Repository navigation
Floor: derive cross-claim pure-share from planned claims' call-site demand; delete the hand roster - #13043
Conversation
…all-site demand Deletes the hand-authored share roster (575 warm + 5 claim-forced rows, the pending-candidate shape, two collision walls, the seed's plain warm loop) and replaces it with a derivation: - .dag (v2.workflow.floor_pure_producer_share): the observation row type CallSiteDemandObservation keyed by std.computation_identity, the closed cause coproduct CallSiteDemandCause, and the decision fold derive_cross_claim_share (admit a closed identity demanded by >=2 planned claims; decline single-claim, unknown-grade, measured-refused and carried-input producers; count every unadmissible site under its cause, never widen). - seed: claim_call_site_demand observes each planned claim's reach and reads its call sites (one realization of the .dag row type; seed-retained under gunbc.floor_call_site_demand_seed_growth until demand-engine M1.b supplies per-claim call-site demand identity to .dag). derive_and_install_cross_claim_share calls the fold after planning, admits the decided producers at their call sites only, and warms each once in its site module's frame, adjudicated against the preparation limits. - interpreter: site-gated admission (install_cross_claim_derived_share, cross_claim_site_admitted) and warm_cross_claim_call_site; stores stay keyed on evaluated argument values with preimage verification. Refused candidates and carried-input rows stay as identity gates. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttributed hits by key The observer called CallSemantics::target() on a FunctionValueCallSemantics call, which has no static target and panics (floor run 37083945879). Such a site is CalleeUnresolved. Per sharp-raven-357: the shared-fill ledger now renders each unattributed hit as one [floor-shared-fill-unattributed] line per (frame, phase, cache, key) via gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror, so preparation's own reads are answerable by identity. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
call_target matches CallSemantics exhaustively (no target() panic path) and returns a typed cause: CalleeIsAValue for function-value and locally bound calls, CalleeUnresolved otherwise. A panic while reading any site is caught and counted as CallShapeUnread, never a crash and never a skip. Both arms are added to the .dag CallSiteDemandCause coproduct. Control: a_function_value_call_is_counted_as_a_value_callee_never_a_panic. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37087208959 refused CrossClaimShareDerivationUndecodable: the fold's lists come from v2.std.algebra list_flat_map / list_map, i.e. FreeMonoid Cons/Empty chains, and the decoder accepted only kernel lists. Decode through v1_interpreter::list_value_items (free_monoid_to_vec under the frame). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ws only Run 37089182924 (first derived run) admitted 2919 identities; 2807 warmed under 5ms, and their stores plus nested stores exhausted the tier's 4096-entry cap, so every identity claims actually needed was refused (EntryCapReached=1460) and 16+ claims crossed the new-witness budget. - v2.workflow.floor_pure_producer_share floor_cross_claim_share_cost_floor_eval_steps (declared policy, DESIGN section 2's recompute-below-the-cost-floor): a warm measured under it is declined BelowCostFloor and counted. - warm_cross_claim_call_site stores only the producer it warms (CROSS_CLAIM_WARM_ONLY); nested admitted calls recompute, so the measured steps are the warm's own and no entry is spent on an unjudged identity. - After the warm the derived share is re-installed with the retained rows only; install replaces the previous derivation, removing dropped producers from the roster so none stays admitted without its site gate. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Agreed with royal-moth-86 (cache program): each closed identity becomes one FrameDemand per demanding planned claim at its claim frame under preparation, judged by std.materialization_ladder group_verdict against the existing cross-claim CacheProvider (MemoTier ContentKeyed, preparation scope). Two or more claims are AuthoredDuplication (the carry is owed; the warm is the carry); one claim is AcceptedSingleRecompute (DemandedByOneClaim); any other verdict is carried on the decline (LadderOwesNoCarry). Observation rows now carry the demanding claim identities instead of a count. The frame path, the tier retention and the provider (cross_claim_share_provider) move into v2.workflow.floor_pure_producer_share as their single authority; v2.workflow.floor_prepared_effect_input_ladder now covers the carried identities with the same provider. The cost floor is documented as DESIGN s2's economic realization after the ladder, not the ladder's below-floor exemption (which the ladder applies only below an isolated LCA). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sharp-raven-357 ruling A: recurrence is a fact about the declared subject, so the observer walks every claim declared in a prepared module and each row carries its declared claims plus how many are planned. The ladder judges the declared demand (deterministic per claim: the same on main and on a PR that plans a narrower set); the fold declines ReachedByNoPlannedClaim so nothing is warmed that no planned claim in this run can consume. Reason stated beside the observation row type. Controls: two_declared_claims_with_one_planned_is_admitted, declared_demand_no_planned_claim_reaches_is_declined_and_named, and the seed's declared_unplanned_claims_count_as_demand_and_are_not_counted_planned. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eclared cost debt Run 37096345499 (f64b8f9): with recurrence counted over declared claims, the class-1 claim (btar) passes; 20 claims remain over the new-witness budget, each the ONLY declared claim reaching its front-end fixture producer, which the deleted roster warmed in preparation (DESIGN s5 externalization). Per sharp-raven-357's ruling each is dispositioned individually: supplying normalized front-end subjects as literals is not practicable in this change, so each is a declared cost-debt row (v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22, measured eval steps beside each) with the per-claim trigger being the s3 witness rule. The coverage loss is a declared s4b(3) drop: gunbc.rung_drop.derived_share_single_claim_fixtures_withheld (rostered; docs/design-rung-drops.md regenerated). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13029) appended the warm row v2.test.claim.body_lowering.if_arm_position.iap_verdicts to the hand roster this PR deletes. Resolved to this PR's side: iap_verdicts is a nullary producer demanded by its four declared claims, so the derived share admits it by recurrence (no row needed); its disposition is read from the next floor run. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Unadmissible sites with a known callee (open argument row, effectful callee) are also aggregated per (producer, cause) and printed as [cross-claim-share-unadmissible] lines, so each deleted roster row's disposition is readable by identity: admitted, declined, open/effectful, or outside the run's subject. The .dag rows stay aggregated by cause. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main added 53 hand warm rows (#12506's 44 and #13050's) to the roster this PR deletes. Resolved to this PR's side; each row is dispositioned from this head's floor run (derived, or a single-declared-claim fill reported to its owning lane, calm-boar-904, for the s3 supply-the-inputs restructure). Two comments in main's new test modules that cited the deleted roster are rewritten. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion, wall-excused in flight Same-revision A/B (PR run 37104970794 vs baseline dispatch 37105064700, both at main 3a22bc2) showed the warm pass costing more than it saves: the derived warm seam took 133.5s thread CPU against the old roster warm's 53.0s, with the claim-evaluation fold unchanged (735.7s vs 731.9s). Most of it was 169 evaluation frames built only to warm 2523 identities, 2404 of which were then discarded below the cost floor. - No warm: an admitted site fills on the first planned claim that evaluates it. Its eval steps are netted from that claim by the existing fill guard (deterministic budgets). - Its wall is excused from the claim's wall deadline while in flight (in_flight_cross_claim_fill_wall_nanos), capped at the preparation wall safety limit so a runaway fill still interrupts: the wall sibling of the existing CPU-deadline FillBudgetExceeded netting. - The declared cost floor is applied to the fill's own steps at retention (CrossClaimStoreOutcome::RefusedBelowCostFloor, counted). - Deleted: warm_cross_claim_call_site, CallSiteWarmRefusal, CROSS_CLAIM_WARM_ONLY, and the observer's site-node bookkeeping. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Same-revision floor comparisonMethod. merry-koi-266's #13037 recipe:
Verdicts. The two runs agree on everything below:
Share-related thread CPU:
Structural prediction, checked over the 195 fill-paying claims common to both runs:
What the comparison caught along the way. The first derived head warmed every admitted identity during preparation. Its same-revision pair (37104970794 vs 37105064700, at main 3a22bc2) showed that seam costing 133.5s against the roster warm's 53.0s:
97f1921 removes the warm pass:
Preparation-read concern. The per-key Roster dispositions. These are pending a planning probe. Dispatch 37112519045 runs on a measurement-only branch that touches the 111 test modules behind deleted or main-added roster rows, so the floor plans their claims. Until then, from 37109381438:
The probe settles the 538 outside-subject rows by identity, and it lists any single-claim claim that goes over budget once its row is gone. — sent from royal-deer-478 |
Conflict in v2.workflow.floor_pure_producer_share: main (#13010) added one more hand warm row to the roster this PR deletes; resolved to this PR's side and recorded for disposition. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Planning probe 37114012751 (all 111 roster-row test modules planned) showed 59 claims each re-preparing the grammar (prepare_grammar, ~1.8M steps / ~4.9s per claim): the derivation also admitted v2.compiler.parse.prepare_grammar at its closed-argument sites, which put its node in the site-gated set and withdrew the built-in arm's admission at every other site. install_cross_claim_derived_share now gates only producers the derivation alone admits; the built-in prepare_grammar arm and roster (carried-input) producers keep every site. Control: a_derived_admission_never_gates_a_producer_already_admitted_ungated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13053) added four hand warm rows to the roster this PR deletes; resolved to this PR's side and recorded for disposition. The new value_base_projection test's comment citing the deleted roster is rewritten. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lared cost debt The planning probe (dispatch 37121610250: every test module behind a deleted or main-added roster row planned, on the site-gate-fixed head; control 37117342059 at main 2d8bfeb with the same touches) finds 25 claims over the new-witness budget only with the roster deleted (two materially worse), each the sole declared claim of its fixture producer. Per sharp-raven-357's class-2 ruling they are declared cost debt (floor_cost_debt_proven_chunk_23, measured steps beside each, trigger the s3 witness rule) and join the population of gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. The probe's four failures fail identically at main (pre-existing reds that only run when their modules are touched) and are not this change's. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37125103721 refused: floor_cost_debt_roster duplicate withheld identity reference_conservation.a_string_literal_is_conserved_by_its_value_holds, already in chunk_22 and re-added to chunk_23 from the planning probe. Removed from chunk_23 and from the second mention in the rung drop population; docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Only docs/design-rung-drops.md conflicted (generated); regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13051) added one hand warm row (if_arm_reader_differential.iard_fixture_censuses) to the roster this PR deletes; resolved to this PR's side and recorded for disposition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
review 74858: the population spans floor_cost_debt_proven_chunk_22 and chunk_23 but the trigger named only chunk_22, so the 24 chunk_23 rows could never retire it (DESIGN s4b(3): a plural loss with a singular trigger). The trigger now names both chunks and states that the row retires when every claim in the population has left its chunk. docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…per claim sharp-raven-357 ruling A. The full planning probe (PR 37131459602 vs main 37131472056, every test declaration in the roster-row modules planned at one revision) found 344 claims over the new-witness budget only with the hand roster deleted, each the sole declared demander of its fixture producer: most of the deleted roster billed a claim's own fixture to preparation rather than sharing anything. - v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt: a monotone debt set, 345 claims in 69 modules, generated once from the probe and marked so. Standing is ActiveFillDebt or RetiredFillDebt with a typed disposition (RestructuredPerWitnessRule, BecameSharedByDemand, ClaimDeleted). - derive_cross_claim_share admits a one-claim identity only when its sole claim is an active member, with basis SingleClaimFillDebt naming the claim; a shared identity keeps basis SharedByDeclaredDemand. The claim's own fill is then netted from its budget by the existing fill guard, so the claim keeps running. - The seed realizes the identity join: a planned active member with no admitted fixture identity refuses SingleClaimFillDebtStale. - One mechanism: the 45 claims first withheld as cost debt (floor_cost_debt_proven_chunk_22/23) and their rung drop are removed, so their verdicts return. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merge: main added four hand warm rows (infer_fold_member_instance fmi_*) to the roster this PR deletes; resolved to this PR's side, recorded for disposition, and the new test's comment citing the deleted roster rewritten. Probe 37137409052 showed 345/345 debt members planned and billed, yet 106 of them still over budget with no fill row: an admitted fill whose store the tier declines stays on the paying claim, and nothing printed it. The floor now prints one [cross-claim-share-store-declined] line per (producer, cause) -- including the recompute-ledger branch that returns without offering the fill to the tier (RecomputeKeyUnavailable) -- and a [cross-claim-share-tier] totals line. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13113, #13056) added three hand warm rows (elif_verdicts, bhr_verdicts, trt_verdicts) to the roster this PR deletes; resolved to this PR's side and recorded for disposition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Roster file keeps this change's side. Main added sixteen roster rows (#13187: gfi_*_reason in v2.test.claim.compiler.generic_formal_instantiation); their module is probed next. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…, from probe 37238532455 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Re-read by sharp-raven-357 at d0a206d (both current-head reviews timed out with no verdict). Since my APPROVE read at 2fa5771, the PR's own diff against its merge base is unchanged in every file except floor_pure_producer_share.dag, where the only addition is the generic_formal_instantiation fill-debt module (12 ActiveFillDebt claims for #13187's rows, cited to probe 37238532455). The interpreter delta is identical to what I read. APPROVE. — sent from sharp-raven-357 |
|
Correction to my earlier read (sharp-raven-357): codex review 76009 is right and I missed it. Digest-only matching of served arguments relies on a 64-bit FNV digest, which isn't collision-safe, so it drops the preimage verification the old structural comparison gave. Dequeued for an instance-identity fast path with structural fallback. — sent from sharp-raven-357 |
…ever by digest alone Review 76009: cross_claim_entry_matches accepted a served composite argument on equality of portable_value_digest, a 64-bit FNV hash that is not injective, so a key-plus-digest collision served another call's value (a section 4b(3) regression from the structural check it replaced). Each entry now records the ServedInstanceKey each argument was stored as; a served probe matches only the same instance, and otherwise falls back to portable_value_eq over the argument reified at most once per lookup. The digest stays as a pre-filter that can only rule a candidate out. Control: two_values_sharing_a_digest_are_not_served_as_one_another forges an entry with the probe's digest over a different value (refused), plus the same-instance (hit, no reify) and equal-value fallback (hit, one reify) arms. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Read of the collision fix at 628b258 by sharp-raven-357 (review 76111 approved but didn't discuss it). APPROVE. cross_claim_entry_matches for a served probe: a digest mismatch rejects (sound, since equal values have equal digests, so the digest only rules OUT); the same recorded ServedInstanceKey accepts (exact, since registered instances are retained for the tier's lifetime); otherwise it falls back to portable_value_eq on the caller's argument, reified at most once per lookup. A digest match alone never accepts. Codex 76009's finding is resolved, and the forged-digest control covers it. — sent from sharp-raven-357 |
…path claim as single-claim fill debt (sharp-raven-357) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Applied this branch's net diff over d0a206d onto main; xl2 nested claim taken from main (renamed, inverted), pointed at xl2_nesting_run, debt row renamed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… hand warm row #13043 deleted the hand-maintained floor_cross_claim_pure_producers_warm roster: cross-claim sharing is now derived from planned claims' call-site demand. dag_prepared_lex is a nullary producer of a portable value demanded by many claims, so the derivation shares it; the row and its comment go. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The 24 #12506 witnesses are restructured per the DESIGN section 3 witness rule, so their single-claim fill debt retires by typed disposition: RestructuredPerWitnessRule for cref (6), fps (10) and dre (4); BecameSharedByDemand for mbt underived_arm_body and sevens_call; ClaimDeleted for fps_a_root_bound_data_value_is_not_yet_projectable_holds (replaced on main by the projects positive control after #13216). mbt hiding and dre imported stay ActiveFillDebt. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…in's #13043) #13043 added floor_seam("cross-claim-share-derivation") to the floor runner without a FloorSeam arm or a FloorSeamToken row; main never runs the unit lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation, its token row, and its arm in receipt_peak_seam. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…#12951) * Regenerate docs/design-rung-drops.md after merging main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: the base arm runs only the reached claims whose head can block reach_head_cannot_block is derived from claim_differential_blocks over every base arm. A passing head never blocks, and a head where the claim is no longer declared is a removal under every base, so neither is run at base. The base arm then runs only the claims that FAIL at head: 60 of 1481 for a one-line v2.std.node edit and 18 of 240 for #12582's change (srv1, 2026-10-01), about 25x less base work. An all-passing reach spawns no base process. Controls: a_head_passed_claim_is_never_run_at_base_and_never_blocks (Rust, real model: the partition sends only the failing head to base, and a passing head blocks under no base) and only_a_failing_head_needs_the_base_arm (.dag). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitted-package join also matches canonicalized paths, so a symlinked crate dir cannot undercount (review 73526) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: the base-arm budget is born typed Milliseconds (review 73528) ReachDifferentialStanding's DifferentialBlocking carries base_arm_wall_budget: Milliseconds (std.types) instead of base_arm_wall_budget_ms: Int, and the host wire reach_differential_blocking_budget returns Milliseconds, so the unit is the type's and not the name's. The branded value reaches the host as Value::Int, which the existing non-negative match unwraps; any other shape still refuses. The sibling required_floor_claim_wall_safety_limit_ms stays as existing debt, not widened here. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: per-identity base verdicts; an unmeasured base blocks only when no roster declares the claim red A non-verdict base outcome (budget, panic, host tool or effect, not attempted) is now not_measured for that identity alone; the other reached claims keep their verdicts (srv1 replay 4d79fc6: one BudgetInterrupted claim voided all 60). Only instrument failures refuse the whole arm. reach_claim_verdict takes the claim identity. An unmeasured base on the declared main-red roster (floor_expected_red_roster, joined by identity) is a counted base_not_measured_rostered finding that does not block. On no roster it BLOCKS as base_not_measured_unrostered (deep-ferret-305 ruling, 2026-10-01). A base verdict decides as before. Control: an_unmeasured_base_blocks_only_when_no_roster_declares_the_claim_red (.dag: rostered reports, unrostered blocks, a base verdict still decides). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: planned on the merge group only (operator ruling 2026-10-01), modeled, announced when deferred, naming what newly failed - v2.workflow.floor_subject_seed reach_planned_for_event decides, over the event the runner reads through the authority that chose its diff window, whether reach consumers are planned: ReachOnMergeGroupOnly, compared against extdeps.github.actions github_event_name_merge_group. This is the phase scoping DESIGN puts in the binary, not the workflow YAML. An unreadable event refuses on CI (ReachEventUnreadable) rather than silently deferring. - On any other event no reach consumer is planned or executed (PRs +0), and the floor prints phase=reach-differential state=deferred_to_merge_group with the count it would have reached. - A blocking regression or failing new claim prints [floor-reach-finding] NewlyFailedAtHead identity=..., so a dequeued author sees what broke without rerunning. Controls: only_a_merge_group_plans_the_reach_differential (.dag, both directions) and a_pull_request_defers_the_reach_differential_and_a_merge_group_plans_it (Rust, real rule plus the deferral line). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR: enumerate the three qemu-host-observe readiness arms main added since (census PR1/3) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: blocking verdicts are a typed outcome field the adjudication names, not free text in failures neat-boar-16's srv1 control (2026-10-01) showed blocking=8 but no per-identity adjudication line for them. RequiredFloorOutcome gains reach_differential_blocking: Vec<(identity, differential)>. required_floor_outcome_is_clean requires it empty, and required_floor_measurement_blockers adds one blocker per identity with cause reach_differential_<differential> (regressed, new_claim, base_not_measured_unrostered, refused). A refused base arm records every claim it left unjudged as base_arm_refused. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: both main-red rosters; a non-verdict at head is not_measured, never failed; one shared test pool - claim_on_declared_main_red_roster joins floor_expected_red by identity AND gunbc.explicit_witness_admission's known-red rows by (entry, function), through that roster's own explicit_witness_admission_is_known_red. On the srv1 control rerun three known_red_probe map_literal claims had blocked as unrostered; they now report. - The head standing uses the base arm's classifier (base_standing_of): a wall interruption at head under load is not_measured, verdict head_not_measured, never sent to base and never read as a regression. It was matches!(Pass), which made a passing base plus a loaded head a false regression. The floor's own interrupted_before_verdict rule still refuses such a run. - The base-only residual is named beside the rule: an unrostered claim whose base lands within load noise of the 8 s hang guard dequeues load-dependently (loud, named). Its trigger: the hang guard gets its own typed refusal and a much larger declared value through one plumbing for both arms. - reach_base_standings tests share one pool (test_roots): the process-global shared index holds a single resident pool, and the fixture test's extra root made test order decide a SharedIndexSecondResidentPool panic. Controls: an_unmeasured_head_is_not_a_regression (.dag); the roster control extended with the explicit-admission arm; the partition test with a not_measured head. Rust 5/5, .dag controls true, clippy clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: locate floor runtime-error rows; typed host IO refusal * Floor runtime-error rows carry message + raising declaration; host write failures are a typed IO refusal Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * RFM: portable value map order is process-random (RandomState HAMT iteration; Symbol hashed by address) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Portable map entries in canonical content order; value_hash hashes variant names by spelling; RFM row scoped by the iteration and value_hash censuses, with the DefaultHasher residual Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * emit-host transport read failures are HostIoFailed too (Cargo config read, tool canonicalize/read, cold receipt read, cache evict); probe spawn via host_tool_spawn_failure Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Review 73653: seed-growth justification for the canonical-order Rust; the row states its controls are off the merge path Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Canonical order: floats by IEEE 754-2019 totalOrder (f64::total_cmp), not raw bits, which invert negatives; control floats_order_by_ieee_total_order Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Six ungated main reds re-derived; three entries admitted by importing LiveTreeDisposition (1)(2) live_deploy.emit sudoers claims: the needle is now the install's own node (gunbc.ci_deploy_sudoers deploy_sudoers_elevated over the fleet visudo row) rendered by the same serializer. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). The two probe negatives are deleted: unmatchable under quoting, and since #12168 those probes are emitted on purpose after the install. (3) twin claim: count equality replaced by an identity join on artifact kind, host singletons (fabric storage + #12747's approval broker front door) subtracted by the functions that decide them. (4) CPUQuota grant: sudoers side read through sudoers_argument_word (escape since #12563). (5) tasks verdict: bare `Absent ==` never named the ConvergeVerdict arm; typed match + a Drifted discriminating conjunct. (6) runner_lifecycle: fabric rows from srv3/srv4_fabric_first_slot, each controlled by the slot below it on its own host (srv4-06 is fabric since 2026-09-18). Admission: build_cache_endpoint_observe, ci_budget_tree_witness, host_allocation_conservation import v2.std.live_tree (the #12540 class #12819 fixed once); variant rows retired ImportsFixed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * ci_budget_tree_witness: three live-tree reds were stale premises; re-derived from the producers witness_live_is_fail_closed asserted the Unestablished arm while srv1 now resolves ReservationBytes; it asserts each arm's relation over session_reservation_bytes(srv1). witness_srv2_symmetric_to_srv1 assumed equal RAM (srv1 is 512 GiB since 2026-08-22; usable RAM per host since #11625); it asserts the pools differ by exactly the RAM gap. witness_srv3_outbudgets_srv1_by_exactly_the_overhead_gap missed the 1,392,640-byte usable-RAM difference; gap = overhead gap + RAM gap, both read from the producers. Removed from floor_expected_red_chunk_live_tree_admission (they now pass). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Floor: unimported-bare-provider standing judged over the whole pool, not the diff; census fixed The diff-scoped standing check let #12540's new pairs in untouched files through while claim_batch's entry route refused them. The floor now judges every pool file (13.6 s over 7,175 files on the warm index, measured). Census at this base: 172 Unrostered + 16 RosterStale. Fixes: 167 pairs import their declared provider (138 files; no new import cycle), 5 bare `ends_with` calls that bound to gunbc.rust_item_scan's private helper use the builtin .ends_with(suffix:) method instead; 16 + 344 rows whose pairs the imports dissolved retire as ImportsFixed. Re-census: zero refusals. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * std.algebra: TotalOrder<T> is the one compare law; OrderedRing and Field compose it (WIP) * Interpreter: one canonical content order (ContentView over Value and PortableValue); map Display/Debug canonical; sort_by admits only emitted-agreeing keys; cmp_values deleted (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Canonical render order: emitter refuses map rendering typed; to_string classified CanonicalOrder; two-process, kind-rank, totalOrder and carrier-differential controls (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Rows: RFM rendering receipt and per-path rung; spelling stand-in on variant_owner_identity_stall; seed-growth row extended (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Witness: emitted map rendering refused typed; to_string classified CanonicalOrder by the gate route (WIP) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Gate comment names the phase line instead of transcribing its measurement; phase line carries standing_ms (review 73712) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v2: production list order from map_keys -> sorted_map_keys (target_model supplemental-bound and representation-choice nodes, rust_crate_partition first-unknown module, legacy_binding_observation expected ids) The #12890 warm-row specimen: rust_classical_not_ingested_target_model_staging varied per process because target_derive_supplemental_generic_bound_requirement_nodes_for_contract built its child list by folding map_keys (HostUnspecifiedOrder). Keys are Symbol/ModuleId/Int, all admitted by sorted_map_keys, whose order is identical in both realizations. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Drop determinism_transitive_reachability: population names the unjudged production corpus; receipt for the six map_keys folds found by the #12890 specimen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitter: a single-field anonymous record literal matching 2+ structs refuses instead of emitting the bare value; VersionScheme literals name their type; revert stage0 files swept in by an interrupted regen std.algebra TotalOrder gained the same single 'compare' field as extdeps.version VersionScheme, so find_unique_struct_name_by_fields stopped being unique and '{ compare: f }' emitted 'f' -- a fail-open arm (DESIGN section 5). It now refuses exactly as the multi-field arm does; the three VersionScheme literals carry the nominal type that remedy names. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Split the two cost-debt-rostered sudoers claims out of this PR The floor's changed cost-debt edit judgment lexes the whole 125 KB emit_test.dag at base and at head per identity in the interpreter; with these two identities changed, site projection ran past the 90-minute cap (run 36856989404). Their fix moves to its own PR, held on that floor defect. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * live_deploy.emit sudoers claims: needle is the install's own node; unmatchable probe negatives deleted Split from #12905. Stale since #12602 (/usr/bin/sudo) and #12525 (bash builder quotes every word). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitter annotation moved to module-item grain Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Retire the one row main's merge made stale (ownership_movable_test#Read); re-census over 7,193 files: 0 refusals after this Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 (std_algebra, std_primitive_projection, v1_compiler_emit_rust); control: supplemental-bound requirement nodes emit in canonical parameter order (the #12890 specimen at its cause) regen-round-cost converged in one stage, changed_paths=3. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Floor cost-debt edit judgment: one lex per changed file, shared by every identity in it v2.workflow.floor_cost_debt_edit judged each changed cost-debt witness in its own call, and each call lexed the whole base and head file, so a file with k changed witnesses paid 2k lexes. With two changed witnesses in the 125 KB emit_test.dag, site projection ran past the floor's 90-minute cap (run 36856989404). The wet entry is now cost_debt_changed_witness_ceilings_at_base, called once per file with every changed cost-debt function in it. It lexes base and head once, reads the base resolution once, and selects each declaration from those streams. The host prints `[floor-cost-debt-edit] judgments= changed_identities=` as the control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Pin PlannedAsReachConsumer as not a changed-witness selection in the sublane join Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * clippy: redundant closure in the per-file ceiling call Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * v2.std.integer: int_ordered_ring composes order: TotalOrder (OrderedRing no longer restates compare/lt/le/gt/ge) Control supplemental_bound_requirement_order: requirement_nodes_are_emitted_in_canonical_parameter_order returns true, and false with map_keys restored at the outer fold (discriminating). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md (docs_projection_gate regen) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a raw string literal opened in a body is tracked; an unattributed refusal names its cause The census could not judge gunbc#12886 because the scanner tracked raw string literals only when opened on an item header. A `let src = r#"...` fixture in a body let its own column-zero `}` close the fn early, and its `"#;` then refused the file (interp_recorded_fixture_witness.rs:458). The same shape put 5 of the 9 hand files on main out of reach. An item ends at its own closing brace, and a brace inside a literal is not one: every item line is now read for an unclosed raw literal (token-start `r`/`br`, terminator from its own hash count). Only a header-opened literal's end may end the item. v1_interpreter.rs was never unscanned: the scanner reads it whole (1040 items, 36 macro regions) and attributes #12814 completely. #12886's v1_interpreter refusal is a line inside `thread_local!`, the declared macro-item ceiling, but it was reported with the out-of-range sentence. The refusal now names which cause fired. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs/design-rung-drops.md after merging main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * RFM: anonymous_record_resolved_by_field_names_guesses_on_ambiguity (the emitter one-field fail-open TotalOrder exposed) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Reach differential: DifferentialBlocking per the operator's 2026-10-01 option-B ruling Base-arm budget 625200 ms: the largest srv1 base arm measured (312.6 s for 22 identities, loaded host) times 2 for load variance; an arm over it still refuses with BaseArmOverBudget. PRs still defer to the merge group. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: an expression-bodied item ends at its own semicolon; a backslash-continued line is string text A `static NAME: T =` header that rustfmt continues before its initializer puts the declaration's `;` one indent deeper, so the item stayed open and swallowed the following items until a column-0 `}`. That was a SILENT mis-attribution: cli_run.rs `static PROVIDER_BOOTSTRAP_STORE_SKIPS` absorbed `fn record_provider_bootstrap_store_skip`. Across 22 hand files, about 125 items were never recorded, 7 of them in v1_interpreter.rs (record_builtin_time_inclusive, canonical_symbol_spelling, ...). An item whose header ends at `=` now ends at the continuation-indent line that ends the statement. A line after a trailing backslash is string-literal text at whatever indent its author chose, never structure. The line that ends such a literal with `;` ends an expression-bodied item; ExprBody is read from rust_item_forms, not listed here. No item key is lost in any hand file, and the refusal count is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_host_observation: carry the refusal from the one attribution; RawLiteral replaces terminator+flag Review 73783 found that change_lines_unattributed reduced each attribution to a line number, and unattributed_line_detail recomputed it. That was the same fact derived twice (DESIGN §2), and the recompute needed two arms that wrote a fabricated sentence (DESIGN §5). change_lines_unattributed now matches once into RustLineRefusal, which has only the two refusing arms (LineInsideUnnamedMacroBlock, LineBeyondTheFile). The detail is read off that value, so the record and its sentence cannot disagree. Also from the review: ItemScope's raw_terminator + raw_opened_on_header could represent "opened on the header with no terminator". They are now one variant, RawLiteral = NoRawLiteral | OpenRawLiteral { terminator, opened_on_header }. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * std.algebra: the TotalOrder comment names the real (seed-retained) realization instead of a symbol that does not exist (review 73794) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Emitted ordering keys fail closed: v1_rt CanonicalOrdKey (String, i64, bool only) bounds sorted_map_keys and sort_by; sort_by drops partial_cmp(..).unwrap_or(Equal); enrolled one-order claims; seed-growth trigger names the capability and first consumer neat-boar-16 conditions for executed agreement on #12925: (1) enrolled claims test.claim.canonical_order_enrolled_witness; (2)+(4) trigger at capability grain naming the first real consumer; (3) the emitted frontier refuses non-admitted keys typed (on_unimplemented message). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a static inside thread_local! is a named item, by upstream citation extdeps.rust.std_thread_local records std's thread_local! as the pinned 1.93.0 docs state it: the macro "wraps any number of static declarations", and "Publicity and attributes for each static are allowed". The scanner reads a thread_local! block as a scope that admits exactly those lines. Each static is an item of the enclosing module, so a change inside one is attributed to it by name. Anything else in the body refuses, and so does a one-line thread_local!(...), which this reader cannot split. Every other macro stays at the declared macro-item ceiling (macro_rules! controls). On #12886's tree the census now observes the change completely: JSON_ENCODE_NESTING is an added static, and the only unreadable hand file left is phase_profile.rs (extern "C"). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rust_item_scan: a header at the open item's own indent refuses; a trailing comment does not hold a declaration open The swallow class becomes structural. Whatever leaves an item open past its end -- a continued initializer, a trailing comment, an ordinary multi-line string, or a construct not yet met -- next meets a sibling item header at the open item's own indent, and no item body puts one there. scan_step now refuses at that header instead of reading it as body. Under the prior reader that refusal fires at the original swallow sites in cli_run.rs and v1_interpreter.rs. A second instance surfaced by the same measurement is fixed. A one-line declaration followed by `// comment` did not end in `;`, so it stayed open and swallowed the next const (resolved_graph_cache.rs PART_DESCRIPTOR_LEN over V3_HEADER_LEN). A `//` with an even quote count before it now starts a comment. Files the recurring failure mode as its general class, gunbc.recurring_failure_mode census_instrument_silently_drops_items: a census instrument whose parser silently drops items reports a smaller population, and a short count reads as success. Its distinguishing fact is that a swallowed item's lines ARE attributed (to the swallower), so a line-coverage join passes. The violated join is header coverage. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 (whole-compiler rebuild: runtime CanonicalOrdKey reaches v1_compiler_stage0_crates) --regen-round-cost refused with WholeCompilerRebuildRequired (partition generation authority changed), so candidates were emitted with --required-regen, installed, the whole compiler rebuilt, and --required-regen re-run: first_generation_equal=true over 161 planned. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Enrolled one-order claims import empty_map/map_insert from v2.std.collection (floor UnimportedBareProvider) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Name the instrument instead of transcribing the probed RAM gap (review 73848) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Merge group: the floor window's base is the group's own parent (merge_group.base_sha), never origin/main #12514's first live merge_group run (group head 529d438) compared against main 8a249e7 and charged the four PRs queued ahead (#12921 #12735 #12770 #12905) to this landing: three order-edge claims from #12770 read as regressed. - extdeps.github.merge_group_event: cited payload reader for merge_group.base_sha and the merge queue's group-composition guarantee (cited), consumed by the resolver. - gunbc.diff_baseline: MergeGroupBase arm; merge_group resolves through resolve_merge_group_base, which REFUSES on an absent/empty/unreadable/malformed base_sha and never falls back to origin/main. Two-dot comparison. - Witnesses: payload parsing (nested member, absent, empty, not an oid, not json) and resolution (own parent, no parent refuses, cause carried). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * WIP: derive gunbc.rung_drop.roster from its directory by declared type (shared fold with RFM) Unverified by CI; main_wet regen of stage0 mirrors not completed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * #12514: cover PlannedAsReachConsumer in main's newer disposition matches; hoist in-body annotations Merging main brought six matches over RequiredFloorDisposition written after the reach-consumer arm existed on this branch (E0004 in emit-build). Each new arm follows the .dag authority: v2.workflow.floor_changed_witness and v2.workflow.required_floor treat PlannedAsReachConsumer exactly as Planned (planned standing, gate runs, not a cost-debt withhold, CostDebtDeclaredButNotWithheld, never suppresses a changed-witness enrollment). merge_group_event.dag carried '//' annotations inside a type body, which DESIGN §4c refuses; they move to the leading block above the declaration. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: cover variants that landed on main after the NFR enumerations were written Composing the burn-downs with main exposed two non-exhaustive matches, the exact class enumeration exists to surface: - floor_unimported_bare_provider_debt_roster: three standing matches lacked Retired { cause: RelocatedOutOfSourceRoots } (floor refusal, CI run 36931173776). - target_model realized-closure body classification lacked ParameterReferenceBody, added by #12766 (emit-build refusal); it projects like DeclarationReferenceBody. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate stage0 mirrors to a fixed point; cover more variants that landed after enumeration - stage0 mirrors regenerated locally (claim_executor --required-regen, whole-compiler rebuild between rounds) until first_generation_equal=true (161/161 adjudicated). - DESIGN.md and docs/design-rung-drops.md from tools.docs_projection_gate regen and generated_artifact_gate main_wet_verified. - More matches the NFR burn-downs enumerated before main added variants; each new arm keeps what main's removed wildcard returned: live_deploy emit identity_member_of_step and member_observe root_members_of_step gain ApprovalBrokerFrontDoor (none / []); mtcollins1_kvm_still kvm_pending_step, kvm_established_step and kvm_gap_mark gain KvmJournalNavigated/PageConsole/PageError (acc / []). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: retire 31 bare-provider rows the composed tree no longer carries The pool-wide standing check (#12908) judged the composed head and found 31 ActiveDebt pairs whose files no longer carry them (imports added by the other merged burn-downs). Each is retired as ImportsFixed, exactly as the refusal names (CI run 36939427278). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate after merging main; name runner_microvm_boot_probe's Filesystem authority - stage0 mirrors regenerated to a fixed point after the main merge (first_generation_equal=true), docs/design-rung-drops.md regenerated; main_wet_verified green. - runner_microvm_boot_probe read Filesystem bare while three modules declare it (AmbiguousBareNameRead, floor run 36941252236); it uses Filesystem.Write, so it imports the service from extdeps.filesystem.filesystem_io, as its sibling runner modules do. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate the rung-drops projection after the main merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: back out #12610 (typed NFR check D) Its typed check judges every module the diff touches, and this branch's diff touches hundreds, so the floor refused with 65 unrostered closed-coproduct wildcard sites (NonFoldResidueRosterDiverged, run 36948688303). That is exactly the joint landing #12610 was waiting on (census roster, old-scan deletion, srv1 typed census at 0/0), which is not built. #12610 is reopened to carry it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: iterative Drop for PortableValue value_depth_walker_tests::a_deep_value_round_trips_through_the_portable_form aborted the test process (stack overflow, SIGABRT, rust-unit-tests run 36951304061) when the deep portable chain was dropped: PortableValue is a plain owned tree, as deep as its value, and had the recursive default drop. It now drops through a heap worklist exactly as impl Drop for Value does (class recursion_over_value_depth_uncounted_by_the_call_limit). The test passes locally, and the other deep-value tests still pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: green the --lib population #12753 makes blocking #12753 turns rust-unit-tests into a blocking lane, so this branch must carry a green --lib population. Main's own reds, which nothing ran: - closure_edge_demand_tests::required_phase_..._catches_a_bypass judged a second root set on the same thread, which #12831's SharedIndexSecondResidentPool now refuses; the twin pool's judgment runs on its own thread, as a separate floor run would. - compile_clean_via_index_verdict_equivalence::regen_subject_admits_a_provider_reached_only_by_ reference wrote a bare cross-tree reference, which #12741 refuses (CrossTreeBareReference); the fixture now writes it qualified, still reference-only with no import. - nfr_roster_receipt: 13 parameter-scrutinee wildcard sites landed on main after the 2026-10-01 census; rostered with a stated reason and the owning-fold dissolution. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: live-pool tests start from no held pool live_pool_thread_tests::two_claims_on_the_live_pool_thread_share_one_index failed whenever an earlier test had left the live-pool thread holding its own fixture pool: #12831 refuses a second resident pool on one thread (SharedIndexSecondResidentPool). Each live-pool test now releases the live pool first (yield_live_pool_before_building_another), so its result no longer depends on test order. The serial suite's live-pool and content-key tests pass (7/7). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: regenerate stage0 after the main merge; roster 2 more post-census NFR sites - v1_compiler_emit{,_rust}.rs regenerated from main's base to a fixed point (first_generation_equal=true); docs projection unchanged. - dag/gunbc/action_use_admission.dag checkout_context_names_a_commit and checkout_ref_value_refusals landed on main after the census; rostered like the earlier 13. - Full serial --lib suite (RUST_TEST_THREADS=1, as CI runs it): 1116 passed, with the only failure being these two sites, now green. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: keep a deleted file's roster row FileDeleted; stop a test helper from providing 'github' pool-wide - import_closure_live_test.dag#ReadsLiveTree: the file is deleted on main, so its row stays Retired FileDeleted (my conflict resolution had taken ImportsFixed). - #12835's fleet_converge_checkout_pin_witness_test.dag declares a top-level helper 'fn github(path:)'. With #12908's pool-wide standing check, that made it a candidate bare provider for every module that reads 'github' bare (115 Unrostered refusals, run 36964372555). The helper is test-local, so it is renamed github_context_access; it no longer collides with the 'github' those modules mean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Revert "integration: merge #12912 (session/deep-deer-663-sudoers)" This reverts commit 9502c4c, reversing changes made to c276c43. * Regenerate stage0 mirrors and rung-drop docs after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * github_app_registry witness: import its live-tree disposition instead of reading it bare Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs and stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: rows for parse_sequence_capture and grammar_emit_sequence (landed on main after the census) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors and docs after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Cover main's new LexicalReferenceKind / LexicalReferenceBody in two enumerated matches; docs regen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider debt roster: the three body_lowering tests' rows are ImportsFixed on this branch (floor: RosterStale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: delete the 757 rows whose wildcards this branch's burn-down PRs enumerated (floor: stale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * semantic_decl_emission: the four edge-label matches name Authored and StructuralLabel (Named is gone after #12799) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * target_model: name StructuralLabel in the wire-child declared-type match; docs regen Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * match_pattern_binds_erased: carry the pattern's parent_identity (main's VariantPattern field) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * program_partition, realization_attempt: name StructuralLabel in three edge-label matches (#12799) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate DESIGN.md from the merged design_document (generated_artifact_gate main_wet) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: restore main's rows for the five wildcard bodies taken from main in the #12799 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * roadmap_belt_actuate: delete belt_spawn_tally_not_admitted, left without a caller once main's arms were taken Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Delete two branch helpers left without a caller once main's arms were taken in the #12787 merge Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors after the #12787 merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider debt roster: retire three pairs the merged files no longer carry (floor: RosterStale -> ImportsFixed) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * unit_standing, runner_microvm_slot_unit: name RuntimeMaxSec in four directive matches taken from main Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Bare-provider roster unit test: ImportsFixed -> FileDeleted now admits (#12787's rule); the reverse still refuses #12787 made FileDeleted terminal in v2.workflow.floor_unimported_bare_provider_debt without updating this Rust test, which main does not run as a blocking lane. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the #12512 merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate after the main merge (fixed point) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate rung-drop docs Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * runner_unit_live_read: the enumerated converge-verdict arms name VerdictAbsent (#12721) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * NFR roster: drop two rows main added for d0 sites this branch enumerates (floor: stale) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: floor fixes after the main merge; #12753 retirement text claims only what was observed - debt roster: fabric_witness_run_test HardRequirements/Shape/current_runner_slot_profile keep main's Retired ResolvesInClosure (the floor refuses a changed retirement, RosterRetirementChanged). - unit_standing_witness_test: import extdeps.systemd { systemd_duration_usec } (Unrostered on the floor; the file declares imports so its bare channel is off). - rust_unit_tests_off_the_merge_path: the merge_group pass had not happened; the text now says the merge_group revision is proven by the queue's own required run at landing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Heal-Candidate-Run: 37180751525 * Regenerate docs projections (docs_projection_gate regen) * Regenerate stage0 mirrors (claim_executor --required-regen, round 1) * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * integration: follow main's #13186 (HeadGrain deleted) in the ownership join; LoadCredential arm in the microvm slot unit - gunbc.refusal_reason_ownership_join: main keyed cause ownership by cause alone and deleted the grain field, so a row owns its cause; reason_is_fatal_owned is the cause match. The witness drops the HeadGrain control (head_row / head_grain_row_does_not_own_a_fatal_reason): the state it planted is no longer constructible. - runner_microvm_slot_unit: main added SystemdServiceDirective LoadCredential; the enumerated directive match was non-exhaustive (floor declarations finding). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: delete the 2 NFR rows whose sites no longer carry a wildcard (floor NonFoldResidueRosterDiverged stale=2) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * chore: regenerate drifted generated artifacts (ci auto-heal) Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md determinism_transitive_reachability Heal-Candidate-Run: 37235281080 * Regenerate docs projections and witnesses.yml after stage0 regen * integration: the four rust-unit-tests reds the restored lane surfaced (all stale against main, which runs no unit lane) - nfr_observation_roster_test: gunbc#13277 enumerated ci_hold_cause_text and drained its NFR row; the test now asserts the row stays drained (renamed observation_hold_cause_row_stays_drained). - process_cwd_mutation_reachability_gate: a_stale_binary_is_refused_before_any_instrument_runs reached test_verb's producers, several of which set the process cwd. The freshness refusal is split out as stale_binary_refusal and the witness calls it, so the route is asserted without reaching any producer; test_verb_after keeps the same behaviour. - changed_selections_outside_discovery_mirror_tests: since gunbc#13138 the .dag decider returns its list as a free-monoid Cons/Empty chain (list_reverse); the test reads either realization. - renderer_hop_decides_realization_from_declaration_identity_without_an_env: the structural-Bool half retires as dissolution of the Bool de-fork (gunbc#12583), mirroring the .dag witness's retired row; the prelude control stays. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: list_items matches the Value by reference (E0509: Value implements Drop) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: pin run_native_serve_program in the cwd gate's undecided set; carry the renderer-hop retirement into its .dag source - process_cwd_mutation_reachability_gate: main's #13135 declared run_native_serve_program in two files, the exact shape of the pinned run_native_claim_program (producer called only from its own TargetProducer match; the native_lane_runner twin reached by the qualified cli_run:: spelling). - compiler_tests.rs is generated from v1.compiler.compiler_tests_rust; the structural-Bool retirement is now authored there, rendering the same lines the mirror carries. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * integration: the compiler_tests_rust mirror carries the renderer-hop retirement its .dag source now authors v1_compiler_compiler_tests_rust.rs is the emitted form of v1.compiler.compiler_tests_rust; its ct_renderer_hop_identity_keying_test is re-rendered in the emitter's own concat shape (the old body round-trips byte-identically through the same rendering), so the regen's first generation agrees. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * Reach differential: an unmeasured head and a claim declared at neither side refuse, never pass (review 76405) reach_claim_verdict returned a non-blocking 'head_not_measured' for a head with no verdict; it now refuses typed and located (DESIGN 5). claim_differential mapped NotDeclared at both sides to DifferentialRemoved (never blocks); it is now DifferentialUndeclaredAtBothSides, which blocks, so a removal runs the base arm to prove it was one. Tests: an_unmeasured_head_is_refused_not_reported, a_claim_declared_at_neither_side_blocks_and_a_removal_reports, and only_a_passing_head_skips_the_base_arm. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Reach differential: not_measured is a declared parsed arm; one constructor builds the verdict (review 76416) ParsedClaimStanding gains StandingNotMeasured, parsed once in claim_standing_named; reach_claim_verdict and reach_head_cannot_block match the arm instead of each comparing the string. reach_verdict_of builds ReachVerdict's name and blocks from ONE ClaimDifferential value, so they cannot disagree; the two flat fields stay because they are the wire the seed floor runner reads. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate docs projections and witnesses.yml after stage0 regen * floor_demand: typed arm for the cross-claim-share-derivation seam (main's #13043) #13043 added floor_seam("cross-claim-share-derivation") to the floor runner without a FloorSeam arm or a FloorSeamToken row; main never runs the unit lane, so every_floor_seam_literal_has_a_typed_arm was latent-red there and the restored rust-unit-tests lane caught it. Adds SeamCrossClaimShareDerivation, its token row, and its arm in receipt_peak_seam. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rung drop rust_unit_tests_off_the_merge_path: retired on its own trigger, runner supply, with the receipt (review 76493) The trigger_fired text cited the population being green and the job being re-added, which the row itself says does not retire it. It now cites the supply receipt from this PR's required runs: the unit job starts with the other lanes (no queueing) and finishes before floor, so the required wall did not rise. It also cites the operator's sign-off for the roster addition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * rung drop rust_unit_tests_off_the_merge_path: restore the declaration the last edit dropped (review 76497) 163ef99 replaced the trigger_fired text but cut through to the end of the declaration's AuthoredProse, deleting the drop's record of what it declared (and leaving the record without a required field). Restored from its parent; only the trigger_fired string differs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs projections (rung-drop retirement text) * Regenerate DESIGN.md (generated_artifact_gate main_wet_one): the unit-test lane is no longer described as off every CI path * rung drop retirement: name the instrument for the supply receipt, not the transcribed wall times (review 76511) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate docs projections and DESIGN.md (retirement receipt names its instrument) * Regenerate stage0 mirrors (claim_executor --required-regen, round 2) * Regenerate stage0 mirrors (claim_executor --required-regen, round 3) * Regenerate stage0 mirrors after the eighth main merge (round 1) * Regenerate docs projections after the tenth main merge * required_floor_runner test: cost_debt_clean_outcome carries reach_differential_blocking Main's test constructor (added with the moved required_floor_outcome_is_clean) predates this branch's field; the unit lane failed to compile (E0063). cargo check --lib --tests is clean. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Regenerate DESIGN.md and docs projections after the eleventh main merge --------- Co-authored-by: gunbc-ci-auto-heal <gunbc-ci-auto-heal@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Co-authored-by: Brian Searls <briansearls1@gmail.com> Co-authored-by: gunbai-bot[bot] <289086189+gunbai-bot[bot]@users.noreply.github.com> Co-authored-by: Brian Searls <briansrls@gmail.com>
Floor repair C3 part 2 (plan #13030): cross-claim pure-share admission is derived from the planned claims' call-site demand, and the hand roster is deleted in the same change (DESIGN §3, replacement migration). Mechanism ruled by sharp-raven-357 (option A, then (i)): the observation row type and the decision live in .dag, and the seed only observes and realizes.
What changes
v2.workflow.floor_pure_producer_share:CallSiteDemandObservationis keyed bystd.computation_identity(NormalizedIdentical, normalizer named on the row).CallSiteDemandCauseis a closed coproduct of why a site has no closed identity.derive_cross_claim_sharedecides: it admits a closed identity demanded by at least 2 planned claims. It declinesDemandedByOneClaim,IdentityGradeNotShareable,RefusedByMeasurementandCarriedInputProducer. Unadmissible sites are counted under their cause, never widened.floor_cross_claim_admitted_producers, and both collision walls. The walls are now unconstructible by the fold.cli_run::claim_call_site_demandis one realization of the row type. It walks each planned claim's reach and reads every call site. It counts distinct claims per identity and decides nothing. It is seed-retained under the new receiptgunbc.floor_call_site_demand_seed_growth, whose trigger is per-claim call-site demand identity available to .dag (demand-engine M1.b).derive_and_install_cross_claim_shareruns after planning.KeyOmitsAnInputTheValueDependsOn) and the carried-input rows. Both stay as identity gates.Structural prediction, stated before the confirming run
[cross-claim-demand]rows ofclaims=k evals=kfor those producers move into[floor-shared-fill] cache=cross_claim_pure_sharewith one fill.cref_assemble/fps_assembleshared fixtures are this class, so their claims' eval steps drop by the fill.prepared-subject-warmconsumer_claims=0fills go to zero.[cross-claim-share-admitted]/[cross-claim-share-declined]lines.ArgumentNotClosedConstant, rather than hidden.Roster dispositions
All 647 rows of main's roster (at 6386677) are dispositioned by identity in this comment, per-row lists in the next:
FrozenRuntimeIdentityProducer; a witness joins the five by identity), trigger: per-call runtime-argument demand identity available to .dag (demand-engine M1.b). Serving is keyed by declaration and argument row and preimage-verified, as it was under the hand roster.ClaimDeletedwhen main reverted v2: kinded type params; type applications checked in exact bijection; de-fork MachineWidth onto std.machine_constraints #13038, 1BecameSharedByDemand). They are a monotone debt set (floor_single_claim_fill_debt), joined by claim identity, with a stale-member refusal. Their fills are netted and not retained. Each module retires its members by restructuring per the DESIGN §3 witness rule. 349 came from the original probes; the rest were added, each with its probe run cited in the file, for roster rows five PRs added to main while this was open (v2 body lowering: a let-match with returning arms heading a tail spine lowers to the match (N7 root F) #13118, N7-1b: std.algebra collection callback ops (map, all) realized through the one fold encoding, keyed on named template rows #13069, census C: collapse import cascades to their root, rank roots by closure fan-out #13120, v2 infer: binary algebra operators derive through inhabitance rows (Bool ||; Int-only add arm deleted) #13060, v2: kinded type params; type applications checked in exact bijection; de-fork MachineWidth onto std.machine_constraints #13038) and for four claims main's corpus pushed over.Evidence
Final pair, all fixes in: PR-side 37210396855 (e46846f) vs main-side 37210398646 (main 44ed81c), 134 modules / 1290 claims force-planned on both.
type_application_kindclaims behind v2: kinded type params; type applications checked in exact bijection; de-fork MachineWidth onto std.machine_constraints #13038's roster rows, now debt members.The price of deleting the hand roster is the derivation seam, and it is stated plainly: observing the declared claims' call sites and running the fold costs about 25 s of thread CPU on an ordinary PR subject and 92 s on this full probe subject. That is new work this change adds to every floor run.
What the comparison caught along the way, each fixed in this PR with a control:
dag_prepared_grammar(few steps, 466-1140 ms of native keying), so every claim re-paid it. The floor now has a CPU arm, typed as aMillisecondand set to the new-witness envelope.Part (b), the TSV uploads, is #13031.
🤖 Generated with Claude Code