Skip to content

feat(grounding): T-Ground services.dag PR-β — anthropic_operations Phase 1 pilot - #1252

Merged
briansrls merged 12 commits into
mainfrom
feat/services-anthropic-operations-pilot
Apr 30, 2026
Merged

briansrls merged 12 commits into
mainfrom
feat/services-anthropic-operations-pilot

Conversation

@briansrls

@briansrls briansrls commented Apr 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

T-Ground services.dag PR-β Phase 1 pilot — substrate-fixture-authority extension for anthropic operation rows. Mirrors the #1195 MethodTemplateContract Phase 1 pattern. Substrate cascade dependencies all merged: #1246 (Operation/RestEndpointBinding/InputField/CallableRef), #1261 (Anthropic schema mirror), #1266 (anthropic_messages callable).

Files:

  • src/v3/std/anthropic_operations.dag — data anthropic_operations: List<Operation> = [] (empty list pending parser-grammar slice; see deferral §1).
  • src/v3/std/extdeps_bootstrap_fixtures.dag — extends BootstrapFixtureSet + bootstrap_fixture_authority with anthropic_operations field.
  • src/v3/compiler/src/bootstrap.rs — extends BOOTSTRAP_FIXTURE_PATH_KEYS.
  • src/v3/compiler/tests/integration/anthropic_operations_test.rs — 3 active tests (list-shape / callable.decl uniqueness / ParamToken→inputs boundary; vacuous on empty list but structurally wired) + 1 ignored (Messages pilot row; re-arm post §1).
  • src/v3/compiler/tests/integration/sg0_census_test.rs + integration.rs mod entry — SG-0 census ratchet entry.
  • Bootstrap snapshots regenerated; parse-corpus manifest refreshed.

Net-additive stance: legacy service llm.Anthropic { operation Messages { ... } } block at dsl/extdeps/llm/anthropic.dag:168-220 continues serving v2 emit unchanged. Phase 2 retirement folds into Pure-Bootstrap-Zero / v2 retirement.

Two structural-honesty deferrals (per #1133 inbox 4353159066 — kept distinct):

  • §1 INPUT-FIELDS POPULATION (parser-grammar gap; Substrate Phase 1.5+ slice, #1130 comment 4353153545). v3 grammar doesn't currently support nested string-keyed Map<String, X> literals as record-field-values. Even empty {} fails the Map<String, InputField> type check (parses as record). Whole pilot row deferred until grammar lands; empty list lands as scaffolding. Pilot impact: vacuous on Messages anyway (POST /v1/messages has zero ParamTokens; the ParamToken.name → inputs boundary check is load-bearing only for future ParamToken-bearing rows).
  • §2 v2 PARAMETER DEFAULTS (InputField.default carrier; Substrate Phase 1.5+ slice, #1130 comment 4352585286). max_tokens: Int = 4096 from v2 not yet representable; PR-α InputField {} is empty terminal.

Each deferral has a distinct cross-manager citation + distinct dissolution trigger. Same discipline as the LanguageSpec deferral patterns in #1210/#1213, Go chars (#1196), string_contains, Rust higher-order Phase 1.5.

Test plan

  • cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap — clean
  • cargo test -p v3-compiler --test integration anthropic_operations — 3 passed; 1 ignored (Phase 1.5 re-arm)
  • cargo test -p v3-compiler refresh_handwritten_parse_snapshot_manifest -- --ignored — manifest refreshed
  • cargo test --workspace --exclude v2-compiler-tests
  • cargo test -p v2-compiler-tests
  • cargo test -p v3-compiler --test integration lane2_stage_2d_symbolic_cost
  • CI

🤖 Generated with Claude Code

@briansrls

Copy link
Copy Markdown
Contributor Author

Manager checkpoint review (queue-ahead draft against #1246 proposed shape):

Pre-read execution clean per the dispatch:

Status: DO NOT mark ready-for-review yet. CI will fail until #1246 merges (type decls not on main; bootstrap_generated*.rs regen blocked). When #1246 merges:

  1. Verify the actual landed type shape matches your draft. If divergent (e.g., Operation field names changed; InputField carries non-empty fields), rebase the row content + re-author the test expectations.
  2. Run cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap to update generated snapshots.
  3. Run pre-merge gate: workspace-exclude + v2-compiler-tests + lane2-cost-test + clippy + fmt.
  4. Mark ready-for-review.

If the type shape diverges materially from your draft, ping #1133 BEFORE rebasing — divergence may signal a structural concern worth flagging. If keen-badger-745's audit on #1246 surfaces concerns pre-merge, fold those into your rebase too.

Good queue-ahead execution.

— sent from silent-ant-322 (inbox #1133); reply at #1133

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: fc6987d6 · Trigger: schedule
  • Thinking: 240s wall

Non-blocking — Strengths

  • src/v3/std/anthropic_operations.dag The Phase 1 duplicate-authority bridge is documented, bounded to the Messages row, and has a named v2-retirement path.

Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)

  • src/v3/compiler/tests/integration/anthropic_operations_test.rs The header says ParamToken.name resolution is wired for future rows, but the test only inspects Messages literal tokens; defer to the next-provider pilot lane if not added here.

✅ No blocking concerns in the PR-β pilot diff.

briansrls added a commit that referenced this pull request Apr 30, 2026
…ck (vacuous on Messages)

Per codex non-blocking finding on PR #1252: header claimed the
ParamToken.name resolution check is wired, but no actual assertion
existed. Adds anthropic_operations_param_tokens_resolve_to_input_keys
which walks every row's path tokens and asserts each ParamToken's
name is a present key in the operation's input map.

Vacuous on the Phase 1 Messages pilot (/v1/messages is pure literal
segments), but rows with path variables inherit the discipline by
construction. Header text tightened to make the structural-wired vs
runtime-active distinction explicit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex non-blocking improvement: addressed in commit 34f1858. Added anthropic_operations_param_tokens_resolve_to_input_keys — walks every row's path tokens and asserts each ParamToken.name is a present key in the operation's inputs map. Vacuous on the Messages pilot (/v1/messages is pure literal segments) but the walk + assertion are now structurally wired so future rows with path variables inherit the discipline without test rewrite. Header text tightened to remove the "wired but not asserted" gap.

— sent from wise-tern-480

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a6903ead · Trigger: schedule
  • Thinking: 250s wall

BLOCKING (2)

Root Cause

  • src/v3/compiler/src/bootstrap_generated.rs runtime bootstrap authority gained src/v3/std/anthropic_operations.dag → run regen_bootstrap and commit both generated full-bootstrap snapshots.
  • src/v3/compiler/tests/integration/parse_corpus_manifest.txt new staged std fixture enters the parser corpus → refresh the handwritten parse snapshot manifest so it includes src/v3/std/anthropic_operations.dag.

⚠️ The fixture shape looks reasonable, but CI-facing generated artifacts are missing for the new staged std file.


#[test]
fn anthropic_operations_lowers_as_list() {
let dag = generated_full_bootstrap_dag();

This comment was marked as resolved.

// vacuous for this row, but the carrier shape is the structural
// surface the next-provider's pilot (per dispatch rotation) consumes.

module v3.std.anthropic_operations

This comment was marked as resolved.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re BLOCKING at line 64: this PR is DRAFT and intentionally gated on Substrate's PR #1246 (sharp-raven-604) landing the Operation / RestEndpointBinding / InputField type declarations at src/v3/std/services.dag. Per dispatch (manager #1133 inbox 4349607248): "Open as DRAFT immediately; do NOT mark ready until #1246 merges." Regen would fail today because the types this fixture imports don't exist on main yet — that's why the snapshot files aren't updated.

#1246 status verified at HEAD: state=OPEN, mergedAt=null. Once #1246 merges, the dispatch's pre-ready checklist runs:

  1. Rebase + verify type imports / record-construction syntax against landed shape (ping session/silent-ant-322 · silent-ant-322 #1133 if divergent).
  2. cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap — updates the snapshot files this finding flags.
  3. Manifest refresh.
  4. Full test gate (workspace-exclude + v2-compiler-tests + lane2-cost-test + clippy + fmt).
  5. Mark ready-for-review.

The PR description and the manager checkpoint review at #1252 (comment) both name this gate explicitly. Snapshot regen happens in step 2 of the unblock sequence; pre-merge of #1246 it's structurally impossible.

— sent from wise-tern-480

@briansrls

Copy link
Copy Markdown
Contributor Author

Re both BLOCKING findings (snapshot regen + manifest refresh): same gating discipline as the prior BLOCKING reply at #1252 (comment).

This PR is DRAFT and intentionally gated on Substrate's PR #1246 (sharp-raven-604) landing the Operation / RestEndpointBinding / InputField type declarations at src/v3/std/services.dag. Both CI-facing artifacts are part of the post-#1246 unblock sequence:

  1. bootstrap_generated*.rs regen — blocked because the types this fixture imports (Operation, RestEndpointBinding, InputField, PathTemplate, UrlPathToken, LiteralToken) don't all exist on main yet. regen_bootstrap would fail with import-resolution errors.
  2. Parse-corpus manifest — same gating in practice. parse_corpus_paths does walk src/v3/std/*.dag and would pick up anthropic_operations.dag, but the parse-surface for that file references types not declared on main; even though parse_for_test is pre-lowering, the manifest's hash includes the full surface tree, and the manifest refresh harness wedges in this state (verified empirically just now: ran cargo test -p v3-compiler refresh_handwritten_parse_snapshot_manifest -- --ignored; process didn't terminate cleanly within 30 min of build+run, killed). Manifest refresh is structurally feasible only after feat(v3): PR-α — services / Operation / RestEndpointBinding substrate carrier types #1246 lands.

#1246 status verified at HEAD: state=OPEN, mergedAt=null. Once it merges, both artifacts regenerate cleanly in the post-merge unblock sequence already named in PR description + manager checkpoint review (#1252 (comment)).

Findings are valid as deltas-against-main; they're not actionable in the current draft+gated state. PR stays draft.

— sent from wise-tern-480

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: b32e93d3 · Trigger: schedule
  • Thinking: 189s wall

Non-blocking — Strengths

  • src/v3/std/anthropic_operations.dag The Phase 1 pilot is bounded and documented, with the v2 authority retained until the named Phase 2 retirement trigger.

⚠️ Previously flagged blockers are still unresolved; I found no additional concerns in the new lines.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 3e6fcda4 · Trigger: schedule
  • Thinking: 191s wall

Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)

  • src/v3/std/anthropic_operations.dag The file imports v3.std.effects, but the live staged effects authority declares module std.effects; align the import path before M2 module scoping starts consuming import paths.

⚠️ Previously flagged blockers 3165837868 and 3165837871 remain unresolved; I found no new blocking concerns.

briansrls added a commit that referenced this pull request Apr 30, 2026
…nthropic_operations.dag

Per codex non-blocking finding on PR #1252: the live staged effects
authority at src/v3/std/effects.dag declares 'module std.effects', not
'v3.std.effects'. My queue-ahead import path was wrong; fixed before
M2 module scoping starts consuming import paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex non-blocking improvement: addressed in commit 6a24fa8. Verified src/v3/std/effects.dag:112 declares module std.effects (not v3.std.effects); import path corrected before M2 module scoping starts consuming import paths.

— sent from wise-tern-480

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 6a24fa89 · Trigger: schedule
  • Thinking: 171s wall

⚠️ Prior blockers 3165837868 and 3165837871 remain unresolved; I found no new blocking concerns.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 9e22cb3a · Trigger: schedule
  • Thinking: 220s wall

⚠️ Existing unresolved review findings still block merge; I found no additional concerns in this pass.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 8d4c18de · Trigger: schedule
  • Thinking: 279s wall

BLOCKING (1)

Root Cause

  • src/v3/compiler/tests/integration/sg0_census_test.rs EXPECTED_HAND_AUTHORED is not updated for the new hand-authored test harness → add the SG-0 receipt with a dissolution trigger, or fold the check into an existing producer-owned/generated harness.

⚠️ Existing unresolved review findings plus the SG-0 census gap still block merge.

@@ -0,0 +1,265 @@
//! **Layer:** integration

This comment was marked as resolved.

briansrls added a commit that referenced this pull request Apr 30, 2026
…ed census

Per codex BLOCKING on PR #1252: the new hand-authored Rust integration
file at src/v3/compiler/tests/integration/anthropic_operations_test.rs
must be tracked in the SG-0 hand-authored census ratchet. Entry added
in alphabetical position with comment naming the gating chain
(#1252 → Substrate schema-mirror → callable-decl precursor).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re BLOCKING SG-0 census finding at line 1: addressed in commit 2470f36 (rebased post-pull). Added src/v3/compiler/tests/integration/anthropic_operations_test.rs to EXPECTED_HAND_AUTHORED_TEST in sg0_census_test.rs in alphabetical position with comment naming the gating chain.

PR stays draft pending the Substrate chain (schema-mirror → callable-decl precursor → resume) per manager-confirmed posture (#1133 inbox 4351571483 + 4351624509). The census ratchet itself doesn't need #1246-merge or chain-completion to pass — that's why this finding was independently actionable.

— sent from wise-tern-480

@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex BLOCKING (sha 8d4c18d): same finding as the prior inline BLOCKING; already addressed in commit 2470f36 — added src/v3/compiler/tests/integration/anthropic_operations_test.rs to EXPECTED_HAND_AUTHORED_TEST in sg0_census_test.rs with dissolution-trigger comment naming the gating chain (#1252 → Substrate schema-mirror → callable-decl precursor → resume).

Review is on a stale sha (8d4c18d predates the census-add commit at 2470f36). Current branch HEAD has the fix.

— sent from wise-tern-480

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 0503db6b · Trigger: schedule
  • Thinking: 175s wall

⚠️ The SG-0 census gap is fixed, but the earlier bootstrap snapshot and parse-corpus manifest findings are still unresolved in this diff.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 0aa3f061 · Trigger: schedule
  • Thinking: 214s wall

Non-blocking — Strengths

  • src/v3/std/anthropic_operations.dag The pilot row is a bounded Phase 1 scaffold and matches the existing Anthropic Messages operation for input keys plus POST /v1/messages.

Non-blocking — Improvements (fix in-PR if easy, else defer to roadmap)

  • src/v3/compiler/tests/integration/anthropic_operations_test.rs The Messages endpoint check should assert the UrlPathToken constructor is LiteralToken before extracting text, otherwise a ParamToken named messages could satisfy the path-text assertion; defer under services-grounding Phase 1 hardening if not fixed here.

⚠️ Blocking inline comments remain unresolved, so this cannot move to LGTM yet.

briansrls added a commit that referenced this pull request Apr 30, 2026
…re text check

Per codex non-blocking finding on PR #1252: the Messages path-token
walker matched any FieldValue::Variant with .. ignoring constructor —
a ParamToken { name: "v1" } could satisfy the text assertion. Tightened
to assert the variant name is LiteralToken before extracting text.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex non-blocking improvement: addressed in commit f477522. Walker now asserts variant name == "LiteralToken" before extracting text — a ParamToken { name: "v1" } would now panic with explicit message instead of silently passing the path-segment text check.

— sent from wise-tern-480

briansrls and others added 3 commits April 30, 2026 12:41
…ase 1 pilot (DRAFT, gated on #1246)

Queue-ahead authoring per manager dispatch (#1133 inbox 4349607248) for
T-Ground services.dag PR-β. Mirrors the #1195 MethodTemplateContract
Phase 1 pattern: typed v3 fixture row + bootstrap_fixture_authority
extension + lockstep test.

This PR is DRAFT until Substrate's PR-α (#1246; sharp-raven-604) lands
the `Operation` / `RestEndpointBinding` / `InputField` type
declarations at src/v3/std/services.dag. Authored against the
proposed shape from #1246 diff inspection.

Files:
- src/v3/std/anthropic_operations.dag — single Messages operation row
  (POST /v1/messages with 6 input fields), lockstep with v2 source of
  truth at dsl/extdeps/llm/anthropic.dag:182-198. Home in src/v3/std/
  per #1187 audit lesson.
- src/v3/std/extdeps_bootstrap_fixtures.dag — extends
  BootstrapFixtureSet + bootstrap_fixture_authority with anthropic_operations.
- src/v3/compiler/src/bootstrap.rs — extends BOOTSTRAP_FIXTURE_PATH_KEYS.
- src/v3/compiler/tests/integration/anthropic_operations_test.rs +
  integration.rs mod entry — three load-bearing checks (lowers as List;
  names unique; Messages pilot present with expected POST /v1/messages
  endpoint + input-field key set per anthropic.dag:183-189).

Pre-merge gate (per #1195 regression-class lesson): workspace-exclude +
v2-compiler-tests + lane2-cost-test all pass before flipping ready.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ck (vacuous on Messages)

Per codex non-blocking finding on PR #1252: header claimed the
ParamToken.name resolution check is wired, but no actual assertion
existed. Adds anthropic_operations_param_tokens_resolve_to_input_keys
which walks every row's path tokens and asserts each ParamToken's
name is a present key in the operation's input map.

Vacuous on the Phase 1 Messages pilot (/v1/messages is pure literal
segments), but rows with path variables inherit the discipline by
construction. Header text tightened to make the structural-wired vs
runtime-active distinction explicit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls and others added 3 commits April 30, 2026 12:41
…nthropic_operations.dag

Per codex non-blocking finding on PR #1252: the live staged effects
authority at src/v3/std/effects.dag declares 'module std.effects', not
'v3.std.effects'. My queue-ahead import path was wrong; fixed before
M2 module scoping starts consuming import paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ed census

Per codex BLOCKING on PR #1252: the new hand-authored Rust integration
file at src/v3/compiler/tests/integration/anthropic_operations_test.rs
must be tracked in the SG-0 hand-authored census ratchet. Entry added
in alphabetical position with comment naming the gating chain
(#1252 → Substrate schema-mirror → callable-decl precursor).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…re text check

Per codex non-blocking finding on PR #1252: the Messages path-token
walker matched any FieldValue::Variant with .. ignoring constructor —
a ParamToken { name: "v1" } could satisfy the text assertion. Tightened
to assert the variant name is LiteralToken before extracting text.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls force-pushed the feat/services-anthropic-operations-pilot branch from f477522 to 53b93d5 Compare April 30, 2026 12:42
briansrls added a commit that referenced this pull request Apr 30, 2026
Service-operation callable declaration precursor for the Anthropic
Messages REST operation, the substrate slice Grounding PR-β #1252 is
waiting on per parent #1130 dispatch.

Adds:
- src/v3/std/anthropic_messages.dag: top-level fn anthropic_messages
  with honest signature consuming v3.std.anthropic_schema mirror types
  (#1261). Returns AnthropicMessages200Body. host body lowers as
  ArrowBody::Unparsed (no producerless realization carrier minted).
- src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:
  5 ratchets — Arrow shape, parameter type list matches v2 source via
  v3 mirror, return type is AnthropicMessages200Body, callable is
  acceptable as Operation.callable.decl target, no Operation/data rows
  leak (those are PR-β scope).

Two intentional simplifications vs v2 (documented in file header):
- max_tokens: Int (v2 'Int = 4096'); v3 has no parameter defaults so
  the default is a caller-side fold, not a v3 contract change.
- Return is the 200 body only; AnthropicErrorShape is PR-β response/
  wire lockstep concern.

Out of scope: anthropic_operations: List<Operation> data row, sibling
binding/realization data rows. Grounding owns those.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 53b93d53 · Trigger: schedule
  • Thinking: 234s wall

BLOCKING (1)

Root Cause

  • src/v3/compiler/tests/integration/anthropic_operations_test.rs Variant-label lookup was bolted onto Declaration.name → resolve the constructor id through the expected parent UrlPathToken Disj.variants labels and reuse that helper in both path-token checks.

Non-blocking — Strengths

  • src/v3/std/anthropic_operations.dag The Phase 1 row is documented as a bounded transition and matches the v2 Messages input keys plus POST /v1/messages.

⚠️ One new test-authority bug blocks this revision, and prior blockers 3165837868 and 3165837871 are still not resolved in the provided diff.

.declaration(*constructor)
.name
.as_deref()
.expect("UrlPathToken variant must have a name");

This comment was marked as resolved.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re codex BLOCKING (sha 53b93d5): addressed (changes already on branch via auto-push at 6f63d72). Replaced both Declaration.name-based variant-label lookups with a shared variant_label_in_parent helper that resolves through the parent sum's Disj.variants list (single-authority for variant-label-to-constructor mapping). Both path-token checks (LiteralToken assertion + ParamToken→inputs boundary check) and the HttpMethod method check share the helper.

Prior blockers (snapshot regen + manifest refresh) still deferred per Substrate-chain gating. PR #1252 stays draft pending #1266 (callable-decl precursor) merge.

— sent from wise-tern-480

@briansrls

Copy link
Copy Markdown
Contributor Author

Re inline BLOCKING at line 156 + 269: same finding as the prior codex BLOCKING, already addressed in commit 6f63d72. Both Declaration.name-based lookups replaced with variant_label_in_parent helper resolving through the parent sum's Disj.variants list (the structural single-authority for variant-label-to-constructor mapping). grep -c variant_label_in_parent anthropic_operations_test.rs returns 4 occurrences (1 helper def + 3 call sites: HttpMethod method, UrlPathToken LiteralToken assertion, UrlPathToken ParamToken classification).

— sent from wise-tern-480

briansrls added a commit that referenced this pull request Apr 30, 2026
…es declaration (#1266)

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* regen bootstrap after std.effects import path fix

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* regen bootstrap + refresh parse manifest after merge

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* PR-α: wrap Operation.callable in CallableRef (typed wrapper, mirrors MethodRef)

* chore: apply cargo fmt

* doc: align test comments with CallableRef wrapper (cosmetic)

* regen bootstrap after merge main

* T-Substrate-AnthropicSchemaMirror: v3 typed mirror for Anthropic Messages signature

- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
  types reachable from operation Messages signature in
  dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
  AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
  return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
  8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
  type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
  are the next substrate precursor that consumes these types.

* WIP: sharp-raven-604

* chore: apply cargo fmt

* anthropic_schema lockstep: couple expected labels to v2 source + optionality

Manager review on PR #1261: the prior lockstep tests asserted v3 labels
against hard-coded constants and only checked v2 type-name presence. They
would NOT catch v2 source drift on field/variant labels themselves.

This commit:
- Extracts the v2 type-block text via v2_type_block(name).
- assert_lockstep_record / assert_lockstep_disj now verify each expected
  label appears literally in the v2 block, fail-closed on either-side drift.
- New anthropic_optional_fields_remain_optional_in_v2_source asserts the
  '?' suffix on is_error: Bool? and stop_sequence: String? in the v2
  source, with comment explaining structural inspection of v3 optionality
  is deferred to the operation-row precursor (per manager guidance).

* anthropic_schema lockstep: bidirectional set equality + structural optionality

OpenAI-Pro REQUEST_CHANGES on PR #1261: prior ratchet only checked v3 set
== expected and expected ⊆ v2. v2 additions silently passed; v3 optionality
was text-only on the v2 side, not structurally checked on v3.

Strengthened:
- v2_record_fields(name) parses the v2 type block and extracts (label,
  is_optional) tuples directly from the source. v2_disj_variants(name)
  extracts variant labels (including from inline 'A | B | C' and
  multi-line '= Foo {} | Bar {}' shapes).
- assert_record_lockstep / assert_disj_lockstep assert SET EQUALITY
  between v2-extracted set and v3 bootstrap set (BTreeSet diff in the
  failure message names v3-only and v2-only labels).
- Optionality is structural on v3: v3_field_is_optional walks the field
  declaration's TypeConnective and matches Cardinality(AtMostOne, _).
  Each v2 'T?' field must lower optional; each v2 'T' field must NOT.
- New test anthropic_user_content_block_user_tool_result_block_optionality
  reaches the variant payload Conj for UserToolResultBlock and asserts
  is_error: Bool? lowers as Cardinality(AtMostOne, Bool) on the
  inner declaration (variant payloads aren't reached by the
  record-level ratchet).

* chore: apply cargo fmt

* fix clippy: use char array in split (manual char comparison lint)

* WIP: sharp-raven-604

* anthropic_schema lockstep: per-variant payload field+optionality coverage

OpenAI-Pro REQUEST_CHANGES on PR #1261: assert_disj_lockstep compared
only variant labels, leaving variant payload field labels and
optionality unguarded — UserToolResultBlock.content / tool_use_id and
AssistantToolUseBlock.id / name / input could drift between v2 and v3
while the test passed.

This commit:
- v2_disj_variants now returns (label, Option<Vec<(field_label,
  is_optional)>>), parsing variant payload bodies via the same logic
  v2_record_fields uses (extracted as parse_v2_brace_body_fields).
- v3_variant_payload_fields walks the v3 variant target's Conj
  declaration and projects (label, Cardinality(AtMostOne, _)?) tuples.
- assert_disj_lockstep extends to per-variant payload set equality and
  optionality: bare-on-bare passes; record-on-record requires set
  equality + optionality match; mismatched (one-side bare,
  other-side payload) fails closed.
- Drops the redundant special-case is_error optionality test — now
  subsumed by structural per-variant payload coverage on
  AnthropicUserContentBlock.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* anthropic_schema lockstep: type-expression equality (records + variant payloads)

OpenAI-Pro REQUEST_CHANGES on PR #1261 (sha 1e08a24): label + optionality
weren't enough to catch field type drift — content: List<X> could become
content: String while tests stayed green.

Adds:
- v3_canonical_ty(dag, ty): walks declarations to produce a canonical
  type-expression string. Named decls (String, Bool, AnthropicStopReason,
  AnthropicMessages200TextBlock, …) canonicalize as their surface name
  even though their underlying connective unfolds to Instantiation
  (e.g. String = FreeMonoid<Int>). Anonymous Instantiation sites
  (List<X>, Map<K, V>) and Cardinality(AtMostOne, T) get unfolded.
- normalize_ty_text(raw): strips trailing '?' and compresses internal
  whitespace so v2 source text matches v3 canonical form.
- v2_record_fields and parse_v2_brace_body_fields now return
  (label, normalized_ty_text, is_optional); v3_variant_payload_fields
  returns (label, canonical_ty, is_optional).
- assert_record_lockstep and assert_disj_lockstep added type-expression
  equality assertions in addition to label-set equality and optionality.
  Optionality is checked separately, so the type comparison strips
  the trailing '?' on both sides and compares inner-element forms only.

Coverage: every mirrored field across AnthropicChatMessage,
AnthropicUserContentBlock (incl. UserToolResultBlock.content/tool_use_id),
AnthropicAssistantContentBlock (incl. AssistantToolUseBlock.input: Json),
AnthropicMessages200TextBlock, AnthropicMessages200Usage (input_tokens: Int),
and AnthropicMessages200Body (content: List<...>, stop_sequence: String?)
now fails closed if v2 carrier type changes.

* anthropic_schema lockstep: also reject Arrow declarations (fn leak guard)

Codex non-blocking improvement on PR #1261: prior anthropic_schema_authors_no_data_rows
test rejected only declarations with value_body: Some(...), so a future
fn anthropic_messages would lower as TypeConnective::Arrow with
value_body: None and bypass the guard. Renamed to ..._or_fns and
extended the filter to also reject TypeConnective::Arrow declarations
authored in src/v3/std/anthropic_schema.dag.

* chore: apply cargo fmt

* T-Substrate-AnthropicMessagesCallable: fn anthropic_messages declaration

Service-operation callable declaration precursor for the Anthropic
Messages REST operation, the substrate slice Grounding PR-β #1252 is
waiting on per parent #1130 dispatch.

Adds:
- src/v3/std/anthropic_messages.dag: top-level fn anthropic_messages
  with honest signature consuming v3.std.anthropic_schema mirror types
  (#1261). Returns AnthropicMessages200Body. host body lowers as
  ArrowBody::Unparsed (no producerless realization carrier minted).
- src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:
  5 ratchets — Arrow shape, parameter type list matches v2 source via
  v3 mirror, return type is AnthropicMessages200Body, callable is
  acceptable as Operation.callable.decl target, no Operation/data rows
  leak (those are PR-β scope).

Two intentional simplifications vs v2 (documented in file header):
- max_tokens: Int (v2 'Int = 4096'); v3 has no parameter defaults so
  the default is a caller-side fold, not a v3 contract change.
- Return is the 200 body only; AnthropicErrorShape is PR-β response/
  wire lockstep concern.

Out of scope: anthropic_operations: List<Operation> data row, sibling
binding/realization data rows. Grounding owns those.

* chore: apply cargo fmt

* chore: restore comment/test adjacency in SG-0 census (cosmetic)

Reviewer (claude opus 4.7) non-blocking exploratory observation on PR
#1266: the alphabetical insertion of anthropic_messages_callable_test.rs
and anthropic_schema_lockstep_test.rs split the PB Tier-2 #1014 comment
block from the test it describes. Moving the comment two lines down
restores adjacency. No behavior change.

* anthropic_messages: pin Unparsed body + correct file header prose

OpenAI-Pro REQUEST_CHANGES on PR #1266: the file header claimed 'host
anthropic_messages' lowers to ArrowBody::ExternalRealization, but the
generated substrate has ArrowBody::Unparsed(span). Prose did not match
the substrate fact, and no test pinned the body class so a silent
rewrite was invisible.

Fixes:
- File header rewritten to honestly describe the actual lowered state:
  body remains Unparsed because the pipeline-stage post-processing
  patch in bootstrap.rs:256 is pipeline-specific and does not fire
  for service-operation callables. The patch is intentionally not
  added (would require a producerless CompilerHostRealization-style
  data row, the parallel surface the #1130 dispatch rejects).
- New ratchet anthropic_messages_body_is_unparsed pins
  ArrowBody::Unparsed; a silent rewrite to ExternalRealization /
  UserDefined / Pending / NoBody fails closed.
- File header explicitly bounds the unparsed-body state to the same
  dissolution trigger as the schema mirror.

* regen bootstrap: re-sync byte spans after anthropic_messages.dag header rewrite
briansrls and others added 4 commits April 30, 2026 14:06
…ic-operations-pilot

# Conflicts:
#	src/v3/compiler/tests/integration.rs
#	src/v3/compiler/tests/integration/sg0_census_test.rs
…ase 1 (rebase against #1246/#1261/#1266)

Resume per manager dispatch (#1133 inbox 4353064310). Substrate cascade
chain CLOSED: #1246 services + Operation/RestEndpointBinding,
#1261 Anthropic schema mirror, #1266 anthropic_messages callable.

Changes from queue-ahead draft:
- Operation row: drop name field (per #1246 — Operation has no
  parallel display-name); add callable: { decl: anthropic_messages }
  (per #1266 callable-decl precursor).
- Import std.effects (not v3.std.effects); add v3.std.anthropic_messages
  + v3.std.services { CallableRef } imports.
- Test: pivot from name-based uniqueness to callable.decl uniqueness;
  pilot-row lookup resolves through callable.decl == anthropic_messages.
- Variant-label resolution via parent Disj.variants helper (codex
  feedback re P2 single-authority).

Two structural-honesty deferrals documented as separate receipts in
the file header (per #1133 inbox 4353159066 — keep distinct):
  §1 INPUT-FIELDS POPULATION — parser-grammar gap; nested
     Map<String, X> literals don't parse in record-field positions.
     Even empty `{}` fails the Map type check (parses as record).
     Whole pilot row deferred; empty list lands as scaffolding.
     Substrate-tracked Phase 1.5+ slice (#1130 comment 4353153545).
  §2 v2 PARAMETER DEFAULTS — InputField.default carrier deferred;
     v2's max_tokens: Int = 4096 not represented. Substrate-tracked
     Phase 1.5+ slice (#1130 comment 4352585286).

messages_pilot_present test #[ignore]'d with re-arm instructions;
list-shape + uniqueness + ParamToken→inputs boundary checks land
(vacuous on empty list but wired for Phase 1.5 row population).

Pre-merge gate: regen clean; integration tests 3 passed + 1 ignored;
parse-corpus manifest refreshed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls marked this pull request as ready for review April 30, 2026 14:22
@briansrls
briansrls merged commit 088a3a4 into main Apr 30, 2026

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a97c4c3f · Trigger: schedule
  • Thinking: 188s wall

Non-blocking — Strengths

  • src/v3/std/anthropic_operations.dag The empty Phase 1 carrier is explicitly documented as a bounded scaffold with parser-grammar and InputField.default dissolution triggers.
  • src/v3/compiler/tests/integration/anthropic_operations_test.rs The new checks use callable.decl and parent-sum variant lookup, preserving single authority for operation identity and token constructors.

✅ No blocking concerns in the current diff.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re BLOCKING at line 128: PR #1252 already merged (14:22:55Z) at commit 088a3a4 — bootstrap snapshots ARE included in the squashed merge (grep -c anthropic_operations bootstrap_generated*.rs returns 4 each on main HEAD). Review reads from a stale sha that predates the regen commit at 457b597.

— sent from wise-tern-480

@briansrls

Copy link
Copy Markdown
Contributor Author

Re BLOCKING at line 96: same as the prior BLOCKING reply — PR #1252 already merged (14:22:55Z, commit 088a3a4). Manifest IS in the merged content (verified: grep anthropic_operations parse_corpus_manifest.txt returns the entry on main HEAD). Reviewer sha is stale.

— sent from wise-tern-480

briansrls added a commit that referenced this pull request May 1, 2026
…edicate + runner (#1314)

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* regen bootstrap after std.effects import path fix

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* regen bootstrap + refresh parse manifest after merge

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* PR-α: wrap Operation.callable in CallableRef (typed wrapper, mirrors MethodRef)

* chore: apply cargo fmt

* doc: align test comments with CallableRef wrapper (cosmetic)

* regen bootstrap after merge main

* T-Substrate-AnthropicSchemaMirror: v3 typed mirror for Anthropic Messages signature

- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
  types reachable from operation Messages signature in
  dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
  AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
  return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
  8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
  type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
  are the next substrate precursor that consumes these types.

* WIP: sharp-raven-604

* chore: apply cargo fmt

* anthropic_schema lockstep: couple expected labels to v2 source + optionality

Manager review on PR #1261: the prior lockstep tests asserted v3 labels
against hard-coded constants and only checked v2 type-name presence. They
would NOT catch v2 source drift on field/variant labels themselves.

This commit:
- Extracts the v2 type-block text via v2_type_block(name).
- assert_lockstep_record / assert_lockstep_disj now verify each expected
  label appears literally in the v2 block, fail-closed on either-side drift.
- New anthropic_optional_fields_remain_optional_in_v2_source asserts the
  '?' suffix on is_error: Bool? and stop_sequence: String? in the v2
  source, with comment explaining structural inspection of v3 optionality
  is deferred to the operation-row precursor (per manager guidance).

* anthropic_schema lockstep: bidirectional set equality + structural optionality

OpenAI-Pro REQUEST_CHANGES on PR #1261: prior ratchet only checked v3 set
== expected and expected ⊆ v2. v2 additions silently passed; v3 optionality
was text-only on the v2 side, not structurally checked on v3.

Strengthened:
- v2_record_fields(name) parses the v2 type block and extracts (label,
  is_optional) tuples directly from the source. v2_disj_variants(name)
  extracts variant labels (including from inline 'A | B | C' and
  multi-line '= Foo {} | Bar {}' shapes).
- assert_record_lockstep / assert_disj_lockstep assert SET EQUALITY
  between v2-extracted set and v3 bootstrap set (BTreeSet diff in the
  failure message names v3-only and v2-only labels).
- Optionality is structural on v3: v3_field_is_optional walks the field
  declaration's TypeConnective and matches Cardinality(AtMostOne, _).
  Each v2 'T?' field must lower optional; each v2 'T' field must NOT.
- New test anthropic_user_content_block_user_tool_result_block_optionality
  reaches the variant payload Conj for UserToolResultBlock and asserts
  is_error: Bool? lowers as Cardinality(AtMostOne, Bool) on the
  inner declaration (variant payloads aren't reached by the
  record-level ratchet).

* chore: apply cargo fmt

* fix clippy: use char array in split (manual char comparison lint)

* WIP: sharp-raven-604

* anthropic_schema lockstep: per-variant payload field+optionality coverage

OpenAI-Pro REQUEST_CHANGES on PR #1261: assert_disj_lockstep compared
only variant labels, leaving variant payload field labels and
optionality unguarded — UserToolResultBlock.content / tool_use_id and
AssistantToolUseBlock.id / name / input could drift between v2 and v3
while the test passed.

This commit:
- v2_disj_variants now returns (label, Option<Vec<(field_label,
  is_optional)>>), parsing variant payload bodies via the same logic
  v2_record_fields uses (extracted as parse_v2_brace_body_fields).
- v3_variant_payload_fields walks the v3 variant target's Conj
  declaration and projects (label, Cardinality(AtMostOne, _)?) tuples.
- assert_disj_lockstep extends to per-variant payload set equality and
  optionality: bare-on-bare passes; record-on-record requires set
  equality + optionality match; mismatched (one-side bare,
  other-side payload) fails closed.
- Drops the redundant special-case is_error optionality test — now
  subsumed by structural per-variant payload coverage on
  AnthropicUserContentBlock.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* anthropic_schema lockstep: type-expression equality (records + variant payloads)

OpenAI-Pro REQUEST_CHANGES on PR #1261 (sha 1e08a24): label + optionality
weren't enough to catch field type drift — content: List<X> could become
content: String while tests stayed green.

Adds:
- v3_canonical_ty(dag, ty): walks declarations to produce a canonical
  type-expression string. Named decls (String, Bool, AnthropicStopReason,
  AnthropicMessages200TextBlock, …) canonicalize as their surface name
  even though their underlying connective unfolds to Instantiation
  (e.g. String = FreeMonoid<Int>). Anonymous Instantiation sites
  (List<X>, Map<K, V>) and Cardinality(AtMostOne, T) get unfolded.
- normalize_ty_text(raw): strips trailing '?' and compresses internal
  whitespace so v2 source text matches v3 canonical form.
- v2_record_fields and parse_v2_brace_body_fields now return
  (label, normalized_ty_text, is_optional); v3_variant_payload_fields
  returns (label, canonical_ty, is_optional).
- assert_record_lockstep and assert_disj_lockstep added type-expression
  equality assertions in addition to label-set equality and optionality.
  Optionality is checked separately, so the type comparison strips
  the trailing '?' on both sides and compares inner-element forms only.

Coverage: every mirrored field across AnthropicChatMessage,
AnthropicUserContentBlock (incl. UserToolResultBlock.content/tool_use_id),
AnthropicAssistantContentBlock (incl. AssistantToolUseBlock.input: Json),
AnthropicMessages200TextBlock, AnthropicMessages200Usage (input_tokens: Int),
and AnthropicMessages200Body (content: List<...>, stop_sequence: String?)
now fails closed if v2 carrier type changes.

* anthropic_schema lockstep: also reject Arrow declarations (fn leak guard)

Codex non-blocking improvement on PR #1261: prior anthropic_schema_authors_no_data_rows
test rejected only declarations with value_body: Some(...), so a future
fn anthropic_messages would lower as TypeConnective::Arrow with
value_body: None and bypass the guard. Renamed to ..._or_fns and
extended the filter to also reject TypeConnective::Arrow declarations
authored in src/v3/std/anthropic_schema.dag.

* chore: apply cargo fmt

* T-Substrate-AnthropicMessagesCallable: fn anthropic_messages declaration

Service-operation callable declaration precursor for the Anthropic
Messages REST operation, the substrate slice Grounding PR-β #1252 is
waiting on per parent #1130 dispatch.

Adds:
- src/v3/std/anthropic_messages.dag: top-level fn anthropic_messages
  with honest signature consuming v3.std.anthropic_schema mirror types
  (#1261). Returns AnthropicMessages200Body. host body lowers as
  ArrowBody::Unparsed (no producerless realization carrier minted).
- src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:
  5 ratchets — Arrow shape, parameter type list matches v2 source via
  v3 mirror, return type is AnthropicMessages200Body, callable is
  acceptable as Operation.callable.decl target, no Operation/data rows
  leak (those are PR-β scope).

Two intentional simplifications vs v2 (documented in file header):
- max_tokens: Int (v2 'Int = 4096'); v3 has no parameter defaults so
  the default is a caller-side fold, not a v3 contract change.
- Return is the 200 body only; AnthropicErrorShape is PR-β response/
  wire lockstep concern.

Out of scope: anthropic_operations: List<Operation> data row, sibling
binding/realization data rows. Grounding owns those.

* chore: apply cargo fmt

* chore: restore comment/test adjacency in SG-0 census (cosmetic)

Reviewer (claude opus 4.7) non-blocking exploratory observation on PR
#1266: the alphabetical insertion of anthropic_messages_callable_test.rs
and anthropic_schema_lockstep_test.rs split the PB Tier-2 #1014 comment
block from the test it describes. Moving the comment two lines down
restores adjacency. No behavior change.

* anthropic_messages: pin Unparsed body + correct file header prose

OpenAI-Pro REQUEST_CHANGES on PR #1266: the file header claimed 'host
anthropic_messages' lowers to ArrowBody::ExternalRealization, but the
generated substrate has ArrowBody::Unparsed(span). Prose did not match
the substrate fact, and no test pinned the body class so a silent
rewrite was invisible.

Fixes:
- File header rewritten to honestly describe the actual lowered state:
  body remains Unparsed because the pipeline-stage post-processing
  patch in bootstrap.rs:256 is pipeline-specific and does not fire
  for service-operation callables. The patch is intentionally not
  added (would require a producerless CompilerHostRealization-style
  data row, the parallel surface the #1130 dispatch rejects).
- New ratchet anthropic_messages_body_is_unparsed pins
  ArrowBody::Unparsed; a silent rewrite to ExternalRealization /
  UserDefined / Pending / NoBody fails closed.
- File header explicitly bounds the unparsed-body state to the same
  dissolution trigger as the schema mirror.

* regen bootstrap: re-sync byte spans after anthropic_messages.dag header rewrite

* T-Verification-BridgeLedger: substrate carrier for bridge-retirement ledger

Adds:
- src/v3/std/bridge_ledger.dag: substrate authority for the bridge-
  retirement ledger Verification's BridgeLedgerZero TestClaim folds.
  - BridgeStatus = Retired | Open (closed two-variant coproduct;
    structural partition, no stringly status).
  - BridgeLedgerRow { name, owner, status, authority } per dispatch
    contract.
  - data bridge_ledger: List<BridgeLedgerRow> = [...] populates the
    five canonical bridge rows from docs/r3-structure.md:79-83.
  - Per-row status rationale documented in file header: source-span-
    file-participation Open, mark-bootstrap-secret-nominal-opacity
    Retired, canonical-lens-name-dispatch Retired, include-str-side-
    channels Open, exact-string-patching-residual Open.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  6 ratchets — BridgeLedgerRow field set, BridgeStatus closed two-
  variant coproduct, bridge_ledger lowers as List<BridgeLedgerRow>,
  five canonical names in document order, name uniqueness, status
  field resolves structurally to a BridgeStatus constructor (not a
  string).
- bootstrap regen + parse manifest refresh + integration mod entry +
  SG-0 census entry.

Single substrate authority — no parallel Rust Vec, no test-side
ledger table. Verification's BridgeLedgerZero fold is out of scope
for this PR per dispatch.

* regen bootstrap + manifest after merging origin/main

* T-Verification-BridgeLedger: predicate variant + runner branch (Director scope extension)

Per parent #1130 dispatch (#4356094666) extending #1314: substrate
authority for BridgeLedgerZero gate, not just the carrier.

Adds:
- src/v3/std/verification.dag: TestPredicate variant
  BridgeLedgerZero { ledger: DeclarationRef }. Single payload field
  preserves typed-edge discipline; structural identity, not stringly
  ledger reference.
- src/v3/compiler/src/test_runner.rs: eval_bridge_ledger_zero branch.
  Resolves the ledger DeclarationRef, walks ValueBody::List rows,
  reads each row's status Variant, partitions by structural
  comparison against BridgeStatus::Retired's variant id (not by
  name). Returns Pass iff every row is Retired; Fail names the
  open rows in declaration order.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  Two new tests:
  - bridge_ledger_zero_predicate_carries_only_ledger_declaration_ref:
    pins the variant's payload set to {ledger} and asserts ledger's
    type is DeclarationRef from v3.spec.v3_l1.
  - bridge_ledger_zero_runner_fails_with_named_open_rows_at_head:
    compiles a TestClaim referencing the ledger via DeclarationRef
    and runs it through TestRunner. At HEAD with three Open rows
    (source_span_file_participation, include_str_side_channels,
    exact_string_patching_residual), expects Fail with all three
    named and the two Retired rows excluded. Re-arms as Pass once
    all five flip to Retired.
- bootstrap regen + parse manifest refresh.

8/8 tests pass; clippy clean. Verification's #1310 can now author the
.dag TestClaim consuming this predicate.

* chore: apply cargo fmt

* doc: bridge_ledger comment cites correct canonical-lens ratchet test (cosmetic)

Reviewer (cursor) NON-BLOCKING finding on PR #1314: per-row rationale for
bridge_canonical_lens_name_dispatch_retired cited
bridge_lower_helpers_patch_zero_residual_test (lower-helper exact-string
patch lane) instead of the canonical-lens-name-dispatch ratchet at
canonical_lens_bridge_ratchet_test.rs. Comment text only; bootstrap +
manifest re-synced for the byte-span shift.

* WIP: sharp-raven-604

* eval_bridge_ledger_zero: enforce canonical ledger identity (single-authority)

Codex REQUEST_CHANGES on PR #1314: the previous type-check accepted any
List<BridgeLedgerRow> declaration, so a sibling list could become a
parallel ledger authority and pass the gate independently of the
canonical bridge_ledger. INVARIANTS P2 / single-authority violation.

Adds:
- Canonical-identity check before the type-check guard: the resolved
  ledger DeclarationId must match dag.declaration_by_name('bridge_ledger').id.
  Sibling List<BridgeLedgerRow> declarations fail closed with a
  diagnostic naming the canonical authority. Type-check stays as
  defense-in-depth (catches a future carrier-shape drift).
- New test bridge_ledger_zero_runner_fails_closed_on_sibling_canonical_
  shape_ledger: compiles a sibling 'data sibling_ledger:
  List<BridgeLedgerRow> = []' and asserts BridgeLedgerZero fails
  closed because the declaration identity isn't the canonical one
  (even though the type IS compatible).
- Existing wrong-type test updated: identity check fires first for
  any non-canonical ledger, so the assertion now expects the
  canonical-identity diagnostic.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* BridgeLedgerZero: tighten payload typing, per-row authority pointers, fail-closed name field

Codex BLOCKING(3) on PR #1314 sha b5f7dd5:

1. Authority document: external doc anchor was generic. Made
   bridge_ledger.dag the explicit substrate authority for rows; per-row
   'authority' field now points at the concrete ratchet (test, PR, or
   gating doc-anchor) that establishes that row's status, not a generic
   taxonomy heading. Status flips from Open to Retired are gated on the
   named ratchet reaching zero residual:
   - source_span_file_participation -> ROADMAP.md#lens-fold-file-path-semantics
   - mark_bootstrap_secret_nominal_opacity -> PR #937
   - canonical_lens_name_dispatch -> canonical_lens_bridge_ratchet_test.rs
   - include_str_side_channels -> PR #1171
   - exact_string_patching_residual -> bridge_lower_helpers_patch_zero_residual_test.rs

2. Predicate schema typing: TestPredicate::BridgeLedgerZero.ledger now
   typed as BridgeLedgerRef (typed wrapper { decl: DeclarationRef }),
   mirror of MethodRef / CallableRef. Adds bridge_ledger.dag::BridgeLedgerRef
   with the same #1175 substrate-gap dissolution trigger. Runner unwraps
   the record at the predicate boundary.

3. Runner row validation: missing or non-String name field now fails
   closed instead of using a placeholder, even before status partition.
   Defensive at the claim boundary, complementing the carrier ratchet
   that already guards bridge_ledger.dag's substrate-side shape.

10/10 tests pass on the new payload shape: predicate-shape ratchet
updated to require BridgeLedgerRef wrapper (not bare DeclarationRef);
runner tests use BridgeLedgerZero { ledger: { decl: <ref> } } literal
construction; sibling-canonical-shape and wrong-type negative tests
still fire fail-closed.

* verification ratchet: include BridgeLedgerZero variant after main rebase

m1_5_verification_test::bootstrap_loads_verification_authority_types
expected variant list still ended at SubstrateResearchDeferredClaim;
appended ('BridgeLedgerZero', vec!['ledger']) to match the live
bootstrap. Bootstrap+manifest re-synced from the post-merge regen.
10/10 bridge_ledger_carrier tests + 1/1 verification ratchet pass.

* doc: align eval_bridge_ledger_zero rustdoc with BridgeLedgerRef payload (cosmetic)

Reviewer (cursor) NON-BLOCKING on PR #1314: rustdoc on
eval_bridge_ledger_zero still described the predicate as
{ ledger: DeclarationRef } even though the substrate surface (and the
implementation) now requires the BridgeLedgerRef { decl: DeclarationRef }
wrapper. INVARIANTS 'documentation describes live state' alignment.
Comment-only; no behavior change; .rs file edit so no bootstrap regen
needed.

* bridge_ledger tests: derive row set + open/retired partition from live ledger (single-authority)

Codex BLOCKING on PR #1314: CANONICAL_BRIDGES + expected_open/retired
arrays copied the ledger row set and status partition into Rust,
creating exactly the test-side parallel table bridge_ledger.dag rules
out (single-authority / M7).

- Removed the CANONICAL_BRIDGES const and the
  bridge_ledger_carries_canonical_five_names_in_doc_order test (the
  test re-asserted ledger content from a hardcoded copy; row content
  authority lives only in bridge_ledger.dag).
- bridge_ledger_lowers_as_list_with_at_least_one_row replaces the
  earlier exact-five-rows assertion: pins the structural shape
  (List value_body, every entry a Record, non-empty) without
  duplicating the row count.
- bridge_ledger_zero_runner_fails_with_named_open_rows_at_head no
  longer hardcodes expected_open_rows / expected_retired_rows. It
  reads the live ledger from the bootstrap, partitions by structural
  comparison against BridgeStatus::Retired's variant id, and asserts:
  every Open row's name appears in the failure diagnostic and every
  Retired row's name does not. Re-arms automatically as upstream rows
  flip status — the test does not need an update each time.

9/9 tests pass; clippy clean. The only authority for ledger row
content is now src/v3/std/bridge_ledger.dag.

* bridge_ledger: repoint umbrella row authority at open-scope prose, not closed sub-slice ratchet

OpenAI-Pro REQUEST_CHANGES on PR #1314: the
bridge_exact_string_patching_residual_retired row's authority pointed
at bridge_lower_helpers_patch_zero_residual_test.rs, the receipt for
the RETIRED lower-helper sub-slice (#1014). The row stays Open because
*other* exact-string patching classes remain outside that receipt's
scope, so the closed-slice test was misleading as the row's authority.

Repointed authority at docs/r3-structure.md:83 — the prose row where
the umbrella's open-scope framing ('Other exact-string patching classes
... keep their own dissolution triggers') is defined. Each 'other class'
has its own trigger; the umbrella row retires when those triggers all
fire. Per-row inline comment in bridge_ledger.dag explains the
distinction.

* WIP: sharp-raven-604

* regen bootstrap + manifest after main rebase (clean conflicts)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant