From 3519979801840f4a454c88b9176a2b3db7c804a5 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 00:53:01 +0000 Subject: [PATCH 01/33] Floor: derive cross-claim pure-share admission from planned claims' call-site demand Deletes the hand-authored share roster (575 warm + 5 claim-forced rows, the pending-candidate shape, two collision walls, the seed's plain warm loop) and replaces it with a derivation: - .dag (v2.workflow.floor_pure_producer_share): the observation row type CallSiteDemandObservation keyed by std.computation_identity, the closed cause coproduct CallSiteDemandCause, and the decision fold derive_cross_claim_share (admit a closed identity demanded by >=2 planned claims; decline single-claim, unknown-grade, measured-refused and carried-input producers; count every unadmissible site under its cause, never widen). - seed: claim_call_site_demand observes each planned claim's reach and reads its call sites (one realization of the .dag row type; seed-retained under gunbc.floor_call_site_demand_seed_growth until demand-engine M1.b supplies per-claim call-site demand identity to .dag). derive_and_install_cross_claim_share calls the fold after planning, admits the decided producers at their call sites only, and warms each once in its site module's frame, adjudicated against the preparation limits. - interpreter: site-gated admission (install_cross_claim_derived_share, cross_claim_site_admitted) and warm_cross_claim_call_site; stores stay keyed on evaluated argument values with preimage verification. Refused candidates and carried-input rows stay as identity gates. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../cross_claim_pure_share_seed_growth.dag | 5 +- .../floor_call_site_demand_seed_growth.dag | 34 + ...dition_re_derived_once_per_claim_frame.dag | 2 +- dag/gunbc/seed_growth_admission.dag | 2 + .../parse_test_fn_decl_return_clause_test.dag | 4 +- src/v1/stage0/src/cli_run.rs | 5 +- .../src/cli_run/claim_call_site_demand.rs | 591 +++++ .../src/cli_run/required_floor_runner.rs | 872 ++++---- src/v1/stage0/src/v1_interpreter.rs | 213 +- src/v2/compiler/program_assembly.dag | 4 +- .../self_host/direct_rust_door_fixture.dag | 5 +- src/v2/extdeps/languages/dag.dag | 2 +- .../fold_operand_structure_test.dag | 6 +- .../claim/body_lowering/map_literal_test.dag | 4 +- .../body_type_annotation_refusal_test.dag | 2 +- ...it_on_demand_family_crate_witness_test.dag | 6 +- ...nd_match_loop_fold_family_witness_test.dag | 6 +- .../pure_producer_share_refusal_test.dag | 293 ++- .../native_refusal_detail_test.dag | 2 +- .../text_string_importer_census_test.dag | 4 +- ...loor_prepared_effect_input_ladder_test.dag | 20 +- src/v2/workflow/floor_pure_producer_share.dag | 1894 +++-------------- 22 files changed, 1596 insertions(+), 2380 deletions(-) create mode 100644 dag/gunbc/floor/floor_call_site_demand_seed_growth.dag create mode 100644 src/v1/stage0/src/cli_run/claim_call_site_demand.rs diff --git a/dag/gunbc/floor/cross_claim_pure_share_seed_growth.dag b/dag/gunbc/floor/cross_claim_pure_share_seed_growth.dag index ad6da329f1b..c627ed9b5cf 100644 --- a/dag/gunbc/floor/cross_claim_pure_share_seed_growth.dag +++ b/dag/gunbc/floor/cross_claim_pure_share_seed_growth.dag @@ -20,7 +20,6 @@ import std.decl_ref { DeclarationRef, WholeDeclaration } // than duplicated beside it, which is the §3 move its own dissolve-on comment demanded. data cross_claim_pure_share_seed_growth_justification: SeedGrowthJustification = SeedGrowthJustification { hand_authored_declarations: [ - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "warm_cross_claim_pure_producer", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_pure_share_roster", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_share_observer", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimShareObserver", field: WholeDeclaration }, @@ -54,8 +53,8 @@ data cross_claim_pure_share_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "refuse_pure_producer_share_refused_carrier_overlap", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "consumer_modules_by_key", field: WholeDeclaration } ], - reason: "WHY RUST IS STILL NEEDED: the required floor executes in the seed, and the boundary this mechanism repairs is the seed's own frame lifecycle -- the floor builds a fresh evaluation frame per claim (deliberately, so one witness cannot contaminate the next), which is exactly why no .dag construct can carry a value across it: the substrate has no modeled claim-frame boundary yet, so the tier that survives it must stand where the frames are built. The eval-frame memo already lived in the interpreter for the same reason; this generalizes its hardcoded prepare_grammar cross-claim arm into the roster-driven tier that arm's own dissolve-on comment demanded, rather than growing a second name arm beside it.\n\nWHAT IS NOT GROWN: no membership policy (the roster is v2.workflow.floor_pure_producer_share and Rust decides nothing about it), no language behavior, no compatibility route, no escape hatch -- every failure arm refuses: a roster module absent from the prepared subject, a stale warm row, a warm that fails to evaluate, and a value that fails TOTAL reification each stop the line as a typed, located REQUIRED-FLOOR REFUSAL, and a store the tier DECLINES (origin-bound value, counted cap overflow, byte budget) degrades to recompute, never to a wrong value. A hash-verified duplicate is NOT in that list and is not a decline at all: #9721 separated it out as AlreadyPresent, because an entry already retained under the same key with a structurally equal argument row is SERVABLE -- later claims can read it, which is the whole obligation -- so it completes the warm rather than recomputing. It bills no second fill, since the call that landed the value already paid for it. Publication portability is a positive coproduct checked at store time with the first non-portable child named by path (the run-33269961629 class: a raw evaluator fn reference at .produced_decl_support.render), and serves verify the full portable argument row so a hash collision cannot alias.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor is the instrument that program gates on. Main run 33258845841 refused at the operator's 500ms per-claim CPU ceiling on a five-string_contains witness because every emit claim was re-deriving the same pure target-model work per frame -- runner variance crossing a fixed re-derivation cost, a nondeterministic gate. The repair the floor's own carriers demand is stop recomputing, never raise the line; verified on run 33272541241: FloorClean, emit rows over 350ms CPU dropped to zero, fills receipted through the existing [floor-shared-fill] ledger under cache=cross_claim_pure_share.\n\nWHAT #9721 ADDED, AND WHY IT IS A REPAIR RATHER THAN GROWTH: one item, CrossClaimStoreOutcome, replacing the bool that store_cross_claim_pure_memo and warm_cross_claim_pure_producer returned. The bool conflated four states -- fresh store, already-present entry, and three distinct refusals -- so the floor reported a CORRECTLY POPULATED tier as PureProducerShareWarmNotStored and printed \"duplicate key, entry cap, or byte budget\" where the cause belonged (the diagnostic_name_mechanism_silent failure mode). The trigger was structural, not incidental: v2.extdeps.languages.rust rust_target_model reaches rust_target_model_staging through its atom-realization catalog rows, so warming the first publishes the second, and the second row's own warm legitimately finds its entry present. AlreadyPresent is servable and does not stop the line; every Refused arm still does, now naming ONE cause. The line did not move and no arm was widened -- a state that was always servable stopped being reported as a refusal, and the three real refusals became individually legible. Its REDs are enrolled: an_already_present_entry_is_servable_while_a_declined_one_is_not (the discriminating pair -- AlreadyPresent and RefusedByteBudget both decline to write, and only one is servable) and an_already_present_publication_bills_no_second_fill.\n\nWHAT THE REFUSED-CARRIER WALL ADDS, AND WHY IT IS ADMITTED: six items, enumerated above, that adjudicate the ledger this tier already renders. v2.workflow.floor_pure_producer_share now carries a typed roster of producers this tier MEASURED AND REFUSED, and the identity-grain fold it declares beside them is not sufficient -- that file contains the case it misses, rust_target_model_staging, a distinct identity that measured clean while a wider row was enrolled and inherited that row's consumers and its regression the moment the wider row was withdrawn. The wall that catches it joins each observed share key's OBSERVED consumer modules against the refused row's measured carriers, and an observed population cannot be declared: it exists only in the run's own shared-fill ledger, which is why this half stands in the seed and not in the .dag. It decides no membership either -- the roster owns every producer, verdict and carrier; the Rust reads them and refuses. Every arm refuses: an undecodable roster, an unknown verdict variant, a refused row with no carriers (which would be enrolled coverage that can never fire), a ledger with fills but no installed roster, and an overlap whose bare ledger key two admitted spellings claim, which is unattributable rather than assignable to either. The refusal fires on the run of the diff that WITHDREW a row rather than the one that proposed the surviving key, so the diagnostic names the admitted key, the refused row it inherited the carriers from, and -- in its own sentence -- that what changed is the roster and not that key's own cost; charging a cost to a principal that did not cause it is DESIGN section 5 externalization unless the transfer is said out loud. Its REDs are enrolled in pure_producer_share_refused_carrier_overlap_tests: the discriminating red is the staging shape in miniature and its positive control varies exactly the consuming module, with the roster, the refused row and the admitted key held fixed. Its rung is MECHANICALLY PREVENTABLE and the receipt says so: the check runs at runtime over one run's observed ledger and depends on the required floor executing and staying enrolled.\n\nHAND-ITEM DELTA: the enumerated items above are the COMPLETE census of new module-scope declarations in the diff against origin/main (fns, types, consts, and thread-local statics across v1_interpreter and cli_run), derived item-by-item from the declaration diff, not from memory (review 57451 caught the earlier 8-item roster omitting portable_value_eq, portable_value_size_bytes and others). Deliberately excluded: CROSS_CLAIM_BYTE_BUDGET_TEST_OVERRIDE, which is cfg(test)-only and never compiled into the shipped seed — it is enrolled test scope, not seed growth. The remaining diff is arms and fields inside declarations that already existed on main (PortableValue arms, try/store_cross_claim_pure_memo bodies, clear_cross_claim_pure_memos, the shared-fill observer wiring, claim_batch's two trace lines), which gunbc.seed_growth_admission classifies ExistingSeedItemModified, plus enrolled test scope (the discriminating fill/serve pair, the reordered-interner field-resolution control, the publication-refusal REDs, the homonym and byte-budget REDs, and the closure-seed refusal trio). HAND-LOC DELTA AT THIS RECEIPT: roughly +1068/-82 across src/v1/stage0/src/v1_interpreter.rs, cli_run.rs, cli_run/required_floor_runner.rs, cli_run/shared_fill.rs and bin/claim_batch.rs against origin/main (claim_batch's two lines wire the previously uncalled recompute-trace printer, adding no declaration). The item observation producer named by gunbc.seed_growth_admission is not invoked by any required phase, so these diff-derived figures are review evidence rather than a mechanically joined admission, and this receipt says so rather than presenting them as measured by the join.", + reason: "WHY RUST IS STILL NEEDED: the required floor executes in the seed, and the boundary this mechanism repairs is the seed's own frame lifecycle -- the floor builds a fresh evaluation frame per claim (deliberately, so one witness cannot contaminate the next), which is exactly why no .dag construct can carry a value across it: the substrate has no modeled claim-frame boundary yet, so the tier that survives it must stand where the frames are built. The eval-frame memo already lived in the interpreter for the same reason; this generalizes its hardcoded prepare_grammar cross-claim arm into the roster-driven tier that arm's own dissolve-on comment demanded, rather than growing a second name arm beside it.\n\nWHAT IS NOT GROWN: no membership policy (the roster is v2.workflow.floor_pure_producer_share and Rust decides nothing about it), no language behavior, no compatibility route, no escape hatch -- every failure arm refuses: a roster module absent from the prepared subject, a stale warm row, a warm that fails to evaluate, and a value that fails TOTAL reification each stop the line as a typed, located REQUIRED-FLOOR REFUSAL, and a store the tier DECLINES (origin-bound value, counted cap overflow, byte budget) degrades to recompute, never to a wrong value. A hash-verified duplicate is NOT in that list and is not a decline at all: #9721 separated it out as AlreadyPresent, because an entry already retained under the same key with a structurally equal argument row is SERVABLE -- later claims can read it, which is the whole obligation -- so it completes the warm rather than recomputing. It bills no second fill, since the call that landed the value already paid for it. Publication portability is a positive coproduct checked at store time with the first non-portable child named by path (the run-33269961629 class: a raw evaluator fn reference at .produced_decl_support.render), and serves verify the full portable argument row so a hash collision cannot alias.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor is the instrument that program gates on. Main run 33258845841 refused at the operator's 500ms per-claim CPU ceiling on a five-string_contains witness because every emit claim was re-deriving the same pure target-model work per frame -- runner variance crossing a fixed re-derivation cost, a nondeterministic gate. The repair the floor's own carriers demand is stop recomputing, never raise the line; verified on run 33272541241: FloorClean, emit rows over 350ms CPU dropped to zero, fills receipted through the existing [floor-shared-fill] ledger under cache=cross_claim_pure_share.\n\nWHAT #9721 ADDED, AND WHY IT IS A REPAIR RATHER THAN GROWTH: one item, CrossClaimStoreOutcome, replacing the bool that store_cross_claim_pure_memo and warm_cross_claim_pure_producer returned. The bool conflated four states -- fresh store, already-present entry, and three distinct refusals -- so the floor reported a CORRECTLY POPULATED tier as PureProducerShareWarmNotStored and printed \"duplicate key, entry cap, or byte budget\" where the cause belonged (the diagnostic_name_mechanism_silent failure mode). The trigger was structural, not incidental: v2.extdeps.languages.rust rust_target_model reaches rust_target_model_staging through its atom-realization catalog rows, so warming the first publishes the second, and the second row's own warm legitimately finds its entry present. AlreadyPresent is servable and does not stop the line; every Refused arm still does, now naming ONE cause. The line did not move and no arm was widened -- a state that was always servable stopped being reported as a refusal, and the three real refusals became individually legible. Its REDs are enrolled: an_already_present_entry_is_servable_while_a_declined_one_is_not (the discriminating pair -- AlreadyPresent and RefusedByteBudget both decline to write, and only one is servable) and an_already_present_publication_bills_no_second_fill.\n\nWHAT THE REFUSED-CARRIER WALL ADDS, AND WHY IT IS ADMITTED: six items, enumerated above, that adjudicate the ledger this tier already renders. v2.workflow.floor_pure_producer_share now carries a typed roster of producers this tier MEASURED AND REFUSED, and the identity-grain fold it declares beside them is not sufficient -- that file contains the case it misses, rust_target_model_staging, a distinct identity that measured clean while a wider row was enrolled and inherited that row's consumers and its regression the moment the wider row was withdrawn. The wall that catches it joins each observed share key's OBSERVED consumer modules against the refused row's measured carriers, and an observed population cannot be declared: it exists only in the run's own shared-fill ledger, which is why this half stands in the seed and not in the .dag. It decides no membership either -- the roster owns every producer, verdict and carrier; the Rust reads them and refuses. Every arm refuses: an undecodable roster, an unknown verdict variant, a refused row with no carriers (which would be enrolled coverage that can never fire), a ledger with fills but no installed roster, and an overlap whose bare ledger key two admitted spellings claim, which is unattributable rather than assignable to either. The refusal fires on the run of the diff that WITHDREW a row rather than the one that proposed the surviving key, so the diagnostic names the admitted key, the refused row it inherited the carriers from, and -- in its own sentence -- that what changed is the roster and not that key's own cost; charging a cost to a principal that did not cause it is DESIGN section 5 externalization unless the transfer is said out loud. Its REDs are enrolled in pure_producer_share_refused_carrier_overlap_tests: the discriminating red is the staging shape in miniature and its positive control varies exactly the consuming module, with the roster, the refused row and the admitted key held fixed. Its rung is MECHANICALLY PREVENTABLE and the receipt says so: the check runs at runtime over one run's observed ledger and depends on the required floor executing and staying enrolled.\n\nHAND-ITEM DELTA: the enumerated items above are the COMPLETE census of new module-scope declarations in the diff against origin/main (fns, types, consts, and thread-local statics across v1_interpreter and cli_run), derived item-by-item from the declaration diff, not from memory (review 57451 caught the earlier 8-item roster omitting portable_value_eq, portable_value_size_bytes and others). Deliberately excluded: CROSS_CLAIM_BYTE_BUDGET_TEST_OVERRIDE, which is cfg(test)-only and never compiled into the shipped seed — it is enrolled test scope, not seed growth. The remaining diff is arms and fields inside declarations that already existed on main (PortableValue arms, try/store_cross_claim_pure_memo bodies, clear_cross_claim_pure_memos, the shared-fill observer wiring, claim_batch's two trace lines), which gunbc.seed_growth_admission classifies ExistingSeedItemModified, plus enrolled test scope (the discriminating fill/serve pair, the reordered-interner field-resolution control, the publication-refusal REDs, the homonym and byte-budget REDs, and the closure-seed refusal trio). HAND-LOC DELTA AT THIS RECEIPT: roughly +1068/-82 across src/v1/stage0/src/v1_interpreter.rs, cli_run.rs, cli_run/required_floor_runner.rs, cli_run/shared_fill.rs and bin/claim_batch.rs against origin/main (claim_batch's two lines wire the previously uncalled recompute-trace printer, adding no declaration). The item observation producer named by gunbc.seed_growth_admission is not invoked by any required phase, so these diff-derived figures are review evidence rather than a mechanically joined admission, and this receipt says so rather than presenting them as measured by the join.\n\nTHE ROSTER IS DELETED (2026-10-02, gunbc#13030 C3 part 2). Admission is no longer a declared roster this tier reads: v2.workflow.floor_pure_producer_share derive_cross_claim_share decides it over the planned claims' call-site demand, and the seed installs the decided producers at their admitted call sites (gunbc.floor_call_site_demand_seed_growth). The plain warm loop and warm_cross_claim_pure_producer are deleted with it; carried-input warms remain. Where the sentences above say roster, the admitted population now means the derived rows plus the carried-input producers.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the seed declarations when the generic cross-claim pure memo lands (gunbc.roadmap_authority five_minute_ci_gate_program_note -- v2.workflow.floor_pure_producer_share's own dissolve-on) AND the interpreter's memo tier migrates with the evaluator into the self-emitted substrate, so the claim-frame boundary and the tier that crosses it are both modeled facts and the hand plumbing disappears with the v1 floor bridge. NOT retired by the roster emptying: an empty roster still needs the tier that would serve it, and a trigger satisfied by the population draining would delete the mechanism while leaving the capability unowned.", - current_boundary: "v2.workflow.floor_pure_producer_share floor_cross_claim_pure_producers_warm / floor_cross_claim_pure_producers_claim_forced / floor_cross_claim_refused_candidates -> v1_compiler.cli_run install_pure_producer_share -> v1_compiler.v1_interpreter cross-claim tier (store, verify, serve, warm) -> [floor-shared-fill] cache=cross_claim_pure_share -> v1_compiler.cli_run refuse_pure_producer_share_refused_carrier_overlap" + current_boundary: "v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation / floor_cross_claim_carried_input_warm_rows / floor_cross_claim_refused_candidates -> v1_compiler.cli_run install_pure_producer_share and derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter cross-claim tier (store, verify, serve, warm) -> [floor-shared-fill] cache=cross_claim_pure_share -> v1_compiler.cli_run refuse_pure_producer_share_refused_carrier_overlap" } diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag new file mode 100644 index 00000000000..dcb25c4dcd6 --- /dev/null +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -0,0 +1,34 @@ +module gunbc.floor_call_site_demand_seed_growth + +import gunbc.roadmap_model { RoadmapNodeId } +import gunbc.seed_growth { SeedGrowthJustification } +import std.decl_ref { DeclarationRef, WholeDeclaration } + +// SEED-RETAINED RECEIPT for the per-claim call-site demand observer: the seed realization of +// v2.workflow.floor_pure_producer_share CallSiteDemandObservation, which the derived cross-claim +// share decides over. The row type, its causes and the decision are .dag; the seed walks the +// planned claims' reach and reads call sites, and installs the decided rows at their sites. +data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = SeedGrowthJustification { + hand_authored_declarations: [ + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "CallSiteDemandCause", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "CallSiteDemandRow", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "CallSiteDemandObserver", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "CLOSED_ARGUMENT_NORMALIZER", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "SiteKey", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "SourceIndices", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "SiteFact", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "DeclFacts", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "IdentityCell", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "site_key_of", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "render_site", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run", decl_name: "derive_and_install_cross_claim_share", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_derived_share", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_site_admitted", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration } + ], + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it, netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.", + owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, + trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", + current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" +} diff --git a/dag/gunbc/recurring_failure_mode/shared_precondition_re_derived_once_per_claim_frame.dag b/dag/gunbc/recurring_failure_mode/shared_precondition_re_derived_once_per_claim_frame.dag index 2680e5b463f..a8b6e488bc9 100644 --- a/dag/gunbc/recurring_failure_mode/shared_precondition_re_derived_once_per_claim_frame.dag +++ b/dag/gunbc/recurring_failure_mode/shared_precondition_re_derived_once_per_claim_frame.dag @@ -20,7 +20,7 @@ data shared_precondition_re_derived_once_per_claim_frame: RecurringFailureMode = "SPECIMEN, gunbc#10882 and gunbc#10992. #10882 landed src/v2/test/native_decl_selection_test.dag into the required floor at 2026-09-10T20:53Z; its four witnesses each called collision_prepared, so the seed tokenized and parsed ~230 characters of synthetic source once per claim. required-witnesses-floor refused on main for nearly an hour with the summary claims_failed=0 interrupted_before_verdict=4 interrupted_cpu_deadline=4 -- NOTHING FAILING and the lane red, because an unreached verdict is fail-closed. Marginal CPU measured by claim_batch: 1113, 1330, 1375 and 1362ms against the 500ms line. #10992 repaired it by sharing the fixture at the resolved seam so the ingest is paid once, and the four rows fit.", - "SECOND SPECIMEN, gunbc#11032, arriving by the same recognition rule a day later and diagnosed by a lane that had not read this row. A newly landed family -- the where-refinement parse witnesses from gunbc#10946 -- refused the 500ms line on main with interrupted_before_verdict and nothing failing. Partitioned, the shared precondition dominated: v2.compiler.parse parse_grammar_digest and the production index were re-derived on EVERY PARSE CALL although prepare_grammar had fixed both before the first token, and the shared fixture sources were re-parsed per claim. The producer that named it is the floor's cross-claim demand census (main run 34556223550, required_floor_cross_claim_demand.tsv, row parse_grammar_digest). The repair was the one this row prescribes: carry both facts on the prepared grammar, the seam where the grammar is already resolved, and share the fixture trees warm (v2.workflow.floor_pure_producer_share floor_cross_claim_pure_producers_warm). Its frame is narrower than a claim -- per parse call -- which widens this row's reach rather than founding a neighbour: the question that finds it is still the one above. It also shows the census already locating the class and nothing refusing on it, which is this row's next-rung trigger unmet.", + "SECOND SPECIMEN, gunbc#11032, arriving by the same recognition rule a day later and diagnosed by a lane that had not read this row. A newly landed family -- the where-refinement parse witnesses from gunbc#10946 -- refused the 500ms line on main with interrupted_before_verdict and nothing failing. Partitioned, the shared precondition dominated: v2.compiler.parse parse_grammar_digest and the production index were re-derived on EVERY PARSE CALL although prepare_grammar had fixed both before the first token, and the shared fixture sources were re-parsed per claim. The producer that named it is the floor's cross-claim demand census (main run 34556223550, required_floor_cross_claim_demand.tsv, row parse_grammar_digest). The repair was the one this row prescribes: carry both facts on the prepared grammar, the seam where the grammar is already resolved, and share the fixture trees across claims (v2.workflow.floor_pure_producer_share, whose admission is now derived by derive_cross_claim_share). Its frame is narrower than a claim -- per parse call -- which widens this row's reach rather than founding a neighbour: the question that finds it is still the one above. It also shows the census already locating the class and nothing refusing on it, which is this row's next-rung trigger unmet.", "THIRD SPECIMEN, gunbc#11291, and it is recorded because of WHERE it occurred rather than because the shape is new: inside the repair for the defect this row's own consumers are blocked on. The reflection guard that makes a bare type spelling refuse rather than resolve to one of several same-spelled declarations had to establish bare-name multiplicity, and v2.std.decl_index decl_facts_at is keyed by QUALIFIED name, which a bare spelling has none of -- so the only substrate answer was to fold the whole declaration corpus, once per call. The lane that was meant to make the floor's cross-claim memo keyable therefore reproduced the recurrence it was meant to unlock, which is the hazard worth naming: a repair for this class is exactly where an author is least likely to look for it.", diff --git a/dag/gunbc/seed_growth_admission.dag b/dag/gunbc/seed_growth_admission.dag index b897bedc0ca..20e836d9ea1 100644 --- a/dag/gunbc/seed_growth_admission.dag +++ b/dag/gunbc/seed_growth_admission.dag @@ -114,6 +114,7 @@ import gunbc.floor_route_gap_seed_growth { floor_route_gap_seed_growth_justifica import gunbc.floor_cgroup_stat_beat_seed_growth { floor_cgroup_stat_beat_seed_growth_justification } import gunbc.cross_claim_pure_share_seed_growth { cross_claim_pure_share_seed_growth_justification } import gunbc.cross_claim_demand_census_seed_growth { cross_claim_demand_census_seed_growth_justification } +import gunbc.floor_call_site_demand_seed_growth { floor_call_site_demand_seed_growth_justification } import gunbc.frame_independent_symbol_seed_growth { frame_independent_symbol_seed_growth_justification } import gunbc.floor_cost_debt_seed_growth { floor_cost_debt_seed_growth_justification } import gunbc.floor_cost_debt_edit_seed_growth { floor_cost_debt_edit_seed_growth_justification } @@ -271,6 +272,7 @@ fn seed_growth_justification_roster() -> List { derived_row_roster_seed_growth_justification, cross_claim_pure_share_seed_growth_justification, cross_claim_demand_census_seed_growth_justification, + floor_call_site_demand_seed_growth_justification, frame_independent_symbol_seed_growth_justification, floor_cost_debt_standing_seed_growth_justification, floor_population_projection_seed_growth_justification, diff --git a/dag/test/claim/parse_test_fn_decl_return_clause_test.dag b/dag/test/claim/parse_test_fn_decl_return_clause_test.dag index 92095a7497c..43cd03825fe 100644 --- a/dag/test/claim/parse_test_fn_decl_return_clause_test.dag +++ b/dag/test/claim/parse_test_fn_decl_return_clause_test.dag @@ -76,8 +76,8 @@ data nfbcp_fn_type_param_source: String = "module m\nfn g(h: fn(Int) -> Int) -> // specification-without-execution. data nfbcp_no_return_type_source: String = "module m\nfn g(h: fn(Int) -> Int) { true }\n" -// The PREPARED grammar, not the whole language model. dag_prepared_grammar is enrolled in -// floor_cross_claim_pure_producers_warm, so the required floor fills it during strict +// The PREPARED grammar, not the whole language model. dag_prepared_grammar is admitted by the derived cross-claim share +// (v2.workflow.floor_pure_producer_share derive_cross_claim_share), so the required floor fills it during strict // preparation -- outside every per-claim budget -- and a claim here pays the lookup rather // than the construction. Building dag_language_model() per claim instead charged ~107k eval // steps to every probe below, which is the parse subject and not this claim's. diff --git a/src/v1/stage0/src/cli_run.rs b/src/v1/stage0/src/cli_run.rs index d979d1f5c54..4b2fb0c600e 100644 --- a/src/v1/stage0/src/cli_run.rs +++ b/src/v1/stage0/src/cli_run.rs @@ -233,6 +233,7 @@ mod emitted_closure_compile_host; // TEST-ONLY, and wired the same #[path] way as the hosts above rather than through lib.rs: the // falsifier exists to be invoked by one #[ignore] test and has no production caller, so declaring // it unconditionally would put a module nothing calls into every release build. +pub(crate) mod claim_call_site_demand; #[cfg(test)] #[path = "evaluation_budget_consequence_falsifier_host.rs"] mod evaluation_budget_consequence_falsifier_host; @@ -44654,8 +44655,8 @@ const REQUIRED_FLOOR_POLICY_MODULE: &str = "v2.workflow.required_floor"; /// (`discover_floor_rows_for_source` / `floor_discovery_finalize_source_outcomes`, qualified — /// the floor's roster IS that fold's answer), the output policy (`resolve_channel_policy` / /// `resolve_shell_trace_stream_policy`, bare, from `install_output_policy_in`), and the -/// cross-claim pure-producer share roster (`floor_cross_claim_pure_producers_warm` / -/// `..._claim_forced`, via `install_pure_producer_share`), and the opaque-host-call surface +/// cross-claim pure-producer share (`floor_cross_claim_share_derivation` and the carried-input +/// rows, via `install_pure_producer_share` / `derive_and_install_cross_claim_share`), and the opaque-host-call surface /// (`opaque_host_call_surface`, via `floor_required_opaque_host_call_surface`, which arms the /// per-claim preemption-reachability recorder). Every one is a closure seed of the /// gate-bounded prepared subject; a new by-name evaluation adds its module here or refuses at diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs new file mode 100644 index 00000000000..8b981ef75e3 --- /dev/null +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -0,0 +1,591 @@ +//! PER-CLAIM CALL-SITE DEMAND IDENTITY — the observation `v2.workflow.floor_pure_producer_share` +//! `derive_cross_claim_share` decides over. +//! +//! The row type is declared in `.dag` (`CallSiteDemandObservation`, keyed by +//! `std.computation_identity`, causes the closed `CallSiteDemandCause`); this module is ONE +//! REALIZATION of it. It exists only because no `.dag` carrier yet hands the floor the call sites a +//! planned claim reaches together with their argument rows -- demand identity is the declared +//! frontier of demand-engine M1.b -- and its seed-growth receipt +//! (`gunbc.floor_call_site_demand_seed_growth`) names that capability as the trigger that deletes +//! it. +//! +//! WHAT IT DOES. For each planned claim it walks the claim function's reach over the prepared +//! subject -- calls, and value references that name a declaration -- and reads every call site in +//! every reached body. A site whose callee is a resolved pure source declaration and whose every +//! argument normalizes to a CLOSED expression (literals, list literals, variant constructors, +//! references to module declarations, binary operators and pure calls over those) has a +//! computation identity: the callee plus the canonical normalized argument row. Every other site +//! is counted under the `.dag` cause it falls in. Rows leave aggregated per identity with the +//! number of DISTINCT planned claims reaching it, because that count is a fact across the +//! claim-frame boundary only the seed can see; the threshold, the identity grade and every +//! exclusion are the `.dag` fold's. +//! +//! WHAT A WRONG JUDGMENT HERE CAN COST, stated because it bounds how much this module must be +//! trusted: the tier keys every store on the evaluated argument VALUES and verifies the stored +//! canonical preimage before any serve, so a site misjudged closed costs at most a store the claim +//! did not need, and a site misjudged open costs a missed share. Neither can serve a wrong value. +//! The normalizer is conservative by construction: an expression form it does not name is open. + +use std::collections::{BTreeMap, BTreeSet, HashMap, HashSet}; +use std::rc::Rc; + +use crate::v1_compiler_infer_items::ResolvedGraph; + +/// The prepared subject's source text index, as `v1_std_core` reads names through it. +type SourceIndices = im::HashMap>; +use crate::v1_std_core::{ + arg_value, authored_name_at, source_text_at, CallTargetIdentity, ExprData, LeafOwner, + NewlineIndex, Node, VarBindingKind, +}; + +/// The `.dag` `CallSiteDemandCause` arms, by their declared spelling. +#[derive(Debug, Clone, Copy, PartialEq, Eq, PartialOrd, Ord, Hash)] +pub(crate) enum CallSiteDemandCause { + CalleeUnresolved, + CalleeDeclaresEffects, + ArgumentNotClosedConstant, +} + +impl CallSiteDemandCause { + pub(crate) fn variant(self) -> &'static str { + match self { + CallSiteDemandCause::CalleeUnresolved => "CalleeUnresolved", + CallSiteDemandCause::CalleeDeclaresEffects => "CalleeDeclaresEffects", + CallSiteDemandCause::ArgumentNotClosedConstant => "ArgumentNotClosedConstant", + } + } +} + +/// The normalizer named on every closed row's `NormalizedIdentical` identity grade. +pub(crate) const CLOSED_ARGUMENT_NORMALIZER: &str = + "v1_compiler.cli_run.claim_call_site_demand closed_argument_row"; + +/// One `.dag` `CallSiteDemandObservation`, aggregated. +#[derive(Debug, Clone, PartialEq, Eq)] +pub(crate) enum CallSiteDemandRow { + Closed { + producer: String, + argument_preimage: String, + claims: u64, + sites: Vec, + }, + Unadmissible { + cause: CallSiteDemandCause, + claims: u64, + sites: u64, + }, +} + +/// A call site's span, as the tier admits it at run time: `(file, start, end)` in bytes. +pub(crate) type SiteKey = (String, i64, i64); + +pub(crate) fn site_key_of(node: &Node) -> SiteKey { + (node.span.file.to_string(), node.span.start, node.span.end) +} + +pub(crate) fn render_site(site: &SiteKey) -> String { + format!("{}:{}-{}", site.0, site.1, site.2) +} + +enum SiteFact { + Closed { producer: String, preimage: String }, + Unadmissible(CallSiteDemandCause), +} + +struct DeclFacts { + reads: Vec<(String, String)>, + sites: Vec<(SiteKey, SiteFact)>, + /// Each closed site's call node, so an admitted site can be warmed in its module's frame. + closed_nodes: Vec<(SiteKey, Rc)>, +} + +/// The observation over one prepared subject. Declarations are read lazily and each body is +/// walked once for the whole run, however many claims reach it. +pub(crate) struct CallSiteDemandObserver<'a> { + graph: &'a ResolvedGraph, + source_indices: Rc, + decls: HashMap<(String, String), Rc>, + facts: HashMap<(String, String), Rc>, + site_nodes: HashMap)>, +} + +#[derive(Default)] +struct IdentityCell { + claims: u64, + last_claim: usize, + sites: BTreeSet, +} + +impl<'a> CallSiteDemandObserver<'a> { + pub(crate) fn new(graph: &'a ResolvedGraph, source_indices: Rc) -> Self { + let mut decls = HashMap::new(); + for module in graph.modules.iter() { + let module_path = module.type_env.module_path.clone(); + for item in module.items.iter() { + if !item.name.is_empty() { + decls.insert((module_path.clone(), item.name.clone()), item.clone()); + } + } + } + CallSiteDemandObserver { + graph, + source_indices, + decls, + facts: HashMap::new(), + site_nodes: HashMap::new(), + } + } + + /// The declaration node for a planned claim or producer, by qualified identity. + pub(crate) fn decl(&self, module_path: &str, name: &str) -> Option<&Rc> { + self.decls.get(&(module_path.to_string(), name.to_string())) + } + + /// The module and call node of a closed site this observer read, for warming it. + pub(crate) fn site_node(&self, site: &SiteKey) -> Option<&(String, Rc)> { + self.site_nodes.get(site) + } + + /// Fold every planned claim's reach into the aggregated `.dag` rows. `claims` are + /// `(module_path, function)`; a claim whose declaration the prepared subject does not carry + /// contributes nothing and is returned in the second component, so the caller can refuse. + pub(crate) fn observe( + &mut self, + claims: &[(String, String)], + ) -> (Vec, Vec) { + let mut closed: BTreeMap<(String, String), IdentityCell> = BTreeMap::new(); + let mut open: BTreeMap = BTreeMap::new(); + let mut unresolved_claims = Vec::new(); + for (index, (module_path, function)) in claims.iter().enumerate() { + let claim_number = index + 1; + let root = (module_path.clone(), function.clone()); + if !self.decls.contains_key(&root) { + unresolved_claims.push(format!("{module_path}.{function}")); + continue; + } + let mut seen: HashSet<(String, String)> = HashSet::new(); + let mut frontier = vec![root.clone()]; + seen.insert(root); + while let Some(decl) = frontier.pop() { + let Some(facts) = self.facts_of(&decl) else { + continue; + }; + for read in &facts.reads { + if seen.insert(read.clone()) { + frontier.push(read.clone()); + } + } + for (site, fact) in &facts.sites { + let cell = match fact { + SiteFact::Closed { producer, preimage } => closed + .entry((producer.clone(), preimage.clone())) + .or_default(), + SiteFact::Unadmissible(cause) => open.entry(*cause).or_default(), + }; + if cell.last_claim != claim_number { + cell.last_claim = claim_number; + cell.claims += 1; + } + cell.sites.insert(site.clone()); + } + } + } + let mut rows: Vec = closed + .into_iter() + .map( + |((producer, argument_preimage), cell)| CallSiteDemandRow::Closed { + producer, + argument_preimage, + claims: cell.claims, + sites: cell.sites.iter().map(render_site).collect(), + }, + ) + .collect(); + rows.extend( + open.into_iter() + .map(|(cause, cell)| CallSiteDemandRow::Unadmissible { + cause, + claims: cell.claims, + sites: cell.sites.len() as u64, + }), + ); + (rows, unresolved_claims) + } + + fn facts_of(&mut self, decl: &(String, String)) -> Option> { + if let Some(f) = self.facts.get(decl) { + return Some(f.clone()); + } + let node = self.decls.get(decl)?.clone(); + let facts = Rc::new(self.read_declaration(&decl.0, &node)); + for (site, call) in &facts.closed_nodes { + self.site_nodes + .insert(site.clone(), (decl.0.clone(), call.clone())); + } + self.facts.insert(decl.clone(), facts.clone()); + Some(facts) + } + + fn name_of(&self, node: &Rc) -> String { + let authored = authored_name_at(self.source_indices.clone(), node.clone()); + if authored.is_empty() { + node.name.clone() + } else { + authored + } + } + + fn source_of(&self, node: &Node) -> Option { + let index = self.source_indices.get(node.span.file.as_str())?; + Some(source_text_at(index.clone(), node.span.clone())) + } + + /// A spelling read from `module`, resolved the way module-scope lookup resolves it: a + /// qualified spelling names its declaring module; a bare one is a sibling, or the unique + /// owner the graph records for that leaf. An ambiguous or absent leaf is unresolved. + fn resolve(&self, module: &str, spelling: &str) -> Option<(String, String)> { + if let Some((qualifier, leaf)) = spelling.rsplit_once('.') { + let key = (qualifier.to_string(), leaf.to_string()); + return self.decls.contains_key(&key).then_some(key); + } + let sibling = (module.to_string(), spelling.to_string()); + if self.decls.contains_key(&sibling) { + return Some(sibling); + } + match self + .graph + .item_leaf_owner_modules + .get(spelling) + .map(|o| o.as_ref()) + { + Some(LeafOwner::SingleOwner { module: owner }) => { + let key = (owner.clone(), spelling.to_string()); + self.decls.contains_key(&key).then_some(key) + } + _ => None, + } + } + + fn call_target(&self, module: &str, call: &Rc) -> Option<(String, String)> { + if let ExprData::ExprCall { + call_semantics: Some(semantics), + .. + } = call.expr_data.as_ref() + { + match semantics.target().as_ref() { + CallTargetIdentity::SourceDeclarationCall { + owner_module_path, + decl_name, + } => { + let key = (owner_module_path.clone(), decl_name.clone()); + return self.decls.contains_key(&key).then_some(key); + } + CallTargetIdentity::RuntimePrimitiveCall { .. } + | CallTargetIdentity::LocallyBoundCall { .. } => return None, + CallTargetIdentity::CallableTargetUndetermined => {} + } + } + let spelling = + crate::v1_std_core::expr_call_func_at(call.clone(), self.source_indices.clone()); + self.resolve(module, &spelling) + } + + fn read_declaration(&self, module: &str, decl: &Rc) -> DeclFacts { + let mut binders: HashSet = HashSet::new(); + for p in decl.params.iter() { + binders.insert(self.name_of(p)); + } + let mut nodes: Vec> = Vec::new(); + let mut stack: Vec> = Vec::new(); + if let Some(body) = &decl.body { + stack.push(body.clone()); + } + stack.extend(decl.children.iter().cloned()); + while let Some(n) = stack.pop() { + if matches!(n.expr_data.as_ref(), ExprData::ExprLet) { + binders.insert(self.name_of(&n)); + } + for p in n.params.iter() { + binders.insert(self.name_of(p)); + } + stack.extend(n.children.iter().cloned()); + if let Some(body) = &n.body { + stack.push(body.clone()); + } + if let Some(t) = &n.transport { + stack.push(t.clone()); + } + nodes.push(n); + } + let mut reads: BTreeSet<(String, String)> = BTreeSet::new(); + let mut sites: Vec<(SiteKey, SiteFact)> = Vec::new(); + let mut closed_nodes: Vec<(SiteKey, Rc)> = Vec::new(); + for n in &nodes { + match n.expr_data.as_ref() { + ExprData::ExprCall { .. } => { + let target = self.call_target(module, n); + if let Some(t) = &target { + reads.insert(t.clone()); + } + let fact = self.site_fact(module, n, target, &binders); + if matches!(fact, SiteFact::Closed { .. }) { + closed_nodes.push((site_key_of(n), n.clone())); + } + sites.push((site_key_of(n), fact)); + } + ExprData::ExprVar { binding_kind } => { + if matches!( + binding_kind.as_deref(), + Some(VarBindingKind::MatchBoundBinding) + | Some(VarBindingKind::VariantValueBinding { .. }) + ) { + continue; + } + let name = self.name_of(n); + if binders.contains(&name) { + continue; + } + if let Some(t) = self.resolve(module, &name) { + reads.insert(t); + } + } + _ => {} + } + } + DeclFacts { + reads: reads.into_iter().collect(), + sites, + closed_nodes, + } + } + + fn site_fact( + &self, + module: &str, + call: &Rc, + target: Option<(String, String)>, + binders: &HashSet, + ) -> SiteFact { + let Some(target) = target else { + return SiteFact::Unadmissible(CallSiteDemandCause::CalleeUnresolved); + }; + if self + .decls + .get(&target) + .is_some_and(|callee| !callee.uses.is_empty()) + { + return SiteFact::Unadmissible(CallSiteDemandCause::CalleeDeclaresEffects); + } + match self.closed_arguments(module, call, binders) { + Some(preimage) => SiteFact::Closed { + producer: format!("{}.{}", target.0, target.1), + preimage, + }, + None => SiteFact::Unadmissible(CallSiteDemandCause::ArgumentNotClosedConstant), + } + } + + /// The canonical argument row, in source order, each argument `name=expr` (`=expr` when + /// positional). `None` when any argument is open. + fn closed_arguments( + &self, + module: &str, + call: &Rc, + binders: &HashSet, + ) -> Option { + let mut parts = Vec::new(); + for arg in call.children.iter().filter(|a| !a.children.is_empty()) { + let name = authored_name_at(self.source_indices.clone(), arg.clone()); + let value = self.closed_expression(module, &arg_value(arg.clone()), binders)?; + parts.push(format!("{name}={value}")); + } + Some(format!("({})", parts.join(","))) + } + + fn closed_expression( + &self, + module: &str, + expr: &Rc, + binders: &HashSet, + ) -> Option { + match expr.expr_data.as_ref() { + ExprData::ExprLiteral { .. } | ExprData::ExprElaboratedLiteral { .. } => { + Some(format!("lit:{}", self.source_of(expr)?)) + } + ExprData::ExprListLit => { + let items = expr + .children + .iter() + .map(|c| self.closed_expression(module, c, binders)) + .collect::>>()?; + Some(format!("[{}]", items.join(","))) + } + ExprData::ExprBinOp { op, .. } => { + let operands = expr + .children + .iter() + .map(|c| self.closed_expression(module, c, binders)) + .collect::>>()?; + Some(format!("{op:?}({})", operands.join(","))) + } + ExprData::ExprVar { binding_kind } => { + let name = self.name_of(expr); + match binding_kind.as_deref() { + Some(VarBindingKind::MatchBoundBinding) => None, + Some(VarBindingKind::VariantValueBinding { parent_enum, .. }) => { + Some(format!("variant:{parent_enum}.{name}")) + } + _ if binders.contains(&name) => None, + _ => self + .resolve(module, &name) + .map(|(m, d)| format!("ref:{m}.{d}")), + } + } + ExprData::ExprCall { .. } => { + let target = self.call_target(module, expr)?; + if self.decls.get(&target).is_some_and(|c| !c.uses.is_empty()) { + return None; + } + let args = self.closed_arguments(module, expr, binders)?; + Some(format!("call:{}.{}{}", target.0, target.1, args)) + } + _ => None, + } + } +} + +#[cfg(test)] +mod tests { + use super::*; + + fn graph_of(sources: &[(&str, &str)]) -> (Rc, Rc) { + let files: Vec> = sources + .iter() + .map(|(path, content)| { + Rc::new(crate::v1_compiler_compile::SourceFile { + path: path.to_string(), + content: content.to_string(), + }) + }) + .collect(); + let result = crate::v1_compiler_compile::compile_to_resolved(Rc::new(files.into())); + ( + result.graph.as_ref().expect("fixture graph").clone(), + result.source_indices.clone(), + ) + } + + // The #12506 shape in miniature: a module-constant fixture text assembled behind a nullary + // helper that several claims call, beside a claim with its own fixture text, a helper whose + // argument is a parameter, and an effectful callee. + const FIXTURE: &str = "module fixture.n7\n\ + fn assemble(src: String) -> Int { 3 }\n\ + fn shared() -> Int { assemble(src: \"module p\") }\n\ + fn from_param(text: String) -> Int { assemble(src: text) }\n\ + fn reads() -> String uses net: Network { \"\" }\n\ + fn reading_helper() -> String { reads() }\n\ + fn claim_a() -> Bool { shared() == 3 }\n\ + fn claim_b() -> Bool { shared() == shared() }\n\ + fn claim_c() -> Bool { assemble(src: \"module own\") == 3 }\n\ + fn claim_d() -> Bool { from_param(text: \"x\") == 3 }\n\ + fn claim_e() -> Bool { reading_helper() == \"\" }\n"; + + fn observe(claims: &[&str]) -> Vec { + observe_source(FIXTURE, claims) + } + + fn observe_source(source: &str, claims: &[&str]) -> Vec { + let (graph, indices) = graph_of(&[("workspace/src/n7.dag", source)]); + let mut observer = CallSiteDemandObserver::new(&graph, indices); + let planned: Vec<(String, String)> = claims + .iter() + .map(|c| ("fixture.n7".to_string(), c.to_string())) + .collect(); + let (rows, unresolved) = observer.observe(&planned); + assert!( + unresolved.is_empty(), + "every fixture claim resolves: {unresolved:?}; indexed={:?}; modules={:?}; diagnostics={}", + observer.decls.keys().collect::>(), + graph.modules.iter().map(|m| m.type_env.module_path.clone()).collect::>(), + graph.diagnostics.len() + ); + rows + } + + fn closed_claims( + rows: &[CallSiteDemandRow], + producer: &str, + preimage_contains: &str, + ) -> Option { + rows.iter().find_map(|r| match r { + CallSiteDemandRow::Closed { + producer: p, + argument_preimage, + claims, + .. + } if p == producer && argument_preimage.contains(preimage_contains) => Some(*claims), + _ => None, + }) + } + + fn has_cause(rows: &[CallSiteDemandRow], cause: CallSiteDemandCause) -> bool { + rows.iter() + .any(|r| matches!(r, CallSiteDemandRow::Unadmissible { cause: c, .. } if *c == cause)) + } + + // THE DISCRIMINATING PAIR at the observation: the shared fixture text reached through one + // helper by two claims counts TWO distinct claims -- and claim_b's second call does not make + // it three -- while the claim's own fixture text counts one. + #[test] + fn a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one() { + let rows = observe(&["claim_a", "claim_b", "claim_c"]); + assert_eq!( + closed_claims(&rows, "fixture.n7.assemble", "module p"), + Some(2), + "the shared fixture is demanded by exactly two distinct claims: {rows:?}" + ); + assert_eq!( + closed_claims(&rows, "fixture.n7.assemble", "module own"), + Some(1), + "a claim's private fixture is demanded once: {rows:?}" + ); + } + + // THE STATIC DEMAND IS THE PLANNED CLAIMS' AND NOTHING WIDER: with claim_b not planned, the + // shared fixture is reached by one claim, so no reuse obligation exists for this run. + #[test] + fn an_unplanned_claim_contributes_no_demand() { + let rows = observe(&["claim_a", "claim_c"]); + assert_eq!( + closed_claims(&rows, "fixture.n7.assemble", "module p"), + Some(1) + ); + } + + // NEVER WIDEN: a call whose argument is the enclosing function's parameter has no closed + // identity, so it is counted under its cause instead of admitting `assemble` wholesale. + #[test] + fn a_parameter_bound_argument_is_counted_open() { + let rows = observe(&["claim_d"]); + assert!( + has_cause(&rows, CallSiteDemandCause::ArgumentNotClosedConstant), + "the parameter-bound site must be counted open: {rows:?}" + ); + assert!( + closed_claims(&rows, "fixture.n7.assemble", "text").is_none(), + "no closed identity may be minted over a parameter: {rows:?}" + ); + } + + // An effectful callee is counted under its own cause, never closed, however constant its + // arguments are. + #[test] + fn an_effectful_callee_is_counted_under_its_cause() { + let rows = observe(&["claim_e"]); + assert!( + has_cause(&rows, CallSiteDemandCause::CalleeDeclaresEffects), + "the effectful nullary call must be counted under CalleeDeclaresEffects: {rows:?}" + ); + assert!(closed_claims(&rows, "fixture.n7.reads", "").is_none()); + } +} diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 161beb74f8a..97501b09689 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6287,16 +6287,6 @@ pub(crate) fn install_pure_producer_share( seed and must be in every required-floor subject: {why}" ) })?; - let warm_rows = floor_decode_module_prefix_roster( - &roster_frame, - &format!("{FLOOR_PURE_PRODUCER_SHARE_MODULE}.floor_cross_claim_pure_producers_warm"), - )?; - let claim_forced_rows = floor_decode_module_prefix_roster( - &roster_frame, - &format!( - "{FLOOR_PURE_PRODUCER_SHARE_MODULE}.floor_cross_claim_pure_producers_claim_forced" - ), - )?; // The two carried-input rosters are decoded HERE, beside the other two, because their // producers are part of the ADMITTED population: admission is one node set, and a producer // that warms into the tier but is not admitted would store nothing while the receipt read @@ -6349,18 +6339,13 @@ pub(crate) fn install_pure_producer_share( .iter() .map(|m| (m.type_env.module_path.as_str(), m.as_ref())) .collect(); - let mut admitted_by_qualified: std::collections::HashMap< - String, - std::rc::Rc, - > = std::collections::HashMap::new(); let mut admitted_nodes = Vec::new(); let mut admitted_qualified: Vec = Vec::new(); let carried_producers: Vec = carried_rows.iter().map(|r| r.producer.clone()).collect(); - for qualified in warm_rows - .iter() - .chain(claim_forced_rows.iter()) - .chain(carried_producers.iter()) - { + // THE ONLY PRODUCERS ADMITTED HERE ARE THE CARRIED-INPUT ONES. Plain pure producers are no + // longer a roster: they are derived from the planned claims' call-site demand once planning + // has fixed the claims (`derive_and_install_cross_claim_share`). + for qualified in carried_producers.iter() { let (module, decl) = match qualified.rsplit_once('.') { Some((module, decl)) => (module.to_string(), decl), None => (qualified.clone(), qualified.as_str()), @@ -6388,7 +6373,6 @@ pub(crate) fn install_pure_producer_share( module; fix or delete the roster row" ) })?; - admitted_by_qualified.insert(qualified.clone(), node.clone()); admitted_nodes.push(node); admitted_qualified.push(qualified.clone()); } @@ -6476,7 +6460,6 @@ pub(crate) fn install_pure_producer_share( .iter() .map(|i| module_of(&i.acquisition)) .chain(carried_rows.iter().map(|r| module_of(&r.producer))) - .chain(warm_rows.iter().map(|q| module_of(q))) .collect::>() .into_iter() .collect(); @@ -6680,134 +6663,6 @@ pub(crate) fn install_pure_producer_share( } } } - - for qualified in warm_rows.iter().filter(|q| &module_of(q) == group) { - let module = match qualified.rsplit_once('.') { - Some((module, _)) => module.to_string(), - None => qualified.clone(), - }; - // Resolution above either framed this row's module or recorded it as outside the - // prepared subject (not evaluated here, counted below); a stale row already refused. - let Some(producer_frame) = frames.frame( - prepared, - corpus_modules, - &mut outside_subject, - &module, - "producer", - qualified, - )? - else { - continue; - }; - let framed = producer_frame.lookup_fn_node(qualified); - let admitted = admitted_by_qualified.get(qualified.as_str()); - if !matches!((&framed, admitted), (Some(f), Some(a)) if std::rc::Rc::ptr_eq(f, a)) { - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=PureProducerShareFrameLookupDiverges producer={qualified} \ - — the module frame resolves the producer to a different declaration than admission \ - read from the prepared graph, so the admitted identity is not the one evaluated" - )); - } - // PROVENANCE IS DERIVED FROM THE TYPED OUTCOME, NOT ASSERTED BEFORE THE CALL, and the - // first revision of this line got that wrong in the direction DESIGN section 4b names. - // It passed `already_built: false` unconditionally, on the reasoning that the outcome - // below is the authority for whether the value was already retained. THAT REASONING - // FAILS BECAUSE THIS LOOP ALSO REPORTS A PROVENANCE: on the `AlreadyPresent` path the - // receipt said `BuiltByPreparation` for an artifact preparation FOUND rather than built. - // Two representations of one fact with one of them lying is worse than either alone, and - // a fabricated provenance in a receipt is the fabricated-plausible-output failure applied - // to this compiler's own self-description (review 59035, codex/gpt-5.6-sol). - // - // The flag cannot carry it: `observe_shared_build` is told before it runs, and the fact - // does not exist until the call returns. So the observation is corrected AFTER the fact, - // from the outcome that owns it. - // - // THE TRIGGER NAME STATES ONLY WHAT IS DECIDABLE. `AlreadyPresent` establishes PRESENCE - // and not who caused it, so the label names the boundary that is knowable rather than - // fabricating a call site -- inside this loop the only writer that can already have - // stored a rostered producer's value is an earlier rostered producer whose traversal - // reached it. That is the same discipline `warm_bare_reference_edge_index` uses when it - // names `a-site-ahead-of-floor-preparation` instead of inventing an author, and it is - // deliberately weaker than a call-site name because a call site is not recorded. - let (warm_result, mut warm_observation) = - observe_shared_build(false, "floor-preparation", || { - v1_interpreter::warm_cross_claim_pure_producer(producer_frame, qualified) - }); - if let Ok(outcome) = &warm_result { - if matches!( - outcome, - v1_interpreter::CrossClaimStoreOutcome::AlreadyPresent - ) { - warm_observation.provenance = SharedBuildProvenance::AlreadyWarmOnEntry { - triggered_by: "an-earlier-rostered-producer-in-this-warm-loop", - }; - } - } - match warm_result { - Ok(outcome) => { - // A NON-SERVABLE outcome means nothing is retained for later claims, so a - // silent decline would relocate the fill onto the first toucher: stop the - // line, naming the ONE cause rather than a disjunction of three. An - // `AlreadyPresent` outcome is servable and therefore not a refusal — a - // rostered producer reachable from an earlier rostered producer is stored - // by that traversal, and its own warm correctly finds the work done. - if !outcome.is_servable() { - // The located detail comes from the OUTCOME, so a cause can only ever be - // paired with its own evidence. Reading the retained slot here instead - // would decorate a byte-budget or entry-cap refusal with a stale path - // left by an earlier producer's unportable value (review 57554). - let detail = match outcome.not_portable_detail() { - Some(refusal) => format!( - "{} path={} kind={}", - outcome.cause(), - if refusal.path_into_value.is_empty() { - "" - } else { - refusal.path_into_value.as_str() - }, - refusal.encountered_kind - ), - None => outcome.cause().to_string(), - }; - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=PureProducerShareWarmNotStored \ - producer={qualified} — the rostered producer evaluated but its value \ - was refused by the cross-claim store: {detail}" - )); - } - floor_warm_row_identity(qualified); - eprintln!( - "[floor-phase] phase=pure-producer-share-warm state=completed \ - producer={qualified} disposition={} cpu_ms={} wall_ms={} \ - rss_growth_bytes={} provenance={}", - outcome.cause(), - warm_observation.cpu_ms, - warm_observation.wall_ms, - warm_observation.rss_growth_bytes, - warm_observation.provenance.render(), - ); - warm_observations.push(( - format!("CrossClaimPureProducerWarm/{qualified}"), - warm_observation, - )); - } - Err(v1_interpreter::PureProducerWarmRefusal::DispatchedEffect { effects }) => { - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=PureProducerShareWarmDispatchedEffect \ - producer={qualified} effects={effects} — the warm row reached the world, \ - so the value depends on an input its empty argument row cannot represent; \ - roster the read as a prepared effect input and the fold as a carried-input \ - warm row instead" - )); - } - Err(v1_interpreter::PureProducerWarmRefusal::Failed(why)) => { - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=PureProducerShareWarmFailed \ - producer={qualified} — {why}" - )); - } - } - } } // Disposition 2 is COUNTED, one line, so a subject that quietly stopped evaluating rows // it should carry is visible in the run's own announcement. @@ -6846,6 +6701,358 @@ pub(crate) fn install_pure_producer_share( Ok(warm_observations) } +/// THE DERIVED CROSS-CLAIM SHARE: admit, for this run, exactly the pure computations its PLANNED +/// claims demand from more than one claim with one closed identity. +/// +/// The seed observes (`claim_call_site_demand`, one realization of the `.dag` row type +/// `CallSiteDemandObservation`) and `v2.workflow.floor_pure_producer_share` +/// `floor_cross_claim_share_derivation` decides; the seed then admits the decided rows at their call +/// sites, and WARMS each admitted row once at one of its sites in that site's module frame, so its +/// fill lands outside the fold -- a claim's wall deadline nets only completed fills, so a fill left +/// to the first toucher could be interrupted mid-flight and re-paid by every claim. The returned +/// observations are adjudicated against the preparation limits by the caller. A warm the tier +/// cannot store (an effect, a call that does not evaluate in isolation, a declined store) is +/// counted under its cause and the site stays admitted: a claim evaluating it computes exactly +/// what it would have without the share. Every arm refuses: a planned claim the prepared subject does not carry, a fold +/// that does not evaluate or decode, a partition that does not reconcile, and an admitted producer +/// with no declaration node or an unparseable site. +pub(crate) fn derive_and_install_cross_claim_share( + prepared: &PreparedRepository, + claims: &[RequiredFloorClaim], +) -> Result, String> { + use super::claim_call_site_demand::{ + CallSiteDemandObserver, CallSiteDemandRow, CLOSED_ARGUMENT_NORMALIZER, + }; + use v1_interpreter::Value; + const MODULE: &str = "v2.workflow.floor_pure_producer_share"; + let started = std::time::Instant::now(); + let planned: Vec<(String, String)> = claims + .iter() + .map(|c| (c.module_path.clone(), c.function.clone())) + .collect(); + let mut observer = + CallSiteDemandObserver::new(&prepared.graph, prepared.source_indices.clone()); + let (rows, unresolved) = observer.observe(&planned); + if !unresolved.is_empty() { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=CallSiteDemandClaimUnresolved claims=[{}] -- a planned \ + claim's declaration is not in the prepared subject, so its call-site demand cannot be \ + observed and the derived share would omit it", + unresolved.join(",") + )); + } + let observe_ms = started.elapsed().as_millis(); + let frame = floor_authority_frame(prepared, MODULE).map_err(|why| { + format!( + "REQUIRED-FLOOR REFUSAL cause=PureProducerShareRosterOutsidePreparedSubject \ + module={MODULE} -- {why}" + ) + })?; + let ctx = &frame; + let sym = |s: &str| ctx.sym(s); + let unit = |ty: &str, variant: &str| Value::Variant { + type_name: sym(ty), + variant_name: sym(variant), + fields: std::rc::Rc::new(vec![]), + }; + let closed_rows = rows + .iter() + .filter(|r| matches!(r, CallSiteDemandRow::Closed { .. })) + .count(); + let values: Vec = rows + .iter() + .map(|row| match row { + CallSiteDemandRow::Closed { + producer, + argument_preimage, + claims, + sites, + } => Value::Variant { + type_name: sym("CallSiteDemandObservation"), + variant_name: sym("ClosedCallSiteDemand"), + fields: std::rc::Rc::new(vec![ + (sym("producer"), str_value(producer)), + (sym("argument_preimage"), str_value(argument_preimage)), + ( + sym("identity"), + Value::Variant { + type_name: sym("ComputationIdentity"), + variant_name: sym("NormalizedIdentical"), + fields: std::rc::Rc::new(vec![( + sym("normalizer"), + str_value(CLOSED_ARGUMENT_NORMALIZER), + )]), + }, + ), + (sym("claims"), Value::Int(*claims as i64)), + ( + sym("sites"), + list_value_from_vec(sites.iter().map(str_value).collect()), + ), + ]), + }, + CallSiteDemandRow::Unadmissible { + cause, + claims, + sites, + } => Value::Variant { + type_name: sym("CallSiteDemandObservation"), + variant_name: sym("UnadmissibleCallSiteDemand"), + fields: std::rc::Rc::new(vec![ + (sym("cause"), unit("CallSiteDemandCause", cause.variant())), + (sym("claims"), Value::Int(*claims as i64)), + (sym("sites"), Value::Int(*sites as i64)), + ]), + }, + }) + .collect(); + let result = v1_interpreter::run_in_context_with_args( + ctx, + &format!("{MODULE}.floor_cross_claim_share_derivation"), + &[( + Some("observations".to_string()), + list_value_from_vec(values), + )], + false, + ) + .map_err(|e| { + format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareDerivationFailed -- \ + floor_cross_claim_share_derivation did not evaluate: {e}" + ) + })?; + let derive_ms = started.elapsed().as_millis() - observe_ms; + let malformed = |what: &str| { + format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareDerivationUndecodable -- {what} (got `{}`)", + ctx.format_value(&result) + ) + }; + let Value::Record { fields, .. } = &result else { + return Err(malformed("expected a CrossClaimShareDerivation record")); + }; + let list_of = |name: &str| -> Result, String> { + match ctx.field(fields, name) { + Some(Value::List(xs)) => Ok(xs.iter().cloned().collect()), + _ => Err(malformed(&format!("no `{name}` list"))), + } + }; + let text_of = |row: &[(v1_interpreter::Symbol, Value)], name: &str| -> Result { + match ctx.field(row, name) { + Some(Value::Str(s)) => Ok(s.to_string()), + _ => Err(malformed(&format!("a row has no `{name}` String"))), + } + }; + let int_of = |row: &[(v1_interpreter::Symbol, Value)], name: &str| -> Result { + match ctx.field(row, name) { + Some(Value::Int(n)) => Ok(*n), + _ => Err(malformed(&format!("a row has no `{name}` Int"))), + } + }; + let variant_of = + |row: &[(v1_interpreter::Symbol, Value)], name: &str| -> Result { + match ctx.field(row, name) { + Some(Value::Variant { variant_name, .. }) => Ok(ctx.resolve(*variant_name)), + _ => Err(malformed(&format!("a row has no `{name}` variant"))), + } + }; + let admitted = list_of("admitted")?; + let declined = list_of("declined")?; + let unadmissible = list_of("unadmissible")?; + if admitted.len() + declined.len() != closed_rows { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareDerivationDoesNotReconcile \ + closed_observations={closed_rows} admitted={} declined={} -- every closed observation \ + must be admitted or declined exactly once", + admitted.len(), + declined.len() + )); + } + let mut nodes = Vec::new(); + let mut sites: std::collections::HashSet<(String, i64, i64)> = std::collections::HashSet::new(); + let mut admitted_qualified = Vec::new(); + // (site module, producer, producer node, call node) -- one warm per admitted row. + let mut warm_plan: Vec<( + String, + String, + std::rc::Rc, + std::rc::Rc, + )> = Vec::new(); + for row in &admitted { + let Value::Record { fields: r, .. } = row else { + return Err(malformed("an admitted row is not a DerivedShareRow record")); + }; + let producer = text_of(r, "producer")?; + let preimage = text_of(r, "argument_preimage")?; + let claims_n = int_of(r, "claims")?; + let (module, decl) = producer.rsplit_once('.').ok_or_else(|| { + malformed(&format!("admitted producer `{producer}` is not qualified")) + })?; + let node = observer.decl(module, decl).cloned().ok_or_else(|| { + format!( + "REQUIRED-FLOOR REFUSAL cause=DerivedShareProducerUnresolved producer={producer} \ + -- the derivation admitted a producer the prepared subject carries no declaration for" + ) + })?; + let row_sites = match ctx.field(r, "sites") { + Some(Value::List(xs)) => xs.iter().cloned().collect::>(), + _ => return Err(malformed("an admitted row has no `sites` list")), + }; + let mut sites_of_row: Vec<(String, i64, i64)> = Vec::new(); + for site in &row_sites { + let Value::Str(text) = site else { + return Err(malformed("a site is not a String")); + }; + let parsed = text.rsplit_once(':').and_then(|(file, span)| { + let (start, end) = span.split_once('-')?; + Some((file.to_string(), start.parse().ok()?, end.parse().ok()?)) + }); + let Some(key) = parsed else { + return Err(malformed(&format!( + "site `{text}` is not :-" + ))); + }; + sites_of_row.push(key.clone()); + sites.insert(key); + } + eprintln!( + "[cross-claim-share-admitted] producer={producer} claims={claims_n} sites={} \ + argument_preimage={preimage}", + row_sites.len() + ); + let first_site = sites_of_row + .first() + .cloned() + .ok_or_else(|| malformed(&format!("admitted producer `{producer}` carries no site")))?; + let (site_module, call) = observer.site_node(&first_site).cloned().ok_or_else(|| { + format!( + "REQUIRED-FLOOR REFUSAL cause=DerivedShareSiteUnobserved producer={producer} \ + site={} -- the derivation admitted a site this run's observer never read", + super::claim_call_site_demand::render_site(&first_site) + ) + })?; + warm_plan.push((site_module, producer.clone(), node.clone(), call)); + admitted_qualified.push(producer); + nodes.push(node); + } + let mut decline_counts: std::collections::BTreeMap = + std::collections::BTreeMap::new(); + for row in &declined { + let Value::Record { fields: r, .. } = row else { + return Err(malformed("a declined row is not a DeclinedShareRow record")); + }; + *decline_counts.entry(variant_of(r, "decline")?).or_default() += 1; + if variant_of(r, "decline")? != "DemandedByOneClaim" { + eprintln!( + "[cross-claim-share-declined] producer={} decline={} argument_preimage={}", + text_of(r, "producer")?, + variant_of(r, "decline")?, + text_of(r, "argument_preimage")? + ); + } + } + let mut unadmissible_rendered = Vec::new(); + for row in &unadmissible { + let Value::Record { fields: r, .. } = row else { + return Err(malformed( + "an unadmissible row is not an UnadmissibleDemandCount record", + )); + }; + unadmissible_rendered.push(format!( + "{}:claims={}:sites={}", + variant_of(r, "cause")?, + int_of(r, "claims")?, + int_of(r, "sites")? + )); + } + eprintln!( + "[floor-phase] phase=cross-claim-share-derivation state=completed planned_claims={} \ + closed_identities={closed_rows} admitted={} admitted_sites={} declined=[{}] \ + unadmissible=[{}] observe_ms={observe_ms} derive_ms={derive_ms}", + claims.len(), + admitted.len(), + sites.len(), + decline_counts + .iter() + .map(|(k, v)| format!("{k}={v}")) + .collect::>() + .join(","), + unadmissible_rendered.join(",") + ); + v1_interpreter::install_cross_claim_derived_share(nodes, sites); + PURE_PRODUCER_SHARE_ROSTER.with(|r| { + if let Some(roster) = r.borrow_mut().as_mut() { + roster.admitted_qualified.extend(admitted_qualified); + } + }); + // THE WARM, grouped by site module so each module is framed once. + warm_plan.sort_by(|a, b| (&a.0, &a.1).cmp(&(&b.0, &b.1))); + let mut observations = Vec::new(); + let mut declined_warms: std::collections::BTreeMap = + std::collections::BTreeMap::new(); + let mut framed: Option<(String, v1_interpreter::InterpContext)> = None; + for (site_module, producer, node, call) in &warm_plan { + if framed + .as_ref() + .map(|(m, _)| m != site_module) + .unwrap_or(true) + { + // Drop the previous module's frame before building the next: one resident at a time. + drop(framed.take()); + let frame = floor_authority_frame(prepared, site_module).map_err(|why| { + format!( + "REQUIRED-FLOOR REFUSAL cause=DerivedShareSiteModuleUnframed \ + module={site_module} producer={producer} -- {why}" + ) + })?; + framed = Some((site_module.clone(), frame)); + } + let frame = &framed.as_ref().expect("framed above").1; + match frame.lookup_fn_node(producer) { + Some(resolved) if std::rc::Rc::ptr_eq(&resolved, node) => {} + _ => { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=PureProducerShareFrameLookupDiverges \ + producer={producer} module={site_module} -- the site's module frame resolves \ + the producer to a different declaration than admission read from the prepared \ + graph, so the admitted identity is not the one a claim would evaluate" + )); + } + } + let (warm, observation) = observe_shared_build(false, "floor-preparation", || { + v1_interpreter::warm_cross_claim_call_site(frame, node, call) + }); + let disposition = match &warm { + Ok(outcome) => outcome.cause().to_string(), + Err(refusal) => { + *declined_warms.entry(refusal.cause()).or_default() += 1; + refusal.cause() + } + }; + eprintln!( + "[cross-claim-share-warm] producer={producer} module={site_module} \ + disposition={disposition} cpu_ms={} wall_ms={} rss_growth_bytes={}", + observation.cpu_ms, observation.wall_ms, observation.rss_growth_bytes + ); + observations.push(( + format!("CrossClaimDerivedShareWarm/{producer}"), + observation, + )); + } + drop(framed); + eprintln!( + "[floor-phase] phase=cross-claim-share-warm state=completed warmed={} \ + not_stored=[{}]", + warm_plan.len(), + declined_warms + .iter() + .map(|(k, v)| format!("{k}={v}")) + .collect::>() + .join(",") + ); + Ok(observations) +} + /// One row of `v2.workflow.floor_pure_producer_share.floor_cross_claim_refused_candidates`: /// a producer that was proposed for the cross-claim share tier, MEASURED, and refused. #[derive(Clone)] @@ -10295,6 +10502,27 @@ pub fn run_required_floor( ); } let claims_planned = claims.len(); + // THE DERIVED CROSS-CLAIM SHARE, admitted now that planning has fixed the claims: the share's + // demand is these claims' reach and nothing wider (`derive_and_install_cross_claim_share`). + floor_seam("cross-claim-share-derivation"); + // The derived warms are shared builds like every preparation warm, so they answer to the same + // three preparation limits; they run here only because their demand is the planned claims. + for (which, warm) in &derive_and_install_cross_claim_share(&prepared, &claims)? { + if warm.cpu_ms > preparation_cpu_limit_ms + || warm.wall_ms > preparation_wall_limit_ms + || warm.rss_growth_bytes > preparation_rss_growth_limit_bytes + { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=FloorPreparationRefused phase={which} \ + observed_cpu_ms={} observed_wall_ms={} observed_rss_growth_bytes={} \ + cpu_limit_ms={preparation_cpu_limit_ms} wall_limit_ms={preparation_wall_limit_ms} \ + rss_growth_limit_bytes={preparation_rss_growth_limit_bytes} -- a derived \ + cross-claim share warm exceeded the preparation limits (v2.workflow.required_floor); \ + no claim executed", + warm.cpu_ms, warm.wall_ms, warm.rss_growth_bytes, + )); + } + } let mut outcome = RequiredFloorOutcome { subject_digest: prepared.subject_digest.clone(), modules_resolved: prepared.modules_resolved, @@ -12829,78 +13057,6 @@ mod pure_producer_share_tests { extra.iter().map(|m| m.to_string()).collect() } - const EMPTY_ROSTER_TAIL: &str = - "data floor_cross_claim_pure_producers_claim_forced: List = []\n\ - type CarriedInputDependence =\n\ - BoundParameter { parameter: String }\n\ - | ImplicitAcquisition\n\ - type PreparedEffectInput {\n\ - acquisition: String\n\ - checkout_input: String\n\ - ground: String\n\ - measurement: String\n\ - }\n\ - type CarriedInputWarmRow {\n\ - producer: String\n\ - carried_input: String\n\ - dependence: CarriedInputDependence\n\ - measurement: String\n\ - }\n\ - data floor_cross_claim_prepared_effect_inputs: List = []\n\ - data floor_cross_claim_carried_input_warm_rows: List = []\n\ - type ShareRefusalVerdict =\n\ - MeasuredServeAboveRecompute\n\ - | NoMeasuredEffectOverItsConsumers\n\ - type RefusedShareCandidate {\n\ - producer: String\n\ - verdict: ShareRefusalVerdict\n\ - carrier_modules: List\n\ - measurement: String\n\ - next_trigger: String\n\ - }\n\ - data floor_cross_claim_refused_candidates: List = []\n"; - - fn roster_naming(row: &str) -> String { - format!( - "module v2.workflow.floor_pure_producer_share\n\ - data floor_cross_claim_pure_producers_warm: List = [\"{row}\"]\n{EMPTY_ROSTER_TAIL}" - ) - } - - /// THE gunbc#11452 SHAPE: a row naming a LIVE producer whose module the corpus carries but - /// this narrow subject does not is not evaluated, and the install succeeds. - #[test] - fn a_live_row_outside_the_prepared_subject_is_not_evaluated() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - &roster_naming("test.claim.elsewhere.emit.witness_apply_script"), - )]); - let warms = - install_pure_producer_share(&prepared, &fixture_corpus(&["test.claim.elsewhere.emit"])) - .expect("a live row outside the subject must not stop the line"); - assert!(warms.is_empty(), "nothing outside the subject warms"); - v1_interpreter::clear_cross_claim_pure_memos(); - } - - /// The discriminating RED beside it: the SAME row, with its module absent from the corpus, - /// is stale and refuses with the cause that tells the author to delete it. - #[test] - fn a_row_whose_module_no_root_carries_refuses_as_stale() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - &roster_naming("test.claim.elsewhere.emit.witness_apply_script"), - )]); - let err = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect_err("a row naming no corpus module must refuse"); - assert!( - err.contains("PureProducerShareRowModuleAbsentFromCorpus") && err.contains("stale"), - "refusal must name the stale cause: {err}" - ); - v1_interpreter::clear_cross_claim_pure_memos(); - } - /// THE CLOSURE RED the review asked for: a prepared subject WITHOUT the roster module /// must REFUSE, never skip — a skip leaves admission empty while the floor reads green, /// memoizing nothing. @@ -12920,235 +13076,6 @@ mod pure_producer_share_tests { v1_interpreter::clear_cross_claim_pure_memos(); } - /// Positive control: a subject carrying the roster module warms its nullary rows into - /// the cross-claim store. - #[test] - fn a_carried_roster_warms_and_stores_its_nullary_rows() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - "module v2.workflow.floor_pure_producer_share\n\ - fn tm_local() -> Bool { true }\n\ - data floor_cross_claim_pure_producers_warm: List = [\"v2.workflow.floor_pure_producer_share.tm_local\"]\n\ - data floor_cross_claim_pure_producers_claim_forced: List = [\"v2.workflow.floor_pure_producer_share.tm_local\"]\n\ - type ShareRefusalVerdict =\n\ - MeasuredServeAboveRecompute\n\ - | NoMeasuredEffectOverItsConsumers\n\ - type RefusedShareCandidate {\n\ - producer: String\n\ - verdict: ShareRefusalVerdict\n\ - carrier_modules: List\n\ - measurement: String\n\ - next_trigger: String\n\ - }\n\ - type CarriedInputDependence =\n\ - BoundParameter { parameter: String }\n\ - | ImplicitAcquisition\n\ - type PreparedEffectInput {\n\ - acquisition: String\n\ - checkout_input: String\n\ - ground: String\n\ - measurement: String\n\ - }\n\ - type CarriedInputWarmRow {\n\ - producer: String\n\ - carried_input: String\n\ - dependence: CarriedInputDependence\n\ - measurement: String\n\ - }\n\ - data floor_cross_claim_prepared_effect_inputs: List = []\n\ - data floor_cross_claim_carried_input_warm_rows: List = []\n\ - data floor_cross_claim_refused_candidates: List = [\n\ - RefusedShareCandidate {\n\ - producer: \"v2.workflow.floor_pure_producer_share.tm_refused\",\n\ - verdict: MeasuredServeAboveRecompute,\n\ - carrier_modules: [\"v2.test.fixture.a_consumer\"],\n\ - measurement: \"fixture\",\n\ - next_trigger: \"fixture\"\n\ - }\n\ - ]\n", - )]); - let observations = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect("carried roster installs and warms"); - let (stores, overflow) = v1_interpreter::cross_claim_pure_memo_counts(); - assert_eq!(overflow, 0); - assert!(stores >= 1, "the warm must land in the store, got {stores}"); - // THE DISCRIMINATING ASSERTION, and it is why this control is no longer only positive: - // the warm is a shared preparation build, and a shared build that produces no - // observation is bounded by nothing -- the preparation refusal is denominated over the - // observations collected here. Before the observation existed this function returned - // `()`, so this assertion could not be written at all, which is precisely the shape of - // the gap: the cost was real, printed, and invisible to the only wall that could stop it. - assert_eq!( - observations.len(), - 1, - "one observation per warm row, got {observations:?}" - ); - let (label, observed) = &observations[0]; - assert_eq!( - label, "CrossClaimPureProducerWarm/v2.workflow.floor_pure_producer_share.tm_local", - "the label must name the ROW, since the refusal names one phase and a reader must \ - reach one roster row from it" - ); - // The three axes the preparation refusal reads. Asserting they are PRESENT rather than - // asserting a magnitude: a fixture's absolute cost is a property of the fixture and the - // runner it ran on, and a threshold copied from this tree would be the measurement-as- - // oracle DESIGN section 5 refuses. - let _: u64 = observed.cpu_ms; - let _: u64 = observed.wall_ms; - let _: u64 = observed.rss_growth_bytes; - v1_interpreter::clear_cross_claim_pure_memos(); - } - - /// THE RED FOR THE CONTENT-BLIND WARM: a nullary row that performs one confirmed checkout - /// read, rostered as a PLAIN warm row. Before the guard the warm path stored it under the - /// empty argument row — `Stored`, no refusal — so a changed file would have been served the - /// old value by every later claim. The read is a real hermetic checkout-input dispatch (the - /// test's cwd is inside the checkout and `Cargo.toml` is committed), not a stubbed counter, - /// so the wall is exercised on the path the floor runs. The positive control is - /// `a_carried_roster_warms_and_stores_its_nullary_rows`: a pure nullary row still stores. - #[test] - fn a_plain_warm_row_that_dispatches_an_effect_stops_the_line() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - "module v2.workflow.floor_pure_producer_share\n\ - service Filesystem {\n\ - operation Read {\n\ - input { path: String }\n\ - output {\n\ - content: String from \"content\"\n\ - success: Bool from \"read_success\"\n\ - error: String from \"error\"\n\ - error_kind: String from \"error_kind\"\n\ - }\n\ - readonly\n\ - transport file { path: \"{path}\" }\n\ - }\n\ - }\n\ - fn reads_checkout() -> String {\n\ - let read = Filesystem.Read(path: \"Cargo.toml\")\n\ - read.content\n\ - }\n\ - data floor_cross_claim_pure_producers_warm: List = [\"v2.workflow.floor_pure_producer_share.reads_checkout\"]\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ - type ShareRefusalVerdict =\n\ - MeasuredServeAboveRecompute\n\ - | NoMeasuredEffectOverItsConsumers\n\ - type RefusedShareCandidate {\n\ - producer: String\n\ - verdict: ShareRefusalVerdict\n\ - carrier_modules: List\n\ - measurement: String\n\ - next_trigger: String\n\ - }\n\ - type CarriedInputDependence =\n\ - BoundParameter { parameter: String }\n\ - | ImplicitAcquisition\n\ - type PreparedEffectInput {\n\ - acquisition: String\n\ - checkout_input: String\n\ - ground: String\n\ - measurement: String\n\ - }\n\ - type CarriedInputWarmRow {\n\ - producer: String\n\ - carried_input: String\n\ - dependence: CarriedInputDependence\n\ - measurement: String\n\ - }\n\ - data floor_cross_claim_prepared_effect_inputs: List = []\n\ - data floor_cross_claim_carried_input_warm_rows: List = []\n\ - data floor_cross_claim_refused_candidates: List = []\n", - )]); - let err = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect_err("an effectful plain warm row must refuse, never store content-blind"); - assert!( - err.contains("cause=PureProducerShareWarmDispatchedEffect") - && err.contains("producer=v2.workflow.floor_pure_producer_share.reads_checkout") - && err.contains("effects=1"), - "the refusal must name the cause, the row and the dispatch it saw: {err}" - ); - let (stores, _) = v1_interpreter::cross_claim_pure_memo_counts(); - assert_eq!(stores, 0, "nothing may be retained for the refused row"); - v1_interpreter::clear_cross_claim_pure_memos(); - } - - /// THE `AlreadyPresent` PATH REPORTS THAT IT FOUND THE VALUE, NOT THAT IT BUILT IT. - /// The discriminating red for review 59035: before the fix this asserted - /// `BuiltByPreparation` on a warm that built nothing, so the receipt claimed preparation - /// produced an artifact it merely found. Running the install TWICE without clearing the - /// memos in between is what puts the second warm on that path, and nothing else in this - /// module reaches it — which is why the defect survived the first round of tests. - #[test] - fn a_second_warm_of_the_same_producer_reports_that_it_was_found_not_built() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - "module v2.workflow.floor_pure_producer_share\n\ - fn tm_local() -> Bool { true }\n\ - data floor_cross_claim_pure_producers_warm: List = [\"v2.workflow.floor_pure_producer_share.tm_local\"]\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ - type ShareRefusalVerdict =\n\ - MeasuredServeAboveRecompute\n\ - | NoMeasuredEffectOverItsConsumers\n\ - type RefusedShareCandidate {\n\ - producer: String\n\ - verdict: ShareRefusalVerdict\n\ - carrier_modules: List\n\ - measurement: String\n\ - next_trigger: String\n\ - }\n\ - type CarriedInputDependence =\n\ - BoundParameter { parameter: String }\n\ - | ImplicitAcquisition\n\ - type PreparedEffectInput {\n\ - acquisition: String\n\ - checkout_input: String\n\ - ground: String\n\ - measurement: String\n\ - }\n\ - type CarriedInputWarmRow {\n\ - producer: String\n\ - carried_input: String\n\ - dependence: CarriedInputDependence\n\ - measurement: String\n\ - }\n\ - data floor_cross_claim_prepared_effect_inputs: List = []\n\ - data floor_cross_claim_carried_input_warm_rows: List = []\n\ - data floor_cross_claim_refused_candidates: List = []\n", - )]); - - let first = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect("first install warms"); - assert!( - matches!( - first[0].1.provenance, - SharedBuildProvenance::BuiltByPreparation - ), - "the first warm BUILDS it: {:?}", - first[0].1.provenance - ); - - // No `clear_cross_claim_pure_memos()` here, deliberately: the retained value is the - // whole subject of this test. - let second = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect("second install re-warms"); - match &second[0].1.provenance { - SharedBuildProvenance::AlreadyWarmOnEntry { triggered_by } => { - // The label names a BOUNDARY and not a call site, because `AlreadyPresent` - // establishes presence and not cause. Asserting the exact string keeps a - // future edit from quietly upgrading it into a fabricated attribution. - assert_eq!( - *triggered_by, - "an-earlier-rostered-producer-in-this-warm-loop" - ); - } - other => panic!("a warm that found the value must not claim it built it: {other:?}"), - } - v1_interpreter::clear_cross_claim_pure_memos(); - } - /// The fixture roster for the carried-input tests: one acquisition (`carrier_a`), one /// producer that reaches it nullary (`projection`), and a SECOND acquisition returning /// different content (`carrier_b`) which exists only so a test can bind a different carrier @@ -13163,8 +13090,6 @@ mod pure_producer_share_tests { fn carrier_b() -> String {{ \"content-B\" }}\n\ fn projection() -> String {{ concat(\"projected:\", carrier_a()) }}\n\ fn consumer() -> String {{ projection() }}\n\ - data floor_cross_claim_pure_producers_warm: List = []\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ type CarriedInputDependence =\n\ BoundParameter {{ parameter: String }}\n\ | ImplicitAcquisition\n\ @@ -13383,8 +13308,6 @@ mod pure_producer_share_tests { "module v2.workflow.floor_pure_producer_share\n\ fn carrier_a() -> String { \"content-A\" }\n\ fn projection() -> String { concat(\"projected:\", carrier_a()) }\n\ - data floor_cross_claim_pure_producers_warm: List = []\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ type CarriedInputDependence =\n\ BoundParameter { parameter: String }\n\ | ImplicitAcquisition\n\ @@ -13440,8 +13363,6 @@ mod pure_producer_share_tests { "module v2.workflow.floor_pure_producer_share\n\ fn carrier_a(seed: String) -> String { concat(\"content-\", seed) }\n\ fn projection() -> String { \"projected\" }\n\ - data floor_cross_claim_pure_producers_warm: List = []\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ type CarriedInputDependence =\n\ BoundParameter { parameter: String }\n\ | ImplicitAcquisition\n\ @@ -13486,45 +13407,6 @@ mod pure_producer_share_tests { ); v1_interpreter::clear_cross_claim_pure_memos(); } - - /// A warm row naming a producer the subject cannot resolve stops the line. - #[test] - fn a_stale_warm_row_stops_the_line() { - v1_interpreter::clear_cross_claim_pure_memos(); - let prepared = prepared_from(&[( - "workspace/src/v2/workflow/floor_pure_producer_share.dag", - "module v2.workflow.floor_pure_producer_share\n\ - data floor_cross_claim_pure_producers_warm: List = [\"v2.workflow.floor_pure_producer_share.tm_gone\"]\n\ - data floor_cross_claim_pure_producers_claim_forced: List = []\n\ - type CarriedInputDependence =\n\ - BoundParameter { parameter: String }\n\ - | ImplicitAcquisition\n\ - type PreparedEffectInput {\n\ - acquisition: String\n\ - checkout_input: String\n\ - ground: String\n\ - measurement: String\n\ - }\n\ - type CarriedInputWarmRow {\n\ - producer: String\n\ - carried_input: String\n\ - dependence: CarriedInputDependence\n\ - measurement: String\n\ - }\n\ - data floor_cross_claim_prepared_effect_inputs: List = []\n\ - data floor_cross_claim_carried_input_warm_rows: List = []\n\ -", - )]); - let err = install_pure_producer_share(&prepared, &fixture_corpus(&[])) - .expect_err("a stale warm row must stop the line"); - // The stop now lands at roster RESOLUTION (admission is by resolved declaration - // identity), before any warm runs — same line-stop, more precisely located. - assert!( - err.contains("PureProducerShareProducerUnresolved"), - "refusal must name the cause: {err}" - ); - v1_interpreter::clear_cross_claim_pure_memos(); - } } #[cfg(test)] diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index da09a84f05f..c308e077c74 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2142,6 +2142,15 @@ thread_local! { RefCell::new(std::collections::HashSet::new()); static CROSS_CLAIM_SHARE_OBSERVER: RefCell> = const { RefCell::new(None) }; + /// Producers admitted by the DERIVED share (`v2.workflow.floor_pure_producer_share` + /// `derive_cross_claim_share`): fn nodes whose admission is not the producer but specific + /// call sites of it, so a call from any other site -- whose argument row the derivation never + /// judged closed -- stays outside the tier. + static CROSS_CLAIM_SITE_GATED: RefCell> = + RefCell::new(std::collections::HashSet::new()); + /// The admitted call sites of site-gated producers, as `(file, start, end)` byte spans. + static CROSS_CLAIM_ADMITTED_SITES: RefCell> = + RefCell::new(std::collections::HashSet::new()); } /// Clears stored values, roster and observer together: the tier's lifetime is ONE prepared @@ -2152,6 +2161,8 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_PURE_MEMO.with(|m| *m.borrow_mut() = CrossClaimPureMemo::default()); CROSS_CLAIM_FN_KEEPALIVE.with(|k| k.borrow_mut().clear()); CROSS_CLAIM_PURE_ROSTER.with(|r| r.borrow_mut().clear()); + CROSS_CLAIM_SITE_GATED.with(|g| g.borrow_mut().clear()); + CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().clear()); CROSS_CLAIM_SHARE_OBSERVER.with(|o| *o.borrow_mut() = None); // The prepared effect inputs are tier state too, and for the sharpest reason: a carry that // outlived its subject would serve a later, differently-prepared evaluation a value acquired @@ -2179,6 +2190,44 @@ pub fn install_cross_claim_pure_share_roster>>(n } } +/// Install the DERIVED share: each producer node is admitted at the listed call sites only. +/// Adds to whatever the roster install admitted (carried-input producers keep their own +/// admission); the site set replaces any previous derivation's. +pub fn install_cross_claim_derived_share>>( + nodes: I, + sites: std::collections::HashSet<(String, i64, i64)>, +) { + let nodes: Vec> = nodes.into_iter().collect(); + CROSS_CLAIM_PURE_ROSTER.with(|r| { + let mut r = r.borrow_mut(); + for node in &nodes { + r.insert(Rc::as_ptr(node) as usize); + } + }); + CROSS_CLAIM_SITE_GATED.with(|g| { + *g.borrow_mut() = nodes.iter().map(|n| Rc::as_ptr(n) as usize).collect(); + }); + CROSS_CLAIM_ADMITTED_SITES.with(|a| *a.borrow_mut() = sites); + for node in &nodes { + keep_cross_claim_fn(node); + } +} + +/// Whether THIS call site may use the cross-claim tier for `fn_node`. True for every producer +/// admitted without a site gate; for a derived producer, only at a site the derivation admitted. +fn cross_claim_site_admitted(fn_node: &Rc, call_node: &Node) -> bool { + let gated = + CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); + !gated + || CROSS_CLAIM_ADMITTED_SITES.with(|a| { + a.borrow().contains(&( + call_node.span.file.to_string(), + call_node.span.start, + call_node.span.end, + )) + }) +} + /// Install the shared-fill observer for the cross-claim tier. `None` uninstalls. pub fn install_cross_claim_share_observer(observer: Option) { CROSS_CLAIM_SHARE_OBSERVER.with(|o| *o.borrow_mut() = observer); @@ -2582,64 +2631,73 @@ pub fn take_cross_claim_store_digest(func_name: &str) -> Option { }) } -/// Why a plain nullary warm stored nothing. Typed apart so the floor names the cause: a -/// dispatched effect is a roster defect with its own remedy, not an evaluation failure. +/// Why a derived call-site warm stored nothing it could serve. Typed apart so the floor counts +/// each cause: a dispatched effect means the value depends on an input the key cannot see, an +/// evaluation failure means the call is not computable in isolation (a refusal fixture, say), and +/// a store the tier declined carries its own outcome. #[derive(Debug)] -pub enum PureProducerWarmRefusal { +pub enum CallSiteWarmRefusal { DispatchedEffect { effects: u64 }, - Failed(String), + EvaluationFailed(String), + NotStored(CrossClaimStoreOutcome), } -/// Evaluate one rostered NULLARY producer in `ctx` and seed the cross-claim tier, under the -/// same guard protocol as a claim-forced fill — so a preparation warm lands in the ledger as an -/// outside-fold fill, not on the first claim. Returns the TYPED outcome: a servable tier -/// (`Stored`, `AlreadyPresent`) vs each refusal by name, not one boolean. -pub fn warm_cross_claim_pure_producer( +impl CallSiteWarmRefusal { + pub fn cause(&self) -> String { + match self { + CallSiteWarmRefusal::DispatchedEffect { effects } => { + format!("DispatchedEffect(effects={effects})") + } + CallSiteWarmRefusal::EvaluationFailed(_) => "EvaluationFailed".to_string(), + CallSiteWarmRefusal::NotStored(outcome) => outcome.cause().to_string(), + } + } +} + +/// Warm ONE admitted call site of a derived producer in `ctx` (a frame over the site's module): +/// evaluate the site's closed arguments with no lexical bindings, call the producer, and publish +/// through the ordinary store under the same fill guard a claim-time fill holds, so the fill lands +/// in the shared-fill ledger outside the fold. `fn_node` must be the node the frame resolves the +/// callee to, which is the identity the tier keys on. +pub fn warm_cross_claim_call_site( ctx: &InterpContext, - qualified_fn: &str, -) -> Result { + fn_node: &Rc, + call_node: &Rc, +) -> Result { with_active_ctx(ctx, || { - let fn_node = ctx - .lookup_fn(qualified_fn) - .ok_or_else(|| { - PureProducerWarmRefusal::Failed(format!( - "no declaration named '{qualified_fn}' in this frame" - )) - })? - .clone(); - let bare = qualified_fn.rsplit('.').next().unwrap_or(qualified_fn); - if !cross_claim_pure_admitted(&fn_node, bare) { - return Err(PureProducerWarmRefusal::Failed(format!( - "'{qualified_fn}' did not resolve to an installed cross-claim roster identity" - ))); - } - let guard = CrossClaimFillGuard::enter(bare); + let func_name = fn_node.name.clone(); let env = Env::empty(); - // THE SAME GUARD THE FOLD PATH HOLDS. The claim-time store refuses to publish a value - // whose evaluation dispatched an effect, because the key `(fn node, argument row)` cannot - // see what the effect read. The warm path stored without that guard, so an effectful - // nullary row rostered as a plain warm row was stored CONTENT-BLIND under the empty - // argument row — the key omitting an input the value depends on. A dispatch here is a - // roster defect (the row belongs in the prepared-effect-input rows, where the read is - // carried and keyed), so it stops the line rather than declining silently. let effects_before = ctx.effect_dispatch_count.get(); - let value = with_lexical_base_env(&env, || call_function(ctx, &fn_node, &[], &env)) - .map_err(|e| PureProducerWarmRefusal::Failed(format!("{qualified_fn}: {e}")))?; + let args: Vec<(Option, Value)> = call_node + .children + .iter() + .filter(|arg_node| !arg_node.children.is_empty()) + .map(|arg_node| { + let name = arg_name_at(arg_node.clone(), ctx.si()); + let val = with_lexical_base_env(&env, || { + eval_expr(&arg_value(arg_node.clone()), &env, ctx) + })?; + Ok((name, val)) + }) + .collect::>() + .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; + let guard = CrossClaimFillGuard::enter(&func_name); + let value = with_lexical_base_env(&env, || call_function(ctx, fn_node, &args, &env)) + .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; let effects = ctx .effect_dispatch_count .get() .saturating_sub(effects_before); if effects != 0 { - return Err(PureProducerWarmRefusal::DispatchedEffect { effects }); + return Err(CallSiteWarmRefusal::DispatchedEffect { effects }); + } + let outcome = + store_cross_claim_pure_memo(ctx, fn_node, &func_name, &args, &value, Some(&guard)); + if outcome.is_servable() { + Ok(outcome) + } else { + Err(CallSiteWarmRefusal::NotStored(outcome)) } - Ok(store_cross_claim_pure_memo( - ctx, - &fn_node, - bare, - &[], - &value, - Some(&guard), - )) }) } @@ -3636,6 +3694,58 @@ mod cross_claim_memo_tests { } } + // THE SITE GATE OF THE DERIVED SHARE. A derived producer is admitted at the call sites the + // derivation judged closed and nowhere else: the same producer called from another site has an + // argument row nobody judged, so it must stay outside the tier. The discriminating pair varies + // only the call site; the control is a producer admitted without a gate (a carried-input + // producer), which is unaffected by any site set. + #[test] + fn a_derived_producer_is_admitted_only_at_its_admitted_sites() { + use super::{ + cross_claim_site_admitted, install_cross_claim_derived_share, + install_cross_claim_pure_share_roster, + }; + super::clear_cross_claim_pure_memos(); + let node_at = |start: i64, end: i64| { + make_expr_node( + Rc::new( + crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic, + ), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + Rc::new(crate::std_types::SourceSpan { + file: "workspace/src/n7.dag".to_string(), + start, + end, + }), + ) + }; + let derived = node_at(0, 1); + let ungated = node_at(2, 3); + install_cross_claim_pure_share_roster([ungated.clone()]); + let mut sites = std::collections::HashSet::new(); + sites.insert(("workspace/src/n7.dag".to_string(), 100, 140)); + install_cross_claim_derived_share([derived.clone()], sites); + assert!( + cross_claim_site_admitted(&derived, &node_at(100, 140)), + "the admitted site uses the tier" + ); + assert!( + !cross_claim_site_admitted(&derived, &node_at(200, 240)), + "another site of the same derived producer must not" + ); + assert!( + cross_claim_site_admitted(&ungated, &node_at(200, 240)), + "control: a producer admitted without a site gate is unaffected" + ); + super::clear_cross_claim_pure_memos(); + assert!( + cross_claim_site_admitted(&derived, &node_at(200, 240)), + "clearing the tier clears the gate with it" + ); + } + // RED (review 57446 F1): admission is by RESOLVED DECLARATION IDENTITY, so a bare-name // HOMONYM in a non-rostered module must NOT store — name-set admission cached any // same-named fn in the subject. Fn-node identity in the key stopped cross-SERVING between @@ -9869,13 +9979,18 @@ fn eval_pure_named_call( args: &[(Option, Value)], env: &Rc, ) -> InterpResult { - if let Some(v) = try_cross_claim_pure_memo(ctx, fn_node, func_name, args) { - return Ok(v); + // A derived producer is admitted at its admitted call sites only; from any other site the + // call neither serves nor stores, exactly as if the producer were not admitted at all. + let share_site = cross_claim_site_admitted(fn_node, call_node); + if share_site { + if let Some(v) = try_cross_claim_pure_memo(ctx, fn_node, func_name, args) { + return Ok(v); + } } // Guard runs only for admitted calls: a store that lands must carry what it cost, so the // paying claim's receipt can net it and the shared-fill ledger can attribute it. Its // `Drop` closes the fill on every path out of this function. - let fill_guard = if cross_claim_pure_admitted(fn_node, func_name) { + let fill_guard = if share_site && cross_claim_pure_admitted(fn_node, func_name) { Some(CrossClaimFillGuard::enter(func_name)) } else { None @@ -9886,7 +10001,7 @@ fn eval_pure_named_call( let effects_before = ctx.effect_dispatch_count.get(); let result = call_function(ctx, fn_node, args, env); if let Ok(v) = &result { - if ctx.effect_dispatch_count.get() == effects_before { + if share_site && ctx.effect_dispatch_count.get() == effects_before { // The ordinary call path publishes opportunistically: every outcome, // servable or refused, is already counted inside the store, and this // call recomputes on a refusal exactly as if never enrolled. @@ -9943,7 +10058,7 @@ fn eval_pure_named_call( let effects_before = ctx.effect_dispatch_count.get(); let result = call_function(ctx, fn_node, args, env); if let Ok(v) = &result { - if ctx.effect_dispatch_count.get() == effects_before { + if share_site && ctx.effect_dispatch_count.get() == effects_before { let _ = store_cross_claim_pure_memo(ctx, fn_node, func_name, args, v, fill_guard.as_ref()); } diff --git a/src/v2/compiler/program_assembly.dag b/src/v2/compiler/program_assembly.dag index 1b44f964751..739d1ddd3ab 100644 --- a/src/v2/compiler/program_assembly.dag +++ b/src/v2/compiler/program_assembly.dag @@ -485,8 +485,8 @@ data program_assembly_prepare_once_note: String = "prepare_grammar is hoisted AB // `dag_grammar()` before its fold can start, and `prepare_grammar` is the cross-claim pure tier's // built-in admitted arm, so one fill serves every claim — if it ever lands. The fill costs more // than one claim's CPU budget, so an in-fold first touch dies mid-flight (FillBudgetExceeded) and is -// abandoned un-stored, and the next claim starts it over. Enrolled in -// `floor_cross_claim_pure_producers_warm` (v2.workflow.floor_pure_producer_share) so the required +// abandoned un-stored, and the next claim starts it over. Admitted by the derived +// cross-claim share (v2.workflow.floor_pure_producer_share derive_cross_claim_share) so the required // floor evaluates this nullary producer during strict preparation — outside every per-claim // budget — and the inner `prepare_grammar` fill lands in the tier before any claim runs. fn dag_prepared_grammar() -> Outcome { diff --git a/src/v2/compiler/self_host/direct_rust_door_fixture.dag b/src/v2/compiler/self_host/direct_rust_door_fixture.dag index 297db5ddb0d..553b74d6d59 100644 --- a/src/v2/compiler/self_host/direct_rust_door_fixture.dag +++ b/src/v2/compiler/self_host/direct_rust_door_fixture.dag @@ -106,9 +106,8 @@ fn direct_rust_door_admission() -> Admission { // stage whose value is closure-free and therefore portable (the InferredTree one stage up carries // the facts PartialFunction and is deliberately not the share point), so the resolved tree is the // cross-claim share point and infer stays per claim. `direct_rust_door_specimen_resolved` is -// nullary and warm-enrolled in `v2.workflow.floor_pure_producer_share` -// (floor_cross_claim_pure_producers_warm), which carries the measured recompute/sharing/serve -// case; the required floor forces it during strict preparation, outside every per-claim budget. +// nullary, so the derived cross-claim share (`v2.workflow.floor_pure_producer_share` +// derive_cross_claim_share) admits it when several planned claims reach it; the required floor forces it during strict preparation, outside every per-claim budget. fn direct_rust_door_specimen_resolved() -> Outcome { assemble_program_from_ingest( ingest: direct_rust_door_ingest(), diff --git a/src/v2/extdeps/languages/dag.dag b/src/v2/extdeps/languages/dag.dag index a6dcdab3a1e..86ff3bdb2c8 100644 --- a/src/v2/extdeps/languages/dag.dag +++ b/src/v2/extdeps/languages/dag.dag @@ -3553,7 +3553,7 @@ fn dag_language_model_binding_canonical_map(m: Map) -> Map) -> Bool { // ONE PARSE PER SOURCE, EVERY VERDICT READ OFF IT. Each claim below inspects one Bool of this value, // and each would otherwise pay its own tokenize, parse and lowering -- the ingest the claims are not -// about. The producer is rostered in v2.workflow.floor_pure_producer_share -// floor_cross_claim_pure_producers_warm, like v2.test.claim.fold_lowering flp_outcomes; the value is -// six Bools, portable for that roster's reason. +// about. The producer is shared by v2.workflow.floor_pure_producer_share +// derive_cross_claim_share, like v2.test.claim.fold_lowering flp_outcomes; the value is +// six Bools, so it reifies portably. type FosOutcomes { and_reader_over_loop: Bool and_walker_over_loop: Bool diff --git a/src/v2/test/claim/body_lowering/map_literal_test.dag b/src/v2/test/claim/body_lowering/map_literal_test.dag index 7e2e25942b9..39fe66cd7e4 100644 --- a/src/v2/test/claim/body_lowering/map_literal_test.dag +++ b/src/v2/test/claim/body_lowering/map_literal_test.dag @@ -122,8 +122,8 @@ data ml_mixed_ingest: SourceRootIngest = [ ] // THE FRONT END RUNS ONCE, NOT ONCE PER CLAIM. The fixture ingest and each subject's resolve are -// nullary pure producers, served across witnesses from v2.workflow.floor_pure_producer_share -// floor_cross_claim_pure_producers_warm (the rows beside #12740's anonymous_record producers); every +// nullary pure producers, served across witnesses by v2.workflow.floor_pure_producer_share +// derive_cross_claim_share (as #12740's anonymous_record producers are); every // claim below only inspects a produced value (DESIGN section 3: a witness discriminates at one // interface, and the front end is not its subject). fn ml_fixture_normalized() -> Outcome> { diff --git a/src/v2/test/claim/body_type_annotation_refusal_test.dag b/src/v2/test/claim/body_type_annotation_refusal_test.dag index 152ee6d391f..d8ceed6b209 100644 --- a/src/v2/test/claim/body_type_annotation_refusal_test.dag +++ b/src/v2/test/claim/body_type_annotation_refusal_test.dag @@ -126,7 +126,7 @@ test fn btar_unannotated_fn_literal_is_not_erased() -> Bool { } // ONE WARM PRODUCER FOR THE TWO FN-LITERAL VERDICTS (3) and (4): each once paid its own front end. -// Enrolled in v2.workflow.floor_pure_producer_share floor_cross_claim_pure_producers_warm; the +// Shared by v2.workflow.floor_pure_producer_share derive_cross_claim_share; the // claims only read their Bool. type BtarFnLiteralOutcomes { annotated_reaches_resolve: Bool diff --git a/src/v2/test/claim/execution/emit_on_demand_family_crate_witness_test.dag b/src/v2/test/claim/execution/emit_on_demand_family_crate_witness_test.dag index 226a36d197d..aff858f6de3 100644 --- a/src/v2/test/claim/execution/emit_on_demand_family_crate_witness_test.dag +++ b/src/v2/test/claim/execution/emit_on_demand_family_crate_witness_test.dag @@ -174,9 +174,9 @@ fn family_crate_native_key(members: List) -> ContentHash { // required floor measured all six within one runner-swing of the 500ms per-claim ceiling (run // 34315228217: 458-487ms cpu against limit_ms=500). The members are not portable (InferredTree's // facts PartialFunction), so the share point is the deepest portable stage: the emitted crate -// source plus its native key. Nullary and warm-enrolled in -// `v2.workflow.floor_pure_producer_share` (floor_cross_claim_pure_producers_warm), which carries -// the measured recompute/sharing/serve case; the required floor forces it during strict +// source plus its native key. Nullary, so the derived cross-claim share +// (`v2.workflow.floor_pure_producer_share` derive_cross_claim_share) admits it when several planned +// claims reach it; the required floor forces it during strict // preparation, outside every per-claim budget, and each claim pays only the cached native run. fn logic_family_primary_emitted() -> Outcome { let members = family_crate_members() diff --git a/src/v2/test/claim/execution/emit_on_demand_match_loop_fold_family_witness_test.dag b/src/v2/test/claim/execution/emit_on_demand_match_loop_fold_family_witness_test.dag index 068aee1cb71..ae1444908cf 100644 --- a/src/v2/test/claim/execution/emit_on_demand_match_loop_fold_family_witness_test.dag +++ b/src/v2/test/claim/execution/emit_on_demand_match_loop_fold_family_witness_test.dag @@ -241,9 +241,9 @@ fn mlf_family_native_key(members: List) -> ContentHash { // and the required floor measured all six within one runner-swing of the 500ms per-claim ceiling // (run 34315228217: 462-504ms cpu, loop_holds over). The members are not portable (InferredTree's // facts PartialFunction), so the share point is the deepest portable stage: the emitted crate -// source plus its native key. Nullary and warm-enrolled in -// `v2.workflow.floor_pure_producer_share` (floor_cross_claim_pure_producers_warm), which carries -// the measured recompute/sharing/serve case; the required floor forces it during strict +// source plus its native key. Nullary, so the derived cross-claim share +// (`v2.workflow.floor_pure_producer_share` derive_cross_claim_share) admits it when several planned +// claims reach it; the required floor forces it during strict // preparation, outside every per-claim budget, and each claim pays only the cached native run. fn mlf_family_primary_emitted() -> Outcome { match match_primary_tree() { diff --git a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag index 273ac1400d8..8aa1e2107a2 100644 --- a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag +++ b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag @@ -7,32 +7,32 @@ import v2.workflow.floor_pure_producer_share { NoMeasuredEffectOverItsConsumers, SupersededBySingleAuthorityRepair, KeyOmitsAnInputTheValueDependsOn, floor_cross_claim_refused_candidates, - floor_cross_claim_admitted_producers, refused_share_producers, - share_roster_refusal_collisions, refused_row_carriers_transfer, - PendingShareCandidate, - floor_cross_claim_pending_candidates, - pending_share_producers, - share_roster_pending_collisions -} + CarriedInputWarmRow, ImplicitAcquisition, + CallSiteDemandObservation, ClosedCallSiteDemand, UnadmissibleCallSiteDemand, + CallSiteDemandCause, ArgumentNotClosedConstant, CalleeDeclaresEffects, + CrossClaimShareDerivation, DeclinedShareRow, + ShareDerivationDecline, DemandedByOneClaim, IdentityGradeNotShareable, RefusedByMeasurement, CarriedInputProducer, + derive_cross_claim_share, floor_cross_claim_share_derivation, + cross_claim_share_derivation_reconciles, derived_share_producers +} +import std.computation_identity { ComputationIdentity, NormalizedIdentical, IdentityUnknown, MissingConcept } import v2.std.collection { List } +import v2.std.algebra { list_map } import v2.std.logic { Bool } import v2.std.live_tree { LiveTreeDisposition, SubstrateInputsOnly } data live_tree_disposition: LiveTreeDisposition = SubstrateInputsOnly -// THE WALL UNDER TEST: `v2.workflow.floor_pure_producer_share` measures share candidates and -// turns some of them down, and until the refused roster existed a withdrawal had nowhere to live -// but an annotation -- a channel DESIGN section 4c says no `Accepted` program can read. These -// probes are what make the refusal mechanical instead of advisory. -// -// THE PAIR IS THE POINT. A disjointness assertion over the LIVE rosters alone is green today and -// can be reddened only by editing the corpus it guards, which DESIGN section 4b calls a -// decoration -- permanently green by construction, carrying no information, and worse than absent -// because it would be cited as coverage. So the collision fold takes its two populations as -// ARGUMENTS: the fixtures below are the source a fixture harness may hand it, where the forbidden -// state is perfectly writable, and the live tree is the positive control. +// THE DECISION UNDER TEST: `v2.workflow.floor_pure_producer_share` `derive_cross_claim_share`, +// the fold that admits a pure computation for cross-claim sharing from the planned claims' +// observed call-site demand. Every probe below hands it authored observation rows -- the forbidden +// states are writable as source handed to the fold, so each RED is authorable -- and the live +// derivation over this tree's refused and carried rows is the positive control. The real +// observation path (the seed walking a prepared subject) is exercised by the required floor +// itself and by `v1_compiler.cli_run.claim_call_site_demand`'s own tests; this module judges the +// decision only. fn probe_refused_row(producer: String) -> RefusedShareCandidate { RefusedShareCandidate { @@ -49,67 +49,131 @@ data probe_refused: List = [ probe_refused_row(producer: "v2.probe.languages.rust.probe_core_edges") ] -// RED: an admitted roster that re-proposes a refused identity must be reported, and the report -// must NAME the identity rather than answer a count -- the remedy is "go read that refused row", -// which needs the row's key. -test fn a_re_proposed_refused_identity_collides_and_is_named() -> Bool { - let collisions = share_roster_refusal_collisions( - admitted: [ - "v2.probe.languages.bash.probe_fold_lex", - "v2.probe.languages.rust.probe_core_edges" - ], - refused: probe_refused - ) - (length(xs: collisions) == 1) - && any(xs: collisions, predicate: fn(c) { c == "v2.probe.languages.rust.probe_core_edges" }) -} - -// RED, both refused rows at once: the fold reports every collision rather than stopping at the -// first. A wall that names one of two re-proposals sends the next author back for a second round. -test fn every_re_proposed_refused_identity_is_reported_not_just_the_first() -> Bool { - let collisions = share_roster_refusal_collisions( - admitted: [ - "v2.probe.languages.rust.probe_target_model", - "v2.probe.languages.bash.probe_fold_lex", - "v2.probe.languages.rust.probe_core_edges" - ], - refused: probe_refused +fn probe_identity() -> ComputationIdentity { + NormalizedIdentical { normalizer: "authored fixture" } +} + +fn probe_closed(producer: String, claims: Int) -> CallSiteDemandObservation { + ClosedCallSiteDemand { + producer: producer, + argument_preimage: "(src: \"module text\")", + identity: probe_identity(), + claims: claims, + sites: ["v2/test/probe.dag:10-40"] + } +} + +data probe_carried: List = [ + CarriedInputWarmRow { + producer: "v2.probe.roadmap.probe_projection", + carried_input: "v2.probe.roadmap.probe_history_load", + dependence: ImplicitAcquisition, + measurement: "authored fixture; no run" + } +] + +fn probe_derive(observations: List) -> CrossClaimShareDerivation { + derive_cross_claim_share(observations: observations, refused: probe_refused, carried: probe_carried) +} + +fn decline_tag(decline: ShareDerivationDecline) -> String { + match decline { + DemandedByOneClaim => "DemandedByOneClaim" + IdentityGradeNotShareable => "IdentityGradeNotShareable" + RefusedByMeasurement => "RefusedByMeasurement" + CarriedInputProducer => "CarriedInputProducer" + } +} + +fn declined_as(d: CrossClaimShareDerivation, producer: String, decline: ShareDerivationDecline) -> Bool { + let wanted = decline_tag(decline: decline) + any(xs: d.declined, predicate: fn(row) { row.producer == producer && decline_tag(decline: row.decline) == wanted }) +} + +// THE DISCRIMINATING PAIR: one closed identity, varied ONLY in how many planned claims demand it. +// Two claims is the reuse obligation DESIGN section 2 names, so it is admitted; one claim has no +// least common ancestor above itself, so it is declined and named. A fold admitting every closed +// row passes the first and reds the second; a fold admitting nothing reds the first. +test fn a_closed_identity_two_claims_demand_is_admitted() -> Bool { + let d = probe_derive(observations: [probe_closed(producer: "v2.probe.n7.probe_assemble", claims: 2)]) + (length(xs: d.admitted) == 1) + && any(xs: derived_share_producers(derivation: d), predicate: fn(p) { p == "v2.probe.n7.probe_assemble" }) +} + +test fn a_closed_identity_one_claim_demands_is_declined_and_named() -> Bool { + let d = probe_derive(observations: [probe_closed(producer: "v2.probe.n7.probe_assemble", claims: 1)]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.probe.n7.probe_assemble", decline: DemandedByOneClaim) +} + +// A MEASURED REFUSAL OUTRANKS DEMAND. The producer is demanded by many claims and still declined, +// naming the refusal -- the literal re-proposal path of the refused-candidate class, now closed by +// construction rather than by a collision wall over an authored roster. +test fn a_refused_producer_is_declined_however_many_claims_demand_it() -> Bool { + let d = probe_derive(observations: [probe_closed(producer: "v2.probe.languages.rust.probe_core_edges", claims: 40)]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.probe.languages.rust.probe_core_edges", decline: RefusedByMeasurement) +} + +// A CARRIED-INPUT PRODUCER IS NEVER ADMITTED AS A PLAIN SHARE. Its entry is keyed on the carried +// content; admitting it again would make one value servable under a key that omits the carrier. +test fn a_carried_input_producer_is_declined_as_a_plain_share() -> Bool { + let d = probe_derive(observations: [probe_closed(producer: "v2.probe.roadmap.probe_projection", claims: 7)]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.probe.roadmap.probe_projection", decline: CarriedInputProducer) +} + +// AN UNKNOWN IDENTITY GRADE IS NOT SHAREABLE, by std.computation_identity's own predicate. +test fn an_identity_of_unknown_grade_is_declined() -> Bool { + let d = probe_derive(observations: [ + ClosedCallSiteDemand { + producer: "v2.probe.n7.probe_unknown", + argument_preimage: "()", + identity: IdentityUnknown { cause: MissingConcept { detail: "authored fixture" } }, + claims: 3, + sites: ["v2/test/probe.dag:50-60"] + } + ]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.probe.n7.probe_unknown", decline: IdentityGradeNotShareable) +} + +// NEVER WIDEN: a call with no closed identity is counted under its cause and is never admitted, +// however many claims reach it -- the absorbing fallback would admit its declaration instead. +test fn an_unadmissible_demand_is_counted_with_its_cause_and_never_admitted() -> Bool { + let d = probe_derive(observations: [ + UnadmissibleCallSiteDemand { cause: ArgumentNotClosedConstant, claims: 9, sites: 30 }, + UnadmissibleCallSiteDemand { cause: CalleeDeclaresEffects, claims: 4, sites: 5 } + ]) + (length(xs: d.admitted) == 0) + && (length(xs: d.declined) == 0) + && (length(xs: d.unadmissible) == 2) +} + +// THE PARTITION RECONCILES over a mixed population: every closed row lands in exactly one of +// admitted or declined, so a row silently dropped by the fold reds this. +test fn the_derivation_partitions_every_closed_observation() -> Bool { + let observations = [ + probe_closed(producer: "v2.probe.n7.probe_assemble", claims: 6), + probe_closed(producer: "v2.probe.n7.probe_single", claims: 1), + probe_closed(producer: "v2.probe.languages.rust.probe_target_model", claims: 3), + UnadmissibleCallSiteDemand { cause: ArgumentNotClosedConstant, claims: 2, sites: 2 } + ] + let d = probe_derive(observations: observations) + cross_claim_share_derivation_reconciles(observations: observations, derivation: d) + && (length(xs: d.admitted) == 1) + && (length(xs: d.declined) == 2) +} + +// THE LIVE POSITIVE CONTROL: the derivation the floor runs consults THIS TREE's refused rows. A +// live refused producer demanded by two claims is declined -- which reds if the floor's fold +// stopped reading floor_cross_claim_refused_candidates. +test fn the_live_derivation_declines_every_live_refused_producer() -> Bool { + let live_refused = refused_share_producers(refused: floor_cross_claim_refused_candidates) + let d = floor_cross_claim_share_derivation( + observations: list_map(xs: live_refused, f: fn(p) { probe_closed(producer: p, claims: 2) }) ) - length(xs: collisions) == 2 -} - -// GREEN CONTROL beside those REDs, and it is the conjunct that makes them mean something: an -// admitted roster sharing NO identity with the refused roster reports nothing. Without this a -// fold that returned its whole input would pass both probes above. -test fn a_roster_that_re_proposes_nothing_reports_no_collision() -> Bool { - length(xs: share_roster_refusal_collisions( - admitted: [ - "v2.probe.languages.bash.probe_fold_lex", - "v2.probe.languages.bash.probe_fold_productions" - ], - refused: probe_refused - )) == 0 -} - -// The empty-refusal control: with nothing refused, nothing collides however the admitted roster -// is spelled. DESIGN's `predicate_vacuously_true_on_an_empty_domain` cuts the other way here -- -// this is the arm that must stay quiet, and the probes above establish the domain is not empty. -test fn an_empty_refused_roster_collides_with_nothing() -> Bool { - length(xs: share_roster_refusal_collisions( - admitted: ["v2.probe.languages.rust.probe_target_model"], - refused: [] - )) == 0 -} - -// THE LIVE POSITIVE CONTROL. Today's admitted rosters and today's refused roster are disjoint, -// and this is the probe that reds if anyone re-enrols `rust_target_model`, -// `rust_target_model_core_edges`, `rust_target_model_staging`, or the argument-taking -// `compile_phase_frontier_standing` without first retiring its refused row. -test fn the_live_rosters_admit_nothing_this_roster_has_refused() -> Bool { - length(xs: share_roster_refusal_collisions( - admitted: floor_cross_claim_admitted_producers(), - refused: floor_cross_claim_refused_candidates - )) == 0 + (length(xs: live_refused) > 0) && (length(xs: d.admitted) == 0) } // THE REFUSED ROSTER IS NOT EMPTY, asserted separately and deliberately. The live control above @@ -145,76 +209,3 @@ test fn a_superseded_row_does_not_transfer_to_other_producers() -> Bool { verdict: SupersededBySingleAuthorityRepair { repaired_by: "an authored fixture" } ) == false } - -// ── THE PENDING WALL ────────────────────────────────────────────────────────────────────── -// -// A pending row is a proposal, so it is refused by the same two populations a re-proposal in an -// admitted roster is: already enrolled, or already measured and turned down. The probes below are -// the fixture arm -- the forbidden state is perfectly writable as source handed to the harness, -// which is what makes the live control worth reading. - -fn probe_pending_row(producer: String) -> PendingShareCandidate { - PendingShareCandidate { - producer: producer, - proposed_because: "authored fixture; no instrument", - deciding_measurement: "authored fixture; no run", - refuses_if: "authored fixture; no verdict" - } -} - -// RED: proposing something already ENROLLED. This is the direction that matters most, because the -// enrolment is the arm that executes while the pending row says the question is still open. -test fn a_pending_row_for_an_already_admitted_identity_collides_and_is_named() -> Bool { - let collisions = share_roster_pending_collisions( - pending: [ - probe_pending_row(producer: "v2.probe.languages.bash.probe_fold_lex"), - probe_pending_row(producer: "v2.probe.index.probe_decl_facts") - ], - admitted: ["v2.probe.languages.bash.probe_fold_lex"], - refused: [] - ) - (length(xs: collisions) == 1) - && any(xs: collisions, predicate: fn(c) { c == "v2.probe.languages.bash.probe_fold_lex" }) -} - -// RED: proposing something already MEASURED AND REFUSED. Without this arm the refused roster is -// bypassable by proposing a row instead of enrolling it, and the measurement that turned it down -// would be re-run rather than read. -test fn a_pending_row_for_a_refused_identity_collides_and_is_named() -> Bool { - let collisions = share_roster_pending_collisions( - pending: [probe_pending_row(producer: "v2.probe.languages.rust.probe_core_edges")], - admitted: ["v2.probe.languages.bash.probe_fold_lex"], - refused: probe_refused - ) - (length(xs: collisions) == 1) - && any(xs: collisions, predicate: fn(c) { c == "v2.probe.languages.rust.probe_core_edges" }) -} - -// GREEN CONTROL beside those two REDs: a pending row naming an identity neither roster has -// decided reports nothing. Without this a fold returning its whole input would pass both probes. -test fn a_pending_row_for_an_undecided_identity_reports_no_collision() -> Bool { - length(xs: share_roster_pending_collisions( - pending: [probe_pending_row(producer: "v2.probe.index.probe_decl_facts")], - admitted: ["v2.probe.languages.bash.probe_fold_lex"], - refused: probe_refused - )) == 0 -} - -// THE LIVE POSITIVE CONTROL. Today's pending candidates are decided by neither roster, and this -// reds if anyone enrols or refuses one of them without retiring its pending row in the same -// motion -- which is the only way a pending row is supposed to leave. -test fn the_live_pending_candidates_are_decided_by_neither_roster() -> Bool { - length(xs: share_roster_pending_collisions( - pending: floor_cross_claim_pending_candidates, - admitted: floor_cross_claim_admitted_producers(), - refused: floor_cross_claim_refused_candidates - )) == 0 -} - -// THE PENDING ROSTER IS NOT EMPTY, asserted separately for the reason its sibling above states: -// the live control is satisfied by an empty pending list, so on its own it cannot tell "nothing is -// double-decided" from "nothing is proposed". Non-emptiness rather than a count, so measuring and -// retiring a candidate does not red a tree-copied oracle. -test fn the_pending_roster_carries_identities() -> Bool { - length(xs: pending_share_producers(pending: floor_cross_claim_pending_candidates)) > 0 -} diff --git a/src/v2/test/claim/native_route/native_refusal_detail_test.dag b/src/v2/test/claim/native_route/native_refusal_detail_test.dag index 5af60a07edf..8ce4b2bf605 100644 --- a/src/v2/test/claim/native_route/native_refusal_detail_test.dag +++ b/src/v2/test/claim/native_route/native_refusal_detail_test.dag @@ -134,7 +134,7 @@ fn ndp_universe_module(module: String, path: Symbol, declaration: String) -> Nat // ONE NULLARY PRODUCER, FORCED ONCE, for the reason v2.test.claim.native_census.whole_tree_census_resolve // gives on its own producer: the floor builds a fresh evaluation frame per claim, and every claim // here inspects one row of a value that costs one whole-ingest front end plus four resolves to -// build. Enrolled WARM in v2.workflow.floor_pure_producer_share floor_cross_claim_pure_producers_warm; +// build. Shared by v2.workflow.floor_pure_producer_share derive_cross_claim_share; // the stored value is four NativeLaneModuleResolution arms carrying rows, diagnostics, symbols // and nodes -- no closures, no resolution context -- so it is portable across claim frames. type NdpResolutions diff --git a/src/v2/test/claim/text_string_importer_census_test.dag b/src/v2/test/claim/text_string_importer_census_test.dag index c2d02d1fd27..8cfa469e72f 100644 --- a/src/v2/test/claim/text_string_importer_census_test.dag +++ b/src/v2/test/claim/text_string_importer_census_test.dag @@ -41,8 +41,8 @@ data live_tree_disposition: LiveTreeDisposition = ReadsLiveTree // whole row's floor budget, and re-ran production these rows are not about. THE PAIRING // OBLIGATION is kept by tsic_real_raw_parse_route_reaches_the_classifier at the bottom: the real // raw parse of one small real importer, through tree_atoms, into the classifier. The parse is -// paid once by a warm pure producer (v2.workflow.floor_pure_producer_share -// floor_cross_claim_pure_producers_warm): grammar validation alone measured about 1M eval steps, +// paid once by a nullary pure producer the derived cross-claim share admits +// (v2.workflow.floor_pure_producer_share derive_cross_claim_share): grammar validation alone measured about 1M eval steps, // a fixed product independent of the module read. // // Each row asserts the EXACT arm its input exists for, never "not" another arm. diff --git a/src/v2/test/floor_prepared_effect_input_ladder_test.dag b/src/v2/test/floor_prepared_effect_input_ladder_test.dag index 6206ba0f7ee..4879909f082 100644 --- a/src/v2/test/floor_prepared_effect_input_ladder_test.dag +++ b/src/v2/test/floor_prepared_effect_input_ladder_test.dag @@ -8,8 +8,7 @@ import v2.workflow.floor_prepared_effect_input_ladder { the_minimized_demand_graph_is_green, prepared_effect_input_provider } import v2.workflow.floor_pure_producer_share { - carried_input_roster_collisions, carried_input_rows_without_a_prepared_input, - floor_cross_claim_admitted_producers, floor_cross_claim_carried_input_warm_rows, + carried_input_rows_without_a_prepared_input, floor_cross_claim_carried_input_warm_rows, floor_cross_claim_prepared_effect_inputs } import std.cache_interface { retention_growth_is_bounded, retention_has_exact_byte_bound } @@ -60,11 +59,12 @@ test fn the_covered_population_is_not_empty() -> Bool { && length(xs: carried_input_verdicts_after_the_carry()) > 0 } -// THE TWO ROSTER WALLS, over the live rows: every carried-input row names an input that is -// actually prepared, and no producer stands in both a plain roster and a carried-input row — -// the second is the one that matters, because a plain warm row stores under the EMPTY argument -// row while a carried-input row stores under the carried content, so a producer in both would be -// servable under a key that does not represent the carrier. +// THE ROSTER WALL, over the live rows: every carried-input row names an input that is actually +// prepared. The second wall that stood here -- no producer both carried and plainly rostered -- +// is construction now: the plain roster is deleted, and the derived share declines every closed +// demand for a carried producer (`CarriedInputProducer`, red in +// `v2.test.floor.pure_producer_share_refusal` +// `a_carried_input_producer_is_declined_as_a_plain_share`). test fn every_carried_row_names_a_prepared_input() -> Bool { length(xs: carried_input_rows_without_a_prepared_input( rows: floor_cross_claim_carried_input_warm_rows, @@ -72,9 +72,3 @@ test fn every_carried_row_names_a_prepared_input() -> Bool { )) == 0 } -test fn no_producer_is_both_carried_and_plainly_rostered() -> Bool { - length(xs: carried_input_roster_collisions( - rows: floor_cross_claim_carried_input_warm_rows, - admitted: floor_cross_claim_admitted_producers() - )) == 0 -} diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index d3b25cc4806..d13a071d04f 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -1,1505 +1,246 @@ module v2.workflow.floor_pure_producer_share import v2.std.collection { List } +import std.computation_identity { ComputationIdentity, identity_permits_share } +import v2.std.algebra { list_flat_map, list_map } -// THE CROSS-CLAIM PURE-PRODUCER SHARE ROSTER — which pure functions the required floor may -// serve from one evaluation across claims. +// THE CROSS-CLAIM PURE-PRODUCER SHARE -- which pure computations the required floor may fill +// once and serve to every planned claim that demands them. // -// THE DEFECT THIS CLOSES. The floor builds a fresh evaluation frame per claim (deliberately — +// THE DEFECT THIS CLOSES. The floor builds a fresh evaluation frame per claim (deliberately -- // one witness must not contaminate the next), so the eval-frame memo dies at every claim -// boundary and every claim that reaches the emit path rebuilds the same target models from -// scratch. Measured on the post-#9680 tree (claim_batch, arm64 session host, 2026-08-29): -// `rust_target_model_staging()` alone is ~125ms of pure re-derivation per claim, a one-word -// bash serialization carries ~110ms of word-independent fixed cost per claim, and main's floor -// receipts carry a ~280-340ms fixed base on every `v2.test.emit.*` row (run 33263972922, -// `required_floor_claim_cost.tsv`) against the operator's 500ms per-claim CPU ceiling — a -// runner-variance-sized margin, which is how main run 33258845841 refused. The producers below -// are pure functions of program content, so re-deriving them per claim is DESIGN §2 redundant -// work, and the repair is "stop recomputing", never "raise the line". -// -// WHAT ENROLLMENT ASSERTS. A rostered producer's value depends only on the prepared subject's -// content: it is a pure function (no effect uses — the seed's admission path only reaches -// pure calls), its arguments are content-hashable, and its value passes TOTAL reification — -// a positive portable shape (scalars, strings, lists, maps, sets, records and variants of -// those, carrying process-canonical symbols across frames), with the first origin-bound child -// (a fn, a closure, any evaluator-node reference) refusing the whole store as a typed, located -// ServeCacheValueNotPortable at publication time, never discovered at retrieval. The seed -// realization (`v1_interpreter` cross-claim tier) keys every entry on fn-node identity plus -// a content hash of the full argument row, serves only after the stored argument row -// verifies structurally equal in portable form (a hash collision degrades to recompute, -// never to a wrong value), refuses to store any call that dispatched an effect, and bounds -// retention twice with counted refusals: an entry-count cap on the key population and a -// byte budget on the reified portable representation (arguments and values, measured at -// publication — reification is total, so the size is always computable before a store -// lands). An over-budget producer recomputes per claim exactly as if never enrolled. -// -// TWO LISTS BECAUSE TWO FILL DISPOSITIONS (the well-posed split the floor-cost-debt carrier -// names): a WARM row is nullary and preparation-forceable — the floor evaluates it once during -// strict preparation and the fill lands outside the fold, billed to preparation like the edge -// index warms; a CLAIM-FORCED row has claim-shaped arguments, so its fills happen inside the -// fold on first touch, and the seed nets the fill from the paying claim's charged clocks and -// reports it through the `[floor-shared-fill]` ledger under cache=cross_claim_pure_share. -// A warm row that fails to evaluate or refuses to store STOPS THE LINE — a roster row whose -// warm silently failed would relocate its fill onto the first toucher, which is exactly the -// nondeterministic charge this roster exists to delete. -// -// ADMISSION IS BY RESOLVED DECLARATION IDENTITY. Preparation resolves each qualified -// spelling below to its declaration's fn node and the seed admits by that node set — a -// bare-name homonym in a non-rostered module is a different declaration and is never -// eligible, and a row whose module or declaration the subject cannot resolve stops the -// line as a stale row. Stored values are additionally keyed on fn-node identity, so even -// the built-in prepare_grammar arm never cross-serves between distinct declarations. -// -// HOW A ROW EARNS ITS PLACE: a measured per-claim recompute of a pure producer — cite the -// instrument (claim_batch + GUNBC_INTERP_PROFILE staging, or a floor cost receipt), not a -// transcribed number. HOW A ROW LEAVES: delete its line; the floor then recomputes it per -// claim and the cost receipt says what that costs. Dissolve-on: -// gunbc.roadmap_authority five_minute_ci_gate_program_note's generic cross-claim pure memo — -// when admission no longer needs a declared roster because every pure content-hashable call -// is safely servable within a byte-bounded store, this roster and its seed consumer delete -// together. +// boundary and every claim that reaches the same pure computation re-derives it. DESIGN section +// 2 calls that one reuse obligation at the least common visible ancestor of the consuming claims: +// required-floor preparation, across an isolation boundary, which only a store tier can discharge. +// +// ADMISSION IS DERIVED, NOT AUTHORED. Until this revision admission was a hand-authored roster of +// several hundred qualified spellings, appended one row per measured incident. That roster was a +// second authority over a fact the demand graph already carries (section 3): a witness module +// whose claims re-ran a module-constant producer had to hand-restructure itself, or hand-append a +// row, before it fit its enrolment margin. The roster is deleted. Admission is now the fold +// below, over one observation row per COMPUTATION IDENTITY reached by the run's PLANNED claims: +// a pure call reached by more than one planned claim with one closed identity is admitted, and +// nothing else is. Because the observation is over the planned claims' reach, the admitted set +// is also exactly what this run can demand -- a producer no planned claim reaches is never filled. +// +// THE KEY IS THE FULL COMPUTATION IDENTITY (std.computation_identity, DESIGN section 3b keys +// row): the callee's resolved declaration plus the canonical preimage of its CLOSED argument row. +// A call whose argument row is not a closed constant has no identity the floor can know before +// the claims run, so it is not a fill candidate; it is COUNTED under a typed cause +// (`CallSiteDemandCause`) and never widened to its declaration. The grade is +// `NormalizedIdentical` with the normalizer named on the row: two sites with equal normalized +// argument expressions denote one value because the callee is pure and the arguments are closed; +// two sites with different expressions that happen to evaluate equal are a missed share, never a +// wrong one. +// +// WHERE THE OBSERVATION COMES FROM, AND WHY IT IS A REALIZATION OF THIS INTERFACE. The rows are +// produced by the seed (`v1_compiler.cli_run.claim_call_site_demand`), which walks each planned +// claim's reach over the prepared subject and reads each reached call site. That is a realization +// of the row type declared here, retained only because no `.dag` carrier yet hands the floor +// per-claim call-site demand identity: when demand-engine M1.b's demand-identity carrier lands +// it produces these same rows and the seed observer is deleted +// (`gunbc.floor_call_site_demand_seed_growth`). The seed counts distinct claims per identity -- +// it carries a fact across the claim-frame boundary only it can see -- and decides nothing: the +// threshold, the identity grade, and every exclusion are this fold's. +// +// WHAT AN ADMITTED ROW DOES AT RUN TIME. The seed admits the row's call sites. The first planned +// claim that actually evaluates one of them fills the tier and the fill is netted from that +// claim's charged clocks and eval steps (`[floor-shared-fill]` cache=cross_claim_pure_share), so +// no claim's budget carries a computation it shares; every later claim is served the retained +// value. A statically reached site no claim evaluates fills nothing. The serve itself is keyed on +// the evaluated argument VALUES, verified against the stored canonical preimage before any serve, +// so the static identity decides only eligibility -- a wrong static judgment can cost a missed +// share or a wasted store, never a wrong value. A store the tier declines (origin-bound value, +// entry cap, byte budget, a dispatched effect) recomputes per claim exactly as if never admitted, +// and is counted. +// +// THE EXCLUSIONS THAT STAY, because derivation cannot see them: a producer this file measured and +// refused (`floor_cross_claim_refused_candidates` -- including the one arm that is a correctness +// refusal rather than a cost one, `KeyOmitsAnInputTheValueDependsOn`), and a producer whose value +// is carried from a committed checkout input (`floor_cross_claim_carried_input_warm_rows`, keyed +// on the carried content and admitted by its own row kind). Both are identity gates under +// `std.materialization_ladder`; neither is an admission roster. -// The warm rows are the constant halves of the bash fold's per-claim fixed cost, measured -// through claim_batch + GUNBC_INTERP_PROFILE (2026-08-29, this lane); on the first enrolled -// floor run each was read by 35-44 later claims (run 33269961629, [floor-shared-fill]). -// -// THE TWO RUST TARGET MODELS ARE NOT HERE, AND THE REASON IS NOW A MEASUREMENT RATHER THAN -// A REFUSAL. Their earlier absence was a portability refusal: the value carried a fn at -// `.produced_decl_support.render`, so publication refused it (ServeCacheValueNotPortable, -// kind=OriginBoundNode). That is FIXED — v2.std.compilers.target_model ProducedDeclRenderRows -// carries the render transform as declared rows, the value reifies totally, and an enrolled -// run stores it clean (disposition=Stored, notportable=0, byte-budget refusals=0). The -// portability trigger fired and is retired. -// -// They are out for a DIFFERENT reason, and it is now MEASURED rather than inferred: SERVING -// THESE VALUES COSTS MORE THAN RECOMPUTING THEM. At the time of that measurement a serve -// re-interned every symbol and re-sorted every record's fields, and a TargetModel is a large -// value (bundle node, lex rules, spelling map, realization catalogs). Frame-independent symbol -// identity now removes the re-interning half; re-enrollment still requires a new measured -// present-vs-absent floor receipt rather than inference from that implementation change. -// -// The discriminating experiment, run because the enrolled floor made the emit rows that touch -// a rust target model SLOWER while the rest of the corpus got faster: hold the renderer fixed -// and remove only these two rows. Renderer=rows/share=on, renderer=rows/share=off and main's -// renderer=fn/share=off are three points over the same five identities in -// required_floor_claim_cost.tsv, and they separate the two candidate causes cleanly. Every one -// of the five got FASTER with the rows removed than it had ever been — below the enrolled run -// and below main — which prices the serve above the recompute and simultaneously clears the -// renderer, since the rows renderer beats the fn it replaced on the same share-off footing. -// Re-derive with the instruments named below rather than trusting these sentences. -// -// THE ADMISSION CRITERION THIS DISCOVERED, now binding on every future row: measured -// per-claim recompute is necessary but NOT sufficient. A row is admitted only when its SERVE -// cost — reification in the consuming frame, not just the avoided recompute — is below its -// recompute cost. Cite the instruments, never a transcribed number: claim_batch under -// GUNBC_RECOMPUTE_TRACE=1 for the recompute side, and the required floor's -// required_floor_claim_cost.tsv joined against a run with the row absent for the serve side. -// A producer that is expensive to BUILD and expensive to REIFY is not a sharing candidate; -// the tier's win comes from values whose reification is cheap relative to their derivation. -// -// RE-ENROL TRIGGER for these two, naming the capability and not an artifact: a serve that -// does not re-intern and re-sort per consuming frame — an interner-stable representation the -// tier can hand over without walking the whole value. -// -// THAT TRIGGER HAS FIRED, AND THIS PARAGRAPH IS THE CAPABILITY IT NAMED. The tier now retains -// the REIFIED VALUE rather than the portable form: publication still walks the value once — -// that walk IS the total portability check and the byte-budget measurement, and neither is -// weakened — but the conversion back happens ONCE, at publication, and every later claim is -// handed an `Rc` clone. Nothing per-frame remains to do, because nothing in a published value -// is frame-bound: the portable shape admits no closure and no evaluator-node reference, its -// symbols are process-canonical `&'static` spelling identities, and record field order sorts -// on that process-global identity — so a value built in one frame is byte-for-byte the value -// the walk used to rebuild in the next. A serve went from O(size) to O(1). -// -// THE EXECUTED EVIDENCE IS AN ALLOCATION-IDENTITY RED, not an equality one, and that -// distinction is the whole of why it discriminates: the served value was ALREADY equal under -// the walk, so a structural assertion is green on both sides and proves nothing. -// `v1_compiler.v1_interpreter` -// `two_frames_are_served_the_same_allocation_rather_than_two_reconstructions` asserts -// `Rc::ptr_eq` across two consuming frames, which is false for a reconstruction and true only -// for a hand-over. The per-context hit cache that existed solely to amortize the walk within -// one frame is DELETED with it (DESIGN §4b(4) dissolution on climb). -// -// CORRECTNESS ROOT, separated from that cost trigger: Symbol identity in the seed used to be -// a per-frame encounter ordinal, so a value crossing this boundary could compare the SAME -// spelling unequal, or DIFFERENT spellings equal, against a consumer-frame value. Symbols are -// now process-canonical spelling identities; crossing frames no longer changes equality. That -// is the property the hand-over rests on, and it was established before this change rather -// than by it. -// -// EVERY RUST TARGET MODEL STAYS OUT, AND THE REASON IS NOW A MEASUREMENT AGAINST THE CURRENT -// SERVE RATHER THAN AGAINST THE OLD ONE. The zero-walk serve made re-enrolment TESTABLE; it did -// not decide it, and that difference is the whole of why this note exists. Admission here is a -// measured present-vs-absent floor receipt and never an inference from "the serve is cheaper -// now" -- that inference is the specification-without-execution DESIGN section 5 names, and it -// would have been wrong three times over, because all three candidates were enrolled on exactly -// that expectation and all three were withdrawn on measurement. -// -// WHAT WAS TRIED, ACROSS FOUR RUNS, NORMALISED AGAINST THE ROWS IN NO CONSUMER MODULE OF ANY -// ENROLLED KEY -- the population the change cannot reach, which is the only sound control when -// the runner moves 17% between runs of one tree: -// -// - `rust_target_model` regressed the `v2.test.emit.produced_decl_two_target` / -// `v2.test.emit.rust_produced_decl_emit` cluster by about 20% normalised, on both present -// runs, and refused a floor run at cost=502ms EXACT. -// THE BASE IT REGRESSED FROM IS A CROSS-TREE ONE AND NOT A SINGLE OBSERVATION, which is -// what licenses reading the regression as large rather than as one run's noise: the same -// identities were independently joined on two further MAIN runs by the FLOOR-COST-500MS lane -// (33664853305 head 22e3d70963 and 33664768371 head dbd57f2af3, both attempt 1, both green) -// and every member moved together between them by 1.09-1.13 while the within-module spread -// stayed near 1.17. Four main-ish trees put the cluster's level inside one narrow band, and -// the present arms sit half again above it. -// - `rust_target_model_core_edges` showed NO effect at all over four consumer modules. A row -// that neither costs nor saves is cache population, which this file already refuses. -// - `rust_target_model_staging` LOOKED like the survivor -- its 17 consumer modules improved -// about an eighth -- and it is out for the same reason as the first, discovered only after -// the first was withdrawn: with `rust_target_model` gone, staging inherited that row's -// consumer set (58 claims across 17 modules became 133 across 44, the produced-decl cluster -// among them) and the cluster's regression came with it, smaller but in the same direction. -// Its consumer set as a whole still improves. THAT IS THE TRADE THIS ROSTER MUST NOT MAKE: -// the ceiling is PER CLAIM, so a family total that improves while the rows nearest the line -// get worse is a loss on the subject, and those six rows sit within one runner-swing of 500. -// -// SO THE COMMON FINDING, WHICH IS THE USEFUL PART OF A NEGATIVE RESULT: serving a rust -// `TargetModel` across claim frames costs its produced-decl consumers MORE than recomputing it, -// and the per-frame WALK WAS NOT THE CAUSE -- #9721's conclusion survives its own re-enrol -// trigger being discharged. THE REMAINING COST IS UNIDENTIFIED, and this file leaves it that way -// rather than carrying a plausible story: an unsupported cause in a carrier is read as a lead by -// the next reader and spends their time before it spends anyone's doubt. -// -// ONE CANDIDATE WAS RAISED HERE AND IS WITHDRAWN, recorded because the next reader will think of -// it too. The suggestion was copy-on-write: a serve hands over an `Rc` every consumer shares, so -// a path that would have mutated a freshly recomputed value in place (`Rc::make_mut` at a strong -// count of one) would copy instead. IT REQUIRES AN IN-PLACE MUTATION PATH OVER `Value` AND THERE -// IS NONE. The seed's only `Rc::make_mut` in `v1_compiler.v1_interpreter` is inside a test -// fixture builder over `Node`, not over a `Value` on any evaluation path; the `v1_compiler.v1_rt` -// occurrences are the EMITTED runtime that compiled `.dag` code calls, which no interpreter serve -// reaches. Value operations in the interpreter rebuild rather than mutate, so sharing defeats -// nothing there. The candidate predicted that only MUTATING consumers would regress, which is -// what made it worth stating and is also what refuted it. -// -// NEXT TRIGGER FOR ALL THREE, naming what must be true rather than what must be built: the -// remaining cost identified, and a measured serve-below-recompute ON THE PRODUCED-DECL -// CONSUMERS SPECIFICALLY -- not on their family total, which has already been observed pointing -// the wrong way. -// -// THE TWO RUNS ARE gunbc#10094 33657893880 (ABSENT: the zero-walk serve, no rust row enrolled) -// AND 33661252708 (PRESENT: the same tree plus those rows), and the comparison is -// `required_floor_claim_cost.tsv` from each, joined at IDENTITY grain. Re-derive it rather than -// trusting a sentence: the absent run REFUSED, `verdict=FloorRefused` with `failed=0`, carried -// entirely by one COMPLETED-OVER-COST-REQUIREMENT row in `v2.test.emit.rust_produced_decl_emit`. -// -// FIVE RUNS IN ALL, AND THE LAST TWO ARE THE WITHDRAWAL'S OWN RECEIPT rather than a repetition -// of the first. 33664119594 carries the same roster as the present arm and agrees with it on -// every judgment above, which is what distinguishes a repeated effect from a single-run artifact -// of the runner. 33667640710 carries `rust_target_model_staging` alone -- the state in which -// that row inherited the wider consumer set -- and 33671317370 carries none of the three, where -// the produced-decl cluster returns to its absent-arm value on the same normalised basis and the -// floor is `verdict=FloorClean`. A withdrawal whose receipt is only "the rows are gone" asserts -// that removing them helped; this pair measures it. -// -// AND THE ABSOLUTE DELTA IS NOT THE EVIDENCE, because the two runs did not get the same runner: -// every row in the corpus got cheaper between them. The admissible reading is the NORMALISED -// one -- each row set against the rows in NO consumer module of these keys, in the same run -// pair -- and the consumer sets are read from the present run's own `[floor-shared-fill]` -// `modules=` field, which names them rather than counting them. A raw comparison would have -// credited the runner with most of the movement in both directions. -// -// MEASURED SHARING WAS NEVER THE QUESTION FOR THE THREE WITHDRAWN ROWS, and saying so guards -// against the next reader re-proposing them on that evidence: the ledger reports -// `rust_target_model` served to 75 consumer claims across 29 modules and -// `rust_target_model_staging` to 133 across 44 once it inherited them -- the widest sharing on -// the roster, and withdrawn anyway. A row earns its place by measured recompute AND measured -// sharing AND a serve below that recompute, and it is the third conjunct that refused all -// three. -// dag_prepared_grammar EARNS ITS ROW ON THE FILL THAT COULD NEVER LAND. `prepare_grammar` is the -// tier's built-in admitted arm, so admission was never its question; the v2-self-host branch's -// required-witnesses-floor lane measured the failure shape directly — twelve claims refused with -// cause=FillBudgetExceeded, every one dying mid-flight inside the SAME in-flight shared fill, and -// the run's cross-claim demand census names `prepare_grammar` at evals=12 with no store ever -// landing. Two independent defects composed into that cascade, and both are repaired at source, -// not budgeted around: (1) the fill's VALUE was not portable — `GrammarFirstAnalysis.nullable_set` -// was a `PointwisePower` closure tower, which publication refuses totally -// (ServeCacheValueNotPortable), so no completed fill could ever store; the carrier is now the -// enumeration it always was (`List`, the `sync_tokens` repair's own precedent); (2) the -// fill costs more than one claim's CPU budget on the lane's runner, so an in-fold first touch can -// never complete — the nullary producer moves that first touch to strict preparation, where this -// roster's warm path already forces the bash rows, and every claim then serves the landed fill. -// The instruments, re-derived rather than transcribed: the required floor's own -// required_floor_claim_cost.tsv outcome column (the twelve refusals) and its cross-claim demand -// census (the demand concentration), plus this run's `[floor-shared-fill]` ledger, which must now -// show the fill landing at preparation with disposition=Stored and the twelve former fillers -// serving hits. -// THE THREE INGESTED-FIXTURE PIPELINE ROWS BELOW EARN THEIR PLACE ON THE v2-self-host BRANCH'S -// OWN FLOOR RECEIPT, not on inference. That run refused five changed witnesses over the per-claim -// ceiling at one head: v2.test.long.emit_host_classical_not_ingested_equals_eval's -// canonical/staging/staging-swapped emit claims (FAIL rows naming marginal_cpu_ns 488209894 and -// 473955219 against limit_ms=500 — each dying when a 13-29ms in-flight fill of the rostered -// target_project_arrow_body_to_value_expression crossed the line — plus the canonical claim -// INTERRUPTED-BEFORE-VERDICT at cpu_at_least=501ms) and -// v2.test.long.emit_host_native_only_verdict's two produced_module claims (505ms -// COMPLETED-OVER-COST-REQUIREMENT, 542ms INTERRUPTED). The recompute instrument is claim_batch's -// gross [witness] receipt over the two entry files: every emit claim in the classical_not family -// re-runs tokenize→parse→normalize→resolve→find-arrow over one of two module-constant sources -// (~370-420ms of each ~475-510ms claim, with every pipeline claim in that file funneling through -// one of the two constants), and produced_add_module_source is ~382ms of each ~476-505ms -// produced_module claim. The sharing census is the call-site graph itself: the two classical_not -// arrows feed every tree producer in their file, and produced_add_module_source feeds the -// equals_eval pair and the native_only pair. Serve-below-recompute is the header's zero-walk -// capability rather than a new measurement: the values are a resolved-module Node tree and a -// Medium, both small and fully portable (no Closure/OriginBoundNode at any depth — the -// InferredTree one stage up carries the facts PartialFunction and is deliberately NOT the share -// point), so a serve is an Rc hand-over against a ~370-382ms recompute. Re-derive rather than -// trust: claim_batch --entry [witness] lines for the recompute side, and this -// run's [floor-shared-fill] ledger, which must show the three fills landing at preparation with -// disposition=Stored and the five former over-budget claims serving hits. -// -// WARM, NEVER CLAIM-FORCED, BY THE CEILING ARITHMETIC. A claim-forced fill happens inside the -// first touching claim's fold; a ~370-382ms fill leaves under 130ms of headroom on this lane's -// own measurement, and the lane's runner crossed the ceiling on the meet/join arms at 545/550ms -// for work this host performs in ~400ms (run 34290525720's COMPLETED-OVER-COST rows) — so an -// in-fold fill of this size dies mid-flight on the lane exactly as prepare_grammar's did (the -// dag_prepared_grammar row above). All three producers are nullary, so preparation forces them -// outside every per-claim budget, and every claiming claim serves the landed fill. -// -// THE DIRECT-RUST-DOOR SPECIMEN'S RESOLVED TREE EARNS ITS ROW ON THE NEXT TIER THE -// prepare_grammar WARM STORE UNMASKED. Required-floor run 34311472357 (PR #10692 head -// abf0908222) refused seven changed witnesses as INTERRUPTED-BEFORE-VERDICT at -// cpu_at_least=501-510ms against limit_ms=500 — the four specimen claims of -// v2.test.execution.infer_atom_grounding_rules, the two of -// v2.test.execution.infer_product_introduction, and the one of -// v2.test.execution.dag_binding_denotation. The prior run 34290525720 names the same seven in -// its prepare_grammar FAIL rows at marginal_cpu_ns ~10-12M: they were inside the shared-fill -// cluster then, and the grammar warm store let them run to their own cost, which is over the -// line on the lane's runner. The recompute instrument is claim_batch's gross [witness] receipt -// over the three entry files (~304-333ms per claim locally, ~390k eval_steps each) plus the -// assemble-only/assemble-then-infer probe pair that splits the pipeline: the -// ingest→assemble walk over the fixture's add_probe module is ~245ms of each claim and infer -// is ~72ms, with the census folds inside the remainder. The sharing census is the call-site -// graph itself: seven claims across three modules funnel through one specimen pipeline, whose -// three per-file specimen_inferred spellings are dissolved into the fixture's home with this -// row (DESIGN §2/§3 — one pipeline, one authority). Serve-below-recompute is the header's -// zero-walk capability rather than a new measurement: the value is the resolved-module -// Outcome tree — small, fully portable (no Closure/OriginBoundNode at any depth; the -// InferredTree one stage up carries the facts PartialFunction and is deliberately NOT the share -// point, so infer re-derives per claim from the served tree) — so a serve is an Rc hand-over -// against a ~245ms recompute. WARM, NEVER CLAIM-FORCED, by the same ceiling arithmetic as the -// rows above: a ~245ms fill on this host is a ~410-440ms fill on the lane's runner (the -// 501-510ms interrupts for ~304-333ms of local work), leaving under ~90ms of in-fold headroom, -// and seven demanding claims means a mid-fill death is abandoned un-stored and restarted per -// claim — the prepare_grammar failure shape exactly. Re-derive rather than trust: claim_batch -// --entry [witness] lines for the recompute side, and this run's -// [floor-shared-fill] ledger, which must show the fill landing at preparation with -// disposition=Stored and the seven former interrupted claims serving hits. -// THE TWO FAMILY-CRATE EMITTED PAIRS EARN THEIR ROWS ON THE RUN THE DOOR-SPECIMEN STORE -// UNMASKED. Required-floor run 34315228217 (PR #10692 head da5c00c301) refused -// v2.test.long.emit_host_native_only_verdict's emit_host_native_only_loop_holds as -// COMPLETED-OVER-COST-REQUIREMENT at cost=504ms CEILING against limit_ms=500 — and the run's own -// cost receipt names the whole exposed population: all twelve native-only family arms (the six -// match/loop/fold claims at 462-503ms cpu, the six complement/meet/join claims at 458-487ms) -// sitting within one runner-swing of the line, while the file's next-nearest claim stands at -// 388ms. The recompute instrument is claim_batch's gross [witness] receipt over the entry file -// plus one probe per producer: each claim re-ran its family's full pure pipeline inline — -// primary trees, member assembly, emit_family, the native key — measured at 186ms -// (mlf_family_primary_emitted) and 142ms (logic_family_primary_emitted) of each ~174-247ms local -// claim on this host, against the lane's 458-503ms for the same work. The sharing census is the -// call-site graph itself: six claims per family funnel through one member-independent pipeline, -// and the two per-arm helper spellings in the verdict module are dissolved into the families' -// own homes with these rows (DESIGN §2/§3 — one pipeline per family, one authority). The share -// point is the deepest PORTABLE stage: the member list carries InferredTrees (the facts -// PartialFunction is origin-bound), so the served value is the emitted crate source plus its -// native key — EmittedFamilyCrate { source: Medium, native_key: ContentHash }, declared -// once in v2.compiler.emit_module rather than once per family — small, fully portable (no -// Closure/OriginBoundNode at any depth), so a serve is an Rc hand-over against a ~142-186ms -// recompute. WARM, NEVER CLAIM-FORCED, by the same ceiling arithmetic as the rows above: a -// 142-186ms fill on this host is a ~370-485ms fill at the lane's observed ratio (458-503ms of -// lane cpu for 174-247ms of local work), and the claim still owes its cached native run after -// the fill — an in-fold fill of this size dies mid-flight on the lane exactly as -// prepare_grammar's did. Re-derive rather than trust: claim_batch --entry -// src/v2/test/claim/execution/long/emit_host_native_only_verdict_test.dag [witness] lines for -// the claim side, one-claim probe entries over the two producers for the pipeline side, and -// this run's [floor-shared-fill] ledger, which must show both fills landing at preparation with -// disposition=Stored and the twelve former ceiling-band claims serving hits. -// THE TWO STAGE0-BOUNDARY EMISSIONS ARE THE SAME SHAPE AS produced_add_module_source ABOVE: a -// nullary producer of a small, closure-free emitted source. v2.test.self_host.stage0_production_target -// asserts that the stage0 target profile emits a boundary-compatible declaration and that the base -// target does not, which is three claims reading two emissions (the base emission is read by both -// per-class controls). An emission is infer plus emit over the door's already-shared resolved -// specimen, and -// claim_batch's [witness] receipt measures each claim at 713-834ms locally against the 500ms -// per-claim ceiling -- structurally over on any runner, and over for the same reason the rows above -// were: three claims recomputing a pure function of one program's content. Shared, each claim is a -// string comparison and the two emissions are evaluated once at preparation. WARM, NEVER -// CLAIM-FORCED, by the same arithmetic as every row above: a ~700ms fill cannot complete inside a -// 500ms claim, so a claim-forced fill dies mid-flight and restarts per claim. -// THE CONSUMING MODULE IS DELIBERATELY NOT IN THE LONG HOME, and that is the whole reason these -// rows are legible. This roster is installed and force-warmed by the REQUIRED FLOOR; the long-home -// prefixes above are an EXCLUSION from that floor, so enrolling a producer whose only callers -// declare v2.test.long. would buy a preparation-time fill that no planned claim reads -- a cache -// with an empty consumer set on the one route that warms it (DESIGN sections 2 and 3c). The -// claims were briefly homed there while their cost was being fixed, which took them off the merge -// path altogether and made a green floor mean nothing about them. They are back on it, and the -// fill is what keeps them under the ceiling there. -// THE SEVEN rust_module_emission_population ROWS EARN THEIR PLACE ON THE FILL-THAT-CANNOT-LAND -// GROUND, NOT ON CROSS-CLAIM SHARING, and the distinction is stated because three of them serve -// exactly one claim and would fail this roster's sharing conjunct if read against it. That is the -// dag_prepared_grammar ground above, restated for a second producer family: the fill costs MORE -// THAN ONE CLAIM'S CPU BUDGET on this lane's runner, so an in-fold first touch can never -// complete, and no amount of sharing is the question. Receipt, re-derivable rather than -// transcribed: required-floor run 34392489718 (PR #10907 head 65f01e1151) refused SEVEN of that -// file's eight arms INTERRUPTED-BEFORE-VERDICT at cpu_at_least=501-507ms against limit_ms=500 -- -// the eighth, the declarationless refusal, is the one specimen whose walk stops at the collector's -// empty population and it completed at ~341ms. Each producer is ONE ingest -> assemble -> infer -> -// collect -> emit production walk over one specimen module, which is the subject of the witnesses -// rather than incidental setup, so the cost cannot be reduced by rewriting the claims: the walk IS -// what they assert over. The share point is a String or a Bool, fully portable, so a serve is a -// hand-over against a ~600-900ms recompute. -// WHAT IS NOT CLAIMED HERE: this enrollment is NOT verified by a local claim_batch run. The warm -// path forces these at STRICT PREPARATION, which is the required-floor recipe's own step, and a -// plain --entry run does not execute it -- measured, with the arms' costs unchanged at -// 341-1545ms under claim_batch after the producers were introduced. The instrument that decides -// it is the required floor's own [floor-shared-fill] ledger, which must show these fills landing -// at preparation with disposition=Stored and the seven former INTERRUPTED arms serving hits. -// THE native_decl_selection ROW IS THE SAME GROUND AGAIN, ON THE NATIVE-ROUTE DRIVER. The four -// witnesses of v2.test.native_decl_selection drive v2.compiler.compile's source-root Eval -// driver over one two-module synthetic ingest, and every one of them was refused -// INTERRUPTED-BEFORE-VERDICT at cpu_at_least=503-508ms against limit_ms=500 on three -// consecutive main heads (runs 34536354438, 34537144168, 34542819448) -- the file was enrolled -// with members whose cost exceeds the budget they were enrolled under, and no run had ever -// reached their verdict. The run's own cross-claim demand census -// (required_floor_cross_claim_demand.tsv, run 34542819448) names the producer: collision_prepared -// / native_test_context_from_ingest, 4 claims, the file's whole censored cost, of which -// `tokenize` alone was ~330ms per claim and `parse_module_prepared` ~160ms -- the seed -// tokenizing and parsing ~230 characters of source, four times. The uncensored stage split -// (claim_batch --entry src/v2/test/native_decl_selection_test.dag [witness] lines, plus one -// probe entry per stage, arm64 session host) measured ~1.1-1.4s per claim: tokenize ~490ms, -// parse ~375ms, normalize + context fold ~210ms, resolve + infer ~220ms, eval ~0. The share -// point is the RESOLVED tree -- the deepest closure-free stage, the same seam -// direct_rust_door_specimen_resolved above uses -- so each claim keeps infer + eval and hands -// over tokenize/parse/normalize/resolve. WARM, NEVER CLAIM-FORCED: a fill that costs more than -// one claim's whole budget on the lane dies mid-flight in the fold, exactly as prepare_grammar's -// did. The instrument that decides it is the required floor's [floor-shared-fill] ledger -// (disposition=Stored at preparation, four hits) joined against required_floor_claim_cost.tsv -// showing the four rows reaching verdict_reached=true with an observed cost. -// THE EIGHT PARSE-WITNESS FIXTURE TREES EARN THEIR ROWS ON MAIN'S OWN RED FLOOR (runs -// 34556215902 at c176027b and 34556223550 at 267d69b8, the two heads that landed -// v2.test.parse.d1_declaration_grammar_parse, v2.test.parse.where_refinement_clause_parse and -// v2.test.parse.expression_bodied_fn_decl_parse): ten identities across those three files plus -// v2.test.claim.body_lowering.declaration_structure_preserved refused INTERRUPTED-BEFORE-VERDICT -// at cpu_at_least=506-610ms against limit_ms=500, and no floor run has ever reached their -// verdict. The cost has TWO halves and this roster carries only the second. The first half was -// the parser re-deriving a once-per-grammar invariant on every parse call -- the run's census -// names parse_grammar_digest at claims=19 evals=19 (~128ms per claim) plus two grammar_to_node -// walks per claim -- and that is repaired at its home, v2.compiler.parse GrammarFirstAnalysis, -// not by a roster row: it is a fact about the warm-shared dag_prepared_grammar, so once it is -// carried on the preparation every consumer of that row inherits it. The second half is the -// same shape as the native_decl_selection and door-specimen rows above: one module-constant -// source tokenized and parsed by two, three or four claims of one file, once per claim frame. -// The recompute instrument is claim_batch's gross [witness] receipt over the three entry files -// with the parser repair already applied (~100-460ms per claim on an uncontended amd64 host, -// of which one tokenize+parse of a ~60-character source is ~130-170ms); the sharing census is -// the call-site graph itself, stated per producer beside its declaration; serve-below-recompute -// is the header's zero-walk capability, since each value is an Outcome parse tree, small -// and fully portable (no Closure/OriginBoundNode at any depth; normalize is deliberately NOT -// the share point, so every normalize claim still executes the stage it names). WARM by the -// same ceiling arithmetic as every row above. Sources read by exactly one claim are NOT -// enrolled -- a single-consumer warm row is the per-claim budget relocated, not a recurrence -// removed -- and the one three-source conjunction (where_refinement_clause_parses_and_is_carried) -// was split into three rows instead. Re-derive rather than trust: claim_batch --entry [witness] lines, and this run's [floor-shared-fill] ledger, which must -// show the eight fills landing at preparation with disposition=Stored and the former interrupted -// claims serving hits. -// THE TWO LIVE-DEPLOY RENDERS ARE NOT ROSTERED HERE, AND THE REASON IS A PROPERTY OF THE SUBJECT -// RATHER THAN OF THEIR COST. gunbc#11204 enrolled `test.claim.live_deploy.emit.witness_apply_script` -// and `.witness_retract_script` on a real cost receipt: that module holds eighteen claims that read -// one of two module-constant renders, and the floor billed the whole render to whichever reader the -// diff happened to plan (86,034 and 205,451 eval steps against a 72,300 ceiling, runs 34927164902 -// and 34931137687). The shape was right and the measurement stands. -// -// WHAT IT MISSED IS THAT A ROSTERED PRODUCER MUST RESOLVE IN *EVERY* REQUIRED-FLOOR SUBJECT, and -// that subject is the required-gate closure plus the changed set plus the declared seeds. Every -// other row here names a module under `src/v2/**`, which the gate closure carries in every run. -// `test.claim.live_deploy.emit` lives under `dag/test/claim/**`, and no prefix in -// `v2.workflow.required_floor` `required_gate_prefixes` covers it -- so it enters a subject ONLY -// when a diff changes it. gunbc#11204's own merge-queue run changed that very file, so the rows -// resolved and the lane went green; every subsequent push to main and every PR that does not touch -// live-deploy refused with `PureProducerShareProducerModuleOutsideSubject` (main e6688ddb8e: green -// in the queue at 19:50Z under event=merge_group, red on the push at 20:50Z, same commit). -// -// So the enrolment was green exactly where it could not fail and red everywhere else, which is why -// it is removed here rather than repaired in place. Seeding a `dag/test/claim/**` module into every -// floor subject is the other available repair and it is a floor POLICY change -- it puts a claim -// module in the closure of every run -- so it belongs to the floor's own lane with its own -// argument, not to a bystander PR restoring the lane. -// -// THE COST PROBLEM IS REAL AND IS NOT ADDRESSED BY THIS REMOVAL. It returns to where it stood -// before gunbc#11204: the render is paid by whichever claim the diff plans, and those identities -// are already carried as declared cost debt in `v2.workflow.floor_cost_debt` (thirty-one -// `test.claim.live_deploy.emit.*` rows), so the ceiling does not refuse them today. A durable fix -// has to make the producer's module reachable from the subject the roster is read in; until that -// exists, no row here may name a module outside the gate closure. -// -// THE LAST ROW IS THE NAMESPACE-XL-4 FIXTURE INGEST, SHARED BY TWO CLAIM FILES. Floor run -// 34730467598 refused v2.test.claim.reference_derived_graph_call_arg_tree and -// v2.test.claim.reference_derived_graph_production_ingest as ENROLMENT-MARGIN-REFUSED / -// interrupted_before_verdict at the 500ms per-claim CPU ceiling -- the class -// gunbc.recurring_failure_mode.shared_precondition_re_derived_once_per_claim_frame. Re-derive with -// claim_batch --entry on those files plus the run's [floor-shared-fill] ledger. ONE producer, consumed -// by both files. THE SEAM IS THE INGEST: those claims name the collector and the edge fold, so sharing -// collection would hand each claim a precomputed answer. Parse trees and located roots travel on the -// same nullary value so parse-tree probes do not re-tokenize. -// THE LAST ROW IS THE NAMESPACE-XL-0 PRODUCTION-ROUTE FIXTURE, AND IT EARNS ITS PLACE THE WAY THIS -// HEADER ASKS: BY A FLOOR COST RECEIPT, NOT A TRANSCRIBED NUMBER. Every claim in -// v2.test.claim.namespace_xl0.call_argument_mention_survival drives the REAL parse-and-normalize -// ingest of two inline fixture modules, and with the producer absent the floor's own -// `required_floor_claim_cost.tsv` records that module's rows as budget_interrupted / -// right_censored against the per-claim CPU deadline -- INTERRUPTED BEFORE VERDICT, which is neither -// pass nor fail, so the lane blocks on a missing answer rather than a wrong one. That is the -// recurrence this tier deletes, and the disposition is worse than a slow pass: an uninterpretable -// row cannot be read as coverage at all. Re-derive with `claim_batch --entry` on that file plus the -// run's [floor-shared-fill] ledger, which must show this fill landing at preparation with -// disposition=Stored and the former interrupted claims serving hits. -// -// WARM, and the value is portable to the bottom: Outcome> is Nodes, -// symbols, strings and loci -- no Closure and no evaluator-node reference at any depth. It is -// nullary and its sources are INLINE in the witness, so preparation forces it without dispatching a -// host read. THE SEAM IS THE INGEST RATHER THAN THE REFERENCE-SITE COLLECTION, for exactly the -// reason the parse rows above keep normalize out: the claims in that file are ABOUT the collector, -// so sharing the collection would hand each one a precomputed answer to the question it asks. The -// walk stays per claim; only the stage no claim names is shared. -// THE LAST ROW IS THE NAMESPACE-XL-0 RESOLUTION-SIDE FIXTURE, THE SAME SHAPE AS THE ROW BEFORE IT -// AND ENROLLED FOR THE SAME REASON. v2.test.claim.namespace_xl0.cross_module_reference_resolution -// drives the real parse-and-normalize of eleven inline modules and then resolves ONE subject per -// claim (v2.compiler.name_resolve resolve_in_context resolves the admitted root alone; the -// other roots feed the symbol index), so the ingest is the stage no claim names and the resolve is -// the stage every claim names. Re-derived with `claim_batch --entry` on that file before enrolment: -// every row measured above the 500ms per-claim ceiling with the fill inside its own budget, and its -// fill (`[floor-shared-fill] ... fill_cpu_ms`) is the same order as the sibling row's. Re-derive -// rather than trust: the run's [floor-shared-fill] ledger must show this fill landing at -// preparation with disposition=Stored and the claims serving hits. Nullary, pure, inline sources, -// and the value is the same Outcome> carrier the row before it stores. -// -// AND THE EIGHT ROWS AFTER IT ARE THAT FILE'S RESOLVED SUBJECTS, ONE PRODUCER PER SUBJECT, EARNED BY -// TWO FLOOR REFUSALS RATHER THAN PREDICTED. gunbc#11582 run 35317696454: every resolve row reached -// its verdict and was refused COMPLETED-OVER-COST-REQUIREMENT at ~92k eval steps against the -// 72,300-step new-witness line, with the ingest fill served. Run 35327371663 then tried to share -// v2.compiler.name_resolve resolution_context and was refused PureProducerShareWarmNotStored -- -// ServeCacheValueNotPortable at .value.lm.canonical_symbols.member kind=Closure: the LanguageModel -// carries a function, and this store serves VALUES. Measured beside it with claim_batch: the -// context is ~12k steps and resolving a one-fn subject ~64k, so no portable context share puts a -// resolve row under the line. The share point is therefore the resolved Outcome per subject -// -- the shape direct_rust_door_specimen_resolved above already inhabits -- executed once by -// preparation (the real path, refused there if it cannot run) and read by the rows. Nullary, pure, -// inline sources; Nodes and located diagnostics, no closure. Re-derive rather than trust: the run's -// [floor-shared-fill] ledger must show all eight Stored at preparation and the rows serving hits. -// AND THE ROW AFTER THOSE IS THE ENUMERATOR FIXTURE, normalized, for -// v2.test.claim.namespace_xl0.qualified_site_enumerator_differential: the rows there name the -// collector's site WALK and share the one-module ingest the walk reads, exactly as the sibling rows -// do. The value is Nodes; no closure. (The parsed twin left with the retired parse walker.) -// -// AND THE FINAL ROW: -// DAG CANONICAL-SYMBOL MAP EARNS ITS ROW ON THE ENROLMENT-MARGIN CPU THE EVAL-STEP GATE -// CANNOT SEE. Sibling floor run 35340819603 (#11580 merging the resolve-cost head that -// establishes this map once per ResolutionContext) passed eval-steps and refused every -// resolving claim at the 302ms enrolment margin, including one-member resolve probes that -// sit near 40k steps. The same fill shows on grandfathered resolve claims. Re-derive with -// required_floor_claim_cost.tsv on that run plus claim_batch --entry -// src/v2/test/claim/name_resolve/one_member_cost_probe_test.dag [witness] cpu vs eval_steps: -// the map fill is host work outside the step counter, paid once per claim frame because the -// eval-frame memo dies at the claim boundary. Sharing census is the call-site graph: every -// dag_language_model() resolve path reads dag_canonical_symbols(), which is a PointwisePower -// closure and therefore not portable (ServeCacheValueNotPortable, the prepare_grammar -// nullable_set shape). The share point is the Map it is built from -- -// dag_canonical_symbol_map -- symbols and bools only; dag_canonical_symbols wraps that map -// at the consumer. Serve-below-recompute is the header's zero-walk Rc hand-over of a small -// map against a fill that already exceeds the enrolment margin in-fold. WARM, NEVER -// CLAIM-FORCED, by the same ceiling arithmetic as dag_prepared_grammar: an in-fold first -// touch of this fill dies on the lane's margin and restarts per claim. The module is under -// src/v2/extdeps, so it resolves in every required-floor subject. -// THE declaration_graft_assemble PRODUCERS EARN THEIR ROWS ON THE FILL-THAT-CANNOT-LAND (ten on the -// receipt below; an eleventh, declaration_graft_where_alias_undeclared_carrier_assembled, is the RED of -// the resolved where-head -- one assembly, on the same ground) -// v2.test.claim.body_cast_node bcn_refinement_of_refinement_as_its_carrier is the same ground for the -// Widened cast's one-step row (gunbc#12407): one assembly of a two-refinement module. -// GROUND, AND SIX OF THEM ON THE SHARING GROUND AS WELL. Receipt, re-derivable: required-floor -// run 35467726264 (gunbc#11574 head 1797ea43bd) reported fourteen of that file's claims -// COMPLETED-OVER-COST-REQUIREMENT at 73,857-148,646 eval steps against the 72,300 new-witness -// line -- the cheapest, a one-member type-only module, barely clearing it. One -// assemble_program_from_ingest over a ~30-200 character source is the whole cost; the -// assertions are a fold over its Outcome (DESIGN section 3's diagnostic: the cost did not move -// when the assertions changed). So no in-fold first touch can land inside a claim's budget, -// which is the dag_prepared_grammar / rust_module_emission_population ground. The share point -// is Outcome (the grafted, resolved root, or the typed refusal), the same seam as -// native_decl_selection.collision_resolved. The combined producer serves SIX claims off one -// tree (combined_accepts, silent_drop_control, coproduct_beside_fn, variant_reference_construct -// _and_match, dag_prefix_user_fn, import_beside_fn -- nine call sites; the type-only producer -// serves two, every other one exactly one); the one-member sources (empty, fn-only, type-only, -// where-alias-only) are the -// containment-spine controls of gunbc#11694 and cannot be combined; the two collided-alias -// sources cannot join the combined module because two where-refinement aliases in one module -// refuse resolve_reason_ambiguous_symbol on main (measured, independent of #11574); and the -// three refusing record sources are the typed-refusal rows whose claims assert the REASON, as -// population_declarationless_refuses does. Discrimination was re-established against the shared -// sources before enrolment: with the flatten's provenance filter reverted to spelling, both -// collided-alias rows red; with Conj-targeted members dropped from the flatten, the -// silent-drop control reds and the combined producer refuses on the conservation check. -// WARM, NEVER CLAIM-FORCED, by the same ceiling arithmetic as every row above. The instrument -// that decides it is the [floor-shared-fill] ledger, and it has been read (floor run -// 35509977276 on gunbc#11574 head 2fdc7f7863): ten fills disposition=Stored at -// pure-producer-share-warm, consumer_claims 6 / 2 / 1 as stated above, all sixteen claims -// admitted at 0-2ms against the 302ms margin, zero over-cost. An earlier revision of this note -// said eight for the combined producer -- a count from before the two collided-alias sources -// were given their own rows -- and the ledger is what corrected it. -// THE explicit_fn_import_binds ROW IS THE native_decl_selection GROUND AGAIN: four claims read four -// verdicts of one eight-read synthetic ingest through the native prepare route (supplied fixtures for -// import binding and for naming an import target's file refusal), so the context and verdicts are -// one nullary producer, WARM for the same reason. A cold fill would exceed one claim's budget. -// THE WHOLE-TREE CENSUS PROBE ROW IS THE native_decl_selection GROUND A THIRD TIME, ON THE SAME -// PRODUCER. v2.test.claim.native_census.whole_tree_census_resolve drives -// v2.compiler.compile native_test_context_from_ingest over one three-specimen supplied ingest, and -// its four context-consuming identities were refused COMPLETED-OVER-COST-REQUIREMENT at -// 197116-200054 evaluator steps against the 72300-step new-witness budget (run 35464948266, job -// 105955463881; observed cpu_ms=463-476, recorded and not gated on). The claims assert over one -// module's outcome each -- resolve-refused, file-refused and resolved -- so the front end they -// rebuilt per claim is work no row is about: DESIGN section 3's "a claim whose evaluation is -// dominated by ONE call whose RESULT SHAPE is all it inspects". -// THE SHARE POINT IS THE DECIDED OUTCOMES, not the context that produced them. NativeTestContext -// carries a resolution context, which is the origin-bound shape this roster refuses at publication; -// CensusProbeOutcomes carries three NativeCensusModuleOutcome variants plus an Int, and those carry -// only diagnostics -- symbols, loci and nodes -- so the stored value is positively portable for the -// same reason collision_resolved's ResolvedTree is. -// WARM, NEVER CLAIM-FORCED, for the reason the rows above give: the fill costs more than one -// claim's whole budget on this lane, so an in-fold fill would die mid-flight exactly as -// prepare_grammar's did. The instrument that decides this row is the required floor's -// [floor-shared-fill] ledger showing disposition=Stored at preparation, joined against -// required_floor_claim_cost.tsv showing the four identities reaching verdict_reached=true. -// THE NATIVE REFUSAL DETAIL PROBE ROW IS THE SAME GROUND A FOURTH TIME, ON THE SAME PRODUCER. -// v2.test.claim.native_route.native_refusal_detail drives native_test_context_from_ingest over one -// eight-specimen supplied ingest and native_lane_module_resolution over four of its modules; its -// six claims each inspect one row of that value. The stored value is four -// NativeLaneModuleResolution arms -- rows, diagnostics, symbols, nodes -- with no resolution -// context and no closure, portable for the same reason census_probe_outcomes is. WARM for the -// same ceiling arithmetic: the fill is a front end plus four resolves, more than one claim's budget. -// THE CLI TRAILING-TOKEN PROBE ROW: v2.test.cli.v2_native_cli drives v2_cli_run over a two-file -// supplied ingest whose second file refuses at parse; two claims read one field each of the -// CliRunOutcome. Stored value is a refused outcome (a Symbol and a String), portable. -// THE ARROW-BODY REFUSAL PROBE ROW IS THE SAME GROUND: v2.test.emit.closure_emit_arrow_body_refusal -// drives the closure emitter over a one-module supplied ingest whose fn has a body; two claims read -// one field each. Stored value is a refused verdict (a Symbol and a String), portable. -// THE NAMESPACE CANDIDATE RULE PROBE ROW IS THE SAME GROUND AGAIN, and the most expensive instance -// of it: v2.test.claim.resolve.namespace_candidate_rule drives native_test_context_from_ingest over -// a TWELVE-specimen supplied ingest TWICE -- once in declared order and once permuted -- because the -// file-order claim's whole content is that the two orders agree, and a second front end is the only -// way to have two orders. Nine claims then read one field each of the stored value. The stored value -// is verdict arms plus two Bool oracle readings (reason symbols, competing declaration paths, counts): -// no resolution context and no closure, portable for the same reason census_probe_outcomes is. WARM -// because the fill is two front ends over twelve modules, many times one claim's budget, and the -// alternative is paying it nine times. -// THE XL-2 CALL-ARGUMENT RESOLVE ROW IS THE SAME GROUND AT FOUR SPECIMENS. -// v2.test.claim.namespace_xl0.call_argument_resolve_refusal drives native_test_context_from_ingest -// once over four inline modules and resolves each; four claims read one verdict each. Absent, each -// claim paid the whole front end and the first floor run of gunbc#12108 refused all four as -// ENROLMENT-MARGIN-REFUSED at ~1.4s CPU. The stored value is verdict arms carrying a reason symbol -// and an optional atom symbol -- no resolution context, no Node, no closure -- portable for the same -// reason ncr_outcomes is. -// THE OPERATOR-SET ROWS ARE A PRODUCTION PRODUCER, THE SAME GROUND AS dag_prepared_grammar: -// v2.compiler.body_lowering_fold body_lower_binary_operator_tokens / body_lower_prefix_operator_tokens -// fold the grammar's binary and unary expressions to their terminal symbols. Every claim that lowers -// an operator expression reads them, and building them per frame cost ~11.4k eval steps. The value -// is a list of symbols. -// THE XL-2 SEQUENCE-OPERAND RESOLVE ROW IS THE SAME GROUND AT FIVE SPECIMENS: -// v2.test.claim.namespace_xl0.sequence_operand_resolve_refusal sqo_outcomes drives one front end -// over five inline modules and stores one verdict arm per module, portable for the same reason. -// THE XL-2 ENCLOSING-EXPRESSION ROW: v2.test.claim.body_lowering.enclosing_expression_structure -// ees_and_match_value, ees_call_match_value, ees_and_match_walked and ees_call_match_walked each -// tokenize and parse one inline module and call one producer on its body expression; the stored value -// is an EesValue (a lowered Node or a reason Symbol, no resolution context and no closure). -// THE XL-2 CALL-ARGUMENT VALUE RESOLVE ROW IS THE SAME GROUND AT TWENTY-ONE SPECIMENS: -// v2.test.claim.namespace_xl0.call_argument_value_resolve_refusal cav_outcomes drives one front end -// over twenty-one inline modules and stores one verdict arm per module, portable for the same reason. -// THE FOLD-LOWERING DISPOSITION ROW IS THE SAME GROUND AT FOUR SPECIMENS: -// v2.test.claim.fold_lowering flp_outcomes ingests the positional, positional-named-step, -// non-fold and well-formed snippets once and stores four Bool verdicts; MQ-1's first floor run refused each claim -// that paid its own ingest against the new-witness budget. Portable for the same reason. -// THE FOLD-ENCODING ROW IS THE SAME GROUND AT ELEVEN SPECIMENS: v2.test.claim.fold_encoding -// fe_outcomes drives the front end over its inline modules (the exact-shape fixture, three planted -// drops measured by reference conservation, the canary, a user-declared fold, fold_x, two piped -// folds and the step-binder fixture) and stores -// eleven Bool verdicts; MQ-5's floor run 36490720680 measured each claim that paid its own front end -// over the new-witness budget. Portable for the same reason. -// THE FOLD-OPERAND ROW IS THE SAME GROUND AT TWO SPECIMENS: v2.test.claim.body_lowering -// .fold_operand_structure fos_outcomes parses the `&&` and call-argument snippets once each and stores -// six Bool verdicts; the first floor run of its PR judged each claim that paid its own parse and lowering -// against the new-witness budget. Portable for the same reason. -// THE XL-2 LET-IN CAST ROW: v2.test.claim.body_cast_node bcn_let_in_value_cast_verdict assembles one -// inline module through the production route and stores one Bool (the lowered body carries exactly -// one cast node with its target), portable because it holds no Node and no closure. -// THE XL-2 IF-ARM AND STATEMENT-SPINE ROW IS THE SAME GROUND AT THIRTEEN SPECIMENS: -// v2.test.claim.namespace_xl0.if_arm_and_statement_lowering_refusal iasl_outcomes drives one front -// end over thirteen inline modules and stores one verdict arm per module, portable for the same reason. -// THE XL-2 MATCH-ARM LIST ROW: v2.test.claim.body_lowering.match_arm_list_structure mals_lowered and -// mals_third_arm_malformed each tokenize and parse one inline module and call one producer -// (body_lower_match_arms_optional) on its match capture; the stored value is the lowered arm list -// (Nodes, no resolution context and no closure), portable for the same reason vpw_normalized is. -// THE XL-2 RETURN-TAIL-POSITION ROW IS THE SAME GROUND AT NINE SPECIMENS: -// v2.test.claim.namespace_xl0.return_tail_position rtp_outcomes drives one front end over nine inline -// modules and stores one verdict arm per module, portable for the same reason cav_outcomes is. -// THE XL-2 WILDCARD-PATTERN-FORM ROW IS THE MATCH-ARM LIST ROW'S GROUND AT ONE MORE SPECIMEN: -// v2.test.claim.body_lowering.wildcard_pattern_form wpf_patterns tokenizes and parses one inline -// module and calls body_lower_match_arms_optional on its match capture; the stored value is the -// lowered arm patterns (Nodes, no resolution context and no closure). Its first floor run refused all -// five claims over the enrolment margin at ~590ms each, every one of them paying the same ingest. -// THE XL-2 ELSE-ARM ROW IS THE SAME GROUND AT FIVE SPECIMENS: v2.test.claim.namespace_xl0.else_arm_nested_if -// eam_outcomes drives one front end over five inline modules and stores one verdict arm per module. -// THE XL-2 REIFY-OPERAND ROW: v2.test.claim.body_lowering.reify_operand_refusal ror_verdicts tokenizes -// and parses two inline modules and reifies two supplied bodies over each; the stored value is four -// verdicts (no Node, no closure), portable for the same reason cav_outcomes is. -// THE XL-2 PARAMETER-SLOT ROW: v2.test.claim.body_lowering.parameter_slot_refusal psr_verdicts parses one -// inline module and lowers a supplied and an unmodified fn declaration; the stored value is two verdicts. -// THE XL-2 MATCH-POSITION ROW: v2.test.claim.body_lowering.match_position_structure mps_normalized -// runs the production route (module_roots_from_source_root_ingest) over three inline modules; the -// stored value is the normalized trees (Nodes, no resolution context and no closure), portable for -// the same reason vpw_normalized is. -// THE XL-2 BOUND-VALUE RESOLVE ROW IS THE SAME GROUND AT ELEVEN SPECIMENS: -// v2.test.claim.namespace_xl0.bound_value_resolve_refusal bvr_outcomes drives one front end over -// eleven inline modules and stores one verdict arm per module, portable for the same reason. -// THE XL-2 WILDCARD-ARM RESOLVE ROW IS THE SAME GROUND AT FOUR SPECIMENS: -// v2.test.claim.namespace_xl0.wildcard_arm_resolve wc_outcomes drives one front end over four inline -// modules and stores one verdict arm per module, portable for the same reason. -// THE BODY-LOWERING NORMALIZE ROW IS THE SAME GROUND, FOUND BY BEING EXPOSED RATHER THAN BY BEING -// NEW. v2.test.manual.body_lowering_normalize_add calls body_lowering_normalized_module() -- one -// front end over a source literal -- from NINETEEN sites, and the value is an Optional: -// a root Node, a marker channel and a binding row list, no resolution context and no closure, -// portable for the same reason ndp_resolutions is. -// -// IT WAS ALWAYS THIS EXPENSIVE; what changed is that it became visible. gunbc#12009 altered the -// arity of admit_normalized_tree, which this file calls, so its identities were read as changed and -// a withheld cost debt stopped being withheld -- body_lowering_normalized_arrow_root_resolves at -// 115,051 steps against the 72,300 new-witness budget, the single remaining blocker on that head. -// The verdict did NOT move: it returns true on origin/main and on that head, same interpreter, -// sources the only variable. So this is not a regression to revert but a pre-existing recompute the -// change surfaced, and the honest repair is the one this roster exists for rather than re-hiding it. -// THE LOADED-CARRIER INGESTS ARE THE SAME GROUND. v2.test.claim.provenance.loaded_carrier_receipts -// runs one front end over two inline modules and every claim in it reads that value: lcr_loaded_roots -// (a FreeMonoid) and lcr_located_roots (the located projection of the same ingest, -// an Outcome>) -- roots, marker channels, binding and record rows, no -// resolution context and no closure. adhoc-68dc5afb-a90 changed lcr_index, so the file's identities -// read as changed and each claim was judged at ~210,000 eval steps against the 72,300 new-witness -// budget, almost all of it the ingest the claims are not about. -// THE XL-2 REHEARSAL CONTROL ROW IS THE census_probe_outcomes GROUND AGAIN: test.claim -// .namespace_xl2_rehearsal_census drives native_test_context_from_ingest once per field of -// Xl2ControlRuns (read the type for the roster, not a count here) over two- and three-specimen ingests, and its -// claims each read one field of the resulting Xl2ControlRuns (GitObjectIds, diagnostics chains, strip coordinate rows -- no resolution context, -// no closure). WARM for the same arithmetic: one front end is more than one claim's budget. -// -// THE OCCURRENCE-ATTRIBUTION ROWS ARE THE SAME GROUND A FIFTH TIME, AND THE LEDGER NAMED THE ROW. -// v2.test.provenance.occurrence_file_attribution establishes that an occurrence resolves to a file -// and byte range; its seven claims each inspect ONE field of a value produced by driving the whole -// front end over a supplied two-file ingest -- which is DESIGN section 3's "a claim whose evaluation -// is dominated by ONE call whose RESULT SHAPE is all it inspects", and section 2's several demands -// for one computation identity with a shared ancestor. The front end each claim rebuilt is work no -// row is about. -// -// THE INSTRUMENT DECIDED THIS ROW RATHER THAN A PREFERENCE: the required floor (the `witnesses` -// lane of `gunbc.witness_floor_workflow`) refused -// `refused_assembly_still_locates_the_files_it_parsed_holds` as both ENROLMENT-MARGIN-REFUSED and -// COMPLETED-OVER-COST-REQUIREMENT; re-derive the figures by running that lane on the claim. The lane's own guidance was checked -// before reducing anything: the cause is not a nested membership scan and not contention at -// constant eval steps -- it is one front end per claim, so the share point is the producer. -// -// THE STORED VALUES ARE PORTABLE, which is the publication rule this roster enforces. None carries -// a ResolutionContext or a closure: `attribution_roots` and `native_route_roots` carry normalized -// trees plus a SpanIndex (a Map of OccurrenceId to OriginEvent -- loci, symbols and nodes), -// `attribution_refused_assembly` carries a SpanIndex and an Outcome, and -// `door_probe_cli_detail` carries a String. `native_route_roots` deliberately publishes -// `ctx.roots.roots` and NOT the NativeTestContext it came from, for the reason census_probe_outcomes -// gives: the context is the origin-bound shape this roster refuses. -// -// WARM, NEVER CLAIM-FORCED, by the same ceiling arithmetic as every row above: the fill is a front -// end over two files, which is more than one claim's budget on this lane, so an in-fold first touch -// would die mid-flight and be abandoned un-stored exactly as prepare_grammar's did. -// -// THE SIX pick_ingested ARROWS ARE THE SAME GROUND AS THE classical_not ROWS, AND A CHANGED-WITNESS -// RUN NAMED THEM. gunbc#12432's floor judged v2.test.long.pick_ingested_structural_lowering's six -// execution rows as changed witnesses at ~132k eval steps each against the 72300 new-witness budget -// (re-derive: that run's COMPLETED-OVER-COST-REQUIREMENT lines, or claim_batch's [witness] receipt -// over the file). Each row re-ran tokenize->parse->normalize->resolve->find-arrow over its own -// module-constant source and inspected only the evaluation of the result, so the share point is the -// nullary arrow producer per source. The values are resolved arrow Nodes -- portable, no closure, -// no resolution context -- and every producer is WARM for the ceiling arithmetic above: one front end -// is more than one claim's budget. ingested_classical_not_real_infer_holds, the seventh row that run -// named, re-ingested the source ingested_classical_not_arrow_with_body already serves from this -// roster; it now reads that producer, so it adds no row here. -// -// THE classical_not TARGET MODEL IS ONE DEMAND FROM EVERY EMIT ROW OF ITS THREE CONSUMER MODULES -// (v2.test.long.emit_host_classical_not_ingested_equals_eval, v2.test.long.emit_host_native_only_verdict, -// v2.test.execution.emit_on_demand_classical_not_ingested_family_witness). Each emit row builds -// rust_classical_not_ingested_target_model_staging from nothing -- a nullary pure producer whose value -// is the same TargetModel in every frame -- so the least common ancestor of those demands is the floor -// process and the per-claim rebuild is duplicated demand (DESIGN section 2), not a recurrence a cache -// excuses. Re-derive the cost with claim_batch per-fn inclusive steps over an emit row: the build is a -// fixed setup that does not move with the emitted module's size (flat classical_not and a four-leaf -// nested match pay the same construction), and its first touch of std.integer's interval-spec data rows -// alone exceeds one claim's new-witness budget, so it is WARM, NEVER CLAIM-FORCED by the arithmetic above. -// The value is a TargetModel record of Nodes, symbol/string Maps and data variants -- the shape the -// three withdrawn rust rows below stored without refusal -- so portability is not what is at risk. -// WHAT IS AT RISK IS THOSE ROWS' MEASURED FINDING: serving a rust TargetModel cost its produced-decl -// consumers more than recomputing it, for a cause this file leaves unidentified. This producer reaches -// none of those consumers, and it stays here only on a measured serve below recompute on its OWN -// consumer rows (required_floor_claim_cost.tsv, present against absent, normalised on rows outside its -// consumer modules); a regression there moves it to floor_cross_claim_refused_candidates. The emit rows -// read the arrow this roster already serves (ingested_emit_shape_frontier_tree_from_arrow) rather than -// re-ingesting, so with this row served they fit the new-witness budget; gunbc#12639's floor runs -// measure present against absent. -// -// THE parameter_reference PROGRAM IS ONE FRONT END FOR FOUR ROUTE ROWS. gunbc#12766's floor refused -// v2.test.claim.parameter_reference's four route rows as ENROLMENT-MARGIN-REFUSED and -// COMPLETED-OVER-COST-REQUIREMENT (re-derive: that run's lines, or claim_batch's [witness] receipt over -// the file): each re-ran ingest -> resolve (and one, infer) over its own module-constant source and -// inspected only a list of paths or four types. The rows now ask one program, so the share point is -// the two nullary producers over it. The values are an Optional list of QualifiedNames and a record of -// four Optional -- portable, no closure, no resolution context -- and both are WARM for the -// ceiling arithmetic above: one front end is more than one claim's budget. -// THE NEWLINE-REFUSAL MUTATION'S TWO GRAMMAR FACTS ARE SUPPLIED, NOT RE-DERIVED PER CLAIM. -// v2.test.parse.newline_dual_role_operator_mutation discriminates the newline-`-` refusal by parsing -// three one-line sources under the live grammar and under a mutant with every RefuseOnMatch arm -// stripped. Preparing that mutant is a whole grammar preparation, past one claim's new-witness budget -// (gunbc#12881's floor: 183k and 229k steps when each claim prepared its own), so the mutant's -// PreparedGrammar is one nullary producer, and the refusal-arm counts over the live grammar are -// another. A PreparedGrammar is the value dag_prepared_grammar already serves; the census is a record -// of two Ints. Both WARM: one grammar preparation is more than one claim's budget. -data floor_cross_claim_pure_producers_warm: List = [ - "v2.test.claim.parameter_reference.pr_program_parameter_paths", - "v2.test.claim.parameter_reference.pr_program_grounding", - "v2.test.claim.text_string_importer_census.tsic_real_route_outcome", - "v2.test.claim.text_string_importer_census.tsic_window_coverage_outcome", - "v2.test.claim.text_string_importer_census.tsil_literal_rows_outcome", - "v2.test.claim.text_string_importer_census.tsil_population_outcome", - "v2.test.claim.text_string_importer_census.tsil_alias_rows_outcome", - "v2.test.claim.text_string_importer_census.tsil_declined_rows_outcome", - "v2.test.claim.text_string_importer_census.tsic_crossing_outcome", - "v2.test.claim.text_string_importer_census.tsic_roster_outcome", - "test.claim.namespace_xl2_rehearsal_census.xl2_control_runs", - "v2.test.claim.provenance.loaded_carrier_receipts.lcr_loaded_roots", - "v2.test.claim.provenance.loaded_carrier_receipts.lcr_located_roots", - "v2.test.provenance.occurrence_file_attribution.attribution_roots", - "v2.test.provenance.occurrence_file_attribution.attribution_refused_assembly", - "v2.test.provenance.occurrence_file_attribution.door_probe_cli_detail", - "v2.test.provenance.occurrence_file_attribution.native_route_roots", - "v2.test.manual.body_lowering_normalize_add.body_lowering_normalized_module", - "v2.test.claim.resolve.namespace_candidate_rule.ncr_outcomes", - "v2.test.claim.namespace_xl0.call_argument_resolve_refusal.xl2_outcomes", - "v2.test.claim.body_lowering.enclosing_expression_structure.ees_and_match_value", - "v2.test.claim.body_lowering.enclosing_expression_structure.ees_call_match_value", - "v2.test.claim.body_lowering.enclosing_expression_structure.ees_and_match_walked", - "v2.test.claim.body_lowering.enclosing_expression_structure.ees_call_match_walked", - "v2.test.claim.namespace_xl0.sequence_operand_resolve_refusal.sqo_outcomes", - "v2.test.claim.namespace_xl0.value_position_whole_read.vpw_outcomes", - "v2.test.claim.namespace_xl0.value_position_whole_read.vpw_normalized", - "v2.test.claim.body_lowering.function_value_body.fvb_lowering_verdicts", - "v2.test.claim.body_lowering.function_value_body_route.fvb_outcomes", - "v2.test.claim.body_lowering.function_value_body_route.fvb_emit_curried_verdict", - "v2.test.claim.body_lowering.function_value_body_route.fvb_emit_direct_verdict", - "v2.test.long.pick_ingested_probe.pick_probe_normalized_module", - "v2.test.claim.body_type_annotation_refusal.btar_fn_literal_outcomes", - "test.claim.roadmap_authority.withheld_sized_subject_verdict", - "v2.test.claim.namespace_xl0.list_literal_value_lowering.llv_normalized", - "v2.test.claim.namespace_xl0.list_literal_value_lowering.llv_self_outcome", - "v2.test.claim.namespace_xl0.list_literal_value_lowering.llv_self_missing_outcome", - "v2.test.claim.namespace_xl0.call_argument_value_resolve_refusal.cav_outcomes", - "v2.test.claim.normalize.authored_marker_spelling.ams_verdicts", - "v2.test.claim.body_lowering.caret_symbol_value_lowering.csv_verdicts", - "v2.test.parse.type_decl_modifier_g0_parse_probe.caret_tree_atom_identities", - "v2.test.claim.body_lowering.string_literal_value_lowering.slv_verdicts", - "v2.test.claim.body_cast_node.bcn_let_in_value_cast_verdict", - "v2.test.claim.namespace_xl0.value_read_refusal.vrr_outcomes", - "v2.test.claim.fold_lowering.flp_outcomes", - "v2.test.claim.fold_encoding.fe_outcomes", - "v2.test.claim.body_lowering.fold_operand_structure.fos_outcomes", - "v2.test.claim.namespace_xl0.if_arm_and_statement_lowering_refusal.iasl_outcomes", - "v2.test.claim.namespace_xl0.bound_value_resolve_refusal.bvr_outcomes", - "v2.test.claim.body_lowering.match_arm_list_structure.mals_lowered", - "v2.test.claim.body_lowering.match_arm_list_structure.mals_third_arm_malformed", - "v2.test.claim.body_lowering.reify_operand_refusal.ror_verdicts", - "v2.test.claim.body_lowering.parameter_slot_refusal.psr_verdicts", - "v2.test.claim.namespace_xl0.return_tail_position.rtp_outcomes", - "v2.test.claim.body_lowering.wildcard_pattern_form.wpf_patterns", - "v2.test.claim.body_lowering.match_position_structure.mps_normalized", - "v2.test.claim.namespace_xl0.wildcard_arm_resolve.wc_outcomes", - "v2.test.claim.namespace_xl0.else_arm_nested_if.eam_outcomes", - "v2.test.cli.v2_native_cli.cli_probe_trailing_outcome", - "v2.test.emit.closure_emit_arrow_body_refusal.arrow_body_probe_verdict", - "v2.test.emit.closure_emit_arrow_body_refusal.arrow_body_mixed_probe_verdict", - "v2.test.emit.closure_emit_arrow_body_refusal.arrow_body_empty_probe_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_coproduct_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_record_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_refinement_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_alias_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_opaque_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_generic_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_payload_variant_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_label_spelled_record_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_bool_signature_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_declared_type_signature_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_bare_parameter_body_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_bare_literal_body_verdict", - "v2.test.claim.emit.module_member_emission.member_emission_supplied_refinement", - "v2.test.execution.infer_declaration_formation.formation_coproduct_verdict", - "v2.test.execution.infer_declaration_formation.formation_payload_coproduct_verdict", - "v2.test.execution.infer_declaration_formation.formation_plain_alias_verdict", - "v2.test.execution.infer_declaration_formation.formation_bodyless_verdict", - "v2.test.execution.infer_declaration_formation.formation_generic_binder_alias_verdict", - "v2.test.execution.infer_declaration_formation.formation_empty_record_verdict", - "v2.test.claim.body_lowering.plain_type_decl_lowering.ptd_coproduct_verdict", - "v2.test.claim.body_lowering.plain_type_decl_lowering.ptd_alias_used_verdict", - "v2.test.claim.body_lowering.plain_type_decl_lowering.ptd_alias_of_alias_verdict", - "v2.test.claim.body_lowering.plain_type_decl_lowering.ptd_bodyless_verdict", - "v2.test.claim.body_lowering.plain_type_decl_lowering.ptd_payload_single_variant_verdict", - "v2.test.claim.coercion.identity_cast_emission_route.identity_cast_route_verdict", - "v2.test.claim.coercion.identity_cast_emission_route.refused_cast_route_verdict", - "v2.test.emit.int_literal_form_unwired_located.int_literal_probe_table", - "v2.test.claim.native_route.native_refusal_detail.ndp_resolutions", - "v2.test.claim.native_census.whole_tree_census_resolve.census_probe_outcomes", - "v2.test.native_decl_selection.collision_resolved", - "v2.test.name_resolve.explicit_fn_import_binds.efib_verdicts", - "v2.extdeps.languages.bash_command_fold.bash_fold_formal_productions", - "v2.extdeps.languages.bash_command_fold.bash_fold_lex", - "v2.compiler.program_assembly.dag_prepared_grammar", - "v2.compiler.body_lowering_fold.body_lower_binary_operator_tokens", - "v2.compiler.body_lowering_fold.body_lower_prefix_operator_tokens", - "v2.test.long.emit_host_produced_module_equals_eval.produced_add_module_source", - "v2.test.long.emit_host_classical_not_ingested_equals_eval.ingested_classical_not_arrow_with_body", - "v2.test.long.emit_host_classical_not_ingested_equals_eval.ingested_classical_not_swapped_arrow_with_body", - "v2.extdeps.languages.rust_test.rust_classical_not_ingested_target_model_staging", - "v2.test.long.pick_ingested_structural_lowering.pick_ingested_true_arrow", - "v2.test.long.pick_ingested_structural_lowering.pick_ingested_false_arrow", - "v2.test.long.pick_ingested_structural_lowering.pick_ingested_swapped_arrow", - "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_true_arrow", - "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_false_arrow", - "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arrow", - "v2.compiler.self_host.direct_rust_door_fixture.direct_rust_door_specimen_resolved", - "v2.test.execution.data_decl_lowering_grounding.ddl_data_resolved", - "v2.test.execution.data_decl_lowering_grounding.ddl_fn_eq_resolved", - "v2.test.execution.data_decl_lowering_grounding.ddl_fn_brace_resolved", - "v2.test.parse.variant_field_lowering.vfs_normalized_0", - "v2.test.parse.variant_field_lowering.vfs_normalized_1", - "v2.test.parse.variant_field_lowering.vfs_normalized_2", - "v2.test.parse.variant_field_lowering.vfs_normalized_3", - "v2.test.parse.variant_field_lowering.vfs_normalized_4", - "v2.test.parse.variant_field_lowering.vfs_normalized_5", - "v2.test.parse.variant_field_lowering.vfs_normalized_6", - "v2.test.parse.variant_field_lowering.vfs_normalized_7", - "v2.test.parse.variant_field_lowering.vfs_normalized_8", - "v2.test.parse.variant_field_lowering.vfs_normalized_9", - "v2.test.parse.variant_field_lowering.vfs_normalized_10", - "v2.test.parse.variant_field_lowering.vfs_normalized_11", - "v2.test.parse.variant_field_lowering.vfs_normalized_12", - "v2.test.parse.variant_field_lowering.vfs_normalized_13", - "v2.test.parse.variant_field_lowering.vfs_normalized_14", - "v2.test.parse.variant_field_lowering.vfs_normalized_15", - "v2.test.parse.variant_field_lowering.vfs_normalized_16", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_0", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_1", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_2", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_3", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_4", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_5", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_6", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_7", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_8", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_9", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_10", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_parsed_11", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_0", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_1", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_2", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_3", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_4", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_5", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_6", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_7", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_8", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_9", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_10", - "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse.cps_normalized_11", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_0", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_1", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_2", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_3", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_4", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_5", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_6", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_7", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_8", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_9", - "v2.test.parse.closure_parse_batch_two.cb2_parsed_10", - "v2.test.parse.closure_parse_batch_two.cb2_normalized_5", - "v2.test.parse.closure_parse_batch_two.cb2_normalized_7", - "v2.test.parse.closure_parse_batch_two.cb2_normalized_8", - "v2.test.parse.closure_parse_batch_two.cb2_normalized_9", - "v2.test.parse.closure_parse_batch_two.cb2_normalized_10", - "v2.test.claim.match_arm_binder_frame.mab_resolved_0", - "v2.test.claim.match_arm_binder_frame.mab_resolved_1", - "v2.test.claim.match_arm_binder_frame.mab_resolved_2", - "v2.test.claim.match_arm_binder_frame.mab_resolved_3", - "v2.test.claim.match_arm_binder_frame.mab_resolved_4", - "v2.test.claim.match_arm_binder_frame.mab_resolved_5", - "v2.test.claim.match_arm_binder_frame.mab_resolved_6", - "v2.test.claim.match_arm_binder_frame.mab_resolved_7", - "v2.test.claim.match_arm_binder_frame.mab_resolved_8", - "v2.test.claim.match_arm_binder_frame.mab_resolved_9", - "v2.test.claim.match_arm_binder_frame.mab_resolved_where_alias_binder", - "v2.test.claim.match_arm_binder_frame.mab_resolved_unshadowed_binder", - "v2.test.claim.match_arm_binder_frame.mab_resolved_record_data_binder", - "v2.test.claim.match_arm_binder_frame.mab_resolved_ambiguous_binder", - "v2.test.claim.match_arm_binder_frame.mab_resolved_module_named_binder", - "v2.test.claim.match_arm_binder_frame.mab_resolved_unimported_constructor", - "v2.test.claim.match_arm_binder_frame.mab_resolved_declared_constructor", - "v2.test.claim.match_arm_binder_frame.mab_resolved_two_module_variant", - "v2.test.claim.match_arm_binder_frame.mab_record_declarations_specimen", - "v2.test.claim.where_predicate_binding.wpb_resolved_declared", - "v2.test.claim.where_predicate_binding.wpb_resolved_undeclared", - "v2.test.claim.where_predicate_binding.wpb_resolved_labelled_then_undeclared", - "v2.test.claim.where_predicate_binding.wpb_resolved_labelled_and_marker", - "v2.test.claim.type_param_binder_frame.tpb_identity", - "v2.test.claim.type_param_binder_frame.tpb_colliding", - "v2.test.claim.type_param_binder_frame.tpb_used_outside", - "v2.test.claim.type_param_binder_frame.tpb_same_name_twice", - "v2.test.claim.type_param_binder_frame.tpb_sibling_binder_leak", - "v2.test.claim.type_param_binder_frame.tpb_two_params", - "v2.test.claim.type_param_binder_frame.tpb_undeclared_type_name", - "v2.test.claim.type_param_binder_frame.tpb_non_generic", - "v2.test.claim.type_param_binder_frame.tpb_type_param_as_value", - "v2.test.claim.type_param_binder_frame.tpb_emitted_add_twin", - "v2.test.claim.type_param_binder_frame.tpb_emitted_add_generic", - "v2.test.claim.anonymous_param_binder.apb_two_anonymous", - "v2.test.claim.anonymous_param_binder.apb_body_reference", - "v2.test.claim.anonymous_param_binder.apb_two_sites", - "v2.test.claim.anonymous_param_binder.apb_mixed", - "v2.test.claim.declared_parameter_order.dpo_b_then_a", - "v2.test.claim.declared_parameter_order.dpo_a_then_b", - "v2.test.claim.declared_parameter_order.dpo_eleven_anonymous", - "v2.test.claim.declared_parameter_order.dpo_label_shadows_a_declaration", - "v2.test.claim.named_argument_binding.nab_reordered", - "v2.test.claim.named_argument_binding.nab_in_order", - "v2.test.claim.named_argument_binding.nab_positional_after_named", - "v2.test.claim.named_argument_binding.nab_label_repeated", - "v2.test.claim.body_type_annotation_refusal.btar_let_annotated", - "v2.test.claim.body_type_annotation_refusal.btar_let_plain", - "v2.test.claim.body_type_annotation_refusal.btar_fn_literal_annotated", - "v2.test.claim.body_type_annotation_refusal.btar_fn_literal_plain", - "v2.test.claim.body_type_annotation_refusal.btar_if_arm_fn_literal", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_coproduct", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_coproduct_colliding", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_record", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_record_two", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_leak", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_non_generic", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_emit_twin", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_emit_generic", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_alias_instantiation", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_alias_colliding", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_alias_undeclared", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_opaque", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_single_variant_after_separator", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_plain_single_variant_after_separator", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_plain_single_alias", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_generic_alias", - "v2.test.claim.type_param_binder_frame.tpb_type_decl_nullary_tag", - "v2.test.claim.type_param_binder_frame.tpb_semantic_emit_twin", - "v2.test.claim.type_param_binder_frame.tpb_semantic_emit_generic_reason", - "v2.test.claim.fold_lowering.lowered_fixture_loop", - "v2.test.claim.body_cast_node.bcn_tail_cast", - "v2.test.claim.body_cast_node.bcn_let_value_cast", - "v2.test.claim.body_cast_node.bcn_call_argument_cast", - "v2.test.claim.body_cast_node.bcn_if_arm_cast", - "v2.test.claim.body_cast_node.bcn_match_arm_cast", - "v2.test.claim.body_cast_node.bcn_call_operand_cast", - "v2.test.claim.body_cast_node.bcn_tail_undeclared", - "v2.test.claim.body_cast_node.bcn_match_arm_undeclared", - "v2.test.claim.body_cast_node.bcn_generic_cast", - "v2.test.claim.body_cast_node.bcn_value_param_as_type", - "v2.test.claim.body_cast_node.bcn_int_sum_as_int", - "v2.test.claim.body_cast_node.bcn_int_sum_as_bool", - "v2.test.claim.body_cast_node.bcn_int_sum_as_int_inferred", - "v2.test.claim.body_cast_node.bcn_int_sum_as_bool_inferred", - "v2.test.claim.body_cast_node.bcn_into_refinement", - "v2.test.claim.body_cast_node.bcn_out_of_refinement", - "v2.test.claim.body_cast_node.bcn_into_refinement_inferred", - "v2.test.claim.body_cast_node.bcn_out_of_refinement_inferred", - "v2.test.claim.body_cast_node.bcn_refinement_param_as_bool", - "v2.test.claim.body_cast_node.bcn_refinement_identity_cast", - "v2.test.claim.body_cast_node.bcn_refinement_param_as_bool_inferred", - "v2.test.claim.body_cast_node.bcn_refinement_identity_cast_inferred", - "v2.test.claim.body_cast_node.bcn_emitted_cast", - "v2.test.claim.body_cast_node.bcn_emitted_cast_without_target", - "v2.test.claim.body_let_annotation.bla_concrete", - "v2.test.claim.body_let_annotation.bla_generic", - "v2.test.claim.body_let_annotation.bla_type_param_as_value", - "v2.test.claim.body_let_annotation.bla_value_param_as_type", - "v2.test.claim.body_let_annotation.bla_int_sum_as_int", - "v2.test.claim.body_let_annotation.bla_int_sum_as_bool", - "v2.test.claim.body_let_annotation.bla_int_sum_as_int_inferred", - "v2.test.claim.body_let_annotation.bla_int_sum_as_bool_inferred", - "v2.test.claim.body_let_annotation.bla_int_literal_as_int", - "v2.test.claim.body_let_annotation.bla_int_literal_as_bool", - "v2.test.claim.body_let_annotation.bla_int_literal_as_int_inferred", - "v2.test.claim.body_let_annotation.bla_int_literal_as_bool_inferred", - "v2.test.claim.body_let_annotation.bla_declared_int_literal", - "v2.test.claim.body_let_annotation.bla_declared_bool_literal", - "v2.test.claim.body_let_annotation.bla_declared_int_literal_inferred", - "v2.test.claim.body_let_annotation.bla_declared_bool_literal_inferred", - "v2.test.claim.body_let_annotation.bla_imported_int_literal", - "v2.test.claim.body_let_annotation.bla_ambiguous_imported_int_literal", - "v2.test.claim.body_let_annotation.bla_ambiguous_kernel_int_literal", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_int", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_int_inferred", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_symbol", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_symbol_inferred", - "v2.test.claim.body_let_annotation.bla_symbol_literal_payload_verdict", - "v2.test.infer_facts.key_collision_ref_and_int.kc_verdicts", - "v2.test.claim.body_let_annotation.bla_int_literal_payload_digit_verdict", - "v2.test.claim.body_let_annotation.bla_string_literal_unimported", - "v2.test.claim.body_let_annotation.bla_string_literal_as_int", - "v2.test.claim.body_let_annotation.bla_unknown_unimported_type", - "v2.test.claim.body_let_annotation.bla_structural_string_literal", - "v2.test.claim.body_let_annotation.bla_structural_string_host_value", - "v2.test.claim.body_let_annotation.bla_string_literal_unimported_inferred", - "v2.test.claim.body_let_annotation.bla_string_literal_as_int_inferred", - "v2.test.claim.body_let_annotation.bla_structural_string_literal_inferred", - "v2.test.claim.body_let_annotation.bla_structural_string_host_value_inferred", - "v2.test.claim.body_let_annotation.bla_string_literal_typed_host_text_verdict", - "v2.test.claim.body_let_annotation.bla_single_tree_declared_int", - "v2.test.claim.body_let_annotation.bla_single_tree_declared_bool", - "v2.test.claim.body_let_annotation.bla_single_tree_undeclared_int", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_int", - "v2.test.claim.body_let_annotation.bla_symbol_literal_as_int_inferred", - "v2.test.claim.body_let_annotation.bla_annotated_bind_emitted", - "v2.test.claim.body_let_annotation.bla_reordered_self_reference", - "v2.test.claim.body_let_annotation.bla_reordered_outer_reference", - "v2.test.claim.body_let_annotation.bla_let_optional", - "v2.test.claim.body_let_annotation.bla_ret_optional", - "v2.test.claim.body_let_annotation.bla_fld_optional", - "v2.test.claim.body_let_annotation.bla_let_pos_int", - "v2.test.claim.body_let_annotation.bla_ret_pos_int", - "v2.test.claim.body_let_annotation.bla_fld_pos_int", - "v2.test.claim.body_let_annotation.bla_let_pos2_pos", - "v2.test.claim.body_let_annotation.bla_ret_pos2_pos", - "v2.test.claim.body_let_annotation.bla_fld_pos2_pos", - "v2.test.claim.body_let_annotation.bla_let_pos2_int", - "v2.test.claim.body_let_annotation.bla_ret_pos2_int", - "v2.test.claim.body_let_annotation.bla_fld_pos2_int", - "v2.test.claim.body_let_annotation.bla_let_neg_pos", - "v2.test.claim.body_let_annotation.bla_ret_neg_pos", - "v2.test.claim.body_let_annotation.bla_fld_neg_pos", - "v2.test.claim.body_let_annotation.bla_plain_let_pos", - "v2.test.claim.body_let_annotation.bla_plain_let_pos2", - "v2.test.claim.body_lowering_qualified_path.body_lowering_qualified_value_normalized", - "v2.test.manual.body_lowering_projection_call.body_lowering_parsed_module", - "v2.test.execution.emit_on_demand_match_loop_fold_family_witness.mlf_family_primary_emitted", - "v2.test.execution.emit_on_demand_family_crate_witness.logic_family_primary_emitted", - "v2.test.self_host.stage0_production_target.stage0_boundary_profile_emitted_source", - "v2.test.self_host.stage0_production_target.stage0_boundary_base_emitted_source", - "v2.test.claim.self_host.rust_module_emission_population.population_emission_add", - "v2.test.claim.self_host.rust_module_emission_population.population_emission_add2", - "v2.test.claim.self_host.rust_module_emission_population.population_emission_add_then_add2", - "v2.test.claim.self_host.rust_module_emission_population.population_declarationless_refuses", - "v2.test.claim.self_host.rust_module_emission_population.population_unwired_two_declaration_refuses", - "v2.test.claim.self_host.rust_module_emission_population.population_declaration_count_add", - "v2.test.claim.self_host.rust_module_emission_population.population_declaration_count_add_then_add2", - "v2.test.parse.d1_declaration_grammar_parse.d1_where_reproducer_parsed", - "v2.test.parse.d1_declaration_grammar_parse.d1_where_bare_parsed", - "v2.test.parse.d1_declaration_grammar_parse.d1_where_control_parsed", - "v2.test.parse.d1_declaration_grammar_parse.d1_cache_identity_where_parsed", - "v2.test.parse.where_refinement_clause_parse.where_refinement_bare_parsed", - "v2.test.parse.expression_bodied_fn_decl_parse.expression_bodied_fn_parsed", - "v2.test.parse.expression_bodied_fn_decl_parse.expression_bodied_literal_fn_parsed", - "v2.test.parse.expression_bodied_fn_decl_parse.braced_fn_control_parsed", - "v2.test.parse.match_arm_statement_body_parse.match_arm_statement_body_parsed", - "v2.test.parse.newline_dual_role_operator_mutation.nlm_mutant_prepared", - "v2.test.parse.newline_dual_role_operator_mutation.nlm_refusal_arm_census", - "v2.test.claim.body_lowering_block_body_call.body_lowering_block_call_parsed", - "v2.test.claim.namespace_xl0.call_argument_mention_survival.call_argument_fixture_normalized", - "v2.test.claim.namespace_xl0.body_shape_contract.body_shape_normalized_root", - "v2.compiler.reference_conservation.dag_declared_token_classes", - "v2.compiler.occurrence_role.dag_name_table_admission", - "v2.compiler.occurrence_role.dag_name_production_emitted_symbols", - "v2.test.claim.namespace_xl0.reference_conservation.clean_control_subject", - "v2.test.claim.namespace_xl0.reference_conservation.clean_control_report", - "v2.test.claim.namespace_xl0.reference_conservation.block_second_statement_subject", - "v2.test.claim.namespace_xl0.reference_conservation.if_arm_call_argument_subject", - "v2.test.claim.namespace_xl0.reference_conservation.infix_right_operand_subject", - "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payload_subject", - "v2.test.claim.normalize.service_declaration_lowering.sdl_posix_census", - "v2.test.claim.normalize.service_declaration_lowering.sdl_shared_prefix_census", - "v2.test.claim.normalize.service_spine.ss_two_under_one_prefix_paths", - "v2.test.claim.normalize.service_spine.ss_body_against_declaration_refused", - "v2.test.claim.normalize.service_spine.ss_repeated_service_refused", - "v2.test.claim.normalize.service_spine.ss_scope_control_admitted", - "v2.test.claim.normalize.service_spine.ss_scope_leak_refused", - "v2.test.claim.normalize.service_spine.ss_boundary_index", - "v2.test.claim.normalize.service_spine.ss_route_bare_prefix", - "v2.test.claim.normalize.service_spine.ss_route_bare_sibling", - "v2.test.claim.normalize.service_spine.ss_route_module_name", - "v2.test.claim.normalize.service_spine.ss_route_qualified", - "v2.test.claim.normalize.service_spine.ss_route_qualified_missing", - "v2.test.claim.normalize.service_spine.ss_importer_assembled", - "v2.test.claim.normalize.service_spine.ss_importer_missing_assembled", - "v2.test.claim.normalize.operation_modifier.om_all_modifiers_lowered", - "v2.test.claim.normalize.operation_modifier.om_repeated_modifier_refused", - "v2.test.claim.binder_default_judgment.bdj_inhabiting_inferred", - "v2.test.claim.binder_default_judgment.bdj_not_inhabiting_inferred", - "v2.test.claim.binder_default_judgment.bdj_outer_value_inferred", - "v2.test.claim.binder_default_judgment.bdj_sibling_param_assembled", - "v2.test.claim.binder_default_judgment.bdj_type_param_as_default_assembled", - "v2.test.claim.binder_default_judgment.bdj_generic_default_inferred", - "v2.test.claim.binder_default_judgment.bdj_generic_coproduct_default_inferred", - "v2.test.claim.namespace_xl0.reference_conservation.repeated_spelling_subject", - "v2.test.claim.namespace_xl0.reference_conservation.named_argument_label_subject", - "v2.test.claim.namespace_xl0.reference_conservation.list_literal_argument_subject", - "v2.test.claim.namespace_xl0.reference_conservation.string_literal_value_subject", - "v2.test.claim.namespace_xl0.reference_conservation.where_refinement_predicate_subject", - "v2.test.claim.namespace_xl0.reference_conservation.match_later_arm_subject", - "v2.test.claim.namespace_xl0.reference_conservation.construct_tags_subject", - "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_subject", - "v2.test.claim.namespace_xl0.reference_conservation.normalization_refused_subject", - "v2.test.claim.namespace_xl0.reference_conservation_census.quota_fixture_files", - "v2.test.claim.namespace_xl0.reference_conservation_census.under_floor_fixture_files", - "v2.test.claim.namespace_xl0.reference_conservation_census.half_share_fixture_files", - "v2.test.claim.occurrence_role.occurrence_role.roles_fixture_outcome", - "v2.test.claim.parse.default_value.param_default_parsed", - "v2.test.claim.parse.default_value.param_default_lowered_onto_its_binder", - "v2.test.claim.parse.default_value.field_default_lowered_onto_its_binder", - "v2.test.claim.parse.default_value.io_default_lowered_onto_its_binder", - "v2.test.claim.parse.default_value.field_key_refused_as_interface", - "v2.test.claim.parse.pattern_and_let_sugar.fn_tree", - "v2.test.claim.parse.pattern_and_let_sugar.pattern_tree", - "v2.test.claim.parse.pattern_and_let_sugar.node_colon_tree", - "v2.test.claim.parse.pattern_and_let_sugar.node_eq_tree", - "v2.test.claim.parse.pattern_and_let_sugar.bare_assign_tree", - "v2.test.claim.parse.pattern_and_let_sugar.pattern_uses_refused_as_unmodeled", - "v2.test.claim.parse.pattern_and_let_sugar.pattern_generic_refused_at_generics", - "v2.test.claim.parse.pattern_and_let_sugar.pattern_eq_body_refused", - "v2.test.claim.parse.admit_callers_trailing_comma.trailing_comma_parsed", - "v2.test.claim.parse.admit_callers_trailing_comma.no_trailing_comma_parsed", - "v2.test.claim.parse.admit_callers_trailing_comma.only_a_comma_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.match_heading_chain_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.if_heading_chain_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.bare_match_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.bare_if_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.ordinary_binary_parsed", - "v2.test.parse.block_expr_as_binary_operand_parse.bare_match_body_is_match", - "v2.test.parse.block_expr_as_binary_operand_parse.bare_if_body_is_branch", - "v2.test.claim.parse.uses_clause.uses_parsed", - "v2.test.claim.parse.uses_clause.uses_refusal", - "v2.test.claim.parse.data_keyword_as_value.data_value_parsed", - "v2.test.claim.parse.data_keyword_as_value.data_value_normalized", - "v2.test.claim.parse.data_keyword_as_value.else_value_parsed", - "v2.test.claim.parse.record_field_tail.default_parsed", - "v2.test.claim.parse.record_field_tail.from_key_refused_as_unmodeled", - "v2.test.claim.parse.record_field_tail.plain_normalized", - "v2.test.claim.parse.where_clause_required_comma.alias_then_service_parsed", - "v2.test.claim.parse.where_clause_required_comma.two_predicates_parsed", - "v2.test.claim.parse.where_clause_required_comma.adjacent_predicates_parsed", - "v2.test.claim.parse.parameter_refinement.refined_parsed", - "v2.test.claim.parse.parameter_refinement.refined_refused_at_clause", - "v2.test.claim.parse.parameter_refinement.plain_normalized", - "v2.test.claim.occurrence_role.occurrence_role.binders_fixture_outcome", - "v2.test.claim.occurrence_role.occurrence_role.mixed_param_list_parsed", - "v2.test.claim.occurrence_role.occurrence_role.mixed_param_list_planted", - "v2.test.claim.namespace_xl0.reference_conservation.statement_let_binder_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.binary_operand_beside_match_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.binary_operand_beside_if_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.record_field_beside_match_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.call_argument_beside_match_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.map_literal_value_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.qualified_constructor_value_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.match_arm_statement_body_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.data_initializer_match_scrutinee_subject", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.fn_body_match_scrutinee_subject", - "v2.test.claim.namespace_xl0.reference_conservation.anonymous_slots_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.two_same_spelled_let_binders_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.operator_call_argument_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.operator_if_arm_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.scope_member_dropping_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.scope_outsider_dropping_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.scope_member_clean_subject", - "v2.test.claim.namespace_xl0.reference_conservation_admission.call_projection_operand_subject", - "v2.test.claim.body_lowering.declaration_structure_preserved.where_refinement_alias_subject", - "v2.test.claim.body_lowering.single_arm_match.three_arm_subject", - "v2.test.claim.body_lowering.single_arm_match.zero_arm_subject", - "v2.test.claim.body_lowering.statement_let_bind.let_then_reference_subject", - "v2.test.claim.body_lowering.statement_let_bind.let_chain_subject", - "v2.test.claim.body_lowering.statement_let_bind.let_in_form_subject", - "v2.test.claim.body_lowering.statement_let_bind.typed_let_subject", - "v2.test.claim.body_lowering.statement_let_bind.unbound_prefix_subject", - "v2.test.claim.body_lowering.statement_let_bind.single_statement_subject", - "v2.test.claim.body_lowering_block_body_call.body_lowering_block_call_subject", - "v2.test.claim.machine_shape_construction_wall.machine_shape_record_literal_subject", - "v2.test.claim.machine_shape_construction_wall.machine_shape_record_literal_home_subject", - "v2.test.claim.body_lowering.qualified_construct.qc_fixture_normalized", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_bare", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_qualified", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_twins", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_type_tag", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_unimported", - "v2.test.claim.body_lowering.qualified_construct.qc_resolved_bodyless", - "v2.test.claim.body_lowering.anonymous_record.ar_fixture_normalized", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_headed", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_headless", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_call_argument", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_coproduct", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_binder", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_value_mismatch", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_value_mismatch_headed", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_list_headed", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_list_headless", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_rename_headed", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_rename_headless", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_reorder", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_constant", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_partial", - "v2.test.claim.body_lowering.anonymous_record.ar_resolved_cycle", - "v2.test.claim.body_lowering.anonymous_record.ar_infer_verdict_value_mismatch", - "v2.test.claim.body_lowering.anonymous_record.ar_infer_verdict_value_mismatch_headed", - "v2.test.claim.body_lowering.anonymous_record.ar_key_bare_subject", - "v2.test.claim.body_lowering.anonymous_record.ar_key_quoted_subject", - "v2.test.claim.body_lowering.map_literal.ml_fixture_normalized", - "v2.test.claim.body_lowering.map_literal.ml_resolved_headed", - "v2.test.claim.body_lowering.map_literal.ml_resolved_headless", - "v2.test.claim.body_lowering.map_literal.ml_resolved_duplicate", - "v2.test.claim.body_lowering.map_literal.ml_resolved_escape_duplicate", - "v2.test.claim.body_lowering.map_literal.ml_resolved_distinct", - "v2.test.claim.body_lowering.map_literal.ml_resolved_key_kind", - "v2.test.claim.body_lowering.map_literal.ml_resolved_name_key", - "v2.test.claim.body_lowering.map_literal.ml_resolved_call_argument", - "v2.test.claim.body_lowering.map_literal.ml_resolved_value_mismatch", - "v2.test.claim.body_lowering.map_literal.ml_resolved_samemod", - "v2.test.claim.body_lowering.map_literal.ml_infer_verdict_headless", - "v2.test.claim.body_lowering.map_literal.ml_infer_verdict_value_mismatch", - "v2.test.claim.body_lowering.map_literal.ml_infer_verdict_samemod", - "v2.test.claim.body_lowering.map_literal.ml_int_key_verdict_refused", - "v2.test.claim.body_lowering.map_literal.ml_mixed_normalized", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_fixture_normalized", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_bad", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_good", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_generic_good", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_nested_good", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_missing", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_unknown", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_generic_bad", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_other", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_far_value", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_far_missing", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_bool_field", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_resolved_pattern", - "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_fixture_normalized", - "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_resolved_phantom", - "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_resolved_two_good", - "v2.test.claim.compiler.kernel_value_type_roster_witness_test.kvr_fixture_normalized", - "v2.test.claim.compiler.kernel_value_type_roster_witness_test.kvr_resolved_return_bad", - "v2.test.claim.compiler.kernel_value_type_roster_witness_test.kvr_resolved_return_good", - "v2.test.claim.compiler.kernel_value_type_roster_witness_test.kvr_resolved_formal", - "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_fixture_normalized", - "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_resolved_return_bad", - "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_resolved_lift", - "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_resolved_field_bad", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_fixture_normalized", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_local_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_declared_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_undeclared_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_data_target_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_field_access_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_shadowing_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_consumer_a", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_consumer_b", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_method_call_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_import_consumer_a", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_import_consumer_b", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_relay_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_imported_param_type_consumer", - "v2.test.claim.namespace_xl0.cross_module_reference_resolution.xl0r_resolved_unimported_param_type_consumer", - "v2.test.claim.reference_closure.rc_fixture_normalized", - "v2.test.claim.reference_closure.rc_resolved_entry", - "v2.test.claim.reference_closure.rc_resolved_imported", - "v2.test.claim.reference_closure.rc_resolved_dotted", - "v2.test.claim.reference_closure.rc_resolved_transitive", - "v2.test.claim.reference_closure.rc_resolved_logic", - "v2.test.claim.reference_closure.rc_resolved_broken_entry", - "v2.test.claim.self_host.closure_emission.ce_emission_outsider_body_refuses", - "v2.test.claim.self_host.closure_emission.ce_emission_outsider_unparseable", - "v2.test.claim.self_host.closure_emission.ce_emission_member_body_refuses", - "v2.test.claim.self_host.closure_emission.ce_emission_duplicate_module", - "v2.test.claim.namespace_xl0.qualified_site_enumerator_differential.qsd_normalized", - "v2.extdeps.languages.dag.dag_canonical_symbol_map", - "v2.test.claim.declaration_graft_assemble.declaration_graft_combined_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_alias_spelled_as_emitted_id_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_alias_spelled_as_production_name_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_empty_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_fn_only_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_type_only_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_where_alias_only_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_record_construct_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_record_type_only_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_flag_and_rec_assembled", - "v2.test.claim.declaration_graft_assemble.declaration_graft_where_alias_undeclared_carrier_assembled", - "v2.test.claim.body_cast_node.bcn_refinement_of_refinement_as_its_carrier" -] +// ── THE OBSERVATION: ONE ROW PER IDENTITY THE PLANNED CLAIMS REACH ──────────────────────── -// grammar_relation_row_for_emitted HAS NOW BEEN MEASURED ON THE THIRD CONJUNCT, AND IT PASSES. -// It was enrolled on recompute AND sharing before the serve-below-recompute criterion above -// existed, so it stood on two of the three tests this file now requires, and gunbc#10141's -// carrier-overlap wall refused it on a NEIGHBOUR's null result -- it serves -// v2.test.manual.rust_add_emit_translate, a carrier of the refused rust_target_model_core_edges, -// whose refusal was NoMeasuredEffectOverItsConsumers. A null about a different producer is -// evidence neither of a cost here nor of its absence, so the state was UNMEASURED, not fine. -// -// HOW TO ACTUALLY RUN A PAIR, CORRECTED BY EXECUTION (2026-09-07). The paragraph below names the -// right hazard and a remedy that does not execute, and the difference matters because this is the -// carrier a reader consults to learn how to measure a candidate. THE HAZARD IS REAL: CI builds -// refs/pull/N/MERGE, so a PR pair measures two different trees the moment main moves between the -// two pushes. THE REMEDY AS WRITTEN DOES NOT RUN: `.github/workflows/witnesses.yml` triggers on -// workflow_dispatch, merge_group, push to branches [main], and pull_request against main -- a -// PUSHED SIDE BRANCH TRIGGERS NOTHING, so a reader following "dispatched on branches" literally -// gets no runs at all and the likeliest conclusion they draw is that these rows are unmeasurable. -// THE REMEDY THAT WORKS is workflow_dispatch on a branch ref pinned to an exact sha: the floor -// then runs against THAT TREE rather than a merge ref, so main moving underneath cannot touch -// either arm, which is strictly stronger than the one-base discipline the hazard asks for. -// Receipt that dispatch executes: runs 34088506991 (absent, 9788d35369023cb6aaac300fb060b88e0202f301) -// and 34088508298 (present, a94e14bab571ddcdccc4e4e5ef8bd8be3173890a), the pair measuring -// `witness_layer_decl_index` for warm enrolment -- a producer that no longer exists: it was the -// zero-arg mint of the whole witness-layer declaration population, and the keyed read in -// `v2.lens.common.outside_modeled_guarantee_join` left it with no consumer. The receipt is kept -// because the refusal is about the VALUE that was measured, which is the reading that produced the -// keyed read; the name is recorded here as the producer of that run rather than as a live symbol. -// -// TWO PRESENT-VS-ABSENT PAIRS, dispatched on branches rather than as pull requests because CI -// builds refs/pull/N/MERGE and a PR pair measures two different trees the moment main moves: -// 33701546412/33701544509 and 33705546522/33705544280, each present/absent off one main commit -// differing in this one line. THE ARM IS VERIFIED TO HAVE VARIED rather than assumed: the key -// carries 148 fills over 60 consumer modules in both present arms and is WHOLLY ABSENT from both -// absent ledgers, while the other five keys carry identical fill counts in all four runs. -// -// CONDITIONED ON, and stated because rust_target_model_staging measured clean beside a wider row -// and inherited that row's regression the moment the wider row was withdrawn: both bash warm rows -// plus bash_fold_serialize_node, formal_productions_from_catalog_node and -// bash_fold_relation_row_witness enrolled in every arm, and no rust row enrolled in any. -// -// THE CONTROL IS NOT THE ROSTER-EXTERNAL CORPUS, and that correction is the transferable part. -// Normalising the subject's consumers against rows in no consumer module of any enrolled key -// reports a ~12% win, and it is mostly composition: eval_steps is in required_floor_claim_cost.tsv -// and is host-independent, so the subject's own rows split into those whose steps FELL (the serve -// reached them) and those whose steps are BYTE-IDENTICAL across arms (the serve never reached -// them, same claims, same runs). The second group is a control the change provably cannot have -// touched, and it moves almost as much as the first. Rows elsewhere are an ASSUMPTION about the -// corpus; rows doing byte-identical work are an OBSERVATION about the row. -// -// AGAINST THAT CONTROL THE SERVE BEATS THE RECOMPUTE IN BOTH PAIRS, by roughly a tenth on the -// rows it reaches, with about an eighth of their eval_steps avoided; the two pairs' bootstrap -// intervals overlap and neither admits 1. The estimate is biased TOWARD the null, not toward this -// result: a row the serve reached whose step count happened not to move lands in the control group. -// -// WHAT RE-DERIVES WHICH HALF OF THAT, BECAUSE ONE INSTRUMENT DOES NOT EXIST. An earlier revision -// of this paragraph said `re-derive with the instrument named`, and named none: the run ids above -// are the measurement's STORAGE and `eval_steps` is its OUTPUT column, and neither performs the -// control split or the interval. Promising a producer that does not exist is worse than -// transcribing a figure, because a reader who tries to act on the sentence finds nothing to run -- -// and it is a different defect from the one the paragraphs above avoid, which name real -// instruments (claim_batch under GUNBC_RECOMPUTE_TRACE=1, and the floor's own cost artifact). -// Corrected rather than softened (raised as REQUEST_CHANGES by codex, review 59321): -// RE-DERIVABLE with no instrument at all, from the four run ids plus -// `required_floor_claim_cost.tsv`: join the subject's rows across a pair at identity grain, -// take the consumer set from the present arm's own `[floor-shared-fill] modules=` field, split -// those rows into steps-FELL and steps-BYTE-IDENTICAL, and ratio the aggregates. That is the -// decisive comparison, and it needs arithmetic rather than tooling. -// NOT RE-DERIVABLE that way: the bootstrap intervals. Resampling needs an RNG the report path -// does not have, so they stand as observed and cannot be reproduced from anything named here. -// The claim they support -- that neither interval admits 1 -- therefore rests on the original -// measurement rather than on anything a later reader can re-run. -// The row's admission stands on the ratio, which is re-derivable; the intervals corroborate it -// and are not load-bearing for it. Dropping the split and the intervals while keeping the -// confident register would have been the same defect with the evidence removed. -// -// SO THE ROW STAYS, on all three conjuncts rather than two. The refusal that opened this question -// is already gone, and by the same reasoning rather than by exemption: gunbc#10141's overlap join -// is narrowed to refused rows whose verdict records a MEASURED cost, so -// `refused_row_carriers_transfer` answers false for NoMeasuredEffectOverItsConsumers and the wall -// never reaches core_edges' carriers. THAT IS OBSERVED AND NOT ONLY DESIGNED: floor run -// 33703215821 is FloorClean with this key enrolled and core_edges in the refused roster -- same -// roster, same carriers, no refusal. An overlap with a producer whose own measurement found no -// effect either way was never evidence about this one. -// -// ONE OBSERVATION LEFT UNEXPLAINED ON PURPOSE, because an unsupported cause in a carrier is read -// as a lead and spends the next reader's time before it spends their doubt: 12 claims carry -// EXACTLY 1044 more eval_steps with this row enrolled -- a constant, not a distribution, across -// claims of very different sizes. It was pre-registered from pair 1 and reproduced 12 of 12 at -// exactly 1044 in pair 2, so it is structural and deterministic rather than a run artifact. It is -// not roster resolution: install_pure_producer_share decodes both lists once per prepared subject. -// It is not admission diverting calls from the cheaper per-frame memo: eval_pure_named_call is -// reached only when pure_call_memo_key returns None, so the tiers are disjoint by key -// availability. Cause unknown; all 12 route through v2.test.manual.rust_add_emit_translate's -// fixture, which is where to look and is not a mechanism. -// -// The claim-forced rows carry claim-independent ARGUMENTS in practice (a production -// catalog node, a production identity) but are not nullary, so they fill on first touch -// and later claims hit on the content-hashed, fully-verified argument row. Measured owners -// of the bash emit path's word-independent fixed cost (recompute trace over a two-word -// serialize: grammar_relation_row_for_emitted ~30ms/call, -// formal_productions_from_catalog_node ~22ms, bash_fold_relation_row_witness ~13ms); -// enrolling them measured a one-word bash serialize claim at 105ms -> 65ms wall in a -// fresh consuming frame, and run 33269961629 measured real cross-claim reuse for each -// (150 fills/175 consumer claims, 16/45, 49/36 respectively). -// -// formal_production_for_lhs_exact was enrolled here and REMOVED by the same run's evidence: -// 1,635 fills for 113 consumer claims — per-argument keys with almost no reuse. A row earns -// its place by measured recompute AND measured sharing; a non-sharing producer is cache -// population, not a saving. -// bash_fold_serialize_node is the cross-WITNESS dedupe row (lane 2, clever-fox-24's -// live_deploy measurement): 21 apply witnesses rebuild one byte-identical script 21 times -// (~3.4s each) because the eval-frame memo dies at the claim boundary; serving the -// per-statement serialization from this tier makes the 20 repeats hits on one fill. -// -// THE PERSISTED FRONTIER STANDING IS NOT ENROLLED HERE, AND ITS ABSENCE IS A DECISION RATHER -// THAN AN OVERSIGHT. `gunbc.self_host_compile_phase_frontier` `compile_phase_frontier_standing` -// is the shared producer under `test.claim.self_host_compile_phase_live_gate_witness` and -// `test.claim.self_host_compile_phase_frontier_witness`, and gunbc#10094 measured a large win -// from enrolling it CLAIM-FORCED at that general declaration -- 13 rows from 445-467 cpu-ms to -// about 73, holding across three present runs. The row was WITHDRAWN anyway, and the reason is -// this file's own single-authority discipline rather than its cost criterion. -// -// The general declaration takes the receipt series as an ARGUMENT, so every consuming frame -// must reify and structurally verify a `List` before it may be -// served -- the shape whose serve cost this file's header already records LOSING to recompute -// twice. That it measured a win here does not make the shape sound; it makes this measurement -// the outlier that a nullary enrolment would not need to explain. gunbc#10108 removes the -// argument instead of paying to verify it: it consolidates the one persisted series into a -// NULLARY standing, which is preparation-forceable with an empty argument row, and enrols that. -// That is the DESIGN section 3 repair, and it also reaches consumers this row could not -- -// `test.claim.compiler_frontend_program_status_witness`, and a fold that took the series and -// re-derived the standing itself. -// -// SO ONE FACT GETS ONE ROW, AT THE DECLARATION THAT MAKES IT CHEAP. Landing both would be two -// roster rows claiming one saving, which is the failure gunbc#10108's own note names about -// enrolling a nest. This paragraph stands in the withdrawn row's place so the next reader does -// not re-derive its cost figures and re-propose it. -// -// THE ARROW-BODY PROJECTION ROW IS MEASURED CROSS-CLAIM WORK, NOT INFERRED FROM THE FOUR ROWS -// that exposed it. Required-floor run 33707763185's complete cross-claim-demand artifact names -// `target_project_arrow_body_to_value_expression` at 95 claims / 117 evaluations, 4396ms total -// and 4350ms cross-claim across the emit family. The four `v2.test.emit.rust_body_add_emit` -// identities are consumers of that same declaration and argument population; moving their five -// fixture values between modules changed each by exactly 39 of ~171k evaluator steps and thereby -// refuted import closure as their cost owner. This row enrolls the producer the run-scoped census -// actually named. Its present-vs-absent receipt is #10170's required-floor claim-cost and shared- -// fill artifacts; if serve does not beat recompute at identity grain, this row is withdrawn under -// the admission criterion above rather than defended by the family aggregate. -data floor_cross_claim_pure_producers_claim_forced: List = [ - "v2.workflow.bash_command_fold_serialize.bash_fold_serialize_node", - "v2.compiler.target_serialize.grammar_relation_row_for_emitted", - "v2.std.grammar.formal_productions_from_catalog_node", - "v2.extdeps.languages.bash_command_fold.bash_fold_relation_row_witness", - "v2.std.compilers.target_model.target_project_arrow_body_to_value_expression" -] +// Why a reached call site carries no closed computation identity. CLOSED: a new reason is a new +// arm, so the seed cannot mint an unclassified one. +// CalleeUnresolved -- the site's callee is not a resolved source declaration (a +// runtime primitive, a locally bound function value, an +// undetermined target): nothing to key a fill on. +// CalleeDeclaresEffects -- the callee declares effect uses; its value depends on the world, +// which the key cannot represent (carried inputs are their own row kind). +// ArgumentNotClosedConstant -- some argument mentions a binder of the enclosing declaration or +// an expression form the normalizer does not admit, so the argument +// row is not fixed before the claim runs. +type CallSiteDemandCause + = CalleeUnresolved + | CalleeDeclaresEffects + | ArgumentNotClosedConstant + +// `producer` is the callee's qualified declaration; `argument_preimage` the canonical normalized +// argument row; `claims` the number of DISTINCT planned claims whose reach contains a site of this +// identity; `sites` those sites as `:-` byte spans, which is what the seed admits. +// An unadmissible row aggregates every site sharing one cause: `claims` counts distinct planned +// claims reaching any of them, `sites` counts the sites. +type CallSiteDemandObservation + = ClosedCallSiteDemand { + producer: String + argument_preimage: String + identity: ComputationIdentity + claims: Int + sites: List + } + | UnadmissibleCallSiteDemand { + cause: CallSiteDemandCause + claims: Int + sites: Int + } + +// ── THE DECISION ────────────────────────────────────────────────────────────────────────── + +type DerivedShareRow { + producer: String + argument_preimage: String + claims: Int + sites: List +} + +// Why a CLOSED identity is still not admitted. The four arms are the whole decision, so every +// closed row lands in exactly one of `admitted` or one of these, and the counts reconcile against +// the observation population (`cross_claim_share_derivation_reconciles`). +type ShareDerivationDecline + = DemandedByOneClaim + | IdentityGradeNotShareable + | RefusedByMeasurement + | CarriedInputProducer + +type DeclinedShareRow { + producer: String + argument_preimage: String + decline: ShareDerivationDecline +} + +type UnadmissibleDemandCount { + cause: CallSiteDemandCause + claims: Int + sites: Int +} + +type CrossClaimShareDerivation { + admitted: List + declined: List + unadmissible: List +} + +fn closed_demand_decline( + producer: String, + identity: ComputationIdentity, + claims: Int, + refused_names: List, + carried_names: List +) -> List { + if identity_permits_share(ci: identity) == false { + [IdentityGradeNotShareable] + } else if any(xs: refused_names, predicate: fn(r) { r == producer }) { + [RefusedByMeasurement] + } else if any(xs: carried_names, predicate: fn(c) { c == producer }) { + [CarriedInputProducer] + } else if claims < 2 { + [DemandedByOneClaim] + } else { + [] + } +} + +fn derived_share_rows_for( + observation: CallSiteDemandObservation, + refused_names: List, + carried_names: List +) -> List { + match observation { + ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: s } => + if length(xs: closed_demand_decline(producer: p, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names)) == 0 { + [DerivedShareRow { producer: p, argument_preimage: a, claims: c, sites: s }] + } else { + [] + } + UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => [] + } +} + +fn declined_share_rows_for( + observation: CallSiteDemandObservation, + refused_names: List, + carried_names: List +) -> List { + match observation { + ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: _ } => + list_map( + xs: closed_demand_decline(producer: p, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names), + f: fn(d) { DeclinedShareRow { producer: p, argument_preimage: a, decline: d } } + ) + UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => [] + } +} + +fn unadmissible_counts_for(observation: CallSiteDemandObservation) -> List { + match observation { + ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, sites: _ } => [] + UnadmissibleCallSiteDemand { cause: k, claims: c, sites: n } => + [UnadmissibleDemandCount { cause: k, claims: c, sites: n }] + } +} + +// THE FOLD THE FLOOR CONSUMES. Each output list is one linear pass over the observations and the +// rows are never accumulated by copying, so the decision is linear in the identity population. +fn derive_cross_claim_share( + observations: List, + refused: List, + carried: List +) -> CrossClaimShareDerivation { + let refused_names = refused_share_producers(refused: refused) + let carried_names = carried_input_warm_producers(rows: carried) + CrossClaimShareDerivation { + admitted: list_flat_map(xs: observations, f: fn(o) { derived_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names) }), + declined: list_flat_map(xs: observations, f: fn(o) { declined_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names) }), + unadmissible: list_flat_map(xs: observations, f: fn(o) { unadmissible_counts_for(observation: o) }), + } +} + +// The live derivation, over the refused and carried rows this file declares. The seed calls this. +fn floor_cross_claim_share_derivation( + observations: List +) -> CrossClaimShareDerivation { + derive_cross_claim_share( + observations: observations, + refused: floor_cross_claim_refused_candidates, + carried: floor_cross_claim_carried_input_warm_rows + ) +} + +fn closed_observation_count(observations: List) -> Int { + length(xs: filter(xs: observations, predicate: fn(o) { + match o { + ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, sites: _ } => true + UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => false + } + })) +} + +// THE PARTITION HOLDS: every closed observation is admitted or declined, exactly once. +fn cross_claim_share_derivation_reconciles( + observations: List, + derivation: CrossClaimShareDerivation +) -> Bool { + length(xs: derivation.admitted) + length(xs: derivation.declined) == closed_observation_count(observations: observations) +} + +// The admitted producers as names, for the refused-carrier overlap wall in the seed and for the +// collision walls below. +fn derived_share_producers(derivation: CrossClaimShareDerivation) -> List { + list_map(xs: derivation.admitted, f: fn(row) { row.producer }) +} // ── REFUSED CANDIDATES: THE ROWS THIS ROSTER MEASURED AND TURNED DOWN ───────────────────── // @@ -1549,7 +290,7 @@ type ShareRefusalVerdict = // `carrier_modules` is the set of consuming modules the refusal was MEASURED OVER -- the claims // that carried it, read from the deciding run's own `[floor-shared-fill]` `modules=` field, which // names the modules rather than counting them. It is descriptive at THIS grain and load-bearing -// at the ledger's: see the overlap note below `share_roster_refusal_collisions`. +// at the ledger's: see the overlap note below `refused_row_carriers_transfer`. type RefusedShareCandidate { producer: String verdict: ShareRefusalVerdict @@ -1649,18 +390,10 @@ data floor_cross_claim_refused_candidates: List = [ }, carrier_modules: ["v2.test.claim.affected_set_universe"], measurement: "THIS ROW IS A WITHDRAWAL OF AN ENROLMENT THIS LANE PROPOSED, recorded as such rather than as a candidate that was never admitted. gunbc#11247 proposed carrying this producer WARM on a real duplication measurement -- the floor own census carried a producer=meta_processes row whose cross-claim share was a visible fraction of its total, and the carry demonstrably worked: with it applied, affected_set_universe_includes_meta_self drops to a SMALL FRACTION of its unserved step count and meta_processes DISAPPEARS from the cross-claim census of run 34742966153 because it is served rather than re-derived. The cost case was correct and is not what refuses it. NO FIGURE FROM THAT MEASUREMENT IS TRANSCRIBED HERE, and the withdrawal does not need one: what is preserved is that a real duplication was measured and that the cost case was sound, both re-derivable from the named run and artifact. What refuses it is the key: the serve-boundary check made when it was proposed asked whether the VALUE was portable (no Closure, no OriginBoundNode at any depth) and never asked whether the KEY covered every input. It does not" as String, - next_trigger: "the same capability: reflection keyed by qualified or scoped identity. When it lands this row returns to floor_cross_claim_pure_producers_warm with the receipt gunbc#11247 already measured, which is why that measurement is preserved above rather than discarded with the enrolment" as String + next_trigger: "the same capability: reflection keyed by qualified or scoped identity. When it lands this refused row is deleted and the derived share admits the producer wherever its planned demand qualifies, with the receipt gunbc#11247 already measured, which is why that measurement is preserved above rather than discarded with the enrolment" as String } ] -// The admitted population, as one list, so a caller cannot check one roster and miss the other. -fn floor_cross_claim_admitted_producers() -> List { - concat( - floor_cross_claim_pure_producers_warm, - floor_cross_claim_pure_producers_claim_forced - ) -} - // Folded rather than mapped, and with no new import: `fold`, `concat`, `reverse` and `any` // resolve as kernel builtins here exactly as they do in `v2.workflow.floor_changed_witness`. // This module is a DECLARED CLOSURE SEED of the required floor @@ -1757,8 +490,8 @@ fn refused_row_carriers_transfer(verdict: ShareRefusalVerdict) -> Bool { // AND THE CLASS'S RUNG IS THE MINIMUM ACROSS ITS PATHS, NOT THE STRONGER WALL'S. DESIGN section // 4b(1) is explicit that a class's current rung is the minimum over its in-scope paths. The class // is "a producer this roster has measured and refused is re-admitted", and it has two paths: -// literal re-proposal of the same spelling, which the fold above refuses structurally over the -// declared rosters, and re-admission through a second identity that inherits the refused row's +// literal re-proposal of the same spelling, which `derive_cross_claim_share` declines by construction (its +// `RefusedByMeasurement` arm), and re-admission through a second identity that inherits the refused row's // consumers, which the executor refuses at RUNTIME over one run's observed ledger. A runtime // refusal is rung 2, mechanically preventable -- the invalid state stays writable and safety // depends on the required floor executing and staying enrolled. So the sentence to carry out of @@ -1770,123 +503,16 @@ fn refused_row_carriers_transfer(verdict: ShareRefusalVerdict) -> Bool { // the graph instead of read off a run. That, and only that, moves the second path from a runtime // refusal to a structural one; a second observed-ledger check would not. // -// THE WALL: an identity may not stand in an admitted roster and in the refused roster at once. -// Re-proposing a measured-and-refused producer then REFUSES by execution, naming the row that -// already measured it, instead of depending on the next author reading a paragraph. -// -// TAKES ITS POPULATIONS AS ARGUMENTS SO ITS RED IS AUTHORABLE. DESIGN section 4b says to ask -// whether the forbidden state can be written anywhere the check could run before writing the -// check. Over the live rosters alone it cannot -- they are disjoint today and a check that can -// only be reddened by editing the corpus it guards is a decoration. As a function of two lists it -// is red on an authored fixture, and the live tree is its positive control. -fn share_roster_refusal_collisions( - admitted: List, - refused: List -) -> List { - let refused_names = refused_share_producers(refused: refused) - reverse(fold(admitted, init: [], f: fn(acc, name) { - if any(xs: refused_names, predicate: fn(r) { r == name }) { - concat([name], acc) - } else { - acc - } - })) -} - -// ── PENDING CANDIDATES: PROPOSED, NOT YET MEASURED ─────────────────────────────────────── -// -// WHY A THIRD SHAPE RATHER THAN A ROW IN ONE OF THE TWO THAT EXIST. This file could express a -// producer it ADMITS and a producer it has measured and REFUSED, and nothing in between. A -// candidate that has been proposed but not yet measured fits neither: putting it in an admitted -// roster enrols it, which is the thing the measurement is supposed to decide, and putting it in -// `floor_cross_claim_refused_candidates` requires a `ShareRefusalVerdict`, so the row would -// assert a measured outcome that nobody measured. That second move is the one worth naming: it -// is DESIGN section 4b(1) rung inflation at the roster grain -- a verdict field filled in from a -// plan rather than from an executed present-vs-absent pair -- and it would be read by the -// overlap wall through `refused_row_carriers_transfer` as a measured cost travelling to other -// producers' consumers, which is a fabricated subject. -// -// SO A PENDING ROW CARRIES NO VERDICT FIELD AT ALL, and that absence is the design rather than -// an omission: there is no place in this type to write an outcome, so the unmeasured state -// cannot be spelled as a measured one (DESIGN section 5 -- correctness by construction, not a -// check that the verdict was earned). -// -// WHAT A PENDING ROW MUST CARRY INSTEAD: why it was proposed, naming the instrument that -// re-derives the recompute cost rather than transcribing what it printed (DESIGN section 6, and -// the same rule the refused rows above already follow); the measurement that would DECIDE it; -// and what would REFUSE it, so a negative result has a stated shape before it is run and cannot -// be quietly reinterpreted as "not yet conclusive". -// -// HOW A PENDING ROW LEAVES, and there is no fourth exit: its deciding measurement runs, and the -// row moves to an admitted roster or to `floor_cross_claim_refused_candidates` with the verdict -// that measurement produced. A pending row that has been standing without its measurement being -// scheduled is a proposal nobody is deciding, and this roster would rather show that than hide it -// in an annotation. -type PendingShareCandidate { - producer: String - proposed_because: String - deciding_measurement: String - refuses_if: String -} - -data floor_cross_claim_pending_candidates: List = [ - PendingShareCandidate { - producer: "v2.std.decl_index.decl_facts", - proposed_because: "A whole-corpus declaration index is re-derived ONCE PER CLAIM and never across claims: the eval-frame memo already collapses every call within one claim and dies at the claim boundary, so the cost is not repetition inside a claim -- it is one build per claim, charged to each. THE INSTRUMENT THIS ROSTER NORMALLY ENROLS FROM CANNOT SEE THIS PRODUCER, and that is stated here rather than discovered by the next reader: the cross-claim demand census absorbs a claim's demands when the claim RETURNS, and a preempted claim never returns, so the producer whose cost caused the preemption is censored out of the census by the very cost that makes it a candidate -- the census is blind exactly where the cost is highest. Read on the required floor's own summary line as claim_cpu_censored_rows_excluded, which on main run 34085084808 excluded precisely the run's four interrupted claims and printed no row for this producer. Its declared omitted_under_floor counters make it a lower bound besides. So the recompute evidence for this row comes from the per-claim cost receipt's OUTCOME column instead (an interrupted claim is a categorical fact, not a censored measurement) and from claim_batch's gross per-claim [witness] receipt, which is not interchangeable with the census: claim_batch does not run required_floor_runner's shared-fill netting, so it prices a recompute and says nothing about what the floor would charge. FOR SCALE, so this row is not read as the largest instance: the same census names producers with two orders of magnitude more consuming claims than this three-witness file, none of them proposed here. This is a small candidate that happens to be preempting the merge path, not the roster's biggest recomputation.", - deciding_measurement: "Present-vs-absent on this row alone, both arms run by WORKFLOW_DISPATCH ON A BRANCH REF PINNED TO AN EXACT SHA, per the corrected procedure in this module's header: a PULL REQUEST pair is refused because CI builds refs/pull/N/MERGE and measures two different trees the moment main moves, and a PUSHED BRANCH is refused because it triggers no run at all under witnesses.yml. Dispatch runs the floor against that tree, so main moving underneath cannot touch either arm. Normalised on claims in no consumer module of any enrolled key, read over required_floor_claim_cost.tsv and the run's own [floor-shared-fill] ledger -- the same discipline every admitted and every refused row above was decided by, with the procedure corrected to the one that executes.", - refuses_if: "Serving costs at or above recomputing over this producer's own consumers (MeasuredServeAboveRecompute), or the present and absent arms do not separate over them (NoMeasuredEffectOverItsConsumers). And a THIRD outcome that is not a verdict about cost at all, stated in advance because the same edit produces it and only one of the two is recoverable by reverting a roster row: a whole-corpus row list against a byte-bounded store with total reification is exactly the value most likely to REFUSE TO STORE at publication, and the header above rules that a WARM row which fails to evaluate or refuses to store STOPS THE LINE. For a claim-forced row an over-budget producer is a silent recompute; for a warm row it is a stopped floor. So the warm arm must be measured with the store byte budget in view, and it did not help must never be reported as it refused the run. Separately, this producer takes pool_roots, so it is claim-shaped and can only ever be a CLAIM-FORCED row -- where the fill still happens inside the fold on first touch, which is why enrolling this spelling cannot by itself remove a first-touch interrupt." - }, - PendingShareCandidate { - producer: "v2.lens.module_graph.module_declaration_facts_live", - proposed_because: "Proposed with decl_facts and not separately: the two are demanded together at every site that resolves a declaration reference, so a measurement enrolling one and not the other prices half a join. Same instruments as the row above, and the same exclusion: the per-claim cost receipt's OUTCOME column and claim_batch's gross receipt, NOT the cross-claim demand census, which is blind to this producer for the reason the row above states -- a preempted claim never returns, so its demands are never absorbed.", - deciding_measurement: "The same present-vs-absent discipline and the same sha-pinned workflow_dispatch procedure as the row above, measured with decl_facts rather than beside it -- the header's rust_target_model_staging row is the receipt for why: a candidate measured clean beside a wider row inherited that row's regression the moment the wider row was withdrawn, so an arm must vary exactly the rows it claims to decide.", - refuses_if: "The same two verdicts and the same store-refusal outcome, over its own consumers. Additionally refused if the pair turns out to be one demand rather than two -- if no consumer reaches this producer without also reaching decl_facts, the single-authority repair is one producer for the joined fact, and enrolling two identities for it would be the fork this roster's SupersededBySingleAuthorityRepair arm already refuses once." - } -] - -// The pending population as names, folded exactly like `refused_share_producers` and for the same -// reason: the wall below needs identities, and a second spelling of this fold would be the kind of -// duplicate this file exists to price. -fn pending_share_producers(pending: List) -> List { - reverse(fold(pending, init: [], f: fn(acc, row) { concat([row.producer], acc) })) -} - -// THE WALL: AN IDENTITY MAY NOT BE PENDING AND ALREADY DECIDED AT THE SAME TIME. -// -// The two collisions this refuses are different mistakes and both are live. A producer that -// stands in an admitted roster AND in the pending list has already been enrolled while a row -// still says its enrolment is an open question -- the roster then answers one question two ways, -// which is the section 3 fork, and the more dangerous direction because the enrolment is the arm -// that executes. A producer that stands in the refused roster AND in the pending list is a -// re-proposal of something this file already measured and turned down, which is exactly what -// `share_roster_refusal_collisions` refuses for the admitted rosters; a pending row is a proposal -// too, so it needs the same refusal or the refused roster is bypassable by proposing instead of -// enrolling. -// -// TAKES ITS POPULATIONS AS ARGUMENTS, for the reason the sibling fold above states and not by -// imitation: over the live rosters this is green today and could be reddened only by editing the -// corpus it guards, which DESIGN section 4b calls a decoration. As a function of three lists the -// forbidden state is writable in a fixture, and the live tree is the positive control. -fn share_roster_pending_collisions( - pending: List, - admitted: List, - refused: List -) -> List { - let decided = concat(admitted, refused_share_producers(refused: refused)) - reverse(fold(pending_share_producers(pending: pending), init: [], f: fn(acc, name) { - if any(xs: decided, predicate: fn(d) { d == name }) { - concat([name], acc) - } else { - acc - } - })) -} +// THE LITERAL PATH IS NOW CONSTRUCTION, NOT A WALL. The fold that refused an admitted roster row +// naming a refused producer is deleted with the roster: `derive_cross_claim_share` declines every +// closed demand whose producer a refused row names (`RefusedByMeasurement`), so a refused producer +// cannot be admitted by its own spelling. The executor's overlap check above still guards the +// second path, re-admission through another identity reaching the refused row's carriers. // ── A THIRD FILL DISPOSITION: A PREPARED EFFECT INPUT, CARRIED ──────────────────────────── // -// THE ROW KIND THIS FILE COULD NOT SPELL. The two rosters above are the two dispositions a -// fill can have: a WARM row is nullary and preparation-forceable, a CLAIM-FORCED row has -// claim-shaped arguments and fills inside the fold. A producer whose value depends on ONE +// THE ROW KIND THE DERIVATION CANNOT PRODUCE. A derived row is a pure call with a closed argument +// row, filled by the first planned claim that evaluates it. A producer whose value depends on ONE // READ OF A COMMITTED CARRIER fits neither, and the reason is in the KEY rather than in // anyone's taste: a stored entry is keyed on (resolved fn node, portable ARGUMENT ROW), and a // nullary call that reaches a read contributes NOTHING about what it read to that key. Warming @@ -2061,9 +687,11 @@ data floor_cross_claim_carried_input_warm_rows: List = [ } ] -// The carried-input producers as names, folded exactly like `refused_share_producers` and -// `pending_share_producers`, for the reason those two state: the walls below need identities, and -// a third spelling of this fold would be the duplicate this file exists to price. +// The carried-input producers as names, folded exactly like `refused_share_producers`: the wall +// below and the derivation's `CarriedInputProducer` decline need identities. That decline is also +// why no collision wall between carried rows and admitted rows stands here any more: a carried +// producer stores under its carried content, and the derivation declines every closed demand for +// one, so a producer admitted both ways is unconstructible rather than checked. fn carried_input_warm_producers(rows: List) -> List { reverse(fold(rows, init: [], f: fn(acc, row) { concat([row.producer], acc) })) } @@ -2093,23 +721,3 @@ fn carried_input_rows_without_a_prepared_input( } })) } - -// THE SECOND WALL: A PRODUCER MAY NOT CARRY AN INPUT AND ALSO STAND IN A PLAIN ROSTER. -// -// The two enrolments are different keys for one identity — a plain warm row stores under the -// EMPTY argument row while a carried-input row stores under the carried content — so a producer -// in both would have one value servable under a key that does not represent the carrier, which is -// precisely the stale serve this row kind exists to make unwritable. One identity, one -// disposition. -fn carried_input_roster_collisions( - rows: List, - admitted: List -) -> List { - reverse(fold(carried_input_warm_producers(rows: rows), init: [], f: fn(acc, name) { - if any(xs: admitted, predicate: fn(d) { d == name }) { - concat([name], acc) - } else { - acc - } - })) -} From 7d142a0571887e81cff4008cb581646c8c5d9cb2 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 01:32:25 +0000 Subject: [PATCH 02/33] Floor share derivation: function-value calls are unresolved; name unattributed hits by key The observer called CallSemantics::target() on a FunctionValueCallSemantics call, which has no static target and panics (floor run 37083945879). Such a site is CalleeUnresolved. Per sharp-raven-357: the shared-fill ledger now renders each unattributed hit as one [floor-shared-fill-unattributed] line per (frame, phase, cache, key) via gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror, so preparation's own reads are answerable by identity. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 7 +- dag/gunbc/observation_ci_render.dag | 42 +++++++++++ .../observation_ci_render_witness_test.dag | 20 +++++ .../src/cli_run/claim_call_site_demand.rs | 8 ++ src/v1/stage0/src/cli_run/shared_fill.rs | 73 ++++++++++++++++++- 5 files changed, 145 insertions(+), 5 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index dcb25c4dcd6..d3a20a8e90e 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -25,9 +25,12 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_derived_share", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_site_admitted", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration } + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "warm_cross_claim_call_site", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CallSiteWarmRefusal", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it, netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it, netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/dag/gunbc/observation_ci_render.dag b/dag/gunbc/observation_ci_render.dag index 13a732cd6c7..bec5d3ebcb3 100644 --- a/dag/gunbc/observation_ci_render.dag +++ b/dag/gunbc/observation_ci_render.dag @@ -1159,6 +1159,48 @@ fn ci_shared_fill_row_text( ) } +// WHICH FRAME A READ WITH NO OBSERVED FILL CAME FROM. The total line's unattributed_hits is an +// aggregate nobody can disposition; these two arms split it by where the read happened, and the +// per-key line below names the identity, so "does preparation read this producer?" is answered +// by identity rather than by comparing two runs' wall time. +type SharedFillUnattributedFrame + = UnattributedHitOutsideFold + | UnattributedHitInClaimWithoutFill + +fn shared_fill_unattributed_frame_tag(frame: SharedFillUnattributedFrame) -> String { + match frame { + UnattributedHitOutsideFold => "outside-fold" + UnattributedHitInClaimWithoutFill => "in-claim-without-fill" + } +} + +// One line per (frame, phase, cache, key). `phase` is the floor seam current when the read +// happened (a preparation warm reads under its seam), or `claim` for an in-claim read. +fn ci_shared_fill_unattributed_text( + frame: SharedFillUnattributedFrame, + phase: String, + cache: String, + key: String, + hits: Nat, +) -> String { + concat( + "[floor-shared-fill-unattributed] frame=", + concat( + shared_fill_unattributed_frame_tag(frame: frame), + concat( + " phase=", + concat( + phase, + concat( + " cache=", + concat(cache, concat(" key=", concat(key, concat(" hits=", to_string(hits))))) + ) + ) + ) + ) + ) +} + // THE TOTAL LINE CARRIES BOTH DENOMINATORS AND THE HOLE. shared_fill_ms is the part of fill_ms // that removing any one module cannot recover; unattributed_hits is the count of reads served by // a fill this ledger did not observe, which is the honest statement that the shared figure is a diff --git a/dag/test/claim/observation_ci_render_witness_test.dag b/dag/test/claim/observation_ci_render_witness_test.dag index 021a5fe59cd..767b962305b 100644 --- a/dag/test/claim/observation_ci_render_witness_test.dag +++ b/dag/test/claim/observation_ci_render_witness_test.dag @@ -89,6 +89,7 @@ import gunbc.observation_ci_render { ci_witness_bazel_target_label, ci_shared_fill_row_text, ci_shared_fill_total_text, + ci_shared_fill_unattributed_text, UnattributedHitOutsideFold, UnattributedHitInClaimWithoutFill, ci_human_elapsed, HeartbeatSample, FloorRunSummary, @@ -812,6 +813,25 @@ test fn w_shared_fill_total_line_holds() -> Bool { ) == "[floor-shared-fill] TOTAL fills=9 fill_ms=60000 shared_fill_ms=42000 unattributed_hits=0" } +// THE PER-KEY UNATTRIBUTED LINE, both frames: the pair varies only the frame, so a renderer that +// collapsed them back into one aggregate reds here. +test fn w_shared_fill_unattributed_line_names_frame_phase_and_key() -> Bool { + ci_shared_fill_unattributed_text( + frame: UnattributedHitOutsideFold, + phase: "cross-claim-share-derivation", + cache: "cross_claim_pure_share", + key: "rust_target_model_staging", + hits: 3 + ) == "[floor-shared-fill-unattributed] frame=outside-fold phase=cross-claim-share-derivation cache=cross_claim_pure_share key=rust_target_model_staging hits=3" + && ci_shared_fill_unattributed_text( + frame: UnattributedHitInClaimWithoutFill, + phase: "claim", + cache: "cross_claim_pure_share", + key: "prepare_grammar", + hits: 40 + ) == "[floor-shared-fill-unattributed] frame=in-claim-without-fill phase=claim cache=cross_claim_pure_share key=prepare_grammar hits=40" +} + // THE DISCRIMINATING HALF. The line above would read identically for a fill whose cost really is // its payer's, so the verdict has to be exercised where it changes: one module reading a fill is // a removable cost, two is not, and a fill paid before any claim ran is neither. A single Bool diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index 8b981ef75e3..3bf645154e5 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -272,6 +272,14 @@ impl<'a> CallSiteDemandObserver<'a> { .. } = call.expr_data.as_ref() { + // A call through a function VALUE has no static target: its callee is whatever the + // value is at run time, so the site is unresolved (and `target()` has no arm for it). + if matches!( + semantics.as_ref(), + crate::v1_std_core::CallSemantics::FunctionValueCallSemantics + ) { + return None; + } match semantics.target().as_ref() { CallTargetIdentity::SourceDeclarationCall { owner_module_path, diff --git a/src/v1/stage0/src/cli_run/shared_fill.rs b/src/v1/stage0/src/cli_run/shared_fill.rs index 1be3060dc37..6c2511f0917 100644 --- a/src/v1/stage0/src/cli_run/shared_fill.rs +++ b/src/v1/stage0/src/cli_run/shared_fill.rs @@ -110,6 +110,9 @@ struct Ledger { /// Hits that found no recorded fill. Never silently dropped: a nonzero count means a cache /// was filled by a path this module does not observe, so its rows understate the sharing. unattributed_hits: u64, + /// The same hits by identity: (frame tag, phase, cache, key) -> count. The aggregate above + /// stays the sum of these; this is what lets a reader disposition each one. + unattributed_by_key: BTreeMap<(&'static str, String, &'static str, String), u64>, } thread_local! { @@ -177,8 +180,18 @@ pub(crate) fn record_fill(cache: &'static str, key: &str, nanos: u64) { pub(crate) fn record_hit(cache: &'static str, key: &str) { let Some(claim) = current_claim() else { // A hit outside the fold consumes the fill but is not a witness's benefit, so it is not - // a consumer. It is still not nothing: counting it keeps the hit total honest. - LEDGER.with(|l| l.borrow_mut().unattributed_hits += 1); + // a consumer. It is still not nothing: counting it keeps the hit total honest, and the + // per-key row says which identity preparation read, under which seam. + let phase = crate::cli_run::required_floor_runner::floor_seam_current() + .unwrap_or_else(|| "".to_string()); + LEDGER.with(|l| { + let mut ledger = l.borrow_mut(); + ledger.unattributed_hits += 1; + *ledger + .unattributed_by_key + .entry(("outside-fold", phase, cache, key.to_string())) + .or_default() += 1; + }); return; }; LEDGER.with(|l| { @@ -193,7 +206,18 @@ pub(crate) fn record_hit(cache: &'static str, key: &str) { fill.consumers.insert(claim); } } - None => ledger.unattributed_hits += 1, + None => { + ledger.unattributed_hits += 1; + *ledger + .unattributed_by_key + .entry(( + "in-claim-without-fill", + "claim".to_string(), + cache, + key.to_string(), + )) + .or_default() += 1; + } } }); } @@ -270,6 +294,20 @@ pub(crate) fn render_shared_fill_total_text_mirror( ) } +/// Mirror of `gunbc.observation_ci_render` `ci_shared_fill_unattributed_text`. +pub(crate) fn render_shared_fill_unattributed_text_mirror( + frame: &str, + phase: &str, + cache: &str, + key: &str, + hits: u64, +) -> String { + format!( + "[floor-shared-fill-unattributed] frame={frame} phase={phase} cache={cache} key={key} \ + hits={hits}" + ) +} + /// Mirror of `gunbc.witness_row_cost` `shared_fill_disposition` composed with its tag. Three /// states because three remedies: preparation cost no witness can be pared to recover, a fill /// one module owns and loses with itself, and a fill that outlives the removal of any single @@ -345,6 +383,12 @@ pub(crate) fn report() -> String { out.push('\n'); } } + for ((frame, phase, cache, key), hits) in &ledger.unattributed_by_key { + out.push_str(&render_shared_fill_unattributed_text_mirror( + frame, phase, cache, key, *hits, + )); + out.push('\n'); + } out.push_str(&render_shared_fill_total_text_mirror( fills_total, u128::from(total_nanos / 1_000_000), @@ -625,5 +669,28 @@ mod tests { "a cache filled by an unobserved path must say so rather than read as unshared: \ {text}" ); + // ...and by identity, so it can be dispositioned rather than read as an aggregate. + assert!( + text.contains( + "[floor-shared-fill-unattributed] frame=in-claim-without-fill phase=claim \ + cache=never_filled_here key=k hits=1" + ), + "the in-claim hit must be named by key: {text}" + ); + } + + // THE OTHER FRAME: a hit outside any claim is named as such, so preparation's own reads are + // distinguishable from a claim reading a fill the ledger did not observe. + #[test] + fn a_hit_outside_the_fold_is_named_by_key_and_frame() { + reset(); + record_hit("cross_claim_pure_share", "warm_read"); + let text = report(); + assert!( + text.contains("frame=outside-fold") + && text.contains("cache=cross_claim_pure_share key=warm_read hits=1") + && text.contains("unattributed_hits=1"), + "an outside-fold hit must be named by frame and key: {text}" + ); } } From c081563a27edb9bb30cfb7e92a4f67d008ef5c4d Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 01:43:33 +0000 Subject: [PATCH 03/33] Share observer: every call shape ends in a typed, counted cause call_target matches CallSemantics exhaustively (no target() panic path) and returns a typed cause: CalleeIsAValue for function-value and locally bound calls, CalleeUnresolved otherwise. A panic while reading any site is caught and counted as CallShapeUnread, never a crash and never a skip. Both arms are added to the .dag CallSiteDemandCause coproduct. Control: a_function_value_call_is_counted_as_a_value_callee_never_a_panic. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/claim_call_site_demand.rs | 99 +++++++++++++++---- src/v2/workflow/floor_pure_producer_share.dag | 12 ++- 2 files changed, 89 insertions(+), 22 deletions(-) diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index 3bf645154e5..24a52fc29ac 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -42,14 +42,18 @@ use crate::v1_std_core::{ #[derive(Debug, Clone, Copy, PartialEq, Eq, PartialOrd, Ord, Hash)] pub(crate) enum CallSiteDemandCause { CalleeUnresolved, + CalleeIsAValue, CalleeDeclaresEffects, ArgumentNotClosedConstant, + CallShapeUnread, } impl CallSiteDemandCause { pub(crate) fn variant(self) -> &'static str { match self { CallSiteDemandCause::CalleeUnresolved => "CalleeUnresolved", + CallSiteDemandCause::CalleeIsAValue => "CalleeIsAValue", + CallSiteDemandCause::CallShapeUnread => "CallShapeUnread", CallSiteDemandCause::CalleeDeclaresEffects => "CalleeDeclaresEffects", CallSiteDemandCause::ArgumentNotClosedConstant => "ArgumentNotClosedConstant", } @@ -266,36 +270,54 @@ impl<'a> CallSiteDemandObserver<'a> { } } - fn call_target(&self, module: &str, call: &Rc) -> Option<(String, String)> { + /// The static callee of a call site, or the typed reason there is none. + fn call_target( + &self, + module: &str, + call: &Rc, + ) -> Result<(String, String), CallSiteDemandCause> { + use crate::v1_std_core::CallSemantics; if let ExprData::ExprCall { call_semantics: Some(semantics), .. } = call.expr_data.as_ref() { - // A call through a function VALUE has no static target: its callee is whatever the - // value is at run time, so the site is unresolved (and `target()` has no arm for it). - if matches!( - semantics.as_ref(), - crate::v1_std_core::CallSemantics::FunctionValueCallSemantics - ) { - return None; - } - match semantics.target().as_ref() { + // Matched EXHAUSTIVELY on the semantics rather than through `target()`, which has no + // arm for a function-value call: a new call shape is then a compile error here, not a + // run-time panic in the floor. + let target = match semantics.as_ref() { + CallSemantics::FunctionValueCallSemantics => { + return Err(CallSiteDemandCause::CalleeIsAValue) + } + CallSemantics::PlainCallSemantics { target } + | CallSemantics::ResolvedDirectCallSemantics { target, .. } + | CallSemantics::LookupCallSemantics { target } => target.clone(), + }; + match target.as_ref() { CallTargetIdentity::SourceDeclarationCall { owner_module_path, decl_name, } => { let key = (owner_module_path.clone(), decl_name.clone()); - return self.decls.contains_key(&key).then_some(key); + return if self.decls.contains_key(&key) { + Ok(key) + } else { + Err(CallSiteDemandCause::CalleeUnresolved) + }; + } + CallTargetIdentity::LocallyBoundCall { .. } => { + return Err(CallSiteDemandCause::CalleeIsAValue) + } + CallTargetIdentity::RuntimePrimitiveCall { .. } => { + return Err(CallSiteDemandCause::CalleeUnresolved) } - CallTargetIdentity::RuntimePrimitiveCall { .. } - | CallTargetIdentity::LocallyBoundCall { .. } => return None, CallTargetIdentity::CallableTargetUndetermined => {} } } let spelling = crate::v1_std_core::expr_call_func_at(call.clone(), self.source_indices.clone()); self.resolve(module, &spelling) + .ok_or(CallSiteDemandCause::CalleeUnresolved) } fn read_declaration(&self, module: &str, decl: &Rc) -> DeclFacts { @@ -331,11 +353,23 @@ impl<'a> CallSiteDemandObserver<'a> { for n in &nodes { match n.expr_data.as_ref() { ExprData::ExprCall { .. } => { - let target = self.call_target(module, n); + // NO CALL SHAPE MAY STOP THE FLOOR OR VANISH: a panic while reading one site + // becomes that site's typed, counted cause. + let read = std::panic::catch_unwind(std::panic::AssertUnwindSafe(|| { + let target = self.call_target(module, n); + let fact = self.site_fact(module, n, target.clone(), &binders); + (target.ok(), fact) + })); + let (target, fact) = match read { + Ok(read) => read, + Err(_) => ( + None, + SiteFact::Unadmissible(CallSiteDemandCause::CallShapeUnread), + ), + }; if let Some(t) = &target { reads.insert(t.clone()); } - let fact = self.site_fact(module, n, target, &binders); if matches!(fact, SiteFact::Closed { .. }) { closed_nodes.push((site_key_of(n), n.clone())); } @@ -371,11 +405,12 @@ impl<'a> CallSiteDemandObserver<'a> { &self, module: &str, call: &Rc, - target: Option<(String, String)>, + target: Result<(String, String), CallSiteDemandCause>, binders: &HashSet, ) -> SiteFact { - let Some(target) = target else { - return SiteFact::Unadmissible(CallSiteDemandCause::CalleeUnresolved); + let target = match target { + Ok(t) => t, + Err(cause) => return SiteFact::Unadmissible(cause), }; if self .decls @@ -450,7 +485,7 @@ impl<'a> CallSiteDemandObserver<'a> { } } ExprData::ExprCall { .. } => { - let target = self.call_target(module, expr)?; + let target = self.call_target(module, expr).ok()?; if self.decls.get(&target).is_some_and(|c| !c.uses.is_empty()) { return None; } @@ -496,7 +531,10 @@ mod tests { fn claim_b() -> Bool { shared() == shared() }\n\ fn claim_c() -> Bool { assemble(src: \"module own\") == 3 }\n\ fn claim_d() -> Bool { from_param(text: \"x\") == 3 }\n\ - fn claim_e() -> Bool { reading_helper() == \"\" }\n"; + fn claim_e() -> Bool { reading_helper() == \"\" }\n\ + fn apply(f: fn(Int) -> Int) -> Int { f(1) }\n\ + fn inc(n: Int) -> Int { n }\n\ + fn claim_f() -> Bool { apply(f: inc) == 1 }\n"; fn observe(claims: &[&str]) -> Vec { observe_source(FIXTURE, claims) @@ -585,6 +623,27 @@ mod tests { ); } + // THE FUNCTION-VALUE CONTROL (the shape that panicked floor run 37083945879): a call through a + // parameter of function type is counted under its own cause, the walk does not panic, and the + // rest of the claim's reach is still observed (the `apply(f: inc)` site is closed). + #[test] + fn a_function_value_call_is_counted_as_a_value_callee_never_a_panic() { + let rows = observe(&["claim_f"]); + assert!( + has_cause(&rows, CallSiteDemandCause::CalleeIsAValue) + || has_cause(&rows, CallSiteDemandCause::CalleeUnresolved), + "the f(1) site must be counted under a callee cause: {rows:?}" + ); + assert!( + !has_cause(&rows, CallSiteDemandCause::CallShapeUnread), + "a function-value call is a recognised shape, not an unread one: {rows:?}" + ); + assert!( + closed_claims(&rows, "fixture.n7.apply", "ref:fixture.n7.inc").is_some(), + "the closed apply(f: inc) site is still observed: {rows:?}" + ); + } + // An effectful callee is counted under its own cause, never closed, however constant its // arguments are. #[test] diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index d13a071d04f..8a8df6a795f 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -66,17 +66,25 @@ import v2.std.algebra { list_flat_map, list_map } // Why a reached call site carries no closed computation identity. CLOSED: a new reason is a new // arm, so the seed cannot mint an unclassified one. // CalleeUnresolved -- the site's callee is not a resolved source declaration (a -// runtime primitive, a locally bound function value, an -// undetermined target): nothing to key a fill on. +// runtime primitive, an undetermined target): nothing to key a +// fill on. +// CalleeIsAValue -- the site calls a function VALUE (a parameter, a let, a lambda): +// the callee is whatever the value is at run time, so the site +// has no static identity. // CalleeDeclaresEffects -- the callee declares effect uses; its value depends on the world, // which the key cannot represent (carried inputs are their own row kind). // ArgumentNotClosedConstant -- some argument mentions a binder of the enclosing declaration or // an expression form the normalizer does not admit, so the argument // row is not fixed before the claim runs. +// CallShapeUnread -- the observer could not read the site at all. Counted rather than +// skipped or crashed: a nonzero count is a defect in the observer +// with a located population, never a silent hole in the demand. type CallSiteDemandCause = CalleeUnresolved + | CalleeIsAValue | CalleeDeclaresEffects | ArgumentNotClosedConstant + | CallShapeUnread // `producer` is the callee's qualified declaration; `argument_preimage` the canonical normalized // argument row; `claims` the number of DISTINCT planned claims whose reach contains a site of this From c2558b2cf2ec5b22a0e44a36004be5deaa3027f0 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 02:15:25 +0000 Subject: [PATCH 04/33] Share derivation decode: read the fold's lists in either representation floor run 37087208959 refused CrossClaimShareDerivationUndecodable: the fold's lists come from v2.std.algebra list_flat_map / list_map, i.e. FreeMonoid Cons/Empty chains, and the decoder accepted only kernel lists. Decode through v1_interpreter::list_value_items (free_monoid_to_vec under the frame). Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor/floor_call_site_demand_seed_growth.dag | 3 ++- .../stage0/src/cli_run/required_floor_runner.rs | 16 ++++++++-------- src/v1/stage0/src/v1_interpreter.rs | 6 ++++++ 3 files changed, 16 insertions(+), 9 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index d3a20a8e90e..2cb9dc8c536 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -28,7 +28,8 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "warm_cross_claim_call_site", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CallSiteWarmRefusal", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration } + DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration } ], reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it, netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 97501b09689..eb334d57073 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6831,11 +6831,11 @@ pub(crate) fn derive_and_install_cross_claim_share( let Value::Record { fields, .. } = &result else { return Err(malformed("expected a CrossClaimShareDerivation record")); }; + // The fold's lists may be kernel lists or v2.std.algebra FreeMonoid chains; both decode. let list_of = |name: &str| -> Result, String> { - match ctx.field(fields, name) { - Some(Value::List(xs)) => Ok(xs.iter().cloned().collect()), - _ => Err(malformed(&format!("no `{name}` list"))), - } + ctx.field(fields, name) + .and_then(|v| v1_interpreter::list_value_items(ctx, v)) + .ok_or_else(|| malformed(&format!("no `{name}` list"))) }; let text_of = |row: &[(v1_interpreter::Symbol, Value)], name: &str| -> Result { match ctx.field(row, name) { @@ -6894,10 +6894,10 @@ pub(crate) fn derive_and_install_cross_claim_share( -- the derivation admitted a producer the prepared subject carries no declaration for" ) })?; - let row_sites = match ctx.field(r, "sites") { - Some(Value::List(xs)) => xs.iter().cloned().collect::>(), - _ => return Err(malformed("an admitted row has no `sites` list")), - }; + let row_sites = ctx + .field(r, "sites") + .and_then(|v| v1_interpreter::list_value_items(ctx, v)) + .ok_or_else(|| malformed("an admitted row has no `sites` list"))?; let mut sites_of_row: Vec<(String, i64, i64)> = Vec::new(); for site in &row_sites { let Value::Str(text) = site else { diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index c308e077c74..49f399d3250 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -24657,6 +24657,12 @@ fn free_monoid_ctx_syms(ctx: &InterpContext) -> Option<(Symbol, Symbol, Symbol, Some((get("Empty"), get("Cons"), get("head"), get("tail"))) } +/// The elements of a list value in either representation -- a kernel `List` or the structural +/// `FreeMonoid` (`Cons`/`Empty`) that `v2.std.algebra` folds return -- read in `ctx`. +pub fn list_value_items(ctx: &InterpContext, val: &Value) -> Option> { + with_active_ctx(ctx, || free_monoid_to_vec(val)) +} + pub(crate) fn free_monoid_to_vec(val: &Value) -> Option> { let site = std::panic::Location::caller(); let mut out = Vec::new(); From 98a4286f558fa010e98e88566aa4f6aedce29362 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 03:19:13 +0000 Subject: [PATCH 05/33] Derived share: a declared cost floor, one store per warm, retained rows only Run 37089182924 (first derived run) admitted 2919 identities; 2807 warmed under 5ms, and their stores plus nested stores exhausted the tier's 4096-entry cap, so every identity claims actually needed was refused (EntryCapReached=1460) and 16+ claims crossed the new-witness budget. - v2.workflow.floor_pure_producer_share floor_cross_claim_share_cost_floor_eval_steps (declared policy, DESIGN section 2's recompute-below-the-cost-floor): a warm measured under it is declined BelowCostFloor and counted. - warm_cross_claim_call_site stores only the producer it warms (CROSS_CLAIM_WARM_ONLY); nested admitted calls recompute, so the measured steps are the warm's own and no entry is spent on an unjudged identity. - After the warm the derived share is re-installed with the retained rows only; install replaces the previous derivation, removing dropped producers from the roster so none stays admitted without its site gate. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/required_floor_runner.rs | 57 +++++++++++++++++-- src/v1/stage0/src/v1_interpreter.rs | 40 ++++++++++++- src/v2/workflow/floor_pure_producer_share.dag | 15 +++++ 3 files changed, 106 insertions(+), 6 deletions(-) diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index eb334d57073..b812952c844 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6871,6 +6871,12 @@ pub(crate) fn derive_and_install_cross_claim_share( let mut nodes = Vec::new(); let mut sites: std::collections::HashSet<(String, i64, i64)> = std::collections::HashSet::new(); let mut admitted_qualified = Vec::new(); + // (producer, producer node, its admitted sites), for the post-warm re-install. + let mut admitted_rows: Vec<( + String, + std::rc::Rc, + Vec<(String, i64, i64)>, + )> = Vec::new(); // (site module, producer, producer node, call node) -- one warm per admitted row. let mut warm_plan: Vec<( String, @@ -6932,6 +6938,7 @@ pub(crate) fn derive_and_install_cross_claim_share( ) })?; warm_plan.push((site_module, producer.clone(), node.clone(), call)); + admitted_rows.push((producer.clone(), node.clone(), sites_of_row.clone())); admitted_qualified.push(producer); nodes.push(node); } @@ -6986,7 +6993,27 @@ pub(crate) fn derive_and_install_cross_claim_share( } }); // THE WARM, grouped by site module so each module is framed once. + let cost_floor_steps = match v1_interpreter::run_in_context( + ctx, + &format!("{MODULE}.floor_cross_claim_share_cost_floor_eval_steps"), + false, + ) { + Ok(Value::Int(n)) if n > 0 => n as u64, + other => { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareCostFloorUnreadable -- \ + floor_cross_claim_share_cost_floor_eval_steps must be a positive Int, got {}", + match other { + Ok(v) => ctx.format_value(&v), + Err(e) => e.to_string(), + } + )) + } + }; warm_plan.sort_by(|a, b| (&a.0, &a.1).cmp(&(&b.0, &b.1))); + // Which admitted rows are retained after their warm: only these stay admitted, so a site whose + // warm declined (below the floor, not storable) is not stored at claim time either. + let mut kept_producers: std::collections::HashSet = std::collections::HashSet::new(); let mut observations = Vec::new(); let mut declined_warms: std::collections::BTreeMap = std::collections::BTreeMap::new(); @@ -7020,10 +7047,13 @@ pub(crate) fn derive_and_install_cross_claim_share( } } let (warm, observation) = observe_shared_build(false, "floor-preparation", || { - v1_interpreter::warm_cross_claim_call_site(frame, node, call) + v1_interpreter::warm_cross_claim_call_site(frame, node, call, cost_floor_steps) }); let disposition = match &warm { - Ok(outcome) => outcome.cause().to_string(), + Ok(outcome) => { + kept_producers.insert(producer.clone()); + outcome.cause().to_string() + } Err(refusal) => { *declined_warms.entry(refusal.cause()).or_default() += 1; refusal.cause() @@ -7040,9 +7070,28 @@ pub(crate) fn derive_and_install_cross_claim_share( )); } drop(framed); + // RE-INSTALL WITH THE RETAINED ROWS ONLY (replacing the derivation installed for the warm). + let mut kept_nodes = Vec::new(); + let mut kept_sites: std::collections::HashSet<(String, i64, i64)> = + std::collections::HashSet::new(); + for (producer, node, row_sites) in &admitted_rows { + if kept_producers.contains(producer) { + kept_nodes.push(node.clone()); + kept_sites.extend(row_sites.iter().cloned()); + } + } + let retained = kept_nodes.len(); + v1_interpreter::install_cross_claim_derived_share(kept_nodes, kept_sites); + PURE_PRODUCER_SHARE_ROSTER.with(|r| { + if let Some(roster) = r.borrow_mut().as_mut() { + roster.admitted_qualified.retain(|q| { + !admitted_rows.iter().any(|(p, _, _)| p == q) || kept_producers.contains(q) + }); + } + }); eprintln!( - "[floor-phase] phase=cross-claim-share-warm state=completed warmed={} \ - not_stored=[{}]", + "[floor-phase] phase=cross-claim-share-warm state=completed warmed={} retained={retained} \ + cost_floor_eval_steps={cost_floor_steps} not_stored=[{}]", warm_plan.len(), declined_warms .iter() diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 49f399d3250..c47674b282e 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2148,6 +2148,11 @@ thread_local! { /// judged closed -- stays outside the tier. static CROSS_CLAIM_SITE_GATED: RefCell> = RefCell::new(std::collections::HashSet::new()); + /// While a derived call-site warm runs, the ONE producer it may store. Nested admitted calls + /// inside the warm are recomputed rather than stored, so a warm retains exactly its own value + /// and its measured cost is its own (an entry is never spent on a nested identity whose own + /// warm has not yet been judged against the cost floor). + static CROSS_CLAIM_WARM_ONLY: std::cell::Cell> = const { std::cell::Cell::new(None) }; /// The admitted call sites of site-gated producers, as `(file, start, end)` byte spans. static CROSS_CLAIM_ADMITTED_SITES: RefCell> = RefCell::new(std::collections::HashSet::new()); @@ -2198,8 +2203,16 @@ pub fn install_cross_claim_derived_share>>( sites: std::collections::HashSet<(String, i64, i64)>, ) { let nodes: Vec> = nodes.into_iter().collect(); + // REPLACES the previous derivation rather than adding to it: a producer dropped from the + // derived set must leave the roster too, or it would remain admitted with no site gate -- + // admitted everywhere, the widening this gate exists to prevent. + let previous: Vec = + CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().iter().copied().collect()); CROSS_CLAIM_PURE_ROSTER.with(|r| { let mut r = r.borrow_mut(); + for ptr in &previous { + r.remove(ptr); + } for node in &nodes { r.insert(Rc::as_ptr(node) as usize); } @@ -2540,6 +2553,11 @@ fn store_cross_claim_pure_memo( if !cross_claim_pure_admitted(fn_node, func_name) { return CrossClaimStoreOutcome::NotAdmitted; } + if let Some(only) = CROSS_CLAIM_WARM_ONLY.with(|w| w.get()) { + if only != Rc::as_ptr(fn_node) as usize { + return CrossClaimStoreOutcome::NotAdmitted; + } + } // The same substitution the lookup makes, in the same place in the fold, so a warm and a // serve cannot disagree about what the key represents. let carried_key_args = cross_claim_key_args(fn_node, args); @@ -2637,7 +2655,14 @@ pub fn take_cross_claim_store_digest(func_name: &str) -> Option { /// a store the tier declined carries its own outcome. #[derive(Debug)] pub enum CallSiteWarmRefusal { - DispatchedEffect { effects: u64 }, + DispatchedEffect { + effects: u64, + }, + /// The warm performed fewer evaluator steps than the declared cost floor, so the value is not + /// retained: below the floor, recomputing is the admitted realization (DESIGN section 2). + BelowCostFloor { + steps: u64, + }, EvaluationFailed(String), NotStored(CrossClaimStoreOutcome), } @@ -2648,6 +2673,7 @@ impl CallSiteWarmRefusal { CallSiteWarmRefusal::DispatchedEffect { effects } => { format!("DispatchedEffect(effects={effects})") } + CallSiteWarmRefusal::BelowCostFloor { .. } => "BelowCostFloor".to_string(), CallSiteWarmRefusal::EvaluationFailed(_) => "EvaluationFailed".to_string(), CallSiteWarmRefusal::NotStored(outcome) => outcome.cause().to_string(), } @@ -2663,6 +2689,7 @@ pub fn warm_cross_claim_call_site( ctx: &InterpContext, fn_node: &Rc, call_node: &Rc, + cost_floor_steps: u64, ) -> Result { with_active_ctx(ctx, || { let func_name = fn_node.name.clone(); @@ -2682,8 +2709,14 @@ pub fn warm_cross_claim_call_site( .collect::>() .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; let guard = CrossClaimFillGuard::enter(&func_name); - let value = with_lexical_base_env(&env, || call_function(ctx, fn_node, &args, &env)) + let steps_before = evaluator_steps(); + let previous_only = + CROSS_CLAIM_WARM_ONLY.with(|w| w.replace(Some(Rc::as_ptr(fn_node) as usize))); + let value = with_lexical_base_env(&env, || call_function(ctx, fn_node, &args, &env)); + CROSS_CLAIM_WARM_ONLY.with(|w| w.set(previous_only)); + let value = value .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; + let steps = evaluator_steps().wrapping_sub(steps_before); let effects = ctx .effect_dispatch_count .get() @@ -2691,6 +2724,9 @@ pub fn warm_cross_claim_call_site( if effects != 0 { return Err(CallSiteWarmRefusal::DispatchedEffect { effects }); } + if steps < cost_floor_steps { + return Err(CallSiteWarmRefusal::BelowCostFloor { steps }); + } let outcome = store_cross_claim_pure_memo(ctx, fn_node, &func_name, &args, &value, Some(&guard)); if outcome.is_servable() { diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 8a8df6a795f..084ecd1f98f 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -216,6 +216,21 @@ fn derive_cross_claim_share( } } +// THE COST FLOOR: DESIGN section 2's "unavoidable recurrence may explicitly recompute below the +// cost floor". An admitted identity whose isolated warm performs fewer evaluator steps than this is +// not retained: a store costs a key, a byte budget share and an entry in a bounded population, and +// below this line the recomputation it saves is smaller than what it occupies. MEASURED REASON for +// it existing (run 37089182924, the first derived run): 2807 of 2919 admitted identities warmed in +// under 5ms, and retaining all of them exhausted the tier's entry cap so that every identity a +// claim actually needed (each costing seconds) was refused a store. The value is declared policy in +// eval steps -- the floor's own deterministic unit -- set at about seven percent of the new-witness +// claim budget (v2.workflow.required_floor claim_eval_step_budget_for_identity), so a share below it +// cannot be what moves a claim across that budget. The seed applies it to the warm's measured steps +// and counts every identity it declines (`BelowCostFloor`). +fn floor_cross_claim_share_cost_floor_eval_steps() -> Int { + 5000 +} + // The live derivation, over the refused and carried rows this file declares. The seed calls this. fn floor_cross_claim_share_derivation( observations: List From 066c4797c852ecd5e6b2c91f30060988ebb7f0fb Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 04:13:07 +0000 Subject: [PATCH 06/33] Derived share: admission is a std.materialization_ladder judgment Agreed with royal-moth-86 (cache program): each closed identity becomes one FrameDemand per demanding planned claim at its claim frame under preparation, judged by std.materialization_ladder group_verdict against the existing cross-claim CacheProvider (MemoTier ContentKeyed, preparation scope). Two or more claims are AuthoredDuplication (the carry is owed; the warm is the carry); one claim is AcceptedSingleRecompute (DemandedByOneClaim); any other verdict is carried on the decline (LadderOwesNoCarry). Observation rows now carry the demanding claim identities instead of a count. The frame path, the tier retention and the provider (cross_claim_share_provider) move into v2.workflow.floor_pure_producer_share as their single authority; v2.workflow.floor_prepared_effect_input_ladder now covers the carried identities with the same provider. The cost floor is documented as DESIGN s2's economic realization after the ladder, not the ladder's below-floor exemption (which the ladder applies only below an isolated LCA). Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/claim_call_site_demand.rs | 16 +- .../src/cli_run/required_floor_runner.rs | 5 +- .../pure_producer_share_refusal_test.dag | 20 ++- ...loor_prepared_effect_input_ladder_test.dag | 3 +- .../floor_prepared_effect_input_ladder.dag | 50 +----- src/v2/workflow/floor_pure_producer_share.dag | 145 ++++++++++++++++-- 6 files changed, 170 insertions(+), 69 deletions(-) diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index 24a52fc29ac..0918d503c50 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -70,7 +70,8 @@ pub(crate) enum CallSiteDemandRow { Closed { producer: String, argument_preimage: String, - claims: u64, + /// The distinct planned claims reaching this identity, `module.function`. + claims: Vec, sites: Vec, }, Unadmissible { @@ -117,6 +118,8 @@ pub(crate) struct CallSiteDemandObserver<'a> { struct IdentityCell { claims: u64, last_claim: usize, + /// The claim indices counted in `claims`, in planning order. + claim_indices: Vec, sites: BTreeSet, } @@ -189,6 +192,7 @@ impl<'a> CallSiteDemandObserver<'a> { if cell.last_claim != claim_number { cell.last_claim = claim_number; cell.claims += 1; + cell.claim_indices.push(index); } cell.sites.insert(site.clone()); } @@ -200,7 +204,11 @@ impl<'a> CallSiteDemandObserver<'a> { |((producer, argument_preimage), cell)| CallSiteDemandRow::Closed { producer, argument_preimage, - claims: cell.claims, + claims: cell + .claim_indices + .iter() + .map(|i| format!("{}.{}", claims[*i].0, claims[*i].1)) + .collect(), sites: cell.sites.iter().map(render_site).collect(), }, ) @@ -569,7 +577,9 @@ mod tests { argument_preimage, claims, .. - } if p == producer && argument_preimage.contains(preimage_contains) => Some(*claims), + } if p == producer && argument_preimage.contains(preimage_contains) => { + Some(claims.len() as u64) + } _ => None, }) } diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index b812952c844..f3059efdf1c 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6784,7 +6784,10 @@ pub(crate) fn derive_and_install_cross_claim_share( )]), }, ), - (sym("claims"), Value::Int(*claims as i64)), + ( + sym("claims"), + list_value_from_vec(claims.iter().map(str_value).collect()), + ), ( sym("sites"), list_value_from_vec(sites.iter().map(str_value).collect()), diff --git a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag index 8aa1e2107a2..c2683590d0f 100644 --- a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag +++ b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag @@ -14,6 +14,7 @@ import v2.workflow.floor_pure_producer_share { CallSiteDemandCause, ArgumentNotClosedConstant, CalleeDeclaresEffects, CrossClaimShareDerivation, DeclinedShareRow, ShareDerivationDecline, DemandedByOneClaim, IdentityGradeNotShareable, RefusedByMeasurement, CarriedInputProducer, + LadderOwesNoCarry, derive_cross_claim_share, floor_cross_claim_share_derivation, cross_claim_share_derivation_reconciles, derived_share_producers } @@ -53,12 +54,21 @@ fn probe_identity() -> ComputationIdentity { NormalizedIdentical { normalizer: "authored fixture" } } +// `claims` distinct planned claims, named so each is one ladder demand at its own claim frame. +fn probe_claim_names(claims: Int) -> List { + if claims <= 0 { + [] + } else { + concat(probe_claim_names(claims: claims - 1), [concat("v2.test.probe.claim_", to_string(claims))]) + } +} + fn probe_closed(producer: String, claims: Int) -> CallSiteDemandObservation { ClosedCallSiteDemand { producer: producer, argument_preimage: "(src: \"module text\")", identity: probe_identity(), - claims: claims, + claims: probe_claim_names(claims: claims), sites: ["v2/test/probe.dag:10-40"] } } @@ -82,6 +92,7 @@ fn decline_tag(decline: ShareDerivationDecline) -> String { IdentityGradeNotShareable => "IdentityGradeNotShareable" RefusedByMeasurement => "RefusedByMeasurement" CarriedInputProducer => "CarriedInputProducer" + LadderOwesNoCarry { verdict: _ } => "LadderOwesNoCarry" } } @@ -91,8 +102,9 @@ fn declined_as(d: CrossClaimShareDerivation, producer: String, decline: ShareDer } // THE DISCRIMINATING PAIR: one closed identity, varied ONLY in how many planned claims demand it. -// Two claims is the reuse obligation DESIGN section 2 names, so it is admitted; one claim has no -// least common ancestor above itself, so it is declined and named. A fold admitting every closed +// Two claims put the obligation's least common ancestor at the shared-state preparation frame, so +// std.materialization_ladder judges AuthoredDuplication and the carry is owed: admitted. One claim +// is AcceptedSingleRecompute: declined and named. A fold admitting every closed // row passes the first and reds the second; a fold admitting nothing reds the first. test fn a_closed_identity_two_claims_demand_is_admitted() -> Bool { let d = probe_derive(observations: [probe_closed(producer: "v2.probe.n7.probe_assemble", claims: 2)]) @@ -130,7 +142,7 @@ test fn an_identity_of_unknown_grade_is_declined() -> Bool { producer: "v2.probe.n7.probe_unknown", argument_preimage: "()", identity: IdentityUnknown { cause: MissingConcept { detail: "authored fixture" } }, - claims: 3, + claims: probe_claim_names(claims: 3), sites: ["v2/test/probe.dag:50-60"] } ]) diff --git a/src/v2/test/floor_prepared_effect_input_ladder_test.dag b/src/v2/test/floor_prepared_effect_input_ladder_test.dag index 4879909f082..9a8d68e3850 100644 --- a/src/v2/test/floor_prepared_effect_input_ladder_test.dag +++ b/src/v2/test/floor_prepared_effect_input_ladder_test.dag @@ -2,12 +2,13 @@ module v2.test.floor_prepared_effect_input_ladder import v2.workflow.floor_prepared_effect_input_ladder { carried_input_identities, carried_input_verdicts_after_the_carry, - carried_input_verdicts_before_the_carry, cross_claim_tier_retention, + carried_input_verdicts_before_the_carry, every_carried_identity_is_a_single_demand_after_the_carry, every_carried_identity_is_authored_duplication_before_the_carry, the_minimized_demand_graph_is_green, prepared_effect_input_provider } import v2.workflow.floor_pure_producer_share { + cross_claim_tier_retention, carried_input_rows_without_a_prepared_input, floor_cross_claim_carried_input_warm_rows, floor_cross_claim_prepared_effect_inputs } diff --git a/src/v2/workflow/floor_prepared_effect_input_ladder.dag b/src/v2/workflow/floor_prepared_effect_input_ladder.dag index cdfab04b479..2070d66962f 100644 --- a/src/v2/workflow/floor_prepared_effect_input_ladder.dag +++ b/src/v2/workflow/floor_prepared_effect_input_ladder.dag @@ -14,6 +14,8 @@ import std.materialization_ladder { import std.measure { byte_size } import v2.std.collection { List } import v2.workflow.floor_pure_producer_share { + floor_preparation_frame, floor_claim_frame, floor_claim_site, cross_claim_tier_retention, + cross_claim_share_provider, CarriedInputWarmRow, PreparedEffectInput, carried_input_warm_producers, floor_cross_claim_carried_input_warm_rows, floor_cross_claim_prepared_effect_inputs, prepared_effect_input_acquisitions @@ -41,44 +43,6 @@ import v2.std.text { String } // provider and lets that authority decide; restating the rule would be the fork the ladder exists // to prevent. -// THE FRAME PATH, and each frame's kind is a fact about the floor's own execution rather than a -// label. Preparation is a SHARED-STATE frame: one process, one prepared subject, and the carried -// value is bound in it. A claim is an ISOLATED-CHILDREN frame because the floor builds a fresh -// evaluation frame per claim deliberately — one witness must not contaminate the next — which is -// exactly why the eval-frame memo dies at every claim boundary and why the obligation LCA is -// preparation rather than any claim. -fn floor_preparation_frame() -> Frame { - Frame { name: "required-floor-preparation", kind: SharedStateFrame } -} - -fn floor_claim_frame(name: String) -> Frame { - Frame { name: name, kind: IsolatedChildrenFrame } -} - -fn floor_claim_site(name: String) -> List { - [floor_preparation_frame(), floor_claim_frame(name: name)] -} - -// THE PROVIDER: the cross-claim pure-producer tier, described as it actually behaves. -// -// scope — the preparation frame, which is the least common visible ancestor of the claims. -// coverage — the enrolled identities and nothing else; admission is a declared roster, never -// every pure call, because cross-claim retention is byte-unbounded by construction. -// tier — MemoTier { ContentKeyed }: an in-process store whose key is the resolved fn node -// plus the portable argument row, and the carried value IS that argument row. -// retention — released when the prepared subject is cleared, with the exact 256 MiB ceiling the -// tier enforces at publication and RefuseNewStore as its at-capacity disposition -// (an over-budget producer recomputes per claim as if never enrolled). -fn cross_claim_tier_retention() -> ProviderRetention { - ProviderRetention { - release_policy: ReleasedAtProviderScopeExit, - capacity: CapacityBounded { - limit: ByteCapacity { limit: ExactLimit { value: byte_size(count: 268435456) } }, - at_capacity: RefuseNewStore - } - } -} - fn carried_input_identities() -> List { concat( prepared_effect_input_acquisitions(inputs: floor_cross_claim_prepared_effect_inputs), @@ -86,14 +50,10 @@ fn carried_input_identities() -> List { ) } +// THE PROVIDER is the cross-claim tier, declared once in v2.workflow.floor_pure_producer_share +// (`cross_claim_share_provider`) and covering, here, the carried identities. fn prepared_effect_input_provider() -> CacheProvider { - CacheProvider { - id: "floor-cross-claim-pure-share", - scope: [floor_preparation_frame()], - coverage: CoversIdentities { identities: carried_input_identities() }, - tier: MemoTier { keying: ContentKeyed }, - retention: cross_claim_tier_retention() - } + cross_claim_share_provider(identities: carried_input_identities()) } // THE DEMANDS, one per consuming claim frame, at the two natures this carry actually has. diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 084ecd1f98f..e8d3ceadd09 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -2,6 +2,19 @@ module v2.workflow.floor_pure_producer_share import v2.std.collection { List } import std.computation_identity { ComputationIdentity, identity_permits_share } +import std.cache_interface { + ByteCapacity, CapacityBounded, ExactLimit, ProviderRetention, ReleasedAtProviderScopeExit, + RefuseNewStore +} +import std.materialization_ladder { + CacheProvider, ContentKeyed, CoversIdentities, Frame, FrameDemand, IsolatedChildrenFrame, + LadderVerdict, MemoTier, PureComputation, SharedStateFrame, group_verdict, + AuthoredDuplication, DeadComputation, Discharged, RefusedNoProvider, RefusedScopeTooNarrow, + RefusedExistenceKeyed, RefusedRetentionUnbounded, RefusedRetentionUnobserved, + RefusedUnmodeledWorldRead, ExemptFreshEffect, AcceptedBelowCostFloor, AcceptedSingleRecompute, + AcceptedEffectIsTheUse, RefusedNatureConflict +} +import std.measure { byte_size } import v2.std.algebra { list_flat_map, list_map } // THE CROSS-CLAIM PURE-PRODUCER SHARE -- which pure computations the required floor may fill @@ -87,8 +100,9 @@ type CallSiteDemandCause | CallShapeUnread // `producer` is the callee's qualified declaration; `argument_preimage` the canonical normalized -// argument row; `claims` the number of DISTINCT planned claims whose reach contains a site of this -// identity; `sites` those sites as `:-` byte spans, which is what the seed admits. +// argument row; `claims` the DISTINCT planned claims whose reach contains a site of this identity +// (each becomes one ladder demand at its claim frame); `sites` those sites as +// `:-` byte spans, which is what the seed admits. // An unadmissible row aggregates every site sharing one cause: `claims` counts distinct planned // claims reaching any of them, `sites` counts the sites. type CallSiteDemandObservation @@ -96,7 +110,7 @@ type CallSiteDemandObservation producer: String argument_preimage: String identity: ComputationIdentity - claims: Int + claims: List sites: List } | UnadmissibleCallSiteDemand { @@ -107,21 +121,94 @@ type CallSiteDemandObservation // ── THE DECISION ────────────────────────────────────────────────────────────────────────── +// THE FRAME PATH, and each frame's kind is a fact about the floor's own execution rather than a +// label. Preparation is a SHARED-STATE frame: one process, one prepared subject, and the carried +// value is bound in it. A claim is an ISOLATED-CHILDREN frame because the floor builds a fresh +// evaluation frame per claim deliberately — one witness must not contaminate the next — which is +// exactly why the eval-frame memo dies at every claim boundary and why the obligation LCA is +// preparation rather than any claim. +fn floor_preparation_frame() -> Frame { + Frame { name: "required-floor-preparation", kind: SharedStateFrame } +} + +fn floor_claim_frame(name: String) -> Frame { + Frame { name: name, kind: IsolatedChildrenFrame } +} + +fn floor_claim_site(name: String) -> List { + [floor_preparation_frame(), floor_claim_frame(name: name)] +} + +// THE PROVIDER: the cross-claim pure-producer tier, described as it actually behaves. +// +// scope — the preparation frame, which is the least common visible ancestor of the claims. +// coverage — the identities a caller admits (the derived rows below, or the carried-input rows) +// and nothing else, never every pure call. +// tier — MemoTier { ContentKeyed }: an in-process store whose key is the resolved fn node +// plus the portable argument row, and the carried value IS that argument row. +// retention — released when the prepared subject is cleared, with the exact 256 MiB ceiling the +// tier enforces at publication and RefuseNewStore as its at-capacity disposition +// (an over-budget producer recomputes per claim as if never enrolled). +fn cross_claim_tier_retention() -> ProviderRetention { + ProviderRetention { + release_policy: ReleasedAtProviderScopeExit, + capacity: CapacityBounded { + limit: ByteCapacity { limit: ExactLimit { value: byte_size(count: 268435456) } }, + at_capacity: RefuseNewStore + } + } +} + +fn cross_claim_share_provider(identities: List) -> CacheProvider { + CacheProvider { + id: "floor-cross-claim-pure-share", + scope: [floor_preparation_frame()], + coverage: CoversIdentities { identities: identities }, + tier: MemoTier { keying: ContentKeyed }, + retention: cross_claim_tier_retention() + } +} + +// THE LADDER JUDGMENT FOR ONE CLOSED IDENTITY (std.materialization_ladder, the structural +// authority DESIGN section 2 names). Each demanding planned claim is one FrameDemand at its claim +// frame under preparation. Two or more claims put the obligation's least common ancestor at the +// SHARED-STATE preparation frame, which the ladder judges AuthoredDuplication: the repair is to +// carry the first value to preparation, and the derived warm is that carry. One claim is +// AcceptedSingleRecompute. The ladder identity is the full computation identity: producer plus +// canonical argument preimage. +fn share_ladder_identity(producer: String, argument_preimage: String) -> String { + concat(producer, concat(" ", argument_preimage)) +} + +fn closed_demand_ladder_verdict(identity: String, claims: List) -> LadderVerdict { + group_verdict( + identity: identity, + group: list_map(xs: claims, f: fn(c) { + FrameDemand { identity: identity, site: floor_claim_site(name: c), nature: PureComputation } + }), + providers: [cross_claim_share_provider(identities: [identity])], + cost_floor_exempt: [] + ) +} + type DerivedShareRow { producer: String argument_preimage: String + identity: String claims: Int sites: List } -// Why a CLOSED identity is still not admitted. The four arms are the whole decision, so every -// closed row lands in exactly one of `admitted` or one of these, and the counts reconcile against -// the observation population (`cross_claim_share_derivation_reconciles`). +// Why a CLOSED identity is still not admitted. Every closed row lands in exactly one of `admitted` +// or one of these, and the counts reconcile against the observation population +// (`cross_claim_share_derivation_reconciles`). The three gates come first because they are +// identity facts the ladder cannot see; the ladder then decides whether a carry is owed. type ShareDerivationDecline = DemandedByOneClaim | IdentityGradeNotShareable | RefusedByMeasurement | CarriedInputProducer + | LadderOwesNoCarry { verdict: LadderVerdict } type DeclinedShareRow { producer: String @@ -141,10 +228,33 @@ type CrossClaimShareDerivation { unadmissible: List } +// The ladder verdict's consequence for admission: AuthoredDuplication owes the carry, so the row +// is admitted (empty list); a single recompute is a one-claim demand; every other verdict owes no +// carry and is carried on the decline so the floor names it. +fn ladder_decline(verdict: LadderVerdict) -> List { + match verdict { + AuthoredDuplication { identity: _, lca: _, site_count: _ } => [] + AcceptedSingleRecompute { identity: _ } => [DemandedByOneClaim] + DeadComputation { identity: _ } => [LadderOwesNoCarry { verdict: verdict }] + Discharged { identity: _, lca: _, provider_id: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedNoProvider { identity: _, lca: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedScopeTooNarrow { identity: _, lca: _, provider_id: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedExistenceKeyed { identity: _, lca: _, provider_id: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedRetentionUnbounded { identity: _, lca: _, provider_id: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedRetentionUnobserved { identity: _, lca: _, provider_id: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedUnmodeledWorldRead { identity: _, lca: _ } => [LadderOwesNoCarry { verdict: verdict }] + ExemptFreshEffect { identity: _ } => [LadderOwesNoCarry { verdict: verdict }] + AcceptedBelowCostFloor { identity: _ } => [LadderOwesNoCarry { verdict: verdict }] + AcceptedEffectIsTheUse { identity: _ } => [LadderOwesNoCarry { verdict: verdict }] + RefusedNatureConflict { identity: _ } => [LadderOwesNoCarry { verdict: verdict }] + } +} + fn closed_demand_decline( producer: String, + argument_preimage: String, identity: ComputationIdentity, - claims: Int, + claims: List, refused_names: List, carried_names: List ) -> List { @@ -154,10 +264,11 @@ fn closed_demand_decline( [RefusedByMeasurement] } else if any(xs: carried_names, predicate: fn(c) { c == producer }) { [CarriedInputProducer] - } else if claims < 2 { - [DemandedByOneClaim] } else { - [] + ladder_decline(verdict: closed_demand_ladder_verdict( + identity: share_ladder_identity(producer: producer, argument_preimage: argument_preimage), + claims: claims + )) } } @@ -168,8 +279,8 @@ fn derived_share_rows_for( ) -> List { match observation { ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: s } => - if length(xs: closed_demand_decline(producer: p, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names)) == 0 { - [DerivedShareRow { producer: p, argument_preimage: a, claims: c, sites: s }] + if length(xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names)) == 0 { + [DerivedShareRow { producer: p, argument_preimage: a, identity: share_ladder_identity(producer: p, argument_preimage: a), claims: length(xs: c), sites: s }] } else { [] } @@ -185,7 +296,7 @@ fn declined_share_rows_for( match observation { ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: _ } => list_map( - xs: closed_demand_decline(producer: p, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names), + xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names), f: fn(d) { DeclinedShareRow { producer: p, argument_preimage: a, decline: d } } ) UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => [] @@ -216,8 +327,12 @@ fn derive_cross_claim_share( } } -// THE COST FLOOR: DESIGN section 2's "unavoidable recurrence may explicitly recompute below the -// cost floor". An admitted identity whose isolated warm performs fewer evaluator steps than this is +// THE COST FLOOR: DESIGN section 2's economic realization, chosen only after the ladder has ruled a +// carry lawful ("only after both hold does section 6 choose the economically optimal realization"). +// It is NOT the ladder's AcceptedBelowCostFloor exemption, which the ladder applies only below an +// isolated least common ancestor; at the shared-state preparation frame the ladder owes the carry +// whatever it costs, so the floor is a policy of the BOUNDED provider about which carried values to +// retain. An admitted identity whose isolated warm performs fewer evaluator steps than this is // not retained: a store costs a key, a byte budget share and an entry in a bounded population, and // below this line the recomputation it saves is smaller than what it occupies. MEASURED REASON for // it existing (run 37089182924, the first derived run): 2807 of 2919 admitted identities warmed in From f64b8f9c647875a6aac60704d0c4266304191926 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 04:22:31 +0000 Subject: [PATCH 07/33] Derived share: recurrence over declared claims, warm only planned reach sharp-raven-357 ruling A: recurrence is a fact about the declared subject, so the observer walks every claim declared in a prepared module and each row carries its declared claims plus how many are planned. The ladder judges the declared demand (deterministic per claim: the same on main and on a PR that plans a narrower set); the fold declines ReachedByNoPlannedClaim so nothing is warmed that no planned claim in this run can consume. Reason stated beside the observation row type. Controls: two_declared_claims_with_one_planned_is_admitted, declared_demand_no_planned_claim_reaches_is_declined_and_named, and the seed's declared_unplanned_claims_count_as_demand_and_are_not_counted_planned. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/claim_call_site_demand.rs | 41 ++++++++++++++++++- .../src/cli_run/required_floor_runner.rs | 38 +++++++++++++++-- .../pure_producer_share_refusal_test.dag | 29 ++++++++++++- src/v2/workflow/floor_pure_producer_share.dag | 32 +++++++++++---- 4 files changed, 125 insertions(+), 15 deletions(-) diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index 0918d503c50..eba6958ecde 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -70,8 +70,10 @@ pub(crate) enum CallSiteDemandRow { Closed { producer: String, argument_preimage: String, - /// The distinct planned claims reaching this identity, `module.function`. + /// The distinct DECLARED claims reaching this identity, `module.function`. claims: Vec, + /// How many of `claims` this run plans. + planned_claims: u64, sites: Vec, }, Unadmissible { @@ -120,6 +122,8 @@ struct IdentityCell { last_claim: usize, /// The claim indices counted in `claims`, in planning order. claim_indices: Vec, + /// How many of them are planned (index below the planned count). + planned: u64, sites: BTreeSet, } @@ -156,9 +160,12 @@ impl<'a> CallSiteDemandObserver<'a> { /// Fold every planned claim's reach into the aggregated `.dag` rows. `claims` are /// `(module_path, function)`; a claim whose declaration the prepared subject does not carry /// contributes nothing and is returned in the second component, so the caller can refuse. + /// `claims[..planned]` are this run's planned claims; the rest are the other claims declared + /// in the prepared subject. Every one contributes demand; `planned_claims` counts the first kind. pub(crate) fn observe( &mut self, claims: &[(String, String)], + planned: usize, ) -> (Vec, Vec) { let mut closed: BTreeMap<(String, String), IdentityCell> = BTreeMap::new(); let mut open: BTreeMap = BTreeMap::new(); @@ -193,6 +200,9 @@ impl<'a> CallSiteDemandObserver<'a> { cell.last_claim = claim_number; cell.claims += 1; cell.claim_indices.push(index); + if index < planned { + cell.planned += 1; + } } cell.sites.insert(site.clone()); } @@ -209,6 +219,7 @@ impl<'a> CallSiteDemandObserver<'a> { .iter() .map(|i| format!("{}.{}", claims[*i].0, claims[*i].1)) .collect(), + planned_claims: cell.planned, sites: cell.sites.iter().map(render_site).collect(), }, ) @@ -555,7 +566,7 @@ mod tests { .iter() .map(|c| ("fixture.n7".to_string(), c.to_string())) .collect(); - let (rows, unresolved) = observer.observe(&planned); + let (rows, unresolved) = observer.observe(&planned, planned.len()); assert!( unresolved.is_empty(), "every fixture claim resolves: {unresolved:?}; indexed={:?}; modules={:?}; diagnostics={}", @@ -618,6 +629,32 @@ mod tests { ); } + // DECLARED DEMAND, PLANNED COUNT: with claim_b declared but not planned, the shared fixture is + // still reached by two declared claims, and exactly one of them is planned. + #[test] + fn declared_unplanned_claims_count_as_demand_and_are_not_counted_planned() { + let (graph, indices) = graph_of(&[("workspace/src/n7.dag", FIXTURE)]); + let mut observer = CallSiteDemandObserver::new(&graph, indices); + let population: Vec<(String, String)> = ["claim_a", "claim_b"] + .iter() + .map(|c| ("fixture.n7".to_string(), c.to_string())) + .collect(); + let (rows, _) = observer.observe(&population, 1); + let row = rows.iter().find_map(|r| match r { + CallSiteDemandRow::Closed { + producer, + argument_preimage, + claims, + planned_claims, + .. + } if producer == "fixture.n7.assemble" && argument_preimage.contains("module p") => { + Some((claims.len(), *planned_claims)) + } + _ => None, + }); + assert_eq!(row, Some((2, 1)), "{rows:?}"); + } + // NEVER WIDEN: a call whose argument is the enclosing function's parameter has no closed // identity, so it is counted under its cause instead of admitting `assemble` wholesale. #[test] diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index f3059efdf1c..fcb8d3a6884 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6719,6 +6719,7 @@ pub(crate) fn install_pure_producer_share( pub(crate) fn derive_and_install_cross_claim_share( prepared: &PreparedRepository, claims: &[RequiredFloorClaim], + declared: &[(String, String)], ) -> Result, String> { use super::claim_call_site_demand::{ CallSiteDemandObserver, CallSiteDemandRow, CLOSED_ARGUMENT_NORMALIZER, @@ -6726,13 +6727,30 @@ pub(crate) fn derive_and_install_cross_claim_share( use v1_interpreter::Value; const MODULE: &str = "v2.workflow.floor_pure_producer_share"; let started = std::time::Instant::now(); - let planned: Vec<(String, String)> = claims + let mut population: Vec<(String, String)> = claims .iter() .map(|c| (c.module_path.clone(), c.function.clone())) .collect(); + let planned_count = population.len(); let mut observer = CallSiteDemandObserver::new(&prepared.graph, prepared.source_indices.clone()); - let (rows, unresolved) = observer.observe(&planned); + // THE DECLARED POPULATION: every other claim declared in a module the prepared subject carries. + // Recurrence is judged over it (so a claim's budget does not depend on which other claims a diff + // plans); a declared claim whose module is outside the subject cannot be walked and is counted. + let planned_set: std::collections::HashSet<(String, String)> = + population.iter().cloned().collect(); + let mut declared_outside_subject = 0usize; + for d in declared { + if planned_set.contains(d) { + continue; + } + if observer.decl(&d.0, &d.1).is_some() { + population.push(d.clone()); + } else { + declared_outside_subject += 1; + } + } + let (rows, unresolved) = observer.observe(&population, planned_count); if !unresolved.is_empty() { return Err(format!( "REQUIRED-FLOOR REFUSAL cause=CallSiteDemandClaimUnresolved claims=[{}] -- a planned \ @@ -6766,6 +6784,7 @@ pub(crate) fn derive_and_install_cross_claim_share( producer, argument_preimage, claims, + planned_claims, sites, } => Value::Variant { type_name: sym("CallSiteDemandObservation"), @@ -6788,6 +6807,7 @@ pub(crate) fn derive_and_install_cross_claim_share( sym("claims"), list_value_from_vec(claims.iter().map(str_value).collect()), ), + (sym("planned_claims"), Value::Int(*planned_claims as i64)), ( sym("sites"), list_value_from_vec(sites.iter().map(str_value).collect()), @@ -6977,9 +6997,11 @@ pub(crate) fn derive_and_install_cross_claim_share( } eprintln!( "[floor-phase] phase=cross-claim-share-derivation state=completed planned_claims={} \ + declared_claims_observed={} declared_outside_subject={declared_outside_subject} \ closed_identities={closed_rows} admitted={} admitted_sites={} declined=[{}] \ unadmissible=[{}] observe_ms={observe_ms} derive_ms={derive_ms}", claims.len(), + population.len(), admitted.len(), sites.len(), decline_counts @@ -10559,7 +10581,17 @@ pub fn run_required_floor( floor_seam("cross-claim-share-derivation"); // The derived warms are shared builds like every preparation warm, so they answer to the same // three preparation limits; they run here only because their demand is the planned claims. - for (which, warm) in &derive_and_install_cross_claim_share(&prepared, &claims)? { + let declared_claims: Vec<(String, String)> = files + .iter() + .flat_map(|f| { + f.functions + .iter() + .map(move |function| (f.module_path.clone(), function.clone())) + }) + .collect(); + for (which, warm) in + &derive_and_install_cross_claim_share(&prepared, &claims, &declared_claims)? + { if warm.cpu_ms > preparation_cpu_limit_ms || warm.wall_ms > preparation_wall_limit_ms || warm.rss_growth_bytes > preparation_rss_growth_limit_bytes diff --git a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag index c2683590d0f..8f6c385ed9d 100644 --- a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag +++ b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag @@ -13,7 +13,7 @@ import v2.workflow.floor_pure_producer_share { CallSiteDemandObservation, ClosedCallSiteDemand, UnadmissibleCallSiteDemand, CallSiteDemandCause, ArgumentNotClosedConstant, CalleeDeclaresEffects, CrossClaimShareDerivation, DeclinedShareRow, - ShareDerivationDecline, DemandedByOneClaim, IdentityGradeNotShareable, RefusedByMeasurement, CarriedInputProducer, + ShareDerivationDecline, DemandedByOneClaim, ReachedByNoPlannedClaim, IdentityGradeNotShareable, RefusedByMeasurement, CarriedInputProducer, LadderOwesNoCarry, derive_cross_claim_share, floor_cross_claim_share_derivation, cross_claim_share_derivation_reconciles, derived_share_producers @@ -69,6 +69,7 @@ fn probe_closed(producer: String, claims: Int) -> CallSiteDemandObservation { argument_preimage: "(src: \"module text\")", identity: probe_identity(), claims: probe_claim_names(claims: claims), + planned_claims: 1, sites: ["v2/test/probe.dag:10-40"] } } @@ -90,6 +91,7 @@ fn decline_tag(decline: ShareDerivationDecline) -> String { match decline { DemandedByOneClaim => "DemandedByOneClaim" IdentityGradeNotShareable => "IdentityGradeNotShareable" + ReachedByNoPlannedClaim => "ReachedByNoPlannedClaim" RefusedByMeasurement => "RefusedByMeasurement" CarriedInputProducer => "CarriedInputProducer" LadderOwesNoCarry { verdict: _ } => "LadderOwesNoCarry" @@ -118,6 +120,30 @@ test fn a_closed_identity_one_claim_demands_is_declined_and_named() -> Bool { && declined_as(d: d, producer: "v2.probe.n7.probe_assemble", decline: DemandedByOneClaim) } +// DECLARED DEMAND DECIDES THE OBLIGATION; PLANNED REACH DECIDES THE WARM. The pair varies only how +// many of the declaring claims this run plans: two declared claims with one planned is admitted +// (the budget of the planned claim is the same as on a run planning both), and two declared claims +// with none planned is declined, because nothing in this run would consume the fill. +test fn two_declared_claims_with_one_planned_is_admitted() -> Bool { + let d = probe_derive(observations: [probe_closed(producer: "v2.probe.n7.probe_assemble", claims: 2)]) + length(xs: d.admitted) == 1 +} + +test fn declared_demand_no_planned_claim_reaches_is_declined_and_named() -> Bool { + let d = probe_derive(observations: [ + ClosedCallSiteDemand { + producer: "v2.probe.n7.probe_unplanned", + argument_preimage: "()", + identity: probe_identity(), + claims: probe_claim_names(claims: 4), + planned_claims: 0, + sites: ["v2/test/probe.dag:70-80"] + } + ]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.probe.n7.probe_unplanned", decline: ReachedByNoPlannedClaim) +} + // A MEASURED REFUSAL OUTRANKS DEMAND. The producer is demanded by many claims and still declined, // naming the refusal -- the literal re-proposal path of the refused-candidate class, now closed by // construction rather than by a collision wall over an authored roster. @@ -143,6 +169,7 @@ test fn an_identity_of_unknown_grade_is_declined() -> Bool { argument_preimage: "()", identity: IdentityUnknown { cause: MissingConcept { detail: "authored fixture" } }, claims: probe_claim_names(claims: 3), + planned_claims: 3, sites: ["v2/test/probe.dag:50-60"] } ]) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index e8d3ceadd09..0dd171ac8be 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -100,9 +100,18 @@ type CallSiteDemandCause | CallShapeUnread // `producer` is the callee's qualified declaration; `argument_preimage` the canonical normalized -// argument row; `claims` the DISTINCT planned claims whose reach contains a site of this identity -// (each becomes one ladder demand at its claim frame); `sites` those sites as -// `:-` byte spans, which is what the seed admits. +// argument row; `claims` the DISTINCT claims DECLARED in the prepared subject whose reach contains +// a site of this identity (each becomes one ladder demand at its claim frame); `planned_claims` +// how many of those this run plans; `sites` those sites as `:-` byte spans, which +// is what the seed admits. +// +// WHY DECLARED AND NOT PLANNED (sharp-raven-357, 2026-10-03): recurrence is a fact about the +// declared subject, not about which claims a diff happens to plan. Counting only planned claims +// made a claim's budget depend on which OTHER claims the diff planned -- a producer two declared +// claims share was shared on a whole-corpus run and charged in full to the one claim a narrow PR +// planned, so the same claim passed on main and failed on the PR. Counting declared claims makes +// each claim's budget deterministic. Warming only what a PLANNED claim reaches keeps the run's own +// demand minimal: an obligation no planned claim can discharge in this run is not filled here. // An unadmissible row aggregates every site sharing one cause: `claims` counts distinct planned // claims reaching any of them, `sites` counts the sites. type CallSiteDemandObservation @@ -111,6 +120,7 @@ type CallSiteDemandObservation argument_preimage: String identity: ComputationIdentity claims: List + planned_claims: Int sites: List } | UnadmissibleCallSiteDemand { @@ -205,6 +215,7 @@ type DerivedShareRow { // identity facts the ladder cannot see; the ladder then decides whether a carry is owed. type ShareDerivationDecline = DemandedByOneClaim + | ReachedByNoPlannedClaim | IdentityGradeNotShareable | RefusedByMeasurement | CarriedInputProducer @@ -255,11 +266,14 @@ fn closed_demand_decline( argument_preimage: String, identity: ComputationIdentity, claims: List, + planned_claims: Int, refused_names: List, carried_names: List ) -> List { if identity_permits_share(ci: identity) == false { [IdentityGradeNotShareable] + } else if planned_claims == 0 { + [ReachedByNoPlannedClaim] } else if any(xs: refused_names, predicate: fn(r) { r == producer }) { [RefusedByMeasurement] } else if any(xs: carried_names, predicate: fn(c) { c == producer }) { @@ -278,8 +292,8 @@ fn derived_share_rows_for( carried_names: List ) -> List { match observation { - ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: s } => - if length(xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names)) == 0 { + ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, sites: s } => + if length(xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names)) == 0 { [DerivedShareRow { producer: p, argument_preimage: a, identity: share_ladder_identity(producer: p, argument_preimage: a), claims: length(xs: c), sites: s }] } else { [] @@ -294,9 +308,9 @@ fn declined_share_rows_for( carried_names: List ) -> List { match observation { - ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, sites: _ } => + ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, sites: _ } => list_map( - xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, refused_names: refused_names, carried_names: carried_names), + xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names), f: fn(d) { DeclinedShareRow { producer: p, argument_preimage: a, decline: d } } ) UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => [] @@ -305,7 +319,7 @@ fn declined_share_rows_for( fn unadmissible_counts_for(observation: CallSiteDemandObservation) -> List { match observation { - ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, sites: _ } => [] + ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, planned_claims: _, sites: _ } => [] UnadmissibleCallSiteDemand { cause: k, claims: c, sites: n } => [UnadmissibleDemandCount { cause: k, claims: c, sites: n }] } @@ -360,7 +374,7 @@ fn floor_cross_claim_share_derivation( fn closed_observation_count(observations: List) -> Int { length(xs: filter(xs: observations, predicate: fn(o) { match o { - ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, sites: _ } => true + ClosedCallSiteDemand { producer: _, argument_preimage: _, identity: _, claims: _, planned_claims: _, sites: _ } => true UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => false } })) From bb22c4401f3aa5f2628f4eef04cad477ba5dd408 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 05:18:25 +0000 Subject: [PATCH 08/33] Class-2 dispositions: 20 single-claim fixture witnesses withheld as declared cost debt Run 37096345499 (f64b8f9c64): with recurrence counted over declared claims, the class-1 claim (btar) passes; 20 claims remain over the new-witness budget, each the ONLY declared claim reaching its front-end fixture producer, which the deleted roster warmed in preparation (DESIGN s5 externalization). Per sharp-raven-357's ruling each is dispositioned individually: supplying normalized front-end subjects as literals is not practicable in this change, so each is a declared cost-debt row (v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22, measured eval steps beside each) with the per-claim trigger being the s3 witness rule. The coverage loss is a declared s4b(3) drop: gunbc.rung_drop.derived_share_single_claim_fixtures_withheld (rostered; docs/design-rung-drops.md regenerated). Co-Authored-By: Claude Opus 5.5 (1M context) --- ...d_share_single_claim_fixtures_withheld.dag | 44 +++++++++++++++++++ dag/gunbc/rung_drop/roster.dag | 2 + docs/design-rung-drops.md | 4 ++ src/v2/workflow/floor_cost_debt.dag | 41 ++++++++++++++++- 4 files changed, 90 insertions(+), 1 deletion(-) create mode 100644 dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag diff --git a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag new file mode 100644 index 00000000000..514e74f7e5e --- /dev/null +++ b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag @@ -0,0 +1,44 @@ +module gunbc.rung_drop.derived_share_single_claim_fixtures_withheld + +import std.types { NonEmptyStr } +import gunbc.rung_drop { RungDrop, Standing, TypedDeclaration, LostAsPassenger } +import gunbc.guarantee_rung { Mitigatable, MechanicallyPreventable } + +data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { + identity: "derived_share_single_claim_fixtures_withheld" as NonEmptyStr, + + subject: "the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation", + + declared: "2026-10-03", + + standing: Standing, + + declaration: TypedDeclaration { + previous: MechanicallyPreventable, + temporary: Mitigatable, + reason: LostAsPassenger { carrier: "gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22" }, + population: [ + "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499)", + "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499)", + "v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499)", + "v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499)", + "v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499)", + "v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499)", + "v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499)", + "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499)" + ], + restoration_trigger: "Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected.", + } +} diff --git a/dag/gunbc/rung_drop/roster.dag b/dag/gunbc/rung_drop/roster.dag index ad6e58e2fed..7e5244736a7 100644 --- a/dag/gunbc/rung_drop/roster.dag +++ b/dag/gunbc/rung_drop/roster.dag @@ -46,6 +46,7 @@ import gunbc.rung_drop.the_job_user_holds_a_path_unrestricted_root_grant { the_j import gunbc.rung_drop.required_lanes_do_not_resolve_product_layer_modules { required_lanes_do_not_resolve_product_layer_modules } import gunbc.rung_drop.emit_copy_qualification_without_a_consumer { emit_copy_qualification_without_a_consumer } import gunbc.rung_drop.floor_cost_high_cpu_withheld { floor_cost_high_cpu_withheld } +import gunbc.rung_drop.derived_share_single_claim_fixtures_withheld { derived_share_single_claim_fixtures_withheld } import gunbc.rung_drop.spark_role_scoped_retirement_production_root { spark_role_scoped_retirement_production_root } import gunbc.rung_drop.builtin_signature_arity_pairing_fabricates { builtin_signature_arity_pairing_fabricates } import gunbc.rung_drop.concat_binary_signature_exempt_from_arg_binding { concat_binary_signature_exempt_from_arg_binding } @@ -150,6 +151,7 @@ data rung_drop_roster: List = [ required_lanes_do_not_resolve_product_layer_modules, emit_copy_qualification_without_a_consumer, floor_cost_high_cpu_withheld, + derived_share_single_claim_fixtures_withheld, spark_role_scoped_retirement_production_root, builtin_signature_arity_pairing_fabricates, concat_binary_signature_exempt_from_arg_binding, diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 13f99e3b565..2589d957958 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -160,6 +160,10 @@ Required lanes do not resolve product-layer modules: a module outside the nomina **132 REQUIRED WITNESSES AT OR ABOVE 219 CPU-MS LEAVE THE FLOOR TO STOP A COIN-FLIP GATE (2026-09-04).** main was refusing intermittently on cost alone: four DISTINCT identities across three runs at 502, 508, 519 and 568 cpu-ms against the 500ms stop, one of them by 2ms, every run reporting passed=3525 and claims_failed=0. No witness was wrong; which one lost was a coin flip, and a merge block nobody can act on is the uninformative-signal failure `gunbc.witness_floor_workflow` warns about when it says a lane may be promoted only when a red in it DISCRIMINATES. PREVIOUS RUNG: mechanically preventable -- these 132 executed on the required floor and a regression in any of them blocked a merge. TEMPORARY RUNG: mitigatable -- they remain authored, correct and executable, and `floor_cost_debt_roster` withholds them AT BUILD so the identity join still balances; what is gone is their merge-blocking authority. THE THRESHOLD IS DERIVED, NOT CHOSEN, AND THAT IS THE WHOLE OF WHY IT IS 219 AND NOT THE OPERATOR'S PERMISSIVE 100. `gunbc.rung_drop` `floor_cost_claim_qualification_unavailable` measures the per-identity inflation floor at 2.280x over twelve green main runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the LOWEST BASELINE THAT CAN REACH THE STOP; it is that row's own attention constant, named here rather than re-derived. The operator authorised anything above 100ms, which is 316 identities. Withdrawing at 219 takes 132 and leaves 184 rows on the floor that cannot trip the line under the measured floor, because withdrawn coverage is safety spent and 184 rows is a large price for no reduction in flapping. A LOWER LINE IS AVAILABLE IF THE FLOOR RISES: 2.280 is a floor and the row says it can only rise, so if a larger inflation is measured this constant falls and the population grows -- that is a re-derivation, not a re-argument. BOUNDED POPULATION: the 132 identities measured `cost_reading=observed` at or above 219 cpu-ms in the green main run 33841933739. 130 of them are enrolled by this row in `v2.workflow.floor_cost_debt` proven chunks 14-20; the remaining TWO -- `produced_decl_module_folds_declarations_in_order` and `produced_decl_two_targets_render_own_order` -- were rostered by gunbc#10389 while this branch was open and are NOT re-enrolled here. The roster totals 421 identities. THAT SPLIT IS RECORDED RATHER THAN TIDIED AWAY BECAUSE IT COST A CI FAILURE: this row's chunks were generated mechanically from the cost TSV, deep-wolf-853 had named those two rows as gunbc#10389's, the reply agreeing to leave them alone was never applied to the artifact, and the duplicate only became reachable when main merged in. `floor_cost_debt_roster` refused it fail-closed -- `duplicate withheld identity` -- before running a single claim, which is the roster behaving correctly and the generation step behaving carelessly. The uniqueness check that would have caught it was run BEFORE the merge, and a merge is exactly the event that can create a duplicate. THREE SUBPOPULATIONS, DISPOSITIONED SEPARATELY BECAUSE THEY END DIFFERENTLY. (1) 37 host-process execution rows (`emit_host`, `rust_emit_host_call`) build and RUN a real host program to assert the executed program agrees with eval; no fixture work moves them, so they are PERMANENT withhold candidates, not pending fixes. (2) 5 live-tree lens rows walk the repository corpus, which is what they assert about, so shrinking their input would delete the check; also permanent. Two of these are the reason cpu and not eval_steps denominates this row at all -- `wall_residue_live` costs 298ms on 28 eval_steps and `test_migration_debt` 288ms on 129, because a corpus walk is host I/O that performs almost no substrate evaluation. (3) The remaining 90 are fixture-optimizable and are being worked: deep-wolf-853's six lanes edit the witness fixtures, and gunbc#10389 owns two of the top three. A row whose baseline drops below 219 leaves this population by re-measurement. WHY eval_steps IS NOT THE DENOMINATOR, recorded because it was proposed and tested rather than dismissed: eval_steps is deterministic where cpu is not, which is a real advantage, and it MATCHES at the 100ms line (Jaccard 0.943, 316 cpu rows against 327 step rows). It DEGRADES at the tail this row is about -- 0.718 at 219ms and 0.294 at 400ms -- because it counts substrate evaluation and cannot see host I/O. The conservative step line covering every at-risk row is steps>=28, which is 3092 of 3602 rows. cpu is the only column that sees both mechanisms. RESTORATION TRIGGER, at capability grain and NOT retired by these rows getting faster: an environment-independent per-claim cost qualification -- a charge readable as a stable property of the claim rather than of the attempt -- so that a cost verdict discriminates a regression from an execution position. That is the same capability `floor_cost_claim_qualification_unavailable` names, and this row is downstream of it: while a claim's charge is not a property of the claim, no threshold anywhere makes this gate discriminate, and moving the line only moves which rows flap. Individual rows returning under 219ms is a POPULATION shrink and retires their own membership, not this row. +### the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation — declared 2026-10-03 + +the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. + ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02 **AN OPERATOR DECISION REMOVED A BEHAVIOUR'S ONLY SUBJECT, AND THIS ROW IS THAT DECLARATION (2026-09-02).** `gunbc.spark.cell_role` assigned srv6 to `SparkTrainingCell`, and the operator withdrew that dedication as premature -- 'i wouldn't dedicate a whole node for any task - just have it converge and serve whatever task we converge it to' -- so the production roster now holds ZERO training cells. Three claims in `test.claim.spark.spark_cell_role_retirement_witness_test` entered through `fleet_converge_plan_artifact`, the root the converge actuator itself walks, and each needed a production host holding that role to have a subject at all: `w_the_production_artifact_plans_four_retirements_for_the_training_cell`, `w_the_production_artifact_plans_no_rows_for_the_converged_serving_cell`, and `w_the_production_retirement_touches_no_baseline_address`. They are DELETED rather than left silently red, because a claim whose subject no longer exists is not a failing test, and leaving it to fail would have made an operator's decision look like a regression. **PREVIOUS RUNG: mechanically preventable** -- the training arm's four retirement rows and the serving arm's zero rows were both exercised through the production root, so a planner regression that pointed `spark_serving_full_membership_plan` back at the unscoped desired members went red there. **TEMPORARY RUNG: mitigatable** -- both arms are still exercised, but only at `spark_serving_role_scoped_desired_members_in` over an authored fixture roster (`w_the_planner_scopes_desired_state_by_role`), which is a real production function and is NOT the path the converge actuator calls; the same PR added `spark_cell_role_in` and that `_in` planner variant precisely so an arm's evidence stops depending on which machines are currently assigned what. **REASON:** operator decision, recorded with its basis at `gunbc.spark.cell_role` `spark_cell_role_assignment_basis`; role is converged desired state rather than a node dedication. **POPULATION, BOUNDED:** the training arm of Spark serving role scoping and the retirement rows it produces, AS REACHED THROUGH `fleet_converge_plan_artifact`. The serving arm, the no-role refusal, the reconcile, the freeze and the apply are unaffected and their production-root claims remain enrolled. **RESTORATION TRIGGER, NAMING THE CAPABILITY:** a roster-parameterized plan artifact -- the assignment roster threaded from `fleet_converge_plan_artifact` down to `spark_serving_role_scoped_desired_members_in` -- SUFFICIENT FOR a witness to drive the production root over an authored roster and read back the four retirement rows with no production host holding `SparkTrainingCell`. Half that capability exists today: both `_in` functions take the roster; what is missing is the threading through the generic artifact entry point. **RESTORING A TRAINING CELL TO THE PRODUCTION ROSTER DOES NOT RETIRE THIS DROP** -- that would re-create the coupling between an arm's evidence and the current assignment, which is the defect this row exists to record, and it is exactly the trigger-names-less-than-the-capability failure §4b(3) warns about. diff --git a/src/v2/workflow/floor_cost_debt.dag b/src/v2/workflow/floor_cost_debt.dag index 9da8f7912ff..ecd50c111aa 100644 --- a/src/v2/workflow/floor_cost_debt.dag +++ b/src/v2/workflow/floor_cost_debt.dag @@ -1017,8 +1017,47 @@ fn floor_cost_debt_proven_chunk_21() -> List { Cons { head: "v2.test.parse.expression_bodied_fn_decl_parse.braced_fn_decl_survives_normalize_holds", tail: Empty {} } } +// PROVEN, AND ADDED BY THE DELETION OF THE HAND SHARE ROSTER (gunbc#13043), so the shrink-only +// contract is crossed in the open and with the cause beside it. Each of these claims is the ONLY +// declared claim reaching its fixture producer (a `*_subject` / `*_route_verdict` front-end +// fixture). The deleted roster warmed those producers in preparation, which billed each claim's +// own fixture work to preparation -- DESIGN section 5's externalization: the cost hidden from the +// claim that causes it. The derived share (v2.workflow.floor_pure_producer_share +// derive_cross_claim_share) admits only declared cross-claim recurrence, so the fill is now charged +// to its claim and each completes over the new-witness eval-step budget. Ruling: sharp-raven-357, +// 2026-10-03 (class 2: disposition each claim; no class-2 claim may pass by being shared). +// Measured on the required floor of record, run 37096345499 (head f64b8f9c64), verdict reached: +// v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds eval_steps=132825 +// v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds eval_steps=198260 +// v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds eval_steps=162404 +// v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds eval_steps=172723 +// v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds eval_steps=87928 +// v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds eval_steps=1617281 +// v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds eval_steps=2010279 +// v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds eval_steps=109109 +// v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds eval_steps=509842 +// v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds eval_steps=359882 +// v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds eval_steps=192203 +// v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds eval_steps=172464 +// v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds eval_steps=241864 +// v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds eval_steps=353331 +// v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds eval_steps=303359 +// v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds eval_steps=504422 +// v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds eval_steps=327104 +// v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds eval_steps=544612 +// v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds eval_steps=152556 +// v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds eval_steps=184724 +// TRIGGER (per row, and it is the capability, not an artifact): the claim's module supplies its +// subject at the interface the claim judges (DESIGN section 3 witness rule) and keeps ONE +// inhabitance claim on the real front-end path, so this row's own eval steps fall under its budget; +// the row then leaves through the debt-removal transaction. The rung loss is declared at +// gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. +fn floor_cost_debt_proven_chunk_22() -> List { + Cons { head: "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}} +} + fn floor_cost_debt_proven_chunks() -> List> { - Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Empty {} } } } } } } } } } } }}}}}}}}}}}} + Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Cons { head: floor_cost_debt_proven_chunk_22(), tail: Empty {} } } } } } } } } } } } }}}}}}}}}}}} } fn floor_cost_debt_censored_chunks() -> List> { From d95712648b687ca6aaf924c58e26b822c76ca8a0 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 05:33:20 +0000 Subject: [PATCH 09/33] Derived share: print every decline, single-claim included Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v1/stage0/src/cli_run/required_floor_runner.rs | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index fcb8d3a6884..5d5fc717580 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6972,7 +6972,9 @@ pub(crate) fn derive_and_install_cross_claim_share( return Err(malformed("a declined row is not a DeclinedShareRow record")); }; *decline_counts.entry(variant_of(r, "decline")?).or_default() += 1; - if variant_of(r, "decline")? != "DemandedByOneClaim" { + // EVERY decline is printed, single-claim ones included, so each producer's disposition is + // readable by identity from the run's own log. + { eprintln!( "[cross-claim-share-declined] producer={} decline={} argument_preimage={}", text_of(r, "producer")?, From b5fe692f2111a1673bc5a0a438601b1b62a407b4 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 07:01:14 +0000 Subject: [PATCH 10/33] Derived share: name unadmissible sites by producer for disposition Unadmissible sites with a known callee (open argument row, effectful callee) are also aggregated per (producer, cause) and printed as [cross-claim-share-unadmissible] lines, so each deleted roster row's disposition is readable by identity: admitted, declined, open/effectful, or outside the run's subject. The .dag rows stay aggregated by cause. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/claim_call_site_demand.rs | 48 +++++++++++++++++-- .../src/cli_run/required_floor_runner.rs | 7 +++ 2 files changed, 52 insertions(+), 3 deletions(-) diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index eba6958ecde..0d8414172b5 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -95,8 +95,17 @@ pub(crate) fn render_site(site: &SiteKey) -> String { } enum SiteFact { - Closed { producer: String, preimage: String }, + Closed { + producer: String, + preimage: String, + }, Unadmissible(CallSiteDemandCause), + /// An unadmissible site whose callee IS known, kept by producer so a reader can disposition + /// each producer (whose site is open, or effectful) by identity. + UnadmissibleOf { + producer: String, + cause: CallSiteDemandCause, + }, } struct DeclFacts { @@ -114,6 +123,7 @@ pub(crate) struct CallSiteDemandObserver<'a> { decls: HashMap<(String, String), Rc>, facts: HashMap<(String, String), Rc>, site_nodes: HashMap)>, + open_producers: Vec<(String, CallSiteDemandCause, u64, u64)>, } #[derive(Default)] @@ -144,6 +154,7 @@ impl<'a> CallSiteDemandObserver<'a> { decls, facts: HashMap::new(), site_nodes: HashMap::new(), + open_producers: Vec::new(), } } @@ -169,6 +180,8 @@ impl<'a> CallSiteDemandObserver<'a> { ) -> (Vec, Vec) { let mut closed: BTreeMap<(String, String), IdentityCell> = BTreeMap::new(); let mut open: BTreeMap = BTreeMap::new(); + let mut open_by_producer: BTreeMap<(String, CallSiteDemandCause), IdentityCell> = + BTreeMap::new(); let mut unresolved_claims = Vec::new(); for (index, (module_path, function)) in claims.iter().enumerate() { let claim_number = index + 1; @@ -195,6 +208,17 @@ impl<'a> CallSiteDemandObserver<'a> { .entry((producer.clone(), preimage.clone())) .or_default(), SiteFact::Unadmissible(cause) => open.entry(*cause).or_default(), + SiteFact::UnadmissibleOf { producer, cause } => { + let by = open_by_producer + .entry((producer.clone(), *cause)) + .or_default(); + if by.last_claim != claim_number { + by.last_claim = claim_number; + by.claims += 1; + } + by.sites.insert(site.clone()); + open.entry(*cause).or_default() + } }; if cell.last_claim != claim_number { cell.last_claim = claim_number; @@ -232,9 +256,21 @@ impl<'a> CallSiteDemandObserver<'a> { sites: cell.sites.len() as u64, }), ); + self.open_producers = open_by_producer + .into_iter() + .map(|((producer, cause), cell)| { + (producer, cause, cell.claims, cell.sites.len() as u64) + }) + .collect(); (rows, unresolved_claims) } + /// The last observation's unadmissible sites with a known callee, per (producer, cause): + /// (producer, cause, distinct claims, sites). Rendered by the floor for disposition only. + pub(crate) fn open_producers(&self) -> &[(String, CallSiteDemandCause, u64, u64)] { + &self.open_producers + } + fn facts_of(&mut self, decl: &(String, String)) -> Option> { if let Some(f) = self.facts.get(decl) { return Some(f.clone()); @@ -436,14 +472,20 @@ impl<'a> CallSiteDemandObserver<'a> { .get(&target) .is_some_and(|callee| !callee.uses.is_empty()) { - return SiteFact::Unadmissible(CallSiteDemandCause::CalleeDeclaresEffects); + return SiteFact::UnadmissibleOf { + producer: format!("{}.{}", target.0, target.1), + cause: CallSiteDemandCause::CalleeDeclaresEffects, + }; } match self.closed_arguments(module, call, binders) { Some(preimage) => SiteFact::Closed { producer: format!("{}.{}", target.0, target.1), preimage, }, - None => SiteFact::Unadmissible(CallSiteDemandCause::ArgumentNotClosedConstant), + None => SiteFact::UnadmissibleOf { + producer: format!("{}.{}", target.0, target.1), + cause: CallSiteDemandCause::ArgumentNotClosedConstant, + }, } } diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 45b4cd5015b..1493e342087 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6784,6 +6784,13 @@ pub(crate) fn derive_and_install_cross_claim_share( )); } let observe_ms = started.elapsed().as_millis(); + for (producer, cause, claims_n, sites_n) in observer.open_producers() { + eprintln!( + "[cross-claim-share-unadmissible] producer={producer} cause={} claims={claims_n} \ + sites={sites_n}", + cause.variant() + ); + } let frame = floor_authority_frame(prepared, MODULE).map_err(|why| { format!( "REQUIRED-FLOOR REFUSAL cause=PureProducerShareRosterOutsidePreparedSubject \ From 97f19210fadf88d2666bf64367d159dd994efcaa Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 08:20:22 +0000 Subject: [PATCH 11/33] Derived share: no preparation warm; fills are lazy, floored at retention, wall-excused in flight Same-revision A/B (PR run 37104970794 vs baseline dispatch 37105064700, both at main 3a22bc24bf) showed the warm pass costing more than it saves: the derived warm seam took 133.5s thread CPU against the old roster warm's 53.0s, with the claim-evaluation fold unchanged (735.7s vs 731.9s). Most of it was 169 evaluation frames built only to warm 2523 identities, 2404 of which were then discarded below the cost floor. - No warm: an admitted site fills on the first planned claim that evaluates it. Its eval steps are netted from that claim by the existing fill guard (deterministic budgets). - Its wall is excused from the claim's wall deadline while in flight (in_flight_cross_claim_fill_wall_nanos), capped at the preparation wall safety limit so a runaway fill still interrupts: the wall sibling of the existing CPU-deadline FillBudgetExceeded netting. - The declared cost floor is applied to the fill's own steps at retention (CrossClaimStoreOutcome::RefusedBelowCostFloor, counted). - Deleted: warm_cross_claim_call_site, CallSiteWarmRefusal, CROSS_CLAIM_WARM_ONLY, and the observer's site-node bookkeeping. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 10 +- .../src/cli_run/claim_call_site_demand.rs | 21 -- .../src/cli_run/required_floor_runner.rs | 166 ++---------- src/v1/stage0/src/v1_interpreter.rs | 245 +++++++++++------- 4 files changed, 178 insertions(+), 264 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 2cb9dc8c536..3550d903f56 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -26,12 +26,16 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_site_admitted", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "warm_cross_claim_call_site", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CallSiteWarmRefusal", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_steps", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_cap_ms", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_wall_nanos", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_below_cost_floor_count", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_COST_FLOOR_STEPS", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it, netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs index 0d8414172b5..a0720f966f1 100644 --- a/src/v1/stage0/src/cli_run/claim_call_site_demand.rs +++ b/src/v1/stage0/src/cli_run/claim_call_site_demand.rs @@ -111,8 +111,6 @@ enum SiteFact { struct DeclFacts { reads: Vec<(String, String)>, sites: Vec<(SiteKey, SiteFact)>, - /// Each closed site's call node, so an admitted site can be warmed in its module's frame. - closed_nodes: Vec<(SiteKey, Rc)>, } /// The observation over one prepared subject. Declarations are read lazily and each body is @@ -122,7 +120,6 @@ pub(crate) struct CallSiteDemandObserver<'a> { source_indices: Rc, decls: HashMap<(String, String), Rc>, facts: HashMap<(String, String), Rc>, - site_nodes: HashMap)>, open_producers: Vec<(String, CallSiteDemandCause, u64, u64)>, } @@ -153,7 +150,6 @@ impl<'a> CallSiteDemandObserver<'a> { source_indices, decls, facts: HashMap::new(), - site_nodes: HashMap::new(), open_producers: Vec::new(), } } @@ -163,14 +159,6 @@ impl<'a> CallSiteDemandObserver<'a> { self.decls.get(&(module_path.to_string(), name.to_string())) } - /// The module and call node of a closed site this observer read, for warming it. - pub(crate) fn site_node(&self, site: &SiteKey) -> Option<&(String, Rc)> { - self.site_nodes.get(site) - } - - /// Fold every planned claim's reach into the aggregated `.dag` rows. `claims` are - /// `(module_path, function)`; a claim whose declaration the prepared subject does not carry - /// contributes nothing and is returned in the second component, so the caller can refuse. /// `claims[..planned]` are this run's planned claims; the rest are the other claims declared /// in the prepared subject. Every one contributes demand; `planned_claims` counts the first kind. pub(crate) fn observe( @@ -277,10 +265,6 @@ impl<'a> CallSiteDemandObserver<'a> { } let node = self.decls.get(decl)?.clone(); let facts = Rc::new(self.read_declaration(&decl.0, &node)); - for (site, call) in &facts.closed_nodes { - self.site_nodes - .insert(site.clone(), (decl.0.clone(), call.clone())); - } self.facts.insert(decl.clone(), facts.clone()); Some(facts) } @@ -404,7 +388,6 @@ impl<'a> CallSiteDemandObserver<'a> { } let mut reads: BTreeSet<(String, String)> = BTreeSet::new(); let mut sites: Vec<(SiteKey, SiteFact)> = Vec::new(); - let mut closed_nodes: Vec<(SiteKey, Rc)> = Vec::new(); for n in &nodes { match n.expr_data.as_ref() { ExprData::ExprCall { .. } => { @@ -425,9 +408,6 @@ impl<'a> CallSiteDemandObserver<'a> { if let Some(t) = &target { reads.insert(t.clone()); } - if matches!(fact, SiteFact::Closed { .. }) { - closed_nodes.push((site_key_of(n), n.clone())); - } sites.push((site_key_of(n), fact)); } ExprData::ExprVar { binding_kind } => { @@ -452,7 +432,6 @@ impl<'a> CallSiteDemandObserver<'a> { DeclFacts { reads: reads.into_iter().collect(), sites, - closed_nodes, } } diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 1493e342087..47823e3bdf2 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6731,20 +6731,16 @@ pub(crate) fn install_pure_producer_share( /// The seed observes (`claim_call_site_demand`, one realization of the `.dag` row type /// `CallSiteDemandObservation`) and `v2.workflow.floor_pure_producer_share` /// `floor_cross_claim_share_derivation` decides; the seed then admits the decided rows at their call -/// sites, and WARMS each admitted row once at one of its sites in that site's module frame, so its -/// fill lands outside the fold -- a claim's wall deadline nets only completed fills, so a fill left -/// to the first toucher could be interrupted mid-flight and re-paid by every claim. The returned -/// observations are adjudicated against the preparation limits by the caller. A warm the tier -/// cannot store (an effect, a call that does not evaluate in isolation, a declined store) is -/// counted under its cause and the site stays admitted: a claim evaluating it computes exactly -/// what it would have without the share. Every arm refuses: a planned claim the prepared subject does not carry, a fold +/// sites. There is no warm: the first planned claim that evaluates an admitted site fills it (see the +/// install note at the end of this function). Every arm refuses: a planned claim the prepared subject does not carry, a fold /// that does not evaluate or decode, a partition that does not reconcile, and an admitted producer /// with no declaration node or an unparseable site. pub(crate) fn derive_and_install_cross_claim_share( prepared: &PreparedRepository, claims: &[RequiredFloorClaim], declared: &[(String, String)], -) -> Result, String> { + in_flight_wall_cap_ms: u64, +) -> Result<(), String> { use super::claim_call_site_demand::{ CallSiteDemandObserver, CallSiteDemandRow, CLOSED_ARGUMENT_NORMALIZER, }; @@ -6925,19 +6921,6 @@ pub(crate) fn derive_and_install_cross_claim_share( let mut nodes = Vec::new(); let mut sites: std::collections::HashSet<(String, i64, i64)> = std::collections::HashSet::new(); let mut admitted_qualified = Vec::new(); - // (producer, producer node, its admitted sites), for the post-warm re-install. - let mut admitted_rows: Vec<( - String, - std::rc::Rc, - Vec<(String, i64, i64)>, - )> = Vec::new(); - // (site module, producer, producer node, call node) -- one warm per admitted row. - let mut warm_plan: Vec<( - String, - String, - std::rc::Rc, - std::rc::Rc, - )> = Vec::new(); for row in &admitted { let Value::Record { fields: r, .. } = row else { return Err(malformed("an admitted row is not a DerivedShareRow record")); @@ -6958,7 +6941,6 @@ pub(crate) fn derive_and_install_cross_claim_share( .field(r, "sites") .and_then(|v| v1_interpreter::list_value_items(ctx, v)) .ok_or_else(|| malformed("an admitted row has no `sites` list"))?; - let mut sites_of_row: Vec<(String, i64, i64)> = Vec::new(); for site in &row_sites { let Value::Str(text) = site else { return Err(malformed("a site is not a String")); @@ -6972,7 +6954,6 @@ pub(crate) fn derive_and_install_cross_claim_share( "site `{text}` is not :-" ))); }; - sites_of_row.push(key.clone()); sites.insert(key); } eprintln!( @@ -6980,19 +6961,6 @@ pub(crate) fn derive_and_install_cross_claim_share( argument_preimage={preimage}", row_sites.len() ); - let first_site = sites_of_row - .first() - .cloned() - .ok_or_else(|| malformed(&format!("admitted producer `{producer}` carries no site")))?; - let (site_module, call) = observer.site_node(&first_site).cloned().ok_or_else(|| { - format!( - "REQUIRED-FLOOR REFUSAL cause=DerivedShareSiteUnobserved producer={producer} \ - site={} -- the derivation admitted a site this run's observer never read", - super::claim_call_site_demand::render_site(&first_site) - ) - })?; - warm_plan.push((site_module, producer.clone(), node.clone(), call)); - admitted_rows.push((producer.clone(), node.clone(), sites_of_row.clone())); admitted_qualified.push(producer); nodes.push(node); } @@ -7050,7 +7018,14 @@ pub(crate) fn derive_and_install_cross_claim_share( roster.admitted_qualified.extend(admitted_qualified); } }); - // THE WARM, grouped by site module so each module is framed once. + // NO WARM. An admitted site fills on the FIRST planned claim that actually evaluates it, so a + // site the static reach over-approximates costs nothing, and no frame is built just to measure + // a value (the first derived runs built one frame per site module -- 169 -- to warm 2523 + // identities and then discarded 2404 below the floor). The fill's evaluator steps are netted + // from the paying claim's budget by the existing fill guard, so budgets stay deterministic; its + // wall is excused from the claim's wall deadline while in flight, capped at the preparation + // wall safety limit, so a runaway fill still interrupts; and the cost floor is applied to the + // fill's own measured steps at the moment it would be retained. let cost_floor_steps = match v1_interpreter::run_in_context( ctx, &format!("{MODULE}.floor_cross_claim_share_cost_floor_eval_steps"), @@ -7068,96 +7043,13 @@ pub(crate) fn derive_and_install_cross_claim_share( )) } }; - warm_plan.sort_by(|a, b| (&a.0, &a.1).cmp(&(&b.0, &b.1))); - // Which admitted rows are retained after their warm: only these stay admitted, so a site whose - // warm declined (below the floor, not storable) is not stored at claim time either. - let mut kept_producers: std::collections::HashSet = std::collections::HashSet::new(); - let mut observations = Vec::new(); - let mut declined_warms: std::collections::BTreeMap = - std::collections::BTreeMap::new(); - let mut framed: Option<(String, v1_interpreter::InterpContext)> = None; - for (site_module, producer, node, call) in &warm_plan { - if framed - .as_ref() - .map(|(m, _)| m != site_module) - .unwrap_or(true) - { - // Drop the previous module's frame before building the next: one resident at a time. - drop(framed.take()); - let frame = floor_authority_frame(prepared, site_module).map_err(|why| { - format!( - "REQUIRED-FLOOR REFUSAL cause=DerivedShareSiteModuleUnframed \ - module={site_module} producer={producer} -- {why}" - ) - })?; - framed = Some((site_module.clone(), frame)); - } - let frame = &framed.as_ref().expect("framed above").1; - match frame.lookup_fn_node(producer) { - Some(resolved) if std::rc::Rc::ptr_eq(&resolved, node) => {} - _ => { - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=PureProducerShareFrameLookupDiverges \ - producer={producer} module={site_module} -- the site's module frame resolves \ - the producer to a different declaration than admission read from the prepared \ - graph, so the admitted identity is not the one a claim would evaluate" - )); - } - } - let (warm, observation) = observe_shared_build(false, "floor-preparation", || { - v1_interpreter::warm_cross_claim_call_site(frame, node, call, cost_floor_steps) - }); - let disposition = match &warm { - Ok(outcome) => { - kept_producers.insert(producer.clone()); - outcome.cause().to_string() - } - Err(refusal) => { - *declined_warms.entry(refusal.cause()).or_default() += 1; - refusal.cause() - } - }; - eprintln!( - "[cross-claim-share-warm] producer={producer} module={site_module} \ - disposition={disposition} cpu_ms={} wall_ms={} rss_growth_bytes={}", - observation.cpu_ms, observation.wall_ms, observation.rss_growth_bytes - ); - observations.push(( - format!("CrossClaimDerivedShareWarm/{producer}"), - observation, - )); - } - drop(framed); - // RE-INSTALL WITH THE RETAINED ROWS ONLY (replacing the derivation installed for the warm). - let mut kept_nodes = Vec::new(); - let mut kept_sites: std::collections::HashSet<(String, i64, i64)> = - std::collections::HashSet::new(); - for (producer, node, row_sites) in &admitted_rows { - if kept_producers.contains(producer) { - kept_nodes.push(node.clone()); - kept_sites.extend(row_sites.iter().cloned()); - } - } - let retained = kept_nodes.len(); - v1_interpreter::install_cross_claim_derived_share(kept_nodes, kept_sites); - PURE_PRODUCER_SHARE_ROSTER.with(|r| { - if let Some(roster) = r.borrow_mut().as_mut() { - roster.admitted_qualified.retain(|q| { - !admitted_rows.iter().any(|(p, _, _)| p == q) || kept_producers.contains(q) - }); - } - }); + v1_interpreter::install_cross_claim_cost_floor_steps(cost_floor_steps); + v1_interpreter::install_cross_claim_in_flight_wall_cap_ms(in_flight_wall_cap_ms); eprintln!( - "[floor-phase] phase=cross-claim-share-warm state=completed warmed={} retained={retained} \ - cost_floor_eval_steps={cost_floor_steps} not_stored=[{}]", - warm_plan.len(), - declined_warms - .iter() - .map(|(k, v)| format!("{k}={v}")) - .collect::>() - .join(",") + "[floor-phase] phase=cross-claim-share-install state=completed \ + cost_floor_eval_steps={cost_floor_steps} in_flight_wall_cap_ms={in_flight_wall_cap_ms}" ); - Ok(observations) + Ok(()) } /// One row of `v2.workflow.floor_pure_producer_share.floor_cross_claim_refused_candidates`: @@ -10642,24 +10534,12 @@ pub fn run_required_floor( .map(move |function| (f.module_path.clone(), function.clone())) }) .collect(); - for (which, warm) in - &derive_and_install_cross_claim_share(&prepared, &claims, &declared_claims)? - { - if warm.cpu_ms > preparation_cpu_limit_ms - || warm.wall_ms > preparation_wall_limit_ms - || warm.rss_growth_bytes > preparation_rss_growth_limit_bytes - { - return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=FloorPreparationRefused phase={which} \ - observed_cpu_ms={} observed_wall_ms={} observed_rss_growth_bytes={} \ - cpu_limit_ms={preparation_cpu_limit_ms} wall_limit_ms={preparation_wall_limit_ms} \ - rss_growth_limit_bytes={preparation_rss_growth_limit_bytes} -- a derived \ - cross-claim share warm exceeded the preparation limits (v2.workflow.required_floor); \ - no claim executed", - warm.cpu_ms, warm.wall_ms, warm.rss_growth_bytes, - )); - } - } + derive_and_install_cross_claim_share( + &prepared, + &claims, + &declared_claims, + preparation_wall_limit_ms, + )?; let mut outcome = RequiredFloorOutcome { subject_digest: prepared.subject_digest.clone(), modules_resolved: prepared.modules_resolved, diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 3b2471a7904..36a0a783230 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2041,6 +2041,8 @@ struct CrossClaimPureMemo { /// portable walk is a sound estimator of what the retained value holds. The ACTUAL byte bound review /// 57446's F2 demanded: the entry cap bounded bucket count while each value was unbounded. bytes: usize, + /// Derived-share fills declined below the declared cost floor (recomputed, not retained). + below_cost_floor: u64, /// Stores refused because the value failed TOTAL reification (`ServeCacheValueNotPortable`). /// Counted, and the most recent refusal is retained for the warm path's diagnostics. unportable_refusals: u64, @@ -2156,11 +2158,6 @@ thread_local! { /// judged closed -- stays outside the tier. static CROSS_CLAIM_SITE_GATED: RefCell> = RefCell::new(std::collections::HashSet::new()); - /// While a derived call-site warm runs, the ONE producer it may store. Nested admitted calls - /// inside the warm are recomputed rather than stored, so a warm retains exactly its own value - /// and its measured cost is its own (an entry is never spent on a nested identity whose own - /// warm has not yet been judged against the cost floor). - static CROSS_CLAIM_WARM_ONLY: std::cell::Cell> = const { std::cell::Cell::new(None) }; /// The admitted call sites of site-gated producers, as `(file, start, end)` byte spans. static CROSS_CLAIM_ADMITTED_SITES: RefCell> = RefCell::new(std::collections::HashSet::new()); @@ -2176,6 +2173,8 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_PURE_ROSTER.with(|r| r.borrow_mut().clear()); CROSS_CLAIM_SITE_GATED.with(|g| g.borrow_mut().clear()); CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().clear()); + CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(0)); + CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(0)); CROSS_CLAIM_SHARE_OBSERVER.with(|o| *o.borrow_mut() = None); // The prepared effect inputs are tier state too, and for the sharpest reason: a carry that // outlived its subject would serve a later, differently-prepared evaluation a value acquired @@ -2254,6 +2253,11 @@ pub fn install_cross_claim_share_observer(observer: Option u64 { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow().below_cost_floor) +} + /// (stores, overflow) for the cross-claim tier on this thread — receipt fodder only. pub fn cross_claim_pure_memo_counts() -> (usize, u64) { CROSS_CLAIM_PURE_MEMO.with(|m| { @@ -2297,6 +2301,7 @@ thread_local! { struct CrossClaimFillFrame { producer: String, cpu_started: u128, + wall_started: Instant, steps_started: u64, stored_children_cpu: u128, stored_children_wall: u128, @@ -2322,6 +2327,7 @@ impl CrossClaimFillGuard { s.borrow_mut().push(CrossClaimFillFrame { producer: func_name.to_string(), cpu_started, + wall_started: Instant::now(), steps_started, stored_children_cpu: 0, stored_children_wall: 0, @@ -2357,6 +2363,7 @@ impl Drop for CrossClaimFillGuard { .unwrap_or(CrossClaimFillFrame { producer: self.func_name.clone(), cpu_started: self.cpu_started, + wall_started: self.wall_started, steps_started: self.steps_started, stored_children_cpu: 0, stored_children_wall: 0, @@ -2514,6 +2521,9 @@ pub enum CrossClaimStoreOutcome { RefusedEntryCap, /// Landing the entry would push retention past `CROSS_CLAIM_PURE_MEMO_BYTE_BUDGET`. RefusedByteBudget, + /// A derived share's fill performed fewer evaluator steps than the declared cost floor, so the + /// value is recomputed rather than retained (DESIGN section 2's economic realization). + RefusedBelowCostFloor, } impl CrossClaimStoreOutcome { @@ -2546,6 +2556,7 @@ impl CrossClaimStoreOutcome { CrossClaimStoreOutcome::RefusedValueNotPortable(_) => "ServeCacheValueNotPortable", CrossClaimStoreOutcome::RefusedEntryCap => "EntryCapReached", CrossClaimStoreOutcome::RefusedByteBudget => "ByteBudgetExceeded", + CrossClaimStoreOutcome::RefusedBelowCostFloor => "BelowCostFloor", } } } @@ -2561,9 +2572,15 @@ fn store_cross_claim_pure_memo( if !cross_claim_pure_admitted(fn_node, func_name) { return CrossClaimStoreOutcome::NotAdmitted; } - if let Some(only) = CROSS_CLAIM_WARM_ONLY.with(|w| w.get()) { - if only != Rc::as_ptr(fn_node) as usize { - return CrossClaimStoreOutcome::NotAdmitted; + // THE COST FLOOR, applied to a derived producer's fill at the moment it would be retained: the + // guard measured the fill's evaluator steps, so the decision rests on this fill's own work. + if let Some(guard) = fill_guard { + let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); + let gated = + CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); + if gated && evaluator_steps().wrapping_sub(guard.steps_started) < floor { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); + return CrossClaimStoreOutcome::RefusedBelowCostFloor; } } // The same substitution the lookup makes, in the same place in the fold, so a warm and a @@ -2657,94 +2674,6 @@ pub fn take_cross_claim_store_digest(func_name: &str) -> Option { }) } -/// Why a derived call-site warm stored nothing it could serve. Typed apart so the floor counts -/// each cause: a dispatched effect means the value depends on an input the key cannot see, an -/// evaluation failure means the call is not computable in isolation (a refusal fixture, say), and -/// a store the tier declined carries its own outcome. -#[derive(Debug)] -pub enum CallSiteWarmRefusal { - DispatchedEffect { - effects: u64, - }, - /// The warm performed fewer evaluator steps than the declared cost floor, so the value is not - /// retained: below the floor, recomputing is the admitted realization (DESIGN section 2). - BelowCostFloor { - steps: u64, - }, - EvaluationFailed(String), - NotStored(CrossClaimStoreOutcome), -} - -impl CallSiteWarmRefusal { - pub fn cause(&self) -> String { - match self { - CallSiteWarmRefusal::DispatchedEffect { effects } => { - format!("DispatchedEffect(effects={effects})") - } - CallSiteWarmRefusal::BelowCostFloor { .. } => "BelowCostFloor".to_string(), - CallSiteWarmRefusal::EvaluationFailed(_) => "EvaluationFailed".to_string(), - CallSiteWarmRefusal::NotStored(outcome) => outcome.cause().to_string(), - } - } -} - -/// Warm ONE admitted call site of a derived producer in `ctx` (a frame over the site's module): -/// evaluate the site's closed arguments with no lexical bindings, call the producer, and publish -/// through the ordinary store under the same fill guard a claim-time fill holds, so the fill lands -/// in the shared-fill ledger outside the fold. `fn_node` must be the node the frame resolves the -/// callee to, which is the identity the tier keys on. -pub fn warm_cross_claim_call_site( - ctx: &InterpContext, - fn_node: &Rc, - call_node: &Rc, - cost_floor_steps: u64, -) -> Result { - with_active_ctx(ctx, || { - let func_name = fn_node.name.clone(); - let env = Env::empty(); - let effects_before = ctx.effect_dispatch_count.get(); - let args: Vec<(Option, Value)> = call_node - .children - .iter() - .filter(|arg_node| !arg_node.children.is_empty()) - .map(|arg_node| { - let name = arg_name_at(arg_node.clone(), ctx.si()); - let val = with_lexical_base_env(&env, || { - eval_expr(&arg_value(arg_node.clone()), &env, ctx) - })?; - Ok((name, val)) - }) - .collect::>() - .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; - let guard = CrossClaimFillGuard::enter(&func_name); - let steps_before = evaluator_steps(); - let previous_only = - CROSS_CLAIM_WARM_ONLY.with(|w| w.replace(Some(Rc::as_ptr(fn_node) as usize))); - let value = with_lexical_base_env(&env, || call_function(ctx, fn_node, &args, &env)); - CROSS_CLAIM_WARM_ONLY.with(|w| w.set(previous_only)); - let value = value - .map_err(|e| CallSiteWarmRefusal::EvaluationFailed(format!("{func_name}: {e}")))?; - let steps = evaluator_steps().wrapping_sub(steps_before); - let effects = ctx - .effect_dispatch_count - .get() - .saturating_sub(effects_before); - if effects != 0 { - return Err(CallSiteWarmRefusal::DispatchedEffect { effects }); - } - if steps < cost_floor_steps { - return Err(CallSiteWarmRefusal::BelowCostFloor { steps }); - } - let outcome = - store_cross_claim_pure_memo(ctx, fn_node, &func_name, &args, &value, Some(&guard)); - if outcome.is_servable() { - Ok(outcome) - } else { - Err(CallSiteWarmRefusal::NotStored(outcome)) - } - }) -} - /// ONE PREPARED EFFECT INPUT, ACQUIRED ONCE AND CARRIED. /// /// The floor acquires a committed carrier's content at PREPARATION and binds it for the @@ -3738,6 +3667,82 @@ mod cross_claim_memo_tests { } } + // THE COST FLOOR IS APPLIED AT RETENTION, TO THE FILL'S OWN STEPS. The pair varies only the + // floor: the same derived producer's fill is declined below it and stored at zero. + #[test] + fn a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored() { + use super::{ + install_cross_claim_cost_floor_steps, install_cross_claim_derived_share, + store_cross_claim_pure_memo, CrossClaimFillGuard, CrossClaimStoreOutcome, + }; + super::clear_cross_claim_pure_memos(); + let ctx = fresh_ctx(); + let derived = make_expr_node( + Rc::new(crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + no_span(), + ); + install_cross_claim_derived_share([derived.clone()], std::collections::HashSet::new()); + install_cross_claim_cost_floor_steps(u64::MAX); + let guard = CrossClaimFillGuard::enter("tm_cheap"); + let below = store_cross_claim_pure_memo( + &ctx, + &derived, + "tm_cheap", + &[], + &Value::Int(1), + Some(&guard), + ); + drop(guard); + assert_eq!(below, CrossClaimStoreOutcome::RefusedBelowCostFloor); + assert_eq!(super::cross_claim_below_cost_floor_count(), 1); + install_cross_claim_cost_floor_steps(0); + let guard = CrossClaimFillGuard::enter("tm_cheap"); + let stored = store_cross_claim_pure_memo( + &ctx, + &derived, + "tm_cheap", + &[], + &Value::Int(1), + Some(&guard), + ); + drop(guard); + assert_eq!(stored, CrossClaimStoreOutcome::Stored); + super::clear_cross_claim_pure_memos(); + } + + // AN IN-FLIGHT FILL'S WALL IS EXCUSED ONLY UP TO THE CAP, AND NOTHING WITHOUT ONE. + #[test] + fn in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one() { + use super::{ + in_flight_cross_claim_fill_wall_nanos, install_cross_claim_in_flight_wall_cap_ms, + CrossClaimFillGuard, + }; + super::clear_cross_claim_pure_memos(); + let guard = CrossClaimFillGuard::enter("tm_slow"); + std::thread::sleep(std::time::Duration::from_millis(5)); + assert_eq!( + in_flight_cross_claim_fill_wall_nanos(), + 0, + "no cap installed, nothing excused" + ); + install_cross_claim_in_flight_wall_cap_ms(1); + let excused = in_flight_cross_claim_fill_wall_nanos(); + assert_eq!( + excused, 1_000_000, + "a 5ms fill against a 1ms cap is excused exactly the cap" + ); + drop(guard); + assert_eq!( + in_flight_cross_claim_fill_wall_nanos(), + 0, + "no fill in flight, nothing excused" + ); + super::clear_cross_claim_pure_memos(); + } + // THE SITE GATE OF THE DERIVED SHARE. A derived producer is admitted at the call sites the // derivation judged closed and nowhere else: the same producer called from another site has an // argument row nobody judged, so it must stay outside the tier. The discriminating pair varies @@ -6067,7 +6072,11 @@ impl InterpContext { let fill_since = crate::cli_run::shared_artifact_fill_wall_nanos().saturating_sub(fill_at_arm); Some(( - start.elapsed().as_nanos().saturating_sub(fill_since), + start + .elapsed() + .as_nanos() + .saturating_sub(fill_since) + .saturating_sub(in_flight_cross_claim_fill_wall_nanos()), budget_ms, )) } @@ -6832,6 +6841,48 @@ pub fn shared_artifact_fill_cpu_nanos() -> u128 { SHARED_ARTIFACT_FILL_CPU_NANOS.with(|c| c.get()) } +thread_local! { + /// The most wall time an IN-FLIGHT admitted fill may be excused from a claim's wall deadline. + /// Zero (the default) excuses nothing. The floor installs its preparation wall safety limit, + /// so a fill a claim performs on first touch is bounded exactly as a preparation build is, + /// and a runaway fill still interrupts. + static CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS: std::cell::Cell = const { std::cell::Cell::new(0) }; + /// The declared cost floor (evaluator steps) below which a derived share's fill is not + /// retained. Zero (the default) retains every admitted fill. + static CROSS_CLAIM_COST_FLOOR_STEPS: std::cell::Cell = const { std::cell::Cell::new(0) }; +} + +/// Install the in-flight fill wall cap (see `CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS`). +pub fn install_cross_claim_in_flight_wall_cap_ms(cap_ms: u64) { + CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(u128::from(cap_ms) * 1_000_000)); +} + +/// Install the derived share's cost floor (see `CROSS_CLAIM_COST_FLOOR_STEPS`). +pub fn install_cross_claim_cost_floor_steps(steps: u64) { + CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(steps)); +} + +/// Wall time the outermost in-flight admitted fill has run, less its stored children (already +/// netted when they completed), capped at the installed cap. This is the wall-clock sibling of +/// `in_flight_cross_claim_fill`: a claim that first-touches a shared fill is not charged the +/// fill's wall while it runs, exactly as it is not charged it once it completes. +fn in_flight_cross_claim_fill_wall_nanos() -> u128 { + let cap = CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.get()); + if cap == 0 { + return 0; + } + CROSS_CLAIM_FILL_FRAMES.with(|frames| { + frames.borrow().first().map_or(0, |outermost| { + outermost + .wall_started + .elapsed() + .as_nanos() + .saturating_sub(outermost.stored_children_wall) + .min(cap) + }) + }) +} + fn in_flight_cross_claim_fill(raw_cpu_nanos: u128) -> Option<(String, u128)> { CROSS_CLAIM_FILL_FRAMES.with(|frames| { frames.borrow().first().map(|outermost| { From dbaf1d88e5f7f7e0d0ea9ebb4e970a6d7ff9b283 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 12:02:31 +0000 Subject: [PATCH 12/33] Derived share: a site gate never narrows an existing admission Planning probe 37114012751 (all 111 roster-row test modules planned) showed 59 claims each re-preparing the grammar (prepare_grammar, ~1.8M steps / ~4.9s per claim): the derivation also admitted v2.compiler.parse.prepare_grammar at its closed-argument sites, which put its node in the site-gated set and withdrew the built-in arm's admission at every other site. install_cross_claim_derived_share now gates only producers the derivation alone admits; the built-in prepare_grammar arm and roster (carried-input) producers keep every site. Control: a_derived_admission_never_gates_a_producer_already_admitted_ungated. Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v1/stage0/src/v1_interpreter.rs | 57 ++++++++++++++++++++++++++--- 1 file changed, 52 insertions(+), 5 deletions(-) diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 36a0a783230..44986af0d19 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2215,18 +2215,28 @@ pub fn install_cross_claim_derived_share>>( // admitted everywhere, the widening this gate exists to prevent. let previous: Vec = CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().iter().copied().collect()); - CROSS_CLAIM_PURE_ROSTER.with(|r| { + // A SITE GATE MAY ONLY NARROW WHAT THE DERIVATION ALONE ADMITS. A producer already admitted + // without a gate -- a carried-input producer on the roster, or the built-in `prepare_grammar` + // arm admitted by name -- keeps every call site: gating it would withdraw an admission the + // derivation never granted, which is how floor probe 37114012751 made 59 claims each + // re-prepare the grammar. + let gated: Vec = CROSS_CLAIM_PURE_ROSTER.with(|r| { let mut r = r.borrow_mut(); for ptr in &previous { r.remove(ptr); } + let mut gated = Vec::new(); for node in &nodes { - r.insert(Rc::as_ptr(node) as usize); + let ptr = Rc::as_ptr(node) as usize; + if node.name == "prepare_grammar" || r.contains(&ptr) { + continue; + } + r.insert(ptr); + gated.push(ptr); } + gated }); - CROSS_CLAIM_SITE_GATED.with(|g| { - *g.borrow_mut() = nodes.iter().map(|n| Rc::as_ptr(n) as usize).collect(); - }); + CROSS_CLAIM_SITE_GATED.with(|g| *g.borrow_mut() = gated.into_iter().collect()); CROSS_CLAIM_ADMITTED_SITES.with(|a| *a.borrow_mut() = sites); for node in &nodes { keep_cross_claim_fn(node); @@ -3667,6 +3677,43 @@ mod cross_claim_memo_tests { } } + // THE GATE NEVER NARROWS AN EXISTING ADMISSION: a producer admitted ungated before the derived + // share is installed (here, by the roster) keeps every call site even when the derivation also + // admits it at one site. + #[test] + fn a_derived_admission_never_gates_a_producer_already_admitted_ungated() { + use super::{ + cross_claim_site_admitted, install_cross_claim_derived_share, + install_cross_claim_pure_share_roster, + }; + super::clear_cross_claim_pure_memos(); + let node_at = |start: i64, end: i64| { + make_expr_node( + Rc::new( + crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic, + ), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + Rc::new(crate::std_types::SourceSpan { + file: "workspace/src/g.dag".to_string(), + start, + end, + }), + ) + }; + let carried = node_at(0, 1); + install_cross_claim_pure_share_roster([carried.clone()]); + let mut sites = std::collections::HashSet::new(); + sites.insert(("workspace/src/g.dag".to_string(), 10, 20)); + install_cross_claim_derived_share([carried.clone()], sites); + assert!( + cross_claim_site_admitted(&carried, &node_at(50, 60)), + "an already-admitted producer keeps a site the derivation did not list" + ); + super::clear_cross_claim_pure_memos(); + } + // THE COST FLOOR IS APPLIED AT RETENTION, TO THE FILL'S OWN STEPS. The pair varies only the // floor: the same derived producer's fill is declined below it and stored at zero. #[test] From 183afcf6224b6f120d2f2b54b9fc51557589c34a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 13:06:54 +0000 Subject: [PATCH 13/33] Class-2 dispositions from the planning probe: 25 more withheld as declared cost debt The planning probe (dispatch 37121610250: every test module behind a deleted or main-added roster row planned, on the site-gate-fixed head; control 37117342059 at main 2d8bfebfe5 with the same touches) finds 25 claims over the new-witness budget only with the roster deleted (two materially worse), each the sole declared claim of its fixture producer. Per sharp-raven-357's class-2 ruling they are declared cost debt (floor_cost_debt_proven_chunk_23, measured steps beside each, trigger the s3 witness rule) and join the population of gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. The probe's four failures fail identically at main (pre-existing reds that only run when their modules are touched) and are not this change's. Co-Authored-By: Claude Opus 5.5 (1M context) --- ...d_share_single_claim_fixtures_withheld.dag | 29 ++++++++++++- docs/design-rung-drops.md | 2 +- src/v2/workflow/floor_cost_debt.dag | 41 ++++++++++++++++++- 3 files changed, 68 insertions(+), 4 deletions(-) diff --git a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag index 514e74f7e5e..85e3fed9134 100644 --- a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag +++ b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag @@ -16,7 +16,7 @@ data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { declaration: TypedDeclaration { previous: MechanicallyPreventable, temporary: Mitigatable, - reason: LostAsPassenger { carrier: "gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22" }, + reason: LostAsPassenger { carrier: "gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23" }, population: [ "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499)", "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499)", @@ -37,7 +37,32 @@ data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499)", "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499)", "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499)" + "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499)", + "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250)", + "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250)", + "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250)", + "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250)", + "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250)", + "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250)", + "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250)", + "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250)", + "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250)", + "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250)", + "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250)", + "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250)", + "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250)", + "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=244093 at planning probe 37121610250)", + "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250)", + "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250)", + "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250)", + "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250)", + "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250)", + "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250)", + "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250)", + "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250)", + "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250)", + "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250)", + "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250)" ], restoration_trigger: "Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected.", } diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 976e3aeaba6..771398327ed 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -170,7 +170,7 @@ Required lanes do not resolve product-layer modules: a module outside the nomina ### the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation — declared 2026-10-03 -the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. +the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=244093 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02 diff --git a/src/v2/workflow/floor_cost_debt.dag b/src/v2/workflow/floor_cost_debt.dag index 4a8cd384f73..c1738919175 100644 --- a/src/v2/workflow/floor_cost_debt.dag +++ b/src/v2/workflow/floor_cost_debt.dag @@ -1056,8 +1056,47 @@ fn floor_cost_debt_proven_chunk_22() -> List { Cons { head: "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}} } +// PROVEN, SAME CAUSE AND RULING AS chunk_22, found by the planning probe rather than by this PR's own +// plan: a measurement-only branch touched every test module behind a deleted (or main-added) roster +// row so the floor planned their claims (dispatch 37121610250, on head dbaf1d8b; control at main +// 2d8bfebfe5 with the same touches, dispatch 37117342059). These claims are over the new-witness +// eval-step budget only with the roster deleted (or, for the two compiler witnesses, materially +// worse: 75073 to 127165 and 82477 to 313895), each the sole declared claim of its fixture +// producer. Measured on 37121610250, verdict reached: +// v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds eval_steps=186193 +// v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder eval_steps=286881 +// v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument eval_steps=265244 +// v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure eval_steps=725632 +// v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds eval_steps=172733 +// v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds eval_steps=105937 +// v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds eval_steps=127165 +// v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds eval_steps=105391 +// v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds eval_steps=313895 +// v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds eval_steps=367569 +// v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home eval_steps=180783 +// v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding eval_steps=377459 +// v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering eval_steps=356677 +// v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds eval_steps=244093 +// v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds eval_steps=517942 +// v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds eval_steps=390189 +// v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds eval_steps=297034 +// v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds eval_steps=270790 +// v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds eval_steps=146906 +// v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds eval_steps=103287 +// v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds eval_steps=88547 +// v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind eval_steps=400797 +// v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds eval_steps=211532 +// v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds eval_steps=213264 +// v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds eval_steps=107371 +// TRIGGER: as chunk_22 -- the claim's module supplies its subject at the interface it judges and +// keeps ONE inhabitance claim on the real path; rung drop +// gunbc.rung_drop.derived_share_single_claim_fixtures_withheld carries the population. +fn floor_cost_debt_proven_chunk_23() -> List { + Cons { head: "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds", tail: Cons { head: "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder", tail: Cons { head: "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument", tail: Cons { head: "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure", tail: Cons { head: "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds", tail: Cons { head: "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds", tail: Cons { head: "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds", tail: Cons { head: "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds", tail: Cons { head: "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds", tail: Cons { head: "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds", tail: Cons { head: "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home", tail: Cons { head: "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding", tail: Cons { head: "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds", tail: Cons { head: "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds", tail: Cons { head: "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds", tail: Cons { head: "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds", tail: Cons { head: "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds", tail: Cons { head: "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds", tail: Cons { head: "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind", tail: Cons { head: "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds", tail: Cons { head: "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds", tail: Cons { head: "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}}}}}}} +} + fn floor_cost_debt_proven_chunks() -> List> { - Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Cons { head: floor_cost_debt_proven_chunk_22(), tail: Empty {} } } } } } } } } } } } }}}}}}}}}}}} + Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Cons { head: floor_cost_debt_proven_chunk_22(), tail: Cons { head: floor_cost_debt_proven_chunk_23(), tail: Empty {} } } } } } } } } } } } } }}}}}}}}}}}} } fn floor_cost_debt_censored_chunks() -> List> { From 808dcccbc431679df99df78ad85e83ef359c6b72 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 14:05:23 +0000 Subject: [PATCH 14/33] Cost debt: one identity was withheld twice floor run 37125103721 refused: floor_cost_debt_roster duplicate withheld identity reference_conservation.a_string_literal_is_conserved_by_its_value_holds, already in chunk_22 and re-added to chunk_23 from the planning probe. Removed from chunk_23 and from the second mention in the rung drop population; docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../rung_drop/derived_share_single_claim_fixtures_withheld.dag | 1 - docs/design-rung-drops.md | 2 +- src/v2/workflow/floor_cost_debt.dag | 3 +-- 3 files changed, 2 insertions(+), 4 deletions(-) diff --git a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag index 85e3fed9134..096b606aa7d 100644 --- a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag +++ b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag @@ -51,7 +51,6 @@ data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250)", "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250)", "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250)", - "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=244093 at planning probe 37121610250)", "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250)", "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250)", "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250)", diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 771398327ed..7f055a0f6b8 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -170,7 +170,7 @@ Required lanes do not resolve product-layer modules: a module outside the nomina ### the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation — declared 2026-10-03 -the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=244093 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. +the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02 diff --git a/src/v2/workflow/floor_cost_debt.dag b/src/v2/workflow/floor_cost_debt.dag index c1738919175..0ec34e29e29 100644 --- a/src/v2/workflow/floor_cost_debt.dag +++ b/src/v2/workflow/floor_cost_debt.dag @@ -1076,7 +1076,6 @@ fn floor_cost_debt_proven_chunk_22() -> List { // v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home eval_steps=180783 // v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding eval_steps=377459 // v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering eval_steps=356677 -// v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds eval_steps=244093 // v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds eval_steps=517942 // v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds eval_steps=390189 // v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds eval_steps=297034 @@ -1092,7 +1091,7 @@ fn floor_cost_debt_proven_chunk_22() -> List { // keeps ONE inhabitance claim on the real path; rung drop // gunbc.rung_drop.derived_share_single_claim_fixtures_withheld carries the population. fn floor_cost_debt_proven_chunk_23() -> List { - Cons { head: "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds", tail: Cons { head: "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder", tail: Cons { head: "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument", tail: Cons { head: "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure", tail: Cons { head: "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds", tail: Cons { head: "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds", tail: Cons { head: "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds", tail: Cons { head: "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds", tail: Cons { head: "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds", tail: Cons { head: "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds", tail: Cons { head: "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home", tail: Cons { head: "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding", tail: Cons { head: "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds", tail: Cons { head: "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds", tail: Cons { head: "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds", tail: Cons { head: "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds", tail: Cons { head: "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds", tail: Cons { head: "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds", tail: Cons { head: "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind", tail: Cons { head: "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds", tail: Cons { head: "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds", tail: Cons { head: "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}}}}}}} + Cons { head: "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds", tail: Cons { head: "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder", tail: Cons { head: "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument", tail: Cons { head: "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure", tail: Cons { head: "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds", tail: Cons { head: "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds", tail: Cons { head: "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds", tail: Cons { head: "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds", tail: Cons { head: "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds", tail: Cons { head: "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds", tail: Cons { head: "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home", tail: Cons { head: "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding", tail: Cons { head: "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds", tail: Cons { head: "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds", tail: Cons { head: "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds", tail: Cons { head: "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds", tail: Cons { head: "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds", tail: Cons { head: "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds", tail: Cons { head: "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind", tail: Cons { head: "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds", tail: Cons { head: "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds", tail: Cons { head: "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}}}}}} } fn floor_cost_debt_proven_chunks() -> List> { From ded8a88509151e48c78fcce4861e6da3a2c4ba95 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 16:06:17 +0000 Subject: [PATCH 15/33] Rung drop: the restoration trigger covers both cost-debt chunks review 74858: the population spans floor_cost_debt_proven_chunk_22 and chunk_23 but the trigger named only chunk_22, so the 24 chunk_23 rows could never retire it (DESIGN s4b(3): a plural loss with a singular trigger). The trigger now names both chunks and states that the row retires when every claim in the population has left its chunk. docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../rung_drop/derived_share_single_claim_fixtures_withheld.dag | 2 +- docs/design-rung-drops.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag index 096b606aa7d..09b431cc9dd 100644 --- a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag +++ b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag @@ -63,6 +63,6 @@ data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250)", "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250)" ], - restoration_trigger: "Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected.", + restoration_trigger: "Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves its v2.workflow.floor_cost_debt chunk (floor_cost_debt_proven_chunk_22 or floor_cost_debt_proven_chunk_23, whichever lists it) through the debt-removal transaction; the row is retired when every claim in the population has left its chunk. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected.", } } diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index deac77d956e..81f1246d549 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -170,7 +170,7 @@ Required lanes do not resolve product-layer modules: a module outside the nomina ### the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation — declared 2026-10-03 -the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves floor_cost_debt_proven_chunk_22 through the debt-removal transaction. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. +the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves its v2.workflow.floor_cost_debt chunk (floor_cost_debt_proven_chunk_22 or floor_cost_debt_proven_chunk_23, whichever lists it) through the debt-removal transaction; the row is retired when every claim in the population has left its chunk. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02 From c5cff13123bd86eed7fe59c86aa0350667144566 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 16:33:09 +0000 Subject: [PATCH 16/33] Single-claim fill debt: 345 claims keep running, each transfer named per claim sharp-raven-357 ruling A. The full planning probe (PR 37131459602 vs main 37131472056, every test declaration in the roster-row modules planned at one revision) found 344 claims over the new-witness budget only with the hand roster deleted, each the sole declared demander of its fixture producer: most of the deleted roster billed a claim's own fixture to preparation rather than sharing anything. - v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt: a monotone debt set, 345 claims in 69 modules, generated once from the probe and marked so. Standing is ActiveFillDebt or RetiredFillDebt with a typed disposition (RestructuredPerWitnessRule, BecameSharedByDemand, ClaimDeleted). - derive_cross_claim_share admits a one-claim identity only when its sole claim is an active member, with basis SingleClaimFillDebt naming the claim; a shared identity keeps basis SharedByDeclaredDemand. The claim's own fill is then netted from its budget by the existing fill guard, so the claim keeps running. - The seed realizes the identity join: a planned active member with no admitted fixture identity refuses SingleClaimFillDebtStale. - One mechanism: the 45 claims first withheld as cost debt (floor_cost_debt_proven_chunk_22/23) and their rung drop are removed, so their verdicts return. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 2 +- ...d_share_single_claim_fixtures_withheld.dag | 68 -- dag/gunbc/rung_drop/roster.dag | 2 - docs/design-rung-drops.md | 4 - .../src/cli_run/required_floor_runner.rs | 79 +- .../pure_producer_share_refusal_test.dag | 78 +- src/v2/workflow/floor_cost_debt.dag | 79 +- src/v2/workflow/floor_pure_producer_share.dag | 830 +++++++++++++++++- 8 files changed, 976 insertions(+), 166 deletions(-) delete mode 100644 dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 3550d903f56..bbbad26282a 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -35,7 +35,7 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag b/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag deleted file mode 100644 index 09b431cc9dd..00000000000 --- a/dag/gunbc/rung_drop/derived_share_single_claim_fixtures_withheld.dag +++ /dev/null @@ -1,68 +0,0 @@ -module gunbc.rung_drop.derived_share_single_claim_fixtures_withheld - -import std.types { NonEmptyStr } -import gunbc.rung_drop { RungDrop, Standing, TypedDeclaration, LostAsPassenger } -import gunbc.guarantee_rung { Mitigatable, MechanicallyPreventable } - -data derived_share_single_claim_fixtures_withheld: RungDrop = RungDrop { - identity: "derived_share_single_claim_fixtures_withheld" as NonEmptyStr, - - subject: "the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation", - - declared: "2026-10-03", - - standing: Standing, - - declaration: TypedDeclaration { - previous: MechanicallyPreventable, - temporary: Mitigatable, - reason: LostAsPassenger { carrier: "gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23" }, - population: [ - "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499)", - "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499)", - "v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499)", - "v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499)", - "v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499)", - "v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499)", - "v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499)", - "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499)", - "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250)", - "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250)", - "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250)", - "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250)", - "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250)", - "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250)", - "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250)", - "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250)", - "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250)", - "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250)", - "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250)", - "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250)", - "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250)", - "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250)", - "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250)", - "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250)", - "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250)", - "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250)", - "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250)", - "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250)", - "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250)", - "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250)", - "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250)", - "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250)" - ], - restoration_trigger: "Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves its v2.workflow.floor_cost_debt chunk (floor_cost_debt_proven_chunk_22 or floor_cost_debt_proven_chunk_23, whichever lists it) through the debt-removal transaction; the row is retired when every claim in the population has left its chunk. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected.", - } -} diff --git a/dag/gunbc/rung_drop/roster.dag b/dag/gunbc/rung_drop/roster.dag index d5a7b6cc107..673109d1af0 100644 --- a/dag/gunbc/rung_drop/roster.dag +++ b/dag/gunbc/rung_drop/roster.dag @@ -46,7 +46,6 @@ import gunbc.rung_drop.the_job_user_holds_a_path_unrestricted_root_grant { the_j import gunbc.rung_drop.required_lanes_do_not_resolve_product_layer_modules { required_lanes_do_not_resolve_product_layer_modules } import gunbc.rung_drop.emit_copy_qualification_without_a_consumer { emit_copy_qualification_without_a_consumer } import gunbc.rung_drop.floor_cost_high_cpu_withheld { floor_cost_high_cpu_withheld } -import gunbc.rung_drop.derived_share_single_claim_fixtures_withheld { derived_share_single_claim_fixtures_withheld } import gunbc.rung_drop.spark_role_scoped_retirement_production_root { spark_role_scoped_retirement_production_root } import gunbc.rung_drop.builtin_signature_arity_pairing_fabricates { builtin_signature_arity_pairing_fabricates } import gunbc.rung_drop.concat_binary_signature_exempt_from_arg_binding { concat_binary_signature_exempt_from_arg_binding } @@ -152,7 +151,6 @@ data rung_drop_roster: List = [ required_lanes_do_not_resolve_product_layer_modules, emit_copy_qualification_without_a_consumer, floor_cost_high_cpu_withheld, - derived_share_single_claim_fixtures_withheld, spark_role_scoped_retirement_production_root, builtin_signature_arity_pairing_fabricates, concat_binary_signature_exempt_from_arg_binding, diff --git a/docs/design-rung-drops.md b/docs/design-rung-drops.md index 81f1246d549..9251cffc5f6 100644 --- a/docs/design-rung-drops.md +++ b/docs/design-rung-drops.md @@ -168,10 +168,6 @@ Required lanes do not resolve product-layer modules: a module outside the nomina **132 REQUIRED WITNESSES AT OR ABOVE 219 CPU-MS LEAVE THE FLOOR TO STOP A COIN-FLIP GATE (2026-09-04).** main was refusing intermittently on cost alone: four DISTINCT identities across three runs at 502, 508, 519 and 568 cpu-ms against the 500ms stop, one of them by 2ms, every run reporting passed=3525 and claims_failed=0. No witness was wrong; which one lost was a coin flip, and a merge block nobody can act on is the uninformative-signal failure `gunbc.witness_floor_workflow` warns about when it says a lane may be promoted only when a red in it DISCRIMINATES. PREVIOUS RUNG: mechanically preventable -- these 132 executed on the required floor and a regression in any of them blocked a merge. TEMPORARY RUNG: mitigatable -- they remain authored, correct and executable, and `floor_cost_debt_roster` withholds them AT BUILD so the identity join still balances; what is gone is their merge-blocking authority. THE THRESHOLD IS DERIVED, NOT CHOSEN, AND THAT IS THE WHOLE OF WHY IT IS 219 AND NOT THE OPERATOR'S PERMISSIVE 100. `gunbc.rung_drop` `floor_cost_claim_qualification_unavailable` measures the per-identity inflation floor at 2.280x over twelve green main runs on three hosts, so 500 / 2.280 = 219 cpu-ms is the LOWEST BASELINE THAT CAN REACH THE STOP; it is that row's own attention constant, named here rather than re-derived. The operator authorised anything above 100ms, which is 316 identities. Withdrawing at 219 takes 132 and leaves 184 rows on the floor that cannot trip the line under the measured floor, because withdrawn coverage is safety spent and 184 rows is a large price for no reduction in flapping. A LOWER LINE IS AVAILABLE IF THE FLOOR RISES: 2.280 is a floor and the row says it can only rise, so if a larger inflation is measured this constant falls and the population grows -- that is a re-derivation, not a re-argument. BOUNDED POPULATION: the 132 identities measured `cost_reading=observed` at or above 219 cpu-ms in the green main run 33841933739. 130 of them are enrolled by this row in `v2.workflow.floor_cost_debt` proven chunks 14-20; the remaining TWO -- `produced_decl_module_folds_declarations_in_order` and `produced_decl_two_targets_render_own_order` -- were rostered by gunbc#10389 while this branch was open and are NOT re-enrolled here. The roster totals 421 identities. THAT SPLIT IS RECORDED RATHER THAN TIDIED AWAY BECAUSE IT COST A CI FAILURE: this row's chunks were generated mechanically from the cost TSV, deep-wolf-853 had named those two rows as gunbc#10389's, the reply agreeing to leave them alone was never applied to the artifact, and the duplicate only became reachable when main merged in. `floor_cost_debt_roster` refused it fail-closed -- `duplicate withheld identity` -- before running a single claim, which is the roster behaving correctly and the generation step behaving carelessly. The uniqueness check that would have caught it was run BEFORE the merge, and a merge is exactly the event that can create a duplicate. THREE SUBPOPULATIONS, DISPOSITIONED SEPARATELY BECAUSE THEY END DIFFERENTLY. (1) 37 host-process execution rows (`emit_host`, `rust_emit_host_call`) build and RUN a real host program to assert the executed program agrees with eval; no fixture work moves them, so they are PERMANENT withhold candidates, not pending fixes. (2) 5 live-tree lens rows walk the repository corpus, which is what they assert about, so shrinking their input would delete the check; also permanent. Two of these are the reason cpu and not eval_steps denominates this row at all -- `wall_residue_live` costs 298ms on 28 eval_steps and `test_migration_debt` 288ms on 129, because a corpus walk is host I/O that performs almost no substrate evaluation. (3) The remaining 90 are fixture-optimizable and are being worked: deep-wolf-853's six lanes edit the witness fixtures, and gunbc#10389 owns two of the top three. A row whose baseline drops below 219 leaves this population by re-measurement. WHY eval_steps IS NOT THE DENOMINATOR, recorded because it was proposed and tested rather than dismissed: eval_steps is deterministic where cpu is not, which is a real advantage, and it MATCHES at the 100ms line (Jaccard 0.943, 316 cpu rows against 327 step rows). It DEGRADES at the tail this row is about -- 0.718 at 219ms and 0.294 at 400ms -- because it counts substrate evaluation and cannot see host I/O. The conservative step line covering every at-risk row is steps>=28, which is 3092 of 3602 rows. cpu is the only column that sees both mechanisms. RESTORATION TRIGGER, at capability grain and NOT retired by these rows getting faster: an environment-independent per-claim cost qualification -- a charge readable as a stable property of the claim rather than of the attempt -- so that a cost verdict discriminates a regression from an execution position. That is the same capability `floor_cost_claim_qualification_unavailable` names, and this row is downstream of it: while a claim's charge is not a property of the claim, no threshold anywhere makes this gate discriminate, and moving the line only moves which rows flap. Individual rows returning under 219ms is a POPULATION shrink and retires their own membership, not this row. -### the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation — declared 2026-10-03 - -the merge-blocking execution of required witnesses whose only declared claim reaches a front-end fixture producer the deleted hand share roster used to warm in preparation: RUNG DROP, mechanically preventable -> mitigatable (lost as a passenger of gunbc#13043: the hand cross-claim share roster is deleted and admission is derived from declared cross-claim demand, so a single-claim fixture fill is charged to its claim instead of to preparation (sharp-raven-357 ruling, 2026-10-03); the claims are withheld as cost debt in v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22 and floor_cost_debt_proven_chunk_23). Population: v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds (eval_steps=132825 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds (eval_steps=198260 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds (eval_steps=162404 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds (eval_steps=172723 at run 37096345499), v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds (eval_steps=87928 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds (eval_steps=1617281 at run 37096345499), v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds (eval_steps=2010279 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds (eval_steps=109109 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds (eval_steps=509842 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds (eval_steps=359882 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds (eval_steps=192203 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds (eval_steps=172464 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds (eval_steps=241864 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds (eval_steps=353331 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds (eval_steps=303359 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds (eval_steps=504422 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds (eval_steps=327104 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds (eval_steps=544612 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds (eval_steps=152556 at run 37096345499), v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds (eval_steps=184724 at run 37096345499), v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds (eval_steps=186193 at planning probe 37121610250), v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder (eval_steps=286881 at planning probe 37121610250), v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument (eval_steps=265244 at planning probe 37121610250), v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure (eval_steps=725632 at planning probe 37121610250), v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds (eval_steps=172733 at planning probe 37121610250), v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds (eval_steps=105937 at planning probe 37121610250), v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds (eval_steps=127165 at planning probe 37121610250), v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds (eval_steps=105391 at planning probe 37121610250), v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds (eval_steps=313895 at planning probe 37121610250), v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds (eval_steps=367569 at planning probe 37121610250), v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home (eval_steps=180783 at planning probe 37121610250), v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding (eval_steps=377459 at planning probe 37121610250), v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering (eval_steps=356677 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds (eval_steps=517942 at planning probe 37121610250), v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds (eval_steps=390189 at planning probe 37121610250), v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds (eval_steps=297034 at planning probe 37121610250), v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds (eval_steps=270790 at planning probe 37121610250), v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds (eval_steps=146906 at planning probe 37121610250), v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds (eval_steps=103287 at planning probe 37121610250), v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds (eval_steps=88547 at planning probe 37121610250), v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind (eval_steps=400797 at planning probe 37121610250), v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds (eval_steps=211532 at planning probe 37121610250), v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds (eval_steps=213264 at planning probe 37121610250), v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds (eval_steps=107371 at planning probe 37121610250). Restored when: Per claim: its module supplies the judged subject at the interface the claim inspects (DESIGN section 3 witness rule), with ONE inhabitance claim kept on the real front-end path, so the claim completes under the new-witness eval-step budget and leaves its v2.workflow.floor_cost_debt chunk (floor_cost_debt_proven_chunk_22 or floor_cost_debt_proven_chunk_23, whichever lists it) through the debt-removal transaction; the row is retired when every claim in the population has left its chunk. Re-enrolling a preparation warm for a single-claim producer does NOT retire this row: that is the externalization the ruling rejected. - ### Spark serving role-scoped retirement evidence at the production plan root — declared 2026-09-02 **AN OPERATOR DECISION REMOVED A BEHAVIOUR'S ONLY SUBJECT, AND THIS ROW IS THAT DECLARATION (2026-09-02).** `gunbc.spark.cell_role` assigned srv6 to `SparkTrainingCell`, and the operator withdrew that dedication as premature -- 'i wouldn't dedicate a whole node for any task - just have it converge and serve whatever task we converge it to' -- so the production roster now holds ZERO training cells. Three claims in `test.claim.spark.spark_cell_role_retirement_witness_test` entered through `fleet_converge_plan_artifact`, the root the converge actuator itself walks, and each needed a production host holding that role to have a subject at all: `w_the_production_artifact_plans_four_retirements_for_the_training_cell`, `w_the_production_artifact_plans_no_rows_for_the_converged_serving_cell`, and `w_the_production_retirement_touches_no_baseline_address`. They are DELETED rather than left silently red, because a claim whose subject no longer exists is not a failing test, and leaving it to fail would have made an operator's decision look like a regression. **PREVIOUS RUNG: mechanically preventable** -- the training arm's four retirement rows and the serving arm's zero rows were both exercised through the production root, so a planner regression that pointed `spark_serving_full_membership_plan` back at the unscoped desired members went red there. **TEMPORARY RUNG: mitigatable** -- both arms are still exercised, but only at `spark_serving_role_scoped_desired_members_in` over an authored fixture roster (`w_the_planner_scopes_desired_state_by_role`), which is a real production function and is NOT the path the converge actuator calls; the same PR added `spark_cell_role_in` and that `_in` planner variant precisely so an arm's evidence stops depending on which machines are currently assigned what. **REASON:** operator decision, recorded with its basis at `gunbc.spark.cell_role` `spark_cell_role_assignment_basis`; role is converged desired state rather than a node dedication. **POPULATION, BOUNDED:** the training arm of Spark serving role scoping and the retirement rows it produces, AS REACHED THROUGH `fleet_converge_plan_artifact`. The serving arm, the no-role refusal, the reconcile, the freeze and the apply are unaffected and their production-root claims remain enrolled. **RESTORATION TRIGGER, NAMING THE CAPABILITY:** a roster-parameterized plan artifact -- the assignment roster threaded from `fleet_converge_plan_artifact` down to `spark_serving_role_scoped_desired_members_in` -- SUFFICIENT FOR a witness to drive the production root over an authored roster and read back the four retirement rows with no production host holding `SparkTrainingCell`. Half that capability exists today: both `_in` functions take the roster; what is missing is the threading through the generic artifact entry point. **RESTORING A TRAINING CELL TO THE PRODUCTION ROSTER DOES NOT RETIRE THIS DROP** -- that would re-create the coupling between an arm's evidence and the current assignment, which is the defect this row exists to record, and it is exactly the trigger-names-less-than-the-capability failure §4b(3) warns about. diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 0581ffa252c..82e641cd960 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6921,6 +6921,8 @@ pub(crate) fn derive_and_install_cross_claim_share( let mut nodes = Vec::new(); let mut sites: std::collections::HashSet<(String, i64, i64)> = std::collections::HashSet::new(); let mut admitted_qualified = Vec::new(); + let mut billed_debt_claims: std::collections::BTreeSet = + std::collections::BTreeSet::new(); for row in &admitted { let Value::Record { fields: r, .. } = row else { return Err(malformed("an admitted row is not a DerivedShareRow record")); @@ -6956,9 +6958,27 @@ pub(crate) fn derive_and_install_cross_claim_share( }; sites.insert(key); } + // WHY the row is admitted, printed so a single-claim fill debt is never read as sharing. + let basis = match ctx.field(r, "basis") { + Some(Value::Variant { + variant_name, + fields: b, + .. + }) => { + let variant = ctx.resolve(*variant_name); + if variant == "SingleClaimFillDebt" { + let claim = text_of(b, "claim")?; + billed_debt_claims.insert(claim.clone()); + format!("SingleClaimFillDebt:{claim}") + } else { + variant + } + } + _ => return Err(malformed("an admitted row has no `basis` variant")), + }; eprintln!( - "[cross-claim-share-admitted] producer={producer} claims={claims_n} sites={} \ - argument_preimage={preimage}", + "[cross-claim-share-admitted] producer={producer} basis={basis} claims={claims_n} \ + sites={} argument_preimage={preimage}", row_sites.len() ); admitted_qualified.push(producer); @@ -7012,6 +7032,61 @@ pub(crate) fn derive_and_install_cross_claim_share( .join(","), unadmissible_rendered.join(",") ); + // THE DEBT CONTRACT'S IDENTITY JOIN (v2.workflow.floor_pure_producer_share + // floor_single_claim_fill_debt, a monotone debt set): every ACTIVE member this run PLANS must + // have at least one single-claim fixture identity admitted on its behalf. A planned member with + // none is STALE -- it was restructured, or its fixture became shared, or its cost is not a + // closed fixture at all -- and a stale row would keep asserting a transfer that no longer + // happens, so it stops the line and names the remedy. + let active_debt = match v1_interpreter::run_in_context( + ctx, + &format!("{MODULE}.floor_single_claim_fill_debt_active_claims"), + false, + ) { + Ok(v) => v1_interpreter::list_value_items(ctx, &v) + .ok_or_else(|| malformed("floor_single_claim_fill_debt_active_claims is not a list"))?, + Err(e) => { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=SingleClaimFillDebtUnreadable -- \ + floor_single_claim_fill_debt_active_claims did not evaluate: {e}" + )) + } + }; + let planned_identities: std::collections::HashSet = claims + .iter() + .map(|c| format!("{}.{}", c.module_path, c.function)) + .collect(); + let mut active_planned = 0usize; + let mut stale_debt: Vec = Vec::new(); + for member in &active_debt { + let Value::Str(member) = member else { + return Err(malformed("a fill-debt member is not a String")); + }; + let member = member.to_string(); + if planned_identities.contains(&member) { + active_planned += 1; + if !billed_debt_claims.contains(&member) { + stale_debt.push(member); + } + } + } + eprintln!( + "[floor-phase] phase=single-claim-fill-debt state=completed active_members={} \ + planned_members={active_planned} billed_members={} stale_members={}", + active_debt.len(), + billed_debt_claims.len(), + stale_debt.len() + ); + if !stale_debt.is_empty() { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=SingleClaimFillDebtStale members=[{}] -- each is an ACTIVE \ + member of v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt that this \ + run plans, and no single-claim fixture identity was admitted for it, so the row asserts \ + a cost transfer that no longer happens. Retire the row with its typed disposition \ + (RestructuredPerWitnessRule, BecameSharedByDemand or ClaimDeleted).", + stale_debt.join(",") + )); + } v1_interpreter::install_cross_claim_derived_share(nodes, sites); PURE_PRODUCER_SHARE_ROSTER.with(|r| { if let Some(roster) = r.borrow_mut().as_mut() { diff --git a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag index 8f6c385ed9d..195065de8c2 100644 --- a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag +++ b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag @@ -15,6 +15,9 @@ import v2.workflow.floor_pure_producer_share { CrossClaimShareDerivation, DeclinedShareRow, ShareDerivationDecline, DemandedByOneClaim, ReachedByNoPlannedClaim, IdentityGradeNotShareable, RefusedByMeasurement, CarriedInputProducer, LadderOwesNoCarry, + ShareBasis, SharedByDeclaredDemand, SingleClaimFillDebt, + SingleClaimFillDebtModule, SingleClaimFillDebtClaim, ActiveFillDebt, RetiredFillDebt, RestructuredPerWitnessRule, + fill_debt_active_claims, derive_cross_claim_share, floor_cross_claim_share_derivation, cross_claim_share_derivation_reconciles, derived_share_producers } @@ -83,8 +86,37 @@ data probe_carried: List = [ } ] +// One active and one retired member of a fixture debt set, in one module. +data probe_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.debt", + claims: [ + SingleClaimFillDebtClaim { claim: "owes_its_fixture", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "was_restructured", standing: RetiredFillDebt { disposition: RestructuredPerWitnessRule } } + ] + } +] + +fn probe_single_claim(producer: String, claim: String) -> CallSiteDemandObservation { + ClosedCallSiteDemand { + producer: producer, + argument_preimage: "()", + identity: probe_identity(), + claims: [claim], + planned_claims: 1, + sites: ["v2/test/debt.dag:10-40"] + } +} + +fn basis_tag(basis: ShareBasis) -> String { + match basis { + SharedByDeclaredDemand => "shared" + SingleClaimFillDebt { claim: c } => concat("debt:", c) + } +} + fn probe_derive(observations: List) -> CrossClaimShareDerivation { - derive_cross_claim_share(observations: observations, refused: probe_refused, carried: probe_carried) + derive_cross_claim_share(observations: observations, refused: probe_refused, carried: probe_carried, debt: probe_debt) } fn decline_tag(decline: ShareDerivationDecline) -> String { @@ -144,6 +176,50 @@ test fn declared_demand_no_planned_claim_reaches_is_declined_and_named() -> Bool && declined_as(d: d, producer: "v2.probe.n7.probe_unplanned", decline: ReachedByNoPlannedClaim) } +// SINGLE-CLAIM FILL DEBT IS EXPOSED, NEVER READ AS SHARING. The triple varies only the sole +// claim's standing in the debt set: an ACTIVE member's fixture identity is admitted and its basis +// NAMES the claim; a RETIRED member's and a non-member's are declined as one-claim demand. A fold +// that admitted every one-claim identity passes the first and reds the other two. +test fn an_active_debt_members_fixture_is_admitted_and_names_its_claim() -> Bool { + let d = probe_derive(observations: [probe_single_claim(producer: "v2.test.debt.fixture_a", claim: "v2.test.debt.owes_its_fixture")]) + (length(xs: d.admitted) == 1) + && any(xs: d.admitted, predicate: fn(row) { basis_tag(basis: row.basis) == "debt:v2.test.debt.owes_its_fixture" }) +} + +test fn a_retired_debt_members_fixture_is_declined_as_one_claim_demand() -> Bool { + let d = probe_derive(observations: [probe_single_claim(producer: "v2.test.debt.fixture_b", claim: "v2.test.debt.was_restructured")]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.test.debt.fixture_b", decline: DemandedByOneClaim) +} + +test fn a_non_members_fixture_is_declined_as_one_claim_demand() -> Bool { + let d = probe_derive(observations: [probe_single_claim(producer: "v2.test.debt.fixture_c", claim: "v2.test.debt.never_listed")]) + (length(xs: d.admitted) == 0) + && declined_as(d: d, producer: "v2.test.debt.fixture_c", decline: DemandedByOneClaim) +} + +// A shared identity keeps the sharing basis even when one of its demanders is a debt member. +test fn a_shared_identity_is_based_on_demand_not_debt() -> Bool { + let d = probe_derive(observations: [ + ClosedCallSiteDemand { + producer: "v2.test.debt.shared_fixture", + argument_preimage: "()", + identity: probe_identity(), + claims: ["v2.test.debt.owes_its_fixture", "v2.test.debt.another"], + planned_claims: 2, + sites: ["v2/test/debt.dag:50-60"] + } + ]) + (length(xs: d.admitted) == 1) + && any(xs: d.admitted, predicate: fn(row) { basis_tag(basis: row.basis) == "shared" }) +} + +// The active-claim projection the seed joins against lists active members only. +test fn only_active_members_are_projected_for_the_identity_join() -> Bool { + let active = fill_debt_active_claims(debt: probe_debt) + (length(xs: active) == 1) && any(xs: active, predicate: fn(c) { c == "v2.test.debt.owes_its_fixture" }) +} + // A MEASURED REFUSAL OUTRANKS DEMAND. The producer is demanded by many claims and still declined, // naming the refusal -- the literal re-proposal path of the refused-candidate class, now closed by // construction rather than by a collision wall over an authored roster. diff --git a/src/v2/workflow/floor_cost_debt.dag b/src/v2/workflow/floor_cost_debt.dag index 0ec34e29e29..ba46bbd544b 100644 --- a/src/v2/workflow/floor_cost_debt.dag +++ b/src/v2/workflow/floor_cost_debt.dag @@ -1017,85 +1017,8 @@ fn floor_cost_debt_proven_chunk_21() -> List { Cons { head: "v2.test.parse.expression_bodied_fn_decl_parse.braced_fn_decl_survives_normalize_holds", tail: Empty {} } } -// PROVEN, AND ADDED BY THE DELETION OF THE HAND SHARE ROSTER (gunbc#13043), so the shrink-only -// contract is crossed in the open and with the cause beside it. Each of these claims is the ONLY -// declared claim reaching its fixture producer (a `*_subject` / `*_route_verdict` front-end -// fixture). The deleted roster warmed those producers in preparation, which billed each claim's -// own fixture work to preparation -- DESIGN section 5's externalization: the cost hidden from the -// claim that causes it. The derived share (v2.workflow.floor_pure_producer_share -// derive_cross_claim_share) admits only declared cross-claim recurrence, so the fill is now charged -// to its claim and each completes over the new-witness eval-step budget. Ruling: sharp-raven-357, -// 2026-10-03 (class 2: disposition each claim; no class-2 claim may pass by being shared). -// Measured on the required floor of record, run 37096345499 (head f64b8f9c64), verdict reached: -// v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds eval_steps=132825 -// v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds eval_steps=198260 -// v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds eval_steps=162404 -// v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds eval_steps=172723 -// v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds eval_steps=87928 -// v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds eval_steps=1617281 -// v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds eval_steps=2010279 -// v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds eval_steps=109109 -// v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds eval_steps=509842 -// v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds eval_steps=359882 -// v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds eval_steps=192203 -// v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds eval_steps=172464 -// v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds eval_steps=241864 -// v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds eval_steps=353331 -// v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds eval_steps=303359 -// v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds eval_steps=504422 -// v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds eval_steps=327104 -// v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds eval_steps=544612 -// v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds eval_steps=152556 -// v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds eval_steps=184724 -// TRIGGER (per row, and it is the capability, not an artifact): the claim's module supplies its -// subject at the interface the claim judges (DESIGN section 3 witness rule) and keeps ONE -// inhabitance claim on the real front-end path, so this row's own eval steps fall under its budget; -// the row then leaves through the debt-removal transaction. The rung loss is declared at -// gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. -fn floor_cost_debt_proven_chunk_22() -> List { - Cons { head: "v2.test.claim.body_lowering.statement_let_bind.single_statement_body_unchanged_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_chain_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.statement_let_then_reference_lowers_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.typed_statement_let_lowers_with_its_annotation_carried_holds", tail: Cons { head: "v2.test.claim.body_lowering.statement_let_bind.unbound_statement_prefix_refuses_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.a_cast_with_no_witness_refuses_before_realization_holds", tail: Cons { head: "v2.test.claim.coercion.identity_cast_emission_route.an_admitted_identity_cast_emits_through_the_closure_route_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_block_with_a_second_statement_is_refused_not_accepted_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_list_literal_call_argument_conserves_every_element_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_named_argument_label_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_statement_let_binder_is_reported_dropped_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.a_string_literal_is_conserved_by_its_value_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.caret_symbol_payloads_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.dotted_spine_segments_keep_their_own_occurrence_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_if_arm_call_argument_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_infix_right_operand_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_third_match_arm_is_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.the_where_refinement_predicates_are_conserved_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation.two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}} -} - -// PROVEN, SAME CAUSE AND RULING AS chunk_22, found by the planning probe rather than by this PR's own -// plan: a measurement-only branch touched every test module behind a deleted (or main-added) roster -// row so the floor planned their claims (dispatch 37121610250, on head dbaf1d8b; control at main -// 2d8bfebfe5 with the same touches, dispatch 37117342059). These claims are over the new-witness -// eval-step budget only with the roster deleted (or, for the two compiler witnesses, materially -// worse: 75073 to 127165 and 82477 to 313895), each the sole declared claim of its fixture -// producer. Measured on 37121610250, verdict reached: -// v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds eval_steps=186193 -// v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder eval_steps=286881 -// v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument eval_steps=265244 -// v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure eval_steps=725632 -// v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds eval_steps=172733 -// v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds eval_steps=105937 -// v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds eval_steps=127165 -// v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds eval_steps=105391 -// v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds eval_steps=313895 -// v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds eval_steps=367569 -// v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home eval_steps=180783 -// v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding eval_steps=377459 -// v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering eval_steps=356677 -// v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds eval_steps=517942 -// v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds eval_steps=390189 -// v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds eval_steps=297034 -// v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds eval_steps=270790 -// v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds eval_steps=146906 -// v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds eval_steps=103287 -// v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds eval_steps=88547 -// v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind eval_steps=400797 -// v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds eval_steps=211532 -// v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds eval_steps=213264 -// v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds eval_steps=107371 -// TRIGGER: as chunk_22 -- the claim's module supplies its subject at the interface it judges and -// keeps ONE inhabitance claim on the real path; rung drop -// gunbc.rung_drop.derived_share_single_claim_fixtures_withheld carries the population. -fn floor_cost_debt_proven_chunk_23() -> List { - Cons { head: "v2.test.claim.binder_default_judgment.a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds", tail: Cons { head: "v2.test.claim.body_let_annotation.bla_reordered_annotation_keeps_the_initializer_outside_its_binder", tail: Cons { head: "v2.test.claim.body_lowering.enclosing_expression_structure.the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument", tail: Cons { head: "v2.test.claim.body_lowering.function_value_body_route.a_fn_returning_fn_emits_impl_fn_with_a_move_closure", tail: Cons { head: "v2.test.claim.body_lowering.map_literal.ml_a_mixed_key_brace_refuses_at_lowering_holds", tail: Cons { head: "v2.test.claim.body_lowering.plain_type_decl_lowering.a_plain_payload_single_variant_stays_a_member_holds", tail: Cons { head: "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test.etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds", tail: Cons { head: "v2.test.claim.compiler.infer_optional_at_required_witness_test.oar_the_lift_is_still_accepted_on_the_route_holds", tail: Cons { head: "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test.rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds", tail: Cons { head: "v2.test.claim.emit.module_member_emission.a_generic_member_refuses_under_its_own_reason_holds", tail: Cons { head: "v2.test.claim.machine_shape_construction_wall.gate_green_machine_shape_record_literal_in_its_home", tail: Cons { head: "v2.test.claim.match_arm_binder_frame.mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding", tail: Cons { head: "v2.test.claim.named_argument_binding.nab_malformed_named_mixes_refuse_at_lowering", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops.the_same_match_as_a_fn_body_conserves_its_scrutinee_holds", tail: Cons { head: "v2.test.claim.namespace_xl0.reference_conservation_admission.a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds", tail: Cons { head: "v2.test.claim.normalize.service_spine.an_imported_service_resolves_through_the_import_holds", tail: Cons { head: "v2.test.claim.parameter_reference.pr_ordinary_named_call_deficit_still_refuses_holds", tail: Cons { head: "v2.test.claim.parse.parameter_refinement.an_unrefined_parameter_still_normalizes_holds", tail: Cons { head: "v2.test.claim.parse.pattern_and_let_sugar.a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds", tail: Cons { head: "v2.test.claim.parse.record_field_tail.a_record_without_a_tail_still_normalizes_holds", tail: Cons { head: "v2.test.claim.where_predicate_binding.wpb_labelled_arguments_and_marker_bind", tail: Cons { head: "v2.test.long.pick_ingested_structural_lowering.pick2_ingested_swapped_arms_red_holds", tail: Cons { head: "v2.test.parse.block_expr_as_binary_operand_parse.a_bare_if_still_lowers_to_the_branch_itself_holds", tail: Cons { head: "v2.test.parse.match_arm_statement_body_parse.a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds", tail: Empty {} }}}}}}}}}}}}}}}}}}}}}}}} -} - fn floor_cost_debt_proven_chunks() -> List> { - Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Cons { head: floor_cost_debt_proven_chunk_22(), tail: Cons { head: floor_cost_debt_proven_chunk_23(), tail: Empty {} } } } } } } } } } } } } }}}}}}}}}}}} + Cons { head: floor_cost_debt_proven_chunk_00(), tail: Cons { head: floor_cost_debt_proven_chunk_01(), tail: Cons { head: floor_cost_debt_proven_chunk_02(), tail: Cons { head: floor_cost_debt_proven_chunk_03(), tail: Cons { head: floor_cost_debt_proven_chunk_04(), tail: Cons { head: floor_cost_debt_proven_chunk_05(), tail: Cons { head: floor_cost_debt_proven_chunk_06(), tail: Cons { head: floor_cost_debt_proven_chunk_07(), tail: Cons { head: floor_cost_debt_proven_chunk_08(), tail: Cons { head: floor_cost_debt_proven_chunk_09(), tail: Cons { head: floor_cost_debt_proven_chunk_10(), tail: Cons { head: floor_cost_debt_proven_chunk_11(), tail: Cons { head: floor_cost_debt_proven_chunk_12(), tail: Cons { head: floor_cost_debt_proven_chunk_13(), tail: Cons { head: floor_cost_debt_proven_chunk_14(), tail: Cons { head: floor_cost_debt_proven_chunk_15(), tail: Cons { head: floor_cost_debt_proven_chunk_16(), tail: Cons { head: floor_cost_debt_proven_chunk_17(), tail: Cons { head: floor_cost_debt_proven_chunk_18(), tail: Cons { head: floor_cost_debt_proven_chunk_19(), tail: Cons { head: floor_cost_debt_proven_chunk_20(), tail: Cons { head: floor_cost_debt_proven_chunk_21(), tail: Empty {} } } } } } } } } } } }}}}}}}}}}}} } fn floor_cost_debt_censored_chunks() -> List> { diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 0dd171ac8be..46e55379a2d 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -201,10 +201,20 @@ fn closed_demand_ladder_verdict(identity: String, claims: List) -> Ladde ) } +// WHY A ROW IS ADMITTED. `SharedByDeclaredDemand` is the reuse obligation: two or more declared +// claims demand the identity. `SingleClaimFillDebt` is NOT sharing and is named so it cannot be +// read as sharing: one declared claim demands the identity, that claim is an ACTIVE member of +// `floor_single_claim_fill_debt`, and admitting the identity nets the claim's own fixture fill from +// its budget -- a cost transfer exposed per claim (DESIGN section 5's honest arm), never a silent one. +type ShareBasis + = SharedByDeclaredDemand + | SingleClaimFillDebt { claim: String } + type DerivedShareRow { producer: String argument_preimage: String identity: String + basis: ShareBasis claims: Int sites: List } @@ -268,7 +278,8 @@ fn closed_demand_decline( claims: List, planned_claims: Int, refused_names: List, - carried_names: List + carried_names: List, + debt: List ) -> List { if identity_permits_share(ci: identity) == false { [IdentityGradeNotShareable] @@ -278,6 +289,8 @@ fn closed_demand_decline( [RefusedByMeasurement] } else if any(xs: carried_names, predicate: fn(c) { c == producer }) { [CarriedInputProducer] + } else if length(xs: sole_active_debt_claim(claims: claims, debt: debt)) == 1 { + [] } else { ladder_decline(verdict: closed_demand_ladder_verdict( identity: share_ladder_identity(producer: producer, argument_preimage: argument_preimage), @@ -286,15 +299,35 @@ fn closed_demand_decline( } } +// The identity's sole demanding claim, when there is exactly one and it is an ACTIVE debt member; +// empty otherwise. A list so the caller reads "none" without an optional. +fn sole_active_debt_claim(claims: List, debt: List) -> List { + if length(xs: claims) == 1 { + filter(xs: claims, predicate: fn(c) { fill_debt_claim_is_active(claim: c, debt: debt) }) + } else { + [] + } +} + +fn share_basis_of(claims: List, debt: List) -> ShareBasis { + let sole = sole_active_debt_claim(claims: claims, debt: debt) + if length(xs: sole) == 1 { + SingleClaimFillDebt { claim: join(sole, "") } + } else { + SharedByDeclaredDemand + } +} + fn derived_share_rows_for( observation: CallSiteDemandObservation, refused_names: List, - carried_names: List + carried_names: List, + debt: List ) -> List { match observation { ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, sites: s } => - if length(xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names)) == 0 { - [DerivedShareRow { producer: p, argument_preimage: a, identity: share_ladder_identity(producer: p, argument_preimage: a), claims: length(xs: c), sites: s }] + if length(xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names, debt: debt)) == 0 { + [DerivedShareRow { producer: p, argument_preimage: a, identity: share_ladder_identity(producer: p, argument_preimage: a), basis: share_basis_of(claims: c, debt: debt), claims: length(xs: c), sites: s }] } else { [] } @@ -305,12 +338,13 @@ fn derived_share_rows_for( fn declined_share_rows_for( observation: CallSiteDemandObservation, refused_names: List, - carried_names: List + carried_names: List, + debt: List ) -> List { match observation { ClosedCallSiteDemand { producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, sites: _ } => list_map( - xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names), + xs: closed_demand_decline(producer: p, argument_preimage: a, identity: i, claims: c, planned_claims: n, refused_names: refused_names, carried_names: carried_names, debt: debt), f: fn(d) { DeclinedShareRow { producer: p, argument_preimage: a, decline: d } } ) UnadmissibleCallSiteDemand { cause: _, claims: _, sites: _ } => [] @@ -330,13 +364,14 @@ fn unadmissible_counts_for(observation: CallSiteDemandObservation) -> List, refused: List, - carried: List + carried: List, + debt: List ) -> CrossClaimShareDerivation { let refused_names = refused_share_producers(refused: refused) let carried_names = carried_input_warm_producers(rows: carried) CrossClaimShareDerivation { - admitted: list_flat_map(xs: observations, f: fn(o) { derived_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names) }), - declined: list_flat_map(xs: observations, f: fn(o) { declined_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names) }), + admitted: list_flat_map(xs: observations, f: fn(o) { derived_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names, debt: debt) }), + declined: list_flat_map(xs: observations, f: fn(o) { declined_share_rows_for(observation: o, refused_names: refused_names, carried_names: carried_names, debt: debt) }), unadmissible: list_flat_map(xs: observations, f: fn(o) { unadmissible_counts_for(observation: o) }), } } @@ -367,7 +402,8 @@ fn floor_cross_claim_share_derivation( derive_cross_claim_share( observations: observations, refused: floor_cross_claim_refused_candidates, - carried: floor_cross_claim_carried_input_warm_rows + carried: floor_cross_claim_carried_input_warm_rows, + debt: floor_single_claim_fill_debt ) } @@ -394,6 +430,780 @@ fn derived_share_producers(derivation: CrossClaimShareDerivation) -> List +} + +fn fill_debt_standing_is_active(standing: FillDebtStanding) -> Bool { + match standing { + ActiveFillDebt => true + RetiredFillDebt { disposition: _ } => false + } +} + +// Whether a claim identity (`.`) is an active member. The module row is found +// first, so the check costs the module population plus one module's claims, not the whole set. +fn fill_debt_claim_is_active(claim: String, debt: List) -> Bool { + any(xs: debt, predicate: fn(m) { + claim.starts_with(concat(m.module, ".")) && any(xs: m.claims, predicate: fn(c) { + fill_debt_standing_is_active(standing: c.standing) && concat(m.module, concat(".", c.claim)) == claim + }) + }) +} + +// The active members as claim identities, for the seed's identity join. +fn fill_debt_active_claims(debt: List) -> List { + list_flat_map(xs: debt, f: fn(m) { + list_map( + xs: filter(xs: m.claims, predicate: fn(c) { fill_debt_standing_is_active(standing: c.standing) }), + f: fn(c) { concat(m.module, concat(".", c.claim)) } + ) + }) +} + +fn floor_single_claim_fill_debt_active_claims() -> List { + fill_debt_active_claims(debt: floor_single_claim_fill_debt) +} + +// GENERATED ONCE, NOT HAND-AUTHORED, and marked so: the population is every claim that completed +// over the new-witness eval-step budget only with the hand roster deleted, read from the planning +// probe pair that planned every test declaration in the roster-row modules at one revision (PR +// dispatch 37131459602 against main dispatch 37131472056 with the same edits), together with the +// claims this change had first withheld as cost debt (floor runs 37096345499 and 37121610250). +// Re-derive with that probe; do not extend by hand. +data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.anonymous_param_binder", + claims: [ + SingleClaimFillDebtClaim { claim: "apb_body_reference_to_an_anonymous_slot_refuses_located", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "apb_slot_label_is_the_position_in_its_own_binder_list", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "apb_two_anonymous_slots_are_accepted_as_distinct_binders", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.binder_default_judgment", + claims: [ + SingleClaimFillDebtClaim { claim: "a_default_does_not_see_a_sibling_parameter_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_default_in_a_generic_coproduct_payload_refuses_until_modeled_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_default_sees_an_outer_value_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_default_that_does_not_inhabit_its_binder_type_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_default_that_inhabits_its_binder_type_infers", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_generic_default_refuses_until_modeled_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_type_parameter_spelling_is_not_a_default_value_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_cast_node", + claims: [ + SingleClaimFillDebtClaim { claim: "bcn_call_argument_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_call_operand_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_cast_into_a_refinement_refuses_at_infer", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_cast_out_of_a_refinement_to_its_declared_carrier_widens", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_generic_target_binds_the_type_parameter", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_identity_cast_into_a_refinement_admits", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_if_arm_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_infer_admits_int_to_int", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_infer_refuses_int_to_bool", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_let_in_value_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_let_value_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_match_arm_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_refinement_of_a_refinement_widens_one_step", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_tail_cast_carries_its_target", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_undeclared_target_refuses_at_q", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bcn_value_binder_does_not_answer_the_target", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_let_annotation", + claims: [ + SingleClaimFillDebtClaim { claim: "bla_ambiguous_imported_int_refuses_rather_than_defaulting_to_the_kernel", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_ambiguous_kernel_declarations_bind_the_kernel_type", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_concrete_annotation_is_carried", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_generic_annotation_binds_the_type_parameter", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_host_text_value_at_structural_string_is_never_matched", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_imported_user_int_refuses_rather_than_binding_the_kernel_int", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_infer_admits_int_sum_ascribed_int", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_infer_refuses_int_sum_ascribed_bool", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_module_declared_bool_shadows_the_kernel_bool", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_module_declared_int_shadows_the_kernel_int", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_optional_at_a_required_let_refuses_as_a_return_and_a_field_do", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_refinement_inhabits_its_declared_carrier_at_a_let_a_return_and_a_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_refinement_of_a_refinement_widens_one_step_at_a_let_a_return_and_a_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_reordered_annotation_keeps_the_initializer_outside_its_binder", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_sibling_refinement_refuses_at_a_let_a_return_and_a_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_single_tree_module_declared_int_and_bool_bind_the_local_declaration", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_single_tree_undeclared_int_binds_the_kernel_type", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_string_literal_ascribed_int_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_symbol_literal_ascribed_int_refuses_at_the_annotation", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_type_parameter_in_value_position_refuses_located", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_unknown_unimported_type_name_still_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bla_value_binder_does_not_answer_the_annotation", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.anonymous_record", + claims: [ + SingleClaimFillDebtClaim { claim: "ar_a_binder_field_type_is_not_substituted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_a_call_argument_has_no_expected_type_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_a_coproduct_expectation_is_not_a_record_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_a_non_renaming_alias_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_a_quoted_key_takes_the_string_key_production_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_an_alias_cycle_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_headless_literals_equal_their_headed_form_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_infer_verdict_is_the_headed_forms_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_list_elements_elaborate_under_the_list_head_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ar_pure_renaming_aliases_elaborate_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.declaration_structure_preserved", + claims: [ + SingleClaimFillDebtClaim { claim: "where_refinement_clause_interior_is_not_retained_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.enclosing_expression_structure", + claims: [ + SingleClaimFillDebtClaim { claim: "a_call_with_a_match_argument_lowers_as_the_call_over_every_argument", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_operand_beside_a_match_lowers_as_the_operator_over_both_operands", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_body_walker_lowers_a_call_with_a_match_argument_as_the_call_over_every_argument", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_body_walker_lowers_an_operand_beside_a_match_as_the_operator_over_both_operands", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.function_value_body_route", + claims: [ + SingleClaimFillDebtClaim { claim: "a_curried_function_typed_return_emits_impl_fn_over_box_dyn_fn", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_fn_returning_fn_emits_impl_fn_with_a_move_closure", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.map_literal", + claims: [ + SingleClaimFillDebtClaim { claim: "ml_a_call_argument_has_no_expected_type_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_a_duplicate_key_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_a_key_of_the_wrong_kind_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_a_mixed_key_brace_refuses_at_lowering_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_a_name_keyed_brace_under_a_map_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_an_escaped_and_a_raw_key_are_one_key_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_an_int_key_under_a_string_map_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_distinct_keys_are_accepted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_headless_literal_equals_the_headed_introduction_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ml_infer_refuses_an_elaborated_value_mismatch_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.plain_type_decl_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "a_plain_alias_declares_no_members_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_plain_alias_lowers_to_the_alias_wrapper_with_no_binders_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_plain_coproduct_lowers_to_its_named_alternatives_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_plain_payload_single_variant_stays_a_member_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.qualified_construct", + claims: [ + SingleClaimFillDebtClaim { claim: "qc_a_type_tag_refuses_as_not_a_constructor_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "qc_dropping_the_qualifier_unbinds_the_constructor_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "qc_dropping_the_record_body_is_not_a_construct_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "qc_same_leaf_in_two_modules_binds_two_declarations_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.single_arm_match", + claims: [ + SingleClaimFillDebtClaim { claim: "three_arm_match_keeps_every_arm_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "zero_arm_match_still_refuses_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering.statement_let_bind", + claims: [ + SingleClaimFillDebtClaim { claim: "single_statement_body_unchanged_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "statement_let_chain_lowers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "statement_let_then_reference_lowers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "typed_statement_let_lowers_with_its_annotation_carried_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "unbound_statement_prefix_refuses_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering_block_body_call", + claims: [ + SingleClaimFillDebtClaim { claim: "body_lowering_block_body_call_reaches_arrow_body", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "body_lowering_block_call_parses_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_lowering_qualified_path", + claims: [ + SingleClaimFillDebtClaim { claim: "body_lowering_qualified_value_reaches_arrow_body_whole", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.body_type_annotation_refusal", + claims: [ + SingleClaimFillDebtClaim { claim: "btar_if_arm_fn_literal_is_not_erased", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "btar_let_annotation_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "btar_unannotated_let_accepts", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.callexec.declaration_reference_eval", + claims: [ + SingleClaimFillDebtClaim { claim: "cref_a_named_call_with_an_argument_executes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cref_a_zero_argument_named_call_executes_to_its_callee_value_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cref_an_unresolved_callee_does_not_execute_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cref_argument_dependent_execution_reaches_the_callee_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cref_the_bool_pair_separates_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cref_the_identity_callee_never_answers_the_other_argument_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.coercion.identity_cast_emission_route", + claims: [ + SingleClaimFillDebtClaim { claim: "a_cast_with_no_witness_refuses_before_realization_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_admitted_identity_cast_emits_through_the_closure_route_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.infer_expected_type_record_instantiation_witness_test", + claims: [ + SingleClaimFillDebtClaim { claim: "etr_a_nested_construct_typed_only_by_its_context_is_decided_at_its_declared_return_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "etr_a_phantom_binder_is_fixed_by_the_declared_type_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.infer_optional_at_required_witness_test", + claims: [ + SingleClaimFillDebtClaim { claim: "oar_an_optional_at_a_required_record_field_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "oar_an_optional_returned_at_a_declared_int_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "oar_the_lift_is_still_accepted_on_the_route_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.infer_record_construct_field_inhabitance_witness_test", + claims: [ + SingleClaimFillDebtClaim { claim: "rcf_a_bool_declared_field_value_of_the_wrong_type_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_construct_is_its_declared_record_at_a_declared_type_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_cross_module_records_field_value_is_counted_not_judged_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_cross_module_records_missing_field_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_generic_record_at_its_instantiation_is_accepted_and_decided_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_generic_records_second_field_must_inhabit_the_instance_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_missing_field_refuses_and_is_named_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_nested_construct_at_a_record_declared_field_is_accepted_and_decided_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_a_pattern_naming_a_subset_of_fields_is_not_a_missing_field_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_an_undeclared_field_refuses_and_is_named_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "rcf_inhabiting_field_values_are_accepted_and_decided_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.kernel_value_type_roster_witness_test", + claims: [ + SingleClaimFillDebtClaim { claim: "kvr_a_declared_bool_return_holding_an_int_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_is_counted_not_judged_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.declaration_graft_assemble", + claims: [ + SingleClaimFillDebtClaim { claim: "declaration_graft_alias_spelled_as_emitted_identity_survives_flatten", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_alias_spelled_as_production_name_survives_flatten", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_coproduct_beside_record_names_both", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_fn_only_accepts", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_record_construct_accepts", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_record_type_only_accepts_and_is_named", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_graft_where_alias_over_an_undeclared_carrier_refuses", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.declared_parameter_order", + claims: [ + SingleClaimFillDebtClaim { claim: "dpo_an_order_label_does_not_bind_to_a_name_in_scope", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dpo_eleven_anonymous_slots_bind_in_declared_order", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dpo_parameter_order_distinguishes_function_types", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.emit.module_member_emission", + claims: [ + SingleClaimFillDebtClaim { claim: "a_bare_literal_body_emits_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_bare_parameter_body_emits_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_bodyless_member_refuses_under_its_own_reason_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_bool_signature_is_spelled_by_its_realization_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_coproduct_beside_a_function_emits_both_in_source_order_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_declared_type_in_a_signature_keeps_its_name_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_generic_member_refuses_under_its_own_reason_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_payload_single_variant_emits_as_a_one_arm_enum_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_record_beside_a_function_emits_as_a_struct_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_record_with_a_where_labelled_field_is_still_a_record_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_refinement_with_a_lowered_carrier_emits_a_transparent_alias_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_where_refinement_emits_its_transparent_alias_on_the_production_route_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_alias_member_refuses_under_its_own_reason_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.field_projection.field_projection_stages", + claims: [ + SingleClaimFillDebtClaim { claim: "fps_a_cross_module_record_projection_infers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_a_multi_root_ingest_does_not_itself_break_retrieval_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_a_qualified_declaration_path_resolves_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_a_root_bound_data_value_is_not_yet_projectable_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_a_same_module_record_projection_infers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_a_scalar_receiver_still_declares_no_fields_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_an_absent_field_does_not_infer_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_an_unresolvable_provider_leaves_its_declaration_unavailable_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_the_int_field_grounds_as_an_int_parameter_does_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fps_two_fields_of_different_types_ground_differently_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.machine_shape_construction_wall", + claims: [ + SingleClaimFillDebtClaim { claim: "gate_green_machine_shape_record_literal_in_its_home", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gate_red_machine_shape_record_literal_outside_its_home", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.match_arm_binder_frame", + claims: [ + SingleClaimFillDebtClaim { claim: "mab_binder_does_not_leak_to_a_sibling_arm", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_binder_spelling_a_non_payload_declared_in_two_modules_binds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_binder_spelling_a_record_data_row_binds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_binder_spelling_a_sibling_module_binds_the_arm", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_binder_spelling_a_variant_declared_in_two_modules_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_binder_spelling_a_where_alias_binds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_declared_constructor_in_a_pattern_stays_a_declaration_reference", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_fresh_binder_binds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_misspelled_tag_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_nested_braced_and_shorthand_binders_bind", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_outer_test_code_name_still_refuses_without_a_binder", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_shadowing_binder_binds_the_arm", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_unbound_name_in_arm_body_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_unimported_constructor_in_a_pattern_refuses_rather_than_binding", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_unshadowed_binder_atom_survives", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mab_where_alias_is_not_a_record", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.match_binder.match_binder_typing", + claims: [ + SingleClaimFillDebtClaim { claim: "mbt_a_binder_hiding_a_same_named_parameter_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mbt_an_underived_arm_body_is_a_counted_frontier_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "mbt_the_sevens_call_scrutinee_is_a_counted_frontier_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.named_argument_binding", + claims: [ + SingleClaimFillDebtClaim { claim: "nab_malformed_named_mixes_refuse_at_lowering", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "nab_reordering_named_actuals_preserves_identity", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.cross_module_reference_resolution", + claims: [ + SingleClaimFillDebtClaim { claim: "a_binder_shadowing_a_root_segment_projects_from_the_binder_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_cross_module_reference_to_a_data_declaration_resolves_to_its_declaring_path_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_cross_module_reference_to_a_declared_fn_resolves_to_its_declaring_path_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_cross_module_reference_to_an_undeclared_name_refuses_unbound", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_local_receiver_method_call_never_accepts_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_re_export_resolves_to_the_home_not_the_relay_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_receiver_with_no_such_child_never_accepts_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_same_module_reference_resolves_on_the_production_route_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_selectively_imported_type_in_parameter_position_resolves_to_its_declaring_path_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_unimported_type_in_parameter_position_refuses_unbound", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_import_bound_same_leaf_targets_resolve_to_distinct_declaring_paths_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_same_leaf_targets_in_different_modules_resolve_to_distinct_declaring_paths_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.list_literal_value_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "std_algebra_own_list_literals_bind_to_its_own_qualified_names", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "std_algebra_without_freemonoid_refuses_its_own_list_literal_at_resolve", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.reference_conservation", + claims: [ + SingleClaimFillDebtClaim { claim: "a_block_with_a_second_statement_is_refused_not_accepted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_list_literal_call_argument_conserves_every_element_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_named_argument_label_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_repeated_spelling_with_one_copy_dropped_is_exactly_one_row_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_statement_let_binder_is_reported_dropped_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_string_literal_is_conserved_by_its_value_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "caret_symbol_payloads_are_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dotted_spine_segments_keep_their_own_occurrence_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_if_arm_call_argument_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_infix_right_operand_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_third_match_arm_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_where_refinement_predicates_are_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_anonymous_parameter_slots_are_conserved_by_minted_identity_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.reference_conservation_accepted_drops", + claims: [ + SingleClaimFillDebtClaim { claim: "a_binary_operand_beside_a_match_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_binary_operand_beside_an_if_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_call_argument_beside_a_match_valued_argument_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_data_initializer_match_scrutinee_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_map_literal_value_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_qualified_constructor_literal_value_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_record_field_beside_a_match_valued_field_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_statement_after_a_let_in_a_match_arm_is_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_same_match_as_a_fn_body_conserves_its_scrutinee_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.reference_conservation_admission", + claims: [ + SingleClaimFillDebtClaim { claim: "a_conserving_body_lowering_member_is_observed_conserved_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_dropping_body_lowering_member_is_observed_dropped_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_field_projection_on_a_call_result_in_an_operand_is_admitted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_operator_expression_call_argument_is_admitted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_operator_expression_in_an_if_arm_is_admitted_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "explaining_one_of_two_same_spelled_drops_leaves_the_other_refused_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.namespace_xl0.reference_conservation_census", + claims: [ + SingleClaimFillDebtClaim { claim: "a_share_under_the_floor_takes_six_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_rule_takes_its_quota_at_the_floor_indices_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.normalize.operation_modifier", + claims: [ + SingleClaimFillDebtClaim { claim: "an_operations_modifiers_lower_onto_its_contract_edges_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.normalize.resource_declaration_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "a_default_tail_lowers_onto_its_binder_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.normalize.service_realization_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "a_config_only_realization_is_held_off_the_full_route_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_unrealizable_realization_refuses_located_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_realization_facts_lower_into_the_sibling_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_siblings_of_a_shared_prefix_merge_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.normalize.service_spine", + claims: [ + SingleClaimFillDebtClaim { claim: "a_merged_namespace_body_grants_no_scope_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_namespace_body_and_a_declaration_of_one_name_refuse_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_service_declared_twice_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_service_namespace_does_not_bind_bare_on_the_resolve_route_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_service_namespace_is_a_lookup_boundary_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_imported_service_resolves_through_the_import_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_services_under_one_prefix_reach_distinct_operation_paths_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parameter_reference", + claims: [ + SingleClaimFillDebtClaim { claim: "pr_let_shadowing_a_parameter_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pr_ordinary_named_call_deficit_still_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pr_parameter_grounds_through_the_index_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.admit_callers_trailing_comma", + claims: [ + SingleClaimFillDebtClaim { claim: "a_trailing_comma_in_admit_callers_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_admit_callers_list_without_a_trailing_comma_parses_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.data_keyword_as_value", + claims: [ + SingleClaimFillDebtClaim { claim: "the_data_keyword_as_a_value_normalizes_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.default_value", + claims: [ + SingleClaimFillDebtClaim { claim: "a_record_field_default_lowers_onto_its_binder_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_service_io_default_lowers_onto_its_binder_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.expression_bodied_continuation", + claims: [ + SingleClaimFillDebtClaim { claim: "cont_braced_fn_decl_survives_normalize_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cont_expression_bodied_fn_decl_survives_normalize_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "cont_expression_bodied_literal_fn_decl_survives_normalize_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.parameter_refinement", + claims: [ + SingleClaimFillDebtClaim { claim: "an_unrefined_parameter_still_normalizes_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.pattern_and_let_sugar", + claims: [ + SingleClaimFillDebtClaim { claim: "a_bare_assignment_lowers_identically_to_let_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_generic_pattern_refuses_at_its_generic_params_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_pattern_lowers_to_the_identical_tree_as_its_fn_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_pattern_with_a_uses_clause_still_refuses_at_the_clause_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_pattern_with_an_expression_body_refuses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "node_colon_lowers_identically_to_let_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "node_eq_lowers_identically_to_let_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.record_field_tail", + claims: [ + SingleClaimFillDebtClaim { claim: "a_record_field_with_a_default_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_record_without_a_tail_still_normalizes_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.parse.where_clause_required_comma", + claims: [ + SingleClaimFillDebtClaim { claim: "a_service_after_a_refined_alias_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "comma_separated_predicates_still_parse_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.provenance.loaded_carrier_receipts", + claims: [ + SingleClaimFillDebtClaim { claim: "a_record_through_the_located_pool_is_a_declared_payload_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.reference_evidence.declaration_reference_evidence", + claims: [ + SingleClaimFillDebtClaim { claim: "dre_a_named_call_to_a_bool_fn_is_grounded_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dre_a_same_leaf_reference_gets_its_own_declarations_contract_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dre_an_imported_reference_grounds_through_the_closure_index_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dre_an_invalid_argument_call_does_not_ground_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "dre_an_unresolved_signature_does_not_ground_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.self_host.closure_emission", + claims: [ + SingleClaimFillDebtClaim { claim: "a_closure_member_whose_body_does_not_lower_refuses_the_emission_at_its_cause_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_files_declaring_one_module_refuse_the_emission_at_the_census_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.self_host.rust_module_emission_population", + claims: [ + SingleClaimFillDebtClaim { claim: "population_two_declaration_module_collects_two", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "population_two_declaration_module_refuses_whole_on_unwired_target", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.text_string_importer_census", + claims: [ + SingleClaimFillDebtClaim { claim: "tsic_every_window_predicate_matches_the_real_parse", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tsic_real_raw_parse_route_reaches_the_classifier", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tsic_rosters_are_derived_from_the_text_module_walk", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tsil_a_declined_module_is_a_named_unresolved_gap", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tsil_aliases_are_chased_to_their_declaring_module", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tsil_population_module_decides_the_bare_string", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.type_param_binder_frame", + claims: [ + SingleClaimFillDebtClaim { claim: "tpb_emitter_refuses_a_generic_arrow", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_every_declared_type_param_is_a_binder", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_alias_carries_its_binders", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_alias_param_shadowing_a_visible_name_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_alias_to_an_instantiation_lowers", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_alias_undeclared_rhs_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_nullary_coproduct_classifies_as_nullary", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_generic_single_variant_after_separator_is_a_coproduct", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_non_generic_fn_carries_no_type_params", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_non_generic_type_decl_carries_no_type_params", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_plain_single_alias_is_not_a_coproduct", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_plain_single_variant_after_separator_is_a_coproduct", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_same_spelling_in_two_declarations_does_not_alias", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_type_decl_param_does_not_leak_to_a_sibling", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_type_decl_param_shadowing_a_visible_name_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_type_param_does_not_leak_to_a_sibling_declaration", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_type_param_in_value_position_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_type_param_shadowing_a_visible_name_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tpb_undeclared_type_name_still_refuses", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.value_base_projection", + claims: [ + SingleClaimFillDebtClaim { claim: "vbp_a_param_spelled_like_the_field_is_not_captured", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vbp_undeclared_field_off_a_call_result_is_carried_on_the_direct_infer_outcome", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.where_predicate_binding", + claims: [ + SingleClaimFillDebtClaim { claim: "wpb_declared_predicate_binds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "wpb_labelled_arguments_and_marker_bind", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "wpb_second_predicate_is_bound", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "wpb_unbound_predicate_refuses", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.execution.data_decl_lowering_grounding", + claims: [ + SingleClaimFillDebtClaim { claim: "fn_eq_body_is_the_literal_not_its_digits_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.execution.infer_declaration_formation", + claims: [ + SingleClaimFillDebtClaim { claim: "a_coproduct_with_a_fielded_alternative_forms_a_sum_and_grounds_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_payloadless_coproduct_forms_a_sum_and_grounds_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.long.emit_host_classical_not_ingested_equals_eval", + claims: [ + SingleClaimFillDebtClaim { claim: "ingested_classical_not_staging_swapped_emit_accepts_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.long.pick_ingested_structural_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "pick2_ingested_pick_false_executes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pick2_ingested_pick_true_executes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pick2_ingested_swapped_arms_red_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pick_ingested_pick_false_executes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pick_ingested_pick_true_executes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "pick_ingested_swapped_arms_red_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.manual.body_lowering_projection_call", + claims: [ + SingleClaimFillDebtClaim { claim: "body_lowering_projection_lowers_to_transform", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.parse.block_expr_as_binary_operand_parse", + claims: [ + SingleClaimFillDebtClaim { claim: "a_bare_if_still_lowers_to_the_branch_itself_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "a_bare_match_still_lowers_to_the_match_itself_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bare_if_still_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "bare_match_still_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "if_heading_a_binary_chain_parses_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "match_heading_a_binary_chain_parses_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.parse.closure_parse_batch_two", + claims: [ + SingleClaimFillDebtClaim { claim: "admit_callers_clause_normalizes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "an_early_return_guard_parses_and_lowers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "declaration_named_node_projection_is_kept_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ordinary_declaration_is_kept_once_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "two_declarations_named_node_projection_normalize_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.parse.coproduct_leading_pipe_and_positional_payload_parse", + claims: [ + SingleClaimFillDebtClaim { claim: "braced_pattern_binder_still_normalizes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "leading_pipe_multiline_coproduct_parses_and_normalizes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "leading_pipe_normalizes_to_the_same_alternatives_as_without_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "positional_pattern_binder_normalizes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "positional_payload_variants_parse_and_normalize_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "positional_payload_without_leading_pipe_with_construction_normalizes_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "positional_wildcard_pattern_still_normalizes_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.parse.match_arm_statement_body_parse", + claims: [ + SingleClaimFillDebtClaim { claim: "a_match_arm_statement_body_is_stamped_and_stops_at_the_next_arm_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.parse.variant_field_lowering", + claims: [ + SingleClaimFillDebtClaim { claim: "vf_braced_pattern_binds_named_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_braced_variant_declares_named_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_content_hash_declarations_and_positional_match_normalize", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_distinct_payloads_normalize_distinct", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_positional_construction_carries_its_operand", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_positional_pattern_binds_field_zero", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_record_construction_is_the_construct_shape", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_record_declaration_is_named_with_declared_fields", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_shadowing_binder_is_carried_on_the_arm", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_shorthand_pattern_binds_field_to_its_own_name", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_single_fielded_variant_is_a_sum", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_two_positional_binders_refuse", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "vf_wildcard_pattern_keeps_its_field", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.provenance.occurrence_file_attribution", + claims: [ + SingleClaimFillDebtClaim { claim: "native_route_threads_the_occurrence_mark_across_files_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "refused_assembly_still_locates_the_files_it_parsed_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.self_host.stage0_production_target", + claims: [ + SingleClaimFillDebtClaim { claim: "stage0_production_target_emits_boundary_compatible_source_holds", standing: ActiveFillDebt } + ] + } +] + // ── REFUSED CANDIDATES: THE ROWS THIS ROSTER MEASURED AND TURNED DOWN ───────────────────── // // WHY A REFUSAL NEEDS A CARRIER AT ALL, and it is not tidiness. Until this type existed the file From ee0f88606b1f737829e5aee2c53a8775603f6c91 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 18:57:11 +0000 Subject: [PATCH 17/33] Fill debt: statement_let_then_reference_lowers_holds became shared by demand floor run 37144277836 refused SingleClaimFillDebtStale for this member: main's #13056 added a second reader of let_then_reference_subject, so the fixture is now admitted as SharedByDeclaredDemand (claims=2) and the debt row asserted a transfer that no longer happens. Retired with its typed disposition. Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 46e55379a2d..b1938f6270a 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -662,7 +662,7 @@ data floor_single_claim_fill_debt: List = [ claims: [ SingleClaimFillDebtClaim { claim: "single_statement_body_unchanged_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "statement_let_chain_lowers_holds", standing: ActiveFillDebt }, - SingleClaimFillDebtClaim { claim: "statement_let_then_reference_lowers_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "statement_let_then_reference_lowers_holds", standing: RetiredFillDebt { disposition: BecameSharedByDemand } }, SingleClaimFillDebtClaim { claim: "typed_statement_let_lowers_with_its_annotation_carried_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "unbound_statement_prefix_refuses_holds", standing: ActiveFillDebt } ] From 309c2005ef6ed977381b627dfc14d2cee1714e3f Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 19:16:14 +0000 Subject: [PATCH 18/33] Single-claim fill debt is netted, not retained; publish unkeyed admitted fills Probe 37142207751 (decline lines): the tier's 256 MiB byte budget was exhausted -- 638 stores declined across 234 producers -- because every single-claim debt fixture's value was retained although exactly one claim ever demands it. A declined store is not netted, so 106 debt members stayed over budget and 16 claims crossed the wall deadline. - A debt-basis site is NET-ONLY: its fill is measured and netted from the one claim (cost floor applied), and no value is retained. Shared identities keep the store. install_cross_claim_derived_share_with_net_only carries the subset. - The recompute-ledger branch that returned without offering an admitted fill to the tier now publishes it (the tier keys arguments itself; a net-only fill needs no key). Control: a_net_only_fill_is_netted_without_retaining_its_value. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/required_floor_runner.rs | 17 +- src/v1/stage0/src/v1_interpreter.rs | 170 ++++++++++++++++-- 2 files changed, 169 insertions(+), 18 deletions(-) diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index b2d916eb14f..ffadbce865f 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6922,6 +6922,8 @@ pub(crate) fn derive_and_install_cross_claim_share( let mut admitted_qualified = Vec::new(); let mut billed_debt_claims: std::collections::BTreeSet = std::collections::BTreeSet::new(); + let mut net_only_sites: std::collections::HashSet<(String, i64, i64)> = + std::collections::HashSet::new(); for row in &admitted { let Value::Record { fields: r, .. } = row else { return Err(malformed("an admitted row is not a DerivedShareRow record")); @@ -6942,6 +6944,7 @@ pub(crate) fn derive_and_install_cross_claim_share( .field(r, "sites") .and_then(|v| v1_interpreter::list_value_items(ctx, v)) .ok_or_else(|| malformed("an admitted row has no `sites` list"))?; + let mut row_keys: Vec<(String, i64, i64)> = Vec::new(); for site in &row_sites { let Value::Str(text) = site else { return Err(malformed("a site is not a String")); @@ -6955,9 +6958,10 @@ pub(crate) fn derive_and_install_cross_claim_share( "site `{text}` is not :-" ))); }; - sites.insert(key); + row_keys.push(key); } // WHY the row is admitted, printed so a single-claim fill debt is never read as sharing. + let mut row_is_debt = false; let basis = match ctx.field(r, "basis") { Some(Value::Variant { variant_name, @@ -6968,6 +6972,7 @@ pub(crate) fn derive_and_install_cross_claim_share( if variant == "SingleClaimFillDebt" { let claim = text_of(b, "claim")?; billed_debt_claims.insert(claim.clone()); + row_is_debt = true; format!("SingleClaimFillDebt:{claim}") } else { variant @@ -6975,6 +6980,14 @@ pub(crate) fn derive_and_install_cross_claim_share( } _ => return Err(malformed("an admitted row has no `basis` variant")), }; + // A debt row's sites are NET-ONLY: the fill is netted from its one claim and no value is + // retained, since no other claim will ever ask for it. + for key in row_keys { + if row_is_debt { + net_only_sites.insert(key.clone()); + } + sites.insert(key); + } eprintln!( "[cross-claim-share-admitted] producer={producer} basis={basis} claims={claims_n} \ sites={} argument_preimage={preimage}", @@ -7086,7 +7099,7 @@ pub(crate) fn derive_and_install_cross_claim_share( stale_debt.join(",") )); } - v1_interpreter::install_cross_claim_derived_share(nodes, sites); + v1_interpreter::install_cross_claim_derived_share_with_net_only(nodes, sites, net_only_sites); PURE_PRODUCER_SHARE_ROSTER.with(|r| { if let Some(roster) = r.borrow_mut().as_mut() { roster.admitted_qualified.extend(admitted_qualified); diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 01484d2fef3..faa7b365f32 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2169,6 +2169,13 @@ thread_local! { /// judged closed -- stays outside the tier. static CROSS_CLAIM_SITE_GATED: RefCell> = RefCell::new(std::collections::HashSet::new()); + /// The admitted sites whose fill is NETTED BUT NOT RETAINED: single-claim fill debt. Exactly + /// one declared claim demands the identity, so no later claim will ever ask for the value; + /// retaining it would spend the tier's byte budget on values nobody reads (floor probe + /// 37142207751: 638 stores declined at the byte budget, each leaving its fill on the claim). + /// The fill is measured and netted from the claim exactly as a retained one is. + static CROSS_CLAIM_NET_ONLY_SITES: RefCell> = + RefCell::new(std::collections::HashSet::new()); /// The admitted call sites of site-gated producers, as `(file, start, end)` byte spans. static CROSS_CLAIM_ADMITTED_SITES: RefCell> = RefCell::new(std::collections::HashSet::new()); @@ -2184,6 +2191,7 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_PURE_ROSTER.with(|r| r.borrow_mut().clear()); CROSS_CLAIM_SITE_GATED.with(|g| g.borrow_mut().clear()); CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().clear()); + CROSS_CLAIM_NET_ONLY_SITES.with(|n| n.borrow_mut().clear()); CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(0)); CROSS_CLAIM_STORE_DECLINES.with(|d| d.borrow_mut().clear()); CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(0)); @@ -2221,6 +2229,17 @@ pub fn install_cross_claim_derived_share>>( nodes: I, sites: std::collections::HashSet<(String, i64, i64)>, ) { + install_cross_claim_derived_share_with_net_only(nodes, sites, std::collections::HashSet::new()) +} + +/// As `install_cross_claim_derived_share`, with the subset of `sites` that are net-only (see +/// `CROSS_CLAIM_NET_ONLY_SITES`). A net-only site must also be in `sites`. +pub fn install_cross_claim_derived_share_with_net_only>>( + nodes: I, + sites: std::collections::HashSet<(String, i64, i64)>, + net_only_sites: std::collections::HashSet<(String, i64, i64)>, +) { + CROSS_CLAIM_NET_ONLY_SITES.with(|n| *n.borrow_mut() = net_only_sites); let nodes: Vec> = nodes.into_iter().collect(); // REPLACES the previous derivation rather than adding to it: a producer dropped from the // derived set must leave the roster too, or it would remain admitted with no site gate -- @@ -2270,6 +2289,50 @@ fn cross_claim_site_admitted(fn_node: &Rc, call_node: &Node) -> bool { }) } +/// Whether this call site is a net-only (single-claim fill debt) site. +fn cross_claim_site_is_net_only(call_node: &Node) -> bool { + CROSS_CLAIM_NET_ONLY_SITES.with(|n| { + let n = n.borrow(); + !n.is_empty() + && n.contains(&( + call_node.span.file.to_string(), + call_node.span.start, + call_node.span.end, + )) + }) +} + +/// Publish one completed admitted fill: retain it in the tier, or -- at a net-only site -- net its +/// cost from the paying claim without retaining the value. The cost floor applies to both: a fill +/// below it is neither retained nor netted. Every declined outcome is counted by producer. +fn publish_cross_claim_fill( + ctx: &InterpContext, + fn_node: &Rc, + func_name: &str, + args: &[(Option, Value)], + value: &Value, + fill_guard: Option<&CrossClaimFillGuard>, + net_only: bool, +) { + if net_only { + if let Some(guard) = fill_guard { + let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); + if evaluator_steps().wrapping_sub(guard.steps_started) < floor { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); + note_cross_claim_store_outcome( + func_name, + &CrossClaimStoreOutcome::RefusedBelowCostFloor, + ); + } else { + guard.mark_stored(); + } + } + return; + } + let outcome = store_cross_claim_pure_memo(ctx, fn_node, func_name, args, value, fill_guard); + note_cross_claim_store_outcome(func_name, &outcome); +} + /// Install the shared-fill observer for the cross-claim tier. `None` uninstalls. pub fn install_cross_claim_share_observer(observer: Option) { CROSS_CLAIM_SHARE_OBSERVER.with(|o| *o.borrow_mut() = observer); @@ -3755,6 +3818,64 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } + // A NET-ONLY FILL IS NETTED AND NOT RETAINED. The pair varies only whether the site is + // net-only: the same fill at a net-only site marks the guard (so the claim is netted) and + // leaves the tier empty; at a retained site it lands in the tier. + #[test] + fn a_net_only_fill_is_netted_without_retaining_its_value() { + use super::{ + cross_claim_pure_memo_counts, install_cross_claim_derived_share, + publish_cross_claim_fill, CrossClaimFillGuard, + }; + super::clear_cross_claim_pure_memos(); + let ctx = fresh_ctx(); + let derived = make_expr_node( + Rc::new(crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + no_span(), + ); + install_cross_claim_derived_share([derived.clone()], std::collections::HashSet::new()); + let guard = CrossClaimFillGuard::enter("tm_debt"); + publish_cross_claim_fill( + &ctx, + &derived, + "tm_debt", + &[], + &Value::Int(1), + Some(&guard), + true, + ); + assert!( + guard.stored.get(), + "a net-only fill is netted from its claim" + ); + drop(guard); + assert_eq!( + cross_claim_pure_memo_counts().0, + 0, + "and its value is not retained" + ); + let guard = CrossClaimFillGuard::enter("tm_debt"); + publish_cross_claim_fill( + &ctx, + &derived, + "tm_debt", + &[], + &Value::Int(1), + Some(&guard), + false, + ); + drop(guard); + assert_eq!( + cross_claim_pure_memo_counts().0, + 1, + "control: a retained site stores" + ); + super::clear_cross_claim_pure_memos(); + } + // THE COST FLOOR IS APPLIED AT RETENTION, TO THE FILL'S OWN STEPS. The pair varies only the // floor: the same derived producer's fill is declined below it and stored at zero. #[test] @@ -10176,7 +10297,8 @@ fn eval_pure_named_call( // A derived producer is admitted at its admitted call sites only; from any other site the // call neither serves nor stores, exactly as if the producer were not admitted at all. let share_site = cross_claim_site_admitted(fn_node, call_node); - if share_site { + let net_only = share_site && cross_claim_site_is_net_only(call_node); + if share_site && !net_only { if let Some(v) = try_cross_claim_pure_memo(ctx, fn_node, func_name, args) { return Ok(v); } @@ -10199,15 +10321,15 @@ fn eval_pure_named_call( // The ordinary call path publishes opportunistically: every outcome, // servable or refused, is already counted inside the store, and this // call recomputes on a refusal exactly as if never enrolled. - let outcome = store_cross_claim_pure_memo( + publish_cross_claim_fill( ctx, fn_node, func_name, args, v, fill_guard.as_ref(), + net_only, ); - note_cross_claim_store_outcome(func_name, &outcome); } } return result; @@ -10223,18 +10345,28 @@ fn eval_pure_named_call( // census, which ranks by duration. Recording after the call is what makes the two // buckets comparable; the earlier count-only form could name a producer it could // never rank. - // AN ADMITTED FILL THAT THIS BRANCH NEVER OFFERS TO THE TIER. The recompute ledger - // cannot key these arguments, and the function returns below without a cross-claim - // store, so the fill stays on the paying claim. Counted under its own cause. - if fill_guard.is_some() { - CROSS_CLAIM_STORE_DECLINES.with(|d| { - *d.borrow_mut() - .entry((func_name.to_string(), "RecomputeKeyUnavailable")) - .or_insert(0) += 1; - }); - } let partial = eval_recompute_partial_key(ctx, fn_node, args); + let effects_before = ctx.effect_dispatch_count.get(); let result = call_function(ctx, fn_node, args, env); + // THE RECOMPUTE LEDGER'S KEY IS NOT THE TIER'S. This branch is taken when the ledger + // cannot key the arguments; the tier keys them itself (or refuses, counted), and a + // net-only fill needs no key at all. Returning here without publishing left an + // admitted fill on the paying claim with nothing said (floor probe 37142207751). + if share_site { + if let Ok(v) = &result { + if ctx.effect_dispatch_count.get() == effects_before { + publish_cross_claim_fill( + ctx, + fn_node, + func_name, + args, + v, + fill_guard.as_ref(), + net_only, + ); + } + } + } eval_recompute_record_unkeyed( ctx, fn_node, @@ -10264,9 +10396,15 @@ fn eval_pure_named_call( let result = call_function(ctx, fn_node, args, env); if let Ok(v) = &result { if share_site && ctx.effect_dispatch_count.get() == effects_before { - let outcome = - store_cross_claim_pure_memo(ctx, fn_node, func_name, args, v, fill_guard.as_ref()); - note_cross_claim_store_outcome(func_name, &outcome); + publish_cross_claim_fill( + ctx, + fn_node, + func_name, + args, + v, + fill_guard.as_ref(), + net_only, + ); } } if memo_on && ctx.effect_dispatch_count.get() == effects_before { From 9184803b5166e75a14deed3efc65d36bee158eaf Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 20:59:41 +0000 Subject: [PATCH 19/33] Fill debt: five members from the later probe; receipt lists the net-only and decline-report declarations Probe 37147337255 vs main 37147367276 (127 modules, every test declaration planned): failures identical (31 each), 0 interrupted, tier byte budget not exhausted (0 overflow refusals), and only 5 claims over budget solely with this change -- single-claim fixtures behind rows main added after the debt set was generated. They join floor_single_claim_fill_debt. 31 claims that are over budget on main are not over with this change. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 11 ++++++++-- src/v2/workflow/floor_pure_producer_share.dag | 20 ++++++++++++++++++- 2 files changed, 28 insertions(+), 3 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index bbbad26282a..12fc2424ee2 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -33,9 +33,16 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_COST_FLOOR_STEPS", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration } + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_derived_share_with_net_only", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_site_is_net_only", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "publish_cross_claim_fill", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_NET_ONLY_SITES", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_STORE_DECLINES", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_store_declines", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "note_cross_claim_store_outcome", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index b1938f6270a..6aab478ec8b 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -510,8 +510,25 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // probe pair that planned every test declaration in the roster-row modules at one revision (PR // dispatch 37131459602 against main dispatch 37131472056 with the same edits), together with the // claims this change had first withheld as cost debt (floor runs 37096345499 and 37121610250). +// Five members were added from the later probe pair 37147337255 against 37147367276, which also +// planned the modules behind rows main added to the hand roster while this change was open +// (dependency_demand_census, infer_fold_member_instance, one more kernel_value_type_roster claim). // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.dependency_demand_census", + claims: [ + SingleClaimFillDebtClaim { claim: "production_lowering_of_the_same_fns_still_refuses_at_the_clause_holds", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.infer_fold_member_instance", + claims: [ + SingleClaimFillDebtClaim { claim: "fmi_fold_member_undeclared_field_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fmi_fold_over_records_is_accepted", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "fmi_fold_step_body_not_the_carrier_refuses", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.anonymous_param_binder", claims: [ @@ -741,7 +758,8 @@ data floor_single_claim_fill_debt: List = [ module: "v2.test.claim.compiler.kernel_value_type_roster_witness_test", claims: [ SingleClaimFillDebtClaim { claim: "kvr_a_declared_bool_return_holding_an_int_refuses_holds", standing: ActiveFillDebt }, - SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_is_counted_not_judged_holds", standing: ActiveFillDebt } + SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_is_counted_not_judged_holds", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_holding_an_int_refuses_holds", standing: ActiveFillDebt } ] }, SingleClaimFillDebtModule { From b172ba593413477d1b4dd0f41c52589f4add3145 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 21:10:15 +0000 Subject: [PATCH 20/33] In-flight fill wall excusal is bounded by the fill's own steps sharp-raven-357 ruling: no blanket excusal. An in-flight admitted fill's wall is excused from the claim's wall deadline only up to (its evaluator steps so far) x (a declared ns-per-step ceiling), under the preparation wall safety limit as the outer hard cap. A stalled fill accrues wall without steps and is excused nothing; the deadline refusal prints a [cross-claim-fill-wall-deadline] line naming the producer, its steps and its wall. - Policy: v2.workflow.floor_pure_producer_share floor_cross_claim_fill_wall_ns_per_step_ceiling (25000), with its reason and the run it was set against cited. - Control: a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 6 +- .../src/cli_run/required_floor_runner.rs | 32 ++++- src/v1/stage0/src/v1_interpreter.rs | 116 +++++++++++++----- src/v2/workflow/floor_pure_producer_share.dag | 21 ++++ 4 files changed, 138 insertions(+), 37 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 12fc2424ee2..3e964589b81 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -27,11 +27,13 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_steps", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_cap_ms", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_bound", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_wall_nanos", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_below_cost_floor_count", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_COST_FLOOR_STEPS", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_FILL_NS_PER_STEP_CEILING", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_progress", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.cli_run.shared_fill", decl_name: "render_shared_fill_unattributed_text_mirror", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "list_value_items", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_derived_share_with_net_only", field: WholeDeclaration }, @@ -42,7 +44,7 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_store_declines", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "note_cross_claim_store_outcome", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline while in flight, capped at the preparation wall safety limit, so a runaway fill still interrupts; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one; the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline only in proportion to the evaluator steps it has performed, at the declared ceiling floor_cross_claim_fill_wall_ns_per_step_ceiling, under the preparation wall safety limit as the outer hard cap, so a stalled fill and a runaway one both still interrupt, naming the producer, its steps and its wall; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps (the stalled control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index ffadbce865f..fa9f0775d2f 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -7110,9 +7110,10 @@ pub(crate) fn derive_and_install_cross_claim_share( // a value (the first derived runs built one frame per site module -- 169 -- to warm 2523 // identities and then discarded 2404 below the floor). The fill's evaluator steps are netted // from the paying claim's budget by the existing fill guard, so budgets stay deterministic; its - // wall is excused from the claim's wall deadline while in flight, capped at the preparation - // wall safety limit, so a runaway fill still interrupts; and the cost floor is applied to the - // fill's own measured steps at the moment it would be retained. + // wall is excused from the claim's wall deadline only in proportion to the steps it has + // performed (a declared ns-per-step ceiling), under the preparation wall safety limit as the + // outer hard cap, so a stalled fill and a runaway one both still interrupt; and the cost floor + // is applied to the fill's own measured steps at the moment it would be retained. let cost_floor_steps = match v1_interpreter::run_in_context( ctx, &format!("{MODULE}.floor_cross_claim_share_cost_floor_eval_steps"), @@ -7131,10 +7132,31 @@ pub(crate) fn derive_and_install_cross_claim_share( } }; v1_interpreter::install_cross_claim_cost_floor_steps(cost_floor_steps); - v1_interpreter::install_cross_claim_in_flight_wall_cap_ms(in_flight_wall_cap_ms); + let ns_per_step_ceiling = match v1_interpreter::run_in_context( + ctx, + &format!("{MODULE}.floor_cross_claim_fill_wall_ns_per_step_ceiling"), + false, + ) { + Ok(Value::Int(n)) if n > 0 => n as u64, + other => { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimFillWallCeilingUnreadable -- \ + floor_cross_claim_fill_wall_ns_per_step_ceiling must be a positive Int, got {}", + match other { + Ok(v) => ctx.format_value(&v), + Err(e) => e.to_string(), + } + )) + } + }; + v1_interpreter::install_cross_claim_in_flight_wall_bound( + in_flight_wall_cap_ms, + ns_per_step_ceiling, + ); eprintln!( "[floor-phase] phase=cross-claim-share-install state=completed \ - cost_floor_eval_steps={cost_floor_steps} in_flight_wall_cap_ms={in_flight_wall_cap_ms}" + cost_floor_eval_steps={cost_floor_steps} fill_wall_ns_per_step_ceiling={ns_per_step_ceiling} \ + in_flight_wall_outer_cap_ms={in_flight_wall_cap_ms}" ); Ok(()) } diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index faa7b365f32..1628aa61123 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2195,6 +2195,7 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(0)); CROSS_CLAIM_STORE_DECLINES.with(|d| d.borrow_mut().clear()); CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(0)); + CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.set(0)); CROSS_CLAIM_SHARE_OBSERVER.with(|o| *o.borrow_mut() = None); // The prepared effect inputs are tier state too, and for the sharpest reason: a carry that // outlived its subject would serve a later, differently-prepared evaluation a value acquired @@ -3922,12 +3923,15 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } - // AN IN-FLIGHT FILL'S WALL IS EXCUSED ONLY UP TO THE CAP, AND NOTHING WITHOUT ONE. + // THE EXCUSAL IS BOUNDED BY THE FILL'S OWN WORK. The stalled control is the point: a fill in + // flight that performs NO evaluator steps is excused nothing, however long it has run, so the + // claim's wall deadline fires on it. The same fill after doing work is excused in proportion + // to its steps, and never past the outer cap. #[test] - fn in_flight_fill_wall_is_excused_up_to_the_cap_and_not_without_one() { + fn a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps() { use super::{ - in_flight_cross_claim_fill_wall_nanos, install_cross_claim_in_flight_wall_cap_ms, - CrossClaimFillGuard, + in_flight_cross_claim_fill_wall_nanos, install_cross_claim_in_flight_wall_bound, + record_eval_step, CrossClaimFillGuard, }; super::clear_cross_claim_pure_memos(); let guard = CrossClaimFillGuard::enter("tm_slow"); @@ -3935,19 +3939,34 @@ mod cross_claim_memo_tests { assert_eq!( in_flight_cross_claim_fill_wall_nanos(), 0, - "no cap installed, nothing excused" + "no bound installed: nothing excused" ); - install_cross_claim_in_flight_wall_cap_ms(1); - let excused = in_flight_cross_claim_fill_wall_nanos(); + install_cross_claim_in_flight_wall_bound(1_000, 1_000); assert_eq!( - excused, 1_000_000, - "a 5ms fill against a 1ms cap is excused exactly the cap" + in_flight_cross_claim_fill_wall_nanos(), + 0, + "STALLED: 5ms of wall and zero steps is excused nothing" + ); + for _ in 0..1_000 { + record_eval_step(); + } + assert_eq!( + in_flight_cross_claim_fill_wall_nanos(), + 1_000_000, + "1000 steps at a 1000ns ceiling excuse exactly 1ms of the 5ms" + ); + install_cross_claim_in_flight_wall_bound(0, 1_000); + assert_eq!( + in_flight_cross_claim_fill_wall_nanos(), + 0, + "no outer cap: nothing excused" ); drop(guard); + install_cross_claim_in_flight_wall_bound(1_000, 1_000); assert_eq!( in_flight_cross_claim_fill_wall_nanos(), 0, - "no fill in flight, nothing excused" + "no fill in flight: nothing excused" ); super::clear_cross_claim_pure_memos(); } @@ -6302,6 +6321,22 @@ impl InterpContext { let (elapsed_nanos, budget_ms) = self.wall_deadline_marginal_nanos()?; let elapsed = std::time::Duration::from_nanos(elapsed_nanos as u64); if elapsed.as_millis() as u64 > budget_ms { + // WHEN A FILL IS IN FLIGHT, THE REFUSAL NAMES IT: the producer, the steps it has + // performed and its wall, beside what was excused. A fill that stopped advancing, or + // outran the outer cap, is then visible as such rather than as an unexplained + // interrupted claim. + if let Some((producer, fill_steps, fill_wall)) = in_flight_cross_claim_fill_progress() { + eprintln!( + "[cross-claim-fill-wall-deadline] entry={} producer={producer} \ + fill_steps={fill_steps} fill_wall_ms={} excused_wall_ms={} limit_ms={budget_ms} \ + ns_per_step_ceiling={} outer_cap_ms={}", + self.budget_entry_or_unnamed(), + fill_wall / 1_000_000, + in_flight_cross_claim_fill_wall_nanos() / 1_000_000, + CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.get()), + CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.get()) / 1_000_000, + ); + } Some(InterpError::EvaluationBudgetExceeded { entry: self.budget_entry_or_unnamed(), clock: EvaluationClock::MonotonicWall, @@ -7051,19 +7086,25 @@ pub fn shared_artifact_fill_cpu_nanos() -> u128 { } thread_local! { - /// The most wall time an IN-FLIGHT admitted fill may be excused from a claim's wall deadline. - /// Zero (the default) excuses nothing. The floor installs its preparation wall safety limit, - /// so a fill a claim performs on first touch is bounded exactly as a preparation build is, - /// and a runaway fill still interrupts. + /// THE OUTER HARD CAP on the wall an in-flight admitted fill may be excused from a claim's + /// wall deadline, so a fill that advances forever still terminates. Zero (the default) + /// excuses nothing. The floor installs its preparation wall safety limit. static CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS: std::cell::Cell = const { std::cell::Cell::new(0) }; + /// THE WORK BOUND: wall is excused only in proportion to the evaluator steps the fill has + /// performed, at this declared ceiling of nanoseconds per step + /// (`v2.workflow.floor_pure_producer_share` + /// `floor_cross_claim_fill_wall_ns_per_step_ceiling`). A fill that is blocked or descheduled + /// accrues wall without steps and is therefore not excused. Zero excuses nothing. + static CROSS_CLAIM_FILL_NS_PER_STEP_CEILING: std::cell::Cell = const { std::cell::Cell::new(0) }; /// The declared cost floor (evaluator steps) below which a derived share's fill is not /// retained. Zero (the default) retains every admitted fill. static CROSS_CLAIM_COST_FLOOR_STEPS: std::cell::Cell = const { std::cell::Cell::new(0) }; } -/// Install the in-flight fill wall cap (see `CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS`). -pub fn install_cross_claim_in_flight_wall_cap_ms(cap_ms: u64) { +/// Install the in-flight fill excusal: the outer hard cap and the nanoseconds-per-step ceiling. +pub fn install_cross_claim_in_flight_wall_bound(cap_ms: u64, ns_per_step_ceiling: u64) { CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(u128::from(cap_ms) * 1_000_000)); + CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.set(u128::from(ns_per_step_ceiling))); } /// Install the derived share's cost floor (see `CROSS_CLAIM_COST_FLOOR_STEPS`). @@ -7071,24 +7112,39 @@ pub fn install_cross_claim_cost_floor_steps(steps: u64) { CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(steps)); } -/// Wall time the outermost in-flight admitted fill has run, less its stored children (already -/// netted when they completed), capped at the installed cap. This is the wall-clock sibling of -/// `in_flight_cross_claim_fill`: a claim that first-touches a shared fill is not charged the -/// fill's wall while it runs, exactly as it is not charged it once it completes. +/// The outermost in-flight admitted fill, as (producer, its own steps so far, its own wall so +/// far), each less the stored children already netted when they completed. +fn in_flight_cross_claim_fill_progress() -> Option<(String, u64, u128)> { + CROSS_CLAIM_FILL_FRAMES.with(|frames| { + frames.borrow().first().map(|outermost| { + ( + outermost.producer.clone(), + evaluator_steps() + .wrapping_sub(outermost.steps_started) + .saturating_sub(outermost.stored_children_steps), + outermost + .wall_started + .elapsed() + .as_nanos() + .saturating_sub(outermost.stored_children_wall), + ) + }) + }) +} + +/// Wall the outermost in-flight admitted fill is EXCUSED from a claim's wall deadline: its own +/// wall so far, bounded by its own WORK (steps so far times the declared ceiling) and by the +/// outer hard cap. This is the wall-clock sibling of `in_flight_cross_claim_fill`: a claim that +/// first-touches a fill is not charged the fill's wall while the fill is doing work, and is +/// charged all of it the moment the fill stops advancing. fn in_flight_cross_claim_fill_wall_nanos() -> u128 { let cap = CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.get()); - if cap == 0 { + let ceiling = CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.get()); + if cap == 0 || ceiling == 0 { return 0; } - CROSS_CLAIM_FILL_FRAMES.with(|frames| { - frames.borrow().first().map_or(0, |outermost| { - outermost - .wall_started - .elapsed() - .as_nanos() - .saturating_sub(outermost.stored_children_wall) - .min(cap) - }) + in_flight_cross_claim_fill_progress().map_or(0, |(_, steps, wall)| { + wall.min(u128::from(steps).saturating_mul(ceiling)).min(cap) }) } diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 6aab478ec8b..bf677c4cbb0 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -395,6 +395,27 @@ fn floor_cross_claim_share_cost_floor_eval_steps() -> Int { 5000 } +// THE IN-FLIGHT FILL WALL CEILING: a declared POLICY budget, in nanoseconds of wall per evaluator +// step. A claim that first-touches an admitted fill has the fill's wall excused from its own wall +// safety deadline only while the fill is DOING WORK: the excused wall is at most the fill's steps +// so far times this ceiling, under the preparation wall safety limit as the outer hard cap +// (v2.workflow.required_floor required_floor_preparation_wall_safety_limit). The wall deadline +// exists to catch a claim that is blocked or descheduled, which step counting cannot see; a fill +// that stops advancing accrues wall without steps, is excused nothing, and the deadline fires +// naming the producer, its steps and its wall. There is no per-producer cost list: the bound is +// each fill's own work, measured in the run it happens in (sharp-raven-357 ruling, 2026-10-03). +// +// HOW THE VALUE WAS SET, as policy and not as a fact about the tree: on the planning probe +// 37147337255 the interpreted fills of 200ms or more ran between the calibrated rate +// (v2.workflow.floor_eval_step_calibration) and about 6,200 ns of wall per step; the ceiling is +// set at four times that observed top, to cover the runner-to-runner timing variance this floor +// has measured without admitting a stall of any useful length. Re-derive the observation from +// that run's [floor-shared-fill] claim= rows (fill_wall_ms over fill_eval_steps); change the +// policy here, never by copying a new figure in. +fn floor_cross_claim_fill_wall_ns_per_step_ceiling() -> Int { + 25000 +} + // The live derivation, over the refused and carried rows this file declares. The seed calls this. fn floor_cross_claim_share_derivation( observations: List From baee1a54c38d95996c41ebc6ec08597cd177530a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 22:39:50 +0000 Subject: [PATCH 21/33] Frozen runtime-identity residual: five producers whose arguments are never closed constants stay shareable The derivation cannot join demand for producers called only with values computed inside the claim (ArgumentNotClosedConstant at every site). Five of the deleted roster's producers are in that class; without them a claim main nets to 44k steps ran 1.40M (action_use_admission_witness, via #13080). They are kept as a closed, frozen residual (sharp-raven-357 ruling): the arms of FrozenRuntimeIdentityProducer, joined by identity in the witness, trigger demand-engine M1.b. Serving is unchanged: keyed by declaration and argument row, preimage-verified. Review 75089: the unattributed-hit line mirror takes the closed frame enum and is asserted against the same two literals as the .dag witness. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../src/cli_run/required_floor_runner.rs | 39 +++++++++- src/v1/stage0/src/cli_run/shared_fill.rs | 57 ++++++++++++-- .../pure_producer_share_refusal_test.dag | 32 +++++++- src/v2/workflow/floor_pure_producer_share.dag | 74 ++++++++++++++++++- 4 files changed, 191 insertions(+), 11 deletions(-) diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index fa9f0775d2f..8e88b007201 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -6365,10 +6365,41 @@ pub(crate) fn install_pure_producer_share( let mut admitted_nodes = Vec::new(); let mut admitted_qualified: Vec = Vec::new(); let carried_producers: Vec = carried_rows.iter().map(|r| r.producer.clone()).collect(); - // THE ONLY PRODUCERS ADMITTED HERE ARE THE CARRIED-INPUT ONES. Plain pure producers are no - // longer a roster: they are derived from the planned claims' call-site demand once planning - // has fixed the claims (`derive_and_install_cross_claim_share`). - for qualified in carried_producers.iter() { + // The frozen runtime-identity residual: producers whose every call site carries arguments + // computed inside the claim, so the derivation cannot join their demand before the run. The + // population is closed in `.dag` (`FrozenRuntimeIdentityProducer`); the tier keys and verifies + // their fills by declaration and argument row like any other. + let residual_name = format!( + "{FLOOR_PURE_PRODUCER_SHARE_MODULE}.floor_cross_claim_runtime_identity_residual_producers" + ); + let residual_producers: Vec = { + let value = v1_interpreter::run_in_context(&roster_frame, &residual_name, false).map_err( + |e| { + format!( + "REQUIRED-FLOOR REFUSAL cause=RuntimeIdentityResidualUnreadable -- {residual_name} did not evaluate: {e}" + ) + }, + )?; + let items = v1_interpreter::list_value_items(&roster_frame, &value).ok_or_else(|| { + format!( + "REQUIRED-FLOOR REFUSAL cause=RuntimeIdentityResidualUnreadable -- {residual_name} is not a list" + ) + })?; + let mut out = Vec::new(); + for item in &items { + let v1_interpreter::Value::Str(producer) = item else { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=RuntimeIdentityResidualUnreadable -- {residual_name} carries a member that is not a String" + )); + }; + out.push(producer.to_string()); + } + out + }; + // THE PRODUCERS ADMITTED HERE ARE THE CARRIED-INPUT ONES AND THE FROZEN RESIDUAL. Plain pure + // producers are no longer a roster: they are derived from the planned claims' call-site + // demand once planning has fixed the claims (`derive_and_install_cross_claim_share`). + for qualified in carried_producers.iter().chain(residual_producers.iter()) { let (module, decl) = match qualified.rsplit_once('.') { Some((module, decl)) => (module.to_string(), decl), None => (qualified.clone(), qualified.as_str()), diff --git a/src/v1/stage0/src/cli_run/shared_fill.rs b/src/v1/stage0/src/cli_run/shared_fill.rs index 6c2511f0917..186ae3a8b82 100644 --- a/src/v1/stage0/src/cli_run/shared_fill.rs +++ b/src/v1/stage0/src/cli_run/shared_fill.rs @@ -112,7 +112,7 @@ struct Ledger { unattributed_hits: u64, /// The same hits by identity: (frame tag, phase, cache, key) -> count. The aggregate above /// stays the sum of these; this is what lets a reader disposition each one. - unattributed_by_key: BTreeMap<(&'static str, String, &'static str, String), u64>, + unattributed_by_key: BTreeMap<(SharedFillUnattributedFrame, String, &'static str, String), u64>, } thread_local! { @@ -189,7 +189,12 @@ pub(crate) fn record_hit(cache: &'static str, key: &str) { ledger.unattributed_hits += 1; *ledger .unattributed_by_key - .entry(("outside-fold", phase, cache, key.to_string())) + .entry(( + SharedFillUnattributedFrame::OutsideFold, + phase, + cache, + key.to_string(), + )) .or_default() += 1; }); return; @@ -211,7 +216,7 @@ pub(crate) fn record_hit(cache: &'static str, key: &str) { *ledger .unattributed_by_key .entry(( - "in-claim-without-fill", + SharedFillUnattributedFrame::InClaimWithoutFill, "claim".to_string(), cache, key.to_string(), @@ -294,14 +299,31 @@ pub(crate) fn render_shared_fill_total_text_mirror( ) } +/// Mirror of `gunbc.observation_ci_render` `SharedFillUnattributedFrame`: the closed set of frames +/// an unattributed hit can be read in, so a tag is never passed as free text. +#[derive(Clone, Copy, Debug, PartialEq, Eq, PartialOrd, Ord)] +pub(crate) enum SharedFillUnattributedFrame { + OutsideFold, + InClaimWithoutFill, +} + +/// Mirror of `gunbc.observation_ci_render` `shared_fill_unattributed_frame_tag`. +fn shared_fill_unattributed_frame_tag(frame: SharedFillUnattributedFrame) -> &'static str { + match frame { + SharedFillUnattributedFrame::OutsideFold => "outside-fold", + SharedFillUnattributedFrame::InClaimWithoutFill => "in-claim-without-fill", + } +} + /// Mirror of `gunbc.observation_ci_render` `ci_shared_fill_unattributed_text`. pub(crate) fn render_shared_fill_unattributed_text_mirror( - frame: &str, + frame: SharedFillUnattributedFrame, phase: &str, cache: &str, key: &str, hits: u64, ) -> String { + let frame = shared_fill_unattributed_frame_tag(frame); format!( "[floor-shared-fill-unattributed] frame={frame} phase={phase} cache={cache} key={key} \ hits={hits}" @@ -385,7 +407,7 @@ pub(crate) fn report() -> String { } for ((frame, phase, cache, key), hits) in &ledger.unattributed_by_key { out.push_str(&render_shared_fill_unattributed_text_mirror( - frame, phase, cache, key, *hits, + *frame, phase, cache, key, *hits, )); out.push('\n'); } @@ -436,6 +458,31 @@ mod tests { "[floor-shared-fill] TOTAL fills=9 fill_ms=60000 shared_fill_ms=42000 \ unattributed_hits=0" ); + // The same two literals as `test.claim.observation_ci_render_witness_test` + // `w_shared_fill_unattributed_line_names_frame_phase_and_key`, one per frame arm. + assert_eq!( + render_shared_fill_unattributed_text_mirror( + SharedFillUnattributedFrame::OutsideFold, + "cross-claim-share-derivation", + "cross_claim_pure_share", + "rust_target_model_staging", + 3, + ), + "[floor-shared-fill-unattributed] frame=outside-fold \ + phase=cross-claim-share-derivation cache=cross_claim_pure_share \ + key=rust_target_model_staging hits=3" + ); + assert_eq!( + render_shared_fill_unattributed_text_mirror( + SharedFillUnattributedFrame::InClaimWithoutFill, + "claim", + "cross_claim_pure_share", + "prepare_grammar", + 40, + ), + "[floor-shared-fill-unattributed] frame=in-claim-without-fill phase=claim \ + cache=cross_claim_pure_share key=prepare_grammar hits=40" + ); } #[test] diff --git a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag index 79483054157..7b026f10cde 100644 --- a/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag +++ b/src/v2/test/claim/floor/pure_producer_share_refusal_test.dag @@ -19,7 +19,9 @@ import v2.workflow.floor_pure_producer_share { SingleClaimFillDebtModule, SingleClaimFillDebtClaim, ActiveFillDebt, RetiredFillDebt, RestructuredPerWitnessRule, fill_debt_active_claims, derive_cross_claim_share, floor_cross_claim_share_derivation, - cross_claim_share_derivation_reconciles, derived_share_producers + cross_claim_share_derivation_reconciles, derived_share_producers, + RuntimeIdentityShareRow, floor_cross_claim_runtime_identity_residual, + floor_cross_claim_runtime_identity_residual_producers } import std.computation_identity { ComputationIdentity, NormalizedIdentical, IdentityUnknown, MissingConcept } import std.types { List } @@ -280,6 +282,34 @@ test fn the_derivation_partitions_every_closed_observation() -> Bool { && (length(xs: d.declined) == 2) } +// THE FROZEN RESIDUAL IS CLOSED, joined by IDENTITY and in both directions: each of the five +// declarations the ruling names is a member, and the population has no sixth. The literals are the +// ruling's own closed set (sharp-raven-357, 2026-10-03), not a measurement of this tree, so adding +// a member reds here until the ruling itself changes. +fn residual_has(producer: String) -> Bool { + length(xs: filter(xs: floor_cross_claim_runtime_identity_residual_producers(), predicate: fn(p) { p == producer })) == 1 +} + +test fn the_frozen_runtime_identity_residual_is_exactly_the_ruled_five() -> Bool { + residual_has(producer: "v2.workflow.bash_command_fold_serialize.bash_fold_serialize_node") + && residual_has(producer: "v2.extdeps.languages.bash_command_fold.bash_fold_relation_row_witness") + && residual_has(producer: "v2.compiler.target_serialize.grammar_relation_row_for_emitted") + && residual_has(producer: "v2.std.grammar.formal_productions_from_catalog_node") + && residual_has(producer: "v2.std.compilers.target_model.target_project_arrow_body_to_value_expression") + && (length(xs: floor_cross_claim_runtime_identity_residual_producers()) == 5) +} + +// Every member carries the one cause that admits a producer to the residual: its arguments are +// not closed constants. A row minted with any other cause is not a residual member. +test fn every_residual_member_carries_the_non_closed_argument_cause() -> Bool { + length(xs: filter(xs: floor_cross_claim_runtime_identity_residual, predicate: fn(r) { + match r.cause { + ArgumentNotClosedConstant => false + _ => true + } + })) == 0 +} + // THE LIVE POSITIVE CONTROL: the derivation the floor runs consults THIS TREE's refused rows. A // live refused producer demanded by two claims is declined -- which reds if the floor's fold // stopped reading floor_cross_claim_refused_candidates. diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 4eeace9dbc8..2960f00c626 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -33,7 +33,7 @@ import v2.std.algebra { any, list_flat_map, list_map } // row, before it fit its enrolment margin. The roster is deleted. Admission is now the fold // below, over one observation row per COMPUTATION IDENTITY reached by the run's PLANNED claims: // a pure call reached by more than one planned claim with one closed identity is admitted, and -// nothing else is. Because the observation is over the planned claims' reach, the admitted set +// nothing else is -- save the five-member frozen residual below, whose identity exists only at run time. Because the observation is over the planned claims' reach, the admitted set // is also exactly what this run can demand -- a producer no planned claim reaches is never filled. // // THE KEY IS THE FULL COMPUTATION IDENTITY (std.computation_identity, DESIGN section 3b keys @@ -1243,6 +1243,78 @@ data floor_single_claim_fill_debt: List = [ } ] +// ── THE FROZEN RUNTIME-IDENTITY RESIDUAL ────────────────────────────────────────────────── +// +// WHAT THE DERIVATION DOES NOT REPRODUCE. Five producers of the deleted hand roster are called only +// with arguments that are values computed inside the claim (a serialized node, a grammar row), so +// every one of their call sites observes as `ArgumentNotClosedConstant` and the fold above can +// neither prove nor refute that two claims demand one identity. The recurrence is real -- the +// same script statements and grammar rows are demanded by many claims -- but it is a fact about +// runtime argument values, and no argument row is fixed before the claim runs. +// +// DISPOSITION (sharp-raven-357, 2026-10-03): kept as a FROZEN residual, DESIGN section 3's +// frozen-X carve-out -- no Y can hold this boundary yet, so X stays and takes no new rows. The +// population is CLOSED: the members are the arms of `FrozenRuntimeIdentityProducer`, the data row +// is derived from every arm, and the witness joins it by identity, so a sixth member is a refusal +// rather than an append. A producer with non-closed arguments that is NOT one of these is counted +// with its cause and never admitted. +// +// PURITY IS UNCHANGED BY THIS ROW. Admission here says only that the tier MAY retain the +// producer's fills. Every fill is still keyed by the resolved declaration AND the full argument +// row, and a hit is served only after the stored argument preimage is compared equal to the +// caller's (std.computation_identity; the hand roster served these the same way -- keyed by +// declaration and arguments, never by name alone). +// +// TRIGGER (the capability, DESIGN section 4b(3)): per-call runtime-argument demand identity +// available to .dag (demand-engine M1.b). With it the observation carries these sites' identities +// like any closed site, the fold decides them, and this residual is deleted whole. +type FrozenRuntimeIdentityProducer + = BashFoldSerializeNode + | BashFoldRelationRowWitness + | GrammarRelationRowForEmitted + | FormalProductionsFromCatalogNode + | TargetProjectArrowBodyToValueExpression + +type RuntimeIdentityShareRow { + member: FrozenRuntimeIdentityProducer + producer: String + cause: CallSiteDemandCause +} + +fn frozen_runtime_identity_producer_declaration(member: FrozenRuntimeIdentityProducer) -> String { + match member { + BashFoldSerializeNode => "v2.workflow.bash_command_fold_serialize.bash_fold_serialize_node" + BashFoldRelationRowWitness => "v2.extdeps.languages.bash_command_fold.bash_fold_relation_row_witness" + GrammarRelationRowForEmitted => "v2.compiler.target_serialize.grammar_relation_row_for_emitted" + FormalProductionsFromCatalogNode => "v2.std.grammar.formal_productions_from_catalog_node" + TargetProjectArrowBodyToValueExpression => "v2.std.compilers.target_model.target_project_arrow_body_to_value_expression" + } +} + +fn runtime_identity_share_row(member: FrozenRuntimeIdentityProducer) -> RuntimeIdentityShareRow { + RuntimeIdentityShareRow { + member: member, + producer: frozen_runtime_identity_producer_declaration(member: member), + cause: ArgumentNotClosedConstant + } +} + +data floor_cross_claim_runtime_identity_residual: List = [ + runtime_identity_share_row(member: BashFoldSerializeNode), + runtime_identity_share_row(member: BashFoldRelationRowWitness), + runtime_identity_share_row(member: GrammarRelationRowForEmitted), + runtime_identity_share_row(member: FormalProductionsFromCatalogNode), + runtime_identity_share_row(member: TargetProjectArrowBodyToValueExpression) +] + +fn runtime_identity_residual_producers(rows: List) -> List { + list_map(xs: rows, f: fn(r) { r.producer }) +} + +fn floor_cross_claim_runtime_identity_residual_producers() -> List { + runtime_identity_residual_producers(rows: floor_cross_claim_runtime_identity_residual) +} + // ── REFUSED CANDIDATES: THE ROWS THIS ROSTER MEASURED AND TURNED DOWN ───────────────────── // // WHY A REFUSAL NEEDS A CARRIER AT ALL, and it is not tidiness. Until this type existed the file From 01d10d28568847c59ca829d72898d1f81d55479a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sat, 3 Oct 2026 23:51:13 +0000 Subject: [PATCH 22/33] Fill wall ceiling per step is a std.measure Nanosecond, not a bare Int (review 75137) Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor/floor_call_site_demand_seed_growth.dag | 2 +- src/v1/stage0/src/cli_run/required_floor_runner.rs | 4 ++-- src/v1/stage0/src/v1_interpreter.rs | 2 +- src/v2/workflow/floor_pure_producer_share.dag | 14 +++++++++++--- 4 files changed, 15 insertions(+), 7 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 3e964589b81..4e6e4497a61 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -44,7 +44,7 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_store_declines", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "note_cross_claim_store_outcome", field: WholeDeclaration } ], - reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline only in proportion to the evaluator steps it has performed, at the declared ceiling floor_cross_claim_fill_wall_ns_per_step_ceiling, under the preparation wall safety limit as the outer hard cap, so a stalled fill and a runaway one both still interrupt, naming the producer, its steps and its wall; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps (the stalled control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", + reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline only in proportion to the evaluator steps it has performed, at the declared ceiling floor_cross_claim_fill_wall_per_step_ceiling, under the preparation wall safety limit as the outer hard cap, so a stalled fill and a runaway one both still interrupt, naming the producer, its steps and its wall; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps (the stalled control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.", owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId, trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.", current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines" diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 8e88b007201..000b17dba68 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -7165,14 +7165,14 @@ pub(crate) fn derive_and_install_cross_claim_share( v1_interpreter::install_cross_claim_cost_floor_steps(cost_floor_steps); let ns_per_step_ceiling = match v1_interpreter::run_in_context( ctx, - &format!("{MODULE}.floor_cross_claim_fill_wall_ns_per_step_ceiling"), + &format!("{MODULE}.floor_cross_claim_fill_wall_per_step_ceiling_nanosecond_count"), false, ) { Ok(Value::Int(n)) if n > 0 => n as u64, other => { return Err(format!( "REQUIRED-FLOOR REFUSAL cause=CrossClaimFillWallCeilingUnreadable -- \ - floor_cross_claim_fill_wall_ns_per_step_ceiling must be a positive Int, got {}", + floor_cross_claim_fill_wall_per_step_ceiling_nanosecond_count must be a positive Int, got {}", match other { Ok(v) => ctx.format_value(&v), Err(e) => e.to_string(), diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 1628aa61123..8e0689f53e6 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -7093,7 +7093,7 @@ thread_local! { /// THE WORK BOUND: wall is excused only in proportion to the evaluator steps the fill has /// performed, at this declared ceiling of nanoseconds per step /// (`v2.workflow.floor_pure_producer_share` - /// `floor_cross_claim_fill_wall_ns_per_step_ceiling`). A fill that is blocked or descheduled + /// `floor_cross_claim_fill_wall_per_step_ceiling`). A fill that is blocked or descheduled /// accrues wall without steps and is therefore not excused. Zero excuses nothing. static CROSS_CLAIM_FILL_NS_PER_STEP_CEILING: std::cell::Cell = const { std::cell::Cell::new(0) }; /// The declared cost floor (evaluator steps) below which a derived share's fill is not diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 2960f00c626..c7d822779ca 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -14,7 +14,7 @@ import std.materialization_ladder { RefusedUnmodeledWorldRead, ExemptFreshEffect, AcceptedBelowCostFloor, AcceptedSingleRecompute, AcceptedEffectIsTheUse, RefusedNatureConflict } -import std.measure { byte_size } +import std.measure { Nanosecond, byte_size, nanosecond, nanosecond_count } import v2.std.algebra { any, list_flat_map, list_map } // THE CROSS-CLAIM PURE-PRODUCER SHARE -- which pure computations the required floor may fill @@ -412,8 +412,16 @@ fn floor_cross_claim_share_cost_floor_eval_steps() -> Int { // has measured without admitting a stall of any useful length. Re-derive the observation from // that run's [floor-shared-fill] claim= rows (fill_wall_ms over fill_eval_steps); change the // policy here, never by copying a new figure in. -fn floor_cross_claim_fill_wall_ns_per_step_ceiling() -> Int { - 25000 +// +// THE UNIT IS IN THE TYPE (review 75137): the ceiling is a std.measure `Nanosecond` of wall per one +// evaluator step, so a millisecond figure cannot be written here by mistake. The seed reads the +// count through `nanosecond_count`, the one crossing std.measure declares for it. +fn floor_cross_claim_fill_wall_per_step_ceiling() -> Nanosecond { + nanosecond(count: 25000) +} + +fn floor_cross_claim_fill_wall_per_step_ceiling_nanosecond_count() -> Int { + nanosecond_count(n: floor_cross_claim_fill_wall_per_step_ceiling()) } // The live derivation, over the refused and carried rows this file declares. The seed calls this. From 88fbe67766979e7f7175fff5568cc29547a2ee5f Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 05:29:45 +0000 Subject: [PATCH 23/33] Fill debt: seven members behind the eleven roster rows main added (#13118, #13069, #13120), from probe 37177499463 Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 25 +++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index c7d822779ca..253f4c171cb 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -542,8 +542,33 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // Five members were added from the later probe pair 37147337255 against 37147367276, which also // planned the modules behind rows main added to the hand roster while this change was open // (dependency_demand_census, infer_fold_member_instance, one more kernel_value_type_roster claim). +// Seven members were added from probe 37177499463, which planned the three modules behind the +// eleven rows main added to the hand roster after the comparison (gunbc#13118, #13069, #13120): each is +// the one claim demanding a nullary producer that roster had warmed. // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.callexec.let_match_early_return_eval", + claims: [ + SingleClaimFillDebtClaim { claim: "the_binding_path_of_a_let_match_and_its_rewrite_refuse_alike_at_infer_grounding", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "the_exit_path_of_a_let_match_and_its_rewrite_refuse_alike_at_infer_grounding", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.collection_callback_realization", + claims: [ + SingleClaimFillDebtClaim { claim: "ccr_all_head_binds_its_row", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ccr_declared_any_stays_an_ordinary_call", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ccr_map_undeclared_field_refuses_at_the_field", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "ccr_piped_map_head_binds_its_row", standing: ActiveFillDebt } + ] + }, + SingleClaimFillDebtModule { + module: "v2.test.claim.native_census.cascade_root_fan_out", + claims: [ + SingleClaimFillDebtClaim { claim: "census_diamond_cascade_counts_modules_not_paths_holds", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.compiler.dependency_demand_census", claims: [ From 931d459a4777c98be4ddadfb1afaccb5408d82f6 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 07:30:23 +0000 Subject: [PATCH 24/33] Carried-input seed controls carry the residual producer function their fixture module now owes (review 75438) install_pure_producer_share reads floor_cross_claim_runtime_identity_residual_producers from the share module; the three in-file fixtures for the carried-input controls declared no such function, so the positive control and both refusal controls stopped at RuntimeIdentityResidualUnreadable before reaching what they test. Each fixture now declares the empty residual. Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v1/stage0/src/cli_run/required_floor_runner.rs | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index ec237ce5388..265945317d9 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -13397,7 +13397,8 @@ mod pure_producer_share_tests { measurement: String\n\ next_trigger: String\n\ }}\n\ - data floor_cross_claim_refused_candidates: List = []\n", + data floor_cross_claim_refused_candidates: List = []\n\ + fn floor_cross_claim_runtime_identity_residual_producers() -> List {{ [] }}\n", dependence = dependence, dependence_input = "v2.workflow.floor_pure_producer_share.carrier_a", ), @@ -13608,7 +13609,8 @@ mod pure_producer_share_tests { measurement: String\n\ next_trigger: String\n\ }\n\ - data floor_cross_claim_refused_candidates: List = []\n", + data floor_cross_claim_refused_candidates: List = []\n\ + fn floor_cross_claim_runtime_identity_residual_producers() -> List { [] }\n", )]); let err = install_pure_producer_share(&prepared, &fixture_corpus(&[])) .expect_err("a row naming an unprepared input must stop the line"); @@ -13663,7 +13665,8 @@ mod pure_producer_share_tests { measurement: String\n\ next_trigger: String\n\ }\n\ - data floor_cross_claim_refused_candidates: List = []\n", + data floor_cross_claim_refused_candidates: List = []\n\ + fn floor_cross_claim_runtime_identity_residual_producers() -> List { [] }\n", )]); let err = install_pure_producer_share(&prepared, &fixture_corpus(&[])) .expect_err("a non-nullary acquisition must stop the line"); From 766fa1d9641296661c4e8715823b87542707124a Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 08:16:52 +0000 Subject: [PATCH 25/33] Fill debt: five members behind the six roster rows #13060 added, from probe 37186494805 Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 253f4c171cb..9e572231f7f 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -545,8 +545,20 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // Seven members were added from probe 37177499463, which planned the three modules behind the // eleven rows main added to the hand roster after the comparison (gunbc#13118, #13069, #13120): each is // the one claim demanding a nullary producer that roster had warmed. +// Five more were added from probe 37186494805, for the six rows gunbc#13060 added to the hand roster +// (v2.test.claim.algebra_operator_derivation), on the same ground. // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.algebra_operator_derivation", + claims: [ + SingleClaimFillDebtClaim { claim: "aod_bool_add_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "aod_bool_join_derives_bool", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "aod_int_add_still_derives_int", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "aod_int_join_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "aod_well_typed_operators_are_accepted", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.callexec.let_match_early_return_eval", claims: [ From a99fc0d7ed56a6d03c824aa6fb70c66ed859f70d Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 11:06:46 +0000 Subject: [PATCH 26/33] Cost floor counts a fill's native work: thread CPU read as steps at the calibration rate A steps-only floor declined dag_prepared_grammar (a nullary wrapper over a served prepare_grammar: few steps, but a content hash and total reification of the grammar to key the lookup; 466 ms on main's fill). Every claim reaching it then re-paid that keying natively, outside its step budget: same claims, fewer steps, more CPU than main. A fill's work is now max(steps, cpu x rate), the rate being v2.workflow.floor_eval_step_calibration's, declared as policy in floor_cross_claim_share_cost_floor_steps_per_millisecond. Control: a fill with CPU and no steps is declined at rate zero and retained when CPU counts. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 2 + .../src/cli_run/required_floor_runner.rs | 22 +++++ src/v1/stage0/src/v1_interpreter.rs | 86 ++++++++++++++++++- src/v2/workflow/floor_pure_producer_share.dag | 16 ++++ 4 files changed, 123 insertions(+), 3 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 4e6e4497a61..3ef593f4282 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -27,6 +27,8 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_steps", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_cpu_rate", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_fill_work_steps", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_bound", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_wall_nanos", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_below_cost_floor_count", field: WholeDeclaration }, diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 265945317d9..2ee4cf6d22a 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -7234,6 +7234,28 @@ pub(crate) fn derive_and_install_cross_claim_share( } }; v1_interpreter::install_cross_claim_cost_floor_steps(cost_floor_steps); + // The floor counts a fill's native work too: its thread CPU, read as steps at the declared + // calibration rate. A fill whose cost is native (keying a served producer's argument row) is + // otherwise declined on its step count and re-paid by every claim. + let cost_floor_steps_per_ms = match v1_interpreter::run_in_context( + ctx, + &format!("{MODULE}.floor_cross_claim_share_cost_floor_steps_per_millisecond"), + false, + ) { + Ok(Value::Int(n)) if n > 0 => n as u64, + other => { + return Err(format!( + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareCostFloorRateUnreadable -- \ + floor_cross_claim_share_cost_floor_steps_per_millisecond must be a positive \ + Int, got {}", + match other { + Ok(v) => ctx.format_value(&v), + Err(e) => e.to_string(), + } + )) + } + }; + v1_interpreter::install_cross_claim_cost_floor_cpu_rate(cost_floor_steps_per_ms); let ns_per_step_ceiling = match v1_interpreter::run_in_context( ctx, &format!("{MODULE}.floor_cross_claim_fill_wall_per_step_ceiling_nanosecond_count"), diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 0cabe7c8194..c3d837b1af9 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2193,6 +2193,7 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().clear()); CROSS_CLAIM_NET_ONLY_SITES.with(|n| n.borrow_mut().clear()); CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(0)); + CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.set(0)); CROSS_CLAIM_STORE_DECLINES.with(|d| d.borrow_mut().clear()); CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(0)); CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.set(0)); @@ -2303,6 +2304,22 @@ fn cross_claim_site_is_net_only(call_node: &Node) -> bool { }) } +/// A fill's work in evaluator-step units: the larger of the steps it performed and its thread CPU +/// converted at the declared calibration rate. STEPS ALONE UNDERCOUNT A FILL WHOSE COST IS NATIVE: +/// a nullary wrapper around an already-served producer performs a handful of steps and still pays +/// the content hash and total reification of that producer's argument row to key the lookup +/// (`dag_prepared_grammar` over `prepare_grammar(grammar:)`: 466 ms, measured on main's own fill +/// of it). Judged on steps it was declined at the floor, so every claim re-paid that keying +/// natively and outside its step budget. A rate of zero (nothing installed) leaves steps alone. +fn cross_claim_fill_work_steps(guard: &CrossClaimFillGuard) -> u64 { + let steps = evaluator_steps().wrapping_sub(guard.steps_started); + let rate = CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.get()); + let cpu_nanos = thread_cpu_nanos().saturating_sub(guard.cpu_started); + let cpu_as_steps = + u64::try_from(cpu_nanos.saturating_mul(u128::from(rate)) / 1_000_000).unwrap_or(u64::MAX); + steps.max(cpu_as_steps) +} + /// Publish one completed admitted fill: retain it in the tier, or -- at a net-only site -- net its /// cost from the paying claim without retaining the value. The cost floor applies to both: a fill /// below it is neither retained nor netted. Every declined outcome is counted by producer. @@ -2318,7 +2335,7 @@ fn publish_cross_claim_fill( if net_only { if let Some(guard) = fill_guard { let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); - if evaluator_steps().wrapping_sub(guard.steps_started) < floor { + if cross_claim_fill_work_steps(guard) < floor { CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); note_cross_claim_store_outcome( func_name, @@ -2688,12 +2705,13 @@ fn store_cross_claim_pure_memo( return CrossClaimStoreOutcome::NotAdmitted; } // THE COST FLOOR, applied to a derived producer's fill at the moment it would be retained: the - // guard measured the fill's evaluator steps, so the decision rests on this fill's own work. + // guard measured the fill's evaluator steps AND its thread CPU, so the decision rests on this + // fill's own work, native work included (`cross_claim_fill_work_steps`). if let Some(guard) = fill_guard { let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); let gated = CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); - if gated && evaluator_steps().wrapping_sub(guard.steps_started) < floor { + if gated && cross_claim_fill_work_steps(guard) < floor { CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); return CrossClaimStoreOutcome::RefusedBelowCostFloor; } @@ -3923,6 +3941,59 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } + // THE COST FLOOR COUNTS NATIVE WORK. The pair varies only the CPU rate: one fill that performs + // NO evaluator steps but burns thread CPU is declined when CPU is not counted (rate zero) and + // retained when it is. This is the `dag_prepared_grammar` shape -- a wrapper whose cost is the + // native keying of the producer beneath it -- which a steps-only floor declined on every claim. + #[test] + fn a_fill_with_native_cost_and_no_steps_clears_the_floor_only_when_cpu_is_counted() { + use super::{ + install_cross_claim_cost_floor_cpu_rate, install_cross_claim_cost_floor_steps, + install_cross_claim_derived_share, store_cross_claim_pure_memo, thread_cpu_nanos, + CrossClaimFillGuard, CrossClaimStoreOutcome, + }; + fn burn_two_milliseconds_of_cpu() { + let started = thread_cpu_nanos(); + let mut acc = 0u64; + while thread_cpu_nanos().saturating_sub(started) < 2_000_000 { + acc = std::hint::black_box(acc.wrapping_mul(31).wrapping_add(7)); + } + } + for (rate, expected) in [ + (0u64, CrossClaimStoreOutcome::RefusedBelowCostFloor), + (1_000u64, CrossClaimStoreOutcome::Stored), + ] { + super::clear_cross_claim_pure_memos(); + let ctx = fresh_ctx(); + let derived = make_expr_node( + Rc::new( + crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic, + ), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + no_span(), + ); + install_cross_claim_derived_share([derived.clone()], std::collections::HashSet::new()); + // 1000 steps: 2 ms of CPU at 1000 steps/ms is 2000 steps of work, above the floor. + install_cross_claim_cost_floor_steps(1_000); + install_cross_claim_cost_floor_cpu_rate(rate); + let guard = CrossClaimFillGuard::enter("tm_native"); + burn_two_milliseconds_of_cpu(); + let outcome = store_cross_claim_pure_memo( + &ctx, + &derived, + "tm_native", + &[], + &Value::Int(1), + Some(&guard), + ); + drop(guard); + assert_eq!(outcome, expected, "cpu rate {rate}"); + } + super::clear_cross_claim_pure_memos(); + } + // THE EXCUSAL IS BOUNDED BY THE FILL'S OWN WORK. The stalled control is the point: a fill in // flight that performs NO evaluator steps is excused nothing, however long it has run, so the // claim's wall deadline fires on it. The same fill after doing work is excused in proportion @@ -7113,6 +7184,9 @@ thread_local! { /// The declared cost floor (evaluator steps) below which a derived share's fill is not /// retained. Zero (the default) retains every admitted fill. static CROSS_CLAIM_COST_FLOOR_STEPS: std::cell::Cell = const { std::cell::Cell::new(0) }; + /// The declared calibration rate (evaluator steps per millisecond of CPU) at which a fill's + /// thread CPU is read as work against the cost floor. Zero judges on steps alone. + static CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS: std::cell::Cell = const { std::cell::Cell::new(0) }; } /// Install the in-flight fill excusal: the outer hard cap and the nanoseconds-per-step ceiling. @@ -7126,6 +7200,12 @@ pub fn install_cross_claim_cost_floor_steps(steps: u64) { CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(steps)); } +/// Install the rate at which a fill's CPU counts toward the cost floor +/// (see `CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS`). +pub fn install_cross_claim_cost_floor_cpu_rate(steps_per_ms: u64) { + CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.set(steps_per_ms)); +} + /// The outermost in-flight admitted fill, as (producer, its own steps so far, its own wall so /// far), each less the stored children already netted when they completed. fn in_flight_cross_claim_fill_progress() -> Option<(String, u64, u128)> { diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 9e572231f7f..066cf7db2f8 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -15,6 +15,7 @@ import std.materialization_ladder { AcceptedEffectIsTheUse, RefusedNatureConflict } import std.measure { Nanosecond, byte_size, nanosecond, nanosecond_count } +import v2.workflow.floor_eval_step_calibration { calibration_rate, floor_eval_step_calibration } import v2.std.algebra { any, list_flat_map, list_map } // THE CROSS-CLAIM PURE-PRODUCER SHARE -- which pure computations the required floor may fill @@ -395,6 +396,21 @@ fn floor_cross_claim_share_cost_floor_eval_steps() -> Int { 5000 } +// THE FLOOR COUNTS NATIVE WORK, as declared policy: a fill's work is the larger of its evaluator +// steps and its thread CPU read as steps at the floor's own calibration rate +// (v2.workflow.floor_eval_step_calibration, the one authority that relates steps to time). Steps +// alone undercount a fill whose cost is native. The measured case: dag_prepared_grammar is a +// nullary wrapper over prepare_grammar(grammar: dag_grammar()); once prepare_grammar is served the +// wrapper performs a handful of steps, and still pays the content hash and total reification of +// the whole grammar value to key that lookup -- 466 ms on main's own fill of it (probe run +// 37160051963). Judged on steps it was declined at this floor (205 times on probe 37160050318), so +// every claim that reached it re-paid that keying natively, outside its step budget: the same +// claims ran with fewer steps and more CPU than on main. Counting CPU retains the wrapper, and a +// claim's hit is then a nullary key again. +fn floor_cross_claim_share_cost_floor_steps_per_millisecond() -> Int { + calibration_rate(calibration: floor_eval_step_calibration) +} + // THE IN-FLIGHT FILL WALL CEILING: a declared POLICY budget, in nanoseconds of wall per evaluator // step. A claim that first-touches an admitted fill has the fill's wall excused from its own wall // safety deadline only while the fill is DOING WORK: the excused wall is at most the fill's steps From 26471cbd7f8b7f43ce8f213c3bd71195a97cdd0f Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 12:58:01 +0000 Subject: [PATCH 27/33] Site-gate check allocates nothing; a site whose fill is below the cost floor is retired for the run Two per-call costs the derived share put on the claim fold, found on same-revision probe pairs as about 30% more native time per evaluator step with fewer steps: - cross_claim_site_admitted built a (String, i64, i64) key, allocating and hashing the file path, on every call of every site-gated producer. The site sets are now indexed by byte span, with the file compared as a borrowed string only on a span match. - a site whose fill came in below the cost floor stayed admitted, so each later call keyed the tier, opened a fill and was declined again (446k declined publications on probe 37199261433). The site is now retired on its first below-floor fill. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 2 + src/v1/stage0/src/v1_interpreter.rs | 122 +++++++++++++++--- 2 files changed, 108 insertions(+), 16 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 3ef593f4282..a9132c89f6f 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -29,6 +29,8 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_steps", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_cpu_rate", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_fill_work_steps", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimSiteSet", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "retire_cross_claim_site_below_cost_floor", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_bound", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_wall_nanos", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_below_cost_floor_count", field: WholeDeclaration }, diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index c3d837b1af9..c77a4eb75d7 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2174,11 +2174,51 @@ thread_local! { /// retaining it would spend the tier's byte budget on values nobody reads (floor probe /// 37142207751: 638 stores declined at the byte budget, each leaving its fill on the claim). /// The fill is measured and netted from the claim exactly as a retained one is. - static CROSS_CLAIM_NET_ONLY_SITES: RefCell> = - RefCell::new(std::collections::HashSet::new()); + static CROSS_CLAIM_NET_ONLY_SITES: RefCell = + RefCell::new(CrossClaimSiteSet::default()); /// The admitted call sites of site-gated producers, as `(file, start, end)` byte spans. - static CROSS_CLAIM_ADMITTED_SITES: RefCell> = - RefCell::new(std::collections::HashSet::new()); + static CROSS_CLAIM_ADMITTED_SITES: RefCell = + RefCell::new(CrossClaimSiteSet::default()); +} + +/// A set of call sites, indexed so that MEMBERSHIP COSTS NO ALLOCATION. The check runs on every +/// call of every site-gated producer, admitted site or not; keyed on `(String, i64, i64)` it +/// allocated and hashed the file path each time, which same-revision floor pairs showed as about +/// 30% more native time per evaluator step across the whole claim fold. The byte span is hashed +/// first (two integers), and the file is compared as a borrowed string only on a span match. +#[derive(Default)] +struct CrossClaimSiteSet { + by_span: std::collections::HashMap<(i64, i64), Vec>, +} + +impl CrossClaimSiteSet { + fn from_sites(sites: std::collections::HashSet<(String, i64, i64)>) -> CrossClaimSiteSet { + let mut by_span: std::collections::HashMap<(i64, i64), Vec> = + std::collections::HashMap::new(); + for (file, start, end) in sites { + by_span.entry((start, end)).or_default().push(file); + } + CrossClaimSiteSet { by_span } + } + + fn contains(&self, file: &str, start: i64, end: i64) -> bool { + self.by_span + .get(&(start, end)) + .is_some_and(|files| files.iter().any(|f| f == file)) + } + + fn remove(&mut self, file: &str, start: i64, end: i64) { + if let Some(files) = self.by_span.get_mut(&(start, end)) { + files.retain(|f| f != file); + if files.is_empty() { + self.by_span.remove(&(start, end)); + } + } + } + + fn clear(&mut self) { + self.by_span.clear(); + } } /// Clears stored values, roster and observer together: the tier's lifetime is ONE prepared @@ -2241,7 +2281,8 @@ pub fn install_cross_claim_derived_share_with_net_only, net_only_sites: std::collections::HashSet<(String, i64, i64)>, ) { - CROSS_CLAIM_NET_ONLY_SITES.with(|n| *n.borrow_mut() = net_only_sites); + CROSS_CLAIM_NET_ONLY_SITES + .with(|n| *n.borrow_mut() = CrossClaimSiteSet::from_sites(net_only_sites)); let nodes: Vec> = nodes.into_iter().collect(); // REPLACES the previous derivation rather than adding to it: a producer dropped from the // derived set must leave the roster too, or it would remain admitted with no site gate -- @@ -2270,7 +2311,7 @@ pub fn install_cross_claim_derived_share_with_net_only, call_node: &Node) -> bool { CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); !gated || CROSS_CLAIM_ADMITTED_SITES.with(|a| { - a.borrow().contains(&( - call_node.span.file.to_string(), + a.borrow().contains( + &call_node.span.file, call_node.span.start, call_node.span.end, - )) + ) }) } /// Whether this call site is a net-only (single-claim fill debt) site. fn cross_claim_site_is_net_only(call_node: &Node) -> bool { CROSS_CLAIM_NET_ONLY_SITES.with(|n| { - let n = n.borrow(); - !n.is_empty() - && n.contains(&( - call_node.span.file.to_string(), - call_node.span.start, - call_node.span.end, - )) + n.borrow().contains( + &call_node.span.file, + call_node.span.start, + call_node.span.end, + ) }) } +/// Retire a derived producer's call site for the rest of the run after its fill came in below the +/// cost floor. A site carries one closed argument row, so one identity, so the same small work on +/// every later call; leaving it admitted would make every such call pay the tier's key (argument +/// hash and total reification), open a fill and be declined again -- several hundred thousand +/// declined publications on a planning probe. A producer admitted without a site gate is untouched. +fn retire_cross_claim_site_below_cost_floor(fn_node: &Rc, call_node: &Node) { + let gated = + CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); + if !gated { + return; + } + let (start, end) = (call_node.span.start, call_node.span.end); + CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().remove(&call_node.span.file, start, end)); + CROSS_CLAIM_NET_ONLY_SITES.with(|n| n.borrow_mut().remove(&call_node.span.file, start, end)); +} + /// A fill's work in evaluator-step units: the larger of the steps it performed and its thread CPU /// converted at the declared calibration rate. STEPS ALONE UNDERCOUNT A FILL WHOSE COST IS NATIVE: /// a nullary wrapper around an already-served producer performs a handful of steps and still pays @@ -2325,6 +2380,7 @@ fn cross_claim_fill_work_steps(guard: &CrossClaimFillGuard) -> u64 { /// below it is neither retained nor netted. Every declined outcome is counted by producer. fn publish_cross_claim_fill( ctx: &InterpContext, + call_node: &Node, fn_node: &Rc, func_name: &str, args: &[(Option, Value)], @@ -2341,6 +2397,7 @@ fn publish_cross_claim_fill( func_name, &CrossClaimStoreOutcome::RefusedBelowCostFloor, ); + retire_cross_claim_site_below_cost_floor(fn_node, call_node); } else { guard.mark_stored(); } @@ -2349,6 +2406,9 @@ fn publish_cross_claim_fill( } let outcome = store_cross_claim_pure_memo(ctx, fn_node, func_name, args, value, fill_guard); note_cross_claim_store_outcome(func_name, &outcome); + if outcome == CrossClaimStoreOutcome::RefusedBelowCostFloor { + retire_cross_claim_site_below_cost_floor(fn_node, call_node); + } } /// Install the shared-fill observer for the cross-claim tier. `None` uninstalls. @@ -3860,6 +3920,7 @@ mod cross_claim_memo_tests { publish_cross_claim_fill( &ctx, &derived, + &derived, "tm_debt", &[], &Value::Int(1), @@ -3880,6 +3941,7 @@ mod cross_claim_memo_tests { publish_cross_claim_fill( &ctx, &derived, + &derived, "tm_debt", &[], &Value::Int(1), @@ -4087,6 +4149,31 @@ mod cross_claim_memo_tests { cross_claim_site_admitted(&ungated, &node_at(200, 240)), "control: a producer admitted without a site gate is unaffected" ); + // A SITE WHOSE FILL CAME IN BELOW THE COST FLOOR IS RETIRED, so its later calls skip the + // tier instead of keying and being declined again. Only the site named is retired, a + // same-span site in another file is a different site, and an ungated producer keeps all. + let mut two = std::collections::HashSet::new(); + two.insert(("workspace/src/n7.dag".to_string(), 100, 140)); + two.insert(("workspace/src/n7.dag".to_string(), 300, 340)); + two.insert(("workspace/src/other.dag".to_string(), 100, 140)); + install_cross_claim_derived_share([derived.clone()], two); + super::retire_cross_claim_site_below_cost_floor(&derived, &node_at(100, 140)); + assert!(!cross_claim_site_admitted(&derived, &node_at(100, 140))); + assert!(cross_claim_site_admitted(&derived, &node_at(300, 340))); + let other_file = make_expr_node( + Rc::new(crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + Rc::new(crate::std_types::SourceSpan { + file: "workspace/src/other.dag".to_string(), + start: 100, + end: 140, + }), + ); + assert!(cross_claim_site_admitted(&derived, &other_file)); + super::retire_cross_claim_site_below_cost_floor(&ungated, &node_at(200, 240)); + assert!(cross_claim_site_admitted(&ungated, &node_at(200, 240))); super::clear_cross_claim_pure_memos(); assert!( cross_claim_site_admitted(&derived, &node_at(200, 240)), @@ -10473,6 +10560,7 @@ fn eval_pure_named_call( // call recomputes on a refusal exactly as if never enrolled. publish_cross_claim_fill( ctx, + call_node, fn_node, func_name, args, @@ -10507,6 +10595,7 @@ fn eval_pure_named_call( if ctx.effect_dispatch_count.get() == effects_before { publish_cross_claim_fill( ctx, + call_node, fn_node, func_name, args, @@ -10548,6 +10637,7 @@ fn eval_pure_named_call( if share_site && ctx.effect_dispatch_count.get() == effects_before { publish_cross_claim_fill( ctx, + call_node, fn_node, func_name, args, From b968968bc02540e09418909caea7b58c0a91e079 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 13:09:27 +0000 Subject: [PATCH 28/33] Cost floor's CPU arm is the new-witness envelope, not the step floor converted to time Converting 5000 steps at the calibration rate gave about 7 ms. That retained some sixty further producers whose fills are tens of milliseconds and whose values are large trees; the tier reached its byte budget (14 refusals) and seven claims ran over budget only with this change (probe 37199261433). The arm exists for a fill whose native cost alone is a claim's whole allowance, so its value is that allowance: required_floor_new_witness_envelope_ms, typed as a Millisecond. A fill is below the floor only when it is below the step floor and below the CPU floor. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 4 +- .../src/cli_run/required_floor_runner.rs | 16 ++--- src/v1/stage0/src/v1_interpreter.rs | 65 +++++++++---------- src/v2/workflow/floor_pure_producer_share.dag | 39 ++++++----- 4 files changed, 66 insertions(+), 58 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index a9132c89f6f..3934bf8ced8 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -27,8 +27,8 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_SITE_GATED", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_ADMITTED_SITES", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_steps", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_cpu_rate", field: WholeDeclaration }, - DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_fill_work_steps", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_cost_floor_cpu_ms", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_fill_below_cost_floor", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimSiteSet", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "retire_cross_claim_site_below_cost_floor", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_bound", field: WholeDeclaration }, diff --git a/src/v1/stage0/src/cli_run/required_floor_runner.rs b/src/v1/stage0/src/cli_run/required_floor_runner.rs index 2ee4cf6d22a..7b8ae6b6149 100644 --- a/src/v1/stage0/src/cli_run/required_floor_runner.rs +++ b/src/v1/stage0/src/cli_run/required_floor_runner.rs @@ -7234,19 +7234,19 @@ pub(crate) fn derive_and_install_cross_claim_share( } }; v1_interpreter::install_cross_claim_cost_floor_steps(cost_floor_steps); - // The floor counts a fill's native work too: its thread CPU, read as steps at the declared - // calibration rate. A fill whose cost is native (keying a served producer's argument row) is - // otherwise declined on its step count and re-paid by every claim. - let cost_floor_steps_per_ms = match v1_interpreter::run_in_context( + // The floor has a CPU arm: a fill whose thread CPU reaches the declared floor is retained + // however few steps it performed. A fill whose cost is native (keying a served producer's + // argument row) is otherwise declined on its step count and re-paid by every claim. + let cost_floor_cpu_ms = match v1_interpreter::run_in_context( ctx, - &format!("{MODULE}.floor_cross_claim_share_cost_floor_steps_per_millisecond"), + &format!("{MODULE}.floor_cross_claim_share_cost_floor_cpu_millisecond_count"), false, ) { Ok(Value::Int(n)) if n > 0 => n as u64, other => { return Err(format!( - "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareCostFloorRateUnreadable -- \ - floor_cross_claim_share_cost_floor_steps_per_millisecond must be a positive \ + "REQUIRED-FLOOR REFUSAL cause=CrossClaimShareCostFloorCpuUnreadable -- \ + floor_cross_claim_share_cost_floor_cpu_millisecond_count must be a positive \ Int, got {}", match other { Ok(v) => ctx.format_value(&v), @@ -7255,7 +7255,7 @@ pub(crate) fn derive_and_install_cross_claim_share( )) } }; - v1_interpreter::install_cross_claim_cost_floor_cpu_rate(cost_floor_steps_per_ms); + v1_interpreter::install_cross_claim_cost_floor_cpu_ms(cost_floor_cpu_ms); let ns_per_step_ceiling = match v1_interpreter::run_in_context( ctx, &format!("{MODULE}.floor_cross_claim_fill_wall_per_step_ceiling_nanosecond_count"), diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index 72f45488c44..bdf18d9f25d 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2233,7 +2233,7 @@ pub fn clear_cross_claim_pure_memos() { CROSS_CLAIM_ADMITTED_SITES.with(|a| a.borrow_mut().clear()); CROSS_CLAIM_NET_ONLY_SITES.with(|n| n.borrow_mut().clear()); CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(0)); - CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.set(0)); + CROSS_CLAIM_COST_FLOOR_CPU_NANOS.with(|c| c.set(0)); CROSS_CLAIM_STORE_DECLINES.with(|d| d.borrow_mut().clear()); CROSS_CLAIM_IN_FLIGHT_WALL_CAP_NANOS.with(|c| c.set(0)); CROSS_CLAIM_FILL_NS_PER_STEP_CEILING.with(|c| c.set(0)); @@ -2359,20 +2359,20 @@ fn retire_cross_claim_site_below_cost_floor(fn_node: &Rc, call_node: &Node CROSS_CLAIM_NET_ONLY_SITES.with(|n| n.borrow_mut().remove(&call_node.span.file, start, end)); } -/// A fill's work in evaluator-step units: the larger of the steps it performed and its thread CPU -/// converted at the declared calibration rate. STEPS ALONE UNDERCOUNT A FILL WHOSE COST IS NATIVE: -/// a nullary wrapper around an already-served producer performs a handful of steps and still pays -/// the content hash and total reification of that producer's argument row to key the lookup -/// (`dag_prepared_grammar` over `prepare_grammar(grammar:)`: 466 ms, measured on main's own fill -/// of it). Judged on steps it was declined at the floor, so every claim re-paid that keying -/// natively and outside its step budget. A rate of zero (nothing installed) leaves steps alone. -fn cross_claim_fill_work_steps(guard: &CrossClaimFillGuard) -> u64 { +/// Whether a fill is BELOW the cost floor: it performed fewer evaluator steps than the step floor +/// AND spent less thread CPU than the CPU floor. STEPS ALONE UNDERCOUNT A FILL WHOSE COST IS +/// NATIVE: a nullary wrapper around an already-served producer performs a handful of steps and +/// still pays the content hash and total reification of that producer's argument row to key the +/// lookup (`dag_prepared_grammar` over `prepare_grammar(grammar:)`: 466 ms and 1140 ms on two +/// measured fills). Judged on steps it was declined, so every claim re-paid that keying natively +/// and outside its step budget. A CPU floor of zero (nothing installed) judges on steps alone. +fn cross_claim_fill_below_cost_floor(guard: &CrossClaimFillGuard) -> bool { let steps = evaluator_steps().wrapping_sub(guard.steps_started); - let rate = CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.get()); - let cpu_nanos = thread_cpu_nanos().saturating_sub(guard.cpu_started); - let cpu_as_steps = - u64::try_from(cpu_nanos.saturating_mul(u128::from(rate)) / 1_000_000).unwrap_or(u64::MAX); - steps.max(cpu_as_steps) + if steps >= CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()) { + return false; + } + let cpu_floor = CROSS_CLAIM_COST_FLOOR_CPU_NANOS.with(|c| c.get()); + cpu_floor == 0 || thread_cpu_nanos().saturating_sub(guard.cpu_started) < cpu_floor } /// Publish one completed admitted fill: retain it in the tier, or -- at a net-only site -- net its @@ -2390,8 +2390,7 @@ fn publish_cross_claim_fill( ) { if net_only { if let Some(guard) = fill_guard { - let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); - if cross_claim_fill_work_steps(guard) < floor { + if cross_claim_fill_below_cost_floor(guard) { CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); note_cross_claim_store_outcome( func_name, @@ -2766,12 +2765,11 @@ fn store_cross_claim_pure_memo( } // THE COST FLOOR, applied to a derived producer's fill at the moment it would be retained: the // guard measured the fill's evaluator steps AND its thread CPU, so the decision rests on this - // fill's own work, native work included (`cross_claim_fill_work_steps`). + // fill's own work, native work included (`cross_claim_fill_below_cost_floor`). if let Some(guard) = fill_guard { - let floor = CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.get()); let gated = CROSS_CLAIM_SITE_GATED.with(|g| g.borrow().contains(&(Rc::as_ptr(fn_node) as usize))); - if gated && cross_claim_fill_work_steps(guard) < floor { + if gated && cross_claim_fill_below_cost_floor(guard) { CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().below_cost_floor += 1); return CrossClaimStoreOutcome::RefusedBelowCostFloor; } @@ -4008,9 +4006,9 @@ mod cross_claim_memo_tests { // retained when it is. This is the `dag_prepared_grammar` shape -- a wrapper whose cost is the // native keying of the producer beneath it -- which a steps-only floor declined on every claim. #[test] - fn a_fill_with_native_cost_and_no_steps_clears_the_floor_only_when_cpu_is_counted() { + fn a_fill_with_native_cost_and_no_steps_is_retained_only_at_or_above_the_cpu_floor() { use super::{ - install_cross_claim_cost_floor_cpu_rate, install_cross_claim_cost_floor_steps, + install_cross_claim_cost_floor_cpu_ms, install_cross_claim_cost_floor_steps, install_cross_claim_derived_share, store_cross_claim_pure_memo, thread_cpu_nanos, CrossClaimFillGuard, CrossClaimStoreOutcome, }; @@ -4021,9 +4019,12 @@ mod cross_claim_memo_tests { acc = std::hint::black_box(acc.wrapping_mul(31).wrapping_add(7)); } } - for (rate, expected) in [ + // The fill burns 2 ms of CPU and performs no steps. With no CPU floor it is judged on + // steps and declined; under a 1 ms CPU floor it is retained; under a 1000 ms one it is not. + for (cpu_floor_ms, expected) in [ (0u64, CrossClaimStoreOutcome::RefusedBelowCostFloor), - (1_000u64, CrossClaimStoreOutcome::Stored), + (1u64, CrossClaimStoreOutcome::Stored), + (1_000u64, CrossClaimStoreOutcome::RefusedBelowCostFloor), ] { super::clear_cross_claim_pure_memos(); let ctx = fresh_ctx(); @@ -4037,9 +4038,8 @@ mod cross_claim_memo_tests { no_span(), ); install_cross_claim_derived_share([derived.clone()], std::collections::HashSet::new()); - // 1000 steps: 2 ms of CPU at 1000 steps/ms is 2000 steps of work, above the floor. install_cross_claim_cost_floor_steps(1_000); - install_cross_claim_cost_floor_cpu_rate(rate); + install_cross_claim_cost_floor_cpu_ms(cpu_floor_ms); let guard = CrossClaimFillGuard::enter("tm_native"); burn_two_milliseconds_of_cpu(); let outcome = store_cross_claim_pure_memo( @@ -4051,7 +4051,7 @@ mod cross_claim_memo_tests { Some(&guard), ); drop(guard); - assert_eq!(outcome, expected, "cpu rate {rate}"); + assert_eq!(outcome, expected, "cpu floor {cpu_floor_ms} ms"); } super::clear_cross_claim_pure_memos(); } @@ -7271,9 +7271,9 @@ thread_local! { /// The declared cost floor (evaluator steps) below which a derived share's fill is not /// retained. Zero (the default) retains every admitted fill. static CROSS_CLAIM_COST_FLOOR_STEPS: std::cell::Cell = const { std::cell::Cell::new(0) }; - /// The declared calibration rate (evaluator steps per millisecond of CPU) at which a fill's - /// thread CPU is read as work against the cost floor. Zero judges on steps alone. - static CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS: std::cell::Cell = const { std::cell::Cell::new(0) }; + /// The declared CPU floor (thread CPU nanoseconds): a fill at or above it is retained however + /// few evaluator steps it performed. Zero judges on steps alone. + static CROSS_CLAIM_COST_FLOOR_CPU_NANOS: std::cell::Cell = const { std::cell::Cell::new(0) }; } /// Install the in-flight fill excusal: the outer hard cap and the nanoseconds-per-step ceiling. @@ -7287,10 +7287,9 @@ pub fn install_cross_claim_cost_floor_steps(steps: u64) { CROSS_CLAIM_COST_FLOOR_STEPS.with(|c| c.set(steps)); } -/// Install the rate at which a fill's CPU counts toward the cost floor -/// (see `CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS`). -pub fn install_cross_claim_cost_floor_cpu_rate(steps_per_ms: u64) { - CROSS_CLAIM_COST_FLOOR_STEPS_PER_MS.with(|c| c.set(steps_per_ms)); +/// Install the CPU arm of the cost floor, in milliseconds (see `CROSS_CLAIM_COST_FLOOR_CPU_NANOS`). +pub fn install_cross_claim_cost_floor_cpu_ms(cpu_ms: u64) { + CROSS_CLAIM_COST_FLOOR_CPU_NANOS.with(|c| c.set(u128::from(cpu_ms) * 1_000_000)); } /// The outermost in-flight admitted fill, as (producer, its own steps so far, its own wall so diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 066cf7db2f8..96f0166f8f0 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -14,8 +14,8 @@ import std.materialization_ladder { RefusedUnmodeledWorldRead, ExemptFreshEffect, AcceptedBelowCostFloor, AcceptedSingleRecompute, AcceptedEffectIsTheUse, RefusedNatureConflict } -import std.measure { Nanosecond, byte_size, nanosecond, nanosecond_count } -import v2.workflow.floor_eval_step_calibration { calibration_rate, floor_eval_step_calibration } +import std.measure { Millisecond, Nanosecond, byte_size, millisecond_count, nanosecond, nanosecond_count } +import v2.workflow.required_floor { required_floor_new_witness_envelope_ms } import v2.std.algebra { any, list_flat_map, list_map } // THE CROSS-CLAIM PURE-PRODUCER SHARE -- which pure computations the required floor may fill @@ -396,19 +396,28 @@ fn floor_cross_claim_share_cost_floor_eval_steps() -> Int { 5000 } -// THE FLOOR COUNTS NATIVE WORK, as declared policy: a fill's work is the larger of its evaluator -// steps and its thread CPU read as steps at the floor's own calibration rate -// (v2.workflow.floor_eval_step_calibration, the one authority that relates steps to time). Steps -// alone undercount a fill whose cost is native. The measured case: dag_prepared_grammar is a -// nullary wrapper over prepare_grammar(grammar: dag_grammar()); once prepare_grammar is served the -// wrapper performs a handful of steps, and still pays the content hash and total reification of -// the whole grammar value to key that lookup -- 466 ms on main's own fill of it (probe run -// 37160051963). Judged on steps it was declined at this floor (205 times on probe 37160050318), so -// every claim that reached it re-paid that keying natively, outside its step budget: the same -// claims ran with fewer steps and more CPU than on main. Counting CPU retains the wrapper, and a -// claim's hit is then a nullary key again. -fn floor_cross_claim_share_cost_floor_steps_per_millisecond() -> Int { - calibration_rate(calibration: floor_eval_step_calibration) +// THE FLOOR HAS A CPU ARM, as declared policy: a fill is below the floor only when it is below the +// step floor above AND its thread CPU is below this one. Steps alone undercount a fill whose cost +// is native. The measured case: dag_prepared_grammar is a nullary wrapper over +// prepare_grammar(grammar: dag_grammar()); once prepare_grammar is served the wrapper performs a +// handful of steps and still pays the content hash and total reification of the whole grammar +// value to key that lookup -- 466 ms and 1140 ms on two measured fills (probe runs 37160051963 and +// 37199261433). Judged on steps it was declined (205 times on probe 37160050318), so every claim +// that reached it re-paid that keying natively, outside its step budget. +// +// WHY THE VALUE IS THE NEW-WITNESS ENVELOPE AND NOT THE STEP FLOOR CONVERTED TO TIME. Converting +// 5000 steps at the calibration rate gives about 7 ms, and that was tried: it retained some sixty +// further producers whose fills are tens of milliseconds and whose values are large trees, the +// tier reached its byte budget, and seven claims ran over budget only with this change (probe +// 37199261433). The arm exists for a fill whose native cost by itself is a claim's whole +// allowance, so its value is that allowance: v2.workflow.required_floor +// required_floor_new_witness_envelope_ms, one authority, not a second literal. +fn floor_cross_claim_share_cost_floor_cpu() -> Millisecond { + required_floor_new_witness_envelope_ms() +} + +fn floor_cross_claim_share_cost_floor_cpu_millisecond_count() -> Int { + millisecond_count(m: floor_cross_claim_share_cost_floor_cpu()) } // THE IN-FLIGHT FILL WALL CEILING: a declared POLICY budget, in nanoseconds of wall per evaluator From 95d7e6724ce8935686e369325e7f33c0e30d33a7 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 13:31:34 +0000 Subject: [PATCH 29/33] Tier lookup verifies a served-instance argument by its digest, not by reifying it per call The lookup reified the caller's whole argument row on every call at an admitted site to verify the preimage. On main that is nearly free (roster producers are nullary); the derived share admits thousands of identities with arguments, some of them served grammars and target models, so this change had added a full walk of those values per call (DESIGN section 6, bare minimum cost). The tier now keeps a registry of the values it serves: root pointer -> content digest, computed once at publication. An argument that is a served instance is verified by that digest against the entry's digest for the same argument; any other argument is reified and compared structurally as before, and still misses on a different value. Control counts the reifies: zero for a served instance, one for an equal value built afresh, a miss for a different one. Co-Authored-By: Claude Opus 5.5 (1M context) --- .../floor_call_site_demand_seed_growth.dag | 7 + src/v1/stage0/src/v1_interpreter.rs | 228 ++++++++++++++++-- 2 files changed, 219 insertions(+), 16 deletions(-) diff --git a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag index 3934bf8ced8..15aeb7e69d0 100644 --- a/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag +++ b/dag/gunbc/floor/floor_call_site_demand_seed_growth.dag @@ -31,6 +31,13 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification = DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_fill_below_cost_floor", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimSiteSet", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "retire_cross_claim_site_below_cost_floor", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimEntry", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "served_instance_key", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "portable_is_composite", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CrossClaimArgProbe", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_arg_probes", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_entry_matches", field: WholeDeclaration }, + DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_lookup_arg_reify_count", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "install_cross_claim_in_flight_wall_bound", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "in_flight_cross_claim_fill_wall_nanos", field: WholeDeclaration }, DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_below_cost_floor_count", field: WholeDeclaration }, diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index bdf18d9f25d..86ca08ea7e7 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2038,7 +2038,16 @@ struct CrossClaimPureMemo { /// on process-global pointer identity, and equality no longer depends on which frame /// interned a spelling. Serving the stored `Value` is therefore the SAME value the walk /// used to rebuild per consuming frame, at O(1) instead of O(size). - map: HashMap<(usize, u64), Vec<(Vec<(Option, PortableValue)>, Value)>>, + map: std::collections::HashMap<(usize, u64), Vec>, + /// THE SERVED-INSTANCE REGISTRY: the root of every value this tier serves, mapped to the + /// content digest computed once, at publication, from its portable form. A served value is + /// handed out by `Rc` clone and retained here for the tier's lifetime, so its root pointer + /// names it for as long as the entry stands. It lets a caller that passes a served value as + /// an ARGUMENT be verified by digest instead of by reifying the whole argument again. + served_instances: std::collections::HashMap>, + /// Argument rows totally reified on the lookup path. A served instance passed as an argument + /// adds nothing here; everything else adds one per composite argument per call. + lookup_arg_reifies: u64, /// Stores refused at `CROSS_CLAIM_PURE_MEMO_ENTRY_CAP` or because the entry would push /// `bytes` past `CROSS_CLAIM_PURE_MEMO_BYTE_BUDGET`. Counted, never silent: the producer /// recomputes, and the receipt reads the count so saturation is visible, not inferred @@ -2059,6 +2068,113 @@ struct CrossClaimPureMemo { unportable_refusals: u64, } +/// One retained call: its argument row in portable form, each composite argument's content digest +/// (`None` for a scalar, which is compared directly), and the value served. +struct CrossClaimEntry { + args: Vec<(Option, PortableValue)>, + arg_digests: Vec>>, + served: Value, +} + +/// The identity of a served value's root: its container pointer, with the kind and the type and +/// variant symbols beside it, because a record and a re-branded record may share one field vector. +type ServedInstanceKey = (usize, u8, Option, Option); + +fn served_instance_key(v: &Value) -> Option { + match v { + Value::List(xs) => Some((Rc::as_ptr(xs) as usize, 0, None, None)), + Value::Map(m) => Some((Rc::as_ptr(m) as usize, 1, None, None)), + Value::Set(s) => Some((Rc::as_ptr(s) as usize, 2, None, None)), + Value::Record { type_name, fields } => { + Some((Rc::as_ptr(fields) as usize, 3, Some(*type_name), None)) + } + Value::Variant { + type_name, + variant_name, + fields, + } => Some(( + Rc::as_ptr(fields) as usize, + 4, + Some(*type_name), + Some(*variant_name), + )), + _ => None, + } +} + +fn portable_is_composite(v: &PortableValue) -> bool { + matches!( + v, + PortableValue::List(_) + | PortableValue::Map(_) + | PortableValue::Set(_) + | PortableValue::Record { .. } + | PortableValue::Variant { .. } + ) +} + +/// What the lookup holds for one caller argument: the digest of a served instance (no walk), or +/// the argument reified in full. +enum CrossClaimArgProbe { + ServedDigest(Rc), + Reified(PortableValue), +} + +/// One probe per caller argument. AN ARGUMENT THAT IS ITSELF A VALUE THIS TIER SERVED IS NAMED BY +/// ITS DIGEST, computed once when it was published; reifying it again on every call re-walked the +/// whole value each time (a derived site whose argument is a served grammar or target model paid +/// that per call). Any other argument is reified as before, and refuses the lookup when it is not +/// portable. +fn cross_claim_arg_probes( + ctx: &InterpContext, + args: &[(Option, Value)], +) -> Option> { + let mut out = Vec::with_capacity(args.len()); + for (_, value) in args { + let served = served_instance_key(value).and_then(|key| { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow().served_instances.get(&key).cloned()) + }); + match served { + Some(digest) => out.push(CrossClaimArgProbe::ServedDigest(digest)), + None => { + let portable = portable_value_from_ctx(ctx, value)?; + if portable_is_composite(&portable) { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().lookup_arg_reifies += 1); + } + out.push(CrossClaimArgProbe::Reified(portable)); + } + } + } + Some(out) +} + +/// Whether a retained entry's argument row is the caller's. A digest probe matches the entry's +/// digest for that argument; a reified probe matches structurally, as it always has. +fn cross_claim_entry_matches( + entry: &CrossClaimEntry, + args: &[(Option, Value)], + probes: &[CrossClaimArgProbe], +) -> bool { + entry.args.len() == args.len() + && entry + .args + .iter() + .zip(entry.arg_digests.iter()) + .zip(args.iter().zip(probes.iter())) + .all(|(((sn, sv), sd), ((an, _), probe))| { + sn == an + && match probe { + CrossClaimArgProbe::ServedDigest(d) => sd.as_ref() == Some(d), + CrossClaimArgProbe::Reified(p) => portable_value_eq(sv, p), + } + }) +} + +/// Composite-argument reifications performed by lookups so far (see `lookup_arg_reifies`). +pub fn cross_claim_lookup_arg_reify_count() -> u64 { + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow().lookup_arg_reifies) +} + /// Entry-count admission for the cross-claim tier: distinct (fn, args) keys stop being STORED /// past this. Enrolled producers are roster-declared and mostly nullary (tens of keys); the cap /// guards a mis-enrolled parametric producer with a claim-shaped argument space. Bounds @@ -2658,17 +2774,17 @@ fn try_cross_claim_pure_memo( }; let args_hash = cross_claim_args_hash(ctx, args)?; let memo_key = (Rc::as_ptr(fn_node) as usize, args_hash); - // The per-ctx hit cache is verified the same way the global bucket is: hash first, then - // the full portable argument row, so an intra-frame hash collision cannot alias either. - let portable_args = portable_args_from_ctx(ctx, args)?; + // Hash first, then the argument row itself, so a hash collision cannot alias: each argument + // is verified by the digest of the served instance it is, or by its full portable form. + let probes = cross_claim_arg_probes(ctx, args)?; // A SERVE IS AN `Rc` CLONE. There is no per-frame reconstruction left to amortize, so the // per-context hit cache this path used to maintain is gone with the walk it existed to // avoid — the DESIGN section 4b(4) dissolution: a climb deletes the lower-rung production // machinery it obsoletes. let value = CROSS_CLAIM_PURE_MEMO.with(|m| { m.borrow().map.get(&memo_key).and_then(|bucket| { - bucket.iter().find_map(|(stored_args, stored)| { - cross_claim_portable_args_match(stored_args, &portable_args).then(|| stored.clone()) + bucket.iter().find_map(|entry| { + cross_claim_entry_matches(entry, args, &probes).then(|| entry.served.clone()) }) }) })?; @@ -2802,15 +2918,16 @@ fn store_cross_claim_pure_memo( }; // The evaluated value's content identity, recorded for the caller BEFORE the presence // check, so an `AlreadyPresent` warm still reports what THIS evaluation produced. - CROSS_CLAIM_LAST_STORE_DIGEST.with(|d| { - *d.borrow_mut() = Some((func_name.to_string(), portable_value_digest(&portable))) - }); + let value_digest = portable_value_digest(&portable); + CROSS_CLAIM_LAST_STORE_DIGEST + .with(|d| *d.borrow_mut() = Some((func_name.to_string(), value_digest.clone()))); let outcome = CROSS_CLAIM_PURE_MEMO.with(|m| { let mut m = m.borrow_mut(); if let Some(bucket) = m.map.get(&memo_key) { - if bucket.iter().any(|(stored_args, _)| { - cross_claim_portable_args_match(stored_args, &portable_args) - }) { + if bucket + .iter() + .any(|entry| cross_claim_portable_args_match(&entry.args, &portable_args)) + { return CrossClaimStoreOutcome::AlreadyPresent; } } @@ -2834,10 +2951,24 @@ fn store_cross_claim_pure_memo( // The portable form has done its two jobs by here — it proved total portability and it // measured the entry — and nothing downstream needs it again. let served = value_from_portable_ctx(ctx, &portable); - m.map - .entry(memo_key) - .or_default() - .push((portable_args, served)); + // The served value's root is registered under its digest, so a later call that passes + // this value as an argument is verified without walking it; and each composite argument + // of THIS entry carries its digest for the same comparison from the other side. + if let Some(key) = served_instance_key(&served) { + m.served_instances + .insert(key, Rc::from(value_digest.as_str())); + } + let arg_digests = portable_args + .iter() + .map(|(_, v)| { + portable_is_composite(v).then(|| Rc::from(portable_value_digest(v).as_str())) + }) + .collect(); + m.map.entry(memo_key).or_default().push(CrossClaimEntry { + args: portable_args, + arg_digests, + served, + }); CrossClaimStoreOutcome::Stored }); // Only a FRESH store bills a fill: an already-present entry did no work to charge, and @@ -4001,6 +4132,71 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } + // A SERVED INSTANCE PASSED AS AN ARGUMENT IS VERIFIED BY ITS DIGEST, WITH NO REIFY; anything + // else is still reified and still refuses on a mismatch. Producer A's value is published and + // served; producer B is published over that served value as its argument. Three lookups of B: + // with the served instance (hit, zero reifies), with an equal value built afresh (hit, one + // reify -- the old path, still sound), and with a different value (miss). + #[test] + fn a_served_instance_argument_is_verified_by_digest_and_others_still_reify() { + use super::{ + cross_claim_lookup_arg_reify_count, install_cross_claim_pure_share_roster, list_value, + store_cross_claim_pure_memo, try_cross_claim_pure_memo, CrossClaimStoreOutcome, + }; + super::clear_cross_claim_pure_memos(); + let ctx = fresh_ctx(); + let node = || { + make_expr_node( + Rc::new( + crate::std_occurrence_identity::NodeOccurrenceIdentity::OccurrenceSynthetic, + ), + Rc::new(ExprData::NoExprData), + Rc::new(im_vec![]), + None, + no_span(), + ) + }; + let (a, b) = (node(), node()); + install_cross_claim_pure_share_roster([a.clone(), b.clone()]); + let built = || list_value(vec![Value::Int(1), Value::Int(2), Value::Int(3)]); + assert_eq!( + store_cross_claim_pure_memo(&ctx, &a, "tm_a", &[], &built(), None), + CrossClaimStoreOutcome::Stored + ); + let served = try_cross_claim_pure_memo(&ctx, &a, "tm_a", &[]).expect("A is served"); + let over = |v: Value| vec![(Some("x".to_string()), v)]; + assert_eq!( + store_cross_claim_pure_memo( + &ctx, + &b, + "tm_b", + &over(served.clone()), + &Value::Int(7), + None + ), + CrossClaimStoreOutcome::Stored + ); + let before = cross_claim_lookup_arg_reify_count(); + assert!(try_cross_claim_pure_memo(&ctx, &b, "tm_b", &over(served.clone())).is_some()); + assert_eq!( + cross_claim_lookup_arg_reify_count(), + before, + "a served instance is named by its digest: no reify" + ); + assert!(try_cross_claim_pure_memo(&ctx, &b, "tm_b", &over(built())).is_some()); + assert_eq!( + cross_claim_lookup_arg_reify_count(), + before + 1, + "an equal value that is not the served instance is reified, and still hits" + ); + let other = list_value(vec![Value::Int(1), Value::Int(2), Value::Int(4)]); + assert!( + try_cross_claim_pure_memo(&ctx, &b, "tm_b", &over(other)).is_none(), + "a different argument is not served another call's value" + ); + super::clear_cross_claim_pure_memos(); + } + // THE COST FLOOR COUNTS NATIVE WORK. The pair varies only the CPU rate: one fill that performs // NO evaluator steps but burns thread CPU is declined when CPU is not counted (rate zero) and // retained when it is. This is the `dag_prepared_grammar` shape -- a wrapper whose cost is the From e644ab5ac4c9c7b3dece1a6dca1acc2f314628ae Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 14:22:59 +0000 Subject: [PATCH 30/33] Fill debt: four members from probe pair 37204679518 / 37204680949 Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 96f0166f8f0..5b2c8e56bcc 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -572,8 +572,17 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // the one claim demanding a nullary producer that roster had warmed. // Five more were added from probe 37186494805, for the six rows gunbc#13060 added to the hand roster // (v2.test.claim.algebra_operator_derivation), on the same ground. +// Four more were added from the probe pair 37204679518 against 37204680949 (main 072c37b6cf): claims +// over budget only without the roster after main's corpus moved, each in a module with a producer +// only it demands. // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.callexec.synthetic_facts_key_collision", + claims: [ + SingleClaimFillDebtClaim { claim: "sfk_the_separation_is_not_specific_to_one_fixture_holds", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.algebra_operator_derivation", claims: [ @@ -848,6 +857,7 @@ data floor_single_claim_fill_debt: List = [ SingleClaimFillDebtModule { module: "v2.test.claim.compiler.kernel_value_type_roster_witness_test", claims: [ + SingleClaimFillDebtClaim { claim: "kvr_a_declared_bool_return_holding_a_bool_is_accepted_and_decided_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "kvr_a_declared_bool_return_holding_an_int_refuses_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_is_counted_not_judged_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "kvr_a_named_calls_bool_formal_holding_an_int_refuses_holds", standing: ActiveFillDebt } @@ -894,6 +904,7 @@ data floor_single_claim_fill_debt: List = [ SingleClaimFillDebtModule { module: "v2.test.claim.field_projection.field_projection_stages", claims: [ + SingleClaimFillDebtClaim { claim: "fps_a_root_bound_data_value_projects_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "fps_a_cross_module_record_projection_infers_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "fps_a_multi_root_ingest_does_not_itself_break_retrieval_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "fps_a_qualified_declaration_path_resolves_holds", standing: ActiveFillDebt }, @@ -1214,6 +1225,7 @@ data floor_single_claim_fill_debt: List = [ SingleClaimFillDebtModule { module: "v2.test.execution.infer_declaration_formation", claims: [ + SingleClaimFillDebtClaim { claim: "an_authored_empty_record_is_not_grounded_by_the_opaque_rule_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "a_coproduct_with_a_fielded_alternative_forms_a_sum_and_grounds_holds", standing: ActiveFillDebt }, SingleClaimFillDebtClaim { claim: "a_payloadless_coproduct_forms_a_sum_and_grounds_holds", standing: ActiveFillDebt } ] From a5ae2c72a78e29f58b0f96e74d9ff757b2220b97 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 15:50:19 +0000 Subject: [PATCH 31/33] Fill debt: nine members behind the nine roster rows #13038 added, from probe pair 37210396855 / 37210398646 Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 5b2c8e56bcc..56b41fc2659 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -575,8 +575,24 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // Four more were added from the probe pair 37204679518 against 37204680949 (main 072c37b6cf): claims // over budget only without the roster after main's corpus moved, each in a module with a producer // only it demands. +// Nine more were added from the probe pair 37210396855 against 37210398646 (main 44ed81c294), for the +// nine rows gunbc#13038 added to the hand roster (v2.test.claim.type_application_kind). // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.type_application_kind", + claims: [ + SingleClaimFillDebtClaim { claim: "tak_application_of_a_non_generic_declaration_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_application_with_more_arguments_than_binders_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_arguments_pair_with_parameters_in_authored_order", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_arguments_swapped_against_authored_order_refuse", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_kinded_parameter_accepts_a_nat_literal_unjudged", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_kinded_parameter_accepts_a_variant_of_its_kind", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_kinded_parameter_refuses_a_kernel_type", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_kinded_parameter_refuses_a_variant_of_another_coproduct", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "tak_unkinded_parameter_is_unchanged", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.callexec.synthetic_facts_key_collision", claims: [ From 6d7f9ae4f1aefecdfa92f81b0d843611ac478be8 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Sun, 4 Oct 2026 22:43:23 +0000 Subject: [PATCH 32/33] Fill debt: twelve members behind the sixteen roster rows #13187 added, from probe 37238532455 Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v2/workflow/floor_pure_producer_share.dag | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/src/v2/workflow/floor_pure_producer_share.dag b/src/v2/workflow/floor_pure_producer_share.dag index 78b4e2d573f..859f4143eb8 100644 --- a/src/v2/workflow/floor_pure_producer_share.dag +++ b/src/v2/workflow/floor_pure_producer_share.dag @@ -579,8 +579,27 @@ fn floor_single_claim_fill_debt_active_claims() -> List { // nine rows gunbc#13038 added to the hand roster (v2.test.claim.type_application_kind). // Those nine are RETIRED as ClaimDeleted: gunbc#13293 reverted #13038 and the module with it. If the // change re-lands, its claims are re-probed, not un-retired by hand. +// Twelve more were added from probe 37238532455, for the sixteen rows gunbc#13187 added to the hand +// roster (v2.test.claim.compiler.generic_formal_instantiation): all twelve claims of the module. // Re-derive with that probe; do not extend by hand. data floor_single_claim_fill_debt: List = [ + SingleClaimFillDebtModule { + module: "v2.test.claim.compiler.generic_formal_instantiation", + claims: [ + SingleClaimFillDebtClaim { claim: "gfi_alias_argument_at_its_aliased_formal_is_accepted", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_alias_argument_at_two_instances_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_alias_of_a_refined_type_keeps_the_refinement", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_nested_consistent_instance_is_accepted", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_nested_instance_disagreement_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_non_list_argument_at_a_list_formal_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_one_consistent_instance_is_accepted", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_one_variable_at_two_instances_refuses", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_plain_formal_takes_its_alias", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_record_wrapper_refuses_as_the_plain_formal_does", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_refined_argument_matches_through_its_carrier", standing: ActiveFillDebt }, + SingleClaimFillDebtClaim { claim: "gfi_refined_type_still_refuses_its_raw_carrier", standing: ActiveFillDebt } + ] + }, SingleClaimFillDebtModule { module: "v2.test.claim.type_application_kind", claims: [ From 628b258ed6203629c8152589e3b80fd959b47032 Mon Sep 17 00:00:00 2001 From: Brian Searls Date: Mon, 5 Oct 2026 01:53:31 +0000 Subject: [PATCH 33/33] Cross-claim lookup: a served argument matches by INSTANCE identity, never by digest alone Review 76009: cross_claim_entry_matches accepted a served composite argument on equality of portable_value_digest, a 64-bit FNV hash that is not injective, so a key-plus-digest collision served another call's value (a section 4b(3) regression from the structural check it replaced). Each entry now records the ServedInstanceKey each argument was stored as; a served probe matches only the same instance, and otherwise falls back to portable_value_eq over the argument reified at most once per lookup. The digest stays as a pre-filter that can only rule a candidate out. Control: two_values_sharing_a_digest_are_not_served_as_one_another forges an entry with the probe's digest over a different value (refused), plus the same-instance (hit, no reify) and equal-value fallback (hit, one reify) arms. Co-Authored-By: Claude Opus 5.5 (1M context) --- src/v1/stage0/src/v1_interpreter.rs | 170 +++++++++++++++++++++++----- 1 file changed, 139 insertions(+), 31 deletions(-) diff --git a/src/v1/stage0/src/v1_interpreter.rs b/src/v1/stage0/src/v1_interpreter.rs index b2754941e3f..a9f72092c87 100644 --- a/src/v1/stage0/src/v1_interpreter.rs +++ b/src/v1/stage0/src/v1_interpreter.rs @@ -2069,10 +2069,14 @@ struct CrossClaimPureMemo { } /// One retained call: its argument row in portable form, each composite argument's content digest -/// (`None` for a scalar, which is compared directly), and the value served. +/// (`None` for a scalar, which is compared directly), the served-instance identity each argument +/// WAS when stored (`None` unless the caller passed a value this tier served), and the value +/// served. The digest is a 64-bit hash and so only a PRE-FILTER: a match is established by +/// instance identity or by the portable row, never by digest equality alone. struct CrossClaimEntry { args: Vec<(Option, PortableValue)>, arg_digests: Vec>>, + arg_instances: Vec>, served: Value, } @@ -2113,15 +2117,18 @@ fn portable_is_composite(v: &PortableValue) -> bool { ) } -/// What the lookup holds for one caller argument: the digest of a served instance (no walk), or -/// the argument reified in full. +/// What the lookup holds for one caller argument: a served instance's identity and digest (no +/// walk unless an entry needs the structural fallback), or the argument reified in full. enum CrossClaimArgProbe { - ServedDigest(Rc), + Served { + key: ServedInstanceKey, + digest: Rc, + }, Reified(PortableValue), } /// One probe per caller argument. AN ARGUMENT THAT IS ITSELF A VALUE THIS TIER SERVED IS NAMED BY -/// ITS DIGEST, computed once when it was published; reifying it again on every call re-walked the +/// ITS INSTANCE, with the digest computed once when it was published as a pre-filter; reifying it again on every call re-walked the /// whole value each time (a derived site whose argument is a served grammar or target model paid /// that per call). Any other argument is reified as before, and refuses the lookup when it is not /// portable. @@ -2132,10 +2139,15 @@ fn cross_claim_arg_probes( let mut out = Vec::with_capacity(args.len()); for (_, value) in args { let served = served_instance_key(value).and_then(|key| { - CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow().served_instances.get(&key).cloned()) + CROSS_CLAIM_PURE_MEMO.with(|m| { + m.borrow() + .served_instances + .get(&key) + .map(|digest| (key, digest.clone())) + }) }); match served { - Some(digest) => out.push(CrossClaimArgProbe::ServedDigest(digest)), + Some((key, digest)) => out.push(CrossClaimArgProbe::Served { key, digest }), None => { let portable = portable_value_from_ctx(ctx, value)?; if portable_is_composite(&portable) { @@ -2148,26 +2160,52 @@ fn cross_claim_arg_probes( Some(out) } -/// Whether a retained entry's argument row is the caller's. A digest probe matches the entry's -/// digest for that argument; a reified probe matches structurally, as it always has. +/// Whether a retained entry's argument row is the caller's. A served probe matches an entry that +/// stored the SAME instance (exact: a registered instance is retained for the tier's lifetime, so +/// its root pointer cannot be reused while the entry stands). A served probe whose instance the +/// entry did not store falls back to the structural comparison, reifying the caller's argument at +/// most once per lookup into `fallback` (counted in `reifies`); the digest only rules a candidate +/// OUT, because a 64-bit FNV digest is not injective and equality of digests proves nothing. +/// A reified probe matches structurally, as it always has. Returns `None` when a fallback +/// reification refuses (the argument is not portable), which refuses the lookup. fn cross_claim_entry_matches( + ctx: &InterpContext, entry: &CrossClaimEntry, args: &[(Option, Value)], probes: &[CrossClaimArgProbe], -) -> bool { - entry.args.len() == args.len() - && entry - .args - .iter() - .zip(entry.arg_digests.iter()) - .zip(args.iter().zip(probes.iter())) - .all(|(((sn, sv), sd), ((an, _), probe))| { - sn == an - && match probe { - CrossClaimArgProbe::ServedDigest(d) => sd.as_ref() == Some(d), - CrossClaimArgProbe::Reified(p) => portable_value_eq(sv, p), + fallback: &mut [Option], + reifies: &mut u64, +) -> Option { + if entry.args.len() != args.len() { + return Some(false); + } + for (i, ((sn, sv), (an, value))) in entry.args.iter().zip(args.iter()).enumerate() { + if sn != an { + return Some(false); + } + let matched = match &probes[i] { + CrossClaimArgProbe::Reified(p) => portable_value_eq(sv, p), + CrossClaimArgProbe::Served { key, digest } => { + if entry.arg_digests[i].as_ref() != Some(digest) { + false + } else if entry.arg_instances[i].as_ref() == Some(key) { + true + } else { + if fallback[i].is_none() { + fallback[i] = Some(portable_value_from_ctx(ctx, value)?); + *reifies += 1; } - }) + fallback[i] + .as_ref() + .is_some_and(|p| portable_value_eq(sv, p)) + } + } + }; + if !matched { + return Some(false); + } + } + Some(true) } /// Composite-argument reifications performed by lookups so far (see `lookup_arg_reifies`). @@ -2781,13 +2819,23 @@ fn try_cross_claim_pure_memo( // per-context hit cache this path used to maintain is gone with the walk it existed to // avoid — the DESIGN section 4b(4) dissolution: a climb deletes the lower-rung production // machinery it obsoletes. + let mut fallback: Vec> = vec![None; args.len()]; + let mut reifies = 0u64; let value = CROSS_CLAIM_PURE_MEMO.with(|m| { - m.borrow().map.get(&memo_key).and_then(|bucket| { - bucket.iter().find_map(|entry| { - cross_claim_entry_matches(entry, args, &probes).then(|| entry.served.clone()) - }) - }) - })?; + let m = m.borrow(); + let bucket = m.map.get(&memo_key)?; + for entry in bucket { + match cross_claim_entry_matches(ctx, entry, args, &probes, &mut fallback, &mut reifies) + { + Some(true) => return Some(Some(entry.served.clone())), + Some(false) => {} + None => return None, + } + } + Some(None) + }); + CROSS_CLAIM_PURE_MEMO.with(|m| m.borrow_mut().lookup_arg_reifies += reifies); + let value = value.flatten()?; cross_claim_observe_hit(func_name); Some(value) } @@ -2964,9 +3012,14 @@ fn store_cross_claim_pure_memo( portable_is_composite(v).then(|| Rc::from(portable_value_digest(v).as_str())) }) .collect(); + let arg_instances = args + .iter() + .map(|(_, v)| served_instance_key(v).filter(|k| m.served_instances.contains_key(k))) + .collect(); m.map.entry(memo_key).or_default().push(CrossClaimEntry { args: portable_args, arg_digests, + arg_instances, served, }); CrossClaimStoreOutcome::Stored @@ -4132,13 +4185,13 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } - // A SERVED INSTANCE PASSED AS AN ARGUMENT IS VERIFIED BY ITS DIGEST, WITH NO REIFY; anything + // A SERVED INSTANCE PASSED AS AN ARGUMENT IS VERIFIED BY ITS INSTANCE, WITH NO REIFY; anything // else is still reified and still refuses on a mismatch. Producer A's value is published and // served; producer B is published over that served value as its argument. Three lookups of B: // with the served instance (hit, zero reifies), with an equal value built afresh (hit, one // reify -- the old path, still sound), and with a different value (miss). #[test] - fn a_served_instance_argument_is_verified_by_digest_and_others_still_reify() { + fn a_served_instance_argument_is_verified_by_instance_and_others_still_reify() { use super::{ cross_claim_lookup_arg_reify_count, install_cross_claim_pure_share_roster, list_value, store_cross_claim_pure_memo, try_cross_claim_pure_memo, CrossClaimStoreOutcome, @@ -4181,7 +4234,7 @@ mod cross_claim_memo_tests { assert_eq!( cross_claim_lookup_arg_reify_count(), before, - "a served instance is named by its digest: no reify" + "a served instance is named by its instance: no reify" ); assert!(try_cross_claim_pure_memo(&ctx, &b, "tm_b", &over(built())).is_some()); assert_eq!( @@ -4197,6 +4250,61 @@ mod cross_claim_memo_tests { super::clear_cross_claim_pure_memos(); } + // A DIGEST IS NOT AN IDENTITY. `portable_value_digest` is a 64-bit FNV hash, so two distinct + // values can share one. An entry is forged whose argument digest EQUALS the served probe's but + // whose stored argument is a different value and a different instance: it must not match (the + // structural fallback refuses it). The positive control is the same entry carrying the probe's + // instance key, which matches with no reify; and an equal digest over an EQUAL value that is + // not the stored instance matches through the fallback, reifying once. + #[test] + fn two_values_sharing_a_digest_are_not_served_as_one_another() { + use super::{ + cross_claim_entry_matches, list_value, served_instance_key, CrossClaimArgProbe, + CrossClaimEntry, PortableValue, + }; + let ctx = fresh_ctx(); + let probe_value = list_value(vec![Value::Int(1), Value::Int(2), Value::Int(3)]); + let key = served_instance_key(&probe_value).expect("a list has an instance key"); + let shared_digest: Rc = Rc::from("forged-collision"); + let args = vec![(Some("x".to_string()), probe_value.clone())]; + let probes = vec![CrossClaimArgProbe::Served { + key, + digest: shared_digest.clone(), + }]; + let stored_as = |stored: Vec, instance| CrossClaimEntry { + args: vec![( + Some("x".to_string()), + PortableValue::List(stored.into_iter().map(PortableValue::Int).collect()), + )], + arg_digests: vec![Some(shared_digest.clone())], + arg_instances: vec![instance], + served: Value::Int(7), + }; + let run = |entry: &CrossClaimEntry| { + let mut fallback = vec![None]; + let mut reifies = 0u64; + let hit = + cross_claim_entry_matches(&ctx, entry, &args, &probes, &mut fallback, &mut reifies) + .expect("the argument is portable"); + (hit, reifies) + }; + assert_eq!( + run(&stored_as(vec![1, 2, 4], None)), + (false, 1), + "a digest collision over a different value is refused by the structural fallback" + ); + assert_eq!( + run(&stored_as(vec![1, 2, 3], Some(key))), + (true, 0), + "the same served instance matches by identity, with no reify" + ); + assert_eq!( + run(&stored_as(vec![1, 2, 3], None)), + (true, 1), + "an equal value that is not the stored instance matches structurally" + ); + } + // THE COST FLOOR COUNTS NATIVE WORK. The pair varies only the CPU rate: one fill that performs // NO evaluator steps but burns thread CPU is declined when CPU is not counted (rate zero) and // retained when it is. This is the `dag_prepared_grammar` shape -- a wrapper whose cost is the