Repository navigation
Converge #10882 to a candidate head H: render the swallowed cargo diagnostic (cargo_verdict_summary), merge current main, regenerate to fixed point, correct the PR body's enrolment claim, get exact-head CI green - #10962
Conversation
…pected_red note's producer The add-slice roster note in v2.workflow.floor_expected_red carried a dated receipt (main 3a8344b: infer accepts dag_add_emitted_root; the infer-then-translate composition refuses headed by infer_grounding_not_derived) and named its own next-rung trigger: a .dag entry returning the per-stage verdicts for one root, so the paragraph can name a producer instead of a commit. v2.compiler.self_host.candidate_generation_stage_verdicts is that entry, parameterized over root and target: the receipt's verdict vocabulary (infer_accepted / infer_rejected; candidate_accepted or the rejection head reason) plus the carried-reasons lists -- the half the verdict symbols cannot say, namely that infer accepts while carrying the frontier diagnostic on its accepted path, so the enrolled witness's d == None conjunct fails even where the composition reaches acceptance. v2.test.execution.self_host_candidate_generation_stage_verdicts binds the instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the runnable gunbc run --function form (ExitSuccess only when infer accepts clean and the composition accepts clean). Two witnesses: infer-accepts as a permanent positive control, and the frontier-state pin that is expected to red the day the add-slice stall's trigger lands, flipping to a permanent regression control in the same change that removes the roster row (DESIGN 4b(4)). Measured by execution on this branch: the entry exits 1 printing infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10], composition=infer_grounding_not_derived, composition_carried=[x11] -- the receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both witnesses PASS; the enrolled semantic witness still fails as enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…nd-to-end infer gains the declared-inhabitant membership derivation: a node declared in the dag language authority's declared-inhabitants roster derives its grounding by lookup, with the roster as evidence -- the namespacing answer to the atom authority question, at specimen scope. The add slice's ten type-spine nodes (Arrow, Conj, Atom) are all roster members, so: - candidate_generation_translate_self_emit_dag_add_slice_holds passes; its floor_expected_red roster row and per-row note delete per the roster's own stale-quarantine arm - the dag same-language ingest path compiles end-to-end: cross_language_compile accepts, byte-equal to the authority's own serialization, no carried diagnostics - the add-slice stall narrows to its four python/typescript round-trip members; the original trigger's causal clause was refuted by execution and is restated against the grammar parse-product population - the instrument's frontier guard flips to add_slice_composition_accepts_holds (DESIGN 4b(4): frontier guard to permanent regression control) - five manual witnesses flip with it: two root flips rewritten to assert the green state, three transitive conjunctions updated The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry GroundingNotDerived exactly as before, and all fourteen enrolled refusal/acceptance controls pass unchanged. The door's production path still reds inside rust emission, untouched by this rule. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…joins binding to inhabitant once The resolver already binds the surface spelling Int to the canonical binding symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts lookup re-authored that join (dag_add_canonical_grounding_for, record_construct_canonical_grounding_for). The language authority now declares it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom whose identity is a canonical dag binding with a declared denotation derives with that denotation as its grounding evidence. Direct-rust-door specimen census: 14 underived -> 10 underived (the four dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms, bare operand atoms, and the arrow/conj spine stay on the frontier unchanged). Specimen-scope interim in the same frame as infer_node_declared_in_dag_inhabitants: both delete in favor of consuming resolution output when the resolver hands infer declaration-resolved identities directly (the namespace migration's completed state). Witness: v2.test.execution.dag_binding_denotation — all four Int binding atoms in the door specimen derive with dag_int_inhabitant_node() as structural evidence, and the two bare operand atoms stay GroundingNotDerived (boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice instruments 2/2 green; every remaining red in the at-risk population reproduces identically on the pre-change tree and is enrolled in floor_expected_red. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ntract A point-in-time orientation that defers to the existing authorities (DESIGN section 7, the four-wave self-host program, the roadmap node chain, the three frontier carriers, the guarantee-stall roster, XL-N) rather than restating them: state is re-derived by the named instruments, never transcribed here. Sequences the remaining work in roadmap order (door, parse-product grounding, first behavioral module, XL-N milestones, native bootstrap, fixed point, v1 deletion) and states which decisions stay operator-gated. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
The sixth and seventh kind rules: a non-roster Conj or Arrow whose every child carries DerivedGrounding derives, its evidence the same shape re-formed over the children's grounding evidence (a fresh OccurrenceSynthetic node, never the source — the self-evidence wall holds by construction). A product with any frontier or absent child stays on the frontier with its typed diagnostic; a childless product has no evidence to compose and stays frontier. Roster members keep their roster evidence. Measured on the direct-rust-door specimen (scratch probe, uncommitted): 10 underived of 15 -> 6. The parameter conj, the module-structure conjs, and the bodied add arrow derive; what remains is the algebra atoms from the + operation (AlgebraPrimitive, ring_field_add), the module atom (dag_surface_module), the parameter references (x, y), and the grammar-projection root conj that cascades once they land. Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag): - product_introduction_derives_fully_evidenced_products_holds — census: 4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived). - product_introduction_composed_evidence_carries_child_groundings_holds — the params conj's evidence is a Conj whose x/y children target the dag authority's Int inhabitant. - product_introduction_leaves_childless_conj_on_the_frontier_holds — boundary control via direct infer over a hand-built childless Conj. Flip census (pre- and post-change, zero unexpected flips): translate_underived_refusal 14/14, infer_self_grounding_wall 12/12, branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6, ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4, inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14, dag_binding_denotation 2/2, stage-verdicts instrument 2/2, dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…roster membership Two more specimen-scope derivations in infer_node_facts, both lookups into declared authorities, never inventions: - Canonical-operations roster (target_model.dag): every CanonicalOperation the target-model authority declares, rendered by target_model_canonical_operation_wire_node and gathered under one Conj root. The resolver canonicalizes surface operators (e.g. +) to those declared operations, so the wire atoms -- the operation discriminant and its field references -- derive by membership with the roster root as evidence. General over all 14 declared operations, not add-narrow. - Grammar-productions roster (dag.dag): every production in dag_grammar_root() projected to its emitted surface atom under one Conj root keyed by production name. The bridge projects a production's parse into (identity atom, captured content) pairs, so the identity atom (dag_surface_module) derives by membership with the roster root as evidence. The roster derives from the grammar root, so a production added to the grammar joins by construction. Both roster roots are Conj nodes, never structurally equal to any member atom, so the self-evidence wall holds by construction (the first attempt at the operations rule used the wire node itself as evidence and was refused by grounding_evidence_is_source -- the wall doing its work). Measured on the direct-rust-door specimen (scratch probe, uncommitted): 6 underived of 15 -> 2 (only the operand atoms x and y remain; the grammar-projection root conj cascades once the module atom grounds). Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule pins derivation + evidence identity + census; a boundary control pins that a bare atom with no authority membership stays frontier; the closing control pins the 2-of-15 state. Flip census: the product-introduction census witness updates 3->4 derived conjs (the top conj now cascades) and gains a hand-built partially-evidenced boundary control to replace the in-specimen one the cascade consumed. Full battery otherwise unchanged: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips, bridge, cross-language, neutralization, emit-host all green; enrolled reds unchanged. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…aration The fifth specimen-scope derivation, closing the direct-rust-door specimen's inference frontier: an Atom whose binding an enclosing arrow's domain declares derives with the declared domain type as its evidence -- the declaration-site annotation, itself derived (x: Int grounds the x reference). This is the same lookup the branch-operand path already performs (infer_find_arrow_domain_type_in_tree), now written to the operand atom's own facts; it is scope-naive (whole-tree, first match), recorded in the frontier note, and deletes with the other specimen-scope rules when the resolver hands infer declaration-resolved identities. The tree is threaded through the fold's init chain to reach infer_node_facts; the helper had exactly one caller. Measured on the door specimen (scratch probe, uncommitted): 2 underived of 15 -> 0. The specimen's inference frontier is fully closed, and the production observation advances from InferenceRejected (infer_grounding_not_derived) to EmissionRejected (target_use_site_ownership_lookup_miss) -- a new, typed, located deficit in the emitter, the next gate on the path. Flip census (all three rewrites verified by execution): - dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds: the boundary moves to the authority itself (the denotation table returns Absent for x/y), true regardless of infer's other rules. - The three emit_host classical-not refusal guards (canonical, staging, staging-swapped) flip to acceptance witnesses pinning the emitted text's shape -- the real-infer tree now fully derives, and the emission is the same one the equals-eval witness proves behaviorally correct. The translate-refuses-underived behavior stays enrolled on hand-staged fixtures in translate_underived_refusal_test.dag (14/14 green). The renames are carried into the commit_workflow and witness_deferral_freeze rosters. - New witnesses: binding_reference_derives_parameter_atoms_holds (evidence is the domain's Int binding atom, census 2) and door_specimen_fully_derives_holds (0 frontier of 15). Full battery at this state: refusal suite 14/14, grounding wall 12/12, instrument 2/2, binding-denotation 2/2, product-introduction 4/4, atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6, branch 2/2, eval-thesis 6/6; door production group still enrolled-red (unchanged). Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…osition and decode canonical operator wires
The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:
Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.
Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.
The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.
Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
… membership to the closed ingest set The declared-inhabitant roster-membership derivation in 04_infer generalized from the dag roster to the closed ingest set (dag, python, typescript): infer_node_declared_in_language_inhabitants returns the declaring authority's roster root as evidence, with deep subtree membership so a declared inhabitant's leaf fact atoms derive exactly as the inhabitant node itself. Measured: the python fixture's 19-node frontier and the typescript fixture's 28-node frontier both close to zero; all four add-slice stall population round-trip witnesses green; the python->typescript cross-language compile accepts, byte-identical to ts_source_text. Section 4b(4) flips (expecting-red probes becoming permanent regression controls for the acceptances): - cross_language_compile_refuses_canonical_underived_holds -> cross_language_compile_python_to_typescript_round_trip_holds - inhabitant_neutralization_emit_after_neutralize / same_flavor_python / go_int64_to_ts refusal helpers -> round-trip controls - inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) -> round-trip control; python->go members stay refusal guards (go is outside the closed ingest set) - cross_language_emit_inhabitant_neutralization_refuses_underived_holds -> round-trip control; the python->typescript emit-matrix row reads ChainProven The add-slice stall's next-rung trigger fired, so it retired per DESIGN 4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay enrolled. Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…ess for the emitted add crate
First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.
- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
stdout pinned to the family's expected octet, sharing the kernel family's
one-build cache key exactly as the classical_not arm shares its family's
key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
control — a no-eval verdict has no oracle leg to break, so the expectation
side breaks (an octet the run never produces must not match); program-side
discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
by construction (the verdict entry is file-grain enrolled in
falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
{classical_not, add}; split 2/13.
Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
…rounding-frontier-3100 # Conflicts: # dag/gunbc/guarantee_stall/roster.dag # src/v2/compiler/self_host/candidate_generation_stage_verdicts.dag # src/v2/test/claim/execution/self_host_candidate_generation_stage_verdicts_test.dag # src/v2/workflow/floor_expected_red.dag
…fication The row classified candidate_generation_translate_self_emit_dag_add_slice_holds as RealDefect/CompilerBehaviourRefusal with measured evidence that translate refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the subject: the declared-inhabitant roster-membership derivation grounds the slice's type spine by lookup, and the witness passes under claim_batch --hermetic on the merged tree. The dated classification is kept verbatim; the disposition flips RoutedToOwner -> RepairedInThisChange with the repair measurement appended to the evidence, so the routing carrier stops dispatching a fixed defect. Structural witnesses (count 13, no NotReproduced, exact partition) are untouched and pass.
Main's annotation-placement wall (source annotations admit only standalone leading blocks attached to module-scope declarations; in-body forms refuse) reached this branch through the merge and refused 8 blocking errors on the 00_compile closure: the add-family promotion note inside the emit_coverage_frontier_roster list and the python->typescript row note inside the cross_language_emit_matrix list. Both blocks move above their enclosing declarations, rephrased to name their subject row. Measured: gunbc compile of src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors; both files' suites stay green (8/8 and 4/4).
…ct witness for the emitted logic family crate The complement family's native execution runs family-grain per the witness_family_build_grain_ruling (one crate for meet + join + complement, argv-dispatched), so the native-only arm emits the logic family crate and runs the complement member through the family dispatcher, sharing the family witness's one-build cache key. The verdict is decided solely by the emitted native run's stdout (expected octet 0, complement(True) = False); the broken control flips the expectation side (octet 1 can never match), with the comparator pinned by the stdout mock pair. Program-side discrimination stays with the equals_eval agreement pair and the family witness's all-alt leg. The frontier row's backing citation lands in the already file-grain-enrolled native-only verdict entry, so it is enrolled by construction; the roster comment is rephrased to cover both 2026-09-07 promotions (add and complement). The frontier test's split and native membership assertions move to 3 native / 12 retained. Verified by execution: claim_batch --hermetic on emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two new complement arms included), and emit_coverage_frontier_test.dag passes all 8.
…ling is_host_text_carrier_type answered true for any type expression whose authored name reads "String", including references to the structural alias v2.std.text.String (type String = FreeMonoid<Char>) that the namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier fields to. The emitter rendered every one of those references as the host String while value-position consumers rendered the structure -- the E0308 family dominating the self-host compile-phase frontier (41 of 64 in v2_compiler_tokenize.rs on the post-merge board). The String arm now consults the resolved declaration's provenance against v1.compiler.coercion structural_declaration_modules_for -- the same roster type_realization_decision reads -- so the legacy arm and the strict decision cannot diverge on one node (DESIGN section 3, and gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling). Kernel mints and unresolved references keep the host answer exactly as before. Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs itself (no module in the stage0 closure references a structurally declared String -- verified by the whole-population candidate tree), installed from target/stage0-regen-candidate after the priced round's partitioned rebuild refused MirrorHasNoOwningPackage on the emitter (the emitter is monolith-shell, not partition-owned). Fixed point verified by execution: claim_executor --required-regen on the rebuilt seed reports first_generation_equal=true over 158 adjudicated mirrors.
… -> 28 errors A field authored v2.std.text.String reached the Rust emitter as an overlay-less resolved reference leaf and rendered the bare terminal name, which binds the prelude String cross-module (#9813: kernel names are never overridden by imports, so the use-line is dropped) while every value position renders the structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family, 41 of 72 errors on the XL-N phase board. The new rust_overlayless_alias_leaf_requires_peel arm in render_rust_type_without_applied_binding detects the population (overlay-less zero-parameter alias leaf, qualified spelling, String terminal segment, closed_alias_peel_verdict agrees) and renders the alias declaration's resolved right-hand side, projecting the same realization the fn-signature positions already produce. The qualified gate is load-bearing: inside the declaring module the bare name is the correct render (the emitted module carries the alias declaration), and the local binding's resolved_type drops the RHS type argument, so an ungated peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare String keeps denoting the kernel scalar through the host-carrier arm. Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/ local-alias positions) compiles clean; XL-N compiler closure cargo check 72 -> 28 errors with the residual census dominated by the declared text_boundary_identity_wall class (kernel String vs structural carrier at bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds (first_generation_equal=true, 158/158 adjudicated).
…rsions + witness_violates helper Four clusters, all measured non-hop additions between receipt_1 (155) and the post-peel census (28); the live gate now measures 15 with zero unadmitted regressions: - integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String; the public boundary converts with chars() (text_boundary_identity_wall specimen discharged at this site). - 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural -> host String with chars_to_string() at construction, mirroring the v1 tokenizer's host-lexeme carrier. - target_model.dag + bash.dag: EmitSpellingEscape.from/to and apply_emit_spelling_escapes go structural (v2.std.text.String); the EmitSpellingQuote arm converts host->structural->host at its boundary; bash's escape rows wrap their kernel String literals with chars(). - witness.dag + 3 call sites (collection list_nth, provenance span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics): new witness_violates<C> helper puts Violates constructions in a Witness-headed position so the emitter resolves the carrier type argument; dissolves once inference records per-call substitutions. Verified: 48 targeted claim witnesses green (tokenize behavioral, shell conformance, string brace escape, string length, map-lookup violates, source text ingress, bash materialize x12, int literal smoke x6, provenance span index x2).
…nsus at 6676531 The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias peel (60cbd7b, 72 -> 28) and the twelve-error source cluster (6676531, 28 -> 15). The epoch changes on the instrument's target pinning (found by review on gunbc#9857), admitted with receipt_1's board as the reclassified predecessor under the identity map. Nine added identities are hop relocations admitted by the hop index; four sit in python/typescript modules newly entered into the emitted closure, admitted as ExposedByNewEmittedModule. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds.
Inference substitutes the resolved declaration into a data annotation's type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the emitter with the arg BEING the type Bool = True | False declaration itself (Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper). type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling answers the kernel declaration -- so the structural enum rendered as host bool against a value of BooleanAlgebra<Bool> (the python.rs:328 / typescript.rs:177 E0308 pair on the XL-N compile-phase frontier). The connective is the discriminator: a reference node is a bare name (NoConnective); a node carrying Conj/Disj structure IS the declaration, and type_reference_provenance's own-span fallback already answers that shape correctly. The guard routes declaration-shaped nodes there directly, bypassing the scope lookup that #9813 makes answer the kernel. Mirror regenerated via the regen round; fixed-point verified (claim_executor --required-regen PASS).
…s at the boundaries The receipt_2 census's fifteen identities, resolved at their sources: - lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the structural carrier (v2.std.text.String); the construction sites held host Strings. Convert at construction with chars() -- the #9907 ingress pattern. - python.dag / typescript.dag bool groundings: qualify the annotation as BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted- declaration provenance guard the qualified arg now renders structural. - target_model.dag: target_lex_rule_literal_step returns the host carrier (chars_to_string over the structural pattern text); TargetText.source converts at the is_empty boundary; the unicode-scalar symbol intern converts its single-codepoint list to the host carrier. - qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier emptiness check (string_length == 0) instead of routing through the structural string_is_empty. - 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier operations (string_length, char_at, code_point) rather than converting to the structural carrier for a two-character lookahead; parse_char_is_arm_pattern_lead takes the codepoint Int directly. - v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered to a .concat() method call on std::string::String (E0599); rewritten as nested concat calls. Measured: the 00_compile closure emits 172 files and cargo check reports cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.
The cargo half runs with cwd = a fresh mktemp directory; with no rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs while different compilers did the measuring -- the fabricated comparability the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a host default of 1.83.0 met a crates.io index whose freshly published dependency manifests require edition2024, resolution failed before any diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured tree. The pin is propagated by copying the repo's rust-toolchain.toml into out_dir: the file remains the sole in-repo channel authority (its header forbids a second pinned literal), and the copy makes the measured channel true by construction on any host. The gate's read_live_toolchain observes the same channel because every documented actuator invokes from the repository root, which the same file governs.
… closure's cargo census is empty Measured at 5ee4892 by the one-entry instrument: the 172-file emitted crate reports zero cargo error diagnostics, so the board attributes every phase a count of zero and furthest_phase_reached stands at Borrowck. The fifteen removals against receipt_2 need no disposition; nothing was added. The epoch does not change: the cargo half now pins the toolchain channel by copying the repo's rust-toolchain.toml into the scratch crate, and every recorded comparison field is identical to receipt_2 (whose census the fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the same-epoch arm carries no reclassified predecessor. The frontier-state pin flips per DESIGN 4b(4): the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the permanent regression control over the green state. Validated: all 36 self_host_compile_phase_frontier_witness claims PASS, including current_persisted_compile_phase_frontier_holds.
Ledger-Repair-Judged: docs/design-failure-modes.md Ledger-Repair-Judged: docs/design-rung-drops.md
…e rosters First native-parity divergence class found by running the emitted closure on a discriminating fixture: the algebra inhabitant rosters still carried PointwisePower after its authority row was cut, so the emitted compiler panicked at 12 record-shaped carrier sites while the interpreted seed refused cleanly. The roster rows are removed in rust/python/go/typescript types.dag, the derived coercion assertions in compiler_tests.rs regenerate without them, and two witnesses pin the boundary: the record shape constructs its structural carrier, and FinitePowerSet still refuses while its row stands. Mirrors regenerated by a converged regen round (fixed point Reached, stage-1 PromoteGenerationInputs over the three language types mirrors).
The admitted side of run_built_seed_regen carries the executable-digest spelling (current_exe_digest, next_pass_executable_digest) while the observed side hashed the file through path_digest, which prepends the fnv1a64: tag. Same bytes, two spellings, so the gate could never pass -- unpassable since fa2d403 (#9771). Factor current_exe_on_disk as the single path authority and read the observed digest through current_exe_digest so both sides spell the same bytes the same way.
A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower roster removal rewrote its derived coercion assertions) refused the rebuild MirrorHasNoOwningPackage: the mirror is owned by no partition package, because every item it defines is #[cfg(test)] and no release unit elaborates it. The refusal conflated two different states -- unowned (a coverage hole) and excluded from the release build by construction (a precise empty scope). The model now names the class: rebuild_scope_release_excluded_mirrors rosters its members (compiler_tests.rs, cited to emit_compiler_tests_module), the decision answers ReleaseScopeEmpty when the whole change set is excluded, and the actuation shape is actuatable with an empty package closure and every partition package excluded -- the build still runs as verification, and a compiled partition package refuses the stage. The host admits the empty closure only when the new stage0_partition_rebuild_release_scope_empty_today query answers true; any other empty closure still refuses. A mixed change set scopes on its release-visible members alone. Verified by execution: the 2026-09-08 round converged (fixed point Reached) with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell crate on its fingerprint (the outer mod line is ungated, so rustc reads the file) while the produced executable was byte-identical -- stage input seed digest == output seed digest. Four new witnesses pin the arm, its actuation shape, the mixed set, and the host-facing query's two arms; the boundary witness (unowned cli_run.rs still refuses) keeps the roster from decaying into the absorbing fallback.
The receipt's partition-rebuild line is rendered by the model over receipt.installed_mirrors, which the host populated from the stages' projected_paths -- full paths -- while the partition rows and rosters key on basenames. Every drifted round's receipt therefore rendered a spurious RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false claim on the round's own receipt. Route the projection through emit_path_basename, the module's single path-to-basename bridge, so the field carries the mirror names the model's vocabulary means.
The ReleaseScopeEmpty modeling commit placed three // blocks inside declaration bodies (stage0_partition_rebuild_is_actuatable, stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today). The .dag realization admits annotations at module-item grain only, so the floor lane's parse phase refused the file with 12 located errors and the run ended floor refused. The prose is unchanged; each block now sits above the declaration it describes.
…d realization The witness added with the fossil-row removal excluded the bare spelling "BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet, so the row could never green. The exclusion's subject is the finite-set REALIZATION the fossil row would have asserted; spell it applied (BTreeSet<i64), which the preamble's import line does not contain.
The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.
The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).
Co-authored-by: briansrls <briansrls@gunb.ai>
Brings in #10692 and the megarac machine-intake corpus. No overlapping edits to the lane's files; the generated workflow mirror is untouched on both sides. Main's floor is red on in-body source annotations in dag/gunbc/machine_intake/megarac_media_attach.dag (main push run 34437200195); the grain repair lands as the next commit.
The file landed on main with three // blocks inside declaration bodies, which the source-annotation grain (DESIGN 4c: standalone leading blocks attached to module-scope declarations only) refuses — main's own floor push run 34437200195 is red on exactly this file. Each block moves, verbatim, to join its enclosing fn's existing leading annotation block, separated by a // paragraph line; no declaration bytes change.
…eview round 2, points 1-3) Point 1: derive_native_universe now carries BOTH directions of the module index's path relation; reclassify_context_refusals queries module->path (was: path->module queried by module, an unmatchable lookup that left context refusals misclassified as prepare-stage). Two unit tests pin the exact-identity join and the off-key miss. Point 2: context backing is a triple join, not a reason match. The receipt carries module_source_index (module <-> source path for every universe member, built at derivation; a miss refuses UniverseEntryOutsideSubject), and native_route_context_refusals_backed requires identity.module == index.module AND file_refusal.path == index.path AND the exact fatal reason. New reds: backing by another module's file, and the right path with the wrong reason. Point 3: the ratchet is identity-grain. native_route_required_pass_identities rosters every identity admitted as a native pass (the smoke member alone today); native_route_required_passes_hold refuses RequiredNativePassRegressed when a rostered identity returns any other disposition, so native capability cannot shrink while the lane stays green. Secondary: universe.sort() without dedup() — duplicates now reach the authority's UniverseDuplicatesPresent clause instead of being erased before it can judge them. Co-authored-by: briansrls <briansrls@gunb.ai>
…sted descent (review round 2, point 4) native_test_find_decl_node recursively walked every nested Named edge, so a same-named graft spine segment (or any nested edge) could be selected and evaluated under the requested test identity — the receipt's module-qualified identity names the request, not the selected node. The search is now exact: unwrap the module production wrapper through the namespace-graft authority, walk one Named spine edge per qualified-name segment (find_named_child, refusing ambiguity), and match direct children of the module scope only. native_test_decl_deeper is deleted. A failed scope walk is its own entry reason (native_test_entry_module_scope_unresolved), deliberately absent from native_route_entry_limit_reasons so a graft-shape surprise reds the lane instead of excluding tests. The committed control (v2.test.native_decl_selection) prepares a synthetic module with no top-level declaration named collision and asserts the nested spine segment is never selected: requesting collision returns declaration_not_found (the recursive walk returned not_arrow), the real declaration still evaluates to NativeTestPassed, and a sibling module's declaration is unreachable. Co-authored-by: briansrls <briansrls@gunb.ai>
…ne (review round 2, point 5) The roster join covered only phase EXISTENCE (variant names off the declaration index); lane OWNERSHIP stayed a parallel Rust match. With three independently selected lanes and the native route's isolation load-bearing, a host edit mapping V2NativePhase to another lane would leave the native job selecting zero phases — phases_run=0, no failure, a green required job that executed no native test. The authority now exposes required_ci_lane_phase_rows (one nullary call, every rostered phase with its owning lane in CLI spelling). Every --required-ci run evaluates it at start, in every lane, and refuses: any (phase, lane) pair present on exactly one side; a selected lane whose authority-expected phase set is empty; and, at run end, an observed ran set that differs from the expected set. Live RED probe: with the host match arm moved to build, the v2-native lane named both divergent pairs and refused the empty ran set instead of greening over zero phases. Co-authored-by: briansrls <briansrls@gunb.ai>
The emit stage refuses in-body annotations (§4c); the two ratchet RED fixtures carried their rationale inside the fn bodies. Same class as the megarac repair, caught by the lane's own emission step. Co-authored-by: briansrls <briansrls@gunb.ai>
…rry the poison specimen off .dag Two CI refusals on run 34471447387, both environment/fixer-carrier defects in the lane's own machinery, neither in the route under test: 1. required-v2-native refused EmittedCrateNotWritten (EACCES): the lane harness rooted the emitted crate at the host-shared /tmp/gunbc-emit-compile, which on the persistent self-hosted fleet collides across jobs, runs and euids. The lane now selects the declared RUNNER_TEMP per-job root when one exists (lane_emit_compile_probe_root, beside the required phase's stricter refusal policy, over one shared env read) and keeps the host temp for the local route. Selection pinned by a unit test over both arms. 2. required-witnesses-floor refused ChangedWitnessObservationFailed: the lane's deliberately unparseable control fixture carried a .dag extension, so the changed-witness observation parsed it and the deliberate tokenize failure refused the whole observation. The committed bytes are not a dag program and no longer claim to be: renamed to poison.dag.poisoned, and the harness materializes them as poison.dag under the lane's scratch root (rebuilt fresh each run) for the control invocation. The observation's refusal arm stays absolute - no exception was added to it. Co-authored-by: briansrls <briansrls@gunb.ai>
Keep the in-branch megarac read-back annotation that already names StartRefused as the unreadable-JSON case. Co-authored-by: Cursor <cursoragent@cursor.com>
The native lane interpolates only this summary on EmittedCompilerBuildFailed, so a status-only Completed arm swallowed the diagnostic the verdict already held. Co-authored-by: Cursor <cursoragent@cursor.com>
…e_ownership_lookup The native cargo refusal (now rendered by cargo_verdict_summary) was irrefutable_let_patterns on v2_compiler_source_authority; the needs_rc_pattern prelude always appended else. The floor red was the door-ledger ownership witness still calling the one-argument lookup after grain became required. Co-authored-by: Cursor <cursoragent@cursor.com>
match_pattern_is_irrefutable is false for every VariantPattern, so a one-variant cause still emitted else { unreachable } and rustc refused under -D irrefutable-let-patterns.
Co-authored-by: Cursor <cursoragent@cursor.com>
match_pattern_is_irrefutable is false for every VariantPattern, so a one-variant cause still emitted else { unreachable } and rustc refused under -D irrefutable-let-patterns.
Co-authored-by: Cursor <cursoragent@cursor.com>
The branch's Char-regrounding edit routed the digest fold through chars(s:), which admits only the native compact-string realization; the lexer's repeat/delimited growth produces modeled Cons-chain strings, so every repeat-lexed token refused with "chars expects a string argument, got Variant" — ten floor witnesses BLOCKING (ingest_bridge, cross_language_add_python_to_typescript, inhabitant_neutralization_03, parse_stamp_span_index). fold_list's free-monoid read accepts every string realization and yields the same Int codepoints, so the memo content key is unchanged: witness_subject_token_stream_scope_sensitive stays green, and all ten previously-BLOCKING identities return true. Co-authored-by: Cursor <cursoragent@cursor.com>
The keyed-container inhabitant arm emits panic!; wrapping it in Rc::new is unreachable_code under the native lane's -D warnings. Co-authored-by: Cursor <cursoragent@cursor.com>
…e-cbbd' into session/royal-bear-211
The in-body comment block refused at emission: only module-item grain annotations are modeled (DESIGN 4c), and the v2-native lane's compile of the 00_compile closure produced six hard diagnostics, one per in-body line. Co-authored-by: Cursor <cursoragent@cursor.com>
The in-body // block is six source annotations; native emit of 00_compile refused each as unmodeled grain. Co-authored-by: Cursor <cursoragent@cursor.com>
…ub.com/gunb-ai/gunbc into session/royal-bear-211
…) at parse_lexeme_digest
The interpreted chars builtin admitted only the native Value::Str realization and
refused modeled Empty/Cons-chain Strings, so the ten floor witnesses whose fixtures
construct Token { lexeme: Empty } went red with "chars expects a string argument,
got Variant". The emitted route has the converse need: fold_list<T, _> cannot infer
T from a host-carrier lexeme (E0282), so parse_lexeme_digest must route through the
chars(s:) boundary conversion.
Widen the interpreted builtin through free_monoid_to_string — the same grounding
length/fold_list/chars_to_string already use — so every string realization chars()
to the same Int codepoints, while a generic List, a non-codepoint chain, or an
unrelated variant keeps expect_str's typed refusal (pinned by new
chars_receiver_tests). With the builtin realization-agnostic, restore chars(s:) at
parse_lexeme_digest: the digest is realization-stable on both routes.
Verified: chars_receiver_tests green; ingest_bridge_realized and
witness_subject_token_stream_scope_sensitive green interpreted (digest unchanged);
v2-native lane emission green and the emitted crate builds under
RUSTFLAGS="-D warnings" (E0282 cured); clippy --all-targets -D warnings and
fmt --check green.
Co-authored-by: briansrls <briansrls@gunb.ai>
d716207 landed its (correct) diverging-panic repair with the rationale as a four-line in-body // block, which the required-CI parse phase refuses at 05_emit_rust.dag:493-496 — source annotations are admitted at module-item grain only. The refusal cascaded: no head index, so namespace-wave-admission did not run, the floor ran degraded, and the build lane's generated-artifact phase refused with the same 4 hard diagnostics from the v2 self-compile. The comment text is unchanged, only moved above the declaration it describes. Verified with v1_src_dag_parse (the same run_dag_parse_sweep the parse phase executes): a planted unattached-annotation probe refuses naming exactly its file, and the repaired tree sweeps 5403 files parse-clean, exit 0. Co-authored-by: briansrls <briansrls@gunb.ai>
Four in-body // lines refused v2 self-compile of the stage0 mirrors under the annotation grain wall. Co-authored-by: Cursor <cursoragent@cursor.com>
…e-cbbd' into session/royal-bear-211
e8ed171 added body_producer_forward_row_test_fn_decl (the native lane's driver evaluates test fn declarations, so they must lower through the forward producer) but did not move this receipt, which still pinned the closed row table at main's six. The table is the controlled subject universe and the sibling forward/fold surface-identity parity witness covers membership at identity grain; this row pins the count. Verified by execution: wave1_gate1_a1_forward_behavior_row_count_witness_holds returns true. Co-authored-by: briansrls <briansrls@gunb.ai>
required_lanes_roster has carried three lanes since the v2-native lane enrolled, but w_RED_neither_lane_waits_on_the_other still pinned the two-lane split, so the floor red-carded the branch's own lane addition (returned Bool(false) on every required run since the roster grew). The witness now asserts the three-lane roster: each lane job carries no needs, and the aggregate's roster carries each of build/floor/v2-native exactly once. w_RED_lane_contexts_collide_with_no_other _emitted_workflow gains the same lane's clauses (no fleet-converge job id collision; pairwise distinct from build, floor, and the aggregate). Verified by execution: both witnesses return true; v1_src_dag_parse sweeps 5403 files clean. Co-authored-by: briansrls <briansrls@gunb.ai>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Closing: this PR was auto-opened by the archive flush of session royal-bear-211. Its head f2e2016 is a strict ancestor of #10882's head 1eb184f on cursor/required-v2-native-ci-lane-cbbd, which is the live PR for the required-v2-native lane. Branch kept (not deleted) so no in-flight run is orphaned. — sent from eager-raven-113 |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f2e2016823
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| // the self-hosted parser (2026-09-09, required-v2-native lane work). | ||
| fn list_snoc_item<T>(xs: FreeMonoid<T>, item: T) -> FreeMonoid<T> { | ||
| list_append(left: xs, right: Cons { head: item, tail: Empty }) | ||
| xs |> list_push(item) |
There was a problem hiding this comment.
Preserve compact strings when appending to free monoids
When a FreeMonoid<Char> uses the interpreter's compact Value::Str realization, list_push explicitly rejects the receiver instead of appending to it. This makes the generic list_snoc_item fail for a valid free-monoid representation and affects the new tokenizer lexeme_grow path whenever its accumulator is compact; running gunbc run ... --function lexeme_grow --arg acc=a --arg chunk=b now returns TypeError { msg: "list_push not supported on String" }, whereas the prior list_append implementation handled the value. Preserve the string realization here or route this case through a string-aware append.
Useful? React with 👍 / 👎.
| drop(withdrawal); | ||
| eprintln!("required-ci: v2-native old route restored"); |
There was a problem hiding this comment.
Refuse admission when restoring the old route fails
If the guard's rename-back operation fails—for example because the withdrawn file was removed or the target directory became unwritable—Drop only prints a warning, after which these lines unconditionally report restoration and continue minting an OldRouteWithdrawn receipt that can be admitted. A successful local run can therefore return success while leaving target/release/gunbc missing; restoration needs an explicit fallible step whose error stops admission rather than relying solely on Drop.
Useful? React with 👍 / 👎.
Auto-opened by session-dashboard for session
royal-bear-211.Pushing to
session/royal-bear-211advances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan