Skip to content

docs: Add Appendix A with DAG modules, interfaces, and type definitions - #16

Merged
briansrls merged 23 commits into
mainfrom
claude/data-structures-dag-design-PSRmu
Feb 2, 2026
Merged

briansrls merged 23 commits into
mainfrom
claude/data-structures-dag-design-PSRmu

Conversation

@briansrls

Copy link
Copy Markdown
Contributor

Summary

Expands the LLM code review pipeline design document with comprehensive technical specifications for the DAG-based architecture. Adds detailed module dependency graphs, operation interfaces, DAG flow structures, and type definitions to serve as a reference for implementation.

Changes

  • Module Dependency Graph: Visual representation of how lib/review, lib/llm-ops, lib/git-ops, and lib/transport depend on each other and core modules
  • ReviewOps Interface: Defined four core operations (PrepareReviewPrompt, ParseReviewResponse, MergeOutputs, HashFinding) with complete port specifications (inputs, outputs, cardinality, types)
  • Existing Ops Reference: Tabular summary of GitOps, LlmOps, and TransportOps for context
  • DAG Flow Structures: Three detailed DAG diagrams showing:
    • ReviewPhase: Core LLM review flow with prompt preparation and response parsing
    • DiffReviewPhase: Git diff composition with review phase
    • MultiSourceReviewPhase: Parallel execution of LLM, cargo check, and clippy with merge
  • Resource Access Declarations: Table documenting which operations access which resources and access type (all read-only for safe parallelization)
  • Type Definitions: Complete Rust struct definitions for Criteria, Check, Finding, Location, ReviewOutput, ReviewBundle, CandidateRemediations, and CandidateTask as they flow through the DAG

Implementation Details

  • All operations are classified as pure (read-only transforms) except TransportOps::Execute, which is the single I/O boundary
  • Finding IDs are stable hashes derived from reviewer-provided issue_key + check_id to enable deduplication across multiple review sources
  • Location tracking supports multiple formats: file+line, span, diff-relative, or unlocated
  • The architecture enables safe parallelization of review sources (LLM, cargo check, clippy) with conflict detection during merge

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT

claude added 23 commits February 2, 2026 01:31
Defines all DAG modules needed for review pipeline with:
- Module dependency graph (review → llm-ops/git-ops → transport)
- ReviewOps enum with port definitions and I/O classification
- Existing ops reference (GitOps, LlmOps, TransportOps)
- DAG structures: ReviewPhase, DiffReviewPhase, MultiSourceReviewPhase
- Resource access declarations for parallelization
- Type definitions (Criteria, Finding, ReviewOutput, etc.)

All ReviewPhase operations are read-only (pure transforms + LLM reads).

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Unified acquisition pattern for all DAG resources:
- Tool: name, version → ToolHandle (infinite, from env)
- Blob: source → ContentBlob (read-only content)
- Lock: name, scope → LockHandle (future)

BlobOps module with:
- PrepareAcquire / ParseAcquire following transport pattern
- ContentSource enum: Inline, File, GitBlob, S3, Http
- ContentBlob with BlobMeta (size, hash, etag for caching)

Updated ReviewPhase to take ContentSource input.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Three-layer stack for all acquisitions:
- Layer 1: Resource (base acquisition trait, shared by tools/blobs/locks)
- Layer 2: Blob (data + metadata, source-agnostic)
- Layer 3: ReviewBlob (schema-aware, extracted content for review)

Key changes:
- Renamed ContentSource → BlobSource, ContentBlob → Blob
- Added Resource trait in core/resource/
- Added ReviewBlobOps with WrapBlob, ContentSchema, ExtractedContent
- Full stack example showing all layers
- Updated module dependency graph to show stack
- Updated ReviewPhase DAG showing all four layers

Each layer is independently testable and reusable.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Replace over-engineered ReviewBlob/ExtractedContent with:
- LlmQueryOps: content + question → answer (generic primitive)
- Review layer just builds questions from criteria

Simplified stack:
1. Resource: params → handle
2. Blob: source → data + meta
3. LlmQuery: content + question → answer
4. Review: criteria → question, answer → findings

Each layer is generic and reusable. Review adds domain
knowledge (what to ask, how to interpret) without
imposing structure on the content.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Six parallel tracks that need to evolve together:
1. Resource abstraction (core/resource/)
2. Blob abstraction (lib/blob/)
3. LLM Query abstraction (lib/llm-ops/)
4. Review domain (lib/review/)
5. DAG composition patterns
6. Transport & I/O

Plus open questions to resolve:
- Blob as first-class Value?
- Resource caching layer?
- Schema validation location?
- Review output as blob?

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Audited codebase and aligned with existing patterns:
- Prepare/Parse sandwich (GistOps, GitOps, LlmOps)
- Upsert pattern (CliToolOp via UpsertBuilder)
- Capability-based handles (ToolHandle → BlobHandle)
- ResourceId + AccessMode for conflict detection
- Declarative definitions (CliToolDef → BlobSource)

BlobOps now mirrors CliToolOp:
- PrepareCheckCached/ParseCheckCached (like check phase)
- PrepareFetch/ParseFetch (like install phase)
- Acquire (convenience upsert via UpsertBuilder)

BlobHandle is sealed (PhantomData) like ToolHandle -
can't use blob without acquiring it first.

Blobs integrate with existing ResourceId for parallel
execution safety (all blobs are Read access).

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Implementation plan now organized by the 6 parallel tracks:
1. Resource Abstraction - trait, UpsertBuilder, ResourceId
2. Blob Abstraction - BlobSource, BlobOps, BlobHandle
3. LLM Query Abstraction - LlmQueryOps, structured output
4. Review Domain - types, ReviewOps, JSON schema
5. DAG Composition - phase builders, DryRun support
6. CLI Integration - command, criteria config, tests

Each track can be worked on in parallel. TODOs reference
the aligned patterns from codebase audit (CliToolOp,
UpsertBuilder, ToolHandle, ResourceId).

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Implements blob abstraction aligned with existing patterns:
- BlobSource: declarative definition (like CliToolDef)
- BlobOps: PrepareFetch/ParseFetch (prepare/parse sandwich)
- BlobHandle: sealed capability handle (like ToolHandle)
- BlobMeta: size, hash, content_type, etag for caching

Source types: Inline, File, GitBlob, S3 (stub), Http (stub)

Key features:
- Inline sources return handle immediately (no I/O)
- File/Git sources return TransportRequest for Execute
- ResourceId integration for conflict detection
- All blobs have AccessMode::Read (safe parallelization)
- Encode/decode for DAG edge transmission

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
New lib/review/ crate with:
- Core types: Criteria, Check, Finding, Location, ReviewOutput, ReviewBundle
- ReviewOps: PrepareReviewPrompt, ParseReviewResponse, MergeOutputs, HashFinding
- ReviewPhase DAG builders: build_review_phase_graph(), build_inline_review_graph()

LlmOps additions:
- PrepareSimpleRequest: content + question → LLM request
- ParseSimpleResponse: LLM response → answer string

These provide the building blocks for the code review pipeline described
in the design doc.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Key issues with current testgen:
- Manual target registration (easy to forget)
- No staleness detection (tests drift from DAG)
- MockSpecs optional (no enforcement)
- Only tests wiring, not node I/O

Proposed model: DAG definition = test specification
- Node.with_example(inputs, outputs) specifies I/O contract
- Testgen generates unit tests from examples
- MockSpecs required for transport nodes
- Staleness check in make test

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Changes:
- Add testgen and testgen-check commands to BuildConfig
- Add --check mode to gunbc-testgen binary (compares generated vs existing)
- Add testgen/testgen-check targets to Makefile generation
- Regenerate all generated_tests.rs files

New workflow:
  make testgen        # Regenerate tests from DAG structures
  make testgen-check  # Fail if generated tests are stale (CI mode)

The check mode compares what would be generated vs what exists on disk.
If any files are stale or missing, it fails with exit code 1 and lists
the files that need regeneration.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
TestGenerator now panics if:
- DAG has transport executor nodes (TransportRequest → TransportResponse pattern)
- No MockSpec was provided via .with_mock_spec()

This ensures test generation fails early with a clear message rather than
producing incomplete tests. Pure DAGs (no transport nodes) don't require MockSpec.

The panic message includes:
- Which transport nodes were detected
- Example code showing how to fix it

Updated existing tests to provide MockSpec where needed.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Implements the "DAG definition = test specification" model for testgen:

- Add NodeExample type for specifying node I/O examples
  - Inputs: HashMap<String, Value> of input port values
  - Outputs: HashMap<String, OutputMatcher> for expected outputs
  - Optional description for test naming

- Add OutputMatcher enum for flexible output assertions
  - Exact(Value): exact equality check
  - Contains(String): substring match for strings
  - NonEmpty: non-empty strings/lists
  - Satisfies{description, predicate}: custom predicates
  - Any: accept any value

- Add MockSpec.node_example() builder method
- Export NodeExample and OutputMatcher from gunbc_test

- Add TestConfig.example_tests flag (default true)
- Add generate_node_example_tests() to TestGenerator
  - Generates tests that execute single nodes with given inputs
  - Asserts outputs match matchers using to_check_code()
  - Test names derived from node_id + sanitized description

- Add comprehensive tests for new functionality:
  - OutputMatcher::check() tests for all variants
  - NodeExample builder tests
  - MockSpec.node_example() integration
  - Test generation tests for exact/contains matchers

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Moves testgen target definitions from hardcoded list to central registry:

Registry (core/codegen/src/registry.rs):
- Add TestgenTargetDef with name, output_path, module_name, config
- Add all_testgen_dags() returning all DAGs that need test generation
- Categories: internal gunbc-dag DAGs (bootstrap, ci, makegen) and
  library DAGs (llm-ops variants)
- Add testgen field to ToolDef for future CLI tool testgen config

Testgen binary (gunbc-dag/src/bin/testgen.rs):
- Read target metadata from all_testgen_dags() registry
- Match registry entries by name to DAG builder functions
- Use registry config for output paths, module names, test config
- --help now shows "REGISTERED DAGS" from registry

Benefits:
- Single source of truth for which DAGs need test generation
- Adding new DAG: add to registry + add builder function
- Metadata (paths, config) in registry, type-safe building in testgen
- Help output dynamically lists registered DAGs

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
- Remove unnecessary '&' before format!() calls (needless_borrows_for_generic_args)
  in lib/blob/src/lib.rs and lib/review/src/lib.rs
- Fix &PathBuf -> &Path clippy warning in testgen.rs
- Fix len_zero clippy warning in lib/review

- Print CI report outside of groups so it's not auto-collapsed in GitHub Actions
  The report now appears at the end of the log, visible without expansion

- Add mock_spec_fn to TestGenerator to properly wire up mock specs in generated tests
  Generated tests now use mock_spec().to_boundary_mocks() instead of default_mocks()
- Remove redundant mock_spec() functions from wrapper modules since generated tests
  now include their own

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
The report node output now appears directly in the log without
a collapsible ::group:: wrapper, making it immediately visible
in GitHub Actions without requiring expansion.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Introduces Simulator that can both generate and validate values:
- Generator: produce random values satisfying constraints
- Validator: check if values fall within expected range

Built-in simulators:
- non_empty_string, boolean, exit_code, success/failure exit codes
- int_range(min, max), json_object, one_of(values), any

IoContract combines input simulators and output validators:
- Generate constrained random inputs
- Validate outputs match expected ranges

This enables property-based testing: "for all generated inputs,
outputs should satisfy contracts."

Also fixes: skip CI group for report node so output is visible.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Documents:
- MockSpec requirement for DAGs with transport nodes
- NodeExample/OutputMatcher for per-node I/O specification
- Testgen registry auto-discovery via all_testgen_dags()
- Makefile integration with staleness detection
- Flow verification tests
- Simulator type for property-based I/O testing
- IoContract for input/output range validation

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
- Add #[allow(clippy::type_complexity)] to Simulator struct
- Use is_multiple_of(2) instead of seed % 2 == 0
- Remove duplicate report printing from ci.rs (executor handles it now)

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
Report improvements:
- Extract and show test failures from stdout (the actual panic messages)
- Test failures section is now visible in the report without digging into parsed output

Skip propagation fixes:
- CI ops (parse_deps_exists, parse_codegen_exists, parse_codegen_result,
  parse_build_result, parse_test_result) now handle Value::Skipped gracefully
- Bootstrap ops (parse_scan_result) also handles Value::Skipped
- All 6 skip propagation tests now pass

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
When tests fail, the report now falls back to showing the full test stdout
if the "failures:" section cannot be extracted. Also improved extraction
to handle different cargo test output formats.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
This enables testing DAGs in isolation even when they have dangling input
ports (inputs with no incoming edge). Previously, testgen only worked for
DAGs where the first node had no inputs (like the CI DAG's env node).

Changes:
- BoundaryMocks: Add input_mocks field and set_input/get_input methods
- Executor: Inject input mocks for dangling ports in DryRun/Simulate mode
- MockSpec: Add input_mock() builder and update to_boundary_mocks()
- LLM mock specs: Add input mocks for prepare node's dangling inputs
- LLM ops: Add skip propagation handling in parse functions

All 63 LLM tests now pass, including skip propagation tests.

https://claude.ai/code/session_01W72j7jkxhDBfFqvXancwmT
@briansrls
briansrls merged commit 410d4e7 into main Feb 2, 2026
1 check passed
briansrls added a commit that referenced this pull request May 12, 2026
…ts, dynamic ratchet floor, polarity-residual)

Brian inline BLOCKINGs + codex scheduled review BLOCKING #9XXX at PR #2725
sha 698ba61 (4 findings total; codex overlaps with all 3 Brian findings):

(1) #2725 line 70 (constraint #4) — shared-fixture helper carve-out
permits expanded hand-Rust under src/v3/compiler/tests without INVARIANTS
P5 receipt. Brian: P5 receipt required for new/expanded src/v3 Rust.
Codex: require P5 receipt OR state SG-0-neutral without helper expansion.

(2) #2725 line 83 (§3 acceptance final bullet) — hard-codes ratchet floor
≤80 (pre-hot-fix baseline), preserving stale debt. Brian: current main has
84 active exemptions with 20 hot-fix rows; post-rebuild floor should be
recomputed, not preserved at 80. Codex: derive final floor from live
non-hot-fix exemptions at Mgr finalization; delete hard-coded ≤80.

(3) #2719 line 217 (§4 hard constraint #5 Polarity invariant sub-bullet) —
restates skip formula as dimension-only, contradicting two-step
NodeRef+dimension contract. Brian: silently drops testclaim_references in
violation of P2 Facts Flow Forward. Codex: rewrite every formula to skip
when refs∩nodes empty OR dims∩changed_dims empty. (Partial-absorption-
residual: cursor's catch on #2725 review #9799 was fixed at §3 substantive
paragraph at commit 403833e but didn't propagate to §4 constraint #5
sub-bullet at line 217 — different polarity-mentioning site within the
same brief.)

Fixes (single-pass per discipline; same pattern as prior 14-catch cycle):

#2725 constraint #4 (line 70) rewrite:
- 'No new hand-Rust beyond shared-fixture helpers' (carve-out) →
  'Shared-fixture helpers require P5 receipt + SG-0-neutrality'
- Per-PR P5 receipt explicit: (a) helper LOC delta cited, (b) dissolution
  path named (helper retires when cluster's pattern lands in .dag
  TestClaim authority), (c) SG-0 census-delta computation showing net
  ≤ 0
- SG-0-neutrality enforcement: helpers may add lines but net delta ≤ 0
  (helper additions offset by exemption-row retirements + ratchet-down).
  Net positive = escalate (substrate-shape signal)

#2725 §3 acceptance final bullet (line 83) rewrite:
- 'ratchet floor returned to ≤80 (pre-hot-fix baseline)' → 'ratchet floor
  recomputed DYNAMICALLY from live state at activation'
- Concrete computation: starts at current main HEAD's
  TEST_TIMEOUT_MAX_EXEMPTIONS (84 at dfbc010; verify via grep at Mgr
  finalization); each rebuild PR decrements by N (cuts rebuilt that PR);
  post-all-20-rebuild target = (value at activation) - 20 (e.g., 64 at
  current state)
- Removed '≤80 pre-hot-fix baseline' framing
- Explicit acknowledgment: 80 was ITSELF stale debt; 16 non-hot-fix
  exemptions have separate paydown owners; rebuild does NOT freeze goal
  at 80; long-run target per feedback_pb_zero_is_r3_close_target is 0

#2719 §4 constraint #5 (line 217) rewrite:
- Header changed: '...dimensions: Set<Dimension> field on every group
  entry' → '...dimensions: Set<Dimension> + testclaim_references:
  Set<NodeRef> fields on every group entry'
- Polarity invariant rewritten to canonical 2-step join (BOTH NodeRef AND
  dimension intersections; skip = either empty)
- Two fail-open bug patterns explicitly named: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved (path-regex over-approximates
  canonical; fail-closed-safe coarseness)

15th + 16th + 17th distinct review-class catches this polish cycle (16
on #2719 brief; #15 on rebuild scaffold #2725):
- #15 (BLOCKING #1): shared-fixture helper P5 receipt obligation
- #16 (BLOCKING #2): dynamic ratchet floor recomputation
- #17 (BLOCKING #3): polarity-residual at second site (partial-absorption-
  residual within partial-absorption-fix; pattern: 'when canonical
  algorithm gets corrected, ENUMERATE all polarity-mentioning sites'
  is the discipline)
briansrls added a commit that referenced this pull request May 12, 2026
* docs(audit): R3 deferral anti-pattern audit (PROPOSAL — Director-authored)

Surfaces the broader anti-pattern class around cost-lens Miss dissolution
(operator-ratified 2026-05-11). Grep-verified ~1600+ instances of
deferral-via-wrapper-variant in v3 compiler production surface across 13
categories (Option<T>, panic!, .expect(), NotYetImplemented, DescentUnknown,
ArrowBody::Pending, _ => catch-alls, etc.).

Per operator-directive: "Miss should go away entirely; if something in
substrate defines a Miss it should fail and be investigated asap" — extended
to whole anti-pattern class. Each category dissolution path proposed.

Tagged for PM (deep-wolf-155) + Mgr ratification: scope, sequencing, PR-template
ratchet authoring authority.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* docs(audit): address openai-pro REQUEST_CHANGES — narrow Miss-class scope; reconcile DescentUnknown authority

Per openai-pro review (#2708 c#4425020297, verdict REQUEST_CHANGES):

3 valid blocking findings addressed:

1. LAYER MODEL — §3.2 DescentEvidence::DescentUnknown removal conflated
   Miss-class deferral with fail-closed lattice bottom (INVARIANTS.md:63-66).
   Reframed: dissolution requires PM-tier ratification on (a) keep 3-variant
   lattice + construction-side narrowing OR (b) authority update first +
   2-variant collapse. No worker dispatch until PM ratifies.

2. INVARIANTS + modeling-discipline — §1 row 1, §2.2 paragraph: "all 83
   Option<T> = pure deferral" overgeneralized. Per modeling-discipline.md:41-50
   + CODING.md:95-97, Option<T> is allowed when absence is meaningful.
   Reframed as triage candidates with per-site classification (error-None
   = Miss-class; legitimate-absence = compliant); explicit "don't bulk-convert."

3. CODING.md — §4 review checklist phrased as "flag for conversion" which
   conflicts with CODING.md:307-309 (Option/Result OK when meaningful).
   Reframed as "flag for justification": reviewer asks, author justifies;
   non-compliant cases convert, compliant wrappers survive.

§0 framing also clarified: Miss-class deferral ≠ all Option<T>; per-site
classification required; bulk-conversion would itself be a discipline violation.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address codex REQUEST_CHANGES — eliminate internal authority contradictions

Per codex review (#2708 c#4425182*, verdict REQUEST_CHANGES):

2 valid blocking findings addressed:

1. §1 table — rows 2-7 stated definitive violations ("should be typed
   Diagnostics", "admits non-exhaustiveness", "explicit 'I haven't decided
   this'") while §2.2 later correctly narrowed these to per-site triage.
   Two conflicting authorities within the same brief violated INVARIANTS P2
   single-authority discipline. Fix: table notes now reflect the triage
   framing (boundary tooling vs interior substrate flow per CODING.md
   307-309; closed-enum vs deliberate-default catch-alls; etc.). Rows 9-13
   tagged with explicit cross-references to §3 disposition.

2. §5 sequencing — proposed §3.2 (DescentUnknown) same-batch dispatch with
   §3.1, but §3.2 itself blocked dispatch on PM ratification of path (a)
   vs (b). Fix: §5 now explicitly marks §3.2 + §3.6 as PM-blocked authority
   gates; only path (a) ratification would enable same-batch with §3.1;
   path (b) requires INVARIANTS.md edit landing first. Authority-gate
   summary appended.

Also relabeled §2.1 "Pure deferral" → "Miss-class deferral" and removed
DescentUnknown from the auto-classified list (consistent with §3.2 gate).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — reconcile §3.3 DescentResidual with Director-ratified γ-shape

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:101
(2026-05-11T21:03:41Z):

> "BLOCKING: §3.3 reclassifies the Director-ratified terminal DescentResidual
> as Miss-shape without reconciling the current termination.dag authority,
> which violates P1 modeling faithfulness and locked-decision discipline."

Valid finding. The `DescentResidual = EvidenceUnknown(NonStrictEvidence) |
EvidenceIncomplete` shape was Director-ratified via the
illegal-states-unrepresentable rationale in
docs/briefs/r3-substrate-descent-execution-proof-worker.md (gunbc#828
issuecomment-4395060514). The audit incorrectly conflated the analyzer's
runtime-failure surface with a Miss-class design-laziness deferral.

Same pattern as the prior §3.2 DescentUnknown correction (openai-pro
REQUEST_CHANGES):

- §3.3 reframed: no direct dissolution proposed; instead, pre-dispatch
  requirement to read existing authority + produce grep-verified reason
  + PM ratification.
- §1 table row 11: tagged "authority-conflicting per Director-ratified
  γ-shape — compliant as written today."
- §2.1: removed residual from Miss-class auto-classified list; appended
  to the "NOT auto-classified" entries alongside DescentUnknown.
- §5 sequencing: §3.3 now authority-blocked (same as §3.2 + §3.6); cannot
  same-batch with §3.1 until reconciliation lands. Authority-gate footer
  updated.

Pattern: every authority-conflicting dissolution proposal must (a) start
from grep-verified read of existing authority, (b) name the specific
authority doc affected, (c) require PM ratification before dispatch.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — §3.6 ArrowBody location was factually wrong

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:120
(2026-05-11T21:03:41Z):

> "BLOCKING: ArrowBody::Pending is stored on TypeConnective::Arrow.body/
> ResolvedArrow, not Behavior::Transform.body, so §3.6 aims the redesign
> at the wrong substrate boundary under P2 facts-flow-forward."

Verified at HEAD:
- ArrowBody enum at src/v3/compiler/src/dag.rs:1092
- Used in TypeConnective::Arrow { body, .. } patterns (bootstrap.rs:288 etc.)
- All ArrowBody::Unparsed sites in bootstrap_generated.rs are inside
  TypeConnective::Arrow { body: ArrowBody::Unparsed(...), .. }

Original §3.6 claim that ArrowBody is on Behavior::Transform.body was wrong.
Actual location is declaration-tier type-connective (Declaration.connective
= TypeConnective::Arrow { body: ArrowBody::Pending }).

Fix: §3.6 reframed. The substrate-shape question is at the declaration-tier
type-connective layer, NOT Behavior::Transform. The "paper-over" cost is at
the type-connective-walking layer; Behavior walkers already see only resolved
bodies. Revised proposal: PM ratification on R3-load-bearing-ness + Substrate
Mgr canvas on partition-vs-sum-with-Pending design question, citing
M1_DESIGN.md authority + per-walker impact analysis.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address inline blocking — LensSurfacePending is terminal, not in-progress

Per inline review finding at docs/audit/r3-deferral-anti-pattern-audit-2026-05-11.md:37
(2026-05-11T21:03:41Z):

> "BLOCKING: LensSurfacePending is a terminal ParallelismUnsupportedKind in
> the effects substrate, not an in-progress substrate state, so grouping it
> with ArrowBody::Pending needs explicit authority reconciliation before
> dispatch under P1 modeling faithfulness."

Verified at HEAD: src/v3/compiler/src/dag/effects.rs:197 places
LensSurfacePending as a variant of ParallelismUnsupportedKind, explicitly
marked 🟢 TERMINAL in code comments. It's an explicit unsupported-reason
payload for the parallelism lens, NOT a transitional in-progress state.
The "Pending" suffix is misleading.

Fix: removed LensSurfacePending from §3.6 (which only covers true pre-lowering
transitional state ArrowBody::Pending). Updated §1 table row 12 + §2.1
Miss-class list to explicitly NOT auto-classify it. Removed scope contradiction.

Pattern continues from prior corrections: every classification in the audit
needs grep-verified factual grounding. Misleading variant names ("Pending"
suffix on terminal carriers) are themselves a discipline gap.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): address cursor NON-BLOCKING table nits — rows #10/#11 misattributed conflict

Per cursor APPROVE_WITH_COMMENTS review at sha 0c07f7a (2026-05-11T21:08:35Z):

> Row 10/11 phrase 'Authority-conflicting per X' but the cited authority X is
> exactly where the standing design is *defined*. The real tension is between
> the operator's Miss-elimination directive and that existing authority text,
> not 'conflict' within or stated by those authorities themselves.

Fix: reframe rows #10/#11 to name the standing authority + locate the tension
correctly:
- Row 10 (DescentUnknown): standing authority is INVARIANTS.md fail-closed
  bottom; tension is with operator directive (not within the invariant).
- Row 11 (DescentResidual): standing authority is Director-ratified γ-shape;
  carrier is compliant; my prior audit framing was the conflict, corrected in
  §3.3.

NON-BLOCKING per reviewer but legitimate clarity improvement; reviewer's verdict
was APPROVE_WITH_COMMENTS.

* docs(audit): tighten CODING.md citations — boundary roles at :311-321, not :307-309

Per cursor APPROVE_WITH_COMMENTS finding at sha 0af402f (2026-05-11T21:24:39Z):

> The notes point boundary-tooling legitimacy at CODING.md:307-309, but those
> lines only state the narrow 'Hidden panic surface' rule (library avoids
> contract-violation panics/unwrap()). The explicit Bootstrap and
> Code-generation binaries edge roles appear under 'When impurity is
> acceptable' beginning around CODING.md:311 (table ~317-321).

Fix: split the citation so:
- CODING.md:307-309 covers the contract-violation-in-library rule (interior
  substrate-flow panics dissolve to typed Diagnostic per C-8).
- CODING.md:311-321 covers the boundary roles legitimacy (Build script /
  Code-generation binaries / Bootstrap entries in the impurity-acceptable
  table).

Updated table rows #2/#3 (lines 27-28), §2.2 prose (line 66), and §4 review
checklist (line 171). NON-BLOCKING per reviewer; landing as documentation
hygiene.

* docs(audit): add §3.8.1 concrete 10-entry NON_TEST inventory per velocity-walk

Per PM ratification (msg_45457c77 in response to Director ask msg_048fdfa6):
empirical-grounding-strengthens-the-case path. §3.8 currently treats
structural_coverage_gap audit as abstract pattern; with zesty-boar-261's
velocity-walk diagnostic (gunbc#846 c#4425420798) producing a 9 NON_TEST +
1 FRAGMENTS enumerated inventory over the 7d window pre-2026-05-11, §3.8
graduates from speculative to grounded.

Adds §3.8.1 with:
- 10-entry table: file path + LOC + adjacent-lane/dissolution-path mapping
- Total 2,171 LOC; omni_shape_b_openapi.rs identified as ~40% of class
- Audit implication: per-file promote-or-carve discipline applies
- Per-PR review state-space framing (Director conformance read flags
  absent dissolution-path mapping)
- Re-audit cadence note (this is window-relative intro composition,
  not full main §3.8 audit; per feedback_intro_rate_not_residual_share)

Citations grep-verified at HEAD eed86ff: all 9 NON_TEST files exist
with stated LOC; FRAGMENTS entry confirmed in sg0_census_test.rs:688-691.

* docs(briefs): Director scaffold-fill for Cluster M Phase 3 reflected-Dag + DimensionReport bulk-port worker briefs

Per feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input
(Director energy INTO system until real workflow substrate exists).

Verification Mgr (clever-tern-670) status pass (msg_755c3f43) identified
Phase 3 dissolution-rate bottleneck as Mgr-tier brief-authoring bandwidth
on the two biggest unauthored classes:

- Reflected-Dag structural assertion family (~25-30 entries; 16 seed-named)
- Generic DimensionReport / runner-discipline family (~20-25 entries; 10 seed-named)

These ~50 entries combined are roughly half of the #84 EXPECTED_HAND_AUTHORED_TEST
partition (116 entries on origin/main eed86ff). Authoring scaffolds + Mgr
finalization + dispatch should land bulk-port PRs within 7-10 days, with
velocity-tripwire arrow (12.7:1 intros:dissolves at gunbc#846 c#4425420798)
flipping intra-week.

Authority split per Director msg_eb2372c7 to PM:
- Director: scaffold shape (this commit) — locked-design citations, substrate
  carrier references at exact lines, Phase-2 pattern site refs, hard constraints,
  STOP-and-escalate criteria, decomposition recommendations.
- Verification Mgr: finalization — complete inventory (Mgr-fill placeholders
  marked throughout), per-entry classification, pilot selection, dispatch.

Substrate citations grep-verified via Verification Mgr msg_755c3f43:
- ProgramGenerator/ProgramShape/Quantifier/QuantifiedTestClaim/SuiteClaim:
  src/v3/std/verification.dag:118-133 + :379-402 (carriers landed)
- TestSuite.claims still List<TestClaim>: verification.dag:404-407 (staged
  trigger at :394-399) — Reflected-Dag class CONSUMER-GATED on this flip
- Phase-2 pattern: t_pb_b_1_dag_runner_test.rs:257-357 (R3_GATE_87_CEMENTING_REGEN_SUITES,
  run_suite_all_pass_with_expected_claim_names)
- Receipt discipline: r3_gate_87_lens_cementing_regen_receipts_test.rs:13-24 + :122-132
- DimensionReport class NOT consumer-gated (Phase-2 pattern is the load-bearing
  predicate, not full #87 PASSING, per feedback_construction_over_ratchets)

* docs(briefs): Director scaffold-fill for R3 CI Layer 2 path-conditional gating

Per PM ratification at gunbc#828 c4425726922 + Director ratification msg_a77c7f42
(Verification Mgr routing per feedback_parallel_representation_debt coherence).

Bridge-debt with named dissolution trigger: when gate
ci_uses_provable_minimal_affected_set_selection lands, the affected-set
Introspect-lens output (canvas PR #2713) replaces the bridge's
required_paths_regex column.

Brief covers:
- §0 scope: extend PR #2718's changes job, do not parallel
- §1 mechanism: per-group skip_* boolean outputs + STEP-level if: on v3
- §2 inventory sources (slow-test-exemptions.txt + /tmp/v3-test-timings.log
  + NEW per-group required-paths mapping)
- §3 per-dimension structural target — every entry has dimension: Dimension
  field matching lens enum (parallel-representation-debt prevention)
- §4 hard constraints (8 invariants)
- §5 acceptance
- §6 decomposition (Mgr-fill recommendation: cost_lens pilot first)
- §7 STOP-and-escalate criteria
- §8 bridge-debt + dissolution path explicit

Verification Mgr (clever-tern-670) fills inventory + per-group regex +
dispatch. Director scaffold preserves coherence; Mgr finalizes per
feedback_director_mgr_energy_input.

* docs(briefs): fix Layer 2 YAML naming inconsistency (skip_cost → skip_cost_lens)

Per cursor APPROVE_WITH_COMMENTS at sha 04c5b08 (review 9701):

> The changes outputs define skip_cost, but the v3 step's if: uses
> needs.changes.outputs.skip_cost_lens. That disagrees with the same brief's
> post-dissolution sketch (skip_$group with cost_lens → skip_cost_lens, lines
> 129-134). Not a formal invariant breach by itself, but it is easy for an
> implementer to copy the wrong name and get an always-on/off step.

Fix: normalize the example YAML outputs block to match the if: lines and the
post-dissolution sketch. Naming convention: skip_<group_name> where
<group_name> matches the per-group table's group_name column verbatim
(no abbreviation). Updated all 4 example outputs:

  skip_lens   → skip_complexity_lens (was vague; tied to specific group)
  skip_emit   → skip_emit_target (matches starting template at §2)
  skip_parser → skip_parser_grammar (matches starting template)
  skip_cost   → skip_cost_lens (matches if: line + post-dissolution sketch)

Also added an inline comment documenting the naming convention so future
copy-paste from the example stays mechanically correct.

* docs(briefs): cite PM pre-staged Mgr-fill template (PR #2721) + converge pilot recommendation on Cluster B

Per PM msg_bba47649 — pre-staged Mgr-fill template landed as PR #2721
(docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md, 220 lines).

Two scaffold updates:

1. §2 (inventory sources): replaced 'PM pre-staged skeleton to be attached
   if/when available' speculative reference with explicit cite-and-link to
   the landed template doc. Describes what the PM template provides:
   - All 78 slow-test-exemptions.txt entries grouped into 9 clusters (A-I)
   - (test_pattern, dimension, required_paths_regex) skeleton table
   - 12 [Mgr-fill] placeholders for substrate-lens / R3-V L4/L7 / R1C-E /
     free-consequences cross-target tracing

2. §6 (decomposition): converged my prior cost_lens-first pilot
   recommendation with PM's Cluster B recommendation — these are the same
   family (Lane 2 Stage 2d symbolic cost = cost-lens). Updated wording to
   reflect Cluster naming + cross-citation to PM template's Cluster B
   detail. Added [Mgr-fill] placeholder resolution wave to decomposition.

Inline sketch table retained as illustrative; defer to PM template for
actual starting inventory.

* WIP: gunbc Director

* docs(briefs): fix singular dimension → Set<Dimension> per PM caught semantic violation

PM (msg_ab551c52) surfaced codex RC on template PR #2721 (review #9707):
singular 'dimension:' field violates locked-design §2 union semantics. A
multi-dim consumer (e.g., LBP demonstration reading both complexity + cost)
declared with singular dimension: cost would be silently skipped when only
complexity changes — fail-open violation against P3.

PM fixed their template at dedcf69: dimension → dimensions (Set<Dimension>),
union-formula clarified, multi-dim rows expanded.

This brief had the same singular semantics; absorbed the fix per PM
recommendation so Verification Mgr inherits coherent dim-set semantic across
both authority chain artifacts (brief + template).

Changes:
- §0 authority bullet: contains(single) → (∩ ≠ ∅) intersection-non-empty;
  dimension: Dimension → dimensions: Set<Dimension>
- §2 table column rename + type spec + union semantics note + multi-dim
  consumer guidance
- §2 starting template citation updated to reflect post-fix template at
  dedcf69
- §3 section header renamed; substantive paragraph explaining WHY
  Set<Dimension> not Dimension (cites PM caught violation + P3 fail-open
  framing)
- §3 YAML example: jq script updated to set-intersection check
- §4.5 hard constraint: dimensions: Set<Dimension> with members from enum;
  empty set invalid
- §5 acceptance: every group has dimensions: Set<Dimension>; multi-dim
  fidelity language
- §6 pilot description: 'singleton {cost} dimensions' phrasing; class wave
  reviewer-check language updated
- §7 STOP: added multi-dim escalation path; explicit warning against
  defaulting to singleton {primary}
- §8 surviving artifact: (group_name, dimensions) — set-typed column survives
- inline illustrative table: explicit set-literal notation with multi-dim row
  example (lbp_demonstration: {complexity, cost})

Same authority chain absorbs cleanly: brief (primary) + template (data
attachment) now both set-typed; Verification Mgr inherits coherent
semantic.

* docs(briefs): fix boolean polarity inversion + add polarity invariant per openai-pro RC on template

PM (msg_9a188e22) surfaced openai-pro BLOCKING re-review (#9721) on template
PR #2721 at 93080af — caught load-bearing boolean polarity inversion:
brief stated skip_* formula as (affected ∩ row.dimensions) ≠ ∅ (skip when
intersection NON-empty) while CI consumer wires if: skip != 'true' (run
when skip is false). Net effect: literal-following Mgr/worker would wire
the gate to silently skip AFFECTED tests when intersection is non-empty.
TESTING.md + Boundary Discipline violation.

PM fixed template at 262f42d (4 sites inverted; explicit polarity table
added at §1/§3/§4/§5).

Same risk on this brief (#2719) at the post-dissolution mapping site I
authored when absorbing the prior dim-set fix at efacecd. Fix:

§0 authority bullet (line 10, the inversion site):
  before: 'skip_* flags become (∩ ≠ ∅)' [INVERTED — fail-open]
  after:  'skip_* flags become skip_<group> = (∩ = ∅)' [canonical]
  + explicit polarity check note + carrier-vs-contract explanation
  + skip-form / run-form equivalence stated

§3 substantive paragraph (after Set<Dimension> WHY): added Polarity
invariant block citing PM's caught inversion + 262f42d fix + explicit
warning that skip = (∩ ≠ ∅) is the canonical fail-open boolean-polarity
bug pattern.

§4 hard constraint #5 (dimensions field): added inline Polarity invariant
restating the canonical skip-form + run-form equivalent + 'never invert'
clause.

§5 acceptance: added 'Polarity check passes' criterion enumerating the
acceptable forms + naming the inverted form as the fail-open pattern to
reject in review. Self-test text clarified: cost-dimension groups run,
other-dimension groups skip (verifies correct polarity in actual gate).

YAML example at §3 (lines 139-149) was already polarity-correct (skip iff
intersection empty; skip=true when intersection empty) so unchanged.

Single-pass absorption per PM recommendation — both brief and template
now lockstep on polarity semantics. Verification Mgr inherits both files
without polarity mismatch in finalization.

* WIP: gunbc Director

* docs(briefs): align §0 example names with §1 naming convention (cursor exploratory)

Per cursor APPROVE exploratory observation on PR #2719 sha 13b0db9
(review #9732):

§0 line 25 illustrative outputs used abbreviated names (skip_lens /
skip_emit / skip_parser) while §1 line 53-54 establishes strict
'skip_<group_name>' naming convention matching the per-group table
verbatim. Non-policy violation per cursor but tightening avoids ambiguity
for implementer.

Fix: replace abbreviated names with full-form (skip_cost_lens /
skip_emit_target / skip_parser_grammar) + cross-reference §1 naming
convention in the same sentence. Brief now consistent across all naming
sites.

* docs(briefs): add P3 fail-closed shared-infrastructure full-run bucket per codex BLOCKING

codex REQUEST_CHANGES on PR #2719 at sha 52c6cf0 (review #9744):

Line 102 narrowed required-paths inventory to 'src/v3/*' deps only; the
illustrative table at lines 114-118 followed that shape. A PR that changes
shared test infrastructure or selection machinery outside src/v3/*
(.github/workflows/ci.yml, scripts/*, Cargo.lock, rust-toolchain.toml,
etc.) would be classified as 'unaffected' for every per-group regex and
silently skip tests whose behavior actually changed.

That's the fail-open boundary class P3 forbids + TESTING.md
behavior-driven discipline violation. Real correctness issue in the
proposed mechanism, not just an implementation detail.

Fix: add shared-infrastructure full-run fail-closed bucket as the
join-point that catches inter-group / cross-cutting changes:

§2 (inventory sources): added 'Shared-infrastructure full-run fail-closed
bucket' subsection with explicit mechanism — changes job computes
force_full_run = (any changed file matches shared-infra regex); when
true, all per-group skip_* short-circuit to false. Regex spec:
^(\.github/.*|scripts/.*|Cargo\.(toml|lock)|rust-toolchain\.toml|
\.cargo/.*|build\.rs)$. Names the structural rationale: per-group
regexes cover ONLY their own src/v3/* deps; the full-run trigger is
the join-point. Fail-closed by construction.

§4 hard constraint #9 (new): formalizes the invariant + 'never collapse
the full-run trigger into per-group regexes' (structural fail-open shape).

§5 acceptance: added 'Shared-infrastructure full-run check passes' as
separate criterion + self-test case (c) — a PR touching only
.github/workflows/ci.yml or Cargo.lock or scripts/check-test-timeout.sh
MUST run all test groups. Expanded self-test from 3 to 4 cases (a/b/c/d).

§2 added [Mgr-fill]: validate shared-infra regex against representative
recent PRs.

Single-pass absorption; brief now P3 fail-closed at the cross-cutting
boundary.

* WIP: gunbc Director

* docs(briefs): fix two openai-pro BLOCKINGs — harness-arm in shared-infra regex + cargo test substring not glob

openai-pro REQUEST_CHANGES on PR #2719 at sha 0d3b44b (review #9749 +
manual c4426188322):

BLOCKING #1 (P3 Fail-Closed): brief at line 104 names 'harness code' as
a class to catch in full-run regex but the actual regex at line 109 had
no harness/test-selection arm. Harness-only changes (e.g., to
tests/integration/common/* or sg0_census_test.rs) would miss both
full-run regex AND per-group regexes — silent skip.

BLOCKING #2 (TESTING.md fail-closed CI): test_pattern field documented
as 'cargo test arg pattern' but examples used glob-looking syntax
(cost_lens_*, *_emit_*). Cargo positional test arg is a libtest SUBSTRING
filter, not a glob. Worker following the brief literally would produce
a step that runs zero intended tests + exits successfully — silent skip
converting 'selected group tested' into 'selected group filtered out.'

Fixes:

#1 (harness arm in shared-infra regex):
- §2 mechanism: extended regex to include
  src/v3/compiler/tests/integration/common/.*,
  sg0_census_test.rs, test_runner_test.rs, t_pb_b_1_dag_runner_test.rs,
  integration.rs, integration test entry points
- §2 new paragraph naming the harness/test-selection-machinery arms
  explicitly + hard rule: harness-class files MUST never appear in a
  per-group required_paths_regex
- §4 hard constraint #9: extended invariant to include harness class
  with explicit file list
- §5 acceptance: extended self-test case (c) to include harness-class
  example (common/cached_compile.rs) + explicit verification list

#2 (cargo test substring, not glob):
- §1 YAML examples: cost_lens_* → cost_lens; *_emit_* → emit; added
  IMPORTANT comment explaining libtest substring semantics +
  forbidding glob syntax
- §2 test_pattern column spec: re-documented as 'libtest test-name
  SUBSTRING filter (NOT a glob)' with cost_lens example + glob
  forbiddance + --exact alternative
- §2 inline illustrative table: cost_lens_* → cost_lens (and others);
  added trailing comment naming substring semantics
- §4 new hard constraint #10: test_pattern is substring filter not
  glob; self-test that the value substitutes verbatim into cargo test
  and runs positive number of tests
- §5 acceptance: new 'test_pattern substring-filter check passes' criterion
  with empirical pilot-wave validation requirement

Brief now P3 fail-closed at both the boundary (shared-infra full-run
including harness) AND the selector (substring filter that workers can
copy verbatim without silent zero-test execution). Single-absorption
pass; awaiting fresh review at new HEAD.

* docs(briefs): reframe PM template citation per codex P1/P2 — template is on PR #2721, NOT yet landed on main

codex REQUEST_CHANGES on PR #2719 (review #9754):

Line 128 named docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md
as a 'landed' starting authority, but git ls-tree origin/main returns no
blob and git ls-files returns nothing. A worker following this brief
would be sent to a non-existent source of truth — INVARIANTS P1/P2
authority-grounding violation in a dispatch document.

Verified at HEAD:
- git ls-tree origin/main -- docs/briefs/r3-ci-layer-2-pm-prestaged-mgr-fill-template.md → empty
- gh pr view 2721 → state=OPEN, mergedAt=null
- Template lives on PR #2721's branch only

Fix: reframe the template citation to acknowledge PR #2721 is open-not-landed.
- 'landed via PR #2721' → 'open as PR #2721 ... NOT yet landed on main'
- Added codex BLOCKING citation + verification receipt (git ls-tree result)
- Added explicit authority caveat: Verification Mgr finalization MUST
  coordinate merge sequencing — (a) merge #2721 first, OR (b) read from
  PR #2721 branch until it merges
- Named PM (deep-wolf-155) as PR #2721 author + cross-link for merge coordination
- Cited sha 262f42d (PR #2721 post-fix state per PM msg_125e3aa5)

Brief now accurately grounded on the actual file location (PR #2721 branch)
with merge-sequencing guidance for Mgr finalization. Authority chain
honest about in-flight vs landed state.

* WIP: gunbc Director

* docs(briefs): absorb 3 BLOCKING findings (Brian + codex) — R4 lifecycle reframe + canonical 2-step + count fix

Brian inline BLOCKING #1 + codex BLOCKING #1 (P5 dissolution-trigger
authority): brief framed dissolution as R3 close-blocking gate
'ci_uses_provable_minimal_affected_set_selection' but
docs/design-affected-set-lens.md:3 = 'R4 wishlist', :354 = 'CI integration
sketch (deferred to R4 full delivery)', :366 = 'CI integration is R4
full-delivery work'. No ROADMAP authority exists for the cited gate name
— that was Director-tier speculation.

Brian inline BLOCKING #2 + codex BLOCKING #2 (Facts Flow Forward / surviving
schema): §3 post-dissolution sketch only encoded dimension intersection,
silently dropping NodeRef intersection. Canonical 2-step per design §5:359
requires BOTH (TestClaim.refs ∩ affected_nodes) ≠ ∅ AND (TestClaim.dims ∩
changed.dims) ≠ ∅. Reducing surviving schema to (group_name, dimensions)
too early.

codex non-blocking: slow-test-exemptions.txt count cited as 78 (PM
template value); actual is 80 at 2026-05-12T00:50Z (verified locally:
grep -v '^#' ... | grep -v '^$' | wc -l = 80).

Fixes (single absorption pass):

§0 'Bridge-debt → dissolution lifecycle' bullet:
- Reframed from 'R3 close-blocking gate' to 'R4-bounded dissolution
  lifecycle (NOT R3 close)' with explicit citation of design doc :3 + :354
  + :366. Names R4.B as R4 owner. Removes the speculative gate name.
  Names Brian's BLOCKING #1 absorption.

§0 NEW 'Post-dissolution selection semantics (canonical 2-step join)'
bullet: explicit NodeRef + dimension joins per design :359; run formula;
skip formula; bridge coarseness acknowledgment (path-regex over-approximates
canonical lens; fail-closed-safe but coarser). Names Brian's BLOCKING #2
absorption.

§0 polarity check bullet: updated skip-form to reflect 2-step (NodeRef-empty
OR dim-empty ⇒ unaffected ⇒ skip).

§2 inventory source (a): count 78 → 80 at 3 sites (replace_all), with
explanation that count grows over time + Mgr re-runs grep at finalization
rather than relying on stale citations.

§2 table column spec: added 'testclaim_references' as 5th column. Cited
Brian's BLOCKING #2; explains bridge-tier proxy vs post-dissolution proxy.

§2 [Mgr-fill]: extended to require testclaim_references computation per
canonical 2-step.

§3 YAML post-dissolution sketch: rewrote classify step to compose BOTH
NodeRef AND dimension intersections via jq + cite Brian's BLOCKING #2
absorption inline. Header comment names R4.B authority and acknowledges
no current ROADMAP gate ID.

§4 #4 PR-body bridge-debt template: reworded from 'R3 close-blocking gate'
to 'R4.B Introspect-lens saturation lane CI integration delivery; NOT R3
close-blocking.'

§8 surviving artifact: corrected from (group_name, dimensions) to
(group_name, dimensions, testclaim_references) per canonical; cited
Brian's BLOCKING #2.

Removed all references to 'ci_uses_provable_minimal_affected_set_selection'
as a current ROADMAP gate name; replaced with R4.B owning-lane references
+ explicit acknowledgment of authority gap.

Brief now P5-honest: dissolution trigger is checkable (R4.B owning lane)
even if no concrete gate ID yet; surviving schema preserves both lens
join inputs per canonical algorithm.

* docs(briefs): reconcile §3 substantive + §7 STOP with §0/§8 — surviving schema is 3-column (cursor internal-consistency catch)

cursor REQUEST_CHANGES on PR #2719 sha 540113f (review #9767):

Two internal contradictions surfaced from my partial absorption of Brian's
BLOCKING #2:

(a) §3 substantive paragraph still said '(group_name, dimensions) mapping
survives the dissolution — only required_paths_regex column gets retired'
contradicting §0 + §8 which were updated to 3-column (group_name,
dimensions, testclaim_references).

(b) §7 STOP bullet referenced 'Layer 2 dissolution shape doesn't match
(group_name, dimensions) schema' — 2-column framing, same contradiction.

Fix:

§3 substantive paragraph (around the parallel-representation-debt rationale):
- 2-column → 3-column framing
- both dimensions AND testclaim_references must be authored
- cite design §:359 canonical 2-step join
- cite cursor internal-consistency catch alongside Brian's BLOCKING #2

§7 STOP escalation bullet:
- (group_name, dimensions) → (group_name, dimensions, testclaim_references)
  + cite canonical 2-step join

Verified via grep: all remaining
references are within meta-statements explicitly documenting the removal
(line 10 + line 268); no live references remain. All
appearances are either in updated 3-column contexts or in meta-statements
referencing the absorption (line 15 catch citation).

Brief now internally coherent across §0, §3, §7, §8 on:
- dissolution trigger (R4.B owning lane, NOT removed-gate-name)
- surviving schema (3 columns including testclaim_references)
- canonical 2-step join semantics

* docs(briefs): fix stale 78 inventory references at §2 lines 114 + 141 per openai-pro BLOCKING

openai-pro REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9779):

Brief had stale '78 active >2s entries' at line 114 + 'All 78 ... entries'
at line 141, despite §0 line 19 + §2 line 157 stating live count is 80
and Mgr should re-run count at finalization. A worker following §2
literally could build the gating table from stale 78-entry basis,
omitting 2 slow-test entries — fail-open shape against the brief's own
P3 fail-closed contract (under-inventory = exemption falls in neither
per-group regex nor full-run bucket = silently skipped).

Fix:

§2 inventory source (a) (line 114): replaced 'start with the 78 active
>2s entries' with 'start with the current live count of active >2s
entries (Mgr MUST re-run grep ... | wc -l at finalization; 80 at
2026-05-12T00:50Z but count grows; do NOT cite the stale 78 from PM
template PR #2721 or any earlier reference)'. Added 'fail-closed
completeness invariant' inline: every active exemption MUST appear in
either a per-group required_paths_regex OR the harness/shared-infra
full-run bucket; no exemption left unclassified.

§2 PM template description (line 141): 'All 78 entries' → 'PM-grouped
entries (PM template snapshot was 78 at template authoring time; live
count grows — Mgr re-verifies via wc -l at finalization, NOT this
stale historical reference)'. Added note that the 9-cluster taxonomy
survives count growth; Mgr maps new entries to existing clusters or
escalates if a new cluster surface emerges.

Brief is now internally consistent on inventory-count freshness:
- §0 line 19: live 80 with verification command
- §2 line 114: re-run command at finalization; explicit do-not-cite-78 instruction
- §2 line 141: PM template snapshot historical; live count grows
- §2 line 157 (Mgr-fill): re-run grep, don't trust stale citations

12th distinct review-class catch this polish cycle: inventory-citation
freshness as fail-closed completeness invariant.

* docs(briefs): §5 acceptance requires testclaim_references explicitly per codex BLOCKING #9780

codex REQUEST_CHANGES on PR #2719 sha 8ae7938 (review #9780):

Finding #1 (stale 78 at lines 114 + 141) already fixed at prior commit
487d175; codex finding overlaps with openai-pro #9779 absorbed before.

Finding #2 (new): §5 acceptance at line 228 only required dimensions:
Set<Dimension> on each group entry, NOT testclaim_references: Set<NodeRef>,
even though the brief makes that column load-bearing at:
- §0 line 104 (post-dissolution selection canonical 2-step)
- §3 line 178 (substantive paragraph: 3-column surviving schema)
- §8 line 269 (surviving artifact 3-column)

A Mgr reading §5 acceptance literally could call PR-set 'done' with
dimensions-only column population — that's the dimensions-only closeout
codex flags as facts-flow-forward violation.

Fix: §5 acceptance adds new explicit criterion:
'Every group entry has testclaim_references: Set<NodeRef> field' with
explicit citation chain (design §:359 + Brian BLOCKING #2 + codex
BLOCKING #9780). Includes bridge-tier-proxy vs post-dissolution-proxy
note. Includes 'Dimensions-only acceptance closeout is rejected: P2
facts-flow-forward requires both lens-join inputs.'

§5 acceptance now coherent with §0/§3/§8 on the 3-column surviving
schema; no path to 'done' that skips testclaim_references.

13th distinct review-class catch this polish cycle:
acceptance-vs-substantive-text divergence on load-bearing fields.

* docs(briefs): Director scaffold for cold-v3 rebuild coordinator (Phase 3-pattern; per-cut child workers)

Per PM greenlight msg_07f73de0 + Brian operator greenlight at gunbc#846
reply (~01:25Z 2026-05-12). Pre-authored scaffold per
feedback_pre_authored_brief_queue + feedback_director_mgr_energy_input;
activation triggers on empirical post-#2723 cold-v3 wall-clock measurement.

Scope: rebuild 20 hot-fix-2026-05-12-tagged cut tests under
OnceLock/cached_compile/shared-fixture amortization. Each rebuild PR:
- Removes #[ignore] attribute
- Retires slow-test-exemptions.txt row
- Decrements TEST_TIMEOUT_MAX_EXEMPTIONS in lockstep
- Verifies <2s wall on cold ubuntu-latest

Brief covers:
- §0 scope: full 20-test inventory grouped into 9 clusters (A-I) by
  lane + amortization affinity
- §1 mechanism: 4-step per-cut worker pattern (baseline, refactor,
  verify, re-enable + retire-exemption)
- §2 6 hard constraints (preserve semantics, ratchet-down per PR,
  amortization-mechanism-only, no new hand-Rust, per-cluster fidelity,
  re-enable-with-ratchet-down enforcement)
- §3 acceptance: per-PR + final cold-v3 ≤10min + ratchet floor ≤80
- §4 decomposition: pilot (Cluster A) → high-impact (Cluster H TC1
  140s) → parallel rollout → ratchet sweep
- §5 STOP-and-escalate criteria
- §6 cross-coordinator notes:
  - T-LAS Mgr seat gap (Cluster F) — Director surfaces ownership
  - Phase 3 #84 cluster overlap — Verification Mgr decides Layer 2
    rebuild PR vs Cluster M Phase 3 PR routing
  - Layer 2 brief #2719 INDEPENDENT — rebuild is structural regardless

Activation decision branch:
- post-#2723 cold-v3 >20min → second cut session
- 10-20min → rebuild alongside possible second-cut
- ≤10min → rebuild can de-prioritize

Per-cluster routing:
- A+I → PB Mgr (Lane 3 Stage 3c)
- B → Substrate Mgr (M1_5_DESIGN)
- C/D/E/G → Verification Mgr (this brief's coordinator)
- F (T-LAS) → Director-routed operator-tier (no standing Mgr seat)
- H (TC1 substrate-adjacent) → Substrate Mgr or dedicated session

Authority chain documented in footer.

* docs(briefs): absorb Brian + codex 3-finding BLOCKING wave (P5 receipts, dynamic ratchet floor, polarity-residual)

Brian inline BLOCKINGs + codex scheduled review BLOCKING #9XXX at PR #2725
sha 698ba61 (4 findings total; codex overlaps with all 3 Brian findings):

(1) #2725 line 70 (constraint #4) — shared-fixture helper carve-out
permits expanded hand-Rust under src/v3/compiler/tests without INVARIANTS
P5 receipt. Brian: P5 receipt required for new/expanded src/v3 Rust.
Codex: require P5 receipt OR state SG-0-neutral without helper expansion.

(2) #2725 line 83 (§3 acceptance final bullet) — hard-codes ratchet floor
≤80 (pre-hot-fix baseline), preserving stale debt. Brian: current main has
84 active exemptions with 20 hot-fix rows; post-rebuild floor should be
recomputed, not preserved at 80. Codex: derive final floor from live
non-hot-fix exemptions at Mgr finalization; delete hard-coded ≤80.

(3) #2719 line 217 (§4 hard constraint #5 Polarity invariant sub-bullet) —
restates skip formula as dimension-only, contradicting two-step
NodeRef+dimension contract. Brian: silently drops testclaim_references in
violation of P2 Facts Flow Forward. Codex: rewrite every formula to skip
when refs∩nodes empty OR dims∩changed_dims empty. (Partial-absorption-
residual: cursor's catch on #2725 review #9799 was fixed at §3 substantive
paragraph at commit 403833e but didn't propagate to §4 constraint #5
sub-bullet at line 217 — different polarity-mentioning site within the
same brief.)

Fixes (single-pass per discipline; same pattern as prior 14-catch cycle):

#2725 constraint #4 (line 70) rewrite:
- 'No new hand-Rust beyond shared-fixture helpers' (carve-out) →
  'Shared-fixture helpers require P5 receipt + SG-0-neutrality'
- Per-PR P5 receipt explicit: (a) helper LOC delta cited, (b) dissolution
  path named (helper retires when cluster's pattern lands in .dag
  TestClaim authority), (c) SG-0 census-delta computation showing net
  ≤ 0
- SG-0-neutrality enforcement: helpers may add lines but net delta ≤ 0
  (helper additions offset by exemption-row retirements + ratchet-down).
  Net positive = escalate (substrate-shape signal)

#2725 §3 acceptance final bullet (line 83) rewrite:
- 'ratchet floor returned to ≤80 (pre-hot-fix baseline)' → 'ratchet floor
  recomputed DYNAMICALLY from live state at activation'
- Concrete computation: starts at current main HEAD's
  TEST_TIMEOUT_MAX_EXEMPTIONS (84 at dfbc010; verify via grep at Mgr
  finalization); each rebuild PR decrements by N (cuts rebuilt that PR);
  post-all-20-rebuild target = (value at activation) - 20 (e.g., 64 at
  current state)
- Removed '≤80 pre-hot-fix baseline' framing
- Explicit acknowledgment: 80 was ITSELF stale debt; 16 non-hot-fix
  exemptions have separate paydown owners; rebuild does NOT freeze goal
  at 80; long-run target per feedback_pb_zero_is_r3_close_target is 0

#2719 §4 constraint #5 (line 217) rewrite:
- Header changed: '...dimensions: Set<Dimension> field on every group
  entry' → '...dimensions: Set<Dimension> + testclaim_references:
  Set<NodeRef> fields on every group entry'
- Polarity invariant rewritten to canonical 2-step join (BOTH NodeRef AND
  dimension intersections; skip = either empty)
- Two fail-open bug patterns explicitly named: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved (path-regex over-approximates
  canonical; fail-closed-safe coarseness)

15th + 16th + 17th distinct review-class catches this polish cycle (16
on #2719 brief; #15 on rebuild scaffold #2725):
- #15 (BLOCKING #1): shared-fixture helper P5 receipt obligation
- #16 (BLOCKING #2): dynamic ratchet floor recomputation
- #17 (BLOCKING #3): polarity-residual at second site (partial-absorption-
  residual within partial-absorption-fix; pattern: 'when canonical
  algorithm gets corrected, ENUMERATE all polarity-mentioning sites'
  is the discipline)

* docs(briefs): apply §3 polarity 2-step rewrite on rebuild-scaffold branch (cursor #9815 catch + #2719-branch parity)

cursor APPROVE_WITH_COMMENTS on #2725 review #9815 caught that line 208
(§3 substantive Polarity invariant paragraph) on rebuild-scaffold branch's
copy of #2719 brief was still dimensions-only — even though line 217 (§4
constraint #5 sub-bullet) was updated to canonical 2-step in commit
900d5a3.

Root cause: my prior #2719 polarity fix at commit 403833e was on #2719's
own branch (director/r3-ci-layer-2-path-conditional-gating-scaffold) and
never propagated to main → never reached rebuild-scaffold branch's copy
of the #2719 brief brought in via main-merge.

Applied same §3 polarity rewrite on rebuild-scaffold branch for parity
with #2719 branch's content:
- run = (refs ∩ nodes) ≠ ∅ AND (dims ∩ changed_dims) ≠ ∅
- skip = ¬run = either intersection ∅
- Explicit naming of TWO fail-open patterns: (a) inversion (b)
  dimension-only collapse
- Bridge-tier proxy framing preserved

Cross-branch state now consistent:
- #2719 branch (director/r3-ci-layer-2-path-conditional-gating-scaffold)
  has canonical 2-step at lines 208 + 229 (via 403833e)
- #2725 branch (director/r3-ci-cold-v3-rebuild-coordinator-scaffold) has
  canonical 2-step at lines 208 + 229 (via 900d5a3 + this commit)

Both branches' copies of #2719 brief now structurally identical on
polarity semantics. Will fully reconcile at merge time if both PRs land
separately.

18th distinct review-class catch this polish cycle:
cross-branch-divergence-on-shared-doc — when two Director-scaffold PRs
both touch a shared brief (one via direct edit, one via main-merge),
fixes on one branch must explicitly propagate to the other branch OR
the shared content reconciles at merge time. Pattern: 'shared doc in
two PRs requires explicit cross-branch parity discipline'.

* docs(briefs): fix Phase 4 ratchet sweep residual ≤80 → dynamic (value − 20) per codex BLOCKING #9827

codex BLOCKING on #2725 review #9827 caught residual at line 92 (§4 Phase 4
ratchet sweep description) — still said 'back to ≤80' despite §3 acceptance
bullet's stale-baseline correction (which removed the ≤80 framing in favor
of dynamic '(value at activation) - 20').

Same partial-absorption-residual class as cursor's earlier catches:
fixing the §3 acceptance bullet correction didn't propagate to §4 Phase 4
description; sites referring to the same stale value need parallel updates.

Fix: Phase 4 description now uses dynamic '(value at activation) − 20'
(e.g., 64 at current state of 84) with explicit acknowledgment that 80
was itself stale debt + cross-link to feedback_pb_zero_is_r3_close_target
naming the long-run target = 0 exemptions.

21st distinct review-class catch this polish cycle:
phase-description-vs-acceptance-bullet-residual — when an acceptance
bullet gets a corrected target, the phase descriptions that motivate
phases toward that target need parallel updates. Pattern: 'when target
gets corrected, ENUMERATE all phase descriptions / decomposition / STOP
criteria that motivate work toward that target.'

* fix(#2725): cursor BLOCKING #9834 absorbed

Two findings addressed:

1. Line 76 copy-paste slip: "The Layer 2 PR-set is acceptable when:"
   in a cold-v3 rebuild brief. Changed to "The cold-v3 rebuild PR-set
   is acceptable when:" to match brief's actual scope. INVARIANTS.md
   P1 modeling faithfulness for dispatch authority.

2. Line 70 prose tightening: SG-0-neutrality framing previously
   conflated SG-0 census mechanism with exemption-list mechanism
   ("helper additions offset by exemption-row retirements +
   ratchet-down"). These are DIFFERENT bookkeeping: SG-0 counts
   hand-Rust files/lines per sg0_census_test.rs; exemption-row
   retirement only reduces slow-test-exemptions.txt count. Corrected
   prose: helper-LOC additions in common/* MUST be offset by EQUAL-
   or-greater LOC reductions in per-test files consuming the helper
   (shared fixture extraction → per-test setup boilerplate dropped).
   Exemption-row retirement + ratchet-down are independent
   obligations per constraint #2 and do NOT count toward SG-0
   census-delta.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* WIP: gunbc Director

* fix(#2725): openai-pro REQUEST_CHANGES — 2 BLOCKING findings absorbed

Finding 1 (P3 Fail-Closed): Layer 2 shared-infra regex anchored Cargo.toml/
Cargo.lock/build.rs to workspace-root only. Crate-local manifests (e.g.,
src/v3/compiler/build.rs per CODING.md:319) would NOT match, silently
skipping tests for crate-local manifest/build-script changes — fail-open
boundary class P3 forbids. Fixed by changing the anchored alternates to
use (.*/)?Cargo\.(toml|lock) and (.*/)?build\.rs — non-capturing optional
path prefix matches both root-level AND any-depth crate-local files.

Finding 2 (ratchet/test discipline): Cold-rebuild brief had execution-path
contradiction. §2#2 + §3 require same-PR lockstep ratchet-down. But §4
Phase 4 description said "drops TEST_TIMEOUT_MAX_EXEMPTIONS to (activation)
- 20", creating a fail-open path where workers could defer per-PR ratchet-
down to Phase 4 cleanup. Reframed Phase 4 as VERIFICATION + budget-tighten
(NOT decrement). Phase 4 verifies cumulative ratchet matches target +
drops cold-CI --timeout. If verification finds mismatch, escalate per §5
(per-PR discipline violation), do NOT silently patch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
Per Director ratification of Q1(a) + Q2(b) (msg_c1daa5ae 2026-05-12):

- dsl/ctrl/README.md — scaffold + path/module/receipt conventions
- docs/briefs/r4-ctrl-migration-pr-digests-worker.md — trio-anchor
  worker brief (catalog #8; smallest Phase 3 footprint)
- Mgr-brief Working-state: Director ratifications recorded; artifact
  index added; full 8-item Wave-1 dispatch queue ordered
  smallest-surface-first

Worker briefs for catalog #10/#16/#14/#12/#11/#3/#5 land in follow-up
PRs (one canonical brief per subsystem per
feedback_one_canonical_subissue_per_workitem.md).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
…and #16

(i) PB lane Wave-1 dispatch per r3-remaining-work-dependency-graph §5.
(ii) Briefs r3-wave1-pb1-tier3-gate2-computation-mirror-worker.md and
r3-wave1-pb2-fixedpoint-gate16-r3-horizon-worker.md; graph §5 links them.
(iii) No SG-0 census edits in this commit.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
regen_bootstrap --verify failed in CI: embedded Span offsets for
src/v3/std/verification.dag drifted when gate #16 banner comments were
added. Refresh bootstrap_generated*.rs from .dag sources.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
briansrls added a commit that referenced this pull request May 12, 2026
…#2777)

* docs(briefs): R4 ctrl-migration Subsystem-Modeling Mgr standing brief

Phase 1.5 Mgr-tier standing program for the ctrl/ → .dag migration
(parent program tree authored via PR #2775; landing as DRAFT pending
that PR's merge so authority chain is clean).

Operationalizes project-plan §3 (16-subsystem catalog) / §6 (parallel-
critical-path with staged-debt throttle) / §7 (Wave-1 / Wave-2 dispatch
shape) / §8 (per-worker brief template) as the Mgr-tier standing
program. Carries forward 7 cross-role discipline items from MEMORY.md
that apply to every dispatch this lane fires.

Key load-bearing elements:
- Wave-1-trio checkpoint (per claude #10327): block Wave-2 dispatch
  until one full trio (algebra ✓ + Phase 1.5 PR ✓ + Phase 3 emission ✓)
  converges; recommended anchor = catalog #8 (PR digests) for smallest
  Phase 3 footprint
- Staged-debt budget: 3 unmatched Phase 1.5 stagings pauses dispatch
  (structural enforcement, not soft signal)
- Per-worker brief template: Practice-4 receipts for EVERY enum/sum
  with ≥2 variants (per codex #10331 finding #5, not just open enums)
- Wave-1 / Wave-2 split derived from §3 catalog dependency annotations

Mgr session merry-newt-448 / work-item adhoc-5d3bbf79-ce5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): scaffold + trio-anchor worker brief + dispatch queue

Per Director ratification of Q1(a) + Q2(b) (msg_c1daa5ae 2026-05-12):

- dsl/ctrl/README.md — scaffold + path/module/receipt conventions
- docs/briefs/r4-ctrl-migration-pr-digests-worker.md — trio-anchor
  worker brief (catalog #8; smallest Phase 3 footprint)
- Mgr-brief Working-state: Director ratifications recorded; artifact
  index added; full 8-item Wave-1 dispatch queue ordered
  smallest-surface-first

Worker briefs for catalog #10/#16/#14/#12/#11/#3/#5 land in follow-up
PRs (one canonical brief per subsystem per
feedback_one_canonical_subissue_per_workitem.md).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): apply Emission-Mgr placement correction to trio anchor

Per Emission-Targets Mgr deep-ibex-326 msg_c83099ac 2026-05-12:
dsl/extdeps/github/ owns GitHub-API source-of-record facts only.
PR-digest rendering is gunbc-owned, not an extdep field.

Updates:
- pr-digests-worker brief: Phase-3 partner renamed
  dsl/extdeps/github/digest_render.dag → dsl/gunbc/digest_render.dag
  (consumes dsl/extdeps/github/pulls.dag + dsl/std/render.dag)
- pr-digests-worker brief: explicit DO-NOT placement directive in
  acceptance gate 3 + STOP-criterion clarifies new GitHub source
  carriers must land in extdeps, not gunbc
- dsl/ctrl/README.md: 3-tier placement discipline (extdeps =
  third-party facts; gunbc = rendering/projection/policy; std =
  domain-agnostic primitives) explicit in consumer-receipt rule
- Mgr standing brief Working-state: cross-Mgr ping refs recorded;
  placement-correction memorialized; future worker briefs MUST
  name correct placement before dispatch (standing checklist item)

Direct application of feedback_extdeps_header_discriminator_before_
field_placement.md to this lane. Trio anchor no longer gates on
Emission Mgr's HTTP/SQL PR #2778 — converges via parallel
gunbc-owned render landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs+audit): Director template-revise + receipt-trail ledger

Three concurrent Mgr ratifications landed 2026-05-12 in one cycle:

1. Director clever-ant-97 (msg_0707a7c8 + msg_d1589d17) — template
   revise: replace dsl/extdeps/github/digest_render.dag trigger with
   neutral 3-part Phase-3 trigger (digest source-fact authority +
   gunbc/std render projection + named parity harness green); do NOT
   inflate PullRequest with render/digest fields; update STOP
   criterion to route source-fact gaps to Emission, not invent on
   gunbc side.

2. Emission-Targets Mgr deep-ibex-326 (msg_f9d2bfab) — confirms #8
   trio anchor + extdep-gap finding: pulls.dag has PullRequest/
   PullRequestRef/IssueComment but NOT GithubPr/CiState/ConflictState.
   Initial brief invented those names — direct
   substrate-grep-before-authoring miss. Memorialized in Mgr brief
   self-correction + added grep-real-type-names discipline to
   per-worker-brief checklist.

3. Verification Mgr deep-badger-38 (msg_5f8db22f + msg_6faaf178) —
   receipt-trail ledger ratified. Single SoT landed at
   docs/audit/r4-ctrl-phase15-subsystem-receipt-trail.md with 4-tuple
   bool columns, derived open_receipt_debt flag, count≥3 dispatch-
   pause gate, full ownership division (Subsystem-Modeling owns row
   inserts; Verification owns column semantics + parity flips;
   Emission flips phase3_emission_landed). First row (catalog #8
   placeholder) inserted.

PR-digests worker brief revised:
- Module header carries neutral 3-part Phase-3 trigger
- Service-block sketch uses REAL PullRequest carrier from
  dsl/extdeps/github/pulls.dag (verified on main 2026-05-12)
- CI/conflict input facts noted as source-fact placeholders pending
  Emission-Mgr placement (NOT defined on gunbc side; NOT fields on
  PullRequest)
- STOP criterion updated per Director: route source-fact gaps to
  Emission, narrow to existing PullRequest fields, or wait

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): narrow trio-anchor scope to smaller-first-path

Per Emission-Targets Mgr deep-ibex-326 msg_c5b7d419 2026-05-12 ratification:
take the smaller first path; do not block trio anchor on new CI/conflict/
mergeability carriers; no pull_digest.dag prerequisite.

PR-digests worker brief:
- Carrier-import scope narrowed to existing PullRequest / PullRequestRef /
  PullReview (ListReviews output) / Diff operation output / IssueComment —
  all verified on main 2026-05-12
- Gunbc-side carriers shrunk: MergeReadinessVerdict reasons derive from
  existing fields only (draft/state/merged_at + review states); no
  CI/conflict reason types
- Service block reduced to 4 signatures: extract_attached_urls /
  render_pr_summary_line / merge_readiness_verdict / classify_rest_fallback
- render_ci_digest + render_conflict_digest deferred to follow-up
  Phase 1.5 PR (post-landing only if parity proves load-bearing)
- STOP criterion replaced: do NOT block this PR on CI/conflict source-fact
  placement; surface unrenderable-digest gaps to Mgr as follow-up routing,
  not prerequisite

Mgr brief Working-state: scope-narrow memorialized; removes Emission-side
prerequisite from trio anchor critical path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): remove live-file assumption for dsl/std/markdown_render.dag

Per Director clever-ant-97 msg_96a23421 2026-05-12: dsl/std/markdown_render.dag
is NOT on main (verified — only a forward-reference comment in
dsl/std/render.dag mentions it as a future format-specific wrapper).

Citations replaced in both brief files:
- "composing dsl/std/render.dag + dsl/std/markdown_render.dag" →
  "render projection over dsl/std/render.dag; any Markdown-specific
  wrapper is a separate authority decision, not assumed live"
- Director attribution + 2026-05-12 verification date inline

No other behavioral changes; rest of placement correction (source facts
from extdeps.github.pulls, no PullRequest inflation, gunbc-owned digest
projection, receipt ledger shape) remains intact.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): fix cursor/composer-2 BLOCKING — extdep→gunbc projection

Per cursor/composer-2 review on PR #2777 2026-05-12T20:13Z: two stale
"render-helpers extdep" references in Wave-1-trio rationale sections
contradicted the corrected placement (gunbc-owned render projection,
not extdep) encoded elsewhere in the PR.

- Mgr brief §"Wave-1-trio checkpoint" / Recommended trio anchor:
  "smallest possible Phase 3 deliverable (a render-helpers extdep,
   essentially zero new external authority)" →
  "smallest possible — a gunbc-owned render projection over
   dsl/std/render.dag (proposed dsl/gunbc/digest_render.dag),
   consuming GitHub source facts already in dsl/extdeps/github/pulls.
   dag. Per INVARIANTS P1 + feedback_extdeps_header_discriminator_
   before_field_placement.md: extdeps own third-party source facts;
   rendering/projection is gunbc-owned. The trio's Phase-3 emission
   is NOT an extdep landing."

- PR-digests worker brief §"Wave-1-trio-anchor status":
  "Phase 3 render-helpers extdep ✓" →
  "Phase 3 gunbc-owned render projection over dsl/std/render.dag ✓
   + named parity-harness gate green ✓"
  plus explicit "Phase-3 is gunbc-owned render projection, NOT a new
  extdep" attribution to Director/Emission ratification 2026-05-12

Grep-verified: zero remaining "render-helpers" or "render helpers"
strings across briefs / README / ledger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs+audit): address operator codex BLOCKING (4 findings, a6bd5f5)

Per operator review on PR #2777 2026-05-12T20:11Z (4 BLOCKING):

#1 Ledger trio gate algebra ambiguity — clarified N/A semantics in
   docs/audit/r4-ctrl-phase15-subsystem-receipt-trail.md: algebra_landed
   ∈ {true, —} is treated as satisfied; only false is unsatisfied.
   open_receipt_debt explicitly does NOT reference algebra_landed (it's
   a per-row receipt, not a global gate). Wave-1-trio gate spelled
   out as the conjunction over the satisfied-set. Admits non-consumer
   trio anchor (catalog #8) without misclassification.

#2 Mgr brief restated throttle predicate — replaced restatement in
   §"Staged-debt budget" with single-source reference to ledger's
   open_receipt_debt + dispatch-pause gate. Mgr enforces; Verification
   owns column semantics; predicate adjustments land in ledger first.

#3 AttachedUrlSource dimensional check miss — split conflated sum
   into two independent coordinates per Practice 4:
   - AttachedUrlContainer: PrBody | IssueCommentBody | PullReviewBody
     | ReviewCommentBody  (source-container dimension)
   - AttachedUrlTextContext: Prose | InlineCode
     (text-context dimension)
   AttachedUrl record now carries both coordinates separately.
   Practice-4 receipts required on both sums.

#4 MergeReadinessVerdict bare-list cardinality — replaced
   NotReady(reasons: List<String>) with structural-cardinality form:
   NotReady { first_reason: String, more_reasons: List<String> }
   The ≥1 invariant is now encoded in the carrier shape; NotReady
   with zero reasons is uninhabitable by construction.

Acceptance gate 2 updated: 4 Practice-4 receipts (was 3) reflecting
dimensional split. Cost-of-change gate updated to cover new variant
additions on both AttachedUrl coordinate sums.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(audit): tighten algebra_landed type to bool | "—"

Reinforces operator-codex BLOCKING #1 (inline at ledger:21) fix landed
in c3eccb3: column type now structurally encodes the N/A admissibility
(was 'bool', now 'bool | "—"') and the evidence cell clarifies that
"—" is a structural assertion of non-consumer-status, not a placeholder
for "unknown". The §"N/A semantics" block remains the authoritative
gate-semantics definition.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(briefs): tighten staged-debt operational-meaning to include parity

Reinforces operator-codex BLOCKING #2 (inline at mgr brief :54) fix
landed in c3eccb3: the §"Staged-debt budget" §-tail operational
paragraph now explicitly states that clearing open_receipt_debt
requires BOTH phase3_emission_landed AND parity_passed (matching the
ledger's predicate exactly), removing the residual "Phase-3 partner"
phrasing that read as ignoring parity. The ledger remains the single
authority for the predicate; this brief defers verbatim.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: fix competing-authority triggers (operator BLOCKING README:5)

Per operator inline review on PR #2777 dsl/ctrl/README.md:5 2026-05-12
T21:29Z: the README declared trio convergence as the STAGED→AUTHORITY
trigger, while the worker brief header AND the README's own line :3
declared the ctrl-side cut-over (TS deletion) as the authority event.
Two triggers for one authority flip violates INVARIANTS P2/P5 single-
trigger discipline.

Resolution: single-trigger discipline made explicit across all three
files. The ONLY event that flips STAGED → AUTHORITY for a subsystem
is the ctrl PR cut-over (Phase 4) deleting the corresponding TS
files. Trio convergence (algebra + Phase 1.5 PR + Phase 3 emission +
parity) is the *gating precondition* that authorizes cut-over
dispatch, not the authority flip itself.

- dsl/ctrl/README.md §"Authority": rewritten to name cut-over as the
  single trigger; trio as gating precondition.
- worker brief module-header receipt: STAGED → AUTHORITY trigger
  named as the cut-over event; trio reframed as the precondition
  list that authorizes cut-over dispatch.
- Mgr brief §"Wave-1-trio checkpoint": Wave-1-trio convergence
  qualified as "gating precondition for Phase 4 cut-over dispatch,
  NOT itself the STAGED→AUTHORITY flip."

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: split parity-proof + deletion gates; remove ReviewCommentBody

Two operator BLOCKING findings (codex sha 42218c5 + inline at worker
brief :77) addressed:

#1 (codex BLOCKING / README): tightened §"Authority" to explicitly
   split the two gates by named role, matching the codex framing:
   - Parity-proof gate (readiness): trio convergence; proves the
     .dag substrate can stand in for TS; does NOT itself flip
     authority.
   - Source-authority deletion gate (STAGED → AUTHORITY flip):
     ctrl PR cut-over deleting TS files; only event that flips
     authority; the PR's merge IS the deletion receipt.
   Parity-proof is the precondition for cut-over dispatch; not
   sufficient alone. No overlap window between substrates.

#2 (inline BLOCKING / worker brief :77): AttachedUrlContainer
   widened to include ReviewCommentBody without matching source-fact
   import (extract_attached_urls only takes PullRequest +
   List<IssueComment> + List<PullReview>; no List<ReviewComment>).
   Resolved by dropping ReviewCommentBody from this worker's scope:
   AttachedUrlContainer = PrBody | IssueCommentBody | PullReviewBody,
   one-to-one with the imported source-fact set. ReviewCommentBody
   gates on a follow-up Phase 1.5 PR that adds ListReviewComments
   to imports. Until then no AttachedUrl value can claim a
   ReviewComment source — INVARIANTS P2 single-authority holds.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: align Wave-1-trio algebra-leg wording with ledger SoT

Per cursor/composer-2 APPROVE_WITH_COMMENTS review on PR #2777
2026-05-12T21:46Z (2 P2 findings + 1 cosmetic):

1. Mgr brief :68 — "algebra ✓ (Phase 1 substrate landed)" omitted
   the ledger's N/A case for non-consumer rows. Rewritten to:
   "algebra_landed ✓ (per ledger N/A semantics: ∈ {true, —} is
   satisfied — non-consumer Wave-1 anchor like catalog #8 satisfies
   this leg with —, does NOT require Phase 1 substrate first)" with
   inline link to ledger §N/A semantics / §Wave-1-trio gate. P2
   compliance: ledger is sole SoT for predicates; brief defers.

2. README §"Authority" parity-proof gate — same shorthand widened
   to ledger-column names + N/A semantics + pointer to ledger as
   single source of truth.

3. Worker brief :39 cosmetic — broken **/doubled-** fixed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 12, 2026
* WIP: R3 PB Mgr — T-LP-Retirement + Tier3 + V2 + FixedPoint lanes

* docs(briefs): Wave-1 PB1/PB2 pre-authored worker briefs for gates #2 and #16

(i) PB lane Wave-1 dispatch per r3-remaining-work-dependency-graph §5.
(ii) Briefs r3-wave1-pb1-tier3-gate2-computation-mirror-worker.md and
r3-wave1-pb2-fixedpoint-gate16-r3-horizon-worker.md; graph §5 links them.
(iii) No SG-0 census edits in this commit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(test): brace-balance source slice for tier3 kernel_algebra_profile ratchet

Addresses claude-opus-4-7 review (PR #2781): replace fixed 1200-byte window
with brace-balanced extraction of pub fn type_iteration_dimension so the
grep receipt cannot silently miss delegation if the function grows.

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: R3 PB Mgr — T-LP-Retirement + Tier3 + V2 + FixedPoint lanes

* docs: P5 receipt + §1.7 vs §P2 split for Tier3 gate #2 (PR #2781 review)

- r3-program-plan §1.7: state-check gates use CONSUMER_LANDED in executable-consumer sense only; §P2 generated-consumer bar is substrate-shape scope (#17).
- §1.8 row #2 + Status-at-HEAD: cite INVARIANTS P5 table row for m2_substrate ratchet.
- INVARIANTS: register m2_substrate_inhabitance_test.rs P5 Mechanism (b) receipt (ROADMAP Tier-3 bullet + r3-program §1.8 #2, interim ratchet named).

Co-authored-by: Cursor <cursoragent@cursor.com>

* WIP: R3 PB Mgr — T-LP-Retirement + Tier3 + V2 + FixedPoint lanes

* docs(INVARIANTS): name both Tier3 gate #2 interim ratchets in m2_substrate P5 row

PR #2789 landed `tier3_computation_mirror_trivial_constructors_dissolved`; PB Mgr
branch keeps `tier3_computation_mirror_kernel_algebra_profile_substrate_authority`.
Single receipt row lists both so SG-0 / plan stay aligned after merge-from-main.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
- Add gate-16 worker brief under docs/briefs (dispatch vs default paths).
- Cross-link self_host_fixed_point, db-8, verification.dag, and CI to
  r3-program-plan §1.8 #16 and r3-pb-t-fixedpoint-worker (two-horizon
  discipline; strong suite remains dispatch-gated).
- Point PB2 row in r3-remaining-work-dependency-graph at the brief.

No R1 verification.dag claim or test_runner semantics changed.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
regen_bootstrap --verify failed in CI: embedded Span offsets for
src/v3/std/verification.dag drifted when gate #16 banner comments were
added. Refresh bootstrap_generated*.rs from .dag sources.

Co-authored-by: Cursor <cursoragent@cursor.com>
briansrls added a commit that referenced this pull request May 12, 2026
(i) PB T-FixedPoint §1.8 gate #16 — Wave-1 P0 readiness slice (two-horizon framing; no R1 semantic change).

(ii) Docs/cross-links: docs/briefs/r3-wave1-pb2-fixedpoint-gate16-r3-horizon-worker.md; docs/db-history/db-8.md; docs/r3-remaining-work-dependency-graph.md; .github/workflows/ci.yml (self_host_ratchet commentary); src/v3/compiler/src/bin/self_host_fixed_point.rs; comment-only banner in src/v3/std/verification.dag before FixedPointConverges; bootstrap_generated.rs + bootstrap_generated_without_parse_surface.rs span regen from .dag comment insert. Authorities: docs/briefs/r3-pb-t-fixedpoint-worker.md; docs/r3-structure.md §T-FixedPoint.

(iii) SG-0 / hand-authored non-test census: no delta (none).
briansrls added a commit that referenced this pull request May 13, 2026
…s (cursor/composer-2 exploratory)

Bare-filename mentions of self_host_fixed_point.rs, db-8.md, verification.dag
in PR #2811 receipts now use full repo-relative paths to match the precision
bar of sibling table rows (e.g. row 428 cites
`src/v3/compiler/src/lens_apply.rs`):

- `src/v3/compiler/src/bin/self_host_fixed_point.rs`
- `docs/db-history/db-8.md`
- `src/v3/std/verification.dag`

cursor/composer-2 review on PR #2811 (artifacts/stdout.log) flagged the
inconsistency as editorial-not-principle; APPROVE verdict otherwise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…t P0 pin landing (#2811)

* docs(r3): §1.5 + §1.8 #16 drift sweep — T-LP redispatch + T-FixedPoint P0 pin landing

§1.5 lane status row T-LensProducer-Retirement: drop stale "valiant-otter-715
active on #5" / "warm-crab-600 active on #7" text — both sessions ARCHIVED
without closing their gates per Director audit (msg_312fead3); files at HEAD
(`src/v3/compiler/src/lens_apply.rs` + `src/v3/compiler/src/bin/regen_lens.rs`).

Replace with: gate #5 redispatched 2026-05-13 under R3 PB Mgr tidy-raven-311
(work-item adhoc-0cb1ea52-4ab against existing brief
`docs/briefs/r3-pb-t-lensproducer-sub1-lens-apply-retirement.md`); gate #7
sequencing-held pending `BinShimFilesSubsetPredicate` substrate landing in
`src/v3/std/verification.dag` (only `LensProducerFilesSubsetPredicate`
precedent at `:44`/`:46` exists at HEAD; brief shape ratified 2026-05-09 via
gunbc#2068 c#4411574142 but carriers not yet in `verification.dag`).

§1.5 lane status row T-FixedPoint: was "(TBD from PB canvas)". Update with
PR #2783 (Wave-1 PB2 P0 pins) MERGED 2026-05-12 23:22Z reflecting gate #16
R3-horizon P0 readiness alignment per
`docs/briefs/r3-wave1-pb2-fixedpoint-gate16-r3-horizon-worker.md`
§"Wave-1 allowed work, default path"; P3 strong-fixed-point sequencing held
on joint-precondition rule.

§1.8 row #16 (`pb_self_compile_fixed_point`): annotate Status with PR #2783
P0 receipts (no R1 Pass/Fail change; R3 stronger interpretation still pending
joint preconditions).

Discipline: per `feedback_grep_audit_docs_before_no_gate_claim` +
`feedback_thesis_gate_state_drift` (Director-cited 2026-05-13 in
msg_312fead3); §1.5 row 428 was carrying ghost-session dispatch text past
worker archival.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): tighten repo-paths in §1.5 #432 + §1.8 #16 PR #2783 receipts (cursor/composer-2 exploratory)

Bare-filename mentions of self_host_fixed_point.rs, db-8.md, verification.dag
in PR #2811 receipts now use full repo-relative paths to match the precision
bar of sibling table rows (e.g. row 428 cites
`src/v3/compiler/src/lens_apply.rs`):

- `src/v3/compiler/src/bin/self_host_fixed_point.rs`
- `docs/db-history/db-8.md`
- `src/v3/std/verification.dag`

cursor/composer-2 review on PR #2811 (artifacts/stdout.log) flagged the
inconsistency as editorial-not-principle; APPROVE verdict otherwise.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 13, 2026
…ncing (DRAFT) (#3013)

* docs(r3): R3 actual-close plan — 10 adversarial gaps with disposition + dispatch sequencing (DRAFT pending Director + operator ratification)

Operator directive 2026-05-13 verbatim: "can we start on the planning docs to get to ACTUAL r3 close? like all of our adversarial questions answered positively? i feel like the planning for this stuff has been continuously dropped".

PM-authored planning doc replacing "viz-as-SoT closed_at + DECLARED-strings-are-drift" framing with explicit per-gap disposition for the 10 substantive counterfactuals surfaced by today's adversarial audit:

1. PB-0 zero hand-Rust (177+ entries in EXPECTED_HAND_AUTHORED_NON_TEST; gate #8 DECLARED)
2. L5 cross-target consistency (gate #15 DECLARED; no Python/Go executable emission on main)
3. Self-host fixed point R3-strong (gate #16 R1-horizon only; 4 joint preconditions deferred)
4. Lens behavioral parity (3 of 4 lenses NOT behaviorally complete; gates #79/#81/#82/#83)
5. Tests-as-data completeness (gate #84 Cluster M Phase 3 bulk-port pending; load-bearing-blocking)
6. v2 retirement terminal (gate #97 coherence-only; src/v2/ exists at HEAD)
7. T-WAD FULL R3 (gates #98-#103 all DECLARED; ci.yml still hand-edited)
8. Bootstrap-seed Rust survivors (folded into Gap 1)
9. Show-the-correct-code (no §1.8 gate exists for THESIS:103-105)
10. Close-audit doc absent (interrogation §8 self-check has no execution log on main)

For each gap: promise verbatim + HEAD evidence + what's missing + plan to cash (owner, sub-program, effort estimate) + close criterion predicate.

§2 dispatch sequencing: 6 phases A-F mapped to Substrate Mgr / Verification Mgr / Debt-Paydown Mgr / Director-tier coordination / PM-direct.

§3 total time-to-actual-close: 8-12 weeks optimistic; 12-20 realistic; 6+ months if PB-0 retirement is the longest tail and can't parallelize aggressively.

§4 operator decision points: 4 binary IN-R3 / R4-defer choices that determine actual R3 scope (PB-0, L5 cross-target, self-host R3-strong, show-correct-code).

§5 process discipline (preventing future drop): single authoritative plan doc, weekly PM closure-cadence message, per-gap closure-PR template, Gap 10 (close-audit doc) authored FIRST as receipt mechanism.

Authority:
- Operator directive 2026-05-13 (planning request)
- Today's adversarial audit findings (counterfactual evidence against viz-as-SoT closure claim)
- THESIS.md promise enumeration + r3-close-interrogation.md §-by-§ adversarial structure
- §1.8 closure-authority ledger gate state at HEAD

Status: DRAFT pending Director ratification + operator scope-decision approval before dispatch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): Gap 4 — cite closed PR #2860 as content-source for parallelism cementing-receipt re-launch (Director msg_b3324a05 flag)

Director (msg_b3324a05) flagged PR #2860 (G87-C parallelism cementing receipt + ratchet repair, closed 2026-05-13T16:45:44Z under operator cleanup directive) as load-bearing for counterfactual #4 / Gap 4 parallelism behavioral parity. The PR content is retrievable via `gh pr view 2860 --json body` so the Gap 4 cementing-receipt re-launch doesn't author from scratch.

Adds PR #2860 reference to Gap 4 sub-program as step 2 (between F-α and F-β.1), with concrete artifact paths + dissolution-trigger naming + relationship-to-F-α clarification (cementing-receipt is gate-#87 ratchet-discipline level, distinct from F-α Stage 2e walker port which is substrate work).

Both are required for full Gap 4 closure. Cementing-receipt re-launch is cheaper (PR #2860 substance ready); F-α walker port is the larger substrate scope.

Authority:
- Director msg_b3324a05 flag (2026-05-13)
- PR #2860 substance per gh API retrieval
- §1.8 row #87 lens_cementing_test_discipline_complete (CONSUMER_LANDED + PASSING; ratchet fires on inventory mismatch)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): integrate Director msg_cd2d8d7d 8 substantive feedback items into close plan

Director (zesty-bear-812) ratified PR #3013 structure + dispatch sequencing + §5 process discipline. 8 substantive items applied:

1. **§4 R4-carve framing collision** — Per `project_no_r4_carves_directive` (Brian 2026-05-08), R4-carve is NOT freely available as default. §4 reframed: 4 decisions default to IN-R3; explicit override required with stated structural-unblockable reason. §5 process-discipline note added.

2. **Gap 3 R2-Evaluator audit** — Director-tier deliverable picked up by zesty-bear-812 (this week per msg_cd2d8d7d). §6 deliverables list tracks.

3. **Gap 4 sequential cadence as Mgr-bandwidth lever** — Effort estimate split: single-Mgr sequential 4-8wk vs parallelized-via-2nd-Substrate-Mgr ~2-4wk. Surfaced as tightening lever, not foreclosed.

4. **Gap 5 close-criterion header-marker filter** — Predicate amended to `xargs grep -L "// AUTO-GENERATED FROM .dag" | wc -l == 0` so generated-from-.dag tests are filterable. Substrate prereq: code-gen emits header line; if not present at HEAD, lands in Gap 5 Phase 3 ratchet.

5. **Gap 6 transitive-dependency depth** — Explicit 5+ deep chain call-out: Gap 6 ← Gap 3 ← {Gap 1, R2-Evaluator, R2-Grounding, Row-B}. Gap 6 framed as close-ceremony terminal gate (last 2 weeks of R3 close).

6. **Gap 9 threshold = operator decision** — ≥80% pragmatic relaxation is operator-decision-shaped, not Director-decision. §4 now surfaces (a) IN-R3 vs not-R3-promised choice + (b) if IN-R3, threshold = 100% (THESIS-correct) or ≥X% pragmatic with named-residual list. Per `project_no_r4_carves_directive`, the not-R3-promised reframe is structurally an R4-carve requiring operator override.

7. **Gap 10 timeline calibrated** — Skeleton 1-2 days (PM-direct, unblocked, immediate); execution 1-2 weeks (Verification Mgr serial) or 3-5 days (ctrl-build parallel). Overall ~1-2 weeks for full landing.

8. **Phase F bookkeeping downstream of close-audit-doc verdict** — §2 Phase F reworded: §1.8 manifest strings sync to close-audit-doc predicate-execution outcome (View-4-authoritative per `feedback_r3_close_three_views_drift`), NOT to procedural `closed_at` markers. Sequencing: close-audit-doc lands first; bookkeeping PR consumes that doc as authority. Avoids procedural-closure trap.

§6 pending-decisions list updated:
- Director ratification: checked ✓
- Operator §4 confirmations: 4 sub-items per gap
- Director-tier deliverables in-flight per msg_cd2d8d7d (4 items)
- Operator Phase A authorization

Authority:
- Director ratification msg_cd2d8d7d (2026-05-13) — substance verdict + 8 feedback items
- `project_no_r4_carves_directive` (Brian 2026-05-08, 5d-old memory but still presumptively in force; surfaced for operator confirmation)
- `feedback_r3_close_three_views_drift` View 4 authoritative (Director memory update post-msg_b3324a05)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): claude review 11247 exploratory observations integrated (PM recs explicit per gap + Gap 9 canvas-promotion note + §3 velocity-citation discipline)

3 non-blocking exploratory observations from claude APPROVE review on PR #3013 sha a4d1608 at 2026-05-13T18:03:26Z:

1. **§4 PM-recommendation explicitness across all 4 gaps** — previously only Gap 1 stated "do not defer." Added explicit PM-recommended IN-R3 + reasoning for Gaps 2/3/9 with each R4-carve's specific dilution impact (omni-emission falsifier loss, self-host thesis dilution, THESIS:103-105 absolute promise drop). §4 preamble now states cross-gap PM view + per-gap recommendation.

2. **Gap 9 substrate-shape canvas-promotion** — `correction: Option<Witness>` field commitment is buried in planning-doc prose; promoted to Substrate-Mgr-canvas-before-worker-dispatch step. Canvas authoring + Director ratification gates worker dispatch.

3. **§3 velocity-citation discipline** — most estimates were unsourced beyond Gap 1's `feedback_pre_authored_brief_queue` reference. Added explicit caveat: Gaps 2/3/5/6/7/9 are PM-prior-cycle-experience-based; final ratified version cites per-gap velocity reference + first weekly closure-cadence message calibrates against actual landing-date data.

Authority:
- claude APPROVE review 11247 on PR #3013 sha a4d1608 at 2026-05-13T18:03:26Z
- All 3 observations non-blocking; addressing pre-operator-review for cleaner ratification

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): retract Gap 5 boundary carve-out + Gap 9 pragmatic-relaxation per codex BLOCKING PR #3013

Two substantive close-criteria fixes per codex BLOCKING 2026-05-13T18:19:56Z:

**Finding 1 — Gap 5 boundary carve-out violates 0-residual** (TESTING.md L212-217 +
docs/design-pure-bootstrap-zero.md:41,138):
- Removed `-not -path "*/boundary/*"` from gate #84 close predicate
- Added authority citation: TESTING.md "🔄 RETRACTED 2026-04-25" + 0-floor target
- Boundary tests ARE counted; migrate to ExecuteCommand-based .dag TestClaim per cascade

**Finding 2 — Gap 9 pragmatic-relaxation dilutes THESIS absolute** (THESIS.md
"show the correct code" reads as absolute promise):
- Removed "Pragmatic relaxation (≥X%)" alternative from Gap 9 close criterion
- Removed §4 operator sub-decision (b) threshold negotiation
- Close criterion is 100% absolute; non-100% requires R4-carve override of
  project_no_r4_carves_directive (NOT within-R3 threshold negotiation)

**Additional: Phase F adversarial re-pass discipline** (operator directive
2026-05-13 — final closeout will be adversarial analysis):
- Phase F now explicitly includes operator+PM adversarial re-pass against
  interrogation doc + close plan + §1.8 row statuses
- Bookkeeping PR sequencing updated: depends on adversarial-re-pass verdict,
  not just predicate execution outcome
- Symmetric to 2026-05-13 adversarial sweep that surfaced 10 counterfactuals;
  applied at close ceremony to confirm none survived

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): retract fabricated Tier-2 R4-deferral authority per briansrls BLOCKING PR #3013

briansrls BLOCKING 2026-05-13T18:22:57Z at docs/r3-actual-close-plan.md:48:

> "The PB-0 alternative disposition cites design-pure-bootstrap-zero.md as
> allowing Tier-2 R4 deferral for grounding submodules, but that authority
> sets a 0 hand-authored in-tree Rust floor, so this creates an unauthorized
> escape hatch against the Pure Bootstrap target."

**Verified**: grep -nE "tier[- ]2|grounding|R4|defer|carve" against
docs/design-pure-bootstrap-zero.md returns ONLY one hit (L131: historical
TESTING.md carve-out which the doc explicitly retracts under 0-floor target).
Zero references to "Tier-2", "grounding submodules deferred", or any
R4-deferral carve-out mechanism. The "Tier-2 R4-deferred per
design-pure-bootstrap-zero.md" citation in Gap 1 alternative-disposition was
fabricated authority — an unauthorized escape hatch against the absolute
0-floor target.

**Fix**:
- Removed the fabricated citation
- Explicit statement: PB-0 design doc admits no internal escape hatch
- R4-carve of PB-0 subsets requires explicit operator override of
  project_no_r4_carves_directive (2026-05-08), naming specific subset +
  structural-unblockable reason — not citation of an unauthorized escape
- PM-recommendation preserved (do NOT R4-defer; standing directive applies)

Symmetric to the Gap 9 pragmatic-relaxation fix at commit 870f6ce — both
findings reflect the same anti-pattern of converting absolute thesis claims
into negotiable thresholds via fabricated/imputed authority.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): replace textual AUTO-GENERATED marker with structural EXPECTED_HAND_AUTHORED_TEST list-emptied predicate per briansrls BLOCKING PR #3013

briansrls BLOCKING 2026-05-13T18:22:57Z at docs/r3-actual-close-plan.md:183:

> "The gate #84 close predicate uses the `// AUTO-GENERATED FROM .dag`
> comment as the authority for generated tests, which can pass with
> hand-authored Rust carrying the marker and does not prove the THESIS
> tests-as-data claim."

**Verified**: this is exactly the feedback_no_textual_enforcement_bridges
anti-pattern — "never propose grep/regex as interim enforcement; text-gating
'be structural' defeats itself." A textual comment is gameable; a developer
could add `// AUTO-GENERATED FROM .dag` to a hand-authored file to bypass
the ratchet. The THESIS claim ("every Rust test ports to .dag or is
generated") is structural and requires a structural predicate.

**Fix**: replaced the textual-marker predicate with the structural
EXPECTED_HAND_AUTHORED_TEST list-emptied authority — the same ratchet Gap 1
uses for EXPECTED_HAND_AUTHORED_NON_TEST. Every hand-authored test entry
must be named on the list (PR-template enforcement); migrations remove
entries; close fires when list empties. The list discriminates structurally,
not textually.

Preserved the no-boundary-carve-out authority citations (separate codex
BLOCKING) — boundary entries are named on EXPECTED_HAND_AUTHORED_TEST and
dissolve through migration like any other entry, no separate carve-out.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): retract Option<Witness> shape per briansrls BLOCKING PR #3013 — Practice-2 carrier refinement

briansrls BLOCKING 2026-05-13T18:22:57Z at docs/r3-actual-close-plan.md:277:

> "The proposed correction: Option<Witness> shape leaves 'diagnostic
> without correction' representable even though the THESIS-correct path
> requires diagnostics to point to the structurally correct program."

**Verified** against three converging memory authorities:
- feedback_state_space_vs_behavioral_invariants — "check if the type admits
  illegal state combinations; type enforcement > API enforcement"
- feedback_optional_models_recovery_as_exception — "T? where absence is the
  norm conceals plurality"
- feedback_practice_2_vs_4_same_variant_vs_cross_variant — Practice-2 carrier
  refinement when the redundant/illegal state crosses variant boundaries

Option<Witness> admits None which structurally represents "diagnostic without
correction" — exactly the state THESIS.md "show the correct code" forbids
absolutely. The type itself admits the illegal state; behavioral checks
("did this fired diagnostic produce a correction?") are API-tier enforcement
that the carrier-tier should subsume.

**Fix**: substrate-shape constraint added to Gap 9 sub-program step 4: canvas
authors MUST commit `correction: Witness` (non-optional) — Practice-2 carrier
refinement makes diagnostic-without-correction unrepresentable by construction.
Anti-pattern symmetric to Gap 9 pragmatic-relaxation fix at 870f6ce (both
findings convert absolute THESIS claim into expressible-but-forbidden state).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): address 3 codex BLOCKING + 1 non-blocking on PR #3013

codex BLOCKING 2026-05-13T18:22:57Z (sha f05359f) — 3 root-causes + 1 improvement:

**B1 — Tier-2 feature-deferral example removed entirely** (Gap 1 alternative-disposition):
Prior fix at a973064 retained the fabricated example in retraction-framing.
Codex stronger ask: "remove the example OR require operator-approved amendment
to PB-zero authority". Reframed: no Tier-2 example survives this section; any
R4-carve requires BOTH (1) override of project_no_r4_carves_directive AND
(2) amendment to docs/design-pure-bootstrap-zero.md authority text adding a
per-subset deferral carrier. Neither alone is sufficient.

**B2 — Generator-manifest positive structural authority** (Gap 5 close criterion):
Prior fix at 29684a0 gave negative authority (list-emptied) but codex asks
positive form. Added dual predicate: (a) EXPECTED_HAND_AUTHORED_TEST = empty
[negative] + (b) generator-manifest maps each surviving test → its .dag source
+ regeneration-byte-equality fail-close on drift [positive]. Catches orphan
generated files that negative form alone misses. Substrate prereq: manifest
carrier authored as Cluster M Phase 3 expansion.

**B3 — Deferral carrier with named reason** (Gap 9 substrate-shape):
Prior fix at 5872dae had correction: Witness covering only the 100% path.
Codex asks separation of absolute-thesis vs pragmatic-residual into named
carrier variants. Reshaped to sum Correction = LiveCorrection { witness } |
DeferredCorrection { reason, retirement_plan }. Diagnostic.correction is
mandatory Correction (not Option). Residual is structurally named with
retirement-plan accountability; gate #84/#106 close requires every
DeferredCorrection ratchetable to zero per its own retirement plan.

**NB1 — Ledger-derived row-count** (Gap 10 close criterion):
Hard-coded "ALL 105 rows" rotted as soon as Gap 9 proposed row #106. Per
feedback_no_snapshot_integers_in_briefs: derive count from §1.8 ledger at
execution time via grep enumeration; Gap 9 row #106 + subsequent additions
automatically included.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): close §6/§4 INVARIANTS P2 violation + footer drift per cursor APPROVE_WITH_COMMENTS PR #3013

cursor/composer-2 APPROVE_WITH_COMMENTS 2026-05-13T18:35:17Z:

**Finding 1 — INVARIANTS P2 violation (§6 vs §4 duplicate Gap 9 authority)**:
§6 operator checklist still offered "ratify threshold = 100% (THESIS-correct) OR
≥X% (pragmatic, X TBD); (b) override with not-R3-promised reframe" — exactly the
within-R3 threshold negotiation that §4 retracted in the prior fix at 870f6ce.
Two "authoritative" asks for the same Gap 9 decision = INVARIANTS P2 single-place-
for-the-fact violation.

**Fix**: rewrote §6 Gap 9 bullet to match §4 — single binary decision (IN-R3 at
100% absolute OR R4-carve via explicit operator override of
project_no_r4_carves_directive). No threshold negotiation; no sub-decision (b)
since §4 removed it. §4 is now the single authority for the Gap 9 disposition.

**Finding 2 (exploratory) — §6 vs footer drift**:
§6 line 453 marks "Director ratifies this plan structure — APPROVED 2026-05-13"
✓ but footer at line 471 still said "DRAFT pending Director ratification +
operator scope approval". Director already ratified structure per msg_cd2d8d7d;
only operator scope approval is pending.

**Fix**: tightened footer to "Director structure-ratified 2026-05-13; DRAFT
pending operator scope approval (§4 IN-R3 confirmations + Phase A dispatch
authorization)" — preserves the actual gating state without contradicting §6
checklist.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): align Gap 9 close criterion to sum-variant Correction carrier per codex BLOCKING #11273 PR #3013

Prior fix at 9d763dd ratified `sum Correction { LiveCorrection | DeferredCorrection }` substrate-shape canvas (Practice-2 carrier refinement: nullable `Option<Witness>` admits illegal "diagnostic without correction" state). But the close criterion still read `correction: Witness` + `Some(_)` — the retracted Option shape it was meant to replace. P2 single-authority violation: two incompatible carrier shapes for the same Diagnostic.correction field in adjacent text.

Rewrote close criterion as:
- Structural (compiler-enforced): every Diagnostic carries mandatory `correction: Correction` field (sum-variant, no Option-wrapping)
- Variant-tally (zero-DeferredCorrection): every fired Diagnostic in test corpus is LiveCorrection variant; count of DeferredCorrection = 0
- Substrate ratchet: every DeferredCorrection entry ratchetable to zero per its own retirement_plan field

Preserved both retraction citations (codex BLOCKING #11254 pragmatic-relaxation + briansrls Option<Witness>) as audit trail. Close criterion now matches the canvas substrate-shape commitment by construction.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): absorb Director R2-Evaluator audit msg_82b9c4bb — Gap 3 expansion + §4 sub-item 5 (Mgr dispatch) + r3-program-plan thesis-state drift reframe

Director-tier R2-Evaluator audit (PR #3013 Gap 3 precondition deliverable from msg_cd2d8d7d) surfaced 3 structural findings:

(a) R2 closed-with-residuals 2026-04-29 16:34Z (#1275; ROADMAP.md:512) with 5 sub-lanes carried as r3-continuation: runtime_value_model_structural (in-flight #1197/#1228/#1231), body_evaluator_structural (not-started), lens_application_complete_reflection (in-flight #1191), witness_construction_structural (not-started), cross_target_equivalence_harness_structural (not-started). Closure-ledger row stale @ #1191-#1231 era (HEAD is #3013+).

(b) R3 Evaluator Mgr merry-gull-128 (#1743) ABSENT from current subtree at HEAD. Authority dispersed across 3 R3 Mgrs without single owner — r2-structure.md:73 anti-pattern reincarnation under R3-tier-slice procedural wrapper.

(c) Brief surface comprehensive (r2-evaluator-manager.md + 4 sub-briefs + 10+ PR-A-E + R3-tier per-slice briefs); not the gap.

(d) Director recommends re-spawn evaluator Mgr as 4th R3 Mgr lane.

PM execution (bundled per feedback_bundle_workstreams_per_pr):

1. r3-actual-close-plan.md Gap 3 expansion: cite all 5 sub-lanes explicitly; reframe R2-Evaluator HEAD evidence from "landed" to "closed-with-residuals with 5 sub-lane debt"; note merry-gull-128 absence; close-criterion now requires (i) 5 sub-lanes ratchet-to-PASSING OR per-sub-lane R4-carve carrier with named retirement plan (substrate-shape symmetry with Gap 9 DeferredCorrection discipline), AND (ii) §4 sub-item 5 Mgr-dispatch disposition ratified.

2. r3-actual-close-plan.md §4 sub-item 5 (subtree-shape decision): R3 Evaluator Mgr dispatch with 3 operator sub-options — (a) re-spawn 4th lane PM+Director recommended, (b) fold into existing R3 Mgrs with named risk, (c) Director-direct ad-hoc PM-does-not-recommend per r2-structure.md:73 retraction. §6 checklist updated to track.

3. r3-program-plan.md lines 429/435 reframe: strike "R2-Evaluator (interpreter-as-data; LANDED)" / "R2-Evaluator landed" → "R2-Evaluator closed-with-residuals 2026-04-29 16:34Z per ROADMAP.md:512 — sub-lane completion partial via R3-tier slices, see Gap 3 in r3-actual-close-plan.md". Catches feedback_thesis_gate_state_drift class.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): split Gap 3 close criterion from dispatch staffing prereq + use r2-closure-ledger authority for sub-lanes per Director notes msg_f0a54769 PR #3013

Director note msg_f0a54769 surfaced 3 substantive shape issues on the 85c230b Director-audit absorption:

Note 1 (sub-lane name authority): the 5 R2-Evaluator sub-lane names (runtime_value_model_structural / body_evaluator_structural / lens_application_complete_reflection / witness_construction_structural / cross_target_equivalence_harness_structural) live in `docs/r2-closure-ledger.md:250-263`, NOT as §1.8 row IDs in `docs/r3-program-plan.md`. Prior draft conflated authorities ("PASSING in §1.8" mismatches the actual artifact). PM-selected path (α): use sub-lane names as predicate authority per `feedback_parallel_representation_debt` — don't introduce 5 new §1.8 rows for already-named ledger content. Predicate is cell-level check of `docs/r2-closure-ledger.md` (each sub-lane row status=green at HEAD); closure-ledger row stale @ #1191-#1231 era requires refresh first.

Note 2 (staffing-as-criterion vs precondition): staffing/dispatch shape is a PRECONDITION for execution, not a close criterion for the substrate-debt itself. If a Mgr exists but doesn't close the 5 sub-lanes, Gap 3 isn't closed; if alternative dispatch (fold/ad-hoc) closes them, Gap 3 IS closed. Moved "(ii) R3 Evaluator Mgr lane owner identified" from close criterion to new "Dispatch staffing prereq" section. Close criterion now purely substrate-debt-shaped.

Note 3 (sequencing): re-spawn AFTER operator §4 sub-item 5 ratification, NOT before. Sequence explicit in Dispatch staffing prereq section per `feedback_construction_over_ratchets` adjacent class — don't author the Mgr until the operator-decision substrate cashes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): operator-ratification recorded — all 4 IN-R3 + §4 sub-item 5 re-spawn (a) + Phase A authorized PR #3013

Operator (briansrls) ratification 2026-05-13 via direct PM dispatch:

- Items 1-4 (R3 scope decisions): ALL IN-R3 confirmed per project_no_r4_carves_directive default. No R4-carves.
  - Gap 1 (PB-0): full 177-entry retirement
  - Gap 2 (L5 cross-target): full 3-target Python+Go
  - Gap 3 (self-host R3-strong): 4-joint-precondition cascade
  - Gap 9 (show-correct-code): 100% absolute (zero DeferredCorrection per sum-variant carrier)

- Item 5 (R3 Evaluator Mgr dispatch subtree-shape decision): (a) re-spawn as 4th R3 Mgr lane confirmed. Director (zesty-bear-812) executes per pre-authorization at msg_d456b60d.

- Phase A immediate dispatch authorized (implicit in ratification). Close-audit doc skeleton + §1.8 row #106 authoring proceeds PM-direct post-merge.

§6 checklist updated: all operator-decision boxes checked. Director-tier deliverable R2-Evaluator audit also marked complete (msg_82b9c4bb 2026-05-13; absorbed at 85c230b + 97cfb9d). Footer status updated from "DRAFT pending operator scope approval" to "operator fully ratified 2026-05-13; READY FOR DISPATCH post-merge".

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): absorb codex BLOCKING #11284 + reframe alternative-disposition class per operator §4 ratification PR #3013

Codex BLOCKING #11284 (2 findings on 97cfb9d):

F1 — `docs/r3-actual-close-plan.md:11` closure target generically allowed any adversarial gap to be "explicitly R4-deferred", semantically reintroducing a carve-out path the design-pure-bootstrap-zero.md + r3-program-plan.md authorities explicitly forbid. PM-intent dilution.

F2 — `docs/r3-actual-close-plan.md:89` Gap 2 alternative-disposition authored Rust-only-Shape-A scope-narrow as an explicit fallback, semantically weakening the §3.1 3-target promise without prior authority reconciliation.

Both findings are an instance of a broader class: alternative-disposition language across §0 + Gaps 1/2/3/9 was authored pre-ratification when operator hadn't yet foreclosed those paths. Post-operator-§4 ratification 2026-05-13 (ALL IN-R3, no R4-carves), they are stale-against-ratification.

Consistent reframe applied to all 4 alternative-disposition instances:
- Line 11 (§0 closure target): R4-defer / THESIS-reframe paths STRUCTURALLY FORECLOSED per operator §4 IN-R3 ratification; legacy alt-disposition sections retained as audit-trail not as available paths.
- Line 48 (Gap 1 alt disposition): operator §4 Item 1 IN-R3 ratification supersedes; dual-amendment authority chain preserved as closure-rule discipline for any future re-opening.
- Line 89 (Gap 2 alt disposition): operator §4 Item 2 IN-R3 ratification forecloses Rust-only-narrow.
- Line 133 (Gap 3 alt disposition): operator §4 Item 3 IN-R3 ratification forecloses R1-horizon-narrow + 5-sub-lane R4-carve.
- Line 342 (Gap 9 alt disposition): operator §4 Item 4 IN-R3 ratification forecloses THESIS-aspirational-not-R3-promised reframe.

Also propagated ratification state into §4 header (request-for-ratification → RATIFIED 2026-05-13) + line 3 Status line (DRAFT → FULLY RATIFIED).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
…chor per codex BLOCKING #11738 PR #3069 schedule-review + feedback_section_anchors_over_line_numbers

codex BLOCKING schedule-review summary on commit 0161ddb (193s wall):
- Phase 2.4 closure-predicate prose encoded volatile line ranges (`docs/r2-closure-ledger.md:250-263`) instead of stable ledger section/gate anchors
- Per feedback_section_anchors_over_line_numbers — section/symbol anchors preferred over line numbers; line numbers drift when ledger is amended
- Cited authority ranges may not cover every required row + line numbers will drift on ledger updates

Fix: replaced both occurrences of `docs/r2-closure-ledger.md:250-263` with stable section anchor `docs/r2-closure-ledger.md §"Evaluator Manager — T-Evaluator"`:
- docs/r3-actual-close-plan.md:114 (Gap 3 close criterion narration)
- docs/r3-program-plan.md:243 (§1.8 gate #16 row)

Section anchor "Evaluator Manager — T-Evaluator" is the H3 header at line 254 of r2-closure-ledger.md and covers all 5 sub-lane rows + the 5 named gate IDs (runtime_value_model_structural / body_evaluator_structural / lens_application_complete_reflection / witness_construction_structural / cross_target_equivalence_harness_structural). Anchor is stable across ledger refreshes; line numbers would drift on any cell content amendment.

5 sub-lane gate IDs remain explicitly cited in adjacent prose so reviewer-grep still verifies cell-level authority per feedback_parallel_representation_debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
… closure-ledger single-source predicate (Phase 2.4) (#3069)

* docs(r3-close+program): update Gap 3 + §1.8 gate #16 to reflect operator §4 Item 5 α-ratification 2026-05-14 + closure-ledger single-source predicate (Phase 2.4)

Gap 3 Plan-to-cash + Dispatch-staffing-prereq sections:
- Owner: warm-wolf-698 expanded scope per operator §4 Item 5 α-ratification 2026-05-14 (R2-Evaluator residuals absorbed as sub-programs alongside 8 PB-X lanes); NOT just "R3 Evaluator Mgr re-spawn"
- Historical note: jolly-ram-652 R3 Evaluator Mgr lane went through one full re-spawn cycle and archived post-PR-#3053-merge per feedback_leaf_shape_mgr_one_pr_then_archive; single-cycle substantive ledger refresh cashed (3-of-5 sub-lanes GREEN at HEAD)
- Remaining 2 sub-lane closures (lens_application_complete_reflection + witness_construction_structural) execute under warm-wolf-698 expanded scope post-deployment-trigger of PR #3041 --shape flag

§1.8 gate #16 row:
- Added explicit cross-reference to docs/r2-closure-ledger.md:250-263 as predicate authority for 5 R2-Evaluator sub-lanes (NOT 5 parallel §1.8 rows)
- Per feedback_parallel_representation_debt discipline + Phase 2.4 single-reference success criterion
- Single-source predicate authority preserved at closure-ledger cell content
- 3-of-5 GREEN at HEAD post-PR-#3053 ledger refresh 2026-05-14; 2-of-5 IN-FLIGHT noted

Addresses systemic-pattern Finding 2 from PR #3061 audit doc §2.2 (R2-Evaluator lane absent → execution dispersed without single owner). Operator α-ratification 2026-05-14 resolved staffing question; this PR reflects ratified state in Gap 3 + §1.8 gate #16.

Phase 2.4 per dispatch plan §1 task table + §7 sequencing recommendation.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3): replace volatile line range :250-263 with stable section anchor per codex BLOCKING #11738 PR #3069 schedule-review + feedback_section_anchors_over_line_numbers

codex BLOCKING schedule-review summary on commit 0161ddb (193s wall):
- Phase 2.4 closure-predicate prose encoded volatile line ranges (`docs/r2-closure-ledger.md:250-263`) instead of stable ledger section/gate anchors
- Per feedback_section_anchors_over_line_numbers — section/symbol anchors preferred over line numbers; line numbers drift when ledger is amended
- Cited authority ranges may not cover every required row + line numbers will drift on ledger updates

Fix: replaced both occurrences of `docs/r2-closure-ledger.md:250-263` with stable section anchor `docs/r2-closure-ledger.md §"Evaluator Manager — T-Evaluator"`:
- docs/r3-actual-close-plan.md:114 (Gap 3 close criterion narration)
- docs/r3-program-plan.md:243 (§1.8 gate #16 row)

Section anchor "Evaluator Manager — T-Evaluator" is the H3 header at line 254 of r2-closure-ledger.md and covers all 5 sub-lane rows + the 5 named gate IDs (runtime_value_model_structural / body_evaluator_structural / lens_application_complete_reflection / witness_construction_structural / cross_target_equivalence_harness_structural). Anchor is stable across ledger refreshes; line numbers would drift on any cell content amendment.

5 sub-lane gate IDs remain explicitly cited in adjacent prose so reviewer-grep still verifies cell-level authority per feedback_parallel_representation_debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(r3-close): replace volatile line range :108-122 with stable Grounding section anchor per codex BLOCKING inline PR #3069

codex BLOCKING inline at docs/r3-actual-close-plan.md:103 (07:50:37Z): R2-Grounding cites `docs/r2-closure-ledger.md:108-122` but T-Ground rows extend to line 126 (Diagnostic / CrossTarget-Meta / Tests / Dissolve rows at 123-126 missing from cited range); joint-precondition receipt incomplete.

Fix: replaced all `docs/r2-closure-ledger.md:108-122` occurrences with stable section anchor `docs/r2-closure-ledger.md §"Grounding Manager — T-Ground"`:
- docs/r3-actual-close-plan.md:103 (Gap 3 R2-Grounding-Rust+Python sub-program)
- docs/r3-actual-close-plan.md:511 (Gap 13 HEAD evidence on engine-reframe)
- docs/r3-actual-close-plan.md:568 (Gap 13 close criterion all 11 sub-lanes)

Section anchor "Grounding Manager — T-Ground" is the H3 header at line 104 of r2-closure-ledger.md and covers all 11 sub-lane rows (Pilot / Rust / Python / Go / LanguageSpec / Coercion-Fold / Lifetime-Analyzer / CrossTarget-Meta / Diagnostic / Tests / Dissolve). Stable across ledger refreshes; row count drift would not invalidate the citation.

Same fix pattern as commit d854e1b for the R2-Evaluator section anchor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
briansrls added a commit that referenced this pull request May 14, 2026
…precondition audit (#3092)

* R3 gate #16 (T-FixedPoint) — P0 readiness pin: cross-link 2026-05-13 Gap-3 joint-precondition coordination audit

Wave-1 PB2 default-path P0 work per docs/briefs/r3-wave1-pb2-fixedpoint-gate16-r3-horizon-worker.md.
No R1 Pass/Fail change to pb_self_compile_fixed_point; gate stays sequencing-held for the R3 strong horizon.

- docs/r3-program-plan.md §1.8 row #16 + T-FixedPoint tracking row: link
  docs/audit/r3-gap3-fixed-point-precondition-coordination-2026-05-13.md
- src/v3/compiler/src/bin/self_host_fixed_point.rs header: add pointer to the audit
  reaffirming pb_self_compile_fixed_point_strong stays unauthored
- src/v3/std/verification.dag FixedPointConverges adjacent comment: same pointer

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* regen bootstrap snapshot after verification.dag comment-only edit

The 3-line comment added to FixedPointConverges adjacent block shifted
byte spans in committed bootstrap_generated.rs (and siblings). No
authority change; refresh snapshot to satisfy --verify gate.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@briansrls
briansrls deleted the claude/data-structures-dag-design-PSRmu branch June 1, 2026 18:41
briansrls added a commit that referenced this pull request Jun 24, 2026
…LIVE-flip prerequisite (#5673)

Adds dsl/gunbc/plans/ci_oom_reclassification.dag (registered in batch_f),
generating docs/plans/ci-oom-reclassification.md — the model-only design of
the cross-run clustering-reclassification consumer that is prerequisite (a)
of the green-on-main LIVE flip (ci-merge-freshness §6).

Captures the grounding signed by bright-stag:
- ONE OOM-kill fact, TWO Realization handlers (§2/§3): kernel cgroup
  memory.events oom_kill counter (hard-limit kill; reuses the
  ci_floor_measurement.dag cgroup-read surface — single measurement
  authority, no 2nd reader) + systemd-oomd journal (PSI pre-emptive kill the
  cgroup counter misses). Dispatch selects; fail-closed to Structural if
  neither confirms.
- Clustering discriminator (infra-OOM vs structural-runaway): simultaneous
  multi-job death + a host boot-id reboot oracle.
- Grounded inputs (§4), not magic numbers: clustering window = measured
  floor-batch span; boot-id = /proc/sys/kernel/random/boot_id (changed UUID
  == reboot == hard OOM-reset), read fail-closed.
- Carrier: extends FloorOutcome (gunbc.ci_failure_class, #5651) as a pure
  second pass; does NOT mutate classify_floor_exit (single-pass stays
  fail-closed). Strictly one-directional Structural→Infra on positive
  evidence only.
- §6 scaffold: model-only now; WIRED build (reclassifier + extdeps handlers
  + boot-id read + discriminating witness) lands on a fresh branch after
  #5651 merges (FloorOutcome carrier must be on main first).

Inbound link added in ci_process_end_to_end.dag §8 (a CI-floor next-step,
NOT ROADMAP) so the doc is reachable.

Verified by execution: generated_artifact_drift_gate ExitSuccess;
doc_graph_has_no_orphan_docs / _dangling_links true;
every_registered_plan_has_dissolution_trigger / _is_titled true;
generated_artifact_drift_witnesses true. Full floor confirming.

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Brian Searls <briansearls1@gmail.com>
briansrls added a commit that referenced this pull request Jun 24, 2026
… design (#5710)

Co-authored-by: Brian Searls <briansrls@gunb.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants