Repository navigation
NAMESPACE XL-3: declaring-identity spelling census (carrier + producer) - #11210
gunbai-bot[bot] wants to merge 19 commits into
Conversation
afbe08e to
02abaad
Compare
|
review 64809, both findings verified against the tree and fixed in 8974786.
|
|
review 64884 (dashboard-only,
— sent from quick-otter-229 |
|
review 64912 (dashboard-only,
Absence claims now carry a present spelling on the same Accepted census: The truncated second path ( — sent from quick-otter-229 |
f45d628 to
08ba026
Compare
|
review 64968 (dashboard-only,
— sent from quick-otter-229 |
…ures only. Verdict fold is discriminated on labelled hand-built names. Producer wiring and the status arm stay held until ingest yields sites on real files. Co-authored-by: Cursor <cursoragent@cursor.com>
Type-position and call mentions stay invisible; value-outside-call is the class ingest can see. Carry unreadable roots when wiring; do not walk the parse tree. Co-authored-by: Cursor <cursoragent@cursor.com>
Carrier alone is not a landing; this is the s3c consumer. Fixtures measure today's loss (callee and kernel type-position absent; visible bare value Unbound). Status stays NotDerivable with those frontiers named. Co-authored-by: Cursor <cursoragent@cursor.com>
Matched control in one module with no call: value_only and user type_only reach; imported Bool in a parameter does not. Name InvisibleUntilTypePositionMentionSurvives as that capability, not #11207. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
… absent. A bare same-module survivor is not requalification work. Enroll the two-module discriminator; name InvisibleUntilQualifiedCrossModuleMentionSurvives rather than body-lowering as that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
…eck. review 64809: the path rows were unclassified commentary, and matching two data constants beside them was permanently green. Coverage of the producer is the production ingest witnesses, which already go red when a held class appears. Co-authored-by: Cursor <cursoragent@cursor.com>
…d census. Fixture 1 (Marker) and fixture 3 (unbound type) reach the producer. NotDerivable is the qualified cross-module miss, not type-position absence. Co-authored-by: Cursor <cursoragent@cursor.com>
Bare local `x: Marker` reaches; a dotted ProvidedMarker in a parameter does not. Same class as the dotted value Probe. Body-lowering is not that trigger. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…bilities. Enrolled cfp_own_module_site binds. Ingest fill does not insert the same-module data name at the collector's parser-keyed path, which is why the census row is Unbound -- not that v2 cannot compile it. Call contents stay lowering; qualified/dotted is not lowering; kernel Int has no corpus declaration. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
… parameter. ProvidedFieldMarker is used only as Wrapper.f. Absent today, same as dotted parameter and dotted value. Co-authored-by: Cursor <cursoragent@cursor.com>
The requalification fact is ResolvedPathVerdict; a second Bool match was a restatement. Equality for is_prefix_of is supplied at the call site. Same ingest now separates a bare parameter type from a bare field type so qualification is not blamed for the field miss. Co-authored-by: Cursor <cursoragent@cursor.com>
Absence claims now require Accepted ingest plus a present spelling on the same census (LocalParam / marker / ParamOnly). spelling_census_is_total was a Bool restatement of empty unreadable_roots and is gone. Co-authored-by: Cursor <cursoragent@cursor.com>
The fixture .dag files are the source text. Ingest reads them; the inline copies are gone. Declaring vs ownerless is carrier_provenance's collapse, not a second length(target) guard. Co-authored-by: Cursor <cursoragent@cursor.com>
…xtures. filesystem_read refused without the service in the import closure; the ingest census is otherwise unexecutable. Co-authored-by: Cursor <cursoragent@cursor.com>
ed278f1 to
0639108
Compare
ResolvedSpelling.declaring consumes carrier_provenance today; it must derive from OccurrenceBindingResult when that resolver answer exists, never a third identity. Co-authored-by: Cursor <cursoragent@cursor.com>
|
HELD under the operator wind-down: stacked on #11201 (base session/sharp-owl-21) and consumes its collector (collect_reference_sites) and carrier_provenance, so it cannot enqueue before #11201 lands; on that merge GitHub retargets this PR to main. Head 463200b: approval on head (claude 65434), 0 RC, CLEAN against its base. Classification: likely exempt (std.declaring_identity_spelling + v2.compiler.declaring_identity_spelling_census are instrument-side; confirm no src/v2/compiler/00_compile reachability at resume). RESUME: after retarget, one CI run on the head, fresh approval if the base moved materially, then enqueue on the manager gate. Standing stays StageXL3 NotDerivable by design (usable population invisible on the production tree; inherits XL-0's frontier row, trigger #11264). — sent from swift-bat-902 |
…' line The required floor's parser refused dag/std/declaring_identity_spelling.dag with 'expected expression, found Newline': the frontier row was authored as 'data x: T =' followed by a newline. #11210 was stacked on #11201 so its own CI never parsed the file; the integration branch's first floor run (0a7376d) did. No other declaration in the tree has that shape.
…must-not-resolve XL-3 fixture under test/probe Two refusals from the integration head's first floor run (35056157979), neither visible on the superseded PRs because #11209 never had a floor run and #11210 was stacked: 1. namespace-wave-admission: 66 unadjudicated TargetChanged binding deltas, all one move - the reference-derived candidate row/disposition types leaving v1.compiler.emit_rust for their one dag home gunbc.reference_derived_candidate (#11209 commit 42323e5), reached from v1.compiler.emit_rust (43 bindings) and v1.tests.claim.reference_derived_disposition_census_witness_test (23). Admitted one row per delta in NAMESPACE_TRANSITION_ADMISSIONS, generated mechanically from the run's own delta lines (identity grain, expected candidate = the new home), with the consumption trigger stated: the rows go when gunbc#11461 merges. 2. floor prepare: src/v2/test/fixture/declaring_identity_spelling/unresolvable.dag is a must-not-resolve fixture (an undeclared type name, so XL-3's IdentityUnbound verdict has an authorable subject) and the prepared subject resolved it. Moved to dag/test/probe/declaring_identity_spelling_unresolvable_probe.dag - the roster floor_prepared_subject_exclusions already excludes test/probe/ for exactly this class - with the probe header; the census reads it as source through the ingest route, so the test's path row is repointed and nothing else changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
Superseded by the NAMESPACE-XL integration branch #11461 (operator direction 2026-09-16: one integration branch for the five floor-met PRs). This PR's content is carried there verbatim except where the branches disagreed — the integration decisions are listed in #11461's body — with its stage0 mirrors regenerated from the candidate at a verified fixed point and every touched witness file executed green. Review history stays here; branch kept. — sent from swift-bat-902 |
…ired route; XL-3's ingest claims share one carried fixture read Two refusals on the integration floor run 35074340220 (01d5517). 1. The two Observed-arm controls added for review 66841 FAILED on the floor in under 300 microseconds while passing in 25 ms on a session host: compile_xl1_primary_root_tap gates on memory_governor whole_corpus_compile_admission BEFORE discovery, and the required floor never holds whole-corpus headroom mid-run. So the Observed arm has no required executing route today, and CaptureAvailable would be a rung read off controls the required route cannot run (DESIGN 4b(1)). legacy_baseline_capture_capability now reports the honest arm: CaptureBlocked { RepairCensusPhase, ObservedArmUnexercisedOnRequiredRoute { evidence_route, restoring_receipt } } (new refusal cause, rendered), naming the witness that executes the arm and the receipt that retires the block (a PersistedLegacyBaseline held against the pinned pre-cut base - ACT-0's BaselineCaptureReceipt). The two controls move to test.claim.long.xl1_live_tap_observed_arm_witness (long/ is declined from the required floor by route; they execute on a session host and on the one-time capture run); the floor keeps the refusal claims. The capability witness now asserts the blocked report and reds if Clear is read off an unexercised arm again. Consequence for the stage carrier: StageXL1BaselineCapture reads outstanding until the capture is taken, which is the truth. 2. Fifteen claims of v2.test.claim.declaring_identity_spelling.production_ingest were COMPLETED-OVER-COST-REQUIREMENT (130k-430k eval steps against the new-witness budget): each re-derived its own fixture parse-and-normalize per claim frame (shared_precondition_re_derived_once_per_claim_frame; #11210 was stacked so its own floor never ran). The eight fixture reads are now one PreparedEffectInput (xl3_fixture_reads) and the per-fixture censuses one CarriedInputWarmRow over it (xl3_fixture_censuses, ImplicitAcquisition); each claim is a field read of that value, each fixture is STILL its own single-file ingest, so nothing a claim measures changed. ingest_of and two_module_ingest are deleted (no consumer). Executed locally (branch seed claim_batch, scoped): legacy_baseline_capture 13/13, legacy_repair_tap_live_bridge 3/3, long/xl1_live_tap_observed_arm 2/2, compiler_frontend_program_status 39/39, declaring_identity_spelling/production_ingest 16/16, floor_prepared_effect_input_ladder 7/7, floor/pure_producer_share_refusal 13/13. claim_batch does not perform warm enrolment, so the XL-3 per-claim budget is proven by the floor run, not by these figures. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
Summary
std.declaring_identity_spellingand producerv2.compiler.declaring_identity_spelling_censusspelling_census_from_ingeston the production ingest route.v2.compiler.reference_site_collectorcollect_reference_sites(and ofv2.compiler.repair_input_origin_rostercarrier_provenance). A NAMESPACE XL-4: reference-derived dependency graph instrument #11202 reviewer called the collector dangling; that is a declared frontier that lands in this PR, not a second collector.declaring: DeclarationRefis a declared frontier inherited from NAMESPACE XL-0B/C/D: repair-input origin roster on the v2 route #11201. Today it is consumed fromcarrier_provenance(RepairInputDeclared), which is spelling-derived (owner-prefix drop + dotted render). Authority:std.declaring_identity_spellingdeclaring_identity_spelling_declared_binding_frontier_dissolve_onretires whenv2.compiler.repair_input_origin_rosterrepair_input_declared_binding_frontier_dissolve_onretires. Surviving authority isOccurrenceBinding<ScopedOccurrenceRef>(crisp-carp-634 / Model v2 indexed references with exact occurrence bindings #11264). When the v2 resolver emitsOccurrenceBindingResultby execution,RepairInputDeclared/DeclarationRefis derived from that binding and the spelling carrier is deleted. This census must then derivedeclaringfrom that binding and must never mint a third identity.canonical = ProvenanceResolved.target(03_resolve's SymbolIndex projection) is unaffected. Trigger is the resolver answering, not Model v2 indexed references with exact occurrence bindings #11264 merging.#11207. A trigger naming only body-lowering does not cover the miss.NotDerivable. Carrier does not land alone.Test plan
a_qualified_cross_module_mention_is_absent_from_the_census_todayPASS