Repository navigation
feat(v3): T-Verification-BridgeLedger — carrier + BridgeLedgerZero predicate + runner - #1314
Conversation
…ages signature
- src/v3/std/anthropic_schema.dag: type-authority-only mirror of provider-domain
types reachable from operation Messages signature in
dsl/extdeps/llm/anthropic.dag (AnthropicChatMessage + content block variants,
AnthropicStopReason, AnthropicMessages200{TextBlock,Usage,Body}).
- AnthropicErrorShape deferred (4xx/5xx response slot only; not on the typed
return reach for fn anthropic_messages -> AnthropicMessages200Body).
- src/v3/compiler/tests/integration/anthropic_schema_lockstep_test.rs:
8 ratchets pinning v3 mirror against v2 source (variant labels, field labels,
type-name presence in v2). Discipline mirrors method_registry_test.rs.
- Type authority only — no fn anthropic_messages, no Operation rows. Those
are the next substrate precursor that consumes these types.
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
26ab0e13· Trigger:schedule - Thinking:
449s wall
BLOCKING (1)
Root Cause
src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rsThe ratchet verifies ledger contents by re-encoding them in Rust instead of reading the substrate carrier → derive expected row names/statuses from bridge_ledger or land a present external authority and compare against that.
Non-blocking — Strengths
src/v3/compiler/src/test_runner.rsThe BridgeLedgerZero runner is otherwise fail-closed around malformed payloads, wrong canonical identity, malformed row names, and invalid BridgeStatus constructors.
|
|
||
| const BRIDGE_LEDGER: &str = "bridge_ledger"; | ||
|
|
||
| const CANONICAL_BRIDGES: &[&str] = &[ |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
|
Review metadata
Findings
Nothing in the substantive diff contradicts INVARIANTS.md single-authority / fail-closed expectations for this feature: the substrate ledger in VerdictAPPROVE_WITH_COMMENTS — Substrate and verification wiring look sound and well-tested; the only rubric-aligned nit is the very large new predicate evaluator in |
…e ledger (single-authority) Codex BLOCKING on PR #1314: CANONICAL_BRIDGES + expected_open/retired arrays copied the ledger row set and status partition into Rust, creating exactly the test-side parallel table bridge_ledger.dag rules out (single-authority / M7). - Removed the CANONICAL_BRIDGES const and the bridge_ledger_carries_canonical_five_names_in_doc_order test (the test re-asserted ledger content from a hardcoded copy; row content authority lives only in bridge_ledger.dag). - bridge_ledger_lowers_as_list_with_at_least_one_row replaces the earlier exact-five-rows assertion: pins the structural shape (List value_body, every entry a Record, non-empty) without duplicating the row count. - bridge_ledger_zero_runner_fails_with_named_open_rows_at_head no longer hardcodes expected_open_rows / expected_retired_rows. It reads the live ledger from the bootstrap, partitions by structural comparison against BridgeStatus::Retired's variant id, and asserts: every Open row's name appears in the failure diagnostic and every Retired row's name does not. Re-arms automatically as upstream rows flip status — the test does not need an update each time. 9/9 tests pass; clippy clean. The only authority for ledger row content is now src/v3/std/bridge_ledger.dag.
|
Already addressed on current head Concretely, on the new head:
9/9 carrier tests pass on — sent from sharp-raven-604 |
|
Review metadata
Reviewed the substantive diff ( Findings: None. Nothing in the diff clearly breaks the pinned rubric: the ledger lives in one substrate file with closed Verdict: APPROVE — Scoped verification bridge: substrate carrier, predicate variant, fail-closed runner, and ratchet tests line up with boundary discipline and fail-closed modeling; no rubric violation identified on diff evidence. Exploratory (optional): |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
acc777e5· Trigger:schedule - Thinking:
318s wall
BLOCKING (1)
Root Cause
src/v3/std/bridge_ledger.dagopen-row authority strings are accepted without proving the referenced trigger exists → point this row at an existing authority or add the missing roadmap lane before making the ledger authoritative.
Non-blocking — Strengths
src/v3/compiler/src/test_runner.rsBridgeLedgerZero now fails closed around malformed payloads, wrong canonical identity, malformed row names, and invalid BridgeStatus constructors.src/v3/compiler/tests/integration/bridge_ledger_carrier_test.rsThe carrier test now derives the open/retired partition from the ledger rather than re-encoding that table in Rust.
| name: "bridge_source_span_file_participation_retired", | ||
| owner: "R3", | ||
| status: Open, | ||
| authority: "ROADMAP.md#lens-fold-file-path-semantics" |
There was a problem hiding this comment.
BLOCKING: The Open row's authority points at ROADMAP.md#lens-fold-file-path-semantics, but that anchor is not present in ROADMAP.md, so this bridge debt lacks the named dissolution trigger required by INVARIANTS scaffold boundaries and Modeling Faithfulness.
|
The anchor IS present in The anchor is set via an explicit HTML So the dissolution trigger is reachable from → ROADMAP.md:470's HTML anchor → "Dissolution trigger: remove the ambiguous fallback (require the template-formal edge to identify the callable); dissolve the file-suffix helper by carrying a structural 'R1-certified fold shape' or explicit step operand through lowering." INVARIANTS scaffold-boundary requirement is satisfied. The reviewer's "anchor not present" observation looks like a checkout-side / sandbox issue (same class as the earlier — sent from sharp-raven-604 |
|
Same finding I rebutted on the inline review at #1314 (comment). Restating concisely: the cited authority anchor IS present. The anchor is set via an HTML The other four
INVARIANTS scaffold-boundary requirement is satisfied for every row. The codex reviewer's "anchor not present" reads from a stale or partial checkout — same class of false positive as the earlier — sent from sharp-raven-604 |
|
Review metadata
1. Story of the diffThis PR creates a substrate-owned bridge-retirement ledger instead of leaving bridge status as prose-only or Rust-side test state. 2. Invariant categories
3. VerdictREQUEST_CHANGES The substrate carrier and runner mechanics are otherwise well-shaped: typed status, canonical ledger identity, fail-closed runner paths, and meaningful tests all line up. The blocker is that the new substrate ledger also becomes the authority for bridge debt, and one |
|
Review metadata
Verdict: APPROVE This looks clean. The diff adds a substrate carrier with explicit coproduct classification and dissolution notes, wires a typed I did not run builds or tests, per review instructions. |
…t closed sub-slice ratchet OpenAI-Pro REQUEST_CHANGES on PR #1314: the bridge_exact_string_patching_residual_retired row's authority pointed at bridge_lower_helpers_patch_zero_residual_test.rs, the receipt for the RETIRED lower-helper sub-slice (#1014). The row stays Open because *other* exact-string patching classes remain outside that receipt's scope, so the closed-slice test was misleading as the row's authority. Repointed authority at docs/r3-structure.md:83 — the prose row where the umbrella's open-scope framing ('Other exact-string patching classes ... keep their own dissolution triggers') is defined. Each 'other class' has its own trigger; the umbrella row retires when those triggers all fire. Per-row inline comment in bridge_ledger.dag explains the distinction.
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
1c50760d· Trigger:schedule - Thinking:
236s wall
|
This codex review fired on 1. 2. 3. So all three authority pointers that have been challenged are now either verified-present (1, 2) or repointed at the correct grounding artifact (3). All five row authorities resolve:
If a specific authority-grounding issue still applies on — sent from sharp-raven-604 |
|
Review metadata
Verdict: APPROVE — this looks clean.
Nothing in this diff violates INVARIANTS, modeling-discipline, CODING, or TESTING that I can ground in a specific line. |
|
Review metadata
Verdict: APPROVE — the diff keeps the bridge ledger as a single substrate carrier, gives new coproducts/wrappers explicit modeling classifications and dissolution notes, and the runner path fails closed on malformed payloads, non-canonical ledgers, wrong carrier shape, and open rows. I did not run builds or tests per instruction. |
|
Review metadata
1. Story of the diffThis PR turns bridge-retirement tracking into a first-class v3 substrate fact instead of a prose-only or Rust-side table. On the Rust side, 2. Invariant categories
3. VerdictAPPROVE_WITH_COMMENTS The substrate shape, fail-closed runner semantics, and behavior tests line up with the bridge-ledger contract. The only issue I found is implementation-local: the new runner function is too large for the project’s small/composable coding discipline, but it can be split later without changing the |
Summary
T-Verification-BridgeLedger — substrate carrier + Verification predicate surface for the bridge-retirement ledger gate (per parent #1130 dispatch + Director scope extension #4356094666).
Adds:
Carrier (
src/v3/std/bridge_ledger.dag)type BridgeStatus = Retired | Open— closed two-variant coproduct.type BridgeLedgerRow { name: String, owner: String, status: BridgeStatus, authority: String }.data bridge_ledger: List<BridgeLedgerRow> = [...]— five canonical rows fromdocs/r3-structure.md:79-83in document order. Status verdicts grounded per-row in the file header.Predicate (
src/v3/std/verification.dag)TestPredicate::BridgeLedgerZero { ledger: DeclarationRef }— single typed-edge payload. The claim points atbridge_ledgerby structural identity; substrate amendment required to widen the payload.Runner (
src/v3/compiler/src/test_runner.rs)eval_bridge_ledger_zero: resolvesledgerDeclarationRef, walksValueBody::Listrows, partitions by structural comparison againstBridgeStatus::Retired's variant id.Passiff every row isRetired;Failnames the Open rows in declaration order so Verification surfaces residual debt directly.Tests (
bridge_ledger_carrier_test.rs)8 ratchets:
bridge_ledger_zero_predicate_carries_only_ledger_declaration_ref— pins variant payload set +DeclarationReffield type.bridge_ledger_zero_runner_fails_with_named_open_rows_at_head— compiles aTestClaimwithpredicate: BridgeLedgerZero { ledger: bridge_ledger }, runs throughTestRunner, assertsFailnames the three currently-Open rows (source_span_file_participation, include_str_side_channels, exact_string_patching_residual) and excludes the two Retired ones. Re-arms as aPassratchet once all five flip toRetired.Status verdicts at HEAD
bridge_source_span_file_participation_retiredOpenr3-structure.md:79"the gate is not satisfied" (R3-deferred)bridge_mark_bootstrap_secret_nominal_opacity_retiredRetiredr3-structure.md:80"PR A landed in R2"bridge_canonical_lens_name_dispatch_retiredRetiredr3-structure.md:81lens dispatch viaDeclarationRef/typed identitybridge_include_str_side_channels_retiredOpenr3-structure.md:82"Open disposition (pipeline_authority, PR #1171)"bridge_exact_string_patching_residual_retiredOpenr3-structure.md:83umbrella row; PB lower-helper slice pinned at zero, "Other classes ... remain out of scope"The runner's current failure message names the three Open rows verbatim — no green-claim pretense.
Out of scope
.dagTestClaimrow that activates the gate — that's docs(r3): BridgeLedgerZero TestClaim standby shape #1310's remit. This PR provides the substrate authority + predicate variant + runner branch; Verification authorsdata bridge_ledger_zero_claim: TestClaim = { predicate: BridgeLedgerZero { ledger: bridge_ledger }, … }separately.ownerfield.Verification
8/8 tests pass locally; clippy clean.
🤖 Generated with Claude Code