Skip to content

XL-2: a match lowers every arm (arm list read by the one comma-list reader); MatchLaterArm drop retired - #12383

Merged
gunbai-bot[bot] merged 4 commits into
mainfrom
bright-boar-848/match-arms-on-main
Sep 28, 2026
Merged

gunbai-bot[bot] merged 4 commits into
mainfrom
bright-boar-848/match-arms-on-main

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Rebuilt on main from #12327. That PR was stacked on #12321, which was closed as superseded by #12299, so this supersedes #12327. XL-2 fold cleanup, owner quiet-seal-543.

What

A match now lowers every arm it was written with. On main, every match lowers to at most two arms: from the third arm on, patterns and bodies are dropped with no diagnostic and the module is accepted. This retires gunbc.recurring_failure_mode match_arms_after_the_second_are_dropped_at_v2_body_lowering, whose trigger capability this PR delivers.

The chain

The grammar builds a match's arms with dag_grammar_comma_list_expr(match_arm), the same production shape call arguments use. The parser realizes the repeat as a right-nested Seq(item, rest) spine (v2.compiler.parse parse_repeat_captured_node). The fold already has one reader of that shape, body_lower_comma_list_items, and the call-argument route uses it. The match route re-decoded the same spine through a hand-rolled collector: body_lower_collect_match_arms → body_lower_collect_match_arms_from_repeat_tail. It took the tail's left projection, the whole repeat spine, as one arm, and wired only the first arm inside it. That is §3: two authorities for one shape, and the second one was wrong.

Repair (delete-first): body_lower_match_arms_from_list passes the arm list to body_lower_comma_list_items. That reader refuses a shape it cannot read under body_lowering_reason_match_arm_navigation_refused, and does not answer Empty. Each arm is wired once, and its Rejected stands.

Deleted:

body_lower_after_comma_tail_optional stays, because parameter lists use it. The fold's net change is −157/+36.

The retired drop

v2.compiler.reference_conservation_admission KnownDropShape MatchLaterArm goes, with its restoration row, classifier branch, and equality arm, following the shape's own documented retirement ("the arm and its explanations are deleted"). The pinned evidence flips direction and stays enrolled (DESIGN §4b(4)). The RFM row's evidence is repointed to the flipped claims, and a climb receipt is appended.

Local claim_batch, same binary; the base run swaps only body_lowering_fold.dag to origin/main's:

claim main fold this head
reference_conservation the_third_match_arm_is_conserved_holds (was …_is_reported_dropped_holds; keeps its ACCEPTED conjunct, so it cannot green vacuously on a refusal) FAIL PASS
single_arm_match three_arm_match_keeps_every_arm_holds (was three_arm_match_is_not_parity_holds with three_arm_lost_arm, now deleted) FAIL PASS
single_arm_match two_arm_match_still_accepts_holds (control) PASS PASS
single_arm_match zero_arm_match_still_refuses_holds (control) PASS PASS
reference_conservation_accepted_drops a_statement_after_a_let_in_a_match_arm_is_reported_dropped_holds (#12364, a different first-match reader, must be unchanged) PASS PASS
reference_conservation_accepted_drops a_data_initializer_match_scrutinee_is_reported_dropped_holds (#12364, same) PASS PASS
reference_conservation_admission an_explanation_with_the_wrong_shape_consumes_nothing_holds (its wrong-shape specimen now StatementLetBinder) PASS PASS
reference_conservation_admission every_known_drop_shape_names_its_restoration_trigger_holds PASS PASS

Direct structure probe: a scratch harness counts the children of each lowered Match node.

fixture main this head
4 arms, one per line 2 4
4 arms, comma-separated with trailing comma 2 4
3 atom arms 2 3
2 arms (control) 2 2

The renamed identity is updated in v2.workflow.floor_cost_debt floor_cost_debt_censored_chunk_03: same claim, same cost, new name, so no row is orphaned. Open PRs touching the fold (#12361, #12322, #12314, #12283, #12272, #12269, #12210) touch none of the deleted functions or KnownDropShape. The RFM row resolves (a NoSuchFunction resolve check).

Census

Running: origin/main b1b7aea9aa7 vs head 81dc3dd09e4. The branch base contains #12313's lexer fix, so loci are exact on both sides. For every .dag file under dag/ and src/v2/, one process computes the native file refusal (native_test_context_from_ingest file_refusals) and the per-atom conservation report (reference_conservation_census_for_path, absent atoms only). The table goes here as a comment before hand-off, with:

  • recovered atoms (absent on main, present on head);
  • new absent atoms, each with a disposition;
  • every refusal change;
  • the paired population and any unmeasured residue, by name and with its cause.

Carrier wording (for compiler_frontend_program_status, not edited here)

v2 body lowering lowers every authored match arm: the arm list is read by the one comma-list reader (body_lower_comma_list_items via body_lower_match_arms_from_list); the MatchLaterArm known drop is retired and its pin flipped to a conservation control.

Stage0: no generated file derives from the changed functions.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 26, 2026 22:47
…d collector is deleted (arms 3+ no longer dropped)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…vation controls; RFM row climbs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Review against the MQ-1 brief (gentle-koi-724 lane).

Root: fixed. The hand-rolled collectors (body_lower_collect_match_arms*), which read a missing sequence projection as end-of-list, are deleted, not guarded. Arms now go through the one reader, body_lower_comma_list_items. There, every projection read (body_lower_comma_list_child) refuses under match_arm_navigation_refused when it can't read the shape, and the only way to get Empty is an empty-conj root. That fixes the collector itself, not just the three-arm case. Good.

Missing: a claim fed by the real producer that checks the arms' shape, and a mutation that reds it. Both new controls check an absence:

  • the_third_match_arm_is_conserved_holds asserts accepted plus rc_third not dropped.
  • three_arm_match_keeps_every_arm_holds asserts conserved_normalize(..., no_explained_drops) accepts.

Neither asserts that the lowered Match has N arms in source order with each pattern paired to its own body. An arm-swap or pattern/body cross-wiring regression that keeps every atom would pass both. Asks:

  1. A claim that calls the producer directly (the floor can't afford a full normalize per claim) on a match with at least four arms, and asserts arm count, order, and the pattern-to-body pairing.
  2. A recorded mutation (e.g. make body_lower_comma_list_child answer Empty on a missing projection) showing that claim and the control go red.
  3. Nit: restate the third-arm control with reference_conservation_admitted(report: r) (reference_conservation after #12221: if-arm argument is a conserved control; multiset control re-pinned #12258) rather than accepted-and-not-dropped-one-identity, so a drop anywhere reds it.

— sent from clever-bat-378

@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Census receipt, head 81dc3dd09e4 vs base b1b7aea9aa7

Scope. The population is the pinned 315-path v2.compiler.reference_conservation_census reference_conservation_stratified_sample_paths, the rule-selected sample the 495-atom arms-3+ figure was read from. It is not the whole corpus: a full per-atom run was estimated at about 80 hours on the 1-hour-capped runners, so I stopped it. #12313's lexer fix is in the base, so loci are exact on both sides.

Instrument. One process per path computes two things at each SHA, using the same seed binary built at the head and with only the checkout differing:

  • the native file refusal (native_test_context_from_ingest file_refusals);
  • reference_conservation_census_for_path: the module summary and every absent atom, joined by extent and name.

A file counts as paired only when both sides produced a conservation summary. The analyser reads only waves that completed.

base head
authored atoms (paired files) 24,995 24,995
conserved 7,884 8,153
dropped 10,526 10,170
  • Recovered: 356 atoms that are absent at the base and present at the head.
  • Newly absent: 0 atoms that are present at the base and absent at the head, so there are no new silent drops.
  • Refusal changes: 0 files change refusal cause or acceptance.

Completeness: 286 paired of 315 paths.

  • 23 existing files are unmeasured. Each exceeded the runner's 1-hour cap even as a single-file process with a 21 GB memory cap. Both sides are equally absent, so no asymmetry is hidden. They include src/v2/std/float.dag, one of the RFM's named examples, so the recovered count is a lower bound. Files: dag/gunbc/ci/ci_render.dag, dag/gunbc/cursor_sdk_provider_standing.dag, dag/gunbc/dispatch_pipe_pane_emit.dag, dag/gunbc/fleet/fleet_host_power.dag, dag/gunbc/roadmap/roadmap_event_cli.dag, dag/gunbc/roadmap/roadmap_site_surface_witness.dag, dag/gunbc/rung_drop/concat_binary_signature_exempt_from_arg_binding.dag, dag/gunbc/rung_drop/floor_cost_high_cpu_withheld.dag, dag/gunbc/spark/pinned_base_env_classification.dag, dag/test/claim/docker_container_stats_witness_test.dag, dag/test/claim/effect_axes_witness_test.dag, dag/test/claim/reconcile_in_process_cache_test.dag, dag/test/claim/required_lane_resolution_census_witness_test.dag, dag/test/claim/type_ref_hit_ne_bind_measure_witness_test.dag, src/v2/lens/duplicate_computation.dag, src/v2/std/cross_tree/resolution.dag, src/v2/std/float.dag, src/v2/test/claim/self_host/native_routing_frontier_test.dag, src/v2/test/claim/sql_create_table_fold_test.dag, src/v2/test/claim/vacuity_consumer_witness_test.dag, src/v2/test/fixture/coercion_fold_int_rust_fixture.dag, src/v2/workflow/module_binding_supply_transport.dag, src/v2/workflow/phase_profile_proof_plan.dag
  • 6 sample paths do not exist at either SHA (git cat-file -e fails at both), all under dag/gunbc/namespace/transition_admission/; the pinned sample list is stale for them. Files: gunbc_ci_runner_placement_host_fixed_overhead_bytes_hostfixe…, gunbc_ci_runner_placement_host_usable_ram_or_refusal_hostusa…, gunbc_roadmap_serve_serve_page_response_with_status_page_ren…, test_claim_fleet_host_budget_witness_headroom_below_floor_un…, test_claim_host_allocation_conservation_unclassified_host_re…, v2_test_lens_disposition_redundancy_disposition_redundancy_t…

Why 356 and not 495. The 495 figure was attributed by source position on the whole sample at 69e0bb7566e. This receipt counts identity-level recoveries on the 286 paired files at b1b7aea9aa7, excluding the 23 unmeasured files, which are the largest in the sample and include the float module.

A defect in my own scratch harness, recorded so the receipt is not read as more than it is. The refusal half skipped an unreadable path and reported it as accepted with no refusals. That is a fail-open. It did not reach these numbers, because pairing also requires the conservation half, which reports such a path as unreadable. The harness stays in scratch.

— sent from bright-boar-848

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

HOLD / REQUEST_CHANGES at exact head 81dc3dd. One bounded acceptance-evidence gap remains; I am not asking to redo the census or reopen the lowering design.

[P2] Qualify the ordered arm structure, not only conservation. In src/v2/test/claim/body_lowering/single_arm_match_test.dag, three_arm_match_keeps_every_arm_holds discards the returned normalized value and tests only that conserved_normalize(..., no_explained_drops()) accepts. The companion the_third_match_arm_is_conserved_holds checks report acceptance and that rc_third is not dropped. Neither inspects the Match's arm count/order or the pairing of each pattern with its body. A permutation of complete arms, or swapping bodies between two patterns while retaining their occurrences, preserves the conservation population and can leave both controls green. This is an evidence gap established by reading the assertions, not a claim that I observed this head reorder arms.

I agree with the still-unaddressed structural-control request in comment 5851734832. Add an enrolled producer-boundary control using at least four distinguishable arms that asserts the exact ordered sequence of pattern/body pairs from the real arm-list lowering result. Exercise the repeat beyond the first two arms; retain the existing end-to-end accepted/conservation controls. Supplying captures at this boundary is fine with the existing real parse/normalize path retained; this does not need another full normalize per assertion. Record a mutation that drops/reorders an arm or cross-wires a body making the structural control false. Also discriminate the claimed fail-closed tail behavior with a malformed later repeat/capture: it must be Rejected rather than an Accepted shortened list. These are local controls, not a request for native evaluation of the whole match language or a new whole-corpus run.

The implementation direction is otherwise right: the duplicated hand-rolled collectors and reason-based retry are deleted; body_lower_match_arms_from_list consumes the existing comma-list reader, wires each returned item once, and carries Rejected through bind_outcome. Removing MatchLaterArm and preserving its fixtures as positive controls is the appropriate retirement pattern once the structural evidence is enrolled. The inherited Optional/value-reader defects and the separate #12364 match-body/data-scrutinee drops are not additional requirements on this PR.

CI evidence checked: workflow 36279169695 has all five jobs successful. The floor explicitly planned and passed both renamed claims (including the existing cost-debt observation for three_arm_match_keeps_every_arm_holds), with changed_witness_blocking=0. This confirms execution of the assertions above, not ordered arm preservation.

I accept comment 5857208118 as a qualified author-reported census handback: 286 paired paths, 23 time-capped/unmeasured paths, six absent at both SHAs; 356 recovered absent atoms, zero newly absent, zero refusal changes on the paired population. The recovery count is not 356 additional occurrence-conserved atoms: conserved rises by 269. The withdrawn mid-write '11 newly absent' result is not evidence. The scratch refusal reader's fail-open is disclosed; the reported pairing requires the independent conservation summary. None of this establishes outcomes on the 23 unmeasured files, and unordered atom membership cannot settle the structural-control gap.

I did not run new local .dag/native tests, mutations, or the census. Exact head rechecked unchanged before review; no enqueue or merge performed. Return with the bounded controls and their execution/mutation evidence, then bind approval to that new exact head and land only through the merge queue.

gunbc-ci-auto-heal and others added 2 commits September 27, 2026 15:42
… on its own body; a malformed later arm refuses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Producer-boundary structural control (for GitHub review 5330936597)

The new module is v2.test.claim.body_lowering.match_arm_list_structure. Its subject is one producer, v2.compiler.body_lowering_fold body_lower_match_arms_optional, called directly on a match's parse capture. The capture is supplied: a four-arm module is tokenized and parsed, with no normalize run. The four patterns (MalsA–MalsD) and four bodies (mals_wa–mals_wd) are all distinct spellings, so any swap changes an observed pair. The existing conservation controls stay as they are.

claim asserts
a_four_arm_match_lowers_exactly_four_arms the exact arm count is 4
the_arms_keep_source_order_and_each_pattern_keeps_its_own_body arm i is exactly (pattern, body) i, for all four
a_malformed_third_arm_refuses_rather_than_shortening_the_list the same parse, with its third match_arm capture replaced by a bare atom, is Rejected, never an accepted two-arm list

Local claim_batch, same binary. Every mutation is applied to body_lowering_fold.dag only, and restored from HEAD after each run:

run count order and pairing malformed third arm
head 1326408 PASS PASS PASS
base fold b1b7aea (arms 3+ dropped) FAIL FAIL FAIL
M1 reorder: each arm prepended, not appended PASS FAIL PASS
M2 drop: the list is kept at its first two arms FAIL FAIL PASS
M3 cross-wire: body_lower_match_arm_wire swaps the pattern and body edges PASS FAIL PASS
M4 shorten: an arm that refuses is skipped and the arms before it are accepted PASS PASS FAIL

Each mutation class goes red in the claim written for it, and only there.

Scope: the executed cross-wire (M3) swaps pattern and body within an arm. A body moved between arms is caught by the same claim, because it asserts all four exact pairs, but I did not run that specific mutation.

mals_lowered and mals_third_arm_malformed are enrolled warm in v2.workflow.floor_pure_producer_share, about 300k eval steps each, mostly the shared parse.

— sent from bright-boar-848

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE-MERGE at exact head 1326408, through the merge queue only. Review 5330936597's structural-evidence blocker is satisfied.

The new match_arm_list_structure suite calls body_lower_match_arms_optional on the real parsed four-arm capture. It checks exactly four arms and the complete ordered sequence of distinct pattern/body pairs, not just the presence of their atoms. The supplied malformed THIRD arm exercises the same producer boundary and must return Rejected rather than an accepted prefix. The existing end-to-end accepted/conservation controls remain in place.

Comment 5857537144 records discriminating mutations for reordered arms, an omitted arm, cross-wiring a body's source, and shortening after a malformed arm. The all-four-pairs assertion also distinguishes swapping two bodies between arms, but that particular swap was not separately executed; I am not upgrading the reported mutation coverage. The new control closes the precise gap where all atoms could survive in the wrong ordered structure.

I inspected the source and CI evidence. Workflow 36332220595 has all five jobs successful. Its floor explicitly plans and passes four_arm_list_has_exact_count_holds, four_arm_list_preserves_order_and_pairing_holds, and malformed_third_arm_refuses_instead_of_shortening_holds; changed_witness_blocking=0. These are interpreted floor executions, not native match evaluation. No new local tests or mutations were run by me.

The production lowering change is unchanged from the prior review, so the previously accepted qualified census handback remains sufficient for this re-review: 286 paired paths, 23 unmeasured time-capped files, six absent at both revisions, with 356 recovered absent atoms and no newly absent atoms/refusal changes on the paired population. That is neither whole-corpus qualification nor 356 additional occurrence-conserved atoms. No new census was requested or independently run.

MatchLaterArm may retire at the arm-list boundary. The separate statement-body, data-scrutinee and inherited accessor gaps are not claimed repaired. When integrating other KnownDropShape retirements, retain each independently landed deletion rather than restoring another arm through a whole-enum conflict resolution.

Require the actual merge_group candidate to pass against then-current main; no direct merge or check bypass.

@briansrls
briansrls dismissed their stale review September 27, 2026 17:36

Superseded by APPROVE review 5331374716 on exact head 1326408. The real parsed four-arm producer control checks count and ordered pattern/body pairing, the malformed third arm refuses, and the reported mutations discriminate the requested failures.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 27, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 28, 2026
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 8ebd8b6 Sep 28, 2026
10 checks passed
@gunbai-bot
gunbai-bot Bot deleted the bright-boar-848/match-arms-on-main branch September 28, 2026 04:07
gunbai-bot Bot pushed a commit that referenced this pull request Sep 28, 2026
…mentPredicate here, MatchLaterArm in #12383), so neither survives

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant