Skip to content

Raw source-bound diagnostic census + UnlistedImportUse emitter-defect repairs - #10890

Merged
briansrls merged 17 commits into
mainfrom
cursor/advisory-census-blocking-4cca
Sep 10, 2026
Merged

briansrls merged 17 commits into
mainfrom
cursor/advisory-census-blocking-4cca

Conversation

@briansrls

@briansrls briansrls commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Status: review-round-2 repairs landed (head 09f56ef35e), CI 4/4 green on the exact head

The four fidelity gaps from the second review are repaired. The census now carries the authority's full three-state gate disposition plus an independent severity axis, classifies and certifies from one immutable policy snapshot, hashes the exact vector handed to compilation, and derives the diagnostic-class schema from the CompilerDiagnostic coproduct authority instead of a manually omissible specimen roster.

Round-2 findings, one by one

1. Third disposition collapsed → full gate axis + separate severity. DiagnosticCensusGateDisposition = CensusBlocking | CensusAdvisoryTypecheck | CensusRenderedUncounted { reason: NonEmptyStr } mirrors the authority's DiagnosticGateDisposition (src/v1/00_core.dag) one-for-one, and DiagnosticCensusSeverity = CensusSeverityError | CensusSeverityNonError is carried as an independent axis, because the repository models severity and gate independently. Every raw class observation is keyed (class, gate, severity); a class whose instances decide differently (e.g. WhereRefinementUnenforced by reason string) carries one row per cell rather than a fabricated class-level answer. Ceiling-roster coverage now applies specifically to CensusAdvisoryTypecheck: the roster-side CeilingRosterStale check requires the specimen's gate to be advisory-typecheck, and the observed-side CeilingRosterUncovered check fires only on advisory-typecheck rows — a RenderedUncounted diagnostic is reported as what it is and can no longer be pulled into advisory-ceiling reasoning.

2. Two policy reads → one immutable PolicySnapshot. compile_clean_diagnostic_policy_snapshot() performs one acquisition, one canonicalization, one resolve, one interpreter context, and reads both the UnlistedImportUse enforcement value and the ceiling-roster identities from that single context. Every census row and every policy-related receipt field — including resolver_policy_digest — is derived from that one snapshot. The census path no longer calls the process-global cached accessor (compile_clean_unlisted_import_use_blocks_cached); the digest now identifies the exact policy bytes that classified the census.

3. Digest identifies the executed vector. Subject sources are acquired once and canonicalized once (sorted by path, in place); that exact vector is handed to both source_vector_digest and compile_to_resolved. The digest identifies the executed vector, not a canonicalized proxy of it — no weakened canonical_source_set_digest prose needed.

4. Manually omissible specimen roster → authority-derived constructor census. compiler_diagnostic_constructor_census() derives the constructor set from the coproduct authority itself: a corpus walk over src/v1 locates the v1.std.core.CompilerDiagnostic declaration (exactly one Disj type item; zero or two declarations refuse DiagnosticCensusSchemaAuthorityAbsent) and reads its variant names structurally. Four executable checks, all evaluated before the expensive whole-tree compile: specimen class identities unique (duplicate insertion refuses DiagnosticCensusSchemaSpecimenDuplicate — a string-keyed overwrite cannot hide non-injectivity); specimen count equals the authority constructor count (DiagnosticCensusSchemaCountMismatch); every authority constructor represented by a specimen (DiagnosticCensusSchemaConstructorUnrepresented); every specimen known to the authority (DiagnosticCensusSchemaSpecimenUnknownToAuthority). A new CompilerDiagnostic constructor now refuses the census until it joins the schema.

Design discovery worth recording: the authority cannot ride inside the census's whole-tree subject closure — witness_layer_roots = ["dag", "src/v2"] (dag/gunbc/ci/ci_layer_roots.dag), and admitting src/v1 would rebind twelve last-segment module collisions documented there. The constructor census is therefore derived at parse level from the authority's source, not from the compiled graph.

Mutation battery (all discriminating)

# Mutation Result
M1 Duplicate specimen class identity refused: two schema specimens project one class identity: UnresolvedImport (pre-compile)
M2 Omit one specimen refused: ... specimen=58 authority=59 count mismatch (pre-compile)
M3 Duplicate roster row CeilingRosterDuplicate: UnlistedVariantValueUse
M4 Roster row naming a blocking class CeilingRosterStale: UnresolvedImport
M5a Promote UnlistedImportUse to Enforced, keep roster row CeilingRosterStale: UnlistedImportUse (fast)
M5b Promote to Enforced, remove roster row Full run: UnlistedImportUse gate=blocking severity=non-error diagnostics=3259; raw_diagnostics=25846 and unlisted_import_use_raw=3259 unchanged — promotion changes the attribute, never the count
M6 Remove an observed class's roster row CeilingRosterUncovered: UnlistedVariantValueUse (full run)
M7a Policy file unparseable Module index refuses with located parse error, exit 1 — before any count is produced
M7b Policy parses, binding row absent compile-clean-diagnostic-census: refused: disposition policy or ceiling roster unreadable: ... no declaration named 'compile_clean_unlisted_import_use_blocks', exit 2 (pre-compile)

Policy-unreadable is thus refused at two layers — the module index for unparseable sources, the census's own PolicyUnreadable arm for a parseable-but-unreadable policy — and neither arm can report zero.

Verification on 09f56ef35e

  • CI: 4/4 green on the exact head — required-witnesses-build, required-witnesses-floor, heal-generated-artifacts, and the aggregating required witnesses context.
  • cargo clippy --all-targets -- -D warnings and cargo fmt --check green.
  • Regeneration fixed point: changed_paths=0, exit 0.
  • Local floor lane green: phases_run=3 phases_failed=0, exit 0.
  • Three census witness tests pass (wall, rendering, refusal-rendering); the wall test carries a discriminating arm per gate state — all three gates, including CensusRenderedUncounted, flip the wall.
  • Real census run (receipt below): exit 1 DidNotHold, as armed.

Receipt (head 09f56ef35e)

compile-clean-diagnostic-census: closure_modules=4166 raw_diagnostics=25846 classes=17 unlisted_import_use_raw=3259
identity source_vector=d4432ec0881c65c8 compiler=98c41daa336e8d8a resolver_policy=9ee6dbeef35128aa diagnostic_class_schema=39df8c7c30095b18 closure=13d41d0c1a3a5959

17 (class, gate, severity) rows; conservation checked by the producer (per-class counts sum to the raw vector length); detail-count law checked (UnlistedImportUse class count == worklist row count). The independent axes are visible in the rows themselves, e.g. DeclaredTypeInhabitanceUndecided gate=advisory-typecheck severity=error — an error-severity class under an advisory gate. No live class currently occupies rendered-uncounted (ComplexityUnknown has zero instances in today's corpus), so the third state is proven by the schema digest covering all 59 authority constructors and by the wall test's CensusRenderedUncounted arm, not by a population row.

Remaining step (sequencing, not correctness)

Per the required landing order, once #10906 lands this branch will be refreshed from the new main, the duplicated emitter repairs and their already-landed witnesses stripped from the authored diff, and generated output regenerated rather than hand-resolved — leaving this PR as the census/ratchet program only.


What this branch carries (round-1 description, still accurate)

A. Emitter-defect repairs (earlier commits, shared with #10906): the kernel-identity guard, the field-access alias peel grounded with masked: false, and the qualified-spelling visibility fold — each with paired false-positive and false-negative controls, each with its discriminating witness enrolled RED-pre/GREEN-post.

B. The census: a severity-independent raw diagnostic census. The 3,367-row import-edit sweep was not started.

Round-1 finding-by-finding

1. False zero → repaired by construction. Every emitted diagnostic is counted with no severity filter anywhere on the count path. The wall is class-specific and severity-independent: unlisted_import_use_raw == 0 over the unfiltered population.

2. CertifiedCount → LiveDiagnosticObservation + identity block. The observation carries five digests: source-vector, compiler-executable, resolver-policy, diagnostic-class-schema, closure. The policy's sizing arm is renamed LiveDiagnosticObservation (not CertifiedCount).

3. No AddImport sweep. The policy rows for both import-list classes are WallAfterGrounding on the Step 0 binding-provenance census, with the no-default-AddImport rule stated in the row text. Binding-source partition: 229 definer-resolvable, 2,607 pool-coincidence, 406 listed-import, 17 ambiguous-leaf.

4. Worklist identity. UnlistedImportCensusRow carries position beside file/module/name/binding-source, sorted by (file, position); the row comment states this is not the Step 0 occurrence identity that must precede any actuated edit.

5. Open-string roster → executed bijection witness. The ceiling roster projects to class names; the producer refuses CeilingRosterDuplicate / CeilingRosterStale / CeilingRosterUncovered, now scoped to the advisory-typecheck gate per round-2 finding 1.

Explicitly out of scope

  • Step 0 binding census: the missing capability both import-list classes are walled on.
  • Per-class monotone ratchet: needs a stored base reading joined against head by an executing consumer.
  • The import-edit sweep: not started; the worklist is not an edit script until Step 0.

Known limitation (pre-existing)

For diagnostics emitted with no_span() (e.g. the effect-summary classes), distinct_positions collapses to 1 because <synthetic>:0 is one position; distinct_modules remains the honest diffuseness signal for those classes. The walled class carries real spans (3,258 distinct positions over 3,259 rows).

Open in Web Open in Cursor 

cursoragent and others added 6 commits September 9, 2026 05:38
The compile-clean advisory census returns as `gunbc test
//gunbc/instruments:compile-clean-advisory-census`: one entry per advisory
diagnostic class over the whole-tree compile-clean closure (count, distinct
modules, distinct source positions), plus the binding-source-attributed
UnlistedImportUse worklist. The entry point is a rostered TargetBinding in
gunbc.instrument_targets with a modeled CompileCleanAdvisoryCensusObservation
in gunbc.target_binding, so the sweep that removed the unrostered bin in
gunbc#9160 cannot recur.

The dead `compile_clean_unlisted_import_census` wrapper deletes with it: the
advisory census's unlisted_import_rows carry the same rows, and a pub fn whose
only call site was its own definition is DESIGN 3c's dangling declaration. The
two .dag citations of the old symbol repoint to the subsuming census, and the
scaffold marker comment now names the remaining hand-Rust classification
surface honestly.

Also repairs a pre-existing red fixture in target_invocation_witness_test: the
planned-site fixture used test.claim.some_witness, which matches no prefix in
the static required_gate_prefixes roster since the 2026-08-29 gate bankruptcy,
so the site was DeclinedOutsideRequiredGate and the positive control could
never hold. The fixture now uses v2.test.some_witness, an on-gate prefix.

Co-authored-by: briansrls <briansrls@gmail.com>
…ilings

unlisted_import_use_burndown_sizing now reads SizedByAuthorityCensus /
CertifiedCount over the restored instrument: 553 modules carrying 1,648
distinct (module, name) pairs out of the 4,057-module whole-tree closure,
against the stand-in's order-only 789/2,190/4,459. The hand-check fields move
into the stand-in arm they describe, and the spent supersedes_when_reachable
and authority_census_reachability fields delete -- reachability is now
constructed by the rostered binding and witnessed, not asserted by a data arm
that could rot beside a deleted entry point.

The hand-Rust dissolve trigger is NOT retired: the census is the same
hand-Rust classification transport made reachable, so the unmodeled
binding-source debt it guards is unchanged. Its description now names the
current surface.

Two annotation corrections, both rung-honesty repairs: the module claimed both
the floor path and the standalone CLI read the enforcement row, but gunbc#8286
cut the CLI's read (its mechanism was an interpreter run to answer one Bool);
the flip's terminal shape is promotion in v1.std.core diagnostic_disposition,
which both consumers already read.

And the per-class ceiling roster for all six advisory classes the census
reports, classified by attainable ceiling rather than by count, in work order:
UnlistedImportUse and UnlistedVariantValueUse mechanically fixable now;
ServiceConfigReferenceJudgmentDeferred and MethodExistenceFrontierAdmitted
declared-admission rosters whose instances carry their own triggers;
WhereRefinementUnenforced and DeclaredTypeInhabitanceUndecided walls after
grounding, each naming the evidence capability it waits on.

Co-authored-by: briansrls <briansrls@gmail.com>
…esolve in the v1-infer partition

The UnlistedImportUse advisory exists to charge an authored reference
against the referencing module's import list. It also fired on
references whose resolved binding is a kernel-minted identity (span
<kernel:NAME>) -- synthetic formal nodes of imported generic functions
reached through the ancestry overlay, and authored occurrences of
lexically-introduced type parameters. No import-list edit can discharge
such a row: the binding does not come from the import list, and adding
one would rebind the reference rather than fix a listing gap.

The emission site in v1.compiler.infer_resolve now consults the existing
resolved_node_is_kernel_identity_for_name predicate (v1.compiler.core)
and declines to charge kernel-identity bindings. The discriminating
witness imported_generic_call_charges_no_unlisted_import_use_on_the_formal
(dag/test/claim/undeclared_bare_type_reference_class_witness_test.dag)
was RED pre-fix (one row on the kernel formal) and is GREEN post-fix.

Regenerating the infer_resolve mirror exposed that the mirror had no
owning package in the stage0 partition roster, so the priced regen round
refused the rebuild with MirrorHasNoOwningPackage. Per the #10037
precedent the module joins the v1-stage0-v1-infer partition (its imports
are v1-infer members and std-core only): authority row in
v2.workflow.rust_crate_partition, regenerated roster and mirrors, and
two enrolled witnesses -- the rebuild-scope owner flip and the
host-shell-to-partition-surface move.

Co-authored-by: briansrls <briansrls@gmail.com>
… the carve-out

The guard's measured effect on the authority census: UnlistedImportUse
4,621 -> 3,745 occurrences at 3,441 distinct positions across 542
modules (denominator unchanged at 4,057; pairs 1,648 -> 1,415). The
pre-fix carve-out under-counted the defect at 19 by measuring occurrence
SPANS; measured by resolved BINDING the undischargable population was
876. The ceiling row's repair note now records the closed carve-out, the
guard, and the enrolled discriminating witness, and the work-order
comment carries the post-guard totals (25,403 advisories across 6
classes; the class order is unchanged).

Co-authored-by: briansrls <briansrls@gmail.com>
…infer stage into the v1-infer partition

The field-access alias peel (v1.compiler.infer peel_alias_once_for_field_access)
expands an imported paramless alias's right-hand side to discover or check its
fields. It resolved that expansion with resolve_node, which enters at
masked=true, so the resolver charged the DEFINER tree's local names against the
IMPORTER's source_visible_names -- names the importer's text never wrote and
could never honestly list. The masked-boundary authority (v1.compiler.infer_resolve
resolve_node_bounded_masked_boundary) states the invariant this violated:
grounding recursions descend into defining-module structure with masked=false,
because that structure is the defining module's import responsibility, not the
use site's. The peel now calls resolve_node_bounded with masked=false; every
authored reference in its input was already charged at its own authored site, so
a masked pass here could only double-charge or mischarge. The discriminating
witness constructing_through_an_imported_alias_charges_no_unlisted_import_use_on_the_expansion
(dag/test/claim/undeclared_bare_type_reference_class_witness_test.dag) was RED
pre-fix and is GREEN post-fix.

Regenerating the infer mirror refused with MirrorHasNoOwningPackage: the
stage-04 root had no owning package in the stage0 partition roster. A generated
mirror resolves cross-module references as crate:: paths, which resolve only
within one crate root, so v1_compiler_infer can join the partition only together
with its whole monolith-owned crate-internal closure. Computed over the
generated mirrors, that closure is self-contained: the infer_* sibling stages
(access, cycle, lookup, method, patterns), v1_compiler_resolve, and
v1_compiler_ownership join v1-infer; ownership's to_string dependency pulls
v1_compiler_emit_core_support in as an owned module (its own references resolve
inside this unit); and infer_lookup's use pulls std_primitive_projection into
std-core, its proper std layer. Authority rows in
v2.workflow.rust_crate_partition, the regenerated roster, and the regenerated
crate boundaries (v1-infer, std-core, and the host shell's subtraction).

Co-authored-by: briansrls <briansrls@gmail.com>
…ord the second closed carve-out

Co-authored-by: briansrls <briansrls@gmail.com>
@cursor cursor Bot changed the title Restore the advisory census as a rostered instrument; certify the burndown sizing; record per-class ceilings Promote compile advisories toward blocking: certified UnlistedImportUse census, two emission-defect carve-outs closed Sep 9, 2026
cursoragent and others added 6 commits September 9, 2026 14:26
The import-scoped policy's gate is that a module's import list says which
qualified names are visible (namespace-resolution-design.md section 7), but
build_type_env's source_visible_names only ever carried BARE spellings, so
the resolver's leaf check fired UnlistedImportUse on every masked qualified
use -- including q.def.QFoo beside import q.def { QFoo }, a row no
import-list edit could discharge. The fold now enters each imported name
under its qualified spelling as well: selective imports qualify exactly the
listed names; is-all imports qualify the module's OWN interface names, never
ancestry names, which are not containment paths under the importing module's
target and could never resolve as <that module>.<name>. A qualified use of
an unlisted name or an unimported module still fires.

The defect's census signature: the listed-import column moved 511 -> 393
(118 occurrences) when the fix landed, while definer-resolvable (242 --
qualified uses with NO import edge, dischargeable by adding the edge, so
genuine worklist rows) and pool-coincidence (2,614) stood unchanged.

Discriminating witness
test.claim.undeclared_bare_type_reference_class_witness
qualified_use_of_a_listed_import_charges_no_unlisted_import_use was RED
pre-fix and is GREEN post-fix, beside the positive control
qualified_use_without_any_import_still_charges_unlisted_import_use (the gate
still gates).

Co-authored-by: briansrls <briansrls@gmail.com>
…authority

run_built_seed_regen compared the admitted executable digest against
path_digest's fnv1a64:-prefixed rendering, while the executable-digest
authority -- current_exe_digest, next_pass_executable_digest, and every
receipt field (producer_seed_digest, output_seed_digest) -- carries
v1_rt::bytes_identity_hash with no algorithm tag, and the .dag admission
(regen_admit_candidate_generation) string-compares that family. The check
admitted the bare form against the prefixed form from its birth in #9771,
so no staged install+rebuild+re-emit round could ever pass it: the refusal
CandidateGeneratedByDifferentSeed fired on every non-trivial convergence
with the two strings differing only by the tag. Read the same authority
here; path_digest stays for artifact surfaces.

Co-authored-by: briansrls <briansrls@gmail.com>
…ord the third closed carve-out

The census re-run on the fixed emitter reads UnlistedImportUse at 3,249
occurrences across 483 modules and 1,303 module/name pairs (from 3,367 /
501 / 1,330). The movement is exactly the listed-import column, 511 -> 393:
the 118 rows cleared are the qualified uses of import-declared names the
source_visible_names fold now credits. Definer-resolvable (242) and
pool-coincidence (2,614) stand unchanged -- those rows have no import
declaration to credit and are the genuine worklist.

The ceiling row records the third closed carve-out beside the first two,
and the work-order header carries the new totals (24,907 advisories across
6 classes).

Note: this row remains the hand-transcribed sizing the HOLD review's
finding 2 and route D address -- the mechanism rework (raw source-bound
receipt, merge-base-derived ratchet) follows separately; this commit keeps
the standing row current rather than stale in the interim.

Co-authored-by: briansrls <briansrls@gmail.com>
Integrates 56 main commits onto the three UnlistedImportUse emission-defect
fixes. Conflict resolution:

- src/v1/stage0/src/required_regen_host.rs: took main's side. Main's
  d86a32d (#10795) fixed the same executable-digest format fork this
  branch's 0580e1e addressed, unifying on the prefixed spelling with the
  current_exe_on_disk/current_exe_digest helpers; that is now the trunk
  authority and the branch commit is superseded.
- v1_compiler_infer.rs / v1_compiler_infer_resolve.rs: the generated-artifact
  merge driver left both unmerged as designed. Regenerated from the merged
  .dag authorities through the declared transaction (claim_executor
  --required-regen emit with a seed built from the merged tree) rather than
  hand-merged; the emit reported drift on exactly these two mirrors and no
  others, confirming the rest of the generated surface is identical between
  main's committed bytes and a merged-tree emission.
- bootstrap_seed_retention_frontier_generated.rs: main's 2db4494 (#10829)
  seed-retention frontier excludes this committed-but-no-longer-emitted
  mirror from adjudication; the merged seed carries that exclusion.

Co-authored-by: briansrls <briansrls@gmail.com>
…on repairs

Review finding 6 (HOLD at c7603fd): the three repair arms prove the selected
false-positive rows disappear but say nothing about the boundary each repair
must not cross. Each repair widens an exclusion; a widened exclusion that also
swallows the nearby true-positive population is the absorbing fallback (DESIGN
5) wearing a repair's clothes. Three controls hold that boundary, one per
repair, each naming the mutation it exists to red:

- authored_reference_spelled_like_a_kernel_formal_still_charges_unlisted_import_use:
  authors the synthetic formal's own spelling (N) as a real declaration and
  references it bare with no import edge. The kernel-identity guard is an
  identity test (v1.std.core resolved_node_is_kernel_identity_for_name), never
  a name test; broadening it to a spelling test silences this row.
- use_site_type_argument_through_an_imported_alias_still_charges_unlisted_import_use:
  lists a parameterized alias and applies it to an authored argument the user
  does not list. The peel's masked=false covers the definer's expansion tree;
  the use-site argument is resolved masked by the standing boundary
  (v1.compiler.infer_resolve resolve_node_bounded_masked_boundary). Setting
  masked=false one level too high silences this row.
- diagnostics_from_the_alias_expansion_still_propagate: constructs through an
  imported alias whose expansion names a type that exists nowhere, so the
  UnresolvedType row reaches the outcome only through the peel's diagnostic
  accumulation. Dropping or filtering the accumulated diagnostics greens the
  compile over a construction whose fields cannot be typed.

All nine arms of the file measured GREEN by execution on the integrated tree
(merge 4324076, regen fixed point changed_paths=0): the six pre-existing
arms plus the three controls above.

Co-authored-by: briansrls <briansrls@gmail.com>
…tomy

The first propagation control asserted UnresolvedType(UbtrGhost) > 0 over a
construction through a broken imported alias. Mutation testing showed it did
not discriminate: with the peel's diagnostic accumulation dropped entirely,
the control stayed green. Probing the fixture shape (same sources, same
entry, same count reader) established the real anatomy on the fixed tree:

- the definer module alone charges UnresolvedType(UbtrGhost) once: the
  definer's own compile resolves a paramless alias's right-hand side at
  definition time, refuting the earlier comment's claim that a paramless
  alias resolves as a leaf until a use forces the expansion;
- an import-only user adds no row (no use, no peel);
- a field access through the alias adds the second row, which reaches the
  outcome only through the peel's concat(once.diagnostics, rest.diagnostics)
  accumulation.

The control now uses the field-access shape (no constructor-path resolution
beside the peel), asserts the exact count == 2 in the FixtureCompileRefused
arm (UnresolvedType is GateBlocking, so a Completed outcome is a gate
failure, never a pass), and names both regressions it reds: dropping the
peel's accumulated diagnostics (2 -> 1, measured under the
peel-drops-diagnostics mutation) and the definer's compile ceasing to
diagnose a broken alias definition (2 -> 1 for the other reason).

Co-authored-by: briansrls <briansrls@gmail.com>
cursoragent and others added 3 commits September 9, 2026 18:35
…s-blocking-4cca

Co-authored-by: briansrls <briansrls@gmail.com>
#10692 added the ReleaseScopeEmpty decision variant on main; the
owner-flip arm enrolled by the infer_resolve partition move predates it
and no longer compiles against the merged tree (non-exhaustive match).
A release-excluded verdict for this mirror would be wrong -- the mirror
is release-visible and owned by v1-stage0-v1-infer -- so the arm answers
false, matching the sibling arms' convention. Same fix landed in the
emitter-repair split-off PR on current main.

Co-authored-by: briansrls <briansrls@gmail.com>
Answers the 2026-09-09 HOLD's census findings (1, 2, 4, 5):

- Finding 1 (false zero): the census counts every emitted diagnostic
  with no severity filter on the count path; disposition is a row
  attribute computed per instance through compile_clean_diagnostic_is_hard,
  keyed (class, disposition) so a mixed class carries one row per side.
  The wall is class-specific: raw UnlistedImportUse == 0, independent of
  its policy disposition, so promotion cannot vacate the assertion.
- Finding 2 (CertifiedCount stronger than provenance): the observation
  carries a five-digest identity block (source vector, compiler
  executable, resolver policy, class schema, closure); the source vector
  is materialized into memory, hashed, and the same bytes compiled, so
  the digest binds by construction. The policy's sizing arm renames to
  LiveDiagnosticObservation and is refreshed to the integrated-tree
  reading.
- Finding 4 (worklist identity): UnlistedImportCensusRow carries the
  occurrence's source position beside file/module/name/binding-source,
  with the comment stating what it is not (the Step 0 occurrence
  identity remains the bar for actuating edits).
- Finding 5 (open-string roster, non-incremental ratchet): the ceiling
  roster projects to class names and the producer executes the bijection
  witness -- duplicate, stale, and uncovered rows are typed refusals.
  The witness's first live run refused Uncovered on
  EffectSummaryIncompleteAtFunctionValue; both effect-summary classes
  are enrolled with WallAfterGrounding ceilings naming their missing
  effect-evidence capabilities.

Also deletes the dead compile_clean_diagnostic_is_advisory (its only
caller was the filtered census) and updates the witness arms: the wall
test now discriminates advisory-vs-blocking carriage of the walled
class, and the rendering/refusal arms assert the new vocabulary.

Co-authored-by: briansrls <briansrls@gmail.com>
@cursor cursor Bot changed the title Promote compile advisories toward blocking: certified UnlistedImportUse census, two emission-defect carve-outs closed Raw source-bound diagnostic census + UnlistedImportUse emitter-defect repairs Sep 9, 2026
cursoragent and others added 2 commits September 9, 2026 21:03
The required-ci parse phase refuses // annotations inside a declaration
body (std.source_annotation BodyGrainNotModeled: only module-item grain
is modeled). The kernel-collision control carried its refusal-arm note
inside the match; move it above the test fn it describes. The
annotation-erased projection is unchanged, so no semantic result moves;
the interpreter entry path had tolerated the body placement, which is
why local control runs stayed green while the floor lane refused.

Co-authored-by: briansrls <briansrls@gmail.com>
…vector digest, authority-derived schema

Review 2026-09-10 findings 1-4 on #10890:

1. RawDiagnosticClassObservation now carries the diagnostic authority's
   complete answer: DiagnosticCensusGateDisposition (CensusBlocking |
   CensusAdvisoryTypecheck | CensusRenderedUncounted{reason}) plus
   DiagnosticCensusSeverity as the independent axis the repository
   models. ComplexityUnknown is reported rendered-uncounted, never
   folded into advisory. Ceiling-roster coverage (Stale/Uncovered)
   scopes to CensusAdvisoryTypecheck alone.

2. Classification and provenance read ONE immutable policy snapshot:
   the policy closure vector is acquired once, canonicalized once,
   resolved once, and the UnlistedImportUse staging decision, the
   ceiling roster, and the resolver-policy digest all derive from that
   one context. The census path no longer calls the process-global
   cached policy accessor.

3. The subject source vector is canonicalized once in place and that
   exact vector feeds both the source-vector digest and
   compile_to_resolved -- the digest identifies the executed vector,
   not a canonicalization of a differently ordered one.

4. The diagnostic class schema is checked against the coproduct
   authority's own constructor census, derived parse-level from the
   v1.std.core CompilerDiagnostic declaration via
   decl_facts_corpus_walk + get_variant_names (the subject closure
   cannot carry src/v1 -- the twelve last-segment collisions). Five
   typed refusals: SchemaAuthorityAbsent, SchemaSpecimenDuplicate,
   SchemaCountMismatch, SchemaConstructorUnrepresented,
   SchemaSpecimenUnknownToAuthority. A new constructor whose author
   repaired the exhaustive matches but omitted the specimen now reds
   the census at the next run.

Co-authored-by: briansrls <briansrls@gmail.com>
@briansrls
briansrls marked this pull request as ready for review September 10, 2026 13:45
@briansrls
briansrls merged commit bfc33c9 into main Sep 10, 2026
4 checks passed
@briansrls
briansrls deleted the cursor/advisory-census-blocking-4cca branch September 10, 2026 13:45
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-10T13:55:57.203093Z 09f56ef Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 09f56ef35e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +1209 to +1210
let policy = compile_clean_diagnostic_policy_snapshot()
.map_err(CompileCleanDiagnosticCensusRefusal::PolicyUnreadable)?;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bind the policy snapshot to the compiled source snapshot

When the working tree changes during this potentially long census, this reads the policy closure now but does not materialize the whole-tree source vector until later at line 1302. Because dag/gunbc/compile_clean_diagnostic_policy.dag is itself part of that source vector, an edit between the two reads can classify diagnostics and validate the ceiling roster using policy version A while compiling and hashing source version B; the producer then returns a seemingly source-bound observation whose source_vector_digest contains a different policy than resolver_policy_digest. Derive the policy context from the already-materialized source vector, or compare the overlapping bytes and refuse/retry on mismatch.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants