Skip to content

FLOW-003 v2.1: fleet hardware + tiered testing, Parts II–III review (R2-1..R2-14), Props 19–20, pv contracts (docs only) - #4533

Closed
noahgift wants to merge 4 commits into
mainfrom
docs/flow-003-v2.1
Closed

noahgift wants to merge 4 commits into
mainfrom
docs/flow-003-v2.1

Conversation

@noahgift

Copy link
Copy Markdown
Contributor

Docs-only. This is FLOW-003 v2.1: the operator-approved v2.0 (Part II fleet hardware, Part III tiered testing), plus the v1.1 fixes it left for this session, plus a review of Parts II and III. Refs #4514 (PMAT-4514).

Applied from the v1.1 review (Part I)

R-3 (Q1–Q3 [U]), R-4 (Thm 8 citations and $\underline E_{ff}$), R-5 (§6 rows fully parameterised), R-6 (QM-04 moves to EV 0 as QM-00's oracle), R-7 (Q5), R-8 (Thm 2 scope), R-9 (Cor. 4 scope; QM-06 records C, F, φ), R-10 (§7 retries basis = Prop. 10 at B=1, φ* = 0.0512), R-11 (ρ_rel / ρ_MQ), R-12 (q′ and λ′ measurement; q_eff, lambda_eff_per_h in §10).

Review of Parts II–III (R2-1..R2-14, full table in §12.2)

  • R2-8 (soundness): the input set 𝓘 from the nightly goes stale at a later base. A code commit after the nightly can include_str! a docs file, and the docs lane is then unsound. Added a validity-at-base rule (INV-BASE) and a QM-10 falsifier.
  • R2-9 (soundness): an openat/stat trace can't see directory listings or ENOENT lookups, so adding a file to a globbed directory escapes. The trace now covers getdents64 and failed lookups, and the ad hoc "fixtures directory" rule is dropped.
  • R2-10: nextest archives don't carry doctests. There is now a separate doctest job, and the never-down invariant counts doctests separately.
  • R2-12: Prop. 18's e_κ counted only what full review missed. It now also counts quorum-caught findings.
  • R2-13: the merge-group diff is taken against merge_group.base_sha.
  • R2-1..R2-7: t* is 17, not 16 (16 is kept as a stated round-down); assumption (H-a) added to Thm 11; precondition added to Prop. 12a; the LP reads CPU-seconds, with RAM rows under reservation only (P0 thread-only bound 3.8/h); the shard figure is derived (≤ 299 s), and "C ≤ 30 by proof" becomes a CI-given-a-free-slot bound of 15.1–25.1 min; an aging rule so backfill can't starve large jobs; §H.6 rows above λ* labelled transient.
  • R2-11: edge notes on Thm 15.
  • R2-14: QM number collision, resolved by the cop: FLOW-003 QM-15: measure q per service class (docs / attested-fork / full) — Prop 12/18 inputs (was QM-08 in v1.1 numbering) #4519 → QM-15.

New

  • Prop. 19: under sound tier routing at B=1, r=0, ρ_HOL = λ′ Σ s_k q′_k T_k, about 57% lower at the v2.0 mix [C]. It supersedes v1.1 Prop. 11.
  • Operator ruling 2026-09-27: the lighter review tier is approved for docs-only PRs and vouched contributors. It switches on per class when Prop. 18 clears, and reverts to full review automatically on the first escape (§7 row 12, QM-15, POLICY-flow-003-queue POST-REV).
  • Operator amendment 2026-09-27 (Prop. 20, §7 row 14): rebase before arm (gh pr update-branch N --rebase, then CI, then quorum on the rebased head, then arm; no force-push), and PR age becomes a model input: P(conflict) = 1 − e^(−κ μ_D a). Short PRs keep the queue model's q stationary. QM-01 gains μ_D, PR age p90 and base age p90 (queue_inputs 14 → 17), the scoreboard gains PR age p90 < 24 h and 0 PRs DIRTY > 4 h, and POLICY gains POST-REBASE. Group 1, retries 0, compile once and tiered tests are unchanged.
  • §11 pv contracts: DOC-spec-flow-003 (QM-00..QM-16), queue-model-v1 (+POST-P19), queue-inputs-v1, ci-input-set-v1 in full, POLICY-flow-003-queue (one clause per §7 row), and a table for the rest. All are declared, so pv reports Unknown and nothing arms.
  • §12: the review record.

QM rows for the cop to mint after merge

QM-00..QM-07 are unchanged from v1.1 (QM-04 moves to EV 0).

keep-open: #4514 #4519 #4527 #4528 #4529 -- this PR is a spec revision (FLOW-003 v2.1); #4514 is the spec ticket, and #4519, #4527, #4528 and #4529 are QM rows the spec specifies, closed by their own implementing PRs

🤖 Generated with Claude Code

…ng v1.1 fixes, a Parts II–III review (R2-1..R2-14), Prop. 19 and pv contracts

v2.0 said "infra-5a applies its remaining v1.1 fixes on top of this
version". This commit applies them: R-3..R-12 on Part I. It also reviews
Parts II and III. Two soundness findings are among them: the input set
goes stale between the nightly and the base (R2-8), and an openat trace
misses directory listings and ENOENT lookups (R2-9). Doctests drop out of
nextest archives (R2-10), and Prop. 18 measured only what full review
missed (R2-12). New: Prop. 19 (tier routing lowers rho_HOL), §11
(ci-input-set-v1 written out in full), and §12 (the review record).
R2-14: the QM-08 number collides with aprender#4519, flagged for the cop
to re-map (not renumbered here).

Refs #4514 (PMAT-4514)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

§13.11 rung 1 — quorum shadow verdict

S13-SHADOW pr=4533 head=e8220cfc98745acd2a48ef3a1c6503f5c031977d verdict=REFUSE class=Q1 arm_rc=1

Shadow mode: this records a verdict and merges nothing. A refusal
to arm is not a block (§13 adds zero rows to §7) — the pull request is
exactly as green as it was.

@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4514",
 "head": "325029f1d4075e08fcc2da3431d65b8454927b1a",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 1
  },
  {
   "lane": 2,
   "verdict": "FAIL",
   "findings": 1
  },
  {
   "lane": 3,
   "verdict": "FAIL",
   "findings": 1
  }
 ]
}

…-4514 to v2.1

Quorum lane 2 found that v2.0 cut QM-00's mutant list from v1.1's four to
three with no record: a gate weakened silently. Restored as the union (the
1/(1-phi) retry mutant, the Prop. 10 rescued-flake mutant, and v2.0's
double-count mutant) plus one for Prop. 20. The ont:falsifier minCount goes
from 3 to 6. Recorded as R2-15 in §12.2.

Quorum lane 3 found that PMAT-4514's title still says v1.1 only. The cop
put v2.1 under PMAT-4514, so the title in the fragment and the aggregate
now names both.

Refs #4514 (PMAT-4514)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): three PASS — agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4514",
 "head": "c163baeb315ad66f77fea9cbae7af7cf0c5b4fca",
 "width": 3,
 "executor": "agy",
 "agreed": true,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 2,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "PASS",
   "findings": 0
  }
 ]
}

…ve-diff guard (PMAT-980) forbids a title edit; the v2.1 scope rides in the PR body and issue #4514

Refs PMAT-4514

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4514",
 "head": "e8220cfc98745acd2a48ef3a1c6503f5c031977d",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "NO-VERDICT",
   "findings": 0
  },
  {
   "lane": 2,
   "verdict": "NO-VERDICT",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "NO-VERDICT",
   "findings": 0
  }
 ]
}

1 similar comment
@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4514",
 "head": "e8220cfc98745acd2a48ef3a1c6503f5c031977d",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "NO-VERDICT",
   "findings": 0
  },
  {
   "lane": 2,
   "verdict": "NO-VERDICT",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "NO-VERDICT",
   "findings": 0
  }
 ]
}

@noahgift

Copy link
Copy Markdown
Contributor Author

quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false)

{
 "ticket": "PMAT-4514",
 "head": "e8220cfc98745acd2a48ef3a1c6503f5c031977d",
 "width": 3,
 "executor": "agy",
 "agreed": false,
 "auto_merge": {
  "checked": true,
  "was_armed": false,
  "disarmed": false,
  "note": "auto-merge not armed"
 },
 "lanes": [
  {
   "lane": 1,
   "verdict": "PASS",
   "findings": 1
  },
  {
   "lane": 2,
   "verdict": "PASS",
   "findings": 0
  },
  {
   "lane": 3,
   "verdict": "FAIL",
   "findings": 3
  }
 ]
}

@noahgift noahgift added owner:orphan owning session (cop inbox claims) owner:aprender-41 owning session (cop inbox claims) and removed owner:orphan owning session (cop inbox claims) labels Sep 27, 2026
@noahgift

Copy link
Copy Markdown
Contributor Author

Moved into #4605 (PRCAP fold, cop order 14:02Z). Fold = MOVE: head 4cfe2485e492b8d5a4aa423ad9182cd53df032a6 is an ancestor of the pushed fold head, so no work is lost. The branch is kept. Agent: aprender-59

@noahgift noahgift closed this Sep 28, 2026
noahgift added a commit that referenced this pull request Oct 4, 2026
Guard-step files (#4415) take main's side: main carries the later
ci/sections.yml form of the same work, and this branch's late fixes
(jq stream death, zombie child, no-manifest step) are all present there.
ci/sections.yml takes main's live-API PR-body reads (#3298) and keeps
its run-all guard step. tests/pr-review.bats keeps both new blocks
(L2 attest and the #3594 jq rows). roadmap.yaml is the union.
The mutation set is now 253 (this branch's 249 plus main's four);
its kill count stays pending until the receipt job's Arm 3 runs.

Refs #4472 #4503 #4517 #4533
Agent: aprender-78
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

owner:aprender-41 owning session (cop inbox claims)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant