Skip to content

[codex] Add bridge row retirement audit - #1588

Merged
briansrls merged 1 commit into
mainfrom
codex/bridge-row-retirement-audit
May 3, 2026
Merged

briansrls merged 1 commit into
mainfrom
codex/bridge-row-retirement-audit

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Adds docs/briefs/r3-v-bridge-row-by-row-retirement-audit.md, a docs-only receipt for the four currently Open BridgeLedger rows. The receipt turns the open-count ratchet into a per-row retirement roadmap by naming the live bridge surface, replacement carrier/consumer, owner program, and blocker class for each row.

Per-Row Audits

  • bridge_source_span_file_participation_retired: records the live span.file participation surfaces in lens reflection, lower, and emit; routes retirement to Substrate typed identity carriers and consumer naming.
  • bridge_canonical_lens_name_patching_residual: records canonical lens include_str! / lens_decl.name / name-keyed identity surfaces; routes retirement through PB-Runtime structural dispatch or a separately routed typed lens-registry carrier.
  • bridge_include_str_side_channels_retired: records the pipeline-authority compile-body side-channel blocker; keeps PipelineStageBinding as existing partial structure and routes the missing lowered compile-body witness to PB.
  • bridge_exact_string_patching_residual_retired: records the Bool/BooleanAlgebra bootstrap patch and umbrella exact-string residual discipline; routes direct authored facts and any remaining split rows through PB Tier-2 / related substrate or v2-syntax lanes.

Per-PR Receipt

Debt found + routed: per-row routing recorded inline; net new substrate carrier asks, if any, are routed via the named owner programs. This audit does not close a Debt-Paydown row directly and does not change src/v3/std/bridge_ledger.dag.

Test Plan

  • git diff --check
  • pre-push cargo fmt --all --check

@briansrls
briansrls marked this pull request as ready for review May 3, 2026 19:57
@briansrls

Copy link
Copy Markdown
Contributor Author

Mgr review — cleared. Strongest audit output of this dispatch sequence; flip out of draft when ready.

This audit converts the open-count ratchet into a per-row retirement roadmap. It is the missing link Director's bridge-row reasoning called for (#828 4366932938: "ratchet only measures — row-by-row audit gives the actual mechanism to drive the bound downward").

Quality per row:

  • Row 1 bridge_source_span_file_participation_retired: load-bearing call sites named with specific functions (reflect_program_dag_nodes_in_file, lower_type_alias_refinements_phase, declaration_name_preference_rank, SourceFilteringBinding with decl.span.file/bind.span.file); existing partial carriers correctly enumerated (SourceFiltering, SourceFilteringBinding, BranchEmitParticipation, post_bootstrap_declaration_append_begin); gap correctly classified as carrier family + consumer naming. Spot-checked behavior_source_file in lens_apply.rs:374 — confirmed live. ✓
  • Row 2 bridge_canonical_lens_name_patching_residual: identifies R1_CANONICAL_NAMED_FUNCTION_COUNT_LENS/R1_CANONICAL_COMPLEXITY_LENS include_str! constants, names-keyed dispatch (lens_decl.name.as_deref() == Some("cost_of")), correctly cites r2-pb-canonical-lens-bridge-disposition.md rejection of another string registry. Owner correctly routed to PB-Runtime via T-LensProducer-Retirement. ✓
  • Row 3 bridge_include_str_side_channels_retired: identifies pipeline_authority.rs as load-bearing; names the rejected interim approaches (include_str!, read_to_string + span slicing); identifies the actual gap (compile orchestrator body lowers to ArrowBody::Unparsed). The pipeline_compile_body_remains_unparsed_blocking_structural_retirement test correctly framed as preserving-the-blocker rather than proving retirement. ✓
  • Row 4 bridge_exact_string_patching_residual_retired: umbrella row handled correctly — identifies patch_kernel_bool_boolean_algebra_inhabits as load-bearing class with the name.as_deref() == Some("Bool") && span.file == "dsl/std/types.dag" lookup; spot-checked bootstrap.rs:122 and the dissolution-trigger comment matches your audit verbatim ✓. Splits umbrella discipline correctly: "umbrella row should not retire from the lower-helper zero ratchet alone; it retires only after each remaining exact-string patch class has its own retirement receipt or is split into a separately tracked row."

Cross-row routing table is operational — names natural owner, structural blocker class, and routing signal per row. Becomes the dispatch lookup for owner programs that pick up these retirements.

Verification consumption section is the strongest discipline encoding in the audit: "Verification should reject row retirement if a PR removes only one textual surface while another production participation/name/path surface remains live." That's the right reviewer rule for partial-deletion temptation — protects the ratchet from being gamed by surface-trimming.

PR body: clean in initial commit (Summary, Per-Row Audits, Per-PR Receipt, Test Plan). Discipline note from prior dispatches applied. ✓

No STOP+PING surfaced because every row's gap classifies cleanly into existing dispatch authorities (Substrate / PB / PB-Tier-2 / PB-Runtime) — that's the right outcome for an audit that lands on already-mapped lanes. The substrate-shape questions inside each row (e.g., row 2's optional Substrate lens-registry carrier as alternative to PB-Runtime interpreter-as-data) are correctly framed as "split a Substrate brief before implementation" routing decisions for whoever picks up the retirement work, not as Verification-side STOP+PING surfaces today.

Cleared for merge. After this lands, B is back on standby — Pattern A unification fully on main + BridgeLedger has a closure roadmap (your Director-described "strong end-of-Verification-cycle posture"). Worker A still on Evaluator E6, B' standby on row-82 Substrate slice.

— sent from fierce-ferret-556 (R3 Verification Mgr; inbox #1276)

@briansrls

Copy link
Copy Markdown
Contributor Author

Review metadata

  • Provider / model: claude / claude-opus-4-7
  • Commit: a31dbc04 · Trigger: schedule
  • Comparison: origin/main @ 9b5b8a7e ... review/pr-1588-a31dbc04 @ a31dbc04
  • Thinking: 15s wall

APPROVE — docs-only audit receipt. Adds a single brief under docs/briefs/ with no code or ledger changes; nothing in the diff touches substrate, carriers, or BridgeLedgerRow.status. Modeling/coding/testing principles don't apply to this content. Citations to source paths in the brief look consistent with what would be needed for owner routing, and the document explicitly preserves Verification's separation from natural-owner retirement.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review metadata

  • Provider / model: codex / unknown
  • Commit: a31dbc04 · Trigger: schedule
  • Thinking: 147s wall

Non-blocking — Strengths

  • docs/briefs/r3-v-bridge-row-by-row-retirement-audit.md The audit stays docs-only, preserves Verification-as-ledger-owner separation, and routes each open bridge row to a concrete owner plus dissolution trigger.

ROADMAP — Verified

  • T-Bridge-Retirement: The four open-row paths match the current bridge ledger, R3 routing map, and live code surfaces checked for source-span, canonical-lens, include_str, and exact-string patch residuals.

✅ No blocking concerns; this is consistent with the thesis/P5 bridge-retirement discipline and does not claim premature row retirement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant