Skip to content

RLM-2b repair: typed launch-environment convergence scope whose plan terminal is FullyApplied (structurally omit runner-slot and activation axes) - #9961

Closed
gunbai-bot[bot] wants to merge 26 commits into
mainfrom
rlm2b-spark
Closed

gunbai-bot[bot] wants to merge 26 commits into
mainfrom
rlm2b-spark

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session fierce-moth-880.
Pushing to rlm2b-spark advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

gunbc-ci-auto-heal and others added 26 commits August 31, 2026 18:03
…nal is FullyApplied

The RLM-2b plan run over srv1 landed
`partially_applied|33|slot=31 cap=0 timer=0 fabric-cell=0 activation=2`. Thirty-one
of those refusals are REFUSED-REMOVAL on runner slots whose ownership no provenance
signal establishes; two are the runner-service activation stall every production
caller supplies. Both belong to CI runner capacity and to its own convergence plan
(docs/plans/runner-service-capacity-convergence.md). Neither says anything about
whether the launch environment is converged -- and gunbc.roadmap_launch_deployment_receipt
accepts only FullyApplied, so RLM-2 could not close for reasons outside its subject.

The scope was answering for a wider resource set than the question, so the fix is to
make the question's resource set nameable rather than to relax the threshold.

WHAT LANDS

`FleetConvergeScope` gains `LaunchEnvironment` and `FleetConvergeRequest` gains
`LaunchEnvironmentConverge { host, observed_timers, observed_caps, observed_fabric_cells }`.
The arm has NO runner-slot field and NO activation field: not an empty list (which is
a positive claim that the host has none, and licenses removals -- the empty-observation
narrow this module already refuses one layer down), and not a selected-then-excused
refusal. The invalid state has no constructor.

Making that honest required moving `observed_activation_readiness` INTO the
`FullHostConverge` arm and turning three functions from loose-family parameters into
folds over the request:

  - `fleet_converge_apply_terminal(request)` -- each arm counts exactly its own axes.
  - `fleet_converge_apply_shell(request, terminal)` -- each arm emits exactly its own
    sections; a launch-environment script has no slot install and no activation lines.
  - `fleet_converge_plan_axis_lines` / `fleet_converge_plan_refusal_counter_lines` --
    lifted out of the full-host fold so the reviewed body and the executed script read
    one request, and so a counter row exists only for a selected axis.

While the axis set was a property of the CALL rather than of the plan, a narrower scope
could only be expressed by passing something for axes it had not selected. That is the
shape this commit removes; the module's own annotations had already ruled that the
apply-side predicates take the request for the same reason.

The artifact fold is factored into `fleet_converge_plan_artifact_of_request`, with the
full-host, launch-environment and allocation-store entries as constructors into it, so
there is one authority for the subject, the lease and the bundle digest. The
allocation-store fold's literal `FullyApplied` becomes a call to the same terminal.

Scope flows to the receipt unchanged: `scope_wire` and the member-set fingerprint come
from the subject, so a launch-environment plan with zero refusals lands `fully_applied`
honestly and RLM-2's join reads it without re-deriving anything it cannot observe.

CLI AND WORKFLOW

`fleet_converge_plan_wet` and the new `fleet_converge_launch_environment_plan_wet` are
one entry point under two scopes: the run binding, expected-revision and expected-host
admissions, the generation lease and the receipt mint are obligations of PLANNING, so
there is no second copy of them. The plan path now routes through
`observe_fleet_converge_request_wet`, the observer apply already used -- a net deletion
of a second reading of the host. The launch-environment arm does not call the slot
observer, because its arm has no field to put the answer in.

`.github/workflows/fleet-converge.yml` is regenerated from its .dag authority with a
`launch_environment_plan` mode beside `allocation_store_plan`. Default stays `plan`;
roadmap_belt and the srv fleet callers keep full-host, unchanged.

`roadmap_launch_deployment_receipt`'s FullyApplied-only acceptance is untouched.

EVIDENCE

dag/test/claim/fleet/fleet_converge_launch_environment_scope_witness_test.dag, eleven
claims, every one a PAIR over the same host observation so a red is attributable to the
scope rather than to the harness. Executed via claim_batch on this tree: 11/11 PASS,
and the 66 existing fleet_converge_plan claims plus the 13 runner_service_activation
claims stay green (90/90) -- no behaviour change for full-host.

THE DISCRIMINATING RED, RUN RATHER THAN ARGUED. The wall was perturbed into exactly the
wrong fix -- the launch-environment terminal selecting the slot and activation axes and
passing empty observations for them -- and 4 of the 11 went red
(`..._is_fully_applied_where_the_host_scope_is_not`, `..._terminal_wire_is_the_token...`,
`..._detail_has_no_slot_or_activation_position`, `..._plan_body_carries_only_its_own_axis_counters`)
while every full-host control stayed green. The perturbation is reverted.

One control caught this commit's own prose: the apply-script claim first matched the bare
spelling `runner-slot` and went red on the script's preamble note naming the omitted axes.
It asserts the emitted SECTION MARKERS now; the annotation records why, because a check
that cannot tell a section from a sentence describing its absence would dictate the prose.

WHAT IS NOT ENROLLED, AND WHY. The structural half -- that a launch-environment request
carrying a slot or activation position has no constructor -- is DESIGN 4b rung 4, and its
executing evidence is the exhaustive matches over `FleetConvergeRequest`: adding an axis
makes the terminal, the apply shell, the baseline text and the axis lines fail to compile.
A fixture-authored RED is expressible (`compile_dag_diagnostic_census` compiles a synthetic
source through the real acceptance path) and is deliberately NOT enrolled: a carrier calling
that builtin declares `ReadsLiveTree` truthfully, and the required floor DECLINES every
ReadsLiveTree identity before the fold (gunbc.guarantee_probe_corpus, measured 2026-08-22).
Enrolling it would add a never-executed identity that reads as coverage. The trigger is that
arm's deletion, which v2.workflow.required_floor already stages.

ONE OUTPUT CHANGE TO THE FULL-HOST PLAN BODY: it gains a `# scope=scope:full-host` row.
The plan.txt a reviewer reads carried no scope at all, which is fine while one scope
exists and is not once two do; carrying it for one scope and not the other would be the
fork. It changes the bundle digest of a freshly minted plan and nothing that compares
across runs.

Out of scope, untouched: the 31 surplus slots, runner-slot ownership grounding, and the
activation observation transaction.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
…control, and the structural dependency argument

Answers the controlling reviewer's stated bar. Five additions.

MUTATION CONTROLS. The scope apply routes on is read back from subject_scope.txt, so
the ways that file can lie are separate defects with separate remedies and are asserted
separately. (a) A mutated persisted wire -- truncated, respelled, empty, or extended --
refuses as ApplyScopeUndecodable rather than choosing a scope; defaulting to FullHost
would widen apply from one resource family to every family on the host, invisibly.
(b) A launch-environment observation and a full-host observation of a slot-less host
agree on every MEMBER, so a fingerprint over members alone would admit one against the
other; the scope row is inside the hashed baseline, so it does not. The claim is a
conjunction: each side's OWN fingerprint still admits, which is what makes the refusal
attributable to the crossing rather than to a fingerprint that matches nothing.
(c) The two crossing claims now pass each plan's REAL fingerprint instead of a dummy,
so they establish that scope is judged BEFORE the member set and refuse before actuation.

THE PRODUCTION-SHAPED CONTROL. The incident's exact observation is reconstructed from
the same authorities the live plan used -- srv1, the thirty-one surplus slot artifacts
(jit-runner.sh, runner-liveness-reconcile.sh, srv1-22..50), the desired caps, and the
activation readiness every production caller supplies. Under FullHost it derives
refused_axis_count 33 with slot=31 activation=2 cap=0 timer=0 fabric-cell=0 -- the run's
terminal, re-derived rather than transcribed -- and the SAME host observation under
LaunchEnvironment is FullyApplied, for no reason other than that those positions are
absent from the type. The thirty-one names are spelled out rather than generated from a
range, because for a control whose content is the number 31 a range would let a boundary
slip unobserved.

AND THE EXCLUDED FAMILIES STILL REFUSE LOUDLY under the scope that owns them: the
full-host plan body still carries REFUSED-REMOVAL runner-slot, OwnershipUnknown,
# slot-refusals=31 and # activation-refusals=2. The narrowing removed an obligation from
RLM and removed nothing from the fleet program.

THE DEPENDENCY ARGUMENT, COMPUTED RATHER THAN ASSERTED. That the deployed roadmap
service and belt path does not consume a runner unit or activation as a selected effect
is decided by a join over two populations that are both derivable, not by prose. The RLM
side is deployment_owned_steps_retract_order(deployment_spec_srv1()) -- every path the
live deployment installs, owns and retracts. The runner side is runner_slot_unit_name
over srv1's committed slot identities plus the unit template, from gunbc.runner_unit.
They are disjoint, and no owned path carries the actions-runner@ prefix at all. A
non-degeneracy guard rides with it: both populations are asserted nonempty in the same
claim, because a disjointness claim over an empty set is free and would go green if
either producer silently stopped answering.

ONE DEFECT OF MY OWN, FOUND BY RUNNING THE AFFECTED WITNESSES RATHER THAN BY REVIEW.
Three annotations sat INSIDE declaration bodies, which DESIGN 4c refuses at parse: only
module-item grain is modeled. They are hard errors that no other check reaches, and they
would have reddened the witnesses lane roughly thirty minutes into CI. They are moved to
the leading annotations of the declarations they describe, with no content lost.

BASELINE, BECAUSE THREE FAILURES IN THAT RUN ARE NOT MINE. A pristine origin/main
worktree reproduces all three identically: workflow_dispatch_choice_input_projects_options_list,
fleet_converge_workflow_has_build_job_needs_release_bins, and the
spark_serving_converge_slice entry resolve failure (serving_converge_plan.dag builds a
FleetConvergePlanArtifact literal with no apply_terminal field, and the witness does the
same). They stand on main and this branch neither causes nor repairs them.

EVIDENCE ON THIS TREE: 187/187 PASS, zero diagnostics, across the launch-environment
controls (16), fleet_converge_plan (66), runner_service_activation (13), the
fleet_converge cli / receipt / apply witnesses, roadmap_launch_deployment_receipt (44),
and workflow_capability_closure. The generated-artifact drift gate exits 0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
review 57936 (claude/opus-4-7) is right: the import block in
gunbc.fleet_converge_plan_cli already listed FleetConvergeScope, and this branch
added a second occurrence beside fleet_converge_scope_of_wire. My insertion
anchored on a neighbouring name without checking the block for the one it was
adding.

One line, nothing else in the diff.

NOT A RESOLVER ERROR, WHICH THE REVIEW HEDGED ON AND IS WORTH SETTLING: the
interpreter accepts it. Every witness was green with the duplicate present, and
the same block carries a SECOND duplicate -- fleet_converge_plan_content_hash_path,
at the block's lines 8 and 49 -- which predates this branch and is present on
origin/main. So the class is dead syntax that reads as an editing slip, exactly as
the review's second reading says, and not a refusal.

The pre-existing duplicate is left alone: it is not this PR's, and a drive-by edit
to it would be a polish rider on a branch being held stable.

Scanned every .dag file this branch touches for the same class; this was the only
one it introduced.

Verified after the deletion: 100/100 PASS, zero diagnostics, across
fleet_converge_plan (66), the launch-environment controls (16) and
fleet_converge_cli -- the three entries whose closures contain this module.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
Resolve three semantic conflicts in the fleet converge plan modules:

- fleet_converge_plan.dag: main's FleetConvergePlanArtifactOutcome, its refusal
  coproduct and its Spark-axis eliminator are preserved unchanged. The assembler
  becomes a constructor into this branch's request-driven artifact fold rather
  than a second fold beside it, so the full-host body and every scoped body come
  from one authority. The Spark wire line moves onto the arm that owns the axis.
  New fleet_converge_plan_outcome_of_request eliminates the Spark axis on the
  full-host arm only, so a Spark observation failure cannot refuse a
  launch-environment plan that has no Spark position.
- fleet_converge_plan_cli.dag: keep main's Spark admission gate ahead of the
  slot observation, plus this branch's activation field on the full-host request.
- serving_converge_plan.dag: take main's deletion of the second artifact
  assembler.

Also, per review 57966: the manifest admission computed path-tagged digests and
discarded every value -- a check whose presence looked load-bearing while its
result went nowhere, and a second digest scheme beside the bundle digest this
repository already owns. Replaced by recomputing the canonical bundle digest
over the actual bytes and comparing it to the run-bound receipt, with two new
controls for doctored plan/apply bytes under an honest hex claim.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
The persisted-member map was a table in the PR description. A prose map beside
the code is the parallel-ledger doc DESIGN section 6 warns about: it would have
gone stale the first time someone added a sidecar, and nothing could have turned
it red.

FleetConvergePersistedMemberAuthority has three arms and no wildcard --
receipt-bound, derived-and-recomputed, non-authoritative-presentation. There is
deliberately no arm for 'covered incidentally by another fingerprint', because
that is the sentence under which subject_member_set.txt and observed_baseline.hex
went unexamined: each was folded into a hash somewhere, so nobody asked whether
apply READ them, and it did.

The classification fold is total over the path and answers
UnclassifiedPersistedMember for anything it does not recognize, so an eleventh
sidecar fails loudly rather than acquiring whatever category a default arm
happened to name.

Five witness rows join the map to the behaviour it describes, so the two cannot
drift: every rostered member classifies; an unrecognized path is refused; each
receipt-bound classification is paired with the executed refusal naming that same
path; the derived members name the value they are recomputed into; and category
three is measured empty rather than asserted empty -- every rostered member is
asked, and none answers NonAuthoritativePresentation.

Path literals in the witness are replaced by the declared path symbols.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
Evidence corrections (A):

- admitted_with_no_diagnostic_change asserted a class-wide FieldNotFound == 0.
  These probes compile against the LIVE TREE, so that could redden from an
  unrelated future corpus diagnostic -- an assertion about the corpus wearing the
  name of an assertion about this field. It now asserts the exact identity naming
  the INSERTED field, plus the empty added/removed identity multiset.
- The initializer-analysis row proved only +1 total and +1 blocking. It now names
  its added identity exactly (InternalError|function:totally_undefined_fn_zz|true,
  measured rather than guessed), requires zero of it in the baseline and exactly
  one in the mutant, and requires every other identity unchanged.
- The plain-product sight control asserted blocking counts only, which permitted
  matching nonblocking residue on both sides. Its total cannot be asserted
  absolutely -- the census module's own closure contributes 95 nonblocking counts
  to BOTH sides, measured -- so the residue is pinned by difference instead, which
  is strictly stronger: total is clean + 1 exactly and every other identity is
  required equal.

Rung-language corrections (B, C, D): the source authority still carried the
withdrawn claims -- that the bad state has no spelling, that a launch request
carrying a foreign axis has no constructor, that the terminal folds exactly three
axes (it folds one), and the CLI line about having no field to put an answer in.
All are corrected in place rather than deleted, because the pattern is the lesson.
The non-interference header carried the superseded sibling-variant mechanism and
now carries the established one. The compile-control enrollment comment reasoned
from the deleted DeclinedLiveTree arm to routed-and-executed; it now states the
actual mechanism, changed-witness selection, and says plainly that an unchanged
fleet witness is not guaranteed to execute on a later PR.

Two gate failures the required run surfaced:

- .github/workflows/fleet-converge.yml was stale. Regenerated; the delta is the
  launch-environment step label, which still advertised caps and fabric cells --
  the axes this PR removed as foreign. A correctness fix, not just a hash.
- namespace-wave-admission refused two unadjudicated deltas, both mine:
  fleet_converge_plan_spark_typed_actions_wire_path moved from the CLI to the
  module that mints the bundle digest it is a member of. Rostered, with the two
  SPARK-PAIR-0 rows the same run reported CONSUMED removed by their own trigger,
  since this is the roster's next touch.

Also review 57982: a cited witness symbol was spelled with a witness_ prefix the
test does not carry.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
…pus number

Two stale descriptions, both flattering, both removed.

The compile-control source carried two contradictory paragraphs beside each
other: a newer one measuring that the census module's own closure contributes a
common nonblocking population to BOTH sides of the plain-product pair, and an
older one still asserting that absolute total-zero assertions are honest there
because the closure "really is empty". The older paragraph is deleted. The
implemented logic was already the paired one; only its description was wrong.

The surviving description also overstated the result. "Strictly stronger than the
absolute" is false: a genuinely clean total-zero-versus-total-one pair would also
prove the ABSENCE of all common residue, which a paired delta cannot claim. The
accepted formulation is that the paired identity-multiset delta is stronger than a
net-count comparison and is the strongest SUBJECT-RELATIVE control available under
a shared nonblocking closure residue.

The residue count is no longer written in prose. It is a corpus property, and
writing it down makes an acceptance number out of it -- the same transcription
DESIGN warns against. The paragraph now names the instrument that reports it.
every_rostered_persisted_member_is_classified asserted the roster length at ten.
That literal was a measurement of the same tree it was checking: automate its
update and the row collapses to measure() == measure(), which is the change
detector DESIGN forbids as an oracle. Review 57997 caught it.

The identity join over the roster is the whole content of the row. Non-vacuity is
kept as a positive bound rather than an equality, because `all` over an empty
roster is true for free and a roster that silently stopped being populated would
otherwise satisfy the row without classifying anything.

The second finding in that review -- the acknowledged-unenforced "22 declarations,
22 entries" count in ci_spec, bumped 21 to 22 here -- is pre-existing, is flagged
by its own comment, and is not repaired under this brief.
… its three cost-shape defects

The required floor's own cost artifact (run 33459143928 at 1ac3485) falsified the
premise this PR previously argued from. Eight of the eleven non-terminal rows cost
6-10ms and were only collateral of a budget their neighbours consumed; the floor uses
batch clamps rather than a per-witness wall; and the 47-183s figures quoted earlier were
workstation numbers that do not describe the runner.

Only three rows are genuinely expensive, and they were the three most expensive
witnesses in the whole 3426-row run: 13532ms, 14044ms and 19342ms against 488ms for the
next-worst row. A census of every decl_facts consumer under dag/test/claim shows why --
every witness outside test/claim/long walks a fixture pool, and this was the sole
whole-production-corpus walk sitting on the per-PR floor.

Fix the cost shape before re-homing anything, so the cadence row carries a measurement
of the subject rather than of a defect:

  - the copied accumulator in sites_constructing is gone (DESIGN section 6 prices this
    regardless of the realized n, and the roster it feeds is expected to grow)
  - the corpus is folded once carrying both targets, not once per target
  - the dotted suffixes are built once instead of per Atom node

The double fold has a visible receipt: pre-fix the sentinel row cost 1.43x its siblings
because it walked twice; post-fix all three measure within 0.8% of each other.

Then move the module to dag/test/claim/long with its module path renamed to
test.claim.long.* (the floor's long_home_storage_agreement enforces
long_path_but_executing_module = 0, so path and module name must agree), and enroll the
three check_fns on FalsifierCadenceJob in the same commit. The pairing is load-bearing:
long/ is excluded from floor discovery at dir grain, and falsifier_cadence_surface_note
records that of 63 files under the two long/ dirs only 9 are enrolled while the rest are
enrolled nowhere -- a move without the enrollment converts deferred into unscheduled.

The eight compile-control check_fns stay per-PR unchanged. No exemption, no declared
drop, no adjudicated non-terminal.

A fourth candidate was tested and rejected rather than shipped: identity_deltas_empty_except
is a genuine quadratic, and an n*log(n) sort_by rewrite measured 183296ms before and
183296ms after. The census dominates, not the fold.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
…e blocker honestly

c6c57ab moved this module under test/claim/long and enrolled its three check_fns on
FalsifierCadenceJob. That enrollment was wrong and is reverted here.

FalsifierCadenceJob has no executing realization. main carries fleet-converge.yml,
fleet-desired.yml and witnesses.yml, none with a schedule: trigger, and there is no
falsifier.yml -- gunbc.deleted_cadence_reference_census records the cadence as
"scheduled by .github/workflows/falsifier.yml, deleted at 611fd02 (#8283,
2026-08-15)". So the enrollment would have moved three witnesses off an executing
surface onto one with no executor, while reading as coverage. That is the bare
de-enrollment falsifier_cadence_surface_note says re-homing never is.

Two reasons nothing catches that, both filed as findings outside this PR: the surface
note is not among the twelve sites in the deleted-cadence census even though it is the
live re-home destination, and enrollment_is_scheduled answers structurally on the
surface's name, so the walls that police bare de-enrollment check that a row rides A
surface and never that the surface executes.

What is kept from that commit is only the cost work, which stands on its own:

  - the copied accumulator in sites_constructing is gone (DESIGN section 6 prices this
    regardless of realized n)
  - the dotted suffixes are built once instead of per Atom node
  - one fold per target, NOT the pair fold c6c57ab introduced: only the sentinel row
    needs two counts, so the pair fold made the two single-target rows compute a count
    they never read

Two false sentences are deleted rather than softened. One claimed three rows converging
within 0.8% as a receipt for the pair fold; the measurement showed three rows doing
identical work, not less work, so there is no true version of it. The other claimed
eight sibling rows "cost 6-10ms each", which came from reading wall_ms on rows the floor
had marked verdict_reached=false, where the diagnostic states the cost is UNMEASURED and
above the budget with no upper bound. The file now quotes no cost figures at all and
names the floor's artifact as the re-derivable instrument instead.

The annotation states the landing state without implying a plan: these witnesses exceed
the per-witness budget, both arms of the floor's remedy sentence are unreachable on this
tree, and the blockers are filed elsewhere. No re-home is claimed and none is pending.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
…used witness executed

Both findings from codex review 58047, both confirmed against the tree.

FORKED EDGE PREDICATE AND FORKED WALKER. This module declared its own
edge_is_construction (match on Named { name } == record_construction_spelling) and its
own fold_node algebra to count target constructions. v2.std.decl_facts_skeleton already
owns that interpretation as skeleton_edge_is_construction_spelling, and already walks a
node with it in skeleton_atom_lexeme_census_fold, whose construction_spelling_lexemes is
exactly the population this census needs. The review named the predicate; the walker was
the same defect one level up, so both are dissolved rather than only the one cited. The
ConstructionCount type, the predicate and the algebra are deleted and the count is now
count_where over the skeleton's census.

Semantics are preserved and the discriminating control still holds: the roster is still
exactly the two declarations, the total is still two, and the sentinel row still sees
FullHostConverge constructions, so the walk is proven non-empty rather than passing
vacuously.

A REFUSED WITNESS WAS BEING CITED AS EXECUTED. gunbc.fleet_converge_plan introduced the
site census under a heading reading "what is executed rather than read off the
declaration". That witness is BUDGET-REFUSED BEFORE VERDICT by the required floor, so it
establishes nothing at the gate grain, and presenting it as executed evidence was rung
inflation in a load-bearing file -- worse than sitting low, because an inflated class
never ranks for climbing.

The bullet now states that it is NOT ESTABLISHED AT THE GATE, that passing when run
directly is not the same claim, and that WHERE construction happens is currently covered
by review of the two named declarations and by nothing executing. The guarantee that does
hold is the non-interference matrix, which executes on the floor and passes.

This lowers the claim; it does not fix the underlying defect, which is not fixable inside
this module. Both blockers are named in the annotation: the required floor tests
changed-witness membership before the long-home decline, so the move to a lane declaring
its own ceiling cannot be performed; and FalsifierCadenceJob, the lane that would declare
one, has no executing realization.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
… probes actually execute

The eight excess-field probes were BUDGET-REFUSED BEFORE VERDICT by the required floor on
its 8000ms per-witness wall, so they established nothing. The cause was the probe source:
each one imported gunbc.fleet_converge_plan and therefore compiled that module's whole
production closure. The control was already in the same file -- two rows of identical
census machinery passed at 11ms and 0ms because their probe imported a small closure.

The subject was wrong, not just the cost. The compiler does not know
LaunchEnvironmentConverge is special: "a payload-carrying coproduct arm literal receives
no unknown-field judgment" is a SUBSTRATE fact that had been pinned to a production type
by accident of where it was first written. DESIGN section 3 puts a fact's home at its
layer, so this moves to its own. The launch-specific claim was never carried here; it is
carried by test.claim.fleet_converge_launch_scope_non_interference, which executes.

THE FIXTURE IS TWO MODULES ON PURPOSE. test.fixture.payload_arm_excess_field.carrier
declares the arm; the synthetic probe imports it and constructs it. Declaration and literal
therefore live in different modules, which is the configuration a real construction site
has -- a single-module probe would have measured the local-declaration resolution path and
reported a rung for a path production does not use. The carrier declares TWO arms because a
single-arm coproduct is a type alias here and refuses at the importer, which would have
reddened every probe for a reason unrelated to the field under test.

WHAT THIS GRAIN CANNOT SEE is declared in the annotation beside what it establishes: it
says nothing about which fields a production constructor supplies, nothing about name
resolution (variant spellings resolve corpus-wide, and a same-spelled arm in another module
is a case this fixture does not construct -- the sibling record_construction_census family
models that homonym case deliberately and this one does not), and nothing about arm shapes
the carrier does not express.

Renamed throughout to the real subject: module test.claim.payload_arm_excess_field_admission,
file moved to match, no launch vocabulary in any check name. A name promising a
launch-specific claim over a fixture-grain mechanism would be the
diagnostic_name_mechanism_silent class. The four axis-named rows are now four distinct
arbitrary names; at this grain the names ARE arbitrary, so those rows are weaker per-row
than their production-grain predecessors while establishing the same fact -- and unlike
their predecessors they reach a verdict.

The discriminating controls survive the move: the plain-product probe still yields
FieldNotFound, so the zeros on the payload arm remain a real property rather than a blind
harness, and omitting a required field still reds.

THE THREE SITE-CENSUS ROWS DO NOT MOVE. They are a claim about which sites in the REAL tree
construct the arm, and a fixture standing in for that would be the empty-observation narrow.
They stay refused. This takes interrupted_before_verdict from 11 to 3; that is NOT progress
toward a green floor, it is eight witnesses moving from establishing nothing to establishing
something. CI stays red and both escalated blockers stand unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012ZHWK38CsX9K77f3HS7hMw
…rather than re-homed

test.claim.fleet_converge_launch_scope_constructor_site_census is DELETED, and what
it covered -- WHERE in the corpus a LaunchEnvironmentConverge request is constructed --
is REMOVED by this commit. Not preserved, not deferred, not covered elsewhere. Nothing
executing stands over that question after this commit; review of the two named
declarations is what is left.

IT ESTABLISHED NOTHING AT THE GATE, ON ANY HEAD THAT CARRIED IT. Every required floor
run over a head carrying the module reports its three identities as
standing=planned-without-terminal-verdict / outcome=budget-refused-before-verdict --
runs 33452449083, 33459143928, 33464344273, 33469217185 and 33472882885, read from the
runs rather than transcribed. A row preempted before verdict asserts neither pass nor
fail, so the enrolled census informed the gate on no run while being counted as an
enrolled witness: the inert shape DESIGN 4b names, which is worse than absence because
it reads as coverage.

BOTH REMEDY ARMS THE FLOOR ITSELF NAMES ARE CLOSED TO A CHANGE MADE HERE. "Reduce the
cost" cannot hold while the subject is the corpus: this was the only
whole-production-corpus decl_facts walk under dag/test/claim -- every other consumer
there walks a fixture pool -- so the import-closure reduction that brought this PR's
other eight probes inside the budget does not reach a walk whose n IS the corpus.
"Move it to a lane declaring its own ceiling" is unreachable for a different reason,
which is not this branch's to fix: the floor's selector tests changed-witness
membership before the long-home decline, so the very edit that performs the move also
selects the witness and refuses it on the budget the move exists to escape. The
cost-debt roster is not a third arm: it is an operator shrink-only contract that admits
no identity the floor did not already discover.

NO SECTION 4b(3) ROW IS OWED, AND THAT WAS CHECKED RATHER THAN ASSUMED. A declared rung
drop presupposes a rung that executed evidence established. These rows reached a verdict
on no run of any head that carried them, on the evidence above, and the module never
reached main. There is no rung to drop, so a drop row would be a claim about a
guarantee this repository never had.

RE-FILED AT node://adhoc-cfdf3366-bc3, and its trigger names capabilities rather than
artifacts, both required before it can start: a floor selector able to route a CHANGED,
cost-bound witness to a lane declaring its own ceiling; and a substrate-readable
per-field label on record-literal children, sufficient for a witness to assert the exact
field-name set of a named construction site. A patch to any one file satisfies neither.

The annotation in gunbc.fleet_converge_plan that cited the census is rewritten in place
to say what is now true -- that the site question is covered by nothing executing -- so
the file does not carry a citation to a deleted module or an unearned bullet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
One conflicting file, and it is the merge-scoped admission roster rather than a
disagreement about code: main ran its own dissolution pass over
NAMESPACE_TRANSITION_ADMISSIONS while this branch removed the consumed SPARK-PAIR-0
rows and added the RLM-2b relocation row.

Resolved by union-then-shrink, which is the only resolution that is correct in both
directions: an unadjudicated row refuses THIS PR before merge, and a stale row refuses
EVERY PR after, so taking either side wholesale breaks someone. Main's shrink history is
kept whole; this branch's duplicate paragraph for the same SPARK-PAIR-0 consumption is
dropped, because main already performed that deletion and two ledger entries for one
event would be two authorities; and the RLM-2b addition stays, since its own trigger --
this PR merging -- has not fired. The ordinal is renumbered LAST, from the settled row
set, so the heading is derived rather than guessed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
…uction spellings, not for every atom

THE ARGUMENT THIS COMMIT WITHDRAWS IS MY OWN. The deletion commit said the census's
cost was subject-shaped -- "n IS the corpus" -- and therefore irreducible. That is an
argument about the WALK, and it was made without measuring what the witness REACHES FOR,
which is the separable half and the one DESIGN section 6's bare-minimum-cost rule is
written to catch. The census is restored and the reduction is applied.

WHAT IT WAS REACHING FOR NEEDLESSLY. The per-declaration fold consumed
skeleton_atom_lexeme_census_fold, whose AtomLexemeCensus materialises EVERY atom lexeme in
a subtree and appends both lists at every step. This census reads only the
construction-spelling members, so a single-spelling question over the production corpus
paid for the corpus's entire atom population and for the list copies on top of it.
v2.std.decl_facts_skeleton now also projects that same edge-provenance fact as a count:
skeleton_construction_spelling_count_where carries one Int and no list, takes the "names my
target" predicate as a parameter so no naming convention moves into std, and lives beside
the list projection so the fact keeps one authority rather than gaining a second walker.

THE SUBJECT IS UNCHANGED, AND THAT IS THE POINT. Same pool roots, same production corpus,
same over-approximating authored-spelling grain, same three verdicts, same roster of two.
A cheaper witness over a smaller subject would have been the empty-observation narrow;
this is the same question asked without acquiring what it never reads.

THE MEASUREMENT THAT DECIDES THIS IS THE FLOOR'S, NOT A LOCAL RUN. A local claim_batch
probe established the closure half -- the module's imports resolve in ~2s and the
closure-only control reaches a verdict at cpu=0ms, so closure acquisition is not what was
refusing these rows -- but the walk half could not be measured in that frame: the probe
host has 7 GiB and post-resolve RSS is already 5.4 GiB, so every whole-corpus run there
was OOM-killed before a verdict. A number from a frame that cannot complete the work is
not a cost. The required floor is the instrument with the right frame and the right
accounting (marginal CPU, shared fill netted out), so this head IS the experiment: its
disposition line for these three identities is the answer, either a terminal verdict or a
second budget refusal. No figure is transcribed into the source for it.

If the floor still refuses them, the deletion returns as a final disposition on measured
evidence rather than on the withdrawn argument -- and the re-file's trigger is a lane with
a dated ceiling that actually executes the exact enrolled witness identity and returns a
candidate-bound terminal verdict.

Also in this head, from review 58080: fleet_converge_plan_content_hash_path joins the
explicit import list in gunbc.fleet_converge_plan_manifest. It is a DECLARED-dependency
correspondence repair (DESIGN section 3), not a name-resolution floor fix -- imports do not
bind here, the name is corpus-unique and pullable, and the use is a value reference rather
than a match arm, so it resolved before this edit and the floor was never violated.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
…s deletion is final, on evidence

REMEDY 1 WAS ATTEMPTED AND HAS FAILED, WHICH IS A RESULT RATHER THAN A SETBACK. d824d35
restored test.claim.fleet_converge_launch_scope_constructor_site_census with its reach cut
-- one Int per node through skeleton_construction_spelling_count_where instead of
materialising every atom lexeme of every declaration -- and with its subject deliberately
untouched. The required floor's own run on that head refused all three rows again:
standing=planned-without-terminal-verdict, outcome=budget-refused-before-verdict.

NO BEFORE/AFTER COST IS CLAIMED HERE, AND THE FLOOR'S DIAGNOSTIC IS WHY. A preempted row
reports interrupt_point, which that diagnostic states is a property of the BUDGET and not
of the row; both shapes were refused with cost=UNMEASURED and above 500ms with no upper
bound, so the honest comparison is of OUTCOMES, which are identical, and there is no
measured figure on either side to compare. What the run did measure is memory: the
census's worst row grew the run's resident set by 2.01GB, the largest single claim in the
run, so this walk is not only over the CPU line.

WHAT WAS TRIED AND WHAT REMAINS, so the record does not have to be reconstructed:
closure acquisition was NOT the cause -- a probe carrying the census's exact imports
resolves in about two seconds and its witness reaches a verdict at cpu=0ms, so the
import-closure reduction that rescued this PR's eight excess-field probes does not apply
to this witness. The walk could not be measured off-gate at all: the probe host has 7 GiB
and post-resolve RSS is already 5.4 GiB there, so every whole-corpus run was OOM-killed
before verdict, and a frame that cannot finish the work does not produce a cost.
The floor's other remedy arm is a lane declaring its own ceiling, and none exists that
EXECUTES anything; moving the source into a non-executing home is the bare de-enrollment
the 2026-08-04 admission ruling forbids, deleting coverage while retaining the source.

SO THE DELETION RETURNS AS FINAL, ON MEASURED EVIDENCE. The coverage -- WHERE in the
corpus a LaunchEnvironmentConverge request is constructed -- is REMOVED. Not preserved,
not deferred, not covered elsewhere; what stands over that question is review of the two
named declarations and nothing executing.

skeleton_construction_spelling_count_where GOES WITH IT. Its only consumer was the census,
and a std projection with no consumer is dead weight that would also have owed a
corpus-scale agreement check against the list projection it sits beside -- two projections
of one edge-provenance fact are two authorities the moment they can disagree. Removing the
consumer removes the obligation rather than deferring it; the fact keeps one projection and
one authority.

NO SECTION 4b(3) ROW IS OWED. A declared drop presupposes a rung that executed evidence
established. These rows reached a verdict on no run of any head, in either shape, and the
module never reached main. There is no rung to drop.

RE-FILED AT node://adhoc-cfdf3366-bc3, and it cannot start until BOTH hold: a lane with a
dated ceiling that actually executes the exact enrolled witness identity and returns a
candidate-bound terminal verdict; and a substrate-readable per-field record-literal label
sufficient for a witness to assert the exact field-name set of a named construction site.
The first clause is deliberate: a lane that runs the row but reaches no verdict does not
satisfy it, which is exactly the state this census has been in throughout.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
…so it cannot be satisfied in form alone

THE TRIGGER AS WRITTEN WAS SATISFIABLE WHILE THE CAPABILITY STAYED DEAD, which is the
exact §4b(3) failure the rule about triggers naming capabilities exists to prevent. "A
lane with a dated ceiling that actually executes the exact enrolled witness identity and
returns a candidate-bound terminal verdict" can be met in FORM by standing up a lane with
a generous dated CPU ceiling -- and that lane would then die the way the off-gate probe
host died, leaving the trigger reading as fired while the witness still reached no verdict.

The reduction experiment measured a constraint the earlier trigger did not imply: this
census's worst row was the LARGEST single claim in its floor run by resident-set growth,
in gigabytes, while its CPU stayed UNMEASURED and above the per-claim ceiling with no
upper bound. Those are two different resources and only one of them was named. The clause
now requires a candidate lane to afford the row's measured resource cost rather than
merely a looser CPU number, and both facts are cited by naming the producing run rather
than by transcribing figures into an annotation no Accepted program can read.

This also makes the two halves of the evidence corroborate instead of merely coexist: the
gigabyte-scale growth is why every off-gate probe was OOM-killed on a 7 GiB host before
reaching a verdict, rather than two unrelated observations about the same witness.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
…tion is really gone, and the roster gains a uniqueness wall

BOTH FOUND BY READERS, NOT BY THE GATE, AND ONE OF THEM CONTRADICTED MY OWN REPORT.

1. skeleton_construction_spelling_count_where AND ConstructionSpellingMatchCount WERE
STILL IN THE TREE. The previous commit's message says the projection goes with the census
and names that census as its only consumer; the source disagreed with it, which is worse
than either state alone. The cause was mechanical and worth recording: the addition had
been COMMITTED on the experiment head, so `git checkout -- <path>` restored HEAD's version
-- the one carrying it -- rather than reverting the addition, and I reported the intent
instead of reading the result. They are now actually deleted, leaving one projection of
the construction-spelling fact and no unconsumed second implementation.
This is exactly the residue the deletion existed to avoid: a dead projection introduced
for a refuted experiment, with no consumer and therefore no possible agreement check --
and no green can see it, because an unconsumed projection cannot make a disagreement
observable.

2. fleet_converge_persisted_member_paths CARRIED fleet_converge_plan_content_hash_path
TWICE. Review 58080 asked for one addition, the missing import; the edit that made it also
inserted the path into the roster below, where it was already present. A roster whose own
annotation calls it "a closed map rather than a lookup nobody enumerates", joined at
identity grain, cannot hold an identity twice and still be what it says it is.

WHY EVERY WITNESS STAYED GREEN OVER IT, which is the part that needed fixing rather than
the line. every_rostered_persisted_member_is_classified requires nonemptiness and that
every occurrence classifies, so a duplicate of an ALREADY-CLASSIFIED path satisfies it BY
CONSTRUCTION. The row passed for a reason unrelated to the property it names.

So the duplicate is removed AND the hole is closed: no_persisted_member_path_is_rostered_twice
asserts multiplicity PER IDENTITY over the real roster -- each member occurs exactly once --
with no length literal, because a count copied from the tree it checks collapses to
measure() == measure(). Its mutation control,
a_repeated_existing_identity_is_refused_by_the_uniqueness_wall, runs the same predicate over
the real roster with one existing identity repeated, which is precisely the defect committed
here, and requires it to refuse. Without that control the new green would be
indistinguishable from a check that cannot see a duplicate.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
… the word "wall" was inviting the higher reading

The new row asserts that every rostered persisted-member identity occurs exactly once,
and nothing about that makes a duplicate UNWRITABLE. The roster is a List<String>: a
repeated identity is still perfectly expressible, and safety depends on this row executing
and staying enrolled, which is DESIGN 4b rung 2 and not rung 3 or 4. Naming a raw list "a
closed map" does not elevate it -- a name is not a constructor -- and the annotation now
says so at the point where a reader would otherwise infer more from the word "wall".

The next-rung trigger is stated as the CAPABILITY rather than as an artifact: a
keyed-roster carrier whose construction admits at most one member per identity, so the
duplicate this row catches has nowhere to be written. It is deliberately NOT adopted here.
Generalizing on a single site trades a proven local wall for an admission problem, and the
bar for lifting the law into a shared carrier is at least two genuine closed-identity
populations; this repository has one today. Ordered sequences, bags, retry histories and
evidence transcripts may legitimately repeat a projected identity, so an all-distinct
helper applied by list-shaped resemblance would strengthen their semantics incorrectly.

Annotation only. No check, roster or predicate changes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
One conflicting file again, the same admission roster, but NOT the same shape as the
previous merge and the previous resolution would have been wrong here. Last time main ran
a DISSOLUTION and the resolution was union-then-shrink. This time main ADDED: seventeen
XL-0T rows (gunbc#9907) adjudicating a structural-text requalification, none of whose
triggers have fired. There is nothing to shrink on either side, so this is a PLAIN UNION
to nineteen rows -- main's seventeen and this branch's two.

BOTH NAIVE RESOLUTIONS FAIL SILENTLY AND IN OPPOSITE DIRECTIONS, which is why neither side
may be taken wholesale: dropping main's seventeen leaves #9907's delta unadjudicated and
the wall then refuses unrelated PRs, and dropping this branch's two leaves this PR's own
delta unadjudicated and the wall refuses this PR.

THE ONE FACT THAT COULD HAVE FLIPPED THIS BRANCH'S SIDE WAS CHECKED RATHER THAN ASSUMED.
Had the relocation landed independently, these two rows would owe deletion instead of
survival. Read from main directly: it carries zero RLM-2b rows, and
`fleet_converge_plan_spark_typed_actions_wire_path` is still declared at its old home,
`dag/gunbc/fleet/fleet_converge_plan_cli.dag`. The delta is still unadjudicated there, so
the rows must survive.

Ordinals renumbered LAST from the settled row set: this branch's paragraph becomes TWELFTH
behind main's ELEVENTH. Numbering before the rows are settled is what forces the next
conflict, and this file has now conflicted on two consecutive main merges.

ONE SENTENCE OF THIS BRANCH'S OWN PROSE IS CORRECTED, because main made it FALSE rather
than stale. It reported both deltas as "closure blast radius: 0 module(s)"; gunbc#9908
changed `closure_blast_radius` to `Option<usize>` precisely because a binding row is never
asked that question, so it now carries `None` and renders no clause. Quoting a measured
zero there would reassert the exact conflation that change removed.

The type change reaches nothing else here, verified by reading rather than by reasoning:
`closure_blast_radius` is a field of `NamespaceDelta`, constructed only in the adjudicator,
and these rows are `TransitionAdmission` values carrying label, subject and disposition.
`cargo check --release -p v1-compiler --lib` is clean on the resolved tree.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
…ous merge imported it

THE PREVIOUS MERGE PRESERVED SEVENTEEN ROWS WHOSE DECLARED LIFETIME HAD ENDED. The
paragraph declaring them states their dissolve-on trigger as "#9907 merging". #9907 merged
to main at 14:02:39. The merge commit that imported them was made at 14:12:13 -- ten
minutes after the trigger fired -- and carried them across anyway. They are removed here,
by their own trigger, which is the only thing that retires a row on this ledger.

THE ROSTER IS LIFECYCLE-MANAGED, NOT APPEND-ONLY, and this file says so twice about earlier
cohorts: rows are "removed by their own dissolve-on trigger, exactly as the seven shrinks
above". Base and head both carry the XL-0T qualification now, so no run can produce those
deltas, all seventeen report stale, and a stale row refuses EVERY unrelated PR in the
repository. That is why deletion is owed on the roster's next touch rather than whenever
convenient, and this merge is that touch.

THE MISTAKE WAS ASKING THE TRIGGER QUESTION OF ONE SIDE ONLY. The check was run carefully
against the rows being KEPT -- this PR's two, whose trigger is this PR merging, which has
not fired -- and it was never run against the cohort being IMPORTED. Both resolution
recipes this file has been given were therefore wrong for this merge: union-then-shrink
because it shrinks only what the previous merge taught us to shrink, and plain-union
because "preserve both sides" is not a safe default for a ledger with dissolution rules.
The rule that survives, and it is now recorded in the file itself: the resolved roster is
the old cohort, UNION newly live main cohorts, MINUS every cohort whose trigger has fired
as of the base being merged -- asked of each side independently.

NOTHING ELSE MOVES. The roster is this PR's two RLM-2b rows and nothing else; the other
sixteen files in this PR are byte-identical to defb324, verified per file by hashing each
against that head rather than by reading the diff. `cargo check --release -p v1-compiler
--lib` is clean on the resolved tree.

ONE THING DELIBERATELY NOT DONE: no explanation is offered for why the consumed-at-base
path did not refuse the previous head. I did not establish the mechanism and will not
invent one -- a stale baseline is a plausible cause and plausibility is not evidence. The
source-level lifecycle contradiction is sufficient to owe this deletion on its own, and if
the mechanism turns up it belongs in its own finding rather than folded into this fix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014aYqbapkp3MEjXYLDcXSc1
Current-main integration before the final required run, so the run measures this branch
against the floor and the compiler main actually carries. Clean merge, no conflict: the
three commits since e39d014 touch src/v2/workflow/required_floor.dag and
src/v1/05_emit_rust.dag with its emitted mirror, and none of this branch's seventeen paths.

TEXTUAL DISJOINTNESS IS NOT THE REASON THIS IS SAFE, and it is not being offered as one.
The paths that moved are the gate this branch is measured by and the emitter it is compiled
through, so the only thing that establishes anything here is the required run bound to the
resulting head. That run is the point of this merge.

The admission roster is untouched by both sides in this merge, so no cohort question arises;
had one, the rule is the one this file now carries -- old cohort UNION newly live main
cohorts MINUS every cohort whose trigger has already fired, asked of each side independently.
@gunbai-bot

gunbai-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Closing as a duplicate: rlm2b-spark points at exactly 17b14ee2d0656d4c5fe219a729cb60aba7ef3c79, the same commit as #9832's head, with no unique commits and an identical tree. This PR carries no work that #9832 does not.

Closing rather than leaving it open, because a duplicate PR of the same commit is a path around a blocking review rather than merely noise. Review 5070355515 is a native CHANGES_REQUESTED authored by the operator and it lives on #9832; a second PR of the same tree would let that head land without the review it is blocked by, and without the P1-4 repair now in progress.

Work on this change continues on #9832. — sent from tidy-swift-334

@gunbai-bot gunbai-bot Bot closed this Sep 1, 2026
@gunbai-bot
gunbai-bot Bot deleted the rlm2b-spark branch September 1, 2026 19:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants