Skip to content

feat(v3): T-Substrate-AnthropicMessagesCallable — fn anthropic_messages declaration - #1266

Merged
briansrls merged 53 commits into
mainfrom
session/sharp-raven-604
Apr 30, 2026
Merged

briansrls merged 53 commits into
mainfrom
session/sharp-raven-604

Conversation

@briansrls

@briansrls briansrls commented Apr 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

T-Substrate-AnthropicMessagesCallable — service-operation callable declaration precursor for the Anthropic Messages REST operation, the Substrate-owned slice Grounding PR-β #1252 is waiting on (per parent #1130 dispatch following #1261's schema mirror).

Grounding target declaration name: anthropic_messages. PR-β can write callable: { decl: anthropic_messages } against the v3 mirror once this merges. The name is pinned by every test in anthropic_messages_callable_test.rs via dag.declaration_by_name("anthropic_messages"), so renames fail closed at the ratchet.

Adds:

  • src/v3/std/anthropic_messages.dag — top-level fn anthropic_messages(...) -> AnthropicMessages200Body { host anthropic_messages }. Honest signature consuming the v3 mirror types from feat(v3): T-Substrate-AnthropicSchemaMirror — provider-domain type mirror for Messages signature #1261 (AnthropicChatMessage, AnthropicMessages200Body).
  • src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs — 5 ratchets:
    • anthropic_messages_is_arrow_shaped — declaration is Arrow-shaped, not a data row or alias.
    • anthropic_messages_parameter_types_match_v2_source_via_v3_mirror — ordered parameter type list matches v2 source via v3 mirror canonicalization.
    • anthropic_messages_returns_anthropic_messages_200_body — return type is the 200 response slot.
    • anthropic_messages_is_acceptable_callable_ref_target — non-empty input list + named output (the PR-β Operation.callable.decl precondition).
    • anthropic_messages_dag_authors_no_operation_rows — no data rows leak into this file (PR-β authors Operation rows in a sibling).

Honest signature simplifications (vs v2 source)

Two intentional differences from dsl/extdeps/llm/anthropic.dag:180-203, documented in the file header:

  1. max_tokens: Int (v2 Int = 4096). v3's function-decl surface does not carry parameter defaults; the default is a caller-side fold, not a v3 contract change. The type is unchanged.
  2. Return is the 200 body only (AnthropicMessages200Body). 4xx/5xx response carriers (AnthropicErrorShape) are not on the typed return reach; error-response handling lives with PR-β's response/wire lockstep lane.

No producerless realization carrier

host anthropic_messages lowers as ArrowBody::Unparsed. v3's pipeline-stage pattern (PipelineStageBinding + CompilerHostRealization) patches the body to ExternalRealization via a hard-coded loop in bootstrap.rs:256 keyed by stage name; for service operations there is no equivalent (and minting one whose only job is to satisfy a binding-carrier slot would be the producerless parallel surface the dispatch explicitly rejects). PR-β's Operation row carries the source-identity edge directly via callable.decl + endpoint.{method, path}; no separate realization data row is needed in this slice.

Out of scope (PR-β, Grounding-owned)

  • data anthropic_operations: List<Operation> = [...] — the operation row that ties anthropic_messages to source identity llm.Anthropic.Messages lives in a sibling src/v3/std/anthropic_operations.dag file.
  • bootstrap_fixture_authority extension — unchanged here. Grounding extends src/v3/std/extdeps_bootstrap_fixtures.dag with the new fixture row alongside the row authoring.
  • Lockstep test against dsl/extdeps/llm/anthropic.dag's service { operation Messages { … } } block — lands with the row authoring.

Dissolution trigger

Same as anthropic_schema.dag (#1261): when v3 grows a service-DSL parse/load surface that ingests dsl/extdeps/llm/*.dag with full structural fidelity, the v2 source becomes the only authority and this callable retires alongside the schema mirror it references.

Verification

cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap
cargo run -p v3-compiler --features bootstrap-regen-fresh --bin regen_bootstrap -- --verify
cargo test -p v3-compiler refresh_handwritten_parse_snapshot_manifest -- --ignored
cargo test -p v3-compiler --test integration anthropic_messages_callable
cargo test -p v3-compiler --test integration anthropic_schema_lockstep
cargo clippy --all-targets -- -D warnings

5/5 callable tests + 8/8 schema lockstep tests pass locally on the head; clippy clean.

🤖 Generated with Claude Code

…ages signature

- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
  types reachable from operation Messages signature in
  dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
  AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
  return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
  8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
  type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
  are the next substrate precursor that consumes these types.
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: bc1b0276 · Trigger: schedule
  • Comparison: origin/main @ ad016c52 ... review/pr-1266-bc1b0276 @ bc1b0276
  • Thinking: 25s wall

Verdict: APPROVE — diff is narrowly scoped: one fn anthropic_messages declaration in a new .dag file, plus a shape-ratchet test, manifest entry, and the regenerated bootstrap. The signature mirrors the v2 source via the existing anthropic_schema types, simplifications (no defaults, 200-body-only return) are documented with dissolution triggers, and the test file fail-closes against data rows leaking into this file. No invariant or modeling-discipline violations observed.

Exploratory observation (non-blocking): in sg0_census_test.rs:229-232, the new entry anthropic_messages_callable_test.rs is inserted between the #1014 PB Tier-2 comment block and the test that comment describes (bridge_lower_helpers_patch_zero_residual_test.rs). Keeping the list alphabetical broke the comment/test adjacency; trivial to fix by moving the comment down one line.

Reviewer (claude opus 4.7) non-blocking exploratory observation on PR
#1266: the alphabetical insertion of anthropic_messages_callable_test.rs
and anthropic_schema_lockstep_test.rs split the PB Tier-2 #1014 comment
block from the test it describes. Moving the comment two lines down
restores adjacency. No behavior change.
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: bc1b0276 · Trigger: manual
  • Comparison: main @ ad016c52 ... session/sharp-raven-604 @ 88feef8b
  • Conversation: View conversation

1. Story of the diff

This PR adds src/v3/std/anthropic_messages.dag, a v3 callable declaration for Anthropic Messages that imports the previously mirrored Anthropic schema types and exposes fn anthropic_messages(api_key, model, messages, max_tokens, temperature?, system?) -> AnthropicMessages200Body. The intended role is narrow: give the upcoming Operation.callable: CallableRef row a real Arrow-shaped declaration to point at, while leaving the actual Operation/endpoint row to a sibling PR. The regenerated bootstraps incorporate the new declaration and anonymous instantiations for List<AnthropicChatMessage>, Float?, and String?; the integration test module pins the Arrow shape, parameter/output types, and absence of data rows in the new .dag file. The parse corpus manifest and SG0 census are also updated to account for the new hand-authored source and test.

2. Invariant categories

  1. LAYER MODEL — Finding

BLOCKING — substrate external-realization fact does not match the authored contract. The new substrate source says the body is intended to lower to an external realization: src/v3/std/anthropic_messages.dag:42-50 says host anthropic_messages lowers to ArrowBody::ExternalRealization and that no CompilerHostRealization-style row is needed. But the regenerated substrate records the callable as body: ArrowBody::Unparsed(...) at src/v3/compiler/src/bootstrap_generated.rs:785 and again in src/v3/compiler/src/bootstrap_generated_without_parse_surface.rs:785.

This matters because the diff touches substrate-facing callable semantics, not just implementation Rust. Under E-9 / external realization authority, the external semantics must live on Arrow.body; here the source prose claims an external body while the actual downstream Dag fact is still unparsed. Either this PR should materialize the declared external realization in the substrate, or it should make the callable intentionally body-less/pending/unparsed and document that as the actual temporary state instead of claiming ExternalRealization.

  1. INVARIANTS.md + modeling-discipline.md — Finding

BLOCKING — facts do not flow forward across source → generated substrate. The authored source and comments establish a semantic fact about the body at src/v3/std/anthropic_messages.dag:42-50, but the bootstrapped Dag fact at src/v3/compiler/src/bootstrap_generated.rs:785 carries only ArrowBody::Unparsed. That is not an explicit discard; it is a silent semantic mismatch between the stated callable realization and the represented callable realization.

The parameter and return type facts do flow forward correctly: the source signature at src/v3/std/anthropic_messages.dag:66-73 becomes a generated Arrow with Secret, String, List<AnthropicChatMessage>, Int, optional Float, optional String, and AnthropicMessages200Body at src/v3/compiler/src/bootstrap_generated.rs:785.

  1. CODING.md — Compliant

The Rust tests use small free helper functions rather than adding methods: arrow_inputs_output and canonical_ty in src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:27-68 keep the test logic data/function-shaped and local to the integration ratchet.

  1. TESTING.md — Finding

NON-BLOCKING as a test gap, but tied to the blocking substrate issue above. The new tests pin Arrow shape and types, e.g. matches!(decl.connective, TypeConnective::Arrow { .. }) at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:76-82 and expected canonical input types at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:98-111, but they never inspect the Arrow body. That lets the PR pass while the generated callable body is ArrowBody::Unparsed at src/v3/compiler/src/bootstrap_generated.rs:785, despite the source comment claiming ExternalRealization. Add a body ratchet for the intended state, whichever state is actually correct.

  1. LOCKED DESIGN DECISIONS — N/A

N/A — the diff references prior PRs and design constraints, but it does not directly alter a locked design document or a locked substrate decision in the uploaded reference docs.

  1. TRACKED vs UNTRACKED DEBT — Finding

BLOCKING — the declared bridge is tracked, but the actual unparsed-body debt is not. The new file does a good job bounding the callable-only scope at src/v3/std/anthropic_messages.dag:53-59 and gives a dissolution trigger at src/v3/std/anthropic_messages.dag:61-65. However, the concrete temporary state that actually lands is not “external realization without a row”; it is ArrowBody::Unparsed in both generated fixtures. That unparsed-body state is not named as the bridge, not bounded as acceptable substrate debt, and not ratcheted by tests.

3. Verdict

REQUEST_CHANGES

The signature/modeling portion is well scoped and well tested, but the callable’s body semantics are currently inconsistent: the source claims an external realization while the generated substrate records an unparsed body. Because this is substrate-facing external-callable authority, I would block until the PR either lands the actual ExternalRealization fact or explicitly models/ratchets the intended body-less or pending precursor state.

OpenAI-Pro REQUEST_CHANGES on PR #1266: the file header claimed 'host
anthropic_messages' lowers to ArrowBody::ExternalRealization, but the
generated substrate has ArrowBody::Unparsed(span). Prose did not match
the substrate fact, and no test pinned the body class so a silent
rewrite was invisible.

Fixes:
- File header rewritten to honestly describe the actual lowered state:
  body remains Unparsed because the pipeline-stage post-processing
  patch in bootstrap.rs:256 is pipeline-specific and does not fire
  for service-operation callables. The patch is intentionally not
  added (would require a producerless CompilerHostRealization-style
  data row, the parallel surface the #1130 dispatch rejects).
- New ratchet anthropic_messages_body_is_unparsed pins
  ArrowBody::Unparsed; a silent rewrite to ExternalRealization /
  UserDefined / Pending / NoBody fails closed.
- File header explicitly bounds the unparsed-body state to the same
  dissolution trigger as the schema mirror.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: 88feef8b · Trigger: schedule
  • Thinking: 259s wall

BLOCKING (1)

Root Cause

  • src/v3/std/anthropic_messages.dag the new callable borrows the pipeline-only host-materialization story without adding a service-operation realization authority -> either model the service realization/Operation endpoint as the body authority in this PR or document and test the current Unparsed scaffold.

⚠️ The callable signature shape is clean, but the body-authority claim contradicts the generated substrate and should be corrected before downstream operation rows consume it.

Comment thread src/v3/std/anthropic_messages.dag Outdated
// Grounding owns).
//
// **Body.** `host anthropic_messages` lowers to
// `ArrowBody::ExternalRealization`, exactly the shape `pipeline.dag`'s

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: This claims host anthropic_messages lowers to ArrowBody::ExternalRealization, but the generated bootstrap in this diff stores the callable with ArrowBody::Unparsed, so the service-operation body fact does not flow forward as modeled (facts-flow-forward/modeling faithfulness).

@briansrls

Copy link
Copy Markdown
Contributor Author

Already addressed on current head c74a9de3a (the codex review here was running against 88feef8b, the head before the fix). Same finding the openai-pro review at #1266 (comment) raised; resolved the same way.

The prior commit took the second of the two paths the codex finding outlines ("document and test the current Unparsed scaffold"):

  1. File header rewritten (src/v3/std/anthropic_messages.dag "Body — actual state and bound" section) to honestly describe the lowered state: host anthropic_messages stays as ArrowBody::Unparsed(span) because the pipeline-stage host parse / host lower patch at bootstrap.rs:256 is pipeline-specific and does not fire for service-operation callables. Adding an equivalent service-realization patch was explicitly rejected by the session/jolly-ram-908 · jolly-ram-908 #1130 dispatch as a producerless parallel surface (a CompilerHostRealization-style data row whose only job is to satisfy a binding-carrier slot).

  2. Body class ratcheted by anthropic_messages_body_is_unparsed in anthropic_messages_callable_test.rs — fails closed against silent rewrites in either direction (ExternalRealization / UserDefined / Pending / NoBody). PR-β consumers (Operation.callable.decl) read the signature, not the body, so the Unparsed state does not block downstream consumption.

  3. Bound named explicitly in the file header: the unparsed-body state retires under the same dissolution trigger as the schema mirror — when v3 grows a service-DSL parse/load surface that ingests dsl/extdeps/llm/*.dag with full structural fidelity.

Verifiable on c74a9de3a:

running 6 tests
test anthropic_messages_callable_test::anthropic_messages_body_is_unparsed ... ok
test anthropic_messages_callable_test::anthropic_messages_dag_authors_no_operation_rows ... ok
test anthropic_messages_callable_test::anthropic_messages_is_acceptable_callable_ref_target ... ok
test anthropic_messages_callable_test::anthropic_messages_is_arrow_shaped ... ok
test anthropic_messages_callable_test::anthropic_messages_parameter_types_match_v2_source_via_v3_mirror ... ok
test anthropic_messages_callable_test::anthropic_messages_returns_anthropic_messages_200_body ... ok
test result: ok. 6 passed; 0 failed

— sent from sharp-raven-604

@briansrls

Copy link
Copy Markdown
Contributor Author

Stale — already fixed on current head c74a9de3a. The reviewer cited line 43 as claiming "lowers to ArrowBody::ExternalRealization"; that prose was on 88feef8b. The current anthropic_messages.dag:42-54 reads:

// **Body — actual state and bound.** `host anthropic_messages` lowers
// to `ArrowBody::Unparsed(span)` in the bootstrap, NOT to
// `ArrowBody::ExternalRealization`. The pipeline-stage pattern in
// `src/v3/compiler/pipeline.dag` (`host parse` / `host lower` / etc.)
// gets its body rewritten to `ExternalRealization(realization_id)` by
// a hard-coded post-processing loop in
// `src/v3/compiler/src/bootstrap.rs:256` keyed by stage name; that
// patch is pipeline-specific and does not fire here. ...
//     the body remains `Unparsed`.

Plus a anthropic_messages_body_is_unparsed test ratchet (anthropic_messages_callable_test.rs) that fails closed if the body class drifts in either direction. Same fix as the rolled-up codex review at #1266 (comment).

— sent from sharp-raven-604

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: c74a9de3 · Trigger: schedule
  • Comparison: origin/main @ ad016c52 ... review/pr-1266-c74a9de3 @ c74a9de3
  • Thinking: 31s wall

Diff looks clean. Single new .dag file declaring fn anthropic_messages, with an Unparsed body whose temporary state is documented, bounded, and tied to a named dissolution trigger (v3 service-DSL parse/load surface). Five-test ratchet pins shape, parameter types, output, body class, and rejects parallel data rows. Bootstrap regen + manifest + census wiring all consistent.

Verdict: APPROVE — narrowly scoped substrate addition. The Unparsed body is a tracked bridge (documented in file header lines 42-68, bounded, dissolution trigger named at lines 78-82, ratcheted by anthropic_messages_body_is_unparsed). Parameter-type ratchet, output ratchet, and "no data rows" leak guard collectively keep the slice fail-closed. No principle-level violations observed.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: c74a9de3 · Trigger: manual
  • Comparison: main @ ad016c52 ... session/sharp-raven-604 @ c74a9de3
  • Conversation: View conversation

1. Story of the diff

This PR introduces src/v3/std/anthropic_messages.dag as a narrow substrate-facing declaration for the Anthropic Messages operation: one fn anthropic_messages(...) -> AnthropicMessages200Body with the parameter surface grounded in Secret, String, List<AnthropicChatMessage>, Int, Float?, and String? at src/v3/std/anthropic_messages.dag:72-92. The body is deliberately not realized as an executable host binding; the file documents that host anthropic_messages currently lowers to ArrowBody::Unparsed, bounded by a future service-DSL parse/load surface that will retire this hand-authored mirror at src/v3/std/anthropic_messages.dag:42-70.

The Rust changes are ratchets around that declaration rather than new production behavior. The new integration module checks that the declaration exists, is Arrow-shaped, has the expected canonical input/output types, remains Unparsed, and does not leak Operation/data rows into this file (src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:28-221). The bootstrap files and parse manifest are regenerated to include the new std file and declaration.

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation).

Compliant — this is substrate-touching, but it adds a callable declaration rather than a parallel Rust-side operation model: fn anthropic_messages(...) -> AnthropicMessages200Body is the single declared surface at src/v3/std/anthropic_messages.dag:72-92, and the operation row is explicitly kept out of this slice at src/v3/std/anthropic_messages.dag:62-67.

  1. INVARIANTS.md + modeling-discipline.md.

Compliant — P2 single-authority / facts-flow-forward is handled by splitting the callable signature from the future Operation row: the new test rejects value_body rows authored in anthropic_messages.dag at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:177-221, so this PR does not create a second source for operation identity. The temporary mirror is also bounded by a named dissolution trigger at src/v3/std/anthropic_messages.dag:64-70, matching the scaffold rule that intermediate shapes need a checkable retirement condition. chatgpt-review-33c866ca-817f-4d…

  1. CODING.md.

Compliant — the Rust test helpers are small free functions over &Dag (arrow_inputs_output and canonical_ty) at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:28-67, matching the data-plus-free-functions style and explicit dependency shape rather than adding methods or hidden state. chatgpt-review-140a2083-3da2-48…

  1. TESTING.md.

Compliant — the PR adds focused behavior ratchets and wires the module into integration.rs at src/v3/compiler/tests/integration.rs:40-41. The tests are at the right level because the contract being pinned is “appears in the full bootstrap as a substrate declaration,” so using generated_full_bootstrap_dag() is the subject, not incidental pipeline coupling. The test names are also behavior-shaped: e.g. anthropic_messages_returns_anthropic_messages_200_body and anthropic_messages_dag_authors_no_operation_rows at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:116 and 177. chatgpt-review-03b3c88b-7d9f-40…

  1. LOCKED DESIGN DECISIONS.

Compliant — the diff references the locked-ish service-operation realization boundary by explicitly refusing to fabricate ExternalRealization: the body-state comment says this lands as ArrowBody::Unparsed, not ExternalRealization, at src/v3/std/anthropic_messages.dag:42-58, and the test pins that exact state at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:146-175.

  1. TRACKED vs UNTRACKED DEBT.

Compliant — the new hand-authored .dag mirror and Rust ratchet are tracked rather than open-ended. Documentation is present at src/v3/std/anthropic_messages.dag:10-70; the bound is “signature only, no operation rows/body realization” at src/v3/std/anthropic_messages.dag:51-67; the named dissolution trigger is the future v3 service-DSL parse/load surface at src/v3/std/anthropic_messages.dag:64-70. The hand-authored Rust test is also added to the SG0 census list at src/v3/compiler/tests/integration/sg0_census_test.rs:227-231.

3. Verdict

APPROVE — This is a narrow, well-ratcheted substrate declaration slice. The potentially risky temporary state (Unparsed body plus hand-authored mirror) is explicitly bounded, tested, and given a dissolution trigger, while operation-row authority is kept out of this PR rather than duplicated.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: cursor / composer-2
  • Commit: 00387e4a · Trigger: schedule
  • Comparison: origin/main @ ad016c52 ... review/pr-1266-00387e4a @ 00387e4a
  • Thinking: 34s wall

Verdict: APPROVE — The diff adds src/v3/std/anthropic_messages.dag (grounded to the v2 service block and the existing anthropic_schema mirror), wires it into bootstrap (regenerated bootstrap_generated*.rs), and adds a focused integration ratchet in anthropic_messages_callable_test.rs plus manifest/census updates. The .dag header documents the two intentional v2/v3 signature differences, the honest Unparsed body, a clear dissolution trigger, and defers Operation rows to the follow-on — consistent with INVARIANTS (boundary discipline, fail-closed via tests, tracked scaffold) and modeling-discipline (named trigger, no silent authority split). CODING / TESTING: new Rust is integration-style with behavior-named tests; using generated_full_bootstrap_dag() matches the repo’s stated integration-test practice. The value_body.is_some() leak check is consistent with how fn lowers (value_body: None per the sibling schema test’s comment), so it targets stray data rows without rejecting the sole fn. No concrete rubric violations tied to lines in this diff.

Exploratory (optional): canonical_ty parallels the schema lockstep module; sharing helpers could reduce duplication later, but that is outside this PR’s scope and not a principle breach.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: 00387e4a · Trigger: manual
  • Comparison: main @ e96f67b9 ... session/sharp-raven-604 @ a69ed2d9
  • Conversation: View conversation

1. Story of the diff

This PR introduces v3.std.anthropic_messages as a narrow substrate declaration for the Anthropic Messages callable, not as the full service-operation model. The new .dag file imports the existing Anthropic schema mirror and declares fn anthropic_messages(api_key: Secret, model: String, messages: List<AnthropicChatMessage>, max_tokens: Int, temperature: Float?, system: String?) -> AnthropicMessages200Body with a host anthropic_messages body at src/v3/std/anthropic_messages.dag:83-91. The file is careful to make this a callable-declaration authority only: it documents the v2 source, the two intentional simplifications, the fact that the host body remains ArrowBody::Unparsed, the sibling PR’s ownership of Operation rows, and the dissolution trigger when v3 can ingest the service DSL directly at src/v3/std/anthropic_messages.dag:16-82.

The generated bootstrap files are refreshed so the callable exists in the full bootstrap as an Arrow, the parse manifest starts tracking the new .dag source, and SG-0 census accounts for the new hand-authored integration ratchet. The test module exercises the intended boundary: declaration resolution, Arrow shape, parameter type sequence, 200-body output, callable-target suitability, Unparsed body status, and absence of data rows in anthropic_messages.dag at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:71-221.

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation).

Compliant — this does touch substrate-facing .dag surface, but the new fact is a typed callable declaration, not an implementation-only Rust mirror: the declaration is authored once in src/v3/std/anthropic_messages.dag:83-91, and the body state is explicitly bounded as Unparsed rather than pretending a host realization exists at src/v3/std/anthropic_messages.dag:42-68.

  1. INVARIANTS.md + modeling-discipline.md.

Compliant — Modeling Faithfulness / facts-flow-forward are handled by grounding the signature in the v2 Anthropic operation and importing the already-modeled schema mirror instead of using primitive-only placeholders: src/v3/std/anthropic_messages.dag:16-23 names the source and explains why the schema mirror is the structural carrier. Fail-closed is also covered by ratchets that reject silent drift in Arrow shape, return type, body class, and leaked operation rows at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:71-221.

  1. CODING.md.

Compliant — the Rust added here is test code with small free helper functions over explicit inputs: arrow_inputs_output(dag, name) at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:27-35 and canonical_ty(dag, ty) at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:41-68. It does not add object-style APIs, hidden global state, or implementation behavior.

  1. TESTING.md.

Compliant — the PR adds a focused integration ratchet and wires it into the integration suite at src/v3/compiler/tests/integration.rs:39-40. The tests are behavior-shaped around the callable boundary: Arrow shape at anthropic_messages_callable_test.rs:71-82, parameter types at :86-112, output type at :115-126, body class at :163-191, and no operation rows at :194-221. Given this is a bootstrap/substrate declaration rather than a narrow pure helper, full-bootstrap integration is the right level.

  1. LOCKED DESIGN DECISIONS.

Compliant — the diff does not silently alter a locked realization model. It explicitly refuses to synthesize a producerless ExternalRealization carrier and documents that the body remains Unparsed until the service-DSL ingestion path exists at src/v3/std/anthropic_messages.dag:42-68; the corresponding test pins that state at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:163-191.

  1. TRACKED vs UNTRACKED DEBT.

Compliant — the temporary shape is tracked: documentation is present at src/v3/std/anthropic_messages.dag:10-82, the bound is explicit (Unparsed body, callable-decl authority only, no Operation rows) at :42-76, and the named dissolution trigger is “when v3 grows a service-DSL parse/load surface that ingests dsl/extdeps/llm/*.dag with full structural fidelity” at :78-82.

3. Verdict

APPROVE

This is a narrow, well-ratcheted substrate declaration slice. The potentially risky part—the callable existing before the full service-operation row—is documented, bounded, and given a concrete dissolution trigger, with tests guarding both the positive callable shape and the negative “no operation rows here” boundary.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: a69ed2d9 · Trigger: schedule
  • Comparison: origin/main @ e96f67b9 ... review/pr-1266-a69ed2d9 @ a69ed2d9
  • Thinking: 146s wall

Verdict: APPROVE

Diff is narrowly scoped: it adds the anthropic_messages callable declaration, documents the temporary ArrowBody::Unparsed bridge with a named dissolution trigger, and adds focused ratchets for callable shape, return type, body state, and no operation-row leakage. I don’t see a concrete violation of the pinned modeling, coding, or testing discipline.

Verification run: cargo test -p v3-compiler anthropic_messages --tests passed, including the new callable tests.

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: openai-pro / gpt-5-5-thinking
  • Commit: a69ed2d9 · Trigger: manual
  • Comparison: main @ e96f67b9 ... session/sharp-raven-604 @ a69ed2d9
  • Conversation: View conversation

1. Story of the diff

This PR introduces src/v3/std/anthropic_messages.dag as a narrow v3 callable declaration for the Anthropic Messages operation, not the full service-operation model. The new declaration imports the existing schema mirror types and exposes an Arrow signature from Secret, String, List<AnthropicChatMessage>, Int, Float?, and String? to AnthropicMessages200Body at src/v3/std/anthropic_messages.dag:89-98.

The PR is deliberately staging only the callable identity that a later Operation.callable.decl row can target: the file documents the v2 source of authority, the two simplifications from v2 defaults/error responses, and the fact that host anthropic_messages currently remains ArrowBody::Unparsed, not an external realization, at src/v3/std/anthropic_messages.dag:31-74. The integration test module is wired into integration.rs at src/v3/compiler/tests/integration.rs:39-40 and ratchets the key shape claims: Arrow-ness, parameter canonical types, 200-body output, callable-ref fitness, unparsed body state, and no operation/data rows in this file at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:76-227. The generated bootstrap files and parse manifest are refreshed to include the new std file.

2. Invariant categories

  1. LAYER MODEL (substrate vs implementation). Compliant — this touches substrate-facing .dag std surface, but it is a declaration-only callable and avoids inventing the operation row or realization carrier; src/v3/std/anthropic_messages.dag:76-82 explicitly keeps Operation authorship out of this slice, while src/v3/std/anthropic_messages.dag:89-98 makes the callable’s type contract structural.
  2. INVARIANTS.md + modeling-discipline.md. Compliant — fail-closed / modeling faithfulness are handled by refusing fake structure: the diff documents that primitive-only signatures and wholesale service parser ingestion are out of scope rather than silently approximating them at src/v3/std/anthropic_messages.dag:22-29, and it names the two honest simplifications at src/v3/std/anthropic_messages.dag:31-46.
  3. CODING.md. Compliant — the new Rust is test-only and uses data + free helper functions (arrow_inputs_output, canonical_ty) over &Dag inputs rather than adding methods or hidden state, at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:32-74. Panics/expect are confined to test assertions, which is acceptable for this surface.
  4. TESTING.md. Compliant — the PR adds focused integration ratchets for the exact staged contract. The tests are behavior-shaped and named by claim: Arrow shape at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:76-89, parameter types at :91-118, output type at :120-132, body class at :168-197, and no operation-row leakage at :199-227.
  5. LOCKED DESIGN DECISIONS. Compliant — the potentially sensitive external-realization decision is not smuggled in. The file says the body remains Unparsed because the pipeline-stage ExternalRealization rewrite is stage-specific and does not apply here at src/v3/std/anthropic_messages.dag:48-60; the test pins that same state at src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:168-197.
  6. TRACKED vs UNTRACKED DEBT. Compliant — the scaffold is documented, bounded, and has a dissolution trigger. The bound is “signature only; body stays Unparsed” at src/v3/std/anthropic_messages.dag:62-74, and the trigger is the future v3 service-DSL parse/load surface that makes the v2 source the only authority at src/v3/std/anthropic_messages.dag:84-88.

3. Verdict

APPROVE. The PR is intentionally narrow and keeps the new substrate-adjacent fact to a typed callable signature, with explicit boundaries around defaults, error responses, operation rows, and external realization. I did not find a changed line that introduces duplicate authority, an untracked scaffold, or a missing ratchet for the staged state.

@briansrls
briansrls merged commit 2111294 into main Apr 30, 2026
4 checks passed
@briansrls
briansrls deleted the session/sharp-raven-604 branch April 30, 2026 13:56
briansrls added a commit that referenced this pull request Apr 30, 2026
…ase 1 (rebase against #1246/#1261/#1266)

Resume per manager dispatch (#1133 inbox 4353064310). Substrate cascade
chain CLOSED: #1246 services + Operation/RestEndpointBinding,
#1261 Anthropic schema mirror, #1266 anthropic_messages callable.

Changes from queue-ahead draft:
- Operation row: drop name field (per #1246 — Operation has no
  parallel display-name); add callable: { decl: anthropic_messages }
  (per #1266 callable-decl precursor).
- Import std.effects (not v3.std.effects); add v3.std.anthropic_messages
  + v3.std.services { CallableRef } imports.
- Test: pivot from name-based uniqueness to callable.decl uniqueness;
  pilot-row lookup resolves through callable.decl == anthropic_messages.
- Variant-label resolution via parent Disj.variants helper (codex
  feedback re P2 single-authority).

Two structural-honesty deferrals documented as separate receipts in
the file header (per #1133 inbox 4353159066 — keep distinct):
  §1 INPUT-FIELDS POPULATION — parser-grammar gap; nested
     Map<String, X> literals don't parse in record-field positions.
     Even empty `{}` fails the Map type check (parses as record).
     Whole pilot row deferred; empty list lands as scaffolding.
     Substrate-tracked Phase 1.5+ slice (#1130 comment 4353153545).
  §2 v2 PARAMETER DEFAULTS — InputField.default carrier deferred;
     v2's max_tokens: Int = 4096 not represented. Substrate-tracked
     Phase 1.5+ slice (#1130 comment 4352585286).

messages_pilot_present test #[ignore]'d with re-arm instructions;
list-shape + uniqueness + ParamToken→inputs boundary checks land
(vacuous on empty list but wired for Phase 1.5 row population).

Pre-merge gate: regen clean; integration tests 3 passed + 1 ignored;
parse-corpus manifest refreshed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request Apr 30, 2026
…ase 1 pilot (#1252)

* feat(grounding): T-Ground services.dag PR-β — anthropic_operations Phase 1 pilot (DRAFT, gated on #1246)

Queue-ahead authoring per manager dispatch (#1133 inbox 4349607248) for
T-Ground services.dag PR-β. Mirrors the #1195 MethodTemplateContract
Phase 1 pattern: typed v3 fixture row + bootstrap_fixture_authority
extension + lockstep test.

This PR is DRAFT until Substrate's PR-α (#1246; sharp-raven-604) lands
the `Operation` / `RestEndpointBinding` / `InputField` type
declarations at src/v3/std/services.dag. Authored against the
proposed shape from #1246 diff inspection.

Files:
- src/v3/std/anthropic_operations.dag — single Messages operation row
  (POST /v1/messages with 6 input fields), lockstep with v2 source of
  truth at dsl/extdeps/llm/anthropic.dag:182-198. Home in src/v3/std/
  per #1187 audit lesson.
- src/v3/std/extdeps_bootstrap_fixtures.dag — extends
  BootstrapFixtureSet + bootstrap_fixture_authority with anthropic_operations.
- src/v3/compiler/src/bootstrap.rs — extends BOOTSTRAP_FIXTURE_PATH_KEYS.
- src/v3/compiler/tests/integration/anthropic_operations_test.rs +
  integration.rs mod entry — three load-bearing checks (lowers as List;
  names unique; Messages pilot present with expected POST /v1/messages
  endpoint + input-field key set per anthropic.dag:183-189).

Pre-merge gate (per #1195 regression-class lesson): workspace-exclude +
v2-compiler-tests + lane2-cost-test all pass before flipping ready.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: apply cargo fmt

* test(grounding): wire ParamToken.name → Operation.inputs boundary check (vacuous on Messages)

Per codex non-blocking finding on PR #1252: header claimed the
ParamToken.name resolution check is wired, but no actual assertion
existed. Adds anthropic_operations_param_tokens_resolve_to_input_keys
which walks every row's path tokens and asserts each ParamToken's
name is a present key in the operation's input map.

Vacuous on the Phase 1 Messages pilot (/v1/messages is pure literal
segments), but rows with path variables inherit the discipline by
construction. Header text tightened to make the structural-wired vs
runtime-active distinction explicit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(grounding): correct import path v3.std.effects → std.effects in anthropic_operations.dag

Per codex non-blocking finding on PR #1252: the live staged effects
authority at src/v3/std/effects.dag declares 'module std.effects', not
'v3.std.effects'. My queue-ahead import path was wrong; fixed before
M2 module scoping starts consuming import paths.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(grounding): add anthropic_operations_test.rs to SG-0 hand-authored census

Per codex BLOCKING on PR #1252: the new hand-authored Rust integration
file at src/v3/compiler/tests/integration/anthropic_operations_test.rs
must be tracked in the SG-0 hand-authored census ratchet. Entry added
in alphabetical position with comment naming the gating chain
(#1252 → Substrate schema-mirror → callable-decl precursor).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(grounding): assert UrlPathToken constructor is LiteralToken before text check

Per codex non-blocking finding on PR #1252: the Messages path-token
walker matched any FieldValue::Variant with .. ignoring constructor —
a ParamToken { name: "v1" } could satisfy the text assertion. Tightened
to assert the variant name is LiteralToken before extracting text.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: wise-tern-480

* WIP: wise-tern-480

* chore: apply cargo fmt

* feat(grounding): T-Ground services.dag PR-β — anthropic_operations Phase 1 (rebase against #1246/#1261/#1266)

Resume per manager dispatch (#1133 inbox 4353064310). Substrate cascade
chain CLOSED: #1246 services + Operation/RestEndpointBinding,
#1261 Anthropic schema mirror, #1266 anthropic_messages callable.

Changes from queue-ahead draft:
- Operation row: drop name field (per #1246 — Operation has no
  parallel display-name); add callable: { decl: anthropic_messages }
  (per #1266 callable-decl precursor).
- Import std.effects (not v3.std.effects); add v3.std.anthropic_messages
  + v3.std.services { CallableRef } imports.
- Test: pivot from name-based uniqueness to callable.decl uniqueness;
  pilot-row lookup resolves through callable.decl == anthropic_messages.
- Variant-label resolution via parent Disj.variants helper (codex
  feedback re P2 single-authority).

Two structural-honesty deferrals documented as separate receipts in
the file header (per #1133 inbox 4353159066 — keep distinct):
  §1 INPUT-FIELDS POPULATION — parser-grammar gap; nested
     Map<String, X> literals don't parse in record-field positions.
     Even empty `{}` fails the Map type check (parses as record).
     Whole pilot row deferred; empty list lands as scaffolding.
     Substrate-tracked Phase 1.5+ slice (#1130 comment 4353153545).
  §2 v2 PARAMETER DEFAULTS — InputField.default carrier deferred;
     v2's max_tokens: Int = 4096 not represented. Substrate-tracked
     Phase 1.5+ slice (#1130 comment 4352585286).

messages_pilot_present test #[ignore]'d with re-arm instructions;
list-shape + uniqueness + ParamToken→inputs boundary checks land
(vacuous on empty list but wired for Phase 1.5 row population).

Pre-merge gate: regen clean; integration tests 3 passed + 1 ignored;
parse-corpus manifest refreshed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…edicate + runner (#1314)

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* regen bootstrap after std.effects import path fix

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* regen bootstrap + refresh parse manifest after merge

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* WIP: sharp-raven-604

* PR-α: wrap Operation.callable in CallableRef (typed wrapper, mirrors MethodRef)

* chore: apply cargo fmt

* doc: align test comments with CallableRef wrapper (cosmetic)

* regen bootstrap after merge main

* T-Substrate-AnthropicSchemaMirror: v3 typed mirror for Anthropic Messages signature

- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
  types reachable from operation Messages signature in
  dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
  AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
  return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
  8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
  type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
  are the next substrate precursor that consumes these types.

* WIP: sharp-raven-604

* chore: apply cargo fmt

* anthropic_schema lockstep: couple expected labels to v2 source + optionality

Manager review on PR #1261: the prior lockstep tests asserted v3 labels
against hard-coded constants and only checked v2 type-name presence. They
would NOT catch v2 source drift on field/variant labels themselves.

This commit:
- Extracts the v2 type-block text via v2_type_block(name).
- assert_lockstep_record / assert_lockstep_disj now verify each expected
  label appears literally in the v2 block, fail-closed on either-side drift.
- New anthropic_optional_fields_remain_optional_in_v2_source asserts the
  '?' suffix on is_error: Bool? and stop_sequence: String? in the v2
  source, with comment explaining structural inspection of v3 optionality
  is deferred to the operation-row precursor (per manager guidance).

* anthropic_schema lockstep: bidirectional set equality + structural optionality

OpenAI-Pro REQUEST_CHANGES on PR #1261: prior ratchet only checked v3 set
== expected and expected ⊆ v2. v2 additions silently passed; v3 optionality
was text-only on the v2 side, not structurally checked on v3.

Strengthened:
- v2_record_fields(name) parses the v2 type block and extracts (label,
  is_optional) tuples directly from the source. v2_disj_variants(name)
  extracts variant labels (including from inline 'A | B | C' and
  multi-line '= Foo {} | Bar {}' shapes).
- assert_record_lockstep / assert_disj_lockstep assert SET EQUALITY
  between v2-extracted set and v3 bootstrap set (BTreeSet diff in the
  failure message names v3-only and v2-only labels).
- Optionality is structural on v3: v3_field_is_optional walks the field
  declaration's TypeConnective and matches Cardinality(AtMostOne, _).
  Each v2 'T?' field must lower optional; each v2 'T' field must NOT.
- New test anthropic_user_content_block_user_tool_result_block_optionality
  reaches the variant payload Conj for UserToolResultBlock and asserts
  is_error: Bool? lowers as Cardinality(AtMostOne, Bool) on the
  inner declaration (variant payloads aren't reached by the
  record-level ratchet).

* chore: apply cargo fmt

* fix clippy: use char array in split (manual char comparison lint)

* WIP: sharp-raven-604

* anthropic_schema lockstep: per-variant payload field+optionality coverage

OpenAI-Pro REQUEST_CHANGES on PR #1261: assert_disj_lockstep compared
only variant labels, leaving variant payload field labels and
optionality unguarded — UserToolResultBlock.content / tool_use_id and
AssistantToolUseBlock.id / name / input could drift between v2 and v3
while the test passed.

This commit:
- v2_disj_variants now returns (label, Option<Vec<(field_label,
  is_optional)>>), parsing variant payload bodies via the same logic
  v2_record_fields uses (extracted as parse_v2_brace_body_fields).
- v3_variant_payload_fields walks the v3 variant target's Conj
  declaration and projects (label, Cardinality(AtMostOne, _)?) tuples.
- assert_disj_lockstep extends to per-variant payload set equality and
  optionality: bare-on-bare passes; record-on-record requires set
  equality + optionality match; mismatched (one-side bare,
  other-side payload) fails closed.
- Drops the redundant special-case is_error optionality test — now
  subsumed by structural per-variant payload coverage on
  AnthropicUserContentBlock.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* chore: apply cargo fmt

* WIP: sharp-raven-604

* anthropic_schema lockstep: type-expression equality (records + variant payloads)

OpenAI-Pro REQUEST_CHANGES on PR #1261 (sha 1e08a24): label + optionality
weren't enough to catch field type drift — content: List<X> could become
content: String while tests stayed green.

Adds:
- v3_canonical_ty(dag, ty): walks declarations to produce a canonical
  type-expression string. Named decls (String, Bool, AnthropicStopReason,
  AnthropicMessages200TextBlock, …) canonicalize as their surface name
  even though their underlying connective unfolds to Instantiation
  (e.g. String = FreeMonoid<Int>). Anonymous Instantiation sites
  (List<X>, Map<K, V>) and Cardinality(AtMostOne, T) get unfolded.
- normalize_ty_text(raw): strips trailing '?' and compresses internal
  whitespace so v2 source text matches v3 canonical form.
- v2_record_fields and parse_v2_brace_body_fields now return
  (label, normalized_ty_text, is_optional); v3_variant_payload_fields
  returns (label, canonical_ty, is_optional).
- assert_record_lockstep and assert_disj_lockstep added type-expression
  equality assertions in addition to label-set equality and optionality.
  Optionality is checked separately, so the type comparison strips
  the trailing '?' on both sides and compares inner-element forms only.

Coverage: every mirrored field across AnthropicChatMessage,
AnthropicUserContentBlock (incl. UserToolResultBlock.content/tool_use_id),
AnthropicAssistantContentBlock (incl. AssistantToolUseBlock.input: Json),
AnthropicMessages200TextBlock, AnthropicMessages200Usage (input_tokens: Int),
and AnthropicMessages200Body (content: List<...>, stop_sequence: String?)
now fails closed if v2 carrier type changes.

* anthropic_schema lockstep: also reject Arrow declarations (fn leak guard)

Codex non-blocking improvement on PR #1261: prior anthropic_schema_authors_no_data_rows
test rejected only declarations with value_body: Some(...), so a future
fn anthropic_messages would lower as TypeConnective::Arrow with
value_body: None and bypass the guard. Renamed to ..._or_fns and
extended the filter to also reject TypeConnective::Arrow declarations
authored in src/v3/std/anthropic_schema.dag.

* chore: apply cargo fmt

* T-Substrate-AnthropicMessagesCallable: fn anthropic_messages declaration

Service-operation callable declaration precursor for the Anthropic
Messages REST operation, the substrate slice Grounding PR-β #1252 is
waiting on per parent #1130 dispatch.

Adds:
- src/v3/std/anthropic_messages.dag: top-level fn anthropic_messages
  with honest signature consuming v3.std.anthropic_schema mirror types
  (#1261). Returns AnthropicMessages200Body. host body lowers as
  ArrowBody::Unparsed (no producerless realization carrier minted).
- src/v3/compiler/tests/integration/anthropic_messages_callable_test.rs:
  5 ratchets — Arrow shape, parameter type list matches v2 source via
  v3 mirror, return type is AnthropicMessages200Body, callable is
  acceptable as Operation.callable.decl target, no Operation/data rows
  leak (those are PR-β scope).

Two intentional simplifications vs v2 (documented in file header):
- max_tokens: Int (v2 'Int = 4096'); v3 has no parameter defaults so
  the default is a caller-side fold, not a v3 contract change.
- Return is the 200 body only; AnthropicErrorShape is PR-β response/
  wire lockstep concern.

Out of scope: anthropic_operations: List<Operation> data row, sibling
binding/realization data rows. Grounding owns those.

* chore: apply cargo fmt

* chore: restore comment/test adjacency in SG-0 census (cosmetic)

Reviewer (claude opus 4.7) non-blocking exploratory observation on PR
#1266: the alphabetical insertion of anthropic_messages_callable_test.rs
and anthropic_schema_lockstep_test.rs split the PB Tier-2 #1014 comment
block from the test it describes. Moving the comment two lines down
restores adjacency. No behavior change.

* anthropic_messages: pin Unparsed body + correct file header prose

OpenAI-Pro REQUEST_CHANGES on PR #1266: the file header claimed 'host
anthropic_messages' lowers to ArrowBody::ExternalRealization, but the
generated substrate has ArrowBody::Unparsed(span). Prose did not match
the substrate fact, and no test pinned the body class so a silent
rewrite was invisible.

Fixes:
- File header rewritten to honestly describe the actual lowered state:
  body remains Unparsed because the pipeline-stage post-processing
  patch in bootstrap.rs:256 is pipeline-specific and does not fire
  for service-operation callables. The patch is intentionally not
  added (would require a producerless CompilerHostRealization-style
  data row, the parallel surface the #1130 dispatch rejects).
- New ratchet anthropic_messages_body_is_unparsed pins
  ArrowBody::Unparsed; a silent rewrite to ExternalRealization /
  UserDefined / Pending / NoBody fails closed.
- File header explicitly bounds the unparsed-body state to the same
  dissolution trigger as the schema mirror.

* regen bootstrap: re-sync byte spans after anthropic_messages.dag header rewrite

* T-Verification-BridgeLedger: substrate carrier for bridge-retirement ledger

Adds:
- src/v3/std/bridge_ledger.dag: substrate authority for the bridge-
  retirement ledger Verification's BridgeLedgerZero TestClaim folds.
  - BridgeStatus = Retired | Open (closed two-variant coproduct;
    structural partition, no stringly status).
  - BridgeLedgerRow { name, owner, status, authority } per dispatch
    contract.
  - data bridge_ledger: List<BridgeLedgerRow> = [...] populates the
    five canonical bridge rows from docs/r3-structure.md:79-83.
  - Per-row status rationale documented in file header: source-span-
    file-participation Open, mark-bootstrap-secret-nominal-opacity
    Retired, canonical-lens-name-dispatch Retired, include-str-side-
    channels Open, exact-string-patching-residual Open.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  6 ratchets — BridgeLedgerRow field set, BridgeStatus closed two-
  variant coproduct, bridge_ledger lowers as List<BridgeLedgerRow>,
  five canonical names in document order, name uniqueness, status
  field resolves structurally to a BridgeStatus constructor (not a
  string).
- bootstrap regen + parse manifest refresh + integration mod entry +
  SG-0 census entry.

Single substrate authority — no parallel Rust Vec, no test-side
ledger table. Verification's BridgeLedgerZero fold is out of scope
for this PR per dispatch.

* regen bootstrap + manifest after merging origin/main

* T-Verification-BridgeLedger: predicate variant + runner branch (Director scope extension)

Per parent #1130 dispatch (#4356094666) extending #1314: substrate
authority for BridgeLedgerZero gate, not just the carrier.

Adds:
- src/v3/std/verification.dag: TestPredicate variant
  BridgeLedgerZero { ledger: DeclarationRef }. Single payload field
  preserves typed-edge discipline; structural identity, not stringly
  ledger reference.
- src/v3/compiler/src/test_runner.rs: eval_bridge_ledger_zero branch.
  Resolves the ledger DeclarationRef, walks ValueBody::List rows,
  reads each row's status Variant, partitions by structural
  comparison against BridgeStatus::Retired's variant id (not by
  name). Returns Pass iff every row is Retired; Fail names the
  open rows in declaration order.
- src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rs:
  Two new tests:
  - bridge_ledger_zero_predicate_carries_only_ledger_declaration_ref:
    pins the variant's payload set to {ledger} and asserts ledger's
    type is DeclarationRef from v3.spec.v3_l1.
  - bridge_ledger_zero_runner_fails_with_named_open_rows_at_head:
    compiles a TestClaim referencing the ledger via DeclarationRef
    and runs it through TestRunner. At HEAD with three Open rows
    (source_span_file_participation, include_str_side_channels,
    exact_string_patching_residual), expects Fail with all three
    named and the two Retired rows excluded. Re-arms as Pass once
    all five flip to Retired.
- bootstrap regen + parse manifest refresh.

8/8 tests pass; clippy clean. Verification's #1310 can now author the
.dag TestClaim consuming this predicate.

* chore: apply cargo fmt

* doc: bridge_ledger comment cites correct canonical-lens ratchet test (cosmetic)

Reviewer (cursor) NON-BLOCKING finding on PR #1314: per-row rationale for
bridge_canonical_lens_name_dispatch_retired cited
bridge_lower_helpers_patch_zero_residual_test (lower-helper exact-string
patch lane) instead of the canonical-lens-name-dispatch ratchet at
canonical_lens_bridge_ratchet_test.rs. Comment text only; bootstrap +
manifest re-synced for the byte-span shift.

* WIP: sharp-raven-604

* eval_bridge_ledger_zero: enforce canonical ledger identity (single-authority)

Codex REQUEST_CHANGES on PR #1314: the previous type-check accepted any
List<BridgeLedgerRow> declaration, so a sibling list could become a
parallel ledger authority and pass the gate independently of the
canonical bridge_ledger. INVARIANTS P2 / single-authority violation.

Adds:
- Canonical-identity check before the type-check guard: the resolved
  ledger DeclarationId must match dag.declaration_by_name('bridge_ledger').id.
  Sibling List<BridgeLedgerRow> declarations fail closed with a
  diagnostic naming the canonical authority. Type-check stays as
  defense-in-depth (catches a future carrier-shape drift).
- New test bridge_ledger_zero_runner_fails_closed_on_sibling_canonical_
  shape_ledger: compiles a sibling 'data sibling_ledger:
  List<BridgeLedgerRow> = []' and asserts BridgeLedgerZero fails
  closed because the declaration identity isn't the canonical one
  (even though the type IS compatible).
- Existing wrong-type test updated: identity check fires first for
  any non-canonical ledger, so the assertion now expects the
  canonical-identity diagnostic.

* chore: apply cargo fmt

* WIP: sharp-raven-604

* BridgeLedgerZero: tighten payload typing, per-row authority pointers, fail-closed name field

Codex BLOCKING(3) on PR #1314 sha b5f7dd5:

1. Authority document: external doc anchor was generic. Made
   bridge_ledger.dag the explicit substrate authority for rows; per-row
   'authority' field now points at the concrete ratchet (test, PR, or
   gating doc-anchor) that establishes that row's status, not a generic
   taxonomy heading. Status flips from Open to Retired are gated on the
   named ratchet reaching zero residual:
   - source_span_file_participation -> ROADMAP.md#lens-fold-file-path-semantics
   - mark_bootstrap_secret_nominal_opacity -> PR #937
   - canonical_lens_name_dispatch -> canonical_lens_bridge_ratchet_test.rs
   - include_str_side_channels -> PR #1171
   - exact_string_patching_residual -> bridge_lower_helpers_patch_zero_residual_test.rs

2. Predicate schema typing: TestPredicate::BridgeLedgerZero.ledger now
   typed as BridgeLedgerRef (typed wrapper { decl: DeclarationRef }),
   mirror of MethodRef / CallableRef. Adds bridge_ledger.dag::BridgeLedgerRef
   with the same #1175 substrate-gap dissolution trigger. Runner unwraps
   the record at the predicate boundary.

3. Runner row validation: missing or non-String name field now fails
   closed instead of using a placeholder, even before status partition.
   Defensive at the claim boundary, complementing the carrier ratchet
   that already guards bridge_ledger.dag's substrate-side shape.

10/10 tests pass on the new payload shape: predicate-shape ratchet
updated to require BridgeLedgerRef wrapper (not bare DeclarationRef);
runner tests use BridgeLedgerZero { ledger: { decl: <ref> } } literal
construction; sibling-canonical-shape and wrong-type negative tests
still fire fail-closed.

* verification ratchet: include BridgeLedgerZero variant after main rebase

m1_5_verification_test::bootstrap_loads_verification_authority_types
expected variant list still ended at SubstrateResearchDeferredClaim;
appended ('BridgeLedgerZero', vec!['ledger']) to match the live
bootstrap. Bootstrap+manifest re-synced from the post-merge regen.
10/10 bridge_ledger_carrier tests + 1/1 verification ratchet pass.

* doc: align eval_bridge_ledger_zero rustdoc with BridgeLedgerRef payload (cosmetic)

Reviewer (cursor) NON-BLOCKING on PR #1314: rustdoc on
eval_bridge_ledger_zero still described the predicate as
{ ledger: DeclarationRef } even though the substrate surface (and the
implementation) now requires the BridgeLedgerRef { decl: DeclarationRef }
wrapper. INVARIANTS 'documentation describes live state' alignment.
Comment-only; no behavior change; .rs file edit so no bootstrap regen
needed.

* bridge_ledger tests: derive row set + open/retired partition from live ledger (single-authority)

Codex BLOCKING on PR #1314: CANONICAL_BRIDGES + expected_open/retired
arrays copied the ledger row set and status partition into Rust,
creating exactly the test-side parallel table bridge_ledger.dag rules
out (single-authority / M7).

- Removed the CANONICAL_BRIDGES const and the
  bridge_ledger_carries_canonical_five_names_in_doc_order test (the
  test re-asserted ledger content from a hardcoded copy; row content
  authority lives only in bridge_ledger.dag).
- bridge_ledger_lowers_as_list_with_at_least_one_row replaces the
  earlier exact-five-rows assertion: pins the structural shape
  (List value_body, every entry a Record, non-empty) without
  duplicating the row count.
- bridge_ledger_zero_runner_fails_with_named_open_rows_at_head no
  longer hardcodes expected_open_rows / expected_retired_rows. It
  reads the live ledger from the bootstrap, partitions by structural
  comparison against BridgeStatus::Retired's variant id, and asserts:
  every Open row's name appears in the failure diagnostic and every
  Retired row's name does not. Re-arms automatically as upstream rows
  flip status — the test does not need an update each time.

9/9 tests pass; clippy clean. The only authority for ledger row
content is now src/v3/std/bridge_ledger.dag.

* bridge_ledger: repoint umbrella row authority at open-scope prose, not closed sub-slice ratchet

OpenAI-Pro REQUEST_CHANGES on PR #1314: the
bridge_exact_string_patching_residual_retired row's authority pointed
at bridge_lower_helpers_patch_zero_residual_test.rs, the receipt for
the RETIRED lower-helper sub-slice (#1014). The row stays Open because
*other* exact-string patching classes remain outside that receipt's
scope, so the closed-slice test was misleading as the row's authority.

Repointed authority at docs/r3-structure.md:83 — the prose row where
the umbrella's open-scope framing ('Other exact-string patching classes
... keep their own dissolution triggers') is defined. Each 'other class'
has its own trigger; the umbrella row retires when those triggers all
fire. Per-row inline comment in bridge_ledger.dag explains the
distinction.

* WIP: sharp-raven-604

* regen bootstrap + manifest after main rebase (clean conflicts)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant