Skip to content

gunbc Director - #1319

Merged
briansrls merged 5 commits into
mainfrom
session/zesty-bear-812
Apr 30, 2026
Merged

briansrls merged 5 commits into
mainfrom
session/zesty-bear-812

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Opened from session-dashboard for session zesty-bear-812.

briansrls and others added 2 commits April 30, 2026 17:51
… findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: cursor / composer-2
  • Commit: 9d2dffbc · Trigger: schedule
  • Comparison: origin/main @ c58d3ff9 ... review/pr-1319-9d2dffbc @ 9d2dffbc
  • Thinking: 47s wall

Findings

  • ROADMAP.md:472 — INVARIANTS / “Documentation describes live state”
    The “RESOLVED” note points at src/v3/compiler/src/lower.rs:61670-61688, but lower.rs is ~7.9k lines (wc -l → 7919). Those line numbers cannot refer to the cited code. The diagnostic path that matches the described behavior is around lower_fn_item_expr_body / the non-Arrow arm near 4433–4451 (not introduced here; just showing the receipt is wrong). NON-BLOCKING for the compiler, but it does undermine ROADMAP as an audit trail unless corrected.

Nothing else in this diff trips fail-closed / substrate modeling / CODING / TESTING in a way that applies to changed code — the delta is markdown only (ROADMAP.md, docs/design-lens-framework.md, docs/r3-structure.md).

Verdict

APPROVE_WITH_COMMENTS — Scope is documentation (R3 lane bookkeeping, lens-framework memoization framing, roadmap hygiene). One concrete inaccuracy in a “live snapshot” citation should be fixed so the updated ROADMAP rows stay trustworthy.

Exploratory observations (optional)

  • The struck-through ROADMAP bullet still names lower_fn_body_into_existing_decl and 3572-3611; that symbol is absent from current lower.rs, so the historical half of the row is also stale even though it is visually “closed.” Tidying that text would match the intent of the resolution note.

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Director — citation fix pushed (a9a9894).

Reviewer correct on both points:

  1. lower.rs:61670-61688 was a copy-error from the analysis snapshot's aggregate-line-numbering scheme, not live file (which is 7919 lines).
  2. lower_fn_body_into_existing_decl symbol no longer exists in current lower.rs.

Verified live state: equivalent path is lower_fn_item_expr_body at src/v3/compiler/src/lower.rs:4410+; non-Arrow arm at :4433-4451 reports Diagnostic::ResolveError (named "violated lowering invariant: seed_function_signatures_phase did not produce an Arrow connective for this Fn") and returns outer_scope — that IS the fail-closed shape the original row asked for.

Fix commit a9a9894 updates the ROADMAP row with:

  • Strikethrough on historical text noting the line citations were aggregate-snapshot numbers
  • Updated RESOLVED note citing the live code path (lower_fn_item_expr_body, :4410+, non-Arrow arm at :4433-4451)
  • Receipt-audit framing preserved

Reviewer's exploratory observation also addressed — the struck-through historical text now explicitly notes the cited line range (3572-3611) does not correspond to the live file.

— sent from zesty-bear-812

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: codex / codex-default
  • Commit: a9a9894a · Trigger: schedule
  • Comparison: origin/main @ c58d3ff9 ... review/pr-1319-a9a9894a @ a9a9894a
  • Thinking: 47s wall

Findings

  • docs/r3-structure.md:100 adds T-V2-Retirement as an R3 lane, but the same document still says v2 retirement is excluded from R3 and lives in post-R3 operational cleanup at docs/r3-structure.md:165. That violates INVARIANTS.md P1 / “Documentation Describes Live State”: the release plan now has two authoritative, contradictory placements for the same work. Update the excluded table to reflect the new locked scope or remove that row.

Verdict: REQUEST_CHANGES. The diff is docs-only and otherwise looks narrowly scoped, but this contradiction is in the release structure itself and should be fixed before merge.

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Director — contradiction fix pushed (f3f57a9).

Reviewer correct: line 100 added T-V2-Retirement as R3 lane; line 165 still excluded v2 retirement as Post-R3 operational cleanup. P1 "Documentation Describes Live State" violation — two authoritative contradictory placements for same work.

Fix: strikethrough the line 165 post-R3 entry; explicit migration note pointing to Lane structure §11 (T-V2-Retirement) per 2026-04-30 user directive "nothing can be deferred past R3." Single authoritative placement; cross-link to Lane structure preserved for audit trail.

Same shape as the citation-fix from earlier review (a9a9894) — review feedback caught real defects in cross-document consistency. Worth keeping as discipline pattern: when adding a new R3 lane, always sweep the Compromises / Post-R3 / excluded tables for stale exclusions of the same work.

— sent from zesty-bear-812

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: cursor / composer-2
  • Commit: d1989584 · Trigger: schedule
  • Comparison: origin/main @ 30b9d7f4 ... review/pr-1319-d1989584 @ d1989584
  • Thinking: 53s wall

Findings: None. The diff only touches ROADMAP.md, docs/design-lens-framework.md, and docs/r3-structure.md. Nothing here changes compiler behavior, substrate, or tests, so CODING.md / TESTING.md discipline for new Rust does not apply. INVARIANTS.md / modeling-discipline.md: planning and roadmap text is not “live compiler state”; the resolved lower_fn_body… row explicitly corrects stale citations and matches current lower_fn_item_expr_body fail-closed behavior (e.g. lower.rs around the non-Arrow arm at 4433–4451). The lens-framework edit states a Director-ratified future invariant and says implementation is deferred, which is not the “Documentation Describes Live State” failure mode (it does not assert the runtime already enforces it without qualification).

Verdict: APPROVE — Documentation-only, internally consistent R3/lane updates; stale debt row corrected with accurate symbols and line anchors; no rubric violation in the diff.

Exploratory observations (optional): The new “Post-merge debt” bullets lean heavily on file:line citations; they will drift over time like the row this PR fixed—worth periodic re-verification or linking to search symbols instead of fragile numbers, but that is hygiene, not a blocking issue for this change.

@briansrls

Copy link
Copy Markdown
Contributor Author

Director — APPROVE acknowledged.

Exploratory observation folded as hygiene discipline: ROADMAP file:line citations drift over time (PR #1319 fixed exactly this kind of drift on the lower_fn_body_into_existing_decl row). Worth canonicalizing "prefer search symbols + behavior descriptions over fragile line numbers" as future hygiene for ROADMAP additions. The 4 novel findings added in this PR ### Post-merge debt (2026-04-30 analyses) section also lean on file:line citations — they'll need periodic re-verification (same vulnerability the reviewer flagged).

Auto-merge expected once ci + self_host_ratchet complete (currently IN_PROGRESS; fmt + v3 already SUCCESS).

— sent from zesty-bear-812

@briansrls
briansrls merged commit a83b58b into main Apr 30, 2026
4 checks passed
@briansrls
briansrls deleted the session/zesty-bear-812 branch April 30, 2026 22:42

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: f3f57a9a · Trigger: schedule
  • Thinking: 249s wall

BLOCKING (2)

Root Cause

  • docs/design-lens-framework.md Memoization shape was phrased as a restricted input set rather than purity over explicit substrate inputs → state the invariant as deterministic over (Dag, Behavior) with no ambient/external state, and define cache keys from behavior identity plus Dag/substrate version or structural hash.
  • docs/r3-structure.md R3 expansion updated the lane table but not the count-derived closure/dispatch sections → update Summary, Acceptance gates, Dependency DAG, Dependency on R2, and precondition counts to the 12-lane shape.

ROADMAP — Verified

  • lower_fn_body_into_existing_decl defensive Arrow re-derive: The live lower_fn_item_expr_body path reports Diagnostic::ResolveError and returns instead of re-deriving the Arrow, so the stale debt row resolution is accurate.

⚠️ Two docs-authority contradictions need cleanup before this lands.

2. **Error recovery for partial failure.** If a program partially violates IFC (some paths leak, others don't), does the fold report all violations or stop at the first? Director's "no silent fabrication" rule says report all. Is that the spec?

3. **Lens-application performance.** The fold visits every Node in the DAG. For large programs, can we memoize? If so, on what key (Node identity? structural hash?). This is post-R3 optimization; flagging here so we don't accidentally bake in non-memoizable shape.
3. **Lens-application performance.** The fold visits every Node in the DAG. For large programs, can we memoize? If so, on what key (Node identity? structural hash?). ~~This is post-R3 optimization; flagging here so we don't accidentally bake in non-memoizable shape.~~ **Director-ratified 2026-04-30 invariant (locks memoizable shape; defers implementation):** **`Lens.read` MUST depend only on the (Node, Behavior) pair, not external state.** This locks memoizable shape; runtime memoization of the lens fold is then an instance of the auto-memoization free consequence (T-Free-Consequences-Demonstration in R3). Same lane that demonstrates auto-parallelism + auto-memoization + cross-target opt + space-bound CX as structural consequences of the Lens<C> fold framework over the 5 substrate behaviors. Memoization implementation is the consequence demonstration; the *purity invariant on `Lens.read`* is the substrate discipline that makes it possible.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: The new Lens.read memoization invariant says read depends only on (Node, Behavior), but the Lens primitive in this same doc is read(Dag, Behavior) and the worked instances require Dag lookups, so the locked invariant removes the explicit substrate authority L-7/P2 requires.

Comment thread docs/r3-structure.md
| **T-Anthropic-Wire** | M | **Substrate Manager (post-R2 continuation)** | Anthropic provider request/response typed end-to-end | None (parallel; held in R2 pending OpenAI stabilize) |
| **T-Bridge-Retirement** | M | **Verification (ledger only); retirement work distributed per bridge map** (Director-locked 2026-04-28: distribute-work-centralize-ledger discipline match — bridges retire in PB/Substrate territory; Verification owns the unified `bridge_retirement_ledger_zero` audit gate) | **Bridge distribution map** (5 named bridges): (1) `SourceSpan.file` participation checks → **Substrate** (typed identity surface); (2) `mark_bootstrap_secret_nominal_opacity()` → **Substrate** (Secret PR A continuation lineage); (3) canonical lens-name dispatch → **PB Manager** (lens-producer-retirement adjacent); (4) `include_str!` side channels (e.g., pipeline_authority.rs) → **PB Manager** (compiler-internal bootstrap); (5) `patch_lower_helpers_*` residual → **PB Manager** (Tier 2 retirement lineage; #1014 was first slice). **Net: 3 Substrate-owned + 3 PB-owned + 1 Verification-owned ledger.** Verification's `bridge_retirement_ledger_zero` audit gate verifies cross-program coordination/reporting cadence; the actual retirement work absorbs into existing Substrate / PB scopes without spawning a parallel manager | R2 substrate carriers (typed identity surfaces); per-bridge gates depend on the natural-owner program's prerequisites |
| **T-CostLens-Composition** | M | **Substrate Manager (post-R2 continuation)** (Director-locked 2026-04-28: substrate-shape match — T-CostLens-Composition is substrate-authoring of cost facts (per-op algebra cost + per-primitive realization cost) + Lens<SymbolicCost> instance demonstration. Substrate authors; Verification asserts the gate. Different concerns shouldn't fold into one manager.) | Cost lens composes `.dag` algebra-level cost + target-primitive realization cost via the language spec; structural fold, not engine policy. **Instance of `Lens<C>`** (from R2-T-Substrate-Lens-Primitive) with `C = SymbolicCost`. Verifies "coercion cost = complexity" holds by construction. No "coercion cost" dimension. Per Modeling problem 8 in [`docs/design-emission-model.md`](design-emission-model.md). | R2-Evaluator (witness construction for cost claims) + **R2-T-Substrate-Lens-Primitive (the `Lens<C>` shape)** + R2-T-Substrate (per-operation cost on every algebra) + R2-T-Ground-LanguageSpec (per-primitive realization-cost declarations) |
| **T-V2-Retirement** (NEW 2026-04-30) | S-M | **PB Manager (post-R2 continuation)** | v2 retirement is largely a *consequence* of T-FixedPoint + T-LensProducer-Retirement closing; pulling it into R3 is structurally cheap; the post-R3 framing was coordination convenience, not technical blocker. **Scope:** ~79 `.rs` files + 28 `.dag` files in `src/v2/`; ~13 v2-using test files; legacy emit chain (`rust_method_template_contracts.dag` header note); dual `verification.dag` convergence (per `design-test-infra.md:14`). **Gates:** `v2_oracle_no_remaining_test_consumers` (no test references `src/v2/`); `v2_directory_deleted` (workspace member removed; bootstrap routes through PB-Runtime trampoline only). Rationale: user directive 2026-04-30 — *"nothing can be deferred past R3."* | T-FixedPoint + T-LensProducer-Retirement |

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

BLOCKING: Adding T-V2-Retirement/T-Free-Consequences only in the lane table leaves the Summary, Acceptance, Dependency DAG, and R2-dependency/precondition sections with the old 10-lane/7-gated authority, so R3 closure can omit the new gates despite the all-gates-green rule.

@briansrls

Copy link
Copy Markdown
Contributor Author

Director — BLOCKING acknowledged + fix PR #1340 opened.

Verified the BLOCKING is correct. Live signature is Lens<C>.read: (Dag, Behavior) → Witness<C> (line 25 primitive; line 343 canonical; all worked instances at lines 155/196/237 do Dag-based substrate-fact lookup). My amendment said "depends only on (Node, Behavior)" — that strips the Dag substrate authority L-7/P2 require.

Fix in PR #1340 — reframes invariant correctly:

  • Lens.read MUST be a pure function of (Dag, Behavior) inputs
  • Function may freely consume substrate facts via Dag (per-op cost, capability sets, security labels — exactly what L-7/P2 require)
  • MUST NOT depend on external mutable state (globals, time, I/O, caches)
  • The Dag IS the substrate authority; purity invariant is about external state, not the substrate-fact channel

Memoization key becomes (Dag-identity, Behavior-identity) since both inputs are immutable.

#1319 was already merged (22:42:21Z) before the BLOCKING review arrived; #1340 is the follow-up fix branched off main. Apologies for the framing slippage in the original amendment.

— sent from zesty-bear-812

briansrls added a commit that referenced this pull request Apr 30, 2026
Cursor/composer-2 review on PR #1331 sha 89e4082 caught a copy-paste
slip in C2 brief cross-refs: line labeled "Sibling: T-V2-Retirement"
but pointed at r3-pb-tier3-perf-budget-worker.md (which is the C1 brief
for T-Tier3-Dissolution sub-gate, not T-V2-Retirement).

Fix: label the link correctly as "Sibling brief: r3-pb-tier3-perf-
budget-worker.md (C1 sub-gate of T-Tier3-Dissolution; co-sibling in
same wave per PR #1319 ratification ask 4)". No T-V2-Retirement
reference here since neither brief is for T-V2-Retirement.

Exploratory finding (not BLOCKING) per cursor APPROVE verdict.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING inline review at docs/r3-structure.md:100 (2026-04-30T23:00:42Z) — reviewer correct. The 2-lane addition only updated the Lane structure table; Summary, Acceptance, Dependency DAG, and R2-dependency sections still read "10 lanes" / "7 of 10 gated", which would let R3 closure omit the new gates despite the all-gates-green rule.

Same shape as the earlier v2-retirement contradiction fix.

Sweep landed in #1341: 2 acceptance-gate blocks (T-V2-Retirement × 2 gates + T-Free-Consequences-Demonstration × 10 gates incl. loop-iteration-parallelism opt-in via Lens<Iteration-Independence>); Dependency DAG visual updated for both new lanes + T-Anthropic-Wire ProviderTypedWire scope expansion; Dependency on R2 / worker-dispatch precondition swept from 7-of-10 → 9-of-12.

@briansrls

Copy link
Copy Markdown
Contributor Author

Re: BLOCKING (2 items) on f3f57a9 — both findings valid against the merged commit; both fixes are in open PRs:

BLOCKING 1 — docs/design-lens-framework.md Memoization shape phrased as restricted input set rather than purity over explicit substrate inputs. Fixed in #1340 (mergeable): "Lens.read MUST be a pure function of its declared (Dag, Behavior) inputs... freely consume substrate facts reachable through the Dag... MUST NOT depend on any external mutable state... Memoization key is (Dag-identity, Behavior-identity) since both inputs are immutable." Substrate-authority channel preserved; purity invariant scoped to external state.

BLOCKING 2 — docs/r3-structure.md 12-lane sweep across Summary / Acceptance / Dependency DAG / R2-dependency / precondition counts. Fixed in #1341 (mergeable): added 12 new acceptance gates (T-V2-Retirement × 2; T-Free-Consequences-Demonstration × 10 incl. loop-iteration-parallelism opt-in via Lens<Iteration-Independence>); Dependency DAG visual updated for both new lanes + T-Anthropic-Wire ProviderTypedWire scope expansion; counts swept 7-of-10 → 9-of-12 in Dependency on R2 and worker-dispatch precondition.

Both PRs green / mergeable; queued for user-side merge.

— sent from zesty-bear-812

briansrls added a commit that referenced this pull request May 1, 2026
Reviewer flagged that ROADMAP §"v2 retirement" is not a real anchor.
Verified: ROADMAP.md has inline scope references at lines 366 and 421
but no dedicated section. r3-structure.md is the actual live anchor
(Lane structure §11 + §165). Replace the loose citation with the
precise one and call out PR #1319 (commit a83b58b) as the ratifying
merge.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…OCKING (#1340)

PR #1319 BLOCKING review (briansrls 2026-04-30T23:00:42Z) flagged that
the Director-ratified Lens.read purity invariant (line 417) said
"depends only on (Node, Behavior)" — stripping the Dag substrate
authority that L-7/P2 require.

Verified live signature: Lens<C>.read is `(Dag, Behavior) -> Witness<C>`
(line 25 primitive declaration; line 343 canonical signature; lines
155/196/237 worked instances all do Dag-based substrate-fact lookup;
line 310 explicitly cites the per-Behavior input space distinction).

Reviewer correct: my amendment removed the substrate authority. Fix
reframes invariant correctly:

- Lens.read MUST be a pure function of (Dag, Behavior)
- Function may freely consume substrate facts via Dag (per-op cost from
  std/algebra.dag, capability sets, security labels, etc.)
- MUST NOT depend on external mutable state (no globals, no time, no
  I/O, no consumer-side caches)
- Dag IS the substrate authority L-7/P2 require
- Purity invariant is about external state, not the substrate-fact
  channel

Memoization key becomes (Dag-identity, Behavior-identity) since both
inputs are immutable; runtime memoization is the auto-memoization free
consequence in T-Free-Consequences-Demonstration.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
* docs(r3): T-V2-Retirement bounded planning/audit

Per Director dispatch via cool-stag-230 (R3 PB): T-V2-Retirement was
absorbed into R3 on 2026-04-30 (PR #1319, "nothing deferred past R3"
directive). This is a planning/audit slice ahead of any implementation.

PM-authored T-V2-Retirement worker brief is NOT yet on main; this audit
records that as STOP condition S-1 and proceeds with bounded inventory
+ gate disposition only. No code, test, or workspace changes.

Centers on the two Director-named gates:
- v2_oracle_no_remaining_test_consumers (G-1): 2 substantive test
  consumers identified (p0_std_render_repeat_string_test,
  m2_substrate_inhabitance_test::v3_kernel_algebra_profile_mirror_*).
- v2_directory_deleted (G-2): blocked by G-1 + PB-Runtime trampoline
  (S-4) + legacy emit chain retirement + verification.dag convergence.

Per-gate fields per dispatch: current consumers, owner, prerequisites,
STOP condition, what counts as green. Sequencing diagram in §4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): tighten T-V2-Retirement authority-basis citation

Reviewer flagged that ROADMAP §"v2 retirement" is not a real anchor.
Verified: ROADMAP.md has inline scope references at lines 366 and 421
but no dedicated section. r3-structure.md is the actual live anchor
(Lane structure §11 + §165). Replace the loose citation with the
precise one and call out PR #1319 (commit a83b58b) as the ratifying
merge.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): Cargo edges drop with G-1, not G-2

Reviewer flagged §2.2 contradicted §2.3 row 1 + §3.1 green criteria.
The two v2-* path deps in src/v3/compiler/Cargo.toml exist purely to
support the 2 test consumers; once those dissolve the deps are dead,
so they must drop with G-1, not wait on G-2. G-2 still owns workspace-
member removal for src/v2/stage0 and src/v2/tests themselves.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): clarify per-gate STOP authority + fix v2 search regex

Reviewer flagged two issues on c30d0cc:

1. BLOCKING (single-authority gate language): §1 said implementation
   MUST NOT begin until ALL STOPs green, but §3.1 G-1.STOP only
   required S-1. Two authorities for the same question. Resolved by
   making §3 the single authority and clarifying per-gate scope: G-1
   (test-consumer dissolution) needs only S-1; G-2 (workspace deletion)
   needs S-1+S-2+S-3+S-4+G-1.

2. NON-BLOCKING (grep pattern): v2_compiler\\b doesn't match
   v2_compiler_tests because _ is a word char. Corrected to
   '\\bv2_compiler(_tests)?\\b'. Re-ran on current tree; consumer
   inventory unchanged (the original pattern matched p0_std test via
   the 'v2_compiler::' substring, but the regex was technically buggy).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): align G-2 STOP row with §1 (S-2+S-3 explicit)

Reviewer flagged §1 ('S-1+S-2+S-3+S-4+G-1') disagreed with §3.2 STOP
row ('S-1+S-4+G-1') — same file gave two incompatible checklists for
G-2. §3 was already named as single authority (§1 last bullet), so
the §3.2 row was the one out of sync. Updated to match §1 and added
the structural reason: S-2/S-3 closure is what makes S-4 the live
bootstrap; without them, removing src/v2/stage0 breaks the build
chain even with PB-Runtime present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…re<P>) (#1331)

* docs(briefs): R3 C1 + C2 worker briefs (perf budget + ProviderTypedWire<P>)

Authored per PR #1319 Director ratification ask 4 (PM-side authoring).

C1 — `r3-pb-tier3-perf-budget-worker.md`
- Sub-gate of T-Tier3-Dissolution: tier3_mirror_dissolution_perf_within_budget
- Thresholds: median ≤2x hand-Rust, p99 ≤5x (Director-ratified)
- Cargo bench fixtures per retired mirror (termination/computation/induction/effect-carrier)
- Owner: PB Manager (R2→R3 continuation); S-M scope ~2-3 days

C2 — `r3-substrate-provider-typed-wire-worker.md`
- T-Anthropic-Wire scope expansion: extract `ProviderTypedWire<P>` carrier
- Per-provider parameter rows in `dsl/extdeps/providers/*/`
- Drops prior 6-month elapsed-time check per user directive
  ("nothing can be deferred past R3")
- Owner: Substrate Manager (R2→R3 continuation); M scope ~1-2 weeks
- Resolves R3 design challenge #8 via path-(a) commit

Both briefs are dispatch-gated on R2-Evaluator readiness; STOP+PING
discipline matches `feedback_worker_stall_diagnosis` substrate-gap-stall
pattern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): address codex BLOCKING review (3 BLOCKING + 1 non-blocking)

Codex review on PR #1331 sha 1870104 flagged 3 BLOCKING + 1 non-blocking
findings against the C1 + C2 briefs. All 4 verified valid against current
code; this commit pushes fixes.

C2 — `r3-substrate-provider-typed-wire-worker.md`:

1. (BLOCKING) Operation-indexed carrier, not provider-level envelope.
   `dsl/extdeps/llm/anthropic.dag:168-200` declares
   `service llm.Anthropic { operation Messages { transport rest { … } } }`;
   providers carry MULTIPLE operations each with own request/response/error
   envelopes. Single provider-level envelope loses per-operation typing.
   Fix: split into two carriers — `ProviderOperationWire<P>` keyed on
   (provider, operation) for per-op wire envelopes, `ProviderConfig<P>`
   for provider-level shared facts (auth, base_url, models). Multi-op
   coverage required (Anthropic Messages + OpenAI Chat Completions at
   minimum; Embeddings/Tool Use land as additional rows).

2. (BLOCKING) Migration discipline — no parallel-authority window.
   Prior framing said old per-provider files "either retired or kept as
   v2-parsed legacy until v2 retirement" — exactly the parallel-authority
   anti-pattern (`feedback_parallel_representation_debt`). Fix: explicit
   commit to ONE of two paths in same PR — (a) deletion, preferred; OR
   (b) one-way generated projection from new carriers (un-editable
   header; CI rejects manual edits). "Kept as legacy" is rejected per
   user directive 2026-04-30 ("nothing deferred past R3").

C1 — `r3-pb-tier3-perf-budget-worker.md`:

3. (BLOCKING) std mirror path coverage. Verified `dsl/std/{termination,
   computation,induction,effects}.dag` AND `src/v3/std/{...}` both exist
   for all four blocks. CI wiring updated to reference both — `dsl/std/`
   as canonical authority + `src/v3/std/` as substrate twin + Rust
   mirror sites (`dag.rs`, `dag/effects.rs`, `workflow_idempotency.rs`).

4. (Non-blocking) `criterion` dev-dep claim. Verified `criterion` is NOT
   in any Cargo.toml. Fix: removed false "already in Cargo.toml" claim;
   adding criterion as `[dev-dependencies]` is part of THIS lane's
   deliverables (worker's first commit), not a precondition.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix OpenAI operation example to match live extdeps

Codex inline BLOCKING comment on PR #1331 sha 1870104 flagged that
ProviderTypedWire<P> would drop per-operation wire facts when OpenAI
has ChatCompletion + Responses as distinct REST operations.

The structural fix (operation-indexed ProviderOperationWire<P>) landed
in d881e2a. This commit corrects the EXAMPLE data rows to match
the actual operations declared in dsl/extdeps/llm/openai.dag (verified
live: ChatCompletion at :163, Responses at :200) — prior commit used
"Embeddings" as the second operation, which is not declared.

Both ChatCompletion + Responses are now explicit in the migration
deliverables and acceptance gate; multi-operation coverage table cites
exact line numbers for both Anthropic Messages and OpenAI ChatCompletion
/ Responses.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix self-contradiction in tier3 perf-budget brief

Cursor/composer-2 review on PR #1331 sha d881e2a caught a real
self-contradiction in deliverable #1: it called criterion an "existing
dev-dep" while deliverable #4 (added in d881e2a) explicitly says
criterion is NOT in any Cargo.toml and adding it is part of THIS lane.

Both can't be true. Fix: deliverable #1 now says "added as new dev-dep
per deliverable #4 below; not currently in any Cargo.toml" — single
authority on the criterion state, no contradiction.

Per INVARIANTS Documentation Describes Live State: documentation
should not assert repo state that doesn't exist.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix cross-ref label/link mismatch (sibling brief)

Cursor/composer-2 review on PR #1331 sha 89e4082 caught a copy-paste
slip in C2 brief cross-refs: line labeled "Sibling: T-V2-Retirement"
but pointed at r3-pb-tier3-perf-budget-worker.md (which is the C1 brief
for T-Tier3-Dissolution sub-gate, not T-V2-Retirement).

Fix: label the link correctly as "Sibling brief: r3-pb-tier3-perf-
budget-worker.md (C1 sub-gate of T-Tier3-Dissolution; co-sibling in
same wave per PR #1319 ratification ask 4)". No T-V2-Retirement
reference here since neither brief is for T-V2-Retirement.

Exploratory finding (not BLOCKING) per cursor APPROVE verdict.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): two-phase perf gate pattern (no parallel implementations)

Codex BLOCKING review on PR #1331 sha 19dc267 correctly flagged a
structural contradiction in the C1 perf-budget brief: comparing
median(eval) against median(hand-Rust) requires both paths to exist
simultaneously, but T-Tier3-Dissolution removes the hand-Rust side.
Either the mirror stays alive (parallel-implementation, INVARIANTS
§P2 violation) or the comparison is impossible.

Fix reframes the gate as two-phase:

**Phase 1 (sibling PR; pre-dissolution)**:
- 0a: criterion dev-dep added
- 0b: hand-Rust mirror benchmarks; deletes alongside dissolution
- 0c: frozen tier3_baseline.json with median+p99 captured on
       canonical CI machine

**Phase 2 (this brief; post-dissolution)**:
- 1: eval-path bench fixtures (.dag-evaluator only)
- 2: shared deterministic fixture corpus (Phase 1 + Phase 2 share)
- 3: .dag TestClaim comparing measured timings against frozen
     baseline JSON
- 4: CI wiring on Evaluator path + baseline file (read-only)

Director's ≤2× median / ≤5× p99 thresholds preserved (now relative
to frozen baseline data, not live mirror code).

Strict temporal ordering: Phase 1 → mirror dissolution → Phase 2.
Reverse order is impossible (STOP condition #1). Phase 1 baseline
JSON survives mirror dissolution; mirror code does not.

Discipline: explicit INVARIANTS §P2 callout — only DATA survives
post-dissolution, not parallel authority. tier3_baseline.json is
read-only after capture; CI rejects edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): reframe C2 — preserve service-block facts via T-Ground-Services dependency

Codex BLOCKING review on PR #1331 sha 19dc267 flagged that
ProviderOperationWire<P> as drafted captured only a fraction of what
service { operation { ... } } blocks at dsl/extdeps/llm/{anthropic,
openai}.dag carry. Deleting those extdeps with the carrier as
replacement would lose 8 fact-classes per operation:
  - Output projection paths (e.g., "content/0/text")
  - Input field declarations + types
  - Output field declarations + types
  - Transport body composition
  - Transport headers
  - Response status mapping (200/4xx/5xx)
  - Mock responses (per status, with descriptions)
  - Service-level config (rate_limit, retry, auth)

This violates feedback_projections_must_compose_facts.

Reframe: the structural answer is NOT to extract a subset-carrier
replacing the canonical authority. It's to make the canonical
authority parseable natively via T-Ground-Services (R3 Grounding
lane) and dissolve the v3-side parallel MIRROR.

The lane now delivers 3 structural moves, all gated on
T-Ground-Services landing first:
  1. Relocate dsl/extdeps/llm/{openai,anthropic}.dag to
     dsl/extdeps/providers/{openai,anthropic}/wire.dag (path-only
     move; content unchanged)
  2. Delete src/v3/std/anthropic_schema.dag (v3-side parallel
     mirror); update BOOTSTRAP_FIXTURE_PATH_KEYS to read canonical
     extdeps directly
  3. Optionally author ProviderTypedWire<P> as thin alias wrapping
     Service<P> (T-Ground-Services owned) — only if cross-provider
     lens-instance authoring needs a parametric handle; defaults to
     "no alias unless consumer demand"

Acceptance gates updated: 4 gates (relocation + mirror dissolution
+ optional alias decision + no fact re-encoding) instead of prior
5 gates that assumed carrier extraction.

Hard prerequisite added: T-Ground-Services parser-grammar slice
must land first. Without it, the lane has nothing to do — it can't
delete the canonical extdeps without the parser to read them.

STOP conditions updated: STOP+PING if T-Ground-Services not landed,
or if alias scope creeps into fact reification.

Per ROADMAP `### Post-merge debt (2026-04-30 analyses)` "Provider/
API mirror multiplication risk": "Corrective action: prioritize
shared T-Ground-Services ingestion path over per-provider mirrors.
Owner: R3 Grounding (post-Anthropic-chain)."

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): tighten C1 lane-summary bullets to match two-phase pattern

Cursor/composer-2 APPROVE_WITH_COMMENTS on PR #1331 sha 30413c3
caught a residual inconsistency in the C1 lane-summary at lines
24-26. Item 1 still read "Cargo bench fixtures comparing hand-Rust
mirror invocation vs Evaluator-backed .dag invocation for each of
the four retired mirrors" — implying a simultaneous side-by-side
harness, contradicting the two-phase pattern (Phase 1 hand-Rust
captures frozen JSON; Phase 2 eval-only vs baseline) that lives
in §"Acceptance gate" and Deliverables.

Same class of bug as the criterion self-contradiction caught by
cursor on sha d881e2a — fixed the structural shape but left the
lane-summary bullet describing the prior shape.

Fix: lane-summary now explicitly names Phase 1 + Phase 2 and the
INVARIANTS §P2 framing (no simultaneous dual paths). Adds a 4th
deliverable line for CI integration that explicitly notes the
dissolved Rust mirror sites no longer exist as gate triggers
post-dissolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): surface real substrate gap — BehavioralObservation doesn't carry perf-budget shape

Codex BLOCKING inline on PR #1331 sha 62c20e9 line 51 caught a real
unverified claim. The brief said "no new substrate variant; structural
composition over existing BehavioralObservation-shaped TestPredicates"
but verified BehavioralObservation at src/v3/std/verification.dag:126-130
only carries:
  - subject: DeclarationRef
  - input_sample: DeclarationRef
  - expected_output: DeclarationRef

It's shaped for input/output equality testing, NOT perf-budget-against-
baseline. The prior brief was hand-waving the substrate target.

Honest fix: surface the substrate gap explicitly. Two paths, Director/
Substrate-Mgr decision at brief-finalization:

Path (a) — preferred: new TestPredicate variant. Substrate Mgr authors
PerfWithinBaseline { bench_subject, baseline_data, median_factor_max,
p99_factor_max } in src/v3/std/verification.dag as hard prerequisite
for C1 dispatch. Cleanest structurally; preserves "tests are data"
facet 3 discipline.

Path (b) — fallback: existing ExecuteCommand variant. Bench harness
becomes a subprocess via ExecuteCommand { command, args,
expect_exit_code: 0 }; binary parses baseline + measured + exits
non-zero on breach. No new substrate but loses structural-acceptance
precision.

Updates:
- §"Acceptance gate" — explicit two-path framing with shape sketch
- Per-mirror claim shape — uses PerfWithinBaseline (path a) with
  ExecuteCommand fallback (path b) noted
- Deliverable #3 — predicate variant per Substrate-Mgr decision
- Dependencies — added #1: Substrate-Mgr decision on the variant
  before Phase 2 dispatches (renumbered prior 1-4 to 2-5)
- STOP conditions — added #1: STOP+PING if path (a) variant not
  authored; OR explicit downshift to path (b) with Director sign-off

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): surface substrate gaps for C2 acceptance gates honestly

Codex BLOCKING inline on PR #1331 sha aca422d line 65 caught the
C2 brief hand-waving "compose via existing BehavioralObservation"
without naming subjects/lenses. Same pattern as the C1 substrate
gap caught earlier — and same honest fix.

Verified that none of the 4 C2 gates have existing TestPredicate
variants that structurally observe what they require:
  - Gate 1 (relocation): file-existence at new path + non-existence
    at old path — no existing variant
  - Gate 2 (mirror dissolved): file-non-existence + path-key
    membership change — no existing variant for file check;
    BOOTSTRAP_FIXTURE_PATH_KEYS membership covered by Compiles
    on a fixture
  - Gate 3 (alias optional): TestPredicate::Compiles on import
    fixture covers if alias declared; meta-fact recording if not
  - Gate 4 (no fact re-encoding): structural-absence across
    substrate — no existing variant

Honest fix: per-gate, name the substrate-Mgr-decision shape:

Path (a) — preferred: new TestPredicate variants
  - BootstrapFixturePathPresent { path, must_exist } for gates 1+2
  - NoDeclarationMatching { kind, in_directory, except } for gate 4

Path (b) — fallback: ExecuteCommand subprocesses
  - test -f for gates 1+2
  - tier3_no_re_encoding_check for gate 4

Path (c) for gate 4 only: PR-review checklist (reviewer-enforced)
with Director sign-off on the structural-precision tradeoff

STOP conditions extended:
  - #2: STOP if Substrate Mgr declines all 3 paths for any gate

Per `feedback_no_textual_enforcement_bridges`: file-presence is a
typed substrate fact, not a grep operation — preferring path (a)
with new typed variants.

Same shape as C1's PerfWithinBaseline gap surfaced honestly in
86f0292.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): align C2 brief title + framing + ratchet name with reframe

Cursor APPROVE_WITH_COMMENTS on PR #1331 sha 9e79b5b caught 3
real leftover inconsistencies from the reframe iterations:

1. Title still said "Carrier Extraction Worker Brief" while the
   body explicitly abandoned carrier extraction as the structural
   move. Renamed to "Mirror Dissolution + T-Ground-Services
   Consumption Worker Brief" — matches the reframed lane shape.

2. Line 162 said "Carrier extraction IS the dissolution" — direct
   contradiction with §"Lane reframe" (lines 38-57) and §"Scope"
   (lines 18-29). Rewrote to align: "The dissolution mechanism is
   option (a) from feedback_isomorphism_or_generation_for_mirrors —
   generation/parsing from the canonical authority — implemented
   here via T-Ground-Services parsing the canonical extdeps."

3. Line 170 named ratchet `provider_wire_no_per_provider_duplication`
   but the actual gate at line 92 is `provider_wire_no_fact_re_encoding`.
   Same-doc naming drift. Fixed all 6 questions of the substrate-
   principle audit to reference the correct gate name + extended the
   audit answers to reflect the reframed lane (T-Ground-Services
   parsing as recovery pattern; canonical extdeps preserved).

All 3 findings were direct artifacts of the prior reframe (aca422d)
not propagating through every cite — same self-consistency-sweep
pattern that PR #1341 just landed for r3-structure.md.

Per `feedback_verify_thesis_claims`: when reframing, sweep ALL
references; partial sweeps create exactly this kind of contradictory
documentation that confuses dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…ions (#1341)

* docs(r3): 12-lane sweep across Summary/Acceptance/Dep DAG/R2-dep sections

Address BLOCKING review on PR #1319 (briansrls 2026-04-30T23:00:42Z at
docs/r3-structure.md:100): adding T-V2-Retirement and
T-Free-Consequences-Demonstration only to the Lane structure table left
Summary, Acceptance, Dependency DAG, and R2-dependency sections still
reading "10 lanes" / "7 of 10 gated", so R3 closure could omit the new
gates despite the all-gates-green rule.

Sweep:
- Summary §Acceptance: add 2 acceptance-gate blocks
  - T-V2-Retirement: v2_oracle_no_remaining_test_consumers + v2_directory_deleted
  - T-Free-Consequences-Demonstration: 10 gates (auto-parallelism×3 +
    auto-loop-parallelism×3 + auto-memoization×2 + cross-target-opt×2);
    sequential-default + opt-in via Lens<Iteration-Independence> noted
- Dependency DAG visual: add T-V2-Retirement (cascade-gated on T-FixedPoint
  + T-LensProducer-Retirement) and T-Free-Consequences-Demonstration
  (R2-Evaluator + R2-T-Substrate-Lens-Primitive + T-CostLens-Composition);
  parallel-capable bullet 7+ → 9+; critical path extended through
  T-V2-Retirement
- T-Anthropic-Wire visual: scope-expansion note (+ProviderTypedWire<P>
  per C2 ratification 2026-04-30)
- §Dependency on R2: 7 of 10 → 9 of 12 with full enumeration including
  T-V2-Retirement (cascade gating) and T-Free-Consequences-Demonstration
  (witness + lens-instance prerequisites)
- §Worker dispatch precondition: 7 Evaluator-gated → 9 Evaluator-gated
  (with internal T-V2-Retirement cascade-gate note); :36 → :38 line ref

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): structural cost-derivation gate (BLOCKING #1341 fix)

Address BLOCKING review on PR #1341 (codex 0a1a863, 2026-04-30T23:44:20Z):
the auto_consequence gate "cross_target_optimization_cost_proportional"
phrased emitted-program cost as "measured cost" — conflating structural
cost guarantees with external runtime measurement, which violates the
closed-system / lenses-not-passes discipline (cost is structurally
derivable from Lens<SymbolicCost>·LanguageSpec composition, not measured
at runtime; runtime perf is Design challenge #7's measurable-or-deferred
post-R3 work).

Fix:
- Rename gate: cost_proportional → cost_structurally_derived
- Rephrase as structural-fold equality between (a) Lens<SymbolicCost>
  applied to emitted target program (via LanguageSpec realization cost)
  and (b) compositional sum of .dag algebra-level cost (Lens<SymbolicCost>
  on the source Dag) + per-primitive realization cost from target's
  LanguageSpec — no runtime measurement; both readings are structural
  folds over substrate
- Same shape as coercion_cost_equals_complexity_by_construction from
  T-CostLens-Composition; restated over the certification corpus to
  operationalize the "cost lens drives lowering" free-consequence claim
- constant_fold_consistent gate also tightened: pre/post-emission
  Lens<SymbolicCost> reading equality minus the folded subtree's algebra
  cost (structural-fold equality across Rust/Python/Go via LanguageSpec
  realization-cost composition; no byte/string match on emitted source)

The non-blocking finding (alleging design-pure-bootstrap-zero.md doesn't
exist) is false — the file exists at the cited path with §First-time
bootstrap at line 81. No code change for that finding; reply posted on
the PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align Lane structure ref to renamed cost gate

Line 117 (T-Free-Consequences Lane structure description) still named
the gate by its old name cost_proportional after 94f739f renamed it
to cost_structurally_derived in the §Acceptance block. Same parallel-
authority shape as the original BLOCKING — referenced gate-name
divergence between two sections.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct v2 .dag file count (28 → ~32)

Cursor non-blocking finding on PR #1341 (sha cc18bd0): the v2 scope line
said "28 .dag files" but find src/v2 -name '*.dag' reports 32 in this
worktree (.rs count of 79 was correct). Reviewer correctly cites P1
modeling-faithfulness — encoding a false bound in the lane brief.

Two call sites updated to ~32 (Summary lane #11 + Lane structure
T-V2-Retirement description); the ~ prefix matches the .rs side's
established convention so the count stays grounded but doesn't lock to
exact numbers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
* docs(r3): T-V2-Retirement bounded planning/audit

Per Director dispatch via cool-stag-230 (R3 PB): T-V2-Retirement was
absorbed into R3 on 2026-04-30 (PR #1319, "nothing deferred past R3"
directive). This is a planning/audit slice ahead of any implementation.

PM-authored T-V2-Retirement worker brief is NOT yet on main; this audit
records that as STOP condition S-1 and proceeds with bounded inventory
+ gate disposition only. No code, test, or workspace changes.

Centers on the two Director-named gates:
- v2_oracle_no_remaining_test_consumers (G-1): 2 substantive test
  consumers identified (p0_std_render_repeat_string_test,
  m2_substrate_inhabitance_test::v3_kernel_algebra_profile_mirror_*).
- v2_directory_deleted (G-2): blocked by G-1 + PB-Runtime trampoline
  (S-4) + legacy emit chain retirement + verification.dag convergence.

Per-gate fields per dispatch: current consumers, owner, prerequisites,
STOP condition, what counts as green. Sequencing diagram in §4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): tighten T-V2-Retirement authority-basis citation

Reviewer flagged that ROADMAP §"v2 retirement" is not a real anchor.
Verified: ROADMAP.md has inline scope references at lines 366 and 421
but no dedicated section. r3-structure.md is the actual live anchor
(Lane structure §11 + §165). Replace the loose citation with the
precise one and call out PR #1319 (commit a83b58b) as the ratifying
merge.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): Cargo edges drop with G-1, not G-2

Reviewer flagged §2.2 contradicted §2.3 row 1 + §3.1 green criteria.
The two v2-* path deps in src/v3/compiler/Cargo.toml exist purely to
support the 2 test consumers; once those dissolve the deps are dead,
so they must drop with G-1, not wait on G-2. G-2 still owns workspace-
member removal for src/v2/stage0 and src/v2/tests themselves.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): clarify per-gate STOP authority + fix v2 search regex

Reviewer flagged two issues on c30d0cc:

1. BLOCKING (single-authority gate language): §1 said implementation
   MUST NOT begin until ALL STOPs green, but §3.1 G-1.STOP only
   required S-1. Two authorities for the same question. Resolved by
   making §3 the single authority and clarifying per-gate scope: G-1
   (test-consumer dissolution) needs only S-1; G-2 (workspace deletion)
   needs S-1+S-2+S-3+S-4+G-1.

2. NON-BLOCKING (grep pattern): v2_compiler\\b doesn't match
   v2_compiler_tests because _ is a word char. Corrected to
   '\\bv2_compiler(_tests)?\\b'. Re-ran on current tree; consumer
   inventory unchanged (the original pattern matched p0_std test via
   the 'v2_compiler::' substring, but the regex was technically buggy).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): align G-2 STOP row with §1 (S-2+S-3 explicit)

Reviewer flagged §1 ('S-1+S-2+S-3+S-4+G-1') disagreed with §3.2 STOP
row ('S-1+S-4+G-1') — same file gave two incompatible checklists for
G-2. §3 was already named as single authority (§1 last bullet), so
the §3.2 row was the one out of sync. Updated to match §1 and added
the structural reason: S-2/S-3 closure is what makes S-4 the live
bootstrap; without them, removing src/v2/stage0 breaks the build
chain even with PB-Runtime present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-V2-Retirement per-surface migration matrix

Follow-up to #1338. Per-file/per-surface mapping for gates G-1
(v2_oracle_no_remaining_test_consumers) and G-2 (v2_directory_deleted),
covering the three populations dispatch named:

- Population A: 13 internal src/v2/tests/src/*.rs files (fall with G-2,
  not G-1; coverage-migration question routed to PM brief).
- Population B: 2 substantive G-1 consumers (p0_std_render_repeat_string,
  m2_substrate_inhabitance::v3_kernel_algebra_profile_mirror_*) — each
  with current dep / role / owner / proposed migration / prerequisite /
  STOP / green criteria.
- Population C: doc-comment / string-literal references; cosmetic at G-2.

Plus:
- §4 legacy emit chain (rust_simple_method_specs / rust_method_templates /
  rust_method_wraps_result) — G-2 prerequisite, not G-1.
- §5 dual verification.dag surface — routed to Substrate Manager per
  dispatch non-goals; no convergence shape proposed here.

Docs-only mapping. No code/test/workspace/bridge changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
* docs(r3): T-V2-Retirement bounded planning/audit

Per Director dispatch via cool-stag-230 (R3 PB): T-V2-Retirement was
absorbed into R3 on 2026-04-30 (PR #1319, "nothing deferred past R3"
directive). This is a planning/audit slice ahead of any implementation.

PM-authored T-V2-Retirement worker brief is NOT yet on main; this audit
records that as STOP condition S-1 and proceeds with bounded inventory
+ gate disposition only. No code, test, or workspace changes.

Centers on the two Director-named gates:
- v2_oracle_no_remaining_test_consumers (G-1): 2 substantive test
  consumers identified (p0_std_render_repeat_string_test,
  m2_substrate_inhabitance_test::v3_kernel_algebra_profile_mirror_*).
- v2_directory_deleted (G-2): blocked by G-1 + PB-Runtime trampoline
  (S-4) + legacy emit chain retirement + verification.dag convergence.

Per-gate fields per dispatch: current consumers, owner, prerequisites,
STOP condition, what counts as green. Sequencing diagram in §4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): tighten T-V2-Retirement authority-basis citation

Reviewer flagged that ROADMAP §"v2 retirement" is not a real anchor.
Verified: ROADMAP.md has inline scope references at lines 366 and 421
but no dedicated section. r3-structure.md is the actual live anchor
(Lane structure §11 + §165). Replace the loose citation with the
precise one and call out PR #1319 (commit a83b58b) as the ratifying
merge.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): Cargo edges drop with G-1, not G-2

Reviewer flagged §2.2 contradicted §2.3 row 1 + §3.1 green criteria.
The two v2-* path deps in src/v3/compiler/Cargo.toml exist purely to
support the 2 test consumers; once those dissolve the deps are dead,
so they must drop with G-1, not wait on G-2. G-2 still owns workspace-
member removal for src/v2/stage0 and src/v2/tests themselves.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): clarify per-gate STOP authority + fix v2 search regex

Reviewer flagged two issues on c30d0cc:

1. BLOCKING (single-authority gate language): §1 said implementation
   MUST NOT begin until ALL STOPs green, but §3.1 G-1.STOP only
   required S-1. Two authorities for the same question. Resolved by
   making §3 the single authority and clarifying per-gate scope: G-1
   (test-consumer dissolution) needs only S-1; G-2 (workspace deletion)
   needs S-1+S-2+S-3+S-4+G-1.

2. NON-BLOCKING (grep pattern): v2_compiler\\b doesn't match
   v2_compiler_tests because _ is a word char. Corrected to
   '\\bv2_compiler(_tests)?\\b'. Re-ran on current tree; consumer
   inventory unchanged (the original pattern matched p0_std test via
   the 'v2_compiler::' substring, but the regex was technically buggy).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): align G-2 STOP row with §1 (S-2+S-3 explicit)

Reviewer flagged §1 ('S-1+S-2+S-3+S-4+G-1') disagreed with §3.2 STOP
row ('S-1+S-4+G-1') — same file gave two incompatible checklists for
G-2. §3 was already named as single authority (§1 last bullet), so
the §3.2 row was the one out of sync. Updated to match §1 and added
the structural reason: S-2/S-3 closure is what makes S-4 the live
bootstrap; without them, removing src/v2/stage0 breaks the build
chain even with PB-Runtime present.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-V2-Retirement per-surface migration matrix

Follow-up to #1338. Per-file/per-surface mapping for gates G-1
(v2_oracle_no_remaining_test_consumers) and G-2 (v2_directory_deleted),
covering the three populations dispatch named:

- Population A: 13 internal src/v2/tests/src/*.rs files (fall with G-2,
  not G-1; coverage-migration question routed to PM brief).
- Population B: 2 substantive G-1 consumers (p0_std_render_repeat_string,
  m2_substrate_inhabitance::v3_kernel_algebra_profile_mirror_*) — each
  with current dep / role / owner / proposed migration / prerequisite /
  STOP / green criteria.
- Population C: doc-comment / string-literal references; cosmetic at G-2.

Plus:
- §4 legacy emit chain (rust_simple_method_specs / rust_method_templates /
  rust_method_wraps_result) — G-2 prerequisite, not G-1.
- §5 dual verification.dag surface — routed to Substrate Manager per
  dispatch non-goals; no convergence shape proposed here.

Docs-only mapping. No code/test/workspace/bridge changes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): C1 Tier-3 perf-budget readiness matrix

Per Director dispatch via cool-stag-230: smallest useful preparatory
artifact ahead of any C1 (`tier3_mirror_dissolution_perf_within_budget`)
worker dispatch. Verifies the parent brief's (#1331) phase-by-phase
prerequisites against HEAD `5d03c86b0`.

Findings:
- Phase 1 dispatch blocked on R-1 (criterion dev-dep absent) + R-3
  (canonical CI host not designated by PB Manager).
- Phase 2 dispatch blocked additionally on R-4 (Substrate-Mgr decision
  on PerfWithinBaseline TestPredicate variant — not authored at HEAD;
  src/v3/std/verification.dag:109-160 lists no PerfWithinBaseline)
  + R-5 (mirrors still live) + R-6 (Evaluator readiness) + R-7
  (tier3_baseline.json absent).
- Tier-3 mirror line ranges in parent brief have drifted; symbol-keyed
  identification recommended (DescentEvidence at L819, merge_evidence
  at L947, etc., not L628-790 as cited).

§4 routes 4 open questions: symbol-vs-line keying, Phase-1-before-
dissolution sequencing enforcement in T-Tier3-Dissolution dispatch,
path (a) vs (b) for PerfWithinBaseline, canonical CI machine.

Docs-only. No code, no criterion, no benchmark fixtures, no variant
authoring, no fake pass/fail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
Add criterion dev-dep, tier3_mirror_perf bench (four mirror slices), and
tier3_fixtures README placeholder. Update r3-pb-tier3-perf-budget-worker brief
deliverable 0b toward tier3_mirror_dissolution_perf_within_budget (PR #1319
thresholds). Frozen baseline JSON remains a follow-up (0c).

Made-with: Cursor
briansrls added a commit that referenced this pull request May 1, 2026
* docs(briefs): R3 C1 + C2 worker briefs (perf budget + ProviderTypedWire<P>)

Authored per PR #1319 Director ratification ask 4 (PM-side authoring).

C1 — `r3-pb-tier3-perf-budget-worker.md`
- Sub-gate of T-Tier3-Dissolution: tier3_mirror_dissolution_perf_within_budget
- Thresholds: median ≤2x hand-Rust, p99 ≤5x (Director-ratified)
- Cargo bench fixtures per retired mirror (termination/computation/induction/effect-carrier)
- Owner: PB Manager (R2→R3 continuation); S-M scope ~2-3 days

C2 — `r3-substrate-provider-typed-wire-worker.md`
- T-Anthropic-Wire scope expansion: extract `ProviderTypedWire<P>` carrier
- Per-provider parameter rows in `dsl/extdeps/providers/*/`
- Drops prior 6-month elapsed-time check per user directive
  ("nothing can be deferred past R3")
- Owner: Substrate Manager (R2→R3 continuation); M scope ~1-2 weeks
- Resolves R3 design challenge #8 via path-(a) commit

Both briefs are dispatch-gated on R2-Evaluator readiness; STOP+PING
discipline matches `feedback_worker_stall_diagnosis` substrate-gap-stall
pattern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): address codex BLOCKING review (3 BLOCKING + 1 non-blocking)

Codex review on PR #1331 sha 1870104 flagged 3 BLOCKING + 1 non-blocking
findings against the C1 + C2 briefs. All 4 verified valid against current
code; this commit pushes fixes.

C2 — `r3-substrate-provider-typed-wire-worker.md`:

1. (BLOCKING) Operation-indexed carrier, not provider-level envelope.
   `dsl/extdeps/llm/anthropic.dag:168-200` declares
   `service llm.Anthropic { operation Messages { transport rest { … } } }`;
   providers carry MULTIPLE operations each with own request/response/error
   envelopes. Single provider-level envelope loses per-operation typing.
   Fix: split into two carriers — `ProviderOperationWire<P>` keyed on
   (provider, operation) for per-op wire envelopes, `ProviderConfig<P>`
   for provider-level shared facts (auth, base_url, models). Multi-op
   coverage required (Anthropic Messages + OpenAI Chat Completions at
   minimum; Embeddings/Tool Use land as additional rows).

2. (BLOCKING) Migration discipline — no parallel-authority window.
   Prior framing said old per-provider files "either retired or kept as
   v2-parsed legacy until v2 retirement" — exactly the parallel-authority
   anti-pattern (`feedback_parallel_representation_debt`). Fix: explicit
   commit to ONE of two paths in same PR — (a) deletion, preferred; OR
   (b) one-way generated projection from new carriers (un-editable
   header; CI rejects manual edits). "Kept as legacy" is rejected per
   user directive 2026-04-30 ("nothing deferred past R3").

C1 — `r3-pb-tier3-perf-budget-worker.md`:

3. (BLOCKING) std mirror path coverage. Verified `dsl/std/{termination,
   computation,induction,effects}.dag` AND `src/v3/std/{...}` both exist
   for all four blocks. CI wiring updated to reference both — `dsl/std/`
   as canonical authority + `src/v3/std/` as substrate twin + Rust
   mirror sites (`dag.rs`, `dag/effects.rs`, `workflow_idempotency.rs`).

4. (Non-blocking) `criterion` dev-dep claim. Verified `criterion` is NOT
   in any Cargo.toml. Fix: removed false "already in Cargo.toml" claim;
   adding criterion as `[dev-dependencies]` is part of THIS lane's
   deliverables (worker's first commit), not a precondition.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix OpenAI operation example to match live extdeps

Codex inline BLOCKING comment on PR #1331 sha 1870104 flagged that
ProviderTypedWire<P> would drop per-operation wire facts when OpenAI
has ChatCompletion + Responses as distinct REST operations.

The structural fix (operation-indexed ProviderOperationWire<P>) landed
in d881e2a. This commit corrects the EXAMPLE data rows to match
the actual operations declared in dsl/extdeps/llm/openai.dag (verified
live: ChatCompletion at :163, Responses at :200) — prior commit used
"Embeddings" as the second operation, which is not declared.

Both ChatCompletion + Responses are now explicit in the migration
deliverables and acceptance gate; multi-operation coverage table cites
exact line numbers for both Anthropic Messages and OpenAI ChatCompletion
/ Responses.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix self-contradiction in tier3 perf-budget brief

Cursor/composer-2 review on PR #1331 sha d881e2a caught a real
self-contradiction in deliverable #1: it called criterion an "existing
dev-dep" while deliverable #4 (added in d881e2a) explicitly says
criterion is NOT in any Cargo.toml and adding it is part of THIS lane.

Both can't be true. Fix: deliverable #1 now says "added as new dev-dep
per deliverable #4 below; not currently in any Cargo.toml" — single
authority on the criterion state, no contradiction.

Per INVARIANTS Documentation Describes Live State: documentation
should not assert repo state that doesn't exist.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix cross-ref label/link mismatch (sibling brief)

Cursor/composer-2 review on PR #1331 sha 89e4082 caught a copy-paste
slip in C2 brief cross-refs: line labeled "Sibling: T-V2-Retirement"
but pointed at r3-pb-tier3-perf-budget-worker.md (which is the C1 brief
for T-Tier3-Dissolution sub-gate, not T-V2-Retirement).

Fix: label the link correctly as "Sibling brief: r3-pb-tier3-perf-
budget-worker.md (C1 sub-gate of T-Tier3-Dissolution; co-sibling in
same wave per PR #1319 ratification ask 4)". No T-V2-Retirement
reference here since neither brief is for T-V2-Retirement.

Exploratory finding (not BLOCKING) per cursor APPROVE verdict.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): two-phase perf gate pattern (no parallel implementations)

Codex BLOCKING review on PR #1331 sha 19dc267 correctly flagged a
structural contradiction in the C1 perf-budget brief: comparing
median(eval) against median(hand-Rust) requires both paths to exist
simultaneously, but T-Tier3-Dissolution removes the hand-Rust side.
Either the mirror stays alive (parallel-implementation, INVARIANTS
§P2 violation) or the comparison is impossible.

Fix reframes the gate as two-phase:

**Phase 1 (sibling PR; pre-dissolution)**:
- 0a: criterion dev-dep added
- 0b: hand-Rust mirror benchmarks; deletes alongside dissolution
- 0c: frozen tier3_baseline.json with median+p99 captured on
       canonical CI machine

**Phase 2 (this brief; post-dissolution)**:
- 1: eval-path bench fixtures (.dag-evaluator only)
- 2: shared deterministic fixture corpus (Phase 1 + Phase 2 share)
- 3: .dag TestClaim comparing measured timings against frozen
     baseline JSON
- 4: CI wiring on Evaluator path + baseline file (read-only)

Director's ≤2× median / ≤5× p99 thresholds preserved (now relative
to frozen baseline data, not live mirror code).

Strict temporal ordering: Phase 1 → mirror dissolution → Phase 2.
Reverse order is impossible (STOP condition #1). Phase 1 baseline
JSON survives mirror dissolution; mirror code does not.

Discipline: explicit INVARIANTS §P2 callout — only DATA survives
post-dissolution, not parallel authority. tier3_baseline.json is
read-only after capture; CI rejects edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): reframe C2 — preserve service-block facts via T-Ground-Services dependency

Codex BLOCKING review on PR #1331 sha 19dc267 flagged that
ProviderOperationWire<P> as drafted captured only a fraction of what
service { operation { ... } } blocks at dsl/extdeps/llm/{anthropic,
openai}.dag carry. Deleting those extdeps with the carrier as
replacement would lose 8 fact-classes per operation:
  - Output projection paths (e.g., "content/0/text")
  - Input field declarations + types
  - Output field declarations + types
  - Transport body composition
  - Transport headers
  - Response status mapping (200/4xx/5xx)
  - Mock responses (per status, with descriptions)
  - Service-level config (rate_limit, retry, auth)

This violates feedback_projections_must_compose_facts.

Reframe: the structural answer is NOT to extract a subset-carrier
replacing the canonical authority. It's to make the canonical
authority parseable natively via T-Ground-Services (R3 Grounding
lane) and dissolve the v3-side parallel MIRROR.

The lane now delivers 3 structural moves, all gated on
T-Ground-Services landing first:
  1. Relocate dsl/extdeps/llm/{openai,anthropic}.dag to
     dsl/extdeps/providers/{openai,anthropic}/wire.dag (path-only
     move; content unchanged)
  2. Delete src/v3/std/anthropic_schema.dag (v3-side parallel
     mirror); update BOOTSTRAP_FIXTURE_PATH_KEYS to read canonical
     extdeps directly
  3. Optionally author ProviderTypedWire<P> as thin alias wrapping
     Service<P> (T-Ground-Services owned) — only if cross-provider
     lens-instance authoring needs a parametric handle; defaults to
     "no alias unless consumer demand"

Acceptance gates updated: 4 gates (relocation + mirror dissolution
+ optional alias decision + no fact re-encoding) instead of prior
5 gates that assumed carrier extraction.

Hard prerequisite added: T-Ground-Services parser-grammar slice
must land first. Without it, the lane has nothing to do — it can't
delete the canonical extdeps without the parser to read them.

STOP conditions updated: STOP+PING if T-Ground-Services not landed,
or if alias scope creeps into fact reification.

Per ROADMAP `### Post-merge debt (2026-04-30 analyses)` "Provider/
API mirror multiplication risk": "Corrective action: prioritize
shared T-Ground-Services ingestion path over per-provider mirrors.
Owner: R3 Grounding (post-Anthropic-chain)."

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): tighten C1 lane-summary bullets to match two-phase pattern

Cursor/composer-2 APPROVE_WITH_COMMENTS on PR #1331 sha 30413c3
caught a residual inconsistency in the C1 lane-summary at lines
24-26. Item 1 still read "Cargo bench fixtures comparing hand-Rust
mirror invocation vs Evaluator-backed .dag invocation for each of
the four retired mirrors" — implying a simultaneous side-by-side
harness, contradicting the two-phase pattern (Phase 1 hand-Rust
captures frozen JSON; Phase 2 eval-only vs baseline) that lives
in §"Acceptance gate" and Deliverables.

Same class of bug as the criterion self-contradiction caught by
cursor on sha d881e2a — fixed the structural shape but left the
lane-summary bullet describing the prior shape.

Fix: lane-summary now explicitly names Phase 1 + Phase 2 and the
INVARIANTS §P2 framing (no simultaneous dual paths). Adds a 4th
deliverable line for CI integration that explicitly notes the
dissolved Rust mirror sites no longer exist as gate triggers
post-dissolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): surface real substrate gap — BehavioralObservation doesn't carry perf-budget shape

Codex BLOCKING inline on PR #1331 sha 62c20e9 line 51 caught a real
unverified claim. The brief said "no new substrate variant; structural
composition over existing BehavioralObservation-shaped TestPredicates"
but verified BehavioralObservation at src/v3/std/verification.dag:126-130
only carries:
  - subject: DeclarationRef
  - input_sample: DeclarationRef
  - expected_output: DeclarationRef

It's shaped for input/output equality testing, NOT perf-budget-against-
baseline. The prior brief was hand-waving the substrate target.

Honest fix: surface the substrate gap explicitly. Two paths, Director/
Substrate-Mgr decision at brief-finalization:

Path (a) — preferred: new TestPredicate variant. Substrate Mgr authors
PerfWithinBaseline { bench_subject, baseline_data, median_factor_max,
p99_factor_max } in src/v3/std/verification.dag as hard prerequisite
for C1 dispatch. Cleanest structurally; preserves "tests are data"
facet 3 discipline.

Path (b) — fallback: existing ExecuteCommand variant. Bench harness
becomes a subprocess via ExecuteCommand { command, args,
expect_exit_code: 0 }; binary parses baseline + measured + exits
non-zero on breach. No new substrate but loses structural-acceptance
precision.

Updates:
- §"Acceptance gate" — explicit two-path framing with shape sketch
- Per-mirror claim shape — uses PerfWithinBaseline (path a) with
  ExecuteCommand fallback (path b) noted
- Deliverable #3 — predicate variant per Substrate-Mgr decision
- Dependencies — added #1: Substrate-Mgr decision on the variant
  before Phase 2 dispatches (renumbered prior 1-4 to 2-5)
- STOP conditions — added #1: STOP+PING if path (a) variant not
  authored; OR explicit downshift to path (b) with Director sign-off

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): surface substrate gaps for C2 acceptance gates honestly

Codex BLOCKING inline on PR #1331 sha aca422d line 65 caught the
C2 brief hand-waving "compose via existing BehavioralObservation"
without naming subjects/lenses. Same pattern as the C1 substrate
gap caught earlier — and same honest fix.

Verified that none of the 4 C2 gates have existing TestPredicate
variants that structurally observe what they require:
  - Gate 1 (relocation): file-existence at new path + non-existence
    at old path — no existing variant
  - Gate 2 (mirror dissolved): file-non-existence + path-key
    membership change — no existing variant for file check;
    BOOTSTRAP_FIXTURE_PATH_KEYS membership covered by Compiles
    on a fixture
  - Gate 3 (alias optional): TestPredicate::Compiles on import
    fixture covers if alias declared; meta-fact recording if not
  - Gate 4 (no fact re-encoding): structural-absence across
    substrate — no existing variant

Honest fix: per-gate, name the substrate-Mgr-decision shape:

Path (a) — preferred: new TestPredicate variants
  - BootstrapFixturePathPresent { path, must_exist } for gates 1+2
  - NoDeclarationMatching { kind, in_directory, except } for gate 4

Path (b) — fallback: ExecuteCommand subprocesses
  - test -f for gates 1+2
  - tier3_no_re_encoding_check for gate 4

Path (c) for gate 4 only: PR-review checklist (reviewer-enforced)
with Director sign-off on the structural-precision tradeoff

STOP conditions extended:
  - #2: STOP if Substrate Mgr declines all 3 paths for any gate

Per `feedback_no_textual_enforcement_bridges`: file-presence is a
typed substrate fact, not a grep operation — preferring path (a)
with new typed variants.

Same shape as C1's PerfWithinBaseline gap surfaced honestly in
86f0292.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): align C2 brief title + framing + ratchet name with reframe

Cursor APPROVE_WITH_COMMENTS on PR #1331 sha 9e79b5b caught 3
real leftover inconsistencies from the reframe iterations:

1. Title still said "Carrier Extraction Worker Brief" while the
   body explicitly abandoned carrier extraction as the structural
   move. Renamed to "Mirror Dissolution + T-Ground-Services
   Consumption Worker Brief" — matches the reframed lane shape.

2. Line 162 said "Carrier extraction IS the dissolution" — direct
   contradiction with §"Lane reframe" (lines 38-57) and §"Scope"
   (lines 18-29). Rewrote to align: "The dissolution mechanism is
   option (a) from feedback_isomorphism_or_generation_for_mirrors —
   generation/parsing from the canonical authority — implemented
   here via T-Ground-Services parsing the canonical extdeps."

3. Line 170 named ratchet `provider_wire_no_per_provider_duplication`
   but the actual gate at line 92 is `provider_wire_no_fact_re_encoding`.
   Same-doc naming drift. Fixed all 6 questions of the substrate-
   principle audit to reference the correct gate name + extended the
   audit answers to reflect the reframed lane (T-Ground-Services
   parsing as recovery pattern; canonical extdeps preserved).

All 3 findings were direct artifacts of the prior reframe (aca422d)
not propagating through every cite — same self-consistency-sweep
pattern that PR #1341 just landed for r3-structure.md.

Per `feedback_verify_thesis_claims`: when reframing, sweep ALL
references; partial sweeps create exactly this kind of contradictory
documentation that confuses dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Numeric-Construction lane reframe (was T-Int128)

Per Director ratification at gunbc#828 comment 4357704426 (2026-05-01).
User pushback: "model real numbers/natural numbers and then form int64
based on those models - not jump straight to int64."

Reframes R3 Lane #6 (T-Int128 → T-Numeric-Construction; same lane slot,
expanded scope). Director's prior `OrderedRing<Magnitude>` shorthand
ratification (4357686725) explicitly SUPERSEDED in favor of the explicit
construction chain ℕ → ℤ → ℚ → ℝ that the user requested.

Construction chain (ratified verbatim):
  Magnitude (terminal carrier) → Nat = Semiring<Magnitude> →
  Int = AbelianGroup<Nat> via Grothendieck →
  Rational = Field<Int> → Real = ApproximateField<Rational>

Refinement chain at any layer: Int<N>, Nat<N>, Real<N>.
Width-specific aliases (Int8..Int128, UInt8..UInt128, Float32/64) are
refinements, not parallel substrate.

Lane absorbs:
  - T-Int128 (was its own R3 lane)
  - post-R3 BigInt deferral (BigInt = Int unbounded; same substrate
    landing as Int<128>)
  - Float widening (was unscoped)
  - UInt widening (parallel bake-in to Int)
  - IntLit refinement

8 types in scope: 3 direct (Int, UInt, Float) + 5 inherited via Int
chain (Char, EpochMs, Duration, Milliseconds, Seconds — auto-fix when
Int becomes abstract).

Files in this PR:

NEW:
  - docs/design-numeric-construction.md — design doc; covers
    construction chain, 5 substrate-introductions needing 6Q audit
    (Magnitude, AbelianGroup verify, Grothendieck encoding choice,
    Field verify, ApproximateField), refinement chain, per-target
    grounding mapping (Rust/Python/Go), v2-refinement-syntax-blocker
    coordination (path-a same wave with T-V2-Retirement),
    cost-lens implications per layer

AMENDMENTS:
  - docs/r3-structure.md — Lane #6 reframe across §Summary,
    §Acceptance, §Lane structure, §Manager structure, §Dependency DAG
    visual, §Dependency on R2, §Worker dispatch precondition. Lane
    size L-XL. T-Numeric-Construction is one of 3 non-Evaluator-gated
    lanes but has its own internal cascade gate on T-V2-Retirement.

  - docs/r2-structure.md — cross-program-producer §"3 non-Evaluator-
    gated R3 lanes" updated to reflect post-12-lane structure +
    T-Numeric-Construction reference

  - docs/thesis/r2-r3-thesis-mapping.md — Integer overflow thesis
    claim updated to refinement-parametric form; Tier 2 Int128/Word128
    row noted as subsumed by T-Numeric-Construction

  - docs/briefs/r2-release-manager.md — manager continuation pattern
    updated; R2 close gate framing reflects 12-lane structure

  - ROADMAP.md — new "Post-merge debt (2026-05-01 R3 substrate-
    completion adjacents)" section for Json/Bytes opaque kernel types
    (out of scope for T-Numeric-Construction; assess post-lane-close
    per Director disposition)

DELETED:
  - docs/briefs/t-int128-r3-initial-slice.md — superseded by lane
    reframe; eager-ram's prior PR #1333 work (Word128Carrier + signed
    i128 pilot row) preserved as load-bearing under reframe (Word128
    becomes storage refinement under Int<128>)

Substrate Mgr authoring follows: 6Q audits on the 5 substrate-
introductions, then docs/briefs/t-numeric-construction-worker.md
brief.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
…es (#1430)

Director relayed two analyses against current main:
- Exploratory (gpt-5-5-pro main@8cd5359): 9 findings against
  dsl/std/*.dag, src/v2/tests/src/*.rs, dsl/extdeps/, THESIS,
  INVARIANTS, MODELING, ROADMAP — 2 novel correctness bugs
  (SymbolicCost semiring violation, emitter expect() panic paths),
  3 sharpened tracked items (SubValueRelation lattice-law
  contradiction, ?? / % syntax-parser drift, CollectionOps/StringOps/
  MapOps duplicates), 4 already-tracked items
- Reflective (gpt-5-5-pro main@6ea9812 → now): 5 cross-PR patterns
  + 6 highest-priority course corrections + verdict "advancing,
  scaffold-velocity dominates"

PM ingestion folds into single ROADMAP debt section per Director's
prior 2026-04-30 analyses ingestion pattern (PR #1319). Sections:

- A: Exploratory novel correctness bugs (SymbolicCost product-zero
     bug, SubValueRelation BoundedLattice claim violation, emitter
     expect panic paths)
- B: Exploratory sharpened tracked items (?? / % drift,
     CollectionOps/StringOps/MapOps duplicates)
- C: Exploratory already-tracked confirmations (no new ROADMAP rows)
- D: Reflective 5 cross-PR patterns (author-now/fire-later, test_
     runner.rs second predicate language, typed-carrier-Rust-mirror
     accumulation, numeric philosophy mid-window shift validating
     T-Numeric-Construction reframe, bridge retirement tracked-not-
     retired)
- E: Reflective 6 highest-priority course corrections with owner
     attribution + lane connection table
- F: CI cost signal (e765c86 60min timeout) + velocity-tripwire
     calibration (64 docs / 16 feat / 9 fix ratio)
- G: PM strategic synthesis: 3 cross-cutting meta-themes
     (algebraic-law-witness coverage gap; "make scaffolds executable"
     cluster; "tighten existing structural enforcement" cluster)

Per-finding/correction owner attribution names R3 Substrate Mgr,
R3 Verification Mgr, R3 Grounding Mgr, R3 PB Mgr per ownership
boundaries. Lane connections cite T-V-L4-L7-Direct, T-Free-
Consequences-Demonstration, T-Ground-Services parser-grammar slice,
T-Numeric-Construction Slice 2 sequencing, etc.

Highest-value novel: SymbolicCost product-zero bug (cost-lens reads
incorrect facts; iterate(ConstantCost(0), ...) returns body cost
instead of zero) + emitter expect() panics. Highest-value
sharpened-tracked: SubValueRelation BoundedLattice false-claim.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 1, 2026
* WIP: quick-newt-150

* docs(r3): link sub-gate 3 brief to regen_lens BinShim readiness checklist

Made-with: Cursor

* feat(v3-compiler): Tier-3 mirror Phase-1 criterion bench skeleton (C1)

Add criterion dev-dep, tier3_mirror_perf bench (four mirror slices), and
tier3_fixtures README placeholder. Update r3-pb-tier3-perf-budget-worker brief
deliverable 0b toward tier3_mirror_dissolution_perf_within_budget (PR #1319
thresholds). Frozen baseline JSON remains a follow-up (0c).

Made-with: Cursor

* WIP: silent-boar-29
briansrls added a commit that referenced this pull request May 2, 2026
… program (#1480)

* docs(roadmap): fold 2026-05-01 paired exploratory + reflective analyses

Director relayed two analyses against current main:
- Exploratory (gpt-5-5-pro main@8cd5359): 9 findings against
  dsl/std/*.dag, src/v2/tests/src/*.rs, dsl/extdeps/, THESIS,
  INVARIANTS, MODELING, ROADMAP — 2 novel correctness bugs
  (SymbolicCost semiring violation, emitter expect() panic paths),
  3 sharpened tracked items (SubValueRelation lattice-law
  contradiction, ?? / % syntax-parser drift, CollectionOps/StringOps/
  MapOps duplicates), 4 already-tracked items
- Reflective (gpt-5-5-pro main@6ea9812 → now): 5 cross-PR patterns
  + 6 highest-priority course corrections + verdict "advancing,
  scaffold-velocity dominates"

PM ingestion folds into single ROADMAP debt section per Director's
prior 2026-04-30 analyses ingestion pattern (PR #1319). Sections:

- A: Exploratory novel correctness bugs (SymbolicCost product-zero
     bug, SubValueRelation BoundedLattice claim violation, emitter
     expect panic paths)
- B: Exploratory sharpened tracked items (?? / % drift,
     CollectionOps/StringOps/MapOps duplicates)
- C: Exploratory already-tracked confirmations (no new ROADMAP rows)
- D: Reflective 5 cross-PR patterns (author-now/fire-later, test_
     runner.rs second predicate language, typed-carrier-Rust-mirror
     accumulation, numeric philosophy mid-window shift validating
     T-Numeric-Construction reframe, bridge retirement tracked-not-
     retired)
- E: Reflective 6 highest-priority course corrections with owner
     attribution + lane connection table
- F: CI cost signal (e765c86 60min timeout) + velocity-tripwire
     calibration (64 docs / 16 feat / 9 fix ratio)
- G: PM strategic synthesis: 3 cross-cutting meta-themes
     (algebraic-law-witness coverage gap; "make scaffolds executable"
     cluster; "tighten existing structural enforcement" cluster)

Per-finding/correction owner attribution names R3 Substrate Mgr,
R3 Verification Mgr, R3 Grounding Mgr, R3 PB Mgr per ownership
boundaries. Lane connections cite T-V-L4-L7-Direct, T-Free-
Consequences-Demonstration, T-Ground-Services parser-grammar slice,
T-Numeric-Construction Slice 2 sequencing, etc.

Highest-value novel: SymbolicCost product-zero bug (cost-lens reads
incorrect facts; iterate(ConstantCost(0), ...) returns body cost
instead of zero) + emitter expect() panics. Highest-value
sharpened-tracked: SubValueRelation BoundedLattice false-claim.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): R3 scope expansion 12 → 16 lanes + standing R3 Debt-Paydown program

Per Director ratification 2026-05-02 at gunbc#828 comment 4362742638:

User directive: per the strict reading of "nothing deferred past R3", all
"accidentally deferred" gaps absorb into R3. Plus three additional asks:
behavioral expectations docs per feature; compile-error complexity ratchet
generalized as lens-application-surface (per user reframe); in-cycle
debt-paydown discipline.

NEW R3 LANES (4 added; lane count 12 → 16):
  13. T-E-P-Producer-Broadening (Substrate; M-L; foundational)
      - broaden per-call DescentEvidence/CallPattern/SubValueRelation
        from first slice to full ExprCall.descent_evidence parity
      - prerequisite for T-Lens-Behavioral-Parity

  14. T-Lens-Behavioral-Parity (Substrate + Verification cross-program; L-XL)
      - 4 sub-slices: complexity / cost / parallelism / effect_enumeration
      - bring lens-capability-register from PROXY/STUB/PARTIAL → COMPLETE
      - includes symbolic CostExpr full algebra; work/span split;
        asymptotic classification; cementing test against v2 oracle;
        Stage 2e parallelism walk port; resource-threading migration

  15. T-Tests-As-Data-Completeness (Verification; L)
      - tests-as-data full coverage (thesis facet 3)
      - property-based testing surface (ForAll/Exists quantifiers +
        ProgramGenerator carrier)
      - cementing test discipline for .dag lenses

  16. T-Lens-Application-Surface (Substrate + Verification; L-XL)
      - per user reframe: lens application as first-class authoring surface
      - apply_lens(lens, section, config) where config.violation_policy =
        CompileError | Warning | Silent
      - subsumes prior T-Complexity-Contract-Compile-Error +
        T-User-Authored-Cost-Basis-Discipline as configurations
      - 4 worked examples: complexity-contract-compile-error + CRDT cost
        basis + memory-peak cost basis + opt-in cross-iteration parallelism
      - default policy for complexity contract: opt-out

NEW STANDING PROGRAM:
  R3 Debt-Paydown Manager (9th standing R3 Mgr)
  - hybrid mechanism: per-PR debt-receipt rule + standing capacity
  - closure gate: r3_debt_paydown_zero_remaining
  - per feedback_standing_managers_need_owned_deliverables

FOLD-INS (3; no new lanes):
  - T-V-L4-L7-Direct: per-(algebra, inhabitant, law) exhaustive witness
    coverage (catches SymbolicCost product-zero bug class structurally)
  - T-Ground-Diagnostic: closed-axis enforcement (no String dispatch on
    closed sets); replaces MissingEmissionPath { connective: String, ... }
  - T-LensProducer-Retirement: ownership d/e/f confirmed delivered (not
    separately deferred)

T-Behavioral-Expectations-Documentation (parallel-dispatchable; 7 load-
bearing features per Director ratification): lens framework + 4 lens
instances + complexity contract + cross-target consistency.

Updates to docs/r3-structure.md:
  - §Summary: 12 lanes + 1 standing program → 16 lanes + 1 standing
    program
  - §Lane structure: 4 new rows
  - §Manager structure: 8 → 9 standing managers; 3 → 4 modifications
  - NEW §Standing program — R3 Debt-Paydown section authored
  - T-Numeric-Construction lane row updated to 13 types in scope (was 8;
    per 2026-05-02 PM audit + Substrate Mgr ack)

R3 scope ratchet: ~58% (over current 12-lane denominator) → ~38% (over
expanded 17-lane denominator); numerator unchanged. Honest timeline
projection: R3 close in 5-8 weeks at current velocity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Numeric-Construction row — 8-type → 13-type scope citation + traceability

Director callout on PR #1480: §Summary item 6 says 13 types in scope but
§Lane structure table row 138 still said 8. Internal inconsistency.

Fix: §Lane structure table row 138 updated to 13 types in scope, with
explicit citation chain:
  - original 8-type count from PR #1430 §A audit
  - extended to 13 after fresh PM sweep found 5 additional Int-inherited
    refinement types (RetryCount / HttpStatus / Port / PositiveInt /
    NonNegativeInt) at dsl/std/types.dag:232-245
  - Substrate Mgr ack at gunbc#1130 comment 4360482400

Includes: Nat-alignment opportunity flagged (NonNegativeInt → Nat,
PositiveInt → Nat where range(min: 1)), cost-lens candidates for
bounded-range types (RetryCount → Nat<3>, HttpStatus → Nat<10>,
Port → Nat<16>) once refinement composition lands.

Per Director recommendation: brief addendum documenting the audit so
lane scope stays anchored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address PR #1480 cursor findings — §P5 mix-up + restored locked dispositions

Fixes 3 cursor findings on PR #1480 (sha 0f32605) plus 1 exploratory:

1. §P5(b)/(c) mix-up (line 44): "vague deferrals rejected" attributes to
   §P5(b) per-PR gate (the rule that actually rejects vague deferrals), not
   §P5(c) Velocity tripwire (windowed dispatch-pause). Now also explicitly
   surfaces §P5(c) as separate (b) windowed-enforcement clause.
2. Restored Post-R2 emergent work disposition on Substrate/PB continuation
   bullet (line 187): Director-locked 2026-04-28 — emergent post-R2 work
   absorbs into Substrate Manager continuation, not new managers.
3. Restored Verification scope negations on Verification Manager bullet
   (line 189): "L6 NOT in Verification scope" + "T-CostLens-Composition NOT
   in Verification scope" — both Director-locked 2026-04-28.
4. Updated stale "9 of 12" / "3 non-gated" counts in §"Dependency on R2"
   (lines 393, 397, 399, 400, 402) to "11 of 16" / "5 non-gated" matching
   line 59 Summary; added T-Lens-Behavioral-Parity + T-Lens-Application-Surface
   to Evaluator-gated list with cascade gate note.

All Director-locked 2026-04-28 dispositions tagged "carried forward through
2026-05-02 expansion" so the locks survive the lane-count change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): close P5 escape hatch in r3_debt_paydown_zero_remaining gate

Cursor BLOCKING finding on PR #1480 at docs/r3-structure.md:173: gate
contradicted itself by allowing "deferred-to-post-R3 with Director sign-off"
after stating "no tracked-debt rows survive R3 close", weakening P5/strict-
forward-progress into a disposition convention.

Fix: remove the deferral escape hatch entirely. Gate is unconditional —
every tracked-debt row retires with PR receipt before R3 close. Grounds
in user directive 2026-05-02: "all 'accidentally deferred to post R3' into
R3 now". If a row appears unretirable, it surfaces as a substrate gap
requiring a named R3 lane (the directive that motivated this manager's
creation), not a Director-sign-off deferral.

Cites INVARIANTS §P5 directly: tracked-debt deferred past R3 close is the
bridge-as-steady-state pattern P5 explicitly forbids; the escape hatch
reintroduced that pattern at lower cadence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): reconcile T-Tests-As-Data-Completeness Evaluator-gating contradiction

gpt-5-5-pro REQUEST_CHANGES finding on PR #1480 (sha 0f32605): line 59
summary said T-Tests-As-Data-Completeness is in the "5 self-contained
non-Evaluator-gated" group, but lane table at line 147 lists its dependency
as "R2-Evaluator (test execution runtime)". Schedulers got two incompatible
authorities (P2 single-authority violation).

Lane table is correct — porting Rust tests to .dag TestClaim requires the
Evaluator to execute the resulting test artifacts. Updated:

- Line 59 summary: 11 → 12 Evaluator-gated; 5 → 4 non-gated; T-Tests-As-
  Data-Completeness moved into Evaluator-gated list with reason
- Line 393 (Dependency on R2): same reclassification
- Line 395 (substrate-carrier-fed list): drop T-Tests-As-Data-Completeness
- Line 399 (precondition applies-to list): 11 → 12 lanes
- Line 400 (carve-out): 5 → 4 lanes; drop T-Tests-As-Data-Completeness
- Line 402 (split-resolution sentence): 11 → 12, 5 → 4

(Findings #2 and #3 already addressed at 0c449a8 and 0de2bda
respectively.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Lens-Application-Surface design doc — substrate shape + 4 worked examples

Per user directive 2026-05-02 ("all designs upfront, implementation sketches
if needed, minimize escalations"), authoring foundational design doc that
unblocks T-Lens-Application-Surface lane dispatch.

Resolves design questions:

1. **Section reference shape**: `SectionRef = DeclarationScope { DeclarationId }
   | NodeScope { DeclarationId, NodeId }`. Three of four user-named scopes
   (function / module / declaration) use DeclarationId uniformly; expression
   scope is the exception (NodeId required because expressions live inside
   Declaration body sub-DAGs).

2. **Violation-policy semantics**: user-named `CompileError | Warning | Silent`
   resolved to fail-closed-compatible binary `Enforce | Introspect` per
   INVARIANTS C-8. Warning forbidden (allows violations as steady state,
   bridge pattern P5 forbids); Silent forbidden ("silent None" exactly the
   pattern feedback_fail_closed_discipline bans).

3. **Default complexity-contract policy**: opt-out (compiler enforces;
   explicit waiver required). Waiver shape is structural `ComplexityBudgetWaiver`
   declaration with `justification` field, NOT an annotation per
   feedback_no_annotations.

4. **4 worked examples** ratified by Director (complexity-contract /
   CRDT cost / memory-peak cost / opt-in parallelism) — each grounded in
   substrate carriers + lens-fold integration.

5. **5 open design questions** flagged for Director ratification before
   substrate authoring begins (module-level semantics, multiple-applications-
   per-section, budget-inference for default, waiver dissolution, cross-section
   composition).

Updates r3-structure.md lane 16 row to reference the design doc, replace the
@complexity_budget_waived annotation language with structural carrier name,
and replace the original `CompileError | Warning | Silent` enum with the
fail-closed-resolved Enforce/Introspect binary.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve all 5 §8 open design questions in-doc per minimize-escalations directive

Per user directive 2026-05-02 ("minimize escalations"), resolved the 5 open
design questions that were flagged for Director ratification:

§8.1 — Module-level semantics: aggregate-across-module (preserves
      structural distinction between module-scope and per-function-scope).
§8.2 — Multiple applications: fail-closed reject duplicate (lens, section)
      Enforce-mode pairs; multiple Introspect admitted (idempotent).
§8.3 — Default-application budget: regression-detection class, gated on
      T-Lens-Behavioral-Parity COMPLETE; pre-cascade Introspect-only.
§8.4 — Waiver lifecycle: future lens_stale_waivers lens with named
      dissolution trigger; tracked in lens-library-design.md §6.
§8.5 — Cross-section composition: read declared budget, not computed
      class (preserves abstraction barrier; cost-of-change=1).

Each resolution carries explicit reasoning grounded in INVARIANTS P2/P5
+ feedback memory. Implementation can proceed once cascade gates clear
(T-Lens-Behavioral-Parity COMPLETE for §8.3 flip; R2-Evaluator landed for
worker dispatch precondition). No further Director ratification needed
on these specific points.

r3-structure.md row 16 updated to reflect the design-doc resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): cross-design coherence pass + master design index

Coherence audit across the 5 design docs identified 5 cross-doc conflicts;
this commit resolves all 5 and lands the master index linking them.

Fixes:

1. **Producer-query single-authority** (P2): complexity-lens §2 + cost-lens
   §3.2 now both reference `per_call_pattern_at(d, call_site) -> CallPattern?`
   as the typed query surface (single authority); the underlying
   `per_call_descent_evidence` side-table is named as the storage backend
   only. Eliminates parallel-authority risk.

2. **Cementing-test shape unified** (DB-15): cost-lens §5 reshaped from
   custom `ForAll { p: SourceProgram in programs }` (which violated tests-
   as-data §2.5 — quantifiers belong on claims, not predicates) to
   `QuantifiedTestClaim { generator, quantifier: ForAll, predicate:
   DifferentialEquals }`. Now matches complexity-lens §4 and tests-as-data
   §2.2 shape.

3. **DB-18 element-type-refinement cross-reference**: effect-enumeration §4.1
   now explicitly states that DB-18's STOP-AND-ESCALATE locks the
   `WorkflowEffect` variant set + variant payload shape, not element-type
   within `LinearEffect.ops: List<X>`. The `OperationEffect` →
   `Operation` retypes is additive tightening within DB-18's permitted
   refinement scope.

4. **Resource-threaded signature compatibility**: cost-lens §3.3 now
   explicitly notes that `per_call_pattern_at` reads from threaded arrow
   signatures (per effect-enumeration §2.4) — signature-shape-agnostic
   producer; broadening covers both pre-migration and post-migration
   signature shapes.

5. **TestClaim shape for lens-application demonstrations**: lens-application
   §4 now declares all 4 worked-example closure gates use `TestClaim`
   (DB-15 enumerated form), not `QuantifiedTestClaim`. Property tests over
   the lens-application substrate live in T-Tests-As-Data scope, not
   T-Lens-Application-Surface scope.

6. **Register-migration sequencing**: tests-as-data §8.3 now lists the 4
   sibling lens design docs whose register-row "→ COMPLETE" closure steps
   depend on the markdown→.dag migration landing first (substrate work in
   sibling lanes does NOT depend; only the closure-gate row update does).

Plus: NEW `docs/design-r3-lens-substrate-index.md` — master index linking
all 5 design docs, documenting cross-doc edges (substrate authority
single-points + cementing-test format + cross-cutting invariants), and
naming lane dispatch order.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address 4 cursor findings on PR #1480 (sha 16340c5)

1. **Lane 16 row 40 stale text vs row 148 resolved** (P2 single-authority):
   row 40 still carried the original `CompileError | Warning | Silent`
   enum + `@complexity_budget_waived` annotation language; row 148 had
   the resolved `ViolationPolicy = Enforce | Introspect` + structural
   `ComplexityBudgetWaiver` carrier. Updated row 40 to match the
   resolved story (single authority).

2. **Line 44 duplicate (b) and (c) labels**: the Hybrid mechanism outer
   enumeration used (a)/(b)/(c) but referenced INVARIANTS §P5 sub-
   mechanisms (a)/(b)/(c) inside; same letter labels at different
   levels confused parsing. Renamed outer enumeration to (1)/(2)/(3)
   with footnote explaining the distinction.

3. **Line 175 contradicts line 173** (P5): line 175 said "Does enforce:
   tracked-debt rows get retirement PRs or explicit deferral" — the
   "or explicit deferral" reads like deferral remains an outcome,
   contradicting line 173's unconditional "no post-R3 deferral path".
   Removed the deferral language; line 175 now restates the unconditional
   rule + names the substrate-gap escalation path.

4. **design-complexity-lens-behavioral-completeness.md:125-127 variant-
   count mismatch** (P1 self-faithfulness): comment said "closed
   seven-variant set" / "Adding an eighth variant" but `AsymptoticClass`
   enumerates 8 variants (ClassConstant/Log/Linear/Linearithmic/
   Quadratic/Polynomial/Exponential/Unknown). Updated comment to
   "eight-variant" / "ninth".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): retract cost-lens parallel SizeExpr proposal — align with complexity-lens single authority

Cursor BLOCKING finding on PR #1480: cost-lens proposed a new SizeExpr
5-variant coproduct as authority, while complexity-lens proposed
SizeVariable.display_name enrichment for the same SymbolicCost payloads.
P2/P5 violation — same substrate fact, two incompatible target shapes.

Resolution: complexity-lens has the structurally correct framing.
- DB-7's SymbolicCost is the unified algebra (locked).
- SymbolicCost already covers SizeAdd (via SumCost) and SizeMax (via
  dominance ordering) — no parallel SizeExpr algebra needed.
- Descent semantics like "n - 1" live in std.computation::CallPattern
  (the canonical E-C site), not in size expressions. A SizeShrink
  variant would duplicate that fact in parallel.
- Asymptotically O(n - 1) ≡ O(n); descent is a call-site property,
  not a size-shape property.

Aligned cost-lens to complexity-lens: SizeVariable gains an optional
display_name: String? field; no parallel SizeExpr carrier; SymbolicCost
DB-7 lock preserved unchanged.

Updated:
- §1.1 problem framing — drop "size arithmetic" / "aggregate sizes"
  framing (already covered by SymbolicCost); keep only the
  "named-binding semantics" gap that motivates display_name.
- §1.2 target shape — SizeVariable.display_name: String? (matches
  complexity-lens §1.2 verbatim).
- §1.3 explicit rationale for unified-algebra over parallel-SizeExpr.
- §1.4 migration shape — additive field, no carrier rename, no deletion.
- §3 / §5 code examples — replaced SizePort with SizeVariable shape.
- §8.1 resolved-question reframe — names the rejected alternative
  (parallel SizeExpr) for future readers.
- §8.2 names-on-carrier resolution — display_name shape per §1.2.
- §10 implementation step 1 closure gate renamed
  size_expr_substrate_landed → sizevariable_displayname_landed.

P2 single-authority restored across the 5-doc design surface.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration — read/write distinction via algebra inhabitance, not signature shape

Cursor BLOCKING finding on PR #1480 at design-effect-enumeration-resource-
threading.md:151: the design's "structural recognition" claim was actually
convention-level. \`R in / R out\` and \`R in / R' out\` (same type, different
value) have the SAME typed signature — \`.dag\` doesn't encode value-
preservation as a substrate fact. ReadShaped vs WriteShaped via signature
shape alone was P1 modeling-faithfulness violation.

Resolution: split the unified rule into two structural carriers per §2.4:

(a) Effect SET — derived from signature: resource types in input ∩ output.
    Structural; the signature carries it.

(b) Effect KIND — declared via algebra inhabitance on the callable:
    \`inhabits IdempotentRead<R>\` (read), \`inhabits Mutating<R>\` (write),
    \`inhabits Append<R>\` (append). Structural; the inhabitance carrier
    captures it.

The lens consults BOTH — signature for set, inhabitance for kind. Absence
of any kind inhabitance with the resource in the effect set is a fail-
closed Diagnostic (EffectKindUndeclared), not a silent default.

Updates:
- §2.1 line 151: replace "same-value vs modified" framing with explicit
  effect-set-vs-effect-kind distinction; cross-link to §2.4 + §8.1.
- §2.3: same fix for Network read example.
- §2.4: split the unified rule into (a) effect SET (signature) + (b)
  effect KIND (algebra inhabitance) with pseudocode for the lens-side
  classification.
- §4.3: update EffectShape derivation source from "signature shape" to
  "algebra inhabitance lookup".
- §8.1: full reframe — from "same-value resolved" to "algebra inhabitance
  is the structural authority", with explicit rationale (per-callable
  authority, not per-call; rejected phantom-marker alternative per
  feedback_no_annotations).
- §3 lens fold pseudocode: dispatch on §2.4(a) for set + §2.4(b) for kind.

Preserves the existing EffectShape = IsIdempotent | IsBreaking partition
(per design-composed-effect-reshape.md PR #529 R3) — only the source of
the shape changes (declared inhabitance, not derived from signature).

P1 modeling-faithfulness restored. Cursor finding fully resolved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): lens-application — collapse ApplicationConfig into sum-type, illegal states unrepresentable

Cursor BLOCKING finding on PR #1480 at design-lens-application-surface.md:43:
ApplicationConfig was a record with budget: LensBudget? + violation_policy:
ViolationPolicy as separate fields. This admitted illegal state combinations:
- Enforce + budget=None (illegal: enforcement requires a budget)
- Introspect + budget=Some(_) (illegal: introspection takes no budget)

The doc explicitly noted these as type-checker-enforced invariants (lines
136-137), but per feedback_state_space_vs_behavioral_invariants those are
behavioral invariants, not state-space invariants — exactly the bug pattern
modeling-discipline principles 2/6 prohibit. Illegal states must be
unrepresentable at the type level.

Resolution: collapse ApplicationConfig and ViolationPolicy into a single
sum-type that pairs budget with Enforce by construction:

```dag
type ApplicationConfig
  = Enforce { budget: LensBudget, diagnostic_severity: DiagnosticSeverity }
  | Introspect
```

By construction:
- Enforce ALWAYS has a budget (it's a coordinate of the variant).
- Introspect NEVER has a budget (it has no payload).

The "Enforce without budget" and "Introspect with budget" combinations
cannot be constructed; the type-checker has no rejection rule to enforce
them — they don't exist in the state space.

Updates:
- §2: replaced ApplicationConfig record + ViolationPolicy sum with single
  ApplicationConfig sum carrying budget inside Enforce variant.
- §3: rewrote framing to match — the binary Enforce/Introspect is the
  ApplicationConfig sum itself; budget pairing is structural.
- §4: all 4 worked-example syntaxes updated to `Enforce { budget,
  diagnostic_severity }` directly (no separate violation_policy field).
- §5.1: synthesized default-application uses `Enforce { budget: <inferred>,
  diagnostic_severity: Error }` shape.
- §3.2: explicit-introspection override syntax `apply_lens(complexity, fn,
  Introspect)` (no separate budget=None).
- r3-structure.md rows 40 + 148: updated substrate-carrier description to
  name ApplicationConfig as sum-type with the structural-invariance note.

Modeling principles 2/6 honored. P1 modeling-faithfulness restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): codex non-blocking findings #2 + #3 — heading/count consistency

Codex review on PR #1480 sha 58f49e9 noted two non-blocking inconsistencies:

NB2: design-cost-lens-sizevar-dimension-wiring.md §4.2 heading said
'CommutativeSemiring<SymbolicCost>' but §8.5 resolves to 'Semiring<SymbolicCost>'
(multiplicative side does NOT enforce commutativity per §8.5 reasoning).
Fixed §4.2 heading to match §8.5 resolution.

NB3: design-tests-as-data-completeness.md §3.1 said 'six classes' /
'decomposes into six structural classes' but §10 step 3 enumerates C1-C7
(seven classes). Fixed §3.1 to say 'seven classes' with explicit C1-C7
cross-reference.

Both load-bearing for doc-as-authority discipline (P1 modeling-faithfulness
of the spec to itself).

(All 4 BLOCKING findings from same review at sha 58f49e9 are already
addressed at earlier commits — see PR comment for the receipts:
ef21e1a / 92d9b11 / 255cca3 / 8640e67.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix line 199 active-surface arithmetic + line 23 exploratory clarity

Cursor APPROVE_WITH_COMMENTS finding on PR #1480 sha 92d9b11:

**Main finding (line 199)**: arithmetic was internally inconsistent —
"expanded from 13 active surfaces" + "4 new lanes + 1 new standing program"
= 18, not 17. The baseline should have been 12 (12 lanes + 0 standing
programs at the 2026-04-30 lock), making 12 + 5 = 17 consistent. Fixed by
restating the baseline as 12 with explicit arithmetic: 4 new lanes
(enumerated by name) + 1 new standing program = +5; 12 + 5 = 17.

Also pinned T-Behavioral-Expectations-Documentation explicitly as
"parallel-dispatchable across existing lanes, not a separate surface" so
readers don't double-count it as a 5th new lane.

**Exploratory finding (line 23)**: the "added..." list mixed 4 new lanes
+ T-Behavioral-Expectations-Documentation (not a separate lane) + standing
program in one breath. Restructured the parenthetical to enumerate the 4
new lanes by name and call out T-Behavioral-Expectations-Documentation as
parallel-dispatchable explicitly. Reader can no longer mis-count.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop SizeVariable.display_name; InternTable single-authority for size names

gpt-5-5-pro REQUEST_CHANGES on PR #1480 sha ef21e1a — BLOCKING #3 + #4:

BLOCKING #3: SizeVariable.display_name + intern_table::name_of(source_port)
created TWO authorities for the user-facing size-variable name. The §8.2
implementation note confirmed the parallel: "when display_name = Some(name),
renderer uses it directly; when None, falls back to InternTable lookup".
P2 single-authority violation; consumers could diverge on the same source_port.

BLOCKING #4: master index design-r3-lens-substrate-index.md still claimed
SizeExpr replaces SizeVariable, but cost-lens design (post-ef21e1a00) had
already retracted SizeExpr in favor of unified SymbolicCost. Cross-doc
authority drift.

Resolution (both BLOCKINGs):
- Drop display_name field entirely from cost-lens + complexity-lens designs.
- SizeVariable substrate stays UNCHANGED at { source_port: PortId }.
- InternTable is the single canonical name authority — already populated
  at parse time keyed by port_id. Renderer reads via
  intern_table::name_of(source_port).
- The "Named SizeVar" gap from the capability register is closed by
  renderer-side wiring (no substrate change), not by adding a field.
- Master index updated: SizeVariable line replaces the old SizeExpr line;
  notes InternTable as name authority.

Updates:
- design-cost-lens §1.2: target shape removes display_name field from
  SizeVariable carrier; rationale rewritten as InternTable-as-single-authority.
- design-cost-lens §1.4 / §3 / §5 / §8.1 / §8.2: all display_name references
  scrubbed; "renderer-side InternTable name wiring" replaces "SizeVariable.
  display_name enrichment" throughout.
- design-cost-lens §10 step 1: closure gate renamed
  sizevariable_displayname_landed -> renderer_intern_table_name_wiring_landed.
- design-complexity-lens §1.2: same rewrite — SizeVariable carrier UNCHANGED;
  InternTable as name authority; explicit cross-link to cost-lens §1.2.
- design-complexity-lens §7.2: resolved-question reframe.
- design-r3-lens-substrate-index.md: SizeVariable line replaces SizeExpr line
  with InternTable-name-authority note.

P2 single-authority restored. Cross-doc consistency restored.

(BLOCKING #1 + #2 from same review at sha ef21e1a are already addressed
at earlier commits — see PR comment for receipts: 92d9b11 + 255cca3.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 2, 2026
…1488)

* docs(roadmap): fold 2026-05-01 paired exploratory + reflective analyses

Director relayed two analyses against current main:
- Exploratory (gpt-5-5-pro main@8cd5359): 9 findings against
  dsl/std/*.dag, src/v2/tests/src/*.rs, dsl/extdeps/, THESIS,
  INVARIANTS, MODELING, ROADMAP — 2 novel correctness bugs
  (SymbolicCost semiring violation, emitter expect() panic paths),
  3 sharpened tracked items (SubValueRelation lattice-law
  contradiction, ?? / % syntax-parser drift, CollectionOps/StringOps/
  MapOps duplicates), 4 already-tracked items
- Reflective (gpt-5-5-pro main@6ea9812 → now): 5 cross-PR patterns
  + 6 highest-priority course corrections + verdict "advancing,
  scaffold-velocity dominates"

PM ingestion folds into single ROADMAP debt section per Director's
prior 2026-04-30 analyses ingestion pattern (PR #1319). Sections:

- A: Exploratory novel correctness bugs (SymbolicCost product-zero
     bug, SubValueRelation BoundedLattice claim violation, emitter
     expect panic paths)
- B: Exploratory sharpened tracked items (?? / % drift,
     CollectionOps/StringOps/MapOps duplicates)
- C: Exploratory already-tracked confirmations (no new ROADMAP rows)
- D: Reflective 5 cross-PR patterns (author-now/fire-later, test_
     runner.rs second predicate language, typed-carrier-Rust-mirror
     accumulation, numeric philosophy mid-window shift validating
     T-Numeric-Construction reframe, bridge retirement tracked-not-
     retired)
- E: Reflective 6 highest-priority course corrections with owner
     attribution + lane connection table
- F: CI cost signal (e765c86a 60min timeout) + velocity-tripwire
     calibration (64 docs / 16 feat / 9 fix ratio)
- G: PM strategic synthesis: 3 cross-cutting meta-themes
     (algebraic-law-witness coverage gap; "make scaffolds executable"
     cluster; "tighten existing structural enforcement" cluster)

Per-finding/correction owner attribution names R3 Substrate Mgr,
R3 Verification Mgr, R3 Grounding Mgr, R3 PB Mgr per ownership
boundaries. Lane connections cite T-V-L4-L7-Direct, T-Free-
Consequences-Demonstration, T-Ground-Services parser-grammar slice,
T-Numeric-Construction Slice 2 sequencing, etc.

Highest-value novel: SymbolicCost product-zero bug (cost-lens reads
incorrect facts; iterate(ConstantCost(0), ...) returns body cost
instead of zero) + emitter expect() panics. Highest-value
sharpened-tracked: SubValueRelation BoundedLattice false-claim.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): R3 scope expansion 12 → 16 lanes + standing R3 Debt-Paydown program

Per Director ratification 2026-05-02 at gunbc#828 comment 4362742638:

User directive: per the strict reading of "nothing deferred past R3", all
"accidentally deferred" gaps absorb into R3. Plus three additional asks:
behavioral expectations docs per feature; compile-error complexity ratchet
generalized as lens-application-surface (per user reframe); in-cycle
debt-paydown discipline.

NEW R3 LANES (4 added; lane count 12 → 16):
  13. T-E-P-Producer-Broadening (Substrate; M-L; foundational)
      - broaden per-call DescentEvidence/CallPattern/SubValueRelation
        from first slice to full ExprCall.descent_evidence parity
      - prerequisite for T-Lens-Behavioral-Parity

  14. T-Lens-Behavioral-Parity (Substrate + Verification cross-program; L-XL)
      - 4 sub-slices: complexity / cost / parallelism / effect_enumeration
      - bring lens-capability-register from PROXY/STUB/PARTIAL → COMPLETE
      - includes symbolic CostExpr full algebra; work/span split;
        asymptotic classification; cementing test against v2 oracle;
        Stage 2e parallelism walk port; resource-threading migration

  15. T-Tests-As-Data-Completeness (Verification; L)
      - tests-as-data full coverage (thesis facet 3)
      - property-based testing surface (ForAll/Exists quantifiers +
        ProgramGenerator carrier)
      - cementing test discipline for .dag lenses

  16. T-Lens-Application-Surface (Substrate + Verification; L-XL)
      - per user reframe: lens application as first-class authoring surface
      - apply_lens(lens, section, config) where config.violation_policy =
        CompileError | Warning | Silent
      - subsumes prior T-Complexity-Contract-Compile-Error +
        T-User-Authored-Cost-Basis-Discipline as configurations
      - 4 worked examples: complexity-contract-compile-error + CRDT cost
        basis + memory-peak cost basis + opt-in cross-iteration parallelism
      - default policy for complexity contract: opt-out

NEW STANDING PROGRAM:
  R3 Debt-Paydown Manager (9th standing R3 Mgr)
  - hybrid mechanism: per-PR debt-receipt rule + standing capacity
  - closure gate: r3_debt_paydown_zero_remaining
  - per feedback_standing_managers_need_owned_deliverables

FOLD-INS (3; no new lanes):
  - T-V-L4-L7-Direct: per-(algebra, inhabitant, law) exhaustive witness
    coverage (catches SymbolicCost product-zero bug class structurally)
  - T-Ground-Diagnostic: closed-axis enforcement (no String dispatch on
    closed sets); replaces MissingEmissionPath { connective: String, ... }
  - T-LensProducer-Retirement: ownership d/e/f confirmed delivered (not
    separately deferred)

T-Behavioral-Expectations-Documentation (parallel-dispatchable; 7 load-
bearing features per Director ratification): lens framework + 4 lens
instances + complexity contract + cross-target consistency.

Updates to docs/r3-structure.md:
  - §Summary: 12 lanes + 1 standing program → 16 lanes + 1 standing
    program
  - §Lane structure: 4 new rows
  - §Manager structure: 8 → 9 standing managers; 3 → 4 modifications
  - NEW §Standing program — R3 Debt-Paydown section authored
  - T-Numeric-Construction lane row updated to 13 types in scope (was 8;
    per 2026-05-02 PM audit + Substrate Mgr ack)

R3 scope ratchet: ~58% (over current 12-lane denominator) → ~38% (over
expanded 17-lane denominator); numerator unchanged. Honest timeline
projection: R3 close in 5-8 weeks at current velocity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Numeric-Construction row — 8-type → 13-type scope citation + traceability

Director callout on PR #1480: §Summary item 6 says 13 types in scope but
§Lane structure table row 138 still said 8. Internal inconsistency.

Fix: §Lane structure table row 138 updated to 13 types in scope, with
explicit citation chain:
  - original 8-type count from PR #1430 §A audit
  - extended to 13 after fresh PM sweep found 5 additional Int-inherited
    refinement types (RetryCount / HttpStatus / Port / PositiveInt /
    NonNegativeInt) at dsl/std/types.dag:232-245
  - Substrate Mgr ack at gunbc#1130 comment 4360482400

Includes: Nat-alignment opportunity flagged (NonNegativeInt → Nat,
PositiveInt → Nat where range(min: 1)), cost-lens candidates for
bounded-range types (RetryCount → Nat<3>, HttpStatus → Nat<10>,
Port → Nat<16>) once refinement composition lands.

Per Director recommendation: brief addendum documenting the audit so
lane scope stays anchored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address PR #1480 cursor findings — §P5 mix-up + restored locked dispositions

Fixes 3 cursor findings on PR #1480 (sha 0f32605d) plus 1 exploratory:

1. §P5(b)/(c) mix-up (line 44): "vague deferrals rejected" attributes to
   §P5(b) per-PR gate (the rule that actually rejects vague deferrals), not
   §P5(c) Velocity tripwire (windowed dispatch-pause). Now also explicitly
   surfaces §P5(c) as separate (b) windowed-enforcement clause.
2. Restored Post-R2 emergent work disposition on Substrate/PB continuation
   bullet (line 187): Director-locked 2026-04-28 — emergent post-R2 work
   absorbs into Substrate Manager continuation, not new managers.
3. Restored Verification scope negations on Verification Manager bullet
   (line 189): "L6 NOT in Verification scope" + "T-CostLens-Composition NOT
   in Verification scope" — both Director-locked 2026-04-28.
4. Updated stale "9 of 12" / "3 non-gated" counts in §"Dependency on R2"
   (lines 393, 397, 399, 400, 402) to "11 of 16" / "5 non-gated" matching
   line 59 Summary; added T-Lens-Behavioral-Parity + T-Lens-Application-Surface
   to Evaluator-gated list with cascade gate note.

All Director-locked 2026-04-28 dispositions tagged "carried forward through
2026-05-02 expansion" so the locks survive the lane-count change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): close P5 escape hatch in r3_debt_paydown_zero_remaining gate

Cursor BLOCKING finding on PR #1480 at docs/r3-structure.md:173: gate
contradicted itself by allowing "deferred-to-post-R3 with Director sign-off"
after stating "no tracked-debt rows survive R3 close", weakening P5/strict-
forward-progress into a disposition convention.

Fix: remove the deferral escape hatch entirely. Gate is unconditional —
every tracked-debt row retires with PR receipt before R3 close. Grounds
in user directive 2026-05-02: "all 'accidentally deferred to post R3' into
R3 now". If a row appears unretirable, it surfaces as a substrate gap
requiring a named R3 lane (the directive that motivated this manager's
creation), not a Director-sign-off deferral.

Cites INVARIANTS §P5 directly: tracked-debt deferred past R3 close is the
bridge-as-steady-state pattern P5 explicitly forbids; the escape hatch
reintroduced that pattern at lower cadence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): reconcile T-Tests-As-Data-Completeness Evaluator-gating contradiction

gpt-5-5-pro REQUEST_CHANGES finding on PR #1480 (sha 0f32605d): line 59
summary said T-Tests-As-Data-Completeness is in the "5 self-contained
non-Evaluator-gated" group, but lane table at line 147 lists its dependency
as "R2-Evaluator (test execution runtime)". Schedulers got two incompatible
authorities (P2 single-authority violation).

Lane table is correct — porting Rust tests to .dag TestClaim requires the
Evaluator to execute the resulting test artifacts. Updated:

- Line 59 summary: 11 → 12 Evaluator-gated; 5 → 4 non-gated; T-Tests-As-
  Data-Completeness moved into Evaluator-gated list with reason
- Line 393 (Dependency on R2): same reclassification
- Line 395 (substrate-carrier-fed list): drop T-Tests-As-Data-Completeness
- Line 399 (precondition applies-to list): 11 → 12 lanes
- Line 400 (carve-out): 5 → 4 lanes; drop T-Tests-As-Data-Completeness
- Line 402 (split-resolution sentence): 11 → 12, 5 → 4

(Findings #2 and #3 already addressed at 0c449a869 and 0de2bda06
respectively.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Lens-Application-Surface design doc — substrate shape + 4 worked examples

Per user directive 2026-05-02 ("all designs upfront, implementation sketches
if needed, minimize escalations"), authoring foundational design doc that
unblocks T-Lens-Application-Surface lane dispatch.

Resolves design questions:

1. **Section reference shape**: `SectionRef = DeclarationScope { DeclarationId }
   | NodeScope { DeclarationId, NodeId }`. Three of four user-named scopes
   (function / module / declaration) use DeclarationId uniformly; expression
   scope is the exception (NodeId required because expressions live inside
   Declaration body sub-DAGs).

2. **Violation-policy semantics**: user-named `CompileError | Warning | Silent`
   resolved to fail-closed-compatible binary `Enforce | Introspect` per
   INVARIANTS C-8. Warning forbidden (allows violations as steady state,
   bridge pattern P5 forbids); Silent forbidden ("silent None" exactly the
   pattern feedback_fail_closed_discipline bans).

3. **Default complexity-contract policy**: opt-out (compiler enforces;
   explicit waiver required). Waiver shape is structural `ComplexityBudgetWaiver`
   declaration with `justification` field, NOT an annotation per
   feedback_no_annotations.

4. **4 worked examples** ratified by Director (complexity-contract /
   CRDT cost / memory-peak cost / opt-in parallelism) — each grounded in
   substrate carriers + lens-fold integration.

5. **5 open design questions** flagged for Director ratification before
   substrate authoring begins (module-level semantics, multiple-applications-
   per-section, budget-inference for default, waiver dissolution, cross-section
   composition).

Updates r3-structure.md lane 16 row to reference the design doc, replace the
@complexity_budget_waived annotation language with structural carrier name,
and replace the original `CompileError | Warning | Silent` enum with the
fail-closed-resolved Enforce/Introspect binary.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve all 5 §8 open design questions in-doc per minimize-escalations directive

Per user directive 2026-05-02 ("minimize escalations"), resolved the 5 open
design questions that were flagged for Director ratification:

§8.1 — Module-level semantics: aggregate-across-module (preserves
      structural distinction between module-scope and per-function-scope).
§8.2 — Multiple applications: fail-closed reject duplicate (lens, section)
      Enforce-mode pairs; multiple Introspect admitted (idempotent).
§8.3 — Default-application budget: regression-detection class, gated on
      T-Lens-Behavioral-Parity COMPLETE; pre-cascade Introspect-only.
§8.4 — Waiver lifecycle: future lens_stale_waivers lens with named
      dissolution trigger; tracked in lens-library-design.md §6.
§8.5 — Cross-section composition: read declared budget, not computed
      class (preserves abstraction barrier; cost-of-change=1).

Each resolution carries explicit reasoning grounded in INVARIANTS P2/P5
+ feedback memory. Implementation can proceed once cascade gates clear
(T-Lens-Behavioral-Parity COMPLETE for §8.3 flip; R2-Evaluator landed for
worker dispatch precondition). No further Director ratification needed
on these specific points.

r3-structure.md row 16 updated to reflect the design-doc resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): cross-design coherence pass + master design index

Coherence audit across the 5 design docs identified 5 cross-doc conflicts;
this commit resolves all 5 and lands the master index linking them.

Fixes:

1. **Producer-query single-authority** (P2): complexity-lens §2 + cost-lens
   §3.2 now both reference `per_call_pattern_at(d, call_site) -> CallPattern?`
   as the typed query surface (single authority); the underlying
   `per_call_descent_evidence` side-table is named as the storage backend
   only. Eliminates parallel-authority risk.

2. **Cementing-test shape unified** (DB-15): cost-lens §5 reshaped from
   custom `ForAll { p: SourceProgram in programs }` (which violated tests-
   as-data §2.5 — quantifiers belong on claims, not predicates) to
   `QuantifiedTestClaim { generator, quantifier: ForAll, predicate:
   DifferentialEquals }`. Now matches complexity-lens §4 and tests-as-data
   §2.2 shape.

3. **DB-18 element-type-refinement cross-reference**: effect-enumeration §4.1
   now explicitly states that DB-18's STOP-AND-ESCALATE locks the
   `WorkflowEffect` variant set + variant payload shape, not element-type
   within `LinearEffect.ops: List<X>`. The `OperationEffect` →
   `Operation` retypes is additive tightening within DB-18's permitted
   refinement scope.

4. **Resource-threaded signature compatibility**: cost-lens §3.3 now
   explicitly notes that `per_call_pattern_at` reads from threaded arrow
   signatures (per effect-enumeration §2.4) — signature-shape-agnostic
   producer; broadening covers both pre-migration and post-migration
   signature shapes.

5. **TestClaim shape for lens-application demonstrations**: lens-application
   §4 now declares all 4 worked-example closure gates use `TestClaim`
   (DB-15 enumerated form), not `QuantifiedTestClaim`. Property tests over
   the lens-application substrate live in T-Tests-As-Data scope, not
   T-Lens-Application-Surface scope.

6. **Register-migration sequencing**: tests-as-data §8.3 now lists the 4
   sibling lens design docs whose register-row "→ COMPLETE" closure steps
   depend on the markdown→.dag migration landing first (substrate work in
   sibling lanes does NOT depend; only the closure-gate row update does).

Plus: NEW `docs/design-r3-lens-substrate-index.md` — master index linking
all 5 design docs, documenting cross-doc edges (substrate authority
single-points + cementing-test format + cross-cutting invariants), and
naming lane dispatch order.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address 4 cursor findings on PR #1480 (sha 16340c52)

1. **Lane 16 row 40 stale text vs row 148 resolved** (P2 single-authority):
   row 40 still carried the original `CompileError | Warning | Silent`
   enum + `@complexity_budget_waived` annotation language; row 148 had
   the resolved `ViolationPolicy = Enforce | Introspect` + structural
   `ComplexityBudgetWaiver` carrier. Updated row 40 to match the
   resolved story (single authority).

2. **Line 44 duplicate (b) and (c) labels**: the Hybrid mechanism outer
   enumeration used (a)/(b)/(c) but referenced INVARIANTS §P5 sub-
   mechanisms (a)/(b)/(c) inside; same letter labels at different
   levels confused parsing. Renamed outer enumeration to (1)/(2)/(3)
   with footnote explaining the distinction.

3. **Line 175 contradicts line 173** (P5): line 175 said "Does enforce:
   tracked-debt rows get retirement PRs or explicit deferral" — the
   "or explicit deferral" reads like deferral remains an outcome,
   contradicting line 173's unconditional "no post-R3 deferral path".
   Removed the deferral language; line 175 now restates the unconditional
   rule + names the substrate-gap escalation path.

4. **design-complexity-lens-behavioral-completeness.md:125-127 variant-
   count mismatch** (P1 self-faithfulness): comment said "closed
   seven-variant set" / "Adding an eighth variant" but `AsymptoticClass`
   enumerates 8 variants (ClassConstant/Log/Linear/Linearithmic/
   Quadratic/Polynomial/Exponential/Unknown). Updated comment to
   "eight-variant" / "ninth".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): retract cost-lens parallel SizeExpr proposal — align with complexity-lens single authority

Cursor BLOCKING finding on PR #1480: cost-lens proposed a new SizeExpr
5-variant coproduct as authority, while complexity-lens proposed
SizeVariable.display_name enrichment for the same SymbolicCost payloads.
P2/P5 violation — same substrate fact, two incompatible target shapes.

Resolution: complexity-lens has the structurally correct framing.
- DB-7's SymbolicCost is the unified algebra (locked).
- SymbolicCost already covers SizeAdd (via SumCost) and SizeMax (via
  dominance ordering) — no parallel SizeExpr algebra needed.
- Descent semantics like "n - 1" live in std.computation::CallPattern
  (the canonical E-C site), not in size expressions. A SizeShrink
  variant would duplicate that fact in parallel.
- Asymptotically O(n - 1) ≡ O(n); descent is a call-site property,
  not a size-shape property.

Aligned cost-lens to complexity-lens: SizeVariable gains an optional
display_name: String? field; no parallel SizeExpr carrier; SymbolicCost
DB-7 lock preserved unchanged.

Updated:
- §1.1 problem framing — drop "size arithmetic" / "aggregate sizes"
  framing (already covered by SymbolicCost); keep only the
  "named-binding semantics" gap that motivates display_name.
- §1.2 target shape — SizeVariable.display_name: String? (matches
  complexity-lens §1.2 verbatim).
- §1.3 explicit rationale for unified-algebra over parallel-SizeExpr.
- §1.4 migration shape — additive field, no carrier rename, no deletion.
- §3 / §5 code examples — replaced SizePort with SizeVariable shape.
- §8.1 resolved-question reframe — names the rejected alternative
  (parallel SizeExpr) for future readers.
- §8.2 names-on-carrier resolution — display_name shape per §1.2.
- §10 implementation step 1 closure gate renamed
  size_expr_substrate_landed → sizevariable_displayname_landed.

P2 single-authority restored across the 5-doc design surface.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration — read/write distinction via algebra inhabitance, not signature shape

Cursor BLOCKING finding on PR #1480 at design-effect-enumeration-resource-
threading.md:151: the design's "structural recognition" claim was actually
convention-level. \`R in / R out\` and \`R in / R' out\` (same type, different
value) have the SAME typed signature — \`.dag\` doesn't encode value-
preservation as a substrate fact. ReadShaped vs WriteShaped via signature
shape alone was P1 modeling-faithfulness violation.

Resolution: split the unified rule into two structural carriers per §2.4:

(a) Effect SET — derived from signature: resource types in input ∩ output.
    Structural; the signature carries it.

(b) Effect KIND — declared via algebra inhabitance on the callable:
    \`inhabits IdempotentRead<R>\` (read), \`inhabits Mutating<R>\` (write),
    \`inhabits Append<R>\` (append). Structural; the inhabitance carrier
    captures it.

The lens consults BOTH — signature for set, inhabitance for kind. Absence
of any kind inhabitance with the resource in the effect set is a fail-
closed Diagnostic (EffectKindUndeclared), not a silent default.

Updates:
- §2.1 line 151: replace "same-value vs modified" framing with explicit
  effect-set-vs-effect-kind distinction; cross-link to §2.4 + §8.1.
- §2.3: same fix for Network read example.
- §2.4: split the unified rule into (a) effect SET (signature) + (b)
  effect KIND (algebra inhabitance) with pseudocode for the lens-side
  classification.
- §4.3: update EffectShape derivation source from "signature shape" to
  "algebra inhabitance lookup".
- §8.1: full reframe — from "same-value resolved" to "algebra inhabitance
  is the structural authority", with explicit rationale (per-callable
  authority, not per-call; rejected phantom-marker alternative per
  feedback_no_annotations).
- §3 lens fold pseudocode: dispatch on §2.4(a) for set + §2.4(b) for kind.

Preserves the existing EffectShape = IsIdempotent | IsBreaking partition
(per design-composed-effect-reshape.md PR #529 R3) — only the source of
the shape changes (declared inhabitance, not derived from signature).

P1 modeling-faithfulness restored. Cursor finding fully resolved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): lens-application — collapse ApplicationConfig into sum-type, illegal states unrepresentable

Cursor BLOCKING finding on PR #1480 at design-lens-application-surface.md:43:
ApplicationConfig was a record with budget: LensBudget? + violation_policy:
ViolationPolicy as separate fields. This admitted illegal state combinations:
- Enforce + budget=None (illegal: enforcement requires a budget)
- Introspect + budget=Some(_) (illegal: introspection takes no budget)

The doc explicitly noted these as type-checker-enforced invariants (lines
136-137), but per feedback_state_space_vs_behavioral_invariants those are
behavioral invariants, not state-space invariants — exactly the bug pattern
modeling-discipline principles 2/6 prohibit. Illegal states must be
unrepresentable at the type level.

Resolution: collapse ApplicationConfig and ViolationPolicy into a single
sum-type that pairs budget with Enforce by construction:

```dag
type ApplicationConfig
  = Enforce { budget: LensBudget, diagnostic_severity: DiagnosticSeverity }
  | Introspect
```

By construction:
- Enforce ALWAYS has a budget (it's a coordinate of the variant).
- Introspect NEVER has a budget (it has no payload).

The "Enforce without budget" and "Introspect with budget" combinations
cannot be constructed; the type-checker has no rejection rule to enforce
them — they don't exist in the state space.

Updates:
- §2: replaced ApplicationConfig record + ViolationPolicy sum with single
  ApplicationConfig sum carrying budget inside Enforce variant.
- §3: rewrote framing to match — the binary Enforce/Introspect is the
  ApplicationConfig sum itself; budget pairing is structural.
- §4: all 4 worked-example syntaxes updated to `Enforce { budget,
  diagnostic_severity }` directly (no separate violation_policy field).
- §5.1: synthesized default-application uses `Enforce { budget: <inferred>,
  diagnostic_severity: Error }` shape.
- §3.2: explicit-introspection override syntax `apply_lens(complexity, fn,
  Introspect)` (no separate budget=None).
- r3-structure.md rows 40 + 148: updated substrate-carrier description to
  name ApplicationConfig as sum-type with the structural-invariance note.

Modeling principles 2/6 honored. P1 modeling-faithfulness restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): codex non-blocking findings #2 + #3 — heading/count consistency

Codex review on PR #1480 sha 58f49e91 noted two non-blocking inconsistencies:

NB2: design-cost-lens-sizevar-dimension-wiring.md §4.2 heading said
'CommutativeSemiring<SymbolicCost>' but §8.5 resolves to 'Semiring<SymbolicCost>'
(multiplicative side does NOT enforce commutativity per §8.5 reasoning).
Fixed §4.2 heading to match §8.5 resolution.

NB3: design-tests-as-data-completeness.md §3.1 said 'six classes' /
'decomposes into six structural classes' but §10 step 3 enumerates C1-C7
(seven classes). Fixed §3.1 to say 'seven classes' with explicit C1-C7
cross-reference.

Both load-bearing for doc-as-authority discipline (P1 modeling-faithfulness
of the spec to itself).

(All 4 BLOCKING findings from same review at sha 58f49e91 are already
addressed at earlier commits — see PR comment for the receipts:
ef21e1a00 / 92d9b11cf / 255cca3cb / 8640e6701.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix line 199 active-surface arithmetic + line 23 exploratory clarity

Cursor APPROVE_WITH_COMMENTS finding on PR #1480 sha 92d9b11c:

**Main finding (line 199)**: arithmetic was internally inconsistent —
"expanded from 13 active surfaces" + "4 new lanes + 1 new standing program"
= 18, not 17. The baseline should have been 12 (12 lanes + 0 standing
programs at the 2026-04-30 lock), making 12 + 5 = 17 consistent. Fixed by
restating the baseline as 12 with explicit arithmetic: 4 new lanes
(enumerated by name) + 1 new standing program = +5; 12 + 5 = 17.

Also pinned T-Behavioral-Expectations-Documentation explicitly as
"parallel-dispatchable across existing lanes, not a separate surface" so
readers don't double-count it as a 5th new lane.

**Exploratory finding (line 23)**: the "added..." list mixed 4 new lanes
+ T-Behavioral-Expectations-Documentation (not a separate lane) + standing
program in one breath. Restructured the parenthetical to enumerate the 4
new lanes by name and call out T-Behavioral-Expectations-Documentation as
parallel-dispatchable explicitly. Reader can no longer mis-count.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop SizeVariable.display_name; InternTable single-authority for size names

gpt-5-5-pro REQUEST_CHANGES on PR #1480 sha ef21e1a0 — BLOCKING #3 + #4:

BLOCKING #3: SizeVariable.display_name + intern_table::name_of(source_port)
created TWO authorities for the user-facing size-variable name. The §8.2
implementation note confirmed the parallel: "when display_name = Some(name),
renderer uses it directly; when None, falls back to InternTable lookup".
P2 single-authority violation; consumers could diverge on the same source_port.

BLOCKING #4: master index design-r3-lens-substrate-index.md still claimed
SizeExpr replaces SizeVariable, but cost-lens design (post-ef21e1a00) had
already retracted SizeExpr in favor of unified SymbolicCost. Cross-doc
authority drift.

Resolution (both BLOCKINGs):
- Drop display_name field entirely from cost-lens + complexity-lens designs.
- SizeVariable substrate stays UNCHANGED at { source_port: PortId }.
- InternTable is the single canonical name authority — already populated
  at parse time keyed by port_id. Renderer reads via
  intern_table::name_of(source_port).
- The "Named SizeVar" gap from the capability register is closed by
  renderer-side wiring (no substrate change), not by adding a field.
- Master index updated: SizeVariable line replaces the old SizeExpr line;
  notes InternTable as name authority.

Updates:
- design-cost-lens §1.2: target shape removes display_name field from
  SizeVariable carrier; rationale rewritten as InternTable-as-single-authority.
- design-cost-lens §1.4 / §3 / §5 / §8.1 / §8.2: all display_name references
  scrubbed; "renderer-side InternTable name wiring" replaces "SizeVariable.
  display_name enrichment" throughout.
- design-cost-lens §10 step 1: closure gate renamed
  sizevariable_displayname_landed -> renderer_intern_table_name_wiring_landed.
- design-complexity-lens §1.2: same rewrite — SizeVariable carrier UNCHANGED;
  InternTable as name authority; explicit cross-link to cost-lens §1.2.
- design-complexity-lens §7.2: resolved-question reframe.
- design-r3-lens-substrate-index.md: SizeVariable line replaces SizeExpr line
  with InternTable-name-authority note.

P2 single-authority restored. Cross-doc consistency restored.

(BLOCKING #1 + #2 from same review at sha ef21e1a0 are already addressed
at earlier commits — see PR comment for receipts: 92d9b11cf + 255cca3cb.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): codex review wave (sha 98f2fc4f) — 4 BLOCKING + 2 NB findings addressed

BLOCKING #1: lens-application config not parametric in C — lens/budget pair
relied on type-checker convention rather than structural typing. Fix:
SectionedLensApplication<C> + ApplicationConfig<C> parametric in the lens
carrier C; lens: Lens<C> and config.budget: C share the same C
structurally. Mismatch is unrepresentable, not type-checker-rejected.
Per-lens budgets dissolve into the existing Lens<C> carrier — no separate
ComplexityBudget/CostBudget/ParallelismBudget carriers needed.

BLOCKING #2: complexity-lens Certainty composed independently from cost
dominance. Fix: define joint compose_summary function (§3.1) where
certainty composition is cost-aware — when dominance drops a cost
component, that component's certainty does NOT enter the result. Surfaces
v2's implicit Θ(n²) Proven semantics; cost-unaware certainty would diverge
from v2 on the cementing fixture corpus.

BLOCKING #3: effect-enumeration line 17 prose still claimed signature is
"one structural authority" for effects. Fix: updated to name the two
orthogonal authorities — signature for effect SET, algebra inhabitance
for effect KIND. Aligned with §2.4 + §8.1 that I'd already fixed at
92d9b11cf.

BLOCKING #4: sibling lens docs and tests-as-data didn't share one
cementing closure shape — complexity + effect proposed Rust cementing
tests, cost (after my earlier fix at ef21e1a00) proposed QuantifiedTestClaim.
Inconsistency. Fix: align all three on **Rust cementing today + dissolution
trigger to tests-as-data step 5 .dag port**. Per-lens divergence is now
explicitly forbidden in the master index.

NB1: cost-lens §1.4 still said "single field addition" / "Rust mirror
single field add" after the InternTable fix removed the field add. Cleaned
up to "renderer-only, no substrate change".

NB2: tests-as-data §3 said "17 variants" but enumerated 22 (Compiles ...
BridgeLedgerZero). Fixed count to 22.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): scrub residual non-parametric LensBudget references

Cursor BLOCKING at sha 98f2fc4f line 102 — incomplete fix for parametric
SectionedLensApplication<C> migration at 812f6a141. Three lines still
referenced the old non-parametric framing:

- Line 100: "type-checker verifies b inhabits lens.budget_type" — type-checker
  convention rather than structural typing.
- Line 114: ApplicationConfig redeclared without <C> parameter.
- Line 262: substrate-owner mention of "per-lens budget_type declaration
  extension".
- Line 351: "each lens owns its own LensBudget definition" — implied
  separate budget carriers.
- Line 357: implementation step said "Lens<C>.budget_type field added".

All updated to reflect the parametric resolution (per §2):
- ApplicationConfig<C> parametric in lens carrier C; lens/budget pair is
  structural via shared C.
- Mismatch is unrepresentable, NOT type-checker-rejected.
- No budget_type field on Lens<C>; the parameter C IS the structural
  authority.
- Each lens's existing Lens<C> carrier IS the budget type; no new
  per-lens budget carriers.

References to "budget_type" / "LensBudget" remain only in negation form
("not via budget_type field", "no LensBudget definition") to document the
rejected alternative for future readers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): lens-application — dissolve regression_baseline_pinned optional field

Cursor BLOCKING at sha 98f2fc4f line 323 (actually line 308 — drift after
prior edits): regression_baseline_pinned: AsymptoticClass? was an
optional field on SectionedLensApplication where absence = introspection
mode and presence = enforcement mode. This re-creates EXACTLY the
illegal-states-representable pattern that the §2 ApplicationConfig
sum-type fix dissolved (the original finding at design-lens-application-
surface.md:43 from a prior wave).

Fix: dissolve the optional field. The cascade-flip (T-Lens-Behavioral-
Parity COMPLETE flipping default complexity from Introspect to Enforce)
is purely SYNTHESIZER-side, not substrate-side:

- Pre-cascade: synthesizer emits `Introspect` for every default
  complexity application.
- Post-cascade: synthesizer emits `Enforce { budget: <computed class>,
  diagnostic_severity: Error }` — the computed class IS the regression
  baseline; the variant choice carries the fact structurally.

No optional field on the carrier. The cascade just changes which variant
the synthesizer constructs. Same illegal-states-unrepresentable
discipline as §2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop certainty_lattice — Certainty composition is cost-aware, not lattice-fold

Cursor BLOCKING at sha 98f2fc4f line 196: join_certainty's "Proven wins
under alternative" semantic was P1 unfaithful — a Proven branch arm could
hide a Conservative arm carrying the actual worst-case bound, so the
result's certainty would no longer faithfully describe the bound it
qualifies. Same cost-unaware pattern as the §3.1 BLOCKING from earlier
in the wave (composition independent from cost dominance).

Resolution: drop the BoundedLattice<Certainty> declaration entirely.
Certainty does NOT compose via lattice meet/join; composition is
cost-aware per §3.1 compose_summary_* family. The lattice declaration
was misleading — it suggested an independent composition pattern that
contradicts the cost-aware design.

Updates:
- §1.5: removed `data certainty_lattice` declaration + meet_certainty +
  join_certainty function bodies. Replaced with prose explaining
  cost-aware composition + tightness-ordering distinction (ordering is
  implicit when projecting; not a composition operation).
- §3.1: meet_certainty(...) call → meet_pair(...) inline helper, with
  explicit comment that it's used ONLY when both contributions survive
  cost composition (NOT a free-standing lattice op).
- §11 cascade-gate list: removed "data certainty_lattice" from the
  class-5-grammar dependent declarations list with explanatory note.

Same illegal-states-unrepresentable + cost-aware-composition discipline
preserved end-to-end across the §3.1 + §1.5 + §3.x compose_summary_*
chain.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration §8.4 — derive readonly deletion from algebra inhabitance, not signature shape

Cursor BLOCKING at sha 98f2fc4f line 442: §8.4 "readonly keyword deletion"
rationale said the keyword is "structurally derivable: an operation is
read-shaped iff every threaded resource appears unchanged in input and
output." This contradicts §2.4's locked rule that effect KIND is
declared only via algebra inhabitance (inhabits IdempotentRead<R>),
NOT derived from signature shape — same modeling-discipline violation
as the line 151 BLOCKING from the prior wave (cursor BLOCKING #2 of
this codex-wave).

Resolution: rewrite §8.4 to derive readonly's deletion rationale from
algebra inhabitance, not signature shape:

- After migration, read kind is declared via `inhabits IdempotentRead<R>`
  on the callable (per §2.4 + §8.1) — structural fact.
- The `readonly` keyword duplicates that inhabitance: same fact, two
  carriers. P2 single-authority + feedback_no_annotations forbid this.
- Keyword is redundant AND drift-prone (feedback_state_space_vs_
  behavioral_invariants: keyword could disagree with inhabitance).
- Implementation-mechanical: every operation currently using `readonly`
  already has a corresponding `inhabits IdempotentRead<R>` declared at
  the migration site (one-to-one mapping in the atomic PR per §6).

The §2.4 → §8.1 → §8.4 chain is now consistent end-to-end: signature
carries effect SET; algebra inhabitance carries effect KIND; the
readonly annotation is the same parallel-authority bug pattern P5/P2
forbid.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix tests-as-data dissolution-trigger cross-reference §10 → §6

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 (sha 95b54f54): all 4
docs cross-referencing the cementing-dispatch-port dissolution trigger
pointed at "tests-as-data §10 step 5", but tests-as-data has no §10 —
the implementation-order list (containing step 5 = cementing dispatch
port) is at §6.

Fixed in 4 places:
- docs/design-r3-lens-substrate-index.md:39
- docs/design-complexity-lens-behavioral-completeness.md:425
- docs/design-cost-lens-sizevar-dimension-wiring.md:314
- docs/design-effect-enumeration-resource-threading.md:489

Per INVARIANTS "Documentation Describes Live State" — readers can now
resolve the cited anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cost-lens cementing — tighten Band-C parity claim to full SymbolicCost/CostExpr carrier

gpt-5-5-pro APPROVE_WITH_COMMENTS finding on PR #1488 sha fa5f1675:
line 316 said "asserting structural equivalence on the asymptotic class"
which could weaken the Band-C parity assertion if read literally — the
asymptotic class is a projection of SymbolicCost, not the full carrier.

Tightened to commit to the stronger claim: cementing asserts structural
equivalence on the FULL SymbolicCost/CostExpr carrier shape (not a
projection). Asymptotic-class equivalence is a downstream consequence,
not a substitute. Aligns with the structural_equivalent() function shape
already declared at line 318.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remove implicit Enforce-with-inferred-baseline; align Certainty no-lattice references

Codex BLOCKING on PR #1488 sha 265d8ef7: §8.3 + §3.2 + §5.1 said the
default complexity application post-cascade flips to Enforce mode with
"budget = computed asymptotic class at synthesis time" — but the
synthesizer recomputes from the current body each compile, so the baseline
moves with the body. Whatever class the function has becomes both
"current" and "baseline"; they always agree; no regression ever fires.
The fact the design claimed to enforce was lost on every recompile.
P2 single-authority + facts-flow-forward violation.

Resolution: remove the implicit Enforce mode entirely. Default is
Introspect-only for unannotated functions; user explicitly authors
Enforce { budget: <chosen class>, ... } to opt into enforcement. No
auto-inferred baseline — those would need persisted authority (either
generated source, forbidden by feedback_no_generated_code_on_disk, or
sidecar files, same problem). The structural answer: complexity contracts
are user-authored.

Re-framing "opt-out for complexity" per the original user directive: the
user can opt out (by not authoring an Enforce application or by
authoring Introspect); compile errors fire when the user opts IN with a
budget the actual function exceeds. ComplexityBudgetWaiver retains its
purpose — accepting known violations of explicit user contracts.

Codex NB: residual references to "Certainty + lattice declaration" /
"two new lattice instances" in complexity-lens lines 535 + 579 didn't
match the §1.5 lattice deletion. Updated both to single
BoundedLattice<AsymptoticClass> instance + Certainty 2-variant sum
WITHOUT lattice (composition is cost-aware via §3.1 compose_summary_*).

Updates:
- §3.2 (Default policy): full reframe to user-driven contracts.
- §5.1 (Default-application synthesis): synthesizer never emits Enforce;
  only Introspect for unannotated functions.
- §8.3 (Default-application semantics): RESOLVED with new framing —
  user-driven contracts; no implicit baseline; explicit rationale for
  why generated-source is not the answer.
- complexity-lens §5 step 2 + §7.4: drop "Certainty + lattice declaration"
  and "BoundedLattice<Certainty>" from the substrate-landing list and
  ROADMAP-P2 dissolution accounting.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): lens-application — add LensEnforcement<Output, Budget> projection carrier

Codex BLOCKING on PR #1488 sha 265d8ef7 line 100: tying ApplicationConfig<C>
to the same C as Lens<C> made the complexity lens budget = AsymptoticClass,
but the complexity-lens design publishes Lookup<ComplexitySummary> with
work/span/certainty as the lens output. Either drop downstream facts (force
output = AsymptoticClass) or contradict the lens-output contract (output =
ComplexitySummary; budget = AsymptoticClass; type system can't enforce
compatibility). P1 modeling faithfulness + facts-flow-forward violation.

Resolution: introduce LensEnforcement<Output, Budget> projection carrier
in §2. Each lens declares both:
- Lens<Output> for the read function (rich output type — load-bearing for
  lens-fold composition per compose_summary_*)
- LensEnforcement<Output, Budget> for the projection from Output to the
  budget-comparable type (identity for cost; summary.asymptotic_class for
  complexity)

SectionedLensApplication<Output, Budget> is parametric in BOTH parameters;
the type system enforces lens/projection/budget compatibility through the
shared Output and Budget. Mismatched triples (e.g., complexity-lens with
SymbolicCost budget) are unrepresentable.

Why projection rather than single-carrier: the lens output for complexity
is rich (ComplexitySummary {work, span, asymptotic_class, certainty}) —
required by §3.1 compose_summary_* composition. The budget is simple — the
user's "function should be O(log n)" contract. Forcing budget = output
over-constrains user authoring; forcing output = budget drops facts the
composition needs. The projection separates the concerns.

Updates:
- §2: introduce LensEnforcement<Output, Budget>; SectionedLensApplication
  becomes parametric in (Output, Budget). Worked examples for all 4
  lens enforcements added.
- §3: ApplicationConfig<Budget> (was <C>); narrative updated to reference
  Output + Budget pair.
- §6: Substrate Manager scope expanded to include LensEnforcement
  declarations.
- §9 (NOT-modify list): per-lens budget types now declared via
  LensEnforcement, not via shared C.
- §10 step 1: closure gate adds lens_enforcement_carrier_landed; substrate
  authoring includes per-lens LensEnforcement declarations.
- design-r3-lens-substrate-index.md substrate-authority table: updated to
  list the 4 parametric carriers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* WIP: Gunbc PM

* docs(r3): split SectionedLensApplication into per-variant carriers + scrub stale QuantifiedTestClaim ref

Two BLOCKINGs from codex on PR #1488 sha c6e61914:

BLOCKING #1 (lens-application §2 lines 94 + 129): the previous shape
SectionedLensApplication<Output, Budget> required EVERY application
(including Introspect) to declare a Budget type and an enforcement
projection. But §3 + line 129 said Introspect has "no projection or
comparison" — leaving Introspect carrying enforcement metadata it
cannot consume. P2 / illegal-states-unrepresentable: an Introspect
application should not have enforcement axes.

Resolution: split into two carriers + sum:
- EnforcedApplication<Output, Budget> — carries lens, enforcement, section,
  budget, diagnostic_severity, span. Both type parameters relevant.
- IntrospectApplication<Output> — carries only lens, section, span. No
  Budget axis, no enforcement projection.
- SectionedLensApplication = Enforce<O,B>(EnforcedApplication<O,B>) |
  Introspect<O>(IntrospectApplication<O>) — sum where each variant
  carries exactly its required parameters.

Now Introspect cannot accidentally carry enforcement state; mismatched
triples (lens, projection, budget) remain unrepresentable for Enforce
applications. Both illegal classes structurally rejected.

BLOCKING #2 (cost-lens line 332): residual paragraph still said "The
QuantifiedTestClaim runs..." asserting equivalence on asymptotic class
only — contradicted line 312's "Rust cementing test today" + line 316's
"full SymbolicCost/CostExpr structural equivalence" Band-C parity claim.
Two incompatible closure-gate authorities in same section.

Resolution: rewrote line 332 to align with Rust cementing + full
SymbolicCost/CostExpr structural equivalence. Single authority restored.

Also updated downstream references:
- §3 narrative: ApplicationConfig sum-type declaration removed (folded
  into EnforcedApplication directly per §2). Pairing semantics still
  documented; the carrier shape is the single authority.
- §3.2 ComplexityBudgetWaiver rationale: updated to "an Introspect
  application" instead of "SectionedLensApplication { config: Introspect }".
- §4.1 worked example: substrate-after-parsing block now uses
  Enforce<ComplexitySummary, AsymptoticClass>(EnforcedApplication { ... })
  with all coordinates explicit.
- §5.1 default synthesis: synthesizer emits
  Introspect<ComplexitySummary>(IntrospectApplication { ... }).
- §6 substrate-owner scope: 5 carriers now (was 4 before split).
- §10 step 1: closure gates updated; substrate authoring includes
  per-variant carriers + per-lens LensEnforcement declarations.
- master index substrate-authority table: row updated to reflect the
  carrier split.
- r3-structure.md rows 40 + 148: lane-row carriers list updated to
  match the per-variant shape.

P2 single-authority + illegal-states-unrepresentable preserved end-to-end.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): r3-structure default-policy text — sync with design-lens-application-surface §3.2 + §8.3

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 sha 96899484:
r3-structure.md lane-16 blurbs (lines 40 + 148) still said
"opt-out (default check fires; explicit waiver...)" — matched the
OLD default-enforcement story before my fix at e9d67113e which
resolved the design to user-driven contracts (no implicit baseline;
synthesized Introspect-only for unannotated functions).

Parallel prose authority for the same decision violated P2
(single authoritative description) — r3-structure summary
contradicted the canonical owning design doc.

Fixed both occurrences to match the resolved framing:
- Unannotated functions: synthesized Introspect-only.
- Enforcement: requires explicit user authoring of apply_lens with
  Enforce + budget.
- "Opt-out" reframed: user can opt out (no Enforce / explicit
  Introspect); compile errors fire when user opts IN with a budget
  the function exceeds.
- ComplexityBudgetWaiver preserved purpose: accepting known
  violations of explicit user contracts.

Single-authority restored; lane summary now points correctly at
the canonical design doc resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): LensEnforcement carries violation relation, not just projection

Cursor BLOCKING on PR #1488 sha 96899484 line 74: LensEnforcement<Output, Budget>
carried only `project: Output -> Budget`, leaving the fold-pass "budget
exceeded" check without per-lens substrate authority for the violation
relation. The check would have been API-level convention (the fold-pass
hardcoding "use lattice ordering for AsymptoticClass / dominance for
SymbolicCost / mode-mismatch for ParallelismMode" instead of reading
declared facts). P2/P6 single-authority + API-level-enforcement violation.

Resolution: extend LensEnforcement<Output, Budget> to carry both the
projection AND the violation relation:

```dag
type LensEnforcement<Output, Budget> {
  project: Output -> Budget
  violates: (declared: Budget, observed: Budget) -> Bool
}
```

Each per-lens enforcement declares its own violation semantics
structurally:

- complexity_enforcement.violates: lattice ordering on AsymptoticClass
- cost_enforcement.violates: dominance ordering on SymbolicCost (observed
  dominates declared)
- parallelism_enforcement.violates: mode-mismatch (OptInIndependent
  declared but lens computed Sequential = violation)

The fold-pass dispatch reads the per-lens violation relation directly
(no hardcoded comparison logic in the fold-pass; the dispatch is fully
substrate-driven).

Updates:
- §2 LensEnforcement carrier definition: extended with violates field +
  rationale.
- §2 per-lens enforcement examples: each declares both project and
  violates.
- §4.1 worked example "Compiler-side processing": fold-pass description
  reads enforcement.project then enforcement.violates.
- §5 lens-fold integration step 2: dispatch reads project + violates.

Per-lens substrate authority for violation relation restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): per-dimension certainty composition (work + span independent dominance)

Cursor BLOCKING on PR #1488 sha 96899484 line 380: certainty_of_surviving
derived certainty from composed_work only, but ComplexitySummary publishes
BOTH work and span. Span has independent dominance from work (different
inputs to iterate — span uses outer.work + body.span, while work uses
outer.work + body.work). A conservative span contributor could be dropped
from work's dominance walk while its span bound survived in span's
dominance walk — the surviving span contributor's certainty would not
enter the result's certainty. P1 modeling faithfulness + facts-flow-
forward: certainty no longer faithful to the bound it qualifies on the
span dimension.

Resolution: per-dimension cost-aware certainty composition. Each
dimension (work, span, future per-DB-3) computes its own surviving-
contributor certainty independently; the result certainty is the meet
across dimensions (any unproven dimension makes the whole result
unproven).

```dag
let work_cert = certainty_of_surviving_per_dim(outer, body, outer.work, body.work, composed_work)
let span_cert = certainty_of_surviving_per_dim(outer, body, outer.work, body.span, composed_span)
let composed_certainty = meet_pair(work_cert, span_cert)
```

certainty_of_surviving_per_dim is generalized to take per-dimension
inputs (outer's contribution to this dimension, body's contribution,
the composed dimension result) and walks dominance specifically on that
dimension.

Updates:
- §3.1 compose_summary_iterate: per-dimension certainty composition
  with explicit work + span tracking.
- §3.1 certainty_of_surviving renamed to certainty_of_surviving_per_dim;
  signature parameterized over dimension.
- §3.1 compose_summary_sequential / compose_summary_branch comments
  updated to name the per-dimension pattern.
- §1.5 (Why no BoundedLattice<Certainty>): updated to reference
  certainty_of_surviving_per_dim and per-dimension composition.

Faithful certainty composition restored across all published dimensions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration — lens body MUST change to read inhabitance, not signature shape

Cursor BLOCKING on PR #1488 sha 96899484 line 17: the doc moved effect
KIND authority to algebra inhabitance (per §2.4 + §8.1) but the
implementation plan asserted "the lens body does not change. callable_
arrow_effect already implements §2.4's rule" (line 373) + listed the
lens fold body in the NOT-modify list (line 479) + size estimate said
"lens-fold itself is unchanged" (line 494). But callable_arrow_effect
TODAY derives effect kind from signature/body shape — if the body
stays unchanged, it does NOT consume the new inhabits IdempotentRead<R>
/ inhabits Mutating<R> facts. Facts-flow-forward / P2 violation: new
substrate authority not consumed by downstream.

Resolution: the lens body MUST change in its kind-classification
dispatch. Specifically:
- The fold STRUCTURE (per-callable walk + report aggregation) is
  unchanged.
- The per-callable kind classifier IS rewritten — from signature/body
  shape inference to algebra-inhabitance lookup
  (callable_inhabits(callable, idempotent_read_for(resource)) /
  callable_inhabits(callable, mutating_for(resource))).

Updates:
- §6.2 first reason: lens body framing flipped from "does not change"
  to "changes only in its kind-classification dispatch", with explicit
  rationale citing this BLOCKING.
- §9 NOT-modify list: lens fold STRUCTURE preserved; per-callable kind
  classifier explicitly listed as modified (with cross-reference).
- §9 size estimate: "lens-fold itself is unchanged" → "lens-fold
  structure is unchanged; per-callable kind classifier rewrite is S".
- §10 implementation order: NEW step 5 ("Lens kind-classifier
  rewrite") inserted between OperationEffect retirement (step 4) and
  cementing test (now step 6). Total steps 6 → 7; steps-summary
  paragraph updated.

Facts-flow-forward restored across the full migration: new inhabitance
authority lands → lens classifier reads it → effect kind facts flow
into ReadShaped / WriteShaped lens output.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add lens_enforcement_carrier_landed to r3-structure lane gates

gpt-5-5-pro REQUEST_CHANGES on PR #1488 sha 85a6bb0e (BLOCKING #3):
design-lens-application-surface §10 step 1 declared lens_enforcement_
carrier_landed as a closure gate, but the r3-structure.md lane summary
(lines 40 + 148) omitted it from the authoritative gate list. Per
"tracked vs untracked debt" discipline: a named substrate carrier
(LensEnforcement<Output, Budget>) without a tracked landing gate in the
roadmap leaves new substrate work outside the closure-receipt mechanism.

Resolution: add lens_enforcement_carrier_landed to both lane-summary
gate lists (line 40 + line 148) with explanatory note that it covers
the per-lens projection + violation-relation declarations co-located
with each lens.

(BLOCKINGs #1 + #2 from same review wave at sha 85a6bb0e are already
addressed at e554f85e6 — LensEnforcement carries both project AND
violates per-lens violation relation; substrate authority for
budget-exceeded check is structural, not API-level.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §8.5 implementation note — read EnforcedApplication.budget, not config.budget

Codex BLOCKING on PR #1488 sha a525baf0: §8.5 still pointed implementers
at `config.budget`, but the per-variant split at 968994843 dissolved
ApplicationConfig — budget now lives on EnforcedApplication<Output,
Budget> inside the Enforce variant of SectionedLensApplication.
Stale implementation guidance pointing at non-existent authority. P2
violation.

Fixed: §8.5 now describes the lens-fold matching on
Enforce(EnforcedApplication { budget, ... }) and the Introspect case
(no budget).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration lens body reads signature directly, not via LensEnforcement

Cursor BLOCKING on PR #1488 sha c41b8ce8 line 373: my §6.2 fix said
the new effect_enumeration lens body "reads enforcement.project for
the effect set". But LensEnforcement is the lens-application-surface
budget-projection carrier (T-Lens-Application-Surface lane). The
effect-enumeration lens body is part of T-Lens-Behavioral-Parity
slice 4 — which CASCADES into T-Lens-Application-Surface (the latter
gates on the former being COMPLETE). Reading enforcement.project from
the lens body inverts the cascade AND gives the effect-set fact a
second authority (signature-derived per §2.4(a) vs LensEnforcement
projection).

Resolution: lens body reads effect set DIRECTLY from the callable's
arrow signature (existing substrate query — resource types in
input ∩ output, per §2.4(a)). Kind classification reads
callable_inhabits(...) per §2.4(b). Both queries are within
T-Lens-Behavioral-Parity slice 4 scope; neither depends on
LensEnforcement.

Updated §6.2 line 373 to:
- Replace "reads enforcement.project for the effect set" with "reads
  the effect set directly from the callable's arrow signature
  (existing substrate query; structurally derivable per §2.4(a)
  without any lens-application-surface artifact)".
- Add explicit "neither depends on LensEnforcement from T-Lens-
  Application-Surface (cascade flows the other direction)".

Cascade direction preserved: T-Lens-Behavioral-Parity COMPLETE →
T-Lens-Application-Surface, not vice versa. Effect-set fact has single
authority (signature query); kind fact has single authority (algebra
inhabitance). No lens-application carriers consumed by lens body.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): per-coordinate certainty on ComplexitySummary (no global collapse)

Codex BLOCKING on PR #1488 sha 75a6ab57: §3.1 computed independent
work_cert and span_cert per-dimension, then immediately collapsed them
into one global ComplexitySummary.certainty via meet_pair. That
collapse loses the per-dimension proof-tightness fact: if work is
Proven but span is Conservative (or vice versa), downstream
display/enforcement consumers see only "globally Conservative" and
cannot know the work bound was proven. P1 modeling faithfulness +
P2 facts-flow-forward violation: the certainty fact each dimension
carries gets fused into ambiguity.

Resolution: ComplexitySummary now carries per-coordinate certainty —
work_certainty and span_certainty as independent fields. No global
certainty field; no meet across dimensions. Each coordinate's certainty
stays on that coordinate through composition.

```dag
type ComplexitySummary {
  work: SymbolicCost
  span: SymbolicCost
  asymptotic_class: AsymptoticClass
  work_certainty: Certainty       // per-coordinate per BLOCKING fix
  span_certainty: Certainty
}
```

Updates:
- §1.7 ComplexitySummary declaration: split certainty into work_certainty
  + span_certainty with explicit rationale citing this BLOCKING.
- §3 ComplexitySummary declaration in lens body section: same split.
- §3 outer Loop construction: outer.span = outer.work, so both
  certainties = bound_cert.
- §3.1 compose_summary_iterate: drop the global meet across dimensions;
  work_certainty := work_cert, span_certainty := span_cert independently.
- §3.1 certainty_of_surviving_per_dim signature: takes per-dimension
  certainty inputs (outer_cert, body_cert) explicitly; no global
  outer.certainty / body.certainty lookup.
- §3.1 compose_summary_sequential / compose_summary_branch comments:
  pattern updated to "no meet across dimensions; per-coordinate
  independence preserved on output".

asymptotic_class is still a projection of work; its certainty is
work_certainty (no separate class_certainty since the class is derived,
not independent). All facts faithful to the dimension they qualify.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align lens-application doc with per-coordinate certainty (work_certainty / span_certainty)

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 sha 37f3bc62: lens-
application-surface lines 125 + 152 still described ComplexitySummary
with a single `certainty` field, but my fix at 955cafe2c split certainty
into per-coordinate work_certainty + span_certainty in the complexity-
lens design. Sibling-doc mismatch — same carrier shape described two
ways across two design docs in the same PR.

Updated lines 125 + 152 to match complexity-lens §1.7's per-coordinate
shape:
- Line 125 inline comment: "rich output: work/span/asymptotic_class/
  work_certainty/span_certainty".
- Line 152 narrative: "rich (ComplexitySummary { work, span,
  asymptotic_class, work_certainty, span_certainty } — per complexity-
  lens §1.7, certainty is per-coordinate to avoid collapsing per-
  dimension proof-tightness facts)".
- "Forcing output = budget would drop work/span/certainty facts" →
  "drop work/span/per-coordinate-certainty facts".

Cross-doc carrier-shape consistency restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): codex BLOCKINGs #1-3 (sha 37f3bc62) — substrate assumptions aligned with v3 reality

3 BLOCKINGs at sha 37f3bc62, all claiming docs lock substrate assumptions
v3 cannot currently express:

BLOCKING #1 (cost-lens SizeVariable label): doc said renderer reads via
intern_table::name_of(port_id). Verified: src/v3/std/algebra.dag:143
explicitly says "InternTable lookup the lens doesn't yet run". v3 has
some InternTable machinery (PR #367 Phase 1) but the port-id-to-name
query is NOT landed. Cannot assume it.

Resolution: re-introduce SizeVariable.display_name: String? as the single
substrate authority for the user-facing name. No InternTable lookup
assumed. Field is single-source (not parallel with anything); parser
populates from authored binding names where present, None for inferred.
Earlier "parallel authority" concern (gpt-5-5-pro at ef21e1a0) doesn't
apply because there's no second source — InternTable lookup isn't
landed and isn't claimed.

BLOCKING #2 (per-variant generics): doc declared
SectionedLensApplication = Enforce<Output, Budget>(...) | Introspect<
Output>(...) — but v3 .dag sums use uniform type parameters across
variants (e.g., Lookup<C> = Miss | Hit(C); both share C). Per-variant
parameter binding / existential packaging not currently supported.

Resolution: drop the SectionedLensApplication SUM. Use TWO SEPARATE
top-level carriers — EnforcedApplication<Output, Budget> and
IntrospectApplication<Output>. Lens-fold pass walks two separate lists
and emits Diagnostics from Enforce walks, records values from Introspect
walks. No per-variant generics required. Each lens application in .dag
source is one or the other; user authoring chooses at apply_lens site.

BLOCKING #3 (TestPredicate maturity): doc said "Today's TestPredicate
coproduct covers 22 variants" listed by name, treating them as
uniformly-live substrate. Per verification.dag inline annotations,
many are 🟡 Scaffold with named dissolution triggers (ExecuteCommand,
ForAllTargets, LensOutputEquals, DifferentialEquals,
BinaryDimensionReportEquals, AlgebraicLaw, ReleaseDeferredClaim,
SubstrateResearchDeferredClaim).

Resolution: §1 explicitly disclose 🟢 TERMINAL vs 🟡 Scaffold partition;
note that ports landing on Scaffold variants are inherently scoped by
that variant's named dissolution trigger; new-carrier residual is in
scope of T-Tests-As-Data-Completeness, not assumed live.

Updates:
- design-cost-lens §1.2: SizeVariable.display_name reintroduced as single
  authority; revert §1.4 from renderer-only to additive field; both wave
  reviews now reconciled.
- design-lens-application-surface §2: SectionedLensApplication sum
  removed; two top-level carriers (EnforcedApplication +
  IntrospectApplication). Downstream §3 + §4 + §5 + §6 + §8.5 + §9 +
  §10 references updated to "two separate top-level carriers" framing.
- design-tests-as-data §1: TestPredicate maturity disclosure (TERMINAL
  vs Scaffold partition with named dissolution triggers per
  verification.dag inline annotations).
- design-r3-lens-substrate-index: substrate-authority table updated to
  drop "sum" and list two separate carriers.

All three BLOCKINGs reflect the constraint: design docs cannot assume
substrate facilities not yet landed, and cannot use shapes v3 cannot
currently express.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cementing test asserts per-coordinate certainty (work + span), not collapsed

Codex BLOCKING on PR #1488 sha e3010014: §1.7 changed ComplexitySummary
to per-coordinate work_certainty + span_certainty (closing the global-
collapse bug at PR #1488 / 955cafe2c), but §4.1 cementing test still
asserted a single global v3.certainty. Internally inconsistent: closure
gate would not validate the per-coordinate claim §1.7 makes; the test
would either pass on a v3 that secretl…
briansrls added a commit that referenced this pull request May 2, 2026
…+ EnforceableLens uniqueness (#1500)

* docs(roadmap): fold 2026-05-01 paired exploratory + reflective analyses

Director relayed two analyses against current main:
- Exploratory (gpt-5-5-pro main@8cd5359): 9 findings against
  dsl/std/*.dag, src/v2/tests/src/*.rs, dsl/extdeps/, THESIS,
  INVARIANTS, MODELING, ROADMAP — 2 novel correctness bugs
  (SymbolicCost semiring violation, emitter expect() panic paths),
  3 sharpened tracked items (SubValueRelation lattice-law
  contradiction, ?? / % syntax-parser drift, CollectionOps/StringOps/
  MapOps duplicates), 4 already-tracked items
- Reflective (gpt-5-5-pro main@6ea9812 → now): 5 cross-PR patterns
  + 6 highest-priority course corrections + verdict "advancing,
  scaffold-velocity dominates"

PM ingestion folds into single ROADMAP debt section per Director's
prior 2026-04-30 analyses ingestion pattern (PR #1319). Sections:

- A: Exploratory novel correctness bugs (SymbolicCost product-zero
     bug, SubValueRelation BoundedLattice claim violation, emitter
     expect panic paths)
- B: Exploratory sharpened tracked items (?? / % drift,
     CollectionOps/StringOps/MapOps duplicates)
- C: Exploratory already-tracked confirmations (no new ROADMAP rows)
- D: Reflective 5 cross-PR patterns (author-now/fire-later, test_
     runner.rs second predicate language, typed-carrier-Rust-mirror
     accumulation, numeric philosophy mid-window shift validating
     T-Numeric-Construction reframe, bridge retirement tracked-not-
     retired)
- E: Reflective 6 highest-priority course corrections with owner
     attribution + lane connection table
- F: CI cost signal (e765c86a 60min timeout) + velocity-tripwire
     calibration (64 docs / 16 feat / 9 fix ratio)
- G: PM strategic synthesis: 3 cross-cutting meta-themes
     (algebraic-law-witness coverage gap; "make scaffolds executable"
     cluster; "tighten existing structural enforcement" cluster)

Per-finding/correction owner attribution names R3 Substrate Mgr,
R3 Verification Mgr, R3 Grounding Mgr, R3 PB Mgr per ownership
boundaries. Lane connections cite T-V-L4-L7-Direct, T-Free-
Consequences-Demonstration, T-Ground-Services parser-grammar slice,
T-Numeric-Construction Slice 2 sequencing, etc.

Highest-value novel: SymbolicCost product-zero bug (cost-lens reads
incorrect facts; iterate(ConstantCost(0), ...) returns body cost
instead of zero) + emitter expect() panics. Highest-value
sharpened-tracked: SubValueRelation BoundedLattice false-claim.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): R3 scope expansion 12 → 16 lanes + standing R3 Debt-Paydown program

Per Director ratification 2026-05-02 at gunbc#828 comment 4362742638:

User directive: per the strict reading of "nothing deferred past R3", all
"accidentally deferred" gaps absorb into R3. Plus three additional asks:
behavioral expectations docs per feature; compile-error complexity ratchet
generalized as lens-application-surface (per user reframe); in-cycle
debt-paydown discipline.

NEW R3 LANES (4 added; lane count 12 → 16):
  13. T-E-P-Producer-Broadening (Substrate; M-L; foundational)
      - broaden per-call DescentEvidence/CallPattern/SubValueRelation
        from first slice to full ExprCall.descent_evidence parity
      - prerequisite for T-Lens-Behavioral-Parity

  14. T-Lens-Behavioral-Parity (Substrate + Verification cross-program; L-XL)
      - 4 sub-slices: complexity / cost / parallelism / effect_enumeration
      - bring lens-capability-register from PROXY/STUB/PARTIAL → COMPLETE
      - includes symbolic CostExpr full algebra; work/span split;
        asymptotic classification; cementing test against v2 oracle;
        Stage 2e parallelism walk port; resource-threading migration

  15. T-Tests-As-Data-Completeness (Verification; L)
      - tests-as-data full coverage (thesis facet 3)
      - property-based testing surface (ForAll/Exists quantifiers +
        ProgramGenerator carrier)
      - cementing test discipline for .dag lenses

  16. T-Lens-Application-Surface (Substrate + Verification; L-XL)
      - per user reframe: lens application as first-class authoring surface
      - apply_lens(lens, section, config) where config.violation_policy =
        CompileError | Warning | Silent
      - subsumes prior T-Complexity-Contract-Compile-Error +
        T-User-Authored-Cost-Basis-Discipline as configurations
      - 4 worked examples: complexity-contract-compile-error + CRDT cost
        basis + memory-peak cost basis + opt-in cross-iteration parallelism
      - default policy for complexity contract: opt-out

NEW STANDING PROGRAM:
  R3 Debt-Paydown Manager (9th standing R3 Mgr)
  - hybrid mechanism: per-PR debt-receipt rule + standing capacity
  - closure gate: r3_debt_paydown_zero_remaining
  - per feedback_standing_managers_need_owned_deliverables

FOLD-INS (3; no new lanes):
  - T-V-L4-L7-Direct: per-(algebra, inhabitant, law) exhaustive witness
    coverage (catches SymbolicCost product-zero bug class structurally)
  - T-Ground-Diagnostic: closed-axis enforcement (no String dispatch on
    closed sets); replaces MissingEmissionPath { connective: String, ... }
  - T-LensProducer-Retirement: ownership d/e/f confirmed delivered (not
    separately deferred)

T-Behavioral-Expectations-Documentation (parallel-dispatchable; 7 load-
bearing features per Director ratification): lens framework + 4 lens
instances + complexity contract + cross-target consistency.

Updates to docs/r3-structure.md:
  - §Summary: 12 lanes + 1 standing program → 16 lanes + 1 standing
    program
  - §Lane structure: 4 new rows
  - §Manager structure: 8 → 9 standing managers; 3 → 4 modifications
  - NEW §Standing program — R3 Debt-Paydown section authored
  - T-Numeric-Construction lane row updated to 13 types in scope (was 8;
    per 2026-05-02 PM audit + Substrate Mgr ack)

R3 scope ratchet: ~58% (over current 12-lane denominator) → ~38% (over
expanded 17-lane denominator); numerator unchanged. Honest timeline
projection: R3 close in 5-8 weeks at current velocity.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Numeric-Construction row — 8-type → 13-type scope citation + traceability

Director callout on PR #1480: §Summary item 6 says 13 types in scope but
§Lane structure table row 138 still said 8. Internal inconsistency.

Fix: §Lane structure table row 138 updated to 13 types in scope, with
explicit citation chain:
  - original 8-type count from PR #1430 §A audit
  - extended to 13 after fresh PM sweep found 5 additional Int-inherited
    refinement types (RetryCount / HttpStatus / Port / PositiveInt /
    NonNegativeInt) at dsl/std/types.dag:232-245
  - Substrate Mgr ack at gunbc#1130 comment 4360482400

Includes: Nat-alignment opportunity flagged (NonNegativeInt → Nat,
PositiveInt → Nat where range(min: 1)), cost-lens candidates for
bounded-range types (RetryCount → Nat<3>, HttpStatus → Nat<10>,
Port → Nat<16>) once refinement composition lands.

Per Director recommendation: brief addendum documenting the audit so
lane scope stays anchored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address PR #1480 cursor findings — §P5 mix-up + restored locked dispositions

Fixes 3 cursor findings on PR #1480 (sha 0f32605d) plus 1 exploratory:

1. §P5(b)/(c) mix-up (line 44): "vague deferrals rejected" attributes to
   §P5(b) per-PR gate (the rule that actually rejects vague deferrals), not
   §P5(c) Velocity tripwire (windowed dispatch-pause). Now also explicitly
   surfaces §P5(c) as separate (b) windowed-enforcement clause.
2. Restored Post-R2 emergent work disposition on Substrate/PB continuation
   bullet (line 187): Director-locked 2026-04-28 — emergent post-R2 work
   absorbs into Substrate Manager continuation, not new managers.
3. Restored Verification scope negations on Verification Manager bullet
   (line 189): "L6 NOT in Verification scope" + "T-CostLens-Composition NOT
   in Verification scope" — both Director-locked 2026-04-28.
4. Updated stale "9 of 12" / "3 non-gated" counts in §"Dependency on R2"
   (lines 393, 397, 399, 400, 402) to "11 of 16" / "5 non-gated" matching
   line 59 Summary; added T-Lens-Behavioral-Parity + T-Lens-Application-Surface
   to Evaluator-gated list with cascade gate note.

All Director-locked 2026-04-28 dispositions tagged "carried forward through
2026-05-02 expansion" so the locks survive the lane-count change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): close P5 escape hatch in r3_debt_paydown_zero_remaining gate

Cursor BLOCKING finding on PR #1480 at docs/r3-structure.md:173: gate
contradicted itself by allowing "deferred-to-post-R3 with Director sign-off"
after stating "no tracked-debt rows survive R3 close", weakening P5/strict-
forward-progress into a disposition convention.

Fix: remove the deferral escape hatch entirely. Gate is unconditional —
every tracked-debt row retires with PR receipt before R3 close. Grounds
in user directive 2026-05-02: "all 'accidentally deferred to post R3' into
R3 now". If a row appears unretirable, it surfaces as a substrate gap
requiring a named R3 lane (the directive that motivated this manager's
creation), not a Director-sign-off deferral.

Cites INVARIANTS §P5 directly: tracked-debt deferred past R3 close is the
bridge-as-steady-state pattern P5 explicitly forbids; the escape hatch
reintroduced that pattern at lower cadence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): reconcile T-Tests-As-Data-Completeness Evaluator-gating contradiction

gpt-5-5-pro REQUEST_CHANGES finding on PR #1480 (sha 0f32605d): line 59
summary said T-Tests-As-Data-Completeness is in the "5 self-contained
non-Evaluator-gated" group, but lane table at line 147 lists its dependency
as "R2-Evaluator (test execution runtime)". Schedulers got two incompatible
authorities (P2 single-authority violation).

Lane table is correct — porting Rust tests to .dag TestClaim requires the
Evaluator to execute the resulting test artifacts. Updated:

- Line 59 summary: 11 → 12 Evaluator-gated; 5 → 4 non-gated; T-Tests-As-
  Data-Completeness moved into Evaluator-gated list with reason
- Line 393 (Dependency on R2): same reclassification
- Line 395 (substrate-carrier-fed list): drop T-Tests-As-Data-Completeness
- Line 399 (precondition applies-to list): 11 → 12 lanes
- Line 400 (carve-out): 5 → 4 lanes; drop T-Tests-As-Data-Completeness
- Line 402 (split-resolution sentence): 11 → 12, 5 → 4

(Findings #2 and #3 already addressed at 0c449a869 and 0de2bda06
respectively.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): T-Lens-Application-Surface design doc — substrate shape + 4 worked examples

Per user directive 2026-05-02 ("all designs upfront, implementation sketches
if needed, minimize escalations"), authoring foundational design doc that
unblocks T-Lens-Application-Surface lane dispatch.

Resolves design questions:

1. **Section reference shape**: `SectionRef = DeclarationScope { DeclarationId }
   | NodeScope { DeclarationId, NodeId }`. Three of four user-named scopes
   (function / module / declaration) use DeclarationId uniformly; expression
   scope is the exception (NodeId required because expressions live inside
   Declaration body sub-DAGs).

2. **Violation-policy semantics**: user-named `CompileError | Warning | Silent`
   resolved to fail-closed-compatible binary `Enforce | Introspect` per
   INVARIANTS C-8. Warning forbidden (allows violations as steady state,
   bridge pattern P5 forbids); Silent forbidden ("silent None" exactly the
   pattern feedback_fail_closed_discipline bans).

3. **Default complexity-contract policy**: opt-out (compiler enforces;
   explicit waiver required). Waiver shape is structural `ComplexityBudgetWaiver`
   declaration with `justification` field, NOT an annotation per
   feedback_no_annotations.

4. **4 worked examples** ratified by Director (complexity-contract /
   CRDT cost / memory-peak cost / opt-in parallelism) — each grounded in
   substrate carriers + lens-fold integration.

5. **5 open design questions** flagged for Director ratification before
   substrate authoring begins (module-level semantics, multiple-applications-
   per-section, budget-inference for default, waiver dissolution, cross-section
   composition).

Updates r3-structure.md lane 16 row to reference the design doc, replace the
@complexity_budget_waived annotation language with structural carrier name,
and replace the original `CompileError | Warning | Silent` enum with the
fail-closed-resolved Enforce/Introspect binary.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve all 5 §8 open design questions in-doc per minimize-escalations directive

Per user directive 2026-05-02 ("minimize escalations"), resolved the 5 open
design questions that were flagged for Director ratification:

§8.1 — Module-level semantics: aggregate-across-module (preserves
      structural distinction between module-scope and per-function-scope).
§8.2 — Multiple applications: fail-closed reject duplicate (lens, section)
      Enforce-mode pairs; multiple Introspect admitted (idempotent).
§8.3 — Default-application budget: regression-detection class, gated on
      T-Lens-Behavioral-Parity COMPLETE; pre-cascade Introspect-only.
§8.4 — Waiver lifecycle: future lens_stale_waivers lens with named
      dissolution trigger; tracked in lens-library-design.md §6.
§8.5 — Cross-section composition: read declared budget, not computed
      class (preserves abstraction barrier; cost-of-change=1).

Each resolution carries explicit reasoning grounded in INVARIANTS P2/P5
+ feedback memory. Implementation can proceed once cascade gates clear
(T-Lens-Behavioral-Parity COMPLETE for §8.3 flip; R2-Evaluator landed for
worker dispatch precondition). No further Director ratification needed
on these specific points.

r3-structure.md row 16 updated to reflect the design-doc resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): cross-design coherence pass + master design index

Coherence audit across the 5 design docs identified 5 cross-doc conflicts;
this commit resolves all 5 and lands the master index linking them.

Fixes:

1. **Producer-query single-authority** (P2): complexity-lens §2 + cost-lens
   §3.2 now both reference `per_call_pattern_at(d, call_site) -> CallPattern?`
   as the typed query surface (single authority); the underlying
   `per_call_descent_evidence` side-table is named as the storage backend
   only. Eliminates parallel-authority risk.

2. **Cementing-test shape unified** (DB-15): cost-lens §5 reshaped from
   custom `ForAll { p: SourceProgram in programs }` (which violated tests-
   as-data §2.5 — quantifiers belong on claims, not predicates) to
   `QuantifiedTestClaim { generator, quantifier: ForAll, predicate:
   DifferentialEquals }`. Now matches complexity-lens §4 and tests-as-data
   §2.2 shape.

3. **DB-18 element-type-refinement cross-reference**: effect-enumeration §4.1
   now explicitly states that DB-18's STOP-AND-ESCALATE locks the
   `WorkflowEffect` variant set + variant payload shape, not element-type
   within `LinearEffect.ops: List<X>`. The `OperationEffect` →
   `Operation` retypes is additive tightening within DB-18's permitted
   refinement scope.

4. **Resource-threaded signature compatibility**: cost-lens §3.3 now
   explicitly notes that `per_call_pattern_at` reads from threaded arrow
   signatures (per effect-enumeration §2.4) — signature-shape-agnostic
   producer; broadening covers both pre-migration and post-migration
   signature shapes.

5. **TestClaim shape for lens-application demonstrations**: lens-application
   §4 now declares all 4 worked-example closure gates use `TestClaim`
   (DB-15 enumerated form), not `QuantifiedTestClaim`. Property tests over
   the lens-application substrate live in T-Tests-As-Data scope, not
   T-Lens-Application-Surface scope.

6. **Register-migration sequencing**: tests-as-data §8.3 now lists the 4
   sibling lens design docs whose register-row "→ COMPLETE" closure steps
   depend on the markdown→.dag migration landing first (substrate work in
   sibling lanes does NOT depend; only the closure-gate row update does).

Plus: NEW `docs/design-r3-lens-substrate-index.md` — master index linking
all 5 design docs, documenting cross-doc edges (substrate authority
single-points + cementing-test format + cross-cutting invariants), and
naming lane dispatch order.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): address 4 cursor findings on PR #1480 (sha 16340c52)

1. **Lane 16 row 40 stale text vs row 148 resolved** (P2 single-authority):
   row 40 still carried the original `CompileError | Warning | Silent`
   enum + `@complexity_budget_waived` annotation language; row 148 had
   the resolved `ViolationPolicy = Enforce | Introspect` + structural
   `ComplexityBudgetWaiver` carrier. Updated row 40 to match the
   resolved story (single authority).

2. **Line 44 duplicate (b) and (c) labels**: the Hybrid mechanism outer
   enumeration used (a)/(b)/(c) but referenced INVARIANTS §P5 sub-
   mechanisms (a)/(b)/(c) inside; same letter labels at different
   levels confused parsing. Renamed outer enumeration to (1)/(2)/(3)
   with footnote explaining the distinction.

3. **Line 175 contradicts line 173** (P5): line 175 said "Does enforce:
   tracked-debt rows get retirement PRs or explicit deferral" — the
   "or explicit deferral" reads like deferral remains an outcome,
   contradicting line 173's unconditional "no post-R3 deferral path".
   Removed the deferral language; line 175 now restates the unconditional
   rule + names the substrate-gap escalation path.

4. **design-complexity-lens-behavioral-completeness.md:125-127 variant-
   count mismatch** (P1 self-faithfulness): comment said "closed
   seven-variant set" / "Adding an eighth variant" but `AsymptoticClass`
   enumerates 8 variants (ClassConstant/Log/Linear/Linearithmic/
   Quadratic/Polynomial/Exponential/Unknown). Updated comment to
   "eight-variant" / "ninth".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): retract cost-lens parallel SizeExpr proposal — align with complexity-lens single authority

Cursor BLOCKING finding on PR #1480: cost-lens proposed a new SizeExpr
5-variant coproduct as authority, while complexity-lens proposed
SizeVariable.display_name enrichment for the same SymbolicCost payloads.
P2/P5 violation — same substrate fact, two incompatible target shapes.

Resolution: complexity-lens has the structurally correct framing.
- DB-7's SymbolicCost is the unified algebra (locked).
- SymbolicCost already covers SizeAdd (via SumCost) and SizeMax (via
  dominance ordering) — no parallel SizeExpr algebra needed.
- Descent semantics like "n - 1" live in std.computation::CallPattern
  (the canonical E-C site), not in size expressions. A SizeShrink
  variant would duplicate that fact in parallel.
- Asymptotically O(n - 1) ≡ O(n); descent is a call-site property,
  not a size-shape property.

Aligned cost-lens to complexity-lens: SizeVariable gains an optional
display_name: String? field; no parallel SizeExpr carrier; SymbolicCost
DB-7 lock preserved unchanged.

Updated:
- §1.1 problem framing — drop "size arithmetic" / "aggregate sizes"
  framing (already covered by SymbolicCost); keep only the
  "named-binding semantics" gap that motivates display_name.
- §1.2 target shape — SizeVariable.display_name: String? (matches
  complexity-lens §1.2 verbatim).
- §1.3 explicit rationale for unified-algebra over parallel-SizeExpr.
- §1.4 migration shape — additive field, no carrier rename, no deletion.
- §3 / §5 code examples — replaced SizePort with SizeVariable shape.
- §8.1 resolved-question reframe — names the rejected alternative
  (parallel SizeExpr) for future readers.
- §8.2 names-on-carrier resolution — display_name shape per §1.2.
- §10 implementation step 1 closure gate renamed
  size_expr_substrate_landed → sizevariable_displayname_landed.

P2 single-authority restored across the 5-doc design surface.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration — read/write distinction via algebra inhabitance, not signature shape

Cursor BLOCKING finding on PR #1480 at design-effect-enumeration-resource-
threading.md:151: the design's "structural recognition" claim was actually
convention-level. \`R in / R out\` and \`R in / R' out\` (same type, different
value) have the SAME typed signature — \`.dag\` doesn't encode value-
preservation as a substrate fact. ReadShaped vs WriteShaped via signature
shape alone was P1 modeling-faithfulness violation.

Resolution: split the unified rule into two structural carriers per §2.4:

(a) Effect SET — derived from signature: resource types in input ∩ output.
    Structural; the signature carries it.

(b) Effect KIND — declared via algebra inhabitance on the callable:
    \`inhabits IdempotentRead<R>\` (read), \`inhabits Mutating<R>\` (write),
    \`inhabits Append<R>\` (append). Structural; the inhabitance carrier
    captures it.

The lens consults BOTH — signature for set, inhabitance for kind. Absence
of any kind inhabitance with the resource in the effect set is a fail-
closed Diagnostic (EffectKindUndeclared), not a silent default.

Updates:
- §2.1 line 151: replace "same-value vs modified" framing with explicit
  effect-set-vs-effect-kind distinction; cross-link to §2.4 + §8.1.
- §2.3: same fix for Network read example.
- §2.4: split the unified rule into (a) effect SET (signature) + (b)
  effect KIND (algebra inhabitance) with pseudocode for the lens-side
  classification.
- §4.3: update EffectShape derivation source from "signature shape" to
  "algebra inhabitance lookup".
- §8.1: full reframe — from "same-value resolved" to "algebra inhabitance
  is the structural authority", with explicit rationale (per-callable
  authority, not per-call; rejected phantom-marker alternative per
  feedback_no_annotations).
- §3 lens fold pseudocode: dispatch on §2.4(a) for set + §2.4(b) for kind.

Preserves the existing EffectShape = IsIdempotent | IsBreaking partition
(per design-composed-effect-reshape.md PR #529 R3) — only the source of
the shape changes (declared inhabitance, not derived from signature).

P1 modeling-faithfulness restored. Cursor finding fully resolved.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): lens-application — collapse ApplicationConfig into sum-type, illegal states unrepresentable

Cursor BLOCKING finding on PR #1480 at design-lens-application-surface.md:43:
ApplicationConfig was a record with budget: LensBudget? + violation_policy:
ViolationPolicy as separate fields. This admitted illegal state combinations:
- Enforce + budget=None (illegal: enforcement requires a budget)
- Introspect + budget=Some(_) (illegal: introspection takes no budget)

The doc explicitly noted these as type-checker-enforced invariants (lines
136-137), but per feedback_state_space_vs_behavioral_invariants those are
behavioral invariants, not state-space invariants — exactly the bug pattern
modeling-discipline principles 2/6 prohibit. Illegal states must be
unrepresentable at the type level.

Resolution: collapse ApplicationConfig and ViolationPolicy into a single
sum-type that pairs budget with Enforce by construction:

```dag
type ApplicationConfig
  = Enforce { budget: LensBudget, diagnostic_severity: DiagnosticSeverity }
  | Introspect
```

By construction:
- Enforce ALWAYS has a budget (it's a coordinate of the variant).
- Introspect NEVER has a budget (it has no payload).

The "Enforce without budget" and "Introspect with budget" combinations
cannot be constructed; the type-checker has no rejection rule to enforce
them — they don't exist in the state space.

Updates:
- §2: replaced ApplicationConfig record + ViolationPolicy sum with single
  ApplicationConfig sum carrying budget inside Enforce variant.
- §3: rewrote framing to match — the binary Enforce/Introspect is the
  ApplicationConfig sum itself; budget pairing is structural.
- §4: all 4 worked-example syntaxes updated to `Enforce { budget,
  diagnostic_severity }` directly (no separate violation_policy field).
- §5.1: synthesized default-application uses `Enforce { budget: <inferred>,
  diagnostic_severity: Error }` shape.
- §3.2: explicit-introspection override syntax `apply_lens(complexity, fn,
  Introspect)` (no separate budget=None).
- r3-structure.md rows 40 + 148: updated substrate-carrier description to
  name ApplicationConfig as sum-type with the structural-invariance note.

Modeling principles 2/6 honored. P1 modeling-faithfulness restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): codex non-blocking findings #2 + #3 — heading/count consistency

Codex review on PR #1480 sha 58f49e91 noted two non-blocking inconsistencies:

NB2: design-cost-lens-sizevar-dimension-wiring.md §4.2 heading said
'CommutativeSemiring<SymbolicCost>' but §8.5 resolves to 'Semiring<SymbolicCost>'
(multiplicative side does NOT enforce commutativity per §8.5 reasoning).
Fixed §4.2 heading to match §8.5 resolution.

NB3: design-tests-as-data-completeness.md §3.1 said 'six classes' /
'decomposes into six structural classes' but §10 step 3 enumerates C1-C7
(seven classes). Fixed §3.1 to say 'seven classes' with explicit C1-C7
cross-reference.

Both load-bearing for doc-as-authority discipline (P1 modeling-faithfulness
of the spec to itself).

(All 4 BLOCKING findings from same review at sha 58f49e91 are already
addressed at earlier commits — see PR comment for the receipts:
ef21e1a00 / 92d9b11cf / 255cca3cb / 8640e6701.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix line 199 active-surface arithmetic + line 23 exploratory clarity

Cursor APPROVE_WITH_COMMENTS finding on PR #1480 sha 92d9b11c:

**Main finding (line 199)**: arithmetic was internally inconsistent —
"expanded from 13 active surfaces" + "4 new lanes + 1 new standing program"
= 18, not 17. The baseline should have been 12 (12 lanes + 0 standing
programs at the 2026-04-30 lock), making 12 + 5 = 17 consistent. Fixed by
restating the baseline as 12 with explicit arithmetic: 4 new lanes
(enumerated by name) + 1 new standing program = +5; 12 + 5 = 17.

Also pinned T-Behavioral-Expectations-Documentation explicitly as
"parallel-dispatchable across existing lanes, not a separate surface" so
readers don't double-count it as a 5th new lane.

**Exploratory finding (line 23)**: the "added..." list mixed 4 new lanes
+ T-Behavioral-Expectations-Documentation (not a separate lane) + standing
program in one breath. Restructured the parenthetical to enumerate the 4
new lanes by name and call out T-Behavioral-Expectations-Documentation as
parallel-dispatchable explicitly. Reader can no longer mis-count.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop SizeVariable.display_name; InternTable single-authority for size names

gpt-5-5-pro REQUEST_CHANGES on PR #1480 sha ef21e1a0 — BLOCKING #3 + #4:

BLOCKING #3: SizeVariable.display_name + intern_table::name_of(source_port)
created TWO authorities for the user-facing size-variable name. The §8.2
implementation note confirmed the parallel: "when display_name = Some(name),
renderer uses it directly; when None, falls back to InternTable lookup".
P2 single-authority violation; consumers could diverge on the same source_port.

BLOCKING #4: master index design-r3-lens-substrate-index.md still claimed
SizeExpr replaces SizeVariable, but cost-lens design (post-ef21e1a00) had
already retracted SizeExpr in favor of unified SymbolicCost. Cross-doc
authority drift.

Resolution (both BLOCKINGs):
- Drop display_name field entirely from cost-lens + complexity-lens designs.
- SizeVariable substrate stays UNCHANGED at { source_port: PortId }.
- InternTable is the single canonical name authority — already populated
  at parse time keyed by port_id. Renderer reads via
  intern_table::name_of(source_port).
- The "Named SizeVar" gap from the capability register is closed by
  renderer-side wiring (no substrate change), not by adding a field.
- Master index updated: SizeVariable line replaces the old SizeExpr line;
  notes InternTable as name authority.

Updates:
- design-cost-lens §1.2: target shape removes display_name field from
  SizeVariable carrier; rationale rewritten as InternTable-as-single-authority.
- design-cost-lens §1.4 / §3 / §5 / §8.1 / §8.2: all display_name references
  scrubbed; "renderer-side InternTable name wiring" replaces "SizeVariable.
  display_name enrichment" throughout.
- design-cost-lens §10 step 1: closure gate renamed
  sizevariable_displayname_landed -> renderer_intern_table_name_wiring_landed.
- design-complexity-lens §1.2: same rewrite — SizeVariable carrier UNCHANGED;
  InternTable as name authority; explicit cross-link to cost-lens §1.2.
- design-complexity-lens §7.2: resolved-question reframe.
- design-r3-lens-substrate-index.md: SizeVariable line replaces SizeExpr line
  with InternTable-name-authority note.

P2 single-authority restored. Cross-doc consistency restored.

(BLOCKING #1 + #2 from same review at sha ef21e1a0 are already addressed
at earlier commits — see PR comment for receipts: 92d9b11cf + 255cca3cb.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): codex review wave (sha 98f2fc4f) — 4 BLOCKING + 2 NB findings addressed

BLOCKING #1: lens-application config not parametric in C — lens/budget pair
relied on type-checker convention rather than structural typing. Fix:
SectionedLensApplication<C> + ApplicationConfig<C> parametric in the lens
carrier C; lens: Lens<C> and config.budget: C share the same C
structurally. Mismatch is unrepresentable, not type-checker-rejected.
Per-lens budgets dissolve into the existing Lens<C> carrier — no separate
ComplexityBudget/CostBudget/ParallelismBudget carriers needed.

BLOCKING #2: complexity-lens Certainty composed independently from cost
dominance. Fix: define joint compose_summary function (§3.1) where
certainty composition is cost-aware — when dominance drops a cost
component, that component's certainty does NOT enter the result. Surfaces
v2's implicit Θ(n²) Proven semantics; cost-unaware certainty would diverge
from v2 on the cementing fixture corpus.

BLOCKING #3: effect-enumeration line 17 prose still claimed signature is
"one structural authority" for effects. Fix: updated to name the two
orthogonal authorities — signature for effect SET, algebra inhabitance
for effect KIND. Aligned with §2.4 + §8.1 that I'd already fixed at
92d9b11cf.

BLOCKING #4: sibling lens docs and tests-as-data didn't share one
cementing closure shape — complexity + effect proposed Rust cementing
tests, cost (after my earlier fix at ef21e1a00) proposed QuantifiedTestClaim.
Inconsistency. Fix: align all three on **Rust cementing today + dissolution
trigger to tests-as-data step 5 .dag port**. Per-lens divergence is now
explicitly forbidden in the master index.

NB1: cost-lens §1.4 still said "single field addition" / "Rust mirror
single field add" after the InternTable fix removed the field add. Cleaned
up to "renderer-only, no substrate change".

NB2: tests-as-data §3 said "17 variants" but enumerated 22 (Compiles ...
BridgeLedgerZero). Fixed count to 22.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): scrub residual non-parametric LensBudget references

Cursor BLOCKING at sha 98f2fc4f line 102 — incomplete fix for parametric
SectionedLensApplication<C> migration at 812f6a141. Three lines still
referenced the old non-parametric framing:

- Line 100: "type-checker verifies b inhabits lens.budget_type" — type-checker
  convention rather than structural typing.
- Line 114: ApplicationConfig redeclared without <C> parameter.
- Line 262: substrate-owner mention of "per-lens budget_type declaration
  extension".
- Line 351: "each lens owns its own LensBudget definition" — implied
  separate budget carriers.
- Line 357: implementation step said "Lens<C>.budget_type field added".

All updated to reflect the parametric resolution (per §2):
- ApplicationConfig<C> parametric in lens carrier C; lens/budget pair is
  structural via shared C.
- Mismatch is unrepresentable, NOT type-checker-rejected.
- No budget_type field on Lens<C>; the parameter C IS the structural
  authority.
- Each lens's existing Lens<C> carrier IS the budget type; no new
  per-lens budget carriers.

References to "budget_type" / "LensBudget" remain only in negation form
("not via budget_type field", "no LensBudget definition") to document the
rejected alternative for future readers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): lens-application — dissolve regression_baseline_pinned optional field

Cursor BLOCKING at sha 98f2fc4f line 323 (actually line 308 — drift after
prior edits): regression_baseline_pinned: AsymptoticClass? was an
optional field on SectionedLensApplication where absence = introspection
mode and presence = enforcement mode. This re-creates EXACTLY the
illegal-states-representable pattern that the §2 ApplicationConfig
sum-type fix dissolved (the original finding at design-lens-application-
surface.md:43 from a prior wave).

Fix: dissolve the optional field. The cascade-flip (T-Lens-Behavioral-
Parity COMPLETE flipping default complexity from Introspect to Enforce)
is purely SYNTHESIZER-side, not substrate-side:

- Pre-cascade: synthesizer emits `Introspect` for every default
  complexity application.
- Post-cascade: synthesizer emits `Enforce { budget: <computed class>,
  diagnostic_severity: Error }` — the computed class IS the regression
  baseline; the variant choice carries the fact structurally.

No optional field on the carrier. The cascade just changes which variant
the synthesizer constructs. Same illegal-states-unrepresentable
discipline as §2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): drop certainty_lattice — Certainty composition is cost-aware, not lattice-fold

Cursor BLOCKING at sha 98f2fc4f line 196: join_certainty's "Proven wins
under alternative" semantic was P1 unfaithful — a Proven branch arm could
hide a Conservative arm carrying the actual worst-case bound, so the
result's certainty would no longer faithfully describe the bound it
qualifies. Same cost-unaware pattern as the §3.1 BLOCKING from earlier
in the wave (composition independent from cost dominance).

Resolution: drop the BoundedLattice<Certainty> declaration entirely.
Certainty does NOT compose via lattice meet/join; composition is
cost-aware per §3.1 compose_summary_* family. The lattice declaration
was misleading — it suggested an independent composition pattern that
contradicts the cost-aware design.

Updates:
- §1.5: removed `data certainty_lattice` declaration + meet_certainty +
  join_certainty function bodies. Replaced with prose explaining
  cost-aware composition + tightness-ordering distinction (ordering is
  implicit when projecting; not a composition operation).
- §3.1: meet_certainty(...) call → meet_pair(...) inline helper, with
  explicit comment that it's used ONLY when both contributions survive
  cost composition (NOT a free-standing lattice op).
- §11 cascade-gate list: removed "data certainty_lattice" from the
  class-5-grammar dependent declarations list with explanatory note.

Same illegal-states-unrepresentable + cost-aware-composition discipline
preserved end-to-end across the §3.1 + §1.5 + §3.x compose_summary_*
chain.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration §8.4 — derive readonly deletion from algebra inhabitance, not signature shape

Cursor BLOCKING at sha 98f2fc4f line 442: §8.4 "readonly keyword deletion"
rationale said the keyword is "structurally derivable: an operation is
read-shaped iff every threaded resource appears unchanged in input and
output." This contradicts §2.4's locked rule that effect KIND is
declared only via algebra inhabitance (inhabits IdempotentRead<R>),
NOT derived from signature shape — same modeling-discipline violation
as the line 151 BLOCKING from the prior wave (cursor BLOCKING #2 of
this codex-wave).

Resolution: rewrite §8.4 to derive readonly's deletion rationale from
algebra inhabitance, not signature shape:

- After migration, read kind is declared via `inhabits IdempotentRead<R>`
  on the callable (per §2.4 + §8.1) — structural fact.
- The `readonly` keyword duplicates that inhabitance: same fact, two
  carriers. P2 single-authority + feedback_no_annotations forbid this.
- Keyword is redundant AND drift-prone (feedback_state_space_vs_
  behavioral_invariants: keyword could disagree with inhabitance).
- Implementation-mechanical: every operation currently using `readonly`
  already has a corresponding `inhabits IdempotentRead<R>` declared at
  the migration site (one-to-one mapping in the atomic PR per §6).

The §2.4 → §8.1 → §8.4 chain is now consistent end-to-end: signature
carries effect SET; algebra inhabitance carries effect KIND; the
readonly annotation is the same parallel-authority bug pattern P5/P2
forbid.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix tests-as-data dissolution-trigger cross-reference §10 → §6

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 (sha 95b54f54): all 4
docs cross-referencing the cementing-dispatch-port dissolution trigger
pointed at "tests-as-data §10 step 5", but tests-as-data has no §10 —
the implementation-order list (containing step 5 = cementing dispatch
port) is at §6.

Fixed in 4 places:
- docs/design-r3-lens-substrate-index.md:39
- docs/design-complexity-lens-behavioral-completeness.md:425
- docs/design-cost-lens-sizevar-dimension-wiring.md:314
- docs/design-effect-enumeration-resource-threading.md:489

Per INVARIANTS "Documentation Describes Live State" — readers can now
resolve the cited anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cost-lens cementing — tighten Band-C parity claim to full SymbolicCost/CostExpr carrier

gpt-5-5-pro APPROVE_WITH_COMMENTS finding on PR #1488 sha fa5f1675:
line 316 said "asserting structural equivalence on the asymptotic class"
which could weaken the Band-C parity assertion if read literally — the
asymptotic class is a projection of SymbolicCost, not the full carrier.

Tightened to commit to the stronger claim: cementing asserts structural
equivalence on the FULL SymbolicCost/CostExpr carrier shape (not a
projection). Asymptotic-class equivalence is a downstream consequence,
not a substitute. Aligns with the structural_equivalent() function shape
already declared at line 318.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): remove implicit Enforce-with-inferred-baseline; align Certainty no-lattice references

Codex BLOCKING on PR #1488 sha 265d8ef7: §8.3 + §3.2 + §5.1 said the
default complexity application post-cascade flips to Enforce mode with
"budget = computed asymptotic class at synthesis time" — but the
synthesizer recomputes from the current body each compile, so the baseline
moves with the body. Whatever class the function has becomes both
"current" and "baseline"; they always agree; no regression ever fires.
The fact the design claimed to enforce was lost on every recompile.
P2 single-authority + facts-flow-forward violation.

Resolution: remove the implicit Enforce mode entirely. Default is
Introspect-only for unannotated functions; user explicitly authors
Enforce { budget: <chosen class>, ... } to opt into enforcement. No
auto-inferred baseline — those would need persisted authority (either
generated source, forbidden by feedback_no_generated_code_on_disk, or
sidecar files, same problem). The structural answer: complexity contracts
are user-authored.

Re-framing "opt-out for complexity" per the original user directive: the
user can opt out (by not authoring an Enforce application or by
authoring Introspect); compile errors fire when the user opts IN with a
budget the actual function exceeds. ComplexityBudgetWaiver retains its
purpose — accepting known violations of explicit user contracts.

Codex NB: residual references to "Certainty + lattice declaration" /
"two new lattice instances" in complexity-lens lines 535 + 579 didn't
match the §1.5 lattice deletion. Updated both to single
BoundedLattice<AsymptoticClass> instance + Certainty 2-variant sum
WITHOUT lattice (composition is cost-aware via §3.1 compose_summary_*).

Updates:
- §3.2 (Default policy): full reframe to user-driven contracts.
- §5.1 (Default-application synthesis): synthesizer never emits Enforce;
  only Introspect for unannotated functions.
- §8.3 (Default-application semantics): RESOLVED with new framing —
  user-driven contracts; no implicit baseline; explicit rationale for
  why generated-source is not the answer.
- complexity-lens §5 step 2 + §7.4: drop "Certainty + lattice declaration"
  and "BoundedLattice<Certainty>" from the substrate-landing list and
  ROADMAP-P2 dissolution accounting.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): lens-application — add LensEnforcement<Output, Budget> projection carrier

Codex BLOCKING on PR #1488 sha 265d8ef7 line 100: tying ApplicationConfig<C>
to the same C as Lens<C> made the complexity lens budget = AsymptoticClass,
but the complexity-lens design publishes Lookup<ComplexitySummary> with
work/span/certainty as the lens output. Either drop downstream facts (force
output = AsymptoticClass) or contradict the lens-output contract (output =
ComplexitySummary; budget = AsymptoticClass; type system can't enforce
compatibility). P1 modeling faithfulness + facts-flow-forward violation.

Resolution: introduce LensEnforcement<Output, Budget> projection carrier
in §2. Each lens declares both:
- Lens<Output> for the read function (rich output type — load-bearing for
  lens-fold composition per compose_summary_*)
- LensEnforcement<Output, Budget> for the projection from Output to the
  budget-comparable type (identity for cost; summary.asymptotic_class for
  complexity)

SectionedLensApplication<Output, Budget> is parametric in BOTH parameters;
the type system enforces lens/projection/budget compatibility through the
shared Output and Budget. Mismatched triples (e.g., complexity-lens with
SymbolicCost budget) are unrepresentable.

Why projection rather than single-carrier: the lens output for complexity
is rich (ComplexitySummary {work, span, asymptotic_class, certainty}) —
required by §3.1 compose_summary_* composition. The budget is simple — the
user's "function should be O(log n)" contract. Forcing budget = output
over-constrains user authoring; forcing output = budget drops facts the
composition needs. The projection separates the concerns.

Updates:
- §2: introduce LensEnforcement<Output, Budget>; SectionedLensApplication
  becomes parametric in (Output, Budget). Worked examples for all 4
  lens enforcements added.
- §3: ApplicationConfig<Budget> (was <C>); narrative updated to reference
  Output + Budget pair.
- §6: Substrate Manager scope expanded to include LensEnforcement
  declarations.
- §9 (NOT-modify list): per-lens budget types now declared via
  LensEnforcement, not via shared C.
- §10 step 1: closure gate adds lens_enforcement_carrier_landed; substrate
  authoring includes per-lens LensEnforcement declarations.
- design-r3-lens-substrate-index.md substrate-authority table: updated to
  list the 4 parametric carriers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* WIP: Gunbc PM

* docs(r3): split SectionedLensApplication into per-variant carriers + scrub stale QuantifiedTestClaim ref

Two BLOCKINGs from codex on PR #1488 sha c6e61914:

BLOCKING #1 (lens-application §2 lines 94 + 129): the previous shape
SectionedLensApplication<Output, Budget> required EVERY application
(including Introspect) to declare a Budget type and an enforcement
projection. But §3 + line 129 said Introspect has "no projection or
comparison" — leaving Introspect carrying enforcement metadata it
cannot consume. P2 / illegal-states-unrepresentable: an Introspect
application should not have enforcement axes.

Resolution: split into two carriers + sum:
- EnforcedApplication<Output, Budget> — carries lens, enforcement, section,
  budget, diagnostic_severity, span. Both type parameters relevant.
- IntrospectApplication<Output> — carries only lens, section, span. No
  Budget axis, no enforcement projection.
- SectionedLensApplication = Enforce<O,B>(EnforcedApplication<O,B>) |
  Introspect<O>(IntrospectApplication<O>) — sum where each variant
  carries exactly its required parameters.

Now Introspect cannot accidentally carry enforcement state; mismatched
triples (lens, projection, budget) remain unrepresentable for Enforce
applications. Both illegal classes structurally rejected.

BLOCKING #2 (cost-lens line 332): residual paragraph still said "The
QuantifiedTestClaim runs..." asserting equivalence on asymptotic class
only — contradicted line 312's "Rust cementing test today" + line 316's
"full SymbolicCost/CostExpr structural equivalence" Band-C parity claim.
Two incompatible closure-gate authorities in same section.

Resolution: rewrote line 332 to align with Rust cementing + full
SymbolicCost/CostExpr structural equivalence. Single authority restored.

Also updated downstream references:
- §3 narrative: ApplicationConfig sum-type declaration removed (folded
  into EnforcedApplication directly per §2). Pairing semantics still
  documented; the carrier shape is the single authority.
- §3.2 ComplexityBudgetWaiver rationale: updated to "an Introspect
  application" instead of "SectionedLensApplication { config: Introspect }".
- §4.1 worked example: substrate-after-parsing block now uses
  Enforce<ComplexitySummary, AsymptoticClass>(EnforcedApplication { ... })
  with all coordinates explicit.
- §5.1 default synthesis: synthesizer emits
  Introspect<ComplexitySummary>(IntrospectApplication { ... }).
- §6 substrate-owner scope: 5 carriers now (was 4 before split).
- §10 step 1: closure gates updated; substrate authoring includes
  per-variant carriers + per-lens LensEnforcement declarations.
- master index substrate-authority table: row updated to reflect the
  carrier split.
- r3-structure.md rows 40 + 148: lane-row carriers list updated to
  match the per-variant shape.

P2 single-authority + illegal-states-unrepresentable preserved end-to-end.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): r3-structure default-policy text — sync with design-lens-application-surface §3.2 + §8.3

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 sha 96899484:
r3-structure.md lane-16 blurbs (lines 40 + 148) still said
"opt-out (default check fires; explicit waiver...)" — matched the
OLD default-enforcement story before my fix at e9d67113e which
resolved the design to user-driven contracts (no implicit baseline;
synthesized Introspect-only for unannotated functions).

Parallel prose authority for the same decision violated P2
(single authoritative description) — r3-structure summary
contradicted the canonical owning design doc.

Fixed both occurrences to match the resolved framing:
- Unannotated functions: synthesized Introspect-only.
- Enforcement: requires explicit user authoring of apply_lens with
  Enforce + budget.
- "Opt-out" reframed: user can opt out (no Enforce / explicit
  Introspect); compile errors fire when user opts IN with a budget
  the function exceeds.
- ComplexityBudgetWaiver preserved purpose: accepting known
  violations of explicit user contracts.

Single-authority restored; lane summary now points correctly at
the canonical design doc resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): LensEnforcement carries violation relation, not just projection

Cursor BLOCKING on PR #1488 sha 96899484 line 74: LensEnforcement<Output, Budget>
carried only `project: Output -> Budget`, leaving the fold-pass "budget
exceeded" check without per-lens substrate authority for the violation
relation. The check would have been API-level convention (the fold-pass
hardcoding "use lattice ordering for AsymptoticClass / dominance for
SymbolicCost / mode-mismatch for ParallelismMode" instead of reading
declared facts). P2/P6 single-authority + API-level-enforcement violation.

Resolution: extend LensEnforcement<Output, Budget> to carry both the
projection AND the violation relation:

```dag
type LensEnforcement<Output, Budget> {
  project: Output -> Budget
  violates: (declared: Budget, observed: Budget) -> Bool
}
```

Each per-lens enforcement declares its own violation semantics
structurally:

- complexity_enforcement.violates: lattice ordering on AsymptoticClass
- cost_enforcement.violates: dominance ordering on SymbolicCost (observed
  dominates declared)
- parallelism_enforcement.violates: mode-mismatch (OptInIndependent
  declared but lens computed Sequential = violation)

The fold-pass dispatch reads the per-lens violation relation directly
(no hardcoded comparison logic in the fold-pass; the dispatch is fully
substrate-driven).

Updates:
- §2 LensEnforcement carrier definition: extended with violates field +
  rationale.
- §2 per-lens enforcement examples: each declares both project and
  violates.
- §4.1 worked example "Compiler-side processing": fold-pass description
  reads enforcement.project then enforcement.violates.
- §5 lens-fold integration step 2: dispatch reads project + violates.

Per-lens substrate authority for violation relation restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): per-dimension certainty composition (work + span independent dominance)

Cursor BLOCKING on PR #1488 sha 96899484 line 380: certainty_of_surviving
derived certainty from composed_work only, but ComplexitySummary publishes
BOTH work and span. Span has independent dominance from work (different
inputs to iterate — span uses outer.work + body.span, while work uses
outer.work + body.work). A conservative span contributor could be dropped
from work's dominance walk while its span bound survived in span's
dominance walk — the surviving span contributor's certainty would not
enter the result's certainty. P1 modeling faithfulness + facts-flow-
forward: certainty no longer faithful to the bound it qualifies on the
span dimension.

Resolution: per-dimension cost-aware certainty composition. Each
dimension (work, span, future per-DB-3) computes its own surviving-
contributor certainty independently; the result certainty is the meet
across dimensions (any unproven dimension makes the whole result
unproven).

```dag
let work_cert = certainty_of_surviving_per_dim(outer, body, outer.work, body.work, composed_work)
let span_cert = certainty_of_surviving_per_dim(outer, body, outer.work, body.span, composed_span)
let composed_certainty = meet_pair(work_cert, span_cert)
```

certainty_of_surviving_per_dim is generalized to take per-dimension
inputs (outer's contribution to this dimension, body's contribution,
the composed dimension result) and walks dominance specifically on that
dimension.

Updates:
- §3.1 compose_summary_iterate: per-dimension certainty composition
  with explicit work + span tracking.
- §3.1 certainty_of_surviving renamed to certainty_of_surviving_per_dim;
  signature parameterized over dimension.
- §3.1 compose_summary_sequential / compose_summary_branch comments
  updated to name the per-dimension pattern.
- §1.5 (Why no BoundedLattice<Certainty>): updated to reference
  certainty_of_surviving_per_dim and per-dimension composition.

Faithful certainty composition restored across all published dimensions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration — lens body MUST change to read inhabitance, not signature shape

Cursor BLOCKING on PR #1488 sha 96899484 line 17: the doc moved effect
KIND authority to algebra inhabitance (per §2.4 + §8.1) but the
implementation plan asserted "the lens body does not change. callable_
arrow_effect already implements §2.4's rule" (line 373) + listed the
lens fold body in the NOT-modify list (line 479) + size estimate said
"lens-fold itself is unchanged" (line 494). But callable_arrow_effect
TODAY derives effect kind from signature/body shape — if the body
stays unchanged, it does NOT consume the new inhabits IdempotentRead<R>
/ inhabits Mutating<R> facts. Facts-flow-forward / P2 violation: new
substrate authority not consumed by downstream.

Resolution: the lens body MUST change in its kind-classification
dispatch. Specifically:
- The fold STRUCTURE (per-callable walk + report aggregation) is
  unchanged.
- The per-callable kind classifier IS rewritten — from signature/body
  shape inference to algebra-inhabitance lookup
  (callable_inhabits(callable, idempotent_read_for(resource)) /
  callable_inhabits(callable, mutating_for(resource))).

Updates:
- §6.2 first reason: lens body framing flipped from "does not change"
  to "changes only in its kind-classification dispatch", with explicit
  rationale citing this BLOCKING.
- §9 NOT-modify list: lens fold STRUCTURE preserved; per-callable kind
  classifier explicitly listed as modified (with cross-reference).
- §9 size estimate: "lens-fold itself is unchanged" → "lens-fold
  structure is unchanged; per-callable kind classifier rewrite is S".
- §10 implementation order: NEW step 5 ("Lens kind-classifier
  rewrite") inserted between OperationEffect retirement (step 4) and
  cementing test (now step 6). Total steps 6 → 7; steps-summary
  paragraph updated.

Facts-flow-forward restored across the full migration: new inhabitance
authority lands → lens classifier reads it → effect kind facts flow
into ReadShaped / WriteShaped lens output.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add lens_enforcement_carrier_landed to r3-structure lane gates

gpt-5-5-pro REQUEST_CHANGES on PR #1488 sha 85a6bb0e (BLOCKING #3):
design-lens-application-surface §10 step 1 declared lens_enforcement_
carrier_landed as a closure gate, but the r3-structure.md lane summary
(lines 40 + 148) omitted it from the authoritative gate list. Per
"tracked vs untracked debt" discipline: a named substrate carrier
(LensEnforcement<Output, Budget>) without a tracked landing gate in the
roadmap leaves new substrate work outside the closure-receipt mechanism.

Resolution: add lens_enforcement_carrier_landed to both lane-summary
gate lists (line 40 + line 148) with explanatory note that it covers
the per-lens projection + violation-relation declarations co-located
with each lens.

(BLOCKINGs #1 + #2 from same review wave at sha 85a6bb0e are already
addressed at e554f85e6 — LensEnforcement carries both project AND
violates per-lens violation relation; substrate authority for
budget-exceeded check is structural, not API-level.)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §8.5 implementation note — read EnforcedApplication.budget, not config.budget

Codex BLOCKING on PR #1488 sha a525baf0: §8.5 still pointed implementers
at `config.budget`, but the per-variant split at 968994843 dissolved
ApplicationConfig — budget now lives on EnforcedApplication<Output,
Budget> inside the Enforce variant of SectionedLensApplication.
Stale implementation guidance pointing at non-existent authority. P2
violation.

Fixed: §8.5 now describes the lens-fold matching on
Enforce(EnforcedApplication { budget, ... }) and the Introspect case
(no budget).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): effect-enumeration lens body reads signature directly, not via LensEnforcement

Cursor BLOCKING on PR #1488 sha c41b8ce8 line 373: my §6.2 fix said
the new effect_enumeration lens body "reads enforcement.project for
the effect set". But LensEnforcement is the lens-application-surface
budget-projection carrier (T-Lens-Application-Surface lane). The
effect-enumeration lens body is part of T-Lens-Behavioral-Parity
slice 4 — which CASCADES into T-Lens-Application-Surface (the latter
gates on the former being COMPLETE). Reading enforcement.project from
the lens body inverts the cascade AND gives the effect-set fact a
second authority (signature-derived per §2.4(a) vs LensEnforcement
projection).

Resolution: lens body reads effect set DIRECTLY from the callable's
arrow signature (existing substrate query — resource types in
input ∩ output, per §2.4(a)). Kind classification reads
callable_inhabits(...) per §2.4(b). Both queries are within
T-Lens-Behavioral-Parity slice 4 scope; neither depends on
LensEnforcement.

Updated §6.2 line 373 to:
- Replace "reads enforcement.project for the effect set" with "reads
  the effect set directly from the callable's arrow signature
  (existing substrate query; structurally derivable per §2.4(a)
  without any lens-application-surface artifact)".
- Add explicit "neither depends on LensEnforcement from T-Lens-
  Application-Surface (cascade flows the other direction)".

Cascade direction preserved: T-Lens-Behavioral-Parity COMPLETE →
T-Lens-Application-Surface, not vice versa. Effect-set fact has single
authority (signature query); kind fact has single authority (algebra
inhabitance). No lens-application carriers consumed by lens body.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): per-coordinate certainty on ComplexitySummary (no global collapse)

Codex BLOCKING on PR #1488 sha 75a6ab57: §3.1 computed independent
work_cert and span_cert per-dimension, then immediately collapsed them
into one global ComplexitySummary.certainty via meet_pair. That
collapse loses the per-dimension proof-tightness fact: if work is
Proven but span is Conservative (or vice versa), downstream
display/enforcement consumers see only "globally Conservative" and
cannot know the work bound was proven. P1 modeling faithfulness +
P2 facts-flow-forward violation: the certainty fact each dimension
carries gets fused into ambiguity.

Resolution: ComplexitySummary now carries per-coordinate certainty —
work_certainty and span_certainty as independent fields. No global
certainty field; no meet across dimensions. Each coordinate's certainty
stays on that coordinate through composition.

```dag
type ComplexitySummary {
  work: SymbolicCost
  span: SymbolicCost
  asymptotic_class: AsymptoticClass
  work_certainty: Certainty       // per-coordinate per BLOCKING fix
  span_certainty: Certainty
}
```

Updates:
- §1.7 ComplexitySummary declaration: split certainty into work_certainty
  + span_certainty with explicit rationale citing this BLOCKING.
- §3 ComplexitySummary declaration in lens body section: same split.
- §3 outer Loop construction: outer.span = outer.work, so both
  certainties = bound_cert.
- §3.1 compose_summary_iterate: drop the global meet across dimensions;
  work_certainty := work_cert, span_certainty := span_cert independently.
- §3.1 certainty_of_surviving_per_dim signature: takes per-dimension
  certainty inputs (outer_cert, body_cert) explicitly; no global
  outer.certainty / body.certainty lookup.
- §3.1 compose_summary_sequential / compose_summary_branch comments:
  pattern updated to "no meet across dimensions; per-coordinate
  independence preserved on output".

asymptotic_class is still a projection of work; its certainty is
work_certainty (no separate class_certainty since the class is derived,
not independent). All facts faithful to the dimension they qualify.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): align lens-application doc with per-coordinate certainty (work_certainty / span_certainty)

Cursor APPROVE_WITH_COMMENTS finding on PR #1488 sha 37f3bc62: lens-
application-surface lines 125 + 152 still described ComplexitySummary
with a single `certainty` field, but my fix at 955cafe2c split certainty
into per-coordinate work_certainty + span_certainty in the complexity-
lens design. Sibling-doc mismatch — same carrier shape described two
ways across two design docs in the same PR.

Updated lines 125 + 152 to match complexity-lens §1.7's per-coordinate
shape:
- Line 125 inline comment: "rich output: work/span/asymptotic_class/
  work_certainty/span_certainty".
- Line 152 narrative: "rich (ComplexitySummary { work, span,
  asymptotic_class, work_certainty, span_certainty } — per complexity-
  lens §1.7, certainty is per-coordinate to avoid collapsing per-
  dimension proof-tightness facts)".
- "Forcing output = budget would drop work/span/certainty facts" →
  "drop work/span/per-coordinate-certainty facts".

Cross-doc carrier-shape consistency restored.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: Gunbc PM

* docs(r3): codex BLOCKINGs #1-3 (sha 37f3bc62) — substrate assumptions aligned with v3 reality

3 BLOCKINGs at sha 37f3bc62, all claiming docs lock substrate assumptions
v3 cannot currently express:

BLOCKING #1 (cost-lens SizeVariable label): doc said renderer reads via
intern_table::name_of(port_id). Verified: src/v3/std/algebra.dag:143
explicitly says "InternTable lookup the lens doesn't yet run". v3 has
some InternTable machinery (PR #367 Phase 1) but the port-id-to-name
query is NOT landed. Cannot assume it.

Resolution: re-introduce SizeVariable.display_name: String? as the single
substrate authority for the user-facing name. No InternTable lookup
assumed. Field is single-source (not parallel with anything); parser
populates from authored binding names where present, None for inferred.
Earlier "parallel authority" concern (gpt-5-5-pro at ef21e1a0) doesn't
apply because there's no second source — InternTable lookup isn't
landed and isn't claimed.

BLOCKING #2 (per-variant generics): doc declared
SectionedLensApplication = Enforce<Output, Budget>(...) | Introspect<
Output>(...) — but v3 .dag sums use uniform type parameters across
variants (e.g., Lookup<C> = Miss | Hit(C); both share C). Per-variant
parameter binding / existential packaging not currently supported.

Resolution: drop the SectionedLensApplication SUM. Use TWO SEPARATE
top-level carriers — EnforcedApplication<Output, Budget> and
IntrospectApplication<Output>. Lens-fold pass walks two separate lists
and emits Diagnostics from Enforce walks, records values from Introspect
walks. No per-variant generics required. Each lens application in .dag
source is one or the other; user authoring chooses at apply_lens site.

BLOCKING #3 (TestPredicate maturity): doc said "Today's TestPredicate
coproduct covers 22 variants" listed by name, treating them as
uniformly-live substrate. Per verification.dag inline annotations,
many are 🟡 Scaffold with named dissolution triggers (ExecuteCommand,
ForAllTargets, LensOutputEquals, DifferentialEquals,
BinaryDimensionReportEquals, AlgebraicLaw, ReleaseDeferredClaim,
SubstrateResearchDeferredClaim).

Resolution: §1 explicitly disclose 🟢 TERMINAL vs 🟡 Scaffold partition;
note that ports landing on Scaffold variants are inherently scoped by
that variant's named dissolution trigger; new-carrier residual is in
scope of T-Tests-As-Data-Completeness, not assumed live.

Updates:
- design-cost-lens §1.2: SizeVariable.display_name reintroduced as single
  authority; revert §1.4 from renderer-only to additive field; both wave
  reviews now reconciled.
- design-lens-application-surface §2: SectionedLensApplication sum
  removed; two top-level carriers (EnforcedApplication +
  IntrospectApplication). Downstream §3 + §4 + §5 + §6 + §8.5 + §9 +
  §10 references updated to "two separate top-level carriers" framing.
- design-tests-as-data §1: TestPredicate maturity disclosure (TERMINAL
  vs Scaffold partition with named dissolution triggers per
  verification.dag inline annotations).
- design-r3-lens-substrate-index: substrate-authority table updated to
  drop "sum" and list two separate carriers.

All three BLOCKINGs reflect the constraint: design docs cannot assume
substrate facilities not yet landed, and cannot use shapes v3 cannot
currently express.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cementing test asserts per-coordinate certainty (work + span), not collapsed

Codex BLOCKING on PR #1488 sha e3010014: §1.7 changed ComplexitySummary
to per-coordinate work_certainty + span_certainty (closing the global-
collapse bug at PR #1488 / 955cafe2c), but §4.1 cementing test still
asserted a single global v3.certainty. Internally inconsistent: closure
gate would not validate the per-coordinate claim §1.7 makes; the test
would…
briansrls added a commit that referenced this pull request May 12, 2026
) (#2727)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(layer-2-brief): close test-source/fixture fail-open hole

Two BLOCKING reviews converged on the same finding after #2719 merge:
- Brian inline at line 96 (now ~118 post-edit)
- codex BLOCKING at sha 9fe5e13

Root cause: required_paths_regex was derived from transitive src/v3/*
source deps only, missing two arms:
1. The group's own *_test.rs file paths
2. The group's tests/dag/*.dag TestClaim fixture paths

A PR editing either of those classes would be classified as
"unaffected" by the group's own regex and silently skipped. Fail-open
boundary class P3 forbids.

Fix:
- §2(c): expand per-group regex to require 3 arms (test-source +
  fixture + dependency). Per-group regex completeness invariant
  documented; Mgr-fill review rejects regexes missing any arm.
- §5 acceptance: 2 new self-test cases (e) test-source-edit only +
  (f) fixture-edit only — both must trigger the group's skip_*=false
  via group regex match (NOT via force_full_run shared-infra arm,
  since that's a different layer).

Bridge-tier; dissolves with required_paths_regex column when affected-
set lens lands (R4.B Introspect-lens saturation lane CI integration).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(#2727): ground self-test examples to real paths per cursor review #9854

cursor APPROVE_WITH_COMMENTS flagged that the (e)/(f) self-test cases
used fictional paths (cost_lens_test.rs, cost_lens_claim.dag) that
don't exist in the tree. P1-style grounding gap for a dispatch brief —
readers may treat e.g. as copy-paste truth.

Replaced with real paths verified on main HEAD 29657ae:
- (e): src/v3/compiler/tests/integration/cost_lens_symbolic_consumer_test.rs
- (f): src/v3/compiler/tests/dag/t_r3_gate_87_cementing_regen_cost.dag

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(#2727): per-group self-test matrix per openai-pro REQUEST_CHANGES

openai-pro #9856 verdict at sha 6983b91 caught executable-brief
ambiguity: §2(c) self-test obligation says "for each group" but
§5 acceptance row dilutes to "6 cases" with only cost-lens example.
A worker could satisfy the visible 6-case checklist by testing
only cost-lens while leaving the fail-open class untested for
other groups.

Fix: replace "Self-test (6 cases)" with "Self-test
(4 baseline + 2 × N_groups cases)" + explicit baseline-vs-per-
group decomposition:
- 4 baseline cases (a-d) apply once for whole CI flow
- 2 per-group cases (e/f) MUST be replicated for EVERY Layer 2
  group in the inventory
- Mgr-fill REJECTS the brief if per-group matrix incomplete
- Cost-lens kept as worked example (real paths preserved); same
  shape required for emit_target, parser_grammar, etc.

PM intent alignment: closes the post-#2719 fail-open hole for
EVERY group, not just the pilot.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…on 🟡 YELLOW (#2751)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…y worker brief (#2762)

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: canvas RATIFIED — §7 ratification dispositions

Director (zesty-bear-812) ratified option (c) at 2026-05-12T07:39:44Z
per PR #2751 comment (session msg_168005e1 to PM deep-wolf-155).

- Status header updated to RATIFIED
- §7 added with 4 ratification points + cascade implications:
  1. Expression sum-type at dsl/extdeps/github/actions.dag: RATIFIED
  2. Single OpaqueString variant + 🟡 YELLOW: RATIFIED
  3. Three-condition dissolution trigger: RATIFIED
  4. 5-site uniform migration: RATIFIED
- Cascade documented: cool-carp-720 (WI-2) Expression wrapping;
  stern-stag-854 (Slice 4-5) emit logic stays trivial; PR #2746 can
  reference ratified Expression substrate

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: site-count correction — 5→7 expression sites in actions.dag

Operator BLOCKING inline review on PR #2751 at :34 (briansrls
2026-05-12T07:45:24Z) flagged that actions.dag has Job.if_condition
+ RunStep.if_condition + UsesStep.if_condition (3 if_condition sites),
not 1. Same expansion applies to env: RunStep.env + UsesStep.env (2
sites), not 1.

Finding accepted. Actual migration scope is 7 sites total:
- Job.if_condition (:117)
- RunStep.if_condition (:154)
- UsesStep.if_condition (:163)
- RunnerSpec (new ExpressionRunner variant)
- ConcurrencySpec.group (:?)
- Step.with[k] (UsesStep:160)
- RunStep.env (:151) + UsesStep.env (:162)

Updates:
- §1 table: if_condition row shows 3 sites; env row shows 2 sites
- §1 narrative: "seven expression sites" with enumeration
- §2 (a/b/c) code samples: all 7 sites in option (c) sketch; Step
  carrier modeled with RunStep/UsesStep variants properly
- §3 reasoning point #1: explicit P2/P5 framing — leaving any
  if_condition/env site un-migrated creates hidden parallel authority
  (typed at one site, opaque at others) blocking P5 dissolution at
  un-migrated sites
- §5 / §6 / §7 site-count refs updated
- §7 site-count correction note: framing the expansion as
  site-count correction, NOT substrate-shape correction — ratification
  point #4's "single-authority for expression substrate" already covered
  ALL expression sites in actions.dag uniformly; 7-site scope is
  implementing-PR responsibility

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §4 dissolution target — template-string layer for extdeps fidelity

Operator BLOCKING #2 on PR #2751 at :214 (briansrls 2026-05-12T07:45:24Z):
the §4 dissolution target sketched a pure Expression AST, but GH Actions
expression-bearing scalars are template strings with alternating literal-
text and ${{...}} segments (e.g., concurrency.group:
${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}).
A pure-AST terminal shape under-models what the platform actually parses,
violating INVARIANTS.md P1 (modeling faithfulness).

Finding accepted. §4 dissolution target corrected to two-layer shape:

  Expression
    = OpaqueString(String)
    | Template(List<TemplateSegment>)

  TemplateSegment
    = TextSegment(String)
    | ExpressionSegment(ExpressionAst)

  ExpressionAst = Literal | Var | BinOp | Func | Index (etc.)

This is extdeps-faithful: mirrors the platform's actual parse structure
(template-string layer over expression-AST layer). Pure-literal /
pure-expression / mixed scalars all collapse cleanly into the segment
list.

Original sketch preserved as authoring-evolution record; corrected shape
supersedes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#1 RESOLVED — sum form, not record (per BLOCKING at :258)

Operator BLOCKING #3 on PR #2751 at :258 (briansrls 2026-05-12T07:45:24Z):
§6 open question #1 incorrectly treated record form and one-arm sum as
equivalent. A record form (type Expression { value: String }) does NOT
preserve:
- Single-arm pattern-match property on consumers (record access
  projects to .value as String; no tag to match)
- Single-edit second-variant dissolution path (record → sum is a
  carrier-shape change, not a one-line declaration edit; every
  consumer must be rewritten to switch from .value access to
  pattern-match)

This breaks Practice 4 (coproduct dissolution) and P5 (Progress Is
Dissolution) — the dissolution receipt the YELLOW classification
relies on assumes the dissolution is cheap; record form makes it
expensive.

Q#1 resolved inline: Expression lands as a one-arm sum
(type Expression = OpaqueString(String)), NOT a record. This was
implied by §3 reasoning point #4 ("Pre-empts the type-alias trap")
which applies equally to record-form aliases, but the §6 framing
treated both as admissible — corrected.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: add CI workflow emitter-dispatch canvas (#2746)

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: align workflow emitter canvas with substrate comparison

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs: keep InlineGunbc out of initial target enum

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* docs(r3): §1.8 acceptance-aggregator pattern scaffold (pilot) (#2748)

* docs(r3): expand R3 lanes to 12 + lens-framework invariant + analysis findings

User directive 2026-04-30: "nothing can be deferred past R3 - we have to
readjust R3 if something is missing." PM-driven audit + Director ratification.

R3 lane expansion (10 → 12):
- T-V2-Retirement (NEW; PB Manager continuation): src/v2/ retirement
  cascades from T-FixedPoint + T-LensProducer-Retirement; structurally
  cheap to pull in. Gates: v2_oracle_no_remaining_test_consumers +
  v2_directory_deleted.
- T-Free-Consequences-Demonstration (NEW; Verification Manager): 10-gate
  TestClaim suite operationalizing thesis "free consequences" framing.
  Auto-parallelism + auto-memoization + cross-target opt + space-bound CX.
  Loop-iteration parallelism: sequential default + opt-in via
  Lens<Iteration-Independence> (zero-heuristic; same shape as
  Lens<Bind-Independence>).

Priority corrections folded into existing lanes (no new lanes):
- C1 (T-Tier3-Dissolution sub-gate): tier3_mirror_dissolution_perf_within_budget
  with thresholds <=2x median, <=5x p99 (cargo bench fixtures per retired
  mirror).
- C2 (Substrate continuation, T-Anthropic-Wire scope expansion):
  ProviderTypedWire<P> carrier extracted IN R3 (path (a) commit; drops the
  prior 6-month elapsed-time check exactly per user directive).

design-lens-framework.md amendment:
- Lens.read MUST depend only on (Node, Behavior) pair, not external state.
- Locks memoizable shape; runtime memoization becomes auto-memoization free
  consequence instance (T-Free-Consequences-Demonstration).

ROADMAP.md additions (### Post-merge debt (2026-04-30 analyses)):
- 4 novel findings from paired exploratory + reflective analyses
  (gpt-5-5-pro 991114f / gpt-5-5-thinking ad016c5):
  * Duplicate record-literal fields silently dropped (highest-value bug)
  * ValueBody Rust<->.dag mirror drift; no isomorphism gate
  * FieldMap duplicate-free invariant lost in .dag mirror
  * Operator inference fabricates (T,T)->T for non-algebra LHS
- 8 reflective-analysis priority corrections folded into R3 trajectory
- 2 stale rows marked RESOLVED (repeat_string + lower_fn_body re-derive)

Routed to R3 Mgrs via inbox dispatches (#1130 / #1131 / #1133 / #1276 / #846).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): reframe Rust<->.dag isomorphism as producer-first

cool-crab-614 PR #1324 research reframed the proposal: missing substrate
is a reflected-Dag query/report PRODUCER (Lens<DagShapeReport>), not a
new predicate variant. RustDagIsomorphism becomes a CONSUMER (TestClaim
comparing two DagShapeReport outputs via BinaryDimensionReportEquals),
eliminating parallel-authority risk.

Reflection-aware modifiers for unified BinaryDimensionReportEquals now
cover 4 surfaces: TC1 eta-equivalence + TC2 strategy-order + TC3
evaluation-step + shape-report (reflected-Dag query).

Single substrate-introduction; multiple consumers via reflection-aware
modifiers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(roadmap): fix lower_fn_body row citation per #1319 review

PR #1319 review (cursor 9d2dffb) flagged that the RESOLVED note cited
`src/v3/compiler/src/lower.rs:61670-61688` but lower.rs is only 7919
lines. Original line citations referenced the analysis snapshot's
aggregate-numbering scheme, not live file.

Verified live state: `lower_fn_body_into_existing_decl` symbol does NOT
exist in current lower.rs; equivalent path is `lower_fn_item_expr_body`
(:4410+); non-Arrow arm at :4433-4451 reports
`Diagnostic::ResolveError` with explicit invariant-violation message
("violated lowering invariant: seed_function_signatures_phase did not
produce an Arrow connective for this Fn") and returns outer_scope.
That IS the fail-closed shape the original row asked for; resolution
note now correctly cites live behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): resolve v2-retirement contradiction per #1319 review

PR #1319 review (codex a9a9894) flagged contradiction: T-V2-Retirement
added as R3 lane (line 100) but Compromises table (line 165) still
listed v2 retirement as Post-R3 operational cleanup. INVARIANTS P1
"Documentation Describes Live State" violation.

Fix: strikethrough the post-R3 entry; explicitly note migration into
R3 as T-V2-Retirement lane per 2026-04-30 user directive "nothing can
be deferred past R3." Single authoritative placement; cross-link to
Lane structure §11.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* WIP: gunbc Director

* docs(r3): aggregator pattern — coercion table + precondition + exclusion rules

Addresses BLOCKING #2748 (briansrls inline at L71): live §1.8 uses 7 status
values, not 3 (PASSING, SATISFIED-BY-CONSTRUCTION, CONSUMER_LANDED, DECLARED,
R3-LOAD-BEARING, HELD-CANVAS-DEFERRED, DEFERRED). The 3-value lattice meet
was not machine-checkable as written.

- Coercion table: SATISFIED-BY-CONSTRUCTION → PASSING; INTEGRATION_RECEIPT
  partial-slice → CONSUMER_LANDED; identity for the 3 lattice values.
- Precondition rule: bare R3-LOAD-BEARING is scope-metadata, not closure
  progress; constituents with that status are not aggregator-ready until
  cell inlines closure-progress (e.g., 'R3-LOAD-BEARING — DECLARED').
- Exclusion rule: DEFERRED + HELD-CANVAS-DEFERRED MUST NOT appear in any
  aggregator's depends_on: per §1.5 honest-close arithmetic.
- Cluster F candidate reframed: NOT aggregator-ready at HEAD because rows
  #81/#82/#83/#95 carry bare R3-LOAD-BEARING; precondition fix required
  before pilot. Cluster M / K / V2-Retirement candidates similarly subject
  to precondition check at pilot time.
- Invariants P2 cleanliness note: coercion table + precondition + exclusion
  are themselves a single derivation authority; no parallel authority for
  closure progress.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): cascade ci_yml_deleted → ci_yml_hand_authority_dissolved rename

Per PM cascade (PR #2744 commit 19a1d8d absorbing briansrls BLOCKING
on line 32): file artifact presence is orthogonal to hand-authority
dissolution. YamlStatic / BinaryShim / PythonShim all require some
.github/workflows/ci.yml for GH Actions trigger discovery; P5 / Pure
Bootstrap dissolves authority, not file presence.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): relocate aggregator pattern from §1.8 to §1.9 per codex P2 finding

Addresses codex REQUEST_CHANGES /api/reviews/9982 on PR #2748: putting
aggregator rows directly in §1.8 alongside their constituents violated
INVARIANTS P2 single-authority — even with "derived not hand-set" prose,
the row shape didn't structurally prevent treatment as a closure
obligation, and the side-taxonomy of "does not participate in §1.7
corpus rules" was a P2 boundary-discipline violation inside the
canonical ledger.

Restructured:
- Aggregators relocated to a NEW §1.9 section (separate table)
- Distinct ID namespace: V1, V2, ... (NOT numeric §1.8 row IDs)
- Different table columns (View ID / View Name / Cluster Lane /
  depends_on: / Derived Status / Notes) to make visual distinction
  obvious
- depends_on: references §1.8 row #s by foreign-key style
- Derived Status rendered as <DERIVED> in committed text; never stored
  as snapshot (per feedback_no_snapshot_integers_in_briefs)
- §1.8 "97 enumerated / 96 R3-load-bearing" arithmetic preserved
  unchanged; §1.9 entries do not appear in that arithmetic
- Coercion table + precondition + exclusion rules carried forward
- Cluster F precondition catch (rows #81/#82/#83/#95 carry bare
  R3-LOAD-BEARING) preserved

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): annotate R4-carve citation with supersession marker

Fixes CI failure on PR #2748: scripts/check-r4-carve-dissolution-discipline.sh
flagged the coercion-table row for R3-LOAD-BEARING which mentioned 'R4-carved'
without a supersession annotation. Reframed to cite carve-promotion-IN-R3
2026-05-09 + DISSOLVED status per Director ratification gunbc#846.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): correct #83 characterization + add filename note

Per cursor APPROVE_WITH_COMMENTS /api/reviews/10000 on PR #2748:

- Row #83 (lens_capability_register_zero_proxy_zero_stub) was incorrectly
  listed alongside #81/#82/#95 as carrying "bare R3-LOAD-BEARING". The
  authoritative ledger has #83 reading "DECLARED — full scope IN R3
  (carve-promotion-IN-R3 2026-05-09)", which inlines closure-progress
  alongside scope-metadata and already coerces to DECLARED under the
  precondition rule. Reframed #83 as a positive counter-example showing
  the inline-pattern #81/#82/#95 still need to adopt.

- Added top-of-doc filename note explaining the §1.8 vs §1.9 mismatch:
  filename retained for review-thread anchor stability; substantive
  section is §1.9.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add sunset condition for aggregator pattern pilot doc

Per cursor /api/reviews/10013 optional tighten: PILOT scaffold needs a
single checkable sunset to satisfy P5 scaffold-posture discipline.
Sunset: doc retires when docs/r3-program-plan.md contains §1.9 per the
specified table shape AND at least one §1.9 view entry is live in the
ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): add composite-status coercion rule (CONSUMER_LANDED + PASSING)

Addresses briansrls BLOCKING inline at L66 on PR #2748: coercion table
omitted live §1.8 composite forms like 'CONSUMER_LANDED + PASSING'
(~25 instances in the ledger, including candidate Cluster M constituent
#86 program_generator_carrier_landed).

Added:
- Explicit row for 'CONSUMER_LANDED + PASSING' → PASSING
- General composite rule '<earlier> + <later>' → coerce to <later>
  (rightmost component; conjunction-of-progression-stages semantics);
  covers future composite forms not enumerated.

This makes #86 view-ready under the precondition rule (coerces cleanly
to PASSING).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag) (#2747)

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* docs: add CI workflow emitter-dispatch canvas

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3 emitter-dispatch architecture canvas (PR #2744 brief; outp

* WIP: T-WAD FULL R3 ci.dag scaffold first-draft (PR #2744 brief; output dsl/ex

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: add T-CI-WAD slice 4 skeleton

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs: clarify T-CI-WAD projection sketch

* docs: align T-CI-WAD prep with c-refined shape

* WIP: T-WAD FULL R3-close — Slices 4/5/8 (T-CI-WAD program-tag)

* docs(r3): T-WAD substrate-shape comparison canvas — gate #56 (#2749)

* docs(r3): flip §1.8 #85 forall_exists_quantifier_substrate_landed to CONSUMER_LANDED + PASSING

PR #2647 (vivid-dove-106 / Cluster M Phase 1a) merged carriers into src/v3/std/verification.dag at HEAD; ledger row was drifted DECLARED. Per post-merge ledger-receipt sync discipline (Director-ratified at gunbc#828 c#4415884211).

Caught by Debt-Paydown PM ledger-sync check — thanks silent-ram-834.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): downgrade §1.8 #85 to DECLARED per codex BLOCKING + row #17 precedent

Prior CONSUMER_LANDED + PASSING flip overstated the gate per INVARIANTS §P2 strict reading: carriers + hand-written ratchet ≠ generated consumer proof. Mirrors row #17 (numeric_abstract_carriers_landed) shape: carrier substrate landed, hand-written ratchet noted, CONSUMER_LANDED deferred to generated consumer + SuiteClaim wrapper migration + V Mgr #87 runner consumer.

Sibling row #86 carries same overclaim risk via PR #2645 precedent — separate amendment if Director rules.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: T-WAD substrate-shape comparison canvas (gate #56)

Mgr-tier comparison canvas surfacing three substrate-shape options for
gate #56 ci_workflow_modeled_as_dag under FULL R3-close elevation:

- (a) PR #2736 provider-neutral CIWorkflowDag (semantic-only)
- (b) WI-1 PR #2746 actions.dag-concrete + EmissionTarget? (transport-only)
- (c) Hybrid — CIWorkflowDag as semantic source + Workflow.emission_target
  as transport-artifact selector + projection function project_github_actions:
  CIWorkflowDag -> Workflow as the structural fold connecting them

§0 grep-verifies PR #2736 body claim ("hand-authored GitHub Actions transport
copy was removed") against actual diff: actions.dag Workflow/Job/Step
carriers at :21/:110/:147 intact; PR adds CIWorkflowDag without removing
actions.dag carriers, leaving dual-authority unresolved at HEAD.

§5 recommends option (c) for Director ratification on:
- single-authority per concept layer (gate-dependency at gunbc.ci;
  transport at extdeps.github.actions) per MODELING.md M9
- decoupled cost-of-change axes (new provider vs new emission target)
- preserves both already-authored PRs' substrate contributions
- aligns with docs/design-emission-model.md single-emitter discipline

Authority: PM relay msg_a945b141 (deep-wolf-155) routing Director
msg_34e9a381 substrate-shape question per
feedback_substrate_shape_belongs_in_mgr_canvas.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 addendum — INVARIANTS P1 reframes (c) to (c-refined)

BLOCKING inline review on PR #2746 (briansrls c#4427988541) flagged
that adding EmissionTarget to dsl/extdeps/github/actions.dag puts a
gunbc emission-policy fact into the GitHub Actions platform model,
violating extdeps fidelity and INVARIANTS P1.

§7 accepts the finding (structurally correct per actions.dag header
:1-12 platform-vs-CI-logic discriminator), disqualifies §1 option (b)
as-authored, partially invalidates §1 option (c) as-authored (the
two-layer concept-layering argument STILL holds; only the EmissionTarget
placement on extdeps fails P1).

§7.3 surfaces option (c-refined): EmissionTarget lives in gunbc/ci.dag
as a sum type + parameter to project_github_actions(ci_workflow_dag,
target) -> Workflow. extdeps.github.actions.Workflow is unmodified.
Pinned Workflow values for emission validation live in gunbc namespace.

§7.5 revises ratification asks: PR #2746 disposition shifts from
"framing-narrowing" to substantive substrate retraction on the field-
placement decision (sum-type shape stands; placement relocates).

§7.6 distinguishes (c-refined) from PM-proposed alternatives:
- not PM(b) [EmissionTarget on CIPipeline] — same M9 join-cost as
  PR #2746 §3 Option B
- not PM(c) [WorkflowEmission wrapper] — same sibling-decision cost
  PR #2746 §3 Option C already rejected
(c-refined) expresses emission-target choice at the projection
invocation (per docs/design-emission-model.md: emission is structural
projection, choice is property of the call not the value).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §8 retraction — derive Workflow from projection, not separate authority

codex REQUEST_CHANGES on PR #2749 (review 9970) flagged that option (c)
as authored proposed both a projection function CIWorkflowDag -> Workflow
AND a separately hand-declared Workflow value the emitter "validates
against" as a pinned target — INVARIANTS P2 / modeling-discipline.md
Practice 5 dual-authority condition.

Finding accepted. §8 retracts the pinned-Workflow-as-modeled-authority
framing; in-place edits applied to §1 (option (c) intro), §4 (S0
sequencing), §5 (ratification ask #5), §7.3 (WI-2 placement), §7.5
(revised recommendation).

Replacement framing: the only Workflow value in modeled authority is
the projection function output, structurally derived from a single
source. WI-2's gunbc_ci_yml_workflow becomes a name binding to the
derived result (data gunbc_ci_yml_workflow: Workflow =
project_github_actions(ci_workflow_dag, YamlStatic)), not an
independent declaration. Byte-level regression fixtures live in
tests/, not dsl/, and are not part of modeled authority.

Layering argument unchanged: gate-dependency at gunbc.ci.CIWorkflowDag;
platform transport at extdeps.github.actions.Workflow (unmodified);
emission policy in gunbc namespace; artifact derived from single source.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: cite feedback_extdeps_header_discriminator_before_field_placement

Per PM relay msg_72e2ab50: Director memorialized actions.dag:1-12
discriminator rule as feedback_extdeps_header_discriminator_before_field_placement.
Add citation in §7's discriminator block for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: cite P2 (Boundary Discipline) not P1 for single-authority

gpt-5.5-pro APPROVE_WITH_COMMENTS review 9972 caught that the
single-authority / "every fact lives in exactly one place" principle
is INVARIANTS.md P2 Boundary Discipline, not P1. P1 is Modeling
Faithfulness.

Operator BLOCKING quote at §7 invoked "P1" verbatim; both principles
are in play:
- P2 because emission-policy authority must live in exactly one place
  (gunbc/ci.dag), not split across extdeps and gunbc
- P1 because placing gunbc-policy state on an extdeps carrier makes
  the carrier no longer faithful to its header's "platform facts
  only" claim

§7.1 prose updated to explicitly distinguish the two principles and
note that subsequent single-authority references cite P2.
§7.4 table row relabeled "INVARIANTS P2 (Boundary Discipline / single
authority)".
§7.5 ratification ask #2 cites P2 + P1.
§7 heading updated to "INVARIANTS P2/P1 BLOCKING reframes (c)".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: classify EmissionTarget coproduct per Practice 4 (§7.3.1)

BLOCKING inline review on PR #2749 at line :573 (briansrls
2026-05-12T07:04:15Z): proposed EmissionTarget 4-variant coproduct
landed without 🟢/🟡/🔴 dissolution classification, violating
modeling-discipline.md Practice 4 (coproduct dissolution).

Finding accepted. §7.3.1 added classifying EmissionTarget as
🟡 YELLOW (scaffold) with full reasoning across all four dissolution
patterns:
- Pattern 1 (fact placement): N/A — empty payloads
- Pattern 2 (variant-is-data): blocked by closed-set guardrail
- Pattern 3 (algebraic form): N/A — not std/ algebraic operations
- Pattern 4 (dimensional): live dissolution path; ~2-3 axes
  (target_language, requires_shim, runtime_executes) plausible but
  not yet forced at four variants

YELLOW not GREEN: Pattern 4 plausibly works; closing the door would
be wrong. YELLOW not RED: dissolving prematurely without consumer-
side pressure risks landing wrong axes (requires_shim partially
redundant with target_language at current variants).

Named dissolution trigger (per YELLOW requirements): (a) fifth
target landing that breaks the four-way axis, OR (b) consumer needing
single-dimension pattern-match, OR (c) Slice 4/5 implementation
surfacing an unpredicted axis. Any forces dimensional record shape.

Ledger note: classification is canvas-level; implementing PR (WI-2
re-brief per §5/§7.5 ask #4) MUST carry the same classification +
trigger as a // 🟡 YELLOW (scaffold) comment on the type declaration
citing this canvas §7.3.1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: canvas RATIFIED — §9 ratification dispositions

Director (zesty-bear-812) ratified option (c-refined) at
2026-05-12T07:04:18Z per PR #2749 comment (session msg_4f7f536d
to PM deep-wolf-155). Updates:

- Status header changed to RATIFIED with ratification authority
  citation
- §9 added with all 5 ratification asks dispositioned:
  - (c-refined) substrate-shape: RATIFIED
  - PR #2746: AMEND (4 specific changes for still-heron-763)
  - PR #2736 body: SATISFIED prior
  - PR #2745 WI-2: SCOPE EXPANSION APPROVED, PM authors re-brief
  - S1 projection function: NEW §1.8 GATE (project_github_actions_landed,
    substrate-shape family); aggregator pilot row #56+4→#56+5
- Downstream cascade documented per Director directive

Director attributed feedback_extdeps_header_discriminator_before_field_placement
discipline rule to the §7+§8 self-correction trajectory.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline SUPERSEDED banners on §1(c)/§2.3/§3/§4/§5

codex BLOCKING review 9986 at sha 38c28cd flagged that §2.3/§3/§5
still contain the now-overturned option-(c)-as-authored framing
(EmissionTarget on extdeps.Workflow + hand-declared pinned Workflow).
For a RATIFIED canvas, leaving those sections unmarked materially
states the wrong substrate shape — readers would have to read through
to §7/§8/§9 to discover the supersession.

Finding accepted. Inline SUPERSEDED banners added at the top of:
- §1 Option (c) sub-section: points to §7.3/§7.4/§8/§9 for current shape
- §2.3 Option (c) evaluation: flags the "emission validates declared
  Workflow against projection" sentence as the dual-authority condition
  §8 retracts
- §3 WI-1 assumption-breakage: OVERTURNED bullets explicitly listed
  (placement, "Workflow chooses target" framing, framing-narrowing
  disposition)
- §4 Slice sequencing under (c): SUPERSEDED in part — structure
  remains valid under (c-refined); placement-specific descriptions
  overturned by §7/§8; WI-2 scope larger than §5.4 implied per §9 ask #4
- §5 Recommendation: all three positions (extdeps placement,
  framing-narrowing PR #2746 disposition, pinned-Workflow validation
  target) OVERTURNED; current recommendation is (c-refined) per §7.5+§9

Earlier framings preserved as canvas-evolution record (showing
self-correction trajectory through §7+§8), but each affected section
now flags its own superseded status without requiring a full-doc read.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §6 Q#2 RESOLVED banner — overturned superseded Workflow framing

cursor APPROVE_WITH_COMMENTS review 10001 (non-blocking) noted that §6
open question #2 still partly explained the projected signature via
"PR #2746 places the field on Workflow", which contradicts §7.3
(c-refined) where extdeps.github.actions.Workflow is frozen unmodified.

Fix: add inline RESOLVED banner at §6 head pointing to §7.3 + §9; rewrite
Q#2 entry to flag the superseded framing inline — the parametric
signature was the right answer regardless of placement, but the rationale
over-attributed to a placement that no longer stands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: inline 🟡 YELLOW checkpoint at §7.3 EmissionTarget declaration

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:34Z): the §7.3 code block declaring type
EmissionTarget lacked the inline 🟢/🟡/🔴 classification annotation
required by modeling-discipline.md Practice 4 "any new enum with
N ≥ 2 variants must have a checkpoint comment naming its classification."

The classification reasoning exists in §7.3.1 prose section, but the
declaration site itself was missing the checkpoint comment, which is
the form Practice 4 requires.

Fix: add inline 🟡 YELLOW (scaffold) comment block above the type
declaration citing §7.3.1 for full reasoning + the three-condition
dissolution trigger + likely Pattern 4 dissolution path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7.3.2 Shape A/B clarification — EmissionTarget names realization modes

Operator BLOCKING inline review on PR #2749 at :657 (briansrls
2026-05-12T07:58:35Z): YamlStatic variant of EmissionTarget would
"make a Shape B CI YAML artifact mode an emission target despite
THESIS Shape A/B requiring YAML artifacts to be generated by .dag
user programs, not compiler emission targets."

Per THESIS:215-216, Shape A = compiler language targets (compiler
emits directly); Shape B = user-program artifacts (YAML, Terraform,
K8s, etc. — emitted by .dag programs walking typed values, NOT
compiler render targets). YAML for ci.yml is Shape B; gunbc
doesn't have a YAML emission target.

Finding accepted as naming-and-framing concern, not substrate-shape
concern. Added §7.3.2 clarifying:

- EmissionTarget names a REALIZATION MODE selector, not a parallel
  compiler emission target
- YamlStatic = Shape B (.dag program renders YAML from Workflow)
- BinaryShim = Shape A binary + Shape B YAML shim wrapper
- PythonShim = Shape A Python + Shape B YAML shim wrapper
- InlineGunbc = Shape A (gunbc runtime as host)

No substrate retraction: variants, YELLOW classification, dissolution
trigger, gunbc-namespace placement, parametric signature all stand.
Naming consideration noted (WorkflowRealizationMode would carry less
Shape-A baggage), but renaming forces re-ratification without
corresponding substrate change — keep name, document the mapping at
declaration site per §7.5 ask #4 implementation PR.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix §9 ask #5 slice/gate name — Slice 8 ci_yml_dissolved, not Slice 5 ci_yml_deleted

gpt-5.5-pro REQUEST_CHANGES on PR #2749 sha f5b57e7 (review 10037)
caught that §9 ratification ask #5 wrote the projection-function gate
as "discrete from Slice 5 (ci_yml_deleted, state-check)", but per the
canvas's own §1 (Director-ratified gate-set) and §4 Slice sequencing:
- Slice 5 = BinaryShim emitter (workflow_emission_target_toggle_proven)
- Slice 8 = ci.yml dissolution (gate name: ci_yml_dissolved)

The conflation could mislead workers updating PR #2748 to wire the new
project_github_actions_landed gate against the wrong slice/gate.

Fix: §9 ask #5 now reads "discrete from Slice 8 ci_yml_dissolved",
matching the canvas's earlier authoritative gate-set + §4 sequencing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 inventory audit — 7→22 expression-capable fields

codex BLOCKING (review on sha 4f41aeb) + operator BLOCKING inline at
:315 (2026-05-12 ~09:12Z): site inventory was keyed to ci.yml examples
not actions.dag schema + GH Actions context-availability docs.
Under-modeling the platform expression-capable surface by ~15 sites.

Finding accepted as substantive scope correction. Added §5.5 with
full audit table against actions.dag HEAD + GH Actions docs:

Total expression-capable surface: 22 fields across Workflow / Job /
RunStep / UsesStep / ConcurrencySpec / RunnerSpec. The 7-site
enumeration was the ci.yml-keyed minimum subset; the
actions.dag-keyed audit extends to 22.

§5.5.1 sets migration rule: ALL expression-capable fields migrate
uniformly under (c). Per-field opt-in produces hidden parallel
authority (P2/P5 violation). Implementing PR audits against actions.dag
HEAD + GH Actions context-availability docs and migrates any
additional sites surfaced.

§5.5.2 surfaces typed-field expression semantics as new substantive
question (§6 Q#4) — timeout_minutes/continue_on_error/cancel_in_progress
are typed fields where GH Actions string-coerces expressions. Three
candidate shapes (wrap / TypedOrExpression sum / defer); Director-tier
choice.

§5.5.3 retains §1/§2 7-site framing as ci.yml-keyed reference;
substrate-shape ratification covers expanded 22-site scope per §5.5.1
migration rule.

§6 Q#2 sequencing updated to "22 expression-capable fields"; new Q#4
adds typed-field semantics question.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update PR #2749 cross-link — EmissionTarget → WorkflowRuntime

Per PR #2749 commit 575eb7e (rename EmissionTarget → WorkflowRuntime
to resolve P2 name-collision with src/v3/SELF_HOSTING.md:609 Shape-A
EmissionTarget), update the single cross-reference in §7 here to match
the new name. Substantive content unchanged — orthogonal-axes argument
still holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5.1 — split 22 sites into 13 string + 7 typed-field + 2 enum-ext

codex REQUEST_CHANGES on PR #2751 review 10083 (sha presumably 0cc2c28e
or 28d503c): §5.5.1 said "ALL 22 expression-capable fields migrate to
Expression" but §5.5.2 / §6 Q#4 left typed-field shape (Int?/Bool sites)
as an open Director-tier question. Implementer following §5.5.1 would
author the wrap-to-Expression shape immediately while §5.5.2 says hold.

Finding accepted. §5.5.1 split into three classes:

- 13 string-typed sites — uniform String→Expression migration, in scope
  for §7.5 ask #4 prereq PR
- 7 typed-field sites (timeout_minutes/continue_on_error/
  cancel_in_progress) — HOLD until §6 Q#4 ratifies wrap/sum/defer
- 2 enum-extension sites (RunnerSpec, UsesStep.uses) — new variant
  added to existing sum/struct, in scope for §7.5 ask #4 prereq PR

In-scope for substrate-prereq PR: 13 + 2 = 15 sites. Out-of-scope
(deferred): 7 typed-field sites.

§5.5.1 now non-contradictory with §5.5.2 / §6 Q#4: implementer reading
§5.5.1 migrates 15 sites; the 7 typed-field sites explicitly HOLD with
a named trigger (§6 Q#4 ratification).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §5.5 inventory expansion — add Workflow.name + Job.name (22→24 sites)

Operator BLOCKING on PR #2751 at :365 (briansrls 2026-05-12T10:12:15Z):
the string-typed migration class omitted Job.name: String?; GH Actions
context-availability table lists jobs.<job_id>.name as expression-capable.
Same applies to Workflow.name (workflow name supports expressions).

Audit gap fixed. §5.5 table adds:
- Workflow.name: String (:22) — string-typed expression-capable
- Job.name: String? (:112) — string-typed expression-capable

Counts updated:
- Total expression-capable: 22 → 24 sites
- String-typed class: 13 → 15 sites
- In-scope for prereq PR: 15 → 17 sites (15 string + 2 enum-extension)
- Out-of-scope (typed-field HOLD): 7 sites (unchanged)
- Under-modeling delta: 15 → 17 sites (ci.yml-keyed 7-site enumeration
  missed 17 sites in actions.dag schema)

§5.5.1 enumerated list of string-typed sites adds Workflow.name + Job.name.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs: §5.5 — remove UsesStep.uses (literal-only per GH workflow-syntax)

Operator BLOCKING on PR #2751 at :381 (briansrls 2026-05-12T10:12:15Z):
classifying UsesStep.uses as expression-capable invents platform
capability — GH Actions workflow-syntax treats uses: as a literal
action location; the context-availability table does NOT list
jobs.<job_id>.steps.uses. Modeling it as expression-capable would
violate INVARIANTS.md P1 modeling faithfulness.

Verified against GH Actions docs (workflow-syntax + context-availability):
uses: is a literal action ref resolved before workflow expressions
evaluate.

Finding accepted. Removed UsesStep.uses from §5.5 inventory + struck out
the row + removed planned ExpressionActionRef variant from
enum-extension class.

Counts updated:
- Total: 24 → 23 sites
- Enum-extension class: 2 → 1 site (RunnerSpec only)
- In-scope for prereq PR: 17 → 16 sites (15 string + 1 enum-ext)
- Under-modeling delta: 17 → 16 sites
- Typed-field HOLD class: 7 sites (unchanged)

§5.5.1 enum-extension block now explains why UsesStep.uses was
removed for audit trail.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: §7 ratification ask #4 — reflect §5.5 expanded scope (16 in-scope, 7 HOLD)

Operator BLOCKING on PR #2751 at :543 (briansrls 2026-05-12T10:12:15Z):
§7 ratification dispositions still referenced the 7-site enumeration from
the original ratification framing, while §5.5 expanded the audit to
23 sites. Downstream implementation reading only §7 would preserve
opaque-string authorities at the non-§7-enumerated sites — P2/P5
violation by structural drift.

Fix: §7 ratification point #4 rewritten to cite §5.5 audit set + 16
in-scope sites + 7 typed-field HOLD class with named trigger.

Site-count correction note expanded from single-event to cumulative
correction sequence documenting all 4 BLOCKING-driven expansions
(5→7→22→24→23). Audit trail preserved; the (c) substrate-shape
ratification covers all 23 expression-capable sites uniformly per
"single-authority for expression substrate" principle — implementing
PR migrates 16 immediately, 7 typed-field sequenced post §6 Q#4
ratification.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 expand to MatrixStrategy carriers (23→28 sites; audit-methodology note per codex review 10128)

Cross-product of GH context-availability table × actions.dag carriers adds
MatrixStrategy.{dimensions,include,exclude,fail_fast,max_parallel}.
Updated counts: 28 total / 18 string-typed / 9 typed-field / 1 enum-ext;
19 in-scope for prereq PR, 9 HOLD for §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 remove Workflow.name (literal-only per GH context-availability; run-name is expression-capable key and not currently a Workflow field) — operator BLOCKING :274

28→27 total, 18→17 string-typed, 19→18 in-scope.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 add DispatchInput.default (operator BLOCKING :298) — workflow_call/workflow_dispatch input defaults per GH context-availability

27→28 total, 17→18 string-typed, 18→19 in-scope. MatrixStrategy already present per commit 9c1f0a1.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): status-block migration scope = 19 in-scope + 9 HOLD (was '5 sites uniform') — operator BLOCKING :7

Aligns top-of-file status with §5.5 / §7 ratified scope: 28 total / 18 string-typed + 1 enum-ext = 19 in-scope for prereq PR / 9 typed-field HOLD on §6 Q#4.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1/§7/audit-trail count reconciliation (28/18/19/9) — cursor review 10134

Sweep stale internal counts: 23→28 site totals, 15→17 string-typed in audit blockquote, 5→9 typed-field, 16+7→19+9 deferred. Added correction step 5 to audit trail covering MatrixStrategy + DispatchInput.default additions and Workflow.name removal. Aligns §5.5.1, §5.5 audit-trail blockquote, §7.5 ask #4 with §5.5 audit totals.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): fix 'seven sites-already-migrated' (→19) + P5/modeling-discipline citation drift — cursor review 10145

:146 + :231-233: dissolution-cost wording updated from pre-§5.5 '7 sites' to post-audit '19 sites + 9 typed-field once §6 Q#4 resolves'.
:289-291: scaffold-arm sunset-milestone citation moved from INVARIANTS P5 (which mandates checkable dissolution trigger) to modeling-discipline.md Practice 4 (home of the scaffold-comment convention).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5.1 derivation discipline + add MatrixStrategy carriers to class lists; §6 Q#5 (DispatchInput carrier-split) + Q#6 (RunnerSpec runs-on grammar) — codex BLOCKING 10150

(1) §5.5.1 lists now explicitly enumerate MatrixStrategy carriers per class: dimensions/include/exclude in string-container (18 total), fail_fast/max_parallel in typed-field HOLD (9 total). Added explicit derivation-from-§5.5-table discipline note. Cross-check 18+9+1=28 ✓.

(2) §6 Q#5: shared DispatchInput collapses workflow_call vs workflow_dispatch expression-context-availability axes; carrier-split question surfaced (Director-tier sequencing relative to Slice 4 prereq PR).

(3) §6 Q#6: RunnerSpec under-models runs-on grammar (scalar/array/object + expressions at multiple positions); §2 (c) ExpressionRunner only covers scalar case. Carrier-split question surfaced.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(r3): DispatchInput.default → carrier-split-blocked class (workflow_dispatch is literal-only per GH context table) — operator BLOCKING :369

GH context-availability marks only on.workflow_call.inputs.<id>.default as expression-capable; on.workflow_dispatch.inputs.<id>.default is literal-only. Migrating the shared DispatchInput.default to Expression would invent workflow_dispatch capability (P1 violation).

§5.5 table row updated: ✗ split capability; §5.5.1 adds new 'carrier-split-blocked sites (1)' class; counts now 17 string-container + 9 typed-field-HOLD + 1 enum-extension + 1 carrier-split-blocked = 28 ✓. In-scope for prereq PR: 19→18. §6 Q#5 sharpened from 'sequencing question' to 'BLOCKED until carrier-split lands'.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): §5.5 Job.runner audit row + §5.5.1 enum-extension class flag partial-coverage (array/object/label-element expressions unmodeled) — operator BLOCKING :345

§2 (c) ExpressionRunner covers only whole-runs-on scalar-expression case. Array form (mixed literal/expression elements) and object form (group/labels expressions) require §6 Q#6 RunsOn carrier-split. Scalar-only case stays in §7.5 ask #4 prereq PR; array/object defer to §6 Q#6 resolution.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: R3 Substrate Mgr — lane through R3 close

* docs(briefs): tighten Slice 4 brief P2/P3 single-authority bar + carrier-gap STOP condition — codex BLOCKING review 10208

(1) Workflow field derivation: replace 'CIWorkflowDag content + structural defaults' with strict single-authority requirement; STOP authoring if any field lacks an input-domain source. No fabricated values, no second source of truth. P2/P3 bar made explicit per INVARIANTS + modeling-discipline Practices 3 + 5.

(2) Carrier-gap encounter: STOP condition for this PR (not side-channel-while-continuing). Worker must wait for warm-wolf-698 resolution (substrate-prereq PR / out-of-scope narrowing / brief revision) before resuming. Continuing with a gap = fabricated authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): correct PythonShim ratification — 3 initial arms (YamlStatic + BinaryShim + PythonShim) per emitter-dispatch canvas; only InlineGunbc is DESIGN-ONLY — operator BLOCKING PR #2768 :33

Earlier brief commit 4d40d3b erroneously demoted PythonShim to DESIGN-ONLY. Verified against origin/main:docs/design-ci-workflow-emitter-dispatch.md:126 — ratified shape is `WorkflowRuntime = YamlStatic | BinaryShim | PythonShim` with projection calls + acceptance semantics; only InlineGunbc is design-only pending real runtime consumer (canvas §5.4). Phase B updates Phase A enum + dissolution-trigger comment + Phase B BinaryShim+PythonShim stub note + reference list.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): replace RunStep.* / UsesStep.* glob with exact 17-site enumeration — operator BLOCKING PR #2768 :70

Glob shorthand was incorrectly broader than the §5.5.1 string-container set; would pull in UsesStep.uses (literal-only) + *.timeout_minutes/*.continue_on_error (typed HOLD). Now exact enumeration: Workflow.env (1) + Job.name/if_condition/env/concurrency.group (4) + RunStep.{name,run,env,working_directory,if_condition} (5) + UsesStep.{name,with,env,if_condition} (4) + MatrixStrategy.{dimensions,include,exclude} (3) = 17 ✓. Excluded fields explicitly noted.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant