Repository navigation
emit_rust: a hand-written impl header carries its item header's bounds (native broker 2A, rule 1) - #13144
Merged
Conversation
…er's bounds (WIP, mirrors not regenerated) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er bounds (fixed point verified at 561db6b) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
approved these changes
Oct 3, 2026
briansrls
left a comment
Contributor
There was a problem hiding this comment.
LGTM. The declaration and every hand-written supplemental impl now read one bound decision: header_clone_param_names is computed once, threaded through the Set and FreeMonoid struct/enum paths, unioned with each trait's own requirements, and deduplicated. The converse fixture prevents this from becoming blanket Clone, and the shared native-emission control is the right executing evidence route.
This was referenced Oct 3, 2026
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 3, 2026
…p this PR's Set-element Ord bound, lambda-argument guard and class-B repairs (mirrors regenerated next) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Oct 3, 2026
…g main (regen fixed point equal); drop the impl-header witness row now owned by main's set_struct_hand_written_impls_carry_header_bounds (#13144) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Native broker 2A, rule 1: a hand-written impl header carries its item header's bounds
Part of the native-broker program (owner gentle-dove-36): class A of the approval broker's native emission errors (
X: Clone/X: Ord/==).The defect
When a generic parameter reaches a
Set(or aFreeMonoid), the Rust emitter takesDebugandPartialEqoff the derive list and writes those impls by hand, bounding each parameter with the trait's own requirement. A derive would also have copied the declaration's bounds onto the impl; the hand-written header did not. So an item whose header earnsC: Clonefrom a bare field emittedwhich rustc refuses at the
fortype (E0277,C: Clonenot satisfied), whatever the body does.v1.compiler.emit_rustalready stated the law ("the item header and its supplemental impl headers are one fact") and applied it to one consumer only, the GroupCompletion impls, as a Bool.The fix
The header decision is taken once (
emit_item_header_clone_param_names) and is now passed as a list into every hand-written impl header:v1_set_impl_type_paramsandv1_freemonoid_impl_type_paramsunion it under the trait's own requirement (deduplicated), for structs and enums alike. The GroupCompletion Bool is derived from the same list.Two readers of the same record are deleted because they could disagree with the header:
v1_carrier_param_needs_clone_bound(it re-read the record without the callable-field subtraction the header applies) andemit_item_type_params_with_clone_bounds(the enum branch now uses the same header function as the struct branch). An unused second call tov1_emit_struct_from_capability_tableinemit_type_def_from_connectiveis removed.Evidence (one remote dispatch, amd64 runner, branch head 561db6b plus the regenerated mirrors)
Native emission control: new
gunbc test //gunbc/instruments:native-emission-controls, aNativeClaimDriverprogram (gunbc.instruments.native_emission_controls) that is emitted, built with-D warnings, and run. Its carriers have thePublicationContext/DisclosureRequestshape; six cases decide==over them, each positive paired with reds.C: Clone,P: Clone,F: Cloneat the four hand-written implswarning_count=0heldTextual witness (
test.claim.generic_item_clone_bound_witness, two new arms): the struct header and both impl headers asserted together, plus a converse control that a bare-header coproduct's impls stayP: Ord + ..and gain noClone. These two arms were not executed locally; CI's floor is their first run.Regen:
claim_executor --required-regendrifted on exactlyv1_compiler_emit_rust.rsandv1_compiler_trait_derive_emit.rs; after installing them,first_generation_equal=trueand--required-regen-fixed-pointreportsfixed_point_equal=true. No other mirror changed, so no emitted seed module carries a bound it did not carry before.Error delta
std.authorization_profileclosure (--entry dag/std/authorization_profile.dag, 13 files)The broker row is small because at this base rustc stops before reporting most of
std_authorization_profile(the 14 E0119 lane 1A's census describes as masking 73 of them); only the two visible ones (F: CloneatDisclosureRequest's Debug,==onRc<im::Vector<F>>) are in the count. On the 1A census base the same module contributes 77, and this rule removes 74 of them. That figure is derived from the small-closure run, not measured on the 1A base.What class A still contains (not this PR)
The baseline shows class A is four rules, not one. The other three stay red:
P: Ord(3 errors,std_authorization_profile.rs:74/85):audience_subset<P: Clone>reachesv1_rt::rc_set_union<T: Ord + Clone>. Next PR from this lane.std_access.rs:25-31): the broker closure holds bothstd.access::AccessRequest<S,A,O,C,E>andgunbc.auth.access_request::AccessRequest<Subject>;type_decl_itemsandclone_bounded_type_paramsare keyed by leaf name, last write wins, sostd.access's header is emitted bare. This is the site the lane brief described as "generic users don't repeat the bound"; the fixpoint does propagate it, and it does so correctly in a closure without the secondAccessRequest.Subject: Cloneat a generic fn passed as a value (2 errors,std_key_relation.rs:106).Shared instrument
native-emission-controlsis one label for all emitter-rule controls: a new rule adds its carrier, its cases and its roster identities to the program rather than a new label. It is run by name and is not a merge gate. The host change is one registry row intarget_invocation_host.rs, the hand mirrorgunbc.native_claim_program_seed_growthalready describes as one arm generic over its entry.🤖 Generated with Claude Code