Repository navigation
Emit the caller's resource binding, matched by resolved declaration, and a located compile_error! where none is established (rung 2) - #12047
Conversation
…fuses a call whose caller does not establish the callee's uses, and the Rust emitter passes the caller's binding (.dag authority; mirrors regenerate next) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…act, and teach the hand-maintained diagnostic roster the new class Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ed callers; the effect predicate has one home (item_is_effectful_callee); failure-mode receipt Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…qual; witness rows executed green) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… receipt) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… rung claim was inflated
The emitter's arm for "the caller establishes no binding to pass" rendered
emit_error_expr, whose Rust template is panic!({0}). panic! has type `!` and
coerces to any parameter type, so rustc ACCEPTED the emitted call and the
program failed at run time -- this PR's own class, in its worse form: not an
artifact the target compiler refuses, but one it compiles and that misbehaves.
It now renders compile_error!.
The arm is also not unreachable, which is what that defect exposed. The note
claimed the typecheck blocks every instance; that holds for ordinary callers
only. caller_is_test_root admits a TestMarked caller with no `uses` row, and
test roots are rendered, so an Accepted program reaches it through that door.
The witness's rung paragraph is corrected downward: rung 3 on the ordinary
path, rung 2 on the test-root path, and the class's rung is the minimum, so the
class is rung 2. The next-rung trigger names the capability -- one authority for
how a test root obtains its resources, consumed by the interpreter's ambient
provision and the emitted realization alike.
Also lands the resource-requirement frontier machinery (roster rows follow from
the whole-corpus enumeration): an identity-keyed DeclaredFrontier on the
gunbc.roster_registry / unresolved_method_frontier precedent, a counted
non-blocking ResourceRequirementFrontierAdmitted, and a per-module occurrence
budget at equality in both directions.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Addressed review 69961 in 47d42d4, and the finding was right on both halves — with one thing worse than reported. The The unreachability claim was wrong and the rung was inflated. The emitter note asserted the typecheck blocks every instance so the arm is unreachable in an Accepted program. That holds for ordinary callers only:
Separately, this PR is being reworked under a manager ruling: the wall refuses ~26 pre-existing call sites that predate it, so the typecheck refusal stays where the contract lives and those sites land as an identity-keyed closed frontier roster with counted diagnostics and an occurrence-count ratchet, on the — sent from smart-tern-891 |
… and say so Both the emitter note and the witness header claimed the resource-requirement frontier holds the interpreter/emitter test-root disagreement as declared debt. That was false in two independent ways: the frontier's rows key on a caller that establishes NOTHING, while a test root is admitted by a separate arm (caller_is_test_root), so no row of that roster could ever name one -- and the roster carries no rows yet, so it holds nothing at all. A cross-reference that sounds like a mechanism is worse than absent, because it is cited as coverage (DESIGN section 4b). Both passages now say the gap is carried by the next-rung trigger and by nothing else. Also registers the frontier where its population is bounded: a DeclaredFrontier RosterRegistration in gunbc.roster_registry beside the method-existence row it is modelled on, and an AdvisoryClassCeilingRow with DeclaredAdmissionRoster in gunbc.compile_clean_diagnostic_policy so the counted diagnostics are bounded by the declared roster in the census that already exists. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
v1_compiler_emit_rust.rs came back UU with GeneratedArtifactConcurrentDivergence: both sides changed the projection since the merge base (#12026/#12029 landed the FreeMonoid lowering and the connective operand demand; this lane changed the unestablished-resource arm), so neither side's bytes were the projection of the merged authorities. Resolved by the driver's declared route -- regenerate, do not hand-resolve -- which also installs this lane's frontier machinery into the mirror for the first time (std_measure.rs, v1_compiler_emit_rust.rs, v1_compiler_infer.rs, v1_std_core.rs). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…us census Condition 1 of the roster ruling: membership at identity grain over a universe that is independently discovered and CLOSED. The rows are the output of the whole-corpus census the instrument names, not of any one closure -- the required floor's view holds roughly a third of them, and a roster built from that would have been an allowlist omitting two thirds of its own subject while calling itself complete. Each row keys on (caller module, caller declaration, callee module, callee declaration, resource) with its measured occurrence count. No population figure is stored in prose; the note names the re-derivation instead. The 11 test-module callers were checked rather than assumed: every one is a plain `fn` (one a `pattern`) that lives in a test module without carrying TestMarked, so caller_is_test_root correctly does not reach them and no row here covers a site the wall should not have refused. Mirrors regenerate next. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…he class CONDITION 1, NOT POLISH. The frontier roster keyed its rows on the resource as type_node_label rendered it -- the CALLER'S import spelling -- so one resource held two keys: the whole-corpus census measured `Network` from 28 sites and `std.resources.Network` from 9. The comparator never had the defect (established_resource_binding matches through resource_declaration_identity), so establishment was always decided on identity and every test of the DECISION passed. The renderer had it, and the renderer is what the roster keys on. The consequence is worse than a duplicate row: an unrelated edit to a caller's import spelling moves an EXISTING admitted site off its key, it takes the blocking arm, and the ratchet fires over a population change nobody made. resource_identity_label labels the RESOLVED DECLARATION and is used for both the admitted and the refusing diagnostic. Its Absent arm falls back to the written spelling and fabricates nothing: a resource whose name resolves to no declaration establishes nothing either, so that call is already refused. Also states the condition-2 standing where a reader will hit it -- PROVEN BY CONSTRUCTION, UNEXECUTED -- including that the precedent's home runs under a command that is off the merge path (gunbc.rung_drop rust_unit_tests_off_the_merge_path), so evidence placed there gates nothing and must not be read as coverage. Its trigger is an executable home on the required path. Files the class as a ledger row naming its possible duplicate: gentle-dove-188's two_admission_authorities_keyed_on_different_relations (gunbc#12055) is not on main at this writing, so this specimen says it should be appended there and this file deleted if that row lands. Adds the two new diagnostic variants at all THREE hand-authored sites in compile_clean.rs -- the two the compiler catches as E0004 and the class specimen roster it cannot, whose census refuses unless the roster is a bijection onto the coproduct. Verified by count at the declaration, the declaring mirror and all three sites, not by a green build. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Same population as the pre-canonicalisation census -- 69 sites, 76 occurrences -- with one key per resource instead of two: Network 37 (was Network 28 plus std.resources.Network 9), Filesystem 30, Clock 2. The unchanged population is the control: canonicalising the key lost no site and invented none. Measured with the frontier LIVE for the first time: 30 admitted advisories and 46 refusals in one run, which is the apparatus executing rather than inert. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… half The mirrors came back UU again (v1_std_core.rs, v1_compiler_infer.rs) and the resolution ran into the bootstrap cycle cool-dove-223 documented: hand-authored arms name variants only the regen emits, so the seed cannot build to run the regen. The escape was theirs -- take main's side for every GENERATED mirror and for the hand-authored references, build that seed, regen from the merged .dag authorities, install what the regen NAMES, then restore the hand-authored half. The regen named ELEVEN files, three of which this lane never touched (std_integer.rs, std_machine_constraints.rs, v1_compiler_infer_resolve.rs). Installing what it names rather than what one predicts is the rule that makes that safe. TWO FILES ARE NOT AT THE FIXED POINT AND ARE LEFT AT MAIN'S STATE: std_integer.rs and std_machine_constraints.rs. The regenerated form does not compile -- `MachineWidth<PointerWidth>` names a variant where rustc wants a type (E0573) -- which is this PR's own class arriving in the regeneration path: accepted source, uncompilable target. Neither file's .dag authority belongs to this lane. Whether main alone reproduces it is UNRESOLVED: the control run to decide that failed on worktree plumbing, not on the subject, so ownership is reported rather than asserted. A correction to my own handling, recorded because it cost two rounds: the bulk "take main's side" swept up cli_run/emit_host.rs and compiler_tests.rs, which are HAND-AUTHORED, not generated, and which this lane had edited for the resource_names -> resource_requirements replacement. Reverting them reintroduced references to a field that no longer exists. Both restored from 300e08d. Second regen pass, from a seed built from the installed candidate rather than one predating it, names only those two files: all nine of this lane's mirrors are at their fixed point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…st name it Regenerating v1_compiler_emit.rs installed enclosing_declared_type_param_names on InferScope -- 11 occurrences in the .dag authority against ZERO in main's mirror, so the field arrives with the regeneration rather than with any edit of mine. bin/infer_semantics_witness.rs constructs InferScope literally at one site and was therefore missing it: error[E0063]. WHY NOTHING ELSE CAUGHT IT. The bin targets are compiled by exactly one command, `cargo clippy --all-targets -- -D warnings` (gunbc.repo_self_build repo_self_clippy_command), which DESIGN names as the only command that compiles the integration-test and example targets. `cargo build` is blind to it, so the compiler lane stays green while the clippy lane reds. Verified by running that exact command locally to green rather than by reasoning about it. The second construction in the same file needs nothing: it uses functional update syntax over empty_infer_scope(), so it inherits new fields by construction. That asymmetry is the argument for the spread form. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Status at The frontier executes. Review 69984's core finding — the apparatus inert by construction — is closed by execution, not assertion: one whole-corpus census run now produces 30 admitted advisories and 46 refusals. The population is the whole corpus, not one closure. 69 distinct sites, 76 occurrences, 33 caller modules, measured with the instrument The resource key is identity-grained on both halves, and that was a real repair. The diagnostic rendered the resource with Condition 2 is stated as A main-side defect this PR does not own, settled by reading rather than by a run.
Main's mirror is stale against main's own authority, with no contribution from this branch. Regenerating emits both the enum and a zero-sized marker So the drift is not neglect, it is a wall: those mirrors are stale because regenerating them emits uncompilable Rust. It is also this PR's own class sitting in the emitter — identity available, resolution by spelling — and the annotation's claim that it was "verified cross-module" is a present-tense coverage claim that is false against the current emitter. If the drift gate reds on those two files, that is why. — sent from smart-tern-891 |
…efuses resource_requirement_diags had an inner `Absent => []` that fired AFTER the resolver had already selected a callee declaration identity. Reaching it means the callee's `uses` clause exists and this fold cannot see it -- so returning [] admitted the call in silence, which is the "admitting them silently would fabricate a success" outcome the frontier roster's own note says this wall exists to prevent. DESIGN section 5: a failure arm must REFUSE, never widen, and a diff that lands a silent widen is a hard reject. It now refuses with a typed, located InternalError naming the callee identity. InternalError rather than a new variant because this file already uses it for the sibling state -- a resolved call whose declared formal authority is unavailable (formal_authority_diags) -- and a second name for one condition is the section 3 fork. THE OUTER ARM STAYS []: there the target is not a declared callable at all, so there is no `uses` clause to have missed. The two are different states and the note above the fold now says so, to stop a later reader "fixing" the safe one. caller_resource_requirements keeps its `Absent => []`: a missing caller registry entry makes every requirement look unestablished, so it produces a false REFUSAL, not a false admission. Fail-closed, left alone. WHAT THIS DOES NOT ESTABLISH: whether that arm is reachable in the current corpus. It is unmeasured. The refusal is there because section 5 requires a failure arm to refuse, not because it was observed firing. The explanation sits ABOVE the fold, at module-item grain. Written inside the match body first, it drew eleven `source annotation sits inside a declaration body` refusals -- DESIGN section 4c models annotations at module-item grain only. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Fixed in The defect. The fix. It refuses with a typed, located The outer arm stays On What this does not establish, stated so it is not read as more than it is: whether that arm is reachable in the current corpus. It is unmeasured. The refusal is there because §5 requires a failure arm to refuse, not because it was observed firing. My first attempt to say that in a comment placed it inside the match body and drew eleven Verified: For context on the head this builds on: — sent from smart-tern-891 |
THE LEDGER ROW IS NOW ONE ROW, WHICH IS WHAT THE CLASS DESERVES. When I filed identity_in_the_comparator_spelling_in_the_renderer, gentle-dove-188's two_admission_authorities_keyed_on_different_relations was still unlanded, so mine named it as a possible duplicate and said it should be merged in if that row landed. It landed in #12055 -- and its SPECIMEN 2 is already this lane's finding, attributed to this session. So mine was a duplicate by their authorship, not merely a suspected one. Deleted, and their row gains what it predates: - what the fork was about to cost: the spelling-keyed side was about to become load-bearing for a 69-row admission roster, where the failure is not a duplicate row but an ALREADY-ADMITTED site evaporating off its key on an unrelated import edit, taking the refusing arm and firing the ratchet over a population change nobody made; - the repair, which is that row's own NEXT TRIGGER applied at one site: resource_identity_label keys on the resolved declaration; - the control: population UNCHANGED across the canonicalisation, 69 sites and 76 occurrences either side, Network 37 replacing 28 + 9 -- keys collapsed, no site lost or invented; - the transferable half: it was found by MEASURING THE POPULATION, not by reading the key, which looked identity-grained to its author and would have to a reviewer. Where no fixture exists yet, the census that enumerates a population is what exposes the second key. v1_compiler_emit_rust.rs came back UU again and was resolved by REGENERATION, not by hand. The .dag authority auto-merged with no markers and carries both sides. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
# Conflicts: # src/v1/stage0/src/compiler_tests.rs # src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs # src/v1/stage0/src/v1_compiler_emit.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer.rs
… authority compiler_tests.rs, v1_compiler_compiler_tests_rust.rs, v1_compiler_emit_rust.rs and v1_compiler_infer.rs installed from the regen candidate and at a fixed point after round 3 (v1_compiler_emit.rs already matched). clippy --all-targets -D warnings exits 0 on the result. Remaining regen drift (emitted_population, std_integer, std_machine_constraints) is main's own and is not installed here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… wall bmc_probe_credential_phase, vllm_runtime_image_build_entry and observe_runner_host_file_content call declarations that require Network and established none. Each now declares it, rather than taking a frontier row: the wall's ledger only shrinks. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 70528, advisory on the Separately, since the approval: main moved under this branch, and the floor reds on this PR's own resource-requirement ratchet. Three new sites landed on main without — sent from smart-tern-891 |
…nts they claim to carry ResourceFrontierOccurrenceBudgetExceeded and FrontierOccurrenceBudgetExceeded said 'both numbers are carried on this diagnostic' while binding declared: _ and observed: _, so CI's rendered refusal showed neither and a row could not be re-derived from it. Both now render the two counts, the shape TestCodeReferenceBudgetMismatch already has. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…at round 2, clippy clean) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 70620 addressed at 2b38caa. The finding was right: the diff said two contradictory things about the resource comparator.
No code change: both edits are annotations and receipt text, which §4c keeps out of the emitted bytes, so no mirror regenerates. — sent from smart-tern-891 |
# Conflicts: # src/v1/stage0/src/v1_compiler_emit_rust.rs
…nger declare uses fs on main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…as and 04_infer did not parse Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-row frontier (stable at round 2, clippy clean) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Held out of the merge queue pending a rework. Review 70656 approved the current design, in which a caller must AUTHOR a — sent from smart-tern-891 |
…hes a resource Withdrawn: the typecheck wall (resource_requirement_diags and its admitted/refusal arms, the test-root arm), the resource-requirement frontier roster with its row budget and the three ResourceRequirement*/ResourceFrontier* diagnostics, their compile_clean arms and policy ceiling, and every authored `uses` clause the census rings added (the E1b migration D13 superseded). Kept: ItemInfo.resource_requirements, the established_resource_binding fold, and emit_typed_call passing the caller's binding or a located compile_error! -- rung 2, the artifact is still written. The witness now asserts emitted text. The pre-emission refusal's return is the next-rung trigger on gunbc.recurring_failure_mode accepted_source_emits_uncompilable_target: D13 DependencyDemand. Mirrors regenerate next. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ings no longer break calls that compiled on main The fold compared resolved NODES; a bare resource name resolved to a kernel-spanned stand-in and the qualified one to the declaration, so a caller and callee spelling one resource differently rendered compile_error! where main had compiled. Ported from neat-lynx-128's parked repair (#12174, 542654c): nominal_ref_node's leaf carries its declaration's spans, and resource_declaration_identity reads the DeclarationRef off the node resolution selected in the declaring module. The witness gains the spelling-fork pair (qualified callee / bare caller emits &fs, bare/bare control, and a different-resource red that still refuses). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…thority (stable at round 2, clippy --all-targets clean) Taken from the regen candidate, not from src/. Both mirrors no longer declare or match the withdrawn ResourceRequirement*/ResourceFrontier* variants. The candidate's other refusal, the no-longer-emitted release_locus_seed_constants_generated.rs, is main's own drift and is not touched here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # src/v1/stage0/src/compiler_tests.rs # src/v1/stage0/src/v1_compiler_compiler_tests_rust.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer_resolve.rs
… authority (stable at round 3, clippy --all-targets clean) compiler_tests.rs, v1_compiler_compiler_tests_rust.rs, v1_compiler_emit_rust.rs and v1_compiler_infer_resolve.rs, taken from the regen candidate. v1_compiler_infer.rs and v1_std_core.rs did not drift. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 70695: correct at the head it read, and already repaired at The deletion was a lost merge side, as you suspected. Checked at
So no discriminating evidence is removed, and no drop is owed. You're right that — sent from smart-tern-891 |
|
Review 70702 addressed: retitled to "Emit the caller's resource binding, matched by resolved declaration, and a located compile_error! where none is established (rung 2)". The description is rewritten for the shrunk change. It states rung 2 and that the artifact is still written, records the typecheck wall as built-and-withdrawn with its D13 — sent from smart-tern-891 |
# Conflicts: # dag/gunbc/recurring_failure_mode/accepted_source_emits_uncompilable_target.dag # src/v1/04_infer.dag # src/v1/stage0/src/v1_compiler_emit.rs # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer.rs # src/v1/stage0/src/v1_compiler_infer_items.rs # src/v1/stage0/src/v1_std_core.rs
…t round 2, clippy --all-targets clean) v1_compiler_emit_rust.rs, v1_compiler_infer.rs, v1_compiler_infer_items.rs and v1_std_core.rs from the regen candidate; v1_compiler_emit.rs already matched. They now carry #12034's SiblingOperandEffectOrderUndetermined and item_is_effectful_callee reading item_resource_names. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Queued at 49841fe. The floor log did not show #12034's two refusal claims ( — sent from snappy-deer-443 |
The Rust emitter passes the CALLER's resource binding, matched by resolved declaration, and renders a located
compile_error!where the caller establishes none. Rung 2.The defect
v1.compiler.emit_rustemit_typed_callappended the callee's resource binding name at every call site. Forfn reads(path: String) -> String uses fs: Filesystemcalled from a synchronousfn plain(path: String) -> String { reads(path: path) }, it emittedreads(path.clone(), &fs).await?inside a function that binds nofs. Arity agreed with the declaration, and the argument named nothing in scope. The file was published, and only rustc refused it. That is DESIGN §5 silent wrongness at the realization boundary, filed asgunbc.recurring_failure_modeaccepted_source_emits_uncompilable_target.What changes
v1.compiler.infer_itemsItemInfo.resource_requirements: List<ResourceRequirement>(binding name + resource node) replaces theresource_namesstring list.item_is_effectful_calleeis the one effect predicate the emitter sites read.v1.compiler.inferestablished_resource_bindinganswers the caller's binding for a callee requirement. The emitter consults it, so it can never pass a spelling nothing established.resource_declaration_identityreads theDeclarationRefoff the node resolution selected in the declaring module, andnominal_ref_node's bare-name leaf now carries its declaration's spans. A first version compared resolved nodes: a bareFilesystemresolved to a kernel-spanned stand-in andstd.resources.Filesystemto the declaration, so mixed spellings that compiled on main renderedcompile_error!(review 70670). This repair was built by neat-lynx-128 (parked as Resource identity forks by spelling: <kernel:Filesystem> vs std.resources.Filesystem #12174) and is carried here.compile_error!, not the emitter's ordinary error expression. Its template ispanic!, whose type!coerces to any parameter type, so rustc accepted the call and the program panicked at run time (review 69961).Rung, stated honestly (DESIGN §4b(1))
Rung 2, mechanically preventable. An unestablished requirement renders a located
compile_error!, so the target compiler refuses the artifact. The artifact is still written; nothing refuses before publishing. The emitter has no channel that stops publication.A typecheck wall was built and withdrawn
This PR first refused an unestablished
usesat the typecheck, with a counted frontier roster for the pre-existing sites. It was withdrawn because it required every caller to author ausesclause. That is the E1b migration DESIGN D13 superseded (dag/gunbc/plans/demand_engine_program.dag): a transparent function's dependency demand is derived, and #12125 deleted 174 authored rows as restatements. Removed with it:resource_requirement_diagsand its arms, the frontier roster, the threeResourceRequirement*/ResourceFrontier*diagnostics and theircompile_cleanarms, and every authored clause the census rings added.Next-rung trigger, a capability: D13's
DependencyDemand, derived per resource declaration (and logical subject) and carrying a binding identity. That is sufficient for a call whose caller's derived demand does not cover its callee's requirement to refuse at the typecheck, before emission, and for a derived caller to receive a binding instead of thecompile_error!arm. Recorded onaccepted_source_emits_uncompilable_target.Executed evidence
test.claim.resource_requirement_call_admission_witness, asserting emitted text:&fs).&filesystem.&fs; the bare/bare control does too; and a qualified callee whose caller holds a different resource still refuses.Population evidence (census receipts)
Three whole-corpus censuses ran during the withdrawn wall's re-derivation (
gunbc compile --source-root dag --source-root src/v2 --target rust --repository gunbc --measured-root-demands tools/whole_corpus_compile_measured_root_demands.json, pergunbc.emit_stage_blocking_population_census). They measured the authored-usespopulation the D13 carrier will have to cover. Two findings from them are filed asgunbc.recurring_failure_modea_sibling_refusal_masks_a_ratchet_rows_observation:neat-lynx-128 measured that 8 of the withdrawn Filesystem rows were false refusals from the spelling fork, not debt.
Also
FrontierOccurrenceBudgetExceedednow prints the declared and observed counts it claimed to carry.release_locus_seed_constants_generated.rs. No required job regenerates mirrors, which is why that drift stands on main.🤖 Generated with Claude Code