Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
3519979
Floor: derive cross-claim pure-share admission from planned claims' c…
Oct 3, 2026
7d142a0
Floor share derivation: function-value calls are unresolved; name una…
Oct 3, 2026
c081563
Share observer: every call shape ends in a typed, counted cause
Oct 3, 2026
c2558b2
Share derivation decode: read the fold's lists in either representation
Oct 3, 2026
98a4286
Derived share: a declared cost floor, one store per warm, retained ro…
Oct 3, 2026
066c479
Derived share: admission is a std.materialization_ladder judgment
Oct 3, 2026
f64b8f9
Derived share: recurrence over declared claims, warm only planned reach
Oct 3, 2026
bb22c44
Class-2 dispositions: 20 single-claim fixture witnesses withheld as d…
Oct 3, 2026
d957126
Derived share: print every decline, single-claim included
Oct 3, 2026
0f871da
Merge origin/main into session/royal-deer-478
Oct 3, 2026
b5fe692
Derived share: name unadmissible sites by producer for disposition
Oct 3, 2026
d496968
Merge origin/main into session/royal-deer-478
Oct 3, 2026
97f1921
Derived share: no preparation warm; fills are lazy, floored at retent…
Oct 3, 2026
e049ff6
Merge origin/main into session/royal-deer-478
Oct 3, 2026
dbaf1d8
Derived share: a site gate never narrows an existing admission
Oct 3, 2026
1f7903d
Merge origin/main into session/royal-deer-478
Oct 3, 2026
183afcf
Class-2 dispositions from the planning probe: 25 more withheld as dec…
Oct 3, 2026
808dccc
Cost debt: one identity was withheld twice
Oct 3, 2026
0debdb6
Merge origin/main into session/royal-deer-478
Oct 3, 2026
b682c73
Merge origin/main into session/royal-deer-478
Oct 3, 2026
ded8a88
Rung drop: the restoration trigger covers both cost-debt chunks
Oct 3, 2026
c5cff13
Single-claim fill debt: 345 claims keep running, each transfer named …
Oct 3, 2026
8f174f3
Merge origin/main into session/royal-deer-478
Oct 3, 2026
7eda7a8
Merge origin/main; report what the cross-claim tier declines to retain
Oct 3, 2026
58f4b5f
Merge origin/main into session/royal-deer-478
Oct 3, 2026
ee0f886
Fill debt: statement_let_then_reference_lowers_holds became shared by…
Oct 3, 2026
309c200
Single-claim fill debt is netted, not retained; publish unkeyed admit…
Oct 3, 2026
9184803
Fill debt: five members from the later probe; receipt lists the net-o…
Oct 3, 2026
b172ba5
In-flight fill wall excusal is bounded by the fill's own steps
Oct 3, 2026
3f2242c
Merge origin/main into session/royal-deer-478
Oct 3, 2026
baee1a5
Frozen runtime-identity residual: five producers whose arguments are …
Oct 3, 2026
cdbcd0c
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 3, 2026
01d10d2
Fill wall ceiling per step is a std.measure Nanosecond, not a bare In…
Oct 3, 2026
7d67b4c
Merge origin/main into session/royal-deer-478
Oct 4, 2026
11389c7
Merge origin/main into session/royal-deer-478
Oct 4, 2026
d4ff7b6
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
88fbe67
Fill debt: seven members behind the eleven roster rows main added (#1…
Oct 4, 2026
931d459
Carried-input seed controls carry the residual producer function thei…
Oct 4, 2026
e1d28ab
Merge origin/main into session/royal-deer-478
Oct 4, 2026
22fb7f4
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
766fa1d
Fill debt: five members behind the six roster rows #13060 added, from…
Oct 4, 2026
fc5b803
Floor: refuse bundle producers in derived pure-share (follow-up to #1…
Oct 4, 2026
a99fc0d
Cost floor counts a fill's native work: thread CPU read as steps at t…
Oct 4, 2026
40cfe21
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
cca7d74
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
e2946e2
Bundle check before planned reach; un-bundle xl2_control_runs
Oct 4, 2026
26471cb
Site-gate check allocates nothing; a site whose fill is below the cos…
Oct 4, 2026
c130ee2
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
b968968
Cost floor's CPU arm is the new-witness envelope, not the step floor …
Oct 4, 2026
0009896
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
95d7e67
Tier lookup verifies a served-instance argument by its digest, not by…
Oct 4, 2026
a4cd45e
Un-bundle the remaining six bundles the refusal names
Oct 4, 2026
e644ab5
Fill debt: four members from probe pair 37204679518 / 37204680949
Oct 4, 2026
5ac393d
Merge remote-tracking branch 'origin/session/royal-deer-478' into ses…
Oct 4, 2026
e46846f
Merge origin/main into session/royal-deer-478
Oct 4, 2026
9a6aa34
Fill debt: eight claims whose own stage the bundles had netted silently
Oct 4, 2026
a5ae2c7
Fill debt: nine members behind the nine roster rows #13038 added, fro…
Oct 4, 2026
488a6d6
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
bf1f239
WIP: linear bundle check (review 75571)
Oct 4, 2026
b1dc951
Merge remote-tracking branch 'origin/session/royal-deer-478' into ses…
Oct 4, 2026
dcdb8d6
Merge origin/main; retire the nine type_application_kind fill-debt me…
Oct 4, 2026
2fa5771
Merge origin/main into session/royal-deer-478
Oct 4, 2026
255af02
Merge origin/main into session/royal-deer-478
Oct 4, 2026
6d7f9ae
Fill debt: twelve members behind the sixteen roster rows #13187 added…
Oct 4, 2026
d0a206d
Merge remote-tracking branch 'origin/main' into session/royal-deer-478
Oct 4, 2026
bbfa816
Merge remote-tracking branch 'origin/session/royal-deer-478' into ses…
Oct 4, 2026
adc6e43
Merge origin/main (#13043 squash-merged) into session/tidy-owl-599
Oct 5, 2026
ea529b4
Merge remote-tracking branch 'origin/main' into session/tidy-owl-599
Oct 5, 2026
bf825d8
Merge origin/main into session/tidy-owl-599
Oct 6, 2026
fe524ca
Re-point leftover v2.std.optional imports to std.optional after #13388.
Oct 6, 2026
cbc8aa5
Fill debt: re-activate identity_cast inhabitance after bundle refusal…
Oct 6, 2026
6d43ba5
Bundle fold: a refused map lookup declines; an unreadable field-acces…
Oct 6, 2026
2c8b533
Merge origin/main into session/tidy-owl-599.
Oct 6, 2026
bdcf9f5
Refuse unread share-map lookups and unreadable field-access bases wit…
Oct 7, 2026
81abb0b
Re-run CI on the restored head
Oct 7, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions dag/gunbc/floor/floor_call_site_demand_seed_growth.dag
Original file line number Diff line number Diff line change
Expand Up @@ -53,9 +53,11 @@ data floor_call_site_demand_seed_growth_justification: SeedGrowthJustification =
DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_NET_ONLY_SITES", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "CROSS_CLAIM_STORE_DECLINES", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "cross_claim_store_declines", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "note_cross_claim_store_outcome", field: WholeDeclaration }
DeclarationRef { module_path: "v1_compiler.v1_interpreter", decl_name: "note_cross_claim_store_outcome", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "ConsumerRead", field: WholeDeclaration },
DeclarationRef { module_path: "v1_compiler.cli_run.claim_call_site_demand", decl_name: "ConsumerReadCause", field: WholeDeclaration }
],
reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline only in proportion to the evaluator steps it has performed, at the declared ceiling floor_cross_claim_fill_wall_per_step_ceiling, under the preparation wall safety limit as the outer hard cap, so a stalled fill and a runaway one both still interrupt, naming the producer, its steps and its wall; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps (the stalled control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.",
reason: "WHAT THIS REPLACES, and why the change is a deletion first. Cross-claim pure-share admission was a hand-authored roster of 575 warm and 5 claim-forced qualified spellings in v2.workflow.floor_pure_producer_share, a second authority over a fact the demand graph carries (DESIGN section 3). Any witness module whose claims re-ran a module-constant producer had to be hand-restructured or hand-rostered before it fit its enrolment margin (gunbc#13030 C3; gunbc#12506 the live case). The roster, its pending-candidate shape, its two collision walls and the seed's plain warm loop (warm_cross_claim_pure_producer, PureProducerWarmRefusal) are deleted in the same change, and admission is now v2.workflow.floor_pure_producer_share derive_cross_claim_share over this observer's rows.\n\nWHY RUST IS STILL NEEDED, and it is one fact: no .dag carrier yet hands the floor PER-CLAIM CALL-SITE DEMAND IDENTITY -- the call sites a planned claim reaches, each with its callee declaration and the canonical preimage of its argument row. DESIGN section 3b's keys row lists demand identity as a declared frontier of demand-engine M1.b, and the floor does not give .dag the claim bodies as values; deriving them in .dag would re-parse and resolve the closure in the interpreter per run. So the seed observes, as one realization of the .dag row type CallSiteDemandObservation, and the operator ruling for this lane (sharp-raven-357, 2026-10-02) admits it on exactly that condition.\n\nWHAT IS NOT GROWN: no admission policy. The seed counts distinct planned claims per identity -- a fact across the claim-frame boundary only it can see -- and decides nothing: the two-claim threshold, the identity grade, and the refused and carried-input exclusions are the .dag fold's, and the seed refuses if the fold's partition does not reconcile with the observed closed rows. No widening: a call whose callee is unresolved or effectful, or whose argument row is not closed, is counted under its CallSiteDemandCause and never admitted. No warm: an admitted site fills on the first planned claim that evaluates it (its wall is excused from the claim's wall deadline only in proportion to the evaluator steps it has performed, at the declared ceiling floor_cross_claim_fill_wall_per_step_ceiling, under the preparation wall safety limit as the outer hard cap, so a stalled fill and a runaway one both still interrupt, naming the producer, its steps and its wall; the declared cost floor is applied to the fill's own steps at retention), netted from that claim's clocks and eval steps through the existing CrossClaimFillGuard, so a statically reached site no claim evaluates costs nothing (which also discharges gunbc#13030 C3 part 1: nothing outside the planned claims' reach is filled). No new correctness dependence: the tier still keys every store on the evaluated argument values and verifies the stored preimage before any serve, so a misjudged site costs a missed share or a wasted store, never a wrong value.\n\nWHY IT IS ADMITTED AGAINST THE v1 FREEZE: gunbc.v1_maintenance_standing v1_seed_standing admits work serving the v2 self-host program, and the required floor gates every v2 change. Seed growth here is realization only -- the observer, the site-gated admission set and its check, and the install -- which is the condition the ruling set.\n\nREDS ENROLLED: claim_call_site_demand tests a_constant_reached_by_two_claims_counts_two_and_a_private_one_counts_one (the discriminating pair, with a claim calling the shared helper twice still counting once), an_unplanned_claim_contributes_no_demand, a_parameter_bound_argument_is_counted_open and an_effectful_callee_is_counted_under_its_cause; v1_interpreter a_derived_producer_is_admitted_only_at_its_admitted_sites (the pair varies only the call site, with an ungated control), a_derived_fill_below_the_cost_floor_is_declined_and_one_above_is_stored (the pair varies only the floor) and a_stalled_in_flight_fill_is_excused_nothing_and_a_working_one_by_its_steps (the stalled control); the decision's REDs are .dag, in v2.test.floor.pure_producer_share_refusal.\n\nTHE SINGLE-CLAIM FILL DEBT JOIN (sharp-raven-357 ruling A, 2026-10-03): v2.workflow.floor_pure_producer_share floor_single_claim_fill_debt is a monotone debt set of claims whose own fixture fill is netted from their budget, each admission reported with basis SingleClaimFillDebt naming the claim. The .dag fold decides which one-claim identities are admitted on a member's behalf; derive_and_install_cross_claim_share realizes the identity join -- a PLANNED active member with no admitted fixture identity refuses SingleClaimFillDebtStale -- and adds no declaration for it. The decision's REDs are .dag (an_active_debt_members_fixture_is_admitted_and_names_its_claim against its retired and non-member controls).\n\nNET-ONLY SITES AND THE DECLINE REPORT: a single-claim fill debt site is netted from its one claim and its value is NOT retained (publish_cross_claim_fill, CROSS_CLAIM_NET_ONLY_SITES), because retaining values only one claim ever demands exhausted the tier byte budget on floor probe 37142207751 and left the declined fills on their claims; and every store the tier declines is reported per producer and cause ([cross-claim-share-store-declined], [cross-claim-share-tier]). RED: a_net_only_fill_is_netted_without_retaining_its_value.\n\nTHE UNATTRIBUTED HITS ARE NAMED BY KEY (sharp-raven-357's condition): the shared-fill ledger's unattributed_hits aggregate is now also rendered one line per (frame, phase, cache, key) through gunbc.observation_ci_render ci_shared_fill_unattributed_text and its seed mirror render_shared_fill_unattributed_text_mirror, so whether preparation reads a producer is answerable by identity. REDs: shared_fill a_hit_with_no_recorded_fill_is_counted_never_dropped (in-claim frame) and a_hit_outside_the_fold_is_named_by_key_and_frame; .dag w_shared_fill_unattributed_line_names_frame_phase_and_key.\n\nTHE CONSUMER-READ FACT (bundle refusal, follow-up to gunbc#13043): the observer also reports, per distinct (claim, read), what the expression consuming a closed call site reads off its result -- the field projected immediately off the call, the whole value, or ConsumerReadUnobserved with its ConsumerReadCause when a projection's field name cannot be read -- as one realization of the .dag ClaimConsumerRead / ConsumerRead row types (ConsumerRead here). It decides nothing: the bundle refusal (BundleOfDisjointProjections, ConsumerReadUnknown) is derive_cross_claim_share's, and an unreadable read is declined there, never widened to the whole value. Same reason Rust is needed as the call sites themselves: the claim bodies are not .dag values. RED: claim_call_site_demand each_claims_immediate_projection_is_reported_once_and_a_bare_use_reads_the_whole; the decision's REDs are .dag (two_claims_reading_disjoint_projections_are_declined_as_a_bundle against its same-field and mixed controls).",
owning_dissolution_lane: "v1-hand-queue-drain" as RoadmapNodeId,
trigger: "Delete the observer (claim_call_site_demand and derive_and_install_cross_claim_share's observation half) when per-claim call-site demand identity is available to .dag: demand-engine M1.b's demand-identity carrier produces CallSiteDemandObservation rows for the planned claims, so the derivation reads them from a modeled carrier and no host walk remains. The site-gated admission set and its check retire with the cross-claim tier itself (gunbc.cross_claim_pure_share_seed_growth's trigger), not with this one.",
current_boundary: "v1_compiler.cli_run.required_floor_runner planned claims -> v1_compiler.cli_run.claim_call_site_demand CallSiteDemandObserver observe -> v2.workflow.floor_pure_producer_share floor_cross_claim_share_derivation -> v1_compiler.cli_run derive_and_install_cross_claim_share -> v1_compiler.v1_interpreter install_cross_claim_derived_share / cross_claim_site_admitted -> [floor-phase] phase=cross-claim-share-derivation and [cross-claim-share-admitted] lines"
Expand Down
Loading