Skip to content

PR-2 cost shape: closure-grain classification, and one contested-name table shared with the fork ledger - #13008

Closed
gunbai-bot[bot] wants to merge 168 commits into
sleek-ibex-207/type-env-surface-walkfrom
calm-pike-525/pr2-lookup-closure-grain
Closed

gunbai-bot[bot] wants to merge 168 commits into
sleek-ibex-207/type-env-surface-walkfrom
calm-pike-525/pr2-lookup-closure-grain

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Cost-shape repair for PR-2, the type_env derived view. This PR targets PR-2's branch, which has no PR yet, so the diff shows only the repair. The attribution is in docs/plans/type-env-single-authority-design.md, section "PR-2 slowdown: attribution", landing on main as a separate PR from session/calm-pike-525.

Defect (DESIGN §6b: the link violated its own grounded contract)

The design's single-exporter fast path ("The winner", fast path) was never implemented. As a result:

  • Every ancestry_lookup that passed presence descended.
  • Each descent level ran surface_has over every import.
  • Each surface_has walked the name's POOL-wide exporter list.

The per-lookup cost therefore grew with the tree. The same pool-wide grain also sized the fork-row candidate set (surface_fork_rows).

Repair

  1. Lookups. closure_sole_declarer classifies a name by its declarers inside the module's CLOSURE, at the top lookup and at every descent level (surface_value).
    • One declarer, and no kernel binding: that declarer's own binding.
    • None: absent.
    • Two or more, or a kernel name: descend, as before.
    • The presence lemma and the fold reach only the closure, which is why the pool-wide grain was wrong. Keyed pool-wide instead (calm-pike-525/pr2-fastpath), the same fast path served under 1% of lookups.
  2. Fork rows. closure_contested_names counts fork candidates from the closure's own declarations, instead of every multi-exporter in the pool. surface_declarers_in_reach loses its only consumer and is deleted.

No cache is added. Both changes evaluate the existing rule at the grain it is stated at.

Receipts

Instrument: cli_run pr2_whole_tree_differential_probe whole_tree_ancestry_digest (--ignored), with phase_cpu guards. The receipt branch is calm-pike-525/pr2-receipt (this PR plus the probe). Subject: whole tree (7,138 modules), BuildBuddy.

  • Regen. claim_executor --required-regen then --required-regen-fixed-point at this head: first_generation_equal=true, fixed_point_equal=true. The stage0 bytes are emitted, not hand-written.
  • Declaration-grain equality. Every one of the 7,135 resolved modules matches PR-2 as written. The 3 blocked modules (9 blocking diagnostics already on main) are reported as a named set.
  • Fork-candidate equality. GUNBC_FORK_CANDIDATE_EQUALITY=1 compares the deleted pool-wide filter against closure_contested_names, per module, over the final pool: equal=7135 differ=0.
  • Cost.
    • PR-2 as written could not finish the whole tree within the runner bound.
    • Every thread-CPU figure compared here comes from a separate runner, and the same BEFORE pin measured about 1.5x apart on two runners. So these figures are read alongside the call counts, which do not depend on the runner. lookup_binding_on_chain demand is identical in every arm.
    • With this PR, the whole tree completes. It still costs more than BEFORE. That residual is representation B's by-construction re-derivation, which the attribution note raises for a ruling.

Added after the ruling: the contested-name table

calm-boar-904 admitted it on 2026-10-02.

  • One production. surface_contested_walk replaces surface_fork_rows. In one walk per module it produces both the fork ledger and each contested name's winner: the direct overlay, else the kernel binding, else the last import's surface value.
  • Retention. The table is kept on AncestryView.contested and ModuleSurface.contested. ancestry_lookup and surface_value only read it.
  • No second producer. ancestry_winner and surface_union_winner lose every caller and are deleted.
  • Derivation, written beside the walk:
    • identity is (view, name), and it is complete, because every input of the union's answer is in it;
    • least common ancestor: the module's build_type_env;
    • retention: the module's TypeEnv;
    • producer: exactly one.
  • Hand Rust. The cli_run assembly loop admits each module with its table. surface_view_controls admits modules through the production walk, so the diamond-lattice control still reds a branching descent.
  • Regen. The fixed point holds at 53f3dd0, and both controls pass.

Table receipts. All arms were built on ONE runner and interleaved, with two runners in counter-order. Subject: GUNBC_PROBE_EXCLUDE=dag/test/,src/v2/test/, which EXCLUDES THE TEST TREES and is closed under importers (4,111 modules). Equality is whole-tree.

The full scored predictions are in #13009.

Not in this PR

  • The deps union and source_visible_names (PR-2 parts b and c).

🤖 Generated with Claude Code

gunbai-bot Bot and others added 30 commits October 1, 2026 08:11
… two closure sizes (#12850)

* Floor memory: per-phase held-set attribution in floor-memory-qualification; structure census at seams; parse index handed over and dropped after planning

- gunbc.floor_demand floor_phase_attribution: fold over the run's own seam/watchdog beats (entry, in-phase peak; left = next phase's entry), reusing floor_seam_of_token and beat_held_set; unknown token refuses.
- //gunbc/instruments:floor-memory-qualification: the supervisor tees the child's stderr, transcribes [floor-cgroup] beats (na counters refuse), and renders the fold per phase beside the verdict.
- floor_retention_census (replaces the uncalled whole-tree ancestry probe): retained vs distinct entries per typecheck-env map, and module-identity overlap, over the process resolve store and the prepared graph at nominal-subject-seeds and prepared-subject-warm.
- New seam bare-reference-edge-index-warm with its typed FloorSeam arm.
- The parse phase's DeclarationIndex is moved (not cloned) to the floor, which drops it once the planning observation returns.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* floor_phase_attribution witness: list index yields Optional; add unread stall/swap supplied-value claim

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor phase attribution: refuse negative counters before nat_magnitude, refuse (not clamp) counters past i64, declare the primitive-boundary dissolution trigger

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Prepared subject: hold the resolved graph without per-module TypeEnvCache

The cache is a typecheck-time carrier (the union of each module's ancestry, consumed only by a later
importer's typecheck). The strict prepared subject is closed and never re-resolved, and no
PreparedRepository reader touches it; floor_retention_census showed every module holding its own
spine (tec.variant_locals ~39M distinct entries over 2335 modules on the main subject). Project it
away at the owner so it drops when the strict resolve returns.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Census and TypeEnvCache projection: state entries-not-bytes and the measured saving (~0.18 GB; im::HashMap shares nodes across merged parents)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Census: entry-independence differential of rewired module copies at identity grain

Every module path held by more than one TypedModule allocation is compared component-wise (module
node, type bindings' resolved nodes, ancestry bindings, parent module paths, function signatures,
parent function envs), by Rc pointer and module path. Gates moving the per-graph rewire to one
wiring per module at the pool's MultiEntryIndex.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor byte attribution: free the typed graph one component class at a time where the floor frees it (strict refusal, prepared teardown), reading mallinfo2 per drop

Order-dependent by construction and reported so: TypeEnv is split into its maps and dropped first,
so each map's figure is a lower bound on its exclusive bytes; shared graphs/modules report
unattributable rather than zero. Armed by the floor only.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* FloorBeatReading: stall and swap are Int? (Absent = the heartbeat's na), not a Bool flag beside a meaningless Int

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: drop the fold's last claim scope when the fold ends, not at function return

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Census: key duplicated copies by module path and source file (the diff base's checkout is a different module)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: correct the last-scope comment -- the teardown's shared modules have another owner (measured unchanged)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Byte probe: each class line states its reading (exclusive / lower bound after shells / includes shared residue)

A late class is credited nodes it shared with earlier ones; read as a saving, emit_graph_info's
4.06 GB at #12381 predicted a cut that measured -0.07 GB (neat-boar-16's A/B on gunbc#12832).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Leave-one-out exclusive bytes for one TypedModule class (the reading a removal's saving is)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* //gunbc/instruments:typed-graph-exclusive-bytes: leave-one-out exclusive bytes per TypedModule class over the whole-tree strict closure

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* typed-graph-exclusive-bytes-floor-subject: the leave-one-out reading at the floor's nominal prepared subject; both rows print ancestry and own TypeEnv entry sums

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* After #12832 landed: #12774's byte probe and TypeEnvCache projection carry item_leaf_owner_modules

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* After #12832 landed: the byte probe and TypeEnvCache projection carry item_leaf_owner_modules

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* gunbc.typed_graph_exclusive_bytes: the leave-one-out meaning as a .dag fold (exclusive, total, typed shared residual) with supplied-value witnesses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclusive-bytes host is transcription only: raw allocator readings cross to gunbc.typed_graph_exclusive_bytes, which decides exclusive, total and the typed shared residual

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73476: cite the instruments, not their output; declare the floor-memory instrumentation's seed growth

- prepared_graph_without_typecheck_caches, the census doc and the byte probe's reading note keep
  the instrument names and the reasoning and drop transcribed figures (DESIGN §6).
- gunbc.floor_memory_instrumentation_seed_growth: the hand-authored census, byte attribution,
  beat transcription and cache-lifetime fix, with reason, v1_seed_standing admission and a
  capability trigger per half; registered in gunbc.seed_growth_admission.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Seed-growth row: the leave-one-out instrument's host declarations, retiring with the typed-graph-as-value trigger

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* typed_graph_exclusive_bytes: consume floor_beat_reading_primitive_boundary for the bare-Int byte readings; name the instrument instead of its figures

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transcribe_floor_beats: only the literal na is unread; a missing, garbled or negative stall or swap refuses like a stat counter

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Exclusive bytes: set-valued classes, type_env_cache as a class, the union's carriers jointly (type_env + type_env_cache + interface); the floor-subject row compiles its subject unprojected so the caches present at the compile peak are read

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…m); XL-2 PR2a (#12863)

* WIP PR2a: Arrow contract edges (draft)

* v2.std.node: an Arrow's contract edges (effect claims, execution-mode claim), closed and not binders

XL-2 PR2a under the 2026-10-01 side-chat ruling (option A). An Arrow may carry
^arrow_effect_claims_edge (readonly / idempotent) and ^arrow_execution_mode_claim_edge
(hermetic), each at most once and each a closed vocabulary arrow_signature_edges_conform
enumerates. Neither counts as the type-binder edge. Duplicates, unknown labels and
hermetic among the effect claims refuse. Identity is order-independent. No producer
emits them yet: lowering and the pipeline readers' metadata arms land together in PR2c
(docs/plans/arrow-contract-edges.md).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a: classify as a DESIGN 3c declared frontier (consumer PR2c, trigger: PR2c lands)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review: claim vocabulary lives in its homes; node owns structure only; no empty claims edge

- review 73521: the claim words are no longer literals in v2.std.node. std.effects gains
  EffectClaim (ReadonlyClaim | IdempotentClaim); hermetic is std.execution_mode Hermetic.
  New v2.std.arrow_contract holds the only spellings as exhaustive projections from those
  types and checks each contract edge's target; v2.std.type_binder runs it on every Arrow
  and reads node's arrow_named_edge_is_non_binder instead of its own allowlist. The
  label-to-variant inverse is a declared bounded residue (no constructor enumeration yet).
- GitHub review 5374647982: an effect-claims edge must hold at least one claim, so "no
  claims" has one form (the absent edge). Reds added for an empty claims edge and an empty
  mode edge; every test checks both walls.
- std_effects.rs stage0 mirror regenerated (required-regen fixed point, round 2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review 73551: one generic optional_is_present; drop the inverse's dead Wet/Record arms

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review 73571: admit labels straight off the projections; no decoded variant, no std presence predicate

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…esses (lands after #12857) (#12858)

* MEASUREMENT ONLY (do not merge): re-admit discovery_census_witness and effect_demand_floor_join_test to the gate, without touching either file, to price their marginal preparation

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Re-admit the floor's own census and effect-demand witnesses to the required gate at exact grain

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Name the instrument, not its output: drop the transcribed closure counts from the roster note (DESIGN §6, review 73545)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (viewer features seeded; hold released always()) (#12830)

* mtcollins1 KVM observer: log in through the context request client, not inside the UI root page

fleet-converge run 36721915217 refused the boot: the observer journalled
"page.evaluate: Execution context was destroyed, most likely because of a
navigation" and released as login-unobserved. It loaded "/" only to borrow an
origin and ran the session POST inside that document, which was replaced
under it.

The session POST, the services read and the session DELETE need a cookie jar,
not a page, so they now go through the browser context's request client. The
sessionStorage keys the viewer reads are seeded by a context init script. The
root page is never loaded; the only in-page evaluations left are on
viewer.html. No retry was added, and every typed refusal and journal word is
unchanged.

The loopback transport's root page now replaces itself on DOMContentLoaded,
and a new wet control asserts the login is seen and the root is never served.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1: read-only fleet-converge mode fetches the BMC's own UI bundle (source.min.js)

Operator decision msg_b3c77f62 (option A on escalation msg_13d5904d): a modeled read-only
route to the firmware's UI bundle, so vendor codes such as cd_error_code are read from
the vendor's source instead of escalated.

- extdeps.bmc.megarac: megarac.Ui.GetServedBundle (readonly, no session, bytes as served)
- gunbc.machine_intake_mtcollins1_ui_bundle_observe: mc info firmware revision first,
  refuse unless 0.32; fetch; sha256; report MATCH or DRIFT against the cited
  2026-09-27 read (never refuses on drift); receipt on every path
- fleet-converge mode mtcollins1_ui_bundle_observe: a mode row on the shared job,
  reusing the fan lane's credential prelude; bytes + receipt uploaded always()
- witness: revision parse, the 0.32/0.33 discriminating pair, unread revision, digest match/drift

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 read-only probes: cut the read-only closures' edges to the compiler

ui_bundle_observe imported the boot diagnostic bundle for two IPMI deadlines,
putting 1019 modules (v2.compiler.*, host_effect_realize, roadmap) in a fetch's
closure; the deadlines are a fact about reaching this unit's BMC, so they move
to gunbc.machine_intake_mtcollins1_access_observation (closure 1019 -> 167).
kvm_still's sol_hold import was dead; sol_hold borrowed the gunbc run step
pipeline's refusal marker and now owns its own (closure 347 -> 96).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 probes: the UI bundle step timeout is a fold of the resolve budget and its read bound

The deadlines keep their names in gunbc.machine_intake_mtcollins1_access_observation, the
destination #12800 uses, so the two branches do not fork where those rows live.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1_kvm_observer_observe: the real KVM observer against the real BMC, no boot; the SPA navigation is journalled

- gunbc.machine_intake_mtcollins1_kvm_observer_observe: under the unit hold, log in,
  establish the viewer, one terminal still, release session/browser/process; journal,
  stills and receipt uploaded always(). Verdict read from the finish record.
- kvm_still: every main-frame navigation is a `navigated` journal line (seq, phase, url)
  through KvmJournalWord / kvm_journal_line / the parser; login waits for Playwright's
  networkidle instead of the first DOMContentLoaded (run 36721915217).
- maintenance_hold: KvmObserverProbe owner arm + admitted acquirer (the boot takes the one
  KVM seat under this hold and refuses its handoff when the seat is busy).
- step timeouts: resolve budget + each probe's declared read bound (workflow-side fold).
- loopback control asserts the recorded route; verdict claims over supplied records.
- fleet-converge.yml regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 probes: always() owner-scoped hold release, bash_emit steps, viewer console journal, served-UI crawl

- maintenance_hold: probe_hold_release_decision / _refused / _committed and the admitted
  mtcollins1_kvm_observer_release_unit_hold: release only KvmObserverProbe{this run} at the
  observed generation; free, foreign or stale is a reported no-op. Reds: foreign holders,
  stale generation. Frontier: runner death / job backstop until #12555 lands on main.
- kvm_observer_observe: mtcollins1_kvm_observer_release_wet (typed owned-process arms), run
  by a new always() step after the probe.
- ci_spec: the ui_bundle, kvm probe and release steps are bash_build nodes rendered by
  bash_emit_stmts (review 73415); no Scaffold, no borrowed fan marker.
- kvm_still: page-console / page-error journal events (viewer never opened /kvm on 36779479938).
- ui_bundle_observe: one read-only served-file observation. Seeds source.min.js and viewer.html;
  further paths parsed from what was served (<script src>, data-main, ./libs/kvm/*), followed
  to closure within a declared 48-file budget; one typed receipt row per file. New
  extdeps.tools.gzip (decode-or-pass-through) so served gzip is parsed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ui_bundle_observe: import ends_with and any from their providers (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM viewer: seed sessionStorage.features from the firmware-0.32 row emitted from the served source.min.js; gzip imports Unit (floor)

Run 36788605665: the served viewer.min.js reads sessionStorage.features.indexOf(...) unguarded
in its KVM view's initialize(), so with features unset it throws and never opens /kvm.

- extdeps.bmc.megarac: megarac_ui_features_0_32 (73 names), EMITTED by
  gunbc.machine_intake_megarac_ui_features megarac_ui_features_row_emit from crawl run
  36787375313's retained source.min.js, refusing unless it digests to the 2026-09-27 pin;
  megarac_ui_features(firmware) and the vendor storage shape megarac_ui_features_json.
- kvm_still: the start looks the list up by firmware (no row -> not started); the launch writes
  features.json and the init script seeds sessionStorage.features; features-unreadable cause.
- loopback viewer reads sessionStorage.features.indexOf unguarded before /kvm; new wet red
  a_viewer_without_its_feature_list_never_opens_kvm (enrolled).
- extdeps.tools.gzip imports Unit from std.types (floor AmbiguousBareNameRead).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* kvm probe: free the unit hold only over a seat observed let go (side-chat blocker 4a)

Both release paths -- the probe's own exit and the always() step -- now keep the unit hold
unless the web session reads released (or no-session), the browser reads closed (or
no-browser), and the observer process is observed exited (or never launched). login-unobserved,
failed/http-/unrecognised words, an unresolved process or an unreadable journal keep the
hold and say why. Reds for each, including failures whose detail contains the success word.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* megarac UI features: the 0.32 list is an observation receipt, not a claimed derivation (review 73613)

The bundle the list is read from is AMI's proprietary MegaRAC UI, not redistributable and not reachable
from CI, so a CI-diffed gate is unavailable: a declared boundary (DESIGN 4b/4d), not a below-ceiling
choice. The list moves out of extdeps.bmc.megarac (observations are receipts in the observing layer,
DESIGN 3) into gunbc.machine_intake_megarac_ui_features as megarac_ui_features_0_32_receipt: firmware
0.32, bundle sha256 (the pinned row), producing run 36787375313, the names, and TranscribedUncited with
the re-derivation route as read obligation. The emitter already refuses any other digest, so a re-fetch
reproduces the names or refuses. extdeps keeps only the vendor storage shape.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…hell; qualified field type is an agreement cell since declaration grafting (#12894)

The service lowering fixture spelled 'transport t {}', a kind #12757 closed to rest|shell|file|local,
so the posix service no longer parsed and three claims returned false. It now spells 'transport shell {}'
with its supplied stream re-offset (the paired tokenize-fidelity claim still guards the stream).

qualified_site_enumerator_differential's disagreement cell asserted the collector does NOT see a
qualified field type; since declaration grafting (#11574) it does, so the cell is flipped to the
agreement control both_enumerators_see_a_qualified_field_type_holds.

The four identities leave the v2_test_family_reds_measured_outside_the_gate list.

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…aults refuse with one typed reason (class G) (#12876)

* v2: a parameter may refine its type with a where clause; it parses and the fn refuses at the clause (body_lowering_reason_parameter_refinement_unmodeled, owned; RFM parameter_refinement_has_no_carrier)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: a default value is one production; a parameter default and a record-field default refuse with one reason (body_lowering_reason_default_value_unmodeled, owned; RFM default_value_has_no_carrier)

Stacked on #12873 (parameter refinement), which edits the same typed_param rule.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* default_value controls: enrol their four producers warm at their alphabetical slot

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ci: retrigger after retargeting to main

* v2: the parameter refusals read one param_list (one find, not one per refusal)

* v2 grammar: one refined-or-defaulted parameter arm, so a plain parameter's head is read twice, not four times

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ult-device control covers fetch_rows and lookup (#12865)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ry declared_field_from_edge (XL-2 PR2b-1) (#12899)

* WIP 2b-1: binder type reads through declared_field_from_edge

* WIP 2b-1: member_edge_type_node; lenses, concept_index, translate, target_model through the reader

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…of killing the process (iterative Value Drop, guarded walkers, located JSON-depth refusal) (#12886)

* Recursion over value depth no longer kills the interpreter: iterative Value Drop, guarded walkers, located JSON-depth refusal

The call-depth limit already held on the native stack (measured: 99,990 passes,
100,010 refuses typed). The rc=134 abort was native recursion over VALUE depth,
which no call limit counts: the derived Drop/PartialEq/Display/Debug and every
hand-written walker recursed once per level. Drop is now iterative; every other
walker runs under the one guard value_depth_guarded; the JSON encoders refuse,
naming the value path, past serde_json's probed read depth before building a
serde_json::Value. The dead recursive encoder value_to_json is deleted. The
recurring_failure_mode row recursion_over_value_depth_uncounted_by_the_call_limit
records the class and the evidence.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enforce the recursive-Value-walker census in build.rs; name the deep-value runtime tests in rust_unit_tests_off_the_merge_path

The source-scan census (value_depth_census.rs) is cheap and needs no deep value, so it
moves onto the merge path: v1-compiler's build.rs includes it and refuses the build on an
unguarded walker (measured red: stripping the guard from value_fast_eq fails cargo check
naming it). The test includes the same function. The deep-value runtime tests genuinely
cannot sit on the floor, so the amendment
value_depth_runtime_tests_named_in_the_population names them in the drop's population.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Bind by reference at the Value destructure main added (iterative Value Drop forbids the move)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Heal-Candidate-Run: 36827634551

* Census lives in build.rs alone (no new stage0 file); install the docs projection CI derived

value_depth_census.rs was refused by the stage0 mirror census: every file under
src/v1/stage0/src is an emitted or rostered surface, so a census there is new seed
growth. build.rs, already hand-maintained and the enforcement point, now carries
unguarded_recursive_value_walkers; the duplicate test copy is dropped (the build
refusal is the check; measured red on value_fast_eq). docs/design-rung-drops.md is
the heal-repair-candidate the generated job derived at fb9547d, with the amendment's
one-line path correction applied.

Ledger-Repair-Judged: docs/design-rung-drops.md

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Key the recursive-Value-walker census on a syn parse (review 73634): the guard must wrap the self-call

The text-grep census passed on body.contains("value_depth_guarded"), which a comment or
string satisfies. build.rs now parses every source with syn and refuses when a function
taking the interpreter's Value calls itself outside a closure handed to
value_depth_guarded. Measured red: stripping the guard from value_fast_eq refuses, and so
does stripping it while a comment and a string name the guard. The parse found two
walkers the grep missed (Value inside a generic): bind_argv_expr and
hoist_call_arg_string_literal_edges, now guarded. Parses run on a thread whose stack is
sized from each file's measured bracket nesting (the emitter mirror nests ~2,000 deep).
syn is a build-dependency; it was already in Cargo.lock.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
…rd; interpreter and emitted Rust disagreed) (#12814)

A false guard falls through to the next arm, a non-Bool guard refuses with the
located InterpError::MatchGuardNotBool, and no admitting arm keeps the existing
non-exhaustive refusal. Discriminating witness with positive controls, and the
recurring_failure_mode row interpreter_ignores_match_arm_guards.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…AfterLineBreak grammar arms (PR1 of 2) (#12773)

* WIP layout model: TokenStream source, named line-break derivation, RefuseOnMatch / AfterLineBreak grammar arms, controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout control: same tokens, different layout, different stream digests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout: derive a per-token line-break index once per stream; a layout question is a lookup (review 73189)

The gap question folded over the whole source per question: O(tokens x source). StreamLayout pairs
the source with a line-break-before answer for every token, derived in one walk over source and
tokens by its only constructor; a line feed inside a token is not layout. The digest reads the
source through the layout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout identity control parses against the warmed dag_prepared_grammar (floor budget: 97k steps vs 72.3k)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout identity control: a module that reaches no layout question (+, not -)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout: keep only line-break-preceded starts; digest covers layout by those, not by every character (floor budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* grammar: cite token_stream_line_break_before (stale symbol, review 73221)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: delete token_stream_source, no consumer after the layout rework (review 73234)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* StreamLayout: drop the unread source field (the source is read once, at lexing); digest renamed to what it covers

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* layout test: the digest covers layout, not source (comment)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: spell the tokenizer's source as v2.std.text.String (emit-build: emitted as host String)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* StreamLayout: one representation, start -> line of each line-break-preceded token (review 73282)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout digest folded once in the layout walk; the parse table reads it (no lookup per token; floor budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: type the layout digest as Fnv1a64Structural, what combine_hash returns (emit-build)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout recorded in the tokenizer's own walk (no second pass over the source); value = the octet the gap begins

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: lexeme_has_line_feed takes v2.std.text.String (emit)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er, joined to the seed over one shared fixture (#12897)

The seed's required_floor_runner declines a changed selection the run's
discovered index cannot declare (DeclinedChangedWitnessOutsideDiscovery),
and v2.workflow.required_floor had no such arm, so the modeled census
could not say what the floor did.

- required_floor: the arm, its wire name, its cost-debt standing, and
  changed_selections_outside_discovery (module = before the LAST `.`).
- floor_changed_witness: Declined standing; blocks unless the home is in
  gunbc.ci_layer_roots non_executing_witness_module_prefixes (the seed's
  identity_home_is_declared_non_executing).
- discovery_census / effect_demand_floor_join: own count bucket; every
  exhaustive match states the arm.
- Shared fixture v2.test.fixture.changed_selection_outside_discovery,
  asserted on the floor by test.claim.discovery_census_witness and joined
  at identity grain to the host decider (extracted as
  changed_selections_outside_discovery) by
  changed_selections_outside_discovery_mirror_tests.

decides_a_changed_selection is not mirrored here: it exists only in
#12833 and follows once that lands.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…che /tmp premise), delete them from the gate amendment (#12887)

* v2.test. floor-lane reds: fix 8 executed identities, delete them from the gate amendment

reference_closure x5 (HARNESS): rc_closure_of passed the ResolvedTree where ReferenceClosureMember
wants its root; production already passes resolved.root since #12432.
effect_demand seam homes (CLAIM-WRONG): a pinned home went stale with #12377; now the relation over
the roster. stage0 wet population (CLAIM-WRONG): count literal broke on #12183's fourth row; now
name-keyed. witness_admission known-red consumer (CLAIM-WRONG): pinned row left the roster in #12651;
now every roster member, plus a control that the de-quarantined row is not expected-red.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* stage0 wet population: annotation at module-item grain (§4c); two-way identity join replaces the count

The in-body // annotation was a hard emit diagnostic (emit-build) and the floor's parse refusal.
The count it replaced existed to catch an ADDED row; the join keeps that: every live row is a named
(basename, route) pair and every pair is live. Planted-red: dropping one pair FAILs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Native cache: no host-global /tmp default; unset roots in the user's cache dir

emit_host_identity_cast_native x3 were red on srv1 (found by neat-boar-16): with
GUNBC_NATIVE_CACHE_ROOT unset, the native-cache namespace stayed at its literal /tmp/gunbc_ path,
shared by every user and runner instance; a directory another runner user left refused the write
(Permission denied), reported as cause=type-error. Unset now roots it at $XDG_CACHE_HOME or
$HOME/.cache (job-user owned; per-instance on the floor runners); neither set refuses. Not under
the checkout: cargo refuses a crate nested in the repo workspace (measured).

Controls: 4 seed unit tests; with an unwritable dir planted at the old /tmp path, all 3 claims
PASS; GUNBC_NATIVE_CACHE_ROOT=/tmp (the old placement) FAILs with Permission denied.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Native cache: one writer per content-keyed workspace (exclusive publish lock)

Two same-user runs outside CI share ~/.cache; materialize, build and the ready marker now run under
an exclusive lock on the realization workspace. A lock, not build-then-rename: a relocated cargo
build recompiles the crate on its first warm run while reporting compile_skipped (measured).
Controls: two concurrent runs on a fresh shared cache both PASS with exactly one cold build and one
.native_ready; a partial dir (marker removed) is rebuilt in place and republished.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Native cache: forward-freeze seed-growth row for the new seed helpers (review 73644 advisory)

The seed comment cited a v1_deletion_plan ^witness_realization_kernel row that no longer exists, so
the growth had no declared row. gunbc.native_cache_root_seed_growth enrolls the three helpers with
purpose, executed controls, and a capability trigger naming BOTH root placement and the per-key
writer. seed_growth_admission witnesses: 7/7 PASS.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…arent-alias relation reads Node.declaration (#12896)

* v1 infer: the transparent-alias head relation reads the declared RHS, not the brand-keeping peel

type_name_transparently_aliases_to asked peel_nominal_alias_identity for an
alias's target name. That peel re-stamps the alias's own identity, so the
relation answered false for every alias of a non-primitive type, and a record
literal was refused against a formal declared through its alias
(TokenThroughput = FieldOfFractions<Nat>, and equally type A = SomeRecord).
Read the head through the declaration's Resolved edge instead, as a bounded chase.

RFM rows: transparent_alias_relation_read_the_brand_keeping_peel (with the
std.algebra anonymous-literal advisories as a declared frontier) and
product_instance_arguments_unjudged_at_call_argument.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Read the alias head from the env declaration's name; instantiate a literal through a non-parameterized alias of an application

The env declaration of an alias is the brand-stamped resolved body with
inferred empty, so the first cut read nothing. Its structural name is the head.
Reading that alone admitted a wrong-field literal into the alias, because the
literal's fields were never instantiated; record_lit_expected_through_generic_alias
gains the non-parameterized arm, transparent_alias_application_at_head.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Park: identity-keyed alias head relation (red until the RHS-head DeclarationRef reaches infer) + non-parameterized arm of record_lit_expected_through_generic_alias; pinned probes

Replaces a84f10d's leaf-keyed head (admitted a cross-module homonym).
type_name_transparently_aliases_to now compares the alias item's RHS-head
DeclarationRef and fails closed when absent, which it is today, so the reds
stay red. transparent_alias_application_at_head is the reusable second link.
Probes: fixtures/alias_head_identity. Blocked on quiet-hawk-702's alias-RHS
identity (decision by quiet-gull-780).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transparent_alias RFM row: cite the pinned probes by function, not line

Review 73372: the PINNED PROBES paragraph cited fixture lines (27, 71, 81,
87, 91, hom_b 9). Name each probe by its function instead, per DESIGN 3's
cite-the-symbol rule, keeping the corpus red's position only as a
convenience beside its symbol.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* transparent_alias RFM row: the wrong-field arm is not independent at execution

Review 73393: link (2), transparent_alias_application_at_head, reads the
head through alias_rhs_head_declaration, so it is inert until the same
alias-RHS identity lands. Say so instead of calling it independent.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Alias-RHS identity: env binding retains the RHS reference; relation reads Node.declaration

Ruling B (quiet-gull-780): TypeBinding.alias_rhs retains the transparent alias's RHS
reference with its head's DeclarationRef written by the one writer in the alias's own
scope; alias_item_rhs_head reads it from the declaring env by exact module path, and
re-resolves no spelling. Builds on witty-ram-630's identity-keyed relation, wrong-field
arm and fixtures (90d568a8).

Two spellings of one declaration (NonEmptyStr / std.types.NonEmptyStr) now agree by the
declaration each names, before any peel; the spelling peel had silently bridged them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Failure-mode row: repair landed, rung by executed probes; comment cites the real writer (review 73642)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enroll the alias-head probes as a floor witness; declare the two below-ceiling populations (review 73656)

Probes move from fixtures/ (run by nothing) to dag/test/probe, judged by
test.claim.alias_head_identity_probe_witness_test through the diagnostic-census
harness, joined by class and subject. The failure-mode row cites the witness and
names the kernel-head and out-of-scope-alias populations with their triggers.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Add the alias-head probe modules (missed by a local exclude rule)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
…pacity_measurement; fleet mode spark_v41_serving_load (#12875)

* serving_load_runner: per-step records and a model-owned host-reading bracket (PR3 groundwork)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Serving-load PR3/3: bind V4.1 to the shared runner; its staircase feeds v41_capacity_measurement

gunbc.spark.v41_serving_load: V4.1's subject (Group A, head srv6 :30000, deepseek-v4.1-flash,
gunbc-v41-tp4), one bench step per v41_staircase_concurrencies level, and a host-pressure reading
on every Group A rank around each step (runner's new per-step bracket). Each step's records are
projected into V41StaircaseStepReading taking the WORST rank per stop rule, and run through
v41_run_staircase under the signed policy. Operator ruling 2026-10-01: pressure on all four ranks,
worst rank; protocol is a copy of GLM's 256/128/0 shape declared as V4.1's own row; the 262k TTFT
gate is not exercised by it and is a stated frontier.

Runner: per-step records + a model-owned host-reading bracket; GLM passes NoHostReading and its
receipt stays byte-equal (witness re-run).

Fleet-converge mode spark_v41_serving_load: a row in every FleetConvergeWorkflowMode match, a step,
and a ci_spec target. No new job.

Executed locally: 5 V4.1 witnesses + 2 GLM runner witnesses rc=0; worst-rank comparison
inverted rc=1 worst_rank.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate fleet-converge.yml for spark_v41_serving_load (main_wet on generated_artifact_gate)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v41_serving_load: a request with no max_concurrency refuses (V41StepConcurrencyUnbound) instead of being judged at level 0

Addresses review 73600. Executed locally: 8 witnesses rc=0; restoring the fabricated-0 arm reds
a_request_without_a_concurrency_refuses_instead_of_judging_level_zero (rc=1).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate fleet-converge.yml after merging main (main_wet on generated_artifact_gate)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…2886) interpreter repairs (#12903)

* Seed-growth receipts for the match-guard (#12814) and value-depth (#12886) interpreter repairs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop declarations already justified by their own seed-growth rows (the roster cites each once)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…able (#12889)

* mtcollins1 KVM observer: log in through the context request client, not inside the UI root page

fleet-converge run 36721915217 refused the boot: the observer journalled
"page.evaluate: Execution context was destroyed, most likely because of a
navigation" and released as login-unobserved. It loaded "/" only to borrow an
origin and ran the session POST inside that document, which was replaced
under it.

The session POST, the services read and the session DELETE need a cookie jar,
not a page, so they now go through the browser context's request client. The
sessionStorage keys the viewer reads are seeded by a context init script. The
root page is never loaded; the only in-page evaluations left are on
viewer.html. No retry was added, and every typed refusal and journal word is
unchanged.

The loopback transport's root page now replaces itself on DOMContentLoaded,
and a new wet control asserts the login is seen and the root is never served.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1: read-only fleet-converge mode fetches the BMC's own UI bundle (source.min.js)

Operator decision msg_b3c77f62 (option A on escalation msg_13d5904d): a modeled read-only
route to the firmware's UI bundle, so vendor codes such as cd_error_code are read from
the vendor's source instead of escalated.

- extdeps.bmc.megarac: megarac.Ui.GetServedBundle (readonly, no session, bytes as served)
- gunbc.machine_intake_mtcollins1_ui_bundle_observe: mc info firmware revision first,
  refuse unless 0.32; fetch; sha256; report MATCH or DRIFT against the cited
  2026-09-27 read (never refuses on drift); receipt on every path
- fleet-converge mode mtcollins1_ui_bundle_observe: a mode row on the shared job,
  reusing the fan lane's credential prelude; bytes + receipt uploaded always()
- witness: revision parse, the 0.32/0.33 discriminating pair, unread revision, digest match/drift

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 read-only probes: cut the read-only closures' edges to the compiler

ui_bundle_observe imported the boot diagnostic bundle for two IPMI deadlines,
putting 1019 modules (v2.compiler.*, host_effect_realize, roadmap) in a fetch's
closure; the deadlines are a fact about reaching this unit's BMC, so they move
to gunbc.machine_intake_mtcollins1_access_observation (closure 1019 -> 167).
kvm_still's sol_hold import was dead; sol_hold borrowed the gunbc run step
pipeline's refusal marker and now owns its own (closure 347 -> 96).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 probes: the UI bundle step timeout is a fold of the resolve budget and its read bound

The deadlines keep their names in gunbc.machine_intake_mtcollins1_access_observation, the
destination #12800 uses, so the two branches do not fork where those rows live.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1_kvm_observer_observe: the real KVM observer against the real BMC, no boot; the SPA navigation is journalled

- gunbc.machine_intake_mtcollins1_kvm_observer_observe: under the unit hold, log in,
  establish the viewer, one terminal still, release session/browser/process; journal,
  stills and receipt uploaded always(). Verdict read from the finish record.
- kvm_still: every main-frame navigation is a `navigated` journal line (seq, phase, url)
  through KvmJournalWord / kvm_journal_line / the parser; login waits for Playwright's
  networkidle instead of the first DOMContentLoaded (run 36721915217).
- maintenance_hold: KvmObserverProbe owner arm + admitted acquirer (the boot takes the one
  KVM seat under this hold and refuses its handoff when the seat is busy).
- step timeouts: resolve budget + each probe's declared read bound (workflow-side fold).
- loopback control asserts the recorded route; verdict claims over supplied records.
- fleet-converge.yml regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 probes: always() owner-scoped hold release, bash_emit steps, viewer console journal, served-UI crawl

- maintenance_hold: probe_hold_release_decision / _refused / _committed and the admitted
  mtcollins1_kvm_observer_release_unit_hold: release only KvmObserverProbe{this run} at the
  observed generation; free, foreign or stale is a reported no-op. Reds: foreign holders,
  stale generation. Frontier: runner death / job backstop until #12555 lands on main.
- kvm_observer_observe: mtcollins1_kvm_observer_release_wet (typed owned-process arms), run
  by a new always() step after the probe.
- ci_spec: the ui_bundle, kvm probe and release steps are bash_build nodes rendered by
  bash_emit_stmts (review 73415); no Scaffold, no borrowed fan marker.
- kvm_still: page-console / page-error journal events (viewer never opened /kvm on 36779479938).
- ui_bundle_observe: one read-only served-file observation. Seeds source.min.js and viewer.html;
  further paths parsed from what was served (<script src>, data-main, ./libs/kvm/*), followed
  to closure within a declared 48-file budget; one typed receipt row per file. New
  extdeps.tools.gzip (decode-or-pass-through) so served gzip is parsed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* ui_bundle_observe: import ends_with and any from their providers (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* KVM viewer: seed sessionStorage.features from the firmware-0.32 row emitted from the served source.min.js; gzip imports Unit (floor)

Run 36788605665: the served viewer.min.js reads sessionStorage.features.indexOf(...) unguarded
in its KVM view's initialize(), so with features unset it throws and never opens /kvm.

- extdeps.bmc.megarac: megarac_ui_features_0_32 (73 names), EMITTED by
  gunbc.machine_intake_megarac_ui_features megarac_ui_features_row_emit from crawl run
  36787375313's retained source.min.js, refusing unless it digests to the 2026-09-27 pin;
  megarac_ui_features(firmware) and the vendor storage shape megarac_ui_features_json.
- kvm_still: the start looks the list up by firmware (no row -> not started); the launch writes
  features.json and the init script seeds sessionStorage.features; features-unreadable cause.
- loopback viewer reads sessionStorage.features.indexOf unguarded before /kvm; new wet red
  a_viewer_without_its_feature_list_never_opens_kvm (enrolled).
- extdeps.tools.gzip imports Unit from std.types (floor AmbiguousBareNameRead).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* kvm probe: free the unit hold only over a seat observed let go (side-chat blocker 4a)

Both release paths -- the probe's own exit and the always() step -- now keep the unit hold
unless the web session reads released (or no-session), the browser reads closed (or
no-browser), and the observer process is observed exited (or never launched). login-unobserved,
failed/http-/unrecognised words, an unresolved process or an unreadable journal keep the
hold and say why. Reds for each, including failures whose detail contains the success word.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* MegaRAC cd_error_code: per-code policy from the vendor's own rmedia table

- extdeps.bmc.megarac megarac_rmedia_status_0_32: the 17 rmedia stop reasons,
  EMITTED by megarac_ui_bundle_rows_emit from the retained source.min.js
  (sha256 5029fae2...), the same single parse entry as megarac_ui_features_0_32;
  refused unless the dictionary is codes 1..N and N is the view's range bound.
- megarac_media_attach: Started/Connecting rows record the code and admit;
  a stopped row refuses BY NAME (MegaRacPresentationStopped) with a per-code
  NoFault/PresentationFailure class; outside-table or unread stays a typed
  knowledge refusal.
- Witnesses for each arm, plus boot run 36721915217's real readings now admit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* megarac UI features: the 0.32 list is an observation receipt, not a claimed derivation (review 73613)

The bundle the list is read from is AMI's proprietary MegaRAC UI, not redistributable and not reachable
from CI, so a CI-diffed gate is unavailable: a declared boundary (DESIGN 4b/4d), not a below-ceiling
choice. The list moves out of extdeps.bmc.megarac (observations are receipts in the observing layer,
DESIGN 3) into gunbc.machine_intake_megarac_ui_features as megarac_ui_features_0_32_receipt: firmware
0.32, bundle sha256 (the pinned row), producing run 36787375313, the names, and TranscribedUncited with
the re-derivation route as read obligation. The emitter already refuses any other digest, so a re-fetch
reproduces the names or refuses. extdeps keeps only the vendor storage shape.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 boot matrix: cd_error cases follow the vendor's rule

Started + 16 (nothing presented, appearing at readiness, stale-replaced with a sticky code) now
proceeds to the boot with the code recorded, as 9263942 asserted. New: an accepted start whose row
falls back to Stopped refuses by the vendor's name -- 11 "Mount Error" as a presentation failure,
16 "Device Ejected" as no fault -- with no handoff. The host-on no-write case uses an uncatalogued
code (99), since a named reason is attached past. megarac_media_model gains stop_at_ready, the one
knob that expresses the stopped-after-start world.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Boot matrix cost rosters: carry the renamed cd_error cases and enrol the two stopped-row cases

Floor run 36846505084 passed every claim (claims_failed=0) and refused six on cost only: the
renamed cd_error cases had lost their rows in gunbc.rung_drop
mtcollins1_boot_matrix_new_witness_eval_step_cost and mtcollins1_boot_matrix_enrolment_dead_band_observed_only,
and the two new stopped-row cases run the same real boot entry. Rows renamed (as 9263942 did) or
added inside the drops' declared population, each citing that run's reading; projection regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…clared resource (D13 step a0) (#12898)

* WIP PR2a: Arrow contract edges (draft)

* v2.std.node: an Arrow's contract edges (effect claims, execution-mode claim), closed and not binders

XL-2 PR2a under the 2026-10-01 side-chat ruling (option A). An Arrow may carry
^arrow_effect_claims_edge (readonly / idempotent) and ^arrow_execution_mode_claim_edge
(hermetic), each at most once and each a closed vocabulary arrow_signature_edges_conform
enumerates. Neither counts as the type-binder edge. Duplicates, unknown labels and
hermetic among the effect claims refuse. Identity is order-independent. No producer
emits them yet: lowering and the pipeline readers' metadata arms land together in PR2c
(docs/plans/arrow-contract-edges.md).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a: classify as a DESIGN 3c declared frontier (consumer PR2c, trigger: PR2c lands)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review: claim vocabulary lives in its homes; node owns structure only; no empty claims edge

- review 73521: the claim words are no longer literals in v2.std.node. std.effects gains
  EffectClaim (ReadonlyClaim | IdempotentClaim); hermetic is std.execution_mode Hermetic.
  New v2.std.arrow_contract holds the only spellings as exhaustive projections from those
  types and checks each contract edge's target; v2.std.type_binder runs it on every Arrow
  and reads node's arrow_named_edge_is_non_binder instead of its own allowlist. The
  label-to-variant inverse is a declared bounded residue (no constructor enumeration yet).
- GitHub review 5374647982: an effect-claims edge must hold at least one claim, so "no
  claims" has one form (the absent edge). Reds added for an empty claims edge and an empty
  mode edge; every test checks both walls.
- std_effects.rs stage0 mirror regenerated (required-regen fixed point, round 2).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review 73551: one generic optional_is_present; drop the inverse's dead Wet/Record arms

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR2a review 73571: admit labels straight off the projections; no decoded variant, no std presence predicate

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2: a `resource` declaration parses and lowers; the index marks its path a declared resource (D13 step a0)

Stacked on #12863. Grammar productions for std.resources' `resource` form, with
every entry read or refused at the entry (v1 skips acquire/release bodies).
Capabilities lower through the operation reader; kind/mode/expires/acquire are
read against std.resources ResourceKind/ResourceMode and std.execution_mode into
a DeclaredResourceContract on a new DeclaredTypeKind arm, captured at normalize.
SymbolIndex gains declared_resources, filled from the captured resource names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* symbol_index: the resource mark is an empty record (a one-arm '= V' reads as an alias)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Resource kind/mode homes move to std.resource_contract so the emitted compiler closure does not pull std.resources' imports

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* comment: home is std.resource_contract

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73658 (DESIGN 3c): carry only the resource name; declare the index mark's consumer and the contract gap

- DeclaredResource carries only { name }. kind/mode/expires/acquire are still read
  against their homes and refuse at the entry, but no consumer reads them yet, so
  they are not carried. That gap is declared as gunbc.recurring_failure_mode
  resource_contract_validated_but_not_carried, with the trigger: the first consumer
  of those facts lands and carries the contract.
- SymbolIndex declared_resources names its production consumer as a declared
  frontier: D13 step (a)'s resolve check on a `requires` member, with deletion if
  step (a) is abandoned.
- The two claims over the eval-step budget now read smaller fixtures: one for the
  census (a resource with one capability beside a record) and one for the full door
  (every property entry, no capability).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* emit_produced: DeclaredResource carries only name

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* A capability's io tail refuses as a service's set-aside member does, not as a malformed entry

GitHub review 5378770924: a capability reads input/output blocks through the shared
io grammar, which admits `from "key"` and `= expr` tails; body_lower_operation sets
them aside, and the capability arm wrapped that in the generic resource_entry_unread
at the whole capability. It now refuses with the owned fatal cause services use,
service_realization_unreachable, at the capability, with interface_member_unmodeled
pending at each tail. resource_entry_unread is reached only by a malformed entry.
Controls for both tail forms; main merged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…chable decline) (#12833)

* Changed-witness join counts DeclinedNoCiWetLane as a changed-witness disposition

gunbc#12794's decline pushed a disposition row, but the sublane's exactness join counted only
PlannedAsChangedWitness, so every declined selection refused as selected_without_disposition
(observed on gunbc#12741's floor, run 36768985832). The decline was unreachable by its route.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Execute the changed-witness join by a unit, decide its membership exhaustively, and file the class

changed_witness_sublane_join is extracted and driven with a DeclinedNoCiWetLane selection
(red on the pre-fix allow-list predicate with ChangedWitnessSublaneJoinInexact, green here);
decides_a_changed_selection is an exhaustive match, so a new disposition arm cannot compile
without stating its membership. Class filed as
gunbc.recurring_failure_mode.a_new_decision_arm_the_downstream_join_does_not_admit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Failure-mode row: say which evidence the merge path executes (review 73414)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM receipt: the join unit runs on no CI path (rust-unit-tests lane deleted 2026-09-29)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eforeDualRoleOperator), as the seed refuses it (PR2a, stacked on #12773) (#12881)

* WIP layout model: TokenStream source, named line-break derivation, RefuseOnMatch / AfterLineBreak grammar arms, controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout control: same tokens, different layout, different stream digests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout: derive a per-token line-break index once per stream; a layout question is a lookup (review 73189)

The gap question folded over the whole source per question: O(tokens x source). StreamLayout pairs
the source with a line-break-before answer for every token, derived in one walk over source and
tokens by its only constructor; a line feed inside a token is not layout. The digest reads the
source through the layout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout identity control parses against the warmed dag_prepared_grammar (floor budget: 97k steps vs 72.3k)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout identity control: a module that reaches no layout question (+, not -)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout: keep only line-break-preceded starts; digest covers layout by those, not by every character (floor budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* grammar: cite token_stream_line_break_before (stale symbol, review 73221)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: delete token_stream_source, no consumer after the layout rework (review 73234)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* StreamLayout: drop the unread source field (the source is read once, at lexing); digest renamed to what it covers

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* layout test: the digest covers layout, not source (comment)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: spell the tokenizer's source as v2.std.text.String (emit-build: emitted as host String)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* StreamLayout: one representation, start -> line of each line-break-preceded token (review 73282)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 parse: refuse a line-break-preceded '-' at the additive continuation (NewlineBeforeDualRoleOperator); controls, emit control, mutation witness

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Mutation witness: every live refusal arm is the newline refusal (the additive row is inlined, so arms > 1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout digest folded once in the layout walk; the parse table reads it (no lookup per token; floor budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: type the layout digest as Fnv1a64Structural, what combine_hash returns (emit-build)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Layout recorded in the tokenizer's own walk (no second pass over the source); value = the octet the gap begins

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* lexing: lexeme_has_line_feed takes v2.std.text.String (emit)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Newline controls: one data declaration each, same-line control parse-only (floor new-witness budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Newline mutation: supply the mutant grammar and the arm census as warm producers (no per-claim preparation); move to the floor

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Newline claims: one parse per mutant claim; drop the live-grammar duplicate of the controls; smaller block source (floor budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…irections) (#12878)

* dag target emit: model for reading dag_grammar_root backward (model before code)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* model: parse-tree subject ruling, core->surface frontier, quoted-key controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag target emit reads dag_grammar_root backward; delete the hand-authored type_decl grammar

v2.std.grammar grammar_emit_parse_tree inverts each GrammarExpr arm over the parse
tree, selecting productions by their stamp. v2.extdeps.languages.dag spells
terminals from the lex rules and from the int/float/string literal inverses (the
string encoder reads dag_string_escapes, the decoder's table). The type_decl
structural grammar and its round-trip test (a parallel authority) are deleted.
Round-trip controls: v2.test.execution.dag_grammar_backward_round_trip.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* round-trip red: read the refusal's NonEmptyDiagnostics through v2.std.fn_index non_empty_diagnostics_list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* round-trip module: rt_why_* probes report the refusing stage and reasons (not claims)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag emit: literal-payload refusals name the missing payload; rt_terminals_* probes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* dag emit: read literal payloads through the model's own readers (named_child_lookup is Conj-only); let/match fixtures use spellings main ingests, originals kept as a named frontier

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* round-trip probes: say first ingest vs re-ingest; candidate let/match spellings

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* round-trip fixtures: let/match spellings the first ingest admits; the refused spellings recorded as the overlap-residue frontier

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* plan doc: implemented; literal readers; emit text is token-spaced, not layout-faithful

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* round-trip fixtures: module paths avoid keywords; let..in and Bool-literal arms return as claims; frontier narrowed to let..in as a data value

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main; RFM dag_target_emits_only_its_fixture_row: parse-tree path climbs (receipts), row rung held at the core-route minimum

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Address review 73651: ambiguous projection edge refuses (grammar_emit_projection_ambiguous) with red + control; plan doc status, refusal names and step 2 corrected; RFM row names the instrument instead of transcribing results

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Emit cost: build the lexer once per emit, not per terminal; round-trip claims prepare the grammar once for both ingests

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Cost restructure (ruling A): data_decl real round trip is the floor inhabitance claim under a declared eval-step drop; per-construct real round trips run off-floor under a declared drop with a named instrument; dag_emit_interface claims the spelling and the stamp-selected key at their own interfaces, under budget

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Off-floor round trips become the named instrument //gunbc/instruments:dag-emit-real-grammar-round-trips (NativeClaimDriver program); its declared roster is the drop's population; the floor claim reuses the instrument's route

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Merge origin/main (#12773); emit walk handles RefuseOnMatch (never selected) and AfterLineBreak (yields a required line break the dag spelling writes as a newline); interface claims for both

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Roster the two dag-emit rung drops in gunbc.rung_drop.roster

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md (docs_projection_gate regen) for the two dag-emit drops

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM dag_target_emits_only_its_fixture_row: cite the interface claim and the instrument roster instead of the moved round-trip fn

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…entity from the prepared graph (#12890)

* Pure-producer warm holds one authority frame at a time, not every producer module's at once

Every producer module's frame (a claim scope over its closure) was built up front into a map and
held for the whole warm phase beside the prepared graph; freed together at the end, they left the
arena grown by their sum. WarmFrameSlot keeps at most one resident, dropped before the next is
built, with the same refusals; frame_builds is reported beside the phase.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm frames: admission reads node identity from the prepared graph; each pass groups rows by module and refuses a re-frame; warm checks frame lookup by pointer against the admitted node

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor warm: one [floor-warm-row] line per warmed producer, (producer, portable-value digest), for a producer-grain differential between runs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm: one module-grouped pass over acquisitions, carried rows and warms, so each module is framed exactly once for the whole warm (a re-frame refuses); a carried row reached before its acquisition refuses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm-row digest is run-invariant: record/variant fields sort by spelling and map entries by digest, since portable field order follows process interning order

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm frame slot reports frame build and drop wall, so the warm's wall cost is attributed by measurement

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm-row digest evidence: armed leaf-line dump of a warmed value for by-hand decode, and controls that the run-invariant digest is blind to entry order only and still discriminates leaf, key, entry, field and list-order changes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Warm-row digest evidence: armed leaf-line dump of a warmed value for by-hand decode, and controls that the run-invariant digest is blind to entry order only and still discriminates leaf, key, entry, field and list-order changes"

This reverts commit 78f7151.

* Revert "Warm-row digest is run-invariant: record/variant fields sort by spelling and map entries by digest, since portable field order follows process interning order"

This reverts commit 4b0cf22.

* Review 73645: the warm-row digest states it is run-comparable only over #12895's canonical encoding; the frames line reports builds beside the roster's in-subject modules from an independent source, and calls the rebuild refusal the wall

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor seams print the floor thread's CPU, so a phase's cost is attributable on a shared host

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Warm frames report index demand: per frame, the distinct names its rows looked up against the frame's index sizes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert "Warm frames report index demand: per frame, the distinct names its rows looked up against the frame's index sizes"

This reverts commit fa740fe.

* Warm frames: seed-growth receipt for WarmFrameSlot and the warm-row digest; the frame CPU residual as a resolver-cost frontier row, retired by the demand-sized frame over PR-2's declarer pool

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Review 73722: the one-pass warm orders modules by the carried-input dependency (topological, ties by row kind and name) and refuses a cross-module cycle, instead of by row kind alone

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…12860 reds, bisected to #12625 (#12909)

* WIP roster membership skips declared-order metadata

* WIP typed helper

* tpb_undeclared_t: re-state against #12566's counted UndecidableFormalUnresolved, with its discriminating twin

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* #12860 amendment: six identities leave (roster fix + tpb re-statement); two uncounted main reds join

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* infer: call v2.std.node arrow_signature_order_edge directly; delete the infer_arrow_signature_order_edge alias (review 73716)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ry binder_edge (XL-2 PR2b-2) (#12904)

* WIP 2b-2: node_query binder_edge, the one binder builder; production constructors through it

* WIP 2b-2: algebra_structure_signature, body_lowering_fold, dag fixtures, copied_port_citations through binder_edge

* WIP 2b-2: test binders through binder_edge

* WIP 2b-2: move misplaced binder_edge imports out of multi-line import blocks

* WIP 2b-2: import-free test modules keep implicit resolution (no added import)

* 2b-2 review 73698: route the mint (binder_relabelled) and the function-value authored binders through the builder; state the rung honestly

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e-ambiguous spellings refuse instead of electing the kernel arm (#12902)

* WIP v1 variant election: expected coproduct decides first; declared-scope tiers; revert #12791 exclusion

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: kernel tier binds only an unambiguous spelling; ambiguous kernel spelling refuses AmbiguousReference at the reference

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Controls for variant election by expected coproduct; compile-clean census specimens for TypeArgumentKindMismatch and TypeParameterInValuePosition

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Variant election: parse-safe forms (a comparison against a constructor before a block reads as a record literal)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Variant election: module-grain comment; typed kernel arm-owner fold

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rfm constructor_equality_consumes_the_branch_brace: receipt from the variant-election cut (respelled, and the reference-closure route drops the locus)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Variant election B: closure-wide tier kept as the stand-in; kernel never fills a closure-ambiguous spelling; Optional-cardinality expected decides Optional's arms

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerated v1_compiler_infer mirror for variant election B

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* rfm: bare_variant_elected_by_spelling_not_by_expected_coproduct

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerated v1_compiler_infer mirror after merging main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…error rule + KVM features seeding (#12874)

* fleet-converge: gate the reset-return dispatch admission on its own mode

The build job's admission step carried if_condition: none, so every mode's
dispatch paid a full gunbc run to reach ResetDispatchNotThisMode. It now
carries fleet_converge_host_reset_return_step_if, derived from the one mode
roster. The route witness asserts the gate.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fleet-converge witness: the admission step's gate must equal the reset job's gate

Drift between the admission step's mode condition and the consuming
host-reset-return job's condition would skip the observer refusal in the
one mode it applies to. Both derive from the roster; the witness now
asserts they stay equal.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Modeled operation realization: file transport arm + gunbc.filesystem_model

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Boot dry realization: environment, local/remote exact-invocation, remote host, wall clock models

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Witness the boot-world models' own semantics (calendar, backward step, remote request, coreutils formats, parent rule)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Boot world: expanded BMC model (override, SEL, SOL session, cycle restore), ipmitool observed-output rows, SOL collector/process table, SDR dump, SMpro, uptime, host console

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* MegaRAC media model + adapter; mtcollins1 boot acceptance matrix over the real entry (deadline refusal, pinned SOL-teardown defect, held-unit contender)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: media, observation, resource and interruption cases asserting each case's own cause; media withdrawal and SOL-drop events

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: rename the covering-grant binder and the matrix grant helper (UnimportedBareProvider on 'grant')

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix floor pricing (cost-debt admissions + declared eval-step drop); wall clock on std.measure carriers; seed-growth row covers the file arm

- Per eager-owl-205's ruling (msg_83af891b): the eleven matrix cases over the
  new-witness eval-step budget are typed cost-debt admissions
  (floor_cost_debt_admission mtcollins1_boot_matrix_typed_admissions, reason not
  reading) and members of a declared 4b(3) drop
  (gunbc.rung_drop mtcollins1_boot_matrix_new_witness_eval_step_cost, list
  floor_eval_step_cost_drop_boot_matrix_rows) whose restoration trigger is the
  natively emitted evaluation frame on the merge path. The two cases under the
  per-subject line are neither (a row there is stale).
- Review 72230: ModeledWallClock carries EpochSecs and a signed
  std.measure SecondDisplacement (new, beside CelsiusDelta/ArcsecondDisplacement).
- Seed-growth row names file_result_of_observation and the file/argv boundary.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Heal-Candidate-Run: 36427507942

* Matrix cost: bindings indexed once at admission, SOL drop armed by the host's boot (one attempt), stale cost-debt rows removed, drop population = the 8 over-budget cases, rung-drop projection regenerated

The first floor run showed every typed cost-debt row stale: the matrix cases sit
under the 500ms per-subject line, where such a row blocks. The honest fix is
cost, not a different exemption: operation_realization_index maps bindings by
identity once per frame (each of ~190 dispatches no longer scans the list), and
the SOL-loss case no longer pays a baseline attempt. Measured locally the
dearest case is now 220ms CPU (was 307ms on CI), under the 302ms enrolment
margin. OperationBoundTwice/BindingMatch deleted (unreachable: duplicates refuse
at admission).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Floor: import the map operations from v2.std.collection (map_lookup, the total form)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix cost: remember each frame's handler selections; advance does nothing when nothing is due

Measured on the deadline case (temporary instrumentation, reverted): the modeled
dispatch was ~110ms of ~243ms CPU, and handler selection ~60ms of that -- the
covering_grant fold re-derived per dispatch for ~15 distinct operations. The
selection reads only the operation identity and readonly flag besides frame-fixed
inputs, so the slot keeps each decided selection keyed by that complete identity.
The world advance short-circuits when no BMC event, media transition or console
line is due. Deadline case now 214ms local (was 307/284ms on CI runs).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: clock jumps and cd_error_code model parameters (not yet cased)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 media: a listing naming the image twice is its own typed cause with both identities, not invalid JSON (#12533 finding 5)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 boot: a presentation affirmed lost after a confirmed handoff is the attempt's named cause (#12533 finding 4)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 unit hold: a boot's hold names its process, and a successor recovers it only once that process is observed dead (#12533 finding 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* BMC model: an event a transition schedules is kept (power restore keeps its SOL drop)

#12423 side-chat review 5342387382: bmc_advance_pending rebuilt pending from its
own accumulator after each applied event, discarding events the transition had
just scheduled -- a power cycle's restore arming the after-boot SOL drop lost
that drop. The advance now fires the earliest due event from the world's own
pending list, applies it, and repeats on the world that transition produced.
New model control a_power_restore_keeps_the_sol_drop_it_schedules (ON host,
cycle at 0, restore at 5, drop at 35; quiet advances to 10 and to 40); it fails
on the previous fold.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: the duplicate-listing case asserts its own cause with both identities (finding 5 flips)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: a presentation lost after the handoff is the reported cause (finding 4 flips; identity renamed in its cost-drop row)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Dry world models the boot worker's procfs identity and its death; the interrupted case flips to recovery, with live and unobservable holder controls (finding 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: backward/forward wall-clock cases and cd_error_code cases over the real boot entry

Clock jumps (ModeledClockStep, a pure function of virtual time) inside the media
readiness wait: a backward step reaches the production ReadinessClockIncoherent
refusal; a forward step closes the window; neither makes a handoff.
cd_error_code: 16 with nothing presented (the 2026-09-27 state) refuses before the
handoff; with the host on, nothing is written; an error appearing with readiness
refuses; a stale lane image with 16 is replaced and booted when the stop clears the
code and refused after the replace when it does not (whether it clears is an
unobserved firmware fact, so both arms run); a foreign presented image is not
stopped. Six of the eight join the declared eval-step drop.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix the floor's refusals: optional list reads, the tag literal's process, callers of boot_run_owner; the held-unit case's other run is live in procfs

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* File arm refuses a pathless dispatch; modeled byte_count is a ByteSize of UTF-8 bytes

- Review 72311: a file operation dispatched without a string `path` is a
  harness fault, not an empty path fed to map_file_outputs.
- Review 72309 (relayed from #12554): FileOperationSucceeded.byte_count is a
  std.measure ByteSize, and gunbc.filesystem_model fills it with the UTF-8
  byte length (std.bytes utf8_encode_bytes, as std.materialization_object does),
  matching the realization's content.len(), not the code-point count. The
  dispatcher reads it through extdeps.transports.file file_observation_byte_count.
  Control: a_modeled_read_counts_utf8_bytes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: the lost-presentation case asserts the named cause wherever it appears in the reason, at either post-handoff look

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: move the live-holder note above its declaration (annotations are module-item grain)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Unit hold: the holder's identity carries its pid namespace; a missing pid is death only when read from that namespace, otherwise unobservable (review 72326)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Hold witness takes its report generation from an observation; the recovery cases (and the duplicate-listing case, now over by procfs reads) join the boot-matrix cost-drop roster, measured by floor run 36474912729

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: the held-unit case matches the owner's run id followed by its process identity, and asserts the holder was observed alive

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate the std.measure stage0 mirror for SecondDisplacement

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Cost-drop rationale matches its rows: the five #12555 members and why each exceeds the budget (review 72465)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Duplicate-listing arm in the two listing matches main's #12546 enumerated (enumeration decision: the ambiguity; presence: listed)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One Gregorian calendar: extdeps.units.iso8601 owns both directions (review 72483)

The wall-clock model re-derived civil-from-days and hard-coded 86400/3600/60 beside
extdeps.units.iso8601's own constants, while the roadmap reader carried a private
days_from_civil with the same literals. Both directions and the month-length rule now live in
extdeps.units.iso8601 over its constants; the reader and the wall-clock model import them. The
reader's witness gains a round trip (format then parse), so the two directions cannot drift apart
without a red.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wall_clock_model: name the reading helper wall_clock_printed (the floor's AmbiguousBareNameRead)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Name String's declarer: extdeps.systemd.journalctl and extdeps.units.iso8601 import std.string_type

The floor refused AmbiguousBareNameRead in gunbc.output_policy's scope: journalctl read String
through std.types, which declares nothing by that name, while std.string_type and v2.std.text
both declare it. The import now names the declarer, as the refusal's remedy says; iso8601, which
this PR grew, gets the same import.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: with_clock_jump takes the jump instant as a Second (review 72522)

It took an Int and returned the world unchanged when the Int was negative, so a mistyped
instant would have run the case with no jump. A Second cannot be negative, so there is no
arm to fall back through.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* iso8601 keeps String through std.types: it is in the stage0 closure (Stage0EmittedEdgesNotCovered)

extdeps.units.iso8601 is reached by std.measure, so it emits into the stage0 crate, which has no
partition row for std.string_type; importing it there refused the regeneration. The floor's one
ambiguous site was journalctl, which keeps its std.string_type import.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Calendar in extdeps.units.iso8601_calendar, off the compiler seed's closure

extdeps.units.iso8601 is imported by std.measure, so the calendar added to it (review 72483)
landed in the stage0 seed and the emitted v2 compiler: a stage0 mirror drift, Nat-as-Int casts
the native emitter cannot realize, and every std.measure consumer's claim scope widened into
bare-name ambiguities (String, then Unit, in journalctl). The calendar now lives in a sibling
module over the same constants, imported only by its two consumers; iso8601 and journalctl
are back to main's bytes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* journalctl names the declarers of String and Unit (floor AmbiguousBareNameRead)

The refusal is main's latent defect in extdeps.systemd.journalctl, which read String through
std.types (a re-export) and Unit bare; it surfaces in the claim scope this PR's touched modules
select. journalctl is outside the stage0 closure, so std.string_type is admissible there (the
earlier stage0 edge refusal was the calendar in iso8601, since moved).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rung-drop row: the route prefix is per-world, not a repeated computation (review 72549)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Six new matrix rows cite a measured run; rung-drop projection regenerated (reviews 72536, 72555)

measured_by now names claim_batch over tree 3639680 with each identity's eval_steps (73,949 to
130,890, all over the 72,300 new-witness budget, all PASS). docs/design-rung-drops.md is
regenerated by generated_artifact_gate main_wet rather than edited: the population lists the
fourteen identities and the trigger reads fourteen. Also merges session/swift-deer-358-pr2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap_served_observation names Filesystem's declarer (floor AmbiguousBareNameRead)

Its Filesystem.Read/Write are the extdeps.filesystem.filesystem_io service; std.resources also
declares the name. Main's latent defect, surfaced in the roadmap witness scope this PR edits.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rung-drop row: the shared world construction is measured, and owes no hoist (review 72606)

claim_batch: building the healthy world, its census console and the frame costs 1,687-3,793
eval steps against 78,317-119,267 per member; with it removed every member stays over 72,300.
The world is already a supplied value, which is the witness rule's remedy, not a derivation.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: bind #12434's SOL route; the two pinned SOL cases flip to controls

The dry realization now answers the route #12434 landed:
- processes carry a start time, visible as /proc/<pid>/stat (field 22) beside cmdline; ActivateHeld
  publishes "<pid> <starttime>", sends the grounded preamble's banner to the capture and its stderr
  to the client diagnostics, and a foreign session's refusal to the diagnostics;
- one exit transition (deactivate, session drop, ReleaseHeld) removes the /proc entry and records the
  supervisor's exit line; ReleaseHeld stops only the recorded instance;
- the notice watcher the step starts before the entry is scenario state (with_notice_watcher);
- shell.Move File is a rename in gunbc.filesystem_model; ipmitool mc info answers with the two
  fields the corpus read from this controller, its layout typed TranscribedUncited.

Flips: pinned_a_healthy_census_is_refused_at_the_sol_teardown ->
a_healthy_census_completes_and_releases_its_collector (ok; deactivate, ReleaseHeld, two retiring
deletes, all under the hold). pinned_a_sol_loss_mid_boot_is_reported_only_at_the_deadline ->
a_sol_loss_mid_boot_is_reported_before_the_deadline (typed ObservationChannelLost, incident frozen,
BMC answering, teardown within 60 s of power-on). The held-elsewhere case asserts the typed cause.

claim_batch, the merged tree: matrix, realization, model and filesystem witnesses 42/42 PASS. The
eval-step drop now covers nine members (the listing case crossed the budget on the longer route),
each row re-measured; docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: the SOL-loss case requires exactly one teardown, after the power action and within 60 s

At bd99cbb first_dispatch_second returned -1 when a dispatch was absent, so an absent teardown,
or one before the power action, satisfied the delta bound (side-chat hold on #12533). Both
instants are now Optional, the delay must exist and be nonnegative, and the route must carry
exactly one SolDeactivate after the power action.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix: six cases admitted to the enrolment dead band under one declared drop; two eval-step rows

Side-chat ruling (eager-owl-205, 2026-09-30): the six cases CI measured strictly above the 302 ms
enrolment margin and under the 500 ms line (396, 394, 378, 361, 339, 332 ms, run 36648847499) are
rostered in v2.workflow.floor_enrolment_dead_band, self-staling both ways, under the declared drop
gunbc.rung_drop.mtcollins1_boot_matrix_enrolment_dead_band_observed_only. Its population derives from
those rows, and its trigger names the one capability both matrix drops wait on, now a single row
(mtcollins1_boot_matrix_native_witness_capability) that the eval-step drop also reads. The CPU is
#12434's own polling route run faithfully; ablation found no model hotspot.

The eval-step drop gains the interrupted-attempt and wrong-share cases (74,419 and 77,423 on CI),
eleven rows. Rung-drop and enrolment witnesses 19/19 PASS; docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL establishment allowance is a monotonic deadline on /proc/uptime, not a count of polls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Integrate #12636: uptime answers over the file transport; one path resolution for wet and modeled

#12636 binds linux.Procfs ReadUptime to the file transport with its path as a literal in the
transport, not an input. The modeled file arm read the path from the inputs, a second and
narrower route to the fact the wet dispatch resolves from the transport, and refused every
matrix case at the uptime read. file_transport_path is now the one resolution both arms use
(rostered in gunbc.modeled_operation_realization_seed_growth), and the dry uptime handler answers
FileObserved with the record's final newline, the byte #12636 exists to keep.

Re-measured on the merged tree: 51/51 PASS. The interrupted-attempt case is back under 72,300
(70,000) and leaves the eval-step drop; ten rows, each at this tree. Rung-drop and enrolment
witnesses 19/19; docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SOL establishment: read the clock before admitting a banner, consume the pace result and refuse a stalled clock, keep the deadline a Millisecond (std.measure second_to_millisecond) (review 5360526125, review 73010)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire the stale unimported-bare-provider roster row for std/measure.dag#Time (ImportsFixed), which the touched-file gate now checks

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retire dag/std/measure.dag#Time from the unimported-bare-provider roster as NotAReference

The floor refused RosterStale: the file no longer carries the pair. measure.dag has imported Time
from extdeps.units.iso_80000_3 since 2026-09-05, before the roster was seeded on 2026-09-25, so the
file did not change; the seeding reader derived an imported name as unimported, and the parsed
reader (#12609) does not. That is NotAReference -- the READER changed -- not ImportsFixed, which
would claim a file change that did not happen. This PR surfaced it by touching measure.dag.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.measure second_to_millisecond at #12492's position with its regenerated stage0 mirror (byte-identical to #12492, so the two merge without a duplicate)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Eval-step drop: the interrupted-attempt case is back, at CI's 75,263

The floor's run 36661418914 measured it over 72,300 where a local claim_batch read 70,000; the
floor's figure decides membership. Eleven rows; docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SolEstablishmentClockStalled carries the uptime as a Millisecond, not a bare Nat (review 73135)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 KVM observer: log in through the context request client, not inside the UI root page

fleet-converge run 36721915217 refused the boot: the observer journalled
"page.evaluate: Execution context was destroyed, most likely because of a
navigation" and released as login-unobserved. It loaded "/" only to borrow an
origin and ran the session POST inside that document, which was replaced
under it.

The session POST, the services read and the session DELETE need a cookie jar,
not a page, so they now go through the browser context's request client. The
sessionStorage keys the viewer reads are seeded by a context init script. The
root page is never loaded; the only in-page evaluations left are on
viewer.html. No retry was added, and every typed refusal and journal word is
unchanged.

The loopback transport's root page now replaces itself on DOMContentLoaded,
and a new wet control asserts the login is seen and the root is never served.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1: read-only fleet-converge mode fetches the BMC's own UI bundle (source.min.js)

Operator decision msg_b3c77f62 (option A on escalation msg_13d5904d): a modeled read-only
route to the firmware's UI bundle, so vendor codes such as cd_error_code are read from
the vendor's source instead of escalated.

- extdeps.bmc.megarac: megarac.Ui.GetServedBundle (readonly, no session, bytes as served)
- gunbc.machine_intake_mtcollins1_ui_bundle_observe: mc info firmware revision first,
  refuse unless 0.32; fetch; sha256; report MATCH or DRIFT against the cited
  2026-09-27 read (never refuses on drift); receipt on every path
- fleet-converge mode mtcollins1_ui_bundle_observe: a mode row on the shared job,
  reusing the fan lane's credential prelude; bytes + receipt uploaded always()
- witness: revision parse, the 0.32/0.33 discriminating pair, unread revision, digest match/drift

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP (wind-down): supplied toolchain resolution, cwd-resolving filesystem model, hostname; KVM dry observer not yet built

State at the operator wind-down, NOT green:
- mtcollins1_boot_wet_on_srv1 is one call into mtcollins1_boot_on_srv1_resolving_toolchain, which takes
  the toolchain resolution as a function called where the observer starts (eager-owl-205 ruling A);
  the matrix supplies Ready/NotReady/Unresolved from production values.
- gunbc.filesystem_model resolves relative paths against a cwd lens; mkdir -p and realpath -e bound.
- os.Hostname.ReadShort answers srv1; the #12492 KVM wet witness world() builds through the constructors.
- OPEN: the Ready arm stops at gunbc.owned_process.launch LaunchOwned -- the dry KVM observer (owned
  process record, journal written through #12767's kvm_journal_line, triggers, stop) is not built,
  so 11 matrix cases fail; the NotReady/Unresolved cases and their no-launch assertions are not yet
  written; re-measure the drop rows after.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP: mtcollins1 boot: executing acceptance matrix over the real orchestrator

* Integration: fs_make_parents carries refused_reads (#12533 x #12555); drop the uncommitted-intent zz_probe scratch probes from #12533's WIP commit

* mtcollins1 boot matrix: dry KVM observer, toolchain NotReady/Unresolved cases, #12437 claim split, regenerated rung drops

(a) The dry world now answers gunbc.owned_process LaunchOwned for the KVM observer. It starts a
process visible in /proc with its "<pid> <start>" record at the pid path, and writes its journal
only through gunbc.machine_intake_mtcollins1_kvm_still kvm_journal_line: connection-requested,
connection-open, then established with the quoted host:port, session, attempt and gen. While live,
it answers each trigger file with a still, and on the stop file it journals stop-requested, session
release, browser close and stopped, then exits. A line kvm_journal_line refuses is a harness fault.
Still digests are supplied beside the bytes (the gunbc.remote_host_model precedent); sha256sum
answers only for those bytes. All 26 matrix cases PASS under claim_batch locally; at ec1b819,
without this binding, 22 returned false.

(b) a_toolchain_that_is_not_ready_... / an_unresolved_toolchain_...: no Mkdir, no LaunchOwned, no
power action, and the refusal names the toolchain's standing.

(c) The matrix now names the pairing claim that runs runner_browser_toolchain_here_wet for real:
mtcollins1_kvm_observer_protocol_wet_witness a_held_observer_is_admitted_and_its_triggered_still_is_hash_bound.

(e) #12437 (test-only) made the_build_job_carries_the_reset_observer_dispatch_admission build the
whole host-reset-return job to read its if. Both gates read fleet_converge_host_reset_return_step_if,
so the claim is split: the step side compares its gate to that datum, and
the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job side.

(f) docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet on the merged
tree; it wrote no other change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* #12800 floor: build-job membership drop (operator option 1), matrix cost rows re-cited from CI, dead-band/cost-debt reclassified, seed-growth cache named

(e) The workflow claim is three claims over three producers:
- the_reset_observer_dispatch_admission_step_carries_its_gate_entry_and_inputs holds the step's
  gate, entry and dispatch inputs over the step's own producer, under budget with no drop
  (claim_batch: 16,102 eval steps including shared fill);
- the_build_job_carries_the_reset_observer_dispatch_admission holds structural membership in the real
  fleet_converge_build_job_own_steps, and is the only claim that runs that producer;
- the_host_reset_return_job_is_gated_by_the_admissions_gate holds the job's side of the gate.
Only the membership claim is under the new declared drop
gunbc.rung_drop fleet_build_job_membership_new_witness_eval_step_cost (eager-owl-205, escalation
msg_00eaf0e6, option 1). Its trigger names the capability: fleet_workflow_steps constructs only the
steps a consumer demands. Its measured_by cites run 36765162766 (155,333 marginal) and run
36743802719 (174,583), and records that the cost predates gunbc#12437.

(d) Every matrix eval-step row now cites PR floor run 36765162766 at 6cac35e, and the two
toolchain arms join that list. The dead-band rows cite that run's CPU, and the stop-clears case
(473 ms) joins them. The interrupted-attempt case (523 ms, over the 500 ms line) leaves the band for a
typed cost-debt admission, as the band's self-staling rule requires.

v2.test.floor_enrolment_margin the_dead_band_authority_names_exactly_the_two_app_attest_claims went
false when gunbc#12533 added the matrix list, and was never re-planned. It now holds the App Attest
list at exactly its two claims, and the honoured identities at exactly the two declared lists.

Review 73376: gunbc.modeled_operation_realization_seed_growth names the per-frame
operation_handler_selection cache: its key, scope and retention. The ProcessArgvExpansion arm was
already covered, and dispatch_file exists on main.

docs/design-rung-drops.md regenerated by tools.generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Dry KVM observer: a pass that sees no new file neither scans nor takes an instant

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Drop gunbc#12795's UI-bundle mode from the integration (review 73415)

Reverts the integration of gunbc#12795 (merge 7393c8e): the megarac.Ui.GetServedBundle
operation, gunbc.machine_intake_mtcollins1_ui_bundle_observe and its witness, the
MtCollins1UiBundleObserve fleet-converge mode row and its ci_spec invoke, the 2026-09-27 bundle digest
row, and the fleet-converge.yml lines. Review 73415 found the mode's step is new string-concat shell
under a Scaffold whose own marker names the modeled route (v2.workflow.bash_emit), which is in use
today. The mode now lands only through eager-cat-463's lane, built on bash_emit nodes. Nothing else in
the tree referenced it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix dead band: the four cases that straddle the enrolment margin between runners

PR floor run 36775473983 at b907f7d (srv3) refused four matrix cases as measured over the
302 ms margin, at 303-318 ms. Run 36765162766 at 6cac35e (srv1) had admitted the same four at
276-290 ms, at identical eval_steps. This is the margin-straddle form of
gunbc.recurring_failure_mode enrolment_dead_band_has_no_representable_standing, which #12533 already
repaired: a dead-band row whose fast-runner reading lies in (envelope floor, margin] is
EnrolmentDeadBandWithinRunnerEnvelope, not stale. Each row cites both runs. docs/design-rung-drops.md
regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Matrix dead band: media_that_never_becomes_ready straddles the margin

PR floor run 36783312538 at 8042d17 (srv3) refused it at 320 ms against the 302 ms margin; run
36765162766 (srv1) admitted it at 283 ms, at identical eval_steps. It is the same straddle form as
the previous four. It was the only blocker on that run: 0 claims failed and 0 over-cost.
docs/design-rung-drops.md regenerated.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 media: a Started row is ready whatever cd_error_code says (vendor UI reads it only when stopped); the code is recorded, an unread code still withholds

Operator decision 2026-10-01 (boot-from-branch fast path). Grounded in the MegaRAC UI bundle source.min.js
sha256 5029fae2 (rmedia changeInSingleImages): error_code is consulted only at redirection_status 0 and
rendered as the stop reason (16 = Device Ejected). Stopped-row codes keep today's refusal; the per-code
table is the separate policy lane. Matrix and convergence witnesses re-asserted; the three matrix cases
that pinned '16 refuses' now assert the boot proceeds with the code recorded.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtcollins1 KVM viewer: seed sessionStorage.features from the firmware-0.32 row (minimum from #12830 for the boot)

Run 36788605665: the served viewer.min.js reads sessionStorage.features.indexOf(...) unguarded in
its KVM view's initialize(), so with features unset it throws and never opens /kvm.

- extdeps.bmc.megarac megarac_ui_features_0_32 (73 names), emitted by
  gunbc.machine_intake_megarac_ui_features megarac_ui_features_row_emit from the retained served
  source.min.js, refused unless it digests to the 2026-09-27 pin (row ported with it);
  megarac_ui_features(firmware) and the vendor storage shape; extdeps.tools.gzip for the decode.
- kvm_still: no row for the firmware -> not started; the launch writes features.json and the init
  script seeds sessionStorage.features; features-unreadable cause.
- loopback viewer reads sessionStorage.features.indexOf unguarded; enrolled wet red
  a_viewer_without_its_feature_list_never_opens_kvm; megarac_ui_features witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* boot dry realization: the observer's command carries the viewer feature-list operand (10 operands); establish only over a seeded list

The features port added a tenth operand; the dry worker read operands at a fixed count of 9 from the
end, so every observer launch read the wrong dir/host/attempt and the matrix's observed boots
failed. It now reads 10, and models the vendor viewer: without the feature list the launch wrote, the
observer journals a no-frame refusal and is never established.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* design-rung-drops.md: take main's projection per the generated-artifact repair route; heal regenerates it from the merged roster

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Boot matrix: the three full-boot cd_error cases move from the dead band to typed cost debt

Since the Started-row rule they boot instead of refusing at the handoff gate,
and at identical eval_steps they read 415-423 ms (run 36820943484) and
583-652 ms (run 36825466924): above the envelope floor on a fast runner and
above the per-subject line on a slow one, which only a typed cost-debt row
grounds (enrolment_dead_band_wrong_ground otherwise).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36831359503

* Delete PresentationStateUnestablished: the Started-row rule left it with no constructor (review 73648)

A Started row with a read cd_error_code is served whatever the code, so the
recheck has no unestablished answer; an unread code is PresentationUnobserved.
The recheck arm, both diagnostic-bundle texts and the witness import go with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_new_witness_eval_step_cost
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36846857547

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md mtcollins1_boot_matrix_enrolment_dead_band_observed_only
Heal-Candidate-Run: 36862331086

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Brian Searls <11205878+briansrls@users.noreply.github.com>
… text-only launch (#12906)

* V4.1 on SM120: 64-token SWA pages (overlay member + self-test member) and a text-only launch

Attempt 13 died on all four ranks in CUDA-graph capture with "SM120 sparse-MLA has no
decode kernel for this shape: num_tokens=8, num_heads=16, topk=1152, page_block_size=32".
Two independent refusals sit behind it, and neither is a combined window+indexer list
(vLLM's SM120 class already passes the window and the indexer picks as separate segments):

- page_block_size=32: vllm/models/deepseek_v4_1/attention.py constructs the SWA cache with
  the literal block_size=32; FlashInfer's SM120 DSv4 decode kernel takes 64-token pages only,
  and every call with <= 64 query tokens must take it. No engine argument reaches the literal,
  so it is an overlay member: swa_block_size class attribute, 64 on the SM120 FlashInfer class.
- topk=1152: the vision variant widens prefill SWA rows to window + vision_max_n_token.
  The launch now serves text only: --language-model-only --hf-overrides.vision_n_layers 0.
  The vision capability is dropped on purpose.

The self-test member creates vllm.models.deepseek_v4_1.nvidia.sm120_decode_shape_selftest.
Probe run 36857198484 (srv6/7/8, image sha256:0f6039eb...): unpatched FAILS in both modalities,
patched+multimodal FAILS at 1152, patched+text-only PASSES all four shapes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* engine_args: vllm_hf_override constructor; serving_arm builds the override through it (sole_constructor)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* V4.1 SM120 gate: the self-test runs on every rank's host over its own engine argv before staging

Review 73720: the self-test member had no executing consumer, and two of its figures were assumed.
- gunbc.spark.v41_group_a_launch v41_sm120_gate runs the image's
  vllm.models.deepseek_v4_1.nvidia.sm120_decode_shape_selftest on each rank's host with that rank's
  engine argv (checkpoint mounted read-only at the argv's model path) and stops the launch before the
  Engram staging on anything short of SELFTEST PASS; the gate's lines land in the receipt.
- The self-test now parses that argv with vLLM's own serve parser, and reads the packed bytes per token
  (FlashInfer _BPT_DSV4), the compressed pools' page (backend kernel block / each compress ratio), the
  local heads and the decode token ceiling off the installed tree.
- Witnesses: every rank's argv is text-only; the gate's argv is the rank's engine argv in its image.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* V4.1 SM120 gate: take the model path through enumerate, not the unimported bare get (floor UnimportedBareProvider)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* V4.1 SM120 gate: the optional model path's empty arm is none (if-branch typing)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d of re-reading it as raw parse (#12862)

* MQ-5 flip: body lowering refuses an unrecognised lowered shape instead of re-reading it as raw parse

At the nine readers that consult body_lower_is_core_substrate, and at the one caller of the
first-match descendant search, a non-atom node with children that the allowlist rejects and that
carries no grammar projection edge (lowered output no reader recognises) now refuses as
body_lowering_reason_unrecognised_lowered_shape, located at that node, instead of being re-read and
answered by a part of itself. Census (two native passes, control-verified, baseline identical) found
zero sites today, so no verdict changes. New RFM row
lowered_output_reread_as_raw_parse_at_v2_body_lowering; cause owned in
compile_door_cause_ownership. Next rung: producer-declared LoweredShape/BodyTerm (neat-boar-16 ruling).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM trigger names the capability: producers declare their shape and the predicate is deleted; staging stated

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM row: why a one-guard-alone mutation is not caught (overlapping guards are duplicated work the cut deletes)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Ask v2.compiler.parse parse_tree_projection_edge, the one roster of parse projection edges, instead of a second ten-label list (review 73534)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…at the install root with ldd readback (#12880)

* census QEMU PR2: job-user toolchain converge (pinned noble debs via dpkg-deb -x), observe retargeted to the install root with ldd readback

- extdeps.tools.ldd owns the ldd output parse (hoisted from runner_browser_toolchain, which now consumes it)
- extdeps.tools.dpkg_deb; extdeps.os.ubuntu_ports_archive UbuntuArchiveBinaryPackage, carried by the qemu and AAVMF rows
- gunbc.machine_intake_mtcollins1_census_qemu_toolchain: recipe-named root, verified fetch, staging + mv -T publish, env -i + LD_LIBRARY_PATH
- observe reads <root><packaged path>, adds the ldd library fact; ready requires every soname resolved
- new fleet-converge mode mtcollins1_census_qemu_toolchain_converge (host-bound)
- recurring failure mode: an unspawnable program aborts the run instead of refusing

Library set is empty pending the srv1 ldd reading (a host fact, not guessed).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* fleet-converge.yml: regenerate for mtcollins1_census_qemu_toolchain_converge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One staging procedure: StagedArchive + stage fold + publish move into gunbc.verified_archive_install; browser and census QEMU toolchains both consume it (review 73671)

- ArchiveExtraction gains ExtractDebData (dpkg-deb -x); archives kept at relative paths (pool paths for debs)
- runner_browser_toolchain: BrowserToolchainArchive/Extraction, stage_archive(s)_wet, all_staged, ArchivePlacement and texts deleted in favour of the shared ones; recipe text unchanged
- census QEMU: copied fold deleted; unconsumed census_qemu_placement_holds deleted
- witness: a .deb is fetched to its pool path and unpacked with dpkg-deb -x at the root

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…separate gunbc run measurement on main (#12921)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot and others added 26 commits October 3, 2026 04:40
…its on the fabric (#13052)

* roadmap: fabric-bringup parents vm-service and fabric-storage; SCM waits on the fabric

Operator rulings 2026-10-03 on the #12787 recut:
- new fabric-bringup project under gunbc-project-root; vm-service moves under it,
  beside a new fabric-storage program (DRAFT container, ruling 2026-10-02)
- the six SCM rows get parent factory (their only consumer is the daily
  workspace) and the four SCM roots take an edge on fabric-bringup, so they
  stay not-ready until the fabric is accepted
- no daily-workspace acceptance row (ongoing, never "done")

ROADMAP.md regenerated via generated_artifact_gate main_wet.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* roadmap: drop the in-body annotation in the edge list (module-item grain only, DESIGN §4c)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-0T ruling B) (#12512)

* Text crossings unfold or refuse: exact-representation text compat (XL-0T ruling B)

Kernel String is host text and a corpus-declared FreeMonoid<Char> is a
code-point sequence. One classifier, v1.compiler.coercion
text_representation_of_type (std.coercion TextRepresentation), is now read by
the corpus compatibility relation, call arguments, declared returns and data
initializers, builtin arguments (previously admitted untyped) and the Rust
renderer, so a pairing the checker admits is one the emitter realizes with
one carrier.

- A host value at a code-point-sequence call argument takes the Unicode
  scalar unfold as a typed node (scalar-string `chars`, typed as the
  destination), gated on the existing literal_homomorphism_rows
  UnicodeScalarSequenceUnfold row. Every other crossing refuses, located.
- Call arguments are typed against the declaration-bound formal, not the
  parameter spelling re-resolved in the caller: the caller-re-resolution
  escape of gunbc.rung_drop text_boundary_identity_wall is closed.
- 71 modules imported std.string_type { String } while treating the values
  as host text (a nickname); the imports are deleted. std.string_type keeps
  its two functions over the kernel String and loses its structural alias.
- A kernel spelling no longer resolves through the global bare fallback,
  which the deleted duplicate had been masking.
- string_eq over two host operands becomes == in five src/v2/lens modules;
  jq's host string_join becomes concat.

Evidence: test.claim.text_boundary_identity_wall_witness_test (16 rows) and
the flipped restoration probe in self_host_structural_text_witness_test.
Whole-corpus compile, base seed vs head seed over the same tree: 0 new
blocking rows, 4 removed. The drop stays Standing, narrowed to callable
values (eq: string_eq) with a restated trigger.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Import the HTTP method names the touched extdeps modules use bare

The unimported-bare-provider gate judges every file a change touches, and
deleting their std.string_type import touched these three.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep std.string_type's String as a frontier; order host text with `<`; fix two emit-classifier defects

Per neat-boar-16's ruling: `type String = FreeMonoid<Char>` in std.string_type
stays, annotated as a declared frontier with no importer, pending the seed
kernel-names ruling; the structural roster entry, the symbol-identity sibling
row and the defork census row are restored. Its two lexicographic functions
are deleted and their eight callers use host String `<` (rfc3339's three-way
match becomes `<`/`==` arms). A new interpreter control asserts that host
String order is code-point order on pairs a UTF-16 order would flip.

Two defects in the text classifier, found as 80 E0308 in the emitted
self-host compiler (emit-build):
- a qualified `v2.std.text.String` spelling took its last segment and fell
  into the bare-String arm, so fields rendered host `String`; a qualified
  spelling is now classified through its module;
- a bare String parameter in a module importing v2.std.text { String } was
  read through the by-name peel, which finds the imported alias; a declared
  host type now wins over the peeled views.
Each has an emission regression control. The emitted self-host crate is now
byte-identical to base's and builds.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Claim-scope ambiguity wall: a kernel spelling is never contested

AmbiguousBareNameRead counted a bare String as contested between
std.string_type and v2.std.text in the 39 modules whose std.string_type
import this change deleted. A kernel or container spelling binds the
substrate; the wall now reads is_substrate_vocabulary, the rule every other
bare-name producer already reads.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 36400142162

* Enroll a control for the kernel-spelling skip in the claim-scope ambiguity wall

Two claimants declare String, the reader uses String bare in a service exit
arm (the shape the floor refused in 39 extdeps modules). The head binary
accepts the scope; the base binary refuses it as AmbiguousBareNameRead.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Rename the namecheap test helper response -> namecheap_api_response

A top-level fn named response (from #12421) made the unimported-bare-provider
gate read every service declaration's response block as a bare use of it in
the extdeps files this PR touches.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Join host lexemes with the kernel join in the stage-verdicts test

symbol_list_text declares the kernel String (bare String beside an import of
v2.std.text { String }) and built it with v2.std.text string_join, a
code-point sequence; the text wall refuses that return. The consumer is host
concat, so the join is the host one.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* text_boundary_identity_wall: record the spelling-collision receipts

A user FreeMonoid record over a user Char admits host text on base and head
(container-template recognition by spelling), and the current classifier
fabricates admissions for a user List<Char>. The capability that closes the
first is named; the second is why the classifier is being re-keyed on
declaration identity.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Text wall keyed on declaration identity; unidentified sides fall through to base (WIP, paused)

Replaces the spelling-keyed classifier (review 72252) with
v1.compiler.infer_env text_representation_by_identity: host text is the
kernel String mint, a code-point sequence is std.algebra FreeMonoid over
std.types Char by declaration identity (through aliases; refinements have
their base's representation). Identity is read by declaring span, qualified
name, or the declaring module's own facts -- never by re-resolving a spelling
in the comparing site's scope. The relations carry the TypeEnv; the Rust
emitter keeps its base provenance-keyed answer (byte-identical crate).

Unidentified sides make no text verdict and base compatibility decides; each
such site emits the advisory TextRepresentationUnidentifiedAtBoundary, the
instrument for the restated drop (trigger: the resolver records declaration
identity on every type reference; staged as node://adhoc-207dd6ac-6d2).

Measured before the pause, against base 02360ee over the same tree:
whole corpus 0 new blocking, 1 base refusal admitted (the ruling-B unfold at
dag_arrow_lambda_witness_test:30); emitted self-host crate byte-identical;
text_boundary_identity_wall_witness_test 21/21; regen first_generation_equal.
NOT yet done: head-side base-vs-head claim comparison, and
docs/design-rung-drops.md is not regenerated for the edited row.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 36498270119

* Text crossing judgment is a coproduct, not an optional env (review 72427 finding 2)

node_type_compatible / node_type_equals / node_type_equals_core and the
index/slice access checks take TextJudgment = TextJudgedIn { env } |
TextNotAsked { reason }, so every call site that skips the text-identity
judgment names why (variant-field summary, callable-component residue,
synthetic witness nodes) instead of passing an absent env.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Text wall row states its current standing; renderer's text answer declared as a stall (review 72772)

- gunbc.rung_drop text_boundary_identity_wall opens with its current standing (identified
  crossings structurally guaranteed; two remaining populations: callable-signature crossings
  and the unidentified population). The 2026-08-30 declaration is kept as labelled history.
- gunbc.guarantee_stall text_carrier_render_not_keyed_on_identity_stall: the Rust renderer's
  provenance-keyed is_host_text_carrier_type is a second authority for 'is this host text'.
  Nothing fell, so it is a 4b(2) stall (current Mitigatable, ceiling StructurallyImpossible),
  with its population and a trigger that names the capability (render paths read the classifier
  through the env they were checked in, sufficient to delete it with no fallback arm).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* module_graph imports ends_with explicitly (floor UnimportedBareProvider)

This PR touches src/v2/lens/module_graph.dag, so the floor's changed-witness gate now reads it.
Its pre-existing bare ends_with read is refused because the file declares imports. Import it
from gunbc.rust_item_scan, the declaration the bare read binds to, as #12494 did for the same
refusal. Entry compile: 0 blocking.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Revert the gunbc.rust_item_scan ends_with import into v2.lens (layer inversion)

A gunbc tool must not provide names to v2.lens (wise-dove-693; the same refusal was ruled on #12526).
The agreed fix is clever-heron-784's PR deleting rust_item_scan's duplicate ends_with, so that the bare
read binds the host primitive. #12512 lands after it.

This reverts commit fa53159.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* One text crossing rule; wall comment states what it executes (review 73008)

- v1.compiler.infer_env text_representations_cross is the one TextRepresentation x TextRepresentation
  crossing rule; text_crossing_by_identity and the call-argument check both use it
  (04_infer text_representations_disagree deleted).
- 04_types comment no longer claims the wall refuses an unidentified side: base decides it,
  text_unjudged_advisories counts it, gunbc.rung_drop text_boundary_identity_wall bounds it.
- argument_text_representation drops its dead module_name parameter and the stale two-view prose.
Behaviour-identical to H: stage0 fixed point; self-host emit 0 files differ; the six wall/neighbour
claim files identical (102 PASS); text_boundary_identity_wall_witness_test 21/21, same names.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Declare the FreeSemigroup<Char> text crossing's second decider as a stall

gunbc.guarantee_stall free_semigroup_text_crossing_decided_by_spelling_stall: at FreeMonoid<Char> the
identity wall decides host-text crossings; at FreeSemigroup<Char> the classifier reads NotText, so the
spelling-keyed kernel_value_declared_type_mismatch (extended by #12695) decides. Both agree on every
fixture (wall 21/21, kernel_refinement_at_structured_parameter 8/8 on one binary). The trigger names
the capability: the classifier recognizes FreeSemigroup<Char>, so every such crossing is decided by
text_representations_cross and the base check's text case retires. guarantee_stall_witness_test 11/11.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Restore the substrate-vocabulary skip: it is not redundant

The previous commit deleted cli_run.rs claim_scope_for_with_memos' is_substrate_vocabulary skip on the
strength of bare_name_ambiguity_wall_witness_test passing 10/10 without it. That fixture file is
covered by main's exit-arm parse fix, but real corpus consumers are not: with the skip removed, the
required floor refused gunbc.output_policy (AmbiguousBareNameRead, String, 4 sites:
extdeps.cloudflare.account_api_tokens, extdeps.docker.container_inspect, extdeps.github.issues,
extdeps.github.pulls). The skip is restored, and its comment records why it stays.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 infer mirrors to the fixed point (claim_executor --required-regen, gunbc sha256 9c31f4a6…, rounds 1==2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs/design-rung-drops.md (docs_projection_gate regen, gunbc sha256 08f520bec5a7, srv1)

* Retire coreutils_stat/sha256sum #get bare-provider debt rows as ImportsFixed (floor RosterStale: #12910's collect_reference_sites no longer reports the pair in these PR-touched files)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate docs (docs_projection_gate regen on fce556f, srv1)

* Annotations: an unidentified text side is UNJUDGED by the wall, not refused (review 74123)

std.coercion TextRepresentationUnidentified and 04_infer's unfold note claimed a refusal the code
does not perform: text_representations_cross answers false for an unidentified side and
text_unjudged_advisories emits only the advisory, so base compatibility decides. Restated at the
true standing, bounded by gunbc.rung_drop text_boundary_identity_wall and its trigger. Annotation-only
(DESIGN 4c): no semantic or generated-byte change.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 infer mirrors to the fixed point after the main merge (claim_executor --required-regen, claim_executor sha256 c6d38a43…, rounds 1==2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: neat-boar-16 <briansrls@gmail.com>
…ecursor) (#13033)

* v2: carry the type-declaration modifier slot (nominal_opaque, sole_constructor) on NormalizedTree

The slot was consumed by G0 and minted nothing, so no reader of a lowered declaration could tell
`type X nominal_opaque = Y` from `type X = Y`. Precursor to M0 of the nominal-type plan
(gunbc#13024): the census's Opaque class is unobservable without it.

- v2.compiler.body_lowering_fold: closed vocabulary TypeDeclModifier and a positional reader of
  the slot off the parse (body_lower_type_decl_declared_modifiers); an unreadable slot refuses,
  located, never read as empty.
- v2.compiler.normalize: type_declaration_modifier_capture, carried on NormalizedTree
  type_declaration_modifiers beside type_declaration_kinds; admit_normalized_tree takes it.
- Control: v2.test.parse.type_decl_modifier_carrier (carries / does not / slot order / spelling as
  a name / real normalize route). Unknown spellings stay refused at parse by the existing probe.
- gunbc.rung_drop g0_type_decl_modifier_parse_without_sealing_property narrowed, not retired:
  carrying enforces nothing, and its trigger is the construction wall.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Slot reader: exhaustive arms over NodeKind/Connective, no wildcard (floor NonFoldResidueRosterDiverged)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Pairing claim: bodyless fixture so the real normalize route fits the new-witness step budget (84854 > 72300 with an alias rhs)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Enroll body_lowering_fixture_resolves as expected-red: red on main (unkeyed lexical refs in a hand-built fixture), first selected by this PR's call-site edit

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Fix the add fixture instead of enrolling it: operand references carry minted occurrences (resolve keys lexical bindings by occurrence)

Drops the floor_expected_red row added in 588c329 (which also broke that file's parse).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md g0_type_decl_modifier_parse_without_sealing_property
Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci
Heal-Candidate-Run: 37090292139

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
… marked advisory (#13005)

* native route: name each refused file; fatal cause leads, head printed as advisory

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refusal summary: group fatal causes by map, not a per-row linear scan

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* seed growth: justify native_file_refusal_summary (gunbc.native_route_refusal_summary_seed_growth)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refusal summary control: every supplied file exactly once, with dropped-b and doubled-a mutations

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci
Heal-Candidate-Run: 37088706855

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
…n row (#13063)

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s not-predicate guards (#13036)

* v2 parse: choice-overlap proof reads k=2 lookahead and proves not-predicate guards

A FIRST-overlap row is now removed only when the declared lookahead
(k=2) proves the alternatives disjoint. A leading not-predicate subtracts
the prefixes it is proved to cover, and only when the guard is plain (a
finite token-string set whose PEG success is membership). A guard naming
one word of a class narrows that position to class-less-word (the k=1
op_requires shape). Every undecidable arm keeps the row.

Roster 51 -> 48: stmt return-vs-bare-assignment, let_expr let-vs-bare,
let_sugar node-vs-bare are disjoint at k=2.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* choice_plan_test: import LiveTreeDisposition and SubstrateInputsOnly; retire its debt row

Touching the file put its bare references under the unimported-provider
gate. Both names are now imported, so the SubstrateInputsOnly row moves
ActiveDebt -> Retired { ImportsFixed }.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 parse lookahead: a guard also refuses the other side's covered prefix; no wildcard arms

The ruling's direction: a pair of prefixes is disjoint when one side's
prefix is covered by the other side's proved-plain guard, whatever length
the guarded side's own prefix has (name: e | !(name :) e, whose positional
side can be one token). Guards ride the prefixes they head and survive
extension. The three GrammarExpr matches are written out arm by arm
(NonFoldResidueRosterDiverged). Two controls added for the short-side case.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 parse lookahead: a site is read as deep as its own longest proved guard (base 2, cap 3)

Every candidate site is read at depth 2; one that still overlaps is read
again only as deep as its longest proved-plain leading guard, capped at
3. Measured on the dag grammar: a global k=3 tripled the roster run
(114s -> 371s); guard-driven depth costs 138s. Controls: a three-token
guard clears its row at its own depth; the near miss keeps it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…es instead of recomputing (#13070)

* std.cache_interface: timed release is retention, a rejected hit refuses

ReleasePolicy gains ReleasedAfterInterval { after_write } -- an object lifecycle
rule or artifact retention period reclaims the entry, after which a lookup is an
established Miss. It is distinct from InvalidationTrigger TtlExpiry (freshness).

realize_route no longer recomputes over every rejected hit: only FreshnessExpired
(a declared invalidation) recomputes; integrity and availability rejections
refuse, so a corrupt or unreachable store is never absorbed by a rebuild.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* artifact_store: refuse a timed-release provider (control)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* realize_kernel witness: exhaustive match on the refuse arm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d projection inference stops calling an unretrievable declaration a fieldless receiver (#12506)

* docs/plans: arrow elimination model for v2 infer (for ruling)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 infer: arrow elimination and the body/declared-return check; one Int and one Bool value type

An application of a derived Arrow now takes the type the Arrow declares it returns (read
from the return atom as written), and a bodied Arrow is admitted only when its body's type
equals that return, else arrow_body_does_not_inhabit_declared_return. Before this, no
application derived, Int included, and eval refused both Int and Bool applications.

dag_binding_denotation is the one binding->value-type join, and its rows point at
v2.std.integer integer_int_type_node and v2.std.logic bool_node. The literal rules consume
it, a type-name atom derives its kind (TypeDenotationKind), and the evaluator's own Int and
Bool type nodes are replaced by the same authorities. Model and ruling are in
docs/plans/arrow-elimination-model.md; the composed-evidence defect is filed as
function_type_evidence_carries_its_body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* infer_product_introduction: evidence control pins the Int type atom's kind, not the retired inhabitant denotation

The parameter conj's composed evidence carries each Int type atom's derived grounding.
After the arrow-elimination ruling that grounding is the atom's kind (TypeDenotationKind);
the control still asserted the roster's Int inhabitant record, the denotation this PR retired.
Found by the srv1 base-vs-head run over the v2 infer/eval/compile test modules
(the one true->false). The partial-evidence control's use of the inhabitant node as a
roster member is unrelated and unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Take infer's ObligatedInferredTree through discharge; flip refinement_discharge to holds/violated; one runtime encoding of true

- infer_arrow_elimination eval control: after the merge of main (#12375) infer returns
  ObligatedInferredTree, so the control reaches eval through
  discharge_refinement_obligations, the only route to an InferredTree.
- refinement_discharge's frontier row flips as it said it would: a true predicate admits,
  a false one refuses refinement_predicate_violated. The undischargeable arm is kept
  over a genuinely unevaluable application (an undenoted return).
- The flip exposed two runtime encodings of true: v2_eval_bool_true_primitive was a one-bit
  byte while every evaluated Bool is built by v2_eval_bool_runtime_value (eight bits), so
  discharge read an evaluated true as violated. The primitive is now that constructor's value.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 resolve: ResolvedTree carries the SymbolIndex resolution consulted; cut every consumer root-first

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* pick_ingested: the arrow extractor returns the arrow Node (my retype over-reached)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* A reference to a corpus declaration is typed by that declaration

THE GAP. v2.compiler.infer's infer_node_facts routes a declaration reference --
Conj-shaped, so infer_atom_binding_sym answers Absent -- straight to
inferred_facts_not_derived. An entry IS admitted for the node and its grounding is
GroundingNotDerived, so inference ACCEPTS the tree and eval refuses later at
whatever consumes it. Nothing typed a reference to a function.

THE REPAIR, IN ONE ARM. Resolution answers WHICH declaration a reference denotes
and carries it as a declaring path; this arm answers WHAT TYPE that declaration
establishes for the use. Two questions, two stages: nothing here re-resolves a
name and resolution mints no types.

  declaration_reference_path_optional(n)           the declaring path, never the leaf
  symbol_index_lookup(resolved.symbol_index, path) the GUARDED read: a path with
                                                   more than one bound declaring
                                                   answers Absent, so a contested
                                                   binding cannot yield a type
  arrow_domain_binder_labels(declared.children)    evidence check
  inferred_facts_from_derived_type(n, declared)    evidence attached to the USE

A LOOKUP HIT IS NOT TYPE EVIDENCE. The index is built from validated normalized
roots, which does not establish that every indexed declaration carries usable type
evidence, so this arm does not ground on presence. A callable's evidence is its
Arrow and the check is that its domain reads; an unsupported or unresolved
signature stays explicitly ungrounded. Non-callable declarations are left to their
own derivation rather than stamped.

THE EVIDENCE ATTACHES TO THE USE. derived_type is the DECLARATION's node while the
entry is keyed by the REFERENCE node, so the use keeps its own occurrence and
locus and canonical_grounding_from_derived_type's self-evidence refusal still
holds.

THE CARRIER IS #12432's, CONSUMED NOT REBUILT. ResolvedTree { root, symbol_index }
already reaches fn infer(tree: ResolvedTree); it was never threaded past there --
symbol_index appeared exactly once in 04_infer.dag, in a comment. The thread is
`resolved: ResolvedTree` under a NEW name at every site, not a second
`index: SymbolIndex` parameter: passing root and index side by side lets them come
from different trees and disagree, and nothing would stop it, while the paired
carrier makes the mismatch unwritable (DESIGN section 5, construction over
validation). Functions that want the root read resolved.root.

ELEVEN FUNCTIONS, NOT THE SIX ESTIMATED. The compiler found the other five --
infer_gather_transform_row_on_entries, infer_gather_application_row_on_entries,
infer_gather_bind_annotation_row_on_entries, infer_gather_fold_step_merged,
infer_gather_settled_row -- which is the argument for renaming at every site
rather than adding a parallel parameter. Non-path callees keep `tree: Node` and
receive resolved.root, so their contracts are untouched. The thread landed first
as a 41/41 behaviour-neutral change, verified by the regression guards passing
with the control still red, so any guard breakage would be attributable to the
derivation rather than the rename.

PARAMETER TYPING IS NOT REPLACED. infer_parameter_scope_search /
infer_parameter_type_in_scope stay. Their comment names "the SymbolIndex /
ResolvedTree.bindings lookup" as their dissolution trigger, and it is tempting to
read this change as that trigger; it is not. A local use resolves to a canonical
Atom at its own occurrence and never acquires a declaring path, so the index
answers a different question. What was established here is only that
symbol_index_fill puts Arrow DOMAINS in the index -- a fact about fill, not about
what a parameter use resolves to. Deleting the walk on that basis would have
reintroduced the defect its comment records: `fn positive(x: Int)` beside
`fn f(x: Pos)` grounding every `x` in `f` as Int.

EVIDENCE.
  dre_a_reference_grounds_to_its_declarations_contract_holds  FAIL -> PASS
  bcn_cast_into_a_refinement_refuses_at_infer                 PASS unchanged
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening  PASS unchanged
  bcn_identity_cast_into_a_refinement_admits                  PASS unchanged

The control asserts the CONTRACT, not the grounding tag: it selects every node
whose decoded declaring path ends in the wanted leaf, requires EXACTLY ONE, and
requires the derived type's Arrow domain to bind exactly the name the fixture
text specifies. A DerivedGrounding carrying the wrong type fails it.

NOT QUALIFIED, STATED AS SUCH. dre_a_same_leaf_reference_gets_its_own_declarations
_contract_holds passes but is NOT yet an identity-collapse detector. The forced-
collapse mutation turned BOTH controls red rather than only the same-leaf one,
because the mutation's path does not exist in the first fixture either -- it broke
everything instead of specifically collapsing identity. Within a single-module
fixture the discriminating case cannot be built: a reference that reaches this arm
denotes a module-level callable whose declaring path IS [module, leaf], so path
and leaf coincide. Qualifying it needs a two-module fixture where each module
declares the same leaf. Until that runs, this control is specified, not qualified.

NOT DONE HERE. The application connection (#12379's rule wants a callee Arrow, and
a reference now grounds to one) and the s3 end-to-end assertion are the next step,
and the outer equality may still lack a typing rule of its own.

Based on #12432 (ResolvedTree carrier) and #12379 (application-result typing);
rebases onto #12379, which lands first.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The reference's guard becomes the one an application will ask

MY COMMENT CLAIMED MORE THAN MY GUARD CHECKED. The arm grounded a reference when
arrow_domain_binder_labels could read the declaration's parameter names, and the
comment beside it said an unsupported or unresolved signature stayed ungrounded.
That was false of the guard. That reader takes only `children`, so it never
establishes the declaration IS an Arrow, and it inspects no parameter type, no
return type, no scope and no body. "I can read the parameter names" is a different
property from "this declaration establishes this callable type", and the comment
asserted the second while the code checked the first -- rung inflation in the
annotation, caught in review rather than by a control, because no control
distinguished the two.

THE GUARD IS NOW THE APPLICATION PATH'S OWN REQUIREMENTS, reused rather than
restated: infer_operator_arrow (the node IS an Arrow), infer_formals_from_domain
(every formal is named), and arrow_declared_parameter_order, where both Absent and
Malformed refuse -- the domain is sorted by label for identity, so its stored
sequence is not the declared order and an Arrow without the order edge is one a
binder already refuses. Grounding a reference whose declaration cannot satisfy
those would mint evidence no consumer can use.

WHAT IT STILL DOES NOT ESTABLISH, stated rather than implied: the type references
inside that signature are not resolved in the declaration's scope here, and no body
or return obligation is discharged. Those stay with the existing inference
contract; a reference consuming a declared signature does not recheck a body at
every use. The claim is the structural callable contract and nothing wider.

Controls unchanged in outcome and now discriminating for the right reason:
  dre_a_reference_grounds_to_its_declarations_contract_holds        PASS
  dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds PASS
  bcn_cast_into_a_refinement_refuses_at_infer                      PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening        PASS
  bcn_identity_cast_into_a_refinement_admits                       PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The same-leaf discriminator is not qualified, and the file says so

FIVE ATTEMPTS, NO DISCRIMINATING CONTROL. A single-module fixture cannot produce
one: a reference reaching this arm denotes a module-level callable whose declaring
path IS [module, leaf], so path and leaf coincide and a leaf-keyed lookup is
accidentally right. A two-module fixture reaches the right shape -- two modules
each declaring `shared(alpha: ...)` with different types, the consumer importing
one -- but the assertion needs the parameter's declared TYPE read out of the
derived Arrow's domain, and neither a walk-order atom search nor find_named_child
on the domain produced it. The control stayed GREEN under a mutation that forced
the wrong declaration, and then went RED on correct code once the reader changed:
both arms wrong, so it distinguished nothing.

A green control that does not discriminate is worse than no control, because it
would be cited as coverage. A red one blocks the PR while asserting nothing. So
neither ships; the gap is recorded where the control would have been.

WHAT IS THEREFORE NOT CLAIMED: that this arm resists declaration-identity
collapse. The declaring path is what it looks up and symbol_index_lookup is the
guarded read, but no executed control here demonstrates that a leaf-keyed answer
would be caught. Qualifying it needs a reliable reader for a parameter's declared
type inside a derived Arrow domain; that reader is the missing piece.

Retained and passing: the two controls that do discriminate their own properties,
and the three refinement guards.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The application path can now see a reference's callable evidence; it still is not enough

THE CONNECTION WAS ABSENT IN CODE, not merely unmeasured.
infer_application_callee_arrow read the callee EXPRESSION's own kind through
infer_operator_arrow, and a resolved declaration reference stays a Conj however
well typed it is -- so the helper answered Absent for it and every consumer
(formals, type parameters, argument inhabitance, result typing) fell through to
the undecidable-accepted arm. Giving the reference callable facts did not make any
of them read those facts. Adding evidence and consuming evidence are two changes
and only the first had landed.

infer_application_callee_arrow_with_facts falls back to the callee's own facts
entry when the node is not itself an Arrow, taking ONLY the type from
DerivedGrounding's structural evidence. The use keeps its node and occurrence; the
declaration's body and identity are not substituted. Wired at the three sites that
asked the old helper, with entries threaded into infer_application_formals and
infer_application_type_params -- the other two callers already carried entries.

NECESSARY, NOT SUFFICIENT, AND THE CONTROL SAYS SO. A named call still does not
ground. dre_a_named_call_is_grounded_expected_red is enrolled as an executed
expected-red rather than a passing claim or a deleted one: the boundary is real,
its cause is not yet identified, and naming it is the next step rather than
widening the reader until something goes green. What is missing between a
grounded callee and a grounded application is unestablished -- I did not
determine whether the call's facts entry is absent or present-and-ungrounded, and
that distinction picks the repair.

Guards unchanged, including the two application-typing rows:
  bcn_cast_into_a_refinement_refuses_at_infer                 PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening  PASS
  bcn_identity_cast_into_a_refinement_admits                  PASS
  bcn_infer_admits_int_to_int                                 PASS
  bcn_infer_refuses_int_to_bool                               PASS
  dre_a_reference_grounds_to_its_declarations_contract_holds   PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A named call grounds: the use carries the facts, the arrow carries the type

THE REMAINING FAILURE WAS ONE MISKEYED LOOKUP. After the application path could SEE
a reference's callable evidence, the call still did not ground, and the cause was
in infer_transform_application_optional:

  match infer_application_callee_arrow_with_facts(...) {
    Present { value: arrow } =>
      match lookup_inferred_facts_in_entries(entries: entries, key: arrow) {

That key is right only while an arrow can be the callee node itself. Once the arrow
may be a DECLARATION's Arrow reached through the use's facts, it is a node of the
declaring module with no entry in this tree, so the lookup answered Absent and the
application dropped to the frontier however well the callee was typed. The grounding
question is about the CALLEE USE; the arrow supplies only the TYPE. They are two
things and only the first has facts here. infer_application_callee_use names the
first; the second stays what it was.

dre_a_named_call_is_grounded_holds goes from an enrolled expected-red to a passing
claim on that one change.

A BOOL-RETURNING CALL STILL DOES NOT GROUND, AND IT IS A DIFFERENT BOUNDARY.
Measured three ways on this base: an Int-returning call grounds; a Bool-returning
call with a literal body does not; a Bool-returning call whose body is its own
parameter does not either. The variable is the RETURN TYPE, not the body, and the
reference itself grounds in every one of the three -- so this sits downstream of the
reference repair, in the application's return derivation,
infer_arrow_declared_return_type -> dag_binding_denotation. Enrolled as an executed
expected-red rather than deleted or chased: which binding symbol a Bool return
actually carries is the next question and answering it is a separate change.

THE EXECUTION CONTROL IS DELIBERATELY BOOL-RETURNING, which is why the boundary
surfaced here rather than later: an Int-returning call compared with `==` would have
coupled the first execution proof to equality, which has its own unproven typing.

Guards unchanged, including both application-typing rows:
  bcn_cast_into_a_refinement_refuses_at_infer                 PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening  PASS
  bcn_identity_cast_into_a_refinement_admits                  PASS
  bcn_infer_admits_int_to_int                                 PASS
  bcn_infer_refuses_int_to_bool                               PASS
  dre_a_reference_grounds_to_its_declarations_contract_holds   PASS
  dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A return that is already a type is consumed, not denoted again

INT MASKED THE READER'S ASSUMPTION AND BOOL EXPOSED IT.
infer_arrow_declared_return_type sent every return Atom's identity to
dag_binding_denotation, which is a BINDING-to-type operation. Int survives that
because its canonical type constructor retains the historical spelling
^dag_binding_type_int, so its binding and type identities coincide and a second
denotation is a no-op. Bool arrives as the DENOTED node -- v2.std.logic bool_node,
^bool_node_symbol -- so the binding lookup answered Absent and BOTH consumers of
this shared reader lost the return: application result typing dropped to the
frontier, and the body-versus-declared-return check skipped its comparison.

MEASURED BEFORE REPAIRING. An Int-returning call grounds; a Bool-returning call with
a literal body does not; a Bool-returning call whose body is its own parameter does
not either. The reference itself grounds in all three, so the variable is the RETURN
TYPE and not the body. The return atom was then read directly: Int carries
^dag_binding_type_int, Bool carries ^bool_node_symbol.

THE REPAIR RECOGNISES BY AUTHORITY, NOT BY SPELLING. The established case is
compared against v2.std.logic's own bool_node() through the existing structural
equality, rather than teaching a second meaning for ^bool_node_symbol here or
widening dag_binding_denotation to accept a denoted symbol -- that lookup stays
strictly binding-to-type, so a specimen fix does not become a muddied contract.
Ordered denotation-first, so the Int path is byte-identical and only a return the
binding lookup cannot denote reaches the established-type question. ONE reader, so
introduction and elimination cannot disagree about the same signature.

dre_a_named_call_to_a_bool_fn_is_grounded_holds: expected-red -> PASS.

THE MISMATCH NEGATIVES ARE RED, AND THAT IS PRE-EXISTING, NOT INTRODUCED. infer
ACCEPTS a Bool-declared function with an Int body and the converse. The cause is
upstream of this reader: infer_arrow_body_inhabits_declared_return is only reached
when the Arrow carries evidence edges; without them the arm answers
inferred_facts_not_derived, and a frontier is not a refusal, so the comparison never
runs. Verified by reverting ONLY the return reader and re-running -- both rows fail
identically. Enrolled as executed expected-reds rather than deleted: they are
exactly the controls that would catch a return recognition which admitted nodes
without activating the check, they cannot discharge that duty while the check is
unreachable, and when the evidence-edge condition is repaired they become its guard
without anyone rediscovering the shape.

The eight input-inspection diagnostics that located this are removed; their results
are recorded above rather than left as permanent obligations.

Guards unchanged:
  bcn_cast_into_a_refinement_refuses_at_infer                 PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening  PASS
  bcn_identity_cast_into_a_refinement_admits                  PASS
  bcn_infer_admits_int_to_int                                 PASS
  bcn_infer_refuses_int_to_bool                               PASS
  dre_a_reference_grounds_to_its_declarations_contract_holds   PASS
  dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds PASS
  dre_a_named_call_is_grounded_holds                          PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The body/return check becomes reachable, so a return mismatch refuses again

THE PREREQUISITE WAS THE RETURN ATOM'S OWN GROUNDING, not the check.
infer_arrow_body_inhabits_declared_return runs only when
infer_product_child_evidence_edges answers Present, and that collector requires
EVERY Arrow child to carry a resolved type. A Bool return atom carried none, so the
whole Arrow dropped to inferred_facts_not_derived -- the frontier -- and the
comparison never ran. A frontier is not a refusal, which is why a Bool-declared
function with an Int body was ACCEPTED rather than reported.

So the same defect had two faces: the reader could not denote an already-denoted
return (fixed in 53022c28ca8), and infer_node_facts could not ground one either.
Both are the same assumption -- that a type-position Atom is a binding awaiting
denotation -- and Int masked both because its binding and type identities coincide.

THE SECOND HALF, BY THE SAME AUTHORITY. The denotation arm of infer_node_facts now
consults infer_established_return_type_optional, which compares against
v2.std.logic's own bool_node() through the existing structural equality. One
recognition, reused; no second meaning for ^bool_node_symbol, and
dag_binding_denotation still stays strictly binding-to-type. Ordered after the
binding lookup, so every previously-denoted path is byte-identical.

UNAVAILABLE EVIDENCE DID NOT BECOME A PASSED CHECK. The repair makes the return
atom GROUND, which makes the check RUN, which makes the mismatch REFUSE. Nothing
was forced to ground to get there and no refusal was weakened: the two controls
went from ACCEPTED (wrongly) to REFUSED (correctly), which is the opposite
direction from admitting more nodes.

  dre_a_bool_declared_int_body_still_refuses_holds   expected-red -> PASS
  dre_an_int_declared_bool_body_still_refuses_holds  expected-red -> PASS

Reference typing, application typing and the return derivation stay connected:
  dre_a_reference_grounds_to_its_declarations_contract_holds        PASS
  dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds PASS
  dre_a_named_call_is_grounded_holds                               PASS
  dre_a_named_call_to_a_bool_fn_is_grounded_holds                  PASS
  bcn_cast_into_a_refinement_refuses_at_infer                      PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening       PASS
  bcn_identity_cast_into_a_refinement_admits                       PASS
  bcn_infer_admits_int_to_int                                      PASS
  bcn_infer_refuses_int_to_bool                                    PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The qualification set: identity discriminated, unavailable evidence refused

FOUR CONTROLS, BATCHED ON THE PINNED BASE.

  dre_an_unresolved_signature_does_not_ground_holds        PASS
  dre_an_invalid_argument_call_does_not_ground_holds       PASS
  dre_an_imported_reference_grounds_the_same_way_holds     PASS
  (with the two mismatch negatives promoted in 5359640d5bb)

UNAVAILABLE EVIDENCE DOES NOT BECOME A PASSED CHECK. A signature whose parameter
type names nothing reads structurally and means nothing: the shape is readable, the
evidence is not, and the reference stays underived. That is the control a permissive
fallback would have turned green, and it is the one that keeps
infer_declaration_callable_evidence honest about what "callable evidence" claims.

AN INVALID ARGUMENT DOES NOT GROUND THE CALL. A Bool passed where the declared
parameter is Int leaves the application ungrounded, so the contract is not satisfied
merely because the callee's type was found.

THE IDENTITY DISCRIMINATOR IS NOW QUALIFIED, and by the mutation that the earlier
five attempts could not construct. Those attempts failed because a single-module
fixture cannot separate path from leaf -- a module-level callable's declaring path IS
[module, leaf]. Across two modules it separates: repointing the imported reference's
lookup at a DIFFERENT EXISTING declaration (m.app rather than m.lib.helper, so the
lookup still SUCCEEDS) turns that row red while the same-module call stays green.
That is wrong-declaration selection being detected, which an absent-path mutation
could never establish -- it tests missing evidence instead.

So the claim this PR would not make three commits ago is now made on executed
evidence: the arm resists declaration-identity collapse.

Full set on the pinned base 80e9a04a5ed:
  dre_a_reference_grounds_to_its_declarations_contract_holds        PASS
  dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds PASS
  dre_a_named_call_is_grounded_holds                               PASS
  dre_a_named_call_to_a_bool_fn_is_grounded_holds                  PASS
  dre_a_bool_declared_int_body_still_refuses_holds                 PASS
  dre_an_int_declared_bool_body_still_refuses_holds                PASS
  dre_an_unresolved_signature_does_not_ground_holds                PASS
  dre_an_invalid_argument_call_does_not_ground_holds               PASS
  dre_an_imported_reference_grounds_the_same_way_holds             PASS
  bcn_cast_into_a_refinement_refuses_at_infer                      PASS
  bcn_cast_out_of_a_refinement_refuses_until_carrier_widening       PASS
  bcn_identity_cast_into_a_refinement_admits                       PASS
  bcn_infer_admits_int_to_int                                      PASS
  bcn_infer_refuses_int_to_bool                                    PASS

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Native execution of a named call: measured, still refused at eval

THE TYPING IS DONE; THE EXECUTION IS NOT, AND THE BOUNDARY IS ELSEWHERE.
A named Bool-returning call now grounds under infer -- reference typing, application
typing and the return derivation all reached -- and the same call through the REAL
native route refuses at EVAL with eval_rejected_grounding_not_derived at a SYNTHETIC
node carrying no authored locus.

So this lane's subject is complete in the sense it was scoped: a reference obtains a
justified callable contract, the application consumes it, valid and invalid cases
separate, and the body/return check is reachable again. What it does not deliver is
an executed assertion, because eval's facts gate is asked about a node this lane
never touches.

THE FALSE CONTROL EARNED ITS PLACE BY NOT DISCRIMINATING. Both rows refused
identically, so neither body ran and a refusal is indistinguishable from a false
answer at this point. Had only the positive row existed, the same outcome would have
read as "the call returned false" rather than "nothing executed".

THE SIGNATURE IS NOT NEW, which is the useful part: a plain-binder match over a
coproduct, and a trivial `fn f(b: Box) -> Int { 7 }` whose assertion never touches a
field, both refuse at eval on this same cause at a synthetic node. Three unrelated
subjects, one wall. That says the next boundary is eval's grounding consumer and not
anything about calls, and it is where the next lane should start rather than
rediscovering it.

Enrolled executed as expected-reds rather than deleted, so the measurement survives
in the corpus with its subject attached.

  nc_a_named_bool_call_executes_expected_red                          eval refusal
  nc_the_false_returning_call_is_the_deliberate_false_control_expected_red  eval refusal
  universe=2 population=2 file_refusals=8

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Attribute the eval refusal: the anchor is inside the callee's declaring path

The native qualification refused with eval_rejected_grounding_not_derived on a
node the renderer prints only as "<synthetic node occurrence>", which is a
PROVENANCE CATEGORY and not an identity -- so that log alone could not say which
node, and could not distinguish this from an unrelated universal eval defect.
This control supplies the same call shape at the eval boundary and reads the
refusal anchor directly. It is the one comparison that decides it, and it says:
the anchor is a node strictly inside the callee reference's encoded declaring
path.

So eval is demanding value-grounding for the internal representation of a
declaration identity rather than consuming that identity as a reference. The
route is established by source and now confirmed by measurement:

  eval_node_is_callee_reference admits an Arrow and a bare Atom only
    -> a resolved reference is a MARKED CONJ (resolve resolved_reference_node)
    -> the callee edge is not recognized, eval_fold_child_for_edge takes its
       ordinary recursive arm
    -> the walk descends into the encoded declaring path, whose spine
       declaration_reference_node builds at OccurrenceSynthetic
    -> infer visited those spine nodes too, so each holds an entry with
       grounding UNDERIVED rather than no entry, which is why the gate reports
       grounding_not_derived and not a facts lookup miss.

The fixture's own positive control is enrolled beside it, so a later red is a
statement about eval and not about an assembly that stopped producing a call.
Both claims PASS on this base.

This corrects the earlier grouping. Three subjects sharing a reason string is
not evidence of one defect; a synthetic occurrence is a provenance category, and
two of those subjects contain applications of their own. They are grouped only
once their failing nodes and consumer paths agree, and this file establishes the
failing node for THIS subject alone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* A named call executes: eval consumes the declaration reference it was descending into

WHAT NOW EXECUTES. A call whose callee is a resolved corpus-declaration reference
dispatches through the declaration it names and returns that declaration's value.
Both executing controls assert the VALUE and not merely acceptance -- any
Int-returning path would satisfy "Accepted" while proving nothing about which
declaration ran, and 7 is written only in the callee's body.

THE CHAIN, one authority per link.

  resolved declaration reference
    -> canonical declaration identity   (symbol_index_lookup, the GUARDED reader)
    -> recorded on the reference's facts (InferredFacts denotation)
    -> read by eval, which re-resolves nothing
    -> the existing arrow dispatch: find_arrow_body_child, eval_bind_arrow_params
    -> the callee's own body in the callee's own frame

Infer records the denotation because infer is the stage HOLDING the symbol index.
eval holds none, so the two routes otherwise open to it were both defects: a
second resolution path over the tree would be a WEAKER authority that accepts
references the ambiguity guard refuses (DESIGN section 3), and reading the body
out of the callable TYPE evidence would conflate two facts. The denotation is a
field separate from the grounding for exactly that reason -- a consumer wanting
the body reads the denotation, one wanting the type reads the grounding -- and
only a GROUNDED reference carries one, so a refused contract reaches no body.

WHY THE WALK WAS THE DEFECT BEFORE THE DISPATCH WAS. eval's callee classifier
admitted an Arrow and a bare Atom; a resolved reference is a marked Conj, so the
callee edge was not recognized, eval_fold_child_for_edge took its ordinary
recursive arm, and the walk descended INTO the reference's encoded declaring
path. The classifier now asks declaration_reference_path_optional -- the same
reader infer and translate ask -- rather than admitting Conj, which would admit
every record shape with it.

A REFERENCE REACHING NO EXECUTABLE DECLARATION REFUSES as an unbound runtime
binding and does not fall through to the primitive table, where it would be
looked up under a name it does not have and reported as a missing primitive
rather than as the declaration it names. The discriminating negative is enrolled:
a callee naming no declaration must not execute.

WHAT IS NOT DONE, enrolled executed and expected-red rather than described.

  - PARAMETER BINDING IS NOT DEMONSTRATED. Both executing controls have CONSTANT
    bodies, so a callee ignoring its argument entirely would pass both. The
    parameter-bodied fixture -- whose value depends on the argument -- still
    refuses. That claim is the one that would demonstrate binding and it is red.
  - A BOOL-RETURNING CALL still refuses, and it is a DIFFERENT boundary: its body
    is a constant, so it differs from the executing control only in return type.

TWO CORRECTIONS TO THE PRECEDING COMMIT'S READING.

The anchor measured there is an EMPTY Conj. An empty Conj is structurally equal
to any empty product, and node equality here is structural, so "inside the
declaring path" is weaker evidence than that commit's wording implies -- it is
consistent with the spine's nil terminator and does not exclude an unrelated
empty product. The classifier/walker mismatch stands on its own, established by
source and confirmed by the repair executing; the anchor comparison corroborates
it rather than proving it.

Four claims in v2.test.long.add_arrow_eval_by_execution fail on the pinned base
BEFORE this change (measured by stashing it), so they are pre-existing and not
caused here. I had no baseline for that set when I first read them as a
regression.

A CHANGE TRIED AND DROPPED. eval_fold_is_callee_reference_edge identifies the
callee edge by a processed-count, which is only correct while the callee is the
first child processed. That looked like the reason a one-argument call refused
where a zero-argument call executed, so it was rewritten to key on
eval_transform_callee_edge. Measured, it changed no verdict in either direction:
all seven controls pass without it. It is dropped rather than kept as an
unneeded second formulation, and the count-based identification is left as a
standing observation about that predicate, not a repair this change needs.

The carrier widening is five construction sites, not the forty-four a first grep
suggested: most matches were `-> InferredFacts {` signatures, and the fixtures
construct through helpers.

Regression: all 9 reference-evidence claims still pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The remaining refusal is a facts-key collision, not a fact about the call

WHAT THE REMAINING NAMED-CALL REFUSAL ACTUALLY IS. InferredTree keys its facts by
Node; Node equality is structural over kind, children and occurrence identity;
and std.occurrence_identity spells "no authored occurrence" as the NULLARY
constructor OccurrenceSynthetic, so it is one VALUE and not one value per
synthetic node. Two synthetic nodes with the same kind and children are therefore
THE SAME KEY, whoever built them and whenever.

Measured: the evaluator builds an empty synthetic Conj at runtime (v2.std.runtime
runtime_value_conj_node, for a value's type), asks the facts map about it, and the
map ANSWERS -- with the facts of an unrelated node that merely shares the shape.
Those facts carry GroundingNotDerived, so eval refuses with
eval_rejected_grounding_not_derived located at a node that exists in no source
position. Three claims enroll it: the refusing node is equal to the runtime-built
empty Conj; the map answers for that node; and a structurally equal node occurs in
the program, which is what makes it a collision rather than a stray key.

THE COLLISION IS SILENT IN BOTH DIRECTIONS, and only one direction is observed
here. A lookup that should MISS instead hits, converting a fail-closed
infer_facts_lookup_miss into a grounding judgment no producer intended. Had the
colliding entry been DERIVED rather than underived, the same collision would hand
the runtime a grounding nothing established -- a fabricated plausible output
rather than a refusal (DESIGN section 5). Nothing currently makes that direction
unreachable; this corpus just happens to collide with an underived entry.

A CORRECTION I OWE, and it retracts my own evidence rather than someone else's.
Commit b65297c57da attributed this refusal to the callee's encoded declaring path
because the anchor was a member of that path's node set. That evidence does not
discriminate: an empty synthetic Conj is a member of almost any node set it is
tested against, including the spine's terminator, which is why the same probe also
answered yes for the call subtree and for the declaration. The anchor comparison
establishes nothing about location and should not have been read as attribution.

What the classifier/walker repair rests on instead is unaffected: it is
established by source -- the classifier admitted Arrow and Atom only while a
resolved reference is a marked Conj -- and by named calls now EXECUTING to their
callee's value, asserted by value and not by acceptance. That evidence does not
pass through the anchor.

WHY THIS STOPS HERE. The repair is to decide the KEYING RELATION for the facts map
-- occurrence identity rather than structural identity -- which is a semantic rule
about node identity, sits in the conformance-identity domain (DESIGN section 3b),
and changes every facts lookup in the corpus rather than anything in this lane.
Escalating rather than reaching for a local guard at the symptom link, which is
the shape DESIGN section 6b names.

The parameter-bodied and Bool-returning controls beside this file stay enrolled
executed and expected-red; this finding explains the node they refuse at without
yet discharging either.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Both remaining reds refuse at the same runtime-built node, measured

The Bool-returning control's callee body is a constant, so it differs from an
EXECUTING control only in its return type, and it refuses at the same
runtime-built empty synthetic Conj as the parameter-bodied one. So this lane's two
remaining reds have ONE cause rather than two.

Scoped deliberately to these two subjects. A matching reason string is not
evidence of a shared defect -- that was the error in an earlier grouping of three
unrelated subjects -- so this claim compares the failing NODES and says nothing
about any other refusal reporting the same reason.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Withdraw the provenance inference; establish the key conflict by enumeration

I WAS TOLD MY EVIDENCE REPEATED THE ERROR IT CORRECTED, AND IT DID. The previous
commit replaced "the anchor lies inside the declaring path" with "the anchor is
what the runtime value constructor builds". Both were inferred from Node == Node,
and equality is the relation under suspicion, so it cannot be the instrument that
establishes provenance. An empty synthetic Conj compares equal to many unrelated
nodes; membership in a node set and equality with a constructor's result are both
uninformative about origin. Both readings are withdrawn.

WHAT ENUMERATION ESTABLISHES INSTEAD, which needs no provenance claim. Walking
infer's own entry list for one small program: MORE THAN ONE ENTRY carries the
empty synthetic Conj as its key, and those entries DISAGREE on whether grounding
was derived. So one key names at least two subjects whose facts differ, and a
consumer asking under that key receives whichever the first-match scan reaches
first. The same conflict stands in a second fixture, so it is a property of the
keying relation over ordinary programs rather than an artifact of one source text.

This is stronger than the earlier claims and differently shaped: it is not that a
freshly built equal value gets an answer, but that the relation ADMITS CONFLICTING
FACTS FOR ONE KEY. facts_map_from_entries checks each entry's own subject
correspondence and establishes no uniqueness or conflict condition across entries
that compare equal.

AND THE FAIL-OPEN DIRECTION IS REACHABLE, not hypothetical. A DERIVED entry exists
under the same key as an underived one, so a subject whose grounding was never
established can receive one that was -- a fabricated plausible output rather than a
refusal (DESIGN section 5) -- and which of the two a consumer gets is decided by
entry order. I had flagged this direction as a credible risk; the enumeration is
what makes it an observed reachability rather than a hypothetical, and it is still
short of an observed successful misexecution.

THE TRAVERSAL PATH, measured with a temporary diagnostic that gave each grounding
demand site in the evaluator its own reason symbol. The instrument is removed and
its result is recorded here rather than asserted, since asserting it would mean
keeping instrumentation in the evaluator:

  - the demanding caller is eval_fold_init, through eval_fold_child_for_edge's
    ORDINARY RECURSIVE ARM -- the node entered the walk as a child, not as a fold
    root, so this is a traversal that descended into it rather than a consumer
    asking about a supplied subject;
  - the node sits under a NAMED edge and is NOT under the declaration-reference
    marker, so it is not the reference spine the previous repair addressed;
  - no node in the call subtree carries it as a POSITIONAL child, which is how the
    named-edge conclusion was reached.

That locates the demand without asserting where the node came from, which is the
distinction the previous commits lost.

ALSO CORRECTED, and this one was a live defect rather than a wrong reading. The
annotation above eval_fold_is_callee_reference_edge described the callee-edge
identity repair as landed while the function still contained `p == 0 &&
is_positional(edge)`: I reverted the change after measuring that it moved no
verdict, and left the comment claiming it. A comment asserting a repair the
function does not contain is worse than no comment, since no Accepted program can
read one to check it (DESIGN section 4c). It now records the count-based
identification as a standing observation, states that rewriting it changed no
verdict in either direction, and says what would justify revisiting it: a call
shape where the two formulations DISAGREE, which is the discriminating case this
lane never found.

Verified after removing the instrumentation: all 7 declaration-reference eval
controls pass, including both executing calls; the 4 key-conflict claims pass. The
two executing controls return Accepted with diagnostics None, checked explicitly --
so they are executions and not acceptances carrying a suppressed refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Enroll the acceptance targets: argument-dependent execution and the Bool pair

THE NEXT RESULT IS NOW WRITTEN AND EXECUTED, not described. Three claims specify
what "argument-dependent execution" means and run the comparison that decides it:

  identity(only_arg: 3) -> 3
  identity(only_arg: 8) -> 8

TWO arguments, because one would not discriminate -- a callee returning a constant
that happened to equal the argument would satisfy a single case. The callee's body
IS its parameter, so its result cannot be produced without consuming the supplied
argument, which is the gap the two constant-bodied executing controls leave open:
a callee ignoring its argument entirely passes both of those.

They are enrolled as the REFUSAL they are today, with the value path supplied and
compared, so what remains when the boundary is repaired is inverting the assertion
rather than authoring the behaviour it checks. Writing it the other way round would
land a red and specify the same thing.

ONE OF THEM IS VACUOUS TODAY AND SAYS SO. The claim that the identity callee must
not answer the OTHER argument's value holds for the wrong reason while nothing
executes -- both conjuncts are satisfied by refusal. It is enrolled anyway because
it is the check that stops the repair being credited by a callee that consumes its
argument and returns the wrong one, and it becomes discriminating the moment the
claim above inverts. The annotation states the vacuity so no reader counts it as
present coverage; an expecting-green claim that cannot currently fail is
specification without execution unless its state is declared.

THE BOOL PAIR GETS THE SAME TREATMENT one type further on: a true-returning and a
false-returning callee must produce DIFFERENT answers, because a repair making both
execute to the same value would satisfy "executes" while destroying the distinction
the pair exists for.

Every one of these refuses at the shared facts key rather than at anything about
calls, arguments or return types -- the conflict is established by enumeration in
v2.test.claim.callexec.synthetic_facts_key_collision, where more than one entry
carries one key and those entries disagree on grounding. So this lane's acceptance
result is blocked behind that one contract question and is fully specified while it
waits, rather than waiting to be specified.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Field projection through resolve, infer and eval, with the field check that closes it

THE FRONTIER WAS DECLARED AND IT IS NOW PERFORMED. Two headers named this exact
gap. v2.compiler.body_lowering_fold PostfixAccum keeps `a.b.c` as ONE qualified
name and says why -- "deciding here would be a second resolver with no scope to
consult" -- naming try_resolve_qualified_name_node as the decider. That function's
own header then said: "Head bound and no absolute hit: the projection this arm
cannot yet perform, refused Unbound rather than fabricated." So the spine arriving
at resolve was never a producer defect; answering Unbound for it was resolve
accepting the job and not doing it, and the two causes -- a bound head needing
projection, and a genuinely unbound name -- were reported identically.

MEASURED FIRST, so a later green is a change in behaviour and not in the question.
On the pinned base, `fn f(b: Box) -> Int { b.tree }` refused at RESOLVE with
resolve_reason_unbound_symbol anchored on a QUALIFIED-NAME SPINE, while the same
receiver with the projection removed resolved and inferred. So the representation
was not reaching resolve as a projection at all.

THE THREE STAGES.

  resolve  a bound head with no absolute candidate becomes a field projection: the
           head resolves to its binder through canonical_atom, and each remaining
           segment folds on left to right, `b.x.y` as `(b.x).y`. It reads segment
           NODES, not the name's symbols, so every field keeps the occurrence of its
           own token and a diagnostic about one field lands on that field rather
           than on the whole chain. The reader for that lives in
           v2.std.qualified_name beside the spine's other reader and its inverse,
           because that module owns the label set.

  infer    a projection is typed by the field the receiver's type declares. It sits
           at the HEAD of the product row because a projection is an ELIMINATION,
           not a record: without it the projection Conj is typed as the product of
           its own children, a type combining the receiver with the field-name atom,
           which is the type of nothing the program computes. The receiver's type
           comes from its own facts through the row's entries; the type's fields come
           through the same GUARDED index reader the callee path uses. This is the
           first production consumer of v2.std.node_query declared_field_named.

  eval     a projection selects the field from the receiver's value. The receiver
           arrives as the one runtime argument through the existing seam, so the base
           is evaluated ONCE by the ordinary walk rather than re-entered per
           projection. The field edge is deliberately not an argument: it carries a
           name, not a value.

THE ABSENT-FIELD CONTROL EARNED ITS PLACE TWICE. With resolve's arm landed and
infer's absent, `b.absent_field` inferred CLEAN -- resolve admits the shape and
nothing checked the field, so a misspelled field became an accepted program. That is
the fail-open the control exists to catch and it caught it.

AND IT CAUGHT A SECOND ONE, IN MY OWN REPAIR. My first infer arm collapsed two
unavailabilities into one Absent: "I could not establish the receiver's type" and
"the receiver's type is established and declares no fields". That is the absorbing
fallback DESIGN section 5 forbids -- it converts a decided negative into "no
evidence" -- and it broke the standing negative control
v2.test.claim.namespace_xl0.cross_module_reference_resolution
a_receiver_with_no_such_child_never_accepts: `Bool.v` passed at the frontier. The
two are now separate arms. ReceiverTypeUnderived waits at the frontier, because
convicting a program whose receiver is typed by a route not yet reaching here would
be wrong in the other direction. ReceiverNotARecord REFUSES.

TWO CONTROLS IN ANOTHER LANE MOVED STAGE, AND THE PROPERTY IS STRICTLY HARDER NOW.
Both asserted refusal AT RESOLVE with resolve_reason_unbound_symbol for a `Bool`
receiver. Resolve no longer refuses those -- it commits the shape -- and infer
refuses them instead. So they now assert through infer: acceptance is still
forbidden, and the claim is harder than before, because a program that resolved and
then inferred clean would fail it where previously only the resolve reason was
checked. The old reason was the collapse rather than the property, which
v2.compiler.resolve's own header already recorded as a defect. One was renamed:
"refuses_unbound_today" pinned a stage and a reason it never meant to pin, and what
the row is FOR is that a method call on a local receiver is not silently admitted.

WHAT EVAL'S EVIDENCE IS AND WHY. Its receiver value is SUPPLIED, which is DESIGN
section 3's witness rule: the subject is one interface -- what eval returns for a
projection over a given aggregate -- and computing the aggregate would re-run
production the claim is not about. The pairing obligation is discharged by a claim
in the same file rather than by assertion: fps_the_resolved_tree_carries_a_field_-
projection asserts the real producer emits this shape over the production route.

A FINDING BEHIND THAT CHOICE, measured while looking for a fixture that would
deliver a projection to eval through surface syntax. Two forms that should, do not:
`Box { .. }.tree` and `make().tree` both resolve and infer with NO field-projection
node in the tree, while the parameter form `b.tree` now produces one. So the
value-receiver path body_lowering describes (PostfixAccumValue, the accumulator
after a call suffix) is not reached from these forms, and the only projection this
corpus's surface syntax currently produces has an unbound receiver at eval -- whose
binding is blocked behind the frozen facts-key question. That is why eval's executed
evidence is at its own boundary and not through a whole-program run.

A TYPE ERROR WORTH RECORDING, because it cost two iterations and will recur.
list_at_optional answers Optional<T>, and a value destructured straight out of it
does not carry its type through a FIELD ACCESS: reading `aggregate.fields` inline
produced a runtime type error while the sibling arm, which reads no field, passed.
Naming a typed parameter restores it. The same shape appears twice more in this
change, in the runtime field walk and in the spine segment reader.

Green: 13 field-projection controls (resolve, infer and eval, valid and absent
field, and two refusal arms) and 15/15 in the namespace lane.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The seven's receiver is a match binder, and its blocker is the match form

WHAT THE SEVEN'S REAL SITE ACTUALLY IS. In v2.test.parse.expression_bodied_fn_decl_-
parse the projection is `artifact.tree`, where `artifact` is bound by the arm
`Accepted { value: artifact, diagnostics: d }`. That is a MATCH-ARM BINDER, not the
function parameter the controls beside it use, so whether the projection repair
reaches it is its own fact and gets its own controls.

MEASURED: resolve reaches it, infer does not, AND THE ISOLATING CONTROL SAYS WHY.
The match form resolves -- resolve's projection arm handles a match binder's head
exactly as it handles a parameter's -- and then fails to infer. The same match form
with the projection REPLACED BY A LITERAL fails to infer identically. So the blocker
is the match construct, not the field access: it is the pre-existing match-arm
boundary already recorded as the seven's first refusal
(body_lowering_reason_match_arm_navigation_refused), owned elsewhere.

Both conjuncts of that claim are load-bearing. The projection form refusing alone
would be consistent with a projection defect; it is the literal-bodied form refusing
too that assigns the refusal to the match construct. When match arms do infer, the
claim goes red and the projection claim beside it becomes the live question, which is
the transition worth being told about.

A VACUOUS CLAIM OF MINE, CAUGHT AND REPLACED. I first asserted that an absent field
off a match binder is not admitted, and it PASSED -- vacuously, because the VALID
projection off a match binder does not infer either. Both arms refuse, so the
assertion distinguished nothing and would have gone on reading as coverage for the
absent-field wall on that shape. The isolating pair replaces it. This is the second
time in this lane that a claim passed while establishing nothing, and both times the
cause was the same: asserting a refusal without first checking that the positive case
reaches the boundary being tested.

AND THE SEVEN THEMSELVES ARE NOT THE EVIDENCE, DELIBERATELY. All seven pass under the
development runner -- both before and after this change -- because that runner
resolves them with the SEED compiler, while their blocker is v2's OWN front end on the
native route. Reporting that green as progress would be citing a signal that was never
about the property claimed, so the shape is reproduced as a small fixture instead and
the seven are left to the route that actually exercises v2.

Green: 15 field-projection controls.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Restore the application-path repair the merge pass silently dropped

WHAT THE MECHANICAL PASS DELETED. Resolving the merge's threading conflicts took
main's side at infer_transform_application_optional, which reverted two things this
lane's headline result depends on: the callee reader went back to
infer_application_callee_arrow (which only recognises an operator that IS an Arrow,
never one reached through its facts), and the facts lookup went back to `key: arrow`
instead of `key: callee_use`. infer_application_callee_use was left DEFINED AND NEVER
CALLED -- a declaration with no consumer, which is the tell.

WHY THE COMPILER COULD NOT CATCH IT, and this is the part worth keeping. The four
places where the same pass rewrote `tree` on a genuine Node parameter were named by
the front end immediately, by parameter, and fixed in one pass. This one compiled
cleanly, because the dropped code was a DIFFERENT ARGUMENT TO A CALL THAT STILL
TYPECHECKS: `key: arrow` and `key: callee_use` are both Nodes. A threading merge
resolved mechanically can therefore delete semantics while every type agrees, and only
an executed claim distinguishes the two. Five claims did: three reference-evidence rows
and BOTH executing named calls.

THE REPAIR RESTORED, with the reason it exists. The lookup is asked of the CALLEE USE
rather than of the arrow, because once the arrow may be a DECLARATION's Arrow reached
through the use's facts, it is a node of the declaring module with no entry in this
tree -- so keying on it answers Absent and the application drops to the frontier however
well the callee was typed.

ALSO RECORDED: every claim_batch verdict taken before this merge's rebuild is void. Main
moved the seed's Rust by roughly 3,700 lines (v1_interpreter.rs alone +967), and the
stale binary reported unbounded recursion in symbol_intern_lexeme on EVERY
assemble-based fixture -- including in a clean main worktree, which briefly read as "main
is broken". It was the instrument. The binary is rebuilt and every verdict below was
taken with it.

Green with the rebuilt binary: 15/15 field projection, 9/9 reference evidence, 10/10
named call.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The seven's downstream continuation, qualified past the match boundary

THE CHAIN, CONTINUED PAST THE ONE CONSTRUCT THAT STOPS IT. The pinned subject runs

  dag_prepared_grammar -> tokenize -> parse_module_prepared -> ParseArtifact.tree
    -> normalize -> recursive Arrow-body search

and stops at the MATCH ARMS in it, owned by the match-inference lane. This is that
same chain over the SAME sources and the SAME production functions, with the arms
replaced by bind_outcome, whose continuation is an ordinary function parameter rather
than an arm binder. Nothing downstream is re-implemented: normalize,
find_arrow_body_child and the recursive fold are the readers the subject itself calls,
and the sources are IMPORTED from the subject so a control here cannot drift from the
text the seven parse.

ALL TWELVE ROWS GREEN, which is the finding: there is no second defect waiting behind
the match boundary. Everything the seven do after it -- the projection, normalize, and
the recursive search, including the empty-`=` refusal -- already works. So when the
match owner lands, the seven have one blocker and not two.

IT IS PROVABLY THE SUBJECT'S CHAIN AND NOT MERELY A SIMILAR ONE. Two rows compare this
continuation's TREE against the subject's own entry point for every source, and its
refusal against the subject's refusal. "I called the same functions" is not that
evidence, and the defect below is exactly how the two can diverge while every other row
stays green.

THE FIDELITY DEFECT THIS CAUGHT, IN THIS FILE. The subject forwards the prepared
grammar's validation residue into parse_module_prepared explicitly. bind_outcome cannot
supply it -- it merges diagnostics into the continuation instead of handing them back --
so the first version passed None, on the assumption that the grammar carries no residue,
and enrolled a claim to check that assumption. The claim went RED: the prepared grammar
DOES carry residue. Without it this control would have parsed under a residue the seven
never use, with all seven mirrored rows still green.

The residue is now read through v2.std.diagnostic outcome_diagnostics, added here as the
reader that was missing: bind_outcome owns the pipeline arms, and a caller that must
FORWARD diagnostics to a producer expecting them as an argument had no route but to
re-spell those arms itself. It has a consumer in this change.

TWO CONTROLS THE SUBJECT DOES NOT CARRY, because every one of its rows answers TRUE
through the recursive search, so a search answering true for ANY tree would satisfy all
of them. A leaf atom must answer FALSE, and the braced control's normalized tree must be
found by RECURSION -- asserted by requiring that the root itself does NOT carry the arrow
body, so a search that only inspected the root fails there and nowhere else.

ParseArtifact.tree is qualified on the REAL carrier -- a production record whose `tree`
is a ParseTree beside a span index and an allocator -- and not on a fixture shaped to
resemble it. The field's type is what makes the projection's target unambiguous: the
other two fields are not Nodes, so selecting either would not compile.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* The chain wins: a bound head resolves local-first, and the interim guard dissolves

WALL 2 OF THE SEVEN, AND IT IS NOT A NEW SEMANTIC RULE. Section 13's rule is that a
chain's FIRST segment resolves on the ancestor chain and the rest projects. This arm
consulted the absolute candidates first and only reached the projection when the index
held nothing, so a bound head plus an absolute hit refused
AmbiguousQualifiedHeadShadowsAbsolute instead of projecting from the binder.

THAT REFUSAL WAS AN INTERIM GUARD AND ITS REASON IS GONE. qualified_head_bound_on_chain's
own header said exactly what it was: "the half of unique-on-chain that can be honest
BEFORE THE PROJECTION EXISTS" -- it refused because the arm could not project, and
therefore must not let the absolute read silently win. The projection now exists
(resolve_bound_head_projection, landed with the field-projection work), so the guard
DISSOLVES rather than weakens (DESIGN section 4b(4)).

WHAT THE OLD CLAIM FORBADE IS STILL FORBIDDEN. The absolute read does not win over a
binder the source spelled; it is now ANSWERED correctly instead of refused, which is the
climb the interim arm was waiting for. A bound head no longer consults the absolute
candidates at all.

THE EVIDENCE DID NOT RETIRE, which is the other half of 4b(4). The shadowing row is
flipped, not deleted: `fn f(v2: Bool) -> Bool { v2.test.xl0r_provider.xl0r_provided_fn }`
now asserts that the resolved tree carries a FIELD PROJECTION rather than that resolution
refused. It stays discriminating -- an implementation consulting the absolute candidates
first resolves that path to the provider's declaring path and carries no projection, so the
claim fails exactly on the behaviour the guard existed to prevent.

Green: 15/15 namespace resolution, 15/15 field projection.

STATED PLAINLY BECAUSE IT IS AN ESCALATION-SHAPED CHANGE: deleting a refusal is normally
something I escalate for. I did not treat this as one because the refusal's own header
declares it interim and names the capability that retires it, and that capability is the
thing this lane built. If the reading is that section 13's ordering is itself the open
question, this commit is the one to revert.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* v2 infer: type a match over a declared (generic) coproduct and its arm binders (#12641)

* match-arm binder typing: probe of infer's refusal over a generic coproduct scrutinee (WIP)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* v2 infer: type a match over a declared coproduct and its arm binders

The index records a generic declaration's type parameters beside the member it binds.
infer routes a non-literal match to a coproduct arm that checks variant and field
membership, the type-argument arity and exhaustiveness. A binder is typed as the
matched variant field's type at the scrutinee's instantiation. An arm body or
scrutinee with no derived type leaves the match at the frontier with a located advisory.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* match-binder typing claims over the exact Outcome<ParseArtifact> payload

Positive controls: binder typed ParseArtifact from Accepted.value, the match typed by
its arms, a binder shadowing a same-named parameter. Discriminating reds: undeclared
variant, undeclared field, too many and too few type arguments, missing variant, record
scrutinee. Frontiers: the seven's call scrutinee and a constructor arm body are
accepted and counted with located advisories.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* infer: only a constructor pattern routes a match to the coproduct family

A match whose patterns are neither literals nor constructors kept the literal family's
refusal before this change. Routing it to the coproduct family let an untyped scrutinee
accept it at the frontier, widening that refusal into an admission.
match_infer_fail_open_audit complement_body_real_infer_refuses_unsupported_pattern_holds
went red on it and is green again.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Two readers disagreed about a callee's arrow, so no named call's arguments were judged

The reference-evidence and field-projection claim sets went red on the composed
head. Re-deriving the slice rather than patching the symptom link found two
boundaries, one masking the other.

FIRST BOUNDARY -- the declaration was read from the wrong index.
infer_declaration_reference_facts and infer_projection_receiver asked
symbol_index_lookup against ResolvedTree.symbol_index, which is DECLARATIONS AS
AUTHORED: resolve's own note says nothing may read it for a body type. A
declaration's return atom there is the source spelling `Int`, and
dag_binding_denotation is a …
…bling (transport fields at the 3b-ii frontier) (#13050)

* WIP service spine: dotted service names lower to a namespace-body spine; graft merges same-named marked bodies

* WIP service spine: service lowering test reads operations at segment paths

* WIP service spine: controls (distinct paths, marked-only merge, no scope)

* WIP service spine: retire the dotted-label frontier receipt

* service spine: typed empty initial list in the namespace-body merge

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: merge a found pair through a typed helper (the emitter could not type the matched edge)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: keep a marked namespace body as a module member (flatten dropped it as parse machinery); spine facts are warm-shared producers

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine review 73940: namespace-body merge is one keyed pass (linear), not a quadratic scan-and-rebuild

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: the repeated-name refusal reads its edge through a typed parameter (emitter: no field 'target' on T)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: the spine controls fill the index from the normalized tree's binding source

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine review 73974: member lists built by prepend-and-reverse (linear); stale repeated_name_edges citations updated

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: prepend through a typed helper (emitter: List<Edge> vs FreeMonoid branch)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine review 73998: delete the unconsumed member reader and the per-Edge reverse/prepend copies; the member step is written over FreeMonoid<Edge> and reversed with list_reverse; specimen on carrier_alias_refuses_its_own_carriers_constructor

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* carrier_alias_refuses_its_own_carriers_constructor: emitter if-branch specimen (gunbc#12949)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service lowering claims: each census fixture is one warm nullary producer read by its claims (floor new-witness budget)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* XL-2 PR3a: the service realization sibling's model (MIRROR), per-kind declared-binding vocabularies, its conformance wall, and the symbol-index arm

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: typed fold steps; no 'pattern' binder (a seed keyword); rest optional via none

* service lowering census count: one unmodeled interface member after PR2c-ii lowered the io default

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: rest field decoder returns v2 Optional, the type its Present/Absent construct

* PR3a: rest field decoder builds its Optional through v2.std.optional's constructors

* PR3a: the sibling's labels in v2.std.service_realization_labels, so the symbol index does not pull the transport vocabularies into the emitted compiler

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM row: escape the interpolation specimens it quotes, so the row's own text is literal

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: a service namespace is a lookup boundary for the unqualified walk (side-chat P1, the nesting ban)

symbol_index_fill marks each path that binds a marked namespace body (a service prefix; the module's own
body is the fill's root, never a member) in SymbolIndex.namespace_bodies. symbol_index_lexical_collect
collects no candidates at such a position and never answers with one, and still ascends to the module.
Qualified paths stay indexed. Controls: bare sibling E and bare prefix s refuse from inside s.F.Run,
qualified s.E and s resolve, module k still binds bare, and the recursive s.a.x / s.a.y case.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM row: describe the escaped-brace control in words, since a quoted escaped backslash leaves the brace live

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: state the seed/v2 channel-vocabulary divergence, why neither side can read the other, and its dissolution (review 74063)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: the seed/v2 channel-vocabulary divergence is a dated RFM debt with an executable exit; module comments point at it (review 74063, XL-2 ruling STATED)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* stage0: regenerate extdeps_ietf_http_semantics.rs for HttpStatusClass (required-regen fixed point, round 2)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: a module root's bare bindings omit its service namespaces, on both resolution entries (side-chat P1, the resolve route)

build_program_namespace's module-root harvest and name_resolve's admit_named_export_edge skip a named
edge whose target is a marked namespace body (module_binding_edge_is_namespace_body), so resolve's
scope chain never answers a bare service prefix before the symbol index is consulted. The Arrow-domain
harvest is unchanged. Full-route control: from inside s.F.Run, bare s and bare E refuse as unbound,
module K binds bare, and the qualified s.E.Get resolves.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a hold: REST codes admitted through http_status_of; the wall enforces the documented shape; shell argv checked in v2.std.operation_argv's vocabulary; a red for every refusal reason

P1a: an exact code is decoded by the dag int reader; rest admits it only through std.types
http_status_of (100 and 599 admit, 99 and 600 refuse at the pattern); a shell exit code stays on its
own integer route.
P1b: an entry is a Conj with each optional member at most once; the transport block is a Conj whose
kind is a childless Atom; arms and projection are Conjs; an output is projected at most once.
P1c: a shell argv is a list literal read through ArgvRefusalCause (BindingMalformed, ArgvEmpty,
ExecutablePositionNotLiteral, UndeclaredInputBound against the operation's declared inputs,
ArgvExpressionUnsupported), carried on RealizationRefusal.argv.
P2: reds for repeated entries, unknown members, malformed config, repeated binding fields, empty and
malformed arms, empty projection and a non-string wire key.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: the resolve-route control's qualified positive is module-qualified (p.s.E.Get), paired with a missing name that refuses

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: an arm must be a Conj before its members are read; red with a Disj arm paired with the equivalent Conj arm (side-chat P1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: an imported service binds bare in the importer; only the module's own service namespaces are withheld (XL-2 ruling)

name_resolve admits exports under ExportAdmissionScope: OwnModuleBody withholds the subject's service
namespaces, ImportedModuleExports admits an imported module's as any export. Control: module a importing
t resolves s.F.Run head-bare; module b without the import refuses it as unbound.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: the import control reaches t's operation through the import (t.s.F.Run); a non-importer refuses it

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* service spine: the import control pairs t.s.F.Run with t.s.F.Nope refusing (an absolute path resolves without an import, so a non-importer does not discriminate)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM: absolute_path_resolves_without_an_import (v2 resolves a module-qualified path through the corpus index regardless of the subject's imports; specimen from the #12949 probe)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* WIP 3b-i: realization facts lower into the MIRROR sibling (first build)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i: lowering claims over the real census route; correct the resource default-tail claim stale since #12948

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i: an arms block is a list introduction, not a Conj of positional edges (post-normalize well_formed); wall and fixtures read it as a list

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i lowering claim: count arms as the list's elements

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: the wall's node-kind readings are one exhaustive match (realization_node_shape) and every named-edge lookup names all three arms; no wildcard arms on closed coproducts (side-chat ruling, NonFoldResidue)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i: carry #12974's exhaustive arms; the doc lookup and the lowering claim's lookup name all three arms

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* PR3a: the wall decodes a status pattern into ShellExitPattern / RestResponseStatus and admits it only when it decodes; the Bool re-checks are deleted (review 74145)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i floor cost: the resource default-tail census and the refused-normalization conservation report are each one warm nullary producer read by their claim

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 3b-i: a service carrying a realization leaf is held off the full route even when nothing is set aside (config-only); paired census/full control (side-chat P1)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… whole pool (#13062)

An entry-subject run demanded the bare-reference edge row of every pool file
before any entry. It now demands the union of the named entries' closures
(warm_bare_reference_edge_index_for_entries); a discovery roster and the
required floor keep the whole-pool demand. Adds [process-partition],
[process-partition-exit] and the [pre-entry] rows to claim_batch so the wall
outside the resolve spans is attributed, and names the producer, grain,
displaced loop and bypass discriminator in the demand-engine program's M3a.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ad of exiting (#13066)

* harness: a belt-spawned turn waits in line for its serving seat instead of exiting

A Pending seat bind (every admissible serving group busy) ended the worker
with exit 1 before any provider call: the dashboard read "Agent failed",
the belt recorded a yield, and a continuation turn was spent on a turn that
never reached a model (srv2, 2026-10-02: group-b saturated by traffic outside
the seat ledger, group-a down). harness_seat already names the remedy --
retry in a moment -- and the worker now performs it in place.

- harness_cli harness_bind_seat_waiting: worker, reviewer, auditor and
  supervisor re-ask every 60s, bounded at 1440 waits; each wait is announced
  as turn.placement_waiting on the attempt's own event stream. An unwritable
  announcement or a failed sleep refuses at once; the cap exits pending as
  before. The wait never places a turn beside unexplained occupants.
- roadmap_provider_events: HarnessPlacementWaiting -> ProviderAwaitingSeat
  { detail } (non-terminal); the jq projector keeps wait, wait_cap, reason.
- Every ProviderExecutionState consumer gains the arm: active agent segment
  with the reason, no commit, handoff awaiting worker, not terminal.
- Witnesses: the harness's own wait line through the real reader; the
  projector keeps the reason; a placed turn leaves the wait; a waiting worker
  is active and holds its lineage; a wait ending in a nonzero exit is failed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* harness_bind_seat_waiting: name every HarnessSeatBinding arm (no wildcard over the closed coproduct)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…y) (#13007)

* gunbc test: refuse a binary not built at HEAD (StaleBinary / BinaryFreshnessUndecided)

Modeled in gunbc.target_invocation (BuiltIdentity, HeadObservation, BinaryFreshness,
assess_binary_freshness), mirrored in target_invocation_host test_verb_at_head.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* freshness keyed on the binary's dep-info input set, not HEAD equality (calm-boar-904 ruling)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* binary_freshness_step: exhaustive arms, no wildcard over BinaryInput (non-fold residue roster)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* seed growth: enrol the freshness mirror in gunbc.target_invocation_seed_growth

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* typo

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* freshness: no build root in dep-info refuses (DepInfoUnreadable), never mtime-only (review 74282)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* freshness: anchor at build start (the unit's fingerprint dep-info), not the binary's mtime

An input edited after rustc read it but before linking finished read Fresh against the
binary's mtime. The anchor is now derived exactly: the binary's hard-link twin in deps/
names the fingerprint unit by hash, and its dep-bin-<name> is cargo's build-start stamp.
Any break in that chain refuses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* freshness: only NotFound is Missing; other stat errors refuse with their own cause (review 74474)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the hand-authored dependency blocks (libc E0433) (#13057)

* Derive every .dag harness Cargo manifest from the emitted one; delete the hand-authored dependency blocks

The curated seed-linked harness, the emission entry instrument, the product
receipt stage and both std.logic transports each overwrote the Cargo.toml the
emission wrote with a literal [dependencies] roster. gunbc#12861 added libc to
the emitted runtime and to two of those rosters and missed the curated one, so
every behavioral transport row failed to build (E0433 libc, fleet run
37079504327: 15 of 15 no-verdict).

tools.emitted_crate_harness_manifest reads the emitted manifest and appends only
what a harness owns: its [lib]/[[bin]] target tables and, for a seed-linked
build, the v1-compiler path dependency as its own subtable. No harness route
names a registry crate any more, and an absent emitted manifest refuses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Harness manifest: decide the refusal in a pure function so its claims supply the reading

The floor's hermetic route has no arm for Mktemp.Dir, so the two claims that
derived a manifest on a real directory never reached their subject. The
read-or-refuse decision is now plan_harness_manifest over a supplied reading;
derive_harness_manifest_in_place performs the read and writes only on the
planned arm.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d from the Redfish Manager Oem keys (#13065)

* mtjade1 BMC family: AMI MegaRAC, discriminated from the Redfish Manager Oem keys

2026-10-03: the unit's single rear port (the GSG's BMC management port; the host has no NIC)
answered on its factory static 10.0.7.2 and accepted the factory admin account read-only.
/redfish/v1/Managers/Self names Oem members Ami and Amp; the capture is committed with its
sha256, and mtjade1_firmware_family_standing is now DERIVED through
gunbc.machine_intake_bmc_firmware_family_discriminator discriminate_family (FamilyObserved
AmiMegaRac), not authored. Corroborating readings (IPMI Ampere/0x0082/2.11, FW_DESC JADE
LTS_SPX12.3, kernel 5.2.8-ami, AMI<MAC> hostname, Debian-packaged sshd) are recorded beside it.
The fan selection now picks the shared MegaRAC route, which is Unbound with its read obligation.
Witness REDs: a manager without the Ami key, and one with both keys, stay unobserved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtjade1 BMC network: operator moved it to DHCP (192.168.1.246); factory prefix corrected to /24 from the controller's own lan print

The factory static row stays as history with its prefix corrected (the controller reports
255.255.255.0; /29 was srv1's chosen access prefix). mtjade1_bmc_reconfigured_network records the
lease and mtjade1_current_bmc_network_standing compares it to the GSG (matches: DHCP). The
first-contact frontier's reasons now state that the discriminator is consumed over a hand-recorded
capture and that the factory-segment converge can no longer reach the unit; the new standing is
rostered there with the managed-host mtjade1 access row as its consumer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* mtjade1 BMC family read from the committed capture: digest-checked, decoded, bound by BoardExtra MAC; retire the discriminator frontier rows

RecordedManagerIdentityObservation is the historical read receipt: read_mtjade1_recorded_manager_identity
reads artifacts/bmc/mtjade1-redfish-manager-self-2026-10-03.json, checks sha256 against the recorded
digest, decodes Id/FirmwareVersion/Model and the root Oem keys, and binds the response to mtjade1 via
Oem.Amp.FruInformation.BoardExtra == the observed BMC link (70:E2:84:95:33:6B) before discriminate_family.
Every failure is FamilyUnobserved naming its gap. Controls: digest drift, non-JSON, missing Model,
another MAC (and another spelling of the same MAC) all refuse; the real artifact is AmiMegaRac.
discriminate_family / family_standing_from_discrimination leave the first-contact frontier, naming
the capture receipt; the two Oem-key standings stay frontiered on their citation obligations.
Corroborating IPMI/FW_DESC/kernel/hostname/sshd readings are operator notes from the same session.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#13079)

* mtcollins1 socket 1: record the operator-reported pin damage from the 2026-10-03 CPU removal

Paste fell on the socket-1 pins during the CPU removal for the one-socket test, and a microfiber
cloth used to clean it probably bent some. A typed OperatorByEyeReport row with the account and the
consequence (any later socket-1 test must inspect the socket first; a socket-1 failure after this
date is not evidence about the pre-damage fault), rendered in the unit's history block and
asserted by its witness.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Socket damage: render the report's own date; the consequence becomes a typed evidence gate read by the renderers

Review 74527: the history label re-typed the date the report carries, and the 'inspect first'
consequence was prose nothing read. socket_evidence_gate derives SocketEvidenceRequiresInspectionSince
{ socket, since } from the report's date; the history line and every OPEN socket-1 hypothesis render
it, and date_text formats the record's date. Witness: a report dated 2027-01-09 renders that date
and gate, not 2026-10-03.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cts; full-input KV gate modelled (#12975)

* spark: the MoA memory proof — the unified seven-axis proof subject, the mechanism-named terms, the wet receipt bundle of 2026-09-25 bound with the doctrine's standings, the cache subproof as its own three-armed verdict, and the whole-arm standing naming its open obligations — MemoryProofSubject binds model, runtime, topology, parallelism, allocator, workload and generation, with the receipt-subject compatibility law computed from the scaling law (a 64Kx1 receipt discharges only terms invariant to the move to 262Kx6: static residency transfers across the workload, per-sequence-fixed requires equal seat counts, every workload-sensitive law refuses; a TP4 receipt on TP2 refuses at the topology axis; the generation axis is provenance, not a gate) and the census projecting every component as a MemoryTerm naming placement law, scaling law, phase, lifetime, bound and derivation; gunbc.spark.arm_memory_experiment_observed binds the bounded experiment's sixteen rank figures beside the raw dated readings — per-rank pools and KV arenas as observed intervals at the reporter's rounding unit, the envelopes derived from the pool interval at the 8567 basis-point decision with the printed figures carried for comparison, weights+nontorch as composite observations that admit as evidence but discharge no placement obligation, activation as subject-scoped observations refused on any other workload, TP1's -2.54 GiB graph figure preserved raw as GraphAttributionUnestablished with zero headroom credit, and the head's printed capacity with the six-seat division carried as a CacheCapacityCandidate no verdict consumes; the cache fold decides only by the direct roster fold (KDA fixed-per-sequence, sparse-MLA per-token, KPool per pooled token, the sparse-indexer tail, and the grouping/padding inside the per-group block rounding) against every rank's allocator evidence, with the roster completeness obligations named; the whole standing carries CacheFitProved beside ArmMemoryFitUnestablished with the 262144 prefill transient open, the sparse-indexer buffer formula cited from the directive and awaiting the pinned source; the declared capacity intent is untouched at 1x65536 and no intent moves to 262KxN here — that change is the owner's call after the subproofs land (owner directive 2026-09-25, docs/plans/moa-memory-modeling.md)

* Revert "spark: the group B capacity intent moves to the derived six-seat 262K window — seats are the derivation floor(1,805,689 / 262,144) = 6 over the converged run's engine KV inventory (limiting rank TP3/srv11 the basis), retiring the harness-seat authority that governed the pre-measurement 64K shape; window 262144, batch ceiling 2048, envelope 8567, fp8 KV unchanged, and the derived profile flows through profile_for_intent to the renderer witness (--max-model-len 262144, --max-num-seqs 6) which keeps discriminating the retired crash-looping shape by seats and utilization"

This reverts commit 54533dd6f57b1a05c3b7de3f243dbed33661167e.

* tracker: assignment IS the execution entry point — the Claimed event carries the qualified-principal assignee and return_to, the results roster drops the ID column with the title as the link and fixed tracks, and the fabric endpoint drives the retired Start Work's launch admission

owner rulings 2026-09-25 (docs/plans/issue-page-architecture.md + the roster amendment): the issue tracker takes Buganizer's assignment semantics — email autocomplete to recently used assignees, the worker identity is a high-level endpoint (fabric@gunb.ai, qualified worker:fabric/offered) and the workflow picks the model, and assignment replaces the retired Start Work button as the execution entry point.

EVENT LOG (gunbc.roadmap.roadmap_event_log): Claimed gains { assignee, return_to }, both qualified-principal strings in email form; the codec VERSIONS — schema bumps to roadmap-event/v2 and v1 logs read BY READ COMPATIBILITY (a v1 Claimed decodes as a self-claim, its id verifies against its own v1 canonical bytes, nothing on disk is rewritten). Reassignment is newest-Claimed-wins by the oldest-first chain fold; the standing's by names the HOLDER (the assignee), the recording author stays on the event. The assignment projection (holder + return_to, released/forked clears) is the rail's read. The recently-used fold (newest-first, deduped, Claimed only) feeds the autocomplete. The carrier gains the all-events read (one sync, every node's envelopes, first refusal refuses whole). The CLI claim records a self-claim (return_to = author).

EXTDEPS (extdeps.google.issue_tracker): one QualifiedPrincipal model — email is the selector never the durable identity, kind Human|Workflow, NO MODEL NAMES in the UI; the avatar resolution chain (internal profile -> directory -> cached -> initials) with AvatarResolved|Absent|Unread and the never-blocks law (absent/unread render initials and never refuse assignment, comments, or rendering); suggestions = viewer + fabric pinned + recents deduped by subject; validation accepts an email spelling or the fabric endpoint and 400s everything else. THE ROSTER: the ID column drops (the title cell IS the link to /issue/<id>), TITLE takes the dominant minmax(0, 2fr) against STATUS's 1fr, and every short column takes a FIXED width from its content's upper bound (P 4ch, TYPE 6ch, ASSIGNEE the avatar chip's size plus gutter, D VIEWS 6ch, LAST MODIFIED 12ch, actions 24ch) — band filtering changes which rows show and NEVER the grid geometry, the template takes no population. The ASSIGNEE cell renders the principal's circular avatar chip (initials, the workflow badge for Fabric, the full identity on the title attribute) or the capture's -- placeholder, never the email text.

SERVE (gunbc.roadmap_serve): POST /issue/<id>/assign records the AssignIssue command — authenticated author, explicit return_to (default the requester), the hidden expected_revision pins the rendered chain head and a mismatch is 409 STALE; a HUMAN assignee never dispatches; the FABRIC endpoint drives the SAME launch admission the /dispatch route answers after the event lands — an admission refusal DOES NOT UNDO the assignment (the issue stays with Fabric, the body renders the located waiting condition in the launch's typed vocabulary — 'waiting on fabric: <label> — <reason>', never 'assignment failed'), and re-assigning the same revision joins the existing request through the admission's own already-live arm. The detail route feeds the assign control the viewer identity and the cross-issue recents (all-events read; a refused read degrades to the seeds alone).

Forms ship enctype text/plain (newline-delimited fields, no percent-encoding to undo); the assign submit deliberately wears no .issue-action class so the emitted client's bodyless action bind never races the native submit. CSS digest re-pinned by execution (c71edd8bb8d7e8e0).

Suites: event_log 10/0 (was 4/0), event_carrier 3/0 (was 2/0), extdeps 39/0 (was 32/0), serve 34/0 (was 28/0), page 73/1 (the known witness_ticket_brief_budget_holds_and_reds only), parity 5/0, presentation 57/0, register 15/3 + altitude 7/1 (the known pre-existing reds, unchanged), frontier/site_register identical to baseline. No new reds.

* tracker: comments are durable events — CommentCreated/Edited/Deleted ride the same chained, fork-refusing log, edits and deletes append never mutate, and retries never duplicate

owner mandate 2026-09-25 (docs/plans/issue-page-architecture.md, 'Comments are durable events'): IssueCommentCreated / Edited / Deleted with issue id, comment ordinal, author principal, body, created/edited times, and visibility — an edit or a delete APPENDS to the same content-addressed, parent-chained event log the assignment events ride, so history is never silently rewritten and any reader folds the same stream.

EVENT LOG (gunbc.roadmap.roadmap_event_log): three new v2 kinds (comment_created/comment_edited/comment_deleted, each requiring its members on decode). THE COMMENT FOLD takes the comment's identity as its creation ordinal in CAUSAL order — the stable deep link /issue/<id>#comment-N survives edits and deletes because the tombstone retains the ordinal; an edit rewrites the body and stamps edited_at on the matching key only (an unknown key is an honest no-op, never a rewrite of someone else's words); the standing and assignment folds pass comment events through untouched. RETRY-IDEMPOTENCE is two predicates: a CommentCreated already carrying the client's key marks the retry, and a keyless composer (the no-JS native form) re-posting the same author, body, and head is the same retry — a different body, head, or author is a new comment, never a suppressed duplicate.

SERVE (gunbc.roadmap_serve): POST /issue/<id>/comment — the event-CLI idiom again (read, refuse forked/incomplete 409, parent = the single head, probed clock, carrier append) with the authenticated author, the expected_revision stale-write guard matching the assign route, and the text/plain body wire (key line first, body LAST — markdown freely carries newlines; the parse cuts at the first body= opener so a literal 'body=' inside the text stays verbatim). The retry arm answers 200 with the EXISTING comment's deep link and appends NOTHING (the duplicate-append-refused half of acceptance control 7); the first-write response names /issue/<id>#comment-N and the event id. Visibility is recorded ('public' this cut). The form-field parser generalizes to issue_form_field (the assign form shares it).

Suites: event_log 14/0 (was 10/0), serve 37/0 (was 34/0, +route selection +body-wire +early-refusals +deep-link witnesses), page 73/1 (the known witness_ticket_brief_budget_holds_and_reds only). No new reds.

* docs: human identity and authorization — tailnet is transport, Google OIDC is human identity, application policy is authorization; one PrincipalRef authority (google-sub, never email) with profile facts separate, OIDC authentication (openid/email/profile only, auth-code+PKCE, opaque sessions, CSRF) vs OAuth for Google data, the approvals three-proof split (human + capability + device integrity), roadmap-event/v3 with PrincipalRef and LegacyEmailPrincipal for history (never auto-matched), the canonical A-E work graph with the stage0 acceptance contract preserved, and the acceptance controls including forged-header and email-change/reuse cases (owner ruling 2026-09-25)

* issue tracker: the header cells stop overlapping — the fixed tracks derive from the wider of the header's own spelling or the content bound (ASSIGNEE 9ch from its header, D VIEWS 8ch), and .issue-col carries the same containment chain as the data cells (owner: ASSIGNEE and STATUS overlap)

* roadmap style: the assignee column centers its content — the avatar chip and the '--' placeholder both read centered under the header (owner: left-aligned pfp looks weird; center the empty too)

* extdeps/vllm: the reviewable KV allocation plan emission patch — vllm @ 8d09804c877c48165c6ba69bc9dc02d09bae0b83, EngineCore._initialize_kv_caches emits one kv-allocation-plan/v1 record per engine at startup on the KV_ALLOCATION_PLAN_JSON log line and (when VLLM_KV_ALLOCATION_PLAN_PATH is set) the identical canonical line at that path via tmp file and atomic rename: runtime self-report, cache format, allocator inventory, requested length, scheduler block size, per-group identity/kind/layer identities/block size/page bytes/tokens per state/max usage/blocks at the requested length computed with the engine's own spec methods so the record reproduces the printed capacity by construction, and the grouping/padding decision quoted from the resolved spec fields; failures log and never gate serving; header names the pinned revision and the sha256 of both touched files at the base revision, and the patch is witnessed to apply cleanly (git apply --check) against a fresh upstream checkout (owner directive 2026-09-25, docs/plans/moa-memory-modeling.md)

* runbooks: rebuild the GLM derived serving image with the KV allocation plan emission patch — pure-Python file-copy layer over the recorded derived image content id (no recompile: the patch touches only vllm/v1/engine/core.py and vllm/envs.py), with pin records for the patch and both patched files, base-image id verification against gunbc.spark.serving_arm glm53_derived_row, an in-image probe of the marker constant, the launch additions (VLLM_KV_ALLOCATION_PLAN_IMAGE_DIGEST self-report, optional file-channel mount), and the honest statement that the first real capture refuses at the mint's revision wall until the modeled revision advances — operator-executed on the fleet, authored here unexecuted

* spark: the capture leg of the allocation-plan rung — gunbc.spark.vllm_allocation_plan_observe reads the patched engine's KV_ALLOCATION_PLAN_JSON line (or the mounted file) off a launch, parses it three-valued through extdeps.languages.json (absent becomes the capture's absent optional for the mint to name, malformed refuses carrying the member's cause), binds the runtime revision from the version string's own +g<sha> self-report read not stamped, folds upstream kind strings back through kv_group_metadata's new vllm_kv_cache_spec_kind_from_wire inverse and its growth-shape mapping, and admits a receipt only past the plan mint's walls and the printed-capacity control, bound to one VllmServingLaunch — with the deployed 8d09804 revision's present refusal at the modeled-revision wall stated as the wall working, not a route defect

* test: the allocation-plan capture fold witnesses — a complete GLM-5.3-Flash-shaped emission (11 sparse-MLA + 34 KDA + kpool tail, figures internally consistent the way the engine's own arithmetic is: 28,236 blocks over a 4,098-block full-context request predicts the printed 6.89x) mints and reproduces the printed capacity end to end, and every refusal arm discriminates: missing field refused by name, the patched-but-unread 8d09804 revision refused at the mint wall before the capacity question, capacity mismatch beyond printed precision Inconsistent with the predicted figure carried, zero-sized group refused at the zero wall, revision-less self-report unreadable, wrong-shaped member unreadable not absent, and the log channel takes the last marker line from restart-concatenated captured stdout

* issue tracker: D VIEWS leaves the results roster — in the product it is a view counter (a popularity signal), not dependencies; we track no views, and blockers live on the detail page's dependency surfaces, never on the list row (owner ruling 2026-09-25)

* spark: the group B capacity intent moves to the six-seat 262K window as the EXPERIMENT SUBJECT — owner pre-authorization 2026-09-25 ('yes if 262k*6 is proved then fine'): seats floor(1,805,689 / 262,144) = 6 over the converged run's engine KV inventory (limiting rank TP3/srv11), window 262144, batch ceiling 2048, envelope 8567, fp8 KV unchanged, derived profile through profile_for_intent (--max-model-len 262144 --max-num-seqs 6). Re-applied after the doctrine revert a7caf00c0e: this sets the bounded experiment's subject so the allocation-plan capture and the direct cache fold can prove or refuse the candidate — normal serving stays walled (FitUnestablished) until the fold, the prefill transient, and the planted-residue proof land; the intent as service promise is adopted only on CacheFitProved with the headroom report

* spark: the arm runs the allocation-plan image — glm_native_image_reference advances to derived-kvplan-20260925, a pure file-copy layer over the recorded base (c7d63d15) carrying the KV_ALLOCATION_PLAN_JSON emission patch (5b75b784, in-image pins verified, marker probed on srv9; runbook docs/runbooks/glm-kv-allocation-plan-image-rebuild.md)

* oidc: the Google login verdict and transaction model — the hd hosted-domain claim (Google's, cited) and the picture standard claim on the ID-token vocabulary, the closed openid/email/profile login-scope coproduct with no API-scope constructor, the auth-code+PKCE login transaction (state, nonce, verifier, bounded lifetime, relative-return-path admission refusing absolute and protocol-relative spellings), the realization-supplied signature/JWKS verdict input naming the checked key, and verify_oidc_id_token with every check a typed refusal arm in ruling order (signature, iss, aud, exp with fractional-second refusal rather than rounding, nonce, email_verified present-and-true, hd == policy domain, absent hd a mismatch not a pass); the production JWKS realization is the named frontier and no production login path exists until it lands; witness: google_oidc_verdict_witness 16/16 (owner directive 2026-09-25, lane A2)

(cherry picked from commit a9a4826e1a9ec292f10d44414e0d22df7d7442e2)

* principal projection: PrincipalRef is the one qualified-principal authority, sealed behind the verified Google ID-token verdict — PrincipalRef { authority, namespace, subject } with the ruling's two authorities (principal:google-oidc/accounts/<sub> via the caller-sealed mint_human_principal_from_verdict, whose sole input is an OidcIdTokenVerdict and which reads only sub, so same sub + changed email is the same principal and same email + different sub is not; principal:gunbc/workflows/fabric as the one workflow principal with fabric@gunb.ai a display alias only); PrincipalProfile carries email/email_verified/hosted_domain/display_name/picture as mutable projections with a profile_revision, minted beside the principal and revised without ever re-identifying it; the a3fd5eb principal_from_email shape has no constructor anywhere in gunbc; the classified-claims ingest moves behind the verdict (product.data_class classify_personal_identity re-admitted to verified_oidc_projection) closing the boundary the predecessor sketch recorded open; the posix projection arm dissolves with zero production consumers; gunbc.auth.google_workspace_login binds the gunb.ai policy (the google-oidc issuer row, per-client admitted audiences, hd == gunb.ai, the transaction nonce); witnesses: principal_projection_witness 8/8 including the unadmitted-caller probe RED, data_class witnesses green (owner directive 2026-09-25, lane A1)

(cherry picked from commit 6959ed9101e06bae3262e7fbb32f7738fc70a472)

* request security: ServeHttpRequest carries a generic RequestSecurityContext with the access path separate from the authentication evidence, and the write law is the std.access conjunction — ServeHttpRequest<Authentication> replaces identity: TailnetIdentity with security: RequestSecurityContext { access_path, authentication }, the tailnet arm modeled through the ACL and serve-route authorities with a versioned readback (a header alone mints no tailnet path: loopback bind + serve-status readback + ACL revision, else the header is dropped unattributed); gunbc.auth.session mints AuthenticatedSession only from a verified verdict bound to a live login transaction (GoogleOidc the one human method, the session seated on the verdict-sealed principal, opaque Secure/HttpOnly/SameSite=Lax bounded cookie attributes, rotation on authentication, CSRF token separate from login state); gunbc.auth.request_authentication owns the evidence vocabulary (GoogleOidcSession | FabricServiceEvidence naming the one workflow principal | AuthAbsent) and the laws as construction: human_write_admission is decision_meet over authentication, action authorization (approve = the exact stable-principal roster, the scoped capability staying with std.scoped_authorization and the signed approval capability), CSRF, and the deployment tailnet-path policy — no fallback permits a write and either axis alone refuses; roadmap_serve builds the context at its one seam (authentication AuthAbsent until the cookie channel lands at the socket realization) so assign/comment refuse at the authentication axis with a located reason and record the principal label as author on admission, the approval decide route passes the proxy-attributed transport observation to the broker seam unchanged, and the belt routes are named as the launch-admission lane's cut; witnesses: auth_session 7/7, request_authentication 13/13, roadmap_serve 37/37, instruments 11/11 (owner directive 2026-09-25, lane A3)

(cherry picked from commit 22751c16fcd7fa965b87d8d1945acab16bb4d3fc)

* identity: the Google OIDC login model in extdeps.auth.oidc — OidcHostedDomain (the Google hd claim entering the OIDC carrier by the owner directive, the ONLY Workspace-membership gate, compared as a claim never parsed from an email) and picture join the standard claims; the login scope wall is a closed coproduct (openid/email/profile only, no API-scope constructor exists to request Gmail/Contacts/Directory/Drive at login); the auth-code+PKCE transaction carries state/nonce/verifier/return-path under a bounded lifetime; relative-return-path admission refuses absolute and protocol-relative spellings so the redirect can never leave the origin; the signature check is a realization-supplied input naming the JWKS key, with the production JWKS fetch named as an unbound dissolution frontier so every production login refuses loud until it lands; and the ID-token verdict fold turns claims plus policy into one verdict with a typed refusal arm per check — signature/JWKS, iss, aud against the admitted roster, exp (refusing fractional seconds rather than rounding), nonce, email_verified present-and-true, hd — each arm carrying both sides, with one rendered reason per arm; the verdict witness drives every arm RED by changing exactly one term of the verified control, and the jwt claims witness fixtures carry the new optional fields

(cherry picked from commit 80b07cf63d6d17649d918ed706d7a537fe382794)

* extdeps: the modeled revision advances to the patched source 8d09804c877c48165c6ba69bc9dc02d09bae0b83 — the model lane's two named acts, resolution and advancement, landed together with the wall-law flip they force. RESOLUTION: the emission's runtime self-report rides the build string verbatim (v0.1.dev1+g8d09804c8, nine hex characters), and the capture leg now resolves the token against the corpus' cited revisions — extdeps.vllm.runtime_defaults' modelled roster, each row read on its own dated evidence — refusing what prefixes nothing cited (the engine claiming a tree this corpus has no authority for) and short or non-hex tokens at the lexical wall, so the abbreviated spelling the real capture carries and the full-sha spelling land on one revision (gunbc.spark.vllm_allocation_plan_observe kv_plan_resolve_revision_token). ADVANCEMENT: extdeps.vllm.server vllm_source_revision_read moves 1967a5627 -> 8d09804c877c48165c6ba69bc9dc02d09bae0b83 because THAT revision's emission was read today — the bounded 262144x6 experiment's captured KV_ALLOCATION_PLAN_JSON line — per the wall law that admits an emission only at the revision it was read at; the patch file's pinned base and runtime_defaults' Vllm8d09804 row, the cited authorities, agree on the full sha. WHAT THE ADVANCE DOES NOT RE-SCOPE, made structural: vllm_source_revision_1967a5627 is named once, and every fact read at the retired revision stamps against it instead of riding the pin — kv_group_metadata's lazy-query emission shape (the patch touches EngineCore._initialize_kv_caches only; nobody re-read get_kv_cache_group_metadata at the patched tree), server.dag's own route population, health-coverage fact and capacity-source ruling, and the batch-defaults / engine-args negatives / sampling-params bound / usage-stats roster riders, each with its reading evidence unchanged. THE FLIP: the refusal arms that used to name 8d09804 as the unread revision now name 1967a5627 — the allocation-plan observe witness, the kv_layout revision-split arm, the kv_group_metadata pin assertion, and the spark_vllm_observed canary, which now asserts the capacity ruling carries 1967a5627 AND differs from the live pin, so a future advance that leaves a rider behind is red at exactly the row that drifted. The 64K wet bundle's readings were always stamped with the engine's own self-report (defaults_source_revision Vllm8d09804), which now equals the pin; the comment there says the agreement is quoted, not assumed. Suites: vllm_kv_group_metadata 9, vllm_allocation_plan_observe 13 (incl. the three new resolution arms), vllm_kv_layout 25, spark_vllm_observed green — no new reds.

* test: the real 262144x6 capture folds end to end — the actual KV_ALLOCATION_PLAN_JSON line off the bounded experiment's launch parses, resolves to the patched source, mints on the engine's own figures, and reproduces the printed 8.41x, with the plan mint's image_digest wall brought in line with the patched emission's contract. THE FIXTURE IS THE ACTUAL BYTES: the captured line is committed verbatim at dag/test/fixture/kv_allocation_plan_emission/glm_5_3_flash_262144x6_2026-09-25_kv_plan_line.log (5058 bytes including its newline, sha256 49917f9a5064dc966ec1c8e6204726dd3cedf3c5a13de4dd76b9eb0ede64c4ce) and shared as test.fixture.kv_allocation_plan_emission.real_262144x6_line.real_262144x6_kv_plan_line so the witness suites have one supplied-value home (length-pinned at 5057 characters against the artifact). WHAT THE REAL BYTES VOUCH, now executed rather than modeled: schema kv-allocation-plan/v1; allocator_blocks 1035; fp8; scheduler_block_size 2304; requested_length 262144; SIX groups — group-0 mla_attention (the 11 sparse layers' indexer.k_cache + attn, 114 blocks x 76032 bytes = 8,667,648), group-1 the sparse-indexer tail (sliding window 4, 1 block), four mamba groups rostering the 34 KDA layers (2 blocks x 1511424 = 3,022,848 each) — 67 identities over 45 layers with per-group max_memory_usage_bytes exactly blocks_at x page on every row; image_digest null, which the mint now reads as the OPTIONAL deployment self-report the patch documents (VLLM_KV_ALLOCATION_PLAN_IMAGE_DIGEST unset at this launch), the corpus mint having been over-specified against the emission's contract — the authoritative image identity remains the receipt's launch executable_digest, and requiring a field the emission does not owe would have refused every launch that omits the knob. THE CONTROL REPRODUCES THE PRINTED CAPACITY OFF THE REAL BYTES: the group figures sum to 123 blocks per full-context request, 1035 / 123 truncates to 841 hundredths against the head's own line at the same launch (pool 2,205,845 tokens, Maximum concurrency for 262,144 tokens per request: 8.41x), and the two sides share no source; the Inconsistent arm discriminates on the real bytes with a garbled 27.55x replay. THE 1035 x 2304 RECONCILIATION, pinned where the control runs: 1035 x 2304 = 2,384,640 is the naive inventory product and is NOT the printed figure — the print is the engine's full-context-equivalent projection, requests x context (1035 / 123 = 8.4146 requests x 262,144 = 2,205,845 tokens); the gap is the per-request non-token content the 123-block charge carries (the mamba states, the tail window) plus group-0's ceil-to-block padding, not scheduler overhead and not lost memory. The admission's receipt digest is the capture's sha256. Suites: vllm_allocation_plan_observe 17 (was 10), vllm_kv_layout 25 — no new reds.

* spark: the direct roster fold consumes the allocation plan — gunbc.spark.arm_memory_fit cache_fit_verdict_from_plan prices the engine's own group figures against every rank's allocator evidence, and the 262144x6 verdict on today's evidence is CacheFitUnestablished naming exactly the three ranks whose KV arenas were not captured, with the block wall proved on every rank and the byte wall proved on the observed one. THE FOLD IS THE PLAN'S SIBLING TO THE LAYOUT FOLD: the layout fold prices per-mechanism rows through the growth taxonomy; the plan IS the exact group roster the doctrine required — the patched emission's groups are the allocator's units and blocks_at_requested_length is the engine's own per-group charge (the arithmetic the plan control reproduced against the printed 8.41x before any consumer may cite it) — so this fold does not re-derive from kind and block size (on the allocation grouping that would double-count: group-0 rosters both the indexer.k_cache and attn entries of each sparse layer) but prices the plan's vouched figures: per-seat blocks are the sum of blocks_at_requested_length, per-seat bytes the sum of blocks_at x page_size_bytes, and the exact-model bind is a census computed from the plan's own layer identities (34 KDA entries across the mamba groups, 11 + 11 k_cache/attn entries in the mla_attention group, 11 tail_cache entries), with the revision wall, the zero-seat wall, the byte wall then the block wall per rank, and the worst-rank headroom on Proved. THE VERDICT ON TODAY'S EVIDENCE: 6 seats x 123 blocks = 738 of the plan's 1035-block inventory (the engine's own figure, computed from the limiting rank and uniform across the TP ranks by construction) — the block wall proves on every rank with 297 blocks (about two seats) of slack. The byte wall: 6 x 20,835,072 = 125,010,432 bytes is 0.52% of TP0/srv9's observed 22.59 GiB KV arena — proved on rank 0; TP1-3's worker lines were not captured (the stop legs fired ~35 seconds after the head's anchor, before the ranks printed), so the byte wall is open on ranks 1-3 and the fold names exactly that — the completing act is one more bounded launch holding the stop legs past the ranks' prints, and the completing arithmetic is pinned at the worst arena this arm has ever read (TP3/srv11's 17.03 GiB from the 64K bundle, a different subject carried as a designed completion, not evidence): six seats prove there with the 125,010,432-byte demand carried. THE HEADROOM, PINNED: the ceiling is floor(1035 / 123) = 8 seats (8 x 123 = 984, slack 51) and the ninth seat refuses at 1107; the printed pool candidate reads floor(2,205,845 / 262,144) = 8 and the fold agrees with the candidate at the floor, while the declared six hold 1,572,864 tokens leaving 632,981 printed tokens and 297 blocks of slack — the candidate stays a sizing hint no verdict consumes. SENSITIVITY, named in the witness: the demand is exact arithmetic (workload x the engine's own layout figures); the arenas are observations at two-decimal GiB rounding that bound nothing until a bounding protocol promotes them; foreign occupancy and fragmentation live outside this subproof's terms (the arm verdict and the supply deductions price them). THE DECLARED CAPACITY INTENT IS UNTOUCHED — the adoption decision on this fold's result is the owner's act, and the persistent apply is not touched. Suites: arm_memory_fit 49 (unchanged), arm_memory_plan_cache_fold 7 new, all green.

* tracker A4: the event carrier is v3 — authors, assignees and return_tos are PrincipalRef event principals, historical v1/v2 email events decode as LegacyEmailPrincipal (readable, never authorizing, never auto-matched), and the assign/comment POSTs record the admitted session's principal through the landed human_write_admission seam

owner ruling 2026-09-25 (docs/plans/human-identity-authorization.md, lanes A4/A5): the event log's principal fields are typed. THE CODEC VERSIONS EXPLICITLY: roadmap-event/v3 is the current wire — author, Claimed.assignee and Claimed.return_to carry the ruling's principal:<authority>/<namespace>/<subject> labels (parsed by the new principal_ref_parse_label in gunbc.principal_projection, fail-closed on malformed spellings), and CommentCreated carries its stable comment id plus parent_comment. v2 (the assignment slice) and v1 stay readable BY READ COMPATIBILITY, never a rewrite: their email strings decode as LegacyEmailPrincipal { email, authentication_unestablished: true } — readable, never authorizing, NEVER auto-matched to a current sub — and each event's id still verifies against the canonical bytes OF THE GENERATION IT DECLARES (re-encoding a v1/v2 event under v3 yields a different id; nothing on disk moves).

THE WRITE SEAM: assign/comment consult the landed human_write_admission (Google OIDC session + action authorization + CSRF + tailnet-path policy); on Permit the author principal comes from the security context — the session's seated PrincipalRef for humans, the one workflow principal for fabric service evidence (a service writer never presents a human session as workload identity) — and the event records it as an authenticated principal. The assignee resolves from the picker's submission: a principal label parses directly, the fabric selector maps by declaration to principal:gunbc/workflows/fabric, and any other email goes through the typed directory lookup — which refuses (none/external/ multiple/unverified) until the A9 directory producer lands, because minting a principal from an email is the banned shape and has no constructor anywhere in gunbc. The comment route records CommentCreated { comment, body, visibility, parent_comment } with the same retry-idempotence (id-present or same-author-body-head refuses the duplicate append).

THE EXTDEPS INTERFACE is reshaped to the ruling: the a3fd5eb QualifiedPrincipal/principal_from_email/subject=email shape is deleted (banned outright), keeping the interface's display vocabulary — the fabric selector spelling, the selector's email-shape validation, the unassigned placeholder, and the avatar display law (resolution chain + never-blocks initials fallback). The page's chips, suggestions and table cell render through the event-principal display projection (fabric wears the workflow badge; legacy rows mark themselves legacy, unverified).

Suites (run 2026-09-25 on this tree): event_log 15/0 (v3 round-trip, malformed-principal refusal, v1/v2 legacy decode with no-auto-match pinned by execution), serve 37/0 (incl. the landed seam's refusal witnesses), page 73/1 (the known witness_ticket_brief_budget_holds_and_reds only). No new reds.

* spark: the bounded experiment's readback phase is per-rank — after the head's anchor leg, ONE readback leg per rank host waits that host's OWN profile line in that host's own rank log, and only when all four readbacks hold do the stop legs run. THE DEFECT IT CLOSES: the 262144x6 run's byte-wall gap — the head printed "Desired GPU memory utilization is (" at 19:41:57 and the one-head collective readback released the stop legs ~35 seconds later, BEFORE ranks 1-3 (srv10/11/12) printed their own per-rank profile lines ("Free memory on device", gpu_worker.py:867) in their own rank logs; commit 0fd1d463f5's fold names exactly that gap as why the byte wall stands open on ranks 1-3, and the completing act it calls for — one more bounded launch holding the stop legs past the ranks' prints — IS this bracket shape. THE FIX, as one execution-cell phase on top of the contract: activation stays the cohort's four non-blocking starts (run 3's repair, untouched); the readback phase then runs the head's anchor leg — pattern unchanged, "Desired GPU memory utilization is (", the same prefix extdeps.vllm.memory_profile parses, so a captured line stays parseable by construction — and ONE LEG PER RANK HOST, each grepping THAT host's rank log for the rank profile line, the same prefix extdeps.vllm.log_lines cites for MemoryProfileSummary. The head's anchor remains the cohort's rendezvous — the head unit's worker is rank 0, so its line carries rank 0's profile — and the cohort contract's observation, one exact generation observed on every rank, IS the four readbacks holding; on the 64K run all four lines printed within one second, which is why the one-head wait accidentally sufficed there. THE RANK LEGS ISSUE ONLY AFTER THE HEAD'S ANCHOR APPEARS — the outcome counts pin the gating: a planted head-readback failure yields 20+4+4+1+0+4 = 33 outcomes (no rank leg issued, because the anchor never appeared), a planted rank failure yields 20+4+4+1+3+4 = 36 with every rank leg attempted and the four stop legs then running as the rollback. A RANK THAT DIES BEFORE PRINTING fails its own host's leg — the script's per-iteration unit-active assertion exits non-zero, exactly as a failed activation leg reports — and the new verdict fold gunbc.spark.native_experiment_apply spark_profile_readback_verdict maps it onto a typed refusal located twice: the member names the host, the variant names the phase (head-anchor wait vs rank-profile wait). The route rolls the started cohort back on a halt exactly as a failed activation leg does (the stop legs are both the deterministic end and the rollback — same legs, because a converged cohort started every member), and the wet entry's failure reason now carries the located halt line beside the full receipt body. THE BUDGET IS THE PLAN'S ONE ADMITTED DURATION, SHARED — never minted per leg: every leg, head's and ranks' alike, derives its poll-iteration backstop from the admission's single admitted_seconds with the identical (seconds + 4) / 5 arithmetic — the same figure every rank unit's RuntimeMaxSec carries — so the cohort is charged one experiment duration in total; a leg's actual consumption is never its backstop (each iteration breaks on its anchor or exits on unit inactivity within one poll, and the sequential waits telescope against the engines' one shared lifetime), and charging the plan's duration four times would count a single run four times. THE ONE SUBSTRATE RECEIPT, named in the code rather than silently routed around: the failed leg's refusal is joined to its leg through the cohort's own key — the host, which execution_cell_cohort_admit vouches unique under systemd_member_key — and NOT spelled zip_map, because measured 2026-09-25 in probe arms (test.claim.spark.probe_readback_verdict_repro, since deleted), a generic function's result feeding first/filter poisons their downstream instantiation in the current interpreter — first returns the bare head instead of the optional it declares, and a filter callback's parameter arrives error-typed — while first and filter over literal/map/filter-built lists behave exactly as declared; that is a sibling of the generic-instantiation classes already rostered under gunbc.recurring_failure_mode (generic_alias_callable_not_instantiated and its neighbors), flagged here for the seed lane rather than half-measured into the ledger from a narrow probe. THE MODELING, named: systemd_execution_cell's one readback script systemd_profile_readback_script is inhabited per host (parameterized member + anchor, so head and rank legs cannot drift); the bracket carries SparkProfileReadbackLeg (member beside plan, so a failure names its host by construction), spark_head_readback_leg / spark_rank_readback_legs, the SparkProfileReadbackVerdict/SparkProfileReadbackRefusal fold, and SparkExperimentRouteResult (outcomes plus the located halt, absent wherever the phase never ran); the admission's collective_readback field is renamed head_readback beside the new rank_readbacks, and the dry entry renders HEAD READBACK then one RANK READBACK per rank host — each carrying that host's log path and the rank pattern, every leg bounded_seconds= the one shared admitted figure — before the STOP block, which the ordering witness pins by exact banner sequence. THE WET ENTRY IS NOT RUN — the owner's go is the gate, unchanged. Suites: execution_cell 20 (was 15), native_experiment_apply 5 (unchanged), native_serving_realization 5 (unchanged) — no new reds.

* docs: the shared-pool byte correction — the 738/1035 block result stands but the 125,010,432-byte fold is withdrawn (~106x wrong): group-spec page bytes are not the shared physical pool bytes per block (vLLM's _get_kv_cache_bytes_per_block; groups overlay one backing allocation, a block ID owned by one group at a time); KvAllocatorCarve vs KvAdmissionDemand split, the plan gains physical_pool_bytes_per_block + allocated_pool_bytes with conservation controls, the block wall becomes authoritative with bytes as a pool-construction check, the cache frontier table (6/738, 7/861, 8/984, 9/1107 refused), the reserve-policy vocabulary (hard ceiling vs guaranteed seats vs burst), mixed-length seat classes through the same plan (no second calculator), and the pre-promotion requirements (prefill derivation, profile-shape binding, falsification run, SLO) (owner directive 2026-09-26)

* tracker A5 surface: the comment stream renders on the detail page — description pinned above the chronological stream (author principal through the display projection with initials fallback, ordinal deep links /issue/<id>#comment-N on the row id and the href, created+edited timestamps, markdown bodies, reply markers, deleted tombstones with the ordinal retained) and a native text/plain composer with key/csrf/expected_revision hidden fields

owner mandate 2026-09-25 (docs/plans/issue-page-architecture.md, lane A5; the production POST stays gated by the landed human_write_admission and refuses until the cookie channel lands — the page surface ships against that seam). THE DESCRIPTION pins above the stream: the roadmap authority rows carry one content string today (the headline), so the description renders THAT until the authority grows a separate body field — the gap is named in the code, never papered over. THE STREAM folds the same durable comment events the v3 carrier records: one row per comment in causal order, each avatar-backed (legacy authors render with the unverified marker, fabric wears the workflow badge — never-blocks law), each carrying its stable ordinal deep link on BOTH the row id and the href, the created and edited timestamps, the markdown body, and the reply marker naming the parent comment's ordinal; a deleted comment renders its tombstone with the ordinal RETAINED so the deep link stays addressed. THE COMPOSER is a native form (honest-before-JS): text/plain with the body LAST (markdown freely carries newlines; the parse cuts at the first body= opener), the key field for retry-idempotence, the csrf field the write law consults, and the expected_revision stale-write pin — the submit wears no .issue-action class so the emitted client's bodyless bind never races the native submit.

Suites: page 75/1 (the two new witnesses green; the known witness_ticket_brief_budget_holds_and_reds the only red), CSS digest re-pinned by execution (76969b74002ce2aa). Parity + serve run on this commit before the pick.

* spark: the completing 262144x6 run lands — the four rank KV arenas are bound as observed intervals at the subject, and cache_fit_verdict_from_plan over them is CacheFitProved { rank: 3, seats: 6 } with the worst-rank headroom carried: the 125,010,432-byte six-seat demand against TP3/srv11's 17.29 GiB arena leaves 18,439,985,704 bytes. THE EVIDENCE: gunbc.spark.arm_memory_experiment_observed carries a second wet receipt bundle, the 2026-09-26 completing launch — the same bounded experiment re-run under the per-rank readback bracket commit c542528314 added, all four rank profile lines (gpu_worker.py:867, 2026-09-26T00:19:24Z, receipt target/spark-native-experiment-apply-receipt.txt) captured where the first launch's early stop legs missed them: TP0/srv9 KV arena 23.45 GiB, TP1/srv10 18.62 GiB, TP2/srv12 18.90 GiB, TP3/srv11 17.29 GiB. The first 262144x6 launch (2026-09-25) printed the KV_ALLOCATION_PLAN_JSON line the fold prices, but its one-head readback released the stop legs ~35 seconds after the head's anchor, before ranks 1-3 printed — commit 0fd1d463f5's verdict named exactly those three uncaptured arenas, and this completing launch IS the act that gap called for. THE BINDING is the 64K bundle's pattern at the new subject: per-rank OBSERVED INTERVALS at the reporter's two-decimal GiB rounding unit, ArmKvCache term, the bound left open, the bundle minting its own subject from the workload the run RAN — six cold seats at 262144 tokens, a 2048 batch ceiling, 8567 basis points, fp8 KV, the group B restoration workload this launch ran at — plus the fold's supply projection at the hundredths floor, the conservative spelling the 2026-09-25-derived supplies carried. THE BUNDLES SUPERSEDE NOTHING: the 2026-09-25 64Kx1 bundle stays stamped at its own subject; the first 262144x6 launch's lone rank-0 reading (22.59 GiB) is not carried — the completing launch's four readings are the one authority this subject stands on; and the cross-launch composition, the plan from the first launch priced against the arenas from the completing launch, is named in the bundle as the designed completion — one experiment, two launches, the second admitted only to capture what the first one's early stop legs missed — not a pairing any consumer may generalize. The run-to-run variance the two launches evidence (TP0 read 22.59 GiB on 2026-09-25 and 23.45 GiB on 2026-09-26 at one subject and configuration) is named so it is never silently folded into a bound: what that variance prices lives outside this subproof's terms, exactly as the 64K bundle's sensitivity note says. THE VERDICT, RE-EXECUTED over all four arenas: the byte wall now proves on EVERY rank — the demand is 67 basis points of the worst arena's floor (TP3/srv11's 17.29 GiB reads 18,564,996,136 bytes at the hundredths floor) and 49/62/61 bp of TP0/srv9's, TP1/srv10's, and TP2/srv12's — and the block wall was already proved on every rank (6 x 123 = 738 of the plan's 1035-block inventory). CacheFitProved { rank: 3, seats: 6, length: 262144, demand_bytes: 125,010,432, headroom_bytes: 18,439,985,704 }: 99.33% of the worst arena remains after the six-seat demand. THE HEADROOM, RESTATED as the Proved verdict's block: the block wall's slack is 297 blocks (about two seats); the ceiling is floor(1035 / 123) = 8 seats (8 x 123 = 984, slack 51) and the ninth seat refuses at 1107; the printed pool candidate reads floor(2,205,845 / 262,144) = 8 and the fold agrees with the candidate at the floor; the declared six hold 1,572,864 tokens leaving 632,981 printed tokens. The reporter's rounding unit cannot move any of it: 0.01 GiB is about 10.7 MB against a headroom of about 18.44 GB. THE WITNESSES: the Proved verdict over the four-arena evidence, naming the limiting rank; the conservation control — drop any one arena and the fold falls back to CacheFitUnestablished naming EXACTLY that rank, the three-unobserved-arenas verdict of 2026-09-25 generalized into a control that must hold in every one of the four positions; the per-rank byte headroom block pinned (49/62/61/67 bp demand shares, 9,932 bp headroom share at the worst rank); and the limiting rank pinned twice over — the observation bundle's rank 3, the host srv11, and the fold's worst-rank corner naming the same rank, so a drift between them is red at the row that moved. A STALE FIGURE, corrected beside the new pins: the block-ceiling witness's "9.5%" was a decimal slip — the eight-seat byte demand (166,680,576 bytes) is 0.9% of the worst arena, and the block wall binds at every seat count through 8 either way. THE DECLARED CAPACITY INTENT IS UNTOUCHED — the adoption decision on this verdict is the owner's act per the 2026-09-25 pre-authorization ("yes if 262k*6 is proved then fine"), and the persistent apply is not touched. Suites: arm_memory_plan_cache_fold 10 (was 7), arm_memory_fit 49 (unchanged), vllm_allocation_plan_observe 17 (unchanged), group_b_serving_capacity 7 (unchanged), execution_cell 20 (unchanged), native_experiment_apply 5 (unchanged) — no new reds.

* roadmap alignment: the typed chain becomes the ONE authority over the alignment answer — AlignmentReady { chain, due_levels, rendered_prompt } | AlignmentUnresolved { cause }, and the refusal-to-neutral conversion is removed at the type level (review finding 2026-09-26, high)

THE FINDING (external review): the alignment module was PARALLEL to execution. alignment_levels() mapped BOTH refusal arms (AlignmentChainAmbiguous, AlignmentChainRowUndeclared) to [] — 'the chain cannot be derived' read downstream as 'no alignment levels are due', the banned refusal-to-neutral conversion (docs/plans/harness-work-lifecycle.md conservation law 2). And the effectful belt never consumed the typed chain at all: the worker brief was built by separate string helpers in roadmap_dispatch_actuator that on ambiguity rendered prose telling the worker to NAME the drift while execution PROCEEDED — two answers to one question, the unsafe one winning.

THE AUTHORITY, this stage (the module and its witness; consumers land in the next stage):

1. THE LEVEL MATH'S DOMAIN IS NARROWED TO THE RESOLVED CHAIN. AlignmentResolvedChain { task, projects, root } IS the AlignmentChained variant's payload under a record type the refusal arms cannot inhabit: alignment_levels and alignment_levels_due now take ONLY that record, so a refused chain can no longer be typed into a levels computation — 'no levels due' is unrepresentable as a refusal reading. The old a_chain_that_refused_has_no_levels_due claim (which pinned the banned []) is deleted.

2. THE RESOLUTION IS THE ONE ANSWER. alignment_resolve_chain(chain, turns_elapsed, state) / alignment_resolve(node_id, turns_elapsed, state) return AlignmentReady { chain: AlignmentResolvedChain, due_levels, rendered_prompt } | AlignmentUnresolved { cause: AlignmentRefusal } — AlignmentChainForked { at, dependents, walked } (two declared owners for one level, docs/plans/one-namespace-hierarchy.md) | AlignmentRowUndeclared { node_id }, each carrying the derivation's facts and named by alignment_refusal_reason. The refusal arms produce NO chain, NO due list, NO render — there is nothing to misread.

3. THE RENDER IS COMPLETE. alignment_chain_render projects every level node to root — the L0 pointer (the continuation lane's authored row, imported), each project level nearest-first with its carried contribution (headline and boundary brief, never a fresh interpretation and never only the immediate L1), the task contract level, and the bounded ask. A projectless node renders the honest standalone shape.

4. THE FINGERPRINT BINDS THE CHAIN. alignment_chain_fingerprint is the Fnv1a64Structural family digest (std.content_hash) over a label-prefixed canonical preimage of every link and the root pointer, so any authority edit that moves the chain — rewired edge, retitled row, reworded boundary — moves the fingerprint with it. Drift detection, not a security boundary.

5. THE ATTEMPT BINDING, at the codec level (the belt consumes it next stage): AlignmentBinding { attempt_identity, fingerprint } on the submission/receipt idiom — schema wall (roadmap-alignment-binding/v1), typed decode envelope, text round-trip.

WITNESSES (suite 32 -> 41, all green): a refused chain resolves Unresolved naming the fork by its dependents and the walked prefix; an undeclared referenced row resolves Unresolved refused BY NAME (arc-missing) and the refusal reason names it; the Ready arm carries the whole answer (chain + due levels + render) in one value; the render lists every level from node to root IN ORDER (the claim walks the rendered lines); a projectless chain renders its own row as the intent; the fingerprint moves when any link moves (retitle, reorder) and is stable otherwise; THE PRODUCTION FORK through the one authority — the real declared edges refuse shell-dag-cron-entry-line-builder at the shell-gate-migration fork naming both dependents, no levels answer existing to be misread; A CLEAN PRODUCTION CHAIN resolves Ready — extended-admission-cardinality climbs accepted-extended-obligation-closure and guarantee-residual-prevalence, every derived level rendered (the roadmap-runtime rows refuse instead, their chains walking through superseded rows: both answers are the one authority reading the live authority); the binding codec round-trips and the schema wall refuses v2 and missing members.

Suites: roadmap_alignment_witness_test 41 (was 32). Adjacent suites untouched by this stage; dispatch and belt consumers land next.

* roadmap dispatch and belt: the brief, the continuation gate, and the supervisor convene consume the ONE alignment resolution — the parallel string helpers are deleted, an unresolved chain refuses the spawn fold with ZERO commands (step "alignment"), and the chain is bound to the attempt identity so a continuation cannot silently use a changed one (review finding 2026-09-26, high)

ONE AUTHORITY, CONSUMED WHOLE. dispatch_brief_for_origin and the spawn fold now take the AlignmentResolution the caller derives from gunbc.roadmap.roadmap_alignment (the belt derives it once per spawn in belt_actuate_spawn_with_origin, off the live authority at the origin's turn; the simple dispatch_spawn_commands entry derives it at turn 1). The continuation preamble IS resolution.rendered_prompt — this module only concatenates; on Unresolved it renders a loud 'Alignment UNRESOLVED — this continuation does not dispatch' marker naming the typed cause (and never dispatches: the gate below fires first). DELETED, so no second answer can exist: dispatch_alignment_project_intent, dispatch_alignment_task_contract, dispatch_alignment_row_text — the string helpers that used to render confident L1 prose for ANY node and, on ambiguity, told the worker to NAME the drift while execution proceeded. The supervisor convene brief consumes the same resolution: belt_supervisor_convene_brief derives it for the node and projects the intent line (nearest project level first, deeper levels carried after it, projectless naming its own row) and the contract line (the task level's carried contribution) from the resolved chain; an unresolved chain names the UNRESOLVED cause in those lines — the fork IS the supervisor's subject, not a guess.

NO REFUSAL REACHES A WORKER-START EFFECT. dispatch_spawn_commands_for_resolved_instance gates FIRST, before destination, brief, or any command: AlignmentUnresolved -> DispatchSpawnRefused { step: "alignment", detail: <typed cause> } — the Refused arm carries no DispatchSpawnCommands, so zero spawn commands exist (no worktree add, no state prepare, no session container). The belt maps that to SpawnFailed at the same step; belt_actuate_spawn_with_origin re-checks the resolution on the Ready path fail-closed, and the binding gate below refuses at step "alignment-binding" before the plan fold.

ATTEMPT BINDING. dispatch_worker_attempt_identity is minted ONCE in the actuator (the spawn argv's --arg and the state's binding file cannot drift). At state initialization the belt writes alignment-binding.json — AlignmentBinding { attempt_identity, fingerprint } at the attempt's own path (dispatch_attempt_alignment_binding_path_for_instance), so the write precedes provider launch and a failed write fails the spawn. Before a CONTINUATION spawns, belt_alignment_binding_gate reads the parent attempt's binding (absence established by listing, never inferred from a failed read) and belt_alignment_binding_check: an absent binding refuses (weaker evidence cannot improve admission), an unreadable or undecodable binding refuses, a binding minted for another attempt refuses (adjacency checked, conservation law 4), and a fingerprint that differs from the chain the authority derives NOW refuses naming BOTH fingerprints — the continuation never silently re-aligns a lineage to a mid-flight authority edit. A fresh start passes (nothing to check); an unresolved resolution defers to the spawn gate so one refusal lands per question.

WITNESSES. Dispatch (50 -> 52): the real forked node namespace-occurrence-transport renders the refusal marker naming the namespace-binding-kernel fork (three dependents) — never 'this task serves project'; a ready chain renders EVERY level node-to-root through the same preamble; project-of-one unchanged; the fresh brief is byte-identical even handed the fixture node's REAL Unresolved resolution (the gate, not the brief, owns fresh refusal); and the discriminating integration control — the REAL producer through the spawn fold with the REAL authority's ambiguous chain (shell-dag-cron-entry-line-builder) answers DispatchSpawnRefused at step "alignment" naming the fork and both dependents, zero commands. Belt (126 -> 134): the convene brief for the production escalation names UNRESOLVED and the fork (the supervisor hears the typed cause); the binding identity is the worker attempt identity; unchanged chain binds; a changed chain refuses naming both fingerprints; an unbound parent, a foreign-identity binding, an unreadable binding, and an undecodable (v2 schema) binding each refuse; an unresolved chain defers through the binding gate; a fresh start passes the real gate.

Suites before/after, all green: roadmap_alignment_witness_test 32 -> 41 (previous stage), roadmap_dispatch_actuator_witness_test 50 -> 52, roadmap_belt_actuate_witness_test 126 -> 134, roadmap_attempt_continuation_witness_test 22 unchanged.

* scm: the envelope save grows a compare-and-set generation guard — a save whose loaded generation no longer matches the on-disk envelope refuses typed (StaleGenerationRefused, both identities carried) instead of silently clobbering, closing the first structural hole of the 2026-09-22 incident, and the load hands every writer the generation of the bytes it decoded

THE INCIDENT (agent-47's diagnosis, classification A): on 2026-09-22 the fmt-gate capture (attempt 2e3b67b4c3e38701) recorded scm_commit_ordinal 1; four minutes later a stale-generation save rewound the envelope to commit-0-only, and no operation reported the loss. The save had no way to say the world had moved. This stage closes that hole; the capture->integrate binding that let the wrong ordinal read as a success is the next stage.

THE GENERATION IDENTITY is a content hash (fnv1a64 structural, the object-identity family's own declared-rung digest, no second authority minted for one compare) of the persisted document's bytes, owned by the format authority as repository_generation_of_content so the loader and the guard derive one fact. It is deliberately over the document BYTES rather than any decoded projection: two byte-different documents that decode to one semantic repository are still two generations, because the guard's subject is the file on disk, not the repository it denotes — a hand edit that preserves semantics still moves the generation, and the next stale writer refuses, which is the conservative refusal the guard exists to perform.

THE GUARD is save_repository_sharded_guarded: encode-checked FIRST (the module's adjudication-ahead law, one level deeper), THEN observe_envelope_generation (absence established by a successful listing, never a failed read; unlistable or listed-but-unreadable fails closed rather than guessing), THEN the write, through admit_repository_generation — the pure, witnessable half: an absent on-disk envelope ADMITS (the first-save path stays admissible, and a vanished envelope destroys nothing), a present generation matching the writer's observation ADMITS, and anything else refuses StaleGenerationRefused carrying BOTH the expected and the found identity, because a stale refusal naming one side sends its operator to compare against a generation they cannot see. The guard's outcome embeds RepositorySave whole so one save vocabulary serves both entries and no consumer matches an arm its route cannot construct — init's fold, the renderer, and the unguarded entry are untouched.

THE GENERATION TRAVELS BESIDE THE ENVELOPE: RepositoryLoaded carries it, because the save must compare against the load's observation — re-reading later could observe a NEWER generation and admit a write derived from older bytes over a newer envelope, the clobber restated. The belt's three sharded saves — seed, capture, integrate — call the guarded writer with the tick's own observation threaded EnvelopeReady -> SeedReady -> delta capture; the guard's stale and unobservable arms classify TRANSIENT there (the next tick observes fresh and re-derives), and a refused save leaves every byte on disk as it found them. repository_convert switches to the guarded writer too: its expectation is the generation of the monolith bytes it just read, so an envelope moved mid-convert refuses as RepositoryConvertSuperseded naming both generations rather than being overwritten by bytes from a world that no longer exists.

WITNESSES. dag/test/claim/scm_repository_save_witness_test.dag grows to nine claims: the pure admission arms over supplied minted generations (match admits, absence admits for both expectations, appeared refuses an absent expectation); the end-to-end stale refusal over a committed v7 fixture — written by the production sharded writer itself — naming both identities with the found side re-derived from a direct read so the claim checks the guard's observation rather than trusting it; the byte-identical claim, read-before/read-after over the fixture (the refused path performs no write — encode, observe, refuse); and the fresh-save claim, idempotent by construction, expecting the generation of the bytes the fixture already holds so the compare-and-set rewrites identical bytes on every run and the read-back asserts them. Whether the required floor admits that one claim's real write stays stated-not-asserted, the standing this file's header already carries for writes in general; every other claim is hermetic. The load witness gains the matching pin: the loaded generation IS the content hash of the document's bytes.

Suites (before -> after, this stage): scm_repository_save 2 -> 9, scm_repository_load 14 -> 15, scm_repository_envelope 70 -> 70, scm_repository_convert 10 -> 10, roadmap_belt_actuate 126 -> 126 — no new reds.

* scm/belt: the capture record authenticates its commit — the capture carries the commit root's content locator beside the ordinal under a bumped v3 schema, and the integrate verifies commits[ordinal].root against the recorded locator before fanin: a mismatch refuses typed (CaptureBindingMismatch { claimed, actual }), a legacy v2 capture refuses as binding-unverifiable rather than being guessed at, and an honest capture integrates — closing the second structural hole of the 2026-09-22 diagnosis

THE HOLE: the capture->integrate binding was a bare repository-relative ordinal, and minted ordinals are per-envelope counters — ordinal 1 recorded against one envelope generation later resolved to a DIFFERENT commit (the cron capture's), so a "successful" integrate could have published the wrong candidate's content while every receipt read honest. The first hole, the unguarded save that let the envelope move under a capture, is closed by the generation-guard commit this lands on.

THE CARRIER bumps to roadmap-submission-capture/v3 and BOTH schemas read. v3 requires the scm_root_locator member and binds it; v2 — the whole population production has written — decodes SubmissionCaptureRootLegacyUnbound, never Bound-by-default, because an invented locator would authenticate nothing and integrate a capture the envelope cannot vouch for. The encoder re-emits each arm under its own schema, so a legacy record this build touches stays a legacy record rather than being silently promoted. Historical captures on disk therefore refuse integrate with the named cause — binding unverifiable — instead of being guessed at.

THE GATE is submission_capture_binding_refusal in gunbc.roadmap.roadmap_submission, pure so the witness reaches every arm: it re-resolves the ordinal against the envelope the integrate ACTUALLY loaded and compares the commit root's digest text — the envelope's own uncontained-root vocabulary, no second rendering beside the codec's. A commit the envelope no longer carries has no resolution to authenticate: the gate passes it through and the integrate's own admissions refuse the missing candidate typed, unchanged from before the binding existed — that refusal keeps the merge base's unwalkable vocabulary rather than a binding-shaped fiction. belt_integrate_into_envelope wraps the gate immediately ahead of fanin_integrate_candidate, so no merge is ever minted against an unauthenticated binding; both refusal arms record an integration-blocked receipt, durable, because a mismatched capture recomputes to the same refusal on every tick until a human looks. The capture site records the locator from the staged manifest the mint consumed — construction over validation, not a re-lookup carrying a dead missing-commit arm.

WITNESSES. dag/test/claim/roadmap/roadmap_submission_witness_test.dag grows by seven: the v3 codec round trip pins the locator; a hand-authored v2 document decodes LegacyUnbound and re-encodes under v2 (the legacy population stays readable and stays honest); a v3 document without the locator is not decodable; and the gate driven over the real scene builders — an honest binding integrates through fanin, an altered locator (the untouched-submission hazard in miniature) refuses with BOTH sides named, a changed commit under an old locator refuses the same way from the other direction, a legacy capture refuses as binding-unverifiable, and an ordinal the envelope lacks passes through to the integrate's own typed refusal.

Suites (before -> after, this stage): roadmap_submission 27 -> 34, roadmap_belt_actuate 126 -> 126, roadmap_attempt_continuation 22 -> 22, roadmap_belt_commit 7 -> 7, scm suites unchanged — no new reds.

* tracker: the detail page takes the mandate's architecture — header chips only, Comments-default…
…due roster by identity (#13022)

* native route: name each refused file; fatal cause leads, head printed as advisory

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refusal summary: group fatal causes by map, not a per-row linear scan

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* seed growth: justify native_file_refusal_summary (gunbc.native_route_refusal_summary_seed_growth)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* refusal summary control: every supplied file exactly once, with dropped-b and doubled-a mutations

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* wip: residue audit by identity

* Advisories step 1: accepted-file advisories counted by identity; residue roster listed by identity

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate stage0 emit_rust mirror for the accepted-file advisory lines

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Advisory rows non-empty by construction (head+tail); declare the advisory decode/summary seed growth (review 74327)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Residue audit: identity carries first sets and a per-production ordinal; positional limit named

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Residue audit ordinal: per-production count map, one probe per row (review 74358)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* chore: regenerate drifted generated artifacts (ci auto-heal)


Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md edited_bin_witness_wet_rows_not_executed_by_ci
Heal-Candidate-Run: 37089709524

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com>
…ne declaration (#12967)

* extdeps scope: retire 45 frontier rows whose subject is the module's single declaration

The 45 kept rows are the modules defining exactly one candidate declaration
(type, data or fn; helper/authority names excluded) -- the rule the 464
hand-adopted carriers already on main follow in every single-declaration case
(114/114, no counterexamples). Multi-declaration modules keep their frontier
rows until each subject is certified by a per-module reading, a split, or a
vocabulary extension.

- manifest 382 -> 337 (single-column frozen artifact, remove-only)
- carrier list 464 -> 509; rosters disjoint; three-way cover holds
- placement-gate route comment corrected (gate is rostered and executing)
- generated mirrors: extdeps_languages_python_types.rs via --regen-round-cost
  (converged; v1_rt.rs/lib.rs byte-identical to main)
- touches nothing outside dag/extdeps, the frontier artifact, its carrier
  roster, the gate instrument comment, and that one mirror

* extdeps scope: tighten retirement to the 10 single-declaration modules; total the placement gate's status match

Per review and floor findings on 0eca339:
- the frontier carrier roster is rebuilt from current origin/main (which had
  migrated more rows in parallel), so no parallel-migration content is
  reverted; the stale inherited carrier row for
  bmc/ipmi_boot_selection.dag (file carries no scope, manifest row untouched)
  is dropped as disk-contradicting
- retirement tightens to modules defining exactly one top-level declaration
  of any kind; ipmi.dag, openbmc.dag, tcgplayer/store.dag and 32 others go
  back to the frozen frontier
- the placement gate's diff-added-paths fold names all nine
  GitDiffChangeStatus variants (no wildcard), per the NonFoldResidue
  affected-set check; no residue roster row needed
- regen: first_generation_equal=true; suite 28 PASS / 0 FAIL

* extdeps mechanism: drop stale non_fold_residue row for totalled placement-gate site

The mechanism commit totalled extdeps_scope_placement_gate.dag's
diff_added_paths_observation (GitDiffChangeStatus match, 9/9 arms), meeting
the row's nfr_dissolve_owning_fold dissolution. Main's roster still carried
the row, which refused merge_group run 37052103708
(NonFoldResidueRosterDiverged stale=1) when composed with the branch.

---------

Co-authored-by: Brian Searls <briansearls1@gmail.com>
* std.fabric_blob: the fabric blob plane interface (exact-key whole objects, sealed FabricBlobReading, put plan with size bound)

Split out of session/royal-moth-86 (#13080) so the bounded local store (C1b) can realize byte parts on it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* std.fabric_blob: state the declared frontier with its trigger; witness address fails closed instead of substituting a digest

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… capture row, collector (#13058)

* SMpro/PMpro internal error records: errmon registers, public decoder, capture row, collector

extdeps.ampere.smpro_register gains the smpro-errmon registers (GPI_RAS_ERR, the
SMpro/PMpro TYPE/INFO/DATA/WARN words, the four event registers), each with its
read safety: the driver clears only by writing (W1C TYPE, write-back events), so
a raw read is inferred non-destructive.

extdeps.ampere.smpro_internal_error decodes TYPE/INFO/DATA into a typed record
(kind, image, direction, location, error code) following ampere-misc
altra-host-error-monitor prepareInternalErrData, with internalErrors.hpp's
image/location/error tables as cited rows at a pinned commit. An unlisted code
is an explicit Undefined arm.

gunbc.machine_intake_mtcollins1_smpro_error_reading records the operator's
2026-10-03 hand read (sha256 of regs.stamped and marker.txt) as raw rows; every
window's record is derived by the decoder. It reads ERR_CCIX_RCA_LINKUP_FAIL (116)
at CCIX initialization (68) on both sockets, not sticky on socket 0.

The boot run's SMpro pass now reads these registers on both sockets, read-only,
TYPE before INFO/DATA, BOOTSTAGE still last; the dossier renders decoded records
and the findings name them.

Public sources only (Linux smpro-errmon @995832b2, ampere-misc @1ecb51ed).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Import filter/any/contains from v2.std.algebra; move the RED fixture comment to module grain

The required floor refused the bare filter in smpro_internal_error (UnimportedBareProvider)
and the parse refused two annotations inside a test body.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* SMpro records pass the driver's GPI_RAS_ERR pending gate; drop the shadowing contains import

Review request: smpro-errmon returns no internal record unless GPI_RAS_ERR bit 0 (SMpro) / bit 1
(PMpro) is set. extdeps.ampere.smpro_internal_error gains SmproRecordGate = PendingAndDecoded |
NotPending | GpiUnavailable (record carried UNGATED) | PendingWithClearOrMissingType |
TypePresentWithoutPending, and the collector and the 2026-10-03 capture both route through it.
Socket 1's capture windows read no GPI, so its CCIX record now stands UNGATED; socket 0's third
window is PendingWithClearOrMissingType. REDs for the last three arms and for the SMpro-only bit.

Also removes `contains` from two witness imports: v2.std.algebra's contains is list membership
with an eq argument and shadowed the string contains (resolve failure on the previous head).

Witnesses: smpro_internal_error 20/20, mtcollins1_smpro_observation 21/21 (BuildBuddy).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regenerate fleet-converge.yml: mtcollins1_boot timeouts follow the larger SMpro read plan

generated_artifact_gate main_wet (BuildBuddy, 22 GiB cgroup) on the main-merged head: job 136 -> 184
and boot step 86 -> 134 minutes, derived from mtcollins1_boot_in_run_smpro_allowance over the 24-register
plan. No job or mode added.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…te was the binding already present (#13076)

* Delete the import-str identity rewire: at a fresh compile every rewrite was the Rc already present

WIP (regen round 1): the .dag and hand Rust only; the generated stage0 follows the regen.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Regen: v1_compiler_infer.rs without the identity rewire

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM name_canonicalisation_depends_on_the_co_compiled_graph: the removal receipt states the unmeasured warm-route memory and its trigger

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* 04_env comment: the kernel-identity consumer list no longer names the deleted rewire guard as live (review 74521)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* RFM receipt: the warm typed-snapshot differential is now measured (srv1): identical answers, no different-declaration rewrite, no memory cost

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
PR-2 now carries no copy of the identity rewire. Main deleted it, and the merge drops PR-2's
view-based version, its unpooled body and its helpers. The one job the rewire's entry point did
for PR-2, re-pointing every view at the graph's ONE surface pool, moves into reconcile ahead of the
parent links. The parent environments those links copy then read the final pool too, so no module
retains its typecheck-time pool snapshot.

Round 1: the stage0 tree is main's verbatim. PR-2's five hand files are withheld until the regen
emits the surface they call.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The merge commit c05a2be carried main's 04_infer.dag verbatim. The resolved file was still marked
unmerged when the round-1 step took main's side for every unmerged GENERATED path, so it was swept
up with them. This re-does the three-way merge (base dd06145, PR-2 b41544c, main) with the same
three resolutions and the final-pool reorder. A per-declaration audit against the base confirms it:
every declaration only PR-2 changed equals PR-2's; typecheck_module is PR-2's plus main's grounding
fold; the rest are the intended deletions.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…on inside a body is refused)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nd Rust re-applied, with the final-pool repoint ahead of the parent links on the assembly route

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Withdrawn by the lane manager's ruling (calm-boar-904, 2026-10-03). This PR exists only for PR-2, and PR-2 is withdrawn as a memory change.

The gate. PR-2 lands only if the floor-subject peak drops by at least 3 GB (neat-boar-16, 2026-10-01).

The reading. neat-boar-16 ran these on srv1 after rebasing PR-2 onto main with #13076. B = main 82558fb; T = PR-2 + this PR + the contested-name table, at 30f261b.

  • Run (1), typed-graph-exclusive-bytes-floor-subject. Joint type_env + cache + interface fell by about 0.50 GB, and type_env by about 0.10 GB. ancestry_entries is equal in both arms, so the two arms answer the same.
  • Run (2), floor-memory-qualification. Same-diff subject, interleaved, with identical plans. Run peak fell by about 0.68 GB.

Why that is the end. Main's own type_env already fell by about 3.1 GB between the two baseline pins. That most likely came from #13076, the identity-rewire deletion; its attribution is being confirmed separately. Either way, on current main the 3 GB gate is out of reach for PR-2. Its remaining saving does not pay for its added representation: a surface pool, closure bitsets, derived views and contested tables.

The branch stays as provenance. The attribution record is #13009.

— sent from calm-pike-525

@gunbai-bot gunbai-bot Bot closed this Oct 3, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Correction to my closing comment. Run (2)'s figure is not a gate read. All four interleaved floor runs refused at the end of strict preparation, before claim evaluation (neat-boar-16). The cause is a main red: two blocking String-type-mismatch diagnostics in src/v2/lens/production_qualification_origin_probe.dag, now routed to the String lane. So the roughly 0.68 GB is the peak at the prepare seam of runs that stopped there, not the floor's run peak. Run (1), the class bytes, is unaffected. The withdrawal stands on run (1) and on the gate being unreachable on current main.

— sent from calm-pike-525

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant