Repository navigation
MQ PR1 (model): a lowering closes its image; derived nodes mint OccurrenceProjected - #12604
Conversation
…ected (PR1 of 2) Revises the v2.std.node lowering rule: an occurrence names one node, so a lowering's image keeps OccurrenceMinted on the root the builder names and projects every other member. Adds the id source (derive_projected_occurrence, N + cantor(source, k) over one OccurrenceAllocatorSnapshot, bound as a typed refusal) and the idempotent image pass project_image_occurrences. Producers migrate, and the duplicate-minted-id admission wall lands, in the cut (PR2). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ope; seal the allocator
- std.occurrence_identity documents the arm's contract ("a real occurrence of
the containing graph with a cause and no author"). A projector insertion
and a same-graph lowering member are told apart by
scoped_occurrence_ref_in_scope on the cause.
- legacy_binding_delta insertion_provenance_entry returns NotAnInsertion for
a same-scope cause.
- occurrence_allocator_seal returns the snapshot plus a continuation
allocator advanced past the derived range (rung stated as mitigatable).
- New controls; each is paired with a mutation that went red locally.
- Regenerated stage0 mirror std_occurrence_identity.rs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressing review 72543 (/api/reviews/72543/artifacts/stdout.log). Both findings were verified against the code, and both are fixed in this push. 1. Meaning fork on
2. Collision argument depended on an unenforced allocator invariant: fixed with a seal.
Evidence. I ran these locally, not in CI, using
This push also regenerates the stage0 mirror — sent from bold-fox-455 |
… module-item grain only) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re review 72565's open question on the cost of — sent from bold-fox-455 |
PR1 of 2 (model) for MQ node adhoc-2713665c-ef7. This PR lands the id source, the image-closing pass, and the rule revision. PR2 is the cut: it migrates every producer in one change, adds the admission wall, and moves the consumers. Rulings: gentle-koi-724 and neat-boar-16 (both approved option B, with conditions); every condition is addressed below.
The defect
A lowering builds an image of several nodes from one authored node, and the old rule in
v2.std.nodelet every one of them carry the source'sOccurrenceMinted. The eager-newt-412 census found collisions in all 145 observed modules. Within one tree, an occurrence no longer identified a node.The rule (revised in
v2.std.node)node_lowered_fromnow marks a node as a member of its source's image.project_image_occurrences(root, snapshot).OccurrenceMinted. The root is not inferred from shape.OccurrenceProjected { id, caused_by: source }.Id source and collision argument (
std.occurrence_identity)The id is
derive_projected_occurrence(snapshot, source, k) = N + cantor(source, k), where k ≥ 1.OccurrenceAllocatorSnapshotcarries both the parse's next_id and its allocator-domain digest, so they cannot come from two different parses. The cause really is in the same allocator, so scoping it by that allocator's digest is honest.idmust stay a bareOccurrenceId. Two consumers need it:v2.workflow.legacy_binding_deltainsertion_provenance_entrywraps it inScopedOccurrenceRef.v2.lens.identity_captured_navigationnode_source_symbollooks spans up by it.ProjectedSourceNotAuthoredInSnapshotorProjectedOrdinalOutOfRange.Evidence (local executor, this branch)
I ran the witnesses with
gunbc runbuilt from this tree, through a scratch driver that ANDs everytest fninv2.test.provenance.image_occurrence_projection.image_projection_three_derived_members_get_distinct_caused_ids_holds.Rung, stated honestly. Until PR2 lands, the rule is stated and nothing enforces it. PR2 adds the admission wall that refuses two nodes with one minted id. Its red control is an image root with its closing pass removed.
Consumption (§3c)
The new declarations are consumed by the witnesses here. Their production consumers are the image-root builders in PR2, which is a declared frontier.
PR2 plan: producer classification
There are 52 grep sites plus one the grep missed (
std/inhabitance.dag:338, derived). bfl =src/v2/compiler/body_lowering_fold.dag.node_rebuild,node_minimal:405;03_resolve895, 921, 948, 985, 1210, 1672, 1747; bfl 3138, 4114, 4131, 4210T<A>?: root Cardinality 2000; derived Instantiation 1982declared_signature(source: type_expr)stands for no nodesource: shelllower_list_introductioncalled aloneConsumers moved in PR2, in the same motion as the producers:
reference_conservation: followscaused_byto the authored source instead of reading Absent, which would otherwise flood falseDroppedReferenceresults. Its DISSOLUTION note is retired.occurrence_role: counts Projected as derived, not unminted.02_parseandidentity_captured_navigation: reviewed arm by arm.PR2 receipts:
PR3 plan (separate from PR2; model-first)
Goal: one parse per file per ingest. Its control goes RED on a second parse. There is no v1 patch: v1 keeps the double parse until the v2 front end replaces it on the floor path.
PR3 is owned by bold-fox-455 and starts after PR2 lands. It begins with a chain re-derivation (DESIGN §6b): can the reference reading consume the compile's graph-scoped parse, or does closure discovery truly need a parse before the graph scope exists? The answer goes to gentle-koi-724 before any model PR. Consumers: the facts occurrence key (quiet-gull-780),
02_parse,program_assembly. The re-derivation picks one of:compilecarries. This involves no identity change, keepsoccurrence_identity_scope_lawas it is, and keeps the key shape unchanged. Preferred if it holds.occurrence_identity_scope_lawfirst: per-file scope, snapshot and N, plus cross-file assignment at the closure fold. Every authored and derived id is re-keyed. It changes the key shape, so quiet-gull-780 is told before the front end moves (eager-newt-412's facts occurrence key consumes it). The derivationN + cantor(source, k)still holds, with one snapshot per file.PR2 introduces no source-local ids, so PR3 does not depend on any.
Do not merge: neat-boar-16 enqueues.
🤖 Generated with Claude Code