Skip to content

Census type_reference_decl_file at class grain: 39 lines are 33 real occurrences, six classes, and the repair is the roster rather than the call sites - #10002

Merged
gunbai-bot[bot] merged 4 commits into
mainfrom
session/quick-crab-396
Sep 2, 2026

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

What this is

The census the brief asked for, at class grain, with real specimens only. No production code changes. Two files: a typed carrier and its witness.

The denominator, and how it was found

Enumerated from the declaration — v1.compiler.coercion type_reference_decl_file plus its repaired sibling v1.compiler.emit_rust type_reference_decl_file_in_env — and every call occurrence under src/. A module-name grep cannot see a bare call and under-reports.

39 reproduces exactly, and it is not 39 debts:

plain call occurrences 37
the declaration line itself 1
an occurrence inside an instrument that exists to MEASURE the legacy answer 1
= the brief's 39
of the 37, sitting inside the repaired sibling's own fallback body (not independent consumers) −4
independent production occurrences 33
already routed through the repaired sibling +5
production sites consuming a declaration identity through this channel 38

The classes — by what each occurrence needs, not by caller or file

Every occurrence's String result is terminally consumed by exactly one predicate, and that predicate is the question. Occurrences in four modules are one class when they reach the same predicate; two occurrences in one function are different classes when they do not.

class occ terminal predicate disposition
native-numeric realization of the referenced declaration 12 decl_file_realizes_natively → numeric_realization_declaring_modules convert at roster grain first
checkpoint applicability for the referenced declaration 25 lookup_checkpoint (two arms) → structural_declaration_modules_for convert at roster grain first
kernel-minted provenance 1 is_kernel_minted_file irreducible until the constructor exists
refusal payload (OperandShapeFacts.decl_file) 1 none — reported, never decided on correct as position
instrument occurrence 1 none — it measures the legacy answer correct as position
fallback arm of the repaired sibling 4 inherited dissolves with the helper

Why this is not a call-site sweep — the argument, in one line already in the tree

src/v1/04_infer.dag, literal_boundary_elaboration:

let natively = decl_file_realizes_natively(decl_file: declaration_file_of(d: destination, env: scope.type_env))

A DeclarationRef is recovered by identity, then discarded down to a file path so a contains() roster can substring-match it. That is the failed version of the naive repair, already sitting in the tree.

Both terminal predicates match rosters of file paths. Routing 33 occurrences to a DeclarationRef without re-keying those rosters makes the citation a symbol at the call site and leaves it a position at the authority — a later edit to either path string silently invalidates every one of them. The unit of repair is the roster, and the occurrences are downstream of it.

The two classes dispositioned as correct

DESIGN §3 admits a position where no symbol exists to name. Both qualify and neither is debt:

  • the refusal payload is the arm that fires precisely because identity could not be recovered — there is no symbol to cite, and converting it would make a located diagnostic less located;
  • the instrument must call the legacy helper, because it exists to compare the legacy answer against the inferred and environment answers. Routing it to the authority would make it agree with itself by construction.

They are counted so the denominator closes, not carried as work.

The kernel-minted class is a receipt, not a discovery

gunbc.recurring_failure_mode state_space_conflation's third form (2026-09-01) already files this specimen and names this exact symbol set. This census reached the same four authorities from the opposite direction — that row by asking what the identity key can hold, this one by asking what each of 39 occurrences needs — so under the row's own recognition rule the convergence is corroboration of the rule, and the class row cites it rather than re-filing it.

Recorded with it, both established rather than assumed:

  • std.repair_input_origin was read for this purpose and does not model this axis. It partitions the same String by producer (six emitter surfaces, bare vs qualified candidate spellings), and its own header states the source branch is deliberately named Candidate rather than DeclarationCarrier because carrying a DeclarationRef is deferred to XL-0B/C. The provenance coproduct is that deferral discharged, not a rival beside it.
  • any KernelMinted arm must derive from v1.compiler.infer_env resolved_node_is_kernel_identity_for_name, which owns kernel identity by exact equality and whose own note records that a prefix test is a second, weaker authority for it. A fifth prefix test would add an authority while claiming to remove four.

One thing the census found that changes ownership

XL-0B's identity route is partly landed: rust_exact_reference_spelling resolves through type_reference_declaration_ref into gunbc.rust_source_type_bindings, and inside five declarations it is consulted ahead of the legacy answer. Those occurrences are fallback arms behind a route that already exists, so converting them from this lane would be parallel authority. These are two separately owned facts, and that is the point: the exact-binding table answers which declaration and is XL-0B's; the rosters answer what that declaration realizes as, positionally, and are this lane's. A reference the bindings table has no row for still falls through to a contains() roster keyed on file paths, so each fallback arm has a condition owned by one authority and an answer owned by the other.

What follows is deliberately not a conversion plan. Once the answer side is keyed on identity, "should this fallback arm exist at all" becomes answerable in a way it is not today — and a fallback behind a route that now answers correctly is dead code, not a migration subject. Several of these may disappear rather than convert, so the occurrence-conversion scope is deferred and will be re-measured, not negotiated: pricing it now would price a population that may not survive. Carried as type_reference_decl_file_prior_route; the lane and its witness are named by symbol in the carrier.

What is constructed rather than checked

The disposition vocabulary has no variant spelling "rewrite the call site", so the sweep this census argues against cannot be filed against it. A class cannot claim an authority without naming the declaration that is it; a class cannot claim irreducibility and name a reachable authority.

Specimens are cited by enclosing symbol, never by line — a census of positional citations that cited positions would be its own subject.

The witness

Guards the two propositions the coproducts could not make unwritable, plus the sizing figures:

  • a class with no exhibitable occurrence or no specimen (the brief's own rule);
  • a class citing more distinct enclosing declarations than it has occurrences;
  • a conversion naming no authority, or an irreducible class naming one (exact converses);
  • an availability price exceeding the class it prices — these are the numbers the PR split rests on;
  • derived totals bounded by the roster they are folded from.

No count is asserted against a literal. Every number is a fold over the rows compared against another fold over the same rows, so adding a class cannot make the file stale and no assertion can be silenced by editing a number.

Rung honesty

The class sits at mitigatable: no occurrence refuses today and this carrier does not change that — it counts. The carrier sits lower than a reader might assume: its rows are hand-classified from source text, so a thirty-fourth occurrence would move no number here and nothing detects the omission. Its dissolution condition names the capability — a classification derived by a lens over the seed's own Node tree — and explicitly says it is not satisfied by the helper retiring, nor by adding rows however many, since a roster that cannot notice its own incompleteness is the defect.

Sizing

Not one PR, and the blocker is env threading rather than class count. Of the 33 independent occurrences, 19 sit in enclosing functions already carrying env: TypeEnv (or a scope holding scope.type_env) and 14 do not. Seven of the 14 are in v1.compiler.emit, the target-generic renderer shared by Rust/Python/Go/Dag, where threading a type environment is a layering decision rather than a signature edit — deliberately not taken under this brief.

🤖 Generated with Claude Code

https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf

briansrls and others added 4 commits September 2, 2026 04:56
…occurrences, six classes, and one class already filed

Enumerated from the DECLARATION -- v1.compiler.coercion type_reference_decl_file plus its
repaired sibling v1.compiler.emit_rust type_reference_decl_file_in_env -- and every call
occurrence under src/, classified by the TERMINAL PREDICATE each String result reaches rather
than by caller or file. A module-name grep cannot see a bare call and under-reports.

39 reproduces exactly and decomposes: 37 plain call occurrences + the declaration line + one
occurrence inside an instrument that exists to MEASURE the legacy answer. Four of the 37 sit
inside the repaired sibling's own fallback body and are not independent consumers, leaving 33
independent production occurrences; five further sites already route through the sibling.

Six classes. Two decided ones (native-numeric realization, 12; checkpoint applicability, 25)
whose repair is NOT a call-site sweep: both terminal predicates substring-match rosters of FILE
PATHS, so routing occurrences to a DeclarationRef without re-keying the rosters moves the
position from the call site into the authority. The tree already contains the failed version of
that repair -- v1.compiler.infer literal_boundary_elaboration recovers a DeclarationRef by
identity and then calls declaration_file_of on it to get a FILE back, purely so
decl_file_realizes_natively can contains() it. Two classes dispositioned CORRECT AS POSITION
under DESIGN section 3's carve-out and counted only so the denominator closes: a refusal payload
that fires precisely because identity was unavailable, and the instrument. One class dissolves
with the helper.

The kernel-minted class is a RECEIPT against gunbc.recurring_failure_mode state_space_conflation's
third form, not a new filing: that row already names this symbol set, and this census reaching
the same four authorities from the opposite direction is corroboration of its recognition rule.
Recorded with it: std.repair_input_origin was read and does not model this axis -- it partitions
the same String by producer, and its own header defers the DeclarationCarrier half to XL-0B/C --
and any KernelMinted arm must derive from v1.compiler.infer_env
resolved_node_is_kernel_identity_for_name's exact equality rather than add a fifth prefix test.

Also carried, because it changes ownership rather than the finding: XL-0B's identity route is
partly landed and is already consulted AHEAD of the legacy answer inside five declarations, so
those occurrences are fallback arms behind an existing route and converting them from this lane
would be parallel authority.

The disposition vocabulary is constructed, not checked: there is no variant spelling "rewrite the
call site", so the sweep this census argues against cannot be filed. The witness guards the two
propositions the coproducts could not make unwritable -- a class with no exhibitable specimen,
and a conversion naming no authority or an irreducible class naming one -- with no count asserted
against a literal. Rung: the class sits at mitigatable and this carrier counts rather than
refuses; the carrier's own rows are hand-classified, and its dissolution names the derived lens
as the capability that retires it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf
…: defer the occurrence scope rather than negotiate it

The row read as though the nine occurrences behind XL-0B's landed identity route were
someone else's work. They are not. The exact-binding route answers WHICH DECLARATION and is
XL-0B's; the rosters answer WHAT THAT DECLARATION REALIZES AS, positionally, and are this
lane's. A reference the bindings table has no row for still falls through to a contains()
roster keyed on file paths, so the fallback arms have a condition owned by one authority and
an answer owned by the other.

What follows is deliberately not a conversion plan. Once the answer side is keyed on
identity, "should this fallback arm exist at all" becomes answerable in a way it is not
today, and a fallback behind a route that now answers correctly is dead code rather than a
migration subject. So the occurrence scope is DEFERRED and will be re-measured rather than
negotiated: pricing it now would price a population that may not survive.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf
…ation it had inherited

None of the three is a member of the 39 and none is fixed here. They are filed because each
sits directly under the repair the classes prescribe, so a reader planning that repair meets
them, and because the first changes what such a repair may CLAIM about its own authority.

v1.std.core kernel_span and v1.compiler.infer kernel_span are byte-identical declarations of
one minter. v1.compiler.infer declares its own while also importing the other, so its 24
in-file call sites bind the local twin by shadowing and every other consumer binds the
v1.std.core one. Nothing observable differs today, which is the point: the kernel-provenance
arm must derive from the minter by exact equality, and a derivation from either twin is
correct only BECAUSE the bodies agree -- a coincidence the tree does not enforce. Such a
repair may say it consumes the authority coercion imports; it may not say it consolidated one.

Eleven citations name module v1.compiler.core, which no file declares; the declarations they
reach for live in v1.std.core. One of the eleven is the annotation directly above
is_kernel_minted_file, the predicate that repair deletes, so a reader following it to check
the derivation is sent to a module that does not exist. This carrier had inherited a twelfth
occurrence from a prior carrier's spelling and corrects it rather than adding to the
population -- which is how the count was noticed.

v1.compiler.type_head_exposure type_declaration_identity_key builds concat(decl_file, "::",
declared_name): a sixth representation of declaration identity, and the one furthest from a
symbol, since the position and the name are fused into a value nothing can read back apart.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf
…seven far consumers

`Disposition` is declared by std.disposition and `CensusBasis` by
gunbc.bare_name_identity_consumer_census. Declaring either a second time makes the bare name
AMBIGUOUS across the whole corpus -- v1.compiler.infer_env global_bare_fallback_invariant keeps
every homonym's full candidate list and refuses far uses of a tied name -- so the floor refused
seven sites that have nothing to do with this carrier: gunbc.host.host_standup (three),
gunbc.host.host_standup_assimilation_deduction, v2.std.decl_index, v2.lens.enforcement.vocab and
a qualified-name test, all `unresolved type 'Disposition'`.

Renamed to OccurrenceDisposition and OccurrenceCensusBasis. No content changes.

The failure is instructive and is exactly what this carrier's own subject warns about, which is
why it is recorded rather than quietly fixed: I checked the names I INVENTED for this change
against the corpus and found them free, and did not check the names that felt generic enough to
be safe. Genericness is what makes a collision likely, not what makes it unlikely. The check is
mechanical -- enumerate type/fn/data/variant declarations and look for the name -- and it now runs
over every introduced name rather than over the ones that looked risky.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf
@gunbai-bot
gunbai-bot Bot merged commit ecda071 into main Sep 2, 2026
9 of 12 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/quick-crab-396 branch September 2, 2026 07:25
gunbai-bot Bot pushed a commit that referenced this pull request Sep 2, 2026
Two conflicts, resolved by construction rather than by picking a side.

dag/gunbc/type_reference_decl_file_occurrence_census.dag was an add/add: #10002
squash-merged the census onto main while this branch carried the same file plus
the citation re-aiming. Diffed both sides before resolving -- main's side adds
nothing this branch lacks, its only difference IS the nine pre-split citations,
which name declarations this branch deletes. Took this branch's side because it is
the strict superset, not because it was ours.

docs/design-ledgers.md came back from the generated-artifact merge driver UNMERGED
with no conflict markers and the ours side verbatim, which is the driver refusing
rather than answering: both sides changed a generated projection since the merge
base, so neither side's bytes are the projection of the MERGED authorities and
taking either drops the other's authority-derived content. Regenerated through
main_wet_one as the driver instructs. It is now 270827 bytes, carries main's new
rows AND this branch's climb receipt, and against origin/main differs by exactly
the one line this branch authored.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015KnTJBDVSyUkrxKNUF4NCf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant