Repository navigation
Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate - #10882
Conversation
…pected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…nd-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ntract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…aration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…osition and decode canonical operator wires
The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:
Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.
Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.
The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.
Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
… membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ess for the emitted add crate
First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.
- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
stdout pinned to the family's expected octet, sharing the kernel family's
one-build cache key exactly as the classical_not arm shares its family's
key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
control — a no-eval verdict has no oracle leg to break, so the expectation
side breaks (an octet the run never produces must not match); program-side
discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
by construction (the verdict entry is file-grain enrolled in
falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
{classical_not, add}; split 2/13.
Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…rounding-frontier-3100 # Conflicts: # dag/gunbc/guarantee_stall/roster.dag # src/v2/compiler/self_host/candidate_generation_stage_verdicts.dag # src/v2/test/claim/execution/self_host_candidate_generation_stage_verdicts_test.dag # src/v2/workflow/floor_expected_red.dag
…fication The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass.
Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4).
…ct witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8.
…ling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors.
… -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated).
…rsions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2).
…nsus at 6676531 The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b, 72 -> 28) and the twelve-error source cluster (6676531, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds.
Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS).
…s at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.
The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs.
… closure's cargo census is empty Measured at 5ee4892 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds.
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md
…e rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors).
The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way.
A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback.
The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means.
The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes.
…d realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain.
The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.
The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).
e8ed171 added body_producer_forward_row_test_fn_decl (the native lane's driver evaluates test fn declarations, so they must lower through the forward producer) but did not move this receipt, which still pinned the closed row table at main's six. The table is the controlled subject universe and the sibling forward/fold surface-identity parity witness covers membership at identity grain; this row pins the count. Verified by execution: wave1_gate1_a1_forward_behavior_row_count_witness_holds returns true. Co-authored-by: briansrls <briansrls@gunb.ai>
required_lanes_roster has carried three lanes since the v2-native lane enrolled, but w_RED_neither_lane_waits_on_the_other still pinned the two-lane split, so the floor red-carded the branch's own lane addition (returned Bool(false) on every required run since the roster grew). The witness now asserts the three-lane roster: each lane job carries no needs, and the aggregate's roster carries each of build/floor/v2-native exactly once. w_RED_lane_contexts_collide_with_no_other _emitted_workflow gains the same lane's clauses (no fleet-converge job id collision; pairwise distinct from build, floor, and the aggregate). Verified by execution: both witnesses return true; v1_src_dag_parse sweeps 5403 files clean. Co-authored-by: briansrls <briansrls@gunb.ai>
The stage0 mirror of v1.compiler.emit_rust (src/v1/05_emit_rust.dag) drifted twice without a regen: d716207 added rust_shared_wrap_ctor (the diverging- panic wrap refusal) and 0e25a0b changed sole-variant coproduct match emission. The parse-phase annotation refusal masked the drift by refusing the generated-artifact phase before the comparison ran; with the parse repaired the drift gate names it. 26 lines across the two sites, installed from the --required-regen candidate tree. Verified: --required-regen first_generation_equal=true over 155 files (1 declared-divergent main.rs); clippy --all-targets -D warnings and fmt green; v1_src_dag_parse sweeps 5403 files clean. Co-authored-by: briansrls <briansrls@gunb.ai>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
#10882 landed; a v2-native timeout at 180 minutes is not this PR's red.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1eb184fd1f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| fn list_snoc_item<T>(xs: FreeMonoid<T>, item: T) -> FreeMonoid<T> { | ||
| list_append(left: xs, right: Cons { head: item, tail: Empty }) | ||
| xs |> list_push(item) |
There was a problem hiding this comment.
Keep snoc working for compact strings
When xs is a modeled String realized as Value::Str—for example, the open_lex accumulator used by the delimited lexer—this pipe dispatches to the interpreter's list_push method, which explicitly returns list_push not supported on String. Consequently, interpreted v2 tokenization fails as soon as lexeme_grow appends a body or closing chunk to a compact-string prefix. Preserve a string-aware append path or convert the accumulator to the structural carrier before using list_push.
Useful? React with 👍 / 👎.
| " compilation_unit: path.clone(),\n", | ||
| " source_root: source_root_for_storage_path(path.clone()),\n", |
There was a problem hiding this comment.
Normalize absolute paths before deriving source-root identity
When --source-root is absolute—a supported case in cli_run's source-root anchoring—the generated walker stores absolute file names here. source_root_for_storage_path classifies only paths beginning with src/ as V2Tree, so every absolute src/v2/... file is mislabeled DagTree; its refusal paths also no longer match the host's workspace-relative module index. Native preparation then resolves against the wrong root identity and the required smoke test can be refused even though the same tree works with relative roots.
Useful? React with 👍 / 👎.
…2-native. #10882 is on main; keep a merge commit (no rebase).
…native. #10882 is on main; keep a merge commit (no rebase).
#10882 landed on main, which fires the trigger this carrier declared and moves it from DESIGN 3c's second state to the first. THE DECLARED CONSUMER IS NOW AN EXECUTING ROUTE. v2.workflow.compile_door_ledger cause_ownership_lookup is grain-keyed on this base and carries FatalGrain ownership for all five terminal reasons this table reports, so every row's terminal_reason is now asked of the ledger at FATAL grain. That clause could not be written before: known_frontier_causes carried four causes, all HEAD grain, none of these five - the witness would have been red then and green on the repair, which is the wrong direction for every subject involved. Writing it now is the trigger having fired, which is the difference between a frontier and an excuse. It is also the only clause over this table that a DIFFERENT module can turn red. Every other witness folds literals the table itself carries; this one goes red if the table names a cause the ledger never owned, or if the ledger retires one while a row still reports it. Its control plants resolve_ambiguous_export - a cause the ledger DOES own, but at head grain only - so the red establishes a grain check rather than a membership check. THE PRODUCER RESOLVES HERE NOW, and the annotation that said otherwise is corrected rather than left to rot in the opposite direction. It was true when written. THE SHORTCUT RECEIPT carries three observation identities and the two pairings that isolate one variable each, and no rows - the members are the table above, and a second copy keyed by join would be the duplication this file exists to avoid. Two witnesses over it, both refusing a shape rather than asserting a measurement: a pairing must actually isolate the variable it names (a DriverBinaryIsolated join whose observations used different roots varied two things and established neither), and a recorded disagreement must name its members (an outcome that could say "they differed" without saying where is unfalsifiable and indistinguishable from not having looked). Neither asserts that the joins agreed; a future observation that disagrees is a finding about the shortcut, not a defect of this carrier. Sixteen witnesses green by execution. Both new clauses have discriminating reds: the head-grain cause for the ledger join, and a mislabelled isolation claim for the receipt - each turning its own witness false while named bystanders stay true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Eg1HkPdjnUAcPCpcGkb4sD
Audited the carrier and the plan doc for prose that was true at the observation head and false on main now that #10882 has landed. Two statements remained after the merge commit fixed the others: the doc's paragraph saying the lane and its row type "are unmerged at this writing", and the carrier's claim that the context fold emits its rows "at the pinned head, not on this base". Both are now false and both are rewritten. THE PATTERN IS WORTH MORE THAN THE TWO FIXES, because that paragraph has now been wrong in BOTH directions. It first said the producing route was "in this repository and is executable" while its three names resolved at no commit on main - the unreachable citation this carrier refuses to make about its own probe digest. A review caught that, and the correction said the names resolve "at the pinned head, not on main" - true when written, false the moment #10882 merged. Correcting prose about a moving branch with more prose about a moving branch just changes which direction it rots in. So the rule is stated in the carrier rather than the sentence fixed again: every statement here about the state of a branch names the head it describes, the pin names the tree the rows were OBSERVED over, and nothing asserts a present tense about main that a later merge can falsify. The doc keeps both wrong revisions on the record, because the second is the easier mistake to repeat. Checked and deliberately unchanged: both dissolve-on triggers, whose named capabilities still do not exist; the digest recipe, which already carries the src/bin exclusion in both places; and the pinned observation itself, which stays at the observation head because that is its identity. Sixteen witnesses green by execution. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Eg1HkPdjnUAcPCpcGkb4sD
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Declarations refused DurableOriginRead/DisposableCacheRead without their ReadSource parent. The four native_decl_selection test fns each re-ingested the fixture and crossed the 500ms CPU line; one witness still checks all four discriminators. Co-authored-by: Cursor <cursoragent@cursor.com>
…our witnesses fit the floor (#10992) The four witnesses of v2.test.native_decl_selection were refused INTERRUPTED-BEFORE-VERDICT at cpu_at_least=503-508ms against the required floor's 500ms per-claim CPU ceiling on three consecutive main heads (runs 34536354438, 34537144168, 34542819448). They are not failing: claims_failed=0, and no run has ever reached their verdict, so main's floor has been red since the file landed in #10882. WHAT THEY SPEND IT ON. The run's own cross-claim demand census (required_floor_cross_claim_demand.tsv, run 34542819448) names the producer: collision_prepared / native_test_context_from_ingest, 4 claims, the file's whole censored cost, with `tokenize` alone ~330ms per claim and parse_module_prepared ~160ms -- the seed tokenizing and parsing ~230 characters of synthetic source once per claim. The uncensored stage split under claim_batch (arm64 session host) measured ~1.1-1.4s per claim: tokenize ~490ms, parse ~375ms, normalize + context fold ~210ms, resolve + infer ~220ms, eval ~0. No quadratic fold or copied accumulator: the shape is one ingest re-derived four times across isolated per-claim frames, DESIGN 2's authored recurrence whose least common ancestor is the floor run. THE REPAIR IS "STOP RECOMPUTING", NEVER "RAISE THE LINE". The prepare grain of the source-root Eval driver (v2.compiler.compile) is split at the portability seam: native_test_resolve_module and native_test_infer_resolved are the two halves and native_test_prepare_module is their composition, so the emitted native-lane harness keeps calling the composition unchanged. The witness fixture shares at the resolved tree -- the deepest closure-free stage, the same seam v2.compiler.self_host.direct_rust_door_fixture uses, since the InferredTree carries a PartialFunction -- through a nullary collision_resolved() enrolled WARM in v2.workflow.floor_pure_producer_share: the floor forces it once during strict preparation, outside every per-claim budget, and each claim keeps infer + eval. Nothing the witnesses assert changes; all four PASS under claim_batch on this branch. The instrument that decides it is the enforcing run's own [floor-shared-fill] ledger (disposition=Stored at preparation, four hits) joined against required_floor_claim_cost.tsv showing the four rows reaching verdict_reached=true with an observed cost. Claude-Session: https://claude.ai/code/session_011tL1ok77LYKmFdEDaX1XUw Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…invoked instrument (#11003) Operator ruling 2026-09-11. The job landed with #10882 citing a ~70-minute native run inside a 180-minute envelope; the only full run on the real runner class took 4h06m at 14.8 GB, and the workflow's concurrency group (per PR number or run id, cancel-in-progress false) never supersedes a running job, so every push added another ~4h claimant. 31 native jobs were running concurrently this morning and the build and floor lanes were failing on main under memory stalls and budget interruptions. Cut at the root: WitnessFloorV2NativeLane leaves gunbc.witness_floor_workflow, the v2-native lane and phase leave gunbc.required_ci_phase_roster and the host binary, witnesses.yml and docs/design-rung-drops.md are regenerated. The route model, harness and admission authority are unchanged and reachable as claim_executor --v2-native-route. Declared as the 4b(3) drop gunbc.rung_drop v2_native_route_off_the_merge_path with a capability-shaped trigger; the consolidation witness reds if required-v2-native returns. Claude-Session: https://claude.ai/code/session_01DQyBe1FaYb3bFZmpTczetX Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Admit expression-bodied fn decls as `= expr` on fn_decl only. Keep fn_body brace-only so if/block/fn-literal stay unchanged, and lower the eq-rhs through normalize so `fn f(a: Int) -> Int = a` survives graft. Co-authored-by: Cursor <cursoragent@cursor.com> * Enrol G predicates as test fn so floor discovery sees the entry. A *_test.dag with only plain fn leaves universe derivation empty; claim_batch --functions is not discovery. Co-authored-by: Cursor <cursoragent@cursor.com> * Refuse eq-body lowering without an `=` witness. last_child without eq was an absorbing fallback; eq is token identity only, matching let navigation. Survives probes now require an arrow body via find_arrow_body_child. Co-authored-by: Cursor <cursoragent@cursor.com> * Type eq-body fold accumulators as Optional, not Absent. Emission rendered Option<Absent> (E0425) and could not infer the eq-token match binder (E0282). Init with optional_absent() so the emitted crate compiles. Co-authored-by: Cursor <cursoragent@cursor.com> * Keep a reduced bare-Absent fold fixture as an open emitter red. G's optional_absent() repair is source-only. The interpreter still accepts init: Absent where the type is Optional, and emission has rendered Option<Absent>. Cite that shape on accepted_source_emits_uncompilable_target (vii) so ACT realization-fidelity still has a subject. Co-authored-by: Cursor <cursoragent@cursor.com> * Give eq-body folds a typed init and typed step. optional_absent() retired E0425; emitted lambdas still render acc: _ so rustc cannot infer Optional's T (E0282). Init and step are now declared functions. The untyped-lambda shape stays as a second emitter-red fixture. Co-authored-by: Cursor <cursoragent@cursor.com> * Unblock required-witnesses-floor on the G merge of #10882. Declarations refused DurableOriginRead/DisposableCacheRead without their ReadSource parent. The four native_decl_selection test fns each re-ingested the fixture and crossed the 500ms CPU line; one witness still checks all four discriminators. Co-authored-by: Cursor <cursoragent@cursor.com> * Revert out-of-scope floor/declarations edits. The fabric witness shape is #10977's; the 500ms native_decl_selection interrupts were fleet contention. Receipt at b5cefb6 stands. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
…ce per claim frame (#11015) #10882 landed four native_decl_selection witnesses into the required floor; each called collision_prepared, so the seed tokenized and parsed the same ~230 characters of synthetic source once per claim. The floor refused on main with claims_failed=0 and interrupted_cpu_deadline=4 -- nothing failing, the lane red. #10992 repaired it by sharing the fixture at the resolved seam. The repair is landed; the class is not filed. This files it. The durable finding is not that four rows were expensive. It is that a cost gate measured N copies of one shared pure derivation and attributed them to N rows, so every disposition the refusal offered -- trim the subject, re-home it to a lane that allows the cost, widen the line -- priced the duplication as though it were the claim's work. Partitioned, the claim's own act (native_test_eval_one) is ~24ms against a ~725ms precondition: three percent. A row whose own work is three percent of its measured cost is a cheap claim behind a shared precondition, and that ratio is what locates the class. The second half is the ceiling: 3,592 planned identities pass the 500ms line precisely because none of them pays per-claim ingest, so the corpus the figure was calibrated against could not have exposed the gap. A newly arrived claim family paying a cost kind no incumbent pays is adjudicated by a constant that never saw it. Bounded against three neighbours it would otherwise be merged with: right_censored_cost_read_as_exact (a carrier defect, fixable while the duplication stands), ceiling_never_exercised_for_a_population_the_census_cannot_plan (those identities are never planned; these were planned and interrupted), and the near-line misplaced-threshold family (these sat 2.2x-2.7x out, so no defensible placement admits them). Rung found at mitigatable; attainable ceiling mechanically preventable, because whether one pure derivation is reached from several claim frames is decidable from the resolved graph -- and deliberately not higher, since the shape stays authorable and is correct whenever the value is cheap. Evidence by execution: the row renders through its consumer, gunbc.design_ledgers expected_design_failure_modes_md, with its identity and receipt text present in the projection. Discriminating control: breaking the consumed receipts field reds the fold (module index refused, unparseable source) and the row's text leaves the projection; restored byte-identical and re-run green. The derived roster (gitignored) picked the row up at lines 189/407. required-regen reports first_generation_equal=true with no committed artifact drift. Claude-Session: https://claude.ai/code/session_01V8Xv998kJjfXLcG34vwGuq Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…0981) * Make required-v2-native's envelope, flags, budget, and main occupancy truthful. The merged native job still declared a 180-minute timeout and a unique-per-push concurrency key while the route's own census is the producer for a multi-hour wall on shared arm64 runners. Raise the job timeout from the workflow authority, serialize main onto github.ref without cancelling in-flight runs, set -D warnings on the emitted crate's cargo, and print HostBudget peak against the slot cgroup on the receipt. Co-authored-by: Cursor <cursoragent@cursor.com> * Scope P0a to native-job supersession and a 360-minute envelope. Workflow-level uniqueness still keeps build and floor verdicts. The required-v2-native job now groups per ref and cancels the previous native job for that main branch or the same PR. Timeout stays a temporary truthful envelope; warnings, HostBudget, and receipt fields wait for P0b. Co-authored-by: Cursor <cursoragent@cursor.com> * Make PR-head native supersession reachable: unique workflow run_id. A workflow group keyed on pull_request.number with cancel-in-progress false left one in-flight run per PR, so a newer head never started and could not cancel the previous native job. Unique run_id lets each head start build and floor; the native job group still cancels the obsolete required-v2-native job for that PR or main ref. Co-authored-by: Cursor <cursoragent@cursor.com> * Supersede stale witnesses.yml runs at whole-workflow PR and main grain. Job-level cancel cannot fire while the predecessor's top-level group still blocks the successor from starting. Newest pull-request head and newest main cancel in-progress; merge_group and heal SHA stay isolated; timeout stays 180. Co-authored-by: Cursor <cursoragent@cursor.com> * Join witnesses.yml cancel to occupancy standing, not a second policy row. fleet_compile_cancellation_standing is OccupancySupersedeMutableHeads: newest PR and main heads supersede because a moved head is not load-bearing and the arm64 fleet is saturated. Workflow cancel-in-progress is that standing's projection. Co-authored-by: Cursor <cursoragent@cursor.com> * Split occupancy grouping from fleet-safe running cancel. MutableHeadStanding is the event table; FleetCompileCancellationStanding stays producer-absent. Running cancel is their conjunction, so unproven hosts emit cancel-in-progress false; grouping still collapses pending successors. Co-authored-by: Cursor <cursoragent@cursor.com> * Delete the witness-only cancel join; four-cell the production chain. YAML cancel still projects fleet standing through running_supersession_for_fleet_standing. Grouping remains pending-run collapse, not running SIGKILL. Co-authored-by: Cursor <cursoragent@cursor.com> * Retire the 2026-08-17 unique-run_id grouping annotation. The occupancy ruling groups PRs by identity and main by github.ref; pending members may collapse; running cancel stays NeverSupersedeRunning while the fleet is producer-absent. Co-authored-by: Cursor <cursoragent@cursor.com> * Derive the concurrency group from the event-name and heal-input authorities. The group string is concat of github_event_name_* and ci_heal_expected_healed_sha_input_name. The witness asserts those keys independently instead of grepping the same row's emission. Co-authored-by: Cursor <cursoragent@cursor.com> * Fold concurrency-group GHA from modeled event/subject rows and resolve fixtures. The group expression no longer embeds event-name literals; a fixture walk of the same branch list is the discriminating RED for swapped or dropped arms. Co-authored-by: Cursor <cursoragent@cursor.com> * Require joined event-and-subject group patterns and a crossed-pairing RED. Independent fragment checks stay green if pull_request and push subjects swap; one concat per branch plus an absent push+pr pairing makes that swap authorable. Co-authored-by: Cursor <cursoragent@cursor.com> * Declare the main per-commit floor drop and bind the heal resolver to the input row. Occupancy grouping lowers a stated unique-run_id guarantee, so the 4b(3) row lands with this change; citations and the fixture lookup follow the same head. Co-authored-by: Cursor <cursoragent@cursor.com> * Correct the main-floor drop trigger and unbind timeout from the grouping witness. The lost property is SHA-bound adjudication of superseded pending mains, not fleet-safe SIGKILL or P0a.2 as currently specified; timeout is a different envelope and must not live in this witness. Co-authored-by: Cursor <cursoragent@cursor.com> * Delete the required-v2-native CI job; the route stays as an operator-invoked instrument Operator ruling 2026-09-11. The job landed with #10882 citing a ~70-minute native run inside a 180-minute envelope; the only full run on the real runner class took 4h06m at 14.8 GB, and the workflow's concurrency group (per PR number or run id, cancel-in-progress false) never supersedes a running job, so every push added another ~4h claimant. 31 native jobs were running concurrently this morning and the build and floor lanes were failing on main under memory stalls and budget interruptions. Cut at the root: WitnessFloorV2NativeLane leaves gunbc.witness_floor_workflow, the v2-native lane and phase leave gunbc.required_ci_phase_roster and the host binary, witnesses.yml and docs/design-rung-drops.md are regenerated. The route model, harness and admission authority are unchanged and reachable as claim_executor --v2-native-route. Declared as the 4b(3) drop gunbc.rung_drop v2_native_route_off_the_merge_path with a capability-shaped trigger; the consolidation witness reds if required-v2-native returns. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DQyBe1FaYb3bFZmpTczetX * Emit occupancy grouping and cancel expressions through extdeps.github.expressions. Route group and cancel through the modeled AST and one fixture evaluator, keep only the heal != '' gap, and rewrite the main-SHA drop so the subject is required obligations rather than a frozen job roster. * Model NotEquals in GitHub expressions and drop the heal gap row. The occupancy group is one interpolated AST; the fixture evaluator walks it, including !=, so heal nonempty-input is no longer a second string path. * Delete the producer-side event-name string serializer. The occupancy group is already one interpolated AST; tests now spell expected YAML from event-name constants instead of a second serializer in the workflow module. * Move GHA evaluation into extdeps.github.expressions and refuse unmodeled forms. The fixture resolver consumes the cited evaluator; empty is no longer the encoding of an unknown path or format arity, so those cases go red instead of collapsing to the run-id fallback. * Derive mutable-head event membership and cancel OR from one roster. Classifier and cancel emission both folded the same {pull_request, push} set by hand, so they could disagree; the four-cell join now pins supersession_available_under on push as well. Co-authored-by: Cursor <cursoragent@cursor.com> * Treat only the empty string as falsy in the GHA expression evaluator. The operators page falsifies boolean false and number 0, not the strings "false" and "0"; Equals already encodes boolean false as "". Co-authored-by: Cursor <cursoragent@cursor.com> * Keep running-cancel restoration to pull_request; do not cancel running main. Occupancy grouping still keys push by github.ref (pending replacement). A landed main SHA's running jobs are not lawful supersession without a declared 4b(3) drop. Co-authored-by: Cursor <cursoragent@cursor.com> * Wire the safe fleet arm to SupersedeMutableHeadRuns over the PR-only roster. The producer was restoring a pull_request literal beside an unused roster and cancel AST, so running-cancel membership had two homes. Classifier, cancel emission, and the four-cell join all read that one list; push stays off it. Co-authored-by: Cursor <cursoragent@cursor.com> * Delete the unused SupersedeMutableHeadRuns surface. Safe-fleet restore is SupersedeRunningForEvent { pull_request }; a one-element mutable-head roster was a nickname of that constructor. Four-cell still pins that push running-cancel stays false. witnesses.yml is unchanged. Co-authored-by: Cursor <cursoragent@cursor.com> * Name grouping and the main-verdict drop instead of citing the group above. The running-cancel annotation claimed main already accepted N concurrent runs; pending main replacement is the occupancy grouping trade, declared as main_per_commit_floor_verdict, and running cancel stays false. Co-authored-by: Cursor <cursoragent@cursor.com> * Split grouping and PR-activity witnesses off the full YAML serialize. Each event fixture is its own claim; group-expression text is interpolated from the AST; the activity set is the roster the trigger already emits. The combined YAML walk was 502–600 ms against a 500 ms deadline. Co-authored-by: Cursor <cursoragent@cursor.com> * Restore trigger-types emission coverage without a full workflow serialize. The activity-set witness now serializes witness_floor_triggers through the same YAML projector the workflow emit uses, so a list change in the trigger still fails while the claim stays at 6ms CPU. Co-authored-by: Cursor <cursoragent@cursor.com> * Record that trigger-types coverage is the on: fragment plus the YAML drift gate. The claim already serializes witness_floor_triggers through the workflow on: projector (6ms); the annotation names that composition so the full-file serialize is not reintroduced as the emission path. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
… seed-prepared artifact (lands after #10990) (#10940) * Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for dag declared inhabitants: the add slice greens end-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Add v2 self-host direct-path orientation: axes, sequence, autonomy contract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Derive grounding for fully-evidenced Conj and Arrow products The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground canonical-operation and grammar-production atoms by authority roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Ground binding-reference atoms from the enclosing arrow's domain declaration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires The door specimen's inference frontier is fully closed, so its production observation now reaches the emission stage. Two defects surfaced there, both fixed here: Emission composition. generate_rust_emission_candidate served two lanes with one root shape: the door's production path (a dag module shell) and a fixture lane (a bare rust Arrow). The translate ownership gate queried the module atom's ownership at a struct-field use site and refused with target_use_site_ownership_lookup_miss, because the module's grammar-projection conj was misread as a type record. The door's real composition is the produced-decl path: collect declaration conjuncts from the inferred tree and emit via emit_produced_decl. A new generate_rust_module_emission_candidate does exactly that, enforcing an exactly-one-declaration admission policy (rust_module_emission_decl_absent / _ambiguous). The observation and production mint paths switch to it; the fixture-lane candidate is retained with a note that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds nodes of produced-decl shape (a Conj whose first child is a Named edge to an Arrow). Its decl-head match routes through a declared FreeMonoid<Edge> parameter because the v1 seed stamps pattern variables from a declared parameter type, not from a field-access scrutinee. Operator decode. With composition fixed, source fidelity still refused: the door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead of { x + y }. Resolution canonicalizes a surface operator atom into a canonical-operation wire node, so a production tree's transform operator position carries the wire, while fixture trees that bypass resolution still carry the surface token atom. translate_project_transform_in_arrow_scope only knew the surface-token table, so the wire missed and fell to callable apply, rendering the discriminant identity. The projection now tries the wire decode first (canonical_operation_from_wire_node) and only on a wire miss falls to the surface-token table, then to callable apply; the arms are disjoint, so the dispatch adds no fallback widening. target_transform_operator_child extracts the operator child safely. The door's closing expectation now greens by execution, so its known_red_probe row in explicit_witness_admission is deleted per its own dissolution condition, and the roadmap authority note, the door contract note, and the direct-path plan are updated to record the green state. realized_closure_for_v2_direct_ rust_door_emit_run's module list reflects the produced-decl route. Verified by execution: the door witness greens; the fixture, containment, algebra, produced-decl, add-slice, and classical-not witnesses stay green; claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and clippy --all-targets -D warnings are clean. One pre-existing red, witness_projection_is_active_only in the floor_cost_debt containment roster, reproduces on the base revision and is unrelated to this change. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate First InterpreterRetained -> SelfEmittedNative promotion after classical_not, executing the v2-emitter-first-behavioral-module first slice at the coverage-frontier grain: the add family (fewest dependencies — integer literals plus one canonical operation) now carries a native-only verdict witness, so its behavior is established by the emitted crate's own stdout with eval() unreachable from the verdict path. - emit_host_native_only_add_holds: real emit -> cargo build -> native run, stdout pinned to the family's expected octet, sharing the kernel family's one-build cache key exactly as the classical_not arm shares its family's key (no duplicated cold build). - emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken control — a no-eval verdict has no oracle leg to break, so the expectation side breaks (an octet the run never produces must not match); program-side discrimination stays with the family's equals_eval primitive-five/six pair. - The add coverage row flips disposition with its backing citation enrolled by construction (the verdict entry is file-grain enrolled in falsifier_self_host_wet_template_entries). - Frontier census tests updated at identity grain: natives are exactly {classical_not, add}; split 2/13. Verified by execution: all six native-only verdict tests green locally (real wet legs — compile_skipped receipts show cold builds and native runs); all eight emit_coverage_frontier tests green, including the unbacked-claim RED control. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com> * Record the add-slice defect's repair in the declined-live-tree classification The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass. * Hoist two in-body annotation blocks to module-item grain Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4). * Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8. * Key the emitter's host-String arm on declaration provenance, not spelling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors. * Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated). * Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2). * Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * Emitter: a substituted declaration node carries its own provenance Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS). * Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain. * Pin the cargo half's toolchain channel by construction The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs. * Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md * Remove the stale PointwisePower inhabitant rows from the four language rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors). * Regen gen-2 gate: compare executable digests in one spelling The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way. * Model ReleaseScopeEmpty for release-excluded mirrors, end to end A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback. * Round-cost receipt: project installed mirrors to the model's vocabulary The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means. * Hoist ReleaseScopeEmpty annotations to module-item grain The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes. * Spell the PointwisePower witness's finite-set exclusion as the applied realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain. * Emit fieldless-record data values as null for the unit-struct carrier The second native-parity divergence class, measured 2026-09-08 on the native run of the emitted 00_compile closure: emit_data_value_json spelled EVERY record literal as a JSON map, including the zero-field record, while emit_struct_from_children renders that same declaration as a Rust unit struct (pub struct BoolEncodingFact;). serde's derived unit-struct Deserialize reads null and rejects {}, so the emitted compiler panicked at first touch of v2.std.logic's bool_primitive_facts: "invalid type: map, expected unit struct BoolEncodingFact". The JSON spelling of a data value must deserialize into the Rust type the same declaration emitted; the record arm now spells the zero-field value null and keeps the map spelling for non-empty records. The mirror is taken from the required-regen candidate, not hand-edited. Two witnesses enroll: the discriminating red (zero-field record spells null, never {}) and the boundary control (a record with fields keeps the map spelling). * Bind the duplicate-definition filter ahead of its branch condition Main's FilterInBranchCondition wall (#10699) refuses to publish a module whose filter call sits in a branch condition, and the v2 00_compile closure emission names primitive_duplicate_semantic_definition_violation as such a site. The filter is pure and total; binding it with a let ahead of the branch is the authored remediation the wall exists to force, and the emitted closure is unchanged in behavior. * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception * Emitter: three native-parity repairs for the post-merge 00_compile closure build Three divergence classes measured as the 21 rustc errors on the natively emitted 00_compile closure after the main merge, each repaired at the .dag source with a discriminating witness: - Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs): alias_rhs_base_module_filename asked the global leaf index, saw LeafAmbiguous for Compose, and emitted the poison marker even inside v2.std.integer itself, where source resolution binds the local declaration before any cross-module lookup. The local physical declaration now shadows foreign declarers; the poison marker still stands for a leaf two FOREIGN modules declare. - The qualifier is the disambiguator (8 E0425/E0433 in v2_lens_fact_density.rs): the qualified use-line route declined any globally-ambiguous leaf, but a qualified reference names its provider in its own spelling. The route now resolves by DeclaredCallableIdentity at the qualifier, keeping the type-declared and export-proof walls. The dotted spelling reaches the route through the value surface (a qualified value projection's borrowed type stamps the match patterns' parent_enum); the witness reproduces that chain exactly, and its exclude half pins the E0603 boundary (the dotted VARIANT head must still be declined). - Clone-bound forwarding is transitive (1 E0277 in std_realization_measurement.rs): the call-forwarding derivation re-derived only each callee's SELF-derived half, so a callee whose bound is itself forwarded re-derived to empty. The derivation now recurses over the call graph with the module's visited-set termination; the equality half stays one-hop as declared. Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds. * Refuse variant record literals on the serde_json data path fail-closed A record literal with parent_enum present is a variant construction whose wire spelling is the parent coproduct's declared VariantEncoding policy -- a module-local fact of the parent's home module that emit_data_value_json does not carry. The zero-field arm's null and the map arm's untagged fields are both measured to fail serde deserialization under the internal-tag default, so the arm now refuses and the caller renders compile_error!, a build-time located refusal where a runtime panic on the data definition's expect was the latent alternative. The refusal names its trigger: a closure-wide wire-policy index beside EmitGraphInfo.type_decl_items. Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed forces the JSON path with a nested-record Holder and asserts the compile_error! spelling while excluding the former null mis-serialization. * Spell variant record literals on the serde_json data path from a closure-wide wire-policy index The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites (SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant record literals reach the JSON data path in the 00_compile closure. This change replaces the refusal with the correct spelling, driven by a new closure-wide index: - v1.compiler.infer_emit_info gains DataVariantWireSpelling, the language-general projection of a coproduct's Rust wire serde policy for one variant (InternalTagged { tag_field, tag } | BareString { tag } | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries data_variant_wire_spellings: Map<String, DataVariantWireSpelling> keyed by coproduct.variant. - v1.compiler.emit_rust builds the index once per emission root via build_data_variant_wire_spellings, resolving each coproduct's policy through the new shared resolve_emission_coproduct_wire_policy (the same function the type-emission side now calls, so the two cannot drift), projecting each variant through data_path_wire_variant_tag (rename_all and StripAffix aware), and poisoning collisions as SpellingRefused so ambiguity stays fail-closed. - v1.compiler.emit's emit_data_value_json variant arm reads the index: internal-tagged spells {"_variant": tag, ...fields}, bare-string spells "tag" for nullary and refuses fielded, untagged spells the bare fields or null; unindexed keys and stored refusals remain compile-time errors. The service mock-property chain threads emit_info through so dry-run data spells identically. Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed is rewritten as ..._spells_the_internal_tag (asserts the internal-tag map, excludes the former null mis-serialization and the refusal), and w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields pins the fielded case. 57/57 witnesses pass; regen fixed-point holds. * Promote field_access to SelfEmittedNative on the emit coverage frontier Fourth native-eval construct promotion, after classical_not, add, and complement. The native-only verdict arm pair lands in the already file-grain-enrolled long/ entry, so the backing citation is enrolled by construction: - emit_host_native_only_field_access_holds pins the family one-build cache run's stdout to octet 9 (the byte the family witness's warm leg pins on the same build), eval() never called. - emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds breaks the expectation side with octet 1, the alt tree's byte. Both arms verified wet locally (real cargo build + native run, sharing the field_access family one-build cache key). The roster row flips to SelfEmittedNative; the two census guards update per 4b(4) — the split moves to 4 native / 11 retained and the identity-grain membership guard is renamed to name the four-member population. The family's equals_eval agreement pair stays enrolled as its program-side discrimination leg. * Drop the scratch parity probe from the tree The probe is a manual parity-loop instrument (the interpreted leg of the native-vs-interpreted comparison), not a corpus declaration with an executing consumer (DESIGN 6 experimental residue). It stays in use locally as an untracked file. * Promote match, loop, and fold_closure to SelfEmittedNative Fifth, sixth, and seventh native-eval construct promotions. The three match_loop_fold family rows flip together on one shared family-crate arm shape, per the witness_family_build_grain_ruling: each arm emits the three-member family crate once and runs its own member through the argv dispatcher against the family one-build cache key. - emit_host_native_only_{match,loop,fold_closure}_holds pin the warm legs' stdout to the family's declared octet lists (match/loop [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called. - The wrong-octet controls break the expectation side with each member's own alt octets (match/loop [0,2,0,0,0], fold [0,255,255,255,255]). All six arms verified wet locally. The census guards update per 4b(4): 7 native / 8 retained, and the identity-grain membership guard is renamed to witness_native_rows_closed_membership_holds so the name stops encoding the volatile population. * Promote meet_join to SelfEmittedNative on the emit coverage frontier The meet_join family's native-only verdict arms land on the complement arm's helper, generalized to take the family member_id: meet and join run through the same argv-dispatched logic family crate (one-build cache key shared with complement, per the witness_family_build_grain_ruling), eval() never called, verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family witness's warm legs pin on this same build; the wrong-octet control expects each member's alt byte (0), which the primary runs can never produce. Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census guards move to 8 native / 7 retained with meet_join_eval_subject named in the closed membership. * Promote variant_construct to SelfEmittedNative on the emit coverage frontier The variant_construct family's native-only verdict arms follow the field_access arm shape exactly: the tree is the family's own equals_eval tree value (emit_variant_construct_eval_tree, no eval leg reachable), the run shares the family one-build cache key that emit_on_demand_variant_construct_native_one_build_holds colds, and the expected octet 9 is the byte the family witness's warm leg pins on this same build. The wrong-octet control expects the alt tree's byte (1), which the primary run can never produce; the wrong-value alt leg in the family witness keeps the program-side discrimination. Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census guards move to 9 native / 6 retained with emit_variant_construct_eval_subgraph_node named in the closed membership. * Close the emit coverage frontier: final six rows to SelfEmittedNative The last six InterpreterRetained rows flip to SelfEmittedNative, taking the roster to 15 native / 0 retained: - filesystem_read and shell_exec_run (host-effect transport families, no translated arrow body): the arms reuse each family's own native leg with the expectation pinned as a literal grounded by the family's enrolled fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run argv materializes to exactly [bash, -s]), run through the families' fixed witness workspaces. - module and produced_module: the arms execute the exact sources the equals_eval pairs run (emit_module over the add fixture tree; produced_add_module_source's ingested two-fn module), octet 5 pinned against the add family's primitive-five/six oracle leg. - call and record_construct: the arms emit the families' own producer trees against their target models, octets 7 and 9 pinned against the primitive-seven/eight and wrong-field oracle legs. The four families without a one-build cache witness run under per-family fixed workspace roots; content-safety comes from the realization-digest nesting in run_host_process_admitted (changed source colds, never serves stale), the same mechanism the filesystem_read fixed workspace relies on. All twelve arms verified wet: PASS/PASS each, cold builds then warm hits. With zero retained rows the retained_via_eval_agreement constructor loses its last consumer and is deleted (DESIGN 3c); the InterpreterRetained variant stays as the disposition authority's other state. Census guards move to 15 native / 0 retained with all fifteen decl names in the closed membership. * Record the emit coverage frontier closure in the direct-path plan Axis C line: all fifteen roster rows are SelfEmittedNative as of 2026-09-08, interpreter_retained_rows() is empty, and the row constructor was deleted with the last flip. Notes explicitly that this closes axis (a) (witness-body-runs-native) only; axis (b) (the regen-grain production flip) remains operator-gated. * Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate Parallel track B (operator authorization 2026-09-09): one additional required CI job whose subject is the compiler/test execution route itself — the emitted-native compiler binary invoked by explicit path over a derived v2.test.* population. The lane is modelled in full in gunbc.witness_v2_native_route: the prefix universe derivation, the per-member verdict rows (head + fatal reason grain), the exclusion taxonomy delegating attribution to the door ledger's known_frontier_causes, the counted exclusion census with a totality check, the terminal-observation receipt carrier, the admission predicate (one predicate per contract clause, all causes collected), and the enrolment gate with today's standing as data. Enrolment is BLOCKED, as data with a named capability trigger: the measured census over the derived universe (882 members, seed withdrawn during the run) refused every member — the emitted DirectIngestDriver admits only the hard-coded compile_driver_subject name with empty imports, and the compile door is at its modelled frontier — so the contracted positive population is empty and native_route_admission over the real receipt executed to 'refused: positive_population_empty'. The exact enrolment edit (phase-roster variants, claim_executor mirror, workflow lane, aggregate join, YAML regen) is carried on the standing row. The census measured five fatal-grain refusal causes the door ledger's head-grain attribution table did not carry; they are added to known_frontier_causes with their owning lanes (three MigrationOwned under nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath). Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and execute green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Split preparation predicates so EmittedClosureUnrecorded is reachable Review on #10882 (briansrls, point 7): native_route_preparation_recorded folded the seed and closure observations into one && predicate, so a receipt with a recorded seed and an unrecorded closure misreported as preparation_seed_unrecorded and the emitted_closure_unrecorded cause had no reachable construction — the grain-mismatch class DESIGN 4b(3) names. One predicate per observation, one admission clause per predicate, and two witnesses pinning each refusal name against its own receipt shape (including the negative: each refuses ONLY by its own name). Co-authored-by: briansrls <briansrls@gunb.ai> * Key cause ownership by diagnostic grain; classify native refusals at fatal grain The door ledger's known_frontier_causes was a head-grain authority; the native route classified fatal reasons through it, crossing grains (review on #10882). Generalize the ownership key with DiagnosticGrain so one table answers both grains: the door ledger's cause_is_attributed keeps its head-grain contract, and the native route's exclusion classifier asks the fatal-grain question of the same table. The head advisory is live receipt data again: every refused row's head reason must be owned at head grain (or by this lane's driver-limit roster), and an unowned advisory blocks admission by its own clause name. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist known_frontier_causes row-group notes above the declaration The grain-keyed ownership change left its row-group commentary inside the list literal; the annotation channel admits only module-item grain, so the emitted closure refused with nine annotation-grain diagnostics. Move the notes to a single block above the declaration. No semantic change. Co-authored-by: briansrls <briansrls@gunb.ai> * Parse test fn as a contextual production in the v2 dag grammar The emitted native compiler could not parse any v2.test.* module: the modeled dag grammar had no test fn production, so every floor witness module refused with parse_g0_tokens_remain (706 of 882 in the census). test stays an ordinary identifier — typescript/program.dag models the TypeScript compiler's Cond.test field under real-upstream-names — so the production is the contextual sequence(ident, fn_decl): a new choice arm in top_level_item with no FIRST overlap with the keyword-led arms, a body-lowering arm that lifts the nested fn member after checking the marker lexeme is literally test (a typed refusal otherwise), and a forward-producer row for the new surface identity. Verified against the emitted native binary: probe_testfn.dag moves from parse_g0_tokens_remain to resolve_module_not_found (the driver's synthetic-subject limit, identical to a plain fn), and the standing choice-overlap residue roster is unchanged at seven rows. Co-authored-by: briansrls <briansrls@gunb.ai> * Add SourceRootEvalDriver: native whole-ingest test-execution route The required-v2-native lane's terminal subject is an exact test identity reaching a native Eval verdict, not a module accepted for translation. DirectIngestDriver (one source, no peers, synthetic subject) stays as the front-door census instrument; the new driver renders a main that reads a host-derived universe of qualified test identities plus the declared source roots, assembles the ingest once, prepares each module (resolve + infer), and Evals each named test body -- one typed verdict row per member, with a prepare-refusal fan-out so no member is silently dropped. Co-authored-by: briansrls <briansrls@gunb.ai> * Escape literal braces in SourceRootEvalDriver main.rs template The .dag string lexer reads '{' followed by an identifier as interpolation, so the emitted Rust use::-import lists and format! captures must spell literal braces as \{ \}. The single parse error desynced the file parse and cascaded into 2618 unattributed-annotation errors; with the escapes the emitter compiles clean (0 blocking, 107 files emitted). Co-authored-by: briansrls <briansrls@gunb.ai> * Collect per-file front-end refusals in the native test context fold The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest, which is wholesale fail-closed: one source hitting the v2 front-end's live corpus frontier would deny verdict rows for every other universe member. The fold now collects each source's tokenize/parse/normalize refusal as a NativeTestFileRefusal row (head and fatal reason grains, matching the door ledger's grain-keyed ownership) and keeps folding; a refused file contributes no root, so its test identities surface as Context-stage refusal rows and nothing is widened. The emitted main.rs prints the file-refusal rows and counts them in the terminal marker, and prepare/eval refusals now classify at the fatal (last diagnostic) grain consistently. Co-authored-by: briansrls <briansrls@gunb.ai> * Add native lane control fixtures Two controls for the required-v2-native lane's host harness: src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a well-formed false control and its true positive half) as plain fns outside the v2.test. prefix, so floor discovery enrolls no universe rows for them; fixtures/native_lane_malformed/poison.dag is a deliberately unterminating string that any honest front-end must refuse at tokenize, kept outside every declared source root so the broken bytes never enter an honest ingest. Co-authored-by: briansrls <briansrls@gunb.ai> * Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template The emitted driver crate aliases im::Vector as Vec, so the template's std Vec-typed bindings and collect calls failed to compile in the emitted crate: universe rows and module order carry Rc<Vector<String>>, the reads vector moves into the FreeMonoid parameter with .into(), and the dotted module name is built from an iterator collect. Co-authored-by: briansrls <briansrls@gunb.ai> * Harden the v2-native route contract: test-identity grain, exact join, paired reference Reframe the terminal subject from module-grain acceptance to the exact test identity reaching a native verdict. The receipt's universe is a list of qualified NativeRouteTestIdentity rows; the observed population joins it exactly (uniqueness, no foreign rows, no omissions); every member verdict is paired against the floor's own expected-red and route-gap rosters for agreement, exclusion, or divergence; refusals are classified from stage and provenance with cause ownership at fatal and head grains; and the four controls (true, false, malformed specimen, old-route withdrawal) are admission clauses. The 46 tests cover universe derivation, identity qualification, reference pairing, refusal classification, disposition, census counting, and every admission clause. Co-authored-by: briansrls <briansrls@gunb.ai> * Wire the required-v2-native lane into the roster, workflow, and aggregate Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's claim_executor command to fabric_witness_run, and the required-v2-native job to the witness floor workflow with the aggregate witnesses job needing it in both verdict arms. Regenerate witnesses.yml. Co-authored-by: briansrls <briansrls@gunb.ai> * Add the required-v2-native host harness and phase dispatch The lane's one phase derives the v2.test.* universe with the floor's own discovery producer over the full module inventory, prepares the emitted-native compiler through the emit-compile phase's crate writer and cargo invocation, withdraws the old-route gunbc binary for the spawn window, runs the emitted binary by explicit path over the universe plus the named controls, reclassifies context-stage refusals against the observed file refusals, mints the NativeRouteReceipt as the authority's own types, and hands it to native_route_admission for the verdict. claim_executor gains the V2Native lane and phase with the roster sizes moved to six. Co-authored-by: briansrls <briansrls@gunb.ai> * Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm std_compiler_entry.rs gains the SourceRootEvalDriver variant and v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs template with its dispatch arm, emitted by the regenerated seed and verified at the fixed point (first_generation_equal=true over the whole 155-module population). Co-authored-by: briansrls <briansrls@gunb.ai> * Name the probe crate's lib target v1_compiled, the emitter's self-name contract emit_rust_selected binds the self-emitted crate's name to v1_compiled for every non-retained-host pipeline entry, and the SourceRootEvalDriver and DirectIngestDriver mains reach the closure through use v1_compiled::. The probe manifest's per-entry package name left the lib target named after the package, so a pipeline entry's driver main failed E0433 in the probe build -- unreachable while every probe entry was pipeline-free, and measured on the required-v2-native lane's first preparation. The lib path stays cargo's default; only the name is stated. Co-authored-by: briansrls <briansrls@gunb.ai> * Release retained emission arena before the native cargo build The lane's first run held ~15GiB RSS from the emission's resolved graph into the cargo build of the emitted compiler and was SIGKILLed (rc=137) with no diagnostic. Drop the emission run and malloc_trim the retained arena at both derivation-to-emission and emission-to-build handoffs, reporting the reclaimed KB so a trim that cannot release live memory shows in the lane log. Co-authored-by: briansrls <briansrls@gunb.ai> * Apply rustfmt to the v2-native lane host changes Co-authored-by: briansrls <briansrls@gunb.ai> * Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy The emitter lowered every cons-match tail on a FreeMonoid to iter().skip(1).cloned().collect(), materializing the whole tail per step: every fold over a FreeMonoid was quadratic. Measured on the required-v2-native lane's first native run (2026-09-09): the self-hosted lexer, which tails the remaining source per character and per rule attempt, tokenized a 22KB file in 23.3s against 70ms for 899B, projecting a multi-hour whole-corpus context fold — the lane's dominant term. im::Vector::skip shares the RRB tree in O(log n). Two mirrors carry the only cons-tail sites in the stage0 corpus: v1_compiler_emit_rust.rs (the emitter itself) and std_occurrence_binding_candidates.rs. The e0599 emitter-decision census and its witness tests move to the new (skip, __fm) site with the measured rationale. Fixed-point regen green: the rebuilt seed regenerates both mirrors byte-identically. Co-authored-by: briansrls <briansrls@gunb.ai> * Route FreeMonoid length/snoc through the count/list_push primitives length folded the whole carrier per call (O(n)); the parse repeat loop calls it on the remaining-token list twice per element — an O(elements x tokens) quadratic measured at 40% of self-hosted parse self-time on the required-v2-native lane's first native run (2026-09-09). list_snoc_item routed through list_append, paying a full O(n) right-fold per snoc and making every build-by-appending accumulator quadratic (measured on the first-set union fold). count is O(1) and list_push amortized O(log n) on the persistent-vector realization. Probe-measured on the emitted crate: 25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB table module. Co-authored-by: briansrls <briansrls@gunb.ai> * Hoist first-fold knowledge into prepared grammar expressions The parse choice dispatch recomputed expr_first_fold on both branches at every Choice node at every token position: right-nested choice chains made that O(k^2) per position with O(t^2) union constants — the dominant self-hosted parse cost once the algebra carriers were fixed. The grammar is fixed for a whole parse, so each node's first fold (and each Choice's ambiguity verdict) is a pure function of the grammar: compute it once at preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its GrammarExpr signature as a compat wrapper that prepares on the fly; parse_nonterminal_memoized_core reads the prepared map. Forecast by a pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB table module. parse_minted_id_list also moves off list_append-per-node (O(n^2) per captured repeat) onto a snoc fold over the list_push primitive. Verified by execution: 29-test battery over parse_table_claims, grammar_validation (left-recursion suite), parse_token_first_empty_ semantics, parse_table_content_key and parse_table_memo_governed_witness all green through the seed interpreter. Co-authored-by: briansrls <briansrls@gunb.ai> * Deref boxed variant fields in enum shared accessors The storage side boxes a variant record…
#10692 has merged. This is the additional native-CI job (operator authorization 2026-09-09: one additional required job, not an advisory experiment, not a replacement of the existing lanes).
What this change is
The complete lane authority for the
required-v2-nativejob, modelled indag/gunbc/witness/v2_native_route.dagbeside the workflow authority that projects it — plus executing floor witnesses (src/v2/test/v2_native_route_test.dag) and the door-ledger attribution rows the lane's census measured as missing (src/v2/workflow/compile_door_ledger.dag). The host harness (src/v1/stage0/src/cli_run/native_lane_runner.rs), theRequiredCiLane/claim_executordispatch,witness_floor_lane_rostermaterialization, and the generated.github/workflows/witnesses.ymlenrol the job as a required lane; the aggregatewitnessesjob reads its result.The route under test
The job's subject is the compiler/test EXECUTION ROUTE itself: the emitted-native compiler binary, invoked by explicit path, executing a derived
v2.test.*population through its own whole-source-root Eval driver (std.compiler_entry SourceRootEvalDriver— thev2.compiler.compilenative_test_*fold), and reaching a TERMINAL TEST VERDICT per identity. The 32 native-only construct arms are explicitly NOT this proof — they show generated Rust programs ran natively while the claim executor stayed seed-backed; this lane's receipt shows which binary answered, and what verdict each named test reached.Modelled in full, as data:
v2.test.prefix over the floor's own discovery producer (v2.workflow.floor_discovery_producer), never a hand-listed roster; admission joins the observed population against the derived universe exactly.<module>.<declaration>identity; the verdict carried is the driver's ownNativeTestVerdictimported fromv2.compiler.compile, never a route-local re-declaration.FloorExpectedPass/FloorExpectedRed/FloorRouteGapRefusal, from thefloor_expected_redandfloor_route_gaprosters). A reached verdict that disagrees is a DIVERGENCE, never an exclusion; a refusal is a capability limit, typed and counted by its classified cause.CompilerFrontierAttributed(delegated to the door ledger'sknown_frontier_causesat FATAL grain — this lane does not re-enumerate that table),NativeEntryResolutionLimit(the named declaration was not an evaluable arrow — a driver fact the interpreted door never faces, owned here),NativeEvalBoundary(the hermetic effect boundary the floor route gaps on), orUnattributedRefusal, which blocks admission until someone owns it. The eight-counter census is derived from the rows and closed over the population.MalformedSpecimenAcceptedmeans every refusal verdict in the census is worthless), and the old-route control (OldRouteWithdrawn/OldRouteFalsifierArmed/OldRouteControlAbsent, the absent case representable precisely so admission refuses it by name).Review round 2 repairs (the HOLD's five blocking points + secondary)
reclassify_context_refusalsread its module-for-path map reversed — fixed, with a production-path test over a parse-refused module.What the lane measured and fed back
The first native runs surfaced real cost-shape defects, each fixed at its root: lexer lexemes grew by
list_append(quadratic in literal length — 18+ minutes on one 132KB literal) and now grow by snoc;length/list_snoc_itemrouted through O(n) folds and now use the O(1) / amortized O(log n) primitives; first-fold knowledge is hoisted into prepared grammar expressions; boxed variant fields are deref'd in enum shared accessors; the emission arena is released before the native cargo build.CI-environment repairs (each measured on a red required run)
RUNNER_TEMP) when declared — the shared host temp was EACCES on the self-hosted runners (run 34488910723 wrote under_work/_temp/gunbc-emit-compile/after the fix)..dag(poison.dag.poisoned) and materialized into a freshly-rebuilt scratch root by the harness — the changed-witness observation was parsing the deliberately-unparseable fixture and refusing the whole floor observation.else { unreachable!() }to anas_reflet-else whose pattern is irrefutable (sole-variant coproduct) — the emitted crate refused under CI's ambientRUSTFLAGS=-D warnings(irrefutable_let_patterns/unreachable_code) while compiling clean under its own posture locally.grainargument tocause_ownership_lookup.rust_shared_wrap_ctorrationale comment landed in-body, which the required-CI parse phase refuses (source annotations are admitted at module-item grain only — §4c); the refusal cascaded to no-head-index, a degraded floor, and a generated-artifact phase refusal carrying the same 4 diagnostics. Hoisted above the declaration, text unchanged.v1_compiler_emit_ruststage0 mirror drifted from its authority (v1.compiler.emit_rust) when the diverging-panic wrap refusal and the sole-variant coproduct emission landed without a regen — masked by the parse refusal, named by the drift gate once the parse was repaired. Regenerated from the--required-regencandidate tree (26 lines, the two sites).parse_lexeme_digestkeeps thechars(s:)boundary conversion the emitted route requires (emittedfold_list<T, _>cannot inferTfrom a host-carrier lexeme — E0282 without it), and the interpretedcharsbuiltin is widened to match: it had admitted only the native compact-string realization, so the ten floor witnesses whose fixtures constructToken { lexeme: Empty }went BLOCKING withchars expects a string argument, got Variant. The builtin now grounds throughfree_monoid_to_string— the same realization-agnostic readlength/fold_list/chars_to_stringalready use — so native compact strings and Empty/Cons chains yield the same Int codepoints, while a generic list, a non-codepoint chain, or an unrelated variant keeps the typed refusal (pinned by the newchars_receiver_tests). The memo content key is unchanged (witness_subject_token_stream_scope_sensitivegreen interpreted) and the emitted crate builds green under CI's ambientRUSTFLAGS=-D warnings.Branch-integration repairs (the lane's own witnesses and receipts)
w_RED_neither_lane_waits_on_the_otherpinned the TWO-lane split (required_lanes_roster() == 2); the roster has carried three lanes since this lane enrolled, so the floor red-carded the branch's own addition on every required run. The witness now asserts the three-lane roster — no lane job carriesneeds, and the aggregate's roster carries build/floor/v2-native exactly once each — andw_RED_lane_contexts_collide_with_no_other_emitted_workflowgains the new lane's clauses.wave1_gate1_a1_forward_behavior_row_count_witness_holdspinned the forward row table at main's six; the branch'stest fncontextual production (e8ed17102c) addedbody_producer_forward_row_test_fn_declwithout moving the receipt. Pinned at 7; membership is covered at identity grain by the sibling forward/fold surface-identity parity witness.Swallowed cargo diagnostic
cargo_verdict_summaryis the native lane's refusal surface (EmittedCompilerBuildFailed). ACompletedarm that rendered onlystatusswallowed the rustc header andstderr_tailthe verdict already held. A non-zero run now prints the attributed diagnostic and line when the scan found them, and always the stderr tail so an unattributed refusal (this lane's dummy attribution symbol) still names what rustc said.Testing
cargo_verdict_summary_renders_the_diagnostic_a_non_zero_run_already_holds; the lane probe-root test pinning both RUNNER_TEMP arms; the newchars_receiver_tests(every string realization grounds to the same codepoints; a generic list, a non-codepoint chain, and an unrelated variant keeps the typed refusal); thev1_interpreterunit module (157 tests) green;cargo clippy --all-targets -- -D warningsandcargo fmt --all --checkgreen;--required-regenfirst-generation-equal over 155 files (1 declared-divergentmain.rs) after the mirror regen.charsrepair;ingest_bridge_realizedandwitness_subject_token_stream_scope_sensitivespot-checked green interpreted.w_RED_neither_lane_waits_on_the_other,w_RED_lane_contexts_collide_with_no_other_emitted_workflow,wave1_gate1_a1_forward_behavior_row_count_witness_holds); the fournative_decl_selectionwitnesses pass standalone (their CI interruptions were the changed-witness budget refusing under runner page-thrash, not verdicts).v1_src_dag_parse(the samerun_dag_parse_sweepthe parse phase executes) sweeps 5403 files clean, with a planted unattached-annotation probe refusing as the discriminating control.RUSTFLAGS="-D warnings": emission green (172 files) and the emitted crate's cargo build green — the E0282 inference failure is cured. The universe census lands with the exact-head CI run.