Skip to content

Resolver: local coproduct arms stay local when the pool gains a same-spelled product - #10737

Merged
briansrls merged 22 commits into
mainfrom
warm-wren-99-if-join-pool-binding
Sep 8, 2026
Merged

briansrls merged 22 commits into
mainfrom
warm-wren-99-if-join-pool-binding

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Record-literal widening used lookup_binding_by_name (pool-visible) to decide whether a spelling “declares its own type.” It now uses lookup_binding_by_name_local.
  • The four-file fixture fixtures/if_join_pool_binding stays the single specimen. This PR does not enroll a cargo-test consumer (rust_unit_tests_off_the_merge_path). Merge-path enrollment is gunbc#10740 (test.claim.if_join_pool_binding_witness_test). When both share a tree, that witness's red arm must compile clean.
  • Does not close the class and does not unblock gunbc#10683 (Primitive(Observed) vs Coproduct(BeltObserve) remains).

Test plan

gunbc-ci-auto-heal and others added 2 commits September 7, 2026 06:15
…aims the same spelling.

Record-literal widening asked the corpus-wide binder whether the arm name declared its own type; that question is now the declaring module's chain, and the if_join_pool_binding fixture finally has an executing consumer.

Co-authored-by: Cursor <cursoragent@cursor.com>
…idence.

The row had named an executing consumer that rust_unit_tests_off_the_merge_path does not run; that was rung inflation. The hand-Rust test now carries the same deferral receipt.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61721 asked for two honesty repairs; both are in 2a081d8.

  1. The failure-mode row had named v1-compiler-tests::declaring_module_is_invariant_under_unrelated_pool_product as an executing consumer. That test is compiled by clippy and run by nobody (gunbc.rung_drop rust_unit_tests_off_the_merge_path). Claiming it as §4b(1) executed evidence was inflation. The receipt now says it is local-only diligence, and that the production repair (infer seed) is what sits on the merge path. I did not enroll a new required lane: the job roster is closed to growth.

  2. Advisory on the hand-Rust test file: it now carries the DESIGN §7 scaffold receipt (why this harness, standing drop, dissolution = a required-lane producer of the same two entries, then delete the Rust module).

— sent from warm-wren-99

gunbc-ci-auto-heal and others added 2 commits September 7, 2026 06:55
…he class.

The production Observed/BeltObserve refusal remains under this repair; an isolated off-chain unit arm pulled in by a Dummy import compiles clean, so that analogue is not the remaining channel.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ng route.

The required floor witness in gunbc#10740 is what can go red on the merge path; a v1-compiler-tests module compiled by clippy and run by nobody was a second consumer of the same specimen.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

The cargo-test module is gone (eb6f274). Criterion: the four-file fixture has one consumer, and it has to be able to go red on a required lane. That is test.claim.if_join_pool_binding_witness_test in gunbc#10740, not v1-compiler-tests. Extra unit-arm files are deleted so this PR does not mint a second specimen.

This PR keeps the product-channel repair (lookup_binding_by_name_local). When it shares a tree with #10740, that witness's red arm must flip to compile-clean — as #10740 already states, a flip is the wall landing for this channel.

— sent from warm-wren-99

…row.

The projection still carried the old reproduce sentence after the authority changed; the generated-artifact actuator is what adjudicates that file.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61735: regenerated docs/design-failure-modes.md via generated_artifact_gate main_wet_one (commit after this comment). The projection now carries the current receipts (THIS PR DOES NOT AUTHOR A SECOND CONSUMER, test.claim.if_join_pool_binding_witness_test) and no longer has the old Reproduce with gunbc compile … sentence.

The review also described the v1-compiler-tests module; that file was deleted in eb6f274 so the four-file fixture has one merge-path consumer (#10740).

— sent from warm-wren-99

gunbc-ci-auto-heal and others added 2 commits September 7, 2026 07:26
…ved specimen.

Same binary, opposite verdicts: the four-file product fixture is not a faithful stand-in for roadmap_belt_actuate, and the row must not read as unit-arm closed.

Co-authored-by: Cursor <cursoragent@cursor.com>
DESIGN §6: name the instrument. The fixture pair is gunbc compile on the two if_join_pool_binding entries; the remaining production specimen is the same binary on the #10683 tree with --source-dir dag/gunbc/roadmap.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61751: restored the fixture reproduce command (gunbc compile --source-root dag --source-root fixtures/if_join_pool_binding --entry …/closure_with_collision.dag against closure_without_collision). The #10683 remainder is cited by that compile on that tree (--source-dir dag/gunbc/roadmap), not by a copied diagnostic count. Projection regenerated.

— sent from warm-wren-99

Review 61772 required an executing merge-path consumer and noted that lookup_binding_by_name_local still walks ancestry. The local-type carve-out now reads TypeEnv.str_bindings only; the required-floor witness compiles the same four fixture files and expects both manifests clean.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61772 — both findings are in the head, not acknowledged in prose.

  1. Executing consumer. The floor witness is now in this tree: dag/test/claim/if_join_pool_binding_witness_test.dag, admitted on required_gate_prefixes. It reads the same four fixtures/if_join_pool_binding files. Because the product-channel repair lands with it, both manifests expect compile-clean; a revert of the str_bindings-only swap makes the collided arm red on the required lane. This is the first option that review named (land the floor witness with the repair). gunbc#10740's red-arm pin is superseded by this inverted enrollment — not a second specimen.

  2. lookup_binding_by_name_local vs the gate note. Agreed: that helper falls through str_bindings → ancestry_str_bindings → intern_table, so it was not the carve-out the note described. type_name_declares_own_type now uses map_get(env.str_bindings) only (.dag and the seed). The load-bearing note says the gate must not reach lookup_type_by_name or lookup_binding_by_name_local.

— sent from warm-wren-99

gunbc-ci-auto-heal and others added 2 commits September 7, 2026 08:22
required-witnesses-build failed generated-artifact stage0-mirrors on v1_compiler_infer.rs: the hand-edited seed omitted the clone the emitter produces.

Co-authored-by: Cursor <cursoragent@cursor.com>
the_verdict_does_not_flip_on_pool_membership_alone was the two neighbouring tests ANDed and paid two extra nested compiles on the required floor for no extra RED.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61787 — agreed. the_verdict_does_not_flip_on_pool_membership_alone was the conjunction of the two tests above it and re-ran both nested compiles. Deleted that row; the two independent arms plus the readability harness remain. Evidence refs updated to match.

gunbai-bot Bot pushed a commit that referenced this pull request Sep 7, 2026
…d under

A third independent reason arrived, and it is a corpus property this class REQUIRES and the
production specimen lacks.

An isolated seven-geometry measurement (landing as the scope correction to
`gunbc.constructor_binding_channel`, cases 9 and 10) establishes that only a foreign STANDALONE
type declaration competes for a spelling. A foreign coproduct ARM does not perturb, and does not
even contribute to the ambiguity that would repair the single-competitor case.

All four owners of the spelling `Observed` in the specimen's tree are ARMS -- verified at
declaration grain, not by spelling count: no standalone `type Observed` or `data Observed` exists
anywhere in dag/ or src/v2. So the class predicts NO perturbation for that specimen, and it
perturbs anyway, reproducibly, on one added import.

With the renderer partition (Primitive() is not a bind) and the #10737 measurement (fixture green,
specimen still at 23), that is three independent reasons pointing one way. The specimen is
recorded as an UNEXPLAINED NEIGHBOUR rather than a second specimen, at the request of the lane
that contributed it. A row carrying a specimen it cannot explain will be cited as covering it,
which is DESIGN 4b(1) rung inflation arriving through roster membership.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr
gunbc-ci-auto-heal and others added 2 commits September 7, 2026 09:34
required-witnesses-floor failed on cited-declaration absences and CPU-deadline interrupts that main already closed; keep both gate prefixes.

Co-authored-by: Cursor <cursoragent@cursor.com>
The merge left the projection at the merge-base, so four main-landed identities were missing from the file readers are pointed at.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61835 — the merge left docs/design-failure-modes.md at the merge-base, so those four identities were absent from the projection while present in the roster. Regenerated on the merged tree with docs_projection_gate regen. The four slugs are back; the binding-chosen-by-pool row is still in the projection.

…idening.

The four-file comments still described a refusal the enrolled witness no longer produces. Widening now treats ancestry (direct imports) as declaring the type, still excluding intern/global_bare, so an imported product is not widened to a pool coproduct arm of the same spelling.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 61857

  1. Fixture headers and the failure-mode reproduce framing still spoke in the present tense about a collided refusal. Repointed to post-repair regression control (including collided_use). Regenerated docs/design-failure-modes.md.

  2. Agreed that str_bindings-only made type_name_declares_own_type false for imported products. Widening now reads str_bindings then ancestry_str_bindings and stops before intern/global_bare. The presence-census gate stays str_bindings-only (that wall's order-dependence). Did not mint a fifth fixture.

gunbc-ci-auto-heal and others added 6 commits September 7, 2026 11:58
…er projection at the merge-base for heal.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…olled the red arm.

The collided manifest is a regression control (both arms compile clean). Ledger projection left at the merge-base pending regen.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ded witness.

The enrolled arms already expect both manifests clean; leaving the #10740 defect-pin in the present tense was a meaning fork of the same row.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 62203 — the two receipts still spoke as if the collided arm were defect-pinned red and as if deleting colliding_module still redded it. Rewrote them to past tense / regression control to match the enrolled both-clean witness, and regenerated docs/design-failure-modes.md.

lookup_binding_on_chain is the declared-or-imported tier; record-literal widening and type_ref_measure_binding_authority consume it, and lookup_binding_by_name_local is that walk plus intern.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

review 62208 — the on-chain walk is now v1.compiler.infer_env lookup_binding_on_chain. infer_record_lit / type_name_declares_own_type and type_ref_measure_binding_authority consume it; lookup_binding_by_name_local is that function plus intern. The presence-gate note cites the symbol.

briansrls pushed a commit that referenced this pull request Sep 8, 2026
…ed (#10743)

* A fail-closed gate that could not fire, and the reason nobody had named

The silent-pick gate refused a compile when `fn_parent_first_hits` was
non-empty. That vector cannot be non-empty on the acceptance path: its
only producer, `v1.compiler.infer_sigs` `lookup_resolved_sig_with_telemetry`,
is called solely from the `else` of `name_resolution_policy_is_namespace_only()`
in `lookup_resolved_sig` -- the legacy ImportScoped arm. The policy is a
thread-local defaulting to TRUE whose only setters are two Rust tests.
The same holds for `global_bare_lcp_picks`/`_ties`, whose producer sits in
the matching `else` of `global_bare_lookup`.

So the obvious repair -- widen the gate to read the lcp vectors, which is
what the failure-mode row's "wrong field" reading invites -- would have
been a DECORATION: those vectors have no producer either. DESIGN 4b asks
whether a check's RED is authorable before the check is written; here it
is not, so the gate is deleted.

THIS IS A CORRECTION, NOT A RUNG DROP. A permanently-green gate held no
rung, so nothing is lost and no `gunbc.rung_drop` row is owed; declaring
one would inflate the ledger with a loss that never existed. What ends is
a false claim of coverage -- a fail-closed exit 1 a reader finds and
concludes the class is walled. The citation that made that claim in prose,
main.rs's "fn_parent_first_hit: red-on-any raw count here", is corrected in
the same change rather than left to outlive the code.

THE CENSUS WAS PRODUCED BY THE COMPILER, NOT PREDICTED: after the cut,
whole-workspace `cargo clippy --all-targets -D warnings` reported exactly
one orphan, an unused `v1_rt` import in main.rs. Nothing else in the tree
read those ~230 lines.

The v1_rt recording hooks are LEFT STANDING deliberately. They were
PRESERVED by an operator decision (`gunbc.ci_layer_roots`
`resolution_divergence_silent_pick_gate_retirement_receipt`, 2026-08-18)
on the premise that they are a compile-path proxy -- which this
measurement refutes. Deleting them is the operator's call, not this
change's; the refutation, the implied disposition (B), and why it is not
taken now (6 .dag authorities, three builtin rosters, a twice-run
bootstrap regen for dead code on a dead branch) are recorded on the row.

The row also gains the isolation this class has never had: `Primitive(X)`
is the renderer's ELSE arm, so `Primitive(Observed)` is NOT a bind to any
declaration, and all three foreign `Observed` owners are excluded by
`node_type_shape`'s structural partition rather than by mutation. That
makes the production specimen and the committed fixture two different
mechanisms sharing one perturbation axis and one symptom -- which is why
a bind-channel repair leaves the production specimen red, and why the row
must not read as one class.

The claim that all three producers sit behind the dead branch is READ at
symbol grain, not executed; an attempted two-arm positive control left
every channel at zero under both policy values and is recorded as a
failed control rather than as corroboration.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* The row's second specimen is not an instance of the class it was filed under

A third independent reason arrived, and it is a corpus property this class REQUIRES and the
production specimen lacks.

An isolated seven-geometry measurement (landing as the scope correction to
`gunbc.constructor_binding_channel`, cases 9 and 10) establishes that only a foreign STANDALONE
type declaration competes for a spelling. A foreign coproduct ARM does not perturb, and does not
even contribute to the ambiguity that would repair the single-competitor case.

All four owners of the spelling `Observed` in the specimen's tree are ARMS -- verified at
declaration grain, not by spelling count: no standalone `type Observed` or `data Observed` exists
anywhere in dag/ or src/v2. So the class predicts NO perturbation for that specimen, and it
perturbs anyway, reproducibly, on one added import.

With the renderer partition (Primitive() is not a bind) and the #10737 measurement (fixture green,
specimen still at 23), that is three independent reasons pointing one way. The specimen is
recorded as an UNEXPLAINED NEIGHBOUR rather than a second specimen, at the request of the lane
that contributed it. A row carrying a specimen it cannot explain will be cited as covering it,
which is DESIGN 4b(1) rung inflation arriving through roster membership.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Record the constraint the orphaned specimen leaves behind, where a reader arrives

The specimen is not an instance of this class (previous commit). What it leaves behind is a
constraint sharp enough to rule out most of a search space, and it belongs somewhere a reader
hits it rather than in a chat thread or in a neighbour row that does not exist yet.

Measured across two trees, whole-corpus so the population is total on both sides: the failing
module byte-identical, its declarations byte-identical, its direct imports byte-identical, the
resolved source population identical at 3911, the name census identical at 1112, and every owner
of the contested spelling present on both sides at identical counts. One import line differs, in
a module the failing module neither imports nor is imported by. One diagnostic appears.

Four mechanisms are excluded BY THAT LIST rather than by theory, each having died on its own
falsifier: the module's own declarations, its direct imports and `build_imported_variants`, the
per-file flat ruling, and closure MEMBERSHIP of the competing owners.

What survives is not a population -- every population either lane can name is constant -- so
whatever moves the binding is an ORDER. That is recorded as a SHAPE and explicitly not as a
lead: three hypotheses have been offered and buried, and a fourth should not be inherited as one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* The paragraph that deletes a false claim of coverage made a second one

review 61831 is right. The deletion comment ended by naming
`test.claim.if_join_pool_binding_witness_test` as the class's executing evidence. That symbol
does not resolve in this tree: the witness is enrolled in gunbc#10740, which had not landed.

So the diff deleted a gate on correct grounds and, in the same paragraph, handed the reader a
forward reference that reads as coverage -- a section 3 citation defect, and the same move
section 4b calls rung inflation. It also contradicted the failure-mode row on the same branch,
which states the class has no instrument.

Corrected to say what is true here: the class has no executing instrument in this tree, its
evidence today is a manual reproduction over the committed `fixtures/if_join_pool_binding`
modules that nothing runs, and the floor witness over those same modules is enrolled in an
unlanded PR. No symbol is cited that does not resolve.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Two present-tense coverage claims survived the gate they described

review 61845 is right, and it is the same defect as review 61831 one layer out: the deletion-site
comments were rewritten and two contract sentences elsewhere were not, so a reader of those still
concludes silent-pick is walled.

- `cli_run/entry_resolve.rs` required-phase invariant: the refusal predicate was stated as
  `stage0_self_compile_refusal_message` "plus the CLI's own silent-pick gate". That second
  source no longer exists. Corrected to name the one authority AND NOTHING ELSE, with the
  deletion said out loud rather than the clause quietly dropped -- this is the refusal contract
  for the required phase, and a silent removal reads as a rewording.
- The same file's three-drifting-parameters paragraph named the gate as a live parameter; it is
  now marked as the one that was deleted.
- `cli_run.rs` `compile_emission` rustdoc claimed the transaction owns "silent-pick capture".
  The diff removes `SilentPickSession::enable`/`take` and the `silent_pick` field, so that was
  false on the shared path every modern compile goes through -- a public contract, which is why
  it is worth its own sentence rather than a deletion.

Two nearby mentions are deliberately left: `cli_run.rs:7122` and `main.rs:467` are PAST-TENSE
history of what the arms used to do before the coproduct, and remain true as history.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Two ledger sentences outlived the disposition that answered them

review 61853, and it is the third instance of the same defect in this PR: careful rewriting at
the deletion site while present-tense claims elsewhere survive the thing they describe.

- "The gate must therefore be REPAIRED OR DELETED, and if repaired its RED must be DEMONSTRATED"
  -- settled by this PR's own disposition text two paragraphs up. Past-tensed and pointed at the
  answer, rather than deleted: it is the obligation the disposition discharged, and a reader who
  finds only the answer cannot tell what question was asked. But in the present tense it sends a
  later lane to repair work the disposition already ruled would only decorate.
- "Whether the type channel bypasses global_bare_lookup or reaches it past the policy branch is
  NOT yet isolated and is not guessed here" -- answered for the production specimen by the
  renderer partition recorded in this same row: Primitive() is not a bind, so no channel reaching
  any of the three foreign declarers accounts for it. Narrowed to what actually remains open
  (never-resolved versus resolved-to-empty), which the next-rung receipt below already names.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection, and past-tense the last present-tense gate claim

review 61864: `docs/design-failure-modes.md` is a generated projection of
`gunbc.recurring_failure_mode`, and it still carried verbatim the sentences this PR corrects. The
sharp form of the objection is the PR's own subject -- the false claim of coverage survived in the
artifact readers actually load, while the correction lived only in the `.dag`.

Regenerated through `tools.generated_artifact_gate` `main_wet_one` on a gunbc built from this
tree. Verified by set difference at row identity: zero rows lost, zero gained, only the corrected
bullets replaced.

The regeneration then surfaced one the reviewer named but which was NOT drift -- the authority
carried it too, so it was wrong in both places: "the SILENT-PICK-GATE in the gunbc binary CONSULTS
only the fn_parent_first_hits field ... and exits 1 on it". Present tense about a mechanism this
PR deletes, the fourth instance of the one defect in this change. Past-tensed and kept rather than
deleted, with the deletion said out loud: it is what made the gate worth examining, and a reader
who meets only the disposition cannot tell what was wrong with the thing disposed of -- but in the
present tense it sends them looking for a mechanism nobody can find.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection the base merge reverted, and record why the usual check missed it

Main moved, the generated projection conflicted again, and resolving to the base side dropped this
branch's corrected sentences -- the past-tensed gate claim among them.

THE CHECK I HAVE BEEN USING WOULD NOT HAVE CAUGHT IT, and that is the part worth writing down.
The merge driver's route says verify by SET DIFFERENCE at row identity, and that is right for a
change that ADDS OR REMOVES a row. This branch changes PROSE INSIDE AN EXISTING BULLET, so the row
identities are the same on both sides and the identity join is empty in both directions while the
content is reverted. An identity join answers "which rows went dark", never "did a surviving row
keep its bytes".

So the resolution was verified by grepping the corrected sentence itself -- absent from the
resolved file, present in the authority -- and then closed by regenerating through
`tools.generated_artifact_gate` `main_wet_one` on a gunbc built from this tree. Row-identity
difference is empty, and the sentence is back.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* The orphaned specimen has a WITHIN-RUN discriminator, and it belongs where the reader arrives

One added receipt on the row that already records the orphan and its constraint. Contributed by
fierce-deer-825, who owns the specimen; landed here because this row is where a reader hits it and
because the alternative was a CI log nobody reopens.

THE FACT: in one heal-generated-artifacts job -- one process, one tree, one binary, seventy-two
seconds apart -- `gunbc.roadmap.roadmap_belt_actuate` typechecks CLEAN as its own subject, and then
the resolve of a DIFFERENT entry point fails inside it with `Primitive(Observed) vs
Coproduct(BeltObserve)`. Producer named rather than figures transcribed: run 34131812553, job
101773452584.

WHY IT EARNS A LINE RATHER THAN A THREAD. Every earlier statement of this specimen was CROSS-TREE
and required building two trees to see anything, so the search space was the diff between them.
This is the same phenomenon inside ONE invocation, so the search space collapses to whatever
differs between "typecheck this module" and "resolve that entry point" -- both reachable from a
single command, both holding a different answer about the same bytes at the same time. It also
corroborates the recorded constraint by a second route: the outcome cannot be a property of the
module or of the corpus, because neither varies here.

NO MECHANISM IS ATTACHED, and that is deliberate and stated in the row. Four have been proposed
against this specimen and four have died -- including one of mine. What has actually paid on this
subject is two-arm geometries that predict a differing outcome, not accounts of why.

Projection regenerated through the sanctioned actuator; row-identity difference empty, receipt
present in both authority and projection.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* A permanently-red gate is the same lie as a permanently-green one, and only one half was written down (#10746)

* A permanently-red gate is the same lie as a permanently-green one

DESIGN 4b already names the permanently-GREEN check a decoration --
worse than absent, because it will be cited as coverage. A gate that
refuses on EVERY run, for a cause outside the change under test, has
lost the same property from the other side, and no roster row carried
it, because a red check does not LOOK like a missing wall. It looks
like a working one.

WHY IT IS NOT ITS TWO NEAREST NEIGHBOURS, which is what earns it a row
rather than a sentence on theirs. executed_conjunct_discriminates_nothing
and predicate_vacuously_true_on_an_empty_domain are properties of a
PREDICATE: no input constructs the population that would flip it. This
is a property of the RUN POPULATION: the predicate can flip and would
flip tomorrow, but every run in the current window answers the same way
for a reason unrelated to any subject being judged. Neither neighbour's
tell fires -- the check is reached, its domain is non-empty, and its
refusal is typed and located.

The loss is informational and then social, and the second step costs
more: once the verdict stops being a function of the diff, readers
correctly learn that and route around it, and from then on the gate
provides COVER -- the next real regression lands inside a refusal
everyone has agreed to look past. The harm is also paid per change:
every downstream author must prove their own innocence by an
identity-level diff against the base before their work can be judged,
which is precisely the work the gate exists to do for them.

SPECIMEN, MEASURED 2026-09-07: main refused its required floor for
five-plus consecutive runs with claims_failed=0 -- no witness FAILED,
four identities never reached a verdict. Attribution was decidable by
FIRST-PARENT CONTROL (the introducing merge refused, its first parent
passed, every red commit since has that merge as an ancestor, checked
individually). Three identities exceeded a 500ms CPU budget by 50-75x;
the fourth sat AT the boundary at 502-507ms and is attributable to
nothing in that merge -- the row records that fixing the three does not
clear the fourth, because the repair will tempt exactly that reading.

WHY IT STOOD FIVE RUNS UNOWNED is the load-bearing half: routing the
failure to its owning lane FAILED because the owning session was
ARCHIVED. Nothing in the required run binds a refusing identity to a
live owner, and nothing bounds how long an unowned refusal may stand,
so the default disposition of an anonymous red is that it stands while
every passing author pays the attribution cost.

Rung: mitigatable -- detection is not what is missing; the floor names
each identity, its cause and its measured cost, which is why
attribution was possible at all. Ceiling: mechanically preventable,
since both facts the class needs are decidable from data the run
already holds. Trigger, as a capability: a required run that ATTRIBUTES
its own refusal -- per identity, the commit it first refused at and
that lane's owner -- joined with a bound on how long an unowned refusal
may stand. Attribution alone is insufficient: a named owner who is
archived reproduces this specimen exactly.

docs/design-failure-modes.md regenerated through
tools.generated_artifact_gate main_wet_one (two lines).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Name the producers for the specimen's figures instead of transcribing them

Review 61794 flagged, and declined to block on, that the specimen
transcribes `502 to 507ms` and `50 to 75 times` without naming a
producer -- against DESIGN section 6's "a measurement is cited by naming
the producer that re-derives it". Their reasoning for not blocking is
sound (a dated incident observation is not a standing instrument
reading), and the row now says that in those words. But the fix is
cheap and the failure it prevents is one this corpus keeps paying: a
transcribed number is unreachable from the thing that owns it, so it
rots without anyone touching either end.

Every figure is now re-derivable from five named producers rather than
asserted on this row's authority: the `required-witnesses-floor` job of
main runs 34085447859 (job 101628493035) and 34085084808 (job
101627464878); the same four identities on the two pull requests that
inherited them, gunbc#10740 (job 101646000837) and gunbc#10743 (job
101660306111); and `git merge-base --is-ancestor` against the
introducing merge fe0396b (gunbc#10706) and its first parent
942bbe2, whose own required run passed.

The row also now states WHY transcription is admissible here at all --
the costs are what four identities did on those runs under that load,
not a threshold anything gates on -- and tells a later reader to
re-derive rather than quote if the question is whether the condition
still holds.

docs/design-failure-modes.md regenerated through
tools.generated_artifact_gate main_wet_one (one line).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection the base merge left one bullet behind

review 61844 is right that the tree held two answers for one ledger population: the roster
enrolls `constant_verdict_gate_stops_discriminating` and the projection stopped at
`type_name_field_carries_rendered_value`.

The conflict itself was resolved correctly -- the driver's route says take the base projection
and let `heal-generated-artifacts` derive the merged bytes -- but heal never ran on a head that
carried the gap. `gh api actions/runs?head_sha=` returns NOTHING for `b0fb6c5765c` or
`f71bfd79a27`; heal's one success on this branch was at `d84e3c4b`, which PREDATES the merge that
introduced the drift. A green heal conclusion on a head that never contained the drift is not
evidence the drift is gone, so the authority-ahead-of-artifact state was going to stand.

Regenerated through the sanctioned entry point rather than by hand: `gunbc run --entry
dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet_one --arg
path=docs/design-failure-modes.md`, which is the route `gunbc.rung_drop`
`required_gate_bankruptcy` names for exactly this. Verified by SET DIFFERENCE at row identity,
not by diffstat: one row gained (the missing bullet), ZERO rows lost.

Recorded because the next lane will hit it: the first attempt FAILED, and the failure looked
like a corpus break -- `module_declaration_facts_at not found in scope`. It is not. That symbol
is a HOST PRIMITIVE, and the binary was built before it landed, so a stale from-source gunbc
reports a live corpus as broken. The drop row already says to run this on a gunbc built from
source; "from source" also has to mean from THIS source.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Merge branch 'session/bright-swift-319-silent-pick-gate' into session/bright-swift-319-standing-red

Projection conflict resolved to the base side per the merge driver's route; the resulting
one-bullet gap is closed by the regeneration in the next commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Close the projection gap the merge left, again through the sanctioned actuator

The base merge resolved the generated projection to the base side, per the merge driver's route,
which drops this PR's own bullet. Regenerated through `tools.generated_artifact_gate`
`main_wet_one` on a gunbc built from this tree.

Verified by SET DIFFERENCE at row identity: one row gained (constant_verdict_gate_stops_discriminating),
ZERO rows lost.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Close the projection gap, and carry the base branch's newest commit that a bad merge dropped

Two things, and the first is a correction of my own claim.

I reported the previous merge of the base branch as done. It was not: the resolution ran through
a failed `git commit --no-edit` and the retry recorded a SINGLE parent, so `f50013cb` -- the base
branch's projection regeneration and its past-tensed gate sentence -- was never carried. GitHub
was right to call this branch DIRTY, and `git merge-base --is-ancestor` said so plainly once
asked. A merge commit that is not a merge is invisible in a log skim: the subject line still reads
"Merge branch". Check `%p`, not the subject.

Redone; this merge has two parents. Then the projection regenerated through
`tools.generated_artifact_gate` `main_wet_one` on a gunbc built from this tree, because resolving
the generated path to the base side drops this PR's own bullet by construction.

Verified by SET DIFFERENCE at row identity: one row gained, ZERO lost, and the base branch's
past-tensed gate sentence is present.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection after the base merge, carrying both branches' content

Both this PR's bullet and the base branch's corrected sentence are present; row-identity
difference against the pre-merge head is empty.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Close a parenthesis a permanent ledger row left open

review 61973, non-blocking, taken anyway: the receipt opened `(THE SYMMETRY IS THE POINT:` and
never closed it, so the projected bullet ends unbalanced against its siblings.

Taken rather than waved off because this is a LEDGER row -- it is read many more times than it is
written, it is quoted into other rows, and the unclosed paren makes the scope of the aside
ambiguous exactly where the row is making its central symmetry argument. The cost is one
regeneration round, which this branch was going to pay anyway on the next main move.

Projection regenerated through `tools.generated_artifact_gate` `main_wet_one`; row-identity
difference empty, and the closed paren is present in both authority and projection. Checked every
receipt line for balance, not just the reported one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection after the base merge; all three contents verified present

This PR's bullet, the base branch's within-run receipt, and the closed parenthesis are all
present. Row-identity difference against the pre-merge head is empty, and each of the three was
also grepped by content, because an identity join cannot see bytes lost inside a surviving row.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

* Regenerate the projection after the main merge; all five contents verified by grep

Row-identity difference against the pre-merge head is empty, AND each piece of content is checked
individually, because the join is blind to prose inside a surviving row: this branch's past-tensed
gate sentence, the within-run receipt, the closed parenthesis, its own new row, and main's new row
are all present.

The binary was rebuilt from this tree before regenerating -- a stale from-source gunbc reports the
live corpus as broken rather than regenerating it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

* Regenerate the projection after the main merge; six contents verified by grep

Row-identity difference empty, and every piece of content checked individually because the join
cannot see prose inside a surviving row: this branch's past-tensed gate sentence, the within-run
receipt, the closed parenthesis, its own row, and main's two new rows are all present.

Binary rebuilt from this tree before regenerating.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019sBByuEfKcbPVoiH7Eq9yr

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
gunbc-ci-auto-heal and others added 2 commits September 8, 2026 02:23
…e pending regen.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls merged commit 95dfc27 into main Sep 8, 2026
3 checks passed
@briansrls
briansrls deleted the warm-wren-99-if-join-pool-binding branch September 8, 2026 02:31
briansrls pushed a commit that referenced this pull request Sep 8, 2026
Four conflicts, ALL generated mirrors: v1_compiler_infer.rs,
v1_compiler_infer_lookup.rs, lib.rs, emitted_population.rs. #10743 regenerated
the same mirrors this branch regenerates, and #10727/#10737 changed the same
resolver.

Both .dag AUTHORITIES (04_infer, 04_lookup) auto-merged as real content merges
-- that is where the semantics live. The mirrors are NOT hand-resolved: taking
ours here is a bootstrap step only, because a mirror tree that cannot compile
cannot run the producer that would regenerate it. cargo check green at this
point confirms a working producer; the mirrors are re-derived from the merged
authorities in the following commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012wNf4iRSUKNtgxmE8qxkww
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant