Skip to content

Model native-compiler ancestry so the seed is never the recurring producer - #11042

Merged
gunbai-bot[bot] merged 12 commits into
mainfrom
session/keen-wolf-909
Sep 12, 2026
Merged

gunbai-bot[bot] merged 12 commits into
mainfrom
session/keen-wolf-909

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

ANCESTRY lane, part 1 of 2 — the model. Operator design-review ruling 2026-09-11 C1: the seed is never the ordinary miss path.

What was wrong

The v2-native route acquired "the emitted compiler" by running the v1 seed in-process on every miss (prepare_emitted_compiler → compile_entry_emission). Read as one execution that is correct and honestly receipted. Read as a migration it is the defect: the seed is not a step in the route that retires it, it is that route's standing producer. A replacement whose miss path is the thing being replaced retires nothing, and its removal date is unreachable because nothing ever stops depending on it.

Filed as a class: gunbc.recurring_failure_mode.the_replaced_route_is_the_replacement_s_miss_path, with the boundary against its neighbour absorbing_fallback stated — that class widens an answer, this one widens the lifetime of the thing being replaced.

The model

v2.compiler.self_host.ancestry — exactly two constructors, no third:

GenesisFromSeed   V1SeedEmitter        -> generation 0       once, then deleted
SucceedsNative    V2EmitterNative(N)   -> generation N + 1   the only recurrence
  • No arm resolves to the seed. NativeAncestorAcquisition's Missing and Unverified arms carry no producer at all, so a caller cannot pattern-match its way back to v1. The refusal names the generation it expected and why the candidate did not qualify.
  • The producer vocabulary is reused, not re-coined. native_generation_producer projects this module's ancestry onto the existing EmitterProducer coproduct in v2.compiler.self_host.emitter_producer_provenance. No second producer coproduct; no used_seed: Bool anywhere — a Boolean would carry the fact while leaving both routes writable on either value.
  • V2EmitterInterpreted is reachable from no arm. An interpreted emit is a development route, never an ancestor; making it unprojectable is stronger than refusing it downstream.

The mint refuses by named cause, per arm:

arm clause
genesis generation is 0; closure must reach v1.compiler.emit_rust (a genesis that did not run the seed is not a genesis); build path pinned or remapped; read-back agrees
successor generation is parent + 1; closure reaches neither the seed emitter nor the interpreted emitter (two causes, not one "not native" verdict); build path remapped — pinned is refused; read-back agrees

ReadBackReceipt carries only what was observed and never a verdict; divergence is derived by comparing the report against the generation's own observed artifact digest, so a "verified" state cannot be authored beside a report that contradicts it.

Genesis executes once — a second is a refusal naming the one that stands — and carries its deletion trigger at the grain of the capability that retires it (§4b meta-obligation 3), not at the grain of an artifact that would contribute to one.

Executed evidence

v2.test.claim.self_host.ancestry_witness, 17 controls, run via claim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/self_host/ancestry_witness_test.dag --functions <all>.

17/17 PASS on the module as written.

Falsification pass — not a green table on its own. With native_producer_closure_admission weakened to admit unconditionally and both read-back arms weakened to NativeGenerationAdmitted, exactly five controls flipped and twelve stayed green (no smear):

FAIL successor_whose_closure_reaches_the_seed_is_refused
FAIL successor_whose_closure_reaches_the_interpreter_is_refused
FAIL successor_without_a_read_back_is_refused
FAIL successor_whose_read_back_diverges_is_refused
FAIL unverified_ancestor_carries_the_mints_own_cause

genesis_whose_closure_omits_the_seed_is_refused correctly stayed green — it reads the genesis arm's own check, which the mutation did not touch.

Every fixture is Optional-valued and no control substitutes a value for a digest that failed to parse: Sha512Digest is reachable only through the validating mint, so a broken fixture reports as a red control rather than a green one exercising a stand-in.

What this PR does NOT claim

  • BuildPathTreatment does not discharge artifact_axis_omits_build_path. It is the declaration that obligation's two remedies were waiting for, and nothing more: remapping is a property of the build that produces the bytes, not of a carrier describing it. The obligation stays unbound until the emitted compiler is actually built with the remap and a two-directory control observes identical bytes. Binding it here on a declaration alone would be rung inflation.
  • Rung honesty. The relation is at rung 4 — with no seed-reaching constructor on the recurring arm the invalid state has no inhabitant. The host route is still at rung 1: prepare_emitted_compiler still calls the seed emitter. A class's rung is the minimum across its paths, so the class's rung today is the realization's, and the failure-mode row says exactly that.

§3c consumption, stated plainly

In this PR the model's consumers are its 17 executed controls. The production consumer is a declared frontier, not a dangling model: scope item 4 replaces prepare_emitted_compiler's compile_entry_emission call with acquire_native_ancestor, and item 5 renames OldRouteWithdrawn to OldRouteAbsentByConstruction (the closure half of which native_producer_closure_admission already decides here, once, rather than re-derived beside the route receipt).

Trigger, and why it is a separate PR: #10940 is open and its diff touches both src/v1/stage0/src/cli_run/native_lane_runner.rs and dag/gunbc/witness/v2_native_route.dag — exactly the two files items 4 and 5 edit. The brief's own base instruction is "main after #10940 lands," and its own ordering is declarations first, host realization second. Part 2 lands on top of #10940.

Until V2EmitterNative(N) -> N+1 executes and verifies, the native route stays operator-invoked and non-blocking (claim_batch --v2-native-route); this PR changes no CI workflow and adds no job.

🤖 Generated with Claude Code

…ducer

The v2-native route acquired "the emitted compiler" by running the v1 seed
in-process on every miss. Read as one execution that is correct and honestly
receipted; read as a migration it is the defect, because the seed is not a step
in the route that retires it — it is that route's standing producer. A
replacement whose miss path is the thing being replaced retires nothing, and its
removal date is unreachable because nothing ever stops depending on it.

v2.compiler.self_host.ancestry models the relation with exactly two arms:

  GenesisFromSeed   V1SeedEmitter      -> generation 0      once, then deleted
  SucceedsNative    V2EmitterNative(N) -> generation N + 1  the only recurrence

There is deliberately no third constructor, and no arm by which a missing or
unverified ancestor resolves to the seed: NativeAncestorAcquisition's Missing and
Unverified arms carry no producer at all, so a caller cannot pattern-match its
way back to v1. The producer axis is projected onto the EXISTING
EmitterProducer coproduct rather than re-coined, and there is no used_seed Bool
anywhere — a Boolean would carry the fact while leaving both routes writable on
either value.

The mint enforces, per arm and by named cause: genesis is generation 0 and its
closure must reach v1.compiler.emit_rust (a genesis that did not run the seed is
not a genesis); a successor is parent + 1, its closure may reach neither the seed
emitter nor the interpreted emitter (two causes, not one "not native" verdict),
its build path must be remapped rather than pinned or unresolved, and its
read-back must report the digest observed of the bytes that were built. Genesis
executes once — a second is a refusal naming the one that stands — and carries
its deletion trigger at the grain of the capability that retires it.

BuildPathTreatment is the declaration the artifact_axis_omits_build_path
obligation's two remedies were waiting for, and it does NOT discharge that
obligation: remapping is a property of the build that produces the bytes, not of
a carrier describing it, so the obligation stays unbound until the emitted
compiler is actually built with the remap and a two-directory control observes
identical bytes.

Evidence: 17 executed controls in v2.test.claim.self_host.ancestry_witness —
positive controls for both arms and for acquisition, plus seven discriminating
reds (seed on the recurring path, interpreter on the recurring path, no
read-back, diverged read-back, wrong generation number, each build-path
treatment, genesis without the seed) and the genesis-once, missing-ancestor,
wrong-generation, stale-identity and artifact-identity-join controls.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot gunbai-bot Bot changed the title Close the decl-index blind spot: a bare String-literal data initializer projects no atom identity, so v1 consumer discovery misses it (repair in v2.std.decl_index, not the instrument); flip the census's go-red witness to a regression control and re-discover Model native-compiler ancestry so the seed is never the recurring producer Sep 11, 2026
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 11, 2026 11:29
…tier in the diff

Two findings, both verified before fixing.

native_ancestor_acquired had ZERO call sites — not in the module, not in the
witness. Counted across all twelve functions; it was the only one at zero. It
was a Bool collapse of a three-arm coproduct with no reader, which is DESIGN
section 6's experimental-residue tell exactly. Deleted.

The frontier was UNDECLARED, not declared. The acquisition note stated
consumption in the present tense as though the route already called this
surface, and the only trigger in the diff — genesis_migration_deletion_trigger —
retires the GenesisFromSeed CONSTRUCTOR, which is a different condition from
retiring the seed CALL. Stating the frontier in the pull request body and not in
the diff is the tell DESIGN section 3c names verbatim. So: the note now says
WILL consume and points at the row; native_route_acquisition_frontier names the
consumer (prepare_emitted_compiler), the route at execution, and its own trigger
(that function's compile_entry_emission call replaced by
acquire_native_ancestor); and the two triggers each say why they are not the
other.

Not asked for, but section 4c forbids it by name: both triggers were bare
data ...: String rows, which is "an ordinary String declaration whose sole
purpose is commentary". Both are now DissolutionCondition via
unbound_dissolution, matching how v1_consumer_census and
self_host_promotion_obligations carry theirs. Both are deliberately unbound and
each states why in its own description — one is an execution verifying by
read-back, the other the removal of a call in a host realization, and neither is
a declaration appearing or retiring, so binding either would be a checkable
trigger impersonating a decision that reports fired the day it is written.

Controls re-run after the change: 17/17 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 63770 at bdb6463. Both findings verified against the code before fixing; neither is disputed.

1. native_ancestor_acquired — confirmed dead, deleted. I counted call sites across all twelve functions in the module plus the witness; it was the only one at zero. The characterisation is exact: a Bool collapse of a three-arm coproduct with no reader, which is DESIGN §6's experimental-residue tell.

2. The frontier was undeclared, not declared — fixed. The review is right on both halves. The acquisition note stated consumption in the present tense as though the route already called the surface; and genesis_migration_deletion_trigger retires the GenesisFromSeed constructor, which is a different condition from retiring the seed call, so it was never a frontier trigger for acquire_native_ancestor reaching native_lane_runner. Stating the frontier in the PR body while it is absent from the diff is the tell §3c names verbatim, and that was my state.

Now in the diff:

  • the note reads "WILL consume" and points at the frontier row, rather than asserting a consumption that has not landed;
  • native_route_acquisition_frontier names the consumer (prepare_emitted_compiler), the route at execution (the harness asks for the generation it expects; NativeAncestorAcquired supplies the artifact spawned, NativeAncestorMissing / NativeAncestorUnverified become its typed refusal), and its trigger (that function's compile_entry_emission call replaced by acquire_native_ancestor, leaving no v1 emitter reachable from the acquisition path);
  • each trigger states why it is not the other, so neither can be read as discharging the other.

One change the review did not ask for. Both triggers were bare data …: String rows, which DESIGN §4c forbids by name — "an ordinary String declaration whose sole purpose is commentary is misplaced or dead data … any … dissolution condition belongs in a typed carrier". Both are now DissolutionCondition via unbound_dissolution, matching how gunbc.v1.v1_consumer_census and gunbc.self_host_promotion_obligations carry theirs. Both are deliberately unbound, each saying why: one is an execution verifying by read-back, the other the removal of a call in a host realization — neither is a declaration appearing or retiring, so binding either to a decl ref would be a checkable trigger impersonating a decision, firing the day it was written.

What I did not do, and why. I did not wire prepare_emitted_compiler in this PR. #10940 is open and its diff touches both src/v1/stage0/src/cli_run/native_lane_runner.rs and dag/gunbc/witness/v2_native_route.dag — exactly the two files that rewiring edits. The lane brief's base is "main after #10940 lands" and its ordering is declarations first, host realization second. That makes this a declared frontier rather than a dangling module, which is what the review asked be made explicit; it does not make the module consumed by production, and the PR body and the failure-mode row both say the class sits at the realization's rung, not the relation's.

Controls re-run after the change: 17/17 PASS, including the five that flip under the falsification pass recorded in the PR body.

— sent from keen-wolf-909

…emit

ancestry_parent_artifact_not_the_producer had ZERO readers. I counted ^ readers
for all eleven cause rows; it was the only one at zero, and the SucceedsNative
arm still bound parent_artifact with a wildcard. Same class as the dead function
in review 63770 -- I swept functions for call sites and did not sweep data rows.

DELETED RATHER THAN WIRED, and the placement is forced rather than stylistic.
native_generation_mint_admission sees ONE generation, so it can read
parent_artifact but has nothing to join it against; a mint clause asserting the
parent artifact is the real parent's could never fire, which is the
specification-without-execution shape the row was already an instance of -- a
wall clause in appearance with the named state still writable. The join is
decidable only where both generations are in hand, and that fold already exists
and is already exercised (successor_names_its_ancestor, with a positive and a
red). The reason the join lives there is now recorded beside it so the mint
clause is not re-proposed.

NOT FLAGGED BY THE REVIEW, same class one step weaker:
ancestry_artifact_not_materialized had a reader but NO executed control -- a
wall clause with no red. read_back_reported_against_an_unbuilt_artifact_is_refused
reaches ArtifactNotMaterialized the only way production can, through an artifact
hex the validating mint rejects.

Controls: 18/18 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 63783 at 2801aa5e4af. Held until run 34596517766 terminated, then pushed once.

Finding confirmed and fixed. ancestry_parent_artifact_not_the_producer had zero ^ readers — I counted readers for all eleven cause rows and it was the only one at zero, with the SucceedsNative arm still binding parent_artifact by wildcard. Same class as the dead function in review 63770; I had swept functions for call sites and not swept data rows.

Deleted rather than wired, and the review's own suggestion is why. native_generation_mint_admission sees one generation, so it can read parent_artifact but has nothing to join it against — a mint clause asserting the parent artifact is the real parent's could never fire, which is the specification-without-execution shape the row was already an instance of. The join is decidable only where both generations are in hand, which is successor_names_its_ancestor, and that fold already exists with a positive and a red. The reason the join lives there is now recorded beside it so the mint clause does not get re-proposed.

One thing the review did not flag, same class one step weaker. ancestry_artifact_not_materialized had a reader but no executed control — a wall clause with no red is a weaker instance of exactly this defect. Added read_back_reported_against_an_unbuilt_artifact_is_refused, which reaches ArtifactNotMaterialized the only way production can: an artifact hex the validating mint rejects.

Evidence. 18/18 controls PASS locally on this head. On the previous head bdb6463f372, the required floor recorded all 17 controls then present with terminal verdicts — standing=planned-and-passed disposition=planned_as_changed_witness outcome=passed — so they are adjudicated on the required gate rather than returning route-gap-before-verdict. The 18th is new in this commit and will appear in this head's run.

— sent from keen-wolf-909

briansrls pushed a commit that referenced this pull request Sep 11, 2026
OldRouteAbsentByConstruction, genesis/acquire host wiring, and the
executing consumer witness now bind to v2.compiler.self_host.ancestry.
generation.dag identity/remap edits stay. Not pushed until #10940 is on
main.

Co-authored-by: Cursor <cursoragent@cursor.com>
… and 63813

TWO GAPS MEASURED BY proud-carp-305 AGAINST #11056's wiring, both real, both
verified here by reading the fold before fixing.

THE EMPTY CLOSURE IS THE SHARPER ONE. Every clause of the closure wall asks a
NEGATIVE question -- is the seed reachable, is an interpreter reachable -- and
negative questions are all vacuously satisfied by a closure that names nothing.
RealizedEmitterClosure { emitter_module_paths: [] } therefore passed the entire
wall and minted an admitted native generation, and the route-level
OldRouteAbsentByConstruction control would have greened on it. That is
bottom-as-ignorance rendered as top-as-answer -- "we did not observe the seed"
reported as "the seed is absent" -- and it is worse here than in general because
the closure carrier is the ONLY evidence this wall consults, so an empty one is
not a weak observation but no observation at all.

THE INTERPRETER CLAUSE NAMED ONLY THE EMITTER. C1 forbids a v1 emitter OR
interpreter on the recurring path, but the wall tested only v2.compiler.emit, so
a closure carrying just v1_compiler.v1_interpreter reached no forbidden emitter
and admitted. Interpreting the program that produced the bytes is producing
them. v1_seed_interpreter_qualified_module is homed in THIS module rather than
in emitter_producer_provenance deliberately: that module owns which modules are
EMITTERS and the interpreter is not one; what forbids it is the ancestry rule,
so the path it forbids belongs to the module that owns the rule.

WHAT THE WALL STILL DOES NOT ESTABLISH, recorded beside the fold rather than
left to be rediscovered: the remaining clauses are still negative, so a closure
naming one arbitrary module is admitted. This establishes that no DISQUALIFYING
producer is named, not that the prior native generation IS. The positive half
needs the admitted closure derived from the acquired ancestor, not supplied
beside it. A hand-authored required-membership roster is deliberately NOT the
remedy: it would false-refuse the moment the native producer's module set moved.

REVIEW 63813, three findings, all correct, one resolved differently than
proposed. ancestor_identity_still_current was a bare alias whose whole body was
generation_identity_agrees -- section 6's never-bare-alias and section 3's
nicknaming in one declaration, and my own note claiming the authority was
"consumed here rather than restated" was exactly the restatement. Deleted.
native_generation_admitted collapsed the admission coproduct to Bool; deleted,
and the control now matches the arms, which is stronger evidence because it sees
the cause. recurring_producer_is_native_only named the witness as its consumer,
which is the dangling state and not a frontier; deleted, and the control asserts
over native_generation_producer directly with two added negative clauses.
successor_names_its_ancestor is KEPT against the review's suggestion, because
#11056 has been rebased to consume it: that is section 3c's middle state, not
its red one, and what was actually missing is the trigger stated beside it --
the same defect review 63770 caught on acquire_native_ancestor -- so it now
carries successor_ancestor_join_frontier naming consumer, route and trigger.

REVIEW 63783 (batched, previously held): the mint-refusal cause with zero
readers is deleted, with the reason the join belongs on the two-generation fold
recorded beside it, plus a control for the clause that had a reader and no red.

EXECUTED: 21/21 PASS. Falsification of the two new walls -- empty check and
seed-interpreter check each disabled -- flips EXACTLY their own two controls and
leaves the other 19 green, so neither is silently carried by another clause.

No import was added into any closure member; ancestry.dag's only importer
remains its witness, so it stays outside the emitted closure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 63813 at b8a6ff1321, batched with review 63783 and two declaration requests from #11056.

All three findings in review 63813 are correct. Two resolved as proposed, one resolved differently on information the reviewer could not have had.

ancestor_identity_still_current — bare alias, deleted. Its entire body was generation_identity_agrees(left: ancestor.identity, right: observed_now). §6's "never bare-alias" and §3's nicknaming in one declaration, and my own note claiming the authority was "consumed here rather than restated" was itself the restatement. The control calls generation_identity_agrees directly.

native_generation_admitted — Bool collapse, deleted. Same shape as native_ancestor_acquired in review 63770, one step weaker because it had a caller. The witness adapter matches the admission arms directly now, which is stronger evidence: the control sees the cause rather than a boolean.

recurring_producer_is_native_only — deleted. Its note named the witness as its consumer, which is §3c's dangling state, not a frontier. The control asserts over native_generation_producer and emitter_producer_eq directly, with two added negative clauses.

successor_names_its_ancestor — kept, with the frontier the review correctly found missing. #11056 has been rebased to consume it alongside admit_genesis, acquire_native_ancestor and native_generation_producer, which makes it §3c's middle state — a consumer landing in a named later change — rather than the red one. What was genuinely absent is the trigger stated beside it, the same defect review 63770 caught on acquire_native_ancestor. It now carries successor_ancestor_join_frontier naming consumer, route and trigger, including why the join is only decidable where both generations are in hand.

Two declaration requests from #11056, both verified by reading the fold before fixing.

  1. The empty closure admitted. Every clause of the closure wall asks a negative question, and negative questions are all vacuously satisfied by a closure naming nothing — so RealizedEmitterClosure { emitter_module_paths: [] } passed the whole wall and minted an admitted native generation, and OldRouteAbsentByConstruction would have greened on it. ⊥-as-ignorance rendered as ⊤-as-answer, and worse here than in general because the closure carrier is the only evidence this wall consults.
  2. The interpreter clause named only the emitter. C1 forbids a v1 emitter or interpreter on the recurring path, but only v2.compiler.emit was tested, so a closure carrying just v1_compiler.v1_interpreter admitted. Interpreting the program that produced the bytes is producing them.

Executed: 21/21 PASS. Falsification of the two new walls — empty check and seed-interpreter check each disabled — flips exactly their own two controls and leaves the other 19 green, so neither is silently carried by another clause.

A boundary this does not close, stated because the green table would otherwise imply it. Refusing the empty closure closes the vacuous case; the wall is still entirely negative, so a closure naming one arbitrary module is admitted. It establishes that no disqualifying producer is named — not that the prior native generation is. The positive half needs the admitted closure derived from the acquired ancestor rather than supplied beside it. A hand-authored required-membership roster is deliberately not the remedy: it would false-refuse the moment the native producer's module set moved. Recorded beside the fold.

— sent from keen-wolf-909

…the succession join

REVIEW 63949, both findings real, and the first is the worst defect found in
this module.

(1) PARALLEL AUTHORITY. emitter_producer_provenance emitter_producer_mint_admission
is already the ONE total match over EmitterProducer x RealizedEmitterClosure --
its own annotation says so and forbids parallel predicates -- and it already
refuses a V2Emitter* producer whose closure reaches v1.compiler.emit_rust. This
module re-derived that identical verdict under a cause symbol of its own and
never routed through it, while importing the authority and projecting onto
EmitterProducer. Importing a thing is not routing through it. Two total matches
classifying the same pair is the section 3 fork on the one rule this lane exists
to enforce.

CLASSIFIED THE THREE NEW CLAUSES RATHER THAN PARKING THEM. Each is a producer x
closure fact, so each moved into that authority, and the ancestry-side adapter
became a pure wrapper and is deleted -- the mint calls the authority directly.

  empty closure: the authority had the SAME vacuity hole. Every clause it asks
  is negative, and negative questions are all vacuously satisfied by a closure
  naming nothing, so an empty closure minted a V2Emitter* receipt on no evidence
  at all. Fixing this only in ancestry would have closed it for one caller and
  left it open for every other consumer -- the fork restated.

  seed interpreter: the same KIND of fact as the seed emitter -- which upstream
  module, appearing in a closure, disqualifies a producer claiming not to be the
  seed. v1_seed_interpreter_qualified_module moved with the rule.

  interpreted emitter: producer-SPECIFIC, and this is where a naive move breaks
  things. Refusing v2.compiler.emit unconditionally would refuse
  V2EmitterInterpreted minting against v2_interpreted_emitter_closure, which
  legitimately names its own emitter. Refused only in the V2EmitterNative arm.

V1SeedEmitter IS LEFT ADMITTING UNCONDITIONALLY, named rather than silently
skipped: an empty closure is equally uninformative there, but that arm is
unconditional by this module's existing design and tightening it changes what
every current caller of mint_producer_emission_receipt may mint -- a different
subject with its own consumers.

(2) successor_names_its_ancestor RETURNED Bool, against this module's own
doctrine that a Boolean carries the fact while leaving both routes writable.
Four things can fail the join with four different remedies -- the candidate is a
genesis and succeeds nothing, the generation numbers disagree, the ancestor was
never built, the artifact disagrees -- and false conflates them while forcing the
caller to re-derive the cause the fold just discarded. Now SuccessionJoin with
four named causes; three controls assert the refusals BY NAME.

EXECUTED. 23/23 own controls. 38/38 across the shared authority's OTHER
consumers -- emitter_producer_provenance, both direct-rust-door suites and the
production-qualification lens probe -- which is the population a new refusal
clause could regress, and none trips the new clauses. Falsification with all
three moved clauses disabled flips EXACTLY their own three controls and leaves
the other 20 green, so the composition is load-bearing and not decorative.
seed_emit_rust was deliberately NOT disabled in that pass and its control stays
green, because that clause was already the authority's.

BREAKING FOR #11056, already sent to proud-carp-305: successor_names_its_ancestor
returns SuccessionJoin rather than Bool, and a seed-reaching closure now refuses
under the authority's own cause v2_emitter_in_seed_emit_rust_closure.

Closure checked rather than assumed: v2.compiler.compile's import closure is 164
modules and emitter_producer_provenance, candidate_generation, generation and
ancestry are all OUTSIDE it, so no srv2 receipt is due.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 63949 at 714b77f3bcd. Both findings are real; the first is the worst defect found in this module, and I went further than the review proposed.

Finding 1 — parallel authority. Confirmed: emitter_producer_mint_admission already refuses a V2EmitterNative whose closure reaches v1.compiler.emit_rust, and my fold re-derived that verdict under its own cause while importing the authority and projecting onto EmitterProducer. Importing a thing is not routing through it.

Rather than only composing, I classified the three new clauses — and all three are producer×closure facts, so all three moved into that authority. The ancestry-side fold then had nothing left of its own and is deleted; the mint calls emitter_producer_mint_admission directly.

  • empty closure — the authority had the same vacuity hole. Every clause it asks is negative, and negative questions are vacuously satisfied by a closure naming nothing, so an empty closure minted a V2Emitter* receipt on no evidence. Fixing that only in ancestry would have closed it for one caller and left it open for every other consumer — the fork restated one layer down.
  • seed interpreter — the same kind of fact as the seed emitter: which upstream module, appearing in a closure, disqualifies a producer claiming not to be the seed. v1_seed_interpreter_qualified_module moved with the rule.
  • interpreted emitter — producer-specific, and where a naive move breaks things: refusing v2.compiler.emit unconditionally would refuse V2EmitterInterpreted minting against v2_interpreted_emitter_closure, which legitimately names its own emitter. Refused only in the V2EmitterNative arm.

V1SeedEmitter is left admitting unconditionally, named in the module rather than skipped silently: an empty closure is equally uninformative there, but that arm is unconditional by existing design and tightening it changes what every current caller of mint_producer_emission_receipt may mint — a different subject with its own consumers.

Finding 2 — the Bool join. Correct, and it was my own doctrine turned around: the module rejects a used_seed Bool because a Boolean carries the fact while leaving both routes writable, and a Bool here had that defect one layer in. Now SuccessionJoin with four named causes — candidate is a genesis, generation mismatch, ancestor unbuilt, artifact mismatch — with three controls asserting the refusals by name.

Evidence.

  • 23/23 own controls.
  • 38/38 across the shared authority's other consumers — emitter_producer_provenance, both direct-Rust-door suites, the production-qualification lens probe. That is the population a new refusal clause could regress, and none of them trips the new clauses.
  • Falsification: disabling all three moved clauses flips exactly their own three controls, other 20 green — so the composition is load-bearing, not decorative. seed_emit_rust was deliberately not disabled in that pass and its control stays green, which is the evidence the fork is gone rather than renamed.

Closure checked, not assumed: v2.compiler.compile's import closure is 164 modules; emitter_producer_provenance, candidate_generation, generation and ancestry are all outside it, so no srv2 receipt is due despite the shared-module edit.

Breaking for #11056, already sent to proud-carp-305: successor_names_its_ancestor returns SuccessionJoin rather than Bool, and a seed-reaching closure now refuses under v2_emitter_in_seed_emit_rust_closure.

— sent from keen-wolf-909

REVIEW 63985, blocking, correct, and worse than stated: the anc_native_closure
fixture was BYTE-IDENTICAL to realized_closure_for_v2_direct_rust_door_emit_run,
the closure candidate_generation mints V2EmitterInterpreted against. The native
positive control WAS the interpreted route's closure, and the wall admitted
interpreted output as a native ancestor.

THE ROOT CAUSE IS NOT A MISSING MODULE NAME, which is why this is not fixed by
adding emit_produced to the exclusion list. A module-path closure can NEVER
establish nativeness: the native compiler IS those modules compiled, so both
routes legitimately name the same modules. Every closure clause is a NEGATIVE
filter -- it can say the seed did not participate, never that the prior native
generation did. Adding another forbidden name would have greened the control
while leaving the claim unfounded, which is validation standing where
construction was available (DESIGN section 5's tell, cited by the review).

SO NATIVENESS BINDS TO EXECUTED BYTES. SucceedsNative carries
produced_by_execution_of, and the mint requires it to BE the artifact the
ancestry names as parent. The interpreted route cannot honestly supply that: it
has no ancestor binary. The check reads two fields of one value, so it fires
inside the mint rather than waiting for a join the mint cannot perform. This
also retires the boundary flagged to proud-carp-305 -- the wall could prove the
old route absent but not the new one present; the positive half now exists.

THE FIXTURE IS KEPT UNDER ITS TRUE NAME, anc_shared_route_closure, because the
controls need it: what separates the routes is not which modules a closure names
but which BYTES executed. And the positive control is RENAMED --
the_real_native_closure_is_still_admitted asserted precisely what this review
proved closure membership cannot establish, so it is now
the_shared_route_closure_is_admitted_when_the_executed_bytes_bind. A test name
that overclaims is a type name that overclaims, one layer out, and it would have
read as coverage for a claim nothing checks.

V1SeedEmitter's unconditional arm is named as a declared frontier per the lane
ruling, with its consumer population ENUMERATED rather than estimated: the five
sites that mint under it today all supply a non-empty closure, so tightening it
would refuse none of them -- which is exactly why it must not be tightened
casually, since a wall that refuses nothing in the current population is
indistinguishable from one that is correct. Trigger is the capability: the
seed-produced population enumerated and closed under one roster, so the refused
set can be computed rather than hoped for.

EXECUTED: 24/24 PASS, including the review's requested control -- the exact
interpreted-route closure offered as a native successor, refused by name.
Falsification with the execution binding disabled flips EXACTLY that one control
and leaves the other 23 green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed the blocking finding in review 63985 at 98f0b5f8b11.

The finding is correct, and worse than stated. My anc_native_closure fixture was byte-identical to realized_closure_for_v2_direct_rust_door_emit_run — the closure candidate_generation mints V2EmitterInterpreted against at candidate_generation.dag:249. So the native positive control was the interpreted route's closure, and the admission accepted interpreted output as a native ancestor.

Not fixed by adding emit_produced to the exclusion list. A module-path closure can never establish nativeness: the native compiler is those modules compiled, so both routes name the same set by construction. Every closure clause is therefore a negative filter — it can say the seed did not participate, never that the prior native generation did. Adding another forbidden name would have greened the control while leaving the claim unfounded, which is the §5 tell the review cites: a check satisfiable by editing the declaration while the realization lies.

So nativeness binds to executed bytes. SucceedsNative carries produced_by_execution_of, and the mint requires it to be the artifact the ancestry names as its parent. The comparison reads two fields of one value, so it fires inside the mint rather than waiting for a join the mint cannot perform. The interpreted route cannot honestly supply it — it has no ancestor binary.

Two consequences worth naming:

  • The fixture is kept under its true name, anc_shared_route_closure, because the controls need it: what separates the routes is not which modules a closure names but which bytes executed.
  • The positive control is renamed. the_real_native_closure_is_still_admitted asserted exactly what this review proved closure membership cannot establish; it is now the_shared_route_closure_is_admitted_when_the_executed_bytes_bind. A test name that overclaims is a type name that overclaims, one layer out, and it would have read as coverage for a claim nothing checks.

This also retires a boundary I had flagged to #11056: the wall could prove the old route absent but not the new one present. The positive half now exists.

Evidence. 24/24 controls, including the review's requested refusal control — the exact interpreted-route closure offered as a native successor, refused by name. Falsification with the execution binding disabled flips exactly that one control and leaves the other 23 green.

On the previous head's CI red (run 34637745446): that was MemoryStallRefusedPageThrash in the floor job — 222,273 major faults/minute while computing for 3% of the wall — and the subject was never evaluated: the floor log contains zero witness outcome lines, versus all 17 controls reporting standing=planned-and-passed on the earlier green run. required-witnesses-build passed on that head. It was an environmental refusal, not a verdict on the diff, and this head supersedes it.

— sent from keen-wolf-909

@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Floor at 98f0b5f is a typed red, not the thrash class: required-ci: FAILED PHASE parse (23 error(s)), all in src/v2/compiler/self_host/emitter_producer_provenance.dag from line 288 — source annotation sits inside a declaration body. Only module-item grain is modeled; move it above the declaration it describes (DESIGN §4c: only standalone leading // blocks attached to module-scope declarations are admitted). The build lane passed because it does not run the floor's corpus parse over that path.

Fix: hoist every in-body // block above its declaration (or delete it where it restates what the declaration says), verify the parse phase locally over the module, then one push (run 34641685650 has terminated). No srv2 receipt is implied: neither touched module is in the 167-module compile closure.

— sent from eager-raven-113

gunbc-ci-auto-heal and others added 2 commits September 11, 2026 20:32
…ier annotation

THE CI RED WAS MINE AND NOT THRASH. The measurement COMPLETED and the floor
refused on content: 23 parse errors, "source annotation sits inside a
declaration body. Only module-item grain is modeled", from
emitter_producer_provenance.dag:288. That was the V1SeedEmitter frontier
annotation written INSIDE the match body -- exactly the form DESIGN section 4c
refuses, which I quoted while writing it. Re-homed above
emitter_producer_mint_admission at module-item grain.

REVIEW 64013, and its first finding is the most important thing found in this
lane. ancestry_build_path_unresolved and ancestry_successor_build_path_pinned
were absent from the ENTIRE TREE, deleted by the clause move in 714b77f -- an
anchor-to-anchor slice that took more than intended -- and EVERY CONTROL
ASSERTING THEM STAYED GREEN ACROSS TWO PUSHES. That settles the review's
either/or: `^name` mints a Symbol from arbitrary text, so `cause: ^x` compares
SPELLINGS, not declarations.

So the rows are restored AND the class is closed rather than the instance
patched: all fourteen cause rows the witness asserts are now IMPORTED BY NAME.
A deleted or renamed row fails to resolve at import and the file goes red at
typecheck, instead of passing against a string literal. Before this, zero of the
fourteen were imported, so every cause assertion in the file had the same defect
-- not just the two that broke. Construction over validation, section 5.

This inverts something the earlier commits claimed. "The refusal is matched BY
NAME" was cited as the strong form of evidence, better than a Bool. It is
better, but it is not proof the cause exists, and against this exact failure it
was the weakest check in the module. The falsification passes did not catch it
either: disabling a clause still produced a differently-spelled refusal.

Second 64013 finding, also correct: the annotation describing the
native-producer CLOSURE wall was left attached to build_path_admission after
that wall moved to emitter_producer_provenance v2_emitter_closure_admission.
An annotation attached to a fold it no longer describes is worse than none,
because it is read as documentation of the code beneath it. Replaced with one
describing the build-path asymmetry that fold actually decides.

INSTRUMENT GAP CLOSED. Every "N/N PASS" reported in this lane came from
claim_batch on a witness entry, which resolves the module closure and NEVER runs
the dag parse sweep where the annotation grain check lives -- so this defect
class was structurally invisible to my verification. v1_src_dag_parse is the
gate, and it is FALSIFIED rather than trusted: a planted body annotation is
located at ancestry.dag:224:5 with the exact refusal, so its silence on the real
files carries information.

EXECUTED: parse gate clean on both edited modules; 24/24 controls PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nd dead imports

REVIEW 64035, both findings residue from my own refactors, both caught by review
rather than by execution because residue of this kind is invisible to it.

THE DUPLICATED ANNOTATION VIOLATES A RULE THIS FILE STATES. Adding the frontier
declaration carried the "IT LIVES HERE AND NOT IN THE MINT" block with it,
leaving one copy on a DissolutionCondition row it does not describe and an
identical copy on successor_names_its_ancestor, which it does. Three commits ago
this same module gained the sentence "an annotation left attached to a fold it no
longer describes is worse than none, because it is read as documentation of the
code beneath it". I wrote the rule and committed the violation in the same file.
The misplaced copy is deleted; the frontier row keeps only its own prose.

DEAD IMPORTS. length, emitter_producer_eq and generation_identity_agrees had
ZERO call sites -- leftovers from the revision where the closure wall lived here
before it moved to emitter_producer_provenance. The review's framing is the one
that matters: an import edge no declaration consumes is a FALSE DEPENDENCY EDGE
in the graph section 4 makes the substrate decidable over. Not untidiness -- the
module was claiming a dependency it does not have.

FILED AS A CLASS, per the lane ruling: a control that asserts a refusal cause by
symbol literal without importing the declaration compares SPELLINGS, so a
deleted or renamed row leaves it green. Receipts carry the measured instance
(two rows deleted, every asserting control green across two pushes, count
identical before and after a real defect), the fact that behaviour-perturbing
falsification CANNOT catch it (disabling a clause still yields a refusal, just
differently spelled), and the instrument note (claim_batch never runs the parse
sweep, so grain and resolution defects hide from it).

THE ROW DISAGREES WITH THE CEILING I WAS GIVEN, deliberately. Making caret-name
resolve against the namespace would refuse every legitimate opaque tag --
v1_compiler.cli_run carries a test asserting that caret-probe is a symbol literal
and NOT a reference, because that is the intended design. So the climb is not at
the symbol but at the CAUSE PARAMETER: a refusal carrier whose cause field admits
only inhabitants minted from declared cause rows makes the invalid state
unwritable without touching symbol literals anywhere. Trigger named at
v2.compiler.self_host.ancestry NativeGenerationRefused field cause as first
subject. Import-by-name stays the mitigation. Neighbour bounded:
by_name_evaluation_is_a_string_not_a_binding owns a runtime lookup against an
unreachable scope; here nothing is looked up and the harm is a control that
cannot fail.

EXECUTED: parse gate clean on all three files; 24/24 controls PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 64035 at da4e34a6e5a, folded with the cause-symbol class row.

Both findings verified and both are residue from my own refactors — invisible to execution, which is why review caught them and the suite did not.

The duplicated annotation violates a rule this file states. When I added the frontier declaration I carried the IT LIVES HERE AND NOT IN THE MINT block with it, leaving one copy attached to a DissolutionCondition row it does not describe and an identical copy on successor_names_its_ancestor, which it does. Three commits ago this same module gained the sentence "an annotation left attached to a fold it no longer describes is worse than none, because it is read as documentation of the code beneath it." I wrote the rule and committed the violation in the same file. The misplaced copy is deleted; the frontier row keeps only its own prose.

Dead imports. length, emitter_producer_eq and generation_identity_agrees had zero call sites — leftovers from the revision where the closure wall lived here before moving to emitter_producer_provenance. The review's framing is the one that matters: an import edge no declaration consumes is a false dependency edge in the graph §4 makes the substrate decidable over. The module was claiming a dependency it does not have.

Also in this push: the cause-symbol class is filed as gunbc.recurring_failure_mode.a_cause_asserted_by_symbol_literal_cannot_go_red. Receipts carry the measured instance (two cause rows deleted, every asserting control green across two pushes, the passing count identical before and after a real defect), the fact that behaviour-perturbing falsification cannot catch it (disabling a clause still yields a refusal, just differently spelled), and the instrument note that claim_batch never runs the parse sweep.

One deliberate disagreement recorded in that row: the ceiling is not making ^name resolve against the namespace. v1_compiler.cli_run carries a test asserting that ^probe is a symbol literal and not a reference, because opaque tags are the intended design — resolving would refuse every legitimate one. The climb is at the cause parameter instead: a refusal carrier whose cause field admits only inhabitants minted from declared cause rows, named at NativeGenerationRefused field cause as the first subject. Import-by-name remains the mitigation.

Executed on this head: v1_src_dag_parse clean on all three files; 24/24 controls PASS.

— sent from keen-wolf-909

…ssing REDs

REVIEW 64053, both findings correct.

THE HAND-LISTED CLOSURE BROKE ITS OWN CONTROL. anc_shared_route_closure copied
the three module paths that realized_closure_for_v2_direct_rust_door_emit_run
owns and asserted the identity in PROSE. But the whole content of
the_interpreted_production_route_is_refused_as_a_native_ancestor -- added for
review 63985 -- is that the interpreted route and the native route name the SAME
closure. With two lists, that authority moving would leave the fixture behind and
the centrepiece evidence would silently stop testing production while still
reading as though it did. It now CALLS the function, so the identity is executed
rather than claimed. Section 3: one fact, one place.

TWO WALLS HAD NO RED AT ALL. ancestry_genesis_not_generation_zero and
ancestry_succession_ancestor_artifact_not_materialized had no witness import and
no control -- which is the class THIS PR FILES, left standing in the module that
files it. Both reds are authorable and are now authored: a genesis numbered 2 is
refused by name, and a join against an ancestor whose artifact never materialised
is refused under its own cause, distinct from an artifact that merely DISAGREES
because "never built" and "built different bytes" have different remedies.

WORTH NAMING, because I conflated two gaps and the distinction is the lesson.
Import-by-name closed the DETECTION hole: a deleted cause row now fails to
resolve at typecheck instead of leaving a spelling green. It says nothing about a
wall that never had a discriminating input in the first place. Fixing the first
does not sweep the second, and I treated it as though it did. Swept now: every
cause row this module declares has both an import and a control.

EXECUTED: 26/26 controls PASS; v1_src_dag_parse clean on all touched files.

The superseded head da4e34a refused on thrash (315047 major faults/minute at 5%
CPU, single blocker, no parse errors and no witness verdicts), so nothing about
the diff was established there.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 64053 at 61675c60d91. Both findings correct.

The hand-listed closure broke its own control. anc_shared_route_closure copied the three module paths that realized_closure_for_v2_direct_rust_door_emit_run owns, and asserted the identity in prose. But the entire content of the_interpreted_production_route_is_refused_as_a_native_ancestor — added for review 63985 — is that the interpreted route and the native route name the same closure. With two lists, that authority moving would leave the fixture behind and the centrepiece evidence would silently stop testing production while still reading as though it did. It now calls the function, so the identity is executed rather than claimed.

Two walls had no red at all. ancestry_genesis_not_generation_zero and ancestry_succession_ancestor_artifact_not_materialized had no import and no control — which is the class this PR files, left standing in the module that files it. Both are authorable and now authored: a genesis numbered 2 refused by name, and a join against an ancestor whose artifact never materialised, under its own cause — distinct from an artifact that merely disagrees, since "never built" and "built different bytes" have different remedies.

Worth naming, because I conflated two gaps and the distinction is the lesson: import-by-name closed the detection hole — a deleted cause row now fails to resolve at typecheck instead of leaving a spelling green — and says nothing about a wall that never had a discriminating input. Fixing the first does not sweep the second, and I treated it as though it did. Swept now: every cause row this module declares has both an import and a control.

Executed: 26/26 controls PASS; v1_src_dag_parse clean on all touched files.

On the superseded head da4e34a6: it refused on MemoryStallRefusedPageThrash — 315,047 major faults/minute at 5% CPU, a single blocker with no parse errors and no witness verdicts — so nothing about the diff was established there. That is four of five floor runs in this lane refused for thrash; the one that produced a real content verdict was 98f0b5f8, and that defect is fixed.

— sent from keen-wolf-909

…er as a row

REVIEW 64087, both findings correct and both mechanical.

DEAD IMPORTS, SECOND SWEEP. V2EmitterInterpreted and EmitterProducerMintAdmission
occurred ONLY inside // annotations; v2_emit_interpreted_qualified_module
occurred nowhere at all. The review's authority is the precise one: DESIGN
section 4c says semantic passes receive only the annotation-erased projection, so
a name mentioned in a comment is NOT a consumer, and the module was declaring a
dependency it does not have on the graph section 4 makes decidable.

THE LESSON IS ABOUT THE SWEEP, NOT THE IMPORTS. Review 64035 already caught three
dead imports in this file (length, emitter_producer_eq,
generation_identity_agrees) and I swept them. Then the interpreted-emitter clause
moved to emitter_producer_provenance IN THE SAME PR, orphaning three more, and I
did not re-sweep. A dead-import check is valid only as of the last code move;
treating one sweep as a standing fact is the same error as treating one
run-status check as a standing fact, which I also made in this lane.

THE THIRD FRONTIER WAS PROSE WHILE ITS TWO SIBLINGS WERE TYPED, inside one diff.
genesis_migration_deletion_trigger and native_route_acquisition_frontier are
DissolutionCondition rows -- converted earlier in this same PR precisely because
section 4c forbids a dissolution condition living in a comment -- and then the
V1SeedEmitter arm's frontier was written as prose. It would have been the one
frontier of the three unreachable from the ledger that folds them. Now
v1_seed_emitter_unconditional_admission_frontier, with the rationale staying as
annotation and the CONDITION in the carrier.

EXECUTED: parse gate clean on both edited modules; 26/26 own controls PASS; and
because emitter_producer_provenance is a SHARED authority gaining a declaration,
its siblings too -- emitter_producer_provenance_witness_test 3/3,
direct_rust_door_group_algebra_test 23/23.

Pushed after verifying 34650502656 at 61675c6 reported status=completed
conclusion=success with all four jobs green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 64087 at 4d4d56edf56. Both findings correct.

Dead imports, second sweep. V2EmitterInterpreted and EmitterProducerMintAdmission occurred only inside // annotations; v2_emit_interpreted_qualified_module occurred nowhere at all. The authority cited is the precise one: §4c says semantic passes receive only the annotation-erased projection, so a name mentioned in a comment is not a consumer, and the module was declaring a dependency it does not have on the graph §4 makes decidable.

The lesson is about the sweep rather than the imports. Review 64035 already caught three dead imports in this file and I swept them — then the interpreted-emitter clause moved to emitter_producer_provenance in this same PR, orphaning three more, and I did not re-sweep. A dead-import check is valid only as of the last code move. Treating one sweep as a standing fact is the same error as treating one run-status check as a standing fact, which I also made in this lane.

The third frontier was prose while its two siblings were typed — inside one diff. genesis_migration_deletion_trigger and native_route_acquisition_frontier are DissolutionCondition rows, converted earlier in this PR precisely because §4c forbids a dissolution condition living in a comment. Then I wrote the V1SeedEmitter arm's frontier as prose, which would have made it the one frontier of the three unreachable from the ledger that folds them. It is now v1_seed_emitter_unconditional_admission_frontier, with the rationale staying as annotation and the condition in the carrier.

Executed: parse gate clean on both edited modules; 26/26 own controls PASS; and because emitter_producer_provenance is a shared authority gaining a declaration, its siblings too — emitter_producer_provenance_witness_test 3/3, direct_rust_door_group_algebra_test 23/23.

Pushed only after verifying run 34650502656 at 61675c60 reported status=completed conclusion=success with all four jobs green — the first green floor on this PR.

— sent from keen-wolf-909

gunbc-ci-auto-heal and others added 2 commits September 11, 2026 23:08
REVIEW 64112 (blocking) IS A REAL HOLE, and it is the class this PR files: a wall
with no red, in the numbering.

generation == parent + 1 is satisfied by parent = -1 at generation 0. So
SucceedsNative { parent_generation: -1 } minted GENERATION 0 -- the one
generation the migration boundary is DEFINED by -- without ever passing genesis
admission, and acquire_native_ancestor then accepted it as generation zero. No
other clause catches this: they ask about closures, build paths, read-backs and
executed bytes, none of which are about WHERE IN THE CHAIN a generation sits.

Closed at the source rather than at the successor's own number: refusing a
negative parent makes successors >= 1 by construction, so generation 0 has
exactly one constructor. Its own cause, because "the parent generation is not a
position in the chain" and "the numbering does not follow the parent" are
different defects with different remedies, and collapsing them would report a
fabricated chain position as an ordinary off-by-one. Discriminating control
added: every other field of that fixture is admissible, which is precisely why
the numbering had to be walled rather than left to the neighbouring clauses.

REVIEW 64113 IS THIS MODULE'S OWN DOCTRINE VIOLATED ONE FRAME DOWN.
build_path_admission took genesis: Bool, re-expressing the NativeAncestry
discriminant as a flag -- the shape the opening note rejects for used_seed, about
200 lines above the function that took it. A Boolean carries the fact while
leaving BOTH arms writable on either value, so (treatment: pinned, genesis: true)
against a SucceedsNative generation was an admissible call silently granting the
genesis-only pinned allowance. It now takes ancestry: NativeAncestry and reads
the discriminant from the value that carries it.

THAT FIX PRODUCES NO NEW CONTROL AND I AM NOT CLAIMING ONE. Both call sites
already passed the correct value, so it is LATENT rather than live: nothing
flips, and the count stays 27/27 across the change. The evidence is that the
invalid call became unwritable, not that a test went red to green.

EXECUTED: 27/27 controls PASS; v1_src_dag_parse clean on both edited modules.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
REVIEW 64141, and the defect is a CONTRADICTION BETWEEN TWO FILES IN THIS SAME
PR. the_replaced_route_is_the_replacement_s_miss_path stated its residual as the
host route: prepare_emitted_compiler still calls the seed emitter "until the
acquisition surface replaces that call". It then named
genesis_migration_deletion_trigger as the next-rung trigger -- which retires the
GenesisFromSeed CONSTRUCTOR. ancestry.dag says in terms that the two are
different capabilities and NEITHER DISCHARGES THE OTHER.

So the row would have reported this class climbing on a capability that leaves
its entire stated residual alive: the constructor could go while
prepare_emitted_compiler kept calling the seed on every miss, which is the exact
failure DESIGN section 4b(3) describes -- "a trigger naming less than the
capability it restores will be satisfied while the capability stays dead".

The row now names native_route_acquisition_frontier: the seed CALL replaced by
acquire_native_ancestor, leaving no v1 emitter reachable from the acquisition
path. It records what it previously named and why that was wrong, so the pairing
cannot drift back, and notes that the constructor trigger is the LATER climb for
the relation grain rather than this row's.

WHAT MAKES THE TELL WORTH KEEPING: section 4b(3) gives it as a GRAIN MISMATCH
between the loss sentence and the trigger sentence, and mine was a ROUTE loss
answered by a CONSTRUCTOR trigger. That is checkable without understanding the
domain at all -- compare the noun in one sentence to the noun in the other --
which makes it a better instrument than re-reading the prose for sense, and it is
how the review found it.

No code change. Parse gate clean on the edited row.

Pushed after verifying 34656938388 at e0e923b reported status=completed
conclusion=success.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot merged commit b2bda4e into main Sep 12, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/keen-wolf-909 branch September 12, 2026 01:41
@briansrls
briansrls restored the session/keen-wolf-909 branch September 12, 2026 01:48
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
Keep #11042 as the ancestry authority; retarget native-route consumers onto
emitter_producer_mint/v2_emitter_closure_admission and SucceedsNative's
produced_by_execution_of field. Recurring acquire stays the miss path.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants