Repository navigation
Namespace cut program manager: import -> containment resolution (NAMESPACE-XL chain), funded now that v1 deletion has advanced - XL-0B-D denominator producer, XL-1 oracle capture before v1 deletion, XL-2/XL-4 instruments, XL-3 census, ACT-0 - #11516
Closed
briansrls wants to merge 142 commits into
Closed
briansrls wants to merge 142 commits into
briansrls wants to merge 142 commits into
Conversation
…ng since it was written v2.compiler.resolution_provenance models one name resolved at one position answering with its target and the module that contains it, and it models the dependency fold over those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were five hand-authored fixture rows in one witness, which makes a well-shaped module dangling in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather than executed. This is that producer. ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived graph ask the same question of the tree -- where is every mention, and at what containment position -- and differ only in what they fold the answers into. Two collectors would be the section 3 fork with the widest blast radius, because a mention one missed would be silently absent from both a denominator and a dependency edge. Landed as its own commit so XL-4 consumes it rather than building a second one. A declaration's NAME is an edge label and never a node, so an Atom is a reference by construction rather than by a filter that could be wrong. The two exclusions -- module header metadata, and _node_projection parse projections that would double-count every mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
std.repair_input_origin's header defers the DeclarationCarrier half to XL-0B/C. This lands it -- on the v2 route, per the fierce-lark-661 ruling: v1.compiler.emit_rust is scheduled for deletion and may at most consume, never own. No src/v1 edits. THE SIX v1 CHANNELS HAVE NO v2 ANALOGUE AND ARE NOT PORTED. They are collectors inside v1.compiler.emit_rust's Rust use-line planner; v2 emits no use lines and has no such planner, so reproducing them would mint a dying emitter's artifact on a route that never carried the surface. What survives the route change is the QUESTION -- what an import-to-containment repair takes as input -- and on v2 it is a resolver fact: v2.compiler.repair_input_origin_roster folds the resolver's four answers, over the mentions the reference-site collector enumerates. THE MODEL. SourceDeclarationCarrierIdentity carries a DeclarationRef and NEVER a CorpusDeclared decl_file -- one fact, one identity. The three departures from std.coercion TypeDeclarationProvenance are stated beside the type (DESIGN section 3b admits a stated divergence and refuses a silent one): the position; the KernelMinted arm having NO PRODUCER on this route, so carrying it would be a permanently uninhabited decoration rather than a weak wall; and DeclarationIdentityAbsent conflating unbound with ambiguous, which are two states with two repairs. There is deliberately no referencing-module field: the module is the longest rostered prefix of the position, so a second field would store one fact twice and then need a fabricated answer for a position no roster covers. GRAIN. Every mention is a row, each with its typed resolver arm. No filter on import-mediation or eligibility -- the stage label says BEFORE eligibility or repair disposition, and a denominator that filtered would be measuring its filter. EVIDENCE BY EXECUTION, AND THE WALLS DISCRIMINATE. Five witnesses pass; four mutations, one per wall, each reds its own wall and leaves the others standing: module-header exclusion removed -> the declared-names wall; a dotted mention walked per segment -> the one-site wall (and the declared-names wall, since the segments become spurious mentions); the position not extended by named edges -> the containment-position wall (and the positive control, which reads that position); unanswerable mentions dropped -> the not-a-drop wall. CARRIERS. StageXL0Denominator was NotDerivable; it now reads the same delivery-receipt channel XL-2 and XL-4 read, so a repair to probe observability still cannot move it and only delivering the producer can. MissingInstrument RepairInputOriginRosterProducer is deleted. The expecting-red status witness did NOT retire -- DESIGN section 4b(4) -- it flipped to a permanent regression control asserting the same rule on the arm that now stands. ACT-0's DenominatorRosterDigest stays outstanding, correctly: a delivery receipt carries no base, and pinning one is ACT-0's act. The census row now says where its undischarged half went: the v2 DeclarationRef carrier discharges it, and the v1 position retires when v1.compiler.emit_rust is deleted, not by a conversion. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…rier Installed from the generated candidate, never hand-edited: the mirror is a generated artifact and the authority is dag/std/repair_input_origin.dag. Adjudicated by `claim_executor --required-regen --regen-affected-scope`, which named this one path and no other (declared_divergent=1 [main.rs] is pre-existing and is not in the differing set). Verified by diffing the whole candidate src tree against the committed one file by file: std_repair_input_origin.rs is the only file that differs, and its diff is exactly the new provenance coproduct, the carrier identity struct, the SourceDeclarationCarrier arm and its two match arms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…trument. Fill the existing swap-body producer from resolved qualified-name sites (never import syntax), report typed diffs against the import graph, and hold the stage delivery receipt. Do not swap dependency_resolution_facts_live. Co-authored-by: Cursor <cursoragent@cursor.com>
…umer Review 64751. The finding is correct and I confirmed it independently: the whole body was `is_empty(xs: roster)` and `git grep` returned exactly one occurrence in the tree -- its own definition. That is two defects at once, a second name for one concept (DESIGN section 3) and a declaration with no call site in the closure (section 3c's third state, the only red one). Callers wanting emptiness call is_empty directly. Also drops the `is_empty` and `Bool` imports it was the sole user of. Removing the function while keeping its imports would have left a smaller instance of the same defect. The sibling entry point repair_input_origin_denominator_digest_lines is deliberately NOT deleted: it is also unconsumed today, but it names its consumer and the pinning act (ACT-0) beside it, which is section 3c's admissible declared frontier rather than a dangling declaration. The review reached the same conclusion. Re-ran the five XL-0 witnesses after the deletion: 5/5 PASS. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…ngling declaration
Three defects, all mine, all introduced by this branch. The required floor named all of
them in one refusal; I had independently found the first before its log was retrievable.
1. NON-EXHAUSTIVE MATCH (the floor red). Adding the SourceDeclarationCarrier arm to
RepairInputOriginCandidate left two wildcard-free two-arm matches in the pre-existing
XL-0A split witness. That is the ordinary compiler floor DESIGN section 4b names --
"closed variants eliminate exhaustively" -- and the roster module's own annotation
predicts exactly this ("a fourth arm added to the shared base refuses to compile here").
Swept every .dag touching the coproduct rather than only the file CI named: four files,
of which the producer and the XL-0 witness already handled all three arms.
2. SOURCE ANNOTATIONS INSIDE DECLARATION BODIES, in the XL-0 status arm and in the
regression control's test body. Hoisted above their declarations, which is the only
grain DESIGN section 4c models. Swept the whole branch diff: no indented `//` remains.
3. repair_input_origin_denominator_digest_lines DELETED (review 64768). It had no call
site, and the declared-frontier defence did not attach to it: the delivery receipt names
repair_input_origin_roster_over_roots, a different function that IS consumed, and both
of this one's components are exercised by the XL-0 witness. Review 64751 had passed the
same declaration as an admissible frontier; that read did not check which symbol the
receipt names. The surviving annotation records why the wrapper is absent so it is not
re-added.
WHY DEFECT 2 SURVIVED A GREEN LOCAL RUN, measured rather than assumed. On the identical
unmodified tree the floor refused, `claim_batch` returned PASS rc=0 for the same witness.
A controlled probe -- one module whose only content is an in-body annotation -- then showed
BOTH local instruments admit it: claim_batch PASSes, and `gunbc run` reaches evaluation and
returns true. So neither local execution path gates this class; only the floor's strict
preparation does, and the cheap local guard is syntactic (grep changed .dag for indented
`//`), not executional. The probe fixture was deleted rather than committed.
Re-ran after the repair: 9/9 PASS across both witness entries (4 XL-0A split + 5 XL-0).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Blanket filesystem import on module_graph forked List onto std.types and the new claim tests were censored at the enrolment ceiling; the producer stays on the named swap body and tools.reference_derived_graph.main remains the RED. Co-authored-by: Cursor <cursoragent@cursor.com>
…ng since it was written v2.compiler.resolution_provenance models one name resolved at one position answering with its target and the module that contains it, and it models the dependency fold over those answers. Nothing in the corpus produced a ReferenceSite: the only constructors were five hand-authored fixture rows in one witness, which makes a well-shaped module dangling in DESIGN section 3c's exact sense -- a declaration whose consumers are described rather than executed. This is that producer. ONE COLLECTOR, TWO STAGES. NAMESPACE-XL's XL-0 denominator and XL-4's reference-derived graph ask the same question of the tree -- where is every mention, and at what containment position -- and differ only in what they fold the answers into. Two collectors would be the section 3 fork with the widest blast radius, because a mention one missed would be silently absent from both a denominator and a dependency edge. Landed as its own commit so XL-4 consumes it rather than building a second one. A declaration's NAME is an edge label and never a node, so an Atom is a reference by construction rather than by a filter that could be wrong. The two exclusions -- module header metadata, and _node_projection parse projections that would double-count every mention -- are recognised by the same predicates v2.compiler.symbol_index_fill consults. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Delete the module_graph mention walk. The swap body consumes collect_module_reference_sites and module_dependencies_from_sites. Co-authored-by: Cursor <cursoragent@cursor.com>
…es and EMPTY on the corpus The receipt this branch landed said the XL-0 instrument was "delivered and discriminated once". It had been discriminated against HAND-BUILT Node trees. Over the tree the production ingest actually yields, the collector returned NO sites at all. That is DESIGN section 5's specification-without-execution in its most flattering form -- the witnesses really executed, against a universe the corpus never produces -- and a stage reading CLEAR off it reports a denominator that does not exist. Raised by the XL-2 lane, independently reproduced by warm-ibex-518 over real .dag files, and confirmed here by a substrate-only fixture that drives the REAL ingest (module_roots_from_source_root_ingest, projected through normalized_tree_roots_to_nodes -- the same projection symbol_index_fill consumes, so the modeled route, not a workaround). WITHDRAWN: the StageDeliveryReceipt row, DenominatorRosterInstrumentDelivered, and StageXL0Denominator reading CLEAR. RESTORED: NotDerivable, awaiting RepairInputOriginRosterProducer -- whose label now demands a NON-EMPTY denominator over the production route, so the same claim cannot be re-made on the same evidence. TWO DEFECTS, BOTH ISOLATED BY MUTATION, ONLY THE FIRST MINE: 1. THE BLACKOUT WAS MY OWN SPECULATIVE GUARD. The collector skipped every `_node_projection` edge to prevent a double-count I never demonstrated. On a real ingested tree a module's content hangs under exactly those edges, so the guard returned zero sites corpus-wide while synthetic fixtures stayed green. Deleted. The lesson is kept in the module rather than only here: a speculative exclusion over a shape the author has not observed is indistinguishable from a blackout until something executes against the real tree. 2. WITH IT GONE, THE ERASURE IS REAL AND WIDER THAN CALLS. Measured on the production route: a value reference outside a call and a parameter reference ARE found; a call argument, a CALLEE name, and a TYPE-POSITION name are NOT. Type references are most of what an import-to-containment repair operates on, which is why XL-0 has no denominator yet rather than a slightly small one. Trigger: the v2 body-lowering repair (XL-2, gunbc#11207). ALSO FIXED, from review 64782: spine unwrapping ran on EVERY node, but namespace_graft_spine_segment_edge_optional recognises ANY single named edge targeting a Conj, so recursion silently dropped nested declaration and field labels from `position` -- a mention recorded at a chain it does not sit at, resolved against the wrong scope. A mislocated mention is worse than a missing one: it is a fabricated plausible answer rather than an absence someone can count. Unwrapping is now one move at the module boundary. THE MEASUREMENTS ARE ENROLLED, NOT NARRATED. v2.test.claim.namespace_xl0.call_argument_mention_survival asserts what the production route produces TODAY, so each deficiency row goes RED when the lowering repair lands and the repair must return here and re-state what is true, instead of widening a denominator nobody re-measured. 42/42 PASS: the 8 production-route probes plus the 34-test program-status closure. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
The swap body folds collect_module_reference_sites through module_dependencies_from_sites. Witness tests over the fixture identities require a reference-only edge, no unused-import edge, exactly one shared edge, and go red on a mutant that re-admits import-decl mentions. Co-authored-by: Cursor <cursoragent@cursor.com>
…urn type moves) Review 64782's second finding, and the manager's condition for #11201 moving. The arm was `Rejected => acc`: a root whose module header does not resolve contributed no mentions and NO EVIDENCE, so a caller could not distinguish an unreadable module from an empty one. DESIGN section 5 calls that a hard reject rather than a weak arm -- a failure arm must refuse, never widen, and every degradation must be a typed, located, countable diagnostic. UnreadableModuleRoot { locus } is all three, and COUNTABLE is the property that matters here rather than merely typed: XL-0 is a DENOMINATOR, so a root silently missing from it does not make the number slightly small, it makes it a different question answered under the same name. "n roots were unreadable" is now answerable instead of inferred from a short population. THE REFUSAL TRAVELS WITH THE RESULT, NOT BESIDE IT. collect_module_reference_sites and collect_reference_sites now return ReferenceSiteCollection { sites, unreadable_roots }, and repair_input_origin_roster_over_roots returns RepairInputOriginRoster { carriers, unreadable_roots }. A caller cannot take the population without also taking what was lost producing it. A collector that counted the loss and a producer that discarded it one call later would be the same silent degradation a layer down, so the seam has its own wall. Both walls assert BOTH halves, because either alone is satisfiable by a wrong implementation: the sites must be unchanged (the unreadable root really did contribute nothing) AND the refusal must be present and countable (it said so). INTERFACE CHANGE, TAKEN DELIBERATELY AND ANNOUNCED FIRST. warm-ibex-518 (XL-4) and quick-otter-229 (XL-3) consume these entry points and are rebasing; the names are unchanged and only the return types moved, so the migration is `.sites` / `.carriers` at the call site, or consuming the refusal list where a total is required. NOT DONE, DELIBERATELY: no parse-tree walker was revived to route around the lowering loss. The type-position and call-expression erasure stays escalated rather than worked around, and XL-0 stays NotDerivable with its probes enrolled. 15/15 PASS across both XL-0 witness entries, including the two new refusal walls. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A fixture whose only provider mention sits in a call argument yields no reference-derived edge on parse_module trees (XL-4 ingest) and on normalized trees. Trigger is eager-raven-113's body-lowering repair. Co-authored-by: Cursor <cursoragent@cursor.com>
Your collector over parse_module trees does not recover type-position or out-of-call body mentions either; the rows record that absence until lowering and site collection catch up. Co-authored-by: Cursor <cursoragent@cursor.com>
…module miss measured
Review 64799, both findings verified against the code before acting, plus a correction that
came from XL-4's execution rather than from review.
1. SPINE UNWRAPPING WAS WRONG BY length(module_qn) - 1. namespace_graft_fold_spine wraps
ONCE PER SEGMENT; this unwrapped one level, and the generic named-edge rule then walked
the survivors as ordinary containment -- re-appending those segments to a position that
already carried them, so a mention in `a.b.c` was recorded at `a.b.c.b.c`. A mislocated
mention is a fabricated plausible answer (section 5) and changes which lexical scope the
resolver walks, so it is worse than an absent one.
THE COUNT IS DERIVED, NOT GUESSED: it is the module qualified name this walk already
resolved from the header, the same value the spine was folded from. Not a
loop-while-the-shape-matches, because namespace_graft_spine_segment_edge_optional
recognises ANY single named edge targeting a Conj, so a shape-driven loop would eat a
genuine one-declaration module body. Consuming the count makes over-unwrapping
unwritable rather than unlikely.
2. THE TRAVERSAL WAS QUADRATIC. qualified_name_from_node folds an entire subtree to answer,
and this walk then descended into that same subtree, so each nesting level re-folded
everything beneath it and everything beneath it was walked again. Now guarded by an O(1)
shape check -- Conj, exactly two children, both labelled head/tail -- using the SAME two
labels v2.std.qualified_name's own fold recognises, so it is a cheap precondition on that
authority rather than a second weaker spelling of it. Section 6: a proven cost-shape
defect is always fixed regardless of the realised n.
3. THE COVERAGE CLAIM I PUBLISHED WAS TOO BROAD, AND THIS IS THE IMPORTANT ONE. I reported
"a value reference outside any call IS found". That was a BARE SAME-MODULE name.
warm-ibex-518 measured a QUALIFIED CROSS-MODULE reference and found nothing; the
discriminator is now enrolled and confirms it. So the production-route population is:
SURVIVES: a bare same-module value reference outside any call; a parameter reference
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name; a type-position name
A bare same-module name resolves inside its own module, so it yields no dependency edge
and contributes nothing to an import-to-containment denominator, which is BY DEFINITION
about references that cross a module boundary. The surviving population is the part
neither XL-0 nor XL-4 has any use for. Stated in the file so no reader mistakes a
non-empty site list for a working instrument.
The partition is unchanged by fixes 1 and 2 -- re-measured after them rather than assumed.
16/16 PASS across both XL-0 witness entries.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
…cle only. The walk sees type-position ProvidedMarker and still misses body-value and call-arg names. It is not the edge producer. Co-authored-by: Cursor <cursoragent@cursor.com>
… as a graph. An unread module must not look like a leaf. The fold carries unreadable_roots; the production Outcome refuses unless the fold is total. Co-authored-by: Cursor <cursoragent@cursor.com>
module_roots_from_source_root_ingest then normalized_tree_roots_to_nodes is the tree. On that route a qualified value mention is still missing, same as type-position and call contents; those rows are measurements of today. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
…ns DO reach the collector
Review 64815, and it is the most consequential finding on this PR. fixture_sites folded the
ingested roots with `cons: fn(acc, root) { collect_module_reference_sites(root: root).sites }`
-- DISCARDING acc -- so it returned only the LAST root's sites and threw away
.unreadable_roots at the only production-route call site in the change.
WHY THAT WAS FATAL RATHER THAN UNTIDY: every load-bearing row in this file is a NEGATIVE
claim, and a negative claim is satisfied for free by a population that never contained the
root in question. The census was truthful about one module while reading as though it
covered two, and its control was green by INGEST ORDERING rather than by the walk --
reorder the reads and the whole result changes with no test naming why. That is DESIGN
section 5's fabricated plausible output: an absence measured over a silently truncated
population.
WHAT IT COST, MEASURED OVER THE FULL POPULATION: a TYPE-POSITION name IS PRESENT. I had
reported it absent. `Bool` is mentioned in both fixture modules and the provider's sites
were the ones dropped, so the absence was manufactured by the fold. That claim had already
travelled: XL-3 was holding type-position census fixtures red on it and XL-4 carried a
type-position row on its declared frontier. Both lanes have been sent the retraction.
CORRECTED PARTITION, re-measured over every ingested root:
SURVIVES: a bare same-module value reference outside any call; a parameter reference;
a TYPE-POSITION name
DOES NOT: a qualified cross-module reference, with or without a call; a call argument;
a callee name
THE DISPOSITION IS UNCHANGED: XL-0 stays NotDerivable, because a denominator is made of
cross-module references and those still do not reach the collector.
TWO CAUSES, ONE LESSON. It hand-rolled a traversal beside collect_reference_sites, which
already threads the accumulator AND carries both halves -- the section 3 fork, in the one
file whose job is measuring that collector. And it discarded the typed, counted refusal
THIS PR ADDS so that a lost root cannot be mistaken for an empty one.
A SECOND INSTANCE THE REVIEW DID NOT NAME: characterise_the_module_header_resolves_on_a_
normalized_root dropped `acc` the same way, one screen below. Found by sweeping the pattern
rather than fixing the reported line. Both now conjoin over every root.
TWO NEW WALLS MAKE THE POPULATION ITSELF A SUBJECT, either of which would have caught this:
the census must speak for every ingested root, and the collection must be total, so an
unreadable root can never be the reason an "is absent" row is green.
11/11 PASS.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
Both carriers said the remaining miss was call erasure, triggered by the v2 body-lowering
repair. That is the 4b(3) defect stated in DESIGN's own words: a trigger naming less than
the capability it restores is retired BY that trigger while the capability stays dead.
Body lowering (XL-2, gunbc#11207) restores the CALL classes and nothing else. The class that
actually denies XL-0 a denominator is the QUALIFIED CROSS-MODULE reference, which is absent
with or without a call. So the repair could land, the trigger would read satisfied, and XL-0
would still have no denominator.
MEASURED OVER EVERY INGESTED ROOT, which is new since the census truncation was fixed:
REACHES IT: a bare same-module value reference outside any call; a parameter reference;
a TYPE-POSITION name
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name
A bare same-module name resolves inside its own module, so the surviving population is the
part an import-to-containment denominator cannot use.
THE THREE CAUSES ARE NOW SEPARATED WITH HONEST OWNERSHIP: two were mine and are fixed (the
parse-projection exclusion that blacked out the corpus; the census fold that discarded its
accumulator and so measured the last root only, manufacturing a type-position miss that does
not exist). The third is OPEN AND DELIBERATELY UNATTRIBUTED: a dotted reference in a body is
not a qualified-name production at all, so the collector never reassembles it, and whether
resolution itself reads dotted body access has NO EXECUTED ANSWER -- the probe built for it
fails its own control, and a structural absence is not evidence.
The capability is now named directly: XL-0 derives when the producer answers NON-EMPTY over
CROSS-MODULE references on the production route.
I flagged this same trigger-scope error in two sibling lanes' plans today while it sat in my
own carrier.
34/34 PASS on the program-status closure.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
… a callee with no arguments is missing too. consumer_type_only has no call; the edge is still absent. The trigger is lowering widened to type positions, not body-lowering alone. Co-authored-by: Cursor <cursoragent@cursor.com>
A qualified cross-module mention is missing; a bare same-module name would not make an edge. A non-empty site list is not a usable graph. Co-authored-by: Cursor <cursoragent@cursor.com>
Call-argument and type-position stay tree-side. The qualified body mention retires when the collector reassembles dag_field_access_body_node, not when lowering lands. Co-authored-by: Cursor <cursoragent@cursor.com>
This fixture's type-position is a qualified name; the full spelling is still not a site. That stays with collector reassembly, not lowering. Call and callee stay tree-side. Co-authored-by: Cursor <cursoragent@cursor.com>
…e does not appear. That absence is resolution or edge derivation, not a declared type-position frontier and not lowering. Call contents stay eager-raven; qualified body stays the collector access-chain gap. Co-authored-by: Cursor <cursoragent@cursor.com>
…port statement
XL-3 (quick-otter-229) measured an IMPORTED type name absent from type position while a
USER-DECLARED type in the same position reaches. That contradicted my row asserting a
type-position name reaches -- and they are right, because my row was never measuring a type
position.
This collector does NOT exclude import statements. `Bool` appears in
`import v2.std.logic { Bool }` in both fixture modules, and a spelling match cannot tell an
import mention from a type-position one. The assertion passed on the import line.
THAT ROW HAS NOW BEEN WRONG TWICE IN OPPOSITE DIRECTIONS: first "absent", which was the
truncated census talking; then "reaches", which was green for the wrong reason. A test whose
NAME claims more than its PREDICATE measures is worse than a red one, because it gets cited
as coverage -- and this one was, by me, to two sibling lanes.
RENAMED to what it can honestly establish (the spelling reaches the collector SOMEWHERE,
import statement included) and the real question is now asked by a discriminator that cannot
be answered by an import line: `Xl0UserType` is declared in the fixture, used only as a
parameter type, and appears in no import anywhere. It reaches.
CORRECTED, at the grain XL-3 established:
REACHES: a bare same-module value reference outside any call; a parameter reference;
a USER-DECLARED type in type position
DOES NOT: a qualified cross-module reference, with or without a call;
a call argument; a callee name
UNSEPARATED BY THIS FIXTURE: an imported type name's type-position occurrence, because its
import statement produces an indistinguishable site here.
12/12 PASS.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01U5avL86NJ1YoyyezZj2BuM
A locally declared LocalMarker in type position is found. The type-position miss on a dotted name is the same class as a qualified body mention, not lowering. Co-authored-by: Cursor <cursoragent@cursor.com>
… the missing class. Co-authored-by: Cursor <cursoragent@cursor.com>
…ive-surface roster Regenerated via gunbc run --entry dag/gunbc/instruments/generated_artifact_gate.dag --function main_wet (the heal lane's own recipe) using the seed built from origin/main. The branch's copy had come from #11209's branch and lacked the three arms main added since (type_declarer_qualified_names, floor_discovery_source_inventory, claim_scope_dag_multi_module_fixture); the regenerated file is main's plus the one XL-1 arm emit_rust_reference_derived_rows_bridge. Every other generated artifact was already at fixed point (main_wet rewrote none).
…' line The required floor's parser refused dag/std/declaring_identity_spelling.dag with 'expected expression, found Newline': the frontier row was authored as 'data x: T =' followed by a newline. #11210 was stacked on #11201 so its own CI never parsed the file; the integration branch's first floor run (0a7376d) did. No other declaration in the tree has that shape.
…must-not-resolve XL-3 fixture under test/probe Two refusals from the integration head's first floor run (35056157979), neither visible on the superseded PRs because #11209 never had a floor run and #11210 was stacked: 1. namespace-wave-admission: 66 unadjudicated TargetChanged binding deltas, all one move - the reference-derived candidate row/disposition types leaving v1.compiler.emit_rust for their one dag home gunbc.reference_derived_candidate (#11209 commit 42323e5), reached from v1.compiler.emit_rust (43 bindings) and v1.tests.claim.reference_derived_disposition_census_witness_test (23). Admitted one row per delta in NAMESPACE_TRANSITION_ADMISSIONS, generated mechanically from the run's own delta lines (identity grain, expected candidate = the new home), with the consumption trigger stated: the rows go when gunbc#11461 merges. 2. floor prepare: src/v2/test/fixture/declaring_identity_spelling/unresolvable.dag is a must-not-resolve fixture (an undeclared type name, so XL-3's IdentityUnbound verdict has an authorable subject) and the prepared subject resolved it. Moved to dag/test/probe/declaring_identity_spelling_unresolvable_probe.dag - the roster floor_prepared_subject_exclusions already excludes test/probe/ for exactly this class - with the probe header; the census reads it as source through the ingest route, so the test's path row is repointed and nothing else changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
namespace_wave_admission.rs: main retired the two consumed gunbc#11177 rows (#11262); kept main's dissolution note and emptied array, re-added only this branch's sixty-six gunbc#11461 rows - zero deletions of main's lines.
…carry the XL-4 fixture ingest as a prepared effect input
review 66826 on gunbc#11461: v2.workflow.legacy_repair_tap answered a bridge row with an
empty spelling (module_name == "" or name == "") with `Absent => acc` in BOTH the roster
fold and the observation fold - the row vanished uncounted while the roster digest still
attested a census that never counted it, and the drop was enrolled as intended behaviour.
DESIGN 5: a failure arm must refuse, never widen. Now ONE fold (admit_bridge_rows)
either admits (roster + observation rows, built together so they cannot disagree) or
refuses with the located rows (MalformedBridgeRow { index, module_name, name }); both
capture entries route the refusal through the capture outcome as
LegacyBaselineExecutionRefused { phase: RepairCensusPhase, cause: BridgeRowSpellingEmpty }
(new arm on LegacyBaselineCaptureRefusal, rendered by capture_refusal_label). The former
drop witness is now the discriminating RED empty_name_row_refuses_the_admission_located_by_index
(a well-formed sibling does not rescue the batch) beside the positive control.
Floor run 35059914771 on 557188a refused PureProducerShareWarmDispatchedEffect for
v2.test.claim.reference_derived_graph_fixture.xl4_fixture_trees (effects=11): the rule
landed on main in #11370 after #11202's last green run, and a warm row that reads the
world has an input its empty argument row cannot represent. Re-rostered in the shape that
rule prescribes: fixture_ingest is a PreparedEffectInput (the eleven committed fixture
modules under dag/test/fixture/reference_derived_graph/, acquired once at preparation,
content-keyed) and xl4_fixture_trees is a CarriedInputWarmRow over it
(ImplicitAcquisition); the plain warm row is removed. Measurements on both rows name the
runs and ledgers that re-derive the present-vs-absent verdict.
Executed locally (branch seed claim_batch, scoped): legacy_repair_tap_persisted_capture
5/5, legacy_repair_tap_live_bridge 3/3, legacy_baseline_capture 13/13,
floor_prepared_effect_input_ladder 7/7, floor/pure_producer_share_refusal 13/13,
reference_derived_graph_witness 5/5, reference_derived_graph_production_ingest 16/16.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ducer file (review 66837) The stage standing's why said the spelling census producer EXISTS while the instrument DeclaringIdentitySpellingCensus stayed NotBuilt with a label that named the whole census - one name, two meanings, and a machine-readable report that would say UNBUILT for a producer this integration lands (DESIGN 3 meaning fork; 4b(1) rung honesty). Repaired the way XL-0's label was: the instrument now names the capability that is absent - a census answering over XL-3's usable population on the production route (qualified cross-module mentions in every position; bare FIELD-position types) - and states that the producer exists and answers over the bare same-module classes only. The stale 'stacks on #11201; waits on #11201 landing' clause is replaced: #11201 lands in this integration. compiler_frontend_program_status_witness 39/39 (branch seed claim_batch). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ureAvailable names it as its evidence (review 66841) review 66841 on gunbc#11461: legacy_baseline_capture_capability returned CaptureAvailable as a constant, StageXL1BaselineCapture folded that into Clear, and the only enrolled execution of the live tap was its refusal arm (empty source roots) - deleting the Observed arm of compile_xl1_primary_root_tap left every control green. Rung inflation (DESIGN 4b(1)). The Observed arm is reachable from a committed root in-claim and cheaply (25 ms over the eleven XL-4 fixture modules), so the evidence is enrolled where it executes: the live-bridge witness now reaches Xl1PrimaryRootObserved over dag/test/fixture/reference_derived_graph with repair rows AND binding rows AND the root echoed, plus the live census counting those rows - the mutation the review describes (deleting the Observed arm) now reds. The capability value is annotated as a report of that executed evidence, naming the claim, with the honest arm stated if it ever reds. legacy_repair_tap_live_bridge_witness 5/5 (branch seed claim_batch). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ransaction and the XL-1 tap (review 66847)
review 66847 on gunbc#11461: compile_xl1_primary_root_tap (emit_host.rs) re-implemented by
hand the PrimaryRoot subject derivation the compile transaction's CompileSubject::PrimaryRoot
arm already owns - same prefix filter, import walk, reference-closure fixpoint - two sources
for one subject (DESIGN 2/6 forked logic), and the copy had already drifted in the fail-open
direction: it lacked the module-less-.dag visibility step, so a .dag under the tapped root
with no module header would have left the closure silently while the live census reported
rows.
Extracted cli_run.rs primary_root_subject_closure (prefix filter, module-less step with its
subject-read refusal, empty-root refusal, sorted import walk, fixpoint) returning typed
PrimaryRootSubjectRefusal { phase, cause }; the transaction arm maps the phase onto
compile_not_executed and the tap onto Xl1PrimaryRootTap::Refused, from one derivation. The
tap's copy is deleted. Hand-written seed files only (no mirror; fixed point unchanged).
cargo clippy --release -p v1-compiler -- -D warnings clean; legacy_repair_tap_live_bridge
5/5 with the Observed-arm control now exercising the shared derivation.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ired route; XL-3's ingest claims share one carried fixture read Two refusals on the integration floor run 35074340220 (01d5517). 1. The two Observed-arm controls added for review 66841 FAILED on the floor in under 300 microseconds while passing in 25 ms on a session host: compile_xl1_primary_root_tap gates on memory_governor whole_corpus_compile_admission BEFORE discovery, and the required floor never holds whole-corpus headroom mid-run. So the Observed arm has no required executing route today, and CaptureAvailable would be a rung read off controls the required route cannot run (DESIGN 4b(1)). legacy_baseline_capture_capability now reports the honest arm: CaptureBlocked { RepairCensusPhase, ObservedArmUnexercisedOnRequiredRoute { evidence_route, restoring_receipt } } (new refusal cause, rendered), naming the witness that executes the arm and the receipt that retires the block (a PersistedLegacyBaseline held against the pinned pre-cut base - ACT-0's BaselineCaptureReceipt). The two controls move to test.claim.long.xl1_live_tap_observed_arm_witness (long/ is declined from the required floor by route; they execute on a session host and on the one-time capture run); the floor keeps the refusal claims. The capability witness now asserts the blocked report and reds if Clear is read off an unexercised arm again. Consequence for the stage carrier: StageXL1BaselineCapture reads outstanding until the capture is taken, which is the truth. 2. Fifteen claims of v2.test.claim.declaring_identity_spelling.production_ingest were COMPLETED-OVER-COST-REQUIREMENT (130k-430k eval steps against the new-witness budget): each re-derived its own fixture parse-and-normalize per claim frame (shared_precondition_re_derived_once_per_claim_frame; #11210 was stacked so its own floor never ran). The eight fixture reads are now one PreparedEffectInput (xl3_fixture_reads) and the per-fixture censuses one CarriedInputWarmRow over it (xl3_fixture_censuses, ImplicitAcquisition); each claim is a field read of that value, each fixture is STILL its own single-file ingest, so nothing a claim measures changed. ingest_of and two_module_ingest are deleted (no consumer). Executed locally (branch seed claim_batch, scoped): legacy_baseline_capture 13/13, legacy_repair_tap_live_bridge 3/3, long/xl1_live_tap_observed_arm 2/2, compiler_frontend_program_status 39/39, declaring_identity_spelling/production_ingest 16/16, floor_prepared_effect_input_ladder 7/7, floor/pure_producer_share_refusal 13/13. claim_batch does not perform warm enrolment, so the XL-3 per-claim budget is proven by the floor run, not by these figures. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
… long-home witness once); file the over-prohibition class Floor run 35079253040 on b080baa: the two Observed-arm controls, moved to test.claim.long, were still planned - the required floor overrides the long-home withhold for a CHANGED witness to establish its verdict (withhold-overridden-for-changed-verdict) - and refused again in microseconds at the tap's whole-corpus admission gate. So no enrolment of the Observed arm can be green on the required route while that gate stands, and an enrolled claim that can only fail there is coverage-by-illusion in the other direction. The controls are withdrawn from the tree. legacy_baseline_capture_capability keeps the honest CaptureBlocked, its evidence_route now naming the census entry (xl1_live_repair_tap_census over a committed root) on a session host or the one-time capture run, and the class is filed as gunbc.recurring_failure_mode.a_gate_sized_for_the_largest_subject_refuses_every_smaller_one: an admission sized for the largest subject applied to every subject (DESIGN 4d second arm), rung mitigatable, ceiling structurally guaranteed by a subject-sized admission, trigger = that admission landing in memory_governor (self-host lane), at which point the controls return. The capability witness asserts the blocked report against the new route text. legacy_baseline_capture 13/13, legacy_repair_tap_live_bridge 3/3, compiler_frontend_program_status 39/39; the ledger row evaluates. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…t dropped (review 66859) review 66859 read reference_edges_for_located_root_sites' Absent arm as a silent zero-edge answer for a root the pool cannot name. It is not: the pool omits a path from qn_by_path exactly when qualified_name_from_module_node rejects the root, and the collector's module_reference_sites rejects on the same call and snocs the root into unreadable_roots at its locus - one predicate, two consumers - so the fold is non-total and the production Outcome refuses. Counting the root again in the lens (tried first) doubled the roster and turned the existing bare-Atom witness red. What was missing was the executed evidence for the Conj shape the review described: added a_headerless_module_root_is_counted_unreadable_not_zero_edges (a Conj root with a body and no header edges, beside a readable provider) asserting the fold is non-total with exactly one unreadable root; the arm's annotation now names both witnesses. reference_derived_graph_witness 6/6, production_ingest 16/16, call_arg_tree 9/9. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
… 66866) xl1_primary_root_cut_subjects was a second name for subjects_deleted_at(stage: StageXL6AtomicCutover) that nothing on the capture path consumed, and its only caller asserted `any(_ => true)` - a witness that a declaration exists (DESIGN 3c's tell) staying green for any non-empty XL-6 list. The join it named (the capture subject bound to the namespace_cut_subject_roster) is deliberately unmade - the frontier is stated on #11201's carrier, not here - so the alias and the witness come out, with their two imports. Tap witnesses 4/4 and 3/3. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ate to .dag files) Conflict resolution: lib.rs and emitted_population.rs are main plus this branch's gunbc_reference_derived_candidate rows; the 66 TargetChanged admissions previously carried in NAMESPACE_TRANSITION_ADMISSIONS are re-authored as one .dag row each under dag/gunbc/namespace/transition_admission/ (gunbc.namespace.transition_admission, per #11250) with owner_pull_request 11461 and deletion_follow_up PullRequest 11466; v1_compiler_emit_rust.rs and v1_compiler_infer_patterns.rs are the adjudicated regen candidates from a seed built at origin/main, re-verified at first_generation_equal=true with this branch's own seed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ot a persisted artifact (review 66891) ObservedArmUnexercisedOnRequiredRoute.restoring_receipt now names the next-rung trigger of a_gate_sized_for_the_largest_subject_refuses_every_smaller_one (subject-sized compile admission, sufficient for the Observed-arm controls to answer on the required floor); a PersistedLegacyBaseline is the XL-1 stage's receipt and is stated as such. One retirement condition per block. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ted compiler can parse the stage The v2 grammar realization admits no modifier between a type name and its field block, so `sole_constructor` left tokens unconsumed on the native route (srv2 pair on 1cc0117: parse_g0_tokens_remain). The pair carries no invariant beyond its fields; the modifier bought nothing here. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
floor_pure_producer_share: main's removal of the live-deploy warm rows kept; the XL-3/XL-4 warm-row annotations follow it. Mirrors at first_generation_equal=true against a seed built at origin/main fc8109e. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ap (review 67039) Both the PrimaryRoot arm of compile_emission and compile_xl1_primary_root_tap now consume compile_clean_pipeline_options_for_sources, the helper the required floor already reads; the two hand copies (which had drifted from it in sort order) are deleted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…mbol_eq (review 67052)
reference_deps, fn_index_depth_agreement, fn_index, resolution_provenance and
bootstrap each carried `fn …(a: Symbol, b: Symbol) -> Bool { a == b }`; one
authority now, owned by the module that owns Symbol.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…fold and the gate (review 67072) QnSpineRole / qn_spine_role own which edge labels form the head/tail spine; qn_fold_step dispatches on the role and qualified_name_spine_shape_present gates on it, so neither re-spells the set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…oor: IMPORT-MEMBER-ABSENT after the 67052 cutover) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ssion reaches the XL-1 tap) Conflict resolution: the compile transaction's PrimaryRoot | RootDemandMeasurement arm consumes primary_root_subject_closure (one derivation, both root subjects). The XL-1 tap now receives the root demand declaration from its .dag caller (repository + measured demand projection path, the same two facts gunbc compile takes on argv) and asks the same per-root admission as the transaction; on a session host the fixture root refuses WholeCorpusCompileUnmeasuredRoot, recorded on a_gate_sized_for_the_largest_subject_refuses_every_smaller_one. Mirrors regenerated (04_method.dag signature) and re-verified at first_generation_equal=true; dispatch table healed via main_wet. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
… fixture root (review 67146) The XL-4 fixture root with dag/std as its pool is measured by gunbc measure-root-demand and its row authored (whole_corpus_compile_xl1_fixture_root_demand, replayed through measured_for_root_from_receipt by a witness), the demand projection regenerated; the two Observed-arm controls return to legacy_repair_tap_live_bridge_witness_test over that root, served from one prepared effect input (xl1_fixture_root_tap) so no claim pays the compile; xl1_live_repair_tap_census_of folds a tap value. The symbol_eq cutover in reference_deps gets its transition admission row (floor: one unadmitted TargetChanged on c0ae8f9). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…ailable on the floor's receipt Deletes gunbc#11440's four consumed admission rows (the roster's next touch owes them; floor run 35181521483). The Observed arm executed on the required floor in that run (prepared-effect-input-acquire xl1_fixture_root_tap disposition=Xl1PrimaryRootObserved, both controls green), so legacy_baseline_capture_capability reports CaptureAvailable, the retired block variant ObservedArmUnexercisedOnRequiredRoute is deleted, its witness turns into the permanent regression control, and the failure-mode row records the retirement for this producer. Mirrors at first_generation_equal=true against a seed at origin/main 3774101. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
…and residual trigger stated as one state (review 67198) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013k9hjAXuaD1HiC1yzd4wnC
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Auto-opened by session-dashboard for session
swift-bat-902.Pushing to
integration/namespace-xladvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan