Repository navigation
Fix the unparseable rung-drop record, and start the cli_run.rs decomposition (13 clusters to named submodules) - #9648
Merged
Conversation
The wall_deadline_shared_fill_attribution_stall record landed without its closing brace, so every gunbc run over the dag root refused at module index (expected expression, found Eq) -- the same collided merge that duplicated the cli_run.rs definitions. With the brace, the documented converge actuator entry runs end-to-end again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… facts, no cwd switch; fast controls were panics Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…(pure code motion) test_migration, compile_clean, non_fold_residue, class_b_census, languages_census, external_authority, inert_carrier — 107 items, ~2.1k lines. Mechanics: each cluster becomes a cli_run/ submodule with 'use super::*' back into the parent plus the parent's use-header; the parent re-exports 'pub(crate) use <mod>::*' so every existing path keeps resolving. Private moved items widen to pub(crate), which rewraps a few signatures under rustfmt. No semantic change; build-verified. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…aph, declared_refs, census_heads (pure code motion) 89 items, ~2.1k lines. Bin-consumed pub fns get explicit pub use re-exports (the pub(crate) glob does not cross the lib/bin crate boundary). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…nterface lints; CI sets -D warnings) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
…into the split modules The two conflict regions were regions this branch had moved: the compile_dag_* emit-check family (unchanged on main — kept in emit_host, const takes main's new dag/gunbc/ci/ path) and the witness-admission source scan (main's updated witness_admission_explicit_consumer_keys ported into witness_gates verbatim). Verified: no submodule carries a dag path literal that no longer exists on disk. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…ead_decode, active_workset (pure code motion) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Both sides of the merge fixed #9612's unclosed record identically; the auto- merge kept both hunks' markers. Smoke-verified: the converge actuator (now at dag/gunbc/repo/ after the filename reorg) compiles and executes again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… ~2.5k lines, pure code motion) The pool-tax subject now has its own reviewable home: module path index, module-graph facts, import closures, the process shared index and resolve store (thread_local statics widened to pub(crate)), typed-module cache, multi-entry index shell, resolve stage/span accounting. Bin-consumed fns get explicit pub use; two cache types widened for the private-interface lint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…xecution (49 items, ~4.8k lines, pure code motion) run_required_floor, claim evaluation/measurement, discovery corpus, diff observation, prepared-subject inventory, resource sampling, cgroup envelope, route-gap expectations, floor stream/verbosity plumbing. Same recipe: bin- consumed fns re-exported pub; two expectation/edit types widened for the private-interface lint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… single pre-registered execution test Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…ntics_witness for the new TypeEnv field Conflicts were the usual moved-region kind: compile_clean_diagnostic_histogram_key and census_heads_module_node/_module_item changed on main and are ported verbatim into their submodules (visibility restored to pub(crate)). Separately, main @ 0ef6f7c (#9656) does not build: it added TypeEnv.unit_variant_index without updating the six TypeEnv literals in bin/infer_semantics_witness.rs (the bins aren't gated while CI is red — third ungated-merge breakage in two days). Fixed forward here with empty-index initializers, matching empty_type_env's shape. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…the string literal it was authored as Bisect pinned main's runtime failure (trim expects a string, got Null on the converge actuator) to 655f82a (#9344). Mechanism: the rewritten parse_optional_from_key built the from_key property's value node with NoExprData (key carried only as a node NAME), and the new field_to_child_node passes parsed properties through instead of re-materializing them — but the interpreter's extract_from_key accepts only ExprLiteral{LitStr}, so every 'output field from "channel"' mapping silently missed, the output key fell back to the field name, and effect-result fields decoded as Null (git.Core.ConfigLocalGetInRepo: .success survived by name, .value did not). The from token IS a string literal in the grammar (ShLitStr), so the fix makes the property value carry ExprLiteral{LitStr{key}} at the one construction site in v1.compiler.parse parse_optional_from_key; the mirror is regenerated via --required-regen (surface drift resolved by installing the candidate). Smoke: the converge actuator executes end-to-end again. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Aug 29, 2026
…o cli_run/required_floor_runner.rs
briansrls
pushed a commit
that referenced
this pull request
Aug 29, 2026
…unit_variant_index after #9656 (#9662) * Unbreak main: drop the JsSite artifact rows whose authority #9641 deleted, and give the six witness-bin TypeEnv initializers the unit_variant_index #9656 added Two integration collisions between independently green PRs: - #9641 deleted dag/examples/js_site but gunbc.generated_artifact and gunbc.generated_artifact_emit still imported it, so the whole-tree strict resolve refused and every floor on main has been red since. - #9656 added TypeEnv.unit_variant_index; infer_semantics_witness.rs builds six TypeEnvs by hand and none carried it, so --bins failed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The lib's own unit tests build one more TypeEnv by hand; give it unit_variant_index too Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Drop the six duplicate unit_variant_index initializers the merge with #9648 produced * Regenerate .gitattributes: the six js_site rows projected from the deleted artifact registry entries go with them * Shrink the namespace transition roster: the 314 std->extdeps consolidation rows landed with #9641 and now refuse every PR as stale --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
6 tasks
briansrls
added a commit
that referenced
this pull request
Aug 29, 2026
…e prepares the roster's closure, not the tree; rust unit tests in their own job; the un-required phases declared as a rung drop (#9663) * Unbreak main: drop the JsSite artifact rows whose authority #9641 deleted, and give the six witness-bin TypeEnv initializers the unit_variant_index #9656 added Two integration collisions between independently green PRs: - #9641 deleted dag/examples/js_site but gunbc.generated_artifact and gunbc.generated_artifact_emit still imported it, so the whole-tree strict resolve refused and every floor on main has been red since. - #9656 added TypeEnv.unit_variant_index; infer_semantics_witness.rs builds six TypeEnvs by hand and none carried it, so --bins failed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The lib's own unit tests build one more TypeEnv by hand; give it unit_variant_index too Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Required CI is the compiler floor: a static gate roster, prepared as its own import closure, with the other four phases and the product witnesses moved off the merge path Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Drop the six duplicate unit_variant_index initializers the merge with #9648 produced * Drop the six duplicate unit_variant_index initializers the merge with #9648 produced * Regenerate .gitattributes: the six js_site rows projected from the deleted artifact registry entries go with them * Regenerate the four projections of this change: witnesses.yml (probe and all-bins steps gone, rust-unit-tests job added), DESIGN.md and design-ledgers.md (the rung-drop row), .gitattributes (js_site rows gone) * Restore the lib-test TypeEnv initializer's unit_variant_index (lost when the merge took main's cli_run.rs wholesale) * The gate closure is the loader's both-closure (imports + reference edges to a fixpoint), not the import headers: stripped modules reach their providers by reference, and the header walk left 1,190 names unresolved * Shrink the namespace transition roster: the 314 std->extdeps consolidation rows landed with #9641 and now refuse every PR as stale * Build the entry index once for both gate closures (it is the expensive part: ~75-110s per build on the corpus) * Gate closure includes containment ancestors to a fixpoint: a module importing only a child of the declaring module still binds the parent's declarations * The floor's policy module is always a closure seed: its rosters are evaluated in a frame over the prepared subject * The reference-closure index is keyed by the prepared subject's digest, bounded to the two subjects a floor process prepares by design — the gate's policy-closure preparation and the gate closure are two subjects in one process, and a once-per-process index refused the second (ReferenceIndexSubjectChanged built_for_modules=47 observed_modules=1952, CI and srv2 at 066725c) The old check keyed on module COUNT: two subjects of equal size would have shared one index silently. The new one keys on `subject_digest`, so the index a scope consults was built from the graph that scope is over, by construction. The population is bounded by FLOOR_PREPARED_SUBJECTS_PER_PROCESS = 2 (policy closure, gate closure) — a third distinct subject still refuses with the same cause, because a subject per claim is the corpus walk per row the index exists to avoid. Evidence: srv2 rerun of `claim_executor --required-ci --required-lane witnesses` at this tree builds the 47-module policy index (subject=09966adcd218af0e) and proceeds into the 1,954-module gate preparation instead of refusing at claim scope. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The floor's own runtime authorities are explicit closure seeds: the gate-bounded subject refused at output-policy install because resolve_channel_policy had only ever resolved by pool-membership coincidence — the flat bare-name channel found gunbc.output_policy because the whole corpus was loaded, not because the policy closure references it REQUIRED_FLOOR_RUNTIME_AUTHORITY_MODULES names every module the floor's Rust evaluates by name outside the gate roster: the policy module (its rosters), v2.workflow.floor_naming_hygiene (qualified evaluations), and gunbc.output_policy (bare, from install_output_policy_in). All three are seeds of the gate closure; a new by-name evaluation adds its module here or refuses at its own call site. Measured: the first gate-bounded run (srv2, at 2d5502a) got past both reference-closure indexes and refused with "no declaration named 'resolve_channel_policy' in this execution's loaded index". Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * A by-name evaluation of a module's declaration runs in THAT module's scope: the floor installed the output policy and the naming-hygiene predicates from the policy module's frame, which reached gunbc.output_policy only by the accident of the whole-tree reference closure — under the gate-bounded subject the module was loaded and the name still refused floor_authority_frame(prepared, module) builds a hermetic frame over one module's exact claim scope. install_output_policy_in now receives the frame over gunbc.output_policy; floor_barren_test_sidecars the one over v2.workflow.floor_naming_hygiene. The policy module's frame keeps only the policy module's own rosters. Measured (srv2, lanes 5 and 6): with gunbc.output_policy present in the 1,954-module subject — the seeds changed the seed count 906 -> 908 and the closure not at all — resolve_channel_policy still refused as "no declaration named ... in this execution's loaded index". The scope, not the subject, was the coincidence. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The floor's rosters are joined only over identities inside the required gate — an enrolled identity whose module the gate never loads is withheld with the same accounting as cost-debt withholding, not refused as stale; and two modules that reached rust_target_model_staging by bare reference now import it, because the loader follows bare references only for import-free modules while the claim scope follows all of them Measured on the first gate-bounded fold (srv2 lane 7, CI at 006b0ef): ExpectedRedIdentityDidNotExecute count=39, every row in a module outside the gate roster; and v2.test.lens_vacuity.vacuity_test x5 ERROR no-such-function `rust_target_model_staging`, reproduced standalone with `gunbc run --entry src/v2/test/lens_vacuity/vacuity_test.dag`. The loader's both-closure (build_both_closure_edge_index) skips the bare scan for any source that declares import lines, so rung_3_4_common (one import) and leaf_model_verification's bare edge to v2.extdeps.languages.rust was never followed; under the whole-tree subject the flat channel found it anyway. The import is the form 10 of the 12 sibling callers already use; the loader/scope divergence is recorded in the PR. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The gate closure follows bare cross-module references from EVERY module, with the loader's own scanner, to a joint fixpoint with containment ancestors — the loader's both-closure bare-scans only import-free sources, while the claim scope the fold builds over the subject follows bare references from all of them; and route-gap expectations located outside the gate are withheld like the roster rows they join Measured 2026-08-29 on srv2: with the gate subject, `gunbc run` of v2.test.lens_vacuity.vacuity_test refused no-such-function `rust_target_model_staging`, then `eval_context` after the first was imported — one absent module per run, because rung_3_4_common (one import line) and leaf_model_verification reach them by bare reference and build_both_closure_edge_index skips the bare scan for any source that declares an import. The fixpoint reuses bare_reference_pull_paths_for_source, so the relation is the loader's and not a second scanner; the count of modules pulled this way is printed on the gate-closure line. Lane 8 (srv2) then refused `floor_route_gap_expectations: located identity is absent from derived roster` for an identity whose module is outside the gate: the roster had its outside-gate rows withheld and the expectations had not. Both sides now withhold by the same predicate, counted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Cost-debt rows outside the required gate are withheld from the staleness join, route-gap expectations honour cost-debt withholding, and emit_on_demand_classical_not_native_one_build_holds moves to the cost-debt roster — it is budget-refused before it reaches the host effect its route-gap enrollment expects, on both hosts Measured on the first complete gate-bounded fold (srv2 lane 10 and CI at e8effe8, identical): verdict=FloorRefused with unexpected_failures=0 — no claim inside the gate fails — and two bookkeeping refusals: 122 STALE-COST-DEBT rows, every one in a module the gate never loads, and one STALE-ROUTE-GAP row whose claim ran past its CPU ceiling before reaching the effect. The first is the same out-of-scope population the expected-red and route-gap joins already withhold, now counted the same way. The second is a real cost debt (floor_cost_debt already records this claim at 502 -> 2374 ms), and cost debt wins over route-gap enrollment by the roster's own rule; the expectations decode now treats a cost-debt-withheld identity as dormant rather than absent. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Two lens_module_gate_witness rows leave the expected-red roster: under the gate-bounded subject both PASS on CI and on srv2, and the floor refuses a passing enrollment as STALE-QUARANTINE Measured at 1f4bda9 (CI) and srv2 lane 12: verdict=FloorRefused with unexpected_failures=0 and exactly these two STALE-QUARANTINE rows on CI. Both are "live" claims whose question ranges over the loaded corpus; under the gate closure that corpus is 2,021 modules rather than 4,260, and the population they were red on is outside it. That is a narrowing of what the claim observes, stated here rather than hidden: the whole-corpus receipts run is where the wider question is asked again. srv2 additionally passes four emit_host_* rows that stay red on the required host; those stay enrolled — CI is the oracle for the required gate. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * Eleven claims interrupted before verdict on the gate-bounded subject join the cost-debt roster as proven chunk 12 — the same eleven on the GitHub runner and on srv2, run after run At 92cc92e the floor reports verdict=FloorRefused with unexpected_failures=0, no stale rows, no now-passing rows, and eleven INTERRUPTED-BEFORE-VERDICT identities (cost_coverage_witness x3, loaded_carrier_receipts x3, lens_closure_question_zero_holds_live, green_control_sanctioned_reader_body_not_flagged, same_grammar_parse_ingest_bridge_holds, kotlin_grammar_parse_accepted, nominal_distinct_control_compiles_ok). The set is identical at e8effe8 and 1f4bda9 on CI and in srv2 lane 12, so it is a property of the subject, not of host load: on the gate closure these claims first-touch artifacts the whole-tree fold had warmed before reaching them. Declared here as the roster's own containment for a cost the ceiling cannot hold; the exit is the warm, as the roster's header states. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * lens_module_gate_holds_live joins cost-debt chunk 12: it was interrupted at 1076ms the run after its sibling was withheld, because the 1.07s pool-root module_path_index fill is billed to whichever consumer runs first CI 0829ad8: verdict=FloorRefused, unexpected_failures=0, one INTERRUPTED-BEFORE-VERDICT row. The claim-cost receipt reads budget_interrupted 1076ms for it and `[floor-shared-fill] cache=module_path_index key=.../src/v2/lens fill_ms=1070 paid_by=...lens_module_gate_holds_live consumer_claims=1`; at 92cc92e the same fill was paid by lens_closure_question_zero_holds_live (consumer_claims=2) and this claim passed. The index is keyed on a pool root the decl_facts seam asks for at claim time, so preparation cannot warm it ahead; with both consumers withheld nothing pays it. The roster's own header names the warm as the exit. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The pool-root module_path_index for src/v2/lens is warmed in preparation by evaluating the declared producer once in its own module's scope — the 1.07s fill was a positional bill that interrupted a different lens_module_gate_witness live claim in each of three consecutive runs — and the two fill-only rows leave cost-debt chunk 12 CI 92cc92e, 0829ad8, 154fb1f: each run's single INTERRUPTED-BEFORE-VERDICT row was the next `lens_module_gate_witness` live claim in evaluation order, at 1068–1252ms, with the claim-cost receipt and `[floor-shared-fill] cache=module_path_index key=.../src/v2/lens` naming that claim as the payer. The witness-roots warm cannot reach a per-pool-root key; this warm evaluates `v2.lens.registry.completeness.lens_registry_completeness_live_facts` in that module's frame, so the root comes from `lens_registry_completeness_pool_roots` and the key is the consumers' by construction. Adjudicated with the other preparation warms as `ModulePathIndexBuild/lens-pool-roots`; skipped (printed) when the subject does not carry the producer; a producer that fails to evaluate refuses. The two rows whose entire cost was this fill leave chunk 12, as the roster header says they must once the warm exists. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * lens_closure_question_zero_holds_live leaves the expected-red roster: with the src/v2/lens pool-root index warmed in preparation it passes, as its two siblings did once they stopped paying that fill srv2 lane 13 at 8ad4091: `[floor-shared-fill] cache=module_path_index key=.../src/v2/lens paid_by=<outside-fold> consumer_claims=3`, no lens claim interrupted, and STALE-QUARANTINE for this row — the same row that was red only while it paid the fill (CI 92cc92e). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The four bootstrap_footprint_anchor claims join cost-debt chunk 12: 474–505ms CPU on three consecutive CI runs with no fill billed to them, so the 500ms ceiling decides them run by run CI f462bc9: planned=executed=2834, passed=2754, known_red_held=27, failed=0, no stale rows, interrupted_before_verdict=4 — these four, at 502–505ms. At 154fb1f the same four completed at 487–504ms and at 0829ad8 at 474–485ms; the run-to-run spread is the runner slot, not the claim. The gate did not change their cost — nothing in the shared-fill attribution names them — so the disposition is the roster's, not a ceiling change: withheld as declared debt until the host-load row lands. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The rust-unit-tests job runs the unit population: the lib tests that prepare or build over the live tree carry a live-corpus ignore reason and leave the required run, and the rot the first-ever `cargo test` exposed is repaired at its authorities, not hidden `cargo test -p v1-compiler --lib` had never run in CI. Its first run (33238828500) was cancelled by its own 60-minute timeout with 204 of 682 tests finished, because ~126 of the "unit" tests each build a fresh multi-entry index over `src/v2`+`dag` (4,260 modules; ~197 single-thread minutes on srv2 under nextest, 97 tests over 60 s, `self_compile_all_modules` alone 505 s), and the runner executes them serially. Those tests now carry `#[ignore = "live-corpus: ..."]` — the crate's existing `manual:` convention, one class, declared on the carrier — and the rung-drop row `required_gate_bankruptcy` names them by their instrument (`cargo test -p v1-compiler --lib -- --ignored --list`). The unit population runs in ~10 s after the compile (srv2: 537 passed / 136 ignored). Of the 44 failures the full run exposed, the 15 in the unit population are repaired where the fact lives: - REAL DEFECTS (two): `try_index_source_root_into_module_index` keyed files by their walked path, absolute since #9548 anchored the root, while the strict builder keys through `module_index_path_key` — the primary-precedence index disagreed with the strict one on every path; keyed through the same authority now. `try_build_module_index` carried `if root_idx > 0 { continue; }` before its collision refusal (from #7791), so a module declared in two roots shadowed silently in the builder named strict; the guard is gone and overlay callers have `build_module_index_primary_precedence`. - v1 TYPECHECK DEFECT: `declared_type_inhabitance` reads `params` as generic type parameters, which is exactly what a callable formal carries, so every higher-order call produced a counted advisory with a false reason (#9194); `direct_call_argument_inhabitance_diags` now excludes callable formals like its sibling `direct_call_arg_type_mismatch`. Mirror regenerated (two passes: the test blob lives inside the emitter). - STALE AUTHORITY ROWS after the #9637 reorg: 12 entry literals in `gunbc.ci_layer_roots` and 2 in `gunbc.offline_local_recipe` repointed; the two long-lane rows and one freeze row whose subjects 611fd02 and #9206 deleted are gone; the three freeze rows for relocated witnesses are DELETED rather than repointed, because the freeze gate defines relocation as growth and the roster may only shrink. `gunbc.non_fold_residue` receives the 22 sites it lacked and loses the 4 whose subjects moved or greened; its .dag twin therefore leaves floor_expected_red (it passes) and joins cost-debt chunk 12 (629 ms against the 500 ms ceiling, its whole cost the corpus scan it checks). - DELETED SUBJECTS: `cli_run::floor_witness_a_prove` (its runner, prove test and fixtures went with the FLOOR-Y cutover); the census pin tests and helpers for `docs/probes/census_extra_excludes.txt` (#9132 deleted every transcription). - EARLY ABORTS: three witness-admission tests and the roadmap jsonl-carrier test were "fast" only because they failed before their expensive step; with their inputs repaired they read the live tree for 2-4 minutes each and join the live-corpus class. - TEST ROT: the reorg rewrote a revision-addressed literal (`9ce6526c528:dag/gunbc/roadmap/...`) that must name the pre-reorg path; the method-existence witness anchored on a `Primitive()` row the frontier no longer holds. Not done here, receipts-lane rot for follow-ups: `test.claim.expectation_frontier_witness_test` names the deleted long-lane file; the affected-set kernel (`floor_diff_edits_from_diff_text`, `rerun_frontier_nodes_for_entry`, …) has no production consumer since FLOOR-Y and should go with its remaining fixture-dependent tests; the roadmap jsonl-carrier test takes 453 s and fails after its expensive step. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 * The host-tool probe root carries the process id: temp_dir() is the host's shared /tmp on a self-hosted runner, and a fixed directory name collided with one another runner slot's uid left behind — PermissionDenied on two tests that had never run in CI before Found by the first green-by-duration run of the unit population (dc3ca52: 533 passed, 2 failed, 9.59s). The same class as the shared-/tmp emit_on_demand collision on srv2: a test that writes a fixed path into a location the process does not own. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2 --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Aug 30, 2026
…red on main; enrol DESIGN's named check in the rust-unit-tests job (#9747) * clippy --all-targets: the 12 never-compiled targets red on main repaired or deleted, and DESIGN's named check enrolled as a step of the rust-unit-tests job Population measured on main 8078e36 with --keep-going (the fail-fast run is a 5-error prefix): E0603 x7 from the #9648 cli_run decomposition, E0063 on Node's occurrence_identity, an include_str! of a fixture deleted in #9641, E0432 on the std_node bridge family retired in #9724, disallowed_macros x5, too_many_arguments, ptr_arg, and two lints hidden behind the compile errors. Every target repaired except examples/prep_profile.rs, whose header declares it scratch not for commit. Two runtime assertions behind the compile wall read their authority now instead of a stale copy (the Rust null keyword row; compile_clean_diagnostic_is_hard). No required phase runs clippy; gunbc.repo_self_build gains repo_self_clippy_command and gunbc.witness_floor_workflow runs it after the unit tests. gunbc.design_document names, per check, the step that executes it and whether it gates. DESIGN.md and witnesses.yml regenerated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018xgqwVB9erqDAnDWhtZ6yb * wip claim_batch rework (to be amended) * The emitted clippy step carries its on-carrier dissolve-on marker (review 57600) rust_clippy_all_targets_shell_emit_dissolution_trigger names the capability the hand-shell `run:` carrier dissolves into (the orchestration-to-shell bash emission ci_pin_rustup_default_script waits on); the step renders it as the leading comment, as every other hand-shell step the model emits does. witnesses.yml regenerated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018xgqwVB9erqDAnDWhtZ6yb * repo_self_clippy_command carries its argv as tokens, like its sibling (review 57608) * The clippy step's argv comes from a modeled cargo node, not a spelled string (review 57608) * The second ad-hoc forensics example goes with the first --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls
pushed a commit
that referenced
this pull request
Sep 4, 2026
…as already rostered
The receipt asserted the floor log's `[over-cost]` listing "is TRUNCATED, and
nothing in it says so". It says so. `required_floor_runner` has emitted
`... and N further row(s) over the {line}ms line, not printed. The complete
population is in the per-claim cost TSV uploaded by this run; this list is the
25 most expensive, ranked on the declared cost basis` since #9648 (2026-08-28),
and that footer is present in the very logs the receipt was measured over
(`and 316 further row(s)` in run 33795674825, `and 277` in 33806684407).
The constant I cited is 25 capped rows plus that footer line. I counted 26
lines across 23 runs without reading the 26th, which is the producer's own
statement that the listing is not the population.
The class is also already rostered, on `instrument_output_read_as_subject_content`,
which records this same `[over-cost]` truncation, quotes the same footer, and
argues why it belongs there rather than on a new row. Re-filing it here was a
second name for one meaning (DESIGN.md §3), and its "next trigger" asked for a
capability that has shipped for a week -- a trigger satisfied at birth can
never retire anything (§4b(3)).
What survives is the first receipt, which is untouched: correcting the line
value would not discharge this row's defect, because the compared column is
not the judged quantity either.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy
briansrls
pushed a commit
that referenced
this pull request
Sep 4, 2026
… the verdict cannot be recomputed (#10311) * Two more ways one cost artifact misleads its reader: the compared column is not the judged quantity, and the listing is capped `artifact_declares_a_threshold_it_is_not_measured_against` records that the floor's cost artifact declares `cost_line_ms=100` while the enforced line is 500ms. Two receipts append to that row, both measured tonight, both the same subject one level deeper: the artifact cannot predict the refusal it exists to explain. CORRECTING THE LINE VALUE WOULD NOT DISCHARGE IT. The row's existing trigger asks each row to emit the line actually applied. Necessary, not sufficient: a correct line compared against the wrong column still cannot predict a refusal. Executed proof from floor run 33806684407, which reported ZERO deadline interrupts -- a claim reports cpu_ms=744 on eval_steps=225857, genuine evaluation work, outcome=pass, while a claim in run 33795674825 was interrupted at cpu_at_least=508ms/500ms. If cpu_ms were the judged quantity the 744 refuses first. It does not, so the column is charged cpu while the judge nets out shared-artifact fill. The trigger is amended, still as a capability: emit the line applied AND the quantity compared, both from the authority the enforcement reads, sufficient to recompute the verdict from the row alone. THE LISTING IS TRUNCATED AND NOTHING SAYS SO. `[over-cost]` printed exactly 26 rows in each of 23 consecutive witnesses.yml push runs on main -- a constancy that reads as the strongest possible evidence the work is stable, which is how it was nearly cited here. It is a cap: the lowest listed row is 336ms while the row's own census records ~300 of 3534 rows over the declared line, and the 26 identities differ between runs. A constant produced by a cap is indistinguishable from a constant produced by stability, and the cap direction is the reassuring one. Both land as receipts on the existing row rather than a new identity: same artifact, same harm, and a second name for one class is what this ledger exists to prevent. First edit exercising the one-row-per-file split from #10206 -- one file plus the regenerated projection, with no tail collision. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * Withdraw the display-cap receipt: the claim was false and the class was already rostered The receipt asserted the floor log's `[over-cost]` listing "is TRUNCATED, and nothing in it says so". It says so. `required_floor_runner` has emitted `... and N further row(s) over the {line}ms line, not printed. The complete population is in the per-claim cost TSV uploaded by this run; this list is the 25 most expensive, ranked on the declared cost basis` since #9648 (2026-08-28), and that footer is present in the very logs the receipt was measured over (`and 316 further row(s)` in run 33795674825, `and 277` in 33806684407). The constant I cited is 25 capped rows plus that footer line. I counted 26 lines across 23 runs without reading the 26th, which is the producer's own statement that the listing is not the population. The class is also already rostered, on `instrument_output_read_as_subject_content`, which records this same `[over-cost]` truncation, quotes the same footer, and argues why it belongs there rather than on a new row. Re-filing it here was a second name for one meaning (DESIGN.md §3), and its "next trigger" asked for a capability that has shipped for a week -- a trigger satisfied at birth can never retire anything (§4b(3)). What survives is the first receipt, which is untouched: correcting the line value would not discharge this row's defect, because the compared column is not the judged quantity either. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * chore: regenerate drifted generated artifacts (ci auto-heal) * Three floor-instrument failure modes, filed: the sub-stride population, a vacuous completion predicate, and a by-name read that is a string not a binding All three are the floor's own instruments misreporting their own coverage, all found while working the FLOOR-COST-500MS subject, and all three carry a capability-grained trigger stating what the capability must be SUFFICIENT FOR. reachability_answered_is_consumed_as_protection_established The poll fires at `stride % 4096 == 0` -- a STEP stride. 273 of 349 claims in a sampled run never reach a poll at all, so `CooperativelyPollable` means "would be observed IF it strided" while enforcement consumes it as "was observed". Harmless today (max cpu under 100ms across those 273) and filed because a cheap-today population is the kind that stops being cheap with nobody re-checking the assumption that made it ignorable. completion_predicate_satisfied_by_the_empty_population `required_floor_outcome_is_clean` is eleven `.is_empty()` conjuncts with no denominator. The protection cited in the code is `claims_planned == claims_executed + not_attempted` -- at zero that is `0 == 0 + 0`: a TRUE invariant, advertised as the protection, vacuous in exactly the case it names. The adjacent `ExpectedRedRosterEmpty` refusal already implements the fix one file away, with its rationale written out. Structural vacuity established; reachability NOT established and the row says so. by_name_evaluation_is_a_string_not_a_binding `run_in_context(ctx, "gunbc.x.y")` type-checks against any ctx and any name. Caught on gunbc#10319 before push: a `gunbc.*` read through a `v2.workflow.*` frame, green under check, clippy and test, and it would have refused the ENTIRE floor -- because a fail-closed arm amplifies a targeting error rather than containing one. THE PROJECTION IS KNOWINGLY STALE AND IS NOT REGENERATED HERE. This branch is already driver-REFUSED and already owes a lap, so a stale projection changes nothing about its state. `docs/design-failure-modes.md` is deliberately NOT hand-edited: a hand-written projection is worse than an absent one, because the lap's regen would then be diffed against a guess instead of against main's bytes. The lap regenerates it. Rows and roster verified by identity join, not count: 88 row files, 88 roster imports, 88 roster entries, and the three sets are identical. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * Install the #10302 merge driver before integrating, so the conflict diagnostic is emitted by the current policy The driver git executes during a merge is the copy already in the worktree, so integrating main with the old script would have printed the pre-#10302 recipe for a path whose repair route that very merge changes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * The merge driver that adjudicates the merge replacing it: an anti-correlation of one, not a timing hazard A policy mechanism the toolchain reads from the WORKING TREE -- a merge driver, a hook, a lint config, a codegen template -- acts at the version already installed. So on every change that leaves it alone its instruction is current, and on the one change that REPLACES it the instruction is guaranteed to be the retired one. The more significant the policy change, the more certainly the author is handed the old policy; there is no bad draw to be unlucky with and no window to shorten. Distinct from verification_bound_to_the_revision_it_started_on, which inverts both halves: there a moving SUBJECT under a stable observer, biting by timing, most runs escaping. Here a fine subject and an observer stale BY CONSTRUCTION. Checked against stable_citation_mutable_referent (an identifier addressing a container, not an executable shipped in the tree it judges), authority_merges_unprotected_while_its_ projection_is_guarded (which side of a derivation a policy protects) and admission_predicate_evidenced_from_inside_its_own_subject (a surface that cannot represent its predicate being false) -- read to the bottom, variants included, since that is exactly the check I skipped on the row folded one commit ago. Specimen is this branch against #10302 at d6fb9d6: the printed repair route was a four-step local whole-tree regeneration, and the merge being performed was the one that delegates that regeneration to heal. Nothing in the output distinguishes the retired recipe from the live one -- real driver, real refusal, real located instructions, one version stale. The mitigation is stated as a procedure rather than as vigilance: install the incoming mechanism first as its own commit, then re-run the merge and read the new diagnostic. Trigger at capability grain -- a tree-resident mechanism that detects its own path among the incoming changes and REFUSES instead of instructing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * Three arms on the stale-policy-mechanism row, reached independently by three lanes in one hour The independent rediscovery is itself the evidence for a distinct identity: three lanes hit this inside an hour and none could find the class in the roster. Arm one is the author following the retired route -- one wasted regeneration. Arm two, snappy-koi-879 on #10271, is the MIRROR and is worse: about to report a landed capability as not having taken effect, from a correct reading of a stale instrument. A false negative about a capability propagates and its correction requires someone to disbelieve a direct instrument reading. Arm three, neat-swift-219's merge-readiness gate, is the ENFORCEMENT INSTRUMENT: its verdict field was IDENTICAL under both driver versions and only the instructions differed, so the arm that decides was unchanged while the arm that explains was wrong. Nothing in the output could have revealed it. Any long-lived checker holding a cached copy of a versioned policy inherits this. The remedy is snappy-koi-879's, quoted as theirs and receipted by neat-swift-219 who executed it independently: take the tool from the incoming side with a one-shot config override, never from the worktree. Including why it beats the obvious fix -- syncing the worktree conflicted on the very roster the tool adjudicates, so the instinctive repair puts the checker into the queue it is checking. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy * chore: regenerate drifted generated artifacts (ci auto-heal) * chore: regenerate drifted generated artifacts (ci auto-heal) * chore: regenerate drifted generated artifacts (ci auto-heal) --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two subjects, both stability work continued from #9635.
1. guarantee_rung_drop parse fix. The #9612 merge collision left
wall_deadline_shared_fill_attribution_stallwithout its closing brace, so everygunbc runover thedagroot refused at module index ("1 unparseable .dag source") — v1 built but could execute nothing. One brace; the documented converge actuator entry runs end-to-end again. (The E0428 half of the same collision was fixed on main separately.)2. cli_run.rs decomposition, first 13 clusters. 50,536 → 46,443 lines, pure code motion into
src/v1/stage0/src/cli_run/submodules, joining the six that already lived there:test_migration,compile_clean,non_fold_residue,class_b_census,languages_census,external_authority,inert_carrier,witness_gates,emit_host,complexity_gates,doc_graph,declared_refs,census_heads.Mechanics (repeatable for the remaining clusters): each submodule carries
use super::*plus the parent's use-header; the parent re-exportspub(crate) use <mod>::*so every existing path keeps resolving; fns consumed frombin/targets get explicitpub use(the pub(crate) glob does not cross the lib/bin boundary); private moved items widen topub(crate); eight report/plan types widened for the private-interface lint (CI sets-D warnings).lib.rsis generated and untouched — submodule declarations live in hand-ownedcli_run.rs, per the existing pattern.Deliberately NOT moved, to avoid conflicting with in-flight operator work: the resolver/index core (
resolve_entry_*,build_module_*, shared-index thread_locals — the pool-tax subject) and the floor runner (floor_*,run_required_*, budgets/accounting). Each moves in a quiet window with the same recipe.Also carries the plan-file updates: the corrected pool-tax finding (linear ~20–25ms/pool-module eager graph facts; the earlier cwd-switch claim retracted — its fast controls were silent panics) and the decomposition log.
Verification:
cargo build --release -p v1-compilerclean with zero warnings after each batch; converge actuator smoke-run executes real host effects post-split.🤖 Generated with Claude Code
https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Generated by Claude Code