Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
381303c
feat(platform-probes): add probe-queue-contention, which prices the t…
Sep 14, 2026
d74a00c
fix(platform-probes): restore the default-features build the probe's …
Sep 14, 2026
d8783f9
Merge remote-tracking branch 'origin/main' into mikegrier/probe-queue…
Sep 14, 2026
d49a71f
fix(platform-probes): time the producers, not this thread, and refuse…
Sep 14, 2026
0ca3ea1
docs(platform-probes): withdraw the "re-apportionment is free" claim
Sep 14, 2026
2ffea52
docs(waitable-queues): drop "at no measured cost" from the layout gui…
Sep 14, 2026
86e851b
docs(platform-probes): treat a wide self-control as a defect report, …
Sep 14, 2026
a9d7427
docs(platform-probes): say what to try first on high variance, and wh…
Sep 14, 2026
123bdbe
docs(platform-probes): record the sampling parameters as capture para…
Sep 14, 2026
a4b752a
docs(platform-probes): withdraw the drained widening figure too
Sep 15, 2026
0759b5c
docs(waitable-queues): three more sites carrying the withdrawn cost c…
Sep 15, 2026
2d29bee
fix(platform-probes): restore the i686 build this probe's features re…
Sep 15, 2026
40226d7
docs(waitable-queues): the last sites of the withdrawn claim, and a s…
Sep 15, 2026
56693ac
fix(platform-probes): warn in the report when the build cannot measure
Sep 15, 2026
b23d70e
fix(platform-probes): stop the attribution correction stopping at one…
Sep 15, 2026
88df746
fix(platform-probes): the "bounds it" correction was itself an over-c…
Sep 15, 2026
236c8d0
docs: stop restating volatile figures outside the one table that owns…
Sep 15, 2026
1a42d9a
docs(platform-probes): an observation is reviewed against its procedu…
Sep 15, 2026
906aa01
fix(platform-probes): label the instrument as what it measures, not w…
Sep 15, 2026
0ad7465
docs: remove advice built on top of measurements
Sep 15, 2026
9c5f3e0
docs: label pre-correction figures, and state the defect instead of r…
Sep 15, 2026
3647539
docs(platform-probes): a broken doc link, a missing capture field, an…
Sep 15, 2026
ea090c5
fix(platform-probes): gate dwcas on the instruction, not just the arc…
Sep 15, 2026
d973924
docs(waitable-queues): fix a broken sentence, a too-strong claim, and…
Sep 15, 2026
bba97ba
docs: derive the layout count, correct the ceiling, and order M4.4 be…
Sep 15, 2026
a99108f
docs: Wide moves the recurrence to 2^64, it does not remove it
Sep 15, 2026
b196db6
docs(waitable-queues): regenerate the published measurements with att…
Sep 15, 2026
d5628ce
docs: the reservation column was a field ceiling, not a reachable count
Sep 15, 2026
c9a9127
docs: the refusal counts do not say what that section said they say
Sep 15, 2026
8b31650
docs: mark D-17 superseded, and scope the forced-split premise to Bal…
Sep 15, 2026
16c329e
docs: the 2^31 capacity is a 64-bit figure, and other target-dependence
Sep 15, 2026
34b47d6
test(platform-probes): cover measured_span and the report's renderer
Sep 15, 2026
c83d411
docs: require review feedback to be answered where it was raised
Sep 15, 2026
23f6e0f
test(platform-probes): cover median_run's selection and the refusal c…
Sep 15, 2026
e0bb76c
docs(waitable-queues): withdraw the producer-count reservation bound …
Sep 15, 2026
b173198
docs: record that restatement count, not prose volume, is the error s…
Sep 15, 2026
679dd8e
docs: the wrap exposure is a count, not a rate, and 6.4x came from wi…
Sep 15, 2026
9f204bd
fix(platform-probes): the baseline has no pushes, so the units are pe…
Sep 16, 2026
c846922
docs(waitable-queues): withdraw the control-band conclusion, which si…
Sep 16, 2026
fecd352
fix(platform-probes): carry the dispersion the crate's own contract r…
Sep 16, 2026
3062c47
chore(topology): the placement tool is placement-probe, not probe-cor…
Sep 16, 2026
81cca99
docs(waitable-queues): publish the dispersion, and stop naming a tool…
Sep 16, 2026
da20e51
docs(platform-probes): record that the dispersion work landed, and ho…
Sep 16, 2026
fca9a9c
docs(waitable-queues): the rustdoc table still held the superseded ca…
Sep 16, 2026
0416f0f
fix(platform-probes): the refusal counts do not rule the tail out
Sep 16, 2026
cddef16
docs(waitable-queues): D-41 still called the reservation half the wro…
Sep 16, 2026
bd82bf9
docs(platform-probes): split M4.2's completed half out as M4.5 and ar…
Sep 16, 2026
bc56465
docs(waitable-queues): the horizons were still "measured" in seven pl…
Sep 16, 2026
0f36dfa
fix(waitable-queues): restore backticks and a newline PowerShell ate
Sep 16, 2026
2039307
docs: a design note should not record which branch a checklist item i…
Sep 16, 2026
32cb97a
fix(platform-probes): the derived ratios had no dispersion either
Sep 16, 2026
8950987
docs: count the tabular/prose split instead of estimating it
Sep 16, 2026
e75bc7e
docs: prose carries the claim, an artifact carries the number
Sep 16, 2026
a8d4c7f
fix(platform-probes): ratio_bounds returned the inverse of what it do…
Sep 16, 2026
3761c63
docs: the field binds only once the queue is at least that large
Sep 16, 2026
ce21ff3
docs: the section arguing against embedded figures was embedded figures
Sep 16, 2026
893a279
docs(waitable-queues): 2^64 is about 5,000 years, not "unreachable"
Sep 16, 2026
f3d5757
fix(platform-probes): a zero numerator rendered 0.00x, which reads as…
Sep 16, 2026
10ef5fc
docs: the capture date needs its offset, and the time-figure count moved
Sep 16, 2026
9340fcf
docs: apply the one-home rule to the prose that introduced it
Sep 16, 2026
28978ba
fix(platform-probes): an unmeasured spread rendered as perfect stability
Sep 16, 2026
ad2491b
style(platform-probes): reflow two assertions cargo fmt wanted wrapped
Sep 16, 2026
df16f01
fix(probes): stop a shape that never ran from publishing figures
Sep 16, 2026
eb807ca
docs(queues): stop calling a finite recurrence horizon an absolute one
Sep 16, 2026
eee03aa
docs(probes): correct the M4.5 archive, which inverted its own lesson
Sep 16, 2026
117a7ad
fix(probes): count measured layouts, and size the ratio column from i…
Sep 16, 2026
0510b92
docs: state every claim-position horizon as finite and rate-dependent
Sep 16, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
100 changes: 98 additions & 2 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -492,8 +492,7 @@ the same time, so both halves of the evidence disappear together.
This is not a small correction. Measured on two runs here: a `windows-topology-sys` sweep
reported 61 survivors of which **57 were in `#[cfg(feature = "serde")]` code**, and a
`windows-file-watcher` sweep reported 247 of which **147 were in `scenario-tool` and
`test-util` modules**. In both cases roughly 60% of the "gaps" were artifacts of the
invocation. So:
`test-util` modules**. In both cases the gated code dominated the survivor list. So:

```
cargo mutants -p <crate> --all-features
Expand Down Expand Up @@ -1271,6 +1270,103 @@ Two corollaries that have each already cost a review round:
written while the old reading was current — generators, test doubles, examples — because those
encode the reading rather than citing it.

### 4. Prose carries the claim; a number belongs in an artifact

Measured data pasted into prose becomes a copy somebody must keep true by hand, in every place it
was pasted, forever. Markdown has no include and rustdoc has no data include, so pasting is the path
of least resistance — and it is where this repository's documentation defects overwhelmingly come
from. Measured on one pull request's review history: almost none of its measurement findings were
*wrong measurements*; they were transcriptions that drifted — a table disagreeing with its own copy
one file away, an attribution naming a superseded capture, one horizon left unqualified across seven
sites in three wordings.

- **Write the claim, not the digits, wherever the digits are not the point.** "Measured faster under
contention, and the spread is wide enough that the ordering is a flag rather than a finding" cannot
drift from the data, because it restates none of it.
- **When a figure must appear, it has exactly one home.** Prefer a committed capture the prose links
to (`mutation-sweeps/<date>/` is this repository's existing example) over the same figure typed
into two documents. Provenance — host, commit, date — travels with the data rather than in a
hand-maintained table beside it.
- **Never restate a proportion over data you already showed.** A ratio over counts in the same
document is not a finding; it is a hand-computed copy of one, checked by nobody and stale the
moment any input moves. The counts are the finding. This rule was earned: an instructions file in
this repository claimed "in both cases roughly 60%" about two figures given four words earlier,
one of which was 57 of 61 — 93%.
- **The same applies to incidental tallies** — test counts, file counts, line counts. If the number
is not itself the finding, leave it out; "the gate is green" says what "308 lib tests" pretends to.

**This is the data-side twin of rule 1.** Rule 1 says define a fact once in code and have everything
ask. This says the same of measurements: hold the number once, and have prose point rather than
paraphrase.

## REVIEW FEEDBACK — answer it where it was raised, not only in the commit

**A review round is not finished when the code changes. It is finished when the reviewer has
been told what happened.** Fixing the code and pushing is half the transaction; the other half
is a reply on GitHub, and omitting it is the default failure mode because the fix *feels* like
completion. It is not, for three reasons:

- **A commit is not an answer.** The reviewer sees a new SHA, not your reasoning. Nothing
connects "I changed `format_ratio`" to the finding that asked for it, so the next round
re-raises what was already addressed — which has repeatedly cost rounds on this repository.
- **Some findings are correctly declined, and silence cannot say so.** A declined finding that
is never answered is indistinguishable from one that was missed. Declining is legitimate;
declining *silently* is not.
- **Suppressed comments have no thread at all.** They arrive in the review summary rather than
attached to a line, so there is no place a reply can land by default and no automatic record
that they were read. They are the easiest feedback to drop and the most likely to be re-raised
verbatim in the next round.

### What to do, by where the feedback lives

- **Inline review comments (a thread on a line).** Reply *on that thread*, naming what changed
and the commit SHA that changed it. Then resolve the thread — but only if the finding is
genuinely discharged; never resolve to clear the queue. Use the `resolveReviewThread` tool, or
`gh api repos/{owner}/{repo}/pulls/{number}/comments/{comment_id}/replies -f body=...`.
- **Suppressed comments, review-summary findings, and anything pasted to you out of band** — no
thread exists, so post **one new PR comment** covering that round:
`gh pr comment <number> --body-file .scratch/<file>.md`. One comment per round, not one per
finding; a reviewer reads the round as a unit.
- **No PR** (work committed straight to a branch, or feedback on a commit):
`gh api repos/{owner}/{repo}/commits/{sha}/comments -f body=...` against the commit that
carries the response.

### What the response must contain

Every finding in the round gets a line, and each line is one of exactly two things:

1. **Changed** — what was changed and the SHA. Where the fix was a *sweep* rather than a
single-line edit (per CONTRACT INTEGRITY rule 3 above), say so and give the count: "swept
`QueueFull`: 13 files, 4 updated". A reviewer who sees only the cited line fixed has no way
to know the population was covered.
2. **Declined** — the argument for why, in enough detail to be argued back against. "Not
applicable" is not an argument; "this is gated behind `test-util`, so the mutant sits in code
the shipping build never compiles" is.

Two further rules, each of which has already cost a round here:

- **Do not claim a fix you have not verified.** The same standard applies as anywhere else in
this file: verify by execution. Where the fix was a test, say what sabotage showed it is
load-bearing — an unverified "added a test" is exactly the cosmetic binding CONTRACT INTEGRITY
rule 1 warns about.
- **Report what the round taught, not just what it touched.** When a review round reveals that
several findings were one underlying error, say that — it is more useful to the reviewer than
five separate acknowledgements, and it is how a recurring defect gets named instead of
repeatedly re-fixed.

### The PR description drifts too, and nothing greps it

A PR body is prose that restates measured claims, gate results, and design rationale — so it
rots exactly like the documents CONTRACT INTEGRITY governs, with one difference: **it is not a
file in the tree, so no sweep, grep, or CI check will ever catch it.** When a round corrects a
claim, check whether the PR description states the same claim, and correct it in the same round.

Keep out of the PR body anything that drifts without carrying information. **Test counts are the
standing example**: "308 lib tests" changes on almost every commit, tells a reader nothing that
"tests pass" does not, and creates a restatement-drift instance out of nothing. State that the
gate is green and which parts of it ran; do not enumerate. The same goes for file counts, line
counts, and any other incidental tally that is not itself the finding.

## CHECKLIST file hygiene

CHECKLIST files are **action-only**: they contain pending, in-progress, and recently
Expand Down
39 changes: 39 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -500,6 +500,45 @@ jobs:
RUSTDOCFLAGS: "-D rustdoc::broken_intra_doc_links -D rustdoc::private_intra_doc_links"
run: cargo doc -p windows-placement-probe --no-deps --no-default-features --locked

waitable-queues-default-features:
name: windows-waitable-queues (default features)
runs-on: windows-latest
# **This job exists because adding `probe-queue-contention` took the default
# configuration away from every other job.** That probe needs `dwcas` and
# `experimental-permit-claim`, and enabling them on a workspace member
# unifies them across the whole workspace -- so the `--workspace` steps that
# deliberately omit `--all-features` stopped being a default-features build
# of THIS crate, and no job was left compiling it without `dwcas`.
#
# That matters because `dwcas` is additive: `Wide` and its `ClaimLayout` impl
# exist only under it, so the configuration that loses them is the one that
# can break unnoticed. The crate's manifest says `dwcas` is "non-default so
# nothing depends on it by accident" and is "the only thing in this crate
# that costs a third-party dependency" -- a claim that is only true while
# something still builds without it.
#
# Named per-crate rather than fixed by making the probe's dependency
# optional: the probe must stay buildable by a plain `cargo build`, and a
# feature that has to be remembered before the probe compiles is a worse
# trade than a job that cannot be forgotten.
env:
RUSTUP_TOOLCHAIN: stable
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
with:
components: clippy
- uses: Swatinem/rust-cache@v2
- name: cargo build
run: cargo build -p windows-waitable-queues --all-targets --locked
- name: cargo clippy
run: cargo clippy -p windows-waitable-queues --all-targets --locked -- -D warnings
- name: cargo test
env:
RUST_BACKTRACE: 1
RUST_LIB_BACKTRACE: 1
run: cargo test -p windows-waitable-queues --locked --no-fail-fast

fmt:
name: rustfmt
runs-on: windows-latest
Expand Down
1 change: 1 addition & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading