Skip to content

v2.std.collection: primitive-backed map_insert/map_lookup delegates - #11121

Merged
briansrls merged 10 commits into
mainfrom
session/clever-fox-89
Sep 12, 2026
Merged

briansrls merged 10 commits into
mainfrom
session/clever-fox-89

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Replace the O(n) Map { lookup: ... } closure-chain bodies with HostRealizedSeam delegates matching empty_map_primitive_delegate, bound to map_insert_contract and lookup_contract.
  • Interpreter map grounding now intercepts the delegate spellings and refuses a non-native map shape instead of falling through into self-recursion; emitted Rust still lowers to v1_rt::rc_map_insert / v1_rt::lookup.
  • Discriminating cost witness: seam fidelity (RED if the closure-chain body is restored) plus first-inserted-key lookup at two sizes. No merge-blocking wall-clock literal.

Closes the capability named in #10940 review 64181 finding 1. The native-lane membership join stays open until it consumes this.

Test plan

  • cargo test -p v1-compiler --test interpreter_dispatch_authority --release
  • Required CI (build + witnesses) on this PR
  • Confirm v2.test.claim.map_carrier_shape_gate holds as a changed witness

Made with Cursor

gunbc-ci-auto-heal and others added 5 commits September 12, 2026 01:09
…closure chain.

Keyed lookup is now the same HostRealizedSeam shape as empty_map, bound to the declared insert and lookup contracts, so native maps stay HAMT on both the interpreter and emitted-Rust paths.

Co-authored-by: Cursor <cursoragent@cursor.com>
The build lane refused generated surface drift: the emitter orders primitive_lookup before empty_map, which the hand patch did not.

Co-authored-by: Cursor <cursoragent@cursor.com>
The seam still refuses wrap-body fallthrough; insert on a non-native
carrier returns the carrier unchanged so lookup stays Absent, which is a
Bool verdict (a TypeError is RuntimeErrored and cannot stay enrolled).

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep the inverted record-shaped control as a Bool predicate over the
same Value::Map match; a throw cannot stay enrolled as a floor verdict.

Co-authored-by: Cursor <cursoragent@cursor.com>
The predicate now runs map_insert grounding instead of a parallel
Value::Map match, so restoring Ok(None) fallthrough turns the control red.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64214 (#11121, dashboard artifact /api/reviews/64214/artifacts/stdout.log) asked to re-enroll a discriminating RED for record-shaped map_insert refusal, not replace it with projection-roster greens.

On 97ac69c941c that control is record_shaped_map_reaches_map_insert again. It feeds a Map { lookup: … } into map_insert_non_native_carrier_is_refused, which runs map_insert's own grounding and treats InterpError::TypeError as the Bool agreement. Restoring Ok(None) fallthrough into the wrap body makes that grounding return None, which the predicate reads as not-refused (RED). Roster HostRealizedSeam tests stay roster agreement only.

Calling map_insert directly from the witness still cannot stay enrolled: floor ExpectedRedArm::RuntimeErrored refuses to hold a throw. Next-rung trigger is named beside the predicate: an expecting-error harness that matches eval TypeError as a typed verdict (ExpectTypedPreVerdictRefusal has no eval-TypeError cause today).

@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64244 (dashboard artifact /api/reviews/64244/artifacts/stdout.log, SHA 25d1ead) asked two things that are no longer true of head 97ac69c941c:

  1. Do not delete the inverted record_shaped control. record_shaped_map_reaches_map_insert is enrolled again. It feeds a record-shaped Map { lookup: … } into map_insert_non_native_carrier_is_refused, which runs map_insert's own grounding and treats InterpError::TypeError as the Bool agreement (positive control native_map_reaches_map_insert is unchanged). Calling map_insert directly from the witness still cannot stay enrolled: floor ExpectedRedArm::RuntimeErrored refuses to hold a throw. That missing expecting-error harness is the next-rung trigger named on map_insert_non_native_carrier_is_refused (ExpectTypedPreVerdictRefusal has no eval-TypeError cause today). Restoring Ok(None) fallthrough into the wrap body makes grounding return None, which the predicate reads as not-refused (RED).

  2. Roster HostRealizedSeam tests are not a cost witness. The header no longer claims they would go RED if the wrap body were restored. They are roster agreement only. first_inserted_key_is_found_after_many_inserts is the executing cost witness (HAMT after n=8 and n=64).

— sent from clever-fox-89

A record-shaped insert refuses with InterpError::TypeError; n HAMT
inserts and sublinear first-key lookup steps witness the delegate vs wrap.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64269 (dashboard artifact /api/reviews/64269/artifacts/stdout.log, SHA 96e018eb) asked that map_insert Ok(None) refuse with TypeError, not return the carrier unchanged.

That arm is gone on head 0488c58eb1f. try_v2_std_collection_map_primitive_grounding maps Ok(None) to InterpError::TypeError for every grounded map primitive (same as lookup / empty_map). The inverted control is src/v1/tests/src/map_insert_record_shaped_refusal_test.rs, which asserts that located TypeError on a record-shaped Map.

— sent from clever-fox-89

@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64373 (dashboard artifact /api/reviews/64373/artifacts/stdout.log, SHA 97ac69c9) found an unrostered map_insert_non_native_carrier_is_refused intercept on v2.std.collection and an unbridged self-call with no projection row.

That declaration is deleted on head 0488c58eb1f. Map grounding only uses the rostered v1_map_grounding_arms! spellings; Ok(None) is InterpError::TypeError. The inverted TypeError control and HAMT cost witness live in src/v1/tests/src/map_insert_record_shaped_refusal_test.rs, not on the production collection surface.

— sent from clever-fox-89

… TypeError control.

Co-authored-by: Cursor <cursoragent@cursor.com>
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64382 (dashboard artifact /api/reviews/64382/artifacts/stdout.log, SHA 0488c58) asked to restore mod grounded_shared_carrier_wrap_test — the TypeError control had overwritten that enrollment.

Head 4c3fbb939db keeps both grounded_shared_carrier_wrap_test and map_insert_record_shaped_refusal_test.

gunbc-ci-auto-heal and others added 2 commits September 12, 2026 07:40
@gunbai-bot

gunbai-bot Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor Author

review 64382 (dashboard artifact /api/reviews/64382/artifacts/stdout.log, SHA 0488c58) was right: the TypeError control had overwritten mod grounded_shared_carrier_wrap_test.

On current head 19171508d33, src/v1/tests/src/lib.rs enrolls both:

  • mod grounded_shared_carrier_wrap_test;
  • mod map_insert_record_shaped_refusal_test;

The wrap-test file remains tracked; clippy --all-targets type-checks it again. No further change.

— sent from clever-fox-89

Keep NAMESPACE_TRANSITION_ADMISSIONS empty after #11137 retired on both sides.

Co-authored-by: Cursor <cursoragent@cursor.com>
@briansrls
briansrls merged commit dfac90c into main Sep 12, 2026
4 checks passed
@briansrls
briansrls deleted the session/clever-fox-89 branch September 12, 2026 14:30
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
Take main's namespace_wave_admission.rs (the #11121/#11137 prose dissolution) and restore the seventeen sizing Binding admissions on top. No rebase.

Co-authored-by: Cursor <cursoragent@cursor.com>
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
… replay

Three conflicts. namespace_wave_admission.rs is doc-comment only again -- main
recorded a thirty-sixth dissolution via #11121 and the roster is empty on both
sides -- so main's text is taken.

compiler_tests.rs and v1_compiler_compiler_tests_rust.rs are GENERATED. Main
changed their .dag generator (#78e8a188aad) and so did this branch (the
five-argument parse_with_table_in_occurrence_scope call); the .dag merged
cleanly, so the authority is right and only the derived files needed
re-deriving. With no build host available, both are booted from main and the
emitter's one-row delta replayed onto each -- the same move that CI's regen
phase confirmed byte-correct on #10850's parser mirror.

The generator mirror is emitted as one left-nested v1_rt::concat chain per
function, so the replay there splices the env row into the chain (one more
concat( at the head, ", E)" after the allocator row) and asserts paren balance
is unchanged. The build lane's regen phase adjudicates; a drift report means
the emitter disagreed and its bytes win.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NQnvBvFGNu9tNL544NJe2j
gunbai-bot Bot pushed a commit that referenced this pull request Sep 12, 2026
…re its row

MERGE of origin/main dfac90c (#11121, #11142, #11154, #10986). Three
conflicts. namespace_wave_admission.rs: main's THIRTY-SIXTH DISSOLUTION record
kept, this branch's 181 still-required rows kept with their 181
expected_candidates. accepted_source_emits_uncompilable_target.dag: took MAIN's
side -- their rung claim is mechanically preventable backed by executing
evidence, this branch's said still-mitigatable and is superseded, and their four
added receipts are preserved. v1_compiler_emit_rust.rs: resolved BY REGEN, never
text-merged; main's bytes stood as a placeholder and the regenerated mirror
overwrote them from the merged .dag authority.

THE WALK IS REPAIRED RATHER THAN DEFERRED, because the primitive it was waiting
for is now in the tree. #11121 landed as dfac90c (v2.std.collection
primitive-backed map_insert/map_lookup delegates), which is the capability the
declared drop named. DESIGN section 6: a proven cost-shape defect is always
fixed, and a trigger amended after the capability arrives is a deferral with
better wording.

SHAPE. native_lane_facts_index builds module -> imports ONCE, before the
recursion. native_lane_module_reachable looks up only what the frontier names and
carries seen_set through the recursion. Neither is rebuilt per round: rebuilding
either would reintroduce the cost under a keyed spelling.

A MODULE DECLARED TWICE APPENDS, AND THIS IS THE CASE A REVIEW WOULD HAVE
PLANTED. The fold this replaces visited every fact whose module the frontier
named, so two facts declaring one module contributed BOTH import lists. A naive
map_insert keeps the last and SHRINKS the closure -- a behaviour change wearing a
performance change's clothes, and the same silent narrowing this PR has already
repaired twice. The index appends on a duplicate key.

PRESERVED: declared membership; the refusal arms (fuel exhaustion still refuses
the whole derivation by identity with budget and frontier); last-round
completion.

DIVERGED, DELIBERATELY AND STATED ON THE CARRIER: discovery order is FRONTIER
order, not FACT order. Preserving fact order needs a per-round pass over all
modules to re-derive it -- the repeated scan this repair removes. It is
unobservable, checked rather than assumed: native_lane_closure_ingest filters by
membership (the ingest supplies its own order), both halves of
native_lane_ingest_matches_closure are membership tests, and the emitted receipt
carries `closure.len()`, a count, never the sequence. If a consumer that reads
the sequence ever appears, THAT change owns this order fact; it cannot be
inherited silently from here.

NOT CLAIMED: that the route is now O(closure). One walk changed. The instrument
is the universe_derivation span -- 192.4 s at 36e6ad9 -- and the successor run
on this head is the before/after. No cost witness is added: no corpus home can
hold a planted-quadratic control for this walk inside the 500 ms line without a
synthetic population that exceeds it, and a witness that cannot discriminate is
worse than none.

ROW RETIRED BY ITS TRIGGER, with the repair as the discharge, in this same
commit -- never in an intermediate state with the original scan still standing.
Retiring on the capability alone would have been the 4b(3) inflation: a row
marked discharged with the quadratic walk intact.

CITATIONS (review 64576). The row's population named native_lane_closure_grow,
which exists nowhere -- a section 3 citation defect, and worst in that field,
because 4b(3) requires a BOUNDED population and an unreadable member means
whoever discharges the row cannot enumerate what to delete. Corrected to the real
symbols. Every candidate symbol in both rung-drop rows and the seed-growth row
was then swept by git grep: 26 checked, all resolve.

AND THE REPAIR RE-STALED A CITATION FIXED MINUTES EARLIER: once the walk stopped
calling native_lane_facts_module_named, the `Consumers:` comment naming it was
wrong again. Corrected, and it now says the frontier walk no longer reads it.

Both projections regenerated mechanically on the final tree: the stage0 mirror
(installed from the candidate) and docs/design-rung-drops.md (4 added, 2 removed,
carrying the retirement).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aZDLk2CxsCDznqn49Xhe8
gunbai-bot Bot pushed a commit that referenced this pull request Sep 13, 2026
… new witnesses at the 100ms-equivalent

Operator ruling via fierce-lark-661, folded into the same change.

A single ceiling has to be either loose enough for the population that grew up
under 500ms or tight enough to be a standard for new work, and it cannot be both.
So the floor now carries a debt and a standard, not two standards.

THE ROSTER IS A MONOTONE DEBT CONTRACT AND ALL THREE OF DESIGN §5'S CONDITIONS
ARE MET RATHER THAN ASSERTED. The subject universe is independently discovered
and closed — 3,795 identities generated from run 34726300841's own
required_floor_disposition artifact, never hand-typed. Membership is at identity
grain. Rows may only LEAVE, each removal carrying a typed disposition; an
ADDITION REFUSES, which is what makes it a debt rather than a list that grows.

THE TIER IS DERIVED FROM MEMBERSHIP AND FROM NOTHING A CALLER SUPPLIES. No flag,
no `legacy` column, no label. An identity outside the roster cannot acquire the
larger budget by landing, by appearing in the tree, or by having been accepted
once. A rename is a deletion plus an addition, so a renamed witness is new —
that falls out of identity-grain membership rather than being a rule on top, and
it closes the one move that would launder an expensive witness into a fresh
identity at the old ceiling.

CALIBRATION. 723 steps/ms — 110,011/152ms, the slowest reading from the machine
that runs the floor, across five readings on two architectures that all returned
an identical eval_steps. Budgets 361,500 and 72,300; neither is a literal, both
are the tier's policy milliseconds through one conversion. THE SPECIMEN WAS
SHRUNK to 55,011 steps so it sits under the new ceiling it helps derive:
grandfathering the measuring stick would exempt it from the tier it defines.

TWO THINGS MEASURED RATHER THAN ASSUMED, BOTH OF WHICH CHANGED THE WORK.
- My own evidence breached the tier it installs. the_roster_identity_join_...
  cost 90,086 steps folded together, over 72,300, and these witnesses are NEW.
  Split into the join and a separate non-truncation check.
- Main landed 54 identities after the cut, so they classify NEW. Ran them: all
  54 under the ceiling. The 8 witnesses in that set that DO exceed 72,300 are
  every one of them grandfathered, so the tier does not red the floor on someone
  else's landings.

THE MAP-PRIMITIVE MEASUREMENT. The roster was built three ways: `any` over a
flattened list (92,490 steps / 148ms), map-backed via empty_map/map_insert/
map_lookup (39,940 steps — the FEWEST — and 36,000ms CPU), and a short-circuiting
descent (8,066/19ms hit, 43,583/76ms miss). map_insert returns a new map, so
folding n rows is O(n^2) host work and none of it is an eval step: the prescribed
repair for a nested scan reads as cheapest on the gated clock while costing 400x
the CPU. Per fierce-lark's ruling that is filed as a REALIZATION DEFECT in the
primitive (gunbc.recurring_failure_mode
nested_membership_scan_where_a_map_primitive_exists, owner clever-fox-89/#11121),
NOT as author guidance — a per-site "check your n" rule prices an exception
around a cost-shape defect. The descent stands as a stated interim.

REVIEW: the blocking bare-Int millisecond finding is fixed — specimen_cpu is
std.measure Millisecond and the conversion takes a Millisecond envelope.

90/90 witnesses green, clippy --all-targets -D warnings clean, --required-regen
first_generation_equal=true planned=155, both docs projections regenerated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BRTesxTRxhRGKX1py2pHVC
gunbai-bot Bot pushed a commit that referenced this pull request Sep 13, 2026
…ed standing

review 65283 on #11254: the appended receipt said the specimen is reproduced while the
older sentences still said NOT REPRODUCED and that no pre-#11121 binary had been run, so one
identity answered both ways about one fact. The specimen line now reads reproduced and names
where the reproduction lives, keeping the prior wording visible as prior wording; the
uncertainties row says which uncertainty is discharged and leaves the emitted-path and
denominator ones standing unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JKwxo5SvZ7qqsqEpEpEwVm
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant