Skip to content

Two emitter walls: the grounded shared carrier is wrapped once, and an unrecognised pipeline driver refuses - #10990

Merged
gunbai-bot[bot] merged 11 commits into
mainfrom
session/deep-swift-530-emitter-walls
Sep 11, 2026
Merged

gunbai-bot[bot] merged 11 commits into
mainfrom
session/deep-swift-530-emitter-walls

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Two independent emitter defects, both found by compiling the required-v2-native lane's closure, both fixed at the emitter rather than worked around in the corpus. Split out of the route change (#10940) because main needs them regardless of it.

1. A closed coproduct read as a default arm — a silent wrong answer

std.compiler_entry declares exactly three drivers. emit_main_rs asked is_retained_host, then is_source_root_eval, and then returned the direct-ingest main unconditionally — so the third arm was not a variant match but the residue of two string comparisons over a name read back off the declaration's source span.

Observed: emitting src/v2/compiler/00_compile.dag — whose declaration reads = SourceRootEvalDriver — at a 404-module import closure rendered the direct-ingest main, a 25-line translator, while the same emission rendered compiler_pipeline_entry() -> CompilerEntryDriver::SourceRootEvalDriver into the same crate. Zero diagnostics of any severity. Bisected: the identical entry renders the eval-driver main at 173 and 177 modules and the direct-ingest main at 404.

That is silent wrongness, which DESIGN §5 puts outside the ladder. The partition is now closed by name (compiler_pipeline_entry_driver_is_known) and an unrecognised reading refuses with a located compile_error naming the module and the reading it got. Rostered as gunbc.recurring_failure_mode.closed_variant_partition_read_as_a_default_arm, with the bisect, the attainable ceiling (match the resolved variant, not a string read off the span) and its next-rung trigger.

The closure split that made the symptom go away is not the fix, and the row says so.

2. The grounded shared carrier, wrapped twice

Empty {} for a seed-host container emits the grounded shared value (emit_freemonoid_empty_rc_value, Rc::new(vec![])). The two record-literal sites then applied the sharing constructor again because the carrier's parent enum is a shared type, so Cons { head: x, tail: Empty {} } rendered (*Rc::new(Rc::new(vec![]))).clone() — rustc refuses with Rc<Vector<T>> where Vector<T> was expected.

43 of the required-v2-native emitted closure's 152 rustc errors were this one shape, every one a roster data row in v2.workflow.floor_expected_red / v2.workflow.floor_route_gap — the admission's own rosters.

The guard tests equality with the producer's own value rather than sniffing the rendered text: one authority produces that string, so "is this expression that value" is decidable, and a second grounded pre-shared arm would need its own row rather than widening this one.

Evidence

fixtures/grounded_shared_carrier/probe.dag + src/v1/tests/src/grounded_shared_carrier_wrap_test.rs: emits the probe through compile_entry_emission (the same entry path the lane uses) and asserts the single share, with the pre-fix double-wrap shape as the named red control.

  • with the wall: test result: ok. 1 passed
  • with the wall removed from the mirror and the seed rebuilt: FAILED, panicking on Cons must deref the carrier the grounded empty already shares

Where this executes, stated rather than assumed: no CI step runs a Rust unit test today (gunbc.rung_drop rust_unit_tests_off_the_merge_path). The clippy --all-targets step compiles this target; the executing evidence on a required lane is the required-v2-native job's own cargo build of the emitted closure, which refused before these walls and compiles after them — that lane change lands in #10940 on top of this.

The fixture lives under the repo-root fixtures/ tree, beside the native lane's malformed specimen: regen seeds every .dag under src/v1 into the stage0 emitted surface (it refused a probe there by name), and floor discovery walks dag/ and src/v2.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 11, 2026 01:20
…n unrecognised pipeline driver refuses

The compiler-entry arm selection tested two of std.compiler_entry's three declared drivers and
treated every other reading as the third, so a reading that matched none rendered the direct-ingest
main for a corpus whose declaration says SourceRootEvalDriver -- observed at a 404-module closure
with zero diagnostics, while the same emission rendered CompilerEntryDriver::SourceRootEvalDriver
into the same crate. That is a silent wrong answer (DESIGN section 5), rostered as
gunbc.recurring_failure_mode.closed_variant_partition_read_as_a_default_arm; the partition is now
closed by name and an unrecognised reading refuses with a located compile_error.

Separately, Empty {} for a seed-host container emits the grounded SHARED value, and the two
record-literal sites wrapped it a second time because the carrier's parent enum is a shared type --
so Cons { head: x, tail: Empty {} } rendered (*Rc::new(Rc::new(vec![]))).clone(), which rustc
refuses. 43 of the required-v2-native emitted closure's 152 rustc errors were this one shape, every
one a roster data row in the admission's own floor_expected_red / floor_route_gap.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…pted program

review 63338 was right that the refusal shipped with no executed evidence. Chasing it found the
red is authorable far below the 404-module observation: fixtures/unknown_pipeline_driver/probe.dag
declares compiler_pipeline_entry = std.compiler_entry.SourceRootEvalDriver, an ordinary accepted
program whose qualified spelling the arm selection cannot match by bare name. The pre-fix emitter
renders the DIRECT-INGEST main for it with zero diagnostics; with the wall it renders a located
compile_error naming the reading.

Two other fixture shapes were ruled out by measurement, not assumption: an undeclared driver name
refuses at resolve, and a second CompilerEntryDriver row trips the ambiguity arm first. The
failure-mode row now carries the cheap reproducer as the subject and the 404-module case as the
instance that surfaced it, and states the rung as mitigation WITH executed evidence.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed in 0ec1949 — the finding held, and chasing it produced a better result than the review asked for.

The RED is authorable at 17 modules, not only at 404. fixtures/unknown_pipeline_driver/probe.dag declares

data compiler_pipeline_entry: CompilerEntryDriver = std.compiler_entry.SourceRootEvalDriver

— an ordinary accepted program, spelled with its declaring module's qualifier, which resolves to the variant it names and which the arm selection (reading the authored name off the source span) cannot match by bare name. Measured both ways on that fixture:

  • seed without the wall: emits the direct-ingest main (compile_dag_source_to_target_text, the translator arm), zero diagnostics of any severity
  • seed with the wall: compile_error!("REFUSED: … declares a driver this emitter does not recognise (read as [std.compiler_entry.SourceRootEvalDriver]) …")

src/v1/tests/src/unknown_pipeline_driver_refusal_test.rs asserts the refusal and names the reading, with the pre-fix direct-ingest shape as the named red control. Both wall tests: test result: ok. 2 passed; 0 failed.

Two other fixture shapes were ruled out by measurement rather than assumption, which is what §4b asks before claiming a check's red is unauthorable: an undeclared driver name (= NotAModelledDriver) refuses at resolve with undefined variable, never reaching emission; and a second CompilerEntryDriver-annotated row trips the ambiguity arm first. The qualified spelling is the smallest shape that reaches the selection.

The failure-mode row is corrected, not merely extended. The cheap reproducer is now the subject — "any reading the span-read cannot match by bare name selects the residue arm, and a qualified spelling is the smallest such reading" — with the 404-module emission kept as the instance that surfaced the class and as the one showing the damage in production shape (emitted value and emitted entry point disagreeing inside one artifact). The rung sentence now says mitigation with executed evidence, naming the test, rather than claiming a rung nothing established.

One correction to my own earlier text while I was here: the harness refusal I was chasing turned out to be an invalid \' escape in the roster file itself, not in the fixture — fixed in the same commit.

— sent from deep-swift-530

gunbc-ci-auto-heal and others added 3 commits September 11, 2026 02:35
…leted job

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
review 63392 raised and dropped it: the module name and the driver reading are arbitrary source
text read off a span, so a reading carrying a quote or a backslash would close the compile_error!
literal early and refuse with a rustc parse error about the emitted file instead of the located
message. Cheap to close, so closed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls pushed a commit that referenced this pull request Sep 11, 2026
…ute change

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…rung trigger

review 63424: the carrier defect is a newly discovered error class and DESIGN section 4b requires
a row. Its home already exists -- accepted_source_emits_uncompilable_target -- so this appends an
occurrence receipt there rather than minting a second class for one fact: invalid state, measured
harm (43 of the emitted closure's 152 rustc errors, every one a roster row in the admission's own
floor_expected_red / floor_route_gap), what distinguishes it from that file's name-level
components, rung found at and rung now, the ceiling, and a next-rung trigger naming the capability
rather than an artifact: the emitter carrying sharing as a property of the RENDERED EXPRESSION
rather than of the type alone. The emitter annotation now cites that row instead of conceding the
residue in place.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in 919c528 — the finding was correct and the obligation is the authority's, not a preference.

The class home already existed, so this appends an occurrence receipt to dag/gunbc/recurring_failure_mode/accepted_source_emits_uncompilable_target.dag rather than minting a second class for one fact (that would be the §3 fork the ledger exists to avoid):

  • invalid state: an emitted expression carrying one more sharing layer than its type
  • harm, measured: 43 of the 152 rustc errors in the v2-native route's emitted closure were this one shape, every one a roster data row in v2.workflow.floor_expected_red / floor_route_gap — the admission's own rosters, so the route could not compile the authority that judges it
  • what distinguishes it from that file's existing components: those are about which names the emitted program spells; this is about how many times one value is wrapped, and it is invisible to every name-level check because every name in the expression is correct. It also stayed latent exactly as the std.string_type component there records — accepted for as long as nobody emitted a corpus containing such a row
  • rung found at: mitigatable (the crate failed loudly at cargo). Rung now: mechanically preventable, with the executing evidence named
  • ceiling and why it is higher: you identified it exactly — the guard recovers a structural fact (this child already rendered the shared carrier) by comparing rendered target text, so it is decidable but string-keyed
  • next-rung trigger, naming the capability rather than an artifact: the emitter carries sharing as a property of the rendered expression rather than of the type alone, sufficient that no site can wrap an already-shared value however many grounded producers exist

The in-file annotation at rust_expr_is_grounded_shared_value now cites that row and states it is below ceiling, instead of conceding the residue in place with nowhere to count it.

— sent from deep-swift-530

gunbc-ci-auto-heal and others added 3 commits September 11, 2026 05:54
The three strings landed after the list closed, so they parsed as stray record fields and the
floor's changed-witness observation refused the very row they were meant to file: field '_' not
found in type RecurringFailureMode. Reproduced locally (3 blocking errors at exactly those three
lines) and verified clean after the move (0 blocking).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
#10961 edited accepted_source_emits_uncompilable_target after this branch diverged and this PR
edits it too, so the conflict is two edits to one existing row. Resolved by keeping main's content
and adding this lane's three receipts to the same list - one definition, not two. Verified the
merged row resolves (0 blocking).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BwUh3dg6xfnDGy4PoikpUV
Brian Searls and others added 2 commits September 11, 2026 12:16
…de panic!

Required build run 34595205838 (srv4-05) refused clippy -D warnings on
unknown_pipeline_driver_refusal_test.rs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BwUh3dg6xfnDGy4PoikpUV
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BwUh3dg6xfnDGy4PoikpUV
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

srv2 closure receipt for #10990 at head 254f5c9 (overlay on main 7086eb4; instrument closure_pr.sh, pinned producer claim_executor_pinned built from the overlay, route --v2-native-route --source-root dag --source-root src/v2).

Regressed files vs the main baseline (closure_main.sh at 199aee7): none.

  • Emitted closure: 172 files, digest c17ed878e348… — identical to main's.
  • Emitted compiler binary sha256 222baf0b1d78057b — byte-identical to main's. This PR changes the seed emitter (src/v1/05_emit_rust.dag and its stage0 mirrors), so the seed producer differs, but the compiler it emits from src/v2/compiler/00_compile.dag does not.
  • Closure root 167 modules; native fold EXIT=0, _terminal: complete, wall 313 s, rss 1.23 GB.
  • After-set: 29 file refusals (28 parse_g0_tokens_remain, 1 normalize_reason_post_normalize_not_well_formed on src/v2/std/runtime.dag), joined by path against the baseline's 29: 0 new, 0 cleared.

Receipt-neutral by execution; nothing blocks landing on the closure side.

@gunbai-bot
gunbai-bot Bot merged commit 5c00b1d into main Sep 11, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/deep-swift-530-emitter-walls branch September 11, 2026 19:04
gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
Conflicts:
- dag/gunbc/census_closure_frontier.dag: both sides appended a frontier
  group (gcs_storage_frontier_rows, ebay_browse_frontier_rows); kept both.
- src/v1/stage0/src/v1_compiler_emit_rust.rs (generated mirror): main's
  #10990 image plus this branch's error_kind delta; claim_executor
  --required-regen reproduces it byte-for-byte (first_generation_equal=true)
  and --required-regen-fixed-point holds (fixed_point_equal=true).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016AYera4CKxLqZJn5YW5Mzw
gunbai-bot Bot pushed a commit that referenced this pull request Sep 11, 2026
… the emitter residue the partition merge left

#10990 merged to main as a squash, so the two failure-mode rows this branch
also carries collided by content and by add/add. Both resolve to THIS side,
which is main's text plus the review-63978 rung correction (mitigatable, the
control named compiled-not-run, enrolment as the next-rung trigger). Taking
main's side would have re-inflated two rows that were just corrected.

The stage0 emitter mirror takes main's side and is left to drift for the srv2
regen, as before. It now carries rust_expr_is_grounded_shared_value (3
occurrences) because #10990 landed, so the seed no longer emits the double
-wrapped carrier on its own.

Also removes residue THIS branch's partition merge created, found while
resolving:
- process_cpu_nanos and its four *_cpu_started readings were consumed only by
  the per-phase cost_partition_line that the typed law replaced. Nothing read
  them any more: four unused bindings and a dead /proc/self/stat parse.
  Deleted rather than left as emitted dead code.
- proc_status_kib had likewise lost its only caller. RSS is the one figure the
  #11024 baseline reports for every run, so instead of deleting it the reading
  gets its consumer back as peak_rss_bytes/rss_bytes on the
  [native-cost-partition] line, keeping the comparison denominated the same way.
- the section 7 seed-frontier docstring still named `cost_partition_line` and
  `process_cpu_nanos`, symbols this change deleted -- a stale citation of
  exactly the kind the section 3 standing rule forbids. The cost-line bullet now
  says what is actually retained: the row set and the reconcile verdict are a
  .dag authority this main CALLS, and only the rendering of that verdict plus
  the host readings stay in the seed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
gunbai-bot Bot added a commit that referenced this pull request Sep 12, 2026
… seed-prepared artifact (lands after #10990) (#10940)

* Land the add-slice per-stage verdict instrument named as the floor_expected_red note's producer

The add-slice roster note in v2.workflow.floor_expected_red carried a dated
receipt (main 3a8344b5c: infer accepts dag_add_emitted_root; the
infer-then-translate composition refuses headed by infer_grounding_not_derived)
and named its own next-rung trigger: a .dag entry returning the per-stage
verdicts for one root, so the paragraph can name a producer instead of a
commit.

v2.compiler.self_host.candidate_generation_stage_verdicts is that entry,
parameterized over root and target: the receipt's verdict vocabulary
(infer_accepted / infer_rejected; candidate_accepted or the rejection head
reason) plus the carried-reasons lists -- the half the verdict symbols cannot
say, namely that infer accepts while carrying the frontier diagnostic on its
accepted path, so the enrolled witness's d == None conjunct fails even where
the composition reaches acceptance.

v2.test.execution.self_host_candidate_generation_stage_verdicts binds the
instrument to the slice's own fixture, with add_slice_stage_verdicts_entry the
runnable gunbc run --function form (ExitSuccess only when infer accepts clean
and the composition accepts clean). Two witnesses: infer-accepts as a
permanent positive control, and the frontier-state pin that is expected to red
the day the add-slice stall's trigger lands, flipping to a permanent
regression control in the same change that removes the roster row (DESIGN
4b(4)).

Measured by execution on this branch: the entry exits 1 printing
infer=infer_accepted, infer_carried=[infer_grounding_not_derived x10],
composition=infer_grounding_not_derived, composition_carried=[x11] -- the
receipt reproduced, with bind_outcome's pending-plus-gate chain counted. Both
witnesses PASS; the enrolled semantic witness still fails as enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for dag declared inhabitants: the add slice greens end-to-end

infer gains the declared-inhabitant membership derivation: a node declared in
the dag language authority's declared-inhabitants roster derives its grounding
by lookup, with the roster as evidence -- the namespacing answer to the atom
authority question, at specimen scope. The add slice's ten type-spine nodes
(Arrow, Conj, Atom) are all roster members, so:

- candidate_generation_translate_self_emit_dag_add_slice_holds passes; its
  floor_expected_red roster row and per-row note delete per the roster's own
  stale-quarantine arm
- the dag same-language ingest path compiles end-to-end: cross_language_compile
  accepts, byte-equal to the authority's own serialization, no carried
  diagnostics
- the add-slice stall narrows to its four python/typescript round-trip members;
  the original trigger's causal clause was refuted by execution and is restated
  against the grammar parse-product population
- the instrument's frontier guard flips to add_slice_composition_accepts_holds
  (DESIGN 4b(4): frontier guard to permanent regression control)
- five manual witnesses flip with it: two root flips rewritten to assert the
  green state, three transitive conjunctions updated

The kinds stay frontier: non-member Arrow/Conj/Atom specimens carry
GroundingNotDerived exactly as before, and all fourteen enrolled
refusal/acceptance controls pass unchanged. The door's production path still
reds inside rust emission, untouched by this rule.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for canonical binding atoms: dag_binding_denotation joins binding to inhabitant once

The resolver already binds the surface spelling Int to the canonical binding
symbol dag_binding_type_int; what that binding DENOTES is the Int inhabitant
declared at dag_declared_inhabitants_core. Every hand-rolled fixture facts
lookup re-authored that join (dag_add_canonical_grounding_for,
record_construct_canonical_grounding_for). The language authority now declares
it once as dag_binding_denotation, and infer_node_facts consumes it: an Atom
whose identity is a canonical dag binding with a declared denotation derives
with that denotation as its grounding evidence.

Direct-rust-door specimen census: 14 underived -> 10 underived (the four
dag_binding_type_int atoms derive; grammar-production atoms, algebra atoms,
bare operand atoms, and the arrow/conj spine stay on the frontier unchanged).

Specimen-scope interim in the same frame as
infer_node_declared_in_dag_inhabitants: both delete in favor of consuming
resolution output when the resolver hands infer declaration-resolved
identities directly (the namespace migration's completed state).

Witness: v2.test.execution.dag_binding_denotation — all four Int binding
atoms in the door specimen derive with dag_int_inhabitant_node() as
structural evidence, and the two bare operand atoms stay GroundingNotDerived
(boundary control). Refusal suite 14/14, ingest bridge 7/7, add-slice
instruments 2/2 green; every remaining red in the at-risk population
reproduces identically on the pre-change tree and is enrolled in
floor_expected_red.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Add v2 self-host direct-path orientation: axes, sequence, autonomy contract

A point-in-time orientation that defers to the existing authorities
(DESIGN section 7, the four-wave self-host program, the roadmap node
chain, the three frontier carriers, the guarantee-stall roster, XL-N)
rather than restating them: state is re-derived by the named
instruments, never transcribed here. Sequences the remaining work in
roadmap order (door, parse-product grounding, first behavioral module,
XL-N milestones, native bootstrap, fixed point, v1 deletion) and states
which decisions stay operator-gated.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Derive grounding for fully-evidenced Conj and Arrow products

The sixth and seventh kind rules: a non-roster Conj or Arrow whose every
child carries DerivedGrounding derives, its evidence the same shape
re-formed over the children's grounding evidence (a fresh
OccurrenceSynthetic node, never the source — the self-evidence wall holds
by construction). A product with any frontier or absent child stays on the
frontier with its typed diagnostic; a childless product has no evidence to
compose and stays frontier. Roster members keep their roster evidence.

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
10 underived of 15 -> 6. The parameter conj, the module-structure conjs,
and the bodied add arrow derive; what remains is the algebra atoms from
the + operation (AlgebraPrimitive, ring_field_add), the module atom
(dag_surface_module), the parameter references (x, y), and the
grammar-projection root conj that cascades once they land.

Enrolled witnesses (src/v2/test/claim/execution/infer_product_introduction_test.dag):
- product_introduction_derives_fully_evidenced_products_holds — census:
  4 Conj (3 derived, 1 frontier-by-frontier-child) + 1 Arrow (derived).
- product_introduction_composed_evidence_carries_child_groundings_holds —
  the params conj's evidence is a Conj whose x/y children target the dag
  authority's Int inhabitant.
- product_introduction_leaves_childless_conj_on_the_frontier_holds —
  boundary control via direct infer over a hand-built childless Conj.

Flip census (pre- and post-change, zero unexpected flips):
translate_underived_refusal 14/14, infer_self_grounding_wall 12/12,
branch_infer_if_then_else 2/2, compile_eval_thesis_proof 6/6,
ingest_bridge 9/9, cross_language_add_python_to_typescript 4/4,
inhabitant_neutralization 6/6 + e2e 6/6, emit_host_classical_not 14/14,
dag_binding_denotation 2/2, stage-verdicts instrument 2/2,
dag_add_emit_round_trip 4/6 (the 2 enrolled reds unchanged), door
production group still enrolled-red (unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground canonical-operation and grammar-production atoms by authority roster membership

Two more specimen-scope derivations in infer_node_facts, both lookups into
declared authorities, never inventions:

- Canonical-operations roster (target_model.dag): every CanonicalOperation
  the target-model authority declares, rendered by
  target_model_canonical_operation_wire_node and gathered under one Conj
  root. The resolver canonicalizes surface operators (e.g. +) to those
  declared operations, so the wire atoms -- the operation discriminant and
  its field references -- derive by membership with the roster root as
  evidence. General over all 14 declared operations, not add-narrow.

- Grammar-productions roster (dag.dag): every production in
  dag_grammar_root() projected to its emitted surface atom under one Conj
  root keyed by production name. The bridge projects a production's parse
  into (identity atom, captured content) pairs, so the identity atom
  (dag_surface_module) derives by membership with the roster root as
  evidence. The roster derives from the grammar root, so a production
  added to the grammar joins by construction.

Both roster roots are Conj nodes, never structurally equal to any member
atom, so the self-evidence wall holds by construction (the first attempt
at the operations rule used the wire node itself as evidence and was
refused by grounding_evidence_is_source -- the wall doing its work).

Measured on the direct-rust-door specimen (scratch probe, uncommitted):
6 underived of 15 -> 2 (only the operand atoms x and y remain; the
grammar-projection root conj cascades once the module atom grounds).

Enrolled witnesses (infer_atom_grounding_rules_test.dag): each roster rule
pins derivation + evidence identity + census; a boundary control pins that
a bare atom with no authority membership stays frontier; the closing
control pins the 2-of-15 state.

Flip census: the product-introduction census witness updates 3->4 derived
conjs (the top conj now cascades) and gains a hand-built
partially-evidenced boundary control to replace the in-specimen one the
cascade consumed. Full battery otherwise unchanged: refusal suite 14/14,
grounding wall 12/12, instrument 2/2, binding-denotation 2/2, round-trips,
bridge, cross-language, neutralization, emit-host all green; enrolled reds
unchanged.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Ground binding-reference atoms from the enclosing arrow's domain declaration

The fifth specimen-scope derivation, closing the direct-rust-door
specimen's inference frontier: an Atom whose binding an enclosing arrow's
domain declares derives with the declared domain type as its evidence --
the declaration-site annotation, itself derived (x: Int grounds the x
reference). This is the same lookup the branch-operand path already
performs (infer_find_arrow_domain_type_in_tree), now written to the
operand atom's own facts; it is scope-naive (whole-tree, first match),
recorded in the frontier note, and deletes with the other specimen-scope
rules when the resolver hands infer declaration-resolved identities. The
tree is threaded through the fold's init chain to reach infer_node_facts;
the helper had exactly one caller.

Measured on the door specimen (scratch probe, uncommitted): 2 underived
of 15 -> 0. The specimen's inference frontier is fully closed, and the
production observation advances from InferenceRejected
(infer_grounding_not_derived) to EmissionRejected
(target_use_site_ownership_lookup_miss) -- a new, typed, located deficit
in the emitter, the next gate on the path.

Flip census (all three rewrites verified by execution):
- dag_binding_denotation_leaves_unbound_operand_atoms_on_the_frontier_holds
  -> dag_binding_denotation_declares_no_denotation_for_operand_bindings_holds:
  the boundary moves to the authority itself (the denotation table returns
  Absent for x/y), true regardless of infer's other rules.
- The three emit_host classical-not refusal guards (canonical, staging,
  staging-swapped) flip to acceptance witnesses pinning the emitted text's
  shape -- the real-infer tree now fully derives, and the emission is the
  same one the equals-eval witness proves behaviorally correct. The
  translate-refuses-underived behavior stays enrolled on hand-staged
  fixtures in translate_underived_refusal_test.dag (14/14 green). The
  renames are carried into the commit_workflow and witness_deferral_freeze
  rosters.
- New witnesses: binding_reference_derives_parameter_atoms_holds (evidence
  is the domain's Int binding atom, census 2) and
  door_specimen_fully_derives_holds (0 frontier of 15).

Full battery at this state: refusal suite 14/14, grounding wall 12/12,
instrument 2/2, binding-denotation 2/2, product-introduction 4/4,
atom-rules 5/5, emit_host 14/14, round-trips 4/6 (2 enrolled reds
unchanged), bridge 9/9, cross-language 4/4, neutralization 6/6 + e2e 6/6,
branch 2/2, eval-thesis 6/6; door production group still enrolled-red
(unchanged).

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Green the direct-rust-door: route emission through produced-decl composition and decode canonical operator wires

The door specimen's inference frontier is fully closed, so its production
observation now reaches the emission stage. Two defects surfaced there, both
fixed here:

Emission composition. generate_rust_emission_candidate served two lanes with
one root shape: the door's production path (a dag module shell) and a fixture
lane (a bare rust Arrow). The translate ownership gate queried the module
atom's ownership at a struct-field use site and refused with
target_use_site_ownership_lookup_miss, because the module's grammar-projection
conj was misread as a type record. The door's real composition is the
produced-decl path: collect declaration conjuncts from the inferred tree and
emit via emit_produced_decl. A new generate_rust_module_emission_candidate does
exactly that, enforcing an exactly-one-declaration admission policy
(rust_module_emission_decl_absent / _ambiguous). The observation and production
mint paths switch to it; the fixture-lane candidate is retained with a note
that it is fixture-only. A pure collector, produced_decl_conjs_in_tree, finds
nodes of produced-decl shape (a Conj whose first child is a Named edge to an
Arrow). Its decl-head match routes through a declared FreeMonoid<Edge>
parameter because the v1 seed stamps pattern variables from a declared
parameter type, not from a field-access scrutinee.

Operator decode. With composition fixed, source fidelity still refused: the
door emitted fn add(x: i32, y: i32) -> i32 { AlgebraPrimitive(x, y) } instead
of { x + y }. Resolution canonicalizes a surface operator atom into a
canonical-operation wire node, so a production tree's transform operator
position carries the wire, while fixture trees that bypass resolution still
carry the surface token atom. translate_project_transform_in_arrow_scope only
knew the surface-token table, so the wire missed and fell to callable apply,
rendering the discriminant identity. The projection now tries the wire decode
first (canonical_operation_from_wire_node) and only on a wire miss falls to
the surface-token table, then to callable apply; the arms are disjoint, so the
dispatch adds no fallback widening. target_transform_operator_child extracts
the operator child safely.

The door's closing expectation now greens by execution, so its known_red_probe
row in explicit_witness_admission is deleted per its own dissolution condition,
and the roadmap authority note, the door contract note, and the direct-path
plan are updated to record the green state. realized_closure_for_v2_direct_
rust_door_emit_run's module list reflects the produced-decl route.

Verified by execution: the door witness greens; the fixture, containment,
algebra, produced-decl, add-slice, and classical-not witnesses stay green;
claim_executor required-ci lanes build and witnesses both exit 0; cargo fmt and
clippy --all-targets -D warnings are clean. One pre-existing red,
witness_projection_is_active_only in the floor_cost_debt containment roster,
reproduces on the base revision and is unrelated to this change.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Close the parse-product grounding frontier: widen declared-inhabitant membership to the closed ingest set

The declared-inhabitant roster-membership derivation in 04_infer generalized
from the dag roster to the closed ingest set (dag, python, typescript):
infer_node_declared_in_language_inhabitants returns the declaring authority's
roster root as evidence, with deep subtree membership so a declared
inhabitant's leaf fact atoms derive exactly as the inhabitant node itself.

Measured: the python fixture's 19-node frontier and the typescript fixture's
28-node frontier both close to zero; all four add-slice stall population
round-trip witnesses green; the python->typescript cross-language compile
accepts, byte-identical to ts_source_text.

Section 4b(4) flips (expecting-red probes becoming permanent regression
controls for the acceptances):
- cross_language_compile_refuses_canonical_underived_holds ->
  cross_language_compile_python_to_typescript_round_trip_holds
- inhabitant_neutralization_emit_after_neutralize / same_flavor_python /
  go_int64_to_ts refusal helpers -> round-trip controls
- inhabitant_neutralization_python_to_ts_cross_language_compile (e2e) ->
  round-trip control; python->go members stay refusal guards (go is outside
  the closed ingest set)
- cross_language_emit_inhabitant_neutralization_refuses_underived_holds ->
  round-trip control; the python->typescript emit-matrix row reads ChainProven

The add-slice stall's next-rung trigger fired, so it retired per DESIGN
4b(4): removed from all_guarantee_stalls, row file deleted, witnesses stay
enrolled.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Promote the add family to SelfEmittedNative: native-only verdict witness for the emitted add crate

First InterpreterRetained -> SelfEmittedNative promotion after classical_not,
executing the v2-emitter-first-behavioral-module first slice at the
coverage-frontier grain: the add family (fewest dependencies — integer
literals plus one canonical operation) now carries a native-only verdict
witness, so its behavior is established by the emitted crate's own stdout
with eval() unreachable from the verdict path.

- emit_host_native_only_add_holds: real emit -> cargo build -> native run,
  stdout pinned to the family's expected octet, sharing the kernel family's
  one-build cache key exactly as the classical_not arm shares its family's
  key (no duplicated cold build).
- emit_host_native_only_add_wrong_octet_mismatch_detected_holds: the broken
  control — a no-eval verdict has no oracle leg to break, so the expectation
  side breaks (an octet the run never produces must not match); program-side
  discrimination stays with the family's equals_eval primitive-five/six pair.
- The add coverage row flips disposition with its backing citation enrolled
  by construction (the verdict entry is file-grain enrolled in
  falsifier_self_host_wet_template_entries).
- Frontier census tests updated at identity grain: natives are exactly
  {classical_not, add}; split 2/13.

Verified by execution: all six native-only verdict tests green locally
(real wet legs — compile_skipped receipts show cold builds and native runs);
all eight emit_coverage_frontier tests green, including the unbacked-claim
RED control.

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* Record the add-slice defect's repair in the declined-live-tree classification

The row classified candidate_generation_translate_self_emit_dag_add_slice_holds
as RealDefect/CompilerBehaviourRefusal with measured evidence that translate
refuses infer_grounding_not_derived. The owner lane (v2 self-host) repaired the
subject: the declared-inhabitant roster-membership derivation grounds the
slice's type spine by lookup, and the witness passes under claim_batch
--hermetic on the merged tree. The dated classification is kept verbatim; the
disposition flips RoutedToOwner -> RepairedInThisChange with the repair
measurement appended to the evidence, so the routing carrier stops dispatching
a fixed defect. Structural witnesses (count 13, no NotReproduced, exact
partition) are untouched and pass.

* Hoist two in-body annotation blocks to module-item grain

Main's annotation-placement wall (source annotations admit only standalone
leading blocks attached to module-scope declarations; in-body forms refuse)
reached this branch through the merge and refused 8 blocking errors on the
00_compile closure: the add-family promotion note inside the
emit_coverage_frontier_roster list and the python->typescript row note inside
the cross_language_emit_matrix list. Both blocks move above their enclosing
declarations, rephrased to name their subject row. Measured: gunbc compile of
src/v2/compiler/00_compile.dag now emits 172 files with 0 blocking errors;
both files' suites stay green (8/8 and 4/4).

* Promote the complement family to SelfEmittedNative: native-only verdict witness for the emitted logic family crate

The complement family's native execution runs family-grain per the
witness_family_build_grain_ruling (one crate for meet + join + complement,
argv-dispatched), so the native-only arm emits the logic family crate and
runs the complement member through the family dispatcher, sharing the
family witness's one-build cache key. The verdict is decided solely by the
emitted native run's stdout (expected octet 0, complement(True) = False);
the broken control flips the expectation side (octet 1 can never match),
with the comparator pinned by the stdout mock pair. Program-side
discrimination stays with the equals_eval agreement pair and the family
witness's all-alt leg.

The frontier row's backing citation lands in the already
file-grain-enrolled native-only verdict entry, so it is enrolled by
construction; the roster comment is rephrased to cover both 2026-09-07
promotions (add and complement). The frontier test's split and native
membership assertions move to 3 native / 12 retained.

Verified by execution: claim_batch --hermetic on
emit_host_native_only_verdict_test.dag passes all 8 witnesses (the two
new complement arms included), and emit_coverage_frontier_test.dag
passes all 8.

* Key the emitter's host-String arm on declaration provenance, not spelling

is_host_text_carrier_type answered true for any type expression whose
authored name reads "String", including references to the structural
alias v2.std.text.String (type String = FreeMonoid<Char>) that the
namespace lane (gunbc#9907) requalified the v2 corpus's text-carrier
fields to. The emitter rendered every one of those references as the
host String while value-position consumers rendered the structure -- the
E0308 family dominating the self-host compile-phase frontier (41 of 64
in v2_compiler_tokenize.rs on the post-merge board).

The String arm now consults the resolved declaration's provenance
against v1.compiler.coercion structural_declaration_modules_for -- the
same roster type_realization_decision reads -- so the legacy arm and the
strict decision cannot diverge on one node (DESIGN section 3, and
gunbc.recurring_failure_mode alias_resolution_collides_with_kernel_spelling).
Kernel mints and unresolved references keep the host answer exactly as
before.

Regen: the only drifted stage0 mirror is v1_compiler_emit_rust.rs
itself (no module in the stage0 closure references a structurally
declared String -- verified by the whole-population candidate tree),
installed from target/stage0-regen-candidate after the priced round's
partitioned rebuild refused MirrorHasNoOwningPackage on the emitter
(the emitter is monolith-shell, not partition-owned). Fixed point
verified by execution: claim_executor --required-regen on the rebuilt
seed reports first_generation_equal=true over 158 adjudicated mirrors.

* Peel qualified String alias leaves in field position: XL-N closure 72 -> 28 errors

A field authored v2.std.text.String reached the Rust emitter as an overlay-less
resolved reference leaf and rendered the bare terminal name, which binds the
prelude String cross-module (#9813: kernel names are never overridden by
imports, so the use-line is dropped) while every value position renders the
structural carrier Rc<Vec<i64>> -- the v2_compiler_tokenize.rs E0308 family,
41 of 72 errors on the XL-N phase board.

The new rust_overlayless_alias_leaf_requires_peel arm in
render_rust_type_without_applied_binding detects the population (overlay-less
zero-parameter alias leaf, qualified spelling, String terminal segment,
closed_alias_peel_verdict agrees) and renders the alias declaration's resolved
right-hand side, projecting the same realization the fn-signature positions
already produce.

The qualified gate is load-bearing: inside the declaring module the bare name
is the correct render (the emitted module carries the alias declaration), and
the local binding's resolved_type drops the RHS type argument, so an ungated
peel rendered Rc<FreeMonoid> there (E0107 x13, E0282 x2 on the probe). Bare
String keeps denoting the kernel scalar through the host-carrier arm.

Measured: probe specimen (qualified/bare/direct-FreeMonoid/container/variant/
local-alias positions) compiles clean; XL-N compiler closure cargo check
72 -> 28 errors with the residual census dominated by the declared
text_boundary_identity_wall class (kernel String vs structural carrier at
bare-authored boundaries, 17 of 20 E0308s); v1-corpus fixed point holds
(first_generation_equal=true, 158/158 adjudicated).

* Resolve the 12 non-hop XL-N closure errors at source: text-wall conversions + witness_violates helper

Four clusters, all measured non-hop additions between receipt_1 (155) and the
post-peel census (28); the live gate now measures 15 with zero unadmitted
regressions:

- integer.dag: integer_string_to_decimal_digits_step takes v2.std.text.String;
  the public boundary converts with chars() (text_boundary_identity_wall
  specimen discharged at this site).
- 01_tokenize.dag: Token/UnboundSourceAnnotation lexemes convert structural
  -> host String with chars_to_string() at construction, mirroring the v1
  tokenizer's host-lexeme carrier.
- target_model.dag + bash.dag: EmitSpellingEscape.from/to and
  apply_emit_spelling_escapes go structural (v2.std.text.String); the
  EmitSpellingQuote arm converts host->structural->host at its boundary;
  bash's escape rows wrap their kernel String literals with chars().
- witness.dag + 3 call sites (collection list_nth, provenance
  span_index_resolve_textual_locus_from_ids, compile outcome_with_diagnostics):
  new witness_violates<C> helper puts Violates constructions in a
  Witness-headed position so the emitter resolves the carrier type argument;
  dissolves once inference records per-call substitutions.

Verified: 48 targeted claim witnesses green (tokenize behavioral, shell
conformance, string brace escape, string length, map-lookup violates, source
text ingress, bash materialize x12, int literal smoke x6, provenance span
index x2).

* Record receipt_2 on the self-host compile-phase frontier: 15-error census at 66765317ec

The census at the XL-N lane tip: 155 -> 15 net, credited to the qualified-alias
peel (60cbd7b697, 72 -> 28) and the twelve-error source cluster (66765317ec,
28 -> 15). The epoch changes on the instrument's target pinning (found by
review on gunbc#9857), admitted with receipt_1's board as the reclassified
predecessor under the identity map. Nine added identities are hop relocations
admitted by the hop index; four sit in python/typescript modules newly entered
into the emitted closure, admitted as ExposedByNewEmittedModule.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* Emitter: a substituted declaration node carries its own provenance

Inference substitutes the resolved declaration into a data annotation's
type-argument position, so BooleanAlgebra<v2.std.logic.Bool> reaches the
emitter with the arg BEING the type Bool = True | False declaration itself
(Disj connective, ident_span in src/v2/std/logic.dag, no Resolved wrapper).
type_reference_provenance_in_env's bare-leaf arm re-resolved that leaf in the
REFERENCING module's scope, where post-#9813 a kernel-shadowed spelling
answers the kernel declaration -- so the structural enum rendered as host
bool against a value of BooleanAlgebra<Bool> (the python.rs:328 /
typescript.rs:177 E0308 pair on the XL-N compile-phase frontier).

The connective is the discriminator: a reference node is a bare name
(NoConnective); a node carrying Conj/Disj structure IS the declaration, and
type_reference_provenance's own-span fallback already answers that shape
correctly. The guard routes declaration-shaped nodes there directly, bypassing
the scope lookup that #9813 makes answer the kernel.

Mirror regenerated via the regen round; fixed-point verified
(claim_executor --required-regen PASS).

* Clear the remaining XL-N closure errors at source: carrier conversions at the boundaries

The receipt_2 census's fifteen identities, resolved at their sources:

- lexing.dag, dag.dag, python.dag, typescript.dag: LexPattern.text is the
  structural carrier (v2.std.text.String); the construction sites held host
  Strings. Convert at construction with chars() -- the #9907 ingress pattern.
- python.dag / typescript.dag bool groundings: qualify the annotation as
  BooleanAlgebra<v2.std.logic.Bool>; with the emitter's substituted-
  declaration provenance guard the qualified arg now renders structural.
- target_model.dag: target_lex_rule_literal_step returns the host carrier
  (chars_to_string over the structural pattern text); TargetText.source
  converts at the is_empty boundary; the unicode-scalar symbol intern converts
  its single-codepoint list to the host carrier.
- qualified_name.dag: qualified_name_from_dotted_string uses the host-carrier
  emptiness check (string_length == 0) instead of routing through the
  structural string_is_empty.
- 02_parse.dag: parse_looks_like_match_arm_start rewritten on host-carrier
  operations (string_length, char_at, code_point) rather than converting to
  the structural carrier for a two-character lookahead;
  parse_char_is_arm_pattern_lead takes the codepoint Int directly.
- v1_interpreter_primitive_surface.dag row_key: the concat pipeline lowered
  to a .concat() method call on std::string::String (E0599); rewritten as
  nested concat calls.

Measured: the 00_compile closure emits 172 files and cargo check reports
cargo_clean=true, cargo_error_population=0 under the pinned 1.93.0 toolchain.

* Pin the cargo half's toolchain channel by construction

The cargo half runs with cwd = a fresh mktemp directory; with no
rust-toolchain.toml there, rustup resolves the host's DEFAULT toolchain, so a
census under cargo 1.83 and one under cargo 1.93 would compare as equal epochs
while different compilers did the measuring -- the fabricated comparability
the target pin (gunbc#9857) excludes, one level up. Measured 2026-09-07: a
host default of 1.83.0 met a crates.io index whose freshly published
dependency manifests require edition2024, resolution failed before any
diagnostic existed, and the zero-diagnostic refusal fired on an unmeasured
tree.

The pin is propagated by copying the repo's rust-toolchain.toml into out_dir:
the file remains the sole in-repo channel authority (its header forbids a
second pinned literal), and the copy makes the measured channel true by
construction on any host. The gate's read_live_toolchain observes the same
channel because every documented actuator invokes from the repository root,
which the same file governs.

* Record receipt_3 on the self-host compile-phase frontier: the emitted closure's cargo census is empty

Measured at 5ee4892b70 by the one-entry instrument: the 172-file emitted crate
reports zero cargo error diagnostics, so the board attributes every phase a
count of zero and furthest_phase_reached stands at Borrowck. The fifteen
removals against receipt_2 need no disposition; nothing was added.

The epoch does not change: the cargo half now pins the toolchain channel by
copying the repo's rust-toolchain.toml into the scratch crate, and every
recorded comparison field is identical to receipt_2 (whose census the
fingerprint evidence shows the same 1.93.0 toolchain already compiled), so the
same-epoch arm carries no reclassified predecessor.

The frontier-state pin flips per DESIGN 4b(4):
the_published_frontier_standing_does_not_claim_typeck_or_borrowck_passed
becomes the_published_frontier_standing_claims_typeck_and_borrowck_passed, the
permanent regression control over the green state.

Validated: all 36 self_host_compile_phase_frontier_witness claims PASS,
including current_persisted_compile_phase_frontier_holds.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-failure-modes.md
Ledger-Repair-Judged: docs/design-rung-drops.md

* Remove the stale PointwisePower inhabitant rows from the four language rosters

First native-parity divergence class found by running the emitted closure on a
discriminating fixture: the algebra inhabitant rosters still carried
PointwisePower after its authority row was cut, so the emitted compiler panicked
at 12 record-shaped carrier sites while the interpreted seed refused cleanly.
The roster rows are removed in rust/python/go/typescript types.dag, the derived
coercion assertions in compiler_tests.rs regenerate without them, and two
witnesses pin the boundary: the record shape constructs its structural carrier,
and FinitePowerSet still refuses while its row stands.

Mirrors regenerated by a converged regen round (fixed point Reached, stage-1
PromoteGenerationInputs over the three language types mirrors).

* Regen gen-2 gate: compare executable digests in one spelling

The admitted side of run_built_seed_regen carries the executable-digest
spelling (current_exe_digest, next_pass_executable_digest) while the observed
side hashed the file through path_digest, which prepends the fnv1a64: tag.
Same bytes, two spellings, so the gate could never pass -- unpassable since
fa2d403dc8 (#9771). Factor current_exe_on_disk as the single path authority
and read the observed digest through current_exe_digest so both sides spell
the same bytes the same way.

* Model ReleaseScopeEmpty for release-excluded mirrors, end to end

A regen round whose only stage-2 drift was compiler_tests.rs (the PointwisePower
roster removal rewrote its derived coercion assertions) refused the rebuild
MirrorHasNoOwningPackage: the mirror is owned by no partition package, because
every item it defines is #[cfg(test)] and no release unit elaborates it. The
refusal conflated two different states -- unowned (a coverage hole) and excluded
from the release build by construction (a precise empty scope).

The model now names the class: rebuild_scope_release_excluded_mirrors rosters
its members (compiler_tests.rs, cited to emit_compiler_tests_module), the
decision answers ReleaseScopeEmpty when the whole change set is excluded, and
the actuation shape is actuatable with an empty package closure and every
partition package excluded -- the build still runs as verification, and a
compiled partition package refuses the stage. The host admits the empty closure
only when the new stage0_partition_rebuild_release_scope_empty_today query
answers true; any other empty closure still refuses. A mixed change set scopes
on its release-visible members alone.

Verified by execution: the 2026-09-08 round converged (fixed point Reached)
with stage-2 installing compiler_tests.rs alone; cargo recompiled the shell
crate on its fingerprint (the outer mod line is ungated, so rustc reads the
file) while the produced executable was byte-identical -- stage input seed
digest == output seed digest. Four new witnesses pin the arm, its actuation
shape, the mixed set, and the host-facing query's two arms; the boundary
witness (unowned cli_run.rs still refuses) keeps the roster from decaying into
the absorbing fallback.

* Round-cost receipt: project installed mirrors to the model's vocabulary

The receipt's partition-rebuild line is rendered by the model over
receipt.installed_mirrors, which the host populated from the stages'
projected_paths -- full paths -- while the partition rows and rosters key on
basenames. Every drifted round's receipt therefore rendered a spurious
RebuildScopeRefused MirrorHasNoOwningPackage line naming a full path, a false
claim on the round's own receipt. Route the projection through
emit_path_basename, the module's single path-to-basename bridge, so the field
carries the mirror names the model's vocabulary means.

* Hoist ReleaseScopeEmpty annotations to module-item grain

The ReleaseScopeEmpty modeling commit placed three // blocks inside
declaration bodies (stage0_partition_rebuild_is_actuatable,
stage0_partition_rebuild_decision, stage0_partition_rebuild_excluded_today).
The .dag realization admits annotations at module-item grain only, so the
floor lane's parse phase refused the file with 12 located errors and the
run ended floor refused. The prose is unchanged; each block now sits above
the declaration it describes.

* Spell the PointwisePower witness's finite-set exclusion as the applied realization

The witness added with the fossil-row removal excluded the bare spelling
"BTreeSet", but every emitted file's preamble imports OrdSet as BTreeSet,
so the row could never green. The exclusion's subject is the finite-set
REALIZATION the fossil row would have asserted; spell it applied
(BTreeSet<i64), which the preamble's import line does not contain.

* Emit fieldless-record data values as null for the unit-struct carrier

The second native-parity divergence class, measured 2026-09-08 on the
native run of the emitted 00_compile closure: emit_data_value_json spelled
EVERY record literal as a JSON map, including the zero-field record, while
emit_struct_from_children renders that same declaration as a Rust unit
struct (pub struct BoolEncodingFact;). serde's derived unit-struct
Deserialize reads null and rejects {}, so the emitted compiler panicked at
first touch of v2.std.logic's bool_primitive_facts: "invalid type: map,
expected unit struct BoolEncodingFact". The JSON spelling of a data value
must deserialize into the Rust type the same declaration emitted; the
record arm now spells the zero-field value null and keeps the map spelling
for non-empty records.

The mirror is taken from the required-regen candidate, not hand-edited.
Two witnesses enroll: the discriminating red (zero-field record spells
null, never {}) and the boundary control (a record with fields keeps the
map spelling).

* Bind the duplicate-definition filter ahead of its branch condition

Main's FilterInBranchCondition wall (#10699) refuses to publish a module
whose filter call sits in a branch condition, and the v2 00_compile closure
emission names primitive_duplicate_semantic_definition_violation as such a
site. The filter is pure and total; binding it with a let ahead of the
branch is the authored remediation the wall exists to force, and the
emitted closure is unchanged in behavior.

* chore: regenerate drifted generated artifacts (ci auto-heal)

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md rust_unit_tests_off_the_merge_path
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Ledger-Rows-Repaired: docs/design-rung-drops.md transitional_admission_exception

* Emitter: three native-parity repairs for the post-merge 00_compile closure build

Three divergence classes measured as the 21 rustc errors on the natively
emitted 00_compile closure after the main merge, each repaired at the .dag
source with a discriminating witness:

- Locality wins over a foreign ambiguity (12 E0433 in v2_std_integer.rs):
  alias_rhs_base_module_filename asked the global leaf index, saw
  LeafAmbiguous for Compose, and emitted the poison marker even inside
  v2.std.integer itself, where source resolution binds the local
  declaration before any cross-module lookup. The local physical
  declaration now shadows foreign declarers; the poison marker still
  stands for a leaf two FOREIGN modules declare.
- The qualifier is the disambiguator (8 E0425/E0433 in
  v2_lens_fact_density.rs): the qualified use-line route declined any
  globally-ambiguous leaf, but a qualified reference names its provider
  in its own spelling. The route now resolves by DeclaredCallableIdentity
  at the qualifier, keeping the type-declared and export-proof walls.
  The dotted spelling reaches the route through the value surface (a
  qualified value projection's borrowed type stamps the match patterns'
  parent_enum); the witness reproduces that chain exactly, and its
  exclude half pins the E0603 boundary (the dotted VARIANT head must
  still be declined).
- Clone-bound forwarding is transitive (1 E0277 in
  std_realization_measurement.rs): the call-forwarding derivation
  re-derived only each callee's SELF-derived half, so a callee whose
  bound is itself forwarded re-derived to empty. The derivation now
  recurses over the call graph with the module's visited-set
  termination; the equality half stays one-hop as declared.

Witnesses: 56/56 PASS on the rebuilt seed; regen fixed point holds.

* Refuse variant record literals on the serde_json data path fail-closed

A record literal with parent_enum present is a variant construction whose
wire spelling is the parent coproduct's declared VariantEncoding policy --
a module-local fact of the parent's home module that emit_data_value_json
does not carry. The zero-field arm's null and the map arm's untagged fields
are both measured to fail serde deserialization under the internal-tag
default, so the arm now refuses and the caller renders compile_error!, a
build-time located refusal where a runtime panic on the data definition's
expect was the latent alternative. The refusal names its trigger: a
closure-wide wire-policy index beside EmitGraphInfo.type_decl_items.

Witness: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
forces the JSON path with a nested-record Holder and asserts the
compile_error! spelling while excluding the former null mis-serialization.

* Spell variant record literals on the serde_json data path from a closure-wide wire-policy index

The fail-closed refusal landed in 73b582dea6 fired on 5 real corpus sites
(SugarKey x2, CopiedPortCitationFrontierDisposition x3), proving variant
record literals reach the JSON data path in the 00_compile closure. This
change replaces the refusal with the correct spelling, driven by a new
closure-wide index:

- v1.compiler.infer_emit_info gains DataVariantWireSpelling, the
  language-general projection of a coproduct's Rust wire serde policy
  for one variant (InternalTagged { tag_field, tag } | BareString { tag }
  | Untagged | SpellingRefused { reason }), and EmitGraphInfo carries
  data_variant_wire_spellings: Map<String, DataVariantWireSpelling>
  keyed by coproduct.variant.
- v1.compiler.emit_rust builds the index once per emission root via
  build_data_variant_wire_spellings, resolving each coproduct's policy
  through the new shared resolve_emission_coproduct_wire_policy (the
  same function the type-emission side now calls, so the two cannot
  drift), projecting each variant through data_path_wire_variant_tag
  (rename_all and StripAffix aware), and poisoning collisions as
  SpellingRefused so ambiguity stays fail-closed.
- v1.compiler.emit's emit_data_value_json variant arm reads the index:
  internal-tagged spells {"_variant": tag, ...fields}, bare-string
  spells "tag" for nullary and refuses fielded, untagged spells the
  bare fields or null; unindexed keys and stored refusals remain
  compile-time errors. The service mock-property chain threads
  emit_info through so dry-run data spells identically.

Witnesses: w_variant_record_lit_on_the_json_data_path_refuses_fail_closed
is rewritten as ..._spells_the_internal_tag (asserts the internal-tag
map, excludes the former null mis-serialization and the refusal), and
w_fielded_variant_record_lit_on_the_json_data_path_spells_tag_and_fields
pins the fielded case. 57/57 witnesses pass; regen fixed-point holds.

* Promote field_access to SelfEmittedNative on the emit coverage frontier

Fourth native-eval construct promotion, after classical_not, add, and
complement. The native-only verdict arm pair lands in the already
file-grain-enrolled long/ entry, so the backing citation is enrolled by
construction:

- emit_host_native_only_field_access_holds pins the family one-build
  cache run's stdout to octet 9 (the byte the family witness's warm leg
  pins on the same build), eval() never called.
- emit_host_native_only_field_access_wrong_octet_mismatch_detected_holds
  breaks the expectation side with octet 1, the alt tree's byte.

Both arms verified wet locally (real cargo build + native run, sharing
the field_access family one-build cache key). The roster row flips to
SelfEmittedNative; the two census guards update per 4b(4) — the split
moves to 4 native / 11 retained and the identity-grain membership guard
is renamed to name the four-member population. The family's equals_eval
agreement pair stays enrolled as its program-side discrimination leg.

* Drop the scratch parity probe from the tree

The probe is a manual parity-loop instrument (the interpreted leg of the
native-vs-interpreted comparison), not a corpus declaration with an
executing consumer (DESIGN 6 experimental residue). It stays in use
locally as an untracked file.

* Promote match, loop, and fold_closure to SelfEmittedNative

Fifth, sixth, and seventh native-eval construct promotions. The three
match_loop_fold family rows flip together on one shared family-crate
arm shape, per the witness_family_build_grain_ruling: each arm emits
the three-member family crate once and runs its own member through the
argv dispatcher against the family one-build cache key.

- emit_host_native_only_{match,loop,fold_closure}_holds pin the warm
  legs' stdout to the family's declared octet lists (match/loop
  [0,1,0,0,0], fold [0,7,0,0,0]), eval() never called.
- The wrong-octet controls break the expectation side with each
  member's own alt octets (match/loop [0,2,0,0,0], fold
  [0,255,255,255,255]).

All six arms verified wet locally. The census guards update per 4b(4):
7 native / 8 retained, and the identity-grain membership guard is
renamed to witness_native_rows_closed_membership_holds so the name
stops encoding the volatile population.

* Promote meet_join to SelfEmittedNative on the emit coverage frontier

The meet_join family's native-only verdict arms land on the complement arm's
helper, generalized to take the family member_id: meet and join run through
the same argv-dispatched logic family crate (one-build cache key shared with
complement, per the witness_family_build_grain_ruling), eval() never called,
verdict decoded from stdout. Octets meet=1 join=1 are the bytes the family
witness's warm legs pin on this same build; the wrong-octet control expects
each member's alt byte (0), which the primary runs can never produce.

Both arms verified wet: cold build then warm hits, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (eighth promotion); census
guards move to 8 native / 7 retained with meet_join_eval_subject named in the
closed membership.

* Promote variant_construct to SelfEmittedNative on the emit coverage frontier

The variant_construct family's native-only verdict arms follow the
field_access arm shape exactly: the tree is the family's own equals_eval
tree value (emit_variant_construct_eval_tree, no eval leg reachable), the
run shares the family one-build cache key that
emit_on_demand_variant_construct_native_one_build_holds colds, and the
expected octet 9 is the byte the family witness's warm leg pins on this
same build. The wrong-octet control expects the alt tree's byte (1), which
the primary run can never produce; the wrong-value alt leg in the family
witness keeps the program-side discrimination.

Both arms verified wet: cold build then warm hit, PASS/PASS. The roster row
flips InterpreterRetained -> SelfEmittedNative (ninth promotion); census
guards move to 9 native / 6 retained with
emit_variant_construct_eval_subgraph_node named in the closed membership.

* Close the emit coverage frontier: final six rows to SelfEmittedNative

The last six InterpreterRetained rows flip to SelfEmittedNative, taking the
roster to 15 native / 0 retained:

- filesystem_read and shell_exec_run (host-effect transport families, no
  translated arrow body): the arms reuse each family's own native leg with
  the expectation pinned as a literal grounded by the family's enrolled
  fixture pin (dag/extdeps/shell/exec.dag contains bash; its shell.Exec.Run
  argv materializes to exactly [bash, -s]), run through the families' fixed
  witness workspaces.
- module and produced_module: the arms execute the exact sources the
  equals_eval pairs run (emit_module over the add fixture tree;
  produced_add_module_source's ingested two-fn module), octet 5 pinned
  against the add family's primitive-five/six oracle leg.
- call and record_construct: the arms emit the families' own producer trees
  against their target models, octets 7 and 9 pinned against the
  primitive-seven/eight and wrong-field oracle legs.

The four families without a one-build cache witness run under per-family
fixed workspace roots; content-safety comes from the realization-digest
nesting in run_host_process_admitted (changed source colds, never serves
stale), the same mechanism the filesystem_read fixed workspace relies on.
All twelve arms verified wet: PASS/PASS each, cold builds then warm hits.

With zero retained rows the retained_via_eval_agreement constructor loses
its last consumer and is deleted (DESIGN 3c); the InterpreterRetained
variant stays as the disposition authority's other state. Census guards
move to 15 native / 0 retained with all fifteen decl names in the closed
membership.

* Record the emit coverage frontier closure in the direct-path plan

Axis C line: all fifteen roster rows are SelfEmittedNative as of
2026-09-08, interpreter_retained_rows() is empty, and the row constructor
was deleted with the last flip. Notes explicitly that this closes axis (a)
(witness-body-runs-native) only; axis (b) (the regen-grain production
flip) remains operator-gated.

* Model the required-v2-native lane authority: route receipt, exclusion taxonomy, admission, enrolment gate

Parallel track B (operator authorization 2026-09-09): one additional required
CI job whose subject is the compiler/test execution route itself — the
emitted-native compiler binary invoked by explicit path over a derived
v2.test.* population.

The lane is modelled in full in gunbc.witness_v2_native_route: the prefix
universe derivation, the per-member verdict rows (head + fatal reason grain),
the exclusion taxonomy delegating attribution to the door ledger's
known_frontier_causes, the counted exclusion census with a totality check,
the terminal-observation receipt carrier, the admission predicate (one
predicate per contract clause, all causes collected), and the enrolment gate
with today's standing as data.

Enrolment is BLOCKED, as data with a named capability trigger: the measured
census over the derived universe (882 members, seed withdrawn during the run)
refused every member — the emitted DirectIngestDriver admits only the
hard-coded compile_driver_subject name with empty imports, and the compile
door is at its modelled frontier — so the contracted positive population is
empty and native_route_admission over the real receipt executed to
'refused: positive_population_empty'. The exact enrolment edit (phase-roster
variants, claim_executor mirror, workflow lane, aggregate join, YAML regen)
is carried on the standing row.

The census measured five fatal-grain refusal causes the door ledger's
head-grain attribution table did not carry; they are added to
known_frontier_causes with their owning lanes (three MigrationOwned under
nimble-boar-198, two normalize/body-lowering SharedSelfHostCriticalPath).

Seventeen floor witnesses (v2.test.v2_native_route) consume the authority and
execute green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Split preparation predicates so EmittedClosureUnrecorded is reachable

Review on #10882 (briansrls, point 7): native_route_preparation_recorded
folded the seed and closure observations into one && predicate, so a
receipt with a recorded seed and an unrecorded closure misreported as
preparation_seed_unrecorded and the emitted_closure_unrecorded cause had
no reachable construction — the grain-mismatch class DESIGN 4b(3) names.

One predicate per observation, one admission clause per predicate, and
two witnesses pinning each refusal name against its own receipt shape
(including the negative: each refuses ONLY by its own name).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Key cause ownership by diagnostic grain; classify native refusals at fatal grain

The door ledger's known_frontier_causes was a head-grain authority; the
native route classified fatal reasons through it, crossing grains (review
on #10882). Generalize the ownership key with DiagnosticGrain so one
table answers both grains: the door ledger's cause_is_attributed keeps
its head-grain contract, and the native route's exclusion classifier
asks the fatal-grain question of the same table. The head advisory is
live receipt data again: every refused row's head reason must be owned
at head grain (or by this lane's driver-limit roster), and an unowned
advisory blocks admission by its own clause name.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist known_frontier_causes row-group notes above the declaration

The grain-keyed ownership change left its row-group commentary inside the
list literal; the annotation channel admits only module-item grain, so the
emitted closure refused with nine annotation-grain diagnostics. Move the
notes to a single block above the declaration. No semantic change.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Parse test fn as a contextual production in the v2 dag grammar

The emitted native compiler could not parse any v2.test.* module: the
modeled dag grammar had no test fn production, so every floor witness
module refused with parse_g0_tokens_remain (706 of 882 in the census).

test stays an ordinary identifier — typescript/program.dag models the
TypeScript compiler's Cond.test field under real-upstream-names — so the
production is the contextual sequence(ident, fn_decl): a new choice arm
in top_level_item with no FIRST overlap with the keyword-led arms, a
body-lowering arm that lifts the nested fn member after checking the
marker lexeme is literally test (a typed refusal otherwise), and a
forward-producer row for the new surface identity.

Verified against the emitted native binary: probe_testfn.dag moves from
parse_g0_tokens_remain to resolve_module_not_found (the driver's
synthetic-subject limit, identical to a plain fn), and the standing
choice-overlap residue roster is unchanged at seven rows.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add SourceRootEvalDriver: native whole-ingest test-execution route

The required-v2-native lane's terminal subject is an exact test identity
reaching a native Eval verdict, not a module accepted for translation.
DirectIngestDriver (one source, no peers, synthetic subject) stays as the
front-door census instrument; the new driver renders a main that reads a
host-derived universe of qualified test identities plus the declared
source roots, assembles the ingest once, prepares each module (resolve +
infer), and Evals each named test body -- one typed verdict row per
member, with a prepare-refusal fan-out so no member is silently dropped.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Escape literal braces in SourceRootEvalDriver main.rs template

The .dag string lexer reads '{' followed by an identifier as
interpolation, so the emitted Rust use::-import lists and format!
captures must spell literal braces as \{ \}. The single parse error
desynced the file parse and cascaded into 2618 unattributed-annotation
errors; with the escapes the emitter compiles clean (0 blocking, 107
files emitted).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Collect per-file front-end refusals in the native test context fold

The SourceRootEvalDriver's context fold reused program_assembly_fold_ingest,
which is wholesale fail-closed: one source hitting the v2 front-end's live
corpus frontier would deny verdict rows for every other universe member. The
fold now collects each source's tokenize/parse/normalize refusal as a
NativeTestFileRefusal row (head and fatal reason grains, matching the door
ledger's grain-keyed ownership) and keeps folding; a refused file contributes
no root, so its test identities surface as Context-stage refusal rows and
nothing is widened. The emitted main.rs prints the file-refusal rows and
counts them in the terminal marker, and prepare/eval refusals now classify at
the fatal (last diagnostic) grain consistently.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add native lane control fixtures

Two controls for the required-v2-native lane's host harness:
src/v2/native_lane_fixture/control.dag carries the live-verdict pair (a
well-formed false control and its true positive half) as plain fns outside
the v2.test. prefix, so floor discovery enrolls no universe rows for them;
fixtures/native_lane_malformed/poison.dag is a deliberately unterminating
string that any honest front-end must refuse at tokenize, kept outside every
declared source root so the broken bytes never enter an honest ingest.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Fix Vec/Vector type mismatches in the SourceRootEvalDriver main.rs template

The emitted driver crate aliases im::Vector as Vec, so the template's
std Vec-typed bindings and collect calls failed to compile in the
emitted crate: universe rows and module order carry Rc<Vector<String>>,
the reads vector moves into the FreeMonoid parameter with .into(), and
the dotted module name is built from an iterator collect.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Harden the v2-native route contract: test-identity grain, exact join, paired reference

Reframe the terminal subject from module-grain acceptance to the exact
test identity reaching a native verdict. The receipt's universe is a
list of qualified NativeRouteTestIdentity rows; the observed population
joins it exactly (uniqueness, no foreign rows, no omissions); every
member verdict is paired against the floor's own expected-red and
route-gap rosters for agreement, exclusion, or divergence; refusals are
classified from stage and provenance with cause ownership at fatal and
head grains; and the four controls (true, false, malformed specimen,
old-route withdrawal) are admission clauses. The 46 tests cover
universe derivation, identity qualification, reference pairing, refusal
classification, disposition, census counting, and every admission
clause.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Wire the required-v2-native lane into the roster, workflow, and aggregate

Add V2NativeLane/V2NativePhase to the required-CI roster, the lane's
claim_executor command to fabric_witness_run, and the
required-v2-native job to the witness floor workflow with the aggregate
witnesses job needing it in both verdict arms. Regenerate
witnesses.yml.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Add the required-v2-native host harness and phase dispatch

The lane's one phase derives the v2.test.* universe with the floor's
own discovery producer over the full module inventory, prepares the
emitted-native compiler through the emit-compile phase's crate writer
and cargo invocation, withdraws the old-route gunbc binary for the
spawn window, runs the emitted binary by explicit path over the
universe plus the named controls, reclassifies context-stage refusals
against the observed file refusals, mints the NativeRouteReceipt as the
authority's own types, and hands it to native_route_admission for the
verdict. claim_executor gains the V2Native lane and phase with the
roster sizes moved to six.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Regenerate stage0 mirrors for the SourceRootEvalDriver emitter arm

std_compiler_entry.rs gains the SourceRootEvalDriver variant and
v1_compiler_emit_rust.rs the emit_source_root_eval_driver_main_rs
template with its dispatch arm, emitted by the regenerated seed and
verified at the fixed point (first_generation_equal=true over the whole
155-module population).

Co-authored-by: briansrls <briansrls@gunb.ai>

* Name the probe crate's lib target v1_compiled, the emitter's self-name contract

emit_rust_selected binds the self-emitted crate's name to v1_compiled
for every non-retained-host pipeline entry, and the SourceRootEvalDriver
and DirectIngestDriver mains reach the closure through use v1_compiled::.
The probe manifest's per-entry package name left the lib target named
after the package, so a pipeline entry's driver main failed E0433 in the
probe build -- unreachable while every probe entry was pipeline-free, and
measured on the required-v2-native lane's first preparation. The lib path
stays cargo's default; only the name is stated.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Release retained emission arena before the native cargo build

The lane's first run held ~15GiB RSS from the emission's resolved graph
into the cargo build of the emitted compiler and was SIGKILLed (rc=137)
with no diagnostic. Drop the emission run and malloc_trim the retained
arena at both derivation-to-emission and emission-to-build handoffs,
reporting the reclaimed KB so a trim that cannot release live memory
shows in the lane log.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Apply rustfmt to the v2-native lane host changes

Co-authored-by: briansrls <briansrls@gunb.ai>

* Lower FreeMonoid tail to im::Vector::skip — O(log n) share, not O(n) copy

The emitter lowered every cons-match tail on a FreeMonoid to
iter().skip(1).cloned().collect(), materializing the whole tail per
step: every fold over a FreeMonoid was quadratic. Measured on the
required-v2-native lane's first native run (2026-09-09): the
self-hosted lexer, which tails the remaining source per character and
per rule attempt, tokenized a 22KB file in 23.3s against 70ms for
899B, projecting a multi-hour whole-corpus context fold — the lane's
dominant term. im::Vector::skip shares the RRB tree in O(log n).

Two mirrors carry the only cons-tail sites in the stage0 corpus:
v1_compiler_emit_rust.rs (the emitter itself) and
std_occurrence_binding_candidates.rs. The e0599 emitter-decision
census and its witness tests move to the new (skip, __fm) site with
the measured rationale. Fixed-point regen green: the rebuilt seed
regenerates both mirrors byte-identically.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Route FreeMonoid length/snoc through the count/list_push primitives

length folded the whole carrier per call (O(n)); the parse repeat loop
calls it on the remaining-token list twice per element — an O(elements x
tokens) quadratic measured at 40% of self-hosted parse self-time on the
required-v2-native lane's first native run (2026-09-09). list_snoc_item
routed through list_append, paying a full O(n) right-fold per snoc and
making every build-by-appending accumulator quadratic (measured on the
first-set union fold). count is O(1) and list_push amortized O(log n) on
the persistent-vector realization. Probe-measured on the emitted crate:
25s -> 6.6s parse on a 4k-element synthetic, 209s -> 33s on a 315KB
table module.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Hoist first-fold knowledge into prepared grammar expressions

The parse choice dispatch recomputed expr_first_fold on both branches at
every Choice node at every token position: right-nested choice chains
made that O(k^2) per position with O(t^2) union constants — the dominant
self-hosted parse cost once the algebra carriers were fixed. The grammar
is fixed for a whole parse, so each node's first fold (and each Choice's
ambiguity verdict) is a pure function of the grammar: compute it once at
preparation, bottom-up, and carry it on a PreparedGrammarExpr tree hung
off GrammarFirstAnalysis / ParseTableRealization. parse_expr keeps its
GrammarExpr signature as a compat wrapper that prepares on the fly;
parse_nonterminal_memoized_core reads the prepared map. Forecast by a
pointer-keyed memo probe on the emitted crate: 33s -> 14s on the 315KB
table module.

parse_minted_id_list also moves off list_append-per-node (O(n^2) per
captured repeat) onto a snoc fold over the list_push primitive.

Verified by execution: 29-test battery over parse_table_claims,
grammar_validation (left-recursion suite), parse_token_first_empty_
semantics, parse_table_content_key and parse_table_memo_governed_witness
all green through the seed interpreter.

Co-authored-by: briansrls <briansrls@gunb.ai>

* Deref boxed variant fields in enum shared accessors

The storage side boxes a variant record…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants