Repository navigation
Census the live-tree stamp join; update one failure-mode row - #10811
Conversation
|
Responding to review 62223 (claude/opus REQUEST_CHANGES on Roster as parallel authority. Verified: Substring scan as deleted classifier. Verified: Ignored census never refuses. Verified on the walk that only identity-joins Hand-Rust / v1 PURPOSE. The seed classifier is gone. What remains is test-only evidence for the failure-mode row ( Head: — sent from clever-moth-266 |
…edLiveTree is gone. compile_dag_diagnostic_census walks the checkout; SubstrateInputsOnly was a dodge so the floor would fold them. They already match required_gate_prefixes, so the honest arm executes without a fourth fabricated stamp. Co-authored-by: Cursor <cursoragent@cursor.com>
…t DeclinedLiveTree is gone." This reverts commit 891a884.
… and derive the disagreement set. The stamp and the body are peers with no relating arm: parse_entry_live_tree_disposition never looks at the call. Do not restamp. Identity-join the named specimens through an unquoted-call census at entry grain. Co-authored-by: Cursor <cursoragent@cursor.com>
The body already walks the checkout; SubstrateInputsOnly was the lie. Same finding on the two gated probes left behind last round, plus the #10713 fabric specimen. Census and the fourth-face row stay; this does not retire the class. Co-authored-by: Cursor <cursoragent@cursor.com>
…count oracle. The withheld restamp is a batch of hand stamps, not a forbidden honest correction; the 52 unmatched ReadsLiveTree rows are this detector's blind spots, not a disagreement set; skip eligibility is not a named production drop. Co-authored-by: Cursor <cursoragent@cursor.com>
…nk roster. Adding the marker is cheaper in authoring and is not the next rung: the conjunction still loses the remaining in-memory census specimen, and effect_reach's own ceiling row forbids patching the substring roster. Skip harm is a skip-eligible lie with no measured miss on record. Co-authored-by: Cursor <cursoragent@cursor.com>
…seed join. Production skip still uses stamps plus effect_reach. Review 62223 was right that a fourth roster in cli_run would be a parallel authority; the substring scan stays fail-open evidence for named identity-joins, not a wall and not a BuiltinSignature fork. Co-authored-by: Cursor <cursoragent@cursor.com>
…etector is textual. The census inhabits the same seed reader as parse_entry_live_tree_disposition because entries may not resolve; callees_from_node needs a Node. The roster is no longer a pasted name list. Falsifier.yml is named as the deleted measuring cadence, not as a drop that happened. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
96a5f43 to
5962a7b
Compare
…hown a skip-miss. The previous sentence still admitted a reading that falsifier.yml itself dropped one of these identities. Co-authored-by: Cursor <cursoragent@cursor.com>
…rities. The row already carries the falsifier wording; this is the derived projection of that authority plus main's new rows, not a hand splice. Co-authored-by: Cursor <cursoragent@cursor.com>
Unenumerated hand src/v1 growth is a stop-line; the annotation beside the helpers is not that row. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 62244 asked for a modeled Landed |
Production skip never consulted it; a pub(crate) surface with only test callers was a dangling seed declaration. The mechanism test is named as lib-test diligence under rust_unit_tests_off_the_merge_path, not merge-path evidence. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 62259 (on 1a2c167):
|
…es it via super. A pub(crate) widening had no extra caller and was unenumerated seed-surface growth. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 62279: held. |
clippy: :single_element_loop failed required-witnesses-build on the one remaining named specimen. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep the fifth-face authority and regenerate the failure-mode projection from the merged authorities so main's new rows are not dropped. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep both seed-growth justifications. Drop the committed failure-mode markdown: main now derives membership from the row directory and generates the projection on demand. Co-authored-by: Cursor <cursoragent@cursor.com>
…tor's declared input (#10871) * The third state of `0 -> 1`: a derived module's binding to its generator's declared input The wave-admission wall has refused every change that ADDS a failure-mode row file since gunbc#10822, and admitted every change that edits one. Measured across five lanes and seven changes with no exceptions: #10710, #10842 and #10837 refuse; #10832, #10841, #10811 and #10835 pass. #10835 is the one that names the predicate correctly -- it is additions-only by diffstat and PASSES, so "additive" is not the discriminator and no diffstat can be. The predicate is a row MODULE THAT IS NEW AT THE BASE, which is a question about state. WHY IT REFUSED. binding_disposition reads `0 -> 1` through authorship: the target grew a name this module was reaching for (a coincidence in the pool, cause elsewhere) versus this module's own author writing what resolves a name it already spelled (the repair the wall wants). THAT DISCRIMINATOR PRESUMES A MODULE THAT HAS AN AUTHOR. Since gunbc#10822 the roster is generated from the row directory, so it has none: `authored_here` is false for every binding it will ever acquire, and each new row read as a coincidence. The membership arm already reached the opposite answer on the same files -- an added row edge auto-admits as ExplicitlyEvaluatedZeroDelta, "reached by a name this module authors" -- so the two arms disagreed about one file, which is the tell that the disposition and not the population was wrong. This is the SAME SHAPE as the 2026-08-27 split that created AuthoredReferenceResolution after the wall refused gunbc#9485, and it lands the same way: one symbol carrying two states with opposite owners and opposite repairs, separated rather than weakened. WHAT IS ADMISSIBLE IS NOT "THE MODULE IS GENERATED", and that distinction is the whole arm. Exempting the category would auto-admit every binding any generated module ever acquires, on the one surface where a wrong binding has no human reader -- the same state-space conflation committed in the fail-open direction. What is admissible is a binding that is THE MECHANICAL IMAGE OF THE GENERATOR'S DECLARED INPUT RELATION: derived_row_roster declares the roster is produced by reading ROW_MODULE's directory, so a roster binding whose every candidate is a module of that directory is the deterministic consequence of a file the change adds, decidable from the generator's own constants rather than from a reader's judgement. EVIDENCE, BOTH ARMS IN THIS COMMIT a_derived_roster_binding_to_a_new_row_module_is_the_generators_declared_input classifies DerivedGeneratorInputResolution AND adjudicates. Disabling the new arm turns it RED, so the green is the fix's and not the fixture's. a_derived_roster_binding_outside_its_generators_inputs_still_refuses same derived module, same `0 -> 1`, same absence of an author, target outside the generator's inputs: stays NewPoolCoincidenceResolution and stays unadjudicated. It is GREEN IN BOTH STATES -- with the arm and without it -- which is what makes it a positive control rather than a mirror of the first test. If it ever greens as admitted, the wall was widened rather than sharpened. Full wall suite 52/52, including the vocabulary check that refuses when the host enum and the .dag authority disagree about the coproduct. THE FIXTURE ITSELF CARRIES A FINDING. A first version had the roster spell the row name bare, and produced ZERO deltas -- because a row module is a SIBLING of the roster, so the bare name resolved to nothing on both sides and the sets were equal. Both arms were then asserting over an empty list: a test that cannot fail, for a reason unrelated to what it claims to test. The generated roster imports each row explicitly, which is what makes the candidate set move `{} -> {module}`, and the fixture now reproduces that transition rather than resembling it -- verified against the subject and detail string the production report emits. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Enumerate the new declaration, and state the partition where the partition is stated review 62773, both findings verified against the tree and both real. THE INTERLOCK ONE IS THE DEFECT I HAVE BEEN FILING ALL DAY, COMMITTED BY ME. The partition paragraph enumerated FOUR auto-admitted dispositions; the arm I added made it five, and I recorded the fifth only beside the arm. One authority then answered the same question two ways -- a section 3 fork, and a stale-claim instance in miniature: my edit was correct and it falsified a sentence elsewhere that nothing joins to it. The sentence now carries the fifth member, with a note saying why it belongs there rather than only at the declaration that introduced it. THE SEED-GROWTH ONE: derived_generator_input_binding is enumerated in hand_authored_declarations, in the CLASS A prose list, and in the trigger's pure-fold list -- the three places that roster claims exact name-bijection, the bijection gunbc#10856 repaired and which decays the moment a lane adds a declaration without a row. Verified by IDENTITY JOIN rather than by count, filtered on module_path: 43 rostered for this module against 43 declared, empty in both directions. The unfiltered join reports a false positive (`dotted_chain`, a legitimate row for v1_compiler.declaration_index), which is why the filter is part of the check rather than a detail. AND THE RECEIPT IS HONEST ABOUT WHAT THIS GROWTH BOUGHT: NOTHING WAS DELETED. No scaffold removed, no fork consolidated; the count goes 42 to 43. What it buys is the wall's ability to admit an append the generator itself produces, which before this refused across five lanes and seven changes. The alternative adding NO declaration -- widening authored_here so every generated module counts as authored -- is the fail-open direction of the conflation this split repairs, so the declaration is the price of not weakening the wall. CLASS A, dissolving with its neighbours unchanged. Wall suite 52/52 after both edits. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Re-home the doc block: the set-disposition paragraphs describe binding_disposition review 62782, verified. Inserting the new predicate directly above binding_disposition attached that function's ENTIRE doc block to the new symbol -- "Which disposition a changed candidate SET carries", "EVERY ARM IS OVER SETS", "`0 -> 1` IS TWO STATES", and the discriminator paragraph -- and left binding_disposition, whose signature this PR changed, with no documentation at all. The block also carried two summary lines for one item. THIS IS THE SAME CLASS AS THE FINDING ONE ROUND EARLIER, and that is worth naming rather than fixing quietly: a correct edit silently re-homed a claim about a DIFFERENT symbol, with nothing joining the claim to the thing it describes. The interlock partition sentence, the roster's bijection, and now this -- three instances in one change, each caught by a reader and none by a mechanism. Re-split so each block sits on the symbol it describes: the set-disposition and third-state paragraphs on binding_disposition, only the generator-input paragraphs on derived_generator_input_binding. AND ONE THE REVIEW DID NOT RAISE, WHICH THE RE-SPLIT EXPOSED. That paragraph said "the discriminator BELOW" -- a positional reference. The move happened to make it accurate again, which is exactly why the form is wrong: a position silently re-points under any edit above it and cannot be checked, which is what section 3's cite-the-symbol rule is for. It now names `authored_here`. Wall suite 52/52. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Remove a fabricated default from an auto-admission path; the generator owns its module name review 62792 (APPROVE, non-blocking) and it is worth fixing rather than deferring. The wall recovered the roster's module name with `ROSTER_BASENAME.strip_suffix(".dag").unwrap_or("roster")` -- a GUESS substituted when the suffix is absent. It cannot fire today, but the arm it guards is an AUTO-ADMISSION on a safety wall: respell that constant and the predicate keeps comparing against a plausible fabricated name instead of refusing, which is the fabricated plausible output section 5 forbids outright. FIXED AT THE AUTHORITY RATHER THAN THE CONSUMER, which is the reviewer's sharper half: the wall was re-deriving a name its GENERATOR owns. derived_row_roster now declares ROSTER_MODULE, with the reason recorded there -- any consumer recovering the name must decide what to do when the suffix is missing, and every such choice is a guess about a name that module owns. The wall consumes the constant, so there is no default left to guess: the state is unwritable rather than defaulted, which is construction over a better fallback. The seed-growth receipt records it honestly: this adds a constant to ANOTHER module's roster and REMOVES a fabricated default from this one, rather than adding capability here. Wall suite 52/52, clippy --all-targets clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Enumerate ROSTER_MODULE in the generator's own roster, with the removal receipt A consequence of the previous commit, caught before CI: derived_row_roster carries its OWN seed-growth roster, so declaring ROSTER_MODULE there put THAT module's name-bijection out by one -- the same decay review 62773 flagged on the wall's roster, one module over. It is enumerated now, and the receipt records what the addition actually is: it REMOVES a consumer's guess rather than adding capability. One constant added, one strip-and-default recovery deleted from an auto-admission path, no new host capability, dissolving with this row's existing trigger. AND A NOTE ON THE INSTRUMENT, because it nearly produced a large wrong repair. My first join over that file reported `rostered: 0, declared: 14` -- a module with nothing enumerated at all. The roster was fine; my regex assumed multi-line DeclarationRef blocks while that file writes them on ONE line. Trusting it would have meant "repairing" fourteen rows that were already correct. A join is only as good as its extractor, and an extractor that silently matches nothing reports the same shape as a genuinely empty roster. Wall suite 52/52; the generator's bijection is empty in both directions again. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * State the arm's residual risk in the tree, not in a review thread The arm trusts the generator's DECLARED inputs, and what it checks is the declaration rather than the generator's behaviour. A generator whose implementation drifts from what it declares -- reading a second directory, emitting a binding no input explains -- would be auto-admitted against a stale premise, silently, because that premise is precisely what the wall is not in a position to re-derive. Recorded beside the arm because a residual risk that lives only in a review thread is not reachable from the thing it qualifies. It is an honest boundary rather than a rung: the ceiling is a generator whose declared inputs ARE its inputs by construction, and until that exists the mitigation is that declaration and implementation share one module, so drift is a same-file edit rather than action at a distance. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF * Disclose that the arm answers for ONE generator, and name what a second would need The prose explained the arm well enough that a reader would reasonably conclude it generalizes over generators with declared inputs. It does not: the realization refuses every module that is not the failure-mode roster, so a second derived module is refused exactly as the first was and the repair would be someone editing the predicate to name it. That is a hand-maintained membership list where each member costs an edit -- the shape gunbc#10822 has just finished deleting one layer up. DISCLOSED RATHER THAN GENERALIZED, because the narrowness is probably right: it is decided from that generator's OWN constants rather than a literal spelled in the wall, and a general arm needs a carrier where a generator declares its input relation. That carrier does not exist -- gunbc.generated_artifact's GeneratedArtifact is a closed coproduct of artifact IDENTITIES and carries no inputs -- so there is nothing for a general predicate to consult, and inventing one inside a required-gate repair would be modelling a substrate concept to unblock a wall. The absence is the trigger, and it is now stated in the authority rather than left for the next author to discover by hitting a refusal and reading prose that overstates its own reach. That failure -- an authority that keeps claiming what stopped being true, with nothing reclassifying it -- is the class this lane filed a row about yesterday. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GwvzQ3SQoWWDgHkAeffMeF --------- Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Brian Searls <briansearls1@gmail.com>
Summary
subject_and_its_digest_as_independent_parameters. No derivation this lane. No batch restamp.compile_dag_diagnostic_censusis absent fromv2.std.effect_reacheffect_reach_host_sink_callee_symbols_v0, soreads_live_tree_effectivedoes not upgrade a lyingSubstrateInputsOnlyand the entry is skip-eligible on an outside-closure diff.HostEffectSinkKindalready namesGunbcCompileEntrySink; the hole is marker coverage.dataString, soConjunctionOfIndependentExistentialswould still lose (adding_the_census_marker_would_still_lose_the_conjunction_on_the_remaining_specimen).effect_reach_detection_ceilingalready forbids patching the substring roster; its trigger stayscall_reachability_live_read_classification. A roster patch would satisfy a weaker sentence while that capability stayed dead.test.claim.citation_cause_subject_disjointness_witness. Unmatched ReadsLiveTree is UNDETECTED-BY-THIS-INSTRUMENT.Seed growth (DESIGN §7)
direct_live_tree_sink_callees/builtin_name_spells_a_live_checkout_sinksit incli_run.rsnext toparse_entry_live_tree_dispositionbecause the census must read entries that may not resolve. That is the same textual seed-reader model, not a resolvedcallees_from_nodefold. Production skip does not consult them. v1 PURPOSE: evidence for the failure-mode row (gunbc.v1_maintenance_standing).Conformance (DESIGN §3b)
Substring matching conforms to that textual reader. It is not an unstated divergence from
callees_from_node. The residual transcription is the predicate (builtin_name_spells_a_live_checkout_sink); a newcompile_dag_*registry key is picked up. A builtin whose name fails the predicate is silent here; what would refuse iscall_reachability_live_read_classification.Harm
The stamp is a lie that is skip-eligible and has no measured miss on record. No named production round after falsifier.yml's deletion; that is the honest answer, not a guess.
Ladder
Found at mitigatable. Ceiling structurally impossible. Trigger unchanged:
v2.std.effect_reachcall_reachability_live_read_classification.Remote env (HostBudgetUnreadable was the env block, not a blocked observation)
CTRL_BUILD_FORWARD_ENV=GUNBC_MEMORY_BUDGET_BYTESwith the var set. Dispatch printedforwarding env: GUNBC_MEMORY_BUDGET_BYTES(not(none)). One-dispatchcargo build && ./target/release/gunbc run …. HostBudgetUnreadable did not persist. The run reached compile asdeclared-unverified(cap=682) and then refused because that witness returnsBool, notProcessExit. Invocation: https://app.buildbuddy.io/invocation/201022d9-e026-4e67-a7ce-d26c2dd18e86Observed execution
Test plan