Repository navigation
Completeness is an identity join: the count comparison accepted a stale row standing in for an unrostered blob - #9976
Merged
Conversation
…le row standing in for an unrostered blob `test.claim.language_source_scaffold_index_test.compiler_tests_rust_blobs_are_all_rostered` was RED on main and ENROLLED, not unenrolled: it sits in `floor_expected_red_chunk_live_tree_admission` in `v2.workflow.floor_expected_red`, and its entry declares `ReadsLiveTree`, which in `entry_eligible_for_discovery_skip_before_resolve` means it never predict-skips. So it genuinely executed and genuinely failed every required run. THE GAP WAS NOT THE FOUR THE COUNTS SUGGESTED. The witness asserted `declared_fn_count(ct_) == rostered_count_for(...)`, 44 against 40. Joined by IDENTITY the residues are of two kinds: FIVE live blobs unrostered (ct_fixture_closure_rustc_discrimination_test, ct_import_lines_follow_resolved_binding_identity_test, ct_witness_carrier_declines_non_witness_expected_type_test, ct_generic_param_declines_fail_closed_unwrap_test, ct_shell_service_output_projection_known_hole_probe_test) and ONE row that outlived its blob -- ct_caret_parse_smoke_native_witness_tests, which #8532 deleted from the carrier while leaving the roster row standing. Rostering four of the five would have balanced the counts at 44 and GREENED the witness with one blob still unmarked and one row still naming a declaration that does not exist. The count was never the claim; it was a necessary condition of the claim being read as the claim. DESIGN section 5 already says this outright: completeness is an identity join, not a count equality. DISPOSITION. The five blobs are hand-authored Rust assertion blobs, the same class as their rostered neighbours, and carry `compiler_tests_rust_hand_assertion_scaffold_trigger`. The stale row is removed. THE CLAIM MADE HONEST. The witness now names the two residues separately -- declared-not-rostered (a blob landed unmarked) and rostered-not-declared (a row outlived its blob) -- and asserts each is empty, so the two directions red with distinct meanings and neither can pay for the other. Cardinality survives as a third conjunct answering the one question containment cannot, a DUPLICATE within one side. The `rt_` arm gets the same treatment. `head_before`'s unreachable Absent arm yields a spelling no roster row can carry rather than fabricating a plausible name: the failure arm refuses, it does not widen. THE EVIDENCE DOES NOT STOP AT THE REPAIRED TREE. A repaired population makes both live arms permanently green and the join indistinguishable from the count it replaced, so five discriminating controls run over authored fixtures, including the equal-counts-different-identities case that is exactly what the old form accepted. Delisted from the expected-red roster, since that roster self-empties on pass. Executed evidence, `gunbc run` against the live tree (BuildBuddy runners expose no cgroup memory limit, so `gunbc run` refuses there under `gunbc.host_budget_source`; this ran in the session container): all ten witnesses in the file return `true`, including compiler_tests_rust_blobs_are_all_rostered, and each of the four `the_join_refuses_*` controls returns `true`, i.e. actively refuses. DESIGN.md and docs/design-ledgers.md are regenerated through `dag/gunbc/instruments/generated_artifact_gate.dag main_wet`, carrying the new `compensating_errors_cancel_in_the_aggregate` recurring-failure-mode row. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg
Main moved to 99ace7a (#9946, selection_view_read_as_population), which touched DESIGN.md and docs/design-ledgers.md — the same two generated projections this branch touches. GitHub reported mergeable=CLEAN, which is not evidence: it does not run this repository's generated-artifact merge driver, so it reports a clean TEXT merge on projections whose bytes would then project neither side's authorities. `git merge-tree --write-tree` is the authority, and it refused with GeneratedArtifactConcurrentDivergence on both paths (gunbc#9969). Neither projection is hand-resolved. The driver left both UNMERGED with the ours side verbatim and no conflict markers, and both were REGENERATED from the merged authorities via `dag/gunbc/instruments/generated_artifact_gate.dag main_wet`. Both ledger rows survive the merge: this branch's `compensating_errors_cancel_in_the_aggregate` and main's `selection_view_read_as_population`. Also adds the boundary sentence the class needed: the row now states explicitly that NO SWEEP FOR SIBLINGS WAS PERFORMED, so the absence of a census reads as a declared boundary rather than as coverage. The receipt establishes the class at one subject and says nothing about the population — reading the row as a census of aggregate-cardinality checks would be the same substitution it names. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 2, 2026
…ed-citation Only the two generated projections diverged; the recurring_failure_mode roster merged cleanly this time, because #9976's authority edit lands in the DESIGN document's own prose rather than on the roster this branch appends to. Neither projection was hand-resolved. Both were reset to main's side and regenerated from the MERGED authorities, so the bytes are the projection of both lanes' facts rather than either side's file. Result against main: one insertion in each, zero deletions -- this branch's index bullet and ledger row, with #9976's identity-join content intact in both files.
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 2, 2026
…N with my blob in it #9976 replaced the roster's count comparison with an identity join. Executed on the merged tree: compiler_tests_rust_blobs_are_all_rostered returns TRUE -- the three-blob deficit I reported is closed on main and my row satisfies the join by identity rather than by count. Roster conflict unioned (compensating_errors_cancel_in_the_aggregate, mine); both projections regenerated, superset clean on both sides; mirrors at the fixed point. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FdxzwWekWhHR2FCTTf8a1b
This was referenced Sep 2, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was asked
compiler_tests_rust_blobs_are_all_rosteredis RED on main (43ct_declarations vs 40 rostered): establish whether it is unenrolled or held known-red, disposition the unrostered blobs, and make the completeness claim honest.It is enrolled, not unenrolled
The identity sits in
floor_expected_red_chunk_live_tree_admissioninv2.workflow.floor_expected_red— held known-red. Its entry declaresReadsLiveTree, which inentry_eligible_for_discovery_skip_before_resolvemeans it never predict-skips, so it genuinely executes and genuinely fails on every required run. Nothing was silently unenrolled.The gap was not the four the counts suggested
The witness asserted
declared_fn_count(ct_) == rostered_count_for(v1.compiler.compiler_tests_rust)— 44 against 40 on the current tree. Joined by identity, the residues are of two different kinds:Five live blobs unrostered:
ct_fixture_closure_rustc_discrimination_testct_import_lines_follow_resolved_binding_identity_testct_witness_carrier_declines_non_witness_expected_type_testct_generic_param_declines_fail_closed_unwrap_testct_shell_service_output_projection_known_hole_probe_testOne row that outlived its blob:
ct_caret_parse_smoke_native_witness_tests, which #8532 deleted from the carrier while leaving the roster row standing.This is the finding worth the PR. Rostering four of the five would have balanced the counts at 44 and greened the witness with one blob still unmarked and one row still naming a declaration that does not exist. The count was never the claim; it was a necessary condition of the claim being read as the claim. DESIGN §5 already says so outright: completeness is an identity join, not a count equality.
Disposition
All five are hand-authored Rust assertion blobs — the same class as their rostered neighbours — so they carry
compiler_tests_rust_hand_assertion_scaffold_trigger. The stale row is removed.language_source_scaffold_roster_sizestays derived; no literal moved.The claim made honest
The witness now names the two residues separately — declared-not-rostered (a blob landed unmarked) and rostered-not-declared (a row outlived its blob) — and asserts each is empty, so the two directions red with distinct meanings and neither can pay for the other. Cardinality survives as a third conjunct answering the one question containment cannot: a duplicate within one side. The
rt_arm gets the same treatment and stays green.head_before's structurally-unreachableAbsentarm yields a spelling no roster row can carry rather than fabricating a plausible name — the failure arm refuses, it does not widen (§5).The evidence does not stop at the repaired tree
A repaired population makes both live arms permanently green and the join indistinguishable from the count it replaced. So five discriminating controls run over authored fixtures, including
the_join_refuses_equal_counts_with_different_identities— exactly the case the old form accepted (DESIGN §4b(1): a rung needs an executed RED plus an accepted positive control).Delisted from the expected-red roster, since that roster self-empties on pass.
Executed evidence
gunbc runagainst the live tree. All ten witnesses in the file returntrue:compiler_tests_rust_blobs_are_all_rosteredtrue← was RED on mainruntime_rust_blobs_are_all_rosteredtruelanguage_source_scaffold_roster_is_fully_dispositionedtruethe_join_refuses_equal_counts_with_different_identitiestruethe_join_refuses_an_unrostered_blobtruethe_join_refuses_a_row_that_outlived_its_blobtruethe_join_refuses_a_duplicate_row_masking_an_unrostered_blobtruethe_join_accepts_the_same_population_in_any_ordertruereasoned_terminal_is_acceptedtruepair_completion_spelling_binds_the_derivation_authoritytrueThe four
the_join_refuses_*rows returningtruemeans the join actively refuses those populations — a discriminating RED, executed rather than asserted.A note for anyone running
.dagwitnesses: this had to run in a session container. BuildBuddy runners expose no cgroup memory limit, sogunbc runrefuses there withHostBudgetUnreadableundergunbc.host_budget_sourcerather than admitting against a machine-wide reading. Remote is fine forcheck/clippy; it cannot execute the interpreter.Generated projections
DESIGN.mdanddocs/design-ledgers.mdare regenerated throughdag/gunbc/instruments/generated_artifact_gate.dag main_wet— one line each — carrying a new recurring-failure-mode row,compensating_errors_cancel_in_the_aggregate, whose recognition rule is: for any check whose sentence contains "every", "all" or "covers", ask what it would report if one member were missing from one side AND one phantom stood on the other.claim_executor --required-regenalso ran clean (first_generation_equal=true, planned=149 executed=149).🤖 Generated with Claude Code
https://claude.ai/code/session_01P7mphvNU1JoCbrowqDM5Zg