Skip to content

v1 refuses any reference to test code, with a shrink-only debt ledger - #11505

Merged
gunbai-bot[bot] merged 32 commits into
mainfrom
session/proud-tern-736-test-refusal
Sep 19, 2026
Merged

gunbai-bot[bot] merged 32 commits into
mainfrom
session/proud-tern-736-test-refusal

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Why

Owner ruling: test is a marker that separates test code from serving code. No code may reference a test fn, including another test in the same module. #11478 added the marker; this PR adds the wall that consumes it.

What

v1.compiler.compile test_reference_diagnostics runs after inference, over the typed graph, in the compile pipeline. The wall is item-scoped: a reference refuses when it reaches a TestMarked declaration. A module is never classified by its members, so importing an ordinary helper from a module that also holds tests is allowed.

A reference is any of these:

  • a call, including one in an uninferred parameter or field default, bare or qualified;
  • a function value, including as a default, bare or qualified;
  • a named import of a test declaration.

Diagnostics:

  • TestCodeReferenced (blocking): an unledgered reference.
  • TestCodeReferenceAdmitted (advisory): a reference whose (module, referrer, target) has a corpus debt row. Its ceiling row is in gunbc.compile_clean_diagnostic_policy. The fixture control row admits nothing.
  • TestCodeReferenceBudgetMismatch (blocking): a row whose observed count differs from its declared count, in either direction.
  • TestCodeReferenceRowOrphaned (blocking; operator ruling A′): a corpus row whose module is neither compiled nor in the census. This is judged only when the compile's index spans every witness-layer root. A compile over narrower --source-roots states CorpusUnknown, because a row outside its roots is absent from that compile, not orphaned (review 68527).

Ledger: test_reference_debt(), an equality budget at identity grain (DESIGN §5), generated from the compiler's own diagnostics. It has one fixture control row plus the corpus rows remaining after the cleanup PRs (#11488–#11496, #11576–#11599). The 26 gunbc.demo.semantic_system_readout rows were removed by fixing the module instead (DESIGN §3 names it as its receipt; review 68483).

Not covered (named, not implied)

Evidence

Executed on every required run (floor-discovered) in test.claim.test_reference_wall_witness, through gunbc.compile_census_probe:

  • Discriminating reds, each naming the exact referrer that must refuse: test→test, serving→test, test as a value, qualified value, default value, qualified default, call in a default, qualified call in a default, and a reference on the control row's own identity.
  • Positive control: a test calling an ordinary fn draws no test-reference diagnostic at any severity, including no orphan.
  • Ratchet: the paid-down control row refuses.

The compiler_tests Rust rows (type/pattern/interface marker refusal, new target under a rostered referrer, import-all call, orphan-row polarity, corpus scope by index roots) are local only: no CI step runs cargo test.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 5 commits September 16, 2026 19:16
`test fn` / `test data` now parse to ModuleItemTestFunction / ModuleItemTestDataValue
rather than being stripped by drop_leading_test_marker. A `test` marker before any
other item form is refused instead of silently ignored. Consumers that only ask what
shape an item has read module_item_kind_shape, so emission and extdeps data reading
are unchanged. Prerequisite for refusing references to a test fn at resolve.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A `test` marker is sugar on an ordinary fn/data item that segregates test code from
serving code, so it no longer changes module_item_kind. Node carries
declaration_marker: Unmarked | TestMarked; rebuilds copy it, everything else is
Unmarked. Emitters and cli_run.rs are back to main. The annotation now states the
resolver refusal as a declared frontier instead of an existing behavior (review 66985).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ed kind

`pattern` and `interface` are BlockBody forms whose constructor stamps
ModuleItemFunction, so checking the parsed kind admitted `test pattern` and
`test interface`. Admissibility now reads the ItemForm body_kind before the item
is parsed (ExprBody = fn, ValueBody = data); the refusal test covers both forms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v1.compiler.compile test_reference_diagnostics runs after inference over the typed graph:
a call to a TestMarked declaration from anywhere (including another test) and an import of
a test-declaring module by a module that declares none are TestCodeReferenced (blocking).
Existing references are admitted per (module, referrer) with an exact count in
test_reference_debt (153 rows, 1175 references across dag and src/v2); a row whose observed
count differs in either direction is TestCodeReferenceBudgetMismatch (blocking).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…advisory class

Addresses review 67156: ledger rows key on (module, referrer, target) with a dissolution
condition (1135 rows); TestCodeReferenceAdmitted has an advisory_class_ceilings row;
a TestMarked declaration used as a function value or named in an import is a reference;
the boolean marker helper is gone; the DeclarationMarker frontier annotation now names
its consumer.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67156 in 0d4e08e:

  1. Untracked advisory class / no trigger / stale frontier. TestCodeReferenceAdmitted now has a DeclaredAdmissionRoster row in gunbc.compile_clean_diagnostic_policy advisory_class_ceilings, pointing at v1.compiler.compile test_reference_debt. Every TestReferenceDebtRow carries dissolution: DissolutionCondition (test_reference_debt_dissolution). The DeclarationMarker annotation no longer says nothing reads it; it names this consumer.
  2. Count equality instead of identity join. Rows key on (module, referrer, target), and the count is only how many times one referrer names one target. Swapping a target under a rostered referrer has no row and refuses. a_new_target_under_a_rostered_referrer_is_refused asserts exactly your scenario: a blocking TestCodeReferenced plus the paid-down mismatch. The ledger is regenerated from the compiler at this grain: 1135 rows / 1135 references (dag-primary 980, src/v2-primary 155).
  3. Function-value and locally-bound path silent. A TestMarked declaration taken as a value (ExprVar with FunctionValueBinding, resolved through the module's own items and explicit import members) and a test declaration named in an import are now references. A value later applied through LocallyBoundCall is decided where it is taken. a_test_fn_used_as_a_value_is_refused is the red.
  4. Predicate helper. declaration_marker_is_test is deleted; the two sites compare == TestMarked.

All 7 marker and wall tests pass locally; regeneration is at its fixed point.

— sent from proud-tern-736

gunbc-ci-auto-heal and others added 3 commits September 17, 2026 06:34
…dratic fold (review 67195)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…6-test-refusal

# Conflicts:
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
#	src/v1/stage0/src/v1_compiler_infer_method.rs
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67195 (cf95303, carried into 60df823): the quadratic fold is gone. test_reference_diagnostics builds maps once per compile: occurrence counts and first spans keyed by (module, referrer, target), the ledger's key set, and the compiled-module set. Admission and each row's budget are then single map_get/map_contains_key lookups, not filter/any scans of the ledger or the occurrence list. The double observed |> count is gone too.

60df823 also merges main and regenerates the ledger on the merged tree (1151 rows). The previous head reds were the ledger working as intended: main had changed host_convergence_protocol_witness_test under a rostered referrer. All 7 marker and wall tests pass; regeneration is at its fixed point.

— sent from proud-tern-736

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67224 in f6985cf. You're right: compiler_tests is #[cfg(test)] inside v1-compiler, no CI step runs cargo test, so the two blocking arms had no executed evidence. The PR body's rung note described the gap but didn't close it.

The wall's evidence is now test.claim.test_reference_wall_witness (dag/test/claim/test_reference_wall_witness_test.dag). It is floor-discovered and asks the compiler through gunbc.compile_census_probe, the same source-string census algebra_expansion_evidence_witness_test uses for this exact reason:

  • a_test_calling_a_test_is_refused / serving_code_calling_a_test_is_refused / a_test_used_as_a_value_is_refused: blocking TestCodeReferenced with the exact referrer as subject (blocking_subject_count_for == 1).
  • a_test_calling_an_ordinary_fn_is_admitted: the positive control; neither TestCodeReferenced nor TestCodeReferenceAdmitted at any severity.
  • a_paid_down_ledger_row_is_refused: TestCodeReferenceBudgetMismatch for a real ledger row compiled with its reference removed. It names that row, so it moves when the row is paid down.

All five PASS locally via claim_batch --source-root dag --source-root src/v2 on the head binary. The compiler_tests rows stay as local diligence only and are no longer cited as the rung.

— sent from proud-tern-736

@gunbai-bot gunbai-bot Bot mentioned this pull request Sep 17, 2026
6 tasks
Base automatically changed from session/proud-tern-736 to main September 17, 2026 21:33
gunbc-ci-auto-heal and others added 2 commits September 17, 2026 21:38
…6-test-refusal

# Conflicts:
#	src/v1/00_core.dag
#	src/v1/compiler_tests_rust.dag
#	src/v1/stage0/src/compiler_tests.rs
#	src/v1/stage0/src/v1_compiler_compile.rs
#	src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
#	src/v1/stage0/src/v1_compiler_infer_method.rs
#	src/v1/stage0/src/v1_compiler_infer_patterns.rs
#	src/v1/stage0/src/v1_std_core.rs
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67357 in 1056c36. Both findings were my merge resolution, not the wall: I resolved the seven generated-Rust conflicts to the branch side, but main now contains #11478, so main's generated files were the newer ones and taking ours reverted them. Fixed by taking main's copy of every generated file and re-running regeneration from the merged .dag sources. src/v1/stage0/src/v1_compiler_infer_method.rs and src/v1/stage0/src/v1_compiler_infer_patterns.rs are now byte-identical to origin/main, so the four builtin_function_registry rows are back and variant lookup is find_variant_child_keyed again, not find_child_named. Regeneration reports first_generation_equal=true.

Also in this head: the ledger is regenerated against main with five cleanup PRs landed — 1135 references down to 324. The 257 dag rows come from the compiler's own diagnostics. The 67 src/v2 rows are carried from the previous head and filtered to calls that still exist in source, because main's whole-corpus admission (#11265) has no demand row for a src/v2-primary compile, so I cannot regenerate that half locally; CI's compile-clean gate is the oracle for those rows and will name any that are stale. All 7 marker and wall tests pass.

— sent from proud-tern-736

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 67402 in bf6b79c.

The stale fixture. Correct and my own doing: the same commit that regenerated the ledger deleted test.claim.host_build_cache_provision_design's row, so a_paid_down_ledger_row_is_refused asserted a mismatch that could no longer be raised. It now names gunbc.demo.semantic_system_readout, which carries rows in the current ledger, and asserts >= 1 because that module has several rows and each refuses on its own. The annotation now states the coupling explicitly: this fixture must be repointed whenever its module's debt is paid down, and it retires with the ledger's last row. All five floor claims PASS locally via claim_batch.

The src/v2 rows. The previous head's floor run was the oracle I said it would be, and it found both directions: 26 references with no row (mostly cross-module, which my text filter could not see) and 13 rows with nothing left to observe. Both applied from CI's own output; the ledger is 337 rows.

The count in the commit subject. You're right, and it was wrong again on this push for the same reason: my rebuild script had the figure hard-coded. Fixed in the script; the PR body carries the accurate numbers and squash-merge takes the PR title, not the commit subject.

— sent from proud-tern-736

gunbc-ci-auto-heal and others added 5 commits September 18, 2026 01:33
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…6-test-refusal

# Conflicts:
#	src/v1/stage0/src/v1_std_core.rs
…s 67441, 67459)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Addressed reviews 67441 and 67459 in 05e247d. Both were real, and both came from my rebuild script rather than the design:

  • The control row had no consumer / the claim named a module with no row (review 67441). The script staged only src/v1, so the floor claim's edit was never committed: the pushed head carried the new wall.fixture.paid_down control row beside the old fixture, which still named test.claim.host_build_cache_provision_design — a module whose rows the same PR had deleted. Both sides are now committed together: the fixture compiles wall.fixture.paid_down, the ledger's first row is that module, and the annotation on test_reference_debt says it is the wall's control rather than debt and why a fixture cannot reproduce a corpus module (it would collide with the loaded corpus and the census would refuse instead of answering — that is how the earlier spelling passed locally and failed on the floor).
  • Broken seed fixed point (review 67459). Correct: the merge left v1_std_core.rs at main's copy while its callers used the new variants. Re-emitted: it now carries the three CompilerDiagnostic variants and their span/message/disposition arms (+34 lines vs origin/main), and claim_executor --required-regen reports first_generation_equal=true.

Evidence on this head: all five floor claims PASS via claim_batch on a freshly built binary, and the 7 compiler_tests rows pass. My earlier local greens on the paid-down claim were against a stale claim_batch — the script builds gunbc and claim_executor only — which is why CI saw a red I did not. The script now stages the claim and policy files and I rebuild claim_batch before trusting a claim result.

— sent from proud-tern-736

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST CHANGES on exact head 05e247dd5021166d8eb74fa91b3afc028902058c.

The central shape is right: the parser-carried marker now has a real typed-graph consumer; the debt is keyed by (module, referrer, target) with equality in both directions; the advisory class is attached to its roster; and the blocking arms have floor-discovered evidence rather than only #[cfg(test)] evidence. I found three remaining source defects in the claimed reference wall.

  1. Default-value expressions are resolved but never scanned. module_test_references starts only from each item.body. But v1 resolves and retains both param_node_default_value in item.params and field_node_default_value in type-item children. A test declaration can therefore be taken as a function value in a default and never reach test_references_in_expr, e.g.:
module wall.fixture.default
import std.types { Bool }

test fn leaf() -> Bool { true }
fn helper(cb: fn() -> Bool = leaf) -> Bool { cb() }

The typed default carries the same ExprVar { binding_kind: FunctionValueBinding } that the body test covers, but this walk never visits it. A field default has the same hole. Please traverse every semantic expression-bearing field of each typed item—at minimum parameter defaults and field defaults—through the same reference fold, and add floor-discovered reds for these routes.

  1. A function value introduced by an import-all cannot be qualified. visible_declaration_keys contains own declarations and import_specific_names_at only. A no-braces import is represented as is_all: true with no specific-name rows, so a bare imported test function used as a value has FunctionValueBinding but function_value_target has no key for it. In a caller module that declares a test, module_refs is suppressed, so the reference disappears entirely:
module wall.fixture.target
import std.types { Bool }
test fn leaf() -> Bool { true }

module wall.fixture.caller
import wall.fixture.target
import std.types { Bool }
test fn expose() -> fn() -> Bool { leaf }

Please derive the declaration identity from the typed binding/decl-ref authority rather than reconstructing it from explicit import syntax, or explicitly expand import-all against the typed target module. Add an executing floor red for this exact route.

  1. The module-dependency arm is not scoped to the test fn item. module_refs classifies the whole caller from module_declares_tests: a module containing any test is exempt, including its ordinary serving functions; conversely, a serving module importing only an ordinary unmarked helper from a mixed module is blocked merely because some other item in that module is marked. That is both under- and over-inclusive relative to the per-declaration marker. The owner ruling was that test fn is the scoped item and ordinary fn helpers remain ordinary. Please make this rule declaration/reachability-grained, or remove the whole-module arm and let exact marked-declaration references carry the wall; module_has_any_test is not a faithful proxy for either the referrer or target being test code.

Non-blocking bookkeeping: the PR body still says 1135 rows / 1135 references, while the branch comments describe the regenerated current ledger as 337. Please update the body once the next regeneration settles.

The current witnesses workflow is still in progress; these findings are source-semantic and do not depend on that result.

…e-level arm (side-chat review)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@briansrls
briansrls added this pull request to the merge queue Sep 19, 2026
@briansrls
briansrls removed this pull request from the merge queue due to a manual request Sep 19, 2026
gunbc-ci-auto-heal and others added 3 commits September 19, 2026 12:42
… is loaded (operator ruling A', review 67730)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…n caller, not inferred from census size (review 68429)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Addressed review 68429 in 504596b, implementing the operator's ruling (option A as refined: orphan rows refuse wherever the corpus is known).

Correct, and the inversion was exactly as described: the census holds modules OUTSIDE the closure, so a whole-tree compile has an empty census and the most complete knowledge, and I read that as ignorance. Corpus knowledge is now stated by the caller, not inferred from census size:

  • v1.compiler.compile CompilePipelineOptions carries corpus: CorpusScope = CorpusKnown | CorpusUnknown. default_compile_pipeline_options is CorpusUnknown.
  • test_reference_census maps CorpusKnown to CensusLoaded over the census names, which may be empty, and CorpusUnknown to CensusAbsent.
  • compile_clean_pipeline_options_for_sources states CorpusKnown whenever an index was consulted, including when the census is empty. It no longer falls back to defaults there.
  • Both whole-tree compile-clean routes (compile_clean_whole_tree_hard_diagnostics, compile_clean_whole_tree_resolved) now compile with those options instead of plain compile_to_resolved, so the deletion PR you describe is judged on its own run.
  • gunbc compile (main.rs) states CorpusUnknown.

The orphan arm itself: a corpus-debt row whose module is neither compiled nor in the census refuses as TestCodeReferenceRowOrphaned (blocking). The fixture control row is exempt by its declared FixtureControlRow scope. Evidence: an_orphaned_ledger_row_is_refused_only_when_the_census_is_loaded calls test_reference_unevaluated_row_diag directly (a red, plus controls for an out-of-closure module, CensusAbsent, and the fixture scope). It runs in no CI step, as its annotation says, because an orphaned row cannot be authored into the real ledger without red-ing every run. The floor control asserts a census-backed fixture compile raises no orphan.

All 10 floor claims and 5 compiler_tests pass on a fresh build; regeneration is at its fixed point.

— sent from proud-tern-736

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REQUEST CHANGES on exact head 504596b613123a170752cf08e172c2e985ff1d63.

The earlier holds are substantially answered on this head. declaration_test_references now reaches parameter/type-child defaults; uninferred bare and qualified values/calls have executing floor reds; the whole-module module_declares_tests proxy is deleted; wildcard direct calls are attributed through the typed target module; and CorpusKnown is now caller-stated so an empty whole-tree census means complete knowledge rather than ignorance. The orphan-row refusal is wired into both whole-tree compile-clean routes.

One blocking defect remains in the new fixture/debt split:

FixtureControlRow is still an admission row.

test_reference_debt() contains the synthetic row

(wall.fixture.paid_down, reader, wall.fixture.paid_down.leaf)

with scope: FixtureControlRow. The scope is consulted only by test_reference_unevaluated_row_diag, so it prevents orphan refusal. But test_reference_diagnostics builds debt_keys from every row, without filtering by scope, and test_reference_occurrence_diag turns any matching occurrence into advisory TestCodeReferenceAdmitted.

Consequently this module inhabits the control identity and passes the wall:

module wall.fixture.paid_down
import std.types { Bool }

test fn leaf() -> Bool { true }
fn reader() -> Bool { leaf() }

The occurrence matches debt_keys, so it is advisory; observed 1 equals declared 1, so there is no budget mismatch; the module is compiled, so there is no orphan. Compile-clean therefore admits a brand-new test-to-test/serving-to-test reference solely because it chose the fixture's identity. That contradicts the row's own annotation that it is "the wall's control, not debt," and leaves a permanent admission backdoor in the production ledger.

Please separate fixture controls from admission authority, or at minimum derive admission keys only from CorpusDebtRow. Keep the fixture row available to exercise the paid-down budget arm if needed, but an inhabited FixtureControlRow identity must produce blocking TestCodeReferenced, never TestCodeReferenceAdmitted. Add the discriminating control for that direction.

Please also repair the stale authority text in the same push: the leading wall annotation in compile.dag, the TestCodeReferenced message in 00_core.dag, and the PR body still describe the deleted whole-module dependency arm; the body also still reports 1,135 rows and five floor claims. Those statements now contradict this head's item-scoped implementation.

The current Actions runs were queued when I reviewed; this hold is source-semantic and independent of their result.

…ference ledger rows are deleted (review 68483)

DESIGN section 3 names this module as the receipt for the layer inversion and rules the remedy
is never a debt row. The capabilities it read from claim functions are established by those
claims on the floor.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Review 68483 addressed in cb5fdc3: gunbc.demo.semantic_system_readout no longer imports or calls any test.claim.* / v2.test.* function. The claim-backed lines are removed (their capabilities remain claimed by their own floor witnesses), and the module's 26 ledger rows are deleted, so the wall now refuses any return of that reach. Locally, the seed regenerates to first_generation_equal=true, a whole-corpus compile shows no blocking test-reference diagnostic, and the readout witness claims pass.

— sent from proud-tern-736

… the index's roots, src/v2 rows restored

- The fixture control row no longer contributes an admission key; a reference on its exact
  identity refuses (side-chat review of 504596b), with a floor claim.
- CorpusKnown is stated only when the index spans every witness-layer root, so a compile over
  narrower --source-roots does not report live rows as orphaned (review 68527).
- Restore the 75 src/v2-primary ledger rows dropped by the 504596b regeneration (floor refusal
  on cb5fdc3).
- The wall annotation and TestCodeReferenced message describe the item-scoped rule.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Pushed 78a7b3a:

  • Review 68527: CorpusKnown is now derived from the index's roots rather than from index.is_some(). compile_clean_corpus_scope states it only when the index spans every witness-layer root. The ordinary compile transaction and the XL-1 tap over narrower --source-roots get CorpusUnknown, so live rows are never reported orphaned there. The Rust test an_index_over_narrower_roots_does_not_know_the_corpus covers both arms. It is local only, since no CI step runs cargo test.
  • Side-chat review of 504596b: debt_keys is built only from CorpusDebtRow rows (test_reference_admission_insert). A reference on the fixture control's exact identity now refuses, and the new floor claim a_reference_on_the_control_identity_is_refused passes locally.
  • Floor refusal on cb5fdc3: the 504596b regeneration counted only dag-primary references and dropped all 75 src/v2 rows. They are restored, and every reference CI named is covered.
  • The wall annotation, the TestCodeReferenced message, and the PR body now describe the item-scoped rule.

— sent from proud-tern-736

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE on exact head 78a7b3a0655663694d49b974c8b5908d3800cb2d.

The prior source hold is closed at the correct boundary. test_reference_admission_insert contributes a key only for CorpusDebtRow; the FixtureControlRow remains available to exercise the equality-budget arm but cannot convert an inhabited control identity into TestCodeReferenceAdmitted. The new floor claim uses the exact formerly-admitted specimen and requires blocking TestCodeReferenced at wall.fixture.paid_down.reader.

The corpus-knowledge correction is also sound: CorpusKnown is stated only when the index spans every live witness-layer root, while a missing or narrower index yields CorpusUnknown. The full-root compile-clean routes therefore retain orphan-row enforcement without making partial-root compiles fabricate orphaned debt.

The restored src/v2 identity rows are present, the semantic readout's test references and their debt rows are removed rather than perpetuated, and the wall annotation, diagnostic text, and PR description now consistently state the item-scoped rule.

I found no remaining source-level hold on this head. Exact-head Actions were still queued at review time; this approval is bound to the source SHA and does not substitute for their execution verdict.

…ps paid down (floor refusal on 78a7b3a)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE on exact head 22072d7bbb36a22100780d79c334238646903bf7.

This is the correct shrink-only ledger response to the exact-head floor receipt from 78a7b3a: that run reported exactly 44 TestCodeReferenceBudgetMismatch diagnostics for src/v2 identities, each with declared 1, observed 0. The new commit deletes exactly 44 source rows from test_reference_debt() and changes only the corresponding generated Rust vector line; there are no additions or wall-semantics changes.

The retained src/v2 rows are not indiscriminately removed: live identities such as v2.test.lens_idempotency.sg_claims and the later wave1/manual rows remain. The deletion set begins with the three paid-down compile_eval_thesis_proof rows and ends with the four paid-down pick_ingested_probe rows, matching the floor's named mismatch population. This is debt dissolution, not a widened admission or suppressed diagnostic.

I found no new source-level hold. Exact-head Actions were still queued/in progress at review time; this approval is bound to the source SHA and does not substitute for their execution verdict.

…m (review 68591)

The two whole-tree routes rebuilt the witness-layer index only to derive the census and the
corpus claim from it; the plan's own build is now returned with the closure and consulted once.
Also drop two redundant field names clippy -D warnings refuses.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Review 68591 addressed in ce322c9. compile_clean_whole_tree_sources_and_index (witness_gates.rs) now returns the whole-tree closure together with the witness-layer index it was loaded from. The plan's WholeTree arm and both whole-tree routes use it, so the index is built once and its census and corpus claim come from that build. compile_clean_whole_tree_options is deleted.

I carried the index rather than stating CorpusKnown with an empty census. That shortcut is exact only if the entry closure reaches every indexed module, and the census derivation makes that true without assuming it.

This head also fixes two corpus: corpus field initialisers that clippy --all-targets -D warnings refused, which would have failed the build lane. Clippy is clean locally.

— sent from proud-tern-736

gunbc-ci-auto-heal and others added 2 commits September 19, 2026 19:33
…ed src/v2 ledger rows; edac names its Unit

- witness_layer_roots_compile_clean_sources_and_index_for_plan returns the closure with the index
  it was loaded from, in the whole-tree and scoped arms; the compile-clean check and emit check
  consult it instead of rebuilding (review 68614, side-chat review of ce322c9). The displaced
  rustdoc is back on witness_layer_roots_compile_clean_check.
- After merging main, 17 ledger rows name src/v2 modules the v2 cleanups deleted; the orphan
  arm refuses them, so they are deleted.
- extdeps.linux.edac read Unit bare while std.types and v2.std.cardinality both declare it
  (floor AmbiguousBareNameRead on 5068e09); an exit arm's Unit is the std.types primitive.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Review 68614 addressed in 6f38316. Both findings match the side chat's review of ce322c9:

  • witness_layer_roots_compile_clean_sources_and_index_for_plan returns the closure together with the index it was loaded from, in both the WholeTree and Scoped arms. witness_layer_roots_compile_clean_check and witness_layer_roots_compile_clean_emit_check consult that one build, and neither rebuilds the index now. The old function is a thin projection for callers that need only sources.
  • The displaced rustdoc (resolve/typecheck leg, CI scoping, skip/whole-tree authority) is back on witness_layer_roots_compile_clean_check. The new helpers carry only their own description.

This head also:

  • deletes 17 ledger rows whose src/v2 modules were removed by the merged v2 cleanups (the orphan arm refused them after merging main);
  • adds Unit to extdeps.linux.edac's std.types import, fixing the floor's AmbiguousBareNameRead on 5068e09, which came in with main.

Locally, clippy -D warnings is clean, the seed regenerates equal, and a whole-corpus compile shows 0 test-reference errors.

— sent from proud-tern-736

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE on exact head 6f38316d70193e7be034cec7234f4cfca5870515.

The ce322c9 producer-provenance hold is closed. witness_layer_roots_compile_clean_sources_and_index_for_plan now returns one (sources, index) transaction for both WholeTree and Scoped; witness_layer_roots_compile_clean_check and witness_layer_roots_compile_clean_emit_check consume that exact pair. Neither check rebuilds an index after loading its closure. The plan/scoping rustdoc is again attached to the check it describes, while the new helpers carry only their own provenance contract.

The ledger shrink is also correct. The 17 deleted rows belong to four src/v2 modules that are absent on this merged head: v2.test.lens_idempotency.sg_claims, v2.test.long.wave1_gate1_a1_projection_call_witness, v2.test.long.wave1_gate1_d_ingested_bind_loop_eval_witness, and v2.test.long.wave1_gate1_general_body_producer_witness. Deleting their corpus rows is the required response to TestCodeReferenceRowOrphaned, and the generated Rust mirror carries the same shrink. Later live v2 debt rows remain.

extdeps.linux.edac now imports Unit from std.types, which is the correct identity for the shell exit-success arm and removes the merged-main AmbiguousBareNameRead without changing that model's behavior.

I found no remaining source-level hold and no semantic widening of the test-reference wall. Exact-head witnesses was queued and heal was in progress at review time; this approval is bound to the source SHA and does not substitute for those execution verdicts.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 19, 2026
Merged via the queue into main with commit 1d77238 Sep 19, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/proud-tern-736-test-refusal branch September 19, 2026 23:56
@briansrls
briansrls restored the session/proud-tern-736-test-refusal branch September 20, 2026 00:00
briansrls pushed a commit that referenced this pull request Oct 1, 2026
- Delete 16 conjunction tests that only re-asserted their module's tests (main #11505 refuses any
  reference to test code); drop their identities from floor_expected_red.
- Execution contracts that named a conjunction now list each claim: gunbc_claims_execution_contract
  (the singular constructor is its one-element case).
- base64_encode takes QualifiedOctets: route List<UInt8> through base64_octets (oidc PEM, base64url wire).
- ServeHttpResponse/ServeWireResponse literals carry headers.
- harness_guidance: SubmissionDeclared arms; harness_cli: seat pattern names store, not layout.
- NodeInProgress.by is an EventPrincipal (sandbox, presentation witness).
- Declared types where a generic algebra fold left T unbound (form_decode parts, spark experiment
  pairs and route result).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant