Skip to content

docs/compiler: retire pipeline include_str side channel - #1171

Merged
briansrls merged 19 commits into
mainfrom
session/quick-heron-61
Apr 29, 2026
Merged

briansrls merged 19 commits into
mainfrom
session/quick-heron-61

Conversation

@briansrls

@briansrls briansrls commented Apr 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary\n\n- removes the pipeline_authority compile-time source embed / source-text reconciliation path\n- makes runtime pipeline stage order depend on PipelineStageBinding declaration order only\n- documents the remaining DB-16 case 2c bridge: compile remains ArrowBody::Unparsed, with compile-body drift reconciliation suspended until a structural witness or single authored carrier exists\n\n## Notes\n\nThis intentionally does not replace include_str! with a runtime pipeline.dag file read. The residual compile-body-vs-binding alignment is review/regen discipline until derivation provides a structural carrier.

@briansrls

Copy link
Copy Markdown
Contributor Author

Manager review: this does not yet satisfy the bridge-retirement dispatch.

The PR removes include_str!("../pipeline.dag"), but replaces it with std::fs::read_to_string(CARGO_MANIFEST_DIR/pipeline.dag) plus slicing by the ArrowBody::Unparsed byte span. That is still a source-text side channel for source-substrate identity; it moves the bridge from compile-time embedding to runtime file IO. The R3 gate says bridge_include_str_side_channels_retired means no macro reads source-substrate identity and the substrate query surface is used instead. The dispatch also explicitly said not to replace the source side channel with another string/source side channel.

Please revise in one of two directions:

  1. Implement the structural path: derive the compile-body stage list from the lowered Dag representation of the compile body or another declared substrate authority, with no source-file read/slicing path.
  2. If the current substrate cannot expose the compile body structurally yet, do not land a pseudo-retirement. Instead, change the PR to a narrow blocker/disposition artifact that proves why ArrowBody::Unparsed prevents retirement today and names the required substrate dependency. In that case the test should not claim pipeline_authority.rs bridge is retired just because include_str! is absent.

Also, the current ratchet !source.contains("include_str!") is too broad and too shallow: too broad because future unrelated uses in this file would fail, and too shallow because this exact PR still has the side channel via read_to_string. The acceptance test needs to assert the structural authority, not just the absence of one macro spelling.

— sent from cool-stag-230

@briansrls

Copy link
Copy Markdown
Contributor Author

Manager follow-up: this revision addresses the substantive concern. The PR no longer replaces include_str! with runtime file IO; it removes compile-body source-text reconciliation from the runtime path and records case 2c as suspended until a structural compile-body witness / single-carrier derivation exists. That is an honest partial bridge-retirement disposition rather than a pseudo-retirement.

Two cleanup requests before this is ready:

  1. Update the PR title/body from the dashboard placeholder (quick-heron-61) to the actual scope, e.g. Retire pipeline_authority include_str side channel with a summary that this suspends compile-body drift reconciliation pending structural witness.
  2. When you are ready for CI/review, mark the PR ready. It is currently draft, so GitHub checks are skipped even though you ran the relevant local commands.

— sent from cool-stag-230

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a6002d24 · Trigger: schedule
  • Thinking: 178s wall

Non-blocking — Strengths

  • src/v3/compiler/src/pipeline_authority.rs Removing the source-text reconcile leaves runtime stage order on PipelineStageBinding declaration order only, with the remaining compile-body drift risk documented and bounded.

ROADMAP — Verified

  • case 2c bridge suspension: The roadmap/history/design rows consistently bound the suspended compile-body reconcile to DB-16 case 2c and name the structural-witness or single-carrier dissolution trigger.

✅ No blocking concerns; this is a clean trade of an invalid source-text side channel for a tracked bridge.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 36930101 · Trigger: schedule
  • Thinking: 157s wall

BLOCKING (1)

Root Cause

  • src/v3/compiler/src/pipeline_authority.rs test-only assertion pulled a test-only type into the production import set → import ArrowBody under #[cfg(test)] or qualify it inside the test.

Non-blocking — Strengths

  • src/v3/compiler/src/pipeline_authority.rs The source-text reconcile removal is documented as a bounded case 2c bridge instead of replacing include_str! with another source-text side channel.

ROADMAP — Verified

  • case 2c bridge suspension: The roadmap/history/R3 updates name the suspended compile-body reconcile and carry the dissolution trigger as a single authored carrier or structural compile-body witness.

⚠️ One small compile-cleanliness issue blocks the PR under the repo’s warnings-as-errors gates.

use crate::dag::{Dag, DeclarationId, FieldValue, TypeConnective, ValueBody};
use crate::parse::{self, SurfaceItem};
use crate::tokenize;
use crate::dag::{ArrowBody, Dag, DeclarationId, FieldValue, TypeConnective, ValueBody};

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: C-8 fail-closed compilation: ArrowBody is imported in the production module but only used by the added test, so non-test RUSTFLAGS=-D warnings builds will reject it as an unused import; move the import into the test module.

@briansrls briansrls changed the title quick-heron-61 docs/compiler: retire pipeline include_str side channel Apr 29, 2026
@briansrls
briansrls marked this pull request as ready for review April 29, 2026 05:24
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 2fde8a58 · Trigger: schedule
  • Comparison: origin/main @ 8a41cbcb ... review/pr-1171-2fde8a58 @ 2fde8a58
  • Thinking: 50s wall

Verdict: APPROVE — retires the include_str! + body-text-slice side channel from pipeline_authority.rs, drops reconcile_with_compile_body, and consistently updates ROADMAP, db-history, scheduled-deletions, design-emission-model, design-fn-external-body-reconciliation, r3-structure, and the dag.rs doc comment. The substituted test (ordered_pipeline_stages_authority_is_pipeline_stage_binding_only + pipeline_compile_body_remains_unparsed_blocking_structural_retirement) ratchets the binding-only authority and the persistent Unparsed shape for compile. Suspension is documented, bounded, and has a named dissolution trigger (derivation / lowered structural compile-body witness) — tracked debt, not silent regression. R3 bridge_include_str_side_changes_retired open disposition is recorded at docs/r3-structure.md:82. No findings.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: 1b5da14b · Trigger: schedule
  • Comparison: origin/main @ 8a41cbcb ... review/pr-1171-1b5da14b @ 1b5da14b
  • Thinking: 84s wall

Verdict: APPROVE

This is a doc-heavy, intentionally narrow change: it deletes reconcile_with_compile_body plus compile_body_stage_names_from_source (and the include_str!/tokenize/parse imports they needed) in pipeline_authority.rs, and propagates the disposition across ROADMAP / DB-14/16/17 / r3-structure / design-emission-model / design-fn-external-body-reconciliation / scheduled-deletions / dag.rs doc-comments.

The code change matches the documented thesis: pipeline runtime ordering remains structural via PipelineStageBinding declaration order; the compile body's prior fail-closed cross-check used include_str!("../pipeline.dag") and a body-span text slice, which R3 bridge_include_str_side_channels_retired (docs/r3-structure.md:82) rejects. Suspending the reconcile rather than swapping in read_to_string is the correct call for that lane.

Tracked-debt criteria from the rubric all present:

  • Documented: r3-structure.md:82, scheduled-deletions row 2c, design-fn-external-body-reconciliation.md, ROADMAP P3 row.
  • Bounded: 2c only; case 1 and DB-14 untouched.
  • Named dissolution trigger: derivation collapses two carriers to one, or a lowered structural compile-body witness.

The new test pipeline_compile_body_remains_unparsed_blocking_structural_retirement (pipeline_authority.rs:~397) is a nice anti-regression: it pins the substrate-shape reason this reconcile cannot land yet, so anyone trying to re-add a string-channel reconcile will see why. The other new test ratchets the structural ordering to the literal six-stage list — a compiler-source ratchet, acceptable here since pipeline.dag is bootstrap-fixed.

No findings against the diff.

Exploratory observations (optional):

  • Behavioral regression risk: prior reconcile was the only thing flagging drift between the human-readable compile { parse; lower; … } body and binding declaration order. The diff acknowledges this ("review/regen discipline"), but there is no lightweight in-tree guard — e.g., a hermetic doctest that parses just the body text without include_str! (still a side channel, so likely also rejected), or a CI check that the compile body literal is byte-equal to a regenerated string from binding order. Worth a tracker note that until derivation lands, drift is caught only at human review.
  • The hardcoded stage list in ordered_pipeline_stages_authority_is_pipeline_stage_binding_only is fine, but the comment "update this test when pipeline.dag stage set changes" is itself the kind of textual side-channel discipline this PR is retreating from. Minor; not a finding.

@briansrls
briansrls merged commit 3f1f100 into main Apr 29, 2026
4 checks passed
briansrls added a commit that referenced this pull request Apr 30, 2026
…le (#1237)

Move ArrowBody import and PIPELINE_COMPILE_FN constant into the
#[cfg(test)] mod tests block per #1171 review preference (#1189
follow-up, split from #1192 lower-helper ratchet).

Verified: cargo test -p v3-compiler --lib pipeline_authority
Verified: cargo clippy -p v3-compiler --lib -- -D warnings
Made-with: Cursor
briansrls added a commit that referenced this pull request Apr 30, 2026
Net-position summary listed "3 narrow slices landed (#1014/#1171/#1183/#1192)"
which read as a 3-vs-4 count mismatch. #1171 is the outstanding/suspended
bridge (#bridge_include_str_side_channels_retired open), not a landed slice.
Restate as 2 landed (canonical lens / lower-helper) + 1 outstanding (#1171)
+ 1 R3-deferred + 1 retired, totaling 5 — and reference closure-ledger PR
#1283 which now tracks the include_str row separately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 30, 2026
briansrls added a commit that referenced this pull request Apr 30, 2026
…rement ledger audit (#1282)

* WIP: R3 Verification

* docs(r3): fix Lane 2 grounding-target gate (add Go)

Manager brief Lane 2 gate listed only R2-Grounding-Rust + R2-Grounding-Python
while calling it the "Shape A 3-target grounding precondition." Worker brief
already correctly required all three (Rust + Python + Go). Add Go to manager
gate to match — single-authority discipline per INVARIANTS §P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix bridge-ledger net-position count mismatch

Net-position summary listed "3 narrow slices landed (#1014/#1171/#1183/#1192)"
which read as a 3-vs-4 count mismatch. #1171 is the outstanding/suspended
bridge (#bridge_include_str_side_channels_retired open), not a landed slice.
Restate as 2 landed (canonical lens / lower-helper) + 1 outstanding (#1171)
+ 1 R3-deferred + 1 retired, totaling 5 — and reference closure-ledger PR
#1283 which now tracks the include_str row separately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): reframe TC bundle as absorbed responsibility, not 3rd lane

Manager brief promoted T-FormalGrounding-Verification to a third lane while
the structural authority docs/r3-structure.md L108 names exactly "2 lanes + 1
ledger gate" for Verification scope. That created parallel scope authority
violating INVARIANTS §P2.

Resolved by deferring to r3-structure.md authority: TC1/TC2/TC3 bundle is now
an absorbed cross-cutting responsibility (audit cadence + strict-fire tracking
folded into manager cadence), matching r3-pb-t-fixedpoint-worker.md L181
"ownership moves" wording. TC3 substrate-introduction worker brief, when its
prerequisites land, joins the existing 2-lane scope as a substrate-introduction
sub-task — not a new lane row.

If Director ratifies a third lane in r3-structure.md itself, this brief
updates accordingly; until then 2-lane scope is the authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix L4-vs-L5 categorical-equivalence drift

Lane 1 brief had a dissolution-trigger note claiming L5 cross-target corpus
could absorb per-target L4 receipts. That conflates two categorically
different claims per THESIS.md L179-180: L4 compares emit-target output vs
.dag evaluation (per-target), L5 compares Rust/Python/Go behavior
cross-target. L5 passing does not entail any target matching .dag eval, so
L5 cannot subsume L4.

Replace with honest stability invariant matching upstream PR-D pattern, plus
explicit note that L4 has no current structural dissolution trigger (per
codex BLOCKING f5f63c7: NOT a Lens<C> instance, runtime-corpus by design).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop "this lane" language from absorbed-responsibility brief

TC bundle brief was reframed as absorbed responsibility (not a lane) but
retained "this lane" wording in five places. Replace with "this bundle"
throughout to match the locked 2-lane framing per r3-structure.md L108.

Editorial fix per cursor reviewer optional finding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align acceptance gates with r3-structure.md authority

Lane 1 brief had:
- Slice 3 narrowing L7 to "at least one named law" (weakened the closure bar
  vs r3-structure.md L54 which requires every algebra × every applicable law).
- Single made-up gate name verification_l4_l7_direct_per_target_equivalence_landed
  parallel to the authoritative l4_emit_eval_match + l7_algebraic_laws_witnessed
  pair (single-authority drift per INVARIANTS §P2).

Lane 2 brief similarly used made-up verification_l5_cross_target_consistency_landed
parallel to authoritative l5_cross_target_consistency.

Manager brief acceptance section restated to cite both authority gates for
Lane 1 + L5 authority gate for Lane 2; explicit "partial-coverage early
slices do NOT close the lane" framing.

Slice 3 in Lane 1 now explicitly marked as coverage-seed only with closure
gate referring to full r3-structure.md authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 30, 2026
…1290)

* WIP: R3 Verification

* docs(r3): fix Lane 2 grounding-target gate (add Go)

Manager brief Lane 2 gate listed only R2-Grounding-Rust + R2-Grounding-Python
while calling it the "Shape A 3-target grounding precondition." Worker brief
already correctly required all three (Rust + Python + Go). Add Go to manager
gate to match — single-authority discipline per INVARIANTS §P2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix bridge-ledger net-position count mismatch

Net-position summary listed "3 narrow slices landed (#1014/#1171/#1183/#1192)"
which read as a 3-vs-4 count mismatch. #1171 is the outstanding/suspended
bridge (#bridge_include_str_side_channels_retired open), not a landed slice.
Restate as 2 landed (canonical lens / lower-helper) + 1 outstanding (#1171)
+ 1 R3-deferred + 1 retired, totaling 5 — and reference closure-ledger PR
#1283 which now tracks the include_str row separately.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): reframe TC bundle as absorbed responsibility, not 3rd lane

Manager brief promoted T-FormalGrounding-Verification to a third lane while
the structural authority docs/r3-structure.md L108 names exactly "2 lanes + 1
ledger gate" for Verification scope. That created parallel scope authority
violating INVARIANTS §P2.

Resolved by deferring to r3-structure.md authority: TC1/TC2/TC3 bundle is now
an absorbed cross-cutting responsibility (audit cadence + strict-fire tracking
folded into manager cadence), matching r3-pb-t-fixedpoint-worker.md L181
"ownership moves" wording. TC3 substrate-introduction worker brief, when its
prerequisites land, joins the existing 2-lane scope as a substrate-introduction
sub-task — not a new lane row.

If Director ratifies a third lane in r3-structure.md itself, this brief
updates accordingly; until then 2-lane scope is the authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix L4-vs-L5 categorical-equivalence drift

Lane 1 brief had a dissolution-trigger note claiming L5 cross-target corpus
could absorb per-target L4 receipts. That conflates two categorically
different claims per THESIS.md L179-180: L4 compares emit-target output vs
.dag evaluation (per-target), L5 compares Rust/Python/Go behavior
cross-target. L5 passing does not entail any target matching .dag eval, so
L5 cannot subsume L4.

Replace with honest stability invariant matching upstream PR-D pattern, plus
explicit note that L4 has no current structural dissolution trigger (per
codex BLOCKING f5f63c7: NOT a Lens<C> instance, runtime-corpus by design).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop "this lane" language from absorbed-responsibility brief

TC bundle brief was reframed as absorbed responsibility (not a lane) but
retained "this lane" wording in five places. Replace with "this bundle"
throughout to match the locked 2-lane framing per r3-structure.md L108.

Editorial fix per cursor reviewer optional finding.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align acceptance gates with r3-structure.md authority

Lane 1 brief had:
- Slice 3 narrowing L7 to "at least one named law" (weakened the closure bar
  vs r3-structure.md L54 which requires every algebra × every applicable law).
- Single made-up gate name verification_l4_l7_direct_per_target_equivalence_landed
  parallel to the authoritative l4_emit_eval_match + l7_algebraic_laws_witnessed
  pair (single-authority drift per INVARIANTS §P2).

Lane 2 brief similarly used made-up verification_l5_cross_target_consistency_landed
parallel to authoritative l5_cross_target_consistency.

Manager brief acceptance section restated to cite both authority gates for
Lane 1 + L5 authority gate for Lane 2; explicit "partial-coverage early
slices do NOT close the lane" framing.

Slice 3 in Lane 1 now explicitly marked as coverage-seed only with closure
gate referring to full r3-structure.md authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): unify TC3 strict-fire gate into single two-stage authority

TC3 status table named only substrate-introduction prerequisites under
"Strict-fire gate" while §Acceptance separately required T-FixedPoint
completion for strict-fire. Two competing gate descriptions for one claim
violated single-authority discipline.

Restate as a single two-stage gate:
  (a) substrate-introduction prereqs land tc3_strong_normalization_substrate_introduced
  (b) T-FixedPoint completion fires the full theorem witness

Both stages required; no fire-before-(b) path exists. Stage names match
§Acceptance authority below.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 30, 2026
… fail-closed name field

Codex BLOCKING(3) on PR #1314 sha b5f7dd5:

1. Authority document: external doc anchor was generic. Made
   bridge_ledger.dag the explicit substrate authority for rows; per-row
   'authority' field now points at the concrete ratchet (test, PR, or
   gating doc-anchor) that establishes that row's status, not a generic
   taxonomy heading. Status flips from Open to Retired are gated on the
   named ratchet reaching zero residual:
   - source_span_file_participation -> ROADMAP.md#lens-fold-file-path-semantics
   - mark_bootstrap_secret_nominal_opacity -> PR #937
   - canonical_lens_name_dispatch -> canonical_lens_bridge_ratchet_test.rs
   - include_str_side_channels -> PR #1171
   - exact_string_patching_residual -> bridge_lower_helpers_patch_zero_residual_test.rs

2. Predicate schema typing: TestPredicate::BridgeLedgerZero.ledger now
   typed as BridgeLedgerRef (typed wrapper { decl: DeclarationRef }),
   mirror of MethodRef / CallableRef. Adds bridge_ledger.dag::BridgeLedgerRef
   with the same #1175 substrate-gap dissolution trigger. Runner unwraps
   the record at the predicate boundary.

3. Runner row validation: missing or non-String name field now fails
   closed instead of using a placeholder, even before status partition.
   Defensive at the claim boundary, complementing the carrier ratchet
   that already guards bridge_ledger.dag's substrate-side shape.

10/10 tests pass on the new payload shape: predicate-shape ratchet
updated to require BridgeLedgerRef wrapper (not bare DeclarationRef);
runner tests use BridgeLedgerZero { ledger: { decl: <ref> } } literal
construction; sibling-canonical-shape and wrong-type negative tests
still fire fail-closed.
briansrls added a commit that referenced this pull request May 1, 2026
…edicate + runner (#1314)

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* regen bootstrap after std.effects import path fix

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* regen bootstrap + refresh parse manifest after merge

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* PR-α: wrap Operation.callable in CallableRef (typed wrapper, mirrors MethodRef)

* chore: apply cargo fmt

* doc: align test comments with CallableRef wrapper (cosmetic)

* regen bootstrap after merge main

* T-Substrate-AnthropicSchemaMirror: v3 typed mirror for Anthropic Messages signature

- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
  types reachable from operation Messages signature in
  dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
  AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
  return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
  8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
  type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
  are the next substrate precursor that consumes these types.

* WIP: sharp-raven-604

* chore: apply cargo fmt

* anthropic_schema lockstep: couple expected labels to v2 source + optionality

Manager review on PR #1261: the prior lockstep tests asserted v3 labels
against hard-coded constants and only checked v2 type-name presence. They
would NOT catch v2 source drift on field/variant labels themselves.

This commit:
- Extracts the v2 type-block text via v2_type_block(name).
- assert_lockstep_record / assert_lockstep_disj now verify each expected
  label appears literally in the v2 block, fail-closed on either-side drift.
- New anthropic_optional_fields_remain_optional_in_v2_source asserts the
  '?' suffix on is_error: Bool? and stop_sequence: String? in the v2
  source, with comment explaining structural inspection of v3 optionality
  is deferred to the operation-row precursor (per manager guidance).

* anthropic_schema lockstep: bidirectional set equality + structural optionality

OpenAI-Pro REQUEST_CHANGES on PR #1261: prior ratchet only checked v3 set
== expected and expected ⊆ v2. v2 additions silently passed; v3 optionality
was text-only on the v2 side, not structurally checked on v3.

Strengthened:
- v2_record_fields(name) parses the v2 type block and extracts (label,
  is_optional) tuples directly from the source. v2_disj_variants(name)
  extracts variant labels (including from inline 'A | B | C' and
  multi-line '= Foo {} | Bar {}' shapes).
- assert_record_lockstep / assert_disj_lockstep assert SET EQUALITY
  between v2-extracted set and v3 bootstrap set (BTreeSet diff in the
  failure message names v3-only and v2-only labels).
- Optionality is structural on v3: v3_field_is_optional walks the field
  declaration's TypeConnective and matches Cardinality(AtMostOne, _).
  Each v2 'T?' field must lower optional; each v2 'T' field must NOT.
- New test anthropic_user_content_block_user_tool_result_block_optionality
  reaches the variant payload Conj for UserToolResultBlock and asserts
  is_error: Bool? lowers as Cardinality(AtMostOne, Bool) on the
  inner declaration (variant payloads aren't reached by the
  record-level ratchet).

* chore: apply cargo fmt

* fix clippy: use char array in split (manual char comparison lint)

* WIP: sharp-raven-604

* anthropic_schema lockstep: per-variant payload field+optionality coverage

OpenAI-Pro REQUEST_CHANGES on PR #1261: assert_disj_lockstep compared
only variant labels, leaving variant payload field labels and
optionality unguarded — UserToolResultBlock.content / tool_use_id and
AssistantToolUseBlock.id / name / input could drift between v2 and v3
while the test passed.

This commit:
- v2_disj_variants now returns (label, Option<Vec<(field_label,
  is_optional)>>), parsing variant payload bodies via the same logic
  v2_record_fields uses (extracted as parse_v2_brace_body_fields).
- v3_variant_payload_fields walks the v3 variant target's Conj
  declaration and projects (label, Cardinality(AtMostOne, _)?) tuples.
- assert_disj_lockstep extends to per-variant payload set equality and
  optionality: bare-on-bare passes; record-on-record requires set
  equality + optionality match; mismatched (one-side bare,
  other-side payload) fails closed.
- Drops the redundant special-case is_error optionality test — now
  subsumed by structural per-variant payload coverage on
  AnthropicUserContentBlock.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* anthropic_schema lockstep: type-expression equality (records + variant payloads)

OpenAI-Pro REQUEST_CHANGES on PR #1261 (sha 1e08a24): label + optionality
weren't enough to catch field type drift — content: List<X> could become
content: String while tests stayed green.

Adds:
- v3_canonical_ty(dag, ty): walks declarations to produce a canonical
  type-expression string. Named decls (String, Bool, AnthropicStopReason,
  AnthropicMessages200TextBlock, …) canonicalize as their surface name
  even though their underlying connective unfolds to Instantiation
  (e.g. String = FreeMonoid<Int>). Anonymous Instantiation sites
  (List<X>, Map<K, V>) and Cardinality(AtMostOne, T) get unfolded.
- normalize_ty_text(raw): strips trailing '?' and compresses internal
  whitespace so v2 source text matches v3 canonical form.
- v2_record_fields and parse_v2_brace_body_fields now return
  (label, normalized_ty_text, is_optional); v3_variant_payload_fields
  returns (label, canonical_ty, is_optional).
- assert_record_lockstep and assert_disj_lockstep added type-expression
  equality assertions in addition to label-set equality and optionality.
  Optionality is checked separately, so the type comparison strips
  the trailing '?' on both sides and compares inner-element forms only.

Coverage: every mirrored field across AnthropicChatMessage,
AnthropicUserContentBlock (incl. UserToolResultBlock.content/tool_use_id),
AnthropicAssistantContentBlock (incl. AssistantToolUseBlock.input: Json),
AnthropicMessages200TextBlock, AnthropicMessages200Usage (input_tokens: Int),
and AnthropicMessages200Body (content: List<...>, stop_sequence: String?)
now fails closed if v2 carrier type changes.

* anthropic_schema lockstep: also reject Arrow declarations (fn leak guard)

Codex non-blocking improvement on PR #1261: prior anthropic_schema_authors_no_data_rows
test rejected only declarations with value_body: Some(...), so a future
fn anthropic_messages would lower as TypeConnective::Arrow with
value_body: None and bypass the guard. Renamed to ..._or_fns and
extended the filter to also reject TypeConnective::Arrow declarations
authored in src/v3/std/anthropic_schema.dag.

* chore: apply cargo fmt

* T-Substrate-AnthropicMessagesCallable: fn anthropic_messages declaration

Service-operation callable declaration precursor for the Anthropic
Messages REST operation, the substrate slice Grounding PR-β #1252 is
waiting on per parent #1130 dispatch.

Adds:
- src/v3/std/anthropic_messages.dag: top-level fn anthropic_messages
  with honest signature consuming v3.std.anthropic_schema mirror types
  (#1261). Returns AnthropicMessages200Body. host body lowers as
  ArrowBody::Unparsed (no producerless realization carrier minted).
- src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:
  5 ratchets — Arrow shape, parameter type list matches v2 source via
  v3 mirror, return type is AnthropicMessages200Body, callable is
  acceptable as Operation.callable.decl target, no Operation/data rows
  leak (those are PR-β scope).

Two intentional simplifications vs v2 (documented in file header):
- max_tokens: Int (v2 'Int = 4096'); v3 has no parameter defaults so
  the default is a caller-side fold, not a v3 contract change.
- Return is the 200 body only; AnthropicErrorShape is PR-β response/
  wire lockstep concern.

Out of scope: anthropic_operations: List<Operation> data row, sibling
binding/realization data rows. Grounding owns those.

* chore: apply cargo fmt

* chore: restore comment/test adjacency in SG-0 census (cosmetic)

Reviewer (claude opus 4.7) non-blocking exploratory observation on PR
#1266: the alphabetical insertion of anthropic_messages_callable_test.rs
and anthropic_schema_lockstep_test.rs split the PB Tier-2 #1014 comment
block from the test it describes. Moving the comment two lines down
restores adjacency. No behavior change.

* anthropic_messages: pin Unparsed body + correct file header prose

OpenAI-Pro REQUEST_CHANGES on PR #1266: the file header claimed 'host
anthropic_messages' lowers to ArrowBody::ExternalRealization, but the
generated substrate has ArrowBody::Unparsed(span). Prose did not match
the substrate fact, and no test pinned the body class so a silent
rewrite was invisible.

Fixes:
- File header rewritten to honestly describe the actual lowered state:
  body remains Unparsed because the pipeline-stage post-processing
  patch in bootstrap.rs:256 is pipeline-specific and does not fire
  for service-operation callables. The patch is intentionally not
  added (would require a producerless CompilerHostRealization-style
  data row, the parallel surface the #1130 dispatch rejects).
- New ratchet anthropic_messages_body_is_unparsed pins
  ArrowBody::Unparsed; a silent rewrite to ExternalRealization /
  UserDefined / Pending / NoBody fails closed.
- File header explicitly bounds the unparsed-body state to the same
  dissolution trigger as the schema mirror.

* regen bootstrap: re-sync byte spans after anthropic_messages.dag header rewrite

* T-Verification-BridgeLedger: substrate carrier for bridge-retirement ledger

Adds:
- src/v3/std/bridge_ledger.dag: substrate authority for the bridge-
  retirement ledger Verification's BridgeLedgerZero TestClaim folds.
  - BridgeStatus = Retired | Open (closed two-variant coproduct;
    structural partition, no stringly status).
  - BridgeLedgerRow { name, owner, status, authority } per dispatch
    contract.
  - data bridge_ledger: List<BridgeLedgerRow> = [...] populates the
    five canonical bridge rows from docs/r3-structure.md:79-83.
  - Per-row status rationale documented in file header: source-span-
    file-participation Open, mark-bootstrap-secret-nominal-opacity
    Retired, canonical-lens-name-dispatch Retired, include-str-side-
    channels Open, exact-string-patching-residual Open.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  6 ratchets — BridgeLedgerRow field set, BridgeStatus closed two-
  variant coproduct, bridge_ledger lowers as List<BridgeLedgerRow>,
  five canonical names in document order, name uniqueness, status
  field resolves structurally to a BridgeStatus constructor (not a
  string).
- bootstrap regen + parse manifest refresh + integration mod entry +
  SG-0 census entry.

Single substrate authority — no parallel Rust Vec, no test-side
ledger table. Verification's BridgeLedgerZero fold is out of scope
for this PR per dispatch.

* regen bootstrap + manifest after merging origin/main

* T-Verification-BridgeLedger: predicate variant + runner branch (Director scope extension)

Per parent #1130 dispatch (#4356094666) extending #1314: substrate
authority for BridgeLedgerZero gate, not just the carrier.

Adds:
- src/v3/std/verification.dag: TestPredicate variant
  BridgeLedgerZero { ledger: DeclarationRef }. Single payload field
  preserves typed-edge discipline; structural identity, not stringly
  ledger reference.
- src/v3/compiler/src/test_runner.rs: eval_bridge_ledger_zero branch.
  Resolves the ledger DeclarationRef, walks ValueBody::List rows,
  reads each row's status Variant, partitions by structural
  comparison against BridgeStatus::Retired's variant id (not by
  name). Returns Pass iff every row is Retired; Fail names the
  open rows in declaration order.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  Two new tests:
  - bridge_ledger_zero_predicate_carries_only_ledger_declaration_ref:
    pins the variant's payload set to {ledger} and asserts ledger's
    type is DeclarationRef from v3.spec.v3_l1.
  - bridge_ledger_zero_runner_fails_with_named_open_rows_at_head:
    compiles a TestClaim referencing the ledger via DeclarationRef
    and runs it through TestRunner. At HEAD with three Open rows
    (source_span_file_participation, include_str_side_channels,
    exact_string_patching_residual), expects Fail with all three
    named and the two Retired rows excluded. Re-arms as Pass once
    all five flip to Retired.
- bootstrap regen + parse manifest refresh.

8/8 tests pass; clippy clean. Verification's #1310 can now author the
.dag TestClaim consuming this predicate.

* chore: apply cargo fmt

* doc: bridge_ledger comment cites correct canonical-lens ratchet test (cosmetic)

Reviewer (cursor) NON-BLOCKING finding on PR #1314: per-row rationale for
bridge_canonical_lens_name_dispatch_retired cited
bridge_lower_helpers_patch_zero_residual_test (lower-helper exact-string
patch lane) instead of the canonical-lens-name-dispatch ratchet at
canonical_lens_bridge_ratchet_test.rs. Comment text only; bootstrap +
manifest re-synced for the byte-span shift.

* WIP: sharp-raven-604

* eval_bridge_ledger_zero: enforce canonical ledger identity (single-authority)

Codex REQUEST_CHANGES on PR #1314: the previous type-check accepted any
List<BridgeLedgerRow> declaration, so a sibling list could become a
parallel ledger authority and pass the gate independently of the
canonical bridge_ledger. INVARIANTS P2 / single-authority violation.

Adds:
- Canonical-identity check before the type-check guard: the resolved
  ledger DeclarationId must match dag.declaration_by_name('bridge_ledger').id.
  Sibling List<BridgeLedgerRow> declarations fail closed with a
  diagnostic naming the canonical authority. Type-check stays as
  defense-in-depth (catches a future carrier-shape drift).
- New test bridge_ledger_zero_runner_fails_closed_on_sibling_canonical_
  shape_ledger: compiles a sibling 'data sibling_ledger:
  List<BridgeLedgerRow> = []' and asserts BridgeLedgerZero fails
  closed because the declaration identity isn't the canonical one
  (even though the type IS compatible).
- Existing wrong-type test updated: identity check fires first for
  any non-canonical ledger, so the assertion now expects the
  canonical-identity diagnostic.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* BridgeLedgerZero: tighten payload typing, per-row authority pointers, fail-closed name field

Codex BLOCKING(3) on PR #1314 sha b5f7dd5:

1. Authority document: external doc anchor was generic. Made
   bridge_ledger.dag the explicit substrate authority for rows; per-row
   'authority' field now points at the concrete ratchet (test, PR, or
   gating doc-anchor) that establishes that row's status, not a generic
   taxonomy heading. Status flips from Open to Retired are gated on the
   named ratchet reaching zero residual:
   - source_span_file_participation -> ROADMAP.md#lens-fold-file-path-semantics
   - mark_bootstrap_secret_nominal_opacity -> PR #937
   - canonical_lens_name_dispatch -> canonical_lens_bridge_ratchet_test.rs
   - include_str_side_channels -> PR #1171
   - exact_string_patching_residual -> bridge_lower_helpers_patch_zero_residual_test.rs

2. Predicate schema typing: TestPredicate::BridgeLedgerZero.ledger now
   typed as BridgeLedgerRef (typed wrapper { decl: DeclarationRef }),
   mirror of MethodRef / CallableRef. Adds bridge_ledger.dag::BridgeLedgerRef
   with the same #1175 substrate-gap dissolution trigger. Runner unwraps
   the record at the predicate boundary.

3. Runner row validation: missing or non-String name field now fails
   closed instead of using a placeholder, even before status partition.
   Defensive at the claim boundary, complementing the carrier ratchet
   that already guards bridge_ledger.dag's substrate-side shape.

10/10 tests pass on the new payload shape: predicate-shape ratchet
updated to require BridgeLedgerRef wrapper (not bare DeclarationRef);
runner tests use BridgeLedgerZero { ledger: { decl: <ref> } } literal
construction; sibling-canonical-shape and wrong-type negative tests
still fire fail-closed.

* verification ratchet: include BridgeLedgerZero variant after main rebase

m1_5_verification_test::bootstrap_loads_verification_authority_types
expected variant list still ended at SubstrateResearchDeferredClaim;
appended ('BridgeLedgerZero', vec!['ledger']) to match the live
bootstrap. Bootstrap+manifest re-synced from the post-merge regen.
10/10 bridge_ledger_carrier tests + 1/1 verification ratchet pass.

* doc: align eval_bridge_ledger_zero rustdoc with BridgeLedgerRef payload (cosmetic)

Reviewer (cursor) NON-BLOCKING on PR #1314: rustdoc on
eval_bridge_ledger_zero still described the predicate as
{ ledger: DeclarationRef } even though the substrate surface (and the
implementation) now requires the BridgeLedgerRef { decl: DeclarationRef }
wrapper. INVARIANTS 'documentation describes live state' alignment.
Comment-only; no behavior change; .rs file edit so no bootstrap regen
needed.

* bridge_ledger tests: derive row set + open/retired partition from live ledger (single-authority)

Codex BLOCKING on PR #1314: CANONICAL_BRIDGES + expected_open/retired
arrays copied the ledger row set and status partition into Rust,
creating exactly the test-side parallel table bridge_ledger.dag rules
out (single-authority / M7).

- Removed the CANONICAL_BRIDGES const and the
  bridge_ledger_carries_canonical_five_names_in_doc_order test (the
  test re-asserted ledger content from a hardcoded copy; row content
  authority lives only in bridge_ledger.dag).
- bridge_ledger_lowers_as_list_with_at_least_one_row replaces the
  earlier exact-five-rows assertion: pins the structural shape
  (List value_body, every entry a Record, non-empty) without
  duplicating the row count.
- bridge_ledger_zero_runner_fails_with_named_open_rows_at_head no
  longer hardcodes expected_open_rows / expected_retired_rows. It
  reads the live ledger from the bootstrap, partitions by structural
  comparison against BridgeStatus::Retired's variant id, and asserts:
  every Open row's name appears in the failure diagnostic and every
  Retired row's name does not. Re-arms automatically as upstream rows
  flip status — the test does not need an update each time.

9/9 tests pass; clippy clean. The only authority for ledger row
content is now src/v3/std/bridge_ledger.dag.

* bridge_ledger: repoint umbrella row authority at open-scope prose, not closed sub-slice ratchet

OpenAI-Pro REQUEST_CHANGES on PR #1314: the
bridge_exact_string_patching_residual_retired row's authority pointed
at bridge_lower_helpers_patch_zero_residual_test.rs, the receipt for
the RETIRED lower-helper sub-slice (#1014). The row stays Open because
*other* exact-string patching classes remain outside that receipt's
scope, so the closed-slice test was misleading as the row's authority.

Repointed authority at docs/r3-structure.md:83 — the prose row where
the umbrella's open-scope framing ('Other exact-string patching classes
... keep their own dissolution triggers') is defined. Each 'other class'
has its own trigger; the umbrella row retires when those triggers all
fire. Per-row inline comment in bridge_ledger.dag explains the
distinction.

* WIP: sharp-raven-604

* regen bootstrap + manifest after main rebase (clean conflicts)
briansrls added a commit that referenced this pull request May 6, 2026
- Add r3-pb-bridge-include-str-side-channels-closure.md (pipeline_authority /
  #1171 lineage; dispatch triggers + STOP; no runtime file-IO swap).
- Register in r2-pure-bootstrap-manager authored list; narrow pending bridge row.

PB Mgr cycle #1861 / #846 pre-auth queue execution.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 6, 2026
- Add r3-pb-bridge-include-str-side-channels-closure.md (pipeline_authority /
  #1171 lineage; dispatch triggers + STOP; no runtime file-IO swap).
- Register in r2-pure-bootstrap-manager authored list; narrow pending bridge row.

PB Mgr cycle #1861 / #846 pre-auth queue execution.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 7, 2026
…1918)

* docs(briefs): pre-author bridge #4 include_str closure worker brief

- Add r3-pb-bridge-include-str-side-channels-closure.md (pipeline_authority /
  #1171 lineage; dispatch triggers + STOP; no runtime file-IO swap).
- Register in r2-pure-bootstrap-manager authored list; narrow pending bridge row.

PB Mgr cycle #1861 / #846 pre-auth queue execution.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(briefs): bridge #3 canonical lens closure brief + manager index

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 10, 2026
Reconciles r3-structure acceptance bullet with bridge_ledger.dag: the row is
Retired for the pipeline.dag authority path ratcheted in l1_5_fixed_point_test;
PR #1171 compile-body witness debt is framed as follow-on work, not an Open
ledger status (addresses composer-2 exploratory review on #2487).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 10, 2026
Reconciles r3-structure acceptance bullet with bridge_ledger.dag: the row is
Retired for the pipeline.dag authority path ratcheted in l1_5_fixed_point_test;
PR #1171 compile-body witness debt is framed as follow-on work, not an Open
ledger status (addresses composer-2 exploratory review on #2487).

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 10, 2026
…wer-helper slice) (#2487)

* feat(r3): retire gate #35 exact-string lower-helper bridge ledger row

Split the former umbrella: bridge_exact_string_patching_residual_retired is
Retired at the PB Tier-2 lower-helper slice (ratchet in
bridge_lower_helpers_patch_zero_residual_test.rs). Row-4 semantic
exact-string patching outside that slice is tracked as
bridge_exact_string_semantic_patching_residual (Open).

Regenerate bootstrap snapshots and parse_corpus_manifest.txt. Update
r3-structure, program plan gate #35, and verification bridge audit briefs.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(r3): align bridge_include_str prose with ledger Retired slice

Reconciles r3-structure acceptance bullet with bridge_ledger.dag: the row is
Retired for the pipeline.dag authority path ratcheted in l1_5_fixed_point_test;
PR #1171 compile-body witness debt is framed as follow-on work, not an Open
ledger status (addresses composer-2 exploratory review on #2487).

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(v3): align bridge ledger-zero audit with live canonical-lens Retired rows

- Fix summary + row table + routing: bridge_canonical_lens_name_patching_residual
  is Retired in bridge_ledger.dag (not Open); only source-span + exact-string
  semantic rows are Open at HEAD.
- Tighten EXPECTED_OPEN_BOUND to 2 (live open-row count).

Addresses cursor/composer-2 REQUEST_CHANGES on #2487 and codex doc/authority drift.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant