Repository navigation
Emitter: item bounds reach every impl and fn header; lambda arguments are not unwrapped; five text crossings repaired in source - #13078
Conversation
… are not unwrapped; five text crossings repaired in source The emitted Rust closure of extdeps.realization.materialization_store_local did not build (84 rustc errors at zero blocking diagnostics). Three classes: A. v1.compiler.trait_derive_emit: the hand-written Debug/PartialEq impl headers for FreeMonoid- and Set-carrying items omitted the item header's own Clone bound, and a generic fn over a Set element carried no Ord. One header renderer now reads the bound record the item header prints; a signature-read set-element row sits beside the keyed-map one. C. v1.compiler.emit_rust: rust_call_arg_fail_closed_unwrap read a lambda argument's body type as the argument's own and appended .expect(..) into the closure body. B. Five kernel-String values at structural-text parameters. Not an emitter defect: these are specimens of gunbc.rung_drop text_boundary_identity_wall, repaired in source with existing kernel-text operations (parent decision, quick-gull-60). The drop and its trigger are unchanged. Control: gunbc test //gunbc/instruments:native-materialization-store-closure emits, cargo builds and runs the closure. Stage0 regenerated; regen fixed point equal. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
APPROVE at exact head 315cc14. The emitter repairs sit at the owning seams: hand-written impl headers consume the same item-header bound population; Set-element function bounds are derived from the signature and existing Rust capability rows; callable arguments are excluded from the optional-value unwrap; and the five text-boundary failures are removed at their source sites without coercion or narrowing the standing rung drop. Exact-head floor/generated/emit-build/witnesses are green. The native materialization-store closure is honestly recorded as a by-name instrument, not merge coverage. Land through the merge queue; keep C2 as the next standing production consumer rather than treating this PR's instrument run as ongoing coverage.
# Conflicts: # dag/gunbc/rung_drop/text_boundary_identity_wall.dag # docs/design-rung-drops.md
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall Heal-Candidate-Run: 37102753099
briansrls
left a comment
There was a problem hiding this comment.
Re-review at e48adc3 after #12512: the five source repairs remain correct, but the branch's standing-evidence claims are no longer correct and need a narrow recut before landing.
The four std.effect_grant changes are still the right source operation: label and service_tree_label_prefix are kernel host text; string_length and substring use the same Unicode-scalar indexing, so this avoids materializing a structural FreeMonoid merely to count it. The generation change is also right: member.identity is kernel String under the now-explicit kernel-precedence rule, and member.identity == "" is the direct host-text emptiness test.
However, #12512 makes the old class-B rustc failure no longer a discriminating red for all five sites. Its enrolled witness u_kernel_value_at_foreign_bare_structural_parameter_unfolds is the exact old row-5 shape: a kernel String passed to foreign v2.std.text.string_is_empty; it now emits .chars() and compiles. Reverting that one source repair would therefore not red the emitted-crate build, and the behavioral case would still hold. So these live claims are false at this head:
- native_materialization_store_closure says every repaired site has a discriminating red and the cargo build is the verdict for all three classes;
- the appended text_boundary_identity_wall paragraph says such a site now refuses at source acceptance and routes row five to the unidentified population;
- the RFM/instrument-target prose still cites this build as the executing class-B discriminator.
Required recut:
- Keep the five source repairs.
- Describe them as representation-local source simplifications / removal of unnecessary crossings after #12512, not as five remaining rustc reds.
- State the post-#12512 rule accurately: an identified host-to-code-point call argument unfolds; other identified crossings refuse. Row five is the unfold arm, not unidentified, and kernel precedence explains why the bare imported
Stringfield is host text. - Narrow the emitted-crate build's discriminating claim to classes A and C, unless a new control specifically proves the no-unnecessary-unfold source property.
- Update the stale PR-body claim that a sixth site would be admitted exactly as before; identified sites now unfold or refuse, while the rung drop remains Standing only for its narrowed callable-signature and unidentified populations.
No objection to the emitter changes or to keeping the rung drop Standing. All exact-head CI is green; this request is solely to make the evidence and standing match the compiler now on main.
…ation-local simplifications (row five is the identified foreign-formal unfold shape), a new identified site unfolds or refuses, and the emitted-crate build discriminates classes A and C only Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ours; regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Ledger-Rows-Repaired: docs/design-rung-drops.md text_boundary_identity_wall Heal-Candidate-Run: 37117663732
…er merging main (regen fixed point equal) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uthorities Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… kept; generated paths regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er merging main (regen fixed point equal) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
One blocking stale authority remains after the otherwise-correct recut.
gunbc.instrument_targets still says native-materialization-store-closure is the executing control for three accepted-source/rustc-refusal classes, explicitly includes the five kernel-String sites, and says a regression in any of them makes the emitted-crate build red before cases run. That directly contradicts both the corrected PR body and the instrument itself: after #12512 the class-B sites are representation-local simplifications whose cases are behavioral controls; the cargo build discriminates A and C only.
Please recut that target comment to say:
- the cargo build discriminates A and C;
- the five class-B cases are behavioral controls of the simplified source functions;
- restoring an unnecessary identified crossing may unfold or refuse at source acceptance and is not guaranteed to red this emitted build.
Also narrow the final sentence of the new accepted_source_emits_uncompilable_target occurrence if it is intended to cite the instrument as a standing verdict for all three producers; as written, the executing control is ... whose emitted-crate build is the verdict remains broader than the instrument's corrected contract.
The five requested semantic/evidence corrections are otherwise present: the source repairs remain, the post-#12512 unfold/refuse rule is accurate, row five is the identified foreign-formal unfold shape, the instrument module narrows build discrimination to A/C, and the rung drop stays Standing for its two remaining populations. Exact-head CI is green. After this prose-authority correction and an exact-head green run, I have no remaining objection.
…to classes A and C; class B's cases are behavioral controls Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Approved at exact head bc2c839. The sole delta from the previously reviewed e5aa052 head closes the remaining authority mismatch: gunbc.instrument_targets now limits cargo-build discrimination to emitter classes A and C and classifies the five class-B cases as behavioral controls whose restored crossing may unfold or refuse at source acceptance; accepted_source_emits_uncompilable_target narrows its 2026-10-03 occurrence and build-verdict claim the same way. This agrees with the post-#12512 text-boundary ruling and leaves text_boundary_identity_wall Standing for its remaining populations. All four exact-head checks are green. Queue it.
…p this PR's Set-element Ord bound, lambda-argument guard and class-B repairs (mirrors regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Note from the native-broker program on rule 2 (Set-element Ord, — sent from gentle-dove-36 |
…g main (regen fixed point equal); drop the impl-header witness row now owned by main's set_struct_hand_written_impls_carry_header_bounds (#13144) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Approved at exact head 1738784. The merge of main correctly resolves the overlapping class-A implementation: #13144 remains the sole repair for hand-written impl headers, and this PR no longer carries its former consolidated renderer or a duplicate impl-header witness. Its remaining production changes are the distinct Set-element function-signature Ord derivation, the callable/lambda guard for optional-returning closures, and the five representation-local source simplifications. The integrated instrument still exercises all 13 cases against main's renderer, while the standing evidence accurately assigns the impl-header fact to #13144. All four exact-head checks are green. Re-queue.
… kept; generated paths regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er merging main (regen fixed point equal) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Approved at exact head 917c86d. Since the previously approved 1738784, the branch merged current main (with both instrument bindings retained) and then regenerated v1_compiler_emit_rust.rs plus docs/design-rung-drops.md; the regeneration commit reports a fixed-point-equal result. I found no new PR-owned source change that reopens the prior review. The PR is CLEAN and all four exact-head jobs—generated, floor, emit-build, and witnesses—are green. Re-queue it.
PR B of the three-PR sequence (parent ruling royal-moth-86, 2026-10-03). The emitted Rust closure of
extdeps.realization.materialization_store_localdid not build:gunbc compileexited 0 andcargo buildof the emitted crate reported 84 errors. It now builds. PR C is unblocked by this.What was wrong, by class
A — an item's declared bound did not reach every header that names its generics (82 errors,
std.authorization_profile). Two sites, not one:Debug/PartialEqimpls forFreeMonoid- andSet-carrying items omitted the item header's ownClonebound (struct PublicationContext<C: Clone, P>followed byimpl<C: std::fmt::Debug, ..>). Main fixed this half independently in gunbc#13144 (v1_item_header_bound_spellings, the same receipt). After merging main, this PR takes emit_rust: a hand-written impl header carries its item header's bounds (native broker 2A, rule 1) #13144's implementation and carries no repair of its own for it, so one defect has one fix. An earlier revision of this PR consolidated the renderers instead; that change is dropped.Setelement (audience_subset,audience_join) emittedP: Cloneand noP: Ord. The bound is now read from the signature (v1_fn_signature_set_element_param_names), beside the keyed-map rule and with the traits taken fromrust_btree_set_supplemental_generic_bound_rows.C — an emitter defect, not a source one (2 errors,
std.materialization_object).rust_call_arg_fail_closed_unwrapread a lambda argument's type as optional because a typed lambda node carries its body's type, and appended.expect(..)to the lambda; Rust parses that into the closure body, so a closure that must returnOption<String>returnedString(and would have panicked on everynonearm at runtime). The guard now passes a function value as written.B — representation-local simplifications, not emitter defects (5 sites). Each site passed a kernel-
Stringvalue to a parameter over the structural text type:std.effect_grantnamespace_tree_of_label→v2.std.algebralength(×4), andv2.compiler.self_host.generationroster_scan_step→v2.std.textstring_is_empty(×1). Each is rewritten to operate on the representation it already holds (string_length; equality with the empty literal), which removes a crossing the computation never needed. Nothing converts at emission and no leaf name is coerced. These were measured at 6b1161c, before gunbc#12512.The drop is still open
gunbc.rung_droptext_boundary_identity_wallstays Standing with its trigger unchanged, and the five sites are recorded on it as specimens. The rule after gunbc#12512: an identified host-text value passed as a call argument to a code-point-sequence parameter unfolds through the declared row (UnicodeScalarSequenceUnfold); every other identified crossing without that route refuses, located. So a new identified site of this shape now unfolds or refuses at source acceptance. It is not admitted as these five were at 6b1161c. Row five is the identified foreign-formal unfold shape (controlu_kernel_value_at_foreign_bare_structural_parameter_unfolds), not the unidentified population. The drop's two remaining populations, callable-signature crossings and genuinely unidentified boundaries, are untouched here.Controls
gunbc test //gunbc/instruments:native-materialization-store-closure— newNativeClaimDriverrow. It emits the closure, builds it under cargo with-D warnings, and runs 13 native cases, one or more per repaired site, each with a red beside it. The build discriminates the two emitter classes, A and C. The class-B cases are behavioral controls of the simplified functions, not reds the build would catch. It executes on no gate — see the named gap below.test.claim.generic_item_ord_bound_witness: one new row (a fn generic over a Set element carriesOrd, with an unrelated generic as the negative control). The existingstruct_propagation_positiverow asserted the ill-formed impl header verbatim in its must-contain list, which is how it stayed green while the defect stood; it is corrected and now excludes the old spelling. The impl-header row this PR first added is dropped: main'sset_struct_hand_written_impls_carry_header_bounds(emit_rust: a hand-written impl header carries its item header's bounds (native broker 2A, rule 1) #13144) asserts the same fact against the implementation that stands.test.claim.self_host_emitted_call_target_realization_witness: one new row for the lambda argument.Named gap: the control executes on no gate
//gunbc/instruments:native-materialization-store-closureruns by name only. It is on neither the merge path nor the CI dispatch list, so as landed no gate executes it and it must not be cited as coverage (DESIGN §4b). Today the emitted crate's cargo build is witnessed only by the runs recorded below. The classes this PR repairs therefore stand at the rung this PR's own runs establish and no higher: a regression in any of them would not block a merge.Evidence (executed)
cargo buildFinished, rc 0, no error lines.falseagainst a seed carrying an earlier, wrong version of the fix, andtrueafter the correction. The class A rows were first run after the fix; their red is the 82 rustc errors above.claim_executor --required-regen:first_generation_equal=true;--required-regen-fixed-point:fixed_point_equal=true. Regenerated mirrors:v1_compiler_emit_rust.rs,v1_compiler_trait_derive_emit.rs.warning_count=0, 13 of 13 cases held, exit 0.gunbc runwere executed in the session container (aarch64), not on BuildBuddy: the remote runner has no memory cgroup and refuses both withHostBudgetUnreadable.Not done here
target_invocation_host.rsgains one hand-mirrored registry row, the existing shape for aNativeClaimProgramProducerbinding.docs/design-rung-drops.mdis regenerated from the drop row.🤖 Generated with Claude Code