From 039dd54510d129c1019b7bc16f4e0bc4310bb8c0 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 17 Sep 2026 01:08:05 +0000 Subject: [PATCH 1/3] Remove cross-module imports of test fns - dag/test/parsecheck.dag (a plain module) imported a test fn from test.claim.installed_bom_reconcile_witness_test and conjoined it into memory_model_holds; the conjunct and the import are dropped. That test fn is enrolled and runs on its own. - src/v2/test/claim/long/no_dual_representation_test_test.dag only re-called the two test fns of v2.lens.no_dual_representation_test, which the floor already runs under their own identities (see floor_cost_debt); the wrapper sat in witness_deferral_freeze and executed nowhere. Module and freeze row deleted. Co-Authored-By: Claude Opus 5 (1M context) --- dag/gunbc/witness/witness_deferral_freeze.dag | 1 - dag/test/parsecheck.dag | 4 ---- .../long/no_dual_representation_test_test.dag | 18 ------------------ 3 files changed, 23 deletions(-) delete mode 100644 src/v2/test/claim/long/no_dual_representation_test_test.dag diff --git a/dag/gunbc/witness/witness_deferral_freeze.dag b/dag/gunbc/witness/witness_deferral_freeze.dag index 7ee6cfe502d..ba804339ff3 100644 --- a/dag/gunbc/witness/witness_deferral_freeze.dag +++ b/dag/gunbc/witness/witness_deferral_freeze.dag @@ -1034,7 +1034,6 @@ data frozen_path_deferrals: List = [ "native_routing_green_control_bound_entry_reaches_subject" ] }, - FrozenPathDeferral { entry: "src/v2/test/claim/long/no_dual_representation_test_test.dag", functions: ["no_violations_in_examined_scope", "coverage_honesty_holds"] }, FrozenPathDeferral { entry: "src/v2/test/claim/long/parse_table_memo_amortization_test.dag", functions: [ diff --git a/dag/test/parsecheck.dag b/dag/test/parsecheck.dag index 3e1d5d647de..815f654f3aa 100644 --- a/dag/test/parsecheck.dag +++ b/dag/test/parsecheck.dag @@ -7,9 +7,6 @@ import gunbc.fleet_intent { srv1_memory_population, srv3_memory_population, srv4 import gunbc.fleet_physical_inventory { fleet_dimm_verdicts, fleet_dimm_expectations } import gunbc.host_memory_qualification { srv2_failed_64gib_population_standing } import gunbc.ci_floor_measurement { gunbc_ci_srv3_memtotal_measured } -import test.claim.installed_bom_reconcile_witness_test { - the_dimm_lot_is_committed_with_a_read_catalog_and_no_public_cost, -} import gunbc.runner_disk_reclaim { admit_reclaim_operation, reclaim_admission_proceeds, reclaim_operations, operation_requires_idle_slot, repack_admits_pack_count, review_ref_should_be_dropped, @@ -35,7 +32,6 @@ fn memory_model_holds() -> Bool { && fleet_dimm_verdicts.length() == 4 && fleet_dimm_expectations.length() == 4 && srv1_memory_population.rows.length() == 1 - && the_dimm_lot_is_committed_with_a_read_catalog_and_no_public_cost() } // Git work refuses on a busy slot and proceeds on an idle one, while diagnostic rotation proceeds diff --git a/src/v2/test/claim/long/no_dual_representation_test_test.dag b/src/v2/test/claim/long/no_dual_representation_test_test.dag deleted file mode 100644 index 0c6f604ebfb..00000000000 --- a/src/v2/test/claim/long/no_dual_representation_test_test.dag +++ /dev/null @@ -1,18 +0,0 @@ -module v2.test.long.no_dual_representation_test_test - -import v2.lens.no_dual_representation_test { - no_dual_representation_test_clean_holds, - no_dual_representation_test_coverage_honesty_holds, -} -import v2.std.logic { Bool } -import v2.std.live_tree { LiveTreeDisposition, ReadsLiveTree } - -data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree - -test fn no_violations_in_examined_scope() -> Bool { - return no_dual_representation_test_clean_holds() -} - -test fn coverage_honesty_holds() -> Bool { - return no_dual_representation_test_coverage_honesty_holds() -} From c4b980e5f1d1d58d8cb4bf437906c23d6b044d6a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 17 Sep 2026 01:09:29 +0000 Subject: [PATCH 2/3] Move the sealed fx_map builder into an ordinary fixture module MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit test.probe.self_authored_map_probe imported fx_map from a test module to show an unadmitted call refuses. fx_map now lives in test.fixture.data_handling_map_fixture (no test items), with the same admit_callers list and authority; product.data_class admits it at the new path, and both the admission witness and the probe import it from there. The probe keeps its ConstructorCallAdmissionRefused, so data_class_refusal_probe_witness keeps its red (DESIGN ยง4b(4)). Co-Authored-By: Claude Opus 5 (1M context) --- dag/gunbc/product/data_class.dag | 2 +- .../data_class_admission_witness_test.dag | 14 ++---------- .../fixture/data_handling_map_fixture.dag | 22 +++++++++++++++++++ dag/test/probe/self_authored_map_probe.dag | 2 +- 4 files changed, 26 insertions(+), 14 deletions(-) create mode 100644 dag/test/fixture/data_handling_map_fixture.dag diff --git a/dag/gunbc/product/data_class.dag b/dag/gunbc/product/data_class.dag index 7d2d0f21b0d..ddbfcdfe318 100644 --- a/dag/gunbc/product/data_class.dag +++ b/dag/gunbc/product/data_class.dag @@ -254,7 +254,7 @@ type DataHandlingMap sole_constructor { fn data_handling_map(authority: DeclarationRef, rows: List) -> DataHandlingMap admit_callers: [ decl_ref(module_path: "strategy.data_map", decl_name: "data_handling_map_rows"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_map"), + decl_ref(module_path: "test.fixture.data_handling_map_fixture", decl_name: "fx_map"), ] = DataHandlingMap { authority: authority, rows: rows } diff --git a/dag/test/claim/fabric/data_class_admission_witness_test.dag b/dag/test/claim/fabric/data_class_admission_witness_test.dag index a905cc91333..6f9223aa508 100644 --- a/dag/test/claim/fabric/data_class_admission_witness_test.dag +++ b/dag/test/claim/fabric/data_class_admission_witness_test.dag @@ -17,13 +17,14 @@ import product.data_class { PostureRevisionStale, DataErasureStanding, ErasureApplied, Redacted, admit_data_effect, durable_origin_sink, log_channel_sink, build_output_category, personal_identity_category, - classified_map, classified_category, redact, public_fabric_map, public_fabric_posture, data_handling_map, + classified_map, classified_category, redact, public_fabric_map, public_fabric_posture, } import gunbc.fabric_m0_origin_commit { job_output_bytes, fabric_durable_origin_route, origin_write_permit_standing, PermitAuthorisesThisOrigin, PermitNamesAnotherSink, PermitNamesAnotherOperation, } import gunbc.principal_projection { oidc_projection } +import test.fixture.data_handling_map_fixture { fx_map } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly @@ -86,17 +87,6 @@ fn fx_row(category: DeclarationRef, sink: SinkKind, posture: CompliancePostureRe fx_row_admitting(category: category, sink: sink, operations: [StoreDurably], posture: posture) } -fn fx_map(rows: List) -> DataHandlingMap - admit_callers: [ - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_admitting_map"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_category_with_rows_for_another_sink_only_is_refused_at_the_sink"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_durable_row_on_another_route_is_refused_at_the_route"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_personal_identity_handed_to_a_build_output_sink_is_refused_before_the_map_is_read"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "admitted_permit_for"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "the_standard_claims_survive_classification_intact"), - ] - = data_handling_map(authority: fx_ref(name: "fixture_map"), rows: rows) - fn fx_admitting_map() -> DataHandlingMap admit_callers: [ decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_build_output_is_admitted_to_the_durable_origin_under_a_row_naming_the_route"), diff --git a/dag/test/fixture/data_handling_map_fixture.dag b/dag/test/fixture/data_handling_map_fixture.dag new file mode 100644 index 00000000000..a575820695c --- /dev/null +++ b/dag/test/fixture/data_handling_map_fixture.dag @@ -0,0 +1,22 @@ +module test.fixture.data_handling_map_fixture + +import std.types { List } +import std.decl_ref { decl_ref } +import product.data_class { DataHandlingRow, DataHandlingMap, data_handling_map } + +// The admission witness's sealed fixture builder, held in an ordinary fixture module rather than in +// the witness module itself: test.probe.self_authored_map_probe reaches for it to show that an +// unadmitted caller refuses (ConstructorCallAdmissionRefused), and a probe may not import a test +// module. Its admit_callers list still names only the witness's own fixtures and tests, and the +// authority it stamps is unchanged. +fn fx_map(rows: List) -> DataHandlingMap + admit_callers: [ + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_admitting_map"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_category_with_rows_for_another_sink_only_is_refused_at_the_sink"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_durable_row_on_another_route_is_refused_at_the_route"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_personal_identity_handed_to_a_build_output_sink_is_refused_before_the_map_is_read"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "admitted_permit_for"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "the_standard_claims_survive_classification_intact"), + ] + = data_handling_map(authority: decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fixture_map"), rows: rows) + diff --git a/dag/test/probe/self_authored_map_probe.dag b/dag/test/probe/self_authored_map_probe.dag index f5005446890..3d022d6caf2 100644 --- a/dag/test/probe/self_authored_map_probe.dag +++ b/dag/test/probe/self_authored_map_probe.dag @@ -20,7 +20,7 @@ import product.data_class { admit_data_effect, durable_origin_sink, personal_identity_category, data_handling_map, public_fabric_posture, } import gunbc.principal_projection { oidc_projection } -import test.claim.fabric.data_class_admission_witness_test { fx_map } +import test.fixture.data_handling_map_fixture { fx_map } fn claims() -> OidcIdTokenClaims { OidcIdTokenClaims { From 35eb5bd80cde10b6fa7a1d1869548e825bef7f92 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Thu, 17 Sep 2026 02:47:40 +0000 Subject: [PATCH 3/3] Probe reaches a sealed fixture builder that cites no test module The previous move of fx_map into the fixture module failed the floor twice: its authority decl_ref cited a declaration the witness module does not declare (CITED-DECLARATION-ABSENT), and rebinding fx_map in seven sites produced unadjudicated TargetChanged namespace deltas. Instead, leave the admission witness and product.data_class untouched and give the probe its own caller-sealed builder in test.fixture.data_handling_map_fixture (sealed to a caller in that module, returning the public empty map, so no second route to the DataHandlingMap mint is admitted). The probe's third function still refuses as ConstructorCallAdmissionRefused, so data_class_refusal_probe_witness keeps its >= 2 count, and the probe no longer imports a test module. Co-Authored-By: Claude Opus 5 (1M context) --- dag/gunbc/product/data_class.dag | 2 +- .../data_class_admission_witness_test.dag | 14 ++++++++-- .../fixture/data_handling_map_fixture.dag | 27 +++++++++---------- dag/test/probe/self_authored_map_probe.dag | 7 ++--- 4 files changed, 29 insertions(+), 21 deletions(-) diff --git a/dag/gunbc/product/data_class.dag b/dag/gunbc/product/data_class.dag index ddbfcdfe318..7d2d0f21b0d 100644 --- a/dag/gunbc/product/data_class.dag +++ b/dag/gunbc/product/data_class.dag @@ -254,7 +254,7 @@ type DataHandlingMap sole_constructor { fn data_handling_map(authority: DeclarationRef, rows: List) -> DataHandlingMap admit_callers: [ decl_ref(module_path: "strategy.data_map", decl_name: "data_handling_map_rows"), - decl_ref(module_path: "test.fixture.data_handling_map_fixture", decl_name: "fx_map"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_map"), ] = DataHandlingMap { authority: authority, rows: rows } diff --git a/dag/test/claim/fabric/data_class_admission_witness_test.dag b/dag/test/claim/fabric/data_class_admission_witness_test.dag index 6f9223aa508..a905cc91333 100644 --- a/dag/test/claim/fabric/data_class_admission_witness_test.dag +++ b/dag/test/claim/fabric/data_class_admission_witness_test.dag @@ -17,14 +17,13 @@ import product.data_class { PostureRevisionStale, DataErasureStanding, ErasureApplied, Redacted, admit_data_effect, durable_origin_sink, log_channel_sink, build_output_category, personal_identity_category, - classified_map, classified_category, redact, public_fabric_map, public_fabric_posture, + classified_map, classified_category, redact, public_fabric_map, public_fabric_posture, data_handling_map, } import gunbc.fabric_m0_origin_commit { job_output_bytes, fabric_durable_origin_route, origin_write_permit_standing, PermitAuthorisesThisOrigin, PermitNamesAnotherSink, PermitNamesAnotherOperation, } import gunbc.principal_projection { oidc_projection } -import test.fixture.data_handling_map_fixture { fx_map } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly @@ -87,6 +86,17 @@ fn fx_row(category: DeclarationRef, sink: SinkKind, posture: CompliancePostureRe fx_row_admitting(category: category, sink: sink, operations: [StoreDurably], posture: posture) } +fn fx_map(rows: List) -> DataHandlingMap + admit_callers: [ + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_admitting_map"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_category_with_rows_for_another_sink_only_is_refused_at_the_sink"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_durable_row_on_another_route_is_refused_at_the_route"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_personal_identity_handed_to_a_build_output_sink_is_refused_before_the_map_is_read"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "admitted_permit_for"), + decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "the_standard_claims_survive_classification_intact"), + ] + = data_handling_map(authority: fx_ref(name: "fixture_map"), rows: rows) + fn fx_admitting_map() -> DataHandlingMap admit_callers: [ decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_build_output_is_admitted_to_the_durable_origin_under_a_row_naming_the_route"), diff --git a/dag/test/fixture/data_handling_map_fixture.dag b/dag/test/fixture/data_handling_map_fixture.dag index a575820695c..670ceaf408a 100644 --- a/dag/test/fixture/data_handling_map_fixture.dag +++ b/dag/test/fixture/data_handling_map_fixture.dag @@ -1,22 +1,19 @@ module test.fixture.data_handling_map_fixture -import std.types { List } import std.decl_ref { decl_ref } -import product.data_class { DataHandlingRow, DataHandlingMap, data_handling_map } +import product.data_class { DataHandlingMap, public_fabric_map } -// The admission witness's sealed fixture builder, held in an ordinary fixture module rather than in -// the witness module itself: test.probe.self_authored_map_probe reaches for it to show that an -// unadmitted caller refuses (ConstructorCallAdmissionRefused), and a probe may not import a test -// module. Its admit_callers list still names only the witness's own fixtures and tests, and the -// authority it stamps is unchanged. -fn fx_map(rows: List) -> DataHandlingMap +// A caller-SEALED fixture builder for test.probe.self_authored_map_probe, which must show that a +// module outside a builder's admit_callers list cannot reach it (ConstructorCallAdmissionRefused). +// It lives in an ordinary fixture module because a probe may not import a test module; the sealed +// DataHandlingMap mint itself stays admitted only to its policy authorities, so this builder hands +// back the public (empty) map and adds no second admitted route to a caller-authored policy. +fn sealed_fixture_map() -> DataHandlingMap admit_callers: [ - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fx_admitting_map"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_category_with_rows_for_another_sink_only_is_refused_at_the_sink"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_durable_row_on_another_route_is_refused_at_the_route"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "a_personal_identity_handed_to_a_build_output_sink_is_refused_before_the_map_is_read"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "admitted_permit_for"), - decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "the_standard_claims_survive_classification_intact"), + decl_ref(module_path: "test.fixture.data_handling_map_fixture", decl_name: "admitted_fixture_map_call"), ] - = data_handling_map(authority: decl_ref(module_path: "test.claim.fabric.data_class_admission_witness_test", decl_name: "fixture_map"), rows: rows) + = public_fabric_map() +fn admitted_fixture_map_call() -> DataHandlingMap { + sealed_fixture_map() +} diff --git a/dag/test/probe/self_authored_map_probe.dag b/dag/test/probe/self_authored_map_probe.dag index 3d022d6caf2..8cd6c796f0c 100644 --- a/dag/test/probe/self_authored_map_probe.dag +++ b/dag/test/probe/self_authored_map_probe.dag @@ -7,7 +7,8 @@ module test.probe.self_authored_map_probe // SoleConstructorViolation on DataHandlingMap; the mint call refuses as // ConstructorCallAdmissionRefused, because data_handling_map admits only the private policy // authority and the admission witness's sealed fixture builder; and the third function reaches for -// that fixture builder directly, which refuses the same way because it is sealed to its tests. +// a caller-sealed fixture builder (test.fixture.data_handling_map_fixture sealed_fixture_map), which +// refuses the same way because it is sealed to its own admitted caller. import std.types { NonEmptyStr, List, Bool } import std.decl_ref { decl_ref } @@ -20,7 +21,7 @@ import product.data_class { admit_data_effect, durable_origin_sink, personal_identity_category, data_handling_map, public_fabric_posture, } import gunbc.principal_projection { oidc_projection } -import test.fixture.data_handling_map_fixture { fx_map } +import test.fixture.data_handling_map_fixture { sealed_fixture_map } fn claims() -> OidcIdTokenClaims { OidcIdTokenClaims { @@ -72,5 +73,5 @@ fn authored_map_through_the_mint() -> OidcStandardClaims? { } fn authored_map_through_the_fixture_builder() -> OidcStandardClaims? { - reveal_under(handling_map: fx_map(rows: my_rows())) + reveal_under(handling_map: sealed_fixture_map()) }