Skip to content

The door's census names every file it could not read, not the first (stacked on #12218) - #12274

Merged
gunbai-bot[bot] merged 26 commits into
mainfrom
session/stern-moth-549-census-refusal-set
Sep 26, 2026
Merged

gunbai-bot[bot] merged 26 commits into
mainfrom
session/stern-moth-549-census-refusal-set

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Stacked on #12218 (base is its branch; retarget to main once it lands). Follow-up (a) agreed with neat-boar-16 after the srv1 run at 239d54d. Gen-one's emit of v2.compiler.compile refused in the census at the first service declaration it met (dag/extdeps/access/posix_effective_principal_read_op.dag), and roughly 110 files declare one. So each run revealed a single blocker.

What

  • The census records and continues. closure_ingest records each refused file as a ClosureCensusRefusal { path, diagnostics } and moves on to the next file.
  • The emission still refuses whenever any file is recorded. A declaration it cannot read may be the one a reference binds, so closure membership can't be derived (§5). The refusal joins every file's chain, in ingest order.
  • Same codec. ClosureEmissionLocated.census_refusals is rendered by closure_census_refusals_json as {census_refused: [{file, reason, at}]}, through extdeps.languages.json.
  • CLI. v2.cli.compile_cli has a new CliCensusRefused { reason, detail, text } arm: stdout is the set, stderr is the located chain, and the exit is non-zero.

One gen-one run over dag + src/v2 therefore yields the complete file-grain blocking set for gen-two (brief deliverable 2).

Evidence (all run locally)

  • v2.test.claim.self_host.closure_emission, 6/6. New rows: two unreadable outsiders give two refusal rows, each naming its own file; a clean census gives none.
  • v2_native_cli_test 18/18 and occurrence_file_attribution_test 7/7. A one-file parse refusal now arrives as CliCensusRefused, so both files' matches gained that arm with the same reason and located-detail predicates.

Next

After this lands, a srv1 run of gen-one over the tree gives the census blocking set. The declaration-grade service lowering (neat-boar-16 is dispatching it as its own lane) is expected to clear most of it.

🤖 Generated with Claude Code

Brian Searls and others added 8 commits September 24, 2026 07:56
…ved closure member by member

v2.compiler.self_host.closure_emission emit_closure_from_ingest_located:
- Phase one parses every file and censuses it (normalize_census, #12187),
  threading one occurrence allocator. A parse or census refusal refuses
  the emission, because the census must be total.
- The closure is v2.compiler.reference_closure reference_derived_closure
  (#12186) over the census index. Each member is normalized once, and its
  tree is handed back as the fold's visit payload (the fold is now generic
  in that payload).
- Every member is resolved again against members' full projections plus
  non-members' census projections, then checked to reach only closure
  members, then inferred and emitted. Each outcome is one typed arm of the
  ClosureEmission carrier.
- The carrier renders through extdeps.languages.json, the one codec.

v2.cli.compile_cli v2_cli_run emits that rendering. CliEmitted carries
closure_size and refused_count, and v2_cli_exit fails the process if any
member refused.

Why the door changes: resolution answers for the admission subject alone,
so the old door emitted the entry module only. And it lowered every
file's bodies, so dag/examples/weather stopped gen-one.

Witness v2.test.claim.self_host.closure_emission covers three refusal
directions plus a codec round trip at identity grain. Each scenario is a
shared nullary producer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ed it inside the body)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…its path

emit-build on #12218 refused the door fixture with
reference_closure_target_ownerless. The integer literal 606060 lowers to a
cons list of digit atoms, the same shape as a qualified-name spine, so
declaration_reference_path_optional read it as the path
integer_tag_digit_6.integer_tag_digit_0... . The resolver mints a spine only
for a path the symbol index answers, so the fold now takes the index and
counts a spine only when the index declares its path. An undeclared spine is
neither a reference nor descended into.

Regression: reference_closure_test's entry now declares
data rc_entry_literal: Int = 606060. A mutant that reverts the check turns
set-equality and three membership rows red (measured locally).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… sentence

emit-build: NativeCliDoorRefusalNotRendered. When any member refused, the
door exited 1 with a one-line summary, but a failing status owes the
located cause (a 'diagnostic chain:' section plus '| FATAL AT <locus>'),
the same as a closure-level refusal. CliEmitted now carries
refusal_detail, rendered by the one v2_cli_refusal_detail over the first
refused member in reach order (closure_emission_first_refusal) and the
ingest's spans. Every refusal is still its member's arm in the carrier.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er; drop the redundant index guard

- adjudicate_cli_emit_probe judges the fixture member's arm, decoded from
  the door's ClosureEmission carrier by the new cli_door_member_arm, never
  stdout as a whole. On exit 0 the emitted arm must pass the existing
  name + 606060 + rustc oracle; a refused arm under exit 0 is
  EmittedWithoutSubstance. On a refusal, stdout may be the carrier or empty
  and nothing else. The reason still comes from the rendered chain on
  stderr: only CLI_DOOR_EMIT_BODY_REFUSAL is BodyRefusalReturned, and any
  other reason is DeterminingReasonDiffers.
  Unit tests: stdout now takes the carrier shape, plus two new rows.
  native_lane_runner 32/32.
- #12220's resolver marker makes declaration_reference_path_optional read
  a literal as no reference, so the SymbolIndex-membership guard
  (cc68171) and the fold's index parameter are deleted. The 606060
  regression row in reference_closure_test stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ent trigger (review 71141)

v2.compiler.self_host.compiler_closure_emit carries
compiler_closure_emit_frozen_dissolve_on. It enumerates the six remaining
consumers by name, forbids new ones, and names the retiring event: the
cutover change that moves them to closure_emission and deletes the
module. The new module's header states that it replaces the old one and
points at the row.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
closure_ingest records each refused file as a ClosureCensusRefusal (its
path and located chain) and continues. The emission still refuses when
any exist, because membership can't be derived while a declaration is
unreadable. The refusal joins every file's chain in ingest order.
ClosureEmissionLocated carries census_refusals, and
closure_census_refusals_json renders them through the same codec as
{census_refused: [{file, reason, at}]}. v2.cli.compile_cli has a new
CliCensusRefused arm that writes that set to stdout and fails with the
located chain. One gen-two run over the tree therefore reports the whole
file-grain blocking set.

Witness: closure_emission 6/6, adding two rows (two unreadable files give
two rows, each naming its file; a clean census gives none). The CLI and
file-attribution witnesses gain the census arm, with the same reason and
located-detail predicates, since a one-file parse refusal now arrives
there. 18/18 and 7/7.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review September 25, 2026 03:49
Brian Searls and others added 3 commits September 25, 2026 04:02
…iew 71151)

The row enumerates the CLI door harness by name, and its own standard is
that a function added beside them without a row entry is the defect.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the census row checks each file (review 71156)

- closure_ingest returns ClosureCensus = ClosureGrammarUnprepared
  { diagnostics } | ClosureCensusRead { state }. A grammar that fails to
  prepare refuses the emission with no census rows. It is no longer
  ClosureCensusRefusal { path: "" }, which rendered as an unreadable
  file with an empty name.
- the_census_names_every_file_it_could_not_read_holds now requires EACH
  fixture path to be named by a row (ce_census_names), so two rows naming
  the same file fail.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Addressing review 71156 in c757148. Both findings were correct.

  1. path: "" was a fabricated value. closure_ingest now returns ClosureCensus = ClosureGrammarUnprepared { diagnostics } | ClosureCensusRead { state }. A grammar failure refuses the emission as its own arm, with an empty census_refusals. Every ClosureCensusRefusal is therefore a file that was read and refused, and no JSON row can carry an empty file name.
  2. The row didn't discriminate a duplicate. It now requires each fixture path to be named by some row (ce_census_names), in addition to the count of 2. So two rows that both name unparseable.dag fail.

closure_emission passes 6/6 locally. I did not run a mutant that duplicates a row. The predicate now needs both distinct paths, so a duplicate can't satisfy it.

— sent from stern-moth-549

Brian Searls and others added 13 commits September 25, 2026 07:25
…nsus; identity-grained carrier witnesses; the probe verifies the carried cause; exact frozen-consumer census

1. Fail-open fixed. The census refuses the second file that declares a
   module identity (closure_census_duplicate_module, located at its
   module node). closure_file_of returns exactly one file or a typed
   refusal and never drops a tail. Each member resolves in a singleton
   context where resolve_duplicate_module_name cannot fire, so the wall
   lives in the census, which sees the whole population. Witness: two
   files, one 'module v2.test.ce_duplicate', independent declarations.
2. The direction-1 witness requires EXACTLY ONE arm for the entry, the
   member and v2.std.logic, and none for the outsider. The codec round
   trip compares the ordered member identities, and row by row each
   module identity plus exactly one of emitted/refused matching its arm.
3. The probe reads the fixture arm's typed reason from the carrier and
   requires it to equal the stderr rendering (new
   CarrierContradictsRendering). The verdict is decided from the carried
   reason, and an emitted arm under a refusal also contradicts.
   native_lane_runner 34/34.
4. The frozen declaration now splits direct consumers (driver,
   frontier_probe, derisk test, body-refusal test, product_receipt_stage
   by type), transitive consumers (product_receipt_stage via the driver)
   and live citations (the failure-mode and rung-drop rows). It drops
   v2.test.execution.self_host_compiler_closure_emit, which reads only a
   static record. namespace_graft's consumer audit and normalized_tree's
   frontier comment now name the new route.

closure_emission witness 5/5 locally.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…im no longer decides when stdout is written

v2.cli.compile_cli v2_cli_outcome_text decides the text: empty for a
plain refusal, the ClosureEmission carrier when a member refused, the
census refusal set when the census refused. The rendered main printed it
only on ExitSuccess, so the failing-arm carrier never reached stdout
(measured on srv1: 0 bytes on the first full gen-two census run). That
was the shim making a decision the fold owns. Both arms now write the
text. Edited in src/v1/05_emit_rust.dag and in its generated stage0 copy
together.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ure-arm stdout) into the census refusal set

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…fold's text once, before the status dispatch

Side-chat REQUEST_CHANGES at 751416d:
1. adjudicate_cli_emit_probe: once stderr renders CLI_DOOR_EMIT_BODY_REFUSAL,
   an empty stdout (no carrier) is the new MemberRefusalCarrierMissing and
   never BodyRefusalReturned. A member refusal is CliEmitted, so it comes
   with every member's arm on stdout.
2. Control a_body_refusal_without_its_carrier_is_not_the_pinned_arm
   (status 1, empty stdout, located body-refusal stderr). The existing
   regression row now supplies the carrier.
3. The generated main (src/v1/05_emit_rust.dag
   emit_native_cli_driver_main_rs and its stage0 copy) writes
   v2_cli_outcome_text once, unconditionally, before matching
   v2_cli_exit. The fold alone decides emptiness, and no per-status write
   can drift.
4. Control the_cli_main_writes_the_fold_text_once_before_the_status_dispatch
   over the generated source: exactly one write, preceding the dispatch.
   Measured red with the write moved into the success arm.
native_lane_runner 36/36.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…door

Resolved: the door emits through cli_emit_target_model(t: target); the
imports are unioned; CliUsageRefused sits beside CliEmitted in the CLI
and its witness; the generated main keeps the single text write before
the status dispatch. native_lane_runner 36/36, v2_native_cli 26/26,
closure_emission 5/5.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…CensusRefused beside CliUsageRefused

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ew 71289)

the_census_refusal_set_renders_one_row_per_refused_file_holds parses
closure_census_refusals_json back through extdeps.languages.json and
requires exactly one row per refused file, each naming its own file with
a non-empty reason. closure_emission 8/8 locally.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ain's frontier-ratchet enumeration with cli_door_member_arm; stage0 mirror taken from main pending regen)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ote --required-regen; second pass regen2=0, fixed point fp=0)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the emitted main prints (#12184 made it required); control that a marker without it refuses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ut requiring Debug

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… ce_member_emitted/ce_member_refused (review, §3c)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Base automatically changed from session/stern-moth-549-door-closure to main September 26, 2026 19:42
gunbc-ci-auto-heal and others added 2 commits September 26, 2026 19:45
…l set

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r mirror taken from main pending regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 8c4374b Sep 26, 2026
5 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/stern-moth-549-census-refusal-set branch September 26, 2026 23:48
@briansrls
briansrls restored the session/stern-moth-549-census-refusal-set branch September 27, 2026 00:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants