag/test/claim/class_b_strip_receipt_witness_test.dag\ndag/test/claim/claude_sdk_parser_drop_live_witness_test.dag\ndag/test/claim/claude_sdk_parser_drop_witness_test.dag\ndag/test/claim/claude_setup_token_enrollment_witness_test.dag\ndag/test/claim/cli_run_floor_lens_oracle_witness_test.dag\ndag/test/claim/cli_run_hand_rust_area_ledger_witness_test.dag\ndag/test/claim/cli_run_witness_admission_hand_rust_witness_test.dag\ndag/test/claim/cli_surface_boundary_probe_test.dag\ndag/test/claim/codex_app_server_press_wet_witness_test.dag\ndag/test/claim/codex_app_server_press_witness_test.dag\ndag/test/claim/codex_device_prompt_witness_test.dag\ndag/test/claim/codex_package_delivery_wet_witness_test.dag\ndag/test/claim/codex_package_lock_parse_witness_test.dag\ndag/test/claim/codex_provider_runtime_receipt_witness_test.dag\ndag/test/claim/codex_supervised_turn_wet_witness_test.dag\ndag/test/claim/codex_supervised_turn_witness_test.dag\ndag/test/claim/commit_check_demand_witness_test.dag\ndag/test/claim/commit_witness_claim_roster_witness_test.dag\ndag/test/claim/commit_writer_admission_witness_test.dag\ndag/test/claim/commit_writer_heal_admission_real_execution_witness_test.dag\ndag/test/claim/commit_writer_index_selection_witness_test.dag\ndag/test/claim/compile_clean_shard_entry_paths_fast_hand_rust_witness_test.dag\ndag/test/claim/compile_diagnostic_census_witness_test.dag\ndag/test/claim/compile_pool_ensure_test.dag\ndag/test/claim/component_dispatch_button_witness_test.dag\ndag/test/claim/compute_board_admission_witness_test.dag\ndag/test/claim/compute_board_article_witness_test.dag\ndag/test/claim/compute_board_emission_entry_witness_test.dag\ndag/test/claim/compute_board_physical_witness_test.dag\ndag/test/claim/compute_board_pin_chain_witness_test.dag\ndag/test/claim/compute_board_power_distribution_witness_test.dag\ndag/test/claim/compute_board_readiness_witness_test.dag\ndag/test/claim/compute_board_simulation_receipt_witness_test.dag\ndag/test/claim/compute_board_spice_projection_witness_test.dag\ndag/test/claim/compute_board_verilog_projection_witness_test.dag\ndag/test/claim/content_hash_family_grounded_witness_test.dag\ndag/test/claim/cooling_qualification_witness_test.dag\ndag/test/claim/cpu_socket_termination_witness_test.dag\ndag/test/claim/crm_stage_vocabulary_witness_test.dag\ndag/test/claim/cross_file_binding_assembly_witness_test.dag\ndag/test/claim/css_grain_witness_test.dag\ndag/test/claim/cursor_cli_invocation_witness_test.dag\ndag/test/claim/cursor_sdk_argv_projection_witness_test.dag\ndag/test/claim/cursor_sdk_auth_standing_witness_test.dag\ndag/test/claim/cursor_sdk_dispatch_bridge_witness_test.dag\ndag/test/claim/cursor_sdk_model_witness_test.dag\ndag/test/claim/cursor_sdk_stream_witness_test.dag\ndag/test/claim/dag_compile_clean_cli_floor_agreement_witness_test.dag\ndag/test/claim/dag_line_comment_annotation_channel_test.dag\ndag/test/claim/dag_parse_continuation_operator_witness_test.dag\ndag/test/claim/decl_facts_initializer_projection_witness_test.dag\ndag/test/claim/decl_facts_reflection_witness_support.dag\ndag/test/claim/decl_facts_reflection_witness_test.dag\ndag/test/claim/deploy_revision_witness_test.dag\ndag/test/claim/deployed_tree_remote_witness_test.dag\ndag/test/claim/devboot_build_product_witness_test.dag\ndag/test/claim/devboot_reuse_seams_witness_test.dag\ndag/test/claim/devboot_subject_identity_witness_test.dag\ndag/test/claim/dgx_spark_pxe_witness_test.dag\ndag/test/claim/dgx_spark_witness_test.dag\ndag/test/claim/diff_baseline_witness_test.dag\ndag/test/claim/diff_window_cross_seam_witness_test.dag\ndag/test/claim/direct_rust_door_write_compile_witness_test.dag\ndag/test/claim/dispatch_attempts_witness_test.dag\ndag/test/claim/dispatch_presentation_witness_test.dag\ndag/test/claim/dispatch_selection_witness_test.dag\ndag/test/claim/dispatch_stop_witness_test.dag\ndag/test/claim/dissolution_census_mechanism_witness_test.dag\ndag/test/claim/dissolution_migration_census_witness_test.dag\ndag/test/claim/documentary_refs_witness_test.dag\ndag/test/claim/e0308_mechanical_trio_test.dag\ndag/test/claim/e0599_emitter_decision_census_witness_test.dag\ndag/test/claim/e0599_probe_census_witness_test.dag\ndag/test/claim/effect_plan_bash_materialize_real_execution_witness_test.dag\ndag/test/claim/electrical_design_identity_witness_test.dag\ndag/test/claim/emitted_lib_rs_module_declaration_witness_test.dag\ndag/test/claim/emitter_bare_variant_expected_adoption_witness_test.dag\ndag/test/claim/emitter_nested_refinement_cast_witness_test.dag\ndag/test/claim/emitter_optional_payload_cast_witness_test.dag\ndag/test/claim/emitter_optional_present_branded_scalar_witness_test.dag\ndag/test/claim/ensure_witness_test.dag\ndag/test/claim/eval_cast_identity_witness_test.dag\ndag/test/claim/evaluation_budget_witness_test.dag\ndag/test/claim/exact_witness_admission_witness_test.dag\ndag/test/claim/executor_schedule_retention_test.dag\ndag/test/claim/expectation_frontier_witness_test.dag\ndag/test/claim/extdeps_llm_claude_trust_witness_test.dag\ndag/test/claim/external_model_scope_live_cover_witness_test.dag\ndag/test/claim/external_model_scope_witness_test.dag\ndag/test/claim/fabric_budget_encumbrance_witness_test.dag\ndag/test/claim/fabric_terminal_contract_witness_test.dag\ndag/test/claim/firmware_applicability_and_loop_cause_witness_test.dag\ndag/test/claim/firmware_prerequisite_evidence_witness_test.dag\ndag/test/claim/fleet_container_demand_envelope_witness_test.dag\ndag/test/claim/fleet_converge_plan_witness_test.dag\ndag/test/claim/fleet_converge_privilege_hold_witness_test.dag\ndag/test/claim/fleet_convergence_verdict_witness_test.dag\ndag/test/claim/fleet_host_key_enrollment_witness_test.dag\ndag/test/claim/fleet_known_hosts_anchor_witness_test.dag\ndag/test/claim/fleet_main_revision_witness_test.dag\ndag/test/claim/fleet_observation_producers_witness_test.dag\ndag/test/claim/fleet_receipt_collector_witness_test.dag\ndag/test/claim/fleet_runner_connectivity_witness_test.dag\ndag/test/claim/fleet_ssh_credential_verify_witness_test.dag\ndag/test/claim/float_add_associativity_law_witness_test.dag\ndag/test/claim/floor_batch_clamp_authority_witness_test.dag\ndag/test/claim/floor_component_receipt_witness_test.dag\ndag/test/claim/floor_discovery_exact_subject_witness_test.dag\ndag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag\ndag/test/claim/floor_discovery_roster_fixture_test.dag\ndag/test/claim/floor_expected_red_coherence_witness_test.dag\ndag/test/claim/floor_preparation_witness_test.dag\ndag/test/claim/floor_resolve_realization_witness_test.dag\ndag/test/claim/free_tier_serving_witness_test.dag\ndag/test/claim/frontend_literal_and_compile_witness_test.dag\ndag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag\ndag/test/claim/generic_item_clone_bound_witness_test.dag\ndag/test/claim/gha_job_projection_witness_test.dag\ndag/test/claim/git_ls_remote_witness_test.dag\ndag/test/claim/git_upstream_model_witness_test.dag\ndag/test/claim/gitattributes_emit_witness_test.dag\ndag/test/claim/githooks_repo_local_git_config_emit_witness_test.dag\ndag/test/claim/github_app_registry_witness_test.dag\ndag/test/claim/gitlab_10k_income_series_witness_test.dag\ndag/test/claim/grub_cmdline_quoting_witness_test.dag\ndag/test/claim/guarantee_measurement_witness_test.dag\ndag/test/claim/guarantee_probe_corpus_witness_test.dag\ndag/test/claim/hand_maintained_map_key_seed_witness_test.dag\ndag/test/claim/hash_checkpoint_retired_witness_test.dag\ndag/test/claim/heal_revalidation_witness_test.dag\ndag/test/claim/homomorphism_trait_derive_emit_witness_test.dag\ndag/test/claim/host_axis_caps_witness_test.dag\ndag/test/claim/host_budget_source_witness_test.dag\ndag/test/claim/host_cli_dependency_wet_witness_test.dag\ndag/test/claim/host_cli_dependency_witness_test.dag\ndag/test/claim/host_codex_runtime_provision_design_witness_test.dag\ndag/test/claim/host_compile_pool_test.dag\ndag/test/claim/host_memory_qualification_witness_test.dag\ndag/test/claim/host_network_diagnosis_witness_test.dag\ndag/test/claim/host_phase_status_witness_test.dag\ndag/test/claim/host_reach_identity_probe_witness_test.dag\ndag/test/claim/host_swap_backing_witness_test.dag\ndag/test/claim/host_toolchain_components_witness_test.dag\ndag/test/claim/hostname_allocation_witness_test.dag\ndag/test/claim/ice40_configuration_witness_test.dag\ndag/test/claim/ice40_supply_witness_test.dag\ndag/test/claim/ilm4926_designation_witness_test.dag\ndag/test/claim/infer_occurrence_binding_scaffold_witness_test.dag\ndag/test/claim/install_transport_qualification_witness_test.dag\ndag/test/claim/installed_bom_reconcile_witness_test.dag\ndag/test/claim/instrument_bob_witness_test.dag\ndag/test/claim/instrument_camera_witness_test.dag\ndag/test/claim/instrument_motion_page_witness_test.dag\ndag/test/claim/instrument_physical_witness_test.dag\ndag/test/claim/instrument_sandbox_witness_test.dag\ndag/test/claim/instrument_tuner_witness_test.dag\ndag/test/claim/interpreter_dispatch_bijection_real_roster_witness_test.dag\ndag/test/claim/interpreter_replacement_cut_witness_test.dag\ndag/test/claim/inventory_ledger_witness_test.dag\ndag/test/claim/jq_invocation_lowering_witness_test.dag\ndag/test/claim/json_parse_witness_test.dag\ndag/test/claim/json_protocol_schema_memory_split_wet_witness_test.dag\ndag/test/claim/jwt_oidc_claims_witness_test.dag\ndag/test/claim/keyed_roster_witness_test.dag\ndag/test/claim/lambda_capture_clone_required_witness_test.dag\ndag/test/claim/language_module_home_test.dag\ndag/test/claim/language_source_scaffold_index_test.dag\ndag/test/claim/language_target_identity_witness_test.dag\ndag/test/claim/language_target_registry_totality_test.dag\ndag/test/claim/language_target_subject_registration_test.dag\ndag/test/claim/ledger_tail_liveness_witness_test.dag\ndag/test/claim/legacy_test_behavior_disposition_acceptance_test.dag\ndag/test/claim/legacy_test_behavior_disposition_witness_test.dag\ndag/test/claim/legacy_test_inflow_witness_test.dag\ndag/test/claim/lifecycle_survivor_corpus_census_test.dag\ndag/test/claim/lifecycle_survivor_scan_witness_test.dag\ndag/test/claim/live_deploy/candidate_checkout_witness_test.dag\ndag/test/claim/live_deploy/deploy_release_fixture.dag\ndag/test/claim/live_deploy/running_release_identity_witness_test.dag\ndag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag\ndag/test/claim/live_rust_observation_contract_test.dag\ndag/test/claim/llm_attempt_receipt_witness_test.dag\ndag/test/claim/local_tidy_fmt_outcome_test.dag\ndag/test/claim/long/commit_witness_claim_roster_witness_test.dag\ndag/test/claim/long/dag_arrow_lambda_witness_test.dag\ndag/test/claim/long/dag_compile_clean_perturb_corpus_witness_test.dag\ndag/test/claim/long/dag_compile_clean_scope_disposition_witness_test.dag\ndag/test/claim/long/dissolution_census_witness_test.dag\ndag/test/claim/long/extdeps_scope_placement_gate_loudness_witness_test.dag\ndag/test/claim/long/g2_data_reference_under_selection_witness_test.dag\ndag/test/claim/long/instrument_sandbox_live_witness_test.dag\ndag/test/claim/long/namespace_graft_body_dissolution_witness_test.dag\ndag/test/claim/long/qualified_declaration_reference_emit_cross_module_witness_test.dag\ndag/test/claim/long/realization_sweep_test.dag\ndag/test/claim/long/roadmap_page_witness_test.dag\ndag/test/claim/long/root_d_checkpoint_scalar_declared_arity_witness_test.dag\ndag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag\ndag/test/claim/long/v1_complexity_capability_census_resolution_test.dag\ndag/test/claim/long/v1_complexity_decl_classification_totality_test.dag\ndag/test/claim/long/where_refinement_enforcement_witness_test.dag\ndag/test/claim/managed_directory_witness_test.dag\ndag/test/claim/map_key_derive_requirement_witness_test.dag\ndag/test/claim/match_arm_pattern_identity_emission_witness_test.dag\ndag/test/claim/match_exhaustiveness_coproduct_witness_test.dag\ndag/test/claim/materialization_kernel_closing_frontier_audit_witness_test.dag\ndag/test/claim/materialization_provider_consumer_hand_rust_witness_test.dag\ndag/test/claim/materialization_provider_witness_test.dag\ndag/test/claim/materialized_secret_witness_test.dag\ndag/test/claim/materialized_ssh_key_file_real_execution_witness_test.dag\ndag/test/claim/media_type_witness_test.dag\ndag/test/claim/memory_provisioning_witness_test.dag\ndag/test/claim/mercurial_upstream_model_witness_test.dag\ndag/test/claim/merge_admission_attempt_witness_test.dag\ndag/test/claim/model_artifact_identity_witness_test.dag\ndag/test/claim/module_graph_edge_source_witness_test.dag\ndag/test/claim/module_impact_query_witness_test.dag\ndag/test/claim/mt_jade_platform_witness_test.dag\ndag/test/claim/namespace_clause_e_projection_law_witness_test.dag\ndag/test/claim/namespace_occurrence_transport_test.dag\ndag/test/claim/namespace_pool_independence_witness_test.dag\ndag/test/claim/namespace_reference_derived_closure_acceptance_test.dag\ndag/test/claim/namespace_reference_derived_closure_contract_test.dag\ndag/test/claim/namespace_structural_root_exposure_generated_witness_test.dag\ndag/test/claim/native_scm_interaction_contract_witness_test.dag\ndag/test/claim/native_scm_interaction_scenario_fixture.dag\ndag/test/claim/native_witness_transition_receipt_witness_test.dag\ndag/test/claim/network_grounding_witness_test.dag\ndag/test/claim/no_fake_anomalies_witness_test.dag\ndag/test/claim/node_power_envelope_witness_test.dag\ndag/test/claim/non_fold_residue_frontier_test.dag\ndag/test/claim/normalize_retention_contract_probe_test.dag\ndag/test/claim/npm_sri_witness_test.dag\ndag/test/claim/observation_ci_render_witness_test.dag\ndag/test/claim/observation_crawl_replay_test.dag\ndag/test/claim/observation_emit_census_witness_test.dag\ndag/test/claim/observation_instant_witness_test.dag\ndag/test/claim/observation_lockstep_witness_test.dag\ndag/test/claim/observation_model_witness_test.dag\ndag/test/claim/observation_raw_print_retirement_acceptance_test.dag\ndag/test/claim/observation_rollup_witness_test.dag\ndag/test/claim/observation_seed_scoped_run_witness_test.dag\ndag/test/claim/observation_tty_render_witness_test.dag\ndag/test/claim/occurrence_binding_candidates_witness_test.dag\ndag/test/claim/occurrence_binding_resolve_witness_test.dag\ndag/test/claim/occurrence_binding_witness_test.dag\ndag/test/claim/occurrence_identity_acceptance_closure_witness_test.dag\ndag/test/claim/occurrence_identity_witness_test.dag\ndag/test/claim/ollama_capability_witness_test.dag\ndag/test/claim/operation_argv_binding_wall_witness_test.dag\ndag/test/claim/operation_argv_corpus_witness_test.dag\ndag/test/claim/optional_carrier_signature_test.dag\ndag/test/claim/optional_consumer_fail_closed_test.dag\ndag/test/claim/orthogonal_geometry_witness_test.dag\ndag/test/claim/orthogonal_topology_witness_test.dag\ndag/test/claim/package_delivery_codex_integrity_witness_test.dag\ndag/test/claim/package_graph_witness_test.dag\ndag/test/claim/pareto_selection_witness_test.dag\ndag/test/claim/pcb_capability_established_witness_test.dag\ndag/test/claim/pcb_copper_witness_test.dag\ndag/test/claim/pcb_footprint_witness_test.dag\ndag/test/claim/pcb_stackup_witness_test.dag\ndag/test/claim/pijul_upstream_model_witness_test.dag\ndag/test/claim/planar_projection_witness_test.dag\ndag/test/claim/posix_principal_allocation_witness_test.dag\ndag/test/claim/preemption_reachability_witness_test.dag\ndag/test/claim/primitive_identity_join_witness_test.dag\ndag/test/claim/principal_projection_witness_test.dag\ndag/test/claim/proc_self_cgroup_real_execution_witness_test.dag\ndag/test/claim/proc_self_cgroup_witness_test.dag\ndag/test/claim/prose_row_introduction_witness_test.dag\ndag/test/claim/provider_account_admission_witness_test.dag\ndag/test/claim/provider_lifecycle_witness_test.dag\ndag/test/claim/provider_standing_probe_bridge_witness_test.dag\ndag/test/claim/provider_standing_selection_witness_test.dag\ndag/test/claim/provider_standing_witness_test.dag\ndag/test/claim/publication_publisher_witness_test.dag\ndag/test/claim/push_event_witness_test.dag\ndag/test/claim/push_event_witness_wet_test.dag\ndag/test/claim/qualified_declaration_reference_emit_witness_test.dag\ndag/test/claim/qualified_leaf_registry_collision_emit_witness_test.dag\ndag/test/claim/rack_mount_witness_test.dag\ndag/test/claim/rack_power_witness_test.dag\ndag/test/claim/readback_independence_witness_test.dag\ndag/test/claim/realization_attempt_keystone_test.dag\ndag/test/claim/realization_vocab_confinement_census_test.dag\ndag/test/claim/record_construction_census_witness_test.dag\ndag/test/claim/record_literal_call_arg_handoff_witness_test.dag\ndag/test/claim/recorded_observation_envelope_witness_test.dag\ndag/test/claim/reference_derived_authored_source_gate_witness_test.dag\ndag/test/claim/reference_derived_variant_induced_parent_gate_witness_test.dag\ndag/test/claim/reference_instrument_witness_test.dag\ndag/test/claim/regional_compute_witness_test.dag\ndag/test/claim/remote_shell_command_witness_test.dag\ndag/test/claim/replacement_cut_witness_test.dag\ndag/test/claim/repo_atlas_projection_witness_test.dag\ndag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag\ndag/test/claim/repo_local_git_config_real_execution_witness_test.dag\ndag/test/claim/repo_local_git_config_witness_test.dag\ndag/test/claim/repository_census_coverage_witness_test.dag\ndag/test/claim/repository_census_observation_witness_test.dag\ndag/test/claim/required_expr_newline_continuation_witness_test.dag\ndag/test/claim/required_regen_admission_witness_test.dag\ndag/test/claim/resolved_graph_cache_hand_rust_witness_test.dag\ndag/test/claim/rest_exchange_replay_test.dag\ndag/test/claim/retained_shell_script_witness_test.dag\ndag/test/claim/roadmap_altitude_witness_test.dag\ndag/test/claim/roadmap_dashboard_instance_apply_witness_test.dag\ndag/test/claim/roadmap_dashboard_instance_witness_test.dag\ndag/test/claim/roadmap_dispatch_environment_witness_test.dag\ndag/test/claim/roadmap_execution_contract_witness_test.dag\ndag/test/claim/roadmap_focus_witness_test.dag\ndag/test/claim/roadmap_forecast_witness_test.dag\ndag/test/claim/roadmap_identity_witness_test.dag\ndag/test/claim/roadmap_presentation_witness_test.dag\ndag/test/claim/roadmap_program_view_live_corpus_receipt_test.dag\ndag/test/claim/roadmap_program_view_witness_test.dag\ndag/test/claim/roadmap_provider_events_witness_test.dag\ndag/test/claim/roadmap_publish_observe_witness_test.dag\ndag/test/claim/roadmap_publish_witness_test.dag\ndag/test/claim/roadmap_receipt_continuity_acceptance_fixture.dag\ndag/test/claim/roadmap_receipt_continuity_acceptance_test.dag\ndag/test/claim/roadmap_receipt_continuity_live_witness_test.dag\ndag/test/claim/roadmap_repo_atlas_sandbox_witness_test.dag\ndag/test/claim/roadmap_row_witness_test.dag\ndag/test/claim/roadmap_sandbox_witness_test.dag\ndag/test/claim/roadmap_site_surface_readiness_witness_test.dag\ndag/test/claim/roadmap_tactile_witness_test.dag\ndag/test/claim/roadmap_validation_oracle_witness_test.dag\ndag/test/claim/roadmap_verification_receipt_witness_test.dag\ndag/test/claim/roadmap_verify_witness_test.dag\ndag/test/claim/roadmap_workflow_command_witness_test.dag\ndag/test/claim/roadmap_workflow_progress_witness_test.dag\ndag/test/claim/root4_measure_missing_generics_witness_test.dag\ndag/test/claim/run_verdict_exit_status_fixture.dag\ndag/test/claim/run_verdict_exit_status_witness_test.dag\ndag/test/claim/runner_activation_wall_test.dag\ndag/test/claim/runner_broker_progress_watchdog_witness_test.dag\ndag/test/claim/runner_capacity_operator_access_witness_test.dag\ndag/test/claim/runner_capacity_plan_witness_test.dag\ndag/test/claim/runner_capacity_realize_witness_test.dag\ndag/test/claim/runner_connectivity_recovery_witness_test.dag\ndag/test/claim/runner_connectivity_repair_plan_witness_test.dag\ndag/test/claim/runner_host_deploy_witness_test.dag\ndag/test/claim/runner_lifecycle_witness_test.dag\ndag/test/claim/runner_replace_incarnation_seam_witness_test.dag\ndag/test/claim/runner_slot_installation_state_witness_test.dag\ndag/test/claim/runner_slot_provision_witness_test.dag\ndag/test/claim/runtime_rust_seed_bootstrap_sync_witness_test.dag\ndag/test/claim/rust_item_identity_witness_test.dag\ndag/test/claim/salience_witness_test.dag\ndag/test/claim/samsung_dram_module_witness_test.dag\ndag/test/claim/scaffold_disposition_census_fixture_witness_test.dag\ndag/test/claim/sccache_pin_witness_test.dag\ndag/test/claim/scm_agentic_stress_witness_test.dag\ndag/test/claim/scm_compatibility_git_witness_test.dag\ndag/test/claim/scm_compatibility_mercurial_witness_test.dag\ndag/test/claim/scm_compatibility_pijul_witness_test.dag\ndag/test/claim/scm_compatibility_shape_witness_test.dag\ndag/test/claim/scm_issuer_corpus_witness_test.dag\ndag/test/claim/scm_provider_matrix_witness_test.dag\ndag/test/claim/scm_serving_model_witness_test.dag\ndag/test/claim/secret_manager_access_version_witness_test.dag\ndag/test/claim/secret_provision_witness_test.dag\ndag/test/claim/secret_rotation_witness_test.dag\ndag/test/claim/seed_growth_admission_witness_test.dag\ndag/test/claim/seed_honesty_discharge_unavailable_test.dag\ndag/test/claim/self_host_artifact_materialization_real_execution_witness_test.dag\ndag/test/claim/self_host_artifact_materialization_witness_test.dag\ndag/test/claim/self_host_generation_identity_witness_test.dag\ndag/test/claim/self_host_promotion_admission_witness_test.dag\ndag/test/claim/self_host_promotion_obligations_witness_test.dag\ndag/test/claim/served_surface_browser_artifact_integrity_witness_test.dag\ndag/test/claim/served_surface_browser_observation_witness_test.dag\ndag/test/claim/serving_privilege_derivation_witness_test.dag\ndag/test/claim/session_residency_witness_test.dag\ndag/test/claim/sessions_panel_witness_test.dag\ndag/test/claim/shared_pool_encoding_control_test.dag\ndag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag\ndag/test/claim/shell_stream_capture_witness_test.dag\ndag/test/claim/shell_target_conformance_witness_test.dag\ndag/test/claim/source_admission_selection_witness_test.dag\ndag/test/claim/source_annotation_attachment_witness_test.dag\ndag/test/claim/source_integration_landing_spine_witness_test.dag\ndag/test/claim/source_integration_proof_kernel_acceptance_test.dag\ndag/test/claim/source_integration_proof_kernel_model_witness_test.dag\ndag/test/claim/spark_bootstrap_provision_witness_test.dag\ndag/test/claim/spark_capability_observation_witness_test.dag\ndag/test/claim/spark_credential_workflow_witness_test.dag\ndag/test/claim/spark_serving_converge_slice_witness_test.dag\ndag/test/claim/spark_serving_effect_wire_witness_test.dag\ndag/test/claim/spark_serving_full_plan_witness_test.dag\ndag/test/claim/spark_serving_member_realization_witness_test.dag\ndag/test/claim/spark_serving_membership_witness_test.dag\ndag/test/claim/spark_serving_observe_witness_test.dag\ndag/test/claim/spark_serving_realization_witness_test.dag\ndag/test/claim/spark_serving_release_witness_test.dag\ndag/test/claim/spark_serving_runtime_receipt_witness_test.dag\ndag/test/claim/spark_serving_write_unit_operation_witness_test.dag\ndag/test/claim/spatial_connectivity_witness_test.dag\ndag/test/claim/spatial_edit_witness_test.dag\ndag/test/claim/spatial_frame_scale_witness_test.dag\ndag/test/claim/spatial_knowledge_witness_test.dag\ndag/test/claim/spatial_placement_witness_test.dag\ndag/test/claim/spatial_projection_witness_test.dag\ndag/test/claim/spatial_units_witness_test.dag\ndag/test/claim/spatial_world_witness_test.dag\ndag/test/claim/srv1_tasks_preapply_observation_witness_test.dag\ndag/test/claim/srv3_subsumption_witness_test.dag\ndag/test/claim/ssh_client_options_witness_test.dag\ndag/test/claim/stage0_regen_convergence_real_execution_witness_test.dag\ndag/test/claim/stage0_rust_honest_frontier_integration_witness_test.dag\ndag/test/claim/stage0_rust_honest_frontier_projection_witness_test.dag\ndag/test/claim/stage0_rust_host_observation_live_witness_test.dag\ndag/test/claim/stage0_rust_lifecycle_totality_witness_test.dag\ndag/test/claim/stage0_rust_maintenance_census_report_live_witness_test.dag\ndag/test/claim/stage0_rust_maintenance_census_report_witness_test.dag\ndag/test/claim/stage0_rust_product_reachability_witness_test.dag\ndag/test/claim/stage0_rust_source_lifecycle_scaffold_witness_test.dag\ndag/test/claim/state_durability_witness_test.dag\ndag/test/claim/state_response_totality_witness_test.dag\ndag/test/claim/string_brace_escape_witness_test.dag\ndag/test/claim/string_length_char_count_witness_test.dag\ndag/test/claim/structured_application_mismatch_wall_witness_test.dag\ndag/test/claim/systemctl_status_read_scaffold_witness_test.dag\ndag/test/claim/systemd_unit_file_witness_test.dag\ndag/test/claim/tailscale_serve_route_key_witness_test.dag\ndag/test/claim/tailscale_serve_status_witness_test.dag\ndag/test/claim/terminal_wire_projection_witness_test.dag\ndag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag\ndag/test/claim/tmux_session_list_outcome_witness_test.dag\ndag/test/claim/tool_pin_witness_test.dag\ndag/test/claim/tool_readiness_witness_test.dag\ndag/test/claim/trait_bound_witness_test.dag\ndag/test/claim/transport_script_stdin_byte_fidelity_witness_test.dag\ndag/test/claim/transport_script_wall_compile_red_test.dag\ndag/test/claim/type_ref_hit_ne_bind_measure_witness_test.dag\ndag/test/claim/type_reference_binding_context_witness_test.dag\ndag/test/claim/type_reference_containment_binding_witness_test.dag\ndag/test/claim/type_reference_resolve_changeover_equivalence_witness_test.dag\ndag/test/claim/typed_module_cache_capacity_witness_test.dag\ndag/test/claim/typed_remote_file_converge_witness_test.dag\ndag/test/claim/typed_remote_file_write_fleet_ssh_fixture.dag\ndag/test/claim/typed_remote_file_write_witness_test.dag\ndag/test/claim/uefi_boot_config_witness_test.dag\ndag/test/claim/uefi_boot_install_decision_witness_test.dag\ndag/test/claim/uefi_shell_environment_witness_test.dag\ndag/test/claim/uefi_shell_over_sol_witness_test.dag\ndag/test/claim/uri_percent_encode_witness_test.dag\ndag/test/claim/v1_complexity_capability_census_witness_test.dag\ndag/test/claim/v1_complexity_decl_classification_witness_test.dag\ndag/test/claim/v1_interpreter_primitive_dispatch_authority_acceptance_test.dag\ndag/test/claim/v1_interpreter_primitive_roster_acceptance_test.dag\ndag/test/claim/v1_interpreter_primitive_surface_witness_test.dag\ndag/test/claim/verification_evidence_addressing_witness_test.dag\ndag/test/claim/virtual_media_unification_witness_test.dag\ndag/test/claim/wc_byte_count_verification_witness_test.dag\ndag/test/claim/web_motion_binding_witness_test.dag\ndag/test/claim/witness_deferral_freeze_witness_test.dag\ndag/test/claim/witness_execution_class_live_census_test.dag\ndag/test/claim/witness_execution_class_test.dag\ndag/test/claim/witness_purpose_taxonomy_witness_test.dag\ndag/test/claim/witness_row_cost_drift_witness_test.dag\ndag/test/claim/witness_row_cost_migration_disclosure_witness_test.dag\ndag/test/claim/witness_row_cost_projection_witness_test.dag\ndag/test/claim/workflow_dispatch_input_witness_test.dag\ndag/test/claim/workflow_reconcile_witness_test.dag\ndag/test/fixture/anonhead_provider.dag\ndag/test/fixture/argv_executable_position_probe.dag\ndag/test/fixture/codex_device_login/README.md\ndag/test/fixture/codex_device_login/device_auth_prompt_2026-07-30.txt\ndag/test/fixture/codex_device_login/device_auth_prompt_tmux_2026-07-30.txt\ndag/test/fixture/codex_provider_events/README.md\ndag/test/fixture/codex_provider_events/agent_message_turn_2026-07-29.jsonl\ndag/test/fixture/cross_file_clause_e_fixture.dag\ndag/test/fixture/cross_shard_seam/importee.dag\ndag/test/fixture/cross_shard_seam/importer.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_b_specimen.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_shared_a.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_shared_b.dag\ndag/test/fixture/decl_facts_reflection/ambiguous_specimen.dag\ndag/test/fixture/decl_facts_reflection/globally_unique_carrier.dag\ndag/test/fixture/decl_facts_reflection/specimens.dag\ndag/test/fixture/decl_facts_reflection/unimported_globally_unique_user.dag\ndag/test/fixture/decl_facts_reflection/witness_support.dag\ndag/test/fixture/decl_facts_reflection_duplicate_qn/primary/shadow_module.dag\ndag/test/fixture/floor_expected_red_coherence/severed_chunk_fixture.dag\ndag/test/fixture/github_push_event/main_push.json\ndag/test/fixture/leaf_key_collision/cross_kind_data_fn/module_a.dag\ndag/test/fixture/leaf_key_collision/cross_kind_data_fn/module_b.dag\ndag/test/fixture/leaf_key_collision/cross_kind_fn_data/module_a.dag\ndag/test/fixture/leaf_key_collision/cross_kind_fn_data/module_b.dag\ndag/test/fixture/leaf_key_collision/module_a.dag\ndag/test/fixture/leaf_key_collision/module_b.dag\ndag/test/fixture/module_graph_edge_source/consumer_bare.dag\ndag/test/fixture/module_graph_edge_source/consumer_imported.dag\ndag/test/fixture/module_graph_edge_source/provider_imported.dag\ndag/test/fixture/module_graph_edge_source/provider_referenced.dag\ndag/test/fixture/provider_terminal/codex_account_rate_limits_exhausted_multibucket_2026-08-06.jsonl\ndag/test/fixture/provider_terminal/codex_account_read_chatgpt_redacted_2026-08-06.jsonl\ndag/test/fixture/record_construction_census/homonym.dag\ndag/test/fixture/record_construction_census/qualified.dag\ndag/test/fixture/record_construction_census/specimens.dag\ndag/test/fixture/rest_exchange_replay_probe.dag\ndag/test/fixture/scaffold_disposition_census/expected_classification.dag\ndag/test/fixture/scaffold_disposition_census/pool/decoy_nullary.dag\ndag/test/fixture/scaffold_disposition_census/pool/decoy_record.dag\ndag/test/fixture/scaffold_disposition_census/pool/specimens.dag\ndag/test/fixture/scaffold_disposition_census/pool_notes.dag\ndag/test/fixture/sole_constructor_sealed/admitted_caller.dag\ndag/test/fixture/sole_constructor_sealed/definer.dag\ndag/test/fixtures/browser/chromium_151_bodied_502.png\ndag/test/fixtures/browser/chromium_151_connection_refused.png\ndag/test/fixtures/browser/chromium_151_empty_502.png\ndag/test/manual/git_upstream_model_execution_test.dag\ndag/test/manual/mercurial_upstream_model_execution_test.dag\ndag/test/manual/pijul_upstream_model_execution_test.dag\ndag/test/manual/process_argv_expansion_receipt_test.dag\ndag/tools/body_lowering_population_probe.dag\ndag/tools/cheap_claim_pool_gate.dag\ndag/tools/cheap_gate_pool.dag\ndag/tools/ci_heal_dispatch.dag\ndag/tools/dag_compile_clean_cli_floor_agreement.dag\ndag/tools/direct_rust_door_transport.dag\ndag/tools/e0599_emitter_decision_census.dag\ndag/tools/e0599_probe_census.dag\ndag/tools/extdeps_scope_placement_gate.dag\ndag/tools/frontier_ingestion_probe.dag\ndag/tools/interpreter_dispatch_bijection_real_roster_transport.dag\ndag/tools/merge_admission_capture.dag\ndag/tools/merge_admission_capture_transport.dag\ndag/tools/merge_admission_current_context.dag\ndag/tools/merge_admission_walk.dag\ndag/tools/module_impact_query_front_door.dag\ndag/tools/namespace_structural_root_exposure_generated_witness_transport.dag\ndag/tools/prose_row_introduction_gate.dag\ndag/tools/publication_publisher.dag\ndag/tools/publication_push_shadow.dag\ndag/tools/self_host_03_normalize_declared_source_refs.dag\ndag/tools/self_host_03_normalize_shims/std_algebra.rs\ndag/tools/self_host_03_normalize_shims/std_types.rs\ndag/tools/self_host_03_normalize_shims/v2_compiler_namespace_graft.rs\ndag/tools/self_host_module_behavioral_transport_roster.dag\ndag/tools/self_host_std_bridge_shims/v2_std_integer.rs\ndocs/plans/arc-store-path-migration-decision.md\ndocs/plans/build-cache-placement-receipt.md\ndocs/plans/c1-cost-expr-authority-design.md\ndocs/plans/candidate-scoped-gates-atomic-landing.md\ndocs/plans/ci-floor-child-spawn-attribution.md\ndocs/plans/ci-floor-time-45-72-band-attribution.md\ndocs/plans/ci-invocation-fixed-tax-attribution.md\ndocs/plans/ci-minutes-product-design.md\ndocs/plans/ci-two-tier-placement-redesign.md\ndocs/plans/ci0-witness-execution-census.md\ndocs/plans/ci2-native-cutover-reobservation.md\ndocs/plans/cli-invocation-emission-design.md\ndocs/plans/cli-run-hollowing-plan.md\ndocs/plans/compiler-guarantee-recovery-gap-analysis.md\ndocs/plans/containment-binding-cross-module-type-references-design.md\ndocs/plans/content-hash-family-grounding.md\ndocs/plans/cross-platform-instrument-motion.md\ndocs/plans/dag-native-scm-design.md\ndocs/plans/dag-note-prose-census.md\ndocs/plans/dag-prose-policy-audit.md\ndocs/plans/dag-scm-design.md\ndocs/plans/determinism-boundary-relative.md\ndocs/plans/discrete-cost-derivation.md\ndocs/plans/disk-tier-repeat-resolve-closeout.md\ndocs/plans/dissolution-census-a-ci-layer-roots.md\ndocs/plans/e0599-implementation-proposal.md\ndocs/plans/emission-admission-stage-aware-pipeline-design.md\ndocs/plans/entry-graph-union-slice1-measurement.md\ndocs/plans/entry-graph-union-slice2-typecheck-attribution.md\ndocs/plans/entry-view-assembly-direction-receipt.md\ndocs/plans/extdeps-modeling-preflight.md\ndocs/plans/extdeps-positioning-restructure.md\ndocs/plans/extdeps-std-grounding-inventory.md\ndocs/plans/fabric-concept-reconciliation.md\ndocs/plans/fabric-recut-program.md\ndocs/plans/fallback-arm-census.md\ndocs/plans/fill-composition-overlay-direction-receipt.md\ndocs/plans/five-minute-ci-gate-design.md\ndocs/plans/floor-cut-replacement-plan.md\ndocs/plans/floor-expected-red-shrink-monotonicity-design.md\ndocs/plans/floor-prep-tax-program.md\ndocs/plans/floor-semantic-artifact-design.md\ndocs/plans/floor-shared-fill-ledger.md\ndocs/plans/for-sugar-over-fold.md\ndocs/plans/formal-concepts-extdeps-grounding.md\ndocs/plans/four-lane-closeout-and-root.md\ndocs/plans/generated-file-conflict-policy.md\ndocs/plans/git-plumbing-extdeps-authority-design.md\ndocs/plans/groupcompletion-pair-construction-design.md\ndocs/plans/hermetic-tool-provisioning-design.md\ndocs/plans/holds-base-runtime-error-investigation-receipts.md\ndocs/plans/hollow-alias-construction-wall.md\ndocs/plans/import-strip-measurement/README.md\ndocs/plans/import-strip-measurement/receipts/control-diagnostics.log\ndocs/plans/import-strip-measurement/receipts/declaration-census-duplicates.tsv\ndocs/plans/import-strip-measurement/receipts/stripped-diagnostics.log\ndocs/plans/import-strip-measurement/receipts/stripped-file-manifest.tsv\ndocs/plans/import-strip-measurement/receipts/subject-tree-hash.txt\ndocs/plans/import-strip-measurement/receipts/summary.txt\ndocs/plans/import-strip-residual-ledger.tsv\ndocs/plans/inner-cost-lanes-scoping.md\ndocs/plans/keying-relation-design.md\ndocs/plans/language-support-completion-design.md\ndocs/plans/m2-floor-retention-measurement-receipt.md\ndocs/plans/measurements/floor-slow-rows-2026-08-17.md\ndocs/plans/measurements/floor-slow-rows-2026-08-17.tsv\ndocs/plans/measurements/floor-slow-rows-2026-08-18.md\ndocs/plans/measurements/floor-slow-rows-2026-08-18.tsv\ndocs/plans/namespace-cut-replacement-plan.md\ndocs/plans/namespace-flip-last-28-root-a-two-std-defork.md\ndocs/plans/namespace-unique-on-chain-operational-plan.md\ndocs/plans/nat-grounding-unification-design.md\ndocs/plans/native-selected-witness-bundle-design.md\ndocs/plans/p1-retention-vs-drain-cohort-receipt.md\ndocs/plans/p3-classification-cost-ab-receipt.md\ndocs/plans/parked-questions.md\ndocs/plans/per-entry-assembly-decomposition-measurement.md\ndocs/plans/production-stage-origin-carrier-design.md\ndocs/plans/progress-observation-design.md\ndocs/plans/provider-control-interface-audit.md\ndocs/plans/push-event-affected-set-baseline-design.md\ndocs/plans/receipts/arc-1-shareability-frontier/after-r1.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/after-r2.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/base-r1.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/base-r2.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/subject.tsv\ndocs/plans/receipts/arc-1-shareability-frontier/summary.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-broad-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-broad.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-narrow-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-narrow.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-typical-byte-weighted.json\ndocs/plans/receipts/entry-graph-union-slice1/closure-overlap-typical.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-amortization-n1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-amortization-n6.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-ci_floor_measurement-r1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-ci_floor_measurement-r2.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-generated_artifact_drift-r1.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition-generated_artifact_drift-r2.json\ndocs/plans/receipts/entry-graph-union-slice1/cost-partition.txt\ndocs/plans/receipts/entry-graph-union-slice2/matrix-governor.log\ndocs/plans/receipts/entry-graph-union-slice2/matrix-run.log\ndocs/plans/receipts/entry-graph-union-slice2/receipt-broad-capped.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-broad-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-explicit-order-a.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-explicit-order-b.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-narrow-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-narrow-production.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-reorder-a.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-reorder-b.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-representative-50.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-typical-disjoint.json\ndocs/plans/receipts/entry-graph-union-slice2/receipt-typical-production.json\ndocs/plans/receipts/entry-view-assembly-direction/after-r1.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/after-r1.tsv\ndocs/plans/receipts/entry-view-assembly-direction/after-r2.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/after-r2.tsv\ndocs/plans/receipts/entry-view-assembly-direction/base-arm-revert.patch\ndocs/plans/receipts/entry-view-assembly-direction/base-r1.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/base-r1.tsv\ndocs/plans/receipts/entry-view-assembly-direction/base-r2.stderr.txt\ndocs/plans/receipts/entry-view-assembly-direction/base-r2.tsv\ndocs/plans/receipts/entry-view-assembly-direction/binary_sha256.txt\ndocs/plans/receipts/entry-view-assembly-direction/cohort.tsv\ndocs/plans/receipts/entry-view-assembly-direction/remote_cohort_run3.log\ndocs/plans/receipts/entry-view-assembly-direction/summary.json\ndocs/plans/receipts/fill-composition-overlay-direction/after-r1.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/after-r1.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/after-r2.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/after-r2.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/base-arm-revert.patch\ndocs/plans/receipts/fill-composition-overlay-direction/base-r1.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/base-r1.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/base-r2.stderr.txt\ndocs/plans/receipts/fill-composition-overlay-direction/base-r2.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/cohort.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/subject.tsv\ndocs/plans/receipts/fill-composition-overlay-direction/summary.json\ndocs/plans/receipts/m2-floor-retention-falsifier-batch1.json\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-candidate-cli_run.patch\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-control-cli_run.patch\ndocs/plans/receipts/p3-classification-cost-ab/harness-overlay-probe.patch\ndocs/plans/receipts/partition-floor-wall-mapping/ci-run-31156588100.snapshot.txt\ndocs/plans/receipts/per-entry-assembly-decomposition/representative-50-r1.txt\ndocs/plans/receipts/per-entry-assembly-decomposition/representative-50-r2.txt\ndocs/plans/receipts/wrapper-consolidation-neutrality/summary.json\ndocs/plans/reconcile-cost-root-cause.md\ndocs/plans/recursive-workflow-advancement-design.md\ndocs/plans/replacement-migration-doctrine.md\ndocs/plans/resolve-regression-journey.md\ndocs/plans/restore-src-v1-required-floor-stall-finding.md\ndocs/plans/review-surface-subject-map.md\ndocs/plans/roadmap-presentation-seam-design.md\ndocs/plans/roadmap-workspace-remodel-plan.md\ndocs/plans/roadmap-workspace-ux-plan.md\ndocs/plans/scaffold-admission-doctrine.md\ndocs/plans/seamless-deploys-design.md\ndocs/plans/secret-version-lifecycle.md\ndocs/plans/self-host-cargo-refusal-root-partition.md\ndocs/plans/sole-modeled-publisher-design.md\ndocs/plans/spark-standup-program-accounting.md\ndocs/plans/srv1-deploy-serialization-and-false-greens.md\ndocs/plans/srv4-bmc-onboarding-gap.md\ndocs/plans/test-decomposition-wcf-cut.md\ndocs/plans/v1rt-witness-diagnostic-carrier-decouple-design.md\ndocs/plans/v2-complexity-capability-parity.md\ndocs/plans/v2-frontend-std-ingestion-frontier-exact-head.md\ndocs/plans/v2-frontend-std-ingestion-frontier.md\ndocs/plans/value-null-split.md\ndocs/plans/width-2-crossover-receipt.md\ndocs/plans/witness-bridge-reobservation.md\ndocs/plans/witness-cost-derives-from-purpose.md\ndocs/plans/witness-cost-first-touch-attribution.md\ndocs/plans/witness-evidence-lifecycle-design.md\ndocs/plans/worker-private-memory-decomposition.md\nfixtures/builtin_shadow/free_call_shadow_specimen.dag\nfixtures/builtin_shadow/method_template_shadow_specimen.dag\nfixtures/class_b_import_closure/perturbation_overlay/src/v2/extdeps/languages/rust_pool_perturb_ambient.dag\nfixtures/class_b_import_closure/perturbation_overlay/src/v2/extdeps/languages/rust_test_decoy.dag\nfixtures/class_b_trim/coincidence_specimen.dag\nfixtures/class_b_trim/monoid_specimen.dag\nfixtures/class_b_trim/narrow_pool/dag/std/types.dag\nfixtures/class_b_trim/perturbation_overlay/dag/std/tr_import_ambient.dag\nfixtures/class_b_trim/specimen.dag\nfixtures/class_b_trim/wire_projection_specimen.dag\nprovider-runtime/codex/README.md\nprovider-runtime/codex/package-lock.json\nprovider-runtime/codex/package.json\nsrc/v1/04_occurrence_binding.dag\nsrc/v1/annotation_bind.dag\nsrc/v1/expected_red_roster_join.dag\nsrc/v1/frontend_observation.dag\nsrc/v1/gunbc/namespace_reference_derived_closure_production_observations.dag\nsrc/v1/gunbc/occurrence_binding_parser_walk.dag\nsrc/v1/stage0/build.rs\nsrc/v1/stage0/src/bin/codex_app_server_stdio_session.rs\nsrc/v1/stage0/src/bin/namespace_structural_root_exposure_generated_witness.rs\nsrc/v1/stage0/src/bin/p1_cohort_roster.txt\nsrc/v1/stage0/src/bin/p1_cohort_small_roster.txt\nsrc/v1/stage0/src/bounded_shell_host_drain.rs\nsrc/v1/stage0/src/cli_run/floor_discovery_snapshot.rs\nsrc/v1/stage0/src/cli_run/materialization_provider_consumer.rs\nsrc/v1/stage0/src/cli_run/roadmap_acceptance_history_carrier.rs\nsrc/v1/stage0/src/cli_run/shared_fill.rs\nsrc/v1/stage0/src/cli_run/test_module_hygiene_bridge.rs\nsrc/v1/stage0/src/codex_app_server_stdio_session.rs\nsrc/v1/stage0/src/data_initializer_identity.rs\nsrc/v1/stage0/src/derived_realization_schedule.rs\nsrc/v1/stage0/src/extdeps_container_oci_digest.rs\nsrc/v1/stage0/src/extdeps_units_dimensionless.rs\nsrc/v1/stage0/src/extdeps_units_iec_80000_13.rs\nsrc/v1/stage0/src/extdeps_units_iso8601.rs\nsrc/v1/stage0/src/extdeps_units_iso_80000_3.rs\nsrc/v1/stage0/src/gunbc_rust_decl_type_overlay.rs\nsrc/v1/stage0/src/required_regen_host.rs\nsrc/v1/stage0/src/std_checked_arithmetic.rs\nsrc/v1/stage0/src/std_dissolution.rs\nsrc/v1/stage0/src/std_keyed_roster.rs\nsrc/v1/stage0/src/std_keyed_row.rs\nsrc/v1/stage0/src/std_occurrence_binding.rs\nsrc/v1/stage0/src/std_occurrence_binding_candidates.rs\nsrc/v1/stage0/src/std_occurrence_binding_resolve.rs\nsrc/v1/stage0/src/std_occurrence_identity.rs\nsrc/v1/stage0/src/std_process_termination.rs\nsrc/v1/stage0/src/std_reference_binding_observation.rs\nsrc/v1/stage0/src/std_roster_frontier.rs\nsrc/v1/stage0/src/std_source_annotation.rs\nsrc/v1/stage0/src/std_trait_derive_shape.rs\nsrc/v1/stage0/src/std_unicode_types.rs\nsrc/v1/stage0/src/std_witness_admission.rs\nsrc/v1/stage0/src/v1_compiler_annotation_bind.rs\nsrc/v1/stage0/src/v1_compiler_expected_red_roster_join.rs\nsrc/v1/stage0/src/v1_compiler_frontend_observation.rs\nsrc/v1/stage0/src/v1_compiler_infer_occurrence_binding.rs\nsrc/v1/stage0/src/v1_compiler_trait_bound_witness.rs\nsrc/v1/stage0/src/v1_compiler_trait_derive_emit.rs\nsrc/v1/stage0/src/v1_gunbc_namespace_reference_derived_closure_production_observations.rs\nsrc/v1/stage0/src/v1_gunbc_occurrence_binding_parser_walk.rs\nsrc/v1/stage0/src/v1_interpreter_dispatch_generated.rs\nsrc/v1/stage0/src/v1_tests_claim_checkpoint_identity_keying_witness_test.rs\nsrc/v1/stage0/tests/bounded_shell_stream_capture_replay.rs\nsrc/v1/stage0/tests/interpreter_dispatch_authority.rs\nsrc/v1/stage0/tests/interpreter_dispatch_bijection_compile_red.rs\nsrc/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs\nsrc/v1/stage0/tests/namespace_occurrence_serde.rs\nsrc/v1/stage0/tests/scoped_run_observation.rs\nsrc/v1/stage0/tests/tokenize_escape_receipt.rs\nsrc/v1/tests/claim/checkpoint_identity_keying_witness_test.dag\nsrc/v1/tests/src/class_b_trim_specimen_test.rs\nsrc/v1/tests/src/decl_facts_dimensionless_projection_test.rs\nsrc/v1/tests/src/field_of_fractions_construction_test.rs\nsrc/v1/tests/src/field_of_fractions_single_declaration_test.rs\nsrc/v1/tests/src/materialization_provider_resolved_graph_consumer_test.rs\nsrc/v1/tests/src/namespace_unique_on_chain_policy_test.rs\nsrc/v1/tests/src/none_undetermined_carrier_refuse_test.rs\nsrc/v1/trait_bound_witness.dag\nsrc/v1/trait_derive_emit.dag\nsrc/v2/compiler/inferred_tree.dag\nsrc/v2/compiler/native_selected_bundle_process.dag\nsrc/v2/compiler/parse_diagnostic.dag\nsrc/v2/compiler/self_host/direct_rust_door_fixture.dag\nsrc/v2/compiler/self_host/direct_rust_door_ingest_fixture.dag\nsrc/v2/compiler/self_host/direct_rust_door_observation.dag\nsrc/v2/compiler/self_host/emit_coverage_frontier.dag\nsrc/v2/compiler/self_host/emitter_producer_provenance.dag\nsrc/v2/compiler/self_host/fixture_synthetic_emission.dag\nsrc/v2/compiler/self_host/frontier_probe_assemble_detail.dag\nsrc/v2/compiler/self_host/frontier_probe_semantic_family_receipt.dag\nsrc/v2/compiler/self_host/generation.dag\nsrc/v2/compiler/self_host/native_agreement_support.dag\nsrc/v2/compiler/self_host/native_routing_frontier.dag\nsrc/v2/compiler/self_host/parity_receipts_local.dag\nsrc/v2/compiler/self_host/parity_window.dag\nsrc/v2/compiler/self_host/promotion_admission.dag\nsrc/v2/compiler/self_host/seed_emitter_behavioral_wet_known_red_entries.dag\nsrc/v2/compiler/self_host/seed_emitter_behavioral_wet_module_bindings.dag\nsrc/v2/compiler/self_host/stage0_crate_layout.dag\nsrc/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag\nsrc/v2/compiler/self_host/witness_bulk_routing.dag\nsrc/v2/compiler/self_host/witness_entry_eligibility_census.dag\nsrc/v2/compiler/trait_derive_completeness.dag\nsrc/v2/extdeps/formats/icestorm_pcf.dag\nsrc/v2/extdeps/language_model/python_l1_static_test.dag\nsrc/v2/extdeps/language_model/python_r1_test.dag\nsrc/v2/extdeps/language_model/rust_r1_test.dag\nsrc/v2/extdeps/language_model/rust_r3_internal_test.dag\nsrc/v2/extdeps/languages/bash_proc_self_cgroup.dag\nsrc/v2/extdeps/languages/c_bool_literal_emit.dag\nsrc/v2/extdeps/languages/rust_test_fixtures.dag\nsrc/v2/lens/application/application_subterm_at_empty_path_test.dag\nsrc/v2/lens/application/apply_lens_enforce_uses_projection_test.dag\nsrc/v2/lens/application/apply_lens_introspect_rejection_is_advisory_test.dag\nsrc/v2/lens/application/empty_required_lenses_skip_gate_test.dag\nsrc/v2/lens/application/enforce_rejecting_gate_fires_test.dag\nsrc/v2/lens/application/introspect_clean_tree_passes_test.dag\nsrc/v2/lens/application/rejecting_lens_blocks_before_compile_test.dag\nsrc/v2/lens/application/substitute_at_ambiguous_duplicate_name_test.dag\nsrc/v2/lens/application/substitute_at_depth_three_test.dag\nsrc/v2/lens/application/substitute_at_depth_two_test.dag\nsrc/v2/lens/application/subterm_at_ambiguous_duplicate_name_test.dag\nsrc/v2/lens/cost/bounded_summation_test.dag\nsrc/v2/lens/cost/disj_max_test.dag\nsrc/v2/lens/cost/expr.dag\nsrc/v2/lens/cost/expr_refusal_test.dag\nsrc/v2/lens/cost/loop_illegal_named_test.dag\nsrc/v2/lens/cost/loop_linear_test.dag\nsrc/v2/lens/cost/loop_unknown_test.dag\nsrc/v2/lens/cost/map_linear_test.dag\nsrc/v2/lens/cost/nested_product_test.dag\nsrc/v2/lens/cost/p9_llvm_instruction_cost_registry_owner_test.dag\nsrc/v2/lens/cost/summary.dag\nsrc/v2/lens/cost/summary_span_test.dag\nsrc/v2/lens/cost/valuation.dag\nsrc/v2/lens/cost/valuation_test.dag\nsrc/v2/lens/coverage/discriminant_predicate_defect_key_test.dag\nsrc/v2/lens/coverage/near_miss_vacuous_not_parallel_test.dag\nsrc/v2/lens/coverage/parallel_authority_defect_key_test.dag\nsrc/v2/lens/coverage/sibling_degenerate_not_hollow_test.dag\nsrc/v2/lens/emitted_binary_effect_confinement.dag\nsrc/v2/lens/enforcement/complexity_contract_subject.dag\nsrc/v2/lens/enforcement/inventory.dag\nsrc/v2/lens/fact_density/computation_not_type_carrier_test.dag\nsrc/v2/lens/fact_density/conj_positional_only_no_fact_test.dag\nsrc/v2/lens/fact_density/fact_bundle_compile_lens_passes_test.dag\nsrc/v2/lens/fact_density/fact_bundle_named_test.dag\nsrc/v2/lens/fact_density/hollow_alias_blocked_in_run_gates_test.dag\nsrc/v2/lens/fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag\nsrc/v2/lens/fact_density/hollow_alias_compile_lens_rejects_test.dag\nsrc/v2/lens/fact_density/hollow_alias_nested_rejected_test.dag\nsrc/v2/lens/fact_density/hollow_alias_no_fact_test.dag\nsrc/v2/lens/fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag\nsrc/v2/lens/fact_density/kernel_ambient_bool_test.dag\nsrc/v2/lens/fallback_arm_census.dag\nsrc/v2/lens/idempotency/write_effect_test.dag\nsrc/v2/lens/lifecycle_carrier.dag\nsrc/v2/lens/lifecycle_carrier/raw_prose_field_flagged_test.dag\nsrc/v2/lens/module_impact_query.dag\nsrc/v2/lens/parallelism/data_dependency_test.dag\nsrc/v2/lens/production_qualification_origin_probe.dag\nsrc/v2/lens/roster_registry.dag\nsrc/v2/lens/synthesis/constant_not_dominated_by_linear_test.dag\nsrc/v2/lens/synthesis/exponential_dominates_polynomial_test.dag\nsrc/v2/lens/synthesis/factorial_dominates_exponential_test.dag\nsrc/v2/lens/synthesis/linear_not_dominated_by_polynomial_test.dag\nsrc/v2/lens/synthesis/synthesis_gap_information_theoretic_test.dag\nsrc/v2/lens/synthesis/synthesis_gap_polynomial_test.dag\nsrc/v2/lens/synthesis/synthesis_no_technique_diagnostic_test.dag\nsrc/v2/lens/vacuity_self_application_fixture.dag\nsrc/v2/std/algebra_laws/field_patch_monoid_test.dag\nsrc/v2/std/compilers/cli_surface.dag\nsrc/v2/std/compilers/coproduct_variant_shape.dag\nsrc/v2/std/data_initializer_identity.dag\nsrc/v2/std/decl_facts_skeleton.dag\nsrc/v2/std/decl_ref_resolution.dag\nsrc/v2/std/grammar_choice_ambiguity.dag\nsrc/v2/std/native_agreement.dag\nsrc/v2/std/operation_argv.dag\nsrc/v2/std/optional.dag\nsrc/v2/std/witness_evaluation.dag\nsrc/v2/std/witness_execution_routing.dag\nsrc/v2/test/claim/bash_program_fold_support.dag\nsrc/v2/test/claim/body_lowering/arrow_body_form_semantic_helpers.dag\nsrc/v2/test/claim/body_lowering/arrow_body_form_witness_test.dag\nsrc/v2/test/claim/body_lowering/atom_body_discriminator_helpers.dag\nsrc/v2/test/claim/body_lowering/frontier_three_state_test.dag\nsrc/v2/test/claim/body_lowering/infer_transform_binary_infix_witness_helpers.dag\nsrc/v2/test/claim/body_lowering/infer_transform_binary_infix_witness_test.dag\nsrc/v2/test/claim/body_lowering/long/atom_body_discriminator_witness_test.dag\nsrc/v2/test/claim/ci_placement_witness_test.dag\nsrc/v2/test/claim/claim_pipeline/infer_test.dag\nsrc/v2/test/claim/claim_pipeline/normalize_test.dag\nsrc/v2/test/claim/claim_pipeline/resolve_test.dag\nsrc/v2/test/claim/claim_pipeline/translate_test.dag\nsrc/v2/test/claim/complexity_contract_subject_partition_witness_test.dag\nsrc/v2/test/claim/computation_identity_test.dag\nsrc/v2/test/claim/concept_index_enumeration/concept_index_enumeration_test.dag\nsrc/v2/test/claim/discrimination_gate/discrimination_roster_test.dag\nsrc/v2/test/claim/effect_plan_bash_materialize_test.dag\nsrc/v2/test/claim/emit/bool_literal_projection_emit_test.dag\nsrc/v2/test/claim/emit/conditional_delimiting_test.dag\nsrc/v2/test/claim/emit/produced_decl_support_preserved_test.dag\nsrc/v2/test/claim/emit/produced_decl_two_target_test.dag\nsrc/v2/test/claim/emit/rust_production_closure_let_emit_test.dag\nsrc/v2/test/claim/emit/trait_derive_seed_emit_binding_test.dag\nsrc/v2/test/claim/emit/trait_derive_supplemental_generic_bound_contract_test.dag\nsrc/v2/test/claim/emitted_binary_effect_confinement_red_control_test.dag\nsrc/v2/test/claim/enforcement_inventory_witness_test.dag\nsrc/v2/test/claim/execution/emit_host_filesystem_read_equals_eval_test.dag\nsrc/v2/test/claim/execution/emit_host_shell_exec_run_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/add_arrow_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/bind_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/emit_host_classical_not_ingested_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/emit_host_native_only_verdict_test.dag\nsrc/v2/test/claim/execution/long/emit_host_produced_module_equals_eval_test.dag\nsrc/v2/test/claim/execution/long/loop_eval_by_execution_test.dag\nsrc/v2/test/claim/execution/long/pick_ingested_probe_test.dag\nsrc/v2/test/claim/execution/long/pick_ingested_structural_lowering_test.dag\nsrc/v2/test/claim/execution/native_selected_witness_bundle_production.dag\nsrc/v2/test/claim/execution/native_selected_witness_bundle_test.dag\nsrc/v2/test/claim/extdeps/spice_element_letter_test.dag\nsrc/v2/test/claim/fallback_arm_census_planted_test.dag\nsrc/v2/test/claim/generated/language_behavior_equivalence_test.dag\nsrc/v2/test/claim/generated/testgen_category_wishlist_test.dag\nsrc/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag\nsrc/v2/test/claim/identity_captured_navigation/long/roster_gate_test.dag\nsrc/v2/test/claim/infer_self_grounding_wall_test.dag\nsrc/v2/test/claim/layer_transition_test.dag\nsrc/v2/test/claim/lean_bit_width_admissibility_witness_test.dag\nsrc/v2/test/claim/lean_overflow_semantics_witness_test.dag\nsrc/v2/test/claim/long/a4_opacity_test.dag\nsrc/v2/test/claim/long/bash_program_real_probes_witness_test.dag\nsrc/v2/test/claim/long/direct_rust_door_production_group_test.dag\nsrc/v2/test/claim/long/effect_reach_test.dag\nsrc/v2/test/claim/long/fallback_arm_census_witness_test.dag\nsrc/v2/test/claim/long/frontier_probe_closure_matrix_integration_test.dag\nsrc/v2/test/claim/long/gauntlet_lane_enrollment_witness_test.dag\nsrc/v2/test/claim/long/infer_transform_binary_infix_witness_test.dag\nsrc/v2/test/claim/long/inhabitant_neutralization_e2e_witness_test.dag\nsrc/v2/test/claim/long/live_read_classification_test.dag\nsrc/v2/test/claim/long/native_routing_membership_receipt_test.dag\nsrc/v2/test/claim/long/production_qualification_origin_probe_witness_test.dag\nsrc/v2/test/claim/long/realization_sweep_probe_entry.dag\nsrc/v2/test/claim/long/typescript_descriptor_node_run_witness_test.dag\nsrc/v2/test/claim/long/vacuity_consumer_witness_long_test.dag\nsrc/v2/test/claim/manual/add_body_producer_claim_test.dag\nsrc/v2/test/claim/manual/body_lowering_infix_test.dag\nsrc/v2/test/claim/manual/body_lowering_match_test.dag\nsrc/v2/test/claim/manual/body_lowering_normalize_add_test.dag\nsrc/v2/test/claim/manual/body_lowering_projection_call_test.dag\nsrc/v2/test/claim/manual/body_lowering_variants_test.dag\nsrc/v2/test/claim/manual/bootstrap_footprint_anchor_test.dag\nsrc/v2/test/claim/manual/call_carrier_node_query_test.dag\nsrc/v2/test/claim/manual/content_hash_loop_bound_edge_order_test.dag\nsrc/v2/test/claim/manual/content_hash_named_edge_order_test.dag\nsrc/v2/test/claim/manual/e0599_phase_a_body_evidence_probe.dag\nsrc/v2/test/claim/manual/fold_source_test.dag\nsrc/v2/test/claim/manual/go_grammar_claim_test.dag\nsrc/v2/test/claim/manual/infer_bounded_lattice_completeness_anchor_test.dag\nsrc/v2/test/claim/manual/kotlin_grammar_claim_test.dag\nsrc/v2/test/claim/manual/llvm_ir_b2_omni_in_b_probe_test.dag\nsrc/v2/test/claim/manual/model_core_anchor_test.dag\nsrc/v2/test/claim/manual/nominal_distinctness_cross_call_test.dag\nsrc/v2/test/claim/manual/posix_output_capture_test.dag\nsrc/v2/test/claim/manual/process_numeric_refinements_test.dag\nsrc/v2/test/claim/manual/python_grammar_claim_test.dag\nsrc/v2/test/claim/manual/qualified_pattern_reconcile_test.dag\nsrc/v2/test/claim/manual/refinement_authoritative_constants_test.dag\nsrc/v2/test/claim/manual/refinement_ordered_iteration_test.dag\nsrc/v2/test/claim/manual/resolve_compile_anchor_test.dag\nsrc/v2/test/claim/manual/sg1b_signature_realization_failclosed_test.dag\nsrc/v2/test/claim/manual/sg2_mode2_non_grammar_emit_test.dag\nsrc/v2/test/claim/manual/sg2_type_expression_projection_test.dag\nsrc/v2/test/claim/manual/sg2_typescript_type_expression_projection_test.dag\nsrc/v2/test/claim/manual/sg5_set_non_ordable_falsification_test.dag\nsrc/v2/test/claim/manual/sg_collection_projection_test.dag\nsrc/v2/test/claim/manual/structured_body_dispatch_test.dag\nsrc/v2/test/claim/manual/structured_body_subsumption_set_test.dag\nsrc/v2/test/claim/manual/target_model_atom_lookup_dissolution_test.dag\nsrc/v2/test/claim/manual/target_model_operator_lookup_dissolution_test.dag\nsrc/v2/test/claim/manual/test_claim_cache_digest_sensitivity_test.dag\nsrc/v2/test/claim/manual/typescript_derive_grammar_relation_row_round_trip_test.dag\nsrc/v2/test/claim/manual/typescript_descriptor_node_run.dag\nsrc/v2/test/claim/manual/typescript_grammar_claim_test.dag\nsrc/v2/test/claim/manual/value_null_split_witness_test.dag\nsrc/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag\nsrc/v2/test/claim/name_resolve/admission_fail_closed_test.dag\nsrc/v2/test/claim/name_resolve/malformed_imported_root_test.dag\nsrc/v2/test/claim/namespace_graft/collapsed_reader_test.dag\nsrc/v2/test/claim/native_cache_fusion_test.dag\nsrc/v2/test/claim/normalized_tree_admission_test.dag\nsrc/v2/test/claim/parse/parse_binding_fidelity_support.dag\nsrc/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag\nsrc/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag\nsrc/v2/test/claim/realize_advisory_soundness_test.dag\nsrc/v2/test/claim/roster_registry_test.dag\nsrc/v2/test/claim/self_host/compiler_closure_ingest_boundary_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_emission_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_fixture_containment_witness_test.dag\nsrc/v2/test/claim/self_host/direct_rust_door_group_algebra_test.dag\nsrc/v2/test/claim/self_host/emit_coverage_frontier_test.dag\nsrc/v2/test/claim/self_host/emitter_producer_provenance_witness_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_cause_location_roundtrip_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_cause_location_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_empty_ingest_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_overlap_detail_test.dag\nsrc/v2/test/claim/self_host/frontier_probe_semantic_family_receipt_test.dag\nsrc/v2/test/claim/self_host/native_agreement_test.dag\nsrc/v2/test/claim/self_host/native_routing_frontier_test.dag\nsrc/v2/test/claim/self_host/parity_window_test.dag\nsrc/v2/test/claim/self_host/production_qualification_origin_probe_structural_fixture.dag\nsrc/v2/test/claim/self_host/production_qualification_origin_probe_witness_test.dag\nsrc/v2/test/claim/self_host/v2_emitter_direct_rust_door_contract_test.dag\nsrc/v2/test/claim/self_host/witness_bulk_routing_test.dag\nsrc/v2/test/claim/self_host/witness_entry_eligibility_census_classification_test.dag\nsrc/v2/test/claim/tokenize/annotation_channel_test.dag\nsrc/v2/test/claim/trait_derive_completeness_predicate_test.dag\nsrc/v2/test/claim/translate_underived_refusal_test.dag\nsrc/v2/test/claim/vacuity_consumer_witness_test.dag\nsrc/v2/test/claim/verilog_interlock_emission_test.dag\nsrc/v2/test/claim/workflow/frontier_probe_closure_matrix_test.dag\nsrc/v2/test/claim/workflow/frontier_probe_closure_readthrough_test.dag\nsrc/v2/test/claim/workflow/source_root_overflow_never_empty_witness_test.dag\nsrc/v2/test/fixture/coproduct_reflection_generic_wrapper.dag\nsrc/v2/test/fixture/frontier_probe_cause_location_manifest_fixture.dag\nsrc/v2/test/fixture/frontier_probe_elision_boundary_overlay.dag\nsrc/v2/test/manual/long/grounding_lens_whole_tree_test.dag\nsrc/v2/workflow/ci_heal_revalidation_preflight_emit.dag\nsrc/v2/workflow/ci_heal_revalidation_preflight_emit_test.dag\nsrc/v2/workflow/ci_materialization_emit.dag\nsrc/v2/workflow/ci_materialization_emit_test.dag\nsrc/v2/workflow/ci_placement.dag\nsrc/v2/workflow/ci_v1_compiler_tests_compile_gate_emit.dag\nsrc/v2/workflow/ci_v1_compiler_tests_compile_gate_emit_test.dag\nsrc/v2/workflow/class_b_import_closure_probe.dag\nsrc/v2/workflow/class_b_import_closure_transport.dag\nsrc/v2/workflow/commit_witness_claim_roster.dag\nsrc/v2/workflow/effect_plan_bash_materialize.dag\nsrc/v2/workflow/floor2_prepared_subject.dag\nsrc/v2/workflow/floor_compile_clean_predicates.dag\nsrc/v2/workflow/floor_discovery.dag\nsrc/v2/workflow/floor_discovery_producer.dag\nsrc/v2/workflow/floor_discovery_transport.dag\nsrc/v2/workflow/floor_expected_red.dag\nsrc/v2/workflow/floor_expected_red_coherence.dag\nsrc/v2/workflow/floor_naming_hygiene.dag\nsrc/v2/workflow/floor_preparation.dag\nsrc/v2/workflow/legacy_test_inflow_audit.dag\nsrc/v2/workflow/native_cache_fusion.dag\nsrc/v2/workflow/orchestration_bash_emit_support.dag\nsrc/v2/workflow/realization_attempt.dag\nsrc/v2/workflow/realization_sweep.dag\nsrc/v2/workflow/realize_advisory_soundness.dag\nsrc/v2/workflow/required_floor.dag\nsrc/v2/workflow/required_regen.dag\ntest/fixture_roots/decl_facts_reflection_duplicate_qn/shadow/shadow_module.dag\ntools/extdeps_scope_exact_census_receipt.txt\ntools/m1c1_subject_map_receipt.txt\ntools/m1c_bulk0_manifest.tsv\ntools/m1c_bulk0_residual.tsv\ntools/m1c_bulk0_subject_map_receipt.txt\n" fn srv1_paths_becoming_tracked() -> List { split(s: srv1_paths_becoming_tracked_wire, sep: "\n") |> filter(p => p != "") diff --git a/dag/gunbc/namespace_census_receipt.dag b/dag/gunbc/namespace/namespace_census_receipt.dag similarity index 100% rename from dag/gunbc/namespace_census_receipt.dag rename to dag/gunbc/namespace/namespace_census_receipt.dag diff --git a/dag/gunbc/namespace_clause_e_projection_law.dag b/dag/gunbc/namespace/namespace_clause_e_projection_law.dag similarity index 100% rename from dag/gunbc/namespace_clause_e_projection_law.dag rename to dag/gunbc/namespace/namespace_clause_e_projection_law.dag diff --git a/dag/gunbc/namespace_cut_landing_order.dag b/dag/gunbc/namespace/namespace_cut_landing_order.dag similarity index 100% rename from dag/gunbc/namespace_cut_landing_order.dag rename to dag/gunbc/namespace/namespace_cut_landing_order.dag diff --git a/dag/gunbc/namespace_pool_independence.dag b/dag/gunbc/namespace/namespace_pool_independence.dag similarity index 100% rename from dag/gunbc/namespace_pool_independence.dag rename to dag/gunbc/namespace/namespace_pool_independence.dag diff --git a/dag/gunbc/namespace_reference_derived_closure_admission.dag b/dag/gunbc/namespace/namespace_reference_derived_closure_admission.dag similarity index 100% rename from dag/gunbc/namespace_reference_derived_closure_admission.dag rename to dag/gunbc/namespace/namespace_reference_derived_closure_admission.dag diff --git a/dag/gunbc/namespace_reference_derived_closure_contract.dag b/dag/gunbc/namespace/namespace_reference_derived_closure_contract.dag similarity index 100% rename from dag/gunbc/namespace_reference_derived_closure_contract.dag rename to dag/gunbc/namespace/namespace_reference_derived_closure_contract.dag diff --git a/dag/gunbc/namespace_structural_observation_bridge_seed_growth.dag b/dag/gunbc/namespace/namespace_structural_observation_bridge_seed_growth.dag similarity index 96% rename from dag/gunbc/namespace_structural_observation_bridge_seed_growth.dag rename to dag/gunbc/namespace/namespace_structural_observation_bridge_seed_growth.dag index 689b74c2407..1f97821681d 100644 --- a/dag/gunbc/namespace_structural_observation_bridge_seed_growth.dag +++ b/dag/gunbc/namespace/namespace_structural_observation_bridge_seed_growth.dag @@ -28,5 +28,5 @@ data namespace_structural_observation_bridge_seed_growth_justification: SeedGrow reason: "WHY A HOST BRIDGE RATHER THAN A .dag WITNESS CALLING THE PRODUCER DIRECTLY, and it is a reachability limit rather than a preference. The four observations are produced by v1.gunbc.namespace_reference_derived_closure_production_observations over v1.compiler.parse, and the required floor resolves --source-root dag --source-root src/v2 only. Measured over the whole corpus: NO dag module imports a v1 module, so a witness under dag/test/claim cannot name the producer at all. The two routes that do not need a bridge were both refused for reasons DESIGN already records. Homing the witness under src/v1/tests would bind the row's closing contract to evidence no required run executes -- the coverage-by-illusion tier DESIGN's compile-clean family is the receipt for. Rebuilding the observations on the v2 pipeline would put a second resolution authority beside the P2a candidate producer and the P1 fold, which is the single-authority violation the whole namespace lane exists to remove.\n\nWHAT THE BRIDGE IS AND IS NOT. It is a TRANSPORT: it takes one in-memory source string plus the four probe spellings from the caller, calls the one .dag producer, and encodes what that producer returned. It reads no repository file, needs no module index, and is hermetic by construction, so the witness on it declares SubstrateInputsOnly truthfully and executes in the required floor rather than landing in its DeclinedLiveTree arm. It decides nothing: the subject is the caller's, the four observations are composed in .dag, and the capability judgement is made by gunbc.namespace_reference_derived_closure_admission assess_reference_binding_observation, which the .dag producer calls. If a policy question ever arises inside the bridge, it belongs in the producer.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits by PURPOSE -- does the change serve the v2 self-host program. Namespace-only resolution is that program's current frontier, and until an ordinary compile can be asked what a name sees, every claim about it rests on hand-built examples.\n\nHAND-ITEM DELTA: +3, all enumerated above, all free functions in src/v1/stage0/src/v1_interpreter.rs and therefore citable as WholeDeclaration with no impl-method class. The third, subject_module_value, encodes the subject's own identity as a typed StructuralObservationSubjectModule rather than a String: an earlier revision of this bridge returned the module path as a bare string with EMPTY standing for the parse having refused, which made 'the parse refused' and 'the module path is empty' one value in a carrier that had a typed absence available. It was fail-closed only by accident of what the one consumer did with the string. The dispatch arm itself is a new match arm inside the existing eval_builtin_inner macro, which is an ExistingSeedItemModified rather than a new declaration, and v1_interpreter_dispatch_generated.rs is generated from gunbc.v1_interpreter_primitive_surface, so its new variant is a generated-surface regeneration and is not netted into a hand census. src/v1/04_method.dag and the .dag producer are substrate changes whose Rust mirrors are generated.", owning_dissolution_lane: "namespace-structural-observations" as RoadmapNodeId, trigger: "Delete both when a .dag witness can ask an ordinary compile what a name sees from where it is written WITHOUT a host bridge -- that is, when the observation-producing walk is reachable from a witness home whose resolution roots include the compiler that produces it, and the four observations for one in-memory source are obtainable there. What does NOT dissolve them is the required floor gaining src/v1 as a source root on its own: that is an artifact, and it can land while the producer is still unreachable from any executing witness -- the capability this bridge supplies is ONE IN-MEMORY SOURCE ANSWERED BY THE ORDINARY COMPILE PATH INSIDE AN EXECUTING WITNESS, and the trigger is satisfied only when something else supplies exactly that. What does NOT dissolve them either is the single-source compile builtins gaining another caller: those resolve through build_module_path_index_from_witness_roots, which walks the live tree, so a witness on them is declined and would retire executing evidence in favour of a name.", - current_boundary: "src/v1/stage0/src/v1_interpreter.rs free_call.namespace_structural_observation_admissions arm and its three encoders; dag/gunbc/namespace_structural_observations_production.dag; dag/gunbc/v1_interpreter_primitive_surface.dag roster row; src/v1/04_method.dag builtin return type; dag/std/primitives.dag spelling roster" + current_boundary: "src/v1/stage0/src/v1_interpreter.rs free_call.namespace_structural_observation_admissions arm and its three encoders; dag/gunbc/namespace/namespace_structural_observations_production.dag; dag/gunbc/v1/v1_interpreter_primitive_surface.dag roster row; src/v1/04_method.dag builtin return type; dag/std/primitives.dag spelling roster" } diff --git a/dag/gunbc/namespace_structural_observations_contract.dag b/dag/gunbc/namespace/namespace_structural_observations_contract.dag similarity index 100% rename from dag/gunbc/namespace_structural_observations_contract.dag rename to dag/gunbc/namespace/namespace_structural_observations_contract.dag diff --git a/dag/gunbc/namespace_structural_observations_production.dag b/dag/gunbc/namespace/namespace_structural_observations_production.dag similarity index 100% rename from dag/gunbc/namespace_structural_observations_production.dag rename to dag/gunbc/namespace/namespace_structural_observations_production.dag diff --git a/dag/gunbc/namespace_wave_admission.dag b/dag/gunbc/namespace/namespace_wave_admission.dag similarity index 99% rename from dag/gunbc/namespace_wave_admission.dag rename to dag/gunbc/namespace/namespace_wave_admission.dag index 28791d816d6..6d3b14a0bdf 100644 --- a/dag/gunbc/namespace_wave_admission.dag +++ b/dag/gunbc/namespace/namespace_wave_admission.dag @@ -237,7 +237,7 @@ data namespace_wave_admission_seed_growth_justification: SeedGrowthJustification reason: "THE OPERATOR RULED THAT A REQUEST TO ADD HAND RUST IS THE OCCASION TO MIGRATE OR DELETE HAND RUST (2026-08-26, relayed by warm-hawk-909: `yes we need to stop adding hand rust asap` and `use it as an opportunity to migrate/delete hand rust`). So this row answers at DECLARATION grain rather than as a count, and it records what the growth request bought back.\n\nWHAT THIS CHANGE DELETES OR AVOIDS, MEASURED, NOT ARGUED. (i) leaf_of was DELETED: it was a nickname for v1.00_core qualified_last_segment, which v1.05_emit_rust rust_fn_sig_leaf_name_dotted_note names as THE single authority for taking an authored spelling to its last segment. The wall now calls that mirror. That is a section 3 fork this change had introduced and removed before landing, and it is also the stronger construction, because the reduction the wall keys on is now the corpus authority rather than a local respelling. (ii) render_set was DELETED and inlined at its two call sites. (iii) claim_executor carried a BYTE-IDENTICAL PRIVATE COPY of git_stdout; the wall needed the same helper, and rather than land a third spelling the lib now owns the one copy, the bin`s copy is DELETED and its call sites read it. That is a NET REDUCTION of one pre-existing hand declaration and one fork.\n\nWHAT WAS NOT DELETED AND WHY, PER CLASS, BECAUSE `THESE ARE IRREDUCIBLE` IS A CLAIM AND A REASON PER DECLARATION IS AN ARGUMENT.\n\nCLASS A -- THE PURE FOLD, thirty-one declarations: adjudicate, binding_rows, binding_disposition, declaring_candidates, declarer_of, closure_of, membership_map, direct_membership, module_prefix_of, membership_supported, blast_radius, disposition_label, disposition_auto_admitted, delta_subject_render, report_unadjudicated, render_delta, vocabulary_findings, and the types and constants they fold over. Every one is a pure function of two indexes and needs NO host effect. They are host Rust for exactly ONE reason and it is not effort: their INPUT TYPE is host-only. ModuleDeclarationRecord and DeclarationIndex are Rust types produced by a host walk, and there is no .dag carrier for a per-module declaration record. Authoring one now would be a SECOND REPRESENTATION of a type gunbc.declaration_index_seed_growth already owns -- the section 3 violation this wall exists to refuse elsewhere -- so the correct move is to FOLLOW that carrier`s migration rather than fork it. Its trigger already names this class: when the record derivation is modeled, `the record builder and every finding function follow it`. This roster is one of those consumers.\n\nCLASS B -- THE ACQUISITION, four declarations: git_stdout, in_sweep_scope, base_records, run_required_wave_admission. These are blocked on a DIFFERENT grounding, which is why they are named separately rather than swept into class A: there is no typed repository-read transport a .dag fold can call to obtain the text of a file AT A REF. That is the scm lane`s subject, not a missing surface this change could have authored. base_records additionally needs the frontend`s own per-source parse, which is the same acquisition boundary.\n\nPR #9436 CHECKABLE HAND-RUST RECEIPT (review 56812). The 53 exact transition admissions are DATA consumed by the already-rostered NAMESPACE_TRANSITION_ADMISSIONS declaration; they add no compiler function, type, or admission mechanism. Measured against origin/main after rebasing: `git diff --numstat origin/main -- src/v1/stage0/src/namespace_wave_admission.rs` reports 559 added / 7 removed. `git show origin/main:src/v1/stage0/src/namespace_wave_admission.rs | grep -cE '^(pub )?(fn|struct|enum|const|static) '` reports 34 declarations, and the same grep on the worktree file reports 37. The anchored added/removed forms over `git diff` report 4 and 1 respectively: the unchanged roster declaration moves from the old `DeltaSubject` element type to `AdmissionSubject`, while `AdmissionSubject`, `admission_subject_matches`, and `admission_subject_render` are the three net additions. All three are enumerated in this justification. The initializer is a literal authored roster, not a scan, file read, environment read, or computed predicate. Each row is exact on subject and disposition; stale rows refuse, so the roster has its own deletion trigger: any absorbed or vanished delta makes required CI red until that row is removed. This is an expansion in maintained lines, not in declarations or host capability, and it dissolves row-by-row with the transition it names.\n\nONE THING THIS ROW WILL NOT DO: shrink the wall`s coverage to lower the count. A smaller wall that adds less Rust would spend correctness to buy a metric, which is the ratchet failure DESIGN names in the other direction.\n\nAND THE COUNT WENT UP RATHER THAN DOWN, WHICH IS THE HONEST DIRECTION. This roster was authored at 25 rows and is now 36, because it was JOINED against the module`s actual declaration population instead of listed from memory: leaf_of, binding_rows, vocabulary_findings and three constants were missing from the first draft. gunbc.seed_growth already warns that hand_authored_declarations is an authored obligation roster rather than a derived denominator; this is that warning firing on its own first use. Four methods were also converted from inherent impl blocks to free functions, because std.decl_ref names WholeDeclaration or NamedField and neither names a method on an impl block -- so as methods they would have been UNCITABLE items the roster structurally cannot enumerate. The module now carries no impl block, and every declaration in it is enumerated here.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete these in TWO steps, one per class above, and a PARTIAL migration is the expected shape rather than a failure. Class A follows gunbc.declaration_index_seed_growth`s first step: the moment a per-module declaration record is a .dag carrier, every one of those twenty-eight moves with it, because they are pure folds over it and nothing else. Class B follows the scm lane: when a typed repository-read transport can supply a file`s text at a ref. adjudicate, binding_disposition, declaring_candidates, declarer_of, closure_of, membership_map, direct_membership, module_prefix_of, membership_supported and blast_radius are pure functions of two indexes and move to .dag the moment the per-module record derivation does -- they need no host effect at all, so they follow gunbc.declaration_index_seed_growth's first step rather than waiting for its second. git_stdout, in_sweep_scope, base_records and run_required_wave_admission stay behind until a typed repository-read transport can supply a file's text at a ref, which is the scm lane's subject. A PARTIAL migration is the expected shape. What does NOT dissolve them is the phase moving to another host entry point, and what does NOT dissolve them is a hermetic witness over a fabricated pair of indexes -- the fixture suite already does that, and it is the evidence rather than the dissolution.", - current_boundary: "src/v1/stage0/src/namespace_wave_admission.rs; src/v1/stage0/src/declaration_index.rs dotted_chain and ModuleDeclarationRecord.referenced; src/v1/stage0/src/bin/claim_executor.rs phase namespace-wave-admission; src/v1/stage0/tests/namespace_wave_admission.rs; dag/gunbc/namespace_wave_admission.dag" + current_boundary: "src/v1/stage0/src/namespace_wave_admission.rs; src/v1/stage0/src/declaration_index.rs dotted_chain and ModuleDeclarationRecord.referenced; src/v1/stage0/src/bin/claim_executor.rs phase namespace-wave-admission; src/v1/stage0/tests/namespace_wave_admission.rs; dag/gunbc/namespace/namespace_wave_admission.dag" } // THE RULING AND THE PLAN THIS WALL DISCHARGES, cited by symbol so a rename or deletion diff --git a/dag/gunbc/non_fold_residue.dag b/dag/gunbc/non_fold_residue.dag index 0596ad3f7a9..767bb2fc2fe 100644 --- a/dag/gunbc/non_fold_residue.dag +++ b/dag/gunbc/non_fold_residue.dag @@ -164,42 +164,42 @@ data non_fold_residue_frontier: List = [ dissolution: nfr_dissolve_provider_standing_limit_draw, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/namespace_reference_derived_closure_admission.dag::binding_outcome_from_resolution" }, + subject: PathSubject { path: "dag/gunbc/namespace/namespace_reference_derived_closure_admission.dag::binding_outcome_from_resolution" }, reason: nfr_reason_binding_outcome_resolution_wildcard, dissolution: nfr_dissolve_binding_outcome_resolution_wildcard, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/namespace_pool_independence.dag::assess_file_dependencies_only_equality" }, + subject: PathSubject { path: "dag/gunbc/namespace/namespace_pool_independence.dag::assess_file_dependencies_only_equality" }, reason: nfr_reason_pool_independence_projection, dissolution: nfr_dissolve_pool_independence_projection, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/namespace_pool_independence.dag::assess_pool_independent_projection_equality" }, + subject: PathSubject { path: "dag/gunbc/namespace/namespace_pool_independence.dag::assess_pool_independent_projection_equality" }, reason: nfr_reason_pool_independence_projection, dissolution: nfr_dissolve_pool_independence_projection, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/roadmap_dispatch_actuator.dag::live_session_row_with_process" }, + subject: PathSubject { path: "dag/gunbc/roadmap/roadmap_dispatch_actuator.dag::live_session_row_with_process" }, reason: nfr_reason_provider_terminal_absorb, dissolution: nfr_dissolve_provider_terminal_absorb, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/roadmap_provider_events.dag::provider_execution_detail" }, + subject: PathSubject { path: "dag/gunbc/roadmap/roadmap_provider_events.dag::provider_execution_detail" }, reason: nfr_reason_provider_terminal_absorb, dissolution: nfr_dissolve_provider_terminal_absorb, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/roadmap_provider_events.dag::provider_execution_fold_event" }, + subject: PathSubject { path: "dag/gunbc/roadmap/roadmap_provider_events.dag::provider_execution_fold_event" }, reason: nfr_reason_provider_terminal_absorb, dissolution: nfr_dissolve_provider_terminal_absorb, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/roadmap_workflow_progress.dag::provider_execution_reconcile_process" }, + subject: PathSubject { path: "dag/gunbc/roadmap/roadmap_workflow_progress.dag::provider_execution_reconcile_process" }, reason: nfr_reason_provider_terminal_absorb, dissolution: nfr_dissolve_provider_terminal_absorb, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/roadmap_workflow_progress.dag::verification_segment" }, + subject: PathSubject { path: "dag/gunbc/roadmap/roadmap_workflow_progress.dag::verification_segment" }, reason: nfr_reason_verification_producer_absent, dissolution: nfr_dissolve_verification_producer_absent, }, @@ -329,17 +329,17 @@ data non_fold_residue_frontier: List = [ dissolution: nfr_dissolve_owning_fold, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/host_converge_slice1.dag::host_converge_slice1_host_result_all_valid" }, + subject: PathSubject { path: "dag/gunbc/host/host_converge_slice1.dag::host_converge_slice1_host_result_all_valid" }, reason: nfr_reason_legacy_slice1_bridge, dissolution: nfr_dissolve_legacy_slice1, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/host_converge_slice1.dag::host_converge_slice1_host_result_applied_count" }, + subject: PathSubject { path: "dag/gunbc/host/host_converge_slice1.dag::host_converge_slice1_host_result_applied_count" }, reason: nfr_reason_legacy_slice1_bridge, dissolution: nfr_dissolve_legacy_slice1, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/host_hygiene_reaper.dag::action_kills_build_cache_server" }, + subject: PathSubject { path: "dag/gunbc/host/host_hygiene_reaper.dag::action_kills_build_cache_server" }, reason: nfr_reason_reaper_oracle, dissolution: nfr_dissolve_derived_equality, }, @@ -349,102 +349,102 @@ data non_fold_residue_frontier: List = [ dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/runner_unit_live_read.dag::converge_target_live_verdict" }, + subject: PathSubject { path: "dag/gunbc/runner/runner_unit_live_read.dag::converge_target_live_verdict" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_bmc_credential_resolve.dag::bmc_credential_resolution_uses_factory" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_bmc_credential_resolve.dag::bmc_credential_resolution_uses_factory" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_bmc_credential_resolve.dag::bmc_credential_resolution_uses_secret_ref" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_bmc_credential_resolve.dag::bmc_credential_resolution_uses_secret_ref" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_boot_override_consumed_or_weak" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_boot_override_consumed_or_weak" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_srv3_install_post_boot" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_srv3_install_post_boot" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_srv3_install_when_serve_observed" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_srv3_install_when_serve_observed" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_srv3_install_when_serve_ready" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_srv3_install_when_serve_ready" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_weak_kvm_or_inconclusive" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_weak_kvm_or_inconclusive" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_when_router_not_installed" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_when_router_not_installed" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::diagnose_when_serve_ready" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::diagnose_when_serve_ready" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_boot_override_consumed_failure" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_boot_override_consumed_failure" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_os_installed" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_os_installed" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_ready_to_boot" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::install_diagnostic_verdict_is_ready_to_boot" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::install_has_progress_evidence" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::install_has_progress_evidence" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::parse_virtual_media_session_observation" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::parse_virtual_media_session_observation" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::router_lacks_os_installed_lease" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::router_lacks_os_installed_lease" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::sol_has_autoinstall_evidence" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::sol_has_autoinstall_evidence" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_boot_override_consumed" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_boot_override_consumed" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_os_installed" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_os_installed" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_ready_to_boot" }, + subject: PathSubject { path: "dag/gunbc/srv3/srv3_os_install_diagnostic.dag::srv3_install_diagnostic_is_ready_to_boot" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, @@ -884,22 +884,22 @@ data non_fold_residue_frontier: List = [ dissolution: unbound_dissolution(description: "DISSOLVE-ON: provenance is read from the containment-tree projection and live-snapshot-duplicate membership is construction-side (illegal states unrepresentable), or a single canonical accessor over TestClaimOperandProvenance answers both this and the independent-oracle question (operand_provenance_is_independent_oracle), replacing both hand-matched predicates at once — never two accessors surviving side by side once one canonical one exists (DESIGN §3 single authority). Same trigger as vacuity_operand_provenance_independent_oracle_predicate_dissolution_note's sibling note."), }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/repo_local_git_config.dag::apply_repo_local_git_config_action_at_repo" }, + subject: PathSubject { path: "dag/gunbc/repo/repo_local_git_config.dag::apply_repo_local_git_config_action_at_repo" }, reason: nfr_reason_legacy_slice1_bridge, dissolution: unbound_dissolution(description: "DISSOLVE-ON: membership apply dispatch derives off-variant noop from MemberAction inhabitance (MemberRemoved/MemberRemovalRefused are construction-unreachable for Ensured bindings) and the wildcard arm deletes with the row"), }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/ci_materialization.dag::warm_without_provider_receipt" }, + subject: PathSubject { path: "dag/gunbc/ci/ci_materialization.dag::warm_without_provider_receipt" }, reason: nfr_reason_resolve_realization_predicate, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/ci_materialization.dag::cold_without_resolve_receipt" }, + subject: PathSubject { path: "dag/gunbc/ci/ci_materialization.dag::cold_without_resolve_receipt" }, reason: nfr_reason_resolve_realization_predicate, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/host_standup.dag::assimilation_complete_input_eq" }, + subject: PathSubject { path: "dag/gunbc/host/host_standup.dag::assimilation_complete_input_eq" }, reason: nfr_reason_structural_eq_backfill, dissolution: nfr_dissolve_derived_equality, }, @@ -924,27 +924,27 @@ data non_fold_residue_frontier: List = [ dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/fleet_runner_connectivity.dag::connectivity_verdict_is_detached" }, + subject: PathSubject { path: "dag/gunbc/fleet/fleet_runner_connectivity.dag::connectivity_verdict_is_detached" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/fleet_runner_connectivity.dag::connectivity_verdict_is_healthy" }, + subject: PathSubject { path: "dag/gunbc/fleet/fleet_runner_connectivity.dag::connectivity_verdict_is_healthy" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/fleet_runner_connectivity.dag::connectivity_verdict_is_orphaned" }, + subject: PathSubject { path: "dag/gunbc/fleet/fleet_runner_connectivity.dag::connectivity_verdict_is_orphaned" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/fleet_runner_connectivity.dag::connectivity_verdict_is_unknown" }, + subject: PathSubject { path: "dag/gunbc/fleet/fleet_runner_connectivity.dag::connectivity_verdict_is_unknown" }, reason: nfr_reason_mint_era, dissolution: nfr_dissolve_wildcard_total, }, FrontierRow { - subject: PathSubject { path: "dag/gunbc/floor_component_receipt_document.dag::component_outcome_agrees_with_failure_mode" }, + subject: PathSubject { path: "dag/gunbc/floor/floor_component_receipt_document.dag::component_outcome_agrees_with_failure_mode" }, reason: nfr_reason_floor_component_receipt_validation, dissolution: nfr_dissolve_floor_component_receipt_validation, }, diff --git a/dag/gunbc/plans/budget_tree.dag b/dag/gunbc/plans/budget_tree.dag index aaf4c280545..1131b053812 100644 --- a/dag/gunbc/plans/budget_tree.dag +++ b/dag/gunbc/plans/budget_tree.dag @@ -50,7 +50,7 @@ fn budget_tree_body() -> List { p(text: "**Construction-first, not validation.** `R = floor(gha_runner_pool / reservation)` is *derived*, so an over-wide run count is unwritable; the leaf appropriation is the *measured* typical peak + margin, so the floor's spawn-width is governed by a real number, not a `totalMem / R` guess. Conservation across the three siblings is the residue lens (`node_conserves`) over the constructed tree."), p(text: "**Reservation-fit vs hard-guarantee (the valve is load-bearing).** `srv1_runs_fit_in_pool()` = `floor(pool / reservation)` = 3 is the *bin-packing* count — it assumes typical usage, so a correlated burst of rust-gate jobs each spiking to the ~30 GiB worst would over-commit (3 × 30 > 49.45 GiB pool). The *hard-guarantee* count `srv1_runs_hard_guaranteed()` = `floor(pool / worst_observed)` = 1 is the number that never over-commits even if every concurrent run hits the measured worst whole-run peak (not the 8 GiB within-run runner cap). `1 ≤ 3` is witnessed. The gap is covered by the host-RSS valve (deep-otter's admission backstop) — i.e. the reservation-based R is **valve-backstopped, not a hard guarantee**, exactly as the dashboard session pool is. The actuator that *enforces* R by start/stopping runner services (B5's \"GHA-runner-pool memory cap\") is a live-fleet apply and stays **operator-fenced** (§5); until it lands deep-otter holds the runner count at R=3 by hand, and the convergence proof is that the hand-walked count already equals the derived R."), p(text: "**Values — provenance.** typical/reservation ← **B4 (quick-lynx-78) verified** (`11592347648`, run 28003119550); worst-observed ← **deep-otter-528's srv2 cgroup `memory.peak` monitor** (`32434110464`); within-run runner cap ← `gunbc_ci_runner_cgroup_memory_cap` (8 GiB); The two-driver invariant (parent): the reservation side is driven by typical claim_executor batches (B4 measures it), the cap/worst side by rust-gate rustc *children* (only deep-otter's rust-gate-present monitor sees it; B4's no-rust-gate run under-reports it). NOTE: B4's #5619 dedup moves the *typical* self-RSS only ~0.57 GiB (8.7→8.1, NOT the earlier-retracted 8.7→4.2) and never touches the cap side. NOTE 2: `gunbc_ci_floor_runner_margin_num/den` (6/5 = 20%) was documented here as applying to the reservation, but its only code consumer was `within_run_spawn_budget()` (RETIRED in #5831 — was computing the wrong budget for within-run spawn-width, not the reservation). The margin constants (`gunbc_ci_floor_runner_margin_num/den`) and `gunbc_ci_floor_whole_run_peak_rss_bytes` are now deleted alongside `within_run_spawn_budget()` (no remaining consumers); the reservation reconciliation with deep-otter-528 is a separate runway."), - p(text: "Carriers: [dag/gunbc/ci_budget_tree.dag](../../dag/gunbc/ci_budget_tree.dag) (the two-pool tree + two-number leaf accessors), [dag/gunbc/ci_floor_measurement.dag](../../dag/gunbc/ci_floor_measurement.dag) (the measured carriers), witness [dag/test/claim/ci_budget_tree_witness_test.dag](../../dag/test/claim/ci_budget_tree_witness_test.dag)."), + p(text: "Carriers: [dag/gunbc/ci/ci_budget_tree.dag](../../dag/gunbc/ci/ci_budget_tree.dag) (the two-pool tree + two-number leaf accessors), [dag/gunbc/ci/ci_floor_measurement.dag](../../dag/gunbc/ci/ci_floor_measurement.dag) (the measured carriers), witness [dag/test/claim/ci_budget_tree_witness_test.dag](../../dag/test/claim/ci_budget_tree_witness_test.dag)."), ] } diff --git a/dag/gunbc/plans/ci_humming.dag b/dag/gunbc/plans/ci_humming.dag index 5e10e2035df..298baca5139 100644 --- a/dag/gunbc/plans/ci_humming.dag +++ b/dag/gunbc/plans/ci_humming.dag @@ -11,7 +11,7 @@ fn ci_humming_body() -> List { p(text: "**GOAL.** CI fast (low wall-clock per PR) + high throughput (many PRs concurrent) + reliable (no reds / OOM / flakes) — and all three falling *out* of a single modeled budget consumed by a verified-effective apply, never a hand-picked number (§2/§5)."), h2(text: "Root cause (live-verified 2026-06-23)"), p(text: "srv1 + srv2 (128c / 125GiB each) sit at ~10-34% CPU, ~24-32% MEM, with only **~3 runner slots per host** — so PRs **queue while the cores idle**. The throttle is the runner-slot count, which is set by the per-host **memory budget allocation**, not by saturation, not by fleet capacity, not by OOM."), - p(text: "The slot count is starved because the budget model (`dag/gunbc/fleet_host_budget.dag`) derives `runner_slice_cap ≈ 0`: build memory is subtracted as a `build_pool` **and** re-charged inside the per-job whole-tree-peak divisor. A GHA-CI runner job *is* a build — its `rustc` lives **inside** `system-actions-runner.slice` — so the build memory must be counted **once**, not twice."), + p(text: "The slot count is starved because the budget model (`dag/gunbc/fleet/fleet_host_budget.dag`) derives `runner_slice_cap ≈ 0`: build memory is subtracted as a `build_pool` **and** re-charged inside the per-job whole-tree-peak divisor. A GHA-CI runner job *is* a build — its `rustc` lives **inside** `system-actions-runner.slice` — so the build memory must be counted **once**, not twice."), h2(text: "oomd demoted (operator §5 insight)"), p(text: "Proper allocation (slice cap + per-slot caps ≤ physical − overhead, **verified-effective**) makes OOM impossible *by construction*. oomd is defense-in-depth for the **residue that is not yet capped-by-construction**, not a hard precondition. The srv2 reboots were construction *failing to realize* (the authored cap sat at `MemoryMax=infinity` on the live cgroup), not a missing daemon."), p(text: "→ Relax `fleet_host_plan`'s hard `OomdUnverified` gate; the primary gate is **caps verified-effective**. oomd stays as a non-blocking backstop, and its honest residual job is the one co-resident slice still uncapped — see SessionSliceEnforcement below."), diff --git a/dag/gunbc/plans/cli_run_hollowing_plan.dag b/dag/gunbc/plans/cli_run_hollowing_plan.dag index 9e8fc3afaa8..0b13a283ee4 100644 --- a/dag/gunbc/plans/cli_run_hollowing_plan.dag +++ b/dag/gunbc/plans/cli_run_hollowing_plan.dag @@ -15,7 +15,7 @@ fn cli_run_hollowing_plan_body() -> List { h2(text: "0. Scale receipt (live tree)"), ul(items: [ li(text: "**THIS SECTION CARRIES NO NUMBERS, DELIBERATELY.** It previously transcribed a whole-file line and fn count measured 2026-07-23. Both had gone stale by roughly 83 percent before anyone noticed, because nothing re-derives a number copied into prose. DESIGN's standing rule (2026-08-24) is *name the instrument, never transcribe its output*, and a plan's own scale receipt is the worst place to break it: a reader sequencing work against it budgets against a file that no longer exists at that size. **The instrument:** `git show origin/main:src/v1/stage0/src/cli_run.rs | wc -l` for scale, and the same stream through `grep -cE '^[[:space:]]*(pub )?(async )?fn '` for the fn count. Read them from the tree at the moment you need them. The DIRECTION is the durable fact and it needs no magnitude: the file has GROWN at every measurement taken so far, because v1 lanes absorb host bridges and floor machinery faster than v2 lanes subsume them."), - li(text: "**Chunk F in `seed-shrink-census.md` names the dissolution SIGN-OFF UNIT** (CI orchestration to workflow `host_effect_apply`), which is a different subject from the whole file. That distinction is the load-bearing half and it survives; the LOC split that used to accompany it here is deleted for the reason above. The remainder is the file's interim seed body, classified by the functional areas in section 2 and tracked as managed seed growth in ROADMAP **section 7 Seed interim** ([`ts-seed-interim`](../../ROADMAP.md) in `dag/gunbc/roadmap_authority.dag`) -- host bridges, lens host feeds, floor and discovery machinery absorbed while v2 lanes land."), + li(text: "**Chunk F in `seed-shrink-census.md` names the dissolution SIGN-OFF UNIT** (CI orchestration to workflow `host_effect_apply`), which is a different subject from the whole file. That distinction is the load-bearing half and it survives; the LOC split that used to accompany it here is deleted for the reason above. The remainder is the file's interim seed body, classified by the functional areas in section 2 and tracked as managed seed growth in ROADMAP **section 7 Seed interim** ([`ts-seed-interim`](../../ROADMAP.md) in `dag/gunbc/roadmap/roadmap_authority.dag`) -- host bridges, lens host feeds, floor and discovery machinery absorbed while v2 lanes land."), li(text: "**Sign-off order:** Chunk F runs **after** emitter chunks A–E and de-fork G per census §4 — orchestration dissolves once the compiler pipeline and host-effect spine can carry the floor without a hand-written driver."), ]), h2(text: "1. Area map (summary)"), diff --git a/dag/gunbc/plans/discrete_cost_derivation.dag b/dag/gunbc/plans/discrete_cost_derivation.dag index 4f169b5be56..e71f1ebe415 100644 --- a/dag/gunbc/plans/discrete_cost_derivation.dag +++ b/dag/gunbc/plans/discrete_cost_derivation.dag @@ -89,7 +89,7 @@ fn discrete_cost_derivation_body() -> List { row(cells: [ cell(text: "Predicted vs measured realization"), cell(text: "`std.realization_schedule` `CostAccount` / `CostBasis`; `std.realization_measurement`; `gunbc.witness_row_cost`"), - cell(text: "time/space/power with `Predicted | Measured`; and a **populated** dated basis corpus (`dag/gunbc/witness_row_cost_basis.tsv`, host_class `srv_fleet_arm64`) with drift verdicts"), + cell(text: "time/space/power with `Predicted | Measured`; and a **populated** dated basis corpus (`dag/gunbc/witness/witness_row_cost_basis.tsv`, host_class `srv_fleet_arm64`) with drift verdicts"), cell(text: "nothing feeds Predicted from graph structure — `cost_account_predicted_zero()` is the tell named by the signed scheduling doc's P1"), ]), ], @@ -172,7 +172,7 @@ fn discrete_cost_derivation_body() -> List { li(text: "**Exact cycles on real hardware is not claimable.** Cache behaviour, branch prediction, instruction scheduling, co-tenancy, frequency scaling and I/O latency are outside the modeled guarantee — the DESIGN §4b column that is deliberately *not* a ladder rung. An exact deterministic cycle count is claimable only against a specified abstract machine or simulator, and that is a different `RealizationTarget`, declared as such. For native hardware, cycles are an **observation that calibrates**, and the honest ceiling for the projection is a distribution, not a scalar."), li(text: "**The basis is dated and cited, per `gunbc.witness_row_cost`'s existing rule** — a basis row names an arm64 srv-fleet run id, never a local x86 measurement, and a re-basis is an appended dated row, never a silent widen."), ]), - p(text: "The measured corpus for calibration exists but its provenance is NOT sound, and C4 must not be planned as though it were. `dag/gunbc/witness_row_cost_basis.tsv` carries 1,173 rows seeded before `ClaimOutcome::TimedOut` could distinguish a killed run from a completed one, so an unknown subset of them are right-censored figures — a deadline ceiling recorded as if it were a cost. For exactly those rows the 2x comparator returned `WithinBasis` against the ceiling, which is not merely unvouched but wrong in the fail-open direction. C4 therefore joins to a corpus of unknown provenance, not to a measurement pipeline. Its real prerequisite is the completion axis reaching the basis rows and the provenance_unknown population draining; calibrating before then calibrates against censored values."), + p(text: "The measured corpus for calibration exists but its provenance is NOT sound, and C4 must not be planned as though it were. `dag/gunbc/witness/witness_row_cost_basis.tsv` carries 1,173 rows seeded before `ClaimOutcome::TimedOut` could distinguish a killed run from a completed one, so an unknown subset of them are right-censored figures — a deadline ceiling recorded as if it were a cost. For exactly those rows the 2x comparator returned `WithinBasis` against the ceiling, which is not merely unvouched but wrong in the fail-open direction. C4 therefore joins to a corpus of unknown provenance, not to a measurement pipeline. Its real prerequisite is the completion axis reaching the basis rows and the provenance_unknown population draining; calibrating before then calibrates against censored values."), h2(text: "10. Why a large input is or is not honest"), p(text: "Cost alone cannot answer whether a witness is merely proving that the computer can compute. That is a second, orthogonal question — **what semantic fact does the extra work establish?** — and it is the question the directory heuristic never asks. A large input is justified only when it is one of:"), @@ -188,7 +188,7 @@ fn discrete_cost_derivation_body() -> List { li(text: "**C1 — the valuation environment and exact pure work.** The seam correction 1 says is absent: bind `SizeVariable` to values, and evaluate to `ExactCost | BoundedCost | UnresolvedCost | CostRefused` over sequential nodes, branches with known conditions, known-finite lists, bounded folds and direct calls. **Accept:** doubling a bounded list doubles the derived fold-body work, by execution; a missing loop bound yields `CostRefused`, not zero; pilot on a real admission function whose cost is independently obvious."), li(text: "**C2 — sharing, and consumption of the engine's loop/recursion/span work.** The binder-carrying sum (correction 3), `span` derivation, and the SCC/descent machinery are the parity note's C1/C2/C4 and are **not duplicated here**; this note's own C2 is the materialization axis — make `Materialization` a derivation input so the same semantic graph derives different work under `Recompute` / `Memoize` / `Share` (§8). **Accept:** memoized and recomputed realizations of one graph derive different work; unknown descent refuses (consumed, not re-derived)."), li(text: "**C3 — effect demand, counted exactly.** Count filesystem reads/writes and bytes, subprocesses, network operations, host compiler invocations, as `ExecuteEffect` atoms keyed by `DeclarationRef`. **Assign no latency where no model exists** — counts stay exact and the projection refuses, which is strictly better than a fabricated duration. **Accept:** changing a fixture's file size changes derived read-byte demand; an unmodeled effect refuses rather than costing zero."), - li(text: "**C4 — realization calibration against the existing basis.** Project the work vector to predicted time/space under a pinned machine model; compare against `dag/gunbc/witness_row_cost_basis.tsv`. Re-home `llvm_instruction_cost` here, cited and dated. **Accept:** a planted omission in the model makes predicted and instrumented counts disagree and the falsifier goes red."), + li(text: "**C4 — realization calibration against the existing basis.** Project the work vector to predicted time/space under a pinned machine model; compare against `dag/gunbc/witness/witness_row_cost_basis.tsv`. Re-home `llvm_instruction_cost` here, cited and dated. **Accept:** a planted omission in the model makes predicted and instrumented counts disagree and the falsifier goes red."), li(text: "**C5 — the admission consumer (this is what retires the proxy).** Replace 'path contains `test/claim/long/`' with a declared cost envelope plus a `CostJustification` plus a named cadence, consumed by floor admission through `v2.lens.witness_cost_locality` `per_pr_admission` — whose own precision-frontier note already names this construction successor and the hand rosters it subsumes. **A missing derivation or a missing consumer refuses; it never silently becomes offline.** **Accept:** the three dissolve-on triggers in §1 fire together, and `witness_exclusion_substrings` hand-rows retire with them."), ]), @@ -248,6 +248,6 @@ data discrete_cost_derivation_plan: Plan = Plan { slug: "discrete-cost-derivation", title: "Discrete cost derivation — the work account between symbolic cost and measured wall", body: discrete_cost_derivation_body(), - retirement: PlanRetiresWhen { condition: unbound_dissolution(description: "Delete this doc when the C0 authority ruling is stated on the carriers themselves (v2.lens.cost owning discrete work, the v1 CostExpr machinery migrated, llvm_instruction_cost re-homed to a cited per-target model), a DAG section plus a declared input plus a realization derives ExactCost or BoundedCost or refuses with typed counted causes by execution, the projection to predicted time calibrates against dag/gunbc/witness_row_cost_basis.tsv with a planted-omission RED, and floor admission consumes declared per-witness cost envelopes so gunbc_ci_fast_lane_rule_note, gunbc_falsifier_substrate_long_lane_budget_note, and long_lane_exclusion_note all fire their own dissolve-on together — at which point the carriers state the policy and this note retires.") + retirement: PlanRetiresWhen { condition: unbound_dissolution(description: "Delete this doc when the C0 authority ruling is stated on the carriers themselves (v2.lens.cost owning discrete work, the v1 CostExpr machinery migrated, llvm_instruction_cost re-homed to a cited per-target model), a DAG section plus a declared input plus a realization derives ExactCost or BoundedCost or refuses with typed counted causes by execution, the projection to predicted time calibrates against dag/gunbc/witness/witness_row_cost_basis.tsv with a planted-omission RED, and floor admission consumes declared per-witness cost envelopes so gunbc_ci_fast_lane_rule_note, gunbc_falsifier_substrate_long_lane_budget_note, and long_lane_exclusion_note all fire their own dissolve-on together — at which point the carriers state the policy and this note retires.") } } diff --git a/dag/gunbc/plans/host_convergence_circuit_residue.dag b/dag/gunbc/plans/host_convergence_circuit_residue.dag index 3dc6d35ebe7..500ba497944 100644 --- a/dag/gunbc/plans/host_convergence_circuit_residue.dag +++ b/dag/gunbc/plans/host_convergence_circuit_residue.dag @@ -24,7 +24,7 @@ fn hccr_done() -> List { ]), h3(text: "P1 core — PerSlotMemoryCap axis on the membership_reconcile spine (4 receipts, GREEN)"), ul(items: [ - li(text: "dag/gunbc/host_axis_caps.dag: the first NON-DEGENERATE membership_reconcile in the repo (desired vs a real observed set, not observed=[]). One spine instantiation with a (key_of, key_eq, value_eq, ownership_of) bundle; ownership DERIVED from the drop-in path (managed -> Owned, foreign -> Ensured), never stored."), + li(text: "dag/gunbc/host/host_axis_caps.dag: the first NON-DEGENERATE membership_reconcile in the repo (desired vs a real observed set, not observed=[]). One spine instantiation with a (key_of, key_eq, value_eq, ownership_of) bundle; ownership DERIVED from the drop-in path (managed -> Owned, foreign -> Ensured), never stored."), li(text: "Interference domain = the drop-in directory, realized through the SAME spine: a foreign occupant is Removed + not-owned -> MemberRemovalRefused (R5, no effect arm, never deleted) -> ApplyRefused wholesale."), li(text: "Four hermetic receipts, each with a RED control, all GREEN, auto-discovered as a CI corpus consumer (not inert): idempotence (zero effects), perturb-and-heal (exactly the drifted row Upsert), foreign occupant (ApplyRefused + zero teardowns; RED = an owned removed file DOES teardown), derived content ([Service]/property/bytes derived, no hand strings)."), ]), diff --git a/dag/gunbc/plans/regime2_shared_emission_fold.dag b/dag/gunbc/plans/regime2_shared_emission_fold.dag index 4dc5c7c03f6..8e068924dea 100644 --- a/dag/gunbc/plans/regime2_shared_emission_fold.dag +++ b/dag/gunbc/plans/regime2_shared_emission_fold.dag @@ -21,7 +21,7 @@ fn regime2_shared_emission_fold_body() -> List { rows: [ row(cells: [cell(text: "yaml (ci.yml)"), cell(text: "`dag/extdeps/languages/yaml/types.dag` + `dag/extdeps/languages/yaml/emit.dag` + `dag/gunbc/ci_yaml_emit.dag`"), cell(text: "`YamlValue` (a real structured IR)"), cell(text: "`serialize_yaml` — hand-rolled recursive `match` (block/flow seq, scalar quoting, indent)")]), row(cells: [cell(text: "gitignore"), cell(text: "`dag/gunbc/gitignore_emit.dag`"), cell(text: "**none** — raw `concat`"), cell(text: "`serialize_gitignore` — hand fold over `IgnoreGroup`")]), - row(cells: [cell(text: "runner_deploy"), cell(text: "`dag/gunbc/runner_deploy_emit.dag`"), cell(text: "**none** — raw `concat`"), cell(text: "`expected_runner_deploy_manifest` — hand fold over hosts")]), + row(cells: [cell(text: "runner_deploy"), cell(text: "`dag/gunbc/runner/runner_deploy_emit.dag`"), cell(text: "**none** — raw `concat`"), cell(text: "`expected_runner_deploy_manifest` — hand fold over hosts")]), ], }, p(text: "That's the §2 violation: layout logic duplicated three ways."), diff --git a/dag/gunbc/plans/shell_emission_model.dag b/dag/gunbc/plans/shell_emission_model.dag index 8573e8fbd89..1636937eccd 100644 --- a/dag/gunbc/plans/shell_emission_model.dag +++ b/dag/gunbc/plans/shell_emission_model.dag @@ -41,7 +41,7 @@ fn shell_emission_model_body() -> List { p(text: "**Done bar:** green by **execution** vs frozen bytes, RED on perturb — never typechecks/emits/self-referential-gate."), h2(text: "5. Slice sequence (each gated by a frozen committed byte oracle)"), ol(items: [ - li(text: "**Slice 0 — CI EAGAIN-retry cutover — LANDED (#6467, verified 2026-07-16).** `dag/gunbc/ci_spec.dag` `ci_cargo_eagain_retry_intent` (:222) is a real `Retry \{ body: Pipeline\{steps:[Do\{run\}], on_failure: FailFast\}, escalations, on_exhausted \}` and `ci_cargo_eagain_retry_core` (:235) routes it through `orch_emit_step(medium: bash_orchestration_emit_medium())`, matching Accepted/Rejected. Refusal carries `ci_retry_emit_refused_poison` — a deliberately-invalid marker so a rejected emission reds BOTH the committed `ci.yml` drift gate and the yaml parse gate rather than letting a hand-spelled fallback mask it (§5 refuse-never-widen). Env lowering is structured since #5868+#6137 (`EnvUnset` + multi-binding `EnvPrefixed`; the `orch_emit_run_env_welded` weld is dissolved). **Precondition RESOLVED:** `Retry.on_exhausted` is no longer emitter-ignored — `05_emit_orchestration.dag:503` threads it to `orch_emit_retry`, bound at :627 via `orch_emit_pipeline(p: on_exhausted)`. The residual `concat` at :250 is a two-part `\"set -o pipefail\\n\"` prefix, not a nested-concat blob."), + li(text: "**Slice 0 — CI EAGAIN-retry cutover — LANDED (#6467, verified 2026-07-16).** `dag/gunbc/ci/ci_spec.dag` `ci_cargo_eagain_retry_intent` (:222) is a real `Retry \{ body: Pipeline\{steps:[Do\{run\}], on_failure: FailFast\}, escalations, on_exhausted \}` and `ci_cargo_eagain_retry_core` (:235) routes it through `orch_emit_step(medium: bash_orchestration_emit_medium())`, matching Accepted/Rejected. Refusal carries `ci_retry_emit_refused_poison` — a deliberately-invalid marker so a rejected emission reds BOTH the committed `ci.yml` drift gate and the yaml parse gate rather than letting a hand-spelled fallback mask it (§5 refuse-never-widen). Env lowering is structured since #5868+#6137 (`EnvUnset` + multi-binding `EnvPrefixed`; the `orch_emit_run_env_welded` weld is dissolved). **Precondition RESOLVED:** `Retry.on_exhausted` is no longer emitter-ignored — `05_emit_orchestration.dag:503` threads it to `orch_emit_retry`, bound at :627 via `orch_emit_pipeline(p: on_exhausted)`. The residual `concat` at :250 is a two-part `\"set -o pipefail\\n\"` prefix, not a nested-concat blob."), li(text: "**Slice 1 — control-flow emission (census-scoped) — LANDED (#6475; tier-2 Procedure/Let band #6566; operator-signed in `roadmap_authority.dag` `6-shell-slice1`).** The `If` band only — `orch_emit_step::If` arm with else (→ `orch_emit_if_step`), the condition forms, plus pipes / cmdsubst assignment / `$?` propagation / AndOr / redirects incl. `>>` / env framing word support, each with byte goldens. Every `Predicate` arm lowers (`ExitZero`, `StrEq`, `StrEmpty`, `StrNonempty`, `LogMatches`, `Not`, `And`, `Or`). `For` emission is **NOT in scope** (census-scoped): the mirror-retry `for` loop maps to the typed Retry/escalation model interpreted by the binary — it refuses **by design**, a decision, not a gap. **`While` emission has since LANDED (#6832); `BoundedPoll` emission was DELETED (2026-08-07):** the 2026-07-03 'zero pre-runtime `While` sites' finding was superseded by the `ci_floor_peak_emit` readiness-poll, so `While` lowers via `05_emit_orchestration` with byte goldens (`orchestration_while_emit_test`) and is no longer emitter-unsupported (the earlier inert `While.bound` field was dissolved by #6718; #6832 gave `While` a real bound-carrying emit). `BoundedPoll` was built solely by its own emit test; the zero-production-constructor census deleted the variant and its emit band outright."), li(text: "**Slice 2 — converge thin-run — implementation MERGED (#6572 keystone `ConvergePlan`+`EmitArtifactThenThinRun`+`converge_apply` · #6585 golden shrink 323→21 lines · #6598 `gunbc converge --host` CLI receiver); operator sign-off PENDING (receipts re-verified by execution 2026-07-20).** Tree receipts: `.github/fleet-converge.sh` is **21 lines** — `gunbc converge --host srv1|srv2|srv3` (ConvergePlan interpreted in-process) plus the fresh-standup bootstrap fragment, the one arm the bash-minimization rule sanctions as pre-runtime; `fleet_converge_emit.dag` has **zero** bash fn defs and emits one artifact (`expected_fleet_converge_sh`); `EmitArtifactThenThinRun` is a live `transport:` arm on `gunbc.host_effect` (`dag/test/claim/fleet_converge_apply_witness_test.dag`), no longer prose-only. The 4 for-loops / while-read drain / verdict arithmetic / 12 functions are gone; FLAGs 2a(i)/2b/2c were signed/discharged 2026-07-14 (recorded in the census §2). **This doc does NOT declare the slice done.** `roadmap_authority.dag` `6-shell-slice2` is the status authority and still reads `done: false` (MERGED, sign-off pending); flipping it requires an `operator` `signed(...)` attestation, which only the operator can give — every `done: true` row in that carrier is operator-signed. **Operator: sign `6-shell-slice2` and this row becomes LANDED.** Dispatch note: do NOT re-dispatch workers onto this slice — the stale `~275 lines / 12+ fn defs` census framing caused two misdispatches onto finished work (2026-07-16 slice 0, 2026-07-20 slice 2); the census §2/§3 rows now carry the landed receipts."), li(text: "**Slice 3 — live_deploy:** RUNTIME-PRESENT (runs on srv1 over LocalShell with gunbc as the invoker) → thin-run/typed-effect candidate, **not** a golden to freeze-and-emit: heredoc file bodies become typed `Filesystem.Write` effects with foreign-media payloads as data; apt/systemctl/tailscale become typed argv invocations. Its self-referential drift gate (compares the emit fn to itself) stays named as the #6023-class trap until the reshape."), diff --git a/dag/gunbc/plans/structural_quadratic_wall_coverage_audit.dag b/dag/gunbc/plans/structural_quadratic_wall_coverage_audit.dag index acad97189bf..c5eb4e8a70c 100644 --- a/dag/gunbc/plans/structural_quadratic_wall_coverage_audit.dag +++ b/dag/gunbc/plans/structural_quadratic_wall_coverage_audit.dag @@ -33,7 +33,7 @@ fn structural_quadratic_wall_coverage_audit_body() -> List { row(cells: [cell(text: "termination / DescentEvidence"), cell(text: "`dag/std/termination.dag` (single authority; the bare `v2.std.cardinality` fork is **consolidated into this dag/std authority by #6209** — still present on main until that PR merges); v1 checker `src/v1/complexity.dag` + `CostBound`/`PolyCost` in `dag/std/induction.dag`"), cell(text: "well-founded descent; poly cost bound; `Strict|NonIncreasing|DescentUnknown` bounded lattice (meet/join/`promote_to_strict`), bottom fails closed"), cell(text: "**WALL** primitive (`DescentUnknown` blocks a proof); §3 fork **consolidated by #6209** — one authority"), cell(text: "via v1-seed consumers"), cell(text: "STRUCTURAL (termination)")]), row(cells: [cell(text: "loop termination multiplicity (body-lowering)"), cell(text: "`src/v2/std/cardinality.dag` `behavior_multiplicity(Loop)` -> `multiplicity_termination_witness`"), cell(text: "decides a raw `Loop`'s termination **tag-only** today — never reads the `^loop_bound_edge` measure, so every raw loop is `Violates` regardless of its descent evidence"), cell(text: "WALL (fail-closed) but **measure-blind** — refined in Stage-2 to derive the verdict from the measure via the consolidated `DescentEvidence` lattice (fail-closed to `DescentUnknown`)"), cell(text: "NO (Stage-2 wiring is model-before-implement, held)"), cell(text: "STRUCTURAL (termination)")]), row(cells: [cell(text: "realization_width / memory_bounded_fit_count"), cell(text: "`dag/std/realization_width.dag`; actuator `cli_run.rs` `spawn_width_cap`"), cell(text: "memory-bounded parallel width = budget / per-shard peak; caps spawn width so co-resident VmHWM <= cgroup cap"), cell(text: "**WALL** / actuator (real floor consumer, fail-closed under-parallelize)"), cell(text: "YES (real consumer)"), cell(text: "RESOURCE (memory)")]), - row(cells: [cell(text: "budget tree (accounting)"), cell(text: "`dag/extdeps/accounting/budget.dag` (`admit_line_item`); `dag/product/budget_tree.dag` (`node_conserves`); `dag/gunbc/ci_budget_tree.dag`"), cell(text: "capped-resource -> line-item admission (Memory); conservation Bool"), cell(text: "admission construction (over-cap unwritable on the admit path) + RESIDUE (`node_conserves` for raw literals)"), cell(text: "YES (`*budget*_witness_test.dag`)"), cell(text: "RESOURCE (memory/money)")]), + row(cells: [cell(text: "budget tree (accounting)"), cell(text: "`dag/extdeps/accounting/budget.dag` (`admit_line_item`); `dag/product/budget_tree.dag` (`node_conserves`); `dag/gunbc/ci/ci_budget_tree.dag`"), cell(text: "capped-resource -> line-item admission (Memory); conservation Bool"), cell(text: "admission construction (over-cap unwritable on the admit path) + RESIDUE (`node_conserves` for raw literals)"), cell(text: "YES (`*budget*_witness_test.dag`)"), cell(text: "RESOURCE (memory/money)")]), row(cells: [cell(text: "node_wall_clock_ratchet"), cell(text: "`dag/gunbc/test_node_wall_clock_ratchet.dag`"), cell(text: "committed roster of test names permitted to emit wall-clock/time warnings"), cell(text: "RATCHET (bumpable roster)"), cell(text: "via testgen oracle"), cell(text: "RESOURCE (wall-clock)")]), row(cells: [cell(text: "EffortBudget (op-count)"), cell(text: "prose only in `dag/gunbc/plans/budget_tree.dag`; nearest live: `estimate_expr_size` `budget: Int` guard in `src/v1/complexity.dag`"), cell(text: "op-count recursion budget"), cell(text: "INERT (no `EffortBudget` type exists in the tree)"), cell(text: "NO"), cell(text: "RESOURCE (op-count)")]), row(cells: [cell(text: "algebraic-rewrite optimization"), cell(text: "`dag/gunbc/plans/algebraic_rewrite_optimization.dag`"), cell(text: "design spec for an O(n^2)->O(n) rewrite catalog + `Unknown` dissolution"), cell(text: "INERT / design-only (POST-STABILITY; no rewrite rows exist)"), cell(text: "NO"), cell(text: "STRUCTURAL (unbuilt)")]), diff --git a/dag/gunbc/prose_row_frontier.dag b/dag/gunbc/prose_row_frontier.dag index db518242bca..fb64514de6d 100644 --- a/dag/gunbc/prose_row_frontier.dag +++ b/dag/gunbc/prose_row_frontier.dag @@ -106,15 +106,15 @@ data prose_row_migration_scope: List = [ "dag/extdeps/tools/sha256sum.dag", "dag/extdeps/vendor/the_wand_company.dag", "dag/gunbc/bach_double_slit_observation.dag", - "dag/gunbc/bmc_converge.dag", - "dag/gunbc/bmc_netboot_shell_boot.dag", - "dag/gunbc/build_cache_endpoint_path.dag", - "dag/gunbc/build_cache_instance.dag", - "dag/gunbc/build_cache_latency_probe.dag", - "dag/gunbc/build_cache_unit.dag", + "dag/gunbc/bmc/bmc_converge.dag", + "dag/gunbc/bmc/bmc_netboot_shell_boot.dag", + "dag/gunbc/build_cache/build_cache_endpoint_path.dag", + "dag/gunbc/build_cache/build_cache_instance.dag", + "dag/gunbc/build_cache/build_cache_latency_probe.dag", + "dag/gunbc/build_cache/build_cache_unit.dag", "dag/gunbc/chapman_which_path_observation.dag", - "dag/gunbc/ci_deploy_access.dag", - "dag/gunbc/ci_runner_placement.dag", + "dag/gunbc/ci/ci_deploy_access.dag", + "dag/gunbc/ci/ci_runner_placement.dag", "dag/gunbc/econ/acquisition.dag", "dag/gunbc/econ/free_tier_serving.dag", "dag/gunbc/econ/knowable_wedge.dag", @@ -125,13 +125,13 @@ data prose_row_migration_scope: List = [ "dag/gunbc/executor_schedule_retention.dag", "dag/gunbc/falsifier_alert_residue.dag", "dag/gunbc/generated_artifact_merge_driver.dag", - "dag/gunbc/githooks_pre_push_emit.dag", + "dag/gunbc/githooks/githooks_pre_push_emit.dag", "dag/gunbc/heal_revalidation.dag", - "dag/gunbc/host_budget_source.dag", - "dag/gunbc/host_compile_pool.dag", - "dag/gunbc/host_network_diagnosis.dag", - "dag/gunbc/host_toolchain_components.dag", - "dag/gunbc/host_toolchain_ensure.dag", + "dag/gunbc/host/host_budget_source.dag", + "dag/gunbc/host/host_compile_pool.dag", + "dag/gunbc/host/host_network_diagnosis.dag", + "dag/gunbc/host/host_toolchain_components.dag", + "dag/gunbc/host/host_toolchain_ensure.dag", "dag/gunbc/legacy_test_behavior_disposition.dag", "dag/gunbc/live_deploy/operations.dag", "dag/gunbc/merge_admission_subject.dag", @@ -146,31 +146,31 @@ data prose_row_migration_scope: List = [ "dag/gunbc/publication_admission_delta.dag", "dag/gunbc/publication_policy.dag", "dag/gunbc/readback_independence.dag", - "dag/gunbc/roadmap_acceptance_history_carrier.dag", - "dag/gunbc/roadmap_acceptance_history_observation.dag", - "dag/gunbc/roadmap_altitude.dag", - "dag/gunbc/roadmap_dashboard_instance.dag", - "dag/gunbc/roadmap_dashboard_instance_apply.dag", - "dag/gunbc/roadmap_focus.dag", - "dag/gunbc/roadmap_forecast.dag", - "dag/gunbc/roadmap_identity.dag", - "dag/gunbc/roadmap_model.dag", - "dag/gunbc/roadmap_page.dag", - "dag/gunbc/roadmap_presentation.dag", - "dag/gunbc/roadmap_provider_events.dag", - "dag/gunbc/roadmap_publish.dag", - "dag/gunbc/roadmap_publish_observe.dag", - "dag/gunbc/roadmap_site_healthz_validate.dag", - "dag/gunbc/roadmap_site_surface_observe.dag", - "dag/gunbc/roadmap_style.dag", - "dag/gunbc/roadmap_validation_oracle.dag", - "dag/gunbc/roadmap_verification_receipt.dag", - "dag/gunbc/roadmap_verify.dag", - "dag/gunbc/roadmap_workflow_progress.dag", - "dag/gunbc/runner_activation.dag", + "dag/gunbc/roadmap/roadmap_acceptance_history_carrier.dag", + "dag/gunbc/roadmap/roadmap_acceptance_history_observation.dag", + "dag/gunbc/roadmap/roadmap_altitude.dag", + "dag/gunbc/roadmap/roadmap_dashboard_instance.dag", + "dag/gunbc/roadmap/roadmap_dashboard_instance_apply.dag", + "dag/gunbc/roadmap/roadmap_focus.dag", + "dag/gunbc/roadmap/roadmap_forecast.dag", + "dag/gunbc/roadmap/roadmap_identity.dag", + "dag/gunbc/roadmap/roadmap_model.dag", + "dag/gunbc/roadmap/roadmap_page.dag", + "dag/gunbc/roadmap/roadmap_presentation.dag", + "dag/gunbc/roadmap/roadmap_provider_events.dag", + "dag/gunbc/roadmap/roadmap_publish.dag", + "dag/gunbc/roadmap/roadmap_publish_observe.dag", + "dag/gunbc/roadmap/roadmap_site_healthz_validate.dag", + "dag/gunbc/roadmap/roadmap_site_surface_observe.dag", + "dag/gunbc/roadmap/roadmap_style.dag", + "dag/gunbc/roadmap/roadmap_validation_oracle.dag", + "dag/gunbc/roadmap/roadmap_verification_receipt.dag", + "dag/gunbc/roadmap/roadmap_verify.dag", + "dag/gunbc/roadmap/roadmap_workflow_progress.dag", + "dag/gunbc/runner/runner_activation.dag", "dag/gunbc/seed_growth_admission.dag", "dag/gunbc/shell_target_conformance.dag", - "dag/gunbc/stage0_cargo_manifest.dag", + "dag/gunbc/stage0/stage0_cargo_manifest.dag", "dag/gunbc/test_module_hygiene.dag", "dag/std/access.dag", "dag/std/authorization_profile.dag", diff --git a/dag/gunbc/repo_atlas_projection.dag b/dag/gunbc/repo/repo_atlas_projection.dag similarity index 100% rename from dag/gunbc/repo_atlas_projection.dag rename to dag/gunbc/repo/repo_atlas_projection.dag diff --git a/dag/gunbc/repo_identity.dag b/dag/gunbc/repo/repo_identity.dag similarity index 100% rename from dag/gunbc/repo_identity.dag rename to dag/gunbc/repo/repo_identity.dag diff --git a/dag/gunbc/repo_local_git_config.dag b/dag/gunbc/repo/repo_local_git_config.dag similarity index 99% rename from dag/gunbc/repo_local_git_config.dag rename to dag/gunbc/repo/repo_local_git_config.dag index 2062b810295..e4bc080c18a 100644 --- a/dag/gunbc/repo_local_git_config.dag +++ b/dag/gunbc/repo/repo_local_git_config.dag @@ -55,7 +55,7 @@ data generated_artifact_merge_driver_value: String = generated_artifact_merge_dr data core_hooks_path_key: String = "core.hooksPath" data core_hooks_path_value: String = ".githooks" -data repo_local_git_config_converge_entry: String = "dag/gunbc/repo_local_git_config.dag" +data repo_local_git_config_converge_entry: String = "dag/gunbc/repo/repo_local_git_config.dag" data repo_local_git_config_converge_function: String = "converge" data repo_local_git_config_lane2_followup_typed_readback_refusal: String = "🟡 dissolve-on: repo_local_git_config read-back — collapse absence / wrong value / read failure into RepoLocalGitConfigApplyReceipt \{ all_success, first_failure \} only; upgrade to typed refusals per charter (operator nonblocking 2026-08-01, crisp-bat-830 second-pass). Countable follow-up slice; not lane-2 PR boundary." diff --git a/dag/gunbc/repo_local_git_config_clone_bootstrap.dag b/dag/gunbc/repo/repo_local_git_config_clone_bootstrap.dag similarity index 97% rename from dag/gunbc/repo_local_git_config_clone_bootstrap.dag rename to dag/gunbc/repo/repo_local_git_config_clone_bootstrap.dag index 2db93cc50d0..87f6f5348c2 100644 --- a/dag/gunbc/repo_local_git_config_clone_bootstrap.dag +++ b/dag/gunbc/repo/repo_local_git_config_clone_bootstrap.dag @@ -32,7 +32,7 @@ fn repo_local_git_config_clone_bootstrap_enrolled_paths() -> List { "ci heal job (gunbc.ci_spec gunbc_ci_heal_repo_local_git_config_invoke — after release bin unpack, before first git merge)", "generated pre-commit hook (githooks_repo_local_git_config_emit reconcile_install_argv)", "generated pre-push hook (githooks_repo_local_git_config_emit reconcile_install_argv)", - "explicit per-clone: gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo_local_git_config.dag --function converge", + "explicit per-clone: gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/repo/repo_local_git_config.dag --function converge", ] } diff --git a/dag/gunbc/repo_ruleset.dag b/dag/gunbc/repo/repo_ruleset.dag similarity index 99% rename from dag/gunbc/repo_ruleset.dag rename to dag/gunbc/repo/repo_ruleset.dag index 59a26b44e2c..15a2548027e 100644 --- a/dag/gunbc/repo_ruleset.dag +++ b/dag/gunbc/repo/repo_ruleset.dag @@ -661,7 +661,7 @@ fn repo_ruleset_verify_at( } } -data repo_ruleset_converge_entry: String = "dag/gunbc/repo_ruleset.dag" +data repo_ruleset_converge_entry: String = "dag/gunbc/repo/repo_ruleset.dag" data repo_ruleset_converge_function: String = "converge" data repo_ruleset_verify_function: String = "verify" diff --git a/dag/gunbc/repo_self_build.dag b/dag/gunbc/repo/repo_self_build.dag similarity index 100% rename from dag/gunbc/repo_self_build.dag rename to dag/gunbc/repo/repo_self_build.dag diff --git a/dag/gunbc/roadmap_acceptance_event_history.jsonl b/dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl similarity index 96% rename from dag/gunbc/roadmap_acceptance_event_history.jsonl rename to dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl index 6b37d927c29..69b1017b714 100644 --- a/dag/gunbc/roadmap_acceptance_event_history.jsonl +++ b/dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl @@ -10,7 +10,7 @@ {"variant":"acceptance_recorded","receipt":{"node":"pderive-typesafe-nullary-reflection","criteria_digest":"dac83172a613e659","red_control":{"variant":"red_control_executed","witness_module":"v2.test.manual.coproduct_reflection_conformance","witness_fn":"witness_nullary_reflection_rejects_requested_a_with_context_b","executed_on":"2026-07-28"},"handback":{"variant":"handback_delivered","first_artifact":"src/v2/std/node_query.dag","further_artifacts":["src/v2/test/claim/manual/coproduct_reflection_conformance_test.dag","src/v1/stage0/src/coproduct_reflection.rs"]},"accepted_by":"operator","accepted_on":"2026-07-28"}} {"variant":"acceptance_recorded","receipt":{"node":"pderive-static-supplemental-contract","criteria_digest":"fa6378dabdb12432","red_control":{"variant":"red_control_executed","witness_module":"v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract","witness_fn":"nested_generic_swap_red_rejects_swapped_slot_requirements","executed_on":"2026-07-29"},"handback":{"variant":"handback_delivered","first_artifact":"dag/std/trait_derive_shape.dag","further_artifacts":["dag/extdeps/languages/rust/derive_contracts.dag","src/v2/test/claim/emit/trait_derive_supplemental_generic_bound_contract_test.dag"]},"accepted_by":"operator","accepted_on":"2026-07-29"}} {"variant":"acceptance_recorded","receipt":{"node":"v1-test-hygiene-producer-retirement","criteria_digest":"8f77a4b2e0ee3387","red_control":{"variant":"red_control_executed","witness_module":"test.claim.test_module_hygiene_hand_rust_equivalence_witness","witness_fn":"test_module_hygiene_equivalence_unparsable_refuse_discriminator_holds","executed_on":"2026-07-29"},"handback":{"variant":"handback_delivered","first_artifact":"dag/gunbc/test_module_hygiene.dag","further_artifacts":["dag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag","src/v1/stage0/src/cli_run/test_module_hygiene_bridge.rs"]},"accepted_by":"operator","accepted_on":"2026-07-29"}} -{"variant":"acceptance_recorded","receipt":{"node":"v1-interpreter-primitive-roster","criteria_digest":"581758f45921b40a","red_control":{"variant":"red_control_executed","witness_module":"test.claim.v1_interpreter_primitive_surface_witness_test","witness_fn":"shadow_detector_catches_a_planted_duplicate","executed_on":"2026-08-02"},"handback":{"variant":"handback_delivered","first_artifact":"dag/gunbc/v1_interpreter_primitive_surface.dag","further_artifacts":["dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag","dag/test/claim/primitive_identity_join_witness_test.dag","src/v1/stage0/src/v1_interpreter.rs"]},"accepted_by":"operator","accepted_on":"2026-08-02"}} +{"variant":"acceptance_recorded","receipt":{"node":"v1-interpreter-primitive-roster","criteria_digest":"581758f45921b40a","red_control":{"variant":"red_control_executed","witness_module":"test.claim.v1_interpreter_primitive_surface_witness_test","witness_fn":"shadow_detector_catches_a_planted_duplicate","executed_on":"2026-08-02"},"handback":{"variant":"handback_delivered","first_artifact":"dag/gunbc/v1/v1_interpreter_primitive_surface.dag","further_artifacts":["dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag","dag/test/claim/primitive_identity_join_witness_test.dag","src/v1/stage0/src/v1_interpreter.rs"]},"accepted_by":"operator","accepted_on":"2026-08-02"}} {"variant":"acceptance_recorded","receipt":{"node":"ladder-measurement-schema","criteria_digest":"74da4d8be7125c81","red_control":{"variant":"red_control_executed","witness_module":"test.claim.guarantee_measurement_witness_test","witness_fn":"duplicate_class_id_reds_uniqueness","executed_on":"2026-08-01"},"handback":{"variant":"handback_delivered","first_artifact":"dag/gunbc/guarantee_measurement.dag","further_artifacts":["dag/test/claim/guarantee_measurement_witness_test.dag"]},"accepted_by":"operator","accepted_on":"2026-08-01"}} {"variant":"acceptance_recorded","receipt":{"node":"v2-emitter-producer-provenance","criteria_digest":"f1c76111c83a0a60","red_control":{"variant":"red_control_executed","witness_module":"v2.test.claim.self_host.emitter_producer_provenance_witness_test","witness_fn":"witness_restored_binding_without_executed_receipt_does_not_authorize_reds","executed_on":"2026-08-02"},"handback":{"variant":"handback_delivered","first_artifact":"src/v2/compiler/self_host/frontier.dag","further_artifacts":["src/v2/test/claim/self_host/emitter_producer_provenance_witness_test.dag"]},"accepted_by":"operator","accepted_on":"2026-08-02"}} -{"variant":"acceptance_recorded","receipt":{"node":"v1-seed-honesty-decision","criteria_digest":"1717cfe258d9afe1","red_control":{"variant":"red_control_executed","witness_module":"test.claim.seed_honesty_discharge_unavailable_test","witness_fn":"seed_honesty_undecided_would_keep_closing_contract_red","executed_on":"2026-08-02"},"handback":{"variant":"handback_delivered","first_artifact":"src/v2/workflow/bootstrap.dag","further_artifacts":["dag/test/claim/seed_honesty_discharge_unavailable_test.dag","dag/gunbc/ci_layer_roots.dag"]},"accepted_by":"operator","accepted_on":"2026-08-02"}} +{"variant":"acceptance_recorded","receipt":{"node":"v1-seed-honesty-decision","criteria_digest":"1717cfe258d9afe1","red_control":{"variant":"red_control_executed","witness_module":"test.claim.seed_honesty_discharge_unavailable_test","witness_fn":"seed_honesty_undecided_would_keep_closing_contract_red","executed_on":"2026-08-02"},"handback":{"variant":"handback_delivered","first_artifact":"src/v2/workflow/bootstrap.dag","further_artifacts":["dag/test/claim/seed_honesty_discharge_unavailable_test.dag","dag/gunbc/ci/ci_layer_roots.dag"]},"accepted_by":"operator","accepted_on":"2026-08-02"}} diff --git a/dag/gunbc/roadmap_acceptance_history_carrier.dag b/dag/gunbc/roadmap/roadmap_acceptance_history_carrier.dag similarity index 97% rename from dag/gunbc/roadmap_acceptance_history_carrier.dag rename to dag/gunbc/roadmap/roadmap_acceptance_history_carrier.dag index 1dab343bd02..845327b430d 100644 --- a/dag/gunbc/roadmap_acceptance_history_carrier.dag +++ b/dag/gunbc/roadmap/roadmap_acceptance_history_carrier.dag @@ -8,7 +8,7 @@ import v2.std.collection { List } import v2.std.text { String } // Append-only JSONL carrier for roadmap acceptance events. gunbc.roadmap_authority loads current history from this file; gunbc.roadmap_acceptance_history_observation git.Core.Shows the same path at HEAD and merge-base and parses each revision independently. When the carrier is absent at merge-base (introduction on main), observation bootstraps prior_history from inline authority history via gunbc.roadmap_acceptance_history_projection. Authored seal count/digest in roadmap_authority.dag are deleted; prefix law is enforced by observed prior_history. -data roadmap_acceptance_event_history_carrier_repo_path: String = "dag/gunbc/roadmap_acceptance_event_history.jsonl" +data roadmap_acceptance_event_history_carrier_repo_path: String = "dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl" type RoadmapAcceptanceEventHistoryParse = RoadmapAcceptanceEventHistoryParsed { events: List } diff --git a/dag/gunbc/roadmap_acceptance_history_observation.dag b/dag/gunbc/roadmap/roadmap_acceptance_history_observation.dag similarity index 92% rename from dag/gunbc/roadmap_acceptance_history_observation.dag rename to dag/gunbc/roadmap/roadmap_acceptance_history_observation.dag index ea0087b4c98..f286008feb5 100644 --- a/dag/gunbc/roadmap_acceptance_history_observation.dag +++ b/dag/gunbc/roadmap/roadmap_acceptance_history_observation.dag @@ -35,9 +35,9 @@ data roadmap_acceptance_history_repository_path: String = "." data roadmap_acceptance_history_repository_path_note: String = "The repository this observation inspects. Declared rather than ambient, for the reason git.Inspect.MergeBase now requires it: an ambient repository makes a right answer and a wrong one indistinguishable, because two checkouts can hold refs that look identical." -data roadmap_acceptance_history_authority_repo_path: String = "dag/gunbc/roadmap_authority.dag" +data roadmap_acceptance_history_authority_repo_path: String = "dag/gunbc/roadmap/roadmap_authority.dag" -data roadmap_acceptance_history_prior_history_next_rung_trigger: String = "DISSOLVED: merge-base prior_history parses dag/gunbc/roadmap_acceptance_event_history.jsonl via gunbc.roadmap_acceptance_history_carrier when the carrier exists at merge-base; when absent (carrier introduction on main) the typed bootstrap projects inline authority history via gunbc.roadmap_acceptance_history_projection. A changed carrier without a valid merge-base observation refuses AcceptanceHistoryIntegrityRefusedPriorHistoryObservation — never prior_history = []. git_show_path_absent_at_ref substring-matches both git stderr shapes for path absent at ref (tree miss: does not exist in; worktree-present-but-not-in-commit: exists on disk, but not in) until extdeps.git carries a typed path-absent-at-ref disposition. Remaining dissolve-on: delete both seed bridges when a modeled revision-addressed carrier ingest lands." +data roadmap_acceptance_history_prior_history_next_rung_trigger: String = "DISSOLVED: merge-base prior_history parses dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl via gunbc.roadmap_acceptance_history_carrier when the carrier exists at merge-base; when absent (carrier introduction on main) the typed bootstrap projects inline authority history via gunbc.roadmap_acceptance_history_projection. A changed carrier without a valid merge-base observation refuses AcceptanceHistoryIntegrityRefusedPriorHistoryObservation — never prior_history = []. git_show_path_absent_at_ref substring-matches both git stderr shapes for path absent at ref (tree miss: does not exist in; worktree-present-but-not-in-commit: exists on disk, but not in) until extdeps.git carries a typed path-absent-at-ref disposition. Remaining dissolve-on: delete both seed bridges when a modeled revision-addressed carrier ingest lands." type RoadmapAcceptanceHistoryPriorObservation = PriorHistoryObserved { prior: List } diff --git a/dag/gunbc/roadmap_acceptance_history_projection.dag b/dag/gunbc/roadmap/roadmap_acceptance_history_projection.dag similarity index 56% rename from dag/gunbc/roadmap_acceptance_history_projection.dag rename to dag/gunbc/roadmap/roadmap_acceptance_history_projection.dag index 20fd0c65e2d..15e9beeb245 100644 --- a/dag/gunbc/roadmap_acceptance_history_projection.dag +++ b/dag/gunbc/roadmap/roadmap_acceptance_history_projection.dag @@ -6,7 +6,7 @@ import std.disposition { Disposition, RealizationDispatch, Scaffold } import v2.std.collection { List } import v2.std.text { String } -data roadmap_acceptance_history_projection_note: String = "One-time migration bootstrap: evaluate roadmap_acceptance_event_history from revision-addressed authority source text when dag/gunbc/roadmap_acceptance_event_history.jsonl is absent at merge-base. Steady-state prior_history parses the carrier via gunbc.roadmap_acceptance_history_carrier; this projection is the typed bridge only for carrier introduction on main. SEED OVERLAY HONESTY (review 48679): v1_compiler.cli_run project_roadmap_acceptance_event_history_from_authority_text overlays only dag/gunbc/roadmap_authority.dag from the passed merge-base text; every other dag/ and src/v2 module resolves from the HEAD worktree. If HEAD carries a schema-touching change to any roadmap_authority dependency, the bootstrap projection is evaluated against HEAD's transitive closure, not a fully revision-pinned tree. Bounded: this arm fires only when git_show_path_absent_at_ref admits carrier introduction at merge-base (this PR's one-time window); dissolve-on is roadmap_acceptance_history_projection_seed_scaffold → modeled revision-addressed carrier ingest." +data roadmap_acceptance_history_projection_note: String = "One-time migration bootstrap: evaluate roadmap_acceptance_event_history from revision-addressed authority source text when dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl is absent at merge-base. Steady-state prior_history parses the carrier via gunbc.roadmap_acceptance_history_carrier; this projection is the typed bridge only for carrier introduction on main. SEED OVERLAY HONESTY (review 48679): v1_compiler.cli_run project_roadmap_acceptance_event_history_from_authority_text overlays only dag/gunbc/roadmap/roadmap_authority.dag from the passed merge-base text; every other dag/ and src/v2 module resolves from the HEAD worktree. If HEAD carries a schema-touching change to any roadmap_authority dependency, the bootstrap projection is evaluated against HEAD's transitive closure, not a fully revision-pinned tree. Bounded: this arm fires only when git_show_path_absent_at_ref admits carrier introduction at merge-base (this PR's one-time window); dissolve-on is roadmap_acceptance_history_projection_seed_scaffold → modeled revision-addressed carrier ingest." type RoadmapAcceptanceHistoryProjection = RoadmapAcceptanceHistoryProjected { events: List } diff --git a/dag/gunbc/roadmap_altitude.dag b/dag/gunbc/roadmap/roadmap_altitude.dag similarity index 100% rename from dag/gunbc/roadmap_altitude.dag rename to dag/gunbc/roadmap/roadmap_altitude.dag diff --git a/dag/gunbc/roadmap_authority.dag b/dag/gunbc/roadmap/roadmap_authority.dag similarity index 99% rename from dag/gunbc/roadmap_authority.dag rename to dag/gunbc/roadmap/roadmap_authority.dag index 5f4bd794ddc..7464e862e5b 100644 --- a/dag/gunbc/roadmap_authority.dag +++ b/dag/gunbc/roadmap/roadmap_authority.dag @@ -365,7 +365,7 @@ fn v1_test_migration_execution_contract() -> WorkItemExecutionContract { ) } -data roadmap_receipt_continuity_execution_contract_note: String = "THE CLOSING CHECK FOR roadmap-receipt-continuity. Acceptance history is append-only JSONL carrier dag/gunbc/roadmap_acceptance_event_history.jsonl; roadmap_acceptance_receipts is a replay projection only. Authored seal count/digest are deleted. Merge-base prior_history parses carrier content via git.Core.Show — never prior_history = [] on a changed carrier (PriorHistoryRevisionEvaluationRequired dissolved). The hermetic contract plants each operator red control: deleted events, prefix law on non-empty observed prior, empty-prior bypass discriminant (proves the old authority-changed path would admit deletion), digest-omitted field mutation, wrong prior digest, revocation while live, duplicate revocations, exact revocation admit, criteria rewrite, git-refusal observation, and typed load/projection refusal chain. Live git-observed integrity executes in test.claim.roadmap_receipt_continuity_live_witness (ReadsLiveTree, bin_witness_wet_entries)." +data roadmap_receipt_continuity_execution_contract_note: String = "THE CLOSING CHECK FOR roadmap-receipt-continuity. Acceptance history is append-only JSONL carrier dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl; roadmap_acceptance_receipts is a replay projection only. Authored seal count/digest are deleted. Merge-base prior_history parses carrier content via git.Core.Show — never prior_history = [] on a changed carrier (PriorHistoryRevisionEvaluationRequired dissolved). The hermetic contract plants each operator red control: deleted events, prefix law on non-empty observed prior, empty-prior bypass discriminant (proves the old authority-changed path would admit deletion), digest-omitted field mutation, wrong prior digest, revocation while live, duplicate revocations, exact revocation admit, criteria rewrite, git-refusal observation, and typed load/projection refusal chain. Live git-observed integrity executes in test.claim.roadmap_receipt_continuity_live_witness (ReadsLiveTree, bin_witness_wet_entries)." fn roadmap_receipt_continuity_execution_contract() -> WorkItemExecutionContract { gunbc_claim_execution_contract( @@ -1587,7 +1587,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_C90239W2TBQX58KQHHPXE9S9VP", id: "v1-emitter-fixed-point", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Get the rest of the compiler to rebuild itself too", boundary: "With the generator already building itself, extend the same two-round test to everything else the compiler does — reading source, working out names, working out types, translating — until the whole thing generates its own source, that source is built, and the result behaves the same. Behaviour has to match; the bytes do not.", @@ -1602,7 +1602,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_3KTM8Q5VXB2NRJ7HDW9FZ0CPGA", id: "v1-rust-source-observation", owner: "self-host", - path: "dag/gunbc/stage0_rust_host_observation.dag", + path: "dag/gunbc/stage0/stage0_rust_host_observation.dag", t: fields( headline: "See the hand-written files as they actually are, from the host", boundary: "The set of tracked Rust files is read from the repository itself at a known revision, not transcribed. Reading it can fail, and when it does it says so rather than returning a shorter list.", @@ -1617,7 +1617,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_M5WCJ1GDZVJ67JXQN2NBPJKB58", id: "v1-honest-frontier", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Keep an honest list of what still depends on the old compiler", boundary: "Every module is either generated by the new compiler or explicitly kept on the old one with a reason and a plan to move. Two separate questions, kept separate: whether the list found every module, and whether every module it found has been decided. A complete list of undecided modules and a decided list that missed modules are different failures and are reported differently.", @@ -1647,7 +1647,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_X9RY6N9HJX29GHHGDRGP86T6NV", id: "v1-verification-ledger", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Prove old and new agree, by running them, not by waiting", boundary: "Run the whole test suite cold on both, compare compile results, check the self-rebuild, and record each family's outcome.", @@ -1662,7 +1662,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_FWSQ19QP41ARPXBM0HFW4MFXGG", id: "v1-ci-floor-cutover", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Switch the build over to the new compiler", boundary: "The real build runs on the new path, with cold comparisons against the old one first.", @@ -1677,7 +1677,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_HM8EEVB6DDD417CJ8RM79T4F3M", id: "v1-hand-queue-drain", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Work through the remaining hand-written files the products need", boundary: "Move the hand-written files the shipping tools still depend on. Anything that genuinely has to stay gets an explicit reason.", @@ -1694,7 +1694,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_0X0GRWB1KQ6KR0SAK1HDKEDGPR", id: "v1-test-migration", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Make sure deleting the old tests loses no coverage", boundary: "Every old test file removed has equivalent coverage that would actually catch the bug it was written for.", @@ -1711,7 +1711,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_HZJEM68DT207HQH449FPR3VZPA", id: "v1-seed-honesty-decision", owner: "operator", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Decide whether the trust-the-compiler check has to happen first", boundary: "A decision: does independently rebuilding with a different compiler have to happen before deletion? And first, make that check capable of failing.", @@ -1757,7 +1757,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_7QVX2K4M9NBTR6HDJ0FZ8SWCPE", id: "v1-interpreter-primitive-roster", owner: "self-host", - path: "dag/gunbc/v1_interpreter_primitive_surface.dag", + path: "dag/gunbc/v1/v1_interpreter_primitive_surface.dag", t: fields( headline: "Make the interpreter's primitive surface enumerable", boundary: "Every interpreter dispatch arm -- free call, method, guard-predicated bridge, native special and the one service carve-out -- has one interpreter-local identity, dispatch form and authored spelling, enumerable independently of semantic primitive identity. Adding or deleting an implementation arm without changing the roster refuses.", @@ -1772,7 +1772,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_5PWQ9J3XZM8TKB2NHR6VD0FCAS", id: "v1-interpreter-primitive-dispatch-authority", owner: "self-host", - path: "dag/gunbc/v1_interpreter_primitive_surface.dag", + path: "dag/gunbc/v1/v1_interpreter_primitive_surface.dag", t: fields( headline: "Let the model, not the Rust, decide what primitives exist", boundary: "Invert the roster. Today the Rust dispatch is the authority and the roster is derived from it; here the roster becomes the authority and the interpreter's local arm identity and spelling/form lookup are GENERATED from it, leaving hand Rust to supply only the handler bodies behind an exhaustive match. The semantic question of which primitive an arm realizes stays a separate join and does not move here.", @@ -1787,7 +1787,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_J4Q81A4BJ8TXN6ZE4481RMB3Y9", id: "v1-interpreter-quarantine", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Build the products with the old runner left out entirely", boundary: "A rehearsal: build without the old runner included at all, and run the products and the build both cold and warm.", @@ -1802,7 +1802,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_SSW55NRPT0931Q12PB8YQ3Q2BH", id: "v1-interpreter-delete", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Delete the old runner", boundary: "Delete it and everything now unreachable, in one change, once the rehearsal above holds. This is about the runner only — not the rest of the old code, and not hand-written Rust generally.", @@ -1817,7 +1817,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_NTQJM3ECTNN49NG2SSR9TNX2RX", id: "v1-products-v1-free", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Build and run every product without the old code present", boundary: "With the old runner gone and the hand-written queue worked through, the products build and run with the old directory absent. Anything that must stay gets an explicit reason.", @@ -1832,7 +1832,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_RSBHA36N72JKQ0NAVKJ5AV153R", id: "v1-zero-hand-maintained-rust", owner: "self-host", - path: "dag/gunbc/v1_deletion_plan.dag", + path: "dag/gunbc/v1/v1_deletion_plan.dag", t: fields( headline: "Get hand-written Rust in this repository down to zero", boundary: "Every Rust file we track is either generated from a description or deleted. Hand-maintaining Rust is a stage we are passing through, not where we stop.", @@ -2357,7 +2357,7 @@ fn declared_roadmap_nodes() -> List { identity: "rn_ANX7D5C8EBN0A41V05PHETTG9K", id: "instrument-rendered-control-coverage", owner: "instrument-motion", - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", t: fields( headline: "Derive interaction coverage from what is actually rendered", boundary: "Coverage of interactive controls is derived from the rendered control contracts rather than from a hand-listed set, so a control that exists on the page but in nobody's list is a counted gap rather than an invisible one.", @@ -2562,7 +2562,7 @@ fn roadmap_acceptance_event_history_load() -> RoadmapAcceptanceEventHistoryLoad load_roadmap_acceptance_event_history(path: roadmap_acceptance_event_history_carrier_repo_path) } -data roadmap_acceptance_history_note: String = "roadmap_acceptance_event_history is the single authority for acceptance facts, loaded from dag/gunbc/roadmap_acceptance_event_history.jsonl (append-only JSONL carrier). roadmap_acceptance_receipts projects the live receipt set by replaying recorded and revoked events only — never a second editable receipt list; LoadRefused is a typed RoadmapAcceptanceReceiptsProjectionRefused, never an empty receipt list. New acceptance appends AcceptanceRecorded to the carrier; withdrawal appends AcceptanceRevoked naming the exact prior receipt, a disposition, and audit fields. Authored seal count/digest are deleted: prefix law is enforced by gunbc.roadmap_acceptance_history_observation parsing merge-base carrier content via git.Core.Show — a changed carrier without valid merge-base parse refuses AcceptanceHistoryIntegrityRefusedPriorHistoryObservation, never prior_history = []." +data roadmap_acceptance_history_note: String = "roadmap_acceptance_event_history is the single authority for acceptance facts, loaded from dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl (append-only JSONL carrier). roadmap_acceptance_receipts projects the live receipt set by replaying recorded and revoked events only — never a second editable receipt list; LoadRefused is a typed RoadmapAcceptanceReceiptsProjectionRefused, never an empty receipt list. New acceptance appends AcceptanceRecorded to the carrier; withdrawal appends AcceptanceRevoked naming the exact prior receipt, a disposition, and audit fields. Authored seal count/digest are deleted: prefix law is enforced by gunbc.roadmap_acceptance_history_observation parsing merge-base carrier content via git.Core.Show — a changed carrier without valid merge-base parse refuses AcceptanceHistoryIntegrityRefusedPriorHistoryObservation, never prior_history = []." fn roadmap_acceptance_receipts_from_carrier_text(text: String) -> RoadmapAcceptanceReceiptsProjection { match load_roadmap_acceptance_event_history_from_carrier_text(text: text) { @@ -2842,7 +2842,7 @@ fn active_roadmap_edges_for_accepted(accepted: List) -> List List { [ HeadingBlock { level: H1, inlines: [TextInline { text: "gunbc — Roadmap" }] }, - ParagraphBlock { inlines: [TextInline { text: "`DESIGN.md` is the authority for why. This file projects the remaining committed deliverables and their dependency order from `dag/gunbc/roadmap_authority.dag`. The authority declares every node and records a typed acceptance receipt per accepted node; the active set is derived as declared minus validly accepted, so acceptance never deletes a row and this projection stays active-only. It carries no mutable pull-request, CI, session, or attempt state. Implementation evidence does not equal acceptance; a merged but unaccepted deliverable remains active." }] }, + ParagraphBlock { inlines: [TextInline { text: "`DESIGN.md` is the authority for why. This file projects the remaining committed deliverables and their dependency order from `dag/gunbc/roadmap/roadmap_authority.dag`. The authority declares every node and records a typed acceptance receipt per accepted node; the active set is derived as declared minus validly accepted, so acceptance never deletes a row and this projection stays active-only. It carries no mutable pull-request, CI, session, or attempt state. Implementation evidence does not equal acceptance; a merged but unaccepted deliverable remains active." }] }, ParagraphBlock { inlines: [TextInline { text: "Indented rows depend on the row above them. Some deliverables have additional cross-chain prerequisites represented by `RoadmapEdge` in the authority. Every active row requires explicit manual acceptance. Automatic admission from this refreshed authority is future work; the existing manual dispatch path remains live and outside this model slice. Ready may schedule only after every dependency is accepted; it never overrides a dependency or refusal. Parked plans remain reachable through the documentation graph but are not active roadmap rows." }] }, ParagraphBlock { inlines: [TextInline { text: "Parked context (non-dispatchable): [compiler algorithm survey](docs/plans/compiler-algorithm-survey-2026-07-04.md) · [dispatch maintain CC](docs/plans/dispatch-maintain-cc.md) · [eval bind proposal](docs/plans/eval-bind-node-eval-propose.md) · [interpreter memory chronicle](docs/plans/interpreter-memory-chronicle.md) · [node/subtree visibility grants](docs/plans/node-subtree-visibility-grants.md) · [non-fold residue catalogue](docs/plans/non-fold-irreducible-residue-catalogue.md) · [post-engine roadmap](docs/plans/post-engine-pr-roadmap.md) · [post-zero regen placement](docs/plans/post-zero-regen-gate-placement.md) · [syntactic sample audit](docs/plans/real-debt-syntactic-sample-audit.md) · [regen 31/32 reconciliation](docs/plans/regen-divergence-31-vs-32-reconciliation.md) · [roadmap spawner](docs/plans/roadmap-spawner.md) · [seed honesty discharge](docs/plans/seed-honesty-discharge-design.md) · [space lens minimal project](docs/plans/space-lens-minimal-project.md)." }] }, ] diff --git a/dag/gunbc/roadmap_belt.dag b/dag/gunbc/roadmap/roadmap_belt.dag similarity index 100% rename from dag/gunbc/roadmap_belt.dag rename to dag/gunbc/roadmap/roadmap_belt.dag diff --git a/dag/gunbc/roadmap_belt_actuate.dag b/dag/gunbc/roadmap/roadmap_belt_actuate.dag similarity index 100% rename from dag/gunbc/roadmap_belt_actuate.dag rename to dag/gunbc/roadmap/roadmap_belt_actuate.dag diff --git a/dag/gunbc/roadmap_closing_contract_authoring.dag b/dag/gunbc/roadmap/roadmap_closing_contract_authoring.dag similarity index 100% rename from dag/gunbc/roadmap_closing_contract_authoring.dag rename to dag/gunbc/roadmap/roadmap_closing_contract_authoring.dag diff --git a/dag/gunbc/roadmap_component.dag b/dag/gunbc/roadmap/roadmap_component.dag similarity index 100% rename from dag/gunbc/roadmap_component.dag rename to dag/gunbc/roadmap/roadmap_component.dag diff --git a/dag/gunbc/roadmap_dashboard_instance.dag b/dag/gunbc/roadmap/roadmap_dashboard_instance.dag similarity index 99% rename from dag/gunbc/roadmap_dashboard_instance.dag rename to dag/gunbc/roadmap/roadmap_dashboard_instance.dag index 091e24a4a66..a952524e896 100644 --- a/dag/gunbc/roadmap_dashboard_instance.dag +++ b/dag/gunbc/roadmap/roadmap_dashboard_instance.dag @@ -229,7 +229,7 @@ fn dashboard_instance_serve_argv(instance: HostDashboardInstance) -> List TmuxSessionScope? { fn carrier_paths_label(carriers: List, repo: String) -> String { if count(carriers) == 0 { - concat("dag/gunbc/roadmap_dispatch_actuator.dag (repo=", concat(repo, ")")) + concat("dag/gunbc/roadmap/roadmap_dispatch_actuator.dag (repo=", concat(repo, ")")) } else { join(map(carriers, p => p.path), " · ") } diff --git a/dag/gunbc/roadmap_dispatch_environment.dag b/dag/gunbc/roadmap/roadmap_dispatch_environment.dag similarity index 100% rename from dag/gunbc/roadmap_dispatch_environment.dag rename to dag/gunbc/roadmap/roadmap_dispatch_environment.dag diff --git a/dag/gunbc/roadmap_document.dag b/dag/gunbc/roadmap/roadmap_document.dag similarity index 100% rename from dag/gunbc/roadmap_document.dag rename to dag/gunbc/roadmap/roadmap_document.dag diff --git a/dag/gunbc/roadmap_emit.dag b/dag/gunbc/roadmap/roadmap_emit.dag similarity index 100% rename from dag/gunbc/roadmap_emit.dag rename to dag/gunbc/roadmap/roadmap_emit.dag diff --git a/dag/gunbc/roadmap_execution_contract.dag b/dag/gunbc/roadmap/roadmap_execution_contract.dag similarity index 99% rename from dag/gunbc/roadmap_execution_contract.dag rename to dag/gunbc/roadmap/roadmap_execution_contract.dag index ecd4ebc8b89..0ff465f3c05 100644 --- a/dag/gunbc/roadmap_execution_contract.dag +++ b/dag/gunbc/roadmap/roadmap_execution_contract.dag @@ -216,7 +216,7 @@ fn gunbc_claim_execution_contract( data closing_contract_authoring_note: String = "ONE PARAMETERIZED KIND, NOT ONE META-WITNESS PER TARGET. gunbc.roadmap_authority closing_contract_task_naming_correction_note recorded the gap this closes: a derived closing-contract task was itself built with ExecutionContractUnspecified, so dispatch refused the very row whose job is to supply a contract, and the belt could not run the frontier it computes. The validation is parameterized by the TARGET node id and its oracle is a single fixed entry point, so adding a target costs no new declaration anywhere -- which is what the note asked for instead of ten bespoke meta-witnesses.\n\nThe target travels as `--arg target=` rather than being baked into a per-target function name, because a function name per target is exactly the hand-maintained roster the derivation exists to avoid: the frontier changes whenever a node is accepted or bound, and a roster of entry points would have to be edited in step with it.\n\nWHAT THE PREDICATE DECIDES AND WHAT IT DOES NOT is stated at gunbc.roadmap_closing_contract_authoring closing_contract_authoring_predicate_note. It is not the whole of the note's wish list, and the boundary is declared there rather than implied by a green." -data closing_contract_authoring_entry: FilePath = "dag/gunbc/roadmap_closing_contract_authoring.dag" as FilePath +data closing_contract_authoring_entry: FilePath = "dag/gunbc/roadmap/roadmap_closing_contract_authoring.dag" as FilePath data closing_contract_authoring_function: NonEmptyStr = "closing_contract_authored" as NonEmptyStr diff --git a/dag/gunbc/roadmap_focus.dag b/dag/gunbc/roadmap/roadmap_focus.dag similarity index 98% rename from dag/gunbc/roadmap_focus.dag rename to dag/gunbc/roadmap/roadmap_focus.dag index 04d07608690..acdac9f2422 100644 --- a/dag/gunbc/roadmap_focus.dag +++ b/dag/gunbc/roadmap/roadmap_focus.dag @@ -192,7 +192,7 @@ fn focus_notice( label, ".** ", to_string(focus_hidden_node_count(focus: focus, nodes: nodes, edges: edges)), - " active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap_authority.dag` to restore the full page.", + " active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap/roadmap_authority.dag` to restore the full page.", focus_pulled_in_summary(focus: focus, nodes: nodes, edges: edges), " Hidden lanes remain readable through their carriers: ", focus_hidden_carrier_links(focus: focus, nodes: nodes, edges: edges), diff --git a/dag/gunbc/roadmap_forecast.dag b/dag/gunbc/roadmap/roadmap_forecast.dag similarity index 100% rename from dag/gunbc/roadmap_forecast.dag rename to dag/gunbc/roadmap/roadmap_forecast.dag diff --git a/dag/gunbc/roadmap_identity.dag b/dag/gunbc/roadmap/roadmap_identity.dag similarity index 100% rename from dag/gunbc/roadmap_identity.dag rename to dag/gunbc/roadmap/roadmap_identity.dag diff --git a/dag/gunbc/roadmap_instrument_motion.dag b/dag/gunbc/roadmap/roadmap_instrument_motion.dag similarity index 100% rename from dag/gunbc/roadmap_instrument_motion.dag rename to dag/gunbc/roadmap/roadmap_instrument_motion.dag diff --git a/dag/gunbc/roadmap_instrument_sandbox.dag b/dag/gunbc/roadmap/roadmap_instrument_sandbox.dag similarity index 100% rename from dag/gunbc/roadmap_instrument_sandbox.dag rename to dag/gunbc/roadmap/roadmap_instrument_sandbox.dag diff --git a/dag/gunbc/roadmap_instrument_tuner.dag b/dag/gunbc/roadmap/roadmap_instrument_tuner.dag similarity index 100% rename from dag/gunbc/roadmap_instrument_tuner.dag rename to dag/gunbc/roadmap/roadmap_instrument_tuner.dag diff --git a/dag/gunbc/roadmap_interaction.dag b/dag/gunbc/roadmap/roadmap_interaction.dag similarity index 100% rename from dag/gunbc/roadmap_interaction.dag rename to dag/gunbc/roadmap/roadmap_interaction.dag diff --git a/dag/gunbc/roadmap_model.dag b/dag/gunbc/roadmap/roadmap_model.dag similarity index 100% rename from dag/gunbc/roadmap_model.dag rename to dag/gunbc/roadmap/roadmap_model.dag diff --git a/dag/gunbc/roadmap_page.dag b/dag/gunbc/roadmap/roadmap_page.dag similarity index 100% rename from dag/gunbc/roadmap_page.dag rename to dag/gunbc/roadmap/roadmap_page.dag diff --git a/dag/gunbc/roadmap_presentation.dag b/dag/gunbc/roadmap/roadmap_presentation.dag similarity index 100% rename from dag/gunbc/roadmap_presentation.dag rename to dag/gunbc/roadmap/roadmap_presentation.dag diff --git a/dag/gunbc/roadmap_program_view.dag b/dag/gunbc/roadmap/roadmap_program_view.dag similarity index 100% rename from dag/gunbc/roadmap_program_view.dag rename to dag/gunbc/roadmap/roadmap_program_view.dag diff --git a/dag/gunbc/roadmap_provider_events.dag b/dag/gunbc/roadmap/roadmap_provider_events.dag similarity index 100% rename from dag/gunbc/roadmap_provider_events.dag rename to dag/gunbc/roadmap/roadmap_provider_events.dag diff --git a/dag/gunbc/roadmap_publish.dag b/dag/gunbc/roadmap/roadmap_publish.dag similarity index 100% rename from dag/gunbc/roadmap_publish.dag rename to dag/gunbc/roadmap/roadmap_publish.dag diff --git a/dag/gunbc/roadmap_publish_observe.dag b/dag/gunbc/roadmap/roadmap_publish_observe.dag similarity index 100% rename from dag/gunbc/roadmap_publish_observe.dag rename to dag/gunbc/roadmap/roadmap_publish_observe.dag diff --git a/dag/gunbc/roadmap_repo_atlas_sandbox.dag b/dag/gunbc/roadmap/roadmap_repo_atlas_sandbox.dag similarity index 100% rename from dag/gunbc/roadmap_repo_atlas_sandbox.dag rename to dag/gunbc/roadmap/roadmap_repo_atlas_sandbox.dag diff --git a/dag/gunbc/roadmap_sandbox.dag b/dag/gunbc/roadmap/roadmap_sandbox.dag similarity index 100% rename from dag/gunbc/roadmap_sandbox.dag rename to dag/gunbc/roadmap/roadmap_sandbox.dag diff --git a/dag/gunbc/roadmap_serve.dag b/dag/gunbc/roadmap/roadmap_serve.dag similarity index 100% rename from dag/gunbc/roadmap_serve.dag rename to dag/gunbc/roadmap/roadmap_serve.dag diff --git a/dag/gunbc/roadmap_site_healthz_validate.dag b/dag/gunbc/roadmap/roadmap_site_healthz_validate.dag similarity index 100% rename from dag/gunbc/roadmap_site_healthz_validate.dag rename to dag/gunbc/roadmap/roadmap_site_healthz_validate.dag diff --git a/dag/gunbc/roadmap_site_surface_expect.dag b/dag/gunbc/roadmap/roadmap_site_surface_expect.dag similarity index 100% rename from dag/gunbc/roadmap_site_surface_expect.dag rename to dag/gunbc/roadmap/roadmap_site_surface_expect.dag diff --git a/dag/gunbc/roadmap_site_surface_observe.dag b/dag/gunbc/roadmap/roadmap_site_surface_observe.dag similarity index 100% rename from dag/gunbc/roadmap_site_surface_observe.dag rename to dag/gunbc/roadmap/roadmap_site_surface_observe.dag diff --git a/dag/gunbc/roadmap_site_surface_render.dag b/dag/gunbc/roadmap/roadmap_site_surface_render.dag similarity index 100% rename from dag/gunbc/roadmap_site_surface_render.dag rename to dag/gunbc/roadmap/roadmap_site_surface_render.dag diff --git a/dag/gunbc/roadmap_site_surface_types.dag b/dag/gunbc/roadmap/roadmap_site_surface_types.dag similarity index 100% rename from dag/gunbc/roadmap_site_surface_types.dag rename to dag/gunbc/roadmap/roadmap_site_surface_types.dag diff --git a/dag/gunbc/roadmap_site_surface_witness.dag b/dag/gunbc/roadmap/roadmap_site_surface_witness.dag similarity index 100% rename from dag/gunbc/roadmap_site_surface_witness.dag rename to dag/gunbc/roadmap/roadmap_site_surface_witness.dag diff --git a/dag/gunbc/roadmap_spawner.dag b/dag/gunbc/roadmap/roadmap_spawner.dag similarity index 100% rename from dag/gunbc/roadmap_spawner.dag rename to dag/gunbc/roadmap/roadmap_spawner.dag diff --git a/dag/gunbc/roadmap_static_site.dag b/dag/gunbc/roadmap/roadmap_static_site.dag similarity index 100% rename from dag/gunbc/roadmap_static_site.dag rename to dag/gunbc/roadmap/roadmap_static_site.dag diff --git a/dag/gunbc/roadmap_status.dag b/dag/gunbc/roadmap/roadmap_status.dag similarity index 100% rename from dag/gunbc/roadmap_status.dag rename to dag/gunbc/roadmap/roadmap_status.dag diff --git a/dag/gunbc/roadmap_style.dag b/dag/gunbc/roadmap/roadmap_style.dag similarity index 100% rename from dag/gunbc/roadmap_style.dag rename to dag/gunbc/roadmap/roadmap_style.dag diff --git a/dag/gunbc/roadmap_validation_oracle.dag b/dag/gunbc/roadmap/roadmap_validation_oracle.dag similarity index 100% rename from dag/gunbc/roadmap_validation_oracle.dag rename to dag/gunbc/roadmap/roadmap_validation_oracle.dag diff --git a/dag/gunbc/roadmap_verification_receipt.dag b/dag/gunbc/roadmap/roadmap_verification_receipt.dag similarity index 100% rename from dag/gunbc/roadmap_verification_receipt.dag rename to dag/gunbc/roadmap/roadmap_verification_receipt.dag diff --git a/dag/gunbc/roadmap_verify.dag b/dag/gunbc/roadmap/roadmap_verify.dag similarity index 100% rename from dag/gunbc/roadmap_verify.dag rename to dag/gunbc/roadmap/roadmap_verify.dag diff --git a/dag/gunbc/roadmap_workflow_command.dag b/dag/gunbc/roadmap/roadmap_workflow_command.dag similarity index 100% rename from dag/gunbc/roadmap_workflow_command.dag rename to dag/gunbc/roadmap/roadmap_workflow_command.dag diff --git a/dag/gunbc/roadmap_workflow_progress.dag b/dag/gunbc/roadmap/roadmap_workflow_progress.dag similarity index 100% rename from dag/gunbc/roadmap_workflow_progress.dag rename to dag/gunbc/roadmap/roadmap_workflow_progress.dag diff --git a/dag/gunbc/roadmap_workflow_stage.dag b/dag/gunbc/roadmap/roadmap_workflow_stage.dag similarity index 100% rename from dag/gunbc/roadmap_workflow_stage.dag rename to dag/gunbc/roadmap/roadmap_workflow_stage.dag diff --git a/dag/gunbc/roster_registry.dag b/dag/gunbc/roster_registry.dag index 9cd63c9b1a1..f4981a58db4 100644 --- a/dag/gunbc/roster_registry.dag +++ b/dag/gunbc/roster_registry.dag @@ -229,7 +229,7 @@ data roster_registry: List = [ unit_kind: "hand-retained stage0 seed file basename (HAND_MAINTAINED_STAGE0_FILES)", membership: DeclaredFrontier { reason: "ENROLLED 2026-08-20, and it arrived here sideways: it was found while repairing the neighbouring generated_stage0_files registration, which #8674 root-cut away entirely, so the roster this one was the sibling OF no longer exists. What survives is the gap roster_registry_visibility_note warns about — this roster was in NO registration at all, so nothing in the registry could see it, and no citation resolver could either: an unregistered list is invisible to the check that would have caught a stale one. Its projection into the seed is the HAND_MAINTAINED_STAGE0_FILES const in src/v1/stage0/src/bootstrap_stage0_crate_layout_generated.rs. It HAS a live producer (gunbc.stage0_crate_layout_emit, actuated by dag/tools/generated_artifact_gate.dag main_wet, drift-gated through gunbc.generated_artifact Stage0CrateLayoutGeneratedRsArtifact), so the Rust const is genuinely derived; but the DECLARATION registered here is the .dag membership itself, and that is a fold over three hand-asserted row lists — seed_retained_intrinsic_registrations, seed_retained_scaffold_registrations and wet_actuator_generated_registrations. A fold over asserted rows is FRONTIER, not DERIVED: registering it ByDerivation from its own projection function would be the self-referential tautology this taxonomy exists to expose. Per-row reasons live beside the rows (pre_existing_hand_retained_registration_backfill_note, seed_retained_quarantine_scaffold_stage0_files_note, data_initializer_identity_seed_retained_note, wet_actuator_generated_files_note)", - dissolution: unbound_dissolution(description: "per row: a basename's .dag authority self-emits and the row leaves this claim, which moves it into the derived generated population by complement (gunbc.stage0_rust_source_lifecycle_scaffold derived_generated_stage0_repo_paths) rather than onto a second roster; roster-wide, the list empties at ZeroHandMaintainedRust (V1FinishLine, dag/gunbc/v1_deletion_plan.dag) and this registration deletes with it") + dissolution: unbound_dissolution(description: "per row: a basename's .dag authority self-emits and the row leaves this claim, which moves it into the derived generated population by complement (gunbc.stage0_rust_source_lifecycle_scaffold derived_generated_stage0_repo_paths) rather than onto a second roster; roster-wide, the list empties at ZeroHandMaintainedRust (V1FinishLine, dag/gunbc/v1/v1_deletion_plan.dag) and this registration deletes with it") } }, RosterRegistration { @@ -253,7 +253,7 @@ data roster_registry: List = [ unit_kind: "tracked .rs path outside derived authority joins (file-grain residue)", membership: DeclaredFrontier { reason: "file-grain paths tracked on disk that no authority join classifies yet — bootstrap copies, hand-retained harness kernels, module_path_index files, frontier layout lag, and authority contradictions (stage0_core lib.rs vs partition rows); each row carries reason and dissolve_on. Cargo [[bin]] paths are host-derived (gunbc.stage0_cargo_manifest), not residue rows", - dissolution: unbound_dissolution(description: "per row: the path derives from the observed generated population (gunbc.stage0_rust_source_lifecycle_scaffold derived_generated_stage0_repo_paths), hand_maintained_stage0_filenames, stage0_cargo_bin_paths_observed (PR B host boundary), or stage0_partition_crate_rows and the row deletes; roster-wide, rust_source_host_observation_note host boundary supplies path evidence and promotes the scaffold to ZeroHandMaintainedRust acceptance (V1FinishLine, dag/gunbc/v1_deletion_plan.dag)") + dissolution: unbound_dissolution(description: "per row: the path derives from the observed generated population (gunbc.stage0_rust_source_lifecycle_scaffold derived_generated_stage0_repo_paths), hand_maintained_stage0_filenames, stage0_cargo_bin_paths_observed (PR B host boundary), or stage0_partition_crate_rows and the row deletes; roster-wide, rust_source_host_observation_note host boundary supplies path evidence and promotes the scaffold to ZeroHandMaintainedRust acceptance (V1FinishLine, dag/gunbc/v1/v1_deletion_plan.dag)") } }, RosterRegistration { diff --git a/dag/gunbc/runner_activation.dag b/dag/gunbc/runner/runner_activation.dag similarity index 100% rename from dag/gunbc/runner_activation.dag rename to dag/gunbc/runner/runner_activation.dag diff --git a/dag/gunbc/runner_broker_progress_watchdog.dag b/dag/gunbc/runner/runner_broker_progress_watchdog.dag similarity index 100% rename from dag/gunbc/runner_broker_progress_watchdog.dag rename to dag/gunbc/runner/runner_broker_progress_watchdog.dag diff --git a/dag/gunbc/runner_capacity_operator_access.dag b/dag/gunbc/runner/runner_capacity_operator_access.dag similarity index 100% rename from dag/gunbc/runner_capacity_operator_access.dag rename to dag/gunbc/runner/runner_capacity_operator_access.dag diff --git a/dag/gunbc/runner_capacity_plan.dag b/dag/gunbc/runner/runner_capacity_plan.dag similarity index 100% rename from dag/gunbc/runner_capacity_plan.dag rename to dag/gunbc/runner/runner_capacity_plan.dag diff --git a/dag/gunbc/runner_capacity_realize.dag b/dag/gunbc/runner/runner_capacity_realize.dag similarity index 100% rename from dag/gunbc/runner_capacity_realize.dag rename to dag/gunbc/runner/runner_capacity_realize.dag diff --git a/dag/gunbc/runner_connectivity_recovery.dag b/dag/gunbc/runner/runner_connectivity_recovery.dag similarity index 100% rename from dag/gunbc/runner_connectivity_recovery.dag rename to dag/gunbc/runner/runner_connectivity_recovery.dag diff --git a/dag/gunbc/runner_connectivity_repair_plan.dag b/dag/gunbc/runner/runner_connectivity_repair_plan.dag similarity index 100% rename from dag/gunbc/runner_connectivity_repair_plan.dag rename to dag/gunbc/runner/runner_connectivity_repair_plan.dag diff --git a/dag/gunbc/runner_deploy_emit.dag b/dag/gunbc/runner/runner_deploy_emit.dag similarity index 100% rename from dag/gunbc/runner_deploy_emit.dag rename to dag/gunbc/runner/runner_deploy_emit.dag diff --git a/dag/gunbc/runner_disk_reclaim.dag b/dag/gunbc/runner/runner_disk_reclaim.dag similarity index 100% rename from dag/gunbc/runner_disk_reclaim.dag rename to dag/gunbc/runner/runner_disk_reclaim.dag diff --git a/dag/gunbc/runner_host_deploy.dag b/dag/gunbc/runner/runner_host_deploy.dag similarity index 100% rename from dag/gunbc/runner_host_deploy.dag rename to dag/gunbc/runner/runner_host_deploy.dag diff --git a/dag/gunbc/runner_host_grants.dag b/dag/gunbc/runner/runner_host_grants.dag similarity index 98% rename from dag/gunbc/runner_host_grants.dag rename to dag/gunbc/runner/runner_host_grants.dag index 01c98a8990f..a487ad843ef 100644 --- a/dag/gunbc/runner_host_grants.dag +++ b/dag/gunbc/runner/runner_host_grants.dag @@ -97,7 +97,7 @@ fn runner_host_privileged_operations(deploy: RunnerHostDeploy) -> List String { join([ - "# GENERATED from dag/gunbc/runner_host_grants.dag ", + "# GENERATED from dag/gunbc/runner/runner_host_grants.dag ", entry_point as String, " — do not hand-edit\n" ], "") @@ -119,7 +119,7 @@ fn runner_host_sudoers_content(deploy: RunnerHostDeploy, entry_point: NonEmptySt // unreproducible from the repository -- exactly the hand-authored host state this module exists to // avoid. Run it with: // gunbc run --source-root dag --source-root src/v2 \ -// --entry dag/gunbc/runner_host_grants.dag --function srv3_runner_host_sudoers +// --entry dag/gunbc/runner/runner_host_grants.dag --function srv3_runner_host_sudoers fn srv3_runner_host_sudoers() -> String { runner_host_sudoers_content( deploy: srv3_runner_host_deploy, diff --git a/dag/gunbc/runner_incarnation.dag b/dag/gunbc/runner/runner_incarnation.dag similarity index 100% rename from dag/gunbc/runner_incarnation.dag rename to dag/gunbc/runner/runner_incarnation.dag diff --git a/dag/gunbc/runner_lifecycle.dag b/dag/gunbc/runner/runner_lifecycle.dag similarity index 100% rename from dag/gunbc/runner_lifecycle.dag rename to dag/gunbc/runner/runner_lifecycle.dag diff --git a/dag/gunbc/runner_lifecycle_realize.dag b/dag/gunbc/runner/runner_lifecycle_realize.dag similarity index 100% rename from dag/gunbc/runner_lifecycle_realize.dag rename to dag/gunbc/runner/runner_lifecycle_realize.dag diff --git a/dag/gunbc/runner_local_state.dag b/dag/gunbc/runner/runner_local_state.dag similarity index 100% rename from dag/gunbc/runner_local_state.dag rename to dag/gunbc/runner/runner_local_state.dag diff --git a/dag/gunbc/runner_service_activation.dag b/dag/gunbc/runner/runner_service_activation.dag similarity index 100% rename from dag/gunbc/runner_service_activation.dag rename to dag/gunbc/runner/runner_service_activation.dag diff --git a/dag/gunbc/runner_shape_census.dag b/dag/gunbc/runner/runner_shape_census.dag similarity index 100% rename from dag/gunbc/runner_shape_census.dag rename to dag/gunbc/runner/runner_shape_census.dag diff --git a/dag/gunbc/runner_slot_allocation.dag b/dag/gunbc/runner/runner_slot_allocation.dag similarity index 100% rename from dag/gunbc/runner_slot_allocation.dag rename to dag/gunbc/runner/runner_slot_allocation.dag diff --git a/dag/gunbc/runner_slot_enforcement.dag b/dag/gunbc/runner/runner_slot_enforcement.dag similarity index 100% rename from dag/gunbc/runner_slot_enforcement.dag rename to dag/gunbc/runner/runner_slot_enforcement.dag diff --git a/dag/gunbc/runner_slot_provision.dag b/dag/gunbc/runner/runner_slot_provision.dag similarity index 100% rename from dag/gunbc/runner_slot_provision.dag rename to dag/gunbc/runner/runner_slot_provision.dag diff --git a/dag/gunbc/runner_spec_from_offer.dag b/dag/gunbc/runner/runner_spec_from_offer.dag similarity index 100% rename from dag/gunbc/runner_spec_from_offer.dag rename to dag/gunbc/runner/runner_spec_from_offer.dag diff --git a/dag/gunbc/runner_unit.dag b/dag/gunbc/runner/runner_unit.dag similarity index 100% rename from dag/gunbc/runner_unit.dag rename to dag/gunbc/runner/runner_unit.dag diff --git a/dag/gunbc/runner_unit_file.dag b/dag/gunbc/runner/runner_unit_file.dag similarity index 100% rename from dag/gunbc/runner_unit_file.dag rename to dag/gunbc/runner/runner_unit_file.dag diff --git a/dag/gunbc/runner_unit_live_read.dag b/dag/gunbc/runner/runner_unit_live_read.dag similarity index 100% rename from dag/gunbc/runner_unit_live_read.dag rename to dag/gunbc/runner/runner_unit_live_read.dag diff --git a/dag/gunbc/served_surface_browser_observation.dag b/dag/gunbc/served_surface_browser_observation.dag index 3be61d6f010..08149e62ea8 100644 --- a/dag/gunbc/served_surface_browser_observation.dag +++ b/dag/gunbc/served_surface_browser_observation.dag @@ -250,7 +250,7 @@ data playwright_chromium_151_linux_arm64_headless_navigation_run: PlaywrightChro requested_url: local_http_url(locator: "127.0.0.1:43822/refused" as NonEmptyStr), origin: LocalSyntheticHarness, screenshot: ScreenshotArtifact { - path: "dag/test/fixtures/browser/chromium_151_connection_refused.png" as BinaryFilePath, + path: "dag/test/fixture/browser/chromium_151_connection_refused.png" as BinaryFilePath, digest: sha256_digest(hex: "637bf51bb5163ec58e6f325d1ed304bfa3618940ac75cb493ddd81d4895b29d3" as NonEmptyStr), bytes: byte_size(19520), }, @@ -260,7 +260,7 @@ data playwright_chromium_151_linux_arm64_headless_navigation_run: PlaywrightChro requested_url: local_http_url(locator: "127.0.0.1:43821/empty" as NonEmptyStr), origin: LocalSyntheticHarness, screenshot: ScreenshotArtifact { - path: "dag/test/fixtures/browser/chromium_151_empty_502.png" as BinaryFilePath, + path: "dag/test/fixture/browser/chromium_151_empty_502.png" as BinaryFilePath, digest: sha256_digest(hex: "f8a0b51701f18c0ff3ea22825103e5016fe68e69c7eca1190ed8162c05df22c6" as NonEmptyStr), bytes: byte_size(14089), }, @@ -270,7 +270,7 @@ data playwright_chromium_151_linux_arm64_headless_navigation_run: PlaywrightChro requested_url: local_http_url(locator: "127.0.0.1:43821/body" as NonEmptyStr), origin: LocalSyntheticHarness, screenshot: ScreenshotArtifact { - path: "dag/test/fixtures/browser/chromium_151_bodied_502.png" as BinaryFilePath, + path: "dag/test/fixture/browser/chromium_151_bodied_502.png" as BinaryFilePath, digest: sha256_digest(hex: "165dea20b5ecdaa9a864ff11c3924e9e6d3bbd956fa94f6b7827d948acc5bf71" as NonEmptyStr), bytes: byte_size(6337), }, diff --git a/dag/gunbc/srv3_actuate_shell_paths.dag b/dag/gunbc/srv3/srv3_actuate_shell_paths.dag similarity index 100% rename from dag/gunbc/srv3_actuate_shell_paths.dag rename to dag/gunbc/srv3/srv3_actuate_shell_paths.dag diff --git a/dag/gunbc/srv3_bmc_credential_resolve.dag b/dag/gunbc/srv3/srv3_bmc_credential_resolve.dag similarity index 100% rename from dag/gunbc/srv3_bmc_credential_resolve.dag rename to dag/gunbc/srv3/srv3_bmc_credential_resolve.dag diff --git a/dag/gunbc/srv3_boot_once_cd.dag b/dag/gunbc/srv3/srv3_boot_once_cd.dag similarity index 100% rename from dag/gunbc/srv3_boot_once_cd.dag rename to dag/gunbc/srv3/srv3_boot_once_cd.dag diff --git a/dag/gunbc/srv3_host_effect_apply.dag b/dag/gunbc/srv3/srv3_host_effect_apply.dag similarity index 100% rename from dag/gunbc/srv3_host_effect_apply.dag rename to dag/gunbc/srv3/srv3_host_effect_apply.dag diff --git a/dag/gunbc/srv3_install_media_fetch.dag b/dag/gunbc/srv3/srv3_install_media_fetch.dag similarity index 97% rename from dag/gunbc/srv3_install_media_fetch.dag rename to dag/gunbc/srv3/srv3_install_media_fetch.dag index 64cb3018b7b..6edbf2d97f6 100644 --- a/dag/gunbc/srv3_install_media_fetch.dag +++ b/dag/gunbc/srv3/srv3_install_media_fetch.dag @@ -35,7 +35,7 @@ data gunbc_srv3_install_media_fetch_scope_disposition: Disposition = Terminal { } data srv3_install_media_fetch_shell_runner_scaffold: Disposition = Terminal { - reason: "srv3_install_media_fetch() routes through host_effect_apply to install_media_fetch_reconcile() in-process (TypedReconcileOnHost cell, dag/gunbc/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" + reason: "srv3_install_media_fetch() routes through host_effect_apply to install_media_fetch_reconcile() in-process (TypedReconcileOnHost cell, dag/gunbc/host/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" } data srv3_ubuntu_install_media_install_path: NonEmptyStr = ubuntu_install_media_install_path( diff --git a/dag/gunbc/srv3_nbd_proxy_serve_intent.dag b/dag/gunbc/srv3/srv3_nbd_proxy_serve_intent.dag similarity index 100% rename from dag/gunbc/srv3_nbd_proxy_serve_intent.dag rename to dag/gunbc/srv3/srv3_nbd_proxy_serve_intent.dag diff --git a/dag/gunbc/srv3_os_install_actuate.dag b/dag/gunbc/srv3/srv3_os_install_actuate.dag similarity index 100% rename from dag/gunbc/srv3_os_install_actuate.dag rename to dag/gunbc/srv3/srv3_os_install_actuate.dag diff --git a/dag/gunbc/srv3_os_install_actuate_scope.dag b/dag/gunbc/srv3/srv3_os_install_actuate_scope.dag similarity index 100% rename from dag/gunbc/srv3_os_install_actuate_scope.dag rename to dag/gunbc/srv3/srv3_os_install_actuate_scope.dag diff --git a/dag/gunbc/srv3_os_install_actuate_workflow.dag b/dag/gunbc/srv3/srv3_os_install_actuate_workflow.dag similarity index 100% rename from dag/gunbc/srv3_os_install_actuate_workflow.dag rename to dag/gunbc/srv3/srv3_os_install_actuate_workflow.dag diff --git a/dag/gunbc/srv3_os_install_actuator_toolchain_ensure.dag b/dag/gunbc/srv3/srv3_os_install_actuator_toolchain_ensure.dag similarity index 100% rename from dag/gunbc/srv3_os_install_actuator_toolchain_ensure.dag rename to dag/gunbc/srv3/srv3_os_install_actuator_toolchain_ensure.dag diff --git a/dag/gunbc/srv3_os_install_diagnostic.dag b/dag/gunbc/srv3/srv3_os_install_diagnostic.dag similarity index 100% rename from dag/gunbc/srv3_os_install_diagnostic.dag rename to dag/gunbc/srv3/srv3_os_install_diagnostic.dag diff --git a/dag/gunbc/srv3_seeded_install_media.dag b/dag/gunbc/srv3/srv3_seeded_install_media.dag similarity index 93% rename from dag/gunbc/srv3_seeded_install_media.dag rename to dag/gunbc/srv3/srv3_seeded_install_media.dag index 7f0cad407e8..c310e6085c9 100644 --- a/dag/gunbc/srv3_seeded_install_media.dag +++ b/dag/gunbc/srv3/srv3_seeded_install_media.dag @@ -6,11 +6,11 @@ data gunbc_srv3_seeded_install_media_scope_disposition: Disposition = std.dispos } data srv3_seeded_install_media_remaster_scaffold: Disposition = std.disposition.Terminal { - reason: "srv3_seeded_install_media_remaster() routes through host_effect_apply to install_media_remaster_reconcile() in-process (TypedReconcileOnHost cell, dag/gunbc/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" + reason: "srv3_seeded_install_media_remaster() routes through host_effect_apply to install_media_remaster_reconcile() in-process (TypedReconcileOnHost cell, dag/gunbc/host/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" } data srv3_seeded_install_media_toolchain_ensure_scaffold: Disposition = std.disposition.Terminal { - reason: "srv3_seeded_install_media_toolchain_ensure routes through host_effect_apply_gated(ci_deploy_srv1_access) to realize_seeded_install_media_toolchain_ensure_on_host (SeededInstallMediaToolchainOnHost cell, dag/gunbc/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" + reason: "srv3_seeded_install_media_toolchain_ensure routes through host_effect_apply_gated(ci_deploy_srv1_access) to realize_seeded_install_media_toolchain_ensure_on_host (SeededInstallMediaToolchainOnHost cell, dag/gunbc/host/host_effect_realize.dag) - no shell script is built, serialized, or run for this effect" } data install_media_remaster_toolchain_ensure_dissolution_trigger: Disposition = std.disposition.Terminal { diff --git a/dag/gunbc/srv3_seeded_install_media_artifact.dag b/dag/gunbc/srv3/srv3_seeded_install_media_artifact.dag similarity index 100% rename from dag/gunbc/srv3_seeded_install_media_artifact.dag rename to dag/gunbc/srv3/srv3_seeded_install_media_artifact.dag diff --git a/dag/gunbc/srv3_ubuntu_install_media_artifact.dag b/dag/gunbc/srv3/srv3_ubuntu_install_media_artifact.dag similarity index 100% rename from dag/gunbc/srv3_ubuntu_install_media_artifact.dag rename to dag/gunbc/srv3/srv3_ubuntu_install_media_artifact.dag diff --git a/dag/gunbc/stage0_cargo_manifest.dag b/dag/gunbc/stage0/stage0_cargo_manifest.dag similarity index 100% rename from dag/gunbc/stage0_cargo_manifest.dag rename to dag/gunbc/stage0/stage0_cargo_manifest.dag diff --git a/dag/gunbc/stage0_crate_layout_emit.dag b/dag/gunbc/stage0/stage0_crate_layout_emit.dag similarity index 100% rename from dag/gunbc/stage0_crate_layout_emit.dag rename to dag/gunbc/stage0/stage0_crate_layout_emit.dag diff --git a/dag/gunbc/stage0_crate_layout_generated.dag b/dag/gunbc/stage0/stage0_crate_layout_generated.dag similarity index 100% rename from dag/gunbc/stage0_crate_layout_generated.dag rename to dag/gunbc/stage0/stage0_crate_layout_generated.dag diff --git a/dag/gunbc/stage0_crate_partition_emit.dag b/dag/gunbc/stage0/stage0_crate_partition_emit.dag similarity index 100% rename from dag/gunbc/stage0_crate_partition_emit.dag rename to dag/gunbc/stage0/stage0_crate_partition_emit.dag diff --git a/dag/gunbc/stage0_crate_partition_generated.dag b/dag/gunbc/stage0/stage0_crate_partition_generated.dag similarity index 100% rename from dag/gunbc/stage0_crate_partition_generated.dag rename to dag/gunbc/stage0/stage0_crate_partition_generated.dag diff --git a/dag/gunbc/stage0_emitted_population_manifest.dag b/dag/gunbc/stage0/stage0_emitted_population_manifest.dag similarity index 100% rename from dag/gunbc/stage0_emitted_population_manifest.dag rename to dag/gunbc/stage0/stage0_emitted_population_manifest.dag diff --git a/dag/gunbc/stage0_rust_honest_frontier_integration.dag b/dag/gunbc/stage0/stage0_rust_honest_frontier_integration.dag similarity index 100% rename from dag/gunbc/stage0_rust_honest_frontier_integration.dag rename to dag/gunbc/stage0/stage0_rust_honest_frontier_integration.dag diff --git a/dag/gunbc/stage0_rust_honest_frontier_projection.dag b/dag/gunbc/stage0/stage0_rust_honest_frontier_projection.dag similarity index 100% rename from dag/gunbc/stage0_rust_honest_frontier_projection.dag rename to dag/gunbc/stage0/stage0_rust_honest_frontier_projection.dag diff --git a/dag/gunbc/stage0_rust_host_observation.dag b/dag/gunbc/stage0/stage0_rust_host_observation.dag similarity index 100% rename from dag/gunbc/stage0_rust_host_observation.dag rename to dag/gunbc/stage0/stage0_rust_host_observation.dag diff --git a/dag/gunbc/stage0_rust_lifecycle_totality.dag b/dag/gunbc/stage0/stage0_rust_lifecycle_totality.dag similarity index 100% rename from dag/gunbc/stage0_rust_lifecycle_totality.dag rename to dag/gunbc/stage0/stage0_rust_lifecycle_totality.dag diff --git a/dag/gunbc/stage0_rust_maintenance_census_report.dag b/dag/gunbc/stage0/stage0_rust_maintenance_census_report.dag similarity index 100% rename from dag/gunbc/stage0_rust_maintenance_census_report.dag rename to dag/gunbc/stage0/stage0_rust_maintenance_census_report.dag diff --git a/dag/gunbc/stage0_rust_product_reachability.dag b/dag/gunbc/stage0/stage0_rust_product_reachability.dag similarity index 100% rename from dag/gunbc/stage0_rust_product_reachability.dag rename to dag/gunbc/stage0/stage0_rust_product_reachability.dag diff --git a/dag/gunbc/stage0_rust_source_lifecycle_scaffold.dag b/dag/gunbc/stage0/stage0_rust_source_lifecycle_scaffold.dag similarity index 99% rename from dag/gunbc/stage0_rust_source_lifecycle_scaffold.dag rename to dag/gunbc/stage0/stage0_rust_source_lifecycle_scaffold.dag index 0cdd17d0fea..9aebb004f0a 100644 --- a/dag/gunbc/stage0_rust_source_lifecycle_scaffold.dag +++ b/dag/gunbc/stage0/stage0_rust_source_lifecycle_scaffold.dag @@ -58,7 +58,7 @@ data rust_source_manifest_state_verdict_query_scaffold: Disposition = Scaffold { } } -data rust_source_manifest_state_verdict_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: rust_source_manifest_state_verdict — interim scaffold evidence fold; DISSOLVES WHEN V1FinishLine ZeroHandMaintainedRust acceptance graph subsumes path-derived ratchets (authority dag/gunbc/v1_deletion_plan.dag, ROADMAP.md:24 / v1-zero-hand-maintained-rust)") +data rust_source_manifest_state_verdict_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: rust_source_manifest_state_verdict — interim scaffold evidence fold; DISSOLVES WHEN V1FinishLine ZeroHandMaintainedRust acceptance graph subsumes path-derived ratchets (authority dag/gunbc/v1/v1_deletion_plan.dag, ROADMAP.md:24 / v1-zero-hand-maintained-rust)") fn path_in_list(path: String, paths: List) -> Bool { any(xs: paths, predicate: fn(p) { p == path }) @@ -757,7 +757,7 @@ data lifecycle_row_well_formed_query_scaffold: Disposition = Scaffold { } } -data lifecycle_row_well_formed_query_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: lifecycle_row_well_formed — interim scaffold obligation-shape validator; DISSOLVES WHEN V1FinishLine ZeroHandMaintainedRust acceptance graph subsumes row well-formedness (authority dag/gunbc/v1_deletion_plan.dag)") +data lifecycle_row_well_formed_query_dissolve_trigger: DissolutionCondition = unbound_dissolution(description: "🟡 dissolve-on: lifecycle_row_well_formed — interim scaffold obligation-shape validator; DISSOLVES WHEN V1FinishLine ZeroHandMaintainedRust acceptance graph subsumes row well-formedness (authority dag/gunbc/v1/v1_deletion_plan.dag)") fn lifecycle_row_well_formed(row: RustSourceLifecycleRow) -> Bool { !(row.path == "") diff --git a/dag/gunbc/v1_complexity_capability_census.dag b/dag/gunbc/v1/v1_complexity_capability_census.dag similarity index 100% rename from dag/gunbc/v1_complexity_capability_census.dag rename to dag/gunbc/v1/v1_complexity_capability_census.dag diff --git a/dag/gunbc/v1_complexity_decl_classification.dag b/dag/gunbc/v1/v1_complexity_decl_classification.dag similarity index 100% rename from dag/gunbc/v1_complexity_decl_classification.dag rename to dag/gunbc/v1/v1_complexity_decl_classification.dag diff --git a/dag/gunbc/v1_complexity_decl_classification_roster.dag b/dag/gunbc/v1/v1_complexity_decl_classification_roster.dag similarity index 100% rename from dag/gunbc/v1_complexity_decl_classification_roster.dag rename to dag/gunbc/v1/v1_complexity_decl_classification_roster.dag diff --git a/dag/gunbc/v1_complexity_decl_classification_types.dag b/dag/gunbc/v1/v1_complexity_decl_classification_types.dag similarity index 100% rename from dag/gunbc/v1_complexity_decl_classification_types.dag rename to dag/gunbc/v1/v1_complexity_decl_classification_types.dag diff --git a/dag/gunbc/v1_deletion_plan.dag b/dag/gunbc/v1/v1_deletion_plan.dag similarity index 100% rename from dag/gunbc/v1_deletion_plan.dag rename to dag/gunbc/v1/v1_deletion_plan.dag diff --git a/dag/gunbc/v1_interpreter_dispatch_emit.dag b/dag/gunbc/v1/v1_interpreter_dispatch_emit.dag similarity index 100% rename from dag/gunbc/v1_interpreter_dispatch_emit.dag rename to dag/gunbc/v1/v1_interpreter_dispatch_emit.dag diff --git a/dag/gunbc/v1_interpreter_primitive_surface.dag b/dag/gunbc/v1/v1_interpreter_primitive_surface.dag similarity index 98% rename from dag/gunbc/v1_interpreter_primitive_surface.dag rename to dag/gunbc/v1/v1_interpreter_primitive_surface.dag index 4aa17aa464c..e8ff822c8b0 100644 --- a/dag/gunbc/v1_interpreter_primitive_surface.dag +++ b/dag/gunbc/v1/v1_interpreter_primitive_surface.dag @@ -1947,8 +1947,8 @@ fn v1_interpreter_roster_seed_scaffold() -> SeedScaffoldDisposition { ], net_added_lines: 0, target_roadmap_node: "v1-interpreter-primitive-dispatch-authority", - deletion_condition: "R1 roster authority lives in dag/gunbc/v1_interpreter_primitive_surface.dag v1_interpreter_authored_roster_arms(); v1_interpreter_dispatch_emit derives Rust enum variants from arm identity and generates lookup tables. interpreter_dispatch_arm_rows and spelling roster functions are deleted. Remaining residue: handler-body macro authorities until emit generates flat match arms. Dissolves when handler bodies are generated from the roster without macro token lists.", + deletion_condition: "R1 roster authority lives in dag/gunbc/v1/v1_interpreter_primitive_surface.dag v1_interpreter_authored_roster_arms(); v1_interpreter_dispatch_emit derives Rust enum variants from arm identity and generates lookup tables. interpreter_dispatch_arm_rows and spelling roster functions are deleted. Remaining residue: handler-body macro authorities until emit generates flat match arms. Dissolves when handler bodies are generated from the roster without macro token lists.", } } -data added_hand_rust_accounting_note: String = "WHAT R1 CHANGED IN HAND-RUST, STATED PLAINLY RATHER THAN IMPLIED AWAY. The roster authority now lives in dag/gunbc/v1_interpreter_primitive_surface.dag v1_interpreter_authored_roster_arms(); gunbc.v1_interpreter_dispatch_emit derives Rust enum variants and lookup tables into src/v1/stage0/src/v1_interpreter_dispatch_generated.rs, drift-gated through gunbc.generated_artifact V1InterpreterDispatchGeneratedRsArtifact and witness_committed_is_fixed_point. Deleted from the seed: interpreter_dispatch_arm_rows, six spelling roster functions, and the self-reading bridge dispatch arm. v1_interpreter.rs now consults generated lookup_* tables before matching handler bodies; compile-time exhaustiveness is the generated enum match on the remaining handler-body macros.\n\nSO R1 CLOSES THE DUAL-AUTHORITY DEFECT the prior scaffold carried: roster edits without regenerating lookup tables now fail the generated-artifact fixed point instead of silently falling through at eval_call_native_intercept. The hand-Rust census does not shrink yet — v1_interpreter_roster_seed_scaffold still carries six macro_rules authorities until emit generates flat match arms, with net_added_lines 0 against the pre-R1 scaffold baseline. What it buys is one roster authority, generated routing, and drift enforcement rather than a second manually synced lookup table." +data added_hand_rust_accounting_note: String = "WHAT R1 CHANGED IN HAND-RUST, STATED PLAINLY RATHER THAN IMPLIED AWAY. The roster authority now lives in dag/gunbc/v1/v1_interpreter_primitive_surface.dag v1_interpreter_authored_roster_arms(); gunbc.v1_interpreter_dispatch_emit derives Rust enum variants and lookup tables into src/v1/stage0/src/v1_interpreter_dispatch_generated.rs, drift-gated through gunbc.generated_artifact V1InterpreterDispatchGeneratedRsArtifact and witness_committed_is_fixed_point. Deleted from the seed: interpreter_dispatch_arm_rows, six spelling roster functions, and the self-reading bridge dispatch arm. v1_interpreter.rs now consults generated lookup_* tables before matching handler bodies; compile-time exhaustiveness is the generated enum match on the remaining handler-body macros.\n\nSO R1 CLOSES THE DUAL-AUTHORITY DEFECT the prior scaffold carried: roster edits without regenerating lookup tables now fail the generated-artifact fixed point instead of silently falling through at eval_call_native_intercept. The hand-Rust census does not shrink yet — v1_interpreter_roster_seed_scaffold still carries six macro_rules authorities until emit generates flat match arms, with net_added_lines 0 against the pre-R1 scaffold baseline. What it buys is one roster authority, generated routing, and drift enforcement rather than a second manually synced lookup table." diff --git a/dag/gunbc/v1_maintenance_standing.dag b/dag/gunbc/v1/v1_maintenance_standing.dag similarity index 100% rename from dag/gunbc/v1_maintenance_standing.dag rename to dag/gunbc/v1/v1_maintenance_standing.dag diff --git a/dag/gunbc/witness_deferral_freeze.dag b/dag/gunbc/witness/witness_deferral_freeze.dag similarity index 100% rename from dag/gunbc/witness_deferral_freeze.dag rename to dag/gunbc/witness/witness_deferral_freeze.dag diff --git a/dag/gunbc/witness_execution_class.dag b/dag/gunbc/witness/witness_execution_class.dag similarity index 100% rename from dag/gunbc/witness_execution_class.dag rename to dag/gunbc/witness/witness_execution_class.dag diff --git a/dag/gunbc/witness_floor_workflow.dag b/dag/gunbc/witness/witness_floor_workflow.dag similarity index 100% rename from dag/gunbc/witness_floor_workflow.dag rename to dag/gunbc/witness/witness_floor_workflow.dag diff --git a/dag/gunbc/witness_row_cost.dag b/dag/gunbc/witness/witness_row_cost.dag similarity index 100% rename from dag/gunbc/witness_row_cost.dag rename to dag/gunbc/witness/witness_row_cost.dag diff --git a/dag/gunbc/witness_row_cost_basis.tsv b/dag/gunbc/witness/witness_row_cost_basis.tsv similarity index 100% rename from dag/gunbc/witness_row_cost_basis.tsv rename to dag/gunbc/witness/witness_row_cost_basis.tsv diff --git a/dag/gunbc/witness_runtime_cause_seed_growth.dag b/dag/gunbc/witness/witness_runtime_cause_seed_growth.dag similarity index 100% rename from dag/gunbc/witness_runtime_cause_seed_growth.dag rename to dag/gunbc/witness/witness_runtime_cause_seed_growth.dag diff --git a/dag/std/realization_measurement.dag b/dag/std/realization_measurement.dag index b10c126d9d7..34f3968543d 100644 --- a/dag/std/realization_measurement.dag +++ b/dag/std/realization_measurement.dag @@ -36,7 +36,7 @@ data space_measure_duality_note: String = "Space composes as time's DUAL (witnes data elapsed_observation_realization_note: String = "ObserveElapsedAtSubject realization seam: observed_monotonic_nanos(boundary) reads nanoseconds since a process-local monotonic epoch. Callers use distinct start/end boundary labels and subtract the observations around the modeled subject; the labels prevent pure-call memoization from collapsing two observations but are never cache or bundle identity material. The absolute reading is neither calendar time nor identity material. The native-selected-witness bundle receipt uses this seam to compare the same selected population through interpreter and native execution." -data elapsed_observation_hand_rust_deferral_note: String = "HAND-RUST GATE explicit deferral. The observed_monotonic_nanos Instant bridge in v1_interpreter.rs is a bounded seed-retained realization of this modeled ObserveElapsedAtSubject effect, not a new decision authority. Lane: v1-hand-queue-drain. Concrete ROADMAP row: 'Get hand-written Rust in this repository down to zero' (authority dag/gunbc/v1_deletion_plan.dag). Dissolve-on: the emitted runtime owns the host monotonic-observation realization and v1-interpreter-delete removes this seed arm; the .dag effect and receipts remain. Until then the arm is counted here, covered by the selected-witness bundle's monotonic positive control, and exercised by the cold/warm plus interpreter/native execution receipts." +data elapsed_observation_hand_rust_deferral_note: String = "HAND-RUST GATE explicit deferral. The observed_monotonic_nanos Instant bridge in v1_interpreter.rs is a bounded seed-retained realization of this modeled ObserveElapsedAtSubject effect, not a new decision authority. Lane: v1-hand-queue-drain. Concrete ROADMAP row: 'Get hand-written Rust in this repository down to zero' (authority dag/gunbc/v1/v1_deletion_plan.dag). Dissolve-on: the emitted runtime owns the host monotonic-observation realization and v1-interpreter-delete removes this seed arm; the .dag effect and receipts remain. Until then the arm is counted here, covered by the selected-witness bundle's monotonic positive control, and exercised by the cold/warm plus interpreter/native execution receipts." fn space_measure_seq(a: ByteSize, b: ByteSize) -> ByteSize { byte_size(count: nat_max(a: measure_count(m: a), b: measure_count(m: b))) diff --git a/dag/test/claim/bmc_bootstrap_provision_witness_test.dag b/dag/test/claim/bmc/bmc_bootstrap_provision_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_bootstrap_provision_witness_test.dag rename to dag/test/claim/bmc/bmc_bootstrap_provision_witness_test.dag diff --git a/dag/test/claim/bmc_capability_solve_witness_test.dag b/dag/test/claim/bmc/bmc_capability_solve_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_capability_solve_witness_test.dag rename to dag/test/claim/bmc/bmc_capability_solve_witness_test.dag diff --git a/dag/test/claim/bmc_factory_credential_witness_test.dag b/dag/test/claim/bmc/bmc_factory_credential_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_factory_credential_witness_test.dag rename to dag/test/claim/bmc/bmc_factory_credential_witness_test.dag diff --git a/dag/test/claim/bmc_fan_converge_witness_test.dag b/dag/test/claim/bmc/bmc_fan_converge_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_fan_converge_witness_test.dag rename to dag/test/claim/bmc/bmc_fan_converge_witness_test.dag diff --git a/dag/test/claim/bmc_firmware_evidence_install_mechanism_witness_test.dag b/dag/test/claim/bmc/bmc_firmware_evidence_install_mechanism_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_firmware_evidence_install_mechanism_witness_test.dag rename to dag/test/claim/bmc/bmc_firmware_evidence_install_mechanism_witness_test.dag diff --git a/dag/test/claim/bmc_firmware_thermal_witness_test.dag b/dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_firmware_thermal_witness_test.dag rename to dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag diff --git a/dag/test/claim/bmc_live_receipts_witness_test.dag b/dag/test/claim/bmc/bmc_live_receipts_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_live_receipts_witness_test.dag rename to dag/test/claim/bmc/bmc_live_receipts_witness_test.dag diff --git a/dag/test/claim/bmc_netboot_serve_witness_test.dag b/dag/test/claim/bmc/bmc_netboot_serve_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_netboot_serve_witness_test.dag rename to dag/test/claim/bmc/bmc_netboot_serve_witness_test.dag diff --git a/dag/test/claim/bmc_netboot_shell_boot_witness_test.dag b/dag/test/claim/bmc/bmc_netboot_shell_boot_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_netboot_shell_boot_witness_test.dag rename to dag/test/claim/bmc/bmc_netboot_shell_boot_witness_test.dag diff --git a/dag/test/claim/bmc_onboard_body_witness_test.dag b/dag/test/claim/bmc/bmc_onboard_body_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_onboard_body_witness_test.dag rename to dag/test/claim/bmc/bmc_onboard_body_witness_test.dag diff --git a/dag/test/claim/bmc_onboarding_lifecycle_witness_test.dag b/dag/test/claim/bmc/bmc_onboarding_lifecycle_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_onboarding_lifecycle_witness_test.dag rename to dag/test/claim/bmc/bmc_onboarding_lifecycle_witness_test.dag diff --git a/dag/test/claim/bmc_redfish_grounding_witness_test.dag b/dag/test/claim/bmc/bmc_redfish_grounding_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_redfish_grounding_witness_test.dag rename to dag/test/claim/bmc/bmc_redfish_grounding_witness_test.dag diff --git a/dag/test/claim/bmc_token_federation_witness_test.dag b/dag/test/claim/bmc/bmc_token_federation_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_token_federation_witness_test.dag rename to dag/test/claim/bmc/bmc_token_federation_witness_test.dag diff --git a/dag/test/claim/bmc_typed_operations_witness_test.dag b/dag/test/claim/bmc/bmc_typed_operations_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_typed_operations_witness_test.dag rename to dag/test/claim/bmc/bmc_typed_operations_witness_test.dag diff --git a/dag/test/claim/bmc_virtual_media_witness_test.dag b/dag/test/claim/bmc/bmc_virtual_media_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_virtual_media_witness_test.dag rename to dag/test/claim/bmc/bmc_virtual_media_witness_test.dag diff --git a/dag/test/claim/bmc_wif_delegation_chain_witness_test.dag b/dag/test/claim/bmc/bmc_wif_delegation_chain_witness_test.dag similarity index 100% rename from dag/test/claim/bmc_wif_delegation_chain_witness_test.dag rename to dag/test/claim/bmc/bmc_wif_delegation_chain_witness_test.dag diff --git a/dag/test/claim/ci_budget_tree_witness_test.dag b/dag/test/claim/ci/ci_budget_tree_witness_test.dag similarity index 100% rename from dag/test/claim/ci_budget_tree_witness_test.dag rename to dag/test/claim/ci/ci_budget_tree_witness_test.dag diff --git a/dag/test/claim/ci_compile_jobs_witness_test.dag b/dag/test/claim/ci/ci_compile_jobs_witness_test.dag similarity index 100% rename from dag/test/claim/ci_compile_jobs_witness_test.dag rename to dag/test/claim/ci/ci_compile_jobs_witness_test.dag diff --git a/dag/test/claim/ci_cost_arc_closeout_receipt_witness_test.dag b/dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag similarity index 100% rename from dag/test/claim/ci_cost_arc_closeout_receipt_witness_test.dag rename to dag/test/claim/ci/ci_cost_arc_closeout_receipt_witness_test.dag diff --git a/dag/test/claim/ci_deploy_observed_wet_test.dag b/dag/test/claim/ci/ci_deploy_observed_wet_test.dag similarity index 87% rename from dag/test/claim/ci_deploy_observed_wet_test.dag rename to dag/test/claim/ci/ci_deploy_observed_wet_test.dag index 8a3a6749029..a957cb2ea17 100644 --- a/dag/test/claim/ci_deploy_observed_wet_test.dag +++ b/dag/test/claim/ci/ci_deploy_observed_wet_test.dag @@ -1,7 +1,7 @@ module test.claim.ci_deploy_observed_wet -data ci_deploy_observed_wet_note: String = "OFFLINE wet integration witness (hermetic-floor split, operator posture 2026-07-11: integration-style witnesses do not run regularly; CI runs hermetic/mocked variants). deploy_access_check_observed shells live whoami + sudo -n, so this half of test.claim.ci_deploy_witness moved here when the discovery corpus flipped Hermetic; the pure half (script pins, enrollment pins, and the mock-shaped deploy_access_check(access, actor) dual) stays discovered. Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/claim/ci_deploy_observed_wet_test.dag. Dissolve-on: the scheduled (nightly) lane un-darkens and admits wet integration rows under its own budget — then enroll this entry there as a declared execution row." +data ci_deploy_observed_wet_note: String = "OFFLINE wet integration witness (hermetic-floor split, operator posture 2026-07-11: integration-style witnesses do not run regularly; CI runs hermetic/mocked variants). deploy_access_check_observed shells live whoami + sudo -n, so this half of test.claim.ci_deploy_witness moved here when the discovery corpus flipped Hermetic; the pure half (script pins, enrollment pins, and the mock-shaped deploy_access_check(access, actor) dual) stays discovered. Local recipe: claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/claim/ci/ci_deploy_observed_wet_test.dag. Dissolve-on: the scheduled (nightly) lane un-darkens and admits wet integration rows under its own budget — then enroll this entry there as a declared execution row." fn ci_deploy_observed_runner_principal_name() -> String { grounded_posix_principal_name(p: ci_deploy_srv1_access.principal) as String diff --git a/dag/test/claim/ci_deploy_target_host_witness_test.dag b/dag/test/claim/ci/ci_deploy_target_host_witness_test.dag similarity index 100% rename from dag/test/claim/ci_deploy_target_host_witness_test.dag rename to dag/test/claim/ci/ci_deploy_target_host_witness_test.dag diff --git a/dag/test/claim/ci_exclusion_proof_test.dag b/dag/test/claim/ci/ci_exclusion_proof_test.dag similarity index 100% rename from dag/test/claim/ci_exclusion_proof_test.dag rename to dag/test/claim/ci/ci_exclusion_proof_test.dag diff --git a/dag/test/claim/ci_failure_class_witness_test.dag b/dag/test/claim/ci/ci_failure_class_witness_test.dag similarity index 100% rename from dag/test/claim/ci_failure_class_witness_test.dag rename to dag/test/claim/ci/ci_failure_class_witness_test.dag diff --git a/dag/test/claim/ci_floor_measurement_test.dag b/dag/test/claim/ci/ci_floor_measurement_test.dag similarity index 100% rename from dag/test/claim/ci_floor_measurement_test.dag rename to dag/test/claim/ci/ci_floor_measurement_test.dag diff --git a/dag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag b/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag similarity index 95% rename from dag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag rename to dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag index 784460db37f..ba9fee6cd16 100644 --- a/dag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag +++ b/dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag @@ -30,5 +30,5 @@ test fn scaffold_names_bounded_deferral_receipt() -> Bool { && !(ci_floor_on_success_materialization_receipt_claim_executor_seed_receipt_plan_anchor == "") && !(ci_floor_on_success_materialization_receipt_claim_executor_seed_roadmap_lane_anchor == "") && ci_floor_on_success_materialization_receipt_claim_executor_seed_witness_entry == - "dag/test/claim/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag" + "dag/test/claim/ci/ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag" } diff --git a/dag/test/claim/ci_oom_reclassify_witness_test.dag b/dag/test/claim/ci/ci_oom_reclassify_witness_test.dag similarity index 100% rename from dag/test/claim/ci_oom_reclassify_witness_test.dag rename to dag/test/claim/ci/ci_oom_reclassify_witness_test.dag diff --git a/dag/test/claim/ci_render_histogram_width_test.dag b/dag/test/claim/ci/ci_render_histogram_width_test.dag similarity index 100% rename from dag/test/claim/ci_render_histogram_width_test.dag rename to dag/test/claim/ci/ci_render_histogram_width_test.dag diff --git a/dag/test/claim/ci_render_slowest_hot_style_test.dag b/dag/test/claim/ci/ci_render_slowest_hot_style_test.dag similarity index 100% rename from dag/test/claim/ci_render_slowest_hot_style_test.dag rename to dag/test/claim/ci/ci_render_slowest_hot_style_test.dag diff --git a/dag/test/claim/ci_runner_target_witness_test.dag b/dag/test/claim/ci/ci_runner_target_witness_test.dag similarity index 100% rename from dag/test/claim/ci_runner_target_witness_test.dag rename to dag/test/claim/ci/ci_runner_target_witness_test.dag diff --git a/dag/test/claim/commit_writer_admission_witness_test.dag b/dag/test/claim/commit_writer_admission_witness_test.dag index 3009c4e1f3d..c3d840b1e91 100644 --- a/dag/test/claim/commit_writer_admission_witness_test.dag +++ b/dag/test/claim/commit_writer_admission_witness_test.dag @@ -149,7 +149,7 @@ fn normal_index_entry(path: GitPath, oid: GitObjectId) -> GitIndexEntry { } fn staged_marker_218dea6_text() -> String { - "data public_file_publish_grants: List = [\n public_file_publish_grant(path: \"dag/extdeps/git/inspect.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/extdeps/session_dashboard.dag\"),\n=======\n public_file_publish_grant(path: \"dag/extdeps/github/workflows.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/extdeps/vendor/alphabet.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/hubspot.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/meta_platforms.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/salesforce.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/econ/acquisition.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_observe.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_page.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_runtime.dag\"),\n=======\n public_file_publish_grant(path: \"dag/gunbc/heal_revalidation.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/gunbc/publication_cutover.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/publication_grant.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/roadmap_presentation.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/source_integration_proof_kernel.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/acquisition_mechanism_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/advertising_interface_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/crm_stage_vocabulary_witness_test.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/test/claim/landing_workflow_witness_test.dag\"),\n=======\n public_file_publish_grant(path: \"dag/test/claim/heal_revalidation_integration_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/heal_revalidation_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/roadmap_presentation_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/source_integration_proof_kernel_acceptance_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/source_integration_proof_kernel_model_witness_test.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/test/claim/tailscale_serve_status_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/workflow_dispatch_input_witness_test.dag\"),\n]\n" + "data public_file_publish_grants: List = [\n public_file_publish_grant(path: \"dag/extdeps/git/inspect.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/extdeps/session_dashboard.dag\"),\n=======\n public_file_publish_grant(path: \"dag/extdeps/github/workflows.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/extdeps/vendor/alphabet.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/hubspot.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/meta_platforms.dag\"),\n public_file_publish_grant(path: \"dag/extdeps/vendor/salesforce.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/econ/acquisition.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_observe.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_page.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/landing_workflow_runtime.dag\"),\n=======\n public_file_publish_grant(path: \"dag/gunbc/heal_revalidation.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/gunbc/publication_cutover.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/publication_grant.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/roadmap/roadmap_presentation.dag\"),\n public_file_publish_grant(path: \"dag/gunbc/source_integration_proof_kernel.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/acquisition_mechanism_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/advertising_interface_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/crm_stage_vocabulary_witness_test.dag\"),\n<<<<<<< HEAD\n public_file_publish_grant(path: \"dag/test/claim/landing_workflow_witness_test.dag\"),\n=======\n public_file_publish_grant(path: \"dag/test/claim/heal_revalidation_integration_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/heal_revalidation_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/roadmap/roadmap_presentation_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/source_integration_proof_kernel_acceptance_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/source_integration_proof_kernel_model_witness_test.dag\"),\n>>>>>>> origin/main\n public_file_publish_grant(path: \"dag/test/claim/tailscale_serve_status_witness_test.dag\"),\n public_file_publish_grant(path: \"dag/test/claim/workflow_dispatch_input_witness_test.dag\"),\n]\n" } fn classified_text_blob( diff --git a/dag/test/claim/documentary_refs_witness_test.dag b/dag/test/claim/documentary_refs_witness_test.dag index ec2b4a4ae33..cf0022a383d 100644 --- a/dag/test/claim/documentary_refs_witness_test.dag +++ b/dag/test/claim/documentary_refs_witness_test.dag @@ -22,8 +22,8 @@ fn fixture_modules() -> List { [ ModuleDeclarationFact { module: "v2.std.symbol_index", path: "src/v2/std/symbol_index.dag" }, ModuleDeclarationFact { module: "v2.compiler.resolve", path: "src/v2/compiler/03_resolve.dag" }, - ModuleDeclarationFact { module: "gunbc.roadmap_authority", path: "dag/gunbc/roadmap_authority.dag" }, - ModuleDeclarationFact { module: "gunbc.v1_maintenance_standing", path: "dag/gunbc/v1_maintenance_standing.dag" }, + ModuleDeclarationFact { module: "gunbc.roadmap_authority", path: "dag/gunbc/roadmap/roadmap_authority.dag" }, + ModuleDeclarationFact { module: "gunbc.v1_maintenance_standing", path: "dag/gunbc/v1/v1_maintenance_standing.dag" }, ] } @@ -44,7 +44,7 @@ fn intact_facts() -> List { fixture_fact( qualified_name: "gunbc.v1_maintenance_standing.v1_seed_standing", name: "v1_seed_standing", - path: "dag/gunbc/v1_maintenance_standing.dag", + path: "dag/gunbc/v1/v1_maintenance_standing.dag", ), ] } diff --git a/dag/test/claim/expectation_frontier_witness_test.dag b/dag/test/claim/expectation_frontier_witness_test.dag index 57abc4d6f59..fe72ba20288 100644 --- a/dag/test/claim/expectation_frontier_witness_test.dag +++ b/dag/test/claim/expectation_frontier_witness_test.dag @@ -51,7 +51,7 @@ data declared_subject_note: String = "roadmap_belt_actuate's three probes (belt_ test fn fully_declared_effects_emit_no_frontier_receipt_holds() -> Bool { let stderr = run_entry_capturing_stderr( - entry: "dag/test/claim/roadmap_belt_actuate_witness_test.dag", + entry: "dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag", function: "witness_exec_ok_runs_echo" ) !string_contains(s: stderr, pattern: frontier_marker) diff --git a/dag/test/claim/fabric_budget_encumbrance_witness_test.dag b/dag/test/claim/fabric/fabric_budget_encumbrance_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_budget_encumbrance_witness_test.dag rename to dag/test/claim/fabric/fabric_budget_encumbrance_witness_test.dag diff --git a/dag/test/claim/fabric_capacity_class_gap_witness_test.dag b/dag/test/claim/fabric/fabric_capacity_class_gap_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_capacity_class_gap_witness_test.dag rename to dag/test/claim/fabric/fabric_capacity_class_gap_witness_test.dag diff --git a/dag/test/claim/fabric_capacity_class_witness_test.dag b/dag/test/claim/fabric/fabric_capacity_class_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_capacity_class_witness_test.dag rename to dag/test/claim/fabric/fabric_capacity_class_witness_test.dag diff --git a/dag/test/claim/fabric_cell_acquire_witness_test.dag b/dag/test/claim/fabric/fabric_cell_acquire_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_acquire_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_acquire_witness_test.dag diff --git a/dag/test/claim/fabric_cell_converge_witness_test.dag b/dag/test/claim/fabric/fabric_cell_converge_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_converge_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_converge_witness_test.dag diff --git a/dag/test/claim/fabric_cell_effect_witness_test.dag b/dag/test/claim/fabric/fabric_cell_effect_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_effect_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_effect_witness_test.dag diff --git a/dag/test/claim/fabric_cell_evidence_algebra_witness_test.dag b/dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_evidence_algebra_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_evidence_algebra_witness_test.dag diff --git a/dag/test/claim/fabric_cell_host_root_witness_test.dag b/dag/test/claim/fabric/fabric_cell_host_root_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_host_root_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_host_root_witness_test.dag diff --git a/dag/test/claim/fabric_cell_observe_witness_test.dag b/dag/test/claim/fabric/fabric_cell_observe_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_cell_observe_witness_test.dag rename to dag/test/claim/fabric/fabric_cell_observe_witness_test.dag diff --git a/dag/test/claim/fabric_contention_witness_test.dag b/dag/test/claim/fabric/fabric_contention_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_contention_witness_test.dag rename to dag/test/claim/fabric/fabric_contention_witness_test.dag diff --git a/dag/test/claim/fabric_control_plane_witness_test.dag b/dag/test/claim/fabric/fabric_control_plane_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_control_plane_witness_test.dag rename to dag/test/claim/fabric/fabric_control_plane_witness_test.dag diff --git a/dag/test/claim/fabric_demand_effect_witness_test.dag b/dag/test/claim/fabric/fabric_demand_effect_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_demand_effect_witness_test.dag rename to dag/test/claim/fabric/fabric_demand_effect_witness_test.dag diff --git a/dag/test/claim/fabric_envelope_witness_test.dag b/dag/test/claim/fabric/fabric_envelope_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_envelope_witness_test.dag rename to dag/test/claim/fabric/fabric_envelope_witness_test.dag diff --git a/dag/test/claim/fabric_floor_dispatch_witness_test.dag b/dag/test/claim/fabric/fabric_floor_dispatch_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_floor_dispatch_witness_test.dag rename to dag/test/claim/fabric/fabric_floor_dispatch_witness_test.dag diff --git a/dag/test/claim/fabric_isolation_witness_test.dag b/dag/test/claim/fabric/fabric_isolation_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_isolation_witness_test.dag rename to dag/test/claim/fabric/fabric_isolation_witness_test.dag diff --git a/dag/test/claim/fabric_sanitation_witness_test.dag b/dag/test/claim/fabric/fabric_sanitation_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_sanitation_witness_test.dag rename to dag/test/claim/fabric/fabric_sanitation_witness_test.dag diff --git a/dag/test/claim/fabric_selection_witness_test.dag b/dag/test/claim/fabric/fabric_selection_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_selection_witness_test.dag rename to dag/test/claim/fabric/fabric_selection_witness_test.dag diff --git a/dag/test/claim/fabric_terminal_contract_witness_test.dag b/dag/test/claim/fabric/fabric_terminal_contract_witness_test.dag similarity index 100% rename from dag/test/claim/fabric_terminal_contract_witness_test.dag rename to dag/test/claim/fabric/fabric_terminal_contract_witness_test.dag diff --git a/dag/test/claim/fabric_witness_run_test.dag b/dag/test/claim/fabric/fabric_witness_run_test.dag similarity index 100% rename from dag/test/claim/fabric_witness_run_test.dag rename to dag/test/claim/fabric/fabric_witness_run_test.dag diff --git a/dag/test/claim/fleet_capacity_control_witness_test.dag b/dag/test/claim/fleet/fleet_capacity_control_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_capacity_control_witness_test.dag rename to dag/test/claim/fleet/fleet_capacity_control_witness_test.dag diff --git a/dag/test/claim/fleet_capacity_gate_witness_test.dag b/dag/test/claim/fleet/fleet_capacity_gate_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_capacity_gate_witness_test.dag rename to dag/test/claim/fleet/fleet_capacity_gate_witness_test.dag diff --git a/dag/test/claim/fleet_capacity_panel_witness_test.dag b/dag/test/claim/fleet/fleet_capacity_panel_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_capacity_panel_witness_test.dag rename to dag/test/claim/fleet/fleet_capacity_panel_witness_test.dag diff --git a/dag/test/claim/fleet_container_demand_envelope_witness_test.dag b/dag/test/claim/fleet/fleet_container_demand_envelope_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_container_demand_envelope_witness_test.dag rename to dag/test/claim/fleet/fleet_container_demand_envelope_witness_test.dag diff --git a/dag/test/claim/fleet_converge_apply_witness_test.dag b/dag/test/claim/fleet/fleet_converge_apply_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_converge_apply_witness_test.dag rename to dag/test/claim/fleet/fleet_converge_apply_witness_test.dag diff --git a/dag/test/claim/fleet_converge_cli_witness_test.dag b/dag/test/claim/fleet/fleet_converge_cli_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_converge_cli_witness_test.dag rename to dag/test/claim/fleet/fleet_converge_cli_witness_test.dag diff --git a/dag/test/claim/fleet_converge_plan_witness_test.dag b/dag/test/claim/fleet/fleet_converge_plan_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_converge_plan_witness_test.dag rename to dag/test/claim/fleet/fleet_converge_plan_witness_test.dag diff --git a/dag/test/claim/fleet_converge_privilege_hold_witness_test.dag b/dag/test/claim/fleet/fleet_converge_privilege_hold_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_converge_privilege_hold_witness_test.dag rename to dag/test/claim/fleet/fleet_converge_privilege_hold_witness_test.dag diff --git a/dag/test/claim/fleet_convergence_verdict_witness_test.dag b/dag/test/claim/fleet/fleet_convergence_verdict_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_convergence_verdict_witness_test.dag rename to dag/test/claim/fleet/fleet_convergence_verdict_witness_test.dag diff --git a/dag/test/claim/fleet_desired_admission_witness_test.dag b/dag/test/claim/fleet/fleet_desired_admission_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_desired_admission_witness_test.dag rename to dag/test/claim/fleet/fleet_desired_admission_witness_test.dag diff --git a/dag/test/claim/fleet_desired_expectation_witness_test.dag b/dag/test/claim/fleet/fleet_desired_expectation_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_desired_expectation_witness_test.dag rename to dag/test/claim/fleet/fleet_desired_expectation_witness_test.dag diff --git a/dag/test/claim/fleet_hardware_standing_panel_witness_test.dag b/dag/test/claim/fleet/fleet_hardware_standing_panel_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_hardware_standing_panel_witness_test.dag rename to dag/test/claim/fleet/fleet_hardware_standing_panel_witness_test.dag diff --git a/dag/test/claim/fleet_host_budget_test.dag b/dag/test/claim/fleet/fleet_host_budget_test.dag similarity index 100% rename from dag/test/claim/fleet_host_budget_test.dag rename to dag/test/claim/fleet/fleet_host_budget_test.dag diff --git a/dag/test/claim/fleet_host_key_enrollment_witness_test.dag b/dag/test/claim/fleet/fleet_host_key_enrollment_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_host_key_enrollment_witness_test.dag rename to dag/test/claim/fleet/fleet_host_key_enrollment_witness_test.dag diff --git a/dag/test/claim/fleet_intent_memory_witness_test.dag b/dag/test/claim/fleet/fleet_intent_memory_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_intent_memory_witness_test.dag rename to dag/test/claim/fleet/fleet_intent_memory_witness_test.dag diff --git a/dag/test/claim/fleet_intent_network_witness_test.dag b/dag/test/claim/fleet/fleet_intent_network_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_intent_network_witness_test.dag rename to dag/test/claim/fleet/fleet_intent_network_witness_test.dag diff --git a/dag/test/claim/fleet_intent_storage_witness_test.dag b/dag/test/claim/fleet/fleet_intent_storage_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_intent_storage_witness_test.dag rename to dag/test/claim/fleet/fleet_intent_storage_witness_test.dag diff --git a/dag/test/claim/fleet_known_hosts_anchor_witness_test.dag b/dag/test/claim/fleet/fleet_known_hosts_anchor_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_known_hosts_anchor_witness_test.dag rename to dag/test/claim/fleet/fleet_known_hosts_anchor_witness_test.dag diff --git a/dag/test/claim/fleet_main_revision_witness_test.dag b/dag/test/claim/fleet/fleet_main_revision_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_main_revision_witness_test.dag rename to dag/test/claim/fleet/fleet_main_revision_witness_test.dag diff --git a/dag/test/claim/fleet_observation_producers_witness_test.dag b/dag/test/claim/fleet/fleet_observation_producers_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_observation_producers_witness_test.dag rename to dag/test/claim/fleet/fleet_observation_producers_witness_test.dag diff --git a/dag/test/claim/fleet_receipt_collector_witness_test.dag b/dag/test/claim/fleet/fleet_receipt_collector_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_receipt_collector_witness_test.dag rename to dag/test/claim/fleet/fleet_receipt_collector_witness_test.dag diff --git a/dag/test/claim/fleet_revision_acceptance_witness_test.dag b/dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_revision_acceptance_witness_test.dag rename to dag/test/claim/fleet/fleet_revision_acceptance_witness_test.dag diff --git a/dag/test/claim/fleet_revision_relation_wet_matrix_test.dag b/dag/test/claim/fleet/fleet_revision_relation_wet_matrix_test.dag similarity index 100% rename from dag/test/claim/fleet_revision_relation_wet_matrix_test.dag rename to dag/test/claim/fleet/fleet_revision_relation_wet_matrix_test.dag diff --git a/dag/test/claim/fleet_runner_connectivity_witness_test.dag b/dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_runner_connectivity_witness_test.dag rename to dag/test/claim/fleet/fleet_runner_connectivity_witness_test.dag diff --git a/dag/test/claim/fleet_show_effective_read_witness_test.dag b/dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_show_effective_read_witness_test.dag rename to dag/test/claim/fleet/fleet_show_effective_read_witness_test.dag diff --git a/dag/test/claim/fleet_ssh_credential_verify_witness_test.dag b/dag/test/claim/fleet/fleet_ssh_credential_verify_witness_test.dag similarity index 100% rename from dag/test/claim/fleet_ssh_credential_verify_witness_test.dag rename to dag/test/claim/fleet/fleet_ssh_credential_verify_witness_test.dag diff --git a/dag/test/claim/floor_attempt_standing_witness_test.dag b/dag/test/claim/floor/floor_attempt_standing_witness_test.dag similarity index 100% rename from dag/test/claim/floor_attempt_standing_witness_test.dag rename to dag/test/claim/floor/floor_attempt_standing_witness_test.dag diff --git a/dag/test/claim/floor_batch_clamp_authority_witness_test.dag b/dag/test/claim/floor/floor_batch_clamp_authority_witness_test.dag similarity index 100% rename from dag/test/claim/floor_batch_clamp_authority_witness_test.dag rename to dag/test/claim/floor/floor_batch_clamp_authority_witness_test.dag diff --git a/dag/test/claim/floor_component_receipt_witness_test.dag b/dag/test/claim/floor/floor_component_receipt_witness_test.dag similarity index 100% rename from dag/test/claim/floor_component_receipt_witness_test.dag rename to dag/test/claim/floor/floor_component_receipt_witness_test.dag diff --git a/dag/test/claim/floor_discovery_exact_subject_witness_test.dag b/dag/test/claim/floor/floor_discovery_exact_subject_witness_test.dag similarity index 100% rename from dag/test/claim/floor_discovery_exact_subject_witness_test.dag rename to dag/test/claim/floor/floor_discovery_exact_subject_witness_test.dag diff --git a/dag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag b/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag similarity index 97% rename from dag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag rename to dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag index 5375a5e8851..5fdde679232 100644 --- a/dag/test/claim/floor_discovery_hand_rust_equivalence_witness_test.dag +++ b/dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag @@ -76,7 +76,7 @@ test fn floor_entry_resolution_host_boundary_is_declared() -> Bool { ) } -data fixture_witness_entry: String = "dag/test/claim/floor_discovery_roster_fixture_test.dag" +data fixture_witness_entry: String = "dag/test/claim/floor/floor_discovery_roster_fixture_test.dag" data fixture_witness_function: String = "floor_discovery_roster_fixture_witness" data fixture_test_fn_content: String = "test fn floor_discovery_roster_fixture_witness() -> Bool { true }\n" data fixture_test_data_content: String = "test data floor_discovery_data_fixture: Bool = true\n" @@ -84,7 +84,7 @@ data fixture_misplaced_entry: String = "src/v2/lens/example.dag" data fixture_barren_test_entry: String = "dag/test/claim/floor_discovery_barren_fixture_test.dag" data fixture_barren_test_content: String = "module test.claim.floor_discovery_barren_fixture_test\n\nfn floor_discovery_barren_helper() -> Bool { true }\n" data fixture_misplaced_wire_contract_entry: String = "dag/test/fixture/floor_discovery/misplaced_wire_contract.dag" -data fixture_live_tree_entry: String = "dag/test/claim/floor_discovery_roster_fixture_test.dag" +data fixture_live_tree_entry: String = "dag/test/claim/floor/floor_discovery_roster_fixture_test.dag" fn fixture_wire_contract_coproduct_content() -> String { concat( @@ -125,7 +125,7 @@ fn fixture_live_tree_trailing_comment_content() -> String { fn fixture_bool_witness_record() -> OwnedDataDeclRecord { OwnedDataDeclRecord { - entry: "dag/gunbc/floor_discovery_scaffold.dag", + entry: "dag/gunbc/floor/floor_discovery_scaffold.dag", module: "gunbc.floor_discovery_scaffold", decl_name: "unified_claim_floor_discovery_fixture", initializer: OwnedBoolWitnessClaimInit { @@ -137,7 +137,7 @@ fn fixture_bool_witness_record() -> OwnedDataDeclRecord { fn fixture_bool_witness_record_empty_transport() -> OwnedDataDeclRecord { OwnedDataDeclRecord { - entry: "dag/gunbc/floor_discovery_scaffold.dag", + entry: "dag/gunbc/floor/floor_discovery_scaffold.dag", module: "gunbc.floor_discovery_scaffold", decl_name: "unified_claim_floor_discovery_fixture_empty", initializer: OwnedBoolWitnessClaimInit { @@ -280,7 +280,7 @@ test fn floor_discovery_sidecar_test_decl_misplaced_red_control() -> Bool { test fn floor_discovery_sidecar_test_decl_allowed_holds() -> Bool { match floor_discovery_test_decl_sidecar_violation( - entry_path: "dag/test/claim/floor_discovery_roster_fixture_test.dag" + entry_path: "dag/test/claim/floor/floor_discovery_roster_fixture_test.dag" ) { Absent => true Present { value: _ } => false diff --git a/dag/test/claim/floor_discovery_roster_fixture_test.dag b/dag/test/claim/floor/floor_discovery_roster_fixture_test.dag similarity index 100% rename from dag/test/claim/floor_discovery_roster_fixture_test.dag rename to dag/test/claim/floor/floor_discovery_roster_fixture_test.dag diff --git a/dag/test/claim/floor_expected_red_coherence_witness_test.dag b/dag/test/claim/floor/floor_expected_red_coherence_witness_test.dag similarity index 100% rename from dag/test/claim/floor_expected_red_coherence_witness_test.dag rename to dag/test/claim/floor/floor_expected_red_coherence_witness_test.dag diff --git a/dag/test/claim/floor_materialization_witness_test.dag b/dag/test/claim/floor/floor_materialization_witness_test.dag similarity index 100% rename from dag/test/claim/floor_materialization_witness_test.dag rename to dag/test/claim/floor/floor_materialization_witness_test.dag diff --git a/dag/test/claim/floor_non_verdict_classification_witness_test.dag b/dag/test/claim/floor/floor_non_verdict_classification_witness_test.dag similarity index 100% rename from dag/test/claim/floor_non_verdict_classification_witness_test.dag rename to dag/test/claim/floor/floor_non_verdict_classification_witness_test.dag diff --git a/dag/test/claim/floor_non_verdict_enrollment_witness_test.dag b/dag/test/claim/floor/floor_non_verdict_enrollment_witness_test.dag similarity index 100% rename from dag/test/claim/floor_non_verdict_enrollment_witness_test.dag rename to dag/test/claim/floor/floor_non_verdict_enrollment_witness_test.dag diff --git a/dag/test/claim/floor_preparation_shared_build_witness_test.dag b/dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag similarity index 100% rename from dag/test/claim/floor_preparation_shared_build_witness_test.dag rename to dag/test/claim/floor/floor_preparation_shared_build_witness_test.dag diff --git a/dag/test/claim/floor_preparation_witness_test.dag b/dag/test/claim/floor/floor_preparation_witness_test.dag similarity index 100% rename from dag/test/claim/floor_preparation_witness_test.dag rename to dag/test/claim/floor/floor_preparation_witness_test.dag diff --git a/dag/test/claim/floor_resolve_realization_witness_test.dag b/dag/test/claim/floor/floor_resolve_realization_witness_test.dag similarity index 100% rename from dag/test/claim/floor_resolve_realization_witness_test.dag rename to dag/test/claim/floor/floor_resolve_realization_witness_test.dag diff --git a/dag/test/claim/githooks_pre_push_emit_test.dag b/dag/test/claim/githooks_pre_push_emit_test.dag index 78f377139e4..865d8453eb6 100644 --- a/dag/test/claim/githooks_pre_push_emit_test.dag +++ b/dag/test/claim/githooks_pre_push_emit_test.dag @@ -11,7 +11,7 @@ fn has(s: String, p: String) -> Bool { test fn witness_generated_header() -> Bool { let sh = expected_githooks_pre_push_sh() - has(s: sh, p: "GENERATED by dag/gunbc/githooks_pre_push_emit.dag") + has(s: sh, p: "GENERATED by dag/gunbc/githooks/githooks_pre_push_emit.dag") && has(s: sh, p: "set -euo pipefail") } diff --git a/dag/test/claim/gunbc_invoke_witness_test.dag b/dag/test/claim/gunbc_invoke_witness_test.dag index 71dea094a59..f346b938c4e 100644 --- a/dag/test/claim/gunbc_invoke_witness_test.dag +++ b/dag/test/claim/gunbc_invoke_witness_test.dag @@ -99,27 +99,27 @@ test fn gunbc_invoke_word_wall_refuses_metacharacter_entry_holds() -> Bool { test fn gunbc_invoke_word_wall_admits_ordinary_entry_holds() -> Bool { let admitted = gunbc_run_step_script( source_roots: witness_layer_roots, - entry: "dag/gunbc/host_reach_identity_probe.dag", + entry: "dag/gunbc/host/host_reach_identity_probe.dag", function: "probe_fleet_reach_wet", claim_run: false, receipt_rel: "target/fleet-reach-probe-receipt.txt" ) !string_contains(s: admitted, pattern: "__GUNBC_INVOKE_EMIT_REFUSED__") && string_contains(s: admitted, pattern: "\"$ROOT/target/release/gunbc\" run --source-root \"$ROOT/dag\"") - && string_contains(s: admitted, pattern: "--entry dag/gunbc/host_reach_identity_probe.dag --function probe_fleet_reach_wet") + && string_contains(s: admitted, pattern: "--entry dag/gunbc/host/host_reach_identity_probe.dag --function probe_fleet_reach_wet") && string_contains(s: admitted, pattern: "cat \"$ROOT/target/fleet-reach-probe-receipt.txt\"") } test fn gunbc_invoke_argv_and_emitted_step_share_one_authority_holds() -> Bool { let argv = gunbc_run_transport_argv( source_roots: witness_layer_roots, - entry: "dag/gunbc/host_reach_identity_probe.dag", + entry: "dag/gunbc/host/host_reach_identity_probe.dag", function: "probe_fleet_reach_wet", claim_run: false ) let words = gunbc_run_invocation_words( source_roots: witness_layer_roots, - entry: "dag/gunbc/host_reach_identity_probe.dag", + entry: "dag/gunbc/host/host_reach_identity_probe.dag", function: "probe_fleet_reach_wet", claim_run: false ) diff --git a/dag/test/claim/host_allocation_conservation_test.dag b/dag/test/claim/host/host_allocation_conservation_test.dag similarity index 100% rename from dag/test/claim/host_allocation_conservation_test.dag rename to dag/test/claim/host/host_allocation_conservation_test.dag diff --git a/dag/test/claim/host_axis_caps_witness_test.dag b/dag/test/claim/host/host_axis_caps_witness_test.dag similarity index 100% rename from dag/test/claim/host_axis_caps_witness_test.dag rename to dag/test/claim/host/host_axis_caps_witness_test.dag diff --git a/dag/test/claim/host_budget_source_witness_test.dag b/dag/test/claim/host/host_budget_source_witness_test.dag similarity index 100% rename from dag/test/claim/host_budget_source_witness_test.dag rename to dag/test/claim/host/host_budget_source_witness_test.dag diff --git a/dag/test/claim/host_build_cache_provision_design_witness_test.dag b/dag/test/claim/host/host_build_cache_provision_design_witness_test.dag similarity index 100% rename from dag/test/claim/host_build_cache_provision_design_witness_test.dag rename to dag/test/claim/host/host_build_cache_provision_design_witness_test.dag diff --git a/dag/test/claim/host_build_cache_provision_real_execution_witness_test.dag b/dag/test/claim/host/host_build_cache_provision_real_execution_witness_test.dag similarity index 100% rename from dag/test/claim/host_build_cache_provision_real_execution_witness_test.dag rename to dag/test/claim/host/host_build_cache_provision_real_execution_witness_test.dag diff --git a/dag/test/claim/host_cli_dependency_wet_witness_test.dag b/dag/test/claim/host/host_cli_dependency_wet_witness_test.dag similarity index 100% rename from dag/test/claim/host_cli_dependency_wet_witness_test.dag rename to dag/test/claim/host/host_cli_dependency_wet_witness_test.dag diff --git a/dag/test/claim/host_cli_dependency_witness_test.dag b/dag/test/claim/host/host_cli_dependency_witness_test.dag similarity index 100% rename from dag/test/claim/host_cli_dependency_witness_test.dag rename to dag/test/claim/host/host_cli_dependency_witness_test.dag diff --git a/dag/test/claim/host_codex_runtime_provision_design_witness_test.dag b/dag/test/claim/host/host_codex_runtime_provision_design_witness_test.dag similarity index 100% rename from dag/test/claim/host_codex_runtime_provision_design_witness_test.dag rename to dag/test/claim/host/host_codex_runtime_provision_design_witness_test.dag diff --git a/dag/test/claim/host_compile_pool_test.dag b/dag/test/claim/host/host_compile_pool_test.dag similarity index 100% rename from dag/test/claim/host_compile_pool_test.dag rename to dag/test/claim/host/host_compile_pool_test.dag diff --git a/dag/test/claim/host_converge_delta_witness_test.dag b/dag/test/claim/host/host_converge_delta_witness_test.dag similarity index 100% rename from dag/test/claim/host_converge_delta_witness_test.dag rename to dag/test/claim/host/host_converge_delta_witness_test.dag diff --git a/dag/test/claim/host_converge_slice1_witness_test.dag b/dag/test/claim/host/host_converge_slice1_witness_test.dag similarity index 100% rename from dag/test/claim/host_converge_slice1_witness_test.dag rename to dag/test/claim/host/host_converge_slice1_witness_test.dag diff --git a/dag/test/claim/host_disk_reclaim_units_witness_test.dag b/dag/test/claim/host/host_disk_reclaim_units_witness_test.dag similarity index 100% rename from dag/test/claim/host_disk_reclaim_units_witness_test.dag rename to dag/test/claim/host/host_disk_reclaim_units_witness_test.dag diff --git a/dag/test/claim/host_disk_reclaim_witness_test.dag b/dag/test/claim/host/host_disk_reclaim_witness_test.dag similarity index 100% rename from dag/test/claim/host_disk_reclaim_witness_test.dag rename to dag/test/claim/host/host_disk_reclaim_witness_test.dag diff --git a/dag/test/claim/host_effect_apply_witness_test.dag b/dag/test/claim/host/host_effect_apply_witness_test.dag similarity index 100% rename from dag/test/claim/host_effect_apply_witness_test.dag rename to dag/test/claim/host/host_effect_apply_witness_test.dag diff --git a/dag/test/claim/host_effect_plan_real_execution_witness_test.dag b/dag/test/claim/host/host_effect_plan_real_execution_witness_test.dag similarity index 100% rename from dag/test/claim/host_effect_plan_real_execution_witness_test.dag rename to dag/test/claim/host/host_effect_plan_real_execution_witness_test.dag diff --git a/dag/test/claim/host_effect_plan_witness_test.dag b/dag/test/claim/host/host_effect_plan_witness_test.dag similarity index 100% rename from dag/test/claim/host_effect_plan_witness_test.dag rename to dag/test/claim/host/host_effect_plan_witness_test.dag diff --git a/dag/test/claim/host_hygiene_liveness_test.dag b/dag/test/claim/host/host_hygiene_liveness_test.dag similarity index 100% rename from dag/test/claim/host_hygiene_liveness_test.dag rename to dag/test/claim/host/host_hygiene_liveness_test.dag diff --git a/dag/test/claim/host_hygiene_reaper_test.dag b/dag/test/claim/host/host_hygiene_reaper_test.dag similarity index 100% rename from dag/test/claim/host_hygiene_reaper_test.dag rename to dag/test/claim/host/host_hygiene_reaper_test.dag diff --git a/dag/test/claim/host_identity_observation_witness_test.dag b/dag/test/claim/host/host_identity_observation_witness_test.dag similarity index 100% rename from dag/test/claim/host_identity_observation_witness_test.dag rename to dag/test/claim/host/host_identity_observation_witness_test.dag diff --git a/dag/test/claim/host_memory_qualification_witness_test.dag b/dag/test/claim/host/host_memory_qualification_witness_test.dag similarity index 100% rename from dag/test/claim/host_memory_qualification_witness_test.dag rename to dag/test/claim/host/host_memory_qualification_witness_test.dag diff --git a/dag/test/claim/host_network_diagnosis_witness_test.dag b/dag/test/claim/host/host_network_diagnosis_witness_test.dag similarity index 100% rename from dag/test/claim/host_network_diagnosis_witness_test.dag rename to dag/test/claim/host/host_network_diagnosis_witness_test.dag diff --git a/dag/test/claim/host_phase_status_witness_test.dag b/dag/test/claim/host/host_phase_status_witness_test.dag similarity index 100% rename from dag/test/claim/host_phase_status_witness_test.dag rename to dag/test/claim/host/host_phase_status_witness_test.dag diff --git a/dag/test/claim/host_reach_identity_probe_witness_test.dag b/dag/test/claim/host/host_reach_identity_probe_witness_test.dag similarity index 100% rename from dag/test/claim/host_reach_identity_probe_witness_test.dag rename to dag/test/claim/host/host_reach_identity_probe_witness_test.dag diff --git a/dag/test/claim/host_run_boundary_admission_witness_test.dag b/dag/test/claim/host/host_run_boundary_admission_witness_test.dag similarity index 100% rename from dag/test/claim/host_run_boundary_admission_witness_test.dag rename to dag/test/claim/host/host_run_boundary_admission_witness_test.dag diff --git a/dag/test/claim/host_standup_assimilation_deduction_witness_test.dag b/dag/test/claim/host/host_standup_assimilation_deduction_witness_test.dag similarity index 100% rename from dag/test/claim/host_standup_assimilation_deduction_witness_test.dag rename to dag/test/claim/host/host_standup_assimilation_deduction_witness_test.dag diff --git a/dag/test/claim/host_standup_spine_witness_test.dag b/dag/test/claim/host/host_standup_spine_witness_test.dag similarity index 100% rename from dag/test/claim/host_standup_spine_witness_test.dag rename to dag/test/claim/host/host_standup_spine_witness_test.dag diff --git a/dag/test/claim/host_swap_backing_witness_test.dag b/dag/test/claim/host/host_swap_backing_witness_test.dag similarity index 100% rename from dag/test/claim/host_swap_backing_witness_test.dag rename to dag/test/claim/host/host_swap_backing_witness_test.dag diff --git a/dag/test/claim/host_toolchain_components_witness_test.dag b/dag/test/claim/host/host_toolchain_components_witness_test.dag similarity index 100% rename from dag/test/claim/host_toolchain_components_witness_test.dag rename to dag/test/claim/host/host_toolchain_components_witness_test.dag diff --git a/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag b/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag index 594269a9624..96ce050a52a 100644 --- a/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag +++ b/dag/test/claim/live_deploy/candidate_checkout_witness_test.dag @@ -61,18 +61,18 @@ test fn empty_status_scans_clean() -> Bool { // ---------------------------------------------------------------- the three dirty axes, separated test fn an_unstaged_tracked_edit_lands_on_the_tracked_axis_only() -> Bool { - let s = scan_checkout_status(entries_nul: scan_of(fields: [" M dag/gunbc/roadmap_component.dag"])) + let s = scan_checkout_status(entries_nul: scan_of(fields: [" M dag/gunbc/roadmap/roadmap_component.dag"])) length(s.tracked) == 1 - && join(s.tracked, ",") == "dag/gunbc/roadmap_component.dag" + && join(s.tracked, ",") == "dag/gunbc/roadmap/roadmap_component.dag" && length(s.staged) == 0 && length(s.untracked) == 0 && !s.malformed } test fn a_staged_edit_lands_on_the_staged_axis_only() -> Bool { - let s = scan_checkout_status(entries_nul: scan_of(fields: ["M dag/gunbc/roadmap_component.dag"])) + let s = scan_checkout_status(entries_nul: scan_of(fields: ["M dag/gunbc/roadmap/roadmap_component.dag"])) length(s.staged) == 1 - && join(s.staged, ",") == "dag/gunbc/roadmap_component.dag" + && join(s.staged, ",") == "dag/gunbc/roadmap/roadmap_component.dag" && length(s.tracked) == 0 && length(s.untracked) == 0 && !s.malformed @@ -81,11 +81,11 @@ test fn a_staged_edit_lands_on_the_staged_axis_only() -> Bool { // The both-columns case is the one a single `dirty: Bool` would erase: the index and the working tree // disagree with HEAD in different ways, and the operator needs both remedies, not one bit. test fn a_file_staged_and_then_edited_again_lands_on_both_axes() -> Bool { - let s = scan_checkout_status(entries_nul: scan_of(fields: ["MM dag/gunbc/roadmap_component.dag"])) + let s = scan_checkout_status(entries_nul: scan_of(fields: ["MM dag/gunbc/roadmap/roadmap_component.dag"])) length(s.staged) == 1 && length(s.tracked) == 1 - && join(s.staged, ",") == "dag/gunbc/roadmap_component.dag" - && join(s.tracked, ",") == "dag/gunbc/roadmap_component.dag" + && join(s.staged, ",") == "dag/gunbc/roadmap/roadmap_component.dag" + && join(s.tracked, ",") == "dag/gunbc/roadmap/roadmap_component.dag" && !s.malformed } diff --git a/dag/test/claim/live_deploy/deployed_tree_observation_witness_test.dag b/dag/test/claim/live_deploy/deployed_tree_observation_witness_test.dag index 31afbaca109..b19ccfa76ec 100644 --- a/dag/test/claim/live_deploy/deployed_tree_observation_witness_test.dag +++ b/dag/test/claim/live_deploy/deployed_tree_observation_witness_test.dag @@ -189,14 +189,14 @@ test fn witness_an_empty_status_and_no_ignored_paths_read_as_matching_the_commit test fn witness_a_modified_tracked_path_reads_as_diverged_and_carries_what_was_seen() -> Bool { match deployed_tree_content_reading( - entries_nul: nul_join([" M dag/gunbc/ci_spec.dag"]), + entries_nul: nul_join([" M dag/gunbc/ci/ci_spec.dag"]), ignored_nul: "", ) { ContentUnreadable { detail: _ } => false ContentRead { state: s } => match s { DeployedScopeMatchesCommit => false - DeployedScopeDiverged { changed_paths: body } => body as String == "dag/gunbc/ci_spec.dag" + DeployedScopeDiverged { changed_paths: body } => body as String == "dag/gunbc/ci/ci_spec.dag" } } } @@ -205,7 +205,7 @@ test fn witness_a_modified_tracked_path_reads_as_diverged_and_carries_what_was_s // excluded prefix would present on a host: rsync never ships it, so the worktree lacks a path HEAD // names, and status lists it like any other difference. test fn witness_a_deleted_tracked_path_reads_as_diverged() -> Bool { - match deployed_tree_content_reading(entries_nul: nul_join([" D dag/gunbc/ci_spec.dag"]), ignored_nul: "") { + match deployed_tree_content_reading(entries_nul: nul_join([" D dag/gunbc/ci/ci_spec.dag"]), ignored_nul: "") { ContentUnreadable { detail: _ } => false ContentRead { state: s } => match s { @@ -333,11 +333,11 @@ test fn witness_right_revision_with_modifications_is_not_converged_and_not_drift desired: a, obs: DeployedTreeObserved { revision: a, - content: DeployedScopeDiverged { changed_paths: "dag/gunbc/ci_spec.dag" as NonEmptyStr }, + content: DeployedScopeDiverged { changed_paths: "dag/gunbc/ci/ci_spec.dag" as NonEmptyStr }, }, ) { DeployedTreeModifiedAtRevision { revision: _, changed_paths: body } => - body as String == "dag/gunbc/ci_spec.dag" + body as String == "dag/gunbc/ci/ci_spec.dag" DeployedTreeConverged { revision: _ } => false DeployedTreeRevisionDrifted { desired: _, local: _ } => false DeployedTreeStandingUnobserved { cause: _ } => false diff --git a/dag/test/claim/live_deploy/deployed_tree_report_witness_test.dag b/dag/test/claim/live_deploy/deployed_tree_report_witness_test.dag index 7f8d024a621..b5461444809 100644 --- a/dag/test/claim/live_deploy/deployed_tree_report_witness_test.dag +++ b/dag/test/claim/live_deploy/deployed_tree_report_witness_test.dag @@ -78,11 +78,11 @@ test fn witness_the_modified_line_carries_what_git_reported() -> Bool { let line = deployed_tree_standing_line( standing: DeployedTreeModifiedAtRevision { revision: a, - changed_paths: "dag/gunbc/ci_spec.dag" as NonEmptyStr, + changed_paths: "dag/gunbc/ci/ci_spec.dag" as NonEmptyStr, }, ) string_contains(s: line, pattern: "MODIFIED-AT-REVISION") - && string_contains(s: line, pattern: "dag/gunbc/ci_spec.dag") + && string_contains(s: line, pattern: "dag/gunbc/ci/ci_spec.dag") && string_contains(s: line, pattern: git_object_id_wire_hex(oid: a) as String) } } diff --git a/dag/test/claim/live_deploy/emit_test.dag b/dag/test/claim/live_deploy/emit_test.dag index d974acbb826..2287a4ad201 100644 --- a/dag/test/claim/live_deploy/emit_test.dag +++ b/dag/test/claim/live_deploy/emit_test.dag @@ -426,7 +426,7 @@ test fn witness_execstart_carries_exactly_the_admitted_revision() -> Bool { ) let expected = join([ "ExecStart=/opt/gunbc/bin/gunbc serve --source-root dag --source-root src/v2", - " --entry dag/gunbc/roadmap_serve.dag --function roadmap_serve_handle", + " --entry dag/gunbc/roadmap/roadmap_serve.dag --function roadmap_serve_handle", " --host 0.0.0.0 --port 8080", " --release-revision ", deploy_witness_release_revision as String, " --eval-budget-cpu-ms 30000", @@ -464,7 +464,7 @@ test fn witness_execstart_at_another_candidate_differs() -> Bool { test fn witness_systemd_unit_emitted() -> Bool { let unit = live_deploy_systemd_unit_for(spec: deployment_spec_srv1(), revision: RevisionBoundAtEmission { revision: deploy_witness_release_revision }) - string_contains(s: unit, pattern: "ExecStart=/opt/gunbc/bin/gunbc serve --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap_serve.dag --function roadmap_serve_handle --host 0.0.0.0 --port 8080") + string_contains(s: unit, pattern: "ExecStart=/opt/gunbc/bin/gunbc serve --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap/roadmap_serve.dag --function roadmap_serve_handle --host 0.0.0.0 --port 8080") && string_contains(s: unit, pattern: "User=briansrls") && string_contains(s: unit, pattern: "Group=briansrls") && string_contains(s: unit, pattern: "WorkingDirectory=/opt/gunbc/gunbc") diff --git a/dag/test/claim/live_deploy/running_release_identity_witness_test.dag b/dag/test/claim/live_deploy/running_release_identity_witness_test.dag index c9186284567..691c78d43ef 100644 --- a/dag/test/claim/live_deploy/running_release_identity_witness_test.dag +++ b/dag/test/claim/live_deploy/running_release_identity_witness_test.dag @@ -265,7 +265,7 @@ test fn witness_duplicate_revision_member_refuses() -> Bool { data duplicate_member_note: String = "TWO REVISION MEMBERS MEANS TWO WRITERS, AND PICKING EITHER WOULD BE A FABRICATED ANSWER ABOUT WHICH PROCESS IS RUNNING. A JSON reader that takes the first or the last would answer plausibly and be right half the time; the observation refuses instead. This is the one arm a hand-written extractor almost always gets wrong, which is why it is stated here rather than left to the general parser's reputation." -data live_process_identity_immutability_receipt: String = "EXECUTED 2026-08-07 AGAINST HEAD c4fe948f201, THREE REAL PROCESSES, AND THE FIRST ATTEMPT AT IT WAS VACUOUS. The property owed was that `gunbc serve` binds what it serves ONCE at process start, so a tree that changes underneath a running process does not change its answers. Recipe, reproducible: launch `gunbc serve --entry dag/gunbc/roadmap_serve.dag --function roadmap_serve_handle --port P --release-revision R` per process, read /healthz, mutate, read again.\\n\\nOBSERVED. Process 1 (port 18731, launched at revision 0123...4567) answered service=gunbc-roadmap. With process 1 still running, dag/gunbc/roadmap_site_surface_render.dag roadmap_site_service_name was edited on disk to gunbc-roadmap-PROBE. Process 1 continued answering service=gunbc-roadmap and revision=0123...4567 — unchanged. Process 3 (port 18733, launched AFTER the edit at revision fedc...ba98) answered service=gunbc-roadmap-PROBE and revision=fedc...ba98. Same bytes on disk, same instant, two different answers, distinguished only by launch time.\\n\\nWHY THE SECOND PROCESS IS THE WHOLE POINT. The first attempt mutated ROADMAP.md and observed no change in the running process — which looked like a pass and proved nothing, because a FRESH process on the mutated tree reported the same digest too. /ROADMAP.md is itself a generated projection of the .dag roadmap authority, so editing the file changes nothing anyone serves. A negative control with no positive control beside it cannot tell immutability from an input that was never read; running the fresh process is what converted a vacuous green into a discriminating one, and it is the reason the mutation subject moved from a generated artifact to a .dag authority.\\n\\nA THIRD FACT FELL OUT, UNLOOKED FOR. Three processes ran concurrently against ONE tree at three declared revisions (0123...4567, 89ab...cdef, fedc...ba98) and each reported its own. Whatever answers /healthz cannot be reading the revision from any shared ambient source — not disk, not env, not git HEAD — because all three share every one of those and disagree anyway.\\n\\nWHAT IS STILL OWED, so this is not read as more than it is: the run was performed by hand, not by an enrolled witness. Each process costs about 100 s of graph compile, so three of them are far outside the per-PR fast lane and enrolling them there would be the cost-shape defect the 2026-08-04 witness-cost ruling names. The trigger is the wet cadence lane: this belongs there as a budgeted wet control, and until it is enrolled the property is established by this receipt at one head rather than defended against regression." +data live_process_identity_immutability_receipt: String = "EXECUTED 2026-08-07 AGAINST HEAD c4fe948f201, THREE REAL PROCESSES, AND THE FIRST ATTEMPT AT IT WAS VACUOUS. The property owed was that `gunbc serve` binds what it serves ONCE at process start, so a tree that changes underneath a running process does not change its answers. Recipe, reproducible: launch `gunbc serve --entry dag/gunbc/roadmap/roadmap_serve.dag --function roadmap_serve_handle --port P --release-revision R` per process, read /healthz, mutate, read again.\\n\\nOBSERVED. Process 1 (port 18731, launched at revision 0123...4567) answered service=gunbc-roadmap. With process 1 still running, dag/gunbc/roadmap/roadmap_site_surface_render.dag roadmap_site_service_name was edited on disk to gunbc-roadmap-PROBE. Process 1 continued answering service=gunbc-roadmap and revision=0123...4567 — unchanged. Process 3 (port 18733, launched AFTER the edit at revision fedc...ba98) answered service=gunbc-roadmap-PROBE and revision=fedc...ba98. Same bytes on disk, same instant, two different answers, distinguished only by launch time.\\n\\nWHY THE SECOND PROCESS IS THE WHOLE POINT. The first attempt mutated ROADMAP.md and observed no change in the running process — which looked like a pass and proved nothing, because a FRESH process on the mutated tree reported the same digest too. /ROADMAP.md is itself a generated projection of the .dag roadmap authority, so editing the file changes nothing anyone serves. A negative control with no positive control beside it cannot tell immutability from an input that was never read; running the fresh process is what converted a vacuous green into a discriminating one, and it is the reason the mutation subject moved from a generated artifact to a .dag authority.\\n\\nA THIRD FACT FELL OUT, UNLOOKED FOR. Three processes ran concurrently against ONE tree at three declared revisions (0123...4567, 89ab...cdef, fedc...ba98) and each reported its own. Whatever answers /healthz cannot be reading the revision from any shared ambient source — not disk, not env, not git HEAD — because all three share every one of those and disagree anyway.\\n\\nWHAT IS STILL OWED, so this is not read as more than it is: the run was performed by hand, not by an enrolled witness. Each process costs about 100 s of graph compile, so three of them are far outside the per-PR fast lane and enrolling them there would be the cost-shape defect the 2026-08-04 witness-cost ruling names. The trigger is the wet cadence lane: this belongs there as a budgeted wet control, and until it is enrolled the property is established by this receipt at one head rather than defended against regression." data surface_projection_refusal_discrimination_note: String = "THE CLAIM THIS CHANGE EXISTS FOR, AND IT IS NOT AN ORDINARY MISSING-CASE TEST. healthz_surface_projection returned String?, so `none` answered BOTH 'this body is not JSON' and 'this body is JSON without the surface members'. At an Optional that collapse is worse than at a Bool: the failure is not merely unreported, it is indistinguishable from the ordinary negative result, and the consumer rendered both as ServedSurfaceStale -- telling a deploy operator that the right process serves the wrong tree when an HTML error page was answering the port. The two witnesses below assert the two causes are now different values; without the pair, either could be produced for everything and a single-cause claim would still pass." diff --git a/dag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag b/dag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag index 086701ef8e8..52d95a8949e 100644 --- a/dag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag +++ b/dag/test/claim/live_deploy_unit_emission_oracle_witness_test.dag @@ -95,7 +95,7 @@ fn live_revision() -> ReleaseRevisionBinding { // when this unit is next applied. test fn the_belt_service_unit_matches_the_deployed_bytes() -> Bool { let emitted = render(doc: emit_belt_service_unit_doc(spec: live_spec()), proto: live_deploy_protocol) - emitted == "[Unit]\nDescription=gunbc roadmap belt tick (one reconcile pass over the ready frontier)\nAfter=network-online.target\nWants=network-online.target\n\n[Service]\nType=oneshot\nUser=briansrls\nGroup=briansrls\nWorkingDirectory=/opt/gunbc/gunbc\nEnvironment=GUNBC_BELT_SPAWN_WORKDIR=/opt/gunbc/gunbc\nExecStart=/opt/gunbc/bin/gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap_belt_actuate.dag --function belt_run_once_cli\n" + emitted == "[Unit]\nDescription=gunbc roadmap belt tick (one reconcile pass over the ready frontier)\nAfter=network-online.target\nWants=network-online.target\n\n[Service]\nType=oneshot\nUser=briansrls\nGroup=briansrls\nWorkingDirectory=/opt/gunbc/gunbc\nEnvironment=GUNBC_BELT_SPAWN_WORKDIR=/opt/gunbc/gunbc\nExecStart=/opt/gunbc/bin/gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap/roadmap_belt_actuate.dag --function belt_run_once_cli\n" } // gunbc-roadmap-belt.timer, as deployed on srv1 2026-08-19. @@ -113,7 +113,7 @@ test fn the_belt_timer_unit_matches_the_deployed_bytes() -> Bool { // deployment_credential_env_path carries the argument. test fn the_serve_unit_matches_the_deployed_bytes() -> Bool { let emitted = render(doc: emit_systemd_unit_doc(spec: live_spec(), revision: live_revision()), proto: live_deploy_protocol) - emitted == "[Unit]\nDescription=gunbc roadmap HTTP server (gunbc serve)\nAfter=network-online.target tailscaled.service\nWants=network-online.target\n\n[Service]\nType=simple\nUser=briansrls\nGroup=briansrls\nWorkingDirectory=/opt/gunbc/gunbc\nExecStart=/opt/gunbc/bin/gunbc serve --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap_serve.dag --function roadmap_serve_handle --host 0.0.0.0 --port 8080 --release-revision b2dd729f92954e50e3d8d9bbd65022c2d58f14dd --eval-budget-cpu-ms 30000 --eval-budget-wall-ms 30000\nRestart=on-failure\n\n[Install]\nWantedBy=multi-user.target\n" + emitted == "[Unit]\nDescription=gunbc roadmap HTTP server (gunbc serve)\nAfter=network-online.target tailscaled.service\nWants=network-online.target\n\n[Service]\nType=simple\nUser=briansrls\nGroup=briansrls\nWorkingDirectory=/opt/gunbc/gunbc\nExecStart=/opt/gunbc/bin/gunbc serve --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap/roadmap_serve.dag --function roadmap_serve_handle --host 0.0.0.0 --port 8080 --release-revision b2dd729f92954e50e3d8d9bbd65022c2d58f14dd --eval-budget-cpu-ms 30000 --eval-budget-wall-ms 30000\nRestart=on-failure\n\n[Install]\nWantedBy=multi-user.target\n" } // gunbc-tree-sync.service. Base transcription: srv1, 2026-08-19, like its siblings — but this diff --git a/dag/test/claim/no_fake_anomalies_witness_test.dag b/dag/test/claim/no_fake_anomalies_witness_test.dag index 2a14562111e..025a31a3446 100644 --- a/dag/test/claim/no_fake_anomalies_witness_test.dag +++ b/dag/test/claim/no_fake_anomalies_witness_test.dag @@ -43,7 +43,7 @@ fn stderr_has_anomaly_glyph(stderr: String) -> Bool { test fn passing_run_shows_no_fake_anomaly_holds() -> Bool { let stderr = run_corpus_capturing_stderr( - entry: "dag/test/claim/roadmap_belt_actuate_witness_test.dag", + entry: "dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag", function: "witness_uuid_deterministic" ) !stderr_has_anomaly_glyph(stderr: stderr) diff --git a/dag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag b/dag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag index ee01236b163..74f8edc0cdd 100644 --- a/dag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag +++ b/dag/test/claim/repo_local_git_config_clone_bootstrap_witness_test.dag @@ -14,7 +14,7 @@ test fn clone_bootstrap_population_records_missing_session_worktree_enrollment() test fn clone_bootstrap_points_at_modeled_converge_entry() -> Bool { (repo_local_git_config_clone_bootstrap_converge_invoke_function == "converge") - && (repo_local_git_config_clone_bootstrap_converge_invoke_entry == "dag/gunbc/repo_local_git_config.dag") + && (repo_local_git_config_clone_bootstrap_converge_invoke_entry == "dag/gunbc/repo/repo_local_git_config.dag") } test fn clone_bootstrap_has_enrolled_paths() -> Bool { diff --git a/dag/test/claim/repo_local_git_config_witness_test.dag b/dag/test/claim/repo_local_git_config_witness_test.dag index 070d17f25aa..65dfd4ef4f2 100644 --- a/dag/test/claim/repo_local_git_config_witness_test.dag +++ b/dag/test/claim/repo_local_git_config_witness_test.dag @@ -41,7 +41,7 @@ test fn witness_desired_binding_count_holds() -> Bool { test fn witness_converge_entry_is_declared() -> Bool { repo_local_git_config_converge_function == "converge" - && repo_local_git_config_converge_entry == "dag/gunbc/repo_local_git_config.dag" + && repo_local_git_config_converge_entry == "dag/gunbc/repo/repo_local_git_config.dag" } test fn witness_empty_observed_reconcile_upserts_holds() -> Bool { diff --git a/dag/test/claim/roadmap_altitude_witness_test.dag b/dag/test/claim/roadmap/roadmap_altitude_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_altitude_witness_test.dag rename to dag/test/claim/roadmap/roadmap_altitude_witness_test.dag diff --git a/dag/test/claim/roadmap_authority_test.dag b/dag/test/claim/roadmap/roadmap_authority_test.dag similarity index 98% rename from dag/test/claim/roadmap_authority_test.dag rename to dag/test/claim/roadmap/roadmap_authority_test.dag index 98199ca329f..d5608521a61 100644 --- a/dag/test/claim/roadmap_authority_test.dag +++ b/dag/test/claim/roadmap/roadmap_authority_test.dag @@ -386,7 +386,7 @@ test fn witness_receipt_for_unknown_node_accepts_nothing() -> Bool { all(nodes(), n => !node_accepted(receipts: [ghost], rn: n)) } -data acceptance_receipt_continuity_witness_note: String = "THE WALL AGAINST SILENT RECEIPT DELETION (acceptance_receipt_continuity_wall_note). roadmap_acceptance_event_history loads from dag/gunbc/roadmap_acceptance_event_history.jsonl; roadmap_acceptance_receipts projects live receipts only. Live git-observed integrity executes in test.claim.roadmap_receipt_continuity_live_witness (ReadsLiveTree, bin_witness_wet_entries). RED controls in test.claim.roadmap_receipt_continuity_acceptance plant deleted events, prefix law, empty-prior bypass discriminant, digest-field mutation, wrong prior digest, revocation while live, duplicate revocations, exact revocation admit, criteria rewrite, git-refusal observation, and typed projection refusal chain." +data acceptance_receipt_continuity_witness_note: String = "THE WALL AGAINST SILENT RECEIPT DELETION (acceptance_receipt_continuity_wall_note). roadmap_acceptance_event_history loads from dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl; roadmap_acceptance_receipts projects live receipts only. Live git-observed integrity executes in test.claim.roadmap_receipt_continuity_live_witness (ReadsLiveTree, bin_witness_wet_entries). RED controls in test.claim.roadmap_receipt_continuity_acceptance plant deleted events, prefix law, empty-prior bypass discriminant, digest-field mutation, wrong prior digest, revocation while live, duplicate revocations, exact revocation admit, criteria rewrite, git-refusal observation, and typed projection refusal chain." fn live_acceptance_event_history() -> List { match roadmap_acceptance_event_history_load() { diff --git a/dag/test/claim/roadmap_belt_actuate_witness_test.dag b/dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_belt_actuate_witness_test.dag rename to dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag diff --git a/dag/test/claim/roadmap_belt_witness_test.dag b/dag/test/claim/roadmap/roadmap_belt_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_belt_witness_test.dag rename to dag/test/claim/roadmap/roadmap_belt_witness_test.dag diff --git a/dag/test/claim/roadmap_closing_contract_authoring_witness_test.dag b/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag similarity index 98% rename from dag/test/claim/roadmap_closing_contract_authoring_witness_test.dag rename to dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag index 4793df5c8dc..cfd0fc4c7f6 100644 --- a/dag/test/claim/roadmap_closing_contract_authoring_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_closing_contract_authoring_witness_test.dag @@ -209,7 +209,7 @@ test fn the_validation_projects_the_target_into_its_argv() -> Bool { ) { Present { value: command } => join(command.args, " ") - == "run --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap_closing_contract_authoring.dag --function closing_contract_authored --arg target=example-node --claim-run" + == "run --source-root dag --source-root src/v2 --entry dag/gunbc/roadmap/roadmap_closing_contract_authoring.dag --function closing_contract_authored --arg target=example-node --claim-run" Absent => false } } diff --git a/dag/test/claim/roadmap_dashboard_instance_apply_witness_test.dag b/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag similarity index 99% rename from dag/test/claim/roadmap_dashboard_instance_apply_witness_test.dag rename to dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag index ba634ea58b6..bcf4df8ed32 100644 --- a/dag/test/claim/roadmap_dashboard_instance_apply_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag @@ -216,7 +216,7 @@ test fn dashboard_service_is_named_and_scoped_off_production() -> Bool { "--source-root", "src/v2", "--entry", - "dag/gunbc/roadmap_serve.dag", + "dag/gunbc/roadmap/roadmap_serve.dag", "--function", "roadmap_serve_handle_srv1_lab", "--host", @@ -406,7 +406,7 @@ test fn dashboard_dirty_controller_source_refuses_before_apply() -> Bool { }, status_read: DashboardExecResult { success: true, - stdout: " M dag/gunbc/roadmap_dashboard_instance.dag", + stdout: " M dag/gunbc/roadmap/roadmap_dashboard_instance.dag", stderr: "", }, shallow_read: DashboardExecResult { diff --git a/dag/test/claim/roadmap_dashboard_instance_witness_test.dag b/dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_dashboard_instance_witness_test.dag rename to dag/test/claim/roadmap/roadmap_dashboard_instance_witness_test.dag diff --git a/dag/test/claim/roadmap_dispatch_actuator_witness_test.dag b/dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_dispatch_actuator_witness_test.dag rename to dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag diff --git a/dag/test/claim/roadmap_dispatch_environment_witness_test.dag b/dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_dispatch_environment_witness_test.dag rename to dag/test/claim/roadmap/roadmap_dispatch_environment_witness_test.dag diff --git a/dag/test/claim/roadmap_document_test.dag b/dag/test/claim/roadmap/roadmap_document_test.dag similarity index 100% rename from dag/test/claim/roadmap_document_test.dag rename to dag/test/claim/roadmap/roadmap_document_test.dag diff --git a/dag/test/claim/roadmap_emit_test.dag b/dag/test/claim/roadmap/roadmap_emit_test.dag similarity index 100% rename from dag/test/claim/roadmap_emit_test.dag rename to dag/test/claim/roadmap/roadmap_emit_test.dag diff --git a/dag/test/claim/roadmap_execution_contract_witness_test.dag b/dag/test/claim/roadmap/roadmap_execution_contract_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_execution_contract_witness_test.dag rename to dag/test/claim/roadmap/roadmap_execution_contract_witness_test.dag diff --git a/dag/test/claim/roadmap_focus_witness_test.dag b/dag/test/claim/roadmap/roadmap_focus_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_focus_witness_test.dag rename to dag/test/claim/roadmap/roadmap_focus_witness_test.dag diff --git a/dag/test/claim/roadmap_forecast_witness_test.dag b/dag/test/claim/roadmap/roadmap_forecast_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_forecast_witness_test.dag rename to dag/test/claim/roadmap/roadmap_forecast_witness_test.dag diff --git a/dag/test/claim/roadmap_frontier_witness_test.dag b/dag/test/claim/roadmap/roadmap_frontier_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_frontier_witness_test.dag rename to dag/test/claim/roadmap/roadmap_frontier_witness_test.dag diff --git a/dag/test/claim/roadmap_gate_test.dag b/dag/test/claim/roadmap/roadmap_gate_test.dag similarity index 100% rename from dag/test/claim/roadmap_gate_test.dag rename to dag/test/claim/roadmap/roadmap_gate_test.dag diff --git a/dag/test/claim/roadmap_identity_witness_test.dag b/dag/test/claim/roadmap/roadmap_identity_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_identity_witness_test.dag rename to dag/test/claim/roadmap/roadmap_identity_witness_test.dag diff --git a/dag/test/claim/roadmap_model_test.dag b/dag/test/claim/roadmap/roadmap_model_test.dag similarity index 100% rename from dag/test/claim/roadmap_model_test.dag rename to dag/test/claim/roadmap/roadmap_model_test.dag diff --git a/dag/test/claim/roadmap_presentation_witness_test.dag b/dag/test/claim/roadmap/roadmap_presentation_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_presentation_witness_test.dag rename to dag/test/claim/roadmap/roadmap_presentation_witness_test.dag diff --git a/dag/test/claim/roadmap_program_view_live_corpus_receipt_test.dag b/dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag similarity index 100% rename from dag/test/claim/roadmap_program_view_live_corpus_receipt_test.dag rename to dag/test/claim/roadmap/roadmap_program_view_live_corpus_receipt_test.dag diff --git a/dag/test/claim/roadmap_program_view_witness_test.dag b/dag/test/claim/roadmap/roadmap_program_view_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_program_view_witness_test.dag rename to dag/test/claim/roadmap/roadmap_program_view_witness_test.dag diff --git a/dag/test/claim/roadmap_provider_events_witness_test.dag b/dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_provider_events_witness_test.dag rename to dag/test/claim/roadmap/roadmap_provider_events_witness_test.dag diff --git a/dag/test/claim/roadmap_publish_observe_witness_test.dag b/dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_publish_observe_witness_test.dag rename to dag/test/claim/roadmap/roadmap_publish_observe_witness_test.dag diff --git a/dag/test/claim/roadmap_publish_witness_test.dag b/dag/test/claim/roadmap/roadmap_publish_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_publish_witness_test.dag rename to dag/test/claim/roadmap/roadmap_publish_witness_test.dag diff --git a/dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_fixture.dag b/dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_fixture.dag new file mode 100644 index 00000000000..e543793667f --- /dev/null +++ b/dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_fixture.dag @@ -0,0 +1,3 @@ +module test.claim.roadmap_receipt_continuity_acceptance_fixture + +data receipt_continuity_acceptance_carrier_fixture_text: String = "{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-git-upstream-model\",\"criteria_digest\":\"b3747b95baf099cc\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.git_upstream_model_execution\",\"witness_fn\":\"witness_git_cli_fixture_hashes_projects_and_independently_reads_back\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/git/object_store.dag\",\"further_artifacts\":[\"dag/test/claim/git_upstream_model_witness_test.dag\",\"dag/test/manual/git_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-mercurial-upstream-model\",\"criteria_digest\":\"c43b17d5134b111d\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.mercurial_upstream_model_execution\",\"witness_fn\":\"witness_mercurial_cli_fixture_projects_and_independently_reads_back\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/mercurial.dag\",\"further_artifacts\":[\"dag/test/claim/mercurial_upstream_model_witness_test.dag\",\"dag/test/manual/mercurial_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-pijul-upstream-model\",\"criteria_digest\":\"098c989bdc87dac7\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.pijul_upstream_model_execution\",\"witness_fn\":\"witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/pijul.dag\",\"further_artifacts\":[\"dag/test/claim/pijul_upstream_model_witness_test.dag\",\"dag/test/manual/pijul_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-claim-indexed-evidence\",\"criteria_digest\":\"2b81ac6aacf6a190\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.claim_indexed_evidence_witness\",\"witness_fn\":\"witness_claim_evidence_roles_are_externally_grounded\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/claim_evidence.dag\",\"further_artifacts\":[\"dag/gunbc/provider_readiness_claim_evidence.dag\",\"dag/gunbc/os_install_claim_evidence.dag\",\"dag/gunbc/source_integration_claim_evidence.dag\",\"dag/test/claim/claim_indexed_evidence_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-compatibility-shape\",\"criteria_digest\":\"f023bb4e862d9e27\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.scm_compatibility_shape_witness\",\"witness_fn\":\"witness_r1_acceptance_contract_holds\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/scm_compatibility_shape.dag\",\"further_artifacts\":[\"dag/gunbc/scm_compatibility/git.dag\",\"dag/gunbc/scm_compatibility/mercurial.dag\",\"dag/gunbc/scm_compatibility/pijul.dag\",\"dag/test/claim/scm/scm_compatibility_shape_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-p0-landing-spine\",\"criteria_digest\":\"9d3aa951e0f5ffa3\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.source_integration_landing_spine_witness\",\"witness_fn\":\"witness_p0_roadmap_acceptance_contract_holds\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/source_integration_landing_spine.dag\",\"further_artifacts\":[\"dag/gunbc/native_scm_interaction_contract.dag\",\"dag/test/claim/source_integration_landing_spine_witness_test.dag\",\"dag/test/claim/native_scm_interaction_contract_witness_test.dag\",\"dag/gunbc/scm_compatibility_shape.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"namespace-occurrence-transport\",\"criteria_digest\":\"d76cf14b12dbf4bf\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.namespace_occurrence_transport_test\",\"witness_fn\":\"namespace_occurrence_equal_text_mints_distinct_ids_holds\",\"executed_on\":\"2026-07-28\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/occurrence_identity.dag\",\"further_artifacts\":[\"dag/test/claim/namespace_occurrence_transport_test.dag\",\"src/v1/tests/claim/pattern_binder_declaration_node_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-28\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"namespace-binding-kernel\",\"criteria_digest\":\"2eba4715cdef42eb\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.occurrence_binding_resolve_witness_test\",\"witness_fn\":\"occurrence_binding_resolve_malformed_transport_refuses_holds\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/occurrence_binding_resolve.dag\",\"further_artifacts\":[\"dag/test/claim/occurrence_binding_resolve_witness_test.dag\",\"src/v1/04_occurrence_binding.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"entry-graph-union-construction\",\"criteria_digest\":\"3502539e920d9e40\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v1-compiler-tests.union_resolve_receipts_test\",\"witness_fn\":\"shared_typecheck_distinct_compute_count_is_order_invariant\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"docs/plans/entry-graph-union-slice2-typecheck-attribution.md\",\"further_artifacts\":[\"docs/plans/receipts/entry-graph-union-slice2/receipt-broad-disjoint.json\",\"docs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-representative-50.json\",\"docs/plans/per-entry-assembly-decomposition-measurement.md\",\"src/v1/tests/src/union_resolve_receipts_test.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"pderive-typesafe-nullary-reflection\",\"criteria_digest\":\"dac83172a613e659\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.manual.coproduct_reflection_conformance\",\"witness_fn\":\"witness_nullary_reflection_rejects_requested_a_with_context_b\",\"executed_on\":\"2026-07-28\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/std/node_query.dag\",\"further_artifacts\":[\"src/v2/test/claim/manual/coproduct_reflection_conformance_test.dag\",\"src/v1/stage0/src/coproduct_reflection.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-28\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"pderive-static-supplemental-contract\",\"criteria_digest\":\"fa6378dabdb12432\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract\",\"witness_fn\":\"nested_generic_swap_red_rejects_swapped_slot_requirements\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/trait_derive_shape.dag\",\"further_artifacts\":[\"dag/extdeps/languages/rust/derive_contracts.dag\",\"src/v2/test/claim/emit/trait_derive_supplemental_generic_bound_contract_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-test-hygiene-producer-retirement\",\"criteria_digest\":\"8f77a4b2e0ee3387\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.test_module_hygiene_hand_rust_equivalence_witness\",\"witness_fn\":\"test_module_hygiene_equivalence_unparsable_refuse_discriminator_holds\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/test_module_hygiene.dag\",\"further_artifacts\":[\"dag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag\",\"src/v1/stage0/src/cli_run/test_module_hygiene_bridge.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-interpreter-primitive-roster\",\"criteria_digest\":\"581758f45921b40a\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.v1_interpreter_primitive_surface_witness_test\",\"witness_fn\":\"shadow_detector_catches_a_planted_duplicate\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/v1/v1_interpreter_primitive_surface.dag\",\"further_artifacts\":[\"dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag\",\"dag/test/claim/primitive_identity_join_witness_test.dag\",\"src/v1/stage0/src/v1_interpreter.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"ladder-measurement-schema\",\"criteria_digest\":\"74da4d8be7125c81\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.guarantee_measurement_witness_test\",\"witness_fn\":\"duplicate_class_id_reds_uniqueness\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/guarantee_measurement.dag\",\"further_artifacts\":[\"dag/test/claim/guarantee_measurement_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v2-emitter-producer-provenance\",\"criteria_digest\":\"f1c76111c83a0a60\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.claim.self_host.emitter_producer_provenance_witness_test\",\"witness_fn\":\"witness_restored_binding_without_executed_receipt_does_not_authorize_reds\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/compiler/self_host/frontier.dag\",\"further_artifacts\":[\"src/v2/test/claim/self_host/emitter_producer_provenance_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-seed-honesty-decision\",\"criteria_digest\":\"1717cfe258d9afe1\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.seed_honesty_discharge_unavailable_test\",\"witness_fn\":\"seed_honesty_undecided_would_keep_closing_contract_red\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/workflow/bootstrap.dag\",\"further_artifacts\":[\"dag/test/claim/seed_honesty_discharge_unavailable_test.dag\",\"dag/gunbc/ci/ci_layer_roots.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n" diff --git a/dag/test/claim/roadmap_receipt_continuity_acceptance_test.dag b/dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_test.dag similarity index 98% rename from dag/test/claim/roadmap_receipt_continuity_acceptance_test.dag rename to dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_test.dag index 9008cd5c60b..588b53cfe26 100644 --- a/dag/test/claim/roadmap_receipt_continuity_acceptance_test.dag +++ b/dag/test/claim/roadmap/roadmap_receipt_continuity_acceptance_test.dag @@ -251,10 +251,10 @@ test fn witness_exact_revocation_admits_vanished_receipt() -> Bool { test fn witness_git_show_exists_on_disk_but_not_in_ref_counts_as_path_absent() -> Bool { git_show_path_absent_at_ref( - stderr: "fatal: path 'dag/gunbc/roadmap_acceptance_event_history.jsonl' exists on disk, but not in '9ce6526c528'", + stderr: "fatal: path 'dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl' exists on disk, but not in '9ce6526c528'", ) && git_show_path_absent_at_ref( - stderr: "fatal: path 'dag/gunbc/roadmap_acceptance_event_history.jsonl' does not exist in '9ce6526c528'", + stderr: "fatal: path 'dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl' does not exist in '9ce6526c528'", ) } diff --git a/dag/test/claim/roadmap_receipt_continuity_live_witness_test.dag b/dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_receipt_continuity_live_witness_test.dag rename to dag/test/claim/roadmap/roadmap_receipt_continuity_live_witness_test.dag diff --git a/dag/test/claim/roadmap_register_witness_test.dag b/dag/test/claim/roadmap/roadmap_register_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_register_witness_test.dag rename to dag/test/claim/roadmap/roadmap_register_witness_test.dag diff --git a/dag/test/claim/roadmap_repo_atlas_sandbox_witness_test.dag b/dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_repo_atlas_sandbox_witness_test.dag rename to dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag diff --git a/dag/test/claim/roadmap_row_witness_test.dag b/dag/test/claim/roadmap/roadmap_row_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_row_witness_test.dag rename to dag/test/claim/roadmap/roadmap_row_witness_test.dag diff --git a/dag/test/claim/roadmap_sandbox_witness_test.dag b/dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_sandbox_witness_test.dag rename to dag/test/claim/roadmap/roadmap_sandbox_witness_test.dag diff --git a/dag/test/claim/roadmap_serve_witness_test.dag b/dag/test/claim/roadmap/roadmap_serve_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_serve_witness_test.dag rename to dag/test/claim/roadmap/roadmap_serve_witness_test.dag diff --git a/dag/test/claim/roadmap_site_healthz_json_parse_witness.dag b/dag/test/claim/roadmap/roadmap_site_healthz_json_parse_witness.dag similarity index 100% rename from dag/test/claim/roadmap_site_healthz_json_parse_witness.dag rename to dag/test/claim/roadmap/roadmap_site_healthz_json_parse_witness.dag diff --git a/dag/test/claim/roadmap_site_surface_readiness_witness_test.dag b/dag/test/claim/roadmap/roadmap_site_surface_readiness_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_site_surface_readiness_witness_test.dag rename to dag/test/claim/roadmap/roadmap_site_surface_readiness_witness_test.dag diff --git a/dag/test/claim/roadmap_spawner_witness_test.dag b/dag/test/claim/roadmap/roadmap_spawner_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_spawner_witness_test.dag rename to dag/test/claim/roadmap/roadmap_spawner_witness_test.dag diff --git a/dag/test/claim/roadmap_static_site_witness_test.dag b/dag/test/claim/roadmap/roadmap_static_site_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_static_site_witness_test.dag rename to dag/test/claim/roadmap/roadmap_static_site_witness_test.dag diff --git a/dag/test/claim/roadmap_status_test.dag b/dag/test/claim/roadmap/roadmap_status_test.dag similarity index 96% rename from dag/test/claim/roadmap_status_test.dag rename to dag/test/claim/roadmap/roadmap_status_test.dag index cf902cdc5fc..7d6b081dce8 100644 --- a/dag/test/claim/roadmap_status_test.dag +++ b/dag/test/claim/roadmap/roadmap_status_test.dag @@ -128,9 +128,9 @@ test fn item_against_prs_drifts() -> Bool { } test fn witness_superseded_is_done_and_names_successor() -> Bool { - let item = SupersededLine { by: "dag/gunbc/v1_deletion_plan.dag", content: "old lane row" } + let item = SupersededLine { by: "dag/gunbc/v1/v1_deletion_plan.dag", content: "old lane row" } item_is_done(item: item, merged: []) - && item_superseded_by(item: item) == "dag/gunbc/v1_deletion_plan.dag" + && item_superseded_by(item: item) == "dag/gunbc/v1/v1_deletion_plan.dag" } test fn witness_superseded_underivable_no_drift() -> Bool { diff --git a/dag/test/claim/roadmap_tactile_witness_test.dag b/dag/test/claim/roadmap/roadmap_tactile_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_tactile_witness_test.dag rename to dag/test/claim/roadmap/roadmap_tactile_witness_test.dag diff --git a/dag/test/claim/roadmap_validation_oracle_witness_test.dag b/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag similarity index 98% rename from dag/test/claim/roadmap_validation_oracle_witness_test.dag rename to dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag index 63b6980b865..4516b0f1d6b 100644 --- a/dag/test/claim/roadmap_validation_oracle_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag @@ -310,7 +310,7 @@ test fn declaration_scan_ignores_the_name_inside_a_note() -> Bool { ) == 1 } -data unpinned_dependency_note: String = "review 45278. The entry-file pin closes the direct attack but leaves a witness's IMPORTED test modules — fixtures and shared assertions, which are oracle rather than subject — outside the digest. The fixture below is the reviewer's own measured specimen reproduced in shape: dag/test/claim/scm_compatibility_shape_witness_test.dag imports four test.claim modules, so weakening one of them would green Verify without moving the pinned entry's digest. The residue is therefore made unreachable rather than deferred: such an oracle refuses. The paired green is what keeps this from being a blanket rejection — a witness importing only subject and std modules still verifies, so the refusal discriminates on the oracle-side dependency rather than on having imports at all." +data unpinned_dependency_note: String = "review 45278. The entry-file pin closes the direct attack but leaves a witness's IMPORTED test modules — fixtures and shared assertions, which are oracle rather than subject — outside the digest. The fixture below is the reviewer's own measured specimen reproduced in shape: dag/test/claim/scm/scm_compatibility_shape_witness_test.dag imports four test.claim modules, so weakening one of them would green Verify without moving the pinned entry's digest. The residue is therefore made unreachable rather than deferred: such an oracle refuses. The paired green is what keeps this from being a blanket rejection — a witness importing only subject and std modules still verifies, so the refusal discriminates on the oracle-side dependency rather than on having imports at all." fn witness_source_importing_test_helpers() -> String { join([ @@ -784,7 +784,7 @@ fn receipt_for(verdict: ValidationVerdict) -> String { executions: [ ValidationExecution { validation: GunbcClaimValidation { - entry: "dag/test/claim/roadmap_validation_oracle_witness_test.dag" as FilePath, + entry: "dag/test/claim/roadmap/roadmap_validation_oracle_witness_test.dag" as FilePath, function: "verify_lamp_stays_pending_without_a_receipt" as NonEmptyStr, }, command: ModeledValidationCommand { diff --git a/dag/test/claim/roadmap_verification_receipt_witness_test.dag b/dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_verification_receipt_witness_test.dag rename to dag/test/claim/roadmap/roadmap_verification_receipt_witness_test.dag diff --git a/dag/test/claim/roadmap_verify_witness_test.dag b/dag/test/claim/roadmap/roadmap_verify_witness_test.dag similarity index 99% rename from dag/test/claim/roadmap_verify_witness_test.dag rename to dag/test/claim/roadmap/roadmap_verify_witness_test.dag index c02f07ad9b6..255d017a523 100644 --- a/dag/test/claim/roadmap_verify_witness_test.dag +++ b/dag/test/claim/roadmap/roadmap_verify_witness_test.dag @@ -78,7 +78,7 @@ fn empty_contract() -> WorkItemExecutionContract { fn one_validation_contract() -> WorkItemExecutionContract { gunbc_claim_execution_contract( - entry: "dag/test/claim/roadmap_verify_witness_test.dag" as FilePath, + entry: "dag/test/claim/roadmap/roadmap_verify_witness_test.dag" as FilePath, function: "roadmap_verify_keystone_holds" as NonEmptyStr, ) } diff --git a/dag/test/claim/roadmap_workflow_command_witness_test.dag b/dag/test/claim/roadmap/roadmap_workflow_command_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_workflow_command_witness_test.dag rename to dag/test/claim/roadmap/roadmap_workflow_command_witness_test.dag diff --git a/dag/test/claim/roadmap_workflow_progress_witness_test.dag b/dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag similarity index 100% rename from dag/test/claim/roadmap_workflow_progress_witness_test.dag rename to dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag diff --git a/dag/test/claim/roadmap_receipt_continuity_acceptance_fixture.dag b/dag/test/claim/roadmap_receipt_continuity_acceptance_fixture.dag deleted file mode 100644 index 59f319c12ba..00000000000 --- a/dag/test/claim/roadmap_receipt_continuity_acceptance_fixture.dag +++ /dev/null @@ -1,3 +0,0 @@ -module test.claim.roadmap_receipt_continuity_acceptance_fixture - -data receipt_continuity_acceptance_carrier_fixture_text: String = "{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-git-upstream-model\",\"criteria_digest\":\"b3747b95baf099cc\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.git_upstream_model_execution\",\"witness_fn\":\"witness_git_cli_fixture_hashes_projects_and_independently_reads_back\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/git/object_store.dag\",\"further_artifacts\":[\"dag/test/claim/git_upstream_model_witness_test.dag\",\"dag/test/manual/git_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-mercurial-upstream-model\",\"criteria_digest\":\"c43b17d5134b111d\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.mercurial_upstream_model_execution\",\"witness_fn\":\"witness_mercurial_cli_fixture_projects_and_independently_reads_back\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/mercurial.dag\",\"further_artifacts\":[\"dag/test/claim/mercurial_upstream_model_witness_test.dag\",\"dag/test/manual/mercurial_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-pijul-upstream-model\",\"criteria_digest\":\"098c989bdc87dac7\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.manual.pijul_upstream_model_execution\",\"witness_fn\":\"witness_pijul_cli_fixture_reads_channel_sets_and_retained_conflict\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/extdeps/pijul.dag\",\"further_artifacts\":[\"dag/test/claim/pijul_upstream_model_witness_test.dag\",\"dag/test/manual/pijul_upstream_model_execution_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-claim-indexed-evidence\",\"criteria_digest\":\"2b81ac6aacf6a190\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.claim_indexed_evidence_witness\",\"witness_fn\":\"witness_claim_evidence_roles_are_externally_grounded\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/claim_evidence.dag\",\"further_artifacts\":[\"dag/gunbc/provider_readiness_claim_evidence.dag\",\"dag/gunbc/os_install_claim_evidence.dag\",\"dag/gunbc/source_integration_claim_evidence.dag\",\"dag/test/claim/claim_indexed_evidence_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-compatibility-shape\",\"criteria_digest\":\"f023bb4e862d9e27\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.scm_compatibility_shape_witness\",\"witness_fn\":\"witness_r1_acceptance_contract_holds\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/scm_compatibility_shape.dag\",\"further_artifacts\":[\"dag/gunbc/scm_compatibility/git.dag\",\"dag/gunbc/scm_compatibility/mercurial.dag\",\"dag/gunbc/scm_compatibility/pijul.dag\",\"dag/test/claim/scm_compatibility_shape_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"2-scm-p0-landing-spine\",\"criteria_digest\":\"9d3aa951e0f5ffa3\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.source_integration_landing_spine_witness\",\"witness_fn\":\"witness_p0_roadmap_acceptance_contract_holds\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/source_integration_landing_spine.dag\",\"further_artifacts\":[\"dag/gunbc/native_scm_interaction_contract.dag\",\"dag/test/claim/source_integration_landing_spine_witness_test.dag\",\"dag/test/claim/native_scm_interaction_contract_witness_test.dag\",\"dag/gunbc/scm_compatibility_shape.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"namespace-occurrence-transport\",\"criteria_digest\":\"d76cf14b12dbf4bf\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.namespace_occurrence_transport_test\",\"witness_fn\":\"namespace_occurrence_equal_text_mints_distinct_ids_holds\",\"executed_on\":\"2026-07-28\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/occurrence_identity.dag\",\"further_artifacts\":[\"dag/test/claim/namespace_occurrence_transport_test.dag\",\"src/v1/tests/claim/pattern_binder_declaration_node_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-28\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"namespace-binding-kernel\",\"criteria_digest\":\"2eba4715cdef42eb\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.occurrence_binding_resolve_witness_test\",\"witness_fn\":\"occurrence_binding_resolve_malformed_transport_refuses_holds\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/occurrence_binding_resolve.dag\",\"further_artifacts\":[\"dag/test/claim/occurrence_binding_resolve_witness_test.dag\",\"src/v1/04_occurrence_binding.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"entry-graph-union-construction\",\"criteria_digest\":\"3502539e920d9e40\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v1-compiler-tests.union_resolve_receipts_test\",\"witness_fn\":\"shared_typecheck_distinct_compute_count_is_order_invariant\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"docs/plans/entry-graph-union-slice2-typecheck-attribution.md\",\"further_artifacts\":[\"docs/plans/receipts/entry-graph-union-slice2/receipt-broad-disjoint.json\",\"docs/plans/receipts/entry-graph-union-slice2/receipt-post-merge-representative-50.json\",\"docs/plans/per-entry-assembly-decomposition-measurement.md\",\"src/v1/tests/src/union_resolve_receipts_test.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"pderive-typesafe-nullary-reflection\",\"criteria_digest\":\"dac83172a613e659\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.manual.coproduct_reflection_conformance\",\"witness_fn\":\"witness_nullary_reflection_rejects_requested_a_with_context_b\",\"executed_on\":\"2026-07-28\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/std/node_query.dag\",\"further_artifacts\":[\"src/v2/test/claim/manual/coproduct_reflection_conformance_test.dag\",\"src/v1/stage0/src/coproduct_reflection.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-28\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"pderive-static-supplemental-contract\",\"criteria_digest\":\"fa6378dabdb12432\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.claim.emit.trait_derive_supplemental_generic_bound_contract\",\"witness_fn\":\"nested_generic_swap_red_rejects_swapped_slot_requirements\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/std/trait_derive_shape.dag\",\"further_artifacts\":[\"dag/extdeps/languages/rust/derive_contracts.dag\",\"src/v2/test/claim/emit/trait_derive_supplemental_generic_bound_contract_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-test-hygiene-producer-retirement\",\"criteria_digest\":\"8f77a4b2e0ee3387\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.test_module_hygiene_hand_rust_equivalence_witness\",\"witness_fn\":\"test_module_hygiene_equivalence_unparsable_refuse_discriminator_holds\",\"executed_on\":\"2026-07-29\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/test_module_hygiene.dag\",\"further_artifacts\":[\"dag/test/claim/test_module_hygiene_hand_rust_equivalence_witness_test.dag\",\"src/v1/stage0/src/cli_run/test_module_hygiene_bridge.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-07-29\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-interpreter-primitive-roster\",\"criteria_digest\":\"581758f45921b40a\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.v1_interpreter_primitive_surface_witness_test\",\"witness_fn\":\"shadow_detector_catches_a_planted_duplicate\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/v1_interpreter_primitive_surface.dag\",\"further_artifacts\":[\"dag/test/claim/v1_interpreter_primitive_surface_witness_test.dag\",\"dag/test/claim/primitive_identity_join_witness_test.dag\",\"src/v1/stage0/src/v1_interpreter.rs\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"ladder-measurement-schema\",\"criteria_digest\":\"74da4d8be7125c81\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.guarantee_measurement_witness_test\",\"witness_fn\":\"duplicate_class_id_reds_uniqueness\",\"executed_on\":\"2026-08-01\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"dag/gunbc/guarantee_measurement.dag\",\"further_artifacts\":[\"dag/test/claim/guarantee_measurement_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-01\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v2-emitter-producer-provenance\",\"criteria_digest\":\"f1c76111c83a0a60\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"v2.test.claim.self_host.emitter_producer_provenance_witness_test\",\"witness_fn\":\"witness_restored_binding_without_executed_receipt_does_not_authorize_reds\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/compiler/self_host/frontier.dag\",\"further_artifacts\":[\"src/v2/test/claim/self_host/emitter_producer_provenance_witness_test.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n{\"variant\":\"acceptance_recorded\",\"receipt\":{\"node\":\"v1-seed-honesty-decision\",\"criteria_digest\":\"1717cfe258d9afe1\",\"red_control\":{\"variant\":\"red_control_executed\",\"witness_module\":\"test.claim.seed_honesty_discharge_unavailable_test\",\"witness_fn\":\"seed_honesty_undecided_would_keep_closing_contract_red\",\"executed_on\":\"2026-08-02\"},\"handback\":{\"variant\":\"handback_delivered\",\"first_artifact\":\"src/v2/workflow/bootstrap.dag\",\"further_artifacts\":[\"dag/test/claim/seed_honesty_discharge_unavailable_test.dag\",\"dag/gunbc/ci_layer_roots.dag\"]},\"accepted_by\":\"operator\",\"accepted_on\":\"2026-08-02\"}}\n" diff --git a/dag/test/claim/runner_activation_wall_test.dag b/dag/test/claim/runner/runner_activation_wall_test.dag similarity index 100% rename from dag/test/claim/runner_activation_wall_test.dag rename to dag/test/claim/runner/runner_activation_wall_test.dag diff --git a/dag/test/claim/runner_broker_progress_watchdog_witness_test.dag b/dag/test/claim/runner/runner_broker_progress_watchdog_witness_test.dag similarity index 100% rename from dag/test/claim/runner_broker_progress_watchdog_witness_test.dag rename to dag/test/claim/runner/runner_broker_progress_watchdog_witness_test.dag diff --git a/dag/test/claim/runner_capacity_operator_access_witness_test.dag b/dag/test/claim/runner/runner_capacity_operator_access_witness_test.dag similarity index 100% rename from dag/test/claim/runner_capacity_operator_access_witness_test.dag rename to dag/test/claim/runner/runner_capacity_operator_access_witness_test.dag diff --git a/dag/test/claim/runner_capacity_plan_witness_test.dag b/dag/test/claim/runner/runner_capacity_plan_witness_test.dag similarity index 100% rename from dag/test/claim/runner_capacity_plan_witness_test.dag rename to dag/test/claim/runner/runner_capacity_plan_witness_test.dag diff --git a/dag/test/claim/runner_capacity_realize_witness_test.dag b/dag/test/claim/runner/runner_capacity_realize_witness_test.dag similarity index 100% rename from dag/test/claim/runner_capacity_realize_witness_test.dag rename to dag/test/claim/runner/runner_capacity_realize_witness_test.dag diff --git a/dag/test/claim/runner_connectivity_recovery_witness_test.dag b/dag/test/claim/runner/runner_connectivity_recovery_witness_test.dag similarity index 100% rename from dag/test/claim/runner_connectivity_recovery_witness_test.dag rename to dag/test/claim/runner/runner_connectivity_recovery_witness_test.dag diff --git a/dag/test/claim/runner_connectivity_repair_plan_witness_test.dag b/dag/test/claim/runner/runner_connectivity_repair_plan_witness_test.dag similarity index 100% rename from dag/test/claim/runner_connectivity_repair_plan_witness_test.dag rename to dag/test/claim/runner/runner_connectivity_repair_plan_witness_test.dag diff --git a/dag/test/claim/runner_host_deploy_witness_test.dag b/dag/test/claim/runner/runner_host_deploy_witness_test.dag similarity index 100% rename from dag/test/claim/runner_host_deploy_witness_test.dag rename to dag/test/claim/runner/runner_host_deploy_witness_test.dag diff --git a/dag/test/claim/runner_lifecycle_witness_test.dag b/dag/test/claim/runner/runner_lifecycle_witness_test.dag similarity index 100% rename from dag/test/claim/runner_lifecycle_witness_test.dag rename to dag/test/claim/runner/runner_lifecycle_witness_test.dag diff --git a/dag/test/claim/runner_local_state_witness_test.dag b/dag/test/claim/runner/runner_local_state_witness_test.dag similarity index 100% rename from dag/test/claim/runner_local_state_witness_test.dag rename to dag/test/claim/runner/runner_local_state_witness_test.dag diff --git a/dag/test/claim/runner_placement_witness_test.dag b/dag/test/claim/runner/runner_placement_witness_test.dag similarity index 100% rename from dag/test/claim/runner_placement_witness_test.dag rename to dag/test/claim/runner/runner_placement_witness_test.dag diff --git a/dag/test/claim/runner_replace_incarnation_seam_witness_test.dag b/dag/test/claim/runner/runner_replace_incarnation_seam_witness_test.dag similarity index 100% rename from dag/test/claim/runner_replace_incarnation_seam_witness_test.dag rename to dag/test/claim/runner/runner_replace_incarnation_seam_witness_test.dag diff --git a/dag/test/claim/runner_service_activation_witness_test.dag b/dag/test/claim/runner/runner_service_activation_witness_test.dag similarity index 100% rename from dag/test/claim/runner_service_activation_witness_test.dag rename to dag/test/claim/runner/runner_service_activation_witness_test.dag diff --git a/dag/test/claim/runner_slot_allocation_witness_test.dag b/dag/test/claim/runner/runner_slot_allocation_witness_test.dag similarity index 100% rename from dag/test/claim/runner_slot_allocation_witness_test.dag rename to dag/test/claim/runner/runner_slot_allocation_witness_test.dag diff --git a/dag/test/claim/runner_slot_enforcement_grounding_witness_test.dag b/dag/test/claim/runner/runner_slot_enforcement_grounding_witness_test.dag similarity index 100% rename from dag/test/claim/runner_slot_enforcement_grounding_witness_test.dag rename to dag/test/claim/runner/runner_slot_enforcement_grounding_witness_test.dag diff --git a/dag/test/claim/runner_slot_installation_state_witness_test.dag b/dag/test/claim/runner/runner_slot_installation_state_witness_test.dag similarity index 100% rename from dag/test/claim/runner_slot_installation_state_witness_test.dag rename to dag/test/claim/runner/runner_slot_installation_state_witness_test.dag diff --git a/dag/test/claim/runner_slot_provision_witness_test.dag b/dag/test/claim/runner/runner_slot_provision_witness_test.dag similarity index 100% rename from dag/test/claim/runner_slot_provision_witness_test.dag rename to dag/test/claim/runner/runner_slot_provision_witness_test.dag diff --git a/dag/test/claim/runner_unit_file_witness_test.dag b/dag/test/claim/runner/runner_unit_file_witness_test.dag similarity index 100% rename from dag/test/claim/runner_unit_file_witness_test.dag rename to dag/test/claim/runner/runner_unit_file_witness_test.dag diff --git a/dag/test/claim/runner_unit_live_read_witness_test.dag b/dag/test/claim/runner/runner_unit_live_read_witness_test.dag similarity index 100% rename from dag/test/claim/runner_unit_live_read_witness_test.dag rename to dag/test/claim/runner/runner_unit_live_read_witness_test.dag diff --git a/dag/test/claim/scm_agentic_stress_witness_test.dag b/dag/test/claim/scm/scm_agentic_stress_witness_test.dag similarity index 100% rename from dag/test/claim/scm_agentic_stress_witness_test.dag rename to dag/test/claim/scm/scm_agentic_stress_witness_test.dag diff --git a/dag/test/claim/scm_ancestry_witness_test.dag b/dag/test/claim/scm/scm_ancestry_witness_test.dag similarity index 100% rename from dag/test/claim/scm_ancestry_witness_test.dag rename to dag/test/claim/scm/scm_ancestry_witness_test.dag diff --git a/dag/test/claim/scm_authoring_witness_test.dag b/dag/test/claim/scm/scm_authoring_witness_test.dag similarity index 100% rename from dag/test/claim/scm_authoring_witness_test.dag rename to dag/test/claim/scm/scm_authoring_witness_test.dag diff --git a/dag/test/claim/scm_checkout_verb_witness_test.dag b/dag/test/claim/scm/scm_checkout_verb_witness_test.dag similarity index 100% rename from dag/test/claim/scm_checkout_verb_witness_test.dag rename to dag/test/claim/scm/scm_checkout_verb_witness_test.dag diff --git a/dag/test/claim/scm_commit_closure_json_v2_witness_test.dag b/dag/test/claim/scm/scm_commit_closure_json_v2_witness_test.dag similarity index 100% rename from dag/test/claim/scm_commit_closure_json_v2_witness_test.dag rename to dag/test/claim/scm/scm_commit_closure_json_v2_witness_test.dag diff --git a/dag/test/claim/scm_commit_closure_witness_test.dag b/dag/test/claim/scm/scm_commit_closure_witness_test.dag similarity index 100% rename from dag/test/claim/scm_commit_closure_witness_test.dag rename to dag/test/claim/scm/scm_commit_closure_witness_test.dag diff --git a/dag/test/claim/scm_compatibility_git_witness_test.dag b/dag/test/claim/scm/scm_compatibility_git_witness_test.dag similarity index 100% rename from dag/test/claim/scm_compatibility_git_witness_test.dag rename to dag/test/claim/scm/scm_compatibility_git_witness_test.dag diff --git a/dag/test/claim/scm_compatibility_mercurial_witness_test.dag b/dag/test/claim/scm/scm_compatibility_mercurial_witness_test.dag similarity index 100% rename from dag/test/claim/scm_compatibility_mercurial_witness_test.dag rename to dag/test/claim/scm/scm_compatibility_mercurial_witness_test.dag diff --git a/dag/test/claim/scm_compatibility_pijul_witness_test.dag b/dag/test/claim/scm/scm_compatibility_pijul_witness_test.dag similarity index 100% rename from dag/test/claim/scm_compatibility_pijul_witness_test.dag rename to dag/test/claim/scm/scm_compatibility_pijul_witness_test.dag diff --git a/dag/test/claim/scm_compatibility_shape_witness_test.dag b/dag/test/claim/scm/scm_compatibility_shape_witness_test.dag similarity index 100% rename from dag/test/claim/scm_compatibility_shape_witness_test.dag rename to dag/test/claim/scm/scm_compatibility_shape_witness_test.dag diff --git a/dag/test/claim/scm_issuer_corpus_witness_test.dag b/dag/test/claim/scm/scm_issuer_corpus_witness_test.dag similarity index 100% rename from dag/test/claim/scm_issuer_corpus_witness_test.dag rename to dag/test/claim/scm/scm_issuer_corpus_witness_test.dag diff --git a/dag/test/claim/scm_load_standing_witness_test.dag b/dag/test/claim/scm/scm_load_standing_witness_test.dag similarity index 100% rename from dag/test/claim/scm_load_standing_witness_test.dag rename to dag/test/claim/scm/scm_load_standing_witness_test.dag diff --git a/dag/test/claim/scm_log_witness_test.dag b/dag/test/claim/scm/scm_log_witness_test.dag similarity index 100% rename from dag/test/claim/scm_log_witness_test.dag rename to dag/test/claim/scm/scm_log_witness_test.dag diff --git a/dag/test/claim/scm_merge_witness_test.dag b/dag/test/claim/scm/scm_merge_witness_test.dag similarity index 100% rename from dag/test/claim/scm_merge_witness_test.dag rename to dag/test/claim/scm/scm_merge_witness_test.dag diff --git a/dag/test/claim/scm_object_store_collision_witness_test.dag b/dag/test/claim/scm/scm_object_store_collision_witness_test.dag similarity index 100% rename from dag/test/claim/scm_object_store_collision_witness_test.dag rename to dag/test/claim/scm/scm_object_store_collision_witness_test.dag diff --git a/dag/test/claim/scm_object_store_witness_test.dag b/dag/test/claim/scm/scm_object_store_witness_test.dag similarity index 100% rename from dag/test/claim/scm_object_store_witness_test.dag rename to dag/test/claim/scm/scm_object_store_witness_test.dag diff --git a/dag/test/claim/scm_provider_matrix_witness_test.dag b/dag/test/claim/scm/scm_provider_matrix_witness_test.dag similarity index 100% rename from dag/test/claim/scm_provider_matrix_witness_test.dag rename to dag/test/claim/scm/scm_provider_matrix_witness_test.dag diff --git a/dag/test/claim/scm_read_command_witness_test.dag b/dag/test/claim/scm/scm_read_command_witness_test.dag similarity index 100% rename from dag/test/claim/scm_read_command_witness_test.dag rename to dag/test/claim/scm/scm_read_command_witness_test.dag diff --git a/dag/test/claim/scm_render_witness_test.dag b/dag/test/claim/scm/scm_render_witness_test.dag similarity index 100% rename from dag/test/claim/scm_render_witness_test.dag rename to dag/test/claim/scm/scm_render_witness_test.dag diff --git a/dag/test/claim/scm_repository_envelope_witness_test.dag b/dag/test/claim/scm/scm_repository_envelope_witness_test.dag similarity index 100% rename from dag/test/claim/scm_repository_envelope_witness_test.dag rename to dag/test/claim/scm/scm_repository_envelope_witness_test.dag diff --git a/dag/test/claim/scm_repository_load_witness_test.dag b/dag/test/claim/scm/scm_repository_load_witness_test.dag similarity index 100% rename from dag/test/claim/scm_repository_load_witness_test.dag rename to dag/test/claim/scm/scm_repository_load_witness_test.dag diff --git a/dag/test/claim/scm_serving_model_witness_test.dag b/dag/test/claim/scm/scm_serving_model_witness_test.dag similarity index 100% rename from dag/test/claim/scm_serving_model_witness_test.dag rename to dag/test/claim/scm/scm_serving_model_witness_test.dag diff --git a/dag/test/claim/scm_status_witness_test.dag b/dag/test/claim/scm/scm_status_witness_test.dag similarity index 100% rename from dag/test/claim/scm_status_witness_test.dag rename to dag/test/claim/scm/scm_status_witness_test.dag diff --git a/dag/test/claim/scm_supersession_witness_test.dag b/dag/test/claim/scm/scm_supersession_witness_test.dag similarity index 100% rename from dag/test/claim/scm_supersession_witness_test.dag rename to dag/test/claim/scm/scm_supersession_witness_test.dag diff --git a/dag/test/claim/spark_bootstrap_provision_witness_test.dag b/dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag similarity index 100% rename from dag/test/claim/spark_bootstrap_provision_witness_test.dag rename to dag/test/claim/spark/spark_bootstrap_provision_witness_test.dag diff --git a/dag/test/claim/spark_capability_observation_witness_test.dag b/dag/test/claim/spark/spark_capability_observation_witness_test.dag similarity index 100% rename from dag/test/claim/spark_capability_observation_witness_test.dag rename to dag/test/claim/spark/spark_capability_observation_witness_test.dag diff --git a/dag/test/claim/spark_credential_workflow_witness_test.dag b/dag/test/claim/spark/spark_credential_workflow_witness_test.dag similarity index 100% rename from dag/test/claim/spark_credential_workflow_witness_test.dag rename to dag/test/claim/spark/spark_credential_workflow_witness_test.dag diff --git a/dag/test/claim/spark_grant_privileged_operation_witness_test.dag b/dag/test/claim/spark/spark_grant_privileged_operation_witness_test.dag similarity index 100% rename from dag/test/claim/spark_grant_privileged_operation_witness_test.dag rename to dag/test/claim/spark/spark_grant_privileged_operation_witness_test.dag diff --git a/dag/test/claim/spark_managed_grant_install_witness_test.dag b/dag/test/claim/spark/spark_managed_grant_install_witness_test.dag similarity index 100% rename from dag/test/claim/spark_managed_grant_install_witness_test.dag rename to dag/test/claim/spark/spark_managed_grant_install_witness_test.dag diff --git a/dag/test/claim/spark_managed_grant_reconcile_witness_test.dag b/dag/test/claim/spark/spark_managed_grant_reconcile_witness_test.dag similarity index 100% rename from dag/test/claim/spark_managed_grant_reconcile_witness_test.dag rename to dag/test/claim/spark/spark_managed_grant_reconcile_witness_test.dag diff --git a/dag/test/claim/spark_secret_access_ensure_witness_test.dag b/dag/test/claim/spark/spark_secret_access_ensure_witness_test.dag similarity index 100% rename from dag/test/claim/spark_secret_access_ensure_witness_test.dag rename to dag/test/claim/spark/spark_secret_access_ensure_witness_test.dag diff --git a/dag/test/claim/spark_serving_boot_provenance_witness_test.dag b/dag/test/claim/spark/spark_serving_boot_provenance_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_boot_provenance_witness_test.dag rename to dag/test/claim/spark/spark_serving_boot_provenance_witness_test.dag diff --git a/dag/test/claim/spark_serving_converge_slice_witness_test.dag b/dag/test/claim/spark/spark_serving_converge_slice_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_converge_slice_witness_test.dag rename to dag/test/claim/spark/spark_serving_converge_slice_witness_test.dag diff --git a/dag/test/claim/spark_serving_durability_transaction_witness_test.dag b/dag/test/claim/spark/spark_serving_durability_transaction_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_durability_transaction_witness_test.dag rename to dag/test/claim/spark/spark_serving_durability_transaction_witness_test.dag diff --git a/dag/test/claim/spark_serving_durability_witness_test.dag b/dag/test/claim/spark/spark_serving_durability_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_durability_witness_test.dag rename to dag/test/claim/spark/spark_serving_durability_witness_test.dag diff --git a/dag/test/claim/spark_serving_effect_wire_witness_test.dag b/dag/test/claim/spark/spark_serving_effect_wire_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_effect_wire_witness_test.dag rename to dag/test/claim/spark/spark_serving_effect_wire_witness_test.dag diff --git a/dag/test/claim/spark_serving_full_plan_witness_test.dag b/dag/test/claim/spark/spark_serving_full_plan_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_full_plan_witness_test.dag rename to dag/test/claim/spark/spark_serving_full_plan_witness_test.dag diff --git a/dag/test/claim/spark_serving_member_realization_witness_test.dag b/dag/test/claim/spark/spark_serving_member_realization_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_member_realization_witness_test.dag rename to dag/test/claim/spark/spark_serving_member_realization_witness_test.dag diff --git a/dag/test/claim/spark_serving_membership_witness_test.dag b/dag/test/claim/spark/spark_serving_membership_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_membership_witness_test.dag rename to dag/test/claim/spark/spark_serving_membership_witness_test.dag diff --git a/dag/test/claim/spark_serving_model_materialization_witness_test.dag b/dag/test/claim/spark/spark_serving_model_materialization_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_model_materialization_witness_test.dag rename to dag/test/claim/spark/spark_serving_model_materialization_witness_test.dag diff --git a/dag/test/claim/spark_serving_model_store_witness_test.dag b/dag/test/claim/spark/spark_serving_model_store_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_model_store_witness_test.dag rename to dag/test/claim/spark/spark_serving_model_store_witness_test.dag diff --git a/dag/test/claim/spark_serving_observe_witness_test.dag b/dag/test/claim/spark/spark_serving_observe_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_observe_witness_test.dag rename to dag/test/claim/spark/spark_serving_observe_witness_test.dag diff --git a/dag/test/claim/spark_serving_realization_witness_test.dag b/dag/test/claim/spark/spark_serving_realization_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_realization_witness_test.dag rename to dag/test/claim/spark/spark_serving_realization_witness_test.dag diff --git a/dag/test/claim/spark_serving_reboot_probe_witness_test.dag b/dag/test/claim/spark/spark_serving_reboot_probe_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_reboot_probe_witness_test.dag rename to dag/test/claim/spark/spark_serving_reboot_probe_witness_test.dag diff --git a/dag/test/claim/spark_serving_release_witness_test.dag b/dag/test/claim/spark/spark_serving_release_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_release_witness_test.dag rename to dag/test/claim/spark/spark_serving_release_witness_test.dag diff --git a/dag/test/claim/spark_serving_runtime_install_witness_test.dag b/dag/test/claim/spark/spark_serving_runtime_install_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_runtime_install_witness_test.dag rename to dag/test/claim/spark/spark_serving_runtime_install_witness_test.dag diff --git a/dag/test/claim/spark_serving_runtime_receipt_witness_test.dag b/dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_runtime_receipt_witness_test.dag rename to dag/test/claim/spark/spark_serving_runtime_receipt_witness_test.dag diff --git a/dag/test/claim/spark_serving_terminal_health_witness_test.dag b/dag/test/claim/spark/spark_serving_terminal_health_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_terminal_health_witness_test.dag rename to dag/test/claim/spark/spark_serving_terminal_health_witness_test.dag diff --git a/dag/test/claim/spark_serving_unit_observation_witness_test.dag b/dag/test/claim/spark/spark_serving_unit_observation_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_unit_observation_witness_test.dag rename to dag/test/claim/spark/spark_serving_unit_observation_witness_test.dag diff --git a/dag/test/claim/spark_serving_unit_render_witness_test.dag b/dag/test/claim/spark/spark_serving_unit_render_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_unit_render_witness_test.dag rename to dag/test/claim/spark/spark_serving_unit_render_witness_test.dag diff --git a/dag/test/claim/spark_serving_write_unit_operation_witness_test.dag b/dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag similarity index 100% rename from dag/test/claim/spark_serving_write_unit_operation_witness_test.dag rename to dag/test/claim/spark/spark_serving_write_unit_operation_witness_test.dag diff --git a/dag/test/claim/srv3_bmc_credential_resolve_witness_test.dag b/dag/test/claim/srv3/srv3_bmc_credential_resolve_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_bmc_credential_resolve_witness_test.dag rename to dag/test/claim/srv3/srv3_bmc_credential_resolve_witness_test.dag diff --git a/dag/test/claim/srv3_boot_once_cd_witness_test.dag b/dag/test/claim/srv3/srv3_boot_once_cd_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_boot_once_cd_witness_test.dag rename to dag/test/claim/srv3/srv3_boot_once_cd_witness_test.dag diff --git a/dag/test/claim/srv3_host_effect_apply_witness_test.dag b/dag/test/claim/srv3/srv3_host_effect_apply_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_host_effect_apply_witness_test.dag rename to dag/test/claim/srv3/srv3_host_effect_apply_witness_test.dag diff --git a/dag/test/claim/srv3_host_effect_realize_witness_test.dag b/dag/test/claim/srv3/srv3_host_effect_realize_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_host_effect_realize_witness_test.dag rename to dag/test/claim/srv3/srv3_host_effect_realize_witness_test.dag diff --git a/dag/test/claim/srv3_install_media_fetch_real_execution_witness_test.dag b/dag/test/claim/srv3/srv3_install_media_fetch_real_execution_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_install_media_fetch_real_execution_witness_test.dag rename to dag/test/claim/srv3/srv3_install_media_fetch_real_execution_witness_test.dag diff --git a/dag/test/claim/srv3_install_media_fetch_witness_test.dag b/dag/test/claim/srv3/srv3_install_media_fetch_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_install_media_fetch_witness_test.dag rename to dag/test/claim/srv3/srv3_install_media_fetch_witness_test.dag diff --git a/dag/test/claim/srv3_install_server_emit_test.dag b/dag/test/claim/srv3/srv3_install_server_emit_test.dag similarity index 100% rename from dag/test/claim/srv3_install_server_emit_test.dag rename to dag/test/claim/srv3/srv3_install_server_emit_test.dag diff --git a/dag/test/claim/srv3_network_identity_subsumption_witness_test.dag b/dag/test/claim/srv3/srv3_network_identity_subsumption_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_network_identity_subsumption_witness_test.dag rename to dag/test/claim/srv3/srv3_network_identity_subsumption_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_actuate_scope_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_actuate_scope_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_actuate_scope_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_actuate_scope_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_actuate_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_actuate_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_actuate_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_actuate_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_actuate_workflow_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_actuate_workflow_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_actuate_workflow_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_actuator_toolchain_ensure_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_actuator_toolchain_ensure_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_actuator_toolchain_ensure_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_actuator_toolchain_ensure_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_diagnostic_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_diagnostic_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_diagnostic_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_diagnostic_witness_test.dag diff --git a/dag/test/claim/srv3_os_install_emit_test.dag b/dag/test/claim/srv3/srv3_os_install_emit_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_emit_test.dag rename to dag/test/claim/srv3/srv3_os_install_emit_test.dag diff --git a/dag/test/claim/srv3_os_install_witness_test.dag b/dag/test/claim/srv3/srv3_os_install_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_os_install_witness_test.dag rename to dag/test/claim/srv3/srv3_os_install_witness_test.dag diff --git a/dag/test/claim/srv3_path_ownership_witness_test.dag b/dag/test/claim/srv3/srv3_path_ownership_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_path_ownership_witness_test.dag rename to dag/test/claim/srv3/srv3_path_ownership_witness_test.dag diff --git a/dag/test/claim/srv3_principal_privilege_witness_test.dag b/dag/test/claim/srv3/srv3_principal_privilege_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_principal_privilege_witness_test.dag rename to dag/test/claim/srv3/srv3_principal_privilege_witness_test.dag diff --git a/dag/test/claim/srv3_runner_memory_cap_plan_verify_witness_test.dag b/dag/test/claim/srv3/srv3_runner_memory_cap_plan_verify_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_runner_memory_cap_plan_verify_witness_test.dag rename to dag/test/claim/srv3/srv3_runner_memory_cap_plan_verify_witness_test.dag diff --git a/dag/test/claim/srv3_runner_memory_converge_witness_test.dag b/dag/test/claim/srv3/srv3_runner_memory_converge_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_runner_memory_converge_witness_test.dag rename to dag/test/claim/srv3/srv3_runner_memory_converge_witness_test.dag diff --git a/dag/test/claim/srv3_seeded_install_media_real_execution_witness_test.dag b/dag/test/claim/srv3/srv3_seeded_install_media_real_execution_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_seeded_install_media_real_execution_witness_test.dag rename to dag/test/claim/srv3/srv3_seeded_install_media_real_execution_witness_test.dag diff --git a/dag/test/claim/srv3_seeded_install_media_witness_test.dag b/dag/test/claim/srv3/srv3_seeded_install_media_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_seeded_install_media_witness_test.dag rename to dag/test/claim/srv3/srv3_seeded_install_media_witness_test.dag diff --git a/dag/test/claim/srv3_subsumption_witness_test.dag b/dag/test/claim/srv3/srv3_subsumption_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_subsumption_witness_test.dag rename to dag/test/claim/srv3/srv3_subsumption_witness_test.dag diff --git a/dag/test/claim/srv3_token_subject_witness_test.dag b/dag/test/claim/srv3/srv3_token_subject_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_token_subject_witness_test.dag rename to dag/test/claim/srv3/srv3_token_subject_witness_test.dag diff --git a/dag/test/claim/srv3_tool_acquisition_witness_test.dag b/dag/test/claim/srv3/srv3_tool_acquisition_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_tool_acquisition_witness_test.dag rename to dag/test/claim/srv3/srv3_tool_acquisition_witness_test.dag diff --git a/dag/test/claim/srv3_unobservable_probe_refuses_witness_test.dag b/dag/test/claim/srv3/srv3_unobservable_probe_refuses_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_unobservable_probe_refuses_witness_test.dag rename to dag/test/claim/srv3/srv3_unobservable_probe_refuses_witness_test.dag diff --git a/dag/test/claim/srv3_websocat_sequence_witness_test.dag b/dag/test/claim/srv3/srv3_websocat_sequence_witness_test.dag similarity index 100% rename from dag/test/claim/srv3_websocat_sequence_witness_test.dag rename to dag/test/claim/srv3/srv3_websocat_sequence_witness_test.dag diff --git a/dag/test/fixtures/browser/chromium_151_bodied_502.png b/dag/test/fixture/browser/chromium_151_bodied_502.png similarity index 100% rename from dag/test/fixtures/browser/chromium_151_bodied_502.png rename to dag/test/fixture/browser/chromium_151_bodied_502.png diff --git a/dag/test/fixtures/browser/chromium_151_connection_refused.png b/dag/test/fixture/browser/chromium_151_connection_refused.png similarity index 100% rename from dag/test/fixtures/browser/chromium_151_connection_refused.png rename to dag/test/fixture/browser/chromium_151_connection_refused.png diff --git a/dag/test/fixtures/browser/chromium_151_empty_502.png b/dag/test/fixture/browser/chromium_151_empty_502.png similarity index 100% rename from dag/test/fixtures/browser/chromium_151_empty_502.png rename to dag/test/fixture/browser/chromium_151_empty_502.png diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/605c5419d7d5b517.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/605c5419d7d5b517.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/605c5419d7d5b517.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/605c5419d7d5b517.json diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/69a63cdcf2f7e5ed.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/69a63cdcf2f7e5ed.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/69a63cdcf2f7e5ed.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/69a63cdcf2f7e5ed.json diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/7be9704682d60499.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/7be9704682d60499.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/7be9704682d60499.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/7be9704682d60499.json diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/b264da0c183bb7fd.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/b264da0c183bb7fd.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/b264da0c183bb7fd.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/b264da0c183bb7fd.json diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/c42cbc47c934d7ae.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/c42cbc47c934d7ae.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/c42cbc47c934d7ae.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/c42cbc47c934d7ae.json diff --git a/dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/c42f940ae04b9e50.json b/dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/c42f940ae04b9e50.json similarity index 100% rename from dag/test/fixtures/fleet-revision-relation/git__Inspect__MergeBase/c42f940ae04b9e50.json rename to dag/test/fixture/fleet_revision_relation/git__Inspect__MergeBase/c42f940ae04b9e50.json diff --git a/docs/briefs/instrument-traps-2026-08-24.md b/docs/briefs/instrument-traps-2026-08-24.md deleted file mode 100644 index 01ac0cf9b55..00000000000 --- a/docs/briefs/instrument-traps-2026-08-24.md +++ /dev/null @@ -1,2413 +0,0 @@ -# Instrument traps measured on 2026-08-24 - -**Read this section and stop, unless you are looking for a specimen.** The rest of the document is -evidence, and it grew past a thousand lines in a day because the class kept recurring while it was -being written. - -## The rule - -**Check the comparands, not the comparison.** - -Every instance below produced output that was **TRUE**. None was a bug in a tool. In each case the -instrument answered a **narrower or neighbouring question than the one asked**, and the reader -supplied the missing binding without noticing. - -The diagnostic question, which is mechanical and is the whole of the method: - -> **What is the instrument supplying that the subject would have to supply for itself?** - - compile-clean supplies the whole-tree pool -> "this module is fine" is not what it said - a stale binary supplies its own identity -> two questions, one TRUE byte - a capped list supplies the unseen 3865 rows -> empty and truncated are one output - two lanes, two refs supplies the branch the ruling names -> both right, neither on the subject - an ambiguity counter supplies "unique means authorized" -> unique-but-wrong reports zero - -## Four things that transfer - -1. **A false absence is worse than a false green.** A green is caught by whatever depends on it; an - absence *terminates the investigation*, because there is nothing downstream to trip over. -2. **"Check when the answer surprises you" is exactly inverted** — it fires on the results least - likely to be corrupted and stays silent where corruption is indistinguishable from truth. -3. **The repair for a claim on the wrong subject is to MOVE it, not to soften it.** Hedging reads as - rigour while discarding signal (§ *the repair for a claim on the wrong subject*). -4. **Attention is not a remedy.** The strongest evidence in this document is that its own authors - committed these errors *while writing it* — one within the hour, on the change recording the class, - and three of us in a single thread that was explicitly about it. - -**Not one instance in this document was caught by its own output.** Every one was caught by someone -re-deriving what they had already said. That is not a run of bad luck with tools; it is what it means -for a distinction to be absent from a channel. - ---- - -## Specimens - -What follows is the evidence, roughly in the order it was found — across two sessions and nine lanes. -Each is recorded with what was measured rather than with advice, because the advice is always the -same and always insufficient ("check your instrument") and what transfers is the specific shape. - ---- - -## 1. `gh run rerun` is not a second observation - -A rerun reuses the **original merge commit**, so it re-measures the same stale base and -reproduces the identical error. Only a new head recomputes the merge ref. - -**Why it is expensive:** the failure looks exactly like a successful reproduction — same -error, same place, twice — which is normally the strongest confirmation signal available. -The defect defeats the instinct rather than requiring carelessness. - -*Found by bold-raven-901, who asserted the wrong remedy on a PR and corrected it there.* - -## 2. ctrl-build has TWO head behaviours and nothing in the output distinguishes them - -- fetch-a-named-commit → `HEAD` genuinely is that commit -- apply-a-diff-onto-the-pushed-base → the echoed head is **main's**, not yours - -Both were observed in this session, same tool, same day. The only distinguishing evidence -is the log preamble. - -**The rule is not "remember which mode you are in."** It is: *never let a git-derived field -carry the attribution.* Assert the subject **in-tree** — e.g. a pair of counters proving the -tree contains the fix and does not contain the defect — so the run proves it measured what -you think it measured regardless of which commit it believes it is on. - -*Found by lively-koi-546, whose `PROBEHEAD` column was main's sha on one run.* - -## 3. `--depth=1` makes ancestry checks uninformative, not false - -`git merge-base --is-ancestor` fails closed on a shallow clone, so a remote probe reporting -`ANCESTOR=absent` is describing the CLONE, not the history. Fails closed, so not dangerous — -but reporting it as a fact rather than an artifact is silence-as-zero. - -## 4. `fn` is not the only declaration keyword — `func` is too - -269 `func` against 36654 `fn`. A census pattern of `^fn ` undercounted a population by a -factor of 2.7, and **two sessions produced the same wrong number independently** from the -same defective pattern. - -A neighbouring failure the same hour: a pattern with no END anchor counted -`witness_verdict_diagnostic_companion` (the derivation itself) and -`lens_verdict_diagnostic_locus_module` (substring only) as producers of a channel that has -none. - -**Four defective greps in one night between two sessions.** The only one that reached nobody -was caught because the finding happened to be interesting enough to double-check before -sending — that is not a discipline anything can rely on. Match both keywords and anchor both -ends. - -## 5. A dashboard-only review is invisible to `gh` - -`dashboard-ops reviews ` rows can carry `dashboard_only: true`. Those do **not** appear on -the GitHub PR — `gh pr view --json reviews` cannot see them at all. - -So a lane checking readiness through `gh` sees `appr=1 rc=0` while the dashboard says -`rc=1`. This is why the working agreements name `dashboard-ops reviews` as the source of -truth, and it is not a preference. - -**And the join still has to be done by hand:** `merge_criteria` has itself published -`1/1 approvals` under a `head_sha` that the only approving row did not sit on. Join -`reviews[].sha` against `merge_criteria.head_sha` yourself, every time. - -**The instrument can also be BEHIND a push** — a join that passes right now may be joining an -approval against the previous commit. Confirm `head_sha` is the commit you mean. - -## 6. Archival is hard-blocked on open PRs - -`dashboard-ops archive ` returns `HTTP 409 archive-refused (reason: open-pr)`. - -So closing lanes does **not** free child slots while their PRs are open. With manual -operator merges, subtree throughput is bounded by **merge rate**, not by lanes. "Close lanes -to free capacity" frees attention, which is real, but is not what the queue is short of. - -## 7a. The side-chat read returns ONLY the other side — your own messages are never in it - -`dashboard-ops side-chat` returns a `turns` array containing the assistant/operator turns. -**Your own posts do not appear in it, ever.** - -So "my message is not in the thread" is *not* evidence that the send failed. It is what the -view always shows. This was measured the hard way: a post was reported as failed on exactly -that reasoning, twice, to a peer who then recorded the wrong lesson — while the operator's -next turn quoted the post's specific content back, including a commit sha only that message -had supplied. - -**And a send can complete asynchronously long after its foreground call gives up.** A send -that produced no output, and appeared absent from a subsequent read, had in fact landed; the -token counter decremented later, which was the only true signal available and was initially -dismissed as stale. - -**Confirmed structurally, not inferentially.** The first account of this reasoned from the -operator quoting back a commit sha only one message had supplied — sound, but it establishes -that *one* send landed. A second session then checked the endpoint itself: across three -separate captures of its own thread (3, 4 and 6 turns), **zero of its four posted messages -appeared in any `turns` array**, including one carrying `sent:true` with a counter decrement. -`role` is `None` on every entry, so there is no field to filter on. The array simply does not -contain your side. - -Correct readings, in order of reliability: the **token counter decrementing**; the other -side **responding to your content**; the returned turns — which cannot answer the question at -all. - -**The third is not weak, it is INCAPABLE, and the distinction decides behaviour.** A weak -signal invites more sampling; an incapable one must be abandoned. Six retries is what you do -to a weak signal — and six retries is exactly what was spent here before anyone asked whether -the instrument could answer at all. The action that survives every reading is the same: **never re-send on a missing -receipt**, and under the asynchronous-landing reading that rule gets *stronger*, because a -missing receipt now carries no information whatsoever about whether the send will land. - -## 7. The side chat's read path needs a long BACKGROUND budget - -Foreground calls (100s, 110s, 400s) return `HTTP 502: conversation fetch failed` or hang with -zero bytes and no stderr. One success in this fleet came from a **900s backgrounded** call. - -**Two different sessions produced two different symptoms** for the same surface — a 502 in one, -zero-bytes-no-stderr in the other — so neither should generalise from its own. - -Side chats are **per session**. One session cannot read another's, so relaying is not -available no matter whose instrument is healthy. - -**The state to hold explicitly:** *never successfully read in this session* means you have no -baseline, so you cannot distinguish a channel that broke from one you never reached. Until a -read succeeds, the absence of a reply is not information — treating it as one is the -empty-observation narrow with your own observation as the victim. - -## 8. A caveat can travel without changing anyone's behaviour - -A measured figure (12278 declared `test fn`) was published together with an explicit caveat -that it was **not** the right denominator, naming the correct one (~10439 routed). The caveat -was received, agreed with in writing, and the caveated figure was then quoted — by both -readers, repeatedly, including into the one channel with a confirmed receipt, with the caveat -dropped in transit. The number was corrected by a third party who had to notice the error from -scratch. - -**This is not a grep failure and no scan discipline prevents it.** The correction existed, was -correct, was acknowledged, and did nothing. What propagated was the figure; what did not -propagate was the *not-to-use-this* attached to it. - -The mitigation that would have worked is structural rather than attentive: **do not publish a -number you have already established is the wrong one.** If the right denominator is not yet -measured, publish the gap, not the figure with a warning stapled to it. A caveat is a request -that every future reader do work; the readers here were two sessions that had just spent a -night refusing exactly that kind of request in code. - -## 9. A timeout kills the payload and the shell reports success - -`timeout N ctrl-build -- ; echo done` exits **0** when the timeout fires. The shell -answers *did the last command in my pipeline succeed*, and you asked *did the payload -complete*. Those differ exactly when a timeout kills the thing you care about. - -**The remedy is a planted completion marker, and it is better than vigilance** — the payload's -last statement echoes a sentinel, and its ABSENCE is what you read. That is positive evidence -you cannot fail to notice, rather than an omission you have to spot. - -> **THIS CLASS HAS A CANONICAL HOME AND THIS ENTRY DEFERS TO IT: gunbc#9066**, authored by -> silent-gull-867, who hit it independently — a dispatch returning exit 0 with the payload -> never executed, the streamed log ending after `git apply`. Their write-up carries the -> distinguishing table (`EMITTED=0` means it ran and produced nothing; *no* `EMITTED=` line -> means it never ran, so the dispatch is **void, not negative**), places the class beside its -> neighbours (`cargo` exiting 0 without compiling, a pipe to `tail` masking a status, `grep -c` -> returning 0 for a missing file), and names how it differs from all of them: those are -> *corrupted* or *absent* statuses, this is an **honest** status answering a narrower question -> than the reader asks of it. -> -> That last formulation is the same one this document arrives at in "The shape they share", -> reached independently the same night from a different specimen. If #9066 lands, this entry -> should shrink to a pointer rather than restate it — two documents for one class is the §3 -> violation these notes exist to catch. - -## 10. ctrl-build cleans `target/` on every dispatch — so splitting an overrunning job is worse - -Every remote dispatch runs `git clean -x -d --force`, which removes `target/`. So a cold -release build is paid **per dispatch**, not once. - -This inverts the obvious remedy. A job that overruns the wall looks like it should be split -into N smaller dispatches; that costs **N cold builds** instead of amortising one, and usually -overruns worse. Either fit it in a single long dispatch or choose a different shape — do not -shard it. - -Measured on a 70-module standalone-compile sweep: a cold build plus seventy compiles does not -fit a 55-minute wall, and no split of it would have. - ---- - -## The shape they share - -Not one of these is an instrument lying. Each answers a real question correctly, and the -question is narrower than the one the reader asked: - -| you asked | it answered | -|---|---| -| does the defect still reproduce | does the base still fail | -| what commit did this measure | what commit does the runner believe it is on | -| is this an ancestor | can this clone see the history | -| how many companions exist | how many `fn`-declared companions exist | -| is this PR approved | is it approved *on GitHub* | -| is a slot free | is the lane closed | -| did the operator reply | did the fetch succeed | -| did my message send | did the last command in my pipeline exit 0 | - -The transferable move is not vigilance. It is to **make the run assert its own subject**, so -that a narrower answer cannot be read as the wider one. - ---- - -## Trap 11 — the completion marker matched the ECHOED COMMAND, not the output - -Measured 2026-08-24 09:15, in the remedy for trap 9, roughly forty minutes after adopting it. - -I planted `MARKER_ALL_DONE` as the last line of a remote payload and waited on -`grep -q 'MARKER_ALL_DONE' out.txt`. The wait returned in seconds. The payload had not run — -the dispatch was still applying patches, and no line of my script had executed. - -`ctrl-build` echoes the command it is about to run, verbatim, into the same stream: - -``` -ctrl-build: command: bash -lc $'...echo "MARKER_ALL_DONE"\n' -``` - -So the marker was present in the file **because I had asked for it**, not because anything -produced it. `grep -q` answered *does this string appear* when I was asking *did the payload -finish* — the shared shape of every trap in this document, arrived at from inside the fix for -one of them. - -**What makes this the sharpest specimen here:** trap 9's remedy is right, and this is not a -retraction of it. Planting a marker is still better than reading a status. But the remedy -introduces a *new* way for the reader to supply an unstated binding — that an occurrence of -the marker is an occurrence of the marker's PRODUCTION — and the header echo falsifies exactly -that binding, silently, on every single dispatch. The remedy for the class re-instantiated the -class. - -**The correction, and it is one character:** `grep -qx 'MARKER_ALL_DONE'` — anchor the match to -a whole line. The echoed header contains the marker inside a longer line and never as a line of -its own. Alternatively, compose the marker at runtime so it does not appear literally in the -command text (`echo "MARKER_${PHASE}_DONE"`), which additionally defeats any future wrapper that -quotes the script back at you. - -**The general rule, one level up from trap 9:** *a marker is evidence only if the channel it -arrives on cannot also carry the request for it.* Where request and response share a stream — -and with a command-echoing dispatcher they always do — the marker needs a shape the request -cannot have. Anchoring to a whole line is the cheapest such shape. - -Recorded as a numbered trap rather than an edit to trap 9 because the two are different -findings: trap 9 is *a status can be honest and narrow*; trap 11 is *your own instrument's -output can be contaminated by your own instrument's input*. Fixing 9 does not fix 11, and I -found 11 only because the void reading was so obviously wrong — had the payload merely been -slow, I would have read the false green and reported a passing test that never ran. - ---- - -## Trap 12 — the witness went where its siblings live, at a grain blind to the case - -Contributed by vivid-boar-345 on gunbc#9058, found twice in one day by the same lane, and -recorded here because it is an instrument trap in the strict sense: the measurement was placed -correctly by every convention except the one that decides whether it can measure anything. - -Repairing an empty-record spelling fork, they wrote the natural witness row beside its -siblings — a `decl_facts` assertion that both empty spellings carry one shape — and **it passed -on the pre-change binary.** `concept_decl_node` marshals a `NoConnective` item through -`unit_type_node`, which is a `TypeNode { connective: Conj }` with zero children: byte-identical -to what an empty record marshals to. So the row was permanently green *whichever way the parser -answered*. It would have shipped as coverage for precisely the thing it cannot see. - -They caught it by running the RED arm first. Nothing else would have — the row is green after -the fix, green before it, and green under any mutation of the behaviour it names. - -**Their generalization, which is the part worth keeping:** *where the behaviour is, not where -the neighbours are.* The pull toward the siblings' grain is strong and it is usually right; it -is wrong exactly when the sibling grain marshals away the distinction under test. `decl_facts` -returns a declaration's CHILDREN, and both the seal and the empty/unit distinction live in its -PROPERTIES — so the whole family of questions about properties is invisible at the grain the -family of witnesses uses. Their replacement asserts through a sealed empty pair instead, because -the seal is the one thing that still differs between a nominal empty record and an alias to unit; -pre-change exactly one of seven rows red, post-change seven green. - -**Why this is trap 11's sibling and not a repeat of it.** Trap 11 is *the channel carrying your -answer also carried your question*. Trap 12 is *the instrument's resolution is coarser than the -distinction you are asking about* — and in both, the output is TRUE and the reader supplies the -missing binding. The distinguishing question is cheap and should be asked of every new witness -before it is enrolled: **can this row go red?** Not *does it pass* — DESIGN §4b already says a -check whose RED is unauthorable is a decoration, worse than absent because it is cited as -coverage. Trap 12 is what that rule looks like when the unauthorable-RED is caused not by the -corpus but by the marshalling in the assertion's own read path. - ---- - -## Trap 11a — anchoring one term of a disjunction leaves the disjunction unanchored - -Same session, ~30 minutes after writing trap 11 and its correction. - -Having established that `grep -q MARKER` matches ctrl-build's echo of my own command, I re-armed -the wait as: - -```sh -until grep -qx 'PHASE_RED_DONE' out.txt \ - || grep -q 'Remote run completed\|PATTERN_MISS\|NO_BINARY' out.txt -do sleep 20; done -``` - -The success marker is anchored. The **failure sentinels are not** — and `PATTERN_MISS` and -`NO_BINARY` are strings *in the script*, so they appear in the echoed header exactly like the -marker did. The wait returned immediately, against a dispatch that was still building. - -**Why this is worth a numbered entry rather than a footnote to trap 11.** I did not forget the -lesson; I applied it to the term I was thinking about. The fix in trap 11 is phrased as a fact -about *the marker* — anchor the marker to a whole line — and I implemented exactly that -sentence. The disjunction's other arms were never re-examined, because they are not "the -marker", they are the error cases, and the correction as written did not reach them. - -That is the general failure of a remedy stated at the wrong grain: **a rule about one term does -not survive being embedded in a compound predicate.** The rule that does survive is a rule about -the *channel*: on a stream that carries the request alongside the response, **every** literal you -match must have a shape the request cannot have — success markers, failure sentinels, error -strings, all of them. Not the one you happened to be reasoning about. - -Corrected form, with every arm anchored: - -```sh -until grep -qxE 'PHASE_RED_DONE|PATTERN_MISS|NO_BINARY' out.txt; do sleep 20; done -``` - -Cost this time: one wasted read and a wrong "still in progress" reading, caught within a minute -because I checked for the markers instead of trusting the wait's return. Had I reported off it, -I would have said a mutation probe had not started when it had — the inverse of trap 11's -failure, from the identical cause. - ---- - -## Reviewer trap — naming the mechanism instead of the property, and the correction to that correction - -Two instructions I gave tonight were wrong *as specified*, in the same way, hours apart: - -- To gunbc#9075: *put these rows in a module whose honest disposition is hermetic.* No such module - can exist — any `compile_dag_diagnostic_census` probe resolves against the live checkout. The - author, given an impossible instruction, produced a false declaration to satisfy it. -- To gunbc#9063: *attest against membership in `rust_identifier_tokens(s: emitted_source)` — same - machinery, no new concept.* That function splits `<>,()[]&:` and space, with no `;`, because it - was written for a **rendered type string**. Against a whole module, `pub type X = Int;` tokenizes - to `Int;`, so membership answers NO for a name the emitter demonstrably wrote. The swap would - have dropped required use-lines and reproduced the exact defect the code exists to prevent. - -In both the **property** was right — evidence must execute on the gating path; attestation must -match whole identifiers — and the **mechanism I named** was wrong. And in both I reached for the -mechanism because it looked *convenient*: an existing module, an existing function. Reusing a -function outside the domain it was written for is not DRY; it is the hollow-alias failure, and the -reviewer is unusually prone to it because the reviewer sees the shape of the machinery and not its -preconditions. - -**The obvious lesson — state the property, let the author choose the mechanism — is half right, and -the author of #9063 supplied the other half:** - -> I would not have found the delimiter problem if you had not named the exact function to reuse — -> checking whether it fit its new domain was a cheap question that only got asked because there was -> a concrete proposal to check. The proposal being wrong in a checkable way is worth more than a -> vaguer one that was not. - -That is correct and it prevents an over-correction. A property stated alone (*match whole -identifiers*) is unfalsifiable at review time and hands the author an open problem; a named -mechanism is **checkable in one grep**, and being wrong in a checkable way is a service. The -failure was not the concreteness — it was the **grammatical mood**. - -**The synthesis: name the property, offer the mechanism as a candidate to check, never as the -instruction.** *Attestation must match whole identifiers rather than substrings; `rust_identifier_tokens` -looks like the right tool — check its delimiter set against a whole module before using it.* Same -concreteness, same one-grep falsifiability, and the author is left holding the domain question -instead of an order. The #9075 case fails the same test in the other direction: had I written -*the evidence must execute on the gating path, or be declared authored-not-executing — is there a -module whose honest disposition gets it there?*, the answer would have come back **no**, which is -the correct answer and was unreachable from the instruction I actually gave. - ---- - -## Trap 13 — when your predictions are absences, a dead harness confirms them - -Contributed by `deep-ant-102`, from a truncated floor probe. This is the sharpest member of the -family recorded here and it subsumes part of traps 9 and 11. - -Their dispatch hit ctrl-build's 45-minute default cap mid-floor. Output ended at their own header: - -``` -===== FLOOR: real roots + probe fixture ===== -[exited with code 0] -``` - -No arm lines, no summary, no exit code from the subject. **And their grep for probe arms would have -returned empty** — which is not a null result here, it is a **confirming** one: - -| pre-registered prediction | what a dead harness returns | -|---|---| -| `declined_live` +0 | nothing found → looks like +0 | -| four files in the roster, not five (arm4 invisible) | nothing found → looks like invisible | -| zero `test data` identities planned | nothing found → looks like zero | -| **the run goes red on arm5** | nothing found → **fails** | - -Three of four predictions apparently confirmed by a run that never executed. - -**The general shape: an absence-shaped prediction is confirmed by the absence of the experiment.** -A probe that predicts *X should not appear* cannot, without further construction, distinguish -*X did not appear* from *nothing appeared, including the experiment*. Every trap in this document is -some form of a signal answering a narrower question than asked; this is the form where the signal -answers **the very question you asked, correctly, about a universe that does not exist**. - -**Why the liveness control is not optional, and why it is the one prediction that cannot be faked.** -Arm 5 was added for a different reason — to catch a harness that runs and evaluates nothing. It -happens also to be the only **presence** prediction in the set, and therefore the only one a dead -harness cannot satisfy. That is not a coincidence to note in passing; it is the design rule: - -> **A pre-registration made mostly of absences needs at least one presence prediction, or the -> experiment cannot fail in a way you will notice.** - -Count the moods in your predictions before you run. If they are all *should not appear*, *should be -zero*, *should be unchanged*, then the null hypothesis and the broken instrument return the same -string and the run cannot inform you. - -**And the marker rule gains its final clause.** Trap 11 established: anchor the marker to a whole -line, because the request shares the channel. Trap 13 adds: **plant it AFTER the subject, not only -before.** A header echo proves the dispatch started; only a trailing marker proves the subject -finished. Their header printed; that is precisely why the truncation was legible as truncation -rather than as data. - -Paired with silent-gull-867's `#9103` false negative (`mirror-drift-four-lanes-2026-08-24.md`), -these are the two ways a run agrees with you for the wrong reason: **the treatment never reached -the instrument**, and **the instrument never reached the subject**. Both return the control's -answer. Neither raises an error. - ---- - -## Trap 14 — exculpatory attribution: the explanations that let the line restart - -Four instances in one morning, across three lanes and one of them mine. It is the author-side -absorbing fallback (DESIGN.md §5) with a specific and predictable shape, and naming the shape is -what makes it catchable, because in the moment each instance feels like ordinary diagnosis. - -**The shape.** A run fails. Several explanations are available. Some place the cause *inside* the -change and some place it *outside* — a race, pre-existing breakage, an unrelated phase, missing -infrastructure, someone else's PR. The outside explanations are the ones that let the line restart -without work, so they are the ones reached for first, and — this is the whole trap — **they are -reached for without being checked**, because checking is a cost you only pay for a hypothesis you -expect to act on. - -**The four instances.** - -1. *smart-wolf-868, #9075:* a failing run attributed to a race, because the run started in the same - minute as a push. The run carried `sha=4e3c2327860` — its own pushed commit. Runs are pinned; - a concurrent push cannot change a checkout already made. One `gh run view` away. -2. *Same lane, same run:* reported as a **regen** failure. The ledger read - `regen first_generation_equal=true` and `FAILED PHASE floor`. The subsequent push "to force a - clean candidate comparison" therefore fixed a phase that had passed. -3. *Same lane, same run:* the floor diagnostics called pre-existing. Main's last six runs were all - `success`, and the PR's base was `bd84f6696` — **the exact commit whose own run passed**. -4. *silent-gull-867, #9076:* `spawn rustfmt: No such file or directory` attributed to "the runner - missing a binary." Eight sibling runs in the same window on the same runner image: zero such - errors. Their run was the only one, twice. -5. *Mine, in the message correcting instance 3:* "the other ~71 PRs are BLOCKED for a different - reason." Measured: 47 CLEAN, 19 BLOCKED, 4 DIRTY, 1 UNSTABLE. Wrong on both halves, asserted in - the same paragraph as an instruction to check before commissioning work. - -**Why instance 5 matters most.** The trap is not a competence failure and it is not confined to the -lane under pressure. I walked into it one paragraph after describing it, against a number I could -have measured with the command I had just run. Any rule of the form *be more careful* would not have -caught it, because I was being careful — about the other lane's claim, not my own aside. - -**The operative rule, which is mechanical rather than attitudinal:** - -> **An explanation that places the cause outside your change is a hypothesis with a cheap test. -> Run the test before you act on the explanation, and especially before you tell anyone.** - -The corollary is what makes it affordable: these tests are nearly free. A pinned SHA is in -`gh run view`. A phase verdict is in the ledger you already opened. "Pre-existing" is answered by -the base commit's own CI run — **which already exists, was already paid for, and is a pre-executed -control on the exact tree** (this is worth internalizing on its own: every PR ships with arm B of -its own two-arm comparison, and lanes routinely commission a 30-minute build to reproduce it). -"Infra" is answered by siblings in the same window. None of the four instances above needed a build. - -**The reviewer-side tell**, since the author cannot always see it: an attribution to something -outside the diff, stated without the measurement that would establish it. The words are usually -*pre-existing*, *unrelated*, *flake*, *infra*, *race*, *stale*, *not mine*. Each is a real category — -that is exactly why the class is durable, and why "distrust these words" is the wrong rule. Ask for -the measurement instead. In all four cases here the measurement existed and took under a minute; in -three of the four it reversed the conclusion. - -**Relation to the rest of this brief.** Traps 11–13 are ways an instrument returns the control's -answer while you believe it measured the treatment. Trap 14 is the step before the instrument: the -decision not to measure at all, taken because a costless explanation was already available. It has -the same signature as the others — no error is raised, the output is true as far as it goes, and the -reader supplies the binding that makes it wrong. - -### Trap 14a — the sharper sub-form: your instrument cannot express the answer - -Instance 5 above was mine: an unmeasured assertion. Within the hour I produced a worse one, and it -deserves separating because the rule from trap 14 would not have caught it — **I did measure.** - -I set out to check whether the floor names the six roster rows it reports as `now PASS and must be -removed`. I searched a 337KB log by extracting `//[a-z_0-9/]+:[a-z_0-9]+`, the label format used by -the per-claim `PASS`/`FAIL` lines. Zero matches. I concluded the floor counts them without naming -them, called it a §5 violation — typed and counted but not located — reported it upward as a defect -worth fixing, and another lane offered to fix it. - -The floor names all six: - -``` -required-floor: STALE-QUARANTINE test.claim.samsung_dram_module.generation_is_ddr4 is enrolled - as expected-red and PASSED — remove it from v2.workflow.floor_expected_red -``` - -Six lines, with remediation text, in the file I had already downloaded, emitted by a loop that sits -beside seven siblings doing the same for `ROUTE-GAP`, `HOST-TOOL-UNRESOLVED`, -`INTERRUPTED-BEFORE-VERDICT` and the rest. These carry **dotted qualified names**. My pattern -required a `//`-prefixed, colon-separated label. It could not have matched a true positive. - -> **A search that returns nothing has told you about your pattern until you have shown the pattern -> can match a true positive.** - -The failure is not carelessness about whether to measure; it is skipping the question of whether the -instrument's vocabulary matches the subject's. A regex is a claim about *format*, and I was asking a -question about *presence*. Zero results answered the format question, and I read the answer as -presence — the same substitution trap 11 makes with a marker and trap 13 makes with a truncated -dispatch, now one level further out: not the instrument reaching the wrong subject, but the -**instrument being unable to represent the finding at all**, returning ⊥ that reads as *absent*. - -The positive control was free and I skipped it: grep for the bare token `STALE-QUARANTINE`, or for -any known-present string, and confirm the harness can find something before trusting that it found -nothing. One `grep -c` would have shown 6. - -**And the evidence that should have stopped me was already in view.** `[floor-known-red-causes]` -prints per-item detail immediately below the counter line I was doubting. I read that as precedent -for what *should* exist rather than as evidence about what *does* — an author who prints a per-cause -census three lines down is not an author who omits a per-identity list. Corroborating structure was -sitting adjacent to my conclusion and I used it to motivate the finding instead of to test it. - -**Cost, and why it is the real argument for the positive control:** the false finding was relayed -upward inside four minutes and a second lane volunteered to fix a defect that does not exist. An -unverified negative does not stay in one head; it recruits. - -**The salvage, which is the honest outcome:** all six stale rows are `test.claim.samsung_dram_module.*` -— one module, six roster lines to delete, a real and trivial unblock. The correct finding was smaller -than the invented one. That is the usual shape. - -### Trap 14b — a spec tells you what a mechanism does, not what invokes it - -The third sub-form, produced an hour after 14a, and it completes the taxonomy: **14** is not measuring; -**14a** is measuring with an instrument that cannot express the answer; **14b** is reading an authority -correctly and drawing a conclusion it does not license. - -I measured that 20 of 50 mergeable PRs touch the stage0 mirror, and that **12 of them modify one file**, -`src/v1/stage0/src/cli_run.rs`. That part was real. I then reasoned from DESIGN.md's Building-&-checks -section, which records that the generated-artifact merge driver *refuses* rather than answering `true`, -leaving the path unmerged with a regeneration recipe. Git invokes a low-level driver exactly when both -sides changed a path since the merge base — true of every pair of the twelve. Conclusion: the twelve -serialize, one merge plus one regeneration cycle each, and the queue's cost is quadratic in the drought. - -I sent that upward as a merge-strategy recommendation, labelled derived-rather-than-measured, and then -measured it. **Both halves are wrong.** - -``` -$ git check-attr merge -- src/v1/stage0/src/cli_run.rs -src/v1/stage0/src/cli_run.rs: merge: unspecified -``` - -`.gitattributes` marks four specific generated artifacts — not the stage0 mirror at large. The refusing -driver never engages for this file. And the merge itself, two of the twelve onto `origin/main` in -sequence: - -``` ---- merge A --- Auto-merging src/v1/stage0/src/cli_run.rs rc=0 ---- merge B --- 13 files changed, 957 insertions(+), 40 deletions(-) rc=0 -``` - -Clean both times. No ordering constraint exists. - -> **A specification describes a mechanism's behaviour. It does not enumerate the inputs the mechanism -> is applied to. Scope of application is a property of the tree, and only the tree can answer it.** - -Everything I read was accurate: the driver does refuse, and git does invoke low-level drivers under -exactly that condition. The invented step was the silent premise that this file is one of the driver's -inputs — which no sentence I read claimed, and which one command falsifies. This is DESIGN.md's own -**authority substitution** in the reader's direction: fact F (how the driver behaves) lives in one -carrier, operation O (how *these paths* merge) is governed by another, and I let the first answer for -the second because both halves checked out and only the arrow between them was missing. - -**It is the most dangerous of the three**, because 14 and 14a produce claims that feel thin while you -are making them, and this one felt like *reasoning from the authority*. The correct move is not more -skepticism toward DESIGN.md; it is noticing that "what does X do" and "does X apply here" are different -questions with different oracles, and the second one is nearly always cheaper. - -**What made it recoverable** was labelling the claim derived-not-measured when sending it. That label is -what sent me back to check twenty minutes later instead of leaving a false mechanism in someone's merge -plan. **Marking a claim's evidential status is not hedging — it is the thing that schedules its own -verification.** - -**And the residue is better than the claim.** Text-merging two independently regenerated halves of a -generated file produces a mirror no single emit produced. Whether it still equals a fresh emit is what -`--required-regen` checks on main *after* the merge — so the failure mode, if it exists, is main going -red on regen after a multi-mirror merge, invisible at merge time. Untested here (a full regen is a -CI-sized job) and recorded as an open question, not a finding. It is presumably why the driver covers -the files it does. - ---- - -## The rule that subsumes traps 14, 14a and 14b — check the comparands, not the comparison - -Five instances in one day, across two sessions. They were catalogued above as separate sub-forms, -and that framing is now superseded: **they are one class, and it has no cheap wall in front of it.** -Arrived at jointly with deep-ant-102, who put it best — every failure was on the axis of *what am I -holding*, never on the axis of *what did I measure*. - -> **Before interpreting a measurement, establish that the things being compared are what you think -> they are.** - -Every instance below is a measurement that was CORRECT, interpreted against a comparand that was -assumed. In each case one cheap query — usually one command, always under a minute — identified the -comparand, and in each case it was not run because the question felt already answered. - -| the assumption | the free query | what it returned | -|---|---|---| -| the merge driver applies to this path | `git check-attr merge -- ` | `merge: unspecified` — it does not | -| these floor errors are pre-existing on main | the base commit's own CI run | main green at that exact sha — they are not | -| my branch is current, so this delta is drift | `git rev-list --count HEAD..origin/main` | `13` — the delta was my staleness | -| my search found nothing, so nothing is there | `grep -c ` | `6` — my pattern could not match the format | -| this list is the population | is the view truncated? | `tail -12` was a window, not a total | - -**Why "be more careful" does not address it.** In four of the five the author *was* being careful — -measuring, controlling, labelling evidential status. The trap sits one step before the care: the -comparand is supplied by memory and never enters the evidence. And the class is symmetric, which is -why the earlier sub-form rules each caught only half of it: - -- **negatives** — a filtered or truncated view returns ⊥, and ⊥ reads as *absent*; -- **positives** — a diff returns a real difference, and the difference is attributed to the wrong side. - -An absence rule (*show the view could contain it*) misses the second; a presence rule (*identify both -sides*) misses nothing, which is why it is the one to keep. - -**The operational half, and it is deep-ant-102's, kept verbatim because it is the only reliable exit:** - -> **When a filtered view yields a negative, go get something that could positively contradict it.** - -Absence never contradicts anything, so no amount of staring at a negative result will overturn it. -The two escapes today were both positive artifacts that made the standing conclusion impossible: a -base64 payload containing the very row I had just concluded was missing, and a `git status` line -naming the file I had just concluded was never written. - -### What it cost, and the near-miss that is the real argument - -Four of the five produced a wrong claim that reached another session inside minutes; two of those -recruited a second party to act on them. The one that matters most never reached anyone. - -Holding a regenerated DESIGN.md, I was one commit from landing it. My branch was 13 commits behind -main, so those bytes would have **reverted two of main's paragraphs** — inside a PR whose stated -purpose was adding one row, in the repository's canonical authority document, with the drift gate -that would have caught it unguarded since the floor cut. Every individual step was sound: regenerate -from the authority rather than hand-edit the artifact, commit authority and output together, verify -the output contains the intended change. It was correct work aimed at a comparand nobody had checked. - -`git rev-list --count HEAD..origin/main` is the whole wall, and it costs nothing. - -**Corollary for reviewers**, since the author's own care demonstrably does not catch this: when a -diff, count, or absence is offered as evidence, ask what it was compared *against* and whether that -was verified or remembered. It is a different question from "is the measurement right", and today it -was the only one that mattered. - -### The case neither rule covers: a complete file that is a partial record - -The comparand rule above was written one instance too early. deep-ant-102 produced a sixth case the -same afternoon that **has no filter and no comparison**, and it is the sharpest of the set. - -They reported that a wet regeneration pass wrote exactly twelve files, none of them DESIGN.md. I -attributed it to a truncating `tail`. They checked, correctly, and refused: their command carried no -`tail`, and `grep -c` over the **whole file** returned 12. Both statements were true. - -The clean-tree run settled it: - -``` -[file] write DESIGN.md (94037 bytes) -``` - -Eighth in a list of at least 69 traces, on an unmodified tree. The twelve were the **final twelve** -of that list. The task-output capture had elided the *middle* of a long stream, keeping the first six -lines and the last twelve — a 31-line file standing in for a 69-line record. `grep -c` over a -complete FILE returned a complete count of an incomplete RECORD. - -> **Does the artifact I am reading claim to be complete, and could it know?** - -A file has no way to tell you it is short. Nothing inside it is wrong, nothing is filtered, and no -comparison is being made — so neither the absence rule nor the comparand rule fires. **File -completeness is not record completeness**, and the gap between them is invisible from inside the -file. - -Only two defences exist, and both must be arranged *before* the run: - -- **a terminal marker you planted yourself** — its absence proves truncation, because you know it was - emitted last (this is the same discipline as the dispatch-marker rule in `#9066`, and both of us had - written that rule down before violating it); -- **a count you can predict independently** — fifteen committed artifacts means fifteen-plus traces, - and twelve should have been recognisable as short. - -### And a meta-error worth more than either rule - -deep-ant named this one against themselves and it is the reason the question stayed open an extra -forty minutes: - -> **A wrong mechanism does not refute a correct conclusion.** - -My diagnosis (*your twelve is a truncation*) was right; my explanation of it (*you must have used -`tail`*) was wrong. They checked the explanation, found it false, and discarded the conclusion with -it. That is an easy inversion to make when the explanation is the only checkable part of what you -were told — and the cost is that a settled question reopens. - -The reviewer's form: when you refute someone's *reason*, you have not yet touched their *claim*. -Say which one you are refuting. - ---- - -## A pre-registration does not protect you when the null and the not-run are the same string - -*silent-gull-867, 2026-08-24. The sharpest statement of this class so far, and it indicts the very -technique the rest of this brief recommends.* - -Everything above assumes that pre-registering a prediction disciplines the reading. It does — **but -only when the predicted null is distinguishable from the instrument never running.** - -The setup: measure whether adding one alias row to a carrier changes floor behaviour. Success -criterion, registered in advance: *counts unchanged*. Sound as far as it goes. - -The failure: **a `.dag` edit reaches the compiler only through regen.** Before the mirror was -installed, the probe measured a binary that did not contain the row. And "counts unchanged" is -exactly the string a stale binary hands back. - -> The probe's positive result and its instrument-never-loaded were **the same observation**. - -The pre-registration could not tell them apart, because the predicted no-effect and the -never-executed produce identical output. What actually caught it was a marker asserting the -instrument *contained the change* — `MARKER_MIRROR_PP_BEFORE=0` — not the prediction. - -**So the discipline has an ordering, and it is the opposite of the intuitive one:** - -1. **First** assert the instrument carries the treatment. A marker, a digest, a `grep -c` on the - *installed* artifact — something only a loaded instrument can produce. -2. **Then** read the pre-registered prediction. - -Reversing them makes step 2 unfalsifiable whenever step 1 has silently failed. This is trap 13's -absence-mood problem generalised: it is not enough that *some* prediction be a presence — the -**instrument's own loadedness** must be a presence assertion, separate from and prior to whatever -the experiment predicts. - -And it is the exact shape as the trap-14 family: the comparand — *which binary am I measuring* — was -supplied by memory rather than by evidence. - -**The residue when it is done right** (from the same lane, on the repaired run): the row's effect -was confirmed absent by identical counts across every field, plus two checks that the agreement was -not manufactured — `declined_live` identical, so nothing agreed by declining to execute; and floor -**preparation** clean on both arms, which is where the failure would surface, ahead of the fold -where no decline arm can reach it. That is what a null result looks like when it carries information. - -## A rename with no diff and no refusal - -*Same lane, worth its own entry because nothing in this brief would have caught it.* - -`container_alias_canonical_spelling` returns the **first sorted key** mapping to an algebra. So -adding a key that sorts ahead of the incumbent silently becomes the canonical emitted spelling for -that algebra **corpus-wide** — adding `"FinitelySupportedFunction"` would sort ahead of `"Map"` and -rename it everywhere. - -No diff shows it: the change is one added row. No refusal fires: the lookup is total and the new key -is legitimate. No test asserts the incumbent, because the incumbent was never chosen — it was the -alphabetical accident of a single-member set. - -The general shape: **a total function whose answer depends on an ordering nobody declared.** The -ordering is an implementation detail until a second element exists, at which point it silently -becomes policy. Neither the comparand rule nor the marker rule reaches this one; the only defence is -noticing that a lookup returns *a* member of a set rather than *the* member, and asking what decides -which. - -Only `"PartialFunction"` was added, which competes with nothing. - -## The strongest instance of the comparand rule: a stale binary and a correct one produce the same green - -*Reported by silent-gull-867, 2026-08-24, against the regen fixed-point loop on #9059 — and the -reason it closes this brief rather than sitting mid-list is the timing, recorded below.* - -The regen loop is: install a mirror, rebuild, re-run, read the verdict. One round ran without the -rebuild — the mirror was installed and then measured **against the binary built before it**. The -round went green. - -That green is the comparand rule's purest specimen. The question asked was *does the committed -mirror match what the compiler emits*. The question answered was *does the committed mirror match -what the compiler emitted **before this mirror existed***. Both are real questions, both are -answerable, and **both answer `true` with the same byte.** Nothing in the output distinguishes them, -because the binary's identity is not one of the comparands the verdict is computed over — it is the -thing computing the verdict, and an instrument does not report itself. - -What makes it worse than the traps above: those had a channel that *could* have carried the -distinction and didn't. Here there is no such channel. The round's output is structurally incapable -of encoding which binary produced it. The only channel that could catch it is a re-read of the -commands that produced the run — which is exactly how it was caught, and it is not a channel that -scales or that a reviewer has access to. - -**Why the damage was zero, stated precisely, because the precise version is the alarming one:** the -round's answer happened not to depend on the reinstall. Not *the loop is robust to this*, not *the -check was redundant anyway* — the inputs that round happened not to differ across the two binaries. -That is luck. A finding whose cost was zero because of what the run happened to contain has not been -handled; it has been survived. - -**The timing is the argument.** This was committed by the author who had written up the probe-staleness -class **within the hour, on the change that records it.** Documenting the class did not immunise its -own documenter against it, one hour later, with the text open. Any proposal whose remedy is "readers -will be careful" is refuted by this single data point — the most primed possible reader, at the moment -of maximum priming, on the most relevant possible change, still committed it and still needed a manual -command re-read to notice. - -So the remedy cannot be attention. It has to be that the run **names the binary it ran** — putting the -instrument's identity into the receipt makes the two questions above textually different, which is the -minimum condition for the output channel to be able to carry the distinction at all. Until that lands, -every green from this loop is a green about an unnamed compiler. - -## The same defect pointing the other way: a silently capped list, where absence is the answer - -*deep-ant-102, 2026-08-24, deciding whether #9059 intersects #8282's changed set. Recorded next to -the entry above because they are one defect read in opposite directions.* - -The query was: do this PR's paths intersect the cut's? The first run came back **EMPTY** — no -intersection, PR is clear. It is wrong. - - gh pr view 8282 --json files -> 100 rows - gh pr view 8282 --json changedFiles -> 3965 - -Same call, same PR. The file list is capped at 100 and **does not say it was capped**. An intersection -computed against those 100 is an intersection against 2.5% of the subject, and it returns exactly what -a genuine non-intersection returns: nothing. - -**Why this belongs beside the stale-binary green rather than in its own section.** That trap answers -`true` to a narrower question than the one asked. This one answers *empty* to a narrower question than -the one asked. In both cases the output is byte-identical to the correct answer for the real question, -and in both cases the instrument's own limitation is not among the things the output can express. The -stale binary cannot report which binary it was; the capped list cannot report that it was capped. - -**The direction matters for how it gets caught, and it is the more dangerous direction.** A false green -is caught by the next thing that depends on it. A **false absence terminates the investigation** — there -is nothing downstream to trip over, because the finding was "nothing here." It was caught here only -because empty *contradicted an expectation*. Had the expectation been "this PR is probably clear," the -empty result would have confirmed it, the PR would have been cleared to land, and it would have landed -into the cut it shares 24 of 25 files with — including `src/v1/04_infer.dag`, where the cut's two -remaining blocking diagnostics live and a hypothesis about them was mid-measurement. - -**So the guard cannot be "check when the answer surprises you."** That guard is exactly inverted: it -fires on the results least likely to be the truncated ones, and stays silent on the results where -truncation is indistinguishable from truth. An absence is only evidence if the instrument that produced -it can be shown to have looked at the whole subject. - -**The operative rule:** never take a file list from `gh pr view` on a large PR. Use -`gh api --paginate .../files?per_page=100`. And note that even the paginated form stopped at **3000 of -3965**, so the honest statement of the result is `>= 24`, never `= 24`. Reporting the exact figure would -have been a second instance of the same trap inside the fix for the first. - -## The adversarial check that refutes the checker: measuring to defend a claim, and finding a third fact - -*silent-gull-867, 2026-08-24, answering a REQUEST_CHANGES on #9059. Recorded because the causality -is the lesson, and it is not the causality the rest of this brief teaches.* - -Every other entry here says: **measure your own claims, because the instrument may be answering a -narrower question than you asked.** This one is different, and the difference is the point. - -A review said the PR expanded two maps and deferred their join — a §3 fork grown rather than -dissolved. The author expected the review to be wrong, and went to measure the two key sets **in -order to demonstrate that the maps were not really one fact.** - -The measurement confirmed the reviewer on the substance (profile keys 7 -> 11, alias keys 6 -> 8, -both grew) and **refuted the manager's framing** on something neither the reviewer nor the review had -raised: the two maps are not the same key set and never were. `Int`, `Float`, `Bool` and `String` -sit in the profile map and are *correctly* absent from the alias map — scalars with a method surface -that are not containers. So there is no derive-one-from-the-other relation for a row to dissolve. -The follow-up had been described, by me, as a *join*. It is a replacement migration with a census: -a new authority carrying per-algebra spellings AND profile AND container-resolution, retiring two -authorities across four files in both v1 and dag. - -**Three parties, three states, and no two of them the same:** - - the reviewer right on the substance, silent on the framing - the author wrong about the review, right to go and check - the manager wrong about the shape of the work, and unchallenged until now - -**The lesson is about what produced the third fact.** It was not diligence and it was not carefulness -— the author says so plainly, and the honesty matters because a lesson that flatters the finder -teaches nothing. It was *adversarial intent*: going to measure in order to WIN an argument reaches -for evidence that a defensive re-read never touches. Nobody re-derives a key set to confirm what they -already believe. They derive it to refute someone. - -So: **"the reviewer was right, and checking why produced a third fact neither of us had" is a -different lesson from "measure your claims."** The first is about being wrong. The second is about -the *mechanism that makes disagreement productive* — the check you run to defend yourself is the one -that reaches material no agreement would have surfaced. A lane that concedes reviews gracefully and a -lane that argues them with measurements produce the same merge outcome and very different corpora. - -**The corollary that binds the manager, which is me.** My "join" framing had been sitting in a -follow-up description, named and apparently owned, for long enough that someone could have picked it -up and built it. It would have been built to the wrong size, and — per the ordering constraint in the -same finding — a flattened lookup would have silently moved which stage refuses. **An unchallenged -framing from someone senior is a defect with no red.** It survived precisely because it was never -worth arguing with. - -## The highest-stakes instance: two lanes both right, about different refs - -*deep-ant-102, 2026-08-24. Recorded last because it is the comparand rule at the largest blast -radius reached today, and because the author found it in their own message rather than in someone -else's.* - -Two reports about the namespace cut, apparently contradicting each other: - - this lane #8282 is draft, DIRTY, CONFLICTING at 13:05Z -> "the cut is not close" - crisp-crab-430 the cut is clean: 94 sources, 0 blocking -> "step 2 is met" - -Both were true. Neither was about the same thing: - - #8282 head ref = integration/namespace-cut 416727a98 draft, CONFLICTING - the 94/0 push = integration/namespace-cut-fresh c6d3a3809 - - merge-base = 416727a98 cut ahead of fresh: 0 fresh ahead of cut: 101 - -`-fresh` is a strict descendant carrying `-cut` plus the 101 commits that include the repair taking -it to zero. **The work is finished and no mergeable artifact carries it**, because the PR still -points at the ancestor. - -**Why this is the same trap and not merely a mix-up.** Nobody measured anything incorrectly. Every -number reported was accurate for the ref it was taken from. What was missing is the thing this brief -keeps finding missing: **the comparands were never checked against the question.** The question was -*is the cut ready to land*, which is a question about the ref the ruling names — and one report -answered it about a descendant branch while the other answered it about the PR's head. - -**The consequence is the reason it outranks the rest.** The 94/0 was carried to the operator as -"step 2 met", in the message whose entire purpose was to open their merge window. Accurate sentences, -wrong comparand, at the exact moment a decision was being requested. And the induced error propagated -the other way too: this lane read draft-and-conflicting as *the window is hours away* and argued from -it that idling six stopped lanes was the expensive choice. **The truth was closer to the opposite** — -the tree is ready, only the artifact is missing, and that is a small mechanical step. An inference -drawn correctly from a comparand that was never the subject. - -**Two properties worth keeping.** - -First, **agreement was never available as a check here.** The two reports contradicted each other, -which is the *lucky* case — it forced someone to look. Had crisp-crab not pushed 94/0, this lane's -reading would have stood unchallenged and been just as wrong about the window. - -Second, and this is why it closes the brief: it was caught by the author re-reading **their own** -message, the same channel that caught the stale-binary green. Across a full day of instances, in this -corpus, **not one was caught by its output.** Every single one was caught by someone re-deriving what -they had already said. That is not a run of bad luck with instruments; it is what it means for a -distinction to be absent from a channel. - -## The class stated as a rule, by someone who was not writing about the class - -*keen-tern-667, 2026-08-24, in the body of gunbc#9083 — a PR about a single module's import header.* - -> **Whole-tree compile-clean is not evidence that a module can be emitted alone.** - -Every other entry in this brief is a war story: an instrument answered a narrower question, someone -caught it, here is what it cost. That sentence is the same content as a **rule**, written by someone -who was diagnosing one module and not writing about instruments at all. - -The mechanism behind it is the one this brief keeps describing. `v2.compiler.program_assembly` -declares two imports and uses about twenty-six names homed in nine other modules. Whole-tree -compile-clean passes, because **the definers are in the pool — put there by some other module's -imports — so the unlisted names bind by coincidence.** The module's own header can be arbitrarily -wrong and nothing goes red. Scope the closure to the module's own declared edges, which is exactly -what emitting it alone does, and every definer drops at once: twenty-six diagnostics from one root. - -**Green compile-clean and emittable-standalone are different properties, and the first was being -read as the second.** No measurement was wrong. The comparands were never checked against the -question. - -### Why it belongs at the end of this brief - -It supplies the **positive form** that the rest of the entries only approach negatively. The other -traps are recognised by their symptoms — a green that cannot go red, an empty that cannot be -distinguished from truncated, a true that is the same byte for two questions. This one names the -general defect directly: *a property that holds of an aggregate is being cited as a property of a -member*, and the aggregate supplies from elsewhere exactly what the member is missing. - -That framing makes the whole class searchable, because the question it licenses is mechanical: -**what is the instrument supplying that the subject would have to supply for itself?** For -compile-clean it is the pool. For the stale binary it is the compiler's identity. For the capped -list it is the unseen 3865 rows. For two lanes reading two refs it is the branch the ruling names. -In every case the instrument was making up a difference the subject could not, and reporting a -result that read as the subject's own. - -**And the corroboration arrived from the opposite direction the same day.** crisp-crab-430 traced -the namespace cut's two remaining blockers to `src/v1/04_infer.dag` pulling `List` by pool-fallback -and resolving to the `FreeMonoid` alias instead of the kernel `List` that imports used to shadow. -Same mechanism, worse symptom — the name finds the *wrong* definer rather than none, so it resolves -and continues. A refusal announces itself; a wrong-definer binding does not. - -## The repair for a claim on the wrong subject is to MOVE it, not to soften it - -*Three authors, three rounds, one afternoon, on the cost forecast for the namespace cut. Recorded -because the correction pattern is sharper than any of the three claims.* - - round 1 smart-ram-730 "pool_parse's frequency changes by a large factor" right shape, wrong term - round 2 deep-ant-102 "pool_bare_census memoizes -> a step function to right memo, wrong subject - certainty, not a multiplication" - round 3 witty-lark-109 the multiplier is on bare_eligible correct - -**Round 1** attached a real forecast to `pool_parse`. **Round 2** checked the memo — correctly — and -concluded there was no multiplier, only a step function. **Round 3** checked the producer and found -both wrong, in different ways: - -- *"Today pays zero" is backwards.* The **scoped** census forces the whole-corpus parse, and it does - so unconditionally. Both calls live in one function — `v1_compiler.cli_run` - `bare_reference_pull_paths_for_source` — with `tree_bare_census_for_root` at its **head** and the - `pool_bare_census` fallback **inside the resolve loop below it**, so the census runs before any - name is looked up at all. A process whose names all resolve in the scoped census pays the parse in - full. The receipt is an ordinary run: `bare_eligible=699`, `tree_census_misses=2` — scoped - hits throughout, parse paid anyway. -- *The memo is real but bounds a different term* — `pool_bare_census`'s own whole-pool symbol index, - the largest of the three and the only one no successful resolve pays for. -- *The multiplier exists on a third term nobody had named.* Bare-eligibility is the **negation** of - `source_declares_import_lines`, and the cut deletes exactly those lines corpus-wide — so - `bare_eligible` goes from 699 toward the whole corpus. **It needs no post-cut estimate, because the - population is defined as the absence of the syntax being removed.** - -### The lesson, which is round 3's and not mine - -> **Deleting a true shape to escape a wrong term loses more than the error did.** - -Round 2's correction was *locally* right — the memo does bound what it was pointed at — and it -destroyed a true forecast in passing. The instinct that a cost was about to change was correct from -the first message; only its subject was wrong. **The repair for a claim attached to the wrong subject -is to move it, not to soften it**, and "soften it" is the tempting move precisely because it feels -like rigour: hedging reads as caution while it is quietly discarding signal. - -**Nobody measured anything incorrectly at any point in this thread.** Every number in all three -rounds was accurate. Each round, the comparand moved and the claim did not — which is this brief's -whole subject, now demonstrated three times inside a single conversation *about* this brief's -subject, by three people who had all read it. - -That last fact is the strongest argument in this document. The class does not yield to knowing about -it. - -## The class is in the escalation channel itself, in both directions - -*Established jointly with deep-ant-102 over the afternoon, from opposite ends of the same tool. -Recorded last because it is the one instance that degrades every other finding in this brief.* - -Everything above is about instruments that report on the *code*. This one is about the channel used -to escalate what those instruments find: - - a SEND can fail silently 429, client timeout, no token charged - -> indistinguishable from success at the caller - a READ can fail silently exit 0, empty payload - -> indistinguishable from "the thread is empty" - -**Both failure modes were hit today, by both parties, and neither announced itself.** A message -believed delivered was confirmed only because a *subsequent* send returned `429: wait 241s` — the -rate limiter was the sole positive receipt available, and it arrived by accident. In the other -direction a read returned exit 0 with nothing, which cannot distinguish between *no reply exists*, -*a reply exists and the read failed*, and *a truncated success*. - -**The only positive confirmations that exist on this channel** are the token counter for sends and a -non-empty rendered payload for reads. Neither is an acknowledgement, and neither is checked by -default. - -### Why this outranks the rest of the brief - -Every other entry describes a claim that could be wrong. **This one describes the medium those claims -travel through** — so a silent failure here does not produce a wrong belief about the code, it -produces a wrong belief about *what has been communicated and agreed*. Two specific errors today came -from exactly that: both of us treated a stale thread as a silent operator, and each of us reported -findings as "raised" that were only ever *sent*. - -The distinction that closed it is worth keeping as a phrasing rule, and it is deep-ant's: - -> **My read failed.** That does not establish that the reply is unreadable, that the thread is -> broken, or that the operator said nothing. - -Reporting **"empty"** rather than reporting **nothing** is the whole discipline. An empty result is a -statement about the reader; silence is a statement about the world; and a channel that cannot -distinguish them will convert the first into the second every time, unless the person holding it -refuses to. - -### The correction that closes it: the read was SLOW, not broken - -**Both of us concluded the read path was gone. It was not — it is timeout-sensitive.** A 300s read -returned empty; a 540s read on the same thread returned 6879 bytes of rendered content. So the -failing reads were **timeouts reported as emptiness**, and `timeout 540` recovers the capability. - -**This is the entry's own class, one level up, and it caught the two people writing the entry.** -Every earlier empty result was a true statement about a reader that had given up, and both of us read -it as a statement about the channel — the exact conversion the section above warns against, committed -while documenting it. I had additionally broadcast "side-chat reads are down" as a status fact. - -**What each observation actually licensed:** - - exit 0, empty at 300s -> "my read did not complete" <- all it ever supported - what we concluded -> "the read path is gone" <- a claim about the channel - what was true -> "the read needs a longer timeout" <- neither of us tested - -**Nobody tried a longer timeout before concluding**, and that is the whole failure: an empty result -was treated as terminal when it was a *parameter* of the call. The distinguishing test cost one -command. - -**Keep the phrasing rule; it survives intact and is what made the correction possible.** deep-ant -reported *"my read returned empty"* rather than *"reads are broken"*, explicitly noting that an empty -payload at exit 0 cannot distinguish *no reply exists* from *the read failed* from *a truncated -success*. Having stated it that way, retrying at a longer timeout was the obvious next move. **The -weaker report is what left room for the stronger answer** — had it been filed as "the channel is -down", nobody would have retried it. - -### The residual, stated because it is not fixed - -The silent-failure shape is unrepaired: there is still no delivery receipt and no read-vs-empty -discriminator, and a send can still fail silently (429, client timeout, no token charged). What -changed is only that one *cause* of empty reads turned out to be recoverable. The positive -confirmations remain the token counter for sends and a non-empty rendered payload for reads — -neither is an acknowledgement, and neither is checked by default. - -## Verification does not generalise - -*My own, caught in review (`review 55425`) on gunbc#9113 — the document reporting the loader finding. -Its front matter read:* - -> **Status of every claim: verified by reading the live tree at `bd84f669681`.** - -That was **true of the mechanism claims and false of the measurement figures.** I had verified three -loader facts line by line — what the fallback arm does, what `pool_bare_census` is built over, what -`[floor-bare-name-ambiguity]` actually reports — and then let one sentence extend that standing over -`0 PoolAmbiguous` and `37389 scoped versus 733 pool-fallback`, which were **lane reports carrying no -run, artifact, or repository receipt** and unverifiable from the tree I had named. - -The reviewer's phrasing of the harm is the precise one: those figures *"cannot be verified from the -cited tree and are used to motivate the requested work."* - -### The rule, which is deep-ant-102's - -> **Standing earned on three checked facts does not extend to a fourth unchecked one in the same -> sentence.** - -Verification attaches to *assertions*, not to documents, authors, or paragraphs. A blanket status -line is a **quantifier over a set the reader cannot see** — and the moment one member of that set was -taken on trust, the line became a stronger evidentiary claim than the evidence supports, which is -exactly what §4b(1) forbids. - -The comparand that moved here was neither a tree nor a number. It was **which assertions the word -"verified" ranged over.** - -### Two things about the repair, because the tempting fix was the wrong one - -**I could have gone and re-measured the two figures and cited my own run.** That would have removed -the reviewer's objection and been the worse outcome: the document's entire ask is *nobody has this -measurement, here is the one line that would produce it*, so quietly producing a partial version -would have blurred the request into a half-answer. **Narrowing the claim is the honest repair; -generating a receipt to rescue a sentence is the other kind.** - -**And the narrowed header had to demonstrate rather than assert its own irrelevance.** It now states -that if every reported figure is wrong, the mechanism finding and the ask are unaffected — and, more -usefully, that a wrong `0 PoolAmbiguous` would *strengthen* the argument, since the whole point of -that section is that the counter **cannot report anything else for this class**. A narrowed claim -that still needs its dropped evidence has not been narrowed, only hedged. - -*Kept because it happened in the front matter of a document about instruments answering narrower -questions than they were asked, written by someone who had spent the day cataloguing the class, and -was caught by a reviewer rather than by its author.* - -## The predicate with no domain — and the two authors who applied it to everyone but themselves - -*The afternoon's capstone, and the one entry whose instances are all the people writing this document.* - -A correct rule was issued: **no PR may land between the prerequisite and the namespace cut if it -alters the cut's conflict set.** Unambiguous, operator-ruled, with a decidable test — does this PR's -file set intersect the cut's. - -**It named its predicate and not its DOMAIN.** It said which PRs must hold without saying over what -set to evaluate that — so the domain silently defaulted to **"the PRs someone happened to mention."** - - largest list anyone had named 6 - one subtree, rebuilt from gh pr list 7 ready, 6 intersecting - computed across all open PRs 41 of 69 intersecting - -The six were real. They were also 15% of the population, and the gap was invisible because every PR -in it was individually fine — approved, green, mergeable. **Nothing was wrong with any of them -except that no one had evaluated the predicate against them.** - -### Then both authors of the census found their own PRs on it - -One session published the intersecting list. The other read it and found **two of their own PRs on -it**, having spent the afternoon telling six other sessions that ready-and-intersecting means hold — -they had read their own PRs' *status field* and run the intersection test only on other people's. - -Ten minutes later the session that **built** the list found **their own PR at row 41 of it**, which -they had written and not noticed. - -**Both PRs turned out to touch the same file: `dag/gunbc/design_document.dag`, the DESIGN.md -authority.** Two people, one authority, each believing only the other's PR was in scope. - -### The near-miss inside the near-miss - -Reasoning from that collision, one of them asserted a mechanism: *the two PRs merge cleanly and the -generated DESIGN.md silently loses a row, with the drift gates removed by the floor cut.* The other -adopted it and called it the strongest available argument for restoring the gate. - -**It was false, and nobody had run the merge.** One `grep '^@@'` on each diff settles it: - - #9002 @@ -137,7 +137,7 @@ DESIGN.md | @@ -168,7 +168,7 @@ design_document.dag - #9098 @@ -137,7 +137,7 @@ DESIGN.md | @@ -168,7 +168,7 @@ design_document.dag - -Byte-identical. Both edited the same long paragraph, so the second to land goes CONFLICTING under any -merge algorithm. **The author of the claim was the instrument that answered a narrower question than -it was asked** — "could this in principle be silent" rather than "is *this one* silent." - -What survives is better than what was claimed, and stronger for being honest: **the case that would -have been silent is one line-number away from the case that was loud.** Different lines in the same -authority merge cleanly while the committed artifact is neither side's regeneration of the merged -authority — untested by anyone, with the near-miss as the only evidence. - -### The ownership column, one field over - - author = briansrls on every PR in the repository - -Ownership had been read off `author`, which is the human's account and identical everywhere. **Not -unreliable — deterministically wrong.** Unreliable would be *better*: it eventually disagrees with -itself and someone notices. A constant wrong answer survives every consistency check anyone would -think to run, which is why two senders misrouted the same session's PRs to the same wrong recipient -without either guessing badly. Ownership derives from `headRefName` and nothing else. - -**A census with a wrong ownership column is a correct set delivered to the wrong people** — the same -failure as an uncomputed domain, one field over. - -### What actually fixed it - -Not a better rule. **A computed domain, and holds that live on the artifact:** - -- the intersection recomputed per PR (one API call each, ~2 minutes for 69) -- an explicit HOLD comment on all 41, carrying the cap and the `>=` inline so the rows cannot travel - without them — because **the merge hand reads the PR, not the thread** -- the two self-caught PRs converted to **draft**, making the hold structural rather than readable - -And two limits kept attached, because both are the difference between a list and a false clearance: - -> **Sound for holding, unsound for releasing.** An intersection found is an intersection; a zero -> means "none among the 3000 of 3965 fetched." A PR overlapping only in the 965 unfetched reads as -> *actively safe* by sitting on a list someone takes as cleared. - -> **"Computed" reads as "solved" and it is only "solved as of a timestamp."** Every PR opened after -> the census starts unheld. - -### Why this closes the brief - -Every other entry is an instrument that misled its reader. This one is a **rule** that misled the -people enforcing it — and it caught both of them, on the same file, inside an hour, while they were -actively cataloguing the class. - -**A rule whose domain is uncomputed is not a weak rule. It is a rule with a silent exemption list, -and the people most confident it is being applied are the ones most likely to be on it.** - -## The fix was more dangerous than the defect: a wrong query outranks a wrong list - -*Immediately after the entry above, and by its own authors. This is the one to read if you read only -two.* - -The previous entry ends by replacing a remembered list of held PRs with a **computed query** — *every -open PR carrying a HOLD comment* — on the reasoning that a list drifts and a query cannot. - -**The query returned 11 of 41. Nothing said so.** - - my pattern startswith("## HOLD") limit 200 -> 13 - corrected test("^#*\s*HOLD") limit 200 -> 41 (matches the census exactly) - corrected test("^#*\s*HOLD") DEFAULT -> 11 - -**Two independent silent narrows, composing.** - -1. **The pattern.** My holds begin `## HOLD`; the other author's begin `HOLD — do not merge…` with no - `##`. Two spellings of one concept, and `startswith("## HOLD")` cannot distinguish *no holds here* - from *holds spelled the other way*. -2. **The default limit.** `gh pr list` caps at 30 without being asked and without saying so — the same - silent truncation as `gh pr view --json files` at 100, in a different command, hit again by people - who had documented the first one that morning. - -Either alone under-reports. Together they returned **27%** of the domain with the confident shape of a -complete answer. - -### Why this is worse than the list it replaced - -**A wrong list is obviously incomplete. A wrong query looks authoritative.** - -Had we acted on it, it would have released 11 PRs and left **30 frozen permanently** — and the freeze -would have been invisible, because the artifact that would have shown the omission is the very query -that omitted them. A list at least invites the question *is anything missing?*; a query answers that -question, wrongly, and is believed. - -**The generalisation is uncomfortable and it is the point:** *"stop maintaining the set, recompute -it"* is correct and is not sufficient. Recomputation moves the failure from **staleness**, which is -loud and expected, to **an under-specified predicate**, which is silent and trusted. The computed -domain still has a domain — the pattern, the limit, the corpus the tool consents to search — and none -of those announce themselves. - -### The practice that caught the second half - -The same exchange corrected a related claim of mine. I had written that one hold rationale — *do not -move a file under a running measurement* — survives independently and reaches **#9026 alone**. True of -my 13. Across all 41 it reaches **seven**: `9079 9075 9028 9026 9024 9007 8974`. - -It was caught for one reason, in the other author's words: - -> I would not have caught that if you had not stated your number **with its denominator attached** — -> *"on my 13"* is what made the gap visible. - -**A count carrying its denominator is falsifiable by anyone holding a larger one.** The same count -stated bare — *"it reaches #9026 alone"* — is not wrong so much as **unaskable**, because nothing in -it invites the question *of what?* That is the cheapest habit in this entire document and the only one -that has repeatedly caught errors before they cost anything. - ---- - -## The self-testing capability: when the instrument and the subject are the same object - -The last specimen of the day is the only one where the comparand that was substituted is not a -subject at all. It is **the moment**. - -I told my manager, as a present-tense fact, *"my sends work, only my reads are gone."* What I -actually held was two past observations — one send confirmed by a token counter dropping, one by a -later rate-limit refusal — and no mechanism connecting either to the present. The next send hung -for five hundred seconds and returned nothing. - -**Nothing looked wrong, and that is the point.** Every other entry in this document substitutes one -subject for a neighbouring one, and the substitution is visible once you name both. Here the subject -is genuinely identical: same command, same session, same channel, same account. The only comparand -that moved was **time**, and *"worked at 12:52"* is not *"works now"* — a capability that held twice -is not a capability that holds. There is no join to check, no denominator to state, no second list -to diff. The habit that catches the rest of the document does not fire on this one at all. - -### The sharper half: the retry was the probe - -The recovery move made it worse in a way worth stating separately, because it is a **shape** rather -than an incident. - -I could not determine whether the hung send had landed. The only available test was **to send -again** — so the instrument and the subject were the same object. That leaves exactly three -outcomes, and only one of them is informative: - - fast rate-limit refusal -> the first one landed (informative) - clean success -> the first one did not (informative) - a hang -> neither, and now there may be two - -I got the third. Eight minutes spent, no information gained, and the population of possibly-sent -messages went from one to two — which is the failure mode to actually fear here, because the -correction for *"I am not sure it arrived"* is to send it five times, and then discover that three -did. - -**The general form: any capability whose only test is its own exercise cannot report its own state.** -It has no observer that is independent of it, so a failure to answer is indistinguishable from a -failure to ask. This is not a property of one flaky channel. It is the condition that makes -*"verify before asserting"* — the instruction every other entry here resolves to — **unexecutable**, -and it is the one case in this document where the standing advice has no purchase. - -What is left when the advice does not apply is not a better probe but a **narrower claim**: - - do not say the channel works - say two messages landed earlier; the most recent is unknown and I cannot resolve it - -The second sentence is worth more than the first even though it promises less, because a reader can -plan against it. The manager receiving it did exactly that — routed around me rather than waiting on -me — which is the whole return on the correction. - -### The symmetry, recorded because both of us made it inside the hour - -My manager, reading the correction, found the same error pointing the other way in their own log: -they had recorded having informed the operator about my channel, and had not — their message was -entirely about a different subject. They caught it only by **re-reading what they had actually -sent** rather than what they remembered sending. - - I asserted a capability I had not verified holding. - They asserted an action they had not verified taking. - -Same hour, same class, opposite halves. Neither was caught by a check; both were caught by someone -else's correction forcing a re-read of the primary artifact. **That is the honest summary of this -entire document: the mechanism that found nearly every specimen in it was a second party re-reading -the source, and no instrument in the repository substitutes for it.** - ---- - -## The marker that exists before the run: counting a string in a log that also contains the command - -Two sessions were caught by this within an hour, from opposite ends, and it is the most mechanical -trap in this document — no judgement required to avoid it, only knowing it exists. - -`ctrl-build` **echoes the dispatched script into the log** before executing it. So any marker you -grep for is present in the log **at time zero**, put there by the echo rather than by the run: - - grep -c "cost-partition" run.log -> 2 - -Which reads as *the line landed twice*. Both matches were the echoed script. The payload emitted -nothing at all — the run was killed at 45 minutes without producing a single partition line. - -### Why it is worse than a wrong count - -A miscount is recoverable; you notice the number is odd and look. **The severe form is a watcher -anchored on presence**, because the marker is there *before anything starts*: - - wait until log contains "DONE" -> fires immediately, on the echo - -> reports a run as settled that has not begun - -That is not a delayed wrong answer, it is an **instantaneous** one, and it arrives during the window -where the correct answer is *"no information yet."* The same session lost an hour to a watcher firing -on its own end-marker in the echoed script. - -### The rule - -**A marker must be something only a real run could emit.** A literal in the script fails that by -construction — the script is data that reaches the log intact. So the marker has to carry a value the -run *computes*: - - bad echo "DONE" a literal; present in the echo - good echo "DONE files=$(wc -l < out)" carries a computed value - good echo "EXIT=$?" carries an outcome - good anchor on a timestamp the run stamps, not a word the script contains - -Failing that, match with an anchor the echo cannot satisfy — line-start on a line the echo indents, -or a count that must *exceed* the number of times the string appears in the script itself. The second -is worth stating because it is the honest general form: **when the instrument's input is visible in -the instrument's output, every measurement has a floor contributed by the input**, and you either -subtract that floor or make the marker unforgeable by it. - -### Its neighbour, from the same failure - -The run that produced the miscount also could not say whether it was slow or hung. **The harness -emits its cost partition only on termination**, so a 45-minute silence and a deadlock are -byte-identical from outside — the only evidence of progress is the artifact that finishing produces. - -That is the self-testing shape from the previous entry, and this one is the **better** case, because -here the repair exists and is cheap: emit per-phase progress markers so that liveness has a signal -distinct from completion. The narrowed re-dispatch does exactly that — one root at a time, each -capped, printing begin/exit stamps per root — which converts *"the run failed"* into *"this root -failed"*, and makes the timeout informative instead of merely negative. - -**Where the two entries meet:** an instrument that reports only at the end cannot report on itself, -and an instrument whose marker is a literal reports before it starts. **Both produce a confident -reading during the interval when nothing is known** — one by silence that looks like a value, one by -a value that precedes the measurement. - -### The generalisation, which is larger than logs - -The framing that makes the previous entry a class rather than a `ctrl-build` quirk, in the words of -the session that hit it: - -> What made the echo dangerous is not that the marker appeared. It is that **it appeared at time -> zero**. Presence-based watchers all have a defined answer before the subject exists. - -**Any check whose predicate is satisfiable by the setup of the experiment is green before the -experiment.** The log echo is one instance; the shape does not need a log: - - a file the harness creates empty, checked for existence - a table the migration creates, checked for presence rather than contents - a metric registered at startup at zero, checked for "is it reported" - a marker string in a script, checked by grep against the script's own output - -In every case the check passes at t=0, and the interval where it is wrong is exactly the interval you -built it to observe. **This is the decoration failure from DESIGN §4b arriving on a timeline instead -of in a corpus** — not a check whose RED is unauthorable, but one whose GREEN precedes its subject. -The repair is the same in both: make the passing state something only the real event could produce. - -### A specimen of the same trap in a different instrument, caught before it was reported - -Checking whether a commit was present in a branch's history: - - git log --oneline | grep -ci "9090" -> 1 reads as PRESENT - git log --oneline | grep -E "\(#9090\)" -> nothing actually ABSENT - -The single match was **`e19090e107` — a commit hash containing `9090` as a substring**, on an -unrelated PR. **A bare PR-number grep over `git log` has a false-positive rate nobody accounts for, -because hashes are hex and PR numbers are decimal digits that occur inside them.** Every short hash -in the log is a lottery ticket against every PR number you might search for, and the log is long. - -What makes it worth recording is the counterfactual: reporting the first number would have said a -cost row *was* present and therefore that three separate measurements *were* comparable — the exact -unrecoverable error the sibling session had written a message an hour earlier to prevent. **The -instrument would have been used to confirm the very claim it was built to refute.** - -The rule is the delimiter, not the number: match `(#9090)`, never `9090`. Same shape as the marker -rule above — **the substring is satisfiable by things that are not the subject**, and narrowing the -pattern until only the subject can satisfy it is the construction move. Anchoring (`^RUN_EXIT=`) is -the validation move and remains defeatable, because an echoed script can begin a line that way too. - -### A first-person receipt for this entry, collected while writing it - -Within the hour of recording the rule above, the author hit it from the other side. A read was -dispatched to the background and the harness reported: - - Background command "... dashboard-ops side-chat 2 > /tmp/sc9.txt ..." completed (exit code 0) - -**The payload had failed.** The file it wrote: - - RC=124 - 0 /tmp/sc9.txt - -`124` is `timeout`'s signal that the command was killed at its limit, and the output was empty. The -reported `exit code 0` belonged to the **wrapper** — the `echo` and `wc` that ran *after* the timeout -and succeeded at printing the failure. **The status was honest about a narrower subject than the -notification's phrasing invited**: "completed" was true of the shell; nothing about it spoke to -whether the read returned. - -Two properties worth extracting, because the specimen is unusually clean: - -- **The failure was legible only because the payload wrote its own status into the file.** `RC=$?` - is exactly the marker rule above — a value the run computes, not a literal — and it is the only - reason the wrapper's green was catchable. Without it, `completed (exit code 0)` and a successful - read are the same artifact. -- **The last thing in the pipeline determines the reported status**, so appending any reporting step - after a failing one converts a failure into a success. `cmd; echo done` exits 0 whatever `cmd` did. - This is the same shape as the log-echo trap: the instrument's own machinery contributing the - evidence that the instrument reads. - -Recorded here rather than paraphrased because the counterfactual is exact: the notification was read, -the green was **not** believed, the file was opened, and the failure was found. The habit that did -that is the one this document keeps arriving at — **do not read the status, read something only the -subject could have produced.** - ---- - -## Two ways to be confidently wrong from real source: the scoping error and the sampling error - -These arrived within an hour of each other, from two sessions reading the same file, and the pair is -worth more than either — because they look identical in the transcript and have **different -remedies**. - -Both sessions were tracing whether a profile lookup misses for a carrier spelled `FreeMonoid`. - -### The scoping error — a row is not the map that contains it - - cited: `"FreeMonoid": "FreeMonoid"` is in container_template_alias_rows - actual: it is in container_template_algebra_rows — a DIFFERENT map, 14 rows to the other's 6 - -Found by `grep 'FreeMonoid' types.dag`, which returns matching lines with **no indication of which -declaration they belong to**. The line was real, the quote was exact, and the container was never -checked. - -**This is the same error as verifying a code snippet without checking its enclosing function** — the -same session had done exactly that earlier the same day, with a `git log`-visible offset attached -that made it look *more* verified. **The remedy is: resolve the containing scope, not the match.** -`grep` is a line instrument being asked a containment question. - -### The sampling error — a map's first row is not the map - -The other session made a **different** mistake with the same outcome. They bound the function to the -**right** map — grepped `container_template_algebra`, saw `map_get(container_template_algebra_rows, -name)`, correct — and then asserted that map's *contents* from the one line of it visible on screen: - -> "rows are keyed by SPELLING: `List` -> `FreeMonoid`" - -**True of the rows they had seen. False of the map**, which also carries `"FreeMonoid": -"FreeMonoid"` and the other algebra-name identity keys. The name resolution was right; the **payload -was filled in from a partial view**, and the partial view was consistent with the conclusion, so -nothing felt wrong. - -**The remedy is different: print the whole thing.** One command settled it — both maps enumerated, -sizes compared, subset relation checked. It was not run, because the visible rows already agreed -with the expected answer. - -### Why separating them matters - - scoping the match was real; the CONTAINER was assumed -> resolve the container - sampling the container was right; the CONTENTS were assumed -> enumerate the contents - -**Neither is carelessness and neither is caught by re-reading your own work**, because in both cases -what you looked at was true. They are caught by a second party tracing the same path, which is what -happened here in both directions inside an hour. **The confident-wrong-answer-from-real-source class -has at least these two members, and a reviewer who knows only one of them will miss the other.** - -### The defect the argument uncovered, which outlived both mistakes - -Printing the maps produced a finding neither session was looking for: - - alias = 6 rows List Map Set list map set - algebra = 14 rows those six PLUS BooleanAlgebra FreeMonoid PartialFunction PointwisePower - and their snake_case forms - alias is a strict subset of algebra True - values agree on every shared key True - -So the six-row map is **exactly the fourteen-row map minus its algebra-name keys**, with identical -values everywhere they overlap. **Its entire semantic content is the subset relation** — it exists to -answer *"is this a surface spelling rather than an algebra name,"* which is a question about what the -**other** map contains. - -That is a single-authority defect in a form worth naming separately: **not two authorities -disagreeing, but one authority whose whole content is a statement about another, spelled as an -independent table.** Two independent readers, both looking directly at the source, both wrong within -an hour, is the measured cost — and it is a better argument for a canonical authority than either -mechanism the sessions were chasing. - -**Both mechanisms they were chasing turned out to be dead.** The inverse *is* reachable -(`container_kind_canonical("FreeMonoid")` → `"List"`, so the profile **hits**), which killed one -session's proposed defect and the other's hypothesis in the same message. **The durable output of the -exchange was the thing found while checking, not the thing being checked.** - ---- - -## Two more from the same hour, both in tooling the author wrote to avoid the first two - -A notification job — deliver "your work is unblocked" to eleven sessions, paced against a rate -limit — produced two specimens in ten minutes. Both are entries already in this document, committed -by someone who had just written them. - -### `pgrep -f` matches the process asking the question - -Checking whether the job was still alive: - - pgrep -f 'relbody|rel2' >/dev/null && echo "STILL RUNNING" || echo "none running" - -> STILL RUNNING - -**Nothing was running.** `pgrep -f` matches against full command lines, and the command line -*containing the pattern* is the shell running the check. The instrument matched itself. - -This is the log-echo trap exactly — **the instrument's own input appearing in the space it -searches** — and the same repair applies: the pattern must be something only the subject could -satisfy. `ps -eo args | grep foo | grep -v grep` is the folk remedy, and it works for the same reason -the marker rule does: it removes the searcher from the searched set. Better still, have the job write -its own liveness (a pid file, a heartbeat line) rather than inferring it from a process table that -contains the question. - -**Cost here: a false "still running" that nearly led to a duplicate job being launched alongside a -dead one** — which would have double-sent to sessions already notified. - -### A retry loop that treats a permanent refusal as a transient one - -The job's failure arm backed off and retried on *any* non-success: - - for try in 1..5; do - out=$(send ...) - case "$out" in *delivered*) ok; return;; esac - sleep 70 - done - -Two retries burned before anyone looked at `$out`. The actual response: - - HTTP 400: {"error":"recipient session not found: sleek-fox-685"} - -**The session did not exist.** No amount of waiting was going to change that, and the loop would have -spent five minutes to report `FAIL` — a word that reads identically to a rate-limit failure and -would have sent the operator looking for a budget problem that was not there. - -**This is the absorbing fallback, in the author's own tooling, in the same afternoon the author -reviewed a PR for it.** The failure arm *widened* — retry, wait, retry — instead of refusing. -The deficit's frequency was zeroed: a nonexistent recipient and a throttled one produced the same -observable, so the distinction that mattered could not surface. - -**The repair is a typed arm per cause**, and it is three lines: - - *'"delivered":true'* -> OK (succeeded) - *'recipient session not found'* -> GONE (permanent; author unreachable, report it) - *'429'*/budget -> RETRY (transient; back off) - -The `GONE` arm is the one that carries information: **it says an author exists who cannot be -reached**, which is a fact the coverage report must state rather than absorb into a retry count. With -the arm present, the job reports *"delivered 10, unreachable 1"*; without it, *"delivered 10, failed -1"* — and only the first tells anyone that a lane is stranded with no channel to it. - -**Both defects were in code written specifically to deliver corrections about undelivered -corrections.** That is not irony worth savouring; it is the measurement this document keeps taking — -**knowing a class does not stop you instantiating it**, because the trap is never labelled at the -moment you commit it. What changes outcomes is not knowledge but the habit of opening the artifact: -`ps` instead of `pgrep`, `$out` instead of the exit status, the map instead of the row. - ---- - -## A count that answers "ever" while the reader asks "now" — and a join applied in only one direction - -The readiness payload for a pull request reports, among other fields: - - head_sha f75fb625217 - approval_count 1 ['claude'] - - 55428 claude approve sha=c6584caf3 STALE - 55358 claude approve sha=223397bd8 STALE - 55351 claude approve sha=06b7e7ebd STALE - 55349 codex request_changes sha=b8ecca0b2 STALE - 55314 claude approve sha=f12d1dbb2 STALE - -**Four approvals, none of them on the head, and the count says one.** The field appears to answer -*"has a distinct provider ever approved this PR"* while every reader consults it to answer *"is this -head approved."* Those questions coincide exactly until someone pushes, and diverge silently -thereafter — no error, no staleness marker on the number itself, no signal that the head moved. - -### The asymmetry is the finding, not the lag - -The same payload reports `stale_providers: ['codex']` and **correctly discounts the -REQUEST_CHANGES** as stale, because that review's sha is not the head. - -**So the join exists.** The machinery for comparing a review's sha against the head is present, -implemented, and demonstrably working — **applied to refusals and not to approvals.** That is worse -than an absent feature, because absence is uniform and this is directional: - - stale REQUEST_CHANGES -> head-joined, discounted -> removes a blocker - stale APPROVE -> not joined, still counted -> preserves a green - -**Both defaults favour merging.** No single decision here is unreasonable on its own; the pair is -what produces a readiness verdict biased in one direction, and neither half looks wrong in -isolation. A reviewer auditing the refusal path would find a correct head join and conclude the -payload is head-aware. - -### The instance where it was RIGHT, which is the part worth keeping - -This document's author read that field at ~15:00, saw `approval_count: 1` with `ready: true`, and -escalated the PR as unblocked. **At that moment the counted approval was genuinely on the head** — -the claim was true when made. The head moved afterwards. - -So the report was accurate, then became false, **and nothing about the field could distinguish the -two states.** It is the same shape as reporting a capability as working because it worked twice: -**the comparand is time**, and a bare count cannot carry a head. The number is identical in the -sound case and the unsound one. - -### The rule - -**Never quote an approval count without joining `reviews[].sha` against the head and reporting the -head-bound number.** If the two differ, report both. A count is not an answer to a question about a -specific revision unless it carries that revision — and a field that silently answers the more -permissive of two readings is exactly the instrument this document keeps finding: honest about a -narrower question than anyone asks of it. - -**The operator's own phrasing anticipated this** — a ruling issued the same day required the PR to -obtain *a head-bound approval*, with an explicit warning not to merge an uncomposed head "just -because old checks are green." That qualifier reads as pedantic until you see the payload; the two -specimens behind this entry are why it was necessary. - ---- - -## The capstone: in a self-hosted compiler, the tool is a variable too - -Everything above concerns an instrument answering a narrower question than the reader asks. This is -the same failure with the largest blast radius the day produced, and it took four sessions an -afternoon to notice. - -A branch's required run refused with **71 hard diagnostics**, and its floor produced **361 lines**. -Four lanes bucketed the symptoms into families and authored mechanism theories: a carrier/profile -lookup miss, a missing inverse in an alias table, a lost type argument, a gap in a call-target -vocabulary, a changed arm selection in expression inference. **Every theory was internally -coherent.** Several were refuted by execution; the survivors were refuted by reading. Nothing fit. - -Then one dispatch settled it. The compiler was rebuilt from the branch's exact merge-base, **the same -sources** were checked out, and the run repeated: - - seeded from the branch's own earlier binary 71 hard diagnostics - seeded from a merge-base-built binary ZERO - -**Same sources. Different compiler. The refusals had no source cause at all.** A binary built from an -earlier state of that branch had been regenerating a mirror that carried a defect forward, and every -diagnostic under investigation was that defect's output. - -### The reasoning error, which was valid and still wrong - -The attribution had been declared *settled* on this argument: - - main is green at the merge-base - the branch is merge-base + one delta - therefore the delta causes the diagnostics - -**The syllogism is valid. The premise was incomplete.** Two trees were compared while a second -variable moved silently — main's CI seeds its compiler *from main*; the branch seeded its compiler -*from itself*. **In a self-hosted repository the compiler is not a constant across a source -comparison**, and treating the source as the only variable is the one assumption that can never hold -there. - -### The rule, and its scope — the scope matters as much as the rule - -**"I changed the compiler and the compiler broke" has two readings, and nothing in the source -distinguishes them.** The discriminator is one dispatch: rebuild the tool from a known-good commit, -hold the sources fixed, re-run. - -**But the test is whether the COMPILER WAS HELD FIXED ACROSS THE ARMS — not whether the claim -involves diagnostics:** - - CROSS-BINARY tree A measured with binary A, tree B with binary B. - The tool moved alongside the variable under test. DEAD. - - PAIRED WITHIN-BINARY both arms measured with the SAME binary, one variable changed. - Contamination shifts both arms equally, so the DELTA survives - even when the absolutes are wrong. NOT KILLED. - -A module refusing standalone and passing with its import header restored, **under one binary**, is -the second shape: for contamination to explain it, the contaminated compiler would have to refuse one -arm and accept the other *on exactly the axis under test*, which is the claimed mechanism rather than -an artifact of it. - -**Second-order, and most likely to be skipped: a paired comparison is immune to a compiler that is -WRONG, not to one that is IRRELEVANT.** If the binary measuring both arms was itself built from a -contaminated mirror, the delta is real *for that compiler* and says nothing about the one the -repository ships. Such a result is stated as *"X changes behaviour in this compiler"*, never *"in -gunbc"* — and re-running the pair under a merge-base-built seed upgrades it only as far as **that -seed's revision** — "in the merge-base compiler" — never to "in gunbc" unconditionally. **A claim -generalises exactly as far as the provenance of the binary that produced it, and no further.** -Reaching "in the compiler this repository ships" requires the pair to be run under that compiler, -which is a different and usually unavailable control. - -**Stating the rule without the scope would have been the next over-correction**, sending lanes to -retract paired comparisons that were never contaminated. The unscoped version was written first, by -the author of this document, and corrected by the session it was sent to. - -### The asymmetry, which is the day's actual finding - -Auditing every claim four sessions made against that boundary produced a clean split: - - SURVIVED every correction, untouched facts established by READING SOURCE - an alias declaration; a map's contents; which parameter a function takes; - a law recorded in a module; the shape of a fall-through - - NEEDED retraction or narrowing facts established by MEASUREMENT - a diagnostic census; a population bound; a per-file cost; an attribution; - a symptom taxonomy - -**Every claim that had to be withdrawn came from a measurement. Every claim that survived came from -reading the source.** - -This is not an argument against measuring — measurement answers questions reading cannot. It is that -**a measurement carries provenance obligations a source read does not**, and the two had been treated -as interchangeable evidence. A source read is reproducible by anyone with the tree, carries its own -context, and cannot be invalidated by a tool. A measurement depends on which binary, which base, -which head, which roots, run when — **and it reports a number either way**, with the same confidence -in both cases. - -**The number does not know it is wrong.** That sentence covers every entry in this document. - ---- - -## Why this class recurs: the checking artifact is one step further away than the reasoning - -Every entry above is an instance. This is an attempt at the generating condition, and it comes from -two sessions comparing error logs at the end of the day and finding the same shape three times each. - -**Session A's three:** a code snippet attributed to the wrong enclosing function; an attribution -declared *settled* from a syllogism whose premise omitted a second variable; a **size** argument -offered against a **structure** objection. - -**Session B's three:** an emitter defect partitioned by POSITION when the wall's coverage is over -PRODUCERS; a fallback count quoted as bounding "the defect" when it bounded one of two paths; "194 -files depend on this declaration" when the census had counted a **spelling**. - -Six errors, two sessions, one afternoon, arrived at independently. **Every one was locally valid and -answered a neighbouring question.** And every one was **a single fetch from being right** — read the -enclosing function, ask which binary, open the ruling text, check what the wall ranges over, ask -whether the count is of names or of resolutions. - -### The condition, stated as a claim rather than a moral - -**The error appears when the artifact that would check a claim is one step further away than the -artifact the claim was reasoned from.** - -Not further in difficulty — further in *steps*. In every case above, the reasoning input was already -open: a grep hit, a count, a review comment, a green run. The checking input required one more -action: resolve the container, name the binary, fetch the ruling, read the producer. **One step.** - -That gap is small enough to be invisible and large enough to be skipped, and it is skipped -*precisely when a lane is moving well* — because the reasoning input is sufficient to produce a -confident, coherent, communicable claim. **Nothing about the moment feels like a gap.** The output is -fluent and internally consistent, which is exactly the artifact this document opened by warning -about. - -### Why "be more careful" is the wrong remedy - -Six instances by two competent sessions in one afternoon is not a diligence failure; it is what the -default produces. The remedy is not vigilance but **shortening the distance to the checking -artifact**, or making its absence loud: - - reasoning from a grep hit -> the check is: what declaration contains it - reasoning from a count -> the check is: over what population, produced by what - reasoning from a green run -> the check is: which workflow, which binary, which head - reasoning from a review's claim -> the check is: the ruling text, not its summary - reasoning from another lane's PR -> the check is: ask that lane, do not infer from files - -**Each is one command or one message.** The entries in this document are, almost without exception, -the record of that one action not being taken — and of a second party taking it later. - -### The corollary that makes it operational - -**A claim's confidence should be bounded by the distance to its checking artifact, not by the -coherence of the reasoning that produced it.** Coherence is available for free on the wrong premise; -it is not evidence and it never was. When the check is one step away and untaken, the honest form is -not the claim but the claim plus its unfetched premise: *"the snippet matches — I have not checked -what contains it."* - -That sentence is longer, weaker, and would have prevented every entry in this document. - ---- - -## The ruling: a measurement identity, and why a structure beat our rule - -The bootstrap finding above was escalated, and the ruling that came back is better than the boundary -two sessions had negotiated. It is recorded here verbatim-where-quoted because it supersedes the -prose rule, not merely endorses it. - -### The scope - -> **A stop-the-line correction for cross-binary source attribution, not a blanket invalidation of -> paired experiments.** - -Retired: the source-causal interpretation of the diagnostic census; the symptom partition derived -from it; and the five mechanism explanations **insofar as their only evidence was that output**. Also -retired — and this is the part a lane would have missed — **any queue ordering based on those -families or their apparent sizes.** A retraction that leaves the decisions the retracted evidence -drove is not a retraction. - -### The sentence - -> **The explanations can remain as hypotheses only if they have independent controls. Their internal -> coherence gives them no residual evidentiary weight.** - -**That is the sharpest statement of this document's subject produced by anyone.** Five explanations -survived an afternoon of scrutiny by competent sessions, and every one was internally consistent, -mechanically plausible, and grounded in real code. **Coherence was doing all the work, and coherence -is available for free on a false premise.** It is not weak evidence; it is *no* evidence, and the -instinct to keep a well-argued hypothesis "on the list" after its observations are withdrawn is the -instinct this sentence forbids. - -### The structure, which is the real correction - - M { source_tree, compiler_binary_identity, command_and_configuration, - measured_subject, terminal_phase } - - "A SOURCE SHA ALONE IS NOT A MEASUREMENT IDENTITY." - -With that shape, the two topologies are not a rule to remember — they are visible in the record: - - CROSS-BINARY DIAGONAL M(source_A, compiler_A) vs M(source_B, compiler_B) - TWO fields differ. Inadmissible for source causation, by inspection. - PAIRED WITHIN A BINARY M(source_A, compiler_X) vs M(source_B, compiler_X) - ONE field differs. Internally causal. - -**We wrote a rule about when a comparison is admissible. They wrote a structure in which the -inadmissible comparison is legible as two fields moving.** Ours requires a reader to remember and -apply it at the moment of temptation; theirs makes the defect a property of the record's shape. - -**That is construction-over-validation applied to our own epistemics** — the preference this -repository's design doctrine states as its central move — and two sessions who had spent the day -citing that doctrine at each other reached for prose when the substrate move was available. **The -document you are reading is a catalogue of instruments answering narrower questions than they were -asked; it was written without noticing that its own central finding was being carried in a form that -could not enforce itself.** - -### The postscript that belongs here rather than anywhere else - -Within an hour of the section above being written, its author took a sibling session's report of a -capability failure — a state change the sibling had marked as certain, and which turned out to be a -byte-count read from a file that was still being written — generalised it from one session to three, -and delivered it to the one reader whose behaviour it would have changed. - -**The checking artifact was not one step away. It arrived unbidden, within minutes, in both -directions.** Neither session waited for it. - -**Knowing the class does not confer immunity to it.** That is not a rueful observation; it is the -argument for the structural move over the prose one, made by the two people who had just written the -prose. - -## A second postscript, one day later: two clocks on one object - -The postscript above says knowing the class confers no immunity. Here is the receipt, in the same -hand, twenty-four hours later, and it is worth recording because it is the cheapest specimen in this -document — the whole error and its correction fit inside eleven minutes and four commands. - -### What happened - -A subtree digest carried a child's title beginning `MAIN RED`. Checking it rather than filing it was -correct, and the check found something real: main's last *completed* witness run was fourteen hours -old, and the run on the current head was `in_progress`. - -The arithmetic was `now - run.createdAt = 142 minutes`, against the ~30 minute floor figure DESIGN.md -records. A 4.7x overrun. That went to the parent session as a report, hedged carefully about *cause* -— explicitly refusing to attribute the stall to the commit under test, naming that refusal as the -correlation this fleet keeps mistaking for a cause — and carrying a suggested next step: pull the log, -find the phase that is not returning, and note that the per-witness eval deadline is on DESIGN.md's -unguarded list, so an unbounded witness is exactly what that rung drop stopped catching. - -Every hedge in that message was about the *cause*. None was about the *measurement*. - -### The measurement - -`run.createdAt` was `15:14:04Z`. The job's own `started_at` was `16:49:56Z`. Ninety-five minutes of -the 142 was **queue** — waiting for a runner. Execution was 44 minutes, sitting in a step that now -carries three phases against a figure recorded for one. - -There was no overrun. There was probably nothing wrong at all. - -### The shape, which is this document's subject exactly - -Two timestamps hang off one object and answer different questions: - -- `run.createdAt` answers **when was this work requested** -- `job.started_at` answers **when did this work begin executing** - -The reader's question was *how long has it been executing*. Only the second answers it. The first is -not wrong, not stale, and not malformed — it is a correct answer to a question nobody asked, sitting -one field away from the one that was, on the same object, in the same response, under a name that -reads like the right one. `--json createdAt` is what a person types when they want to know how long -something has been going. - -**The hedging went to the wrong layer.** Enormous care was spent on *what explains the number* and -none on *whether the number measures what the sentence says it measures*. That is the same asymmetry -the bootstrap-contamination entry records at much greater expense: five mechanism theories, each -internally coherent, all of them explanations of a difference that the experiment's own design had -manufactured. Care about causes is not a substitute for care about instruments, and it is -systematically the more available kind — a cause is interesting, an instrument is plumbing. - -### Why this specimen is worth more than its size - -Because of what the wrong reading *emitted*. It did not merely record a false number. It issued an -**actionable misdirection**: go read the in-progress log, find the phase that is not returning, -suspect an unbounded witness against a known rung drop. That instruction is well-formed, cites a real -gap in DESIGN.md, and would have cost its recipient an afternoon discovering that the hang is a -queue. The retraction had to name it explicitly and say *disregard entirely*, because a plausible -next step outlives the finding that motivated it — it gets forwarded, and the forwarded copy carries -none of the hedging. - -And the hedged hypothesis had to be withdrawn too, for a reason worth stating on its own: it was -raised only because the overrun needed explaining. Remove the overrun and nothing points at that -commit — but a hedged hypothesis, once relayed, is remembered as *someone suspected #9024* long after -the measurement that motivated it is gone. **A hypothesis inherits the life of its evidence, and -nothing in the way we write them down enforces that.** Withdrawing it by name was the only mechanism -available. - -### The cost asymmetry, which is the operational point - -Finding the error cost one command — reading the job object instead of the run object. Ninety -seconds. The error itself had already been broadcast to a session that routes work to fifteen others. - -That ratio is the entire argument for the structural correction over the prose one. There is no -version of *be more careful* that reliably fires here, because the careful thing was done: the report -named its own weakest link, refused an attribution, and asked for a discriminator. It named the wrong -weakest link. **A measurement identity is a structure you fill in; care is a thing you feel about the -half of the problem that happens to be interesting.** - -### What generalises - -Any object that carries both a *requested* and a *started* timestamp will support this error, and CI -systems all do. The rule that would have caught it is not about CI: **when a duration is the evidence, -name both endpoints before dividing.** An elapsed time computed from a single field is a subtraction -against an unstated assumption about what that field marks — which is the positional-citation defect -(§3) transposed onto time: a number that decays without anyone touching it, because what it measures -was never written down beside it. - -### The coda: the figure was doing the misleading, and the document owns it - -The run finished green while the retraction above was still being written — 47 minutes in the -three-phase step, every step green, the fourteen-hour gap closed at 17:39Z. The 44-minute reading was -the same step three minutes from finishing. So the retraction was right on the merits and not merely -procedurally, which is a pleasant outcome and not the interesting one. - -The interesting one is what the sibling session produced next: the wall-clock of the last fourteen -main runs. - - 146 84 143 148 147 120 108 145 231 219 216 187 165 158 (minutes) - -Median ~146. Range 84–231. **All fourteen `conclusion=success`.** There is no overrun anywhere in that -window, and 142 — the number that started this whole exchange — is *four minutes under the median*. - -So the reading was not merely wrong, it was wrong in the direction of an alarm, against a population -where the alarm can never be right. And the mechanism is not carelessness on the reader's part: - -**DESIGN.md's ~30 minute figure describes the floor fold alone.** Not the queue. Not the toolchain -build. Not the parse sweep or the regen phase, both of which were consolidated into the same step on -2026-08-20 and 2026-08-23. The figure was accurate when written, remains accurate about its own -subject, and sits in a document where the natural comparand — the number a reader can actually obtain -— is the run's wall-clock. **Anyone dividing one by the other concludes a 3–5x overrun, every single -time, from a correct figure and a correct measurement.** - -That is a sharper version of this document's thesis than any of the specimens above it. Earlier -entries describe a reader asking the wrong field. Here the *document* offers a figure whose subject is -narrower than the only question its readers can cheaply ask, and does not say so. The trap is -published, not stumbled into — and the same clause has been re-pointed at fresh run counters twice in -three days, which the Building-&-checks entry itself flags as evidence that transcribed run figures -are positional citations wearing a number's clothes. - -The repair is not a bigger number. It is naming the subject beside it: *the fold takes ~30 minutes; -a green main run's wall-clock has run 84–231 minutes, median ~146, of which the majority is -frequently runner queue*. Two numbers, each with its denominator attached, so that neither can be -divided by the other. **A figure without its subject is not a measurement, it is a number that will -eventually be misused by someone reading carefully.** - -## The discriminator that shared a premise with the thing it was discriminating - -The coda above was written by an author who had, twenty minutes earlier, sent a colleague a -"cheap discriminator" to settle a question. The discriminator was ill-posed, the colleague noticed, -and the shape of the error is one this document had not yet recorded. - -### The setup - -A child session's work-item title read `MAIN RED: returns Bool(false), and its refusal arm -collapses to empty string`. Fourteen of fourteen main runs measured `success`. Two claims, apparently -in tension, so the reconciliation offered was: the floor holds known reds, therefore the witness is -either **enrolled-and-false** (quiet, known, unremarkable) or **unenrolled-and-false** (a false -witness reaching a terminal pass — a serious finding). Check the expected-red roster join; enrolled -means world one, absent means world two. - -That is a clean partition, it is cheap to run, and it is exhaustive over the space it names. - -### Why it could not work - -Both branches carry `false`. The partition varies *enrollment* while holding the witness's value -fixed — and the witness's value was the stale part. The witness **passes**. It pinned a literal -`'sudo' 'systemctl' 'enable' '--now'` while the extdeps module had moved to `/usr/bin/sudo` plus a -non-interactive flag; a merged PR replaced the literal with a form derived from the three owning -authorities, and arm 6 has been true ever since. `MAIN RED` was accurate when written and expired when -that landed. - -So the instrument's output space did not contain the answer. Worse — and this is the part that makes -it a specimen rather than a miss — **its "absent" branch was wired to the alarming conclusion.** A -passing witness that was simply never enrolled is the ordinary state of most witnesses. Running the -join would have returned *absent*, which the framing had pre-labelled *a false witness reaching a -terminal pass*, and the report would have manufactured an alarm out of a repaired witness. The -discriminator was not merely uninformative; it was **biased toward the more exciting world** by a -premise nobody had checked. - -### The general shape - -**A discriminator is only as good as the proposition its branches share.** Every partition holds -something fixed in order to vary something else, and that fixed thing is a premise the instrument -cannot see, cannot test, and will silently carry into whichever branch it returns. The two worlds -were carefully distinguished on *enrollment* — the axis that was already decided — while the axis -that actually mattered was never in the instrument at all. - -The tell is available before running anything, and costs one sentence: **write out what both branches -assert in common, and ask how that was established.** Here the common conjunct was "the witness -returns false", whose entire provenance was *a title written at dispatch time* — a fact with a -timestamp, in a fleet where the underlying file had been rewritten by someone else's merge in the -interim. - -**That rule as stated is not yet actionable, and the qualifier is the whole of it.** Every partition -has a shared conjunct; most are perfectly sound; a rule that fires on all of them fires on none. The -colleague who caught the original error supplied the missing half, and it is **provenance -asymmetry**: the shared conjunct here was not merely shared, it was *the only part of the instrument -that nothing in the instrument could check*, and its provenance — a third party's string, written -once, at dispatch — was **weaker than the varying half's**. Enrollment was live, joinable, and -re-measurable on every run. So the instrument was exquisitely precise about the half that could not -be wrong and silent on the half that was. - -**The tell is therefore a shared conjunct whose provenance is weaker than the varying one's.** Where -the fixed half is the well-established part and the variation carries the uncertainty, a discriminator -is doing exactly its job, and this entry says nothing against it. - -### The second-order point, which is the reason this is filed here - -A *partial* check was already in the author's own message and went unused. The floor reports an -enrolled-but-passing witness as `stale_quarantine`, and the same DESIGN.md line the author had quoted -for `known_red_held=206` also carries `stale_quarantine=0`. The author cited the line, took one -number off it, and did not notice the number beside it. - -**But that figure does not close the question, and an earlier revision of this section said it did — -which would have taught the wrong lesson from an incident whose root cause was trusting a static -string.** `stale_quarantine=0` eliminates exactly one branch, `{enrolled-and-passing}`. It says -nothing whatever about the unenrolled branch — the one the alarm was actually wired to. What closed -the question was *running the witness*. Filing this as "the answer was sitting on the line I already -quoted" would recommend a static document figure over an execution, in a document whose entire -argument is the other way round. - -**The correct and narrower lesson: a ledger figure can eliminate a branch, and eliminating a branch is -not producing an answer.** That is worth having — it is cheap, and it would have halved the space — -but it is a different act from measuring, and conflating the two is how a document figure comes to -stand in for a run. - -Which is this document's thesis one turn further in, with the correction applied: **the checking -artifact is sometimes in the sentence you already wrote — and it is usually partial.** Three of this -brief's entries were caught by their own recipients within minutes, including this section's own -overreach, corrected by the colleague whose refutation it records. That is a functioning fleet, and -it is also the measurement of how little the author's own care was contributing at the margin. - -### What survived, sharpened by the colleague - -The refusal arm still discards its bound cause: `RunnerCommandRefused { host_label: _, reason: _ }` -returning `""`. It hides nothing today, because the command builds. What it guarantees is that *if* -it ever refuses, the witness fails with `reason` in scope and thrown away one line above the failure. -The fix is worth landing precisely because the witness is green — it is not repairing a failure, it is -making the next one legible. - -And that generalises the line this brief already carried about held reds. A **passing** witness whose -refusal arm has no located cause is in the same position as a held red with no located cause: nothing -prompts anyone to look until it breaks, and when it breaks the message is `false`. The empty-string -arm is the not-applicable-versus-malformed conflation collapsed one step further — not a wrong reason -symbol, but *no* reason symbol, chosen at the exact site where the reason was bound and available. - -## The quantifier that no measurement covered - -Every specimen above blames an instrument: a field answering a neighbouring question, a figure whose -subject is narrower than its readers' question, a partition holding the stale half fixed. This one has -no instrument defect at all, which is why it belongs last. - -### What happened - -A sibling session reported that the side-chat read endpoint was hanging, was scrupulous about it — -three completed zero-byte runs, two `HTTP 000` curls, an explicit control returning 200 in 1.64s on -the same host, seconds apart — and asked one question: *does yours work, or not?* - -The reply was measured with equal care. Treatment: 0 bytes on stdout, **0 bytes on stderr**, hung past -a 50-second timeout. Control: 8424 bytes in 1.9 seconds, same host, same auth. Paired, controlled, -same-session, minutes apart. As a measurement of *this session* it was correct, and it is still -correct now. - -It went out under the subject line **CONFIRMED FLEET-WIDE**, with the recommendation that the sibling -spend one of their scarce operator tokens reporting the outage. - -It was not fleet-wide. The sibling's endpoint recovered on the next attempt — intermittent, not down. -The operator's own row: one session healthy, two with reads unavailable and sends fine. A known, -per-session, already-routed-around condition. - -### The shape - -**The measurement was sound and the sentence built on it was not.** Nothing in the treatment, the -control, or the pairing was wrong. What had no evidence behind it was the *quantifier* — a word -attached to a population of fifteen on the strength of a sample of two, one of which was already -known to be flaky at the moment it was cited. - -And the care is what disguised it. Constructing a proper control makes a claim *feel* earned, and the -feeling attaches to the whole sentence rather than to the clause the control actually covers. **A -control licenses the comparison it controls, and nothing else.** Here it licensed *this session's read -path is broken relative to this session's other reads* — a genuinely useful fact, which was in the -message, under a headline the evidence did not reach. - -The scope error also inverted the usual direction of this document's specimens: the earlier entries -describe an instrument answering a *narrower* question than the reader asked. Here the instrument -answered exactly the question posed to it, and the *reader* enlarged the answer on the way out. - -### Why this one is worth its space - -Because it cost someone else something. The other entries wasted the author's time. This one carried -an explicit instruction — *spend a token on this* — to a colleague with a hard budget, on a premise -that was already false when it was sent. **A confident sentence is an instruction to someone**, and it -travels without the measurement that motivated it, exactly as the withdrawn `#9024` hypothesis did -three sections above. - -Two sessions broke the same rule in one exchange, in opposite directions: one described an -intermittent endpoint as a hang; the other took that report plus a single paired reading and promoted -it to a property of the fleet. The second is worse. Over-describing your own observation is an error -about a thing you looked at. Attaching a quantifier is an error about everything you *didn't*. - -### The rule - -**Name the population your evidence covers, in the same sentence as the claim.** Not as a hedge -afterwards — in the sentence, because that is the unit that gets quoted, forwarded, and acted on. "My -session's read path is dead, measured against a working control" would have been true, useful, and -would have prompted exactly the check that settled it. It is one word shorter than the version that -was sent. - -## The positive specimen: what the discipline looks like when nobody is watching - -Every entry above is a failure, and a document made only of failures teaches suspicion rather than -practice. It also flatters its author: catalogue enough traps and you can look rigorous while never -demonstrating rigour. So this last entry is somebody else's work, done right, and — the part that -matters — authored the day *before* the ruling that would have demanded it. - -`docs/probes/underscore_named_call_order_treatment_2026-08-23.md` reports a paired before/after on an -emission change. What it does: - -- **Preregisters the prediction.** The registered result is written down *before* the candidate board - is observed, with the two expected emissions named literally. -- **Runs both arms in one dispatch.** Not two runs compared afterwards. -- **Names its confound and holds it constant.** An annotation-only correction from a different PR - conflicted with the older tree, so *both* arms took the same resolved file, and the receipt says so: - "common setup rather than a treatment difference." The confound is disclosed, not eliminated — - which is honest, because it could not be eliminated. -- **Carries controls that could have moved and didn't.** Three preregistered control identities, plus - an unrelated error code, unchanged across the pair. Without those, "seven blocks vanished" is - consistent with the whole board shifting. -- **Refuses the comparison it is not entitled to.** The paired total is 324 where the retained board - says 316, and rather than quietly using the nicer number or suppressing the discrepancy, it - explains that the common file resolution changes the composite subject and states: *"no count is - compared across those subjects. Only the within-pair delta is claimed here."* - -That last bullet is the whole document in one sentence, written by someone who had not read it. **The -discipline is not producing better numbers; it is declining the comparisons your numbers do not -license.** Every failure catalogued above is the same act refused: a duration divided across two -clocks, a figure divided by a subject it never covered, a partition run over a premise it could not -test, a quantifier attached to a population of two. - -### The one thing it does not settle, stated so the praise is not itself an overclaim - -The after arm includes its own regenerated stage0 mirrors, so the two arms ran under **different -compiler binaries**. For a change *to emission* that is not a confound — the compiler difference *is* -the treatment — and the receipt is right not to control it away. But it means the result is a -within-pair delta under a bootstrap-produced binary, and the day-after ruling on measurement identity -(source ref + compiler binary identity + command and configuration + subject kind + terminal phase) -would ask that the binary be *named*, not that it be identical. Naming it costs a line and closes the -only door this receipt leaves open. - -Which is the right note to end on. The receipt is not perfect, and pointing at it as a model while -suppressing its one gap would be the same flattery this section opened by refusing. - -## Postscript the third: the counter - -Recorded without ceremony because it happened *after* the rule was written, in the same document, by -the same author. - -A dashboard notice reported a side-chat token balance of 14. It had read 14 all morning, so a pending -send was judged not to have landed, and a retry loop was killed on that basis. The balance later read -13. The send had landed all along; the notice was generated before the charge posted. - -`balance` answers **what was the balance when this notice was built**. The question asked of it was -**did my message arrive**. One number, two questions, no error at the boundary — and by then the -identical shape had already been written up twice on the pages above. - -**Knowing the class does not confer immunity.** The first postscript said so; this is the receipt for -the sentence. - -## Two the corpus produced, not the authors - -The entries above are mistakes people made. These two were made by machinery, and both were invisible -for the same reason: **they produced agreement.** - -### The name our own emitter minted - -A ruling went out this evening replacing fraction-of-a-board reports with sets of site identities: -report *which* sites, not *how many*, so that union and overlap are computable without a shared -denominator. The stated constraint was **module plus symbol, never `file:line`** — a line number is -not stable across trees or binaries, which is the positional-citation class the design document -already forbids. - -A lane implemented it against 154 sites and came back with a hole in it. Their sites live in *emitted -Rust*, so the walk took the nearest enclosing item, and thirteen of them came back as: - - v2_lens_coverage :: CACHED 13 sites - -`CACHED` is the `thread_local` static our own emitter generates inside every data-definition function. -Thirteen distinct authority symbols, reported as one name. Restricting the walk to top-level items -gives thirteen symbols with one site each. - -**The constraint was one-sided.** It said where an identity may not come from and never said where it -must. The two-sided form: **module plus AUTHORITY-DERIVED symbol — never a positional coordinate, and -never an emitter-generated name.** `CACHED`, `__m`, `__sorted` and everything else codegen mints are -not identities; they are collisions waiting to be read as clusters. - -What makes this the sharpest instance of the shorter-spelling class recorded here is that **no author -chose the name.** Every other instance in this document has a human picking a spelling that failed to -discriminate. Here a machine emitted the same name at thirteen sites *by design*, so the collision is -guaranteed rather than accidental — and the resulting report is finding-shaped: one symbol, thirteen -sites, a tidy cluster no reviewer would question. The walk was not careless. It asked a reasonable -question of a structure that cannot answer it. - -The same lane also showed the identity was still lossy at symbol grain — 154 sites collapse to 99 -symbols, one symbol holds ten sites, and one spans two mechanism roots. Two lanes hitting *different* -sites inside the same symbol would read as agreement, which would have destroyed the overlap detection -that motivated the whole change. **A join that manufactures false agreement is worse than the -fractions it replaced, because a fraction at least announces that it is a summary.** - -### The duplicate git could not see - -A hand-written 116-line line-based `.dag` parser was found in the seed — stripping declaration -prefixes off trimmed lines, walking characters for identifiers, tracking a coproduct flag. Its own -comment documents a cross-module type corruption it caused: type parameters scanned as references, -resolved whole-pool to an unrelated function, giving one module closure edges to an unrelated witness -and mistyping a third. **The defect and the argument against the mechanism are the same artifact.** - -Then the routing turned up the part no one had seen: **the identical function had been authored twice, -independently, by two sessions.** One PR merged it. Another still carries a byte-identical copy — -same 116 lines, same start line, same md5 — awaiting a disposition on that very function. - -`git merge-tree` over the two produces exactly one definition and **zero conflict markers**. Git -collapses identical additions at one location into a single change. So the collision was invisible to -git, to both reviewers, and to both authors — **precisely because the two copies agreed.** A -divergence would have conflicted loudly; convergence passed silently. - -Two consequences, and the second inverts a decision: - -- **When a fact is not published, the number of hand re-derivations is bounded only by the number of - consumers who need it.** Two sessions independently needed *which names does this module declare* — - a fact the parser already owns — and independently wrote the same scanner. That is the corpus making - the single-authority argument on its own behalf. -- **Refusing the open PR now produces the worse outcome.** The receipt that would admit the scanner - lives only on that branch; nothing on the main line mentions the function at all. So rejecting it - deletes the accounting and leaves the code — a hand-written second parser sitting in a frozen seed - with no growth receipt whatsoever. The refusal has been converted into its own opposite by a merge - that landed first. - -**Agreement is not corroboration when both parties derive from the same absence.** Two independent -implementations matching each other is normally the strongest evidence available. Here it was the -mechanism of concealment, and the thing they agreed about was a fact neither of them should have been -computing. diff --git a/docs/briefs/mirror-drift-four-lanes-2026-08-24.md b/docs/briefs/mirror-drift-four-lanes-2026-08-24.md deleted file mode 100644 index f2596d4139b..00000000000 --- a/docs/briefs/mirror-drift-four-lanes-2026-08-24.md +++ /dev/null @@ -1,172 +0,0 @@ -# Four lanes, one night, one class: a `.dag` edit reaches the executing binary only through regen - -Measured 2026-08-24, 06:00–10:15Z, across four independent sessions that were not working together -and did not know they shared a failure until it was collated here. - -## The class - -`gunbc` is built from the Rust seed. A `.dag` authority edit changes what the seed *should* be; it -changes what the seed *is* only after regen emits the mirror and the mirror is committed. Between -those two moments the tree contains an authority and a realization that disagree, and **every -measurement taken through the binary answers a question about the old authority.** - -## The four - -| lane | authority edited | mirror | how it surfaced | -|---|---|---|---| -| gunbc#9063 | `src/v1/05_emit_rust.dag` (token attestation) | `v1_compiler_emit_rust.rs` never regenerated into the commit — the token commit touched **one file, 18 insertions** | found in review, by grepping the committed mirror for the new symbol | -| gunbc#9076 | `dag/std/algebra.dag` (`kernel_algebra_profile`) | `std_algebra.rs` still carried the seven-key map | CI: `regen FAIL generated surface drift: std_algebra.rs`, **17 minutes before** the floor refused for that exact reason | -| gunbc#9075 | `std.primitive_projection` | `std_primitive_projection.rs` drifted by generator-required expression braces | CI required-regen | -| gunbc#9058 | `.dag` only, evidence `.dag`-side | n/a | unaffected — the control case | - -**Three of the four drew a conclusion from a measurement taken through a binary that lacked their -change**, and in two of them the wrong conclusion was specific and confident: - -- #9063 attributed a 20-line improvement to a gate change that was not in the executing emitter. - A producer-side explanation fits the same numbers and was not excluded. -- #9076 read an unchanged floor error as *the fix did not work* rather than *the fix has not - arrived*. - -## The fifth instance is the worst shape: agreement with the control, for the wrong reason - -Found by `silent-gull-867` in their **own probe**, before running it. - -gunbc#9103 was built to settle a `PointwisePower` residue by measurement rather than argument — a -scratch branch carrying #9059 plus one withheld row, whose floor result differenced against #9059's -was the discriminator. It was branched from #9059 **before the mirror existed**, so the withheld row -sat in the `.dag` and not in the binary that runs the floor. - -Its result would have come back **identical to #9059's**, for a reason having nothing to do with -`PointwisePower` — and *unchanged* is precisely the outcome the probe was pre-registered to read as -**risk not realised**. A measurement whose entire purpose was to stop an argument being shipped -would have shipped it. - -**That is the sub-shape worth naming, and it is not the same as the three above.** Those produced a -wrong number or a wrong attribution. This one produces **no error at all** — the run succeeds, the -numbers are internally consistent, the control and the treatment agree, and the agreement is an -artifact of the treatment never having been applied. In their own words: - -> On this substrate a `.dag` change is not measurable until its mirror is regenerated, and the -> failure mode is not an error — it is a run that agrees with the control for the wrong reason. - -A null result from a stale binary is indistinguishable from a null result from a real one. Every -other member of this class announces itself eventually; this one is **silently confirmatory**, and -it is worst precisely in the probes built to keep their authors honest. - -### The silent member has no self-detection route — it was found by its loud sibling - -`silent-gull-867` corrected the credit given here, and the correction is the most useful fact in -this document. An earlier revision said they saw the false negative *before running it*, which -implies suspicion did the work. It did not: - -> I hit the staleness on #9076 first, where it produced a LOUD failure — the floor refusing with an -> unchanged error while regen named the file — and only then asked whether the probe I had cut from -> that same head shared it. The loud instance is what made the silent one visible. Had #9076 not -> failed first, #9103 would have come back "unchanged" and I would have closed the residue on it. - -**Nothing about #9103 in isolation would have prompted the check, and its pre-registration would -have actively discouraged one** — *unchanged → risk not realised* is an instruction to accept the -very string a stale binary produces. - -So the detection route for the silent member is: **a sibling sharing its cause failed loudly, and -the author generalised from it.** That is not a method. It requires a loud sibling to exist, to be -noticed, to be diagnosed correctly, and to be recognised as sharing a cause with something that has -not failed — four conditions, none of them under the author's control, and all four happened to hold -here. - -The practical consequence is the one that matters for the repair: **you cannot catch this after the -fact.** Every other member of the class announces itself eventually — a wrong number gets -questioned, a refused gate names its file. The silent member's only tell is a confirmation you were -already expecting. The property must therefore be enforced **before** measurement, which is why the -repair belongs at commit or dispatch time and not in anyone's reading discipline. - -Confirmed by measurement rather than left as inference, using the guard proposed for #9063: - -``` -MARKER_DAG_PP=1 the row IS in dag/std/algebra.dag -MARKER_MIRROR_PP_BEFORE=0 the row is NOT in the mirror the binary is built from -``` - -and after installing the regenerated mirror, 6581 bytes against #9059's 6564 — **a 17-byte delta -that is itself the cheap confirmation that the two mirrors differ by exactly the treatment and -nothing else.** - -## Why four, and why in one night - -**The gate is correct.** Required-regen detects the drift and names the file. Nothing is broken -about the detection. - -**It arrives too late to prevent the class.** The only place mirror drift is caught is CI, roughly -20–30 minutes after the edit, in a phase separate from the symptom it produces. By then the author -has usually already dispatched a measurement, read a number, and formed a conclusion. - -Measured: `.githooks/pre-commit` and `.githooks/pre-push` run **`cargo fmt` and nothing else**. -There is no local regen check at all. So the feedback loop for *your authority edit has not reached -your binary* is one full CI round-trip, and the signal arrives beside — and sometimes long before — -the downstream symptom that actually gets the author's attention. - -## What #9076 got right, and it is the most transferable thing here - -Its ledger printed both failures, in order: - -``` -required-ci: regen first_generation_equal=false -required-ci: regen FAIL generated surface drift: std_algebra.rs -... (17 minutes later) -required-ci: floor refused: ... 'Node(std.algebra.PartialFunction)' - establishes no method surface -``` - -**Two failures in one ledger, and their order is the diagnosis.** That is a direct argument for the -independent-phases design: a line-stopping regen phase would have shown the drift and *hidden* the -floor error, leaving one fact instead of the relation between two — and the author would have had -no way to see that the second was caused by the first. Independent phases are usually justified as -completeness; here they were load-bearing for *attribution*. - -## The property a repair must have - -Stated as a property rather than a mechanism, deliberately — see the reviewer trap in -`instrument-traps-2026-08-24.md`: - -> **An author who edits a `.dag` authority in the seed closure should learn, before they measure -> anything, that their change has not reached the binary.** - -Candidate mechanisms to check rather than implement: `claim_executor --required-regen` in -`pre-push` (correct but possibly too slow to be tolerable); or a cheap syntactic pre-push check that -a commit touching a seed-closure `.dag` also touches its mirror (fast, but false-positives on -comment-only edits — loudly, which is the right direction, and confirmable by running regen). -Neither is specified here; the population and the property are. - -## What is NOT claimed - -That any of the four authors was careless. Three of them found their own drift, one within the same -ledger that reported it. The class is a feedback-latency defect, not an attention defect — and the -evidence for that is that it caught four people in four hours on four different files. - ---- - -## Two communication failures the collation exposed - -**A caution restated by a third party becomes a claim.** The retracted 830 finding was sent to -`silent-gull-867` as *how to read a result* — read `declined_live` beside pass/fail, because an -absent row may be a declined one. It came back as *"the arm that swallows 830 identities... the -ladder inverted"*: a number and an arm name generalised into an assertion about a mechanism nobody -in that exchange had traced. Nothing was misquoted. The **mood** changed, from caution to claim, and -a claim propagates where a caution would have prompted a check. - -Their own account of why, which is the sharper half and applies far past this instance: - -> I did the careful thing on the half that touched my own work and the credulous thing on the half -> that did not. - -That is the allocation problem. Scrutiny goes where the author has skin, and a finding handed over -by someone else arrives pre-vetted by their apparent authority. Both of us did it in the same hour — -they took my mechanism claim without opening `run_required_floor`; I took a call-site list as an -answer to a question it was not asked. - -**A retraction does not catch up with what it retracts.** The 830 claim was retracted at the top of -its brief an hour before it was restated. Putting the correction first is necessary and was not -sufficient: the reader had already formed the belief, and nothing re-reads a document you have -already read. The only thing that actually stopped it was a direct message to the specific person -who had it. **Corrections must be pushed to the holders, not published to the artifact** — the -artifact fixes the next reader, not the current one. diff --git a/docs/plans/budget-tree.md b/docs/plans/budget-tree.md index 94f651e3180..dda45dd849f 100644 --- a/docs/plans/budget-tree.md +++ b/docs/plans/budget-tree.md @@ -69,7 +69,7 @@ A third measured field calibrates **INTER-run** co-residence (distinct from the **Values — provenance.** typical/reservation ← **B4 (quick-lynx-78) verified** (`11592347648`, run 28003119550); worst-observed ← **deep-otter-528's srv2 cgroup `memory.peak` monitor** (`32434110464`); within-run runner cap ← `gunbc_ci_runner_cgroup_memory_cap` (8 GiB); The two-driver invariant (parent): the reservation side is driven by typical claim_executor batches (B4 measures it), the cap/worst side by rust-gate rustc *children* (only deep-otter's rust-gate-present monitor sees it; B4's no-rust-gate run under-reports it). NOTE: B4's #5619 dedup moves the *typical* self-RSS only ~0.57 GiB (8.7→8.1, NOT the earlier-retracted 8.7→4.2) and never touches the cap side. NOTE 2: `gunbc_ci_floor_runner_margin_num/den` (6/5 = 20%) was documented here as applying to the reservation, but its only code consumer was `within_run_spawn_budget()` (RETIRED in #5831 — was computing the wrong budget for within-run spawn-width, not the reservation). The margin constants (`gunbc_ci_floor_runner_margin_num/den`) and `gunbc_ci_floor_whole_run_peak_rss_bytes` are now deleted alongside `within_run_spawn_budget()` (no remaining consumers); the reservation reconciliation with deep-otter-528 is a separate runway. -Carriers: [dag/gunbc/ci_budget_tree.dag](../../dag/gunbc/ci_budget_tree.dag) (the two-pool tree + two-number leaf accessors), [dag/gunbc/ci_floor_measurement.dag](../../dag/gunbc/ci_floor_measurement.dag) (the measured carriers), witness [dag/test/claim/ci_budget_tree_witness_test.dag](../../dag/test/claim/ci_budget_tree_witness_test.dag). +Carriers: [dag/gunbc/ci/ci_budget_tree.dag](../../dag/gunbc/ci/ci_budget_tree.dag) (the two-pool tree + two-number leaf accessors), [dag/gunbc/ci/ci_floor_measurement.dag](../../dag/gunbc/ci/ci_floor_measurement.dag) (the measured carriers), witness [dag/test/claim/ci_budget_tree_witness_test.dag](../../dag/test/claim/ci_budget_tree_witness_test.dag). ## Dissolution trigger (DESIGN §6) diff --git a/docs/plans/ci-humming.md b/docs/plans/ci-humming.md index cd09ae9ac03..b70db42e47c 100644 --- a/docs/plans/ci-humming.md +++ b/docs/plans/ci-humming.md @@ -8,7 +8,7 @@ Home: ROADMAP §1 (CI as the substrate integration dogfood). This is the **▸ N srv1 + srv2 (128c / 125GiB each) sit at ~10-34% CPU, ~24-32% MEM, with only **~3 runner slots per host** — so PRs **queue while the cores idle**. The throttle is the runner-slot count, which is set by the per-host **memory budget allocation**, not by saturation, not by fleet capacity, not by OOM. -The slot count is starved because the budget model (`dag/gunbc/fleet_host_budget.dag`) derives `runner_slice_cap ≈ 0`: build memory is subtracted as a `build_pool` **and** re-charged inside the per-job whole-tree-peak divisor. A GHA-CI runner job *is* a build — its `rustc` lives **inside** `system-actions-runner.slice` — so the build memory must be counted **once**, not twice. +The slot count is starved because the budget model (`dag/gunbc/fleet/fleet_host_budget.dag`) derives `runner_slice_cap ≈ 0`: build memory is subtracted as a `build_pool` **and** re-charged inside the per-job whole-tree-peak divisor. A GHA-CI runner job *is* a build — its `rustc` lives **inside** `system-actions-runner.slice` — so the build memory must be counted **once**, not twice. ## oomd demoted (operator §5 insight) diff --git a/docs/plans/cli-run-hollowing-plan.md b/docs/plans/cli-run-hollowing-plan.md index 941aebd6d79..764d3b7298a 100644 --- a/docs/plans/cli-run-hollowing-plan.md +++ b/docs/plans/cli-run-hollowing-plan.md @@ -9,7 +9,7 @@ ## 0. Scale receipt (live tree) - **THIS SECTION CARRIES NO NUMBERS, DELIBERATELY.** It previously transcribed a whole-file line and fn count measured 2026-07-23. Both had gone stale by roughly 83 percent before anyone noticed, because nothing re-derives a number copied into prose. DESIGN's standing rule (2026-08-24) is *name the instrument, never transcribe its output*, and a plan's own scale receipt is the worst place to break it: a reader sequencing work against it budgets against a file that no longer exists at that size. **The instrument:** `git show origin/main:src/v1/stage0/src/cli_run.rs | wc -l` for scale, and the same stream through `grep -cE '^[[:space:]]*(pub )?(async )?fn '` for the fn count. Read them from the tree at the moment you need them. The DIRECTION is the durable fact and it needs no magnitude: the file has GROWN at every measurement taken so far, because v1 lanes absorb host bridges and floor machinery faster than v2 lanes subsume them. -- **Chunk F in `seed-shrink-census.md` names the dissolution SIGN-OFF UNIT** (CI orchestration to workflow `host_effect_apply`), which is a different subject from the whole file. That distinction is the load-bearing half and it survives; the LOC split that used to accompany it here is deleted for the reason above. The remainder is the file's interim seed body, classified by the functional areas in section 2 and tracked as managed seed growth in ROADMAP **section 7 Seed interim** ([`ts-seed-interim`](../../ROADMAP.md) in `dag/gunbc/roadmap_authority.dag`) -- host bridges, lens host feeds, floor and discovery machinery absorbed while v2 lanes land. +- **Chunk F in `seed-shrink-census.md` names the dissolution SIGN-OFF UNIT** (CI orchestration to workflow `host_effect_apply`), which is a different subject from the whole file. That distinction is the load-bearing half and it survives; the LOC split that used to accompany it here is deleted for the reason above. The remainder is the file's interim seed body, classified by the functional areas in section 2 and tracked as managed seed growth in ROADMAP **section 7 Seed interim** ([`ts-seed-interim`](../../ROADMAP.md) in `dag/gunbc/roadmap/roadmap_authority.dag`) -- host bridges, lens host feeds, floor and discovery machinery absorbed while v2 lanes land. - **Sign-off order:** Chunk F runs **after** emitter chunks A–E and de-fork G per census §4 — orchestration dissolves once the compiler pipeline and host-effect spine can carry the floor without a hand-written driver. ## 1. Area map (summary) diff --git a/docs/plans/compiler-guarantee-recovery-gap-analysis.md b/docs/plans/compiler-guarantee-recovery-gap-analysis.md index 3bfd680158d..c2e5b371d48 100644 --- a/docs/plans/compiler-guarantee-recovery-gap-analysis.md +++ b/docs/plans/compiler-guarantee-recovery-gap-analysis.md @@ -3365,7 +3365,7 @@ enforces end to end. definition is the one that binds. **A confirmed production victim, not a hypothetical.** gunbc#9081 commit `29088e133` landed - `dag/gunbc/fabric_cell_converge.dag` carrying two definitions each of `fabric_cell_ids` and + `dag/gunbc/fabric/fabric_cell_converge.dag` carrying two definitions each of `fabric_cell_ids` and `fabric_cell_population_unobserved`. The compile was clean, the witness rows were green, and the copy that executed was the second — a §3 single-authority violation running in production, found by a reviewer reading the file and by nothing else. The reviewer's own diff --git a/docs/plans/discrete-cost-derivation.md b/docs/plans/discrete-cost-derivation.md index 1d0671f45df..ed67eb254a2 100644 --- a/docs/plans/discrete-cost-derivation.md +++ b/docs/plans/discrete-cost-derivation.md @@ -40,7 +40,7 @@ Four load-bearing pieces exist. This note reuses all four and mints no parallel | Symbolic cost fold | `v2.lens.cost` — `SymbolicCost`, `symbolic_cost_of_node`, `cost_lens`, `asymptotic_class_of_cost` | total fold over the closed Node kernel via `fold_node`; `UnknownCost` is lattice top (fail-closed); loop cost reads the modeled bound, never a guess | **scalar, not a vector**; no span; no valuation environment; no binder-carrying sum | | Loop bound + termination | `v2.std.cardinality` — `loop_bound_witness_for_node`, `loop_bound_measure`; `std.termination` `DescentEvidence` | a loop must carry one unambiguous bound measure or the fold yields `UnknownCost` with a `Diagnostic` — exactly the substrate a concrete iteration count needs | nothing — this is the piece that already works | | Concrete cost expressions | `v1.compiler.complexity` — `CostExpr`, `ComplexitySummary`, `Certainty` | `CostSum { binder, upper, body }`, `CostMax`, `CostLog`; and a summary carrying `work` / `span` / `output_size` / `peak_space` / `certainty` | lives in the **v1 seed**, not the shared authority; not reachable from v2 consumers | -| Predicted vs measured realization | `std.realization_schedule` `CostAccount` / `CostBasis`; `std.realization_measurement`; `gunbc.witness_row_cost` | time/space/power with `Predicted | Measured`; and a **populated** dated basis corpus (`dag/gunbc/witness_row_cost_basis.tsv`, host_class `srv_fleet_arm64`) with drift verdicts | nothing feeds Predicted from graph structure — `cost_account_predicted_zero()` is the tell named by the signed scheduling doc's P1 | +| Predicted vs measured realization | `std.realization_schedule` `CostAccount` / `CostBasis`; `std.realization_measurement`; `gunbc.witness_row_cost` | time/space/power with `Predicted | Measured`; and a **populated** dated basis corpus (`dag/gunbc/witness/witness_row_cost_basis.tsv`, host_class `srv_fleet_arm64`) with drift verdicts | nothing feeds Predicted from graph structure — `cost_account_predicted_zero()` is the tell named by the signed scheduling doc's P1 | There is also a live admission law: `v2.lens.witness_cost_locality` already classifies a witness `Local | CouplesToAmbient` from its import closure and routes it `AdmitContinuous | RouteScheduledLane` against a `WitnessInputEnvelope`. That is the consumer seam this note's output plugs into — see §11 C5. @@ -149,7 +149,7 @@ Predicted cycles is then the sum over atoms of count x calibrated cost, and pred 2. **Exact cycles on real hardware is not claimable.** Cache behaviour, branch prediction, instruction scheduling, co-tenancy, frequency scaling and I/O latency are outside the modeled guarantee — the DESIGN §4b column that is deliberately *not* a ladder rung. An exact deterministic cycle count is claimable only against a specified abstract machine or simulator, and that is a different `RealizationTarget`, declared as such. For native hardware, cycles are an **observation that calibrates**, and the honest ceiling for the projection is a distribution, not a scalar. 3. **The basis is dated and cited, per `gunbc.witness_row_cost`'s existing rule** — a basis row names an arm64 srv-fleet run id, never a local x86 measurement, and a re-basis is an appended dated row, never a silent widen. -The measured corpus for calibration exists but its provenance is NOT sound, and C4 must not be planned as though it were. `dag/gunbc/witness_row_cost_basis.tsv` carries 1,173 rows seeded before `ClaimOutcome::TimedOut` could distinguish a killed run from a completed one, so an unknown subset of them are right-censored figures — a deadline ceiling recorded as if it were a cost. For exactly those rows the 2x comparator returned `WithinBasis` against the ceiling, which is not merely unvouched but wrong in the fail-open direction. C4 therefore joins to a corpus of unknown provenance, not to a measurement pipeline. Its real prerequisite is the completion axis reaching the basis rows and the provenance_unknown population draining; calibrating before then calibrates against censored values. +The measured corpus for calibration exists but its provenance is NOT sound, and C4 must not be planned as though it were. `dag/gunbc/witness/witness_row_cost_basis.tsv` carries 1,173 rows seeded before `ClaimOutcome::TimedOut` could distinguish a killed run from a completed one, so an unknown subset of them are right-censored figures — a deadline ceiling recorded as if it were a cost. For exactly those rows the 2x comparator returned `WithinBasis` against the ceiling, which is not merely unvouched but wrong in the fail-open direction. C4 therefore joins to a corpus of unknown provenance, not to a measurement pipeline. Its real prerequisite is the completion axis reaching the basis rows and the provenance_unknown population draining; calibrating before then calibrates against censored values. ## 10. Why a large input is or is not honest @@ -178,7 +178,7 @@ Ordered; each names its acceptance. **This note lands the design record only.** 2. **C1 — the valuation environment and exact pure work.** The seam correction 1 says is absent: bind `SizeVariable` to values, and evaluate to `ExactCost | BoundedCost | UnresolvedCost | CostRefused` over sequential nodes, branches with known conditions, known-finite lists, bounded folds and direct calls. **Accept:** doubling a bounded list doubles the derived fold-body work, by execution; a missing loop bound yields `CostRefused`, not zero; pilot on a real admission function whose cost is independently obvious. 3. **C2 — sharing, and consumption of the engine's loop/recursion/span work.** The binder-carrying sum (correction 3), `span` derivation, and the SCC/descent machinery are the parity note's C1/C2/C4 and are **not duplicated here**; this note's own C2 is the materialization axis — make `Materialization` a derivation input so the same semantic graph derives different work under `Recompute` / `Memoize` / `Share` (§8). **Accept:** memoized and recomputed realizations of one graph derive different work; unknown descent refuses (consumed, not re-derived). 4. **C3 — effect demand, counted exactly.** Count filesystem reads/writes and bytes, subprocesses, network operations, host compiler invocations, as `ExecuteEffect` atoms keyed by `DeclarationRef`. **Assign no latency where no model exists** — counts stay exact and the projection refuses, which is strictly better than a fabricated duration. **Accept:** changing a fixture's file size changes derived read-byte demand; an unmodeled effect refuses rather than costing zero. -5. **C4 — realization calibration against the existing basis.** Project the work vector to predicted time/space under a pinned machine model; compare against `dag/gunbc/witness_row_cost_basis.tsv`. Re-home `llvm_instruction_cost` here, cited and dated. **Accept:** a planted omission in the model makes predicted and instrumented counts disagree and the falsifier goes red. +5. **C4 — realization calibration against the existing basis.** Project the work vector to predicted time/space under a pinned machine model; compare against `dag/gunbc/witness/witness_row_cost_basis.tsv`. Re-home `llvm_instruction_cost` here, cited and dated. **Accept:** a planted omission in the model makes predicted and instrumented counts disagree and the falsifier goes red. 6. **C5 — the admission consumer (this is what retires the proxy).** Replace 'path contains `test/claim/long/`' with a declared cost envelope plus a `CostJustification` plus a named cadence, consumed by floor admission through `v2.lens.witness_cost_locality` `per_pr_admission` — whose own precision-frontier note already names this construction successor and the hand rosters it subsumes. **A missing derivation or a missing consumer refuses; it never silently becomes offline.** **Accept:** the three dissolve-on triggers in §1 fire together, and `witness_exclusion_substrings` hand-rows retire with them. ## 12. Discriminating controls (each must go red when the behavior is wrong) @@ -230,4 +230,4 @@ The four questions this note raised are ruled. Where a ruling changes a carrier ## Dissolution trigger (DESIGN §6) -Delete this doc when the C0 authority ruling is stated on the carriers themselves (v2.lens.cost owning discrete work, the v1 CostExpr machinery migrated, llvm_instruction_cost re-homed to a cited per-target model), a DAG section plus a declared input plus a realization derives ExactCost or BoundedCost or refuses with typed counted causes by execution, the projection to predicted time calibrates against dag/gunbc/witness_row_cost_basis.tsv with a planted-omission RED, and floor admission consumes declared per-witness cost envelopes so gunbc_ci_fast_lane_rule_note, gunbc_falsifier_substrate_long_lane_budget_note, and long_lane_exclusion_note all fire their own dissolve-on together — at which point the carriers state the policy and this note retires. +Delete this doc when the C0 authority ruling is stated on the carriers themselves (v2.lens.cost owning discrete work, the v1 CostExpr machinery migrated, llvm_instruction_cost re-homed to a cited per-target model), a DAG section plus a declared input plus a realization derives ExactCost or BoundedCost or refuses with typed counted causes by execution, the projection to predicted time calibrates against dag/gunbc/witness/witness_row_cost_basis.tsv with a planted-omission RED, and floor admission consumes declared per-witness cost envelopes so gunbc_ci_fast_lane_rule_note, gunbc_falsifier_substrate_long_lane_budget_note, and long_lane_exclusion_note all fire their own dissolve-on together — at which point the carriers state the policy and this note retires. diff --git a/docs/plans/dispatch-maintain-cc.md b/docs/plans/dispatch-maintain-cc.md index b0a19f42702..5333cfdb946 100644 --- a/docs/plans/dispatch-maintain-cc.md +++ b/docs/plans/dispatch-maintain-cc.md @@ -9,7 +9,7 @@ and the spawn-request contract from that doc still hold (graph readiness comes f ## What exists (verified against the live tree, 2026-07-03) -- **Frontier + brief**: `dag/gunbc/roadmap_spawner.dag` — `spawn_frontier` (ready/upcoming/done), +- **Frontier + brief**: `dag/gunbc/roadmap/roadmap_spawner.dag` — `spawn_frontier` (ready/upcoming/done), per-node metadata JSON, `dispatch_brief_template`. Served today at `/target/roadmap-dispatch.json`; the roadmap page renders Ready/Upcoming/Done buckets. - **The srv1 server**: emitted static Node server — `node_http_server_emit.dag` @@ -86,7 +86,7 @@ The server is emitted from `.dag`; the actuator must be too — no hand-written is one realization handler bound to the route shape; the route/interface shape stays in the model. Witness: emitted server source contains the dispatch arm; an emitted toy server executes a harmless command on POST and 404s on GET (RED: drop the row → route gone). -- **M2 — dispatch actuator model** (`dag/gunbc/roadmap_dispatch_actuator.dag`): brief fill +- **M2 — dispatch actuator model** (`dag/gunbc/roadmap/roadmap_dispatch_actuator.dag`): brief fill (template × node metadata → filled brief string), spawn command construction (worktree + tmux + claude argv as data), tmux session naming (`gunbc-dispatch-`), lease classifier reuse, intricacy/volume → effort map, `tmux ls` output parse for GET /sessions, diff --git a/docs/plans/dissolution-census-a-ci-layer-roots.md b/docs/plans/dissolution-census-a-ci-layer-roots.md index 6cf93701276..f31b3b59a22 100644 --- a/docs/plans/dissolution-census-a-ci-layer-roots.md +++ b/docs/plans/dissolution-census-a-ci-layer-roots.md @@ -13,7 +13,7 @@ re-running a script. **Scope note:** Dated observation pinned at the named HEAD. Evidence for selecting dissolution work — not a claim about current main. Re-read live gunbc.ci_layer_roots before acting on any row. -**Scope:** every prose-bearing site inside `dag/gunbc/ci_layer_roots.dag` — the CI floor's single-authority witness-layer, discovery-exclusion, and falsifier-roster carrier (25.3 KiB prose mass per [dag-note-prose-census.md](dag-note-prose-census.md) §1). +**Scope:** every prose-bearing site inside `dag/gunbc/ci/ci_layer_roots.dag` — the CI floor's single-authority witness-layer, discovery-exclusion, and falsifier-roster carrier (25.3 KiB prose mass per [dag-note-prose-census.md](dag-note-prose-census.md) §1). **Instrument (retired):** the rows below were produced by a row-level register of 263 sites and its generated summary, both deleted 2026-08-16 with the projection script under the operator ruling to delete anything not actively derived. Nothing here is re-derivable from a stored artifact; the numbers are a dated observation and re-deriving them means re-running the census against live `gunbc.ci_layer_roots`. **Grain key:** a *site* is one `reason`, `dissolve_on`, or `data String` field; a site is *inline prose* when `is_ref=False` (literal string body); template-ref sites (`reason: excl_*`) carry `is_ref=True` and are not prose. diff --git a/docs/plans/floor-cut-replacement-plan.md b/docs/plans/floor-cut-replacement-plan.md index d7cc8e0a404..553df491023 100644 --- a/docs/plans/floor-cut-replacement-plan.md +++ b/docs/plans/floor-cut-replacement-plan.md @@ -9,7 +9,7 @@ The `.github/workflows/*.yml` files are projections; the cut population is the * - **Old root:** the generated CI surface and its .dag authorities — every job of `ci.yml` (`build`, `regen`, `ci` — whose core is the floor pass `claim_executor --plan-entry src/v2/workflow/ci_floor_plan.dag --plan-function gunbc_ci_floor_plan` — and `heal_generated_artifacts`), plus the falsifier cadence (`falsifier.yml`, `falsifier-alert.yml`). - **New root:** one job calling `run_required_floor`, then whatever jobs the operator re-agrees, one at a time. The seed exists as quarry: branch `session/vivid-bear-458-floor2`, commit `b19a3e2942` — the `run_required_floor` fn in `cli_run.rs`, the `claim_executor` dispatch arm, the one-job emit in `dag/gunbc/ci_workflow.dag`. - **X's residual roles** (closed vocabulary per the doctrine): bootstrap producer and historical measurement source, served from git history and the vivid-bear branch. Never a fallback, internal resolver, or production second opinion. -- **Boundary exclusion:** `.github/workflows/fleet-converge.yml` and `dag/gunbc/fleet_converge_workflow.dag` are fleet operations, not CI — outside this cut unless the operator rules otherwise. +- **Boundary exclusion:** `.github/workflows/fleet-converge.yml` and `dag/gunbc/fleet/fleet_converge_workflow.dag` are fleet operations, not CI — outside this cut unless the operator rules otherwise. ## Step 0 — DONE (dated receipt, 2026-08-15): selection deletion @@ -30,7 +30,7 @@ Delete entirely: Gut or delete the emitting authorities **in the same motion**, so drift gates stop expecting the artifacts: - `src/v2/workflow/ci_floor_plan.dag` — whole file, including `gunbc_ci_regen_floor_plan` (it returns from quarry when the regen job is re-agreed; keeping the obvious survivor is how X's structure creeps back) -- `dag/gunbc/ci_workflow.dag` and the `dag/gunbc/ci_spec.dag` job rows / emit surface for the three files; `dag/tools/gunbc_ci.dag` refuses or emits nothing until the first agreed job returns +- `dag/gunbc/ci_workflow.dag` and the `dag/gunbc/ci/ci_spec.dag` job rows / emit surface for the three files; `dag/tools/gunbc_ci.dag` refuses or emits nothing until the first agreed job returns - `dag/tools/emit_falsifier_yaml.dag` · `dag/gunbc/falsifier_workflow.dag` · `dag/gunbc/falsifier_cold_corpus_execution.dag` · `dag/gunbc/falsifier_lane.dag` · `dag/gunbc/falsifier_alert_admission.dag` · `dag/gunbc/falsifier_alert_decision.dag` · `dag/gunbc/falsifier_alert_residue.dag` · `dag/gunbc/falsifier_alert_state.dag` · `dag/gunbc/falsifier_run_control.dag` (the shared release-build step ids `falsifier_release_build_step_id` / `ci_release_bins_step_id` move or die with it) - the `CiYamlArtifact` / `FalsifierYamlArtifact` rows in `dag/gunbc/generated_artifact.dag` @@ -43,9 +43,9 @@ Side effect: once `ci.yml` is deleted on the branch, PR #8283 stops running CI a Known-certain from the sweep; delete as reachability confirms: - `src/v2/workflow/affected_set_floor_runner.dag` + `affected_set_floor_runner_test.dag` · `floor_skip_proof_plan.dag` · `floor_preparation.dag` (+ `dag/test/claim/floor_preparation_witness_test.dag`) · `affected_set_selection.dag` remnants · `probe_selector_affected_tests.dag` · `probe_selector_ci_runner_test.dag` · `probe_selector_host_health.dag` · `affected_testgen_ci_runner.dag` (+ its gate test) · `claim_witness_corpus_ci_runner.dag` -- `dag/gunbc/floor_component_receipt.dag` + `floor_component_receipt_document.dag` · `dag/gunbc/floor_materialization.dag` · `dag/gunbc/floor_resolve_realization.dag` · `dag/gunbc/floor_discovery_scaffold.dag` · `dag/gunbc/affected_set_stop_line.dag` +- `dag/gunbc/floor/floor_component_receipt.dag` + `floor_component_receipt_document.dag` · `dag/gunbc/floor/floor_materialization.dag` · `dag/gunbc/floor_resolve_realization.dag` · `dag/gunbc/floor/floor_discovery_scaffold.dag` · `dag/gunbc/affected_set_stop_line.dag` - `dag/tools/floor_effect_gate_witness.dag` — the wrapper dies; its **seven gate obligations** go to the re-add queue -- `dag/tools/floor_skip_discovery_witness_transport.dag` + `src/v1/stage0/src/bin/floor_skip_discovery_witness.rs` (requires the `dag/gunbc/ci_release_bins.dag` row removal) +- `dag/tools/floor_skip_discovery_witness_transport.dag` + `src/v1/stage0/src/bin/floor_skip_discovery_witness.rs` (requires the `dag/gunbc/ci/ci_release_bins.dag` row removal) - `src/v1/stage0/src/cli_run/floor_discovery_snapshot.rs` (767 lines; sole consumer is the claim_executor coordinator pre-plan digest) - fixtures: `src/v2/test/fixture/floor_skip/` (all 7 files) - witness tests: `dag/test/claim/falsifier_workflow_witness_test.dag` · `falsifier_lane_witness_test.dag` · `falsifier_run_control_witness_test.dag` · `falsifier_alert_decision_witness_test.dag` · `falsifier_alert_migration_witness_test.dag` · `floor_component_receipt_witness_test.dag` · `floor_batch_clamp_authority_witness_test.dag` · `floor_gate_failure_receipt_witness_test.dag` · `ci_floor_measurement_test.dag` · `floor_materialization_witness_test.dag` · `ci_floor_on_success_materialization_receipt_hand_rust_witness_test.dag` · `floor_skip_discovery_witness_test.dag` · the `dag_compile_clean_cli_floor_agreement` pair · `src/v2/test/claim/ci_floor_plan_witness_test.dag` · `src/v2/test/claim/falsifier_lane_plan_agreement_test.dag` @@ -79,8 +79,8 @@ Observed at the wipe boundary (identity-grain, 2026-08-15), beyond the predicted ## Contested / do-not-delete (sweep-verified non-floor consumers) - **Keep whole:** `src/v1/stage0/src/bin/claim_batch.rs` (the local path) · `src/v2/workflow/floor_discovery.dag`, `floor_discovery_producer.dag`, `floor_discovery_transport.dag` (reached by the local producer path in cli_run, not by the floor) · `src/v2/workflow/floor_naming_hygiene.dag` (surviving `test fn` placement rule; non-floor importer) · `src/v2/workflow/executor.dag`, `scheduler.dag`, `batch_runner.dag` (generic substrate) · the fleet-converge pair · the regen bins -- **Trim rows only:** `dag/tools/dag_compile_clean_scope.dag` (broad non-floor consumers) · `dag/gunbc/ci_layer_roots.dag` (~40 importers) · `dag/gunbc/ci_release_bins.dag` (the owned-CI control plane formerly listed here was deleted whole with its lane; it is no longer a trim row) -- `dag/gunbc/ci_floor_measurement.dag` is a **fleet budget authority** (runner placement, oomd, host budgets import it) — survives despite the name +- **Trim rows only:** `dag/tools/dag_compile_clean_scope.dag` (broad non-floor consumers) · `dag/gunbc/ci/ci_layer_roots.dag` (~40 importers) · `dag/gunbc/ci/ci_release_bins.dag` (the owned-CI control plane formerly listed here was deleted whole with its lane; it is no longer a trim row) +- `dag/gunbc/ci/ci_floor_measurement.dag` is a **fleet budget authority** (runner placement, oomd, host budgets import it) — survives despite the name - **Field grain:** `node_frontier_selection` comes off the generic `Runnable` in `dag/std/realization_schedule.dag` + `src/v1/stage0/src/std_realization_schedule.rs` (in flight with step 0's area) - `dag/gunbc/plans/ci_*.dag` planning carriers are registered quarry — deleting any requires plan-registry surgery; `dag/gunbc/plans/affected_set_self_confirmation.dag` is the only unregistered one - **Frozen X:** `src/v1/stage0/src/cli_run.rs` and the interpreter — trims only, never file deletion, and no new builtin rows land there diff --git a/docs/plans/gunbc-served-dashboard-design.md b/docs/plans/gunbc-served-dashboard-design.md index 427f2164aad..661a64a6356 100644 --- a/docs/plans/gunbc-served-dashboard-design.md +++ b/docs/plans/gunbc-served-dashboard-design.md @@ -66,7 +66,7 @@ type RouteSelection ## 2. Handlers: the gunbc instantiation -New `dag/gunbc/roadmap_serve.dag`, `H = RoadmapServeHandler`: +New `dag/gunbc/roadmap/roadmap_serve.dag`, `H = RoadmapServeHandler`: ``` type RoadmapServeHandler @@ -108,7 +108,7 @@ New subcommand in the seed (`main.rs` dispatch + `cli_run::handle_serve`; both f ``` gunbc serve --source-root dag --source-root src/v2 \ - --entry dag/gunbc/roadmap_serve.dag --function roadmap_serve_handle \ + --entry dag/gunbc/roadmap/roadmap_serve.dag --function roadmap_serve_handle \ --host 127.0.0.1 --port 8080 ``` @@ -130,7 +130,7 @@ The launch button + minimal client script land in `gunbc.roadmap_page` in **belt `gunbc.live_deploy.spec` today: members = {tailscale pkg, nodejs pkg (Ensured), server.js, systemd unit, tailscale-serve (Owned)}. B's desired membership: -- **New single authority `dag/gunbc/host_layout.dag`** (`gunbc.host_layout`): `srv1_gunbc_repo_root = /opt/gunbc/gunbc`, `srv1_gunbc_serve_binary = /opt/gunbc/bin/gunbc`, `srv1_dispatch_worktree_root = /opt/gunbc/dispatch-worktrees`. `roadmap_belt_actuate.belt_actuate_workdir` AND `roadmap_dispatch_actuator.dispatch_worktree_root` re-ground as projections of these rows (deleting their private copies — the belt spawn root and the serve tree are **the same fact**, which is precisely why dispatch works in-process: the serving tree is the repo the belt worktrees from). The deploy spec and the systemd unit consume the same rows. Lane agreement (parent 2026-07-20): A provisions srv1 **manually to these exact paths** for the interim (no env-var fork, no .dag path change on A's side), so the baked defaults work today; B's PR formalizes that same provisioning through the deploy membership — after B's apply, the paths exist *because the deploy's own membership says so*, and the interim hand-provisioning retires. +- **New single authority `dag/gunbc/host/host_layout.dag`** (`gunbc.host_layout`): `srv1_gunbc_repo_root = /opt/gunbc/gunbc`, `srv1_gunbc_serve_binary = /opt/gunbc/bin/gunbc`, `srv1_dispatch_worktree_root = /opt/gunbc/dispatch-worktrees`. `roadmap_belt_actuate.belt_actuate_workdir` AND `roadmap_dispatch_actuator.dispatch_worktree_root` re-ground as projections of these rows (deleting their private copies — the belt spawn root and the serve tree are **the same fact**, which is precisely why dispatch works in-process: the serving tree is the repo the belt worktrees from). The deploy spec and the systemd unit consume the same rows. Lane agreement (parent 2026-07-20): A provisions srv1 **manually to these exact paths** for the interim (no env-var fork, no .dag path change on A's side), so the baked defaults work today; B's PR formalizes that same provisioning through the deploy membership — after B's apply, the paths exist *because the deploy's own membership says so*, and the interim hand-provisioning retires. - **Members:** `ServeBinary` (Owned, path `srv1_gunbc_serve_binary`; upsert = `sudo install -m 0755` of the deploy job's built seed binary — the deploy job already builds the seed to run `gunbc run --function live_deploy_apply_srv1_wet`, so the artifact is present by construction), `GunbcSourceTree` (Owned, path `srv1_gunbc_repo_root`; upsert = rsync of the runner checkout **including `.git`** — the belt's `git worktree add` requires a real repo), `DispatchWorktreeRoot` (Owned, path `srv1_dispatch_worktree_root`; upsert = `install -d` — the belt's worktree target must exist before the first spawn), `SystemdUnit` (ExecStart flips to `gunbc serve …` per §3, `WorkingDirectory` = repo root), `TailscaleServeMapping` (unchanged), `TmuxPackage` (Ensured — the belt's observe/spawn substrate; today present by hand). `NodeJsPackage` and `ServerScript` leave the desired set — under the membership poles that is exactly a `Removed → Teardown` for the Owned server.js and **no teardown** for the Ensured nodejs (R5: Ensured is never torn down — the wall already in the spine). The `claude` CLI is deliberately NOT a member this PR (hand-present on srv1; a follow-up models its provisioning honestly rather than smuggling a curl|bash). - The apply/retract scripts + systemd unit goldens regenerate through the existing `emit.dag` pipeline (`orch_emit_pipeline` over the bash medium); the committed `.github/live-deploy-srv1-apply.sh`/`-retract.sh` drift gates stay the byte oracles. The `install_d_shared_setup_latent_coupling_note` marker fires by design: a second (and third) `/opt/gunbc` writer arrives, so the `install -d` moves to the shared-prefix form the note prescribes. - Readiness/digest read-back (`live_deploy.readiness`, `roadmap_static_site` digest): unchanged consumers — `/healthz` and the served-digest read-back now prove the **gunbc-served** process. The digest artifact remains content-addressed over the *body*, so the read-back is server-implementation-agnostic by construction (the receipt that proves A→B preserved the contract). diff --git a/docs/plans/machine-shape-orthogonal-scheduling.md b/docs/plans/machine-shape-orthogonal-scheduling.md index 3e58ccba7e8..e27b6011b34 100644 --- a/docs/plans/machine-shape-orthogonal-scheduling.md +++ b/docs/plans/machine-shape-orthogonal-scheduling.md @@ -6,9 +6,9 @@ Dissolution trigger (DESIGN §6): this document's authority transfers to the car ## 0. Displaced cost (§6 — what pain this removes) -- **Fusion is modeled but unpriced.** The accelerator demo's `RunnableKernelWorkload { fused_op_count }` is the on-chip form of cache shaping (operand stays in registers across ops), but its cost is literally `cost_account_predicted_zero()` (`dag/gunbc/accelerator_demo_plan.dag:87-89`): fused and unfused have identical (zero) cost, so nothing can *justify* fusion. A decision the model makes but cannot price is a decision made by convention (§1). +- **Fusion is modeled but unpriced.** The accelerator demo's `RunnableKernelWorkload { fused_op_count }` is the on-chip form of cache shaping (operand stays in registers across ops), but its cost is literally `cost_account_predicted_zero()` (`dag/gunbc/accelerator_demo/accelerator_demo_plan.dag:87-89`): fused and unfused have identical (zero) cost, so nothing can *justify* fusion. A decision the model makes but cannot price is a decision made by convention (§1). - **The reduce spine on parallel hardware.** `docs/plans/execution-spine-design.md:67` measures 1/128 serialism from non-monoidal accumulator-threading; its enforcement item "every combine inhabits Monoid" is design-level only — no carrier a scheduler could dispatch on exists (`Monoid`/`CommutativeMonoid` are field-identical records, `dag/std/algebra.dag:14-23`; no law is machine-carried). -- **Placement is modeled but inert.** `dag/gunbc/roadmap_authority.dag:285`: "`Placement`/`Materialization` are modeled but inert — CI consuming them is the lane's real deliverable." The demo stamps `LocalAccelerator` as inspectable data; nothing routes execution by it. The WGSL handler is `DormantAwaitingOperator`. +- **Placement is modeled but inert.** `dag/gunbc/roadmap/roadmap_authority.dag:285`: "`Placement`/`Materialization` are modeled but inert — CI consuming them is the lane's real deliverable." The demo stamps `LocalAccelerator` as inspectable data; nothing routes execution by it. The WGSL handler is `DormantAwaitingOperator`. - **Locality handled reactively, with a declared dissolve-on.** Runtime AIMD memory governor note (`src/v2/workflow/ci_floor_plan.dag:225`): "Dissolve-on: graph-derived per-node demand (CostAccount.space measured) replaces the reactive estimator." `CostAccount.space` is first-class but constructor-zeroed (`dag/std/realization_schedule.dag:39-46`); populating it is already declared P1 (`docs/plans/bounded-input-cost-envelope-scheduling.md` §7.2). ## 1. The two design axioms diff --git a/docs/plans/restore-src-v1-required-floor-stall-finding.md b/docs/plans/restore-src-v1-required-floor-stall-finding.md index 4d51c2d6476..8d310cedb47 100644 --- a/docs/plans/restore-src-v1-required-floor-stall-finding.md +++ b/docs/plans/restore-src-v1-required-floor-stall-finding.md @@ -1,6 +1,6 @@ # RESTORE-stall finding: widening the required floor's source roots to admit `src/v1` -Standalone finding, split out of triage prose per parent-session request (dashboard node `adhoc-9b80ec49-d63`, session `zesty-newt-828`, 2026-08-19). This document is the receipt for the RESTORE disposition ruled out repo-wide across `v1_dead_witness_tree_triage_receipt`, `v1_dead_witness_tree_triage_receipt_remainder`, and `v1_dead_witness_tree_triage_receipt_emitter_ambiguous_variant_owner` (`dag/gunbc/ci_layer_roots.dag`) — those receipts cite this finding rather than re-deriving it. +Standalone finding, split out of triage prose per parent-session request (dashboard node `adhoc-9b80ec49-d63`, session `zesty-newt-828`, 2026-08-19). This document is the receipt for the RESTORE disposition ruled out repo-wide across `v1_dead_witness_tree_triage_receipt`, `v1_dead_witness_tree_triage_receipt_remainder`, and `v1_dead_witness_tree_triage_receipt_emitter_ambiguous_variant_owner` (`dag/gunbc/ci/ci_layer_roots.dag`) — those receipts cite this finding rather than re-deriving it. ## The question diff --git a/docs/plans/roadmap-spawner.md b/docs/plans/roadmap-spawner.md index ead056fcf79..1be713a372b 100644 --- a/docs/plans/roadmap-spawner.md +++ b/docs/plans/roadmap-spawner.md @@ -12,7 +12,7 @@ the realization is a seed that shrinks to zero; host-effect-orchestration.md Pha Two *different kinds* of fact, each with exactly one home — they are not two copies of one fact: - **Graph structure** — what work exists, dependencies, sizing, acceptance conditions. Home: - the gunbc `.dag` authority (`dag/gunbc/roadmap_authority.dag` + `roadmap_model.dag`). Edited + the gunbc `.dag` authority (`dag/gunbc/roadmap/roadmap_authority.dag` + `roadmap_model.dag`). Edited by committing the `.dag` to main. ctrl never authors structure. - **Runtime state** — is a node actually done, is a session live. Home: ctrl/GitHub. Flows **one direction, ctrl → gunbc, read-only**, as acceptance *evidence* (PR merged, session diff --git a/docs/plans/s2-v2-self-emit-direction.md b/docs/plans/s2-v2-self-emit-direction.md index 1cdbaeca820..123c3a2f4cd 100644 --- a/docs/plans/s2-v2-self-emit-direction.md +++ b/docs/plans/s2-v2-self-emit-direction.md @@ -139,7 +139,7 @@ Byte-matching v1's *exact* decoration is **no longer required** (operator: drop Cross-boundary changes (e.g. the `Symbol` carrier decision C6, the reparse fix §5) are a one-message sync with the operator, not a silent edit. -**CI note:** the `emit/` receipts are green by execution but are **not yet in the discovery roster** (`witness_discovery_scan_dirs` in `dag/gunbc/ci_layer_roots.dag` lists only `dag/test/claim` and `src/v2/test/claim/manual`). Adding `src/v2/test/claim/emit` there enrolls them into tree-wide discovery — a floor-lane config change to coordinate, tracked here. +**CI note:** the `emit/` receipts are green by execution but are **not yet in the discovery roster** (`witness_discovery_scan_dirs` in `dag/gunbc/ci/ci_layer_roots.dag` lists only `dag/test/claim` and `src/v2/test/claim/manual`). Adding `src/v2/test/claim/emit` there enrolls them into tree-wide discovery — a floor-lane config change to coordinate, tracked here. --- diff --git a/docs/plans/shell-intent-emit-realization-design.md b/docs/plans/shell-intent-emit-realization-design.md index 2049895543a..ac7841510f8 100644 --- a/docs/plans/shell-intent-emit-realization-design.md +++ b/docs/plans/shell-intent-emit-realization-design.md @@ -24,7 +24,7 @@ This is not a new principle. It is §3 (single authority; a transport is one Rea | **Intent** | the `.dag` graph: modeled operations + data-dependency edges | **No** | the workflow's own `.dag` | | **Interface** | each operation = its dependency's *semantics* (git's diff semantics), transport-agnostic | No | `extdeps/**` operation shapes | | **Emit** | intent-graph → target surface syntax, target as parameter | Yes (the grammar) | `src/v2/extdeps/languages/bash.dag` + emit rows | -| **Realization** | pure-spec → host-effect, N transports | the transport, not the intent | `dag/gunbc/host_effect_realize.dag` | +| **Realization** | pure-spec → host-effect, N transports | the transport, not the intent | `dag/gunbc/host/host_effect_realize.dag` | `git diff` argv is a nickname for git's diff semantics; hardwiring the bash-CLI transport into the workflow *is* the §3/§4 N×M-adapter trap (libgit2, the GitHub compare API are the other handlers). The business policy ("which base ref") stays a parameter on the operation; the regression tell is an argv carrying `origin/main...HEAD` as a literal. diff --git a/docs/plans/shell-to-dag-residual-census-and-arc-completion.md b/docs/plans/shell-to-dag-residual-census-and-arc-completion.md index 83d8fc458bf..d0377e7391e 100644 --- a/docs/plans/shell-to-dag-residual-census-and-arc-completion.md +++ b/docs/plans/shell-to-dag-residual-census-and-arc-completion.md @@ -208,7 +208,7 @@ The surviving srv\* dissolution triggers are unanimous: runtime-present raw tran **Not a shell-residual row** — this is a dead-code finding, surfaced while working the `host_build_cache_provision_script.dag` deletion (row above) precisely because the two module names differ by one suffix (`host_build_cache_provision.dag` vs `host_build_cache_provision_script.dag`), hold unrelated concepts, and one was being edited while the other was being deleted in the same PR — a naming hazard that produced a real false-negative dependents-census answer during that PR's review. Recorded here so the next person near either file gets the warning where they stand, and so the fold is sequenced deliberately rather than appended to an unrelated vertical. -`dag/gunbc/host_build_cache_provision.dag` carries a full catalog-gate/verdict fold — `BuildCacheDaemonObservation`, `provision_build_cache_verdict`, `placement_verdict`, `build_cache_provision_gate_accepts` — with **zero non-test, non-self-file callers tree-wide**, confirmed by grep on both `main` and `session/proud-swift-703` (2026-08-20). The zero-caller count reproduces. **The characterization that followed it did not survive re-measurement, and is corrected below** — this is an *unconsumed authority*, not dead code. PR #8598's arm-swap touched only the two effect-constructor functions at the bottom of the file (mechanically required by the `HostEffect` rename) and did not create, fix, or reach this dead fold. +`dag/gunbc/host/host_build_cache_provision.dag` carries a full catalog-gate/verdict fold — `BuildCacheDaemonObservation`, `provision_build_cache_verdict`, `placement_verdict`, `build_cache_provision_gate_accepts` — with **zero non-test, non-self-file callers tree-wide**, confirmed by grep on both `main` and `session/proud-swift-703` (2026-08-20). The zero-caller count reproduces. **The characterization that followed it did not survive re-measurement, and is corrected below** — this is an *unconsumed authority*, not dead code. PR #8598's arm-swap touched only the two effect-constructor functions at the bottom of the file (mechanically required by the `HostEffect` rename) and did not create, fix, or reach this dead fold. Two test consumers, and they do **not** get the same disposition: - `dag/test/claim/host_build_cache_provision_design_witness_test.dag` — entirely dedicated to this fold (gate/verdict/classifier). Its subject disappears whole with the fold: pure deletion population, no assertion needs rehoming. @@ -570,7 +570,7 @@ The 07-22 snapshot is ~7 merges stale. What has landed since, keyed to the rows | **#7265** | bucket D PR1 — `ci_sccache_provider_shell_injection` + `ci_floor_disposition_marker_init_script` → `ci_materialization_emit` / `ci_merge_admission_emit` | 4.E/4.I/4.J rows for those two symbols DONE; §4.E/4.J true-up folded here (orphan doc deleted) | | **this PR** | **bucket A** — the last `date -Iseconds` in `host_runner_memory_cap_verify.dag` onto `Clock.Now`; `meta_exec_confinement_exception_roster` **3 → 0** | 4.C `date -Iseconds` and `hostname -s` rows DONE; the meta-exec roster is now empty, so §4.F's wall has no exceptions left to grant | -**Meta-exec roster: 3 → 0, and the dark lane that hid it.** Two of the three rows (`dag/gunbc/tools/review.dag`, `dag/gunbc/ci_deploy_target_host.dag`) were **stale** — their sites had stopped importing `extdeps.shell.exec` merges earlier and nobody noticed, because `meta_exec_roster_sound_live` existed in the lens but ran on **no** per-PR cadence; the only enrolled roster RED was synthetic (hand-written fact rows, blind to the live roster). Measured this PR: the live receipt costs **13.5s cold** against a 5s fast-lane budget, so it cannot be enrolled per-PR as-is. The per-PR enforcement is instead a **construction wall** — `stale_count` is bounded above by roster length, so the empty roster proves soundness with no scan, and any re-added row reds `meta_exec_roster_shrunk_to_empty_holds` in the same PR that adds it. The live receipt stays as a backstop in `src/v2/test/claim/long/meta_exec_confinement_clean_tree_test.dag` (with a non-degeneracy control, since a clean tree makes a live scan vacuously true if the walk reads nothing). **Named residue:** that long lane is still dark (not roster-enrolled); its dissolve-on is a falsifier batch admitting live-tree lens receipts. +**Meta-exec roster: 3 → 0, and the dark lane that hid it.** Two of the three rows (`dag/gunbc/tools/review.dag`, `dag/gunbc/ci/ci_deploy_target_host.dag`) were **stale** — their sites had stopped importing `extdeps.shell.exec` merges earlier and nobody noticed, because `meta_exec_roster_sound_live` existed in the lens but ran on **no** per-PR cadence; the only enrolled roster RED was synthetic (hand-written fact rows, blind to the live roster). Measured this PR: the live receipt costs **13.5s cold** against a 5s fast-lane budget, so it cannot be enrolled per-PR as-is. The per-PR enforcement is instead a **construction wall** — `stale_count` is bounded above by roster length, so the empty roster proves soundness with no scan, and any re-added row reds `meta_exec_roster_shrunk_to_empty_holds` in the same PR that adds it. The live receipt stays as a backstop in `src/v2/test/claim/long/meta_exec_confinement_clean_tree_test.dag` (with a non-degeneracy control, since a clean tree makes a live scan vacuously true if the walk reads nothing). **Named residue:** that long lane is still dark (not roster-enrolled); its dissolve-on is a falsifier batch admitting live-tree lens receipts. ### Wind-down PR ledger — snapshot @ 2026-07-22 (calm-ferret-849 subtree) @@ -745,7 +745,7 @@ The governing rule for the rest of the sweep, so "all other instances" stays dec - **`CaptureSpec.CmdSubst`** — genuinely dead: zero constructors tree-wide. (`ExprCmdSubst` and `CmdSubstLines` are different types.) - **`CaptureSpec.TeeTo`** — **was live but inert; fixed by merged #7293.** - - *Before #7293:* `ci_retry_body_run` (`dag/gunbc/ci_spec.dag:224`) constructed `capture: TeeTo { log: "BUILD_LOG" }`, but `orch_retry_step_command` returned only `r.command` and `orch_emit_retry_run` rebuilt the `Run` with `redirect`/`capture` `Absent`. The identical tee semantics were **hardcoded as fixed tokens** at `bash.dag:1093-1133`, so the emitted bytes were right and the *model* was the copy that did nothing — editing `log: "BUILD_LOG"` changed no output. Exactly the tell §5 names: the spec could be edited while the realizer kept doing its own thing. + - *Before #7293:* `ci_retry_body_run` (`dag/gunbc/ci/ci_spec.dag:224`) constructed `capture: TeeTo { log: "BUILD_LOG" }`, but `orch_retry_step_command` returned only `r.command` and `orch_emit_retry_run` rebuilt the `Run` with `redirect`/`capture` `Absent`. The identical tee semantics were **hardcoded as fixed tokens** at `bash.dag:1093-1133`, so the emitted bytes were right and the *model* was the copy that did nothing — editing `log: "BUILD_LOG"` changed no output. Exactly the tell §5 names: the spec could be edited while the realizer kept doing its own thing. - *Current main after #7293:* `ci_retry_body_run` is `redirect: Absent, capture: Absent` — the lying declaration is **deleted** — and the retry path refuses any `Present` redirect/capture instead of emitting while dropping it. The discriminating RED (`ci_merge_admission_emit_test.dag`, `orch_retry_body_tee_to_refused_holds`) proves a retry-body `TeeTo` is rejected. `TeeTo` now has **zero production constructors**; the only constructor is that refusal control. - **It was a divergence, not one bug:** the ordinary `Run` emit path already refused the same field fail-closed and typed (`^orch_emit_run_capture_unsupported`, `:230`/`:249`), while the retry path silently dropped it. **#7293 closes that** — both paths now refuse. @@ -758,7 +758,7 @@ The governing rule for the rest of the sweep, so "all other instances" stays dec ### Dissolution trigger for §4 -**The construction wall this trigger waited on has PARTIALLY landed (#7184, 2026-07-24)** — it record-walls the **`ShellOnHost` realization edge** (`ResolvedHostEffectCell.ShellOnHost { script: RetainedShellScript }`, `dag/gunbc/host_effect_realize.dag:167`) and deletes the free minter `extdeps.shell.exec.transport_script_from_body(body: String)`, so a hand-assembled `String` no longer typechecks *on that edge*, with compile-fail REDs (§4.F, §5.E). +**The construction wall this trigger waited on has PARTIALLY landed (#7184, 2026-07-24)** — it record-walls the **`ShellOnHost` realization edge** (`ResolvedHostEffectCell.ShellOnHost { script: RetainedShellScript }`, `dag/gunbc/host/host_effect_realize.dag:167`) and deletes the free minter `extdeps.shell.exec.transport_script_from_body(body: String)`, so a hand-assembled `String` no longer typechecks *on that edge*, with compile-fail REDs (§4.F, §5.E). It did not close the `shell.Exec.Run` sink; **#7962 did.** `TransportScript` is a **`sole_constructor` record** whose single mint `transport_script_seal` is `admit_callers`-sealed to exactly two production declarations (`gunbc.retained_shell_script` `retained_shell_script_to_transport`, `gunbc.bash_materialized_transport` `bash_materialized_transport`), and the cast form closed with it — `04_infer` `sole_constructor_construction_diags` judges a cast into a sealed type (#7962). The `meta_exec_confinement` scan and `host_language_transport_script` remain as validation backstops, but construction is no longer what they guard. The leak fixture at `src/v2/test/fixture/meta_exec_confinement_scan/leak/plant.dag` is now **scan input and historical record only** — it can no longer be cited as evidence that the cast compiles. diff --git a/docs/plans/space-lens-minimal-project.md b/docs/plans/space-lens-minimal-project.md index ecd4d6e09a1..3cf8b0c364c 100644 --- a/docs/plans/space-lens-minimal-project.md +++ b/docs/plans/space-lens-minimal-project.md @@ -16,7 +16,7 @@ The architecture is already designed and signed. This doc only fills the one hol | --- | --- | --- | | `ResourceEnvelope` single authority, every knob derived | `compute-envelope-model.md`, `gunbc.fleet_container` | designed, signed (#5904 moved the type; `product.compute_fabric` is deleted) | | **"Derivation is the authority; measurement is the falsifier"** | `resource-aware-scheduler.md` (operator ruling 2026-06-25) | signed | -| `InputEnvelope = BoundedInput \| EnvelopeUnknown` + fail-closed admission | `dag/gunbc/ci_input_envelope.dag` | **landed** (P1) — this is "forcing modeling on inputs" | +| `InputEnvelope = BoundedInput \| EnvelopeUnknown` + fail-closed admission | `dag/gunbc/ci/ci_input_envelope.dag` | **landed** (P1) — this is "forcing modeling on inputs" | | `CostAccount{ time, space, power, basis }`, `CostBasis = Predicted \| Measured` | `dag/std/realization_schedule.dag` | carrier exists, **`space` always `byte_size(0)`** (`cost_account_predicted_zero`) | | width formula `floor(budget ÷ per_shard_peak)` | `dag/std/realization_width.dag` | exists, reads `predicted_peak` from a **static data row** | | per-shard RSS + closure-node-count measurement | #6425 (this session), `claim_executor` | **landed** — the *falsifier* half, explicitly "not the scheduler directly" | diff --git a/docs/plans/unconsumed-module-census.md b/docs/plans/unconsumed-module-census.md index 7a735a0b22f..b2ebde5693a 100644 --- a/docs/plans/unconsumed-module-census.md +++ b/docs/plans/unconsumed-module-census.md @@ -833,10 +833,10 @@ executable against the real corpus rather than against a fixture someone has to | `examples.nominal_distinctness_twin` | `dag/examples/nominal_distinctness_witness/twin.dag` | 15 | — | | `examples.nominal_distinctness_witness` | `dag/examples/nominal_distinctness_witness/witness.dag` | 19 | — | | `gunbc.assimilate.bmc_wif_canary_bootstrap` | `dag/gunbc/assimilate/bmc_wif_canary_bootstrap.dag` | 126 | — | -| `gunbc.ci_oom_reclassify` | `dag/gunbc/ci_oom_reclassify.dag` | 87 | — | +| `gunbc.ci_oom_reclassify` | `dag/gunbc/ci/ci_oom_reclassify.dag` | 87 | — | | `gunbc.cursor_sdk_secure_api_key` | `dag/gunbc/cursor_sdk_secure_api_key.dag` | 73 | — | | `gunbc.devboot.vertical_receipt` | `dag/gunbc/devboot/vertical_receipt.dag` | 68 | — | -| `gunbc.host_converge_delta` | `dag/gunbc/host_converge_delta.dag` | 119 | — | +| `gunbc.host_converge_delta` | `dag/gunbc/host/host_converge_delta.dag` | 119 | — | | `gunbc.install_media` | `dag/gunbc/install_media.dag` | 43 | — | | `gunbc.parse_allowlist` | `dag/gunbc/parse_allowlist.dag` | 20 | — | | `gunbc.plans.wave2_prep_design` | `dag/gunbc/plans/wave2_prep_design.dag` | 205 | — | @@ -904,7 +904,7 @@ executable against the real corpus rather than against a fixture someone has to | `gunbc.code_change_workflow` | `dag/gunbc/code_change_workflow.dag` | 371 | — | | `gunbc.floor_resolve_realization` | `dag/gunbc/floor_resolve_realization.dag` | 28 | — | | `gunbc.hand_lens_host_bridge_scaffold_watchdog` | `dag/gunbc/hand_lens_host_bridge_scaffold_watchdog.dag` | 46 | — | -| `gunbc.host_runner_memory_cap_plan_emit` | `dag/gunbc/host_runner_memory_cap_plan_emit.dag` | 110 | — | +| `gunbc.host_runner_memory_cap_plan_emit` | `dag/gunbc/host/host_runner_memory_cap_plan_emit.dag` | 110 | — | | `gunbc.hostname_allocation` | `dag/gunbc/hostname_allocation.dag` | 148 | — | | `gunbc.language_subject_scope_scaffold` | `dag/gunbc/language_subject_scope_scaffold.dag` | 10 | — | | `gunbc.p3a1_self_fork_homonym_disposition` | `dag/gunbc/p3a1_self_fork_homonym_disposition.dag` | 10 | — | @@ -964,53 +964,53 @@ executable against the real corpus rather than against a fixture someone has to | `extdeps.sec.mock_corpus` | `dag/extdeps/sec/mock_corpus.dag` | 23 | {'dag': 1} `dag/gunbc/extdeps_scope_frontier.dag` | | `extdeps.shell.mock_corpus` | `dag/extdeps/shell_mock_corpus.dag` | 31 | {'dag': 1} `dag/gunbc/extdeps_scope_frontier.dag` | | `extdeps.tcgplayer.mock_corpus` | `dag/extdeps/tcgplayer/mock_corpus.dag` | 63 | {'dag': 1} `dag/gunbc/extdeps_scope_frontier.dag` | -| `gunbc.apply` | `dag/gunbc/apply.dag` | 118 | {'dag': 2} `dag/gunbc/runner_lifecycle.dag` `dag/gunbc/runner_capacity_realize.dag` | +| `gunbc.apply` | `dag/gunbc/apply.dag` | 118 | {'dag': 2} `dag/gunbc/runner/runner_lifecycle.dag` `dag/gunbc/runner/runner_capacity_realize.dag` | | `gunbc.auth.credentials` | `dag/gunbc/auth/credentials.dag` | 89 | {'dag': 1, 'rs': 1} `dag/gunbc/tailscale_acl_phase2_credential.dag` `src/v1/stage0/src/bin/parse_witness.rs` | | `gunbc.auth.optional_impersonation` | `dag/gunbc/auth/optional_impersonation.dag` | 20 | {'dag': 2} `dag/test/claim/tailscale_acl_phase2_design_witness_test.dag` `dag/gunbc/tailscale_acl_phase2_credential.dag` | | `gunbc.auth.patterns` | `dag/gunbc/auth/patterns.dag` | 113 | {'rs': 1} `src/v1/stage0/src/cli_run.rs` | | `gunbc.bootstrap` | `dag/gunbc/bootstrap.dag` | 126 | {'dag': 2} `dag/gunbc/doc_graph_roots.dag` `src/v2/compiler/self_host/frontier_probe_types.dag` | | `gunbc.char_at_scaling_probe_support` | `dag/gunbc/char_at_scaling_probe_support.dag` | 58 | {'rs': 1} `src/v1/stage0/src/bin/char_at_scaling_probe.rs` | -| `gunbc.ci_build_job_v1_compiler_unit_receipt` | `dag/gunbc/ci_build_job_v1_compiler_unit_receipt.dag` | 21 | {'dag': 1} `dag/gunbc/ci_spec.dag` | -| `gunbc.ci_input_envelope` | `dag/gunbc/ci_input_envelope.dag` | 86 | {'dag': 3} `dag/gunbc/doc_graph_roots.dag` `dag/gunbc/plans/bounded_input_cost_envelope_scheduling.dag` | +| `gunbc.ci_build_job_v1_compiler_unit_receipt` | `dag/gunbc/ci/ci_build_job_v1_compiler_unit_receipt.dag` | 21 | {'dag': 1} `dag/gunbc/ci/ci_spec.dag` | +| `gunbc.ci_input_envelope` | `dag/gunbc/ci/ci_input_envelope.dag` | 86 | {'dag': 3} `dag/gunbc/doc_graph_roots.dag` `dag/gunbc/plans/bounded_input_cost_envelope_scheduling.dag` | | `gunbc.compile_source_model` | `dag/gunbc/compile_source_model.dag` | 65 | {'dag': 1} `dag/gunbc/plans/seed_debt_bundle_item_2.dag` | -| `gunbc.deployed_intent_v0` | `dag/gunbc/deployed_intent_v0.dag` | 61 | {'dag': 2} `dag/gunbc/host_standup.dag` `dag/gunbc/host_identity_adopt.dag` | -| `gunbc.deployed_intent_v1` | `dag/gunbc/deployed_intent_v1.dag` | 69 | {'dag': 1} `dag/gunbc/host_standup.dag` | +| `gunbc.deployed_intent_v0` | `dag/gunbc/deployed_intent_v0.dag` | 61 | {'dag': 2} `dag/gunbc/host/host_standup.dag` `dag/gunbc/host/host_identity_adopt.dag` | +| `gunbc.deployed_intent_v1` | `dag/gunbc/deployed_intent_v1.dag` | 69 | {'dag': 1} `dag/gunbc/host/host_standup.dag` | | `gunbc.design_argument` | `dag/gunbc/design_argument.dag` | 93 | {'dag': 1} `dag/gunbc/plans/axiom_syllogism_lens.dag` | -| `gunbc.githooks_pre_push_cli` | `dag/gunbc/githooks_pre_push_cli.dag` | 10 | {'dag': 2, 'rs': 2} `dag/std/emit_on_demand.dag` `dag/gunbc/githooks_pre_push_fmt_transport_scaffold.dag` | -| `gunbc.host_authorized_keys_reconcile` | `dag/gunbc/host_authorized_keys_reconcile.dag` | 104 | {'dag': 1} `dag/gunbc/build_cache_instance.dag` | -| `gunbc.host_build_cache_provision` | `dag/gunbc/host_build_cache_provision.dag` | 335 | {'dag': 4} `dag/gunbc/build_cache_instance.dag` `dag/gunbc/fleet_host_budget.dag` | -| `gunbc.host_identity_assimilation` | `dag/gunbc/host_identity_assimilation.dag` | 266 | {'dag': 3} `dag/gunbc/host_standup.dag` `dag/gunbc/host_identity_adopt.dag` | -| `gunbc.host_identity_converge` | `dag/gunbc/host_identity_converge.dag` | 250 | {'dag': 1} `dag/gunbc/host_standup.dag` | -| `gunbc.host_identity_knob` | `dag/gunbc/host_identity_knob.dag` | 55 | {'dag': 1} `dag/gunbc/host_standup.dag` | -| `gunbc.host_identity_observation` | `dag/gunbc/host_identity_observation.dag` | 89 | {'dag': 1} `dag/gunbc/host_standup.dag` | -| `gunbc.host_network_diagnosis` | `dag/gunbc/host_network_diagnosis.dag` | 213 | {'dag': 1} `dag/gunbc/prose_row_frontier.dag` | -| `gunbc.host_toolchain_components` | `dag/gunbc/host_toolchain_components.dag` | 195 | {'dag': 1} `dag/gunbc/prose_row_frontier.dag` | +| `gunbc.githooks_pre_push_cli` | `dag/gunbc/githooks/githooks_pre_push_cli.dag` | 10 | {'dag': 2, 'rs': 2} `dag/std/emit_on_demand.dag` `dag/gunbc/githooks/githooks_pre_push_fmt_transport_scaffold.dag` | +| `gunbc.host_authorized_keys_reconcile` | `dag/gunbc/host/host_authorized_keys_reconcile.dag` | 104 | {'dag': 1} `dag/gunbc/build_cache/build_cache_instance.dag` | +| `gunbc.host_build_cache_provision` | `dag/gunbc/host/host_build_cache_provision.dag` | 335 | {'dag': 4} `dag/gunbc/build_cache/build_cache_instance.dag` `dag/gunbc/fleet/fleet_host_budget.dag` | +| `gunbc.host_identity_assimilation` | `dag/gunbc/host/host_identity_assimilation.dag` | 266 | {'dag': 3} `dag/gunbc/host/host_standup.dag` `dag/gunbc/host/host_identity_adopt.dag` | +| `gunbc.host_identity_converge` | `dag/gunbc/host/host_identity_converge.dag` | 250 | {'dag': 1} `dag/gunbc/host/host_standup.dag` | +| `gunbc.host_identity_knob` | `dag/gunbc/host/host_identity_knob.dag` | 55 | {'dag': 1} `dag/gunbc/host/host_standup.dag` | +| `gunbc.host_identity_observation` | `dag/gunbc/host/host_identity_observation.dag` | 89 | {'dag': 1} `dag/gunbc/host/host_standup.dag` | +| `gunbc.host_network_diagnosis` | `dag/gunbc/host/host_network_diagnosis.dag` | 213 | {'dag': 1} `dag/gunbc/prose_row_frontier.dag` | +| `gunbc.host_toolchain_components` | `dag/gunbc/host/host_toolchain_components.dag` | 195 | {'dag': 1} `dag/gunbc/prose_row_frontier.dag` | | `gunbc.interpreter_kernel_model` | `dag/gunbc/interpreter_kernel_model.dag` | 82 | {'dag': 1} `dag/gunbc/plans/interpreter_kernel_d.dag` | -| `gunbc.namespace_census_receipt` | `dag/gunbc/namespace_census_receipt.dag` | 74 | {'dag': 1} `dag/gunbc/doc_graph_roots.dag` | +| `gunbc.namespace_census_receipt` | `dag/gunbc/namespace/namespace_census_receipt.dag` | 74 | {'dag': 1} `dag/gunbc/doc_graph_roots.dag` | | `gunbc.network_identity_subsumption` | `dag/gunbc/network_identity_subsumption.dag` | 134 | {'dag': 5} `dag/test/claim/dgx_spark_witness_test.dag` `dag/test/claim/host_phase_status_witness_test.dag` | | `gunbc.p1_retention_cohort_receipt` | `dag/gunbc/p1_retention_cohort_receipt.dag` | 8 | {'dag': 1} `dag/gunbc/doc_graph_roots.dag` | | `gunbc.plans.affected_set_self_confirmation` | `dag/gunbc/plans/affected_set_self_confirmation.dag` | 29 | {'rs': 1} `src/v1/stage0/src/cli_run.rs` | | `gunbc.plans.branch_merge_admission_model` | `dag/gunbc/plans/branch_merge_admission_model.dag` | 172 | {'dag': 2} `dag/test/claim/merge_lifecycle_interleaving_witness_test.dag` `dag/gunbc/merge_lifecycle.dag` | -| `gunbc.plans.fleet_subsumption_manual_gaps` | `dag/gunbc/plans/fleet_subsumption_manual_gaps.dag` | 196 | {'dag': 12} `dag/test/claim/retained_shell_script_witness_test.dag` `dag/gunbc/build_cache_instance.dag` | -| `gunbc.plans.host_convergence_circuit_residue` | `dag/gunbc/plans/host_convergence_circuit_residue.dag` | 75 | {'dag': 1} `dag/gunbc/host_converge.dag` | +| `gunbc.plans.fleet_subsumption_manual_gaps` | `dag/gunbc/plans/fleet_subsumption_manual_gaps.dag` | 196 | {'dag': 12} `dag/test/claim/retained_shell_script_witness_test.dag` `dag/gunbc/build_cache/build_cache_instance.dag` | +| `gunbc.plans.host_convergence_circuit_residue` | `dag/gunbc/plans/host_convergence_circuit_residue.dag` | 75 | {'dag': 1} `dag/gunbc/host/host_converge.dag` | | `gunbc.plans.merge_admission_gate_shape_proposal` | `dag/gunbc/plans/merge_admission_gate_shape_proposal.dag` | 78 | {'dag': 1} `dag/gunbc/merge_admission.dag` | | `gunbc.plans.transport_argv_anemia_dissolution` | `dag/gunbc/plans/transport_argv_anemia_dissolution.dag` | 89 | {'dag': 2} `dag/extdeps/git/git.dag` `dag/extdeps/exec/command.dag` | | `gunbc.process_algebra` | `dag/gunbc/process_algebra.dag` | 147 | {'dag': 3} `dag/gunbc/doc_graph_roots.dag` `dag/gunbc/plans/invert_hand_maintained.dag` | -| `gunbc.runner_slot_enforcement` | `dag/gunbc/runner_slot_enforcement.dag` | 129 | {'dag': 3} `dag/gunbc/host_standup.dag` `dag/gunbc/runner_slot_allocation.dag` | +| `gunbc.runner_slot_enforcement` | `dag/gunbc/runner/runner_slot_enforcement.dag` | 129 | {'dag': 3} `dag/gunbc/host/host_standup.dag` `dag/gunbc/runner/runner_slot_allocation.dag` | | `gunbc.seed_closed_vocabulary_wildcard_census` | `dag/gunbc/seed_closed_vocabulary_wildcard_census.dag` | 175 | {'rs': 1} `src/v1/stage0/src/cli_run.rs` | | `gunbc.site.interaction` | `dag/gunbc/site/interaction.dag` | 14 | {'dag': 1} `dag/gunbc/design/interaction.dag` | | `gunbc.spark.provisioning` | `dag/gunbc/spark/provisioning.dag` | 543 | {'dag': 2} `dag/extdeps/systems/nvidia_dgx_spark_setup.dag` `dag/test/claim/spark_provisioning_witness_test.dag` | -| `gunbc.srv3_os_install_diagnostic` | `dag/gunbc/srv3_os_install_diagnostic.dag` | 1410 | {'dag': 1} `dag/gunbc/non_fold_residue.dag` | -| `gunbc.tailscale_acl_emit` | `dag/gunbc/tailscale_acl_emit.dag` | 52 | {'dag': 1} `dag/gunbc/host_standup.dag` | +| `gunbc.srv3_os_install_diagnostic` | `dag/gunbc/srv3/srv3_os_install_diagnostic.dag` | 1410 | {'dag': 1} `dag/gunbc/non_fold_residue.dag` | +| `gunbc.tailscale_acl_emit` | `dag/gunbc/tailscale_acl_emit.dag` | 52 | {'dag': 1} `dag/gunbc/host/host_standup.dag` | | `gunbc.test_node_wall_clock_ratchet` | `dag/gunbc/test_node_wall_clock_ratchet.dag` | 99 | {'dag': 1} `dag/gunbc/plans/structural_quadratic_wall_coverage_audit.dag` | | `gunbc.tools.review` | `dag/gunbc/tools/review.dag` | 187 | {'dag': 4} `dag/test/claim/workflow_default_field_projection_fold_witness_test.dag` `src/v2/lens/meta_exec_confinement.dag` | -| `gunbc.tools.review_codex` | `dag/gunbc/tools/review_codex.dag` | 205 | {'dag': 2, 'rs': 1} `dag/test/claim/workflow_default_field_projection_fold_witness_test.dag` `dag/gunbc/roadmap_belt_actuate.dag` | -| `gunbc.v1_maintenance_standing` | `dag/gunbc/v1_maintenance_standing.dag` | 83 | {'dag': 6, 'rs': 1} `dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag` `dag/test/claim/documentary_refs_witness_test.dag` | +| `gunbc.tools.review_codex` | `dag/gunbc/tools/review_codex.dag` | 205 | {'dag': 2, 'rs': 1} `dag/test/claim/workflow_default_field_projection_fold_witness_test.dag` `dag/gunbc/roadmap/roadmap_belt_actuate.dag` | +| `gunbc.v1_maintenance_standing` | `dag/gunbc/v1/v1_maintenance_standing.dag` | 83 | {'dag': 6, 'rs': 1} `dag/test/claim/match_arm_pattern_identity_emission_witness_test.dag` `dag/test/claim/documentary_refs_witness_test.dag` | | `gunbc.workflow.types` | `dag/gunbc/workflow/types.dag` | 311 | {'dag': 1} `dag/gunbc/plans/host_effect_orchestration.dag` | | `std.behavioral` | `dag/std/behavioral.dag` | 51 | {'rs': 1} `src/v1/stage0/src/bin/parse_witness.rs` | | `std.durable_compare_and_set` | `dag/std/durable_compare_and_set.dag` | 292 | {'dag': 1} `dag/test/claim/durable_compare_and_set_witness_test.dag` | | `std.methods` | `dag/std/methods.dag` | 67 | {'dag': 1, 'rs': 2} `src/v1/compiler_tests_rust.dag` `src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs` | -| `std.stack` | `dag/std/stack.dag` | 56 | {'dag': 1, 'rs': 1} `dag/gunbc/witness_floor_workflow.dag` `src/v1/stage0/src/bin/parse_witness.rs` | +| `std.stack` | `dag/std/stack.dag` | 56 | {'dag': 1, 'rs': 1} `dag/gunbc/witness/witness_floor_workflow.dag` `src/v1/stage0/src/bin/parse_witness.rs` | | `std.verification` | `dag/std/verification.dag` | 34 | {'dag': 3} `dag/gunbc/plans/resolver_type_name_collision_wall.dag` `dag/gunbc/plans/realization_measurement_loop.dag` | | `tools.gunbc_ci` | `dag/tools/gunbc_ci.dag` | 25 | {'dag': 2, 'rs': 1} `dag/std/emit_on_demand.dag` `src/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag` | | `v2.extdeps.languages.ecmascript` | `src/v2/extdeps/languages/ecmascript.dag` | 1340 | {'dag': 1} `dag/gunbc/language_target_registry.dag` | @@ -1024,7 +1024,7 @@ executable against the real corpus rather than against a fixture someone has to | `v2.test.workflow.glob_discovery_law` | `src/v2/workflow/glob_discovery_law.dag` | 113 | {'dag': 1} `src/v2/test/claim/complexity/accumulator_copy_roster_gate_test.dag` | | `v2.workflow.class_b_import_closure_transport` | `src/v2/workflow/class_b_import_closure_transport.dag` | 118 | {'dag': 2, 'rs': 1} `dag/test/claim/long/rust_test_fixtures_import_closure_witness_test.dag` `src/v2/workflow/class_b_import_closure_probe.dag` | | `v2.workflow.compile_door_ledger` | `src/v2/workflow/compile_door_ledger.dag` | 341 | {'dag': 1} `src/v2/test/claim/long/door_real_module_probe_test.dag` | -| `v2.workflow.compiler_closure_ingest_transport` | `src/v2/workflow/compiler_closure_ingest_transport.dag` | 150 | {'dag': 4} `dag/tools/ci_gates.dag` `dag/gunbc/ci_layer_roots.dag` | +| `v2.workflow.compiler_closure_ingest_transport` | `src/v2/workflow/compiler_closure_ingest_transport.dag` | 150 | {'dag': 4} `dag/tools/ci_gates.dag` `dag/gunbc/ci/ci_layer_roots.dag` | | `v2.workflow.phase_profile_proof_plan` | `src/v2/workflow/phase_profile_proof_plan.dag` | 22 | {'rs': 1} `src/v1/stage0/tests/phase_profile_claim_executor.rs` | | `v2.workflow.source_root_ingest_gate` | `src/v2/workflow/source_root_ingest_gate.dag` | 18 | {'dag': 3} `dag/test/claim/guarantee_rung_drop_witness_test.dag` `dag/tools/ci_gates.dag` | | `v2.workflow.source_root_ingest_transport` | `src/v2/workflow/source_root_ingest_transport.dag` | 90 | {'dag': 2} `dag/tools/ci_gates.dag` `src/v2/test/claim/host_language_transport_script/corpus/migrated_transports_clean_test.dag` | @@ -1124,7 +1124,7 @@ executable against the real corpus rather than against a fixture someone has to | `extdeps.runtime.local` | `dag/extdeps/runtime/local.dag` | 22 | — | | `extdeps.sec.edgar_rest` | `dag/extdeps/sec/edgar_rest.dag` | 71 | {'dag': 2} `dag/extdeps/sec/edgar.dag` `dag/gunbc/prose_row_frontier.dag` | | `extdeps.shell.credentials` | `dag/extdeps/shell/credentials.dag` | 19 | — | -| `extdeps.tailscale.acl` | `dag/extdeps/tailscale/acl.dag` | 312 | {'dag': 2} `dag/test/claim/host_standup_spine_witness_test.dag` `dag/gunbc/host_standup.dag` | +| `extdeps.tailscale.acl` | `dag/extdeps/tailscale/acl.dag` | 312 | {'dag': 2} `dag/test/claim/host_standup_spine_witness_test.dag` `dag/gunbc/host/host_standup.dag` | | `extdeps.tailscale.acl_api` | `dag/extdeps/tailscale/acl_api.dag` | 70 | — | | `extdeps.tcgplayer.catalog` | `dag/extdeps/tcgplayer/catalog.dag` | 180 | — | | `extdeps.tcgplayer.pricing` | `dag/extdeps/tcgplayer/pricing.dag` | 78 | — | diff --git a/docs/plans/unconsumed-module-residue-disposition.md b/docs/plans/unconsumed-module-residue-disposition.md index e1e81c719fc..a72c5c0eaf7 100644 --- a/docs/plans/unconsumed-module-residue-disposition.md +++ b/docs/plans/unconsumed-module-residue-disposition.md @@ -706,10 +706,10 @@ Named by a live `.dag`, `.rs` or data file, or otherwise carrying an obligation | `gunbc.auth.optional_impersonation` | `dag/gunbc/auth/optional_impersonation.dag` | STILL-UNCONSUMED | | `gunbc.auth.patterns` | `dag/gunbc/auth/patterns.dag` | STILL-UNCONSUMED | | `gunbc.char_at_scaling_probe_support` | `dag/gunbc/char_at_scaling_probe_support.dag` | STILL-UNCONSUMED | -| `gunbc.ci_build_job_v1_compiler_unit_receipt` | `dag/gunbc/ci_build_job_v1_compiler_unit_receipt.dag` | STILL-UNCONSUMED | +| `gunbc.ci_build_job_v1_compiler_unit_receipt` | `dag/gunbc/ci/ci_build_job_v1_compiler_unit_receipt.dag` | STILL-UNCONSUMED | | `gunbc.generic_binder_field_projection_deficit` | `dag/gunbc/generic_binder_field_projection_deficit.dag` | STILL-UNCONSUMED | -| `gunbc.githooks_pre_push_cli` | `dag/gunbc/githooks_pre_push_cli.dag` | STILL-UNCONSUMED | -| `gunbc.namespace_census_receipt` | `dag/gunbc/namespace_census_receipt.dag` | STILL-UNCONSUMED | +| `gunbc.githooks_pre_push_cli` | `dag/gunbc/githooks/githooks_pre_push_cli.dag` | STILL-UNCONSUMED | +| `gunbc.namespace_census_receipt` | `dag/gunbc/namespace/namespace_census_receipt.dag` | STILL-UNCONSUMED | | `gunbc.p1_retention_cohort_receipt` | `dag/gunbc/p1_retention_cohort_receipt.dag` | STILL-UNCONSUMED | | `gunbc.plans.affected_set_self_confirmation` | `dag/gunbc/plans/affected_set_self_confirmation.dag` | STILL-UNCONSUMED | | `gunbc.plans.fleet_subsumption_manual_gaps` | `dag/gunbc/plans/fleet_subsumption_manual_gaps.dag` | STILL-UNCONSUMED | @@ -718,7 +718,7 @@ Named by a live `.dag`, `.rs` or data file, or otherwise carrying an obligation | `gunbc.seed_closed_vocabulary_wildcard_census` | `dag/gunbc/seed_closed_vocabulary_wildcard_census.dag` | STILL-UNCONSUMED | | `gunbc.site.interaction` | `dag/gunbc/site/interaction.dag` | STILL-UNCONSUMED | | `gunbc.test_node_wall_clock_ratchet` | `dag/gunbc/test_node_wall_clock_ratchet.dag` | STILL-UNCONSUMED | -| `gunbc.v1_maintenance_standing` | `dag/gunbc/v1_maintenance_standing.dag` | STILL-UNCONSUMED | +| `gunbc.v1_maintenance_standing` | `dag/gunbc/v1/v1_maintenance_standing.dag` | STILL-UNCONSUMED | | `std.exec_format` | `dag/std/exec_format.dag` | DEAD-CONSUMER-ONLY | | `std.import` | `dag/std/import.dag` | STILL-UNCONSUMED | | `std.methods` | `dag/std/methods.dag` | STILL-UNCONSUMED | diff --git a/docs/plans/v1-run-stability-throughline.md b/docs/plans/v1-run-stability-throughline.md index 8ef9959dfd3..407520b34c7 100644 --- a/docs/plans/v1-run-stability-throughline.md +++ b/docs/plans/v1-run-stability-throughline.md @@ -20,7 +20,7 @@ ## 0. The displaced cost (why this lane, in one line) -Whole-corpus floor runs currently pin at the 15 GiB `memory.high` reclaim clamp and die by step-cap at swap speed (runs 29183446733: 270 min; 29197126623: 60 min; four floor_peak_post reads pinned within 0.65 MiB of exactly 16,106,127,360 B, 2026-07-11 — `dag/gunbc/ci_floor_measurement.dag`). Every interpreter-touching PR, every main push with a wide diff, and every falsifier cold run pays this. The affected-set path is healthy (run 29220300831: 114/1,759 affected, 2.12 GiB peak, ci job 11m40s) — **the unstable regime is exactly the whole-corpus-affected run**. +Whole-corpus floor runs currently pin at the 15 GiB `memory.high` reclaim clamp and die by step-cap at swap speed (runs 29183446733: 270 min; 29197126623: 60 min; four floor_peak_post reads pinned within 0.65 MiB of exactly 16,106,127,360 B, 2026-07-11 — `dag/gunbc/ci/ci_floor_measurement.dag`). Every interpreter-touching PR, every main push with a wide diff, and every falsifier cold run pays this. The affected-set path is healthy (run 29220300831: 114/1,759 affected, 2.12 GiB peak, ci job 11m40s) — **the unstable regime is exactly the whole-corpus-affected run**. **The failure axis, stated precisely (review correction, 2026-07-13):** the adaptive governor *packs width to the `memory.high` line by construction* (`ci_floor_measurement.dag`: "The run-time memory governor packs to this line by construction: it reads the tightest memory.high as its budget and backs off on the creep signals") — so the floor's cgroup peak is a **design constant** whenever queued work remains, not a defect signal. The defect is that per-worker retention is so large the governor is forced to `forced_serial=1` (one worker ≈ the whole budget, 474 ceiling back-offs), the corpus runs serially at swap speed, and the run **dies by step-cap — a time death caused by a memory shape**. Retention reduction therefore buys *width and wall-clock*, not a lower floor peak; the success metric throughout this doc is **completion within the step budget at width > 1**, with the **isolated probe peak** (single-process `measure_whole_tree_resolve`) as the retention-reduction measure. `floor_peak_post` staying pinned at ~15 GiB after a successful cut is expected, not failure. diff --git a/docs/runbooks/srv3-nbd-proxy-ws-upgrade-dry-run.md b/docs/runbooks/srv3-nbd-proxy-ws-upgrade-dry-run.md index f72cd20841b..1e70697bc4e 100644 --- a/docs/runbooks/srv3-nbd-proxy-ws-upgrade-dry-run.md +++ b/docs/runbooks/srv3-nbd-proxy-ws-upgrade-dry-run.md @@ -29,7 +29,7 @@ non-upgrade GET (inconclusive — ws routes commonly 404 without an `Upgrade` he ## Prerequisites - Management-network reachability to srv3 BMC: **192.168.1.192** (cited in - `dag/gunbc/bmc_onboarding.dag`). + `dag/gunbc/bmc/bmc_onboarding.dag`). - OpenBMC 2.07.00 (srv3 cited row in `dag/extdeps/bmc/capability.dag`). - BMC credentials: factory `root` / `0penBmc` until rotated (`dag/extdeps/bmc/openbmc.dag`), or operator netrc per [BMC Redfish operator access](bmc-redfish-operator-access.md). diff --git a/docs/runbooks/srv3-os-install-actuate.md b/docs/runbooks/srv3-os-install-actuate.md index d3cfe1f1af8..dd06c0aa9b4 100644 --- a/docs/runbooks/srv3-os-install-actuate.md +++ b/docs/runbooks/srv3-os-install-actuate.md @@ -39,7 +39,7 @@ websocat is **not** in Ubuntu Noble apt; the modeled ensure installs curl/nbdkit export PATH="/var/lib/gunbc/bin:$PATH" gunbc run --source-root dag \ - --entry dag/gunbc/srv3_os_install_actuator_toolchain_ensure.dag \ + --entry dag/gunbc/srv3/srv3_os_install_actuator_toolchain_ensure.dag \ --function srv3_os_install_actuator_toolchain_ensure ``` @@ -54,7 +54,7 @@ GUNBC_ROOT="${GUNBC_ROOT:-$PWD}" cd "$GUNBC_ROOT" gunbc run --source-root dag \ - --entry dag/gunbc/srv3_install_media_fetch.dag \ + --entry dag/gunbc/srv3/srv3_install_media_fetch.dag \ --function srv3_install_media_fetch ``` @@ -76,11 +76,11 @@ repack (srv1 was verified to lack xorriso/genisoimage/mkisofs — do not assume ```bash gunbc run --source-root dag \ - --entry dag/gunbc/srv3_seeded_install_media.dag \ + --entry dag/gunbc/srv3/srv3_seeded_install_media.dag \ --function srv3_seeded_install_media_toolchain_ensure gunbc run --source-root dag \ - --entry dag/gunbc/srv3_seeded_install_media.dag \ + --entry dag/gunbc/srv3/srv3_seeded_install_media.dag \ --function srv3_seeded_install_media_remaster ``` @@ -110,7 +110,7 @@ Requires **gcloud auth** on the actuator host when BMC is in `RotatedCredentialA ```bash gunbc run --source-root dag \ - --entry dag/gunbc/srv3_os_install_actuate.dag \ + --entry dag/gunbc/srv3/srv3_os_install_actuate.dag \ --function srv3_bmcweb_session_login ``` @@ -122,7 +122,7 @@ Run in **two terminals** on the actuator host. ```bash gunbc run --source-root dag \ - --entry dag/gunbc/srv3_os_install_actuate.dag \ + --entry dag/gunbc/srv3/srv3_os_install_actuate.dag \ --function srv3_nbd_proxy_serve ``` @@ -138,7 +138,7 @@ After serve is stable (give nbd-proxy ~10s to attach): ```bash cd "$GUNBC_ROOT" gunbc run --source-root dag \ - --entry dag/gunbc/srv3_boot_once_cd.dag \ + --entry dag/gunbc/srv3/srv3_boot_once_cd.dag \ --function srv3_boot_once_cd_operator_approved ``` @@ -227,10 +227,10 @@ srv3 os-install-actuated receipt ## Related model files -- `dag/gunbc/srv3_os_install_actuate.dag` — runnable prep + serve/login funcs -- `dag/gunbc/srv3_boot_once_cd.dag` — Redfish boot-once CD + force restart -- `dag/gunbc/srv3_os_install_diagnostic.dag` — `Srv3InstallDebugObservation` + `diagnose_srv3_install` +- `dag/gunbc/srv3/srv3_os_install_actuate.dag` — runnable prep + serve/login funcs +- `dag/gunbc/srv3/srv3_boot_once_cd.dag` — Redfish boot-once CD + force restart +- `dag/gunbc/srv3/srv3_os_install_diagnostic.dag` — `Srv3InstallDebugObservation` + `diagnose_srv3_install` - `dag/gunbc/srv3_install_diagnostic_checklist.dag` — executable observe + classify on srv1 - `dag/gunbc/network_identity_subsumption.dag` — DHCP option-12 subsumption checks -- `dag/gunbc/host_standup.dag` — `prefix:os-install-actuated` spine gap +- `dag/gunbc/host/host_standup.dag` — `prefix:os-install-actuated` spine gap - `docs/plans/srv3-webui-kvm-virtual-media.md` — architecture B design diff --git a/src/v1/stage0/src/bin/claim_executor.rs b/src/v1/stage0/src/bin/claim_executor.rs index 76eaaf982f1..1962fa97c9e 100644 --- a/src/v1/stage0/src/bin/claim_executor.rs +++ b/src/v1/stage0/src/bin/claim_executor.rs @@ -1878,7 +1878,7 @@ mod tests { /// Test-only obligation-subject literals must track gunbc.ci_materialization authority rows. #[test] fn floor_resolve_obligation_seed_constants_match_dag_authority() { - let ci_materialization = dag_source_from_repo("dag/gunbc/ci_materialization.dag"); + let ci_materialization = dag_source_from_repo("dag/gunbc/ci/ci_materialization.dag"); assert_eq!( dag_record_string_field( &ci_materialization, diff --git a/src/v1/stage0/src/cli_run.rs b/src/v1/stage0/src/cli_run.rs index 5629ccea19e..70170a27e36 100644 --- a/src/v1/stage0/src/cli_run.rs +++ b/src/v1/stage0/src/cli_run.rs @@ -394,7 +394,7 @@ fn project_roadmap_acceptance_event_history_from_authority_text_inner( }; } } - let overlay_path = temp_dir.join("dag/gunbc/roadmap_authority.dag"); + let overlay_path = temp_dir.join("dag/gunbc/roadmap/roadmap_authority.dag"); if let Err(error) = std::fs::create_dir_all(overlay_path.parent().unwrap()) .and_then(|_| std::fs::write(&overlay_path, authority_text)) { @@ -818,7 +818,7 @@ mod roadmap_acceptance_history_projection_tests { #[test] fn merge_base_authority_projection_matches_jsonl_carrier() { let authority = std::process::Command::new("git") - .args(["show", "9ce6526c528:dag/gunbc/roadmap_authority.dag"]) + .args(["show", "9ce6526c528:dag/gunbc/roadmap/roadmap_authority.dag"]) .output() .expect("git show merge-base authority"); assert!( @@ -828,7 +828,7 @@ mod roadmap_acceptance_history_projection_tests { ); let authority = String::from_utf8(authority.stdout).expect("utf8 authority"); let jsonl = std::fs::read_to_string( - super::workspace_root().join("dag/gunbc/roadmap_acceptance_event_history.jsonl"), + super::workspace_root().join("dag/gunbc/roadmap/roadmap_acceptance_event_history.jsonl"), ) .expect("jsonl carrier"); let projected = project_roadmap_acceptance_event_history_from_authority_text(&authority); @@ -1279,12 +1279,12 @@ mod process_workspace_root_tests { #[test] fn repo_relative_path_normalizes_under_process_root() { let root = process_workspace_root(); - let abs = root.join("dag/gunbc/ci_layer_roots.dag"); + let abs = root.join("dag/gunbc/ci/ci_layer_roots.dag"); let rel = repo_relative_path(&abs).expect("under process root"); - assert_eq!(rel, "dag/gunbc/ci_layer_roots.dag"); + assert_eq!(rel, "dag/gunbc/ci/ci_layer_roots.dag"); assert_eq!( workspace_relative_repo_path(&abs.to_string_lossy()), - "dag/gunbc/ci_layer_roots.dag" + "dag/gunbc/ci/ci_layer_roots.dag" ); } @@ -1292,7 +1292,7 @@ mod process_workspace_root_tests { fn anchor_source_root_resolves_relative_dag() { let anchored = anchor_source_root("dag"); assert!(Path::new(&anchored) - .join("gunbc/ci_layer_roots.dag") + .join("gunbc/ci/ci_layer_roots.dag") .is_file()); } @@ -1300,7 +1300,7 @@ mod process_workspace_root_tests { fn try_anchor_source_root_resolves_declared_present_root() { let anchored = try_anchor_source_root("dag").expect("dag exists in every checkout"); assert!(Path::new(&anchored) - .join("gunbc/ci_layer_roots.dag") + .join("gunbc/ci/ci_layer_roots.dag") .is_file()); } @@ -1474,12 +1474,12 @@ mod process_workspace_root_tests { fn repo_relative_path_normalized_reanchors_baked_absolute_file() { let ws = process_workspace_root(); let baked = workspace_root(); - let abs = baked.join("dag/gunbc/ci_layer_roots.dag"); + let abs = baked.join("dag/gunbc/ci/ci_layer_roots.dag"); if !abs.is_file() { return; } let rel = repo_relative_path_normalized(&abs); - assert_eq!(rel, "dag/gunbc/ci_layer_roots.dag"); + assert_eq!(rel, "dag/gunbc/ci/ci_layer_roots.dag"); assert_eq!(workspace_relative_repo_path(&abs.to_string_lossy()), rel); assert!(ws.join(&rel).is_file()); } @@ -1490,13 +1490,13 @@ mod process_workspace_root_tests { /// through once verified against the process root, never strip-prefix-panic. #[test] fn repo_relative_path_normalized_accepts_relative_spelling_under_root() { - let rel_in = Path::new("dag/gunbc/ci_layer_roots.dag"); + let rel_in = Path::new("dag/gunbc/ci/ci_layer_roots.dag"); if !process_workspace_root().join(rel_in).is_file() { return; } assert_eq!( repo_relative_path_normalized(rel_in), - "dag/gunbc/ci_layer_roots.dag" + "dag/gunbc/ci/ci_layer_roots.dag" ); } @@ -2718,13 +2718,13 @@ fn compile_dag_rust_emit_check_uncached( } } -const CI_LAYER_ROOTS_AUTHORITY_REL: &str = "dag/gunbc/ci_layer_roots.dag"; +const CI_LAYER_ROOTS_AUTHORITY_REL: &str = "dag/gunbc/ci/ci_layer_roots.dag"; /// The function-grain exact witness admission authority (`gunbc.explicit_witness_admission`). /// Separate from the path-policy carrier above on purpose: an admission names one witness and /// its executing cadence, a path policy names a place, and fusing them into one substring /// representation is what made the old reconciliation weaker than its name. const EXPLICIT_WITNESS_ADMISSION_AUTHORITY_REL: &str = "dag/gunbc/explicit_witness_admission.dag"; -const WITNESS_DEFERRAL_FREEZE_AUTHORITY_REL: &str = "dag/gunbc/witness_deferral_freeze.dag"; +const WITNESS_DEFERRAL_FREEZE_AUTHORITY_REL: &str = "dag/gunbc/witness/witness_deferral_freeze.dag"; const COMMIT_WORKFLOW_AUTHORITY_REL: &str = "dag/gunbc/commit_workflow.dag"; const WITNESS_LAYER_ROOTS_DATA_NAME: &str = "witness_layer_roots"; const WITNESS_DISCOVERY_SCAN_DIRS_DATA_NAME: &str = "witness_discovery_scan_dirs"; @@ -12503,12 +12503,12 @@ mod live_read_selection_manifest_producer_tests { &ctx, "PathPattern", "LiteralPath", - vec![("path", str_value("dag/gunbc/ci_spec.dag".to_string()))], + vec![("path", str_value("dag/gunbc/ci/ci_spec.dag".to_string()))], ); assert_eq!( decoded_carriers(&ctx, vec![fs_carrier(&ctx, pattern)]), vec![LiveReadCarrier::FilesystemReadPath( - LiveReadPathPattern::LiteralPath("dag/gunbc/ci_spec.dag".to_string()) + LiveReadPathPattern::LiteralPath("dag/gunbc/ci/ci_spec.dag".to_string()) )] ); } @@ -12612,10 +12612,10 @@ mod live_read_selection_manifest_producer_tests { fn a_literal_path_carrier_intersects_only_its_own_path() { let row = LiveReadSelectionRow::Classified(LiveReadClassification::RuntimeRead { carriers: vec![LiveReadCarrier::FilesystemReadPath( - LiveReadPathPattern::LiteralPath("dag/gunbc/ci_spec.dag".to_string()), + LiveReadPathPattern::LiteralPath("dag/gunbc/ci/ci_spec.dag".to_string()), )], }); - assert!(row.touched_by(&touched(&["dag/gunbc/ci_spec.dag"]))); + assert!(row.touched_by(&touched(&["dag/gunbc/ci/ci_spec.dag"]))); // The whole point of preserving the literal: an unrelated diff does NOT select it. A // `runtime_read: bool` row could not express this and had to say true here. assert!(!row.touched_by(&touched(&["dag/gunbc/unrelated.dag"]))); @@ -12648,7 +12648,7 @@ mod live_read_selection_manifest_producer_tests { #[test] fn a_local_read_is_never_touched_and_a_refusal_always_is() { let local = LiveReadSelectionRow::Classified(LiveReadClassification::LocalRead); - assert!(!local.touched_by(&touched(&["dag/gunbc/ci_spec.dag"]))); + assert!(!local.touched_by(&touched(&["dag/gunbc/ci/ci_spec.dag"]))); let refused = LiveReadSelectionRow::Refused { cause: "partial subject".to_string(), }; @@ -14829,7 +14829,7 @@ fn typed_module_cache_cap_derivation() -> (usize, String, bool) { // the enum instead of re-parsing its display label (§3, avoid a second representation). let degraded = !(source_label.contains("memory.max") || source_label.contains("memory.high")); // REFUSE rather than widen when no budget is readable (operator ruling 2026-08-05; - // authority `dag/gunbc/host_budget_source.dag` `HostBudgetUnreadable`). + // authority `dag/gunbc/host/host_budget_source.dag` `HostBudgetUnreadable`). // // This was `.unwrap_or(TYPED_MODULE_CACHE_MAX_ENTRIES_CEIL)`: a budget that could not // be computed became the MOST PERMISSIVE cap available — top-as-answer conflated with @@ -14852,7 +14852,7 @@ fn typed_module_cache_cap_derivation() -> (usize, String, bool) { unknown budget cannot be defaulted — the previous default was the ceiling, which \ OOM-killed this process rather than refusing. Declare one with \ GUNBC_MEMORY_BUDGET_BYTES, or model this platform's memory source \ - (dag/gunbc/host_budget_source.dag)." + (dag/gunbc/host/host_budget_source.dag)." ); }; let cap = ((budget_bytes / TYPED_MODULE_BYTES_PER_ENTRY_ESTIMATE) as usize).clamp( @@ -17989,7 +17989,7 @@ fn tree_bare_census_for_root( /// Whole-pool census: every pool module regardless of tree. The loader's /// cross-tree fallback (see the `pool_bare_census` field note) — a v2 module's -/// bare `gunbc_ci_spec` (declared in dag/gunbc/ci_spec.dag) resolves here after +/// bare `gunbc_ci_spec` (declared in dag/gunbc/ci/ci_spec.dag) resolves here after /// missing the v2 tree census, so the provider is pulled and becomes /// closure-visible at typecheck. fn pool_bare_census(index: &MultiEntryIndex) -> Result, String> { @@ -20183,7 +20183,7 @@ pub fn run_witness_verdict_diagnostic( /// `append_failure_receipt_companion_loudness` / `gunbc.test_module_hygiene.failure_receipt_companion` /// stack — no parallel naming authority. Lane: **v1 exit** (zero hand-maintained Rust). /// ROADMAP row: "Get hand-written Rust in this repository down to zero" -/// (authority `dag/gunbc/v1_deletion_plan.dag`). Dissolution trigger: deleted with +/// (authority `dag/gunbc/v1/v1_deletion_plan.dag`). Dissolution trigger: deleted with /// `claim_executor` when witness execution leaves the seed runner; witnesses then call the /// loudness projection directly without this bridge. pub fn seed_runner_bool_false_failure_detail( @@ -23185,7 +23185,7 @@ pub fn compute_percentiles(mut values: Vec) -> TimingPercentiles { // SCAFFOLD (§7 hand-Rust shrink-to-zero, dissolution named): the v1 evaluator measures its own // per-witness resolve+eval percentiles here — seed-side justified (the evaluator cannot measure -// itself without circularity). The *rendering* of these timings now lives in `dag/gunbc/ci_render.dag` +// itself without circularity). The *rendering* of these timings now lives in `dag/gunbc/ci/ci_render.dag` // (boxed Frames over `std.render`, width-parameterized by the medium's `Viewport.width`); this Rust // only produces the measured data. Full dissolution: ROADMAP lane "CI observability" emits the // `TimingPercentiles` rows as a substrate value so a .dag witness measures + histograms natively, @@ -23397,10 +23397,10 @@ pub fn project_witness_cost_receipt( let entry = source_roots .iter() - .map(|root| Path::new(root).join("gunbc/witness_row_cost.dag")) + .map(|root| Path::new(root).join("gunbc/witness/witness_row_cost.dag")) .find(|path| path.is_file()) .ok_or_else(|| { - "[witness-row-cost] REFUSED: gunbc/witness_row_cost.dag is absent from source roots" + "[witness-row-cost] REFUSED: gunbc/witness/witness_row_cost.dag is absent from source roots" .to_string() })? .to_string_lossy() @@ -24016,7 +24016,7 @@ fn witness_admission_manifest_key(entry: &str, function: &str) -> String { // ROADMAP lane `5-dissolve-patches` / module-identity-storage-binding Phase 1 (b) // (gunbc.roadmap_authority / ROADMAP.md; module-identity-storage-binding-design (plan doc deleted 2026-08-28)). // The host Phase 0(b) admission key set is a hand-rolled text scan over enrollment forms in -// dag/gunbc/ci_layer_roots.dag, src/v2/compiler/self_host/wet_receipt_enrollment.dag, and the +// dag/gunbc/ci/ci_layer_roots.dag, src/v2/compiler/self_host/wet_receipt_enrollment.dag, and the // cycle-free leaf src/v2/compiler/self_host/seed_emitter_behavioral_wet_known_red_entries.dag. // The third target is NOT new HAND-RUST surface (review 44441): wet_receipt aliases the leaf as // `falsifier_self_host_wet_known_red_entries = seed_emitter_behavioral_wet_known_red_entries` @@ -24184,7 +24184,7 @@ pub fn witness_admission_explicit_consumer_keys() -> Vec { static KEYS: OnceLock> = OnceLock::new(); KEYS.get_or_init(|| { let mut keys = witness_admission_entry_function_keys_from_source( - "dag/gunbc/ci_layer_roots.dag", + "dag/gunbc/ci/ci_layer_roots.dag", ci_layer_roots_authority_content(), ); let wet = @@ -24488,7 +24488,7 @@ fn format_expected_red_freeze_intersection_refusal( "REQUIRED-FLOOR REFUSAL cause=ExpectedRedFreezeIntersection count={} head={head} — {} \ identity(ies) are simultaneously enrolled in \ v2.workflow.floor_expected_red.floor_expected_red_roster (known-red, removable only by \ - an observed pass) AND path-deferred in dag/gunbc/witness_deferral_freeze.dag \ + an observed pass) AND path-deferred in dag/gunbc/witness/witness_deferral_freeze.dag \ frozen_path_deferrals (LegacyFrozenPathDeferral, admitted as never-executed). Both \ claims cannot hold of one identity: this roster's own did-not-execute check below \ proves every enrolled row here DOES execute, so the freeze row is stale evidence, not a \ @@ -24516,7 +24516,7 @@ fn format_route_gap_freeze_intersection_refusal( identity(ies) are simultaneously enrolled in \ v2.workflow.floor_route_gap.floor_route_gap_roster (a typed witness that this required \ floor attempts to execute but cannot route to its subject) AND path-deferred in \ - dag/gunbc/witness_deferral_freeze.dag frozen_path_deferrals \ + dag/gunbc/witness/witness_deferral_freeze.dag frozen_path_deferrals \ (LegacyFrozenPathDeferral, admitted as having no executing consumer). Both claims cannot \ hold of one identity: the typed route-gap receipt exists only because this required \ floor consumed the row, so the freeze classification is stale evidence, not a live \ @@ -28977,7 +28977,7 @@ fn emit_batch_summary(merged: &DiscoverySummary) { // `run_discovery_rows`); these helpers only choose how the already-decided run is printed. They // live in Rust because the v1 evaluator narrates its own floor walk (the same seed-side reason as // `phase_profile.rs` and `GUNBC_FLOOR_GANTT`). The *rendering* they emit is the same class of -// output already migrating into `dag/gunbc/ci_render.dag` (the timing histogram + slowest-witness +// output already migrating into `dag/gunbc/ci/ci_render.dag` (the timing histogram + slowest-witness // rollup render there today). Full dissolution: when v2 emit-host owns floor observability — a // `.dag` floor-event carrier a witness consumes by execution, the retirement event shared with // `phase_profile.rs` (`docs/plans/realization-measurement-loop.md` Phase 0) and the fractal Gantt @@ -30733,7 +30733,7 @@ mod module_grain_affected_equivalence_tests { "dag/test/claim/v1_dag_parse_witness_test.dag", "dag/tools/host_prelude.dag", "dag/tools/build_step.dag", - "dag/gunbc/ci_layer_roots.dag", + "dag/gunbc/ci/ci_layer_roots.dag", "src/v2/test/claim/bash_command_fold_test.dag", "src/v2/workflow/orchestration_emit_test.dag", "dag/test/claim/long/import_closure_live_test.dag", @@ -41231,7 +41231,7 @@ mod module_path_index_tests { let sample = index .get("gunbc.ci_layer_roots") .expect("gunbc.ci_layer_roots must be indexed from relative roots"); - assert_eq!(sample, "dag/gunbc/ci_layer_roots.dag"); + assert_eq!(sample, "dag/gunbc/ci/ci_layer_roots.dag"); assert!( ws.join(sample).is_file(), "indexed rel path must resolve under workspace_root()" diff --git a/src/v1/stage0/src/coproduct_reflection.rs b/src/v1/stage0/src/coproduct_reflection.rs index 1173989209c..01c55ad31ee 100644 --- a/src/v1/stage0/src/coproduct_reflection.rs +++ b/src/v1/stage0/src/coproduct_reflection.rs @@ -1614,7 +1614,7 @@ fn nullary_coproduct_variant_value( // DESIGN section 7 seed-retained repair. This bridge retires with // `coproduct_reflection` under ROADMAP "Drain the hand-maintained v1 product -// queue" (`dag/gunbc/v1_deletion_plan.dag` milestone `^hand_queue_drain`). +// queue" (`dag/gunbc/v1/v1_deletion_plan.dag` milestone `^hand_queue_drain`). // Checkable receipt: the imported-named-coproduct generic-wrapper witness must // resolve, while the wrong-A/context-B and payload-bearing controls must refuse. struct TypedNullaryCoproductWitness { diff --git a/src/v1/stage0/src/memory_governor.rs b/src/v1/stage0/src/memory_governor.rs index 54301cc7822..0eda12a3514 100644 --- a/src/v1/stage0/src/memory_governor.rs +++ b/src/v1/stage0/src/memory_governor.rs @@ -389,7 +389,7 @@ pub fn whole_corpus_compile_refusal_diagnostic( than admitting against the widest cap available — an unbounded resolve on an \ unbounded host is the OOM-kill this arm exists to prevent. Declare one with \ GUNBC_MEMORY_BUDGET_BYTES, or model this platform's memory source \ - (dag/gunbc/host_budget_source.dag)." + (dag/gunbc/host/host_budget_source.dag)." )), } } @@ -443,7 +443,7 @@ pub fn read_host_budget_bytes() -> (Option, String) { return (Some(budget), source); } // Terminal arms. Authority for the source vocabulary and its rendering is - // `dag/gunbc/host_budget_source.dag` (`HostBudgetSource`); `dag/extdeps/linux/procfs.dag` + // `dag/gunbc/host/host_budget_source.dag` (`HostBudgetSource`); `dag/extdeps/linux/procfs.dag` // carries why a Darwin host never reaches the meminfo arm. // // The meminfo arm used to be unconditional: `(mem_total_bytes(), "/proc/meminfo diff --git a/src/v1/stage0/src/pre_push.rs b/src/v1/stage0/src/pre_push.rs index 5035a1ff512..493fd92503e 100644 --- a/src/v1/stage0/src/pre_push.rs +++ b/src/v1/stage0/src/pre_push.rs @@ -12,7 +12,7 @@ use std::process::{Command, ExitCode, Stdio}; use super::{make_eval_context, resolve_entry_graph_shared, witness_layer_roots}; use crate::v1_interpreter::{self, str_value, ExecutionMode, Value}; -const PLAN_ENTRY: &str = "dag/gunbc/githooks_pre_push_plan.dag"; +const PLAN_ENTRY: &str = "dag/gunbc/githooks/githooks_pre_push_plan.dag"; struct PrePushStdinRow { local_ref: String, diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 7a1c24ea5b8..db639011ae0 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -4844,7 +4844,7 @@ fn native_map_absent_diagnostic_value(ctx: &InterpContext) -> Value { // // Citation note: the two sibling deferrals in this file and in // `emit_on_demand_host_seed_deferral_note` name a -// `dag/gunbc/v1_deletion_plan.dag ^witness_realization_kernel` deletion row. That row +// `dag/gunbc/v1/v1_deletion_plan.dag ^witness_realization_kernel` deletion row. That row // no longer exists — the brick ledger it belonged to was retired 2026-07-28 by that // file's own `v1_exit_model_doc`, which moved per-node acceptance onto the roadmap // tickets. This deferral therefore names the live roadmap node instead of copying a @@ -9597,7 +9597,7 @@ fn argv_materialization_value( /// `extdeps.render.ansi` authority (`ansi_mappings` in `dag/extdeps/render/ansi.dag`). /// Seed realization until the interpreter consumes that table directly; the /// dissolution is the single checkable receipt ROADMAP §1 "interpreter -/// terminal-output de-fork" (`dag/gunbc/roadmap_authority.dag`). +/// terminal-output de-fork" (`dag/gunbc/roadmap/roadmap_authority.dag`). pub mod sgr { pub const SUCCESS: &str = "38;5;34"; pub const ERROR: &str = "38;5;196"; @@ -12583,7 +12583,7 @@ fn eval_emit_host_run_transport_builtin( /// file, not a census-shrink receipt and not a new Rust authority. Its lane is /// ROADMAP "Make native materialization the shared execution kernel", /// witness-realization-plan (plan doc deleted 2026-08-28) P3/P6, with the concrete deletion row -/// dag/gunbc/v1_deletion_plan.dag ^witness_realization_kernel. Delete these +/// dag/gunbc/v1/v1_deletion_plan.dag ^witness_realization_kernel. Delete these /// observation/apply helpers when the self-emitted transport consumes the modeled /// ResolvedBuildContext and the dispatcher-change, environment-change, and /// cold/warm agreement witnesses remain green without them. diff --git a/src/v1/stage0/src/v1_tests_claim_reference_derived_disposition_census_witness_test.rs b/src/v1/stage0/src/v1_tests_claim_reference_derived_disposition_census_witness_test.rs index 227c7bae45a..ccf7ad12ae3 100644 --- a/src/v1/stage0/src/v1_tests_claim_reference_derived_disposition_census_witness_test.rs +++ b/src/v1/stage0/src/v1_tests_claim_reference_derived_disposition_census_witness_test.rs @@ -34,7 +34,7 @@ use std::rc::Rc; pub fn reference_derived_disposition_census_witness_note() -> String { thread_local! { static CACHED: String = { - "THE ROUTE HALF OF THIS FILE IS ABSENT AND THE REASON IS A WALL RATHER THAN A CHOICE, stated here because it is the first thing a reader of a five-row file should know: the end-to-end pair this file was designed around -- a two-module manifest whose consumer calls a peer fn in VALUE position with no import, against a control differing by one authored import line -- was authored and DOES NOT RUN. A nested compile is not evaluable in the interpreter: compile_to_resolved over an authored source vector refuses with NoSuchField Node.ident during the nested pipeline, measured 2026-08-27 on three separate subjects. That is not a property of this change; it is why the two nested-compile instruments the corpus already has (gunbc.compile_diagnostic_census and tools.multi_module_compile_fixture) both route through a HOST BUILTIN rather than calling the pipeline from .dag. The rows are not retained in a form that cannot execute, because a probe that always errors is not a red -- it is an inert artifact that would be counted as coverage. NEXT-RUNG TRIGGER FOR THE ROUTE: a nested-compile builtin returning the resolved graph, the shape tools.multi_module_compile_fixture already has, widened to carry the emitter reference-derived rows.\n\nWHERE THIS RUNS, STATED FIRST AND WITHOUT FLATTERY. THIS WITNESS IS NOT RUN BY CI. gunbc.ci_layer_roots witness_discovery_scan_dirs is [dag/test/claim, src/v2/test/claim/manual, src/v2/test/claim/emit] -- src/v1/tests/claim is not among them -- and the required run invokes claim_executor with --source-root dag --source-root src/v2, which could not resolve this file's import of v1.compiler.emit_rust even if discovery reached it. The scoped batch that once ran this directory died in the 2026-08-15 floor cut; gunbc.ci_layer_roots v1_claim_scoped_witness_batch_deleted_note records that and states the entries here have no executing consumer. The roster its sibling checkpoint_identity_keying_witness_test claims to be enrolled in, v1_claim_scoped_witness_entries, is not declared anywhere in dag/gunbc/ci_layer_roots.dag -- verified by grep in both directions rather than taken from the note. THE FIVE ROWS BELOW WERE RUN DIRECTLY ON 2026-08-27 AND ALL FIVE PASS. Direct execution is evidence the assertions HOLD, never evidence that CI runs them, and conflating those two is the rung inflation this directory has now recorded twice.\n\nWHAT THE SUBJECT IS. Since PR 6848 a cross-module name resolves whether or not it is imported. At TYPE positions the resolver says so advisorily (UnlistedImportUse, is_error_diagnostic false); at VALUE positions it says nothing at all, and the emitter silently synthesizes the use-line the author did not write. That synthesis is unchanged here and deliberately so. What changed is that the per-candidate decision behind it stopped being an inline flat_map whose three non-surviving arms all returned the empty list, and became a four-armed coproduct one census can count.\n\nWHY BOTH HALVES ARE HERE. The four unit rows discriminate the DECISION: each names a distinct arm, and two of them differ ONLY in whether the provider's export set proves the symbol, so no constant, disabled mechanism or name-keyed rule satisfies them together. The end-to-end rows discriminate the CENSUS ROUTE: a two-module manifest compiled through compile_to_resolved, whose consumer references a peer's fn in VALUE position with no import, against a control differing by exactly one authored import line. The unlisted arm must produce a survived row naming peer_answer; the control must produce no row for that name at all, because an already-provided name never reaches the decision. Neither can pass vacuously -- a census that always reported zero fails the first, and one that reported every reference fails the second.\n\nTHE RED IS AUTHORABLE AT THE FIXTURE BOUNDARY, which is what makes this a probe rather than a decoration. No Accepted corpus module can be relied on to hold a value-position unlisted use on demand, but a fixture manifest can author one directly, and this file does. DESIGN 4b: a check whose RED cannot be produced anywhere it runs is permanently green by construction and worse than absent, because it gets cited as coverage. What this file lacks is a RUNNER, not a reachable red.\n\nWHAT THIS DOES NOT ESTABLISH. Nothing about the SIZE of the live population -- these are fixtures; NO PRODUCER FOR A REAL FIGURE EXISTS YET, and this file does not name one: the only route from .dag to a corpus census is a nested compile, which the interpreter refuses, so any figure quoted today names nothing that can produce it. And nothing about the names the census never sees: a candidate already provided by an authored import, the prelude, a carrier use-line or the module's own declarations is filtered before the decision, so every count is a LOWER BOUND and the gap is unmeasured. Quote it as at least N.\n\nNEXT-RUNG TRIGGER FOR THIS FILE'S EVIDENCE, which is NOT the same trigger as the class's and must not be folded into it: one prepared subject spanning dag, src/v1 and src/v2 -- the restoration gunbc.ci_layer_roots already names for the deleted batch -- at which point these rows execute and this first paragraph deletes. The CLASS's own trigger (the value-position case joining the fail-closed wall, retiring the census and the synthesis together) lives on v1.compiler.emit_rust reference_derived_census_rung_note. Either can land first; neither closes the other.".to_string() + "THE ROUTE HALF OF THIS FILE IS ABSENT AND THE REASON IS A WALL RATHER THAN A CHOICE, stated here because it is the first thing a reader of a five-row file should know: the end-to-end pair this file was designed around -- a two-module manifest whose consumer calls a peer fn in VALUE position with no import, against a control differing by one authored import line -- was authored and DOES NOT RUN. A nested compile is not evaluable in the interpreter: compile_to_resolved over an authored source vector refuses with NoSuchField Node.ident during the nested pipeline, measured 2026-08-27 on three separate subjects. That is not a property of this change; it is why the two nested-compile instruments the corpus already has (gunbc.compile_diagnostic_census and tools.multi_module_compile_fixture) both route through a HOST BUILTIN rather than calling the pipeline from .dag. The rows are not retained in a form that cannot execute, because a probe that always errors is not a red -- it is an inert artifact that would be counted as coverage. NEXT-RUNG TRIGGER FOR THE ROUTE: a nested-compile builtin returning the resolved graph, the shape tools.multi_module_compile_fixture already has, widened to carry the emitter reference-derived rows.\n\nWHERE THIS RUNS, STATED FIRST AND WITHOUT FLATTERY. THIS WITNESS IS NOT RUN BY CI. gunbc.ci_layer_roots witness_discovery_scan_dirs is [dag/test/claim, src/v2/test/claim/manual, src/v2/test/claim/emit] -- src/v1/tests/claim is not among them -- and the required run invokes claim_executor with --source-root dag --source-root src/v2, which could not resolve this file's import of v1.compiler.emit_rust even if discovery reached it. The scoped batch that once ran this directory died in the 2026-08-15 floor cut; gunbc.ci_layer_roots v1_claim_scoped_witness_batch_deleted_note records that and states the entries here have no executing consumer. The roster its sibling checkpoint_identity_keying_witness_test claims to be enrolled in, v1_claim_scoped_witness_entries, is not declared anywhere in dag/gunbc/ci/ci_layer_roots.dag -- verified by grep in both directions rather than taken from the note. THE FIVE ROWS BELOW WERE RUN DIRECTLY ON 2026-08-27 AND ALL FIVE PASS. Direct execution is evidence the assertions HOLD, never evidence that CI runs them, and conflating those two is the rung inflation this directory has now recorded twice.\n\nWHAT THE SUBJECT IS. Since PR 6848 a cross-module name resolves whether or not it is imported. At TYPE positions the resolver says so advisorily (UnlistedImportUse, is_error_diagnostic false); at VALUE positions it says nothing at all, and the emitter silently synthesizes the use-line the author did not write. That synthesis is unchanged here and deliberately so. What changed is that the per-candidate decision behind it stopped being an inline flat_map whose three non-surviving arms all returned the empty list, and became a four-armed coproduct one census can count.\n\nWHY BOTH HALVES ARE HERE. The four unit rows discriminate the DECISION: each names a distinct arm, and two of them differ ONLY in whether the provider's export set proves the symbol, so no constant, disabled mechanism or name-keyed rule satisfies them together. The end-to-end rows discriminate the CENSUS ROUTE: a two-module manifest compiled through compile_to_resolved, whose consumer references a peer's fn in VALUE position with no import, against a control differing by exactly one authored import line. The unlisted arm must produce a survived row naming peer_answer; the control must produce no row for that name at all, because an already-provided name never reaches the decision. Neither can pass vacuously -- a census that always reported zero fails the first, and one that reported every reference fails the second.\n\nTHE RED IS AUTHORABLE AT THE FIXTURE BOUNDARY, which is what makes this a probe rather than a decoration. No Accepted corpus module can be relied on to hold a value-position unlisted use on demand, but a fixture manifest can author one directly, and this file does. DESIGN 4b: a check whose RED cannot be produced anywhere it runs is permanently green by construction and worse than absent, because it gets cited as coverage. What this file lacks is a RUNNER, not a reachable red.\n\nWHAT THIS DOES NOT ESTABLISH. Nothing about the SIZE of the live population -- these are fixtures; NO PRODUCER FOR A REAL FIGURE EXISTS YET, and this file does not name one: the only route from .dag to a corpus census is a nested compile, which the interpreter refuses, so any figure quoted today names nothing that can produce it. And nothing about the names the census never sees: a candidate already provided by an authored import, the prelude, a carrier use-line or the module's own declarations is filtered before the decision, so every count is a LOWER BOUND and the gap is unmeasured. Quote it as at least N.\n\nNEXT-RUNG TRIGGER FOR THIS FILE'S EVIDENCE, which is NOT the same trigger as the class's and must not be folded into it: one prepared subject spanning dag, src/v1 and src/v2 -- the restoration gunbc.ci_layer_roots already names for the deleted batch -- at which point these rows execute and this first paragraph deletes. The CLASS's own trigger (the value-position case joining the fail-closed wall, retiring the census and the synthesis together) lives on v1.compiler.emit_rust reference_derived_census_rung_note. Either can land first; neither closes the other.".to_string() }; } CACHED.with(|c: &String| c.clone()) diff --git a/src/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs b/src/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs index 74313a8ad52..72b54da9b46 100644 --- a/src/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs +++ b/src/v1/stage0/tests/interpreter_dispatch_bijection_real_roster_red.rs @@ -109,7 +109,7 @@ fn cargo_build_v1_compiler(clone_root: &Path) -> Output { .expect("cargo build -p v1-compiler") } -const ROSTER_REL: &str = "dag/gunbc/v1_interpreter_primitive_surface.dag"; +const ROSTER_REL: &str = "dag/gunbc/v1/v1_interpreter_primitive_surface.dag"; const INTERPRETER_REL: &str = "src/v1/stage0/src/v1_interpreter.rs"; /// Direction 1: add a roster row at `eval_builtin_inner` with a fresh identity/spelling that has diff --git a/src/v1/tests/claim/reference_derived_disposition_census_witness_test.dag b/src/v1/tests/claim/reference_derived_disposition_census_witness_test.dag index 5fce048d415..895e408187d 100644 --- a/src/v1/tests/claim/reference_derived_disposition_census_witness_test.dag +++ b/src/v1/tests/claim/reference_derived_disposition_census_witness_test.dag @@ -25,7 +25,7 @@ import v1.std.core { import v1.compiler.infer_emit_info { TypeSummary, EnumRepr } import v1.compiler.compile { SourceFile, compile_to_resolved } -data reference_derived_disposition_census_witness_note: String = "THE ROUTE HALF OF THIS FILE IS ABSENT AND THE REASON IS A WALL RATHER THAN A CHOICE, stated here because it is the first thing a reader of a five-row file should know: the end-to-end pair this file was designed around -- a two-module manifest whose consumer calls a peer fn in VALUE position with no import, against a control differing by one authored import line -- was authored and DOES NOT RUN. A nested compile is not evaluable in the interpreter: compile_to_resolved over an authored source vector refuses with NoSuchField Node.ident during the nested pipeline, measured 2026-08-27 on three separate subjects. That is not a property of this change; it is why the two nested-compile instruments the corpus already has (gunbc.compile_diagnostic_census and tools.multi_module_compile_fixture) both route through a HOST BUILTIN rather than calling the pipeline from .dag. The rows are not retained in a form that cannot execute, because a probe that always errors is not a red -- it is an inert artifact that would be counted as coverage. NEXT-RUNG TRIGGER FOR THE ROUTE: a nested-compile builtin returning the resolved graph, the shape tools.multi_module_compile_fixture already has, widened to carry the emitter reference-derived rows.\n\nWHERE THIS RUNS, STATED FIRST AND WITHOUT FLATTERY. THIS WITNESS IS NOT RUN BY CI. gunbc.ci_layer_roots witness_discovery_scan_dirs is [dag/test/claim, src/v2/test/claim/manual, src/v2/test/claim/emit] -- src/v1/tests/claim is not among them -- and the required run invokes claim_executor with --source-root dag --source-root src/v2, which could not resolve this file's import of v1.compiler.emit_rust even if discovery reached it. The scoped batch that once ran this directory died in the 2026-08-15 floor cut; gunbc.ci_layer_roots v1_claim_scoped_witness_batch_deleted_note records that and states the entries here have no executing consumer. The roster its sibling checkpoint_identity_keying_witness_test claims to be enrolled in, v1_claim_scoped_witness_entries, is not declared anywhere in dag/gunbc/ci_layer_roots.dag -- verified by grep in both directions rather than taken from the note. THE FIVE ROWS BELOW WERE RUN DIRECTLY ON 2026-08-27 AND ALL FIVE PASS. Direct execution is evidence the assertions HOLD, never evidence that CI runs them, and conflating those two is the rung inflation this directory has now recorded twice.\n\nWHAT THE SUBJECT IS. Since PR 6848 a cross-module name resolves whether or not it is imported. At TYPE positions the resolver says so advisorily (UnlistedImportUse, is_error_diagnostic false); at VALUE positions it says nothing at all, and the emitter silently synthesizes the use-line the author did not write. That synthesis is unchanged here and deliberately so. What changed is that the per-candidate decision behind it stopped being an inline flat_map whose three non-surviving arms all returned the empty list, and became a four-armed coproduct one census can count.\n\nWHY BOTH HALVES ARE HERE. The four unit rows discriminate the DECISION: each names a distinct arm, and two of them differ ONLY in whether the provider's export set proves the symbol, so no constant, disabled mechanism or name-keyed rule satisfies them together. The end-to-end rows discriminate the CENSUS ROUTE: a two-module manifest compiled through compile_to_resolved, whose consumer references a peer's fn in VALUE position with no import, against a control differing by exactly one authored import line. The unlisted arm must produce a survived row naming peer_answer; the control must produce no row for that name at all, because an already-provided name never reaches the decision. Neither can pass vacuously -- a census that always reported zero fails the first, and one that reported every reference fails the second.\n\nTHE RED IS AUTHORABLE AT THE FIXTURE BOUNDARY, which is what makes this a probe rather than a decoration. No Accepted corpus module can be relied on to hold a value-position unlisted use on demand, but a fixture manifest can author one directly, and this file does. DESIGN 4b: a check whose RED cannot be produced anywhere it runs is permanently green by construction and worse than absent, because it gets cited as coverage. What this file lacks is a RUNNER, not a reachable red.\n\nWHAT THIS DOES NOT ESTABLISH. Nothing about the SIZE of the live population -- these are fixtures; NO PRODUCER FOR A REAL FIGURE EXISTS YET, and this file does not name one: the only route from .dag to a corpus census is a nested compile, which the interpreter refuses, so any figure quoted today names nothing that can produce it. And nothing about the names the census never sees: a candidate already provided by an authored import, the prelude, a carrier use-line or the module's own declarations is filtered before the decision, so every count is a LOWER BOUND and the gap is unmeasured. Quote it as at least N.\n\nNEXT-RUNG TRIGGER FOR THIS FILE'S EVIDENCE, which is NOT the same trigger as the class's and must not be folded into it: one prepared subject spanning dag, src/v1 and src/v2 -- the restoration gunbc.ci_layer_roots already names for the deleted batch -- at which point these rows execute and this first paragraph deletes. The CLASS's own trigger (the value-position case joining the fail-closed wall, retiring the census and the synthesis together) lives on v1.compiler.emit_rust reference_derived_census_rung_note. Either can land first; neither closes the other." +data reference_derived_disposition_census_witness_note: String = "THE ROUTE HALF OF THIS FILE IS ABSENT AND THE REASON IS A WALL RATHER THAN A CHOICE, stated here because it is the first thing a reader of a five-row file should know: the end-to-end pair this file was designed around -- a two-module manifest whose consumer calls a peer fn in VALUE position with no import, against a control differing by one authored import line -- was authored and DOES NOT RUN. A nested compile is not evaluable in the interpreter: compile_to_resolved over an authored source vector refuses with NoSuchField Node.ident during the nested pipeline, measured 2026-08-27 on three separate subjects. That is not a property of this change; it is why the two nested-compile instruments the corpus already has (gunbc.compile_diagnostic_census and tools.multi_module_compile_fixture) both route through a HOST BUILTIN rather than calling the pipeline from .dag. The rows are not retained in a form that cannot execute, because a probe that always errors is not a red -- it is an inert artifact that would be counted as coverage. NEXT-RUNG TRIGGER FOR THE ROUTE: a nested-compile builtin returning the resolved graph, the shape tools.multi_module_compile_fixture already has, widened to carry the emitter reference-derived rows.\n\nWHERE THIS RUNS, STATED FIRST AND WITHOUT FLATTERY. THIS WITNESS IS NOT RUN BY CI. gunbc.ci_layer_roots witness_discovery_scan_dirs is [dag/test/claim, src/v2/test/claim/manual, src/v2/test/claim/emit] -- src/v1/tests/claim is not among them -- and the required run invokes claim_executor with --source-root dag --source-root src/v2, which could not resolve this file's import of v1.compiler.emit_rust even if discovery reached it. The scoped batch that once ran this directory died in the 2026-08-15 floor cut; gunbc.ci_layer_roots v1_claim_scoped_witness_batch_deleted_note records that and states the entries here have no executing consumer. The roster its sibling checkpoint_identity_keying_witness_test claims to be enrolled in, v1_claim_scoped_witness_entries, is not declared anywhere in dag/gunbc/ci/ci_layer_roots.dag -- verified by grep in both directions rather than taken from the note. THE FIVE ROWS BELOW WERE RUN DIRECTLY ON 2026-08-27 AND ALL FIVE PASS. Direct execution is evidence the assertions HOLD, never evidence that CI runs them, and conflating those two is the rung inflation this directory has now recorded twice.\n\nWHAT THE SUBJECT IS. Since PR 6848 a cross-module name resolves whether or not it is imported. At TYPE positions the resolver says so advisorily (UnlistedImportUse, is_error_diagnostic false); at VALUE positions it says nothing at all, and the emitter silently synthesizes the use-line the author did not write. That synthesis is unchanged here and deliberately so. What changed is that the per-candidate decision behind it stopped being an inline flat_map whose three non-surviving arms all returned the empty list, and became a four-armed coproduct one census can count.\n\nWHY BOTH HALVES ARE HERE. The four unit rows discriminate the DECISION: each names a distinct arm, and two of them differ ONLY in whether the provider's export set proves the symbol, so no constant, disabled mechanism or name-keyed rule satisfies them together. The end-to-end rows discriminate the CENSUS ROUTE: a two-module manifest compiled through compile_to_resolved, whose consumer references a peer's fn in VALUE position with no import, against a control differing by exactly one authored import line. The unlisted arm must produce a survived row naming peer_answer; the control must produce no row for that name at all, because an already-provided name never reaches the decision. Neither can pass vacuously -- a census that always reported zero fails the first, and one that reported every reference fails the second.\n\nTHE RED IS AUTHORABLE AT THE FIXTURE BOUNDARY, which is what makes this a probe rather than a decoration. No Accepted corpus module can be relied on to hold a value-position unlisted use on demand, but a fixture manifest can author one directly, and this file does. DESIGN 4b: a check whose RED cannot be produced anywhere it runs is permanently green by construction and worse than absent, because it gets cited as coverage. What this file lacks is a RUNNER, not a reachable red.\n\nWHAT THIS DOES NOT ESTABLISH. Nothing about the SIZE of the live population -- these are fixtures; NO PRODUCER FOR A REAL FIGURE EXISTS YET, and this file does not name one: the only route from .dag to a corpus census is a nested compile, which the interpreter refuses, so any figure quoted today names nothing that can produce it. And nothing about the names the census never sees: a candidate already provided by an authored import, the prelude, a carrier use-line or the module's own declarations is filtered before the decision, so every count is a LOWER BOUND and the gap is unmeasured. Quote it as at least N.\n\nNEXT-RUNG TRIGGER FOR THIS FILE'S EVIDENCE, which is NOT the same trigger as the class's and must not be folded into it: one prepared subject spanning dag, src/v1 and src/v2 -- the restoration gunbc.ci_layer_roots already names for the deleted batch -- at which point these rows execute and this first paragraph deletes. The CLASS's own trigger (the value-position case joining the fail-closed wall, retiring the census and the synthesis together) lives on v1.compiler.emit_rust reference_derived_census_rung_note. Either can land first; neither closes the other." fn fixture_item_info(name: String, module_name: String) -> ItemInfo { ItemInfo { diff --git a/src/v2/compiler/self_host/stage0_crate_layout.dag b/src/v2/compiler/self_host/stage0_crate_layout.dag index 9fbd931f9c7..2e8a4433066 100644 --- a/src/v2/compiler/self_host/stage0_crate_layout.dag +++ b/src/v2/compiler/self_host/stage0_crate_layout.dag @@ -301,7 +301,7 @@ data wet_actuator_generated_registrations: List` was -tried on small probe functions during Move 1 (see **git history** on this -branch for the ephemeral probe sources: nat_add/nat_mul recursion, kernel -`1 == 1`, bool meet via lattice top/bottom, well_formed on empty Conj, -trivial ProcessExit). No placeholder `probes.dag` module is kept in-tree — real -`dag run` probes should land with **T-22**, not as an empty reserved module. - -Findings (v2 seed interpreter, merged v2 graph) ------------------------------------------------ -COVERED by compile-only gate today - - Entire `src/v2/**/*.dag` module graph parses, resolves imports, and - type-checks under v2 — including new `test/claim/manual/*` TestClaim data. - -NOT COVERED by v2 `run` (runtime) — honest gaps - - Cross-module calls into substrate `fn` values (e.g. `nat_add`) from a - `func` probe: runtime error `undefined variable: nat_add`. - - Returning `ProcessExit` / `ExitSuccess` from a minimal probe: runtime - error `undefined variable: int_add` (host/exit plumbing not wired for this - graph shape). - - `well_formed` on a tiny well-formed `Node`: non-terminating under the - interpreter in local trials (treated as interpreter gap, not claimed - substrate bug). - -Interpretation --------------- -v2 `compile` is the reliable pre-T-22 bridge; v2 `run` is **not** a truthful -execution oracle for v2 substrate yet. Phase 2 testing that requires -evaluating v2 programs + TestClaims must wait on **T-22 (v2 compiler/05_eval -and claim runner)** — dissolution trigger for an automated `v1-compiler run` -TestClaim CI lane. - -There is **no** `ProcessExit` duplicate under `src/v2/` — canonical carrier -remains **`dag/std/process.dag`** only (P2 single authority). A prior test-only -shim was removed once it had zero consumers; reintroduce only with an explicit -Practice-4 receipt **and** a real `dag run` entry consumer, or after T-22 when -v2 owns eval without cross-root duplication. - -Interim CI (Move 3) -------------------- -Per brief: **DEFERRED** — no required `v1-compiler run` gate on TestClaim -execution until T-22. The `v2` workflow adds a **non-blocking informational** -step after bootstrap viability (`.github/workflows/ci.yml`): it sets -`V2_PREFLIGHT_SKIP_COMPILE=1` and runs `scripts/v2-run-preflight.sh`, which -**skips** a second `v1-compiler compile` (the prior step already compiled -`src/v2`) and only emits the GitHub `::notice::` tying deferral to **T-22** — -visible in logs, not a silent drop. The step is **not** `continue-on-error` -(the script always exits 0; the flag was redundant and removed). - -Atom-shaped manual TestClaims ------------------------------ -K-1 forbids minting `Symbol` values in `.dag` data literals; `Atom {…}` -TestClaims are therefore absent from `test/claim/manual/connective_anchors.dag` -with an explicit note in that file. diff --git a/src/v2/lens/meta_exec_confinement.dag b/src/v2/lens/meta_exec_confinement.dag index fb9efbe92a5..8144182110e 100644 --- a/src/v2/lens/meta_exec_confinement.dag +++ b/src/v2/lens/meta_exec_confinement.dag @@ -30,7 +30,7 @@ data meta_exec_realization_edge_path_prefixes: List = [ "dag/test/claim/" ] -data meta_exec_confinement_roster_empty_note: String = "Roster 3 -> 0 (shell->dag bucket A). dag/gunbc/tools/review.dag and dag/gunbc/ci_deploy_target_host.dag were STALE — neither has invoked extdeps.shell.exec for several merges (review.dag imports only extdeps.git; ci_deploy_target_host.dag imports extdeps.shell for shell.Env.Get, which is not the confined module — see non_exec_import_is_not_leak_holds). dag/gunbc/host_runner_memory_cap_verify.dag was the genuine remainder and dissolved in the same PR: its probed_at read moved from a retained_runtime shell.Exec.Run onto the typed extdeps.clock Clock.Now op via gunbc.clock_read, joining the memory-property reads already on typed systemd.Systemctl.ShowProperty. An EMPTY roster is the shrink-only end state: with no rows, every intent-layer import of the confined module is a leak with no exception to grant, so meta_exec_confinement_holds_canonical alone gates the tree. Adding a row back is a conspicuous, reviewable event BY EXECUTION, not by diligence: meta_exec_roster_shrunk_to_empty_holds (v2.test.meta_exec_confinement.roster_soundness, enrolled per-PR) reds in the same PR that adds one. That wall is what runs on the fast lane, NOT meta_exec_roster_sound_live — the live receipt costs 13.5s cold against a 5s budget (measured 2026-07-25) and lives in v2.test.long.meta_exec_confinement_clean_tree as a backstop on a lane that is still dark. The wall is affordable because it needs no scan at all: stale_count is bounded above by roster length, so length 0 proves soundness outright. A future justified row must therefore land WITH a live soundness receipt on a real cadence — the wall relaxes to that receipt, never the reverse." +data meta_exec_confinement_roster_empty_note: String = "Roster 3 -> 0 (shell->dag bucket A). dag/gunbc/tools/review.dag and dag/gunbc/ci/ci_deploy_target_host.dag were STALE — neither has invoked extdeps.shell.exec for several merges (review.dag imports only extdeps.git; ci_deploy_target_host.dag imports extdeps.shell for shell.Env.Get, which is not the confined module — see non_exec_import_is_not_leak_holds). dag/gunbc/host/host_runner_memory_cap_verify.dag was the genuine remainder and dissolved in the same PR: its probed_at read moved from a retained_runtime shell.Exec.Run onto the typed extdeps.clock Clock.Now op via gunbc.clock_read, joining the memory-property reads already on typed systemd.Systemctl.ShowProperty. An EMPTY roster is the shrink-only end state: with no rows, every intent-layer import of the confined module is a leak with no exception to grant, so meta_exec_confinement_holds_canonical alone gates the tree. Adding a row back is a conspicuous, reviewable event BY EXECUTION, not by diligence: meta_exec_roster_shrunk_to_empty_holds (v2.test.meta_exec_confinement.roster_soundness, enrolled per-PR) reds in the same PR that adds one. That wall is what runs on the fast lane, NOT meta_exec_roster_sound_live — the live receipt costs 13.5s cold against a 5s budget (measured 2026-07-25) and lives in v2.test.long.meta_exec_confinement_clean_tree as a backstop on a lane that is still dark. The wall is affordable because it needs no scan at all: stale_count is bounded above by roster length, so length 0 proves soundness outright. A future justified row must therefore land WITH a live soundness receipt on a real cadence — the wall relaxes to that receipt, never the reverse." data meta_exec_confinement_exception_roster: List = [] diff --git a/src/v2/lens/realization_vocabulary_containment.dag b/src/v2/lens/realization_vocabulary_containment.dag index d28bb1b122c..71a562c14b9 100644 --- a/src/v2/lens/realization_vocabulary_containment.dag +++ b/src/v2/lens/realization_vocabulary_containment.dag @@ -69,7 +69,7 @@ type RealizationVocabGrandfatheredEdgeRow { data realization_vocab_grandfathered_edge_roster: List = [ RealizationVocabGrandfatheredEdgeRow { edge: RealizationVocabImportEdge { - importer_path: "dag/gunbc/roadmap_component.dag", + importer_path: "dag/gunbc/roadmap/roadmap_component.dag", vocab_module: "extdeps.languages.typescript.program" }, debt_class: ProductLayerTargetAstDebt, diff --git a/src/v2/std/algebra_laws/.gitkeep b/src/v2/std/algebra_laws/.gitkeep deleted file mode 100644 index e69de29bb2d..00000000000 diff --git a/src/v2/std/algebra_laws/field_patch_monoid_test.dag b/src/v2/test/algebra_laws/field_patch_monoid_test.dag similarity index 100% rename from src/v2/std/algebra_laws/field_patch_monoid_test.dag rename to src/v2/test/algebra_laws/field_patch_monoid_test.dag diff --git a/src/v2/std/algebra_laws/is_prefix_of_prefix_check.dag b/src/v2/test/algebra_laws/is_prefix_of_prefix_check.dag similarity index 100% rename from src/v2/std/algebra_laws/is_prefix_of_prefix_check.dag rename to src/v2/test/algebra_laws/is_prefix_of_prefix_check.dag diff --git a/src/v2/std/algebra_laws/nat_semiring.dag b/src/v2/test/algebra_laws/nat_semiring.dag similarity index 100% rename from src/v2/std/algebra_laws/nat_semiring.dag rename to src/v2/test/algebra_laws/nat_semiring.dag diff --git a/src/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag b/src/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag index 13959a3c782..c3791575eee 100644 --- a/src/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag +++ b/src/v2/test/claim/host_language_transport_script/corpus/wall_residue_live_test.dag @@ -9,31 +9,31 @@ data wall_residue_roster_note: String = "The roster is the non-test corpus set o test fn residue_host_effect_realize_clean() -> Bool { transport_script_live_literal_violation_count_for_path( - path: "dag/gunbc/host_effect_realize.dag" + path: "dag/gunbc/host/host_effect_realize.dag" ) == 0 } test fn residue_host_converge_slice1_clean() -> Bool { transport_script_live_literal_violation_count_for_path( - path: "dag/gunbc/host_converge_slice1.dag" + path: "dag/gunbc/host/host_converge_slice1.dag" ) == 0 } test fn residue_host_identity_adopt_clean() -> Bool { transport_script_live_literal_violation_count_for_path( - path: "dag/gunbc/host_identity_adopt.dag" + path: "dag/gunbc/host/host_identity_adopt.dag" ) == 0 } test fn residue_host_identity_assimilation_clean() -> Bool { transport_script_live_literal_violation_count_for_path( - path: "dag/gunbc/host_identity_assimilation.dag" + path: "dag/gunbc/host/host_identity_assimilation.dag" ) == 0 } test fn residue_host_runner_memory_cap_verify_clean() -> Bool { transport_script_live_literal_violation_count_for_path( - path: "dag/gunbc/host_runner_memory_cap_verify.dag" + path: "dag/gunbc/host/host_runner_memory_cap_verify.dag" ) == 0 } diff --git a/src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag b/src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag index 2c76f045be7..f16fdff4fbd 100644 --- a/src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag +++ b/src/v2/test/claim/meta_exec_confinement/lens_unit/discriminators_test.dag @@ -85,12 +85,12 @@ test fn non_exec_import_is_not_leak_holds() -> Bool { } data stale_roster: List = [ - "dag/gunbc/ci_deploy_access.dag", + "dag/gunbc/ci/ci_deploy_access.dag", "dag/gunbc/_perturb_stale_meta_exec_roster.dag" ] data live_leak_paths: List = [ - "dag/gunbc/ci_deploy_target_host.dag" + "dag/gunbc/ci/ci_deploy_target_host.dag" ] test fn roster_stale_entry_red_holds() -> Bool { meta_exec_roster_stale_count(roster: stale_roster, live_leak_paths: live_leak_paths) == 2 diff --git a/src/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag b/src/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag index 36c26320604..b4a11a76dc4 100644 --- a/src/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag +++ b/src/v2/test/claim/meta_exec_confinement/roster_soundness_test.dag @@ -16,7 +16,7 @@ data planted_roster_entry: String = "dag/gunbc/_perturb_stale_meta_exec_roster.d data empty_live_leak_paths: List = [] -data roster_dark_lane_finding: String = "WHY THIS FILE EXISTS. meta_exec_roster_sound_live already existed in the lens but ran on NO per-PR cadence — the only enrolled roster RED was the synthetic roster_stale_entry_red_holds in lens_unit/discriminators_test.dag, which feeds hand-written fact rows and therefore cannot see the live roster at all. That is exactly how two rows (dag/gunbc/tools/review.dag, dag/gunbc/ci_deploy_target_host.dag) stayed on the roster for several merges after their sites stopped importing extdeps.shell.exec: nothing per-PR ever compared the roster against the tree." +data roster_dark_lane_finding: String = "WHY THIS FILE EXISTS. meta_exec_roster_sound_live already existed in the lens but ran on NO per-PR cadence — the only enrolled roster RED was the synthetic roster_stale_entry_red_holds in lens_unit/discriminators_test.dag, which feeds hand-written fact rows and therefore cannot see the live roster at all. That is exactly how two rows (dag/gunbc/tools/review.dag, dag/gunbc/ci/ci_deploy_target_host.dag) stayed on the roster for several merges after their sites stopped importing extdeps.shell.exec: nothing per-PR ever compared the roster against the tree." data roster_emptiness_is_construction_not_validation_note: String = "MEASURED, then designed (DESIGN section 5: construction over validation; section 6: priced in displaced cost). The obvious fix — enroll meta_exec_roster_sound_live per-PR — is not affordable, and saying so is part of the receipt: measured 2026-07-25 on the bucket-A branch, that receipt evaluates COLD in 13470ms over meta_exec_consumer_scan_roots and still 11485ms over dag/gunbc alone, against a 5s fast-lane eval budget (gunbc_ci_fast_lane_rule_note) and an enrolled sibling (scanner_planted_meta_exec_leak_detected_holds) costing 2ms. The cold number is the honest one: re-run in the same process behind an already-warmed scan the same receipt reports 1852ms, which is warmth borrowed from whichever witness paid the 13s first and is not a property this row can declare. The cost is intrinsic to layer_import_facts_live over a real tree, so no narrower root rescues it; the live receipt therefore lives in v2.test.long.meta_exec_confinement_clean_tree beside the clean-tree receipt. What CAN run per-PR is stronger than soundness anyway. A stale row is only possible because the roster is a hand-written SECOND representation of a fact the tree already carries (which files import the confined module). At length 0 that second representation is gone and staleness is not merely absent but UNWRITABLE — stale_count is bounded above by roster length, so length 0 proves stale_count 0 with no scan at all. This receipt walls the empty state directly: it is a live read of the actual roster declaration, it costs nothing, and re-introducing the parallel ledger cannot happen quietly — adding any row reds this witness by name in the same PR that adds it, which is precisely the event that went unnoticed before. Shrink-only stops depending on memory. Dissolve-on: if a future row is genuinely justified, it lands together with a live soundness receipt on a real cadence (a falsifier batch, not test/claim/long/'s dark lane) and this emptiness wall relaxes to that receipt — never the reverse order." diff --git a/src/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag b/src/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag index c6b7937ff41..37ecd1fe05e 100644 --- a/src/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag +++ b/src/v2/test/claim/realization_vocabulary_containment/cli_vocabulary/rest_path_reaches_no_cli_test.dag @@ -232,7 +232,7 @@ test fn dropping_the_definition_edge_roster_surfaces_more() -> Bool { data transport_realization_edges: List = [ "dag/gunbc/retained_shell_script.dag", "dag/gunbc/bash_materialized_transport.dag", - "dag/gunbc/host_effect_realize.dag" + "dag/gunbc/host/host_effect_realize.dag" ] // CONSUMERS HOLDING A TRANSPORT, admitted as exact pairs so that a SEVENTH consumer diff --git a/src/v2/test/claim/realization_vocabulary_containment/lens_unit/discriminators_test.dag b/src/v2/test/claim/realization_vocabulary_containment/lens_unit/discriminators_test.dag index 21b8b26a99f..975d74a4c23 100644 --- a/src/v2/test/claim/realization_vocabulary_containment/lens_unit/discriminators_test.dag +++ b/src/v2/test/claim/realization_vocabulary_containment/lens_unit/discriminators_test.dag @@ -62,7 +62,7 @@ test fn rostered_consumer_import_is_not_leak_holds() -> Bool { data de_rostered_consumer_import_facts: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/ci_spec.dag", + path: "dag/gunbc/ci/ci_spec.dag", import_module: sidecar_module } ] @@ -100,7 +100,7 @@ fn edge_in_grandfathered_roster(edge: RealizationVocabImportEdge) -> Bool { test fn ci_spec_excused_from_bash_roster_holds() -> Bool { !edge_in_grandfathered_roster( edge: RealizationVocabImportEdge { - importer_path: "dag/gunbc/ci_spec.dag", + importer_path: "dag/gunbc/ci/ci_spec.dag", vocab_module: bash_vocab_module } ) @@ -151,7 +151,7 @@ test fn node_http_server_emit_rostered_for_typescript_sidecar_holds() -> Bool { test fn roadmap_component_rostered_for_typescript_sidecar_holds() -> Bool { edge_in_grandfathered_roster( edge: RealizationVocabImportEdge { - importer_path: "dag/gunbc/roadmap_component.dag", + importer_path: "dag/gunbc/roadmap/roadmap_component.dag", vocab_module: sidecar_module } ) @@ -211,6 +211,6 @@ test fn de_rostered_ci_materialization_emit_edge_is_leak_holds() -> Bool { test fn grandfathered_edge_keys_are_exact_identity_holds() -> Bool { list_contains_str( xs: realization_vocab_grandfathered_edge_keys(), - target: "dag/gunbc/roadmap_component.dag -> extdeps.languages.typescript.program" + target: "dag/gunbc/roadmap/roadmap_component.dag -> extdeps.languages.typescript.program" ) } diff --git a/src/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag b/src/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag index 87ad14c80a7..21618fc2064 100644 --- a/src/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag +++ b/src/v2/test/claim/realization_vocabulary_containment/no_new_debt_gate_test.dag @@ -23,7 +23,7 @@ data typescript_sidecar_module: String = "extdeps.languages.typescript.program" data bash_build_module: String = "v2.extdeps.languages.bash_build" data ts0_census_roadmap_component_edge: RealizationVocabImportEdge = RealizationVocabImportEdge { - importer_path: "dag/gunbc/roadmap_component.dag", + importer_path: "dag/gunbc/roadmap/roadmap_component.dag", vocab_module: typescript_sidecar_module } @@ -84,7 +84,7 @@ test fn ts0_census_build_step_edge_is_grandfathered_holds() -> Bool { data ts0_frozen_roadmap_component_fact: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module } ] @@ -132,12 +132,12 @@ test fn ts0_unrostered_non_edge_import_is_leak_holds() -> Bool { data ts0_grandfathered_file_second_vocab_facts: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module }, LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: bash_build_module } ] @@ -149,7 +149,7 @@ test fn ts0_grandfathered_file_cannot_acquire_second_vocab_edge_holds() -> Bool data ts0_different_importer_same_vocab_facts: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module }, LayerImportFact { @@ -166,7 +166,7 @@ test fn ts0_different_importer_same_vocab_new_edge_is_leak_holds() -> Bool { data ts0_frozen_facts_union: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module }, LayerImportFact { @@ -198,7 +198,7 @@ test fn ts0_frozen_population_containment_holds_holds() -> Bool { test fn ts0_grandfathered_edge_keys_use_exact_edge_identity_holds() -> Bool { list_contains_str( xs: realization_vocab_grandfathered_edge_keys(), - target: "dag/gunbc/roadmap_component.dag -> extdeps.languages.typescript.program" + target: "dag/gunbc/roadmap/roadmap_component.dag -> extdeps.languages.typescript.program" ) && list_contains_str( xs: realization_vocab_grandfathered_edge_keys(), diff --git a/src/v2/test/claim/realization_vocabulary_containment/roster_soundness_test.dag b/src/v2/test/claim/realization_vocabulary_containment/roster_soundness_test.dag index 086d3efb468..dee8dcc7195 100644 --- a/src/v2/test/claim/realization_vocabulary_containment/roster_soundness_test.dag +++ b/src/v2/test/claim/realization_vocabulary_containment/roster_soundness_test.dag @@ -24,7 +24,7 @@ data roster_soundness_fast_lane_note: String = "Live-corpus roster soundness rec data ts0_frozen_census_facts: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module }, LayerImportFact { @@ -52,7 +52,7 @@ data ts0_frozen_census_facts: List = [ data ts0_frozen_census_facts_missing_build_step: List = [ LayerImportFact { layer: LayerPrefixStd, - path: "dag/gunbc/roadmap_component.dag", + path: "dag/gunbc/roadmap/roadmap_component.dag", import_module: typescript_sidecar_module }, LayerImportFact { @@ -92,12 +92,12 @@ test fn realization_vocab_grandfathered_edge_roster_keys_are_distinct_holds() -> test fn realization_vocab_grandfathered_edge_keys_distinct_red_on_planted_duplicate_holds() -> Bool { let planted = [ - "dag/gunbc/roadmap_component.dag -> extdeps.languages.typescript.program", + "dag/gunbc/roadmap/roadmap_component.dag -> extdeps.languages.typescript.program", "dag/tools/build_step.dag -> v2.extdeps.languages.bash_build", - "dag/gunbc/roadmap_component.dag -> extdeps.languages.typescript.program" + "dag/gunbc/roadmap/roadmap_component.dag -> extdeps.languages.typescript.program" ] let distinct = [ - "dag/gunbc/roadmap_component.dag -> extdeps.languages.typescript.program", + "dag/gunbc/roadmap/roadmap_component.dag -> extdeps.languages.typescript.program", "dag/tools/build_step.dag -> v2.extdeps.languages.bash_build" ] !realization_vocab_grandfathered_edge_keys_are_distinct(keys: planted) diff --git a/src/v2/test/claim/self_host/crate_layout_witness_test.dag b/src/v2/test/claim/self_host/crate_layout_witness_test.dag index 346bc1466cf..7a4ea115744 100644 --- a/src/v2/test/claim/self_host/crate_layout_witness_test.dag +++ b/src/v2/test/claim/self_host/crate_layout_witness_test.dag @@ -17,7 +17,7 @@ import v2.std.collection { List } import v2.std.logic { Bool } import v2.std.text { String } -data witness_red_control_note: String = "Discriminating RED, both directions: (1) OMIT — drop a basename from generated_pub_mod_basenames while its registration row stands, and witness_generated_basenames_match_registrations_holds goes false on the length comparison; (2) INCLUDE — append phantom_module to generated_pub_mod_basenames with no registration row, and witness_generated_has_no_phantom_registration_holds goes false. A third RED sits outside this file: perturb a suffix in dag/gunbc/stage0_crate_layout_generated.dag and the generated-artifact drift gate reds on bytes." +data witness_red_control_note: String = "Discriminating RED, both directions: (1) OMIT — drop a basename from generated_pub_mod_basenames while its registration row stands, and witness_generated_basenames_match_registrations_holds goes false on the length comparison; (2) INCLUDE — append phantom_module to generated_pub_mod_basenames with no registration row, and witness_generated_has_no_phantom_registration_holds goes false. A third RED sits outside this file: perturb a suffix in dag/gunbc/stage0/stage0_crate_layout_generated.dag and the generated-artifact drift gate reds on bytes." data witness_roster_half_deleted_note: String = "SEVEN WITNESSES WERE DELETED FROM THIS FILE with the self-host frontier roster, and none of them could fail. Three asked whether a specific roster row's basename was registered, each guarded by a match on that row's disposition whose EmitterProduced arm was unreachable — every row was SeedRetained, so all three took the other arm and returned true without consulting the layout at all. Three more compared an emitter-produced basename projection against the emitter-produced count; both sides derived from the same empty projection, so each compared zero with zero. The seventh opened with `if compiler_frontier_emitter_produced_count() == 0 { true }` and had therefore never evaluated its body. diff --git a/src/v2/lens/complexity_accumulator_copy_test.dag b/src/v2/test/complexity_accumulator_copy_test.dag similarity index 100% rename from src/v2/lens/complexity_accumulator_copy_test.dag rename to src/v2/test/complexity_accumulator_copy_test.dag diff --git a/src/v2/extdeps/coordination_claims_test.dag b/src/v2/test/extdeps/coordination_claims_test.dag similarity index 100% rename from src/v2/extdeps/coordination_claims_test.dag rename to src/v2/test/extdeps/coordination_claims_test.dag diff --git a/src/v2/extdeps/formats/spice_passive_projection_test.dag b/src/v2/test/extdeps/formats/spice_passive_projection_test.dag similarity index 100% rename from src/v2/extdeps/formats/spice_passive_projection_test.dag rename to src/v2/test/extdeps/formats/spice_passive_projection_test.dag diff --git a/src/v2/extdeps/react/structural_receipts_test.dag b/src/v2/test/extdeps_react/structural_receipts_test.dag similarity index 100% rename from src/v2/extdeps/react/structural_receipts_test.dag rename to src/v2/test/extdeps_react/structural_receipts_test.dag diff --git a/src/v2/test/fixture/.gitkeep b/src/v2/test/fixture/.gitkeep deleted file mode 100644 index e69de29bb2d..00000000000 diff --git a/src/v2/lens/identity_captured_navigation_test.dag b/src/v2/test/identity_captured_navigation_test.dag similarity index 100% rename from src/v2/lens/identity_captured_navigation_test.dag rename to src/v2/test/identity_captured_navigation_test.dag diff --git a/src/v2/extdeps/language_model/python_l1_static_test.dag b/src/v2/test/language_model/python_l1_static_test.dag similarity index 100% rename from src/v2/extdeps/language_model/python_l1_static_test.dag rename to src/v2/test/language_model/python_l1_static_test.dag diff --git a/src/v2/extdeps/language_model/python_r1_test.dag b/src/v2/test/language_model/python_r1_test.dag similarity index 100% rename from src/v2/extdeps/language_model/python_r1_test.dag rename to src/v2/test/language_model/python_r1_test.dag diff --git a/src/v2/extdeps/language_model/rust.dag b/src/v2/test/language_model/rust.dag similarity index 100% rename from src/v2/extdeps/language_model/rust.dag rename to src/v2/test/language_model/rust.dag diff --git a/src/v2/extdeps/language_model/rust_r1_test.dag b/src/v2/test/language_model/rust_r1_test.dag similarity index 100% rename from src/v2/extdeps/language_model/rust_r1_test.dag rename to src/v2/test/language_model/rust_r1_test.dag diff --git a/src/v2/extdeps/language_model/rust_r3_internal_test.dag b/src/v2/test/language_model/rust_r3_internal_test.dag similarity index 100% rename from src/v2/extdeps/language_model/rust_r3_internal_test.dag rename to src/v2/test/language_model/rust_r3_internal_test.dag diff --git a/src/v2/lens/application/application_subterm_at_empty_path_test.dag b/src/v2/test/lens_application/application_subterm_at_empty_path_test.dag similarity index 100% rename from src/v2/lens/application/application_subterm_at_empty_path_test.dag rename to src/v2/test/lens_application/application_subterm_at_empty_path_test.dag diff --git a/src/v2/lens/application/apply_lens_enforce_uses_projection_test.dag b/src/v2/test/lens_application/apply_lens_enforce_uses_projection_test.dag similarity index 100% rename from src/v2/lens/application/apply_lens_enforce_uses_projection_test.dag rename to src/v2/test/lens_application/apply_lens_enforce_uses_projection_test.dag diff --git a/src/v2/lens/application/apply_lens_introspect_rejection_is_advisory_test.dag b/src/v2/test/lens_application/apply_lens_introspect_rejection_is_advisory_test.dag similarity index 100% rename from src/v2/lens/application/apply_lens_introspect_rejection_is_advisory_test.dag rename to src/v2/test/lens_application/apply_lens_introspect_rejection_is_advisory_test.dag diff --git a/src/v2/lens/application/empty_required_lenses_skip_gate_test.dag b/src/v2/test/lens_application/empty_required_lenses_skip_gate_test.dag similarity index 100% rename from src/v2/lens/application/empty_required_lenses_skip_gate_test.dag rename to src/v2/test/lens_application/empty_required_lenses_skip_gate_test.dag diff --git a/src/v2/lens/application/enforce_rejecting_gate_fires_test.dag b/src/v2/test/lens_application/enforce_rejecting_gate_fires_test.dag similarity index 100% rename from src/v2/lens/application/enforce_rejecting_gate_fires_test.dag rename to src/v2/test/lens_application/enforce_rejecting_gate_fires_test.dag diff --git a/src/v2/lens/application/introspect_clean_tree_passes_test.dag b/src/v2/test/lens_application/introspect_clean_tree_passes_test.dag similarity index 100% rename from src/v2/lens/application/introspect_clean_tree_passes_test.dag rename to src/v2/test/lens_application/introspect_clean_tree_passes_test.dag diff --git a/src/v2/lens/application/rejecting_lens_blocks_before_compile_test.dag b/src/v2/test/lens_application/rejecting_lens_blocks_before_compile_test.dag similarity index 100% rename from src/v2/lens/application/rejecting_lens_blocks_before_compile_test.dag rename to src/v2/test/lens_application/rejecting_lens_blocks_before_compile_test.dag diff --git a/src/v2/lens/application/serialize_applied_diff_swap_operands_test.dag b/src/v2/test/lens_application/serialize_applied_diff_swap_operands_test.dag similarity index 100% rename from src/v2/lens/application/serialize_applied_diff_swap_operands_test.dag rename to src/v2/test/lens_application/serialize_applied_diff_swap_operands_test.dag diff --git a/src/v2/lens/application/sg_claims_test.dag b/src/v2/test/lens_application/sg_claims_test.dag similarity index 100% rename from src/v2/lens/application/sg_claims_test.dag rename to src/v2/test/lens_application/sg_claims_test.dag diff --git a/src/v2/lens/application/substitute_at_ambiguous_duplicate_name_test.dag b/src/v2/test/lens_application/substitute_at_ambiguous_duplicate_name_test.dag similarity index 100% rename from src/v2/lens/application/substitute_at_ambiguous_duplicate_name_test.dag rename to src/v2/test/lens_application/substitute_at_ambiguous_duplicate_name_test.dag diff --git a/src/v2/lens/application/substitute_at_depth_three_test.dag b/src/v2/test/lens_application/substitute_at_depth_three_test.dag similarity index 100% rename from src/v2/lens/application/substitute_at_depth_three_test.dag rename to src/v2/test/lens_application/substitute_at_depth_three_test.dag diff --git a/src/v2/lens/application/substitute_at_depth_two_test.dag b/src/v2/test/lens_application/substitute_at_depth_two_test.dag similarity index 100% rename from src/v2/lens/application/substitute_at_depth_two_test.dag rename to src/v2/test/lens_application/substitute_at_depth_two_test.dag diff --git a/src/v2/lens/application/subterm_at_ambiguous_duplicate_name_test.dag b/src/v2/test/lens_application/subterm_at_ambiguous_duplicate_name_test.dag similarity index 100% rename from src/v2/lens/application/subterm_at_ambiguous_duplicate_name_test.dag rename to src/v2/test/lens_application/subterm_at_ambiguous_duplicate_name_test.dag diff --git a/src/v2/lens/common/infer_fixture.dag b/src/v2/test/lens_common/infer_fixture.dag similarity index 100% rename from src/v2/lens/common/infer_fixture.dag rename to src/v2/test/lens_common/infer_fixture.dag diff --git a/src/v2/lens/complexity/algebra_receipts_test.dag b/src/v2/test/lens_complexity/algebra_receipts_test.dag similarity index 100% rename from src/v2/lens/complexity/algebra_receipts_test.dag rename to src/v2/test/lens_complexity/algebra_receipts_test.dag diff --git a/src/v2/lens/complexity/map_id_test.dag b/src/v2/test/lens_complexity/map_id_test.dag similarity index 100% rename from src/v2/lens/complexity/map_id_test.dag rename to src/v2/test/lens_complexity/map_id_test.dag diff --git a/src/v2/lens/complexity/nested_test.dag b/src/v2/test/lens_complexity/nested_test.dag similarity index 100% rename from src/v2/lens/complexity/nested_test.dag rename to src/v2/test/lens_complexity/nested_test.dag diff --git a/src/v2/lens/complexity/typescript_type_alias_task.dag b/src/v2/test/lens_complexity/typescript_type_alias_task.dag similarity index 100% rename from src/v2/lens/complexity/typescript_type_alias_task.dag rename to src/v2/test/lens_complexity/typescript_type_alias_task.dag diff --git a/src/v2/lens/complexity/while_external_condition_test.dag b/src/v2/test/lens_complexity/while_external_condition_test.dag similarity index 100% rename from src/v2/lens/complexity/while_external_condition_test.dag rename to src/v2/test/lens_complexity/while_external_condition_test.dag diff --git a/src/v2/lens/complexity_lowering/catalog_sound_test.dag b/src/v2/test/lens_complexity_lowering/catalog_sound_test.dag similarity index 100% rename from src/v2/lens/complexity_lowering/catalog_sound_test.dag rename to src/v2/test/lens_complexity_lowering/catalog_sound_test.dag diff --git a/src/v2/lens/complexity_lowering/loop_invariant_hoist_test.dag b/src/v2/test/lens_complexity_lowering/loop_invariant_hoist_test.dag similarity index 100% rename from src/v2/lens/complexity_lowering/loop_invariant_hoist_test.dag rename to src/v2/test/lens_complexity_lowering/loop_invariant_hoist_test.dag diff --git a/src/v2/lens/cost/arrow_body_cost_domain_excluded.dag b/src/v2/test/lens_cost/arrow_body_cost_domain_excluded.dag similarity index 100% rename from src/v2/lens/cost/arrow_body_cost_domain_excluded.dag rename to src/v2/test/lens_cost/arrow_body_cost_domain_excluded.dag diff --git a/src/v2/lens/cost/atom_zero_test.dag b/src/v2/test/lens_cost/atom_zero_test.dag similarity index 100% rename from src/v2/lens/cost/atom_zero_test.dag rename to src/v2/test/lens_cost/atom_zero_test.dag diff --git a/src/v2/lens/cost/bounded_summation_test.dag b/src/v2/test/lens_cost/bounded_summation_test.dag similarity index 100% rename from src/v2/lens/cost/bounded_summation_test.dag rename to src/v2/test/lens_cost/bounded_summation_test.dag diff --git a/src/v2/lens/cost/copied_port_derivation_test.dag b/src/v2/test/lens_cost/copied_port_derivation_test.dag similarity index 100% rename from src/v2/lens/cost/copied_port_derivation_test.dag rename to src/v2/test/lens_cost/copied_port_derivation_test.dag diff --git a/src/v2/lens/cost/disj_alternative_floor_test.dag b/src/v2/test/lens_cost/disj_alternative_floor_test.dag similarity index 100% rename from src/v2/lens/cost/disj_alternative_floor_test.dag rename to src/v2/test/lens_cost/disj_alternative_floor_test.dag diff --git a/src/v2/lens/cost/disj_max_test.dag b/src/v2/test/lens_cost/disj_max_test.dag similarity index 100% rename from src/v2/lens/cost/disj_max_test.dag rename to src/v2/test/lens_cost/disj_max_test.dag diff --git a/src/v2/lens/cost/expr_refusal_test.dag b/src/v2/test/lens_cost/expr_refusal_test.dag similarity index 100% rename from src/v2/lens/cost/expr_refusal_test.dag rename to src/v2/test/lens_cost/expr_refusal_test.dag diff --git a/src/v2/lens/cost/loop_illegal_named_test.dag b/src/v2/test/lens_cost/loop_illegal_named_test.dag similarity index 100% rename from src/v2/lens/cost/loop_illegal_named_test.dag rename to src/v2/test/lens_cost/loop_illegal_named_test.dag diff --git a/src/v2/lens/cost/loop_iteration_floor_test.dag b/src/v2/test/lens_cost/loop_iteration_floor_test.dag similarity index 100% rename from src/v2/lens/cost/loop_iteration_floor_test.dag rename to src/v2/test/lens_cost/loop_iteration_floor_test.dag diff --git a/src/v2/lens/cost/loop_linear_test.dag b/src/v2/test/lens_cost/loop_linear_test.dag similarity index 100% rename from src/v2/lens/cost/loop_linear_test.dag rename to src/v2/test/lens_cost/loop_linear_test.dag diff --git a/src/v2/lens/cost/loop_unknown_test.dag b/src/v2/test/lens_cost/loop_unknown_test.dag similarity index 100% rename from src/v2/lens/cost/loop_unknown_test.dag rename to src/v2/test/lens_cost/loop_unknown_test.dag diff --git a/src/v2/lens/cost/map_linear_test.dag b/src/v2/test/lens_cost/map_linear_test.dag similarity index 100% rename from src/v2/lens/cost/map_linear_test.dag rename to src/v2/test/lens_cost/map_linear_test.dag diff --git a/src/v2/lens/cost/nested_product_test.dag b/src/v2/test/lens_cost/nested_product_test.dag similarity index 100% rename from src/v2/lens/cost/nested_product_test.dag rename to src/v2/test/lens_cost/nested_product_test.dag diff --git a/src/v2/lens/cost/p9_llvm_instruction_cost_registry_owner_test.dag b/src/v2/test/lens_cost/p9_llvm_instruction_cost_registry_owner_test.dag similarity index 100% rename from src/v2/lens/cost/p9_llvm_instruction_cost_registry_owner_test.dag rename to src/v2/test/lens_cost/p9_llvm_instruction_cost_registry_owner_test.dag diff --git a/src/v2/lens/cost/summary_span_test.dag b/src/v2/test/lens_cost/summary_span_test.dag similarity index 100% rename from src/v2/lens/cost/summary_span_test.dag rename to src/v2/test/lens_cost/summary_span_test.dag diff --git a/src/v2/lens/cost/valuation_test.dag b/src/v2/test/lens_cost/valuation_test.dag similarity index 100% rename from src/v2/lens/cost/valuation_test.dag rename to src/v2/test/lens_cost/valuation_test.dag diff --git a/src/v2/lens/coverage/discriminant_predicate_defect_key_test.dag b/src/v2/test/lens_coverage/discriminant_predicate_defect_key_test.dag similarity index 100% rename from src/v2/lens/coverage/discriminant_predicate_defect_key_test.dag rename to src/v2/test/lens_coverage/discriminant_predicate_defect_key_test.dag diff --git a/src/v2/lens/coverage/hollow_type_defect_key_test.dag b/src/v2/test/lens_coverage/hollow_type_defect_key_test.dag similarity index 100% rename from src/v2/lens/coverage/hollow_type_defect_key_test.dag rename to src/v2/test/lens_coverage/hollow_type_defect_key_test.dag diff --git a/src/v2/lens/coverage/near_miss_vacuous_not_parallel_test.dag b/src/v2/test/lens_coverage/near_miss_vacuous_not_parallel_test.dag similarity index 100% rename from src/v2/lens/coverage/near_miss_vacuous_not_parallel_test.dag rename to src/v2/test/lens_coverage/near_miss_vacuous_not_parallel_test.dag diff --git a/src/v2/lens/coverage/parallel_authority_defect_key_test.dag b/src/v2/test/lens_coverage/parallel_authority_defect_key_test.dag similarity index 100% rename from src/v2/lens/coverage/parallel_authority_defect_key_test.dag rename to src/v2/test/lens_coverage/parallel_authority_defect_key_test.dag diff --git a/src/v2/lens/coverage/sibling_degenerate_not_hollow_test.dag b/src/v2/test/lens_coverage/sibling_degenerate_not_hollow_test.dag similarity index 100% rename from src/v2/lens/coverage/sibling_degenerate_not_hollow_test.dag rename to src/v2/test/lens_coverage/sibling_degenerate_not_hollow_test.dag diff --git a/src/v2/lens/dependency_fidelity_test.dag b/src/v2/test/lens_dependency_fidelity/dependency_fidelity_test.dag similarity index 100% rename from src/v2/lens/dependency_fidelity_test.dag rename to src/v2/test/lens_dependency_fidelity/dependency_fidelity_test.dag diff --git a/src/v2/lens/determinism/reach_witness_test.dag b/src/v2/test/lens_determinism/reach_witness_test.dag similarity index 100% rename from src/v2/lens/determinism/reach_witness_test.dag rename to src/v2/test/lens_determinism/reach_witness_test.dag diff --git a/src/v2/lens/disposition_redundancy_test.dag b/src/v2/test/lens_disposition_redundancy/disposition_redundancy_test.dag similarity index 100% rename from src/v2/lens/disposition_redundancy_test.dag rename to src/v2/test/lens_disposition_redundancy/disposition_redundancy_test.dag diff --git a/src/v2/lens/doc_reachability_test.dag b/src/v2/test/lens_doc_reachability/doc_reachability_test.dag similarity index 100% rename from src/v2/lens/doc_reachability_test.dag rename to src/v2/test/lens_doc_reachability/doc_reachability_test.dag diff --git a/src/v2/lens/effect/effect_depends_on.dag b/src/v2/test/lens_effect/effect_depends_on.dag similarity index 100% rename from src/v2/lens/effect/effect_depends_on.dag rename to src/v2/test/lens_effect/effect_depends_on.dag diff --git a/src/v2/lens/enforcement/gate_test.dag b/src/v2/test/lens_enforcement/gate_test.dag similarity index 100% rename from src/v2/lens/enforcement/gate_test.dag rename to src/v2/test/lens_enforcement/gate_test.dag diff --git a/src/v2/lens/fact_density/computation_not_type_carrier_test.dag b/src/v2/test/lens_fact_density/computation_not_type_carrier_test.dag similarity index 100% rename from src/v2/lens/fact_density/computation_not_type_carrier_test.dag rename to src/v2/test/lens_fact_density/computation_not_type_carrier_test.dag diff --git a/src/v2/lens/fact_density/conj_positional_only_no_fact_test.dag b/src/v2/test/lens_fact_density/conj_positional_only_no_fact_test.dag similarity index 100% rename from src/v2/lens/fact_density/conj_positional_only_no_fact_test.dag rename to src/v2/test/lens_fact_density/conj_positional_only_no_fact_test.dag diff --git a/src/v2/lens/fact_density/fact_bundle_compile_lens_passes_test.dag b/src/v2/test/lens_fact_density/fact_bundle_compile_lens_passes_test.dag similarity index 100% rename from src/v2/lens/fact_density/fact_bundle_compile_lens_passes_test.dag rename to src/v2/test/lens_fact_density/fact_bundle_compile_lens_passes_test.dag diff --git a/src/v2/lens/fact_density/fact_bundle_named_test.dag b/src/v2/test/lens_fact_density/fact_bundle_named_test.dag similarity index 100% rename from src/v2/lens/fact_density/fact_bundle_named_test.dag rename to src/v2/test/lens_fact_density/fact_bundle_named_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_blocked_in_run_gates_test.dag b/src/v2/test/lens_fact_density/hollow_alias_blocked_in_run_gates_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_blocked_in_run_gates_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_blocked_in_run_gates_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag b/src/v2/test/lens_fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_blocked_via_always_required_lenses_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_compile_lens_rejects_test.dag b/src/v2/test/lens_fact_density/hollow_alias_compile_lens_rejects_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_compile_lens_rejects_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_compile_lens_rejects_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_nested_rejected_test.dag b/src/v2/test/lens_fact_density/hollow_alias_nested_rejected_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_nested_rejected_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_nested_rejected_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_no_fact_test.dag b/src/v2/test/lens_fact_density/hollow_alias_no_fact_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_no_fact_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_no_fact_test.dag diff --git a/src/v2/lens/fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag b/src/v2/test/lens_fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag similarity index 100% rename from src/v2/lens/fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag rename to src/v2/test/lens_fact_density/hollow_alias_vtc_empty_lenses_rejected_test.dag diff --git a/src/v2/lens/fact_density/kernel_ambient_bool_test.dag b/src/v2/test/lens_fact_density/kernel_ambient_bool_test.dag similarity index 100% rename from src/v2/lens/fact_density/kernel_ambient_bool_test.dag rename to src/v2/test/lens_fact_density/kernel_ambient_bool_test.dag diff --git a/src/v2/lens/idempotency/sg_claims_test.dag b/src/v2/test/lens_idempotency/sg_claims_test.dag similarity index 100% rename from src/v2/lens/idempotency/sg_claims_test.dag rename to src/v2/test/lens_idempotency/sg_claims_test.dag diff --git a/src/v2/lens/idempotency/write_effect_test.dag b/src/v2/test/lens_idempotency/write_effect_test.dag similarity index 100% rename from src/v2/lens/idempotency/write_effect_test.dag rename to src/v2/test/lens_idempotency/write_effect_test.dag diff --git a/src/v2/lens/identical_variant_payload/sg_claims_test.dag b/src/v2/test/lens_identical_variant_payload/sg_claims_test.dag similarity index 100% rename from src/v2/lens/identical_variant_payload/sg_claims_test.dag rename to src/v2/test/lens_identical_variant_payload/sg_claims_test.dag diff --git a/src/v2/lens/inert_carrier_test.dag b/src/v2/test/lens_inert_carrier/inert_carrier_test.dag similarity index 100% rename from src/v2/lens/inert_carrier_test.dag rename to src/v2/test/lens_inert_carrier/inert_carrier_test.dag diff --git a/src/v2/lens/lifecycle_carrier/raw_prose_field_flagged_test.dag b/src/v2/test/lens_lifecycle_carrier/raw_prose_field_flagged_test.dag similarity index 100% rename from src/v2/lens/lifecycle_carrier/raw_prose_field_flagged_test.dag rename to src/v2/test/lens_lifecycle_carrier/raw_prose_field_flagged_test.dag diff --git a/src/v2/lens/mutation_adequacy_test.dag b/src/v2/test/lens_mutation_adequacy/mutation_adequacy_test.dag similarity index 100% rename from src/v2/lens/mutation_adequacy_test.dag rename to src/v2/test/lens_mutation_adequacy/mutation_adequacy_test.dag diff --git a/src/v2/lens/non_fold_residue_test.dag b/src/v2/test/lens_non_fold_residue/non_fold_residue_test.dag similarity index 100% rename from src/v2/lens/non_fold_residue_test.dag rename to src/v2/test/lens_non_fold_residue/non_fold_residue_test.dag diff --git a/src/v2/lens/ownership/resource_dependency.dag b/src/v2/test/lens_ownership/resource_dependency.dag similarity index 100% rename from src/v2/lens/ownership/resource_dependency.dag rename to src/v2/test/lens_ownership/resource_dependency.dag diff --git a/src/v2/lens/ownership/subject_roster.dag b/src/v2/test/lens_ownership/subject_roster.dag similarity index 100% rename from src/v2/lens/ownership/subject_roster.dag rename to src/v2/test/lens_ownership/subject_roster.dag diff --git a/src/v2/lens/parallelism/data_dependency_test.dag b/src/v2/test/lens_parallelism/data_dependency_test.dag similarity index 100% rename from src/v2/lens/parallelism/data_dependency_test.dag rename to src/v2/test/lens_parallelism/data_dependency_test.dag diff --git a/src/v2/lens/registry/sg_claims_test.dag b/src/v2/test/lens_registry/sg_claims_test.dag similarity index 100% rename from src/v2/lens/registry/sg_claims_test.dag rename to src/v2/test/lens_registry/sg_claims_test.dag diff --git a/src/v2/lens/structural_resolution/binds_to_resolved_test.dag b/src/v2/test/lens_structural_resolution/binds_to_resolved_test.dag similarity index 100% rename from src/v2/lens/structural_resolution/binds_to_resolved_test.dag rename to src/v2/test/lens_structural_resolution/binds_to_resolved_test.dag diff --git a/src/v2/lens/structural_resolution/claim_carrier.dag b/src/v2/test/lens_structural_resolution/claim_carrier.dag similarity index 100% rename from src/v2/lens/structural_resolution/claim_carrier.dag rename to src/v2/test/lens_structural_resolution/claim_carrier.dag diff --git a/src/v2/lens/structural_resolution/facts_lookup_miss.dag b/src/v2/test/lens_structural_resolution/facts_lookup_miss.dag similarity index 100% rename from src/v2/lens/structural_resolution/facts_lookup_miss.dag rename to src/v2/test/lens_structural_resolution/facts_lookup_miss.dag diff --git a/src/v2/lens/structural_resolution/module_import_out_of_scope.dag b/src/v2/test/lens_structural_resolution/module_import_out_of_scope.dag similarity index 100% rename from src/v2/lens/structural_resolution/module_import_out_of_scope.dag rename to src/v2/test/lens_structural_resolution/module_import_out_of_scope.dag diff --git a/src/v2/lens/structural_resolution/unbound_symbol_at_use.dag b/src/v2/test/lens_structural_resolution/unbound_symbol_at_use.dag similarity index 100% rename from src/v2/lens/structural_resolution/unbound_symbol_at_use.dag rename to src/v2/test/lens_structural_resolution/unbound_symbol_at_use.dag diff --git a/src/v2/lens/structural_resolution/unresolved_infer_witness.dag b/src/v2/test/lens_structural_resolution/unresolved_infer_witness.dag similarity index 100% rename from src/v2/lens/structural_resolution/unresolved_infer_witness.dag rename to src/v2/test/lens_structural_resolution/unresolved_infer_witness.dag diff --git a/src/v2/lens/synthesis/constant_not_dominated_by_linear_test.dag b/src/v2/test/lens_synthesis/constant_not_dominated_by_linear_test.dag similarity index 100% rename from src/v2/lens/synthesis/constant_not_dominated_by_linear_test.dag rename to src/v2/test/lens_synthesis/constant_not_dominated_by_linear_test.dag diff --git a/src/v2/lens/synthesis/exponential_dominates_polynomial_test.dag b/src/v2/test/lens_synthesis/exponential_dominates_polynomial_test.dag similarity index 100% rename from src/v2/lens/synthesis/exponential_dominates_polynomial_test.dag rename to src/v2/test/lens_synthesis/exponential_dominates_polynomial_test.dag diff --git a/src/v2/lens/synthesis/factorial_dominates_exponential_test.dag b/src/v2/test/lens_synthesis/factorial_dominates_exponential_test.dag similarity index 100% rename from src/v2/lens/synthesis/factorial_dominates_exponential_test.dag rename to src/v2/test/lens_synthesis/factorial_dominates_exponential_test.dag diff --git a/src/v2/lens/synthesis/linear_not_dominated_by_polynomial_test.dag b/src/v2/test/lens_synthesis/linear_not_dominated_by_polynomial_test.dag similarity index 100% rename from src/v2/lens/synthesis/linear_not_dominated_by_polynomial_test.dag rename to src/v2/test/lens_synthesis/linear_not_dominated_by_polynomial_test.dag diff --git a/src/v2/lens/synthesis/polynomial_dominates_linear_test.dag b/src/v2/test/lens_synthesis/polynomial_dominates_linear_test.dag similarity index 100% rename from src/v2/lens/synthesis/polynomial_dominates_linear_test.dag rename to src/v2/test/lens_synthesis/polynomial_dominates_linear_test.dag diff --git a/src/v2/lens/synthesis/synthesis_gap_information_theoretic_test.dag b/src/v2/test/lens_synthesis/synthesis_gap_information_theoretic_test.dag similarity index 100% rename from src/v2/lens/synthesis/synthesis_gap_information_theoretic_test.dag rename to src/v2/test/lens_synthesis/synthesis_gap_information_theoretic_test.dag diff --git a/src/v2/lens/synthesis/synthesis_gap_polynomial_test.dag b/src/v2/test/lens_synthesis/synthesis_gap_polynomial_test.dag similarity index 100% rename from src/v2/lens/synthesis/synthesis_gap_polynomial_test.dag rename to src/v2/test/lens_synthesis/synthesis_gap_polynomial_test.dag diff --git a/src/v2/lens/synthesis/synthesis_no_technique_diagnostic_test.dag b/src/v2/test/lens_synthesis/synthesis_no_technique_diagnostic_test.dag similarity index 100% rename from src/v2/lens/synthesis/synthesis_no_technique_diagnostic_test.dag rename to src/v2/test/lens_synthesis/synthesis_no_technique_diagnostic_test.dag diff --git a/src/v2/lens/table_decision_tree/sg_claims_test.dag b/src/v2/test/lens_table_decision_tree/sg_claims_test.dag similarity index 100% rename from src/v2/lens/table_decision_tree/sg_claims_test.dag rename to src/v2/test/lens_table_decision_tree/sg_claims_test.dag diff --git a/src/v2/lens/testgen/dag_input_surface_test.dag b/src/v2/test/lens_testgen/dag_input_surface_test.dag similarity index 100% rename from src/v2/lens/testgen/dag_input_surface_test.dag rename to src/v2/test/lens_testgen/dag_input_surface_test.dag diff --git a/src/v2/lens/testgen/generator_provenance_test.dag b/src/v2/test/lens_testgen/generator_provenance_test.dag similarity index 100% rename from src/v2/lens/testgen/generator_provenance_test.dag rename to src/v2/test/lens_testgen/generator_provenance_test.dag diff --git a/src/v2/lens/testgen/shadow_ci_receipt_test.dag b/src/v2/test/lens_testgen/shadow_ci_receipt_test.dag similarity index 100% rename from src/v2/lens/testgen/shadow_ci_receipt_test.dag rename to src/v2/test/lens_testgen/shadow_ci_receipt_test.dag diff --git a/src/v2/lens/unit_modeling/bitwidth_flat_scalar_flagged_test.dag b/src/v2/test/lens_unit_modeling/bitwidth_flat_scalar_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/bitwidth_flat_scalar_flagged_test.dag rename to src/v2/test/lens_unit_modeling/bitwidth_flat_scalar_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/bitwidth_modeled_passes_test.dag b/src/v2/test/lens_unit_modeling/bitwidth_modeled_passes_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/bitwidth_modeled_passes_test.dag rename to src/v2/test/lens_unit_modeling/bitwidth_modeled_passes_test.dag diff --git a/src/v2/lens/unit_modeling/coordinate_index_not_flagged_test.dag b/src/v2/test/lens_unit_modeling/coordinate_index_not_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/coordinate_index_not_flagged_test.dag rename to src/v2/test/lens_unit_modeling/coordinate_index_not_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/electrical_blocked_pending_flagged_test.dag b/src/v2/test/lens_unit_modeling/electrical_blocked_pending_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/electrical_blocked_pending_flagged_test.dag rename to src/v2/test/lens_unit_modeling/electrical_blocked_pending_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/flat_scalar_unit_leaf_flagged_test.dag b/src/v2/test/lens_unit_modeling/flat_scalar_unit_leaf_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/flat_scalar_unit_leaf_flagged_test.dag rename to src/v2/test/lens_unit_modeling/flat_scalar_unit_leaf_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/label_version_not_flagged_test.dag b/src/v2/test/lens_unit_modeling/label_version_not_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/label_version_not_flagged_test.dag rename to src/v2/test/lens_unit_modeling/label_version_not_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/modeled_unit_field_admitted_via_always_required_lenses_test.dag b/src/v2/test/lens_unit_modeling/modeled_unit_field_admitted_via_always_required_lenses_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/modeled_unit_field_admitted_via_always_required_lenses_test.dag rename to src/v2/test/lens_unit_modeling/modeled_unit_field_admitted_via_always_required_lenses_test.dag diff --git a/src/v2/lens/unit_modeling/modeled_unit_field_passes_test.dag b/src/v2/test/lens_unit_modeling/modeled_unit_field_passes_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/modeled_unit_field_passes_test.dag rename to src/v2/test/lens_unit_modeling/modeled_unit_field_passes_test.dag diff --git a/src/v2/lens/unit_modeling/novel_unit_flagged_test.dag b/src/v2/test/lens_unit_modeling/novel_unit_flagged_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/novel_unit_flagged_test.dag rename to src/v2/test/lens_unit_modeling/novel_unit_flagged_test.dag diff --git a/src/v2/lens/unit_modeling/unit_modeling_blocked_via_always_required_lenses_test.dag b/src/v2/test/lens_unit_modeling/unit_modeling_blocked_via_always_required_lenses_test.dag similarity index 100% rename from src/v2/lens/unit_modeling/unit_modeling_blocked_via_always_required_lenses_test.dag rename to src/v2/test/lens_unit_modeling/unit_modeling_blocked_via_always_required_lenses_test.dag diff --git a/src/v2/lens/unused_parameters/binds_to_edge.dag b/src/v2/test/lens_unused_parameters/binds_to_edge.dag similarity index 100% rename from src/v2/lens/unused_parameters/binds_to_edge.dag rename to src/v2/test/lens_unused_parameters/binds_to_edge.dag diff --git a/src/v2/lens/unused_parameters/non_use_edges.dag b/src/v2/test/lens_unused_parameters/non_use_edges.dag similarity index 100% rename from src/v2/lens/unused_parameters/non_use_edges.dag rename to src/v2/test/lens_unused_parameters/non_use_edges.dag diff --git a/src/v2/lens/unused_parameters/rollup_unused_declaration.dag b/src/v2/test/lens_unused_parameters/rollup_unused_declaration.dag similarity index 100% rename from src/v2/lens/unused_parameters/rollup_unused_declaration.dag rename to src/v2/test/lens_unused_parameters/rollup_unused_declaration.dag diff --git a/src/v2/lens/vacuity_test.dag b/src/v2/test/lens_vacuity/vacuity_test.dag similarity index 100% rename from src/v2/lens/vacuity_test.dag rename to src/v2/test/lens_vacuity/vacuity_test.dag diff --git a/src/v2/lens/visibility_test.dag b/src/v2/test/lens_visibility/visibility_test.dag similarity index 100% rename from src/v2/lens/visibility_test.dag rename to src/v2/test/lens_visibility/visibility_test.dag diff --git a/src/v2/lens/wiring_liveness_corpus_test.dag b/src/v2/test/lens_wiring_liveness/wiring_liveness_corpus_test.dag similarity index 100% rename from src/v2/lens/wiring_liveness_corpus_test.dag rename to src/v2/test/lens_wiring_liveness/wiring_liveness_corpus_test.dag diff --git a/src/v2/lens/wiring_liveness_preflight_test.dag b/src/v2/test/lens_wiring_liveness/wiring_liveness_preflight_test.dag similarity index 100% rename from src/v2/lens/wiring_liveness_preflight_test.dag rename to src/v2/test/lens_wiring_liveness/wiring_liveness_preflight_test.dag diff --git a/src/v2/lens/wiring_liveness_test.dag b/src/v2/test/lens_wiring_liveness/wiring_liveness_test.dag similarity index 100% rename from src/v2/lens/wiring_liveness_test.dag rename to src/v2/test/lens_wiring_liveness/wiring_liveness_test.dag diff --git a/src/v2/compiler/manual/retry_eagain_bash.dag b/src/v2/test/manual/retry_eagain_bash.dag similarity index 100% rename from src/v2/compiler/manual/retry_eagain_bash.dag rename to src/v2/test/manual/retry_eagain_bash.dag diff --git a/src/v2/std/nat_semiring/rung_0_to_2_three_targets.dag b/src/v2/test/nat_semiring/rung_0_to_2_three_targets.dag similarity index 100% rename from src/v2/std/nat_semiring/rung_0_to_2_three_targets.dag rename to src/v2/test/nat_semiring/rung_0_to_2_three_targets.dag diff --git a/src/v2/extdeps/runtimes/effect_io_handler_claims_test.dag b/src/v2/test/runtimes/effect_io_handler_claims_test.dag similarity index 100% rename from src/v2/extdeps/runtimes/effect_io_handler_claims_test.dag rename to src/v2/test/runtimes/effect_io_handler_claims_test.dag diff --git a/src/v2/extdeps/runtimes/effect_io_host_mode_test.dag b/src/v2/test/runtimes/effect_io_host_mode_test.dag similarity index 100% rename from src/v2/extdeps/runtimes/effect_io_host_mode_test.dag rename to src/v2/test/runtimes/effect_io_host_mode_test.dag diff --git a/src/v2/std/reducible_test.dag b/src/v2/test/std/reducible_test.dag similarity index 100% rename from src/v2/std/reducible_test.dag rename to src/v2/test/std/reducible_test.dag diff --git a/src/v2/std/timeseries_signal_passives_test.dag b/src/v2/test/std/timeseries_signal_passives_test.dag similarity index 100% rename from src/v2/std/timeseries_signal_passives_test.dag rename to src/v2/test/std/timeseries_signal_passives_test.dag diff --git a/src/v2/std/dependents/dependents_test.dag b/src/v2/test/std_dependents/dependents_test.dag similarity index 100% rename from src/v2/std/dependents/dependents_test.dag rename to src/v2/test/std_dependents/dependents_test.dag diff --git a/src/v2/std/grounding/runtime_value_node_projection_test.dag b/src/v2/test/std_grounding/runtime_value_node_projection_test.dag similarity index 100% rename from src/v2/std/grounding/runtime_value_node_projection_test.dag rename to src/v2/test/std_grounding/runtime_value_node_projection_test.dag diff --git a/src/v2/std/grounding/value_carrier_laws_test.dag b/src/v2/test/std_grounding/value_carrier_laws_test.dag similarity index 100% rename from src/v2/std/grounding/value_carrier_laws_test.dag rename to src/v2/test/std_grounding/value_carrier_laws_test.dag diff --git a/src/v2/std/model_core/bool_fact_lookup_test.dag b/src/v2/test/std_model_core/bool_fact_lookup_test.dag similarity index 100% rename from src/v2/std/model_core/bool_fact_lookup_test.dag rename to src/v2/test/std_model_core/bool_fact_lookup_test.dag diff --git a/src/v2/std/text/carrier_claims_test.dag b/src/v2/test/std_text/carrier_claims_test.dag similarity index 100% rename from src/v2/std/text/carrier_claims_test.dag rename to src/v2/test/std_text/carrier_claims_test.dag diff --git a/src/v2/workflow/glob_discovery_law.dag b/src/v2/test/workflow/glob_discovery_law.dag similarity index 100% rename from src/v2/workflow/glob_discovery_law.dag rename to src/v2/test/workflow/glob_discovery_law.dag diff --git a/src/v2/workflow/lens_discrimination_family_eval_test.dag b/src/v2/test/workflow/lens_discrimination_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_discrimination_family_eval_test.dag rename to src/v2/test/workflow/lens_discrimination_family_eval_test.dag diff --git a/src/v2/workflow/lens_effect_family_eval_test.dag b/src/v2/test/workflow/lens_effect_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_effect_family_eval_test.dag rename to src/v2/test/workflow/lens_effect_family_eval_test.dag diff --git a/src/v2/workflow/lens_idempotency_family_eval_test.dag b/src/v2/test/workflow/lens_idempotency_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_idempotency_family_eval_test.dag rename to src/v2/test/workflow/lens_idempotency_family_eval_test.dag diff --git a/src/v2/workflow/lens_leaf_model_verification_family_eval_test.dag b/src/v2/test/workflow/lens_leaf_model_verification_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_leaf_model_verification_family_eval_test.dag rename to src/v2/test/workflow/lens_leaf_model_verification_family_eval_test.dag diff --git a/src/v2/workflow/lens_ownership_family_eval_test.dag b/src/v2/test/workflow/lens_ownership_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_ownership_family_eval_test.dag rename to src/v2/test/workflow/lens_ownership_family_eval_test.dag diff --git a/src/v2/workflow/lens_parallelism_family_eval_test.dag b/src/v2/test/workflow/lens_parallelism_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_parallelism_family_eval_test.dag rename to src/v2/test/workflow/lens_parallelism_family_eval_test.dag diff --git a/src/v2/workflow/lens_subsumption_family_eval_test.dag b/src/v2/test/workflow/lens_subsumption_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_subsumption_family_eval_test.dag rename to src/v2/test/workflow/lens_subsumption_family_eval_test.dag diff --git a/src/v2/workflow/lens_synthesis_family_eval_test.dag b/src/v2/test/workflow/lens_synthesis_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_synthesis_family_eval_test.dag rename to src/v2/test/workflow/lens_synthesis_family_eval_test.dag diff --git a/src/v2/workflow/lens_unused_parameters_family_eval_test.dag b/src/v2/test/workflow/lens_unused_parameters_family_eval_test.dag similarity index 100% rename from src/v2/workflow/lens_unused_parameters_family_eval_test.dag rename to src/v2/test/workflow/lens_unused_parameters_family_eval_test.dag