Repository navigation
Floor C1: fixture compiles render only the modules their reader reads - #13037
Conversation
compile_dag_rust_emit_check and compile_dag_diagnostic_census compiled a fixture's live import closure and then rendered Rust for every module of it, though the emit check reads one file and the census reads diagnostics (among them the fixture module's own emit refusals). The render set is now derived from the compiled graph: the fixture's own modules plus the closure module whose emitted path is the read path. No fixture module, or a clean compile that emitted no file at the read path, refuses with a typed FixtureRenderRefusal; nothing falls back to rendering every module. render_selection_agreement_receipt, run by the required floor on every run over RENDER_SELECTION_AGREEMENT_FIXTURES, is the enrolled control: it renders full and selected at the same revision and refuses the floor when the read bytes, the diagnostics, or the narrowing route disagree. Its import-free fixture is the red for the route. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Before/after evidence at one revisionBoth runs are at main
Read from the floor's own carriers (
Top modules by fill, before → after:
Prediction check
Verdict grain (option C). The floor logs refusals per claim and aggregates passes, so equality is read as: identical planned set (664), the same 197 fill claims, |
… (review 74373) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Review 74373: fixed in a489ddb. |
|
Correction to my evidence comment above. "The same 664 claims ran" overstates what I checked. Both runs report |
…me the read diagnostics gunbc#12846 retired std.magnitude, so on main+#13037 the reads_fixture_module fixture no longer compiled and render_selection_agreement_receipt refused the merge-group floor (merge-group run 37094610954). The fixtures now import leaf modules whose retirement would cascade visibly, the coupling is documented, and the read-path refusal names the full render's diagnostics. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Floor repair C1 from #13030 (
docs/plans/floor-time-attribution-2026-10-02.md), redirected by sharp-raven-357's ruling (option A).Derivation (DESIGN §6b)
The brief proposed compiling each fixture against the prepared closure. Re-deriving the chain did not support that:
compile_to_resolved_with_options→emit_resolved_for_target) has no add-one-module seam.with_type_ref_hit_ne_bind_measure, while the census does. And the prepared pool is the gate closure, not the fixture's own imports.The earliest unjustified link is later: emit renders every closure module (
RenderEveryModule), but the emit check reads one file, and the census reads only diagnostics. That is redundant demand (DESIGN §2), and the repair deletes it rather than caching it. Rendering throughRenderSelectedMirrorsis already a production route (required_regen_host).Change
compile_fixture_rendering_only_what_is_readis now the single route for both instruments. Its render set comes fromfixture_render_selection, which derives it from the compiled graph:FIXTURE_SOURCE_PATH;The selection therefore cannot name a module outside the closure.
Refusals are typed (
FixtureRenderRefusal):NoFixtureModuleInClosure;ReadPathNotEmitted: a clean compile that did not produce the path the check reads. Before this change, that case passed as a silentfalse.They surface as
InterpError::FixtureRenderRefused/WitnessRuntimeCause::FixtureRenderRefused. Nothing widens to a full render.The census still renders the fixture's modules. It reads their per-module emit refusals, so rendering nothing would drop them. Whole-graph emit checks (collisions, anonymous records, effectful recursion) run before selection and are unchanged.
Stated narrowing: a corpus module inside a fixture's closure is no longer rendered, so its own emit refusal no longer reaches the census rows or the emit check's hard gate. Corpus emission is the subject of the generated-artifact lanes.
Enrolled control (requirement 2; DESIGN §3 pairing, §4b(4))
render_selection_agreement_receiptruns overRENDER_SELECTION_AGREEMENT_FIXTURESon every required floor run, right after the module-path index warm. For each fixture it renders full and selected at one revision and requires three things: equal read-path bytes, equal diagnostics, and a strictly smaller selected file set exactly when the fixture says it narrows.On mismatch it returns
REQUIRED-FLOOR REFUSAL cause=RenderSelectionDisagreement receipt=… fixture=… read_path=…, naming the first differing byte offset or diagnostic index. It refuses the floor; it never warns. It prints[floor-receipt] receipt=render-selection-agreement …lines.The fixtures:
reads_fixture_moduleandreads_imported_module: these import the leaf modulesstd.magnitudeandstd.error_primitives, and the read-path one readssrc/std_magnitude.rs.import_free_has_nothing_to_narrow: the red for the route.Measured cost, by hand on a remote runner (index already warm): 18ms for all three fixtures (10/5/1ms).
Structural prediction (stated before the confirming run)
compile.emitinside the 14 v1-checker modules'fill_cpu_msshould shrink to the fixture module's own rendering.fixture-render-refusedcause appearing on a claim, which would mean a witness was passing on an absent read path;claim-evaluation-foldCPU not falling by roughly the emit share.Evidence
fixture_render_selection_probe, run by hand with--ignored): bytes equal and diagnostics equal on the sample fixture; full emit 4,845ms against selected emit 24ms.cargo clippy --all-targets -D warningsis clean, run remotely.floorjob. The comparison uses the floor's own carriers (floor-seam-cpu,[floor-shared-fill]) and will be added here. Option C, reading verdicts at claim grain from those two runs, is also pending.Seed growth is recorded in
gunbc.fixture_render_selection_seed_growth. No budget is raised.🤖 Generated with Claude Code