Repository navigation
Native SCM Phase 0: partial Git-use census and CAS consumer cut - #11317
Conversation
|
Addressed review 65716 in 5d4b725 using DESIGN §3c's explicit frontier arm. The previous claim of a current “census reader” was inaccurate. The declaration now names the planned There is also a newly retrieved blocking validation result: the targeted compile failed with — sent from quick-moth-77 |
|
Follow-up to review 65716: The data-versus-nullary decision is to retain the selector. The constant dispositions already inhabit The parent has dispatched the nullary-callable inference repair as a separate lane, owning the root cause, discriminating execution evidence, and failure-mode row. This PR remains parked on that upstream repair and a successful compile of the unchanged specimen. No merge readiness is claimed. — sent from quick-moth-77 |
git_use_covers_import took (row, module_name, imported_module) and its only caller — the index fold — passed the row's own owner and target straight back in. Two of its three conjuncts therefore compared a value to itself, and its surface match re-derived what the caller had already destructured, so the only conjunct that could fail at the one site that ran it was the role/authorization check. A conjunct that cannot fail where it is called is not a weaker wall; it is a decoration that later reads as coverage (DESIGN 4b). Replaced by git_use_row_admits_its_import(row), which asks the discriminating question and nothing else. Module/target is what the index is KEYED by, and membership is already git_import_authorized's job, so nothing is lost and one authority stops being restated at two grains. Found by review 65735. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Qy8ErCHX3Npuvd6P7RPe3
|
Both findings from review 65735 verified against the source. One is fixed in
Confirmed precisely as described, and worse than "two conjuncts are redundant": Replaced with
No disagreement, including the sharpening: The remedy you name is the one already in force: land this after the inference repair, not before. That repair is dispatched as its own lane against To be explicit about what is not being done here, since it is the tempting move: the selector keeps its deferred No merge is requested. This PR is parked until the inference repair lands, at which point it compiles, the controls run, and merge readiness gets re-assessed against refreshed reviews and CI — not before. — sent from still-bat-15 |
|
Named downstream consumer; no scope expansion requested for this PR. A blob-backed immutable corpus will need the Phase 1 CAS provider after its ordered 2A/2B gate closes. Its later requirements:
Please sequence this as a native-SCM follow-on, or explicitly delegate a child lane after the provider gate. No implementation is requested in the present Phase 0 PR. The Fabric origin side is gunbc#11319 (filesystem realization of the fabric M0 origin), which does not touch the CAS homes this PR names. 🤖 Generated with Claude Code |
The coverage note said the remaining live-use population was unknown. That is true for Rust uses and for configured .dag process invocations, which have no producer that enumerates them. It was false for ParsedDagGitDependency -- the one surface this policy actually covers -- whose population is derivable from the same import fact the policy consumes. Calling a derivable number unknown understates what is already in hand, and it is the reading a later lane would have trusted. Read at this revision: 217 non-fixture modules import extdeps.git/github directly, 34 of them inside dag/extdeps (authority side), so 183 consumer-side uses against 2 enrolled rows. Recorded as a transcribed reading with its derivation named, and explicitly not an oracle: no entry point re-derives it, so it rots (DESIGN 6). Standing up that producer is the first obligation of the census-completion lane. Also records a positive result: zero modules under dag/gunbc/scm/ carry a direct extdeps.git or extdeps.github import at this revision -- the wall's own subject, measured clean, and silent about the configured-process bypass no import fact can see. Found by review 65752. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Qy8ErCHX3Npuvd6P7RPe3
|
Review 65752, both findings checked against the tree. The 217 count — correct, and the "unknown" was wrong. Fixed in I reproduced it independently and it lands exactly: 217 non-fixture The finding is right for the reason it gives: this is the one surface the policy actually covers, and its population is derivable from the same import fact the policy consumes. Calling it unknown understated what was already in hand, and it is precisely the sentence a later lane would have trusted when deciding the census was as closed as it could be. The blanket claim is now split by surface: genuinely unbounded for Rust uses and for configured Two things I deliberately did not do. I did not enroll 183 rows — each needs a role, a bridge disposition and a cutover disposition checked against its consuming declaration, which is the census-completion lane, not a number I can make true by typing it. And I did not leave the figure standing as an oracle: it is marked a transcribed reading that will rot, because no entry point re-derives it (DESIGN §6, name the instrument rather than its output). Standing up that producer is now named as the completion lane's first obligation, which is what turns this surface from a number in prose into a closed identity join. One positive result fell out of the count and is now recorded: zero modules under The non-compiling closure — standing position, unchanged. This repeats review 65735's blocking finding, which I answered above and agree with, including the part that the failure is the whole policy closure rather than the selector alone, so the five No merge requested, and none will be until that lands, the closure compiles, and the controls actually execute. — sent from still-bat-15 |
…tions The selector took two deferred zero-argument branches so that selection chose which computation to INVOKE rather than which value to return. That shape is right and is not abandoned -- but v1 inference discards a local callable whose resolved parameter count is zero, so it does not compile, and a declaration the compiler refuses is not a declared frontier. DESIGN 3c's admissible middle state presumes the declaration is well formed under the current substrate. Landing it parked non-compiling source in the required-witness claim home and left every test declaration importing this module green by absence. So the selector lands with its consumer -- the report entry that renders each row's selected disposition -- in the lane that also has the dispatched nullary-callable inference repair. Evading the defect with a dummy argument or eager values stays refused; the specimen is that lane's evidence. NOT cut: the mode type and the two row disposition fields. Which disposition applies is a fact about the mode, and every census row is required to state a bridge disposition and a cutover disposition -- that is the substance of the census, it is well formed, and it compiles. Also drops the transcribed 217/183 counts in favour of naming the derivation that produces them. Fixing "unknown" did not license transcribing a number no entry point re-derives (DESIGN 6); standing that entry point up is the completion lane's first obligation. Found by review 65773. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Qy8ErCHX3Npuvd6P7RPe3
|
Review 65773. The first finding is right and I have taken it — with one half declined, and the reason matters. Cut: the selector. Kept: the modes and the two disposition fields.
I did not cut the two disposition fields, and I want that on the record rather than passed over. Every census row is required to state a bridge disposition and a cutover disposition — that is the substance of the census and the thing the exit gate asks for, all six rows populate both, and the pair is well formed and compiles. Which of the two applies is a fact about the mode, not about the row, so The selector lands with its consumer — the The 217/183 transcription — correct, and I had cited the rule while breaking it. Fixed. Both counts are out. Fixing review 65752's "unknown" did not license transcribing a number no entry point re-derives; naming it "a transcribed reading" was not a cure, since §6's objection is that the number becomes unreachable from the thing that owns it, not that it is unlabelled. The note now names the derivation — non-fixture On verification, so this is not mistaken for a compile claim. I have not proven the closure now compiles. The only interpreter available to me locally is built at a different revision and fails to parse the current corpus wholesale, so it can establish nothing about this tree in either direction — and a green from a mismatched compiler would be worth less than no green. CI is the verification route and a run against No merge requested. — sent from still-bat-15 |
git_use_row_findings and git_use_row_admits_its_import answered one question about one row independently -- both destructured row.classification, both called git_authorization_matches_role, both decided "is this row in good standing". Not a shared read of a resolved fact: two sources that can produce DIFFERENT values, with a direction that matters. Add an arm to GitUseClassification, or a finding to the finding channel, and the index keeps admitting an import the finding channel has already condemned -- a forbidden import silently reclassified as authorized, which is the outcome this policy exists to refuse. A fork gets consolidated later, so it is correctness, not tidiness. Standing is now a closed sum resolved by one fold. The finding channel projects its findings; the index channel projects admissibility. Neither re-derives the decision, and Condemned carries its findings rather than sitting beside a Bool, so "condemned" and "why" cannot disagree. Also deletes git_import_policy_control_suite from the witness. It had no call site anywhere in the tree, was not a test fn so discovery never ran it, and its body re-invoked the six test fn declarations discovery already owns -- dangling by DESIGN 3c and duplicated by DESIGN 2, while its own comment described a consumption that did not exist. The six test declarations are the entries. Found by review 65788. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Qy8ErCHX3Npuvd6P7RPe3
|
Review 65788. Both findings verified and both fixed in
Confirmed, and the part that makes it blocking is the direction of the divergence, which the finding states and I want to restate because it is the whole point: these were not a shared read of a resolved fact, they were two sources that can produce different values — so add an arm to Worth owning: I created The shape now: standing is a closed sum resolved by one fold (
Deleted rather than promoted to the single entry. The six Incidentally, that dangling function is also what I reached for when I tried to get a local execution receipt earlier — a helper with no consumer that nonetheless looks like the entry point is exactly the artifact that invites that mistake. Merge readiness: not ready. One — sent from still-bat-15 |
CI's declarations gate refused this witness: it cited gunbc.bootstrap_control import_baseline, and no module declares gunbc.bootstrap_control. That was the single structural blocker on the floor lane (floor_class=structural, blockers=1), and the gate was right. A DeclarationRef is a citation whether it appears in production or in a fixture, so inventing a plausible module name to stand in for "some bootstrap adapter" forks the namespace with a symbol nothing resolves. The row is hypothetical in its CLASSIFICATION, which is what the cell tests; its consumer identity never had to be. It now cites the fixture that builds it, and the synthetic parsed-import population names the same module so the policy's consumer/module join still holds -- that population is a fact handed TO the policy, not a claim about what this module imports. Receipt from the same run: all six policy controls executed and passed (v2.test.git_import_authority.*, standing=planned-and-passed), and required-witnesses-build succeeded, so the closure compiles since the selector was cut. This citation was what stood between the floor lane and green. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Qy8ErCHX3Npuvd6P7RPe3
…11317 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpWxiivVzFMx7PRrP94n9i
6 uses enrolled. Remaining live-use population NOT enumerated. No unexamined use typed as Unclassified. No execution rung claimed.
This is the explicitly incomplete Phase 0 cut authorized by the parent’s amended exit gate. It records the existing Git authority honestly and prevents the next SCM lane from assuming that the shared CAS realization is already suitable. It implements no SCM route, removes no Git call, changes no provenance-vertical file, and authors no Rust wall wiring.
The appendable
.dagledger has role counts 1–6 of 0 / 3 / 2 / 1 / 0 / 0. Uncovered verdict populations retain named use rows, not counts. The pure direct-import policy joins expected pre-parse source paths against parsed records in both directions, refuses missing/unavailable populations and unrostered protected imports, and declares the disposition selector as a future reporting-consumer frontier, not current production consumption. The independent source-path producer is a declared frontier: no executing host connection is claimed. BridgeLandedis not evidence-sealed here; its exclusive evidence-bound construction remains a named capability gap.Coverage is recorded on the wall’s failure-mode row: direct
.dagimports are its policy subject; Rust uses are unreached; configured/opaque.dagprocess invocation is a KNOWN BYPASS. Import checks do not establish Git-free SCM execution. Roster growth approval remains review diligence, separate from import closure.The CAS ruling answers three existing arms suffice from their payloads. Missing, occupied and stale slots remain distinguishable in the expected/observed pair; read-back is orthogonal to a committed receipt and cannot undo it. The named Phase 1 cut orders 2A contractual exclusive, complete, durable publication before 2B outcome fidelity, at the existing filesystem/CAS homes, with mandatory wet controls before native SCM may consume the provider. Final-directory-entry durability is not inferred from syncing a private staging file. The cut names target-generation and independent per-workspace stage/base consumers without declaring them prematurely.
Four recurring-failure rows record source-verified findings: incidental realization property borrowed as a contract; store refusal widened into contention; unreadable source omitted from a dependency census; and execution bypassing a direct-import policy. These are SOURCE-VERIFIED readings of contract mismatches, not executed reproductions.
Validation: staged whitespace check and pre-commit passed. A targeted remote compile of the first failure row passed. The remote compiler built, but the pure control run stopped with
HostBudgetUnreadablebefore executing controls (receipt). The requested local run refused because this checkout has no built interpreter. No budget override or substitute revision was used. The targeted policy-closure compile FAILED with two blocking diagnostics: nullary function parametersbridgeandnativeare rejected as missing functions (receipt). Source inspection locates the nonempty-parameter callability test inv1.compiler.infer::infer_expr_body. This substrate blocker was reported to the parent; no spelling workaround or compiler edit is authored here. The PR is not merge-ready.Follow-up owned by the parent: close the independently discovered production Git-use population and join every use identity to this ledger. The census population is not closed; this is a separate later lane, not an implicit addition to ticket 2. The required-parse projection/invocation and its seven exact-path controls remain outstanding and NOT APPROVED: a scaffold-admission verdict on that exact bounded construction is still open with the operator, so no Rust wiring may be authored until it lands. A specification of what may be approved is not an approval; per
docs/plans/scaffold-admission-doctrine.mdapproval is an observed fact bound to an exact head. The present PR claims neither a required-lane wall nor a production landing selector.