Repository navigation
Raw source-bound diagnostic census + UnlistedImportUse emitter-defect repairs - #10890
Conversation
The compile-clean advisory census returns as `gunbc test //gunbc/instruments:compile-clean-advisory-census`: one entry per advisory diagnostic class over the whole-tree compile-clean closure (count, distinct modules, distinct source positions), plus the binding-source-attributed UnlistedImportUse worklist. The entry point is a rostered TargetBinding in gunbc.instrument_targets with a modeled CompileCleanAdvisoryCensusObservation in gunbc.target_binding, so the sweep that removed the unrostered bin in gunbc#9160 cannot recur. The dead `compile_clean_unlisted_import_census` wrapper deletes with it: the advisory census's unlisted_import_rows carry the same rows, and a pub fn whose only call site was its own definition is DESIGN 3c's dangling declaration. The two .dag citations of the old symbol repoint to the subsuming census, and the scaffold marker comment now names the remaining hand-Rust classification surface honestly. Also repairs a pre-existing red fixture in target_invocation_witness_test: the planned-site fixture used test.claim.some_witness, which matches no prefix in the static required_gate_prefixes roster since the 2026-08-29 gate bankruptcy, so the site was DeclinedOutsideRequiredGate and the positive control could never hold. The fixture now uses v2.test.some_witness, an on-gate prefix. Co-authored-by: briansrls <briansrls@gmail.com>
…ilings unlisted_import_use_burndown_sizing now reads SizedByAuthorityCensus / CertifiedCount over the restored instrument: 553 modules carrying 1,648 distinct (module, name) pairs out of the 4,057-module whole-tree closure, against the stand-in's order-only 789/2,190/4,459. The hand-check fields move into the stand-in arm they describe, and the spent supersedes_when_reachable and authority_census_reachability fields delete -- reachability is now constructed by the rostered binding and witnessed, not asserted by a data arm that could rot beside a deleted entry point. The hand-Rust dissolve trigger is NOT retired: the census is the same hand-Rust classification transport made reachable, so the unmodeled binding-source debt it guards is unchanged. Its description now names the current surface. Two annotation corrections, both rung-honesty repairs: the module claimed both the floor path and the standalone CLI read the enforcement row, but gunbc#8286 cut the CLI's read (its mechanism was an interpreter run to answer one Bool); the flip's terminal shape is promotion in v1.std.core diagnostic_disposition, which both consumers already read. And the per-class ceiling roster for all six advisory classes the census reports, classified by attainable ceiling rather than by count, in work order: UnlistedImportUse and UnlistedVariantValueUse mechanically fixable now; ServiceConfigReferenceJudgmentDeferred and MethodExistenceFrontierAdmitted declared-admission rosters whose instances carry their own triggers; WhereRefinementUnenforced and DeclaredTypeInhabitanceUndecided walls after grounding, each naming the evidence capability it waits on. Co-authored-by: briansrls <briansrls@gmail.com>
…esolve in the v1-infer partition The UnlistedImportUse advisory exists to charge an authored reference against the referencing module's import list. It also fired on references whose resolved binding is a kernel-minted identity (span <kernel:NAME>) -- synthetic formal nodes of imported generic functions reached through the ancestry overlay, and authored occurrences of lexically-introduced type parameters. No import-list edit can discharge such a row: the binding does not come from the import list, and adding one would rebind the reference rather than fix a listing gap. The emission site in v1.compiler.infer_resolve now consults the existing resolved_node_is_kernel_identity_for_name predicate (v1.compiler.core) and declines to charge kernel-identity bindings. The discriminating witness imported_generic_call_charges_no_unlisted_import_use_on_the_formal (dag/test/claim/undeclared_bare_type_reference_class_witness_test.dag) was RED pre-fix (one row on the kernel formal) and is GREEN post-fix. Regenerating the infer_resolve mirror exposed that the mirror had no owning package in the stage0 partition roster, so the priced regen round refused the rebuild with MirrorHasNoOwningPackage. Per the #10037 precedent the module joins the v1-stage0-v1-infer partition (its imports are v1-infer members and std-core only): authority row in v2.workflow.rust_crate_partition, regenerated roster and mirrors, and two enrolled witnesses -- the rebuild-scope owner flip and the host-shell-to-partition-surface move. Co-authored-by: briansrls <briansrls@gmail.com>
… the carve-out The guard's measured effect on the authority census: UnlistedImportUse 4,621 -> 3,745 occurrences at 3,441 distinct positions across 542 modules (denominator unchanged at 4,057; pairs 1,648 -> 1,415). The pre-fix carve-out under-counted the defect at 19 by measuring occurrence SPANS; measured by resolved BINDING the undischargable population was 876. The ceiling row's repair note now records the closed carve-out, the guard, and the enrolled discriminating witness, and the work-order comment carries the post-guard totals (25,403 advisories across 6 classes; the class order is unchanged). Co-authored-by: briansrls <briansrls@gmail.com>
…infer stage into the v1-infer partition The field-access alias peel (v1.compiler.infer peel_alias_once_for_field_access) expands an imported paramless alias's right-hand side to discover or check its fields. It resolved that expansion with resolve_node, which enters at masked=true, so the resolver charged the DEFINER tree's local names against the IMPORTER's source_visible_names -- names the importer's text never wrote and could never honestly list. The masked-boundary authority (v1.compiler.infer_resolve resolve_node_bounded_masked_boundary) states the invariant this violated: grounding recursions descend into defining-module structure with masked=false, because that structure is the defining module's import responsibility, not the use site's. The peel now calls resolve_node_bounded with masked=false; every authored reference in its input was already charged at its own authored site, so a masked pass here could only double-charge or mischarge. The discriminating witness constructing_through_an_imported_alias_charges_no_unlisted_import_use_on_the_expansion (dag/test/claim/undeclared_bare_type_reference_class_witness_test.dag) was RED pre-fix and is GREEN post-fix. Regenerating the infer mirror refused with MirrorHasNoOwningPackage: the stage-04 root had no owning package in the stage0 partition roster. A generated mirror resolves cross-module references as crate:: paths, which resolve only within one crate root, so v1_compiler_infer can join the partition only together with its whole monolith-owned crate-internal closure. Computed over the generated mirrors, that closure is self-contained: the infer_* sibling stages (access, cycle, lookup, method, patterns), v1_compiler_resolve, and v1_compiler_ownership join v1-infer; ownership's to_string dependency pulls v1_compiler_emit_core_support in as an owned module (its own references resolve inside this unit); and infer_lookup's use pulls std_primitive_projection into std-core, its proper std layer. Authority rows in v2.workflow.rust_crate_partition, the regenerated roster, and the regenerated crate boundaries (v1-infer, std-core, and the host shell's subtraction). Co-authored-by: briansrls <briansrls@gmail.com>
…ord the second closed carve-out Co-authored-by: briansrls <briansrls@gmail.com>
The import-scoped policy's gate is that a module's import list says which
qualified names are visible (namespace-resolution-design.md section 7), but
build_type_env's source_visible_names only ever carried BARE spellings, so
the resolver's leaf check fired UnlistedImportUse on every masked qualified
use -- including q.def.QFoo beside import q.def { QFoo }, a row no
import-list edit could discharge. The fold now enters each imported name
under its qualified spelling as well: selective imports qualify exactly the
listed names; is-all imports qualify the module's OWN interface names, never
ancestry names, which are not containment paths under the importing module's
target and could never resolve as <that module>.<name>. A qualified use of
an unlisted name or an unimported module still fires.
The defect's census signature: the listed-import column moved 511 -> 393
(118 occurrences) when the fix landed, while definer-resolvable (242 --
qualified uses with NO import edge, dischargeable by adding the edge, so
genuine worklist rows) and pool-coincidence (2,614) stood unchanged.
Discriminating witness
test.claim.undeclared_bare_type_reference_class_witness
qualified_use_of_a_listed_import_charges_no_unlisted_import_use was RED
pre-fix and is GREEN post-fix, beside the positive control
qualified_use_without_any_import_still_charges_unlisted_import_use (the gate
still gates).
Co-authored-by: briansrls <briansrls@gmail.com>
…authority run_built_seed_regen compared the admitted executable digest against path_digest's fnv1a64:-prefixed rendering, while the executable-digest authority -- current_exe_digest, next_pass_executable_digest, and every receipt field (producer_seed_digest, output_seed_digest) -- carries v1_rt::bytes_identity_hash with no algorithm tag, and the .dag admission (regen_admit_candidate_generation) string-compares that family. The check admitted the bare form against the prefixed form from its birth in #9771, so no staged install+rebuild+re-emit round could ever pass it: the refusal CandidateGeneratedByDifferentSeed fired on every non-trivial convergence with the two strings differing only by the tag. Read the same authority here; path_digest stays for artifact surfaces. Co-authored-by: briansrls <briansrls@gmail.com>
…ord the third closed carve-out The census re-run on the fixed emitter reads UnlistedImportUse at 3,249 occurrences across 483 modules and 1,303 module/name pairs (from 3,367 / 501 / 1,330). The movement is exactly the listed-import column, 511 -> 393: the 118 rows cleared are the qualified uses of import-declared names the source_visible_names fold now credits. Definer-resolvable (242) and pool-coincidence (2,614) stand unchanged -- those rows have no import declaration to credit and are the genuine worklist. The ceiling row records the third closed carve-out beside the first two, and the work-order header carries the new totals (24,907 advisories across 6 classes). Note: this row remains the hand-transcribed sizing the HOLD review's finding 2 and route D address -- the mechanism rework (raw source-bound receipt, merge-base-derived ratchet) follows separately; this commit keeps the standing row current rather than stale in the interim. Co-authored-by: briansrls <briansrls@gmail.com>
Integrates 56 main commits onto the three UnlistedImportUse emission-defect fixes. Conflict resolution: - src/v1/stage0/src/required_regen_host.rs: took main's side. Main's d86a32d (#10795) fixed the same executable-digest format fork this branch's 0580e1e addressed, unifying on the prefixed spelling with the current_exe_on_disk/current_exe_digest helpers; that is now the trunk authority and the branch commit is superseded. - v1_compiler_infer.rs / v1_compiler_infer_resolve.rs: the generated-artifact merge driver left both unmerged as designed. Regenerated from the merged .dag authorities through the declared transaction (claim_executor --required-regen emit with a seed built from the merged tree) rather than hand-merged; the emit reported drift on exactly these two mirrors and no others, confirming the rest of the generated surface is identical between main's committed bytes and a merged-tree emission. - bootstrap_seed_retention_frontier_generated.rs: main's 2db4494 (#10829) seed-retention frontier excludes this committed-but-no-longer-emitted mirror from adjudication; the merged seed carries that exclusion. Co-authored-by: briansrls <briansrls@gmail.com>
…on repairs Review finding 6 (HOLD at c7603fd): the three repair arms prove the selected false-positive rows disappear but say nothing about the boundary each repair must not cross. Each repair widens an exclusion; a widened exclusion that also swallows the nearby true-positive population is the absorbing fallback (DESIGN 5) wearing a repair's clothes. Three controls hold that boundary, one per repair, each naming the mutation it exists to red: - authored_reference_spelled_like_a_kernel_formal_still_charges_unlisted_import_use: authors the synthetic formal's own spelling (N) as a real declaration and references it bare with no import edge. The kernel-identity guard is an identity test (v1.std.core resolved_node_is_kernel_identity_for_name), never a name test; broadening it to a spelling test silences this row. - use_site_type_argument_through_an_imported_alias_still_charges_unlisted_import_use: lists a parameterized alias and applies it to an authored argument the user does not list. The peel's masked=false covers the definer's expansion tree; the use-site argument is resolved masked by the standing boundary (v1.compiler.infer_resolve resolve_node_bounded_masked_boundary). Setting masked=false one level too high silences this row. - diagnostics_from_the_alias_expansion_still_propagate: constructs through an imported alias whose expansion names a type that exists nowhere, so the UnresolvedType row reaches the outcome only through the peel's diagnostic accumulation. Dropping or filtering the accumulated diagnostics greens the compile over a construction whose fields cannot be typed. All nine arms of the file measured GREEN by execution on the integrated tree (merge 4324076, regen fixed point changed_paths=0): the six pre-existing arms plus the three controls above. Co-authored-by: briansrls <briansrls@gmail.com>
…tomy The first propagation control asserted UnresolvedType(UbtrGhost) > 0 over a construction through a broken imported alias. Mutation testing showed it did not discriminate: with the peel's diagnostic accumulation dropped entirely, the control stayed green. Probing the fixture shape (same sources, same entry, same count reader) established the real anatomy on the fixed tree: - the definer module alone charges UnresolvedType(UbtrGhost) once: the definer's own compile resolves a paramless alias's right-hand side at definition time, refuting the earlier comment's claim that a paramless alias resolves as a leaf until a use forces the expansion; - an import-only user adds no row (no use, no peel); - a field access through the alias adds the second row, which reaches the outcome only through the peel's concat(once.diagnostics, rest.diagnostics) accumulation. The control now uses the field-access shape (no constructor-path resolution beside the peel), asserts the exact count == 2 in the FixtureCompileRefused arm (UnresolvedType is GateBlocking, so a Completed outcome is a gate failure, never a pass), and names both regressions it reds: dropping the peel's accumulated diagnostics (2 -> 1, measured under the peel-drops-diagnostics mutation) and the definer's compile ceasing to diagnose a broken alias definition (2 -> 1 for the other reason). Co-authored-by: briansrls <briansrls@gmail.com>
…s-blocking-4cca Co-authored-by: briansrls <briansrls@gmail.com>
#10692 added the ReleaseScopeEmpty decision variant on main; the owner-flip arm enrolled by the infer_resolve partition move predates it and no longer compiles against the merged tree (non-exhaustive match). A release-excluded verdict for this mirror would be wrong -- the mirror is release-visible and owned by v1-stage0-v1-infer -- so the arm answers false, matching the sibling arms' convention. Same fix landed in the emitter-repair split-off PR on current main. Co-authored-by: briansrls <briansrls@gmail.com>
Answers the 2026-09-09 HOLD's census findings (1, 2, 4, 5): - Finding 1 (false zero): the census counts every emitted diagnostic with no severity filter on the count path; disposition is a row attribute computed per instance through compile_clean_diagnostic_is_hard, keyed (class, disposition) so a mixed class carries one row per side. The wall is class-specific: raw UnlistedImportUse == 0, independent of its policy disposition, so promotion cannot vacate the assertion. - Finding 2 (CertifiedCount stronger than provenance): the observation carries a five-digest identity block (source vector, compiler executable, resolver policy, class schema, closure); the source vector is materialized into memory, hashed, and the same bytes compiled, so the digest binds by construction. The policy's sizing arm renames to LiveDiagnosticObservation and is refreshed to the integrated-tree reading. - Finding 4 (worklist identity): UnlistedImportCensusRow carries the occurrence's source position beside file/module/name/binding-source, with the comment stating what it is not (the Step 0 occurrence identity remains the bar for actuating edits). - Finding 5 (open-string roster, non-incremental ratchet): the ceiling roster projects to class names and the producer executes the bijection witness -- duplicate, stale, and uncovered rows are typed refusals. The witness's first live run refused Uncovered on EffectSummaryIncompleteAtFunctionValue; both effect-summary classes are enrolled with WallAfterGrounding ceilings naming their missing effect-evidence capabilities. Also deletes the dead compile_clean_diagnostic_is_advisory (its only caller was the filtered census) and updates the witness arms: the wall test now discriminates advisory-vs-blocking carriage of the walled class, and the rendering/refusal arms assert the new vocabulary. Co-authored-by: briansrls <briansrls@gmail.com>
The required-ci parse phase refuses // annotations inside a declaration body (std.source_annotation BodyGrainNotModeled: only module-item grain is modeled). The kernel-collision control carried its refusal-arm note inside the match; move it above the test fn it describes. The annotation-erased projection is unchanged, so no semantic result moves; the interpreter entry path had tolerated the body placement, which is why local control runs stayed green while the floor lane refused. Co-authored-by: briansrls <briansrls@gmail.com>
…vector digest, authority-derived schema Review 2026-09-10 findings 1-4 on #10890: 1. RawDiagnosticClassObservation now carries the diagnostic authority's complete answer: DiagnosticCensusGateDisposition (CensusBlocking | CensusAdvisoryTypecheck | CensusRenderedUncounted{reason}) plus DiagnosticCensusSeverity as the independent axis the repository models. ComplexityUnknown is reported rendered-uncounted, never folded into advisory. Ceiling-roster coverage (Stale/Uncovered) scopes to CensusAdvisoryTypecheck alone. 2. Classification and provenance read ONE immutable policy snapshot: the policy closure vector is acquired once, canonicalized once, resolved once, and the UnlistedImportUse staging decision, the ceiling roster, and the resolver-policy digest all derive from that one context. The census path no longer calls the process-global cached policy accessor. 3. The subject source vector is canonicalized once in place and that exact vector feeds both the source-vector digest and compile_to_resolved -- the digest identifies the executed vector, not a canonicalization of a differently ordered one. 4. The diagnostic class schema is checked against the coproduct authority's own constructor census, derived parse-level from the v1.std.core CompilerDiagnostic declaration via decl_facts_corpus_walk + get_variant_names (the subject closure cannot carry src/v1 -- the twelve last-segment collisions). Five typed refusals: SchemaAuthorityAbsent, SchemaSpecimenDuplicate, SchemaCountMismatch, SchemaConstructorUnrepresented, SchemaSpecimenUnknownToAuthority. A new constructor whose author repaired the exhaustive matches but omitted the specimen now reds the census at the next run. Co-authored-by: briansrls <briansrls@gmail.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 09f56ef35e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| let policy = compile_clean_diagnostic_policy_snapshot() | ||
| .map_err(CompileCleanDiagnosticCensusRefusal::PolicyUnreadable)?; |
There was a problem hiding this comment.
Bind the policy snapshot to the compiled source snapshot
When the working tree changes during this potentially long census, this reads the policy closure now but does not materialize the whole-tree source vector until later at line 1302. Because dag/gunbc/compile_clean_diagnostic_policy.dag is itself part of that source vector, an edit between the two reads can classify diagnostics and validate the ceiling roster using policy version A while compiling and hashing source version B; the producer then returns a seemingly source-bound observation whose source_vector_digest contains a different policy than resolver_policy_digest. Derive the policy context from the already-materialized source vector, or compare the overlapping bytes and refuse/retry on mismatch.
Useful? React with 👍 / 👎.
Status: review-round-2 repairs landed (head
09f56ef35e), CI 4/4 green on the exact headThe four fidelity gaps from the second review are repaired. The census now carries the authority's full three-state gate disposition plus an independent severity axis, classifies and certifies from one immutable policy snapshot, hashes the exact vector handed to compilation, and derives the diagnostic-class schema from the
CompilerDiagnosticcoproduct authority instead of a manually omissible specimen roster.Round-2 findings, one by one
1. Third disposition collapsed → full gate axis + separate severity.
DiagnosticCensusGateDisposition = CensusBlocking | CensusAdvisoryTypecheck | CensusRenderedUncounted { reason: NonEmptyStr }mirrors the authority'sDiagnosticGateDisposition(src/v1/00_core.dag) one-for-one, andDiagnosticCensusSeverity = CensusSeverityError | CensusSeverityNonErroris carried as an independent axis, because the repository models severity and gate independently. Every raw class observation is keyed(class, gate, severity); a class whose instances decide differently (e.g.WhereRefinementUnenforcedby reason string) carries one row per cell rather than a fabricated class-level answer. Ceiling-roster coverage now applies specifically toCensusAdvisoryTypecheck: the roster-sideCeilingRosterStalecheck requires the specimen's gate to be advisory-typecheck, and the observed-sideCeilingRosterUncoveredcheck fires only on advisory-typecheck rows — aRenderedUncounteddiagnostic is reported as what it is and can no longer be pulled into advisory-ceiling reasoning.2. Two policy reads → one immutable
PolicySnapshot.compile_clean_diagnostic_policy_snapshot()performs one acquisition, one canonicalization, one resolve, one interpreter context, and reads both theUnlistedImportUseenforcement value and the ceiling-roster identities from that single context. Every census row and every policy-related receipt field — includingresolver_policy_digest— is derived from that one snapshot. The census path no longer calls the process-global cached accessor (compile_clean_unlisted_import_use_blocks_cached); the digest now identifies the exact policy bytes that classified the census.3. Digest identifies the executed vector. Subject sources are acquired once and canonicalized once (sorted by path, in place); that exact vector is handed to both
source_vector_digestandcompile_to_resolved. The digest identifies the executed vector, not a canonicalized proxy of it — no weakenedcanonical_source_set_digestprose needed.4. Manually omissible specimen roster → authority-derived constructor census.
compiler_diagnostic_constructor_census()derives the constructor set from the coproduct authority itself: a corpus walk oversrc/v1locates thev1.std.core.CompilerDiagnosticdeclaration (exactly oneDisjtype item; zero or two declarations refuseDiagnosticCensusSchemaAuthorityAbsent) and reads its variant names structurally. Four executable checks, all evaluated before the expensive whole-tree compile: specimen class identities unique (duplicate insertion refusesDiagnosticCensusSchemaSpecimenDuplicate— a string-keyed overwrite cannot hide non-injectivity); specimen count equals the authority constructor count (DiagnosticCensusSchemaCountMismatch); every authority constructor represented by a specimen (DiagnosticCensusSchemaConstructorUnrepresented); every specimen known to the authority (DiagnosticCensusSchemaSpecimenUnknownToAuthority). A newCompilerDiagnosticconstructor now refuses the census until it joins the schema.Design discovery worth recording: the authority cannot ride inside the census's whole-tree subject closure —
witness_layer_roots = ["dag", "src/v2"](dag/gunbc/ci/ci_layer_roots.dag), and admittingsrc/v1would rebind twelve last-segment module collisions documented there. The constructor census is therefore derived at parse level from the authority's source, not from the compiled graph.Mutation battery (all discriminating)
refused: two schema specimens project one class identity: UnresolvedImport(pre-compile)refused: ... specimen=58 authority=59count mismatch (pre-compile)CeilingRosterDuplicate: UnlistedVariantValueUseCeilingRosterStale: UnresolvedImportUnlistedImportUsetoEnforced, keep roster rowCeilingRosterStale: UnlistedImportUse(fast)Enforced, remove roster rowUnlistedImportUse gate=blocking severity=non-error diagnostics=3259;raw_diagnostics=25846andunlisted_import_use_raw=3259unchanged — promotion changes the attribute, never the countCeilingRosterUncovered: UnlistedVariantValueUse(full run)compile-clean-diagnostic-census: refused: disposition policy or ceiling roster unreadable: ... no declaration named 'compile_clean_unlisted_import_use_blocks', exit 2 (pre-compile)Policy-unreadable is thus refused at two layers — the module index for unparseable sources, the census's own
PolicyUnreadablearm for a parseable-but-unreadable policy — and neither arm can report zero.Verification on
09f56ef35erequired-witnesses-build,required-witnesses-floor,heal-generated-artifacts, and the aggregating requiredwitnessescontext.cargo clippy --all-targets -- -D warningsandcargo fmt --checkgreen.changed_paths=0, exit 0.phases_run=3 phases_failed=0, exit 0.CensusRenderedUncounted, flip the wall.DidNotHold, as armed.Receipt (head
09f56ef35e)17 (class, gate, severity) rows; conservation checked by the producer (per-class counts sum to the raw vector length); detail-count law checked (
UnlistedImportUseclass count == worklist row count). The independent axes are visible in the rows themselves, e.g.DeclaredTypeInhabitanceUndecided gate=advisory-typecheck severity=error— an error-severity class under an advisory gate. No live class currently occupiesrendered-uncounted(ComplexityUnknownhas zero instances in today's corpus), so the third state is proven by the schema digest covering all 59 authority constructors and by the wall test'sCensusRenderedUncountedarm, not by a population row.Remaining step (sequencing, not correctness)
Per the required landing order, once #10906 lands this branch will be refreshed from the new
main, the duplicated emitter repairs and their already-landed witnesses stripped from the authored diff, and generated output regenerated rather than hand-resolved — leaving this PR as the census/ratchet program only.What this branch carries (round-1 description, still accurate)
A. Emitter-defect repairs (earlier commits, shared with #10906): the kernel-identity guard, the field-access alias peel grounded with
masked: false, and the qualified-spelling visibility fold — each with paired false-positive and false-negative controls, each with its discriminating witness enrolled RED-pre/GREEN-post.B. The census: a severity-independent raw diagnostic census. The 3,367-row import-edit sweep was not started.
Round-1 finding-by-finding
1. False zero → repaired by construction. Every emitted diagnostic is counted with no severity filter anywhere on the count path. The wall is class-specific and severity-independent:
unlisted_import_use_raw == 0over the unfiltered population.2. CertifiedCount → LiveDiagnosticObservation + identity block. The observation carries five digests: source-vector, compiler-executable, resolver-policy, diagnostic-class-schema, closure. The policy's sizing arm is renamed
LiveDiagnosticObservation(notCertifiedCount).3. No AddImport sweep. The policy rows for both import-list classes are
WallAfterGroundingon the Step 0 binding-provenance census, with the no-default-AddImport rule stated in the row text. Binding-source partition: 229 definer-resolvable, 2,607 pool-coincidence, 406 listed-import, 17 ambiguous-leaf.4. Worklist identity.
UnlistedImportCensusRowcarriespositionbeside file/module/name/binding-source, sorted by (file, position); the row comment states this is not the Step 0 occurrence identity that must precede any actuated edit.5. Open-string roster → executed bijection witness. The ceiling roster projects to class names; the producer refuses
CeilingRosterDuplicate/CeilingRosterStale/CeilingRosterUncovered, now scoped to the advisory-typecheck gate per round-2 finding 1.Explicitly out of scope
Known limitation (pre-existing)
For diagnostics emitted with
no_span()(e.g. the effect-summary classes),distinct_positionscollapses to 1 because<synthetic>:0is one position;distinct_modulesremains the honest diffuseness signal for those classes. The walled class carries real spans (3,258 distinct positions over 3,259 rows).