Repository navigation
BT-0: gunbc build gunbc — commanded exact build through the emitted CLI - #9775
Conversation
# Conflicts: # dag/gunbc/seed_growth_admission.dag # src/v1/stage0/src/main.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
The parent lane's read of the first draft is right — a shape says where the value goes, only a disposition says whether the two realizations answer differently on an input the corpus can reach, and this document is about to be cited instead of re-derived. 186 occurrences resolve to 181 real sites over 81 files plus 5 non-sites (4 inside `//` annotations, 1 inside a string literal carrying a probe program), which reconciles exactly with the parent's 187/82 as that count minus #9775's own known-red row. Dispositions, each measured rather than asserted: - AgreesUnderCompensation, 142. Its failure condition is an element type that is itself `Optional`, and the corpus declares five list-of-optional carriers in total, all in witness tests, none reaching a `first`. Zero harmed today — which is exactly why the class stayed invisible: the shape that dominates the corpus is the one the compensation covers. - Propagates, 36. Resolved one level out by following all 36 functions to their call sites: 72 callers eliminate by `match`, 2 tail-propagate into another `T?`, and 4 compare `== none`, which agrees only because a miss is `Null` on one side and `Absent` on the other and both compare equal to that one constructor. Zero harmed today, by a margin one constructor wide. - HarmedNow, 3, listed in full: `cache_facts_for_id` declaring `-> CacheInterfaceFacts` over a `first()` (with `cache_layer_plan_primary`/`_fallback` as sibling defects in the same module), and two `measure_count(m: .. |> first)` argument sites that agree while non-empty and diverge on empty. Three of 181 read alone argues the class is not worth repairing. It is the wrong denominator, and the method-spelling section already says why. Both filters over that population are now named beside their producers — 646/180 here, 655/178 by the parent's independent filter — because they disagree, and a disagreement is the reason to cite the producer rather than the figure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N8xvN1T1NKiJqCUqwEmDgK
# Conflicts: # src/v1/stage0/src/emitted_population.rs # src/v1/stage0/src/lib.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
# Conflicts: # src/v1/stage0/src/emitted_population.rs # src/v1/stage0/src/extdeps_languages_rust_emit.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
…across three seed generations Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Q7kxQnLVogzdgyRYTfpjEn
# Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v2/workflow/floor_expected_red.dag
# Conflicts: # src/v1/stage0/src/emitted_population.rs # src/v1/stage0/src/lib.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
briansrls
left a comment
There was a problem hiding this comment.
TECHNICAL-ONLY REVIEW at exact head ecfcc7435e1d5a86d7718a93749e8d3f26b8d53e — not merge authorization.
I find no new source/content blocker beyond the previously accepted exact subject d11ea319b74917f992f2c612ea605f5429e2d5e9. The branch-authored program is unchanged after that subject: the intervening commits are main integrations, with the three generated-projection conflicts resolved by regenerating from the composed authorities rather than by choosing a side. The exact-head required build then established first_generation_equal=true, planned/executed/adjudicated 150/150/150, declared-divergent only main.rs, and generated-artifact 35/35 adjudicated with 35 matches, zero drift/absence/unadjudicated. The full exact-head workflow is green.
So this PR is technically suitable to become a merge-queue entry without restarting its substantive investigation.
It is not a landing candidate now. Those receipts were produced for composition with pinned base 373b8d11a13d5fdae56b7db7a9e2cc83672fc1cc; current main is c4e498652fcf5522200a118079c50586349b38c2. The observed change between two consecutive base reads proves that a human check followed by an ordinary GitHub merge does not implement the required predicate. MERGEABLE/CLEAN and zero textual conflicts do not transfer the receipts to the new composed tree.
Landing remains HOLD until one qualifying mechanism constructs and tests the actual candidate and atomically refuses stale base: preferably a commissioned merge queue whose merge-group commit runs the complete acceptance packet, or an explicitly operator-authorized exact-tree/base-CAS actuation. On a queue route, enqueue this head and let base movement rebuild/retest the merge-group candidate; do not treat this review or the green PR-head run as permission for ordinary auto-merge.
briansrls
left a comment
There was a problem hiding this comment.
FRESHNESS ADDENDUM to technical-only review 5083921844: while completing that review, main advanced again from c4e498652fcf5522200a118079c50586349b38c2 to 7810e68b3ea12d29ad811a2f2a0e1023f0dcd241. The earlier comment's named c4e49865 was current when observed and is already historical. This does not alter the technical-content verdict; it further demonstrates that a human-observe-then-merge sequence cannot maintain the base-equality predicate. The HOLD is against every ordinary merge path until a merge-group candidate or atomic expected-base actuation supplies it.
# Conflicts: # src/v1/stage0/src/emitted_population.rs # src/v1/stage0/src/gunbc_cli_dispatch_surface.rs # src/v1/stage0/src/main.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
…the stage0 seed Second regen cycle. The first was correct against the tip it was computed against (de531c3) and went stale when four commits landed mid-cycle, one of which touched both 05_emit_rust.dag and its mirror. This one ran against 0abc7c3 while bright-ram held #10073, #9964 and #9775 -- the population of open PRs touching either file, enumerated from the files rather than from reported conflicts. The generated-artifact driver refused v1_compiler_emit_rust.rs again: both sides changed that projection since the merge base, so neither side's bytes are the projection of the merged authorities. Regenerated, not resolved. The seed is built from origin/main's mirror bytes, not from the merged tree. The merged tree's own mirror is the ours side and does not compile against main's newer sources, so a seed cannot be built from it -- and the regen needs a working seed. The seed is only the TOOL: it emits from the MERGED .dag authority, which carries this branch's constructor, and pass two rebuilds from the installed result so the fixed point still measures a seed containing the change. EVIDENCE, two passes, because pass one runs a binary predating the change it emits and can self-verify at divergence 0 for the wrong reason: pass 1 seed from main -> FAIL generated surface drift: v1_compiler_emit_rust.rs installed 1; main.rs skipped (declared_divergent=1, expected) pass 2 rebuild FROM the installed seed -> first_generation_equal=true, rc=0 census 222 candidate files vs installed mirror, 0 differing -- the regeneration is the subject, not the conflict list fixed point --required-regen-fixed-point rc=0 The tree committed here is the tree those checks ran against, established by content: sha256 of all 238 .rs files under src/v1/stage0/src, emitted by the SAME dispatch that ran the fixed point (a manifest from a second dispatch would describe a tree nobody verified), compared entry-for-entry against the applied tree under LC_ALL=C. 238/238 identical, both directions. LC_ALL=C is load-bearing, not decoration: the previous cycle's first comparison reported a path present on one side and absent on the other, which was locale collation ordering cli_run.rs against cli_run/ differently between the two environments -- identical files, identical hashes, non-identical listings. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G9q7HZqy1inoJYfnNdBB5J
# Conflicts: # src/v1/stage0/src/lib.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs
# Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs
What
gunbc build <program>reaches the exact product-build operation through the installed generatedCLI carrier. The modeled row owns the verb, operand, and realization; committed
main.rsdelegatesthrough
RetainedCliHostand contains no Build arm.BT-0P also closes the two blockers exposed by the first commanded cold build: a materialized source
tree has no ambient Git checkout from which
build.rscan derive version identity, and the producerand consumer previously interpreted one relative answer path against different roots.
Why
gunbc.devboot.buildcarried the intended production/reuse protocol but had no production consumer.The first real cold invocation reached its cargo producer and then refused: the materialized tree had
no
.git, whilesrc/v1/stage0/build.rscorrectly refused to stamp provenance it could not observe.The same run exposed a response-coordinate defect in which
CheckoutIndexToPrefixsucceeded underthe scratch repository while the reader searched under the caller root. These were latent blockers,
not evidence of a successful production path; BT-0P repairs both before BT-0 can claim cold success.
CLI construction and guarantees
CliArmRealizationnow drives the installed carrier. The former independent arm renderers aredeleted, and a known operation with no realization refuses.
AdmittedBootstrapOperationIdentityis a closed coproduct with one inhabitant. Runtime selectionuses the qualified whole-declaration identity and refuses partial declarations.
--dry-run buildrefuses before publishing a request or creating a receipt or artifact.derived from that receipt identity, so there is one uniqueness authority.
main.rsdivergenceboundary. The §4b row records the compile-time mitigation and the structural trigger: derive both
contracts from one authority.
Authority placement
Three facts have three homes:
gunbc.cli_dispatch_surface.extdeps.languages.rust.emit.__gunbc_dispatch_executor_prefix: gunbc data passed to the generic allocator.The first draft put Rust realization in the product-interface authority. Review caught that
ownership defect; the functions moved once rather than being copied. Both closure directions remain
clean:
src/v1does not reachv2.*/gunbc.devboot, anddag/does not importv1.*.BT-0P: provenance and answer coordinates
The build subject remains keyed by the existing Git tree object id, not by a commit. The injected
build identity is derived from that same
tree_oidand rendered astree:<existing GitObjectId wire>—for SHA-1,tree:sha1:<hex>. It adds no build-key axis.build.rsvalidates a suppliedmaterialized-tree identity, consumes it without consulting Git, refuses an invalid supplied value
instead of falling back, and retains the ordinary ambient-checkout arm. One build-script control
proves valid injected identity without Git; another proves invalid injected identity refuses rather
than falling back. A clean/dirty ambient control uses the same build-script executable and changes
only worktree state: the clean clone reports bare 40-hex commit identity and the dirty clone reports
the identical hex plus
-dirty.The answer repair makes writer and reader consume one exact derived output coordinate. The defect
was root relativity erased into a string:
exchange_out_dirproduced a caller-root-relative path,while
materialize_ref_treehanded it to a scratch-repositoryCheckoutIndexToPrefixoperation.Git therefore succeeded at a different location and the reader later substituted
ArtifactNotRetrievablefor the producer's actual refusal. The adjacentclient_repo_dirprosealready knew the roots differed; the distinction was not load-bearing in the type. The repaired
failure-fidelity control requires
ProducerRefusedRequestwith the producer's exact cause.One adjacent finding remains outside BT-0P:
extdeps.git.object_storesays the Git object-id wirerenderer belongs at the GitObjectId authority, but
render_git_object_id_wireactually lives ingunbc.merge_admission_subject. Build identity now makes that misplacement load-bearing as abuild-identity-to-merge-admission dependency edge. Relocating the renderer is the repair; this PR
does not create another spelling. The separate
git.oid.v1.*subject-digest atom is deliberatelyunchanged because it is part of the artifact-cache key.
Generated carrier ownership and generation role
gunbc_cli_dispatch_generated.rsis a synthesized non-module product. Its producer ownership isdeclared in
gunbc.regen_affected_setas an aggregate generated product owned byv1.compiler.emit_rust; it is not aBootstrapEdge, because that would also remove the emitterfrom
regen_generation_inputs/regen_generation_role_modulesand silently narrow future emitteredits.
Neither pre-existing generation-role arm was true.
AggregateGenerationInputwould assert that thecarrier bytes feed the next generation; they do not.
AggregateNonSeedGeneratedOutputwould deriveOutsideSeed;lib.rsembeds the carrier in the seed. Because construction was available, this PRadds
AggregateGenerationSubjectrather than declaring a rung drop.Enrolled evidence proves independently that the emitter remains a
GenerationInputproducer, thecarrier is a
GenerationSubject, the carrier isSeedEmbedded, it is absent from bootstrap productpaths, and its owner path occurs exactly once. The real host join through
convergence_surface_rolesandconvergence_plan_from_modelproves thatPromoteGenerationInputsdefers it,InstallSeedCompatibilityCutplans it with its seed-compatibleclosure, and
PublishNonSeedOutputsdoes not plan it.Interpreter Optional divergence found here
The allocator claims' first execution exposed that interpreter
first,last,get, andlookupdisagree with the
OptionalOfresult shape already declared bystd.algebra;map_getis thepositive control. This PR does not repair that shared seam. It enrolls
test.claim.cli_dispatch_surface.interpreter_first_returns_the_modeled_optionalas the sole newexpected red and records a capability-grain §4b trigger, including builtin parameter
cardinality/coercion.
The population and dispositions are an operator-authored roster in PR #9785's
docs/plans/first-optional-divergence-census.md. That document explicitly calls itself the rosterproducer; there is no executable/enrolled census symbol that re-derives it today. At
final-candidate composition, if the interpreter Optional divergence is still live, the
expected-red row remains enrolled and held. If a complete repair has landed and the exact
discriminator passes, the row is retired by its recorded trigger and the claim stays enrolled as
an ordinary passing regression control. The scheduling hold is not the row's trigger.
The required-floor history's 21→20 held-count change is fully accounted at identity grain. Main
#9710 retired
test.claim.declared_type_inhabitance_direct_call_witness.w_kernel_numeric_at_the_peano_nat_is_refusedby its recorded trigger and enrolled the renamed arrival
w_kernel_numeric_at_the_peano_nat_is_admitted_through_its_homomorphism; the arrival passes, as doall 12 claims in
self_host_peano_literal_operator_realization_witness_test. Departure, arrival,and roster retirement occurred together; nothing became unenrolled.
The previously inert
clean_version_identity_is_the_exact_commitfixture was also incomplete forproduct-built artifacts: its commit-only premise is in tension with
gunbc.devboot.subject, whichdeliberately forbids a bare commit SHA as a build-key axis. BT-0P adds arm-specific materialized-tree
and ambient-checkout controls instead of treating that fixture as coverage.
Regeneration and exact evidence subject
The authoritative acceptance subject will be one serialized landing candidate:
<FINAL_CANDIDATE_COMMIT><FINAL_ROOT_TREE_OID><BT_HEAD> + <PINNED_MAIN><PINNED_MAIN>Every final receipt below must name that commit and root tree. The cold/warm subject is keyed by the
exact root tree OID, so any tracked-path change—including a workflow-only change—creates a different
subject. An old cold receipt cannot prove production of the new tree, and warm reuse must follow
production of that same subject. No hand-maintained dependency list computes applicability for the
other arms either. Consequently no earlier arm is merge-authorizing evidence for a later tree.
Guarded landing checklist
The acceptance subject is the root tree
T, not the candidate commit identity. An earlierrevision of this section claimed a squash merge "synthesizes a different commit/tree after
acceptance". That is too broad and is corrected here: because this PR deliberately excludes the
commit SHA from the materialized-tree build subject, a different landed commit is expected and
harmless. Only a different landed tree is inadmissible.
The retained landing predicate is therefore three conjuncts, and the landed commit may be a
two-parent merge commit or a one-parent squash-shaped commit:
Landing must be guarded at the ref update, so that it refuses if
mainno longer equals thepinned base
<M>. Immediately before landing, record and prove all three admission conjuncts:git rev-parse <LANDED>^{tree}equals the tested<T>.git merge-base --is-ancestor <M> <LANDED>succeeds. The explicit lease can authorize anon-fast-forward update, so ancestry is an independent requirement.
refs/heads/main == <M>via exactly:git push --force-with-lease=refs/heads/main:<M> origin <LANDED>:refs/heads/main.The bare
--force-with-leaseform is forbidden because its expectation may come from a movedremote-tracking ref. A plain non-forced push is also insufficient because it tests ancestry rather
than equality with the reviewed base.
A squash-shaped landing is admissible, and does not require the tested two-parent commit
Ctoland. The exact equivalent is a precomputed one-parent commit
Sbuilt from the named tree andparent —
tree(S) == T,parent(S) == M— actuated through the same lease. That preserves linearhistory, the exact tested tree, and the atomic stale-base refusal together.
What is NOT admissible is an ordinary unguarded GitHub squash under this repository's present
configuration. GitHub's squash computes a new integration tree against whatever the base branch
currently is; its merge API can pin the PR head SHA but does not compare the base SHA, and this
repository's required-status rule is loose (
strict_required_status_checks_policy: false) androle-bypassable, so nothing supplies the missing old-base predicate. The failure sequence is then:
the packet proves
T, main advancesM -> M', GitHub integrates againstM', main receivesT',and the post-hoc comparison reports
T' != T— after an unaccepted tree is already published andconsumable by other automation. That cannot be repaired by regenerating afterwards: a regeneration
produces yet another tree and never establishes that the published
T'satisfied cold production,warm reuse, failure fidelity, reversal, the ambient control, or the floor at the moment it became
main. A post-landing
tree(origin/main) == Tcheck is required after any admissible mechanism,but it is an audit of a guarded actuation and never a substitute for the guard.
Qualifying mechanisms, any one of which supplies the missing predicate: a merge queue whose
merge-group candidate runs the complete acceptance packet; strict non-bypassable up-to-date status
checks carrying the final BT evidence; a fleet-wide hold covering the packet and the merge; or
operator-authorized direct CAS to the precomputed squash commit
S. Ordinary squash under thepresent configuration is not one of them.
Direct ref actuation requires explicit operator authorization in every case. A general permission to
merge one's own PRs through ordinary policy does not authorize replacing GitHub's PR merge operation
with a direct ref update. If no qualifying mechanism is authorized, stop at the merge boundary.
Final regeneration evidence to fill without changing the source head:
<FINAL_G0_TO_FIXED_POINT>v1_compiler_emit_rust.rscontains the carrier producersymbols before the generation that creates the carrier:
<FINAL_PRODUCED_EMITTER_CHECK>RenderEveryModule, zero content drift:<FINAL_ZERO_DRIFT>v1.compiler.emit_rust.emit_emitted_population_manifest, reached throughv1.compiler.emit_rust.emit_rust_selected:<FINAL_DECLARED_PATHS>total,<FINAL_SRC_MIRRORS>src/*mirrors,<FINAL_ADJUDICATED>adjudicated, plus declared-divergentmain.rs;Cargo.tomlis a declared path but not a Rust mirror<FINAL_FILE_SET_EQUALITY>The current pre-final observation is 151 declared paths =
Cargo.toml+ 150src/*mirrors, with149 adjudicated plus declared-divergent
main.rs. It is a prior observation, not a value to copyinto the final packet.
Development and preflight receipts — not merge authorization
Head
3ea80ffaae154a81ac1f1bf08b1632ca2d8ab2fbis pre-final diagnostic evidence only.33392133259passed all five jobs. Required floor: 3246 planned/executed/terminal, 3177 passed, 20 known-red-held, zero failed/interrupted,
known_red_now_passing=0,non_verdict_unenrolled=0,FloorClean. Claim-grain disposition showsboth allocator controls, bootstrap admission, aggregate ownership, and all three stage-boundary
claims passed; the interpreter Optional discriminator was known-red-held. Workspace-wide clippy
executed and passed.
RenderEveryModulereportedfirst_generation_equal=true planned=149 executed=149 adjudicated=149, with declared-divergentmain.rsexcluded.9c6aa3f24586dc6b69b4ce906456aab424f2f5b9a921e710431abbdb9c2ba5c1.0f6d54f67229113ac8f26bc4c70f0025fbd88801; receipt tokenfnv1a64-f70c8b201ac4ed79,reused=false, artifact digestb350a078aefb967a1dcda6d2f8d5d3900e81097d038a010a59be9fc37687431f. Independent digestmatched, the artifact executed, and
--versionreportedgunbc tree:sha1:<that tree oid>.reused=true, and thesame digest. It was not a preseeded substitute.
Producer and client exited 1; the client returned
ProducerRefusedRequestpreserving the exactproducer cause, never
ArtifactNotRetrievable.CliKnownOperationNoRealization. The reversed tree reached zero drift after generation 1 namedgunbc_cli_dispatch_generated.rsandgunbc_cli_dispatch_surface.rs, and generation 2 reportedfirst_generation_equal=true planned=149 executed=149 adjudicated=149. The identicalgunbc build gunbcargv exited 2 with the exact qualified-operation refusal; a fresh-directorycensus found only redirected stdout/stderr, with zero request, receipt, or artifact files.
Restoration named the modeled surface in generation 1 and the carrier in generation 2; generation
3 returned to zero drift at 149/149/149. Source and mirrors match
HEAD; the restored carriersha256 is
8594598fb25b3739323a229be172fb8e8e4eeeac85e882e84675852310aeed9dand the restored binary sha256 is the preflight binary digest above.
build.rsonce and ran that same executablein a fresh clone at root tree
0f6d54f67229113ac8f26bc4c70f0025fbd88801. Clean emittedGUNBC_BUILD_IDENTITY=3ea80ffaae154a81ac1f1bf08b1632ca2d8ab2fb; after changing onlyone tracked file, dirty emitted the identical commit plus
-dirty. Both stderr streams were empty.All five arms in this section are diagnostic only and cannot be promoted into final evidence.
Earlier focused receipts remain corroboration only: workspace-wide dry-run semantics measured the
same argv and exported cache root at 0 effect files in Hermetic mode versus 70 in Wet mode; Build
dry-run showed identical refusal bytes at emitter, installed-carrier, and runtime grains; allocator
collision and receipt/PID isolation controls each selected and passed one non-vacuous test.
Final acceptance receipts — fill on the serialized candidate
non_verdict_unenrolled:<FINAL_CI>--help,--version, Build dry-run no-effect, and semantic Run dry-run:<FINAL_BINARY_CONTROLS>.git: production command, exact tree identity, returned bytes,independent digest, execution, and tree-tagged version:
<FINAL_COLD><FINAL_WARM>ProducerRefusedRequest, never artifact retrieval:<FINAL_FAILURE_FIDELITY>artifact, and initiates no producer work; restore returns the original carrier bytes and green:
<FINAL_REVERSAL_AND_RESTORE><FINAL_AMBIENT_BUILD>Hand-Rust residue
The exact new production residue is modeled at declaration identity in
gunbc.bootstrap_operation_seed_growth:v1_compiler.cli_run.run_bootstrap_dag_operationv1_compiler.cli_run.bootstrap_invocation_receipt_pathv1_compiler.main.RetainedCliHostThe
CliDispatchHost for RetainedCliHostimpl is recorded as uncitable untilstd.decl_refgainsimpl-block identity. The current 86-file outside-manifest candidate set and its 3/83 leading-banner
diagnostic are pre-final observations and will be re-derived on the serialized candidate. The
repeated total of 86 across changing trees is coincidence from offsetting population deltas, not
evidence that the population was stable. This diagnostic is not a theorem that every generator
emits a banner, and the declaration roster does not depend on it.
Worker attestation
Generated-surface output-neutrality receipt
gunbc run --source-root dag --source-root src/v2 --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wetregenerated the full generated set on the composed branch and left no worktree diff. As an independent untouched-projection control,docs/design-rung-drops.mdwas blob-identical toorigin/mainata845ea5ecb9596df7c8a57b2aa81d9555901b47b. The shipped-consumer regression testshipped_build_command_reaches_the_generated_dispatcherexecutes the built binary, requires the generated dispatcher’s exact typed refusal, and is enrolled through the requiredrust-unit-testsall-targets job.Shipped-consumer planted-revert receipt
The generated-dispatch consumer control was exercised in both directions. Restoring the pre-routing private-parser
main.rsand executingshipped_build_command_reaches_the_generated_dispatcherproduced RED: Clap returned status 2 withunrecognized subcommand 'build'rather than the generated dispatcher refusal. Restoring the currentmain.rsmade the identical test PASS. The exact refusal text is deliberately load-bearing: a wording change must update this control intentionally, because matching only status 2 would accept both the generated dispatch path and Clap’s unrelated usage-error path.