Repository navigation
v1 refuses any reference to test code, with a shrink-only debt ledger - #11505
Conversation
`test fn` / `test data` now parse to ModuleItemTestFunction / ModuleItemTestDataValue rather than being stripped by drop_leading_test_marker. A `test` marker before any other item form is refused instead of silently ignored. Consumers that only ask what shape an item has read module_item_kind_shape, so emission and extdeps data reading are unchanged. Prerequisite for refusing references to a test fn at resolve. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A `test` marker is sugar on an ordinary fn/data item that segregates test code from serving code, so it no longer changes module_item_kind. Node carries declaration_marker: Unmarked | TestMarked; rebuilds copy it, everything else is Unmarked. Emitters and cli_run.rs are back to main. The annotation now states the resolver refusal as a declared frontier instead of an existing behavior (review 66985). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ed kind `pattern` and `interface` are BlockBody forms whose constructor stamps ModuleItemFunction, so checking the parsed kind admitted `test pattern` and `test interface`. Admissibility now reads the ItemForm body_kind before the item is parsed (ExprBody = fn, ValueBody = data); the refusal test covers both forms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v1.compiler.compile test_reference_diagnostics runs after inference over the typed graph: a call to a TestMarked declaration from anywhere (including another test) and an import of a test-declaring module by a module that declares none are TestCodeReferenced (blocking). Existing references are admitted per (module, referrer) with an exact count in test_reference_debt (153 rows, 1175 references across dag and src/v2); a row whose observed count differs in either direction is TestCodeReferenceBudgetMismatch (blocking). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…advisory class Addresses review 67156: ledger rows key on (module, referrer, target) with a dissolution condition (1135 rows); TestCodeReferenceAdmitted has an advisory_class_ceilings row; a TestMarked declaration used as a function value or named in an import is a reference; the boolean marker helper is gone; the DeclarationMarker frontier annotation now names its consumer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 67156 in 0d4e08e:
All 7 marker and wall tests pass locally; regeneration is at its fixed point. — sent from proud-tern-736 |
…dratic fold (review 67195) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…6-test-refusal # Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer_method.rs
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 67195 (cf95303, carried into 60df823): the quadratic fold is gone. 60df823 also merges main and regenerates the ledger on the merged tree (1151 rows). The previous head reds were the ledger working as intended: main had changed — sent from proud-tern-736 |
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 67224 in f6985cf. You're right: The wall's evidence is now
All five PASS locally via — sent from proud-tern-736 |
…6-test-refusal # Conflicts: # src/v1/00_core.dag # src/v1/compiler_tests_rust.dag # src/v1/stage0/src/compiler_tests.rs # src/v1/stage0/src/v1_compiler_compile.rs # src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer_method.rs # src/v1/stage0/src/v1_compiler_infer_patterns.rs # src/v1/stage0/src/v1_std_core.rs
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 67357 in 1056c36. Both findings were my merge resolution, not the wall: I resolved the seven generated-Rust conflicts to the branch side, but main now contains #11478, so main's generated files were the newer ones and taking ours reverted them. Fixed by taking main's copy of every generated file and re-running regeneration from the merged .dag sources. Also in this head: the ledger is regenerated against main with five cleanup PRs landed — 1135 references down to 324. The 257 dag rows come from the compiler's own diagnostics. The 67 src/v2 rows are carried from the previous head and filtered to calls that still exist in source, because main's whole-corpus admission (#11265) has no demand row for a src/v2-primary compile, so I cannot regenerate that half locally; CI's compile-clean gate is the oracle for those rows and will name any that are stale. All 7 marker and wall tests pass. — sent from proud-tern-736 |
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 67402 in bf6b79c. The stale fixture. Correct and my own doing: the same commit that regenerated the ledger deleted The src/v2 rows. The previous head's floor run was the oracle I said it would be, and it found both directions: 26 references with no row (mostly cross-module, which my text filter could not see) and 13 rows with nothing left to observe. Both applied from CI's own output; the ledger is 337 rows. The count in the commit subject. You're right, and it was wrong again on this push for the same reason: my rebuild script had the figure hard-coded. Fixed in the script; the PR body carries the accurate numbers and squash-merge takes the PR title, not the commit subject. — sent from proud-tern-736 |
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…6-test-refusal # Conflicts: # src/v1/stage0/src/v1_std_core.rs
…s 67441, 67459) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed reviews 67441 and 67459 in 05e247d. Both were real, and both came from my rebuild script rather than the design:
Evidence on this head: all five floor claims PASS via — sent from proud-tern-736 |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES on exact head 05e247dd5021166d8eb74fa91b3afc028902058c.
The central shape is right: the parser-carried marker now has a real typed-graph consumer; the debt is keyed by (module, referrer, target) with equality in both directions; the advisory class is attached to its roster; and the blocking arms have floor-discovered evidence rather than only #[cfg(test)] evidence. I found three remaining source defects in the claimed reference wall.
- Default-value expressions are resolved but never scanned.
module_test_referencesstarts only from eachitem.body. But v1 resolves and retains bothparam_node_default_valueinitem.paramsandfield_node_default_valuein type-item children. A test declaration can therefore be taken as a function value in a default and never reachtest_references_in_expr, e.g.:
module wall.fixture.default
import std.types { Bool }
test fn leaf() -> Bool { true }
fn helper(cb: fn() -> Bool = leaf) -> Bool { cb() }
The typed default carries the same ExprVar { binding_kind: FunctionValueBinding } that the body test covers, but this walk never visits it. A field default has the same hole. Please traverse every semantic expression-bearing field of each typed item—at minimum parameter defaults and field defaults—through the same reference fold, and add floor-discovered reds for these routes.
- A function value introduced by an import-all cannot be qualified.
visible_declaration_keyscontains own declarations andimport_specific_names_atonly. A no-braces import is represented asis_all: truewith no specific-name rows, so a bare imported test function used as a value hasFunctionValueBindingbutfunction_value_targethas no key for it. In a caller module that declares a test,module_refsis suppressed, so the reference disappears entirely:
module wall.fixture.target
import std.types { Bool }
test fn leaf() -> Bool { true }
module wall.fixture.caller
import wall.fixture.target
import std.types { Bool }
test fn expose() -> fn() -> Bool { leaf }
Please derive the declaration identity from the typed binding/decl-ref authority rather than reconstructing it from explicit import syntax, or explicitly expand import-all against the typed target module. Add an executing floor red for this exact route.
- The module-dependency arm is not scoped to the
test fnitem.module_refsclassifies the whole caller frommodule_declares_tests: a module containing any test is exempt, including its ordinary serving functions; conversely, a serving module importing only an ordinary unmarked helper from a mixed module is blocked merely because some other item in that module is marked. That is both under- and over-inclusive relative to the per-declaration marker. The owner ruling was thattest fnis the scoped item and ordinaryfnhelpers remain ordinary. Please make this rule declaration/reachability-grained, or remove the whole-module arm and let exact marked-declaration references carry the wall;module_has_any_testis not a faithful proxy for either the referrer or target being test code.
Non-blocking bookkeeping: the PR body still says 1135 rows / 1135 references, while the branch comments describe the regenerated current ledger as 337. Please update the body once the next regeneration settles.
The current witnesses workflow is still in progress; these findings are source-semantic and do not depend on that result.
…e-level arm (side-chat review) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… is loaded (operator ruling A', review 67730) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…n caller, not inferred from census size (review 68429) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 68429 in 504596b, implementing the operator's ruling (option A as refined: orphan rows refuse wherever the corpus is known). Correct, and the inversion was exactly as described: the census holds modules OUTSIDE the closure, so a whole-tree compile has an empty census and the most complete knowledge, and I read that as ignorance. Corpus knowledge is now stated by the caller, not inferred from census size:
The orphan arm itself: a corpus-debt row whose module is neither compiled nor in the census refuses as All 10 floor claims and 5 compiler_tests pass on a fresh build; regeneration is at its fixed point. — sent from proud-tern-736 |
briansrls
left a comment
There was a problem hiding this comment.
REQUEST CHANGES on exact head 504596b613123a170752cf08e172c2e985ff1d63.
The earlier holds are substantially answered on this head. declaration_test_references now reaches parameter/type-child defaults; uninferred bare and qualified values/calls have executing floor reds; the whole-module module_declares_tests proxy is deleted; wildcard direct calls are attributed through the typed target module; and CorpusKnown is now caller-stated so an empty whole-tree census means complete knowledge rather than ignorance. The orphan-row refusal is wired into both whole-tree compile-clean routes.
One blocking defect remains in the new fixture/debt split:
FixtureControlRow is still an admission row.
test_reference_debt() contains the synthetic row
(wall.fixture.paid_down, reader, wall.fixture.paid_down.leaf)
with scope: FixtureControlRow. The scope is consulted only by test_reference_unevaluated_row_diag, so it prevents orphan refusal. But test_reference_diagnostics builds debt_keys from every row, without filtering by scope, and test_reference_occurrence_diag turns any matching occurrence into advisory TestCodeReferenceAdmitted.
Consequently this module inhabits the control identity and passes the wall:
module wall.fixture.paid_down
import std.types { Bool }
test fn leaf() -> Bool { true }
fn reader() -> Bool { leaf() }
The occurrence matches debt_keys, so it is advisory; observed 1 equals declared 1, so there is no budget mismatch; the module is compiled, so there is no orphan. Compile-clean therefore admits a brand-new test-to-test/serving-to-test reference solely because it chose the fixture's identity. That contradicts the row's own annotation that it is "the wall's control, not debt," and leaves a permanent admission backdoor in the production ledger.
Please separate fixture controls from admission authority, or at minimum derive admission keys only from CorpusDebtRow. Keep the fixture row available to exercise the paid-down budget arm if needed, but an inhabited FixtureControlRow identity must produce blocking TestCodeReferenced, never TestCodeReferenceAdmitted. Add the discriminating control for that direction.
Please also repair the stale authority text in the same push: the leading wall annotation in compile.dag, the TestCodeReferenced message in 00_core.dag, and the PR body still describe the deleted whole-module dependency arm; the body also still reports 1,135 rows and five floor claims. Those statements now contradict this head's item-scoped implementation.
The current Actions runs were queued when I reviewed; this hold is source-semantic and independent of their result.
…ference ledger rows are deleted (review 68483) DESIGN section 3 names this module as the receipt for the layer inversion and rules the remedy is never a debt row. The capabilities it read from claim functions are established by those claims on the floor. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68483 addressed in cb5fdc3: — sent from proud-tern-736 |
… the index's roots, src/v2 rows restored - The fixture control row no longer contributes an admission key; a reference on its exact identity refuses (side-chat review of 504596b), with a floor claim. - CorpusKnown is stated only when the index spans every witness-layer root, so a compile over narrower --source-roots does not report live rows as orphaned (review 68527). - Restore the 75 src/v2-primary ledger rows dropped by the 504596b regeneration (floor refusal on cb5fdc3). - The wall annotation and TestCodeReferenced message describe the item-scoped rule. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Pushed 78a7b3a:
— sent from proud-tern-736 |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE on exact head 78a7b3a0655663694d49b974c8b5908d3800cb2d.
The prior source hold is closed at the correct boundary. test_reference_admission_insert contributes a key only for CorpusDebtRow; the FixtureControlRow remains available to exercise the equality-budget arm but cannot convert an inhabited control identity into TestCodeReferenceAdmitted. The new floor claim uses the exact formerly-admitted specimen and requires blocking TestCodeReferenced at wall.fixture.paid_down.reader.
The corpus-knowledge correction is also sound: CorpusKnown is stated only when the index spans every live witness-layer root, while a missing or narrower index yields CorpusUnknown. The full-root compile-clean routes therefore retain orphan-row enforcement without making partial-root compiles fabricate orphaned debt.
The restored src/v2 identity rows are present, the semantic readout's test references and their debt rows are removed rather than perpetuated, and the wall annotation, diagnostic text, and PR description now consistently state the item-scoped rule.
I found no remaining source-level hold on this head. Exact-head Actions were still queued at review time; this approval is bound to the source SHA and does not substitute for their execution verdict.
…ps paid down (floor refusal on 78a7b3a) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE on exact head 22072d7bbb36a22100780d79c334238646903bf7.
This is the correct shrink-only ledger response to the exact-head floor receipt from 78a7b3a: that run reported exactly 44 TestCodeReferenceBudgetMismatch diagnostics for src/v2 identities, each with declared 1, observed 0. The new commit deletes exactly 44 source rows from test_reference_debt() and changes only the corresponding generated Rust vector line; there are no additions or wall-semantics changes.
The retained src/v2 rows are not indiscriminately removed: live identities such as v2.test.lens_idempotency.sg_claims and the later wave1/manual rows remain. The deletion set begins with the three paid-down compile_eval_thesis_proof rows and ends with the four paid-down pick_ingested_probe rows, matching the floor's named mismatch population. This is debt dissolution, not a widened admission or suppressed diagnostic.
I found no new source-level hold. Exact-head Actions were still queued/in progress at review time; this approval is bound to the source SHA and does not substitute for their execution verdict.
…m (review 68591) The two whole-tree routes rebuilt the witness-layer index only to derive the census and the corpus claim from it; the plan's own build is now returned with the closure and consulted once. Also drop two redundant field names clippy -D warnings refuses. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68591 addressed in ce322c9. I carried the index rather than stating This head also fixes two — sent from proud-tern-736 |
…ed src/v2 ledger rows; edac names its Unit - witness_layer_roots_compile_clean_sources_and_index_for_plan returns the closure with the index it was loaded from, in the whole-tree and scoped arms; the compile-clean check and emit check consult it instead of rebuilding (review 68614, side-chat review of ce322c9). The displaced rustdoc is back on witness_layer_roots_compile_clean_check. - After merging main, 17 ledger rows name src/v2 modules the v2 cleanups deleted; the orphan arm refuses them, so they are deleted. - extdeps.linux.edac read Unit bare while std.types and v2.std.cardinality both declare it (floor AmbiguousBareNameRead on 5068e09); an exit arm's Unit is the std.types primitive. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 68614 addressed in 6f38316. Both findings match the side chat's review of ce322c9:
This head also:
Locally, clippy — sent from proud-tern-736 |
briansrls
left a comment
There was a problem hiding this comment.
APPROVE on exact head 6f38316d70193e7be034cec7234f4cfca5870515.
The ce322c9 producer-provenance hold is closed. witness_layer_roots_compile_clean_sources_and_index_for_plan now returns one (sources, index) transaction for both WholeTree and Scoped; witness_layer_roots_compile_clean_check and witness_layer_roots_compile_clean_emit_check consume that exact pair. Neither check rebuilds an index after loading its closure. The plan/scoping rustdoc is again attached to the check it describes, while the new helpers carry only their own provenance contract.
The ledger shrink is also correct. The 17 deleted rows belong to four src/v2 modules that are absent on this merged head: v2.test.lens_idempotency.sg_claims, v2.test.long.wave1_gate1_a1_projection_call_witness, v2.test.long.wave1_gate1_d_ingested_bind_loop_eval_witness, and v2.test.long.wave1_gate1_general_body_producer_witness. Deleting their corpus rows is the required response to TestCodeReferenceRowOrphaned, and the generated Rust mirror carries the same shrink. Later live v2 debt rows remain.
extdeps.linux.edac now imports Unit from std.types, which is the correct identity for the shell exit-success arm and removes the merged-main AmbiguousBareNameRead without changing that model's behavior.
I found no remaining source-level hold and no semantic widening of the test-reference wall. Exact-head witnesses was queued and heal was in progress at review time; this approval is bound to the source SHA and does not substitute for those execution verdicts.
- Delete 16 conjunction tests that only re-asserted their module's tests (main #11505 refuses any reference to test code); drop their identities from floor_expected_red. - Execution contracts that named a conjunction now list each claim: gunbc_claims_execution_contract (the singular constructor is its one-element case). - base64_encode takes QualifiedOctets: route List<UInt8> through base64_octets (oidc PEM, base64url wire). - ServeHttpResponse/ServeWireResponse literals carry headers. - harness_guidance: SubmissionDeclared arms; harness_cli: seat pattern names store, not layout. - NodeInProgress.by is an EventPrincipal (sandbox, presentation witness). - Declared types where a generic algebra fold left T unbound (form_decode parts, spark experiment pairs and route result). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Why
Owner ruling:
testis a marker that separates test code from serving code. No code may reference atest fn, including another test in the same module. #11478 added the marker; this PR adds the wall that consumes it.What
v1.compiler.compile test_reference_diagnosticsruns after inference, over the typed graph, in the compile pipeline. The wall is item-scoped: a reference refuses when it reaches aTestMarkeddeclaration. A module is never classified by its members, so importing an ordinary helper from a module that also holds tests is allowed.A reference is any of these:
Diagnostics:
TestCodeReferenced(blocking): an unledgered reference.TestCodeReferenceAdmitted(advisory): a reference whose(module, referrer, target)has a corpus debt row. Its ceiling row is ingunbc.compile_clean_diagnostic_policy. The fixture control row admits nothing.TestCodeReferenceBudgetMismatch(blocking): a row whose observed count differs from its declared count, in either direction.TestCodeReferenceRowOrphaned(blocking; operator ruling A′): a corpus row whose module is neither compiled nor in the census. This is judged only when the compile's index spans every witness-layer root. A compile over narrower--source-roots statesCorpusUnknown, because a row outside its roots is absent from that compile, not orphaned (review 68527).Ledger:
test_reference_debt(), an equality budget at identity grain (DESIGN §5), generated from the compiler's own diagnostics. It has one fixture control row plus the corpus rows remaining after the cleanup PRs (#11488–#11496, #11576–#11599). The 26gunbc.demo.semantic_system_readoutrows were removed by fixing the module instead (DESIGN §3 names it as its receipt; review 68483).Not covered (named, not implied)
LocalValueBindingby v1 inference, so the wall cannot see it; this is declared with its trigger. Direct calls through an import-all are covered.Evidence
Executed on every required run (floor-discovered) in
test.claim.test_reference_wall_witness, throughgunbc.compile_census_probe:The
compiler_testsRust rows (type/pattern/interface marker refusal, new target under a rostered referrer, import-all call, orphan-row polarity, corpus scope by index roots) are local only: no CI step runscargo test.🤖 Generated with Claude Code