Skip to content

Text crossings unfold or refuse: exact-representation text compat (XL-0T ruling B) - #12512

Merged
gunbai-bot[bot] merged 39 commits into
mainfrom
session/royal-newt-820
Oct 3, 2026
Merged

gunbai-bot[bot] merged 39 commits into
mainfrom
session/royal-newt-820

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Climbs gunbc.rung_drop text_boundary_identity_wall under XL-0T ruling B: one type, two representations. Kernel String is host text and a corpus-declared FreeMonoid<Char> is a code-point sequence. Every crossing between them goes through the Unicode scalar unfold or refuses. Nothing is collapsed onto one carrier and nothing is renamed.

What changed

Text representation is decided by declaration identity, not spelling (review 72252). v1.compiler.infer_env text_representation_by_identity returns std.coercion TextRepresentation = HostText | CodePointSequence | NotText | TextRepresentationUnidentified:

  • HostText: the kernel String mint (declaration_provenance_of).
  • CodePointSequence: the declaration std.algebra FreeMonoid applied to the declaration std.types Char, directly or through transparent aliases.
  • A where-refinement has its base's representation, so std.types NonEmptyStr is host text.
  • Any other kernel mint, a type variable, or an error type is NotText.

Identity is read only by declaring span, by qualified name, or, inside a declaration's body, by that declaration's own module (its local declarations, then kernel spellings, then a corpus-unique declaration). It is never read by re-resolving a spelling in the comparing site's scope. The relations node_type_equals, node_type_compatible and node_type_equals_core now carry env: TypeEnv?. Which env each site passes, and why:

  • 04_infer checker sites: Present { value: scope.type_env }, the site's own census (identity is env-independent).
  • 04_access index and slice checks: the caller's scope.type_env.
  • 04_emit_info variant field summaries: none. There's no census there, and it isn't a representation boundary.
  • callable_component_ground_mismatch: none. Callable-value crossings are the declared residue (eq: string_eq).
  • infer_semantics_witness.rs: the module env for the brand tests, None for the synthetic access and container tests.

Unidentified sides are unjudged, not refused (option A, neat-boar-16's ruling). Where one side is identified text and the other has no readable declaration identity, the text wall adds no verdict and base compatibility decides, never an admission base wouldn't make. Each such site emits the non-blocking TextRepresentationUnidentifiedAtBoundary, located, as the census instrument.

The unfold, and caller re-resolution. A host value at a code-point-sequence call argument takes the Unicode scalar unfold as a typed node (chars, typed as the destination), gated on the existing UnicodeScalarSequenceUnfold row. Call arguments are typed against the declaration-bound formal, not the spelling re-resolved in the caller.

The Rust emitter is unchanged from main (is_host_text_carrier_type keeps its provenance-keyed answer, since its renderers hold no env). The emitted self-host crate is byte-identical to base.

std.string_type keeps type String = FreeMonoid<Char> as a declared frontier with no importer (neat-boar-16's ruling). Its two lex functions are deleted, and the 8 callers use host <, which is code-point order (interpreter control plus an emitted Rust check).

Kernel spelling in global and claim-scope lookups. global_bare_lookup never binds a kernel spelling to a corpus declaration. claim_scope_for_with_memos reads is_substrate_vocabulary (control a_kernel_spelling_declared_twice_is_not_contested).

Evidence (head vs base 02360ee, same tree)

  • Whole corpus (gunbc compile --source-root dag --source-root src/v2 --target dag): 0 new blocking rows, so head refusals ⊇ base. One base refusal is admitted at head: dag/test/claim/long/dag_arrow_lambda_witness_test.dag:30, a host String at lex_walk_artifact's FreeMonoid<Char> source, now carried by the sanctioned ruling-B unfold, not the unjudged path.
  • Emitted self-host crate (--entry src/v2/compiler/00_compile.dag --target rust): byte-identical to base, and it builds.
  • test.claim.text_boundary_identity_wall_witness_test 21/21 in one run: refusals (local, renamed and qualified alias into a kernel primitive; kernel value at a qualified, alias-of-text, or structure-identical-alias return and at a data initializer), unfolds (qualified, alias, foreign bare formal, foreign literal, refined NonEmptyStr), collision refusals A and B (user type Char), and controls (including roadmap_page script_src_attr admitted and literals unfolding). The alias and caller-re-resolution arms are identified in these fixtures.
  • Neighbour claims, base vs head: see the comment below; the requirement is no true->false.
  • The previously named false refusal, std.content_hash:145: the seed's kernel-minted Hash read as unidentified. Fixed by identifying any kernel mint that names no corpus declaration as the kernel's own type.

Drop standing

text_boundary_identity_wall is restated. The IDENTIFIED crossings are structurally guaranteed. The unidentified population is unjudged, bounded by identity, and produced by the diagnostic class TextRepresentationUnidentifiedAtBoundary from the two compile entry points above. The trigger, verbatim: the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures. The staged replacement is node://adhoc-207dd6ac-6d2. Remaining named gaps: callable values (eq: string_eq); case C (a user FreeMonoid record, which is container-template recognition by spelling); case D (a user List<Char> into a host-text builtin, because builtin args are untyped).

The 71 modules: import deleted (none kept an unfold)

Per-module check: after the deletion, none of these modules gained a refusal in the whole-corpus compile. A module that relied on structural operations over the value would have refused. neat-boar-16's per-file census is the independent receipt.

  • dag/extdeps/access/posix_effective_principal_read_op.dag: import deleted
  • dag/extdeps/bmc/http.dag: import deleted
  • dag/extdeps/bmc/ipmi.dag: import deleted
  • dag/extdeps/bmc/megarac.dag: import deleted
  • dag/extdeps/bmc/openbmc_fan_control.dag: import deleted
  • dag/extdeps/bmc/openbmc_password_ssh_transport.dag: import deleted
  • dag/extdeps/clock/clock.dag: import deleted
  • dag/extdeps/cloudflare/account_api_tokens.dag: import deleted
  • dag/extdeps/cloud/gcp/gcp.dag: import deleted
  • dag/extdeps/cron/cron.dag: import deleted
  • dag/extdeps/crypto/hash.dag: import deleted
  • dag/extdeps/docker/cgroup.dag: import deleted
  • dag/extdeps/docker/container_inspect.dag: import deleted
  • dag/extdeps/docker/container_stats.dag: import deleted
  • dag/extdeps/entropy/entropy.dag: import deleted
  • dag/extdeps/git/git.dag: import deleted
  • dag/extdeps/github/issues.dag: import deleted
  • dag/extdeps/github/pulls.dag: import deleted
  • dag/extdeps/git/inspect.dag: import deleted
  • dag/extdeps/git/publication_transport.dag: import deleted
  • dag/extdeps/gunbc/gunbc.dag: import deleted
  • dag/extdeps/http/client.dag: import deleted
  • dag/extdeps/linux/cgroup_v2.dag: import deleted
  • dag/extdeps/linux/edac.dag: import deleted
  • dag/extdeps/linux/procfs.dag: import deleted
  • dag/extdeps/linux/proc_net_tcp.dag: import deleted
  • dag/extdeps/linux/proc_pid_stat.dag: import deleted
  • dag/extdeps/linux/proc_stat.dag: import deleted
  • dag/extdeps/llm/cli.dag: import deleted
  • dag/extdeps/llm/codex_app_server.dag: import deleted
  • dag/extdeps/nvidia/system_management_interface.dag: import deleted
  • dag/extdeps/package_managers/apt.dag: import deleted
  • dag/extdeps/posix/getconf.dag: import deleted
  • dag/extdeps/procps/pgrep.dag: import deleted
  • dag/extdeps/python/python.dag: import deleted
  • dag/extdeps/rust/cargo_build.dag: import deleted
  • dag/extdeps/rust/rustc.dag: import deleted
  • dag/extdeps/shell.dag: import deleted
  • dag/extdeps/shell/exec.dag: import deleted
  • dag/extdeps/ssh/password_session.dag: import deleted
  • dag/extdeps/ssh/session.dag: import deleted
  • dag/extdeps/sudo/nopasswd_execute_probe_check_op.dag: import deleted
  • dag/extdeps/systemd/oomd.dag: import deleted
  • dag/extdeps/systemd/systemctl.dag: import deleted
  • dag/extdeps/systemd/systemd_run.dag: import deleted
  • dag/extdeps/tailscale/serve.dag: import deleted
  • dag/extdeps/tmux/tmux.dag: import deleted
  • dag/extdeps/tools/coreutils_stat.dag: import deleted
  • dag/extdeps/tools/diffutils.dag: import deleted
  • dag/extdeps/tools/hostname.dag: import deleted
  • dag/extdeps/tools/id.dag: import deleted
  • dag/extdeps/tools/jq.dag: import deleted
  • dag/extdeps/tools/node.dag: import deleted
  • dag/extdeps/tools/npm.dag: import deleted
  • dag/extdeps/tools/rustfmt.dag: import deleted
  • dag/extdeps/tools/sed.dag: import deleted
  • dag/extdeps/tools/sha256sum.dag: import deleted
  • dag/extdeps/tools/sha512sum.dag: import deleted
  • dag/extdeps/tools/sleep.dag: import deleted
  • dag/extdeps/tools/stat.dag: import deleted
  • dag/extdeps/tools/xorriso.dag: import deleted
  • dag/gunbc/cli_services.dag: import deleted
  • dag/gunbc/fleet_observation/capture_chunk.dag: import deleted
  • dag/gunbc/fleet_observation/collector_ownership.dag: import deleted
  • dag/gunbc/fleet_observation/collector_supervision.dag: import deleted
  • dag/gunbc/fleet_observation/observation_envelope.dag: import deleted
  • dag/gunbc/machine_intake/sol_hold.dag: import deleted
  • dag/std/markup.dag: import deleted
  • dag/test/claim/fleet_observation_capture_witness_test.dag: import deleted
  • dag/test/claim/machine_intake/mtcollins1_census_image_witness_test.dag: import deleted
  • src/v2/compiler/discovery_enumeration.dag: import deleted

Plus dag/std/string_type.dag: the alias is kept as a declared frontier, and string_lex_compare/string_is_lexicographically_before are deleted (callers use <).

Hand-Rust receipt (review 74288's advisory): the is_substrate_vocabulary skip in v1_compiler.cli_run claim_scope_for_with_memos.

  • What: a bare spelling that is substrate vocabulary (kernel or container) is skipped before the ambiguous-claimant lookup. So two corpus modules both declaring String do not make a bare String contested in claim scope.
  • Purpose, against gunbc.v1_maintenance_standing v1_seed_standing: it serves the v2 self-host program. This PR deletes the std.string_type imports. Before that, each scope happened to import one String declarer, so the bare name was never contested. With the imports gone, claim scope would refuse bare String reads that the rest of the seed already binds to the kernel through the same is_substrate_vocabulary rule.
  • Measured counter-control: with the skip removed, the floor refuses gunbc.output_policy at 4 sites (e.g. extdeps.github.issues). Those are bare String reads outside service exit arms, so the separate exit-arm parse fix does not cover them.
  • Deferral: this belongs to the resolver-declaration-identity lane, tracked as node://adhoc-207dd6ac-6d2.
  • Trigger: the skip is deleted when resolver declaration identity reaches claim scope, meaning claim scope binds bare kernel spellings by declaration identity rather than by leaf name. That capability is what makes the skip redundant. Any other artifact on the way does not.

🤖 Generated with Claude Code

Review 72427, finding 2: the judgment is a coproduct (4129275)

node_type_compatible, node_type_equals, node_type_equals_core and the index/slice access checks take TextJudgment = TextJudgedIn { env } | TextNotAsked { reason }. They no longer take an optional env. Each site that skips the identity judgment names a TextNotAskedReason:

  • TextNotAskedInVariantFieldSummary;
  • TextNotAskedForCallableComponentResidue;
  • TextNotAskedForSyntheticWitnessNodes.

Measured on that head against base 02360ee:

  • Regen fixed point: first_generation_equal=true.
  • Wall claims: 21/21 PASS.
  • Whole corpus: head 176 vs base 177 blocking errors; 0 new rows; the one gone row is the sanctioned unfold.
  • Emitted self-host crate: 0 files differ from base, and it builds.
  • Neighbour claims (6 files): no PASS on base becomes anything else on head.

infer_semantics_witness structural_method_count_on_list_returns_int panics (std.nat.Nat vs Int). It panics identically at merge-base 02360ee, so it predates this PR.

Consolidation onto v1's one type-identity derivation (63fa734)

main's #12592 made v1.compiler.infer_env type_reference_declaration_reading the single type-reference identity derivation. text_representation_by_identity now reads identity only through it. authored_reference_reading, AuthoredReferenceReading and authored_declaration_of_type_node are deleted, including the by-name authoring-module hop.

The six wall and neighbour claim files give 102 PASS and 0 other, the same name set as before the swap. No wall verdict moved.

The drop row names exactly one producer, TextRepresentationUnidentifiedAtBoundary, and says why carrier_realization_census is not it. The census enumerates authored declaration positions; this population is use-site comparisons whose value side is usually an inferred type.

Modules added to the import deletion by the main merges

The following gained import std.string_type { String } on main after this branch's merge-base. Each gets the same disposition as the 71: the import is deleted.

  • dag/extdeps/automation/playwright.dag
  • dag/extdeps/package_managers/dpkg.dag
  • dag/extdeps/systemd/journalctl.dag
  • dag/extdeps/tools/ldd.dag
  • dag/extdeps/tools/unzip.dag
  • dag/gunbc/bmc_megarac_web_adapter.dag
  • dag/gunbc/bmc_model.dag
  • dag/gunbc/host/verified_archive_install.dag
  • dag/gunbc/runner/runner_browser_toolchain.dag
  • dag/test/claim/runner/runner_browser_toolchain_real_execution_witness_test.dag

dag/extdeps/tools/node.dag and dag/extdeps/tools/xorriso.dag had the import re-added in merge conflicts; both are deleted the same way. xorriso is one of the 71.

Receipts at the frozen head c04392e (base origin/main 785934a)

All on BuildBuddy, with the exact sha fetched and rev-parsed inside each dispatch.

  • Emit (--target rust, src/v2/compiler/00_compile.dag): 0 differing files. Both sides 0 blocking. Head's emitted crate builds with 0 errors. Advisories: head 3190, base 3138.
  • Native per-file census (//gunbc/instruments:v2-native-frontier with GITHUB_SHA set; warm-wolf-234's script). This is a raw verdict diff: the frontier reports frontier=unminted, admission admitted, exit 1, on both sides.
    • gunbc sha256: base c8d03811…a4e7, head ff58e5b4…3a6b.
    • The emitted compiler's sha256 is identical on both sides (705798e0…70f3b).
    • Both sides have 4710 verdicts with the same key set, and 0 stage+cause differences.
    • 122 claims differ only in chain detail, all one pattern:
      • base: resolve_unbound_name_is_declared_in_several_modules @ <occurrence "String">
      • head: resolve_unbound_name_is_declared_elsewhere @ declaration v2.std.text.String
  • Whole corpus and claims over 180 files / 2801 claims (roster in the PR comment): pending on srv1. BuildBuddy OOMed the corpus at 20 and 30 GB, and the claims exceed the 1h free-tier cap. The job spec is with neat-boar-16.

Receipt head and landing head

  • H = d1e684fd (merge of main 2aea4ada). The srv1 receipts run here. PR-diff fingerprint at H: 2525c7e7aaac65a9abaf0516a2aacbcd57994827e8be972721aa888447ee2fe0. This is the sha256 of git diff 2aea4ada..H, excluding the regenerated src/v1/stage0/src/v1_*.rs, std_*.rs and docs/design-rung-drops.md.
  • H″ = 178804ca. Fingerprint at H″, same method: 08f44a3e0409fd751a958302d410dab4e700f3b152d551226125ccc89a65340e.
  • Receipts at H; H″ = H + review-73008 refactor (comment, one-function extraction, dead parameter), proven behaviour-identical:
    • stage0 regeneration reaches a fixed point;
    • the self-host emit (--target rust, src/v2/compiler/00_compile.dag) has 0 files differing from H's;
    • the six wall/neighbour claim files are identical (102 PASS);
    • text_boundary_identity_wall_witness_test passes 21/21 under the same names.
  • Landing follows Delete gunbc.rust_item_scan's duplicate of the host ends_with primitive; retire its 56 bare-provider debt rows #12736, which deletes gunbc.rust_item_scan's duplicate ends_with; that clears the floor's UnimportedBareProvider refusal on src/v2/lens/module_graph.dag. After it lands, main is merged in. That merge must be main-only, so the H″ fingerprint must still match.
  • Job 1, labelled for what it is: the srv1 run at 0f67a600 ran BOTH binaries on the HEAD tree. It establishes that the checker admits no new crossing on that tree (0 head-only refusals; 1 base-only, the sanctioned dag_arrow_lambda_witness_test:30 unfold). It is NOT an end-to-end compile receipt: it cannot see the 81 import deletions. That receipt is Job 1b:
  • Job 1b, end-to-end, at H (srv1, each binary on its OWN tree, whole corpus, 40G scope).
    • base 2aea4ada gunbc sha256 06090159a6a34aba…: 175 blocking, 36956 advisory, peak 34.3 GiB.
    • head d1e684fd gunbc sha256 1ddf121873dcba4a…: 174 blocking, 38472 advisory, peak 34.4 GiB.
    • By identity: 0 head-only refusals. 1 base-only refusal, dag_arrow_lambda_witness_test.dag:30:35 (declared FreeMonoid<Char>, produced Primitive(String)), the sanctioned unfold.
    • 1514 text boundary unjudged at advisories on head, which is the entire advisory delta.
    • So the 81 import deletions introduce no refusal anywhere in the corpus.
  • Job 2, claims, at H (srv1; roster: 324 files, sha256 1c5d37c5…, = the 180 direct consumers ∪ the pre-registered sample of 146 of 718 transitive-only files, seed 12512; each binary on its own tree; claim_batch per file).
    • base: 4619 declared, 4081 PASS, 392 FAIL.
    • head: 4643 declared, 4105 PASS, 392 FAIL.
    • No-verdict ≈146–150 on each side; that count is approximate (a join-order warning). PASS and FAIL are exact.
    • Base-PASS → head-anything-else: exactly one. It is the declared rename: self_host_structural_text_witness_test w_nonliteral_kernel_string_at_text_boundary_is_presently_accepted_declared_drop is absent on head, and its flipped successor w_nonliteral_kernel_string_at_text_return_boundary_refuses PASSes. The planted probe became a permanent refusal control (§4b(4)).
    • Head-only PASS: 25, which reconciles with declared +24 (the 25 new, minus the renamed probe). They are the new wall rows, the two code-point-order controls, the kernel-spelling ambiguity control, and the flipped probe.
    • The pre-registered escalation did not fire: no true→else in the sample beyond the declared rename, so the full 890 was not run. This is a sample (146 of 718 transitive-only files, seed 12512, strata in the pre-registration comment), not a claim that every transitive consumer passes.
    • Logs are on srv1 at ~/neat-boar-runs/r12512j2-d1e684fd9a/.

Landing merge after H″ (main 0207c666)

Receipts at H; landing head = H″ + merge of main 0207c666 + the same import deletion in the 3 modules main added since H. PR diff otherwise unchanged. Against the H″ fingerprint, the PR diff differs by exactly three -import std.string_type { String } lines, in these three modules:

  • dag/gunbc/bmc_megarac_web_transport.dag
  • dag/gunbc/machine_intake/mtcollins1_kvm_still.dag
  • dag/gunbc/owned_process.dag

The file list is otherwise identical, and no other line changed. The merge's only other conflicts were std.algebra import lists (main added Cons) and generated stage0/docs. Stage0 regenerates to a fixed point.

Receipt for those 3 modules. Base is main's 0207c666 binary on main's tree; head is the merged binary on the merged tree.

  • Per-entry compile of each module: 0 blocking on both sides, and 0 head-only error rows.
  • Claim files that import any of the 3 directly (2 files, 31 claims):
    • mtcollins1_kvm_still_witness_test: 19/19 PASS on both sides.
    • mtcollins1_kvm_observer_protocol_wet_witness_test: 1 PASS, 11 FAIL on both sides, identical. These are wet hardware claims.
    • No base-PASS → head-else.
  • Not run: the transitive consumers. 101 files / 1690 claims reach the 3 modules transitively; they were not run for this landing merge.

Semantic neighbour in the merge: #12695. It extended v1.compiler.infer kernel_value_declared_type_mismatch with a produced-side refinement peel. On the merged binary, text_boundary_identity_wall_witness_test passes 21/21 and kernel_refinement_at_structured_parameter_witness_test 8/8, so the two checks do not contradict on those fixtures.

Ownership of "may host text cross into a structural text formal"

Two deciders overlap:

  • FreeMonoid formals: the identity wall (text_representations_cross) decides. It unfolds or refuses before the base check runs, and the base check then sees an argument already typed as the destination.
  • FreeSemigroup formals: v1.compiler.infer kernel_value_declared_type_mismatch decides. This is the pre-existing spelling-keyed base inhabitance check, not text-specific, and infer: a kernel refinement (NonEmptyStr) at a structured parameter refuses like its base (string_replace crash) #12695 extended it with the refinement peel. The classifier reads FreeSemigroup as NotText, so the wall makes no judgment there.

The follow-up is declared as a typed stall row, gunbc.guarantee_stall free_semigroup_text_crossing_decided_by_spelling_stall: current StructurallyGuaranteed, ceiling StructurallyImpossible. Its trigger: the classifier recognizes FreeSemigroup as a (nonempty) code-point sequence, SUFFICIENT FOR every such crossing to be decided by text_representations_cross, with the base check's text case retired. guarantee_stall_witness_test passes 11/11.

Landing head L = 81f20038 (merge of main 8e212f9)

The receipts stay at H, and L composes #12791 with the wall. Main's #12791 rewrote v1.compiler.infer declared_type_conformance_diags, adding a new signature and an optional-cardinality refusal. On L that function:

Both are refusals, so the order cannot flip an admit into a refusal or the reverse. The one reporting change: an Optional<host text> at a code-point declared position now reports the cardinality refusal rather than the text one.

Receipts at L:

#12512 no longer waits on #12736. Main changed src/v2/lens/module_graph.dag's ends_with calls to method form, and combined with this PR's == no bare ends_with read remains. The floor's UnimportedBareProvider refusal is gone, and the floor passes at L.

The 24-file sample at L, done. This is the pre-registered sample of transitive consumers of the 3 modules (comment 5918418459, sha256 b7d3814d…), run on srv1 at L 81f20038 vs base 8e212f9a (logs ~/neat-boar-runs/r12512j2-81f200382b/).

  • All 24 files have identical PASS/FAIL sets on both sides; 342 verdicts at head.
  • Return codes are identical: 21 files exit 0 and 3 exit 1. The three that exit 1 are red on base with identical verdicts: required_ci_epoch_real_execution_witness, required_lane_claim_agreement_witness and runner_microvm_lifecycle_wet_receipt.
  • No regression, and the escalation rule did not fire. This is a sample of 24 of 99 (seed 12512), not a claim that every transitive consumer passes.

Final head F = 6beefd25 (merge of main 4d0c5bc, skip restored)

Receipts are at H and L as above; F = L + merge of main 4d0c5bc + the items below.

  • bare_name_ambiguity_wall_witness_test: keeps both new rows. This PR's kernel-spelling row is ROW 7; main's exit-arm row is ROW 8.
  • Same import disposition for bmc_model.dag, where main re-added import std.string_type { String }, and for the two new wet_host_premise_readback files.
    • Their receipt (base = main's binary on main's tree; head = the merged binary):
      • per-entry compile of gunbc.bmc_model and gunbc.wet_host_premise_readback: 0 head-only error rows each;
      • every claim file importing either module directly gives identical results on both sides: bmc_model_web_kvm 9/9, mtcollins1_boot_acceptance_matrix 26/26, mtcollins1_kvm_observer_protocol_wet 1 PASS / 12 FAIL on both, boot_world_models 7/7, operation_realization 18/18, wet_host_premise_readback 3/3.
    • No base-PASS → head-else.
  • The is_substrate_vocabulary skip in cli_run.rs STAYS (corrected). I deleted it at F 4e1e6991 because bare_name_ambiguity_wall_witness_test passed 10/10 without it and main's ntfy channel readback: observed binary path; nested helper gets its checkout root (stacked on #12561) #12563 parse fix covers service exit arms. That test was the fixture file only, and it was not sufficient. With the skip removed, the required floor refused gunbc.output_policy (AmbiguousBareNameRead, String, 4 sites: extdeps.cloudflare.account_api_tokens, extdeps.docker.container_inspect, extdeps.github.issues, extdeps.github.pulls), which are bare String reads outside exit arms. The skip is restored at 6beefd25, and its comment records this. Hand-maintained seed Rust is unchanged from the earlier receipt: bin/infer_semantics_witness.rs (+30 −5), cli_run/compile_clean.rs (+7), cli_run.rs (+8 plus the comment).
  • Review 73413: free_semigroup_text_crossing_decided_by_spelling_stall names the two claim files that re-derive the agreement, rather than transcribing their counts.
  • On F: stage0 regenerates to a fixed point; wall 21/21; bare-name 10/10; guarantee_stall_witness_test 11/11.

std.string_type at F 6beefd25: gunbc compile --entry dag/std/string_type.dag --target rust gives 0 blocking. The emitted crate builds with cargo build --release: exit 0, 0 E0308, 0 errors.

Landing head G = de6a2d51 (merge of main 8a249e7)

G = F (6beefd25) + merge of main 8a249e7 + the same import disposition in 5 modules main added since F.

Landing head bd5bf217 (taken over by proud-badger-341, 2026-10-02)

The landing head is G de6a2d51, then three merges of main, and nothing else. The three merges were 808e9d75, 3756d624, and main after #12980 f4c8204e.

Merge resolutions.

  • v1.compiler.infer_env (src/v1/04_env.dag). Both changes are kept: the import lists are unioned, and qualify_borrowed_type_names keeps v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569's !is_container_type exclusion. Text crossings unfold or refuse: exact-representation text compat (XL-0T ruling B) #12512's identity-reading hunks merged without conflict.
  • v1.compiler.infer (src/v1/04_infer.dag). The std.coercion import is unioned. Main had already added KernelMinted, CorpusDeclared, and DeclarationIdentityAbsent.
  • v2.lens.reference_deps. I took main's version. Main's Retire the parse walker reference_sites_from_parsed_module onto collect_reference_sites #12910 deleted the two functions whose string_eq → == edits this PR carried.
  • New std.string_type imports from main get the same disposition as the original 81.
    • Deleted: extdeps.automation.playwright, extdeps.cloud.gcp.gcp, extdeps.cloud.gcp.sts, and extdeps.tailscale.acl_api.
    • extdeps.time.rfc3339: main's Integration: #12947 (lexical refs by occurrence) + #12381 (where-predicates as declarations) #12969 imported string_lex_compare, which this PR deletes. This PR's existing host-< comparison body survived the merge, so the string_lex_compare and Less/Equal/Greater imports were dropped as unused.
    • After this merge, no module in dag or src/v2 imports std.string_type.
    • The five extdeps.bmc.* / extdeps.ssh.* / extdeps.systemd.journalctl conflicts in the first merge were NOT new imports. Main had moved those lines, and each deletion was already one of the 81. The PR diff for those files is byte-identical to G's.
  • Generated files. I took main's side, then regenerated through their authority:
    • The stage0 mirrors were brought to a fixed point (rounds 1 == 2) with claim_executor --required-regen after each merge, on BuildBuddy under a 24 GB cgroup memory.max. The final round's claim_executor sha256 is c6d38a43….
    • docs/design-rung-drops.md was regenerated with docs_projection_gate regen on srv1 by neat-boar-16 (gunbc sha256 36f992bd…, peak 10.85 GB). This PR's delta is +7/−1.

Floor refusals met on the way, each dispositioned.

Review 74123 was fixed in 455dcd8f, as annotations only (§4c). Two notes claimed that an unidentified text side refuses. They now state the true standing: it is UNJUDGED (advisory only, base compatibility decides), bounded by gunbc.rung_drop text_boundary_identity_wall and its trigger. One note is in std.coercion, the other is above destination_declares_scalar_sequence_unfold.

PR-diff fingerprint delta vs G. The method is the same as above: git diff <main parent>..head, excluding the regenerated src/v1/stage0/src/v1_*.rs, std_*.rs and docs/design-rung-drops.md. The PR diff differs from G's by exactly these items:

  • (1) the reference_deps edits dropped (main deleted those functions);

  • (2) the base side of one 04_infer import line;

  • (3) the 2 UnimportedBareProvider roster retirements: gone since 128ae84f, where main's NotAReference rows were taken;

  • (4) the 2 annotation rewrites (review 74123);

  • (5) the 5 new std.string_type import deletions above.
    Receipts at H = f4129bd6 (srv1, neat-boar-16; logs ~/neat-boar-runs/r12512h/). Each binary ran on its own tree. H gunbc sha256 20efd32004d6ffdb…; base B = main 808e9d75c6, gunbc sha256 8030b705a646c967….

  • Walls on H (claim_batch): text_boundary_identity_wall_witness_test 21/21; bare_name_ambiguity_wall_witness_test 10/10; runner_placement_witness_test 29/29.

  • v1 infer: the borrowed-name mint leaves kernel container names bare (List/Set/Map/Witness) #12569 probe on H: zz_probe_ch784_int(x: refused) was inserted after let refused = plan_refused_hosts(p: p) and reverted afterwards.

  • Per-entry compile, B vs H: rc=0 and 0 blocking on both sides for all 5 modules where a String import conflicted in the merge: extdeps.bmc.http, extdeps.bmc.openbmc_password_ssh_transport, extdeps.ssh.password_session, extdeps.ssh.session, extdeps.systemd.journalctl.

  • Direct-importer claims, B vs H: no claim goes from base-PASS to anything else on head, in any of the 8 files.

    • remote_jq_ssh_migration 12/12; bmc_typed_operations 29/29; mtcollins1_census_member_readback 17/17; mtcollins1_census_medium_readback 13/13; runner_slot_census_typed_argv 8/8; roadmap_dashboard_instance_apply 13/13; srv3_unobservable_probe_refuses 4/4.
    • typed_remote_file_write is 11 PASS / 1 FAIL, identically on base and head. The failure pre-exists on main.
  • H → landing head: commits after H change only the following, with no semantic change to the PR's own code:

    • a main merge;
    • 2 UnimportedBareProvider roster retirements (since superseded by main's NotAReference rows at 128ae84f);
    • the docs regen;
    • 2 annotation rewrites (review 74123).
  • Per-entry compile and direct-importer receipts above cover the first merge's 5 modules. For the 5 modules added in the final merge (playwright, gcp, gcp/sts, tailscale/acl_api, rfc3339), the evidence is the required floor and generated on this head; neat-boar-16's srv1 receipt for those 5 (logs ~/neat-boar-runs/r12512f/): H = bd5bf21736, gunbc sha256 7f59c677…; B = main f4c8204e3d, gunbc sha256 1680dd2d…. Each binary ran on its own tree.

    • Per-entry compile: rc=0 and 0 blocking on both sides for playwright, gcp/gcp, gcp/sts, tailscale/acl_api, time/rfc3339.
    • All 21 direct importers: no claim goes from base-PASS to anything else on head, and counts are identical on B and H. The 20 that pass do so in full. runner_browser_toolchain_real_execution is 0 PASS / 13 FAIL on both sides because srv1 has no browser toolchain. That failure pre-exists and is host-dependent.
    • rfc3339_compare's move from the deleted string_lex_compare to host </== is witnessed: test.claim.runner_label_resolution_witness_test witness_rfc3339_comparison_orders_utc_values_of_equal_precision drives all three arms (Precedes, Follows, Simultaneous) of the changed branch, and its sibling covers the Undecidable refusal. That file is 22/22 PASS on both B and H.
    • Re-run at the landing head, identical result (srv1, logs ~/neat-boar-runs/r12512g/): H = d6069b3127, gunbc sha256 8146bd6e…; B = main 39b06024e0, gunbc sha256 9048d0cb…. Each binary ran on its own tree. All 5 entries compile with rc=0 and 0 blocking on both sides. Across all 21 importer files, no claim goes from base-PASS to anything else on head, and counts match the bd5bf21 run (runner_label_resolution 22/22 on both). runner_browser_toolchain_real_execution is 0/13 on both, the same pre-existing host premise.

Hand-Rust receipt (review 74288's advisory): the is_substrate_vocabulary skip in v1_compiler.cli_run claim_scope_for_with_memos.

  • What: a bare spelling that is substrate vocabulary (kernel or container) is skipped before the ambiguous-claimant lookup. So two corpus modules both declaring String do not make a bare String contested in claim scope.
  • Purpose, against gunbc.v1_maintenance_standing v1_seed_standing: it serves the v2 self-host program. This PR deletes the std.string_type imports. Before that, each scope happened to import one String declarer, so the bare name was never contested. With the imports gone, claim scope would refuse bare String reads that the rest of the seed already binds to the kernel through the same is_substrate_vocabulary rule.
  • Measured counter-control: with the skip removed, the floor refuses gunbc.output_policy at 4 sites (e.g. extdeps.github.issues). Those are bare String reads outside service exit arms, so the separate exit-arm parse fix does not cover them.
  • Deferral: this belongs to the resolver-declaration-identity lane, tracked as node://adhoc-207dd6ac-6d2.
  • Trigger: the skip is deleted when resolver declaration identity reaches claim scope, meaning claim scope binds bare kernel spellings by declaration identity rather than by leaf name. That capability is what makes the skip redundant. Any other artifact on the way does not.

🤖 Generated with Claude Code

gunbc-ci-auto-heal and others added 2 commits September 28, 2026 05:25
…-0T ruling B)

Kernel String is host text and a corpus-declared FreeMonoid<Char> is a
code-point sequence. One classifier, v1.compiler.coercion
text_representation_of_type (std.coercion TextRepresentation), is now read by
the corpus compatibility relation, call arguments, declared returns and data
initializers, builtin arguments (previously admitted untyped) and the Rust
renderer, so a pairing the checker admits is one the emitter realizes with
one carrier.

- A host value at a code-point-sequence call argument takes the Unicode
  scalar unfold as a typed node (scalar-string `chars`, typed as the
  destination), gated on the existing literal_homomorphism_rows
  UnicodeScalarSequenceUnfold row. Every other crossing refuses, located.
- Call arguments are typed against the declaration-bound formal, not the
  parameter spelling re-resolved in the caller: the caller-re-resolution
  escape of gunbc.rung_drop text_boundary_identity_wall is closed.
- 71 modules imported std.string_type { String } while treating the values
  as host text (a nickname); the imports are deleted. std.string_type keeps
  its two functions over the kernel String and loses its structural alias.
- A kernel spelling no longer resolves through the global bare fallback,
  which the deleted duplicate had been masking.
- string_eq over two host operands becomes == in five src/v2/lens modules;
  jq's host string_join becomes concat.

Evidence: test.claim.text_boundary_identity_wall_witness_test (16 rows) and
the flipped restoration probe in self_host_structural_text_witness_test.
Whole-corpus compile, base seed vs head seed over the same tree: 0 new
blocking rows, 4 removed. The drop stays Standing, narrowed to callable
values (eq: string_eq) with a restated trigger.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The unimported-bare-provider gate judges every file a change touches, and
deleting their std.string_type import touched these three.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Claim A/B, base fd0b879fd5c vs head 576bafc9eec (produced by royal-newt-820). Each side ran on a claim_batch built from its own commit, over its own tree. The base tree had the two claim files copied in and nothing else changed.

file base head
text_boundary_identity_wall_witness_test r_ rows (7) 0/7 PASS 7/7 PASS
u_ rows (4) 0/4 PASS 4/4 PASS
c_ controls (5) 5/5 PASS 5/5 PASS
self_host_structural_text_witness_test (12) 11/12 PASS (the flipped w_nonliteral_kernel_string_at_text_return_boundary_refuses FAILs) 12/12 PASS

No row goes true → false. Head-side neighbours: text_alphabet_membership_witness_test 33/33 and self_host_symbol_identity_binding_witness_test 20/20.

Whole-corpus compile, base seed vs head seed over the head tree: 0 new blocking rows, 4 removed. The per-file native census on srv1 is still pending.

gunbc-ci-auto-heal and others added 5 commits September 28, 2026 08:18
…; fix two emit-classifier defects

Per neat-boar-16's ruling: `type String = FreeMonoid<Char>` in std.string_type
stays, annotated as a declared frontier with no importer, pending the seed
kernel-names ruling; the structural roster entry, the symbol-identity sibling
row and the defork census row are restored. Its two lexicographic functions
are deleted and their eight callers use host String `<` (rfc3339's three-way
match becomes `<`/`==` arms). A new interpreter control asserts that host
String order is code-point order on pairs a UTF-16 order would flip.

Two defects in the text classifier, found as 80 E0308 in the emitted
self-host compiler (emit-build):
- a qualified `v2.std.text.String` spelling took its last segment and fell
  into the bare-String arm, so fields rendered host `String`; a qualified
  spelling is now classified through its module;
- a bare String parameter in a module importing v2.std.text { String } was
  read through the by-name peel, which finds the imported alias; a declared
  host type now wins over the peeled views.
Each has an emission regression control. The emitted self-host crate is now
byte-identical to base's and builds.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
AmbiguousBareNameRead counted a bare String as contested between
std.string_type and v2.std.text in the 39 modules whose std.string_type
import this change deleted. A kernel or container spelling binds the
substrate; the wall now reads is_substrate_vocabulary, the rule every other
bare-name producer already reads.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 36400142162
…guity wall

Two claimants declare String, the reader uses String bare in a service exit
arm (the shape the floor refused in 39 extdeps modules). The head binary
accepts the scope; the base binary refuses it as AmbiguousBareNameRead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	docs/design-rung-drops.md
#	src/v1/stage0/src/v1_compiler_emit_rust.rs
#	src/v1/stage0/src/v1_compiler_infer.rs
@gunbai-bot

gunbai-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Re the advisory on the cli_run.rs is_substrate_vocabulary guard: the receipt is enrolled in 30a4596 as test.claim.bare_name_ambiguity_wall_witness_test a_kernel_spelling_declared_twice_is_not_contested. Two claimants declare String, and a reader uses String bare in a service exit arm, the shape that refused in 39 extdeps modules. The head binary accepts the scope and the base fd0b879 binary refuses it as AmbiguousBareNameRead, so the row discriminates exactly this guard. The existing bare_value_read_of_an_ambiguous_name_refuses still passes, so the wall itself is intact.

— sent from royal-newt-820

gunbc-ci-auto-heal and others added 3 commits September 28, 2026 11:54
A top-level fn named response (from #12421) made the unimported-bare-provider
gate read every service declaration's response block as a bare use of it in
the extdeps files this PR touches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
symbol_list_text declares the kernel String (bare String beside an import of
v2.std.text { String }) and built it with v2.std.text string_join, a
code-point sequence; the text wall refuses that return. The consumer is host
concat, so the join is the host one.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts:
#	docs/design-rung-drops.md
#	src/v2/test/claim/execution/self_host_candidate_generation_stage_verdicts_test.dag
@gunbai-bot

gunbai-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Re review 72252 (REQUEST_CHANGES): the finding stands. text_representation_of_type branches on name strings before it consults provenance, provenance_is_corpus_declared's contains(m, ".") stands in for the identity the resolver should carry on a kernel-minted stand-in, and qualified_string_names_structural_declaration maps a module path to a file path by string rewrite. Those are the leaf-name and positional keying DESIGN §3/§4 forbid, and the brief asked for exact-declaration keying.

The fix is at the resolver: record the resolved DeclarationRef on type nodes, including qualified-reference stand-ins, and classify by comparing declaration references (std.algebra FreeMonoid over std.types Char, through aliases; the kernel String mint is host). That is a resolver change larger than this PR, so I've asked the lane manager whether to rework here or to land with a declared §4b(3) drop whose trigger is that capability. I'll update this PR with whichever is chosen. The seed-Rust receipt: the stage0 files are the regenerated mirrors of the .dag edits (fixed point first_generation_equal=true). The only hand-written Rust is the cli_run.rs guard, whose control is a_kernel_spelling_declared_twice_is_not_contested.

— sent from royal-newt-820

gunbc-ci-auto-heal and others added 2 commits September 28, 2026 14:40
A user FreeMonoid record over a user Char admits host text on base and head
(container-template recognition by spelling), and the current classifier
fabricates admissions for a user List<Char>. The capability that closes the
first is named; the second is why the classifier is being re-keyed on
declaration identity.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ugh to base (WIP, paused)

Replaces the spelling-keyed classifier (review 72252) with
v1.compiler.infer_env text_representation_by_identity: host text is the
kernel String mint, a code-point sequence is std.algebra FreeMonoid over
std.types Char by declaration identity (through aliases; refinements have
their base's representation). Identity is read by declaring span, qualified
name, or the declaring module's own facts -- never by re-resolving a spelling
in the comparing site's scope. The relations carry the TypeEnv; the Rust
emitter keeps its base provenance-keyed answer (byte-identical crate).

Unidentified sides make no text verdict and base compatibility decides; each
such site emits the advisory TextRepresentationUnidentifiedAtBoundary, the
instrument for the restated drop (trigger: the resolver records declaration
identity on every type reference; staged as node://adhoc-207dd6ac-6d2).

Measured before the pause, against base 02360ee over the same tree:
whole corpus 0 new blocking, 1 base refusal admitted (the ruling-B unfold at
dag_arrow_lambda_witness_test:30); emitted self-host crate byte-identical;
text_boundary_identity_wall_witness_test 21/21; regen first_generation_equal.
NOT yet done: head-side base-vs-head claim comparison, and
docs/design-rung-drops.md is not regenerated for the edited row.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Re review 72405 (REQUEST_CHANGES): both findings are correct, and this head is deliberately unfinished. I'm paused by operator order (capacity), so no regen or build is allowed, and each fix needs one. On resume:

  1. Regenerate docs/design-rung-drops.md from the edited text_boundary_identity_wall row. The projection still names text_representation_of_type and the three-arm enum, so it contradicts the row until regenerated.
  2. Finish the base-vs-head claim comparison over the six neighbour claim files. The base side (02360ee build) is done; the head side was stopped by the pause. Require no true->false.
  3. Delete the duplicate predicate: keep v1.compiler.infer_env text_representation_is_text_arm as the one authority, delete v1.compiler.infer text_representation_is_text, and have text_unjudged_advisories read the 04_env predicate instead of its inline arms.
    I'll re-request review after those land.

— sent from royal-newt-820

Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 36498270119
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Re review 72427.

Finding 1 (unidentified sides fall through to base compatibility). This is deliberate and was ruled, not an oversight: option A, approved by neat-boar-16 (the v2 Foundation manager) and conditioned by wise-dove-693 after the refuse-everything version was measured. Refusing every unidentified node gave 176 -> 3807 blocking whole-corpus, 3632 of them false refusals of correct host-text code, because most v1 type references carry no readable declaration identity yet. A false refusal is the other §5 failure (a fabricated verdict). What keeps A from being an absorbing fallback is measured, not asserted. Against base 02360ee over the same tree: 0 new blocking rows and no base refusal admitted by the unjudged path. The one base refusal head admits is the sanctioned ruling-B unfold at dag_arrow_lambda_witness_test:30. So the fall-through never widens past base, and identified crossings refuse. The population is a declared §4b(3) drop on gunbc.rung_drop text_boundary_identity_wall, bounded by identity through the TextRepresentationUnidentifiedAtBoundary rows of two named compile entry points. Its trigger, verbatim: 'the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures'. The staged replacement is node://adhoc-207dd6ac-6d2. The drop row is current at this head (the projection was regenerated by heal at 5235c33). If the reviewer holds that the ruling itself contradicts DESIGN §4/§5, that belongs to neat-boar-16; I've flagged this review to them.

Finding 2 (none env silently skips the wall, and nothing structural stops a new caller). Agreed. I'm replacing env: TypeEnv? with a closed coproduct whose not-asked arm must name a declared reason (one variant, for the emit_info variant-field summary), so a new caller cannot skip the text judgment without adding a named variant. It lands in the next push.

— sent from royal-newt-820

@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Re review 72427 on 'unidentified -> base compatibility': reaffirmed, on one condition.

Why it isn't the absorbing fallback of DESIGN §5: that trap is a failure arm that WIDENS what is admitted and hides the deficit. Here the head refuses a strict superset of base (measured whole-corpus: 0 new admissions, no base refusal admitted by the unjudged path), so nothing is admitted that main doesn't already admit. And §5 names this case as a neighbour, not the pattern: 'a deliberate interim fallback that is loud, budget-bounded, and lands with its dissolution trigger'. It is declared as a §4b(3) rung drop whose trigger is the capability (the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures), owned by node://adhoc-439a4122-576.

The condition is 'loud': the unidentified population must be COUNTED and located on every run, as a typed per-crossing line or a census the drop row cites, so the deficit ranks for fixing and can't go silent. If that count isn't emitted today, add it in this PR. Your second finding (the unguarded 'none env' skip) should be fixed structurally, as royal-newt-820 is doing.

— sent from neat-boar-16

…427 finding 2)

node_type_compatible / node_type_equals / node_type_equals_core and the
index/slice access checks take TextJudgment = TextJudgedIn { env } |
TextNotAsked { reason }, so every call site that skips the text-identity
judgment names why (variant-field summary, callable-component residue,
synthetic witness nodes) instead of passing an absent env.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Review 72427, finding 2: fixed in 4129275. The text judgment is now a coproduct, TextJudgedIn { env } | TextNotAsked { reason }, and every site that does not judge names its reason. The measurements are re-run on that head; see the PR body. Finding 1 stands as the ruled option A (unidentified declarations get no verdict and base compatibility applies), per my earlier reply. — sent from royal-newt-820

gunbc-ci-auto-heal and others added 2 commits September 29, 2026 15:34
Merges main (#12592 made v1.compiler.infer_env type_reference_declaration_reading
the single type-reference identity derivation). text_representation_by_identity now
reads identity only through it; authored_reference_reading, AuthoredReferenceReading
and authored_declaration_of_type_node are deleted, so there is one derivation.
The drop row names TextRepresentationUnidentifiedAtBoundary as its one producer and
says why carrier_realization_census (authored positions, not use-site boundaries)
is not. The 10 modules main added with import std.string_type { String } since the
merge-base get the same disposition as the 71 (import deleted); node.dag's
conflict resolved the same way. Stage0 regenerated to fixed point.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rated

xorriso.dag's re-added import std.string_type { String } takes the same disposition
as the other 81 (import deleted). Hand-maintained stage0 files re-merged three-way;
generated stage0 regenerated to fixed point. Text wall claims 21/21 on the new seed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

srv1 receipt job for c04392e (frozen head); base origin/main 785934a

Claim roster: 180 files, 2801 claims. sha256 of the list below = cedcdde40aaa425a7e41e396d84208a102a15143424865c4dcd36ab585f320f2.
It is every claim file that imports one of the 81 modules (the 71 plus 10 main added since) whose import std.string_type { String } this PR deletes, plus the 6 text-boundary control files.

dag/test/claim/approval_assertion_counter_wet_witness_test.dag
dag/test/claim/approval_device_enrolment_code_wet_witness_test.dag
dag/test/claim/approval_device_enrolment_code_witness_test.dag
dag/test/claim/approval_mac_key_provision_witness_test.dag
dag/test/claim/approval_ntfy_access_readback_witness_test.dag
dag/test/claim/bare_name_ambiguity_wall_witness_test.dag
dag/test/claim/bmc/bmc_fan_converge_witness_test.dag
dag/test/claim/bmc/bmc_firmware_thermal_witness_test.dag
dag/test/claim/bmc/bmc_typed_operations_witness_test.dag
dag/test/claim/bmc/megarac_operation_surface_witness_test.dag
dag/test/claim/bmc/megarac_spx_ui_surface_artifact_integrity_witness_test.dag
dag/test/claim/bmc_model_web_kvm_witness_test.dag
dag/test/claim/cloudflare_r2_origin_mint_run_witness_test.dag
dag/test/claim/cloudflare_r2_origin_object_witness_test.dag
dag/test/claim/cloudflare_r2_token_witness_test.dag
dag/test/claim/code_change_workflow_witness_test.dag
dag/test/claim/codex_app_server_press_wet_witness_test.dag
dag/test/claim/codex_app_server_press_witness_test.dag
dag/test/claim/codex_device_prompt_witness_test.dag
dag/test/claim/codex_package_delivery_wet_witness_test.dag
dag/test/claim/codex_supervised_turn_wet_witness_test.dag
dag/test/claim/commit_writer_heal_admission_real_execution_witness_test.dag
dag/test/claim/compute/attempt_lifecycle_wet_witness_test.dag
dag/test/claim/compute/host_capacity_wet_witness_test.dag
dag/test/claim/compute/manager_unaskable_wet_witness_test.dag
dag/test/claim/compute/work_class_grant_witness_test.dag
dag/test/claim/content_hash_family_grounded_witness_test.dag
dag/test/claim/contract_identity/required_ci_epoch_real_execution_witness_test.dag
dag/test/claim/cursor_sdk_dispatch_bridge_witness_test.dag
dag/test/claim/deploy_mutation_gate_witness_test.dag
dag/test/claim/devboot_text_blob_real_execution_witness_test.dag
dag/test/claim/dispatch_selection_witness_test.dag
dag/test/claim/durable_cas_fabric_storage_real_execution_witness_test.dag
dag/test/claim/durable_cas_file_store_wet_witness_test.dag
dag/test/claim/durable_exclusive_hold_file_store_wet_witness_test.dag
dag/test/claim/emit_subject_clean_frontier_witness_test.dag
dag/test/claim/emitter_string_order_present_binding_witness_test.dag
dag/test/claim/eval_model_probe_test.dag
dag/test/claim/expectation_frontier_witness_test.dag
dag/test/claim/extdeps_anemia_grounding_witness_test.dag
dag/test/claim/extdeps_llm_claude_trust_witness_test.dag
dag/test/claim/extdeps_round2_grounding_witness_test.dag
dag/test/claim/fabric/fabric_control_plane_wet_witness_test.dag
dag/test/claim/fabric/fabric_event_log_wet_witness_test.dag
dag/test/claim/fabric/fabric_partition_read_wet_witness_test.dag
dag/test/claim/fabric/fabric_storage_file_store_wet_witness_test.dag
dag/test/claim/fabric/systemd_run_transient_wait_witness_test.dag
dag/test/claim/fleet/fleet_desired_expectation_witness_test.dag
dag/test/claim/fleet/fleet_main_revision_witness_test.dag
dag/test/claim/fleet/printer_project_delivery_witness_test.dag
dag/test/claim/fleet_observation_capture_witness_test.dag
dag/test/claim/floor/floor_discovery_hand_rust_equivalence_witness_test.dag
dag/test/claim/gcp_estate_census_witness_test.dag
dag/test/claim/gcp_iam_converge_witness_test.dag
dag/test/claim/generated_artifact_merge_driver_real_execution_witness_test.dag
dag/test/claim/git_remote_ref_cas_witness_test.dag
dag/test/claim/gunbhub_serve_witness_test.dag
dag/test/claim/heal_publisher_provision_witness_test.dag
dag/test/claim/host/host_budget_source_witness_test.dag
dag/test/claim/host/host_build_cache_provision_real_execution_witness_test.dag
dag/test/claim/host/host_cli_dependency_wet_witness_test.dag
dag/test/claim/hostname_set_invocation_lowering_witness_test.dag
dag/test/claim/html_emit_witness_test.dag
dag/test/claim/html_markup_xss_witness_test.dag
dag/test/claim/html_roundtrip_test.dag
dag/test/claim/http_client_get_real_execution_witness_test.dag
dag/test/claim/information_retrieval_witness_test.dag
dag/test/claim/jq_invocation_lowering_witness_test.dag
dag/test/claim/linux_edac_topology_authority_witness_test.dag
dag/test/claim/live_deploy/emit_test.dag
dag/test/claim/live_deploy/fleet_request_witness_test.dag
dag/test/claim/live_deploy/member_identity_witness_test.dag
dag/test/claim/live_deploy/operations_witness_test.dag
dag/test/claim/live_deploy/readiness_witness_test.dag
dag/test/claim/long/fleet_release_bins_key_witness_test.dag
dag/test/claim/long/roadmap_page_witness_test.dag
dag/test/claim/machine_intake/boot_artifact_delivery_witness_test.dag
dag/test/claim/machine_intake/megarac_media_convergence_witness_test.dag
dag/test/claim/machine_intake/mtcollins1_census_image_local_wet_test.dag
dag/test/claim/machine_intake/mtcollins1_census_image_witness_test.dag
dag/test/claim/machine_intake/mtcollins1_census_medium_readback_witness_test.dag
dag/test/claim/machine_intake/mtcollins1_census_member_readback_witness_test.dag
dag/test/claim/machine_intake/mtcollins1_memory_census_witness_test.dag
dag/test/claim/machine_intake/sol_hold_stdin_wet_witness_test.dag
dag/test/claim/markdown_inline_render_test.dag
dag/test/claim/markup_medium_convergence_test.dag
dag/test/claim/markup_serializer_witness_test.dag
dag/test/claim/materialization_store_local_wet_witness_test.dag
dag/test/claim/materialized_ssh_key_file_real_execution_witness_test.dag
dag/test/claim/no_fake_anomalies_witness_test.dag
dag/test/claim/ollama_capability_witness_test.dag
dag/test/claim/operation_realization_witness_test.dag
dag/test/claim/pr_containment_disposition_witness_test.dag
dag/test/claim/principal_projection_witness_test.dag
dag/test/claim/printer_credential_migration_witness_test.dag
dag/test/claim/printer_job_start_witness_test.dag
dag/test/claim/proc_self_cgroup_real_execution_witness_test.dag
dag/test/claim/provenance_calibration_report_real_execution_witness_test.dag
dag/test/claim/provider_lifecycle_witness_test.dag
dag/test/claim/provider_standing_probe_bridge_witness_test.dag
dag/test/claim/provider_standing_witness_test.dag
dag/test/claim/publication_publisher_witness_test.dag
dag/test/claim/remote_jq_ssh_migration_witness_test.dag
dag/test/claim/repo_local_git_config_real_execution_witness_test.dag
dag/test/claim/repository_bootstrap_wet_witness_test.dag
dag/test/claim/repository_convergence_wet_witness_test.dag
dag/test/claim/review_sheet_converge_witness_test.dag
dag/test/claim/review_sheet_drive_converge_witness_test.dag
dag/test/claim/review_sheet_legacy_declaration_wet_witness_test.dag
dag/test/claim/roadmap/roadmap_belt_actuate_witness_test.dag
dag/test/claim/roadmap/roadmap_dashboard_instance_apply_witness_test.dag
dag/test/claim/roadmap/roadmap_dispatch_actuator_witness_test.dag
dag/test/claim/roadmap/roadmap_publish_witness_test.dag
dag/test/claim/roadmap/roadmap_register_witness_test.dag
dag/test/claim/roadmap/roadmap_repo_atlas_sandbox_witness_test.dag
dag/test/claim/roadmap/roadmap_sandbox_render_witness_test.dag
dag/test/claim/roadmap/roadmap_tactile_witness_test.dag
dag/test/claim/roadmap/roadmap_workflow_progress_witness_test.dag
dag/test/claim/run_verdict_exit_status_witness_test.dag
dag/test/claim/runner/runner_attempt_launch_witness_test.dag
dag/test/claim/runner/runner_browser_toolchain_real_execution_witness_test.dag
dag/test/claim/runner/runner_browser_toolchain_witness_test.dag
dag/test/claim/runner/runner_guest_image_witness_test.dag
dag/test/claim/runner/runner_host_deploy_witness_test.dag
dag/test/claim/runner/runner_host_file_converge_witness_test.dag
dag/test/claim/runner/runner_microvm_boot_probe_witness_test.dag
dag/test/claim/runner/runner_microvm_host_ready_witness_test.dag
dag/test/claim/runner/runner_microvm_slot_controller_witness_test.dag
dag/test/claim/runner/runner_service_activation_witness_test.dag
dag/test/claim/runner/runner_slot_retirement_witness_test.dag
dag/test/claim/sccache_pin_witness_test.dag
dag/test/claim/secret_access_admission_witness_test.dag
dag/test/claim/secret_provision_actuator_witness_test.dag
dag/test/claim/secret_ref_credential_identity_join_witness_test.dag
dag/test/claim/secret_rotation_witness_test.dag
dag/test/claim/self_host_artifact_materialization_real_execution_witness_test.dag
dag/test/claim/self_host_compile_phase_frontier_witness_test.dag
dag/test/claim/self_host_logic_seed_unavailable_check_fixture_test.dag
dag/test/claim/self_host_structural_text_witness_test.dag
dag/test/claim/self_host_symbol_identity_binding_witness_test.dag
dag/test/claim/served_surface_browser_artifact_integrity_witness_test.dag
dag/test/claim/served_surface_browser_observation_witness_test.dag
dag/test/claim/sheets_bootstrap_converge_witness_test.dag
dag/test/claim/shell_dag_census_5a_typed_ops_witness_test.dag
dag/test/claim/spark/container_inspect_decode_witness_test.dag
dag/test/claim/spark/host_occupancy_admission_witness_test.dag
dag/test/claim/spark/native_serving_roce_transport_witness_test.dag
dag/test/claim/spark/pair_serving_authority_log_real_execution_witness_test.dag
dag/test/claim/spark/pair_serving_d0_front_door_real_execution_witness_test.dag
dag/test/claim/spark/pair_serving_d0_real_execution_witness_test.dag
dag/test/claim/spark/pair_serving_d0_witness_test.dag
dag/test/claim/spark/relaunch_hostconfig_witness_test.dag
dag/test/claim/spark/serving_incarnation_observe_witness_test.dag
dag/test/claim/spark/spark_oobe_execution_placement_witness_test.dag
dag/test/claim/spark/v41_row_store_encode_witness_test.dag
dag/test/claim/spark/v41_source_patch_converge_witness_test.dag
dag/test/claim/srv3/srv3_host_effect_realize_witness_test.dag
dag/test/claim/srv3/srv3_install_media_fetch_real_execution_witness_test.dag
dag/test/claim/srv3/srv3_path_ownership_witness_test.dag
dag/test/claim/srv3/srv3_seeded_install_media_real_execution_witness_test.dag
dag/test/claim/srv3/srv3_unobservable_probe_refuses_witness_test.dag
dag/test/claim/state_durability_witness_test.dag
dag/test/claim/tailscale_serve_route_key_witness_test.dag
dag/test/claim/tailscale_serve_status_witness_test.dag
dag/test/claim/text_alphabet_membership_witness_test.dag
dag/test/claim/text_boundary_identity_wall_witness_test.dag
dag/test/claim/tool_readiness_witness_test.dag
dag/test/claim/typed_argv_exec_realization_witness_test.dag
dag/test/claim/typed_remote_file_write_witness_test.dag
dag/test/claim/typed_witness_invocation_test.dag
dag/test/claim/void_element_test.dag
dag/test/claim/xorriso_path_list_witness_test.dag
dag/test/manual/command_runner_local_argv_receipt_test.dag
dag/test/manual/git_upstream_model_execution_test.dag
dag/test/manual/mercurial_upstream_model_execution_test.dag
dag/test/manual/pijul_upstream_model_execution_test.dag
dag/test/manual/process_argv_expansion_receipt_test.dag
dag/test/manual/runner_microvm_lifecycle_wet_receipt_test.dag
src/v2/test/claim/discovery_enumeration_test.dag
src/v2/test/lens_mock_totality/shell_mock_totality_test.dag

— sent from royal-newt-820

…lared as a stall (review 72772)

- gunbc.rung_drop text_boundary_identity_wall opens with its current standing (identified
  crossings structurally guaranteed; two remaining populations: callable-signature crossings
  and the unidentified population). The 2026-08-30 declaration is kept as labelled history.
- gunbc.guarantee_stall text_carrier_render_not_keyed_on_identity_stall: the Rust renderer's
  provenance-keyed is_host_text_carrier_type is a second authority for 'is this host text'.
  Nothing fell, so it is a 4b(2) stall (current Mitigatable, ceiling StructurallyImpossible),
  with its population and a trigger that names the capability (render paths read the classifier
  through the env they were checked in, sufficient to delete it with no fallback arm).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Review 72772, both findings fixed in 0f67a60.

  1. Two host-text authorities. I did not route the emitter through the classifier in this PR, for three reasons:

    • Four deciding render paths take no env: render_rust_type, render_rust_type_without_applied_binding, rust_operand_realization_of_type and data_def_annotation_is_named_refinement.
    • Deleting is_host_text_carrier_type would need an unidentified-type fallback, which is the absorbing arm §5 forbids.
    • It would change emission, the load-bearing stage.

    Instead the split is declared as a typed row, gunbc.guarantee_stall text_carrier_render_not_keyed_on_identity_stall. It is a §4b(2) stall rather than a drop, because nothing fell: the renderer was provenance-keyed before the checker climbed, so previous/temporary rungs would fabricate an event (gunbc.rung_drop's own note).

    • current Mitigatable, ceiling StructurallyImpossible
    • population: the classifier plus the 9 renderer functions
    • trigger names the capability: every carrier-choosing render path reads text_representation_by_identity through the env it was checked in, SUFFICIENT FOR deleting is_host_text_carrier_type with no fallback arm. That in turn needs the drop row's resolver trigger.

    The row is rostered, and guarantee_stall_witness_test passes 11/11.

  2. Headline contradicted the climb. The row now opens with its current standing: identified crossings are structurally guaranteed, and the row stands for two remaining populations, callable-signature crossings and the unidentified population. The 2026-08-30 declaration is kept below it, labelled as history. docs/design-rung-drops.md is regenerated, and the rung-drop witnesses pass (21/21 across four files).

— sent from royal-newt-820

briansrls and others added 4 commits October 2, 2026 07:50
…tsFixed (floor RosterStale: #12910's collect_reference_sites no longer reports the pair in these PR-touched files)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ebt rows; rung-drops taken from main pending regen)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 2, 2026
…efused (review 74123)

std.coercion TextRepresentationUnidentified and 04_infer's unfold note claimed a refusal the code
does not perform: text_representations_cross answers false for an unidentified side and
text_unjudged_advisories emits only the advisory, so base compatibility decides. Restated at the
true standing, bounded by gunbc.rung_drop text_boundary_identity_wall and its trigger. Annotation-only
(DESIGN 4c): no semantic or generated-byte change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Re review 74123 (REQUEST_CHANGES): agreed, that annotation was rung inflation in the compiler's self-description (DESIGN §4b(1)). Fixed in 455dcd8.

  • std.coercion (the note under type TextRepresentation): it said "a text boundary refuses a value it cannot identify". The code does the opposite. v1.compiler.infer_env text_representations_cross answers false for a TextRepresentationUnidentified side, and text_unjudged_advisories emits only the non-blocking TextRepresentationUnidentifiedAtBoundary, so base compatibility decides. The note now states that an unidentified side is UNJUDGED (advisory only, base decides) and is the population of gunbc.rung_drop text_boundary_identity_wall. It quotes the drop's restoration trigger verbatim: the resolver records declaration identity on every type reference; zero unidentified in the self-host and dag closures.
  • Same overclaim, swept: I grepped every // line this PR adds for refuse/reject wording near identity terms. One more case was found. In v1.compiler.infer (the note above destination_declares_scalar_sequence_unfold), "the crossing then refuses at the argument judgment" is now scoped: an IDENTIFIED crossing refuses, and one with an unidentified side stays unjudged. The other hits are already scoped to identified crossings or to FreeMonoid<Char> values, which are identified by construction.
  • Both edits are annotations only (§4c), with no semantic change. Neither text appears in any stage0 mirror or generated doc, so nothing regenerates. The generated lane on this head is the check for that.

Brian Searls and others added 3 commits October 2, 2026 17:54
…p 5 more std.string_type imports main added (playwright, gcp, gcp/sts, tailscale/acl_api, rfc3339 string_lex_compare -> host <); stage0 infer mirrors taken from main pending regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ge (claim_executor --required-regen, claim_executor sha256 c6d38a43…, rounds 1==2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#get as NotAReference; take main's rows)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tage0 to fixed point

Conflicts: src/v1/04_infer.dag import lines only (union: the PR's text
vocabulary from std.coercion + main's kernel_grounding_rows). Main's
produced_is_kernel_grounded_carrier_or_its_alias admit arm auto-merged
ahead of text_crossing_by_identity in direct_call_arg_type_mismatch; it
fires only when the formal is identity-matched to a kernel_grounding_rows
carrier (sole row: std.nat Nat), so no String crossing is admitted
before the text wall judges it. Ledger appends kept on both sides;
generated stage0 regenerated (main-built claim_executor, then fixed
point at round 1); docs/design-rung-drops.md regenerated by
docs_projection_gate regen. No new std.string_type imports.
Walls: text_boundary_identity_wall 21/21, bare_name_ambiguity_wall 10/10.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 3, 2026
Merged via the queue into main with commit 5c49920 Oct 3, 2026
7 of 8 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/royal-newt-820 branch October 3, 2026 06:07
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
- structural_realization_bindings: take main's Peano fixture row and kernel_grounding_rows;
  the cut's deletion of the Boolean literal row and the connective-row family stands.
- emit_rust: a type declaration realizes as a native alias (Bool, this cut) or a kernel-
  grounded decl (Nat, #12846) before falling back to the connective emission; the
  use-line filters keep both exclusions.
- defork census: the open Nat/Bool row goes; both are in defork_census_resolved.
- peano test: main's StructuralNat fixture, without the connective_rows argument or the
  BooleanUnfold arm.
- realize_advisory_soundness: deleted on main (#13016), stays deleted.
- Import lines: main's side, with Bool/True/False removed from v2.std.logic imports.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…cker imports; mirrors and rung-drop docs from main, regen follows

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…ernel String; Unit imports kept; fleet witness names VerdictAbsent

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
… v2.std.text String

The two string_eq(symbol_lexeme(..), <v2.std.text String>) sites refused under the #12512
text wall (pre-existing on main; the Bool-import edit put this file under the floor's
changed-file judgment). node_contains_atom_text had no callers and is deleted.
decl_contains_atom takes the atom as a Symbol and compares identities with symbol_eq; its one
caller interns the row the way the file's fixture already does.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…ation-local simplifications (row five is the identified foreign-formal unfold shape), a new identified site unfolds or refuses, and the emitted-crate build discriminates classes A and C only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot pushed a commit that referenced this pull request Oct 3, 2026
…the #12512 text-crossing precedent)

The List cut gives the any() predicate's binder a resolved element type, so the
checker now identifies both sides of string_eq(a: symbol_lexeme(..), ..) and
refuses the host/code-point crossing #12512 walls. Compare as #12512 did in
v2.lens.module_graph: ==.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Oct 5, 2026
…#12951)

* Regenerate docs/design-rung-drops.md after merging main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: the base arm runs only the reached claims whose head can block

reach_head_cannot_block is derived from claim_differential_blocks over every base arm.
A passing head never blocks, and a head where the claim is no longer declared is a
removal under every base, so neither is run at base. The base arm then runs only the
claims that FAIL at head: 60 of 1481 for a one-line v2.std.node edit and 18 of 240
for #12582's change (srv1, 2026-10-01), about 25x less base work. An all-passing reach
spawns no base process.

Controls: a_head_passed_claim_is_never_run_at_base_and_never_blocks (Rust, real
model: the partition sends only the failing head to base, and a passing head blocks
under no base) and only_a_failing_head_needs_the_base_arm (.dag).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitted-package join also matches canonicalized paths, so a symlinked crate dir cannot undercount (review 73526)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: the base-arm budget is born typed Milliseconds (review 73528)

ReachDifferentialStanding's DifferentialBlocking carries base_arm_wall_budget:
Milliseconds (std.types) instead of base_arm_wall_budget_ms: Int, and the host wire
reach_differential_blocking_budget returns Milliseconds, so the unit is the type's
and not the name's. The branded value reaches the host as Value::Int, which the
existing non-negative match unwraps; any other shape still refuses. The sibling
required_floor_claim_wall_safety_limit_ms stays as existing debt, not widened here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: per-identity base verdicts; an unmeasured base blocks only when no roster declares the claim red

A non-verdict base outcome (budget, panic, host tool or effect, not attempted) is now
not_measured for that identity alone; the other reached claims keep their verdicts
(srv1 replay 4d79fc6: one BudgetInterrupted claim voided all 60). Only instrument
failures refuse the whole arm.

reach_claim_verdict takes the claim identity. An unmeasured base on the declared
main-red roster (floor_expected_red_roster, joined by identity) is a counted
base_not_measured_rostered finding that does not block. On no roster it BLOCKS as
base_not_measured_unrostered (deep-ferret-305 ruling, 2026-10-01). A base verdict
decides as before.

Control: an_unmeasured_base_blocks_only_when_no_roster_declares_the_claim_red (.dag:
rostered reports, unrostered blocks, a base verdict still decides).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: planned on the merge group only (operator ruling 2026-10-01), modeled, announced when deferred, naming what newly failed

- v2.workflow.floor_subject_seed reach_planned_for_event decides, over the event the
  runner reads through the authority that chose its diff window, whether reach
  consumers are planned: ReachOnMergeGroupOnly, compared against
  extdeps.github.actions github_event_name_merge_group. This is the phase scoping
  DESIGN puts in the binary, not the workflow YAML. An unreadable event refuses on CI
  (ReachEventUnreadable) rather than silently deferring.
- On any other event no reach consumer is planned or executed (PRs +0), and the floor
  prints phase=reach-differential state=deferred_to_merge_group with the count it
  would have reached.
- A blocking regression or failing new claim prints
  [floor-reach-finding] NewlyFailedAtHead identity=..., so a dequeued author sees
  what broke without rerunning.

Controls: only_a_merge_group_plans_the_reach_differential (.dag, both directions) and
a_pull_request_defers_the_reach_differential_and_a_merge_group_plans_it (Rust, real
rule plus the deferral line).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR: enumerate the three qemu-host-observe readiness arms main added since (census PR1/3)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: blocking verdicts are a typed outcome field the adjudication names, not free text in failures

neat-boar-16's srv1 control (2026-10-01) showed blocking=8 but no per-identity
adjudication line for them. RequiredFloorOutcome gains reach_differential_blocking:
Vec<(identity, differential)>. required_floor_outcome_is_clean requires it empty, and
required_floor_measurement_blockers adds one blocker per identity with cause
reach_differential_<differential> (regressed, new_claim, base_not_measured_unrostered,
refused). A refused base arm records every claim it left unjudged as base_arm_refused.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: both main-red rosters; a non-verdict at head is not_measured, never failed; one shared test pool

- claim_on_declared_main_red_roster joins floor_expected_red by identity AND
  gunbc.explicit_witness_admission's known-red rows by (entry, function), through that
  roster's own explicit_witness_admission_is_known_red. On the srv1 control rerun three
  known_red_probe map_literal claims had blocked as unrostered; they now report.
- The head standing uses the base arm's classifier (base_standing_of): a wall
  interruption at head under load is not_measured, verdict head_not_measured, never
  sent to base and never read as a regression. It was matches!(Pass), which made a
  passing base plus a loaded head a false regression. The floor's own
  interrupted_before_verdict rule still refuses such a run.
- The base-only residual is named beside the rule: an unrostered claim whose base lands
  within load noise of the 8 s hang guard dequeues load-dependently (loud, named). Its
  trigger: the hang guard gets its own typed refusal and a much larger declared value
  through one plumbing for both arms.
- reach_base_standings tests share one pool (test_roots): the process-global shared
  index holds a single resident pool, and the fixture test's extra root made test order
  decide a SharedIndexSecondResidentPool panic.

Controls: an_unmeasured_head_is_not_a_regression (.dag); the roster control extended
with the explicit-admission arm; the partition test with a not_measured head. Rust 5/5,
.dag controls true, clippy clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: locate floor runtime-error rows; typed host IO refusal

* Floor runtime-error rows carry message + raising declaration; host write failures are a typed IO refusal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM: portable value map order is process-random (RandomState HAMT iteration; Symbol hashed by address)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Portable map entries in canonical content order; value_hash hashes variant names by spelling; RFM row scoped by the iteration and value_hash censuses, with the DefaultHasher residual

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* emit-host transport read failures are HostIoFailed too (Cargo config read, tool canonicalize/read, cold receipt read, cache evict); probe spawn via host_tool_spawn_failure

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73653: seed-growth justification for the canonical-order Rust; the row states its controls are off the merge path

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Canonical order: floats by IEEE 754-2019 totalOrder (f64::total_cmp), not raw bits, which invert negatives; control floats_order_by_ieee_total_order

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Six ungated main reds re-derived; three entries admitted by importing LiveTreeDisposition

(1)(2) live_deploy.emit sudoers claims: the needle is now the install's own node
(gunbc.ci_deploy_sudoers deploy_sudoers_elevated over the fleet visudo row) rendered by the same
serializer. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). The
two probe negatives are deleted: unmatchable under quoting, and since #12168 those probes are
emitted on purpose after the install.
(3) twin claim: count equality replaced by an identity join on artifact kind, host singletons
(fabric storage + #12747's approval broker front door) subtracted by the functions that decide them.
(4) CPUQuota grant: sudoers side read through sudoers_argument_word (escape since #12563).
(5) tasks verdict: bare `Absent ==` never named the ConvergeVerdict arm; typed match + a Drifted
discriminating conjunct.
(6) runner_lifecycle: fabric rows from srv3/srv4_fabric_first_slot, each controlled by the
slot below it on its own host (srv4-06 is fabric since 2026-09-18).
Admission: build_cache_endpoint_observe, ci_budget_tree_witness, host_allocation_conservation
import v2.std.live_tree (the #12540 class #12819 fixed once); variant rows retired ImportsFixed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci_budget_tree_witness: three live-tree reds were stale premises; re-derived from the producers

witness_live_is_fail_closed asserted the Unestablished arm while srv1 now resolves ReservationBytes;
it asserts each arm's relation over session_reservation_bytes(srv1). witness_srv2_symmetric_to_srv1
assumed equal RAM (srv1 is 512 GiB since 2026-08-22; usable RAM per host since #11625); it asserts
the pools differ by exactly the RAM gap. witness_srv3_outbudgets_srv1_by_exactly_the_overhead_gap
missed the 1,392,640-byte usable-RAM difference; gap = overhead gap + RAM gap, both read from the
producers. Removed from floor_expected_red_chunk_live_tree_admission (they now pass).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: unimported-bare-provider standing judged over the whole pool, not the diff; census fixed

The diff-scoped standing check let #12540's new pairs in untouched files through while
claim_batch's entry route refused them. The floor now judges every pool file (13.6 s over
7,175 files on the warm index, measured). Census at this base: 172 Unrostered + 16 RosterStale.
Fixes: 167 pairs import their declared provider (138 files; no new import cycle), 5 bare
`ends_with` calls that bound to gunbc.rust_item_scan's private helper use the builtin
.ends_with(suffix:) method instead; 16 + 344 rows whose pairs the imports dissolved retire as
ImportsFixed. Re-census: zero refusals.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.algebra: TotalOrder<T> is the one compare law; OrderedRing and Field compose it (WIP)

* Interpreter: one canonical content order (ContentView over Value and PortableValue); map Display/Debug canonical; sort_by admits only emitted-agreeing keys; cmp_values deleted (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Canonical render order: emitter refuses map rendering typed; to_string classified CanonicalOrder; two-process, kind-rank, totalOrder and carrier-differential controls (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rows: RFM rendering receipt and per-path rung; spelling stand-in on variant_owner_identity_stall; seed-growth row extended (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witness: emitted map rendering refused typed; to_string classified CanonicalOrder by the gate route (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Gate comment names the phase line instead of transcribing its measurement; phase line carries standing_ms (review 73712)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: production list order from map_keys -> sorted_map_keys (target_model supplemental-bound and representation-choice nodes, rust_crate_partition first-unknown module, legacy_binding_observation expected ids)

The #12890 warm-row specimen: rust_classical_not_ingested_target_model_staging varied per process because
target_derive_supplemental_generic_bound_requirement_nodes_for_contract built its child list by folding
map_keys (HostUnspecifiedOrder). Keys are Symbol/ModuleId/Int, all admitted by sorted_map_keys, whose order
is identical in both realizations.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop determinism_transitive_reachability: population names the unjudged production corpus; receipt for the six map_keys folds found by the #12890 specimen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitter: a single-field anonymous record literal matching 2+ structs refuses instead of emitting the bare value; VersionScheme literals name their type; revert stage0 files swept in by an interrupted regen

std.algebra TotalOrder gained the same single 'compare' field as extdeps.version VersionScheme, so
find_unique_struct_name_by_fields stopped being unique and '{ compare: f }' emitted 'f' -- a fail-open
arm (DESIGN section 5). It now refuses exactly as the multi-field arm does; the three VersionScheme
literals carry the nominal type that remedy names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Split the two cost-debt-rostered sudoers claims out of this PR

The floor's changed cost-debt edit judgment lexes the whole 125 KB emit_test.dag at base and at
head per identity in the interpreter; with these two identities changed, site projection ran past
the 90-minute cap (run 36856989404). Their fix moves to its own PR, held on that floor defect.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* live_deploy.emit sudoers claims: needle is the install's own node; unmatchable probe negatives deleted

Split from #12905. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitter annotation moved to module-item grain

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire the one row main's merge made stale (ownership_movable_test#Read); re-census over 7,193 files: 0 refusals after this

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 (std_algebra, std_primitive_projection, v1_compiler_emit_rust); control: supplemental-bound requirement nodes emit in canonical parameter order (the #12890 specimen at its cause)

regen-round-cost converged in one stage, changed_paths=3.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor cost-debt edit judgment: one lex per changed file, shared by every identity in it

v2.workflow.floor_cost_debt_edit judged each changed cost-debt witness in its own call, and each
call lexed the whole base and head file, so a file with k changed witnesses paid 2k lexes. With two
changed witnesses in the 125 KB emit_test.dag, site projection ran past the floor's 90-minute cap
(run 36856989404). The wet entry is now cost_debt_changed_witness_ceilings_at_base, called once
per file with every changed cost-debt function in it. It lexes base and head once, reads the base
resolution once, and selects each declaration from those streams. The host prints
`[floor-cost-debt-edit] judgments= changed_identities=` as the control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Pin PlannedAsReachConsumer as not a changed-witness selection in the sublane join

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* clippy: redundant closure in the per-file ceiling call

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2.std.integer: int_ordered_ring composes order: TotalOrder (OrderedRing no longer restates compare/lt/le/gt/ge)

Control supplemental_bound_requirement_order: requirement_nodes_are_emitted_in_canonical_parameter_order
returns true, and false with map_keys restored at the outer fold (discriminating).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md (docs_projection_gate regen)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a raw string literal opened in a body is tracked; an unattributed refusal names its cause

The census could not judge gunbc#12886 because the scanner tracked raw string
literals only when opened on an item header. A `let src = r#"...` fixture in a
body let its own column-zero `}` close the fn early, and its `"#;` then refused
the file (interp_recorded_fixture_witness.rs:458). The same shape put 5 of the
9 hand files on main out of reach. An item ends at its own closing brace, and a
brace inside a literal is not one: every item line is now read for an unclosed
raw literal (token-start `r`/`br`, terminator from its own hash count). Only a
header-opened literal's end may end the item.

v1_interpreter.rs was never unscanned: the scanner reads it whole (1040 items,
36 macro regions) and attributes #12814 completely. #12886's v1_interpreter
refusal is a line inside `thread_local!`, the declared macro-item ceiling, but
it was reported with the out-of-range sentence. The refusal now names which
cause fired.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md after merging main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM: anonymous_record_resolved_by_field_names_guesses_on_ambiguity (the emitter one-field fail-open TotalOrder exposed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Reach differential: DifferentialBlocking per the operator's 2026-10-01 option-B ruling

Base-arm budget 625200 ms: the largest srv1 base arm measured (312.6 s for 22
identities, loaded host) times 2 for load variance; an arm over it still refuses
with BaseArmOverBudget. PRs still defer to the merge group.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: an expression-bodied item ends at its own semicolon; a backslash-continued line is string text

A `static NAME: T =` header that rustfmt continues before its initializer puts
the declaration's `;` one indent deeper, so the item stayed open and swallowed
the following items until a column-0 `}`. That was a SILENT mis-attribution:
cli_run.rs `static PROVIDER_BOOTSTRAP_STORE_SKIPS` absorbed
`fn record_provider_bootstrap_store_skip`. Across 22 hand files, about 125
items were never recorded, 7 of them in v1_interpreter.rs
(record_builtin_time_inclusive, canonical_symbol_spelling, ...). An item whose
header ends at `=` now ends at the continuation-indent line that ends the
statement.

A line after a trailing backslash is string-literal text at whatever indent
its author chose, never structure. The line that ends such a literal with `;`
ends an expression-bodied item; ExprBody is read from rust_item_forms, not
listed here. No item key is lost in any hand file, and the refusal count is
unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_host_observation: carry the refusal from the one attribution; RawLiteral replaces terminator+flag

Review 73783 found that change_lines_unattributed reduced each attribution to a
line number, and unattributed_line_detail recomputed it. That was the same fact
derived twice (DESIGN §2), and the recompute needed two arms that wrote a
fabricated sentence (DESIGN §5). change_lines_unattributed now matches once
into RustLineRefusal, which has only the two refusing arms
(LineInsideUnnamedMacroBlock, LineBeyondTheFile). The detail is read off that
value, so the record and its sentence cannot disagree.

Also from the review: ItemScope's raw_terminator + raw_opened_on_header could
represent "opened on the header with no terminator". They are now one variant,
RawLiteral = NoRawLiteral | OpenRawLiteral { terminator, opened_on_header }.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.algebra: the TotalOrder comment names the real (seed-retained) realization instead of a symbol that does not exist (review 73794)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emitted ordering keys fail closed: v1_rt CanonicalOrdKey (String, i64, bool only) bounds sorted_map_keys and sort_by; sort_by drops partial_cmp(..).unwrap_or(Equal); enrolled one-order claims; seed-growth trigger names the capability and first consumer

neat-boar-16 conditions for executed agreement on #12925: (1) enrolled claims
test.claim.canonical_order_enrolled_witness; (2)+(4) trigger at capability grain naming the first
real consumer; (3) the emitted frontier refuses non-admitted keys typed (on_unimplemented message).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a static inside thread_local! is a named item, by upstream citation

extdeps.rust.std_thread_local records std's thread_local! as the pinned 1.93.0
docs state it: the macro "wraps any number of static declarations", and
"Publicity and attributes for each static are allowed". The scanner reads a
thread_local! block as a scope that admits exactly those lines. Each static is
an item of the enclosing module, so a change inside one is attributed to it by
name. Anything else in the body refuses, and so does a one-line
thread_local!(...), which this reader cannot split. Every other macro stays at
the declared macro-item ceiling (macro_rules! controls).

On #12886's tree the census now observes the change completely:
JSON_ENCODE_NESTING is an added static, and the only unreadable hand file left
is phase_profile.rs (extern "C").

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rust_item_scan: a header at the open item's own indent refuses; a trailing comment does not hold a declaration open

The swallow class becomes structural. Whatever leaves an item open past its
end -- a continued initializer, a trailing comment, an ordinary multi-line
string, or a construct not yet met -- next meets a sibling item header at the
open item's own indent, and no item body puts one there. scan_step now refuses
at that header instead of reading it as body. Under the prior reader that
refusal fires at the original swallow sites in cli_run.rs and v1_interpreter.rs.

A second instance surfaced by the same measurement is fixed. A one-line
declaration followed by `// comment` did not end in `;`, so it stayed open and
swallowed the next const (resolved_graph_cache.rs PART_DESCRIPTOR_LEN over
V3_HEADER_LEN). A `//` with an even quote count before it now starts a comment.

Files the recurring failure mode as its general class,
gunbc.recurring_failure_mode census_instrument_silently_drops_items: a census
instrument whose parser silently drops items reports a smaller population, and
a short count reads as success. Its distinguishing fact is that a swallowed
item's lines ARE attributed (to the swallower), so a line-coverage join passes.
The violated join is header coverage.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 (whole-compiler rebuild: runtime CanonicalOrdKey reaches v1_compiler_stage0_crates)

--regen-round-cost refused with WholeCompilerRebuildRequired (partition generation authority
changed), so candidates were emitted with --required-regen, installed, the whole compiler rebuilt,
and --required-regen re-run: first_generation_equal=true over 161 planned.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enrolled one-order claims import empty_map/map_insert from v2.std.collection (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Name the instrument instead of transcribing the probed RAM gap (review 73848)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge group: the floor window's base is the group's own parent (merge_group.base_sha), never origin/main

#12514's first live merge_group run (group head 529d438) compared against main
8a249e7 and charged the four PRs queued ahead (#12921 #12735 #12770 #12905) to
this landing: three order-edge claims from #12770 read as regressed.

- extdeps.github.merge_group_event: cited payload reader for merge_group.base_sha
  and the merge queue's group-composition guarantee (cited), consumed by the resolver.
- gunbc.diff_baseline: MergeGroupBase arm; merge_group resolves through
  resolve_merge_group_base, which REFUSES on an absent/empty/unreadable/malformed
  base_sha and never falls back to origin/main. Two-dot comparison.
- Witnesses: payload parsing (nested member, absent, empty, not an oid, not json)
  and resolution (own parent, no parent refuses, cause carried).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: derive gunbc.rung_drop.roster from its directory by declared type (shared fold with RFM)

Unverified by CI; main_wet regen of stage0 mirrors not completed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* #12514: cover PlannedAsReachConsumer in main's newer disposition matches; hoist in-body annotations

Merging main brought six matches over RequiredFloorDisposition written after the
reach-consumer arm existed on this branch (E0004 in emit-build). Each new arm follows
the .dag authority: v2.workflow.floor_changed_witness and v2.workflow.required_floor
treat PlannedAsReachConsumer exactly as Planned (planned standing, gate runs, not a
cost-debt withhold, CostDebtDeclaredButNotWithheld, never suppresses a changed-witness
enrollment).

merge_group_event.dag carried '//' annotations inside a type body, which DESIGN §4c
refuses; they move to the leading block above the declaration.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: cover variants that landed on main after the NFR enumerations were written

Composing the burn-downs with main exposed two non-exhaustive matches, the
exact class enumeration exists to surface:
- floor_unimported_bare_provider_debt_roster: three standing matches lacked
  Retired { cause: RelocatedOutOfSourceRoots } (floor refusal, CI run 36931173776).
- target_model realized-closure body classification lacked ParameterReferenceBody,
  added by #12766 (emit-build refusal); it projects like DeclarationReferenceBody.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate stage0 mirrors to a fixed point; cover more variants that landed after enumeration

- stage0 mirrors regenerated locally (claim_executor --required-regen, whole-compiler
  rebuild between rounds) until first_generation_equal=true (161/161 adjudicated).
- DESIGN.md and docs/design-rung-drops.md from tools.docs_projection_gate regen and
  generated_artifact_gate main_wet_verified.
- More matches the NFR burn-downs enumerated before main added variants; each new arm
  keeps what main's removed wildcard returned:
  live_deploy emit identity_member_of_step and member_observe root_members_of_step
  gain ApprovalBrokerFrontDoor (none / []); mtcollins1_kvm_still kvm_pending_step,
  kvm_established_step and kvm_gap_mark gain KvmJournalNavigated/PageConsole/PageError
  (acc / []).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: retire 31 bare-provider rows the composed tree no longer carries

The pool-wide standing check (#12908) judged the composed head and found 31 ActiveDebt
pairs whose files no longer carry them (imports added by the other merged burn-downs).
Each is retired as ImportsFixed, exactly as the refusal names (CI run 36939427278).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate after merging main; name runner_microvm_boot_probe's Filesystem authority

- stage0 mirrors regenerated to a fixed point after the main merge (first_generation_equal=true),
  docs/design-rung-drops.md regenerated; main_wet_verified green.
- runner_microvm_boot_probe read Filesystem bare while three modules declare it
  (AmbiguousBareNameRead, floor run 36941252236); it uses Filesystem.Write, so it imports the
  service from extdeps.filesystem.filesystem_io, as its sibling runner modules do.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate the rung-drops projection after the main merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: back out #12610 (typed NFR check D)

Its typed check judges every module the diff touches, and this branch's diff touches
hundreds, so the floor refused with 65 unrostered closed-coproduct wildcard sites
(NonFoldResidueRosterDiverged, run 36948688303). That is exactly the joint landing
#12610 was waiting on (census roster, old-scan deletion, srv1 typed census at 0/0),
which is not built. #12610 is reopened to carry it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: iterative Drop for PortableValue

value_depth_walker_tests::a_deep_value_round_trips_through_the_portable_form aborted the
test process (stack overflow, SIGABRT, rust-unit-tests run 36951304061) when the deep
portable chain was dropped: PortableValue is a plain owned tree, as deep as its value, and had
the recursive default drop. It now drops through a heap worklist exactly as impl Drop for
Value does (class recursion_over_value_depth_uncounted_by_the_call_limit). The test passes
locally, and the other deep-value tests still pass.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: green the --lib population #12753 makes blocking

#12753 turns rust-unit-tests into a blocking lane, so this branch must carry a green --lib
population. Main's own reds, which nothing ran:
- closure_edge_demand_tests::required_phase_..._catches_a_bypass judged a second root set on
  the same thread, which #12831's SharedIndexSecondResidentPool now refuses; the twin pool's
  judgment runs on its own thread, as a separate floor run would.
- compile_clean_via_index_verdict_equivalence::regen_subject_admits_a_provider_reached_only_by_
  reference wrote a bare cross-tree reference, which #12741 refuses (CrossTreeBareReference);
  the fixture now writes it qualified, still reference-only with no import.
- nfr_roster_receipt: 13 parameter-scrutinee wildcard sites landed on main after the
  2026-10-01 census; rostered with a stated reason and the owning-fold dissolution.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: live-pool tests start from no held pool

live_pool_thread_tests::two_claims_on_the_live_pool_thread_share_one_index failed whenever
an earlier test had left the live-pool thread holding its own fixture pool: #12831 refuses a
second resident pool on one thread (SharedIndexSecondResidentPool). Each live-pool test now
releases the live pool first (yield_live_pool_before_building_another), so its result no longer
depends on test order. The serial suite's live-pool and content-key tests pass (7/7).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: regenerate stage0 after the main merge; roster 2 more post-census NFR sites

- v1_compiler_emit{,_rust}.rs regenerated from main's base to a fixed point
  (first_generation_equal=true); docs projection unchanged.
- dag/gunbc/action_use_admission.dag checkout_context_names_a_commit and
  checkout_ref_value_refusals landed on main after the census; rostered like the earlier 13.
- Full serial --lib suite (RUST_TEST_THREADS=1, as CI runs it): 1116 passed, with the only
  failure being these two sites, now green.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: keep a deleted file's roster row FileDeleted; stop a test helper from providing 'github' pool-wide

- import_closure_live_test.dag#ReadsLiveTree: the file is deleted on main, so its row stays
  Retired FileDeleted (my conflict resolution had taken ImportsFixed).
- #12835's fleet_converge_checkout_pin_witness_test.dag declares a top-level helper
  'fn github(path:)'. With #12908's pool-wide standing check, that made it a candidate bare
  provider for every module that reads 'github' bare (115 Unrostered refusals, run
  36964372555). The helper is test-local, so it is renamed github_context_access; it no
  longer collides with the 'github' those modules mean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "integration: merge #12912 (session/deep-deer-663-sudoers)"

This reverts commit 9502c4c, reversing
changes made to c276c43.

* Regenerate stage0 mirrors and rung-drop docs after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* github_app_registry witness: import its live-tree disposition instead of reading it bare

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs and stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: rows for parse_sequence_capture and grammar_emit_sequence (landed on main after the census)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors and docs after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Cover main's new LexicalReferenceKind / LexicalReferenceBody in two enumerated matches; docs regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider debt roster: the three body_lowering tests' rows are ImportsFixed on this branch (floor: RosterStale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: delete the 757 rows whose wildcards this branch's burn-down PRs enumerated (floor: stale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* semantic_decl_emission: the four edge-label matches name Authored and StructuralLabel (Named is gone after #12799)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* target_model: name StructuralLabel in the wire-child declared-type match; docs regen

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* match_pattern_binds_erased: carry the pattern's parent_identity (main's VariantPattern field)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* program_partition, realization_attempt: name StructuralLabel in three edge-label matches (#12799)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate DESIGN.md from the merged design_document (generated_artifact_gate main_wet)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: restore main's rows for the five wildcard bodies taken from main in the #12799 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap_belt_actuate: delete belt_spawn_tally_not_admitted, left without a caller once main's arms were taken

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Delete two branch helpers left without a caller once main's arms were taken in the #12787 merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors after the #12787 merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider debt roster: retire three pairs the merged files no longer carry (floor: RosterStale -> ImportsFixed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* unit_standing, runner_microvm_slot_unit: name RuntimeMaxSec in four directive matches taken from main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bare-provider roster unit test: ImportsFixed -> FileDeleted now admits (#12787's rule); the reverse still refuses

#12787 made FileDeleted terminal in v2.workflow.floor_unimported_bare_provider_debt without updating this Rust test, which main does not run as a blocking lane.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the #12512 merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate after the main merge (fixed point)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate rung-drop docs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* runner_unit_live_read: the enumerated converge-verdict arms name VerdictAbsent (#12721)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* NFR roster: drop two rows main added for d0 sites this branch enumerates (floor: stale)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: floor fixes after the main merge; #12753 retirement text claims only what was observed

- debt roster: fabric_witness_run_test HardRequirements/Shape/current_runner_slot_profile keep
  main's Retired ResolvesInClosure (the floor refuses a changed retirement, RosterRetirementChanged).
- unit_standing_witness_test: import extdeps.systemd { systemd_duration_usec } (Unrostered on the
  floor; the file declares imports so its bare channel is off).
- rust_unit_tests_off_the_merge_path: the merge_group pass had not happened; the text now says the
  merge_group revision is proven by the queue's own required run at landing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Heal-Candidate-Run: 37180751525

* Regenerate docs projections (docs_projection_gate regen)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 1)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* integration: follow main's #13186 (HeadGrain deleted) in the ownership join; LoadCredential arm in the microvm slot unit

- gunbc.refusal_reason_ownership_join: main keyed cause ownership by cause alone and deleted the grain
  field, so a row owns its cause; reason_is_fatal_owned is the cause match. The witness drops the
  HeadGrain control (head_row / head_grain_row_does_not_own_a_fatal_reason): the state it planted is
  no longer constructible.
- runner_microvm_slot_unit: main added SystemdServiceDirective LoadCredential; the enumerated
  directive match was non-exhaustive (floor declarations finding).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: delete the 2 NFR rows whose sites no longer carry a wildcard (floor NonFoldResidueRosterDiverged stale=2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability
Heal-Candidate-Run: 37235281080

* Regenerate docs projections and witnesses.yml after stage0 regen

* integration: the four rust-unit-tests reds the restored lane surfaced (all stale against main, which runs no unit lane)

- nfr_observation_roster_test: gunbc#13277 enumerated ci_hold_cause_text and drained its NFR row;
  the test now asserts the row stays drained (renamed observation_hold_cause_row_stays_drained).
- process_cwd_mutation_reachability_gate: a_stale_binary_is_refused_before_any_instrument_runs
  reached test_verb's producers, several of which set the process cwd. The freshness refusal is
  split out as stale_binary_refusal and the witness calls it, so the route is asserted without
  reaching any producer; test_verb_after keeps the same behaviour.
- changed_selections_outside_discovery_mirror_tests: since gunbc#13138 the .dag decider returns
  its list as a free-monoid Cons/Empty chain (list_reverse); the test reads either realization.
- renderer_hop_decides_realization_from_declaration_identity_without_an_env: the structural-Bool
  half retires as dissolution of the Bool de-fork (gunbc#12583), mirroring the .dag witness's
  retired row; the prelude control stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: list_items matches the Value by reference (E0509: Value implements Drop)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: pin run_native_serve_program in the cwd gate's undecided set; carry the renderer-hop retirement into its .dag source

- process_cwd_mutation_reachability_gate: main's #13135 declared run_native_serve_program in two
  files, the exact shape of the pinned run_native_claim_program (producer called only from its own
  TargetProducer match; the native_lane_runner twin reached by the qualified cli_run:: spelling).
- compiler_tests.rs is generated from v1.compiler.compiler_tests_rust; the structural-Bool
  retirement is now authored there, rendering the same lines the mirror carries.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* integration: the compiler_tests_rust mirror carries the renderer-hop retirement its .dag source now authors

v1_compiler_compiler_tests_rust.rs is the emitted form of v1.compiler.compiler_tests_rust; its
ct_renderer_hop_identity_keying_test is re-rendered in the emitter's own concat shape (the old body
round-trips byte-identically through the same rendering), so the regen's first generation agrees.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* Reach differential: an unmeasured head and a claim declared at neither side refuse, never pass (review 76405)

reach_claim_verdict returned a non-blocking 'head_not_measured' for a head
with no verdict; it now refuses typed and located (DESIGN 5). claim_differential
mapped NotDeclared at both sides to DifferentialRemoved (never blocks); it is
now DifferentialUndeclaredAtBothSides, which blocks, so a removal runs the
base arm to prove it was one. Tests: an_unmeasured_head_is_refused_not_reported,
a_claim_declared_at_neither_side_blocks_and_a_removal_reports, and
only_a_passing_head_skips_the_base_arm.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Reach differential: not_measured is a declared parsed arm; one constructor builds the verdict (review 76416)

ParsedClaimStanding gains StandingNotMeasured, parsed once in
claim_standing_named; reach_claim_verdict and reach_head_cannot_block match the
arm instead of each comparing the string. reach_verdict_of builds ReachVerdict's
name and blocks from ONE ClaimDifferential value, so they cannot disagree; the
two flat fields stay because they are the wire the seed floor runner reads.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate docs projections and witnesses.yml after stage0 regen

* floor_demand: typed arm for the cross-claim-share-derivation seam (main's #13043)

#13043 added floor_seam("cross-claim-share-derivation") to the floor runner
without a FloorSeam arm or a FloorSeamToken row; main never runs the unit
lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the
restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation,
its token row, and its arm in receipt_peak_seam.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung drop rust_unit_tests_off_the_merge_path: retired on its own trigger, runner supply, with the receipt (review 76493)

The trigger_fired text cited the population being green and the job being
re-added, which the row itself says does not retire it. It now cites the
supply receipt from this PR's required runs: the unit job starts with the
other lanes (no queueing) and finishes before floor, so the required wall
did not rise. It also cites the operator's sign-off for the roster addition.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rung drop rust_unit_tests_off_the_merge_path: restore the declaration the last edit dropped (review 76497)

163ef99 replaced the trigger_fired text but cut through to the end of
the declaration's AuthoredProse, deleting the drop's record of what it
declared (and leaving the record without a required field). Restored from
its parent; only the trigger_fired string differs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs projections (rung-drop retirement text)

* Regenerate DESIGN.md (generated_artifact_gate main_wet_one): the unit-test lane is no longer described as off every CI path

* rung drop retirement: name the instrument for the supply receipt, not the transcribed wall times (review 76511)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs projections and DESIGN.md (retirement receipt names its instrument)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 2)

* Regenerate stage0 mirrors (claim_executor --required-regen, round 3)

* Regenerate stage0 mirrors after the eighth main merge (round 1)

* Regenerate docs projections after the tenth main merge

* required_floor_runner test: cost_debt_clean_outcome carries reach_differential_blocking

Main's test constructor (added with the moved required_floor_outcome_is_clean)
predates this branch's field; the unit lane failed to compile (E0063).
cargo check --lib --tests is clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate DESIGN.md and docs projections after the eleventh main merge

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansrls@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant