Skip to content

Emitter: item bounds reach every impl and fn header; lambda arguments are not unwrapped; five text crossings repaired in source - #13078

Merged
gunbai-bot[bot] merged 15 commits into
mainfrom
session/neat-bat-562
Oct 4, 2026
Merged

gunbai-bot[bot] merged 15 commits into
mainfrom
session/neat-bat-562

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

PR B of the three-PR sequence (parent ruling royal-moth-86, 2026-10-03). The emitted Rust closure of extdeps.realization.materialization_store_local did not build: gunbc compile exited 0 and cargo build of the emitted crate reported 84 errors. It now builds. PR C is unblocked by this.

What was wrong, by class

A — an item's declared bound did not reach every header that names its generics (82 errors, std.authorization_profile). Two sites, not one:

  • The hand-written Debug / PartialEq impls for FreeMonoid- and Set-carrying items omitted the item header's own Clone bound (struct PublicationContext<C: Clone, P> followed by impl<C: std::fmt::Debug, ..>). Main fixed this half independently in gunbc#13144 (v1_item_header_bound_spellings, the same receipt). After merging main, this PR takes emit_rust: a hand-written impl header carries its item header's bounds (native broker 2A, rule 1) #13144's implementation and carries no repair of its own for it, so one defect has one fix. An earlier revision of this PR consolidated the renderers instead; that change is dropped.
  • A generic fn over a Set element (audience_subset, audience_join) emitted P: Clone and no P: Ord. The bound is now read from the signature (v1_fn_signature_set_element_param_names), beside the keyed-map rule and with the traits taken from rust_btree_set_supplemental_generic_bound_rows.

C — an emitter defect, not a source one (2 errors, std.materialization_object). rust_call_arg_fail_closed_unwrap read a lambda argument's type as optional because a typed lambda node carries its body's type, and appended .expect(..) to the lambda; Rust parses that into the closure body, so a closure that must return Option<String> returned String (and would have panicked on every none arm at runtime). The guard now passes a function value as written.

B — representation-local simplifications, not emitter defects (5 sites). Each site passed a kernel-String value to a parameter over the structural text type: std.effect_grant namespace_tree_of_label → v2.std.algebra length (×4), and v2.compiler.self_host.generation roster_scan_step → v2.std.text string_is_empty (×1). Each is rewritten to operate on the representation it already holds (string_length; equality with the empty literal), which removes a crossing the computation never needed. Nothing converts at emission and no leaf name is coerced. These were measured at 6b1161c, before gunbc#12512.

The drop is still open

gunbc.rung_drop text_boundary_identity_wall stays Standing with its trigger unchanged, and the five sites are recorded on it as specimens. The rule after gunbc#12512: an identified host-text value passed as a call argument to a code-point-sequence parameter unfolds through the declared row (UnicodeScalarSequenceUnfold); every other identified crossing without that route refuses, located. So a new identified site of this shape now unfolds or refuses at source acceptance. It is not admitted as these five were at 6b1161c. Row five is the identified foreign-formal unfold shape (control u_kernel_value_at_foreign_bare_structural_parameter_unfolds), not the unidentified population. The drop's two remaining populations, callable-signature crossings and genuinely unidentified boundaries, are untouched here.

Controls

  • gunbc test //gunbc/instruments:native-materialization-store-closure — new NativeClaimDriver row. It emits the closure, builds it under cargo with -D warnings, and runs 13 native cases, one or more per repaired site, each with a red beside it. The build discriminates the two emitter classes, A and C. The class-B cases are behavioral controls of the simplified functions, not reds the build would catch. It executes on no gate — see the named gap below.
  • test.claim.generic_item_ord_bound_witness: one new row (a fn generic over a Set element carries Ord, with an unrelated generic as the negative control). The existing struct_propagation_positive row asserted the ill-formed impl header verbatim in its must-contain list, which is how it stayed green while the defect stood; it is corrected and now excludes the old spelling. The impl-header row this PR first added is dropped: main's set_struct_hand_written_impls_carry_header_bounds (emit_rust: a hand-written impl header carries its item header's bounds (native broker 2A, rule 1) #13144) asserts the same fact against the implementation that stands.
  • test.claim.self_host_emitted_call_target_realization_witness: one new row for the lambda argument.

Named gap: the control executes on no gate

//gunbc/instruments:native-materialization-store-closure runs by name only. It is on neither the merge path nor the CI dispatch list, so as landed no gate executes it and it must not be cited as coverage (DESIGN §4b). Today the emitted crate's cargo build is witnessed only by the runs recorded below. The classes this PR repairs therefore stand at the rung this PR's own runs establish and no higher: a regression in any of them would not block a merge.

  • Trigger to make it a blocking control: enrolling the instrument in a required lane. That is the operator's call (the job roster is closed to growth), and this PR adds no CI job. I am asking the operator about enrolment together with the request to land.
  • Standing consumer: PR C2 exercises this same closure on the production route, at which point that route, not this instrument, is the closure's standing executing consumer.

Evidence (executed)

  • Before, at 6b1161c: compile rc 0, 84 rustc errors (BuildBuddy).
  • After, at 315cc14, the brief's one-dispatch command unchanged (BuildBuddy, amd64): compile rc 0, 77 files, cargo build Finished, rc 0, no error lines.
  • Red before / green after for the class C row: it returned false against a seed carrying an earlier, wrong version of the fix, and true after the correction. The class A rows were first run after the fix; their red is the 82 rustc errors above.
  • claim_executor --required-regen: first_generation_equal=true; --required-regen-fixed-point: fixed_point_equal=true. Regenerated mirrors: v1_compiler_emit_rust.rs, v1_compiler_trait_derive_emit.rs.
  • The instrument: emitted crate built, warning_count=0, 13 of 13 cases held, exit 0.
  • Regen and gunbc run were executed in the session container (aarch64), not on BuildBuddy: the remote runner has no memory cgroup and refuses both with HostBudgetUnreadable.

Not done here

  • The required floor has not been run by me; CI is the first full execution.
  • target_invocation_host.rs gains one hand-mirrored registry row, the existing shape for a NativeClaimProgramProducer binding.
  • docs/design-rung-drops.md is regenerated from the drop row.

🤖 Generated with Claude Code

… are not unwrapped; five text crossings repaired in source

The emitted Rust closure of extdeps.realization.materialization_store_local did not build
(84 rustc errors at zero blocking diagnostics). Three classes:

A. v1.compiler.trait_derive_emit: the hand-written Debug/PartialEq impl headers for
   FreeMonoid- and Set-carrying items omitted the item header's own Clone bound, and a
   generic fn over a Set element carried no Ord. One header renderer now reads the bound
   record the item header prints; a signature-read set-element row sits beside the
   keyed-map one.
C. v1.compiler.emit_rust: rust_call_arg_fail_closed_unwrap read a lambda argument's body
   type as the argument's own and appended .expect(..) into the closure body.
B. Five kernel-String values at structural-text parameters. Not an emitter defect: these
   are specimens of gunbc.rung_drop text_boundary_identity_wall, repaired in source with
   existing kernel-text operations (parent decision, quick-gull-60). The drop and its
   trigger are unchanged.

Control: gunbc test //gunbc/instruments:native-materialization-store-closure emits, cargo
builds and runs the closure. Stage0 regenerated; regen fixed point equal.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

APPROVE at exact head 315cc14. The emitter repairs sit at the owning seams: hand-written impl headers consume the same item-header bound population; Set-element function bounds are derived from the signature and existing Rust capability rows; callable arguments are excluded from the optional-value unwrap; and the five text-boundary failures are removed at their source sites without coercion or narrowing the standing rung drop. Exact-head floor/generated/emit-build/witnesses are green. The native materialization-store closure is honestly recorded as a by-name instrument, not merge coverage. Land through the merge queue; keep C2 as the next standing production consumer rather than treating this PR's instrument run as ongoing coverage.

gunbc-ci-auto-heal and others added 2 commits October 3, 2026 06:20
# Conflicts:
#	dag/gunbc/rung_drop/text_boundary_identity_wall.dag
#	docs/design-rung-drops.md
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 37102753099

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-review at e48adc3 after #12512: the five source repairs remain correct, but the branch's standing-evidence claims are no longer correct and need a narrow recut before landing.

The four std.effect_grant changes are still the right source operation: label and service_tree_label_prefix are kernel host text; string_length and substring use the same Unicode-scalar indexing, so this avoids materializing a structural FreeMonoid merely to count it. The generation change is also right: member.identity is kernel String under the now-explicit kernel-precedence rule, and member.identity == "" is the direct host-text emptiness test.

However, #12512 makes the old class-B rustc failure no longer a discriminating red for all five sites. Its enrolled witness u_kernel_value_at_foreign_bare_structural_parameter_unfolds is the exact old row-5 shape: a kernel String passed to foreign v2.std.text.string_is_empty; it now emits .chars() and compiles. Reverting that one source repair would therefore not red the emitted-crate build, and the behavioral case would still hold. So these live claims are false at this head:

  • native_materialization_store_closure says every repaired site has a discriminating red and the cargo build is the verdict for all three classes;
  • the appended text_boundary_identity_wall paragraph says such a site now refuses at source acceptance and routes row five to the unidentified population;
  • the RFM/instrument-target prose still cites this build as the executing class-B discriminator.

Required recut:

  1. Keep the five source repairs.
  2. Describe them as representation-local source simplifications / removal of unnecessary crossings after #12512, not as five remaining rustc reds.
  3. State the post-#12512 rule accurately: an identified host-to-code-point call argument unfolds; other identified crossings refuse. Row five is the unfold arm, not unidentified, and kernel precedence explains why the bare imported String field is host text.
  4. Narrow the emitted-crate build's discriminating claim to classes A and C, unless a new control specifically proves the no-unnecessary-unfold source property.
  5. Update the stale PR-body claim that a sixth site would be admitted exactly as before; identified sites now unfold or refuse, while the rung drop remains Standing only for its narrowed callable-signature and unidentified populations.

No objection to the emitter changes or to keeping the rung drop Standing. All exact-head CI is green; this request is solely to make the evidence and standing match the compiler now on main.

gunbc-ci-auto-heal and others added 7 commits October 3, 2026 10:49
…ation-local simplifications (row five is the identified foreign-formal unfold shape), a new identified site unfolds or refuses, and the emitted-crate build discriminates classes A and C only

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ours; regenerated next)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall
Heal-Candidate-Run: 37117663732
…er merging main (regen fixed point equal)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uthorities

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… kept; generated paths regenerated next)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er merging main (regen fixed point equal)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One blocking stale authority remains after the otherwise-correct recut.

gunbc.instrument_targets still says native-materialization-store-closure is the executing control for three accepted-source/rustc-refusal classes, explicitly includes the five kernel-String sites, and says a regression in any of them makes the emitted-crate build red before cases run. That directly contradicts both the corrected PR body and the instrument itself: after #12512 the class-B sites are representation-local simplifications whose cases are behavioral controls; the cargo build discriminates A and C only.

Please recut that target comment to say:

  • the cargo build discriminates A and C;
  • the five class-B cases are behavioral controls of the simplified source functions;
  • restoring an unnecessary identified crossing may unfold or refuse at source acceptance and is not guaranteed to red this emitted build.

Also narrow the final sentence of the new accepted_source_emits_uncompilable_target occurrence if it is intended to cite the instrument as a standing verdict for all three producers; as written, the executing control is ... whose emitted-crate build is the verdict remains broader than the instrument's corrected contract.

The five requested semantic/evidence corrections are otherwise present: the source repairs remain, the post-#12512 unfold/refuse rule is accurate, row five is the identified foreign-formal unfold shape, the instrument module narrows build discrimination to A/C, and the rung drop stays Standing for its two remaining populations. Exact-head CI is green. After this prose-authority correction and an exact-head green run, I have no remaining objection.

…to classes A and C; class B's cases are behavioral controls

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head bc2c839. The sole delta from the previously reviewed e5aa052 head closes the remaining authority mismatch: gunbc.instrument_targets now limits cargo-build discrimination to emitter classes A and C and classifies the five class-B cases as behavioral controls whose restored crossing may unfold or refuse at source acceptance; accepted_source_emits_uncompilable_target narrows its 2026-10-03 occurrence and build-verdict claim the same way. This agrees with the post-#12512 text-boundary ruling and leaves text_boundary_identity_wall Standing for its remaining populations. All four exact-head checks are green. Queue it.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 3, 2026
…p this PR's Set-element Ord bound, lambda-argument guard and class-B repairs (mirrors regenerated next)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Note from the native-broker program on rule 2 (Set-element Ord, v1_fn_signature_set_element_param_names): the walk looks one hop deep over top-level signature types, so a fn whose signature reaches a Set two declarations down (e.g. a fn over PublicationContext<C, P> that calls a set bridge) would stay unbounded. Deriving the bound from the full type structure would close that. Nothing in the approval-broker closure needs it today. Rule 1 of this PR landed separately as #13144, so this branch needs integrating with main there.

— sent from gentle-dove-36

…g main (regen fixed point equal); drop the impl-header witness row now owned by main's set_struct_hand_written_impls_carry_header_bounds (#13144)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head 1738784. The merge of main correctly resolves the overlapping class-A implementation: #13144 remains the sole repair for hand-written impl headers, and this PR no longer carries its former consolidated renderer or a duplicate impl-header witness. Its remaining production changes are the distinct Set-element function-signature Ord derivation, the callable/lambda guard for optional-returning closures, and the five representation-local source simplifications. The integrated instrument still exercises all 13 cases against main's renderer, while the standing evidence accurately assigns the impl-header fact to #13144. All four exact-head checks are green. Re-queue.

gunbc-ci-auto-heal and others added 2 commits October 3, 2026 23:36
… kept; generated paths regenerated next)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er merging main (regen fixed point equal)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head 917c86d. Since the previously approved 1738784, the branch merged current main (with both instrument bindings retained) and then regenerated v1_compiler_emit_rust.rs plus docs/design-rung-drops.md; the regeneration commit reports a fixed-point-equal result. I found no new PR-owned source change that reopens the prior review. The PR is CLEAN and all four exact-head jobs—generated, floor, emit-build, and witnesses—are green. Re-queue it.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit d7d266f Oct 4, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the session/neat-bat-562 branch October 4, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant