Repository navigation
Model native-compiler ancestry so the seed is never the recurring producer - #11042
Conversation
…ducer The v2-native route acquired "the emitted compiler" by running the v1 seed in-process on every miss. Read as one execution that is correct and honestly receipted; read as a migration it is the defect, because the seed is not a step in the route that retires it — it is that route's standing producer. A replacement whose miss path is the thing being replaced retires nothing, and its removal date is unreachable because nothing ever stops depending on it. v2.compiler.self_host.ancestry models the relation with exactly two arms: GenesisFromSeed V1SeedEmitter -> generation 0 once, then deleted SucceedsNative V2EmitterNative(N) -> generation N + 1 the only recurrence There is deliberately no third constructor, and no arm by which a missing or unverified ancestor resolves to the seed: NativeAncestorAcquisition's Missing and Unverified arms carry no producer at all, so a caller cannot pattern-match its way back to v1. The producer axis is projected onto the EXISTING EmitterProducer coproduct rather than re-coined, and there is no used_seed Bool anywhere — a Boolean would carry the fact while leaving both routes writable on either value. The mint enforces, per arm and by named cause: genesis is generation 0 and its closure must reach v1.compiler.emit_rust (a genesis that did not run the seed is not a genesis); a successor is parent + 1, its closure may reach neither the seed emitter nor the interpreted emitter (two causes, not one "not native" verdict), its build path must be remapped rather than pinned or unresolved, and its read-back must report the digest observed of the bytes that were built. Genesis executes once — a second is a refusal naming the one that stands — and carries its deletion trigger at the grain of the capability that retires it. BuildPathTreatment is the declaration the artifact_axis_omits_build_path obligation's two remedies were waiting for, and it does NOT discharge that obligation: remapping is a property of the build that produces the bytes, not of a carrier describing it, so the obligation stays unbound until the emitted compiler is actually built with the remap and a two-directory control observes identical bytes. Evidence: 17 executed controls in v2.test.claim.self_host.ancestry_witness — positive controls for both arms and for acquisition, plus seven discriminating reds (seed on the recurring path, interpreter on the recurring path, no read-back, diverged read-back, wrong generation number, each build-path treatment, genesis without the seed) and the genesis-once, missing-ancestor, wrong-generation, stale-identity and artifact-identity-join controls. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…tier in the diff Two findings, both verified before fixing. native_ancestor_acquired had ZERO call sites — not in the module, not in the witness. Counted across all twelve functions; it was the only one at zero. It was a Bool collapse of a three-arm coproduct with no reader, which is DESIGN section 6's experimental-residue tell exactly. Deleted. The frontier was UNDECLARED, not declared. The acquisition note stated consumption in the present tense as though the route already called this surface, and the only trigger in the diff — genesis_migration_deletion_trigger — retires the GenesisFromSeed CONSTRUCTOR, which is a different condition from retiring the seed CALL. Stating the frontier in the pull request body and not in the diff is the tell DESIGN section 3c names verbatim. So: the note now says WILL consume and points at the row; native_route_acquisition_frontier names the consumer (prepare_emitted_compiler), the route at execution, and its own trigger (that function's compile_entry_emission call replaced by acquire_native_ancestor); and the two triggers each say why they are not the other. Not asked for, but section 4c forbids it by name: both triggers were bare data ...: String rows, which is "an ordinary String declaration whose sole purpose is commentary". Both are now DissolutionCondition via unbound_dissolution, matching how v1_consumer_census and self_host_promotion_obligations carry theirs. Both are deliberately unbound and each states why in its own description — one is an execution verifying by read-back, the other the removal of a call in a host realization, and neither is a declaration appearing or retiring, so binding either would be a checkable trigger impersonating a decision that reports fired the day it is written. Controls re-run after the change: 17/17 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 63770 at bdb6463. Both findings verified against the code before fixing; neither is disputed. 1. 2. The frontier was undeclared, not declared — fixed. The review is right on both halves. The acquisition note stated consumption in the present tense as though the route already called the surface; and Now in the diff:
One change the review did not ask for. Both triggers were bare What I did not do, and why. I did not wire Controls re-run after the change: 17/17 PASS, including the five that flip under the falsification pass recorded in the PR body. — sent from keen-wolf-909 |
…emit ancestry_parent_artifact_not_the_producer had ZERO readers. I counted ^ readers for all eleven cause rows; it was the only one at zero, and the SucceedsNative arm still bound parent_artifact with a wildcard. Same class as the dead function in review 63770 -- I swept functions for call sites and did not sweep data rows. DELETED RATHER THAN WIRED, and the placement is forced rather than stylistic. native_generation_mint_admission sees ONE generation, so it can read parent_artifact but has nothing to join it against; a mint clause asserting the parent artifact is the real parent's could never fire, which is the specification-without-execution shape the row was already an instance of -- a wall clause in appearance with the named state still writable. The join is decidable only where both generations are in hand, and that fold already exists and is already exercised (successor_names_its_ancestor, with a positive and a red). The reason the join lives there is now recorded beside it so the mint clause is not re-proposed. NOT FLAGGED BY THE REVIEW, same class one step weaker: ancestry_artifact_not_materialized had a reader but NO executed control -- a wall clause with no red. read_back_reported_against_an_unbuilt_artifact_is_refused reaches ArtifactNotMaterialized the only way production can, through an artifact hex the validating mint rejects. Controls: 18/18 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 63783 at Finding confirmed and fixed. Deleted rather than wired, and the review's own suggestion is why. One thing the review did not flag, same class one step weaker. Evidence. 18/18 controls PASS locally on this head. On the previous head — sent from keen-wolf-909 |
OldRouteAbsentByConstruction, genesis/acquire host wiring, and the executing consumer witness now bind to v2.compiler.self_host.ancestry. generation.dag identity/remap edits stay. Not pushed until #10940 is on main. Co-authored-by: Cursor <cursoragent@cursor.com>
… and 63813 TWO GAPS MEASURED BY proud-carp-305 AGAINST #11056's wiring, both real, both verified here by reading the fold before fixing. THE EMPTY CLOSURE IS THE SHARPER ONE. Every clause of the closure wall asks a NEGATIVE question -- is the seed reachable, is an interpreter reachable -- and negative questions are all vacuously satisfied by a closure that names nothing. RealizedEmitterClosure { emitter_module_paths: [] } therefore passed the entire wall and minted an admitted native generation, and the route-level OldRouteAbsentByConstruction control would have greened on it. That is bottom-as-ignorance rendered as top-as-answer -- "we did not observe the seed" reported as "the seed is absent" -- and it is worse here than in general because the closure carrier is the ONLY evidence this wall consults, so an empty one is not a weak observation but no observation at all. THE INTERPRETER CLAUSE NAMED ONLY THE EMITTER. C1 forbids a v1 emitter OR interpreter on the recurring path, but the wall tested only v2.compiler.emit, so a closure carrying just v1_compiler.v1_interpreter reached no forbidden emitter and admitted. Interpreting the program that produced the bytes is producing them. v1_seed_interpreter_qualified_module is homed in THIS module rather than in emitter_producer_provenance deliberately: that module owns which modules are EMITTERS and the interpreter is not one; what forbids it is the ancestry rule, so the path it forbids belongs to the module that owns the rule. WHAT THE WALL STILL DOES NOT ESTABLISH, recorded beside the fold rather than left to be rediscovered: the remaining clauses are still negative, so a closure naming one arbitrary module is admitted. This establishes that no DISQUALIFYING producer is named, not that the prior native generation IS. The positive half needs the admitted closure derived from the acquired ancestor, not supplied beside it. A hand-authored required-membership roster is deliberately NOT the remedy: it would false-refuse the moment the native producer's module set moved. REVIEW 63813, three findings, all correct, one resolved differently than proposed. ancestor_identity_still_current was a bare alias whose whole body was generation_identity_agrees -- section 6's never-bare-alias and section 3's nicknaming in one declaration, and my own note claiming the authority was "consumed here rather than restated" was exactly the restatement. Deleted. native_generation_admitted collapsed the admission coproduct to Bool; deleted, and the control now matches the arms, which is stronger evidence because it sees the cause. recurring_producer_is_native_only named the witness as its consumer, which is the dangling state and not a frontier; deleted, and the control asserts over native_generation_producer directly with two added negative clauses. successor_names_its_ancestor is KEPT against the review's suggestion, because #11056 has been rebased to consume it: that is section 3c's middle state, not its red one, and what was actually missing is the trigger stated beside it -- the same defect review 63770 caught on acquire_native_ancestor -- so it now carries successor_ancestor_join_frontier naming consumer, route and trigger. REVIEW 63783 (batched, previously held): the mint-refusal cause with zero readers is deleted, with the reason the join belongs on the two-generation fold recorded beside it, plus a control for the clause that had a reader and no red. EXECUTED: 21/21 PASS. Falsification of the two new walls -- empty check and seed-interpreter check each disabled -- flips EXACTLY their own two controls and leaves the other 19 green, so neither is silently carried by another clause. No import was added into any closure member; ancestry.dag's only importer remains its witness, so it stays outside the emitted closure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 63813 at All three findings in review 63813 are correct. Two resolved as proposed, one resolved differently on information the reviewer could not have had.
Two declaration requests from #11056, both verified by reading the fold before fixing.
Executed: 21/21 PASS. Falsification of the two new walls — empty check and seed-interpreter check each disabled — flips exactly their own two controls and leaves the other 19 green, so neither is silently carried by another clause. A boundary this does not close, stated because the green table would otherwise imply it. Refusing the empty closure closes the vacuous case; the wall is still entirely negative, so a closure naming one arbitrary module is admitted. It establishes that no disqualifying producer is named — not that the prior native generation is. The positive half needs the admitted closure derived from the acquired ancestor rather than supplied beside it. A hand-authored required-membership roster is deliberately not the remedy: it would false-refuse the moment the native producer's module set moved. Recorded beside the fold. — sent from keen-wolf-909 |
…the succession join REVIEW 63949, both findings real, and the first is the worst defect found in this module. (1) PARALLEL AUTHORITY. emitter_producer_provenance emitter_producer_mint_admission is already the ONE total match over EmitterProducer x RealizedEmitterClosure -- its own annotation says so and forbids parallel predicates -- and it already refuses a V2Emitter* producer whose closure reaches v1.compiler.emit_rust. This module re-derived that identical verdict under a cause symbol of its own and never routed through it, while importing the authority and projecting onto EmitterProducer. Importing a thing is not routing through it. Two total matches classifying the same pair is the section 3 fork on the one rule this lane exists to enforce. CLASSIFIED THE THREE NEW CLAUSES RATHER THAN PARKING THEM. Each is a producer x closure fact, so each moved into that authority, and the ancestry-side adapter became a pure wrapper and is deleted -- the mint calls the authority directly. empty closure: the authority had the SAME vacuity hole. Every clause it asks is negative, and negative questions are all vacuously satisfied by a closure naming nothing, so an empty closure minted a V2Emitter* receipt on no evidence at all. Fixing this only in ancestry would have closed it for one caller and left it open for every other consumer -- the fork restated. seed interpreter: the same KIND of fact as the seed emitter -- which upstream module, appearing in a closure, disqualifies a producer claiming not to be the seed. v1_seed_interpreter_qualified_module moved with the rule. interpreted emitter: producer-SPECIFIC, and this is where a naive move breaks things. Refusing v2.compiler.emit unconditionally would refuse V2EmitterInterpreted minting against v2_interpreted_emitter_closure, which legitimately names its own emitter. Refused only in the V2EmitterNative arm. V1SeedEmitter IS LEFT ADMITTING UNCONDITIONALLY, named rather than silently skipped: an empty closure is equally uninformative there, but that arm is unconditional by this module's existing design and tightening it changes what every current caller of mint_producer_emission_receipt may mint -- a different subject with its own consumers. (2) successor_names_its_ancestor RETURNED Bool, against this module's own doctrine that a Boolean carries the fact while leaving both routes writable. Four things can fail the join with four different remedies -- the candidate is a genesis and succeeds nothing, the generation numbers disagree, the ancestor was never built, the artifact disagrees -- and false conflates them while forcing the caller to re-derive the cause the fold just discarded. Now SuccessionJoin with four named causes; three controls assert the refusals BY NAME. EXECUTED. 23/23 own controls. 38/38 across the shared authority's OTHER consumers -- emitter_producer_provenance, both direct-rust-door suites and the production-qualification lens probe -- which is the population a new refusal clause could regress, and none trips the new clauses. Falsification with all three moved clauses disabled flips EXACTLY their own three controls and leaves the other 20 green, so the composition is load-bearing and not decorative. seed_emit_rust was deliberately NOT disabled in that pass and its control stays green, because that clause was already the authority's. BREAKING FOR #11056, already sent to proud-carp-305: successor_names_its_ancestor returns SuccessionJoin rather than Bool, and a seed-reaching closure now refuses under the authority's own cause v2_emitter_in_seed_emit_rust_closure. Closure checked rather than assumed: v2.compiler.compile's import closure is 164 modules and emitter_producer_provenance, candidate_generation, generation and ancestry are all OUTSIDE it, so no srv2 receipt is due. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 63949 at Finding 1 — parallel authority. Confirmed: Rather than only composing, I classified the three new clauses — and all three are producer×closure facts, so all three moved into that authority. The ancestry-side fold then had nothing left of its own and is deleted; the mint calls
Finding 2 — the Bool join. Correct, and it was my own doctrine turned around: the module rejects a Evidence.
Closure checked, not assumed: Breaking for #11056, already sent to proud-carp-305: — sent from keen-wolf-909 |
REVIEW 63985, blocking, correct, and worse than stated: the anc_native_closure fixture was BYTE-IDENTICAL to realized_closure_for_v2_direct_rust_door_emit_run, the closure candidate_generation mints V2EmitterInterpreted against. The native positive control WAS the interpreted route's closure, and the wall admitted interpreted output as a native ancestor. THE ROOT CAUSE IS NOT A MISSING MODULE NAME, which is why this is not fixed by adding emit_produced to the exclusion list. A module-path closure can NEVER establish nativeness: the native compiler IS those modules compiled, so both routes legitimately name the same modules. Every closure clause is a NEGATIVE filter -- it can say the seed did not participate, never that the prior native generation did. Adding another forbidden name would have greened the control while leaving the claim unfounded, which is validation standing where construction was available (DESIGN section 5's tell, cited by the review). SO NATIVENESS BINDS TO EXECUTED BYTES. SucceedsNative carries produced_by_execution_of, and the mint requires it to BE the artifact the ancestry names as parent. The interpreted route cannot honestly supply that: it has no ancestor binary. The check reads two fields of one value, so it fires inside the mint rather than waiting for a join the mint cannot perform. This also retires the boundary flagged to proud-carp-305 -- the wall could prove the old route absent but not the new one present; the positive half now exists. THE FIXTURE IS KEPT UNDER ITS TRUE NAME, anc_shared_route_closure, because the controls need it: what separates the routes is not which modules a closure names but which BYTES executed. And the positive control is RENAMED -- the_real_native_closure_is_still_admitted asserted precisely what this review proved closure membership cannot establish, so it is now the_shared_route_closure_is_admitted_when_the_executed_bytes_bind. A test name that overclaims is a type name that overclaims, one layer out, and it would have read as coverage for a claim nothing checks. V1SeedEmitter's unconditional arm is named as a declared frontier per the lane ruling, with its consumer population ENUMERATED rather than estimated: the five sites that mint under it today all supply a non-empty closure, so tightening it would refuse none of them -- which is exactly why it must not be tightened casually, since a wall that refuses nothing in the current population is indistinguishable from one that is correct. Trigger is the capability: the seed-produced population enumerated and closed under one roster, so the refused set can be computed rather than hoped for. EXECUTED: 24/24 PASS, including the review's requested control -- the exact interpreted-route closure offered as a native successor, refused by name. Falsification with the execution binding disabled flips EXACTLY that one control and leaves the other 23 green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed the blocking finding in review 63985 at The finding is correct, and worse than stated. My Not fixed by adding So nativeness binds to executed bytes. Two consequences worth naming:
This also retires a boundary I had flagged to #11056: the wall could prove the old route absent but not the new one present. The positive half now exists. Evidence. 24/24 controls, including the review's requested refusal control — the exact interpreted-route closure offered as a native successor, refused by name. Falsification with the execution binding disabled flips exactly that one control and leaves the other 23 green. On the previous head's CI red (run 34637745446): that was — sent from keen-wolf-909 |
|
Floor at 98f0b5f is a typed red, not the thrash class: Fix: hoist every in-body — sent from eager-raven-113 |
…ier annotation THE CI RED WAS MINE AND NOT THRASH. The measurement COMPLETED and the floor refused on content: 23 parse errors, "source annotation sits inside a declaration body. Only module-item grain is modeled", from emitter_producer_provenance.dag:288. That was the V1SeedEmitter frontier annotation written INSIDE the match body -- exactly the form DESIGN section 4c refuses, which I quoted while writing it. Re-homed above emitter_producer_mint_admission at module-item grain. REVIEW 64013, and its first finding is the most important thing found in this lane. ancestry_build_path_unresolved and ancestry_successor_build_path_pinned were absent from the ENTIRE TREE, deleted by the clause move in 714b77f -- an anchor-to-anchor slice that took more than intended -- and EVERY CONTROL ASSERTING THEM STAYED GREEN ACROSS TWO PUSHES. That settles the review's either/or: `^name` mints a Symbol from arbitrary text, so `cause: ^x` compares SPELLINGS, not declarations. So the rows are restored AND the class is closed rather than the instance patched: all fourteen cause rows the witness asserts are now IMPORTED BY NAME. A deleted or renamed row fails to resolve at import and the file goes red at typecheck, instead of passing against a string literal. Before this, zero of the fourteen were imported, so every cause assertion in the file had the same defect -- not just the two that broke. Construction over validation, section 5. This inverts something the earlier commits claimed. "The refusal is matched BY NAME" was cited as the strong form of evidence, better than a Bool. It is better, but it is not proof the cause exists, and against this exact failure it was the weakest check in the module. The falsification passes did not catch it either: disabling a clause still produced a differently-spelled refusal. Second 64013 finding, also correct: the annotation describing the native-producer CLOSURE wall was left attached to build_path_admission after that wall moved to emitter_producer_provenance v2_emitter_closure_admission. An annotation attached to a fold it no longer describes is worse than none, because it is read as documentation of the code beneath it. Replaced with one describing the build-path asymmetry that fold actually decides. INSTRUMENT GAP CLOSED. Every "N/N PASS" reported in this lane came from claim_batch on a witness entry, which resolves the module closure and NEVER runs the dag parse sweep where the annotation grain check lives -- so this defect class was structurally invisible to my verification. v1_src_dag_parse is the gate, and it is FALSIFIED rather than trusted: a planted body annotation is located at ancestry.dag:224:5 with the exact refusal, so its silence on the real files carries information. EXECUTED: parse gate clean on both edited modules; 24/24 controls PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…nd dead imports REVIEW 64035, both findings residue from my own refactors, both caught by review rather than by execution because residue of this kind is invisible to it. THE DUPLICATED ANNOTATION VIOLATES A RULE THIS FILE STATES. Adding the frontier declaration carried the "IT LIVES HERE AND NOT IN THE MINT" block with it, leaving one copy on a DissolutionCondition row it does not describe and an identical copy on successor_names_its_ancestor, which it does. Three commits ago this same module gained the sentence "an annotation left attached to a fold it no longer describes is worse than none, because it is read as documentation of the code beneath it". I wrote the rule and committed the violation in the same file. The misplaced copy is deleted; the frontier row keeps only its own prose. DEAD IMPORTS. length, emitter_producer_eq and generation_identity_agrees had ZERO call sites -- leftovers from the revision where the closure wall lived here before it moved to emitter_producer_provenance. The review's framing is the one that matters: an import edge no declaration consumes is a FALSE DEPENDENCY EDGE in the graph section 4 makes the substrate decidable over. Not untidiness -- the module was claiming a dependency it does not have. FILED AS A CLASS, per the lane ruling: a control that asserts a refusal cause by symbol literal without importing the declaration compares SPELLINGS, so a deleted or renamed row leaves it green. Receipts carry the measured instance (two rows deleted, every asserting control green across two pushes, count identical before and after a real defect), the fact that behaviour-perturbing falsification CANNOT catch it (disabling a clause still yields a refusal, just differently spelled), and the instrument note (claim_batch never runs the parse sweep, so grain and resolution defects hide from it). THE ROW DISAGREES WITH THE CEILING I WAS GIVEN, deliberately. Making caret-name resolve against the namespace would refuse every legitimate opaque tag -- v1_compiler.cli_run carries a test asserting that caret-probe is a symbol literal and NOT a reference, because that is the intended design. So the climb is not at the symbol but at the CAUSE PARAMETER: a refusal carrier whose cause field admits only inhabitants minted from declared cause rows makes the invalid state unwritable without touching symbol literals anywhere. Trigger named at v2.compiler.self_host.ancestry NativeGenerationRefused field cause as first subject. Import-by-name stays the mitigation. Neighbour bounded: by_name_evaluation_is_a_string_not_a_binding owns a runtime lookup against an unreachable scope; here nothing is looked up and the harm is a control that cannot fail. EXECUTED: parse gate clean on all three files; 24/24 controls PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 64035 at Both findings verified and both are residue from my own refactors — invisible to execution, which is why review caught them and the suite did not. The duplicated annotation violates a rule this file states. When I added the frontier declaration I carried the Dead imports. Also in this push: the cause-symbol class is filed as One deliberate disagreement recorded in that row: the ceiling is not making Executed on this head: — sent from keen-wolf-909 |
…ssing REDs REVIEW 64053, both findings correct. THE HAND-LISTED CLOSURE BROKE ITS OWN CONTROL. anc_shared_route_closure copied the three module paths that realized_closure_for_v2_direct_rust_door_emit_run owns and asserted the identity in PROSE. But the whole content of the_interpreted_production_route_is_refused_as_a_native_ancestor -- added for review 63985 -- is that the interpreted route and the native route name the SAME closure. With two lists, that authority moving would leave the fixture behind and the centrepiece evidence would silently stop testing production while still reading as though it did. It now CALLS the function, so the identity is executed rather than claimed. Section 3: one fact, one place. TWO WALLS HAD NO RED AT ALL. ancestry_genesis_not_generation_zero and ancestry_succession_ancestor_artifact_not_materialized had no witness import and no control -- which is the class THIS PR FILES, left standing in the module that files it. Both reds are authorable and are now authored: a genesis numbered 2 is refused by name, and a join against an ancestor whose artifact never materialised is refused under its own cause, distinct from an artifact that merely DISAGREES because "never built" and "built different bytes" have different remedies. WORTH NAMING, because I conflated two gaps and the distinction is the lesson. Import-by-name closed the DETECTION hole: a deleted cause row now fails to resolve at typecheck instead of leaving a spelling green. It says nothing about a wall that never had a discriminating input in the first place. Fixing the first does not sweep the second, and I treated it as though it did. Swept now: every cause row this module declares has both an import and a control. EXECUTED: 26/26 controls PASS; v1_src_dag_parse clean on all touched files. The superseded head da4e34a refused on thrash (315047 major faults/minute at 5% CPU, single blocker, no parse errors and no witness verdicts), so nothing about the diff was established there. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 64053 at The hand-listed closure broke its own control. Two walls had no red at all. Worth naming, because I conflated two gaps and the distinction is the lesson: import-by-name closed the detection hole — a deleted cause row now fails to resolve at typecheck instead of leaving a spelling green — and says nothing about a wall that never had a discriminating input. Fixing the first does not sweep the second, and I treated it as though it did. Swept now: every cause row this module declares has both an import and a control. Executed: 26/26 controls PASS; On the superseded head — sent from keen-wolf-909 |
…er as a row REVIEW 64087, both findings correct and both mechanical. DEAD IMPORTS, SECOND SWEEP. V2EmitterInterpreted and EmitterProducerMintAdmission occurred ONLY inside // annotations; v2_emit_interpreted_qualified_module occurred nowhere at all. The review's authority is the precise one: DESIGN section 4c says semantic passes receive only the annotation-erased projection, so a name mentioned in a comment is NOT a consumer, and the module was declaring a dependency it does not have on the graph section 4 makes decidable. THE LESSON IS ABOUT THE SWEEP, NOT THE IMPORTS. Review 64035 already caught three dead imports in this file (length, emitter_producer_eq, generation_identity_agrees) and I swept them. Then the interpreted-emitter clause moved to emitter_producer_provenance IN THE SAME PR, orphaning three more, and I did not re-sweep. A dead-import check is valid only as of the last code move; treating one sweep as a standing fact is the same error as treating one run-status check as a standing fact, which I also made in this lane. THE THIRD FRONTIER WAS PROSE WHILE ITS TWO SIBLINGS WERE TYPED, inside one diff. genesis_migration_deletion_trigger and native_route_acquisition_frontier are DissolutionCondition rows -- converted earlier in this same PR precisely because section 4c forbids a dissolution condition living in a comment -- and then the V1SeedEmitter arm's frontier was written as prose. It would have been the one frontier of the three unreachable from the ledger that folds them. Now v1_seed_emitter_unconditional_admission_frontier, with the rationale staying as annotation and the CONDITION in the carrier. EXECUTED: parse gate clean on both edited modules; 26/26 own controls PASS; and because emitter_producer_provenance is a SHARED authority gaining a declaration, its siblings too -- emitter_producer_provenance_witness_test 3/3, direct_rust_door_group_algebra_test 23/23. Pushed after verifying 34650502656 at 61675c6 reported status=completed conclusion=success with all four jobs green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 64087 at Dead imports, second sweep. The lesson is about the sweep rather than the imports. Review 64035 already caught three dead imports in this file and I swept them — then the interpreted-emitter clause moved to The third frontier was prose while its two siblings were typed — inside one diff. Executed: parse gate clean on both edited modules; 26/26 own controls PASS; and because Pushed only after verifying run 34650502656 at — sent from keen-wolf-909 |
REVIEW 64112 (blocking) IS A REAL HOLE, and it is the class this PR files: a wall
with no red, in the numbering.
generation == parent + 1 is satisfied by parent = -1 at generation 0. So
SucceedsNative { parent_generation: -1 } minted GENERATION 0 -- the one
generation the migration boundary is DEFINED by -- without ever passing genesis
admission, and acquire_native_ancestor then accepted it as generation zero. No
other clause catches this: they ask about closures, build paths, read-backs and
executed bytes, none of which are about WHERE IN THE CHAIN a generation sits.
Closed at the source rather than at the successor's own number: refusing a
negative parent makes successors >= 1 by construction, so generation 0 has
exactly one constructor. Its own cause, because "the parent generation is not a
position in the chain" and "the numbering does not follow the parent" are
different defects with different remedies, and collapsing them would report a
fabricated chain position as an ordinary off-by-one. Discriminating control
added: every other field of that fixture is admissible, which is precisely why
the numbering had to be walled rather than left to the neighbouring clauses.
REVIEW 64113 IS THIS MODULE'S OWN DOCTRINE VIOLATED ONE FRAME DOWN.
build_path_admission took genesis: Bool, re-expressing the NativeAncestry
discriminant as a flag -- the shape the opening note rejects for used_seed, about
200 lines above the function that took it. A Boolean carries the fact while
leaving BOTH arms writable on either value, so (treatment: pinned, genesis: true)
against a SucceedsNative generation was an admissible call silently granting the
genesis-only pinned allowance. It now takes ancestry: NativeAncestry and reads
the discriminant from the value that carries it.
THAT FIX PRODUCES NO NEW CONTROL AND I AM NOT CLAIMING ONE. Both call sites
already passed the correct value, so it is LATENT rather than live: nothing
flips, and the count stays 27/27 across the change. The evidence is that the
invalid call became unwritable, not that a test went red to green.
EXECUTED: 27/27 controls PASS; v1_src_dag_parse clean on both edited modules.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
REVIEW 64141, and the defect is a CONTRADICTION BETWEEN TWO FILES IN THIS SAME PR. the_replaced_route_is_the_replacement_s_miss_path stated its residual as the host route: prepare_emitted_compiler still calls the seed emitter "until the acquisition surface replaces that call". It then named genesis_migration_deletion_trigger as the next-rung trigger -- which retires the GenesisFromSeed CONSTRUCTOR. ancestry.dag says in terms that the two are different capabilities and NEITHER DISCHARGES THE OTHER. So the row would have reported this class climbing on a capability that leaves its entire stated residual alive: the constructor could go while prepare_emitted_compiler kept calling the seed on every miss, which is the exact failure DESIGN section 4b(3) describes -- "a trigger naming less than the capability it restores will be satisfied while the capability stays dead". The row now names native_route_acquisition_frontier: the seed CALL replaced by acquire_native_ancestor, leaving no v1 emitter reachable from the acquisition path. It records what it previously named and why that was wrong, so the pairing cannot drift back, and notes that the constructor trigger is the LATER climb for the relation grain rather than this row's. WHAT MAKES THE TELL WORTH KEEPING: section 4b(3) gives it as a GRAIN MISMATCH between the loss sentence and the trigger sentence, and mine was a ROUTE loss answered by a CONSTRUCTOR trigger. That is checkable without understanding the domain at all -- compare the noun in one sentence to the noun in the other -- which makes it a better instrument than re-reading the prose for sense, and it is how the review found it. No code change. Parse gate clean on the edited row. Pushed after verifying 34656938388 at e0e923b reported status=completed conclusion=success. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Keep #11042 as the ancestry authority; retarget native-route consumers onto emitter_producer_mint/v2_emitter_closure_admission and SucceedsNative's produced_by_execution_of field. Recurring acquire stays the miss path. Co-authored-by: Cursor <cursoragent@cursor.com>
ANCESTRY lane, part 1 of 2 — the model. Operator design-review ruling 2026-09-11 C1: the seed is never the ordinary miss path.
What was wrong
The v2-native route acquired "the emitted compiler" by running the v1 seed in-process on every miss (
prepare_emitted_compiler→compile_entry_emission). Read as one execution that is correct and honestly receipted. Read as a migration it is the defect: the seed is not a step in the route that retires it, it is that route's standing producer. A replacement whose miss path is the thing being replaced retires nothing, and its removal date is unreachable because nothing ever stops depending on it.Filed as a class:
gunbc.recurring_failure_mode.the_replaced_route_is_the_replacement_s_miss_path, with the boundary against its neighbourabsorbing_fallbackstated — that class widens an answer, this one widens the lifetime of the thing being replaced.The model
v2.compiler.self_host.ancestry— exactly two constructors, no third:NativeAncestorAcquisition'sMissingandUnverifiedarms carry no producer at all, so a caller cannot pattern-match its way back to v1. The refusal names the generation it expected and why the candidate did not qualify.native_generation_producerprojects this module's ancestry onto the existingEmitterProducercoproduct inv2.compiler.self_host.emitter_producer_provenance. No second producer coproduct; noused_seed: Boolanywhere — a Boolean would carry the fact while leaving both routes writable on either value.V2EmitterInterpretedis reachable from no arm. An interpreted emit is a development route, never an ancestor; making it unprojectable is stronger than refusing it downstream.The mint refuses by named cause, per arm:
v1.compiler.emit_rust(a genesis that did not run the seed is not a genesis); build path pinned or remapped; read-back agreesReadBackReceiptcarries only what was observed and never a verdict; divergence is derived by comparing the report against the generation's own observed artifact digest, so a "verified" state cannot be authored beside a report that contradicts it.Genesis executes once — a second is a refusal naming the one that stands — and carries its deletion trigger at the grain of the capability that retires it (§4b meta-obligation 3), not at the grain of an artifact that would contribute to one.
Executed evidence
v2.test.claim.self_host.ancestry_witness, 17 controls, run viaclaim_batch --source-root dag --source-root src/v2 --entry src/v2/test/claim/self_host/ancestry_witness_test.dag --functions <all>.17/17 PASS on the module as written.
Falsification pass — not a green table on its own. With
native_producer_closure_admissionweakened to admit unconditionally and both read-back arms weakened toNativeGenerationAdmitted, exactly five controls flipped and twelve stayed green (no smear):genesis_whose_closure_omits_the_seed_is_refusedcorrectly stayed green — it reads the genesis arm's own check, which the mutation did not touch.Every fixture is Optional-valued and no control substitutes a value for a digest that failed to parse:
Sha512Digestis reachable only through the validating mint, so a broken fixture reports as a red control rather than a green one exercising a stand-in.What this PR does NOT claim
BuildPathTreatmentdoes not dischargeartifact_axis_omits_build_path. It is the declaration that obligation's two remedies were waiting for, and nothing more: remapping is a property of the build that produces the bytes, not of a carrier describing it. The obligation stays unbound until the emitted compiler is actually built with the remap and a two-directory control observes identical bytes. Binding it here on a declaration alone would be rung inflation.prepare_emitted_compilerstill calls the seed emitter. A class's rung is the minimum across its paths, so the class's rung today is the realization's, and the failure-mode row says exactly that.§3c consumption, stated plainly
In this PR the model's consumers are its 17 executed controls. The production consumer is a declared frontier, not a dangling model: scope item 4 replaces
prepare_emitted_compiler'scompile_entry_emissioncall withacquire_native_ancestor, and item 5 renamesOldRouteWithdrawntoOldRouteAbsentByConstruction(the closure half of whichnative_producer_closure_admissionalready decides here, once, rather than re-derived beside the route receipt).Trigger, and why it is a separate PR: #10940 is open and its diff touches both
src/v1/stage0/src/cli_run/native_lane_runner.rsanddag/gunbc/witness/v2_native_route.dag— exactly the two files items 4 and 5 edit. The brief's own base instruction is "main after #10940 lands," and its own ordering is declarations first, host realization second. Part 2 lands on top of #10940.Until
V2EmitterNative(N) -> N+1executes and verifies, the native route stays operator-invoked and non-blocking (claim_batch --v2-native-route); this PR changes no CI workflow and adds no job.🤖 Generated with Claude Code