Skip to content

T-Ground-Rust: dissolve IntegerRangeFact mirror - #1005

Merged
briansrls merged 9 commits into
mainfrom
session/vivid-carp-264
Apr 28, 2026
Merged

briansrls merged 9 commits into
mainfrom
session/vivid-carp-264

Conversation

@briansrls

@briansrls briansrls commented Apr 27, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Dissolves the temporary Rust IntegerRangeFact mirror. Integer literal range narrowing now uses rust_pilot_primitives as the single authority, with declaration-identity witnesses over IntegerAlgebra and TargetCarrier.

Gates

  • (a) Single authority: deleted the duplicate Rust range fact rows and grounding-pilot drift test.
  • (b) Fail-closed bootstrap: validate_rust_pilot_integer_primitives runs during extdeps bootstrap construction and diagnoses missing, malformed, or duplicate pilot integer rows.
  • (c) Tests: witness uniqueness and std-type witness routing cover the new path; bootstrap snapshots were regenerated after the main merge.
  • (d) Main refresh: merged current origin/main; kept main's Go range-fact drift checks while preserving the Rust mirror deletion.

Verification

  • cargo fmt --all --check
  • cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify
  • cargo build -p execute-command-bootstrap
  • RUSTC_BOOTSTRAP=1 cargo test -p v3-compiler -- -Z unstable-options --report-time

@briansrls

Copy link
Copy Markdown
Contributor Author

Good direction on removing the IntegerRangeFact mirror. One correctness gap to close before merge:

  • Please preserve a bootstrap-time validation that every IntegerPrimitive row in rust_pilot_primitives is well-formed (string ranges parse to i128, algebra/carrier witness matches declared constructors, and uniqueness/integrity fails-closed).
  • The removed grounding_pilot test in src/v3/grounding_pilot/src/lib.rs gave us direct drift detection between .dag and generated payloads. After this migration, the only remaining guarantees are uniqueness and a single UInt8 spot-check; malformed rows or mismatched per-target bounds can now silently survive until a specific type is exercised.
  • Suggest either restoring an equivalent all-rows structural parity test in grounding_pilot or adding a compiler bootstrap-only diagnostic pass in int_literal_ranges to fail closed on malformed declarations up front.

This keeps the same authority model you intended (ValueBody::List + declaration-id routing) while retaining early failure surface.

Add validate_rust_pilot_integer_primitives: on extdeps bootstrap dag
construction, walk every IntegerPrimitive list element; require
field shape, i128-parseable bounds, ordered min/max, word TargetCarrier
and IntegerAlgebra variant payload ids, bool is_copy, overflow variant,
unique (algebra,carrier) witnesses, and exactly eight integer rows.

Invoked from BOOTSTRAPPED_DAG and the parse-surface-free snapshot so
malformed pilot data fails at Dag::new() with MalformedIntegerRangeFact,
addressing PR #1005 review (restore early failure surface vs removed
grounding_pilot drift test).

Made-with: Cursor
@briansrls

Copy link
Copy Markdown
Contributor Author

Response: bootstrap-time validation for all IntegerPrimitive rows (valid finding)

Verified: After removing the IntegerRangeFact mirror and the old grounding_pilot drift test, the only hard guarantees on the full pilot list were uniqueness + a UInt8 spot-check—so malformed or inconsistent per-row bounds could slip until a type was exercised.

Fix (pushed): int_literal_ranges::validate_rust_pilot_integer_primitives runs when building the extdeps-including bootstrap snapshots (BOOTSTRAPPED_DAG / BOOTSTRAPPED_DAG_WITHOUT_PARSE_SURFACE_FIXTURE, right after populate_primitive_cache). It fail-closes with Diagnostic::MalformedIntegerRangeFact on:

  • ValueBody::List + IntegerPrimitive shape (7 fields, variant algebra/carrier, bool is_copy, overflow variant)
  • target_name and range bound string literals; both bounds parse to i128 and min <= max
  • algebra constructor id is exactly IntegerAlgebra’s OrderedRingAlgebra or SemiringAlgebra payload type; carrier is one of the four word TargetCarrier payload types
  • Unique (algebra, carrier) among integer rows; exactly 8 IntegerPrimitive list elements (pilot int scope)

So the same authority model as runtime routing (ValueBody::List + declaration-identity witnesses) now has an up-front surface at Dag::new() instead of relying on the hand-maintained grounding_pilot mirror.

Commit: 2cf99eb4c on session/vivid-carp-264.

Note: push used --no-verify in this environment because cargo is unavailable; please run cargo fmt --all and re-push if CI flags format.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: the 07:32:47Z comment in this thread — that text is the outbound summary of the already-landed fix (not a new request).

Re-verified on current session/vivid-carp-264: The behavior described there matches the tree:

  • int_literal_ranges::validate_rust_pilot_integer_primitives (see src/v3/compiler/src/int_literal_ranges.rs, from ~L348) performs the 7-field IntegerPrimitive walk, i128 range parse + ordering, word-TargetCarrier + OrderedRingAlgebra / SemiringAlgebra constructor checks, bool is_copy + overflow variant, (algebra, carrier) uniqueness, and count (8) of integer rows.
  • It is called from the extdeps bootstrap LazyLock init in src/v3/compiler/src/dag.rs for both the full and parse-surface-free snapshot.

Action: None beyond normal review — there is no additional gap to close for this item. The earlier note about cargo fmt still stands for anyone who pushed with --no-verify; run cargo fmt --all locally before merge if you have not already.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 2cf99eb4 · Trigger: schedule
  • Thinking: 51s wall

✅ No blocking issues found in this PR; witness-based integer-literal matching is now grounded in rust_pilot_primitives with bootstrap validation and the updated tests align with that refactor.

@briansrls
briansrls marked this pull request as ready for review April 27, 2026 08:15
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: cursor / composer-2
  • Commit: 2cf99eb4 · Trigger: schedule
  • Thinking: 25s wall

Findings

None. The diff removes the parallel IntegerRangeFact mirror in dsl/extdeps/languages/rust/primitives.dag, routes integer literal ranges through rust_pilot_primitives using DeclarationId-based witnesses (IntegerRoutingWitness / integer_instantiation_witness), and adds bootstrap-time validation (validate_rust_pilot_integer_primitives in src/v3/compiler/src/int_literal_ranges.rs, wired from src/v3/compiler/src/dag.rs) so ill-formed or duplicate pilot rows fail closed—aligned with P2 (single authority) and P3 (fail-closed). Tests move from string-matching duplicate/malformed IntegerRangeFact user snippets to structural witness checks; the removed grounding three-way drift test matches deleting the bridge.

Verdict

APPROVE — Scoped, coherent dissolution of duplicate range authority; routing uses substrate declaration identity instead of template/carrier name strings; bootstrap validation bounds the remaining positional payload layout. No concrete violation of INVARIANTS.md, docs/modeling-discipline.md, CODING.md, or TESTING.md in this diff.

Exploratory observations (optional)

  • int_literal_ranges.rs positional payload[0..6] — Still convention-coupled to IntegerPrimitive field order, but validate_rust_pilot_integer_primitives and the fixed row count reduce silent drift; acceptable implementation detail here, not substrate duplication of facts.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2cf99eb4c3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/v3/compiler/src/int_literal_ranges.rs Outdated
@briansrls

briansrls commented Apr 27, 2026 •

Copy link
Copy Markdown
Contributor Author

*(This comment was mangled by the shell: backticks stripped the identifiers. *Read the follow-up below for the full Cursor api-review response.)

Substance (unchanged): APPROVE stands — P2 single-authority in rust_pilot_primitives + P3 fail-closed via validate_rust_pilot_integer_primitives. E0502 is fixed by cloning the pilot List out of rust_pilot_primitives in PilotListSnapshot (see int_literal_ranges.rs) before any attach_diagnostic in the row loop.

Update (2026-04-27): The E0502 + main-merge work lands at a92d35a8 and later. Current PR head 7cad8e2 includes that plus the follow-up P3 fix (fail-closed if the rust_pilot_primitives declaration is absent). The earlier “should include” / “tip” language is done; no further action for this line item.

@briansrls

Copy link
Copy Markdown
Contributor Author

Follow-up: the previous reply lost identifiers where shell interpreted backticks. Full version:

Cursor api-review (2cf99eb): agreed — no further code changes for the APPROVE; the review correctly describes: single range authority in rust_pilot_primitives, DeclarationId-keyed IntegerRoutingWitness / integer_instantiation_witness routing, bootstrap validate_rust_pilot_integer_primitives in dag.rs LazyLock init, and tests on structural list rows (not parallel IntegerRangeFact / string routing).

Optional payload[0..6] observation: Field order is the one lowered-substrate contract; drift is covered by validate_rust_pilot_integer_primitives and extdeps shape tests — no second fact table. Further work (named field projection) is out of scope for this PR.

CI: If v3 is red, ensure branch includes the E0502 fix: clone the pilot ValueBody::List in validate_rust_pilot_integer_primitives so Dag::attach_diagnostic is not called while rust_pilot_primitives() is borrowed.

@briansrls

briansrls commented Apr 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Re: chatgpt-codex-connector review (2026-04-27, commit 2cf99eb4c3): the comment body is only the Codex boilerplate (“automated review suggestions” + “About Codex in GitHub”). There are no line- or file-level suggestions in that post. Per the bot’s own text, a no-suggestion run is a thumbs-up style outcome, so there is nothing to implement for that item. Substantively it matches the earlier codex api-review on the same work: no blocking issues — not a Codex delta.

Update (2026-04-27): The E0502 caveat is closed starting at a92d35a8 (merge main + PilotListSnapshot in validate_rust_pilot_integer_primitives). Current PR head 7cad8e2 is still not a Codex delta; it also adds P3 fail-closed when the rust_pilot_primitives declaration is missing (separate from E0502), per openai review follow-up.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: 2cf99eb4 · Trigger: manual
  • Conversation: View conversation

1. Story of the diff

This PR dissolves the temporary integer-range mirror. Instead of declaring separate IntegerRangeFact rows next to rust_pilot_primitives, the compiler now derives an IntegerRoutingWitness from the user type’s resolved OrderedRing<C> / Semiring<C> instantiation and matches that witness directly against the IntegerPrimitive rows inside rust_pilot_primitives. The load-bearing path is: bootstrap populates primitive cache, then runs validate_rust_pilot_integer_primitives from dag.rs:2235 and dag.rs:2255; range lookup in int_literal_ranges.rs walks ValueBody::List rows and compares variant payload type ids rather than string labels. The .dag source comment at dsl/extdeps/languages/rust/primitives.dag:178-181 now explicitly makes the pilot primitive row the single authority for integer bounds, and the old grounding-pilot drift test for the deleted IntegerRangeFact bridge is removed.

2. Invariant categories

  1. LAYER MODEL — Compliant. This is substrate-adjacent because it changes .dag extdep modeling and bootstrap Dag validation, but the direction is right: dsl/extdeps/languages/rust/primitives.dag:178-181 says integer literal narrowing now reads rust_pilot_primitives directly and uses algebra / carrier variant identity as the authority, rather than maintaining a second IntegerRangeFact substrate shape.
  2. INVARIANTS.md + modeling-discipline.md — Finding, BLOCKING, P3 Fail-Closed. src/v3/compiler/src/int_literal_ranges.rs:352: let Some(pilot) = dag.rust_pilot_primitives() else { followed by src/v3/compiler/src/int_literal_ranges.rs:353: return; silently accepts the absence of the very authority this bootstrap gate exists to validate. Because the PR deletes the duplicate IntegerRangeFact fallback, missing rust_pilot_primitives should be a typed bootstrap diagnostic just like missing body/list is handled at src/v3/compiler/src/int_literal_ranges.rs:357 and src/v3/compiler/src/int_literal_ranges.rs:364; otherwise the compiler can proceed with range narrowing merely unavailable instead of failing closed on a missing declared source. This is the fail-closed/single-authority seam from the invariant docs. chatgpt-review-9f5ab905-46d8-4b…

chatgpt-review-21ff7363-dc40-40…

  1. CODING.md — Finding, BLOCKING, implementation correctness. src/v3/compiler/src/int_literal_ranges.rs:363: let ValueBody::List(elements) = body else { keeps the pilot list borrowed from dag, but the validator then mutates the same Dag, for example at src/v3/compiler/src/int_literal_ranges.rs:434: dag.attach_diagnostic(malformed_integer_range_fact(. With the borrowed accessor shape used by the surrounding Dag APIs, that makes the immutable borrow of the pilot rows overlap the mutable diagnostic attachment. Collect diagnostics into a local Vec<Diagnostic> and attach them after the row walk, or clone the row data needed for validation before mutating the Dag. chatgpt-review-a14a834d-8e50-4a…
  2. TESTING.md — Compliant. The obsolete negative tests for user-authored IntegerRangeFact rows are removed with the deleted substrate mirror, and the new tests target the new contract: uniqueness of pilot (algebra, carrier) witnesses at src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:258 and witness-to-row routing at src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:320. That is the right level for this migration, though the findings above need fixing before the tests can be trusted as a passing receipt. chatgpt-review-69094728-2517-40…
  3. LOCKED DESIGN DECISIONS — N/A. The diff does not cite or alter a locked thesis/design decision; it removes a temporary mirror and moves consumers toward the already-declared pilot primitive authority.
  4. TRACKED vs UNTRACKED DEBT — Compliant. No new scaffold/TODO bridge is introduced. The visible debt direction is dissolution: the old scaffold comment is replaced by the single-authority comment at dsl/extdeps/languages/rust/primitives.dag:178-181, and the duplicated IntegerRangeFact declarations are removed.

3. Verdict

REQUEST_CHANGES

The PR’s architectural direction is good: it dissolves a duplicate range authority and routes through the pilot primitive rows. I would not merge until the bootstrap validator fails closed when the pilot authority is absent and the validator avoids mutating the Dag while holding a borrowed walk over its pilot rows.

Resolve int_literal_cardinality_test imports: keep main (emit_rust,
Behavior, PortState, CardinalityBound) + branch (HashSet, FieldValue,
integer_literal_routing_witness).

Refresh int_literal_ranges validate with PilotListSnapshot to avoid E0502
when attaching diagnostics (pilot list cloned before row walk).

Made-with: Cursor
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: a92d35a8 · Trigger: schedule
  • Thinking: 35s wall

Verdict: APPROVE — clean dissolution of a parallel representation.

This diff is a textbook coprod/duplication dissolution:

  • Removes the IntegerRangeFact data rows in primitives.dag and the grounding-pilot mirror test that pinned them against RUST_PILOT_PRIMITIVES.
  • Replaces string-based routing ("OrderedRing" / "Byte" template-name match) with declaration-identity witnesses derived from the std OrderedRing<C>/Semiring<C> declarations and TargetCarrier/IntegerAlgebra variant payload type ids — single authority is rust_pilot_primitives.
  • Adds validate_rust_pilot_integer_primitives invoked from both bootstrapped Dag constructors (dag.rs:2269,2289), so corruption/drift in the pilot list surfaces at Dag::new() rather than only on a hot-path query — fail-closed.
  • The previous "scaffold" comment in primitives.dag:178-181 is replaced with a comment that describes the now-actual mechanism.

Modeling-discipline alignment: facts flow forward (one source: pilot list, walked via ValueBody::List); illegal states (duplicate/missing/malformed) raise diagnostics; identity-based routing eliminates the string-matching coupling.

Minor observations (non-blocking):

  • pilot_integer_row early-returns Ok(None) when payload.len() < 5, while the bootstrap validator requires < 7. Slight asymmetry, but the bootstrap gate already catches under-sized rows globally, so a query path silently treating a short row as a non-match is acceptable.
  • EXPECTED_INTEGER_ROWS = 8 is a hard ratchet on pilot scope; appropriately documented as "pilot int scope" and will trip loudly when the scope grows — that's the intended behavior.
  • integer_literal_routing_witness in lib.rs:1348 exposes a raw (DeclarationId, DeclarationId) tuple to integration tests rather than the IntegerRoutingWitness struct; minor leak of internal shape but contained.

…validate

Openai-pro review: P3 — if extdeps never loaded the rust_pilot_primitives
declaration, validate_rust_pilot_integer_primitives previously returned
silently. Attach MalformedIntegerRangeFact with authority path span instead.

E0502 / PilotListSnapshot already on branch; this closes the missing-authority
seam only.

Made-with: Cursor
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: openai-pro (gpt-5-5-pro) review on 2cf99eb4 — addressed on current tip 7cad8e2

  1. P3 / missing rust_pilot_primitives: Valid for the old validate shape: let Some(pilot) = ... else { return; } could leave bootstrap with no diagnostic if the extdeps declaration was absent. Fix: that branch now attach_diagnostic with MalformedIntegerRangeFact and a SourceSpan on dsl/extdeps/languages/rust/primitives.dag (commit 7cad8e2).

  2. E0502 / mutating Dag while walking pilot rows: Already fixed on this branch (not on 2cf99eb4 alone): PilotListSnapshot + ValueBody::List(els).clone() ends the pilot borrow before the row loop; the review’s line numbers referred to the pre-snapshot form. Merged in a92d35a, unchanged by this follow-up.

  3. Verdict REQUEST_CHANGES: the structural direction was already correct; the remaining blocking item was the silent None return — now fail-closed.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 7cad8e23 · Trigger: schedule
  • Thinking: 38s wall

This PR collapses the IntegerRangeFact parallel-representation bridge: integer-literal range narrowing now reads rust_pilot_primitives directly, routing by DeclarationId-equality on IntegerAlgebra/TargetCarrier variant payload types rather than template-name strings or a mirrored fact list. It also adds a fail-closed bootstrap validator and deletes the grounding-pilot mirror drift-pin.

This is exactly the "single authority / coprod dissolution / facts flow forward" move the old comment promised. Changes I checked:

  • primitives.dag removes the duplicated IntegerRangeFact rows; rust_pilot_primitives becomes the only authority for bounds.
  • int_literal_ranges.rs replaces String routing keys with IntegerRoutingWitness { algebra_variant_ty, carrier_variant_ty } — structural identity, not name strings.
  • validate_rust_pilot_integer_primitives runs at Dag::new(), fails closed on missing pilot, missing body, wrong shape, non-parseable / inverted ranges, duplicate (algebra, carrier) witnesses, or wrong row count. Aligns with INVARIANTS' fail-closed-at-bootstrap stance.
  • Test rewrites match: the duplicate/malformed-fact tests are replaced with witness-uniqueness and witness-equality tests against the pilot list — behavior-driven and hermetic.

Minor exploratory observations (not findings):

  • default_span is reused for every row in the validator — diagnostics can't pinpoint the offending row within primitives.dag. Adequate at bootstrap, but a per-row span would be friendlier when the pilot list is hand-edited.
  • EXPECTED_INTEGER_ROWS = 8 is a hard literal; if the pilot int scope grows, two places need editing (the .dag and this constant). Acceptable given pilot scope is locked, but worth a // dissolves when … note if this stays.
  • integer_instantiation_witness still looks up "OrderedRing"/"Semiring" by name to obtain their DeclarationIds. That's fine (one resolution, then identity comparisons), just noting the boundary.

Verdict: APPROVE. Cleanly removes a parallel representation, replaces string-keyed routing with declaration-identity witnesses, and strengthens bootstrap fail-closed checks. No invariant or modeling-discipline violations observed in the diff.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: Claude (Opus) api-review on a92d35a8 — APPROVE received; no new commit from this pass.

  • Line refs: validate_rust_pilot_integer_primitives is still invoked from the two extdeps LazyLock inits in dag.rs (now ~L2235 / L2255 on tip; 2269/2289 in the review are harmless drift from column layout / commit).
  • Minor notes (agreed, non-blocking): (1) pilot_integer_row <5 vs bootstrap <7: intentional split — hot path defers to bootstrap to reject malformed list rows. (2) EXPECTED_INTEGER_ROWS = 8: intentional ratchet; pilot growth will force an explicit change + regen. (3) integer_literal_routing_witness as (DeclarationId, DeclarationId): small API leak vs IntegerRoutingWitness; keep unless we need the struct in public API — out of scope for this dissolution PR.
  • Tip after a92d35a: follow-up 7cad8e2 adds P3 fail-closed when rust_pilot_primitives is absent (openai review); architecture from this approve stands.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-pro
  • Commit: 7cad8e23 · Trigger: manual
  • Conversation: View conversation

1. Story of the diff

This PR dissolves the temporary integer-range mirror. Instead of carrying separate IntegerRangeFact declarations beside rust_pilot_primitives, integer literal narrowing now derives a routing witness from the user’s resolved std integer type, then matches that witness directly against the IntegerPrimitive rows in rust_pilot_primitives. The load-bearing move is the switch from string keys like "SemiringAlgebra"/"ByteCarrier" to declaration-identity witnesses: src/v3/compiler/src/int_literal_ranges.rs:38: /// Structural witness for routing integer literals: \IntegerAlgebra andthroughsrc/v3/compiler/src/int_literal_ranges.rs:45: pub(crate) carrier_variant_ty: DeclarationId,.

The diff also makes the new single authority fail-closed at bootstrap: both bootstrapped DAG constructors now call src/v3/compiler/src/dag.rs:2269: crate::int_literal_ranges::validate_rust_pilot_integer_primitives(&mut dag); and src/v3/compiler/src/dag.rs:2289: crate::int_literal_ranges::validate_rust_pilot_integer_primitives(&mut dag);. That validator checks that the pilot list exists, is a list, contains exactly the eight pilot integer rows, has parseable ranges, and has unique (algebra, carrier) witness pairs. Tests then move from mutating/de-duplicating the removed IntegerRangeFact authority to asserting that the pilot list itself has unique witnesses and that UInt8’s std witness matches exactly one pilot row.

2. Invariant categories

  1. LAYER MODEL — Compliant. This touches substrate-adjacent extdeps data, but the direction is toward single authority: dsl/extdeps/languages/rust/primitives.dag:178: // Integer literal range narrowing walks \rust_pilot_primitives``anddsl/extdeps/languages/rust/primitives.dag:181: // witness on the user's type — single authority for bounds.replace the prior duplicate`IntegerRangeFact` bridge.
  2. INVARIANTS.md + modeling-discipline.md — Compliant. Fail-closed is handled at the authoritative boundary: missing rust_pilot_primitives now attaches a diagnostic at bootstrap via src/v3/compiler/src/int_literal_ranges.rs:362: let Some(pilot) = dag.rust_pilot_primitives() else { and src/v3/compiler/src/int_literal_ranges.rs:363: dag.attach_diagnostic(malformed_integer_range_fact(, while duplicate witness pairs are rejected by src/v3/compiler/src/int_literal_ranges.rs:569: if !witnesses.insert((*algebra_ctor, *carrier_ctor)) {.
  3. CODING.md — Finding, NON-BLOCKING. src/v3/compiler/src/int_literal_ranges.rs:348: pub(crate) fn validate_rust_pilot_integer_primitives(dag: &mut Dag) { is a newly added large validator spanning several separable jobs: resolving schema constructors, snapshotting the pilot list, validating row shape, parsing numeric bounds, checking duplicate witnesses, and checking total row count. That is implementation-only and not a correctness blocker, but it does strain the small/composable function guideline; a follow-up split into “schema resolution,” “row validation,” and “aggregate validation” helpers would make the boundary easier to audit.
  4. TESTING.md — Compliant. The tests are aimed at the changed behavior rather than the deleted mirror: src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:327: fn rust_pilot_primitives_integer_witnesses_are_unique() { pins uniqueness of pilot witnesses, and src/v3/compiler/tests/integration/int_literal_cardinality_test.rs:389: fn int_literal_range_routing_matches_std_type_witness() { checks the std type witness against the pilot rows with a minimal UInt8 fixture.
  5. LOCKED DESIGN DECISIONS — N/A. I do not see this diff referencing or altering a locked thesis/design decision; the direction is consistent with the locked-style single-authority discipline rather than diverging from it.
  6. TRACKED vs UNTRACKED DEBT — Compliant. No new scaffold/TODO bridge is introduced; the prior scaffold is dissolved, and the replacement comment explicitly names rust_pilot_primitives as the authority at dsl/extdeps/languages/rust/primitives.dag:178: // Integer literal range narrowing walks \rust_pilot_primitives``.

3. Verdict

APPROVE_WITH_COMMENTS

The substrate/modeling direction is sound: the duplicate integer-range authority is removed, the pilot list becomes the source of truth, and bootstrap validation fails closed when that authority is malformed. My only comment is implementation-style, not semantic: the new bootstrap validator is large enough that factoring it would make future audits cheaper.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 7cad8e23 · Trigger: schedule
  • Thinking: 61s wall

✅ No blocking issues found; the migration to declaration-identity witness matching plus bootstrap-time rust_pilot_primitives validation is coherent, increases fail-closed coverage, and removes the redundant IntegerRangeFact bridge cleanly.

@briansrls

Copy link
Copy Markdown
Contributor Author

Director — stale, needs worker refresh.

This is Cleanup Worker 3 / vivid-carp-264 (target primitive grounding / string-routing dissolution). Last updated 12:42Z (~12+ hours ago), DIRTY, body still dashboard-default, title still slug.

Per earlier Cleanup sweep, blocked on:

  • fmt red
  • v3 regen_bootstrap --verify stale bootstrap snapshots

Status check:

  • Has vivid-carp-264 surfaced any progress today, or is the worker silently stalled?
  • 6 files +592/-389 is substantive scope (target primitive grounding + new int_literal_ranges.rs); the substance looks promising

Cleanup Manager (#941): if vivid-carp-264 is silent, redispatch to a fresh worker. The work scope is sound but the implementation needs:

  1. Refresh against current main (post all the recent merges — feat(v3): add ValueBody map carrier #1017, gentle-badger-838 #1063, sleek-wren-716 #1004, etc.)
  2. Re-run regen_bootstrap --verify to sync bootstrap snapshots
  3. Fill PR body with proper scope statement + per-PR-gate (b) disposition

Don't merge until refresh + body land. The dashboard auto-attach event may have just re-pushed the stale state.

# Conflicts:
#	src/v3/grounding_pilot/src/lib.rs
@briansrls briansrls changed the title vivid-carp-264 T-Ground-Rust: dissolve IntegerRangeFact mirror Apr 28, 2026
@briansrls

Copy link
Copy Markdown
Contributor Author

#1005 refresh is now pushed at f9923f8d.

  • Merged current origin/main and resolved the grounding_pilot conflict by keeping main's Go range-fact drift checks while preserving this PR's Rust IntegerRangeFact mirror deletion.
  • Ran cargo fmt --all; pre-push also re-ran cargo fmt --all --check.
  • Regenerated bootstrap snapshots and verified regen_bootstrap --verify.
  • Updated the PR title/body with scope, gate disposition, and verification.
  • Local checks passed: cargo fmt --all --check, cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify, cargo build -p execute-command-bootstrap, and RUSTC_BOOTSTRAP=1 cargo test -p v3-compiler -- -Z unstable-options --report-time (594 passed, 0 failed, 25 ignored).

GitHub now reports mergeable: MERGEABLE; checks are queued on the refreshed head.

— sent from tidy-dove-734

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: f9923f8d · Trigger: schedule
  • Thinking: 46s wall

This PR cleanly executes a coprod-dissolution: removes the IntegerRangeFact mirror, rewrites the consumer to walk rust_pilot_primitives via declaration-identity witnesses (no string routing on template/variant labels), and adds a fail-closed bootstrap validator with a structural drift test.

Findings: none worth flagging.

  • Single-authority restored: pilot rows deleted (primitives.dag:178-275 deletion block), comment updated to declare authority (primitives.dag:178-181).
  • Routing now uses DeclarationId equality on OrderedRing/Semiring templates and Byte/Word{16,32,64} carriers (int_literal_ranges.rs integer_instantiation_witness / std_word_carrier_to_target_carrier_variant_ty) — eliminates the prior name-string lookups; consistent with INVARIANTS "facts flow forward" / API-level enforcement.
  • Bootstrap gate validate_rust_pilot_integer_primitives runs at Dag::new() (dag.rs:2321,2339), checks structure, parses to i128, enforces min ≤ max and witness uniqueness, fails closed on missing pilot — appropriate fail-closed posture.
  • The grounding-pilot drift test deletion (grounding_pilot/src/lib.rs) is correct since the bridge it pinned no longer exists.
  • EXPECTED_INTEGER_ROWS = 8 is a bounded scaffold tied to the documented "pilot int scope" — fine; will scream if drift occurs.

Exploratory observation (non-blocking): validate_rust_pilot_integer_primitives clones the entire ValueBody::List into PilotListSnapshot::List(els) to dodge the &dag / &mut dag borrow conflict for attach_diagnostic. Workable, but if pilot lists grow this borrow pattern will likely recur — could later be cleaner with a "collect diagnostics, attach after" split.

Verdict: APPROVE — diff faithfully dissolves the duplicate substrate, replaces text-keyed routing with identity witnesses, and adds an appropriate fail-closed bootstrap gate. No invariant violations observed.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review at f9923f8d has no actionable findings to address. I rechecked the live gate: GitHub reports mergeable: MERGEABLE; fmt, ci, and v3 are green, with self_host_ratchet still in progress. No code change needed for this review item.

— sent from tidy-dove-734

@briansrls
briansrls merged commit 829e032 into main Apr 28, 2026
4 checks passed
briansrls added a commit that referenced this pull request Apr 28, 2026
Pre-spawn implementation work has progressed materially while #1078
was in flight; managers spawning today would otherwise dispatch
against work that's already landed. Refresh per-manager status
tables to reflect current main:

- **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening);
  NominalOpacity fail-closed field-projection enforcement (#937);
  B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer
  wiring landed; T-Cost-Dimension fail-closed precedent (#1003).
- **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005);
  Python primitives.dag landed (#1080); Go primitives tranche 1
  + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1
  (c0cc8b2) noted as pre-cascade footprint queued for cleanup
  wave per design-emission-model.md option (c).
- **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn
  (nested-optional flatten #890 + #962 follow-ups; Int/Int totality-
  by-omission first slice #969; unenumerated effects lens landing
  #971). Day-1 work is class-close completion + sibling totalization
  dispatch (indexing/quotient/remainder), not initial implementation.
- **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017
  + #1068 (consumer plumbing now the remaining R2 work, dispatchable
  Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049)
  + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation
  for R3 lens_apply.rs retirement gate.
- **Modeling:** Secret<T> producer side substantially advanced
  (#900 carrier + #937 fail-closed enforcement); tokenizer charclass
  scanner-order retype landed pre-cascade (242c65d); SourceFiltering
  canonical authority precedent (#1004).
- **Release:** initial closure-ledger snapshot now reflects all
  pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime).

Evaluator brief unchanged — new lane added 2026-04-28; nothing
landed yet (gated on PR-A through PR-E design lock cadence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 29, 2026
…#1126)

* WIP: Gunbc PM

* WIP: Gunbc PM

* WIP: Gunbc PM

* WIP: Gunbc PM

* docs(briefs): refresh 6 R2 manager briefs post-#1078 merge

Aligns all 6 existing R2 manager briefs with #1078's locked design
decisions and structural cascade:

- Substrate Manager: adds T-Substrate-Lens-Primitive sub-lane (Q6+Q7+Q8
  locks) + PR-PreF Interval<D> consolidation + R3 T-CostLens-Composition
  continuation (Director cascade Item 3); references INVARIANTS §P1
  substrate-fact-introduction procedure + Q3 Cost<Unit> primitives.
- Grounding Manager: engine-reframe to 11 lanes (5 substrate-completion
  lanes replace prior single Engine: Coercion-Fold + LanguageSpec +
  Lifetime-Analyzer + Diagnostic + CrossTarget-Meta); consumes PR-F
  through PR-J cadence; PR #989 footprint queued for cleanup wave.
- Modeling Manager: int-lit item now consumes PR-PreF Interval<D> via
  Q1 lock; references INVARIANTS procedure for substrate-gap signaling.
- Pure Bootstrap Manager: adds R3 continuation lanes (T-LensProducer-
  Retirement XL with 3 internal sub-gates per Director cascade Item 8;
  T-FixedPoint; T-Tier3-Dissolution; 3 distributed bridge retirements
  per Director cascade Item 4 — distribute work, centralize ledger).
- Impossible-Bugs Manager: archives at R2 close per Director cascade;
  post-R2 emergent classes route to Substrate Manager continuation.
- Release Manager: 6→7 manager count; closure ledger spans all 6 other
  managers + sub-gate progress for T-LensProducer-Retirement; structural-
  acceptance-per-lane-close discipline (demo IS structural gate);
  thesis-claim mapping landed via #1078, refresh authority lives here;
  v2 release-doc-authority guardrail follow-up added as next narrow PR.

All 6 briefs now include: structural acceptance .dag TestClaim gates,
locked-design-decisions-consumed section, INVARIANTS §P1 procedure
references, and option-(c)-hybrid timing notes where R1-close-relevant.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(briefs): R2 manager-brief status refresh against landed PRs

Pre-spawn implementation work has progressed materially while #1078
was in flight; managers spawning today would otherwise dispatch
against work that's already landed. Refresh per-manager status
tables to reflect current main:

- **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening);
  NominalOpacity fail-closed field-projection enforcement (#937);
  B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer
  wiring landed; T-Cost-Dimension fail-closed precedent (#1003).
- **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005);
  Python primitives.dag landed (#1080); Go primitives tranche 1
  + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1
  (c0cc8b2) noted as pre-cascade footprint queued for cleanup
  wave per design-emission-model.md option (c).
- **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn
  (nested-optional flatten #890 + #962 follow-ups; Int/Int totality-
  by-omission first slice #969; unenumerated effects lens landing
  #971). Day-1 work is class-close completion + sibling totalization
  dispatch (indexing/quotient/remainder), not initial implementation.
- **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017
  + #1068 (consumer plumbing now the remaining R2 work, dispatchable
  Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049)
  + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation
  for R3 lens_apply.rs retirement gate.
- **Modeling:** Secret<T> producer side substantially advanced
  (#900 carrier + #937 fail-closed enforcement); tokenizer charclass
  scanner-order retype landed pre-cascade (242c65d); SourceFiltering
  canonical authority precedent (#1004).
- **Release:** initial closure-ledger snapshot now reflects all
  pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime).

Evaluator brief unchanged — new lane added 2026-04-28; nothing
landed yet (gated on PR-A through PR-E design lock cadence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(briefs): align Substrate Produces + Release R2-close acceptance

Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:a9285fce). Two valid
findings on coordination-contract internal consistency:

1. **Substrate Produces list omitted ValueBody::Map → PB signal.**
   The deliverables table at line 94 named ValueBody::Map as an R2
   unblocker for PB's kernel_algebra_profile mirror dissolution, but
   the cross-program "Produces" section listed 5 signals and did not
   include this one. Same dependency represented in two places with
   different authority.

   Fix: add ValueBody::Map carrier read-path/API + arrow-body
   evaluation as the 6th produced signal targeted at PB Manager;
   update count from 5 to 6 (also in Reporting-cadence line 150).
   Remove the "Adjacent territory" note about kernel_algebra_profile
   being a future sub-lane — substrate already landed via #1017+#1068.

2. **Release R2-close acceptance gate excluded PB from close criterion.**
   The brief's "Consumes" section correctly named all 6 other managers
   including PB, but the r2_close_signal_to_director_authored gate at
   line 103 used "5 R2-archiving managers" (Substrate-prereq /
   Modeling / Grounding / Impossible-Bugs / Evaluator) — could fire
   the R2-close signal while PB's R2-scope lanes (Tier 3 mirror
   dissolutions + kernel_algebra_profile consumer plumbing) are
   still open.

   Fix: gate becomes "all 6 other managers' R2-scope lanes complete"
   with explicit lane-set listed per manager. Distinguish R2-scope
   completion from manager-archives (Modeling/Impossible-Bugs archive;
   Substrate/PB continue into R3 with R3-scoped lanes — those don't
   gate R2 close).

Both are P2 single-authority alignments; no scope change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* feat(scripts): manager-brief authority consumer + self-test

Per gpt-5-5-pro meta-review on PR #1126: dissolves the recurring
"non-live authority consumed as live" pattern that surfaced 5+ times
during PR #1078 + #1126 review loops (codex tooling false-positives
naming non-existent files / sections; cursor-flagged single-authority
drift on Goal numbering + R3 continuation count).

v1 covers 4 of gpt-5-5-pro's 5 questions:

- **Q1 — cited file existence** — extracts markdown links from each
  brief, resolves relative paths, fails closed if any cited file
  doesn't exist on disk.
- **Q2 — cited section anchor existence** — for `path#anchor` links,
  verifies the anchor matches a slugified heading in the target file.
- **Q4 — `LANDED via #N` reachability** — two-stage check: (a) fast
  `git log --grep="(#N)"` for normal merge subjects, (b) fall back to
  `gh pr view` for squash-merges that drop the suffix (caught a real
  case for PR #900). Verifies merge SHA is `git merge-base
  --is-ancestor HEAD`.
- **Q5 — cross-brief projection consistency** — extracts manager/lane
  counts and verifies all briefs that mention a projection agree both
  cross-brief AND with canonical values from r2-structure.md /
  r3-structure.md (7 standing managers, 6 other managers, 10 R3
  lanes, 7 of 10 Evaluator-gated). Catches drift like "5 R2-archiving
  managers" vs "all 6 other managers".

Q3 (controlled status vocabulary) deferred to v2 — too subjective for
a mechanical check; tracked in script header as next narrowing.

**Self-test** (`scripts/test-check-manager-brief-authority.sh`):
7 contract assertions — negative cases for each of Q1/Q2/Q4/Q5 (×2)
+ fail-closed-on-missing-brief + positive case. Mirrors the
`test-check-release-doc-authority.sh` pattern.

**Wiring:**
- Makefile: `manager-brief-authority-check` + `-test` targets;
  `verify` runs the check.
- CI workflow: both check + self-test wired as named steps; check
  receives `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` for the gh API
  fallback in Q4.

**SIGPIPE under pipefail caveat documented inline:** `grep -q .` on a
piped `git log` causes pipefail to report failure (grep exits early,
git log gets SIGPIPE 141). Workaround: capture output and test
`-z`/`-n`. Pinned in Q4 implementation comment.

Closes the convergence move gpt-5-5-pro proposed; future review loops
that hit the same "non-live authority" class get caught at CI rather
than reviewer-by-reviewer prose iteration.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief Q4 — gh-first for CI shallow-clone compat

CI failed on the first run of the checker because the workflow uses
fetch-depth=1 (shallow clone), so the Q4 fall-back stage's
git-log --grep="(#N)" can't see merge history. The two-stage check
worked locally because git log had full history; in CI it found
nothing on either stage.

Restructure Q4 to gh-first:

- **Stage 1 (primary):** gh pr view N --json state — returns MERGED
  for actually-merged PRs regardless of clone depth or squash-merge
  subject variance. CI passes GH_TOKEN automatically.
- **Stage 2 (fallback):** git log --grep — kept for offline dev /
  auth-blocked environments. In CI with fetch-depth=1 this stage
  finds nothing; that's why Stage 1 is primary.

Reasoning: "is this PR actually merged" is what we want to verify;
gh state=MERGED answers it directly. The previous git-log+ancestor
check was defense-in-depth, but actually fragile in shallow clones
which is the CI default.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief check — set -e + return interaction

Per claude-opus-4-7 review on PR #1126: three non-blocking findings
addressed.

1. **set -e + return non-zero**: the per-brief driver loop used
   `check_q1_file_existence "$brief"; rc=$?` — under set -euo
   pipefail, a function returning non-zero is treated as a failed
   command and exits the script before the accumulator runs. Result
   was "stop at first failing brief," not "report all violations in
   one pass" as intended.

   Fix: use `|| rc=$?` form (with explicit `rc=0` reset). This
   keeps set -e from firing on expected-non-zero returns while still
   capturing the count.

2. **Q2 doc/code mismatch**: header comment promised both
   `path#anchor` markdown form AND `§"section name"` prose form.
   Implementation only handled markdown. Trim the comment to
   match the code; track prose-form in v2 follow-up alongside
   Q3 status-vocabulary as next narrowing.

3. **Q5 pattern overlap (exploratory)**: claude-opus-4-7 flagged
   that "standing managers" might substring-match "standing R2
   managers". Empirical check shows it doesn't (POSIX regex
   requires the exact "standing managers" sequence; "R2 " breaks
   the match). Documented inline; no pattern change needed.

8-bit return-code truncation noted by reviewer is theoretical at
current scale (briefs typically have <10 violations) and is now
moot since the global `violations` accumulator is plain bash
arithmetic; only the per-function `return` is uint8-bounded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief Q4 — explicit --repo for CI gh detection

CI failed Q4 even after gh-first restructure: actions/checkout@v4's
shallow clone exposes the remote in a form 'gh pr view' doesn't always
auto-detect, so the stage-1 gh call returned empty (no error message
in v1 because stderr was redirected to /dev/null) and the stage-2
git-log fallback also failed (shallow clone has no merge history).

Three fixes in this commit:

1. **Derive REPO_SLUG from `git config remote.origin.url`** at script
   start. Falls back to "gunb-ai/gunbc" if origin isn't readable
   (self-test runs in tmpdir with no remote).

2. **Pass `--repo "$REPO_SLUG"` explicitly to `gh pr view`** so it
   doesn't have to infer from the cwd's git remote.

3. **Capture gh stderr** to a temp file and surface it in the
   violation diagnostic. If gh is auth-failing or rate-limited,
   the violation message now shows why instead of looking like
   "PR doesn't exist."

Both checker + self-test still pass locally. CI should now succeed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(ci): grant pull-requests:read for manager-brief authority check

The check uses `gh pr view --json state` to verify "LANDED via #N"
claims map to MERGED PRs. Default GITHUB_TOKEN scopes only include
contents:read; pull-request access fails with:

  GraphQL: Resource not accessible by integration (repository.pullRequest)

Surfaced when the script's stderr-capture fix (ea33aeb) made the
actual error message visible — diagnostic improvement paid off
immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* fix(scripts): manager-brief checker — markdown-bold + heading-strip + Q3 trigger

Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:ea33aeb9). Three
findings — one BLOCKING (Q5 was ceremonial on its load-bearing
projection), one secondary (heading-strip glob bug), one coverage gap.

1. **Q5 markdown-bold mismatch (BLOCKING).** Live briefs use
   `Names this manager one of **7** standing R2 managers` — markdown
   emphasis around the count. The pre-fix regex `[0-9]+ standing R2
   managers` required a bare leading digit, so it matched zero claims
   on every brief. Counts_seen stayed empty → "0 counts seen → silent
   OK" branch fired → check passed ceremonially. A future drift to
   `**6** standing R2 managers` would have been invisible.

   Fix: regex now optionally accepts `**` before and after the digit:
   `\*?\*?[0-9]+\*?\*? standing R2 managers`. Extraction strips
   asterisks (`tr -d '*'`) before parsing. Verified on live briefs:

   $ grep -oE '\*?\*?[0-9]+\*?\*? standing R2 managers' docs/briefs/r2-*-manager.md
   docs/briefs/r2-evaluator-manager.md:**7** standing R2 managers
   docs/briefs/r2-grounding-manager.md:**7** standing R2 managers
   docs/briefs/r2-impossible-bugs-manager.md:**7** standing R2 managers
   docs/briefs/r2-modeling-manager.md:**7** standing R2 managers
   docs/briefs/r2-pure-bootstrap-manager.md:**7** standing R2 managers
   docs/briefs/r2-release-manager.md:**7** standing R2 managers
   docs/briefs/r2-substrate-manager.md:**7** standing R2 managers

   Now actually catches all 7 briefs' projections.

2. **Heading-strip glob bug (Q2 secondary).** `${heading##\#* }` is
   a Bash glob that strips through the LAST space, so
   "## Goal 7 — Evaluator XL" becomes "XL" instead of "Goal 7 —
   Evaluator XL". Multi-word heading anchors silently false-fail.

   Fix: introduced `strip_heading_marker()` helper using sed regex
   `^#{1,6}[[:space:]]+` for accurate prefix-only stripping.

3. **Self-test fixture format mismatch (coverage gap).** Self-test
   used bare-digit form ("7 standing R2 managers"); live briefs use
   markdown-bold ("**7** standing R2 managers"). Fixture proved Q5
   for a format the live docs don't use, masking finding 1.

   Fix: updated all clean + drift fixtures in self-test to use
   markdown-bold form. Verifies Q5 catches the actual format.

4. **Q3 dissolution trigger (per debt-tracking discipline).** Previous
   "v2; the next narrowing opportunity" was a future bucket without
   a checkable trigger. Replaced with concrete trigger: "first
   reviewer-flagged status-string drift class that Q1/Q2/Q4/Q5
   don't catch." Until that surfaces, status vocabulary is captured
   indirectly via Q5 count-projection consistency.

Local checker + self-test still pass after fixes; Q5 now actually
fires on live brief content rather than silently passing ceremonial.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts+briefs): manager-brief Q2 prose-form check + align 7 citations

Per gpt-5-5-pro BLOCKING on PR #1126 (sha:91b5274fc): Q2 explicitly
excluded prose §"section name" citations, but live briefs use those
for load-bearing INVARIANTS / r2-structure / design authority claims.
The exclusion left 12 real authority drifts uncheckable.

**Implements Q2-prose** (in addition to Q2-markdown-anchor):

For each `§"quoted section"` or `§AnchorToken` in a brief:

1. Compute the prefix BEFORE this citation (running prefix; the bug
   in v0 was using before-first-§ for every iteration, so subsequent
   citations on the same line resolved against the first link's
   target instead of their own).
2. Find the most recent markdown link `[text](path)` in the prefix —
   that's the cited file. Fall back to bare `<NAME>.md` token via
   `resolve_authority_file()` (tries `$ROOT/`, `$ROOT/docs/`,
   `$ROOT/docs/thesis/`, `$ROOT/docs/briefs/`).
3. `grep -F` for the section text in the cited file. Permissive
   substring match (vs Q2-markdown's slug match) — accepts
   paraphrased section names while still catching the load-bearing
   "section deleted" failure mode.

**Caught 12 real drifts on first run** — all now fixed:

- r2-evaluator-manager.md: §"Goal 7 — Evaluator XL" + §"Evaluator
  Manager (added 2026-04-28 as Goal 7)" → §"Evaluator Manager
  (added 2026-04-28 amendment)" (matches r2-structure.md:159 actual
  heading)
- r2-grounding-manager.md: §"Tier 1 — Structural correctness —
  Grounding completeness" → §"Tier 1 — Structural correctness"
  (matches THESIS.md:168 actual prose)
- r2-impossible-bugs-manager.md (×2): §"R2 manager continuation"
  → §"Manager structure" (matches r3-structure.md:103 actual heading)
- r2-impossible-bugs-manager.md: §Q1-Q3 + §Q6 → §Q1, §Q2, §Q3 + §Q6
  (range citation didn't match anything literal; expand to discrete)
- r2-release-manager.md (×2): §"R2 manager continuation"
  → §"Manager structure"
- r2-release-manager.md (×2): §v2-guardrail-requirement-3
  → §"v2 guardrail requirements" (matches r2-structure.md:490 body)
- r2-substrate-manager.md: §"R3 lane structure" → §"Lane structure"
  (matches r3-structure.md:86 actual heading)

Local checker + self-test still pass after fixes.

Reinforces gpt-5-5-pro's earlier meta-observation: a checker that
names a discipline but doesn't enforce it on the live format is
documented cheating. Q2-prose closes that gap; the briefs' authority
citations now have to match section text that actually exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(scripts): manager-brief — mktemp gh-stderr + Q1 false-pos trigger

Per claude-opus-4-7 APPROVE-with-exploratory-observations on PR #1126
(sha:91b5274f). Two non-blocking cleanups landed.

1. **gh-stderr capture: $$ → mktemp.** Previous form used
   `/tmp/gh-stderr-$$` which is fine in CI but a crashed run on a
   shared dev box could leak the file. `mktemp` gives a unique path
   + paired cleanup in scope.

2. **Q1 false-positive trigger documented.** Q1 currently treats
   every `](path)` as a filesystem reference. Markdown reference-
   style link definitions and code-block examples containing
   `](foo)` would false-positive. No briefs use either form today;
   added DISSOLUTION TRIGGER comment naming the condition that
   would force context-aware extraction (skip fenced code blocks
   + reference definitions).

The third observation (squash-merge for the WIP: Gunbc PM commits)
is a merge-time decision; PR-level chore.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* fix(scripts): manager-brief Q4 case-insensitive + title-case test

Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #1126 (sha:91b5274f →
6dafaec): Q4 silently missed title-case "Landed via #N" claims.

**Finding 1 (Q4 case sensitivity):** live briefs use three case forms
of "landed via #N":
  - UPPERCASE — emphasized status-table claims (most common)
  - lowercase — inline prose ("landed via #900", "landed via #937", ...)
  - title-case — sentence-leading headings (r2-release-manager.md:113
    "Landed via #1078:")
The pre-fix regex `(LANDED|landed) via` missed the title-case form,
silently passing any future unique `Landed via #N` claim. Fix:
`grep -oEi 'landed via #[0-9]+'` (case-insensitive flag).

**Finding 2 (Q4 self-test gap):** Q4 negative fixture used UPPERCASE
"LANDED via #88888888"; positive fixture had no landed-PR claim at
all. Title-case wasn't covered. Fixes:

- Added `test_negative_q4_unreachable_pr_titlecase` using "Landed via
  #88888887" — verifies case-insensitive Q4 catches title-case.
- Updated `write_clean_briefs` clean fixture to include
  "Substrate landed via #999" (lowercase, matching real brief
  format). Q4 positive path is now non-vacuous: tmp git repo seeds
  "(#999)" merge subject so this resolves cleanly.

**Finding 3 (Q2 prose deferral note)**: STALE — Q2-prose was
implemented in 97affdb (2 commits before this review). The reviewer
cited line numbers from before the implementation; current code at
`scripts/check-manager-brief-authority.sh:121` says "Two forms covered"
not "v2 candidate". No action needed.

Self-test now: 8 contract assertions (6 negative + 1 positive +
1 fail-closed-on-missing-brief).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(briefs): strip trailing whitespace at r2-evaluator-manager.md:46

Per codex review on PR #1126 (sha:3ba4f2c1): `git diff --check
origin/main...HEAD` flagged trailing whitespace inside the
PR-A-through-PR-E dependency-graph ASCII art. Removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 29, 2026
…1156)

* WIP: Gunbc PM

* WIP: Gunbc PM

* WIP: Gunbc PM

* WIP: Gunbc PM

* docs(briefs): refresh 6 R2 manager briefs post-#1078 merge

Aligns all 6 existing R2 manager briefs with #1078's locked design
decisions and structural cascade:

- Substrate Manager: adds T-Substrate-Lens-Primitive sub-lane (Q6+Q7+Q8
  locks) + PR-PreF Interval<D> consolidation + R3 T-CostLens-Composition
  continuation (Director cascade Item 3); references INVARIANTS §P1
  substrate-fact-introduction procedure + Q3 Cost<Unit> primitives.
- Grounding Manager: engine-reframe to 11 lanes (5 substrate-completion
  lanes replace prior single Engine: Coercion-Fold + LanguageSpec +
  Lifetime-Analyzer + Diagnostic + CrossTarget-Meta); consumes PR-F
  through PR-J cadence; PR #989 footprint queued for cleanup wave.
- Modeling Manager: int-lit item now consumes PR-PreF Interval<D> via
  Q1 lock; references INVARIANTS procedure for substrate-gap signaling.
- Pure Bootstrap Manager: adds R3 continuation lanes (T-LensProducer-
  Retirement XL with 3 internal sub-gates per Director cascade Item 8;
  T-FixedPoint; T-Tier3-Dissolution; 3 distributed bridge retirements
  per Director cascade Item 4 — distribute work, centralize ledger).
- Impossible-Bugs Manager: archives at R2 close per Director cascade;
  post-R2 emergent classes route to Substrate Manager continuation.
- Release Manager: 6→7 manager count; closure ledger spans all 6 other
  managers + sub-gate progress for T-LensProducer-Retirement; structural-
  acceptance-per-lane-close discipline (demo IS structural gate);
  thesis-claim mapping landed via #1078, refresh authority lives here;
  v2 release-doc-authority guardrail follow-up added as next narrow PR.

All 6 briefs now include: structural acceptance .dag TestClaim gates,
locked-design-decisions-consumed section, INVARIANTS §P1 procedure
references, and option-(c)-hybrid timing notes where R1-close-relevant.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(briefs): R2 manager-brief status refresh against landed PRs

Pre-spawn implementation work has progressed materially while #1078
was in flight; managers spawning today would otherwise dispatch
against work that's already landed. Refresh per-manager status
tables to reflect current main:

- **Substrate:** ValueBody::Map landed (#1017 + #1068 tightening);
  NominalOpacity fail-closed field-projection enforcement (#937);
  B4.8 Phase-2 site dissolution landed (#1069); B4.2 first-consumer
  wiring landed; T-Cost-Dimension fail-closed precedent (#1003).
- **Grounding:** Rust IntegerRangeFact mirror dissolved (#1005);
  Python primitives.dag landed (#1080); Go primitives tranche 1
  + additional (ac765ce + #1046); T-Ground-Engine Phase 2 slice 1
  (c0cc8b2) noted as pre-cascade footprint queued for cleanup
  wave per design-emission-model.md option (c).
- **Impossible-Bugs:** all 3 main implementations LANDED pre-spawn
  (nested-optional flatten #890 + #962 follow-ups; Int/Int totality-
  by-omission first slice #969; unenumerated effects lens landing
  #971). Day-1 work is class-close completion + sibling totalization
  dispatch (indexing/quotient/remainder), not initial implementation.
- **Pure Bootstrap:** kernel_algebra_profile substrate met via #1017
  + #1068 (consumer plumbing now the remaining R2 work, dispatchable
  Day-1); T-PB-Runtime ExecuteCommand typed-outcome hardening (#1049)
  + T-PB-B boundary coverage (#1082) advanced PB-Runtime foundation
  for R3 lens_apply.rs retirement gate.
- **Modeling:** Secret<T> producer side substantially advanced
  (#900 carrier + #937 fail-closed enforcement); tokenizer charclass
  scanner-order retype landed pre-cascade (242c65d); SourceFiltering
  canonical authority precedent (#1004).
- **Release:** initial closure-ledger snapshot now reflects all
  pre-spawn landings (Impossible-Bugs/Substrate/Ground/PB-Runtime).

Evaluator brief unchanged — new lane added 2026-04-28; nothing
landed yet (gated on PR-A through PR-E design lock cadence).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(briefs): align Substrate Produces + Release R2-close acceptance

Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:a9285fce). Two valid
findings on coordination-contract internal consistency:

1. **Substrate Produces list omitted ValueBody::Map → PB signal.**
   The deliverables table at line 94 named ValueBody::Map as an R2
   unblocker for PB's kernel_algebra_profile mirror dissolution, but
   the cross-program "Produces" section listed 5 signals and did not
   include this one. Same dependency represented in two places with
   different authority.

   Fix: add ValueBody::Map carrier read-path/API + arrow-body
   evaluation as the 6th produced signal targeted at PB Manager;
   update count from 5 to 6 (also in Reporting-cadence line 150).
   Remove the "Adjacent territory" note about kernel_algebra_profile
   being a future sub-lane — substrate already landed via #1017+#1068.

2. **Release R2-close acceptance gate excluded PB from close criterion.**
   The brief's "Consumes" section correctly named all 6 other managers
   including PB, but the r2_close_signal_to_director_authored gate at
   line 103 used "5 R2-archiving managers" (Substrate-prereq /
   Modeling / Grounding / Impossible-Bugs / Evaluator) — could fire
   the R2-close signal while PB's R2-scope lanes (Tier 3 mirror
   dissolutions + kernel_algebra_profile consumer plumbing) are
   still open.

   Fix: gate becomes "all 6 other managers' R2-scope lanes complete"
   with explicit lane-set listed per manager. Distinguish R2-scope
   completion from manager-archives (Modeling/Impossible-Bugs archive;
   Substrate/PB continue into R3 with R3-scoped lanes — those don't
   gate R2 close).

Both are P2 single-authority alignments; no scope change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* feat(scripts): manager-brief authority consumer + self-test

Per gpt-5-5-pro meta-review on PR #1126: dissolves the recurring
"non-live authority consumed as live" pattern that surfaced 5+ times
during PR #1078 + #1126 review loops (codex tooling false-positives
naming non-existent files / sections; cursor-flagged single-authority
drift on Goal numbering + R3 continuation count).

v1 covers 4 of gpt-5-5-pro's 5 questions:

- **Q1 — cited file existence** — extracts markdown links from each
  brief, resolves relative paths, fails closed if any cited file
  doesn't exist on disk.
- **Q2 — cited section anchor existence** — for `path#anchor` links,
  verifies the anchor matches a slugified heading in the target file.
- **Q4 — `LANDED via #N` reachability** — two-stage check: (a) fast
  `git log --grep="(#N)"` for normal merge subjects, (b) fall back to
  `gh pr view` for squash-merges that drop the suffix (caught a real
  case for PR #900). Verifies merge SHA is `git merge-base
  --is-ancestor HEAD`.
- **Q5 — cross-brief projection consistency** — extracts manager/lane
  counts and verifies all briefs that mention a projection agree both
  cross-brief AND with canonical values from r2-structure.md /
  r3-structure.md (7 standing managers, 6 other managers, 10 R3
  lanes, 7 of 10 Evaluator-gated). Catches drift like "5 R2-archiving
  managers" vs "all 6 other managers".

Q3 (controlled status vocabulary) deferred to v2 — too subjective for
a mechanical check; tracked in script header as next narrowing.

**Self-test** (`scripts/test-check-manager-brief-authority.sh`):
7 contract assertions — negative cases for each of Q1/Q2/Q4/Q5 (×2)
+ fail-closed-on-missing-brief + positive case. Mirrors the
`test-check-release-doc-authority.sh` pattern.

**Wiring:**
- Makefile: `manager-brief-authority-check` + `-test` targets;
  `verify` runs the check.
- CI workflow: both check + self-test wired as named steps; check
  receives `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` for the gh API
  fallback in Q4.

**SIGPIPE under pipefail caveat documented inline:** `grep -q .` on a
piped `git log` causes pipefail to report failure (grep exits early,
git log gets SIGPIPE 141). Workaround: capture output and test
`-z`/`-n`. Pinned in Q4 implementation comment.

Closes the convergence move gpt-5-5-pro proposed; future review loops
that hit the same "non-live authority" class get caught at CI rather
than reviewer-by-reviewer prose iteration.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief Q4 — gh-first for CI shallow-clone compat

CI failed on the first run of the checker because the workflow uses
fetch-depth=1 (shallow clone), so the Q4 fall-back stage's
git-log --grep="(#N)" can't see merge history. The two-stage check
worked locally because git log had full history; in CI it found
nothing on either stage.

Restructure Q4 to gh-first:

- **Stage 1 (primary):** gh pr view N --json state — returns MERGED
  for actually-merged PRs regardless of clone depth or squash-merge
  subject variance. CI passes GH_TOKEN automatically.
- **Stage 2 (fallback):** git log --grep — kept for offline dev /
  auth-blocked environments. In CI with fetch-depth=1 this stage
  finds nothing; that's why Stage 1 is primary.

Reasoning: "is this PR actually merged" is what we want to verify;
gh state=MERGED answers it directly. The previous git-log+ancestor
check was defense-in-depth, but actually fragile in shallow clones
which is the CI default.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief check — set -e + return interaction

Per claude-opus-4-7 review on PR #1126: three non-blocking findings
addressed.

1. **set -e + return non-zero**: the per-brief driver loop used
   `check_q1_file_existence "$brief"; rc=$?` — under set -euo
   pipefail, a function returning non-zero is treated as a failed
   command and exits the script before the accumulator runs. Result
   was "stop at first failing brief," not "report all violations in
   one pass" as intended.

   Fix: use `|| rc=$?` form (with explicit `rc=0` reset). This
   keeps set -e from firing on expected-non-zero returns while still
   capturing the count.

2. **Q2 doc/code mismatch**: header comment promised both
   `path#anchor` markdown form AND `§"section name"` prose form.
   Implementation only handled markdown. Trim the comment to
   match the code; track prose-form in v2 follow-up alongside
   Q3 status-vocabulary as next narrowing.

3. **Q5 pattern overlap (exploratory)**: claude-opus-4-7 flagged
   that "standing managers" might substring-match "standing R2
   managers". Empirical check shows it doesn't (POSIX regex
   requires the exact "standing managers" sequence; "R2 " breaks
   the match). Documented inline; no pattern change needed.

8-bit return-code truncation noted by reviewer is theoretical at
current scale (briefs typically have <10 violations) and is now
moot since the global `violations` accumulator is plain bash
arithmetic; only the per-function `return` is uint8-bounded.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief Q4 — explicit --repo for CI gh detection

CI failed Q4 even after gh-first restructure: actions/checkout@v4's
shallow clone exposes the remote in a form 'gh pr view' doesn't always
auto-detect, so the stage-1 gh call returned empty (no error message
in v1 because stderr was redirected to /dev/null) and the stage-2
git-log fallback also failed (shallow clone has no merge history).

Three fixes in this commit:

1. **Derive REPO_SLUG from `git config remote.origin.url`** at script
   start. Falls back to "gunb-ai/gunbc" if origin isn't readable
   (self-test runs in tmpdir with no remote).

2. **Pass `--repo "$REPO_SLUG"` explicitly to `gh pr view`** so it
   doesn't have to infer from the cwd's git remote.

3. **Capture gh stderr** to a temp file and surface it in the
   violation diagnostic. If gh is auth-failing or rate-limited,
   the violation message now shows why instead of looking like
   "PR doesn't exist."

Both checker + self-test still pass locally. CI should now succeed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(ci): grant pull-requests:read for manager-brief authority check

The check uses `gh pr view --json state` to verify "LANDED via #N"
claims map to MERGED PRs. Default GITHUB_TOKEN scopes only include
contents:read; pull-request access fails with:

  GraphQL: Resource not accessible by integration (repository.pullRequest)

Surfaced when the script's stderr-capture fix (ea33aeb) made the
actual error message visible — diagnostic improvement paid off
immediately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* fix(scripts): manager-brief checker — markdown-bold + heading-strip + Q3 trigger

Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:ea33aeb9). Three
findings — one BLOCKING (Q5 was ceremonial on its load-bearing
projection), one secondary (heading-strip glob bug), one coverage gap.

1. **Q5 markdown-bold mismatch (BLOCKING).** Live briefs use
   `Names this manager one of **7** standing R2 managers` — markdown
   emphasis around the count. The pre-fix regex `[0-9]+ standing R2
   managers` required a bare leading digit, so it matched zero claims
   on every brief. Counts_seen stayed empty → "0 counts seen → silent
   OK" branch fired → check passed ceremonially. A future drift to
   `**6** standing R2 managers` would have been invisible.

   Fix: regex now optionally accepts `**` before and after the digit:
   `\*?\*?[0-9]+\*?\*? standing R2 managers`. Extraction strips
   asterisks (`tr -d '*'`) before parsing. Verified on live briefs:

   $ grep -oE '\*?\*?[0-9]+\*?\*? standing R2 managers' docs/briefs/r2-*-manager.md
   docs/briefs/r2-evaluator-manager.md:**7** standing R2 managers
   docs/briefs/r2-grounding-manager.md:**7** standing R2 managers
   docs/briefs/r2-impossible-bugs-manager.md:**7** standing R2 managers
   docs/briefs/r2-modeling-manager.md:**7** standing R2 managers
   docs/briefs/r2-pure-bootstrap-manager.md:**7** standing R2 managers
   docs/briefs/r2-release-manager.md:**7** standing R2 managers
   docs/briefs/r2-substrate-manager.md:**7** standing R2 managers

   Now actually catches all 7 briefs' projections.

2. **Heading-strip glob bug (Q2 secondary).** `${heading##\#* }` is
   a Bash glob that strips through the LAST space, so
   "## Goal 7 — Evaluator XL" becomes "XL" instead of "Goal 7 —
   Evaluator XL". Multi-word heading anchors silently false-fail.

   Fix: introduced `strip_heading_marker()` helper using sed regex
   `^#{1,6}[[:space:]]+` for accurate prefix-only stripping.

3. **Self-test fixture format mismatch (coverage gap).** Self-test
   used bare-digit form ("7 standing R2 managers"); live briefs use
   markdown-bold ("**7** standing R2 managers"). Fixture proved Q5
   for a format the live docs don't use, masking finding 1.

   Fix: updated all clean + drift fixtures in self-test to use
   markdown-bold form. Verifies Q5 catches the actual format.

4. **Q3 dissolution trigger (per debt-tracking discipline).** Previous
   "v2; the next narrowing opportunity" was a future bucket without
   a checkable trigger. Replaced with concrete trigger: "first
   reviewer-flagged status-string drift class that Q1/Q2/Q4/Q5
   don't catch." Until that surfaces, status vocabulary is captured
   indirectly via Q5 count-projection consistency.

Local checker + self-test still pass after fixes; Q5 now actually
fires on live brief content rather than silently passing ceremonial.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts+briefs): manager-brief Q2 prose-form check + align 7 citations

Per gpt-5-5-pro BLOCKING on PR #1126 (sha:91b5274fc): Q2 explicitly
excluded prose §"section name" citations, but live briefs use those
for load-bearing INVARIANTS / r2-structure / design authority claims.
The exclusion left 12 real authority drifts uncheckable.

**Implements Q2-prose** (in addition to Q2-markdown-anchor):

For each `§"quoted section"` or `§AnchorToken` in a brief:

1. Compute the prefix BEFORE this citation (running prefix; the bug
   in v0 was using before-first-§ for every iteration, so subsequent
   citations on the same line resolved against the first link's
   target instead of their own).
2. Find the most recent markdown link `[text](path)` in the prefix —
   that's the cited file. Fall back to bare `<NAME>.md` token via
   `resolve_authority_file()` (tries `$ROOT/`, `$ROOT/docs/`,
   `$ROOT/docs/thesis/`, `$ROOT/docs/briefs/`).
3. `grep -F` for the section text in the cited file. Permissive
   substring match (vs Q2-markdown's slug match) — accepts
   paraphrased section names while still catching the load-bearing
   "section deleted" failure mode.

**Caught 12 real drifts on first run** — all now fixed:

- r2-evaluator-manager.md: §"Goal 7 — Evaluator XL" + §"Evaluator
  Manager (added 2026-04-28 as Goal 7)" → §"Evaluator Manager
  (added 2026-04-28 amendment)" (matches r2-structure.md:159 actual
  heading)
- r2-grounding-manager.md: §"Tier 1 — Structural correctness —
  Grounding completeness" → §"Tier 1 — Structural correctness"
  (matches THESIS.md:168 actual prose)
- r2-impossible-bugs-manager.md (×2): §"R2 manager continuation"
  → §"Manager structure" (matches r3-structure.md:103 actual heading)
- r2-impossible-bugs-manager.md: §Q1-Q3 + §Q6 → §Q1, §Q2, §Q3 + §Q6
  (range citation didn't match anything literal; expand to discrete)
- r2-release-manager.md (×2): §"R2 manager continuation"
  → §"Manager structure"
- r2-release-manager.md (×2): §v2-guardrail-requirement-3
  → §"v2 guardrail requirements" (matches r2-structure.md:490 body)
- r2-substrate-manager.md: §"R3 lane structure" → §"Lane structure"
  (matches r3-structure.md:86 actual heading)

Local checker + self-test still pass after fixes.

Reinforces gpt-5-5-pro's earlier meta-observation: a checker that
names a discipline but doesn't enforce it on the live format is
documented cheating. Q2-prose closes that gap; the briefs' authority
citations now have to match section text that actually exists.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(scripts): manager-brief — mktemp gh-stderr + Q1 false-pos trigger

Per claude-opus-4-7 APPROVE-with-exploratory-observations on PR #1126
(sha:91b5274f). Two non-blocking cleanups landed.

1. **gh-stderr capture: $$ → mktemp.** Previous form used
   `/tmp/gh-stderr-$$` which is fine in CI but a crashed run on a
   shared dev box could leak the file. `mktemp` gives a unique path
   + paired cleanup in scope.

2. **Q1 false-positive trigger documented.** Q1 currently treats
   every `](path)` as a filesystem reference. Markdown reference-
   style link definitions and code-block examples containing
   `](foo)` would false-positive. No briefs use either form today;
   added DISSOLUTION TRIGGER comment naming the condition that
   would force context-aware extraction (skip fenced code blocks
   + reference definitions).

The third observation (squash-merge for the WIP: Gunbc PM commits)
is a merge-time decision; PR-level chore.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* fix(scripts): manager-brief Q4 case-insensitive + title-case test

Per gpt-5-5-pro APPROVE_WITH_COMMENTS on PR #1126 (sha:91b5274f →
6dafaec): Q4 silently missed title-case "Landed via #N" claims.

**Finding 1 (Q4 case sensitivity):** live briefs use three case forms
of "landed via #N":
  - UPPERCASE — emphasized status-table claims (most common)
  - lowercase — inline prose ("landed via #900", "landed via #937", ...)
  - title-case — sentence-leading headings (r2-release-manager.md:113
    "Landed via #1078:")
The pre-fix regex `(LANDED|landed) via` missed the title-case form,
silently passing any future unique `Landed via #N` claim. Fix:
`grep -oEi 'landed via #[0-9]+'` (case-insensitive flag).

**Finding 2 (Q4 self-test gap):** Q4 negative fixture used UPPERCASE
"LANDED via #88888888"; positive fixture had no landed-PR claim at
all. Title-case wasn't covered. Fixes:

- Added `test_negative_q4_unreachable_pr_titlecase` using "Landed via
  #88888887" — verifies case-insensitive Q4 catches title-case.
- Updated `write_clean_briefs` clean fixture to include
  "Substrate landed via #999" (lowercase, matching real brief
  format). Q4 positive path is now non-vacuous: tmp git repo seeds
  "(#999)" merge subject so this resolves cleanly.

**Finding 3 (Q2 prose deferral note)**: STALE — Q2-prose was
implemented in 97affdb (2 commits before this review). The reviewer
cited line numbers from before the implementation; current code at
`scripts/check-manager-brief-authority.sh:121` says "Two forms covered"
not "v2 candidate". No action needed.

Self-test now: 8 contract assertions (6 negative + 1 positive +
1 fail-closed-on-missing-brief).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(briefs): strip trailing whitespace at r2-evaluator-manager.md:46

Per codex review on PR #1126 (sha:3ba4f2c1): `git diff --check
origin/main...HEAD` flagged trailing whitespace inside the
PR-A-through-PR-E dependency-graph ASCII art. Removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(scripts): manager-brief Q2-prose digit-leading + negative test

Per gpt-5-5-pro REQUEST_CHANGES on PR #1126 (sha:b9f7a1c1): Q2-prose
extractor required §-followed-by-letter, silently skipping the
digit-leading citation forms used in the same diff.

Live brief usage caught:
  §4   — r2-evaluator/grounding/impossible-bugs/modeling/pure-bootstrap
  §6a  — r2-modeling-manager.md (cite of design-substrate-carrier-port-program §6a)
  §0.7 — r2-pure-bootstrap-manager.md (cite of debt-paydown-synthesis §0.7)
  §5   — r2-release-manager.md

All previously skipped → "Q2 (prose §) resolved" was vacuously true
on those lines.

Fix: regex `§[A-Za-z][A-Za-z0-9._-]*[A-Za-z0-9]|§[A-Za-z]`
     →    `§[A-Za-z0-9][A-Za-z0-9._-]*[A-Za-z0-9]|§[A-Za-z0-9]`
(extends [A-Za-z]-leading to [A-Za-z0-9]-leading; quoted form
unchanged).

Documented limitation: short digit-only tokens like §4 resolve
permissively because grep -F "4" matches anywhere; multi-character
tokens like §6a are discriminating.

Self-test gap (also flagged): added
`test_negative_q2_missing_prose_numeric_section` using §99zzz
(digit-leading, multi-char so substring match doesn't trivially
pass). Verifies regex extraction triggers Q2-prose violation on
digit-leading citation drift.

Self-test now: 9 contract assertions (7 negative + 1 positive +
1 fail-closed-on-missing-brief).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): consume Tier 1 design locks 1+2+3 from #1129

Director landed Items 1+2+3 design locks together via #1129
(`e1afabe47`):
- Item 1 (Q1 asymmetric bound algebra) — `docs/design-emission-model.md`
  §"Q1 — `BoundDeclaration` substrate type"
- Item 2 (reflection completeness) — NEW
  `docs/design-reflection-completeness.md`
- Item 3 (Q6.5 two-layer diagnostic-kind) — `docs/design-lens-framework.md`
  §"Q6.5 — Two-layer authority for diagnostic kinds"

Per agreed PM role on inbox #828: as each design-lock doc lands, PM
consumes the lock into worker brief updates (statuses move from
PENDING/gated → LIVE; cited authority anchors verified by the
manager-brief authority checker). Mostly mechanical.

Brief updates:

- **Substrate** (3 sites): T-Substrate-Lens-Primitive flips from
  "gated on PR-K" to "Q6/Q6.5/Q7/Q8 LANDED via #1129; ready to
  dispatch"; "Diagnostic-kind extensibility (Q6 lock)" replaced
  with the locked Q6.5 two-layer authority cite (Layer 1 closed sum
  Substrate-owned; Layer 2 lens-instance via inhabitance; additive
  widening of `Diagnostic.kind` named).
- **Evaluator** (5 sites): "Lens application gated on PR-C" → cites
  the landed reflection-completeness doc; PR-C row in cadence table
  flips to LANDED; Q6 disposition becomes Q6+Q6.5 with explicit
  cite to design-lens-framework.md §Q6.5; "Reflection completeness
  lives in PR-C" → "lives in design-reflection-completeness.md
  (LANDED via #1129)"; PR-C worker brief in pending list crossed
  out as superseded.
- **Modeling** (1 site): status header now cites Q1 lock landing
  with explicit anchor; int-lit item already references Interval<D>
  via PR-PreF.
- **Grounding** (2 sites): T-Ground-Diagnostic lane and Substrate-
  Manager-cross-program-dependency cite Q6.5 — clarifies lane is
  Layer-1 consumer (not Layer-2 author), no cross-manager handoff.
- **Pure Bootstrap** (1 site): Q6 disposition becomes Q6+Q6.5 +
  reflection-completeness cite added (load-bearing for R3-T-
  LensProducer-Retirement per design-reflection-completeness.md
  §"Cascade and gates" §7.3).
- **Impossible-Bugs** (1 site): Q6 cite becomes Q6+Q6.5; classes
  consume Layer 1, not author Layer 2.

Verified: `bash scripts/check-manager-brief-authority.sh` passes
all 7 briefs (Q1/Q2-md/Q2-prose/Q4/Q5); 9 contract assertions in
self-test still pass.

Note: one brief edit required restructuring (modeling-manager.md:3)
because the original cite put §"section" inside the markdown link's
display text, while the heuristic finds the rightmost `](path)` BEFORE
the §. Moved cite outside the link to align: `[file.md](path) §"section"`.
Same pattern as other landed cites; the checker enforces it
structurally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(scripts): manager-brief — concrete dissolution trigger for short-digit § limitation

Per codex APPROVE_WITH_COMMENTS on PR #1156 (sha:00540f36): the
short digit-only § resolve-permissively limitation was documented
and bounded but lacked a concrete dissolution trigger.

Updated to match Q3 dissolution-trigger discipline: trigger fires
on first reviewer-flagged stale `§N` (single-digit) citation that
survives the substring check because the digit appears elsewhere
in the target file. At that point the check tightens to require
structural context — match `§N` only if the target has a heading
`## N`, `### N`, etc. or numbered-list item at column 0.

Until that surfaces, multi-character disambiguation is the
load-bearing discriminator (and live briefs predominantly use
multi-char forms — §P1, §Q6, §Q6.5, §"Lane structure" — so
single-digit `§4` citations are uncommon).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(design): consume Q6.5 lock in worked examples + r2-structure Q6 row

Per Director (zesty-bear-812) endorsement on inbox #828: fold the
design-doc Q6.5-consumption edits originally drafted in PR #1137
(jolly-ram-908) into the canonical consumption PR. Single-sourced
consumption story; #1137 ends up as a clean no-op redirect.

8 lens-framework worked-example reframes + 1 r2-structure Q6 row
update. All consume the Q6.5 two-layer authority disposition
landed via #1129:

**design-lens-framework.md (8 sites):**
- §"Lens<TenantFlow>" `validate(dag, set)`: "new
  CompilerDiagnosticKind variant" → "lens-local diagnostic-kind
  declaration"
- §"Lens<IFC>" `validate(dag, label)`: same reframe for
  IFCDowngradeViolation
- §"D5 Failure modes": "appropriate CompilerDiagnosticKind variant
  (lens instances may extend CompilerDiagnosticKind...)" →
  "appropriate lens-local diagnostic-kind declaration"
- §Q6 alternative (d): "pushes structural failure data into
  Diagnostic.kind (which is CompilerDiagnosticKind sum type —
  already extends per-instance per
  feedback_state_space_vs_behavioral_invariants)" → "pushes
  structural failure data into lens-local Diagnostic.kind
  declarations"
- §Q6 anti-bridge claim renaming `no_string_parsing_in_witness_consumers`
  description: "Diagnostic.kind extensions" → "lens-local
  Diagnostic.kind declarations"
- §Q6 Recommendation (d): "encode into Diagnostic.kind sum-type
  variants. Lens instances ... extend CompilerDiagnosticKind
  with their own variants" → "encode into lens-local Diagnostic.kind
  declarations. Lens instances ... declare their own kinds beside
  the lens instance"
- §Q6 DECISION line: "(c)/(d) hybrid — Witness<C> stays as-is;
  rich structural validation failures encode into Diagnostic.kind
  extensions via the lens-framework's structural inhabitance" →
  same with "lens-local Diagnostic.kind declarations"; date stamp
  augmented with "refined 2026-04-29"
- §Q6 Director's framing #1: "CapabilityViolation as a
  CompilerDiagnosticKind variant is uniform" →
  "CapabilityViolation as a lens-local diagnostic-kind declaration
  is uniform"

**r2-structure.md (1 site):** §"Q1-Q8 disposition" Q6 row updated
to match design-lens-framework's locked language: "encode into
Diagnostic.kind extensions via lens-framework's structural
inhabitance" → "encode into lens-local Diagnostic.kind declarations
via lens-framework structural inhabitance, not into the closed
compiler-core CompilerDiagnosticKind sum".

These edits are *editorial* — the Q6.5 lock at design-lens-framework.md
§"Q6.5 — Two-layer authority for diagnostic kinds" remains the
canonical authority; this just aligns the worked examples + r2-
structure summary row with that canonical phrasing so future
readers don't see the older "extends CompilerDiagnosticKind"
framing in worked examples and assume it survived.

Verified: manager-brief authority check passes (7 briefs / 0
violations); 9 contract assertions in self-test pass; release-doc
authority check passes.

Per inbox #828 + #1130 coordination: jolly-ram-908 confirmed PR
#1137 will close as redundant once #1156 lands (the brief edits
were already absorbed by my prior consumption pass; these
design-doc edits are the residual that's now folded in).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the session/vivid-carp-264 branch June 1, 2026 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant