Text crossings unfold or refuse: exact-representation text compat (XL-0T ruling B) - #12512
Conversation
…-0T ruling B)
Kernel String is host text and a corpus-declared FreeMonoid<Char> is a
code-point sequence. One classifier, v1.compiler.coercion
text_representation_of_type (std.coercion TextRepresentation), is now read by
the corpus compatibility relation, call arguments, declared returns and data
initializers, builtin arguments (previously admitted untyped) and the Rust
renderer, so a pairing the checker admits is one the emitter realizes with
one carrier.
- A host value at a code-point-sequence call argument takes the Unicode
scalar unfold as a typed node (scalar-string `chars`, typed as the
destination), gated on the existing literal_homomorphism_rows
UnicodeScalarSequenceUnfold row. Every other crossing refuses, located.
- Call arguments are typed against the declaration-bound formal, not the
parameter spelling re-resolved in the caller: the caller-re-resolution
escape of gunbc.rung_drop text_boundary_identity_wall is closed.
- 71 modules imported std.string_type { String } while treating the values
as host text (a nickname); the imports are deleted. std.string_type keeps
its two functions over the kernel String and loses its structural alias.
- A kernel spelling no longer resolves through the global bare fallback,
which the deleted duplicate had been masking.
- string_eq over two host operands becomes == in five src/v2/lens modules;
jq's host string_join becomes concat.
Evidence: test.claim.text_boundary_identity_wall_witness_test (16 rows) and
the flipped restoration probe in self_host_structural_text_witness_test.
Whole-corpus compile, base seed vs head seed over the same tree: 0 new
blocking rows, 4 removed. The drop stays Standing, narrowed to callable
values (eq: string_eq) with a restated trigger.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The unimported-bare-provider gate judges every file a change touches, and deleting their std.string_type import touched these three. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Claim A/B, base
No row goes true → false. Head-side neighbours: Whole-corpus compile, base seed vs head seed over the head tree: 0 new blocking rows, 4 removed. The per-file native census on srv1 is still pending. |
…; fix two emit-classifier defects
Per neat-boar-16's ruling: `type String = FreeMonoid<Char>` in std.string_type
stays, annotated as a declared frontier with no importer, pending the seed
kernel-names ruling; the structural roster entry, the symbol-identity sibling
row and the defork census row are restored. Its two lexicographic functions
are deleted and their eight callers use host String `<` (rfc3339's three-way
match becomes `<`/`==` arms). A new interpreter control asserts that host
String order is code-point order on pairs a UTF-16 order would flip.
Two defects in the text classifier, found as 80 E0308 in the emitted
self-host compiler (emit-build):
- a qualified `v2.std.text.String` spelling took its last segment and fell
into the bare-String arm, so fields rendered host `String`; a qualified
spelling is now classified through its module;
- a bare String parameter in a module importing v2.std.text { String } was
read through the by-name peel, which finds the imported alias; a declared
host type now wins over the peeled views.
Each has an emission regression control. The emitted self-host crate is now
byte-identical to base's and builds.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
AmbiguousBareNameRead counted a bare String as contested between std.string_type and v2.std.text in the 39 modules whose std.string_type import this change deleted. A kernel or container spelling binds the substrate; the wall now reads is_substrate_vocabulary, the rule every other bare-name producer already reads. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall Heal-Candidate-Run: 36400142162
…guity wall Two claimants declare String, the reader uses String bare in a service exit arm (the shape the floor refused in 39 extdeps modules). The head binary accepts the scope; the base binary refuses it as AmbiguousBareNameRead. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/design-rung-drops.md # src/v1/stage0/src/v1_compiler_emit_rust.rs # src/v1/stage0/src/v1_compiler_infer.rs
|
Re the advisory on the — sent from royal-newt-820 |
A top-level fn named response (from #12421) made the unimported-bare-provider gate read every service declaration's response block as a bare use of it in the extdeps files this PR touches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
symbol_list_text declares the kernel String (bare String beside an import of
v2.std.text { String }) and built it with v2.std.text string_join, a
code-point sequence; the text wall refuses that return. The consumer is host
concat, so the join is the host one.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # docs/design-rung-drops.md # src/v2/test/claim/execution/self_host_candidate_generation_stage_verdicts_test.dag
|
Re review 72252 (REQUEST_CHANGES): the finding stands. The fix is at the resolver: record the resolved — sent from royal-newt-820 |
A user FreeMonoid record over a user Char admits host text on base and head (container-template recognition by spelling), and the current classifier fabricates admissions for a user List<Char>. The capability that closes the first is named; the second is why the classifier is being re-keyed on declaration identity. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ugh to base (WIP, paused) Replaces the spelling-keyed classifier (review 72252) with v1.compiler.infer_env text_representation_by_identity: host text is the kernel String mint, a code-point sequence is std.algebra FreeMonoid over std.types Char by declaration identity (through aliases; refinements have their base's representation). Identity is read by declaring span, qualified name, or the declaring module's own facts -- never by re-resolving a spelling in the comparing site's scope. The relations carry the TypeEnv; the Rust emitter keeps its base provenance-keyed answer (byte-identical crate). Unidentified sides make no text verdict and base compatibility decides; each such site emits the advisory TextRepresentationUnidentifiedAtBoundary, the instrument for the restated drop (trigger: the resolver records declaration identity on every type reference; staged as node://adhoc-207dd6ac-6d2). Measured before the pause, against base 02360ee over the same tree: whole corpus 0 new blocking, 1 base refusal admitted (the ruling-B unfold at dag_arrow_lambda_witness_test:30); emitted self-host crate byte-identical; text_boundary_identity_wall_witness_test 21/21; regen first_generation_equal. NOT yet done: head-side base-vs-head claim comparison, and docs/design-rung-drops.md is not regenerated for the edited row. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 72405 (REQUEST_CHANGES): both findings are correct, and this head is deliberately unfinished. I'm paused by operator order (capacity), so no regen or build is allowed, and each fix needs one. On resume:
— sent from royal-newt-820 |
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall Heal-Candidate-Run: 36498270119
|
Re review 72427. Finding 1 (unidentified sides fall through to base compatibility). This is deliberate and was ruled, not an oversight: option A, approved by neat-boar-16 (the v2 Foundation manager) and conditioned by wise-dove-693 after the refuse-everything version was measured. Refusing every unidentified node gave 176 -> 3807 blocking whole-corpus, 3632 of them false refusals of correct host-text code, because most v1 type references carry no readable declaration identity yet. A false refusal is the other §5 failure (a fabricated verdict). What keeps A from being an absorbing fallback is measured, not asserted. Against base 02360ee over the same tree: 0 new blocking rows and no base refusal admitted by the unjudged path. The one base refusal head admits is the sanctioned ruling-B unfold at dag_arrow_lambda_witness_test:30. So the fall-through never widens past base, and identified crossings refuse. The population is a declared §4b(3) drop on Finding 2 ( — sent from royal-newt-820 |
|
Re review 72427 on 'unidentified -> base compatibility': reaffirmed, on one condition. Why it isn't the absorbing fallback of DESIGN §5: that trap is a failure arm that WIDENS what is admitted and hides the deficit. Here the head refuses a strict superset of base (measured whole-corpus: 0 new admissions, no base refusal admitted by the unjudged path), so nothing is admitted that main doesn't already admit. And §5 names this case as a neighbour, not the pattern: 'a deliberate interim fallback that is loud, budget-bounded, and lands with its dissolution trigger'. It is declared as a §4b(3) rung drop whose trigger is the capability (the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures), owned by node://adhoc-439a4122-576. The condition is 'loud': the unidentified population must be COUNTED and located on every run, as a typed per-crossing line or a census the drop row cites, so the deficit ranks for fixing and can't go silent. If that count isn't emitted today, add it in this PR. Your second finding (the unguarded 'none env' skip) should be fixed structurally, as royal-newt-820 is doing. — sent from neat-boar-16 |
…427 finding 2)
node_type_compatible / node_type_equals / node_type_equals_core and the
index/slice access checks take TextJudgment = TextJudgedIn { env } |
TextNotAsked { reason }, so every call site that skips the text-identity
judgment names why (variant-field summary, callable-component residue,
synthetic witness nodes) instead of passing an absent env.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 72427, finding 2: fixed in 4129275. The text judgment is now a coproduct, |
Merges main (#12592 made v1.compiler.infer_env type_reference_declaration_reading the single type-reference identity derivation). text_representation_by_identity now reads identity only through it; authored_reference_reading, AuthoredReferenceReading and authored_declaration_of_type_node are deleted, so there is one derivation. The drop row names TextRepresentationUnidentifiedAtBoundary as its one producer and says why carrier_realization_census (authored positions, not use-site boundaries) is not. The 10 modules main added with import std.string_type { String } since the merge-base get the same disposition as the 71 (import deleted); node.dag's conflict resolved the same way. Stage0 regenerated to fixed point. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rated
xorriso.dag's re-added import std.string_type { String } takes the same disposition
as the other 81 (import deleted). Hand-maintained stage0 files re-merged three-way;
generated stage0 regenerated to fixed point. Text wall claims 21/21 on the new seed.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
srv1 receipt job for c04392e (frozen head); base origin/main 785934aClaim roster: 180 files, 2801 claims. sha256 of the list below = cedcdde40aaa425a7e41e396d84208a102a15143424865c4dcd36ab585f320f2. — sent from royal-newt-820 |
…lared as a stall (review 72772) - gunbc.rung_drop text_boundary_identity_wall opens with its current standing (identified crossings structurally guaranteed; two remaining populations: callable-signature crossings and the unidentified population). The 2026-08-30 declaration is kept as labelled history. - gunbc.guarantee_stall text_carrier_render_not_keyed_on_identity_stall: the Rust renderer's provenance-keyed is_host_text_carrier_type is a second authority for 'is this host text'. Nothing fell, so it is a 4b(2) stall (current Mitigatable, ceiling StructurallyImpossible), with its population and a trigger that names the capability (render paths read the classifier through the env they were checked in, sufficient to delete it with no fallback arm). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 72772, both findings fixed in 0f67a60.
— sent from royal-newt-820 |
…bc sha256 08f520bec5a7, srv1)
…tsFixed (floor RosterStale: #12910's collect_reference_sites no longer reports the pair in these PR-touched files) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ebt rows; rung-drops taken from main pending regen) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…efused (review 74123) std.coercion TextRepresentationUnidentified and 04_infer's unfold note claimed a refusal the code does not perform: text_representations_cross answers false for an unidentified side and text_unjudged_advisories emits only the advisory, so base compatibility decides. Restated at the true standing, bounded by gunbc.rung_drop text_boundary_identity_wall and its trigger. Annotation-only (DESIGN 4c): no semantic or generated-byte change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 74123 (REQUEST_CHANGES): agreed, that annotation was rung inflation in the compiler's self-description (DESIGN §4b(1)). Fixed in 455dcd8.
|
…p 5 more std.string_type imports main added (playwright, gcp, gcp/sts, tailscale/acl_api, rfc3339 string_lex_compare -> host <); stage0 infer mirrors taken from main pending regen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ge (claim_executor --required-regen, claim_executor sha256 c6d38a43…, rounds 1==2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#get as NotAReference; take main's rows) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tage0 to fixed point Conflicts: src/v1/04_infer.dag import lines only (union: the PR's text vocabulary from std.coercion + main's kernel_grounding_rows). Main's produced_is_kernel_grounded_carrier_or_its_alias admit arm auto-merged ahead of text_crossing_by_identity in direct_call_arg_type_mismatch; it fires only when the formal is identity-matched to a kernel_grounding_rows carrier (sole row: std.nat Nat), so no String crossing is admitted before the text wall judges it. Ledger appends kept on both sides; generated stage0 regenerated (main-built claim_executor, then fixed point at round 1); docs/design-rung-drops.md regenerated by docs_projection_gate regen. No new std.string_type imports. Walls: text_boundary_identity_wall 21/21, bare_name_ambiguity_wall 10/10. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- structural_realization_bindings: take main's Peano fixture row and kernel_grounding_rows; the cut's deletion of the Boolean literal row and the connective-row family stands. - emit_rust: a type declaration realizes as a native alias (Bool, this cut) or a kernel- grounded decl (Nat, #12846) before falling back to the connective emission; the use-line filters keep both exclusions. - defork census: the open Nat/Bool row goes; both are in defork_census_resolved. - peano test: main's StructuralNat fixture, without the connective_rows argument or the BooleanUnfold arm. - realize_advisory_soundness: deleted on main (#13016), stays deleted. - Import lines: main's side, with Bool/True/False removed from v2.std.logic imports. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cker imports; mirrors and rung-drop docs from main, regen follows Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ernel String; Unit imports kept; fleet witness names VerdictAbsent Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… v2.std.text String The two string_eq(symbol_lexeme(..), <v2.std.text String>) sites refused under the #12512 text wall (pre-existing on main; the Bool-import edit put this file under the floor's changed-file judgment). node_contains_atom_text had no callers and is deleted. decl_contains_atom takes the atom as a Symbol and compares identities with symbol_eq; its one caller interns the row the way the file's fixture already does. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ation-local simplifications (row five is the identified foreign-formal unfold shape), a new identified site unfolds or refuses, and the emitted-crate build discriminates classes A and C only Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the #12512 text-crossing precedent) The List cut gives the any() predicate's binder a resolved element type, so the checker now identifies both sides of string_eq(a: symbol_lexeme(..), ..) and refuses the host/code-point crossing #12512 walls. Compare as #12512 did in v2.lens.module_graph: ==. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#12951) * Regenerate docs/design-rung-drops.md after merging main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: the base arm runs only the reached claims whose head can block reach_head_cannot_block is derived from claim_differential_blocks over every base arm. A passing head never blocks, and a head where the claim is no longer declared is a removal under every base, so neither is run at base. The base arm then runs only the claims that FAIL at head: 60 of 1481 for a one-line v2.std.node edit and 18 of 240 for #12582's change (srv1, 2026-10-01), about 25x less base work. An all-passing reach spawns no base process. Controls: a_head_passed_claim_is_never_run_at_base_and_never_blocks (Rust, real model: the partition sends only the failing head to base, and a passing head blocks under no base) and only_a_failing_head_needs_the_base_arm (.dag). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitted-package join also matches canonicalized paths, so a symlinked crate dir cannot undercount (review 73526) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: the base-arm budget is born typed Milliseconds (review 73528) ReachDifferentialStanding's DifferentialBlocking carries base_arm_wall_budget: Milliseconds (std.types) instead of base_arm_wall_budget_ms: Int, and the host wire reach_differential_blocking_budget returns Milliseconds, so the unit is the type's and not the name's. The branded value reaches the host as Value::Int, which the existing non-negative match unwraps; any other shape still refuses. The sibling required_floor_claim_wall_safety_limit_ms stays as existing debt, not widened here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: per-identity base verdicts; an unmeasured base blocks only when no roster declares the claim red A non-verdict base outcome (budget, panic, host tool or effect, not attempted) is now not_measured for that identity alone; the other reached claims keep their verdicts (srv1 replay 4d79fc6: one BudgetInterrupted claim voided all 60). Only instrument failures refuse the whole arm. reach_claim_verdict takes the claim identity. An unmeasured base on the declared main-red roster (floor_expected_red_roster, joined by identity) is a counted base_not_measured_rostered finding that does not block. On no roster it BLOCKS as base_not_measured_unrostered (deep-ferret-305 ruling, 2026-10-01). A base verdict decides as before. Control: an_unmeasured_base_blocks_only_when_no_roster_declares_the_claim_red (.dag: rostered reports, unrostered blocks, a base verdict still decides). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: planned on the merge group only (operator ruling 2026-10-01), modeled, announced when deferred, naming what newly failed - v2.workflow.floor_subject_seed reach_planned_for_event decides, over the event the runner reads through the authority that chose its diff window, whether reach consumers are planned: ReachOnMergeGroupOnly, compared against extdeps.github.actions github_event_name_merge_group. This is the phase scoping DESIGN puts in the binary, not the workflow YAML. An unreadable event refuses on CI (ReachEventUnreadable) rather than silently deferring. - On any other event no reach consumer is planned or executed (PRs +0), and the floor prints phase=reach-differential state=deferred_to_merge_group with the count it would have reached. - A blocking regression or failing new claim prints [floor-reach-finding] NewlyFailedAtHead identity=..., so a dequeued author sees what broke without rerunning. Controls: only_a_merge_group_plans_the_reach_differential (.dag, both directions) and a_pull_request_defers_the_reach_differential_and_a_merge_group_plans_it (Rust, real rule plus the deferral line). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR: enumerate the three qemu-host-observe readiness arms main added since (census PR1/3) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: blocking verdicts are a typed outcome field the adjudication names, not free text in failures neat-boar-16's srv1 control (2026-10-01) showed blocking=8 but no per-identity adjudication line for them. RequiredFloorOutcome gains reach_differential_blocking: Vec<(identity, differential)>. required_floor_outcome_is_clean requires it empty, and required_floor_measurement_blockers adds one blocker per identity with cause reach_differential_<differential> (regressed, new_claim, base_not_measured_unrostered, refused). A refused base arm records every claim it left unjudged as base_arm_refused. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: both main-red rosters; a non-verdict at head is not_measured, never failed; one shared test pool - claim_on_declared_main_red_roster joins floor_expected_red by identity AND gunbc.explicit_witness_admission's known-red rows by (entry, function), through that roster's own explicit_witness_admission_is_known_red. On the srv1 control rerun three known_red_probe map_literal claims had blocked as unrostered; they now report. - The head standing uses the base arm's classifier (base_standing_of): a wall interruption at head under load is not_measured, verdict head_not_measured, never sent to base and never read as a regression. It was matches!(Pass), which made a passing base plus a loaded head a false regression. The floor's own interrupted_before_verdict rule still refuses such a run. - The base-only residual is named beside the rule: an unrostered claim whose base lands within load noise of the 8 s hang guard dequeues load-dependently (loud, named). Its trigger: the hang guard gets its own typed refusal and a much larger declared value through one plumbing for both arms. - reach_base_standings tests share one pool (test_roots): the process-global shared index holds a single resident pool, and the fixture test's extra root made test order decide a SharedIndexSecondResidentPool panic. Controls: an_unmeasured_head_is_not_a_regression (.dag); the roster control extended with the explicit-admission arm; the partition test with a not_measured head. Rust 5/5, .dag controls true, clippy clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: locate floor runtime-error rows; typed host IO refusal * Floor runtime-error rows carry message + raising declaration; host write failures are a typed IO refusal Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * RFM: portable value map order is process-random (RandomState HAMT iteration; Symbol hashed by address) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Portable map entries in canonical content order; value_hash hashes variant names by spelling; RFM row scoped by the iteration and value_hash censuses, with the DefaultHasher residual Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * emit-host transport read failures are HostIoFailed too (Cargo config read, tool canonicalize/read, cold receipt read, cache evict); probe spawn via host_tool_spawn_failure Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Review 73653: seed-growth justification for the canonical-order Rust; the row states its controls are off the merge path Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Canonical order: floats by IEEE 754-2019 totalOrder (f64::total_cmp), not raw bits, which invert negatives; control floats_order_by_ieee_total_order Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Six ungated main reds re-derived; three entries admitted by importing LiveTreeDisposition (1)(2) live_deploy.emit sudoers claims: the needle is now the install's own node (gunbc.ci_deploy_sudoers deploy_sudoers_elevated over the fleet visudo row) rendered by the same serializer. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). The two probe negatives are deleted: unmatchable under quoting, and since #12168 those probes are emitted on purpose after the install. (3) twin claim: count equality replaced by an identity join on artifact kind, host singletons (fabric storage + #12747's approval broker front door) subtracted by the functions that decide them. (4) CPUQuota grant: sudoers side read through sudoers_argument_word (escape since #12563). (5) tasks verdict: bare `Absent ==` never named the ConvergeVerdict arm; typed match + a Drifted discriminating conjunct. (6) runner_lifecycle: fabric rows from srv3/srv4_fabric_first_slot, each controlled by the slot below it on its own host (srv4-06 is fabric since 2026-09-18). Admission: build_cache_endpoint_observe, ci_budget_tree_witness, host_allocation_conservation import v2.std.live_tree (the #12540 class #12819 fixed once); variant rows retired ImportsFixed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * ci_budget_tree_witness: three live-tree reds were stale premises; re-derived from the producers witness_live_is_fail_closed asserted the Unestablished arm while srv1 now resolves ReservationBytes; it asserts each arm's relation over session_reservation_bytes(srv1). witness_srv2_symmetric_to_srv1 assumed equal RAM (srv1 is 512 GiB since 2026-08-22; usable RAM per host since #11625); it asserts the pools differ by exactly the RAM gap. witness_srv3_outbudgets_srv1_by_exactly_the_overhead_gap missed the 1,392,640-byte usable-RAM difference; gap = overhead gap + RAM gap, both read from the producers. Removed from floor_expected_red_chunk_live_tree_admission (they now pass). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Floor: unimported-bare-provider standing judged over the whole pool, not the diff; census fixed The diff-scoped standing check let #12540's new pairs in untouched files through while claim_batch's entry route refused them. The floor now judges every pool file (13.6 s over 7,175 files on the warm index, measured). Census at this base: 172 Unrostered + 16 RosterStale. Fixes: 167 pairs import their declared provider (138 files; no new import cycle), 5 bare `ends_with` calls that bound to gunbc.rust_item_scan's private helper use the builtin .ends_with(suffix:) method instead; 16 + 344 rows whose pairs the imports dissolved retire as ImportsFixed. Re-census: zero refusals. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * std.algebra: TotalOrder<T> is the one compare law; OrderedRing and Field compose it (WIP) * Interpreter: one canonical content order (ContentView over Value and PortableValue); map Display/Debug canonical; sort_by admits only emitted-agreeing keys; cmp_values deleted (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Canonical render order: emitter refuses map rendering typed; to_string classified CanonicalOrder; two-process, kind-rank, totalOrder and carrier-differential controls (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Rows: RFM rendering receipt and per-path rung; spelling stand-in on variant_owner_identity_stall; seed-growth row extended (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Witness: emitted map rendering refused typed; to_string classified CanonicalOrder by the gate route (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Gate comment names the phase line instead of transcribing its measurement; phase line carries standing_ms (review 73712) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v2: production list order from map_keys -> sorted_map_keys (target_model supplemental-bound and representation-choice nodes, rust_crate_partition first-unknown module, legacy_binding_observation expected ids) The #12890 warm-row specimen: rust_classical_not_ingested_target_model_staging varied per process because target_derive_supplemental_generic_bound_requirement_nodes_for_contract built its child list by folding map_keys (HostUnspecifiedOrder). Keys are Symbol/ModuleId/Int, all admitted by sorted_map_keys, whose order is identical in both realizations. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop determinism_transitive_reachability: population names the unjudged production corpus; receipt for the six map_keys folds found by the #12890 specimen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitter: a single-field anonymous record literal matching 2+ structs refuses instead of emitting the bare value; VersionScheme literals name their type; revert stage0 files swept in by an interrupted regen std.algebra TotalOrder gained the same single 'compare' field as extdeps.version VersionScheme, so find_unique_struct_name_by_fields stopped being unique and '{ compare: f }' emitted 'f' -- a fail-open arm (DESIGN section 5). It now refuses exactly as the multi-field arm does; the three VersionScheme literals carry the nominal type that remedy names. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Split the two cost-debt-rostered sudoers claims out of this PR The floor's changed cost-debt edit judgment lexes the whole 125 KB emit_test.dag at base and at head per identity in the interpreter; with these two identities changed, site projection ran past the 90-minute cap (run 36856989404). Their fix moves to its own PR, held on that floor defect. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * live_deploy.emit sudoers claims: needle is the install's own node; unmatchable probe negatives deleted Split from #12905. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitter annotation moved to module-item grain Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Retire the one row main's merge made stale (ownership_movable_test#Read); re-census over 7,193 files: 0 refusals after this Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 (std_algebra, std_primitive_projection, v1_compiler_emit_rust); control: supplemental-bound requirement nodes emit in canonical parameter order (the #12890 specimen at its cause) regen-round-cost converged in one stage, changed_paths=3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Floor cost-debt edit judgment: one lex per changed file, shared by every identity in it v2.workflow.floor_cost_debt_edit judged each changed cost-debt witness in its own call, and each call lexed the whole base and head file, so a file with k changed witnesses paid 2k lexes. With two changed witnesses in the 125 KB emit_test.dag, site projection ran past the floor's 90-minute cap (run 36856989404). The wet entry is now cost_debt_changed_witness_ceilings_at_base, called once per file with every changed cost-debt function in it. It lexes base and head once, reads the base resolution once, and selects each declaration from those streams. The host prints `[floor-cost-debt-edit] judgments= changed_identities=` as the control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Pin PlannedAsReachConsumer as not a changed-witness selection in the sublane join Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * clippy: redundant closure in the per-file ceiling call Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v2.std.integer: int_ordered_ring composes order: TotalOrder (OrderedRing no longer restates compare/lt/le/gt/ge) Control supplemental_bound_requirement_order: requirement_nodes_are_emitted_in_canonical_parameter_order returns true, and false with map_keys restored at the outer fold (discriminating). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md (docs_projection_gate regen) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a raw string literal opened in a body is tracked; an unattributed refusal names its cause The census could not judge gunbc#12886 because the scanner tracked raw string literals only when opened on an item header. A `let src = r#"...` fixture in a body let its own column-zero `}` close the fn early, and its `"#;` then refused the file (interp_recorded_fixture_witness.rs:458). The same shape put 5 of the 9 hand files on main out of reach. An item ends at its own closing brace, and a brace inside a literal is not one: every item line is now read for an unclosed raw literal (token-start `r`/`br`, terminator from its own hash count). Only a header-opened literal's end may end the item. v1_interpreter.rs was never unscanned: the scanner reads it whole (1040 items, 36 macro regions) and attributes #12814 completely. #12886's v1_interpreter refusal is a line inside `thread_local!`, the declared macro-item ceiling, but it was reported with the out-of-range sentence. The refusal now names which cause fired. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md after merging main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * RFM: anonymous_record_resolved_by_field_names_guesses_on_ambiguity (the emitter one-field fail-open TotalOrder exposed) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: DifferentialBlocking per the operator's 2026-10-01 option-B ruling Base-arm budget 625200 ms: the largest srv1 base arm measured (312.6 s for 22 identities, loaded host) times 2 for load variance; an arm over it still refuses with BaseArmOverBudget. PRs still defer to the merge group. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: an expression-bodied item ends at its own semicolon; a backslash-continued line is string text A `static NAME: T =` header that rustfmt continues before its initializer puts the declaration's `;` one indent deeper, so the item stayed open and swallowed the following items until a column-0 `}`. That was a SILENT mis-attribution: cli_run.rs `static PROVIDER_BOOTSTRAP_STORE_SKIPS` absorbed `fn record_provider_bootstrap_store_skip`. Across 22 hand files, about 125 items were never recorded, 7 of them in v1_interpreter.rs (record_builtin_time_inclusive, canonical_symbol_spelling, ...). An item whose header ends at `=` now ends at the continuation-indent line that ends the statement. A line after a trailing backslash is string-literal text at whatever indent its author chose, never structure. The line that ends such a literal with `;` ends an expression-bodied item; ExprBody is read from rust_item_forms, not listed here. No item key is lost in any hand file, and the refusal count is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_host_observation: carry the refusal from the one attribution; RawLiteral replaces terminator+flag Review 73783 found that change_lines_unattributed reduced each attribution to a line number, and unattributed_line_detail recomputed it. That was the same fact derived twice (DESIGN §2), and the recompute needed two arms that wrote a fabricated sentence (DESIGN §5). change_lines_unattributed now matches once into RustLineRefusal, which has only the two refusing arms (LineInsideUnnamedMacroBlock, LineBeyondTheFile). The detail is read off that value, so the record and its sentence cannot disagree. Also from the review: ItemScope's raw_terminator + raw_opened_on_header could represent "opened on the header with no terminator". They are now one variant, RawLiteral = NoRawLiteral | OpenRawLiteral { terminator, opened_on_header }. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * std.algebra: the TotalOrder comment names the real (seed-retained) realization instead of a symbol that does not exist (review 73794) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitted ordering keys fail closed: v1_rt CanonicalOrdKey (String, i64, bool only) bounds sorted_map_keys and sort_by; sort_by drops partial_cmp(..).unwrap_or(Equal); enrolled one-order claims; seed-growth trigger names the capability and first consumer neat-boar-16 conditions for executed agreement on #12925: (1) enrolled claims test.claim.canonical_order_enrolled_witness; (2)+(4) trigger at capability grain naming the first real consumer; (3) the emitted frontier refuses non-admitted keys typed (on_unimplemented message). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a static inside thread_local! is a named item, by upstream citation extdeps.rust.std_thread_local records std's thread_local! as the pinned 1.93.0 docs state it: the macro "wraps any number of static declarations", and "Publicity and attributes for each static are allowed". The scanner reads a thread_local! block as a scope that admits exactly those lines. Each static is an item of the enclosing module, so a change inside one is attributed to it by name. Anything else in the body refuses, and so does a one-line thread_local!(...), which this reader cannot split. Every other macro stays at the declared macro-item ceiling (macro_rules! controls). On #12886's tree the census now observes the change completely: JSON_ENCODE_NESTING is an added static, and the only unreadable hand file left is phase_profile.rs (extern "C"). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a header at the open item's own indent refuses; a trailing comment does not hold a declaration open The swallow class becomes structural. Whatever leaves an item open past its end -- a continued initializer, a trailing comment, an ordinary multi-line string, or a construct not yet met -- next meets a sibling item header at the open item's own indent, and no item body puts one there. scan_step now refuses at that header instead of reading it as body. Under the prior reader that refusal fires at the original swallow sites in cli_run.rs and v1_interpreter.rs. A second instance surfaced by the same measurement is fixed. A one-line declaration followed by `// comment` did not end in `;`, so it stayed open and swallowed the next const (resolved_graph_cache.rs PART_DESCRIPTOR_LEN over V3_HEADER_LEN). A `//` with an even quote count before it now starts a comment. Files the recurring failure mode as its general class, gunbc.recurring_failure_mode census_instrument_silently_drops_items: a census instrument whose parser silently drops items reports a smaller population, and a short count reads as success. Its distinguishing fact is that a swallowed item's lines ARE attributed (to the swallower), so a line-coverage join passes. The violated join is header coverage. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 (whole-compiler rebuild: runtime CanonicalOrdKey reaches v1_compiler_stage0_crates) --regen-round-cost refused with WholeCompilerRebuildRequired (partition generation authority changed), so candidates were emitted with --required-regen, installed, the whole compiler rebuilt, and --required-regen re-run: first_generation_equal=true over 161 planned. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Enrolled one-order claims import empty_map/map_insert from v2.std.collection (floor UnimportedBareProvider) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Name the instrument instead of transcribing the probed RAM gap (review 73848) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Merge group: the floor window's base is the group's own parent (merge_group.base_sha), never origin/main #12514's first live merge_group run (group head 529d438) compared against main 8a249e7 and charged the four PRs queued ahead (#12921 #12735 #12770 #12905) to this landing: three order-edge claims from #12770 read as regressed. - extdeps.github.merge_group_event: cited payload reader for merge_group.base_sha and the merge queue's group-composition guarantee (cited), consumed by the resolver. - gunbc.diff_baseline: MergeGroupBase arm; merge_group resolves through resolve_merge_group_base, which REFUSES on an absent/empty/unreadable/malformed base_sha and never falls back to origin/main. Two-dot comparison. - Witnesses: payload parsing (nested member, absent, empty, not an oid, not json) and resolution (own parent, no parent refuses, cause carried). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: derive gunbc.rung_drop.roster from its directory by declared type (shared fold with RFM) Unverified by CI; main_wet regen of stage0 mirrors not completed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * #12514: cover PlannedAsReachConsumer in main's newer disposition matches; hoist in-body annotations Merging main brought six matches over RequiredFloorDisposition written after the reach-consumer arm existed on this branch (E0004 in emit-build). Each new arm follows the .dag authority: v2.workflow.floor_changed_witness and v2.workflow.required_floor treat PlannedAsReachConsumer exactly as Planned (planned standing, gate runs, not a cost-debt withhold, CostDebtDeclaredButNotWithheld, never suppresses a changed-witness enrollment). merge_group_event.dag carried '//' annotations inside a type body, which DESIGN §4c refuses; they move to the leading block above the declaration. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: cover variants that landed on main after the NFR enumerations were written Composing the burn-downs with main exposed two non-exhaustive matches, the exact class enumeration exists to surface: - floor_unimported_bare_provider_debt_roster: three standing matches lacked Retired { cause: RelocatedOutOfSourceRoots } (floor refusal, CI run 36931173776). - target_model realized-closure body classification lacked ParameterReferenceBody, added by #12766 (emit-build refusal); it projects like DeclarationReferenceBody. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate stage0 mirrors to a fixed point; cover more variants that landed after enumeration - stage0 mirrors regenerated locally (claim_executor --required-regen, whole-compiler rebuild between rounds) until first_generation_equal=true (161/161 adjudicated). - DESIGN.md and docs/design-rung-drops.md from tools.docs_projection_gate regen and generated_artifact_gate main_wet_verified. - More matches the NFR burn-downs enumerated before main added variants; each new arm keeps what main's removed wildcard returned: live_deploy emit identity_member_of_step and member_observe root_members_of_step gain ApprovalBrokerFrontDoor (none / []); mtcollins1_kvm_still kvm_pending_step, kvm_established_step and kvm_gap_mark gain KvmJournalNavigated/PageConsole/PageError (acc / []). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: retire 31 bare-provider rows the composed tree no longer carries The pool-wide standing check (#12908) judged the composed head and found 31 ActiveDebt pairs whose files no longer carry them (imports added by the other merged burn-downs). Each is retired as ImportsFixed, exactly as the refusal names (CI run 36939427278). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate after merging main; name runner_microvm_boot_probe's Filesystem authority - stage0 mirrors regenerated to a fixed point after the main merge (first_generation_equal=true), docs/design-rung-drops.md regenerated; main_wet_verified green. - runner_microvm_boot_probe read Filesystem bare while three modules declare it (AmbiguousBareNameRead, floor run 36941252236); it uses Filesystem.Write, so it imports the service from extdeps.filesystem.filesystem_io, as its sibling runner modules do. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate the rung-drops projection after the main merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: back out #12610 (typed NFR check D) Its typed check judges every module the diff touches, and this branch's diff touches hundreds, so the floor refused with 65 unrostered closed-coproduct wildcard sites (NonFoldResidueRosterDiverged, run 36948688303). That is exactly the joint landing #12610 was waiting on (census roster, old-scan deletion, srv1 typed census at 0/0), which is not built. #12610 is reopened to carry it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: iterative Drop for PortableValue value_depth_walker_tests::a_deep_value_round_trips_through_the_portable_form aborted the test process (stack overflow, SIGABRT, rust-unit-tests run 36951304061) when the deep portable chain was dropped: PortableValue is a plain owned tree, as deep as its value, and had the recursive default drop. It now drops through a heap worklist exactly as impl Drop for Value does (class recursion_over_value_depth_uncounted_by_the_call_limit). The test passes locally, and the other deep-value tests still pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: green the --lib population #12753 makes blocking #12753 turns rust-unit-tests into a blocking lane, so this branch must carry a green --lib population. Main's own reds, which nothing ran: - closure_edge_demand_tests::required_phase_..._catches_a_bypass judged a second root set on the same thread, which #12831's SharedIndexSecondResidentPool now refuses; the twin pool's judgment runs on its own thread, as a separate floor run would. - compile_clean_via_index_verdict_equivalence::regen_subject_admits_a_provider_reached_only_by_ reference wrote a bare cross-tree reference, which #12741 refuses (CrossTreeBareReference); the fixture now writes it qualified, still reference-only with no import. - nfr_roster_receipt: 13 parameter-scrutinee wildcard sites landed on main after the 2026-10-01 census; rostered with a stated reason and the owning-fold dissolution. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: live-pool tests start from no held pool live_pool_thread_tests::two_claims_on_the_live_pool_thread_share_one_index failed whenever an earlier test had left the live-pool thread holding its own fixture pool: #12831 refuses a second resident pool on one thread (SharedIndexSecondResidentPool). Each live-pool test now releases the live pool first (yield_live_pool_before_building_another), so its result no longer depends on test order. The serial suite's live-pool and content-key tests pass (7/7). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate stage0 after the main merge; roster 2 more post-census NFR sites - v1_compiler_emit{,_rust}.rs regenerated from main's base to a fixed point (first_generation_equal=true); docs projection unchanged. - dag/gunbc/action_use_admission.dag checkout_context_names_a_commit and checkout_ref_value_refusals landed on main after the census; rostered like the earlier 13. - Full serial --lib suite (RUST_TEST_THREADS=1, as CI runs it): 1116 passed, with the only failure being these two sites, now green. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: keep a deleted file's roster row FileDeleted; stop a test helper from providing 'github' pool-wide - import_closure_live_test.dag#ReadsLiveTree: the file is deleted on main, so its row stays Retired FileDeleted (my conflict resolution had taken ImportsFixed). - #12835's fleet_converge_checkout_pin_witness_test.dag declares a top-level helper 'fn github(path:)'. With #12908's pool-wide standing check, that made it a candidate bare provider for every module that reads 'github' bare (115 Unrostered refusals, run 36964372555). The helper is test-local, so it is renamed github_context_access; it no longer collides with the 'github' those modules mean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert "integration: merge #12912 (session/deep-deer-663-sudoers)" This reverts commit 9502c4c, reversing changes made to c276c43. * Regenerate stage0 mirrors and rung-drop docs after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * github_app_registry witness: import its live-tree disposition instead of reading it bare Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs and stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: rows for parse_sequence_capture and grammar_emit_sequence (landed on main after the census) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors and docs after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Cover main's new LexicalReferenceKind / LexicalReferenceBody in two enumerated matches; docs regen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider debt roster: the three body_lowering tests' rows are ImportsFixed on this branch (floor: RosterStale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: delete the 757 rows whose wildcards this branch's burn-down PRs enumerated (floor: stale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * semantic_decl_emission: the four edge-label matches name Authored and StructuralLabel (Named is gone after #12799) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * target_model: name StructuralLabel in the wire-child declared-type match; docs regen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * match_pattern_binds_erased: carry the pattern's parent_identity (main's VariantPattern field) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * program_partition, realization_attempt: name StructuralLabel in three edge-label matches (#12799) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate DESIGN.md from the merged design_document (generated_artifact_gate main_wet) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: restore main's rows for the five wildcard bodies taken from main in the #12799 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * roadmap_belt_actuate: delete belt_spawn_tally_not_admitted, left without a caller once main's arms were taken Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Delete two branch helpers left without a caller once main's arms were taken in the #12787 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the #12787 merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider debt roster: retire three pairs the merged files no longer carry (floor: RosterStale -> ImportsFixed) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * unit_standing, runner_microvm_slot_unit: name RuntimeMaxSec in four directive matches taken from main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider roster unit test: ImportsFixed -> FileDeleted now admits (#12787's rule); the reverse still refuses #12787 made FileDeleted terminal in v2.workflow.floor_unimported_bare_provider_debt without updating this Rust test, which main does not run as a blocking lane. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the #12512 merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * runner_unit_live_read: the enumerated converge-verdict arms name VerdictAbsent (#12721) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: drop two rows main added for d0 sites this branch enumerates (floor: stale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: floor fixes after the main merge; #12753 retirement text claims only what was observed - debt roster: fabric_witness_run_test HardRequirements/Shape/current_runner_slot_profile keep main's Retired ResolvesInClosure (the floor refuses a changed retirement, RosterRetirementChanged). - unit_standing_witness_test: import extdeps.systemd { systemd_duration_usec } (Unrostered on the floor; the file declares imports so its bare channel is off). - rust_unit_tests_off_the_merge_path: the merge_group pass had not happened; the text now says the merge_group revision is proven by the queue's own required run at landing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Heal-Candidate-Run: 37180751525 * Regenerate docs projections (docs_projection_gate regen) * Regenerate stage0 mirrors (claim_executor --required-regen, round 1) * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * integration: follow main's #13186 (HeadGrain deleted) in the ownership join; LoadCredential arm in the microvm slot unit - gunbc.refusal_reason_ownership_join: main keyed cause ownership by cause alone and deleted the grain field, so a row owns its cause; reason_is_fatal_owned is the cause match. The witness drops the HeadGrain control (head_row / head_grain_row_does_not_own_a_fatal_reason): the state it planted is no longer constructible. - runner_microvm_slot_unit: main added SystemdServiceDirective LoadCredential; the enumerated directive match was non-exhaustive (floor declarations finding). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: delete the 2 NFR rows whose sites no longer carry a wildcard (floor NonFoldResidueRosterDiverged stale=2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Heal-Candidate-Run: 37235281080 * Regenerate docs projections and witnesses.yml after stage0 regen * integration: the four rust-unit-tests reds the restored lane surfaced (all stale against main, which runs no unit lane) - nfr_observation_roster_test: gunbc#13277 enumerated ci_hold_cause_text and drained its NFR row; the test now asserts the row stays drained (renamed observation_hold_cause_row_stays_drained). - process_cwd_mutation_reachability_gate: a_stale_binary_is_refused_before_any_instrument_runs reached test_verb's producers, several of which set the process cwd. The freshness refusal is split out as stale_binary_refusal and the witness calls it, so the route is asserted without reaching any producer; test_verb_after keeps the same behaviour. - changed_selections_outside_discovery_mirror_tests: since gunbc#13138 the .dag decider returns its list as a free-monoid Cons/Empty chain (list_reverse); the test reads either realization. - renderer_hop_decides_realization_from_declaration_identity_without_an_env: the structural-Bool half retires as dissolution of the Bool de-fork (gunbc#12583), mirroring the .dag witness's retired row; the prelude control stays. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: list_items matches the Value by reference (E0509: Value implements Drop) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: pin run_native_serve_program in the cwd gate's undecided set; carry the renderer-hop retirement into its .dag source - process_cwd_mutation_reachability_gate: main's #13135 declared run_native_serve_program in two files, the exact shape of the pinned run_native_claim_program (producer called only from its own TargetProducer match; the native_lane_runner twin reached by the qualified cli_run:: spelling). - compiler_tests.rs is generated from v1.compiler.compiler_tests_rust; the structural-Bool retirement is now authored there, rendering the same lines the mirror carries. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: the compiler_tests_rust mirror carries the renderer-hop retirement its .dag source now authors v1_compiler_compiler_tests_rust.rs is the emitted form of v1.compiler.compiler_tests_rust; its ct_renderer_hop_identity_keying_test is re-rendered in the emitter's own concat shape (the old body round-trips byte-identically through the same rendering), so the regen's first generation agrees. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * Reach differential: an unmeasured head and a claim declared at neither side refuse, never pass (review 76405) reach_claim_verdict returned a non-blocking 'head_not_measured' for a head with no verdict; it now refuses typed and located (DESIGN 5). claim_differential mapped NotDeclared at both sides to DifferentialRemoved (never blocks); it is now DifferentialUndeclaredAtBothSides, which blocks, so a removal runs the base arm to prove it was one. Tests: an_unmeasured_head_is_refused_not_reported, a_claim_declared_at_neither_side_blocks_and_a_removal_reports, and only_a_passing_head_skips_the_base_arm. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Reach differential: not_measured is a declared parsed arm; one constructor builds the verdict (review 76416) ParsedClaimStanding gains StandingNotMeasured, parsed once in claim_standing_named; reach_claim_verdict and reach_head_cannot_block match the arm instead of each comparing the string. reach_verdict_of builds ReachVerdict's name and blocks from ONE ClaimDifferential value, so they cannot disagree; the two flat fields stay because they are the wire the seed floor runner reads. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * floor_demand: typed arm for the cross-claim-share-derivation seam (main's #13043) #13043 added floor_seam("cross-claim-share-derivation") to the floor runner without a FloorSeam arm or a FloorSeamToken row; main never runs the unit lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation, its token row, and its arm in receipt_peak_seam. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rung drop rust_unit_tests_off_the_merge_path: retired on its own trigger, runner supply, with the receipt (review 76493) The trigger_fired text cited the population being green and the job being re-added, which the row itself says does not retire it. It now cites the supply receipt from this PR's required runs: the unit job starts with the other lanes (no queueing) and finishes before floor, so the required wall did not rise. It also cites the operator's sign-off for the roster addition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rung drop rust_unit_tests_off_the_merge_path: restore the declaration the last edit dropped (review 76497) 163ef99 replaced the trigger_fired text but cut through to the end of the declaration's AuthoredProse, deleting the drop's record of what it declared (and leaving the record without a required field). Restored from its parent; only the trigger_fired string differs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs projections (rung-drop retirement text) * Regenerate DESIGN.md (generated_artifact_gate main_wet_one): the unit-test lane is no longer described as off every CI path * rung drop retirement: name the instrument for the supply receipt, not the transcribed wall times (review 76511) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs projections and DESIGN.md (retirement receipt names its instrument) * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate stage0 mirrors after the eighth main merge (round 1) * Regenerate docs projections after the tenth main merge * required_floor_runner test: cost_debt_clean_outcome carries reach_differential_blocking Main's test constructor (added with the moved required_floor_outcome_is_clean) predates this branch's field; the unit lane failed to compile (E0063). cargo check --lib --tests is clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate DESIGN.md and docs projections after the eleventh main merge --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com> Co-authored-by: Brian Searls <briansrls@gmail.com>
Climbs
gunbc.rung_drop text_boundary_identity_wallunder XL-0T ruling B: one type, two representations. KernelStringis host text and a corpus-declaredFreeMonoid<Char>is a code-point sequence. Every crossing between them goes through the Unicode scalar unfold or refuses. Nothing is collapsed onto one carrier and nothing is renamed.What changed
Text representation is decided by declaration identity, not spelling (review 72252).
v1.compiler.infer_envtext_representation_by_identityreturnsstd.coercionTextRepresentation=HostText | CodePointSequence | NotText | TextRepresentationUnidentified:HostText: the kernelStringmint (declaration_provenance_of).CodePointSequence: the declarationstd.algebraFreeMonoidapplied to the declarationstd.typesChar, directly or through transparent aliases.std.typesNonEmptyStris host text.NotText.Identity is read only by declaring span, by qualified name, or, inside a declaration's body, by that declaration's own module (its local declarations, then kernel spellings, then a corpus-unique declaration). It is never read by re-resolving a spelling in the comparing site's scope. The relations
node_type_equals,node_type_compatibleandnode_type_equals_corenow carryenv: TypeEnv?. Which env each site passes, and why:04_inferchecker sites:Present { value: scope.type_env }, the site's own census (identity is env-independent).04_accessindex and slice checks: the caller'sscope.type_env.04_emit_infovariant field summaries:none. There's no census there, and it isn't a representation boundary.callable_component_ground_mismatch:none. Callable-value crossings are the declared residue (eq: string_eq).infer_semantics_witness.rs: the module env for the brand tests,Nonefor the synthetic access and container tests.Unidentified sides are unjudged, not refused (option A, neat-boar-16's ruling). Where one side is identified text and the other has no readable declaration identity, the text wall adds no verdict and base compatibility decides, never an admission base wouldn't make. Each such site emits the non-blocking
TextRepresentationUnidentifiedAtBoundary, located, as the census instrument.The unfold, and caller re-resolution. A host value at a code-point-sequence call argument takes the Unicode scalar unfold as a typed node (
chars, typed as the destination), gated on the existingUnicodeScalarSequenceUnfoldrow. Call arguments are typed against the declaration-bound formal, not the spelling re-resolved in the caller.The Rust emitter is unchanged from main (
is_host_text_carrier_typekeeps its provenance-keyed answer, since its renderers hold no env). The emitted self-host crate is byte-identical to base.std.string_type keeps
type String = FreeMonoid<Char>as a declared frontier with no importer (neat-boar-16's ruling). Its two lex functions are deleted, and the 8 callers use host<, which is code-point order (interpreter control plus an emitted Rust check).Kernel spelling in global and claim-scope lookups.
global_bare_lookupnever binds a kernel spelling to a corpus declaration.claim_scope_for_with_memosreadsis_substrate_vocabulary(controla_kernel_spelling_declared_twice_is_not_contested).Evidence (head vs base 02360ee, same tree)
gunbc compile --source-root dag --source-root src/v2 --target dag): 0 new blocking rows, so head refusals ⊇ base. One base refusal is admitted at head:dag/test/claim/long/dag_arrow_lambda_witness_test.dag:30, a hostStringatlex_walk_artifact'sFreeMonoid<Char>source, now carried by the sanctioned ruling-B unfold, not the unjudged path.--entry src/v2/compiler/00_compile.dag --target rust): byte-identical to base, and it builds.test.claim.text_boundary_identity_wall_witness_test21/21 in one run: refusals (local, renamed and qualified alias into a kernel primitive; kernel value at a qualified, alias-of-text, or structure-identical-alias return and at a data initializer), unfolds (qualified, alias, foreign bare formal, foreign literal, refinedNonEmptyStr), collision refusals A and B (usertype Char), and controls (including roadmap_pagescript_src_attradmitted and literals unfolding). The alias and caller-re-resolution arms are identified in these fixtures.std.content_hash:145: the seed's kernel-mintedHashread as unidentified. Fixed by identifying any kernel mint that names no corpus declaration as the kernel's own type.Drop standing
text_boundary_identity_wallis restated. The IDENTIFIED crossings are structurally guaranteed. The unidentified population is unjudged, bounded by identity, and produced by the diagnostic classTextRepresentationUnidentifiedAtBoundaryfrom the two compile entry points above. The trigger, verbatim: the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures. The staged replacement is node://adhoc-207dd6ac-6d2. Remaining named gaps: callable values (eq: string_eq); case C (a userFreeMonoidrecord, which is container-template recognition by spelling); case D (a userList<Char>into a host-text builtin, because builtin args are untyped).The 71 modules: import deleted (none kept an unfold)
Per-module check: after the deletion, none of these modules gained a refusal in the whole-corpus compile. A module that relied on structural operations over the value would have refused. neat-boar-16's per-file census is the independent receipt.
dag/extdeps/access/posix_effective_principal_read_op.dag: import deleteddag/extdeps/bmc/http.dag: import deleteddag/extdeps/bmc/ipmi.dag: import deleteddag/extdeps/bmc/megarac.dag: import deleteddag/extdeps/bmc/openbmc_fan_control.dag: import deleteddag/extdeps/bmc/openbmc_password_ssh_transport.dag: import deleteddag/extdeps/clock/clock.dag: import deleteddag/extdeps/cloudflare/account_api_tokens.dag: import deleteddag/extdeps/cloud/gcp/gcp.dag: import deleteddag/extdeps/cron/cron.dag: import deleteddag/extdeps/crypto/hash.dag: import deleteddag/extdeps/docker/cgroup.dag: import deleteddag/extdeps/docker/container_inspect.dag: import deleteddag/extdeps/docker/container_stats.dag: import deleteddag/extdeps/entropy/entropy.dag: import deleteddag/extdeps/git/git.dag: import deleteddag/extdeps/github/issues.dag: import deleteddag/extdeps/github/pulls.dag: import deleteddag/extdeps/git/inspect.dag: import deleteddag/extdeps/git/publication_transport.dag: import deleteddag/extdeps/gunbc/gunbc.dag: import deleteddag/extdeps/http/client.dag: import deleteddag/extdeps/linux/cgroup_v2.dag: import deleteddag/extdeps/linux/edac.dag: import deleteddag/extdeps/linux/procfs.dag: import deleteddag/extdeps/linux/proc_net_tcp.dag: import deleteddag/extdeps/linux/proc_pid_stat.dag: import deleteddag/extdeps/linux/proc_stat.dag: import deleteddag/extdeps/llm/cli.dag: import deleteddag/extdeps/llm/codex_app_server.dag: import deleteddag/extdeps/nvidia/system_management_interface.dag: import deleteddag/extdeps/package_managers/apt.dag: import deleteddag/extdeps/posix/getconf.dag: import deleteddag/extdeps/procps/pgrep.dag: import deleteddag/extdeps/python/python.dag: import deleteddag/extdeps/rust/cargo_build.dag: import deleteddag/extdeps/rust/rustc.dag: import deleteddag/extdeps/shell.dag: import deleteddag/extdeps/shell/exec.dag: import deleteddag/extdeps/ssh/password_session.dag: import deleteddag/extdeps/ssh/session.dag: import deleteddag/extdeps/sudo/nopasswd_execute_probe_check_op.dag: import deleteddag/extdeps/systemd/oomd.dag: import deleteddag/extdeps/systemd/systemctl.dag: import deleteddag/extdeps/systemd/systemd_run.dag: import deleteddag/extdeps/tailscale/serve.dag: import deleteddag/extdeps/tmux/tmux.dag: import deleteddag/extdeps/tools/coreutils_stat.dag: import deleteddag/extdeps/tools/diffutils.dag: import deleteddag/extdeps/tools/hostname.dag: import deleteddag/extdeps/tools/id.dag: import deleteddag/extdeps/tools/jq.dag: import deleteddag/extdeps/tools/node.dag: import deleteddag/extdeps/tools/npm.dag: import deleteddag/extdeps/tools/rustfmt.dag: import deleteddag/extdeps/tools/sed.dag: import deleteddag/extdeps/tools/sha256sum.dag: import deleteddag/extdeps/tools/sha512sum.dag: import deleteddag/extdeps/tools/sleep.dag: import deleteddag/extdeps/tools/stat.dag: import deleteddag/extdeps/tools/xorriso.dag: import deleteddag/gunbc/cli_services.dag: import deleteddag/gunbc/fleet_observation/capture_chunk.dag: import deleteddag/gunbc/fleet_observation/collector_ownership.dag: import deleteddag/gunbc/fleet_observation/collector_supervision.dag: import deleteddag/gunbc/fleet_observation/observation_envelope.dag: import deleteddag/gunbc/machine_intake/sol_hold.dag: import deleteddag/std/markup.dag: import deleteddag/test/claim/fleet_observation_capture_witness_test.dag: import deleteddag/test/claim/machine_intake/mtcollins1_census_image_witness_test.dag: import deletedsrc/v2/compiler/discovery_enumeration.dag: import deletedPlus
dag/std/string_type.dag: the alias is kept as a declared frontier, andstring_lex_compare/string_is_lexicographically_beforeare deleted (callers use<).Hand-Rust receipt (review 74288's advisory): the
is_substrate_vocabularyskip inv1_compiler.cli_runclaim_scope_for_with_memos.Stringdo not make a bareStringcontested in claim scope.gunbc.v1_maintenance_standingv1_seed_standing: it serves the v2 self-host program. This PR deletes thestd.string_typeimports. Before that, each scope happened to import oneStringdeclarer, so the bare name was never contested. With the imports gone, claim scope would refuse bareStringreads that the rest of the seed already binds to the kernel through the sameis_substrate_vocabularyrule.gunbc.output_policyat 4 sites (e.g.extdeps.github.issues). Those are bareStringreads outside service exit arms, so the separate exit-arm parse fix does not cover them.node://adhoc-207dd6ac-6d2.🤖 Generated with Claude Code
Review 72427, finding 2: the judgment is a coproduct (4129275)
node_type_compatible,node_type_equals,node_type_equals_coreand the index/slice access checks takeTextJudgment = TextJudgedIn { env } | TextNotAsked { reason }. They no longer take an optional env. Each site that skips the identity judgment names aTextNotAskedReason:TextNotAskedInVariantFieldSummary;TextNotAskedForCallableComponentResidue;TextNotAskedForSyntheticWitnessNodes.Measured on that head against base 02360ee:
first_generation_equal=true.infer_semantics_witnessstructural_method_count_on_list_returns_intpanics (std.nat.NatvsInt). It panics identically at merge-base 02360ee, so it predates this PR.Consolidation onto v1's one type-identity derivation (63fa734)
main's #12592 made
v1.compiler.infer_envtype_reference_declaration_readingthe single type-reference identity derivation.text_representation_by_identitynow reads identity only through it.authored_reference_reading,AuthoredReferenceReadingandauthored_declaration_of_type_nodeare deleted, including the by-name authoring-module hop.The six wall and neighbour claim files give 102 PASS and 0 other, the same name set as before the swap. No wall verdict moved.
The drop row names exactly one producer,
TextRepresentationUnidentifiedAtBoundary, and says whycarrier_realization_censusis not it. The census enumerates authored declaration positions; this population is use-site comparisons whose value side is usually an inferred type.Modules added to the import deletion by the main merges
The following gained
import std.string_type { String }on main after this branch's merge-base. Each gets the same disposition as the 71: the import is deleted.dag/extdeps/automation/playwright.dagdag/extdeps/package_managers/dpkg.dagdag/extdeps/systemd/journalctl.dagdag/extdeps/tools/ldd.dagdag/extdeps/tools/unzip.dagdag/gunbc/bmc_megarac_web_adapter.dagdag/gunbc/bmc_model.dagdag/gunbc/host/verified_archive_install.dagdag/gunbc/runner/runner_browser_toolchain.dagdag/test/claim/runner/runner_browser_toolchain_real_execution_witness_test.dagdag/extdeps/tools/node.daganddag/extdeps/tools/xorriso.daghad the import re-added in merge conflicts; both are deleted the same way. xorriso is one of the 71.Receipts at the frozen head c04392e (base origin/main 785934a)
All on BuildBuddy, with the exact sha fetched and rev-parsed inside each dispatch.
--target rust,src/v2/compiler/00_compile.dag): 0 differing files. Both sides 0 blocking. Head's emitted crate builds with 0 errors. Advisories: head 3190, base 3138.//gunbc/instruments:v2-native-frontierwithGITHUB_SHAset; warm-wolf-234's script). This is a raw verdict diff: the frontier reportsfrontier=unminted, admission admitted, exit 1, on both sides.resolve_unbound_name_is_declared_in_several_modules @ <occurrence "String">resolve_unbound_name_is_declared_elsewhere @ declaration v2.std.text.StringReceipt head and landing head
d1e684fd(merge of main2aea4ada). The srv1 receipts run here. PR-diff fingerprint at H:2525c7e7aaac65a9abaf0516a2aacbcd57994827e8be972721aa888447ee2fe0. This is the sha256 ofgit diff 2aea4ada..H, excluding the regeneratedsrc/v1/stage0/src/v1_*.rs,std_*.rsanddocs/design-rung-drops.md.178804ca. Fingerprint at H″, same method:08f44a3e0409fd751a958302d410dab4e700f3b152d551226125ccc89a65340e.--target rust,src/v2/compiler/00_compile.dag) has 0 files differing from H's;text_boundary_identity_wall_witness_testpasses 21/21 under the same names.gunbc.rust_item_scan's duplicateends_with; that clears the floor'sUnimportedBareProviderrefusal onsrc/v2/lens/module_graph.dag. After it lands, main is merged in. That merge must be main-only, so the H″ fingerprint must still match.0f67a600ran BOTH binaries on the HEAD tree. It establishes that the checker admits no new crossing on that tree (0 head-only refusals; 1 base-only, the sanctioneddag_arrow_lambda_witness_test:30unfold). It is NOT an end-to-end compile receipt: it cannot see the 81 import deletions. That receipt is Job 1b:2aea4adagunbc sha25606090159a6a34aba…: 175 blocking, 36956 advisory, peak 34.3 GiB.d1e684fdgunbc sha2561ddf121873dcba4a…: 174 blocking, 38472 advisory, peak 34.4 GiB.dag_arrow_lambda_witness_test.dag:30:35(declaredFreeMonoid<Char>, producedPrimitive(String)), the sanctioned unfold.text boundary unjudged atadvisories on head, which is the entire advisory delta.1c5d37c5…, = the 180 direct consumers ∪ the pre-registered sample of 146 of 718 transitive-only files, seed 12512; each binary on its own tree;claim_batchper file).self_host_structural_text_witness_testw_nonliteral_kernel_string_at_text_boundary_is_presently_accepted_declared_dropis absent on head, and its flipped successorw_nonliteral_kernel_string_at_text_return_boundary_refusesPASSes. The planted probe became a permanent refusal control (§4b(4)).~/neat-boar-runs/r12512j2-d1e684fd9a/.Landing merge after H″ (main
0207c666)Receipts at H; landing head = H″ + merge of main
0207c666+ the same import deletion in the 3 modules main added since H. PR diff otherwise unchanged. Against the H″ fingerprint, the PR diff differs by exactly three-import std.string_type { String }lines, in these three modules:dag/gunbc/bmc_megarac_web_transport.dagdag/gunbc/machine_intake/mtcollins1_kvm_still.dagdag/gunbc/owned_process.dagThe file list is otherwise identical, and no other line changed. The merge's only other conflicts were
std.algebraimport lists (main addedCons) and generated stage0/docs. Stage0 regenerates to a fixed point.Receipt for those 3 modules. Base is main's
0207c666binary on main's tree; head is the merged binary on the merged tree.mtcollins1_kvm_still_witness_test: 19/19 PASS on both sides.mtcollins1_kvm_observer_protocol_wet_witness_test: 1 PASS, 11 FAIL on both sides, identical. These are wet hardware claims.Semantic neighbour in the merge: #12695. It extended
v1.compiler.inferkernel_value_declared_type_mismatchwith a produced-side refinement peel. On the merged binary,text_boundary_identity_wall_witness_testpasses 21/21 andkernel_refinement_at_structured_parameter_witness_test8/8, so the two checks do not contradict on those fixtures.Ownership of "may host text cross into a structural text formal"
Two deciders overlap:
text_representations_cross) decides. It unfolds or refuses before the base check runs, and the base check then sees an argument already typed as the destination.v1.compiler.inferkernel_value_declared_type_mismatchdecides. This is the pre-existing spelling-keyed base inhabitance check, not text-specific, and infer: a kernel refinement (NonEmptyStr) at a structured parameter refuses like its base (string_replace crash) #12695 extended it with the refinement peel. The classifier reads FreeSemigroup as NotText, so the wall makes no judgment there.The follow-up is declared as a typed stall row,
gunbc.guarantee_stallfree_semigroup_text_crossing_decided_by_spelling_stall: current StructurallyGuaranteed, ceiling StructurallyImpossible. Its trigger: the classifier recognizes FreeSemigroup as a (nonempty) code-point sequence, SUFFICIENT FOR every such crossing to be decided bytext_representations_cross, with the base check's text case retired.guarantee_stall_witness_testpasses 11/11.Landing head L =
81f20038(merge of main8e212f9)The receipts stay at H, and L composes #12791 with the wall. Main's #12791 rewrote
v1.compiler.inferdeclared_type_conformance_diags, adding a new signature and an optional-cardinality refusal. On L that function:text_unjudged_advisories;_corein this order: v1 checker: an optional at a required record field, declared return, let annotation or data initializer refuses #12791's cardinality refusal first, then this PR's identity-crossing refusal, then the shared branches.Both are refusals, so the order cannot flip an admit into a refusal or the reverse. The one reporting change: an
Optional<host text>at a code-point declared position now reports the cardinality refusal rather than the text one.Receipts at L:
text_boundary_identity_wall_witness_test21/21kernel_refinement_at_structured_parameter_witness_test8/8optional_at_required_position_witness_test20/208e212f9(BuildBuddy; rev-parse exact; gunbc sha256 based6b50558…, head015e96f9…): 0 files differ, both sides 0 blocking, and head's emitted crate builds.#12512 no longer waits on #12736. Main changed
src/v2/lens/module_graph.dag'sends_withcalls to method form, and combined with this PR's==no bareends_withread remains. The floor'sUnimportedBareProviderrefusal is gone, and the floor passes at L.The 24-file sample at L, done. This is the pre-registered sample of transitive consumers of the 3 modules (comment 5918418459, sha256
b7d3814d…), run on srv1 at L81f20038vs base8e212f9a(logs~/neat-boar-runs/r12512j2-81f200382b/).required_ci_epoch_real_execution_witness,required_lane_claim_agreement_witnessandrunner_microvm_lifecycle_wet_receipt.Final head F =
6beefd25(merge of main4d0c5bc, skip restored)Receipts are at H and L as above; F = L + merge of main
4d0c5bc+ the items below.bare_name_ambiguity_wall_witness_test: keeps both new rows. This PR's kernel-spelling row is ROW 7; main's exit-arm row is ROW 8.bmc_model.dag, where main re-addedimport std.string_type { String }, and for the two newwet_host_premise_readbackfiles.gunbc.bmc_modelandgunbc.wet_host_premise_readback: 0 head-only error rows each;bmc_model_web_kvm9/9,mtcollins1_boot_acceptance_matrix26/26,mtcollins1_kvm_observer_protocol_wet1 PASS / 12 FAIL on both,boot_world_models7/7,operation_realization18/18,wet_host_premise_readback3/3.is_substrate_vocabularyskip incli_run.rsSTAYS (corrected). I deleted it at F4e1e6991becausebare_name_ambiguity_wall_witness_testpassed 10/10 without it and main's ntfy channel readback: observed binary path; nested helper gets its checkout root (stacked on #12561) #12563 parse fix covers service exit arms. That test was the fixture file only, and it was not sufficient. With the skip removed, the required floor refusedgunbc.output_policy(AmbiguousBareNameRead,String, 4 sites:extdeps.cloudflare.account_api_tokens,extdeps.docker.container_inspect,extdeps.github.issues,extdeps.github.pulls), which are bareStringreads outside exit arms. The skip is restored at6beefd25, and its comment records this. Hand-maintained seed Rust is unchanged from the earlier receipt:bin/infer_semantics_witness.rs(+30 −5),cli_run/compile_clean.rs(+7),cli_run.rs(+8 plus the comment).free_semigroup_text_crossing_decided_by_spelling_stallnames the two claim files that re-derive the agreement, rather than transcribing their counts.guarantee_stall_witness_test11/11.std.string_typeat F6beefd25:gunbc compile --entry dag/std/string_type.dag --target rustgives 0 blocking. The emitted crate builds withcargo build --release: exit 0, 0 E0308, 0 errors.Landing head G =
de6a2d51(merge of main8a249e7)G = F (
6beefd25) + merge of main8a249e7+ the same import disposition in 5 modules main added since F.Node.declaration): on the merged binary,text_boundary_identity_wall_witness_testis 21/21 with the alias rows unchanged, and Alias-RHS identity: env binding retains the RHS reference; the transparent-alias relation reads Node.declaration #12896'salias_head_identity_probe_witness_testis 4/4. Also on G:bare_name_ambiguity_wall10/10,guarantee_stall11/11, and stage0 at a fixed point.extdeps.os.ubuntu_ports_archive,extdeps.tools.dpkg_deb,extdeps.tools.gzip,gunbc.machine_intake_mtcollins1_census_qemu_toolchainandgunbc.machine_intake_mtcollins1_kvm_observer_observe. Base is main's binary on main's tree; head is the merged binary.mtcollins1_census_qemu_host_observe14/14 andmtcollins1_kvm_observer_observe11/11. No base-PASS → head-else.Landing head
bd5bf217(taken over by proud-badger-341, 2026-10-02)The landing head is G
de6a2d51, then three merges of main, and nothing else. The three merges were808e9d75,3756d624, and main after #12980f4c8204e.Merge resolutions.
v1.compiler.infer_env(src/v1/04_env.dag). Both changes are kept: the import lists are unioned, andqualify_borrowed_type_nameskeeps v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569's!is_container_typeexclusion. Text crossings unfold or refuse: exact-representation text compat (XL-0T ruling B) #12512's identity-reading hunks merged without conflict.v1.compiler.infer(src/v1/04_infer.dag). Thestd.coercionimport is unioned. Main had already addedKernelMinted,CorpusDeclared, andDeclarationIdentityAbsent.v2.lens.reference_deps. I took main's version. Main's Retire the parse walker reference_sites_from_parsed_module onto collect_reference_sites #12910 deleted the two functions whosestring_eq→==edits this PR carried.std.string_typeimports from main get the same disposition as the original 81.extdeps.automation.playwright,extdeps.cloud.gcp.gcp,extdeps.cloud.gcp.sts, andextdeps.tailscale.acl_api.extdeps.time.rfc3339: main's Integration: #12947 (lexical refs by occurrence) + #12381 (where-predicates as declarations) #12969 importedstring_lex_compare, which this PR deletes. This PR's existing host-<comparison body survived the merge, so thestring_lex_compareandLess/Equal/Greaterimports were dropped as unused.dagorsrc/v2importsstd.string_type.extdeps.bmc.*/extdeps.ssh.*/extdeps.systemd.journalctlconflicts in the first merge were NOT new imports. Main had moved those lines, and each deletion was already one of the 81. The PR diff for those files is byte-identical to G's.claim_executor --required-regenafter each merge, on BuildBuddy under a 24 GB cgroupmemory.max. The final round'sclaim_executorsha256 isc6d38a43….docs/design-rung-drops.mdwas regenerated withdocs_projection_gateregenon srv1 by neat-boar-16 (gunbcsha25636f992bd…, peak 10.85 GB). This PR's delta is +7/−1.Floor refusals met on the way, each dispositioned.
RosterStaledag/extdeps/tools/{coreutils_stat,sha256sum}.dag#get. These are files this PR touches (String import deletion). Retire the parse walker reference_sites_from_parsed_module onto collect_reference_sites #12910'scollect_reference_sitesno longer reports the pair. Both rows are retired asImportsFixed, which is the refusal's own remedy and Fabric peer blob transfer: one sha256-keyed Spark file handler, a rail rsync source, image distribution off the executor relay #12941's precedent.coreutils_statandsha256sum#getrows asNotAReference. Merge128ae84ftook main's rows, so this PR no longer carries its own retirement for them.RosterRetirementChanged(3 spark#getrows). These were retired on main by Fabric peer blob transfer: one sha256-keyed Spark file handler, a rail rsync source, image distribution off the executor relay #12941 after the merge base. Merging main fixed it.NonFoldResidueRosterDiverged unrostered=37. NFR: typed, diff-scoped non-fold-residue check on the required floor (D) #12610's diff-scoped NFR check landed after G, so files this PR touches only for the import deletion came into its scope.path::fnin neat-boar-16's whole-corpus NFR census of mainca5ed1724b(artifact/nfr-census-ca5ed1724b).Review 74123 was fixed in
455dcd8f, as annotations only (§4c). Two notes claimed that an unidentified text side refuses. They now state the true standing: it is UNJUDGED (advisory only, base compatibility decides), bounded bygunbc.rung_droptext_boundary_identity_walland its trigger. One note is instd.coercion, the other is abovedestination_declares_scalar_sequence_unfold.PR-diff fingerprint delta vs G. The method is the same as above:
git diff <main parent>..head, excluding the regeneratedsrc/v1/stage0/src/v1_*.rs,std_*.rsanddocs/design-rung-drops.md. The PR diff differs from G's by exactly these items:(1) the
reference_depsedits dropped (main deleted those functions);(2) the base side of one
04_inferimport line;(3)
the 2: gone sinceUnimportedBareProviderroster retirements128ae84f, where main'sNotAReferencerows were taken;(4) the 2 annotation rewrites (review 74123);
(5) the 5 new
std.string_typeimport deletions above.Receipts at H =
f4129bd6(srv1, neat-boar-16; logs~/neat-boar-runs/r12512h/). Each binary ran on its own tree. H gunbc sha25620efd32004d6ffdb…; base B = main808e9d75c6, gunbc sha2568030b705a646c967….Walls on H (
claim_batch):text_boundary_identity_wall_witness_test21/21;bare_name_ambiguity_wall_witness_test10/10;runner_placement_witness_test29/29.v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569 probe on H:
zz_probe_ch784_int(x: refused)was inserted afterlet refused = plan_refused_hosts(p: p)and reverted afterwards.Container(List,Primitive(gunbc.ci_runner_placement.RefusedHostDeployment)).Liststays bare, which is v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569's container exclusion held.Primitive(…), where v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569's body showed it bare. The qualification v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569 cares about is unchanged.Per-entry compile, B vs H: rc=0 and 0 blocking on both sides for all 5 modules where a String import conflicted in the merge:
extdeps.bmc.http,extdeps.bmc.openbmc_password_ssh_transport,extdeps.ssh.password_session,extdeps.ssh.session,extdeps.systemd.journalctl.Direct-importer claims, B vs H: no claim goes from base-PASS to anything else on head, in any of the 8 files.
H → landing head: commits after H change only the following, with no semantic change to the PR's own code:
UnimportedBareProviderroster retirements (since superseded by main'sNotAReferencerows at128ae84f);Per-entry compile and direct-importer receipts above cover the first merge's 5 modules. For the 5 modules added in the final merge (playwright, gcp, gcp/sts, tailscale/acl_api, rfc3339), the evidence is the required floor and
generatedon this head; neat-boar-16's srv1 receipt for those 5 (logs~/neat-boar-runs/r12512f/): H =bd5bf21736, gunbc sha2567f59c677…; B = mainf4c8204e3d, gunbc sha2561680dd2d…. Each binary ran on its own tree.playwright,gcp/gcp,gcp/sts,tailscale/acl_api,time/rfc3339.runner_browser_toolchain_real_executionis 0 PASS / 13 FAIL on both sides because srv1 has no browser toolchain. That failure pre-exists and is host-dependent.rfc3339_compare's move from the deletedstring_lex_compareto host</==is witnessed:test.claim.runner_label_resolution_witness_testwitness_rfc3339_comparison_orders_utc_values_of_equal_precisiondrives all three arms (Precedes, Follows, Simultaneous) of the changed branch, and its sibling covers the Undecidable refusal. That file is 22/22 PASS on both B and H.~/neat-boar-runs/r12512g/): H =d6069b3127, gunbc sha2568146bd6e…; B = main39b06024e0, gunbc sha2569048d0cb…. Each binary ran on its own tree. All 5 entries compile with rc=0 and 0 blocking on both sides. Across all 21 importer files, no claim goes from base-PASS to anything else on head, and counts match the bd5bf21 run (runner_label_resolution 22/22 on both). runner_browser_toolchain_real_execution is 0/13 on both, the same pre-existing host premise.Hand-Rust receipt (review 74288's advisory): the
is_substrate_vocabularyskip inv1_compiler.cli_runclaim_scope_for_with_memos.Stringdo not make a bareStringcontested in claim scope.gunbc.v1_maintenance_standingv1_seed_standing: it serves the v2 self-host program. This PR deletes thestd.string_typeimports. Before that, each scope happened to import oneStringdeclarer, so the bare name was never contested. With the imports gone, claim scope would refuse bareStringreads that the rest of the seed already binds to the kernel through the sameis_substrate_vocabularyrule.gunbc.output_policyat 4 sites (e.g.extdeps.github.issues). Those are bareStringreads outside service exit arms, so the separate exit-arm parse fix does not cover them.node://adhoc-207dd6ac-6d2.🤖 Generated with Claude Code