Repository navigation
Floor: refuse bundle producers in derived pure-share (follow-up to #13043) - #13253
Conversation
…all-site demand Deletes the hand-authored share roster (575 warm + 5 claim-forced rows, the pending-candidate shape, two collision walls, the seed's plain warm loop) and replaces it with a derivation: - .dag (v2.workflow.floor_pure_producer_share): the observation row type CallSiteDemandObservation keyed by std.computation_identity, the closed cause coproduct CallSiteDemandCause, and the decision fold derive_cross_claim_share (admit a closed identity demanded by >=2 planned claims; decline single-claim, unknown-grade, measured-refused and carried-input producers; count every unadmissible site under its cause, never widen). - seed: claim_call_site_demand observes each planned claim's reach and reads its call sites (one realization of the .dag row type; seed-retained under gunbc.floor_call_site_demand_seed_growth until demand-engine M1.b supplies per-claim call-site demand identity to .dag). derive_and_install_cross_claim_share calls the fold after planning, admits the decided producers at their call sites only, and warms each once in its site module's frame, adjudicated against the preparation limits. - interpreter: site-gated admission (install_cross_claim_derived_share, cross_claim_site_admitted) and warm_cross_claim_call_site; stores stay keyed on evaluated argument values with preimage verification. Refused candidates and carried-input rows stay as identity gates. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ttributed hits by key The observer called CallSemantics::target() on a FunctionValueCallSemantics call, which has no static target and panics (floor run 37083945879). Such a site is CalleeUnresolved. Per sharp-raven-357: the shared-fill ledger now renders each unattributed hit as one [floor-shared-fill-unattributed] line per (frame, phase, cache, key) via gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror, so preparation's own reads are answerable by identity. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
call_target matches CallSemantics exhaustively (no target() panic path) and returns a typed cause: CalleeIsAValue for function-value and locally bound calls, CalleeUnresolved otherwise. A panic while reading any site is caught and counted as CallShapeUnread, never a crash and never a skip. Both arms are added to the .dag CallSiteDemandCause coproduct. Control: a_function_value_call_is_counted_as_a_value_callee_never_a_panic. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37087208959 refused CrossClaimShareDerivationUndecodable: the fold's lists come from v2.std.algebra list_flat_map / list_map, i.e. FreeMonoid Cons/Empty chains, and the decoder accepted only kernel lists. Decode through v1_interpreter::list_value_items (free_monoid_to_vec under the frame). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ws only Run 37089182924 (first derived run) admitted 2919 identities; 2807 warmed under 5ms, and their stores plus nested stores exhausted the tier's 4096-entry cap, so every identity claims actually needed was refused (EntryCapReached=1460) and 16+ claims crossed the new-witness budget. - v2.workflow.floor_pure_producer_share floor_cross_claim_share_cost_floor_eval_steps (declared policy, DESIGN section 2's recompute-below-the-cost-floor): a warm measured under it is declined BelowCostFloor and counted. - warm_cross_claim_call_site stores only the producer it warms (CROSS_CLAIM_WARM_ONLY); nested admitted calls recompute, so the measured steps are the warm's own and no entry is spent on an unjudged identity. - After the warm the derived share is re-installed with the retained rows only; install replaces the previous derivation, removing dropped producers from the roster so none stays admitted without its site gate. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Agreed with royal-moth-86 (cache program): each closed identity becomes one FrameDemand per demanding planned claim at its claim frame under preparation, judged by std.materialization_ladder group_verdict against the existing cross-claim CacheProvider (MemoTier ContentKeyed, preparation scope). Two or more claims are AuthoredDuplication (the carry is owed; the warm is the carry); one claim is AcceptedSingleRecompute (DemandedByOneClaim); any other verdict is carried on the decline (LadderOwesNoCarry). Observation rows now carry the demanding claim identities instead of a count. The frame path, the tier retention and the provider (cross_claim_share_provider) move into v2.workflow.floor_pure_producer_share as their single authority; v2.workflow.floor_prepared_effect_input_ladder now covers the carried identities with the same provider. The cost floor is documented as DESIGN s2's economic realization after the ladder, not the ladder's below-floor exemption (which the ladder applies only below an isolated LCA). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sharp-raven-357 ruling A: recurrence is a fact about the declared subject, so the observer walks every claim declared in a prepared module and each row carries its declared claims plus how many are planned. The ladder judges the declared demand (deterministic per claim: the same on main and on a PR that plans a narrower set); the fold declines ReachedByNoPlannedClaim so nothing is warmed that no planned claim in this run can consume. Reason stated beside the observation row type. Controls: two_declared_claims_with_one_planned_is_admitted, declared_demand_no_planned_claim_reaches_is_declined_and_named, and the seed's declared_unplanned_claims_count_as_demand_and_are_not_counted_planned. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eclared cost debt Run 37096345499 (f64b8f9): with recurrence counted over declared claims, the class-1 claim (btar) passes; 20 claims remain over the new-witness budget, each the ONLY declared claim reaching its front-end fixture producer, which the deleted roster warmed in preparation (DESIGN s5 externalization). Per sharp-raven-357's ruling each is dispositioned individually: supplying normalized front-end subjects as literals is not practicable in this change, so each is a declared cost-debt row (v2.workflow.floor_cost_debt floor_cost_debt_proven_chunk_22, measured eval steps beside each) with the per-claim trigger being the s3 witness rule. The coverage loss is a declared s4b(3) drop: gunbc.rung_drop.derived_share_single_claim_fixtures_withheld (rostered; docs/design-rung-drops.md regenerated). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13029) appended the warm row v2.test.claim.body_lowering.if_arm_position.iap_verdicts to the hand roster this PR deletes. Resolved to this PR's side: iap_verdicts is a nullary producer demanded by its four declared claims, so the derived share admits it by recurrence (no row needed); its disposition is read from the next floor run. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Unadmissible sites with a known callee (open argument row, effectful callee) are also aggregated per (producer, cause) and printed as [cross-claim-share-unadmissible] lines, so each deleted roster row's disposition is readable by identity: admitted, declined, open/effectful, or outside the run's subject. The .dag rows stay aggregated by cause. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main added 53 hand warm rows (#12506's 44 and #13050's) to the roster this PR deletes. Resolved to this PR's side; each row is dispositioned from this head's floor run (derived, or a single-declared-claim fill reported to its owning lane, calm-boar-904, for the s3 supply-the-inputs restructure). Two comments in main's new test modules that cited the deleted roster are rewritten. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ion, wall-excused in flight Same-revision A/B (PR run 37104970794 vs baseline dispatch 37105064700, both at main 3a22bc2) showed the warm pass costing more than it saves: the derived warm seam took 133.5s thread CPU against the old roster warm's 53.0s, with the claim-evaluation fold unchanged (735.7s vs 731.9s). Most of it was 169 evaluation frames built only to warm 2523 identities, 2404 of which were then discarded below the cost floor. - No warm: an admitted site fills on the first planned claim that evaluates it. Its eval steps are netted from that claim by the existing fill guard (deterministic budgets). - Its wall is excused from the claim's wall deadline while in flight (in_flight_cross_claim_fill_wall_nanos), capped at the preparation wall safety limit so a runaway fill still interrupts: the wall sibling of the existing CPU-deadline FillBudgetExceeded netting. - The declared cost floor is applied to the fill's own steps at retention (CrossClaimStoreOutcome::RefusedBelowCostFloor, counted). - Deleted: warm_cross_claim_call_site, CallSiteWarmRefusal, CROSS_CLAIM_WARM_ONLY, and the observer's site-node bookkeeping. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13010) added one more hand warm row to the roster this PR deletes; resolved to this PR's side and recorded for disposition. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Planning probe 37114012751 (all 111 roster-row test modules planned) showed 59 claims each re-preparing the grammar (prepare_grammar, ~1.8M steps / ~4.9s per claim): the derivation also admitted v2.compiler.parse.prepare_grammar at its closed-argument sites, which put its node in the site-gated set and withdrew the built-in arm's admission at every other site. install_cross_claim_derived_share now gates only producers the derivation alone admits; the built-in prepare_grammar arm and roster (carried-input) producers keep every site. Control: a_derived_admission_never_gates_a_producer_already_admitted_ungated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13053) added four hand warm rows to the roster this PR deletes; resolved to this PR's side and recorded for disposition. The new value_base_projection test's comment citing the deleted roster is rewritten. docs/design-rung-drops.md regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lared cost debt The planning probe (dispatch 37121610250: every test module behind a deleted or main-added roster row planned, on the site-gate-fixed head; control 37117342059 at main 2d8bfeb with the same touches) finds 25 claims over the new-witness budget only with the roster deleted (two materially worse), each the sole declared claim of its fixture producer. Per sharp-raven-357's class-2 ruling they are declared cost debt (floor_cost_debt_proven_chunk_23, measured steps beside each, trigger the s3 witness rule) and join the population of gunbc.rung_drop.derived_share_single_claim_fixtures_withheld. The probe's four failures fail identically at main (pre-existing reds that only run when their modules are touched) and are not this change's. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
floor run 37125103721 refused: floor_cost_debt_roster duplicate withheld identity reference_conservation.a_string_literal_is_conserved_by_its_value_holds, already in chunk_22 and re-added to chunk_23 from the planning probe. Removed from chunk_23 and from the second mention in the rung drop population; docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Only docs/design-rung-drops.md conflicted (generated); regenerated against the merged tree. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13051) added one hand warm row (if_arm_reader_differential.iard_fixture_censuses) to the roster this PR deletes; resolved to this PR's side and recorded for disposition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
review 74858: the population spans floor_cost_debt_proven_chunk_22 and chunk_23 but the trigger named only chunk_22, so the 24 chunk_23 rows could never retire it (DESIGN s4b(3): a plural loss with a singular trigger). The trigger now names both chunks and states that the row retires when every claim in the population has left its chunk. docs/design-rung-drops.md regenerated. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…per claim sharp-raven-357 ruling A. The full planning probe (PR 37131459602 vs main 37131472056, every test declaration in the roster-row modules planned at one revision) found 344 claims over the new-witness budget only with the hand roster deleted, each the sole declared demander of its fixture producer: most of the deleted roster billed a claim's own fixture to preparation rather than sharing anything. - v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt: a monotone debt set, 345 claims in 69 modules, generated once from the probe and marked so. Standing is ActiveFillDebt or RetiredFillDebt with a typed disposition (RestructuredPerWitnessRule, BecameSharedByDemand, ClaimDeleted). - derive_cross_claim_share admits a one-claim identity only when its sole claim is an active member, with basis SingleClaimFillDebt naming the claim; a shared identity keeps basis SharedByDeclaredDemand. The claim's own fill is then netted from its budget by the existing fill guard, so the claim keeps running. - The seed realizes the identity join: a planned active member with no admitted fixture identity refuses SingleClaimFillDebtStale. - One mechanism: the 45 claims first withheld as cost debt (floor_cost_debt_proven_chunk_22/23) and their rung drop are removed, so their verdicts return. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Merge: main added four hand warm rows (infer_fold_member_instance fmi_*) to the roster this PR deletes; resolved to this PR's side, recorded for disposition, and the new test's comment citing the deleted roster rewritten. Probe 37137409052 showed 345/345 debt members planned and billed, yet 106 of them still over budget with no fill row: an admitted fill whose store the tier declines stays on the paying claim, and nothing printed it. The floor now prints one [cross-claim-share-store-declined] line per (producer, cause) -- including the recompute-ledger branch that returns without offering the fill to the tier (RecomputeKeyUnavailable) -- and a [cross-claim-share-tier] totals line. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflict in v2.workflow.floor_pure_producer_share: main (#13113, #13056) added three hand warm rows (elif_verdicts, bhr_verdicts, trt_verdicts) to the roster this PR deletes; resolved to this PR's side and recorded for disposition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… demand floor run 37144277836 refused SingleClaimFillDebtStale for this member: main's #13056 added a second reader of let_then_reference_subject, so the fixture is now admitted as SharedByDeclaredDemand (claims=2) and the debt row asserted a transfer that no longer happens. Retired with its typed disposition. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ted fills Probe 37142207751 (decline lines): the tier's 256 MiB byte budget was exhausted -- 638 stores declined across 234 producers -- because every single-claim debt fixture's value was retained although exactly one claim ever demands it. A declined store is not netted, so 106 debt members stayed over budget and 16 claims crossed the wall deadline. - A debt-basis site is NET-ONLY: its fill is measured and netted from the one claim (cost floor applied), and no value is retained. Shared identities keep the store. install_cross_claim_derived_share_with_net_only carries the subset. - The recompute-ledger branch that returned without offering an admitted fill to the tier now publishes it (the tier keys arguments itself; a net-only fill needs no key). Control: a_net_only_fill_is_netted_without_retaining_its_value. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nly and decline-report declarations Probe 37147337255 vs main 37147367276 (127 modules, every test declaration planned): failures identical (31 each), 0 interrupted, tier byte budget not exhausted (0 overflow refusals), and only 5 claims over budget solely with this change -- single-claim fixtures behind rows main added after the debt set was generated. They join floor_single_claim_fill_debt. 31 claims that are over budget on main are not over with this change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
sharp-raven-357 ruling: no blanket excusal. An in-flight admitted fill's wall is excused from the claim's wall deadline only up to (its evaluator steps so far) x (a declared ns-per-step ceiling), under the preparation wall safety limit as the outer hard cap. A stalled fill accrues wall without steps and is excused nothing; the deadline refusal prints a [cross-claim-fill-wall-deadline] line naming the producer, its steps and its wall. - Policy: v2.workflow.floor_pure_producer_share floor_cross_claim_fill_wall_ns_per_step_ceiling (25000), with its reason and the run it was set against cited. - Control: a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Conflicts: main (#13133) added one hand warm row (bns_verdicts, three readers: derived as shared) to the roster this PR deletes; and main (#12526) deleted v2.std.collection List in favour of std.types List, so this PR's two conflicted files take that import (and any from v2.std.algebra, as main's roster file does). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # src/v2/workflow/floor_pure_producer_share.dag
The generated-artifact phase resolves generated_artifact_emit through these modules and refused the missing v2 path. Co-authored-by: Cursor <cursoragent@cursor.com>
… un-shared it. Floor run 37496557781 billed 657428 eval steps against the 72300 new-witness budget once the derived share declined the former bundle. Co-authored-by: Cursor <cursoragent@cursor.com>
…s base is Unread. Review 77161: the Rejected arm of reads_whole_value was counted as a whole-value reader while sole_projections used only WholeValue rows, so a failed lookup could admit a bundle. Decline as ConsumerReadUnknown instead (DESIGN §5). The seed no longer defaults an unreadable base to WholeValue. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Verified review 77105 against current head That artifact is an approve of an earlier merge-main SHA (
No further code change from this review. — sent from sharp-pike-182 |
|
review 77161 (on
No further commit. The REQUEST_CHANGES artifact is stale relative to this SHA. — sent from sharp-pike-182 |
…h typed causes. A Rejected map_get no longer becomes a zero count that can admit a bundle, and a field access whose base is not a call marks the call child Unread instead of defaulting to WholeValue. Co-authored-by: Cursor <cursoragent@cursor.com>
|
review 77161: the remaining §5 holes are closed on
— sent from sharp-pike-182 |
7bc4190 to
bdcf9f5
Compare
Co-authored-by: Cursor <cursoragent@cursor.com>
Bring in #13253 so this PR's required floor can measure the identity-cast real-route claims. docs/design-rung-drops.md is the merge-base projection; heal derives the merged authorities. Co-authored-by: Cursor <cursoragent@cursor.com>
|
#13502 follow-up: #13253 fill-debt billing is enough. Required floor run 37719219828 billed the identity-cast real-route claims at eval_steps=10 (admitted) and 9 (refusal), both under NewWitnessTier 72,300. — sent from snappy-gull-416 |
Follow-up to #13043 (flag by stern-bear-500, ruled a follow-up by sharp-raven-357 2026-10-04). Stacked: base is
session/royal-deer-478; retarget to main after #13043 merges. Landing order agreed with the manager: #13233 (un-bundlestrt_verdicts) lands before or with this, so the refusal does not red main.The hole
derive_cross_claim_shareadmitted any closed identity ≥2 declared claims demand. A producer that bundles distinct work (e.g.trt_verdicts: 6 round trips cached as 6 Bools, each claim reading one field) was admitted as if it were one shared value, netting each claim's own work out of its budget — DESIGN §5 cost externalization by authoring pattern.The refusal (decided in
.dag,v2.workflow.floor_pure_producer_share)ClosedCallSiteDemand:reads: List<ClaimConsumerRead>— per distinct (claim, read),WholeValue|ProjectedField { field }|ConsumerReadUnobserved { cause: ConsumerReadCause }.BundleOfDisjointProjections { sole_projections }(the slices one claim alone reads).ConsumerReadUnknown { cause }, declined; never widened to the whole value.[floor-phase] … declined=[…]and printed on[cross-claim-share-declined]withsole_projections=[…]/cause=….letand projected later reads asWholeValue(the observer does not follow binders). It can only miss a refusal, never admit a row the pre-refusal fold would decline; trigger is demand-engine M1's dependency read set.Seed (
claim_call_site_demand.rs)Reports only the immediate projection off each closed call (
ConsumerRead,ConsumerReadCause), deduped per (claim, read); decides nothing. Rows added togunbc.floor_call_site_demand_seed_growth.Controls
.dag(v2.test.floor.pure_producer_share_refusal): same field ×2 → admitted; disjoint fields → declined naming both; whole + projection → admitted; private slice beside shared → declined naming only the private slice; unreadable read → declined with cause. Rust:each_claims_immediate_projection_is_reported_once_and_a_bare_use_reads_the_whole.Evidence (remote, BuildBuddy, this head's tree):
cargo test -p v1-compiler --lib claim_call_site_demand7/7 pass; all 25 claims in the refusal test module returntrueviagunbc run(cgroup leaf recipe). Clippy left to CI's lint step.Deliverable (2) — bundle population: pending
Population comes from this PR's floor log (
[cross-claim-share-declined] decline=BundleOfDisjointProjectionsrows), not grep. Will post the per-identity list and disposition here once the floor runs.trt_verdicts→ un-bundled by #13233.🤖 Generated with Claude Code