diff --git a/ROADMAP.md b/ROADMAP.md index e4d64cdb7ac..f67d1306a8a 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -10,7 +10,7 @@ Parked context (non-dispatchable): [compiler algorithm survey](docs/plans/compil The graph has sixteen lanes: SCM compatibility · namespace · P-derive · observation · placement · compute · CI cost · CI control · generated artefacts · v1 exit (four finish lines: compiler fixed point, interpreter deleted, products v1-free, zero hand-maintained Rust) · shell · roadmap runtime · fleet/hygiene · judgment · hermetic toolchain · compiler-guarantee (the DESIGN §4b ladder climbs; rung STATE lives in the guarantee claims carrier and is emitted, never restated in tickets — [gap analysis](docs/plans/compiler-guarantee-recovery-gap-analysis.md)). The three independent SCM R0 models, the separate P−1 evidence carrier, R1 compatibility-shape extraction, and P0 user-contract/landing spine are accepted; the operator-authored P1 proof-kernel node is active and fail-closed pending its first discriminating closing validation, while P2 and later product lanes remain parked. The toolchain pin model is an independent root. The P-derive receipt feeds the emitter fixed point, so the v1 chain nests under it. Compute owns the one contract everything else asks for work through — an exact subject in, a typed ending and the outputs it promised back out — and it sits ABOVE CI rather than inside it, because owning CI, converging the fleet, serving models and eventually judging changes are four consumers of one fabric, not four execution systems. It grounds on the signed realization spine rather than minting a second scheduler beside it. CI control owns who starts, queues and hands out required work and how its result reaches GitHub; CI cost owns how much computation that work performs. Fleet owns whether a merge to main becomes applied machine state and whether that question has one answer. Node fields define boundary, first slice, RED control, exclusions, owner, and handback. -**Focused view — the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main + the harness, roadmap workflow and dashboard lanes.** 132 active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap/roadmap_authority.dag` to restore the full page. 11 of the rows below are NOT lane deliverables — they are prerequisites pulled in from other lanes because lane work is blocked on them: commit-writer-admission, shell-gate-migration, shell-effectplan-to-bash, shell-typed-invocation, placement-compile-pool-envelope, placement-live-roster-preflight, observation-scoped-run-consumer, observation-scoped-run-seed-growth-justification, observation-scoped-run-seed-growth-justification-closing-contract, fleet-spark-host-enrollment, confidence-semantic-impact-query. Hidden lanes remain readable through their carriers: [docs/plans/namespace-cut-replacement-plan.md](docs/plans/namespace-cut-replacement-plan.md) · [docs/plans/dag-scm-design.md](docs/plans/dag-scm-design.md) · [docs/plans/native-scm-cas-fit-and-consumer-cut.md](docs/plans/native-scm-cas-fit-and-consumer-cut.md) · [docs/plans/namespace-unique-on-chain-operational-plan.md](docs/plans/namespace-unique-on-chain-operational-plan.md) · [docs/plans/v2-self-hosting.md](docs/plans/v2-self-hosting.md) · [src/v2/compiler/05_emit.dag](src/v2/compiler/05_emit.dag) · [docs/plans/progress-observation-design.md](docs/plans/progress-observation-design.md) · [src/v2/compiler/self_host/candidate_generation.dag](src/v2/compiler/self_host/candidate_generation.dag) · [src/v2/compiler/self_host/stage0_production_target.dag](src/v2/compiler/self_host/stage0_production_target.dag) · [src/v2/compiler/self_host/wet_receipt_enrollment.dag](src/v2/compiler/self_host/wet_receipt_enrollment.dag) · [src/v2/workflow/rust_crate_partition.dag](src/v2/workflow/rust_crate_partition.dag) · [src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag](src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag) · [dag/gunbc/v1/v1_deletion_plan.dag](dag/gunbc/v1/v1_deletion_plan.dag) · [dag/gunbc/stage0/stage0_rust_host_observation.dag](dag/gunbc/stage0/stage0_rust_host_observation.dag) · [docs/plans/witness-realization-plan.md](docs/plans/witness-realization-plan.md) · [src/v1/05_emit_rust.dag](src/v1/05_emit_rust.dag) · [dag/gunbc/v1/v1_interpreter_primitive_surface.dag](dag/gunbc/v1/v1_interpreter_primitive_surface.dag) · [docs/plans/shell-to-dag-residual-census-and-arc-completion.md](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) · [docs/plans/roadmap-workspace-ux-plan.md](docs/plans/roadmap-workspace-ux-plan.md) · [docs/plans/hermetic-tool-provisioning-design.md](docs/plans/hermetic-tool-provisioning-design.md) · [dag/gunbc/capability_binding.dag](dag/gunbc/capability_binding.dag) · [dag/gunbc/roadmap/roadmap_component.dag](dag/gunbc/roadmap/roadmap_component.dag) · [dag/gunbc/design_document.dag](dag/gunbc/design_document.dag) · [docs/plans/compiler-guarantee-recovery-gap-analysis.md](docs/plans/compiler-guarantee-recovery-gap-analysis.md) · [docs/plans/cardinality-refinement.md](docs/plans/cardinality-refinement.md) · [dag/gunbc/roadmap/roadmap_authority.dag](dag/gunbc/roadmap/roadmap_authority.dag) · [dag/test/claim/closing/namespace_reference_derived_producer_bounded_closing_contract_witness_test.dag](dag/test/claim/closing/namespace_reference_derived_producer_bounded_closing_contract_witness_test.dag) · [dag/test/claim/closing/2_scm_native_write_spine_acceptance_closing_contract_witness_test.dag](dag/test/claim/closing/2_scm_native_write_spine_acceptance_closing_contract_witness_test.dag) · [dag/test/claim/closing/2_scm_native_authority_program_closing_contract_witness_test.dag](dag/test/claim/closing/2_scm_native_authority_program_closing_contract_witness_test.dag) · [dag/test/claim/closing/namespace_cross_file_provenance_closing_contract_witness_test.dag](dag/test/claim/closing/namespace_cross_file_provenance_closing_contract_witness_test.dag) · [dag/test/claim/closing/v1_materialization_kernel_closing_contract_witness_test.dag](dag/test/claim/closing/v1_materialization_kernel_closing_contract_witness_test.dag) · [dag/test/claim/closing/gate_refusal_reason_survives_wrapper_closing_contract_witness_test.dag](dag/test/claim/closing/gate_refusal_reason_survives_wrapper_closing_contract_witness_test.dag) · [dag/test/claim/closing/toolchain_pin_model_closing_contract_witness_test.dag](dag/test/claim/closing/toolchain_pin_model_closing_contract_witness_test.dag) · [dag/test/claim/closing/instrument_motion_physical_qualification_closing_contract_witness_test.dag](dag/test/claim/closing/instrument_motion_physical_qualification_closing_contract_witness_test.dag) · [dag/test/claim/closing/instrument_rendered_control_coverage_closing_contract_witness_test.dag](dag/test/claim/closing/instrument_rendered_control_coverage_closing_contract_witness_test.dag) · [dag/test/claim/closing/discarded_bool_result_wall_closing_contract_witness_test.dag](dag/test/claim/closing/discarded_bool_result_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/ladder_probe_corpus_closing_contract_witness_test.dag](dag/test/claim/closing/ladder_probe_corpus_closing_contract_witness_test.dag) · [dag/test/claim/closing/method_established_surface_wall_closing_contract_witness_test.dag](dag/test/claim/closing/method_established_surface_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/call_label_and_surplus_wall_closing_contract_witness_test.dag](dag/test/claim/closing/call_label_and_surplus_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/declared_conformance_ground_fragment_closing_contract_witness_test.dag](dag/test/claim/closing/declared_conformance_ground_fragment_closing_contract_witness_test.dag) · [dag/test/claim/closing/v2_self_grounding_frontier_closing_contract_witness_test.dag](dag/test/claim/closing/v2_self_grounding_frontier_closing_contract_witness_test.dag) · [dag/test/claim/closing/interpreter_primitive_roster_closing_contract_witness_test.dag](dag/test/claim/closing/interpreter_primitive_roster_closing_contract_witness_test.dag) · [dag/test/claim/closing/unforgeable_construction_capability_closing_contract_witness_test.dag](dag/test/claim/closing/unforgeable_construction_capability_closing_contract_witness_test.dag). +**Focused view — the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main + the harness, roadmap workflow and dashboard lanes + the primitive-egress wind-down.** 132 active deliverable(s) in other lanes are declared in the authority and hidden here; nothing is deleted or parked by focusing. Clear `roadmap_focus_selection` in `dag/gunbc/roadmap/roadmap_authority.dag` to restore the full page. 11 of the rows below are NOT lane deliverables — they are prerequisites pulled in from other lanes because lane work is blocked on them: commit-writer-admission, shell-gate-migration, shell-effectplan-to-bash, shell-typed-invocation, placement-compile-pool-envelope, placement-live-roster-preflight, observation-scoped-run-consumer, observation-scoped-run-seed-growth-justification, observation-scoped-run-seed-growth-justification-closing-contract, fleet-spark-host-enrollment, confidence-semantic-impact-query. Hidden lanes remain readable through their carriers: [docs/plans/namespace-cut-replacement-plan.md](docs/plans/namespace-cut-replacement-plan.md) · [docs/plans/dag-scm-design.md](docs/plans/dag-scm-design.md) · [docs/plans/native-scm-cas-fit-and-consumer-cut.md](docs/plans/native-scm-cas-fit-and-consumer-cut.md) · [docs/plans/namespace-unique-on-chain-operational-plan.md](docs/plans/namespace-unique-on-chain-operational-plan.md) · [docs/plans/v2-self-hosting.md](docs/plans/v2-self-hosting.md) · [src/v2/compiler/05_emit.dag](src/v2/compiler/05_emit.dag) · [docs/plans/progress-observation-design.md](docs/plans/progress-observation-design.md) · [src/v2/compiler/self_host/candidate_generation.dag](src/v2/compiler/self_host/candidate_generation.dag) · [src/v2/compiler/self_host/stage0_production_target.dag](src/v2/compiler/self_host/stage0_production_target.dag) · [src/v2/compiler/self_host/wet_receipt_enrollment.dag](src/v2/compiler/self_host/wet_receipt_enrollment.dag) · [src/v2/workflow/rust_crate_partition.dag](src/v2/workflow/rust_crate_partition.dag) · [src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag](src/v2/compiler/self_host/v2_emitter_direct_rust_door_contract.dag) · [dag/gunbc/v1/v1_deletion_plan.dag](dag/gunbc/v1/v1_deletion_plan.dag) · [dag/gunbc/stage0/stage0_rust_host_observation.dag](dag/gunbc/stage0/stage0_rust_host_observation.dag) · [docs/plans/witness-realization-plan.md](docs/plans/witness-realization-plan.md) · [src/v1/05_emit_rust.dag](src/v1/05_emit_rust.dag) · [dag/gunbc/v1/v1_interpreter_primitive_surface.dag](dag/gunbc/v1/v1_interpreter_primitive_surface.dag) · [docs/plans/shell-to-dag-residual-census-and-arc-completion.md](docs/plans/shell-to-dag-residual-census-and-arc-completion.md) · [docs/plans/roadmap-workspace-ux-plan.md](docs/plans/roadmap-workspace-ux-plan.md) · [docs/plans/hermetic-tool-provisioning-design.md](docs/plans/hermetic-tool-provisioning-design.md) · [dag/gunbc/capability_binding.dag](dag/gunbc/capability_binding.dag) · [dag/gunbc/roadmap/roadmap_component.dag](dag/gunbc/roadmap/roadmap_component.dag) · [dag/gunbc/design_document.dag](dag/gunbc/design_document.dag) · [docs/plans/compiler-guarantee-recovery-gap-analysis.md](docs/plans/compiler-guarantee-recovery-gap-analysis.md) · [docs/plans/cardinality-refinement.md](docs/plans/cardinality-refinement.md) · [dag/gunbc/roadmap/roadmap_authority.dag](dag/gunbc/roadmap/roadmap_authority.dag) · [dag/test/claim/closing/namespace_reference_derived_producer_bounded_closing_contract_witness_test.dag](dag/test/claim/closing/namespace_reference_derived_producer_bounded_closing_contract_witness_test.dag) · [dag/test/claim/closing/2_scm_native_write_spine_acceptance_closing_contract_witness_test.dag](dag/test/claim/closing/2_scm_native_write_spine_acceptance_closing_contract_witness_test.dag) · [dag/test/claim/closing/2_scm_native_authority_program_closing_contract_witness_test.dag](dag/test/claim/closing/2_scm_native_authority_program_closing_contract_witness_test.dag) · [dag/test/claim/closing/namespace_cross_file_provenance_closing_contract_witness_test.dag](dag/test/claim/closing/namespace_cross_file_provenance_closing_contract_witness_test.dag) · [dag/test/claim/closing/v1_materialization_kernel_closing_contract_witness_test.dag](dag/test/claim/closing/v1_materialization_kernel_closing_contract_witness_test.dag) · [dag/test/claim/closing/gate_refusal_reason_survives_wrapper_closing_contract_witness_test.dag](dag/test/claim/closing/gate_refusal_reason_survives_wrapper_closing_contract_witness_test.dag) · [dag/test/claim/closing/toolchain_pin_model_closing_contract_witness_test.dag](dag/test/claim/closing/toolchain_pin_model_closing_contract_witness_test.dag) · [dag/test/claim/closing/instrument_motion_physical_qualification_closing_contract_witness_test.dag](dag/test/claim/closing/instrument_motion_physical_qualification_closing_contract_witness_test.dag) · [dag/test/claim/closing/instrument_rendered_control_coverage_closing_contract_witness_test.dag](dag/test/claim/closing/instrument_rendered_control_coverage_closing_contract_witness_test.dag) · [dag/test/claim/closing/discarded_bool_result_wall_closing_contract_witness_test.dag](dag/test/claim/closing/discarded_bool_result_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/ladder_probe_corpus_closing_contract_witness_test.dag](dag/test/claim/closing/ladder_probe_corpus_closing_contract_witness_test.dag) · [dag/test/claim/closing/method_established_surface_wall_closing_contract_witness_test.dag](dag/test/claim/closing/method_established_surface_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/call_label_and_surplus_wall_closing_contract_witness_test.dag](dag/test/claim/closing/call_label_and_surplus_wall_closing_contract_witness_test.dag) · [dag/test/claim/closing/declared_conformance_ground_fragment_closing_contract_witness_test.dag](dag/test/claim/closing/declared_conformance_ground_fragment_closing_contract_witness_test.dag) · [dag/test/claim/closing/v2_self_grounding_frontier_closing_contract_witness_test.dag](dag/test/claim/closing/v2_self_grounding_frontier_closing_contract_witness_test.dag) · [dag/test/claim/closing/interpreter_primitive_roster_closing_contract_witness_test.dag](dag/test/claim/closing/interpreter_primitive_roster_closing_contract_witness_test.dag) · [dag/test/claim/closing/unforgeable_construction_capability_closing_contract_witness_test.dag](dag/test/claim/closing/unforgeable_construction_capability_closing_contract_witness_test.dag). - [x] **Run the worker on DeepSeek V4 Flash with thinking on, straight at the engines, from briefs it can finish** — The harness posts to the Spark vLLM engines directly on the chat-completions shape with Think Max as the request switch, decodes inline reasoning client-side, replays it, and derives its deadline from the engine's own decode rate. A write brief names files small enough to hold whole and the decisions already made. Why: A day of runs with 0 files changed: briefs naming one file when the change spans its importers, a co-tenanted router killing every long step, a deadline that could not cover max_tokens, and agents deliberating modeling decisions a brief should have made. [authority](dag/gunbc/harness/harness_cli.dag) — ✓ signed off: operator curation 2026-09-06 (session 019iXPtAqzPaNBZbaaM5rxrY) - [x] **The roadmap commits, verifies, and opens the pull request itself once verification passes** — After the provider completes, the belt commits the attempt worktree, verifies the committed head in a detached checkout, admits publication only on a ValidationPassed receipt for that exact head, and the token-holding helper pushes the branch and opens the pull request, then answers with what GitHub shows. Why: Verification was checking out an uncommitted worktree's head, publication never consulted the verdict, and no operation existed to push or create a pull request, so every attempt stalled in the Agent segment and a human harvested by hand. [authority](dag/gunbc/roadmap/roadmap_publish_admission.dag) — ✓ signed off: operator curation 2026-09-06 (session 019iXPtAqzPaNBZbaaM5rxrY) @@ -76,3 +76,19 @@ The graph has sixteen lanes: SCM compatibility · namespace · P-derive · obser - [ ] **Bring Mt. Collins unit 1 into service as our first owned host, from observation rather than assumption** — Every fact the unit's intake depends on is either bound to a git-tracked observation consumed at mint time, or stays in its typed unobserved arm and refuses. The remaining facts: OCP bay occupancy and riser fitment observed from the unit interior; the bring-up evidence captures bound onto an executing consumer rather than stored beside it; one PCI identity authority with its superseded namespace admissions deleted; pre-OS assessment derived from SEL and captured inventory with its absence and indexed-replay controls executed; live pre-OS acquisition; supervision-to-envelope realization; PCI address cross-rendering equivalence between firmware and kernel renderings; and one meaning for AttachmentVerdict, since mtcollins1_expansion_attachment attachment_against_evidence discards the OCP standing (ocp: _) and so admits installability on the PCIe path but only interface compatibility on the OCP path (either match the OCP standing before the generation comparison with typed occupied and unobserved refusals, or split the verdict). Zero offers, over-reports and populated bays refuse rather than answer. Why: Hardware bought against an assumed slot, riser or bay costs a returned part and a lost week; a credential believed rotated but readable on another controller address is a silent exposure. [authority](dag/gunbc/machine_intake/mtcollins1_expansion_observation.dag) - [ ] **Write the closing check for: Prove on a real machine that a retired job slot is actually finished** — One executable check states when this is done, transcribed from the node's own bar: A slot whose leftover work is still running must not read as finished, and must not let the ceiling move. Reading the machine unsuccessfully must not read as nothing-running. The second pass doing work is a failure, not a retry. Why: Turns a prose bar into a runnable verdict, so the node it gates can be dispatched and its completion checked rather than judged. [authority](dag/gunbc/roadmap/roadmap_authority.dag) [witness](dag/test/claim/closing/fleet_slot_retirement_wet_proof_closing_contract_witness_test.dag) [subject](docs/plans/floor-memory-envelope-2026-09-12.md) - [ ] **Prove on a real machine that a retired job slot is actually finished** — The whole retirement transaction is built and checked without touching a machine: it decides which slots must go from a written-down prior width, checks the operator has permitted interrupting those exact ones, stops and pins them so they cannot come back, and then reads the machine again -- separately -- to decide whether the work under them really ended. None of that has ever run on a host. This is the first real one: interrupt the permitted slots on one machine, watch the independent read-back say they are finished, let the raised ceiling follow from that, read the ceiling back off the machine, and run the whole thing a second time to see it do nothing. Why: Every claim about this path is currently a claim about a model of the machine. The specific thing nobody has watched is the part that matters: stopping a slot is not the same as its work having stopped, and the check that separates those two has never been asked a real question. [authority](docs/plans/floor-memory-envelope-2026-09-12.md) +- [ ] **Write the closing check for: NUMERIC-BIT cut 1: one sealed octet carrier minted only by admission (gunbc#11643)** — One executable check states when this is done, transcribed from the node's own bar: A literal QualifiedOctets outside the admission functions refuses at resolve; an admission fed 256 refuses with a typed cause; a forged-octet witness that once diverged has no author. Why: Turns a prose bar into a runnable verdict, so the node it gates can be dispatched and its completion checked rather than judged. [authority](dag/gunbc/roadmap/roadmap_authority.dag) [witness](dag/test/claim/closing/egress_numeric_bit_sealed_carrier_closing_contract_witness_test.dag) [subject](docs/plans/demand-engine-program.md) + - [ ] **NUMERIC-BIT cut 1: one sealed octet carrier minted only by admission (gunbc#11643)** — A sole_constructor QualifiedOctets { members: List } minted only by the admission functions, RealizableWidth sole_constructor, and every bit-width operation consuming the sealed carrier. UInt8 is a Phantom transparent to Int and cannot carry the proof, so 256 inhabits List today. Why: Every downstream encoder (base64, SHA-256, CBOR) re-checks or silently accepts an out-of-range octet; the forged-octet divergence row exists only because the carrier is literal-writable. [authority](docs/plans/demand-engine-program.md) + - [ ] **NUMERIC-BIT cut 2: Width32/Width64 kernel arms in the interpreter and the emitter** — The bit operations over the sealed carrier at machine widths 32 and 64 realized as kernel arms in the v1 interpreter and in the Rust emitter, with one differential witness proving both targets agree on a discriminating corpus. Why: SHA-256 and every rotate-heavy primitive run as interpreted folds over Int, which is the cost that gates CRYPTO-0's landing. [authority](docs/plans/demand-engine-program.md) + - [ ] **NUMERIC-BIT cut 3: the multi-limb carrier for widths above 64** — A carrier of N sealed limbs for P-256 field arithmetic and SHA-512 words, derived from the same width axis rather than a fresh type per width. Why: P-256 and SHA-384/512 have no honest home without it. [authority](docs/plans/demand-engine-program.md) + - [ ] **CRYPTO-0: land pure .dag SHA-256 and HMAC with utf8_encode_octets (gunbc#11647)** — gunbc#11647 retargeted onto the kernel arms and landed: SHA-256, HMAC-SHA256 and utf8_encode_octets as pure .dag, the native receipt instrument row //gunbc/instruments:crypto-native, and the two hmac evidence rows in gunbc.primitive_egress.dispositions_text deleted in the same change (review 69198: with the primitives gone they join no identity and every primitive-egress-census label exits 1). Why: Every hashing primitive is still a host route the substrate cannot see, and the hmac evidence rows stay as un-retired debt. [authority](docs/plans/demand-engine-program.md) + - [ ] **CRYPTO-0: SHA-384/512, P-256 ECDSA, ES256 for APNs, App Attest verification** — The remaining primitives App Attest and APNs consume, each pure .dag over the multi-limb carrier, replacing the typed ECDSA frontier at which ios_enrolment_admission currently refuses. Why: Device enrolment cannot mint AttestationVerified; the openssl RS256 route stays the only signing path. [authority](docs/plans/demand-engine-program.md) — requires all: egress-crypto-0-sha256-landing, egress-numeric-bit-multi-limb + - [ ] **CENSUS-0 follow-ups: quiet-host runs at one sha and the open class rows** — The -dag, -seed and full census runs executed on a quiet host at one sha; the reference_deps class-2 open row; the D13 DependencyDemand carrier join; decomposition of the 44 MixedSemanticQuestions rows; and retirement of the hmac evidence rows after CRYPTO-0 lands. Why: 157/212 Unresolved is honest but unranked without a same-sha run, and the mixed rows hide which primitive each question really asks. [authority](docs/plans/demand-engine-program.md) + - [ ] **CONTENT-HASH cut 2: the FNV kernel arm and the final registry deletion** — FNV realized as a kernel arm over the sealed carrier in both targets, then the content-hash registry entry deleted once nothing routes through it. Why: The registry keeps a second producer of every content hash alive beside the .dag one. [authority](docs/plans/demand-engine-program.md) + - [ ] **ENCODING-0: land pure .dag CBOR, DER and X.509 parsing (gunbc#11727)** — gunbc#11727 (approved, receipt 8 modules / 170 claims / 0 failed) retargeted from the sharp-raven base onto main once the sealed carrier lands, fresh receipt, landed. Why: The attestation parsers sit approved but unlandable, and every consumer of std.octet_span waits on them. [authority](docs/plans/demand-engine-program.md) + - [ ] **ENCODING-0: content_hash hex consolidation, UTF-8 typed causes, the std.bytes seam** — std.content_hash consumes extdeps.numeric.base16 with the stage0 mirror regenerated and the seed population change declared; utf8_decode_octets refuses malformed, incomplete and bad-octet distinctly at construction instead of collapsing onto Absent; utf8_encode_bytes, utf8_decode_bytes, bytes_octets and octets_bytes switch to the .dag route with the displaced interpreter routes deleted and the registry deletion last and serialized. Why: The hex alphabet still forks inside the emitted seed; UTF-8 failures are indistinguishable; the bytes primitives remain host routes. [authority](docs/plans/demand-engine-program.md) — requires all: egress-encoding-0-cbor-der-landing, egress-crypto-0-sha256-landing +- [ ] **Write the closing check for: EFFECTS-1: land cut (c) and the E2 LocalFilesystem provider** — One executable check states when this is done, transcribed from the node's own bar: A new demand_restatement row refuses; an emitted closure reaching filesystem_read directly refuses under the handler binding. Why: Turns a prose bar into a runnable verdict, so the node it gates can be dispatched and its completion checked rather than judged. [authority](dag/gunbc/roadmap/roadmap_authority.dag) [witness](dag/test/claim/closing/egress_effects_1_filesystem_provider_closing_contract_witness_test.dag) [subject](docs/plans/demand-engine-program.md) + - [ ] **EFFECTS-1: land cut (c) and the E2 LocalFilesystem provider** — gunbc#11744 (head b170ce27, CLEAN, 412 uses rows cut with zero residue) lands once its follow-up roster is re-derived: it declares 26 rows over 5ff323b6d29..a35c7cede3e while the head carries 48 across 9 modules, and the roster is rendered into docs/plans/demand-engine-program.md whose regeneration refuses under host memory pressure. Then E2 binds one native Filesystem handler at the NativeCliDriver root reusing emit_file_call's semantics, the 48 rows retire, and a refusal lands on any new restatement row. Why: Filesystem effects in the emitted closure still reach a bare primitive that is neither the handler nor the interface, and restatement rows accrue without a wall. [authority](docs/plans/demand-engine-program.md) +- [ ] **Write the closing check for: Optional-at-required tail: five modules outside every gated closure** — One executable check states when this is done, transcribed from the node's own bar: Each site's Absent arm refuses with a typed cause; a bare Present in srv3 resolves to exactly one declaration. Why: Turns a prose bar into a runnable verdict, so the node it gates can be dispatched and its completion checked rather than judged. [authority](dag/gunbc/roadmap/roadmap_authority.dag) [witness](dag/test/claim/closing/egress_optional_at_required_tail_closing_contract_witness_test.dag) [subject](docs/plans/demand-engine-program.md) + - [ ] **Optional-at-required tail: five modules outside every gated closure** — bmc_fan_monitor, bmc_fan_converge, fabric_required_build_cell, fleet_show_effective_read and srv3_install_media_fetch matched on their Optional first() sites so gunbc#11720's wall holds over them; the srv3 module's own Present/Absent variants shadow Optional's and must be qualified or renamed. Branch fierce-seal-607/optional-at-required-tail carries the uncommitted work. Why: Five closures no gate compiles keep an Optional flowing into a required T, which the floor cannot see. [authority](docs/plans/demand-engine-program.md) +- [ ] **Write the closing check for: Primitive-egress residue: TEXT-0 alphabet collapse, alias fixture enrolment, admission rows, hex literal** — One executable check states when this is done, transcribed from the node's own bar: A consumed admission row surviving deletion reds; a hex literal that lexes as two tokens refuses. Why: Turns a prose bar into a runnable verdict, so the node it gates can be dispatched and its completion checked rather than judged. [authority](dag/gunbc/roadmap/roadmap_authority.dag) [witness](dag/test/claim/closing/egress_program_residue_closing_contract_witness_test.dag) [subject](docs/plans/demand-engine-program.md) + - [ ] **Primitive-egress residue: TEXT-0 alphabet collapse, alias fixture enrolment, admission rows, hex literal** — TEXT-0's alphabet collapse; enrolment of the applied-generic alias fixture; the 40 consumed ACTION-USE transition-admission rows deleted as gunbc#11790 deleted the first 11; a hex literal form for .dag; heal.yml dispatch-only with the dashboard readiness pending quirk recorded; batch floor 2 on a quiet host under ruling A; the unlanded demand-engine plan refinements on branch fierce-seal-607/plan-e2-handler (D11 realization ruling, E2 handler shape) folded into docs/plans/demand-engine-program.md. Why: Each is a small known debt whose only cost today is being remembered by a person instead of a row. [authority](docs/plans/demand-engine-program.md) diff --git a/dag/gunbc/roadmap/roadmap_authority.dag b/dag/gunbc/roadmap/roadmap_authority.dag index c5c38df42f8..7b9083c3350 100644 --- a/dag/gunbc/roadmap/roadmap_authority.dag +++ b/dag/gunbc/roadmap/roadmap_authority.dag @@ -2755,6 +2755,186 @@ fn declared_roadmap_nodes() -> List { handback: "Return the census, the wall or the frozen roster with its dissolution trigger, and both controls." ) ), + active( + identity: "rn_RVJ5GW9Q2D7Y3PKAKTNRT0DCSB", + id: "egress-numeric-bit-sealed-carrier", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "NUMERIC-BIT cut 1: one sealed octet carrier minted only by admission (gunbc#11643)", + boundary: "A sole_constructor QualifiedOctets { members: List } minted only by the admission functions, RealizableWidth sole_constructor, and every bit-width operation consuming the sealed carrier. UInt8 is a Phantom transparent to Int and cannot carry the proof, so 256 inhabits List today.", + displaced_cost: "Every downstream encoder (base64, SHA-256, CBOR) re-checks or silently accepts an out-of-range octet; the forged-octet divergence row exists only because the carrier is literal-writable.", + first_slice: "Retarget gunbc#11643 onto the sealed carrier, delete base64_encode_forged_qualified_octet_diverges, floor clean, side-chat APPROVE on the exact head, land.", + red_control: "A literal QualifiedOctets outside the admission functions refuses at resolve; an admission fed 256 refuses with a typed cause; a forged-octet witness that once diverged has no author.", + out_of_scope: "Kernel arms and multi-limb carriers are the next two rows.", + handback: "Return the landed head, the admission roster, and the deleted divergence row." + ) + ), + active( + identity: "rn_06FZGM9B7W8J44J7R6QXA1MJWM", + id: "egress-numeric-bit-kernel-arms", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "NUMERIC-BIT cut 2: Width32/Width64 kernel arms in the interpreter and the emitter", + boundary: "The bit operations over the sealed carrier at machine widths 32 and 64 realized as kernel arms in the v1 interpreter and in the Rust emitter, with one differential witness proving both targets agree on a discriminating corpus.", + displaced_cost: "SHA-256 and every rotate-heavy primitive run as interpreted folds over Int, which is the cost that gates CRYPTO-0's landing.", + first_slice: "Interpreter arms for the four rotate/shift/mask operations at Width32, the emitter twin, the differential witness.", + red_control: "A mutated emitter arm reds the differential witness while the interpreter arm stays green; an unrealized width refuses rather than falling back to the fold.", + out_of_scope: "Multi-limb widths above 64.", + handback: "Return both realizations, the witness, and the measured cost of SHA-256 through the arms." + ) + ), + active( + identity: "rn_V42QB2G0GX8FK5APP66A0MPRNE", + id: "egress-numeric-bit-multi-limb", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "NUMERIC-BIT cut 3: the multi-limb carrier for widths above 64", + boundary: "A carrier of N sealed limbs for P-256 field arithmetic and SHA-512 words, derived from the same width axis rather than a fresh type per width.", + displaced_cost: "P-256 and SHA-384/512 have no honest home without it.", + first_slice: "Limb carrier and add-with-carry over two limbs, with its witness.", + red_control: "A carry dropped between limbs reds; a limb outside its width refuses at admission.", + out_of_scope: "Curve arithmetic itself belongs to the CRYPTO-0 curve row.", + handback: "Return the carrier, the arithmetic roster, and the witness." + ) + ), + active( + identity: "rn_SYXHP92KEGX92XNFBZRXBQW2BV", + id: "egress-crypto-0-sha256-landing", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "CRYPTO-0: land pure .dag SHA-256 and HMAC with utf8_encode_octets (gunbc#11647)", + boundary: "gunbc#11647 retargeted onto the kernel arms and landed: SHA-256, HMAC-SHA256 and utf8_encode_octets as pure .dag, the native receipt instrument row //gunbc/instruments:crypto-native, and the two hmac evidence rows in gunbc.primitive_egress.dispositions_text deleted in the same change (review 69198: with the primitives gone they join no identity and every primitive-egress-census label exits 1).", + displaced_cost: "Every hashing primitive is still a host route the substrate cannot see, and the hmac evidence rows stay as un-retired debt.", + first_slice: "Retarget, floor clean, land; then the instrument row and the evidence-row retirement.", + red_control: "A mutated round constant reds the FIPS 180-4 vectors; the native instrument refuses on a wrong label rather than reporting pass.", + out_of_scope: "SHA-384/512, P-256 and ES256 are the next row.", + handback: "Return the landed head, the instrument row, and the retired evidence rows." + ) + ), + active( + identity: "rn_YFQ6WQM8AAHBKJ5CASXXZPJ569", + id: "egress-crypto-0-curve-and-sign", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "CRYPTO-0: SHA-384/512, P-256 ECDSA, ES256 for APNs, App Attest verification", + boundary: "The remaining primitives App Attest and APNs consume, each pure .dag over the multi-limb carrier, replacing the typed ECDSA frontier at which ios_enrolment_admission currently refuses.", + displaced_cost: "Device enrolment cannot mint AttestationVerified; the openssl RS256 route stays the only signing path.", + first_slice: "SHA-384 and SHA-512 over the limb carrier with FIPS vectors.", + red_control: "A wrong-curve point refuses; a signature over a mutated digest fails verification; every vector row is a cited upstream value.", + out_of_scope: "Key custody stays a bound host effect (the gunbc#11677 ruling).", + handback: "Return each primitive with its cited vectors and the first AttestationVerified minted through the pure path." + ) + ), + active( + identity: "rn_KKAGM3C9SB50J0KSHGPYXDTM4J", + id: "egress-encoding-0-cbor-der-landing", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "ENCODING-0: land pure .dag CBOR, DER and X.509 parsing (gunbc#11727)", + boundary: "gunbc#11727 (approved, receipt 8 modules / 170 claims / 0 failed) retargeted from the sharp-raven base onto main once the sealed carrier lands, fresh receipt, landed.", + displaced_cost: "The attestation parsers sit approved but unlandable, and every consumer of std.octet_span waits on them.", + first_slice: "Retarget onto main after egress-numeric-bit-sealed-carrier, re-run the receipt, land.", + red_control: "The three mutant REDs in the receipt stay red on the retargeted head.", + out_of_scope: "content_hash consolidation, UTF-8 causes and the bytes seam are their own rows.", + handback: "Return the landed head and the fresh receipt." + ) + ), + active( + identity: "rn_TNT1ZEDDB0C3KNE6CYV9K4GJBX", + id: "egress-encoding-0-bytes-seam", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "ENCODING-0: content_hash hex consolidation, UTF-8 typed causes, the std.bytes seam", + boundary: "std.content_hash consumes extdeps.numeric.base16 with the stage0 mirror regenerated and the seed population change declared; utf8_decode_octets refuses malformed, incomplete and bad-octet distinctly at construction instead of collapsing onto Absent; utf8_encode_bytes, utf8_decode_bytes, bytes_octets and octets_bytes switch to the .dag route with the displaced interpreter routes deleted and the registry deletion last and serialized.", + displaced_cost: "The hex alphabet still forks inside the emitted seed; UTF-8 failures are indistinguishable; the bytes primitives remain host routes.", + first_slice: "content_hash consolidation with its mirror regeneration and declared population row.", + red_control: "A mutated digit-15 spelling reds the content_hash witness; an incomplete UTF-8 sequence and a bad octet refuse with different causes.", + out_of_scope: "App Attest steps 2-5 and 10 wait on CRYPTO-0 SHA-256.", + handback: "Return each switched primitive with its deleted interpreter route and the registry deletion receipt." + ) + ), + active( + identity: "rn_RTHC6H20EMH3K0C8TAMCJ6P527", + id: "egress-effects-1-filesystem-provider", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "EFFECTS-1: land cut (c) and the E2 LocalFilesystem provider", + boundary: "gunbc#11744 (head b170ce27, CLEAN, 412 uses rows cut with zero residue) lands once its follow-up roster is re-derived: it declares 26 rows over 5ff323b6d29..a35c7cede3e while the head carries 48 across 9 modules, and the roster is rendered into docs/plans/demand-engine-program.md whose regeneration refuses under host memory pressure. Then E2 binds one native Filesystem handler at the NativeCliDriver root reusing emit_file_call's semantics, the 48 rows retire, and a refusal lands on any new restatement row.", + displaced_cost: "Filesystem effects in the emitted closure still reach a bare primitive that is neither the handler nor the interface, and restatement rows accrue without a wall.", + first_slice: "On a quiet host: re-derive the roster and its range at the head, regenerate the plan projection in the same commit, floor clean, land gunbc#11744.", + red_control: "A new demand_restatement row refuses; an emitted closure reaching filesystem_read directly refuses under the handler binding.", + out_of_scope: "Network and process effects are later program cuts.", + handback: "Return the landed cut, the handler binding, and the restatement refusal." + ) + ), + active( + identity: "rn_5NMAXZFR0Q4ER63G6VYDH6NHA5", + id: "egress-content-hash-fnv-kernel", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "CONTENT-HASH cut 2: the FNV kernel arm and the final registry deletion", + boundary: "FNV realized as a kernel arm over the sealed carrier in both targets, then the content-hash registry entry deleted once nothing routes through it.", + displaced_cost: "The registry keeps a second producer of every content hash alive beside the .dag one.", + first_slice: "The FNV arm with a differential witness against the .dag fold.", + red_control: "A mutated prime reds both targets; the registry deletion reds any surviving route.", + out_of_scope: "Nothing beyond FNV and its registry row.", + handback: "Return the arm, the witness, and the deletion receipt." + ) + ), + active( + identity: "rn_AEJBJV14KK79Y09AY00WVZ0056", + id: "egress-census-quiet-host-and-decomposition", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "CENSUS-0 follow-ups: quiet-host runs at one sha and the open class rows", + boundary: "The -dag, -seed and full census runs executed on a quiet host at one sha; the reference_deps class-2 open row; the D13 DependencyDemand carrier join; decomposition of the 44 MixedSemanticQuestions rows; and retirement of the hmac evidence rows after CRYPTO-0 lands.", + displaced_cost: "157/212 Unresolved is honest but unranked without a same-sha run, and the mixed rows hide which primitive each question really asks.", + first_slice: "One same-sha run of all three census modes on a quiet host (srv1 access is required and was lost on a container restart).", + red_control: "Runs at differing shas refuse to join; a MixedSemanticQuestions row that decomposes to fewer questions than it names reds.", + out_of_scope: "No new census classes.", + handback: "Return the same-sha receipts and the decomposed rows." + ) + ), + active( + identity: "rn_Q71AC17SGZB8PMP7PF756C3P13", + id: "egress-optional-at-required-tail", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "Optional-at-required tail: five modules outside every gated closure", + boundary: "bmc_fan_monitor, bmc_fan_converge, fabric_required_build_cell, fleet_show_effective_read and srv3_install_media_fetch matched on their Optional first() sites so gunbc#11720's wall holds over them; the srv3 module's own Present/Absent variants shadow Optional's and must be qualified or renamed. Branch fierce-seal-607/optional-at-required-tail carries the uncommitted work.", + displaced_cost: "Five closures no gate compiles keep an Optional flowing into a required T, which the floor cannot see.", + first_slice: "Resolve the srv3 name collision, commit the branch, floor clean, land.", + red_control: "Each site's Absent arm refuses with a typed cause; a bare Present in srv3 resolves to exactly one declaration.", + out_of_scope: "The gunbc#11720 residuals in gated closures are already covered by the wall.", + handback: "Return the landed head and the collision resolution." + ) + ), + active( + identity: "rn_1KRJKPNSVCMTVHGHXH91HYFPZ4", + id: "egress-program-residue", + owner: "primitive-egress", + path: "docs/plans/demand-engine-program.md", + t: fields( + headline: "Primitive-egress residue: TEXT-0 alphabet collapse, alias fixture enrolment, admission rows, hex literal", + boundary: "TEXT-0's alphabet collapse; enrolment of the applied-generic alias fixture; the 40 consumed ACTION-USE transition-admission rows deleted as gunbc#11790 deleted the first 11; a hex literal form for .dag; heal.yml dispatch-only with the dashboard readiness pending quirk recorded; batch floor 2 on a quiet host under ruling A; the unlanded demand-engine plan refinements on branch fierce-seal-607/plan-e2-handler (D11 realization ruling, E2 handler shape) folded into docs/plans/demand-engine-program.md.", + displaced_cost: "Each is a small known debt whose only cost today is being remembered by a person instead of a row.", + first_slice: "The 40 consumed admission rows, which is a deletion whose census is the floor.", + red_control: "A consumed admission row surviving deletion reds; a hex literal that lexes as two tokens refuses.", + out_of_scope: "None of these widens the program.", + handback: "Return each item landed or reclassified with its trigger." + ) + ), ], guarantee_ladder_nodes()) } @@ -2916,6 +3096,16 @@ fn declared_roadmap_edges() -> List { edge(child: "toolchain-rust-hermetic", parent: "toolchain-single-resolver"), edge(child: "toolchain-residue-zero", parent: "toolchain-rust-hermetic"), edge(child: "toolchain-system-floor", parent: "toolchain-single-resolver"), + edge(child: "egress-numeric-bit-kernel-arms", parent: "egress-numeric-bit-sealed-carrier"), + edge(child: "egress-numeric-bit-multi-limb", parent: "egress-numeric-bit-kernel-arms"), + edge(child: "egress-crypto-0-sha256-landing", parent: "egress-numeric-bit-kernel-arms"), + edge(child: "egress-crypto-0-curve-and-sign", parent: "egress-crypto-0-sha256-landing"), + edge(child: "egress-crypto-0-curve-and-sign", parent: "egress-numeric-bit-multi-limb"), + edge(child: "egress-encoding-0-cbor-der-landing", parent: "egress-numeric-bit-sealed-carrier"), + edge(child: "egress-encoding-0-bytes-seam", parent: "egress-encoding-0-cbor-der-landing"), + edge(child: "egress-encoding-0-bytes-seam", parent: "egress-crypto-0-sha256-landing"), + edge(child: "egress-content-hash-fnv-kernel", parent: "egress-numeric-bit-kernel-arms"), + edge(child: "egress-census-quiet-host-and-decomposition", parent: "egress-crypto-0-sha256-landing"), ], guarantee_ladder_edges()) } @@ -3844,8 +4034,8 @@ fn preamble() -> List { // hidden lane as retained and unexplained rather than as decided. data roadmap_focus_selection: RoadmapFocus = FocusOnOwners { - label: "the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main + the harness, roadmap workflow and dashboard lanes", - owners: ["compute", "fleet", "ci-placement", "ci-control", "generated-artifact", "ci-cost", "confidence", "harness", "roadmap", "dashboard"], + label: "the compute fabric + the infrastructure stabilisation lanes + fleet convergence from main + the harness, roadmap workflow and dashboard lanes + the primitive-egress wind-down", + owners: ["compute", "fleet", "ci-placement", "ci-control", "generated-artifact", "ci-cost", "confidence", "harness", "roadmap", "dashboard", "primitive-egress"], } fn projected_roadmap_nodes_for_accepted(