Skip to content

Completeness is an identity join: the count comparison accepted a stale row standing in for an unrostered blob - #9976

Merged
gunbai-bot[bot] merged 2 commits into
mainfrom
session/clever-crane-462
Sep 2, 2026
Merged

gunbai-bot[bot] merged 2 commits into
mainfrom
session/clever-crane-462

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

What was asked

compiler_tests_rust_blobs_are_all_rostered is RED on main (43 ct_ declarations vs 40 rostered): establish whether it is unenrolled or held known-red, disposition the unrostered blobs, and make the completeness claim honest.

It is enrolled, not unenrolled

The identity sits in floor_expected_red_chunk_live_tree_admission in v2.workflow.floor_expected_red — held known-red. Its entry declares ReadsLiveTree, which in entry_eligible_for_discovery_skip_before_resolve means it never predict-skips, so it genuinely executes and genuinely fails on every required run. Nothing was silently unenrolled.

The gap was not the four the counts suggested

The witness asserted declared_fn_count(ct_) == rostered_count_for(v1.compiler.compiler_tests_rust) — 44 against 40 on the current tree. Joined by identity, the residues are of two different kinds:

Five live blobs unrostered:

  • ct_fixture_closure_rustc_discrimination_test
  • ct_import_lines_follow_resolved_binding_identity_test
  • ct_witness_carrier_declines_non_witness_expected_type_test
  • ct_generic_param_declines_fail_closed_unwrap_test
  • ct_shell_service_output_projection_known_hole_probe_test

One row that outlived its blob: ct_caret_parse_smoke_native_witness_tests, which #8532 deleted from the carrier while leaving the roster row standing.

This is the finding worth the PR. Rostering four of the five would have balanced the counts at 44 and greened the witness with one blob still unmarked and one row still naming a declaration that does not exist. The count was never the claim; it was a necessary condition of the claim being read as the claim. DESIGN §5 already says so outright: completeness is an identity join, not a count equality.

Disposition

All five are hand-authored Rust assertion blobs — the same class as their rostered neighbours — so they carry compiler_tests_rust_hand_assertion_scaffold_trigger. The stale row is removed. language_source_scaffold_roster_size stays derived; no literal moved.

The claim made honest

The witness now names the two residues separately — declared-not-rostered (a blob landed unmarked) and rostered-not-declared (a row outlived its blob) — and asserts each is empty, so the two directions red with distinct meanings and neither can pay for the other. Cardinality survives as a third conjunct answering the one question containment cannot: a duplicate within one side. The rt_ arm gets the same treatment and stays green.

head_before's structurally-unreachable Absent arm yields a spelling no roster row can carry rather than fabricating a plausible name — the failure arm refuses, it does not widen (§5).

The evidence does not stop at the repaired tree

A repaired population makes both live arms permanently green and the join indistinguishable from the count it replaced. So five discriminating controls run over authored fixtures, including the_join_refuses_equal_counts_with_different_identities — exactly the case the old form accepted (DESIGN §4b(1): a rung needs an executed RED plus an accepted positive control).

Delisted from the expected-red roster, since that roster self-empties on pass.

Executed evidence

gunbc run against the live tree. All ten witnesses in the file return true:

witness result
compiler_tests_rust_blobs_are_all_rostered true ← was RED on main
runtime_rust_blobs_are_all_rostered true
language_source_scaffold_roster_is_fully_dispositioned true
the_join_refuses_equal_counts_with_different_identities true
the_join_refuses_an_unrostered_blob true
the_join_refuses_a_row_that_outlived_its_blob true
the_join_refuses_a_duplicate_row_masking_an_unrostered_blob true
the_join_accepts_the_same_population_in_any_order true
reasoned_terminal_is_accepted true
pair_completion_spelling_binds_the_derivation_authority true

The four the_join_refuses_* rows returning true means the join actively refuses those populations — a discriminating RED, executed rather than asserted.

A note for anyone running .dag witnesses: this had to run in a session container. BuildBuddy runners expose no cgroup memory limit, so gunbc run refuses there with HostBudgetUnreadable under gunbc.host_budget_source rather than admitting against a machine-wide reading. Remote is fine for check/clippy; it cannot execute the interpreter.

Generated projections

DESIGN.md and docs/design-ledgers.md are regenerated through dag/gunbc/instruments/generated_artifact_gate.dag main_wet — one line each — carrying a new recurring-failure-mode row, compensating_errors_cancel_in_the_aggregate, whose recognition rule is: for any check whose sentence contains "every", "all" or "covers", ask what it would report if one member were missing from one side AND one phantom stood on the other.

claim_executor --required-regen also ran clean (first_generation_equal=true, planned=149 executed=149).

🤖 Generated with Claude Code

https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg

gunbc-ci-auto-heal and others added 2 commits September 1, 2026 23:39
…le row standing in for an unrostered blob

`test.claim.language_source_scaffold_index_test.compiler_tests_rust_blobs_are_all_rostered`
was RED on main and ENROLLED, not unenrolled: it sits in
`floor_expected_red_chunk_live_tree_admission` in `v2.workflow.floor_expected_red`,
and its entry declares `ReadsLiveTree`, which in
`entry_eligible_for_discovery_skip_before_resolve` means it never predict-skips.
So it genuinely executed and genuinely failed every required run.

THE GAP WAS NOT THE FOUR THE COUNTS SUGGESTED. The witness asserted
`declared_fn_count(ct_) == rostered_count_for(...)`, 44 against 40. Joined by
IDENTITY the residues are of two kinds: FIVE live blobs unrostered
(ct_fixture_closure_rustc_discrimination_test,
ct_import_lines_follow_resolved_binding_identity_test,
ct_witness_carrier_declines_non_witness_expected_type_test,
ct_generic_param_declines_fail_closed_unwrap_test,
ct_shell_service_output_projection_known_hole_probe_test) and ONE row that
outlived its blob -- ct_caret_parse_smoke_native_witness_tests, which #8532
deleted from the carrier while leaving the roster row standing.

Rostering four of the five would have balanced the counts at 44 and GREENED the
witness with one blob still unmarked and one row still naming a declaration that
does not exist. The count was never the claim; it was a necessary condition of
the claim being read as the claim. DESIGN section 5 already says this outright:
completeness is an identity join, not a count equality.

DISPOSITION. The five blobs are hand-authored Rust assertion blobs, the same
class as their rostered neighbours, and carry
`compiler_tests_rust_hand_assertion_scaffold_trigger`. The stale row is removed.

THE CLAIM MADE HONEST. The witness now names the two residues separately --
declared-not-rostered (a blob landed unmarked) and rostered-not-declared (a row
outlived its blob) -- and asserts each is empty, so the two directions red with
distinct meanings and neither can pay for the other. Cardinality survives as a
third conjunct answering the one question containment cannot, a DUPLICATE within
one side. The `rt_` arm gets the same treatment. `head_before`'s unreachable
Absent arm yields a spelling no roster row can carry rather than fabricating a
plausible name: the failure arm refuses, it does not widen.

THE EVIDENCE DOES NOT STOP AT THE REPAIRED TREE. A repaired population makes both
live arms permanently green and the join indistinguishable from the count it
replaced, so five discriminating controls run over authored fixtures, including
the equal-counts-different-identities case that is exactly what the old form
accepted.

Delisted from the expected-red roster, since that roster self-empties on pass.

Executed evidence, `gunbc run` against the live tree (BuildBuddy runners expose
no cgroup memory limit, so `gunbc run` refuses there under
`gunbc.host_budget_source`; this ran in the session container):
all ten witnesses in the file return `true`, including
compiler_tests_rust_blobs_are_all_rostered, and each of the four
`the_join_refuses_*` controls returns `true`, i.e. actively refuses.

DESIGN.md and docs/design-ledgers.md are regenerated through
`dag/gunbc/instruments/generated_artifact_gate.dag main_wet`, carrying the new
`compensating_errors_cancel_in_the_aggregate` recurring-failure-mode row.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg
Main moved to 99ace7a (#9946, selection_view_read_as_population), which
touched DESIGN.md and docs/design-ledgers.md — the same two generated
projections this branch touches. GitHub reported mergeable=CLEAN, which is not
evidence: it does not run this repository's generated-artifact merge driver, so
it reports a clean TEXT merge on projections whose bytes would then project
neither side's authorities. `git merge-tree --write-tree` is the authority, and
it refused with GeneratedArtifactConcurrentDivergence on both paths (gunbc#9969).

Neither projection is hand-resolved. The driver left both UNMERGED with the ours
side verbatim and no conflict markers, and both were REGENERATED from the merged
authorities via `dag/gunbc/instruments/generated_artifact_gate.dag main_wet`.
Both ledger rows survive the merge: this branch's
`compensating_errors_cancel_in_the_aggregate` and main's
`selection_view_read_as_population`.

Also adds the boundary sentence the class needed: the row now states explicitly
that NO SWEEP FOR SIBLINGS WAS PERFORMED, so the absence of a census reads as a
declared boundary rather than as coverage. The receipt establishes the class at
one subject and says nothing about the population — reading the row as a census
of aggregate-cardinality checks would be the same substitution it names.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg
@gunbai-bot
gunbai-bot Bot merged commit 7e1479e into main Sep 2, 2026
6 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/clever-crane-462 branch September 2, 2026 00:52
gunbai-bot Bot pushed a commit that referenced this pull request Sep 2, 2026
…ed-citation

Only the two generated projections diverged; the recurring_failure_mode roster
merged cleanly this time, because #9976's authority edit lands in the DESIGN
document's own prose rather than on the roster this branch appends to.

Neither projection was hand-resolved. Both were reset to main's side and
regenerated from the MERGED authorities, so the bytes are the projection of both
lanes' facts rather than either side's file. Result against main: one insertion
in each, zero deletions -- this branch's index bullet and ledger row, with
#9976's identity-join content intact in both files.
@briansrls
briansrls restored the session/clever-crane-462 branch September 2, 2026 01:05
gunbai-bot Bot pushed a commit that referenced this pull request Sep 2, 2026
…N with my blob in it

#9976 replaced the roster's count comparison with an identity join. Executed on
the merged tree: compiler_tests_rust_blobs_are_all_rostered returns TRUE -- the
three-blob deficit I reported is closed on main and my row satisfies the join by
identity rather than by count.

Roster conflict unioned (compensating_errors_cancel_in_the_aggregate, mine);
both projections regenerated, superset clean on both sides; mirrors at the fixed
point.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants