Repository navigation
NAMESPACE-XL integration: XL-4 graph instrument, XL-0 origin roster, XL-3 spelling census, exhaustiveness coverage key, XL-1 live tap (supersedes #11202 #11201 #11210 #11301 #11209) - #11461
Conversation
…ng since it was written v2.compiler.resolution_provenance models one name resolved at one position answering with its target and the module that contains it, and it models the dependency fold over those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were five hand-authored fixture rows in one witness, which makes a well-shaped module dangling in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather than executed. This is that producer. ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived graph ask the same question of the tree -- where is every mention, and at what containment position -- and differ only in what they fold the answers into. Two collectors would be the section 3 fork with the widest blast radius, because a mention one missed would be silently absent from both a denominator and a dependency edge. Landed as its own commit so XL-4 consumes it rather than building a second one. A declaration's NAME is an edge label and never a node, so an Atom is a reference by construction rather than by a filter that could be wrong. The two exclusions -- module header metadata, and _node_projection parse projections that would double-count every mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
std.repair_input_origin's header defers the DeclarationCarrier half to XL-0B/C. This lands it -- on the v2 route, per the fierce-lark-661 ruling: v1.compiler.emit_rust is scheduled for deletion and may at most consume, never own. No src/v1 edits. THE SIX v1 CHANNELS HAVE NO v2 ANALOGUE AND ARE NOT PORTED. They are collectors inside v1.compiler.emit_rust's Rust use-line planner; v2 emits no use lines and has no such planner, so reproducing them would mint a dying emitter's artifact on a route that never carried the surface. What survives the route change is the QUESTION -- what an import-to-containment repair takes as input -- and on v2 it is a resolver fact: v2.compiler.repair_input_origin_roster folds the resolver's four answers, over the mentions the reference-site collector enumerates. THE MODEL. SourceDeclarationCarrierIdentity carries a DeclarationRef and NEVER a CorpusDeclared decl_file -- one fact, one identity. The three departures from std.coercion TypeDeclarationProvenance are stated beside the type (DESIGN section 3b admits a stated divergence and refuses a silent one): the position; the KernelMinted arm having NO PRODUCER on this route, so carrying it would be a permanently uninhabited decoration rather than a weak wall; and DeclarationIdentityAbsent conflating unbound with ambiguous, which are two states with two repairs. There is deliberately no referencing-module field: the module is the longest rostered prefix of the position, so a second field would store one fact twice and then need a fabricated answer for a position no roster covers. GRAIN. Every mention is a row, each with its typed resolver arm. No filter on import-mediation or eligibility -- the stage label says BEFORE eligibility or repair disposition, and a denominator that filtered would be measuring its filter. EVIDENCE BY EXECUTION, AND THE WALLS DISCRIMINATE. Five witnesses pass; four mutations, one per wall, each reds its own wall and leaves the others standing: module-header exclusion removed -> the declared-names wall; a dotted mention walked per segment -> the one-site wall (and the declared-names wall, since the segments become spurious mentions); the position not extended by named edges -> the containment-position wall (and the positive control, which reads that position); unanswerable mentions dropped -> the not-a-drop wall. CARRIERS. StageXL0Denominator was NotDerivable; it now reads the same delivery-receipt channel XL-2 and XL-4 read, so a repair to probe observability still cannot move it and only delivering the producer can. MissingInstrument RepairInputOriginRosterProducer is deleted. The expecting-red status witness did NOT retire -- DESIGN section 4b(4) -- it flipped to a permanent regression control asserting the same rule on the arm that now stands. ACT-0's DenominatorRosterDigest stays outstanding, correctly: a delivery receipt carries no base, and pinning one is ACT-0's act. The census row now says where its undischarged half went: the v2 DeclarationRef carrier discharges it, and the v1 position retires when v1.compiler.emit_rust is deleted, not by a conversion. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…rier Installed from the generated candidate, never hand-edited: the mirror is a generated artifact and the authority is dag/std/repair_input_origin.dag. Adjudicated by `claim_executor --required-regen --regen-affected-scope`, which named this one path and no other (declared_divergent=1 [main.rs] is pre-existing and is not in the differing set). Verified by diffing the whole candidate src tree against the committed one file by file: std_repair_input_origin.rs is the only file that differs, and its diff is exactly the new provenance coproduct, the carrier identity struct, the SourceDeclarationCarrier arm and its two match arms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…trument. Fill the existing swap-body producer from resolved qualified-name sites (never import syntax), report typed diffs against the import graph, and hold the stage delivery receipt. Do not swap dependency_resolution_facts_live. Co-authored-by: Cursor <cursoragent@cursor.com>
…umer Review 64751. The finding is correct and I confirmed it independently: the whole body was `is_empty(xs: roster)` and `git grep` returned exactly one occurrence in the tree -- its own definition. That is two defects at once, a second name for one concept (DESIGN section 3) and a declaration with no call site in the closure (section 3c's third state, the only red one). Callers wanting emptiness call is_empty directly. Also drops the `is_empty` and `Bool` imports it was the sole user of. Removing the function while keeping its imports would have left a smaller instance of the same defect. The sibling entry point repair_input_origin_denominator_digest_lines is deliberately NOT deleted: it is also unconsumed today, but it names its consumer and the pinning act (ACT-0) beside it, which is section 3c's admissible declared frontier rather than a dangling declaration. The review reached the same conclusion. Re-ran the five XL-0 witnesses after the deletion: 5/5 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…ngling declaration
Three defects, all mine, all introduced by this branch. The required floor named all of
them in one refusal; I had independently found the first before its log was retrievable.
1. NON-EXHAUSTIVE MATCH (the floor red). Adding the SourceDeclarationCarrier arm to
RepairInputOriginCandidate left two wildcard-free two-arm matches in the pre-existing
XL-0A split witness. That is the ordinary compiler floor DESIGN section 4b names --
"closed variants eliminate exhaustively" -- and the roster module's own annotation
predicts exactly this ("a fourth arm added to the shared base refuses to compile here").
Swept every .dag touching the coproduct rather than only the file CI named: four files,
of which the producer and the XL-0 witness already handled all three arms.
2. SOURCE ANNOTATIONS INSIDE DECLARATION BODIES, in the XL-0 status arm and in the
regression control's test body. Hoisted above their declarations, which is the only
grain DESIGN section 4c models. Swept the whole branch diff: no indented `//` remains.
3. repair_input_origin_denominator_digest_lines DELETED (review 64768). It had no call
site, and the declared-frontier defence did not attach to it: the delivery receipt names
repair_input_origin_roster_over_roots, a different function that IS consumed, and both
of this one's components are exercised by the XL-0 witness. Review 64751 had passed the
same declaration as an admissible frontier; that read did not check which symbol the
receipt names. The surviving annotation records why the wrapper is absent so it is not
re-added.
WHY DEFECT 2 SURVIVED A GREEN LOCAL RUN, measured rather than assumed. On the identical
unmodified tree the floor refused, `claim_batch` returned PASS rc=0 for the same witness.
A controlled probe -- one module whose only content is an in-body annotation -- then showed
BOTH local instruments admit it: claim_batch PASSes, and `gunbc run` reaches evaluation and
returns true. So neither local execution path gates this class; only the floor's strict
preparation does, and the cheap local guard is syntactic (grep changed .dag for indented
`//`), not executional. The probe fixture was deleted rather than committed.
Re-ran after the repair: 9/9 PASS across both witness entries (4 XL-0A split + 5 XL-0).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Blanket filesystem import on module_graph forked List onto std.types and the new claim tests were censored at the enrolment ceiling; the producer stays on the named swap body and tools.reference_derived_graph.main remains the RED. Co-authored-by: Cursor <cursoragent@cursor.com>
…ng since it was written v2.compiler.resolution_provenance models one name resolved at one position answering with its target and the module that contains it, and it models the dependency fold over those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were five hand-authored fixture rows in one witness, which makes a well-shaped module dangling in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather than executed. This is that producer. ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived graph ask the same question of the tree -- where is every mention, and at what containment position -- and differ only in what they fold the answers into. Two collectors would be the section 3 fork with the widest blast radius, because a mention one missed would be silently absent from both a denominator and a dependency edge. Landed as its own commit so XL-4 consumes it rather than building a second one. A declaration's NAME is an edge label and never a node, so an Atom is a reference by construction rather than by a filter that could be wrong. The two exclusions -- module header metadata, and _node_projection parse projections that would double-count every mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Delete the module_graph mention walk. The swap body consumes collect_module_reference_sites and module_dependencies_from_sites. Co-authored-by: Cursor <cursoragent@cursor.com>
…es and EMPTY on the corpus The receipt this branch landed said the XL-0 instrument was "delivered and discriminated once". It had been discriminated against HAND-BUILT Node trees. Over the tree the production ingest actually yields, the collector returned NO sites at all. That is DESIGN section 5's specification-without-execution in its most flattering form -- the witnesses really executed, against a universe the corpus never produces -- and a stage reading CLEAR off it reports a denominator that does not exist. Raised by the XL-2 lane, independently reproduced by warm-ibex-518 over real .dag files, and confirmed here by a substrate-only fixture that drives the REAL ingest (module_roots_from_source_root_ingest, projected through normalized_tree_roots_to_nodes -- the same projection symbol_index_fill consumes, so the modeled route, not a workaround). WITHDRAWN: the StageDeliveryReceipt row, DenominatorRosterInstrumentDelivered, and StageXL0Denominator reading CLEAR. RESTORED: NotDerivable, awaiting RepairInputOriginRosterProducer -- whose label now demands a NON-EMPTY denominator over the production route, so the same claim cannot be re-made on the same evidence. TWO DEFECTS, BOTH ISOLATED BY MUTATION, ONLY THE FIRST MINE: 1. THE BLACKOUT WAS MY OWN SPECULATIVE GUARD. The collector skipped every `_node_projection` edge to prevent a double-count I never demonstrated. On a real ingested tree a module's content hangs under exactly those edges, so the guard returned zero sites corpus-wide while synthetic fixtures stayed green. Deleted. The lesson is kept in the module rather than only here: a speculative exclusion over a shape the author has not observed is indistinguishable from a blackout until something executes against the real tree. 2. WITH IT GONE, THE ERASURE IS REAL AND WIDER THAN CALLS. Measured on the production route: a value reference outside a call and a parameter reference ARE found; a call argument, a CALLEE name, and a TYPE-POSITION name are NOT. Type references are most of what an import-to-containment repair operates on, which is why XL-0 has no denominator yet rather than a slightly small one. Trigger: the v2 body-lowering repair (XL-2, gunbc#11207). ALSO FIXED, from review 64782: spine unwrapping ran on EVERY node, but namespace_graft_spine_segment_edge_optional recognises ANY single named edge targeting a Conj, so recursion silently dropped nested declaration and field labels from `position` -- a mention recorded at a chain it does not sit at, resolved against the wrong scope. A mislocated mention is worse than a missing one: it is a fabricated plausible answer rather than an absence someone can count. Unwrapping is now one move at the module boundary. THE MEASUREMENTS ARE ENROLLED, NOT NARRATED. v2.test.claim.namespace_xl0.call_argument_mention_survival asserts what the production route produces TODAY, so each deficiency row goes RED when the lowering repair lands and the repair must return here and re-state what is true, instead of widening a denominator nobody re-measured. 42/42 PASS: the 8 production-route probes plus the 34-test program-status closure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
The swap body folds collect_module_reference_sites through module_dependencies_from_sites. Witness tests over the fixture identities require a reference-only edge, no unused-import edge, exactly one shared edge, and go red on a mutant that re-admits import-decl mentions. Co-authored-by: Cursor <cursoragent@cursor.com>
…urn type moves) Review 64782's second finding, and the manager's condition for #11201 moving. The arm was `Rejected => acc`: a root whose module header does not resolve contributed no mentions and NO EVIDENCE, so a caller could not distinguish an unreadable module from an empty one. DESIGN section 5 calls that a hard reject rather than a weak arm -- a failure arm must refuse, never widen, and every degradation must be a typed, located, countable diagnostic. UnreadableModuleRoot { locus } is all three, and COUNTABLE is the property that matters here rather than merely typed: XL-0 is a DENOMINATOR, so a root silently missing from it does not make the number slightly small, it makes it a different question answered under the same name. "n roots were unreadable" is now answerable instead of inferred from a short population. THE REFUSAL TRAVELS WITH THE RESULT, NOT BESIDE IT. collect_module_reference_sites and collect_reference_sites now return ReferenceSiteCollection { sites, unreadable_roots }, and repair_input_origin_roster_over_roots returns RepairInputOriginRoster { carriers, unreadable_roots }. A caller cannot take the population without also taking what was lost producing it. A collector that counted the loss and a producer that discarded it one call later would be the same silent degradation a layer down, so the seam has its own wall. Both walls assert BOTH halves, because either alone is satisfiable by a wrong implementation: the sites must be unchanged (the unreadable root really did contribute nothing) AND the refusal must be present and countable (it said so). INTERFACE CHANGE, TAKEN DELIBERATELY AND ANNOUNCED FIRST. warm-ibex-518 (XL-4) and quick-otter-229 (XL-3) consume these entry points and are rebasing; the names are unchanged and only the return types moved, so the migration is `.sites` / `.carriers` at the call site, or consuming the refusal list where a total is required. NOT DONE, DELIBERATELY: no parse-tree walker was revived to route around the lowering loss. The type-position and call-expression erasure stays escalated rather than worked around, and XL-0 stays NotDerivable with its probes enrolled. 15/15 PASS across both XL-0 witness entries, including the two new refusal walls. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A fixture whose only provider mention sits in a call argument yields no reference-derived edge on parse_module trees (XL-4 ingest) and on normalized trees. Trigger is eager-raven-113's body-lowering repair. Co-authored-by: Cursor <cursoragent@cursor.com>
Your collector over parse_module trees does not recover type-position or out-of-call body mentions either; the rows record that absence until lowering and site collection catch up. Co-authored-by: Cursor <cursoragent@cursor.com>
…module miss measured
Review 64799, both findings verified against the code before acting, plus a correction that
came from XL-4's execution rather than from review.
1. SPINE UNWRAPPING WAS WRONG BY length(module_qn) - 1. namespace_graft_fold_spine wraps
ONCE PER SEGMENT; this unwrapped one level, and the generic named-edge rule then walked
the survivors as ordinary containment -- re-appending those segments to a position that
already carried them, so a mention in `a.b.c` was recorded at `a.b.c.b.c`. A mislocated
mention is a fabricated plausible answer (section 5) and changes which lexical scope the
resolver walks, so it is worse than an absent one.
THE COUNT IS DERIVED, NOT GUESSED: it is the module qualified name this walk already
resolved from the header, the same value the spine was folded from. Not a
loop-while-the-shape-matches, because namespace_graft_spine_segment_edge_optional
recognises ANY single named edge targeting a Conj, so a shape-driven loop would eat a
genuine one-declaration module body. Consuming the count makes over-unwrapping
unwritable rather than unlikely.
2. THE TRAVERSAL WAS QUADRATIC. qualified_name_from_node folds an entire subtree to answer,
and this walk then descended into that same subtree, so each nesting level re-folded
everything beneath it and everything beneath it was walked again. Now guarded by an O(1)
shape check -- Conj, exactly two children, both labelled head/tail -- using the SAME two
labels v2.std.qualified_name's own fold recognises, so it is a cheap precondition on that
authority rather than a second weaker spelling of it. Section 6: a proven cost-shape
defect is always fixed regardless of the realised n.
3. THE COVERAGE CLAIM I PUBLISHED WAS TOO BROAD, AND THIS IS THE IMPORTANT ONE. I reported
"a value reference outside any call IS found". That was a BARE SAME-MODULE name.
warm-ibex-518 measured a QUALIFIED CROSS-MODULE reference and found nothing; the
discriminator is now enrolled and confirms it. So the production-route population is:
SURVIVES: a bare same-module value reference outside any call; a parameter reference
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name; a type-position name
A bare same-module name resolves inside its own module, so it yields no dependency edge
and contributes nothing to an import-to-containment denominator, which is BY DEFINITION
about references that cross a module boundary. The surviving population is the part
neither XL-0 nor XL-4 has any use for. Stated in the file so no reader mistakes a
non-empty site list for a working instrument.
The partition is unchanged by fixes 1 and 2 -- re-measured after them rather than assumed.
16/16 PASS across both XL-0 witness entries.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…cle only. The walk sees type-position ProvidedMarker and still misses body-value and call-arg names. It is not the edge producer. Co-authored-by: Cursor <cursoragent@cursor.com>
… as a graph. An unread module must not look like a leaf. The fold carries unreadable_roots; the production Outcome refuses unless the fold is total. Co-authored-by: Cursor <cursoragent@cursor.com>
module_roots_from_source_root_ingest then normalized_tree_roots_to_nodes is the tree. On that route a qualified value mention is still missing, same as type-position and call contents; those rows are measurements of today. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ns DO reach the collector
Review 64815, and it is the most consequential finding on this PR. fixture_sites folded the
ingested roots with `cons: fn(acc, root) { collect_module_reference_sites(root: root).sites }`
-- DISCARDING acc -- so it returned only the LAST root's sites and threw away
.unreadable_roots at the only production-route call site in the change.
WHY THAT WAS FATAL RATHER THAN UNTIDY: every load-bearing row in this file is a NEGATIVE
claim, and a negative claim is satisfied for free by a population that never contained the
root in question. The census was truthful about one module while reading as though it
covered two, and its control was green by INGEST ORDERING rather than by the walk --
reorder the reads and the whole result changes with no test naming why. That is DESIGN
section 5's fabricated plausible output: an absence measured over a silently truncated
population.
WHAT IT COST, MEASURED OVER THE FULL POPULATION: a TYPE-POSITION name IS PRESENT. I had
reported it absent. `Bool` is mentioned in both fixture modules and the provider's sites
were the ones dropped, so the absence was manufactured by the fold. That claim had already
travelled: XL-3 was holding type-position census fixtures red on it and XL-4 carried a
type-position row on its declared frontier. Both lanes have been sent the retraction.
CORRECTED PARTITION, re-measured over every ingested root:
SURVIVES: a bare same-module value reference outside any call; a parameter reference;
a TYPE-POSITION name
DOES NOT: a qualified cross-module reference, with or without a call; a call argument;
a callee name
THE DISPOSITION IS UNCHANGED: XL-0 stays NotDerivable, because a denominator is made of
cross-module references and those still do not reach the collector.
TWO CAUSES, ONE LESSON. It hand-rolled a traversal beside collect_reference_sites, which
already threads the accumulator AND carries both halves -- the section 3 fork, in the one
file whose job is measuring that collector. And it discarded the typed, counted refusal
THIS PR ADDS so that a lost root cannot be mistaken for an empty one.
A SECOND INSTANCE THE REVIEW DID NOT NAME: characterise_the_module_header_resolves_on_a_
normalized_root dropped `acc` the same way, one screen below. Found by sweeping the pattern
rather than fixing the reported line. Both now conjoin over every root.
TWO NEW WALLS MAKE THE POPULATION ITSELF A SUBJECT, either of which would have caught this:
the census must speak for every ingested root, and the collection must be total, so an
unreadable root can never be the reason an "is absent" row is green.
11/11 PASS.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Both carriers said the remaining miss was call erasure, triggered by the v2 body-lowering
repair. That is the 4b(3) defect stated in DESIGN's own words: a trigger naming less than
the capability it restores is retired BY that trigger while the capability stays dead.
Body lowering (XL-2, gunbc#11207) restores the CALL classes and nothing else. The class that
actually denies XL-0 a denominator is the QUALIFIED CROSS-MODULE reference, which is absent
with or without a call. So the repair could land, the trigger would read satisfied, and XL-0
would still have no denominator.
MEASURED OVER EVERY INGESTED ROOT, which is new since the census truncation was fixed:
REACHES IT: a bare same-module value reference outside any call; a parameter reference;
a TYPE-POSITION name
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name
A bare same-module name resolves inside its own module, so the surviving population is the
part an import-to-containment denominator cannot use.
THE THREE CAUSES ARE NOW SEPARATED WITH HONEST OWNERSHIP: two were mine and are fixed (the
parse-projection exclusion that blacked out the corpus; the census fold that discarded its
accumulator and so measured the last root only, manufacturing a type-position miss that does
not exist). The third is OPEN AND DELIBERATELY UNATTRIBUTED: a dotted reference in a body is
not a qualified-name production at all, so the collector never reassembles it, and whether
resolution itself reads dotted body access has NO EXECUTED ANSWER -- the probe built for it
fails its own control, and a structural absence is not evidence.
The capability is now named directly: XL-0 derives when the producer answers NON-EMPTY over
CROSS-MODULE references on the production route.
I flagged this same trigger-scope error in two sibling lanes' plans today while it sat in my
own carrier.
34/34 PASS on the program-status closure.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
… a callee with no arguments is missing too. consumer_type_only has no call; the edge is still absent. The trigger is lowering widened to type positions, not body-lowering alone. Co-authored-by: Cursor <cursoragent@cursor.com>
A qualified cross-module mention is missing; a bare same-module name would not make an edge. A non-empty site list is not a usable graph. Co-authored-by: Cursor <cursoragent@cursor.com>
Call-argument and type-position stay tree-side. The qualified body mention retires when the collector reassembles dag_field_access_body_node, not when lowering lands. Co-authored-by: Cursor <cursoragent@cursor.com>
This fixture's type-position is a qualified name; the full spelling is still not a site. That stays with collector reassembly, not lowering. Call and callee stay tree-side. Co-authored-by: Cursor <cursoragent@cursor.com>
…e does not appear. That absence is resolution or edge derivation, not a declared type-position frontier and not lowering. Call contents stay eager-raven; qualified body stays the collector access-chain gap. Co-authored-by: Cursor <cursoragent@cursor.com>
…port statement
XL-3 (quick-otter-229) measured an IMPORTED type name absent from type position while a
USER-DECLARED type in the same position reaches. That contradicted my row asserting a
type-position name reaches -- and they are right, because my row was never measuring a type
position.
This collector does NOT exclude import statements. `Bool` appears in
`import v2.std.logic { Bool }` in both fixture modules, and a spelling match cannot tell an
import mention from a type-position one. The assertion passed on the import line.
THAT ROW HAS NOW BEEN WRONG TWICE IN OPPOSITE DIRECTIONS: first "absent", which was the
truncated census talking; then "reaches", which was green for the wrong reason. A test whose
NAME claims more than its PREDICATE measures is worse than a red one, because it gets cited
as coverage -- and this one was, by me, to two sibling lanes.
RENAMED to what it can honestly establish (the spelling reaches the collector SOMEWHERE,
import statement included) and the real question is now asked by a discriminator that cannot
be answered by an import line: `Xl0UserType` is declared in the fixture, used only as a
parameter type, and appears in no import anywhere. It reaches.
CORRECTED, at the grain XL-3 established:
REACHES: a bare same-module value reference outside any call; a parameter reference;
a USER-DECLARED type in type position
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name
UNSEPARATED BY THIS FIXTURE: an imported type name's type-position occurrence, because its
import statement produces an indistinguishable site here.
12/12 PASS.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A locally declared LocalMarker in type position is found. The type-position miss on a dotted name is the same class as a qualified body mention, not lowering. Co-authored-by: Cursor <cursoragent@cursor.com>
… the missing class. Co-authored-by: Cursor <cursoragent@cursor.com>
…ot a persisted artifact (review 66891) ObservedArmUnexercisedOnRequiredRoute.restoring_receipt now names the next-rung trigger of a_gate_sized_for_the_largest_subject_refuses_every_smaller_one (subject-sized compile admission, sufficient for the Observed-arm controls to answer on the required floor); a PersistedLegacyBaseline is the XL-1 stage's receipt and is stated as such. One retirement condition per block. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 66891: agreed — restoring_receipt named an artifact (a persisted baseline) where the block is the required-route admission gap, so the block had two retirement conditions. Fixed in 1cc0117: ObservedArmUnexercisedOnRequiredRoute.restoring_receipt now names the capability — the next-rung trigger of gunbc.recurring_failure_mode.a_gate_sized_for_the_largest_subject_refuses_every_smaller_one (subject-sized compile admission), stated as sufficient for the Observed-arm controls to return to legacy_repair_tap_live_bridge_witness_test and answer Xl1PrimaryRootObserved on the required floor; a PersistedLegacyBaseline is named as the XL-1 STAGE's receipt, not this block's. The witness the_reported_capability_is_blocked_until_the_observed_arm_executes_on_a_required_route now asserts the capability spelling. The earlier head 05a0bef is the merge of main (admission rows relocated to dag/gunbc/namespace/transition_admission/ per #11250, 66 rows, deletion follow-up #11466). — sent from swift-bat-902 |
…ted compiler can parse the stage The v2 grammar realization admits no modifier between a type name and its field block, so `sole_constructor` left tokens unconsumed on the native route (srv2 pair on 1cc0117: parse_g0_tokens_remain). The pair carries no invariant beyond its fields; the modifier bought nothing here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
floor_pure_producer_share: main's removal of the live-deploy warm rows kept; the XL-3/XL-4 warm-row annotations follow it. Mirrors at first_generation_equal=true against a seed built at origin/main fc8109e. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ap (review 67039) Both the PrimaryRoot arm of compile_emission and compile_xl1_primary_root_tap now consume compile_clean_pipeline_options_for_sources, the helper the required floor already reads; the two hand copies (which had drifted from it in sort order) are deleted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 67039: agreed — the tap and the PrimaryRoot arm each carried a copy of the census-only derivation and both had drifted from compile_clean_census_only_sources_for_compiled (file-path vs module-path sort). Fixed in 9ccd19c: both sites now consume compile_clean_pipeline_options_for_sources (the helper the required floor already reads); the hand copies are deleted and the transaction reads census_modules off the options it consumes. — sent from swift-bat-902 |
…mbol_eq (review 67052)
reference_deps, fn_index_depth_agreement, fn_index, resolution_provenance and
bootstrap each carried `fn …(a: Symbol, b: Symbol) -> Bool { a == b }`; one
authority now, owned by the module that owns Symbol.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 67052: agreed — the authority was minted and its five production copies left standing. Fixed in 9f0143d: reference_deps, fn_index_depth_agreement, fn_index, resolution_provenance and bootstrap now import v2.std.node symbol_eq and their local copies are deleted (grammar_coverage_symbol_reason_eq is a different fact — digest equality — and stays). Test-fixture copies under src/v2/test and dag/test are subjects of their own claims and are out of this cut. — sent from swift-bat-902 |
…fold and the gate (review 67072) QnSpineRole / qn_spine_role own which edge labels form the head/tail spine; qn_fold_step dispatches on the role and qualified_name_spine_shape_present gates on it, so neither re-spells the set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 67072: agreed — the gate re-spelled the spine label set the fold owns. Fixed in 3428cd5: QnSpineRole / qn_spine_role in v2.std.qualified_name is the one authority (the only site naming ^fold_list_node_head / ^fold_list_node_tail); qn_fold_step dispatches its arms on the role and qualified_name_spine_shape_present gates on it, so a renamed or added spine label changes both consumers from one row. qualified_name and reference_derived_graph witnesses green by execution through claim_batch; the from_module_node TestClaim rows run on the floor. — sent from swift-bat-902 |
…oor: IMPORT-MEMBER-ABSENT after the 67052 cutover) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ssion reaches the XL-1 tap) Conflict resolution: the compile transaction's PrimaryRoot | RootDemandMeasurement arm consumes primary_root_subject_closure (one derivation, both root subjects). The XL-1 tap now receives the root demand declaration from its .dag caller (repository + measured demand projection path, the same two facts gunbc compile takes on argv) and asks the same per-root admission as the transaction; on a session host the fixture root refuses WholeCorpusCompileUnmeasuredRoot, recorded on a_gate_sized_for_the_largest_subject_refuses_every_smaller_one. Mirrors regenerated (04_method.dag signature) and re-verified at first_generation_equal=true; dispatch table healed via main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
… fixture root (review 67146) The XL-4 fixture root with dag/std as its pool is measured by gunbc measure-root-demand and its row authored (whole_corpus_compile_xl1_fixture_root_demand, replayed through measured_for_root_from_receipt by a witness), the demand projection regenerated; the two Observed-arm controls return to legacy_repair_tap_live_bridge_witness_test over that root, served from one prepared effect input (xl1_fixture_root_tap) so no claim pays the compile; xl1_live_repair_tap_census_of folds a tap value. The symbol_eq cutover in reference_deps gets its transition admission row (floor: one unadmitted TargetChanged on c0ae8f9). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 67146: agreed — the Observed encoders had no executing consumer; only the refusal arm ran. Fixed in 78a801e, by the route the block itself named: #11265 made whole-root admission a per-root measured row, so the XL-4 fixture root (with dag/std as its pool) is measured by gunbc measure-root-demand, its row is authored in gunbc.whole_corpus_compile_admission (whole_corpus_compile_xl1_fixture_root_demand; a witness replays the receipt through measured_for_root_from_receipt and checks the authored row against the constructor's output) and the demand projection regenerated. The two Observed-arm controls are back in legacy_repair_tap_live_bridge_witness_test over that root — a_measured_fixture_root_reaches_the_observed_arm_with_rows_and_bindings and the_live_census_over_the_measured_fixture_root_counts_its_rows — served from one prepared effect input (xl1_fixture_root_tap) so the compile is paid once at preparation. Deleting the Observed arm of compile_xl1_primary_root_tap turns both red; deleting the fixture row turns both red at admission. legacy_baseline_capture_capability stays CaptureBlocked until this head's floor run executes them on the required route; it flips on that receipt, not before. — sent from swift-bat-902 |
…ailable on the floor's receipt Deletes gunbc#11440's four consumed admission rows (the roster's next touch owes them; floor run 35181521483). The Observed arm executed on the required floor in that run (prepared-effect-input-acquire xl1_fixture_root_tap disposition=Xl1PrimaryRootObserved, both controls green), so legacy_baseline_capture_capability reports CaptureAvailable, the retired block variant ObservedArmUnexercisedOnRequiredRoute is deleted, its witness turns into the permanent regression control, and the failure-mode row records the retirement for this producer. Mirrors at first_generation_equal=true against a seed at origin/main 3774101. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…and residual trigger stated as one state (review 67198) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
|
review 67198: agreed — the row carried three states at once (mitigatable + withdrawn controls; retired by execution; a trigger already satisfied). Rewritten in 3089b2f as one state: RUNG FOUND AT mitigatable / RUNG NOW mechanically preventable (#11265's per-root rows; the whole-corpus constant has no constructor left, an unmeasured root refuses rather than being extrapolated), RECEIPT OF THE CLIMB (the measured fixture row, floor run 35181521483 executing the Observed arm, controls enrolled as regression evidence), and NEXT-RUNG TRIGGER naming the residual capability at the grain of the loss — a demand derived from the compile's own closure rather than looked up by root identity, the instrument whole_corpus_compile_measured_demand_note already names. — sent from swift-bat-902 |
…at its landing) The 67 TargetChanged rows (v1.compiler.emit_rust bindings resolving to gunbc.reference_derived_candidate, and reference_deps symbol_eq resolving to v2.std.node) were consumed by #11461's merge_group run; the roster returns to its designed resting state, empty. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
Summary
Single integration branch for the five NAMESPACE-XL PRs that were each at the tally floor and blocked only on integration and the class-1 receipt (operator direction, 2026-09-16: "make a single integration branch"). It supersedes and closes:
tools.reference_derived_graph;v2.lens.module_graph reference_derived_resolution_factsas the future XL-6 swap body, NOT swapped;held_stage_delivery_receiptsstays empty — no production positive control yet).RepairInputOriginRosterProducer;StageXL0DenominatorstaysNotDerivableBY DESIGN — its production-route population is empty; three brief clauses unmet by design, see NAMESPACE XL-0B/C/D: repair-input origin roster on the v2 route #11201's body).std.declaring_identity_spelling,v2.compiler.declaring_identity_spelling_census;StageXL3staysNotDerivableby design).v1.compiler.infer_patterns); the forcedextdeps.systemdSubStateduplicate deletion; ledger rowa_coproduct_declares_one_variant_twice.emit_rust_reference_derived_rows_bridge(fierce-lark-661 rulings 2026-09-12; seed-growth ledger row; v1 deletion roster), sole consumerpersist_named_base_from_primary_root_tap→CaptureAvailable. (NAMESPACE XL-1: feed repair census envelope and persist capture by GitObjectId #11203, its base, is already on main.)Each superseded PR keeps its review history; the integration resolves their mutual conflicts once.
Integration decisions (where the branches disagreed)
src/v2/compiler/reference_site_collector.dag: taken from NAMESPACE XL-0B/C/D: repair-input origin roster on the v2 route #11201 (its home; the walker returnsReferenceSiteCollectionwith unreadable-root accounting; exported shapes identical to what NAMESPACE XL-4: reference-derived dependency graph instrument #11202's lens consumes).src/v2/std/qualified_name.dag: both NAMESPACE XL-0B/C/D: repair-input origin roster on the v2 route #11201 and NAMESPACE XL-4: reference-derived dependency graph instrument #11202 had independently folded the O(1) spine gate intoqualified_name_from_node's own entry; NAMESPACE XL-4: reference-derived dependency graph instrument #11202's reviewed, verdict-preserving implementation kept (reviews 65558/65666).src/v2/lens/module_graph.dag: NAMESPACE XL-4: reference-derived dependency graph instrument #11202's producer plus main's consolidatedv2.std.text string_eq(Collapse the v2.lens string_eq copies into one authority #11138); no module-local copy survives.namespace_cut_stagereceipts,shared_precondition_re_derived_once_per_claim_frame,absent_reads_identically_to_never_looked,floor_pure_producer_sharewarm roster): both sides kept; one superseded duplicate receipt dropped in favour of main's longer revision.Regeneration receipt
claim_executor --required-regen --regen-affected-scope --source-root dag --source-root src/v2on this branch: regen-scope WholePopulationScope, planned/executed/adjudicated 156, elapsed 463,757 ms, sampled peak RSS 12,060,996 KiB underulimit -v 23,000,000KiB (cap proven beforehand with a must-fail 24 GiB allocation control). Adjudicator named exactly four drifted paths (v1_compiler_emit_rust.rs,v1_compiler_infer_method.rs,v1_compiler_infer_patterns.rs,v1_tests_claim_reference_derived_disposition_census_witness_test.rs;declared_divergent=1 [main.rs]pre-existing); whole-candidatesrccomparison found the same four and no other. Installed from the candidate (commit 4bcc89c).v1_interpreter_dispatch_generated.rsis healed bygenerated_artifact_gate main_wet, not by--required-regen: regenerated with the main seed'sgunbc(commit 0a7376d) — main's file plus the one XL-1 arm;main_wetrewrote no other artifact.v1_interpreter.rs: origin/main's file plus XL-1: emit-rust repair-row interpreter bridge and persist producer #11209's two additive hunks (+363), after a cherry-pick resolution had wrongly taken XL-1: emit-rust repair-row interpreter bridge and persist producer #11209's whole-file copy (commit ab2ec3c).first_generation_equal=true, 156/156, on 0a7376d (peak 12,076,856 KiB), again after merging main's Refuse duplicate record-literal fields (build the declared trigger of duplicate_record_literal_field_silently_last_wins) #11391 (peak 12,123,248 KiB), and again on 7898426 after the parse fix (regen4). The branch is buildable at every head after 0a7376d.Evidence
Every claim file touched by the five PRs, executed to completion with the branch's own
claim_batch(scoped--entry/--functions,ulimit -v 23 GiB), on 7898426 / 114ba1d:193/193. First integration floor run (35056157979) refused twice and both are repaired in 114ba1d: 66 unadjudicated
TargetChangeddeltas (#11209's type-home move, admitted one row per delta with the consumption trigger) and the must-not-resolve XL-3 fixture resolved by the prepared subject (moved underdag/test/probe/). Earlier run 35053755879 refuseddag/std/declaring_identity_spelling.dagat parse (data … =before a newline) — fixed in 7898426; #11210 was stacked so its own CI never parsed it.Classification
Class 1 (pre-landing receipt): reachable emitted-closure members
v2.std.qualified_name,v2.compiler.program_assembly,v2.std.node,std.repair_input_origin(+ mirror), and the seed (v1.compiler.infer_patterns, the XL-1 builtin, regenerated mirrors). One receipt for the whole train instead of five.🤖 Generated with Claude Code
https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
Native-route deltas outside the pre-registration (srv2 pair fold11461g on 1cc0117)
dag/extdeps/systemd/systemd.dag{sugar_reason_malformed}: attributed to Key the declared constructor and the pattern with one identity #11301 (in this train, commit 77c99ea) deleting the duplicateSubStatevariant ofSystemdUnitPropertyand its duplicate match arm; the removal is why T's terminal reaches admitted=true.src/v2/compiler/program_assembly.dag{parse_g0_tokens_remain}: caused bytype LocatedNormalizedTree sole_constructor { ... }; the v2 grammar realization (v2.extdeps.languages.dagdag_grammar_type_decl_expr) admits no modifier between the type name and its field block. Repaired in e424b72 by making it a plain record (the pair carries no invariant beyond its fields).