Skip to content

v2-native route: closure-scoped ingest and native adjudication over a seed-prepared artifact (lands after #10990) - #10940

Merged
gunbai-bot[bot] merged 158 commits into
mainfrom
session/deep-swift-530
Sep 12, 2026
Merged

gunbai-bot[bot] merged 158 commits into
mainfrom
session/deep-swift-530

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

What this changes

The --v2-native-route instrument (operator-invoked since #11003) now derives its test universe, ingests only that universe's import closure, and adjudicates the receipt (native_route_admission) inside the emitted native compiler. The seed does one genesis emit plus cargo build, and after that it is never the miss path (C1).

This is not "interpreter-free end to end". The compiler artifact is still prepared by the seed. What this PR claims is native adjudication over a seed-prepared artifact, and the title says that.

Lands after #10990 (emitter walls). That PR's head is merged under this branch, so after it lands this diff is the route alone.

Closure-scoped ingest (the root fix)

  • Discovery still scans every corpus source textually, because a test-marked declaration outside a sidecar must still be found. The front end (tokenize, parse, normalize) is given only the transitive import closure of the universe's modules plus the live-control module.
  • The route checks the ingest receipt's identity join itself: every ingested source declares a closure module, and every closure module that some source declares was ingested. A mismatch refuses with INGEST-CLOSURE-REFUSED. The universe_derivation cost row reports scanned_paths and ingested_paths separately.
  • The closure walk's budget (native_lane_closure_round_budget, a policy budget on import depth) refuses the whole derivation when it runs out (native_lane_closure_budget_exhausted: budget, unexpanded frontier size, first module). It never returns a truncated closure. RED control: an_exhausted_closure_budget_refuses_the_derivation. Boundary: a_closure_finishing_on_its_last_round_is_accepted.

Namespace wave

There are 175 TargetChanged admission rows, one per exact identity, for four module splits: native_test_vocabulary, compile_door_cause_ownership, floor_discovery_source_authority and floor_discovery_row. Each spelling still denotes the same declaration, now in its new home. Dissolve-on: this PR merging. Main's #10956 row was consumed and is deleted here (the twenty-first dissolution).

Cost

Every build-by-appending accumulator in the derivation goes through list_snoc_item (review 63719, DESIGN §6).

Known remaining cost-shape item: the closure walk and the ingest join test membership with contains over List<String>, which is O(n·m) over about 5.4k modules. The fix is a keyed set realization in the native lane. It is named here so it is not silently skipped.

One cost partition, not two (merge with #11060)

Main landed #11060 (a typed [native-cost-partition]: NativeDriverExclusiveRows + native_driver_cost_account in std.compiler_entry) while this branch carried its own hand-rolled cost_partition_line over the same emitted function. Two emitters of one fact is the meaning fork DESIGN §3 forbids, so the merge collapses them into the typed law rather than keeping both.

The two drivers genuinely differ in shape: #11060's is given a universe.tsv, this route derives its universe, so this route pays two phases the other cannot have. The row set is therefore extended additively with universe_derivation (which carries scanned_paths vs ingested_paths — the receipt closure-scoped ingest is judged by) and receipt_admission. Both are members of the same exclusive sum, so:

  • a driver handed its universe reports zero for them and the sum and tolerance verdict are unchanged — the extension cannot alter Native driver typed [native-cost-partition] instrument #11060's own accounting;
  • an over-attribution routed through either new row is caught by native_driver_cost_account itself, not by a second check.

Controls, in test.claim.native_driver_cost_partition: an_over_attribution_routed_through_universe_derivation_is_the_same_refusal and its receipt_admission twin are each discriminating — with the row dropped from the fold the remaining rows sum to 50 against a parent of 100 and the call reconciles, so each probe fails exactly when its own row is missing from native_driver_exclusive_sum. a_driver_handed_its_universe_reconciles_with_the_phases_it_does_not_have_at_zero and a_driver_that_derives_its_universe_reconciles_over_the_same_law hold both shapes against the one law. The docstring that previously spelled the grain out in prose now names the row set as the grain, so adding a phase cannot leave a stale list behind.

The driver's remainder_nanos is the residual the accounting returns, never parent.saturating_sub(sum): on the over-attributed arm it is null, because there is no remainder to report there. The terminal marker's phase_wall_nanos block is deleted — it restated the partition's own numbers and nothing read it.

Not done here, and deliberately: making the non-Reconciled arms fail the driver, and folding [native-prepare] into [native-prepare-split] (review 63891) are a separate item off main.

The five-minute wall is unreachable, and the measurement corrected why

Measured at full N on this branch (srv1, cgroup-bound; posted in full on #11024): wall 4736 s over 3544 identities. Five minutes is 300 s, so the wall stands — but not for the reason this section previously gave, and the correction matters more than the number.

row seconds share
prepare 2772.8 58.5%
context 1733.3 36.6%
universe_derivation 139.6 2.9%
receipt_admission 90.1 1.9%
eval 0.2 0.004%
load 0.1 —

Prepare is already once per unique MODULE, not per identity. 709 modules carry 3544 identities (5.0 each) at 3.91 s mean, and 709 × 3.91 s accounts for the whole prepare row. The earlier "~5 s per identity → hours of sequential prepare" reading was an artifact of #11024's baseline sampling 32 identities that each happened to sit in a distinct module, which makes per-module and per-identity indistinguishable. Measured prepare is 46 min, not the projected 5.75 h. So C4's remaining win is not deduplicating identities within a module — that factor is already collected — but sharing resolve/infer across modules with overlapping import closures.

Context did drop, and the population is the evidence for it, not the clock. scanned_paths 5437 vs ingested_paths 2154: the front end is handed 40% of what discovery scans. The context term moved from 3808–4205 s to 1733 s, a ratio of 0.41–0.46 against an ingest ratio of 0.396 — consistent, and reported as corroboration only, because that baseline ran on srv2 under load and this ran on srv1. Cross-machine walls are not a speedup claim.

The partition did not reconcile, and is reported as failing. Verdict NativeDriverCostRemainderExceedsTolerance: 158.6 ms unattributed against the 50 ms tolerance. That is 0.003% of the wall, but the tolerance is absolute, so this receipt is not a partition and is not called one. Per-identity row serialization sits outside the eval span, which is the likeliest home — the same unattributed region review 63891 names.

Evidence

  • Required floor at 8ae6fac (run 34573949372): FloorClean on claims. Adjudication refused on 5 unadjudicated deltas, which are admitted here by identity.
  • Phase rows: posted on Per-phase [cost-partition] receipts for the required-v2-native run #11024 (comment 5640437664), full N=3544. N=1/N=32 is not the instrument on this head and no N knob was added for it: Native driver typed [native-cost-partition] instrument #11060's baseline took N by subsetting rows of a universe.tsv argument, and this driver derives its universe internally, so one full-N run is strictly more informative and yields both receipts at once.
  • file_refusal composition: posted here (comment 5641175405). ADMITTED, universe 3544, population 3544, file_refusals 790, the tally summing to exactly 790 across 6 of 14 rostered fatal causes. 94.6% are one cause — parse_g0_tokens_remain, lane MigrationOwned, 747 files — with the remaining 43 on the shared self-host critical path. fierce-lark's ruling (every surviving refusal must be a file the universe transitively imports) holds by construction: the front end is handed closure_ingest and nothing else, so a path outside the closure is never tokenized and cannot refuse.
  • Known limitation of the instrument, not the route: the [native-prepare] line reports 596/709 modules refused, which must not be read as "84% of modules fail to prepare". It keys on the NativeLaneModuleRowsDecided arm, entered either when the module's file already refused in the front end or when prepare rejects, so it conflates two causes and overlaps the 790 file refusals rather than being independent of them. Splitting it is follow-up.
  • The measurement is evidence for the body and the profile work. It is not the landing account; see below.

How this landed, and what it left broken

This did not land through the gate the section above describes. That text is superseded and is kept only because the measurements in it are still the measurements.

Landed under an explicit operator exception for the frozen head ef4a21ba, merged at 22:45:52Z, with the standing understanding that a test red would be admin-merged and fixed forward. Nothing on the merge path consumes --v2-native-route, which is why landing it broken was admissible.

The route was broken on main from this merge until #11216. The emitted driver refused at its own build — error: value assigned to module_prepare_nanos is never read, fatal under RUSTFLAGS="-D warnings" — so claim_executor --v2-native-route could not run on 6c7b0819. #11216 (5f18d9f2) restores it. The defect arrived with this PR's per-arm repair of the preparation span and was not caught here because the test that guards that driver asserts on its source text and never compiles it; the only consumer that compiles it is a route run.

Acceptance obligations moved post-landing rather than being discharged here: SUCC6 on the successor head, the closure capture (done), and the BASELINE4 identity-row join that supplies main's side of the five-cell comparison. BASELINE3 produced no rows artifact — main's runner parses the child's stdout and drops it on a non-zero exit — so the baseline had to be re-run against a branch carrying a persisting tee.

🤖 Generated with Claude Code

https://claude.ai/code/session_01BwUh3dg6xfnDGy4PoikpUV

cursoragent and others added 30 commits September 6, 2026 16:29
…pected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…nd-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ntract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…aration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…osition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
… membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ess for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…rounding-frontier-3100

# Conflicts:
#	dag/gunbc/guarantee_stall/roster.dag
#	src/v2/compiler/self_host/candidate_generation_stage_verdicts.dag
#	src/v2/test/claim/execution/self_host_candidate_generation_stage_verdicts_test.dag
#	src/v2/workflow/floor_expected_red.dag
…fication

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.
Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).
…ct witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.
…ling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.
… -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).
…rsions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).
…nsus at 6676531

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b, 72 -> 28) and the twelve-error source cluster (6676531,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.
Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).
…s at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.
The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.
… closure's cargo census is empty

Measured at 5ee4892 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.
Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md
…e rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).
The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.
A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.
The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.
The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.
…d realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.
The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
briansrls pushed a commit that referenced this pull request Sep 12, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
…derived

Fifth merge of the cut (toll now 29+26+3+28+3). Mirrors re-booted from current
main with the two-site grammar patch, and the parser mirror re-derived by
replaying the emitter's delta -- the replay CI's regen phase already confirmed
byte-correct on the previous head. Zero "func" literals remain in the parser.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NQnvBvFGNu9tNL544NJe2j
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
…escription

The required floor refused `namespace-wave-admission` on this branch with
0 unadjudicated deltas, 0 stale admissions and 181 CONSUMED admissions
due for correction or deletion.

THEIR OWN TRIGGER FIRED, CHECKED BY IDENTITY RATHER THAN INFERRED FROM
THE REFUSAL. The block above them authored `DISSOLVE-ON: this PR merging,
after which the base binds these spellings to exactly these targets and
the rows read as consumed`. #10940 merged as 6c7b081, verified with
`git log --oneline 6c7b081` before this was written -- so the base
carries the four module splits, the deltas stopped being producible, and
every one of the 181 reported `already satisfied at the base -- consumed
by its own merge`. That is the trigger discharging the debt, not a wall
being tidied for convenience; the THIRTY-SIXTH entry in this file records
why that distinction matters and the same discipline is applied here.

THE PARTITION, so a count does not stand for a population nobody
enumerated: all 181 carry a `v2-native-route ` label prefix -- 175
`module split` rows over the four moved authorities and 6 `policy split`
rows for `repo_self_warning_denial` / `_rustflags`. Main's roster held
exactly these and nothing else, so the array now carries only this
change's own two rows.

The four paragraphs that described the deleted rows go with them, as the
THIRTY-FIFTH entry's precedent requires. Audited: `git diff origin/main`
on this file deletes 37 doc lines and all 37 are that description -- no
unrelated receipt is touched.

Recorded as the THIRTY-SEVENTH DISSOLUTION.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M5dKcSuYW3nvAjtVcDxqhT
gunbai-bot Bot added a commit that referenced this pull request Sep 13, 2026
…11216)

main's emitted driver refuses at its own build:

  V2-NATIVE REFUSAL cause=EmittedCompilerBuildFailed — Completed status=101
  error: value assigned to `module_prepare_nanos` is never read
  could not compile `gunbc-emitted-closure-src-v2-compiler-00-compile-dag`
  (RUSTFLAGS="-D warnings")

Observed independently four times: SUCC5 and the closure capture on srv2, and two
compile-proof route runs on srv1. Nothing on the merge path consumes the route,
which is why #10940 landed with this standing; this PR restores it.

WHERE IT CAME FROM. #10940 closed the preparation span per arm so prepare would
stop containing the module's eval intervals -- a real defect, observed as
NativeDriverCostOverAttributed with the exclusive sum exceeding the parent by the
size of eval. Each arm assigned an outer `let mut module_prepare_nanos: u128 = 0;`.
Every path assigns before any read, so the initialiser is a dead store, and the
emitted crate is built under -D warnings where a dead store is an error.

THE REPAIR: the close is the ARM'S VALUE.

  let (outcome_label, module_prepare_nanos) = match &*resolution {
      ..ContextRowsDecided { rows } => { let this_prepare = span_nanos(prepare_started); ..; ("context_refused", this_prepare) }
      ..ResolveRowsDecided { rows } => { let this_prepare = span_nanos(prepare_started); ..; ("resolve_refused", this_prepare) }
      ..Resolved { resolved }       => { ..; let this_prepare = span_nanos(prepare_started); match &*preparation { .. } }
  };

There is no outer binding to overwrite and nothing dead to warn on. No
allow(unused_assignments) and no warning downgrade: a toggle whose only effect is
to proceed as if the refusal had not fired is the escape hatch DESIGN section 5
forbids, and this refusal was correct -- the dead store was real.

The exclusivity #10940 established is unchanged. Every close still precedes the
evaluation loop, so prepare never contains its module's eval intervals.

THE CONTROL now asserts exactly THREE closes, one per arm, and that the last
precedes where evaluation opens. The count is load-bearing: collapsing the arms
back onto one outer assignment reds on the count before it reds on the order.

WHY THE CONTROL COULD NOT CATCH THIS. It reads the emitted driver's SOURCE TEXT
and cannot establish that the text compiles; the only consumer that compiles it is
a route run (gunbc.source_root_eval_driver_seed_growth names that boundary). Two
questions, two instruments -- which is why this PR's receipt is a route run's own
build line rather than a green test.


Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Sep 13, 2026
Two review findings on #10970 (review 64883), both real.

1. THE PROVENANCE PROBE RACED. `the_loader_reads_the_revision_not_the_worktree`
   mutated the process cwd while the other two tests in the binary ran on other
   threads, and `workspace_root()` is a OnceLock seeded from the cwd on first
   use -- so whichever test called it first during the chdir window decided
   every test's colour. The probe this PR exists to add was nondeterministic in
   both directions.

   The loader now takes the repository explicitly at every git site --
   git_capture, blob_id_at, materialize_dag_tree_at, load_parse_environment_at,
   environment_agreement, kernel_set_serves_both -- the convention
   git_stdout(&workspace, ..) already uses in the same gate. The two production
   callers pass &workspace; the test passes the scratch repo and no longer
   touches the cwd. That also closes the production-side coupling the review
   named: the new git calls had read whatever cwd the binary was launched in
   while every other git call in run_required_wave_admission read workspace.

   The materialization DESTINATION deliberately stays under workspace_root()/
   target rather than under the repository being read: the resolver refuses
   paths outside the workspace root, which is the refusal this probe caught
   earlier. Only the git reads move.

2. Two refusal strings carried ~22-space runs mid-sentence (a triple-quoted
   insert kept its continuation indent, then rustfmt joined the lines). These
   are the messages a stopped line prints; collapsed.

ALSO PAID: the post-#10940 merge brought #10940's 181 `v2-native-route policy
split` admission rows into this roster, and the required floor on this head
reported every one as CONSUMED -- #10940 is at the base, its targets are where
the base authors them, the deltas have stopped being producible. This change
touches the roster, so the deletion is due here; thirty-seventh dissolution
recorded, roster empty.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPx1Ayuz3Co5ktU1uw8fti
briansrls pushed a commit that referenced this pull request Sep 13, 2026
Freeze released (#10940 landed). Merge commit rather than rebase, per the merge policy.

Preconditions checked against this exact main tip rather than assumed: this branch does not
touch src/v1/stage0/src/namespace_wave_admission.rs, so fierce-lark's take-main's-file rule
does not apply here; and no file changed on this branch is also changed on main since the
branch point, so the merge carries no content conflict to resolve.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
gunbai-bot Bot pushed a commit that referenced this pull request Sep 13, 2026
…be isolated

TWO RULES, THREE ENUMERATED. Review 64962 caught the preamble announcing two
rules and then listing FIRST, SECOND and THIRD. I introduced that when the
pipe-status rule went in as SECOND and the path-addressed-binary rule slid to
THIRD without the header moving. The reviewer's point about WHICH rule got
miscounted is the part worth keeping: it is the path-addressed-binary rule, the
one step 7's own verification says readers miss. On a page whose exit is a
stranger following it unaided, a header that undercounts its own rules is the
kind of defect that costs exactly the rule it drops. Header now says three, and
the stranger count beside it moves from two to three, which is also now correct.

AND A ROW FROM AN ATTEMPT THAT FAILED. I tried to upgrade step 5's remedy from
UNTESTED by running one of the two failing witnesses directly rather than paying
for the twenty-five minute lane. It did not reach the subject: the direct runner
executes claims HERMETICALLY with effects mocked, and these witnesses are WET --
they shell out, build a crate and run the binary they built. What came back was
a refusal naming itself a route gap and saying the claim never reached its
subject.

SO THE REMEDY IS STILL UNTESTED AND THE PAGE STILL SAYS SO. What the attempt DID
establish is a finding a newcomer will hit for certain, because isolating one
failing witness is the first thing anyone does: the direct runner cannot exercise
a wet witness at all, and its refusal is a non-verdict rather than a failing
claim. Reading it as a failing claim sends you to debug a witness that never ran.
The refusal is honest about this -- it says route gap in as many words -- so the
row's job is to tell a reader to believe it.

The consequence for step 5 is the unwelcome one and the page states it: the
twenty-five minute lane IS the instrument, isolation is not available, and that
is why the page asks you to qualify the host and read the refusal carefully
BEFORE spending the run rather than after.

17/17 witnesses PASS on post-#10940 main.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015jgT1w3Swh75GVat63TVN6
gunbai-bot Bot pushed a commit that referenced this pull request Sep 13, 2026
Remerged at eager-raven-113's request so this PR can land first: its
deletion of #10940's consumed relocation rows is what reds
`namespace-wave-admission` on every open PR's floor.

The merge itself was clean -- main's roster rows and this branch's
deletion of them do not textually collide -- so the take-main's-file-whole
procedure had nothing to resolve, and the audit was re-run rather than
assumed: `git diff origin/main` on that file deletes 37 doc lines, all 37
the description of the deleted rows, and NOTHING outside the deleted row
bodies. Main carries 182 label lines, the merged tree carries 3 (this
change's two rows plus the struct field).

ONE CORRECTION TO THE SEQUENCING NOTE, measured rather than argued: the
consumed population is 181 rows, not 179 -- 175 `v2-native-route module
split` and 6 `v2-native-route policy split`, which is what the floor
enumerated as CONSUMED and what this deletion removes.

NOTE FOR ANYONE READING THIS CLONE'S HISTORY: the first remerge attempt
refused with `fatal: refusing to merge unrelated histories`, and
`git merge-base` was empty. That is NOT a rewritten main. This clone had
gone SHALLOW (`.git/shallow`, `git rev-list --count origin/main` = 5), so
every ancestry answer it gave was an artifact of the graft.
`git fetch --unshallow` restored 12,991 commits and the merge base
resolved to 6c7b081 -- #10940 -- exactly as expected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M5dKcSuYW3nvAjtVcDxqhT
briansrls pushed a commit that referenced this pull request Sep 13, 2026
Both sides recorded the thirty-seventh dissolution of #10940's rows; main's
record is kept. Main's two #11156 rows are dissolved as the thirty-eighth:
#11156 is an ancestor of origin/main (checked by identity), their own trigger
has fired, and this change touches the roster. Their admission arguments go
with them, per the rule the thirty-seventh dissolution itself states.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPx1Ayuz3Co5ktU1uw8fti
gunbai-bot Bot pushed a commit that referenced this pull request Sep 13, 2026
…it does not adjudicate it

bright-boar-435 flagged that specimen 2 does not meet
`condition_authored_before_enqueue`. I measured both specimens from
commit history rather than from PR creation dates, and BOTH fail:

  #10940 merged 2026-09-12T22:45:52Z; its deletion authored a5bc810 at
  2026-09-12T23:55:07Z  -- 1h09m AFTER the carrier merged.

  #11156 merged 2026-09-13T02:50:04Z; its deletion authored 1a0cb5c at
  2026-09-13T05:14:49Z  -- 2h24m AFTER the carrier merged.

Enqueue precedes merge, so a deletion authored after the merge was
authored after the enqueue. The row said "Both conditions met." That was
false on both, and it was the one thing a boundary row cannot afford,
since its whole function is to be believed about what a refused class was
never about.

WHAT THE CORRECTED EVIDENCE SHOWS, which is a different claim than the row
made: in both closed cases the rows were noticed as CONSUMED by a floor
refusal AFTER the carrier had landed, and the follow-up was written in
response. That is exactly the practice condition one exists to end. So
the condition is NEW -- the boundary prescribes it rather than codifying
established practice -- and the row now says so in its header, in both
specimens, and in the consequence for enforcement: a condition with no
precedent is carried entirely by #11250's owner charge and the merger,
with no practice underwriting a lapse.

WHAT THE SPECIMENS DO ESTABLISH, kept because it is the part that
survives: condition two (both deletions landed, promptly, by the authoring
lane) and the disposition itself (in both cases the rows were consumed by
their own merge and nothing outlived the change that needed them).

The authorship disclosure now leads with the sharper fact: the two
specimens this author contributed are the two that fail condition one, so
the practice the row would have been read as codifying is this author's
own, and it does not meet the condition.

Volunteered before the verdict rather than conceded after it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M5dKcSuYW3nvAjtVcDxqhT
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant