Skip to content

Fix the unparseable rung-drop record, and start the cli_run.rs decomposition (13 clusters to named submodules) - #9648

Merged
briansrls merged 17 commits into
mainfrom
claude/repo-stability-priorities-frtsy4
Aug 29, 2026
Merged

briansrls merged 17 commits into
mainfrom
claude/repo-stability-priorities-frtsy4

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Two subjects, both stability work continued from #9635.

1. guarantee_rung_drop parse fix. The #9612 merge collision left wall_deadline_shared_fill_attribution_stall without its closing brace, so every gunbc run over the dag root refused at module index ("1 unparseable .dag source") — v1 built but could execute nothing. One brace; the documented converge actuator entry runs end-to-end again. (The E0428 half of the same collision was fixed on main separately.)

2. cli_run.rs decomposition, first 13 clusters. 50,536 → 46,443 lines, pure code motion into src/v1/stage0/src/cli_run/ submodules, joining the six that already lived there: test_migration, compile_clean, non_fold_residue, class_b_census, languages_census, external_authority, inert_carrier, witness_gates, emit_host, complexity_gates, doc_graph, declared_refs, census_heads.

Mechanics (repeatable for the remaining clusters): each submodule carries use super::* plus the parent's use-header; the parent re-exports pub(crate) use <mod>::* so every existing path keeps resolving; fns consumed from bin/ targets get explicit pub use (the pub(crate) glob does not cross the lib/bin boundary); private moved items widen to pub(crate); eight report/plan types widened for the private-interface lint (CI sets -D warnings). lib.rs is generated and untouched — submodule declarations live in hand-owned cli_run.rs, per the existing pattern.

Deliberately NOT moved, to avoid conflicting with in-flight operator work: the resolver/index core (resolve_entry_*, build_module_*, shared-index thread_locals — the pool-tax subject) and the floor runner (floor_*, run_required_*, budgets/accounting). Each moves in a quiet window with the same recipe.

Also carries the plan-file updates: the corrected pool-tax finding (linear ~20–25ms/pool-module eager graph facts; the earlier cwd-switch claim retracted — its fast controls were silent panics) and the decomposition log.

Verification: cargo build --release -p v1-compiler clean with zero warnings after each batch; converge actuator smoke-run executes real host effects post-split.

🤖 Generated with Claude Code

https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y


Generated by Claude Code

claude added 7 commits August 28, 2026 19:54
The wall_deadline_shared_fill_attribution_stall record landed without its
closing brace, so every gunbc run over the dag root refused at module index
(expected expression, found Eq) -- the same collided merge that duplicated the
cli_run.rs definitions. With the brace, the documented converge actuator entry
runs end-to-end again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… facts, no cwd switch; fast controls were panics

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…(pure code motion)

test_migration, compile_clean, non_fold_residue, class_b_census,
languages_census, external_authority, inert_carrier — 107 items, ~2.1k lines.
Mechanics: each cluster becomes a cli_run/ submodule with 'use super::*' back
into the parent plus the parent's use-header; the parent re-exports
'pub(crate) use <mod>::*' so every existing path keeps resolving. Private
moved items widen to pub(crate), which rewraps a few signatures under rustfmt.
No semantic change; build-verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…aph, declared_refs, census_heads (pure code motion)

89 items, ~2.1k lines. Bin-consumed pub fns get explicit pub use re-exports
(the pub(crate) glob does not cross the lib/bin crate boundary).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…nterface lints; CI sets -D warnings)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-28T22:48:39.755708Z dd516ad PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

claude added 10 commits August 28, 2026 22:49
…into the split modules

The two conflict regions were regions this branch had moved: the compile_dag_*
emit-check family (unchanged on main — kept in emit_host, const takes main's
new dag/gunbc/ci/ path) and the witness-admission source scan (main's updated
witness_admission_explicit_consumer_keys ported into witness_gates verbatim).
Verified: no submodule carries a dag path literal that no longer exists on disk.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…ead_decode, active_workset (pure code motion)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Both sides of the merge fixed #9612's unclosed record identically; the auto-
merge kept both hunks' markers. Smoke-verified: the converge actuator (now at
dag/gunbc/repo/ after the filename reorg) compiles and executes again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… ~2.5k lines, pure code motion)

The pool-tax subject now has its own reviewable home: module path index,
module-graph facts, import closures, the process shared index and resolve
store (thread_local statics widened to pub(crate)), typed-module cache,
multi-entry index shell, resolve stage/span accounting. Bin-consumed fns get
explicit pub use; two cache types widened for the private-interface lint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…xecution (49 items, ~4.8k lines, pure code motion)

run_required_floor, claim evaluation/measurement, discovery corpus, diff
observation, prepared-subject inventory, resource sampling, cgroup envelope,
route-gap expectations, floor stream/verbosity plumbing. Same recipe: bin-
consumed fns re-exported pub; two expectation/edit types widened for the
private-interface lint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
… single pre-registered execution test

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…ntics_witness for the new TypeEnv field

Conflicts were the usual moved-region kind: compile_clean_diagnostic_histogram_key
and census_heads_module_node/_module_item changed on main and are ported verbatim
into their submodules (visibility restored to pub(crate)).

Separately, main @ 0ef6f7c (#9656) does not build: it added
TypeEnv.unit_variant_index without updating the six TypeEnv literals in
bin/infer_semantics_witness.rs (the bins aren't gated while CI is red — third
ungated-merge breakage in two days). Fixed forward here with empty-index
initializers, matching empty_type_env's shape.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
…the string literal it was authored as

Bisect pinned main's runtime failure (trim expects a string, got Null on the
converge actuator) to 655f82a (#9344). Mechanism: the rewritten
parse_optional_from_key built the from_key property's value node with
NoExprData (key carried only as a node NAME), and the new field_to_child_node
passes parsed properties through instead of re-materializing them — but the
interpreter's extract_from_key accepts only ExprLiteral{LitStr}, so every
'output field from "channel"' mapping silently missed, the output key fell
back to the field name, and effect-result fields decoded as Null
(git.Core.ConfigLocalGetInRepo: .success survived by name, .value did not).

The from token IS a string literal in the grammar (ShLitStr), so the fix makes
the property value carry ExprLiteral{LitStr{key}} at the one construction site
in v1.compiler.parse parse_optional_from_key; the mirror is regenerated via
--required-regen (surface drift resolved by installing the candidate).
Smoke: the converge actuator executes end-to-end again.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017qPeVyc2VjbdN4os17UG3y
@briansrls
briansrls merged commit 2f2815d into main Aug 29, 2026
0 of 2 checks passed
@briansrls
briansrls deleted the claude/repo-stability-priorities-frtsy4 branch August 29, 2026 01:51
gunbai-bot Bot pushed a commit that referenced this pull request Aug 29, 2026
briansrls pushed a commit that referenced this pull request Aug 29, 2026
…unit_variant_index after #9656 (#9662)

* Unbreak main: drop the JsSite artifact rows whose authority #9641 deleted, and give the six witness-bin TypeEnv initializers the unit_variant_index #9656 added

Two integration collisions between independently green PRs:
- #9641 deleted dag/examples/js_site but gunbc.generated_artifact and
  gunbc.generated_artifact_emit still imported it, so the whole-tree
  strict resolve refused and every floor on main has been red since.
- #9656 added TypeEnv.unit_variant_index; infer_semantics_witness.rs
  builds six TypeEnvs by hand and none carried it, so --bins failed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The lib's own unit tests build one more TypeEnv by hand; give it unit_variant_index too

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Drop the six duplicate unit_variant_index initializers the merge with #9648 produced

* Regenerate .gitattributes: the six js_site rows projected from the deleted artifact registry entries go with them

* Shrink the namespace transition roster: the 314 std->extdeps consolidation rows landed with #9641 and now refuse every PR as stale

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Aug 29, 2026
…e prepares the roster's closure, not the tree; rust unit tests in their own job; the un-required phases declared as a rung drop (#9663)

* Unbreak main: drop the JsSite artifact rows whose authority #9641 deleted, and give the six witness-bin TypeEnv initializers the unit_variant_index #9656 added

Two integration collisions between independently green PRs:
- #9641 deleted dag/examples/js_site but gunbc.generated_artifact and
  gunbc.generated_artifact_emit still imported it, so the whole-tree
  strict resolve refused and every floor on main has been red since.
- #9656 added TypeEnv.unit_variant_index; infer_semantics_witness.rs
  builds six TypeEnvs by hand and none carried it, so --bins failed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The lib's own unit tests build one more TypeEnv by hand; give it unit_variant_index too

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Required CI is the compiler floor: a static gate roster, prepared as its own import closure, with the other four phases and the product witnesses moved off the merge path

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Drop the six duplicate unit_variant_index initializers the merge with #9648 produced

* Drop the six duplicate unit_variant_index initializers the merge with #9648 produced

* Regenerate .gitattributes: the six js_site rows projected from the deleted artifact registry entries go with them

* Regenerate the four projections of this change: witnesses.yml (probe and all-bins steps gone, rust-unit-tests job added), DESIGN.md and design-ledgers.md (the rung-drop row), .gitattributes (js_site rows gone)

* Restore the lib-test TypeEnv initializer's unit_variant_index (lost when the merge took main's cli_run.rs wholesale)

* The gate closure is the loader's both-closure (imports + reference edges to a fixpoint), not the import headers: stripped modules reach their providers by reference, and the header walk left 1,190 names unresolved

* Shrink the namespace transition roster: the 314 std->extdeps consolidation rows landed with #9641 and now refuse every PR as stale

* Build the entry index once for both gate closures (it is the expensive part: ~75-110s per build on the corpus)

* Gate closure includes containment ancestors to a fixpoint: a module importing only a child of the declaring module still binds the parent's declarations

* The floor's policy module is always a closure seed: its rosters are evaluated in a frame over the prepared subject

* The reference-closure index is keyed by the prepared subject's digest, bounded to the two subjects a floor process prepares by design — the gate's policy-closure preparation and the gate closure are two subjects in one process, and a once-per-process index refused the second (ReferenceIndexSubjectChanged built_for_modules=47 observed_modules=1952, CI and srv2 at 066725c)

The old check keyed on module COUNT: two subjects of equal size would have
shared one index silently. The new one keys on `subject_digest`, so the
index a scope consults was built from the graph that scope is over, by
construction. The population is bounded by
FLOOR_PREPARED_SUBJECTS_PER_PROCESS = 2 (policy closure, gate closure) — a
third distinct subject still refuses with the same cause, because a
subject per claim is the corpus walk per row the index exists to avoid.

Evidence: srv2 rerun of `claim_executor --required-ci --required-lane
witnesses` at this tree builds the 47-module policy index
(subject=09966adcd218af0e) and proceeds into the 1,954-module gate
preparation instead of refusing at claim scope.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The floor's own runtime authorities are explicit closure seeds: the gate-bounded subject refused at output-policy install because resolve_channel_policy had only ever resolved by pool-membership coincidence — the flat bare-name channel found gunbc.output_policy because the whole corpus was loaded, not because the policy closure references it

REQUIRED_FLOOR_RUNTIME_AUTHORITY_MODULES names every module the floor's
Rust evaluates by name outside the gate roster: the policy module (its
rosters), v2.workflow.floor_naming_hygiene (qualified evaluations), and
gunbc.output_policy (bare, from install_output_policy_in). All three are
seeds of the gate closure; a new by-name evaluation adds its module here
or refuses at its own call site.

Measured: the first gate-bounded run (srv2, at 2d5502a) got past both
reference-closure indexes and refused with "no declaration named
'resolve_channel_policy' in this execution's loaded index".

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* A by-name evaluation of a module's declaration runs in THAT module's scope: the floor installed the output policy and the naming-hygiene predicates from the policy module's frame, which reached gunbc.output_policy only by the accident of the whole-tree reference closure — under the gate-bounded subject the module was loaded and the name still refused

floor_authority_frame(prepared, module) builds a hermetic frame over one
module's exact claim scope. install_output_policy_in now receives the
frame over gunbc.output_policy; floor_barren_test_sidecars the one over
v2.workflow.floor_naming_hygiene. The policy module's frame keeps only
the policy module's own rosters.

Measured (srv2, lanes 5 and 6): with gunbc.output_policy present in the
1,954-module subject — the seeds changed the seed count 906 -> 908 and
the closure not at all — resolve_channel_policy still refused as "no
declaration named ... in this execution's loaded index". The scope, not
the subject, was the coincidence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The floor's rosters are joined only over identities inside the required gate — an enrolled identity whose module the gate never loads is withheld with the same accounting as cost-debt withholding, not refused as stale; and two modules that reached rust_target_model_staging by bare reference now import it, because the loader follows bare references only for import-free modules while the claim scope follows all of them

Measured on the first gate-bounded fold (srv2 lane 7, CI at 006b0ef):
ExpectedRedIdentityDidNotExecute count=39, every row in a module outside
the gate roster; and v2.test.lens_vacuity.vacuity_test x5 ERROR
no-such-function `rust_target_model_staging`, reproduced standalone with
`gunbc run --entry src/v2/test/lens_vacuity/vacuity_test.dag`. The
loader's both-closure (build_both_closure_edge_index) skips the bare
scan for any source that declares import lines, so rung_3_4_common
(one import) and leaf_model_verification's bare edge to
v2.extdeps.languages.rust was never followed; under the whole-tree
subject the flat channel found it anyway. The import is the form 10 of
the 12 sibling callers already use; the loader/scope divergence is
recorded in the PR.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The gate closure follows bare cross-module references from EVERY module, with the loader's own scanner, to a joint fixpoint with containment ancestors — the loader's both-closure bare-scans only import-free sources, while the claim scope the fold builds over the subject follows bare references from all of them; and route-gap expectations located outside the gate are withheld like the roster rows they join

Measured 2026-08-29 on srv2: with the gate subject, `gunbc run` of
v2.test.lens_vacuity.vacuity_test refused no-such-function
`rust_target_model_staging`, then `eval_context` after the first was
imported — one absent module per run, because rung_3_4_common (one
import line) and leaf_model_verification reach them by bare reference
and build_both_closure_edge_index skips the bare scan for any source
that declares an import. The fixpoint reuses
bare_reference_pull_paths_for_source, so the relation is the loader's
and not a second scanner; the count of modules pulled this way is
printed on the gate-closure line.

Lane 8 (srv2) then refused `floor_route_gap_expectations: located
identity is absent from derived roster` for an identity whose module is
outside the gate: the roster had its outside-gate rows withheld and the
expectations had not. Both sides now withhold by the same predicate,
counted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Cost-debt rows outside the required gate are withheld from the staleness join, route-gap expectations honour cost-debt withholding, and emit_on_demand_classical_not_native_one_build_holds moves to the cost-debt roster — it is budget-refused before it reaches the host effect its route-gap enrollment expects, on both hosts

Measured on the first complete gate-bounded fold (srv2 lane 10 and CI at
e8effe8, identical): verdict=FloorRefused with unexpected_failures=0 —
no claim inside the gate fails — and two bookkeeping refusals: 122
STALE-COST-DEBT rows, every one in a module the gate never loads, and
one STALE-ROUTE-GAP row whose claim ran past its CPU ceiling before
reaching the effect. The first is the same out-of-scope population the
expected-red and route-gap joins already withhold, now counted the same
way. The second is a real cost debt (floor_cost_debt already records
this claim at 502 -> 2374 ms), and cost debt wins over route-gap
enrollment by the roster's own rule; the expectations decode now treats
a cost-debt-withheld identity as dormant rather than absent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Two lens_module_gate_witness rows leave the expected-red roster: under the gate-bounded subject both PASS on CI and on srv2, and the floor refuses a passing enrollment as STALE-QUARANTINE

Measured at 1f4bda9 (CI) and srv2 lane 12: verdict=FloorRefused with
unexpected_failures=0 and exactly these two STALE-QUARANTINE rows on
CI. Both are "live" claims whose question ranges over the loaded
corpus; under the gate closure that corpus is 2,021 modules rather
than 4,260, and the population they were red on is outside it. That
is a narrowing of what the claim observes, stated here rather than
hidden: the whole-corpus receipts run is where the wider question is
asked again. srv2 additionally passes four emit_host_* rows that stay
red on the required host; those stay enrolled — CI is the oracle for
the required gate.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* Eleven claims interrupted before verdict on the gate-bounded subject join the cost-debt roster as proven chunk 12 — the same eleven on the GitHub runner and on srv2, run after run

At 92cc92e the floor reports verdict=FloorRefused with
unexpected_failures=0, no stale rows, no now-passing rows, and eleven
INTERRUPTED-BEFORE-VERDICT identities (cost_coverage_witness x3,
loaded_carrier_receipts x3, lens_closure_question_zero_holds_live,
green_control_sanctioned_reader_body_not_flagged,
same_grammar_parse_ingest_bridge_holds, kotlin_grammar_parse_accepted,
nominal_distinct_control_compiles_ok). The set is identical at e8effe8
and 1f4bda9 on CI and in srv2 lane 12, so it is a property of the
subject, not of host load: on the gate closure these claims first-touch
artifacts the whole-tree fold had warmed before reaching them. Declared
here as the roster's own containment for a cost the ceiling cannot
hold; the exit is the warm, as the roster's header states.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* lens_module_gate_holds_live joins cost-debt chunk 12: it was interrupted at 1076ms the run after its sibling was withheld, because the 1.07s pool-root module_path_index fill is billed to whichever consumer runs first

CI 0829ad8: verdict=FloorRefused, unexpected_failures=0, one
INTERRUPTED-BEFORE-VERDICT row. The claim-cost receipt reads
budget_interrupted 1076ms for it and
`[floor-shared-fill] cache=module_path_index key=.../src/v2/lens
fill_ms=1070 paid_by=...lens_module_gate_holds_live consumer_claims=1`;
at 92cc92e the same fill was paid by lens_closure_question_zero_holds_live
(consumer_claims=2) and this claim passed. The index is keyed on a pool
root the decl_facts seam asks for at claim time, so preparation cannot
warm it ahead; with both consumers withheld nothing pays it. The
roster's own header names the warm as the exit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The pool-root module_path_index for src/v2/lens is warmed in preparation by evaluating the declared producer once in its own module's scope — the 1.07s fill was a positional bill that interrupted a different lens_module_gate_witness live claim in each of three consecutive runs — and the two fill-only rows leave cost-debt chunk 12

CI 92cc92e, 0829ad8, 154fb1f: each run's single INTERRUPTED-BEFORE-VERDICT
row was the next `lens_module_gate_witness` live claim in evaluation
order, at 1068–1252ms, with the claim-cost receipt and
`[floor-shared-fill] cache=module_path_index key=.../src/v2/lens`
naming that claim as the payer. The witness-roots warm cannot reach a
per-pool-root key; this warm evaluates
`v2.lens.registry.completeness.lens_registry_completeness_live_facts`
in that module's frame, so the root comes from
`lens_registry_completeness_pool_roots` and the key is the consumers'
by construction. Adjudicated with the other preparation warms as
`ModulePathIndexBuild/lens-pool-roots`; skipped (printed) when the
subject does not carry the producer; a producer that fails to evaluate
refuses. The two rows whose entire cost was this fill leave chunk 12,
as the roster header says they must once the warm exists.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* lens_closure_question_zero_holds_live leaves the expected-red roster: with the src/v2/lens pool-root index warmed in preparation it passes, as its two siblings did once they stopped paying that fill

srv2 lane 13 at 8ad4091: `[floor-shared-fill] cache=module_path_index
key=.../src/v2/lens paid_by=<outside-fold> consumer_claims=3`, no lens
claim interrupted, and STALE-QUARANTINE for this row — the same row
that was red only while it paid the fill (CI 92cc92e).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The four bootstrap_footprint_anchor claims join cost-debt chunk 12: 474–505ms CPU on three consecutive CI runs with no fill billed to them, so the 500ms ceiling decides them run by run

CI f462bc9: planned=executed=2834, passed=2754, known_red_held=27,
failed=0, no stale rows, interrupted_before_verdict=4 — these four, at
502–505ms. At 154fb1f the same four completed at 487–504ms and at
0829ad8 at 474–485ms; the run-to-run spread is the runner slot, not the
claim. The gate did not change their cost — nothing in the shared-fill
attribution names them — so the disposition is the roster's, not a
ceiling change: withheld as declared debt until the host-load row
lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The rust-unit-tests job runs the unit population: the lib tests that prepare or build over the live tree carry a live-corpus ignore reason and leave the required run, and the rot the first-ever `cargo test` exposed is repaired at its authorities, not hidden

`cargo test -p v1-compiler --lib` had never run in CI. Its first run (33238828500) was cancelled by its own 60-minute timeout with 204 of 682 tests finished, because ~126 of the "unit" tests each build a fresh multi-entry index over `src/v2`+`dag` (4,260 modules; ~197 single-thread minutes on srv2 under nextest, 97 tests over 60 s, `self_compile_all_modules` alone 505 s), and the runner executes them serially. Those tests now carry `#[ignore = "live-corpus: ..."]` — the crate's existing `manual:` convention, one class, declared on the carrier — and the rung-drop row `required_gate_bankruptcy` names them by their instrument (`cargo test -p v1-compiler --lib -- --ignored --list`). The unit population runs in ~10 s after the compile (srv2: 537 passed / 136 ignored).

Of the 44 failures the full run exposed, the 15 in the unit population are repaired where the fact lives:
- REAL DEFECTS (two): `try_index_source_root_into_module_index` keyed files by their walked path, absolute since #9548 anchored the root, while the strict builder keys through `module_index_path_key` — the primary-precedence index disagreed with the strict one on every path; keyed through the same authority now. `try_build_module_index` carried `if root_idx > 0 { continue; }` before its collision refusal (from #7791), so a module declared in two roots shadowed silently in the builder named strict; the guard is gone and overlay callers have `build_module_index_primary_precedence`.
- v1 TYPECHECK DEFECT: `declared_type_inhabitance` reads `params` as generic type parameters, which is exactly what a callable formal carries, so every higher-order call produced a counted advisory with a false reason (#9194); `direct_call_argument_inhabitance_diags` now excludes callable formals like its sibling `direct_call_arg_type_mismatch`. Mirror regenerated (two passes: the test blob lives inside the emitter).
- STALE AUTHORITY ROWS after the #9637 reorg: 12 entry literals in `gunbc.ci_layer_roots` and 2 in `gunbc.offline_local_recipe` repointed; the two long-lane rows and one freeze row whose subjects 611fd02 and #9206 deleted are gone; the three freeze rows for relocated witnesses are DELETED rather than repointed, because the freeze gate defines relocation as growth and the roster may only shrink. `gunbc.non_fold_residue` receives the 22 sites it lacked and loses the 4 whose subjects moved or greened; its .dag twin therefore leaves floor_expected_red (it passes) and joins cost-debt chunk 12 (629 ms against the 500 ms ceiling, its whole cost the corpus scan it checks).
- DELETED SUBJECTS: `cli_run::floor_witness_a_prove` (its runner, prove test and fixtures went with the FLOOR-Y cutover); the census pin tests and helpers for `docs/probes/census_extra_excludes.txt` (#9132 deleted every transcription).
- EARLY ABORTS: three witness-admission tests and the roadmap jsonl-carrier test were "fast" only because they failed before their expensive step; with their inputs repaired they read the live tree for 2-4 minutes each and join the live-corpus class.
- TEST ROT: the reorg rewrote a revision-addressed literal (`9ce6526c528:dag/gunbc/roadmap/...`) that must name the pre-reorg path; the method-existence witness anchored on a `Primitive()` row the frontier no longer holds.

Not done here, receipts-lane rot for follow-ups: `test.claim.expectation_frontier_witness_test` names the deleted long-lane file; the affected-set kernel (`floor_diff_edits_from_diff_text`, `rerun_frontier_nodes_for_entry`, …) has no production consumer since FLOOR-Y and should go with its remaining fixture-dependent tests; the roadmap jsonl-carrier test takes 453 s and fails after its expensive step.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

* The host-tool probe root carries the process id: temp_dir() is the host's shared /tmp on a self-hosted runner, and a fixed directory name collided with one another runner slot's uid left behind — PermissionDenied on two tests that had never run in CI before

Found by the first green-by-duration run of the unit population (dc3ca52: 533 passed, 2 failed, 9.59s). The same class as the shared-/tmp emit_on_demand collision on srv2: a test that writes a fixed path into a location the process does not own.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013G3t66QwKJFK5w8jXxMXP2

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Aug 30, 2026
…red on main; enrol DESIGN's named check in the rust-unit-tests job (#9747)

* clippy --all-targets: the 12 never-compiled targets red on main repaired or deleted, and DESIGN's named check enrolled as a step of the rust-unit-tests job

Population measured on main 8078e36 with --keep-going (the fail-fast run is a
5-error prefix): E0603 x7 from the #9648 cli_run decomposition, E0063 on Node's
occurrence_identity, an include_str! of a fixture deleted in #9641, E0432 on the
std_node bridge family retired in #9724, disallowed_macros x5, too_many_arguments,
ptr_arg, and two lints hidden behind the compile errors. Every target repaired
except examples/prep_profile.rs, whose header declares it scratch not for commit.
Two runtime assertions behind the compile wall read their authority now instead of
a stale copy (the Rust null keyword row; compile_clean_diagnostic_is_hard).

No required phase runs clippy; gunbc.repo_self_build gains repo_self_clippy_command
and gunbc.witness_floor_workflow runs it after the unit tests. gunbc.design_document
names, per check, the step that executes it and whether it gates. DESIGN.md and
witnesses.yml regenerated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018xgqwVB9erqDAnDWhtZ6yb

* wip claim_batch rework (to be amended)

* The emitted clippy step carries its on-carrier dissolve-on marker (review 57600)

rust_clippy_all_targets_shell_emit_dissolution_trigger names the capability the
hand-shell `run:` carrier dissolves into (the orchestration-to-shell bash emission
ci_pin_rustup_default_script waits on); the step renders it as the leading comment,
as every other hand-shell step the model emits does. witnesses.yml regenerated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018xgqwVB9erqDAnDWhtZ6yb

* repo_self_clippy_command carries its argv as tokens, like its sibling (review 57608)

* The clippy step's argv comes from a modeled cargo node, not a spelled string (review 57608)

* The second ad-hoc forensics example goes with the first

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Sep 4, 2026
…as already rostered

The receipt asserted the floor log's `[over-cost]` listing "is TRUNCATED, and
nothing in it says so". It says so. `required_floor_runner` has emitted
`... and N further row(s) over the {line}ms line, not printed. The complete
population is in the per-claim cost TSV uploaded by this run; this list is the
25 most expensive, ranked on the declared cost basis` since #9648 (2026-08-28),
and that footer is present in the very logs the receipt was measured over
(`and 316 further row(s)` in run 33795674825, `and 277` in 33806684407).

The constant I cited is 25 capped rows plus that footer line. I counted 26
lines across 23 runs without reading the 26th, which is the producer's own
statement that the listing is not the population.

The class is also already rostered, on `instrument_output_read_as_subject_content`,
which records this same `[over-cost]` truncation, quotes the same footer, and
argues why it belongs there rather than on a new row. Re-filing it here was a
second name for one meaning (DESIGN.md §3), and its "next trigger" asked for a
capability that has shipped for a week -- a trigger satisfied at birth can
never retire anything (§4b(3)).

What survives is the first receipt, which is untouched: correcting the line
value would not discharge this row's defect, because the compared column is
not the judged quantity either.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy
briansrls pushed a commit that referenced this pull request Sep 4, 2026
… the verdict cannot be recomputed (#10311)

* Two more ways one cost artifact misleads its reader: the compared column is not the judged quantity, and the listing is capped

`artifact_declares_a_threshold_it_is_not_measured_against` records that the
floor's cost artifact declares `cost_line_ms=100` while the enforced line is
500ms. Two receipts append to that row, both measured tonight, both the same
subject one level deeper: the artifact cannot predict the refusal it exists to
explain.

CORRECTING THE LINE VALUE WOULD NOT DISCHARGE IT. The row's existing trigger
asks each row to emit the line actually applied. Necessary, not sufficient: a
correct line compared against the wrong column still cannot predict a refusal.
Executed proof from floor run 33806684407, which reported ZERO deadline
interrupts -- a claim reports cpu_ms=744 on eval_steps=225857, genuine
evaluation work, outcome=pass, while a claim in run 33795674825 was interrupted
at cpu_at_least=508ms/500ms. If cpu_ms were the judged quantity the 744 refuses
first. It does not, so the column is charged cpu while the judge nets out
shared-artifact fill. The trigger is amended, still as a capability: emit the
line applied AND the quantity compared, both from the authority the enforcement
reads, sufficient to recompute the verdict from the row alone.

THE LISTING IS TRUNCATED AND NOTHING SAYS SO. `[over-cost]` printed exactly 26
rows in each of 23 consecutive witnesses.yml push runs on main -- a constancy
that reads as the strongest possible evidence the work is stable, which is how
it was nearly cited here. It is a cap: the lowest listed row is 336ms while the
row's own census records ~300 of 3534 rows over the declared line, and the 26
identities differ between runs. A constant produced by a cap is
indistinguishable from a constant produced by stability, and the cap direction
is the reassuring one.

Both land as receipts on the existing row rather than a new identity: same
artifact, same harm, and a second name for one class is what this ledger exists
to prevent.

First edit exercising the one-row-per-file split from #10206 -- one file plus
the regenerated projection, with no tail collision.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* Withdraw the display-cap receipt: the claim was false and the class was already rostered

The receipt asserted the floor log's `[over-cost]` listing "is TRUNCATED, and
nothing in it says so". It says so. `required_floor_runner` has emitted
`... and N further row(s) over the {line}ms line, not printed. The complete
population is in the per-claim cost TSV uploaded by this run; this list is the
25 most expensive, ranked on the declared cost basis` since #9648 (2026-08-28),
and that footer is present in the very logs the receipt was measured over
(`and 316 further row(s)` in run 33795674825, `and 277` in 33806684407).

The constant I cited is 25 capped rows plus that footer line. I counted 26
lines across 23 runs without reading the 26th, which is the producer's own
statement that the listing is not the population.

The class is also already rostered, on `instrument_output_read_as_subject_content`,
which records this same `[over-cost]` truncation, quotes the same footer, and
argues why it belongs there rather than on a new row. Re-filing it here was a
second name for one meaning (DESIGN.md §3), and its "next trigger" asked for a
capability that has shipped for a week -- a trigger satisfied at birth can
never retire anything (§4b(3)).

What survives is the first receipt, which is untouched: correcting the line
value would not discharge this row's defect, because the compared column is
not the judged quantity either.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* chore: regenerate drifted generated artifacts (ci auto-heal)

* Three floor-instrument failure modes, filed: the sub-stride population, a vacuous completion predicate, and a by-name read that is a string not a binding

All three are the floor's own instruments misreporting their own coverage, all
found while working the FLOOR-COST-500MS subject, and all three carry a
capability-grained trigger stating what the capability must be SUFFICIENT FOR.

reachability_answered_is_consumed_as_protection_established
  The poll fires at `stride % 4096 == 0` -- a STEP stride. 273 of 349 claims in
  a sampled run never reach a poll at all, so `CooperativelyPollable` means
  "would be observed IF it strided" while enforcement consumes it as "was
  observed". Harmless today (max cpu under 100ms across those 273) and filed
  because a cheap-today population is the kind that stops being cheap with
  nobody re-checking the assumption that made it ignorable.

completion_predicate_satisfied_by_the_empty_population
  `required_floor_outcome_is_clean` is eleven `.is_empty()` conjuncts with no
  denominator. The protection cited in the code is
  `claims_planned == claims_executed + not_attempted` -- at zero that is
  `0 == 0 + 0`: a TRUE invariant, advertised as the protection, vacuous in
  exactly the case it names. The adjacent `ExpectedRedRosterEmpty` refusal
  already implements the fix one file away, with its rationale written out.
  Structural vacuity established; reachability NOT established and the row says so.

by_name_evaluation_is_a_string_not_a_binding
  `run_in_context(ctx, "gunbc.x.y")` type-checks against any ctx and any name.
  Caught on gunbc#10319 before push: a `gunbc.*` read through a `v2.workflow.*`
  frame, green under check, clippy and test, and it would have refused the
  ENTIRE floor -- because a fail-closed arm amplifies a targeting error rather
  than containing one.

THE PROJECTION IS KNOWINGLY STALE AND IS NOT REGENERATED HERE. This branch is
already driver-REFUSED and already owes a lap, so a stale projection changes
nothing about its state. `docs/design-failure-modes.md` is deliberately NOT
hand-edited: a hand-written projection is worse than an absent one, because the
lap's regen would then be diffed against a guess instead of against main's bytes.
The lap regenerates it.

Rows and roster verified by identity join, not count: 88 row files, 88 roster
imports, 88 roster entries, and the three sets are identical.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* Install the #10302 merge driver before integrating, so the conflict diagnostic is emitted by the current policy

The driver git executes during a merge is the copy already in the worktree, so
integrating main with the old script would have printed the pre-#10302 recipe
for a path whose repair route that very merge changes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* The merge driver that adjudicates the merge replacing it: an anti-correlation of one, not a timing hazard

A policy mechanism the toolchain reads from the WORKING TREE -- a merge driver, a
hook, a lint config, a codegen template -- acts at the version already installed.
So on every change that leaves it alone its instruction is current, and on the one
change that REPLACES it the instruction is guaranteed to be the retired one. The
more significant the policy change, the more certainly the author is handed the old
policy; there is no bad draw to be unlucky with and no window to shorten.

Distinct from verification_bound_to_the_revision_it_started_on, which inverts both
halves: there a moving SUBJECT under a stable observer, biting by timing, most runs
escaping. Here a fine subject and an observer stale BY CONSTRUCTION. Checked against
stable_citation_mutable_referent (an identifier addressing a container, not an
executable shipped in the tree it judges), authority_merges_unprotected_while_its_
projection_is_guarded (which side of a derivation a policy protects) and
admission_predicate_evidenced_from_inside_its_own_subject (a surface that cannot
represent its predicate being false) -- read to the bottom, variants included, since
that is exactly the check I skipped on the row folded one commit ago.

Specimen is this branch against #10302 at d6fb9d6: the printed repair route was a
four-step local whole-tree regeneration, and the merge being performed was the one
that delegates that regeneration to heal. Nothing in the output distinguishes the
retired recipe from the live one -- real driver, real refusal, real located
instructions, one version stale.

The mitigation is stated as a procedure rather than as vigilance: install the
incoming mechanism first as its own commit, then re-run the merge and read the new
diagnostic. Trigger at capability grain -- a tree-resident mechanism that detects its
own path among the incoming changes and REFUSES instead of instructing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* Three arms on the stale-policy-mechanism row, reached independently by three lanes in one hour

The independent rediscovery is itself the evidence for a distinct identity: three
lanes hit this inside an hour and none could find the class in the roster.

Arm one is the author following the retired route -- one wasted regeneration.
Arm two, snappy-koi-879 on #10271, is the MIRROR and is worse: about to report a
landed capability as not having taken effect, from a correct reading of a stale
instrument. A false negative about a capability propagates and its correction
requires someone to disbelieve a direct instrument reading.
Arm three, neat-swift-219's merge-readiness gate, is the ENFORCEMENT INSTRUMENT: its
verdict field was IDENTICAL under both driver versions and only the instructions
differed, so the arm that decides was unchanged while the arm that explains was
wrong. Nothing in the output could have revealed it. Any long-lived checker holding
a cached copy of a versioned policy inherits this.

The remedy is snappy-koi-879's, quoted as theirs and receipted by neat-swift-219 who
executed it independently: take the tool from the incoming side with a one-shot
config override, never from the worktree. Including why it beats the obvious fix --
syncing the worktree conflicted on the very roster the tool adjudicates, so the
instinctive repair puts the checker into the queue it is checking.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RuWuQWB6MPkY7sNM4jEqAy

* chore: regenerate drifted generated artifacts (ci auto-heal)

* chore: regenerate drifted generated artifacts (ci auto-heal)

* chore: regenerate drifted generated artifacts (ci auto-heal)

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants