Skip to content

NAMESPACE-XL integration: XL-4 graph instrument, XL-0 origin roster, XL-3 spelling census, exhaustiveness coverage key, XL-1 live tap (supersedes #11202 #11201 #11210 #11301 #11209) - #11461

Merged
gunbai-bot[bot] merged 142 commits into
mainfrom
integration/namespace-xl
Sep 17, 2026

Conversation

@briansrls

@briansrls briansrls commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Single integration branch for the five NAMESPACE-XL PRs that were each at the tally floor and blocked only on integration and the class-1 receipt (operator direction, 2026-09-16: "make a single integration branch"). It supersedes and closes:

Each superseded PR keeps its review history; the integration resolves their mutual conflicts once.

Integration decisions (where the branches disagreed)

Regeneration receipt

  • Seed for the first generation: built from origin/main 23a15bd in an isolated worktree (claim_executor sha256 cd7107a4eb0d10df…). claim_executor --required-regen --regen-affected-scope --source-root dag --source-root src/v2 on this branch: regen-scope WholePopulationScope, planned/executed/adjudicated 156, elapsed 463,757 ms, sampled peak RSS 12,060,996 KiB under ulimit -v 23,000,000 KiB (cap proven beforehand with a must-fail 24 GiB allocation control). Adjudicator named exactly four drifted paths (v1_compiler_emit_rust.rs, v1_compiler_infer_method.rs, v1_compiler_infer_patterns.rs, v1_tests_claim_reference_derived_disposition_census_witness_test.rs; declared_divergent=1 [main.rs] pre-existing); whole-candidate src comparison found the same four and no other. Installed from the candidate (commit 4bcc89c).
  • v1_interpreter_dispatch_generated.rs is healed by generated_artifact_gate main_wet, not by --required-regen: regenerated with the main seed's gunbc (commit 0a7376d) — main's file plus the one XL-1 arm; main_wet rewrote no other artifact.
  • Hand-written seed file v1_interpreter.rs: origin/main's file plus XL-1: emit-rust repair-row interpreter bridge and persist producer #11209's two additive hunks (+363), after a cherry-pick resolution had wrongly taken XL-1: emit-rust repair-row interpreter bridge and persist producer #11209's whole-file copy (commit ab2ec3c).
  • Fixed point: the seed built from THIS branch regenerates every mirror byte-identically — first_generation_equal=true, 156/156, on 0a7376d (peak 12,076,856 KiB), again after merging main's Refuse duplicate record-literal fields (build the declared trigger of duplicate_record_literal_field_silently_last_wins) #11391 (peak 12,123,248 KiB), and again on 7898426 after the parse fix (regen4). The branch is buildable at every head after 0a7376d.

Evidence

Every claim file touched by the five PRs, executed to completion with the branch's own claim_batch (scoped --entry/--functions, ulimit -v 23 GiB), on 7898426 / 114ba1d:

dag/test/claim/compiler_frontend_program_status_witness_test.dag: exit=0 PASS=39 FAIL=0 of 39
dag/test/claim/legacy_baseline_capture_witness_test.dag: exit=0 PASS=13 FAIL=0 of 13
dag/test/claim/legacy_baseline_persisted_observation_witness_test.dag: exit=0 PASS=3 FAIL=0 of 3
dag/test/claim/legacy_repair_observation_witness_test.dag: exit=0 PASS=24 FAIL=0 of 24
dag/test/claim/legacy_repair_tap_live_bridge_witness_test.dag: exit=0 PASS=3 FAIL=0 of 3
dag/test/claim/legacy_repair_tap_persisted_capture_witness_test.dag: exit=0 PASS=5 FAIL=0 of 5
dag/test/claim/match_exhaustiveness_coproduct_witness_test.dag: exit=0 PASS=26 FAIL=0 of 26
src/v2/test/claim/declaring_identity_spelling/production_ingest_test.dag: exit=0 PASS=16 FAIL=0 of 16 (re-run after the fixture move: 16/16)
src/v2/test/claim/declaring_identity_spelling/verdict_fold_test.dag: exit=0 PASS=5 FAIL=0 of 5
src/v2/test/claim/namespace_xl0/call_argument_mention_survival_test.dag: exit=0 PASS=14 FAIL=0 of 14
src/v2/test/claim/namespace_xl0/field_type_tree_presence_test.dag: exit=0 PASS=4 FAIL=0 of 4
src/v2/test/claim/namespace_xl0/repair_input_origin_denominator_test.dag: exit=0 PASS=7 FAIL=0 of 7
src/v2/test/claim/reference_derived_graph_call_arg_tree_test.dag: exit=0 PASS=9 FAIL=0 of 9
src/v2/test/claim/reference_derived_graph_fixture.dag: 0 claims (fixture/helper module)
src/v2/test/claim/reference_derived_graph_production_ingest_test.dag: exit=0 PASS=16 FAIL=0 of 16
src/v2/test/claim/reference_derived_graph_witness_test.dag: exit=0 PASS=5 FAIL=0 of 5
src/v2/test/claim/repair_input_origin_split_witness_test.dag: exit=0 PASS=4 FAIL=0 of 4

193/193. First integration floor run (35056157979) refused twice and both are repaired in 114ba1d: 66 unadjudicated TargetChanged deltas (#11209's type-home move, admitted one row per delta with the consumption trigger) and the must-not-resolve XL-3 fixture resolved by the prepared subject (moved under dag/test/probe/). Earlier run 35053755879 refused dag/std/declaring_identity_spelling.dag at parse (data … = before a newline) — fixed in 7898426; #11210 was stacked so its own CI never parsed it.

Classification

Class 1 (pre-landing receipt): reachable emitted-closure members v2.std.qualified_name, v2.compiler.program_assembly, v2.std.node, std.repair_input_origin (+ mirror), and the seed (v1.compiler.infer_patterns, the XL-1 builtin, regenerated mirrors). One receipt for the whole train instead of five.

🤖 Generated with Claude Code

https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC

Native-route deltas outside the pre-registration (srv2 pair fold11461g on 1cc0117)

  • REMOVED file_refusal dag/extdeps/systemd/systemd.dag {sugar_reason_malformed}: attributed to Key the declared constructor and the pattern with one identity #11301 (in this train, commit 77c99ea) deleting the duplicate SubState variant of SystemdUnitProperty and its duplicate match arm; the removal is why T's terminal reaches admitted=true.
  • ADDED file_refusal src/v2/compiler/program_assembly.dag {parse_g0_tokens_remain}: caused by type LocatedNormalizedTree sole_constructor { ... }; the v2 grammar realization (v2.extdeps.languages.dag dag_grammar_type_decl_expr) admits no modifier between the type name and its field block. Repaired in e424b72 by making it a plain record (the pair carries no invariant beyond its fields).

gunbc-ci-auto-heal and others added 30 commits September 12, 2026 19:35
…ng since it was written

v2.compiler.resolution_provenance models one name resolved at one position answering
with its target and the module that contains it, and it models the dependency fold over
those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were
five hand-authored fixture rows in one witness, which makes a well-shaped module dangling
in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather
than executed. This is that producer.

ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived
graph ask the same question of the tree -- where is every mention, and at what containment
position -- and differ only in what they fold the answers into. Two collectors would be the
section 3 fork with the widest blast radius, because a mention one missed would be silently
absent from both a denominator and a dependency edge. Landed as its own commit so XL-4
consumes it rather than building a second one.

A declaration's NAME is an edge label and never a node, so an Atom is a reference by
construction rather than by a filter that could be wrong. The two exclusions -- module
header metadata, and _node_projection parse projections that would double-count every
mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
std.repair_input_origin's header defers the DeclarationCarrier half to XL-0B/C. This
lands it -- on the v2 route, per the fierce-lark-661 ruling: v1.compiler.emit_rust is
scheduled for deletion and may at most consume, never own. No src/v1 edits.

THE SIX v1 CHANNELS HAVE NO v2 ANALOGUE AND ARE NOT PORTED. They are collectors inside
v1.compiler.emit_rust's Rust use-line planner; v2 emits no use lines and has no such
planner, so reproducing them would mint a dying emitter's artifact on a route that never
carried the surface. What survives the route change is the QUESTION -- what an
import-to-containment repair takes as input -- and on v2 it is a resolver fact:
v2.compiler.repair_input_origin_roster folds the resolver's four answers, over the
mentions the reference-site collector enumerates.

THE MODEL. SourceDeclarationCarrierIdentity carries a DeclarationRef and NEVER a
CorpusDeclared decl_file -- one fact, one identity. The three departures from
std.coercion TypeDeclarationProvenance are stated beside the type (DESIGN section 3b
admits a stated divergence and refuses a silent one): the position; the KernelMinted arm
having NO PRODUCER on this route, so carrying it would be a permanently uninhabited
decoration rather than a weak wall; and DeclarationIdentityAbsent conflating unbound with
ambiguous, which are two states with two repairs. There is deliberately no
referencing-module field: the module is the longest rostered prefix of the position, so a
second field would store one fact twice and then need a fabricated answer for a position
no roster covers.

GRAIN. Every mention is a row, each with its typed resolver arm. No filter on
import-mediation or eligibility -- the stage label says BEFORE eligibility or repair
disposition, and a denominator that filtered would be measuring its filter.

EVIDENCE BY EXECUTION, AND THE WALLS DISCRIMINATE. Five witnesses pass; four mutations,
one per wall, each reds its own wall and leaves the others standing:
module-header exclusion removed -> the declared-names wall; a dotted mention walked per
segment -> the one-site wall (and the declared-names wall, since the segments become
spurious mentions); the position not extended by named edges -> the containment-position
wall (and the positive control, which reads that position); unanswerable mentions dropped
-> the not-a-drop wall.

CARRIERS. StageXL0Denominator was NotDerivable; it now reads the same delivery-receipt
channel XL-2 and XL-4 read, so a repair to probe observability still cannot move it and
only delivering the producer can. MissingInstrument RepairInputOriginRosterProducer is
deleted. The expecting-red status witness did NOT retire -- DESIGN section 4b(4) -- it
flipped to a permanent regression control asserting the same rule on the arm that now
stands. ACT-0's DenominatorRosterDigest stays outstanding, correctly: a delivery receipt
carries no base, and pinning one is ACT-0's act.

The census row now says where its undischarged half went: the v2 DeclarationRef carrier
discharges it, and the v1 position retires when v1.compiler.emit_rust is deleted, not by
a conversion.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…rier

Installed from the generated candidate, never hand-edited: the mirror is a generated
artifact and the authority is dag/std/repair_input_origin.dag.

Adjudicated by `claim_executor --required-regen --regen-affected-scope`, which named this
one path and no other (declared_divergent=1 [main.rs] is pre-existing and is not in the
differing set). Verified by diffing the whole candidate src tree against the committed
one file by file: std_repair_input_origin.rs is the only file that differs, and its diff
is exactly the new provenance coproduct, the carrier identity struct, the
SourceDeclarationCarrier arm and its two match arms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…trument.

Fill the existing swap-body producer from resolved qualified-name sites (never import syntax), report typed diffs against the import graph, and hold the stage delivery receipt. Do not swap dependency_resolution_facts_live.

Co-authored-by: Cursor <cursoragent@cursor.com>
…umer

Review 64751. The finding is correct and I confirmed it independently: the whole body was
`is_empty(xs: roster)` and `git grep` returned exactly one occurrence in the tree -- its own
definition. That is two defects at once, a second name for one concept (DESIGN section 3) and
a declaration with no call site in the closure (section 3c's third state, the only red one).
Callers wanting emptiness call is_empty directly.

Also drops the `is_empty` and `Bool` imports it was the sole user of. Removing the function
while keeping its imports would have left a smaller instance of the same defect.

The sibling entry point repair_input_origin_denominator_digest_lines is deliberately NOT
deleted: it is also unconsumed today, but it names its consumer and the pinning act (ACT-0)
beside it, which is section 3c's admissible declared frontier rather than a dangling
declaration. The review reached the same conclusion.

Re-ran the five XL-0 witnesses after the deletion: 5/5 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…ngling declaration

Three defects, all mine, all introduced by this branch. The required floor named all of
them in one refusal; I had independently found the first before its log was retrievable.

1. NON-EXHAUSTIVE MATCH (the floor red). Adding the SourceDeclarationCarrier arm to
   RepairInputOriginCandidate left two wildcard-free two-arm matches in the pre-existing
   XL-0A split witness. That is the ordinary compiler floor DESIGN section 4b names --
   "closed variants eliminate exhaustively" -- and the roster module's own annotation
   predicts exactly this ("a fourth arm added to the shared base refuses to compile here").
   Swept every .dag touching the coproduct rather than only the file CI named: four files,
   of which the producer and the XL-0 witness already handled all three arms.

2. SOURCE ANNOTATIONS INSIDE DECLARATION BODIES, in the XL-0 status arm and in the
   regression control's test body. Hoisted above their declarations, which is the only
   grain DESIGN section 4c models. Swept the whole branch diff: no indented `//` remains.

3. repair_input_origin_denominator_digest_lines DELETED (review 64768). It had no call
   site, and the declared-frontier defence did not attach to it: the delivery receipt names
   repair_input_origin_roster_over_roots, a different function that IS consumed, and both
   of this one's components are exercised by the XL-0 witness. Review 64751 had passed the
   same declaration as an admissible frontier; that read did not check which symbol the
   receipt names. The surviving annotation records why the wrapper is absent so it is not
   re-added.

WHY DEFECT 2 SURVIVED A GREEN LOCAL RUN, measured rather than assumed. On the identical
unmodified tree the floor refused, `claim_batch` returned PASS rc=0 for the same witness.
A controlled probe -- one module whose only content is an in-body annotation -- then showed
BOTH local instruments admit it: claim_batch PASSes, and `gunbc run` reaches evaluation and
returns true. So neither local execution path gates this class; only the floor's strict
preparation does, and the cheap local guard is syntactic (grep changed .dag for indented
`//`), not executional. The probe fixture was deleted rather than committed.

Re-ran after the repair: 9/9 PASS across both witness entries (4 XL-0A split + 5 XL-0).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Blanket filesystem import on module_graph forked List onto std.types and the
new claim tests were censored at the enrolment ceiling; the producer stays on
the named swap body and tools.reference_derived_graph.main remains the RED.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ng since it was written

v2.compiler.resolution_provenance models one name resolved at one position answering
with its target and the module that contains it, and it models the dependency fold over
those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were
five hand-authored fixture rows in one witness, which makes a well-shaped module dangling
in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather
than executed. This is that producer.

ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived
graph ask the same question of the tree -- where is every mention, and at what containment
position -- and differ only in what they fold the answers into. Two collectors would be the
section 3 fork with the widest blast radius, because a mention one missed would be silently
absent from both a denominator and a dependency edge. Landed as its own commit so XL-4
consumes it rather than building a second one.

A declaration's NAME is an edge label and never a node, so an Atom is a reference by
construction rather than by a filter that could be wrong. The two exclusions -- module
header metadata, and _node_projection parse projections that would double-count every
mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Delete the module_graph mention walk. The swap body consumes
collect_module_reference_sites and module_dependencies_from_sites.

Co-authored-by: Cursor <cursoragent@cursor.com>
…es and EMPTY on the corpus

The receipt this branch landed said the XL-0 instrument was "delivered and discriminated
once". It had been discriminated against HAND-BUILT Node trees. Over the tree the
production ingest actually yields, the collector returned NO sites at all. That is
DESIGN section 5's specification-without-execution in its most flattering form -- the
witnesses really executed, against a universe the corpus never produces -- and a stage
reading CLEAR off it reports a denominator that does not exist.

Raised by the XL-2 lane, independently reproduced by warm-ibex-518 over real .dag files,
and confirmed here by a substrate-only fixture that drives the REAL ingest
(module_roots_from_source_root_ingest, projected through normalized_tree_roots_to_nodes --
the same projection symbol_index_fill consumes, so the modeled route, not a workaround).

WITHDRAWN: the StageDeliveryReceipt row, DenominatorRosterInstrumentDelivered, and
StageXL0Denominator reading CLEAR. RESTORED: NotDerivable, awaiting
RepairInputOriginRosterProducer -- whose label now demands a NON-EMPTY denominator over the
production route, so the same claim cannot be re-made on the same evidence.

TWO DEFECTS, BOTH ISOLATED BY MUTATION, ONLY THE FIRST MINE:

1. THE BLACKOUT WAS MY OWN SPECULATIVE GUARD. The collector skipped every `_node_projection`
   edge to prevent a double-count I never demonstrated. On a real ingested tree a module's
   content hangs under exactly those edges, so the guard returned zero sites corpus-wide
   while synthetic fixtures stayed green. Deleted. The lesson is kept in the module rather
   than only here: a speculative exclusion over a shape the author has not observed is
   indistinguishable from a blackout until something executes against the real tree.

2. WITH IT GONE, THE ERASURE IS REAL AND WIDER THAN CALLS. Measured on the production route:
   a value reference outside a call and a parameter reference ARE found; a call argument, a
   CALLEE name, and a TYPE-POSITION name are NOT. Type references are most of what an
   import-to-containment repair operates on, which is why XL-0 has no denominator yet rather
   than a slightly small one. Trigger: the v2 body-lowering repair (XL-2, gunbc#11207).

ALSO FIXED, from review 64782: spine unwrapping ran on EVERY node, but
namespace_graft_spine_segment_edge_optional recognises ANY single named edge targeting a
Conj, so recursion silently dropped nested declaration and field labels from `position` --
a mention recorded at a chain it does not sit at, resolved against the wrong scope. A
mislocated mention is worse than a missing one: it is a fabricated plausible answer rather
than an absence someone can count. Unwrapping is now one move at the module boundary.

THE MEASUREMENTS ARE ENROLLED, NOT NARRATED. v2.test.claim.namespace_xl0.call_argument_mention_survival
asserts what the production route produces TODAY, so each deficiency row goes RED when the
lowering repair lands and the repair must return here and re-state what is true, instead of
widening a denominator nobody re-measured.

42/42 PASS: the 8 production-route probes plus the 34-test program-status closure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
The swap body folds collect_module_reference_sites through
module_dependencies_from_sites. Witness tests over the fixture identities
require a reference-only edge, no unused-import edge, exactly one shared
edge, and go red on a mutant that re-admits import-decl mentions.

Co-authored-by: Cursor <cursoragent@cursor.com>
…urn type moves)

Review 64782's second finding, and the manager's condition for #11201 moving. The arm was
`Rejected => acc`: a root whose module header does not resolve contributed no mentions and
NO EVIDENCE, so a caller could not distinguish an unreadable module from an empty one.
DESIGN section 5 calls that a hard reject rather than a weak arm -- a failure arm must
refuse, never widen, and every degradation must be a typed, located, countable diagnostic.

UnreadableModuleRoot { locus } is all three, and COUNTABLE is the property that matters
here rather than merely typed: XL-0 is a DENOMINATOR, so a root silently missing from it
does not make the number slightly small, it makes it a different question answered under
the same name. "n roots were unreadable" is now answerable instead of inferred from a short
population.

THE REFUSAL TRAVELS WITH THE RESULT, NOT BESIDE IT. collect_module_reference_sites and
collect_reference_sites now return ReferenceSiteCollection { sites, unreadable_roots }, and
repair_input_origin_roster_over_roots returns RepairInputOriginRoster { carriers,
unreadable_roots }. A caller cannot take the population without also taking what was lost
producing it. A collector that counted the loss and a producer that discarded it one call
later would be the same silent degradation a layer down, so the seam has its own wall.

Both walls assert BOTH halves, because either alone is satisfiable by a wrong
implementation: the sites must be unchanged (the unreadable root really did contribute
nothing) AND the refusal must be present and countable (it said so).

INTERFACE CHANGE, TAKEN DELIBERATELY AND ANNOUNCED FIRST. warm-ibex-518 (XL-4) and
quick-otter-229 (XL-3) consume these entry points and are rebasing; the names are unchanged
and only the return types moved, so the migration is `.sites` / `.carriers` at the call
site, or consuming the refusal list where a total is required.

NOT DONE, DELIBERATELY: no parse-tree walker was revived to route around the lowering loss.
The type-position and call-expression erasure stays escalated rather than worked around,
and XL-0 stays NotDerivable with its probes enrolled.

15/15 PASS across both XL-0 witness entries, including the two new refusal walls.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A fixture whose only provider mention sits in a call argument yields no
reference-derived edge on parse_module trees (XL-4 ingest) and on
normalized trees. Trigger is eager-raven-113's body-lowering repair.

Co-authored-by: Cursor <cursoragent@cursor.com>
Your collector over parse_module trees does not recover type-position or
out-of-call body mentions either; the rows record that absence until lowering
and site collection catch up.

Co-authored-by: Cursor <cursoragent@cursor.com>
…module miss measured

Review 64799, both findings verified against the code before acting, plus a correction that
came from XL-4's execution rather than from review.

1. SPINE UNWRAPPING WAS WRONG BY length(module_qn) - 1. namespace_graft_fold_spine wraps
   ONCE PER SEGMENT; this unwrapped one level, and the generic named-edge rule then walked
   the survivors as ordinary containment -- re-appending those segments to a position that
   already carried them, so a mention in `a.b.c` was recorded at `a.b.c.b.c`. A mislocated
   mention is a fabricated plausible answer (section 5) and changes which lexical scope the
   resolver walks, so it is worse than an absent one.

   THE COUNT IS DERIVED, NOT GUESSED: it is the module qualified name this walk already
   resolved from the header, the same value the spine was folded from. Not a
   loop-while-the-shape-matches, because namespace_graft_spine_segment_edge_optional
   recognises ANY single named edge targeting a Conj, so a shape-driven loop would eat a
   genuine one-declaration module body. Consuming the count makes over-unwrapping
   unwritable rather than unlikely.

2. THE TRAVERSAL WAS QUADRATIC. qualified_name_from_node folds an entire subtree to answer,
   and this walk then descended into that same subtree, so each nesting level re-folded
   everything beneath it and everything beneath it was walked again. Now guarded by an O(1)
   shape check -- Conj, exactly two children, both labelled head/tail -- using the SAME two
   labels v2.std.qualified_name's own fold recognises, so it is a cheap precondition on that
   authority rather than a second weaker spelling of it. Section 6: a proven cost-shape
   defect is always fixed regardless of the realised n.

3. THE COVERAGE CLAIM I PUBLISHED WAS TOO BROAD, AND THIS IS THE IMPORTANT ONE. I reported
   "a value reference outside any call IS found". That was a BARE SAME-MODULE name.
   warm-ibex-518 measured a QUALIFIED CROSS-MODULE reference and found nothing; the
   discriminator is now enrolled and confirms it. So the production-route population is:

     SURVIVES:  a bare same-module value reference outside any call; a parameter reference
     DOES NOT:  a qualified cross-module reference, with or without a call;
                a call argument; a callee name; a type-position name

   A bare same-module name resolves inside its own module, so it yields no dependency edge
   and contributes nothing to an import-to-containment denominator, which is BY DEFINITION
   about references that cross a module boundary. The surviving population is the part
   neither XL-0 nor XL-4 has any use for. Stated in the file so no reader mistakes a
   non-empty site list for a working instrument.

The partition is unchanged by fixes 1 and 2 -- re-measured after them rather than assumed.
16/16 PASS across both XL-0 witness entries.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…cle only.

The walk sees type-position ProvidedMarker and still misses body-value and call-arg names. It is not the edge producer.

Co-authored-by: Cursor <cursoragent@cursor.com>
… as a graph.

An unread module must not look like a leaf. The fold carries unreadable_roots; the production Outcome refuses unless the fold is total.

Co-authored-by: Cursor <cursoragent@cursor.com>
module_roots_from_source_root_ingest then normalized_tree_roots_to_nodes is the tree. On that route a qualified value mention is still missing, same as type-position and call contents; those rows are measurements of today.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ns DO reach the collector

Review 64815, and it is the most consequential finding on this PR. fixture_sites folded the
ingested roots with `cons: fn(acc, root) { collect_module_reference_sites(root: root).sites }`
-- DISCARDING acc -- so it returned only the LAST root's sites and threw away
.unreadable_roots at the only production-route call site in the change.

WHY THAT WAS FATAL RATHER THAN UNTIDY: every load-bearing row in this file is a NEGATIVE
claim, and a negative claim is satisfied for free by a population that never contained the
root in question. The census was truthful about one module while reading as though it
covered two, and its control was green by INGEST ORDERING rather than by the walk --
reorder the reads and the whole result changes with no test naming why. That is DESIGN
section 5's fabricated plausible output: an absence measured over a silently truncated
population.

WHAT IT COST, MEASURED OVER THE FULL POPULATION: a TYPE-POSITION name IS PRESENT. I had
reported it absent. `Bool` is mentioned in both fixture modules and the provider's sites
were the ones dropped, so the absence was manufactured by the fold. That claim had already
travelled: XL-3 was holding type-position census fixtures red on it and XL-4 carried a
type-position row on its declared frontier. Both lanes have been sent the retraction.

CORRECTED PARTITION, re-measured over every ingested root:
  SURVIVES:  a bare same-module value reference outside any call; a parameter reference;
             a TYPE-POSITION name
  DOES NOT:  a qualified cross-module reference, with or without a call; a call argument;
             a callee name

THE DISPOSITION IS UNCHANGED: XL-0 stays NotDerivable, because a denominator is made of
cross-module references and those still do not reach the collector.

TWO CAUSES, ONE LESSON. It hand-rolled a traversal beside collect_reference_sites, which
already threads the accumulator AND carries both halves -- the section 3 fork, in the one
file whose job is measuring that collector. And it discarded the typed, counted refusal
THIS PR ADDS so that a lost root cannot be mistaken for an empty one.

A SECOND INSTANCE THE REVIEW DID NOT NAME: characterise_the_module_header_resolves_on_a_
normalized_root dropped `acc` the same way, one screen below. Found by sweeping the pattern
rather than fixing the reported line. Both now conjoin over every root.

TWO NEW WALLS MAKE THE POPULATION ITSELF A SUBJECT, either of which would have caught this:
the census must speak for every ingested root, and the collection must be total, so an
unreadable root can never be the reason an "is absent" row is green.

11/11 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Both carriers said the remaining miss was call erasure, triggered by the v2 body-lowering
repair. That is the 4b(3) defect stated in DESIGN's own words: a trigger naming less than
the capability it restores is retired BY that trigger while the capability stays dead.

Body lowering (XL-2, gunbc#11207) restores the CALL classes and nothing else. The class that
actually denies XL-0 a denominator is the QUALIFIED CROSS-MODULE reference, which is absent
with or without a call. So the repair could land, the trigger would read satisfied, and XL-0
would still have no denominator.

MEASURED OVER EVERY INGESTED ROOT, which is new since the census truncation was fixed:
  REACHES IT:  a bare same-module value reference outside any call; a parameter reference;
               a TYPE-POSITION name
  DOES NOT:    a qualified cross-module reference, with or without a call;
               a call argument; a callee name

A bare same-module name resolves inside its own module, so the surviving population is the
part an import-to-containment denominator cannot use.

THE THREE CAUSES ARE NOW SEPARATED WITH HONEST OWNERSHIP: two were mine and are fixed (the
parse-projection exclusion that blacked out the corpus; the census fold that discarded its
accumulator and so measured the last root only, manufacturing a type-position miss that does
not exist). The third is OPEN AND DELIBERATELY UNATTRIBUTED: a dotted reference in a body is
not a qualified-name production at all, so the collector never reassembles it, and whether
resolution itself reads dotted body access has NO EXECUTED ANSWER -- the probe built for it
fails its own control, and a structural absence is not evidence.

The capability is now named directly: XL-0 derives when the producer answers NON-EMPTY over
CROSS-MODULE references on the production route.

I flagged this same trigger-scope error in two sibling lanes' plans today while it sat in my
own carrier.

34/34 PASS on the program-status closure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
… a callee with no arguments is missing too.

consumer_type_only has no call; the edge is still absent. The trigger is lowering widened to type positions, not body-lowering alone.

Co-authored-by: Cursor <cursoragent@cursor.com>
A qualified cross-module mention is missing; a bare same-module name would not make an edge. A non-empty site list is not a usable graph.

Co-authored-by: Cursor <cursoragent@cursor.com>
Call-argument and type-position stay tree-side. The qualified body mention retires when the collector reassembles dag_field_access_body_node, not when lowering lands.

Co-authored-by: Cursor <cursoragent@cursor.com>
This fixture's type-position is a qualified name; the full spelling is still not a site. That stays with collector reassembly, not lowering. Call and callee stay tree-side.

Co-authored-by: Cursor <cursoragent@cursor.com>
…e does not appear.

That absence is resolution or edge derivation, not a declared type-position frontier and not lowering. Call contents stay eager-raven; qualified body stays the collector access-chain gap.

Co-authored-by: Cursor <cursoragent@cursor.com>
…port statement

XL-3 (quick-otter-229) measured an IMPORTED type name absent from type position while a
USER-DECLARED type in the same position reaches. That contradicted my row asserting a
type-position name reaches -- and they are right, because my row was never measuring a type
position.

This collector does NOT exclude import statements. `Bool` appears in
`import v2.std.logic { Bool }` in both fixture modules, and a spelling match cannot tell an
import mention from a type-position one. The assertion passed on the import line.

THAT ROW HAS NOW BEEN WRONG TWICE IN OPPOSITE DIRECTIONS: first "absent", which was the
truncated census talking; then "reaches", which was green for the wrong reason. A test whose
NAME claims more than its PREDICATE measures is worse than a red one, because it gets cited
as coverage -- and this one was, by me, to two sibling lanes.

RENAMED to what it can honestly establish (the spelling reaches the collector SOMEWHERE,
import statement included) and the real question is now asked by a discriminator that cannot
be answered by an import line: `Xl0UserType` is declared in the fixture, used only as a
parameter type, and appears in no import anywhere. It reaches.

CORRECTED, at the grain XL-3 established:
  REACHES:   a bare same-module value reference outside any call; a parameter reference;
             a USER-DECLARED type in type position
  DOES NOT:  a qualified cross-module reference, with or without a call;
             a call argument; a callee name
  UNSEPARATED BY THIS FIXTURE: an imported type name's type-position occurrence, because its
             import statement produces an indistinguishable site here.

12/12 PASS.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A locally declared LocalMarker in type position is found. The type-position miss on a dotted name is the same class as a qualified body mention, not lowering.

Co-authored-by: Cursor <cursoragent@cursor.com>
… the missing class.

Co-authored-by: Cursor <cursoragent@cursor.com>
…ot a persisted artifact (review 66891)

ObservedArmUnexercisedOnRequiredRoute.restoring_receipt now names the
next-rung trigger of a_gate_sized_for_the_largest_subject_refuses_every_smaller_one
(subject-sized compile admission, sufficient for the Observed-arm controls
to answer on the required floor); a PersistedLegacyBaseline is the XL-1
stage's receipt and is stated as such. One retirement condition per block.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

review 66891: agreed — restoring_receipt named an artifact (a persisted baseline) where the block is the required-route admission gap, so the block had two retirement conditions. Fixed in 1cc0117: ObservedArmUnexercisedOnRequiredRoute.restoring_receipt now names the capability — the next-rung trigger of gunbc.recurring_failure_mode.a_gate_sized_for_the_largest_subject_refuses_every_smaller_one (subject-sized compile admission), stated as sufficient for the Observed-arm controls to return to legacy_repair_tap_live_bridge_witness_test and answer Xl1PrimaryRootObserved on the required floor; a PersistedLegacyBaseline is named as the XL-1 STAGE's receipt, not this block's. The witness the_reported_capability_is_blocked_until_the_observed_arm_executes_on_a_required_route now asserts the capability spelling. The earlier head 05a0bef is the merge of main (admission rows relocated to dag/gunbc/namespace/transition_admission/ per #11250, 66 rows, deletion follow-up #11466).

— sent from swift-bat-902

Brian Searls and others added 3 commits September 16, 2026 19:05
…ted compiler can parse the stage

The v2 grammar realization admits no modifier between a type name and its
field block, so `sole_constructor` left tokens unconsumed on the native
route (srv2 pair on 1cc0117: parse_g0_tokens_remain). The pair carries
no invariant beyond its fields; the modifier bought nothing here.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
floor_pure_producer_share: main's removal of the live-deploy warm rows kept; the
XL-3/XL-4 warm-row annotations follow it. Mirrors at first_generation_equal=true
against a seed built at origin/main fc8109e.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ap (review 67039)

Both the PrimaryRoot arm of compile_emission and compile_xl1_primary_root_tap
now consume compile_clean_pipeline_options_for_sources, the helper the
required floor already reads; the two hand copies (which had drifted from it
in sort order) are deleted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

review 67039: agreed — the tap and the PrimaryRoot arm each carried a copy of the census-only derivation and both had drifted from compile_clean_census_only_sources_for_compiled (file-path vs module-path sort). Fixed in 9ccd19c: both sites now consume compile_clean_pipeline_options_for_sources (the helper the required floor already reads); the hand copies are deleted and the transaction reads census_modules off the options it consumes.

— sent from swift-bat-902

…mbol_eq (review 67052)

reference_deps, fn_index_depth_agreement, fn_index, resolution_provenance and
bootstrap each carried `fn …(a: Symbol, b: Symbol) -> Bool { a == b }`; one
authority now, owned by the module that owns Symbol.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

review 67052: agreed — the authority was minted and its five production copies left standing. Fixed in 9f0143d: reference_deps, fn_index_depth_agreement, fn_index, resolution_provenance and bootstrap now import v2.std.node symbol_eq and their local copies are deleted (grammar_coverage_symbol_reason_eq is a different fact — digest equality — and stays). Test-fixture copies under src/v2/test and dag/test are subjects of their own claims and are out of this cut.

— sent from swift-bat-902

…fold and the gate (review 67072)

QnSpineRole / qn_spine_role own which edge labels form the head/tail spine;
qn_fold_step dispatches on the role and qualified_name_spine_shape_present
gates on it, so neither re-spells the set.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

review 67072: agreed — the gate re-spelled the spine label set the fold owns. Fixed in 3428cd5: QnSpineRole / qn_spine_role in v2.std.qualified_name is the one authority (the only site naming ^fold_list_node_head / ^fold_list_node_tail); qn_fold_step dispatches its arms on the role and qualified_name_spine_shape_present gates on it, so a renamed or added spine label changes both consumers from one row. qualified_name and reference_derived_graph witnesses green by execution through claim_batch; the from_module_node TestClaim rows run on the floor.

— sent from swift-bat-902

Brian Searls and others added 3 commits September 17, 2026 00:32
…oor: IMPORT-MEMBER-ABSENT after the 67052 cutover)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ssion reaches the XL-1 tap)

Conflict resolution: the compile transaction's PrimaryRoot | RootDemandMeasurement
arm consumes primary_root_subject_closure (one derivation, both root subjects).
The XL-1 tap now receives the root demand declaration from its .dag caller
(repository + measured demand projection path, the same two facts gunbc
compile takes on argv) and asks the same per-root admission as the transaction;
on a session host the fixture root refuses WholeCorpusCompileUnmeasuredRoot,
recorded on a_gate_sized_for_the_largest_subject_refuses_every_smaller_one.
Mirrors regenerated (04_method.dag signature) and re-verified at
first_generation_equal=true; dispatch table healed via main_wet.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
… fixture root (review 67146)

The XL-4 fixture root with dag/std as its pool is measured by gunbc
measure-root-demand and its row authored (whole_corpus_compile_xl1_fixture_root_demand,
replayed through measured_for_root_from_receipt by a witness), the demand
projection regenerated; the two Observed-arm controls return to
legacy_repair_tap_live_bridge_witness_test over that root, served from one
prepared effect input (xl1_fixture_root_tap) so no claim pays the compile;
xl1_live_repair_tap_census_of folds a tap value. The symbol_eq cutover in
reference_deps gets its transition admission row (floor: one unadmitted
TargetChanged on c0ae8f9).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

review 67146: agreed — the Observed encoders had no executing consumer; only the refusal arm ran. Fixed in 78a801e, by the route the block itself named: #11265 made whole-root admission a per-root measured row, so the XL-4 fixture root (with dag/std as its pool) is measured by gunbc measure-root-demand, its row is authored in gunbc.whole_corpus_compile_admission (whole_corpus_compile_xl1_fixture_root_demand; a witness replays the receipt through measured_for_root_from_receipt and checks the authored row against the constructor's output) and the demand projection regenerated. The two Observed-arm controls are back in legacy_repair_tap_live_bridge_witness_test over that root — a_measured_fixture_root_reaches_the_observed_arm_with_rows_and_bindings and the_live_census_over_the_measured_fixture_root_counts_its_rows — served from one prepared effect input (xl1_fixture_root_tap) so the compile is paid once at preparation. Deleting the Observed arm of compile_xl1_primary_root_tap turns both red; deleting the fixture row turns both red at admission. legacy_baseline_capture_capability stays CaptureBlocked until this head's floor run executes them on the required route; it flips on that receipt, not before.

— sent from swift-bat-902

Brian Searls and others added 2 commits September 17, 2026 05:54
…ailable on the floor's receipt

Deletes gunbc#11440's four consumed admission rows (the roster's next touch
owes them; floor run 35181521483). The Observed arm executed on the required
floor in that run (prepared-effect-input-acquire xl1_fixture_root_tap
disposition=Xl1PrimaryRootObserved, both controls green), so
legacy_baseline_capture_capability reports CaptureAvailable, the retired block
variant ObservedArmUnexercisedOnRequiredRoute is deleted, its witness turns
into the permanent regression control, and the failure-mode row records the
retirement for this producer. Mirrors at first_generation_equal=true against a
seed at origin/main 3774101.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…and residual trigger stated as one state (review 67198)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

review 67198: agreed — the row carried three states at once (mitigatable + withdrawn controls; retired by execution; a trigger already satisfied). Rewritten in 3089b2f as one state: RUNG FOUND AT mitigatable / RUNG NOW mechanically preventable (#11265's per-root rows; the whole-corpus constant has no constructor left, an unmeasured root refuses rather than being extrapolated), RECEIPT OF THE CLIMB (the measured fixture row, floor run 35181521483 executing the Observed arm, controls enrolled as regression evidence), and NEXT-RUNG TRIGGER naming the residual capability at the grain of the loss — a demand derived from the compile's own closure rather than looked up by root identity, the instrument whole_corpus_compile_measured_demand_note already names.

— sent from swift-bat-902

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 17, 2026
Merged via the queue into main with commit f523abe Sep 17, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the integration/namespace-xl branch September 17, 2026 10:54
gunbai-bot Bot pushed a commit that referenced this pull request Sep 17, 2026
…at its landing)

The 67 TargetChanged rows (v1.compiler.emit_rust bindings resolving to
gunbc.reference_derived_candidate, and reference_deps symbol_eq resolving to
v2.std.node) were consumed by #11461's merge_group run; the roster returns to
its designed resting state, empty.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
@briansrls
briansrls restored the integration/namespace-xl branch September 17, 2026 12:34
@gunbai-bot
gunbai-bot Bot deleted the integration/namespace-xl branch September 17, 2026 14:06
@briansrls
briansrls restored the integration/namespace-xl branch September 17, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant