Skip to content
Closed

XL-1 #9993

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions DESIGN.md
Original file line number Diff line number Diff line change
Expand Up @@ -186,6 +186,7 @@ One row per class, each carrying its recognition rule and its receipts, in [docs

- `censored_estimator_drops_its_own_tail`
- `selection_view_read_as_population`
- `unlanded_citation_indistinguishable_at_the_citing_end`
- `hollow_alias`
- `state_space_conflation`
- `absorbing_fallback`
Expand Down
3 changes: 3 additions & 0 deletions dag/gunbc/recurring_failure_mode.dag
Original file line number Diff line number Diff line change
Expand Up @@ -189,9 +189,12 @@ data accepted_source_emits_uncompilable_target: RecurringFailureMode = Recurring
}
data selection_view_read_as_population: RecurringFailureMode = RecurringFailureMode { identity: "selection_view_read_as_population" as NonEmptyStr, authored: "**a selection view read as the population** (a decidable predicate is written over MEASURED values -- cost at or above N, latency under N, rows a report printed -- and its output is then treated as the population of the class under study. Membership in that set is a property of THE MEASUREMENT, not of the subject: it moves when the instrument moves, when load moves, when the reporter truncates, while the subject is unchanged. The set and the population are two objects joined by an assumption nobody states, and the assumption is false exactly when the measured quantity carries an unbounded term the threshold cannot see beneath. **WHAT MAKES THIS DIFFERENT FROM ITS NEIGHBOURS IS THE ROUTE IT ARRIVES BY, AND THAT IS ALSO THE WHOLE DIFFICULTY: IT ARRIVES AS THE FIX FOR A REAL OBJECTION.** `instrument_output_read_as_subject_content` is a report read past its own promise, and its closest unnamed relative here is a statistic computed over the observations that SURVIVED a threshold on the very variable being estimated -- filed separately as `censored_estimator_drops_its_own_tail`, and cited here by identity because that row now resolves in this tree; it was carried descriptively while it was unlanded, since a boundary drawn against a symbol that does not resolve is worse than a boundary drawn descriptively. Both of those are errors in the READING. This one is produced BY diligence. The predicate is decidable, it is honestly derived, and it is very often the correct answer to a legitimate refusal -- which is precisely why the next question does not get asked. **BEING CAREFUL IS WHAT MAKES IT INVISIBLE: the diligence is spent on the repair, and the repair's correctness is what stops anyone asking whether it answers the question that was posed.** A defect arriving inside a correct fix is not caught by the diligence that produced the fix. SPECIMEN, WITH BOTH ENDS BELONGING TO THE SAME AUTHOR THREE HOURS APART, which is why it is filed rather than blamed. (i) A peer lane computed a median and p95 over the rows a required-floor run's `[over-cost]` listing PRINTED -- an instrument that ranks by cost and truncates to a fixed head, and whose own closing line says so and names the per-claim cost artifact the run uploads as the complete population. This author correctly told them an order statistic of a truncated tail describes nothing, because the truncation is a property of the REPORTER. THE TWO PRODUCERS ARE NAMED RATHER THAN THEIR OUTPUTS TRANSCRIBED, per DESIGN section 6: the truncated view is that `[over-cost]` listing, and the population is `required_floor_claim_cost.tsv` as uploaded by the same run -- either is re-derivable from any floor run, and no count here needs to be trusted. (ii) The same author then had a declared drop refused for defining its population as `every required row whose headroom is smaller than the observed inflation` while calling that inflation censored with no upper bound -- an undecidable membership predicate, correctly refused under DESIGN section 4b(3). The fix was a decidable admission rule over each run's own per-claim cost artifact, which was the right repair for the refusal, and its output was then written into the row AS THE POPULATION. With an unbounded contention term, no lower threshold can prove the rows beneath it unaffected, so the set was a view the whole time. REPAIR: name the closed subject universe from the SUBJECT rather than from any measurement -- for the specimen, every required identity for which the cpu deadline is armed while it executes under the uncontrolled shared-runner envelope -- and keep the threshold set, which is genuinely useful, under an honest name: an EXPOSED ATTENTION SUBSET for prioritising work. A COROLLARY WORTH CARRYING SEPARATELY, because conflating the two hides the seam: the evidence floor behind such a threshold may be MONOTONE while the membership set is NOT. An observed floor only rises, so a constant derived from it only falls; individual identities still enter and leave the subset as their measured values vary. Monotonicity of the bound says nothing about stability of the set. **RECOGNITION RULE: when a set is produced by comparing a MEASURED value against a threshold, ask what the set would contain if the measurement were taken again under different conditions -- and ask it hardest when the predicate was just written to satisfy a reviewer, because that is the moment the answer feels settled.**)", evidence: [] }

data unlanded_citation_indistinguishable_at_the_citing_end: RecurringFailureMode = RecurringFailureMode { identity: "unlanded_citation_indistinguishable_at_the_citing_end" as NonEmptyStr, authored: "**a citation to a symbol that has not landed** (a canonical row cites an identity that exists only in an OPEN PR, so on main -- the tree the row lands in -- the citation resolves to nothing. **THE MECHANISM IS THAT THE TWO STATES ARE INDISTINGUISHABLE AT THE CITING END.** A name that resolves and a name that will resolve are the same text in the same position; nothing at the point of authorship separates them, so this is not carelessness and reading more carefully does not find it. The check that discriminates is a LOOKUP AGAINST MAIN; the check an author naturally performs is a lookup against their own context, in which the symbol is vividly present because they or a peer just wrote it. Both receipts below were caught by CI and neither by review, which is what that asymmetry predicts. **A VOCABULARY DEFECT CARRIES IT BETWEEN LANES, AND THAT HALF IS WHAT MAKES THE CLASS PREVENTABLE RATHER THAN MERELY DETECTABLE.** One receipt arrived through a MESSAGE saying a class was `filed`. That word is true the moment a row is authored in a branch and is heard as `the tree carries it`; the two states collapse into one utterance. So the rule has a speech half: never say FILED without saying filed WHERE -- `authored in gunbc#NNNN, open` or `landed on main` -- because a reader cannot recover the distinction the word destroyed. TWO INDEPENDENT RECEIPTS, ONE HOUR APART, DIFFERENT LANES AND DIFFERENT CARRIERS, EACH CAUGHT BY CI. (i) A recurring-failure-mode row drew its load-bearing boundary against a sibling class that lived in the author's own other open PR. (ii) A proof field in a separate lane cited a class living in a third session's open PR, reached through the `filed` message above. Both authors repaired it the same way without knowing of each other: DESCRIBE THE SIBLING BY SHAPE RATHER THAN NAMING IT. THE RULE, and it is stronger than it first sounds: A CANONICAL ROW MAY CITE ONLY WHAT RESOLVES ON MAIN AT THE MOMENT THE ROW LANDS. Not `resolves eventually`. **That formulation FORBIDS STACKING the citing PR behind the cited one**, which is the tempting repair precisely because it feels like it fixes the citation -- it satisfies resolves-eventually and fails resolves-at-landing, so it defers the defect rather than removing it. THREE ADMISSIBLE FORMS, AND THE RANKING BETWEEN THE FIRST TWO IS CONDITIONAL ON WHETHER THE CITED IDENTITY IS STABLE -- an unconditional ranking was proposed, and withdrawn by its own author on the argument below. WHERE THE CITED IDENTITY IS STABLE, name the PR AND ITS OPENNESS -- `authored as <identity> in gunbc#NNNN, which is open at this writing, so this points at the PR carrying the row rather than asserting an identity that does not yet resolve`. It stays TRUE after the cited PR lands and TIGHTENS to the bare identity rather than needing correction. **WHERE THE CITED IDENTITY IS NOT STABLE, BOUNDARY BY DESCRIPTION RANKS FIRST INSTEAD, AND AN IDENTITY IN AN OPEN PR UNDER ACTIVE REVIEW IS PRECISELY THE UNSTABLE CASE.** If the cited PR RENAMES its row before landing -- under review pressure, or because two lanes converge and merge their classes -- the PR-naming form points at a real PR carrying a row that no longer has that name, AND IT FAILS WHILE STILL LOOKING RESOLVABLE: the PR number resolves, the identity does not, and the sentence reads as correct. A description survives that, because it does not name the thing that changed. So: PR-plus-openness when the identity is settled, description when it is in motion. BOUNDARY BY DESCRIPTION -- name the sibling's shape and not its symbol -- is otherwise second: correct, but it must be REWRITTEN once the sibling lands, and a rewrite is where a citation quietly stops matching the row it describes. Never: a bare identity that does not resolve on main today, which is worse than no citation at all because a reader takes the name as established and stops checking. RUNG, CEILING AND TRIGGER, per DESIGN section 4b. RUNG FOUND AT: MITIGATABLE. The repository already runs a required cited-symbol resolution check -- its rung drop `cited_symbol_census` is RETIRED, so the capability is live -- and it did not fire on either receipt, because BOTH CITATIONS WERE PROSE INSIDE AN `authored: String`, not typed references. A prose name is not reachable from the namespace tree the check walks, so the check was not weak here; it was not applicable. What caught both was a review bot reading the text, which is containment after the fact and not prevention. ATTAINABLE CEILING, AND IT IS NOT STRUCTURAL WHILE THE CITATION STAYS PROSE: deciding whether an identity-shaped token inside a paragraph is a CITATION or merely a mention is not decidable, so a scanner over prose would be a heuristic, and DESIGN section 5 forbids dressing one as a wall. This class therefore sits in the *outside the modeled guarantee* column for as long as row-to-row citation is prose -- observed and repaired by reading, never gated -- which is the same standing `unbacked_execution_claim` records for the same reason. NEXT-RUNG TRIGGER, A CAPABILITY AND NOT AN ARTIFACT: A TYPED ROW-TO-ROW CITATION CARRIER -- the ability to express `this row's boundary is drawn against THAT row` as a reference the namespace authority resolves, rather than as a name inside a paragraph. The moment such a citation is typed, the EXISTING required check covers it and the class climbs to structurally guaranteed for every typed citation in one step, with no new gate to build. `RecurringFailureMode` carries an `evidence: List<DeclarationRef>` field, which is the nearest existing carrier and is NOT that capability: it records declarations that witness the class, not the class's boundary against a sibling, and pressing it into service would be a second meaning for one field. WHY THIS ROW'S OWN `evidence` IS EMPTY, stated rather than left to look like an omission: both receipts are PULL REQUESTS AND REVIEW ARTIFACTS, not declarations, so there is no `DeclarationRef` to carry them and the field is honestly empty rather than padded. THE RECEIPTS AT CHECKABLE GRAIN: (i) gunbc#9946, review 58237 -- the boundary clause of `selection_view_read_as_population` named `censored_estimator_drops_its_own_tail`, which at that moment lived only in the same author's other open PR, gunbc#9932. BOTH IDENTITIES RESOLVE IN THIS TREE NOW, which is why they are named here rather than described: the receipt is that they did NOT resolve when the citation was written, and the repair the citing row carries is the descriptive-then-tightened form this row ranks second; (ii) gunbc#9949, review 58260 -- a proof field naming a class living in a third session's open PR, gunbc#9939, reached through the `filed` message. Both reviews are codex, both on the first pushed head of their PR, and each names the unresolvable identity explicitly. **THE TWO RECEIPTS ARE CARRIED IN TWO DIFFERENT ADMISSIBLE FORMS, AND THAT IS DELIBERATE: the first names identities because its two subjects have since landed, the second names a PR and its openness because gunbc#9939 has not. A reader who sees the ranking stated learns the conclusion; a reader who sees one paragraph use both forms because its two cited PRs are in different states learns the DISCRIMINATOR.** A COROLLARY THAT THIS ROW ITSELF DEMONSTRATES, and it is the reason the first receipt does not read as two bare names: WHEN A CITATION TIGHTENS FROM DESCRIPTION TO IDENTITY, THE RECEIPT USUALLY LIVES IN THE STATE THAT JUST ENDED, so tightening SILENTLY DESTROYS IT. This row's first receipt is the historical NON-RESOLUTION of those two names, not the names; tightened to identities alone it would show a reader two symbols that resolve and no evidence the class ever occurred -- a row about unresolvable citations, evidenced by resolvable ones. So a tightening must carry the ended state as a stated fact beside the new name, never merely replace it. THE CAUSE IS A SEPARATE SHAPE AND IS DELIBERATELY NOT FOLDED IN HERE: a correct decomposition -- splitting two classes into two PRs because a rider in a large PR gets skimmed rather than read -- is often what SEVERS the citation path between the pieces. That is a cause held at one receipt and not yet filed; this row is about why the severance is invisible from the citing end, which is a different question with a different repair. If both are ever filed, the causal link is named rather than merged.)", evidence: [] }

data recurring_failure_mode_roster: List<RecurringFailureMode> = [
censored_estimator_drops_its_own_tail,
selection_view_read_as_population,
unlanded_citation_indistinguishable_at_the_citing_end,
hollow_alias,
state_space_conflation,
absorbing_fallback,
Expand Down
Loading
Loading